A long-awaited security proof

This is a Perspective on "Security of differential phase shift QKD from relativistic principles" by Martin Sandfuchs, Marcus Haberland, V. Vilasini, and Ramona Wolf, published in Quantum 9, 1611 (2025).

By Stefan Bäuml (ICFO-Institut de Ciencies Fotoniques, The Barcelona Institute of Science and Technology, Av. Carl Friedrich Gauss 3, 08860 Castelldefels (Barcelona), Spain).

The history of quantum key distribution (QKD) began in 1984 with a beautifully simple proof-of-concept result [1], where a sender, commonly called Alice, randomly prepares one of four single-qubit states from two complementary bases which she sends to a receiver, commonly known as Bob, via an insecure quantum channel. Bob then measures in one of the two bases, randomly chosen, which is followed by a number of classical post-processing steps including sifting, parameter estimation, error correction and privacy amplification. If all those steps succeed, Alice and Bob obtain a common key they can use to encrypt their communication using the one-time pad protocol, the security of which has been proven mathematically [2] and does not rely on any computational assumptions on an eavesdropper, commonly named Eve.

The reason that today, 40 years later, QKD is still an active field of basic research rather than a standard tool in communication, is that effectively implementing a QKD protocol in practice, without violating any of the assumptions made when proving its security, is a highly non-trivial task, both for the experimentalists reducing imperfections in their apparatuses that might be exploited by Eve, and for the theorists that include such imperfections into their security proofs. While a lot of progress has been made in recent decades, see [3,4] for recent reviews, I do not believe those two sides have completely converged yet.

A major challenge for implementing protocols such as BB84 in its original and very simple form is the need for single-photon states. Since exact single-photon sources are difficult to implement, one typically uses weak laser pulses described by coherent states with low average photon number [5]. Such pulses, however, can contain additional photons with small probability. Eve can make use of such pulses to obtain information, while remaining undetected, e.g., by an attack known as photon-number splitting (PNS). To counteract such a security loophole, techniques such as decoy states have been developed [6], however at the cost of complicating the protocol and its security proof.

An alternative way to overcome such PNS attacks has been introduced by [7] in 2002. Unlike most QKD protocols the so-called differential-phase-shift (DPS) protocol involves Bob measuring the relative phase between two pulses, which counteracts attacks on individual pulses, including the PNS attack. In the DPS protocol, raw key bits are obtained from the relative phase between two coherent states, rather than from a single coherent state. In an implementation Alice uses a source of weak coherent pulses and a phase modulator to encode random phases, whereupon Bob uses a Mach-Zehnder interferometer to measure the phase between subsequent pulses. Assuming Eve performs a PNS attack, this would require a photon-number measurement, which can be detected in such a setup.

Of course, security against a particular kind of attack is by far not sufficient for a protocol to be deemed secure against a general quantum adversary. Given the huge range of possible attacks, one typically considers the following three classes of attacks: Assuming a prepare-and-measure QKD protocol, in an individual attack, Eve can control the Stinespring isometry of the channel between Alice and Bob in every round, but is assumed not to possess a quantum memory, and hence has to measure her quantum output after each round individually. A generalisation is a collective attack, where Eve controls the individual Stinespring isometries of each round, but can store her quantum outputs until the end of the protocol and measure them collectively then.

A further generalisation is a coherent, also called general, attack, where Eve is not restricted to controlling the Stinespring isometries in each round individually, but is allowed to control the entire transmission part of the protocol in a coherent way. Whereas proving security against individual and collective attacks is often straightforward, the possibility of coherent attacks typically poses significant challenges. Tools for security proofs against coherent attacks include de Finetti theorems [8], post-selection techniques [9] and entropy-accumulation theorems (EATs) [10,11,12]. Using such techniques it is often possible to reduce coherent-state security to collective-attack security.

