Source-linked AI summary
Quantum key distribution surpassing the repeaterless rate-transmittance bound without global phase locking
Pei Zeng, Hongyi Zhou, Weijie Wu, Xiongfeng Ma
TL;DR
Quantum key distribution is limited by channel-loss-dependent key rates and by the phase-locking demands of high-performance single-photon-interference schemes. The paper proposes mode-pairing MDI-QKD, which determines pair bases and key bits during postprocessing, and reports O(√η) scaling when local phase fluctuations are mild.
Problem
High-performance QKD schemes can require global phase locking over long fibres, while key-rate performance remains constrained by channel loss.
Method
The mode-pairing scheme pairs independently prepared optical signals after Charlie’s announcements and determines key bits and bases during postprocessing.
Results
With sufficiently large pairing intervals, the mode-pairing scheme has key-rate scaling R = O(√η), while intermediate intervals interpolate between O(η) and O(√η).
Takeaways & Limitations
The design combines postprocessing-based mode pairing with a security proof based on entanglement distillation and fixed-pairing equivalence.
Abstract
from arXiv · showhide
Quantum key distribution -- the establishment of information-theoretically secure keys based on quantum physics -- is mainly limited by its practical performance, which is characterised by the dependence of the key rate on the channel transmittance $R(η)$. Recently, schemes based on single-photon interference have been proposed to improve the key rate to $R=O(\sqrtη)$ by overcoming the point-to-point secret key capacity bound with interferometers. Unfortunately, all of these schemes require challenging global phase locking to realise a stable long-arm single-photon interferometer with a precision of approximately 100 nm over fibres that are hundreds of kilometres long. Aiming to address this problem, we propose a mode-pairing measurement-device-independent quantum key distribution scheme in which the encoded key bits and bases are determined during data post-processing. Using conventional second-order interference, this scheme can achieve a key rate of $R=O(\sqrtη)$ without global phase locking when the local phase fluctuation is mild. We expect this high-performance scheme to be ready-to-implement with off-the-shelf optical devices.
A. Mode-pairing scheme
The mode-pairing MDI-QKD scheme independently prepares optical modes, pairs successful detections during postprocessing, and determines bases and key bits from each pair. This recycles single-click events while retaining a security analysis related to two-mode MDI-QKD.
- Scheme procedure: Alice and Bob independently prepare coherent states with random intensities and phases, send them to Charlie, and use his detection announcements for postprocessing.Successful detections are grouped into pairs, whose intensities determine the basis assignment.
- Basis use and key generation: Z-pairs generate keys, while X-pairs provide data for phase-error estimation after basis sifting and alignment-angle comparison.The protocol estimates single-photon contributions and error rates before error correction and privacy amplification.
- Security rationale: Global phase randomisation lets the emitted pair states be treated as mixtures of photon-number states for estimating secure single-photon contributions.This makes the security analysis similar to that of traditional two-mode schemes.
- Security rationale: Independent optical modes decouple encoded information, supporting the claim that postselected qubits cannot be revealed through other pulses.The security proof establishes equivalence to a group of fixed-pairing two-mode schemes under Charlie’s possible measurements and announcements.
- Postprocessing: Successful detection rounds are paired after measurement, converting relative information between two independent optical modes into raw key data.The pairing setting is determined from clicked rounds rather than fixed during state preparation.
B. Pairing strategy
The pairing strategy groups nearby successful detections, with the allowable interval l controlling the balance between phase stability and pairing efficiency. Its rate approaches O(√η) when the local phase reference remains stable over sufficiently long intervals, while l = 1 gives O(η).
- Phase constraint: The pairing interval l is limited by phase fluctuation because the relative phase between paired pulses carries the X-basis information.Longer intervals can therefore increase pairing opportunities while degrading phase stability.
- Simple pairing: Adjacent successful detections are paired when their separation is no greater than l, while unsuccessful or double-click rounds are excluded.The simple strategy uses Charlie’s binary detection announcements to identify eligible rounds.
- Rate scaling: When the local phase reference is sufficiently stable, l can approach infinity and the pairing rate follows the high-loss scaling associated with O(√η).The optimal intensity in this regime is stated to be µ = O(1).
- Rate scaling: When the local phase reference is not stable, setting l = 1 reduces the scheme to the short-range pairing regime with linear transmittance scaling.In this limit, the experimental requirements are close to those of time-bin MDI-QKD.
