Source-linked AI summary
A Loss-Robust Disturbance Certificate for Minimal-Receiver Quantum Key Distribution
Roberto Di Pietro
TL;DR
Deployed QKD is vulnerable to receiver-side attacks, and single-detector BB84 lacks a detection theory for conclusive zero-probability events. The paper introduces a loss-robust orthogonal-click certificate and analyzes its soundness, completeness, finite-size behavior, and implementation. Four BB84 states yield an ideal trip probability of 1/4 per orthogonal round, with numerical verification and quantified detector-noise and hardware trade-offs.
Problem
Receiver-side attacks exploit which detector clicks, while single-detector BB84 lacks a detection theory for conclusive zero-probability events.
Method
The paper uses a single-polarizer, single-detector receiver and certifies disturbance through sampled orthogonal rounds where an ideal click has zero probability.
Results
Four BB84 states give an ideal trip probability of 1/4 per orthogonal round, observed as η/4, for fixed-basis projective intercept-resend attacks independent of interception angle.
Takeaways & Limitations
The certificate provides a conclusive, loss-robust disturbance alarm for minimal-detector polarization QKD and lowers the hardware entry barrier for security-monitored edge networks.
Takeaways & Limitations
The certificate relies on trusted-device assumptions because detector blinding can induce orthogonal clicks and forge trips.
Abstract
from arXiv · showhide
Quantum Key Distribution (QKD) enjoys information-theoretic security, yet the most damaging attacks against deployed systems exploit the receiver, where the key bit is encoded in which one of a pair of never-identical detectors clicks. The minimal receiver, one rotatable polarizer and one threshold detector, removes that attack surface, and single-detector BB84 demonstrations already run sampled error estimation; the structure of its zero-probability error subensemble, however, has remained uncharacterized. We characterize exactly that structure, introducing a deterministic impossible-event certificate: a click behind a polarizer set orthogonal to the transmitted state has probability exactly zero on an ideal channel, so a single occurrence is a probability-one witness of disturbance; and, since loss deletes clicks and never creates them, the certificate is loss-robust. We prove it sound but incomplete over three polarization states, and show that the four BB84 states close the gap: a fixed-basis intercept-resend attack yields an ideal trip probability of $1/4$ per orthogonal round ($η/4$ observed at detection efficiency $η$), independent of the interception angle. An illustrative finite-size budget yields 256 retained bits from $\approx 62{,}000$ transmitted rounds at $η= 0.1$; under realistic detector noise ($q_0 = 10^{-6}$ per opened gate), each trip retains $\approx 12$ bits of evidence at a sub-percent honest false-abort probability per session. The core ideal trip-probability predictions are numerically verified on the Qiskit circuit simulator, via a released, seed-fixed implementation. Overall, by endowing the minimal-detector receiver of polarization QKD with a conclusive, loss-robust disturbance alarm, our solution lowers the hardware entry cost of security-monitored QKD, hence fostering its adoption at the cost-sensitive network edge.
I. INTRODUCTION
The paper targets receiver-side attacks and the deployment cost of multi-detector QKD. It introduces a loss-robust certificate based on conclusive zero-probability events in a single-detector receiver.
- Motivation: One detector can reduce receiver cost and calibration burden for cost-sensitive quantum-network endpoints.The paper identifies detector count as a first-order driver of network economics.
- Research gap: Single-detector BB84 demonstrations already use sampled error estimation, but lack a detection theory for conclusive zero-probability events.The paper presents this missing theory and experimentally shows its viability.
- Motivation: Receiver-side attacks exploit the detector pair because the key bit is encoded in which imperfect detector clicks.The cited attacks include time-shift, faked-state, blinding, and detector-efficiency-mismatch attacks.
- Contribution: An orthogonal click is impossible on an ideal channel, so one trip is a probability-one disturbance witness that loss cannot forge.Loss can delete clicks and slow detection, but cannot create an observed trip.
- Contribution: The paper analyzes completeness over three and four polarization states and estimates finite-size costs with dark-count and leakage corrections.The four-setting result gives an ideal trip probability of 1/4 per orthogonal round, while the finite-size analysis includes a structural factor two versus BB84.
