Source-linked AI summary
Analysis of Imperfections in Practical Continuous-Variable Quantum Key Distribution
Paul Jouguet, Sébastien Kunz-Jacques, Eleni Diamanti, Anthony Leverrier
TL;DR
The paper addresses gaps between idealized CVQKD security proofs and practical implementations, focusing on modulation, detection calibration, and preparation-stage phase noise. It models these imperfections and finds that discrete Gaussian modulation can be sufficient in practice, while accounting for phase noise can improve secret-key performance. Experimentally, the realistic phase-noise treatment increases achievable distance by about 40 km.
Problem
Practical CVQKD implementations cannot exactly realize the assumptions used in theoretical security proofs, creating a need to assess imperfections that may enable side-channel attacks.
Method
The paper models imperfect Gaussian modulation, finite-precision detection calibration, and intrinsic preparation-stage phase noise, then evaluates their effects on security and secret-key performance.
Results
Accounting for phase noise in a realistic model increases the achievable distance by about 40 km in the reported experimental scenario.
Takeaways & Limitations
Discrete Gaussian modulation can be adequate in practice, and phase noise controlled by Alice can be excluded from Eve’s information calculation to improve secret-key rates.
Abstract
from arXiv · showhide
As quantum key distribution becomes a mature technology, it appears clearly that some assumptions made in the security proofs cannot be justified in practical implementations. This might open the door to possible side-channel attacks. We examine several discrepancies between theoretical models and experimental setups in the case of continuous-variable quantum key distribution. We study in particular the impact of an imperfect modulation on the security of Gaussian protocols and show that approximating the theoretical Gaussian modulation with a discrete one is sufficient in practice. We also address the issue of properly calibrating the detection setup, and in particular the value of the shot noise. Finally, we consider the influence of phase noise in the preparation stage of the protocol and argue that taking this noise into account can improve the secret key rate because this source of noise is not controlled by the eavesdropper.
I. SECURITY OF GAUSSIAN PROTOCOLS WITH AN IMPERFECT MODULATION
Practical Gaussian modulation is necessarily bounded and discrete, so the paper evaluates whether this approximation threatens CVQKD security. It argues that sufficiently fine discretization keeps the security penalty small.
- I. SECURITY OF GAUSSIAN PROTOCOLS WITH AN IMPERFECT MODULATION: Exact Gaussian modulation is impossible because it is continuous and unbounded, while practical hardware imposes discrete voltages, finite ranges, and limited randomness.The practical state is centered on finite-grid values (q′, p′) rather than ideal Gaussian samples (q, p).
- I. SECURITY OF GAUSSIAN PROTOCOLS WITH AN IMPERFECT MODULATION: Shot noise can hide small modulation imperfections when the discretization grid is sufficiently fine compared with N0.Figure 1 illustrates the required grid scale relative to shot noise.
- I. SECURITY OF GAUSSIAN PROTOCOLS WITH AN IMPERFECT MODULATION: From Eve’s perspective, the ideal sent state is a Gaussian mixture of coherent states, equivalently a thermal state.Security can be related to how distinguishable the practical state is from this ideal thermal state.
- I. SECURITY OF GAUSSIAN PROTOCOLS WITH AN IMPERFECT MODULATION: If the ideal and actual states differ by trace distance ϵprep, an ϵ-secure perfect-preparation protocol becomes (ϵ + ϵprep)-secure.A realistic implementation therefore targets ϵprep on the order of 10^-10.
A. The quality of a Gaussian modulation
The paper quantifies the quality of discrete Gaussian approximations by bounding the trace distance between ideal and approximate states. The required cutoff dimension grows with the ideal thermal state’s mean photon number.
- A. The quality of a Gaussian modulation: The analysis computes ||ρ − σ||1 for Cartesian and polar discretizations using the gentle measurement lemma.The bound separates contributions associated with truncation, diagonal terms, and nondiagonal terms.
- A. The quality of a Gaussian modulation: The relevant approximation bound depends on the ideal thermal state’s mean photon number x, with x = 2VA for Gaussian modulation.Larger modulation variance therefore requires a larger cutoff dimension Q.
B. Cartesian approximation
A Cartesian grid can approximate Gaussian modulation with practical discretization resources while meeting a stringent preparation-distance target. The construction truncates the distribution and uses quarter-shot-noise spacing.
- B. Cartesian approximation: The Cartesian approximation uses coherent states on a grid with amplitudes αkl = qk + ipk, with parameters A and N optimized for the target variance.The discretization step is δ = A/N.
