Source-linked AI summary

Phase-Matching Quantum Key Distribution

Xiongfeng Ma, Pei Zeng, Hongyi Zhou

arXiv:1805.05538v3quant-ph

TL;DR

Photon loss imposes a linear transmittance-dependent key-rate limit on practical QKD. This paper proposes PM-QKD, using common-phase encoding, interference at an untrusted site, and an optical-mode security proof. The scheme has R = O(√η), remains measurement-device independent, and is made practical without phase locking through phase postcompensation.

  • Problem

    Photon loss limits practical QKD because many current schemes have secure key rates bounded by R ≤ O(η).

  • Method

    PM-QKD encodes key information into the common phase of independently prepared coherent states, matches phases through interference at an untrusted site, and uses an optical-mode security proof.

  • Results

    R = O(√η), and simulations show PM-QKD can exceed the linear key-rate bound under practical settings.

  • Takeaways & Limitations

    PM-QKD combines measurement-device-independent security with a practical phase-postcompensation implementation that avoids phase locking.

Abstract

from arXiv · show

Quantum key distribution allows remote parties to generate information-theoretic secure keys. The bottleneck throttling its real-life applications lies in the limited communication distance and key generation speed, due to the fact that the information carrier can be easily lost in the channel. For all the current implementations, the key rate is bounded by the channel transmission probability, $η$. Rather surprisingly, by matching the phases of two coherent states and encoding the key information into the common phase, this linear key-rate constraint can be overcome---the secure key rate scales with the square root of the transmission probability, $O(\sqrtη)$, as proposed in twin-field quantum key distribution [Nature (London) 557, 400 (2018)]. To achieve this, we develop an optical-mode-based security proof that is different from the conventional qubit-based security proofs. Furthermore, the proposed scheme is measurement device independent, i.e., it is immune to all possible detection attacks. The simulation result shows that the key rate can even exceed the transmission probability $η$ between two communication parties. In addition, we apply phase postcompensation to devise a practical version of the scheme without phase locking, which makes the proposed scheme feasible with the current technology. This means that quantum key distribution can enjoy both sides of the world---practicality and security.

I. INTRODUCTION

Photon loss limits practical QKD because its secure key rate is bounded linearly by channel transmittance. PM-QKD addresses this limit through phase matching, an optical-mode security proof, and measurement-device-independent operation.

  • Motivation: Photon loss makes channel transmittance η an upper bound on secure key generation, with R ≤ O(η) for many implemented schemes.When encoded photons are lost, no secure key can be distributed.
  • Related approaches: Quantum repeaters require high-quality memories and complex entanglement distillation, while trusted relays require an impractical trust assumption.These approaches therefore do not straightforwardly resolve the practical security and distance constraints.
  • Related approaches: TF-QKD suggested a quadratic key-rate improvement, but its rigorous security proof was still missing and the photon-number channel model was invalid in this setting.PM-QKD follows this direction while addressing the security-analysis problem.
  • Contribution: PM-QKD encodes information in the common phase of independently prepared coherent states and matches those phases through interference at an untrusted site.The scheme is investigated as a single-detection phase-encoding MDI-QKD protocol.
  • Contribution: PM-QKD uses an optical-mode security proof, achieves R = O(√η), and remains immune to all possible detection attacks within the MDI framework.The paper also develops phase postcompensation to ease experimental requirements.

II. PM-QKD PROTOCOL

PM-QKD uses independently generated coherent pulses whose phase-encoded bits are tested through interference at an untrusted detector. After phase announcement and sifting, retained data undergo parameter estimation and key distillation.

  • State preparation and measurement: Alice and Bob independently generate coherent states and encode key bits into their phases before sending them to an untrusted measurement site.Eve records a successful detection when exactly one detector clicks.
  • Protocol variant: The protocol studied primarily uses d = 2 with phase randomization, adding independent random phases before transmission and announcing them after Eve reports detection results.Signals are subsequently postselected according to the announced phases.
  • Sifting: Alice and Bob retain raw bits after successful single-detector announcements and phase matching, applying bit flips according to Eve’s detector and the phase difference.They keep signals only when the announced phases differ by 0 or π.
  • Parameter estimation: They estimate the total gain Qµ and bit error rate EZµ from retained data, then estimate the phase error rate EXµ.These quantities support the subsequent security analysis.
  • Key distillation: After parameter estimation, Alice and Bob perform error correction and privacy amplification on the sifted key to generate a private key.The reference pulse need not be sent because it can be regarded as shared, and no basis switching is required.

