Source-linked AI summary
Practical continuous-variable quantum key distribution with composable security
Nitin Jain, Hou-Man Chin, Hossein Mani, Cosmo Lupo, Dino Solar Nikolic, Arne Kordts, Stefano Pirandola, Thomas Brochmann Pedersen, Matthias Kolb, Bernhard Ömer, Christoph Pacher, Tobias Gehring, Ulrik L. Andersen
TL;DR
Composable security is essential for QKD keys used in other cryptographic applications, but practical coherent-state CVQKD has faced finite-size and noise constraints. This work improves parameter estimation and system operation, generating a composable key with N ≲3.5×10^8 coherent states.
Problem
Practical coherent-state CVQKD has lagged in composability because finite-size security requires many quantum-state transmissions and stringent tolerable-excess-noise conditions.
Method
The system combines improved confidence intervals for parameter estimation with fast, low-noise, stable Gaussian-modulated coherent-state CVQKD operation.
Results
53452436 bits were obtained from 2 × 9.84 × 10^8 real symbols, yielding a worst-case composable SKF of 0.027 bits/symbol.
Takeaways & Limitations
Composable keys can be generated with N ≲3.5×10^8 coherent states, advancing coherent-state CVQKD toward practical deployment and discrete-variable QKD in security and performance.
Takeaways & Limitations
Assuming Gaussian-distributed I and Q symbols could tighten confidence intervals but would restrict the security analysis to Gaussian collective attacks, so the calculations do not make this assumption.
Abstract
from arXiv · showhide
A quantum key distribution (QKD) system must fulfill the requirement of universal composability to ensure that any cryptographic application (using the QKD system) is also secure. Furthermore, the theoretical proof responsible for security analysis and key generation should cater to the number $N$ of the distributed quantum states being finite in practice. Continuous-variable (CV) QKD based on coherent states, despite being a suitable candidate for integration in the telecom infrastructure, has so far been unable to demonstrate composability as existing proofs require a rather large $N$ for successful key generation. Here we report the first Gaussian-modulated coherent state CVQKD system that is able to overcome these challenges and can generate composable keys secure against collective attacks with $N \lesssim 3.5\times10^8$ coherent states. With this advance, possible due to novel improvements to the security proof and a fast, yet low-noise and highly stable system operation, CVQKD implementations take a significant step towards their discrete-variable counterparts in practicality, performance, and security.
I. INTRODUCTION
QKD distributes secret keys over public channels, but practical CVQKD must also account for finite-size effects and composable security. The paper addresses stringent transmission, noise, and proof requirements with a practical GMCS-CVQKD system that generates composable keys.
- I. INTRODUCTION: Finite-size corrections reduce key length but are necessary because practical protocols use a finite number of quantum states.Security analysis must therefore account for the actual number of transmitted states.
- I. INTRODUCTION: Composable security is essential because QKD keys are typically reused in applications such as data encryption.A non-composable QKD implementation is described as practically useless.
- I. INTRODUCTION: Existing coherent-state CVQKD demonstrations faced strict bounds, large transmission requirements, and stringent excess-noise limits that hindered composability experiments.These obstacles arose from complex parameter estimation and finite-size security terms.
- I. INTRODUCTION: The paper demonstrates a practical GMCS-CVQKD system generating composable keys secure against collective attacks.The approach combines new confidence intervals for collective attacks with noise reduction and machine-learning phase compensation.
- I. INTRODUCTION: N ≲3.5 × 10^8 coherent states sufficed for positive composable key length, while N = 10^9 produced > 53.4 Mbits of secure key material.These results include finite-size effects and calibration confidence intervals.
II. COMPOSABLY SECURE KEY
The security analysis derives a finite-size composable key bound for reverse reconciliation under collective attacks. Improved confidence intervals tighten parameter estimation, reducing the state number needed for a positive key while accounting for digitization constraints.
- II. COMPOSABLY SECURE KEY: The analysis assumes collective attacks, finite transmissions, reverse reconciliation, parameter estimation, and privacy amplification.Alice corrects her data according to Bob’s quantum symbols after information reconciliation.
- II. COMPOSABLY SECURE KEY: The composable key length is bounded using smooth min-entropy, subtracting information-reconciliation leakage and accounting for correctness and hashing security parameters.The framework uses the leftover hash lemma and explicitly tracks failure and smoothing parameters.
- II. COMPOSABLY SECURE KEY: Failed information-reconciliation frames are discarded, leaving n′ = np′ quantum symbols for subsequent security processing.This projects the original product state into a non-i.i.d. state that must be included in the entropy analysis.
- II. COMPOSABLY SECURE KEY: The finite-size entropy bound uses the asymptotic equipartition property and an improved penalty relative to earlier analyses.The conditional entropy is expressed as H(Ȳ|E)ρ = H(Ȳ)ρ − I(Ȳ;E)ρ.
