Source-linked AI summary
Continuous-variable quantum key distribution system: past, present, and future
Yichen Zhang, Yiming Bian, Zhengyu Li, Song Yu, Hong Guo
TL;DR
The paper addresses how CV-QKD using coherent states can develop into practical, telecom-compatible quantum-network technology. It reviews protocols and security, system implementations, and advances in digital, chip-based, and point-to-multipoint architectures. The review reports progress from proof-of-principle demonstrations toward in-field implementations and technological prototypes, with demonstrated potential for metropolitan and access networks.
Problem
CV-QKD requires protocols, security analyses, and system architectures that can support practical, scalable quantum networking while exploiting compatibility with classical optical communications.
Method
The paper reviews coherent-state CV-QKD protocols and security, system structures and implementations, future digital, chip-based, and point-to-multipoint developments, and practical security.
Results
CV-QKD has progressed from proof-of-principle demonstrations toward high-performance, robust implementations, including digital systems, chip-based detectors, and point-to-multipoint networks.
Takeaways & Limitations
High-speed implementations, chip integration, and field networking tests demonstrate potential for CV-QKD in metropolitan and access networks compatible with existing optical infrastructures.
Abstract
from arXiv · showhide
Quantum key distribution provides secure keys with information-theoretic security ensured by the principle of quantum mechanics. The continuous-variable version of quantum key distribution using coherent states offers the advantages of its compatibility with telecom industry, e.g., using commercial laser and homodyne detector, is now going through a booming period. In this review article, we describe the principle of continuous-variable quantum key distribution system, focus on protocols based on coherent states, whose systems are gradually moving from proof-of-principle lab demonstrations to in-field implementations and technological prototypes. We start by reviewing the theoretical protocols and the current security status of these protocols. Then, we discuss the system structure, the key module, and the mainstream system implementations. The advanced progress for future applications are discussed, including the digital techniques, system on chip and point-to-multipoint system. Finally, we discuss the practical security of the system and conclude with promising perspectives in this research field.
I. INTRODUCTION
CV-QKD using coherent states has advanced through protocol and security developments toward robust, telecom-compatible systems and future network applications. This review surveys the protocols, system architectures, implementations, digital and chip-based techniques, and practical-security considerations underlying that progression.
- Motivation: CV-QKD using coherent states benefits from compatibility with telecom components such as continuous-wave lasers and coherent receivers.This compatibility has supported advances in protocol design, security analysis, and implementation.
- Theoretical progress: Security proofs progressed from asymptotic Gaussian-modulated coherent-state protocols to finite-size security against collective attacks.
- System evolution: CV-QKD implementations progressed from proof-of-principle demonstrations to high-performance, robust systems and a modern architecture compatible with classical optical coherent communication.
- System evolution: Reverse reconciliation overcame the initial 3 dB limit, while improved reconciliation enabled long-distance transmission from 25 km to 80 km.In-line LO systems suppress phase noise by generating the quantum signal and LO from the same transmitter laser, but strong-LO crosstalk remains a challenge.
- System evolution: Generating the LO inside the receiver with pilot-assisted phase recovery relaxed the need for extremely high isolation and enabled frequency-division multiplexing.The alternative architecture reduces the need for high-extinction time-division pulses and can also use polarization multiplexing.
- Future applications: Digital techniques, chip-based detectors, and point-to-multipoint networking support higher-speed, more compact, and more scalable CV-QKD systems.Chip-based homodyne detection has reached 10 GBaud, while downstream point-to-multipoint systems support multiuser access with low-cost devices and simplified network structures.
- Review scope: The review covers CV-QKD principles, protocols and security analysis, system structures and key modules, mainstream implementations, future applications, and practical security.
B. A historical outline of CV-QKD protocols and the current security status
CV-QKD protocols evolved from squeezed-state proposals to coherent-state and varied modulation, measurement, and architecture choices. Security analyses cover standard, two-way, MDI, and SDI approaches, while practical systems remain separated from ideal theoretical limits by implementation constraints.
- Protocol evolution: The 1999 squeezed-state proposal was followed by the 2002 GG02 coherent-state protocol, whose laser-generated states encouraged further development.The no-switching protocol and Gaussian-modulated coherent-state variants subsequently expanded the protocol family.
