Quantum key distribution
| English | Português |
|---|---|
| quantum cryptography/ˈkwɒntəm krɪpˈtɒɡrəfi/ | quantum cryptography |
| quantum key distribution/ˈkwɒntəm kiː ˌdɪstrɪˈbjuːʃn/ | quantum key distribution |
| photon/ˈfəʊtɒn/ | photon |
| authenticated/ɔːˈθentɪkeɪtɪd/ | authenticated |
A key that cannot be photocopied quietly
- A shop can send an encrypted file over an ordinary network, but first it must share a secret key. Making the key longer does not explain how the two sides obtain it safely.
- Quantum cryptography 量子密码学 includes quantum key distribution 量子密钥分发 (QKD): sharing key material using quantum states. The key exchange and the encrypted file are two separate jobs.
What is the main job of QKD?
QKD shares key material; an encryption scheme uses a key to protect the message.
Photons carry the key material
- A sender encodes random bits in quantum states of photons 光子. The receiver measures the incoming photons. In a simple protocol, the two sides use different measurement choices and later keep results from compatible choices.
- Measuring an unknown quantum state can disturb it; an attacker cannot make a perfect copy of an arbitrary unknown state. Interception can therefore leave a statistical error signal in the retained results.
An attacker can always copy an arbitrary unknown quantum state perfectly and leave it unchanged.
An unknown state cannot be perfectly cloned; interception can affect measured results.
A sample test, not a detector on every photon
- The two sides compare a sample of retained bits over an authenticated channel: they must know who is speaking. They do not publish the whole secret key; revealed sample bits are discarded.
- Too many errors mean aborting the exchange and discarding the proposed key. Errors may come from interception or equipment noise, so an error does not identify an attacker. Accepted results still need error correction and privacy processing.
Order this simplified QKD exchange.
A sample is revealed for testing, so those tested bits cannot remain part of the secret key.
Worked example: reject a noisy exchange
- A simplified classroom test compares 40 sample bits. Six differ. Calculate the sample error rate: $r = \dfrac{6}{40}\times100 = 15\%$. Suppose this exercise's stated acceptance limit is 10%; the exchange is rejected.
- Discard the candidate key and investigate or retry. Do not use the revealed sample bits in a secret key, and do not conclude that six errors prove six bits were stolen. The 10% limit is an exercise assumption, not a universal QKD threshold.
Six of 40 sample bits differ. What percentage differ?
Error rate = 6 / 40 × 100 = 15%.
The sample error rate is 15%; the exercise acceptance limit is 10%. What should the parties do?
15% exceeds the stated limit. Discard the candidate key; the result does not prove who caused the errors.
The benefit follows from the mechanism
- In an ideal protocol, the key's secrecy is supported by quantum physics rather than only the difficulty of a mathematical problem. Attempts to measure the transmitted states can affect the test results.
- This helps with key distribution. It does not protect a stolen endpoint, authenticate the other party on its own, or make every practical implementation immune to attack.
Why ordinary networks still need ordinary encryption
- Practical QKD needs special equipment and a suitable quantum link, such as optical fibre or a free-space path. Loss, distance and key-generation rate constrain deployment; ordinary routers cannot simply copy and forward arbitrary quantum states.
- The agreed key is then used by an encryption scheme to protect the actual data on an ordinary channel. QKD supplies key material, not a new way of emailing a whole document as photons.
Which constraints remain with practical QKD? Select all that apply.
QKD does not by itself provide identity assurance or secure endpoints, and it needs suitable equipment and links.
Marks that slip away
- Explain a benefit through its cause: unknown states cannot be perfectly copied, and interception can introduce detectable errors. Avoid “every attack is instantly detected” or “the whole system is unhackable”.
- Explain a drawback through its effect: specialised links and equipment increase cost and limit where the method can be deployed. Authentication and secure endpoints are still necessary.
Choose the right job for each tool
- QKD shares key material; ordinary encryption protects the message with a key. A sample error test can cause the exchange to be rejected, and tested bits are not kept secret.
- A complete answer gives the purpose, the physical reason interception can be noticed, a benefit and a practical limit. It also keeps identity checks separate from key distribution.
Further reading: QKD in an authenticated key-exchange framework and · e practical deployment limitations. Sources checked 2 October 2026; this lesson is original classroom material.
Match the job to the mechanism.
Key distribution, data encryption and authentication serve different jobs.