Source-linked AI summary

Asymptotic security analysis of discrete-modulated continuous-variable quantum key distribution

Jie Lin, Twesh Upadhyaya, Norbert Lütkenhaus

arXiv:1905.10896v2quant-ph

TL;DR

Discrete-modulated CV QKD has practical appeal but less mature security analysis than Gaussian-modulated schemes. The paper applies a versatile numerical method to quaternary protocols and finds tight asymptotic collective-attack rates, including improvements from postselection with reverse reconciliation.

  • Problem

    Discrete-modulated CV QKD has less mature security analysis than Gaussian-modulated schemes, while prior binary and ternary proofs are not tight or readily generalizable.

  • Method

    The paper applies numerical key-rate optimization to quaternary protocols with homodyne and heterodyne detection, extending the framework to postprocessing and postselection.

  • Results

    The quaternary scheme achieves key rates comparable to Gaussian modulation; with β = 0.95, protocol 1 reaches roughly 1/2 of the pure-loss repeaterless bound.

  • Takeaways & Limitations

    The method supports direct and reverse reconciliation and shows that postselection can improve key rates, including under reverse reconciliation.

  • Takeaways & Limitations

    The analysis assumes a photon-number cutoff and leaves finite-size effects, general attacks, and removal of the cutoff for future work.

Abstract

from arXiv · show

Continuous-variable quantum key distribution (CV QKD) protocols with discrete modulation are interesting due to their experimental simplicity and their great potential for massive deployment in the quantum-secured networks, but their security analysis is less advanced than that of Gaussian modulation schemes. In this work, we apply a numerical method to analyze the security of discrete-modulation protocols against collective attacks in the asymptotic limit, paving the way for a full security proof with finite-size effects. While our method is general for discrete-modulation schemes, we focus on two variants of the CV QKD protocol with quaternary modulation. Interestingly, thanks to the tightness of our proof method, we show that this protocol is capable of achieving much higher key rates over significantly longer distances with experimentally feasible parameters compared with previous security proofs of binary and ternary modulation schemes and also yielding key rates comparable to Gaussian modulation schemes. Furthermore, as our security analysis method is versatile, it allows us to evaluate variations of the discrete-modulated protocols, including direct and reverse reconciliation, and postselection strategies. In particular, we demonstrate that postselection of data in combination with reverse reconciliation can improve the key rates.

I. INTRODUCTION

Discrete-modulated CV QKD offers practical advantages but lacks the mature, tight security analysis available for Gaussian modulation. This work develops a numerical asymptotic-security method for quaternary protocols that supports multiple detection, reconciliation, and postselection variants.

  • Motivation: Discrete modulation could approach Gaussian-modulation performance with only a few coherent-state amplitudes, but its security analysis lacks comparable analytical tools.Binary and ternary proofs are not tight and are not expected to generalize readily to larger constellations.
  • Contribution: The method analyzes quaternary modulation with homodyne and heterodyne detection, obtaining tight asymptotic key rates against collective attacks without invoking Gaussian optimality.The framework is based on numerical key-rate optimization and applies to two protocol variants.
  • Extensions: Postselection can improve key rates under collective attacks, and the proof method supports both direct and reverse reconciliation.The method handles postselection through an extension of the classical postprocessing framework.
  • Protocol overview: Protocol 1 uses homodyne detection and two of four states for key generation, whereas protocol 2 uses heterodyne detection and encodes two bits per round.Both protocols include parameter estimation, key mapping, error correction, and privacy amplification.
  • Protocol 1: The homodyne protocol prepares four coherent states, measures randomly selected quadratures, and uses matched signal-and-measurement rounds for key generation.Other rounds are retained for testing and parameter estimation; Bob discretizes outcomes into binary symbols with an optional discarded symbol ⊥.

B. Protocol 2 (heterodyne detection)

Protocol 2 combines four-state coherent-state preparation with heterodyne detection and a four-region key map. Bob retains outcomes in selected regions as quaternary symbols and discards the rest, with region thresholds controlling postselection.

