Quantum Key Distribution
What QKD Establishes
Section titled “What QKD Establishes”Quantum key distribution (QKD) is a family of interactive protocols through which two remote parties, conventionally Alice and Bob, generate matching secret classical bit strings. The security argument combines quantum measurements with authenticated classical postprocessing. The intended output is a key,
that is nearly uniform and nearly independent of everything available to an adversary Eve.
QKD is key establishment, not message transmission and not an encryption algorithm. Once generated, the key can be supplied to a one-time pad, an authenticated-encryption scheme, or another cryptographic application. The resulting application’s security depends on that later construction, its key management, its endpoints, and the way the QKD security guarantee composes with them.
Classical Information Review owns the classical entropy, source-coding, secrecy, and cost baselines. This page owns composable QKD key security: entropy or unpredictability alone is not a secrecy proof.
The phrase “security from physics” is incomplete by itself. A QKD theorem always has the form:
For a specified protocol, device model, source of randomness, authenticated-channel construction, adversary model, and finite statistical procedure, either the parties abort or their output is close to an ideal shared key by a stated security parameter.
This page is the canonical overview of that contract, the common distillation pipeline, protocol families, finite-key accounting, authentication, and implementation boundaries. Dedicated pages own the detailed security proofs and optical designs of BB84, E91, decoy-state QKD, measurement-device-independent QKD, and device-independent QKD.
Quantum Randomness owns entropy-source trust models, health tests, standalone extraction, and Bell-certified randomness expansion or amplification. QKD consumes local random choices and performs privacy amplification inside a two-party protocol; those uses must enter its composable failure and leakage ledger.
Security Contract
Section titled “Security Contract”Systems and adversary
Section titled “Systems and adversary”Alice and Bob use:
- an insecure quantum channel, which Eve may control completely;
- a public but authenticated classical channel, which Eve may read but cannot modify or forge except with a bounded failure probability;
- local laboratories whose trusted components and leakage assumptions must be stated;
- local random choices with a specified quality and independence model.
A strong proof may allow Eve to replace the channel, inject arbitrary states, correlate all transmissions, retain a quantum memory indefinitely, postpone her measurement, and perform one joint coherent attack. This does not mean every implementation is secure against every physical attack. The proof only covers physical behavior represented by its model.
Let denote the event that the protocol passes all tests rather than aborting, let be the complete public transcript, and let denote Eve’s final quantum and classical side information. Three properties must be kept distinct.
Correctness
Section titled “Correctness”The keys should disagree only with small probability:
An error-verification tag sent after reconciliation normally enforces this condition. A low observed quantum bit error rate alone does not guarantee identical final strings.
Secrecy
Section titled “Secrecy”Conditioned on acceptance, Alice’s key should be close to an ideal uniform key independent of Eve and the public transcript:
where . The factor prevents a protocol that almost never accepts from receiving an artificially strong conditional security claim. Trace Distance explains why this distance bounds the distinguishing advantage between real and ideal resources.
Composable soundness and honest abort
Section titled “Composable soundness and honest abort”Correctness and secrecy combine into an overall soundness error that can be bounded by
Composable security means the real key resource can replace an ideal key resource in a larger protocol while changing the larger system’s behavior by at most the declared error. Failure budgets therefore add when secure components are composed.
A separate robustness or completeness parameter controls honest abort:
Soundness asks whether an accepted key is secure. Robustness asks whether an honest run is likely to produce one. Eve can always block the quantum channel and force an abort, so QKD does not guarantee availability or prevent denial of service.
End-to-End Protocol
Section titled “End-to-End Protocol”A generic QKD session. Eve may control the quantum channel and read the classical transcript. Authentication prevents undetected substitution of classical messages. Parameter estimation and verification can force an abort; privacy amplification converts a partially secret reconciled string into a shorter composably secret key.
