Same B92 (Bennett, 1992) protocol and event-by-event physics as the 3D version, flattened onto a pannable, zoomable channel diagram. Alice encodes each bit into one of two non-orthogonal states instead of BB84's four:
bit 0 → |0⟩
bit 1 → |+⟩ = (|0⟩ + |1⟩)/√2 (45° from |0⟩)
⟨0|+⟩ = 1/√2 → the states are NOT orthogonal
Bob randomly measures each photon in the Z basis {|0⟩,|1⟩} or the X basis {|+⟩,|−⟩} (50/50, his own choice, unknown to Alice). Because the states overlap, only two outcomes are ever conclusive:
Z-basis result |1⟩ → bit must have been 1 (|0⟩ can never yield |1⟩)
X-basis result |−⟩ → bit must have been 0 (|+⟩ can never yield |−⟩)
anything else → inconclusive, discarded
Each of those two discriminating outcomes needs the right basis (P=1/2) and the right random projection (P=1/2), so only P = 1/2 × 1/2 = 25% of photons survive sifting — half BB84's efficiency, the price of using one basis pair per bit value instead of two.
Non-orthogonal states can't be copied (no-cloning theorem), so an intercept-resend eavesdropper (toggle "Eve" on) is forced to measure and re-encode each photon herself. Whenever her own measurement is inconclusive (75% of the time) she must guess a bit blind, and that guess disagrees with Alice's original bit half the time — a per-photon error probability of 0.75 × 0.5 = 37.5% among the photons Bob later keeps, exactly the signal Alice and Bob use to detect an eavesdropper by comparing a public subset of the key.
- Transmission rate — how many photons per second Alice sends; watch the sifted-key panel and channel diagram fill in faster.
- Eve toggle — switches the intercept-resend attacker on the channel; QBER should sit near 0% off and climb toward ~37.5% on.
- Drag / scroll — pan across the channel and zoom in on the growing sifted-key grid below it.