38
3 Introducing Quantum Key Distribution
defined by the horizontal/vertical directions (0
◦ /90
◦ ) and the other defined by the
diagonal/antidiagonal (+45
◦ /−45
◦ ) directions. The polarization state of a photon is
thus represented by a qubit in H 2 . We associate the eigenbasis {|0, |1} of Pauli
operator Z to the horizontal/vertical basis and the eigenbasis {|++, |−−} of X to
the diagonal/antidiagonal basis, where |±± = (|0 ± |1)/
√
2. The BB84 protocol
comprises the following steps:
1. Alice sends to Bob a sequence of M photons randomly prepared in one of the
four states |0, |1, |++ and |−−, via the quantum channel. The parties identify the
bit value 0 (1) with the non-orthogonal states |0 and |++ (|1 and |−−). The nonorthogonality condition ensures that any tampering with the quantum channel by
Eve, in order to gain information on the transmitted key, leads to a disturbance of
the signal and can be later detected by the parties.
2. Upon receiving a photon, Bob measures randomly in either the Z or the X basis.
If Bob measures in the same basis Alice used to prepare the photon, he learns the
bit she encoded on that photon, provided that the signal has not been altered. If
instead Bob measures in the complementary basis, he obtains a random bit since
the two bases are mutually unbiased (c.f. Sect. 2.1).
3. Sifting Once the quantum communication is over, Alice and Bob publicly compare the bases they used on each photon and discard the bits corresponding to
unmatching bases. This process leaves Alice and Bob with strings of approximately M/2 bits. In absence of errors due to noise or eavesdropping, the bitstrings
of Alice and Bob would coincide.
4. Parameter estimation (PE) Alice and Bob reveal a random sample of their bits in
order to estimate the error rate in the quantum channel and thus the information
gained by Eve.
2 In particular, the parties estimate the quantum bit error rate
(QBER) in the Z (X ) basis, i.e. the fraction E Z (E X ) of bits generated by measuring
in the Z (X ) basis that disagree. The computed QBERs are the input parameters
of the following steps. The parties are now left with two partially-correlated and
partially-secret bitstrings, called the raw keys. We denote a generic raw key bit of
Alice (Bob) by the random variable R A (R B ).
5. Error correction (EC) Alice and Bob run a one-way error correction algorithm
to correct Bob’s raw key to match Alice’s. Alice sends the required information
over a classical public channel to Bob. Other EC schemes are possible.
6. Privacy amplification (PA) The parties remove the information that Eve gained
on their error-corrected keys by compressing them to a shorter secret key via a
randomness extractor (e.g., two-universal hashing, Sect. 2.10).
The figure of merit of every QKD protocol is the secret key rate, i.e. the fraction of
secure key bits produced per protocol round.
3 A round is commonly regarded as the
2 For security reasons one needs to consider the worst-case scenario, i.e. that all the noise in the
channel is due to Eve.
3 In experiments, the secret key rate is often given in terms of secret key bits per second. This is
obtained by multiplying the secret key rate defined here by the repetition rate of the protocol, i.e.
the number of protocol rounds per second.
3 Introducing Quantum Key Distribution
defined by the horizontal/vertical directions (0
◦ /90
◦ ) and the other defined by the
diagonal/antidiagonal (+45
◦ /−45
◦ ) directions. The polarization state of a photon is
thus represented by a qubit in H 2 . We associate the eigenbasis {|0, |1} of Pauli
operator Z to the horizontal/vertical basis and the eigenbasis {|++, |−−} of X to
the diagonal/antidiagonal basis, where |±± = (|0 ± |1)/
√
2. The BB84 protocol
comprises the following steps:
1. Alice sends to Bob a sequence of M photons randomly prepared in one of the
four states |0, |1, |++ and |−−, via the quantum channel. The parties identify the
bit value 0 (1) with the non-orthogonal states |0 and |++ (|1 and |−−). The nonorthogonality condition ensures that any tampering with the quantum channel by
Eve, in order to gain information on the transmitted key, leads to a disturbance of
the signal and can be later detected by the parties.
2. Upon receiving a photon, Bob measures randomly in either the Z or the X basis.
If Bob measures in the same basis Alice used to prepare the photon, he learns the
bit she encoded on that photon, provided that the signal has not been altered. If
instead Bob measures in the complementary basis, he obtains a random bit since
the two bases are mutually unbiased (c.f. Sect. 2.1).
3. Sifting Once the quantum communication is over, Alice and Bob publicly compare the bases they used on each photon and discard the bits corresponding to
unmatching bases. This process leaves Alice and Bob with strings of approximately M/2 bits. In absence of errors due to noise or eavesdropping, the bitstrings
of Alice and Bob would coincide.
4. Parameter estimation (PE) Alice and Bob reveal a random sample of their bits in
order to estimate the error rate in the quantum channel and thus the information
gained by Eve.
2 In particular, the parties estimate the quantum bit error rate
(QBER) in the Z (X ) basis, i.e. the fraction E Z (E X ) of bits generated by measuring
in the Z (X ) basis that disagree. The computed QBERs are the input parameters
of the following steps. The parties are now left with two partially-correlated and
partially-secret bitstrings, called the raw keys. We denote a generic raw key bit of
Alice (Bob) by the random variable R A (R B ).
5. Error correction (EC) Alice and Bob run a one-way error correction algorithm
to correct Bob’s raw key to match Alice’s. Alice sends the required information
over a classical public channel to Bob. Other EC schemes are possible.
6. Privacy amplification (PA) The parties remove the information that Eve gained
on their error-corrected keys by compressing them to a shorter secret key via a
randomness extractor (e.g., two-universal hashing, Sect. 2.10).
The figure of merit of every QKD protocol is the secret key rate, i.e. the fraction of
secure key bits produced per protocol round.
3 A round is commonly regarded as the
2 For security reasons one needs to consider the worst-case scenario, i.e. that all the noise in the
channel is due to Eve.
3 In experiments, the secret key rate is often given in terms of secret key bits per second. This is
obtained by multiplying the secret key rate defined here by the repetition rate of the protocol, i.e.
the number of protocol rounds per second.
