Source-linked AI summary
Finite-key analysis on the 1-decoy state QKD protocol
Davide Rusca, Alberto Boaron, Fadri Grünenfelder, Anthony Martin, Hugo Zbinden
TL;DR
The paper addresses whether the asymptotic advantage of the 2-decoy protocol persists for finite keys. It derives a finite-key analysis for the 1-decoy method and finds that, for practical detector settings and block sizes, 1-decoy often achieves the higher secret key rate.
Problem
Finite-key analysis must determine how vacuum and single-photon contributions can be bounded when only two intensity levels are used.
Method
The paper derives finite-key bounds using observed detection and error counts, Hoeffding corrections, vacuum-event estimates, and simulated detector behavior.
Results
For attenuations between 30 dB and 70 dB, the 1-decoy protocol gives the best secret key rate for practical privacy-amplification block sizes with InGaAs detectors.
Takeaways & Limitations
The finite-key analysis supports using one decoy in most practical configurations, while two decoys remain useful in detector-saturation regimes and at very long distances.
Abstract
from arXiv · showhide
It has been shown that in the asymptotic case of infinite-key length the 2-decoy state QKD protocol outperforms the 1-decoy state protocol. Here, we present a finite-key analysis of the 1-decoy method. Interestingly, we find that for practical block sizes of up to $10^8$ bits, the 1-decoy protocol achieves for almost all experimental settings higher secret key rates than the 2-decoy protocol. Since using only one decoy is also easier to implement, we conclude that it is the best choice for practical QKD.
Appendix A: Calculation of the SKR
Appendix A derives the finite-key secret-key-rate calculation for the 1-decoy protocol from observed detection and error counts. Hoeffding bounds connect finite observed data to asymptotic quantities with explicit failure probabilities.
- The appendix calculates all terms of the main-text secret key-rate expression from experimental data.
- The 1-decoy protocol uses two intensity levels, µ1 and µ2, with µ1 > µ2, and analyzes detections separately by photon number and basis.
- Finite-key analysis bounds the difference between observed detections nZ,k and corresponding asymptotic values n∗Z,k using Hoeffding’s inequality.
- The same finite-statistics treatment applies to error estimation, with mZ defined as the total number of errors in the Z basis.
Bounds on the vacuum and single-photon events
The appendix derives finite-key bounds for vacuum and single-photon events using two decoy intensities. Because vacuum contributions are not directly measurable, the single-photon lower bound requires an upper bound inferred from observed errors.
- Bayes’ rule and the coherent-state photon distribution define conditional probabilities linking intensity choices to photon-number events.
- Two intensity levels yield an inequality that isolates a lower bound on the single-photon detection events sZ,1 after accounting for multiphoton contributions.
- The single-photon lower bound requires an upper bound on the vacuum contribution, which cannot be tightly obtained using only two intensity levels.
- Vacuum events are related to errors because their expected error probability is one half of the corresponding total events.
- Since vacuum detections and errors are not directly available, the analysis upper-bounds them using experimentally observed total detections and errors, yielding a pessimistic estimate.
- The authors compare two ways to upper-bound vacuum events and choose the second approach because it gives the best secret key rate after finite-key corrections.
Phase error rate
The phase-error analysis supplies the remaining bounds needed to estimate the secret key length. It uses an analytic bound on single-photon bit errors in the X basis to bound the Z-basis phase-error rate.
- The phase error in the Z basis is estimated using a specified analytical formula.
- The number of single-photon bit errors in the X basis is upper-bounded analytically using the result from the 2-decoy analysis.
- The resulting bound on the X-basis single-photon errors is used to upper-bound the phase-error rate in the Z basis.
- Together with the preceding bounds, these terms provide all quantities needed to estimate the secret key length.
Secret Key Length parameters a and b
This section relates the 1-decoy security parameters to the existing 2-decoy analysis and gives the resulting security-parameter expression. The optimization figures concern protocol variables as attenuation increases.
- The 2-decoy security analysis assigns the specific values a = 6 and b = 21.
- The 1-decoy analysis follows the same security-proof approach but uses a different definition of εsec.
- The security parameter is expressed as εsec = 2[α1 + 2α2 + α3] + ν + 6ε1 + 4ε2.
- The coefficients of ε1 and ε2 reflect how often the corresponding concentration inequalities enter the secret-key-length formula.
- Setting all error terms to a common value ε gives εsec = 19ε for the 1-decoy security proof.
Appendix B: Detection and Error Simulation
The simulation models detections and errors in the Z basis, then derives pulse requirements and secret-key rate from the resulting finite-key quantities.
- The Z-basis detection count for each intensity is calculated as a fraction of the fixed total detection count nZ.The fraction uses the intensity-specific detection probability relative to the total over all intensities.
- The intensity-specific detection probability incorporates basis-choice probability, decoy-selection probability, and detector-dead-time correction.The correction factor is modeled using the source repetition rate, total detection probability, and detector dead time.
- The simulation computes error probability from setup misalignment and detector dark counts, then obtains Z-basis QBER as error probability divided by detection probability.
- The total number of transmitted pulses needed for a target nZ is calculated, and SKR is obtained from secret-key length per pulse multiplied by source repetition rate.
- Figure 5 compares 1-decoy and 2-decoy secret-key rates across privacy-amplification block sizes and plots their difference.
Appendix C: Simulation Variables
The appendix reports the optimized simulation variables for both protocols at block size 10^7 as functions of attenuation.
- At block size 10^7, the simulation varies basis-choice probabilities, decoy probabilities, and mean photon numbers with attenuation.The listed variables include pZ, pµi, and the signal and decoy intensities µi.
- The intensities are small at low attenuation because the detectors are saturated, then increase and remain constant at their optima as attenuation rises.
Appendix D: Simulation with InGaAs Detectors
The InGaAs-detector simulation examines secret-key rates under a 1 Hz dark-count rate and 20 µs dead time, finding a practical regime where 1-decoy performs best.
- The simulation models an InGaAs detector with a dark-count rate of 1 Hz and a dead time of 20 µs.
- The higher detector dead time enlarges the attenuation interval in which secret-key rate is limited mainly by detector saturation.
- For attenuations between 30 dB and 70 dB, the 1-decoy protocol gives the best secret-key rate for practical privacy-amplification block sizes.