Searcharxiv⌕ Search

arXiv subjects

Akihiro Mizutani

Publications and source records attributed to Akihiro Mizutani.

At least 19 recordsLinked to original sources

Deterministic QKD source robust against side-channel attacks

Quantum key distribution (QKD) is secure in principle, but practical security can be undermined by discrepancies between real devices and the idealized models assumed in security proofs. Source side channels, including those exploited by Trojan-horse attacks, are particularly detrimental: neglecting them compromises implementation security, whereas accounting for them reduces performance. Here we propose a QKD source that is intrinsically robust against side-channel attacks. Unlike existing passive and modulator-free schemes, it requires neither post-selection of the emitted pulses nor devices with a perfect extinction ratio to suppress side channels, and it does not introduce correlations between the intensity and the encoded bit or basis. Consequently, under idealized source assumptions commonly adopted in proposals for existing schemes, conventional decoy-state security analyses apply directly, yielding substantially higher key rates. Our proposal appears to be within reach of current technology and therefore provides a clear and practical path toward implementation-secure QKD.

quant-ph↗

Phase-error estimation for quantum key distribution with leaky receivers

Practical quantum key distribution (QKD) receivers may leak information about their measurement outcomes and settings to the channel (e.g., through detector backflashes or back-reflected Trojan-horse light) that could compromise the protocol's security. Here we present a simple finite-key security proof based on phase-error estimation for prepare-and-measure QKD in the presence of either a priori information leakage about the basis choices and/or a posteriori information leakage about the measurement outcomes. The proof requires only a bound on the distinguishability of the side-channel states. Furthermore, the analysis is modular and compatible with existing security proofs that address detector and source imperfections, making it applicable to a wide range of practical QKD implementations.

quant-ph↗

Finite-key security analysis of the decoy-state BB84 QKD with passive measurement

The decoy-state Bennett-Brassard 1984 (BB84) quantum key distribution (QKD) protocol is widely regarded as the de facto standard for practical implementations. On the receiver side, passive basis choice is attractive because it significantly reduces the need for random number generators and eliminates the need for optical modulators. Despite these advantages, a finite-key analytical security proof for the decoy-state BB84 protocol, where the basis is chosen passively with a biased probability, has been lacking. In this work, we present a simple analytical finite-key security proof for this setting, yielding a closed-form secret-key rate formula that can be directly evaluated using experimentally accessible parameters. Numerical simulations show that the key rates of passiveand active-measurement implementations are nearly identical, indicating that passive measurement does not compromise key-generation efficiency in practical QKD systems.

quant-ph↗

Security loophole in error verification in quantum key distribution

The security of quantum key distribution (QKD) is evaluated based on the secrecy of Alice's key and the correctness of the keys held by Alice and Bob. A practical method for ensuring correctness is known as error verification, in which Alice and Bob reveal a portion of their reconciled keys and check whether the revealed information matches. In this paper, we point out that when error verification is performed in a QKD protocol, the definition of secrecy must be revised accordingly. We illustrate the necessity of this revision with a counterexample, showing that neglecting it can lead to an incorrect security claim. In particular, we observe that in the case of security proof method based on phase error correction, which is one of the mainstream approaches and also known as Koashi's approach, no explicit method has been established to properly incorporate the revised secrecy definition. To resolve this issue, we present a way to translate the phase error correction-based approach into another mainstream approach, called the leftover hashing lemma-based approach, also known as Renner's approach, where a solution has already been formulated. As a consequence, security proofs under the phase error correction-based approach automatically remain valid without any change in the secret key length, even if they implicitly consider error verification without revising the secrecy definition.

quant-ph↗

Protocol-level description and self-contained security proof of decoy-state BB84 QKD protocol

In this paper, we present a flowchart-based description of the decoy-state BB84 quantum key distribution (QKD) protocol and provide a step-by-step, self-contained information-theoretic security proof for this protocol within the universal composable security framework. As a result, our proof yields a key rate consistent with previous findings. Importantly, unlike all the prior security proofs, our approach offers a fully rigorous and mathematical justification for achieving the key rate with the claimed correctness and secrecy parameters, thereby representing a significant step toward the formal certification of QKD systems.

