Source-linked AI summary
Composable security proof for continuous-variable quantum key distribution with coherent states
Anthony Leverrier
TL;DR
The proof addresses composable secrecy analysis for continuous-variable QKD after parameter estimation and postselection disrupt the i.i.d. structure needed for direct entropy arguments. It combines covariance estimation, a weak AEP for conditional states, and Gaussian-state Holevo evaluation to establish security against collective attacks, with an open question about active symmetrization for reverse reconciliation.
Problem
Postselection in continuous-variable QKD destroys the initial i.i.d. structure, so the asymptotic equipartition property does not directly apply to the required smooth min-entropy.
Method
The proof estimates the remaining modes’ covariance matrix, relates smooth min-entropy to von Neumann entropy for the postselected state, and evaluates Eve’s information using a Gaussian state parametrized by Σmax.
Results
The protocol E0 is ε-secure against collective attacks under a security parameter combining smoothing, parameter-estimation, correctness, and entropy terms; the bad event is bounded by εPE.
Takeaways & Limitations
The parameter-estimation test bounds the probability that Eve’s information exceeds the Gaussian-state value characterized by Σmax.
Takeaways & Limitations
For reverse reconciliation, the proof leaves open whether active symmetrization is necessary, attributing this question to the current Postselection technique.
Abstract
from arXiv · showhide
We give the first composable security proof for continuous-variable quantum key distribution with coherent states against collective attacks. Crucially, in the limit of large blocks the secret key rate converges to the usual value computed from the Holevo bound. Combining our proof with either the de Finetti theorem or the Postselection technique then shows the security of the protocol against general attacks, thereby confirming the long-standing conjecture that Gaussian attacks are optimal asymptotically in the composable security framework. We expect that our parameter estimation procedure, which does not rely on any assumption, will find applications elsewhere, for instance for the reliable quantification of continuous-variable entanglement in finite-size settings.
Appendix B: Description of the CV QKD protocol
Protocol E0 is an entanglement-based, reverse-reconciliation CV QKD protocol using heterodyne measurements, discretization, error correction, parameter estimation, and privacy amplification. Its theorem gives composable security against collective attacks under an explicit finite-size security condition.
- Protocol scope: E0 focuses on reverse reconciliation in the entanglement-based protocol, while direct reconciliation follows by exchanging Alice’s and Bob’s classical post-processing roles.The protocol’s prepare-and-measure version uses coherent states and heterodyne detection.
- Protocol steps: Bob sends error-correction information, including a syndrome and verification hash, so Alice can reconstruct U except with failure probability ǫcor.The transmitted syndrome contributes leakEC bits of leakage, and mismatched hashes cause abortion.
- Protocol steps: Parameter estimation uses nPE communicated bits and bounds covariance parameters so the protocol continues only when the estimated quantities satisfy the prescribed thresholds.The test has failure probability ǫPE and uses bounds optimized for expected channel characteristics.
- Protocol steps: Alice and Bob prepare a 2n-mode shared state and measure all modes with heterodyne detection, producing real vectors X and Y.Bob discretizes Y into an m-bit string U with m = 4dn.
- Security statement: Theorem 3 establishes that E0 is ǫ-secure against collective attacks when ǫ combines smoothing, parameter-estimation, correctness, and entropic terms with the protocol’s finite-size key condition.The key condition includes the Holevo-information function f evaluated for a Gaussian covariance matrix parametrized by Σmax.
3. Error correction
Error correction converts Bob’s discretized measurement string into a string Alice can reconstruct using syndrome communication and hash verification. Its efficiency is measured relative to the mutual information of the expected Gaussian channel.
- Reconciliation procedure: Bob sends the syndrome of discretized string U using a pre-agreed linear error-correcting code, allowing Alice to decode an estimate Ũ from X and ∥Y∥.Slice reconciliation encodes 4dn-bit strings and accounts for most of the communication leakage.
- Efficiency: Reconciliation efficiency β compares extracted information with the available mutual information for a Gaussian channel, with β = 1 representing perfect correction.The protocol models this contribution using the Gaussian-channel mutual information 1/2 log2(1 + SNR) per channel use.
