Source-linked AI summary
Multi-partite entanglement speeds up quantum key distribution in networks
Michael Epping, Hermann Kampermann, Chiara Macchiavello, Dagmar Bruß
TL;DR
The paper asks how multipartite entanglement can support secure conference key distribution and compare with bipartite links, especially in constrained quantum networks. It generalizes the security analysis, derives secret-key rates, and examines network implementations. Multipartite entanglement can outperform bipartite QKD in bottlenecked networks, with the advantage depending on gate and channel noise.
Problem
The paper examines conference key distribution for N parties using genuine multipartite entanglement and compares its resources, rates, and error thresholds with bipartite entanglement.
Method
The authors generalize composable security analysis to N parties, derive an analytical secret-key-rate formula using depolarization, and model noisy gates, channels, and network-coding configurations.
Results
Multipartite QKD has a higher secret-key rate than bipartite QKD in the studied bottleneck networks, with N = 3 outperforming when gate failure rates are below 7.2%.
Takeaways & Limitations
Network coding can let multipartite entanglement exploit bottlenecked quantum networks more effectively than bipartite entanglement links.
Abstract
from arXiv · showhide
The laws of quantum mechanics allow for the distribution of a secret random key between two parties. Here we analyse the security of a protocol for establishing a common secret key between N parties (i.e. a conference key), using resource states with genuine N-partite entanglement. We compare this protocol to conference key distribution via bipartite entanglement, regarding the required resources, achievable secret key rates and threshold qubit error rates. Furthermore we discuss quantum networks with bottlenecks for which our multipartite entanglement-based protocol can benefit from network coding, while the bipartite protocol cannot. It is shown how this advantage leads to a higher secret key rate.
I. MULTIPARTITE QKD: PROTOCOL AND SECURITY ANALYSIS
The NQKD protocol distributes an N-qubit GHZ state, uses basis-dependent measurements and classical post-processing, and provides a security analysis for conference keys. Its prepare-and-measure equivalent preserves the same correlations, whereas a single-qubit scheme becomes less secure as N grows.
- Protocol: The N-party protocol shares an N-qubit GHZ state among Alice and the Bobs before measurement.Alice can prepare the GHZ state locally and send one qubit to each Bob.
- Protocol: The parties measure in the Z basis for key generation and randomly use X or Y bases for parameter estimation.They announce selected bases and outcomes to estimate Q_X and Q_Z, which determine the secret key rate.
- Security analysis: Classical post-processing applies error correction followed by privacy amplification to produce the shared conference key.The security analysis uses one-way communication and extends the composable bipartite security definition to N parties.
- Prepare-and-measure schemes: Single-qubit prepare-and-measure conference QKD has a secret key rate that decreases with N and approaches zero as N becomes infinite.An eavesdropper can jointly distinguish the N−1 transmitted states more effectively as N increases.
- Prepare-and-measure schemes: The prepare-and-measure formulation based on GHZ projections is equivalent to NQKD because it reproduces the correlations among all parties.It uses multipartite entanglement for four less-frequent sent states, while the two product states occur more often.
- Security analysis: The error-correction leakage is governed by the noisiest Alice–Bob channel, even without assuming symmetric channel quality.The same error-correction information is sent to all Bobs, so the relevant leakage is determined by the Bob requiring the most correction information.
D. The secret key rate
The paper derives an analytical multipartite secret-key-rate formula by depolarising the shared state and expressing its entropic terms through experimentally estimated error parameters.
- The extended depolarisation procedure transforms arbitrary N-qubit states into a GHZ-diagonal form using local operations.The operator set includes X⊗N, pairwise Z operations, and operators R_k acting on individual Bob subsystems.
- QZ measures the probability that at least one Bob disagrees with Alice in a Z-basis measurement, unlike the individual bipartite error rates QABi.The X-basis parameter QX instead quantifies unexpected X⊗N outcomes and is not an Alice–Bob disagreement probability.
- Setting q = 0 eliminates preprocessing noise, so the processed key variable is U = K in the secret-fraction calculation.The resulting entropic expressions relate Eve’s uncertainty and each Bob’s conditional uncertainty to the measured statistics.