  • State preparation: Alice prepares one of four coherent states {|α⟩, |−α⟩, |iα⟩, |−iα⟩} with equal probability and sends it to Bob.The modulation amplitude α is real and predetermined.
  • Measurement: Bob performs heterodyne detection using the POVM {Eγ = 1/π |γ⟩⟨γ| : γ ∈ C} and obtains a complex measurement outcome.The outcome is later partitioned into key and discarded regions.
  • Sifting: After selecting test rounds for parameter estimation, Alice and Bob use the remaining rounds as the key-generation set.The protocol defines I_test and I_key by partitioning the N rounds.
  • Key mapping: Bob maps each complex outcome to one of four key symbols when it lies in a corresponding shaded region, and maps all other outcomes to ⊥.The parameters ∆a and ∆p determine the postselection regions; discarded ⊥ positions are removed before forming the raw key.
  • Postprocessing: The resulting raw strings undergo error correction and privacy amplification to generate a secret key.The quaternary alphabet may be recast as binary depending on the chosen error-correcting code.

III. SECURITY PROOF APPROACH

The security analysis reformulates the protocols in an entanglement-based picture and computes asymptotic collective-attack key rates through a constrained numerical optimization. Classical announcements, sifting, key mapping, and pinching are incorporated into the optimization map.

  • Framework: The analysis uses the numerical key-rate framework of Refs. to optimize asymptotic secret-key rates against collective attacks.The prepare-and-measure protocols are converted to equivalent entanglement-based schemes using source replacement.
  • Source replacement: Alice’s source ensemble {|α⟩, |−α⟩, |iα⟩, |−iα⟩} becomes a bipartite state, with her register retained and the transmitted register sent through a quantum channel.Alice’s local measurement selects which coherent state is effectively prepared for Bob.
  • Key-rate expression: The reverse-reconciliation Devetak–Winter rate depends on H(Z|E) − H(Z|X), multiplied by the probability that a round passes sifting.H(Z|X) represents Shannon-limit error-correction leakage, later replaced by the actual leakage δEC when inefficiency is included.
  • Optimization: The optimization constrains density operators to those compatible with experimental observations and rewrites the conditional entropy as a convex objective involving quantum relative entropy.The feasible set contains all states consistent with the observed data.
  • Postprocessing: The postprocessing map G models announcements, sifting, and the key-map isometry, while the pinching channel dephases the key register for readout.The map can produce a subnormalized state whose normalization factor is the pass probability.

3. Constraints

The security analysis formulates a convex optimization over bipartite states compatible with observed constraints, made numerically finite by imposing a photon-number cutoff on Bob’s system. The constraints use Alice’s fixed reduced state and measured quadrature-related moments, while the cutoff remains a working assumption requiring future removal for a watertight proof.

  • The feasible set contains bipartite density operators compatible with experimental observables and their measured expectation values.
  • Alice’s reduced state is fixed because Eve cannot modify Alice’s system in a prepare-and-measure scheme.
  • The optimization is a convex nonlinear semidefinite program with a jointly convex quantum-relative-entropy objective.
  • Bob’s infinite-dimensional optical system is truncated to photon numbers 0 through Nc, enabling finite-dimensional numerical optimization.The cutoff assumes ρ = ΠNcρΠNc for the state under consideration.
  • Choosing Nc much larger than the conditional mean photon numbers makes excluded photon-number sectors negligible, and numerical checks verify unchanged key rates at sufficiently large Nc.
  • The cutoff has not been removed analytically, so the security proof remains restricted despite the assumption’s numerical plausibility.Possible extensions use a CV squashing model or entropy-continuity bounds, but both are deferred to future work.
  • Homodyne-derived first and second moments constrain the state through quadrature, photon-number, and d = q^2 − p^2 observables.Additional fine-grained constraints could only improve the key rate, although the existing set already gives tight rates.
  • For reverse reconciliation with postselection, the Kraus map projects Alice onto the two key-generating states and Bob onto relevant q-quadrature intervals.