III. SECURITY OF PM-QKD

PM-QKD’s security is analyzed through an equivalent entanglement-based optical-mode description rather than a single-qubit model. The argument uses global-phase indistinguishability to limit Eve’s information while retaining MDI security against detection attacks.

  • Equivalent scenario: A trusted Charlie can split a prepared state and send the outputs to Alice and Bob, who encode their bits by phase modulation before transmission.This equivalent scenario provides an intuitive security picture for the real protocol.
  • Encoded states: The protocol’s four encoded outputs correspond to combinations of Alice’s and Bob’s phase modulations, including the equal-bit cases analyzed for Eve’s information.For equal bits, the relevant states are |Ψ0,0⟩ and |Ψπ,π⟩.
  • Security intuition: For a Fock-state source, equal global phases are indistinguishable, so Eve cannot determine whether the common modulation was 0 or π.Eve can still learn that Alice’s and Bob’s bits are equal.
  • Phase randomization: Phase randomization makes the coherent source equivalent to a mixture of Fock states with P(k) = e^−µµ^k/k!, and security requires that Eve cannot learn the random phase φ.The phase-sifting condition φa = φb = φ supplies the corresponding equivalent source description.
  • Security proof: The security proof applies entanglement-distillation arguments directly to optical modes instead of modeling the implementation as a single qubit.This approach is intended to support security analysis for coherent-light QKD schemes.
  • Implementation security: The real PM-QKD implementation isolates sources and modulators in an optical circulator, preserving MDI security against Trojan-horse-like attacks.The virtual Charlie used in the equivalent proof is removed from the real implementation.

IV. PRACTICAL IMPLEMENTATION

Exact phase matching is impractical because continuous-phase postselection has vanishing probability and phase locking is difficult. Phase postcompensation replaces exact phases with slices and estimates an offset from sampled QBER, enabling practical operation without compromising security.

  • Practical challenges: Exact phase postselection has vanishing success probability, while perfectly locking Alice’s and Bob’s laser references is experimentally challenging.These constraints motivate a practical phase-sifting procedure.
  • Phase postcompensation: Phase postcompensation divides [0, 2π) into M slices and compares slice indexes instead of exact phases, introducing an intrinsic misalignment error.The phase-sifting step is performed during data postprocessing.
  • Offset estimation: Bob samples bits, tests candidate offsets jd, and selects the offset that minimizes the sampling QBER before sifting the remaining bits.For a phase difference of M/2, Bob flips his key bit.
  • Drift handling: The compensation offset can be adjusted across data blocks or in real time as phase references drift, while phase fluctuations add bit errors but do not affect security.This permits adaptation to changing experimental conditions.
  • Illustration: With M = 12 and reference deviation φ0 = 70°, the example selects jd = 2 to compensate the phase-reference mismatch.The offset is chosen by minimizing QBER from random sampling.
  • Alternative calibration: Strong calibration pulses can alternatively interfere at the measurement site to estimate channel phase fluctuations and determine jd.The calibration pulses may use a slightly offset optical mode to reduce crosstalk.
  • Key-rate accounting: The practical key-rate expression includes a 2/M phase-sifting factor and the error-correction efficiency f.The phase error rate is determined by the protocol’s security analysis.

V. SIMULATION RESULTS

Simulations show that PM-QKD can surpass established key-rate benchmarks at long distances, while its security and practical features remain advantageous. The comparison also clarifies that the cited linear bound applies to point-to-point protocols.

