Source-linked AI summary

Advances in Quantum Cryptography

S. Pirandola, U. L. Andersen, L. Banchi, M. Berta, D. Bunandar, R. Colbeck, D. Englund, T. Gehring, C. Lupo, C. Ottaviani, J. Pereira, M. Razavi, J. S. Shaari, M. Tomamichel, V. C. Usenko, G. Vallone, P. Villoresi, P. Wallden

arXiv:1906.01645v1quant-phmath-phphysics.app-phphysics.comp-phphysics.optics

TL;DR

Quantum cryptography faces evolving threats to classical confidentiality and practical constraints in implementing secure quantum protocols. This review synthesizes theoretical and experimental advances across QKD, device independence, networks, random generation, and quantum cryptographic primitives. It surveys progress toward practical systems while identifying implementation limitations and developments that address them.

  • Problem

    Classical cryptographic confidentiality may have a limited lifespan because intercepted communications can be stored for later decryption using future quantum or classical algorithms.

  • Method

    The review synthesizes theoretical and experimental advances across QKD, device independence, quantum networks, random-number generation, and beyond-QKD cryptographic primitives.

  • Results

    New developments improve practical quantum cryptography, including low-SNR error correction for long-distance CV-QKD and QDS over tens to hundreds of kilometers.

  • Takeaways & Limitations

    The surveyed advances move quantum cryptography toward practical communication primitives while retaining explicit device, detection, and side-channel constraints.

  • Takeaways & Limitations

    The review identifies the original GC-QDS protocol as highly impractical because of three major practical restrictions.

Abstract

from arXiv · show

Quantum cryptography is arguably the fastest growing area in quantum information science. Novel theoretical protocols are designed on a regular basis, security proofs are constantly improving, and experiments are gradually moving from proof-of-principle lab demonstrations to in-field implementations and technological prototypes. In this review, we provide both a general introduction and a state of the art description of the recent advances in the field, both theoretically and experimentally. We start by reviewing protocols of quantum key distribution based on discrete variable systems. Next we consider aspects of device independence, satellite challenges, and high rate protocols based on continuous variable systems. We will then discuss the ultimate limits of point-to-point private communications and how quantum repeaters and networks may overcome these restrictions. Finally, we will discuss some aspects of quantum cryptography beyond standard quantum key distribution, including quantum data locking and quantum digital signatures.

I. INTRODUCTION

The review introduces quantum cryptography as a response to threats to classical confidentiality and surveys QKD principles, security analyses, implementations, and long-distance limits. It covers discrete- and continuous-variable systems, device assumptions, post-processing, composability, and network-enabled approaches.

  • I. INTRODUCTION: Quantum computing and possible classical factorization advances threaten current public-key cryptosystems, including RSA.Stored encrypted communications may later be decrypted once sufficiently capable algorithms or hardware become available.
  • I. INTRODUCTION: Post-quantum cryptography offers a classical countermeasure, but the review describes it as partial and temporary because undiscovered algorithms might break new systems.
  • I. INTRODUCTION: QKD trades security, implementation demands, and key rate: device-independent protocols provide stronger security but extremely low rates, while trusted devices permit higher rates with side-channel exposure.
  • I. INTRODUCTION: For a lossy link with transmissivity η, point-to-point QKD is bounded by −log2(1 −η), scaling as 1.44η secret bits per channel use at long distance.Continuous-variable Gaussian-state protocols may approach this capacity, whereas discrete-variable protocols fall below it by additional factors.
  • I. INTRODUCTION: The review surveys discrete- and continuous-variable QKD, device-independent and measurement-device-independent protocols, finite-size security, composability, and quantum networks.Its scope is both theoretical and experimental and includes qubits or finite-dimensional systems alongside bosonic continuous-variable modes.
  • I. INTRODUCTION: A prepare-and-measure QKD protocol combines quantum communication with parameter estimation, error correction, privacy amplification, and sometimes basis-dependent sifting.Entanglement-based formulations replace state preparation with measurement on an entangled state and support security analysis and key-rate derivation.

