Source-linked AI summary

Practical aspects of measurement-device-independent quantum key distribution

Feihu Xu, Marcos Curty, Bing Qi, Hoi-Kwong Lo

arXiv:1305.6965v3quant-ph

TL;DR

Practical MDI-QKD must address implementation errors, finite-key estimation, intensity selection, and unequal channel losses. This paper develops system and decoy-state models to analyze these issues and optimize operation. It finds polarization misalignment dominates QBER, while optimized asymmetric operation can substantially improve key rates.

  • Problem

    Practical MDI-QKD requires analysis of error sources, finite decoy-state and finite-key effects, optimal intensities, and unequal channel transmittances.

  • Method

    The paper develops a general MDI-QKD system model, a two-general-decoy analytical method, and a combined framework for optimizing signal and decoy intensities, including asymmetric channels.

  • Results

    Polarization misalignment is the major QBER source, mode mismatch is not a major problem, and asymmetric optimization can improve key rates by around 80% or over 130% depending on channel imbalance.

  • Takeaways & Limitations

    MDI-QKD can be implemented with standard optical devices, while the analytical decoy method can be used directly by experimentalists.

  • Takeaways & Limitations

    The polarization model uses a simple unitary matrix rather than the general transformation, although the authors expect similar results.

Abstract

from arXiv · show

A novel protocol - measurement-device-independent quantum key distribution (MDI-QKD) - removes all attacks from the detection system, the most vulnerable part in QKD implementations. In this paper, we present an analysis for practical aspects of MDI-QKD. To evaluate its performance, we study various error sources by developing a general system model. We find that MDI-QKD is highly practical and thus can be easily implemented with standard optical devices. Moreover, we present a simple analytical method with only two (general) decoy states for the finite decoy-state analysis. This method can be used directly by experimentalists to demonstrate MDI-QKD. By combining the system model with the finite decoy-state method, we present a general framework for the optimal choice of the intensities of the signal and decoy states. Furthermore, we consider a common situation, namely asymmetric MDI-QKD, in which the two quantum channels have different transmittances. We investigate its properties and discuss how to optimize its performance. Our work is of interest not only to experiments demonstrating MDI-QKD but also to other non-QKD experiments involving quantum interference.

1. Introduction

MDI-QKD addresses practical security vulnerabilities by removing detector side-channel attacks, while this paper analyzes implementation errors, finite decoy states, intensity optimization, and asymmetric channels.

  • Motivation: QKD implementations remain vulnerable to quantum hacking because real-device imperfections can expose detector and other loopholes.Reported attacks include time-shift, phase-remapping, and detector-control attacks.
  • MDI-QKD approach: MDI-QKD removes detector side-channel attacks by sending Alice’s and Bob’s states to an untrusted relay for Bell state measurement.The measurement setting is used to post-select entanglement and can therefore be treated as a black box.
  • Practical error modelling: The paper develops generic error models and finds polarization misalignment is the major QBER source, whereas time- or frequency-domain mode mismatch is not a major problem.The model also supports analysis of quantum-interference experiments beyond QKD.
  • Finite decoy-state analysis: A two-general-decoy analytical method avoids assuming that Alice and Bob can prepare vacuum states, which is difficult with finite-extinction-ratio intensity modulators.The method provides experimentalists with a direct rough performance estimate when finite-key effects are temporarily ignored.
  • Intensity optimization: Combining the system model, finite decoy-state protocol, and finite-key analysis yields a framework for optimizing signal and decoy intensities.The framework was adopted and verified in an experimental demonstration.
  • Asymmetric MDI-QKD: The asymmetric analysis determines the experimental configuration that maximizes secret key rate when Alice–Charles and Bob–Charles channels have different transmittances.Such asymmetry is common in practice and may make adding balancing fiber non-optimal.

2. Preliminary

The preliminary formulation defines the asymptotic secure-key-rate quantities and the finite-decoy notation used to estimate single-photon parameters and optimize practical MDI-QKD.

