EP4248608A1 - Quantum key distribution transmitter, receiver and method - Google Patents
Quantum key distribution transmitter, receiver and methodInfo
- Publication number
- EP4248608A1 EP4248608A1 EP20815738.8A EP20815738A EP4248608A1 EP 4248608 A1 EP4248608 A1 EP 4248608A1 EP 20815738 A EP20815738 A EP 20815738A EP 4248608 A1 EP4248608 A1 EP 4248608A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- transmission symbols
- constellation diagram
- continuous
- distribution
- qkd
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Withdrawn
Links
- 238000009826 distribution Methods 0.000 title claims abstract description 135
- 238000000034 method Methods 0.000 title claims abstract description 38
- 230000005540 biological transmission Effects 0.000 claims abstract description 138
- 238000010586 diagram Methods 0.000 claims abstract description 83
- 230000003287 optical effect Effects 0.000 claims abstract description 52
- 230000001427 coherent effect Effects 0.000 claims abstract description 39
- 238000012937 correction Methods 0.000 claims abstract description 21
- 238000001514 detection method Methods 0.000 claims description 21
- 238000007493 shaping process Methods 0.000 claims description 13
- 238000013507 mapping Methods 0.000 claims description 12
- 230000010363 phase shift Effects 0.000 claims description 8
- 230000000875 corresponding effect Effects 0.000 description 10
- 238000004891 communication Methods 0.000 description 8
- 238000013459 approach Methods 0.000 description 5
- 230000010287 polarization Effects 0.000 description 5
- 230000003321 amplification Effects 0.000 description 4
- 238000005259 measurement Methods 0.000 description 4
- 238000003199 nucleic acid amplification method Methods 0.000 description 4
- 230000002596 correlated effect Effects 0.000 description 3
- 239000013307 optical fiber Substances 0.000 description 3
- 238000012360 testing method Methods 0.000 description 2
- 238000009827 uniform distribution Methods 0.000 description 2
- 230000006978 adaptation Effects 0.000 description 1
- 239000000654 additive Substances 0.000 description 1
- 230000000996 additive effect Effects 0.000 description 1
- 230000015572 biosynthetic process Effects 0.000 description 1
- 238000006243 chemical reaction Methods 0.000 description 1
- 230000007423 decrease Effects 0.000 description 1
- 239000000835 fiber Substances 0.000 description 1
- 230000001788 irregular Effects 0.000 description 1
- 230000003278 mimic effect Effects 0.000 description 1
- 230000005693 optoelectronics Effects 0.000 description 1
- 238000012805 post-processing Methods 0.000 description 1
- 238000012545 processing Methods 0.000 description 1
- 230000011664 signaling Effects 0.000 description 1
- VLCQZHSMCYCDJL-UHFFFAOYSA-N tribenuron methyl Chemical compound COC(=O)C1=CC=CC=C1S(=O)(=O)NC(=O)N(C)C1=NC(C)=NC(OC)=N1 VLCQZHSMCYCDJL-UHFFFAOYSA-N 0.000 description 1
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0816—Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
- H04L9/0852—Quantum cryptography
- H04L9/0858—Details about key distillation or coding, e.g. reconciliation, error correction, privacy amplification, polarisation coding or phase coding
Definitions
- the invention relates to a continuous-variable quantum key distribution, CV-QKD, transmitter, a CV-QKD receiver and to a method of CV-QKD.
- Quantum key distribution, QKD, protocols are based on fundamental laws of quantum physics. The state of a quantum object changes after a measurement and it is not possible to perfectly clone the information carried by a physical system. The security of these protocols relies on the fact that an eavesdropper reveals their attack by introducing unavoidable errors that can be later detected by an exchange of information on a classical authenticated channel, the so-called reconciliation stage.
- QKD protocols can be implemented, but, in practice, they can be classified with respect to the detection technique required to recover the key information encoded in the observable properties of light. Protocols based on the exchange of quantum states representable in finite dimensional Hilbert spaces are referred to as discretevariable, DV, protocols. In contrast, the protocols are referred to as continuous-variable, CV, protocols when a Hilbert space of infinite dimensions is necessary to represent a quantum state.
- DV discretevariable
- CV continuous-variable
- the first DV-QKD protocol was invented in 1984 by Charles H. Bennett and Gilles Brassard and is known as BB84.