II. RELATED WORK
Related work establishes single-detector QKD implementations and several detector-side countermeasures, but does not provide the paper’s conclusive detection theory. The paper positions its certificate between lower-hardware single-detector designs and higher-infrastructure measurement-device-independent QKD.
- Single-detector BB84: Single-detector BB84 demonstrations use conventional sampled error estimation but do not isolate orthogonal zero-probability events as per-event certificates.The cited demonstrations include variable-Faraday-rotator and decoy-state implementations.
- Single-detector BB84: Time-multiplexed single-detector designs relocate bit encoding to time slots, preserving a time-shift attack surface.The attack applies when the detector’s possible click time carries the bit value.
- Four-state Bob: Bit-assignment randomization suppresses detector-efficiency mismatch but leaves standard QBER monitoring on a basis-resolving receiver.The remaining gap is detection theory for a receiver without basis-resolving optics.
- MDI-QKD: MDI-QKD removes detector trust through an untrusted Bell-state-measuring relay, requiring strictly more infrastructure than the single-detector receiver.The single-detector certificate instead removes the inter-detector attack surface but not attacks on the detector itself.
- B92: Single-detector B92 supplies the closest physical ancestor, but uses the impossible event for key generation rather than disturbance certification.Its announcement structure also anticipates the present receiver’s hidden-setting sifting.
III. THE RECEIVER AND THE CERTIFICATE
The receiver records pass or no-pass using one rotatable polarizer and one threshold detector, with Bob’s angle encoding the raw bit. Orthogonal clicks form a loss-robust certificate whose soundness holds under trusted-device channel attacks, while detector blinding remains outside its protection.
- The receiver: The honest pass probability is η cos^2(θA−θB), where η is end-to-end detection efficiency.η is the probability that a transmitted photon yields a click when Bob’s polarizer is aligned with Alice’s state.
- The certificate: An orthogonal round has |θA−θB| = 90°; a pass is a trip with honest probability exactly zero at every η.Loss can suppress evidence but cannot fabricate a trip.
- Sifting protocol: The sampled protocol commits Bob’s detection record, reveals bases, tests a random same-basis subset, and discloses exact angles only on test rounds.Undisclosed same-basis detected rounds retain their bits as sifted key.
- Soundness: Soundness follows from the honest zero probability and holds against arbitrary quantum-channel attacks in the trusted-device model.The cited scope includes individual, collective, and coherent attacks.
- Scope boundary: Detector blinding can induce an orthogonal click and forge a trip, so the certificate does not remove attacks on the detector itself.The paper treats detector-blinding countermeasures as complementary requirements for deployment.
IV. THREE STATES ARE INCOMPLETE FOR THE PROPOSED CERTIFICATE
The certificate is sound but incomplete with three polarization states because an eigenbasis intercept-resend attack can avoid trips. Adding the fourth BB84 state closes this gap, fixing the ideal trip probability at 1/4 per orthogonal round for every interception angle.
- Three-state incompleteness: Three states yield trip probability 1/2 sin^2(2∆), which vanishes when the adversary measures at ∆ = 0° or 90°.At either rectilinear eigenbasis, the adversary reads every rectilinear key bit and never trips the certificate.
- Three-state incompleteness: The three-state certificate is sound but incomplete: a trip proves disturbance, yet an eigenbasis attack produces no trips.The 45° check states then require a statistical test rather than the loss-robust certificate.
- Four-state closure: Four BB84 states create orthogonal rounds in both bases, eliminating every safe measurement direction through averaging.The cancellation follows from sin^2 x + cos^2 x = 1.
- Four-state closure: 1/4 is the four-state ideal trip probability per orthogonal round for every fixed interception angle ∆.This is BB84’s 25% intercept-resend disturbance restricted to orthogonal rounds.
- Operational interpretation: The certificate statistic coincides with sampled matched-basis error counting, but its zero-count regime provides a zero-false-positive alarm in the ideal model.The honest trip probability remains zero regardless of η, alignment, or channel loss; detector background q0 sets false alarms.
V. NUMERICAL VERIFICATION ON THE QISKIT CIRCUIT MODEL
The analytic certificate predictions were translated into executable two-qubit circuits and independently checked on the Qiskit simulator. Seed-fixed simulations reproduced the zero honest-trip rate and the angle-independent four-state trip probability.