Although protocol details differ, a complete session has a recognizable ledger.
| Stage | Main output | Security role | Typical failure or leakage |
|---|---|---|---|
| authenticated setup | session identities, parameters, fresh nonces | binds messages to this run | impersonation, replay, downgrade |
| quantum exchange | preparation and detection records | creates correlations constrained by quantum theory | loss, noise, side channels, adversarial replacement |
| sifting | compatible events and basis labels | selects data used for tests and key | public disclosure of settings and discarded events |
| parameter estimation | confidence region for channel or state parameters | bounds Eve’s information or a phase-error quantity | finite-sample failure |
| information reconciliation | Bob’s corrected candidate string | removes Alice–Bob discrepancies | transcript leakage |
| error verification | accept or abort | bounds residual key mismatch | hash-collision failure |
| privacy amplification | shorter final strings | removes Eve’s bounded side information | extractor failure |
| key delivery | key identifiers and synchronized key material | hands the key to an application | endpoint, storage, reuse, or API compromise |
Every public bit need not be subtracted one-for-one, but every message must appear in the security analysis. Every randomized test needs a failure probability. Authentication consumes or relies on a credential. A reported “secret-key rate” is meaningful only after these choices and the denominator have been stated.
Why Quantum Signals Help
Section titled “Why Quantum Signals Help”Prepare-and-measure protocols encode data in nonorthogonal quantum states. Entanglement-based protocols distribute correlations that cannot be reproduced under the protocol’s accepted parameter region without limiting Eve’s side information. In either description, incompatible measurements create a tradeoff: gaining predictive power about one key-generating observable constrains correlations in a complementary observable.
The security mechanism is therefore not simply “measurement disturbs the photon.” A modern proof connects observed statistics to a bound such as a conditional entropy,
or a smooth conditional min-entropy,
These quantify Eve’s uncertainty about Alice’s prospective key data under the declared model. Von Neumann Entropy supplies the asymptotic entropy language; smooth min-entropy is the one-shot quantity needed for finite blocks.
The No-Cloning and No-Signaling restrictions are relevant but insufficient as a security proof. No-cloning forbids a universal perfect copier of unknown states. It does not by itself:
- bound Eve’s information in an optimal approximate or collective attack;
- account for loss, multiphoton pulses, imperfect state preparation, or detector behavior;
- authenticate Alice and Bob;
- specify finite-sample confidence;
- prove that the final extracted key is composably secret.
Parameter estimation does not identify Eve or distinguish malicious disturbance from ordinary noise. It determines whether the observed data fall inside a region for which a security theorem certifies an acceptable key length.
Prepare-and-Measure Protocols
Section titled “Prepare-and-Measure Protocols”In a prepare-and-measure protocol, Alice chooses a classical symbol and setting, prepares a corresponding quantum state, and sends it to Bob. Bob chooses a measurement setting and records an outcome. Only later do they disclose enough setting information to sift and test the data.
BB84 is the canonical example: two conjugate qubit bases encode candidate key bits. The six-state protocol uses three mutually unbiased qubit bases and obtains more symmetric parameter information at the cost of additional setting choices. B92 uses two nonorthogonal states and an unambiguous-outcome structure. Continuous-variable protocols encode quadratures of optical modes and require a distinct detector, channel, and security analysis.
Real optical transmitters commonly emit phase-randomized weak coherent pulses rather than deterministic single photons. Such pulses contain vacuum, one-photon, and multiphoton components. Decoy-state methods vary the mean intensity so Alice and Bob can estimate the behavior of photon-number sectors and bound the single-photon contribution. Decoy analysis addresses photon-number-splitting vulnerabilities under its source assumptions; it does not certify every possible source imperfection.
The prepare-and-measure description is operationally direct, but security proofs often use a source-replacement picture. Alice may be imagined to prepare an entangled state
and measure to choose the signal sent through . This mathematical equivalence connects state preparation to entanglement and complementarity without requiring an actual entangled source in the laboratory.
Entanglement-Based Protocols
Section titled “Entanglement-Based Protocols”In an entanglement-based protocol, a source distributes bipartite systems and Alice and Bob choose local measurements. The source may be trusted, partially characterized, or entirely untrusted depending on the protocol. Some measurement outcomes form the raw key; others estimate correlations relevant to secrecy.
