Source-linked AI summary

Experimental quantum key distribution certified by Bell's theorem

D. P. Nadlinger, P. Drmota, B. C. Nichol, G. Araneda, D. Main, R. Srinivas, D. M. Lucas, C. J. Ballance, K. Ivanov, E. Y-Z. Tan, P. Sekatski, R. L. Urbanke, R. Renner, N. Sangouard, J-D. Bancal

arXiv:2109.14600v2quant-phcs.CR

TL;DR

Device-independent quantum key distribution addresses vulnerabilities caused by imperfect quantum devices. This work combines loophole-aware isolation with trapped-ion entanglement and cryptographic post-processing, demonstrating secrecy certified by observed statistics and a key rate exceeding the estimated leakage bound.

  • Problem

    Implementation defects in quantum devices can undermine the security assumptions of conventional quantum key distribution.

  • Method

    The experiment combines event-ready trapped-ion entanglement with finite-statistics analysis, error correction, privacy amplification, and physical isolation of the qubits before measurement.

  • Results

    The demonstration achieved a key rate of 0.064, exceeding the upper-bounded leakage entropy of 0.025.

  • Takeaways & Limitations

    Observed measurement statistics certify secrecy without requiring trusted quantum-device operations.

  • Takeaways & Limitations

    The security analysis assumes isolation that excludes information transfer from one party's input to the other party's device before its outcome is produced.

Abstract

from arXiv · show

Cryptographic key exchange protocols traditionally rely on computational conjectures such as the hardness of prime factorisation to provide security against eavesdropping attacks. Remarkably, quantum key distribution protocols like the one proposed by Bennett and Brassard provide information-theoretic security against such attacks, a much stronger form of security unreachable by classical means. However, quantum protocols realised so far are subject to a new class of attacks exploiting implementation defects in the physical devices involved, as demonstrated in numerous ingenious experiments. Following the pioneering work of Ekert proposing the use of entanglement to bound an adversary's information from Bell's theorem, we present here the experimental realisation of a complete quantum key distribution protocol immune to these vulnerabilities. We achieve this by combining theoretical developments on finite-statistics analysis, error correction, and privacy amplification, with an event-ready scheme enabling the rapid generation of high-fidelity entanglement between two trapped-ion qubits connected by an optical fibre link. The secrecy of our key is guaranteed device-independently: it is based on the validity of quantum theory, and certified by measurement statistics observed during the experiment. Our result shows that provably secure cryptography with real-world devices is possible, and paves the way for further quantum information applications based on the device-independence principle.

METHODS

The experiment addresses DIQKD’s isolation and locality requirements by disconnecting the qubits from external channels before measurement and keeping private data within each node. Classical communication is limited to protocol messages and experiment coordination.

  • Assumptions: The locality condition requires each party’s measurement inputs to remain unknown to the other device when outcomes are produced.This requirement is necessary for device-independent quantum key distribution and can be supported by local random measurement choices.
  • Assumptions: The isolation assumption requires preventing information leakage from the qubits to the outside after heralded entanglement generation.The experiment treats isolation as distinct from the detection loophole, which requires separate analysis.
  • Link disconnection: After heralding, the ions are shuttled 3 µm from the imaging focus, reducing coupling to the outside by a factor of > 10^4 before basis choices and readout.The protocol preserves entanglement while physically reducing the qubits’ external coupling.
  • Link disconnection: A macroscopic fast fibre switch could further disconnect the optical link, while independent laser sources are compatible with the stated synchronisation requirements.The required synchronisation concerns matched qubit frequencies and alignment of 7 ns single-photon wave packets at the heralding station.
  • Data handling: Each node uses an independent ARTIQ-based PC–FPGA control system, with random choices generated commercially and stored before the experiment.The setup is designed to remain compatible with the protocol’s security and isolation assumptions.
  • Data handling: Heralding events are never post-selected: every event contributes to the final strings, while private outcomes remain on the respective node PCs.The nodes exchange only public protocol information, such as error-correction syndrome data, and coordinate experimental scheduling.