The non-standard structure of the DPS protocol, which even without attack involves operations performed jointly on subsequent rounds, has for a long time hindered its security analysis including coherent attacks. In particular the fact that there is no permutation symmetry between rounds has prevented a treatment using de Finetti. Intuitively one would also expect that collective attacks are not the best choice for Eve. More than 20 years after the initial proposal of the DPS protocol, Sandfuchs et al. [13] have now proven security against coherent attacks using the generalised entropy-accumulation theorem (GEAT) [11], which is a major achievement. In addition, Sandfuchs et al. have shown that coherent attacks of the DPS protocol can indeed be stronger than collective ones, confirming the intuition.

The EAT, and its generalisation the GEAT, are powerful tools that have previously been used to prove coherent security of device-indecent QKD [14], conference key agreement [15], and discrete-modulated continuous-variable QKD [16]. However they are far from being easily applicable plug-and-play results. For one, it is necessary to formulate the protocol as a sequence of channels that fulfil certain conditions. In the original EAT, a Markov condition has to be fulfilled ensuring that side-information produced in a certain round has to be taken into account in that round rather than passed along to future rounds and adding to their side information. In the GEAT this condition is relaxed to a condition of no-signalling. Such conditions typically require the invention of a virtual or hypothetical protocol to which the EAT is applied, but which is different from the actual protocol performed by Alice and Bob. It then has to be shown that security of the virtual protocol also implies security of the actual protocol.

In their security proof of the DPS, Sandfuchs et al. use a so-called relativistic protocol as virtual protocol to which they apply the GEAT, and then show that security of the relativistic protocol also implies security against coherent attacks for the DPS protocol. In the relativistic protocol, the Mach-Zehnder interferometer is distributed between the labs of Alice and Bob. Namely, Alice sends a coherent state onto a beam splitter, resulting in a reference and signal system. The reference system is sent to Bob immediately, whereas the signal system gets modulated and delayed in Alice’s lab before being sent to Bob. Meanwhile, Bob delays the reference system in his lab until the signal systems arrives, recombines the two on the beam splitter, measuring the relative phase between the two. Combined with exact time-keeping, such a setup allows Alice and Bob to enforce the necessary non-signalling and sequentiality conditions from relativistic principles.

While the security proof presented by Sandfuchs et al. works against coherent attacks, it still relies on a non-signalling assumption. Since Alice and Bob can enforce such an assumption, i.e., they can check wether the assumption was fulfilled in an experiment and otherwise abort, this is not a limitation of security. The importance of enforcing the assumption becomes obvious when considering a known upper bound on the key rate given by [17], which does not satisfy the non-signalling condition, and which is violated by Sandfuchs et al. Since all collective attacks fulfil the non-signalling assumption, the attack corresponding to [17] shows that techniques such as entropy accumulation, which reduce coherent-attack security to collective attack cannot be applied with additional assumptions, such as non-signalling, showing the limitations of such techniques. So, while there is still work to be done in the future, the present security proof represents a large step forward and seems to be as general as possible given the current state of the art.

► BibTeX data

► References

[1] Charles H. Bennett and Gilles Brassard, Quantum Cryptography: Public Key Distribution and Coin Tossing, in Proceedings of the IEEE International Conference on Computers, Systems and Signal Processing (IEEE Computer Society Press, New York, Bangalore, India, 1984).
https:/​/​doi.org/​10.1016/​j.tcs.2014.05.025

[2] Shannon, Communication theory of secrecy systems, Bell System Technical Journal 28, 656–715 (1949).
https:/​/​doi.org/​10.1002/​j.1538-7305.1949.tb00928.x

[3] Stefano Pirandola, Ulrik L Andersen, Leonardo Banchi, Mario Berta, Darius Bunandar, Roger Colbeck, Dirk Englund, Tobias Gehring, Cosmo Lupo, Carlo Ottaviani, et al., Advances in quantum cryptography, Advances in Optics and Photonics 12, 1012–1236 (2020).
https:/​/​doi.org/​10.1364/​AOP.361502

