- Photonics Research
- Vol. 11, Issue 11, 1861 (2023)
Abstract
1. INTRODUCTION
Quantum key distribution (QKD), one of the most active areas in quantum information [1], allows remote legitimate parties to share encryption keys in the quantum secure network [2]. QKD is designed based on the laws of quantum mechanics and thus offers prestigious security against quantum code breaking. In contrast to the discrete-variable (DV) QKD with dedicated single-photon detectors [3], the continuous-variable (CV) QKD relies on optical coherent detection to gain information encoded in the electromagnetic field quadratures of coherent states [4]. In other words, single-photon detection can be replaced by more conventional detection methods. Hence, CVQKD demonstrates better compatibility with commercially available telecom components and provides higher key distribution rates in metropolitan areas, which is well suited for large-scale, cost-effective deployment. Its security has been thoroughly studied with consideration of realistic devices [5]. Emerging protocols, such as discrete modulation CVQKD with quadrature phase shift keying [6], keep pushing the CVQKD frontier toward high tolerance to excess noise and long transmission distance. The prominent and well-studied protocol of CVQKD is undoubtedly the GG02 [7], which utilizes Gaussian-modulated coherent states as quantum objects to deliver the raw key. With quantum channel transmission and shot noise-limited coherent detection of the coherent states, the secure key can be subsequently extracted via a series of postprocessing procedures.
The GG02 protocol possesses the most developed security proofs, which have established information-theoretic security against collective attacks [8] and coherent attacks [9]. Like the other types of CV protocols, the amount of the distillable secure information depends on the difference between the two legal parties’ (Alice and Bob) mutual information and the eavesdropper’s (Eve) potential information about Bob (assuming reverse reconciliation). The mutual information of Alice and Bob is usually upper-bounded by the channel capacity of the Shannon limit in the homodyne or heterodyne detection schemes; whereas Eve’s potential information is related to the type of eavesdropping attacks and system architecture, including the detection mode, the reconciliation direction, and the finite block sizes [1]. Here, we consider the asymptotic secure key rate (SKR) with reverse reconciliation in the case of collective attacks, namely,
Developing novel CVQKD systems mainly focuses on alternative state preparation and measurement schemes. For example, the subcarrier wave (SCW) CVQKD using a modulated multimode state is proposed in Refs. [12,13]. The quantum state is prepared by modulating the monochromatic light via an electro-optic phase modulator to produce weak sidebands without suppressing the central carrier. The carrier wave acts as the local oscillator (LO) at the receiver side for coherent detection of the sidebands [14]. This scheme provides an alternative GG02 implementation with an LO transmitting through a quantum channel, thus still suffering from LO intensity bottleneck and LO-signal cross talk. Also, the sharp spectral filtering needed to separate the LO at the receiver end may pose a technical challenge. Another implementation uses a carrier-suppressed sideband signal modulation and a discrete frequency component as the pilot tone for synchronizing a local LO [15]. The subcarrier-modulated signal can be downconverted to an intermediate frequency (IF) stage by heterodyne detection with one balanced photodetector (BPD) and be recovered through subsequent signal processing in the digital domain.
Sign up for Photonics Research TOC. Get the latest issue of Photonics Research delivered right to you!Sign up now
This paper proposes a multimode implementation of GG02 CVQKD utilizing the digital phase-conjugated subcarrier (PCS) modulation and phase-sensitive heterodyne detection. The proposed scheme is experimentally demonstrated using only one quadrature for signal modulation and detection. We show that the phase-sensitive detection of PCS exhibits a higher information capacity than ordinary GG02 prepare-and-measure schemes at the cost of lower spectral efficiency. We develop the theoretical information capacity of the proposed scheme and experimentally achieve a higher SKR than the conventional GG02. The PCS uses the same phase-conjugated first-order subcarriers as the SCW scheme [12,13]. However, the PCS ensures maximum modulation efficiency with complete carrier suppression. At the same time, a weak reference signal transmits on an orthogonal polarization for LO regeneration based on optical injection locking (OIL) [16]. Despite the implementation differences between the two schemes, the security analysis developed for SCW also applies to PCS, because they both use symmetric modes carrying the same information without interaction and thus act as two separate GG02 channels. The complete experimental demonstration and detailed information capacity analysis performed in this paper have not been seen in previous studies. Moreover, the phase-sensitive multimode preparation and measurement developed in this work are expected to find applications in scientific areas such as phase-sensitive amplification [17] and phase-sensitive quantum storage [18]. The PCS can also be employed as a multiplexing technique for the multichannel CVQKD system [19,20].
