Source-linked AI summary
Limits and Security of Free-Space Quantum Communications
Stefano Pirandola
TL;DR
Free-space quantum links need rate and security analysis that accounts for diffraction, extinction, turbulence, pointing errors, fading, and noise. The paper combines quantum-information, optical, and turbulence tools with composable finite-size analysis for coherent-state protocols. It finds that pilot-guided, post-selected protocols can achieve secret-key rates sufficiently close to ultimate limits, supporting high-rate free-space QKD.
Problem
Free-space quantum communications lack fully developed theoretical limits and rigorous security analysis under the diffraction, extinction, turbulence, pointing, fading, and noise effects typical of free-space links.
Method
The paper combines quantum information theory, optics, and turbulence theory to bound key and entanglement rates and develops composable finite-size security analysis for coherent-state protocols across stable and fading channels.
Results
Pilot-guided, post-selected coherent-state protocols achieve high secret-key rates within one order of magnitude of ultimate bounds under weak turbulence.
Takeaways & Limitations
The results show that free-space channels can support high-rate quantum-secured communications.
Abstract
from arXiv · showhide
The study of free-space quantum communications requires tools from quantum information theory, optics and turbulence theory. Here we combine these tools to bound the ultimate rates for key and entanglement distribution through a free-space link, where the propagation of quantum systems is generally affected by diffraction, atmospheric extinction, turbulence, pointing errors, and background noise. Besides establishing ultimate limits, we also show that the composable secret-key rate achievable by a suitable (pilot-guided and post-selected) coherent-state protocol is sufficiently close to these limits, therefore showing the suitability of free-space channels for high-rate quantum key distribution. Our work provides analytical tools for assessing the composable finite-size security of coherent-state protocols in general conditions, from the standard assumption of a stable communication channel (as is typical in fiber-based connections) to the more challenging scenario of a fading channel (as is typical in free-space links).
I. INTRODUCTION
Free-space quantum communications require analysis beyond fiber-based channels because diffraction, extinction, turbulence, pointing errors, and noise jointly affect performance. The paper combines quantum information, optical, and turbulence tools to bound ultimate rates and assess composable coherent-state QKD, including fading channels.
- Motivation: Free-space quantum channels remain theoretically under-developed because diffraction, atmospheric extinction, turbulence, and pointing errors complicate rigorous limits and security assessment.The paper motivates hybrid architectures that combine fixed ground-station fiber links with mobile-device free-space links.
- Ultimate limits: The analysis establishes upper and lower bounds on secret-key and entanglement-distribution rates while accounting for channel fading and background noise.The treatment focuses mainly on weak turbulence and discusses extensions to stronger fluctuations.
- Composable security: The paper develops composable finite-size security analysis for coherent-state CV-QKD from stable channels to free-space fading channels.The framework addresses both fiber-like stable communication and the more challenging nonstationary free-space setting.
- Achievable rates: Pilot-guided, post-selected coherent-state protocols achieve high secret-key rates within one order of magnitude of ultimate bounds under weak turbulence.This result supports high-rate QKD over generally turbulent free-space channels.
- Physical limits: Diffraction-limited bounds depend on receiver aperture and beam spot size, with focused beams optimal but typically restricted to short distances and collimated beams more broadly applicable.The bound is presented as a simple baseline before adding extinction, setup loss, turbulence, pointing errors, and noise.
- Channel impairments: Atmospheric propagation introduces extinction through absorption and scattering, while turbulence and pointing errors produce beam broadening and centroid wandering on distinct time scales.The treatment uses atmospheric density and extinction models together with turbulence-theory parameters and detector-resolvable wandering dynamics.
2. Incorporating short-term effects and deflection
The channel model replaces diffraction-limited transmissivity with a short-term, deflection-dependent transmissivity and then treats beam wandering as fading. This yields capacity bounds that remain valid with thermal noise, with achievability in the pure-loss case and tighter bounds when noise matters.