- The achievable asymptotic secret-key rate follows by inserting the Eve-related entropies and measured parameters into the general multipartite rate expression.The relevant quantities are determined directly from parameter-estimation measurement statistics, without an additional infimum over Γ.
- The estimated parameters in the rate formula depend on the number of parties N.This dependence must be accounted for when comparing protocol performance across different network sizes.
II. IMPLEMENTATION AND NOISE
The paper compares multipartite-entanglement-based conference key distribution with a protocol built from bipartite entanglement.
- The NQKD protocol is compared with a bipartite-entanglement protocol called 2QKD.
A. Conference key distribution with bipartite entangled quantum states (2QKD)
The implementation distributes a GHZ state, estimates QZ and QX through selected measurement rounds, and applies classical error correction and privacy amplification to obtain the NQKD key rate.
- 2QKD distributes Bell states between Alice and each Bob, creates separate bipartite keys, and combines them into a conference key.The comparison assumes the six-state protocol and allows the N − 1 channels to have different QBERs.
- The number of rounds needed to estimate ⟨X⊗N⟩dep does not increase with N, unlike full tomography.
- NQKD begins by distributing a GHZ state, using pre-shared randomness to mark less frequent parameter-estimation rounds.The marked rounds use X- or Y-basis measurements, while other rounds use Z-basis measurements.
- Parameter estimation reveals QZ from sampled Z rounds and QX from the announced outcomes and bases of the second-type rounds.Alice adjusts or flips outcomes according to the number of Y-basis measurements to implement the required measurement rule.
- The NQKD post-processing sends error-correction information based on max_i QABi and applies a randomly chosen two-universal hash function.
C. Example of depolarising noise
For a GHZ state mixed with white noise, the paper expresses the key rate as a function of QZ and N, then examines thresholds as the party count changes.
- The noise model assumes the shared state is a mixture of a GHZ state and white noise.
- For this model, the key rate depends only on QZ and N.
- For N = 2, the multipartite key rate coincides with the six-state protocol’s rate.
- The paper numerically determines the QBER threshold below which a non-zero secret key is achievable for different party counts N.For fixed Q, the key rate increases with N, while creating larger GHZ states may increase the experimental QBER.
D. Noisy gates and channels
The analysis models depolarising noise in two-qubit gates and transmission channels, showing how errors affect QBER and secret-key performance as the number of parties increases.
- Depolarising gate noise occurs with probability fG when a two-qubit gate fails, replacing the processed qubits with the completely mixed state.
- Increasing the number of parties raises the demands on gates used to produce an N-party GHZ state.
- The threshold QBER increases with N, and therefore the threshold gate-failure probability also increases for the single multi-qubit-gate construction.
- Individual depolarising transmission channels affect each Bob and contribute to the QBER used to calculate the secret-key rate.
III. QUANTUM KEY DISTRIBUTION IN NETWORKS
Multipartite entanglement can exploit network coding to distribute a conference-key resource through bottlenecks more efficiently than bipartite links. This produces higher key rates when noise remains below network- and party-dependent thresholds.
- Multipartite entanglement yields a higher secret key rate than bipartite entanglement in constrained-capacity networks with quantum routers when gate quality exceeds a threshold.
- A GHZ-like resource can cross the bottleneck network in one use, whereas the bipartite protocol requires N−1 uses.
- For less noise than the Fig. 4 threshold, NQKD has higher key rates than 2QKD in the bottleneck network.
- With one-qubit-per-second channels, network coding gives NQKD a repetition time of 1 s, compared with (N−1) s for distributing Bell pairs.
- In the ideal case, the NQKD key rate is (N−1) times larger than the 2QKD rate, but noisy gates increase NQKD's QBER with N.
- For N = 3, gate failure rates below 7.2 % make NQKD outperform 2QKD; analogous threshold behavior occurs for noisy channels.
Appendix A: The resource state and its properties
The appendix characterizes the N-qubit states that provide perfect key-generation correlations. For N ≥ 3, such correlations are restricted to one local basis, and uniform outcomes uniquely select the GHZ state.
- The appendix derives the state form and examines correlations for measurements in other local bases.
- Perfect correlations in the key-generation basis require all parties to measure in the Z-basis.
- For N ≥ 3, perfect correlations in one local basis preclude perfect pairwise or multipartite correlations in any other local bases.
