The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →In BB84, an eavesdropper who measures a photon without knowing how it was prepared can disturb it. Alice and Bob look for evidence of that disturbance by comparing a sample of their sifted bits and calculating the disagreement rate. This can tell them whether the transmission is safe enough to use under the protocol’s security analysis; it does not identify an attacker, and an error alone does not prove one was present.
How BB84 turns photon disturbance into an eavesdropping check
BB84 is a prepare-and-measure quantum key distribution (QKD) protocol. Alice sends quantum signals that encode random bits, and Bob measures them. In the ideal single-photon formulation, the protocol uses four possible states arranged in two bases. Those bases are incompatible: measuring a state in the wrong basis generally does not preserve the encoded information. Practical systems often use weak laser pulses rather than perfect single-photon sources. ETSI’s QKD components report describes these states and practical considerations.
- Alice prepares and sends signals. For each signal, she randomly chooses a bit and one of the two encoding bases.
- Bob measures each signal. He independently chooses a basis and records his result. When his basis differs from Alice’s, his result generally cannot be relied on to reveal her bit.
- They sift their results. Over a classical channel, Alice and Bob announce which bases they used, not the bit values they intend to keep. They retain detections where their bases matched and discard the rest.
- They test a sample. They publicly compare some of the retained bit values and count disagreements. The error rate in this sample estimates the quantum bit error rate, or QBER, in the sifted material.
- They decide whether to continue. They use the estimate and other protocol parameters in a security analysis. If the run cannot support a secure final key, they abort rather than use the material.
The sample is disclosed so the parties can estimate errors while leaving other sifted bits undisclosed. A disagreement may be consistent with disturbance from an interceptor, but it can also come from ordinary channel or detector noise. QBER is a statistical input to a security decision, not an alarm that names or proves the presence of an eavesdropper. NIST’s overview of QKD post-processing stages explains parameter estimation, reconciliation and privacy amplification.
What an interception would do
Suppose Eve intercepts each photon, measures it in a randomly chosen BB84 basis, and sends Bob a replacement. If she chooses the wrong basis, her measurement can disturb the state; that disturbance may show up as a mismatch when Alice and Bob test their sifted bits. This is the intuition behind the protocol’s check, not a universal numerical threshold or a guarantee that every attack creates an obvious error pattern.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11#1 Best Overall
The National Institute of Standards and Technology (NIST) summarizes the idealized principle this way: “If someone tries to peek or record the information, the very act of observing the data destroys the fragile quantum state.” That explanation describes the quantum-state principle; practical devices are imperfect, so the observed error rate must be interpreted within a security analysis. NIST, “What Is Quantum Cryptography?”
Why a measured error rate is not a universal cutoff
There is no single QBER number that applies to every QKD protocol, device, implementation or security proof. Noise can raise the observed rate without an attacker, finite samples make an estimate uncertain, and a low rate by itself does not establish that a system is secure. The parties must assess the measured parameters under the assumptions and proof applicable to their system.
A NIST-hosted paper, “Worldwide standardization activity for quantum key distribution”, reports that some error-correction configurations can extract secret bits while dealing with QBER “up to 11%.” That is a figure from the paper’s described setting, not a general BB84 alarm threshold or a blanket assurance for current QKD equipment.
What happens after the disturbance test
Passing the test does not mean the sifted bits are already a finished encryption key. If the run remains eligible, Alice and Bob use classical reconciliation to correct residual mismatches. Reconciliation reveals some information, which the security calculation must account for. They then apply privacy amplification to shorten the shared material and reduce any information an attacker may have about the final key. If the available security margin is insufficient, they do not produce a key from that run. NIST’s description of QKD stages distinguishes parameter estimation from these later steps.
Practical limits that affect the check
Weak pulses and multiple photons
Many practical transmitters use weak coherent laser pulses, which sometimes contain more than one photon. That creates risks not captured by the simplest picture of Eve measuring and resending a single photon: a photon-number-splitting attack can obtain information from multi-photon signals without necessarily producing the same straightforward error pattern. Decoy-state methods use observed statistics to estimate the single-photon contribution. ETSI discusses weak coherent sources and decoy states in its QKD components report.
Imperfect sources and detectors
Real devices do not behave exactly like idealized components. Sources may emit multiple photons, and detectors may fail to register every photon; implementation flaws can create opportunities that a simplified protocol description does not cover. NIST warns that “An eavesdropper can exploit these imperfections to evade detection.” The security of a deployed system therefore depends on its implementation and the protections covered by its security analysis, not only on the abstract BB84 idea. NIST, “What Is Quantum Cryptography?”
The classical channel must be authenticated
Basis announcements and later post-processing travel over a classical channel. That channel need not be secret, but it must be authenticated so Alice and Bob can verify who they are communicating with. Without authentication, an attacker could impersonate each party to the other in a man-in-the-middle attack. NIST’s 2003 report discusses such attacks against particular QKD protocols and cautions that a proof against specified attacks is not proof against every possible attack. NIST IR 6977, “Vulnerabilities in Quantum Key Distribution Protocols”.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How other QKD approaches signal trouble
BB84 is not the only approach, and not every family relies on the same detection signal or device assumptions.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesBest Value
| Approach | What is assessed | Important qualification |
|---|---|---|
| Prepare-and-measure BB84 | Errors in sampled, sifted-key bits after Alice and Bob compare bases | Practical weak coherent pulse implementations may use decoy states to estimate single-photon events. |
| Entanglement-based E91 | Correlations between measurements, including tests based on Bell inequalities | The correlation test and security analysis depend on the protocol and implementation. |
| Measurement-device-independent QKD | Uses a design intended to address detector-side imperfections and side channels | It addresses detector risks; it does not eliminate every implementation risk. |
These distinctions are described in ETSI GR QKD 003. Across approaches, the broader principle remains: the parties evaluate observed data under a security model, rather than treating one unusual measurement as proof of an identified intruder.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




