Source-linked AI summary

10~Mb/s quantum key distribution

Z. L. Yuan, A. Plews, R. Takahashi, K. Doi, W. Tam, A. W. Sharpe, A. R. Dixon, E. Lavelle, J. F. Dynes, A. Murakami, M. Kujiraoka, M. Lucamarini, Y. Tanizawa, H. Sato, A. J. Shields

arXiv:1807.04484v1quant-ph

TL;DR

QKD systems have been limited by the need to sustain high secure-key rates across photonic and post-processing layers, especially when large finite datasets are required. The paper combines an efficient finite-size protocol with high-speed photonic and hardware-accelerated processing modules, achieving 13.72 Mb/s over a 2 dB channel and stable month-long operation of a second system.

  • Problem

    Sustained QKD secure-key rates were limited by post-processing speed, while large datasets were needed to mitigate finite-size effects.

  • Method

    The systems combine an efficient decoy-state finite-size protocol with high-speed photonic hardware and specialized sifting, FPGA-based error-correction, and co-processor privacy-amplification modules.

  • Results

    13.72 Mb/s record secure key rate was achieved over a 2 dB channel, and a second system averaged 11.53 Mb/s during one month of continuous operation.

  • Takeaways & Limitations

    The complete systems operate above 10 Mb/s without layer bottlenecks and support simultaneous multi-user quantum-network service with Mb/s key rates.

Abstract

from arXiv · show

We report the first quantum key distribution (QKD) systems capable of delivering sustainable, real-time secure keys continuously at rates exceeding 10 Mb/s. To achieve such rates, we developed high speed post-processing modules, achieving maximum data throughputs of 60 MC/s, 55 Mb/s, and 108 Mb/s for standalone operation of sifting, error correction and privacy amplification modules, respectively. The photonic layer of the QKD systems features high-speed single photon detectors based on self-differencing InGaAs avalanche photodiodes, phase encoding using asymmetric Mach-Zehnder interferometer, and active stabilization of the interferometer phase and photon polarisation. An efficient variant of the decoy-state BB84 protocol is implemented for security analysis, with a large dataset size of $10^8$ bits selected to mitigate finite-size effects. Over a 2 dB channel, a record secure key rate of 13.72 Mb/s has been achieved averaged over 4.4 days of operation. We confirm the robustness and long-term stability on a second QKD system continuously running for 1 month without any user intervention.

I. INTRODUCTION

Raising sustainable secure key rates requires coordinated improvements across QKD’s photonic and post-processing layers. The paper addresses post-processing bottlenecks with specialized hardware and demonstrates secure-key delivery above 10 Mb/s.

  • System bottleneck: The final secure key rate is determined by the slowest sequential layer, from photon preparation and detection through sifting, error correction, and privacy amplification.An authenticated classical communication channel facilitates the post-processing layers.
  • System bottleneck: 1.9 Mb/s was the previous record secure rate, while software-based error correction and privacy amplification limited further improvement.The photonic bottleneck had shifted upward to data-processing layers as detector technology improved.
  • Contribution: 13.72 ± 0.74 Mb/s sustainable real-time secure key rate was achieved over a 2 dB channel, while a second system averaged 11.53 Mb/s during one month.The second system’s operation confirmed robustness over a 2 dB quantum channel.

II. REQUIREMENTS FOR HIGH SECURE KEY RATES

High secure key rates depend on matching photonic generation, sifting efficiency, and post-processing throughput. The required system resources therefore span high-rate detection, efficient protocol operation, and sufficiently fast error correction and privacy amplification.

  • Rate determinants: The secure key rate R depends on clock frequency, detection probability, sifting efficiency, single-photon probability, phase-error rate, QBER, and error-correction information leakage.The expression also includes binary entropy and the efficiency of the employed error-correction algorithm.
  • Photonic and sifting requirements: High SKR requires high-clock-rate photon transmission and detection, with short or low-loss fiber channels favored because fiber SKR decreases exponentially with distance.Sifting electronics must also handle raw count rates greater than fηd.
  • Photonic and sifting requirements: Efficient protocols increase the fraction of raw detection events retained as sifted keys, whereas standard BB84 has η_sift ≤0.5.The requirements include both high sifting throughput and an efficient protocol.
  • Post-processing requirements: 40 Mb/s error-correction and privacy-amplification throughput plus 50 MC/s sifting throughput are required for 10 Mb/s secure key rates under typical parameters.Privacy amplification must process large datasets to mitigate finite-size effects.

