Source-linked AI summary
Continuous Variable Quantum Key Distribution: Finite-Key Analysis of Composable Security against Coherent Attacks
Fabian Furrer, Torsten Franz, Mario Berta, Anthony Leverrier, Volkher B. Scholz, Marco Tomamichel, Reinhard F. Werner
TL;DR
The paper develops a security-proof framework using smooth min- and max-entropies, parameter estimation, and an uncertainty relation with quantum side information. It derives entropy bounds for the protocol and shows that Gaussian representatives attain the relevant covariance-constrained infimum.
Problem
The security proof must handle non-maximally complementary measurements and states constrained by a covariance matrix.
Method
The analysis applies an uncertainty relation with quantum side information, estimates parameters from random samples, models loss and excess noise through covariance matrices, and uses Gaussian extremality.
Results
The relevant entropy bound is obtained, and the covariance-constrained infimum of H(X|E) is attained by the Gaussian representative.
Takeaways & Limitations
Gaussian states provide the representative needed to evaluate the conditional entropy optimization for states sharing a covariance matrix.
Abstract
from arXiv · showhide
We provide a security analysis for continuous variable quantum key distribution protocols based on the transmission of squeezed vacuum states measured via homodyne detection. We employ a version of the entropic uncertainty relation for smooth entropies to give a lower bound on the number of secret bits which can be extracted from a finite number of runs of the protocol. This bound is valid under general coherent attacks, and gives rise to keys which are composably secure. For comparison, we also give a lower bound valid under the assumption of collective attacks. For both scenarios, we find positive key rates using experimental parameters reachable today.
Appendix A: Smooth Min- and Max-Entropies
This appendix defines smooth conditional min- and max-entropies for quantum and classical systems, including their optimization over nearby states and their behavior under quantum processing.
- For a classical-quantum state, conditional min-entropy characterizes the optimal probability of guessing the classical variable given the quantum system.
- The purified distance defines which nearby states are included in the smoothing optimization.
- Smooth min-entropy is defined by optimizing conditional min-entropy over states within purified distance ϵ of the original state.The optimization ranges over subnormalized states.
- Smooth max-entropy is likewise optimized over states within purified distance ϵ, with the non-smoothed quantity obtained at ϵ = 0.
- Data processing implies that conditional smooth min- and max-entropies can only increase when the conditioning system is subjected to a quantum operation.
Appendix B: Derivation of the Uncertainty Relation
This appendix derives the uncertainty relation used for the protocol by combining discretized quadrature measurements, source assumptions, and a trusted-source correction for non-complementary boundary intervals.
- Alice and Bob discretize phase and amplitude quadratures into intervals and retain a finite key alphabet while separately refining the unbounded boundary regions.The finite alphabet has size |X| = 2α/δ.
- The protocol uses random, uniform choices between phase and amplitude measurements, and parameter estimation tests the remaining systems after a sampled subset.
- The uncertainty proof applies smooth-entropy uncertainty relations with quantum side information to relate Eve’s information to correlations between Alice and Bob.
- Because the outer phase and amplitude projectors almost commute, the trusted source assumption is used to bound the purified distance to a state with a non-trivial uncertainty relation.
- The resulting entropy bounds are transferred through smoothing and data processing to obtain the uncertainty relation used in the main-text key-length expression.
Appendix C: Statistical Analysis for Coherent Attacks
This appendix bounds coherent-attack fluctuations by converting observed sample correlations into a bound on the raw-key distance and then into a smooth max-entropy estimate.
- The protocol aborts when the parameter-estimation distance exceeds d0; conditioned on passing, the remaining raw-key distance is therefore controlled statistically.
- A distribution truncated to pairs with distance at most d0 is used to construct a nearby state whose max-entropy can be bounded.
- The smooth max-entropy is bounded whenever the probability of distances exceeding d0 is sufficiently small, using purified-distance smoothing and a conditional 0-Rényi-entropy estimate.
- The analysis treats the parameter-estimation data as a random sample without replacement from all measurements and bounds the probability that raw-key distance exceeds the sample distance by ν.