2. OPERATION PRINCIPLE
A semi-classic approach is sufficient to describe the operation principle of PCS and compare it to other schemes. Consider a narrowband, linearly polarized optical signal with randomly distributed complex field amplitude . Like the GG02, we consider the distribution of to be zero-mean Gaussian. The variance, , has the interpretation of the mean photon number of the signal, and it is also called the modulation variance, denoted by . Propagation through a standard additive white Gaussian noise (AWGN) channel is modeled by the transformation , where the transmittance specifies the change of the optical signal power, and is a complex-valued zero-mean Gaussian random variable that characterizes the excess noise. The mean photon numbers of both the received signal, denoted as , and the excess noise, , are the same for all schemes discussed below. We also consider the detectors to have ideal quantum efficiencies and operate at the shot noise-limited level. We define the shot noise unit () as a zero-mean complex-valued noise with variance corresponding to the vacuum state. Hence, the received signal has a total variance of .
Consider first the scheme where both quadrature components of the optical signal are carrying information and measured simultaneously (denoted as 2Q2D). The so-called “no-switching” protocol is one example [21]. Denote the complex amplitude of the received signal by , and the mean photon number of each quadrature is thus . As illustrated in Fig. 1(a), using a phase-diversity homodyne receiver with a 3-dB coupler, half of the input power is directed to each of the two homodyne detectors for quadrature measurement. Therefore, the mean photon number of one signal quadrature is . For the same reason, the mean photon number of one noise quadrature is , where the 1/4 denotes one quadrature of vacuum noise. Thus, we can express the signal-to-noise ratio (SNR) of the 2Q2D scheme as
Figure 1.Optical spectra of different detection schemes with quadrature components representation. (a) Two-quadrature encoding with phase-diversity homodyne detection (2Q2D); (b) two-quadrature encoding with LO phase switching (2Q1D), showing a
In contrast, the CVQKD protocol that uses two quadratures to carry information but measures only one quadrature at a time by randomly switching the LO phase between 0 and is illustrated in Fig. 1(b) (denoted as 2Q1D). With the absence of the input 3 dB loss, the mean photon number of the selected signal quadrature is thus , and the noise quadrature is . The SNR of 2Q1D is
Moreover, the unidimensional protocol [22] uses only one quadrature at both the transmitter and the receiver (denoted as 1Q1D), shown as Fig. 1(c). Since all information is encoded in one quadrature, we assign the mean photon number of the received signal as , where is real-valued. The excess noise is, however, still complex. Hence, the SNR of the 1Q1D scenario is
In contrast to the schemes discussed above, the subcarrier CVQKD schemes exhibit intermediate frequencies, , in the coherently detected signals. They can be implemented via subcarrier modulation at the transmitter and/or heterodyne detection at the receiver with one balanced photodetector. The quantum theory of optical heterodyne detection relies on image band vacuum mode [23–25]. Denote the center frequency of the signal band as . The LO will be outside the signal band and has the frequency . The scheme is identified as sub-2Q2D and is illustrated in Fig. 1(d). The signal that is optically downconverted to the IF preserves all information of both quadratures and can be recovered via subsequent electrical processing. During the optical downconversion, the signal is superimposed with the image band at , which doubles the shot noise power. The mean photon number in each quadrature of signal and excess noise detected by the free-running LO will be and , respectively. The SNR of sub-2Q2D turns out to be the same as the 2Q2D,
