scieee AI-readable full text Open interactive document viewer

Continuous-Variable Quantum Key Distribution

Ben Saoud Benjerri, Walid

Abstract

Continuous-Variable Quantum Key Distribution is an alternative to the usual discrete variable quantum key distribution schemes, such as BB84, based on quantum states of light. Optical quantum states are defined in an infinite dimensional Hilbert space hence the "continuous" prefix. Compared to DV-QKD, CVQKD has several advantages such as being compatible with existing telecommunications equipment as one only needs to modulate coherent states of light and perform homodyne/heterodyne detections, but suffers from a lower range, and security proofs are somewhat harder.

Full text

Continuous-Variable Quantum Key Distribution Master Thesis submitted to the Faculty of the Escola Tècnica d’Enginyeria de Telecomunicació de Barcelona Universitat Politècnica de Catalunya by Walid Ben Saoud Benjerri In partial fulfillment of the requirements for the master in Cybersecurity Advisor: Rodriguez Fonollosa, Javier Barcelona, September 2022 Contents List of Figures 4 1 Introduction 7 1.1 Cryptography VS Physical-Layer Security . . . . . . . . . . . . . . . . . . 7 1.2 Overview of discrete QKD . . . . . . . . . . . . . . . . . . . . . . . . . . . 8 1.3 High level description of CVQKD . . . . . . . . . . . . . . . . . . . . . . . 9 2 Mathematical tools and formalisms 11 2.1 Basics of Information Theory . . . . . . . . . . . . . . . . . . . . . . . . . 11 2.1.1 Information metrics . . . . . . . . . . . . . . . . . . . . . . . . . . 11 2.1.2 Wiretapmodels............................. 13 2.1.3 Key agreement from a source, and sequential key distillation . . . . 13 2.2 Basics of Quantum Mechanics . . . . . . . . . . . . . . . . . . . . . . . . . 15 2.2.1 The four postulates . . . . . . . . . . . . . . . . . . . . . . . . . . . 15 2.2.2 Motivation for the measurement postulate: The Stern-Gerlach experiment................................. 19 2.2.3 QKD as an instance of the secret key agreement from a source model 20 2.2.4 Density matrix : A useful formalism for mixed states . . . . . . . . 20 2.2.5 Partial trace and purification . . . . . . . . . . . . . . . . . . . . . 21 2.2.6 Purification............................... 23 2.3 Quantum Information theory . . . . . . . . . . . . . . . . . . . . . . . . . 23 2.3.1 Encoding classical variables . . . . . . . . . . . . . . . . . . . . . . 23 2.3.2 Quantumchannels ........................... 23 2.3.3 HolevoTheorem ............................ 24 2.4 Quantum optics for CVQKD . . . . . . . . . . . . . . . . . . . . . . . . . . 24 2.4.1 Quantum states of light . . . . . . . . . . . . . . . . . . . . . . . . 24 2.4.2 Physical origin: Quantization of the electromagnetic field . . . . . . 26 2.4.3 Generating coherent states: q/p modulation . . . . . . . . . . . . . 27 2.4.4 Measurement : Homodyne and Heterodyne detection . . . . . . . . 28 2.4.5 Multiplesmodes ............................ 29 3 Protocol with Gaussian modulation using coherent states (GG02) 30 3.1 Prepare and measure scenario . . . . . . . . . . . . . . . . . . . . . . . . . 30 3.2 Entanglement based scenario . . . . . . . . . . . . . . . . . . . . . . . . . 31 3.3 SecurityAnalysis................................ 32 3.3.1 KeyRate ................................ 32 3.3.2 Calculation of the mutual information . . . . . . . . . . . . . . . . 33 3.3.3 Formal proof of equivalence of the PM and EB scenarios . . . . . . 33 3.4 Possibleattacks................................. 35 3.4.1 Classification of attacks . . . . . . . . . . . . . . . . . . . . . . . . 35 3.4.2 Entangling cloner attack . . . . . . . . . . . . . . . . . . . . . . . . 35 3.4.3 Purification............................... 37 3.5 Basic numerical verification . . . . . . . . . . . . . . . . . . . . . . . . . . 37 3.5.1 Variance and Mean in the PM scenario . . . . . . . . . . . . . . . . 38 2 3.5.2 Error on a fixed coherent state . . . . . . . . . . . . . . . . . . . . 38 3.5.3 Variances in the EB scenario . . . . . . . . . . . . . . . . . . . . . 38 4 Conclusions 41 Bibliography 42 3 List of Figures 1 Evolution of information through key distillation steps . . . . . . . . . . . 14 2 Stern-Gerlach apparatus . . . . . . . . . . . . . . . . . . . . . . . . . . . . 19 3 Covariances of the 𝑞quadrature on all 3 modes. . . . . . . . . . . . . . . . 40 4 Covariances of 𝑞1,𝑝2and 𝑞3.......................... 