arxiv: v1 [quant-ph] 18 May 2018

Similar documents
Quantum secret sharing based on quantum error-correcting codes

arxiv:quant-ph/ v2 2 Jan 2007

Two-Step Efficient Deterministic Secure Quantum Communication Using Three-Qubit W State

Trustworthiness of detectors in quantum key distribution with untrusted detectors

arxiv:quant-ph/ v1 10 Apr 2006

Experimental realization of quantum cryptography communication in free space

arxiv:quant-ph/ v1 27 Dec 2004

Quantum Secure Direct Communication with Authentication Expansion Using Single Photons

Security of Quantum Cryptography using Photons for Quantum Key Distribution. Karisa Daniels & Chris Marcellino Physics C191C

Multiparty Quantum Secret Sharing via Introducing Auxiliary Particles Using a Pure Entangled State

Efficient controlled quantum secure direct communication based on GHZ-like states

Biased decoy-state reference-frame-independent quantum. key distribution

arxiv:quant-ph/ v2 3 Oct 2000

Counterfactual Quantum Deterministic Key Distribution

Ping Pong Protocol & Auto-compensation

Title Experimental long-distance quantum secure direct communication

Practical quantum-key. key- distribution post-processing

arxiv: v3 [quant-ph] 25 Feb 2015

Implementation and Security Analysis of Practical Quantum Secure Direct Communication

Quantum Secure Direct Communication Based on Dense Coding and Detecting Eavesdropping with Four-Particle Genuine Entangled State

Security of Quantum Key Distribution with Imperfect Devices

Chapter 13: Photons for quantum information. Quantum only tasks. Teleportation. Superdense coding. Quantum key distribution

An Introduction to Quantum Information. By Aditya Jain. Under the Guidance of Dr. Guruprasad Kar PAMU, ISI Kolkata

Security Implications of Quantum Technologies

Quantum key distribution with 2-bit quantum codes

arxiv:quant-ph/ v1 6 Dec 2005

Quantum secure direct communication network with Einstein-Podolsky-Rosen pairs

Bidirectional quantum teleportation and secure direct communication via entanglement swapping

Quantum Cryptography and Security of Information Systems

Entanglement and information

Fault-Tolerant Quantum Dialogue Without Information Leakage Based on Entanglement Swapping between Two Logical Bell States

Multiparty Quantum Remote Control

Selection of unitary operations in quantum secret sharing without entanglement

A Quantum Multi-Proxy Blind Signature Scheme Based on Entangled Four-Qubit Cluster State

10 - February, 2010 Jordan Myronuk

arxiv: v2 [quant-ph] 9 Nov 2011

Circular Semi-Quantum Secret Sharing Using Single Particles

Quantum cryptography: from theory to practice

arxiv:quant-ph/ v1 13 Jan 2003

Scheme for Asymmetric and Deterministic Controlled Bidirectional Joint Remote State Preparation

Perfectly secure cipher system.

Quantum Entanglement Assisted Key Distribution

5th March Unconditional Security of Quantum Key Distribution With Practical Devices. Hermen Jan Hupkes

Problem Set: TT Quantum Information

Quantum Hacking. Feihu Xu Dept. of Electrical and Computer Engineering, University of Toronto

Realization of B92 QKD protocol using id3100 Clavis 2 system

A. Quantum Key Distribution

arxiv: v7 [quant-ph] 20 Mar 2017

arxiv: v5 [quant-ph] 28 Oct 2015

Multiparty Quantum Secret Sharing Using Quantum Fourier Transform

Eavesdropping or Disrupting a Communication On the Weakness of Quantum Communications

A Superluminal communication solution based on Four-photon entanglement

Simulation and Implementation of Decoy State Quantum Key Distribution over 60km Telecom Fiber

Quantum Information Transfer and Processing Miloslav Dušek

An Introduction. Dr Nick Papanikolaou. Seminar on The Future of Cryptography The British Computer Society 17 September 2009

EPR paradox, Bell inequality, etc.

