Beating the repeaterless bound with adaptive measurement-device-independent quantum key distribution
R\'obert Tr\'enyi, Koji Azuma, Marcos Curty

TL;DR
This paper analyzes the robustness of a quantum key distribution protocol that surpasses the repeaterless bound, focusing on the impact of source imperfections and identifying conditions sources must meet to maintain this advantage.
Contribution
It derives necessary conditions on photon-number statistics for sources to beat the repeaterless bound and shows that certain practical sources like parametric down-conversion cannot achieve this.
Findings
Parametric down-conversion sources do not meet the necessary conditions.
The protocol's robustness depends on specific photon-number statistics.
Idealized devices are required to surpass the repeaterless bound.
Abstract
Surpassing the repeaterless bound is a crucial task on the way towards realizing long-distance quantum key distribution. In this paper, we focus on the protocol proposed by Azuma et al. in [Nature Communications 6, 10171 (2015)], which can beat this bound with idealized devices. We investigate the robustness of this protocol against imperfections in realistic setups, particularly the multiple-photon pair components emitted by practical entanglement sources. In doing so, we derive necessary conditions on the photon-number statistics of the sources in order to beat the repeaterless bound. We show, for instance, that parametric down-conversion sources do not satisfy the required conditions and thus cannot be used to outperform this bound.
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Beating the repeaterless bound with adaptive measurement-device-independent quantum key distribution
Róbert Trényi
Escuela de Ingeniería de Telecomunicación, Dept. of Signal Theory and Communications, University of Vigo, E-36310 Vigo, Spain
Koji Azuma
NTT Basic Research Laboratories, NTT Corporation, 3-1 Morinosato Wakamiya, Atsugi, Kanagawa 243-0198, Japan
NTT Research Center for Theoretical Quantum Physics, NTT Corporation, 3-1 Morinosato-Wakamiya, Atsugi, Kanagawa 243-0198, Japan
Marcos Curty
Escuela de Ingeniería de Telecomunicación, Dept. of Signal Theory and Communications, University of Vigo, E-36310 Vigo, Spain
Abstract
Surpassing the repeaterless bound is a crucial task on the way towards realizing long-distance quantum key distribution. In this paper, we focus on the protocol proposed by Azuma et al. in [Nature Communications 6, 10171 (2015)], which can beat this bound with idealized devices. We investigate the robustness of this protocol against imperfections in realistic setups, particularly the multiple-photon pair components emitted by practical entanglement sources. In doing so, we derive necessary conditions on the photon-number statistics of the sources in order to beat the repeaterless bound. We show, for instance, that parametric down-conversion sources do not satisfy the required conditions and thus cannot be used to outperform this bound.
I Introduction
Quantum key distribution (QKD) protocols can provide two distant parties (Alice and Bob) with information-theoretically secure secret keys GisinReview ; NorbertReview ; MarcosReview . However, in point-to-point QKD via pure-loss bosonic channels, the achievable secret key rate is fundamentally limited by the so-called repeaterless bound TGW ; PLOB ; AnotherPaperOnBounds . In the limit of high channel loss (i.e., long distances) the repeaterless bound is proportional to the transmittance of the channel connecting Alice and Bob, denoted by . This means that the secret key rate of any point-to-point QKD protocol scales at most with . As in the case of optical fibers , where is the distance between the parties and is the attenuation length of the fiber, this poses a stringent limitation on the achievable secret key rate. Therefore, surpassing the repeaterless bound is an essential step towards efficient long-distance quantum communication.
A simple idea to outperform the repeaterless bound is to introduce intermediate nodes, dividing the channel into many smaller segments so that the probability of losing a signal stays relatively small on each segment. This naturally leads to the concept of quantum repeaters BriegelRepeater ; DuanRepeater ; HybridRepeater ; KokRepeater ; JiangRepeater ; SangouardRepeater ; KojiRepeater ; MunroRepeater ; KojiRepeater2 , which are typically based on entanglement swapping and distillation. However, to truly benefit from a quantum repeater, one needs many nodes and demanding technological resources, which makes the experimental realization very challenging with current technology RepeaterDifficult .
Another, recently proposed idea is twin-field QKD (TF-QKD) LucamariniTfQkd , which is based on single-photon interference and includes one intermediate node performing such conceptually simple interferometric measurement. Indeed, this offers a square root improvement in the scaling of the secret key rate. This proposal has triggered a lot of attention in the field and various simple security proofs and improved versions of the original protocol have been very recently introduced MarcosTf ; CuiTF ; JieTF ; kiyoshiTF ; MaTF ; WangTF ; YinTF . Proof-of-principle experiments to show the feasibility of some of the suggested TF-type QKD protocols have already been demonstrated experimentally ProofOfPrincipleTF ; ToshibaExpTF ; PanTF ; WangTFExp , which may suggest the viability of this approach to achieve intercity QKD with current technology.
The same square root improved scaling can be achieved if one extends the original measurement-device-independent QKD (MDI-QKD) mdi protocol, based on two-photon interference, with some feedback mechanism to make sure that the Bell state measurement (BSM) is performed between signals that actually survived the channel loss. One way is to make use of quantum memories luong ; abruzzo ; panayi , but the required memory parameters are still challenging for current technology posterQCrypt . To avoid the need for quantum memories while having the same square root improved scaling, Azuma et al. proposed the idea of a fully optical, adaptive MDI-QKD koji (AMDI-QKD) protocol, using standard optical teleportation for performing a quantum non-demolition measurement (QND) qnd to confirm the arrival of the single-photon signals at the middle node. While the required technology to implement the AMDI-QKD protocol is far off our current experimental capabilities, this protocol could offer higher secret key rates than the TF-QKD protocol, because the former is based on two-photon interference at the middle node while the latter is based on single-photon interference HadamardOperation .
The original AMDI-QKD scheme koji assumes highly idealized devices, like, for instance, perfect entanglement sources, which are capable of generating a perfect EPR pair on demand for the teleportation in the QND measurement, and perfect single-photon sources. In this paper, we investigate the robustness of this protocol against source imperfections, like for example a non-vanishing probability of emitting multiple-photon signals and thus introducing extra noise into the system. By performing a full-mode analysis of a realistic setup we derive a necessary condition on the photon-number statistics of the sources for overcoming the repeaterless bound in PLOB .
In doing so, we also show, for example, that with parametric down-conversion (PDC) sources, the AMDI-QKD protocol has a scaling of at most , therefore unable to beat the repeaterless bound. This is due to the fact that PDC sources have a too large probability of emitting multiple-photon pairs compared to the probability of emitting single-photon pairs.
