Skip to main content
Sandbox Physics

Q044 · Prepare / sift / reveal

BB84 Key Distribution

Send four-state signals through a channel with an optional intercept–resend observer. Keep matching bases, reveal a random test subset and inspect a toy parity filter and binary hash. Follow every retained and discarded bit back to the sending record.

Interactive modelBB84 Key Distribution
Model sifted error probability—\text{—}
Model detected and matched fraction—\text{—}
Recorded evidence and resource cost

SIMULATED TRIALS

Where the bits went

Test errors use only the publicly revealed random subset. Pointwise 95% Wilson intervals describe this model’s test probability, not a security bound on the remaining string. Loss is independent of bit and basis.

Public test errors / 95% range

—\text{—}

Untested sifted bits

—\text{—}

Sent / detected signals

—\text{—}

Public stage ledger
Latest 12 simulated trials; CSV retains all. Includes teaching-only private fields.

Physics tutorial

Follow the public transcript

BackgroundAlice selects a random bit and one of two bases. Bob independently selects a basis. After transmission they publicly compare bases and retain detected matching-basis events.

Why it mattersThe public test consumes part of the sifted record. Postprocessing must account for published information and residual errors, rather than labeling every surviving bit secret.

Start with the essentials

Focus question
Can zero observed test errors certify the unrevealed string?
One-sentence intuition
A finite test estimates errors under assumptions. It neither identifies a specific attack nor by itself proves a secure key length.

Core mathematical model

Four signal states

∣0⟩, ∣1⟩, ∣+⟩=∣0⟩+∣1⟩2, ∣−⟩=∣0⟩−∣1⟩2|0\rangle,\ |1\rangle,\ |+\rangle=\frac{|0\rangle+|1\rangle}{\sqrt2},\ |-\rangle=\frac{|0\rangle-|1\rangle}{\sqrt2}

States are represented as qubits. Same-basis measurement is deterministic; conjugate-basis outcomes are equiprobable.

Independent channel reference

P(sifted)=η/2,Q=q+(1−2q)f/4P(\mathrm{sifted})=\eta/2,\qquad Q=q+(1-2q)f/4

The intercept fraction uses a uniformly random Eve basis followed by resend. Detection is independent; the readout flip is applied at Bob. The formula is a separate reference, never an estimate from the record.

Public test estimate

Q^=Ntest,errorNtest\widehat Q=\frac{N_{\mathrm{test,error}}}{N_{\mathrm{test}}}

Each sifted trial has an independently preassigned random test flag. Revealing the flag does not resample it. Wilson ranges are pointwise for this IID probability, not finite-key security bounds.

Pair-parity rejection

pA=a1⊕a2,pB=b1⊕b2p_A=a_1\oplus a_2,\quad p_B=b_1\oplus b_2

Both parties publish one parity per pair. A disagreement drops both bits. Otherwise only the first bit is retained. Two errors in a pair can remain undetected. An unpaired final bit is discarded.

Toeplitz demonstration

yi=⨁j=0n−1Tijxj,Tij=sn−1−j+iy_i=\bigoplus_{j=0}^{n-1}T_{ij}x_j,\quad T_{ij}=s_{n-1-j+i}

A reproducible public binary seed defines the matrix. Both strings are hashed to half their surviving length. This arbitrary compression is not derived from an entropy bound and is not certified privacy amplification.

Common difficulties

Loss versus disturbance

Typical misconceptionLosing signals raises the error rate automatically.

Better mental modelUnder the declared independent loss model it lowers sample size; the expected conditional error rate is unchanged.

Detecting an attack

Typical misconceptionAny disagreement proves Eve was present.

Better mental modelReadout noise also produces errors. Conversely zero observed errors does not exclude interception in a finite sample.

Secure deployment

Typical misconceptionThe final toy hash can encrypt a real message.

Better mental modelNo cryptographic randomness, authenticated channel implementation, finite-key entropy analysis or final equality verification is provided. The full teaching record exposes private values.

Run the experiment

  1. 01

    Transmit

    Send a clear-channel batch and view the received signals.

    What to observe: Noiseless same-basis results agree. Mismatched bases produce random results even without an observer.
  2. 02

    Sift and reveal

    Advance through matching bases and public tests.

    What to observe: Test bits are removed from the candidate string. Increasing the reveal fraction costs more bits but supplies more test data.
  3. 03

    Add an observer

    Intercept every signal, send a fresh batch and reveal tests.

    What to observe: The reference sifted error rate is one quarter with no other noise; finite records fluctuate.
  4. 04

    Inspect postprocessing

    Advance to the last stage and export the parity/hash audit.

    What to observe: Check the parity transcript, the public matrix seed and both output strings. Equal outputs still do not imply secrecy.