Entangled State Quantum Cryptography: Eavesdropping On The Ekert Protocol

You might also like

Download as pdf or txt
Download as pdf or txt
You are on page 1of 4

Entangled state quantum cryptography: Eavesdropping on the Ekert protocol

D. S. Naik1 , C. G. Peterson1, A. G. White1,2 , A. J. Berglund1 , and P. G. Kwiat1∗


1
Physics Division, P-23, Los Alamos National Laboratory, Los Alamos, New Mexico 87545, USA
2
Department of Physics, University of Queensland, Brisbane, Queensland 4072, AUSTRALIA
(Submitted to Phys. Rev. Lett, Oct. 17, 1999; resubmitted 12/22/99)
Using polarization-entangled photons from spontaneous parametric downconversion, we have imple-
mented Ekert’s quantum cryptography protocol. The near-perfect correlations of the photons allow
the sharing of a secret key between two parties. The presence of an eavesdropper is continually
checked by measuring Bell’s inequalities. We investigated several possible eavesdropper strategies,
including pseudo-quantum non-demolition measurements. In all cases, the eavesdropper’s presence
was readily apparent. We discuss a procedure to increase her detectability.
arXiv:quant-ph/9912105v1 23 Dec 1999

PACS numbers: 03.67.Dd, 03.65.-a, 42.79.Sz, 03.65.Bz

The emerging field of quantum information science protocol have been reported in the literature [17]. It is
aims to use the nonclassical features of quantum systems now well established that one cannot employ these non-
to achieve performance in communications and compu- local correlations for superluminal signaling [18]. Never-
tation that is superior to that achievable with systems theless, Ekert showed that one can use the correlations
based solely on classical physics. For example, current to establish a secret random key between two parties, as
methods of public-key cryptography base their security part of a completely secure cryptography protocol [3].
on the supposed (but unproven) computational difficulty In our version of the Ekert protocol, “Alice” and “Bob”
in solving certain problems, e.g., finding the prime fac- each receive one photon of a polarization-entangled
√ pair
tors of large numbers – these problems have not only in the state |φ+ i = (|H1 H2 i + |V1 V2 i)/ 2, where H (V )
been unproven to be difficult, but actually been shown represents horizontal (vertical) polarization. They each
to be computational “easy” in the context of quantum respectively measure the polarization of their photons in
computation [1]. In contrast, it is now generally accepted the bases (|H1 i + eiα |V1 i) and (|H2 i + eiβ |V2 i), where
that techniques of quantum cryptography can allow com- α and β randomly take on the values α1 = 45◦ , α2 =
pletely secure communications between distant parties 90◦ , α3 = 135◦, α4 = 180◦ ; β1 = 0◦ , β2 = 45◦ , β3 = 90◦ , β4 =
[2–5]. Specifically, by using single photons to distribute a 135◦. They then disclose by public discussion which bases
secret random cryptographic key, one can ensure that no were used, but not the measurement results. For the state
eavesdropping goes unnoticed; more precisely, one can set |φ+ i, the probabilities for a coincidence between Alice’s
rigid upper bounds on the possible information known to detector 1 (or detector 1’, which detects the orthogonally-
a potential eavesdropper, based on measured error rates, polarized photons) and Bob’s detector 2 (2’) are given by
and use appropriate methods of “privacy amplification”
to reduce this information to an acceptable level [6]. P12 (α, β) = P1′ 2′ (α, β) = (1 + cos(α + β))/4 (1)
Since its discovery, quantum cryptography has been P12′ (α, β) = P1′ 2 (α, β) = (1 − cos(α + β))/4 .
demonstrated by a number of groups using weak coherent
states, both in fiber-based systems [7] and in free space Note that when α + β = 180◦ , they will have completely
arrangements [8,9]. These experiments are provably se- correlated results, which then constitute the quantum
cure against all eavesdropping attacks based on presently cryptographic key. As indicated in Table I, the results
available technology; however, there are certain conceiv- from other combinations are revealed and used in two in-
able attacks to which they are vulnerable, as sometimes dependent tests of Bell’s inequalities, to check the pres-
the pulses used necessarily contain more than one pho- ence of an intermediate eavesdropper (“Eve”). Here we
ton – an eavesdropper could in principle use these events present an experimental realization of this protocol, and
to gain information about the key without introducing look at the effect of various eavesdropping strategies.
any extra errors [10]. Use of true single-photon sources
can close this potential security loophole; and while the TABLE I. Distribution of data dependent on Alice’s and
loophole still exists when using pairs of photons as from Bob’s respective phase settings αi and βi (see text for details).
parametric down-conversion (because occasionally there
will be double pairs), it has been shown that they may Alice
allow secure transmissions over longer distances [11]. α1 α2 α3 α4
While a number of groups use correlated photon pairs β1 S – S QKey
to study nonlocal correlations (via tests of Bell’s inequal- Bob β2 – S′ QKey S′
ities [12–14]), and their possible application for quantum β3 S QKey S –
cryptography [15,16], to our knowledge no results explic- β4 QKey S′ – S′
itly using entangled photons in a quantum cryptographic