E91 and Entanglement-Based QKD uses entangled pairs and Bell-type correlations. BBM92 gives an entanglement-based counterpart to BB84. Entanglement-based reasoning is especially useful because it turns secrecy into a statement about entanglement, complementarity, or monogamy of correlations. Bell States owns the standard two-qubit maximally entangled states.
Three labels that are often conflated have different trust boundaries:
| Family | What is moved outside the trusted model? | What remains |
|---|---|---|
| entanglement-based QKD | the source may be placed in the channel | measurements and other declared local behavior remain modeled |
| measurement-device-independent QKD | the measurement station and detectors may be untrusted | source preparation and local isolation still need characterization |
| device-independent QKD | security is inferred from loophole-controlled nonlocal correlations | random settings, laboratory isolation, authentication, and finite statistics still matter |
Bell violation is not required for every entanglement-based QKD proof. Conversely, observing some Bell-inequality violation is not automatically a complete device-independent implementation proof. Detection, locality, memory, input-independence, and finite-size assumptions all enter.
Parameter Estimation and Abort
Section titled “Parameter Estimation and Abort”Alice and Bob publicly reveal a randomly selected subset of outcomes or use designated test settings. From those data they construct a confidence region for quantities such as yields, bit-error rates, phase-error rates, or Bell parameters. The key-generating sample remains unrevealed.
For a simple independent Bernoulli model, Hoeffding’s inequality illustrates the statistical logic:
where is an error frequency from test trials and is the underlying mean. Actual QKD analyses may sample without replacement, use random stopping times, estimate several photon-number sectors, or defend against coherent attacks. They therefore use bounds matched to the protocol rather than inserting this illustrative expression blindly.
The bit-error rate quantifies disagreement in the key basis. A phase-error rate is usually a counterfactual or complementary-basis quantity that controls secrecy; it need not equal the observed bit-error rate unless symmetry or another proof step establishes the relation. A valid proof explains how test data bound the phase-error quantity with failure probability .
Loss is not automatically evidence of security and cannot simply be discarded from the threat model. Eve may replace a lossy channel, suppress selected signals, or exploit efficiency mismatch. Detection events, no-clicks, double clicks, basis dependence, and postselection rules must be included in the model. If the resulting confidence region permits no positive key length, Alice and Bob abort.
Reconciliation and Error Verification
Section titled “Reconciliation and Error Verification”After sifting and testing, Alice and Bob hold correlated strings and . Information reconciliation sends parity data or another error-correcting transcript over the authenticated public channel so Bob can infer Alice’s string. One-way methods and interactive two-way methods have different leakage and proof implications.
The transcript is visible to Eve. A security analysis tracks an upper bound
on the information revealed by reconciliation, including disclosed syndromes and any other correlated messages covered by the chosen definition.
Reconciliation may fail silently. Alice and Bob therefore compare a short authentication-style hash of their candidate strings. If a universal hash tag has effective verification bits, the undetected-disagreement probability is typically bounded on the order of
with the exact statement determined by the hash family and protocol. A mismatch causes an abort; the verification tag and seed belong in the public transcript.
Privacy Amplification
Section titled “Privacy Amplification”Even after error correction, Eve may have partial quantum information about the reconciled string. Privacy amplification applies a randomly selected strong extractor, commonly a two-universal hash function,
and publicly announces the seed specifying . The seed need not be secret. Security comes from shortening the string below its conditional min-entropy, not from hiding the hash function.
A representative quantum leftover-hash bound has the schematic form
Conventions alter constants and where the transcript is conditioned, but the operational message is stable: sacrificing additional output bits exponentially suppresses the extractor’s distinguishing error.
Privacy amplification does not “repair” an unmodeled side channel. It removes side information only to the extent that the proof has correctly lower-bounded the min-entropy of the reconciled data.
