Skip to content

Quantum Key Distribution

Quantum key distribution (QKD) is a family of interactive protocols through which two remote parties, conventionally Alice and Bob, generate matching secret classical bit strings. The security argument combines quantum measurements with authenticated classical postprocessing. The intended output is a key,

KA=KB∈{0,1}ℓ,K_A=K_B\in\{0,1\}^{\ell},

that is nearly uniform and nearly independent of everything available to an adversary Eve.

QKD is key establishment, not message transmission and not an encryption algorithm. Once generated, the key can be supplied to a one-time pad, an authenticated-encryption scheme, or another cryptographic application. The resulting application’s security depends on that later construction, its key management, its endpoints, and the way the QKD security guarantee composes with them.

Classical Information Review owns the classical entropy, source-coding, secrecy, and cost baselines. This page owns composable QKD key security: entropy or unpredictability alone is not a secrecy proof.

The phrase “security from physics” is incomplete by itself. A QKD theorem always has the form:

For a specified protocol, device model, source of randomness, authenticated-channel construction, adversary model, and finite statistical procedure, either the parties abort or their output is close to an ideal shared key by a stated security parameter.

This page is the canonical overview of that contract, the common distillation pipeline, protocol families, finite-key accounting, authentication, and implementation boundaries. Dedicated pages own the detailed security proofs and optical designs of BB84, E91, decoy-state QKD, measurement-device-independent QKD, and device-independent QKD.

Quantum Randomness owns entropy-source trust models, health tests, standalone extraction, and Bell-certified randomness expansion or amplification. QKD consumes local random choices and performs privacy amplification inside a two-party protocol; those uses must enter its composable failure and leakage ledger.

Alice and Bob use:

  • an insecure quantum channel, which Eve may control completely;
  • a public but authenticated classical channel, which Eve may read but cannot modify or forge except with a bounded failure probability;
  • local laboratories whose trusted components and leakage assumptions must be stated;
  • local random choices with a specified quality and independence model.

A strong proof may allow Eve to replace the channel, inject arbitrary states, correlate all transmissions, retain a quantum memory indefinitely, postpone her measurement, and perform one joint coherent attack. This does not mean every implementation is secure against every physical attack. The proof only covers physical behavior represented by its model.

Let Ω\Omega denote the event that the protocol passes all tests rather than aborting, let CC be the complete public transcript, and let EE denote Eve’s final quantum and classical side information. Three properties must be kept distinct.

The keys should disagree only with small probability:

Pr⁡[KA≠KB ∧ Ω]≤εcor.\Pr[K_A\ne K_B\ \wedge\ \Omega] \le \varepsilon_{\mathrm{cor}}.

An error-verification tag sent after reconciliation normally enforces this condition. A low observed quantum bit error rate alone does not guarantee identical final strings.

Conditioned on acceptance, Alice’s key should be close to an ideal uniform key τKA\tau_{K_A} independent of Eve and the public transcript:

pΩ12∥ρKAEC∣Ω−τKA⊗ρEC∣Ω∥1≤εsec,p_{\Omega} \frac12 \left\| \rho_{K_AEC\mid\Omega} - \tau_{K_A}\otimes\rho_{EC\mid\Omega} \right\|_1 \le \varepsilon_{\mathrm{sec}},

where pΩ=Pr⁡[Ω]p_{\Omega}=\Pr[\Omega]. The factor pΩp_{\Omega} prevents a protocol that almost never accepts from receiving an artificially strong conditional security claim. Trace Distance explains why this distance bounds the distinguishing advantage between real and ideal resources.

Correctness and secrecy combine into an overall soundness error that can be bounded by

εsnd≤εcor+εsec.\varepsilon_{\mathrm{snd}} \le \varepsilon_{\mathrm{cor}} + \varepsilon_{\mathrm{sec}}.

Composable security means the real key resource can replace an ideal key resource in a larger protocol while changing the larger system’s behavior by at most the declared error. Failure budgets therefore add when secure components are composed.

A separate robustness or completeness parameter controls honest abort:

Pr⁡[¬Ω∣honest modeled devices]≤εrob.\Pr[\neg\Omega\mid\text{honest modeled devices}] \le \varepsilon_{\mathrm{rob}}.

Soundness asks whether an accepted key is secure. Robustness asks whether an honest run is likely to produce one. Eve can always block the quantum channel and force an abort, so QKD does not guarantee availability or prevent denial of service.