arxiv:quant-ph/ v2 7 Nov 2001

Massachusetts Institute of Technology Department of Electrical Engineering and Computer Science Quantum Optical Communication

An Improved Quantum Information Hiding Protocol Based on Entanglement Swapping of χ-type Quantum States

arxiv:quant-ph/ v2 17 Sep 2002

Research, Development and Simulation of Quantum Cryptographic Protocols

Quantum Key Distribution. The Starting Point

Quantum Error Correcting Codes and Quantum Cryptography. Peter Shor M.I.T. Cambridge, MA 02139

1 1D Schrödinger equation: Particle in an infinite box

Simulation of BB84 Quantum Key Distribution in depolarizing channel

arxiv:quant-ph/ v3 13 Mar 2007

Cryptography CS 555. Topic 25: Quantum Crpytography. CS555 Topic 25 1

Quantum Cryptography. Marshall Roth March 9, 2007

arxiv: v3 [quant-ph] 6 Sep 2009

Seminar Report On QUANTUM CRYPTOGRAPHY. Submitted by SANTHIMOL A. K. In the partial fulfillment of requirements in degree of

arxiv:quant-ph/ v2 25 May 2005

Quantum Secure Direct Communication by Using Three-Dimensional Hyperentanglement

arxiv: v2 [quant-ph] 8 Feb 2013

State Decoding in Multi-Stage Cryptography Protocols

Introduction to Quantum Cryptography

John Preskill, Caltech Biedenharn Lecture 2 8 September The security of quantum cryptography

+ = OTP + QKD = QC. ψ = a. OTP One-Time Pad QKD Quantum Key Distribution QC Quantum Cryptography. θ = 135 o state 1

Introduction to Quantum Cryptography

High rate quantum cryptography with untrusted relay: Theory and experiment

arxiv: v1 [quant-ph] 10 Mar 2018

arxiv: v1 [quant-ph] 3 Jul 2018

Quantum Cryptography

Chapter 5. Quantum Cryptography

Unconditional Security of the Bennett 1992 quantum key-distribution protocol over a lossy and noisy channel

9. Distance measures. 9.1 Classical information measures. Head Tail. How similar/close are two probability distributions? Trace distance.

arxiv:quant-ph/ v2 11 Jan 2006

1 1D Schrödinger equation: Particle in an infinite box

Simulation and Implementation of Decoy State Quantum Key Distribution over 60km Telecom Fiber

FUNDAMENTAL AND PRACTICAL PROBLEMS. OF QKD SECURITY-THE ACTUAL AND THE arxiv: v4 [quant-ph] 4 Jun 2012 PERCEIVED SITUATION

Deterministic Quantum Key Distribution Using Gaussian-Modulated Squeezed States

Asymptotic Analysis of a Three State Quantum Cryptographic Protocol

Physics is becoming too difficult for physicists. David Hilbert (mathematician)

Technical Report Communicating Secret Information Without Secret Messages

Intrinsic-Stabilization Uni-Directional Quantum Key Distribution. Between Beijing and Tianjin

Perfect quantum teleportation and dense coding protocols via the 2N-qubit W state

Attacks against a Simplified Experimentally Feasible Semiquantum Key Distribution Protocol

arxiv:quant-ph/ v1 13 Mar 2007

Single-photon quantum error rejection and correction with linear optics

Research Proposal for Secure Double slit experiment. Sandeep Cheema Security Analyst, Vichara Technologies. Abstract

LECTURE NOTES ON Quantum Cryptography

Transcription:

Measurement-Device-Independent Quantum Secure Direct Communication, arxiv:1805.078v1 [quant-ph] 18 May 018 Zeng-Rong Zhou, 1,, 3, 4, 5, 6, Yu-Bo Sheng, 7, 8, 9, Peng-Hao Niu, 1,, 3, 4, 5, 6 Liu-Guo Yin, 3, 4, 1,, 3, 4, 5, 6, and Gui-Lu Long 1 State Key Laboratory of Low-dimensional Quantum Physics, Beijing, 100084, China Department of Physics, Tsinghua University, Beijing, 100084, China 3 Beijing National Research Center for Information Science and Technology, Beijing, 100084, China 4 School of Information and Technology,Tsinghua University, Beijing, 100084, China 5 Collaborative Innovation Center of Quantum Matter, Beijing, 100084, China 6 Beijing Academy of Quantum Information, Beijing, 100084, China 7 Institute of Quantum Information and Technology, Nanjing University of Posts and Telecommunications, Nanjing, 10003, China 8 College of Telecommunications & Information Engineering, Nanjing University of Posts and Telecommunications, Nanjing, 10003, China 9 Key Lab of Broadband Wireless Communication and Sensor Network Technology, Nanjing University of Posts and Telecommunications, Ministry of Education, Nanjing, 10003, China Quantum secure direct communication (QSDC) is the technology to transmit secret information directly through a quantum channel without neither key nor ciphertext. It provides us with a secure communication structure that is fundamentally different from the one that we use today. In this Letter, we report the first measurement-device-independent(mdi) QSDC protocol with sequences of entangled photon pairs and single photons. It eliminates security loopholes associated with the measurement device. In addition, the MDI technique doubles the communication distance compared to those without using the technique. We also give a protocol with linear optical Bell-basis measurement, where only two of the four Bell-basis states could be measured. When the number of qubit in a sequence reduces to 1, the MDI-QSDC protocol reduces to a deterministic MDI quantum key distribution protocol, which is also presented in the Letter. Introduction A secure communication structure is usually composed of a key distribution channel and a ciphertext transmission channel, as shown in Fig. 1a. Usually, ciphertext is encoded with the AES cipher [1], and key is distributed using RSA public cryptosystem []. There are three potential security loopholes in this structure: leak of key during distribution, loss of key in storage and in transition at users sites, and interception of ciphertext in transmission. Quantum principle enables legitimate users to detect Eve, and quantum key distribution (QKD) offers provably security for key agreement [3, 4]. In QKD, sends random numbers encoded in quantum states to. They can detect Eve by publicly comparing some samples. If Eve is found, they discard the transmitted data because all or part of them has already leaked. If they are certain that there is no eavesdropping, the transmitted data will be used as key to encode a message into ciphertext. QKD eliminates in principle the security loophole in the key distribution channel, but the other two loopholes still persist. An Eve can always intercept the ciphertext and store them for cryptanalysis. Only Vernam s one-time-pad was shown to be perfectly secure [5, 6] provided the key is absolutely protected. Though happened very rarely, loss of key or repeated use of key still occurred, with disastrous consequences [7]. QSDC [8 10] transmits a message directly over a quantum channel. It does not use key, hence there is no key distribution and key storage and management. The security loopholes associated with the key are all eliminated. QSDC establishes a secure quantum channel first, and any attempt to intercept the QSDC channel would obtain only random numbers, hence the security loophole associated with the ciphertext is also wiped out. As shown in Fig.1b, QSDC eliminates all three security Encrypt Key Public Channel Key Distribution (a) QSDC Channel (b) Encrypt Key Figure 1. (coloronline)(a) Structure of a general secure communication. Usually key distribution is completed using RSA. With QKD, unconditional key distribution can be achieved. (b) The structure of quantum secure direct communication. It has no key distribution, key storage and management, and no ciphertext. It eliminates all three security loopholes in a general secure communication structure. loopholes in traditional secure communication, and changes fundamentally the structure. This could lead further changes in future secure communication. Recently, there have been remarkable developments in experimental QSDC. A single-photon QSDC protocol with error correction code was proposed and experimentally demonstrated [11]. It has shown that QSDC works in noisy and lossy environment. QSDC protocols based on Einstein-Podolsky- Rosen (EPR) pair in Refs.[8, 9] have been experimentally realized using atomic quantum memory in optical platform [1], and fiber-photonics devices at a distance of a few kilo-meters [13] respectively. They have attracted widespread attention both in the academic and security circles [14]. All components in a practical setting have defects and imperfections, and they can be used to steal secret key in practical QKD systems [15 19]. Among these loopholes, those

