Source-linked AI summary

Provably Secure and Practical Quantum Key Distribution over 307 km of Optical Fibre

Boris Korzh, Charles Ci Wen Lim, Raphael Houlmann, Nicolas Gisin, Ming Jun Li, Daniel Nolan, Bruno Sanguinetti, Rob Thew, Hugo Zbinden

arXiv:1407.7427v1quant-ph

TL;DR

Practical fibre QKD has been limited by detector noise and stringent finite-key post-processing requirements. This work combines low-noise InGaAs/InP NFAD detectors, ultra-low-loss fibre, and a sharper finite-key analysis to distribute secure keys over 307 km. The results demonstrate practical long-distance QKD with standard telecom components.

  • Problem

    Practical fibre-based QKD has been limited to about 150 km by semiconductor-detector background noise and stringent minimum classical post-processing block sizes.

  • Method

    The system combines COW QKD with low-noise InGaAs/InP NFAD detectors, ultra-low-loss fibre, universal composable security, and a new finite-key tail inequality.

  • Results

    The system distributed secure keys over 307 km, achieving 3.18 bps at that distance and 84.5% of the asymptotic limit at 300 km with n_cpp = 10^7.

  • Takeaways & Limitations

    Practical, robust, autonomous long-distance QKD is feasible using standard telecom components in a rack-mounted architecture.

Abstract

from arXiv · show

Proposed in 1984, quantum key distribution (QKD) allows two users to exchange provably secure keys via a potentially insecure quantum channel. Since then, QKD has attracted much attention and significant progress has been made in both theory and practice. On the application front, however, the operating distance of practical fibre-based QKD systems is limited to about 150 km, which is mainly due to the high background noise produced by commonly used semiconductor single-photon detectors (SPDs) and the stringent demand on the minimum classical- post-processing (CPP) block size. Here, we present a compact and autonomous QKD system that is capable of distributing provably-secure cryptographic key over 307 km of ultra-low-loss optical fibre (51.9 dB loss). The system is based on a recently developed standard semiconductor (inGaAs) SPDs with record low background noise and a novel efficient finite-key security analysis for QKD. This demonstrates the feasibility of practical long-distance QKD based on standard fibre optic telecom components.

I. INTRODUCTION

Long-distance fibre QKD has been constrained by detector noise, finite-key requirements, and security assumptions. Prior record-distance demonstrations did not fully account for finite-key corrections.

  • Long-distance QKD systems commonly use SNSPDs for low dark-count rates, but these require cryogenic temperatures below 3 K.
  • Previous demonstrations often assumed individual attacks rather than coherent attacks, providing a weaker security framework.
  • Finite-key corrections are non-negligible for realistic classical post-processing block sizes.

II. RESULTS

The system combines COW QKD, low-noise InGaAs/InP NFAD detectors, ultra-low-loss fibre, and a sharper finite-key bound. It distributes secret keys over 307 km while maintaining measurable performance and stability.

  • COW encodes bits in weak coherent pulses’ arrival times and monitors channel disturbance through interference visibility.
  • The security analysis uses universal composability and collective-attack assumptions to bound the extractable secret-key length.
  • The new tail inequality uses the measured error rate of a random sample to obtain a sharper finite-key bound.
  • At 300 km, the secret-key rate reaches 84.5% of the asymptotic limit with n_cpp = 10^7.
  • The NFAD dark-count rate drops by approximately a factor of two per 10 K below 200 K, reaching a few counts per second below 150 K at efficiencies above 20%.
  • The system generated 12.7 kbps at 104 km and 3.18 bps at 307 km, with approximately 6.6 × 10^5 post-processing bits used at the longest distance.
  • At 200 km, continuous operation maintained an average QBER of 1.55%, visibility of 97.7%, and secret-key rate around 900 bps.

III. CONCLUSION

The work demonstrates secure, robust, autonomous QKD over 307 km using compact InGaAs detectors and standard telecom components. Its finite-key analysis also enables quantified security for small post-processing blocks.

  • The system achieves secure key distribution over 307 km using practical and compact InGaAs single-photon detectors.
  • The sharpened finite-key analysis improves protocol performance when classical post-processing blocks are small.
  • The complete protocol has a quantified security parameter of ϵ_qkd = 4 × 10^-9.
  • The results demonstrate feasibility of practical, robust, autonomous QKD using standard telecom components in a rack-mounted architecture.

IV. ADDITIONAL INFORMATION

The additional information details the finite-key security proof, implementation choices, and fibre technology underlying the QKD system. It also reports the system’s total security parameter and practical integration considerations.

  • Implementation: CASCADE was used for information reconciliation because it processes small blocks efficiently and high throughput was unnecessary.Its processing blocks were typically 2–3 orders of magnitude smaller than ncpp, enabling frequent QBER measurements for active stabilisation.
  • Security parameters: 4 × 10^-9: the system’s upper bound on the total security parameter for all tested fibre lengths.The selected security level uses β = 10^-9, with error-verification and service-channel-authentication failure probabilities of approximately 10^-11 and 10^-15.
  • Security analysis: The security proof sketches a bound on extractable secret-key length, with the complete analysis deferred to the supplementary information.The technical core is bounding Hϵ_min(X|E), where X is the raw key and E is the adversary’s knowledge.
  • Security analysis: The secret-key bound is derived from smooth min-entropy using the quantum leftover hash lemma, chain rules, and collective-attack assumptions.The analysis connects entropy bounds to the COW protocol’s error rate and visibility, then incorporates finite-size corrections.
  • Fibre technology: The ultra-low-loss fibre used has average attenuation of 0.160 dB/km without splices and connectors.The passage states that attenuation below 0.1 dB/km could enable QKD distances beyond 500 km.