Quantum key distribution pipeline from quantum exchange through authenticated sifting, estimation, reconciliation, verification, and privacy amplification, with abort branches

A generic QKD session. Eve may control the quantum channel and read the classical transcript. Authentication prevents undetected substitution of classical messages. Parameter estimation and verification can force an abort; privacy amplification converts a partially secret reconciled string into a shorter composably secret key.

Although protocol details differ, a complete session has a recognizable ledger.

StageMain outputSecurity roleTypical failure or leakage
authenticated setupsession identities, parameters, fresh noncesbinds messages to this runimpersonation, replay, downgrade
quantum exchangepreparation and detection recordscreates correlations constrained by quantum theoryloss, noise, side channels, adversarial replacement
siftingcompatible events and basis labelsselects data used for tests and keypublic disclosure of settings and discarded events
parameter estimationconfidence region for channel or state parametersbounds Eve’s information or a phase-error quantityfinite-sample failure εPE\varepsilon_{\mathrm{PE}}
information reconciliationBob’s corrected candidate stringremoves Alice–Bob discrepanciestranscript leakage leakEC\mathrm{leak}_{\mathrm{EC}}
error verificationaccept or abortbounds residual key mismatchhash-collision failure εcor\varepsilon_{\mathrm{cor}}
privacy amplificationshorter final stringsremoves Eve’s bounded side informationextractor failure εPA\varepsilon_{\mathrm{PA}}
key deliverykey identifiers and synchronized key materialhands the key to an applicationendpoint, storage, reuse, or API compromise

Every public bit need not be subtracted one-for-one, but every message must appear in the security analysis. Every randomized test needs a failure probability. Authentication consumes or relies on a credential. A reported “secret-key rate” is meaningful only after these choices and the denominator have been stated.

Prepare-and-measure protocols encode data in nonorthogonal quantum states. Entanglement-based protocols distribute correlations that cannot be reproduced under the protocol’s accepted parameter region without limiting Eve’s side information. In either description, incompatible measurements create a tradeoff: gaining predictive power about one key-generating observable constrains correlations in a complementary observable.

The security mechanism is therefore not simply “measurement disturbs the photon.” A modern proof connects observed statistics to a bound such as a conditional entropy,

H(ZA∣E),H(Z_A\mid E),

or a smooth conditional min-entropy,

Hmin⁡εs(ZAn∣E).H_{\min}^{\varepsilon_s}(Z_A^n\mid E).

These quantify Eve’s uncertainty about Alice’s prospective key data under the declared model. Von Neumann Entropy supplies the asymptotic entropy language; smooth min-entropy is the one-shot quantity needed for finite blocks.

The No-Cloning and No-Signaling restrictions are relevant but insufficient as a security proof. No-cloning forbids a universal perfect copier of unknown states. It does not by itself:

  • bound Eve’s information in an optimal approximate or collective attack;
  • account for loss, multiphoton pulses, imperfect state preparation, or detector behavior;
  • authenticate Alice and Bob;
  • specify finite-sample confidence;
  • prove that the final extracted key is composably secret.

Parameter estimation does not identify Eve or distinguish malicious disturbance from ordinary noise. It determines whether the observed data fall inside a region for which a security theorem certifies an acceptable key length.

In a prepare-and-measure protocol, Alice chooses a classical symbol and setting, prepares a corresponding quantum state, and sends it to Bob. Bob chooses a measurement setting and records an outcome. Only later do they disclose enough setting information to sift and test the data.

BB84 is the canonical example: two conjugate qubit bases encode candidate key bits. The six-state protocol uses three mutually unbiased qubit bases and obtains more symmetric parameter information at the cost of additional setting choices. B92 uses two nonorthogonal states and an unambiguous-outcome structure. Continuous-variable protocols encode quadratures of optical modes and require a distinct detector, channel, and security analysis.

Real optical transmitters commonly emit phase-randomized weak coherent pulses rather than deterministic single photons. Such pulses contain vacuum, one-photon, and multiphoton components. Decoy-state methods vary the mean intensity so Alice and Bob can estimate the behavior of photon-number sectors and bound the single-photon contribution. Decoy analysis addresses photon-number-splitting vulnerabilities under its source assumptions; it does not certify every possible source imperfection.