Key-Length and Rate Accounting
Section titled “Key-Length and Rate Accounting”For asymptotically many independent uses and one-way direct reconciliation, the Devetak–Winter expression provides a common rate skeleton:
The first term is Alice’s uncertainty from Eve’s viewpoint; the second is the information Bob lacks and reconciliation must supply. This is not a universal finite-key formula. A protocol proof must justify the state, direction of reconciliation, attack reduction, and observed-parameter constraints used to evaluate the entropies.
For a finite accepted block, a safer generic ledger is
where the terms pay for verification, privacy-amplification failure, parameter estimation, smoothing, and protocol-specific disclosures. Whether a particular transcript has already been included in the conditional entropy or must be subtracted separately is a bookkeeping convention; counting it twice is pessimistic, while omitting it is insecure.
An illustrative ledger might begin with a proven min-entropy lower bound of bits, subtract bits of reconciliation leakage, verification bits, and a -bit privacy-amplification margin:
If fresh key bits must replenish authentication material, the net expansion is at most bits. These numbers illustrate accounting only; they are not a rate claim for any physical protocol.
Possible denominators include transmitted optical pulses, detected events, sifted bits, channel uses, seconds, or occupied wavelength-time resources. A credible performance statement reports at least:
- secret bits after all finite-key penalties;
- security parameters and block duration;
- total sent signals and accepted detections;
- distance, loss, clock rate, detector conditions, and postselection;
- authentication consumption and whether the rate is gross or net;
- whether the result is modeled, simulated, laboratory measured, or field measured.
Authentication Is Required
Section titled “Authentication Is Required”Without authentication, Eve can mount a man-in-the-middle attack: she runs one QKD session while pretending to be Bob to Alice and another while pretending to be Alice to Bob. Each session may show excellent quantum statistics, yet Eve shares a separate key with each endpoint and can relay or alter later traffic.
Information-theoretic message authentication can be built from universal hashing, as in Wegman–Carter constructions, using a short pre-shared secret. Successful QKD rounds can replenish consumed authentication material and expand the remaining key pool. Precise key-recycling claims depend on the authentication construction and whether the run accepts.
The classical discussion must be authentic but may be public. Encrypting basis announcements or reconciliation data is unnecessary for secrecy if those messages are already included in . Integrity without endpoint identity is also insufficient: Alice must know that the authenticated peer is Bob.
One may bootstrap a first session with post-quantum digital signatures or another computational credential. That is a legitimate hybrid design, but its initial authentication then has a computational security assumption. The long-term claim must state whether later sessions retain, replace, or continue to depend on that assumption.
Implementation Security
Section titled “Implementation Security”A proof’s abstract devices are mathematical interfaces. Physical hardware may expose degrees of freedom that the interface omits. The correct response is not to dismiss the theorem or to trust it blindly, but to connect each implementation to a model that includes its relevant behavior.
| Implementation issue | Broken or stressed assumption | Representative response | Residual question |
|---|---|---|---|
| multiphoton weak-coherent pulses | signal behaves as a single qubit | phase randomization and decoy-state estimation | are intensity distributions, correlations, and leakage bounded? |
| detector blinding or efficiency mismatch | measurement response matches the trusted POVM | monitored detectors, explicit detector model, or MDI-QKD | which receiver modes and control inputs remain exposed? |
| Trojan-horse light and back-reflections | Alice’s or Bob’s settings remain local | isolators, filters, watchdog detectors, energy bounds | are wavelength, timing, and detector limits covered? |
| spectral, temporal, spatial, or polarization leakage | encoded states differ only in the modeled degree of freedom | source characterization and loss-tolerant proofs | are pulse-to-pulse correlations included? |
| imperfect phase randomization | coherent-pulse mixture has the assumed photon-number form | active randomization and verification | how is residual coherence bounded? |
| biased or predictable random choices | settings are private and independent | characterized quantum RNG and extraction | can devices correlate with the RNG or its timing? |
| calibration drift and memory | trials follow the assumed stationary model | online monitoring and non-i.i.d. analysis | what happens across blocks, resets, and firmware states? |
| finite precision and software faults | declared tests and bounds are implemented exactly | verified arithmetic, logs, test vectors, fail-closed behavior | are overflows, rounding, and parameter downgrade excluded? |
Measurement-Device-Independent QKD is designed to remove relay detector side channels from the trusted boundary by moving detection to an untrusted station. It does not remove source assumptions. Device-Independent QKD reduces characterization assumptions further, but demands loophole-controlled correlations, high total efficiency, independent inputs, laboratory isolation, and demanding finite-key analysis.