in the measurement devices are dominant. One solution to this problem is to fabricate near perfect devices. However it takes somehow long time to advance related fabrication technology, and there is always some degree of inaccuracy in any real device. An alternative way is to design new protocols, taking into account the imperfections existent in these devices. This has been successfully done in QKD in the measurementdevice-independent(mdi) protocol [0]. In the MDI technique, the measurement-device is in principle in the hands of an untrusted Charlie who performs the measurement. It eliminates the security loopholes in the measurement part of the system. QSDC is secure under ideal conditions, such as perfect quantum source, noiseless channel, perfect devices and detectors [8 10, 1, ]. In order for QSDC to go for practical application, measurement-device-independent QSDC is essential. In this Letter, we propose a measurement-deviceindependent QSDC (MDI-QSDC) protocol based on single photons and entangled photon pairs. In this scheme, prepares a sequence of EPR-pairs, and prepares a sequence of single photon states and "send" them to through teleportation, in which the Bell-basis measurement is performed by an untrusted Charlie. Then after checking the security, encodes her message in the teleported single photons, and sends them to Charlie who performs the single qubit measurement for. MDI-QSDC enhances greatly the security of QSDC under realistic condition. In addition to the security advantage, MDI-QSDC effectively doubles the communication distance because both and send their qubits to the measurement-device which lies in the middle of them. We also give a protocol with linear optics Bell-basis measurement, where only two of the four Bell-basis states could be measured. QSDC enables the direct secure transmission of information by the block data transmission technique [8, 9], in which the quantum information carriers are transmitted in a block of large number of qubits. When the number of qubit in a block is reduced to 1, the MDI-QSDC protocol is reduced to a deterministic MDI-QKD protocol, which is also described toward the end of the Letter. Method The protocol uses both Bell-basis states, φ ± = ( 00 ± 11 ) /, ψ ± = ( 01 ± 10 ) /, (1) and single qubit states ± = ( 0 ± 1 )/, 0 and 1. The protocol consists of the following 6 steps, and we suppose sends information to. The protocol is illustrated in Fig.. Step 1) and prepare ordered qubits sequences. produces a sequence of N + t 0 EPR-pairs in Bell-state ψ1 in her site. She divides her EPR pair sequence into two single qubit sequences, S Ah and S At, whose qubits are partners each other in the EPR pairs. She also prepares a sequence of t 1 number of single qubits whose states are randomly in one of the +,, 0 states, 1, and inserts them into S At in random positions so as to form an ordered sequence P A of N + t 0 + t 1 single qubits. Meanwhile, prepares a se- s state φ + 3 φ 3 ψ+ 3 ψ 3 0 3 1 3 0 1 + 3 3 + 1 Table I. ψ 1 q 3 in terms of Bell-states of qubit and 3. In front of each term, there is a coefficient 1/. quence of N + t 0 + t 1 single qubits, P B, whose states are randomly in one of the four states +,, 0 and 1. The EPR pairs in s side are used for directly communicating secret information, and the single qubits are used for security check. Step ). sends sequence P A, and sends sequence P B to Charlie. Charlie performs Bell-basis measurement on every pair of qubits he receives from and, and publishes the results. The Bell-basis measurement of a single qubit from an EPR-pair of P A with a single qubit from P B leads to the collapse of s EPR-pair into one of the four single qubit states, { +,, 0, 1 } with equal probabilities, as shown in Table I. The state after measurement is only known to, and unknown to both and Eve. This is a quantum teleportation process in a slightly complicated manner, where s single qubit is almost teleported, apart from a unitary operation U T to transform s corresponding qubit in S Ah into s state. U T is known to all, and Charlie after Charlie announces his Bell-basis measurement result. For instance, for ψ1 0 3, U T = I if the Bell-basis measurement yields ψ 3 + or ψ 3 ; U T = iσ Y, if the Bell-basis measurement yields φ + 3 or φ 3. Step 3). Security check. publishes the positions and states of the t 1 single qubits in P A, and also publishes the corresponding states of the corresponding qubits in P B. This security check is identical to that in the MDI-QKD. For those qubits whose basis are different, a Bell-basis measurement will yield any one of the four Bell-basis states, as shown in Eq. (), + 0 = + 1 φ+ + 1 φ + 1 ψ+ + 1 ψ, 1 = 1 φ+ + 1 φ + 1 ψ+ + 1 ψ. () There are not useful for security check. The decomposition of qubits with identical basis in terms of Bell-basis states are shown in Eq. (3). + + = 1 ( φ + + ψ + ), + = 1 ( φ ψ ), 0 0 = 1 ( φ + + φ ), 0 1 = 1 ( ψ + + ψ ). A Bell-basis measurement can only obtain one of two Bellbasis states. Charlie s eavesdropping will have a 50% probability to obtain the other two Bell-basis states, hence increases (3)