- the sender generates a bit and encodes it in one of two different bases for the polarization state of a photon. In each base, a first polarization state is used for “0” bits and a second orthogonal polarization state for “1 ” bits.
- the receiver ignores the base used by the sender and measures the polarization of the received photons by randomly selecting one of the two bases. If sender’s and receiver’s bases are equal, the receiver will detect the correct bit value; otherwise, the measurement will be wrong with 50% probability.
- sender and receiver After having exchanged a long sequence of photons, sender and receiver compare the bases they have used for each photon, communicating over a classical channel (reconciliation stage). They will keep only the bits generated and detected with a matched base,
- SUBSTITUTE SHEET (RULE 26) which constitute the so-called sifted keys.
- the two sifted keys will be identical and can be used as a secret symmetric key.
- CV-QKD protocols information is encoded in the quadrature components of light that are detected by means of homodyne or heterodyne coherent detection techniques. This has important advantages as the detection hardware does not require any specific component, such as actively cooled single-photon detectors, and exhibits a better compatibility with a wavelength division multiplexing environment.
- the simplest CV-QKD protocol introduced by Grosshans and Grangier in 2002, known as GG02, relies on Gaussian modulation. It is known from information theory that a Gaussian distributed signal meets the maximum channel capacity in a communication system. The protocol consists of four main steps: (i) state distribution and measurement; (ii) error reconciliation; (iii) parameter estimation; and (iv) privacy amplification.
- Step (iii), parameter estimation, is not present in DV-QKD and can be applied after or before error correction.
- the sender prepares and transmits a large number of coherent states, representable as independent and identically distributed complex Gaussian variables with a certain variance, V0.
- the receiver measures the states, obtaining a sequence of values that is used as raw key (reverse reconciliation).
- CV-QKD protocols exploit laser sources and homodyne/heterodyne detection schemes, which are much faster and more efficient than the detection of single photons.
- CV-QKD protocols can also theoretically provide higher key generation rates.
- far field tests for CV-QKD systems have resulted in limited transmission distances and low key rates.
- S. Pirandola, et al. “Fundamental limits of repeaterless quantum communications”, Nat. Commun.
- CV-QKD systems should allow for higher key rates with respect to DV-QKD systems and thus there is room for improving their performance. Indeed, as reported by Y. Zhang, et al., Continuous-variable QKD over 50km commercial fiber, arXiv:1709.04618 (2017), using propertechniques, both distances and key rates can be considerably increased.
- a QKD system In order to be commercially viable, a QKD system has to operate over already installed optical fiber networks, employing only commercially available optical devices and sharing the network resources with conventional communication systems. Low cost and robustness are indispensable features for QKD systems to be used in real world applications.
- One of the difficulties in obtaining a high key generation rate with CV-QKD is generating a Gaussian modulated signal.
- An aspect of the invention provides a continuous-variable quantum key distribution, CV-QKD, transmitter comprising a quantum random bit generator, QRBG, symbol encoding apparatus and optical transmission apparatus.
- the QRBG is operable to generate random bits.
- the symbol encoding apparatus is operable to map the random bits to transmission symbols defining an approximating constellation diagram in a complex plane.
- the transmission symbols are distributed in both amplitude and phase across the approximating constellation diagram.
- the transmission symbols have a probability of occurrence distribution within the approximating constellation diagram that approximates a continuous two-dimensional Gaussian distribution.
- the optical transmission apparatus is configured to encode the transmission symbols on a single-mode coherent state optical carrier signal.
- the CV-QKD transmitter enables a modulating signal having a Gaussian distributed random variable to be approximated using standard optical components, as used in classic coherent transmission systems, avoiding the need to use expensive, inefficient components such as single-photon sources.
- the CV-QKD transmitter advantageously mitigates the cost, speed and accuracy bottlenecks faced by the quantum random number generator, QRNG, based CV-QKD system of Y. Zhang, et al (ibid) the CV-QKD transmitter only needs to generate random bits, using the QRBG, rather true Gaussian random variables using a QRNG, resulting in an advantageous simplification of the CV-QKD transmitter and enabling gains in speed and accuracy of CV-QKD.
- the CV-QKD transmitter enables QKD over existing installed optical fiber networks, with network resources shared with conventional communications systems, such as wavelength division multiplexing, WDM, systems.
- the transmission symbols are located within respective nonoverlapping symbol areas within the complex plane.