- Efficiency: β ≈0.95 is typically achievable for a Gaussian channel according to the paper’s cited practical benchmark.The appendix uses β = 0.95 consistently with the best schemes available in the literature.
- Correctness verification: A universal2 hash check makes the protocol abort when Alice’s and Bob’s reconstructed strings disagree, achieving correctness except with probability ǫcor.The hash length is chosen as ⌈log(1/ǫcor)⌉.
a. Estimation of the covariance matrix of a CV system
The covariance-estimation procedure symmetrizes the CV state, measures half the modes, and constructs a confidence region without assuming an i.i.d. input. It addresses unbounded covariance coefficients through symmetrization and limited classical communication.
- Tomography framework: The tomography map symmetrizes an input state, measures a subsystem, and outputs a remaining state together with a confidence region for its density operator.The output state need not retain an i.i.d. structure.
- Covariance target: CV parameter estimation targets three averaged covariance parameters, Σa, Σb, and Σc, because Gaussian extremality bounds the Holevo information using covariance data.The relevant symmetrized covariance matrix is characterized by these parameters.
- Symmetrization: Unbounded covariance coefficients make naive finite-sample estimation unreliable, so the procedure first symmetrizes the state before measuring a subset of modes.The paper illustrates the failure using a rare high-energy component that can be missed by sampling.
- Measurement and communication: With k = n, Alice and Bob heterodyne-measure n modes each and use ∥X2∥2, ∥Y2∥2, and ⟨X2,Y2⟩ to estimate the covariance parameters.Passive linear symplectic transformations implement the random-unitary symmetrization.
- Measurement and communication: Bob discretizes Y2 and communicates a small amount of information so Alice can estimate the inner product ⟨X2,Y2⟩ despite holding separate measurement data.The protocol approximates Y2 by conditional quantile means and treats discretization errors as arbitrarily small for the main analysis.
- Acceptance test: The parameter-estimation test continues only when the estimated covariance quantities satisfy upper bounds involving Σmax.The thresholds δa, δb, and δc are optimized to balance robustness against secret-key rate.
Appendix C: Expected secret key rate
The expected secret-key-rate calculation models the channel as Gaussian, combines error-correction and Holevo terms with finite-size corrections, and optimizes the modulation variance. Robustness is incorporated through the probability that parameter estimation passes.
- Channel model: The expected-rate calculation models the quantum channel by fixed transmittance T and excess noise ξ, even though the security proof itself allows arbitrary channels.The Gaussian model is used to evaluate robustness and expected performance.
- Numerical settings: The numerical example targets ǫ = 10^-20 using a slightly suboptimal allocation of the component failure parameters.The chosen values include ǫsm = ¯ǫ = 10^-21 and ǫPE = ǫcor = ǫent = 10^-41.
- Numerical settings: The error-correction model uses reconciliation efficiency β = 0.95 and Gaussian-channel mutual information expressed through the signal-to-noise ratio.The corresponding mutual-information term is 1/2 log2(1 + SNR).
- Robustness: Robustness is chosen near 1%, corresponding to a parameter-estimation pass probability of at least 0.99 under the modeled Gaussian channel.The covariance thresholds are selected using deviations from expected values of the estimated quantities.
- Rate expression: The key-rate expression includes a robustness factor, finite-size security corrections, error-correction leakage, and the Holevo-information function evaluated at covariance bounds.The security parameter combines smoothing, parameter-estimation, correctness, and entropic contributions.
- Optimization: The final computation optimizes the secret key rate over the modulation variance V.This optimization is performed after the expected channel and finite-size parameters are specified.
2. Smooth min-entropy of a conditional state
The section addresses smooth min-entropy after postselection, where the initial i.i.d. structure is lost and the Asymptotic Equipartition Property does not directly apply. It establishes a weaker AEP-style relation to von Neumann entropy for the postselected state.
- Postselection in CV QKD destroys the initial i.i.d. structure, preventing direct application of the AEP to the smooth min-entropy.The section develops a weak AEP for the postselected state instead.
- Theorem 4 formulates an AEP for a conditional state obtained by projecting an i.i.d. classical-quantum state.
