wai-quantum 0.3.18

A deterministic quantum stack in pure Rust: byte-exact circuit simulation (statevector / stabilizer / tensor-network MPS / sparse-Pauli backends), error mitigation, qLDPC decoding, noise learning, circuit-equivalence proofs, a phasor interference-ML layer, information-theoretic limits, noisy channels and state tomography, and signed energy-accounted receipts. No QPU, no cloud, no system libraries — identical results native, in the browser, and as a WASI component at the edge.
Documentation
//! Quantum communication and security: key distribution, and why eavesdropping
//! on it is not a matter of being careful.
//!
//! Classical key exchange rests on a problem being hard to solve. Quantum key
//! distribution rests on measurement being destructive: an eavesdropper cannot
//! look at a state without disturbing it, and cannot copy it to look later. So
//! interception does not merely risk detection — it *leaves evidence in the error
//! rate*, and the legitimate parties measure that evidence directly.
//!
//! The protocols here run on the real simulator: states are prepared, rotated
//! into a measurement basis and sampled, and the collapse is applied. Given a
//! seed the whole run is reproducible, so a reported error rate is a fact about a
//! specific run that anyone can reproduce, not a number from a private die.

use crate::quantum::{fxmul, inv_sqrt2, Amp, Circuit, StateVector, FRAC, ONE};

fn splitmix64(s: &mut u64) -> u64 {
    *s = s.wrapping_add(0x9E37_79B9_7F4A_7C15);
    let mut z = *s;
    z = (z ^ (z >> 30)).wrapping_mul(0xBF58_476D_1CE4_E5B9);
    z = (z ^ (z >> 27)).wrapping_mul(0x94D0_49BB_1331_11EB);
    z ^ (z >> 31)
}
fn coin(s: &mut u64) -> bool {
    splitmix64(s) >> 63 == 1
}

/// Prepare `bit` in the Z basis (`false`) or the X basis (`true`).
fn prepare(bit: bool, x_basis: bool) -> StateVector {
    let mut c = Circuit::new(1);
    if bit {
        c.x(0);
    }
    if x_basis {
        c.h(0);
    }
    c.simulate().expect("one qubit")
}

/// Measure a single qubit in the chosen basis, returning the outcome. The state
/// is destroyed, which is the entire point — the caller must re-prepare to carry
/// anything forward, exactly as a real eavesdropper must.
fn measure(sv: &StateVector, x_basis: bool, rng: &mut u64) -> bool {
    // Rotate the chosen basis onto Z, then read the |0> weight. Measuring in the
    // X basis is measuring in Z after a Hadamard.
    let (a0, a1) = (sv.amps[0], sv.amps[1]);
    let p0 = if x_basis {
        let inv = inv_sqrt2();
        let h0 = Amp { re: fxmul(inv, a0.re + a1.re), im: fxmul(inv, a0.im + a1.im) };
        (h0.norm2() >> FRAC) as i64
    } else {
        (a0.norm2() >> FRAC) as i64
    };
    let draw = (splitmix64(rng) >> 11) as i64 % ONE;
    draw >= p0
}

/// The result of a BB84 run.
#[derive(Clone, Copy, Debug)]
pub struct Bb84 {
    pub rounds: u32,
    /// Rounds kept because Alice and Bob happened to choose the same basis.
    pub sifted: u32,
    /// Sifted rounds where their bits disagree.
    pub errors: u32,
    /// Quantum bit error rate over the sifted key, in parts per million.
    pub qber_ppm: u32,
    pub eavesdropper: bool,
}

/// Run BB84, optionally with an intercept-resend eavesdropper.
///
/// Alice sends a random bit in a random basis; Bob measures in a random basis;
/// they keep the rounds where the bases matched. With a quiet channel those bits
/// agree perfectly. An eavesdropper who measures and resends must guess the
/// basis, and guesses wrong half the time; when she does, Bob's outcome is random,
/// so **a quarter of the sifted key goes wrong**. That 25% is not a modelling
/// choice — it falls out of the geometry, and it is what makes interception
/// visible rather than merely risky.
pub fn bb84(rounds: u32, seed: u64, eavesdropper: bool) -> Bb84 {
    let mut rng = seed ^ 0xB1B8_4A55_1234_9E37;
    let (mut sifted, mut errors) = (0u32, 0u32);
    for _ in 0..rounds {
        let a_bit = coin(&mut rng);
        let a_basis = coin(&mut rng);
        let mut state = prepare(a_bit, a_basis);

        if eavesdropper {
            let e_basis = coin(&mut rng);
            let e_bit = measure(&state, e_basis, &mut rng);
            // she cannot copy it, so she must send *something* on: her own guess
            state = prepare(e_bit, e_basis);
        }

        let b_basis = coin(&mut rng);
        let b_bit = measure(&state, b_basis, &mut rng);

        if a_basis == b_basis {
            sifted += 1;
            if a_bit != b_bit {
                errors += 1;
            }
        }
    }
    let qber_ppm = if sifted == 0 { 0 } else { ((errors as u64 * 1_000_000) / sifted as u64) as u32 };
    Bb84 { rounds, sifted, errors, qber_ppm, eavesdropper }
}