- Protocol evolution: Discrete modulation was proposed because ideal Gaussian modulation presents technical experimental challenges.The four-state protocol used a QPSK-like modulation, followed by proposals for multidimensional discrete modulation.
- Protocol families: Standard one-way protocols are classified by quantum state, modulation, or measurement, while two-way, MDI, and source-device-independent protocols address other application scenarios.The review also discusses passive protocols using thermal states.
- Security status: One-way and two-way protocols are theoretically secure only with trustworthy equipment, motivating semi-device-independent approaches because comprehensive device independence remains challenging.Semi-device-independent protocols include MDI and SDI schemes that eliminate certain reliability assumptions.
- Security status: MDI protocols remove assumptions about selected device reliability, with CV-MDI sending coherent states to an untrusted party for Bell-state measurement.The untrusted party can be controlled by Eve, addressing detector loopholes.
- Security status: Ideal CV-QKD protocols approach the PLOB bound, but practical systems remain constrained by reconciliation efficiency below 100% and modulation variance below 5.These constraints leave room for improving practical performance and for protocols that approach the theoretical limit more closely.
- Security analysis: The PM and EB schemes are equivalent but serve different roles: PM supports experimental implementation, whereas EB facilitates theoretical analysis.In the EB representation, heterodyne or homodyne detection on one EPR mode projects the other mode onto a coherent or squeezed state.
- Security analysis: Reverse reconciliation overcomes the 3 dB loss limit of direct reconciliation by correcting modulation data to detection data.This distinction is central to the reconciliation procedures used in CV-QKD.
1. Gaussian-modulated protocol
Gaussian-modulated protocols are foundational CV-QKD schemes, especially those using coherent states generated by off-the-shelf lasers. Their security analysis evaluates secret-key rates from mutual information, Eve’s Holevo information, and covariance-matrix symplectic eigenvalues under the relevant detection and reconciliation choices.
- Protocol structure: Gaussian-modulated protocols are categorized by coherent or squeezed states and homodyne or heterodyne detection.Gaussian-modulated coherent-state protocols receive particular attention because they can use off-the-shelf lasers.
- Key-rate criterion: A positive secret key rate indicates that Alice and Bob can distill a secret key under the considered attack; otherwise, the protocol is ineffective.The asymptotic reverse-reconciliation rate is the principal security indicator described here.
- Key-rate calculation: The reverse-reconciliation key rate combines Alice–Bob mutual information with a bound on Eve’s accessible information.Mutual information is estimated from modulation and detection data, while Eve’s information is bounded by the Holevo quantity.
- Key-rate calculation: The channel-added noise χline = 1/T −1 + ε depends on transmittance T and excess noise ε, expressed in shot-noise units.These channel parameters enter the calculation alongside variances and conditional variances associated with the received and inferred states.
- Security analysis: Gaussian extremity provides an upper bound on χBE and therefore a lower bound on the secret key rate.The bound is evaluated through symplectic eigenvalues of covariance matrices for the joint and conditionally measured states.
- Security analysis: The covariance matrix is estimated from modulation and detection data, and symplectic eigenvalues are obtained from the covariance matrix and measurement operation.The review summarizes analytical cases for homodyne and heterodyne detection, including Moore–Penrose pseudoinverse handling where required.
2. Discrete-modulated protocol
Discrete-modulated CV-QKD security analysis evolved from linear-channel assumptions to methods that no longer require them, including uncertainty-principle, semidefinite-programming, and entropy-based approaches. These frameworks bound eavesdropping and support secret-key-rate estimation, while auxiliary-mode methods extend covariance-based analysis to arbitrary discrete modulation formats.
- Motivation: Discrete modulation was motivated partly by Gaussian-variable error-correction limitations that restricted a system to less than 30 km.The proposed discrete-modulated protocol reduces the error-correction requirement at low signal-to-noise ratio.
- Security assumptions: Early security proofs assumed a linear channel because discrete modulation could not directly provide the covariance term Z.Without this assumption, worst-case secret-key-rate estimation for the unknown Z becomes zero.
- Security advances: Since 2018, improved proofs no longer require linear channel assumptions and bound eavesdropping using uncertainty principles, semidefinite programming, or entropy methods.The secret-key rate is obtained by searching for a lower bound.