No implementation can stop Eve from cutting a fiber, flooding a receiver, or otherwise forcing an abort. Availability monitoring and operational incident response remain classical security responsibilities.
From a Link to a Secure Application
Section titled “From a Link to a Secure Application”A point-to-point QKD proof establishes a key between the security boundaries of two modules. A deployed service adds:
- endpoint identity, physical protection, access control, and tamper response;
- key storage, synchronization, identifiers, deletion, and audit;
- an API that supplies keys to applications without reuse or misbinding;
- encryption and integrity protection for application data;
- routing or trusted relays when there is no direct QKD link;
- availability, redundancy, maintenance, update, and supply-chain controls.
In a trusted-node QKD network, keys may be decrypted and re-encrypted or one-time-pad relayed inside intermediate nodes. Compromise of such a node can expose end-to-end key material. Quantum Repeaters aim at a different trust model, but they are not interchangeable with deployed trusted relays.
Using a QKD key in a one-time pad can give information-theoretic confidentiality only if the key is uniform enough, used once, as long as the message, protected against reuse, and combined with suitable authentication. Using it in AES or another symmetric primitive instead yields the security of that cryptographic construction under its computational assumptions. QKD does not transform an insecure application into a secure one merely by supplying key bits.
QKD and post-quantum cryptography
Section titled “QKD and post-quantum cryptography”QKD and post-quantum cryptography (PQC) address overlapping risks through different resources.
| Question | QKD | PQC |
|---|---|---|
| main mechanism | measured quantum signals plus classical postprocessing | classical algorithms based on computational hardness |
| infrastructure | specialized endpoints and a quantum channel | deployable over ordinary digital networks |
| authentication | still required | signatures or pre-shared symmetric credentials can provide it |
| availability | vulnerable to channel blocking | vulnerable to ordinary network denial of service |
| long-distance scaling | loss, trusted nodes, satellites, or future repeaters | ordinary routed networks |
| core trust | physical model, implementation isolation, randomness, endpoints | algorithm, parameters, implementation, randomness, endpoints |
They are not simple substitutes. A hybrid can diversify assumptions, but it also combines integration obligations. A comparison should use an explicit threat horizon, cost model, topology, performance target, and migration plan.
How to Audit a QKD Claim
Section titled “How to Audit a QKD Claim”Ask the following before accepting a theorem, experiment, product, or network statement:
- What ideal resource is claimed? A shared key, a rate, or only correlated raw data?
- What is the security definition? Correctness, secrecy, composability, and honest-abort parameters?
- What can Eve control? Channel, source, measurement, timing, loss, memory, and classical network?
- Which components are trusted? Include RNGs, clocks, modulators, detectors, software, and laboratories.
- How are finite statistics handled? State the sample rule, confidence method, and failure allocation.
- How is the classical channel authenticated? State the initial credential and consumed key.
- What leakage is counted? Reconciliation, verification, side information, and public metadata?
- What is the denominator? Pulses, detections, seconds, distance, loss, or deployed resources?
- Which implementation attacks were modeled and tested?
- Where are the key-management and application boundaries?
“Unhackable,” “guaranteed by nature,” and “eavesdropping is always detected” fail this audit. The defensible statement is narrower and stronger: under declared assumptions, acceptance implies a quantified distance from an ideal key resource.
Common Mistakes
Section titled “Common Mistakes”Treating QKD as encryption
Section titled “Treating QKD as encryption”QKD outputs key material. An application still needs confidentiality, integrity, replay protection, identities, and key-lifecycle rules.