- the respective integrals of the continuous two-dimensional Gaussian distribution within the symbol areas is less than or equal to a probability increment, AP, representing an accuracy chosen to approximate the continuous two- dimensional Gaussian distribution with a discrete Gaussian distribution.
- the integral of the continuous two-dimensional Gaussian distribution over a remaining area of the complex plane outside a combined area of the symbol areas gives a probability of less than AP.
- a constellation diagram approximating a two-dimensional Gaussian distribution with a discrete Gaussian distribution with any chosen accuracy, i.e. probability increment, can thereby be formed.
- the symbol encoding apparatus comprises a symbol mapper and a distribution matcher.
- the symbol mapper is operable to map the random bits to transmission symbols defining an initial constellation diagram in the complex plane.
- the transmission symbols are distributed in both amplitude and phase across the initial constellation diagram and the transmission symbols having a uniform probability of occurrence.
- the distribution matcher is operable to perform probabilistic constellation shaping, PCS, on the initial constellation diagram to modify the probability of occurrence of the transmission symbols to approximate the continuous two-dimensional Gaussian distribution, thereby forming the approximating constellation diagram.
- the use of PCS over a discrete alphabet enables source entropy to be adapted to channel signal to noise ratio, SNR, with the possibility to increase the key generation rate when working at high SNR (short distance) while remaining close to the Shannon limit.
- the CV-QKD transmitter enables a modulating signal having a Gaussian distributed random variable to be approximated using a standard symbol mapper.
- the initial constellation diagram has one of a Quadrature Amplitude Modulation, QAM, template or an Amplitude and Phase Shift Keying, APSK, template.
- the CV- QKD transmitter enables a modulating signal having a Gaussian distributed random variable to be approximated using standard optical components, such as a standard symbol mapper for QAM or APSK modulation.
- the distribution matcher is operable to perform PCS by assigning probabilities of occurrence according to distances, R, of the transmission symbols from an origin in the complex plane of the initial constellation diagram using the Maxwell-Boltzmann distribution.
- the transmission symbols of the initial constellation diagram are separated by a maximum distance corresponding to a probability increment, AP, representing an accuracy chosen to approximate the continuous two-dimensional Gaussian distribution with a discrete Gaussian distribution.
- AP probability increment
- Performing PCS on the initial constellation diagram using a Maxwell- Boltzmann distribution enables the CV-QKD transmitter to approach channel capacity given by Shannon’s limit and theoretically achievable by a Gaussian modulation.
- An aspect of the invention provides a continuous-variable quantum key distribution, CV-QKD, receiver comprising an optical coherent receiver, symbol decoding apparatus and error-correcting apparatus.
- the optical coherent receiver is operable to receive a single-mode coherent state optical carrier signal encoded with transmission symbols and to detect the transmission symbols.
- the symbol decoding apparatus is operable to decode the detected transmission symbols into bits.
- the error-correcting apparatus is operable to apply a binary error-correction code to the bits.
- the use of discrete modulation transmission symbols for QKD transmission enables the CV-QKD receiver to use classical error correction algorithms developed for binary AWGN channels, with high correction efficiency also at very low SNR. It also enables use of an optical coherent receiver, which gives the CV-QKD receiver good tolerance to noise, thanks to the local oscillator of the optical coherent receiver that acts as a selective filter.
- the CV-QKD receiver advantageously enables use of standard off-the-shelf optical components, as used in classical coherent transmission systems. Use of expensive and inefficient components, such actively cooled single-photon detectors, is thereby avoided.
- the use of discrete modulation transmission symbols having a probability of occurrence distribution that approximates a continuous two-dimensional Gaussian distribution enables a binary error-correction code to be applied to the bits
- the binary error-correction code is a low-density parity-check, LDPC, code.
- LDPC low-density parity-check
- An aspect of the invention provides a method of continuous-variable quantum key distribution, CV-QKD, comprising steps as follows.
- the transmission symbols are distributed in both amplitude and phase across the approximating constellation diagram and the transmission symbols have a probability of occurrence distribution within the approximating constellation diagram that approximates a continuous two-dimensional Gaussian distribution.
- the method enables a modulating signal having a Gaussian distributed random variable to be approximated using standard optical components, as used in classic coherent transmission systems, avoiding the need to use expensive, inefficient components such as single-photon sources.