D. Optimization problem for protocol 2 (heterodyne detection)

For heterodyne detection, protocol 2 retains the same optimization structure while obtaining constraints from the Husimi Q function and using protocol-specific postprocessing and pinching maps. Region operators encode postselection areas in the measurement-output plane.

  • Protocol 2 uses the same optimization form as protocol 1, but heterodyne-derived expectation values and postprocessing maps differ.
  • Heterodyne detection is represented by a coherent-state POVM, whose outcomes define the Husimi Q function.
  • The Q function provides expectation values for q, p, n, and d through antinormally ordered operator expressions.
  • Postselection is encoded by region operators whose integration areas correspond to the regions shown in Fig. 1 and depend on Δa and Δp.
  • The heterodyne protocol uses a Kraus postprocessing map and a pinching channel defined by projections onto the four register states.
  • As in protocol 1, the Kraus operator is simplified to reduce the optimization state dimension.

E. Generalization to other discrete-modulation schemes beyond four coherent states

The numerical security method is not tied to Gaussian statistics and can extend to discrete-modulated CV QKD with more coherent states. The paper’s simulations model realistic phase-invariant Gaussian channels using transmittance and excess-noise parameters to generate optimization inputs.

  • The proof technique does not depend on whether the observed statistics are Gaussian or non-Gaussian.
  • With ℓ coherent states, Alice’s source-replacement register becomes ℓ-dimensional, while the optimization framework otherwise retains its essential form.
  • The simulations produce expectation values such as ⟨q⟩ and ⟨p⟩ that serve as inputs to the numerical key-rate optimization.
  • The modeled optical channel is phase-invariant and Gaussian, characterized by transmittance η and excess noise ξ.
  • The paper uses ξ for excess noise measured at Alice’s output and δ for noise measured at Bob’s received state.
  • The channel simulation can represent transmission as a displaced thermal state followed by pure loss, with output excess noise related by δ = ηξ.

B. About numerical algorithm and performance

The study uses a two-step numerical procedure to estimate secure key rates, comparing an approximate upper bound with a reliable lower bound and analytical results. In the pure-loss scenario, numerical rates track analytical results to about 120 km, while optimization gaps and convergence limitations become important at longer distances.

  • Two-step numerical procedure: The first step uses Frank-Wolfe optimization to find a suboptimal attack state, while the second solves a linear SDP for a reliable lower bound.The first-step result is treated as an approximate upper bound, whereas the second-step result is reliable but can be pessimistic.
  • Two-step numerical procedure: The first-step optimization may converge slowly, so the implementation limits it to 300 iterations and considers alternative solvers, initial points, and iteration counts.Different algorithms and solvers can have different convergence rates within the available time limit.
  • Loss-only performance: The plotted curves compare two-step bounds, analytical results, and the repeaterless secret-key capacity bound as functions of distance, using η = 10^-0.02L and β = 0.95.Protocol 1 uses homodyne detection with α searched over [0.36, 0.6], while protocol 2 uses heterodyne detection with α searched over [0.6, 0.95].
  • Loss-only performance: In the pure-loss channel, numerical results for both protocols remain close to direct Devetak-Winter evaluations up to around 120 km.Above 120 km, a visible gap between the approximate upper bound and reliable lower bound indicates room for numerical improvement.
  • Loss-only performance: With β = 0.95, protocol 1 reaches roughly 1/15 of the repeaterless capacity bound, while protocol 2 reaches approximately 1/10.Gaussian modulation with perfect reconciliation can reach 1/2 of this bound, placing quaternary modulation comparatively near Gaussian performance in the loss-only case.
  • Extensions and assumptions: The numerical method also models nonzero excess noise, postselection, error correction, and key-rate optimization for experimentally simulated statistics.Postselection is represented through a cutoff parameter, and reconciliation inefficiency is modeled with β = 0.95 unless otherwise noted.

2. Key rates for protocol 1

For protocol 1, the analysis identifies stable amplitude choices, long-distance key generation under experimentally feasible noise, and potential gains from postselection in reverse reconciliation.