We note that a similar behavior has also been observed in the context of the ensemble-based quantum memory assisted MDI-QKD mohsen protocol. Ensemble-based quantum memories have many favorable properties, but they inherently suffer from a non-negligible probability of emitting multiple-photons (similar to that of the PDC sources) causing the advantageous scaling offered by a traditional memory assisted system luong ; abruzzo ; panayi to vanish. In this regard, we remark that our result is stronger than that introduced in mohsen in the sense that it applies even with photon-number resolving (PNR) detectors, while mohsen assumes threshold detectors.
The paper is organised as follows. In Sec. II, the investigated protocol is introduced and its secret key rate formula is presented. Sec. III describes mathematically the physical devices used for the implementation of the protocol. Next, in Sec. IV we present the main results of the paper. Here, we obtain necessary conditions on the applied entanglement sources for overcoming the repeaterless bound PLOB with the AMDI-QKD protocol. As a corollary, we prove that the protocol is not capable of beating the repeaterless bound PLOB using PDC sources. Lastly, Sec. V contains the conclusions of the paper. The paper also includes two appendices for providing the details of the calculations.
II The AMDI-QKD protocol
II.1 Protocol steps
The schematic layout of the AMDI-QKD protocol koji can be seen in Fig. 1. The protocol runs as follows:
Each of Alice and Bob generates signals with their on-demand entanglement sources and , respectively. One mode of each signal is sent to Charlie’s QND measurement simultaneously via the quantum channel, using a multiplexing technique (e.g. wavelength based). The other mode is kept by Alice and Bob and they measure it in the or basis, which they choose with probabilities and , respectively. 2. 2.
Charlie applies QND measurements to the incoming pulses to confirm the arrival of the signals coming from Alice and Bob. 3. 3.
Charlie pairs the successfully arriving signals via optical switches and performs BSMs between signals coming from the different parties. To be more precise, if there are, say () successfully arriving signals from Alice (Bob), then Charlie performs BSMs. 4. 4.
Charlie announces to Alice and Bob which BSMs were successful, together with the measurement result obtained. Here the successful BSM is assumed to distinguish the Bell states and from the others, as we consider (see Fig. 3 in Sec. III) a standard linear-optics implementation of the BSMs. Here () represents a horizontally (vertically) polarized single-photon state. 5. 5.
For key generation, Alice and Bob post-select the events by communicating over an authenticated classical channel where they used the -basis to measure their modes in step 1 (and in which they both had a successful photon detection) and also the corresponding BSM was successful. To make sure that their key bits are identical, they apply a bit flip procedure mdi . To be precise, Alice or Bob flips her or his bits, except for the cases when they chose the basis and Charlie’s BSM outcome was the state .
II.2 Secret key rate formula
The secret key rate formula for the protocol above has been derived in koji when the number of multiplexing tends to infinity. It reads:
[TABLE]
where is the probability that Charlie’s QND and the measurements are both successful either at Alice’s or Bob’s site. The quantity represents the success probability of one BSM. The quantities and , on the other hand denote the bit and phase error rates, respectively. The parameter is an inefficiency function for the error correction process and is the binary entropy function. We remark that the fact that in Eq. (1) only rather than the square of it appears is due to the advantage that the original AMDI-QKD protocol offers, that is, BSMs are only performed between signals that survived the channel loss. Therefore, a particular signal only needs to survive travelling through one path koji .
We also note that since we evaluate the secret key rate in the asymptotic regime where , the parties perform steps 1-5 of the protocol only once. Also, for simplicity, we assume that , so that we take in Eq. (1) for the simulations below. Moreover, we assume for simplicity that .
The full-mode analysis of the AMDI-QKD protocol described above can be found in Appendix B, based on Eq. (1) and the device models described in the next section.
III Device models
Here, we describe the mathematical models that we use to characterise the behavior of the different devices employed to evaluate the performance of the AMDI-QKD protocol.
III.1 Photonic sources
We shall assume that all entanglement sources emit states of the following form:
[TABLE]
where and . The -photon pair states are given by
[TABLE]
where and ( and ) are the creation operators of horizontally (vertically) polarized photons in the modes and , respectively and denotes the vacuum state.
We note that if we choose (i.e., for any ) then Eq. (2) represents a perfect entanglement source that is capable of emitting maximally entangled states with certainty. Another interesting special case is when
[TABLE]
holds, in which case Eq. (2) describes a type-II PDC source PDC with being a positive parameter, related to the amplitude of the pumping laser.
III.2 Detectors
We shall assume that all the detectors are PNR detectors, characterized by the following positive operator-valued measure (POVM) elements
[TABLE]
with denoting the number of detected photons. In Eq. (5), the parameter is the detection efficiency of the detectors and is the -photon Fock state. We note that for simplicity in Eq. (5) we have disregarded the dark count probability of the PNR detectors.
III.3 QND measurement
A linear-optics teleportation-based implementation of the QND measurement can be seen in Fig. 2. It consists of a standard linear-optics BSM module together with an entanglement source that emits the state described in Eq. (2). The purpose of the QND measurement module is to herald if a photon successfully arrived at Charlie’s node, so that, in this case, he can continue the protocol with performing his BSMs. The successful heralding events are constituted by the same detection patterns as in the original MDI-QKD protocol mdi , that is, a successful heralding event occurs if the detectors detect exactly one photon in horizontal polarization and one photon in vertical polarization. The setup is based on quantum teleportation. Indeed, in the case of a single-photon input and being a perfect EPR source with , the QND module teleports its input mode to its output mode teleportation . We note that there exist more efficient implementations of a BSM GriceBSM ; ewertBSM in terms of the success probability (which can approach instead of as in the scheme shown in Fig. 2), but they come with the overhead of the need for complicated ancilla states.
III.4 Optical switches
Charlie directs the successfully arriving signals into his BSMs with the help of optical switches. For this, an active feedforward mechanism is required since it takes time to align the ports of the switches properly, so that successful signals from Alice and Bob end up in the same BSM at Charlie’s site. It is assumed that one active feedforward takes time , during which signals propagate in optical fibers. Therefore, the feedforward procedure can be modelled as a lossy channel with transmittance due to the propagation of the signals through the fibers, where denotes the speed of light in the optical fiber. Otherwise, we assume perfect switching devices with unlimited number of entries.
III.5 BSM modules after the switches
In this case, the linear-optics implementation of the middle BSM modules is depicted in Fig. 3. Similarly to the QND module, the success events are constituted by the same detection patterns as in the original MDI-QKD protocol mdi . Note, however, that this middle BSM module differs from the one used in the QND measurement. Here, Hadamard gates (denoted in Fig. 3 by H) are applied HadamardOperation , whose operation can be described as
[TABLE]
where () and () are the creation operators of the input and output modes of the Hadamard gate in horizontal (vertical) polarization.
