Source-linked AI summary

Practical round-robin differential-phase-shift quantum key distribution

Zhen Zhang, Xiao Yuan, Zhu Cao, Xiongfeng Ma

arXiv:1505.02481v2quant-ph

TL;DR

RRDPS addresses the conventional dependence of privacy amplification on bit-error rates by bounding leakage from the prepared quantum source. This paper tightens the security analysis with GLLP tagging and decoy states, and simulations show tolerance of misalignment errors up to 50% under the modeled conditions.

  • Problem

    Conventional QKD privacy amplification depends on bit-error rates, whereas RRDPS requires a tighter practical security analysis for coherent sources and imperfect systems.

  • Method

    The paper applies GLLP tagging to photon-number states, uses decoy states to estimate yields, and simulates background noise and misalignment.

  • Results

    Misalignment error up to 50% is tolerated, while decoy-state analysis improves RRDPS performance and remains near-optimal at L = 32.

  • Takeaways & Limitations

    RRDPS has negligible practical restriction on error rate within the reported typical experiment setting.

  • Takeaways & Limitations

    The n-photon phase-error bound is only a rough estimate, and the original analysis assumes single-photon states and detectors that are challenging experimentally.

Abstract

from arXiv · show

The security of quantum key distribution (QKD) relies on the Heisenberg uncertainty principle, with which legitimate users are able to estimate information leakage by monitoring the disturbance of the transmitted quantum signals. Normally, the disturbance is reflected as bit flip errors in the sifted key; thus, privacy amplification, which removes any leaked information from the key, generally depends on the bit error rate. Recently, a round-robin differential-phase-shift QKD protocol for which privacy amplification does not rely on the bit error rate [Nature 509, 475 (2014)] was proposed. The amount of leaked information can be bounded by the sender during the state-preparation stage and hence, is independent of the behaviour of the unreliable quantum channel. In our work, we apply the tagging technique to the protocol and present a tight bound on the key rate and employ a decoy-state method. The effects of background noise and misalignment are taken into account under practical conditions. Our simulation results show that the protocol can tolerate channel error rates close to 50% within a typical experiment setting. That is, there is a negligible restriction on the error rate in practice.

1. Introduction

RRDPS avoids the conventional error-rate bottleneck by bounding phase errors from the prepared quantum source rather than the observed bit error rate. This work tightens the bound with tagging and decoy states, then evaluates practical noise and misalignment.

  • Motivation: Conventional QKD privacy amplification depends on both bit- and phase-error rates, with BB84 reaching zero key rate at ebit ≥11%.The key rate is R = 1 − 2H(ebit) when eph = ebit.
  • RRDPS advantage: RRDPS bounds Eve’s information from the quantum source, independently of how she interferes with the channel.Bob randomly selects two optical modes and measures their phase difference.
  • RRDPS advantage: Large mode number L can reduce the phase error toward zero, allowing secure keys even when ebit is close to 50%.The protocol encodes information across a superposition of L sequential pulses.
  • Practical sources: For weak coherent sources, multi-photon states can contribute secure keys because their phase error is bounded by eph ≤ n/(L−1).Phase randomization represents the source as a Poisson mixture of photon-number states.
  • This work: The study applies GLLP tagging and decoy states to derive a tighter key-rate bound and assess RRDPS under practical conditions.The simulation compares the original SYK analysis with the new analysis with and without decoy states.

2. Review of the RRDPS protocol

RRDPS encodes a random L-bit sequence into the phases of an equal-amplitude superposition of optical modes. Ancillary-qubit control operations extend this preparation to general multi-photon states.

  • Single-photon preparation: Alice prepares an equal-amplitude superposition of L optical modes and encodes each key bit sk as a phase of 0 or π.Temporal modes form an L-pulse sequence in the paper’s example, though other degrees of freedom can also represent the modes.
  • General states: For general states, Alice couples L ancillary qubits to an L-pulse state through photon-number-controlled π phase shifts.The control operation applies the phase shift when an ancillary qubit is |1⟩.
  • General states: Measuring the ancillary qubits in the Z basis produces the final random bit sequence s that labels the encoded optical state.The resulting sequence is s = (s0, s1, . . . , sL−1).
  • Single-photon preparation: For a single photon, Eq. (2.1) distributes the photon across L modes with phase signs determined by the random sequence s.The ancillary-qubit measurements generate the L bits used in the encoded state.
  • Key extraction: Alice can obtain a sifted bit si ⊕ sj by applying a C-NOT to the selected ancillary qubits and measuring the target in the Z basis.Measuring that target in the X basis instead identifies the phase-error event associated with the |−⟩ outcome.