The prepare-and-measure description is operationally direct, but security proofs often use a source-replacement picture. Alice may be imagined to prepare an entangled state

∣Ψ⟩AA′=∑xpx ∣x⟩A∣ψx⟩A′|\Psi\rangle_{AA'} = \sum_x \sqrt{p_x}\, |x\rangle_A|\psi_x\rangle_{A'}

and measure AA to choose the signal ∣ψx⟩|\psi_x\rangle sent through A′A'. This mathematical equivalence connects state preparation to entanglement and complementarity without requiring an actual entangled source in the laboratory.

In an entanglement-based protocol, a source distributes bipartite systems and Alice and Bob choose local measurements. The source may be trusted, partially characterized, or entirely untrusted depending on the protocol. Some measurement outcomes form the raw key; others estimate correlations relevant to secrecy.

E91 and Entanglement-Based QKD uses entangled pairs and Bell-type correlations. BBM92 gives an entanglement-based counterpart to BB84. Entanglement-based reasoning is especially useful because it turns secrecy into a statement about entanglement, complementarity, or monogamy of correlations. Bell States owns the standard two-qubit maximally entangled states.

Three labels that are often conflated have different trust boundaries:

FamilyWhat is moved outside the trusted model?What remains
entanglement-based QKDthe source may be placed in the channelmeasurements and other declared local behavior remain modeled
measurement-device-independent QKDthe measurement station and detectors may be untrustedsource preparation and local isolation still need characterization
device-independent QKDsecurity is inferred from loophole-controlled nonlocal correlationsrandom settings, laboratory isolation, authentication, and finite statistics still matter

Bell violation is not required for every entanglement-based QKD proof. Conversely, observing some Bell-inequality violation is not automatically a complete device-independent implementation proof. Detection, locality, memory, input-independence, and finite-size assumptions all enter.

Alice and Bob publicly reveal a randomly selected subset of outcomes or use designated test settings. From those data they construct a confidence region for quantities such as yields, bit-error rates, phase-error rates, or Bell parameters. The key-generating sample remains unrevealed.

For a simple independent Bernoulli model, Hoeffding’s inequality illustrates the statistical logic:

Pr⁡[q≥q^m+μ]≤exp⁡(−2mμ2),\Pr[ q \ge \widehat q_m+\mu ] \le \exp(-2m\mu^2),

where q^m\widehat q_m is an error frequency from mm test trials and qq is the underlying mean. Actual QKD analyses may sample without replacement, use random stopping times, estimate several photon-number sectors, or defend against coherent attacks. They therefore use bounds matched to the protocol rather than inserting this illustrative expression blindly.

The bit-error rate quantifies disagreement in the key basis. A phase-error rate is usually a counterfactual or complementary-basis quantity that controls secrecy; it need not equal the observed bit-error rate unless symmetry or another proof step establishes the relation. A valid proof explains how test data bound the phase-error quantity with failure probability εPE\varepsilon_{\mathrm{PE}}.

Loss is not automatically evidence of security and cannot simply be discarded from the threat model. Eve may replace a lossy channel, suppress selected signals, or exploit efficiency mismatch. Detection events, no-clicks, double clicks, basis dependence, and postselection rules must be included in the model. If the resulting confidence region permits no positive key length, Alice and Bob abort.

After sifting and testing, Alice and Bob hold correlated strings ZAnZ_A^n and ZBnZ_B^n. Information reconciliation sends parity data or another error-correcting transcript over the authenticated public channel so Bob can infer Alice’s string. One-way methods and interactive two-way methods have different leakage and proof implications.

The transcript is visible to Eve. A security analysis tracks an upper bound

leakEC\mathrm{leak}_{\mathrm{EC}}

on the information revealed by reconciliation, including disclosed syndromes and any other correlated messages covered by the chosen definition.

Reconciliation may fail silently. Alice and Bob therefore compare a short authentication-style hash of their candidate strings. If a universal hash tag has tt effective verification bits, the undetected-disagreement probability is typically bounded on the order of

εcor≲2−t,\varepsilon_{\mathrm{cor}} \lesssim 2^{-t},

with the exact statement determined by the hash family and protocol. A mismatch causes an abort; the verification tag and seed belong in the public transcript.

Even after error correction, Eve may have partial quantum information about the reconciled string. Privacy amplification applies a randomly selected strong extractor, commonly a two-universal hash function,

F:{0,1}n⟶{0,1}ℓ,K=F(ZAn),F:\{0,1\}^{n}\longrightarrow\{0,1\}^{\ell}, \qquad K=F(Z_A^n),

and publicly announces the seed specifying FF. The seed need not be secret. Security comes from shortening the string below its conditional min-entropy, not from hiding the hash function.