  • Amplitude optimization: The optimal coherent-state amplitude is around 0.4 for distances of 20, 50, 80, and 100 km at excess noise ξ = 0.01.This corresponds to a mean photon number of 0.16 and changes little across the tested distances.
  • Distance performance: Protocol 1 with homodyne detection reaches around 200 km before the key rate falls below 10^-6 per pulse at ξ = 0.01.The amplitude is optimized by a coarse-grained search over [0.35, 0.6].
  • Distance performance: 103 bits per second are obtained at around 170 km when total excess noise is at most 1%, using a 1 GHz repetition rate and 55% detector efficiency.
  • Postselection: Postselection discards noisy data where Eve has greater advantages and can improve key rates in reverse reconciliation.The strategy is implemented by modifying the postprocessing map, and setting ∆c = 0 recovers the no-postselection protocol.
  • Postselection: Figure 5 compares postselection and no postselection across transmission distance for reconciliation efficiencies β = 0.95 and β = 0.9.It also varies the postselection parameter ∆c at L = 20 km under ξ = 0.02 and α = 0.45.

2. Key rates for protocol 2

Protocol 2 with heterodyne detection achieves strong key rates across distance and excess-noise settings, with optimized amplitudes around α = 0.7. Its rates exceed protocol 1 and a prior security analysis, approach Gaussian-modulated performance, and can benefit from reverse-reconciliation postselection.

  • Amplitude optimization: α ≈ 0.7 is optimal for protocol 2 across selected distances, corresponding to a mean photon number around 0.49.Protocol 1 instead uses α ≈ 0.4, or a mean photon number around 0.16.
  • Distance and noise tolerance: Around 200 km is reachable with protocol 2 even at excess noise ξ = 0.02.The amplitude is optimized by a coarse-grained search over [0.6, 0.92].
  • Protocol comparison: Protocol 2 achieves much higher key rates than protocol 1 when excess noise is large.The direct comparison covers ξ = 0.01 and ξ = 0.02.
  • Comparison with prior analysis: The security proof yields higher key rates than Ref., while amplitude optimization further improves the rates.The comparison uses fixed α = 0.35 and optimized α values over [0.6, 0.92].
  • Comparison with Gaussian modulation: Protocol 2 has key rates comparable to Gaussian-modulated CV QKD when both modulation choices are optimized.The comparison uses heterodyne detection and distance-specific optimization.
  • Postselection: Postselection with reverse reconciliation can improve key rates.For ξ = 0.04 and α = 0.6, the optimal amplitude postselection parameter is roughly within [0.4, 0.7].

APPENDIX A: FRAMEWORK FOR POSTPROCESSING: DERIVATION AND SIMPLIFICATION

The appendix constructs a general postprocessing framework for numerical security analysis by representing announcement, sifting, and key-map operations as isometries. It tracks public information and produces explicit maps for direct and reverse reconciliation.

  • Framework: The framework represents announcement, sifting, and key-map steps as isometries acting on local registers.The initial pure state is evolved by local unitaries that introduce registers for announcements, measurements, sifting, and keys.
  • Announcement and measurement: Announcement and measurement isometries implement Alice’s and Bob’s POVMs while copying public announcements to Eve.Announcement registers and measurement-outcome registers are introduced locally, with coherent copying for publicly available information.
  • Sifting: The sifting isometry classifies announcement pairs as kept or discarded and stores the result in a dedicated register.The sets of announcement events are partitioned into K and D, and a controlled unitary computes the decision.
  • Key map: The key-map isometry converts announcement and measurement outcomes into one of N key symbols, assigning discarded events the auxiliary symbol ⊥.Direct reconciliation uses Alice’s outcome, whereas reverse reconciliation uses Bob’s outcome.
  • Purification and leakage: The construction preserves a purification-based description of the protocol under collective attacks by applying isometries to the initial pure state.The appendix explicitly notes that the resulting state remains pure because only isometries are applied.

2. Removing the dependence on Eve’s registers

The appendix shows how the numerical postprocessing maps can omit or simplify registers without changing the key-rate calculation. The simplifications exploit local isometries, classical announcement structure, and the coarse-grained information used by the key map.

