Source-linked AI summary
Experimental demonstration of Gaussian protocols for one-sided device-independent quantum key distribution
Nathan Walk, Sara Hosseni, Jiao Geng, Oliver Thearle, Jing Yan Haw, Seiji Armstrong, Syed M Assad, Jiri Janousek, Timothy C Ralph, Thomas Symul, Howard M Wiseman, Ping Koy Lam
TL;DR
The paper asks which Gaussian CVQKD protocols can provide one-sided device-independent security and how much loss they tolerate. It derives their asymptotic key rates and steering connection, then experimentally demonstrates entanglement-based and coherent-state implementations over fibre-equivalent losses up to 7.5 km and 3.5 km, respectively.
Problem
The paper addresses how to obtain QKD security with one untrusted device across the Gaussian CVQKD family while accounting for channel loss and experimental implementation.
Method
The authors analyse all 16 Gaussian CVQKD protocols using entropic uncertainty relations, identify 1sDI cases, derive asymptotic key rates, and implement selected entanglement-based and coherent-state schemes.
Results
Six protocols are proven 1sDI; experiments obtain positive key independent of one party’s devices up to 7.57±0.26 km for entanglement-based reverse reconciliation and 3.47±0.46 km for direct-reconciliation coherent states.
Takeaways & Limitations
Coherent states can support 1sDI-CVQKD, linking practical CVQKD hardware to a more secure setting and providing an operational connection between steering and extractable key bits.
Takeaways & Limitations
Even under ideal conditions, the asymptotic analysis limits 1sDI-CVQKD to transmission through urban networks.
Abstract
from arXiv · showhide
Nonlocal correlations, a longstanding foundational topic in quantum information, have recently found application as a resource for cryptographic tasks where not all devices are trusted, for example in settings with a highly secure central hub, such as a bank or government department, and less secure satellite stations which are inherently more vulnerable to hardware "hacking" attacks. The asymmetric phenomena of Einstein-Podolsky-Rosen steering plays a key role in one-sided device-independent quantum key distribution (1sDI-QKD) protocols. In the context of continuous-variable (CV) QKD schemes utilizing Gaussian states and measurements, we identify all protocols that can be 1sDI and their maximum loss tolerance. Surprisingly, this includes a protocol that uses only coherent states. We also establish a direct link between the relevant EPR steering inequality and the secret key rate, further strengthening the relationship between these asymmetric notions of nonlocality and device independence. We experimentally implement both entanglement-based and coherent-state protocols, and measure the correlations necessary for 1sDI key distribution up to an applied loss equivalent to 7.5 km and 3.5 km of optical fiber transmission respectively. We also engage in detailed modelling to understand the limits of our current experiment and the potential for further improvements. The new protocols we uncover apply the cheap and efficient hardware of CVQKD systems in a significantly more secure setting.
I. INTRODUCTION
The paper addresses how to achieve QKD security with fewer device-characterisation assumptions by identifying Gaussian CVQKD protocols that remain secure when one party’s devices are untrusted.
- I. INTRODUCTION: The paper identifies all Gaussian CVQKD protocols that can be proven secure in a one-sided device-independent setting.The analysis covers the full Gaussian family and includes prepare-and-measure schemes.
- I. INTRODUCTION: Six protocols, including two prepare-and-measure schemes, are shown to be 1sDI, with secret-key rates calculated against arbitrary attacks in the asymptotic setting.
- I. INTRODUCTION: 1sDI-CVQKD is possible using coherent states, extending the approach to a cheap and practical quantum-optical resource.
- I. INTRODUCTION: The protocols are reasonably robust to losses but remain inherently loss-limited, making them more practical than discrete-variable counterparts over short to medium distances.
- I. INTRODUCTION: The work experimentally implements entanglement-based and coherent-state protocols and targets short-range 1sDI metropolitan networks.
A. Entropic uncertainty relations and CVQKD
The paper derives secret-key bounds for Gaussian CVQKD from entropic uncertainty relations, reducing security evaluation to experimentally accessible statistics under the relevant asymptotic assumptions.