  • Key-rate formulation: The asymptotic MDI-QKD secure key rate assumes infinitely many decoy states and signals.The Z basis is used for key generation and the X basis for testing.
  • Key-rate quantities: Y_1,1^X denotes the single-photon yield in the X basis, while Q_Z and E_Z are the measured Z-basis gain and QBER.The yield is the probability that Charles declares a successful event.
  • Parameter estimation: The finite decoy-state method estimates Y_1,1^X from experimentally measured quantities.Q_Z and E_Z are measured directly in the experiment.
  • Finite-decoy notation: The protocol uses one signal state and two weak decoy states with intensities satisfying µ > ν > ω ≥ 0.µ is the signal mean photon number, while ν and ω are the decoy intensities.
  • System parameters: The notation includes Alice’s and Bob’s intensity sets, optimal intensities, channel distances and transmittances, detector efficiency, background rate, and error parameters.For fiber links, transmittance is determined by channel loss coefficient and distance.

3. Practical error sources

The analysis models polarization misalignment and mode mismatch in a fiber-based polarization-encoding MDI-QKD system, finding that both errors can be tolerated under practical conditions.

  • Error sources: The model focuses primarily on polarization misalignment and mode mismatch, while treating intensity fluctuations and beam-splitter asymmetry as minor contributions.State-preparation error is excluded because its strict security treatment is deferred to future work.
  • Polarization misalignment: Three unitary operators model polarization misalignment in Alice’s channel, Bob’s channel, and the additional measurement basis.The model uses a simplified two-dimensional unitary transformation and defines the total misalignment error from the individual rotation errors.
  • Polarization misalignment: At 0 km, the system tolerates about 6.7% polarization misalignment, decreasing to 5% at 120 km.The simulations use asymptotic key rates while temporarily ignoring mode mismatch.
  • Mode mismatch: The time-jitter model represents Bob’s state as overlapping and orthogonal temporal modes relative to Alice’s reference state.The same framework can analyze spectral and pulse-shape mismatch in other quantum-interference experiments.
  • Mode mismatch: At 0 km, the system tolerates up to 80% mode mismatch, while the tolerable value is about 50% at 120 km.The polarization-encoding implementation is less sensitive to mode mismatch than to polarization misalignment in these simulations.

4. Finite decoy-state protocol with two general decoy states

The paper presents a two-decoy-state analytical protocol that estimates the single-photon yield and error rate without requiring a vacuum decoy state.

  • Parameter estimation: The finite decoy-state analysis estimates a lower bound for Y 1,1_Z and an upper bound for e1,1_X from gains and QBERs measured with different intensity settings.These quantities are obtained from the linear equations relating observed gains and QBERs to photon-number yields and error rates.
  • Practical use: The final equations are summarized in Table 2 and can be used directly by experimentalists for a rough estimate of expected system performance.The method avoids assuming that one decoy state is vacuum, which is useful because practical intensity modulators have finite extinction ratios.
  • Protocol: The protocol uses signal and decoy intensities satisfying µ > ν > ω and allows either ω = 0 or ω ≠ 0.It is designed for finite decoy-state estimation with two general decoy states.
  • Workflow: The procedure derives expected gain and QBER by modeling the system before applying the finite decoy-state protocol.The framework is illustrated as part of the broader optimization workflow for selecting intensities.

5. Optimal choice of intensities

The paper combines system modeling, two-decoy-state estimation, finite-key analysis, and numerical optimization to select signal and decoy intensities for different transmission distances.

  • Optimization framework: The optimization framework has five steps: quantify errors, model gain and QBER, implement two decoy states, apply finite-key analysis, and numerically optimize parameters.It also optimizes the probabilities assigned to different intensity settings.
  • Simulation settings: The simulations use a minimum weakest-decoy intensity of 5 × 10^-4 per pulse, N=10^14 signals, and a security bound of ϵ=10^-10.The finite-key analysis and numerical optimization are applied after the two-decoy-state estimation.
  • Results: The framework produces optimal intensities that maximize the secure key rate at different transmission distances.The resulting values are presented in Figure 7 and correspond to the finite-key scenario.
  • Experimental application: The framework was applied in an experimental MDI-QKD demonstration, where polarization misalignment was around 0.7% and total mode mismatch was below 2%.That experimental setting used ω=0.01 because of its low operation rate.
  • Results: The weakest decoy state is optimized at its minimum value, ωopt=5 × 10^-4, under the stated finite-key simulation settings.The reported figure notes that nonsmooth behavior mainly reflects limited numerical accuracy.

