Contents
1. Introduction to CV-QKD
Continuous-Variable Quantum Key Distribution (CV-QKD) enables two parties (Alice and Bob) to establish a shared secret key with information-theoretic security guaranteed by quantum mechanics. Unlike discrete-variable QKD that uses single photons, CV-QKD encodes information in the continuous quadratures of the electromagnetic field.
Key Advantages of CV-QKD:
- Compatible with standard telecom infrastructure
- Higher key rates at metropolitan distances
- Room-temperature operation (no cryogenics)
- Potential for photonic integration
- Efficient reconciliation with low-density parity-check codes
The security of CV-QKD stems from the Heisenberg uncertainty principle: any eavesdropper (Eve) attempting to measure the quantum states will inevitably introduce detectable noise.
2. Gaussian Quantum States
In CV-QKD, information is encoded in coherent states |α⟩, which are minimum-uncertainty states displaced from the vacuum. The quadrature operators X̂ and P̂ satisfy the commutation relation:
For a coherent state |α⟩ with α = x + ip:
The Shot Noise Unit (SNU) is the fundamental reference for all noise measurements in CV-QKD. It represents the quantum vacuum fluctuations and equals 1 by convention.
Covariance Matrix
Gaussian states are fully characterized by their first moments (mean values) and covariance matrix γ. For a two-mode state shared between Alice and Bob:
3. GMCS Protocol
The Gaussian-Modulated Coherent State (GMCS) protocol is the most widely implemented CV-QKD scheme:
State Preparation (Alice)
Alice draws random values x, p from Gaussian distribution N(0, V_A) and prepares coherent state |α = x + ip⟩
Quantum Transmission
State transmitted through quantum channel (fiber) with transmittance T and excess noise ξ
Measurement (Bob)
Bob performs homodyne (one quadrature) or heterodyne (both quadratures) detection
Classical Post-Processing
Parameter estimation, error correction (reconciliation), and privacy amplification
Modulation Variance V_A
The modulation variance V_A (in SNU) determines the signal strength. Typical values range from 1-20 SNU. Higher V_A increases mutual information I_AB but also increases Eve's accessible information. Optimal V_A depends on channel parameters.
4. Coherent Detection
Homodyne Detection
- • Measures single quadrature (X or P)
- • Bob randomly selects measurement basis
- • Half of data discarded (basis mismatch)
- • No 3 dB vacuum noise penalty
- • Shot-noise limited with balanced detection
Heterodyne Detection
- • Measures both quadratures simultaneously
- • No basis selection needed
- • All data used for key generation
- • 3 dB noise penalty per quadrature
- • Simpler implementation
Balanced Detection
Balanced (differential) detection uses two photodiodes to subtract common-mode noise, achieving shot-noise limited performance. The signal is interfered with a strong Local Oscillator (LO) at a 50:50 beamsplitter. Key parameters: Common-Mode Rejection Ratio (CMRR), phase matching, and amplitude balance.
5. Quantum Channel Model
The quantum channel is modeled as a thermal-loss channel characterized by transmittance T and excess noise ξ:
Transmittance T
α ≈ 0.2 dB/km for standard fiber at 1550 nm
Channel-Added Noise
Noise referred to channel input
Total Noise
Including excess noise and electronic noise
Critical: Excess Noise
Excess noise ξ is the most critical parameter limiting CV-QKD range. Sources include: laser phase noise, timing jitter, polarization drift, and imperfect modulation. A change of 0.005 SNU can halve the achievable distance.
6. Security Analysis
CV-QKD security is proven against various attack models with increasing power:
Individual Attacks
Eve measures each signal independently. Weakest attack model.
Collective Attacks
Eve performs identical operations on each signal but may delay measurement until reconciliation. Security bounded by Holevo information χ_BE.
Coherent (General) Attacks
Eve can perform arbitrary joint quantum operations on all signals. Strongest attack model. Security proven via de Finetti theorem reduction.
Composable Security
Modern CV-QKD proofs provide composable security, meaning the key can be safely used in any cryptographic application. The security is characterized by small failure probabilities ε_sec (secrecy), ε_cor (correctness), with total security ε_tot = ε_sec + ε_cor.
7. Secret Key Rate
The asymptotic secret key rate (in reverse reconciliation) is:
where β is reconciliation efficiency (typically 0.90-0.98)
Mutual Information I_AB
For homodyne detection:
Holevo Bound χ_BE
Eve's accessible information:
λᵢ: symplectic eigenvalues
Finite-Size Effects
For practical block sizes N, corrections reduce the key rate:
Δ_PE: parameter estimation, Δ_PA: privacy amplification, Δ_EC: error correction
8. PIC Implementation
Photonic Integrated Circuit (PIC) implementation offers compact, stable, and potentially mass-manufacturable CV-QKD systems. Key considerations:
Typical PIC Loss Budget
| Grating coupler (per facet) | 3-6 dB |
| Waveguide propagation | 0.5-2 dB/cm |
| Modulator | 1-3 dB |
| Splitters/combiners | 0.1-0.5 dB |
| LO routing | 2-4 dB |
Design Trade-offs
- • 1 dB PIC loss ≈ 5% effective detector QE reduction
- • Integration benefits: stability, compactness, cost reduction
- • Challenges: loss minimization, thermal management, packaging
- • Platform options: Silicon photonics (high integration), InP (active devices), SiN (low loss)
References
- Grosshans et al., "Continuous variable quantum cryptography," Phys. Rev. Lett. 88, 057902 (2002)
- Weedbrook et al., "Gaussian quantum information," Rev. Mod. Phys. 84, 621 (2012)
- Leverrier, "Composable security proof for CV-QKD," Phys. Rev. Lett. 114, 070501 (2015)
- Diamanti et al., "Practical challenges in CV-QKD," npj Quantum Information 2, 16025 (2016)
- Zhang et al., "Integrated silicon photonic CV-QKD transmitter," Nature Photonics (2019)