- A. Entropic uncertainty relations and CVQKD: Gaussian CVQKD protocols encode information in optical quadratures using squeezed or coherent states with homodyne or heterodyne detection.
- A. Entropic uncertainty relations and CVQKD: The security analysis uses Gaussian extremality and the infinite-dimensional de Finetti theorem to reduce asymptotic coherent attacks to Gaussian collective attacks.
- A. Entropic uncertainty relations and CVQKD: A tripartite entropic uncertainty relation bounds Eve’s information about conjugate quadratures in the infinite-dimensional setting relevant to CVQKD.
- A. Entropic uncertainty relations and CVQKD: The resulting key-rate bound depends only on conditional Shannon entropies accessible to Alice and Bob and can be evaluated from conditional variances.
- A. Entropic uncertainty relations and CVQKD: For heterodyne protocols, only one reconciliation direction can support a 1sDI protocol.
B. One-sided device-independent CVQKD
One-sided device independence trusts one party’s measurement operations while treating the other party’s device as a black box, with security tied to steering on the trusted side.
- B. One-sided device-independent CVQKD: A 1sDI protocol leaves Alice’s or Bob’s device untrusted while assuming the other station performs a specified set of quantum operations.
- B. One-sided device-independent CVQKD: For EPR states with homodyne measurements, positive entropic key rates are 1sDI, independent of Alice for reverse reconciliation and Bob for direct reconciliation.
- B. One-sided device-independent CVQKD: Heterodyne detection on the untrusted side invalidates device independence because the proof requires characterising that detector and lacks the measurement choice needed for steering.
- B. One-sided device-independent CVQKD: The best theoretical loss tolerance is achieved by the reverse-reconciliation EPR protocol with homodyne detection, remaining secure up to 73% loss at low excess noise.
- B. One-sided device-independent CVQKD: The direct-reconciliation coherent-state scheme performs worst theoretically but remains secure up to around 33% loss.
C. Connection to EPR steering
The paper connects Gaussian 1sDI key generation to EPR steering by expressing the key condition through conditional-variance criteria and interpreting the steering parameter operationally.
- C. Connection to EPR steering: For Gaussian states and measurements, Alice steers Bob when the product of conditional variances satisfies E▶ := V_XB|XA V_PB|PA < 1.
- C. Connection to EPR steering: For homodyne protocols, a positive key requires a stricter condition than EPR steering, with K◁ > 0 only if E▶ is below the key-rate threshold.
- C. Connection to EPR steering: The Reid product of conditional variances is directly related to the number of secure 1sDI bits extractable from Gaussian states with Gaussian measurements.
- C. Connection to EPR steering: When Eve is restricted to individual attacks, the entropic steering criteria precisely quantify the extractable secret 1sDI bits.
D. Experimental Results
The experiment implements five Gaussian 1sDI protocols and demonstrates positive-key operation for entanglement-based and coherent-state schemes under fiber-equivalent loss. Reverse-reconciliation EPR measurements reach the longest distance, while source imperfections limit entanglement-based and heterodyne performance.
- Experimental implementation: Five of the sixteen Gaussian protocols are implemented experimentally, and three exhibit correlations sufficient for 1sDI-CVQKD.The implementations use EPR sources for entanglement-based protocols and a coherent-state prepare-and-measure setup.
- Comparison across protocols: The experimentally observed loss-tolerance hierarchy places EPR reverse reconciliation first, coherent-state prepare-and-measure second, and EPR direct reconciliation last.The observed ordering differs from the theoretical hierarchy because the experiment has limited squeezing and additional losses and imperfections.
- Protocol limitations: Heterodyne protocols produce no positive key because their shot-noise penalty requires extremely strong correlations, including at least 7 dB of pure squeezing even over a perfect channel.This threshold assumes reconciliation efficiency of 0.95 and no losses.
- EPR protocols: 7.57±0.26 km: the EPR reverse-reconciliation protocol maintains a positive key rate, compared with 2.52±0.21 km for direct reconciliation.Theoretical maximum ranges are 8 km and 2.8 km, respectively.