40 4 Revision history and approval record Revision Date Purpose 0 01/06/2022 Document creation 1 01/09/2022 Document revision 2 04/10/2022 Document revision 3 18/10/2022 Document revision 2 22/10/2022 Document revision DOCUMENT DISTRIBUTION LIST Name e-mail [Walid Ben Saoud Benjerri] [email protected] [Javier Rodriguez Fonollosa ] [email protected] [Project Supervisor 2] Written by: Reviewed and approved by: Date 22/10/2022 Date 22/10/2022 Name Walid Ben Saoud Benjerri Name Javier Rodriguez Fonollosa Position Project Author Position Project Supervisor 5 Abstract Continuous-Variable Quantum Key Distribution is an alternative to the usual discrete variable quantum key distribution schemes, such as BB84, based on quantum states of light. Optical quantum states are defined in an infinite dimensional Hilbert space hence the ”continuous” prefix. Compared to DV-QKD, CVQKD has several advantages such as being compatible with existing telecommunications equipment as one only needs to modulate coherent states of light and perform homodyne/heterodyne detections, but suffers from a lower range, and security proofs are somewhat harder. In the first chapter, we briefly remind the reader about the motivations for physical layer security(of which QKD and CVQKD are instances) against cryptography, the dominant approach for network security. Chapter 2 gives the necessary background for this topic, which requires both a mathematically rigorous theory of quantum mechanics in infinite dimensional Hilbert spaces, and a quantitative theory of information to be able to prove the security of protocols and measure the shared information between the legitimate and illegitimate parties. Chapter 3 studies in detail the protocol using coherent states with Gaussian modulation, the most common one. 6 1 Introduction 1.1 Cryptography VS Physical-Layer Security One may legitimately enquire about the purpose of an exotic security scheme such as QKD, whereas cryptography is well-known, understood, and used in an ubiquitous fashion nowadays. For example, almost most Internet-based communications today rely on public and private key (asymmetric) cryptography to achieve both authentication and confidentiality without the need of a confidential or authenticated channel, and without the need of a preshared key (though the other party’s public key has to be authenticated). Symmetric cryptography is also used as part of hybrid schemes once a session key has been agreed upon with these asymmetric protocols. The answer to that question is that despite their ubiquity, public key cryptography protocols are only secure if two assumptions are true : 1. Some mathematical problem is hard (Integer factorization for RSA, discrete logarithm for Diffie-Hellman) 2. The attacker has limited computational power. This is commonly expressed as the attacker running a polynomial-on-𝑛(the key size) computation, therefore unable to solve a hard problem in reasonable time for a large enough value of 𝑛. If any of these two assumptions is false, security is compromised and the protocol is no longer secure. Indeed, there is no known proof of the hardness of the mathematical problems underlying for example RSA or Diffie-Hellman, it is only presumed since efforts to find a polynomial algorithm didn’t succeed. Furthermore, even if these assumptions are true, computational power is ever increasing, which leads to key length being a determinant parameter in the security even against a polynomial adversary, so a key size that is secure today may cease to be in a few years. For example, RSA with a key length of 1024 is no longer considered secure for long-term. Moreover, a mathematical problem that is hard for traditional computers can actually be easy for quantum computers : Shor famously devised an algorithm that can factorize integers in polynomial time, breaking the security of RSA if the attacker has access to a quantum computer with enough qubits. Today this is not possible (or not disclosed), but might be so in a few years, A solution to this last issue however is the design of algorithms based on mathematical problems that are resistants to attacks even by quantum computers. This area of research is called post-quantum cryptography,but this is not the subject of this thesis. The protocols that we are interested in belongs to the wider class of Informationtheoretic security also called Unconditional Security or Physical layer security. These designations are justified as we shall see next. Unlike cryptography, security is guaranteed and proven in a mathematical sense against every possible attacker. 7 Roughly speaking, if 𝑋is the original message, 𝑌is the message as observed by the legitimate recipient and 𝑍is the message as observed by an eavesdropper, we want 𝐻(𝑋|𝑌)to be small (a small conditional entropy means there will be less uncertainty on the message for the legitimate recipient) but 𝐻(𝑋|𝑍)be high (a high entropy of 𝑋conditioned on 𝑍 means he will have a higher uncertainty, for this reason this quantity is also called equivocation). The ideal case would be that 𝐻(𝑋|𝑍)=𝐻(𝑋)so the attacker doesn’t gain supplementary information (measured in bits) than what he had a priori before observing 𝑍. This is called perfect secrecy, but it is impractical to achieve, so IT security focuses instead on the asymptotic analysis. For the simplicity of analysis, we assume the source to encode a message 𝑀into a sequence of symbols 𝑋𝑛. Similarly 𝑌𝑛and 𝑍𝑛are the noisy observations of 𝑋𝑛by the intended recipient and the eavesdropper. Then the goal is to compute the conditional entropy, that is compute 𝐻(𝑀|𝑍𝑛)as a function of 𝑛and study the asymptotic information leakage given by the limit as 𝑛→∞ of 𝐼(𝑀;𝑍𝑛). This limit should be 0which implies that the eavesdropper’s information regarding the