Source-linked AI summary

The Security of Practical Quantum Key Distribution

Valerio Scarani, Helle Bechmann-Pasquinucci, Nicolas J. Cerf, Miloslav Dusek, Norbert Lutkenhaus, Momtchil Peev

arXiv:0802.4155v3quant-ph

TL;DR

Practical QKD requires security analyses that account for real experimental effects while remaining theoretically sound. This paper reviews practical QKD and develops tools for assessing discrete-variable, continuous-variable, and distributed-phase-reference platforms, emphasizing composable security and systematic comparison.

  • Problem

    Practical QKD needs security models and comparisons that incorporate experimental imperfections while guiding theoretically valid claims about device security.

  • Method

    The paper reviews practical QKD, develops security-analysis tools across major experimental platforms, and emphasizes composable security for key use in arbitrary applications.

  • Results

    The review presents security bounds and analyses for discrete-variable, continuous-variable, and distributed-phase-reference QKD, including comparisons across practical platforms.

  • Takeaways & Limitations

    Practical QKD security depends on composable post-processing and platform-specific analyses that account for implementation constraints and channel effects.

  • Takeaways & Limitations

    Security results for discrete-modulation continuous-variable QKD are complete only when the quantum channel adds no excess noise.

Abstract

from arXiv · show

Quantum key distribution (QKD) is the first quantum information task to reach the level of mature technology, already fit for commercialization. It aims at the creation of a secret key between authorized partners connected by a quantum channel and a classical authenticated channel. The security of the key can in principle be guaranteed without putting any restriction on the eavesdropper's power. The first two sections provide a concise up-to-date review of QKD, biased toward the practical side. The rest of the paper presents the essential theoretical tools that have been developed to assess the security of the main experimental platforms (discrete variables, continuous variables and distributed-phase-reference protocols).

I. INTRODUCTION … 5. An example of eavesdropping

The paper introduces QKD as a quantum-physics-based approach to distributing secret keys, with security against unrestricted eavesdropping in principle. It explains the generic setting, practical light-based implementation, BB84, and how intercept-resend attacks reveal security limits.

  • A. Cryptography: Classical cryptography seeks confidential communication, while QKD addresses the key-distribution problem using quantum physics.The review focuses on key distribution rather than only message encryption; secret keys can also authenticate messages.
  • 1. Generic setting: QKD connects Alice and Bob through a quantum channel for signals and an authenticated classical channel for public communication.Eve may listen to the classical channel but can manipulate the quantum channel subject only to physical laws.
  • 2. The origin of security: QKD security arises because extracting information from quantum states disturbs them, while perfect copying of unknown quantum states is forbidden.These principles motivate unconditional security, which has been proved for several QKD protocols.
  • 3. The choice of light: Light is the practical choice for QKD because its quantum states can travel macroscopic distances with little decoherence, although losses remain a central problem.Practical quantum channels therefore use optical fiber or free space with line of sight.
  • 4. The BB84 protocol: BB84 encodes bits in four single-photon polarization states across two complementary bases, which Alice and Bob later compare during sifting.They discard events measured in different bases, leaving a raw key of approximately N/2 bits.
  • 4. The BB84 protocol: After sifting, Alice and Bob estimate the error rate, correct discrepancies, and remove information potentially obtained by Eve through classical post-processing.In the absence of errors, the identical raw key is already secret; otherwise error correction and privacy amplification are required.
  • 5. An example of eavesdropping: In intercept-resend, Eve measures each intercepted photon in a random basis and resends it, gaining information while introducing detectable errors.This attack gives Eve full information on half of the raw-key bits, IE = 0.5, and produces Q = 0.25.
  • 5. An example of eavesdropping: Q >∼17% prevents secure-key extraction under the stated post-processing assumptions because Eve’s information exceeds Bob’s.For an attack on fraction p of photons, Q = p/4 and IE = p/2 = 2Q; at Q = 0.25, I(A : B) < IE.

6. Beyond the example: the field of QKD … 2. Quantum information processing

The review traces QKD from foundational protocols and experimental milestones to practical security, emphasizing the need to reconcile rigorous proofs with real devices, competing platforms, and implementation vulnerabilities. It also explains how QKD protocols use non-orthogonal states, incompatible measurements, and equivalent entanglement-based descriptions to assess and extract secrecy.

