Towards Quantum Cryptography
Table of Contents
Classical methods rely on mathematical complexity (problems that are easy to pose but hard to solve), while QKD relies on the immutable laws of physics.
Security foundation
Classical Key Distribution: based on computationally difficult mathematical problems, such as factoring large prime numbers. assume that an adversary lacks the computing power to solve these problems within a practical time frame.
Quantum Key Distribution: leverages the principles of quantum mechanics, specifically the quantum no-cloning theorem. Instead of relying on computational difficulty, it uses the physical properties of quantum states to achieve information-theoretic secure communication.
Eavesdropper Detection
Classical: data is transmitted as classical bits. An eavesdropper can passively intercept, copy, and read these bits without altering the original message, making their presence incredibly difficult to detect.
QKD: Because quantum states are inherently non-duplicable due to the No Cloning Theorem, any eavesdropping attempt unavoidably introduces disturbance in the quantum signals. If an attacker intercepts the quantum key, they irreversibly change its state, immediately alerting the sender and receiver to the intrusion.
In classical computing, you can easily copy a piece of data (a 1 can be copied to another 1 indefinitely). However, quantum states are inherently non-duplicable due to the no-cloning theorem. If an eavesdropper (Eve) intercepts a quantum signal—such as a single photon—she cannot make a perfect copy of it to hold onto while sending the original along to the receiver (Bob). Because she cannot clone it, she must measure it. In quantum mechanics, measuring a state fundamentally alters or collapses it, which unavoidably introduces disturbance to the quantum signals. That disturbance is what alerts Alice and Bob to her presence.
The Setup
QKD is not purely quantum, and it is strictly used for the key exchange, not the communication of the actual secret message itself. A standard QKD setup requires two distinct channels:
-
The Quantum Channel: This channel is used exclusively for transmitting the quantum states from the sender (Alice) to the receiver (Bob). An attacker is assumed to be able to perform any physically possible transformation on the quantum states within this channel.
-
The Authenticated Classical Channel: This is a standard, traditional communication link used for exchanging classical information related to postprocessing. Any information on classical channels can potentially be accessed by an attacker, but it is authenticated to ensure Eve cannot secretly impersonate Alice or Bob.
Once Alice and Bob use this dual-channel setup to securely generate and share a final key, the QKD portion is complete. They then use that key to encrypt their actual data and transmit that encrypted data over a normal classical network
How the Keys are Equalized
When the quantum transmission phase is over, Alice and Bob each hold a “raw key.” Due to natural hardware imperfections, channel noise, or a potential eavesdropper, their raw keys will have errors and will not be perfectly identical.
They equalize and secure these keys by communicating over the classical channel in a phase called postprocessing. This phase takes the flawed raw data and distills it down into a perfect, shared secret key through the following subprotocols:
- Parameter Estimation: They sacrifice a portion of their raw data to estimate the parameters of the communication channel, specifically looking at the error rate to determine if an eavesdropper has intercepted too much information.
- Sifting: They compare notes (without revealing the key itself) to filter out invalid data caused by system loss and basis inconsistency.
- Information Reconciliation: This acts as error correction. They use algorithms to detect and correct transmission errors, ensuring that Bob can accurately recover Alice’s original information and their keys become 100% identical.
- Privacy Amplification: Because the previous steps required public discussion over the classical channel, Eve might have picked up some partial clues about the key. They use hash functions to compress their reconciled key into a shorter, final secure key, wiping out any partial knowledge Eve might have gathered.
(Pre-Processing)
-
Alice’s Hardware: Her FPGA generates true random numbers and maps them into continuous variables, usually following a Gaussian distribution. These digital values are sent to a Digital-to-Analog Converter (DAC) to modulate the amplitude and phase of a laser pulse.
-
Bob’s Hardware: A homodyne detector receives the light, and an Analog-to-Digital Converter (ADC) digitizes the quantum states back into continuous variables (e.g., as 12-bit values).
-
Initial Data: They begin with a massive block of raw data (e.g., to symbols). Due to channel loss and inherent quantum noise, Bob’s digitized values are correlated with Alice’s, but not perfectly identical.
Sifting & Parameter Estimation
-
Sifting: If Bob randomly chose to measure a different physical property (quadrature) than Alice encoded, that data is useless. Bob transmits his measurement choices over the classical channel, and both FPGAs drop the mismatched pulses from their memory buffers.
-
Parameter Estimation (PE): They randomly select a subset (e.g., 10%) of their remaining sifted variables and publicly reveal them over the classical channel.
-
The Sacrifice: The FPGA computes the covariance of these samples to calculate channel noise. Because this subset was exposed on the public channel, Eve knows it, so it must be permanently deleted from the key pool.
Information Reconciliation
-
Inputs: The remaining noisy, continuous variables.
-
Process: FPGAs use protocols like Multidimensional or Slice Reconciliation to map these continuous values into discrete binary strings. Bob’s FPGA uses a Low-Density Parity-Check (LDPC) encoder to generate parity bits (syndromes), which are sent to Alice. Alice runs an LDPC decoder to correct her noisy variables to exactly match Bob’s.
-
Output: Both FPGAs now hold an identical, error-free array of discrete binary bits.
Privacy Amplification
-
Process: The FPGAs use Universal Hash Functions (often implemented as a Toeplitz matrix multiplication) to compress the reconciled binary key.
-
The Sacrifice: The string is drastically shortened to destroy any partial information Eve might have learned during the physical transmission or the error-correction chatter.