- Circuit model: The two-qubit circuit models state preparation, deferred-measurement intercept-resend, polarizer rotation, and threshold detection.Deferred measurement entangles the signal with an ancilla and traces the ancilla out to reproduce the adversary’s measurement channel.
- Honest-round validation: 1.6 million honest orthogonal-round trials produced zero trips across all four BB84 states.The result matches the ideal impossible-event prediction at the circuit level.
- Detection budget: 1,375 rounds are required for 2^-128 escape probability in dedicated-test operation, compared with 665 for BB84.The certificate’s factor-of-two cost reflects its loss-robust, zero-ideal-channel-false-positive event class.
- Attack-model validation: 0.2500 was the simulated four-state trip probability across the entire interception-angle grid.The worst-case deviation from 1/4 was below 3 × 10^-4, with ten-seed standard errors below 5 × 10^-4.
- Attack-model validation: The three-state simulator reproduced zero trips at eigenbasis angles ∆ ∈ {0°, 90°}.The event-by-event reproduction confirms the completeness failure motivating the fourth state.
VI. DEPLOYMENT: PHOTONS, HARDWARE, AND REAL DETECTORS
Deployment requires twice the photon budget of BB84, while detector noise turns the ideal certificate into a statistical witness whose evidence and false-abort rates remain quantifiable. Hardware savings are strongest for independently packaged APD channels and shrink with shared-cryostat SNSPDs.
- Photons: 2× the photon budget is required because disclosed certificate rounds reduce retained detections relative to BB84.The test fraction gives n⊥ = τN/4 and nraw ≈ (1 −τ)ηN/4, versus BB84’s ηN/2 before test sacrifice.
- Photons: 256 retained bits result from approximately 62,000 transmitted rounds at τ = 1/2, η = 0.1, and ε = 2^-64 under the intercept-resend model.The example has n⊥ = 7,750, bounds the attacked fraction by f ≤ 0.23, and obtains nraw ≈ 775 before finite-key deductions.
- Real detectors: q0 ≃ d + ηξ captures honest trips from dark counts and orthogonal leakage, replacing the ideal zero-background certificate with a statistical witness.The false-abort probability under the single-trip rule is at most n⊥q0.
- Real detectors: ≈12 bits of evidence per trip arise at f = 0.2, η = 0.1, and q0 = 10^-6, while a two-trip rule reduces the honest false-abort probability below 10^-4.The likelihood ratio is approximately 2^12 under the independent-background composition.
- Hardware: APD-based receivers gain the largest cost advantage because removing detector modules removes independently packaged cooling and quenching hardware.With SNSPDs, a shared cryostat makes additional channels comparatively inexpensive, shrinking the minimal receiver’s advantage.
VII. CONCLUSION AND FUTURE WORK
The paper concludes that a single-polarizer, single-detector receiver can provide a conclusive, loss-robust disturbance alarm with quantified deployment costs. Its quantitative security beyond intercept-resend, weak-coherent implementation, and broader composability remain open.
- VII. CONCLUSION AND FUTURE WORK: A single orthogonal-round trip proves disturbance, and four BB84 states give an ideal trip probability of 1/4 per orthogonal round against fixed-basis intercept-resend.The guarantee costs a factor of two in photons and remains worth roughly a dozen bits of evidence per trip under real detectors.
- VII. CONCLUSION AND FUTURE WORK: Approximately 62,000 transmitted rounds yield more than 256 retained bits at η = 0.1 and τ = 1/2 under the specified intercept-resend model.At q0 = 10^-6, the honest false-abort probability is below one percent with a single-trip rule and below 10^-4 when requiring a second trip.
- VII. CONCLUSION AND FUTURE WORK: The certificate lowers the hardware entry barrier for security-monitored QKD at cost-sensitive quantum-network edges.The conclusion ties the disturbance alarm to a quantified and modest cost.
- VII. CONCLUSION AND FUTURE WORK: Quantitative security against general collective or coherent adversaries is not yet established beyond the intercept-resend model.The open problem involves loss, postselection, and conditioning on detection in a quantum-instrument model.
- VII. CONCLUSION AND FUTURE WORK: The analysis assumes single-photon sources, leaving weak-coherent decoy-state extension for future work.The paper states that the per-round certificate structure should admit such an extension but does not develop it.