  • 6. Beyond the example: the field of QKD: QKD developed by addressing whether security holds against unrestricted eavesdropping, which protocols and encodings are useful, how closely implementations realize qubits, and what side-channel threats devices introduce.The field evolved in response to these questions about unconditional security, alternative processing, physical realizations, and neglected leakage channels.
  • C. Scope of this review; 1. Focus: Practical QKD occupies the interface between theory and experiment, requiring theorists to model real effects and experimentalists to understand security claims and formulas.The review focuses on this middle ground rather than purely abstract or strictly technological work.
  • 1. Focus; 2. Outline: The review updates security proofs, compares experimental platforms and their shortcomings, and balances secret-key rate and distance against practical factors such as stability and cost.Its structure proceeds from QKD fundamentals and key-generation rates to detailed platform analyses, comparisons, and future perspectives.
  • A. Milestones; 1. Foundations: 1984-1995; 2. The theory-experiment gap opens: 1993-2000: BB84 established qubit coding in two complementary bases, while subsequent demonstrations in laboratory and installed fibers showed that QKD could become robust enough for real-world implementation.Plug&Play setups were an important experimental milestone, and entangled-QKD demonstrations had also appeared by 2000.
  • 2. The theory-experiment gap opens: 1993-2000: By 2000, theoretical advances and experiments had progressed substantially, but security proofs still treated idealized schemes while practical setups neglected important security issues.The resulting theory–experiment gap became especially visible as new protocols and rigorous proofs were developed.
  • 3. Closing the gap: 2000 to present: t^2 versus t: attenuated laser pulses exposed photon-number-splitting vulnerabilities, making extractable key rates scale worse with distance than for single-photon sources.SARG04 improved the scaling to t^3/2 through modified BB84 announcements, while varying the quantum state provided another hardware-based improvement.
  • B. Generic QKD Protocol; 1. Classical and quantum channels: QKD requires a quantum channel, where Eve’s interaction changes signals, and an authenticated classical channel, which Eve may hear but not alter; authentication requires preshared secrecy for unconditional security.Thus QKD expands a short secret key into a longer one rather than creating secrecy from nothing.
  • 2. Quantum information processing: Protocols use non-orthogonal states and non-compatible measurements so Bob can decode signals while estimating coherence loss and Eve’s information; prepare-and-measure schemes translate directly into entanglement-based security proofs.No key can be extracted from an entanglement-breaking channel, although more general private states may involve shielding systems and are not treated as practical schemes here.

3. Classical information processing … 1. Three families

The paper develops QKD security from classical post-processing, composable security definitions, and explicit proof techniques, then organizes practical protocols into discrete-variable, continuous-variable, and distributed-phase-reference families. Practical performance depends on finite-key effects, implementation conditions, detection technology, and classical processing choices.

  • 3. Classical information processing: Parameter estimation extracts channel error, coherence-loss, transmission, and detection statistics after quantum transmission, forming the basis for subsequent classical processing.Alice and Bob exchange classical communication after measuring N signals on the quantum channel.
  • 4. Secret fraction and secret key rate: The practical secret key rate is the product of the secret fraction and raw-key rate, whose dominant dependence is on source repetition, channel loss, detector efficiency, dead time, and duty cycle.The raw-key rate also includes protocol-dependent sifting factors.
  • 4. Secret fraction and secret key rate: Finite-key corrections reduce the secret fraction because parameter estimation must accommodate statistical fluctuations and classical post-processing includes terms that vanish only asymptotically.The asymptotic secret fraction is therefore not directly representative of finite-length keys.
  • 1. Unconditional security, and its conditions: Unconditional security permits arbitrary eavesdropper resources and techniques, but requires protected devices, trusted randomness, authenticated classical communication, and an eavesdropper obeying quantum physics.Security also requires that theoretical signal descriptions match implementations and that side-channel leakage or back-doors be excluded.
  • 2. Definition of security: A composable security definition bounds deviation from a perfect key by ε and guarantees security regardless of the key’s application; the trace-norm criterion gives ε the meaning of maximum extraction-failure probability.The criterion is 1/2∥ρKE −τK ⊗ρE∥1 ≤ε.
  • 3. Security proofs: Security proofs convert the trace-norm requirement into an extractable-key length using concentration inequalities, with failure probability exponentially small when ℓ<∼F(ρKE, ε).Approaches include uncertainty principles, entanglement-distillation correspondences, and information-theoretical techniques.
  • 1. Three families: Continuous-variable performance depends crucially on classical key extraction: reverse reconciliation and post-selection are important tools, while squeezed-state heterodyne protocols have the highest rate and range among Gaussian protocols.The highest rate and range require a source of squeezed light.

E. Sources … 1. Fiber Links

The paper reviews practical QKD sources and channels, emphasizing laser-based implementations, multiphoton security issues, entangled-photon generation, transmission losses, and fiber-specific decoherence. Practical security depends on source characterization, phase handling, and accounting for channel and multiphoton effects.

  • 1. Lasers: Lasers are the most practical and versatile light sources, so most QKD implementations use them as prepare-and-measure sources.A laser output in a given mode is described by a coherent state.
  • 1. Lasers: Phase references are essential for continuous-variable and distributed-phase-reference protocols but irrelevant to attenuated-laser qubit protocols.A physically available phase reference can nevertheless create coherence that requires active randomization.
  • 1. Lasers: Laser signals described by photon-number mixtures enable photon-number-splitting attacks, a major practical QKD security concern.The state commutes with photon-number measurement, opening the possibility of PNS attacks.
  • 2. Sub-Poissonian Sources: Sub-Poissonian sources reduce the probability of emitting two photons and are evaluated using g2(0), which is smaller for sources closer to ideal single-photon behavior.For Poissonian sources, g2(0) = 1, and g2(0) ≈2p(2)/p(1)2.
  • 2. Sub-Poissonian Sources: Sub-Poissonian sources attracted QKD research because they can achieve higher secret fractions and have been tested experimentally, including in fibers.Their relevance was triggered by the discovery of PNS attacks.
  • 3. Sources of Entangled Photons: SPDC predominantly generates entangled photon pairs for entanglement-based QKD and heralded sub-Poissonian sources, but discrete-variable protocols must account for multipair components.The ideal single-pair regime requires λ ≪1, equivalently a mean pair number per pulse µ = 2λ2/(1 −λ2) ≪1.
  • 3. Sources of Entangled Photons: Quantum-dot entangled-photon sources remain at an early development stage because they require a cryogenic environment, while cw-pumped SPDC may require continuum frequency-mode modeling.For cw pumping or pulse durations much larger than the photons’ coherence time τ, the four-mode approximation is not applicable.
  • 1. Fiber Links: Fiber transmission losses decrease exponentially with length, are lowest near 1550nm at α ≃0.2dB/km, and interact with dispersion and decoherence to limit QKD performance.Raw key rates decrease with transmission, dark counts limit maximal distance, and lost photons can leak information to Eve.

