72
5 Quantum Key Distribution with Imperfect Devices
Clearly the number of photons in a WCP is not well defined, opposed to the assumption made in Chap. 3 of Alice sending a single photon to Bob in each round of the
protocol. In particular, there is a non-zero probability that Alice sends a multiphoton
signal to Bob in one protocol round:
p multi = 1 − Pr(0) − Pr(1) = 1 − e
−|α|
2 − |α|
2 e
−|α|
2 > 0.
(5.3)
This allows Eve to perform new eavesdropping attacks which severely compromise
security, like the photon number splitting attack (PNS) [1, 2].
In a PNS attack, Eve first replaces the lossy channel linking Alice and Bob with a
lossless channel. She then performs quantum non-demolition (QND) measurements
1
on the pulses sent by Alice that project them onto subspaces characterized by a fixed
photon number, without modifying the pulses’ polarization. If the pulse contains
just one photon, she blocks it with the same probability of having a loss in the
original lossy channel. If she observes multiple photons, she deterministically splits
one photon off the signal and stores it in her quantum memory, while sending the
remaining photons to Bob. In this way, she has a copy of the photon(s) received by
Bob without being noticed. After the parties reveal the bases used in every round,
Eve measures the photons in her quantum memory accordingly and learns the key.
From the above example, we learn that only the single-photon signals emitted
by Alice are still secure. The security proof by Gottesman-Lo-Lütkenhaus-Preskill
(GLLP) [3] states that a BB84 protocol implemented with WCPs is still secure,
provided that one extracts the key only from single-photon signals. The resulting
asymptotic secret key rate, for an asymmetric BB84 protocol where the Z basis is
used for key generation and the X basis for PE, reads [4, 5]:
r GLLP = p
2
Z
Q
0
Z + Q
1
Z (1 − h(e
1
X )) − Q Z h(E Z )
,
(5.4)
where p Z is the probability that Alice (Bob) chooses the Z basis (asymptotically it can
be chosen p Z → 1). In the GLLP rate (5.4), we recognize the contribution coming
from the estimation of Eve’s uncertainty from single-photon signals Q
0
Z + Q
1
Z (1 −
h(e
1
X )) from which we subtract the information leaked during error correction (EC)
Q Z h(E Z ), similarly to the asymptotic BB84 rate in (3.26). In particular, Q
n
Z (n =
0, 1) is the probability that Alice sent n photons in the Z basis and Bob had a detection
event, while Q Z is the gain in the Z basis, i.e. the probability that Bob had a detection
given that Alice sent a WCP in that basis. Analogous quantities are defined for the
X basis. We have that:
Q Z (X ) =
∞
n=0
Q
n
Z (X ) .
(5.5)
We note that Q
0
Z = Q
0
X = Q
0 is independent of the basis, since in this case Bob’s
detection is caused by dark counts or stray light in his detectors. Hence, the data Bob
1 A QND measurement preserves the physical integrity of the system being measured.
5 Quantum Key Distribution with Imperfect Devices
Clearly the number of photons in a WCP is not well defined, opposed to the assumption made in Chap. 3 of Alice sending a single photon to Bob in each round of the
protocol. In particular, there is a non-zero probability that Alice sends a multiphoton
signal to Bob in one protocol round:
p multi = 1 − Pr(0) − Pr(1) = 1 − e
−|α|
2 − |α|
2 e
−|α|
2 > 0.
(5.3)
This allows Eve to perform new eavesdropping attacks which severely compromise
security, like the photon number splitting attack (PNS) [1, 2].
In a PNS attack, Eve first replaces the lossy channel linking Alice and Bob with a
lossless channel. She then performs quantum non-demolition (QND) measurements
1
on the pulses sent by Alice that project them onto subspaces characterized by a fixed
photon number, without modifying the pulses’ polarization. If the pulse contains
just one photon, she blocks it with the same probability of having a loss in the
original lossy channel. If she observes multiple photons, she deterministically splits
one photon off the signal and stores it in her quantum memory, while sending the
remaining photons to Bob. In this way, she has a copy of the photon(s) received by
Bob without being noticed. After the parties reveal the bases used in every round,
Eve measures the photons in her quantum memory accordingly and learns the key.
From the above example, we learn that only the single-photon signals emitted
by Alice are still secure. The security proof by Gottesman-Lo-Lütkenhaus-Preskill
(GLLP) [3] states that a BB84 protocol implemented with WCPs is still secure,
provided that one extracts the key only from single-photon signals. The resulting
asymptotic secret key rate, for an asymmetric BB84 protocol where the Z basis is
used for key generation and the X basis for PE, reads [4, 5]:
r GLLP = p
2
Z
Q
0
Z + Q
1
Z (1 − h(e
1
X )) − Q Z h(E Z )
,
(5.4)
where p Z is the probability that Alice (Bob) chooses the Z basis (asymptotically it can
be chosen p Z → 1). In the GLLP rate (5.4), we recognize the contribution coming
from the estimation of Eve’s uncertainty from single-photon signals Q
0
Z + Q
1
Z (1 −
h(e
1
X )) from which we subtract the information leaked during error correction (EC)
Q Z h(E Z ), similarly to the asymptotic BB84 rate in (3.26). In particular, Q
n
Z (n =
0, 1) is the probability that Alice sent n photons in the Z basis and Bob had a detection
event, while Q Z is the gain in the Z basis, i.e. the probability that Bob had a detection
given that Alice sent a WCP in that basis. Analogous quantities are defined for the
X basis. We have that:
Q Z (X ) =
∞
n=0
Q
n
Z (X ) .
(5.5)
We note that Q
0
Z = Q
0
X = Q
0 is independent of the basis, since in this case Bob’s
detection is caused by dark counts or stray light in his detectors. Hence, the data Bob
1 A QND measurement preserves the physical integrity of the system being measured.