message is arbitrary close to zero, so we can chose a high enough value of 𝑛to achieve the desired closeness. It can be shown that the optimal rate of encoding (from the message 𝑀to 𝑋𝑛) is 𝐼(𝑋,𝑌)−𝐼(𝑋,𝑍)which is intuitively true since it can be thought of as the difference of bits shared by Alice and Bob, and bits shared between Alice and Eve. The model we just described is called Wyner’s wiretap channel, since the attacker is able to get a noisy version of the message. Being a passive attacker we call it an eavesdropper. This paradigm received less attention than public key cryptography which was also a revolution in the same decade (1970s), perhaps due to the lack of a concrete channel. Information theoretical security therefore studies fundamental bounds on the possible information an attacker (or legitimate recipient) can get, regardless of the algorithm employed. A key difference however from Public Key cryptography is the need for an authenticated channel, but it can be a public channel. Quantum Key Distribution in its discrete flavour is perhaps the best illustration of this paradigm. 1.2 Overview of discrete QKD Quantum key distribution is a protocol relying on quantum mechanical properties to generate a shared key between two parties, here denoted Alice and Bob, knowledge of which is mathematically proven to be impossible for an outside eavesdropper (in an asymptotic sense that is similar to the previously described Wyner model, which is actually the secret-key agreement from a source model). It is radically different in its principle than well known and used cryptography protocols such as Diffie-Hellman since it doesn’t rely on a hard problem, but instead on the properties of quantum systems. QKD is an instance of the Wyner model, in which the channel is a quantum system, in the discrete case this channel is simply a qubit register. Note that the qubits are generated independently i.e they are not entangled Discrete QKD, here we illustrate the BB84 protocol, is based on the fact that measuring a 8 quantum system will alter its state, but only if the system is not already in an eigenstate of the measurement operator. So even a passive eavesdropper will leave an ”evidence” of the measurement, unless she knows the encoding basis of each qubit. Based on this idea, the protocol is designed so that the possible prepared states are non-orthogonal making impossible for Eve the task of knowing precisely the state prepared by Alice, and there is a positive chance to modify the state when eavesdropping, thus introducing errors in Bob´s statistics. More precisely there are 4 possible states prepared by Alice which are the result of the following encoding of her bit (classical) input : she encodes 0as |0⟩or |+⟩at random, and 1 as |+⟩or |−⟩similarly. Introducing the Pauli X and Z basis, this means that 0is encoded as the first eigenvector of either two basis, and 1as the second vector. The choice of basis for a given pulse is made at random with 50% chance of choosing the Z basis, and 50% chance of choosing the X basis. Assume Bob measures in the same base Alice used, which happens with 50%probability. In this case the post-measurement state is necessarily the same as the original state prepared by Alice. So by reversing the encoding used by Alice he recovers the input bit for 50%of the pulses, in average. In other words, Bob identifies the original quantum state with certainty and hence the original bit. For example, suppose Alice prepares in the X basis, and Bob measures in the same basis, let 𝑓the function that represent Alice’s encoding should she choose the X basis i.e 𝑓(0)= |+⟩and 𝑓(1)=|−⟩. In this case Bob’s outcome is 𝑓−1(𝑓(𝑏))=𝑏. So assuming no attacker is present, there shouldn’t be more than 50%incorrect decodings, and they can check this without revealing their entire keys by ”sacrifying” half of their keys, a procedure that is called sifting. Note that sifting is rarely employed in CVQKD as we shall see later. Having recast the protocol in Information Theory terms, the next steps are classical processing derived from the sequential key agreement model and results therein(such as using universal families to achieve privacy amplification), so the next steps are fully classical. Several other protocols are possible expanding on this idea. For example, a six-state protocol is a natural generalization of this scheme, by using all three Pauli basis. 