Source-linked AI summary
Experimental device-independent quantum key distribution between distant users
Wei Zhang, Tim van Leent, Kai Redeker, Robert Garthoff, Rene Schwonnek, Florian Fertig, Sebastian Eppelt, Valerio Scarani, Charles C. -W. Lim, Harald Weinfurter
TL;DR
DIQKD seeks secure key distribution without trusting the internal operation of quantum devices, but experiments must combine loophole-free Bell violation with low QBER. This work implements heralded entanglement swapping between two trapped 87Rb atoms 400 metres apart and observes a positive asymptotic key rate. The setup demonstrates proof-of-concept fully device-independent key distribution, while finite-key security remains constrained by the low event rate.
Problem
Realising DIQKD experimentally is difficult because secure operation requires a loophole-free Bell test across remote locations with both high Bell violation and low QBER.
Method
The experiment uses heralded entanglement swapping between two independently trapped 87Rb atoms separated by 400 metres to implement a robust DIQKD protocol.
Results
An expected secret key rate of 0.07 is obtained in the asymptotic limit, with positive rates retained using worst-case estimates at a 3% probability error.
Takeaways & Limitations
The experiment demonstrates proof-of-concept fully device-independent key distribution over a 400 metre user separation.
Takeaways & Limitations
Finite-key security would require months of measurement time at the current distance because the event rate is intrinsically limited.
Abstract
from arXiv · showhide
Device-independent quantum key distribution (DIQKD) is the art of using untrusted devices to establish secret keys over an untrusted channel. So far, the real-world implementation of DIQKD remains a major challenge, as it requires the demonstration of a loophole-free Bell test across two remote locations with very high quality entanglement to ensure secure key exchange. Here, we demonstrate for the first time the distribution of a secure key -- based on asymptotic security estimates -- in a fully device-independent way between two users separated by 400 metres. The experiment is based on heralded entanglement between two independently trapped single Rubidium 87 atoms. The implementation of a robust DIQKD protocol indicates an expected secret key rate of r=0.07 per entanglement generation event and r>0 with a probability error of 3%. Furthermore, we analyse the experiment's capability to distribute a secret key with finite-size security against collective attacks.
I. INTRODUCTION
DIQKD aims to establish secret keys using uncharacterised quantum devices, relying on input-output statistics and loophole-free Bell tests rather than device characterisation. This experiment addresses the difficulty of achieving both strong Bell violation and low QBER across distant locations.
- Motivation: DIQKD lets users bound eavesdropper information from input-output statistics without characterising their quantum devices.This removes the requirement to trust device specifications and provides security against implementation flaws and misalignment.
- Motivation: A loophole-free Bell test is required to ensure the secure functioning of untrusted QKD devices.The users must also satisfy basic assumptions concerning device inputs and outputs, communication control, and information leakage.
- Experimental challenge: The central experimental challenge is simultaneously achieving a high Bell violation and low QBER.Existing loophole-free Bell experiments had significant Bell violations but QBERs that were not yet sufficient for DIQKD.
- Experimental architecture: The DIQKD connection uses separate devices receiving inputs and producing outputs, with trusted local randomness, storage, and authenticated public post-processing communication.The devices are connected through a quantum channel, while the parties retain control over the required classical resources.
- Contribution: The work demonstrates a proof-of-concept DIQKD experiment between two users separated by 400 metres.It implements the randomised-key-setting protocol using heralded entanglement between two independently trapped 87Rb atoms and an event-ready Bell experiment.
A. DIQKD protocol
The protocol uses randomly chosen measurement inputs and outputs to estimate Bell nonlocality and key errors, then applies classical post-processing to extract a secure key. Its two key-generation settings improve noise tolerance relative to the standard protocol.
- Measurement rounds: Alice’s device receives X_i ∈ {0, 1, 2, 3}, Bob’s receives Y_i ∈ {0, 1}, and each produces a binary output in every measurement round.Inputs come from trusted local randomness, and the devices respond with outputs A ∈ {↑, ↓} and B ∈ {↑, ↓}.
- Parameter estimation: Rounds with differing settings are used to compute the CHSH value S, while equal-setting rounds are sifted for key generation.The key settings are X = Y = 0 and X = Y = 1.
- Security criterion: A Bell violation requires S > 2 when the devices share a sufficiently entangled state.The protocol estimates asymptotic security performance under a depolarising-channel model.
- Security processing: QBERs Q0 and Q1 quantify errors in the two key settings, while S and the QBERs determine the information potentially available to an eavesdropper.The protocol then uses leftover hashing to reduce quantum side information to the chosen security error.
B. Quantum network link
The quantum network links two trapped 87Rb atoms across 400 metres using atom-photon entanglement and heralded entanglement swapping. Improved collection, coherence, and swapping fidelity support high-quality atom-atom correlations for DIQKD.
- Quantum network link: Two optically trapped 87Rb atoms in laboratories 400 metres apart are connected by a 700 metre optical fibre channel.The atoms encode qubits in Zeeman substates of the 5S1/2|F = 1, mF = ±1⟩ ground state.
