Source-linked AI summary

Continuous-Variable Measurement-Device-Independent Quantum Key Distribution

Zhengyu Li, Yi-Chen Zhang, Feihu Xu, Xiang Peng, Hong Guo

arXiv:1312.4655v3quant-ph

TL;DR

Practical CV QKD is threatened by detector side channels that are difficult to characterize comprehensively. The paper proposes CV-MDI QKD with an untrusted measurement party and analyzes it through an equivalent coherent-state heterodyne model. The protocol reaches 80 km with ideal reconciliation and 40 km at βR = 0.95 when Charlie is close to Bob, while a minimally revised one-way detection scheme is also proposed.

  • Problem

    Detector attacks can manipulate CV-QKD measurements, and fully characterizing real detectors and all detector loopholes is difficult.

  • Method

    The paper introduces CV-MDI QKD with an untrusted Charlie and derives security using an equivalent entanglement-based model corresponding to coherent-state CV QKD with heterodyne detection.

  • Results

    80 km is reached with βR = 1 and 40 km with βR = 0.95 when Charlie is close to Bob; the proposed detection scheme is immune to collective detector attacks.

  • Takeaways & Limitations

    A corresponding detection scheme requires only slight revisions to existing CV-QKD systems and is presented as feasible for practical use.

Abstract

from arXiv · show

We propose a continuous-variable measurement-device-independent quantum key distribution (CV-MDI QKD) protocol, in which detection is conducted by an untrusted third party. Our protocol can defend all detector side channels, which seriously threaten the security of a practical CV QKD system. Its security analysis against arbitrary collective attacks is derived based on the fact that the entanglement-based scheme of CV-MDI QKD is equivalent to the conventional CV QKD with coherent states and heterodyne detection. We find that the maximal total transmission distance is achieved by setting the untrusted third party close to one of the legitimate users. Furthermore, an alternate detection scheme, a special application of CV-MDI QKD, is proposed to enhance the security of the standard CV QKD system.

I. INTRODUCTION

CV QKD offers practical advantages but detector imperfections create serious security loopholes that are difficult to characterize comprehensively. The paper proposes CV-MDI QKD with an untrusted measurement party and develops its security analysis and performance evaluation.

  • Motivation: Detector imperfections can open security loopholes because practical devices deviate from ideal theoretical models.The paper identifies detector attacks as a central practical threat to QKD security.
  • Motivation: Calibration, local-oscillator fluctuation, wavelength, and saturation attacks can manipulate measurements or conceal intercept-resend attacks.These attacks can cause secret-key overestimation or excess-noise underestimation.
  • Motivation: Fully characterizing real detectors and accounting for every loophole is difficult, motivating protection against general detector attacks.Targeted countermeasures are useful once an attack is known, but do not address unknown loopholes comprehensively.
  • Proposal: CV-MDI QKD introduces an untrusted third party, Charlie, to perform the measurement while Alice and Bob generate the key through post-processing.The protocol is designed to defend all detector side channels.
  • Contributions: The security analysis uses an equivalent entanglement-based scheme, while a corresponding prepare-and-measure implementation and numerical performance study are provided.The entanglement-based scheme is equivalent to coherent-state CV QKD with heterodyne detection.
  • Organization: The paper presents the protocol description, security analysis, numerical secret-key-rate simulations, and potential applications in four main sections.The sections cover both entanglement-based and prepare-and-measure schemes.

MEASUREMENT-DEVICE-INDEPENDENT QKD PROTOCOL

The protocol has equivalent entanglement-based and prepare-and-measure descriptions: Alice and Bob send independently prepared states to Charlie, whose announced measurements are used in Bob’s data correction. Charlie remains completely untrusted.

  • Post-processing: Alice and Bob complete parameter estimation, information reconciliation, and privacy amplification over an authenticated public channel.These steps follow Charlie’s public measurement announcement and Bob’s data modification.
  • Equivalent descriptions: In the entanglement-based description, Charlie’s measurement and Bob’s displacement entangle the retained modes, producing correlated final heterodyne data.This establishes the connection between the entanglement-based and prepare-and-measure descriptions.
  • Protocol preparation: Alice and Bob independently prepare Gaussian-modulated coherent states and send them through separate channels to Charlie.The equivalent entanglement-based description instead uses two-mode squeezed states with one mode retained by each user.
  • Post-processing: Bob forms corrected data as XB = xB + kXC and PB = pB − kPD, while Alice keeps XA = xA and PA = pA.The coefficient k depends on channel loss.
  • Security model: The prepare-and-measure scheme requires no measurements inside Alice’s or Bob’s devices, and Charlie is totally untrusted.This device arrangement gives the protocol its measurement-device-independent characterization.

III. SECURITY ANALYSIS

Security is analyzed through an equivalent one-way coherent-state CV-QKD model with heterodyne detection, treating Charlie and relevant internal operations as controlled by Eve. The resulting practical key-rate expression is immune to collective detector attacks, though its bound is not tight.