3 D 4 BSM D EPR-pairs whose density is Tr 1 ( ψ1 ψ 1 ) and a sequence of t 1 qubits randomly in four states, whose density is I/, PBS D 3 BS Charlie PBS1 D 1 Figure. (coloronline)sketch for experimental implementation of MDI-QSDC the error rate. If the error rate is above the threshold, then the process will be terminated. Otherwise, go to the next step. Step 4). Encoding message by. announces the basis of his remaining qubits. s encoding operation U is the product of two operations, U = U m U T. The first one is the unitary operation to complete the quantum teleportation U T, and the other operation is the message encoding operation U m, namely I for 0, which does not change the state at all, and iσ Y for 1, which flips the state. To ensure the integrity of the message, also encodes t 0 qubits with random numbers, which are positioned randomly in S Ah. Step 5). sends the sequence to Charlie. Charlie first performs unitary operations, U B s, so that the qubit basis becomes { 0, 1 }, namely U B = I if the basis of s qubit is { 0, 1 }, and U B = H if the basis of s qubit is { +, }. Charlie measures the qubits in sequence S Ah in σ Z basis and announces the results. Upon these results, can derive the message and random numbers encoded by. Step 6). Integrity check. announces the random numbers of the t 0 check qubits. If the error rate is below threshold, the transmission is safe. and conclude that the direct communication is secure and complete the session. Otherwise, they conclude the communication is tampered by Eve or the untrusted Charlie. It should be emphasized that Eve or Charlie s eavesdropping at step 5) could not steal any information, it can only disturb the communication. Integrity check ensures the message receives is correct. Security analysis The security check in step 3) is identical to that in MDI-QKD. After the security check, the security of teleportation process of s qubits is ascertained. Before the Bell-basis measurement, the density matrix of qubit in s sequence P A is composed qubits from N + t 0 entangled ρ A = N + t 0 N + t 0 + t 1 I + t 1 N + t 0 + t 1 I = I. (4) The density matrix of qubit in sequence P B is I/. After the security check in step 3, state q 3 of s qubit is "teleported" to, in the form of U 1 T q 3., and Charlie all know the explicit form of U T from the result of Bell-basis measurement. and Charlie do not know q 3. After s encoding and Charlie s measurement, U m q 3 is announced publicly. can derive U m by comparing U m q 3 with his initial state q 3. Under noisy channel, after the security check, could choose a classical linear code for the remaining qubits. The procedures are almost identical to those in the Shor-Preskill type of proof BB84 QKD protocol in Ref. [3]. The difference between QSDC and QKD is that the error correction encoding must be implemented before sends her sequence of N +t 0 encoded qubits to Charlie. In the limit of large qubit numbers, the error rate threshold is 11%. MDI-QSDC protocol using linear optical devices Using linear optics, only two of the four Bell-basis states, ψ ±, can be distinctively measured. Hence the MDI-QSDC protocol should be revised accordingly. Some modification to the 6 steps with full-bell-basis measurements are described here. Step 1 is the same. In step, only ψ ± can be obtained after the Bell-basis measurements. When the measured result is φ ±, there is simply no clicks in the detectors. Therefore with high probability, only half of the qubits in P A and P B can give the results ψ ± when measured using linear optical device, as can be seen from Table I. There is no change in step 3, and eavesdropper will be found in the similar way as that in the MDI-QKD. There is no change in step 4, the encoding operation is U m U T. Steps 5 and 6 are also the same. Deterministic MDI-QKD protocol In a QKD protocol, eavesdropper can be found only after certain number of qubits have gone through the whole transmission process. Therefore when Eve is found, she has already acquired some transmitted data, which is disastrous for direct communicating secret message. In QSDC, block transmission is essential to prevent information leak before Eve s detection [8]. For instance, in the security check in step 3, the comparisons of t 1 check pairs out of a block of N + t 0 + t 1 pairs give a good estimate of the error rate, and ensures the security of qubits in S Ah before they are encoded with message and sent to Charlie. If the security of S Ah is not assured, Charlie or Eve could eavesdrop, for instance, Charlie does not make the Bell-basis measurement and stores the qubit in P A instead. After encodes the message on her qubit in S Ah and sends it to Charlie, Charlie can perform Bell-basis measurement on the encoded qubit from S Ah and the stored qubit from P A to read s encoded bit. Of course, Charlie s cheating will be found after dozens of rounds of transmission, the data transmitted before and finding her will be lost completely. Therefore the number of qubit in a block is reduced to 1, the

