Source-linked AI summary

Implementation of Continuous-Variable Quantum Key Distribution with Composable and One-Sided-Device-Independent Security Against Coherent Attacks

Tobias Gehring, Vitus Händchen, Jörg Duhme, Fabian Furrer, Torsten Franz, Christoph Pacher, Reinhard F. Werner, Roman Schnabel

arXiv:1406.6174v4quant-ph

TL;DR

The paper addresses the need for finite-size continuous-variable QKD that remains composably secure against coherent attacks and robust to implementation side channels. It implements an EPR-based protocol with one-sided device-independent security under a memoryless-detector assumption, achieving positive key rates over measured attenuation. The demonstrated distance is scope-limited by the security proof and setup losses.

  • Problem

    Finite-size CV QKD implementations had not established composable security against coherent attacks together with robustness to implementation side channels.

  • Method

    The protocol distributes Gaussian EPR-entangled light, uses homodyne detection and controlled quadrature switching, and combines measurement-flaw security analysis with hybrid error reconciliation.

  • Results

    0.1 bit/sample at an equivalent fiber length of 2.7 km (≈0.76 dB channel loss) was achieved with 2 × 10^8 samples and no frame errors.

  • Takeaways & Limitations

    The implementation demonstrates composable, coherent-attack-secure CV QKD with one-sided device-independent security against memoryless attacks on Bob’s detector.

  • Takeaways & Limitations

    The implementation is estimated to be limited to about 4.8 km, while longer distances require lower-loss fibers, reverse reconciliation, or new finite-size security proofs.

Abstract

from arXiv · show

Secret communication over public channels is one of the central pillars of a modern information society. Using quantum key distribution this is achieved without relying on the hardness of mathematical problems which might be compromised by improved algorithms or by future quantum computers. State-of-the-art quantum key distribution requires composable security against coherent attacks for a finite number of distributed quantum states as well as robustness against implementation side-channels. Here, we present an implementation of continuous-variable quantum key distribution satisfying these requirements. Our implementation is based on the distribution of continuous-variable Einstein-Podolsky-Rosen entangled light. It is one-sided device independent, which means the security of the generated key is independent of any memory-free attacks on the remote detector. Since continuous-variable encoding is compatible with conventional optical communication technology, our work is a crucial step towards practical implementations of quantum key distribution with state-of-the-art security based solely on telecom components.

RESULTS

The implementation uses EPR-entangled light and homodyne detection, with controlled quadrature switching and protections against memoryless detector attacks. Same-quadrature measurements produce strong correlations that enter key-length computation.

  • Robustness against Implementation Side-Channels: The protocol is secure against memoryless attacks on Bob’s untrusted detector, including attacks involving local-oscillator intensity, calibration, wavelength, and detector saturation.It also addresses Trojan-horse attacks on the source and local-oscillator side channels associated with Alice’s trusted detector.
  • Einstein-Podolsky-Rosen Source: The implementation places an EPR source at Alice’s station and sends one entangled output to Bob for homodyne-based QKD.Alice’s and Bob’s quadrature measurements are performed locally, while Bob receives the transmitted optical mode.
  • Einstein-Podolsky-Rosen Source: Same-quadrature X or P measurements show strong correlations, whereas measurements of different quadratures are uncorrelated.The correlation strength is related to the initial squeezing and enters the key-length computation through an average distance.
  • Implementation: Both receivers use balanced homodyne detection with computer-controlled quadrature angles, while a phase shifter compensates slow phase drifts.A variable attenuator models transmission losses to Bob, and the measurement rate is 100 kHz.

Precise Steps of the QKD Protocol

The protocol measures randomly selected quadratures of an EPR state, sifts compatible outcomes, discretizes them, estimates channel parameters, reconciles errors, and applies privacy amplification. Negative calculated key lengths cause protocol abortion.