quant-ph↗

Rewindable Quantum Computation and Its Equivalence to Cloning and Adaptive Postselection

We define rewinding operators that invert quantum measurements. Then, we define complexity classes ${\sf RwBQP}$, ${\sf CBQP}$, and ${\sf AdPostBQP}$ as sets of decision problems solvable by polynomial-size quantum circuits with a polynomial number of rewinding operators, cloning operators, and adaptive postselections, respectively. Our main result is that ${\sf BPP}^{\sf PP}\subseteq{\sf RwBQP}={\sf CBQP}={\sf AdPostBQP}\subseteq{\sf PSPACE}$. As a byproduct of this result, we show that any problem in ${\sf PostBQP}$ can be solved with only postselections of events that occur with probabilities polynomially close to one. Under the strongly believed assumption that ${\sf BQP}\nsupseteq{\sf SZK}$, or the shortest independent vectors problem cannot be efficiently solved with quantum computers, we also show that a single rewinding operator is sufficient to achieve tasks that are intractable for quantum computation. Finally, we show that rewindable Clifford circuits remain classically simulatable, but rewindable instantaneous quantum polynomial time circuits can solve any problem in ${\sf PP}$.

quant-ph↗

Loss-tolerant quantum key distribution with detection efficiency mismatch

Current implementations of quantum key distribution (QKD) typically rely on prepare-and-measure (P&M) schemes. Unfortunately, these implementations are not completely secure, unless security proofs fully incorporate all imperfections of real devices. So far, existing proofs have primarily focused on imperfections of either the light source or the measurement device. In this paper, we establish a security proof for the loss-tolerant P&M QKD protocol that incorporates imperfections in both the source and the detectors. Specifically, we demonstrate the security of this scheme when the emitted states deviate from the ideal ones and Bob's measurement device does not meet the basis-independent detection efficiency condition. Furthermore, we conduct an experiment to characterise the detection efficiency mismatch of commercial single-photon detectors as a function of the polarisation state of the input light, and determine the expected secret key rate in the presence of state preparation flaws when using such detectors. Our work provides a way towards guaranteeing the security of actual implementations of widely deployed P&M QKD.

quant-ph↗

Differential-phase-shift QKD with practical Mach-Zehnder interferometer

Differential-phase-shift (DPS) quantum key distribution stands as a promising protocol due to its simple implementation, which can be realized with a train of coherent pulses and a passive measurement unit. To implement the DPS protocol, it is crucial to establish security proofs incorporating practical imperfections in users' devices, however, existing security proofs make unrealistic assumptions on the measurement unit using a Mach-Zehnder interferometer. In this paper, we enhance the implementation security of the DPS protocol by incorporating a major imperfection in the measurement unit. Specifically, our proof enables us to use practical beam splitters with a known range of the transmittance rather than the one with exactly $50\%$, as was assumed in the existing security proofs. Our numerical simulations demonstrate that even with fluctuations of $\pm0.5\%$ in the transmittance from the ideal value, the key rate degrades only by a factor of 0.57. This result highlights the feasibility of the DPS protocol with practical measurement setups.

quant-ph↗

Tight scaling of key rate for differential-phase-shift quantum key distribution

The performance of quantum key distribution (QKD) protocols is evaluated based on the ease of implementation and key generation rate. Among major protocols, the differential-phase-shift (DPS) protocol has the advantage of simple implementation using a train of coherent pulses and a passive detection unit. Unfortunately, however, its key rate is known to be at least proportional to $η^2$ with respect to channel transmission $η\to0$. If one can only prove the rate proportional to $η^2$ and cannot improve the analysis beyond that, then the DPS protocol will be deemed inferior to other major protocols, such as the decoy BB84 protocol. In this paper, we consider a type of DPS protocol in which the phase of each emitted block comprising $n$ pulses is randomized and significantly improve the analysis of its key rate. Specifically, we reveal that the key rate is proportional to $η^{1+\frac{1}{n-2}}$ and this rate is tight. This implies that the DPS protocol can achieve a key rate proportional to $η$ for a large number of $n$, which is the same scaling as the decoy BB84 protocol. Our result suggests that the DPS protocol can achieve a combination of both advantages of ease of implementation and a high key generation rate.