- the method advantageously mitigates the cost, speed and accuracy bottlenecks faced by the quantum random number generator, QRNG, based CV-QKD system of Y.
- Zhang, et al (ibid) the method only needs to generate random bits, using a QRBG, rather true Gaussian random variables using a QRNG, resulting in an advantageous simplification and enabling gains in speed and accuracy of CV-QKD.
- the method enables QKD over existing installed optical fiber networks, with network resources shared with conventional communications systems, such as wavelength division multiplexing, WDM, systems.
- the transmission symbols are located within respective nonoverlapping symbol areas within the complex plane.
- the respective integrals of the continuous two-dimensional Gaussian distribution within the symbol areas are less than or equal to a probability increment, AP, representing an accuracy chosen to approximate the continuous two- dimensional Gaussian distribution with a discrete Gaussian distribution.
- the integral of the continuous two-dimensional Gaussian distribution over a remaining area of the complex plane outside a combined area of the symbol areas gives a probability of less than AP.
- a constellation diagram approximating a two-dimensional Gaussian distribution with a discrete Gaussian distribution with any chosen accuracy, i.e. probability increment, can thereby be formed.
- mapping the random bits to transmission symbols comprises the following steps.
- a step of mapping the random bits to transmission symbols defining an initial constellation diagram in the complex plane.
- the transmission symbols are distributed in both amplitude and phase across the initial constellation diagram and the transmission symbols having a uniform probability of occurrence.
- PCS probabilistic constellation shaping
- the use of PCS over a discrete alphabet enables source entropy to be adapted to channel signal to noise ratio, SNR, with the possibility to increase the key generation rate when working at high SNR (short distance) while remaining close to the Shannon limit.
- the method enables a modulating signal having a Gaussian distributed random variable to be approximated using a standard symbol mapping techniques.
- the initial constellation diagram has one of a Quadrature Amplitude Modulation, QAM, template or an Amplitude and Phase Shift Keying, APSK, template.
- the method enables a modulating signal having a Gaussian distributed random variable to be approximated using standard symbol mapping techniques for QAM or APSK modulation.
- performing PCS comprises assigning probabilities of occurrence according to distances, R, of the transmission symbols from an origin in the complex plane of the initial constellation diagram using the Maxwell-Boltzmann distribution.
- the transmission symbols of the initial constellation are separated by a maximum distance corresponding to a probability increment, AP, representing an accuracy chosen to approximate the continuous two- dimensional Gaussian distribution with a discrete Gaussian distribution.
- AP probability increment
- the method comprises the further steps as follows.
- the binary error-correction code is a low-density parity-check, LDPC, code.
- LDPC low-density parity-check
- FIGS. 1 , 3 and 4 are block diagrams illustrating embodiments of a CV-QKD transmitter
- Figures 2a to 2d are diagrams of a complex plane illustrating the formation of an approximating constellation diagram that approximates a continuous two-dimensional Gaussian distribution;
- Figure 5 illustrates the theoretical limit of the information per symbol that can be transmitted over a Gaussian channel (the Shannon limit) and the transmission of binary or quaternary symbols through binary or quaternary phase-shift keying modulation formats;
- Figure 6 is a block diagram illustrating an embodiment of a CV-QKD receiver
- Figure 7 is a block diagram illustrating embodiments of a CV-QKD transmitter and a CV-QKD receiver, forming a CV-QKD system
- FIGS. 8 to 10 are flowcharts illustrating embodiments of method steps.
- an embodiment provides a CV-QKD transmitter 100 comprising a quantum random bit generator, QRBG, 102, symbol encoding apparatus 104 and optical transmission apparatus 106.
- the QRBG is operable to generate random bits.
- the symbol encoding apparatus 104 is operable to map the random bits to transmission symbols defining an approximating constellation diagram in a complex plane.
- the transmission symbols are distributed in both amplitude and phase across the approximating constellation diagram.
- the transmission symbols have a probability of occurrence distribution within the approximating constellation diagram that approximates a continuous two-dimensional Gaussian distribution.
- the optical transmission apparatus 106 is configured to encode the transmission symbols on a single-mode coherent state optical carrier signal.
- Figure 2d illustrates an embodiment of the approximating constellation diagram 220 in a complex plane 200, which may be defined as follows.
- continuous two- dimensional Gaussian distribution 202 is approximated with a discrete two-dimensional Gaussian distribution defined by a plurality of level curves 204, each of which corresponds to a probability increment AP, which is the accuracy chosen to approximate the continuous Gaussian distribution with the discrete one.