Contributions

The contributions span experimental apparatus, data collection and analysis, key extraction, error-correction design, protocol and security-proof development, manuscript preparation, and supervision.

  • Experimental work: DPN and PD built and operated the apparatus, led data collection, and performed the data analysis.DPN and PD are also identified among the researchers who built and operated the experimental apparatus.
  • Data processing: JDB and DPN extracted the key from raw data, while KI, RLU, and JDB designed the error-correction code.These roles connect raw-data processing with the protocol’s classical post-processing.
  • Theory and protocol: JDB, EYZT, NS, PS, and RR established the protocol steps and derived the corresponding security proof.NS and JDB initiated the project and supervised the theoretical work with the stated collaborators.
  • Manuscript and supervision: NS, JDB, DPN, and CJB wrote the manuscript, while CJB and DML supervised experimental work and JDB and NS supervised theoretical work.All authors contributed to discussion, interpretation, and the manuscript.

Competing interests

The paper reports one competing interest: CJB is a director of Oxford Ionics; the remaining authors declare none.

  • Disclosure: CJB is a director of Oxford Ionics, while the remaining authors declare no competing interests.

ADDITIONAL INFORMATION

The paper provides supplementary information for the study, including additional material associated with the experimental quantum key distribution protocol.

  • Supplementary material: Supplementary Information is available for this paper.
  • Supplementary material: The supplementary information is titled “Experimental quantum key distribution certified by Bell’s theorem.”

S1. NOTATION

Table S1 lists the acronyms, symbols, and expressions used throughout the supplementary material.

  • Table S1 provides a reference list for commonly used acronyms, symbols, and expressions.

S2. EXPERIMENTAL DETAILS

The experiment uses two nominally identical trapped-ion nodes with independently controlled local hardware, while the apparatus layout shows their optical and classical connections.

  • Each node is based on a nominally identical room-temperature trapped-ion system, with technical improvements supporting more stable remote entanglement.
  • The manuscript swaps the Alice and Bob labels relative to the earlier reference so node roles match the protocol analysis.
  • The apparatus connects Alice’s and Bob’s nodes to a central heralding station, with shared laser sources switched locally by AOMs.

A. The two-node ion trap network

The network links two trapped-ion nodes through a heralded photonic connection and executes local measurements only after successful entanglement generation and link disconnection.

  • A. The two-node ion trap network: Each node confines one 88Sr+ ion and uses resonant laser radiation for cooling, state preparation, coherent control, and readout.
  • A. The two-node ion trap network: 422 nm photons entangled with local ion states travel through single-mode fibres to a central station performing a Bell-basis measurement.
  • A. The two-node ion trap network: The attempt cycle repeats until a heralding signal announces remote entanglement or an attempt-duration limit triggers recooling.
  • A. The two-node ion trap network: After heralding, both ions are moved away from the optical link before Bob announces the round type and the parties perform local analysis.
  • A. The two-node ion trap network: 180 000 successful heralds required 1 133 526 525 attempts, corresponding to a 1.6 × 10^-4 success probability and a 100 s^-1 heralding rate.
  • A. The two-node ion trap network: The nodes can use separate laser sets because the protocol does not require optical phase coherence between them.

B. Entanglement characterisation

The experiment characterises the ion-ion entangled state using optical-qubit analysis and maximum-likelihood tomography, obtaining high fidelity while identifying unresolved error sources.

  • B. Entanglement characterisation: The remote ground-state entanglement is mapped to an optical qubit, with 674 nm pulses selecting measurement bases and reducing computational-basis shelving errors.
  • B. Entanglement characterisation: Tomography measures Pauli eigenstates using an over-complete set of analysis bases to reduce systematic bias in the xy plane.
  • B. Entanglement characterisation: The maximum-likelihood density matrices are reconstructed separately for each of the four heralding detector coincidence patterns.
  • B. Entanglement characterisation: A detailed model of the fidelity error sources remains unavailable, with uncharacterised polarisation mixing suspected as the primary contribution.
  • B. Entanglement characterisation: Measured coherence times and local control errors were assessed as not significantly limiting the experiment at its current fidelity level.