1.3 High level description of CVQKD We provide a sketch of CVQKD with Gaussian modulation and using coherent states, which is arguably the most common flavour of CVQKD. In the following chapters, we analyze the protocol and its security in detail. CVQKD is slightly different than the conventional discrete QKD protocol BB84 as its security principle is not based on a 50% chance (or more, for example in the six-state protocol) for the eavesdropper to measure in the wrong basis therefore introducing errors and leaving evidence. Instead, the encoding process (from the classical input to the quantum state) happens to be deterministic, but Alice´s classical input will be a pair of two reals numbers (or equivalently a complex number) encoded as the coherent state |𝛼⟩. Coherent 9 Another way to formulate this is that a physical state is an element of a projective Hilbert space, since by definition equivalence classes, called rays, are in 1-to-1 correspondence with norm 1 states when ignoring the global phase. The individual components of these vectors(complex numbers) are called probability amplitudes, for a reason made clear by the measurement postulate. It is common to write such a state with the ket notation |𝜓⟩The 𝜓is just a label whose meaning depends on the context. A basic fact of Hilbertian analysis is that ℋis its own dual, that is each element |𝑥⟩of ℋinduces a continuous linear form given by the inner product with 𝑥:𝜓→⟨𝑥|𝜓⟩. In the finite case, after fixing a basis, we can view |𝜓⟩as a column vector of complex numbers, ⟨𝜓|can therefore be seen as the row vector containing the same values but conjugated, that is, the Hermitian transpose of |𝜓⟩. The simplest non trivial Hilbert space is the one of dimension 2. All Hilbert spaces of the same finite dimension are isomorphic, that is essentially the same for the purpose of linear algebra, so we can consider this space to be ℂ2. Such an element is called a Qubit. Qubits are the bread-and-butter of discrete-variable quantum computing and quantun information theory, arguably the most common and studied paradigm. The other one being continuous variable quantum computing and information theory, which is more challenging mathematically, but sometimes easier to implement. Since a qubit register of 𝑛qubits can be seen as qudit with 𝑑=2𝑘, so registers of qubits can simulate any qudit (where we call qudit the elements of the d-dimensional complex Hilbert space). The formula 𝑑=2𝑘might seem surprising as classically one might except 𝑑=2𝑘, but the reason for why such exponentiation is given by the 4th axiom. Intuitively, we see that qubits can ”hold” much more information due to superposition, although retrieving it is not trivial as we show later in the measurement postulate and Holevo theorem. It is also important to consider infinite dimensional Hilbert spaces as they arise in some situations : for example a particle’s state can be modeled as an element of 𝐿2 (informally speaking a function representing the probability to find the particle at a given location when modulus squared). More relevant to this thesis are quantum states of light, which also live in infinite-dimensional Hilbert spaces and can in fact be represented by tensor product of (separable) Hilbert spaces. They are used in quantum computing as well. As a concrete example of the realization of a qubit, we can consider the spin of an electron, or the polarization of a photon. 2. Evolution postulate The time evolution of a quantum system, in the absence of measurement and interaction with environment, is fully deterministic and even reversible, which does not display quantum ”weirdness”. It can be described by a unitary operator 𝑈, so that starting from a state |𝛼⟩at time 𝑡1, the state of the system at time 𝑡2is 𝑈|𝛼⟩where 𝑈only depends on the time. The postulate does not specify the form of the unitary 𝑈which is delegated to the physicist. A more down to earth formulation is the Schrodinger equation which 16 explicitly introduces the Hamiltonian: 𝑖ℏ𝑑 𝑑𝑡|Ψ(𝑡)⟩=  𝐻|Ψ(𝑡)⟩ Both formulation are, in fact, equivalent. 3. Composite systems postulate The state space of a joint system of two systems each of which would be described individually by ℋ𝐴and ℋ𝐵, shall be described by tensor product of Hilbert spaces ℋ𝐴and ℋ𝐵:ℋ𝐴⊗ℋ𝐵Moreover if the two systems have never interacted then the state of the system is |𝜓⟩𝐴|𝜙⟩𝐵The tensor product can be defined rigorously via its Universal Property, however for most purposes it is enough to see it as all the expressions of the form, where (𝑒𝑖)and (𝑓𝑖)are basis of ℋ𝐴and ℋ𝐵respectively. ∑ 𝑖∈𝐼,𝑗∈𝐽𝑐𝑖𝑗|𝑒𝑖⟩⊗|𝑓𝑗⟩ subject to the normalization condition ∑ 𝑖∈𝐼,𝑗∈𝐽|𝑐𝑖𝑗|2=1 By manipulating such expressions as if the symbol ⊗was the usual multiplication, we get alternative expressions of a given state, for example if it turns out that ∀𝑖,𝑗𝑐𝑖𝑗 =𝑎𝑖𝑏𝑗then the usual factorization of a sum of products gives us: |𝜓⟩=∑𝑎𝑖𝑒𝑖⊗∑𝑏𝑖𝑒𝑖 In such case, the two systems can be studied independently and there is no further need for this postulate. Such states are called separables. Even if elements of ℋ𝐴and ℋ𝐵are not in general separable, the shares can be at two different physical locations(say Alice’s and Bob’s laboratories), which brings the question: What is the result of applying a measurement represented by an operator 𝑀on ℋ𝐴on the first share? This question can be answered by the tensor product of operators. The product operator of 𝑀and 𝑁is defined as the unique operator such that ∀𝑢,𝑣𝑀⊗𝑁|𝑢𝑣⟩=𝑀|𝑢⟩⊗𝑁|𝑣⟩ The uniqueness is trivial because such condition constrains the values it takes on every𝑒𝑖⊗𝑒𝑗, and the existence follows from developing the expressions of Note that the order of measurement doesn’t matter. When dealing with composite systems, the Kronecker product of matrices turns out to be handy, as the density matrices can be obtained by taking the Kronecker product of subsystems. Density matrices are defined in the next chapter. 