1. BB84 protocol

BB84 encodes bits in non-orthogonal states across complementary bases, so eavesdropping creates detectable errors and uncertainty. Its security analysis yields an approximately 11% QBER threshold, while related protocols and implementations address practical source and attack constraints.

  • 1. BB84 protocol: BB84 uses four states in two complementary bases, with non-orthogonality preventing an eavesdropper from perfectly cloning or measuring the transmitted states.
  • 1. BB84 protocol: After publicly comparing measurement bases, Alice and Bob discard mismatched events and retain the matching outcomes as a sifted key.
  • 1. BB84 protocol: An eavesdropper’s measurement basis determines a trade-off between uncertainty in Alice’s Z- and X-basis encodings.Minimizing uncertainty in one basis maximizes uncertainty in the complementary basis.
  • 1. BB84 protocol: Eve’s basis mismatch creates errors: measuring in Z while Alice and Bob use X produces a 1/2 error rate in those instances.The intercept-resend strategy gives Eve information only when her basis matches Alice’s.
  • 1. BB84 protocol: 11% is the approximate maximum QBER for extracting a secret key under the stated symmetric collective-attack analysis.The same threshold is obtained for the most general coherent attacks and corresponds to R = 0.
  • 1. BB84 protocol: Practical DV-QKD must account for imperfect single-photon sources, multiple-photon emissions, dark counts, basis sifting, privacy amplification, and error correction.The effective rate includes the detected raw-key fraction and penalties from privacy amplification and error correction.

2. Decoy States

Decoy states let QKD users estimate single-photon properties despite multiphoton pulses, improving practical distance; related protocols and attack analyses define security thresholds and remaining limitations.

  • Decoy States: Decoy states enable QKD beyond a hundred kilometers despite implementation imperfections.Varying pulse intensities allows Alice and Bob to estimate single-photon quantities relevant to privacy amplification.
  • Decoy States: Alice and Bob use randomly varied intensities so Eve cannot identify which pulses carry key data, while linear equations estimate photon-number yields and error rates.The measured gains and QBERs across intensities provide solution sets for Y_i and e_i.
  • Decoy States: An infinite range of decoy states would be required for precise Y1 and e1 values, making finite implementations an important limitation.Experimental studies nevertheless demonstrated that decoy states can extend BB84 distance.
  • SARG04: SARG04 uses announced non-orthogonal state pairs and unambiguous state discrimination to limit photon-number-splitting attacks.Its security analysis supports QBER thresholds of 9.68% for single-photon and 2.71% for double-photon pulses.
  • Security and Practical Limits: Two-way protocols face distinct security and implementation constraints, including noisy attacks, device side channels, fragile direct communication, and unresolved tight security-rate bounds.Device-independent protocols avoid assumptions about device operation, while some attack strategies yield substantial information at detectable error rates.

C. Quantitative bounds

Device-independent QKD links observed CHSH violations to extractable randomness through entropy bounds and the entropy accumulation theorem. The reviewed protocol uses spot-checking, aborts when the CHSH value is too low, and extracts key from untested rounds.

  • Quantitative bounds: CHSH tests certify randomness by connecting a high observed violation to Alice’s smooth min-entropy conditioned on Eve.The security goal is to make simultaneous high CHSH values and failed key extraction unlikely.
  • Quantitative bounds: The entropy accumulation theorem extends one-round conditional von Neumann entropy bounds to general sequential adversaries.For n rounds, the total min-entropy is at least n times the one-round entropy, up to correction factors of order √n.
  • Quantitative bounds: Combining the CHSH-dependent entropy bound with the EAT yields roughly n times the corresponding amount of extractable uniform randomness.The conditional von Neumann entropy is evaluated as a function of the observed CHSH value.
  • Quantitative bounds: Tight entropy bounds are known for CHSH but remain an open problem for general non-local games, where semidefinite-program hierarchies can be loose.The reviewed CHSH bound relies on technical tricks specific to that scenario.
  • Protocol: The spot-checking protocol uses mostly key-generation rounds and randomly selected CHSH-test rounds, aborting when the average falls below β −δ.Users choose α, n, β, and δ before execution; the EAT then determines key extraction after error correction.
  • Protocol: For an ideal implementation, the completeness error is exponentially small in the number of rounds.Abort occurs when statistical fluctuations reduce the observed CHSH value below β −δ.