Including the Hadamard gates is advantageous, since they can prevent errors that can occur otherwise. For example, when the source emits a two-photon pair state and the input of the QND module is the vacuum state, a successful heralding event can still occur, despite of the fact that the signal coming from the corresponding party was lost. In this scenario, it can be shown (see Appendix A) that the output state of the QND measurement, heading towards the middle BSM, is a two photon signal consisting of one vertically and one horizontally polarized photon. Now, without the Hadamard gates, this state could give a successful detection event at the middle BSM, which is undesired since there was no signal received from the party connected to the seemingly successful QND measurement. Intuitively, one expects that adding the Hadamard gates, i.e., rotating the signal, will just decrease the chance of the two photons ending up in detectors corresponding to different polarizations. This is so because, after the rotation, it is not predetermined any more which detector they hit after the polarizing beam splitter, and it rather becomes a probabilistic process. However, carrying out the calculation shows (see Appendix A) that, in fact, the Hadamard gates force the spurious two photon signal to give non-conclusive detection events at the final BSM, which is the best possible scenario.
III.6 Quantum channel
For concreteness, we assume that the quantum channel connecting Alice (Bob) to Charlie is an optical fiber with attenuation length and transmittance
[TABLE]
where is the distance between Alice and Bob, and , where denotes the natural logarithm and is the loss coefficient of the channel measured in dB/km. For simplicity, we do not consider any misalignment effect in our system.
Using the above devices, we can summarize the differences between the AMDI-QKD scheme considered in this paper and the original proposal. In particular, here we have replaced both the perfect entanglement source for the QND measurement and the perfect single-photon sources of Alice and Bob in the original AMDI-QKD koji by more realistic entanglement sources, described by Eq. (2), which have non-zero probability of emitting multiple-photon signals in general. Note that the single-photon sources possessed by Alice and Bob are achieved in our scheme by measuring one mode of their entanglement sources. Another modification is to change all the threshold detectors, which were in the BSM and the QND measurement, to PNR detectors. Apart from these, the protocol, of course, runs in a similar manner as in the original proposal koji , described in Sec. II.1.
IV Necessary conditions
In this section, we first derive a simple but non-trivial analytical necessary condition on the photon-number statistics of the sources for the AMDI-QKD protocol to be able to beat the repeaterless bound reported in PLOB , which is given by the formula . For this, we use the fact that, if one cannot beat the bound with and , then it is also impossible to beat it with and , since the secret key rate cannot increase with lower efficiency detectors. Thus, we can construct the necessary condition by requiring that the bound in PLOB is overcome when we set and , which significantly simplifies the secret key rate formula, making the derivation of an analytical result possible. With this simple necessary condition, it is already possible to show that PDC sources cannot beat the repeaterless bound with the AMDI-QKD protocol.
Afterwards, we consider the general case where and . In this scenario we can only obtain the condition on the sources to beat the repeaterless bound by numerically evaluating the secret key rate formula, given by Eq. (1). The required formulas to evaluate Eq. (1) can be found in Appendix B.
By comparing the two results, we see that the finite detection efficiency of the detectors has a significant impact on the required photon-number statistics of the sources. To be precise, when the detection efficiency of the detectors decreases, then the requirements on the maximum values of the multi-photon probabilities of the sources become more severe.
IV.1 Simple analytical necessary condition
When we set and , we find that the secret key rate formula can be written as (for the details of the calculation see Appendix B):
[TABLE]
where the () values represent the photon-number statistics of the sources and (). We remark that we can choose the values of to be equal for the sources and because Charlie is located halfway between them, and such selection is optimal in this scenario. Importantly, we note that in Eq. (8) only the probabilities , and appear. This is so because of the following. The appearance of and is the consequence of the fact that only single-photon pairs can give rise to true success events. Using unit efficiency detectors, the only possible way for multiple-photon pairs to cause a seemingly successful QND measurement is when the source emits the state and the signal from Alice (Bob) is lost during the transmission through the optical fiber, which explains the appearance of .
From Eq. (8) we learn, that in the case of the use of detectors with unit efficiency, in the asymptotic limit of (i.e., ), , which means that choosing the parameters , and properly, we can actually beat the repeaterless bound PLOB in this limit. The reason why the secret key rate never breaks down in the unit efficiency detector case is due to the fact that we have neglected dark counts and misalignment in the quantum channel.
Claim**.**
To beat the repeaterless bound PLOB with the AMDI-QKD protocol, using PNR detectors and entanglement sources and () of the form given by Eq. (2), with photon-number statistics (), it is necessary that
[TABLE]
is fulfilled.
Proof.
Making use of the Taylor expansion, the following inequality trivially holds for the repeaterless bound, reported in PLOB :
[TABLE]
Then, for the necessary condition, we require that , given by Eq. (8), is greater than .
If holds for the sources, an upper bound can be given on by plugging in the denominator of Eq. (8):
[TABLE]
Therefore, to be able to overcome the repeaterless bound PLOB , must hold, which means that we can upper bound the secret key rate by plugging in the denominator of Eq. (8):
[TABLE]
For the necessary condition it is then required that
[TABLE]
holds, which can be simplified to
[TABLE]
This inequality is tighter than . Moreover, since , we have that
[TABLE]
Considering this validity condition, we obtain the simple necessary condition given by Eq. (9). ∎
The necessary condition, given by Eq. (9), is depicted in Fig. 4, where we plot the value of , above which it is not possible to beat the bound PLOB , given the values of and . We can see that the necessary condition is more sensitive to the value of , than to the value of in the sense that if is too small then no matter how large we set , we need to have (purple area in Fig. 4). However, in the converse situation, having small does not imply that . One can also see this formally by noting that in Eq. (9) only appears squared. This is so, because, as explained before, even in the ideal efficiency detector case the source can cause errors by introducing two-photon pair signals. While the sources and cannot, since the detectors in the / measurement filter out all the two-photon pair signals.
Corollary**.**
Using PDC sources, it is impossible to beat the repeaterless bound PLOB with the AMDI-QKD protocol.
Proof.
The photon-number statistics of the PDC sources can be written as
[TABLE]
where, as already mentioned previously, () is a positive parameter, related to the amplitude of the laser used to pump the sources and (). We note that due to the symmetries of the setup, that is, Charlie is located halfway between Alice and Bob, we can set the values for the sources and equal.
Plugging Eq. (16) into Eq. (9), we have that
[TABLE]
is necessary to overcome the repeaterless bound PLOB . However, since and (the latter can be seen easily by taking the derivative with respect to ), we have that
[TABLE]
which obviously contradicts Eq. (17), meaning that for PDC sources the necessary condition cannot be fulfilled. Therefore, it is impossible to overcome the repeaterless bound PLOB . ∎
IV.2 Tighter necessary condition
In this section, we now analyse the necessary condition without the assumption of and . For this, we numerically evaluate the general secret key rate formula derived in Appendix B.