2. Free Space Links … A. Raw key rate

Practical QKD performance depends on channel losses, detector and synchronization constraints, coding architecture, and the balance between raw key generation and secret fraction. The raw key rate is limited by hardware-dependent repetition rates, detector dead time, and setup duty cycles.

  • 2. Free Space Links: Free-space QKD supports rooftop, ground-space, and space-space links, with negligible decoherence but geometric and atmospheric losses, including scintillation.Geometric losses depend on telescope apertures, beam divergence, alignment, and turbulence; atmospheric losses arise from scattering and scintillation.
  • 1. Photon Counters: Photon counters are characterized by quantum efficiency η, dark-count rate pd, and detector dead time, with APDs commonly used across visible and telecom wavelengths.Si APDs cover approximately 400–1000nm, while InGaAs/InP devices are commonly used from about 950nm to 1650nm.
  • 2. Homodyne Detection: Homodyne detection measures light quadratures by mixing a signal with a stronger local oscillator at a balanced beam splitter and measuring output intensity differences.The measured quadrature depends on the signal–local-oscillator phase difference, which must remain stable and generally requires transmitting the local oscillator with the signal.
  • 2. Homodyne Detection: 80% detection efficiency enables homodyne detection to operate in principle at GHz repetition rates, but complementary-quadrature uncertainty and transmission losses introduce intrinsic noise.Detector and electronics generate excess noise, which can be reduced to 20 dB below shot noise in real systems, subject to spectral-window constraints.
  • H. Synchronization and alignment: Synchronization and alignment are technically solvable but require secure synchronization channels and stabilization of polarization directions or interferometers.Decoherence-free coding avoids alignment but is highly impractical because it requires complex multiphoton preparation and measurement and is very sensitive to losses.
  • 2. Phase coding: two configurations: Phase-coded QKD uses one-way or Plug&Play configurations; Plug&Play self-stabilizes interferometers and can compensate channel polarization effects with a Faraday mirror.The configuration has an intrinsic long-distance duty-cycle limitation and raises security concerns because Eve may modify the Bob-to-Alice path.
  • 2. Phase coding: two configurations: Plug&Play remains an important practical-QKD milestone because first commercial QKD systems were based on it, despite stabilized one-way systems exceeding 99% optical visibility.Stabilized one-way configurations also have a less constraining duty cycle.
  • A. Raw key rate: The secret key rate K is the product of raw key rate R and secret fraction r, while R depends on protocol, hardware losses, detectors, source repetition rate, and setup constraints.For pulsed sources, νS is the pulse-source repetition rate; detector dead time limits useful light, and duty cycles impose a minimum interval Tdc between pulses.

B. Secret fraction · 1. Classical information post-processing · 2. Individual, Collective and Coherent Attacks

Secret-key extraction combines error correction and privacy amplification, while two-way and pre-processing methods can improve tolerable error rates. Security is analyzed progressively from individual and collective attacks to general coherent attacks, with unconditional bounds established in many cases.

  • 1. Classical information post-processing: One-way post-processing first uses error correction to create perfectly correlated lists, bounded by the mutual information I(A : B), then privacy amplification to remove Eve’s information.The removed fraction is min (IEA, IEB), selecting the raw key on which Eve has less information.
  • 1. Classical information post-processing: Practical error-correction codes fall short of Shannon’s bound, so theoretical estimates should remove 10-20% more bits, with final performance evaluated for each code.Implemented codes such as Cascade use two-way communication, which can be incorporated into a one-way framework by revealing error positions or encrypting the reconciliation data.
  • 1. Classical information post-processing: Two-way post-processing and local random pre-processing can improve bounds and extract secret keys where one-way post-processing fails, although the optimal two-way procedure remains unknown.These methods can push the critical tolerable error rate higher.
  • 2. Individual, Collective and Coherent Attacks: Individual attacks independently target each transmitted system using the same strategy, and Eve must measure her ancillae before classical post-processing begins.The resulting classical variables form a product probability distribution, and one-way security uses the Csiszár-Körner bound.
  • 1. Classical information post-processing: 11% is the critical QBER for BB84 with single-photon implementation and one-way post-processing without pre-processing; bitwise pre-processing raises it to 12.4%, and more complex pre-processing to 12.9%.These values concern security against the most general attacks.
  • 2. Individual, Collective and Coherent Attacks: Collective attacks retain the independent-system interaction but allow Eve to keep ancillae in quantum memory and perform a later collective measurement.The one-way secret fraction is bounded using the Devetak-Winter bound and the Holevo quantity χ(A : E), which is easier to compute than mutual information.
  • 2. Individual, Collective and Coherent Attacks: General coherent attacks allow entangling multiple systems and adapting interactions, making brute-force optimization impossible, yet unconditional security bounds have been found in many cases.For several protocols, symmetries or the exponential De Finetti theorem relate the relevant statistics to those under individual-attack constraints, though continuous-variable QKD remains problematic because the bound depends on Hilbert-space dimension.