E. Historical remarks

The review traces device-independent and measurement-device-independent QKD from Bell-based security ideas to practical relay-based implementations. It also situates twin-field QKD as a protocol that beats the repeaterless point-to-point bound while remaining below the ideal-repeater capacity.

  • Historical remarks: Ekert’s protocol introduced entanglement into QKD, while later self-checking work enabled security without trusting the devices.The first fully security-proven protocol in this line was due to Barrett, Hardy, and Kent.
  • Device independence: DI-QKD proves security from collected Bell-violating data without specifying a mathematical model for the devices.Its conceptual strength comes with limited attainable key rates.
  • Measurement device independence: MDI-QKD removes assumptions about the detectors by sending trusted users’ signals to a potentially malicious central relay.Alice and Bob retain control of the states they prepare, while the relay may be controlled by Eve.
  • Measurement device independence: Ideal Bell detection induces strong sifted correlations between Alice’s and Bob’s locally prepared bits while revealing only their relation, not the bit values.The Bell outcome determines whether Bob should flip his bit to match Alice’s.
  • Measurement device independence: Linear-optics Bell detection realizes only two of four POVM elements, introducing nondeterminism that reduces the secret-key rate.Practical implementations replace single photons with phase-randomized attenuated coherent states.
  • Twin-field QKD: Twin-field QKD overcomes MDI-QKD’s inability to beat the PLOB bound, with rates also approaching the single-repeater bound.A finite phase-slice choice of M = 16 was estimated to give an intrinsic QBER of approximately 1.28%.

A. Detector technology

Detector capabilities and photonic integration shape QKD’s achievable rate, distance, dimensionality, and deployment practicality. Demonstrations span record-distance links, high-dimensional encoding, and integrated transmitters and receivers.

  • Detector-limited QKD: 13.72 Mb/s is the highest reported QKD key rate in the short-distance detector-saturation regime.At distances up to approximately 100 km, detector dead time limits the rate; additional detectors or higher-dimensional alphabets are proposed to increase it.
  • High-dimensional QKD: High-dimensional QKD reaches 7.4 secret bits per detected photon and secret key rates of 23 Mbps and 26.2 Mbps in temporal-spectral demonstrations.A 43-km field demonstration achieved a maximum secret key generation rate of 1.2 Mbps, while OAM demonstrations reached 2.05 bits per sifted photon and 0.65 bits per detected photon.
  • High-dimensional QKD: High-dimensional OAM QKD remains constrained by encoding and decoding devices that reconfigure much more slowly than multi-gigahertz electro-optic modulators.Reported switching times include 20 µs for thermo-optic ring resonators and 2.5 µs for on-chip MEMS actuation.
  • Photonic integrated circuits: Photonic integrated circuits combine compact, stable, high-speed QKD operations and support wavelength multiplexing, heterogeneous integration, and multiple protocol implementations.An InP transmitter with a TriPleX receiver demonstrated multiple time-bin protocols at 1 GHz, while silicon photonics enabled polarization QKD over a 43-km intercity link.

2. Low-Earth-orbit (LEO)

LEO satellites offer relatively accessible platforms for space-based quantum communication, enabling demonstrations over moving, long-distance links while imposing short contact windows and severe Doppler shifts. Experiments progressed from reflected single-photon simulations to operational satellite QKD and tests of entanglement and other quantum phenomena.

