Frontier physics
Quantum cryptography
Quantum key distribution uses measurement disturbance to detect eavesdropping; BB84 illustrates the principle.
Quantum key distribution uses measurement disturbance to detect eavesdropping; BB84 illustrates the principle.
Definition: Core idea
BB84: Alice randomly encodes each bit in the Z or X basis; Bob measures in a random basis. They publicly compare bases, not bit values, retain matching-basis events, then estimate errors to test for eavesdropping.
Model and interpretation
BB84: Alice randomly encodes each bit in the Z or X basis; Bob measures in a random basis. They publicly compare bases, not bit values, retain matching-basis events, then estimate errors to test for eavesdropping.
Example: Quantitative example
In 1000 BB84 rounds, suppose 500 use matching bases. A 2% error rate in the test sample means about 10 observed errors.
Solution
The expected test errors are 500×0.02=10; security analysis must also account for sampling fluctuations, authentication, error correction, and privacy amplification.
Quick check
BB84 uses two incompatible measurement bases, such as rectilinear and diagonal. Alice sends randomly chosen quantum bit states; Bob measures in randomly chosen bases. They later reveal bases but not bit values, then compare a sample to estimate the error rate. No-cloning and disturbance from a wrong-basis measurement make eavesdropping raise errors; the key is used only after privacy amplification and authentication checks.
Security does not mean assumption-free: users must authenticate the classical channel, estimate errors, and discard the key if a security threshold is exceeded. Security proofs bound an adversary’s probability of guessing the key while accounting for noise and information leakage. Quantum cryptography distributes keys; it does not itself encrypt data, so deployment still combines it with conventional symmetric encryption.
Quantum key distribution requires a classical step to sift bases and compare test samples. The error rate bounds an eavesdropper’s information, but device-originated errors must also be modeled. Practical protocols therefore need authentication, leakage bounds, and a security proof matched to the chosen device assumptions. The authenticated classical discussion is essential to prevent active interception or message substitution.
In BB84, why does revealing bases not reveal the key?
Which statement best describes “Quantum cryptography”?
References
- Michael A. Nielsen, Isaac L. Chuang (2010). Nielsen & Chuang, Quantum Computation and Quantum Information, 2010