For simplicity, however, in the simulations, we restrict ourselves to the case where every source emits at most two photon pairs, that is, we set for any . We remark, however, that, with the general secret key rate formula given in Appendix B, it is possible to allow for an arbitrary number of emitted photon pairs if one has sufficient computational power. The results can be seen in Fig. 5. We introduced the quantities and to characterise the quality of the sources, lower values meaning higher quality sources since emitting two photon pairs is less likely than emitting the desired EPR pair, for given values of and .
Let denote the maximally allowable value of to be able to overcome the bound PLOB , as a function of and , given the parameters and . In Fig. 5, we plot the quantity as a function of and for different values of , given the value of . So that we can observe how does the value decreases for a given and if we have and , compared to the and case. We set as illustration, since this is the value used in the original implementation koji , based on the experiments reported in feedforward1 ; feedforward2 . Our simulations show that the value of does not influence significantly the order of magnitude tendencies observed while decreasing the detection efficiency of the detectors. Loosely speaking, varying the value of only translates the secret key rate curve vertically (i.e., the secret key rate basically decreases by a constant factor for all values of the channel loss) for given and values. This means that in the comparison, every curve for the different detection efficiencies will be translated by the same factor, therefore, for a different value, the values will also be altered by a common factor for each detection efficiency, and since we are plotting their quotients, it means that the plots on Fig. 5 will stay very similar.
First, let us examine the region of the plots where (reddish areas in Fig. 5), which means that the sources of Alice and Bob are close to perfect entanglement sources. We see that decreasing the value of from 1 to 0.9, 0.7 and 0.5 results in the need for about an order of magnitude higher quality sources at Charlie’s hand for each efficiency compared to the previous one. This is partly due to fact that eight detections are needed for obtaining a raw key bit (one in the / measurement of each Alice and Bob, two in the QND measurement at each side and two more in the BSM), therefore, now we have a factor of in the probability of each key generation event, but this only translates the secret key rate curve vertically. On top of this, and what is more important, we now have an increased probability of obtaining erroneous key generation events from the two-photon pair component of the sources . To see this, suppose that one of the sources on Alice’s side emits a two-photon pair signal and all the other sources emit one-photon pair signals, and suppose that the signal from Alice towards the QND measurement is lost in the transmission. In this case, as already mentioned previously, we can get a seemingly successful detection event if one photon out of the two going from the QND module towards the BSM is lost in the detection process of the BSM, which happens with a probability . Thus, the error rate will increase as we decrease the detection efficiency. The only way to compensate this error is to have better quality sources at Charlie’s hand (meaning lower values).
Now, let us observe the part of the plots, where (purplish areas in Fig. 5), meaning that Alice and Bob no longer have perfect entanglement sources. In this case, we find that the more we decrease the value of the more the values of in the region of will decrease compared to the values in the region of . In other words, in the region the values do not decrease linearly with , which is more or less true in the region. What has been said before for the region is true for this region as well, but, on top of those effects, since , the sources of Alice and Bob now have a non-zero probability of producing erroneous successful detections in the / measurements due to their two-photon pair component, which was not possible before in the region. Consider the previously explained situation with the difference, that Alice’s source now emits a two-photon pair signal and both photons from Alice heading towards the QND module are lost in the transmission. In this case we can only get a seemingly successful raw key generation event if one photon out of the two in the / measurement at Alice’s site is lost in the detection, which occurs with a probability . Thus, the probability of this type of error scales with (the other factor comes from the fact that in the scenario considered, we need to lose one more photon in the detection process of the BSM to have a seemingly successful raw key generation event), meaning that it does not depend linearly on the detection efficiency as in the region, which explains the observed behaviour for the region. From this, we can see that, as expected, has a more significant impact on the values than , which, since increasing will not increase the probabilities of an error, just translates the secret key rate curve vertically. These are the main reasons behind this dramatic increase in the quality of Charlie’s sources as we decrease .
Summing up the observations from Fig. 5 we can say that the necessary quality of the sources can be much higher than what is expected from the unit detection efficiency condition if we have non-perfect detectors. We also note that using the formulas for the secret key rate from Appendix B, Fig. 5 can be easily made for arbitrary and .
V Conclusion
We have investigated the performance of a more realistic implementation of the original AMDI-QKD protocol koji , assuming that the parties have access to a broad class of entanglement sources of the form given by Eq. (2) and photon-number resolving (PNR) detectors. We have shown that the improved scaling (with being the transmittance of the channel connecting Alice and Bob to Charlie), offered by the protocol, is very sensitive to multiple-photon pair components emitted by the sources.
More precisely, we have derived a simple non-trivial analytical necessary condition on the photon-number statistics of the entanglement sources to be able to overcome the repeaterless bound PLOB with the AMDI-QKD protocol. With this condition, we have demonstrated analytically that employing the widely available parametric down-conversion sources does not enable the protocol to beat the repeaterless bound. Furthermore, we have quantitatively investigated the effect that the finite detection efficiency of the detectors have on the required photon-number statistics of the sources. In this regard, we have shown that, when the detection efficiency of the detectors decreases, then the maximum tolerable values of the multi-photon probabilities of the sources in order to beat the repeaterless bound become significantly more severe. This latter study, however, was only feasible by numerically evaluating the secret key rate formula of the protocol.
Our results suggest, that, while the AMDI-QKD protocol could in principle overcome the repeaterless bound with idealized devices, in practice it demands very high quality entanglement sources, which are thus still challenging to realize with current technology, besides, of course, the involved multiplexing techniques depending on the channel length.
VI Acknowledgement
We thank the Spanish Ministry of Economy and Competitiveness (MINECO), the Fondo Europeo de Desarrollo Regional (FEDER) through the grant TEC2017-88243-R, and the European Union’s Horizon 2020 research and innovation programme under the Marie Sklodowska-Curie grant agreement No 675662 (project QCALL) for financial support. K.A. thanks support, in part, from PRESTO, JST JPMJPR1861.
Appendix A BSM with Hadamard gates
In this appendix we give an intuitive argument on the reason why the use of Hadamard gates is advantageous in the BSM after the optical switches. Suppose that the state used for key generation is , given by Eq. (3). If every source emits this state and a successful detection pattern occurs, the parties share the desired quantum correlation to obtain their secret key (given that dark counts are neglected). However, if some of the sources emit multiple-photon pair states, for example the state , also given by Eq. (3), this could result in a seemingly successful detection event, which does not provide the parties with the desired correlations and will end up producing errors. As we will show below, including the Hadamard gates in the BSM removes the possibility of getting errors from the state .
Let us illustrate this with an example depicted in Fig. 6. In particular, let us consider the situation when emits the state and there is a correct detection in Alice’s / measurement but the photon in the other mode (mode in Fig. 6), going towards the QND measurement, is lost in the transmission. Moreover, suppose that the source on Alice’s side emits the state, which can cause a seemingly successful QND measurement on Alice’s side and also a seemingly successful BSM at Charlie’s site.