3. Quantum side channels and zero-error attacks … 1. Photon-number statistics

The paper frames practical QKD security as requiring explicit treatment of quantum side channels, implementation-level hacking, and device imperfections. Its discrete-variable analysis therefore uses uncalibrated-device assumptions and photon-number statistics to characterize observable rates and Eve’s possible strategies.

  • 3. Quantum side channels and zero-error attacks: Losses constitute a universal quantum side channel, but security is preserved when corresponding attacks are incorporated into privacy amplification.The beam-splitting attack gives Eve all channel-lost light without changing Bob’s received optical mode or introducing errors.
  • 3. Quantum side channels and zero-error attacks: Photon-number-splitting attacks let Eve condition her action on each signal’s photon number and can be more powerful than beam-splitting attacks.With one known signal intensity, PNS attacks may be undetectable in principle; decoy states and distributed-phase-reference protocols are used to detect them.
  • 3. Quantum side channels and zero-error attacks: Side channels may arise in any imperfect component, requiring careful testing, while unambiguous-state-discrimination attacks provide another zero-error mechanism that generally changes photon-number statistics.Specific protocols and security proofs can sometimes be made robust against such imperfections.
  • 4. Hacking on Practical QKD: Practical QKD must address both quantum-channel security bounds and implementation weaknesses, including feasible hacking attacks such as Trojan Horse, faked-state, phase-remapping, and time-shift attacks.Trojan Horse attacks probe device settings by sending light into Alice’s or Bob’s devices and collecting reflected signals.
  • 5. A crutch: the “uncalibrated-device scenario”: Detector inefficiency and dark counts occur inside authorized parties’ devices, so security proofs must distinguish device imperfections from channel losses and errors.The naive procedure of removing calibrated imperfections from privacy-amplification parameters yields only an upper bound, even for individual attacks.
  • 5. A crutch: the “uncalibrated-device scenario”: The uncalibrated-device scenario remains necessary for deriving lower bounds, although in some cases its lower bounds coincide for practical purposes with naive calibrated-device upper bounds.The paper works systematically in this scenario while presenting an upper-bound derivation for calibrated devices.
  • A. Generic Assumptions and Tools: For discrete-variable protocols, each signal is modeled as a phase-randomized diagonal state with n photons occurring with probability pA(n), and Eve can learn n without modifying it.The analysis assumes no phase reference and no coherence between successive signals.
  • 1. Photon-number statistics: The key-exchange statistics are detection and error rates: R is total detection, Rn is detection for n-photon signals, Yn = Rn/R, εn is the n-photon error rate, and Q is the total QBER.Eve’s photon-number-dependent strategy can make Bob’s photon statistics differ completely from those expected from random channel losses.

2. Qubits and Modes … 3. P&M with decoy states

The section reduces practical optical QKD security analyses to qubit protocols using source tagging and detector squashing, while addressing double-click loopholes. It then derives prepare-and-measure bounds and shows how decoy states let Alice and Bob estimate photon-number-dependent parameters against attacks independent of the source setting.

  • 2. Qubits and Modes: Tagging treats all multi-photon signals as fully known to Eve, leaving single photons and their coding degree of freedom as effective qubits.The coding degree of freedom can be polarization or the relative phase between two modes.
  • 2. Qubits and Modes: Randomly assigning double clicks prevents a security loophole that would arise if multiphoton- or dark-count-induced double clicks were simply ignored.An intercept/resend attack with many photons can otherwise give Eve full information on retained single-click events while producing discardable double clicks in the other basis.
  • 2. Qubits and Modes: Squashing models detection as mapping an optical signal to a single-photon qubit before an ideal qubit measurement, providing an elegant shortcut for security proofs.Combining tagging at the source with squashing at the detector reduces the analysis to qubit protocols, although squashing is not necessary for proving security.
  • B. BB84 coding: lower bounds: In BB84 coding, Bob accepts an item based on using Alice’s basis, which occurs with probability psift, so ˜νS = νS psift.The attack is optimized over the forwarding probabilities {fn}n≥0 compatible with the observed parameters.
  • 1. Prepare-and-Measure: Generalities: For P&M BB84, Eve’s information is equal from Alice’s and Bob’s perspectives; vacuum detections give IE,0 = 0, while single-photon information is IE,1 = h(ε1).On single-photon pulses, Eve gains information only by introducing an error ε1.
  • 2. P&M without decoy states: Without decoy states, only R and Q are measured, so assuming εn≥2 = 0 gives ε1 = Q/Y1 and an attack minimizing Y1.The minimizing choice is f0 = 0 and fn≥2 = 1; the resulting key expression depends only on calibrated or parameter-estimated quantities.
  • 3. P&M with decoy states: Decoy states randomly vary a source parameter ξ, such as laser intensity µ, then sort data by ξ to estimate parameters separately.Because Eve does not know ξ for each pulse, fn and εn are independent of ξ; the resulting equations constrain photon-number contributions.
  • 3. P&M with decoy states: |X| = 3 decoy settings typically approach exact determination of the meaningful n = 0, 1, 2 contributions, enabling bounds on Y ξ 1 and ε1.The achievable rate is summed over settings with Kξ ≥0; whole-key post-processing instead gives K = R[1 − leakEC(Q)] −P ξ Kξ, with coincidence when one ξ is used almost always.