- Security analysis methods: Auxiliary-mode entanglement-based analysis enables covariance-matrix security methods for arbitrary discrete modulation formats.The review reports that 256 QAM with Gaussian probability shaping performs close to Gaussian modulation, while 64 QAM supports transmission beyond 100 km.
- Rate calculation: The asymptotic secret-key rate combines Alice–Bob mutual information with reconciliation efficiency and an upper bound on Eve’s information.The security calculation uses an optimization feasible set constrained by experimental observations.
- Security analysis methods: Semidefinite-programming analyses formulate security estimation as optimization over states constrained by modulation and detection statistics.The framework can analyze QPSK and extend in principle to higher-order formats, although one approach is limited by high computational-resource demands.
3. Practical protocol with trusted noise
Trusted-noise analysis models detector imperfections through detection efficiency and electronic noise within an entanglement-based representation. The resulting covariance-matrix treatment incorporates detector-added noise into total channel noise and the bounds used for secret-key-rate analysis.
- Detector model: Practical detection efficiency and electronic noise increase the effective channel loss and excess noise.A trusted detector noise model can relax degradation caused by these imperfections.
- Detector model: Trusted detector imperfections are modeled by an entanglement-based covariance-matrix construction involving an auxiliary EPR-state mode.The analysis uses covariance matrices containing the detector and channel modes.
- Detector model: The detector is characterized by efficiency η and electronic noise νele, with η represented by a beamsplitter transmittance.For heterodyne detection, the electronic-noise contribution is replaced by 2νele.
- Noise accounting: Detection-added noise χh contributes to total input-referred noise as χtot = χline + χh/T.The same practical-protocol mutual-information expressions are used after replacing χline with χtot.
- Security analysis: The security analysis derives Eve’s information bound from symplectic eigenvalues of covariance matrices for homodyne and heterodyne scenarios.The relevant eigenvalues are associated with γAB and a conditional covariance matrix involving detector modes.
III. CV-QKD SYSTEM AND KEY MODULE
A CV-QKD system combines optical transmission, monitoring, synchronization, randomness generation, calibration, digital signal processing, and postprocessing. Its implementation is organized around in-line-LO or local-LO architectures and increasingly capable QRNG and digital subsystems.
- System architecture: CV-QKD systems are categorized mainly as in-line-LO or local-LO architectures, distinguished by whether the local oscillator is generated inside the receiver.The two structures differ in how the optical reference is supplied and managed.
- System architecture: The transmitter and receiver handle optical encoding and decoding, while monitoring, synchronization, DSP, calibration, and postprocessing support key extraction.SNU calibration links practical detector outputs to theoretical security analysis.
- Quantum random number generation: QRNGs provide true random numbers for modulation, detection-basis selection, and postprocessing operations.The review distinguishes practical, semi-device-independent, and device-independent QRNGs, as well as discrete- and continuous-variable types.
- Quantum random number generation: 100 Gbps is the reported generation rate for a vacuum-noise QRNG implemented with photonic integrated circuits.The implementation uses a laser source and homodyne detector, supporting high speed, compactness, and scalability.
- Quantum random number generation: Uniform QRNG outputs require transformation into Gaussian-distributed random numbers when Gaussian modulation is used.Discrete modulation can avoid this continuous-variable random-number transformation because it replaces Gaussian modulation.
B. Transmitter
The transmitter prepares modulated quantum states and multiplexes them with classical auxiliary signals, using laser, modulation, attenuation, and monitoring components. Gaussian and discrete formats generally require two-quadrature control, while unidimensional and PSK formats simplify modulation requirements.
- Transmitter architecture: The transmitter comprises a laser source, modulation module, and monitoring module for preparing quantum and auxiliary optical signals.The laser may operate in pulsed or continuous-wave form, and the transmitter multiplexes LO or pilot signals with the quantum signal.
- Laser source: Continuous-wave lasers became attractive because increasing repetition frequency makes simultaneous high extinction ratio and repetition rate difficult for pulsed sources.Local-LO architectures also reduce crosstalk and relax the need for extremely high isolation.
- Modulation formats: Two-dimensional encoding uses either separate phase and amplitude modulators or an IQ modulator.For IQ modulation, the in-phase and quadrature data correspond to the x and p phase-space quadratures and follow normal distributions for Gaussian modulation.