- B. Cartesian approximation: For VA = 20, the grid truncates the Gaussian distribution to 7 standard deviations and uses steps of 1/4 shot-noise units.These choices correspond to A = 7√VA and N = ⌈4A⌉.
- B. Cartesian approximation: 253 discretization steps, or an 8-bit grid, suffice for the stated VA = 20 construction.The corresponding pair of discretized Gaussian values has entropy 12.4 bits, and source coding can approach this average randomness requirement.
- B. Cartesian approximation: For Q = 2000, the paper numerically evaluates the resulting approximation error for the Cartesian construction.The numerical evaluation is presented after selecting Q to make Rσ sufficiently small.
C. Polar approximation
Polar discretization reflects separate phase and intensity modulation but is less resource-efficient than the Cartesian grid at comparable approximation quality. Gauss-Hermite quadrature substantially reduces its amplitude entropy requirement.
- C. Polar approximation: Polar coordinates are natural for devices that modulate phase and intensity separately, so the paper studies uniform discretization on [0, R] × [0, 2π].The polar grid uses discretized radial values and angular values.
- C. Polar approximation: The polar discretization requires a finer grid than the Cartesian discretization for the same approximation quality.This comparison is made using VA = 20, Q = L = 2000, and R = 7√VA.
- C. Polar approximation: 17-bit amplitude discretization is required to obtain |⟨0|ρ|0⟩ − ⟨0|σ|0⟩| ≤ 10^-10 under the stated uniform polar construction.Drawing the corresponding values uses 11 angle bits and 15.5 modulus bits on average.
- C. Polar approximation: Gauss-Hermite quadrature reduces the required amplitude discretization entropy to 9 bits for ϵprep ≤ 10^-10.This remains slightly worse than the Cartesian grid, with further improvement possible through amplitude-dependent angle discretization.
D. Robustness of bounds
The security bounds are tested against systematic disturbances of the discretization grid, including errors introduced by practical modulation devices.
- Systematic errors can disturb the discretization grid through calibration inaccuracies or complex effects in the experimental setup.An amplitude modulator maps discrete voltages through its realized nonlinear function, producing a corresponding discrete set of amplitudes.
- The modeled grid disturbance adds Gaussian errors with standard deviation σerror to each Cartesian-grid point and evaluates the resulting ϵprep numerically.
- For the stated parameters, the preparation-state distance is approximately ||ρ−σ|| ≈ 0.1×σerror.
- Achieving ϵprep ≤10^-10 may be difficult, while values around 10^-4 or 10^-5 are considered more realistic in practice.The passage suggests these larger approximation errors might nevertheless be sufficient, based on security results for non-Gaussian modulation against linear-channel attacks.
II. IMPERFECT CALIBRATION OF THE DETECTION SETUP
Finite-size estimation and imperfect calibration must be incorporated into CVQKD security analysis, especially for detection efficiency, electronic noise, and shot noise. Under the studied parameters, calibration uncertainty has little effect on the secret key rate, but precise shot-noise knowledge remains important at long distances.
- Detection calibration must account for finite-precision estimates of Bob’s quantum efficiency and electronic noise when proving security.
- The observed detection noise is modeled using a beamsplitter with transmittance η and added thermal noise, while vel is measured from output variance without optical input.
- A fiber-based homodyne detector requires estimating mode matching, photodiode efficiency, and fiber-optic transmittance, each with its own precision.
- Parameter estimation samples m = N − n correlated pairs, with n signals reserved for key establishment and the remaining data used to estimate channel statistics.
- The normal linear model uses y = tx + z, where t = √ηT and z has variance σ2 = N0 + ηTξ + vel, although this Gaussian assumption is not fully justified by current proof techniques.
- With ∆η = 0.1η and ∆vel = 0.1vel, calibration uncertainty has little effect on the secret key rate, but high shot-noise precision is needed over long distances.Even 10^6 samples yield a positive secret key rate for the Gaussian protocol under the figure’s conditions.
III. IMPROVED KEY RATE WITH PHASE NOISE CALIBRATION
Phase noise is an unavoidable preparation imperfection in Gaussian CVQKD, but it leaves Eve’s reduced state unchanged. Modeling it as local noise on Alice can therefore separate its effect on mutual information from its effect on Eve’s information and improve practical key-rate estimates.
- Phase noise is unavoidable, has a typical variance of 10^-4N0 per photon, and cannot be removed simply by increasing and attenuating the modulation variance.
