Lab · Quantum security
Catch an eavesdropper with physics
BB84 is the original quantum key distribution protocol. Its security doesn't rest on maths being hard; it rests on the fact that measuring a quantum state disturbs it. Play with it below.
Encode
Alice sends each bit as a single photon, polarised in one of two randomly chosen bases: rectilinear (↕ ↔) or diagonal (⤢ ⤡).
Measure
Bob measures every photon in his own random basis. When his basis matches Alice's he reads the bit perfectly; otherwise he gets a coin flip.
Sift & check
They publicly compare bases (never bits), keep the matches, and sacrifice a sample to measure the error rate. Too many errors means someone was listening.
Controls
Try it: transmit with Eve at 0%, then drag her to 100%. Her measurements disturb the photons and the error rate jumps to ~25%.
256
Photons sent
114
Bases matched
57
Bits checked
57
Key bits left
Measured error rate (QBER)
0.0%
Channel secure
QBER is below the 11.0% threshold, so Alice and Bob keep a 57-bit key.
First 24 photons
kept error
| Alice bit | 1 | 0 | 1 | 0 | 0 | 1 | 0 | 1 | 1 | 0 | 0 | 0 | 1 | 0 | 1 | 0 | 1 | 0 | 0 | 0 | 1 | 1 | 1 | 1 |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Alice basis | + | × | + | + | + | + | + | + | × | × | × | + | + | × | + | × | × | × | + | × | + | + | × | + |
| Photon sent | ↔ | ⤢ | ↔ | ↕ | ↕ | ↔ | ↕ | ↔ | ⤡ | ⤢ | ⤢ | ↕ | ↔ | ⤢ | ↔ | ⤢ | ⤡ | ⤢ | ↕ | ⤢ | ↔ | ↔ | ⤡ | ↔ |
| Eve | · | · | · | · | · | · | · | · | · | · | · | · | · | · | · | · | · | · | · | · | · | · | · | · |
| Bob basis | × | + | × | + | + | × | + | + | + | × | × | + | × | + | + | + | × | × | + | + | × | × | × | + |
| Bob bit | 0 | 0 | 1 | 0 | 0 | 0 | 0 | 1 | 0 | 0 | 0 | 0 | 0 | 1 | 1 | 1 | 1 | 0 | 0 | 0 | 1 | 1 | 1 | 1 |
| Match? | – | – | – | ✓ | ✓ | – | ✓ | ✓ | – | ✓ | ✓ | ✓ | – | – | ✓ | – | ✓ | ✓ | ✓ | – | – | – | ✓ | ✓ |
Error rate vs eavesdropping
Expected QBER as Eve intercepts more photons (at 1.0% channel noise). The dot is your last run.
Show data table
| Point | Expected QBER |
|---|---|
| 0% | 1.0% |
| 5% | 2.2% |
| 10% | 3.5% |
| 15% | 4.7% |
| 20% | 5.9% |
| 25% | 7.1% |
| 30% | 8.3% |
| 35% | 9.6% |
| 40% | 11% |
| 45% | 12% |
| 50% | 13% |
| 55% | 14% |
| 60% | 16% |
| 65% | 17% |
| 70% | 18% |
| 75% | 19% |
| 80% | 21% |
| 85% | 22% |
| 90% | 23% |
| 95% | 24% |
| 100% | 26% |
Shared secret key
1a05aa788bbfc8
In a real system this key would go through error correction and privacy amplification, then encrypt data with a one-time pad or AES.
Why this matters
Physics is only half the story
QKD detects eavesdroppers, but Alice and Bob still need an authenticated classical channel to compare bases. Otherwise Eve can simply pretend to be Bob. Today that usually means pre-shared keys, which don't scale.
Post-quantum cryptography (PQC) can authenticate that channel with signatures designed to resist quantum computers. Combining the two gives a hybrid scheme that stays secure even if one layer is broken.
Hybrid PQC–QKD security algorithms: First paper in progress · 2026
Talk research with me