Saying Eve must be detected
Section titled “Saying Eve must be detected”Alice and Bob estimate parameters and may abort. The data generally do not identify an attacker, and an attack can remain statistically indistinguishable from ordinary channel behavior while still being covered by the secrecy bound.
Using no-cloning as the whole proof
Section titled “Using no-cloning as the whole proof”No-cloning does not quantify partial information, finite statistics, device flaws, or authentication.
Calling the public channel secret
Section titled “Calling the public channel secret”Classical postprocessing may be public. It must be authenticated, and its leakage must be included in the proof.
Quoting an asymptotic rate for a finite experiment
Section titled “Quoting an asymptotic rate for a finite experiment”Finite blocks pay parameter-estimation, smoothing, verification, and privacy-amplification penalties. A positive asymptotic expression can coexist with zero certified finite-block key.
Assuming a countermeasure closes every side channel
Section titled “Assuming a countermeasure closes every side channel”Decoy states, MDI-QKD, and device-independent protocols move or refine particular trust boundaries. Each leaves other assumptions that must be stated and validated.
Exercises
Section titled “Exercises”1. Compose correctness and secrecy
Section titled “1. Compose correctness and secrecy”Suppose a protocol is correct and secret. Give a valid upper bound on its overall soundness error. What does this number not say?
Solution
By the triangle or hybrid argument used to replace the real resource first by a matching-key resource and then by a uniform secret-key resource,
This does not bound the probability of honest abort, guarantee availability, describe implementation side channels, or certify the encryption application that later consumes the key.
2. Show why authentication cannot be omitted
Section titled “2. Show why authentication cannot be omitted”Construct a man-in-the-middle attack against a QKD protocol whose classical channel is public and integrity-protected only by unauthenticated checksums.
Solution
Eve terminates Alice’s quantum and classical traffic and initiates a separate session with Bob. She presents herself as Bob to Alice and as Alice to Bob. Checksums detect accidental corruption but do not bind either transcript to an identity, so Eve can generate valid checksums for both sessions.
Alice finishes with a key shared with Eve, while Bob finishes with a different key shared with Eve. Eve can decrypt, alter, and re-encrypt later traffic between the two sessions. Quantum error tests can pass because Eve is a legitimate endpoint in each separate run.
3. Find the gap in a no-cloning argument
Section titled “3. Find the gap in a no-cloning argument”A proposed proof says, “Eve cannot copy an unknown photon perfectly, so she has zero information about every accepted key bit.” Give three independent reasons the conclusion does not follow.
Solution
First, Eve need not make a perfect copy; an approximate interaction can trade disturbance for partial information. Second, a practical pulse may contain multiple photons or leak its setting in another degree of freedom, so Eve may learn information without cloning the modeled qubit. Third, even an ideal signal argument says nothing about finite-sample inference, error-correction leakage, authentication, or privacy amplification. A security proof must bound Eve’s side information after all accepted protocol steps.
4. Illustrative parameter bound
Section titled “4. Illustrative parameter bound”Under an independent Bernoulli model, test bits have observed error frequency . Use Hoeffding’s inequality to find such that the upper-tail failure probability is at most .
Solution
Set
Then
The illustrative upper confidence value is therefore
This calculation is not automatically valid for a QKD sample drawn without replacement or for a non-i.i.d. attack; the protocol must use the statistical theorem matching its sampling procedure and adversary reduction.
5. Complete a finite-key ledger
Section titled “5. Complete a finite-key ledger”A proof gives bits. Reconciliation leaks at most bits, verification costs bits, and the privacy-amplification margin is bits. Find the largest output length allowed by this simplified ledger. If output bits replenish authentication, what is the net expansion?
Solution
The output length obeys
After reserving bits for authentication, the net expansion is
bits. A real proof may place some transcript terms inside the conditional min-entropy and may contain additional finite-size penalties.
6. Privacy-amplification margin
Section titled “6. Privacy-amplification margin”Ignore smoothing and convention-dependent prefactors. If the reconciled string has conditional min-entropy at least bits and Alice extracts bits, estimate the leftover-hash contribution
Solution
The entropy sacrifice is bits, so
The extractor contribution is therefore extremely small. The total secrecy parameter may nevertheless be dominated by smoothing, parameter estimation, authentication, or other allocated failures.
