1 Decoy State Quantum Key Distribution (QKD) Hoi-Kwong Lo Center for Quantum Information and Quantum Control Dept. of Electrical & Comp. Engineering (ECE);

Slides:



Advertisements
Similar presentations
Numbers Treasure Hunt Following each question, click on the answer. If correct, the next page will load with a graphic first – these can be used to check.
Advertisements

© 2008 Pearson Addison Wesley. All rights reserved Chapter Seven Costs.
Copyright © 2003 Pearson Education, Inc. Slide 1 Computer Systems Organization & Architecture Chapters 8-12 John D. Carpinelli.
Chapter 1 The Study of Body Function Image PowerPoint
Milan Vojnović Microsoft Research Cambridge Collaborators: E. Perron and D. Vasudevan 1 Consensus – with Limited Processing and Signalling.
1 Copyright © 2013 Elsevier Inc. All rights reserved. Chapter 1 Embedded Computing.
Copyright © 2011, Elsevier Inc. All rights reserved. Chapter 6 Author: Julia Richards and R. Scott Hawley.
Author: Julia Richards and R. Scott Hawley
1 Copyright © 2013 Elsevier Inc. All rights reserved. Appendix 01.
STATISTICS HYPOTHESES TEST (III) Nonparametric Goodness-of-fit (GOF) tests Professor Ke-Sheng Cheng Department of Bioenvironmental Systems Engineering.
Properties Use, share, or modify this drill on mathematic properties. There is too much material for a single class, so you’ll have to select for your.
UNITED NATIONS Shipment Details Report – January 2006.
Quantum Cryptography Post Tenebras Lux!
Jeopardy Q 1 Q 6 Q 11 Q 16 Q 21 Q 2 Q 7 Q 12 Q 17 Q 22 Q 3 Q 8 Q 13
Jeopardy Q 1 Q 6 Q 11 Q 16 Q 21 Q 2 Q 7 Q 12 Q 17 Q 22 Q 3 Q 8 Q 13
Properties of Real Numbers CommutativeAssociativeDistributive Identity + × Inverse + ×
FACTORING ax2 + bx + c Think “unfoil” Work down, Show all steps.
Year 6 mental test 5 second questions
1 Discreteness and the Welfare Cost of Labour Supply Tax Distortions Keshab Bhattarai University of Hull and John Whalley Universities of Warwick and Western.
Quantum Cryptography Nick Papanikolaou Third Year CSE Student
Chapter 7 Sampling and Sampling Distributions
Evaluating Window Joins over Unbounded Streams Author: Jaewoo Kang, Jeffrey F. Naughton, Stratis D. Viglas University of Wisconsin-Madison CS Dept. Presenter:
Vote Elicitation with Probabilistic Preference Models: Empirical Estimation and Cost Tradeoffs Tyler Lu and Craig Boutilier University of Toronto.
Solve Multi-step Equations
REVIEW: Arthropod ID. 1. Name the subphylum. 2. Name the subphylum. 3. Name the order.
Short seed extractors against quantum storage Amnon Ta-Shma Tel-Aviv University 1.
The Weighted Proportional Resource Allocation Milan Vojnović Microsoft Research Joint work with Thành Nguyen Microsoft Research Asia, Beijing, April, 2011.
EU market situation for eggs and poultry Management Committee 20 October 2011.
Hash Tables.
5-1 Chapter 5 Theory & Problems of Probability & Statistics Murray R. Spiegel Sampling Theory.
Bellwork Do the following problem on a ½ sheet of paper and turn in.