- Short-term effects and deflection: Turbulence changes the diffraction-limited transmissivity ηd into a short-term transmissivity ηst determined by the broadened beam waist wst.The short-term beam is additionally affected by deflection from the receiver aperture center.
- Beam wandering: Gaussian centroid wandering makes τ fluctuate below its maximum η, inducing a fading channel described by an ensemble of instantaneous channels with distribution P0(τ).The deflection r is modeled through a Weibull distribution, which induces the corresponding transmissivity distribution.
- Short-term effects and deflection: The instantaneous link transmissivity is τ(r)=ηst(r)ηatmηeff, where r measures the beam-centroid deflection from the receiver aperture center.The receiver also collects thermal background and setup-generated excess noise.
- Capacity bounds: The main capacity formula bounds both secret-key and entanglement-distribution rates for free-space loss involving diffraction, extinction, setup loss, turbulence, and pointing errors.For negligible thermal noise, the bound is achievable and reduces to the diffraction-only result when extinction and setup loss are also absent.
- Thermal noise: Thermal noise preserves the loss-based upper bound but can prevent achievability, motivating tighter upper and lower bounds for noisy fading channels.When noise becomes comparable to the maximum transmissivity, the upper bound can reach zero, implying a maximum security distance for free-space QKD.
E. Analysis of the ultimate bounds
The bounds depend strongly on receiver noise, background conditions, filtering, and aperture size. Narrow filtering can suppress thermal noise, while aperture optimization balances transmissivity against added noise.
- Thermal noise creates a gap between the loss-based upper bound and thermal bounds, with untrusted setup noise important at night and background noise added during daytime.Daytime rates are further degraded by stronger turbulence and non-negligible background photons.
- For a noiseless receiver, the thermal bounds coincide with the loss-based bound at night but remain separated during the day because of external background noise.
- Daytime performance is optimized at an intermediate receiver aperture because increasing aR simultaneously raises transmissivity and thermal noise.For the stated regime, the optimum is around aR ≃10 cm at z = 1 km.
- A narrow filter of ∆λ = 0.1 pm increases daytime thermal bounds and can make them collapse into the loss-based bound for a noiseless setup.The filtering reduces effective bandwidth and makes ¯n ≃0 in the stated case.
- Slow detection reduces bits-per-second throughput because integration smooths fading but sharply lowers the system clock and can increase daytime background noise.A 100 MHz detector supports about 3.3 × 10^7 uses per second, whereas 100 ms detection gives about 3.3 uses per second.
2. Intermediate and strong turbulence
The analysis extends free-space quantum-communication bounds beyond weak turbulence by using long-term spot sizes and accounting for detector averaging. Practical CV-QKD security is formulated for both stable and fading channels.
- 2. Intermediate and strong turbulence: The long-term spot size remains robust across turbulence regimes, including cases where the beam breaks into multiple patches.
- 2. Intermediate and strong turbulence: This robustness supports extending upper bounds beyond weak turbulence, including intermediate-strong regimes characterized by σ^2_Rytov ≃1.
- 2. Intermediate and strong turbulence: For strong turbulence with negligible pointing error, the strong-turbulence capacity bounds can retain a high system clock because they do not arise from operationally reducing detection time.
- 2. Intermediate and strong turbulence: The composable-security framework covers stable channels and is then extended to fading channels relevant to free-space, ground, and satellite communications.
3. Setup noise versus channel transmissivity
The practical CV-QKD analysis models receiver imperfections as untrusted and derives composable finite-size rates through parameter estimation. The framework uses Gaussian-modulated coherent states and supports homodyne or heterodyne detection.
- 3. Setup noise versus channel transmissivity: Setup noise includes local-oscillator, electronic, and other independent contributions, and its dependence on transmissivity differs between transmitted and local oscillators.
- 3. Setup noise versus channel transmissivity: The protocol models channel loss, background noise, receiver efficiency, and setup noise, with Eve controlling leakage and thermal noise in the worst-case scenario.