[4] Christopher Portmann and Renato Renner, Security in quantum cryptography, Reviews of Modern Physics 94, 025008 (2022).
https:/​/​doi.org/​10.1103/​RevModPhys.94.025008

[5] Hoi-Kwong Lo and John Preskill, Security of quantum key distribution using weak coherent states with nonrandom phases, Quantum Information & Computation 7, 431–458 (2007).
https:/​/​doi.org/​10.26421/​QIC7.5-6-2

[6] Won-Young Hwang, Quantum Key Distribution with High Loss: Toward Global Secure Communication, Physical Review Letters 91, 057901 (2003).
https:/​/​doi.org/​10.1103/​PhysRevLett.91.057901

[7] Kyo Inoue, Edo Waks, and Yoshihisa Yamamoto, Differential Phase Shift Quantum Key Distribution, Physical Review Letters 89, 037902 (2002).
https:/​/​doi.org/​10.1103/​PhysRevLett.89.037902

[8] Renato Renner, Symmetry of large physical systems implies independence of subsystems, Nature Physics 3, 645–649 (2007).
https:/​/​doi.org/​10.1038/​nphys684

[9] Matthias Christandl, Robert König, and Renato Renner, Postselection Technique for Quantum Channels with Applications to Quantum Cryptography, Physical Review Letters 102, 020504 (2009).
https:/​/​doi.org/​10.1103/​PhysRevLett.102.020504

[10] Frédéric Dupuis, Omar Fawzi, and Renato Renner, Entropy Accumulation, Communications in Mathematical Physics 379, 867–913 (2020).
https:/​/​doi.org/​10.1007/​s00220-020-03839-5

[11] Tony Metger, Omar Fawzi, David Sutter, and Renato Renner, Generalised entropy accumulation, in 2022 IEEE 63rd Annual Symposium on Foundations of Computer Science (FOCS) (IEEE, 2022) pp. 844–850.
https:/​/​doi.org/​10.1109/​FOCS54457.2022.00085

[12] Amir Arqand, Thomas A Hahn, and Ernest Y-Z Tan, Generalized Rényi entropy accumulation theorem and generalized quantum probability estimation, arXiv preprint arXiv:2405.05912 (2024).
https:/​/​doi.org/​10.48550/​arXiv.2405.05912
arXiv:2405.05912

[13] Martin Sandfuchs, Marcus Haberland, Venkatesh Vilasini, and Ramona Wolf, Security of differential phase shift QKD from relativistic principles, Quantum 9, 1611 (2025). 2023).
https:/​/​doi.org/​10.22331/​q-2025-01-27-1611

[14] Rotem Arnon-Friedman, Frédéric Dupuis, Omar Fawzi, Renato Renner, and Thomas Vidick, Practical device-independent quantum cryptography via entropy accumulation, Nature Communications 9, 459 (2018).
https:/​/​doi.org/​10.1038/​s41467-017-02307-4

[15] Jérémy Ribeiro, Gláucia Murta, and Stephanie Wehner, Fully device-independent conference key agreement, Physical Review A 97, 022307 (2018).
https:/​/​doi.org/​10.1103/​PhysRevA.97.022307

[16] Stefan Bäuml, Carlos Pascual-García, Victoria Wright, Omar Fawzi, and Antonio Acín, Security of discrete-modulated continuous-variable quantum key distribution, Quantum 8, 1418 (2024).
https:/​/​doi.org/​10.22331/​q-2024-07-18-1418

[17] Marcos Curty, Kiyoshi Tamaki, and Tobias Moroder, Effect of detector dead times on the security evaluation of differential-phase-shift quantum key distribution against sequential attacks, Physical Review A 77, 052321 (2008).
https:/​/​doi.org/​10.1103/​PhysRevA.77.052321

Cited by

On Crossref's cited-by service no data on citing works was found (last attempt 2026-08-12 04:48:30). On SAO/NASA ADS no data on citing works was found (last attempt 2026-08-12 04:48:30).