- Adaptability: The interval l can be adjusted during postprocessing according to laser quality and quantum-channel fluctuations.This permits adaptation to changing environmental conditions without changing the entire pairing procedure.
C. Practical issues and simulation
The simulations evaluate the mode-pairing key rate against established QKD schemes and vary the maximal pairing interval. Increasing l moves performance from linear transmittance scaling toward O(√η), while practical implementation can adapt l to hardware stability.
- Rate analysis: The key-rate expression uses the pairing rate, Z-pair proportion, single-photon-pair fraction, phase-error rate, error-correction efficiency, and sifted-data bit error rate.The single-photon quantities are estimated with the decoy-state method.
- Simulation setup: The simulations compare mode-pairing MDI-QKD with time-bin MDI-QKD, PM-QKD, SNS-TFQKD, BB84, and the PLOB bound under a symmetric channel model.The horizontal axis is communication distance and the vertical axis is key generation rate.
- Simulation results: l = 1 gives R = O(η), while l above 1 × 10^5 produces a rate similar to PM-QKD and SNS-TFQKD with R = O(√η).At l = 1 × 10^3, the key rate is enhanced by 3 orders of magnitude relative to l = 1.
- Simulation results: For intermediate l values from 1 to 1 × 10^6, the key-rate scaling lies between O(η) and O(√η) and is dominated by the pairing rate.The interval can be selected to match practical optical-system stability.
- Practical performance: The scheme can nearly multiply the original time-bin MDI-QKD key rate by l before saturation at l = p^-1 = (µ√η)^-1.With the existing time-bin MDI-QKD apparatus, the authors state that the key rate could increase by approximately 100 times.
II. DISCUSSION
The discussion presents mode-pairing MDI-QKD as combining high key-rate performance with practical security and implementation advantages. It also identifies extensions involving multiplexing, pairing strategies, other optical degrees of freedom, and quantum repeaters.
- Mode-pairing MDI-QKD retains the high key rate and easy implementation of one-mode and two-mode approaches.The authors describe it as combining the advantages of both approaches while preserving MDI-QKD’s practical security.
- More sophisticated pairing strategies could improve bit and basis sifting efficiency beyond the adjacent-detection-pulse strategy.The proposed refinement reveals parts of the encoded intensity and phase information to seek better pairings.
- Future extensions include angular-momentum and spectrum modes, as well as multiplexing different optical degrees of freedom.These extensions are proposed to enhance repetition rate and extend the pairing interval.
- Multiplexing m quantum channels can improve the key generation rate proportionally to m^2 in the high-channel-loss regime.Multiplexing provides both an m-fold channel increase and a larger pairing interval ml, producing more paired signals.
- The mode-pairing technique may help design robust quantum repeaters against lossy channels.The discussion connects the technique to entanglement-swapping-based MDI-QKD and compares it with memory-assisted and all-photonic protocols.
- The scheme determines key bits during postprocessing rather than during encoding or measurement.The authors identify this feature as potentially useful beyond the present QKD setting, including continuous-variable communication.
A. Source replacement of the encoding state
The security proof replaces randomized phase and encoding information with purified ancillary systems, enabling a global measurement of photon number and relative phase. A modified encoding with extra phase modulation is shown equivalent to the original procedure.
- The security proof reduces the mode-pairing scheme to a traditional two-mode MDI-QKD scheme through an entanglement-based construction.This reduction is implemented using a systematic source-replacement procedure.
- The modified proof uses discrete random phases and adds π-phase modulations storing auxiliary bits z′′_1 and z′′_2.These changes separate phase randomisation from phase encoding in the security analysis.
- The modified encoding and postprocessing procedures are equivalent to those of the original scheme.The equivalence is established in Appendix B5, while the modified procedure directly announces the relative phase for alignment-angle sifting.
- Table I contrasts the original and modified phase-encoding and postprocessing procedures used in the main scheme and security proof.The modified scheme adds an extra π-phase modulation to store z′′_1 and decouple phase-randomisation and phase-encoding analyses.
- Alice introduces ancillary qubit and qudit systems to purify the encoded random information.The source-replacement procedure substitutes random encoded information with extra ancillary systems and controlled-phase operations.
- A global measurement M(k, θ) on purified systems simultaneously obtains overall photon number and relative phase information.This measurement supports the security proof by linking the two-mode optical encoding to the relevant photon-number and phase variables.