17 4. Measurement postulate Measurement is perhaps the most surprising postulate along with the composite system postulate as it introduces inherent randomness to the theory, contrasting with classical physics where evolution is always deterministic, in principle. Several interpretations exist to explain this randomness, such as the Many Worlds interpretation which has the advantage of eliminating randomness by simply speculating all outcomes are in fact realized, but in different universes. But one needs not to care about the interpretations since we can still calculate probabilities which is arguably all we need to make predictions. This is the point of view of the Copenhagen interpretation jokingly referred to as ”Shut up and calculate”. In fact, this inherent randomness is the main resource exploited by quantum security protocols. The BB84 protocol, for example, does not even make use of the evolution or the composite system postulates. This states that the value of an observable quantity (like the position, or momentum) is random, even if the state is purely determined physically according to the first postulate (by a state vector or wavefunction). However the probabilities are well defined (given the underlying state) by the theory and therefore we can still make ”predictions”. There are two kinds of measurements considered: projective measurements are the most common, and POVM are an abstract generalization. A protective measurement is defined by a set of real numbers 𝑚𝑖representing the possible measurement outcomes, and a collection of corresponding states (kets) |𝑖⟩ According to this postulate, the probability of observing outcome 𝑚𝑖given that the underlying state is 𝜌is the modulus squared of the coordinate of 𝜓along the basis. Since this is an orthogonal basis, these coordinates are simply inner products. Moreover the postulate states that after measurement, the state will collapse into |𝑖⟩. This is called the Born rule. An obvious consequence of is that measurement is repeatable : ⟨𝚤|𝚤⟩=1so we will keep observing the value 𝑚𝑖if we repeat the measurement on the post-measurement states. Conversely, any Hermitian operator can be written in such fashion and thus seen as a measurement, thanks to the spectral theorem. An important consequence of this axiom is that the order in which we perform measurement matters, but it can be shown that as long that the observables commute, the order does not. The expectation of this measurement (on a given state |𝜓⟩) is defined as the expectation of the induced random variable. So it is the average result we would observe if we repeated the measurement on multiples copies of the state, it is denoted ⟨𝐴⟩. We can write it ⟨𝜓|  𝐴|𝜓⟩and this can be seen by grouping the basis elements into columns of a matrix 𝑁, and by defining the diagonal matrix 𝐷whose diagonal elements are the measurement outcome. An alternative representation of measurement that is widely used is through Hermitian operators. For each basis elements we can define the projector Π𝑖. Define 18 the Hermitian operator ∑Π𝑖. This Hermitian operator contains all the information about the measurement outcomes (the probability distribution). Conversely, any Hermitian operator can be written in such fashion and thus seen as a measurement, thanks to the spectral theorem. In this context, we often call them Observables. The observable representation is handy as for example the expectation of an operator 𝑀on a state |𝜓⟩is just ⟨𝜓|𝑀|𝜓⟩ 2.2.2 Motivation for the measurement postulate: The Stern-Gerlach experiment When trying to measure the deflection of electrons along the 𝑍axis, physicists observed that although this deflection should have been 0 as they have 0angular momentum, particles still deflected as if they had an angular momentum, furthermore these values were quantized i.e taking only a discrete set of values, in fact just 2 : 1/2and −1/2. This suggests that particles posses an intrinsic property (like the mass or charge) known as Spin(a priori one for each axis), but at this stage one can still assume the randomness might simply be due to the preparation of the particles as an ensemble with half the particles having spin −1/2and the other 1/2However, when cascading the experiments, results that are counter-intuitive showed up. Let’s consider an apparatus where we first measure the spin along the Z axis. According to our classical intuition, no matter which measurement we perform next, this should not affect the value already measured(”realism”). It turns out that even while filtering say particles with Z spin 1/2, these particles reappaear with probability 1/2after measuring them again, with a measurement of the 𝑋spin in between. So we have the apparent contradiction of electrons having an intrinsic property, but whose value can change. The measurement postulate provides a clear explanation of these observations: If we assume that the eigenbasis of 𝑋expressed in the 𝑍basis are the sum and differences of them, then the Born rule correctly predicts