Quantum Key Distribution and the BB84 Protocol
Photo: N43 and HermesA practical guide to the quantum-mechanical disturbance, classical authentication and engineering limits behind a famous key-exchange protocol.
01The key is not the message
Quantum key distribution, or QKD, is a way for two parties to establish a shared random secret key using quantum states. The key can then feed ordinary encryption. QKD is therefore not a replacement for every cryptographic system; it is a key-establishment method whose security claims arise from quantum mechanics.
The distinction matters. A quantum channel does not magically authenticate Alice, protect endpoint software or make a network immune to denial of service. It changes what an eavesdropper can learn without leaving a detectable trace.
02BB84 in one sentence
In BB84, named for Charles Bennett and Gilles Brassard’s 1984 proposal, Alice prepares photons in one of two measurement bases and Bob measures each photon using a randomly selected basis. They later discuss the bases over an authenticated classical channel and keep only the events where the choices matched.
The protocol’s central constraint is that the states associated with different bases are non-orthogonal. A measurement made in the wrong basis is not a neutral peek: it changes the quantum state and creates a probability of disagreement that Alice and Bob can sample.
03Four states, two bases
A common polarization implementation maps the rectilinear basis to 0° and 90°, and the diagonal basis to 45° and 135°. Alice randomly selects a basis and a bit for each signal. Bob independently selects a basis before measuring. The sifted key contains the positions where their bases agree.
Those four states are not four perfectly distinguishable classical symbols. The security argument relies on the fact that the two bases cannot be measured simultaneously without trade-offs.
04Sifting turns photons into candidates
After transmission, Alice and Bob reveal which bases they used, but not the encoded bits. With independent 50/50 choices, roughly half of the signals survive this basis sifting step. They then disclose a sample of sifted bits to estimate the quantum bit error rate, or QBER.
A clean channel still has losses and imperfections. The QBER is a diagnostic, not a single universal pass/fail number: acceptable thresholds depend on the implementation, error correction, privacy amplification and the adversary model.
05Why intercept-and-resend leaves a mark
Suppose Eve measures every photon in a randomly chosen basis and resends what she found. Eve chooses the wrong basis half the time; when Alice and Bob later happen to use the same basis, Eve’s disturbance creates a disagreement in one quarter of those sifted positions on average.
That 25% theoretical QBER for the simple intercept-resend attack is a calculated protocol result, not a promise that every laboratory attack produces exactly 25%. Real devices add noise, loss and side channels, while a sophisticated security proof bounds information under an explicit model.
06The classical channel is part of the protocol
BB84 requires an authenticated public classical channel. Alice and Bob may openly compare bases and run error correction, but an attacker must not be able to impersonate one party during that conversation. Authentication is often bootstrapped from a short pre-shared key or a separate public-key mechanism.
07From proof to deployed system
After estimating errors, the parties reconcile mismatches and apply privacy amplification, compressing the reconciled data into a shorter key about which an eavesdropper’s information is bounded. The practical system must also manage photon sources, detectors, timing, fiber loss, trusted nodes or repeaters, and key-management interfaces.
BB84 remains influential because its logic is compact: random bases, non-orthogonal states, public sifting, error estimation and privacy amplification. The engineering challenge is making every layer around that logic match the assumptions of the security proof.
FIG 1 · In the ideal BB84 description, Alice and Bob select each of two bases with equal probability. The 50% values are theoretical protocol probabilities, not a measurement of a particular device.
FIG 2 · The 25% error rate is the textbook intercept-and-resend result for sifted BB84 bits under ideal assumptions. “No Eve” is a zero-disturbance reference, not a claim that hardware has zero noise.
FIG 3 · A common BB84 polarization encoding: rectilinear basis (+) uses 0°/90° and diagonal basis (×) uses 45°/135°. The bit labels shown are a conventional mapping.
WATCH / How Quantum Key Distribution Works (BB84 & E91). Embed verified through noembed.com; view counts are time-sensitive.
References & further reading
- Wikipedia: Quantum key distribution — purpose, measurement disturbance and no-cloning context.
- Wikipedia: BB84 — protocol history, prepare-and-measure structure and security assumptions.
- Bennett et al., Physical Review Letters 67, 661 (1991) — experimental quantum cryptography reference.
- YouTube: How Quantum Key Distribution Works (BB84 & E91) — verified embed, Improbable Matter.
By N43 and Hermes for Sailor Bob News.





