Source-linked AI summary
Field test of a continuous-variable quantum key distribution prototype
Simon Fossier, Eleni Diamanti, Thierry Debuisschert, André Villing, Rosa Tualle-Brouri, Philippe Grangier
TL;DR
The paper addresses whether a coherent-state CVQKD system can operate securely and reliably in a realistic metropolitan network. It implements a reverse-reconciliation prototype with multiplexed optical transmission, feedback stabilization, and classical post-processing, and reports 8 kbit/s over 3 dB loss during a 57-hour field operation. The results identify reconciliation and computational processing as current rate limitations while supporting metropolitan-network deployment.
Problem
The paper investigates practical deployment of secure, high-rate CVQKD in realistic network environments rather than only laboratory conditions.
Method
The prototype combines coherent-state reverse-reconciliation CVQKD, time and polarization multiplexing, feedback stabilization, error correction, privacy amplification, and network integration.
Results
8 kbit/s average secret key generation was achieved over a 3 dB loss fibre during 57 hours, including quantum and classical communication and key extraction.
Takeaways & Limitations
The prototype is suitable for metropolitan-size secure networks requiring high communication rates, with rates above 100 kbit/s identified as a future objective.
Takeaways & Limitations
Finite reconciliation efficiency and limited processor speed constrain the prototype’s secret-key rate and transmission range.
Abstract
from arXiv · showhide
We have designed and realized a prototype that implements a continuous-variable quantum key distribution protocol based on coherent states and reverse reconciliation. The system uses time and polarization multiplexing for optimal transmission and detection of the signal and phase reference, and employs sophisticated error-correction codes for reconciliation. The security of the system is guaranteed against general coherent eavesdropping attacks. The performance of the prototype was tested over preinstalled optical fibres as part of a quantum cryptography network combining different quantum key distribution technologies. The stable and automatic operation of the prototype over 57 hours yielded an average secret key distribution rate of 8 kbit/s over a 3 dB loss optical fibre, including the key extraction process and all quantum and classical communication. This system is therefore ideal for securing communications in metropolitan size networks with high speed requirements.
1. Introduction
The paper presents coherent-state CVQKD as a practical alternative to established QKD technologies, using quadrature modulation and reverse reconciliation. Its field-tested prototype achieved 8 kbit/s over a 3 dB channel, supporting metropolitan high-rate applications.
- Protocol motivation: Coherent-state CVQKD encodes information in the X and P quadratures of Gaussian-modulated coherent states and measures one quadrature by homodyne detection.Alice sends a phase reference with the states, and Bob randomly measures X or P.
- Practical motivation: The coherent-state approach uses a simple architecture without single-photon sources or detectors and evolved toward telecom-wavelength operation with advanced error correction.The prototype operates at 1550 nm using standard telecommunications components.
- Field performance: 8 kbit/s was achieved over a 3 dB channel corresponding to 15 km of standard optical fibre, including quantum and classical communication.The field test was conducted within the SECOQC quantum cryptography network.
2. CVQKD prototype layout
The prototype uses fibre-optic telecom components to transmit and detect a Gaussian-modulated coherent-state signal with its local oscillator. Time and polarization multiplexing, feedback control, and automated drift correction support stable operation.
- Optical generation: Alice generates 1550 nm, 500 kHz coherent-light pulses and Gaussian-modulates both quadratures after splitting the pulses into signal and local-oscillator paths.A true random-number generator supplies modulation randomness, and attenuation sets the target modulation variance.
- Multiplexing: Time and polarization multiplexing transmit the signal and local oscillator through the same fibre while maintaining low crosstalk.Two 400 ns delay lines and Faraday mirrors separate the pulses in time and polarization.
- Detection: Bob uses pulsed shot-noise-limited homodyne detection and randomly selects X0 or Xπ/2 by applying a π/2 phase shift to the local oscillator.The detector output is proportional to the signal quadrature selected by the signal–local-oscillator phase difference.
- Feedback control: Feedback procedures correct polarization, temperature, amplitude, and relative-phase drifts during operation.Polarization control and photodiode-based monitoring automate corrections in the transmission and modulation systems.
- Automation: 1 minute is sufficient for a complete feedback-control cycle, allowing the devices to remain in an optimal state during operation.The cycle is short compared with typical temperature drifts.
3. Security of the CVQKD prototype
The security analysis models the reverse-reconciliation CVQKD protocol against general coherent attacks using an equivalent entanglement-based description. Channel and detector parameters determine shared information and an upper bound on Eve’s information, from which the secret information is calculated.