Furthermore, suppose that the sources and on Bob’s side both emit the state. Let us assume that these signals cause successful / and QND measurements on Bob’s side, but the photon in the other mode (mode in Fig. 6), going from the source towards Charlie’s BSM module, is lost, say during the feedforward mechanism. Therefore, in this example, there is no actual signal coming from Bob to the BSM. This way, if the Hadamard gates are not used, it is possible that the state coming from the source on Alice’s side will result in a seemingly successful BSM. Consequently, the parties would conclude that the protocol had run correctly and they can obtain a secret key bit, but in reality, they will get random outcomes instead of correlated ones. Next, we show that this cannot occur in the presence of the Hadamard gates.
For simplicity, instead of , we assume that the source on Alice’s side emits the following unnormalised state
[TABLE]
The QND measurement is successful if there are exactly two, orthogonally polarized photons in the modes and (see Fig. 6):
[TABLE]
where we expressed the output modes and after the 50:50 BS in the QND measurement as a function of the input modes and . As explained above, in the particular example considered, there is no photon in mode . Therefore, a successful event could only be caused by the component from Eq. (A). Comparing with in Eq. (A), we conclude, that if the QND measurement on Alice’s side succeeded, then the state in mode has to be characterised by .
As explained previously, there is no photon in mode (coming from Bob). This means that, since there is one horizontally and one vertically polarized photon incident on the 50:50 BS in the BSM (mode ), a successful detection pattern in the BSM is easily produced, if there are no Hadamard gates.
Now, let us consider what happens with the Hadamard gates. Similarly to the QND measurement, the BSM is successful if there are exactly two, orthogonally polarized photons in the modes and :
[TABLE]
[TABLE]
[TABLE]
[TABLE]
where we expressed the modes and after the Hadamard gates as a function of the input modes and . In doing so, we used the matrices describing the quantum optical operation of the BS and the Hadamard gate. It is clear that in this example, the state , which we have after the seemingly successful QND measurement, cannot cause a successful BSM, since in Eqs. (A)-(A) there is no component that contains . Therefore, the error that was possible before is now filtered out by the Hadamard gates.
Appendix B Full-mode analysis
B.1 Rephrasing the secret key rate formula
The secret key rate formula, given by Eq. (1), can be written as koji
[TABLE]
where we have set . Also, as explained in the main text, we assume that since we consider the asymptotic scenario. We remind the reader that is the probability that Charlie’s QND and the / measurements are both successful either at Alice’s or Bob’s site. The quantity represents the success probability of one BSM. We note that since the -basis is used for the key generation the above quantities are defined in the case when Alice and Bob choose the -basis. We also note that the probabilities and by definition include all the possible detection patterns that constitute that particular success event.
However, due to the symmetries of the channel model, for our simulations, it is not necessary to calculate the probabilities of all the detection patterns that constitute a certain event, which would be rather tedious and redundant. Thus, in the remainder of this section, we are going to relate the quantities , , and to the probabilities of some particular detection patterns, relying on the symmetries of the channel model.
First, let denote the probability that there is exactly one photon detected in each of the detectors , and and zero photons detected in the other detectors , and in Fig. 7. Note that this means a successful QND measurement and simultaneously a successful measurement on Alice’s side, where she obtained the horizontal () polarization, and therefore this particular detection pattern represents one of the patterns that constitute . A successful QND measurement can be realized by four different detection patterns (observing altogether two photons in the QND module, one in polarization and one in polarization, i.e., if and , or and , or and , or and in Fig. 7 detect one photon each). The measurement can be realized by two different detection patterns (one photon detected in either or in Fig. 7). Altogether, this means eight different possibilities. Note that these eight detection patterns all have the same probability due to the symmetries of the channel model considered. Moreover, is also independent of the basis choice of Alice. Therefore, we can write that
[TABLE]
Now, let us also express with probabilities corresponding to particular detection patterns. For this, first, let (correct) denote the probability of the following particular detection pattern given that the parties choose to measure their local modes in the -basis. Suppose that Charlie’s QND and the measurement were successful on both Alice’s and Bob’s side with the particular detection pattern described before for (i.e., both parties detected polarization) and then in the BSM after the optical switches there is exactly one photon detected in each of the detectors and and zero photons detected in the other detectors and in Fig. 8. Note, that this detection pattern corresponds to a projection into the Bell state , which means that the parties will not apply bit flip, this way obtaining correlated (correct) raw key bits. The success probability of the BSM alone, corresponding to the above described particular detection pattern can be written as . We also note that in the BSM after the switches there is another detection pattern that corresponds to obtaining correlated (correct) raw key bits (projection into the Bell state ), which happens when there is one photon detected in both and and zero photons detected in and in Fig. 8. Due to the symmetries, this particular click pattern will also have probability . Therefore, the contribution to in this case will be .
Now, let us define (non-correct) in the same way as we defined , with the only difference being that in the BSM after the optical switches there is exactly one photon detected in each of the detectors and and zero photons detected in the other detectors and in Fig. 8. Note that this particular detection pattern corresponds to a projection into the Bell state , meaning that one of the parties will apply a bit flip, therefore obtaining anti-correlated (non-correct) raw key bits. Similarly to , there is another detection pattern that corresponds to obtaining the same anti-correlated raw key bits (one photon detected in both and and zero photons detected in and in Fig. 8). Again, due to the symmetries, this particular click pattern will also have probability, therefore the contribution to is in this case.
The quantity can be defined and calculated, similarly to the case for , by considering probabilities with which agreed and disagreed bits are adopted by Alice and Bob. However, for clarity, here we use another method to calculate . Choosing the -basis means that the parties apply a Hadamard gate on the mode in Fig. 7 before their local measurement with detectors and . From the symmetry of the protocol, without loss of generality, we can focus on a specific success event of Charlie where Charlie’s QND measurements on Alice’s side and Bob’s side announce single-photon detection in each of the detectors and and zero-photon detection in the other detectors and in Fig. 7, and Charlie’s final Bell measurement announces single-photon detection in each of the detectors and and zero-photon detection in the other detectors and in Fig. 8. Then, since Alice and Bob would share entanglement close to , we define (correct) [ (non-correct)] as a probability with which Charlie obtains the specific success event and Alice (Bob) detects exactly one photon in the detector () [ ()] on her (his) side and zero photons in the other detector included in her (his) measurement in Fig. 7.
With these at our hands, we can write that
[TABLE]
and
[TABLE]
Consequently, we can rewrite Eq. (25) to the following form:
[TABLE]
The remainder of Appendix B is structured as follows. In Appendix B.2 we derive , then in Appendix B.3 and Appendix B.4 we derive , and , . And finally, in B.5 we obtain the secret key rate formula for the and case.
