This condition is unavoidable because a perfect single-photon state is fundamentally impossible to prepare (although a good approximation can be produced with phenomena such as parametric downconversion).

Strictly speaking, the total number of multiphoton bit cells is a Gaussian random variable, and only its average and variance are determined. Still, based on these parameters, it can be bounded from above with any desired confidence level.

B. Slutsky, R. Rao, P.-C. Sun, Y. Fainman, “Security of quantum cryptography against individual attacks,” Phys. Rev. A (to be published).

D. Mayers, “Quantum key distribution and string oblivious transfer in noisy channels,” in Advances in Cryptology, CRYPTO’96, N. Kobitz, ed., Vol. 1109 of Springer Lecture Notes in Computer Science Series (Springer, New York, 1996), pp. 343–357.

Inconclusive bits are those whose value is not revealed with certainty by Bob’s measurement, for example, those measured in the wrong BB84 basis by Bob.1 Inconclusive bits are an integral feature of quantum cryptographic protocols, even in the absence of channel and detector imperfections.

Eve cannot use group information such as block checksums, revealed later in the protocol, because, by assumption, she must attack each bit independently of other bits.

The B92 curves in Fig. 5 are qualitatively similar to those in Fig. 4 of Ref. 20, although the latter are computed based on a suboptimal family of eavesdropping strategies and with Shannon rather than Renyi entropy.

Because individual bits are transmitted and received independently of one another, errors are distributed uniformly throughout raw data, regardless of the quantum cryptosystem used.