quant-ph↗

Unconditional verification of quantum computation with classical light

Verification of quantum computation is a task to efficiently check whether an output given from a quantum computer is correct. Existing verification protocols conducted between a quantum computer to be verified and a verifier necessitate quantum communication to unconditionally detect any malicious behavior of the quantum computer solving any promise problem in ${\sf BQP}$. In this paper, we remove the necessity of the communication of qubits by proposing a "physically classical" verification protocol in which the verifier just sends coherent light to the quantum computer.

quant-ph↗

Quantum key distribution with unbounded pulse correlations

A prevalent issue in practical applications of quantum key distribution (QKD) is the emergence of correlations among the emitted signals. Although recent works have proved the security of QKD in the presence of this imperfection, they rest on the premise that pulse correlations are of finite length. However, this assumption is not necessarily met in practice, since the length of these correlations could be potentially unbounded. Indeed, the first emitted pulse could be correlated with the last one, even if very faintly. Still, intuitively, there should exist a pulse separation threshold after which these correlations become so small as to be essentially negligible, rendering them inconsequential from a security standpoint. Building on this insight, we introduce a general formalism designed to extend existing security proofs to the practically relevant scenario in which pulse correlations have an unbounded length. This approach significantly enhances the applicability of these proofs and the robustness of QKD's implementation security.

quant-ph↗

Finite-key security analysis of differential-phase-shift quantum key distribution

Differential-phase-shift (DPS) quantum key distribution (QKD) is one of the major QKD protocols that can be implemented with a simple setup using a laser source and a passive detection unit. Recently, an information-theoretic security proof of this protocol has been established in [npj Quant. Inf. 5, 87 (2019)] assuming the infinitely large number of emitted pulses. To implement the DPS protocol in a real-life world, it is indispensable to analyze the security with the finite number of emitted pulses. The extension of the security proof to the finite-size regime requires the accommodation of the statistical fluctuations to determine the amount of privacy amplification. In doing so, Azuma's inequality is often employed, but unfortunately we show that in the case of the DPS protocol, this results in a substantially low key rate. This low key rate is due to a loose estimation of the sum of probabilities regarding three-photon emission whose probability of occurrence is very small. The main contribution of our work is to show that this obstacle can be overcome by exploiting the recently found novel concentration inequality, Kato's inequality. As a result, the key rate of the DPS protocol is drastically improved. For instance, assuming typical experimental parameters, a 3 Mbit secret key can be generated over 77 km for 8.3 hours, which shows the feasibility of DPS QKD under a realistic setup.

quant-ph↗

Quantum key distribution with correlated sources

In theory, quantum key distribution (QKD) offers information-theoretic security. In practice, however, it does not due to the discrepancies between the assumptions used in the security proofs and the behaviour of the real apparatuses. Recent years have witnessed a tremendous effort to fill the gap, but the treatment of correlations among pulses has remained a major elusive problem. Here, we close this gap by introducing a simple yet general method to prove the security of QKD with arbitrarily long-range pulse correlations. Our method is compatible with those security proofs that accommodate all the other typical device imperfections, thus paving the way towards achieving implementation security in QKD with arbitrary flawed devices. Moreover, we introduce a new framework for security proofs, which we call the reference technique. This framework includes existing security proofs as special cases and it can be widely applied to a number of QKD protocols.

quant-ph↗

Quantum key distribution with any two independent and identically distributed states