- II. COMPOSABLY SECURE KEY: The improved confidence intervals reduced the required coherent-state number by an order of magnitude for obtaining a composable key.The improvement is attributed to the new confidence-interval construction used in parameter estimation.
- II. COMPOSABLY SECURE KEY: The implementation approximates Gaussian-modulated coherent states with a 7-standard-deviation range and d = 6-bit digitization, yielding 4096 coherent states.This finite range and resolution are presented as a technical limitation of practical devices.
III. EXPERIMENT
The experiment uses a schematic transmitter–receiver setup whose operation, calibration, and protocol implementation are described in the surrounding sections. The detailed functional blocks are provided in the Supplement.
- III. EXPERIMENT: The experimental setup is organized around transmitter and receiver operation, calibration measurements, and protocol implementation.The paper refers to Fig. 2 for the schematic and the Supplement for detailed functional blocks.
A. Transmitter (Tx)
The transmitter generates Gaussian-modulated coherent states using optical single-sideband modulation with carrier suppression. A pilot tone is multiplexed with the quantum-data signal to provide a shared phase reference.
- A. Transmitter (Tx): Optical single-sideband modulation with carrier suppression generates coherent states in a 100 MHz frequency sideband away from the optical carrier.An IQ modulator, automatic bias controller, and arbitrary waveform generator drive the modulation.
- A. Transmitter (Tx): A 25 MHz pilot tone is frequency-multiplexed with the 200 MHz quantum-data signal to share a phase reference with the receiver.The pilot tone supports phase-reference distribution during transmission.
B. Receiver (Rx)
The receiver uses polarization control and heterodyne detection to measure the incoming quantum signal, with high-speed digitization and spectral monitoring of noise components.
- B. Receiver (Rx): The receiver tunes the incoming polarization and uses a symmetric beam splitter with balanced detection for radio-frequency heterodyne measurement.The detector output is sampled by a 16-bit ADC at 1 GSps.
- B. Receiver (Rx): The receiver’s free-running local oscillator is frequency-detuned from the transmitter laser by approximately 320 MHz, producing the beat signal used in the measured spectrum.The quantum-data band and pilot tone are also identified in the receiver spectrum.
- B. Receiver (Rx): Vacuum noise exceeds electronic detector noise by more than 15 dB across the entire quantum-data band.Separate measurements were made with the transmitter laser off and with both lasers off.
C. Noise analysis & Calibration
The experiment calibrates modulation, trusted parameters, and noise sources while selecting operating conditions that limit excess noise and quantify security parameters.
- C. Noise analysis & Calibration: The pilot tone and quantum-data band are positioned to balance phase-reference accuracy against leakage and spurious frequency-mixing noise.The setup avoids placing sum- and difference-frequency spurs inside the wide quantum-data band.
- C. Noise analysis & Calibration: The modulation strength is calibrated through direct transmitter–receiver heterodyne measurements to optimize the coherent-state mean photon number.The AWG electronic gain and optical attenuation provide fine-grained control of the modulation strength.
- C. Noise analysis & Calibration: The nonparanoid analysis decomposes total transmittance and excess noise into trusted and untrusted components, requiring additional trusted-parameter measurements.Some loss and excess noise are assumed to be beyond Eve’s control.
D. Protocol operation
The protocol processes heterodyne symbols through information reconciliation, parameter estimation, and privacy amplification to produce a reverse-reconciled key under collective-attack assumptions.
- D. Protocol operation: The experiment collects 10^9 complex symbols in 25 blocks and uses offline digital signal processing to form the raw key.After synchronization discards, 9.88 × 10^8 correlated symbols remain for information reconciliation.
- D. Protocol operation: Information reconciliation uses multidimensional multi-edge-type LDPC codes, followed by correctness confirmation using hashes exchanged between Bob and Alice.Bob sends the mapping, syndromes, and Toeplitz-hash values to Alice.
- D. Protocol operation: During parameter estimation, Alice evaluates corrected-symbol entropy and covariance statistics to bound channel parameters and Eve’s Holevo information.Erroneous frames are included in the covariance evaluation after being publicly announced.
- D. Protocol operation: Privacy amplification applies a randomly selected Toeplitz hash with a high-speed, large-scale implementation to generate the final key.Alice and Bob use a shared seed from the preceding protocol step.
IV. RESULTS & DISCUSSION
The system achieves positive composable secret-key generation with finite data by combining low-noise operation and tighter parameter-estimation confidence intervals.
- IV. RESULTS & DISCUSSION: Positive composable key generation begins at N/B ≲ 3.5 seconds when the worst-case untrusted-noise estimator falls below the null-key threshold.The SKF evolution accounts for finite-size corrections using average and worst-case parameter values.