7. Interpret the Devetak–Winter terms
Section titled “7. Interpret the Devetak–Winter terms”Suppose a justified asymptotic model gives
bits per sifted signal. What one-way rate skeleton follows, and why is it not yet an experimental throughput?
Solution
The expression gives
secret bits per sifted signal in the stated asymptotic model. It omits finite-block penalties, sifting and detection probabilities, authentication cost, clock rate, dead time, loss, postselection, and the distinction between sifted signals and transmitted pulses. Those are needed to convert the entropy rate into net bits per second.
8. Separate secrecy from availability
Section titled “8. Separate secrecy from availability”Eve blocks every quantum signal. What should a sound QKD implementation do, and has Eve broken secrecy?
Solution
The implementation should observe too few valid detections or fail another acceptance condition and abort without outputting a key. Eve has denied service but has not learned an accepted key because no key exists. Treating availability and secrecy as separate properties prevents an abort from being mislabeled as a cryptographic break while still recognizing its operational impact.
9. Match countermeasures to assumptions
Section titled “9. Match countermeasures to assumptions”For each case, name the most directly relevant protocol or engineering response: multiphoton weak-coherent pulses, detector blinding, and untrusted state preparation together with untrusted measurements.
Solution
- Multiphoton weak-coherent pulses motivate phase randomization plus decoy-state estimation.
- Detector blinding motivates an explicit detector model and hardening; MDI-QKD removes detector behavior from the trusted security boundary.
- Simultaneously untrusted preparation and measurement motivates a device-independent analysis based on loophole-controlled nonlocal correlations.
These labels are not blanket guarantees. Decoy-state analysis retains source assumptions, MDI-QKD retains source trust, and device-independent QKD retains assumptions about random inputs, isolation, authentication, and finite statistics.
10. Compose QKD with message protection
Section titled “10. Compose QKD with message protection”Alice and Bob obtain a -bit QKD key. Compare using it for a -bit one-time pad with using 256 bits as an AES key. State the additional requirements in each case.
Solution
For a one-time pad, the full -bit key can encrypt one message of the same length with information-theoretic confidentiality, provided the key is sufficiently uniform, never reused, synchronized, erased appropriately, and combined with a secure message-authentication mechanism. The pad alone is malleable.
Using 256 bits as an AES key allows much more data to be processed, but confidentiality rests on the computational security and correct mode of operation of AES. An authenticated-encryption construction, nonce discipline, endpoint security, and key lifecycle are still required. In neither case does the QKD layer by itself protect the application.
References
Section titled “References”- C. H. Bennett and G. Brassard, “Quantum cryptography: Public key distribution and coin tossing,” in Proceedings of the IEEE International Conference on Computers, Systems and Signal Processing, Bangalore, 175–179 (1984); reprinted in Theoretical Computer Science 560, 7–11 (2014), doi:10.1016/j.tcs.2014.05.025.
- A. K. Ekert, “Quantum cryptography based on Bell’s theorem,” Physical Review Letters 67, 661–663 (1991), doi:10.1103/PhysRevLett.67.661.
- C. H. Bennett, G. Brassard, and N. D. Mermin, “Quantum cryptography without Bell’s theorem,” Physical Review Letters 68, 557–559 (1992), doi:10.1103/PhysRevLett.68.557.
- D. Mayers, “Unconditional security in quantum cryptography,” Journal of the ACM 48, 351–406 (2001), doi:10.1145/382780.382781.
- H.-K. Lo and H. F. Chau, “Unconditional security of quantum key distribution over arbitrarily long distances,” Science 283, 2050–2056 (1999), doi:10.1126/science.283.5410.2050.
- P. W. Shor and J. Preskill, “Simple proof of security of the BB84 quantum key distribution protocol,” Physical Review Letters 85, 441–444 (2000), doi:10.1103/PhysRevLett.85.441.