A representative quantum leftover-hash bound has the schematic form

εsec≲2εs+122−12[Hmin⁡εs(ZAn∣EC)−ℓ].\varepsilon_{\mathrm{sec}} \lesssim 2\varepsilon_s + \frac12 2^{ -\frac12 \left[ H_{\min}^{\varepsilon_s}(Z_A^n\mid EC) -\ell \right] }.

Conventions alter constants and where the transcript is conditioned, but the operational message is stable: sacrificing additional output bits exponentially suppresses the extractor’s distinguishing error.

Privacy amplification does not “repair” an unmodeled side channel. It removes side information only to the extent that the proof has correctly lower-bounded the min-entropy of the reconciled data.

For asymptotically many independent uses and one-way direct reconciliation, the Devetak–Winter expression provides a common rate skeleton:

r≥H(ZA∣E)−H(ZA∣ZB).r \ge H(Z_A\mid E) - H(Z_A\mid Z_B).

The first term is Alice’s uncertainty from Eve’s viewpoint; the second is the information Bob lacks and reconciliation must supply. This is not a universal finite-key formula. A protocol proof must justify the state, direction of reconciliation, attack reduction, and observed-parameter constraints used to evaluate the entropies.

For a finite accepted block, a safer generic ledger is

ℓ≤Hmin⁡εs(ZAn∣E)ρΩ−leakEC−Δver−ΔPA−Δother,\begin{aligned} \ell \le{}& H_{\min}^{\varepsilon_s} (Z_A^n\mid E)_{\rho^\Omega} - \mathrm{leak}_{\mathrm{EC}} \\ &- \Delta_{\mathrm{ver}} - \Delta_{\mathrm{PA}} - \Delta_{\mathrm{other}}, \end{aligned}

where the Δ\Delta terms pay for verification, privacy-amplification failure, parameter estimation, smoothing, and protocol-specific disclosures. Whether a particular transcript has already been included in the conditional entropy or must be subtracted separately is a bookkeeping convention; counting it twice is pessimistic, while omitting it is insecure.

An illustrative ledger might begin with a proven min-entropy lower bound of 740,000740{,}000 bits, subtract 180,000180{,}000 bits of reconciliation leakage, 6464 verification bits, and a 256256-bit privacy-amplification margin:

ℓ≤740,000−180,000−64−256=559,680.\ell \le 740{,}000 - 180{,}000 - 64 - 256 = 559{,}680.

If 256256 fresh key bits must replenish authentication material, the net expansion is at most 559,424559{,}424 bits. These numbers illustrate accounting only; they are not a rate claim for any physical protocol.

Possible denominators include transmitted optical pulses, detected events, sifted bits, channel uses, seconds, or occupied wavelength-time resources. A credible performance statement reports at least:

  • secret bits after all finite-key penalties;
  • security parameters and block duration;
  • total sent signals and accepted detections;
  • distance, loss, clock rate, detector conditions, and postselection;
  • authentication consumption and whether the rate is gross or net;
  • whether the result is modeled, simulated, laboratory measured, or field measured.

Without authentication, Eve can mount a man-in-the-middle attack: she runs one QKD session while pretending to be Bob to Alice and another while pretending to be Alice to Bob. Each session may show excellent quantum statistics, yet Eve shares a separate key with each endpoint and can relay or alter later traffic.

Information-theoretic message authentication can be built from universal hashing, as in Wegman–Carter constructions, using a short pre-shared secret. Successful QKD rounds can replenish consumed authentication material and expand the remaining key pool. Precise key-recycling claims depend on the authentication construction and whether the run accepts.

The classical discussion must be authentic but may be public. Encrypting basis announcements or reconciliation data is unnecessary for secrecy if those messages are already included in CC. Integrity without endpoint identity is also insufficient: Alice must know that the authenticated peer is Bob.

One may bootstrap a first session with post-quantum digital signatures or another computational credential. That is a legitimate hybrid design, but its initial authentication then has a computational security assumption. The long-term claim must state whether later sessions retain, replace, or continue to depend on that assumption.

A proof’s abstract devices are mathematical interfaces. Physical hardware may expose degrees of freedom that the interface omits. The correct response is not to dismiss the theorem or to trust it blindly, but to connect each implementation to a model that includes its relevant behavior.