1
problem by keeping only the first event in any given win-
RANDOM ALICE 1Õ
HWP PBS
dow. Assuming that Alice and Bob each have completely
a1,a2,a3,a4
1 isolated measurement systems (i.e., there is no way for
Ar+ LC an eavesdropper to learn about the measurement param-
laser PBS
eters α and β by sending in extra photons of her own),
BBO this system is secure even though no rapid switching is
EVE LC 2
HWP employed, since only ∼1 photon pair event is used for
b1,b2,b3,b4 2Õ any particular α-β setting [21]. Given the 22ms cycle
RANDOM BOB period determined by the liquid crystals [22], the maxi-
mum rate of data collection in our system is 45.4Hz. The
FIG. 1. Schematic of quantum cryptography system. usable rate is slightly less, because the LC voltages were
351.1nm light from an Argon ion laser is used to pump two occasionally in transition when the digitizer read them,
perpendicularly-oriented nonlinear optical crystals (BBO). yielding an ambiguous determination of the actual phase
The resultant entangled photons are sent to Alice and Bob,
setting. Typically we collected 40 useful pairs per second.
who each analyze them in one of four randomly chosen bases.
The eavesdropper, if present, was incorporated using either a
As seen in Table I, only 1/4 of the data actually con-
polarizer or a decohering birefringent plate (both orientable, tributes to the raw cryptographic key; half the data are
and in some cases with additional wave plates to allow anal- used to test Bell’s inequalities; and 1/4 are not used at
ysis in arbitrary elliptical polarization bases [Fig. 2a,c]). all [23]. In four independent runs of ∼10 minutes each,
we obtained a total of 24252 secret key bits (see Table
II), corresponding to a raw bit rate of 10.1s−1 ; the corre-
We prepare the polarization-entangled state using the sponding bit error rate (BER) was 3.06 ± 0.11% [24]. If
process of spontaneous parametric down-conversion in a we attribute this BER (conservatively estimated as 3.4%)
nonlinear crystal [14]. In brief, two identically-cut ad- entirely to an eavesdropper, we should assume she has
jacent crystals (beta-barium-borate, BBO) are oriented
p
knowledge of up to 0.7% + (4/ (2) ∗ 3.4% = 10.3%
with their optic axes in planes perpendicular to each (∼2500 bits) of the key, where the 0.7% comes from pos-
other (Fig. 1). A 45◦ -polarized pump photon is then sible double-pair events [21], and the second term as-
equally likely to convert in either crystal. Given the co- sumes an intercept-resend strategy (see [8]). We must
herence and high spatial overlap (for our 0.6mm-thick then perform sufficient privacy amplification to reduce
crystals) between these two processes, the photon pairs this to an acceptable level. After running an error detec-
are then created in the maximally-entangled state |φ+ i. tion procedure on our raw key material, 17452 error-free
