University Physics V · Introduction to Quantum Information · 20.8
Quantum Cryptography: BB84 & E91
BB84 and E91 are where the course's linear algebra turns into a guarantee. Learn to write each protocol as states, projectors and a sifting rule, to convert a measured error rate into a secret-key rate, and to name the assumptions — single photons, an authenticated classical channel, honest devices — the guarantee silently rests on.
Build the model
Connect the measurement to the mechanism.
Quantum key distribution rests on one fact of Hilbert space: a set of non-orthogonal states can be neither copied nor identified without being disturbed. BB84 exploits it with two mutually unbiased bases, the eigenbases of σz and σₓ, chosen so that the ensemble Eve sees is I/2 whichever basis Alice used — the basis is invisible to any operator she can apply, and her only route to the bit is a measurement that, half the time, projects the state onto the wrong basis and leaves a trace. That trace is the quantum bit error rate Q, estimated on a sacrificed sample of the sifted key, and the Shor–Preskill argument turns it into a rate: r = 1 − 2h(Q) secret bits per sifted bit, positive only below Q ≈ 11%.
E91 keeps the same logic but replaces trust in the source with a CHSH test on a shared singlet, and device-independent protocols go further, trusting nothing but the Bell violation. None of this is free. Sifting discards half the rounds, error correction and privacy amplification shrink what remains, and the theorem holds only under its hypotheses: one photon per pulse, a classical channel that cannot be impersonated, and hardware that measures the operators the model says it measures.
Break an assumption and the proof says nothing — the history of attacks on QKD is the history of those breaks.
- Simple definition
- Quantum key distribution grows a shared secret key between two parties over a public quantum channel, because an eavesdropper who measures the non-orthogonal signal states necessarily raises an error rate the parties can detect and bound.
- Example
- An eavesdropper who intercepts every BB84 photon and measures σz or σₓ at random guesses the wrong operator half the time, and each wrong guess errs at Bob with probability 1/2, so the sifted key shows Q = 1/2 × 1/2 = 25%.
Averaged over the bit, either basis sends ρ = I/2: no measurement Eve can make distinguishes which basis Alice used.
|⟨0|±⟩|² = |⟨1|±⟩|² = 1/2, so the bases are mutually unbiased; the bit is the eigenvalue ±1 of the chosen operator
Wrong operator half the time, and a wrong-basis resend errs at Bob half the time: full interception gives Q = 25% and Eve learns half the key.
f is the fraction of photons Eve intercepts (0 to 1), Q the error rate on the sifted key, IE her certain knowledge per sifted bit
The cost of correcting one bit that is wrong with probability Q, and the privacy amplification one phase error per bit demands.
Q dimensionless; h in bits per bit — 0 at Q = 0, 0.286 at Q = 0.05, exactly 1/2 at Q = 0.110, 1 at Q = 1/2
Shor–Preskill: error correction pays h(Q), privacy amplification pays h(Q) again, and the sum reaches 1 at Q ≈ 11.0%, where the key vanishes.
secret bits per sifted bit; basis symmetry makes Qₚₕₐₛₑ = Qbit; with error-correction inefficiency c ≥ 1, r = 1 − (1 + c)h(Q)
Pauli matrices are traceless, so the white-noise part contributes nothing to the trace: the CHSH value reads the singlet fraction directly.
Werner source ρ = V|Ψ⁻⟩⟨Ψ⁻| + (1 − V)I/4 with visibility V; local realism needs |S| ≤ 2; matched-basis error Q = (1 − V)/2
Trust moves from the devices to the Bell violation; the price is a tolerable error rate of about 7% instead of 11%.
S the observed CHSH value, positive only for S > 2; with depolarising noise S = 2√2(1 − 2Q) and the rate reaches zero at Q ≈ 7.1%
Encode the bit in an operator Eve cannot identify
BB84 picks one of two Hermitian operators, σz or σₓ, and sends the eigenstate whose eigenvalue +1 or −1 carries the bit: |0⟩ or |1⟩ in the σz basis, |+⟩ = (|0⟩ + |1⟩)/√2 or |−⟩ = (|0⟩ − |1⟩)/√2 in the σₓ basis. The bases are mutually unbiased — every cross overlap satisfies |⟨i|j⟩|² = 1/2 — and that is the whole design. Average over the bit Alice might have sent and the density operator is (|0⟩⟨0| + |1⟩⟨1|)/2 = I/2 in one basis and (|+⟩⟨+| + |−⟩⟨−|)/2 = I/2 in the other: the two ensembles are the same operator, so no measurement, POVM or unitary Eve applies can tell her which basis is in play. She cannot copy the photon either, because a linear map that cloned both |0⟩ and |+⟩ would have to clone their superpositions, which no-cloning forbids. Her only move is to measure something, and measuring σₓ on a σz eigenstate returns ±1 with probability 1/2 each and projects the state onto |±⟩. The information she gains and the disturbance she causes are the same event.