C. DIQKD primitives

The protocol uses calibrated ion measurements to maximize Bell-test performance and key-generation correlations, with empirical statistics collected across 1,920,000 rounds. Numerical optimization suggested improved error rates, but the improvement was not observed conclusively.

  • Measurement settings: Alice and Bob use computational-basis and rotated measurements for Bell tests, while key-generation settings X = 0 and Y = 2 maximize correlations.Bob’s phase is calibrated separately for each heralding click pattern to compensate differing phases between the |01⟩ and |10⟩ components.
  • Experimental statistics: 1 920 000 DIQKD data-acquisition rounds were collected to estimate the empirical joint probabilities P(A_iB_i|X_iY_i).The outcomes were recombined with their inputs for analysis and summarized in Table S4 and Figure S4.
  • Experimental statistics: The empirical probabilities are organized by Alice’s outcomes in matrix rows and Bob’s outcomes in columns, with multinomial standard errors.Alice’s classical outcomes were inverted so that 0 corresponds to finding the ion in the S1/2 manifold.
  • Optimization and limitation: Numerical optimization predicted statistically significant improvements in quantum bit error rate and CHSH score for slightly tilted measurement axes, but these improvements were not observed in practice.The authors could not conclusively determine whether tomography bias caused the discrepancy.
  • Randomness: The setting choices X and Y, together with the initial shared key K0, are generated by a commercial quantum random-number generator.A cursory inspection of approximately 3 × 10^10 bits found no obvious defects using dieharder and TestU01 batteries.

D. Shuttling-based link isolation

The experiment isolates the ions from the optical link after heralded entanglement by physically shuttling them away from the collection focus. Isolation is essential but remains an external assumption, and measured leakage is bounded below the demonstrated key rate.

  • Isolation requirement: Isolation requires disconnecting the optical link every round so private node data cannot leak during measurement.The authors identify this requirement as intrinsically in tension with coupling matter-based qubits to the fibre during entanglement generation.
  • Shuttling implementation: After heralding, the ions are moved relative to the high-NA objective by modulating the trapping potential, physically suppressing photon collection through the remote fibre link.The implementation modifies four second-nearest-neighbour electrodes because of DAC-system limitations.
  • Timing sequence: A 30 µs delay after switching DAC voltages ensures the link is fully disconnected before Bob communicates the round type.The ions are first mapped into a less magnetic-field-sensitive optical qubit before the later measurement-basis choice.
  • Security assumption: Isolation cannot be verified device-independently and must be established through independent technical means.The authors note that bounded residual leakage can instead be incorporated by shortening the final key.
  • Measured leakage: 2.5 × 10^-3 is the estimated probability of a photon leaking from either system during measurement, based on detector counts conditioned on classical outcomes.Table S5 reports registered-photon counts and conditional means; background for outcome 00 is attributed to detector dark counts within uncertainty.
  • DIQKD assumptions: The DIQKD assumptions include quantum theory, isolation, truly random inputs, trusted classical processing, and trusted quantum operations.DIQKD relaxes only the trusted-quantum-operations assumption; isolation remains required.
  • Motivation: Conventional QKD’s trusted-device assumption is vulnerable to imperfect calibration and devices operating outside their intended regime.DIQKD seeks to improve security by lifting this assumption.
  • Scope boundary: DIQKD remains susceptible to attacks that violate isolation, such as an unshielded emitter broadcasting secret information from a laboratory.Users must gain confidence in proper isolation independently of the protocol.

D. The DIQKD assumptions in the experiment

The experiment implements DIQKD with explicit assumptions about isolation, independent randomness, and separated laboratories. Its protocol uses heralded entanglement, randomized testing, error correction, validation, privacy amplification, and authentication across n rounds.