To prove the security of quantum key distribution (QKD) protocols, several assumptions have to be imposed on users' devices. From an experimental point of view, it is preferable that such theoretical requirements are feasible and the number of them is small. In this paper, we provide a security proof of a QKD protocol where the usage of any light source is allowed as long as it emits two independent and identically distributed (i.i.d.) states. Our QKD protocol is composed of two parts: the first part is characterization of the photon-number statistics of the emitted signals up to three-photons based on the method [Opt. Exp. 27, 5297 (2019)], followed by running our differential-phase-shift (DPS) protocol [npj Quantum Inf. 5, 87 (2019)]. It is remarkable that as long as the light source emits two i.i.d. states, even if we have no prior knowledge of the light source, we can securely employ it in the QKD protocol. As this result substantially simplifies the requirements on light sources, it constitutes a significant contribution on realizing truly secure quantum communication.

quant-ph↗

Security of round-robin differential-phase-shift quantum key distribution protocol with correlated light sources

Among various quantum key distribution (QKD) protocols, the round-robin differential-phase-shift (RRDPS) protocol has a unique feature that its security is guaranteed without monitoring any statistics. Moreover, this protocol has a remarkable property of being robust against source imperfections assuming that the emitted pulses are independent. Unfortunately, some experiments confirmed the violation of the independence due to pulse correlations, and therefore the lack of a security proof without taking into account this effect is an obstacle for the security. In this paper, we prove that the RRDPS protocol is secure against any source imperfections by establishing a proof with the pulse correlations. Our proof is simple in the sense that we make only three experimentally simple assumptions for the source. Our numerical simulation based on the proof shows that the long-range pulse correlation does not cause a significant impact on the key rate, which reveals another striking feature of the RRDPS protocol. Our security proof is thus effective and applicable to wide range of practical sources and paves the way to realize truly secure QKD in high-speed systems.

quant-ph↗

Characterisation of state-preparation uncertainty in quantum key distribution

To achieve secure quantum key distribution, all imperfections in the source unit must be incorporated in a security proof and measured in the lab. Here we perform a proof-of-principle demonstration of the experimental techniques for characterising the source phase and intensity fluctuation in commercial quantum key distribution systems. When we apply the measured phase fluctuation intervals to the security proof that takes into account fluctuations in the state preparation, it predicts a key distribution distance of over 100 km of fiber. The measured intensity fluctuation intervals are however so large that the proof predicts zero key, indicating a source improvement may be needed. Our characterisation methods pave the way for a future certification standard.

quant-ph↗

Modified BB84 quantum key distribution protocol robust to source imperfections

The Bennett-Brassard 1984 (BB84) protocol is the most widely implemented quantum key distribution (QKD) scheme. However, despite enormous theoretical and experimental efforts in the past decades, the security of this protocol with imperfect sources has not yet been rigorously established. In this work, we address this shortcoming and prove the security of the BB84 protocol in the presence of multiple source imperfections, including state preparation flaws and side channels, such as Trojan-horse attacks, mode dependencies and classical correlations between the emitted pulses. To do so, we consider a modified BB84 protocol that exploits the basis mismatched events, which are often discarded in standard security analyses of this scheme; and employ the reference technique, a powerful mathematical tool to accommodate source imperfections in the security analysis of QKD. Moreover, we compare the achievable secret-key rate of the modified BB84 protocol with that of the three-state loss-tolerant protocol, and show that the addition of a fourth state, while redundant in ideal conditions, significantly improves the estimation of the leaked information in the presence of source imperfections, resulting in a better performance. This work demonstrates the relevance of the BB84 protocol in guaranteeing implementation security, taking us a step further towards closing the existing gap between theory and practice of QKD.

quant-ph↗

Computational self-testing for entangled magic states

In the seminal paper [Metger and Vidick, Quantum '21], they proposed a computational self-testing protocol for Bell states in a single quantum device. Their protocol relies on the fact that the target states are stabilizer states, and hence it is highly non-trivial to reveal whether the other class of quantum states, non-stabilizer states, can be self-tested within their framework. Among non-stabilizer states, magic states are indispensable resources for universal quantum computation. In this letter, we show that a magic state for the CCZ gate can be self-tested while that for the T gate cannot. Our result is applicable to a proof of quantumness, where we can classically verify whether a quantum device generates a quantum state having non-zero magic.

quant-ph↗