B. Mode-pairing scheme with decoy states
The decoy-state mode-pairing protocol prepares independently randomized coherent states, pairs successful detections after Charlie’s announcements, and assigns bases and key bits during postprocessing. Decoy data then supports parameter estimation and key distillation.
- Alice’s paired-location encoding uses multiple qudits and qubits whose measurements provide photon number, relative phase, intensity, and basis-assignment information.The two qudits yield overall photon number and relative phase, while additional qubits support key mapping and basis assignment.
- Alice and Bob prepare coherent states with intensities selected from {0, ν, µ} and independently randomized phases before sending them to Charlie.The measurement uses single-photon interference, after which Charlie announces detector clicks for postprocessing.
- Successful detection rounds are grouped into pairs, and basis labels are assigned from the two paired intensities.Z uses one zero and one nonzero intensity, X uses two equal nonzero intensities, ‘0’ supports decoy estimation, and incompatible nonzero settings are discarded.
- Alice and Bob retain or discard pairs according to announced basis compatibility and then assign raw keys from intensity patterns or relative phases.Z-pair keys use which paired pulse has zero intensity, while X-pair keys use the relative phase and matching alignment angles.
- The decoy-state method estimates the clicked single-photon fraction q_11 and the X-basis single-photon phase-error rate e^X_11.Z-pairs with varied intensities estimate q_11, while X-pairs estimate e^X_11.
- Z-pairs generate the key after error correction and privacy amplification using the estimated single-photon and error parameters.The protocol uses Z-pair raw-key data for final key distillation.
C. Mode-pairing-efficiency calculation
The efficiency analysis models the expected number of pairs produced by the simple pairing strategy through the click probability and maximal pairing interval. It decomposes the pulse gaps and uses a geometric distribution for one component.
- The expected pairing number r_p(p, l) depends on the average click probability p and maximal pairing interval l.The calculation targets the pair yield of the simple mode-pairing strategy.
- The analysis records each pair’s first and last clicked locations, F_k and R_k, and its starting location S_k.S_k marks the first successful detection used in the pairing procedure, while a second click within l locations determines whether F_k equals S_k.
- The expected pairing number is obtained by calculating the expectation of G_k and separately analysing the more complex within-pair interval H_k.The analysis conditions E(H_k) on the distance between the starting point and the following click.
- The gap G_k between successive starting pulses is decomposed into the within-pair interval H_k and the interval G_k^(b) after the pair ends.This decomposition separates the distance to the second click from the gap until the next pair begins.
- The post-pair gap G_k^(b) follows a geometric distribution with success probability p.Its probability mass is expressed as (1 − p)^(d−1)p for d = 1, 2, ... .
- The security analysis also uses overall photon-number measurements on two optical modes to post-select a single-photon encoding qubit.The mode-pairing scheme chooses which two modes to measure after receiving detection results.
1. Single-optical-mode case
The single-optical-mode construction purifies a discretely phase-randomised coherent state with an ancillary qudit, allowing phase or pseudo-photon-number information to be read through different ancillary measurements.
- Source replacement: A coherent state with discrete random phase is purified by recording the phase in an ancillary qudit and applying a controlled-phase gate.The gate acts from the ancillary qudit to the optical mode, with φ∆ = 2π/D.
- Ancillary measurements: Measuring the ancillary system in the phase basis reads the random phase, whereas the complementary basis corresponds to a pseudo-photon-number measurement.The pseudo-Fock states are mutually orthogonal, so the ancillary measurement can project the optical mode onto them.
- Continuous-phase limit: As D →∞, the pseudo-Fock states become Fock states and the distribution approaches the Poisson distribution Pµ(k) = e^-µ µ^k/k!.In practice, D ≥12 makes the discretisation effect ignorable.
2. Two-optical-mode case
The two-optical-mode construction jointly tracks global photon number and relative phase, making these observables compatible for two independently phase-randomised coherent states.
- State preparation: Two coherent states are purified with separate ancillary qudits that store their independent random phases before controlled-phase gates generate the optical state.A joint ancillary measurement later accesses both global photon number and relative phase.
- Joint measurement: The measurement M(k, θ) jointly determines global photon number k and encoded relative phase θ because the corresponding observables are compatible.The measurement is defined on the joint ancillary basis and is used in the subsequent security proof.
- Encoding equivalence: The entangled-state procedure and direct preparation of two random-phase coherent states are equivalent after global photon-number and relative-phase measurements.Both procedures produce the same family of states indexed by k and θ.
