Source-linked AI summary

Security of continuous-variable quantum key distribution against general attacks

Anthony Leverrier, Raúl García-Patrón, Renato Renner, Nicolas J. Cerf

arXiv:1208.4920v1quant-ph

TL;DR

The paper uses phase-space symmetries and symmetrization to analyze continuous-variable protocols through finite-dimensional subspaces. Its theorems bound the probability of passing the test while failing the relevant finite-dimensional projection by ǫ, including for homodyne and heterodyne protocols.

  • Problem

    The proof must control the probability that a tested state lies outside the relevant finite-dimensional subspace.

  • Method

    The analysis exploits invariance under beamsplitters and phase shifts, which commute with heterodyne measurement and permit the test to be applied to selected modes after symmetrization.

  • Results

    The main theorems bound the probability of passing the test while the projection onto the finite-dimensional subspace fails by less than ǫ.

  • Takeaways & Limitations

    Phase-space symmetrization provides a common route for controlling finite-dimensional projections in both heterodyne and homodyne analyses.

Abstract

from arXiv · show

We prove the security of Gaussian continuous-variable quantum key distribution against arbitrary attacks in the finite-size regime. The novelty of our proof is to consider symmetries of quantum key distribution in phase space in order to show that, to good approximation, the Hilbert space of interest can be considered to be finite-dimensional, thereby allowing for the use of the postselection technique introduced by Christandl, Koenig and Renner (Phys. Rev. Lett. 102, 020504 (2009)). Our result greatly improves on previous work based on the de Finetti theorem which could not provide security for realistic, finite-size, implementations.

Appendix

The appendix organizes the technical development around separate heterodyne and homodyne protocols. It states the corresponding main theorems and establishes phase-space symmetry for both measurement settings.

  • Appendix A states the main theorem for the continuous-variable protocol with Bob using heterodyne detection.
  • The heterodyne proof uses three lemmas established in Appendices B, C, and D.
  • Appendix E justifies the symmetry assumption for Bob’s quantum state by analyzing beamsplitters and phase shifts.
  • Appendix F states the main theorem for the protocol with Bob using homodyne detection.
  • For homodyne detection, the proof reuses two heterodyne lemmas and establishes a variant of the third in Appendix H.

Appendix A: Main theorem for the heterodyne protocol

Appendix A constructs the heterodyne protocol’s active symmetrization and energy test, then states a theorem bounding the probability that a tested state lies outside a finite-dimensional subspace.

  • Symmetrization: Bob randomly applies a Haar-distributed unitary U(n + k) through beamsplitters and phase shifts to symmetrize his n + k modes.The resulting state is called rotationally invariant.
  • Symmetrization: The phase-space symmetrization commutes with heterodyne measurement, so the same transformation can be implemented on Bob’s classical measurement vector.Alice and Bob can apply the corresponding local classical coordinate transformation after measurement.
  • Energy test: After symmetrization, the test can be applied to the first k modes, while the remaining n modes constitute the state ρn used by the protocol.The test uses Bob’s first k measurement outcomes.
  • Finite-dimensional reduction: The proof defines POVM elements for the failed test, excessive total photon number, and excessive photons in any single mode.These operators support the reduction to a finite-dimensional subspace.
  • Main theorem: Theorem A.1 bounds pbad, the probability that the state passes the test while its projection onto the finite-dimensional subspace fails.The theorem is proved using variants of three technical lemmas from Appendices B, C, and D.

Appendix B: Concentration of measure on the sphere

Appendix B proves the concentration lemma for uniformly distributed points on a sphere by replacing normalized spherical vectors with independent Gaussian variables and applying χ2 bounds.

  • Lemma B.1 concerns a vector uniformly distributed on the unit sphere of R^(n+k).
  • A uniformly chosen spherical vector can be generated by drawing independent normal variables and normalizing the resulting vector.This reduction avoids directly manipulating normalized vectors on the sphere.
  • The proof introduces independent variables Xi ∼ N(0, 1) and associated quantities to establish the spherical concentration statement.
  • The proof bounds Pr[Zn ≥ g(δ)Yk] by splitting it into probabilities involving Yk and Zn relative to an arbitrary threshold A.
  • Yk and Zn are treated as independent χ2(k) and χ2(n) random variables, respectively, and Laurent–Massart bounds are applied.Choosing x = log(2/δ) in both bounds completes the estimate.
  • The resulting bound concludes the proof of Lemma B.1.

Appendix C: Proof of Lemma A.3

Appendix C establishes Lemma A.3, which supplies an inequality for the operators introduced in the heterodyne proof.

  • Appendix C proves Lemma A.3, recalled at the start of the section.
  • Lemma A.3 applies to the operators Tn and Un defined for the heterodyne protocol.
  • The lemma provides an inequality used as a technical bound in the proof.

1. Some preliminaries

The preliminaries introduce a family of integrals for a > 0 and state that they admit explicit evaluation. The first equality is established by induction from I1(a) = e−a.

  • For a > 0, the section defines integrals that will be used later.
  • These integrals can be computed explicitly.
  • The first equality is proved by induction, beginning with I1(a) = e−a.