- IV. RESULTS & DISCUSSION: 53,452,436 secret bits are extracted from 9.84 × 10^8 post-reconciliation symbols, giving a worst-case SKF of 0.027 bits/symbol.The measured operating point uses 10^9 prepared coherent states and 20 km transmission.
- IV. RESULTS & DISCUSSION: Tighter confidence intervals for covariance estimation are identified as the main reason positive composable keys are obtained with N ≲ 3.5 × 10^8 coherent states.The improvement is evaluated against the original proof using Beta-distribution-based intervals.
- IV. RESULTS & DISCUSSION: Using the original confidence intervals would have required NPA ≳ 7.5 × 10^9 to reach the reported peak SKF in simulation.The comparison reflects the quadratic dependence of untrusted noise on covariance.
- IV. RESULTS & DISCUSSION: At B = 100 MSymbols/s, careful excess-noise removal supports fast, low-noise, and stable operation, while DSP and classical processing remain offline in the experiment.The plotted temporal evolution therefore represents hypothetical real-time protocol operation.
V. CONCLUSION & OUTLOOK
The work targets CVQKD based on coherent states as a potentially cost-effective option for quantum cryptography at access-network scales, while addressing its security gap relative to discrete-variable systems.
- Coherent-state CVQKD is presented as a potentially cost-effective approach for deploying quantum cryptography across 10–50 km access-network channels.
- The implemented system addresses CVQKD’s lag behind discrete-variable systems in demonstrating composability and robustness against finite-size effects.
- The implementation uses a prepare-and-measure Gaussian-modulated coherent-state CVQKD design.
Practical continuous-variable quantum key distribution with composable security: supplemental document
The supplemental document provides additional detail on theoretical security analysis and the experimental system beyond the main manuscript.
- The supplemental sections detail aspects of the theoretical security analysis that were not explained in the main manuscript.
- The supplemental sections also detail aspects of the experimental system omitted from the main manuscript.
- The document is identified as arXiv:2110.09262v1, dated 18 October 2021.
1. IMPROVED CONFIDENCE INTERVALS
The method estimates variances and covariances from finite empirical data with confidence intervals, improving bounds used in composable key-length calculations. It combines distribution-based bounds, optimized covariance intervals, and entropy and Holevo-information estimates for finite-size security analysis.
- Improved confidence intervals: The parameter-estimation routine estimates variances and covariances of unbounded transmitter and receiver variables from 2n quadrature values forming n complex symbols.The receiver variables arise from heterodyne detection, while transmitter variables are preparation values.
- Improved confidence intervals: Improved confidence intervals use numerical beta-distribution bounds instead of exponential χ2-distribution bounds for parameter estimation.The revised approach targets empirical estimates of transmitted and received variances and their covariance.
- Improved confidence intervals: Covariance confidence intervals are optimized by choosing λ2 = y-hat/x-hat under Gaussianity and λ = ||Y||/||X|| without that assumption.These choices minimize the corresponding interval expressions in the two derivations.
- Secret key calculation: The composable key-length calculation combines an entropy estimator, Gaussian-state Holevo information, error-correction success, receiver resolution, and a finite-size AEP correction.Calibration, parameter-estimation, and random-number security parameters enter the overall security analysis, including implicitly where specified.
B. Modulation (quantum data & pilot tone)
The system converts Gaussian-modulated I/Q symbols into filtered digital waveforms, adds a pilot tone for phase referencing, and reconstructs synchronized receiver symbols through DSP. Receiver calibration estimates trusted loss and noise parameters used in the security analysis, while reconciliation achieves 91.6% overall efficiency.
- Quantum data waveform: 100 MHz quantum symbols were upsampled to 1 GSps and interpolated with a root-raised-cosine filter to form the baseband I/Q waveforms.The RRC filter used a rolloff factor of 0.2 and a span of 20 symbols.
- Pilot tone: A 200 MHz quantum-data waveform was combined with a 25 MHz pilot tone to provide a receiver phase reference.The pilot tone was multiplexed in frequency with the quantum data signal.
- Digital signal processing: The receiver DSP estimated pilot frequency, recovered phase with an unscented Kalman filter, synchronized timing, and filtered-downsampled the signal into final I/Q symbols.The quantum signal was down-converted using the 175 MHz quantum-signal-to-pilot frequency difference.
- Receiver calibration: Trusted receiver loss and noise were estimated from calibration measurements and incorporated into the security proof under the assumption that the receiver is inaccessible to Eve.The trusted efficiency was estimated as τ = 0.69, corresponding to 1.6 dB loss.
- Reconciliation efficiency: 91.6% overall reconciliation efficiency was obtained from βCode = 94.1% and βChannel = 97.4% at SNR = 0.323.The efficiency combines finite-length code performance with the channel efficiency.