  • Assumptions: The protocol assumes that measurement choices are sufficiently independent of the devices and that shared laser equipment does not undermine device-independent security.The authors rely on tested quantum randomness and argue that each user accesses only its own laser mode.
  • Assumptions: The experiment treats the laboratories as spatially separated systems with factorized Hilbert spaces and locally stored classical information.Each lab contains a trapped ion and independent local control and storage components.
  • Scope and improvements: The experiment identifies stronger isolation as a remaining improvement, including further fibre attenuation or future quantum memories storing about 10^6 qubits.Space-like separation can help in some cases but does not replace isolation of the ion–fibre link.
  • Protocol: The protocol begins with a shared key K0 and repeats state preparation, sampling, measurement, and classical post-processing over n rounds.Bob samples test settings with P(Yi = 0) = P(Yi = 1) = γ/2 and P(Yi = 2) = 1 − γ; Yi = 2 denotes key-generation rounds.
  • Protocol: Post-processing includes basis revelation, syndrome-based error correction, parameter estimation, error-correction validation, Bell-violation validation, privacy amplification, and authentication.The protocol aborts when validation fails; otherwise, both parties extract matching final keys.

S6. ERROR CORRECTION

The error-correction problem is to let Bob reconstruct Alice’s outcomes while minimizing public leakage. The paper develops a universal, efficient coding strategy suited to finite statistics, multiple channels, and changing experimental conditions.

  • S6. ERROR CORRECTION: Bob must reconstruct Alice’s raw key from correlated outcomes while Alice sends a syndrome whose public length is as short as possible.Longer messages reveal more information and reduce the secrecy of Alice’s key.
  • S6. ERROR CORRECTION: The scheme must combine short messages with noise robustness and efficient implementation, not merely succeed at a small syndrome length.These requirements motivate a code designed for practical finite-size operation.
  • S6. ERROR CORRECTION: Asymmetric Slepian–Wolf coding sends a syndrome M derived from A so Bob can reconstruct A from B and M.Its asymptotic overhead can approach the conditional entropy limit.
  • S6. ERROR CORRECTION: The experimental statistics comprise four test-round binary symmetric channels and one key-round channel, with distinct error probabilities determined by S and Q.The test channels are sampled γn times in total, while the key channel is sampled (1 − γ)n times.
  • S6. ERROR CORRECTION: Because larger blocks reduce finite-length overhead, the data from all channels are encoded jointly and decoded with one procedure.This replaces separate coding of each string with a single combined block.
  • C. Practical coding approaches: SC-LDPC codes are selected as a practical option because their belief-propagation threshold approaches the maximum-likelihood threshold and they achieve capacity universally asymptotically.Protograph construction provides a simple route to variable-length LDPC codes.
  • 3. Belief propagation decoding: The standard belief-propagation decoder is used because its behavior for SC-LDPC codes on non-erasure channels lacks a corresponding theoretical analysis for several proposed improvements.The same gap also applies to early-termination schemes.

D. Simulations

The simulations evaluate finite-block error-correction performance, showing convergence toward asymptotic overhead limits and benefits from exploiting distinct bit reliabilities and joint decoding.

  • Finite-length convergence: For n = 5e6, the recovery threshold is η∗ = 0.196, only 6% above the asymptotic value ˜η∞ ≈ 0.1847.The same threshold is 3.7% above ˜η(5e6) ≈ 0.189.
  • Threshold definition: Finite-length thresholds are defined as the smallest overhead η yielding successful recovery probability above a fixed p∗.The simulations use this threshold to quantify the extra overhead required at finite block length.
  • Finite-length convergence: At p∗ = 0.9, simulations across multiple γ, S, and Q regimes show similar convergence, supporting the universality of the code construction.The plotted bounds for γ = 13/256, S = 2.6507, and Q = 0.0239 provide lower and upper references.
  • Reliability information: Using only global symmetric error gives a much higher best-possible overhead, while distinguishing bit reliabilities lowers the threshold for every finite block length.The global-error reference converges faster because it avoids a small block, but its overhead remains larger.
  • Comparison with prior schemes: The construction achieves smaller overhead than the AFRV bound and comparable overhead to the TSBSRSL bound.These comparisons concern schemes previously considered for DIQKD that lack a known efficient decoding algorithm.
  • Finite-size behavior: The simulated critical threshold is systematically shifted from the Eq. (19) bound because scaling depends more on lifting factor M than total block length n.This identifies a finite-size implementation effect affecting the observed convergence.
  • Joint decoding: Joint decoding one large block requires one code and yields lower gap than independently decoding separate more- and less-noisy bits.The comparison is g(˜η(n)) versus γ · g(˜η(γn)) + (1 −γ) · g(˜η((1 −γ)n)).