- Unlike thermal preparation noise, phase noise leaves the state sent through the channel, and thus seen by Eve, invariant.
- Phase noise can be modeled as local noise acting on Alice’s system, degrading Alice–Bob mutual information without increasing Eve’s information about Bob’s outcome.
- Removing phase noise from the excess noise used to compute Eve’s information is expected to produce better secret key rates in practice.
A. Model for the phase noise
The paper models preparation phase noise as random phase rotations and incorporates its effect into the covariance matrix and security parameters. In reverse reconciliation, the phase noise does not change Eve’s information, enabling correction of the inferred channel parameters when its strength is known.
- Phase-noise model: Phase noise is modeled by applying a random rotation U(θ) = exp(iθa†a) to Alice’s mode before transmission.The prepared coherent state becomes a mixture of phase-rotated states weighted by p(θ).
- Phase-noise model: The phase-noise parameter κ is defined from the phase distribution through κ = (E[cos θ])2 under a symmetric-distribution assumption.The model assumes the phase distribution is symmetric and uses E[X] for expectation.
- Security consequence: In reverse reconciliation, random phase shifts do not change χ(y : E), Eve’s information about Bob’s raw key.The paper notes that this invariance does not hold for direct reconciliation, where the raw key uses Alice’s noisy data.
- Parameter estimation: Ignoring phase noise causes Alice and Bob to estimate modified parameters T′ and ξ′ rather than the channel parameters T and ξ.The relations connect T′ and ξ′ to T, ξ, κ, and VA; knowing κ allows recovery of T and ξ for computing Eve’s information.
- Parameter estimation: Using the measured κ, Alice and Bob can correct their covariance-matrix estimate and compute Eve’s information with the recovered T and ξ.The correction requires experimental measurement of κ.
B. Experimental evaluation of the phase noise
The paper proposes estimating preparation phase noise from homodyne or heterodyne measurements by separating noise parallel and orthogonal to the signal. In the reported experiment, treating calibrated phase noise as local increases the achievable secret-key distance by about 40 km relative to the paranoid model.
- Measurement procedure: Phase noise can be evaluated with a phase-sensitive apparatus using homodyne or heterodyne detection on modulated signals.The procedure estimates noise between a known signal sequence and selected quadrature-measurement outputs.
- Measurement procedure: Alice’s quadrature measurements infer κ by measuring the variance of outcomes from a bivariate Gaussian modulation.The method represents the measured noise B relative to the random angle φ between the prepared state and measured quadrature.
- Noise decomposition: The noise B is decomposed into orthogonal B⊥ and parallel B∥ components, allowing their variances to be estimated from measurements of B cos φ and B sin φ.The decomposition assumes B⊥ and B∥ are independent of φ.
- Noise decomposition: Under the shot-noise-plus-phase-noise model, V[B⊥] = N0 + V[A sin θ] = N0 + E[sin2 θ]E[A2].This expression uses E[sin θ] = 0 and identifies the orthogonal noise with shot noise plus phase noise.
- Secret-key impact: An experimentally measured E1 = 3 10−3 at VA = 2.5 gives ξreal = 1.75% and increases achievable distance by about 40 km.Figure 4 compares the realistic calibrated-local-noise model with the paranoid model attributing all noise to Eve.
IV. CONCLUSION
The paper analyzes practical imperfections in Gaussian CVQKD and finds that their security impact depends on how they are modeled and calibrated. Accounting for trusted phase noise and carefully approximating modulation can improve practical secret-key performance, while finite-size effects must also be included.
- Conclusion: The study models approximate Gaussian modulation, finite-precision detection calibration, and intrinsic preparation phase noise, then evaluates their security and performance effects.The analysis covers imperfections at both Alice’s state preparation and Bob’s detection.
- Conclusion: Accounting for phase noise as local noise in a realistic scenario provides an important secret-key-rate advantage.The paper treats this noise as not controlled by Eve.
- Conclusion: Carefully approximating the ideal Gaussian modulation with respect to shot-noise values can minimize the impact of modulation imperfection.The conclusion emphasizes matching the practical approximation to the relevant shot-noise values.
- Conclusion: Finite-size effects at all protocol stages should be considered when calculating practical secret-key rates.This is stated as a general requirement for practical rate calculations.
- Conclusion: Refining CVQKD security proofs to include practical imperfections provides ways to address attacks based on improperly modeled devices and procedures.The paper identifies this need particularly for CVQKD, where potential side channels have received limited study.