Quantum Key Distribution (QKD) Protocols: BB84, Decoy States, and Quantum Satellite Relays Explained

Information-Theoretic Security vs Computational Hardness

In classical cryptography and even post-quantum algorithmic cryptography, security always relies on computational complexity. We assume that factoring integers, taking elliptic curve discrete logarithms, or finding short vectors in multi-dimensional lattices requires more computational operations than any supercomputer or quantum device can perform within thousands of years. However, computational hardness can never be mathematically proven to be unbreakable; an unexpected breakthrough in mathematics or quantum algorithms could shatter any mathematical cipher overnight.

Quantum Key Distribution (QKD) takes an entirely different philosophical approach. Instead of relying on mathematical complexity, QKD bases its security directly on the immutable laws of quantum mechanics. Specifically, it exploits the Heisenberg Uncertainty Principle and the Quantum No-Cloning Theorem. In a properly implemented QKD system, an eavesdropper cannot intercept or measure quantum keys without inevitably introducing detectable physical disturbances into the quantum channel.

This technical guide dissects the physical and informational architecture of QKD, analyzing the foundational BB84 protocol, decoy-state single-photon sources, fiber attenuation limits, optical quantum repeaters, and transcontinental quantum satellite networks.

The Foundations of BB84 Protocol Physics

Invented in 1984 by Charles Bennett and Gilles Brassard, the BB84 protocol remains the archetype of quantum key distribution. BB84 utilizes single photons polarized across two non-orthogonal conjugate measurement bases:

  • Rectilinear Basis ($+$): Horizontal polarization ($|0rangle$ representing bit 0) and Vertical polarization ($|1rangle$ representing bit 1).
  • Diagonal Basis ($times$): Diagonal $+45^circ$ polarization ($|+rangle = (|0rangle + |1rangle)/sqrt{2}$ representing bit 0) and Diagonal $-45^circ$ polarization ($|-rangle = (|0rangle – |1rangle)/sqrt{2}$ representing bit 1).

Because these two bases are conjugate, measuring a photon polarized in the diagonal basis using a rectilinear detector forces the quantum state to collapse randomly into either $|0rangle$ or $|1rangle$ with a 50% probability, completely destroying the original diagonal phase information.

Step-by-Step BB84 Exchange Mechanism

  1. Quantum State Preparation: Alice generates a random stream of classical bits. For each bit, she randomly chooses either the Rectilinear ($+$) or Diagonal ($times$) basis and polarizes a single photon accordingly.
  2. Quantum Transmission: Alice transmits the stream of polarized single photons over an optical channel (single-mode fiber or free-space optical link) to Bob.
  3. Random Measurement: Bob receives each incoming photon and independently chooses a random basis ($+$ or $times$) to measure it, recording his measurement outcomes.
  4. Public Basis Sifting: Over an authenticated classical channel, Alice and Bob openly declare which basis they used for each photon, without revealing the actual bit values. They retain only the bits where their basis choices matched (approximately 50% of the transmitted photons). This retained bit sequence is called the “Sifted Key”.
  5. Error Rate Estimation and Eavesdropper Detection: Alice and Bob publicly compare a small random subset of their sifted key bits to compute the Quantum Bit Error Rate (QBER). If an eavesdropper (Eve) intercepted and measured photons in transit, quantum wave function collapse will have introduced errors into Bob’s measurements. If QBER exceeds a theoretical threshold (typically ~11%), they abort the session immediately.
  6. Error Correction and Privacy Amplification: If QBER is below the threshold, Alice and Bob apply classical error correction (Cascade or LDPC codes) to reconcile discrepancies, followed by universal hashing (Privacy Amplification) to shrink the key and compress Eve’s potential information leakage to strictly zero. The resulting string is used as a One-Time Pad (OTP) key for provably unbreakable symmetric encryption.

Continuous-Variable QKD (CV-QKD) vs Discrete-Variable QKD (DV-QKD)

While the standard BB84 protocol belongs to the Discrete-Variable QKD (DV-QKD) family (counting individual single photons with avalanche diodes), a parallel technological branch known as Continuous-Variable QKD (CV-QKD) has matured significantly. CV-QKD modulates the continuous quadratures (amplitude and phase) of coherent laser pulses using standard telecom telecommunications equipment, measuring them with balanced homodyne and heterodyne detectors.

CV-QKD offers major commercial advantages because it does not require cryogenically cooled single-photon detectors. Furthermore, CV-QKD can coexist alongside high-power classical DWDM channels within the same optical fiber strand using standard optical bandpass filtering, significantly reducing dark-fiber leasing costs for enterprise banking links.

The Photon Number Splitting (PNS) Attack and Decoy-State Innovation

Theoretical BB84 assumes an idealized single-photon source that emits exactly one photon per pulse. In physical laboratory and commercial systems, true single-photon emitters are exceptionally difficult to manufacture. Commercial QKD transmitters instead use attenuated semiconductor laser diodes, which produce weak coherent pulses (WCP) governed by a Poisson distribution:

P(n) = (mu^n * e^(-mu)) / n!

