Source-linked AI summary

Twin-field Quantum Key Distribution without Phase Post-Selection

Chaohan Cui, Zhen-Qiang Yin, Rong Wang, Feng-Yu Lu, Wei Chen, Shuang Wang, Guang-Can Guo, Zheng-Fu Han

arXiv:1807.02334v3quant-ph

TL;DR

TF-QKD variants can surpass the linear rate-loss limit but traditionally require active phase randomization and phase post-selection. This paper removes both from the coding mode, develops a different security proof, and obtains R = O(√η) with higher practical key rates over relevant channel losses.

  • Problem

    TF-QKD and its variants rely on active phase randomization and phase post-selection, while phase post-selection can impair practical secret key rates.

  • Method

    The paper introduces a simplified TF-QKD protocol encoding bits in phase 0 or π without active phase randomization or coding-mode phase post-selection, and bounds latent information leakage against collective attacks.

  • Results

    R = O(√η), and simulations show higher key rates than original PM-QKD, with the protocol beating the linear bound across reported loss ranges.

  • Takeaways & Limitations

    Removing phase randomization and phase post-selection remains compatible with beating the linear rate-loss limit and may improve practical performance over relevant channel losses.

Abstract

from arXiv · show

Twin-field quantum key distribution (TF-QKD) protocol and its variants, e.g. phase-matching (PM) QKD and TF-QKD based on sending or not sending, are highly attractive since they are able to overcome the well-known rate-loss limit for QKD protocols without repeater: $R=O(η)$ with $η$ standing for the channel transmittance. However, all these protocols require active phase randomization and post-selection that play an essential role together in their security proof. Counterintuitively, we find that in TF-QKD, beating the rate-loss limit is still possible even if phase randomization and post-selection in the coding mode are both removed, which means our final secure key rate $R=O(\sqrtη)$. Furthermore, our protocol is more feasible in practice and more promising according to its higher final key rate in the valid distance. Our security proof counters collective attack and can also counter coherent attack in asymptotical case

I. INTRODUCTION

TF-QKD overcomes the conventional linear key-rate bound, but existing variants rely on active phase randomization and phase post-selection. The paper asks whether both requirements can be removed in coding mode while retaining improved performance.

  • Motivation: The conventional QKD secret-key rate obeys R ⩽ −log2(1 −η), which becomes R = O(η) at long distance.TF-QKD was proposed to overcome this rate-loss limit.
  • Existing protocols: PM-QKD generates raw keys only after post-selecting trials with approximately matching phases φA ≈φB.Alice and Bob send weak coherent states with independently randomized phases to an untrusted middle party.
  • Existing protocols: TF-QKD and its variants generally require active phase randomization and post-selection for security of the sifted key bits.The sending-or-not-sending variant can tolerate large optical misalignment but has an unsatisfactory final key rate.
  • Paper contribution: The proposed simplified protocol encodes key bits in phase 0 or π without active phase randomization or phase post-selection in coding mode.Its security proof estimates an upper bound on latent information leakage, and simulations report satisfactory or better performance than other protocols.

II. SIMPLIFIED TF-QKD

The simplified protocol removes post-selection from TF-QKD coding mode while retaining decoy-mode estimation. Alice and Bob use code or decoy trials, receive Eve’s public detector message, and generate or estimate data accordingly.

  • Protocol flow: The simplified TF-QKD protocol removes the post-selection part of the original protocol.The protocol proceeds through randomized mode selection, state preparation, public measurement announcements, and subsequent sifting.
  • Protocol flow: Alice and Bob randomly choose code mode or decoy mode in each trial.The choice is made independently for every trial before state preparation.
  • Code mode: In code mode, each party sends a weak coherent state determined by a random classical bit, without active phase randomization.The encoded states are | ± √µ⟩A-out and (±|√µ⟩B-out).
  • Decoy mode: In decoy mode, each party sends a phase-randomized weak coherent state with a randomly selected mean photon number from a predetermined set.The phase is never publicly announced, so the emitted state is treated as a mixed state in Fock space.
  • Measurement announcement: Eve publicly announces success or failure and, upon success, declares detector message |L⟩M or |R⟩M.Double clicks are randomly assigned to one detector message for simplicity.
  • Sifting and estimation: After mode announcements, matching code trials produce raw keys, while matching decoy trials estimate the yield Yn,m.Bob flips his bit when Eve announces |R⟩M; Yn,m is the probability of a successful announcement for n- and m-photon inputs.