2 |SharePoint Saturday New York City
IP Multicast Information management 2 Groep T Leuven – Information department 2/14 Agenda •Why IP Multicast ? •Multicast fundamentals •Intradomain.
VOORBLAD.
Factor P 16 8(8-5ab) 4(d² + 4) 3rs(2r – s) 15cd(1 + 2cd) 8(4a² + 3b²)
Basel-ICU-Journal Challenge18/20/ Basel-ICU-Journal Challenge8/20/2014.
1..
© 2012 National Heart Foundation of Australia. Slide 2.
LO: Count up to 100 objects by grouping them and counting in 5s 10s and 2s. Mrs Criddle: Westfield Middle School.
Understanding Generalist Practice, 5e, Kirst-Ashman/Hull
Model and Relationships 6 M 1 M M M M M M M M M M M M M M M M
25 seconds left…...
1 Using one or more of your senses to gather information.
Subtraction: Adding UP
Analyzing Genes and Genomes
1 Let’s Recapitulate. 2 Regular Languages DFAs NFAs Regular Expressions Regular Grammars.
©Brooks/Cole, 2001 Chapter 12 Derived Types-- Enumerated, Structure and Union.
Essential Cell Biology
Intracellular Compartments and Transport
PSSA Preparation.
Essential Cell Biology
1 Chapter 13 Nuclear Magnetic Resonance Spectroscopy.
Energy Generation in Mitochondria and Chlorplasts
User Security for e-Post Applications Dr Chandana Gamage University of Moratuwa.
Implementation of Practically Secure Quantum Bit Commitment Protocol Ariel Danan School of Physics Tel Aviv University September 2008.
1 Decoy State Quantum Key Distribution (QKD) Hoi-Kwong Lo Center for Quantum Information and Quantum Control Dept. of Electrical & Comp. Engineering (ECE);
Quantum Cryptography Ranveer Raaj Joyseeree & Andreas Fognini Alice Bob Eve.
Paraty, Quantum Information School, August 2007 Antonio Acín ICFO-Institut de Ciències Fotòniques (Barcelona) Quantum Cryptography (III)
Security of practical quantum cryptography with heralded single photon sources Mikołaj Lasota 1, Rafał Demkowicz-Dobrzański 2, Konrad Banaszek 2 1 Nicolaus.
1 A Randomized Space-Time Transmission Scheme for Secret-Key Agreement Xiaohua (Edward) Li 1, Mo Chen 1 and E. Paul Ratazzi 2 1 Department of Electrical.
IIS 2004, CroatiaSeptember 22, 2004 Quantum Cryptography and Security of Information Systems 1 2
Trondheim 2002 NTNU Quantum Cryptography FoU NTNU Vadim Makarov and Dag R. Hjelme Institutt for fysikalsk elektronikk NTNU Norsk kryptoseminar,
Quantum Key Distribution Chances and Restrictions Norbert Lütkenhaus Emmy Noether Research Group Institut für Theoretische Physik I Universität Erlangen-Nürnberg.
Introduction to Quantum Key Distribution
CS555Topic 251 Cryptography CS 555 Topic 25: Quantum Crpytography.
1 Security of Quantum Key Distribution with Imperfect Devices Hoi-Kwong Lo Dept. of Electrical & Comp. Engineering (ECE); & Dept. of Physics University.
1 Conference key-agreement and secret sharing through noisy GHZ states Kai Chen and Hoi-Kwong Lo Center for Quantum Information and Quantum Control, Dept.
Quantum Cryptography Antonio Acín
Presentation transcript:

1 Decoy State Quantum Key Distribution (QKD) Hoi-Kwong Lo Center for Quantum Information and Quantum Control Dept. of Electrical & Comp. Engineering (ECE); & Dept. of Physics University of Toronto Joint work with: Xiongfeng Ma Kai Chen [Paper in preparation] Supported by CFI, CIPI, CRC program, NSERC, OIT, and PREA.

2 Outline 1.Motivation and Introduction 2.Problem 3.Our Solution and its significance

3 1.Motivation and Introduction

4 Commercial Quantum Crypto products available on the market Today! Distance over 100 km of commercial Telecom fibers. MAGIQ TECH. ID QUANTIQUE

5 Bad News (for theorists) Theory of quantum key distribution (QKD) is behind experiments. Opportunity: By developing theory, one can bridge gap between theory and practice.

6 Theory and Experiment go hand in hand.

7 To do so, they need to share a common random string of number----key Key Distribution Problem AliceBob Eve Alice and Bob would like to communicate in absolute security in the presence of an eavesdropper, Eve.

8 Bennett and Brassard’s scheme (BB84) ASSSUMPTIONS: 1.Source: Emits perfect single photons. (No multi-photons) 2.Channel: noisy but lossless. (No absorption in channel) 3.Detectors: a) Perfect detection efficiency. (100 %) 4.Basis Alignment: Perfect. (Angle between X and Z basis is exactly 45 degrees.) Alice Bob Conclusion: QKD is secure in theory. Assumptions lead to security proofs: Mayers (BB84), Lo and Chau (quantum-computing protocol), Biham et al. (BB84), Ben-Or (BB84), Shor-Preskill (BB84), …

9 Reminder: Quantum No-cloning Theorem An unknown quantum state CANNOT be cloned. Therefore, eavesdropper, Eve, cannot have the same information as Bob. Single-photon signals are secure. aaa IMPOSSIBLE

10 Photon-number splitting attack against multi-photons A multi-photon signal CAN be split. (Therefore, insecure.) a a Bob Eve Splitting attack a a Alice Summary: Single-photon good. Multi-photon bad.

11 QKD : Practice Question: Is QKD secure in practice? 2.Channel: Absorption inevitable. (e.g. 0.2 dB/km) 3.Detectors: (a) Efficiency ~15% for Telecom wavelengths (b) “Dark counts”: Detector’s erroneous fire. Detectors will claim to have detected signals with some probability even when the input is a vacuum. 4. Basis Alignment: Minor misalignment inevitable. Reality: 1. Source: (Poisson photon number distribution) Mixture. Photon number = k with probability: Some signals are, in fact, double photons!

12 Prior art on BB84 with imperfect devices 1.Inamori, Lutkenhaus, Mayers (ILM) 2.Gottesman, Lo, Lutkenhaus, Preskill (GLLP) GLLP: Under (semi-) realistic assumptions, if imperfections are sufficiently small, then BB84 is secure. Question: Can we go beyond these results

13 2.Problem

14 Big Problem: Nice guys come last Alice: Problems: 1) Multi-photon signals (bad guys) can be split. 2) Eve may suppress single-photon signals (Good guys). Bob: Eve: Signature of this attack: Multi-photons are much more likely to reach Bob than single-photons. (Nice guys come last). Eve may disguise herself as absorption in channel. QKD becomes INSECURE as Eve has whatever Bob has.

15 Yield as a function of photon number Bob: Eve: Let us define Y n = yield = conditional probability that a signal will be detected by Bob, given that it is emitted by Alice as an n-photon state. For example, with photon number splitting attack: Y 2 = 1 : all two-photon states are detected by Bob. Y 1 = 0 : all single-photon states are lost.

16 Figures of merits in QKD # of Secure bits per signal (emitted by Alice). How long is the final key that Alice and Bob can generate? (Maximal) distance of secure QKD. How far apart can Alice and Bob be from each other?

17 Prior Art Result Consider the worst case scenario where all signals received by Bob are bad guys. (Insecure.) Consider channel transmittance η. For security, we use weak Poisson photon number distribution: μ = O (η). To prevent this from happening, we need: # of signals received by Bob > # of multi-photon signals emitted by Alice. Secure bits per signal S = O (η 2 ).

18 Big Gap between theory and practice of BB84 Theory Experiment Key generation rate: S = O (η 2 ). S= O (η). Maximal distance: d ~ 35km. d >120km. Prior art solutions (All bad): 1)Use Ad hoc security: Defeat main advantage of Q. Crypto. : unconditional security. (Theorists unhappy .) 2)Limit experimental parameters: Substantially reduce performance. (Experimentalists unhappy .) 3)Better experimental equipment (e.g. Single-photon source. Low- loss fibers. Photon-number-resolving detectors): Daunting experimental challenges. Impractical in near-future. (Engineers unhappy .) Question: How can we make everyone happy ?

19 (Recall) Problem: Photon number splitting attack Bob: Eve: Let us define Y n = yield = conditional probability that a signal will be detected by Bob, given that it is emitted by Alice as an n-photon state. For example, with photon number splitting attack: Y 2 = 1 : all two-photon states are detected by Bob. Y 1 = 0 : all single-photon states are lost. Yield for multi-photons may be much higher than single-photons. Is there any way to detect this?

