Source-linked AI summary
High-rate quantum cryptography in untrusted networks
Stefano Pirandola, Carlo Ottaviani, Gaetana Spedalieri, Christian Weedbrook, Samuel L. Braunstein, Seth Lloyd, Tobias Gehring, Christian S. Jacobsen, Ulrik L. Andersen
TL;DR
The paper studies continuous-variable quantum cryptography when end-users connect through insecure links to an untrusted relay rather than sharing a direct channel. It proposes coherent-state transmission with continuous-variable Bell detection and shows that secret keys remain possible under coherent attacks, with experimentally demonstrated rates several orders of magnitude above comparable qubit-based protocols.
Problem
The paper addresses how end-users can establish secret keys in network topologies without direct quantum channels when the intermediate relay and links are untrusted.
Method
Alice and Bob modulate coherent states with Gaussian distributions, send them to an intermediate continuous-variable Bell relay, and infer correlations from the broadcast outcome while analyzing coherent attacks.
Results
Secret-key distribution remains possible under coherent attacks, with rates well beyond 100km in suitable asymmetric configurations and experimentally demonstrated performance several orders of magnitude above comparable qubit-based protocols.
Takeaways & Limitations
An untrusted relay can act as a proxy near one party, supporting efficient star-network quantum cryptography with simple relay resources.
Abstract
from arXiv · showhide
We extend the field of continuous-variable quantum cryptography to a network formulation where two honest parties connect to an untrusted relay by insecure quantum links. To generate secret correlations, they transmit coherent states to the relay where a continuous-variable Bell detection is performed and the outcome broadcast. Even though the detection could be fully corrupted and the links subject to optimal coherent attacks, the honest parties can still extract a secret key, achieving high rates when the relay is proximal to one party, as typical in public networks with access points or proxy servers. Our theory is confirmed by an experiment generating key-rates which are orders of magnitude higher than those achievable with discrete-variable protocols. Thus, using the cheapest possible quantum resources, we experimentally show the possibility of high-rate quantum key distribution in network topologies where direct links are missing between end-users and intermediate relays cannot be trusted.
I. RESULTS
The protocol combines coherent-state transmission with continuous-variable Bell detection at an untrusted relay, and reduces general eavesdropping to coherent Gaussian attacks on the links. Secret-key generation remains possible, with the strongest rates when the relay is close to Alice and Bob’s link is long.
- Protocol: Alice and Bob send Gaussian-modulated coherent states to a continuous-variable Bell relay, whose broadcast outcome creates correlations they can postprocess.The relay mixes the incoming modes and performs conjugate homodyne detection; Bob can use the broadcast outcome to infer Alice’s variable.
- Security analysis: Eve’s most general joint attack can be modeled through a relay simulator and quantum memory, then reduced to a coherent Gaussian attack on the links.Random permutations reduce attacks coherent across many uses to attacks coherent within one use, while Gaussian statistics permit analysis through first- and second-order moments.
- Secret-key rate: The secret-key rate is R = IAB − IE, and positive rates allow error correction and privacy amplification to distill R secret bits per relay use.The equivalent noise separates loss from excess noise, with the latter included in the rate as R(τA, τB, ε).
- Network configuration: In the symmetric pure-loss configuration, the rate vanishes near τ ≃0.84, limiting each party to approximately 3.8km from a central relay.This motivates asymmetric configurations with one low-loss link.
- Network configuration: With Alice’s link nearly lossless, the rate remains positive as Bob’s transmissivity approaches zero, enabling extremely long distances when the relay is near Alice.For a relay sufficiently close to Alice, key distribution remains possible beyond 100km and is robust to excess noise ε = 0.1.
II. DISCUSSION
The paper extends continuous-variable quantum cryptography to networks with untrusted relays and insecure links, using a simple relay and an asymmetric configuration to achieve high rates.
- The protocol supports secret-key extraction despite a fully corrupted relay and coherent attacks on the links.
- The relay uses continuous-variable Bell detection with highly efficient photodetectors and linear optics, while post-processing remains with the end-users.