- the transmission symbols 222 are thus located within respective non-overlapping symbol areas 214 within the complex plane 200, the respective integrals of the continuous two- dimensional Gaussian distribution within the symbol areas being less than or equal to a probability increment, AP, representing an accuracy chosen to approximate the continuous two- dimensional Gaussian distribution with a discrete Gaussian distribution.
- AP probability increment
- the integral of the continuous two-dimensional Gaussian distribution over a remaining area 212 of the complex plane outside the combined area 210 of the symbol areas gives a probability of less than AP.
- the symbol encoding apparatus comprises a symbol mapper 302 and a distribution matcher 304.
- the symbol mapper is operable to map the random bits to transmission symbols defining an initial constellation diagram in the complex plane.
- the transmission symbols are distributed in both amplitude and phase across the initial constellation diagram and the transmission symbols have a uniform probability of occurrence across the initial constellation diagram.
- the distribution matcher 304 is operable to perform probabilistic constellation shaping, PCS, on the initial constellation diagram to modify the probability of occurrence of the transmission symbols to approximate the continuous two-dimensional Gaussian distribution, thereby forming the approximating constellation diagram.
- PCS probabilistic constellation shaping
- Geometric constellation shaping adjusts the position of the transmission symbols within the constellation diagram in the complex plane to approximate a Gaussian distribution but it has some disadvantages: there is no simple method for finding the optimal constellation in any working condition; irregular distributions of transmission symbols increase cost and complexity of digital to analog conversion, DAC, and digital signal processing, DSP; and gray mapping is not possible, complicating the receiver structure.
- Probabilistic constellation shaping, PCS adjusts the probability of occurrence of the transmission symbols rather than their position within the constellation diagram to approximate a Gaussian distribution. This simplifies implementation since it is easier to change the number of occurrences of each transmission symbol rather than its position, i.e. its amplitude and phase, meaning that state-of the-art receivers designed for QAM constellations can be used.
- constellations can be employed for the initial constellation diagram, so long as the transmission symbols are distributed in both amplitude and phase.
- Any digital modulation technique producing a modulated signal having a constellation diagram representation whose constellation points are carved out of an integer lattice may be used.
- the initial constellation diagram has one of a Quadrature Amplitude Modulation, QAM, template or an Amplitude and Phase Shift Keying, APSK, template.
- the initial constellation diagram has an M-ary template where M is at least 16. It may be advantageous to use a dense template, i.e. a higher-order modulation format, for example where M is at least 256 or 4096.
- the theoretical limit of the information per symbol that can be transmitted over a Gaussian channel is obtained when transmitting symbols drawn from a Gaussian random number generator and having SNR values that correspond to a given variance of the distribution.
- the distribution matcher 304 is operable to perform PCS by assigning probabilities of occurrence according to distances, R, of the transmission symbols from an origin in the complex plane of the initial constellation diagram using the Maxwell- Boltzmann distribution.
- the transmission symbols of the initial constellation diagram are separated by a maximum distance corresponding to a probability increment, AP, representing an accuracy chosen to approximate the continuous two-dimensional Gaussian distribution with a discrete Gaussian distribution, as described above with reference to Figure 2a.
- the Maxwell-Boltzmann distribution is the optimal probability distribution.
- the Maxwell- Boltzmann distribution is a description of the statistical distribution of the energies of the molecules of a classical gas. Performing PCS using the Maxwell-Boltzmann distribution on the initial constellation diagram changes the probability distribution of the transmission symbols from an initial uniform distribution to a probability distribution in which each transmission symbol has a probability that depends on its distance, R, from the origin (the distances R of the transmission symbols are equated to the energies of the molecules).
- R distance that depends on its distance, R, from the origin (the distances R of the transmission symbols are equated to the energies of the molecules).
- the Maxwell-Boltzmann distribution maximizes the information rate that can be achieved with a given discrete modulation alphabet (i.e. the transmission symbols), providing the closest approximation to the channel capacity theoretically achievable by a continuous Gaussian distribution of the transmission symbols.