III. PROTOCOL

The implemented T12 protocol adapts decoy-state BB84 for finite datasets by optimizing basis and photon-flux choices. Its settings target efficient key extraction while controlling statistical finite-size effects.

  • Finite-size security: The T12 protocol provides composable security against collective attacks in the finite-size scenario rather than assuming an infinite dataset.Its security is related to the size of the experimental data sample.
  • Basis selection: Alice randomly selects Z or X states, with Z used mainly for key generation and X used for phase-error estimation; the basis probability pX is optimized for key rate.The secure key rate is the sum of rates distilled separately in the two bases.
  • Decoy-state operation: Signal, decoy, and vacuum photon fluxes are randomly selected, and decoy-state parameters are numerically optimized for every acquired dataset.The three flux categories are denoted u, v, and w.
  • Finite-size security: 100 Mb datasets were chosen to reduce finite-size effects while remaining manageable for privacy amplification, retaining 85% of the asymptotic secure key rate.The T12 protocol can tolerate security parameters as small as 10^-10, but larger datasets improve statistical precision and key generation.
  • Implemented settings: 0.90 sifting efficiency and approximately 0.29 privacy-amplification compression were obtained for typical QBER of 3% and PA dataset size of 10^8 bits.The sifting efficiency is almost twice that of standard BB84, and compression yields about 0.29 secure bits per error-corrected bit.

IV. SYSTEM HARDWARE

The QKD hardware packages transmitter, receiver, optics, and control electronics into compact rack units while placing error-correction and privacy-amplification accelerators in servers. High-bandwidth Ethernet carries local and remote classical communications.

  • Hardware architecture: 2U 19-inch rack units house the quantum transmitter and receiver, while EC/PA hardware accelerators are housed inside control servers.The rack units contain the optical and control/sifting electronics.
  • Classical communications: 10G communication interfaces handle and route classical communications between servers, sifting electronics, and the remote peer over the data-fiber link.The system uses standard 10G Ethernet interfaces for both local and remote communication.
  • Optical layout: The optical layout uses active components controlled by sifting/control electronics, including DWDM, polarization combining or splitting, and an electrically controlled attenuator.DWDM denotes dense wavelength division multiplexing; PBC/PBS denotes polarization beam combiner/splitter; Att denotes variable optical attenuation.

A. Optics

The optical subsystem combines decoy-state phase encoding, high-speed self-differencing detectors, and active stabilization to support continuous QKD operation.

  • Four wavelengths carry quantum, classical data, and clock-synchronization signals between Alice and Bob.The quantum signal uses λ1 at 1550.12 nm, while three wavelengths support classical communication and synchronization.
  • Three optical pulse intensities implement the decoy-state technique at a 1 GHz clock rate.The intensities are 0.4, 0.08, and 0.0007 photons per pulse; phase encoding uses an asymmetric Mach-Zehnder interferometer.
  • Matching asymmetric Mach-Zehnder interferometers decode phase information into two self-differencing InGaAs avalanche photodiodes with count rates above 100 MC/s.The receiver interferometer loss is about 2 dB.
  • Active stabilization compensates environmental disturbances affecting photon polarisation, interferometer phase delay, and photon arrival time.Alice controls polarisation, while Bob stabilizes phase and detector gate delay.

B. Control and sifting electronics

The control and sifting electronics use custom FPGA hardware to coordinate high-speed optical control, detection processing, stabilization, communication, and real-time sifting.

  • Custom FPGA boards handle optical modulation, photon time-tagging, active stabilization, random-number generation, sifting, and packet communication.Each board includes 10G SFP+ interfaces for connections to control servers and communication links.
  • 60 MC/s is the demonstrated capacity for hardware-level sifting, including basis reconciliation and decoy-state statistics collection.
  • LDPC error correction was selected for post-processing throughput above 40 Mb/s because it uses a single unidirectional reconciliation message.Its communication structure avoids throughput reductions from repeated round trips and supports parallel implementation.
  • 1.13 to 1.20 is the FPGA-LDPC EC efficiency for QBER values between 2% and 10%.The implementation uses code-rate adaptation based on the QBER in each error-correction block.
  • Estimated rather than precisely known QBER slightly reduces practical EC efficiency because a safety margin is added to avoid decoding failures.
  • 55 Mb/s is the measured EC throughput, sufficient to support 10 Mb/s secure key rates.Each 1 Mb EC block is divided into sub-blocks processed in parallel, and failed verification causes the whole block to be discarded.

D. Privacy amplification module

The privacy amplification module combines NTT-based Toeplitz multiplication with Xeon Phi parallelism to process large datasets needed for finite-size QKD security.