4. P&M: analytical estimates

The section develops analytical estimates for practical P&M implementations, emphasizing intensity optimization for attenuated lasers with and without decoy states. It shows that decoy states change the loss dependence of the key rate by enabling detection-fraction estimation and excluding photon-number-splitting attacks.

  • Single-photon sources: For single-photon sources, the meaningful scheme is P&M without decoy states, with pA(1) = 1 and Y1 = 1.The expected detection rate is R = ˜νSt tBη.
  • Attenuated lasers: Attenuated lasers have an optimal intensity µ balancing a larger detection rate against a smaller two-photon emission probability.The relevant probabilities are pA(1) = µe−µ and pA(2) = µ2e−µ/2.
  • Without decoy states: Without decoy states, µopt ∼t and consequently K ∝t2, so greater line loss requires stronger laser attenuation.This scaling is attributed to photon-number-splitting attacks, because Eve can fully learn photons from two-photon pulses.
  • With decoy states: With decoy states, varying the laser intensity enables estimation of the fraction of detections originating from two-photon pulses and can exclude photon-number-splitting attacks when that fraction is as low as expected.The decoy implementation varies the intensity from one pulse to the next and uses sufficiently many decoy values for full parameter estimation.
  • Calibration limitation: An intensity double than the optimal one is already enough to spoil all security, making calibration potentially critical at long distances without decoy states.The critical value µcrit is defined as the one for which K ≈0.

5. Entanglement-Based … 2. Upper bounds

The paper treats entanglement-based QKD through its equivalence to prepare-and-measure schemes while accounting separately for correlated and uncorrelated multi-pair events. It then develops calibrated-device upper bounds for BB84, distinguishing photon detections from dark counts and using a deliberately simple, sub-optimal recipe.

  • 5. Entanglement-Based: Entanglement-based QKD with Alice holding the source is equivalent to a prepare-and-measure scheme, so corresponding security proofs apply.The main additional issue is the treatment of multi-pair emissions within a coincidence window.
  • 5. Entanglement-Based: Correlated multi-pair events can leak key-bit information through PNS attacks, whereas independent pairs permit only standard single-particle attacks on Bob’s symbol.The analysis conservatively treats Eve as able to identify the pair selected by Alice’s detector and counts all non-negligibly correlated events as correlated.
  • 5. Entanglement-Based: Under the stated assumptions, deviations from a perfect two-photon source, including multi-photon components, are accounted for by measuring the error rate Q.The resulting expression formally matches the single-photon P&M result with Y1 = 1.
  • C. BB84 coding: upper bounds incorporating the calibration of the devices: Calibrated-device upper bounds are introduced to compare with unconditional-security lower bounds and identify the range where improvements on K may remain possible.The error-correction contribution leakEC(Q) is independent of the device-calibration scenario.
  • 1. Statistical parameters: The calibrated analysis separates detection contributions from photon events and dark counts by redefining Yn = Rn,p/R, with total detection yield Y < 1.Errors affect photon contributions, while dark counts contribute an error rate of 1/2.
  • 2. Upper bounds: The upper-bound recipe follows the preceding calculations with necessary modifications, although it is known to be sub-optimal and lacks a justified squashing model.Eve is still assumed to forward at most one photon to Bob, despite this being sub-optimal.
  • 2. Upper bounds: In decoy-state P&M schemes, Yn and εn are known, so calibration mainly changes the treatment of dark counts relative to the uncalibrated formula.Without decoy states, only R and Q are directly measured, while Y1 and ε1 must be bounded under the assumed attack strategy.
  • 2. Upper bounds: Y1 can be significantly larger than in the uncalibrated-device scenario because the subtracted term is multiplied by tBη when Eve cannot influence detector efficiency.This difference arises specifically from excluding Eve’s control over the detector efficiency.

D. Bounds for the SARG04 coding … 2. Modeling the noise

The paper contrasts SARG04’s security and performance with BB84, then reviews continuous-variable QKD security bounds, their limitations, Gaussian-protocol analysis, and the decomposition of channel noise. SARG04 can outperform BB84 in specific weak-coherent implementations, while CV security remains incomplete and depends on explicit noise modeling.