Implementation issueBroken or stressed assumptionRepresentative responseResidual question
multiphoton weak-coherent pulsessignal behaves as a single qubitphase randomization and decoy-state estimationare intensity distributions, correlations, and leakage bounded?
detector blinding or efficiency mismatchmeasurement response matches the trusted POVMmonitored detectors, explicit detector model, or MDI-QKDwhich receiver modes and control inputs remain exposed?
Trojan-horse light and back-reflectionsAlice’s or Bob’s settings remain localisolators, filters, watchdog detectors, energy boundsare wavelength, timing, and detector limits covered?
spectral, temporal, spatial, or polarization leakageencoded states differ only in the modeled degree of freedomsource characterization and loss-tolerant proofsare pulse-to-pulse correlations included?
imperfect phase randomizationcoherent-pulse mixture has the assumed photon-number formactive randomization and verificationhow is residual coherence bounded?
biased or predictable random choicessettings are private and independentcharacterized quantum RNG and extractioncan devices correlate with the RNG or its timing?
calibration drift and memorytrials follow the assumed stationary modelonline monitoring and non-i.i.d. analysiswhat happens across blocks, resets, and firmware states?
finite precision and software faultsdeclared tests and bounds are implemented exactlyverified arithmetic, logs, test vectors, fail-closed behaviorare overflows, rounding, and parameter downgrade excluded?

Measurement-Device-Independent QKD is designed to remove relay detector side channels from the trusted boundary by moving detection to an untrusted station. It does not remove source assumptions. Device-Independent QKD reduces characterization assumptions further, but demands loophole-controlled correlations, high total efficiency, independent inputs, laboratory isolation, and demanding finite-key analysis.

No implementation can stop Eve from cutting a fiber, flooding a receiver, or otherwise forcing an abort. Availability monitoring and operational incident response remain classical security responsibilities.

A point-to-point QKD proof establishes a key between the security boundaries of two modules. A deployed service adds:

  • endpoint identity, physical protection, access control, and tamper response;
  • key storage, synchronization, identifiers, deletion, and audit;
  • an API that supplies keys to applications without reuse or misbinding;
  • encryption and integrity protection for application data;
  • routing or trusted relays when there is no direct QKD link;
  • availability, redundancy, maintenance, update, and supply-chain controls.

In a trusted-node QKD network, keys may be decrypted and re-encrypted or one-time-pad relayed inside intermediate nodes. Compromise of such a node can expose end-to-end key material. Quantum Repeaters aim at a different trust model, but they are not interchangeable with deployed trusted relays.

Using a QKD key in a one-time pad can give information-theoretic confidentiality only if the key is uniform enough, used once, as long as the message, protected against reuse, and combined with suitable authentication. Using it in AES or another symmetric primitive instead yields the security of that cryptographic construction under its computational assumptions. QKD does not transform an insecure application into a secure one merely by supplying key bits.

QKD and post-quantum cryptography (PQC) address overlapping risks through different resources.

QuestionQKDPQC
main mechanismmeasured quantum signals plus classical postprocessingclassical algorithms based on computational hardness
infrastructurespecialized endpoints and a quantum channeldeployable over ordinary digital networks
authenticationstill requiredsignatures or pre-shared symmetric credentials can provide it
availabilityvulnerable to channel blockingvulnerable to ordinary network denial of service
long-distance scalingloss, trusted nodes, satellites, or future repeatersordinary routed networks
core trustphysical model, implementation isolation, randomness, endpointsalgorithm, parameters, implementation, randomness, endpoints

They are not simple substitutes. A hybrid can diversify assumptions, but it also combines integration obligations. A comparison should use an explicit threat horizon, cost model, topology, performance target, and migration plan.

Ask the following before accepting a theorem, experiment, product, or network statement:

  1. What ideal resource is claimed? A shared key, a rate, or only correlated raw data?
  2. What is the security definition? Correctness, secrecy, composability, and honest-abort parameters?
  3. What can Eve control? Channel, source, measurement, timing, loss, memory, and classical network?
  4. Which components are trusted? Include RNGs, clocks, modulators, detectors, software, and laboratories.
  5. How are finite statistics handled? State the sample rule, confidence method, and failure allocation.
  6. How is the classical channel authenticated? State the initial credential and consumed key.
  7. What leakage is counted? Reconciliation, verification, side information, and public metadata?
  8. What is the denominator? Pulses, detections, seconds, distance, loss, or deployed resources?
  9. Which implementation attacks were modeled and tested?
  10. Where are the key-management and application boundaries?