that the outcomes of the last 𝑍measurement should be a 𝐵𝑒𝑟𝑛(1/2)In fact we say that the 𝑍and 𝑋are mutually unbiased bases, and it is precisely on this fact that BB84 is based. Figure 2: Stern-Gerlach apparatus 19 2.2.3 QKD as an instance of the secret key agreement from a source model QKD can effectively be seen as an instance of secret key agreement from a source model, as we can clearly model 𝑋,𝑌and 𝑍as random variables and find their joint distribution once Eve’s intervention has been modelled. Let’s say that Eve measures in the Breidbart basis, which eigenstates are the qubits obtained by rotating the computational basis by 𝜋/8:|𝜙0⟩=cos(𝜋/8)|0⟩+sin(𝜋/8)|1⟩,|𝜙1⟩=−sin(𝜋/8)|0⟩+cos(𝜋/8)|1⟩ We could assume that the components of 𝑋𝑛are i.i.d Bern(1/2), it remains to explicit the conditional distribution of (𝑌𝑛,𝑍𝑛). This can be done by separating cases, that is further conditioning on the choices of basis. We only examine the case of one symbol since they are i.i.d. For example if we wish to calculate 𝑝(𝑌 =0,𝑍=0|𝑋=0), we can further condition on the basis chosen, there are 4 cases. Given that Alice has chosen the Z basis, Bob the Z basis, and Eve the Breidbart basis, we find by applying the Born rule (inner product of the first vector of the 𝑍basis, first vector Breidbart basis) 𝑝(𝑍=0|𝑋=0,𝑏𝑜𝑏𝑏𝑎𝑠𝑖𝑠=𝑍,𝑎𝑙𝑖𝑐𝑒𝑏𝑎𝑠𝑖𝑠=𝑍)=|cos 𝜋 8|2 Then the probability of Bob still observing 0 after the intervention is again with the Born rule 𝑝(𝑌 =0|𝑍=0,𝑋=0,𝑏𝑜𝑏𝑏𝑎𝑠𝑖𝑠=𝑍,𝑎𝑙𝑖𝑐𝑒𝑏𝑎𝑠𝑖𝑠=𝑍)=|cos 𝜋 8|2 So we have calculated 𝑝(𝑦,𝑧|𝑥,𝐶)given some condition 𝐶, then the usual law of total probabilities(conditional case) can be used to collect them to get 𝑝(𝑦,𝑧|𝑥). Here the set of conditions is all the possible choice of basis, which happens with probabilities 1/4 So by a weighted sum of such conditional probabilities(here the weights would be 1/4 since each of the 4 choices of basis are equiprobable), we can explicit the distribution(𝑋,𝑌,𝑍) and the theoretical results of the secret key agreement from a source, hold. 2.2.4 Density matrix : A useful formalism for mixed states Density matrices provide a powerful alternative to state vectors for dealing with mixed states. A mixed state is just a superposition, in the classical sense, of pure states(i.e. a probability distribution over pure states, capturing the fact that the pure state is unknown). So it is described with a set of probabilities 𝑝𝑗, and the corresponding pure states 𝜓𝑗. So with probability 𝑝𝑗, the system is in the state 𝜓𝑗. Mixed states allow for some combinations of observables and probabilities distributions that wouldn’t occur using pure states alone. For example, consider the mixed states that is in either |0⟩or |1⟩with probability 1/2. When measured in the 𝑍basis, the probabilities of obtaining 0 and 1 are obviously 1/2respectively. This is similar to the pure state |+⟩, but when measured in the 𝑋basis the situation is different : |+⟩will obviously always 20 yield the same outcome since it is an eigenstate of 𝑋, while the mixed state has 1/2 chance to be in either the Z basis states, and these states projected on the X basis have the same probabilities. This behaviour isn’t possible using a pure state since such pure state will be similar to |+⟩(with a relative phase difference). Another motivation for density matrices is that a mixed state can be represented in a compact manner. Indeed, consider a mixed state, it could be fully specified by the set of pure states it can be in and their respective probabilities. Based on this knowledge, we can calculate the probabilities for an arbitrary observable by simply applying the law of total probabilities as in classical probabilities 𝑝(𝑚)=∑ 𝑗𝑝𝑗⟨𝜓𝑗|Π𝑚|𝜓𝑗⟩ However the above sum involves an arbitrary large number of terms. Even by considering a single qubit, the specification of single mixed state could be arbitrary long. Taking advantage of the well-known identity 𝑡𝑟(𝐴𝐵)=⟨𝑥,𝐴𝑥⟩where 𝐵is the projector associated to 𝑥i.e 𝐵=𝑥𝑡𝑥and by taking out the trace from the sum, which is justified since the trace is linear, the formula becomes 𝑝(𝑚)=∑ 𝑗𝑝𝑗⟨𝜓𝑗|Π𝑚|𝜓𝑗⟩=tr [Π𝑚(∑ 𝑗𝑝𝑗|𝜓𝑗⟩⟨𝜓𝑗|)] which only has 𝑑2complex degrees of freedom for a single qudit that are the entries of the matrix 𝜌=∑𝑗𝑝𝑗|𝜓𝑗⟩⟨𝜓𝑗|(in fact less since the matrix is hermitian) For example for a qubit is is fully determined by two complex numbers (since it is Hermitian) in this formalism instead of two arbitrary large sets as the naive approach. The expectation of an operator 𝑀in this formalism can be shown to be 𝑡𝑟(𝑀⋅𝜌)The density matrix (or operator, since it generalizes to arbitrary Hilbert spaces) also have some additional properties which are trivial from its definition : it is positive semidefinite and has a trace 1. Since every ensemble correspond to a PSD operator of trace 1 and vice-versa, we can take density matrices/operators as the fundamental definition of ”state” in quantum mechanics, and the others postulates can be reframed with density matrices. For example, the measurement postulate in this form tells us that the expectation of an observable 𝐴is 𝑡𝑟(𝑀𝜌𝐴). It is easy to verify that the density matrix of a product state in ℋ𝐴⊗ℋ𝐵is obtained by the Kronecker product of the two states. 