- the distribution matcher 304 may be implemented with one of the methods known for classical PCS transmission, for example, constant-composition distribution matching, CCDM, as reported by Schulte, P.; Bbcherer, G. “Constant composition distribution matching”. IEEE Trans. Inf. Theory 2016, 62, 430-434., enumerative sphere shaping, ESS, as reported by Y. C. Gultekin et al. “Enumerative Sphere Shaping for Wireless Communications With Short Packets”, IEEE Trans. Wireless Commun., Vol. 19, No. 2, February 2020, or hierarchical distribution matching, Hi-DM, as reported by S. Civelli, M. Secondini, “Hierarchical Distribution Matching for Probabilistic Amplitude Shaping”, Entropy 2020, 22, 958.
- the optical transmission apparatus comprises a digital to analog, DAC, converter 402, a modulator driver 404 and an optical modulator 406.
- the optical modulator has I and Q branches and the distribution matcher 302 is configured to perform PCS independently on the I and Q branches of the optical modulator.
- the initial constellation has an M 2 -ary QAM template.
- the Maxwell-Boltzmann distribution is obtained by the distribution matcher, which maps a block of random input bits (with uniform distribution) to a block of output amplitudes, so that lower amplitudes are selected with a higher probability than higher amplitudes.
- the proportion between the amplitudes is selected to match the desired Maxwell-Boltzmann distribution. This is done, for instance, by the CCDM, ESS, or Hi-DM techniques mentioned above. Other distributions could be applied in principle, but the Maxwell-Boltzmann is theoretically the most efficient one. In practice, since the block lengths k and n are finite, an approximation of the MB distribution is typically obtained.
- M-ary pulse amplitude modulation PAM
- PAM pulse amplitude modulation
- the random bits generated by the QRBG 102 are processed in blocks.
- Each branch of the optical modulator 406 receives a block of k+N random bits: k bits are sent to the distribution matcher 304, which maps them to the (positive) amplitudes of the M PAM transmission symbols with the target Maxwell-Boltzmann probability distribution; the other N bits are mapped to the (positive or negative) sign of the PAM transmission symbols.
- Each amplitude is then multiplied by the corresponding sign to obtain the /VP-QAM transmission symbols with the desired probability distribution.
- Corresponding embodiments apply to the method of CV-QKD described below.
- an embodiment provides a CV-QKD receiver 600 comprising an optical coherent receiver 602, symbol decoding apparatus 604 and error-correcting apparatus 606.
- the optical coherent receiver 602 is operable to receive a single-mode coherent state optical carrier signal encoded with transmission symbols and to detect the transmission symbols.
- the optical coherent receiver may be configured for homodyne or heterodyne detection.
- the symbol decoding apparatus 604 is operable to decode the detected transmission symbols into bits.
- the error-correcting apparatus 606 is operable to apply a binary errorcorrection code to the bits decoded by the symbol decoding apparatus.
- the binary error-correction code is a low-density parity-check, LDPC, code.
- Figure 7 illustrates a QKD system comprising a CV-QKD transmitter 700 according to an embodiment and a CV-QKD receiver 720 according to an embodiment, connected via a transmission line 702.
- Both DV-QKD and CV-QKD protocols comprise a raw key distribution phase and a post processing phase.
- CV-QKD protocols require an additional step of parameter estimation, envisaging the exchange of correlated quantum information by the communicating parties before proceeding to steps of information reconciliation and privacy amplification.
- the CV-QKD transmitter 710 modulates a single-mode coherent state optical carrier signal generated by a laser 712 in its quadratures I and Q with randomly generated transmission symbols. Rather than true Gaussian symbols, QAM symbols with approximately a Maxwell- Boltzmann probability distribution are used (“PCS symbols” 716), which are generated using a QRBG 102, symbol mapper 302 and distribution mapper 304, as described above with reference to Figure 3 or Figure 4.
- PCS symbols QAM symbols with approximately a Maxwell- Boltzmann probability distribution
- the resulting modulated single-mode coherent state optical carrier signal is transmitted over a noisy channel, optical link 702, to the CV-QKD receiver 720.
- the coherent optical receiver may be configured for homodyne or heterodyne detection. In the case of homodyne detection, the receiver measures only one of the quadratures using coherent optical detection techniques. To do so, the receiver has to vary the phase, (p, of a local laser oscillator 724. The choice of the quadrature to be detected is performed by randomly choosing (p e ⁇ 0, TT/2 ⁇ .
- the receiver informs the transmitter about which quadrature was measured, so transmitter may discard the irrelevant data.
