Source-linked AI summary
Long Distance Continuous-Variable Quantum Key Distribution with a Gaussian Modulation
Paul Jouguet, Sébastien Kunz-Jacques, Anthony Leverrier
TL;DR
Long-distance Gaussian-modulated CVQKD is limited by inefficient reconciliation at low SNR. The paper designs high-efficiency error-correcting codes for a binary-input AWGN channel and combines them with multidimensional reconciliation. The resulting procedure supports secret-key distribution over distances above 150 km against collective attacks in the asymptotic regime.
Problem
Reconciliation efficiency limits the secret-key rate and secure range of Gaussian-modulated CVQKD, especially at the low SNRs associated with long distances.
Method
The paper designs low-rate multi-edge LDPC codes for the BIAWGNC and combines them with multidimensional reconciliation of Gaussian variables.
Results
Above 150 km secure distance is obtained against collective attacks in the asymptotic regime, with codeword efficiency within 1% of asymptotic efficiency at length 220.
Takeaways & Limitations
The codes enable Gaussian-modulated CVQKD secret-key distribution over long distances and can be implemented through software modifications to existing experimental setups.
Abstract
from arXiv · showhide
We designed high-efficiency error correcting codes allowing to extract an errorless secret key in a continuous-variable quantum key distribution protocol using a Gaussian modulation of coherent states and a homodyne detection. These codes are available for a wide range of signal-to-noise ratios on an AWGN channel with a binary modulation and can be combined with a multidimensional reconciliation method proven secure against arbitrary collective attacks. This improved reconciliation procedure considerably extends the secure range of a continuous-variable quantum key distribution with a Gaussian modulation, giving a secret key rate of about 10^{-3} bit per pulse at a distance of 120 km for reasonable physical parameters.
I. INTRODUCTION
Gaussian-modulated CVQKD offers theoretically optimal secret-key rates and uses standard telecommunication components, but reconciliation inefficiency limits long-distance operation. The paper addresses this bottleneck with efficient low-SNR codes combined with multidimensional reconciliation.
- Gaussian-modulated coherent states measured by homodyne or heterodyne detection use standard telecommunication components and are theoretically optimal for secret-key rate.
- Existing reconciliation inefficiency limits Gaussian-modulated CVQKD, especially at the low SNRs associated with long distances.
- Non-Gaussian protocols may increase achievable secure distance theoretically, but they had not yet been demonstrated experimentally and generally require lower modulation variance at long distances.
- High-efficiency error-correcting codes combined with multidimensional reconciliation enable secret-key distillation with Gaussian modulation at very low SNR.
- The reconciliation problem is translated into BIAWGNC channel coding, followed by the design of very low-rate error-correcting codes and evaluation of long-distance Gaussian-protocol performance.
II. THEORY OF RECONCILIATION OF GAUSSIAN VARIABLES
The paper develops a multidimensional reconciliation framework that maps correlated Gaussian variables to a virtual binary-input AWGN channel. Its efficiency depends on both code quality and the approximation dimension, while the construction has algebraic dimensionality limits.
- Reconciliation efficiency affects both the secret-key rate and secure range, making correlated Gaussian-variable reconciliation central to CVQKD.
- The multidimensional scheme maps d physical Gaussian-channel instances to d approximate copies of a virtual BIAWGNC for error correction and secret-key distillation.
- Overall efficiency is determined by the error-correcting code’s BIAWGNC efficiency and the quality of the virtual-channel approximation.
- Increasing the code efficiency and rotation dimension improves the global reconciliation efficiency.
- The correlated Gaussian model represents direct reconciliation as y = tx + z and reverse reconciliation as x = t′y + z′ with Gaussian noise.
- The virtual-channel noise becomes a fading channel with known side information, approaching BIAWGNC behavior as dimension increases.
- The required division operator exists only in dimensions 1, 2, 4, and 8, preventing this construction from being used in arbitrary dimension.
III. RECONCILIATION OF GAUSSIAN VARIABLES: IMPLEMENTATION WITH LDPC CODES
The implementation uses optimized low-rate multi-edge LDPC codes for BIAWGNC reconciliation at very low SNR. These codes approach Shannon-limit performance and retain near-asymptotic efficiency at finite block length.
- LDPC codes use sparse parity-check matrices and can be decoded efficiently through iterative belief propagation.
- Differential Evolution and Discretized Density Evolution optimize LDPC ensembles by maximizing the correctable channel threshold.
- Multi-edge-type LDPC codes provide low-rate, high-efficiency BIAWGNC codes suited to very low SNR, with degree-1 edges improving the threshold.
- Reconciliation efficiency β is defined as R/C(s), and prior Gaussian-modulation techniques achieved at most 90% efficiency.
- 95.9% efficiency is reported for a rate 1/10 BIAWGNC code, while the paper introduces lower-rate codes with higher asymptotic thresholds.
- The finite-length efficiency of codewords of length 220 is within 1% of the asymptotic efficiency.
A. Simulation Results with Rotations on S1, S3 and S7
The simulations evaluate multidimensional reconciliation with rotations at dimensions d = 1, 2, 4, and 8, using low-rate multi-edge LDPC codes. Increasing dimension brings the virtual channel closer to the BIAWGNC, while successful decoding yields zero bit errors.
- Simulation setup: The simulations compare dimensions d = 1, 2, 4, and 8 using multidimensional reconciliation with low-rate multi-edge LDPC codes.The evaluated codes use block size 2^20.
- Decoding outcomes: A frame error rate of about 1/3 coexists with a null bit error rate on successfully decoded blocks.Residual-error removal with concatenated BCH codes is therefore unnecessary for these blocks.