- Modulation formats: Gaussian and discrete modulation displace coherent states along both phase-space quadratures, whereas unidimensional modulation uses only one quadrature.PSK discrete modulation requires only phase modulation, while unidimensional modulation can use a single amplitude modulator.
- Practical constraints: Imperfectly adjusted modulators can increase excess noise and open security loopholes.The two main modulation methods also require different acquisition procedures.
- Power control: The average quantum-signal power is attenuated to a few-photon level because practical devices cannot reliably measure quantum characteristics of high-power states.Variable optical attenuators can also independently adjust frame-signal and quantum-signal powers.
- Auxiliary signals: Classical frame signals provide synchronization and phase-compensation information, while pilot tones or LOs support reference recovery.Quantum and classical signals may be multiplexed using time, polarization, or frequency division.
3. Transmitter Monitoring
Transmitter monitoring estimates the prepared quantum state and helps detect injected-light attacks and source fluctuations before transmission. Receiver-side monitoring and compensation then preserve signal quality and alignment through detection.
- Source monitoring: Source monitors use an optical switch or beamsplitter to sample the modulated signal before it enters the quantum channel.The monitor may use homodyne or heterodyne detection, while Gaussian modulation also permits optical-power monitoring.
- Source characterization: VM = 2Pout/(hν frep) converts measured output power into the modulation variance used for state preparation and security analysis.The relation follows from the average photon energy hν and pulse repetition frequency frep.
- Source characterization: Monitoring source noise can tighten channel-parameter estimation because attributing uncontrolled source noise entirely to Eve overestimates Eve’s power.Laser fluctuation and imperfect modulation introduce source noise, which can undermine the secret key rate.
- Practical security: Injected-light monitoring uses a circulator to direct Trojan-horse light toward a homodyne detector or optical power meter.This structure helps resist strong-light attacks that open transmitter side channels.
- Receiver monitoring and compensation: Receiver monitoring tracks LO or pilot-tone wavelength, frequency, power, and amplitude, while demodulation compensates polarization, phase, multiplexing, and synchronization effects.Digital compensation is increasingly used in continuous-wave systems, paralleling integrated coherent optical receivers.
3. Detection
CV-QKD detection relies on balanced homodyne or heterodyne measurement of optical quadratures. Detector bandwidth, efficiency, electronic noise, and QCNR determine practical performance, while photonic integration extends bandwidth and compactness.
- Homodyne detection: Homodyne detection interferes the quantum signal and LO at a 50:50 coupler and outputs their photodiode differential current.A phase modulator switches the measured basis so both quadratures can be statistically characterized.
- Heterodyne detection: Heterodyne detection combines two homodyne detectors to measure both x and p quadratures simultaneously.A π/2 phase shift in one LO path enables simultaneous quadrature detection, with digital or analog down-conversion also possible.
- Detector performance: Bandwidth, detection efficiency, electronic noise, and QCNR are the key practical parameters of homodyne detectors.Bandwidth shapes multiplexing and processing settings, while detection efficiency corresponds to detector parameter η.
- Chip-based detection: Chip-based homodyne detectors reach a 3 dB bandwidth above 1.5 GHz, 28 dB shot-noise clearance, and 80 dB common-mode rejection ratio.The core integration challenges are balanced photonic circuits, efficient photodiodes, and low-noise transimpedance amplifiers.
- Detector calibration: Measurement power density distinguishes electronic noise from the combined electronic and shot-noise level used in practical detector characterization.SNU denotes the variance of shot noise, while Vd and Vele denote total-noise and electronic-noise variances.
D. Shot noise unit calibration
SNU calibration maps electrical detection data into normalized phase-space variables while accounting for electronic noise. One-time calibration simplifies operation and enables real-time tracking, but treats electronic-noise loss as untrusted and slightly lowers performance.
- Conventional calibration: SNU is the shot-noise variance used to normalize practical electrical measurements of coherent-state detection data.Electronic noise must be calibrated because it is inevitably added to practical measurements.
- Conventional calibration: Conventional calibration independently measures electronic noise and total noise, then uses their difference to obtain SNU.The calibrated output supports a trusted detector model containing detection efficiency and normalized electronic noise.