- heterodyne detection the receiver measures both quadratures.
- the heterodyne configuration corresponds to the phase-diversity coherent detection scheme that is usually employed in classical optical communications.
- two coherent detectors are used, in which the signal and a local oscillator are mixed with two different phase relations, 0 and TT/2 (rather than using a single detector that randomly selects the phase relation, as in the homodyne case).
- a Sender using the CV-QKD transmitter 710 and a Receiver using the CV-QKD receiver 720 share a set of correlated variables; the Sender knows the transmitted symbols, whereas the Receiver knows the measured quadratures and these variables are correlated (the latter are a noisy replica of the former).
- the Sender and Receiver then compare a random sample of their variables using a public communications channel to estimate the transmission efficiency of the quantum channel.
- KGR maximum secure key generation rate
- KGR pi AB — x EB
- I AB is the mutual information between Sender, A, and Receiver, B
- p ⁇ 1 is the efficiency of the employed reconciliation algorithm (error correction code)
- EB is the Holevo information between the Eavesdropper, E, and the Receiver, B, corresponding to the maximum information that the Eavesdropper may have gained by a coherent attack. If the Sender and Receiver find that KGR > 0, they proceed to performing information reconciliation, privacy amplification, and extract the secure key. Otherwise, if they find that KGR ⁇ 0, this means that the Eavesdropper may have gained too much information about the secret key, so they abort the key exchange and start the CV-QKD procedure again.
- an embodiment provides a method 800 of CV-QKD.
- the method 800 comprises generating 802 random bits and mapping 804 the random bits to transmission symbols defining an approximating constellation diagram in a complex plane.
- the transmission symbols are distributed in both amplitude and phase across the approximating constellation diagram and the transmission symbols have a probability of occurrence distribution within the approximating constellation diagram that approximates a continuous two-dimensional Gaussian distribution.
- the transmission symbols are then encoded 806 on a single-mode coherent state optical carrier signal.
- the transmission symbols 222 are located within respective non-overlapping symbol areas 214 within the complex plane 200, the respective integrals of the continuous two-dimensional Gaussian distribution within the symbol areas being less than or equal to a probability increment, AP, representing an accuracy chosen to approximate the continuous two- dimensional Gaussian distribution with a discrete Gaussian distribution.
- AP a probability increment
- the integral of the continuous two-dimensional Gaussian distribution over a remaining area 212 of the complex plane outside the combined area 210 of the symbol areas gives a probability of less than AP.
- mapping 804 the random bits to transmission symbols comprises mapping 902 the random bits to transmission symbols defining an initial constellation diagram in the complex plane and performing 904 probabilistic constellation shaping, PCS, on the initial constellation diagram.
- the transmission symbols defining the initial constellation diagram are distributed in both amplitude and phase across the initial constellation diagram and the transmission symbols of the initial constellation diagram have a uniform probability of occurrence.
- the PCS performed on the initial constellation diagram is configured to modify the probability of occurrence of the transmission symbols to approximate the continuous two-dimensional Gaussian distribution, thereby forming the approximating constellation diagram.
- the PCS therefore changes the transmission symbols defining the initial constellation diagram from having a uniform probability of occurrence to having a probability of occurrence that approximates a continuous two- dimensional Gaussian distribution.
- the initial constellation diagram has one of a Quadrature Amplitude Modulation, QAM, template or an Amplitude and Phase Shift Keying, APSK, template.
- performing PCS comprises assigning probabilities of occurrence according to distances, R, of the transmission symbols from an origin in the complex plane of the initial constellation diagram using the Maxwell-Boltzmann distribution, as described above.
- the transmission symbols of the initial constellation are separated by a maximum distance corresponding to a probability increment, AP, representing an accuracy chosen to approximate the continuous two-dimensional Gaussian distribution with a discrete Gaussian distribution.
- the method 1000 further comprises transmitting 1002 the single-mode coherent state optical carrier signal with encoded transmission symbols across an optical link. Following receiving 1004 the transmitted singlemode coherent state optical carrier signal encoded with the transmission symbols, the transmission symbols are detected 1006 using one of homodyne detection or heterodyne detection. The detected transmission symbols are then decoded into bits and a binary errorcorrection code is applied 1010 to the bits. As described above with reference to Figure 7, steps of reconciliation, privacy amplification, and extracting a secure key can then be performed.