Alice’s and Bob’s analysis systems each consist of a ran- bits remained. Using appropriate privacy amplification
domly driven liquid crystal [LC] (to set the applied phase techniques [6], this was further compressed to 12215 use-
shift), a half wave plate [HWP] (with optic axis at 22.5◦ ), ful secret bits (a net bit rate of 5.1s−1 ); the residual in-
and a calcite Glan-Thompson prism [PBS]. Photons from formation available to any potential eavesdropper is then
the horizontal and vertical polarization outputs of each 2−(17452−12215−2500) / ln 2, i.e., ≪ 1 bit [8].
prism are detected (after narrow-band interference fil- In contrast to nearly all tests of Bell’s inequalities
ters) using silicon avalanche photodiodes (EG&G SPCM- previously reported, instead of using linear polarization
AQ’s, efficiency ∼ 60%, dark count < 400s−1). The cor- analyses (i.e., in the equatorial plane of the Poincaré
related detector signals are synchronized and temporally sphere), we used elliptical polarization analysis (i.e., on
discriminated through AND gates. Because of the narrow the plane containing the circularly polarized poles of the
gate window (5 ns), the rate of accidental coincidences sphere and the ±45◦ linearly polarized states). In par-
(resulting from multiple pairs or background counts) is ticular, we measured the Bell parameters [25]:
only 10−5 s−1 . From separate computers, Alice and Bob
control their respective LC’s with synchronously clocked S = −E(α1 , β1 ) + E(α1 , β3 ) + E(α3 , β1 ) + E(α3 , β3 ) (2)
arbitrary waveform generator cards [19]. A coincident S ′ = E(α2 , β2 ) + E(α2 , β4 ) + E(α4 , β2 ) − E(α4 , β4 ) ,
event triggers a digitizer, which records the LC states,
and the outputs from each of the four detector pairs [20]. where E(α,β) = R 12 (α,β)+R1′ 2′ (α,β)−R12′ (α,β)−R1′ 2 (α,β)
R12 (α,β)+R1′ 2′ (α,β)+R12′ (α,β)+R1′ 2 (α,β) , and
Because the total rate of coincidences between Alice’s the R’s are the various coincidence counts between Al-
and Bob’s detectors was typically 5000 s−1 , the proba- ice’s and Bob’s detectors. For any local realistic theory
bility of having at least one pair of photons during the |S|,|S ′ | ≤ 2, while for the combinations of α and β indi-
collection time window of 1 ms was 99%. Of course, cated in Table 1, the
there was then also a high probability of more than one √quantum mechanically expected val-
ues of |S|,|S ′ | are 2 2. In a typical 10 minute run of our
pair being detected within the window (96%). Because system, we observed S=−2.67±0.04 and S ′ =−2.65±0.04;
the phase setting remains unchanged during a collection for the 40 minutes of collected data, our combined val-
window, muliple pairs could conceivably give extra in- ues were S=−2.665 ± 0.019, S ′ =−2.644 ± 0.019, each a
formation to a potential eavesdropper. We avoided this 34-σ violation of Bell’s inequality. It is expected (and