3. Phase error estimation

The security analysis replaces Bob’s ordinary announcement scenario with an equivalent random-offset description. This makes the phase-error rate estimable from randomly selected ancillary qubits.

  • Equivalent scenario: Bob’s equivalent analysis scenario samples a nonzero offset r, detects pulse i, computes j = i + r (mod L), and announces i and j.The two scenarios are equivalent from Eve’s viewpoint.
  • Key and phase errors: Alice obtains the sifted bit si ⊕ sj by applying a C-NOT with the i-th ancillary qubit as control and the j-th as target.The target is measured in the Z basis for key extraction.
  • Key and phase errors: The phase-error rate eph is the probability that the target-qubit X-basis measurement yields |−⟩.A |+⟩ outcome corresponds to no leaked information in this analysis.
  • Key and phase errors: Because Bob’s offset is uniformly random, the phase-error rate can be estimated from any pulse except the detected i-th pulse.The C-NOT preserves the target qubit’s X eigenvalue.
  • Photon-number bound: For an n-photon state, the phase-error bound follows from the probability that an odd number of photons occupy a pulse.At most n pulses can contain odd photon numbers.

4. GLLP analysis

The GLLP analysis separates privacy-amplification costs by photon number and combines this tagging treatment with decoy-state yield estimation. The resulting key rate is optimized over a photon-number threshold.

  • Photon-number decomposition: The phase-randomized coherent source is treated as a mixture of n-photon states, with each photon-number contribution assigned a phase-error estimate.The pulse intensity is Lµ, while each of the L small pulses has intensity µ.
  • Key-rate formulation: The final key rate is normalized from L·R key bits per L-pulse train to R key bits per pulse.The overall gain QLµ is observable, while individual yields Yn may be unknown and manipulable by Eve.
  • Tagging analysis: GLLP tagging estimates privacy-amplification terms separately, assigning worst-case losses to low-photon states and transparent transmission to high-photon states.The threshold nth separates states with n < nth from those with n > nth.
  • Threshold optimization: The threshold photon number nth is chosen so contributions with n ≥ nth can account for the total gain QLµ.Its value generally differs from the threshold optimized in the original SYK analysis.
  • Decoy-state estimation: Decoy states enable accurate estimation of the photon-number yields Yn, which cannot be directly measured in experiments.The text states this accuracy for an infinite number of decoy states.

5. Simulation model and result

The practical simulation compares security analyses and QKD protocols while incorporating device imperfections. The improved RRDPS analysis, especially with decoy states, enhances key-rate and transmission-distance performance and tolerates substantial misalignment.

  • Simulation setup: The simulation models RRDPS with misalignment, environmental noise, and dark counts, using parameters from a typical QKD system.
  • Analysis comparison: Figure 3 compares SYK, new no-decoy, and new decoy analyses for L = 32 with µ optimized for maximum transmission distance.
  • Analysis comparison: The improved analysis increases both the final key rate and maximum transmission distance, while the decoy-state method is useful for RRDPS.
  • Protocol comparison: RRDPS final key rates exceed BB84 when misalignment exceeds 7%, tolerating over 40% at 50 km and 25% at 100 km.
  • Protocol comparison: RRDPS tolerates higher error rates than MDIQKD, while potentially providing higher key rates than MDIQKD at short distances.

6. Discussion

The discussion evaluates practical constraints in RRDPS security analysis and implementation, including detector assumptions, photon-number bounds, phase randomization, background noise, and mode-number selection.

  • Practical assumptions: The original analysis assumes single-photon signals and detectors, whereas practical systems commonly use coherent sources and threshold detectors.This creates a gap between the security analysis and implementation.
  • Mode-number optimization: 140 km is reached in the simulation with large L in the no-decoy cases, while the decoy-state result is already close to optimal at L = 32.The decoy-state method is therefore more stable across choices of L and easier to implement practically.
  • Background noise: Under linearly increasing background noise, the maximum transmission distance is limited even as the phase error rate decreases with increasing L.By contrast, a fixed background rate can permit unbounded distance in the idealized model.
  • Error tolerance: The protocol tolerates misalignment error ed up to 50% in the practical simulation.The discussion attributes this tolerance to misalignment being independent of L.
  • Implementation limits: Exact continuous phase randomization is difficult experimentally, so discrete phase randomization is proposed as an approximation for future extension.The study uses a phase-randomized coherent-state input.