Sift on the announced bases, then sacrifice a sample
Run N rounds. In each, Alice draws a random bit and a random basis and sends the matching state; Bob draws his own random basis and measures σz or σₓ. Afterwards, over a public but authenticated classical channel, both announce which basis they used — never the outcome — and keep only the rounds where the bases agree. That is the sifted key, about N/2 bits long, and on it Bob's result equals Alice's bit whenever nothing intervened. Now they publish a random subset, say a tenth of it, compare bit by bit and count disagreements: the fraction is the quantum bit error rate Q. The revealed bits are discarded. With N = 10⁶ pulses, ideal detectors and no loss, that leaves 4.5 × 10⁵ candidate bits and an estimate of Q good to better than ±0.1%. Real links add detector inefficiency and fibre loss of about 0.2 dB km⁻¹, so the sifted length falls as 10(−0.02 L/km) and a 100 km link keeps roughly 1% of what was sent — distance attacks the rate, not the security.
The intercept-resend arithmetic, and why 25% is a description
Let Eve intercept a fraction f of the photons, measure each in a random basis and resend the eigenstate she found. Half the time she picks Alice's operator, learns the bit exactly and passes it on unchanged. Otherwise she gets ±1 at random and resends a state with overlap 1/2 against each of Alice's basis states, so Bob, in Alice's basis, errs with probability 1/2. Hence Q = f × ½ × ½ = f/4, and Eve knows a fraction f/2 of the sifted key with certainty: 25% and one half at full interception. That describes one crude attack, not a bound. Let her instead measure the Breidbart operator (σz + σₓ)/√2, whose eigenstates sit at Bloch angle 45° between the two bases. For an incoming |0⟩ she obtains the +1 eigenstate with probability cos²(π/8) = 0.854 and resends it; Bob then reads 0 with probability cos⁴(π/8) + sin⁴(π/8) = 3/4. Same 25% disturbance, but she now guesses every sifted bit correctly with probability 0.854 instead of 0.75. Q measures how much Eve disturbed the key, not how much she knows; a security claim needs a bound that holds for every attack.
Turn Q into a key rate: 1 − 2h(Q) and the 11% line
The bound that holds for every attack is Shor and Preskill's. Picture the sifted key as if it had been made by measuring shared Bell pairs: an error in the σz record is a bit flip, and Eve's information about the key is equivalent to phase flips in the σₓ record. Correcting the bit flips costs h(Qbit) bits per sifted bit; removing the phase flips — which is what privacy amplification does — costs h(Qₚₕₐₛₑ). BB84's basis symmetry makes the two equal, so r = 1 − 2h(Q) with h(Q) = −Q log₂Q − (1 − Q) log₂(1 − Q). At Q = 2%, h = 0.141 and r = 0.717; at Q = 5%, h = 0.286 and r = 0.427; at Q = 11.0%, h = 1/2 and r = 0. Above that, one-way post-processing yields nothing and the run is aborted, even though 11% is far below the 25% of naive interception — the gap between one attack and all attacks. Real error correction leaks more than the Shannon minimum: a Cascade-type protocol costs about c = 1.1 to 1.2 times h(Q), so r = 1 − (1 + c)h(Q) and the threshold falls to about 9.5% at c = 1.2. A finite key pays a further statistical penalty for estimating Q from a sample.