Where $mu$ is the mean photon number per pulse (typically $mu approx 0.1$). Because of Poisson statistics, a small percentage of laser pulses inevitably contain two or more photons. This allows an eavesdropper to launch a devastating attack known as the Photon Number Splitting (PNS) attack:

Mechanism of PNS Attack

Eve sits on the optical fiber span. Whenever a multi-photon pulse passes by, she non-destructively splits off one photon and stores it in a quantum memory loop, allowing the remaining photon to continue unharmed to Bob. During classical basis announcement, Eve retrieves her stored photon and measures it in the correct basis. In this manner, Eve acquires the entire encryption key without introducing a single quantum error into the channel.

The Decoy-State Countermeasure

In 2003-2005, researchers introduced the Decoy-State protocol (standardized in ITU-T Y.3800). Alice intentionally and randomly interleaves weak signal pulses with “decoy pulses” of differing average intensities (e.g., signal $mu = 0.5$, decoy $nu = 0.1$, and vacuum pulses $omega = 0$). By comparing the photon detection yield and error rates across these differing intensity states at Bob’s receiver, Alice and Bob can mathematically verify whether multi-photon pulses are being selectively attacked, completely neutralizing the PNS threat.

Physical Reach Barriers: Optical Attenuation and Quantum Repeaters

In classical optical telecommunications, EDFAs and optical amplifiers boost degraded light every 80 kilometers. In quantum communication, optical amplifiers cannot be used because the No-Cloning Theorem strictly prohibits copying an unknown quantum state. Therefore, single-photon attenuation in silica fiber (0.2 dB/km) imposes a severe physical distance barrier.

Fiber Distance (km) Optical Attenuation (dB) Photon Transmission Probability Secure Key Rate (BB84 Decoy)
20 km 4 dB ~40% ~1.2 Mbps
50 km 10 dB ~10% ~120 kbps
100 km 20 dB ~1% ~15 kbps
200 km 40 dB ~0.01% ~150 bps
400 km 80 dB ~10^-8 Practical limit for direct terrestrial fiber

To bridge distances exceeding 100-200km, today’s commercial QKD deployments use “Trusted Node” relays. In a trusted node network, keys are decrypted and re-encrypted at intermediate hardened physical facilities. While practical, trusted nodes compromise end-to-end security because any compromised intermediate node compromises the entire key. True end-to-end quantum repeaters using quantum teleportation, atomic spin quantum memories, and entanglement purification remain an active area of global experimental physics.

Satellite QKD: Space-to-Ground Quantum Channels

To establish secure keys across thousands of kilometers without trusted terrestrial repeaters, quantum physicists turned to outer space. In low Earth orbit (500km altitude), vacuum space has virtually zero optical attenuation, and atmospheric absorption only affects the final 10 kilometers of transit near the ground station.

China pioneered this frontier in 2016 with the launch of the Micius quantum satellite. Using high-precision telescope tracking systems, Micius established entangled photon links between ground stations separated by 1,200 kilometers across the Tibetan plateau and achieved intercontinental QKD key exchanges between Beijing and Vienna. Modern satellite constellations are now being designed with LEO quantum payloads to provide daily global QKD key distribution to national banking hubs and critical defense nodes.

Architectural Comparison: QKD vs Post-Quantum Cryptography (PQC)

Network architects frequently ask whether QKD renders PQC obsolete, or vice versa:

Architectural Comparison Matrix:
---------------------------------------------------------------------
Parameter               Quantum Key Distribution (QKD)   Post-Quantum Cryptography (PQC)
---------------------------------------------------------------------
Security Foundation     Physical Laws of Quantum Physics Computational Lattice Hardness
Hardware Requirement   Dedicated Dark Fiber, Detectors, Lasers Standard Commodity Servers
Authentication Vector   Requires Pre-Shared Auth Keys    Inherent Digital Signatures
Physical Reach          Limited (100km terrestrial fiber) Infinite (Works over regular Internet)
Deployment Cost         Extremely High ($50k-$200k/link) Zero Hardware Cost (Software update)
Applicability           Point-to-point backbone links    Universal (Web, Mobile, Email, IoT)
---------------------------------------------------------------------

The Synthesis: Defense-in-Depth Cryptography

QKD and PQC are not mutually exclusive adversaries; they are complementary layers of high-assurance security architectures. Forward-looking financial clearinghouses and governmental networks deploy PQC algorithms (such as ML-KEM and ML-DSA) at the application and transport layers across public internet infrastructure, while utilizing QKD and One-Time Pad encryption across mission-critical point-to-point metropolitan dark fiber links. This defense-in-depth model ensures that neither a mathematical breakthrough nor a hardware quantum computer can compromise the crown jewels of enterprise data.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top