Appendix B. Potential improvement for phase error rate estimation

The appendix compares an improved phase-error estimation method with the original SYK bound for multi-photon states. The improved estimate is tighter and may improve key rates, while its ideal-case behavior depends mainly on the average photon number per pulse.

  • Potential improvement for phase error rate estimation: The RRDPS phase-error rate is determined during quantum-state preparation rather than by Eve’s interaction, making it independent of the bit error rate.This lets Alice and Bob derive the phase-error rate without accepting the channel’s worst-case behavior.
  • Potential improvement for phase error rate estimation: The improved method gives a tighter phase-error bound than the original SYK method for an n-photon state.The paper expects, and later simulations confirm, improved key rates from this tighter estimate.
  • Potential improvement for phase error rate estimation: When the total photon number n exceeds L, the phase error rate rapidly approaches 1/2.The ratio n/L represents the mean photon number per pulse.
  • Potential improvement for phase error rate estimation: Under the ideal independent-photon scenario, the phase error rate mainly depends on the average photon number per pulse, n/L.This scenario assumes the quantum channel preserves photon independence.

Appendix C. Maximal transmission distance

This appendix derives the maximal transmission distance by relating secure key generation to the final key rate, bit error threshold, and overall transmittance. It then converts transmittance into loss and distance under the adopted channel model.

  • Maximal transmission distance: A secure key can be generated when 1 − H(ebit) − H(eph) ≥ 0.This condition is evaluated in the asymptotic regime where L and Lµ are very large.
  • Maximal transmission distance: The bit-flip threshold c determines the minimum overall transmittance ηmin required for secure communication.The bit error rate must satisfy ebit ≤ c, and the bit-flip error rate decreases with η.
  • Maximal transmission distance: When ηmin is small, 1 − e^(-ηminLµ) can be approximated by ηminLµ to obtain an approximate minimum transmittance.This approximation simplifies the maximal-distance calculation.
  • Maximal transmission distance: Transmission loss Tl and distance D are determined from the overall transmittance η, with channel loss α = 0.2 dB/km.For this model, transmission distance increases as overall transmittance decreases.

Appendix C.1. L-independent Y0

With L-independent background noise, increasing the number of optical modes can reduce overall transmittance without preventing secure transmission. Near the maximal distance, the optimized key-rate expression becomes linear in 1/L.

  • L-independent Y0: When Y0 = y0 is independent of L, secure transmission loss can become arbitrarily large as L increases.Under this idealized condition, secure transmission distance can also become arbitrarily large.
  • L-independent Y0: The optimized value of µ is around 0.06 for the experimental parameters in Table 1.At this value, Lη depends only on µ and the overall transmittance scales linearly with 1/L.
  • L-independent Y0: Near the maximal transmission distance, the final key rate R is a linear function of 1/L, or equivalently η.The argument treats optimal Lη and Lηµ as fixed values, making the relevant rate terms constant.

Appendix C.2. L-dependent Y0

With L-dependent background noise, the total background contribution increases with the number of pulses and imposes a finite transmission limit. The resulting transmittance bound is not tight.

  • L-dependent Y0: For vacuum input, the total background contribution is Y0 = 1 − (1 − y0)^L.Here y0 is the per-pulse probability of a successful background detection, and L is the number of pulses.
  • L-dependent Y0: For any reasonable µ, the overall transmittance has an L-independent lower bound under L-dependent background noise.This prevents the transmission distance from reaching infinity, although the bound is not tight.

Appendix D. Tolerable bit error rate

Under practical conditions, the RRDPS protocol generates a secure key at a bit-flip error rate of 0.4923, demonstrating tolerance close to 0.5.

  • 0.4923 bit-flip error rate: RRDPS generates a secure key under practical conditions.The simulation uses experimental parameters from Table 1, with ηd = 90% and Y0 = 1 −(1 −y0)L.
  • The Table D1 simulation evaluates RRDPS with a bit error rate close to 0.5.
  • The analysis employs a new decoy-state method without approximation.
Loading 1505.02481v2…