- Coherent-state protocol: 3.47±0.46 km: the coherent-state direct-reconciliation protocol remains secure, exceeding the entanglement-based direct-reconciliation range.The model predicts a 4.5 km maximum for the current coherent-state setup.
- Steering and key generation: Positive key generation coincides with steering-parameter thresholds, while all plotted data points violate the Reid EPR-steering criteria.The reported thresholds connect the measured steering parameter with the conditions for 1sDI key generation.
III. DISCUSSION
The paper completes a one-sided device-independent taxonomy of Gaussian CVQKD, experimentally demonstrating secure key distribution and identifying routes toward longer distances.
- III. DISCUSSION: Six of sixteen Gaussian protocols are 1sDI, with asymptotic secret-key rates derived for all six and linked explicitly to Gaussian EPR-steering parameters.The analysis uses entropic uncertainty relations and identifies coherent-state protocols among the 1sDI schemes.
- III. DISCUSSION: Secure key was demonstrated over lossy channels equivalent to 7.5 km of optical fibre, including the first 1sDI CVQKD demonstration using only coherent states.The coherent-state protocol reached an experimentally measured distance of 3.47±0.46 km.
- III. DISCUSSION: Finite-size security proofs are identified as an important extension, while current asymptotic results limit 1sDI-CVQKD to urban-network transmission distances.Existing finite-size results cover some homodyne protocols, but not all protocols considered here.
- III. DISCUSSION: Longer-distance performance may be pursued by revisiting assumptions about Eve or using noiseless linear amplification, including measurement-based variants.These approaches are presented as future directions rather than demonstrated improvements in this experiment.
Funding Information
The supplied passages describe continuous-variable entropic uncertainty methods and Gaussian CVQKD protocol choices; they contain no funding details beyond acknowledgements.
- Appendix A: Entropic uncertainty relations: The appendix develops an uncertainty relation for continuous quadrature observables in infinite-dimensional Hilbert spaces, as required for CVQKD.The relation builds on earlier discrete-measurement results and applies to homodyne detection.
- Appendix B: Secret key rates for Gaussian protocols: Gaussian CVQKD protocols vary by squeezed or coherent-state preparation, homodyne or heterodyne detection, and direct or reverse reconciliation.For heterodyne-involving protocols, only one reconciliation direction permits a 1sDI protocol.
1. Homodyne-Homodyne (Squeezed states and Homodyne Detection)
The homodyne-homodyne analysis derives direct-reconciliation key rates from conditional variances and shows that positive key requires sufficiently strong EPR-type correlations.
- Key-rate construction: The direct-reconciliation key rate is formulated for asymptotic collective attacks when Bob homodyne-measures a quadrature.Alice and Bob randomly choose x or p and retain matching-basis events.
- Key-rate construction: The analysis uses continuous Shannon entropies and the Holevo bound to connect measured correlations with secret-key security.The derivation substitutes entropy expressions into the key-rate bound.
2. Heterodyne-Homodyne (Coherent States and Homodyne Detection)
The heterodyne-homodyne analysis treats coherent-state protocols through an entanglement-based picture and identifies which measurement direction can remain one-sided device-independent.
- Entanglement-based representation: Alice’s heterodyne detection is represented by splitting her EPR mode into two modes and measuring x and p separately.The prepare-and-measure data are rescaled to obtain effective entanglement-based data.
- Key-rate construction: The key-rate bound uses an entropic uncertainty relation together with Gaussian conditional-variance estimates for the unmeasured quadrature.Trust in Alice’s beamsplitter permits replacing the unmeasured conditional variance with a directly measured one.
- Security condition: The heterodyne-homodyne protocol requires V_XA1|XB V_PA2|PB ≤ 0.55 for positive key, equivalent to V_XA|XB V_PA|PB ≤ 0.22 under quadrature symmetry.The latter condition is expressed in terms of homodyne-homodyne conditional variances.