- Calibration limitations: Pre-calibration can become insecure when LO power and electronic noise drift with time or temperature during operation.Real-time monitoring is therefore needed because SNU fading can create security issues.
- One-time calibration: One-time SNU calibration obtains SNU by measuring total noise, significantly simplifying the calibration procedure.The improved security analysis redefines SNU so electronic-noise measurement is not required repeatedly.
- One-time calibration: Real-time SNU calibration monitors split-LO power instead of constantly measuring electronic noise.The method has been adopted in experimental demonstrations, although its electronic-noise loss is treated as untrusted.
E. Digital signal processing
Digital signal processing increasingly replaces optical compensation and coordinates waveform generation, synchronization, equalization, and frame recovery. Postprocessing then converts correlated measurements into secret keys through sifting, estimation, reconciliation, and privacy amplification.
- DSP architecture: DSP maximizes transmitter–receiver data correlation through clock synchronization, static and dynamic equalization, and frame synchronization.Its role expanded from optical-layer feedback in early systems to broad transmitter and receiver processing in high-speed local-LO systems.
- Transmitter processing: Transmitter DSP performs upsampling, RRC pulse shaping, frequency shifting, pilot insertion, and frame synchronization-sequence insertion.The sequence is used to support bounded-bandwidth quantum pulses, phase reference, and frame alignment.
- Receiver processing: Receiver DSP separates multiplexed signals, down-converts quantum data, synchronizes clocks, and applies static and dynamic equalization.Machine learning has been introduced for phase estimation across a wide range of pilot SNRs.
- Postprocessing: Postprocessing applies sifting, parameter estimation, information reconciliation, and privacy amplification after quantum transmission and detection.Alice and Bob use an authenticated channel and then verify the resulting key material.
- Postprocessing: Heterodyne detection can remove basis sifting by retaining both quadratures, simplifying postprocessing compared with homodyne detection.Parameter estimation uses modulation and detection data to estimate security parameters and secret-key rates, including finite-size effects.
3. Information reconciliation
Information reconciliation maps continuous-variable outcomes into shared bit strings and corrects errors, but public information leakage makes efficiency below 100%. Its strategy strongly affects secret-key rate and distance, with multidimensional reconciliation enabling operation at very low SNR.
- 3. Information reconciliation: Information reconciliation maps quadrature results to bits and applies error correction so Alice and Bob obtain the same bit string.Practical reconciliation publicly transmits information, causing secret-information leakage and efficiency below 100%.
- 3. Information reconciliation: Reconciliation efficiency affects both the final secret-key rate and maximum transmission distance, so optimization must balance whole-system performance.The relevant quantities include Shannon information, public leakage, and Alice–Bob mutual information.
- 3. Information reconciliation: Direct reconciliation cannot exceed the 3 dB limit, whereas reverse reconciliation enables operation beyond that limit and became the common approach.Direct reconciliation corresponds to about 15 km of fiber transmission in the described setting.
- 3. Information reconciliation: Slice reconciliation suits SNR above 0 dB, while multidimensional reconciliation targets SNR below 0 dB and can operate down to -26 dB.Multidimensional reconciliation converts the Gaussian-variable problem into discrete-variable channel coding and can use LDPC or Raptor codes.
- 3. Information reconciliation: LDPC codes are commonly used at low SNR, with decoding throughput reaching 1.44 Gbps and 0.78 Gbps at code rates 0.2 and 0.1.These rates support real-time secret-key generation at 71.89 Mbps over 25 km and 9.97 Mbps over 50 km.
- 3. Information reconciliation: Privacy amplification applies a universal hash function after error correction to distill the final secret key, including finite-size operation through leftover hashing.Toeplitz matrices are identified as a common implementation.
A. In-line LO systems
In-line LO systems generate the quantum signal and local oscillator from the same laser, using multiplexing to control their large power disparity. Their development progressed from early demonstrations to long-distance, field-tested systems with increasingly effective reconciliation and noise control.
- A. In-line LO systems: In-line LO systems co-generate the quantum signal and local oscillator, but LO leakage is a major noise source because of their large power difference.Time-, polarization-, and frequency-division multiplexing separate the signals during transmission and reception.