6. Asymmetric MDI-QKD

The paper analyzes asymmetric MDI-QKD, where channel transmittances differ, and develops numerical and analytical guidance for choosing signal and decoy intensities. Optimal intensity choices can substantially improve key rates over symmetric choices, especially for large channel mismatches.

  • Problem and optimization: Asymmetric MDI-QKD concerns two channels with different transmittances, quantified by the mismatch parameter x.The symmetric choice balances the effective intensities, whereas the optimal choice is determined through numerical optimization.
  • Problem and optimization: Large signal intensities in the short channel can increase QBER through polarization misalignment and imperfect Hong-Ou-Mandel interference.These effects reduce the key rate through error correction and privacy amplification costs.
  • Optimal intensities: The optimal choice is found by numerical optimization and is compared with the symmetric choice using two-decoy-state and finite-key analyses.The comparison is shown for a 50 km channel mismatch in Fig. 8 and Table 3.
  • Performance: 80% larger key rates are obtained with the optimal choice than with the symmetric choice at x=0.1 in both asymptotic and practical cases.For x=0.01, corresponding to a 100 km length difference, the improvement is about 150%.
  • Asymptotic properties: In the asymptotic case, the optimal intensities depend on x rather than separately on ta or tb, while the optimal key rate is quadratically proportional to tb.When x is near 1, improvements can be small; Calgary’s x=0.752 gives around 2%, whereas Tokyo’s x=0.017 gives over 130%.

7. Discussion and Conclusion

The discussion emphasizes the practical assumptions and conclusions of the MDI-QKD analysis. State-preparation devices remain trusted, while the model and analytical methods support experimental optimization and broader quantum-interference studies.

  • Assumptions: MDI-QKD assumes that Alice and Bob can prepare ideal BB84 states, although preparation imperfections can instead be incorporated into security proofs.The paper regards this trust assumption as practical because the users prepare and can experimentally verify their own states.
  • Conclusions: The authors conclude that polarization misalignment is the major QBER source in polarization-encoding MDI-QKD.They identify polarization feedback control as a practical way to improve stabilization and generate a higher key rate.
  • Conclusions: A simple analytical finite-decoy-state method and a general intensity-optimization framework are presented for experimental MDI-QKD.The conclusion also covers optimization of asymmetric MDI-QKD performance.
  • Modeling scope: Other practical error sources with insignificant QBER contributions are ignored in the simulations.The paper notes that this modeling choice does not prevent those sources from being included in the analysis.

Appendix A.2. Threshold detector with background counts

The appendix models threshold detectors, background counts, beam-splitter imbalance, and selected polarization effects in practical MDI-QKD. It identifies operating conditions under which these imperfections can be neglected or tolerated.

  • Detector model: The detector model represents a threshold single-photon detector as a beam splitter with transmission ηd followed by a unit-efficiency detector.Background counts are modeled independently of incoming signals, and identical detectors are assumed for simplicity.
  • Detector model: The system model can be adapted to detector-efficiency mismatch, although the baseline model assumes four identical detectors with efficiency ηd and background rate Y0.This establishes the model’s main simplifying assumption and its stated extension.
  • Background counts: 10^-3 background counts per pulse are tolerable at 0 km in the simulated MDI-QKD system.The main-text simulations use Y0=6.02×10^-6.
  • Beam-splitter imbalance: At 1542 nm, a fiber beam splitter ratio of 0.5007 introduces QBER below 0.01%.The paper therefore treats this beam-splitter imbalance as negligible in the theoretical model.
  • Analytical model: The analytical model calculates Y_1,1 and estimates the expected key rate, considering polarization misalignment, background counts, and detector efficiency.Other practical error sources are omitted when their contributions are not significant.
  • Analytical model: With polarization misalignment and background counts ignored, e_1,1^X is zero and P_1,1^Z is maximized at μa=μb=1.In practice, the optimal intensities depend on the values of practical errors.

