76
5 Quantum Key Distribution with Imperfect Devices
go under the name of detector side channels. An example is the detector blinding
attack [11], where Eve first sends bright light to Bob’s single-photon detectors to
“blind” them and make them operate in linear-mode. This means that his detectors
are now unable to detect single photons and produce a click only above a certain
intensity threshold. Eve then sends tailored light pulses to Bob which yield a click
only when Bob chooses the same basis in which Eve prepared the pulse. Hence
Eve knows the outcome of each detection observed by Bob, without introducing
noticeable disturbance.
Measurement-device-independent QKD (MDI-QKD) [13, 14] provides a solution
which removes all possible detector side channels with a new QKD paradigm. Here,
the honest parties send quantum signals to an intermediate relay which applies some
measurement and publicly announces the outcome. The founding idea is to remove
all trust from the measurement apparatus, which can be operated by Eve, and place it
on the sources, held by Alice and Bob. Typically, QKD sources are attenuated lasers
which can be easily characterized in a controlled environment such as Alice’s and
Bob’s laboratories. Note that this scenario is opposite to the previous one, where the
source was untrusted and the measurement devices were trusted.
Despite the fact that Eve has potentially full control on the relay and on the
connecting quantum channels, Alice and Bob can still establish a secret key. This is
possible if the measurement outcome publicly announced by the relay, in an honest
implementation, is informative for Alice and Bob but is not informative—i.e. it does
not reveal information on the key—for anyone else, including Eve.
To make things more concrete, let us consider an idealized MDI-QKD protocol [15] where Alice and Bob independently encode their bits in the rectilinear or
diagonal polarization of single-photon states, represented by the bases {|0, |1} and
{|++, |−−} (with |±± = (|0 + |1)/
√
2), respectively. The quantum signals are then
sent to the relay. Here a Bell-state measurement, i.e. a projection on one of the four
Bell states |ψ i j given in (3.15), is applied on the incoming signals and its outcome
(i, j) is announced. Upon sifting, Alice and Bob are only left with bits corresponding
to rounds in which they used the same basis. If both parties used the rectilinear basis,
the outcomes (i, 0) (for i = 0, 1) inform them that their bit values coincide, while
the outcomes (i, 1) indicate that they encoded opposite bit values. Similarly, if Alice
and Bob used the diagonal basis, the outcomes (0, j) indicate they have same bit
values while (1, j) indicate opposite bit values. Bob can thus flip his bit according
to the measurement outcome and recover Alice’s bit.
In simple terms, the outcome of the Bell-state measurement reveals the parity of
the parties’ bits but not their values. Therefore, it provides useful information only
if one of the two bit values is known (i.e. to Alice and Bob), while being useless
otherwise.
Of course, Eve could implement any other operation on the incoming pulses but
she is still required to announce an outcome of the form (i, j) at every round. Thus,
by comparing a fraction of their sifted bits, Alice and Bob can verify the deviation
of the actual measurement apparatus from the ideal one and quantify the amount of
information gained by Eve.
Précédent

- 88/163

Suivant