/// How well a CNOT "copies" a qubit — the no-cloning theorem, made concrete.
///
/// Copying basis states is easy, and a CNOT does it perfectly. The theorem says
/// no single device can do that for *every* state, and this measures the price:
/// the same circuit applied to a superposition does not produce two copies, it
/// produces an entangled pair, and the fidelity against a true clone collapses.
pub fn clone_fidelity(x_basis_input: bool) -> f64 {
    // attempt: |psi> (x) |0>  --CNOT-->  hoping for |psi> (x) |psi>
    let mut attempt = Circuit::new(2);
    if x_basis_input {
        attempt.h(0);
    }
    attempt.cx(0, 1);
    let got = attempt.simulate().expect("two qubits");

    // the state a real cloner would have produced
    let mut ideal = Circuit::new(2);
    if x_basis_input {
        ideal.h(0);
        ideal.h(1);
    }
    let want = ideal.simulate().expect("two qubits");

    got.fidelity_fx(&want) as f64 / ONE as f64
}

#[cfg(test)]
mod tests {
    use super::*;

    /// A quiet channel gives a perfect key. Not "low error" — the sifted bits
    /// agree exactly, because when the bases match the measurement is
    /// deterministic.

    #[test]
    #[ignore]
    fn probe_bb84() {
        println!("\n  BB84, 20000 rounds");
        for eve in [false, true] {
            let r = bb84(20000, 7, eve);
            println!("   eavesdropper={:<5}  sifted {:>6}  errors {:>6}  QBER {:>7.4}",
                eve, r.sifted, r.errors, r.qber_ppm as f64 / 1e6);
        }
        println!("\n  cloning fidelity");
        println!("   |0> (basis state)   {:.6}", clone_fidelity(false));
        println!("   |+> (superposition) {:.6}", clone_fidelity(true));
    }

    #[test]
    fn a_quiet_channel_yields_a_perfect_key() {
        let r = bb84(4000, 7, false);
        assert_eq!(r.errors, 0, "no eavesdropper must mean no errors, got {}", r.errors);
        assert_eq!(r.qber_ppm, 0);
        // and roughly half the rounds survive sifting
        let frac = r.sifted as f64 / r.rounds as f64;
        assert!((frac - 0.5).abs() < 0.05, "sifted fraction {frac}, want ~1/2");
    }

    /// Intercept-resend costs a quarter of the key. This is the number that makes
    /// the protocol worth using: the eavesdropper cannot avoid it by being
    /// careful, because she cannot know which basis to use and cannot copy the
    /// state to decide later.
    #[test]
    fn intercept_resend_shows_up_as_a_quarter_of_the_key() {
        let r = bb84(6000, 11, true);
        let qber = r.qber_ppm as f64 / 1.0e6;
        assert!(
            (qber - 0.25).abs() < 0.03,
            "intercept-resend QBER should sit at 1/4, got {qber} ({} of {})",
            r.errors,
            r.sifted
        );
    }

    /// Same seed, same run — an error rate anyone can reproduce.
    #[test]
    fn runs_are_reproducible() {
        let a = bb84(500, 99, true);
        let b = bb84(500, 99, true);
        assert_eq!((a.sifted, a.errors), (b.sifted, b.errors));
        let c = bb84(500, 100, true);
        assert!((a.sifted, a.errors) != (c.sifted, c.errors) || a.rounds != c.rounds);
    }

    /// No-cloning, priced. A CNOT copies a basis state perfectly and a
    /// superposition not at all — it entangles instead.
    #[test]
    fn cloning_works_on_basis_states_and_fails_on_superpositions() {
        let basis = clone_fidelity(false);
        let superposed = clone_fidelity(true);
        assert!(basis > 0.999, "|0> should clone perfectly, got {basis}");
        assert!(
            superposed < 0.6,
            "|+> must NOT clone; a CNOT entangles instead, got fidelity {superposed}"
        );
    }
}