Appendix B.2.1. Derivation of QHH

The derivation computes detection and coincidence probabilities for polarization-encoded states after the beam splitter and polarization beam splitter. It averages over the relative optical phase and simplifies the resulting expressions under explicit approximations.

  • Assumptions and notation: The derivation assumes Alice’s and Bob’s polarization rotations have the same direction, with the opposite-direction case treated separately.The state configurations are represented using horizontal, vertical, and diagonal BB84 polarization modes.
  • Detection model: Optical intensities received by each single-photon detector are calculated after the beam splitter and polarization beam splitter.These intensities are then used to obtain each detector’s detection probability.
  • Coincidence events: Coincident detections are classified as triplet or singlet projections according to the detector pairs that click.The triplet corresponds to {ch & cv} or {dh & dv}, while the singlet corresponds to {ch & dv} or {cv & dh}.
  • Phase averaging: Averaging over the relative phase φ produces the coincidence expressions, including the modified Bessel function I0(·).The phase average integrates φ over [0,2π].
  • Approximation: The QHH expression is simplified by setting Y0=0 and using a second-order approximation because β and γ are typically of order 0.01.The resulting approximation is then used to estimate the corresponding equation.
  • Cross-polarization case: The cross-polarization case is evaluated analogously using the same detector-probability relation and a second-order approximation.The derivation obtains QHV,ψ+ after phase averaging and then simplifies it by neglecting background counts.

Appendix B.2.3. Derivation of QZ and EZ

The appendix derives analytical expressions for QZ and EZ by combining error-source terms, then relates polarization-rotation directions to projected-state QBER and key rates.

  • QZ and EZ are assembled from the equation terms given in Appendix B and combined with Eq. (B.1) to derive the analytical key rate.
  • When θ1θ2 > 0, projection on |ψ+⟩ produces a larger QBER than projection on |ψ−⟩.
  • When θ1θ2 < 0, projection on |ψ+⟩ produces a smaller QBER than projection on |ψ−⟩.
  • The individual key rates Rψ− and Rψ+ depend on the relative rotation direction, but their total R remains independent of it.The relative direction is determined by whether θ1θ2 is positive or negative.
  • A practical polarization-encoding system models each channel’s rotation angle with a Gaussian distribution having standard deviation θstd.The relative direction randomly takes both θ1θ2 > 0 and θ1θ2 < 0 cases.

Appendix C.1. Estimated key rate

The estimated key rate is developed under negligible-background conditions and reduced to an optimization over the channel mismatch and two signal intensities.

  • Rest is defined while ignoring background counts, an assumption considered reasonable for short-distance transmission.
  • Under fixed x, the optimal intensities depend only on x rather than ta or tb.
  • Under fixed x, Rest and the optimal key rate are quadratically proportional to tb.
  • Optimizing Rest is equivalent to maximizing G(x, µa, µb), whose maximizers determine the optimal intensities µopt a and µopt b.

Appendix C.2. Properties of asymmetric MDI-QKD

The appendix studies asymmetric MDI-QKD by comparing rigorous and estimated rates, optimizing intensities, and examining distance, background-count, and finite-key effects.

  • For total length Lac + Lbc < 100 km, Rest overlaps Rrig, demonstrating the accuracy of the estimated-rate model.The asymmetric system tolerates x=0.004, corresponding to a 120 km length difference for standard fiber links.
  • At short distances x≥0.5, the optimal intensities µopt a and µopt b depend only on x; at long distances x<0.5, background counts cause non-smooth behavior.
  • The optimal intensities µopt a and µopt b are both in O(1).
  • For a standard fiber link with α=0.2 dB/km, log10 Rest varies linearly with channel distance with slope -0.4.
  • With N = 1014 signals and ǫ = 10−10, finite-key analysis at x=0.1 gives µa/µb ≈νa/νb ≈7 and tolerates a total fiber link of 110 km.
Loading 1305.6965v3…