20 A solution: Decoy State (Toy Model) Goal: Design a method to test experimentally the yield (i.e. transmittance) of multi-photons. Alice sends N two-photon signals to Bob. Alice and Bob estimate the yield Y 2 = x/N. If Eve selectively sends multi-photons, Y 2 will be abnormally large. Eve will be caught! Alice: N signals Bob: x signals Method: Use two-photon states as decoys and test their yield.

21 Procedure of Decoy State QKD (Toy Model). A) Signal state: Poisson photon number distribution α (at Alice). B) Decoy state: = two-photon signals 1) Alice randomly sends either a signal state or decoy state to Bob. 2) Bob acknowledges receipt of signals. 3) Alice publicly announces which are signal states and which are decoy states. 4) Alice and Bob compute the transmission probability for the signal states and for the decoy states respectively. If Eve selectively transmits two-photons, an abnormally high fraction of the decoy state B) will be received by Bob. Eve will be caught.

22 Practical problem with toy model Problem: Making perfect two-photon states is hard, in practice Solution: Make another mixture of good and bad guys with a different weight.

23 1)Signal state: Poisson photon number distribution: α (at Alice). Mixture 1. 2) Decoy state: Poisson photon number distribution: μ~ 2 (at Alice). Mixture 2 Decoy state idea (Heuristic) W.-Y. Hwang’s heuristic idea (PRL): If Eve lets an abnormally high fraction of multi-photons go to Bob, then decoy states (which has high weight of multi- photons) will have an abnormally high transmission probability. Therefore, Alice and Bob can catch Eve!

24 Can we make things rigorous? YES!

25 3.Our solution:

26 Experimental observation Yield: Error Rate If Eve cannot treat the decoy state any differently from a signal state Y n (signal)=Y n (decoy), e n (signal)=e n (decoy) Y n : yield of an n-photon signal e n : quantum bit error rate (QBER) of an n-photon signal.

27 Idea We propose that Alice switches power of her laser up and down, thus producing as decoy states Poisson photon number distributions, μ’s for all possible values of μ’s. Each μ gives Poisson photon number distribution: Try every Poisson distribution μ!

28 1.Making things rigorous (Combine with entanglement distillation approach in Shor-Preskill’s proof.) 2.Constraining dark counts (Detectors may claim to have registered events even when the input is a vacuum. These dark counts are often the limiting factor to the distance of secure QKD. Using vacuum as a decoy state to constrain the “dark count” rate.) 3.Constructing a general theory (Infering all Y n, e n.) Conclusion: We severely limit Eve’s eavesdropping strategies. Any attempt by Eve to change any of Y n, e n ‘s will, in principle be caught. Our Contributions

29 Old Picture Theory Experiment Secure bits per signal: S = O (η 2 ). S= O (η). Maximal distance: d ~ 35km. d >120km. There is a big gap between theory and practice of BB84.

30 NEW Picture Theory Experiment Secure bits per signal: S = O (η). S= O (η). Maximal distance: d >120 km. d >120km. Even with imperfect devices, one gets highest performance possible without compromising security.

31 Compare the results with and without decoy states The experiment data for the simulation come from the recent paper: C. Gobby, Z. L. Yuan, and A. J. Shields, Applied Physics Letters, (2004) Key parameter: Wavelength: 1550nm Channel loss: 0.21dB/km Signal error rate: 3.3% Dark count: 8.5*10 -7 per pulse Receiver loss and detection efficiency: 4.5%

32 Related Work Using another approach (strong reference pulse), another protocol (essentially B92) has recently been proven to be secure with R=O(η). [Koashi, quant-ph/ ] In future, it will be interesting to compare this approach with ours.

33 Summary 1.Decoy state BB84 allows: Secure bits per signal: O (η) where η : channel transmittance. Distance > 100km 2.Easy to implement. Alice just switches power of laser up and down (and measure transmittance and error rate). 3. Theory and experiment go hand-in-hand for standard BB84 quantum key distribution protocol.

34 THE END