B.2 Derivation of
The layout for this derivation can be seen in Fig. 7. For convenience, we use the density matrix formalism for the sources. It is easy to see that converting the emitted state , given by Eq. (2), into a density matrix in the -basis, only the diagonal terms will give contributions when calculating the probabilities of the different detection patterns (described by the POVMs of Eq. (5), which are diagonal in the Fock basis) since different values of represent different photon numbers. This means that for our calculations, instead of using the pure states given by Eq. (2), we can use mixed states of the following form:
[TABLE]
with and . For the experimental setup considered, the results in both cases (i.e., by using Eq. (2) or Eq. (B.2)) coincide. The states and are given by
[TABLE]
where , , and (, , and ) are the creation operators of horizontally (vertically) polarized photons of the corresponding modes.
Next, we calculate the quantum state from Alice that enters the 50:50 beam splitter (BS) within the QND measurement after travelling through the quantum channel. For this, we model the quantum channel by a BS with transmittance . In doing so, it turns out that such a state is given by
[TABLE]
where the states are given by
[TABLE]
The 50:50 BS combines the states and . So, the state after the 50:50 BS can be written as
[TABLE]
where the pure states have the form of
[TABLE]
The quantity is defined (see Appendix B.1) by the probability of the event that there is exactly one photon detected in each of the modes , and (detectors , and in Fig. 7) and zero photons detected in the modes , and (detectors , and in Fig. 7). This event is described by the following POVM
[TABLE]
where we extended the notation used in Eq. (5) with including the corresponding optical mode as a superscript.
The unnormalised state that enters Charlie’s BSM module from Alice (Bob) is then given by
[TABLE]
We repeatedly make use of the following transformation of the summation indices, whenever we calculate the trace of an expression.
[TABLE]
where is an arbitrary function of the indices , and we introduced the sum of the summation indices. Carrying out the calculations, it can be shown, by using Eq. (38), that can be put into the following form
[TABLE]
where can be written as
[TABLE]
where denotes that there are and photons in modes and , respectively. The quantity , on the other hand, equals to
[TABLE]
The probability can be obtained as the normalization factor of :
[TABLE]
B.3 Derivation of and
The layout for this derivation can be seen in Fig. 8. Using the previous result for the state coming from the QND and the measurement, which is given by Eq. (39), the state that enters Charlie’s BSM module from Alice’s (Bob’s) side is (). Therefore, their collective state can be written as
[TABLE]
where note that upper case indices are used to describe quantities corresponding to mode (coming from Bob’s side), while using lower case indices to describe quantities corresponding to mode (coming from Alice’s side). For simplicity, in Eq. (B.3) we introduced the following notation:
[TABLE]
For brevity, after the last equation sign in Eq. (B.3) we denoted all the sums collectively by . The state after the 50:50 BS can then be written concisely as
[TABLE]
where the states are given by
[TABLE]
Then, the state after the Hadamard gates can be written as
[TABLE]
where the pure states have the form
[TABLE]
With Eq. (38), we can rewrite the states into a form, in which it will be more convenient to take the trace of Eq. (47):
[TABLE]
The quantity is defined (see Appendix B.1) by the probability of the event that, one photon is observed in each of the modes and (one detection in each of the detectors and in Fig. 8) and zero photons are observed in each of the modes and (no detection in neither of the detectors and in Fig. 8)
Similarly, is by definition equal to the probability of the event that one photon is observed in each of the modes and (one detection in each of the detectors and in Fig. 8) and zero photons are observed in each of the modes and (no detection in neither of the detectors and in Fig. 8).
These events are described by the following POVMs
[TABLE]
and
[TABLE]
Since for convenience in the calculations we incorporate the loss corresponding to the active feedforward mechanism into the efficiency of the detectors in the BSM module, the efficiency becomes
[TABLE]
This is the efficiency assumed in the POVM elements given by Eq. (50) and Eq. (51), where is the necessary time for performing one active feedforward and is the speed of light in the optical fiber.
Therefore, and can be calculated as follows
[TABLE]
and
[TABLE]
with given by Eq. (47). Carrying out the calculations and plugging all the indices back in, we find that and are given by the following formulas:
[TABLE]
and
[TABLE]
Note, that the only differences between and are in the limits of the index and in the expression after the sums. Moreover, the term is given by the following expression
[TABLE]
B.4 Derivation of and
The derivation of the probabilities and is very similar to the derivation of and in Appendix B.3. However, for the -basis we perform the derivation with a slightly different structure, that is, we perform the measurements at the very end, after Charlie’s QND measurement and BSM have gone through successfully. However, we remark that the calculations could also be done using the same structure like in Appendix B.3.
So firstly, we obtain the state that Alice (Bob) has after Charlie’s QND measurement was performed successfully on her (his) side, which is described by the following POVM:
[TABLE]
where note that we use the same notation for the modes as in Fig. 7 and we excluded the measurement so far. Let us denote this state by () on Alice’s (Bob’s) side. Then, we take the tensor product and perform the middle BSM with the POVM of Eq. (58), but here the modes correspond to Fig. 8 since this is the measurement being executed. Next, on the obtained state from the BSM, the parties perform the measurement, which essentially means that they apply Hadamard gates on their modes and after that they perform the measurement in Fig. 7. Let denote the state held by Alice and Bob after they apply the Hadamard gates, where () represents the optical mode entering the PNR detectors in the measurement at Alice’s (Bob’s) site.
Considering the detection patterns that define the correlated (correct) and anti-correlated (non-correct) raw key generation events, as explained previously in Appendix B.1, we have that
[TABLE]
[TABLE]
with
[TABLE]
and
[TABLE]
Here, for simplicity we only present the results for the main steps of the derivation. The state is given by the following formula:
[TABLE]
where () is the mode that enters Alice’s measurement (Charlie’s BSM from Alice’s side) and is given by the following expression:
[TABLE]
We note that has the exact same form with mode () entering Bob’s measurement (Charlie’s BSM from Bob’s side) and in the expression of we use capital letter indices similarly to Appendix B.3:
[TABLE]
Then we obtain by performing Charlie’s BSM on modes and and applying Hadamard gates to the modes and :
[TABLE]
where, for the sake of convenience, we introduced the following functions:
[TABLE]
and
[TABLE]
which enters into the expressions when the Fock-states are expressed with the creation/annihilation operators, and
[TABLE]
which is introduced due to the Hadamard gates included in the implementation, and
[TABLE]
which comes from the successful detection pattern’s POVM. With the formula for , given by Eq. (B.4), and Eqs. (59)-(60) we can obtain
[TABLE]
and
[TABLE]
Note that the differences between and are in the limits of the summation index and in the arguments of the function . Moreover, we note that we have found strong numerical evidence that and hold, but we have not been able to show it analytically by comparing Eq. (B.3) and Eq. (B.3) to Eq. (B.4) and Eq. (B.4).