2. Proof of Lemma A.3

The proof exploits phase-space rotation invariance to decompose Tn into a mixture with nonnegative coefficients, then establishes coefficient properties using incomplete Gamma functions.

  • Rotation invariance in phase space lets Tn be written as a mixture of Πn_k.
  • The mixture coefficients satisfy qk = Jn(k, nd0) and are nonnegative.
  • The incomplete Gamma function is used to show that Γ(k+1,a)/m! is positive and increasing with k for a ≥ 0.
  • For k ≥ nd0 + 1, the bound Γ(x+1,0) ≥ 1/2 supports the final conclusion.

Appendix D: Proof of Lemma A.4

The proof bounds the probability that the maximum photon number exceeds a threshold by combining a union bound with Stirling-based estimates and a concavity argument.

  • pk(m, n) denotes the probability that the maximum measured photon number exceeds m for σn.
  • A union bound reduces the maximum-photon-number estimate to componentwise contributions.
  • Introducing k = dn and m = δn rewrites the factorial ratio in terms of d and δ.
  • The function g(x) = (x + 1) log(x + 1) −x log x is used through its concavity to derive a lower bound involving δ log(1 + 1/d).
  • The resulting bound gives pk(m, n) ≤ ǫ and proves Lemma A.4.

Appendix E: Symmetry of the state for heterodyne detection

The appendix shows that the phase-space symmetries relevant to the protocol commute with heterodyne detection. This supports treating the state and post-processing as invariant under the corresponding transformations.

  • The compact subgroup K(n) of phase shifts and beamsplitters is isomorphic to U(N).
  • Under the relevant symplectic transformation, annihilation and creation operators transform independently using a unitary matrix U.
  • The rotated state’s Q-function is obtained by a local coordinate transformation involving V = Re(U) and W = −Im(U).
  • Alice’s and Bob’s heterodyne outcomes are distributed according to the Q-function of the shared state ρn+k_AB.
  • Because this coordinate transformation is local and classical, the quantum networks of beamsplitters and phase shifts commute with heterodyne measurement.

Appendix F: Main theorem for the homodyne protocol

The homodyne protocol uses random quadrature measurements and orthogonal processing to exploit phase-space symmetries. Its main theorem bounds the probability that the tested modes appear low-energy while the remaining state has excessive photon number.

  • Main theorem: The appendix presents the main result as a theorem and indicates that its proof is completed in Section H.The theorem is framed for the homodyne protocol described above.
  • Main theorem: The theorem tests k modes and projects the remaining n-mode state onto the subspace with fewer than dB photons.The stated failure event combines an acceptable test average with failure of the low-photon-number projection.
  • Main theorem: The operator Wn projects onto the event [Zn ≥ d0/2], providing the main technical distinction from the heterodyne protocol.This operator is introduced specifically for the homodyne analysis.
  • Protocol and symmetry: The protocol randomly measures quadratures, applies an orthogonal transformation to all outcomes, and communicates these choices to Alice.The orthogonal transformation can equivalently be implemented with a network of beamsplitters.
  • Protocol and symmetry: Random quadrature choices make Bob’s state invariant under local phase-space rotations.The state is also treated as invariant under networks of beamsplitters, including mode swaps and infinitesimal beamsplitters.

Appendix H: Proof of Lemma F.2

The proof bounds a radial function using spherical symmetry and a Poisson-tail estimate. These ingredients control the relevant high-norm contribution for the homodyne analysis.

  • Symmetry reduction: Spherical symmetry makes F(a) depend only on the norm of the vector a.The vector may therefore be represented as (a, 0, · · ·, 0) when useful.
  • Integral bound: Lemma H.1 establishes a bound for F at an arbitrary threshold d0.The proof evaluates an n-dimensional integral in spherical coordinates.
  • Integral bound: The integral bound is obtained by enlarging the integration domain relative to the definition of F(a).This yields the first inequality used in the proof.
  • Tail estimate: A Chernoff bound for a Poisson variable with parameter λ = nc0d0 supplies the tail estimate used in the argument.The proof assumes n is even at this step.

2. Proof of the lemma

The lemma’s proof constructs an operator representation for quadrature choices and compares complementary measurement strings. It then bounds the resulting function by separating low- and high-norm eigenvectors.

  • Operator construction: The operator Tn is written using complementary quadrature choices and a beamsplitter transformation.The beamsplitter operator is U = e±π/4(a ⊗a′† −a† ⊗a′).
  • Quadrature representation: For each measurement string s, Rs specifies the supported phase-space region, while the complementary coordinates remain unbounded.The operator S selects Q or P for each mode according to s.
  • Operator relation: The proof transfers the integral identity between a string s and its complement ¯s to establish the needed operator relation.This uses the equality of the corresponding integrals over the chosen region.
  • Case analysis: For an eigenvector of S, the bound on F separates the cases ||s⃗||^2 ≥ a^2 and ||s⃗||^2 ≤ a^2.The first case uses F(||s⃗||) ≤ 1 + F(a), while the second uses monotonicity of F.
Loading 1208.4920v1…