- Device independence: Protocols with heterodyne measurements on both sides are not 1sDI because devices on both sides must be trusted.The analysis treats the x and p channels separately in this case.
Appendix C: Security proof with imperfect reconciliation efficiency
The appendix incorporates imperfect reconciliation efficiency into the Gaussian key-rate analysis by separating Eve’s information bound from the parties’ measured mutual information.
- Imperfect reconciliation: The practical key rate is bounded by βI(XA:XB), with reconciliation efficiency β < 1 replacing ideal Shannon-capacity reconciliation.The observable XA can represent quadrature measurements with or without a shot-noise penalty and is averaged across quadratures when needed.
- Security bound: The entropic uncertainty relation is used to upper-bound Eve’s information, while βI(XA:XB) is measured independently to obtain the actual key rate.Eve’s information is bounded using the Holevo quantity.
- Entropy treatment: The entropy derivation bounds conditional von Neumann entropies using Gaussian Shannon entropies and fixed-variance maximality.The reverse-reconciliation expression is obtained by interchanging Alice and Bob.
Appendix D: Experimental Details and modeling of EB scheme with Homodyne-Homodyne detection
The experiment generates an entanglement-based Gaussian source, models optical and detection imperfections with covariance matrices, and compares predicted key-rate distances with measured data.
- Source preparation: The entanglement-based source is produced by locking two squeezed states in quadrature and mixing them on a 50:50 beamsplitter.A phase shift models imperfect locking before the modes are combined.
- Data acquisition: The experiment samples and filters millions of homodyne data points before extracting key rates from the resulting correlations.The processed data are reduced to 4 × 10^6 points after filtering and resampling.
- Covariance-matrix modeling: The covariance-matrix model captures Gaussian operations, imperfect locking, unbalanced beamsplitters, channel loss, and detection imperfections.Gaussian states and operations are represented through symplectic transformations.
- Imperfection modeling: Optical loss and detector inefficiency are modeled by beamsplitters that mix signal modes with vacuum or thermal noise modes.Detector dark noise is represented through a thermal state in the homodyne-station model.
- Experimental validation: The model and measured conditional variances show excellent agreement as key rates are plotted against effective transmission distance.The applied loss is inferred from correlation ratios relative to full transmission.
- Performance projections: With improved squeezing and detection efficiencies, the model predicts secure ranges extending to 17 km for reverse reconciliation and more than 8 km for direct reconciliation.The prediction assumes -10 dB squeezing, 16 dB anti-squeezing, improved detection, and reduced phase rotation.
Appendix E: Experimental Details and modeling of P&M with coherent states and homodyne detection
The coherent-state experiment models Gaussian modulation, channel loss, detector imperfections, and cross-quadrature correlations to predict secure key rates and optimize modulation. Experimental optimum variances agree with the model, while unwanted cross-talk limits performance and motivates an improved setup.
- Key-rate optimization: For each channel transmission, the experiment scans modulation variance and selects the value producing the highest secure key rate.The scan covers modulation variances from 2 to 19 times the shot noise, with reconciliation coefficient 0.95.
- Equivalent entanglement-based model: The model represents the prepare-and-measure experiment through an equivalent two-mode EPR state, with Alice heterodyning one mode and Bob homodyning the other after channel loss.The coherent-state source is related to the EPR squeezing parameter by cosh(2s) = VS + 1.
- Experimental modeling: The channel model incorporates quadrature excess noise, an experimentally unknown rotation, detector imperfections, and cross-talk effects.The rotation matrix is fitted to represent the unknown rotation caused by the experimental imperfections.
- Imperfection modeling: Increasing modulation strengthens unwanted cross-quadrature effects, reducing the optimal modulation parameter relative to an ideal experiment governed only by reconciliation efficiency.The inset compares the ideal cross-talk-free model with the realistic model including experimental imperfections.
- Experimental validation: The experimentally selected optimal variances agree well with theoretical predictions across the tested transmissions.Figure 7(a) plots key rates against effective modulation squeezing for five transmissions, while Figure 7(c) reports rates at the selected optima.