  • Simulation performance: Over 400 km is the longest practical transmission distance for PM-QKD at the cutoff R = 10^-8, versus below 250 km for BB84 and MDI-QKD.PM-QKD reaches approximately 4–6 orders of magnitude higher key rates than MDI-QKD when l > 300 km.
  • Simulation performance: l > 250 km marks where PM-QKD exceeds the linear key-rate bound under practical settings including dark counts, misalignment errors, and sifting factors.The simulation uses a lossy channel symmetrical for Alice and Bob, with dark counts and other typical parameters.
  • Protocol comparison: PM-QKD achieves a quadratic key-rate scaling, O(√η), and is measurement-device independent against detection attacks.The scheme also removes the requirement for basis switching, simplifying the apparatus and reducing randomness consumption.
  • Interpretation of the bound: The cited linear key-rate bound is derived for point-to-point QKD, whereas PM-QKD and other MDI-QKD schemes use an untrusted relay held by Eve.The authors note that the quadratic improvement may appear unsurprising if the untrusted middle node is viewed as a quantum repeater.
  • Protocol comparison: Security and performance analysis for TF-QKD apply when its basis information X, Y is ignored.The possibility of obtaining a higher key rate by using the basis information together remains open.

VI. OUTLOOK

The outlook identifies extensions to the phase structure, phase randomization, error estimation, and repeaterless capacity limits. It also records practical and theoretical boundaries that currently constrain PM-QKD.

  • Open directions: The general d-phase PM-QKD protocol, with and without phase randomization, remains an open direction for security analysis.A multibases interpretation may also support extensions to polarization-based phase matching.
  • Practical limitations: The phase-sifting factor 2/M is very small, undermining PM-QKD’s advantage for near-distance communication below 120 km.Biased phase randomization is proposed as one possible solution.
  • Error estimation: The total phase-error bound is pessimistic because even-photon components are assigned phase errors of 1.More decoy states may improve estimates of the two-photon errors eZ_2 and eX_2, yielding tighter bounds.
  • Capacity limits: PM-QKD’s key rate remains far from the single-repeater bound −log(1 − √η), despite overcoming the linear key-rate bound.The authors propose investigating whether repeaterless schemes can reach scalings such as O(η^1/3) or O(η^1/4).

Appendix A: Security Proof of PM-QKD

The security proof establishes PM-QKD security by working directly with continuous optical modes rather than conventional qubit or qudit channel states. It connects virtual entanglement-based reasoning, protocol equivalence, parity structure, and decoy-state phase-error bounds.

  • Security-proof strategy: The proof directly explores continuous optical modes instead of assuming qubit or qudit states transmitted through the channel.This is the central departure from existing discrete-variable QKD security proofs described by the authors.
  • Security-proof strategy: The proof organizes security through a virtual entanglement-based protocol, equivalency arguments, and a final security proof for PM-QKD.The decoy-state method is then used to bound phase-error rates, followed by phase postcompensation for the phase-reference issue.
  • Optical-mode representation: A coherent state is characterized using mean photon number µ = |α|^2, while optical modes are represented in Fock-state Hilbert spaces.Fock states |k⟩A contain k photons, and odd and even subspaces are spanned by Fock states with corresponding photon-number parity.
  • Optical-mode representation: The security analysis separates optical states by photon-number parity using odd/even parity measurements and photon-number measurements.The parity-state channel model parallels the photon-number channel used in decoy-state security proofs.
  • Optical operations: The optical modes are transformed by a beam splitter, while a control-phase gate applies a phase shift to an optical mode.The proof defines these operations using creation operators and the phase-shifter operation UA(φ).
  • Protocol equivalence: Equivalent QKD protocols must share transmitted states, announced classical information, measurements for raw-key generation, and postprocessing.Under these criteria, equivalent protocols have identical key rates.

1. Security proof via entanglement distillation

The security proof analyzes an entanglement-based PM-QKD protocol by distilling EPR pairs and relating observable Z-errors to inferred X-errors. Parity states create the correlation needed for this inference.

  • Security proof via entanglement distillation: The one-way hashing EDP reduces general coherent attacks to an equivalent Bell-diagonal analysis.The proof uses dephasing between pairs without changing the error syndrome or EDP performance.
  • Security proof via entanglement distillation: The key rate is determined by the Z-error and X-error rates through the CSS-based distillation ratio.The paper identifies Z-basis errors with bit errors and X-basis errors with phase errors.
  • Security proof via entanglement distillation: Protocol I prepares an optical state, splits it into two pulses, and sends the pulses to an untrusted interference measurement.Alice and Bob initialize local qubits, apply controlled phase operations, retain click rounds, and estimate errors by sampling.
  • Security proof via entanglement distillation: Entanglement distillation converts nearly pure EPR pairs into private keys after parameter estimation and error correction.Alice and Bob estimate EZ and infer EX before applying a standard EDP and measuring the resulting EPR pairs.
  • Security proof via entanglement distillation: Parity states correlate X- and Z-error rates, enabling X-error inference from Z-basis observations.The relation is established first for Fock states and then extended to pure and mixed parity states.