A traditional heterodyne detector is a phase-insensitive device that suffers a 3 dB noise penalty caused by the extra quantum noise in the image sideband vacuum mode, which contributes nothing to the signal. However, suppose the image sideband vacuum mode is also excited to a coherent state at the same level as the signal mode, but with a conjugated phase. In that case, the 3 dB noise penalty can be eliminated [26,27]. This, however, requires phase-sensitive detection, where the phase of LO should be locked to the combined signal . As shown in Fig. 1(e), two phase-conjugated signal bands are modulated at the subcarrier frequency . After the phase-sensitive detection, the mean photon number of signal and noise will be and , respectively. The twofold increase in and relative to the ordinary sub-2Q2D is due to the coherent signal and image band superposition. The SNR of the PCS scheme is therefore
The classical information capacity (Shannon capacity) of an analog communication channel with power constraint is expressed as , where or 2 corresponds to using one or two quadratures for information extraction. The expressions of Shannon capacity of the CVQKD schemes discussed above are summarized in Table 1. The Holevo bound for the AWGN channel is also listed [28] with the entropy function, AWGN Channel Capacities of Various CVQKD Schemes and the Holevo BoundCVQKD Scheme AWGN Channel Capacity 1Q1D (sub-)2Q2D 2Q1D PCS Holevo
The channel capacities as functions of the received signal photon number are plotted in Fig. 2 for the loss-only case, i.e., . The PCS scheme with phase-sensitive detection offers the highest capacity that is closest to the Holevo bound for all , at the cost of using twice the usable bandwidth. It is easy to verify that increasing the number of modes, i.e., using more pairs of phase-conjugates subcarriers, each carrying the same information, does not further increase the capacity.
Figure 2.Loss-only (
3. SECURITY ANALYSIS
Note that comprehensive unconditional security proof of the PCS scheme requires dedicated efforts and is outside the scope of this paper. We thus follow the previous study [13] to acknowledge that the state prepared by PCS is the modulator-generated multimode state written as the tensor product over the two symmetric modes around the carrier frequency without mode intersections. Namely, Alice prepares and sends
Using the same procedure of GG02, Bob estimates the Holevo information based on calculating symplectic eigenvalues of Eve’s covariance matrices [29],
We distinguish two scenarios where in one case, Bob makes a crude assumption that Eve cannot perform the perfect phase-sensitive detection without the seed light (PCS with loose assumption). Hence, the values and are used for Holevo information calculation. Without this assumption, those values are and . The secure key rate simulation results are shown in Fig. 3 with transmittance , , , and perfect detectors. The PCS scheme achieves a slightly higher key rate than the standard 2Q2D implementation of GG02. The improvement is more significant if we apply the loose assumption.
Figure 3.Simulated secure key rate of the PCS scheme, with and without the loose assumption, and other typical GG02 schemes as functions of received signal photon numbers (
A potential way to enhance the PCS scheme and eliminate the loose assumption is to prepare and transmit two pairs of phase-conjugated subcarriers on the primary carrier’s two quadratures with independent data encoded. Bob decides randomly to measure one of the data with phase-sensitive detection. This will require an additional sifting stage in the key distillation process and increase implementation complexity, but it will further reduce the eavesdropper’s information, while leaving unchanged.
4. EXPERIMENTAL IMPLEMENTATION
We generate the phase-conjugated signal bands with subcarrier modulation by the arbitrary waveform generator (AWG) to implement the PCS quantum state encoding. The resulting signal in the equivalent baseband form is expressed as
Figure 4.Experimental setups. (a) Block diagram of the CVQKD system with phase-conjugated subcarrier modulation and the phase-sensitive heterodyne detector; (b) OIL setup with an electrical phase-locked loop (PLL). AM, amplitude modulator; BPF, bandpass filter; BS, beam splitter; EDFA, erbium-doped fiber amplifier; LNA, low-noise amplifier; LPF, lowpass filter; PD, photodetector; PBC, polarization beam combiner; PBS, polarization beam splitter; PC, polarization controller; PID, proportional-integral-differential; PZFS, piezoelectric fiber stretcher.