  • LEO characteristics: LEO was initially favored because its low altitude eases launch and reduces exposure to ionizing radiation.Orbits below 2000 km also provide rapid one-to-two-hour round trips and broad coverage opportunities.
  • LEO limitations: A LEO ground-station pass lasts only a few minutes, while satellite speeds can reach 7 km/s and produce Doppler shifts of tens of GHz.The stated example is a 400-km orbit such as the ISS.
  • Early demonstrations: Satellite demonstrations used reflected 100 MHz qubit pulses at the single-photon level and 10 Hz bright laser-ranging pulses for synchronization.The reflected pulses mimicked a QKD source during the demonstration.
  • Satellite experiments: Micius enabled ground-to-satellite quantum experiments, including teleportation with average fidelity 0.80 ± 0.01 and decoy-BB84 key rates exceeding 10 kbps.Its payload could generate, transmit, and measure quantum states.
  • Satellite experiments: Micius demonstrated entanglement-based QKD over about 1200 km, but channel losses reduced the key rate to roughly half a bit per second.The demonstration used an entangled-photon downlink between Delingha and Lijiang.
  • Tests of quantum mechanics: The Micius experiment observed CHSH violation with S = 2.37 ± 0.09, exceeding the local-reality limit of 2 by four standard deviations.The result tested quantum nonlocality between ground stations separated by 1200 km.

F. Finite-size aspects

Two-way CV-QKD introduces ON/OFF configurations that adapt the protocol to different attack correlations and can raise security thresholds in noisy channels. Its analyses include asymptotic Gaussian attacks, while finite-size and composable-security treatments address practical implementations and performance limits.

  • Protocol structure: Two-way CV-QKD uses the insecure channel twice, with Bob sending a reference state that Alice encodes before returning it for measurement.The scheme can improve robustness to excess noise, but its quantum communication is round-trip.
  • Protocol structure: ON and OFF configurations provide an additional control choice: ON suits memoryless round-trip attacks, whereas OFF suits attacks with inter-channel memory.The parties publicly compare a data fraction to estimate round-trip transmissivity and noise.
  • Security analysis: Two-way security analyses reduce general coherent attacks to two-mode Gaussian attacks in the asymptotic regime using random permutations and Gaussian-state descriptions.The treatment bounds Eve’s accessible information through the Holevo quantity.
  • Security analysis: Setting R = 0 gives two-way security thresholds higher than those of corresponding one-way protocols, making them suitable for channels with high thermal noise.The review identifies THz and microwave channels as relevant examples.
  • Security analysis: Two-way CV-QKD security was initially analyzed asymptotically, while composable security was later proven for these protocols.The review also notes extensions involving optical amplifiers and other two-way schemes.
  • Protocol variants: For coherent-state homodyne protocols, the asymptotic rate is approximately (η log2 e)/3, compared with (η log2 e)/2 for standard one-way coherent-state homodyne detection.The stated comparison concerns the relevant UD CV-QKD and standard one-way protocol limits.

1. Basic concepts and protocol

CV-QKD and MDI-QKD implementations translate quantum states into measured correlations, while post-processing and security analysis determine whether those correlations yield a secret key. Experimental progress improved rates and distance, but finite-size estimation and hardware realism remain important constraints.

  • MDI-QKD: In CV MDI-QKD, Alice and Bob send Gaussian-modulated coherent states to an untrusted relay, which performs a continuous-variable Bell measurement and broadcasts its result.The broadcast creates correlations that let each party infer the other’s variable without trusting the relay’s measurement device.
  • MDI-QKD: Under ideal asymmetric conditions, CV MDI-QKD can reach about 170 km with a key rate of 2 × 10^-4 bit/use.The stated case has ηA = 1 and arbitrary ηB in standard fiber with 0.2 dB/km attenuation.
  • Experimental progress: Telecom-compatible CV-QKD systems achieved up to 1 Mbps over 25 km and around 300 bps over 100 km after introducing telecom components, improved error correction, and active stabilization.These innovations addressed wavelength compatibility, mechanical stability, and processing limitations of earlier systems.
  • Post-processing: Low-SNR reconciliation reached 96% efficiency at SNR = 0.08 over 80 km and 95.6% at SNR = 0.002 over 150 km.The review attributes these advances to high-efficiency error-correcting codes operating below the SNR range of earlier systems.
  • Post-processing: Multi-edge LDPC codes combined with multidimensional reconciliation produced throughputs of 25 Mbit/s and 30 Mbit/s, though parameter estimation remains a major distance-limiting factor.The reported decoder speeds were not yet compatible with clock rates above 100 MHz.
  • Finite-size constraints: Finite-size effects can eliminate key extraction: reducing an 80-km experiment’s block size from 10^9 to 10^8 produced no key.Longer distances require larger blocks, greater system stability, higher clock rates, and higher detector bandwidth.