- Security scope: Security against coherent attacks is guaranteed because such attacks are no more powerful than collective attacks for the implemented protocol.The security proof extends from individual and collective attacks to the most general coherent attacks allowed by quantum mechanics.
- Security model: The entanglement-based description is formally equivalent to the prepare-and-measure protocol and represents Alice’s bi-Gaussian modulation with an EPR state.Alice measures both quadratures, while Bob’s detector noise and losses are modeled with a beamsplitter.
- Secret-key calculation: The secret information is computed from the reverse-reconciliation expression using the reconciliation efficiency β and the Holevo-information bound χBE.The expression quantifies the information retained by Alice and Bob after accounting for Eve’s maximum information.
- Parameterization: VA, T, ε, η, and vel parameterize modulation, channel transmission, excess noise, Bob’s transmission efficiency, and detector noise for calculating IAB and χBE.These measured parameters connect the physical system to the security-rate calculation.
- Rate evaluation: The prototype’s security analysis supplies the theoretical secret-key generation rates used to evaluate the implementation.The rates are derived from the protocol’s security expression.
4. From continuous data to a secret key
The protocol converts correlated continuous measurements into a secure discrete key through parameter estimation, reconciliation, privacy amplification, and verification. The implementation processes 2 million pulses per key generation, producing about 150,000 final bits in 20 seconds.
- Post-processing requirements: Continuous-variable QKD requires substantial post-processing because quantum noise affects Bob’s measurements even without eavesdropping.This distinguishes CVQKD post-processing from schemes where ideal noiseless measurements can yield identical sifted data.
- Data processing: 2 million pulses are used per key generation, with 1 million for channel evaluation and 1 million for key generation, yielding about 150,000 final bits in 20 seconds.Amplitude and phase are coded on 16 bits for the transmitted samples used in channel evaluation.
- Parameter estimation and reconciliation: Alice and Bob estimate transmission parameters from shared samples, then discretize each quadrature into 16 slots with 4-bit labels for reconciliation.The evaluated parameters include VA, T, and ε, while v_el and η are calibrated before transmission.
- Parameter estimation and reconciliation: Multilevel LDPC-code reconciliation corrects Alice’s data with respect to Bob’s data under reverse reconciliation, producing identical discrete data that remain only partially secret.The protocol then applies privacy amplification to extract a shorter sequence unknown to Eve.
- Privacy amplification and verification: Privacy amplification combines non-universal and universal hash functions to produce a secure key, after which key verification checks that Alice and Bob hold identical final sequences.Verification is needed because residual LDPC errors can otherwise leave different keys and disrupt network synchronization.
5. Results and discussion
The field-tested CVQKD prototype operated stably in the SECOQC network, but practical noise, reconciliation, processing, and communication constraints reduced its rate below the theoretical value. It generated keys continuously for 57 hours at 8 kbit/s and was suited to metropolitan high-speed communications.
- Network integration: The prototype’s software and network interface achieved good stability and compatibility with the SECOQC central network program.Classical communication still added 5 seconds to key extraction, while authentication consumed approximately 128 bits per generated key.
- Prototype performance: 100 kbit/s was the theoretically expected rate, while the actual experimental rate was one order of magnitude lower.The decrease reflected several practical limitations summarized in Figure 4.
- Prototype stability: Excess noise varied typically between 0 and 10% of shot noise and directly affected the secret information rate.The excess noise was induced by the prototype’s vibrational environment.
- Rate limitations: Reconciliation efficiency was β = 0.9, limiting information extraction and contributing to the prototype’s restricted transmission distance.Increasing reconciliation efficiency could significantly increase the system’s range.
- Rate limitations: Post-processing was the dominant throughput constraint: quadruple-core parallelization increased the secret key rate by a 2.1 factor, but processing remained 3 times slower than the optical rate.A single processor core processed fewer than 20% of available pulses, producing a factor-of-6 loss between optical and final extracted rates.
- Prototype performance: 8 kbit/s was the average secret key rate during 57 hours of continuous field testing.The experiment took place in Vienna during the SECOQC network implementation.
6. Conclusion
The CVQKD prototype operated automatically within a quantum cryptography network, achieving 8 kbit/s over a 3 dB-loss fibre for 57 hours. The authors identify processor speed as the main current limitation and project rates above 100 kbit/s with further improvements.
- 8 kbit/s average secret key generation was achieved over a 3 dB-loss fibre during 57 hours.
- The prototype used time and polarization multiplexing, feedback control, and was proven secure against general coherent eavesdropping attacks.
- The processor’s computing capacity currently limits the secret key generation rate, motivating faster classical post-processing.
- Greater than 100 kbit/s secret-key rates are identified as an achievable metropolitan-network objective with these improvements.