  • D. Bounds for the SARG04 coding: In weak-coherent implementations without decoy states and at small error rate, SARG04 performs better than BB84 and scales ∼t3/2 with distance.SARG04’s advantage is linked to extracting a fraction of fully secure key from 2-photon pulses.
  • D. Bounds for the SARG04 coding: With decoy states, BB84 can outperform SARG04 when decoy analysis reveals no PNS attack, as losses typically appear random and beam-splitter-like.The comparison depends on what additional information about Eve’s attack the decoy method reveals.
  • D. Bounds for the SARG04 coding: For single-photon sources, the improved SARG04 bound tolerates ε1 ≈11.67%, slightly above BB84’s ε1 ≈11.0%, but SARG04 has critical visibility V ≈87% versus BB84’s V ≈78%.The improved optimal IE,1 is not known analytically but can be computed numerically.
  • A. Status of security proofs: Gaussian-modulation CV QKD security has been proved against collective attacks, but extending the same bound to general attacks remains unresolved.The exponential de Finetti bound does not help because it explicitly depends on the quantum-signal dimension.
  • A. Status of security proofs: Discrete-modulation CV security is less advanced: a full analysis exists only when the quantum channel adds no excess noise, while unconditional security proofs are unavailable generally.The difficulty arises because Alice’s raw key is discrete whereas Bob’s data are real numbers.
  • B. Bounds for Gaussian protocols: For coherent-state homodyne detection, Gaussian attacks allow the channel to be represented by a Gaussian two-mode state with covariance matrix γAB.The channel is characterized by transmittance tη and input-referred noise δ in the uncalibrated-device scenario.
  • 2. Modeling the noise: The total input-referred noise δ comprises loss-induced vacuum noise, homodyne-detection noise, and excess noise ǫ; ǫ vanishes for a lossy but noiseless line.The first term is (1−t)/t, while detector inefficiency and thermal electronic noise model imperfections.

3. Information Alice-Bob … 6. Collective attacks and post-selection

The paper develops security analyses for continuous-variable QKD from Alice–Bob information and individual attacks through Gaussian-optimal collective attacks and post-selection. It identifies error-correction efficiency, reverse reconciliation, and conditional-data filtering as central determinants of achievable security and key rates.

  • 3. Information Alice-Bob: Error correction leaves only a fraction β of I(A : B), strongly affecting the achievable secret key rate and limiting distance.The bottleneck is the heavy post-processing needed to correct errors induced by vacuum noise from line losses.
  • 4. Individual attacks: Security against individual attacks assumes Eve holds the purification and uses conditional uncertainty relations for Bob’s quadratures.Alice’s and Eve’s measurements project Bob’s share onto a pure conditional state, enabling the uncertainty-based analysis.
  • 4. Individual attacks: The minimum conditional variance bounds Eve’s information and determines the extractable secret key rate under individual attacks.The bound applies particularly to reverse reconciliation, where the key is formed from Bob’s data.
  • 4. Individual attacks: In the high-loss and large-modulation limit, reverse reconciliation retains a non-zero secret key rate when excess noise satisfies ǫ < 1/2.The optimal attack saturating the bound is the entanglement cloner.
  • 5. Collective attacks: For coherent-state homodyne detection, Gaussian collective attacks are optimal, so security need only be assessed against that class.The corresponding rates were first derived under the Gaussian assumption and later shown to retain optimality.
  • 5. Collective attacks: Against collective attacks, the secret key rate is K = R [β I(A : B) −χ(B : E)].This expression combines the error-corrected Alice–Bob information with Eve’s Holevo information.
  • 6. Collective attacks and post-selection: When observed data and noise are Gaussian, the protocol admits a security proof incorporating post-selection, with Gaussianity verifiable in each run.The collective-attack analysis uses the product structure of subsequent signals and Eve’s purification of ρAB.
  • 6. Collective attacks and post-selection: Data are discarded whenever 1 −h[ea,b] −χa,b is negative, giving the corresponding effective binary channel zero contribution to the overall key rate.The conditional Eve states have at most rank four, allowing χa,b to be calculated analytically; the remaining evaluation is numerical.

VI. DISTRIBUTED-PHASE-REFERENCE PROTOCOLS … 2. More sophisticated attacks

Distributed-phase-reference protocols were developed for practicality and may achieve rates comparable to decoy-state implementations because photon-number-splitting attacks are no longer zero-error. Security analyses consider beam-splitting and more sophisticated coherent attacks, but available bounds remain estimates pending unconditional proofs.