- Early systems: The 2003 first CV-QKD implementation achieved 1.7 Mbps without loss and 75 kbps with 3.1 dB loss using reverse reconciliation.It used a 780 nm free-space setup with Gaussian modulation and a shared laser for the quantum signal and LO.
- Early systems: The first all-fiber system in 2007 achieved 2 kbps over 25 km with 5.2 dB loss by co-transmitting the quantum signal and LO.Time-division multiplexing reduced phase-noise accumulation from separate transmission paths.
- Early systems: Polarization and frequency multiplexing produced 70 dB isolation and a 0.3 bit/pulse secret-key rate over 5 km.The two signals were separated by polarization and frequency at the receiver.
- Long-distance achievements: Multidimensional reconciliation raised reconciliation efficiency from no more than 90% to 95%, supporting over 100 bps at 80 km in 2013.The system combined polarization and time-division multiplexing with trusted detection noise and active polarization control.
- Long-distance achievements: The transmission record reached 202.81 km in 2020, doubling the previous distance record, while later field demonstrations covered 49.85 km and 71.03 km links.A metropolitan demonstration achieved an average secret-key rate above 12.00 kbps over 71.03 km.
4. Systems on chip
CV-QKD systems are moving toward compact chip-based and digitally processed architectures. Silicon photonics integrates major optical functions, while local-LO systems use DSP and modulation formats suited to practical, cost-sensitive deployment, although LO-access security remains a limitation for in-line architectures.
- 4. Systems on chip: Photonic integrated circuits can miniaturize CV-QKD systems and support lower-cost mass production as production volume increases.The review presents chipization as a route toward scalable, cost-sensitive systems.
- 4. Systems on chip: The first chip-based platform integrated phase and amplitude modulators, a variable optical attenuator, and a homodyne detector on a silicon-on-insulator chip.The system demonstrated an in-line LO architecture using chip-based polarization multiplexing and demultiplexing.
- 4. Systems on chip: Chip-based homodyne detection limited the demonstrated platform to 10 MHz bandwidth, despite 200-MHz modulation capability.The limitation was mainly attributed to the two-stage transimpedance amplifier.
- Practical security: In-line LO architectures retain a security loophole because an eavesdropper can manipulate the transmitted LO and cause secret-key-rate overestimation.Monitoring the LO can defend against some attacks, but the loophole remains.
- B. Local LO systems: Continuous-wave local-LO systems use DSP, pilot tones, and modulation structures resembling classical coherent communications.One system achieved 6 × 10^-3 bit/symbol at 40 km using discrete modulation and digital heterodyne detection.
- Systems with continuous-wave light: A 16-order two-ring phase-shift-keying system achieved 49.02 Mbps, 11.86 Mbps, and 2.11 Mbps over 25 km, 50 km, and 80 km.These values corresponded to 67.4%, 70.0%, and 66.5% of Gaussian-modulated performance, respectively.
4. Recent progresses
Recent CV-QKD progress spans high-rate, composably secure, long-distance, classical-coexistence, free-space, and digitally processed systems. These developments support future compact integration and point-to-multipoint quantum access networks.
- High-rate and long-distance systems: Local-LO CV-QKD achieved 233.87 Mbps, 133.6 Mbps, and 21.53 Mbps secret key rates at 5 km, 10 km, and 25 km, respectively.The system used 4-state discrete modulation, frequency and polarization multiplexing, and digital heterodyne detection.
- High-rate and long-distance systems: Composable-security CV-QKD achieved 0.0471 bits/symbol at 20.3 km while generating composable keys from 2×10^8 coherent states.The implementation used an IQ modulator and digital heterodyne detector.
- High-rate and long-distance systems: Local-LO CV-QKD extended transmission beyond 100 km, reaching 7.55 Mbps, 1.87 Mbps, and 0.51 Mbps at 50 km, 75 km, and 100 km.The results demonstrate simultaneous progress toward long-distance and high-speed QKD using telecom devices.
- Coexistence with classical signals: CV-QKD has been demonstrated alongside classical channels, tolerating 11.5 dBm forward and 9.7 dBm backward classical-channel noise over 25 km, while another system supported 18.3 Tbps data channels.A separate multiplexed system achieved 90 kbps over 20 km with 2 mW optical power under ideal QKD conditions.
