Source-linked AI summary

Multidimensional reconciliation for continuous-variable quantum key distribution

Anthony Leverrier, Romain Alléaume, Joseph Boutros, Gilles Zémor, Philippe Grangier

arXiv:0712.3823v2quant-phcs.IT

TL;DR

Imperfect reconciliation limits the rate and distance of continuous-variable QKD. The paper proposes octonion-based eight-dimensional reconciliation without postselection, enabling secure QKD over more than 50 km.

  • Problem

    Imperfect reconciliation limits both the rate and distance of continuous-variable QKD.

  • Method

    The paper presents an eight-dimensional reconciliation protocol based on octonions, without postselection and with proven security.

  • Results

    More than 50 km of secure QKD is achieved without postselection.

  • Takeaways & Limitations

    The protocol enables continuous-variable QKD over longer distances without postselection while retaining proven security.

Abstract

from arXiv · show

We propose a method for extracting an errorless secret key in a continuous-variable quantum key distribution protocol, which is based on Gaussian modulation of coherent states and homodyne detection. The crucial feature is an eight-dimensional reconciliation method, based on the algebraic properties of octonions. Since the protocol does not use any postselection, it can be proven secure against arbitrary collective attacks, by using well-established theorems on the optimality of Gaussian attacks. By using this new coding scheme with an appropriate signal to noise ratio, the distance for secure continuous-variable quantum key distribution can be significantly extended.

I. INTR ODUCTION

The paper targets the reconciliation bottleneck in Gaussian-modulated continuous-variable QKD by introducing an octonion-based approach that avoids postselection while extending secure operation beyond 50 km. Its method uses higher-dimensional structure to separate states without sacrificing the security arguments available for non-postselected protocols.

  • Protocol: Gaussian-modulated coherent-state QKD uses homodyne detection to generate correlated continuous variables from which a secret key can be extracted.Alice samples (X_A, P_A) from N(0, V_A), sends the corresponding coherent state, and Bob randomly measures one quadrature.
  • Motivation: Imperfect reconciliation limits both the key rate and the operational range of continuous-variable QKD.The reconciliation step must extract the available information from correlated variables shared after the quantum stage.
  • Security limitation: Postselection improves sign discrimination for low-amplitude Gaussian data but weakens security because the optimal attack is unknown for postselected protocols.The resulting secret rate can be calculated only for restricted attack classes, unlike the non-postselected Gaussian-modulated protocol.

I I. RECONCILIA TION AND SECURITY

The section formulates secret-key security under reverse reconciliation and shows how reconciliation efficiency limits the achievable key rate. It also identifies conditions under which Eve’s information remains bounded by the original quantum mutual information.

  • Reverse reconciliation: Reverse reconciliation extracts the final key from Bob’s data, with Bob sending authenticated classical information to help Alice correct errors.The protocol uses reverse rather than one-way reconciliation because Bob–Eve quantum mutual information is smaller than Alice–Eve mutual information.
  • Ideal security range: For sufficiently low excess noise, K is strictly positive for any transmission, so the ideal protocol has no theoretical range limitation.This statement assumes access to a perfect reconciliation scheme that extracts all information available in the correlated data.
  • Rate limitation: Imperfect reconciliation limits the protocol range because the effective key rate reaches zero for finite channel transmission.The ideal rate K is relevant only with perfect reconciliation, whereas practical reconciliation requires accounting for the information revealed through α.
  • Reconciliation protocol: A reconciliation code of size N must satisfy log2(N) ≤ I(x; y), and successful decoding produces a common string U with H(U|y, α) = 0.Alice sends syndrome information α, allowing Bob to recover U from y and α; privacy amplification then converts U into a secret key.
  • Security bound: When α is independent of U, the reconciliation leakage obeys S(U : E, α) ≤ S(x : E), preserving the original bound on Eve’s information.The result follows from the lemma for independent classical variables and from choosing U independently of x.