B. Finite-size statistical analysis

Finite-size security reduces practical key extraction to bounding the smooth min-entropy of corrected raw keys from observed data. The review surveys several proof techniques and highlights both successful continuous-variable approaches and remaining hardware-model and device-independent limitations.

  • Security framework: Composable finite-size security first requires a sufficiently strong lower bound on the smooth min-entropy of Alice and Bob’s corrected raw key conditioned on Eve.Privacy amplification then converts the bounded raw key into a secret key.
  • Privacy amplification: Random two-universal hashing extracts a shorter secret key from a raw key with partial eavesdropper information, including when Eve has quantum memory.The hashing seed is independent of the resulting random bit string.
  • Proof techniques: Finite-size proofs use asymptotic equipartition with de Finetti or post-selection, virtual entanglement distillation, and entropic uncertainty relations with side quantum information.The techniques replace or bound smooth min-entropy through state estimation, code-based interpretations, or correlations between users’ keys.
  • Continuous-variable limitations: For infinite-dimensional systems, exponential de Finetti and post-selection approaches fail without additional assumptions, whereas entropic uncertainty methods provide tight finite-key characterizations for certain squeezed-state protocols.The supported example uses TMSV states measured by homodyne detection.
  • Open problems: Security proofs must better match implemented quantum hardware because mismatches can leave vulnerabilities to side-channel attacks.The review calls for closer collaboration between theorists and experimentalists to narrow the gap between realistic implementations and provable security.
  • Open problems: Device-independent QKD reduces assumptions about devices, but its ultimate achievable finite-key rates remain undetermined.State-of-the-art analyses rely on entropy accumulation and have recently been improved.
  • Side-channel security: Trojan-horse analyses identify coherent states as optimal Gaussian attack states under stated constraints and show that added thermal noise can reduce distinguishability.Other countermeasures include passively limiting leakage using the fiber’s laser-induced damage threshold.

2. Saturation attacks on detectors

The review describes detector and device side-channel attacks in QKD, alongside countermeasures and broader security trade-offs. It also situates these vulnerabilities within rate limits and approaches such as device-independent QKD.

  • Saturation attacks on detectors: Homodyne-detector saturation attacks exploit the finite linearity range assumed away by CV-QKD security proofs.Above a threshold, different quadrature values can produce the same measurement result.
  • Countermeasures: Gaussian post-selection, random signal attenuation, and active monitoring are proposed to detect or mitigate detector and Trojan-horse attacks.These measures respectively restrict key-generation data, test linearity, or monitor incoming light.
  • Device side channels: Trojan-horse attacks target encoding devices by extracting modulation information through injected states or leakage modes.CV analyses model leakage with beamsplitters, untrusted noise, or bounded-energy Trojan states.
  • Device independence: Device-independent QKD permits untrusted devices but is harder to implement, generally has lower key rates, and still requires isolation from external access.MDI-QKD reduces measurement-device trust requirements but remains vulnerable to source imperfections.
  • Rate limits: The PLOB capacity −log2(1 −η) ≃ 1.44η secret bits per channel use is an upper limit for point-to-point QKD over a lossy link.Point-to-point protocols cannot beat this bound; repeaters or pre-shared randomness are required to outperform it.