- I. Devetak and A. Winter, “Distillation of secret key and entanglement from quantum states,” Proceedings of the Royal Society A 461, 207–235 (2005), doi:10.1098/rspa.2004.1372.
- R. Renner, Security of Quantum Key Distribution, Ph.D. thesis, ETH Zürich (2005), doi:10.3929/ethz-a-005115027.
- R. Renner and R. König, “Universally composable privacy amplification against quantum adversaries,” in Theory of Cryptography, Lecture Notes in Computer Science 3378, 407–425 (2005), doi:10.1007/978-3-540-30576-7_22.
- M. N. Wegman and J. L. Carter, “New hash functions and their use in authentication and set equality,” Journal of Computer and System Sciences 22, 265–279 (1981), doi:10.1016/0022-0000(81)90033-7.
- V. Scarani et al., “The security of practical quantum key distribution,” Reviews of Modern Physics 81, 1301–1350 (2009), doi:10.1103/RevModPhys.81.1301.
- M. Tomamichel et al., “Tight finite-key analysis for quantum cryptography,” Nature Communications 3, 634 (2012), doi:10.1038/ncomms1631.
- H.-K. Lo, M. Curty, and B. Qi, “Measurement-device-independent quantum key distribution,” Physical Review Letters 108, 130503 (2012), doi:10.1103/PhysRevLett.108.130503.
- H.-K. Lo, M. Curty, and K. Tamaki, “Secure quantum key distribution,” Nature Photonics 8, 595–604 (2014), doi:10.1038/nphoton.2014.149.
- M. Tomamichel and A. Leverrier, “A largely self-contained and complete security proof for quantum key distribution,” Quantum 1, 14 (2017), doi:10.22331/q-2017-07-14-14.
- F. Xu, X. Ma, Q. Zhang, H.-K. Lo, and J.-W. Pan, “Secure quantum key distribution with realistic devices,” Reviews of Modern Physics 92, 025002 (2020), doi:10.1103/RevModPhys.92.025002.
- C. Portmann and R. Renner, “Security in quantum cryptography,” Reviews of Modern Physics 94, 025008 (2022), doi:10.1103/RevModPhys.94.025008.
- ITU-T, Framework of Quantum Key Distribution Protocols in QKD Networks, Recommendation X.1711 (2026), official publication.
Further Connections
Section titled “Further Connections”- BB84 develops the four signal states, basis sifting, intercept–resend benchmark, source-replacement picture, and asymptotic bit–phase error rate.
- E91 and Entanglement-Based QKD derives the three-setting transcript, singlet CHSH value, key-round sifting, and device-dependent versus device-independent trust boundary.
- Decoy-State QKD derives photon-number yield equations, vacuum-plus-weak bounds, and the source assumptions needed for weak coherent pulses.
- Measurement-Device-Independent QKD moves the joint measurement and detectors to an untrusted relay while retaining characterized endpoint sources.
- Device-Independent QKD develops the black-box input-output model, Bell-to-entropy bounds, loophole-aware trial contract, and finite-key entropy ledger.
- No-Cloning and No-Signaling gives the precise no-go statements while explaining why neither one is a complete QKD security proof.
- Communication with Quantum Systems separates secret-key generation from classical-message transmission, quantum-state preservation, and entanglement distribution.
- Quantum Teleportation contrasts key establishment with quantum state transfer and makes the role of authenticated versus ordinary classical communication easier to separate.
- Entanglement Distillation develops the Bell-pair recurrence and hashing protocols that underlie the virtual entanglement-purification viewpoint used in important QKD security proofs.
- Density Operators for Quantum Information supplies the classical–quantum states used in secrecy definitions.
- Entanglement Measures distinguishes operational entanglement resources from the secret-key resource.
- Entanglement in Quantum Information places QKD among other uses of nonclassical correlations.
- Claims, Hype, and Evidence Standards gives the wider framework for auditing security, rate, and deployment claims.
- Quantum Information Roadmap places cryptography after states, channels, measurements, entanglement, and no-go theorems.