- The proof relates conditional smooth min-entropy to von Neumann entropy using purification duality, the AEP, and continuity bounds.It uses conditional-entropy identities and the Alicky-Fannes inequality to control the postselected state.
- Combining the derived bound with Eq. D10 completes the proof.
- The resulting bound applies when the passing probability satisfies p ≥ ǫ.
3. Lower bound on the entropy of an i.i.d. variable
This section develops an observable lower bound on the entropy of an i.i.d. discrete variable from empirical observations. The bound combines the negative bias of the maximum-likelihood entropy estimator with a concentration result.
- The maximum-likelihood estimator, also called empirical entropy, provides a lower bound on the true entropy but is negatively biased.
- The Antos–Kontoyiannis concentration theorem controls deviations of empirical entropy around its conditional mean.
- The estimator is directly measurable, enabling an experimentally accessible entropy lower bound from n i.i.d. realizations.
- The resulting finite-sample bound includes a logarithmic dependence on the smoothing or failure parameter.
- The construction is applied to the raw-key variable U, represented as a string of size 4n.
4. Gaussian states and covariance matrices
The section reduces the relevant Holevo-information bound to covariance-matrix parameters and exploits Gaussian-state extremality. Symmetrization makes the security analysis depend on three variables, with key quantities independent of the phase parameter.
- The smooth min-entropy problem is reduced to computing the Holevo information χ(Y;E), which is upper bounded by the corresponding Gaussian state with the same covariance matrix.
- After symmetrization, a general two-mode covariance matrix depends on three variables without loss of security.
- The determinant D and quantity ∆ = x^2 + y^2 − 2z^2 are independent of θ, so the symplectic eigenvalues are also independent of θ.
- The conditional covariance matrix after Bob’s heterodyne detection is likewise independent of θ.
- For fixed x and y at θ = 0, the Gaussian Holevo-information function is numerically decreasing as the correlation parameter z increases.
- Bounding the Holevo information therefore requires bounds on the covariance blocks Σa, Σb, and Σc.
1. Principle
The parameter-estimation principle first constructs confidence regions for measured norms and inner products, then converts them into covariance-matrix bounds. A symmetrized GedankenExperiment motivates a simulation using Alice’s and Bob’s available data.
- 1. Principle: Parameter estimation begins by computing a confidence region for ∥X∥2, ∥Y∥2, and ⟨X,Y⟩.
- 1. Principle: These confidence regions are then used to obtain bounds on the shared state’s covariance matrix.
- 1. Principle: The GedankenExperiment symmetrizes the state with random beamsplitters and phase shifters before splitting modes between two pairs of auxiliary players.
- 1. Principle: The protocol organizes the procedure around state preparation and Haar-random state symmetrization implemented optically.
- 1. Principle: Alice and Bob can simulate the auxiliary players’ actions because the same measurement is used for key extraction and parameter estimation.
- 1. Principle: The simulation requires confidence regions for the first subset’s norms and inner product, namely ∥X1∥2, ∥Y1∥2, and ⟨X1,Y1⟩.
2. Proofs related to the analysis of Parameter Estimation
The parameter-estimation analysis uses symmetrization and random-subspace concentration to infer covariance information for unmeasured modes. A sequence of lemmas controls projected norms, correlations, and expectation bounds.
- Concentration bounds: The proof develops concentration bounds for projected norms and inner products, then combines them with union bounds to control simultaneous estimation events.These bounds support estimation of variances and correlations for the remaining modes.
- Random projections: Symmetrization lets Alice model the first-half measurement as projection onto a random n-dimensional complex subspace.This connects the physical protocol to concentration bounds for random projections.
- Random projections: The projected norm analysis reduces to rotational invariance and chi-squared random variables generated from normalized independent Gaussian coordinates.The projection statistic is represented using independent χ2 variables.
- Covariance estimation: Alice and Bob estimate covariance parameters from local squared norms and cross-inner products while limiting the classical information exchanged.The simulated protocols infer confidence regions for the complementary modes from these quantities.
- Covariance estimation: Additional lemmas bound expectations over selected events, completing the ingredients needed for the main parameter-estimation result.The section assembles these expectation and concentration estimates before entering the bad-event analysis.