I I I. RECONCILIA TION OF BINAR Y · V ARIABLES

Reconciliation extracts common information from correlated data and can be formulated as a channel-coding problem for binary variables. The section explains coset coding with linear codes and identifies the generalization to continuous variables as the central question.

  • V ARIABLES: Reconciliation enables Alice and Bob to extract common information from correlated data.
  • V ARIABLES: For binary strings, reconciliation resembles channel coding, where Alice’s messages pass through a noisy channel to Bob.
  • V ARIABLES: Shannon’s theorem bounds the code size |C| by the mutual information between Alice and Bob.
  • V ARIABLES: Unlike channel coding, reconciliation does not let Alice choose or restrict the transmitted word to a codeword.
  • V ARIABLES: Alice can instead describe a coset containing her word, allowing Bob to recover a shared bit sequence when the code matches the channel.
  • V ARIABLES: With a linear code C and parity-check matrix H, Alice can send the syndrome H·x, defining the coset containing x.
  • V ARIABLES: The side information sent over the authenticated classical channel acts as a coordinate change that transforms reconciliation into channel coding.
  • V ARIABLES: The section asks whether this reconciliation framework can be generalized from binary to continuous variables.

IV. RECONCILIA TION OF GA USSIAN · V ARIABLES · A. Gaussian mo dulation

Gaussian modulation replaces the uniform variable distribution used in discrete protocols with a spherical Gaussian setting, motivating spherical codes for continuous-variable reconciliation. A continuous transformation enabling the analogue of discrete side information exists only in dimensions 1, 2, 4, or 8, yielding the octonionic eight-dimensional case.

  • A. Gaussian modulation: Gaussian modulation uses a non-uniform Gaussian distribution on R^n instead of the uniform distribution used for discrete protocols.Uniformity is important for proving that Alice’s public side information does not reveal relevant information about her chosen codeword.
  • A. Gaussian modulation: Binary LDPC and turbo codes can be adapted to binary spherical codes and optimized for BPSK modulation over AWGN.At low SNR, a binary code optimized for BPSK can almost achieve the Shannon limit for Gaussian modulation.
  • A. Gaussian modulation: The same dimensional restriction follows because the map produces n − 1 independent vector fields on the unit sphere S^(n−1).The only spheres admitting this structure are the unit spheres associated with R, R^2, the quaternions, and the octonions.

V. R OT A TIONS ON S1 · AND S7 · A. Existen e

The section asks whether the required application M exists, can be computed efficiently, and leaks information to Eve. It establishes existence in dimensions 2, 4, and 8 through rotations, complex numbers, quaternions, and octonions.

  • AND S7: The construction must address existence, efficient computation by Alice, and possible information leakage to Eve.These are identified as three questions following the restriction that M can exist only in R and R^2.
  • AND S7: The trivial R case corresponds to encoding one bit in the sign of a Gaussian variable.This is identified as the unit-sphere case {−1, 1}.
  • A. Existen e: For R^2, the required application M is the rotation centered at the angle between x and the x-axis.This rotation verifies M(x, y)·x = y for the unit circle.
  • A. Existen e: The two-dimensional construction can alternatively identify x and y with complex numbers of modulus 1.The passage presents this as an alternative description of the same case.
  • A. Existen e: The same type of construction extends to dimensions 4 and 8.The cited passage explicitly states that the corresponding cases are dimensions 4 and 8.
  • A. Existen e: In dimension 4, the relevant unit representation uses quaternion units.The passage groups the quaternion and octonion descriptions with valid constructions in the higher-dimensional cases.
  • A. Existen e: In dimension 8, the construction uses octonion units, and a valid division exists.The statement links the octonion-unit identification to the existence of a valid division.

B. Computation of M(x, y)

For n = 2, 4, and 8, suitable orthogonal matrix families define a continuous function M(x, y) that maps x to y while preserving orthogonality. In the QKD protocol, communicating α(x, u) lets Bob compute a noisy version of u whose noise is Gaussian and has the same variance as his noise on x.