  • Equivalent model: Treating Bob’s initial entangled state and displacement as untrusted makes the entanglement-based protocol equivalent to one-way CV QKD with coherent states and heterodyne detection.The CV-MDI scheme is a constrained case of this equivalent model, so the security analysis applies against arbitrary collective attacks.
  • Key-rate bound: The secret-key rate is bounded by the reconciliation-weighted Alice–Bob mutual information minus Bob–Eve’s Holevo information.The expression uses βR I(XA, PA : XB, PB) − χ2(XB, PB : E).
  • Attack model: The analysis assumes Eve can purify the whole system and invokes optimality of Gaussian collective attacks to bound the relevant Holevo quantity.These assumptions reduce the security calculation to properties of the shared quantum state.
  • Parameter estimation: The shared-state covariance matrix can be estimated experimentally through parameter estimation.This connects the theoretical security expression to practical implementation.
  • Practical security rate: The practical rate KR2 is calculable from parameter estimation under the assumption that Eve controls Charlie.This rate is used because it provides a practical bound even though it is not very tight.
  • Detector security: Using KR2 as the secret-key rate makes the protocol immune to all collective attacks against detectors.The security argument treats Charlie’s measurement device as controlled by Eve.

A. Numerical simulation

The simulations model CV-MDI QKD under independent entangling-cloner attacks and compare secret-key performance across symmetric and asymmetric channel configurations. They show that symmetric links are limited to short distances, while placing Charlie near one user substantially extends transmission distance.

  • Simulation model: The simulations assume independent entangling-cloner attacks on Alice–Charlie and Bob–Charlie channels, with Charlie performing CV entanglement swapping.Channel loss is modeled as α = 0.2 dB/km, with transmittances ηA and ηB determined by the respective distances.
  • Alternate detection scheme: The alternate one-way detection scheme uses a modified heterodyne measurement followed by data processing based on measurement results and quadrature means.It corresponds to the CV-MDI QKD entanglement-based scheme with Bob taking over Charlie’s operations and LBC = 0 km.
  • Symmetric configuration: In the symmetric case, the maximal total transmission distance LAB = LAC + LBC is around 7 km under both ideal and practical conditions.The practical case uses VA = VB = 40 and εA = εB = 0.002, while the ideal case uses VA = VB = 105 and zero excess noise.
  • Symmetric configuration: At LAC = 3.5 km, the equivalent excess noise is around 0.35 even without channel excess noise, preventing secret-key extraction at longer symmetric distances.The equivalent excess noise increases quickly as the transmission distance grows.

B. Discussion and application

The protocol’s asymmetric postprocessing makes channel placement decisive: symmetric links are limited, while placing Charlie near Bob enables longer transmission. A related one-way detection scheme preserves detector-attack immunity with modest implementation changes.

  • Equation (5) is asymmetric because only Bob modifies his data, so symmetric channel placement cannot optimize performance.
  • When Charlie is close to Bob, the asymmetric configuration can reach up to 80 km in theory.
  • The alternate detection scheme replaces heterodyne vacuum input with a Gaussian-modulated coherent state and optimizes Bob’s data-processing gain classically.
  • With reconciliation efficiency βR = 0.95, the alternate scheme reaches a maximal transmission distance of 40 km.
  • The scheme’s optimized gain makes local-oscillator fluctuation and calibration attacks leave the final secret-key rate unchanged from the nonattack case.

V. CONCLUSION

The paper proposes CV-MDI QKD immune to collective detector attacks and evaluates its transmission limits under symmetric and asymmetric placement. It also introduces a one-way detection scheme requiring only slight revisions to existing CV-QKD systems.

  • The protocol is immune to all collective attacks against detectors.
  • Under entangling-cloner simulations, symmetric placement limits transmission, whereas placing Charlie close to Bob enables up to 80 km for βR = 1 and 40 km for β = 0.95.
  • The corresponding one-way detection scheme is immune to all collective detector attacks and requires only slight revisions to existing CV-QKD systems.
  • An independent work uses conditional-scenario security analysis, complex postprocessing, and a model of Eve’s general attack.

Appendix A: Equivalence between PM scheme and EB scheme

The appendix establishes equivalence between the prepare-and-measure and entanglement-based constructions by matching their joint probabilities under appropriate displacements and gain choices.

  • Modified protocol: Alice and Bob’s modified protocol replaces coherent-state preparation with independent two-mode squeezed states followed by heterodyne measurements.This construction produces the variables used to compare the modified protocol with the entanglement-based scheme.
  • Entanglement-based scheme: The entanglement-based scheme conditions Alice and Bob’s remaining state on Eve’s measurement results {XC, PD}.Bob then displaces mode B1 by g(XC + iPD) before heterodyne detection.
  • Equivalence condition: The two schemes have identical joint probabilities when the displacement gain satisfies g = 2k1.The equality follows by comparing the measurement probabilities after the beam splitter and displacement operations.
  • Conclusion: Therefore, the entanglement-based scheme is equivalent to the modified protocol and, through their prior equivalence, to the prepare-and-measure scheme.This establishes the equivalence used for the protocol’s security analysis.

Appendix B: Relationship of quadratures used in numerical simulation

The appendix describes the optical sequence used in numerical simulation: channel outputs interfere at a balanced beam splitter before the resulting modes are detected.

  • Optical transformation: After transmission through the channels, modes A′ and B′ interfere on a 50:50 beam splitter.The resulting modes C and D are then used in the detection sequence.
  • Displacement: The appendix separately identifies the state of mode B′ after displacement as part of the simulation procedure.No further quantitative comparison is stated in the supplied passages.
Loading 1312.4655v3…