3. Probability of the bad event
The bad-event analysis collects failures of variance and correlation estimation across virtual tests. Parameter choices distribute the failure budget across individual events and yield an overall bound.
- Bad-event construction: The bad event includes anomalously large observed norms, incompatible conditional expectations, and underestimated correlations in the virtual parameter-estimation tests.These events cover failures for Alice’s and Bob’s variances and their correlations.
- Probability bound: The analysis assigns probability ǫ/18 to each of 18 individual events and combines them to bound the total parameter-estimation failure probability.The resulting bound is denoted pPE^bad.
- Consequence: The resulting parameter choice bounds the bad event by ǫ while supporting the confidence-region conclusion for the covariance parameters.The corollary connects passing the parameter-estimation test to the Gaussian covariance-matrix bound.
4. Analysis of the Parameter Estimation
The parameter-estimation proof compares the actual protocol with virtual tests on symmetrized halves of the state. Passing the actual test makes Eve’s information bounded by the Gaussian state associated with the estimated covariance matrix, except with controlled probability.
- Virtual tests: After symmetrization, virtual players measure opposite halves to infer confidence regions for the covariance matrices of the remaining modes.The two virtual tests estimate complementary halves of the state.
- Virtual tests: The bad event is that the actual test passes while a virtual test aborts or passes with an invalid covariance confidence region.This defines the failure mode transferred from the virtual analysis to the true protocol.
- Information bound: Strong subadditivity bounds the joint Holevo information by the sum of the Holevo informations for the two halves.This decomposes the information analysis across the symmetrized state’s mode partitions.
- Information bound: Except with probability ǫPE/p, passing parameter estimation implies that Eve’s information about Bob’s heterodyne string is bounded by the Gaussian covariance-matrix evaluation.The bound is conditioned on the state passing the parameter-estimation test.
Appendix F: Security of the protocol E0 against collective attacks
The collective-attack security proof lower-bounds the smooth min-entropy of the raw key conditioned on Eve and the public transcript. Error correction, entropy bounds, and the Leftover Hash Lemma then establish secrecy.
- Security reduction: The proof targets a lower bound on the smooth min-entropy of the raw key conditioned on Eve’s quantum system and the public transcript when the protocol does not abort.The smoothing parameter is optimized within the proof.
- Security reduction: Parameter estimation and error correction combine into an error parameter ǫerr = ǫPE + ǫcor for the subsequent entropy analysis.The analysis assumes a sufficiently large probability that both tests pass.
- Entropy bound: The Holevo information is maximized by the Gaussian state with the same covariance matrix, so the Gaussian evaluation supplies the relevant information bound.This is the extremality step used to connect covariance estimation to Eve’s information.
- Entropy bound: The smooth min-entropy bound combines the Asymptotic Equipartition Property, the Holevo-information definition, empirical-entropy bounds, and data processing.These ingredients produce the final entropy lower bound except with a controlled failure probability.
- Privacy amplification: The Leftover Hash Lemma converts the final smooth min-entropy bound into the secrecy conclusion of Theorem 3.Privacy amplification completes the collective-attack security proof.
Appendix G: A security proof against general attacks without active symmetrization
The Postselection technique is sketched as a route to security against general attacks without active symmetrization for direct reconciliation. Reverse reconciliation remains an open case, while related symmetrization issues also arise for practical BB84 with large losses.
- Direct reconciliation: For direct reconciliation, the Postselection technique yields a security proof against general attacks without applying active symmetrization.The construction simulates symmetrization during parameter estimation after preparing two-mode squeezed vacuum states.
- Reverse reconciliation: Whether active symmetrization is necessary for reverse reconciliation remains an open question.The authors conjecture that a better Postselection technique exploiting phase-space symmetries could remove this requirement.
- Related protocols: Postselecting only detector-click events in BB84 can break joint-permutation symmetry and similarly require active symmetrization.The passage identifies detector-click postselection as a form of reverse reconciliation in this setting.
- Related protocols: Thus, symmetrization concerns extend beyond CV QKD to practical BB84 protocols operating with large losses.