2
demonstrated experimentally; see below) that the pres- a. L 50

ence of an eavesdropper will reduce the observed values 2.5 no eavesdropper


40

of |S|,|S ′ |. In fact, if the eavesdropper√measures one pho- 2.0


H
45û

BER (%)
30
ton from every pair, then |Seve | ≤ 2 [3]. Because we

|S|
1.5

observed high values of |S|,|S ′ |, in our system the pres- 1.0


20

ence of an eavesdropper could thus be detected in ∼1s 0.5


no eavesdropper
10

of data collection
√ (the time interval for which our |S|,|S ′ | 0.0

0û 30û 60û 90û 120û 150û 0û


180û 0û 30û 60û 90û 120û 150û 180û
0

exceed 2 by 2σ). Of course one could similarly use EveÕs basis angle, f
the BER as a check for a potential eavesdropper, who b. 50

introduces a minimum BER of 25% if she measures ev- 2.5 no eavesdropper


H V 40

ery photon; however, this requires sacrificing some of the 2.0

BER (%)
30

cryptographic key to accurately determine the BER.

|S|
1.5

20
In investigating the effects of the presence of an eaves- 1.0

dropper there are two main difficulties. First, there are 0.5
no eavesdropper
10

various possible strategies; and second, we always assume 0.0

-90û -60û -30û 0û 30û 60û 90û-90û


-90û -60û -30û 0û 30û 60û 90û
0

that Eve has essentially perfect equipment and proce- EveÕs basis angle, q
dures, which of course is experimentally impossible to c. L 50

implement. Hence, we can at best simulate the effects 2.5 no eavesdropper


40

she would have; we did this for two particular inter- 2.0
H

BER (%)
30
cept/resend eavesdropping strategies. In the first, we
|S|
1.5

make a strong filtering measurement of the polarization, 1.0


20

in some basis χ, and send on the surviving photons to 0.5


no eavesdropper
10

Bob. The simulated eavesdropper thus makes the pro- 0.0 0

0û 30û 60û 90û 120û 150û 180û 0û


0û 30û 60û 90û 120û 150û 180û

jective measurement |χihχ|. The effect on the measured EveÕs basis angle, y
value of S and S ′ and the BER depend strongly on what
eavesdropping basis |χi is used [8]. Theoretical predic- FIG. 2. Data and theory showing the effect of an eaves-
tions and results for bases in three orthogonal planes in dropper on S and BER for various attack bases (as S ′ closely
the Poincaré sphere are shown in Figure 2. agrees with S, it is omitted for clarity). Diamonds represent
strong measurements, made with a polarizer; circles repre-
The second eavesdropping strategy examined was
sent QND attacks, simulated with a 3mm-thick BBO crystal;
a quantum non-demolition (QND) measurement [26]. error bars are within the points. The attacks bases are: a.
QND measurements of optical photon number and po- |Hi + eiφ |V i; b. cos θ|Hi + sin θ|V i; and c. |45◦ i + eiψ |-45◦ i;
larization are presently impossible. In fact, precisely for the actual measurement points in these bases are illustrated
this reason current quantum cryptography implementa- on the inset Poincaré spheres. The measured average values
tions are secure, even though they employ weak optical with no eavesdropper are indicated by unbroken grey lines,
pulses (with average photon number/pulse less than 1) the broken lines represent the maximum classical value of |S|.
[27]. Nevertheless, the ideal of quantum cryptography is
that it can be made secure against any physically possi-
and ordinary components of the photon wavepacket by
ble eavesdropping strategies; hence, it is desirable to test more than the coherence length (∼ 140µm, determined
any system against as many strategies as possible.
by the interference filters before the detectors); the re-
Although appropriate QND measurements cannot be
sult is a completely random phase between these po-
performed at present, it is well known that their effect
larization components, just as if a QND measurement
is to produce a random phase between the eigenstates
had been made on them. Mathematically, the effect of
of the measurement, in turn due to the entanglement of the eavesdropper is to make a projective measurement
these states with the readout quantum system. We can
|χihχ| + eihξi |χ⊥ ihχ⊥ |, where hξi represents a random
exactly simulate this effect by inserting, in Bob’s path,
phase. Note that the theoretical predictions are identical
a birefringent element that separates the extraordinary with that for the strong polarization measurement. The
experimental data are also shown in Fig. 2.
TABLE II. 100 bits of typical shared quantum key data for We see immediately that the optimal bases for eaves-
Alice (A) and Bob (B), generated using the Ekert protocol.
dropping lie in the same plane (on the Poincaré sphere)
Italic entries indicate errors; our average BER was 3.06%.
as the bases employed by Alice and Bob – for this case,
the probability that the eavesdropper causes an error
A: 1111100101010110100110000 1010011100110111010100000 is
B: 1111100101010110100110000 1010011100100011010101000 √ “only” 25% per intercepted bit, and the |S| value is
2 (Fig. 2a). On the other hand, if the eavesdropper
A: 1000100101000010100111101 1101001001010101010010111
does not know the plane of the measurement bases, and
B: 1100100101000011100111101 1101001001011101010010111
uses, e.g., random measurements in an orthogonal plane,