- The optimal configuration places the untrusted relay near one party, such as a proxy server in a public network.
- The experiment demonstrates rates several orders of magnitude higher than qubit-based protocols over comparable distances.
- The scheme can remove trust and reliability requirements from half of the nodes in a large network.
III. METHODS
The supplementary information contains the theoretical methods, experimental details, and data analysis.
- The supplementary information provides full theoretical methods and derivations.
- It includes experimental details for the study.
- It includes the analysis of experimental data.
Supplementary Information
The document covers theoretical derivations, experimental procedures, post-processing, and finite-size effects.
- Section I presents the theoretical methods and derivations used in the study.
- Section II discusses the experimental setup and data post-processing.
- The document analyzes various finite-size effects.
I. THEORETICAL METHODS
The theoretical analysis represents the protocol with entanglement-based tools, reduces joint relay-and-link attacks to Gaussian link attacks, and derives the secret-key rate from observed statistics and conditional covariance matrices.
- The protocol is analyzed using an entanglement-based representation in which coherent states arise from heterodyne measurements on EPR states.
- The secret-key rate is determined from the conditional state and relay-outcome statistics, and can be computed from the post-relay covariance matrix.
- An arbitrary joint attack on the links and relay can be reduced to an attack on the links with a properly working relay while preserving observed statistics.
- Gaussian extremality permits replacing the observed distribution with a Gaussian distribution having the same first- and second-order moments for the security analysis.
- Random permutations reduce attacks coherent across many relay uses to attacks coherent within a single use.
- The conditional covariance matrix is reconstructed from observed joint statistics and second-order moments during data comparison.
D. Realistic Gaussian attack against the links
The realistic Gaussian attack is parameterized by link transmissivities, thermal noises, and correlations between Eve’s ancillary modes. Physical correlations occupy a bounded convex region that separates separable from entangled attacks, including EPR attacks that help or disrupt Bell detection.
- Attack model: Eve’s two-mode Gaussian attack uses beam splitters with transmissivities τA and τB, mixing the incoming modes with ancillary modes E1 and E2.The output ancillas are stored in quantum memory, while relay outputs are measured and broadcast.
- Correlation plane: For fixed thermal noises ωA and ωB, the correlation parameters g and g′ determine Eve’s covariance matrix and form the correlation plane.The allowed points are constrained by bona-fide conditions derived from the uncertainty principle.
- Correlation plane: The accessible correlation region is bounded, continuous, and convex, collapsing to g′ = g = 0 when either thermal noise equals one.Its boundary depends on ωA and ωB.
- Attack classes: The inner region represents separable ancillary attacks, while peripheral regions represent attacks using entangled ancillas.The distinction is determined by the least partially transposed symplectic eigenvalue.
- EPR attacks: Positive EPR correlations help Bell detection, whereas negative EPR correlations oppose it and correspond to the extremal top-left point.The positive and negative attacks occupy the bottom-right and top-left peripheral regions, respectively.
E. Analytical derivation of the secret-key rate
The secret-key rate is derived from the post-relay covariance matrix, combining Alice–Bob mutual information with Eve’s Holevo information. The resulting rate depends on the transmissivities, thermal noises, and ancillary correlations, with a continuous symmetric limit for equal transmissivities.
- Post-relay state: The post-relay covariance matrix Vab|γ is computed first, because it determines the remote states of Alice and Bob after relay measurement.The subsequent reduced covariance matrices support the mutual-information and conditional-entropy calculations.
- Mutual information: Alice–Bob mutual information is computed from the classical covariance matrix of their conditioned detector outcomes and can be expressed using an equivalent noise χ.The equivalent noise depends on the post-relay covariance matrix reconstructed from observed statistics.
- Eve’s information: Eve’s information is bounded by the Holevo quantity, evaluated from symplectic spectra of the joint and conditionally reduced states.The entropy terms use the symplectic eigenvalues of Vab|γ and Bob’s state conditioned on Alice’s outcome.