  • Measurement Phase: Alice prepares an EPR state, sends one output and a local oscillator to Bob, and both parties randomly measure X or P by homodyne detection.The measurement phase repeats until 2N samples have been collected.
  • Sifting: Alice and Bob announce their measurement bases and discard samples measured in different quadratures.
  • Discretization: The remaining continuous outcomes are discretized into consecutive 2^d bins, with equal-width bins over [−α, α] and two overflow bins.The parameter α incorporates the finite detector range into the security proof.
  • Channel Parameter Estimation: The parties randomly select k sifted, discretized samples, reveal them publicly, calculate the average distance, and abort if it exceeds a threshold.
  • Error Reconciliation: Bob corrects his data to match Alice’s using hybrid error reconciliation, after which both parties confirm successful reconciliation.
  • Key Generation: Alice and Bob calculate the secret key length from channel estimation and published reconciliation bits, aborting when it is negative, then hash corrected strings to length ℓ.Privacy amplification uses a randomly chosen hash function from a two-universal family.

Assumptions of the Security Proof

The security proof assumes a private Alice station, an isolated Bob station, bounded energy, random quadrature selection, memoryless Bob measurements, and Gaussian phase noise. The implementation characterizes phase noise and uses optimized reconciliation under these assumptions.

  • Assumptions of the Security Proof: Alice’s station must be private, Bob’s station isolated, and Alice’s EPR-mode energy bounded so excursions beyond α can be bounded.
  • Assumptions of the Security Proof: Alice randomly switches between orthogonal X and P quadratures with 50% probability, while Bob randomly chooses between two memoryless measurements.
  • Assumptions of the Security Proof: Alice’s measurement phase noise is assumed Gaussian, with characterized variances VX = VP ≈ (0.46° ± 0.01°)^2.The measured quadratures were reported to satisfy the Gaussian-distribution assumption.
  • Error Reconciliation Protocol: The hybrid reconciliation protocol splits samples into least and most significant bits, using weakly correlated low bits and a non-binary LDPC code over GF(2^d2).The bit split and code are optimized for channel conditions using revealed parameter-estimation samples.
  • Secret Key Generation: The finite-size experiment compares secure key rates across sample sizes and optical attenuation using experimental points and theoretical models.The figure uses common parameters α = 61.6, d = 12, and ϵ = 2×10−10.

Secret Key Generation

The implementation generated positive secret keys at finite sample sizes and maintained key generation over measured channel losses. The authors estimate a practical limit of about 4.8 km for the demonstrated security regime.

  • Secret Key Generation: 0.485 bit/sample was achieved with 2 × 10^8 samples, with the secret key rate close to saturation.A positive secret key rate was already obtained with 5×10^6 samples.
  • Secret Key Generation: About 0.1 bit/sample remained achievable at an equivalent fiber length of 2.7 km, corresponding to approximately 0.76 dB channel loss.The overall error reconciliation efficiency was between β = 94.3 % and 95.5 %, without a single frame error.
  • Secret Key Generation: The theoretical model indicates that nearly 1.2 dB of optical transmission loss, equivalent to about 4.8 km, should be possible.This distance is described as sufficient for composable 1sDI-secure CV QKD links against coherent attacks in a city’s central business district.
  • Secret Key Generation: The implementation combines strong EPR entanglement, highly efficient error reconciliation, and fast random quadrature switching with low phase noise.The setup could in principle connect Alice and Bob through standard telecommunication fiber.
  • Secret Key Generation: The demonstrated implementation is limited to about 4.8 km, while longer distances require lower-loss fibers, reverse reconciliation, or improved finite-size security proofs.The current uncertainty-principle proof does not converge to the collective-attack rate as the number of distributed states increases.

Details of the Experimental Setup

The experiment used high-rate balanced-homodyne measurements with randomly selected amplitude and phase quadratures. Its optical and electronic design supported efficient acquisition, calibration, and a possible fiber-separated configuration.

  • Details of the Experimental Setup: Measurements ran at 100 kHz, with Alice and Bob randomly choosing between the X and P quadratures for each measurement.Relative phase shifts of π/2 were applied to the local oscillator using a high-bandwidth electro-optical phase modulator.
  • Details of the Experimental Setup: 200 samples per channel were acquired at 256 MHz, digitally mixed down to 8 MHz, lowpass filtered at 200 kHz, and down-sampled to one sample.Classical QKD post-processing followed completion of sample acquisition.
  • Details of the Experimental Setup: Both local oscillators used 10 mW power, the homodyne detectors had 98 % efficiency, and the squeezed-light sources used 140 mW and 170 mW pump powers.The local-oscillator measurements yielded about 18 dB dark-noise clearance.
  • Details of the Experimental Setup: The variable attenuator’s optical loss was calibrated using a 35.5 MHz phase modulation measured by Bob’s homodyne detector.Figure error bars reflect the accuracy of this attenuation measurement.
  • Details of the Experimental Setup: Although both parties shared one optical table, standard telecommunication fibers could separate them by time-multiplexing the entangled state and Bob’s local oscillator.A dedicated fiber for both beams was also identified as possible.

