By endowing the minimal-detector receiver of polarization QKD with a conclusive, loss-robust disturbance alarm, the solution lowers the hardware entry cost of security-monitored QKD, hence fostering its adoption at the cost-sensitive network edge.
Abstract
Quantum Key Distribution (QKD) enjoys information-theoretic security, yet the most damaging attacks against deployed systems exploit the receiver, where the key bit is encoded in which one of a pair of never-identical detectors clicks. The minimal receiver, one rotatable polarizer and one threshold detector, removes that attack surface, and single-detector BB84 demonstrations already run sampled error estimation; the structure of its zero-probability error subensemble, however, has remained uncharacterized. We characterize exactly that structure, introducing a deterministic impossible-event certificate: a click behind a polarizer set orthogonal to the transmitted state has probability exactly zero on an ideal channel, so a single occurrence is a probability-one witness of disturbance; and, since loss deletes clicks and never creates them, the certificate is loss-robust. We prove it sound but incomplete over three polarization states, and show that the four BB84 states close the gap: a fixed-basis intercept-resend attack yields an ideal trip probability of $1/4$ per orthogonal round ($\eta/4$ observed at detection efficiency $\eta$), independent of the interception angle. An illustrative finite-size budget yields 256 retained bits from $\approx 62{,}000$ transmitted rounds at $\eta = 0.1$; under realistic detector noise ($q_0 = 10^{-6}$ per opened gate), each trip retains $\approx 12$ bits of evidence at a sub-percent honest false-abort probability per session. The core ideal trip-probability predictions are numerically verified on the Qiskit circuit simulator, via a released, seed-fixed implementation. Overall, by endowing the minimal-detector receiver of polarization QKD with a conclusive, loss-robust disturbance alarm, our solution lowers the hardware entry cost of security-monitored QKD, hence fostering its adoption at the cost-sensitive network edge.
Twin-field (TF) quantum key distribution (QKD) can overcome the fundamental rate-loss bound of repeaterless QKD, enabling secure communication over long distances. However, in practical implementations, its security relies on accurate intensity modulation, which may be compromised by source imperfections and light-injection attacks. In this work, we investigate the security of the NPP TF-QKD protocol in the presence of imperfect intensity modulation, focusing on Trojan-horse attacks and induced photorefractive attacks. By employing the reference technique, we establish a finite-key security proof that explicitly incorporates this source-side information leakage. Numerical simulations show that with realistic transmitter isolation, the NPP TF-QKD protocol can still surpass the rate-loss bound and achieve secret-key rates close to the ideal case. Our results further demonstrate strong robustness against modulation deviations induced by photorefractive effects. These findings confirm the practical security of TF-QKD under realistic source imperfections and provide quantitative guidance for the design of secure quantum communication systems.
Hua-Jian Ding, Chao Sun, Kai Pan et al.· Optics Express· 0 citations
Quantum Key Distribution (QKD) is a cryptographic solution that leverages the properties of quantum mechanics to be resistant and secure even against an attacker with unlimited computational power. Satellite-based links are important in QKD because they can reach distances that the best fiber systems cannot. However, links between satellites in low Earth orbit and ground stations have a duration of only a few minutes, resulting in the generation of a small amount of secure keys. In this context, we investigate the optimization of the information reconciliation step of the QKD postprocessing in order to generate as much secure key as possible. As a first step, we build an accurate model of the downlink signal and Quantum Bit Error Rate (QBER) during a complete satellite pass, which are time-varying due to three effects: 1 the varying link geometry over time; 2) the scintillation effect; and 3) the different signal intensities adopted in the Decoy-State protocol. Leveraging the a priori information on the instantaneous QBER, we improve the efficiency of information reconciliation (i.e., the error correction phase) in the Decoy-State BB84 protocol, resulting in a secure key that is almost 3% longer for realistic scenarios, with no computational or hardware complexity overhead.
