Source-linked AI summary
Fundamental rate-loss tradeoff for optical quantum key distribution
Masahiro Takeoka, Saikat Guha, Mark M. Wilde
TL;DR
The paper asks whether optical QKD without quantum repeaters can avoid exponential rate loss with distance. It uses squashed entanglement to upper-bound two-way assisted private capacity, showing that lossy optical channels have a power-independent, loss-only limit that is nearly tight at high loss.
Problem
Known QKD protocols have key rates that decay exponentially with distance, motivating whether undiscovered optical protocols could avoid this tradeoff without quantum repeaters.
Method
The paper defines channel squashed entanglement and proves it upper-bounds two-way assisted private capacity, then applies the bound to pure-loss optical channels.
Results
In the high-loss regime, the upper and lower bounds are approximately 2η/ln 2 and η/ln 2 key bits per mode, respectively.
Takeaways & Limitations
The upper bound depends only on channel loss, not transmit power, and known protocols show essentially no scaling gap from the ultimate secret-key-agreement capacity.
Takeaways & Limitations
The bound applies to finite channel uses but may be improved by a strong-converse theorem or second-order analysis; its achievability remains open.
Abstract
from arXiv · showhide
Since 1984, various optical quantum key distribution (QKD) protocols have been proposed and examined. In all of them, the rate of secret key generation decays exponentially with distance. A natural and fundamental question is then whether there are yet-to-be discovered optical QKD protocols (without quantum repeaters) that could circumvent this rate-distance tradeoff. This paper provides a major step towards answering this question. We show that the secret-key-agreement capacity of a lossy and noisy optical channel assisted by unlimited two-way public classical communication is limited by an upper bound that is solely a function of the channel loss, regardless of how much optical power the protocol may use. Our result has major implications for understanding the secret-key-agreement capacity of optical channels---a long-standing open problem in optical quantum information theory---and strongly suggests a real need for quantum repeaters to perform QKD at high rates over long distances.
Results
The paper defines squashed entanglement for quantum channels and proves it upper-bounds two-way assisted private capacity. Applied to lossy optical channels, this yields a single-letter, loss-dependent bound that remains valid under excess noise and finite channel uses.
- Channel bound: Squashed entanglement of a channel is defined as the maximum squashed entanglement registered between a sender and receiver across the channel.This extends the state quantity to a channel input-output setting.
- Channel bound: Theorem 1 proves that a channel’s squashed entanglement upper-bounds its private capacity with unlimited forward and backward classical communication.The proof uses secrecy monotonicity under local operations and public classical communication.
- Channel bound: The resulting upper bound is single-letter, depending on one channel use despite protocols using many channel uses, entangled inputs, and collective measurements.Subadditivity is critical to this single-letterization.
- Scope: The bound applies to finite channel uses, where the key rate is bounded in terms of channel squashed entanglement and protocol reliability and security.A stronger converse or refined second-order analysis could potentially improve the result.
- Optical channel: For the pure-loss bosonic channel, the analysis uses a pure-loss squashing channel for Eve and minimizes the resulting expression at environmental transmittance η1 = 1/2.The channel transmittance η is the average fraction of input photons reaching Bob.
- Optical channel: Taking the input photon-number limit NS →∞ produces a photon-number-independent upper bound for the pure-loss channel.The finite photon-number constrained squashed entanglement is already an upper bound on P2(Nη).
- Optical channel: Excess channel noise can only reduce squashed entanglement, so the pure-loss bound remains a fundamental upper limit for lossy noisy optical channels.This follows from quantum data processing; protocol-specific noisy processing may still improve rates without exceeding the bound.
Discussion
In the high-loss regime, the upper bound nearly matches the best known lower bound, leaving essentially no scaling gap for known optical QKD rates. The results also extend to two-way channel use and identify unresolved questions about converse strength and achievability.
- The upper and lower bounds become close when η ≪1, the high-loss regime relevant for long-distance QKD.