The phase-sensitive heterodyne detection is implemented at Bob’s site with the help of the close phase relation between the quantum-signal polarization and carrier-wave polarization in polarization multiplexing transmission. The output of the fiber link is demultiplexed by a polarization beam splitter (PBS) placed after a polarization controller (PC) that is used to maximize the power of the carrier-wave polarization. The OIL module takes the isolated carrier wave as the seed light to regenerate an LO with 2.7 dBm optical power. The detailed setup of the OIL module with an electrical phase-locked loop (PLL) is shown in Fig. 4(b), the operating principle of which is described in Ref. [16]. After polarization demultiplexing, the quantum signal is mixed with the LO via a 50/50 coupler before being received by a commercially available BPD. The adopted BPD is engineered particularly to separate the lower frequency components (DC-400 kHz) with a monitor port. The reference signal at 125 kHz is detected from the monitor port, which is connected to a high-speed servo controller consisting of a lock-in amplifier and a PID controller. The servo controller drives the piezoelectric fiber stretchers (PZFSs) placed on the LO path for compensating the slow phase changing between the signal path and the LO path. The PLL is designed to lock the amplitude of the reference signal to the minimum point so that the quantum signal retains the maximum because of the orthogonal relation. Note that the reference signal can be combined with PCS modulation using only one MZM to simplify the setup, provided the PLL can be modified to lock the maximum instead. Afterward, the phase-sensitive detected signal output from the BPD is digitized by a 10-bit digital storage oscilloscope (DSO, Keysight DSOS404A) with a sampling rate of 1 GS/s, followed by the offline DSP to prepare the data for raw key rate calculation. The DSP consists of downconverting the quantum signal to the baseband, matched filtering, phase correction, and downsampling. An electrical connection between the AWG and the DSO is used for clock synchronization to avoid additional penalties from the otherwise required digital clock recovery algorithm.
To experimentally evaluate the information capacity of the proposed PCS scheme, a series of received signals with different numbers of received photons are collected by setting different modulation variance by the power stabilizer at the transmitter. With the equivalence between the 2Q2D and the sub-2Q2D, we compare the proposed PCS scheme against the sub-2Q2D, which is relatively easy to implement in our current setup. The mutual information is calculated from the correlation coefficient between the received signals and the original transmitted signal, cf. Eq. (11). We calculate based on SNR defined by correlation coefficient instead of the pessimistic estimate method in typical postprocessing to determine the number of the received signal photons and excess noise photons. The received SNR can be written as
By calculating the SNR with correlation coefficient and calibrating the SNU and the detector’s electric noise, we can determine the photons number of the received signal and excess noise through Eqs. (14) and (15). Considering a realistic detector with electric noise and limited quantum efficiency, the information capacity formula should be modified to
Figure 5.(a) Experimental results of AWGN capacity of the proposed scheme and the sub-2Q2D scheme, and the theoretical curve plotted with zero excess noise; (b) the corresponding excess noise photons of the experimental points.
Within the framework of the GG02 protocol and the security proof against collective attacks, we evaluate the achievable raw key rate in the asymptotic regime based on Eq. (1). In the calculation of each part of the formula, is obtained from the estimated correlation coefficient of received signals, and is calculated as a function of the excess noise and the other calibrated system parameters. The secure key rate of the proposed phase-sensitive scheme and the single sideband heterodyne scheme are shown in Fig. 6(a). The corresponding estimated values of excess noise are shown in Fig. 6(b). By comparison, the proposed phase-sensitive scheme (with the loose assumption) provides a higher secure key rate than the single sideband heterodyne scheme with higher tolerance to excess noise observed in our experiments. However, the PCS performs more like GG02 when applying more strict assumptions. As mentioned above, this calls for solutions such as the dual quadrature PCS with phase-switched measurement to enhance the current scheme.
Figure 6.(a) Experimental results of secure key rate of the proposed scheme and the sub-2Q2D scheme; (b) corresponding excess noise of photons of the experimental points.