“Unhackable,” “guaranteed by nature,” and “eavesdropping is always detected” fail this audit. The defensible statement is narrower and stronger: under declared assumptions, acceptance implies a quantified distance from an ideal key resource.

QKD outputs key material. An application still needs confidentiality, integrity, replay protection, identities, and key-lifecycle rules.

Alice and Bob estimate parameters and may abort. The data generally do not identify an attacker, and an attack can remain statistically indistinguishable from ordinary channel behavior while still being covered by the secrecy bound.

No-cloning does not quantify partial information, finite statistics, device flaws, or authentication.

Classical postprocessing may be public. It must be authenticated, and its leakage must be included in the proof.

Quoting an asymptotic rate for a finite experiment

Section titled “Quoting an asymptotic rate for a finite experiment”

Finite blocks pay parameter-estimation, smoothing, verification, and privacy-amplification penalties. A positive asymptotic expression can coexist with zero certified finite-block key.

Assuming a countermeasure closes every side channel

Section titled “Assuming a countermeasure closes every side channel”

Decoy states, MDI-QKD, and device-independent protocols move or refine particular trust boundaries. Each leaves other assumptions that must be stated and validated.

Suppose a protocol is εcor=10−12\varepsilon_{\mathrm{cor}}=10^{-12} correct and εsec=10−10\varepsilon_{\mathrm{sec}}=10^{-10} secret. Give a valid upper bound on its overall soundness error. What does this number not say?

Solution

By the triangle or hybrid argument used to replace the real resource first by a matching-key resource and then by a uniform secret-key resource,

εsnd≤10−12+10−10=1.01×10−10.\varepsilon_{\mathrm{snd}} \le 10^{-12}+10^{-10} = 1.01\times10^{-10}.

This does not bound the probability of honest abort, guarantee availability, describe implementation side channels, or certify the encryption application that later consumes the key.

2. Show why authentication cannot be omitted

Section titled “2. Show why authentication cannot be omitted”

Construct a man-in-the-middle attack against a QKD protocol whose classical channel is public and integrity-protected only by unauthenticated checksums.

Solution

Eve terminates Alice’s quantum and classical traffic and initiates a separate session with Bob. She presents herself as Bob to Alice and as Alice to Bob. Checksums detect accidental corruption but do not bind either transcript to an identity, so Eve can generate valid checksums for both sessions.

Alice finishes with a key KAEK_{AE} shared with Eve, while Bob finishes with a different key KEBK_{EB} shared with Eve. Eve can decrypt, alter, and re-encrypt later traffic between the two sessions. Quantum error tests can pass because Eve is a legitimate endpoint in each separate run.

A proposed proof says, “Eve cannot copy an unknown photon perfectly, so she has zero information about every accepted key bit.” Give three independent reasons the conclusion does not follow.

Solution

First, Eve need not make a perfect copy; an approximate interaction can trade disturbance for partial information. Second, a practical pulse may contain multiple photons or leak its setting in another degree of freedom, so Eve may learn information without cloning the modeled qubit. Third, even an ideal signal argument says nothing about finite-sample inference, error-correction leakage, authentication, or privacy amplification. A security proof must bound Eve’s side information after all accepted protocol steps.

Under an independent Bernoulli model, m=106m=10^6 test bits have observed error frequency q^m=0.018\widehat q_m=0.018. Use Hoeffding’s inequality to find μ\mu such that the upper-tail failure probability is at most 10−1010^{-10}.

Solution

Set

exp⁡(−2mμ2)=10−10.\exp(-2m\mu^2) = 10^{-10}.

Then

μ=ln⁡(1010)2×106≈0.00339.\mu = \sqrt{ \frac{\ln(10^{10})}{2\times10^6} } \approx 0.00339.

The illustrative upper confidence value is therefore

q≲0.018+0.00339=0.02139.q \lesssim 0.018+0.00339 = 0.02139.

This calculation is not automatically valid for a QKD sample drawn without replacement or for a non-i.i.d. attack; the protocol must use the statistical theorem matching its sampling procedure and adversary reduction.

A proof gives Hmin⁡εs(ZAn∣E)≥310,000H_{\min}^{\varepsilon_s}(Z_A^n\mid E)\ge 310{,}000 bits. Reconciliation leaks at most 72,00072{,}000 bits, verification costs 6464 bits, and the privacy-amplification margin is 256256 bits. Find the largest output length allowed by this simplified ledger. If 512512 output bits replenish authentication, what is the net expansion?

