Source-linked AI summary
Loss-tolerant quantum cryptography with imperfect sources
Kiyoshi Tamaki, Marcos Curty, Go Kato, Hoi-Kwong Lo, Koji Azuma
TL;DR
State-preparation flaws can make standard QKD security analyses non-loss-tolerant. The paper develops a phase-error estimation approach based on virtual protocols and transmission-rate reconstruction, extending it to imperfect and coherent-attack settings. The approach applies to multiple QKD schemes, including tilted four-state and three-state protocols.
Problem
Standard security treatments of state-preparation flaws are not loss-tolerant, while QKD implementations must account for imperfect preparation and coherent attacks.
Method
The paper uses virtual protocols, linear relations among transmission rates, and conditional-probability analysis to estimate phase errors for imperfect sources and coherent attacks.
Results
The technique applies to tilted four-state protocols, three-state protocols with modulation errors, and three-state preparations with linearly independent state vectors.
Takeaways & Limitations
The approach extends phase-error estimation across several QKD protocols and supports security analysis with less restrictive state-preparation geometry.
Abstract
from arXiv · showhide
In principle, quantum key distribution (QKD) offers unconditional security based on the laws of physics. In practice, flaws in the state preparation undermine the security of QKD systems, as standard theoretical approaches to deal with state preparation flaws are not loss-tolerant. An eavesdropper can enhance and exploit such imperfections through quantum channel loss, thus dramatically lowering the key generation rate. Crucially, the security analyses of most existing QKD experiments are rather unrealistic as they typically neglect this effect. Here, we propose a novel and general approach that makes QKD loss-tolerant to state preparation flaws. Importantly, it suggests that the state preparation process in QKD can be significantly less precise than initially thought. Our method can widely apply to other quantum cryptographic protocols.
Appendix A: Three-state protocol & coherent attacks
The appendix extends the three-state protocol proof to coherent attacks by representing preparation and measurement paths explicitly, then using conditional probabilities and Azuma’s inequality to recover event counts and estimate the phase error rate.
- Key generation uses events where both parties choose Z, while Bob’s X-basis events provide parameter estimation.
- Alice’s Z-basis preparation and the |0x⟩ signal are represented through virtual entangled states followed by measurements on her auxiliary system.
- The five sending-state paths are indexed by a shield-system measurement, linking each path to one of Alice’s possible signals.
- For coherent attacks, conditional probabilities depend on previous outcomes, while Azuma’s inequality converts these probabilities into actual event counts.
- Figure 2 tracks Alice’s sending states, Bob’s POVM outcomes, and inconclusive events in the virtual protocol used to define ex.
- Summing the conditional probabilities preserves the main-text linear relations, allowing the virtual phase error rate to be estimated under coherent attacks.
Appendix B: Imperfect state preparation
The appendix applies the phase-error estimation technique to a tilted four-state protocol and to the three-state protocol with modulation errors.
- The analysis covers both a tilted four-state variant of BB84 and a three-state protocol with modulation errors.
1. A tilted four-state protocol
For the tilted four-state protocol, linearly independent Bloch vectors let the analysis reconstruct Pauli-operator transmission rates and therefore the phase error rate of virtual states.
- 1. A tilted four-state protocol: The four state vectors are assumed mutually linearly independent, forming a triangular pyramid through their Bloch-vector endpoints.
- 1. A tilted four-state protocol: Alice’s Z-basis preparation can use either of two purifications that differ by a bit-flip, and the choice may optimize the key-generation rate.
- 1. A tilted four-state protocol: The virtual protocol measures the purification in the X basis and defines virtual states whose detection probabilities determine ex.
- 1. A tilted four-state protocol: The observed experimental constraints form linear equations for the identity and Pauli transmission rates.
- 1. A tilted four-state protocol: When the vectors are linearly independent, solving those equations gives the exact transmission rate of any state, including the virtual states used for ex.
- 1. A tilted four-state protocol: If Bob’s POVM acts on qubits and includes a Y-basis measurement, the same construction can estimate the Y-basis error rate.
2. Three-state protocol
The same phase-error technique extends to three-state protocols with modulation errors and, under linear-independence conditions, to broader three-state preparations.
- 2. Three-state protocol: The phase-error estimation technique applies directly to the three-state protocol with modulation errors.
- 2. Three-state protocol: When the actual states lie in the X-Z plane and the corresponding vectors are linearly independent, the virtual states can also be placed in that plane.
- 2. Three-state protocol: Because the virtual states share the X-Z plane, their transmission rates and the phase error rate follow from the same linear-reconstruction argument.
- 2. Three-state protocol: Any three states can support secure key distribution when their vectors are mutually linearly independent, forming a triangle on the Bloch sphere.
- 2. Three-state protocol: A filtering operation can lift X-Z-plane states into the plane spanned by the three actual states, enabling reconstruction of the virtual-state transmission rates.
Appendix C: Simulation for the three-state protocol
The appendix models the three-state protocol’s single-photon signals as a qubit system, derives the relevant gains and error rates, and uses the phase-error method to obtain precise transmission rates.
- Signal model: The single-photon components are represented in a qubit basis for the signal states used in the simulation.The construction identifies the relevant photon-number states and chooses corresponding Z- and Y-basis representations.
- Virtual protocol: Alice’s virtual entanglement-based state is expressed using the Z-basis states before system B is sent through the channel.This virtual representation supports the subsequent phase-error analysis.
- Phase-error estimation: The phase-error estimation technique provides the exact transmission rates Y_sx,jx needed for the analysis.These rates are then used to determine the relevant phase-error quantities for the imperfect signals.
- Channel simulation: The simulation uses conditional detection probabilities determined by the channel model, dark counts, total loss, and the modulation-error transformation.The model separates photon-generated clicks, dark-count clicks, and simultaneous clicks, assigning random bits to simultaneous detections.
- Key-rate inputs: The appendix derives the overall gain and Z-basis bit-error rate alongside the phase-error quantities for the simulated protocol.The phase-modulation distribution and the resulting gain and error parameters enter the lower-bound key-rate calculation.