To evaluate the system’s long-term performance, we collected 120 sets of signal samples from the stably operating system in 2 h to evaluate the excess noise and the raw key rate in the asymptotic regime. In the calibration stage, the detector electrical noise and the SNU are calibrated based on symbols each time the parameters are estimated. Bob’s detector, which is assumed to be inaccessible to Eve, is characterized by an electric noise of 0.1473 SNU referring to the channel input and a detection efficiency of 0.6. The excess noise and achievable key rate are estimated per symbols. The results obtained from each set of signal samples are shown in Fig. 7(a). The estimated excess noise is 0.19 SNU on average. The obtained parameters are compatible with a raw key rate in the asymptotic regime between 7.2 and 7.7 Mbit/s with , an averaged value of 7.4 Mbit/s over a 20-km fiber transmission. The variation of raw key rate is attributed to factors such as the modulator bias drift and the polarization-dependent loss at the receiver. To compare the signal phase fluctuation in the phase-sensitive and phase-insensitive schemes, we calculate the phase standard deviation of the pilot-tone frequency downconverted to the baseband followed by narrow lowpass filtering (a 1-MHz rectangular filter). The results are shown in Fig. 7(b). The standard deviation of the pilot phase keeps around the value of 1.9° with a small range of 1.85°–1.95° in the phase-sensitive scheme. In comparison, the phase-insensitive scheme exhibits a more significant fluctuation of the pilot phase without the phase locking.
Figure 7.(a) Estimated excess noise; (b) SKR in the asymptotic regime. The standard deviation of the pilot phase is compared for (c) the sub-2Q2D and (d) the PCS scheme with phase-sensitive detection.
To further verify the LO phase is locked to the state that ensures the maximum amplitude of quantum signal (i.e., the maximum SNR), the power of pilot-tone at 100 MHz is measured with an electronic spectrum analyzer (ESA) in zero-span mode when the LO phase is either locking or scanning. The resolution bandwidth and video bandwidth of the ESA are both 1.8 MHz. The results are shown in Fig. 8. The magnitude at the frequency of pilot-tone fluctuates regularly when the LO phase is scanned with PZFS driven by a ramp voltage, whereas in the phase-locked case, the magnitude of pilot tone remains steady at the maximum level in the phase-scanning case.
Figure 8.Normalized power at the pilot frequency in the LO phase-scanned and phase-locked cases.
The improvement of classical information capacity in the proposed scheme is at the cost of spectral efficiency, which is at most half of the single-sideband modulation. From a telecommunication point of view, the proposed scheme possesses several additional advantages. First of all, the use of one balanced detector and possibly one MZM simplifies the system implementation. Second, the detected signal is at an intermediate frequency and hence is free from the noise of the detector and the laser dithering signal at lower frequencies. The PCS scheme can be easily multiplexed with many subcarriers and combined with the wavelength division multiplexing (WDM) technique to construct a CVQKD network. It is also important to note that the PCS-modulated multimode signal can replace the optical copier for the idler component generation in phase-sensitive amplification (PSA) [30]. Therefore, the proposed scheme is fully compatible with the PSA application, which is a project we are currently working on.
5. CONCLUSION
We develop a phase-sensitive multimode CVQKD scheme exploiting phase-conjugated subcarrier modulation and phase-sensitive homodyne detection. The proposed scheme transmits two phase-conjugated subbands carrying a Gaussian-modulated signal. It is advantageous among the conventional CVQKD schemes, with continuous modulation in the classical information capacity when phase-sensitive detection is applied at the receiver. The experimental implementation of the novel scheme is performed with a simple transmitter. The phase-sensitive detection is realized via OIL and active feedback control. The experimental results confirm the information capacity improvement. Within the GG02 security analysis framework, the proposed scheme offers a higher secure key rate and better excess noise tolerance with a loose assumption. The developed scheme also has great potential for a phase-sensitive optical amplification enhanced CVQKD.
References
[15] H. H. Brunner, L. C. Comandar, F. Karinou, S. Bettelli, D. Hillerkuss, F. Fung, D. Wang, S. Mikroulis, Q. Yi, M. Kuschnerov, A. Poppe, C. Xie, M. Peev. A low-complexity heterodyne CV-QKD architecture. 19th International Conference on Transparent Optical Networks (ICTON), 1-4(2017).
[27] C. M. Caves. Quantum limits on noise in linear amplifiers. Phys. Rev. D, 26, 1817-1839(1982).
Set citation alerts for the article
Please enter your email address