4 QSDC protocol is no longer secure in sending secret message. Instead, it becomes a deterministic QKD protocol, namely it can still transmit random numbers deterministically and find eavesdropper after a session is finished. If an eavesdropper is found, they discard the transmitted data, otherwise they retain the transmitted data as raw key. The detailed procedure for the deterministic MDI-QKD is given below. Step 1) produces with probability p k = (N + t 0 )/(N + t 0 + t 1 ) an EPR pair in state ψ1, and with probability p c = 1 p k a single qubit (labeled qubit ) randomly in one of the four states +,, 0 and 1. Meanwhile prepares qubit 3 randomly in one of the four states +,, 0, 1. Step ). sends qubit, and sends qubit 3 to Charlie. Charlie performs Bell-basis measurement on the pair of qubits and publishes the result. Step 3) After hearing from Charlie the Bell-basis measurement result, announces the basis of his qubit in the Bell-basis measured pair. performs encoding operation U m U T on qubit 1, where m is a random bit and determined by, U T is the unitary operation to complete the teleportation. sends the encoded qubit 1 to Charlie, and Charlie first performs a unitary operation U B so that the qubit basis becomes 0, 1, namely U B = I if the basis of s qubit is 0, 1, and U B = H if the basis of s qubit is +,. Then Charlie measures qubit 1 in σ Z basis and publishes the result. Step 4) After sufficient number N + t 0 + t 1 of transmission has been performed ( N + t 0 number of EPR-pairs and t 1 number of single qubits), announces the initial states of the t 1 single qubits and announces the initial states of corresponding single qubits, they will get an estimate of the error rate. If the error rate is above a threshold, they conclude the transmission insecure and terminate the process. If the error rate is below a threshold, they conclude the transmission is secure. Then announces the positions and bit values of the t 0 random check bits, and estimate the error rate. If the error rate is small, then they conclude the key distribution is safe. and will keep these N random numbers as key. This MDI-QKD protocol does not use the block transmission technique, the security is confirmed only after the distribution of the random numbers. This protocol could not send secret information directly, because all the transmitted data would leak to Eve before her detection. Classical communications are deterministic, but it cannot found eavesdropping. QKD can find eavesdropper, but cannot prevent Eve to access the transmitted data. QSDC can find eavesdropping and prevent Eve from obtaining the transmitted data. Discussion and Summary We proposed a MDI-QSDC protocol using both EPR-pairs and single qubits. We also give a simplified version using linear optics devices, which only distinguishes two Bell-basis states. These MDI-QSDC protocols can be implemented with the present-day technology. Using the decoy method [4, 5] and the ILM-GLLP method [6, 7], faint laser pulses and EPR-pairs from down conversion could be used with minor