Thomas Scarinzi, D. Orsucci, Marco Ferrari et al.· IEEE Transactions on Quantum...· 0 citations
Quantum key distribution (QKD) employs quantum states to generate shared cryptographic keys. An attacker interacting with the modeled non-orthogonal quantum signals can affect the monitored statistics, and hence they can be detected under the specified protocol assumptions, but this trait does not inherently authenticate the classical channel, and it does not prevent implementation side channels. In this work, we introduce ModPhase-8 (QUEST), a proposed QKD modulation and adaptive-receiver architecture evaluated through analytical modeling and simulation. Instead of using only a few quantum signal types, our system uses eight carefully designed signal variations created by adjusting the phase between two very short light pulses. The eight phase states are organized into four phase bases, each containing two antipodal states that encode one binary raw-key value. The enlarged signal set diversifies the physical representation of the key bit and changes the state-discrimination problem faced by an eavesdropper, but it does not increase the raw-key payload beyond one bit per successfully sifted signal. On the receiving side, the system adaptively switches between two measurement techniques based on the prevailing channel conditions. This adaptive detection mechanism enhances reliability and helps maintain low error rates even when the communication channel is affected by noise. We provide an analytical security assessment under the stated collective-attack, source, channel, receiver, and trusted-device assumptions, supplemented by attack-specific analyses of intercept–resend, beam-splitting, source-side multi-photon leakage, and selected implementation-related vulnerabilities. Simulation studies were conducted to examine the physical-layer and post-processing behavior of the proposed protocol under explicitly stated channel, receiver, detector, and finite-sample values. Under the adopted simulation model, ModPhase-8 maintains low error rates in the low- and moderate-noise operating regimes and exhibits favorable receiver-level robustness across the investigated channel conditions. The reported rate values are model-based performance estimates rather than rigorously certified secret-key lower bounds. In particular, Qiskit simulation does not establish a composable security proof or an optimal bound on Eve’s information for the exact eight-state time-bin ensemble. A protocol-specific numerical security analysis incorporating the homodyne–heterodyne measurement operators, post-selection, reconciliation efficiency, finite-size effects, and Eve’s Holevo information remains necessary before definitive rate comparisons can be made. ModPhase-8 should therefore be interpreted as a practically motivated receiver and modulation framework whose security-rate performance remains subject to further protocol-specific analysis.
Vidhya Prakash Rajendran, D. Perumalsamy, Basker Palaniswamy et al.· Information· 0 citations
By applying the framework of entropic uncertainty relation (EUR) and the Quantum Leftover Hash Lemma (QLHL), we introduce a security-proof method for variable-length side-channel-secure (SCS) quantum key distribution (QKD) against coherent attacks. This method reframes composable security as a statistical fluctuation problem of phase errors, enabling direct proofs against coherent attacks through observables and virtual observables. It yields tight key rates for the SCS protocol and reduces pulse requirements by over two orders of magnitude compared to prior works that employ the post-selection technique. We prove that the secure key length for the SCS protocol can be determined after error correction by exploiting the fact that untagged bits are free from bit-flip errors, using the actual information leakage during error correction and the post-error-correction statistics of each state to calculate the final key rate. We further identify sufficient conditions under which the final key length may be determined after error correction in a broader class of QKD protocols. Under the framework of EUR and QLHL, we clarify the applicability of several commonly used concentration bounds to variable-length QKD and the appropriate manner of their implementation. This work enhances the practical value of the SCS protocol and clarifies the security justification of key-rate formulas used in practical variable-length QKD implementations.
Continuous-variable quantum key distribution (CVQKD) has attracted extensive attention due to its compatibility and low costs. However, bandwidth mismatch exists to varying degrees between the transmitter and receiver. This may prevent frequency components carrying modulation information from being fully perceived by the legitimate party. In this paper, we identify a practical security loophole caused by bandwidth mismatch and propose a corresponding spectral attack scheme. Different from previous approaches that exploit security loopholes to conceal the excess noise introduced by intercept-resend attacks, this scheme can directly obtain raw-key information without introducing additional disturbances. A proof-of-principle attack on a CVQKD system with filtering operation is constructed to verify the feasibility. Experimental results indicate that Eve can obtain enough information to render the system insecure if this practical security loophole is ignored. Based on the identified security loophole, corresponding defense strategies are proposed. This work helps bridge the gap between theoretical models and practical implementations, providing a reference for defense design in practical quantum communication systems.
Chen Gong, Mingxuan Guo, P. Huang et al.· 0 citations
Quantum key distribution (QKD) is secure in principle, but practical security can be undermined by discrepancies between real devices and the idealized models assumed in security proofs. Source side channels, including those exploited by Trojan-horse attacks, are particularly detrimental: neglecting them compromises implementation security, whereas accounting for them reduces performance. Here we propose a QKD source that is intrinsically robust against side-channel attacks. Unlike existing passive and modulator-free schemes, it requires neither post-selection of the emitted pulses nor devices with a perfect extinction ratio to suppress side channels, and it does not introduce correlations between the intensity and the encoded bit or basis. Consequently, under idealized source assumptions commonly adopted in proposals for existing schemes, conventional decoy-state security analyses apply directly, yielding substantially higher key rates. Our proposal appears to be within reach of current technology and therefore provides a clear and practical path toward implementation-secure QKD.
Kiyoshi Tamaki, M. Curty, Akihiro Mizutani et al.· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.