- The final bound incorporates the smoothing parameter ϵ′, the pass probability ppass, and the source-related correction f(pα,n).
Appendix D: The Error Model
The error model represents channel loss and acquisition noise as two Gaussian parameters acting on the covariance matrix.
- Loss µloss replaces part of the signal with vacuum, while excess noise µen represents classical noise from the data-acquisition system.
- Both noise sources transform the covariance matrix according to Γ → (1 − µloss)Γ + (µloss + µen)Γvac.
Appendix E: Asymptotic Equipartition Property
The appendix applies a smooth-entropy bound under finite-dimensional entropy conditions and simplifies it using data processing, yielding the inequality used for the key-length analysis.
- Asymptotic Equipartition Property: For ϵ > 0 and sufficiently large n, the smooth-entropy formalism provides the applicable bound for the protocol’s classical-quantum state.The condition requires finite H(A)ω, which holds here because H(XA)ω is finite.
- Asymptotic Equipartition Property: Data processing bounds Hmax(XA|E)ω by Hmax(XA)ω and produces the simplified inequality used in the main paper.The resulting expression is 2^-1/2 Hmin(XA|E)ω + 2^1/2 Hmax(XA|E)ω ≤ 2^1/2 Hmax(XA)ω + 1.
- Asymptotic Equipartition Property: ∆ depends only on ϵ and Alice’s measurement distribution, so it can be calculated directly for the known source.This term enters the key-length formula together with the protocol parameters.
Appendix F: Gaussian Extremality
The appendix proves that, among states sharing a covariance matrix, the Gaussian representative minimizes the conditional entropy relevant to the protocol.
- Gaussian Extremality: The infimum of H(X|E)ω over states with covariance matrix Γ is attained by the corresponding Gaussian representative.This extremality result reduces the optimization over compatible states to Gaussian states.
- Gaussian Extremality: A classification theorem identifies Gaussian-optimized functions through lower semicontinuity, local-unitary invariance, and strong superadditivity.Strong superadditivity requires f(ωABA′B′) ≥ f(ωAB) + f(ωA′B′), with equality for product states.
- Gaussian Extremality: For f(ωAB) = H(X|E)ω, the conditional von Neumann entropy is defined using relative entropy and finite classical-alphabet entropy conditions.The finite-dimensional approximation property extends the relevant entropy result to infinite-dimensional Hilbert spaces.
- Gaussian Extremality: The entropy function satisfies the required properties through data processing, conditional mutual-information nonnegativity, and finite-dimensional approximation.Additivity gives equality when the input state is a product state.
Appendix G: Calculation of H(XA|E) for Discretized Measurements
The appendix evaluates the conditional entropy for discretized homodyne measurements on a two-mode squeezed Gaussian state by decomposing the measured outcomes and conditional states.
- State and entropy setup: The collective-attack calculation evaluates H(XA|E)ω for a two-mode squeezed Gaussian state with a Gaussian purification.The entropy is rewritten using the purification structure before analyzing the measurement-conditioned states.
- State and entropy setup: The entropy H(AB)ω is determined by symplectic invariants of the two-mode Gaussian state.Purity gives H(E) = H(AB), while the finite measurement alphabet makes H(XA)ω the Shannon entropy of {pk}.
- Discretized measurements: Amplitude measurements are discretized into intervals Ik with spectral-measure operators Ek, producing normalized post-measurement states conditioned on each outcome.The appendix assumes symmetric amplitude and phase correlations and calculates the amplitude case.
- Conditional-state analysis: Gaussian conditional states differ by Weyl phase-space translations, so their entropy can be related to the reference state at outcome x = 0.The translation depends continuously on the covariance matrix ΓAE.
- Conditional-state analysis: H(E|XA)ω is bounded below by H(E)ω(0) for the two-mode squeezed Gaussian state.Proposition 2 states H(E)ωk ≥ H(E)ω(0), hence H(E|XA)ω ≥ H(E)ω(0).