  • A. Status of security proofs: Distributed-phase-reference protocols were invented as practical solutions and may yield rates comparable to decoy-state implementations.Photon-number-splitting attacks are no longer zero-error for both DPS and COW.
  • 1. Collective beam-splitting attack: In the beam-splitting attack, Eve keeps part of each coherent-state signal and forwards the remainder to Bob through a lossless line.The study uses the uncalibrated-device scenario for comparison, although it does not provide a lower bound.
  • 1. Collective beam-splitting attack: For both DPS and COW, the beam-splitting attack does not modify Bob’s optical mode and introduces no error.Other zero-error attacks include whole-key photon-number splitting and, for COW, unambiguous state discrimination.
  • IDP S: Eve’s information differs between DPS and COW because their bit encodings use different pairs of coherent states.The analysis evaluates Eve’s information from her systems after Bob announces a detection involving two consecutive pulses.
  • IDP S: The secret-key-rate calculation for COW accounts for the fraction of decoy sequences excluded from the raw key and the empty pulses among the remainder.The stated factor of 2 arises because the decoy fraction does not contribute and half of the remaining pulses are empty.
  • 2. More sophisticated attacks: More sophisticated analyses use coherent attacks on pulse pairs and provide upper bounds in the limit µt ≪1.For COW, the key error ε and interferometer visibility V have no a priori relation, and security is impossible when µ is too large.
  • 2. More sophisticated attacks: DPS is slightly more robust than COW under the same attack family, so the COW formula is used to estimate distributed-phase-reference performance in the presence of errors.The comparison again adopts the uncalibrated-device scenario, and the available bounds are intended to be replaced by unconditional security proofs.

VII. COMPARISON OF EXPERIMENTAL PLATFORMS … C. Comparison based on the “cost of a linear network”

The paper compares practical QKD platforms using a priori models, parameter sets, key-rate plots, calibrated-device bounds, and a linear-network cost criterion. It emphasizes that these comparisons involve arbitrary assumptions and that network-optimal device distances can be short.

  • A. Generalities: Platform choice balances secret key rate against practical parameters such as simplicity, stability, and cost.With unlimited resources, maximizing K for the desired distance would determine the best platform, but real-world choices require additional tradeoffs.
  • 1. Model for the source and channel: Security assessments should use measured values, whereas the comparisons here rely on universally accepted but necessarily arbitrary a priori channel and source models.The channel model is intended to match observations, but reproducing data does not establish that the model is correct.
  • 2. Choice of the parameters: The analysis uses two parameter sets: today’s state-of-the-art and a more optimistic but not unrealistic development.Plots generally use the uncalibrated-device scenario because unconditional security has been proved only there, while fiber parameters assume α = 0.2dB/km.
  • 1. All platforms on a plot: The all-platform comparison plots K/νS against channel transmittivity t, but the curves do not provide the same degree of security.They also represent steady-state rates that neglect classical post-processing time, and actual performance is K when source-rate bottlenecks occur.
  • 2. Upper bound incorporating the calibration of the devices: For BB84 with weak coherent pulses, calibrated-device bounds offer basically no improvement with decoy states, while implementations without decoy states may still improve.The difference for decoy states mainly concerns treatment of dark counts.
  • 2. Upper bound incorporating the calibration of the devices: For continuous-variable QKD with Gaussian modulation, calibration matters significantly for parameter set #1 but negligibly for the more optimistic set #2.The latter result holds even though detector efficiency is 85% in set #2.
  • C. Comparison based on the “cost of a linear network”: In a linear QKD chain, the preferred platform minimizes network cost by maximizing F(ℓ) = ℓK(ℓ), plotted normalized to νS for both parameter sets.The toy model targets Ktarget over distance L using parallel devices and trusted repeater stations, while neglecting repeater-station cost.
  • C. Comparison based on the “cost of a linear network”: For α ≈0.2dB/km, optimal device distances are ℓopt ≈20km when k = 1 and ℓopt ≈10km when k = 2.These short optima follow from K(ℓ) ∝t for several platforms and K(ℓ) ∝t2 for weak coherent pulses without decoy states; detector saturation may dominate dark counts.

VIII. PERSPECTIVES … B. QKD versus other solutions

The perspectives section identifies unresolved security and scalability challenges within QKD, while comparing QKD’s security, speed, and distance trade-offs with standard cryptographic solutions. It also outlines practical architectures for black-box security, long-distance links, networks, and finite-key operation.

  • 1. Finite-key analysis: Finite-key security requires composable proofs because existing asymptotic bounds and earlier non-composable analyses do not fully characterize practical finite keys.Recent work incorporates finite statistics while meeting composable-security requirements.
  • 2. Open issues in unconditional security: Unconditional security remains unavailable for CV QKD and distributed-phase-reference protocols, although CV proofs may generalize existing independent-signal analyses.Security proofs should also exploit detector calibration rather than assuming devices are uncalibrated, potentially improving rates.
  • 3. Black-box security proofs: The quantum part of a commercial QKD system can in principle be kept in a black box, subject to trusted randomness, authenticated communication, and preventing key leakage.The black-box approach aims to prove the devices’ quantumness without exposing their internal implementation.
  • 4. Toward longer distances: satellites and repeaters: Long-distance QKD is pursued through ground-to-satellite free-space links and quantum repeaters that distribute entanglement across segments and swap it between endpoints.Quantum relays avoid quantum memories but are inefficient; cryogenic detectors may offer a simpler solution to dark-count limitations, while afterpulse correlations require security analysis.
  • 5. QKD in networks: QKD is inherently a point-to-point link, whereas networked communication connects many users; optical switching can provide one-to-many connectivity, and repeater-based nodes can preserve endpoint privacy.In repeater or relay networks, intermediate authorized nodes perform entanglement swapping while Eve may monitor all links.
  • B. QKD versus other solutions: Information-theoretically secure key agreement cannot be achieved through public communication alone, while standard cryptography relies on computational assumptions and additional authentication resources.Public-key infrastructures commonly depend on digital-signature assumptions and trusted external certifying entities.
  • B. QKD versus other solutions: QKD can be paired with a One-Time Pad for information-theoretic security or with a high-speed encryptor; in the latter case, at 25 km it can refresh AES-256 keys several times per second.The One-Time Pad scenario supports highly sensitive data but not broad-band transmission, while the high-speed-encryptor scenario is reported to outperform the standard solution at 25 km in speed and security; QKD remains distance-limited.
  • Note added in proof: Subsequent claims addressed the pending CV QKD issue of making collective- and general-attack security bounds coincide asymptotically, using either an exponential de Finetti theorem or a different argument.The de Finetti approach applies under assumptions fulfilled in CV QKD, while the alternative argument avoids requiring a de Finetti-type theorem.