- Free-space systems: Free-space CV-QKD addressed atmospheric disturbances through phase compensation and related techniques, achieving 1.015 Mbps at a simulated −15 dB channel transmittance.Atmospheric fading, beam wandering, and excess noise remain important practical constraints.
- Future directions: Future systems are expected to combine full-scale DSP and photonic-chip integration with point-to-multipoint architectures for high-speed quantum access networks.Digital processing security has also received formal attention, including security proofs for linear DSP algorithms.
B. Chip-based local LO systems
Chip-based local-LO systems target compact, stable, scalable CV-QKD implementations, while point-to-multipoint protocols address access-network deployment. Progress includes integrated receivers, transmitters, lasers, multiuser estimation, and parallel key distillation.
- Chip-based local LO systems: Photonic integration is being pursued to improve local-LO CV-QKD stability, scalability, and cost-effective large-scale deployment.The main fabrication platforms are Silicon-On-Insulator and III-V technologies.
- Chip-based local LO systems: A Silicon-On-Insulator receiver reached 250 MHz bandwidth and achieved 280 kbps secret key rate under 1.38 dB untrusted loss.The receiver had 0.26 overall detection efficiency and excess noise of 0.1102 at Alice’s side.
- Chip-based local LO systems: Silicon integration faces low optical coupling efficiency and lacks a high-performance integrated light source, limiting detection efficiency and full integration.Device optimization can address coupling loss, whereas integrated lasers require III-V or heterogeneous integration approaches.
- Chip-based local LO systems: On-chip external-cavity lasers enabled 0.75 Mbps secret key rate within 50 km fiber with excess noise controlled at 0.0579.The review identifies integrated light sources as the remaining obstacle to fully chip-based CV-QKD and points to III-V integration as a solution path.
- Point-to-multipoint systems: Point-to-multipoint access networks must address splitter-induced channel loss and upstream user separation, motivating multiuser protocols over passive optical networks.The protocol jointly estimates channel parameters across users and calculates secret-key rates from the resulting covariance matrix.
- Point-to-multipoint systems: Parallel key distillation allows all users to generate independent keys with the sender simultaneously, increasing the overall network secret-key rate.A high-rate access network uses multiplexed quantum and pilot signals with heterodyne detection at the receivers.
VI. PRACTICAL SECURITY
Practical CV-QKD security requires addressing device imperfections that create attack surfaces, while balancing countermeasure effectiveness against implementation cost. The review surveys attack-specific defenses, semi-device-independent approaches, and experimental progress toward secure metropolitan networks.
- Security vulnerabilities: Practical CV-QKD devices are imperfect, so attacks can exploit source, detector, local-oscillator, and other security loopholes.Theoretical security commonly assumes trusted devices, whereas practical optical and electrical components introduce imperfections.
- Security vulnerabilities: Local-LO architectures avoid attacks on transmitted local oscillators but expose the unsecured pilot tone to attacks such as reference-pulse manipulation.Generating the local oscillator inside the receiver removes one vulnerability while introducing a separate pilot-tone attack surface.
- Countermeasures: Countermeasures include monitoring, optical isolation, detector protection, filtering, and real-time local-oscillator monitoring against source, detector, and wavelength attacks.The review describes defenses including isolators, source-monitoring detectors, detector safeguards, and filters.
- Countermeasure evaluation: Countermeasure evaluation must weigh defense effectiveness against equipment price, integration difficulty, technical complexity, computational power, and sacrificed raw keys.The review explicitly frames practical defense cost across hardware, implementation, computation, and postprocessing requirements.
- Device-independent approaches: Device-independent protocols remove device-security assumptions but face loophole-free Bell-test requirements and low key rates, motivating semi-device-independent compromises.CV-SDI and CV-MDI protocols retain trust assumptions for some components while seeking higher practical performance.
- Experimental progress: CV-MDI QKD uses an untrusted third-party detector, and fiber implementation reached 0.19 bit/pulse over 10 km using phase control and 99% efficient detection.The fiber demonstration used optical phase locking, phase estimation, real-time feedback, quadrature remapping, and a free-space time-domain homodyne detector.
- Outlook: The review concludes that high-performance CV-QKD networks remain promising, but future systems must improve integration, speed, distance, and practical security.The broader outlook links system advances with metropolitan and access-network deployment and emphasizes unresolved implementation challenges.