- Entanglement generation: Synchronous excitation creates atom-photon entanglement locally, and a Bell-state measurement on the photons heralds atom-atom entanglement.A successful |Ψ+⟩ projection sends a ready signal before the atomic qubits are measured.
- Atomic readout: State-selective ionisation maps a chosen atomic-qubit state to ionisation, while fluorescence detection produces the final binary measurement outcome.The readout uses a polarisation-controlled 795 nm pulse followed by ionisation with a 473 nm pulse.
- Performance improvements: The upgraded setup improves entanglement generation rate, atomic-state coherence, and entanglement-swapping fidelity.Custom high-NA objectives increase single-photon collection efficiency by a factor greater than 2.5, yielding an atom-atom entanglement generation efficiency of 0.49 × 10^-6 per excitation pulse pair.
- Performance improvements: The atomic coherence time improves by a factor of 1.5 to approximately 330 µs, with lower-bound atom-photon entanglement fidelities of 0.952(7) and 0.941(7).The fidelities correspond to Alice’s and Bob’s devices, respectively, under the stated readout delays.
- Entanglement fidelity: Two-photon emissions from one atom reduce Bell-state-measurement fidelity, motivating photon filtering to improve atom-atom entanglement quality.The multi-level structure, finite excitation-pulse duration, and experimental imperfections contribute to these unwanted events.
C. DIQKD implementation
The implementation uses independent quantum randomness and laboratory protections to satisfy device-independent assumptions, then evaluates correlations and key performance. The measured Bell violation and QBER place the experiment in the positive asymptotic key-rate region.
- DIQKD implementation: Independent QRNGs select uniformly distributed input combinations, mapping Alice’s four inputs and Bob’s two inputs to measurement angles.Alice uses two random bits and Bob uses one random bit for each input choice.
- DIQKD implementation: A shutter and spectral filter on Bob’s side limit leakage of settings and measurement results through the quantum channel.The trap is emptied before the shutter reopens, while the shutter’s approximately 5 ms reaction time motivates spectral filtering.
- Experimental results: S = 2.578(75) and Q = 0.0779(91) yield an expected secret key rate of 0.07 in the asymptotic limit.The correlation data also give fitted visibilities of 0.869(25) and 0.888(45).
III. RESULTS
The experiment demonstrates positive device-independent secret-key rates over a 400-metre separation, supported by Bell violation and low QBER. Finite-key analysis projects 10^-5 security at a block length of 1.75 × 10^5 rounds under collective attacks.
- 3342 rounds were recorded over 75 hours, producing output (anti-)correlation probabilities for eight input combinations.
- F ≥ 0.892(19) is the lower bound on fidelity to a maximally entangled atom-atom state.The estimated visibilities were 0.869(25) and 0.888(45) for the two Bob-input settings.
- S = 2.578(75), Q0 = 0.0781(127), and Q1 = 0.0777(132), yielding an average QBER of Q = 0.0779(91).
- 0.07 is the estimated asymptotic secret key rate per entanglement-generation event for the robust DIQKD protocol.
- Positive rates remain when worst-case S, Q1, and Q2 estimates are used with a common probability error of 3%.The analysis assumes independent and identically distributed input-output probability distributions and uses standard Bayesian methods.
- 1.75 × 10^5 is the minimal block length for ϵDI = 10^-5 security under collective attacks.The finite-key analysis assumes error-correction efficiency 1.15 and uniformly distributed measurement settings.
IV. OUTLOOK AND DISCUSSION
The work establishes a proof-of-concept fully device-independent quantum-network link over 400 metres, but finite-key operation at that distance is not yet practical. Higher event rates are needed, and event-ready feedback creates a distance–finite-key-security trade-off.
- Positive secret key rates were achieved over 400 metres, corresponding to 700 metres of optical fibre, in a fully device-independent setting.
- Finite-key security and longer reach require further enhancements to the current setup.
- Months of measurement time would be needed to achieve finite-key security at the current distance and setup.A significantly higher entanglement-generation event rate is required for a practical time frame.
- Event-ready feedback limits repetition rate through communication times, creating a trade-off between event rate and distance.Improving the Bell-state-measurement setup could increase entanglement-generation rate by a factor of 2.
Supplemental Material for: “Experimental device-independent quantum key distribution between distant users”
DIQKD treats devices as black boxes, but secure operation still depends on separated devices, controlled communication, trusted inputs, authenticated classical communication, secure storage, and no information leakage. The appendix explains how these assumptions shape practical implementations and proof-of-concept experiments.
- Device independence: DIQKD bounds an eavesdropper’s information from input-output statistics and a loophole-free Bell-inequality violation, rather than device characterization.The Bell test must satisfy locality, random inputs, and detection-loophole requirements.
- Device requirements: The two parties need separated devices that produce unambiguous outputs in well-defined measurement rounds.A single device connecting both laboratories would violate the Bell-test assumptions.