- Rate formula: The entropy, Holevo information, and secret-key rate remain continuous at τA = τB.This continuity resolves the apparent distinction between asymmetric and symmetric transmissivity cases.
- Rate formula: The secret-key rate is R = IAB − IE and is expressed as R(τA, τB, ωA, ωB, g, g′) for large modulation.A continuous limit is obtained when τA = τB.
1. Minimization of the rate at fixed thermal noise
At fixed transmissivities and thermal noises, rate minimization reduces to the accessible correlation-plane bisector because both the rate and physical region are symmetric there. The optimal attack is the negative EPR attack at the extremal top-left point.
- Symmetry reduction: The rate depends on g and g′ only through λ and λ′ and is invariant under their permutation, giving symmetry about g′ = −g.The accessible correlation region has the same symmetry and is convex.
- Symmetry reduction: Minimization can therefore be restricted to accessible points on the bisector g′ = −g, where λ′ = λ.This converts the two-correlation optimization into a one-dimensional boundary search.
- Optimal attack: The rate is minimized by maximizing λ, which occurs at the maximal accessible g′ and yields g′ = −g = φ.This point is the extremal top-left point of the accessible correlation region.
- Optimal attack: The optimal coherent attack is the negative EPR attack, whose injected correlations tend to destroy those established by Bell detection.The minimum rate has a continuous expression at τA = τB.
- Comparison: The negative EPR attack outperforms the collective entangling-cloner attack, represented by the origin g′ = g = 0.This makes the security analysis more complex than analyses restricted to independent entangling cloners.
2. Minimization of the rate at fixed equivalent noise
When only transmissivities and equivalent noise are known, the rate can still be minimized over hidden correlation parameters. The resulting formulas show an asymmetric positive-rate region favoring a relay close to one party and remain robust to excess noise.
- Reduced-parameter minimization: The equivalent noise χ is determined by the post-relay covariance matrix and empirical statistics, so τA, τB, and χ provide sufficient accessible parameters for minimization.The general rate is reduced to a minimum-rate formula depending on these three quantities.
- Reduced-parameter minimization: At fixed equivalent noise, the minimum occurs where each iso-noise curve intersects the bisector g′ = −g.The construction compares iso-rate and iso-noise curves on the accessible correlation plane.
- Theoretical result: The resulting minimum-rate formulas are the paper’s main theoretical result and coincide with the main-text equations.They provide the rate under the constrained knowledge of transmissivities and equivalent noise.
- Noise regimes: For pure loss, ε = 0, the minimum rate simplifies, while excess noise ε worsens the rate through the decomposition χ = χ_loss + ε.The pure-loss case estimates the protocol’s maximum performance.
- Network configuration: Positive rates occur above an asymmetric transmissivity threshold; when τA is close to one, τB can approach zero.With standard optical fibre loss, this corresponds to Alice being close to the relay while Bob is far away, and the behavior remains robust for ε > 0.
G. Minimum rate in limit configurations
The optimal asymmetric configuration places the relay close to Alice, while the opposite and symmetric configurations have more restrictive distance limits. The conditional covariance-matrix derivation supplies the theoretical rate expressions used for these comparisons.
- Alice close to relay: When Alice’s link has small loss, the rate vanishes only as Bob’s transmissivity τB approaches zero, allowing Bob to be arbitrarily far from the relay.This limit corresponds to the coherent Gaussian attack collapsing to an entangling-cloner attack on Bob’s link only.
- Rate equivalence: The τA→1 rate equals the reverse-reconciliation rate of a point-to-point no-switching protocol from Alice to Bob.This equivalence explains why comparable security performance is possible without a direct Alice–Bob link.
- Bob close to relay: When Bob’s link has small loss, the rate is zero at τA ≃0.73, restricting Alice’s relay distance to about 6.8km in standard optical fibre.The same limit coincides with the direct-reconciliation rate of a point-to-point no-switching protocol.