- Single-photon sector: For global photon number k = 1, the conditional state forms the single-photon qubit subspace used in QKD.The resulting state is independent of the intensity µ.
Appendix B: Security of mode-pairing scheme
The security proof reduces the mode-pairing scheme to established single-photon and two-mode MDI-QKD security through source replacement, equivalence arguments, and post-selection.
- Security framework: The security proof uses QKD equivalence to replace the mode-pairing scheme with an equivalent entanglement-based construction.The key tool is an equivalence argument for MDI-QKD schemes.
- Security framework: Two MDI-QKD schemes are equivalent in security when their initial states and Charlie-conditioned key-generation control operations coincide.The equivalence holds under the same attack because Charlie’s operations are treated as one joint black-box operation.
- Reduction strategy: Source replacement reduces coherent-state two-mode MDI-QKD to single-photon MDI-QKD after overall photon-number measurement and post-selection.The proof identifies the single-photon encoding sector with the case reviewed for single-photon two-mode MDI-QKD.
- Mode pairing: The fixed-pairing mode-pairing scheme uses ancillary-qubit measurements and post-selection to reproduce two-mode MDI-QKD encoding states.Free pairing chosen from Charlie’s announcements is shown equivalent to fixed pairing with the same setting.
- Single-photon two-mode MDI-QKD: In single-photon two-mode MDI-QKD, an X(θ)-basis measurement is implemented by rotating the ancillary qubit or equivalently phase-modulating one optical mode before X-basis measurement.A Z-axis rotation RZ(θ) on the ancilla and phase modulation of A1 encode the same basis choice.
2. Coherent-state two-mode MDI-QKD
Coherent-state two-mode MDI-QKD purifies random phases locally and uses joint ancillary measurements to identify photon-number and relative-phase sectors, reducing the single-photon sector to the established qubit encoding.
- Coherent-state construction: Alice and Bob can replace single-photon sources with weak coherent states while treating Charlie’s operation as a photon-number-channel model.The scheme uses local ancillary systems to store random-phase information before Charlie’s measurement strategy is applied.
- Encoding states: The purified construction stores each emitted mode’s random phase in an ancillary qudit and defines separate Z-basis and X(θ)-basis encoding states.The phases are independently and uniformly randomised, with discrete randomisation approximating continuous randomisation when D ≥12.
- Joint measurement: The joint measurement M(k, θ) produces global photon-number and relative-phase information from the local ancillary qudits.This measurement is the basis for reducing the coherent-state encoding to photon-number sectors.
- Encoding-state reduction: For Z-basis states, the photon-number result follows a Poisson distribution with mean 2µ.The result is stated in the D →∞ limit.
- Encoding-state reduction: The post-measurement state is independent of intensity µ, and the single-photon conditional state is basis-independent for Z-basis and X(θ)-basis encodings.When k = 1, both encoding procedures reduce to the single-photon encoding state.
- Security consequence: The coherent-state two-mode security reduces to single-photon MDI-QKD, while averaged X(θ)-basis phase-error rates characterize Z-basis privacy.The averaging remains valid through the concavity of the binary entropy function.
3. Fixed-pairing MP scheme
The fixed-pairing MP scheme prepares independent optical modes, then forms predetermined pairs whose bases and correlations are recovered through collective ancillary operations. For any fixed pairing, the scheme reduces to coherent-state MDI-QKD and supports secure key generation.
- Construction: The MP scheme introduces encoding redundancies into coherent-state MDI-QKD while initially preparing optical modes independently.Correlations between rounds are created later through pairing and collective operations.
- Basis assignment: The basis choice for each location pair is determined after transmission by pairwise measurements on ancillary systems.The encoding-state reduction maps the resulting conditional states to the Z- or X(θ)-basis states used in coherent-state MDI-QKD, up to possible π-phase modulations.
- Pairing definition: Pairing setting χ partitions all N locations into N/2 pairs, with every location appearing exactly once.The pairing is defined over all locations, including those without successful detections.
- Fixed-pairing definition: In fixed-pairing MP, the pairing setting is predetermined and independent of Charlie’s measurement announcement.This makes the scheme a fixed-pairing instance suitable for security reduction.
- Security: For every fixed pairing, the X(θ)-basis error rate of single-photon pairs estimates the Z-basis phase-error rate, enabling secure key generation with the tagging key-rate formula.The security proof reduces the fixed-pairing scheme to two-mode MDI-QKD.