E91: let a CHSH test certify the source
Ekert's protocol starts from a source of singlets |Ψ⁻⟩ = (|01⟩ − |10⟩)/√2, with Alice measuring along 0°, 45° or 90° and Bob along 45°, 90° or 135°. For the singlet E(a, b) = ⟨Ψ⁻|(a⋅σ ⊗ b⋅σ)|Ψ⁻⟩ = −cos(a − b), so coinciding directions give perfect anticorrelation: Bob flips his outcome and the pair is a key bit. Rounds 45° apart are published and assembled into S = E(a, b) − E(a, b′) + E(a′, b) + E(a′, b′), 2√2 in magnitude for a clean singlet and at most 2 for any local hidden-variable description, including any record Eve kept. A noisy or tampered source is a Werner state ρ = V|Ψ⁻⟩⟨Ψ⁻| + (1 − V)I/4, and since every Pauli matrix is traceless the noise term drops out: E = −V cos(a − b), S = 2√2 V, and the matched-basis error rate is Q = (1 − V)/2. The violation disappears at V = 1/√2, where Q = 14.6%, yet a positive key needs Q < 11%, that is V > 0.78 and S > 2.2: a Bell violation is necessary for a key and not sufficient. Device independence, trusting only the observed S, gives r ≥ 1 − h(Q) − h[(1 + √(S²/4 − 1))/2], positive for depolarising noise only below Q ≈ 7.1%.
Name the assumptions, because each one has been broken
Each proof is a theorem with hypotheses. First, one photon per pulse. An attenuated laser is Poissonian: at mean μ = 0.1 the chance of two or more photons is 1 − e(−μ)(1 + μ) ≈ μ²/2 = 0.5%, and there Eve keeps one photon, waits for the basis announcement and reads the bit undisturbed: photon-number splitting. Decoy states, pulses at randomly varied μ, expose it and restore a proof at a lower rate. Second, an authenticated classical channel. Forgeable announcements let Eve play Bob to Alice and Alice to Bob; Wegman–Carter authentication stops that but spends a pre-shared key, so QKD expands a secret rather than creating one. Third, honest devices. The proof assumes the source emits the four stated states and the detectors implement the σz and σₓ projectors; bright-light blinding turned real avalanche photodiodes into classical switches and stole full keys. Device independence keeps only the Bell violation, yet still assumes no leakage from the laboratory, free setting choices and correct quantum mechanics. A distilled key is only a key; encrypting the message is a separate step.
Change one variable at a time
Make the relationship visible.
Drag the intercept fraction up and watch the filled marker slide down the solid curve: the rate reaches zero near Q = 11%, long before the 25% that full interception produces. Then raise the error-correction cost c and watch both curves meet the axis sooner.
QBER Q6.8 %
KEY RATE r (BB84)0.283 per sifted bit
CHSH S (DEPOLARISING NOISE)2.44
EVE KNOWS (INTERCEPT-RESEND)0.10 per sifted bit
Live interpretationQBER Q: 6.8 %. KEY RATE r (BB84): 0.283 per sifted bit. CHSH S (DEPOLARISING NOISE): 2.44. EVE KNOWS (INTERCEPT-RESEND): 0.10 per sifted bit
Catch the common trap
Explain before calculating.
Alice and Bob run BB84 with an ideal single-photon source and estimate a QBER of 15% on their sifted key. What does the security analysis tell them to do?
Choose an answer to test the model.
Practice & worked examples
Reason from the model, then test the result.
EasyAlice sends 8000 BB84 photons over an ideal, lossless link. Eve intercepts every one, measures σz or σₓ at random and resends the eigenstate she finds. How long is the sifted key, how many errors does it contain, and how many of its bits does Eve know with certainty? Repeat for Eve intercepting only one photon in five.
- Sifting keeps the rounds where Bob's random basis matches Alice's: probability 1/2, so the sifted key has 8000 × 1/2 = 4000 bits.
- Eve's basis choice is independent of both. In half the sifted rounds, 2000, she measured Alice's own operator: she learns the bit exactly, resends the same eigenstate, and Bob reads it correctly.
- In the other 2000 she measured the wrong operator and resent one of its eigenstates, which has overlap |⟨i|j⟩|² = 1/2 with each of Alice's basis states. Bob, measuring Alice's operator, errs in half of them: 1000 errors, so Q = 1000/4000 = 25%.
- Eve knows the 2000 matched-basis bits with certainty and only guesses the rest, so IE = 1/2 per sifted bit — she holds half the key, not all of it.
- Intercepting a fraction f = 0.2 scales both: Q = f/4 = 5.0% and IE = f/2 = 0.10 per sifted bit, that is 400 of the 4000 bits known for certain.