- 3. Setup noise versus channel transmissivity: The composable key rate is evaluated from mutual information and Eve’s Holevo information, with realistic reconciliation efficiency β accounting for imperfect post-processing.
- 3. Setup noise versus channel transmissivity: Finite-size parameter estimation lowers the rate because Alice and Bob must use conservative estimates of transmissivity and thermal noise.
- 3. Setup noise versus channel transmissivity: Alice and Bob estimate channel parameters from a randomly disclosed subset of signals, using estimators whose uncertainties are characterized through Gaussian and chi-square statistics.
2. Worst-case estimators
Alice and Bob use finite-sample estimators and confidence intervals to obtain worst-case bounds for transmissivity and thermal noise. Gaussian approximations work at typical error probabilities, while tail bounds are needed for extremely small εpe.
- Gaussian confidence estimates: Alice and Bob estimate transmissivity and thermal noise from sampled channel data, then construct worst-case estimators using confidence intervals.The bounds account for an acceptable parameter-estimation error probability εpe.
- Gaussian confidence estimates: 2εpe approximately gives the combined estimation error for transmissivity and thermal noise.The two parameters contribute separate error events, yielding an approximately doubled total error.
- Gaussian confidence estimates: εpe = 2^-33 corresponds to confidence parameter w approximately 6.34 under the Gaussian treatment.This value is used for the typical parameter-estimation setting described in the section.
- Tail bounds: For εpe ≤ 10^-17, the Gaussian approach diverges because w tends to infinity, so suitable tail bounds are required.The tail-bound treatment also supports smaller error probabilities, including εpe = 10^-43 with w approximately 14.
- Composable security: The resulting worst-case estimates enter the composable finite-size key-rate analysis together with parameter-estimation, error-correction, and privacy-amplification imperfections.The key-rate formulation is given for Gaussian-modulated coherent-state protocols and includes the success probability of error correction.
F. Key rate under general coherent attacks
The paper extends security against collective Gaussian attacks to general coherent attacks by symmetrizing the heterodyne protocol and applying energy tests. In fading channels, pilot pulses enable transmissivity tracking, while filtering suppresses background noise.
- General coherent attacks: The collective-Gaussian key-rate result is extended to general coherent attacks using protocol symmetrization and an additional privacy-amplification step.The extension applies to the heterodyne coherent-state protocol and modifies both the rate and security parameter.
- General coherent attacks: Symmetrization applies identical random orthogonal transformations to the parties’ classical continuous variables and is compatible with heterodyne detection.The protocol is then subjected to an energy test on randomly selected mode pairs.
- General coherent attacks: Choosing energy-test thresholds near the transmitter’s mean thermal photon number makes the test success probability approximately one for sufficiently many tested modes.For the considered lossy channel, the receiver threshold can be chosen equal to the transmitter threshold.
- General coherent attacks: The finite-size coherent-attack extension requires very small initial security, such as ε approximately 10^-43, so that the final security remains well below one.The corresponding confidence parameter must therefore be computed using the tail-bound expression.
- Fading-channel implementation: Pilot pulses track instantaneous transmissivity in fading channels, allowing signals to be grouped into nearly equal-transmissivity bins for de-fading.Bright pilots can provide practically perfect transmissivity estimates with mP approximately O(1) in the relevant regime.
- Fading-channel implementation: Interferometric local-oscillator filtering narrows the effective receiver bandwidth from 1 nm to 0.1 pm and suppresses external background noise.The filtering remains secure provided frequency cross-talk outside the local-oscillator bandwidth is negligible.
D. De-fading
De-fading maps post-selected data from fluctuating transmissivity slots to the minimum transmissivity, producing a stable thermal-loss representation for security analysis. The resulting channel supports worst-case parameter estimation and lower-bounded key-rate calculations.
- Data transformation: De-fading eliminates or reduces transmissivity fluctuations by mapping all post-selected data to the minimum transmissivity in the selected interval.The procedure uses the minimum transmissivity and provides an achievable lower bound for the secret-key rate.