III. MAIN RESULTS OF SECURITY PROOF

The security proof bounds Eve’s information under general collective attacks using photon-number representations and observable yields. Combining this leakage bound with Devetak–Winter gives a secure rate that scales as O(√η) in the ideal case and extends asymptotically to coherent attacks.

  • Attack model: Eve’s collective attack is modeled as an arbitrary measurement following an arbitrary unitary operation on the entire system with a prepared ancilla.The proof makes no assumptions beyond those used in MDI-QKD.
  • Attack model: The photon-number attack representation assigns successful-message probability Yn,m and Eve states to n- and m-photon inputs.The proof focuses on bounding Eve’s information IAE about Alice’s key bit when a successful message is announced.
  • Information bound: The upper bound IuAE is obtained by an optimization over variables constrained by photon-number probabilities, yields, and the observed code-mode raw-key probability Qµ.The entropy-like function h(x, y) and constraints separate even- and odd-photon contributions.
  • Key-rate bound: The secret key rate per code-mode trial follows from Devetak–Winter’s bound using the information-leakage bound and raw-key error rate eµ.The observable quantities include Pn, Pm, Qµ, and Yn,m.
  • Ideal scaling: In the ideal case, x00 and x11 scale as µ^2O(√η), while x01 and x10 scale as µO(√η), yielding IuAE ≪1 for suitable µ.The dominant terms arise from yields with total photon number two.
  • Ideal scaling: R = O(√η) in the ideal case, confirming that the protocol can beat the linear rate-loss bound without phase randomization or post-selection.The proof initially assumes collective attacks, while coherent-attack security follows asymptotically from cited results.

IV. ESTIMATION AND SIMULATION WITH INFINITE DECOY STATES

With infinite decoy states, the protocol estimates yields accurately and achieves a secure-key-rate scaling of R = O(√η), overcoming the linear rate-loss bound over 30–60 dB fiber loss.

  • Yield estimation: Infinite decoy states provide linear equations that can calculate the yields Y_n,m accurately.The resulting yield estimates are used to evaluate the secure key rate through the information-leakage bound.
  • Simulation results: R = O(√η) when fiber loss is below 60 dB, matching the single-repeater linear-bound slope.This reconfirms beating the linear rate-loss bound across 30–60 dB fiber loss.
  • Protocol comparison: The protocol has a higher key rate than original PM-QKD with infinite decoy states because it avoids phase post-selection and extra error estimations.It also outperforms BB84 at lower channel loss than original PM-QKD.

V. ESTIMATION AND SIMULATION WITH FINITE DECOY STATES

Finite decoy states are implemented with four intensities and linear-programming bounds on yields, producing a practical protocol that retains R = O(√η) and beats the linear bound from 40 to 60 dB loss.

  • Finite-decoy estimation: Four intensities, µ, ν1, ν2, and 0, make finite-decoy implementation more feasible in practice.The observed gains from these intensities provide bounds for the relevant yields.
  • Finite-decoy estimation: Linear programming bounds the yields Y_0,0, Y_0,1, Y_1,0, Y_2,0, Y_0,2, and Y_2.The bounds are derived from gain equations such as Q_µ,0, Q_0,µ, and Q_µ,µ.
  • Finite-decoy estimation: Y_1,1 is constrained between lower and upper bounds using bounded yields from the finite-decoy statistics.These constraints support the final optimization of the secure key rate.
  • Key-rate optimization: The final optimization finds the best information-theoretically secure key rate subject to the estimated yield bounds.The optimization uses the bounds on x_00, x_01, x_10, and x_11.
  • Simulation results: R = O(√η) with finite decoy states, allowing the protocol to beat the linear bound from 40 dB to 60 dB loss.The result is shown for the simulated practical case with four decoy states.

