36
3 Introducing Quantum Key Distribution
3.1 The Origins of Security
QKD is a specific task of quantum cryptography where two honest parties, traditionally called Alice and Bob, establish a shared secret key when connected by an
insecure quantum channel and an authenticated public classical channel. The combination of QKD with the Vernam cipher [1, 2], also called one-time pad, allows for
ever-lasting secure communication.
Indeed, suppose that Alice wants to send a secret message m, composed of n bits,
to Bob. According to the Vernam cipher, Alice encrypts her message by adding it
modulo two
1 with a n-bit key k she shares with Bob, thanks to a prior execution of
a QKD protocol: m e = m ⊕ k. She then sends the encrypted message m e to Bob,
who decrypts it by again adding the encryption key: m e ⊕ k = m ⊕ k ⊕ k = m.
The Vernam cipher is provably secure as long as the number of key bits matches the
number of message bits, and the key (or parts of it) is not reused [3]. The security of
the communication thus depends on the security of the QKD protocol.
Many QKD protocols are based on the transmission of quantum states from Alice
to Bob, through the quantum channel. The crucial fact which makes QKD secure is
that a potential eavesdropper, Eve, cannot gain any information from the transmitted
states without disturbing them.
For instance, an obvious attack by Eve would be to create perfect copies of the
transmitted states before they reach Bob, as in classical wiretapping. However, quantum mechanics prevents this, as shown by the no-cloning theorem.
Theorem 3.1 (no-cloning [4]) It is not possible to perfectly clone an unknown quantum state.
Proof Suppose by contradiction that we have a cloning machine and that we apply it
on two distinct quantum states |ψ = |φ which are also non-orthogonal φ|ψ = 0.
The action of the cloning machine is represented by a unitary operation U , which
copies the input state on some auxiliary system initially in a normalized state |s:
U (|ψ ⊗ |s) = |ψ ⊗ |ψ
(3.1)
U (|φ ⊗ |s) = |φ ⊗ |φ.
(3.2)
By taking the inner product of equations (3.1) and (3.2) we obtain:
φ|ψ = (φ|ψ)
2
,
(3.3)
which is only true when the states |ψ and |φ are either the same state or are
orthogonal, thus a general cloning machine is not possible.
We remark that this theorem does not contradict our common sense that classical
information can be copied, since the latter is always stored in physical systems (e.g., a
1 In this case the “⊕” symbol indicates the XOR operation on bits or bitstrings.
3 Introducing Quantum Key Distribution
3.1 The Origins of Security
QKD is a specific task of quantum cryptography where two honest parties, traditionally called Alice and Bob, establish a shared secret key when connected by an
insecure quantum channel and an authenticated public classical channel. The combination of QKD with the Vernam cipher [1, 2], also called one-time pad, allows for
ever-lasting secure communication.
Indeed, suppose that Alice wants to send a secret message m, composed of n bits,
to Bob. According to the Vernam cipher, Alice encrypts her message by adding it
modulo two
1 with a n-bit key k she shares with Bob, thanks to a prior execution of
a QKD protocol: m e = m ⊕ k. She then sends the encrypted message m e to Bob,
who decrypts it by again adding the encryption key: m e ⊕ k = m ⊕ k ⊕ k = m.
The Vernam cipher is provably secure as long as the number of key bits matches the
number of message bits, and the key (or parts of it) is not reused [3]. The security of
the communication thus depends on the security of the QKD protocol.
Many QKD protocols are based on the transmission of quantum states from Alice
to Bob, through the quantum channel. The crucial fact which makes QKD secure is
that a potential eavesdropper, Eve, cannot gain any information from the transmitted
states without disturbing them.
For instance, an obvious attack by Eve would be to create perfect copies of the
transmitted states before they reach Bob, as in classical wiretapping. However, quantum mechanics prevents this, as shown by the no-cloning theorem.
Theorem 3.1 (no-cloning [4]) It is not possible to perfectly clone an unknown quantum state.
Proof Suppose by contradiction that we have a cloning machine and that we apply it
on two distinct quantum states |ψ = |φ which are also non-orthogonal φ|ψ = 0.
The action of the cloning machine is represented by a unitary operation U , which
copies the input state on some auxiliary system initially in a normalized state |s:
U (|ψ ⊗ |s) = |ψ ⊗ |ψ
(3.1)
U (|φ ⊗ |s) = |φ ⊗ |φ.
(3.2)
By taking the inner product of equations (3.1) and (3.2) we obtain:
φ|ψ = (φ|ψ)
2
,
(3.3)
which is only true when the states |ψ and |φ are either the same state or are
orthogonal, thus a general cloning machine is not possible.
We remark that this theorem does not contradict our common sense that classical
information can be copied, since the latter is always stored in physical systems (e.g., a
1 In this case the “⊕” symbol indicates the XOR operation on bits or bitstrings.