Solution

The output length obeys

ℓ≤310,000−72,000−64−256=237,680.\ell \le 310{,}000 - 72{,}000 - 64 - 256 = 237{,}680.

After reserving 512512 bits for authentication, the net expansion is

237,680−512=237,168237{,}680-512 = 237{,}168

bits. A real proof may place some transcript terms inside the conditional min-entropy and may contain additional finite-size penalties.

Ignore smoothing and convention-dependent prefactors. If the reconciled string has conditional min-entropy at least 200,000200{,}000 bits and Alice extracts ℓ=199,744\ell=199{,}744 bits, estimate the leftover-hash contribution

122−(Hmin⁡−ℓ)/2.\frac12 2^{-\left(H_{\min}-\ell\right)/2}.
Solution

The entropy sacrifice is 256256 bits, so

122−256/2=2−129.\frac12 2^{-256/2} = 2^{-129}.

The extractor contribution is therefore extremely small. The total secrecy parameter may nevertheless be dominated by smoothing, parameter estimation, authentication, or other allocated failures.

Suppose a justified asymptotic model gives

H(ZA∣E)=0.86,H(ZA∣ZB)=0.19H(Z_A\mid E)=0.86, \qquad H(Z_A\mid Z_B)=0.19

bits per sifted signal. What one-way rate skeleton follows, and why is it not yet an experimental throughput?

Solution

The expression gives

r≥0.86−0.19=0.67r \ge 0.86-0.19 = 0.67

secret bits per sifted signal in the stated asymptotic model. It omits finite-block penalties, sifting and detection probabilities, authentication cost, clock rate, dead time, loss, postselection, and the distinction between sifted signals and transmitted pulses. Those are needed to convert the entropy rate into net bits per second.

Eve blocks every quantum signal. What should a sound QKD implementation do, and has Eve broken secrecy?

Solution

The implementation should observe too few valid detections or fail another acceptance condition and abort without outputting a key. Eve has denied service but has not learned an accepted key because no key exists. Treating availability and secrecy as separate properties prevents an abort from being mislabeled as a cryptographic break while still recognizing its operational impact.

For each case, name the most directly relevant protocol or engineering response: multiphoton weak-coherent pulses, detector blinding, and untrusted state preparation together with untrusted measurements.

Solution
  • Multiphoton weak-coherent pulses motivate phase randomization plus decoy-state estimation.
  • Detector blinding motivates an explicit detector model and hardening; MDI-QKD removes detector behavior from the trusted security boundary.
  • Simultaneously untrusted preparation and measurement motivates a device-independent analysis based on loophole-controlled nonlocal correlations.

These labels are not blanket guarantees. Decoy-state analysis retains source assumptions, MDI-QKD retains source trust, and device-independent QKD retains assumptions about random inputs, isolation, authentication, and finite statistics.

Alice and Bob obtain a 10610^6-bit QKD key. Compare using it for a 10610^6-bit one-time pad with using 256 bits as an AES key. State the additional requirements in each case.

Solution

For a one-time pad, the full 10610^6-bit key can encrypt one message of the same length with information-theoretic confidentiality, provided the key is sufficiently uniform, never reused, synchronized, erased appropriately, and combined with a secure message-authentication mechanism. The pad alone is malleable.

Using 256 bits as an AES key allows much more data to be processed, but confidentiality rests on the computational security and correct mode of operation of AES. An authenticated-encryption construction, nonce discipline, endpoint security, and key lifecycle are still required. In neither case does the QKD layer by itself protect the application.