- The correlated N-qubit state has the form a0,...,0|0,...,0⟩ + a1,...,1|1,...,1⟩.
- Equal amplitudes for the all-zero and all-one components ensure uniformly random key-generation outcomes, uniquely yielding a GHZ state.
Appendix B: Security analysis of the NQKD protocol
The security analysis extends composable bipartite reasoning to N-party conference keys under coherent attacks. Its key-length treatment accounts for asymmetric channels through the worst Bob's error-correction leakage.
- The analysis assumes Alice and the Bobs share n multipartite states while Eve holds a purification of the global state.
- Classical post-processing uses Alice's preprocessed raw key and one common error-correction message, from which each Bob computes a guess.
- Channel qualities need not be symmetric: error-correction leakage is determined by the Bob with the noisiest channel.
- Unlike the bipartite case, the worst of the N−1 channels influences the key length through maximal error-correction leakage.
- The asymptotic secret fraction is expressed using conditional von Neumann entropy, conditional Shannon entropy, and states consistent with parameter estimation.
Appendix C: Details for the network coding example
The appendix describes distributing a GHZ state through a router using one transmitted qubit, local entangling operations, measurement, correction, and final distribution. This realizes the multipartite resource needed for NQKD, whereas N−1 Bell pairs cannot be created from one transmitted qubit.
- GHZ-state distribution: Alice creates a Bell state, sends one qubit C to the router, and the router entangles C with N−1 locally prepared qubits Bi.The router applies N−1 controlled-Phase gates after receiving C.
- GHZ-state distribution: Measuring C in the X basis and conditionally applying X to B1 leaves the distributed qubits in a GHZ state up to a local Hadamard basis choice.The router then sends B1 through BN−1 to the corresponding parties.
- Resource comparison: A single transmitted qubit has entanglement entropy at most 1, while N−1 Bell pairs require entropy N−1, so local operations cannot create those pairs.The bipartite resource therefore requires N−1 network uses, reducing its key rate accordingly.
- NQKD consequence: The resulting GHZ resource enables the multipartite entanglement-based NQKD protocol to be performed.
Appendix D: Gate error rates and the QBER
The appendix models imperfect two-qubit gates with depolarizing noise and evaluates their effects on QBER and secret-key rates for multipartite and bipartite protocols. Randomizing gate order equalizes relevant error terms and improves the key rate, while network coding introduces a gate-error threshold for NQKD's advantage.
- Simple network: Alice prepares the GHZ resource from |+⟩A|0⟩⊗N−1 using controlled-NOT gates from A to each other qubit.The resulting QBER is evaluated for circuits with N = 2, 3, 4, ..., 8.
- Noise model: Depolarizing gate noise replaces both processed qubits with the completely mixed state whenever a two-qubit gate fails, with probability fG.
- Gate ordering: Randomizing the order of the gates makes all QABi equal, improves the key rate relative to fixed ordering, and removes the maximum in Eq. (23).
- Threshold behavior: For fixed N, a threshold gate-error probability exists below which NQKD outperforms the bipartite approach in the network of Fig. 3.NQKD is more sensitive to gate errors but requires Alice to send only one qubit.
- Key-rate comparison: The multipartite protocol's key rate decreases with increasing N because more imperfect gates are applied, while the bipartite protocol follows 1/(N −1) scaling.Figure 7 compares both protocols at fG = 0 %, 1 % and 5 %.
Appendix E: Key distribution in the butterfly network
The butterfly-network example uses quantum network coding to create two GHZ states in one time step. This permits two NQKD rounds, whereas the bipartite protocol permits only one, yielding twice the key rate for NQKD.
- Network setup: The butterfly network has unit rate constraints, with each channel transmitting one qubit per time step.
- Network coding: The corresponding quantum network code produces two GHZ states shared by A, B1, and B2.
- NQKD throughput: Two GHZ states permit two rounds of NQKD in a single time step.
- Protocol comparison: The bipartite protocol can perform only one round because the network can distribute only two Bell pairs due to Alice's outgoing capacity.
- Protocol comparison: The NQKD key rate is twice as high as in the standard bipartite approach in this butterfly-network construction.More generally, if Alice multicasts n bits, the quantum network produces n GHZ states per network use, while 2QKD performs n/(N−1) rounds per time step.