APPENDIX A: Unconditional security bounds for BB84 and six-states, single-qubit signals · APPENDIX B: Elementary estimates for quantum repeaters · 1. Quantum memories

Appendix A derives unconditional single-qubit security bounds for six-state and BB84 QKD, yielding secret-fraction thresholds of approximately 12.61% and 11%, respectively. The paper also introduces quantum memories as coherence-preserving storage and on-demand re-emission devices, with implementations pursued across several physical platforms.

  • APPENDIX A: Unconditional security bounds for BB84 and six-states, single-qubit signals: The security analysis applies to BB84 and six-state protocols when signals are single qubits or qubit channels followed by qubit detection.For real optical channels, the treatment assumes tagging for real sources and a squashing model for detection.
  • APPENDIX A: Unconditional security bounds for BB84 and six-states, single-qubit signals: Protocol symmetries reduce the unconditional-security calculation to collective attacks whose Alice–Bob state is Bell-diagonal.The derivation is performed in the entanglement-based scheme, with the prepare-and-measure application following directly.
  • APPENDIX A: Unconditional security bounds for BB84 and six-states, single-qubit signals: Six-state QKD measures εx and εy, directly determining all four Bell-state weights and yielding the secret fraction r = 1 − h(Q) − IE(Q).Under the depolarizing-channel assumption εx = εy = εz = Q, this fraction goes to 0 for Q ≈ 12.61%.
  • APPENDIX A: Unconditional security bounds for BB84 and six-states, single-qubit signals: BB84 measures only εx in addition to the key-basis error, so Eve’s information is maximized over a remaining free parameter.The optimization gives u = v = εx.
  • APPENDIX A: Unconditional security bounds for BB84 and six-states, single-qubit signals: 11% is the BB84 QBER threshold where r = 1 − h(Q) − IE(Q) goes to 0 under εx = εz = Q.This error pattern implies εy = 2Q(1 − Q), corresponding to a phase-covariant cloning machine rather than a depolarizing channel.
  • 1. Quantum memories: A quantum memory stores an incoming quantum state and re-emits it on demand without loss of coherence.Research uses techniques including atomic ensembles, NV centers, and doped crystals.

A B C … b. Detection rates

The paper models direct links and quantum repeaters using idealized sources, channels, detectors, memories, and Bell measurements. It finds that repeaters can outperform direct transmission beyond roughly 500 km, while larger repeaters impose stringent memory and fidelity requirements.

  • 2. Model of quantum repeater: The comparison considers direct links, two-link repeaters, and four-link repeaters within the architecture sketched in Fig. 8.The analysis follows the original repeater idea and focuses on advantages and implementation problems as repeater complexity increases.
  • a. Definition of the model: The model assumes a perfect two-photon source with repetition rate νS and a noiseless lossy channel of transmittivity t = 10^-αℓ/10.The total distance is ℓ, and channel loss is characterized by α.
  • a. Definition of the model: Detectors have efficiency η with dark counts, dead time, and other nuisances neglected, while memories store N modes and re-emit absorbed photons on demand.Memory storage uses probability pM for absorption and re-emission, with lifetime TM.
  • a. Definition of the model: The Bell measurement uses linear optics with success probability 1/2, fidelity F, depolarized noise, detector efficiency ηM, and no dark counts.A detection is attributed to the desired Bell state with probability F and to the other states with probability (1 − F)/3.
  • b. Detection rates: For the direct link, the key rate equals the detection rate in the simplified model.This establishes the baseline against which the repeater rates are compared.
  • b. Detection rates: In the two-link repeater, Christoph stores one photon from each of N-pair groups and retries until Alice and Bob independently announce detections.Each elementary run takes ℓ/c, and the detection probability per link is 1−(1 − tη)^N.
  • b. Detection rates: R2 scales with tη rather than tη^2 because the two links can be activated independently, while the error rate depends only on Bell-measurement fidelity.The fidelity of a Bell measurement must exceed 83.5% to have K2 > 0.
  • b. Detection rates: Quantum repeaters overcome the direct link for ℓ>∼500km in fibers; with η = 0.5 and N = 1000, this requires TM ≈10s.The number of supported memory modes is more critical than Bell-measurement fidelity; four-link repeaters reach R4 ∝t1/4 but require F >∼95% for ε < 11%.
Loading 0802.4155v3…