  1. C. H. Bennett and G. Brassard, “Quantum cryptography: Public key distribution and coin tossing,” in Proceedings of the IEEE International Conference on Computers, Systems and Signal Processing, Bangalore, 175–179 (1984); reprinted in Theoretical Computer Science 560, 7–11 (2014), doi:10.1016/j.tcs.2014.05.025.
  2. A. K. Ekert, “Quantum cryptography based on Bell’s theorem,” Physical Review Letters 67, 661–663 (1991), doi:10.1103/PhysRevLett.67.661.
  3. C. H. Bennett, G. Brassard, and N. D. Mermin, “Quantum cryptography without Bell’s theorem,” Physical Review Letters 68, 557–559 (1992), doi:10.1103/PhysRevLett.68.557.
  4. D. Mayers, “Unconditional security in quantum cryptography,” Journal of the ACM 48, 351–406 (2001), doi:10.1145/382780.382781.
  5. H.-K. Lo and H. F. Chau, “Unconditional security of quantum key distribution over arbitrarily long distances,” Science 283, 2050–2056 (1999), doi:10.1126/science.283.5410.2050.
  6. P. W. Shor and J. Preskill, “Simple proof of security of the BB84 quantum key distribution protocol,” Physical Review Letters 85, 441–444 (2000), doi:10.1103/PhysRevLett.85.441.
  7. I. Devetak and A. Winter, “Distillation of secret key and entanglement from quantum states,” Proceedings of the Royal Society A 461, 207–235 (2005), doi:10.1098/rspa.2004.1372.
  8. R. Renner, Security of Quantum Key Distribution, Ph.D. thesis, ETH Zürich (2005), doi:10.3929/ethz-a-005115027.
  9. R. Renner and R. König, “Universally composable privacy amplification against quantum adversaries,” in Theory of Cryptography, Lecture Notes in Computer Science 3378, 407–425 (2005), doi:10.1007/978-3-540-30576-7_22.
  10. M. N. Wegman and J. L. Carter, “New hash functions and their use in authentication and set equality,” Journal of Computer and System Sciences 22, 265–279 (1981), doi:10.1016/0022-0000(81)90033-7.
  11. V. Scarani et al., “The security of practical quantum key distribution,” Reviews of Modern Physics 81, 1301–1350 (2009), doi:10.1103/RevModPhys.81.1301.
  12. M. Tomamichel et al., “Tight finite-key analysis for quantum cryptography,” Nature Communications 3, 634 (2012), doi:10.1038/ncomms1631.
  13. H.-K. Lo, M. Curty, and B. Qi, “Measurement-device-independent quantum key distribution,” Physical Review Letters 108, 130503 (2012), doi:10.1103/PhysRevLett.108.130503.
  14. H.-K. Lo, M. Curty, and K. Tamaki, “Secure quantum key distribution,” Nature Photonics 8, 595–604 (2014), doi:10.1038/nphoton.2014.149.
  15. M. Tomamichel and A. Leverrier, “A largely self-contained and complete security proof for quantum key distribution,” Quantum 1, 14 (2017), doi:10.22331/q-2017-07-14-14.
  16. F. Xu, X. Ma, Q. Zhang, H.-K. Lo, and J.-W. Pan, “Secure quantum key distribution with realistic devices,” Reviews of Modern Physics 92, 025002 (2020), doi:10.1103/RevModPhys.92.025002.
  17. C. Portmann and R. Renner, “Security in quantum cryptography,” Reviews of Modern Physics 94, 025008 (2022), doi:10.1103/RevModPhys.94.025008.
  18. ITU-T, Framework of Quantum Key Distribution Protocols in QKD Networks, Recommendation X.1711 (2026), official publication.
  • BB84 develops the four signal states, basis sifting, intercept–resend benchmark, source-replacement picture, and asymptotic bit–phase error rate.
  • E91 and Entanglement-Based QKD derives the three-setting transcript, singlet CHSH value, key-round sifting, and device-dependent versus device-independent trust boundary.
  • Decoy-State QKD derives photon-number yield equations, vacuum-plus-weak bounds, and the source assumptions needed for weak coherent pulses.
  • Measurement-Device-Independent QKD moves the joint measurement and detectors to an untrusted relay while retaining characterized endpoint sources.
  • Device-Independent QKD develops the black-box input-output model, Bell-to-entropy bounds, loophole-aware trial contract, and finite-key entropy ledger.
  • No-Cloning and No-Signaling gives the precise no-go statements while explaining why neither one is a complete QKD security proof.
  • Communication with Quantum Systems separates secret-key generation from classical-message transmission, quantum-state preservation, and entanglement distribution.
  • Quantum Teleportation contrasts key establishment with quantum state transfer and makes the role of authenticated versus ordinary classical communication easier to separate.
  • Entanglement Distillation develops the Bell-pair recurrence and hashing protocols that underlie the virtual entanglement-purification viewpoint used in important QKD security proofs.
  • Density Operators for Quantum Information supplies the classical–quantum states used in secrecy definitions.
  • Entanglement Measures distinguishes operational entanglement resources from the secret-key resource.
  • Entanglement in Quantum Information places QKD among other uses of nonclassical correlations.
  • Claims, Hype, and Evidence Standards gives the wider framework for auditing security, rate, and deployment claims.
  • Quantum Information Roadmap places cryptography after states, channels, measurements, entanglement, and no-go theorems.