Answer4000 sifted bits with 1000 errors (Q = 25%); Eve knows 2000 of them. At f = 0.2: Q = 5.0%, Eve knows 400 bits (IE = 0.10).
MediumA BB84 run leaves 5000 sifted bits after the test sample is removed. Find the secret-key length for a measured QBER of 4.0% with ideal error correction, then with a Cascade-type protocol that leaks c = 1.2 times the Shannon minimum, and finally decide what happens at a QBER of 12%.
- Binary entropy: h(Q) = −Q log₂Q − (1 − Q) log₂(1 − Q). At Q = 0.040: −0.040 log₂0.040 = 0.040 × 4.644 = 0.1858 and −0.960 log₂0.960 = 0.960 × 0.05889 = 0.0565, so h(0.040) = 0.2423.
- Ideal post-processing: r = 1 − 2h(Q) = 1 − 0.4846 = 0.5154 secret bits per sifted bit, so the key is 5000 × 0.5154 ≈ 2577 bits.
- Error correction leaking c h(Q) instead of h(Q): r = 1 − (1 + c)h(Q) = 1 − 2.2 × 0.2423 = 0.4670, giving 5000 × 0.4670 ≈ 2335 bits — the inefficiency costs about 240 bits.
- At Q = 0.12: −0.12 log₂0.12 = 0.12 × 3.059 = 0.3671 and −0.88 log₂0.88 = 0.88 × 0.1844 = 0.1623, so h(0.12) = 0.5294 and r = 1 − 1.0588 = −0.059.
- A negative rate means Eve's bound on the key exceeds what error correction leaves: no secret bits can be distilled and the run is aborted, although 12% is well below the 25% of full intercept-resend.
AnswerQ = 4.0%: h = 0.242, r = 0.515 → about 2577 bits (2335 bits at c = 1.2). Q = 12%: h = 0.529, r = −0.06 → abort.
HardAn E91 source is meant to emit singlets but delivers the Werner state ρ = V|Ψ⁻⟩⟨Ψ⁻| + (1 − V)I/4 with V = 0.85. Alice measures spin along a = 0° or a′ = 90°, Bob along b = 45° or b′ = 135°. Find E(a, b), the CHSH value S, the matched-basis error rate, the trusted-device key rate 1 − 2h(Q) and the device-independent rate, then the visibility below which the CHSH test itself fails.
- E(a, b) = Tr[ρ (a⋅σ ⊗ b⋅σ)]. The singlet part gives −V cos(a − b); the white-noise part gives (1 − V) Tr[a⋅σ ⊗ b⋅σ]/4 = 0 because every Pauli matrix is traceless. So E(a, b) = −0.85 cos(a − b).
- CHSH with the four settings: S = E(0°, 45°) − E(0°, 135°) + E(90°, 45°) + E(90°, 135°) = −0.85(cos 45° − cos 135° + cos 45° + cos 45°) = −0.85 × 4 × 0.7071 = −2.404, so |S| = 2.40 > 2: the test passes.
- In a matched pair of directions E = −V, and Bob flips his bit, so an error is a coincidence of equal outcomes: Q = (1 + E)/2 = (1 − V)/2 = 0.075, a 7.5% QBER.
- Trusted devices: h(0.075) = 0.075 × 3.737 + 0.925 × 0.1125 = 0.2803 + 0.1040 = 0.3843, so r = 1 − 2 × 0.3843 = 0.231 secret bits per sifted bit.
- Device-independent: S²/4 − 1 = 1.445 − 1 = 0.445 and √0.445 = 0.667, so the argument is (1 + 0.667)/2 = 0.834 and h(0.834) = 0.650. Then rDI = 1 − 0.384 − 0.650 = −0.03: no key without trusting the devices, since 7.5% exceeds the 7.1% device-independent threshold.
- The violation vanishes when 2√2 V = 2, that is V = 1/√2 = 0.707, where Q = (1 − 0.707)/2 = 14.6%. A key with trusted devices already needs Q < 11%, that is V > 0.78: a Bell violation is necessary for E91 but far from sufficient.
AnswerE = −0.85 cos(a − b); |S| = 2.40 (violation); Q = 7.5%; trusted-device rate 0.23 per sifted bit; device-independent rate −0.03 (no key); CHSH fails below V = 0.707, where Q = 14.6%.