Now, with Eq. (B.2), Eq. (B.3), Eq. (B.3), Eq. (B.4) and Eq. (B.4) we have all the quantities that are required in order to evaluate the secret key rate of the protocol, which is given by Eq. (29).
B.5 Derivation of the secret key rate in the case of and
The unit efficiency secret key rate formula can be obtained by noting that in the quantities , , , and , given by Eq. (B.2), Eq. (B.3), Eq. (B.3), Eq. (B.4) and Eq. (B.4) only those terms in which the power of and is [math] contribute to the sums. This gives restriction on the indices appearing in the power of the terms and . Systematically examining the different cases one by one, we can rule out most of possibilities for the indices. For this, we need to keep in mind that if a sum happens to have a smaller number in the upper limit than that in the lower limit, then the corresponding term gives no contribution to the sum.
Using the recipe given above and the formulas Eq. (B.2), Eq. (B.3), Eq. (B.3), Eq. (B.4) and Eq. (B.4), we have that
[TABLE]
[TABLE]
and
[TABLE]
It is interesting that turns out to be [math] when we set and . In the case considered in the calculations above, Alice and Bob both measured (horizontal) polarizations in their measurement and the two QND measurements succeeded on both side. This means that Charlie’s BSM will get input signals in (vertical) polarizations from both sides. An error can only occur when they apply the bit flip (see step 5 of the protocol), which only happens when Charlie detects a singlet state. But due to the Hong-Ou-Mandel effect the photons will always go to the same arm, therefore in this ideal case Charlie cannot obtain a singlet detection. The same argument holds for the -basis as well. Plugging Eq. (73), Eq. (74) and Eq. (75) into Eq. (29) we obtain the secret key rate formula for the unit detection efficiency case, given by Eq. (8).
References
(2) N. Gisin, G. Ribordy, W. Tittel and H. Zbinden: Quantum cryptography, Reviews of Modern Physics 74, 145 (2002).
(3) V. Scarani, H. B.-Pasquinucci, N. J. Cerf, M. Dušek, N. Lütkenhaus and M. Peev: The security of practical quantum key distribution, Reviews of Modern Physics 81, 1301 (2009).
(4) H.-K. Lo, M. Curty and K. Tamaki: Secure quantum key distribution, Nature Photonics 8, 595-604 (2014).
(5) M. Takeoka, S. Guha, and M. M. Wilde: Fundamental rate-loss tradeoff for optical quantum key distribution, Nature Communications 5, 5235 (2014).
(6) S. Pirandola, R. Laurenza, C. Ottaviani and L. Banchi: Fundamental limits of repeaterless quantum communications, Nature Communications 8, 15043 (2017).
(7) M. M. Wilde, M. Tomamichel and M. Berta: Converse Bounds for Private Communication Over Quantum Channels IEEE Transactions on Information Theory 63, 1792-1817 (2017).
(8) H.-J. Briegel, W. Dür, J. I. Cirac and P. Zoller: Quantum repeaters: the role of imperfect local operations in quantum communication, Physical Review Letters 81, 5932 (1998).
(9) L.-M. Duan, M. D. Lukin, J. I. Cirac and P. Zoller: Long-distance quantum communication with atomic ensembles and linear optics, Nature 414, 413-418 (2001).
(10) P. Kok, C. P. Williams and J. P. Dowling: Construction of a quantum repeater with linear optics, Physical Review A 68, 022301 (2003).
(11) P. van Loock et al.: Hybrid Quantum Repeater Using Bright Coherent Light, Physical Review Letters 96, 240501 (2006).
(12) L. Jiang, J. M. Taylor, K. Nemoto, W. J. Munro, R. Van Meter and M. D. Lukin: Quantum repeater with encoding, Physical Review A 79, 032325 (2009).
(13) N. Sangouard, C. Simon, H. de Riedmatten and N. Gisin: Quantum repeaters based on atomic ensembles and linear optics, Reviews of Modern Physics 83, 33 (2011).
(14) K. Azuma, H. Takeda, M. Koashi and N. Imoto: Quantum repeaters and computation by a single module: Remote nondestructive parity measurement, Physical Review A 85, 062309 (2012).
(15) W. J. Munro, A. M. Stephens, S. J. Devitt, K. A. Harrison and K. Nemoto: Quantum communication without the necessity of quantum memories, Nature Photonics 6, 777-781 (2012).
(16) K. Azuma, K. Tamaki and H.-K. Lo: All-photonic quantum repeaters, Nature Communications 6, 6787 (2015).
(17) N. Sangouard: A future without long memories?, Nature Photonics 6, 722-724 (2012).
(18) M. Lucamarini, Z. L. Yuan, J. F. Dynes and A. J. Shields: Overcoming the rate-distance limit of quantum key distribution without quantum repeaters, Nature 557, 400-403 (2018).
(19) K. Tamaki, H.-K. Lo, W. Wang and M. Lucamarini: Information theoretic security of quantum key distribution overcoming the repeaterless secret key capacity bound, preprint arXiv:1805.05511v3 (2018).
(20) X. Ma, P. Zeng and H. Zhou: Phase-Matching Quantum Key Distribution, Physical Review X 8, 031043 (2018).
(21) X.-B. Wang, Z.-W. Yu and X.-L. Hu: Twin-field quantum key distribution with large misalignment error, Physical Review A 98, 062323 (2018).
(22) J. Lin and N. Lütkenhaus: Simple security analysis of phase-matching measurement-device-independent quantum key distribution, Physical Review A 98, 042332 (2018).
(23) C. Cui et al.: Twin-field quantum key distribution without phase post-selection, Physical Review Applied 11, 034053 (2019).
(24)
H.-L. Yin and Y. Fu: Measurement-Device-Independent Twin-Field Quantum Key Distribution, Scientific Reports 9, 3045 (2019).
(25) M. Curty, K. Azuma and H.-K. Lo: Simple security proof of twin-field type quantum key distribution protocol, npj Quantum Information 5, 64 (2019).
(26) X. Zhong, J. Hu, M. Curty, L. Qian and H.-K. Lo: Proof-of-principle experimental demonstration of twin-field type quantum key distribution, preprint arXiv:1902.10209v1 (2019).
(27) M. Minder et al.: Experimental quantum key distribution beyond the repeaterless secret key capacity, Nature Photonics 13, 334-338 (2019)
(28) Y. Liu et al.: Experimental Twin-Field Quantum Key Distribution Through Sending-or-Not-Sending, preprint arXiv:1902.06268v1 (2019).
(29) S. Wang et al.: Beating the Fundamental Rate-Distance Limit in a Proof-of-Principle Quantum Key Distribution System, Physical Review X 9, 021046 (2019).