3
her average probability of producing an error climbs√to haus, Acta. Phys. Slov. 49, 549 (1999); G. Brassard, T.
32.5%/bit, and the average value of |S| drops to 1/ 2. Mor, and B. C. Sanders, quant-ph/9906074.
This suggests a strategy for improved security: Alice and [11] N. Lutkenhaus, Phys. Rev. A 59, 3301 (1999); see also,
Bob should choose bases corresponding to at least two N. Lutkenhaus, quant-ph/9910093.
(and ideally three) orthogonal planes, thereby “magnify- [12] J. S. Bell, Physics 1, 195 (1965).
[13] P. R. Tapster, J. G. Rarity, and P. C. M Owens, Phys.
ing” the presence of an eavesdropper (at least one imple-
Rev. Lett. 73, 1923 (1994); W. Tittel, J. Brendel, H.
menting the sort of strong projective or QND-like mea-
Zbinden, and N. Gisin, Phys. Rev. Lett. 81, 3563 (1998);
surements strategies investigated here) above the usual G. Weihs, et al., Phys. Rev. Lett. 81, 5039 (1998).
25%/bit error probability. Quantitative theoretical in- [14] P. G. Kwiat, et al., Phys. Rev. A 60, R773 (1999).
vestigations of such a strategy, known as the “six-state” [15] J. Brendel, N. Gisin, W. Tittel, and H. Zbinden, Phys.
protocol, support these claims [28]. Rev. Lett. 82, 2594 (1999).
An eavesdropper could also examine only a fraction [16] A. V. Sergienko, et al., Phys. Rev. A 60, R2622 (1999).
of the photons, thus reducing her induced BER and in- [17] During completion of our work, related results were re-
creasing the S value measured by Alice and Bob, at the ported by T. Jennewein et al., to appear in Phys. Rev.
expense of her own knowledge of the cryptographic key. Lett.; and more recently by W. Tittel et al., in quant-
For example, if she measures (in the optimal basis) less ph/9911109.
[18] See, for instance, P. H. Eberhard and R. R. Ross, Found.
than 58.6% of the photons, S > 2 and the correspond-
Phys. Lett. 2, 127 (1989).
ing BER < 15%, but Eve’s knowledge of the key will
[19] The random pulse sequences to drive the LC’s were gen-
be less than Bob’s (and privacy amplification techniques erated by LabView on each of Alice’s and Bob’s separate
will still permit generation of a secret key) [29,30]. computers. For our comparatively short data strings, the
In summary, we have implemented the Ekert quantum pseudo-random numbers were adequate.
cryptography protocol using entangled photon pairs. For [20] In order to average out the effect of different detector
this proof-of-principle experiment, Alice and Bob were efficiencies, different detectors represented “0” and “1”
situated side by side on the same optical table, obviously depending on the phase settings, i.e., detector 1 (2’) rep-
not the optimal configuration for useful cryptography. resented a “0” for α1 , α3 (β4 , β2 ), but a “1” for α2 , α4
Nevertheless, our system demonstrates the essential fea- (β3 , β1 ). The resulting key contained 49% “1”s.
tures of the Ekert protocol, and moreover, we believe [21] There is a small contribution (∼ 0.7% per key bit) of
events in which a double pair was emitted within the
is the first to experimentally investigate the effect of a
detection time (conservatively estimated as the 5ns gate