- Data transformation: Bob rescales each slot’s data by τmin/τk, but this can reduce the effective noise below the minimum allowed by the final quantum measurement.A further classical Gaussian-noise step resolves this issue.
- Channel representation: The completed slot-dependent transformation is equivalent to a beam-splitter channel followed by the original thermal-loss channel.The composite channel is written as Fk := Ck ◦ Ek for each slot.
- Channel representation: Gaussianification replaces the resulting non-Gaussian channel with a thermal-loss Gaussian channel having the same minimum transmissivity and thermal number for worst-case analysis.This yields an asymptotic key-rate lower bound based on the post-processed variables.
- Parameter estimation: Signal parameter estimation is needed in addition to pilot tracking because an adversary may distinguish pilots from signals and impose different transmissivity or noise.The parties estimate the signal-derived minimum transmissivity and noise and use the corresponding worst-case values.
- Parameter estimation: The de-faded channel is characterized by worst-case estimators for τmin and thermal number n̄G, with confidence controlled by εpe.The total estimation error for the two worst-case estimators is approximately 2εpe.
G. Composable key rate for free-space CV-QKD
The free-space protocol post-selects and de-fades pilot-tracked signals, then applies composable finite-size security analysis to obtain rates against collective Gaussian and general coherent attacks. In weak turbulence, the achievable rates approach the ultimate loss-based bound within one order of magnitude.
- Protocol construction: Pilot-guided post-selection selects signals with transmissivity between τmin = fthη and τmax = η, after which de-fading maps them to τmin.The post-selected signals are processed through a thermal-loss channel with transmissivity τmin and thermal number n̄G.
- Composable rate: The finite-size rate includes parameter estimation, error correction, privacy amplification, and composable security terms for the post-selected data.The rate is ε-secure against collective Gaussian attacks with ε = 2pecεpe + εcor + εsec.
- Composable rate: General coherent-attack security adds symmetrization and energy tests, reducing the key-generation block through the extra tested modes.The final block uses n = N − (m + mP + met) modes before the protocol’s prefactors are applied.
- Numerical performance: In most of the weak-turbulence range, collective-attack rates lie within one order of magnitude of the ultimate loss-based upper bound.Fixed threshold and modulation values are compared with distance-wise optimization over fth and µ, which substantially improves performance.
- Numerical performance: Against general attacks, the rates are not far from collective-attack results, with final security ranging from approximately 1.38 × 10^-11 to 1.32 × 10^-9 for the stated settings.The values correspond respectively to LLO at z = 1066 m and TLO at z = 200 m.
- Throughput caveat: The reported Fig. 6 rates are bits per quantum-channel use and exclude local-oscillator reference pulses; LLO throughput is therefore halved unless both signal polarizations compensate it.Using both polarizations can fully compensate the LLO factor of 1/2.
- Conclusions: The study establishes ultimate bounds under diffraction, extinction, pointing errors, turbulence, and thermal background while deriving achievable composable CV-QKD rates close to those bounds.The analysis treats weak turbulence and extends the results to stronger turbulence.
Appendix A: Propagation of Gaussian beams
The appendix models quasi-monochromatic Gaussian-beam propagation under scalar and paraxial approximations, deriving diffraction, mode-transmission, and finite-aperture effects. It also specifies transmitter-aperture conditions that preserve the Gaussian profile.
- Gaussian-beam model: Gaussian beams provide an analytical eigensolution for paraxial free-space propagation, with field spot size, curvature, and phase evolving along distance z.The beam is represented by a slowly varying transverse field amplitude satisfying the Fresnel-Kirchhoff integral.
- Beam propagation: In the far field, the beam spot size grows linearly with z and the divergence angle is approximately θ ≃ λ/(πw0).The far-field diffraction term dominates the initial spot-size contribution.
- Finite-aperture diffraction: A finite receiver aperture produces diffraction-induced transmissivity by collecting only part of the spread Gaussian beam.The transmissivity is obtained by integrating the beam power over the receiver’s circular aperture.