2.2.5 Partial trace and purification Motivation : Reduced states 21 Consider a general state 𝜌on ℋ𝐴⊗ℋ𝐵. Physically, we can apply operators defined on ℋ𝐴to the first share even though the two subsystems may be entangled and impossible to describe by describing each one individually (as respectively a mixed state of ℋ𝐴and a mixed state of ℋ𝐵. So there is no a priory defined state 𝜌𝐴on ℋ𝐴which gets us the measurement statistics of applying an operator 𝑀of ℋ𝐴(through Tr(𝑀⋅𝜌𝐴)) but we still have a mathematically well defined operator on the product space given by 𝑀×𝐼 which is the one matching the experience. It is therefore natural to ask if there is a state 𝜌𝐴which when measured by 𝑀would give us statistics as if the first subsystem was in 𝜌𝐴. In other words, 𝜌𝐴must fulfill the following condition, for any operator 𝑀: Tr(𝑀⋅𝜌𝐴)=Tr(𝑀⊗𝐼⋅𝜌) Such state would allow us to view the system as if it wasn´t entangled. The answer is positive (and unique) and is given by the partial trace.Partial trace The partial trace over 𝐴is defined as a liner application that maps operators of ℋ𝐴⊗ℋ𝐵to operators on ℋ𝐴in the following manner Given such application 𝑇, we can fix 𝑖and 𝑗and consider the linear map 𝐹𝑖𝑗 that maps 𝑢 to a vector 𝑣by applying 𝑇to 𝑒𝑖⊗𝑢and having decomposed this image as 𝑇(𝑒𝑖⊗𝑢)= ∑𝑞𝑒𝑘⊗𝑣𝑘we define 𝑣=𝑣𝑗. The trace of this application is denoted 𝑓𝑖𝑗. The expression of 𝑓𝑖𝑗 is trivial to calculate from the coefficients of 𝑇since the coefficients of the tensor 𝑇with 𝑖fixed reappear in 𝑇(𝑒𝑖⊗𝑢)and by keeping only the term 𝑒𝑗⊗𝑣𝑗, we are fixing two coefficients of the tensor so we are left with a sum along one indice: 𝐹𝑖,𝑗 =𝑛 ∑ 𝑘=1𝑇𝑘,𝑗 𝑖,𝑘. The partial trace is the linear application of ℋ𝐴defined by such coefficients 𝑓𝑖𝑗. It is then easy to see that this definition is equivalent to this coordinate-free definition : Tr𝑊(𝑅⊗ 𝑆)=Tr(𝑆)𝑅 ∀𝑅∈L(𝑉) ∀𝑆∈L(𝑊). Now back to the original motivation, we can interpret 𝜌as an operator on ℋ𝐴⊗ℋ𝐵 (which has additional properties : positive semidefinite with trace 1). If we define 𝜌𝐴as its partial trace, then the sought-after identity will hold, for any operator 𝑀: Tr(𝑀⋅𝜌𝐴)=Tr(𝑀⊗𝐼⋅𝜌) This is because Tr(𝑀⋅𝜌𝐴)=Tr(𝑀)Tr(𝜌𝐴) =1 𝑑𝑖𝑚ℋ𝐵Tr(𝑀⊗𝐼)𝑑𝑖𝑚ℋ𝐵Tr(𝜌) (1) where 𝑑𝑖𝑚ℋdenotes the dimension of Hilbert space ℋ. 22 2.2.6 Purification An interesting feature of the partial trace is that even a pure state on ℋ𝐴⊗ℋ𝐵can become a mixed state on ℋ𝐴when tracing out ℋ𝐵. A natural question is thus if any mixed state on ℋ𝐴can be written as the partial trace of some pure state on ℋ𝐴⊗ℋ𝐵for some Hilbert space ℋ𝐵. The answer is yes, although such purification is not necessarily unique. Analysis of the possible purification show that all purifying state differ only by an unitary operator which is crucial to the security analysis of CVQKD as we will see Obtaining a purification of a mixed state is in principle easy because we can just tensor each element of its ensemble with the respective state of an orthonormal basis of the ancilla space, and the partial trace will ”remove” this basis because Tr𝐾(𝑀)=𝑀. 2.3 Quantum Information theory 2.3.1 Encoding classical variables Classical states can simply be encoded as elements of a chosen family of orthogonal quantum states. Random variables are convex combinations(i.e linear combinations with positive coefficients summing to 1). So their density matrix is diagonal. 2.3.2 Quantum channels A quantum channel is a formalization of the evolution of a quantum state(represented by a density matrix) in the most general manner. Such evolution could include but is not limited to, unitary evolution and measurements. There are two usual ways to define it, both equivalent. The constructive approach is based on the observation that one kind of transformation a system 𝜌can undergo is through interaction with the outside environment, represented by an ancilla 𝑎, then the global system will undergo some unitary transformation. At this stage if we measure our system, the answer will be given by the partial trace as explained in the Partial trace section before. So from this observation, one kind of quantum channel must be those of the form: ℰ(𝜌)=Tr𝐾𝑈(𝜌⊗𝑎)𝑈† In fact, every quantum channel can be written in this form. An alternative but equivalent definition of quantum channels is possible. It is more axiomatic as it a set of conditions a map ℰmust verify instead of an explicit construction. First, since density operators are positive, ℰmust be positive, and it must be trace preserving since density operators have trace 1. Finally, these properties must hold for the induced application ℰ⊗𝐼𝑑𝑛. Such maps are called completely positive trace preserving (CPTP), these two definitions of quantum channels are equivalent by Stinespring’s dilation theorem. 23 2.3.3 Holevo Theorem Consider the situation where we have a mixed state, but we don’t know which one. That is, the mixed state is drawn at random from a collection {𝜌1,𝜌2,...