D. LOCC simulation of quantum channels

The review formulates quantum-channel simulation through LOCC operations and resource states, including asymptotic limits. This framework enables protocol stretching and single-letter capacity bounds, while some channels still lack useful non-asymptotic simulations.

  • LOCC simulation: An arbitrary quantum channel can be simulated by applying an LOCC operation to the input state and a resource state.The simulation may be represented as E(ρ) = T(ρ ⊗ σ).
  • Asymptotic simulation: Asymptotic simulation approximates a channel with sequences of LOCCs and resource states whose point-wise limit defines the target channel.This generalization is important for bosonic and some discrete-variable channels.
  • Limitations: For the amplitude-damping channel, only asymptotic simulations are known, leaving its secret-key capacity unknown and non-asymptotic simulation open.Known constructions require limits in Hilbert-space dimension or resource-state size.
  • Teleportation covariance: Teleportation-covariant channels admit teleportation simulation using an LOCC and the channel’s Choi matrix as resource state.The family includes Pauli, erasure, and bosonic Gaussian channels.
  • Protocol stretching: Protocol stretching reduces arbitrary adaptive communication, entanglement-distribution, or key-generation protocols to block protocols while preserving the original task.Combining stretching with relative entropy of entanglement yields single-letter upper bounds for two-way capacities.

J. Capacities for distillable channels

For distillable channels, one-way entanglement distillation rates coincide with secret-key and other two-way capacities, yielding exact formulas for several fundamental channels and repeater chains. Open gaps remain for important non-distillable channels.

  • Capacity equalities: Distillable channels satisfy D1(σE) = D2(E) = Q2 = K = P2, so their two-way capacities are fully established.The equality follows because D1(σE) is a lower bound to D2(E) and coincides with the relevant achievable rates.
  • Capacity equalities: Two-way capacities for these channels can be achieved through rounds of one-way classical communication without adaptiveness.The amount of classical communication is limited.
  • Fundamental channels: Simple formulas are obtained for pure-loss, quantum-limited amplifier, dephasing, and erasure channels.The review identifies all four as distillable channels.
  • Open problems: Secret-key capacity gaps remain open for thermal-loss, noisy-amplifier, additive-noise Gaussian, depolarizing, and amplitude-damping channels.Possible improvements include refined relative-entropy calculations and better channel simulations.
  • Repeater chains: For a repeater chain of distillable channels, the secret-key capacity equals the minimum channel capacity among its links.For pure-loss chains, the capacity is therefore determined by the minimum transmissivity.
  • Quantum networks: In lossy networks, optimal multi-path routing is formulated as a maximum-flow problem and generally outperforms single-path routing.Orlin’s algorithm finds the routing in O(|P|× |E|) time.

D. Practical designs for quantum repeaters

Quantum repeaters extend entanglement across long distances by nested swapping, but probabilistic operations, accumulated errors, memory coherence, and demanding hardware constrain practical designs. Multiple memories and advanced repeater architectures can improve rates while introducing further implementation requirements.

  • Nested repeaters: Entanglement swapping extends an elementary link of length L0 to 2L0, and repeated nesting can extend it over still longer distances.A Bell-state measurement at an intermediate node entangles the two outer systems.
  • Nested repeaters: Nested distribution is more efficient than attempting transmission over the full distance because elementary-link success scales as exp(−αL0).Direct transmission over the total distance would have an exponentially worse success rate.
  • Practical constraints: Probabilistic Bell-state measurements require waiting for earlier outcomes, slowing the process and imposing more demanding memory-coherence requirements.In the nesting-level-2 example, BSM2 waits for the middle node to learn whether BSM1 succeeded.
  • Probabilistic repeaters: A bank of N memories enables repeated elementary-link attempts and informed swapping, generating roughly NPSP nM end-to-end entangled states per period for N ≫1.The generation time is roughly T = L/c, reducing memory-coherence requirements; PS and PM denote elementary-link and BSM success probabilities.
  • Probabilistic repeaters: Memory-assisted QKD with one probabilistic repeater can improve rate-versus-distance scaling over conventional QKD at long distances.The review attributes this possibility to existing quantum-memory technologies.
  • Practical constraints: Repeater performance is limited by the trade-off between more nesting levels, higher elementary-link success, and fewer nesting levels with less accumulated error.Imperfect states and operations may require entanglement distillation, increasing computational cost and implementation difficulty.
  • Memory-less repeaters: Memory-less repeaters require operation errors of 10−4−10−3, large photonic cluster states, advanced photon sources, and many intermediate nodes.These requirements may conflict with sparsely located nodes in existing optical networks.