Supplementary Information: Provably secure and practical quantum key

The supplementary information identifies the paper’s title, authors, and institutional affiliations.

  • The supplementary information concerns provably secure and practical quantum key distribution over 307 km of optical fibre.
  • The paper is authored by Boris Korzh, Charles Ci Wen Lim, Raphael Houlmann, Nicolas Gisin, Ming Jun Li, Daniel Nolan, Bruno Sanguinetti, Rob Thew, and Hugo Zbinden.
  • The authors are affiliated with the University of Geneva’s Group of Applied Physics and Corning Incorporated.

I. EXPERIMENTAL PARAMETERS

This section introduces a table of optimised experimental parameters recorded at different fibre distances.

  • The section lists key experimental parameters for each distance.
  • The parameters are presented as experimentally optimised values associated with the tested distances.
  • Table I provides an overview of experimental parameters at different distances.

II. DETAILS OF SECURITY ANALYSIS

The security-analysis details define the security criteria, attack model, and derivation of the extractable secret-key bound from experimental statistics.

  • The section first introduces the security criteria used in the analysis.
  • It then specifies the security model, including assumptions and the class of attacks considered.
  • Finally, it derives a bound on extractable secret-key length in terms of experimental statistics.

A. Security Criteria and Universal Composable Security

The protocol permits controlled correctness and secrecy errors, defining security through key agreement and closeness to an ideal uniformly random key. Its universally composable formulation preserves security when QKD keys are used in subsequent cryptographic tasks.

  • Security Criteria: The ideal secrecy criterion models the key as uniformly distributed and independent of Eve’s quantum information.
  • Security Criteria: A protocol is εcor-correct when Alice and Bob’s output keys are identical with probability at least 1−εcor.
  • Security Criteria: A protocol is εsec-secret when its real key–Eve state is sufficiently close to the ideal uniform-key state under the trace norm.The definition also scales the secrecy distance by the non-abort probability.
  • Universal Composable Security: Universal composability allows secure QKD keys to be safely used in other composable cryptographic tasks.If QKD and encryption have security parameters ε1 and ε2, their composition is (ε1 + ε2)-secure.

B. Coherent One-Way and Security Model

COW QKD encodes bits in the time pattern of successive coherent pulses and monitors phase coherence with an additional test state. Its security analysis remains challenging in general and is treated here under a collective-attack model.

  • Coherent One-Way Protocol: COW encodes bit 0 as |0⟩|α⟩ and bit 1 as |α⟩|0⟩, with Bob decoding the arrival time.
  • Coherent One-Way Protocol: Alice sends |α⟩|α⟩ test states to monitor phase coherence between successive laser pulses and detect attacks on the signal states.
  • Security Model: A general security analysis of COW remains elusive because phase-coherence measurements are difficult to interpret as measurements on individual states.
  • Security Model: The analysis derives bounds under collective attacks, where Eve interacts identically and independently with each individual state.The cited model also restricts Eve to forwarding either an empty state or a single photon to Bob.
  • Security Model: The collective-attack model reflects finite extinction ratios in practical intensity modulators, which produce imperfectly suppressed intensities and erroneous detected events.

C. Bounds on extractable secret key length

The finite-key analysis combines privacy amplification, smooth min-entropy bounds, and direct random-sampling estimates to obtain a secrecy guarantee for the extracted key. A new hypergeometric tail bound tightens visibility estimation from finite samples.

  • Privacy Amplification: The Quantum Leftover Hash Lemma provides the privacy-amplification basis for extracting a secret key from the distillation string X.
  • Secret-Key Bound: The proposed key length is controlled by smooth min-entropy, which quantifies uncertainty about X given Eve’s quantum side information E+.
  • Secret-Key Bound: The analysis lower-bounds the remaining uncertainty after accounting for public information revealed during error correction and verification.
  • Finite-Key Parameter Estimation: A new tail inequality uses hypergeometric sampling without replacement to tightly bound deviations between observed and key-bit error or visibility rates.The bound is derived using a sharp inequality for binomial coefficients.
  • Finite-Key Parameter Estimation: The estimated key visibility is ˆV = Vobs − t(ncpp, nvis, Vobs, ϵ′), with failure probability controlled by ϵ′.This estimate uses the observed visibility and the number of monitoring bits to account for finite sampling.
  • Security Guarantee: The resulting secrecy bound is ∆≤2ϵ + β + ϵ′, and choosing ϵ = ϵ′ = β = ϵqkd/4 yields ∆≤εqkd.

III. ULTRA-LOW-LOSS OPTICAL FIBRE

Ultra-low-loss fibre requires reducing both intrinsic and extrinsic attenuation mechanisms. The paper describes material purification, drying, waveguide control, and silica-composition choices as routes to lower loss.

  • Loss Sources: Total fibre attenuation is the sum of Rayleigh scattering, absorption, waveguide-imperfection, and bending-loss contributions.The expression includes αRS, αIR, αUV, αTM, αOH, αIM, and αBL.
  • Loss Reduction: High-purity chemical-vapour deposition can reduce transition-metal contamination in the fibre preform.
  • Loss Reduction: Chlorine drying reduces hydroxyl-ion concentration, lowering one extrinsic absorption contribution.
  • Loss Reduction: Waveguide-imperfection loss arises from core–cladding geometry fluctuations and must be minimized to achieve ultra-low attenuation.
  • Rayleigh Scattering: Rayleigh scattering can be reduced by lowering fictive temperature and GeO2 concentration, motivating pure-silica cores.The passage notes that pure silica also has a high fictive temperature.
Loading 1407.7427v1…