VI. CONCLUSION

The paper concludes that its simplified TF-QKD protocol generates raw keys without active phase randomization or phase post-selection while retaining a secure rate scaling of R = O(√η). It also reports practical advantages over PM-QKD and BB84 in relevant loss ranges.

  • Conclusion: Raw key bits are generated without active phase randomization or phase post-selection.This is the central simplification of the proposed protocol.
  • Conclusion: The security proof estimates information leakage and shows that the protocol retains R = O(√η) over transmittance η.The leakage bound does not rely on the error rate.
  • Conclusion: The protocol can outperform BB84 at shorter channel distances than original PM-QKD.The reported competitive channel-loss range is around 15 dB to 60 dB.
  • Related work: Two other groups independently reported similar ideas after the work was posted, but did not include the practical finite-decoy case.The note places the paper’s finite-decoy treatment in relation to those later works.

APPENDIX A: SECURITY PROOF

The security proof models Eve’s most general collective attack under MDI-QKD assumptions and groups the encoded optical states by photon-number parity. It then bounds Eve’s information about Alice’s key from the resulting conditional states and observables.

  • Attack model: The proof assumes no more about Eve than measurement-device-independent QKD and models her attack as arbitrary unitary evolution followed by measurement.Eve’s prepared ancilla is included in the model.
  • Attack model: The collective-attack representation allows Eve to distinguish decoy and code modes because her ancilla is arbitrary.Any measurement-dependent transformation can be represented by a larger “giant” unitary operator.
  • Encoding structure: Alice and Bob encode classical bits using C-π gates applied to weak coherent-state pulses, then measure their ancillary qubits.The encoding phases are 0 or π.
  • Parity decomposition: The proof groups photon-number components into four unnormalized states according to whether Alice’s and Bob’s photon numbers are even or odd.The four groups are even-even, odd-odd, even-odd, and odd-even.
  • Information bound: Conditioning on Eve’s successful message and tracing out Bob produces a density matrix for Eve and Alice’s mode, which is used to bound the Holevo information.The proof applies the Holevo bound to these conditional states.
  • Information bound: The resulting bound limits Eve’s information about Alice’s classical key bit even when active phase randomization is removed.The Devetak–Winter bound then gives the secret key rate per code-mode trial.

APPENDIX B: DETAILS OF MATHEMATICS IN SIMULATION

The appendix derives numerical and analytical procedures for bounding detector responses, error rates, and information leakage in the protocol’s simulation. Finite-decoy statistics are combined with constrained optimization, while the analysis assumes zero misalignment for best performance.

  • Simulation model: The simulation models detector dark counts, coherent-state inputs, channel loss, interference, and possible wrong-detector responses.Each detector has dark-count probability p_d per trial, and each sender’s coherent state carries average µ photons.
  • Simulation model: The response probability and error rate are computed from gain contributions involving dark counts and channel loss.The appendix gives an explicit expression for Q_µ and introduces the corresponding error-rate calculation.
  • Assumption: The analysis assumes zero device misalignment, although misalignment could be incorporated into both gain and error-rate calculations.This assumption corresponds to evaluating the protocol’s best-performance case.
  • Decoy-state estimation: With infinite decoy states, the yields Y_n,m can be approximated directly, while random assignment of double clicks simplifies their security bounds.The double-click treatment is stated to preserve security while assigning events to |L⟩_M or |R⟩_M at random.
  • Decoy-state estimation: With finite decoy states, linear programming bounds selected low-order yields, including Y_0,0, Y_0,1, Y_1,0, Y_2,0, Y_0,2, and Y_1,1.The remaining information-leakage terms are bounded through an optimization problem constrained by observed statistics.
  • Analytical bounds: The optimization reduces to selecting an integer k ≥ 2 at the boundary of the feasible yield region, using positivity, exponential decay, and inequalities including arithmetic–quadratic mean and Cauchy–Schwarz.The same approach is also used to estimate upper bounds for x_10, x_01, and x_11.
Loading 1807.02334v3…