E. Quantum data locking for communication: the quantum enigma machine

Quantum data locking exploits limited eavesdropper information to separate accessible information from other information measures, while related randomness protocols address imperfect randomness sources. These approaches offer strong theoretical effects but face security assumptions and substantial implementation challenges.

  • Quantum data locking: Weak QDL capacity is never smaller than private capacity, while entanglement-breaking and Hadamard channels have vanishing weak QDL capacity.Some channels exhibit a large gap between private capacity and weak QDL capacity.
  • Experimental challenges: Current QDL protocols require coherent control over asymptotically large Hilbert spaces, making experimental realization impractical without smaller-dimensional and noise-robust designs.The review identifies both requirements as necessary for feasible demonstrations.
  • Randomness amplification: Quantum randomness amplification can work for every ε < 1/2, including sources with arbitrarily little initial randomness.The current state of the art includes a two-device protocol that tolerates noise for all ε < 1/2.
  • Randomness amplification: Protocols against arbitrary no-signalling adversaries tend to lack efficiency because randomness extraction is difficult in that adversarial model.Several protocols nevertheless provide security against post-quantum adversaries limited only by no-signalling.
  • Randomness amplification: Randomness amplification can use a public random seed, allowing users to increase trust in outputs from an imperfect randomness beacon.This property holds for many reviewed protocols, except the protocol of Ref..

XV. QUANTUM DIGITAL SIGNATURES

Quantum digital signatures extend digital-signature functionality with quantum communications and information-theoretic security. The review traces QDS definitions, the Gottesman–Chuang scheme, its practical restrictions, and developments that lifted them.

  • Overview: QDS provides authenticity, integrity, and non-repudiation for digital messages through a sender and potentially multiple receivers.A QDS scheme is organized into key generation, signing, and verification phases.
  • Overview: The sender uses a private key to generate a signature, while receivers obtain public quantum keys during key generation.The signing phase sends the message together with its signature to the intended receiver.
  • The Gottesman–Chuang scheme: The Gottesman–Chuang protocol uses non-orthogonal quantum states as a quantum one-way function whose inversion is prevented by quantum mechanics rather than computational assumptions.Unknown quantum states cannot be perfectly distinguished or assigned their classical descriptions with certainty.
  • Security properties: QDS security separates forging, repudiation, and honest-rejection probabilities through thresholds satisfying 0 < pe < sa < sv < pf.The associated undesirable-event probabilities decrease exponentially with signature length under the stated threshold conditions.
  • Practical restrictions: The original scheme required quantum public keys to be stored, compared using multiple copies and controlled SWAP tests, and transmitted over authenticated quantum channels.These requirements introduced substantial memory, communication, gate, ancilla, and authentication costs.
  • Practical progress: Four major developments lifted the original restrictions and transformed QDS from a theoretical proposal into a practical quantum communication primitive.Coherent-state comparison replaces the SWAP test with beam splitters, mirrors, and photon detectors, while later work addressed other assumptions.

3. QDS from QKD technology

Modern QDS protocols adapt techniques from QKD to remove quantum-memory and authenticated-channel assumptions while retaining security properties. The review highlights practical ranges, scaling trade-offs, and comparisons with classical information-theoretically secure signatures.