physical intermediate eavesdropper [31]. We see no bar window + 35ns dead time). In principle an eavesdropper
to extending the transmission distance to hundreds of could learn the value of these key bits, using methods
meters [9] or even to earth-to-satellite distances [32]. similar to those for weak pulse schemes [10].
We gratefully acknowledge the laboratory assistance [22] Heating the LC’s to 35◦ , and applying “overshoot” volt-
of S. Lopez, the error correction/privacy amplification ages, improved the switching times to under 19 ms for
programs written by E. Twyeffort, and very helpful dis- all transitions; photons were collected in the following 1
cussions with R. Hughes and N. Lutkenhaus. ms. The cycle time could be improved to nanoseconds by
∗ using, e.g., electro-optic modulators instead of LC’s.
Please address correspondence to: Kwiat@lanl.gov.
[23] If Alice and Bob use only three settings and the standard
Bell’s inequality (as proposed by Ekert [3]), 4/9 of the
[1] P. W. Shor, SIAM Review, 41, 303 (1999). pairs go to testing Bell’s inequality, and 2/9 to the key.
[2] C. H. Bennett and G. Brassard, in Proc. of the IEEE [24] The BER is defined as the number of errors divided by
Int. Conf. on Computers, Systems, and Signal Process- the total size of the cryptographic key; BER = 0.5 implies
ing, Bangalore, India (IEEE, New York, 1984), p. 175. Alice and Bob have completely uncorrelated strings.
[3] A. K. Ekert, Phys. Rev. Lett, 67, (1991). [25] J. F. Clauser, M. A. Horne, A. Shimony, and R. A. Holt,
[4] C. H. Bennett, G. Brassard, and N. D. Mermin, Phys. Phys. Rev. Lett. 23, 880 (1969); A. Garuccio and V. A.
Rev. Lett. 68, 557 (1992). Rapisarda, Nuovo Cim. A 65, 269 (1981).
[5] C. H. Bennett,Phys. Rev. Lett. 68, 3121 (1992). [26] M. Werner and G. Milburn, Phys. Rev. A 47, 639 (1993).
[6] U. M. Maurer, IEEE Trans. Inform. Theory 39, 773 [27] W. T. Buttler et al., Phys. Rev. Lett. 83, 2477 (1999).
(1993); C. H. Bennett, G. Brassard, C. Crepeau, and U. [28] D. Bruß, Phys. Rev. Lett. 81, 3018 (1999); H. Bechmann-
M. Maurer, ibid. 41, 1915 (1995); and references therein. Pasquinucci and N. Gisin, Phys. Rev. A 59, 4238 (1999).
[7] P. D. Townsend, J. G. Rarity, and P. R. Tapster, Elec- [29] N. Gisin and B. Huttner, Phys. Lett. A 228, 13 (1997);
tron. Lett, 29, 1291 (1993); P. D. Townsend, ibid. 30, C. A. Fuchs et al., Phys. Rev. A 56, 1163 (1997).
809 (1994); A. Muller et al., Appl. Phys. Lett. 70, 793 [30] Information lost during error correction actually reduces
(1997); R. J. Hughes, G. L. Morgan, and C. G. Peterson, the BER “safety” threshold to < 11% [11].
J. Mod. Opt., to appear (1999). [31] The very first quantum cryptography experiment [8] sim-
[8] C. H. Bennett, et al., J. Cryptol. 5, 3 (1992). ulated the effect of an intermediate eavesdropper by let-
[9] B. Jacobs and J. D. Franson, Opt. Lett. 21, 1854 (1996); ting her “borrow” Alice’s and Bob’s apparatus, and by
W. T. Buttler, et al., Phys. Rev. Lett. 81, 3283 (1998). introducing her in the post-detection computation.
[10] T. Durt, Phys. Rev. Lett. 83, 2476 (1999); N. Lutken- [32] R. Hughes and J. Nordholt, Phys. World 12, 31 (1999).

You might also like