  • Matrix construction: For n = 2, 4, and 8, non-unique families of n orthogonal matrices define the construction of M.The matrices satisfy the stated anticommutation relations for indices i, j > 1.
  • QKD application: In the QKD protocol, Alice sends Bob α(x, u), enabling him to compute M(x, u)y, a noisy version of u.Alice chooses u randomly from a finite code.
  • Noise behavior: The final noise is a rotated version of Bob’s noise on x, with both noises Gaussian and having the same variance.Thus the transformation changes the noise orientation without changing these stated distributional properties.

C. No leak age of information

The section argues that α = M(x, u) reveals no information about u by establishing their independence. The argument uses a spherical code and a transformation with constant Jacobian equal to 1.

  • No leakage of information: The no-leakage condition is that u and α = M(x, u) are independent.This is expressed through equality of the conditional and prior probabilities for each codeword u_i.
  • No leakage of information: For the spherical code CN = {u1, . . . , uN}, the required condition is stated as Pr(u = ui|M(x, u) = α) = Pr(u = ui) = 1.The passage presents this probability identity as the criterion for independence.
  • No leakage of information: The mapping has a constant Jacobian equal to 1 for each u ∈ CN.The Jacobian argument is supported by lines that form an orthonormal system.

CONTINUOUS-V ARIABLE QKD

In continuous-variable QKD, the secret-key rate depends on the signal-to-noise ratio, which can be optimized through the modulation variance. Rotations in R8 achieve comparable reconciliation efficiency to slice reconciliation while enabling longer-distance QKD under the stated experimental conditions.

  • Secret-key rate and SNR: The secret key rate is a function of the SNR for fixed transmission and excess noise, and modulation variance can optimize it.The SNR is the ratio of signal variance to noise variance and quantifies mutual information for Gaussian modulation over a Gaussian channel.
  • Performance comparison: Both approaches achieve comparable reconciliation efficiencies around 90%, but at different SNR.Figure 3 compares rotations in R8 with slice reconciliation for the experimental parameters of the Institut d'Optique QKD system.
  • Performance comparison: For low loss and short distance, slice reconciliation performs better, whereas rotations in R8 enable QKD over longer distances.The reported distinction is between low-loss performance and the longer-distance regime.
  • Performance comparison: Over 50 km is achievable with rotations in R8 using the current experimental parameters.The figure discussion identifies this as the longer-distance regime enabled by rotations in R8.
  • Computational complexity: The presented reconciliation has lower complexity than slice reconciliation because most computing time is spent decoding binary codes and rotations require negligible additional computation.Slice reconciliation uses several codes, one per slice, whereas the presented method avoids that overhead.

I. CONCLUSION … 2. Examples

The proposed reconciliation protocol addresses the low signal-to-noise regime of continuous-variable QKD, enabling operation over more than 50 km without post-selection while retaining security against general collective attacks. The surrounding material introduces 4^2 × 2 × 2 matrices and lists foundational, security, coding, and experimental references.

  • I. CONCLUSION: The paper presents a protocol for reconciling correlated Gaussian variables, targeting the information-extraction bottleneck that limits continuous-variable QKD range and key-distribution rate.The method is particularly adapted to low signal-to-noise ratios encountered in long-distance QKD.
  • I. CONCLUSION: More than 50 km: the reconciliation method allows QKD over distances exceeding 50 km using the experimental parameters of the Institut d’Optique link.The distance claim is tied to the current experimental parameters of the referenced QKD link.
  • I. CONCLUSION: No post-selection: unlike other proposed range-extension protocols, this protocol requires no post-selection.This preserves the security proofs based on the optimality of Gaussian attacks.
  • I. CONCLUSION: Security against general collective attacks: the security proofs remain valid because they rely on the optimality of Gaussian attacks.The conclusion explicitly states that the protocol is secure against general collective attacks.
  • 2. Examples: The examples section lists prior work on quantum key distribution, continuous-variable protocols, security, information theory, and coding theory.The references include foundational QKD papers, Gaussian-attack security results, coding references, and an experimental QKD-link reference.
Loading 0712.3823v2…