- User-controlled assumptions: Alice and Bob must control device communication and prevent devices from sending unauthorized classical information to an eavesdropper.These conditions ensure local measurements and prevent direct leakage of secret data.
- Cryptographic infrastructure: DIQKD requires trusted inputs unknown to devices and attackers, together with an authenticated classical channel and trusted local storage.Authentication prevents man-in-the-middle attacks, while trusted storage protects recorded data integrity.
- Proof-of-concept scope: A proof-of-concept implementation may relax user-addressed requirements because its goal is to demonstrate technological feasibility rather than send a secret message.Practical secure locations cannot be guaranteed unconditionally and require best-known leakage-prevention methods.
Appendix B: Atom-Photon Entanglement Generation
The experiment generates atom-photon entanglement by exciting individually trapped rubidium atoms and analyzing the emitted photon together with the atomic spin. Measurements characterize the entanglement quality and generation probability for Alice’s and Bob’s devices.
- Entanglement generation: The atom is optically pumped and excited on a resonant transition, producing a photon whose polarization becomes entangled with the atomic spin.The emitted photon travels along the quantization axis, and the resulting state is analyzed in multiple polarization bases.
- Generation probability: 5.98 × 10^-3 and 1.44 × 10^-3 are the entanglement-generation success probabilities for Alice’s and Bob’s devices, respectively.Bob’s lower probability is attributed to attenuation in the 700 m fiber and additional optical losses.
- Atomic analysis: The atomic qubit is measured using state-selective ionization controlled by a readout polarization, followed by fluorescence detection of the atom’s presence.The readout polarization is parameterized by the analysis angle and determines the projected atomic state.
- Correlation measurements: The atom-photon correlations are measured by varying the atomic analysis angle while recording photonic polarization in H/V and, for Device 1, D/A bases.The test runs recorded 35259 events for Alice and 20001 for Bob; sinusoidal fits provide the measured visibilities.
- Entanglement quality: 0.952(7) and 0.941(7) are the estimated atom-photon entanglement fidelities for Alice’s and Bob’s devices, respectively.The fidelities are inferred from fitted visibility measurements under a depolarizing-noise model that includes a third atomic spin state.
Appendix C: Improving the Atom-Atom Entanglement Quality
The appendix models imperfections in 87Rb atom–photon entanglement and optimizes the photon-acceptance window to improve atom–atom entanglement quality. A 95 ns window increases entanglement quality but reduces event rate, creating a key trade-off for DIQKD.
- Imperfections: Imperfect polarization, off-resonant excitation, and multilevel dynamics can produce extra photons that reduce atom–photon and atom–atom state fidelity.These processes also degrade two-photon interference in the Bell-state measurement.
- Optimization: A numerical model uses time-dependent photon-emission probabilities to optimize the two-photon acceptance window for the Bell-state measurement.The model incorporates the 87Rb multilevel structure, finite excitation-pulse duration, and experimental imperfections.
- Optimization: 95 ns is the defined two-photon acceptance window, starting after the excitation pulse and ending at te = 850 ns.Both photons must arrive within the acceptance window for an event to be accepted.
- Trade-off: 4 is the factor by which the shorter acceptance window reduces the event rate while drastically increasing entanglement fidelity.The window is selected before the experiment and therefore does not create a detection loophole in the Bell test.
- Trade-off: Smaller windows might further increase S and reduce QBER, but they also reduce event rates and lengthen the measurement time.Pulse-shape optimization and narrow-band filtering are proposed to improve the event-rate trade-off.
Appendix D: Estimating the expected secret key rate
The appendix estimates the expected DIQKD secret-key rate using Bayesian models for the observed CHSH winning probability and QBERs. A 3% tail-error analysis yields critical thresholds supporting positive key rates, while finite-key security remains constrained by event rate and block-length requirements.
- Security analysis: Finite-key security requires accounting for consumed resources and block length, but the experiment’s low event rate prevents a realistic demonstration using known methods.The limitation reflects a trade-off between event rate and the 400 m laboratory separation.
- Rate estimation: Bayesian analysis models the CHSH winning probability and Q0, Q1 as Beta-distributed random variables to estimate the expected secret key rate.The winning probability is related to the CHSH value by Pwin = (S + 4)/8.
- Rate estimation: 3% tail errors correspond to a 97% chance that each parameter lies beyond its critical threshold in the required direction.This gives S ≥2.4256 and Q0 = Q1 ≤0.107, which provide positive key rates with uniform settings.
Appendix E: Towards DIQKD Applications
The appendix identifies three requirements for practical DIQKD: positive-key entanglement quality, cryptographically relevant distance, and sufficiently high entanglement rates. The demonstrated setup meets the first two requirements but has a very low event rate.
- Requirements: A practical DIQKD apparatus should demonstrate entanglement quality enabling a positive key rate, cryptographically relevant distance, and practical entanglement rates.These are stated as three requirements for practical key distribution.
- Requirements: Approximately 80 s is required to generate one high-quality atom–atom entanglement event over the demonstrated distance.This event rate limits key distribution on practical timescales.