  • Modern QDS protocols: Symmetrization ensures that receivers’ classical verification keys remain symmetric even when Alice distributes different quantum states.Sending different states also limits forging attacks because forgers lack copies of the full legitimate quantum public key.
  • Performance: QDS can operate at channel-error rates higher than those tolerable for QKD, allowing signatures where QKD is experimentally infeasible.This comparison is reported for the protocol of Ref..
  • Modern QDS protocols: Modern QDS can avoid quantum memory, use QKD-compatible technology, and make no assumption about the quantum channels.The generic protocol description is given for three parties but can be generalized to more.
  • Security and optimization: Forging, repudiation, and honest abort probabilities decrease exponentially with signature length when thresholds are chosen relative to pe, pf, sa, and sv.The practical error rate pe depends on the channel and experimental setup and increases with distance.
  • Scaling: Most QDS protocols require a quadratic number of communication channels, although some constructions demonstrate linear scaling with quantum channels.Multi-party settings also require consideration of collusion and repeated message transfers.
  • Experimental progress: Decoy states and related improvements enabled QDS over tens to hundreds of kilometers, while MDI-QDS was implemented over a metropolitan network and at high rates.These developments brought QDS closer to QKD in practicality.
  • Comparison with classical schemes: QDS offers information-theoretic security but lacks universal verifiability, and a classical universal-signature scheme can be more efficient for long messages.The cited classical construction has similar guarantees and cost while scaling exponentially better with message length.
  • Outlook: The review presents QDS developments that transformed the primitive from a theoretical observation into a practical possibility within broader quantum-cryptography advances.The field still faces challenges including robust long-distance QKD at reasonably high rates and practical quantum repeaters.

Appendix A: Formulas for Gaussian states

The appendix reviews phase-space and symplectic tools for multimode Gaussian states, including basis-independent calculations of Gibbs matrices and information-theoretic quantities. It also summarizes closed-form fidelity methods and their computational advantages.

  • Appendix A: Formulas for Gaussian states: Multimode Gaussian states are described by quadrature operators, a symplectic form, first moments, and a covariance matrix.Different groupings of quadratures are valid when the grouping and symplectic matrix are chosen consistently.
  • Appendix A: Formulas for Gaussian states: Williamson’s theorem decomposes a covariance matrix using a symplectic matrix and symplectic eigenvalues, with purity determined by their minimum values.The vacuum-noise convention changes whether pure-state eigenvalues are 1/2 or 1.
  • Appendix A: Formulas for Gaussian states: Gaussian-state quantities can be computed algebraically from first and second moments through an operator-exponential representation involving the Gibbs matrix.The relations are basis independent and allow direct calculation of G from V without symplectic diagonalization.
  • 1. Symplectic action and its computation: The symplectic action extends ordinary functions to matrices with symplectic structure by applying the function to symplectic eigenvalues.Matrix-function implementations make the resulting numerical or symbolic calculations convenient.
  • 1. Symplectic action and its computation: Full symplectic diagonalization remains difficult because closed formulas for the diagonalizing matrix are known only for specific two-mode Gaussian states.The symplectic spectrum itself is easier to compute than the matrix performing the diagonalization.
  • 2. Fidelity between arbitrary Gaussian states: Fidelity quantifies similarity between quantum states, and a general closed form for arbitrary multimode Gaussian states uses their covariance matrices and first moments.The formulation derives the result through Gibbs matrices, operator square roots, auxiliary matrix functions, and covariance-matrix expressions.
  • 2. Fidelity between arbitrary Gaussian states: Gaussian-state fidelity supports quantum-state discrimination, where fidelity-based bounds can estimate the minimum error probability for multiple copies.The exact Helstrom bound has no closed form for Gaussian states in the cited discussion.
  • 3. Entropic quantities: Entropic quantities can be calculated directly from statistical moments without full symplectic diagonalization.This avoids reliance on symplectic matrices whose closed forms are available only in limited cases.
Loading 1906.01645v1…