3. Coherent state protocol and equivalent process

The paper replaces Charlie’s source and beam splitter with independently prepared coherent states whose common phase encodes the key. Protocol II is shown to be equivalent to Protocol I for the corresponding input state.

  • Coherent state protocol and equivalent process: Protocol II is equivalent to Protocol I with input state ρ(√µ, −√µ).The state in Protocol II is the beam-splitter output of the state defined for Protocol I.
  • Coherent state protocol and equivalent process: Protocol II has Alice and Bob independently prepare coherent states of intensity µ/2 and apply the same random phase φ ∈{0, π}.They use controlled phase gates before sending the optical pulses to Eve, who announces an L/R detection or failure.
  • Coherent state protocol and equivalent process: After Eve announces a click, Alice and Bob sift the qubits, estimate EZ, infer EX, and distill keys when error rates are below threshold.Bob applies a Pauli Y gate for an R click, and the distillation ratio is given by Eq. (A15).
  • Coherent state protocol and equivalent process: The protocol initially requires a shared random phase, phase-reference locking, and information about odd- and even-parity parameters.The paper addresses these requirements by bounding the parameters and removing phase locking through phase postcompensation.

4. Security with phase announcement

Phase announcements are handled by comparing protocols with different announcement timing and by independently randomizing Alice’s and Bob’s phases. These modifications preserve the relevant sifted-qubit error patterns and yield Protocol III.

  • Security with phase announcement: Protocol IIa differs from Protocol II because the common phase is announced after Eve’s detection announcement.The timing difference changes the classical postprocessing and can make security differ under specific attacks.
  • Security with phase announcement: Protocol II treats phase-randomized optical signals as mixtures of odd- and even-parity states, whereas Protocol IIa cannot use that parity measurement after phase announcement.The parity measurement does not commute with the announced phases in Protocol IIa.
  • Security with phase announcement: Protocols II and IIa have identical X- and Z-error patterns after sifting, so their X-error rates are the same.Eve announces before phase information in Protocol IIa, preventing her strategy from depending on that later announcement.
  • Security with phase announcement: Protocol III independently randomizes φa and φb, announces them after Eve’s announcement, and applies a Y correction when their difference is π.This protocol is equivalent to Protocol IIa, while retaining discarded π-difference rounds for entanglement distillation.

5. Decoy-state method and phase randomization

The decoy-state method estimates parity components and error parameters from multiple intensities, while continuous phase randomization and postselection produce a practical Protocol IV and its prepare-and-measure form.

  • Decoy-state method and phase randomization: Continuous phase randomization decomposes coherent states into Fock-state components, which are parity states suitable for the security analysis.The vacuum contribution has q0 from dark counts and Z-error rate eZ_0 = 1/2.
  • Decoy-state method and phase randomization: The decoy-state method uses several intensity values to form linear equations for yields and Z-error rates.With infinitely many decoy states, Alice and Bob can estimate these parameters accurately and bound the X-error rate.
  • Decoy-state method and phase randomization: Finite decoy sets remain an open practical question because vacuum and weak decoy states may not suffice for valid estimation.The paper specifically identifies finite-decoy performance as an issue for practical implementations.
  • Decoy-state method and phase randomization: Protocol IV independently randomizes continuous phases and intensities, keeps equal-intensity signals with phase difference 0 or π, and estimates EZ and EX.Bob applies a Y correction when the phase difference is π before entanglement distillation.
  • Decoy-state method and phase randomization: The entanglement-based protocol becomes prepare-and-measure by moving the key measurements before entanglement distillation and parameter estimation.The reduction follows the Shor-Preskill argument.

6. Phase PostCompensation

Phase postcompensation removes the need for phase locking by estimating and compensating the changing phase-reference offset. The practical protocol uses phase slicing, intensity matching, interference detection, parameter estimation, and key distillation.