  • Privacy amplification compresses error-corrected keys to remove information potentially known to Eve.Direct matrix multiplication has O(n^2) complexity and becomes problematic for large datasets.
  • NTT transforms Toeplitz multiplication and reduce its computational complexity from O(n^2) to O(n log n).The transformation belongs to the family of universal-2 hash functions.
  • Xeon Phi coprocessor parallelism is used to increase privacy-amplification throughput through vectorization, loop unrolling, and multithreading.
  • 108.77 Mb/s is the evaluated NTT throughput at a dataset size of about 100 Mb, supporting secure key rates exceeding 20 Mb/s at 5% QBER.The implementation supports variable dataset sizes up to 227 bits (134 Mb).
  • 100.66 Mb is the selected PA dataset size, and the module allows a maximum compression ratio of 1/3.

V. SYSTEM EVALUATION AND PERFORMANCE

Two QKD systems were evaluated with real-time pipelined processing over a 2 dB channel, including continuous runs lasting 4.4 days and 1 month without user intervention.

  • 2 dB was the quantum-channel loss, equivalent to 10 km of standard single-mode fiber at 0.2 dB/km.
  • All sifting, error correction, and privacy amplification processes were pipelined and performed in real time, with secure keys written to hard drives.
  • 4.4 days and 1 month were the continuous evaluation durations for Systems I and II, respectively, without user intervention.

A. Record secure key rate

The QKD system combined stable high-speed sifted-key generation with LDPC error correction and privacy amplification to sustain secure-key production above 10 Mb/s over a 2 dB channel.

  • 47.83 ± 0.22 Mb/s sifted key rate was measured with a stable QBER of (3.07 ± 0.05)%.The sifted-key data were reported approximately every 2 seconds; detector afterpulsing contributed 2.2% to the measured QBER.
  • (0.73 ± 0.15)% LDPC error-correction failure probability was measured, with failed blocks discarded before privacy amplification.
  • 0.292 ± 0.016 privacy-amplification compression ratio was obtained during the test.The system distilled 29.39 Mb secure bits per 100.66 Mb error-corrected keys.
  • 13.72 Mb/s average secure key rate was achieved over the test duration, generating 5.2 Tb of secure key material.Secure-rate values remained above 10 Mb/s except for a few data points.

B. Long-term system stability

A second QKD system maintained stable key generation during one month of continuous operation, despite lower detector efficiency and additional fiber-induced instability.

  • 28% detector efficiency characterized System II, which had comparable afterpulsing and dark-count performance to System I.
  • 25 km fiber spools were used for the quantum and communication channels, each with 5 dB loss, to provide a realistic polarization-drift test.The extra loss was compensated to maintain the same quantum-channel loss as System I.
  • 42.21 ± 1.65 Mb/s sifted rate, 11.53 ± 0.65 Mb/s secure rate, and 3.16 ± 0.07% QBER were measured during the one-month test.The quantities showed excellent stability, while fluctuations were slightly larger than in System I because of the 25 km fiber spool.
  • Secure bit rate stayed over 10 Mb/s throughout the entire period, despite rates about 16% lower than System I.The lower rates were attributed to lower detector efficiency and slightly higher QBER.
  • 31.35 Tb of secure key material was generated during the one-month test.

VI. CONCLUSION

The paper demonstrates complete QKD systems that sustain real-time secure-key generation above 10 Mb/s. The reported rate improves substantially on the previous record and supports high-rate network and dedicated-link applications.

  • VI. CONCLUSION: 60 MC/s, 55 Mb/s, and 108 Mb/s were the individual maximum throughputs of sifting, error correction, and privacy amplification modules.These modules were integrated into a compact QKD system.
  • VI. CONCLUSION: 13.72 Mb/s secure key rate was achieved over a 2 dB loss channel equivalent to 10 km standard telecom fiber.
  • VI. CONCLUSION: 1-month continuous operation over a 2 dB-loss quantum channel made from 10 km fiber confirmed system robustness on real fiber.
  • VI. CONCLUSION: 13.72 Mb/s secure-key distribution rate increased from the previous 1.9 Mb/s record, while all system layers operated without bottlenecks.
  • VI. CONCLUSION: Mb/s key rates for multiple users sharing a network link became feasible according to the paper’s stated network implication.
  • VI. CONCLUSION: Dedicated-link operation can provide key rates for one-time-pad encryption of voice, video, medical, and financial communications.
Loading 1807.04484v1…