(30) H.-K. Lo, M. Curty, and B. Qi: Measurement-Device-Independent Quantum Key Distribution, Physical Review Letters 108, 130503 (2012).
(31) D. Luong, L. Jiang, J. Kim and N. Lütkenhaus: Overcoming lossy channel bounds using a single quantum repeater node, Applied Physics B 122, 96 (2016).
(32) S. Abruzzo, H. Kampermann and D. Bruß: Measurement-device-independent quantum key distribution with quantum memories, Physical Review A 89, 012301 (2014).
(33) C. Panayi, M. Razavi, X. Ma and N. Lütkenhaus: Memory-assisted measurement-device-independent quantum key distribution, New Journal of Physics 16, 043005 (2014).
(34) R. Trényi and N. Lütkenhaus: Beating direct transmission bounds for quantum key distribution with a multiple quantum memory station. 8th International Conference on Quantum Cryptography, Shanghai, China (2018).
(35) K. Azuma, K. Tamaki and W. J. Munro: All-photonic intercity quantum key distribution, Nature Communications 6, 10171 (2015).
(36) P. Kok, H. Lee, and J. P. Dowling: Single-photon quantum-nondemolition detectors constructed with linear optics and projective measurements, Physical Review A 66, 063814 (2002).
(37) B. Zhao, Z.-B. Chen, Y.-A. Chen, J. Schmiedmayer and J.-W. Pan: Robust creation of entanglement between remote memory qubits, Physical Review Letters 98, 240502 (2007).
(38) N. L. Piparo, M. Razavi and C. Panayi: Measurement-Device-Independent Quantum Key Distribution With Ensemble-Based Memories, IEEE Journal of Selected Topics in Quantum Electronics 21, 6601010 (2015).
(39) X. Ma, C. H. F. Fung and H.-K. Lo: Quantum key distribution with entangled photon sources, Physical Review A 76, 012307 (2007).
(40) C. H. Bennett, G. Brassard, C. Crepeau: Teleporting an unknown quantum state via dual classical and Einstein-Podolsky-Rosen channels, Physical Review Letters 70, 1895-1899 (1993).
(41) W. P. Grice: Arbitrarily complete Bell-state measurement using only linear optical elements, Physical Review A 84, 042331 (2011).
(42) F. Ewert and P. van Loock: 3/4-efficient Bell measurement with passive linear optics and unentangled ancillae, Physical Review Letters 113, 140403 (2014).
(43) R. Prevedel et al.: High-speed linear optics quantum computing using active feed-forward, Nature 445, 65-69 (2007).
(44) X.-song Ma, S. Zotter, J. Kofler, T. Jennewein and A. Zeilinger: Experimental generation of single photons via active multiplexing, Physical Review A 83, 043814 (2011).
The reference list from the paper itself. Each links out to its DOI / PubMed record.
- 1(1)
- 2(2) N. Gisin, G. Ribordy, W. Tittel and H. Zbinden: Quantum cryptography, Reviews of Modern Physics 74, 145 (2002). (3) V. Scarani, H. B.-Pasquinucci, N. J. Cerf, M. Dušek, N. Lütkenhaus and M. Peev: The security of practical quantum key distribution, Reviews of Modern Physics 81, 1301 (2009). (4) H.-K. Lo, M. Curty and K. Tamaki: Secure quantum key distribution, Nature Photonics 8, 595-604 (2014). (5) M. Takeoka, S. Guha, and M. M. Wilde: Fundamental rate-loss tradeoff f
- 3(3) V. Scarani, H. B.-Pasquinucci, N. J. Cerf, M. Dušek, N. Lütkenhaus and M. Peev: The security of practical quantum key distribution, Reviews of Modern Physics 81, 1301 (2009). (4) H.-K. Lo, M. Curty and K. Tamaki: Secure quantum key distribution, Nature Photonics 8, 595-604 (2014). (5) M. Takeoka, S. Guha, and M. M. Wilde: Fundamental rate-loss tradeoff for optical quantum key distribution, Nature Communications 5, 5235 (2014). (6) S. Pirandola, R. Laurenza, C. Ottavia
- 4(4) H.-K. Lo, M. Curty and K. Tamaki: Secure quantum key distribution, Nature Photonics 8, 595-604 (2014). (5) M. Takeoka, S. Guha, and M. M. Wilde: Fundamental rate-loss tradeoff for optical quantum key distribution, Nature Communications 5, 5235 (2014). (6) S. Pirandola, R. Laurenza, C. Ottaviani and L. Banchi: Fundamental limits of repeaterless quantum communications, Nature Communications 8, 15043 (2017). (7) M. M. Wilde, M. Tomamichel and M. Berta: Converse Bounds fo
- 5(5) M. Takeoka, S. Guha, and M. M. Wilde: Fundamental rate-loss tradeoff for optical quantum key distribution, Nature Communications 5, 5235 (2014). (6) S. Pirandola, R. Laurenza, C. Ottaviani and L. Banchi: Fundamental limits of repeaterless quantum communications, Nature Communications 8, 15043 (2017). (7) M. M. Wilde, M. Tomamichel and M. Berta: Converse Bounds for Private Communication Over Quantum Channels IEEE Transactions on Information Theory 63, 1792-1817 (2017). (8
- 6(6) S. Pirandola, R. Laurenza, C. Ottaviani and L. Banchi: Fundamental limits of repeaterless quantum communications, Nature Communications 8, 15043 (2017). (7) M. M. Wilde, M. Tomamichel and M. Berta: Converse Bounds for Private Communication Over Quantum Channels IEEE Transactions on Information Theory 63, 1792-1817 (2017). (8) H.-J. Briegel, W. Dür, J. I. Cirac and P. Zoller: Quantum repeaters: the role of imperfect local operations in quantum communication, Physical Review L
- 7(7) M. M. Wilde, M. Tomamichel and M. Berta: Converse Bounds for Private Communication Over Quantum Channels IEEE Transactions on Information Theory 63, 1792-1817 (2017). (8) H.-J. Briegel, W. Dür, J. I. Cirac and P. Zoller: Quantum repeaters: the role of imperfect local operations in quantum communication, Physical Review Letters 81, 5932 (1998). (9) L.-M. Duan, M. D. Lukin, J. I. Cirac and P. Zoller: Long-distance quantum communication with atomic ensembles and linear optics,
- 8(8) H.-J. Briegel, W. Dür, J. I. Cirac and P. Zoller: Quantum repeaters: the role of imperfect local operations in quantum communication, Physical Review Letters 81, 5932 (1998). (9) L.-M. Duan, M. D. Lukin, J. I. Cirac and P. Zoller: Long-distance quantum communication with atomic ensembles and linear optics, Nature 414, 413-418 (2001). (10) P. Kok, C. P. Williams and J. P. Dowling: Construction of a quantum repeater with linear optics, Physical Review A 68, 022301 (2003).