Phase Noise

Phase noise during random switching between amplitude and phase measurements was characterized by monitoring the local-oscillator beat with a control beam. The measurement used phase scanning and oscilloscope recordings.

  • Phase Noise: 0.46° ± 0.01° was the standard deviation of the fitted Gaussian phase-noise distribution.The fitted Gaussian is shown as the red solid line in Figure 4.
  • Phase Noise: Phase noise was measured while Alice’s homodyne detector randomly switched between the X and P quadratures.The local-oscillator phase was scanned to calibrate detector output voltage against the phase angle between the local oscillator and signal field.
  • Phase Noise: The phase-noise measurements were recorded with an oscilloscope during random quadrature switching.The passage also specifies a segment containing 1000 data points from a total of 10000.

Quantum Random Number Generator

The protocol used a quantum random number generator based on vacuum-state measurements with a balanced homodyne detector to support random protocol choices.

  • Quantum Random Number Generator: A balanced homodyne detector with its signal port blocked generated quantum randomness from vacuum-state measurements.The random numbers selected X or P quadratures and determined the random hash function used during privacy amplification.

Security Proof Considering Measurement Flaws

The security proof extends continuous-variable QKD to account for phase errors in Alice’s X and P measurements, while bounding the resulting measurement overlap and secure key length.

  • Security-proof extension: The proof generalizes Ref. 14 to phase errors in Alice’s X and P measurements and establishes when a secure key can be extracted.The protocol uses n = N − k key-generation samples, with γ determined by the agreed average distance threshold d0.
  • Measurement overlap: The only term depending on Alice’s measurement device is c(δ), the overlap of her discretized X and P measurements.For ideal measurements, c(δ) ≤ δ2/(2πℏ), with approximate equality for relevant δ.
  • Measurement flaws: Experimental phase deviations modify the commutation relation to [X, P] = iℏ′, where ℏ′ = ℏcos θ and θ = θX + θP.The phase errors θX and θP are modeled as Gaussian variables centered at zero with variances VX and VP.
  • Measurement flaws: The resulting overlap becomes c(δ, θ) = δ2/(2πℏ′) = c(δ)/cos θ.This expression incorporates the effect of phase misalignment into the security bound.
  • Finite-sample bound: For n independent measurements, Hoeffding’s inequality bounds the accumulated phase-error contribution with probability exponentially small in εP^2.Using independent Gaussian phase errors gives an expected θ2 of VX + VP, which is then inserted into the key-length bound.

Classical Post Processing

The implementation combines parameter estimation, hybrid reconciliation, confirmation, and privacy amplification to turn discretized continuous-variable measurements into a secure key.

  • Data preparation: Alice and Bob discretize quadrature samples into 2^d equal bins, representing each bin as a d-bit symbol in χkg.Bob first multiplies P-quadrature samples by −1 to account for anti-correlation; the key-generation alphabet has size |χkg| = 2^12.
  • Channel parameter estimation: A random subset of k sifted samples is used to estimate the average distance between Alice’s and Bob’s binned symbols.The protocol aborts if the measured distance exceeds the threshold d0; otherwise, the estimation samples are removed to form raw keys.
  • Hybrid reconciliation: Hybrid reconciliation splits each key symbol into most- and least-significant bit components, then directly copies the least-significant bits before LDPC correction.Alice chooses d1, d2, and code rate R to minimize expected leakage, while Bob corrects his raw key to Alice’s using direct reconciliation.
  • Confirmation and privacy amplification: Two-universal hashing confirms corrected blocks with failure probability bounded by ϵc, and privacy amplification produces the ϵ-secure key from confirmed blocks.The final key length ℓ is calculated from the accumulated leakage ℓLK.
Loading 1406.6174v4…