  • Removing auxiliary symbols: The auxiliary discarded-event symbol ⊥ contributes no key rate and can be removed from the final key measurement.On the subspace selected by the sifting projector, ⊥ does not appear.
  • Numerical simplification: The resulting simplified maps reduce the dimensions required for numerical analysis while preserving the calculated key rates.The appendix derives these reductions from the general postprocessing map and its objective-function properties.
  • Isometry invariance: The key-rate objective is invariant under local isometries that commute with the G and Z maps.This invariance permits adding or removing such isometries in the final expression.
  • Register simplification: For reverse reconciliation, Alice’s refined measurement can be omitted when it commutes with the G and Z maps and does not affect the key map.The refinement is local to Alice, so it can be postponed or dropped from the key-rate calculation.
  • Coarse-grained measurements: When the key map uses only coarse-grained information, Bob’s refined measurement can be removed from the effective Kraus-operator construction.The key-map isometry effectively undoes the refined-measurement unitary.

APPENDIX B: OPERATORS WITH THE PHOTON-NUMBER CUTOFF

The photon-number cutoff converts the infinite-dimensional operator problem into a finite-dimensional matrix optimization. The appendix specifies how truncated states, operators, and POVM elements are represented and square-rooted consistently.

  • Cutoff assumption: The photon-number cutoff restricts Bob’s state to the subspace spanned by |0⟩ through |Nc⟩.The cutoff assumes ρAB is projected onto this finite photon-number subspace.
  • Finite-dimensional representation: Truncated operators are represented by ΠNc Ô ΠNc, yielding finite-dimensional matrices for the optimization.The relevant operators include truncated conditional states and observables.
  • Operator construction: The annihilation operator is written in the photon-number basis, after which creation and other observables follow directly.The appendix constructs q̂, p̂, n̂, and d̂ from â and â†.
  • POVM construction: Quadrature and region operators are obtained from overlaps between quadrature eigenstates and photon-number states.These overlaps provide the matrix elements needed for interval and region POVM operators.
  • POVM square roots: The square root of a POVM element must be taken after truncation, because truncation can destroy projectivity.The required operator is √(ΠNc F ΠNc), not the untruncated square root followed by projection.

APPENDIX C: EVALUATION OF LOSS-ONLY KEY RATES

The loss-only analysis uses Eve’s generalized beam-splitting attack and exploits the resulting product structure to simplify her conditional states. The Devetak-Winter formula can then be evaluated directly from finite-dimensional representations of those states.

  • In the pure-loss channel, Eve’s optimal attack is the generalized beam-splitting attack.
  • Bob’s measurement outcome does not influence Eve’s state because Bob and Eve share a product state after the channel.
  • Eve’s conditional state depends on Alice’s symbol x but is independent of Bob’s raw-key value z.

1. Protocol 1

The protocols’ conditional Eve states occupy low-dimensional subspaces determined by the modulation alphabet, enabling direct matrix-based evaluation of the Devetak-Winter formula. The binary and quaternary cases use two- and four-dimensional representations, respectively.

  • Protocol 1: For protocol 1, the modulation alphabet {α, −α} makes Eve’s conditional states span a two-dimensional subspace.
  • Protocol 1: The Devetak-Winter formula is evaluated directly using the mutual information I(X; Z) and the Holevo quantity χ(Z : E).
  • Protocol 1: The von Neumann entropy H(σ) = −Tr(σ log2 σ) supplies the entropy used in the relevant state calculations.
  • Protocol 1: The relevant probabilities and two-dimensional matrix representations make direct numerical evaluation of the Devetak-Winter formula straightforward.
  • Protocol 2: For protocol 2, the alphabet {α, iα, −α, −iα} makes Eve’s conditional states span a four-dimensional subspace.
  • Protocol 2: Protocol 2 uses an orthonormal four-dimensional basis and extends the summation indices from 0–1 to 0–3 in the corresponding expressions.
Loading 1905.10896v2…