- Mode transmission: In the far-field single-mode regime, only one mode is effectively transmitted and its transmissivity is approximately the Fresnel number product nf.This connects the mode decomposition to the far-field collimated-beam transmissivity.
Appendix B: Diffraction-limited free-space bounds
The appendix derives diffraction-limited free-space communication bounds by modeling propagation as thermal-loss channels and applying relative-entropy and PLOB-type capacity bounds. The resulting limits depend on beam-receiver geometry and can be optimized by focusing.
- Channel model: Free-space Gaussian-beam propagation is represented quantum mechanically by a single-mode Bogoliubov transformation coupling the signal to a thermal environmental mode.The environmental photon number depends on operating conditions such as daytime or nighttime background.
- Pure-loss limit: Neglecting thermal noise yields a pure-loss channel whose PLOB bound Φ(ηd) = −log2(1 −ηd) upper-bounds the secret-key and entanglement rates.Thermal noise can be omitted for a universal upper bound because adding noise cannot increase the relevant information-theoretic rate.
- Capacity bounds: The secret-key, entanglement-distribution, and quantum capacities of a bosonic Gaussian channel are bounded using a relative-entropy-of-entanglement bound.The derivation uses monotonicity of relative entropy under completely positive trace-preserving maps.
- Geometric dependence: The diffraction-limited bound depends on the receiver aperture and beam spot size, and it is not restricted to the far-field regime.For a focused beam, the bound is maximized when the focus is placed at the receiver distance.
Appendix C: Atmospheric turbulence
The appendix models atmospheric turbulence as beam-waist broadening and beam-centroid wandering, then converts centroid statistics into transmissivity fading. It distinguishes weak-turbulence approximations from regimes requiring more general treatment.
- Turbulence regime: The refractive-index structure constant C^2_n quantifies turbulence strength, with the Rytov variance providing a criterion for weak turbulence.Weak turbulence corresponds to Rytov < 1, where scintillation is negligible and the mean beam remains approximately Gaussian.
- Turbulence effects: Small turbulent eddies broaden the beam waist rapidly, whereas larger eddies slowly deflect the beam and produce centroid wandering.The long-term spot size combines short-term beam broadening with the variance of beam-centroid motion.
- Approximation validity: Yura’s short-term spot-size expressions are rigorous for φ ≪1 and are treated as good approximations for ρ0/w0 < 1, or φ < 0.33.For the stated daytime parameters, this approximation corresponds to distances z ≳200 m, while exceeding the threshold requires numerical evaluation.
- Strong turbulence: The long-term spot size remains applicable in strong turbulence, where the beam breaks into multiple patches and the spot size describes their mean observed region.This extends the interpretation of the long-term quantity beyond the weak-turbulence approximation.
- Pointing-induced fading: Centroid displacement follows a Rician distribution for nonzero mean offset and reduces to a Weibull distribution when the mean deflection is zero.Combining this displacement model with the deflection-to-transmissivity relation yields the fading transmissivity distribution P0(τ).
Appendix E: Achievability of the loss-based bounds
The appendix studies when loss-based free-space bounds are achievable and how thermal noise changes them. Pure-loss fading permits asymptotic saturation, whereas thermal-loss channels generally leave only upper and lower bounds.
- Pure-loss achievability: For each instantaneous pure-loss channel, the PLOB rate Φ(τ) is achievable for secret-key and entanglement distribution.The optimal capacities satisfy Q2(Eτ) = D2(Eτ) = K(Eτ) = Φ(τ).
- Fading-channel achievability: A strongly biased squeezed-state protocol asymptotically reaches the fading-channel upper bound by averaging instantaneous pure-loss rates over P0(τ).The unbiased protocol achieves Φ(τ)/2, while the completely biased limit approaches Φ(τ).
- Coherent-state protocol: The squeezed-state construction is theoretical, whereas coherent-state homodyne QKD achieves half of the pure-loss bound in the large-modulation limit.The coherent-state instantaneous rate is Rcoh(τ) = Φ(τ)/2.