Landscapes
- Engineering & Computer Science (AREA)
- Physics & Mathematics (AREA)
- Electromagnetism (AREA)
- Theoretical Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Optical Communication System (AREA)
Abstract
Description
Claims
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
PCT/EP2020/083068 WO2022106036A1 (en) | 2020-11-23 | 2020-11-23 | Quantum key distribution transmitter, receiver and method |
Publications (1)
Publication Number | Publication Date |
---|---|
EP4248608A1 true EP4248608A1 (en) | 2023-09-27 |
Family
ID=73598832
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
EP20815738.8A Withdrawn EP4248608A1 (en) | 2020-11-23 | 2020-11-23 | Quantum key distribution transmitter, receiver and method |
Country Status (2)
Country | Link |
---|---|
EP (1) | EP4248608A1 (en) |
WO (1) | WO2022106036A1 (en) |
Families Citing this family (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN115348010B (en) * | 2022-07-20 | 2024-04-26 | 中国电子科技集团公司第三十研究所 | Method and system suitable for eliminating residual error codes of continuous variable quantum key distribution |
CN116723054B (en) * | 2023-08-08 | 2023-10-27 | 合肥量芯科技有限公司 | Method for resisting detection efficiency mismatch loopholes introduced in calibration process |
Family Cites Families (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
GB2551685B (en) * | 2016-02-16 | 2019-12-11 | Toshiba Kk | An optical device, a transmitter for a quantum communication system and a quantum communication system |
US11258594B2 (en) * | 2018-11-21 | 2022-02-22 | Ut-Battelle, Llc | Quantum key distribution using a thermal source |
-
2020
- 2020-11-23 EP EP20815738.8A patent/EP4248608A1/en not_active Withdrawn
- 2020-11-23 WO PCT/EP2020/083068 patent/WO2022106036A1/en active Application Filing
Also Published As
Publication number | Publication date |
---|---|
WO2022106036A1 (en) | 2022-05-27 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
US10476728B2 (en) | Probabilistic shaping for arbitrary modulation formats | |
Djordjevic | Physical-layer security and quantum key distribution | |
CN107113169B (en) | Permanent secure communications from short-term secure encrypted quantum communications | |
Zhou et al. | Continuous-variable quantum key distribution with rateless reconciliation protocol | |
EP3813294A1 (en) | Quantum communication system that switches between quantum key distribution (qkd) protocols and associated methods | |
Qu et al. | Universal hybrid probabilistic-geometric shaping based on two-dimensional distribution matchers | |
CN111669343B (en) | Probabilistic amplitude shaping | |
US8189787B2 (en) | Data transmitting apparatus, data receiving apparatus and data communication apparatus | |
Guha et al. | Polar coding to achieve the Holevo capacity of a pure-loss optical channel | |
CN106254072B (en) | Quantum key distribution method | |
WO2007036012A1 (en) | Methods and systems for communicating over a quantum channel | |
Qi | Simultaneous classical communication and quantum key distribution using continuous variables | |
EP4248608A1 (en) | Quantum key distribution transmitter, receiver and method | |
CN108650088A (en) | Including at least quantum communications device and method of tripartite | |
CN113141252A (en) | Quantum key distribution method, quantum communication method, device and system | |
CN112702162B (en) | One-dimensional continuous variable quantum key distribution system based on discrete state and implementation method thereof | |
Pfeiffer et al. | Multilevel coding for physical-layer security | |
EP3404856B1 (en) | Method of and apparatus for modulating an optical carrier | |
EP4123958B1 (en) | Method for coherent optical communications for the transmission of information and for the distribution of a cryptographic key and a system for implementing the method | |
US10944553B2 (en) | Simultaneous classical and quantum communication scheme based on coherent detection | |
CN208956064U (en) | Quantum communications device comprising at least tripartite | |
US7869600B2 (en) | Optical transmitter and transmitting method for transmitting cryptogram | |
Mountogiannakis et al. | Data postprocessing for the one-way heterodyne protocol under composable finite-size security | |
Qu et al. | Hybrid probabilistic-geometric shaping in optical communication systems | |
US7606367B2 (en) | Quantum cryptography with fewer random numbers |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: UNKNOWN |
|
STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
17P | Request for examination filed |
Effective date: 20230608 |
|
AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION HAS BEEN WITHDRAWN |
|
18W | Application withdrawn |
Effective date: 20240108 |