- Symmetric configuration: In the symmetric pure-loss configuration, the rate vanishes at τ ≃0.84, restricting both parties’ distances from the relay to about 3.8km.Its performance is comparable to the configuration with Bob approaching the relay.
- Covariance-matrix derivation: The theoretical analysis derives the conditional remote covariance matrix after Bell measurement by transforming and reducing the global covariance matrix.The derivation applies beam-splitter transformations, traces out Eve’s modes, and uses covariance-matrix rules for Bell-like measurements.
II. EXPERIMENTAL METHODS
The experimental-methods section first introduces the optical setup, then develops its mathematical interpretation and addresses data post-processing and finite-size effects.
- Section organization: The experiment is organized into a general optical-setup description followed by mathematical modeling, data post-processing, and finite-size analysis.These topics are treated in Sections II A and II B.
A. General description of the optical setup
The experiment uses phase-locked bright coherent beams, independently Gaussian-modulated at Alice and Bob, with Bob’s modulation attenuated to emulate channel loss. A balanced-beam-splitter relay performs continuous-variable Bell detection on the beams.
- Laser and local oscillator: A stable 1064nm laser is split between Alice and Bob to provide a common local oscillator for the two stations.The paper notes that future implementations could achieve phase locking through atom-clock synchronization and classical communication.
- State preparation: Amplitude and phase electro-optical modulators apply independent Gaussian signals to the beams at Alice’s and Bob’s stations.The modulations are white within the measurement bandwidth, with polarization controlled to separate amplitude and phase modulation.
- Bell detection: At the relay, a balanced beam splitter and two balanced detectors measure the difference of amplitude quadratures and the sum of phase quadratures.The beam splitter visibility is 96%, and a piezo-mounted mirror actively controls the relative phase.
- Acquisition: Measurements are performed at 10.5MHz, mixed down, low-pass filtered at 100kHz, and digitized at 500kHz with 14-bit resolution.Each data block contains 10^6 points collected over 2 seconds.
- Loss simulation: Bob’s modulation depth is reduced to simulate beam-splitter transmission loss while keeping the carrier power relative to the sidebands constant.This attenuation is experimentally convenient while reproducing the channel’s effect on the modulated sidebands.
B. Detailed mathematical description of the experiment and data post-processing
The experiment maps electronic modulations to optical quadratures, models channel loss through modulation attenuation, and estimates the key rate from relay-conditioned covariance matrices. Finite-size effects become negligible after roughly 10^5 rounds, while residual experimental noise is modeled as excess noise.
- Relay processing: The relay outcome is formed from weighted sums and differences of detector outputs, with optimization parameter r compensating quadrature asymmetries and q-p correlations.In the experiment, the optimal r can lie between 0.45 and 0.75; r=1 gives the standard quadrature combinations.
- Calibration: Electro-optical gains convert electronic displacements into optical quadratures through qA=t1Aq, qB=t2Bq, pA=t3Ap, and pB=t4Bp.These calibrated quadratures provide the experimental variables used in the covariance-matrix analysis.
- Channel modeling: The modulation variance is approximately ϕ≃65 vacuum-noise units, and Bob’s equivalent transmissivity is implemented as ϕB=τBϕ.The experiment reaches τB≈4×10^-4, corresponding to 34dB loss or 170km of optical fibre.
- Rate estimation: Alice and Bob estimate τB and the global classical covariance matrix from their data, then derive the secret-key rate from those estimated statistics.The relay variables are eliminated to form a conditional covariance matrix, which is symmetrized before constructing the equivalent quantum covariance matrix.
- Finite-size effects: Asymptotic statistical values are reached after approximately 10^5 rounds, so finite-size effects on the key rate can be neglected with that comparison subset.The experiment uses blocks of 10^6 points, making the estimation subset comparatively small in a real-time implementation.
- Experimental imperfections: Residual experimental imperfections affect the rate like a coherent Gaussian attack with excess noise ε≲0.02, while reconciliation efficiency is ξ≃97% in current practice.The ideal reconciliation value is ξ=1.