E. Practical implementation of the coding scheme

The practical coding scheme selects syndrome lengths and decoder priors from experimental parameters, then evaluates completeness through error correction, authentication, and Bell-test acceptance conditions.

  • Code parameters: The syndrome length is chosen as a function of S, Q, γ, and n, with margin for success probability above 90% and statistical deviations.The choice is based on numerical experiments and is intended to provide sufficient syndrome information for decoding.
  • Code parameters: Decoder priors are defined from the expected channel statistics in Table S6 for test and key-generating rounds.The table specifies Alice–Bob outcome correlations used by the decoder.
  • Experimental coding: The practical implementation runs belief-propagation decoding on an Intel Core i7-9700 CPU, taking 250 s for n = 1.5 × 10^6.The reported runtime describes the actual DIQKD demonstration.
  • Protocol completeness: Protocol parameters are selected to accept expected experimental behavior with high probability while maximizing the key rate.The feasibility analysis considers error correction, authentication and activation, and Bell-test verification as possible abort points.
  • Protocol completeness: Error correction accepts when its hashes match, authentication and activation accept matching tags, and Bell verification bounds losing CHSH test rounds.The syndrome-length choice supports reliable reconstruction, while classical communication reliability supports authentication.
  • Protocol completeness: Choosing k = 3 allows three standard deviations of tolerance and guarantees εcom ≤ 0.01 for the honest implementation.The allowance separates expected behavior from the acceptance threshold and contributes an error probability well below 1%.
  • Security framework: The security analysis compares the final state with an ideal uniformly random state using trace distance and entropy tools for sub-normalized states.The framework introduces trace norms, trace distance, purified distance, and conditional min- and max-entropies.

S10. SECURITY STATEMENT

The protocol derives a secure key length from CHSH statistics and finite-size parameters, then establishes correctness and secrecy through classical post-processing and privacy amplification. Its analysis includes a modified protocol whose statistics match the original while enabling a security proof that accommodates general quantum side information and device memory.

  • Secure key length: Proposition 2 gives a secure key-length expression based on CHSH-winning statistics, entropy accumulation, smoothing parameters, privacy amplification, and error-correction hashing.The resulting key is (max(εEA, εPA + 2εs) + 4εh)-sound.
  • Protocol parameters: The protocol fixes the number of rounds, testing probability, CHSH threshold, and syndrome length before execution, while optimizing remaining proof parameters to maximize ℓ.In the reported optimization, εh = 2^-61 is fixed by the VHASH algorithm.
  • Finite-size behavior: A positive key rate in the depolarizing model begins at approximately 2.6 × 10^5 rounds, with the required round count depending on S and Q.The supplementary analysis also reports optimal testing probability as a function of the number of rounds for εsnd = 10^-10.
  • Security proof: The modified protocol rearranges sampling and basis revelation while distributing the quantum state initially, preserving the original protocol’s relevant statistics for security analysis.Additional registers and variables simplify the proof without changing the estimation statistics used by the original protocol.
  • Security proof: After measurements and parameter estimation, error correction lets Bob reconstruct Alice’s outcomes; matching hashes establish correctness, while privacy amplification bounds secrecy against Eve’s side information.The correctness analysis obtains εcorr = εh, and the secrecy analysis uses trace-distance bounds for the key conditioned on protocol success.
  • Security guarantees: The security analysis explicitly permits arbitrary quantum side information and measurement-device memory, while requiring authenticated communication and successful protocol checks.The protocol’s event definitions track communication, authentication, and parameter-estimation conditions governing whether it aborts.
Loading 2109.14600v2…