- Thermal fading: With thermal noise, the free-space link is modeled as an ensemble of instantaneous thermal-loss channels whose transmissivity follows P0(τ).The channel thermal number combines detected environmental photons and extra receiver-added photons.
- Thermal-noise bounds: For thermal-loss fading channels, the secret-key capacity is bounded above while reverse coherent information supplies an achievable lower bound.The two-way assisted capacities are not known in general, so the analysis produces a sandwich relation rather than an exact capacity.
- Low-noise limit: For small thermal photon numbers, the upper and lower bounds collapse to the loss-based bound B(η, σ).This regime is compatible with nighttime operation in the paper’s discussion.
1. Composable key rate under collective attacks
The protocol derives a composable secret-key-rate bound for continuous-variable QKD under collective attacks, incorporating error correction, privacy amplification, and parameter estimation. The resulting security parameter includes correctness, smoothing, hashing, and parameter-estimation contributions.
- Protocol model: Under collective attacks, Alice, Bob, and Eve share an n-copy CQ state, and error correction plus privacy amplification target an ideal sn-bit shared state decoupled from Eve.Reverse reconciliation has Bob reveal leakec bits so Alice can reconstruct Bob’s sequence before hash verification and privacy amplification.
- Error correction: Hash verification accepts with probability pec and bounds the probability of unequal sequences by εcor when the hashes coincide.The verification exchanges ⌈−log2 εcor⌉ bits, negligible compared with leakec.
- Privacy amplification: Two-universal hashing produces sn shared uniform bits bounded through the smooth min-entropy after accounting for error-correction leakage.The bound subtracts the logarithm of the leakage register dimension, with dR = 2^leakec.
- Rate bound: The combination of the finite-size entropy bounds yields a lower bound for the secret bits and an asymptotic rate expressed through conditional entropy and Eve’s Holevo information.Digitalization and reconciliation relate the discretized variables to continuous-variable mutual information through β ∈ [0,1].
- Security: The collective-attack protocol has security ε = εcor + εs + εh and success probability pec.This security statement accompanies the lower bound for the protocol rate.
- Parameter estimation: Parameter estimation sacrifices m modes, replaces R∞(p) with the worst-case rate Rpe = R∞(pwc), and yields the composable secret-key-rate bound after division by N = n + m.The worst-case estimators are constructed from standard-deviation or tail-bound constraints, with total estimation failure probability approximately npmεpe.
2. Proof of Eq. (G9)
The proof establishes Eq. (G9) by relating generalized distance, projected sub-normalized states, and smooth min-entropy under a quantum channel. It applies these inequalities to the protocol state and the n-copy reference state.
- Distance framework: The proof begins with purified distance and generalized fidelity for generally sub-normalized states, establishing the distance framework used for the later projection bounds.The states may have trace at most one, so the argument extends beyond normalized states.
- CQ-state setup: For CQ states, the classical component is represented on an alphabet while the quantum component has dimension at least that alphabet, allowing projected-state comparisons.The proof uses probability distributions and generally sub-normalized conditional quantum states.
- Channel step: A quantum channel acting on the quantum subsystem is used to relate the relevant smooth min-entropies before and after projection.The construction employs an entangled state over an orthonormal classical basis and a quantum output space of dimension dQ′ ≥ d.
- Projection bounds: The proof bounds differences between projected states and their associated probabilities using trace-distance and purified-distance inequalities.A two-outcome POVM provides a probability-distance bound, which is combined with triangle inequalities for the projected states.
- Sub-normalized extension: The resulting inequalities extend the normalized-state argument to sub-normalized states and lead to the intermediate relations needed for Eq. (G9).The extension is obtained by combining bounds on the two terms contributing to the trace-distance estimate.
- Application to Eq. (G9): Choosing a nearby sub-normalized CQ state and applying the projection inequalities yields Eq. (G9) after substituting the protocol systems ˜ρn, ρ⊗n, ln, and En.The argument assumes p > 0 and ε < p/3 so that the rescaled ε′-ball is well defined.