5.1 BB84 with Weak Coherent Pulses
73
collected in these instances is secure and added to Eve’s uncertainty, as there is no
way for Eve to know it.
Finally E Z (X ) is the QBER in the Z (X ) basis given that Bob had a detection, and
e
n
Z (X ) is the error rate in the Z (X ) basis given that Alice sent n photons and Bob had
a detection. It thus holds:
E Z (X ) Q Z (X ) =
∞
n=0
Q
n
Z (X ) e
n
Z (X ) .
(5.6)
In a real experiment, the observed quantities are the gains Q Z , Q X and the QBERs
E Z , E X , while p Z is an input parameter and Q
0
, Q
1
Z and e
1
X must be estimated. In
particular, one can lower bound the achievable key rate (5.4) by upper bounding
e
1
X and by lower bounding Q
0 and Q
1
Z . The decoy-state method [4, 6, 7] provides
an excellent way to obtain such bounds, thus guaranteeing high key rates for QKD
protocols implemented with WCPs.
Before presenting the decoy-state method in Sect. 5.2, we remark that PNS attacks
are not a threat to QKD (or CKA) protocols based on the distribution of entangled
states from an untrusted source.
Remark 5.1 [PNS attacks and entanglement] The security proofs of entanglementbased QKD and CKA protocols (c.f. Lemmas 3.1 and 4.1) allow Eve to be in control of
the quantum source distributing entangled states to the parties. Indeed, no assumption
is made on the state distributed by Eve in each protocol round. In this context, a PNS
attack is equivalent to a collective attack where Eve attaches an ancilla photon to the
ideal entangled state the parties expect to receive, and keeps the ancillary photon. For
instance, in a BB84 protocol Eve would prepare the Bell state |
+
(c.f. Chap. 3)
with two identical photons destined to Alice, and then she keeps one of the two.
This means that Eve prepares a three-qubit state and keeps one of the qubits, i.e. she
performs a collective attack.
Collective attacks are already accounted for in the security proofs of QKD and
CKA protocols and can be readily detected by the parties with parameter estimation.
In conclusion, PNS attacks are already included in the security of QKD and CKA
based on the distribution of entangled states and do not pose any threat to their
security.
5.2 Decoy-State Method
We start by requiring Alice to prepare and send a phase-randomized WCP in each
round, whose state is a mixture of Fock states:
ρ μ =
1
2π
2π
0
dθ |
√ μe
iθ
√ μe
iθ
| =
∞
n=0
e
−μ μ
n
n!
|nn |.
(5.7)
73
collected in these instances is secure and added to Eve’s uncertainty, as there is no
way for Eve to know it.
Finally E Z (X ) is the QBER in the Z (X ) basis given that Bob had a detection, and
e
n
Z (X ) is the error rate in the Z (X ) basis given that Alice sent n photons and Bob had
a detection. It thus holds:
E Z (X ) Q Z (X ) =
∞
n=0
Q
n
Z (X ) e
n
Z (X ) .
(5.6)
In a real experiment, the observed quantities are the gains Q Z , Q X and the QBERs
E Z , E X , while p Z is an input parameter and Q
0
, Q
1
Z and e
1
X must be estimated. In
particular, one can lower bound the achievable key rate (5.4) by upper bounding
e
1
X and by lower bounding Q
0 and Q
1
Z . The decoy-state method [4, 6, 7] provides
an excellent way to obtain such bounds, thus guaranteeing high key rates for QKD
protocols implemented with WCPs.
Before presenting the decoy-state method in Sect. 5.2, we remark that PNS attacks
are not a threat to QKD (or CKA) protocols based on the distribution of entangled
states from an untrusted source.
Remark 5.1 [PNS attacks and entanglement] The security proofs of entanglementbased QKD and CKA protocols (c.f. Lemmas 3.1 and 4.1) allow Eve to be in control of
the quantum source distributing entangled states to the parties. Indeed, no assumption
is made on the state distributed by Eve in each protocol round. In this context, a PNS
attack is equivalent to a collective attack where Eve attaches an ancilla photon to the
ideal entangled state the parties expect to receive, and keeps the ancillary photon. For
instance, in a BB84 protocol Eve would prepare the Bell state |
+
(c.f. Chap. 3)
with two identical photons destined to Alice, and then she keeps one of the two.
This means that Eve prepares a three-qubit state and keeps one of the qubits, i.e. she
performs a collective attack.
Collective attacks are already accounted for in the security proofs of QKD and
CKA protocols and can be readily detected by the parties with parameter estimation.
In conclusion, PNS attacks are already included in the security of QKD and CKA
based on the distribution of entangled states and do not pose any threat to their
security.
5.2 Decoy-State Method
We start by requiring Alice to prepare and send a phase-randomized WCP in each
round, whose state is a mixture of Fock states:
ρ μ =
1
2π
2π
0
dθ |
√ μe
iθ
√ μe
iθ
| =
∞
n=0
e
−μ μ
n
n!
|nn |.
(5.7)