  • Phase slicing: Phase slicing replaces exact phase matching with ja = jb or |jb − ja| = M/2, adding a phase-sifting factor 2/M.Announcing slices rather than exact phases leaks less information to Eve; small M can increase misalignment and QBER.
  • Practical protocol: The practical protocol prepares independently randomized coherent states, sends them to an untrusted interferometer, and keeps matching-intensity rounds after detector announcements.Alice and Bob announce phase-slice indices and sampled bits for QBER testing, then estimate gains and phase-error rates before error correction and privacy amplification.
  • Phase postcompensation: Phase postcompensation removes phase locking by letting Bob estimate an offset jd and sift using |jb + jd − ja| mod M = 0 or M/2.For the M/2 case, Bob flips his key bit; jd is chosen by minimizing the sampled QBER.
  • Real-time compensation: Bob can adjust jd in real time approximately every τM, the interval during which phase fluctuation remains below π/M.Adequate sampled detections are needed to estimate the offset; the phase references may differ by a fixed but unknown offset.
  • Practical boundary: For M = 16, the tolerable phase fluctuation is about 0.196 rad.The paper compares this threshold with measured interferometer phase fluctuations and reported TF-QKD phase drift.
  • Simulation model: The protocol models a symmetric pure-loss channel with transmittance η, detector efficiency ηd, faithful interference, and dark-count rate pd.Detection probabilities, yields, gains, and error rates are evaluated for interference outcomes, with no-click and double-click events treated as failures.

2. Yields, gain, and error rates

The analysis derives photon-number yields, total gains, and bit-error rates for PM-QKD under the detection model, then uses them in the key-rate evaluation. It also compares the resulting rate with BB84, MDI-QKD, and the linear bound while examining the beam-splitting attack.

  • Yields and gain: The PM-QKD yield Yk and total gain Qµ are calculated from detection probabilities, with no-click and double-click events treated as failed detections.The simulation explicitly evaluates photon components up to k = 5 and uses their contributions to valid L/R-click detections.
  • Error sources: The phase-reference mismatch contributes a misalignment error, and for sufficiently small phase-slice number M, slice misalignment produces a large QBER.The derived rates are averaged over the phase-reference difference and compared with regular QKD-model expressions.
  • Key-rate evaluation: The key-rate calculation substitutes simulated gains, QBERs, photon fractions, and phase-error rates into the PM-QKD key-rate formula.The simulation compares PM-QKD with decoy-state BB84, MDI-QKD, and the linear key-rate bound.
  • Error rates: The average QBER combines photon-component error rates and the residual non-component contribution, while double-click handling differs from BB84.PM-QKD discards double clicks, whereas BB84 randomly assigns a bit to them.
  • Security-model boundary: The photon-number channel model fails for PM-QKD when random phases are announced, so naive tagging can produce a key-rate lower bound exceeding an attack-based upper bound.The paper therefore analyzes PM-QKD with a security proof rather than directly applying the tagging technique.
  • Beam-splitting attack: The beam-splitting attack gives an upper bound on the secure key rate by letting Eve store reflected light, interfere transmitted pulses, and perform unambiguous state discrimination.For sufficiently large µ, Eve’s successful guessing probability can approach one.

3. Comparison

The comparison shows that phase-encoding MDI-QKD suffers a source flaw despite O(√η) single-detection events, whereas PM-QKD uses an optical-mode security proof and supports secure key generation under the considered attack.

  • Under the BS-attack, the GLLP tagging formula fails for the single-photon component when η < 0.6.
  • At fixed η = 0.2, the GLLP tagging formula also cannot hold under the BS-attack.
  • The BS-attack can reveal all key bits, while the GLLP formula gives rate 0.5 and the proposed proof gives strictly zero.
  • Phase-encoding MDI-QKD: Phase-encoding MDI-QKD has O(√η) clicked signals but its coherent-state source flaw reduces the final key rate to O(η).
  • d-phase PM-QKD: PM-QKD independently prepares coherent pulses, encodes key information in their phases, and uses interference detection at an untrusted site.
  • d-phase PM-QKD: After detection announcements and parameter estimation, Alice and Bob calculate the key rate and extract private keys; the d = 2 case is proved with random phase announcement.
  • Comparison: PM-QKD switches from a qubit-based to an optical-mode-based view while following the phase-encoding MDI-QKD and TF-QKD schemes with modified encoding and basis choice.
Loading 1805.05538v3…