- Reconciliation efficiency: The rotated channels always achieve lower efficiencies than BIAWGNC density-evolution predictions because they are not exact BIAWGNCs.The efficiency gap reflects the approximation between the physical Gaussian channel and its virtual binary-input channel.
- Reconciliation efficiency: Increasing rotation dimension improves efficiency by making the virtual channel closer to the BIAWGNC.The input-vector norm follows a χ(d) distribution that approaches a Dirac distribution as d increases.
- Capacity comparison: Figure 1 compares multidimensional-channel capacities with BIAWGNC capacity and BIAWGNC capacity with AWGNC capacity across SNR values.The multidimensional cases shown are d = 1, 2, 4, and 8.
B. Use of rotations in higher dimension spaces
The paper examines higher-dimensional rotations for multidimensional reconciliation and develops a more efficient representation of random orthogonal transformations. The proposed representation reduces complexity to O(d^2), while the available reconciliation scheme is restricted to dimensions 1, 2, 4, and 8.
- Dimensional scope: The multidimensional reconciliation construction is limited to dimensions 1, 2, 4, and 8 because only these dimensions support the required division structure.
- Original construction: The standard construction draws a random orthogonal transformation and composes it with a reflection, with complexity O(d^3).The resulting transformation maps Alice’s vector x to u while preserving Euclidean distance.
- Improved construction: The proposed representation reduces the transformation-drawing complexity to O(d^2) without revealing information about u beyond the constraint R(x) = u.The method avoids revealing the transformation in matrix form.
- Improved construction: Householder decomposition represents a Haar-distributed orthogonal transform recursively through reflections described by vectors.The decomposition uses a fixed orthogonal basis and recursively transforms the subspace spanned by e2 through ed.
- Constrained sampling: The constrained sampling procedure chooses g so that u · g = x · e1, enabling the required relation Q(x) = u and Q(e1) = g.For d > 1, g is selected from unit vectors satisfying the constraint; the resulting vector is computed in linear time.
- Higher-dimensional performance: For the rate 1/2 multi-edge LDPC code, increasing dimension above 8 at high SNR significantly increases reconciliation efficiency and the resulting QKD key rate.The code’s BIAWGNC threshold is s* = 1.074, corresponding to 98.2% efficiency.
C. Dealing with a continuous range of SNR with puncturing, shortening and repetition
A finite family of low-rate codes is extended across a continuous SNR range using repetition, puncturing, and shortening, while retaining high efficiency for small rate changes.
- Repetition: A rate-0.02 code with 98% efficiency at SNR 0.03 yields 97% efficiency at SNR 0.01 using repetition length 3.Repetition factors 2 and 4 produce the rate-0.01 and rate-0.005 codes listed in Table V.
- Puncturing and shortening: Puncturing deletes p symbols and shortening deletes s symbols, adapting an (n, k) LDPC code to nearby rates.Puncturing changes the code to (n−p, k), while shortening changes the rate according to the stated transformed expression.
- Puncturing and shortening: A 5% rate decrease through shortening or 10% increase through puncturing incurs an efficiency loss smaller than 1%.The loss remains small for small relative variations of the code rate.
IV. PRACTICAL USE FOR A CONTINUOUS-VARIABLE QUANTUM KEY DISTRIBUTION SYSTEM
The proposed reconciliation codes are evaluated in Gaussian-modulated CVQKD under practical channel and detector assumptions, showing improved key-rate robustness across SNR and distance.
- Code evaluation: The reconciliation efficiency is computed relative to AWGNC capacity, β = R / C_AWGNC, because the physical quantum channel is Gaussian.For small SNR values, BIAWGNC and AWGNC capacities are very close.
- Code evaluation: The codes achieve about 95% efficiency at selected low SNRs, and the analysis omits finite-size effects.The key-rate plots therefore represent the asymptotic regime described in the section.
- Experimental assumptions: The practical model restricts modulation variance to [1, 100], assumes 0.2 dB/km attenuation, 0.6 homodyne efficiency, and 1% electronic noise.The lower modulation bound reflects compatibility with synchronization and phase-tracking signals under limited modulator extinction ratios.
- Modulation choice: Good reconciliation efficiency permits high modulation variance, whereas previous discrete-modulation schemes require variances 10 times lower.Figure 2 plots optimal modulation variance against distance for β = 95% and β = 90%.
- Key-rate performance: Improved reconciliation efficiency provides a wider SNR range with a close-to-optimum secret key rate at every distance.Figures 3 and 4 consider excess noise of 1% and 4% of shot noise, respectively.
- Key-rate performance: Above 150 km secure distance is obtained with 1% excess noise, and above 140 km with 4% excess noise using the same codes.This exceeds the approximately 50 km distance associated with 90% efficiency at SNR 0.5 in the cited prior scheme.
V. CONCLUSION
The paper presents high-efficiency error-correcting codes for long-distance Gaussian-modulated CVQKD and reports secure operation beyond 150 km against collective attacks asymptotically.
- Conclusion: The codes enable secret-key distribution with Gaussian modulation over long distances in a continuous-variable quantum key distribution system.The conclusion states that implementation requires only software modifications to the experimental setups of references and.
- Conclusion: Above 150 km secure distance is achieved against collective attacks in the asymptotic regime.
Appendix A: A rate 1/50 multi-edge LDPC code (σ∗= 5.91 on the BIAWGNC)
The appendix describes a rate-0.02 multi-edge LDPC code through variable- and check-node multidegree distributions.
- Code construction: The rate-0.02 multi-edge LDPC ensemble is specified by multidegree distributions for variable nodes and check nodes.The left half of the array describes variable-node distributions, while the right half describes check-node distributions.
- Code construction: A variable node has multidegree [2, 57, 0] with probability 0.0225 in the illustrated ensemble.