- 2η/ ln 2 and η/ ln 2 key bits per mode approximate the upper and lower bounds, respectively, when η ≪1.
- The lower-bound-achieving protocol is nearly optimal at small η, while ideal BB84 is worse than the reverse coherent information lower bound by only a constant factor of 2/ ln 2 ≈2.88.
- Any super-additive gain cannot be very large in the high-loss regime, and P2(Nη) must scale as ∼η when η ≪1.
- For two-way use of the lossy channel, the secret-key agreement capacity is upper bounded by 2 log2((1 + η)/(1 −η)) secret key bits per mode transmitted in both directions.
- The bound leaves essentially no scaling gap between known protocol rates and ultimate capacity, but open questions concern strong converses, second-order analysis, achievability, and tighter bounds.
Methods
The methods address finite-size effects and infinite-dimensional optical systems, while quantifying how the weak-converse bound depends on error and security. They also describe practical imperfections used for protocol-rate calculations.
- Finite-size analysis: In the large-n limit, the finite-size correction term 4h2(2√ε)/n vanishes.
- Finite-size analysis: The finite-size expression suggests a tradeoff between communication rate and error probability or security quantified by ε.A strong converse could remove this implied tradeoff and yield R ≤ Esq(N) independently of ε in the large-n limit.
- Finite-size analysis: For ε = 10^-10 and n = 10^4, a 200 km fiber with 0.2 dB km^-1 has η = 10^-4 and an upper-bound value approximately 2.885 × 10^-4.The resulting finite-size estimate is reported as rather close to this asymptotic upper-bound value.
- Optical and practical setting: Infinite-dimensional processing is handled by starting and ending with finite-dimensional states, allowing continuity arguments while intermediate processing remains infinite-dimensional.The supplied methods text also describes experimentally imperfect decoy BB84 and CV-GG02 calculations.
SUPPLEMENTARY NOTE 2: SQUASHED ENTANGLEMENT UPPER BOUND FOR THE PURE-LOSS BOSONIC CHANNEL
The supplementary derivation bounds pure-loss-channel secret-key capacity by optimizing a squashed-entanglement construction over a pure-loss squashing channel. Symmetry and convexity identify the minimizing squashing transmittance and its infinite-energy limit.
- Proof strategy: The proof establishes an upper bound on P2(Nη) for a pure-loss bosonic channel with transmittance η.
- Proof strategy: A pure-loss channel with transmittance η1 is used as Eve’s specific squashing channel, reducing the calculation to conditional entropies of a reduced Gaussian state.
- Gaussian calculation: The covariance-matrix calculation uses beamsplitter transformations and identifies the marginal E′ state as thermal with photon number (1 −η)η1NS.
- Gaussian calculation: The resulting conditional-mutual-information expression is a sum of entropy differences involving g and the channel parameters η, η1, and NS.
- Optimization: η1 = 1/2 minimizes the expression by symmetry and convexity, and the bound converges to log((1+η)/(1−η)) as NS →∞.
PROTOCOLS
The protocols section specifies asymptotic rate calculations for decoy BB84 and Gaussian-modulated coherent-state CV-GG02 under device and noise assumptions. Rates are optimized over protocol parameters and evaluated for calibrated and uncalibrated scenarios.
- Rate models: The supplementary calculations use asymptotic secret-key rates, assuming channel estimation is effectively perfect.
- Decoy BB84: For decoy BB84, the mean photon number μ is optimized to maximize the key-rate expression.The model includes detection rates, photon-number yields, error rates, QBER, and error-correction efficiency.
- Decoy BB84: The decoy BB84 model incorporates channel transmittance, Bob’s device and detector efficiencies, dark counts, and visibility-dependent errors.
- CV-GG02: For CV-GG02, the rate depends on reconciliation efficiency, Alice–Bob mutual information, and Bob–Eve Holevo information.