4. Free-pairing MP scheme
The free-pairing MP scheme chooses the pairing setting from Charlie’s announced detection results rather than fixing it in advance. The security proof shows that any such strategy produces a private state with the same tagging key-rate formula as an appropriate fixed-pairing scheme.
- Definition: A pairing strategy T maps Charlie’s announcement C to a pairing setting χ.Free-pairing schemes allow this mapping to be selected from a finite set of strategies.
- Pairing scope: All locations are paired, including those without successful detections, and undetected pairs can be used for parameter estimation.For example, successful locations 1 and 4 may be paired with the lost pair (2,3).
- Post-processing: Alice and Bob determine χ=T(C) during post-processing after Charlie announces the detection results.They then perform basis sifting, key mapping, parameter estimation, and key distillation as in fixed-pairing MP.
- Security theorem: For any pairing strategy and Charlie measurement, the free-pairing scheme generates a private key state with the tagging key-rate formula.The result holds under all Charlie measurement operations and announcements.
- Security proof: The free-pairing final state equals the private state generated by one of the corresponding fixed-pairing schemes.This establishes security by relating announcement-dependent pairing to the fixed-pairing security result.
Appendix E: Numerical results for the optimal intensity
The appendix analyzes how the MP scheme’s optimal intensity depends on pairing length and detection probability, comparing it with other QKD schemes under matched simulation parameters. The resulting behavior differs from BB84 and conventional MDI-QKD because MP also depends on the pairing rate.
- Simulation setup: The simulations compare optimal intensities across QKD schemes using the same parameters as the main-text simulations.Separate figures examine different communication distances, pairing lengths, and scheme-specific intensity definitions.
- Error behavior: For time-bin BB84, two-mode MDI-QKD, and MP, the Z-basis bit error is almost zero and largely independent of intensity μ.Consequently, the error-correction contribution is negligible in the key-rate analysis for these schemes.
- Comparison: Before dark counts dominate the bit error, the optimal intensity μ for BB84 and MDI-QKD is 1.This behavior follows from the asymptotic condition described for those schemes.
- MP dependence: The MP optimal intensity cannot be obtained directly from its key-rate formula because the rate also depends on the pairing rate r_p.The appendix therefore analyzes limiting regimes of the pairing length and detection probability.
- Distance dependence: For fixed pairing length, the optimal μ may begin near 0.5 and increase toward nearly 1 as communication distance grows.The trend depends on the behavior of the pairing probability p_l.
Appendix F: Proof-of principle experimental demonstration
The demonstration distinguishes local phase stabilization from global phase locking and tests whether paired detection events can support mode-pairing without locking remote laser phases. The experiment finds reasonable error performance for paired signals and projects that larger pairing lengths could surpass the repeaterless bound.
- Phase-stabilization requirement: Local phase stabilization estimates phase differences between two moments, whereas global phase locking stabilizes or estimates the phase difference at every moment.The local requirement is defined over pairs of times separated by a bounded interval, while global locking applies throughout the experiment.
- Phase-stabilization requirement: For short intervals, tracking the lasers’ frequency difference and integrating it estimates the phase difference more easily than directly measuring the phase.Slow phase fluctuations remain small when the interval is short; longer intervals introduce additional fluctuation effects.
- Phase-stabilization requirement: When the interval is much shorter than the inverse linewidth, frequency differences are stable and local phase stabilization is easy to realize.When the interval is much longer, local stabilization approaches global phase locking because both endpoint phases must be estimated accurately.
- Experimental demonstration: The experiment uses two independent lasers without global phase-locking techniques and estimates their frequency difference from paired detection results during post-processing.The setup uses lasers with approximately equal central frequencies and 2 kHz linewidth, while paired outcomes provide the data for probabilistic estimation.
- Experimental demonstration: Mode pairing evaluates whether two paired detection results agree, a relation determined by the phase difference between the paired locations rather than each round’s global phase.The paired results are tested by assigning detector combinations as correct or erroneous according to estimated phase slices.
- Experimental demonstration: The paired-pulse error includes a 25% intrinsic multi-photon contribution plus a reasonable additional error, supporting feasibility without global phase locking.The authors state that post-selecting good reference signals could further reduce errors and yield a reasonable single-photon phase-error value.
- Experimental demonstration: Stable error rates up to pairing lengths of 3000–4000 suggest that a 4 GHz system could reach a maximal pairing length of 20000 and potentially surpass the repeaterless key-rate bound.A full demonstration of the mode-pairing scheme is left for future work.