revisions to the protocols presented in this Letter. When the number of qubit in a block is reduced to 1, QSDC protocols reduce to deterministic QKD protocols. Acknowledgement This work was supported by the National Basic Research Program of China under Grant Nos. 017YFA0303700 and 015CB91001, National Natural Science Foundation of China under Grant Nos. 6176801, 11474168 and 11474181. These authors made equal contribitutions Corresponding author: yinlg@tsinghua.edu.cn Corresponding author: gllong@tsinghua.edu.cn [1] V. Rijmen and J. Daemen, Proceedings of Federal Information Processing Standards Publications, National Institute of Standards and Technology, 19 (001). [] R. L. Rivest, A. Shamir, and L. Adleman, Communications of the ACM 1, 10 (1978). [3] C. H. Bennet, in Proc. of IEEE Int. Conf. on Comp., Syst. and Signal Proc., Bangalore, India, Dec. 10-1, 1984 (1984). [4] A. K. Ekert, Physical Review Letters 67, 661 (1991). [5] G. S. Vernam, Journal of the AIEE 45, 109 (196). [6] C. E. Shannon, Bell Labs Technical Journal 8, 656 (1949). [7] M. Holzman, Guy Burgess: Revolutionary in an Old School Tie (Chelmsford Press, 01). [8] G.-L. Long and X.-S. Liu, Physical Review A 65, 0330 (00), also at Epreprint arxiv:quant-ph/001056. [9] F.-G. Deng and G.-L. Long, Physical Review A 68, 04315 (003). [10] F.-G. Deng and G. L. Long, Physical Review A 69, 05319 (004). [11] J.-Y. Hu, B. Yu, M.-Y. Jing, L.-T. Xiao, S.-T. Jia, G.-Q. Qin, and G.-L. Long, Light: Science & Applications 5, e16144 (016). [1] W. Zhang, D.-S. Ding, Y.-B. Sheng, L. Zhou, B.-S. Shi, and G.-C. Guo, Physical Review Letters 118, 0501 (017). [13] F. Zhu, W. Zhang, Y. Sheng, and Y. Huang, Science Bulletin 6, 1519 (017). [14] To list just a few: defenceone.com, MIT technology review, phys.org, fortunascorner.com, gregorybufithis.com, oodaloop.com, cnas.org, fedcyber.com and so on.. [15] C.-H. F. Fung, B. Qi, K. Tamaki, and H.-K. Lo, Physical Review A 75, 03314 (007). [16] F. Xu, B. Qi, and H.-K. Lo, New Journal of Physics 1, 11306 (010). [17] Y. Zhao, C.-H. F. Fung, B. Qi, C. Chen, and H.-K. Lo, Physical Review A 78, 04333 (008). [18] L. Lydersen, C. Wiechers, C. Wittmann, D. Elser, J. Skaar, and V. Makarov, Nature Photonics 4, 686 (010). [19] A. Meda, I. P. Degiovanni, A. Tosi, Z. Yuan, G. Brida, and M. Genovese, Light: Science & Applications 6, e1661 (017). [0] H.-K. Lo, M. Curty, and B. Qi, Physical Review Letters 108, 130503 (01). [1] L. Jian, S. Feng-Qi, P. Ze-Shi, N. Jin-Rui, C. Yan-Hua, and Y. Kai-Guo, Chinese Physics Letters 3, 080301 (015). [] H. Lu, C.-H. F. Fung, X. Ma, and Q.-y. Cai, Physical Review A 84, 04344 (011). [3] P. W. Shor and J. Preskill, Physical Review Letters 85, 441 (000).

5 [4] W.-Y. Hwang, Physical Review Letters 91, 057901 (003). [5] X.-B. Wang, Physical Review Letters 94, 30503 (005). [6] H. Inamori, N. Lütkenhaus, and D. Mayers, The European Physical Journal D 41, 599 (007). [7] D. Gottesman, H.-K. Lo, N. Lutkenhaus, and J. Preskill, in Information Theory, 004. ISIT 004. Proceedings. International Symposium on (IEEE, 004) p. 136.