𝜌𝑛}. The total state is therefore ∑𝑝𝑖𝜌𝑖. The challenge is thus identifying 𝑖, we can therefore ask the following question: What POVM would maximize 𝐼(𝑋;𝑌)(𝑌being the r.v representing the outcome of the measurement, and 𝑋the r.v whose outcomes are the indexes 𝑖)? An upper bound is known and is called Holevo theorem. This bound involves the von Neumann entropy: 𝐼(𝑋;𝑌)≤𝐻(𝜌)−∑ 𝑖𝑝𝑖𝐻(𝜌𝑖) 2.4 Quantum optics for CVQKD 2.4.1 Quantum states of light The main difference between discrete and continuous quantum key distribution is that the underlying Hilbert space is infinite dimensional. The analogue of a qubit is one mode of light, sometimes called qumode. Just as qubits can be represented as elements of twodimensional complex Hilbert space(and multiple qubits by elements of the tensor product of such spaces) with a chosen orthogonal basis, we can represent states of light with an Infinite dimensional separable Hilbert space, with a chosen Hilbert basis. A rigorous derivation of this space requires the quantization of the electromagnetic field, however we assume the space is given and only present the main operators and types of states. The next section sheds some light as why operators are defined as such. Although it is an infinite dimensional space, is has the topological property of being separable, which according to basic Hilbert theory implies that a Hilbert basis can be found, and in this basis, called Fock basis, any state can be expressed as an infinite linear combination of the Fock states. It should be noted that this is not a basis in the sense of linear algebra since an algebra basis always has a finite cardinality. Here we deal with infinite sums as well. That is, the meaning is that of a limit, and not a usual finite sum. It is a well-known fact that ∑∞ 𝑛=0𝑐𝑛|𝑛⟩converges if and only if ∑∞ 𝑛=0𝑐2 𝑛<∞so even though the Hilbert space is an arbitrary infinite dimensional separable vector space with inner product, we can still see its elements as sequences of complex numbers(albeit infinite) who are square summable just like an arbitrary vector space of dimension 𝑛can be seen as the set of sequences of length 𝑛, and in particular just as a qubit can be seen as a couple of complex numbers(up to normalization and global phase). In this basis, we can runiquely define two important operators called the ladder operators, or creation and annihilation operators : 𝑎|𝑛⟩=√𝑛|𝑛−1⟩  𝑎†|𝑛⟩=√𝑛+1|𝑛+1⟩ As the notation hints, it is easy to check that they are adjoints of each other. The name 24 ladder or creation/annhilation is justified as they add or remove an element of the Fock basis. In fact, the Fock basis correspond to number of photons, so they can be interpreted as literally adding or removing a photon. The photon number operator is defined as 𝑛|𝑛⟩=𝑛|𝑛⟩ From the definition, it is clearly an observable. It can be used to measure(count) the number of photons as the Fock states are its eigenstates, and the corresponding eigenvalue of |𝑛⟩is precisely 𝑛. This observable is actually implemented as photon detectors, but is experimentally challenging, so what we usually have is the simpler POVM {|1⟩,𝟙−|1⟩} and it is trivial to see that 𝑛=  𝑎†𝑎which is an important factorization of the number operator. Coherent states, which form the backbone of most CVQKD protocols are defined as the eigenvectors of annihilation operators, it it possible to find their expression in the Fock basis as : |𝛼⟩= ∞ ∑ 𝑛=0 𝛼𝑛 √𝑛!𝑒−|𝛼|2 2|𝑛⟩ This expansion is easy enough to derive, as the coefficient 𝑐𝑛must divide by √𝑛the previous coefficient( to cancel the √𝑛introduced by the definition of 𝑎 and multiply by |𝛼(since 𝛼is the desired eigenvalue. The outer coefficient follows from normalization. The above expansion shows (Born rule) that the number of a photons follows a Poisson distribution. The quadrature operators are defined as 𝑝= 𝑎+ 𝑎† 𝑞=−𝑖( 𝑎− 𝑎†) The name quadrature comes from the fact that the expectation value of these operators applied to coherent states, viewed as a function of time, is offset in phase by a quarter. Some other definitions exist for the quadrature operators, which only differ by a scale parameter (i.e. different units). The convention used here is called Shot-Noise because the uncertainty on coherent states is 1 (Heisenberg uncertainty principle). 𝛿 𝑞𝛿 𝑝≥1 The quadratures operators are also called position and momentum-like operators(as the notation hints), because they satisfy the same commutation relation as the position and momentum operators in quantum mechanics, the so called Canonical commutation relation (CCR). [ 𝑞, 𝑝]=2𝑖 25 ⎛ ⎜ ⎜ ⎜ ⎜ ⎜ ⎝ 𝑉+1 212𝑉−1 212√1 2(𝑉2−1)𝜎𝑧 𝑉−1 212𝑉+1 212√1 2(𝑉2−1)𝜎𝑧 √1 2(𝑉2−1)𝜎𝑧√1 2(𝑉2−1)𝜎𝑧𝑉12 ⎞ ⎟ ⎟ ⎟ ⎟ ⎟ ⎠ The formal proof of equivalence of such protocol with the PM one is the object of the next section. 3.3 Security Analysis Security analysis has been carried out in the asymptotic sense, that is, assuming that the block length goes to infinity. Although not realistic, it is still useful, at least in providing upper bounds to the maximum achievable security. 3.3.1 Key Rate The (per symbol) key rate is defined as the average amount of secret bits Alice and Bob can extract from a single symbol. Here the symbol for Alice is a complex number, modulated into a coherent state on which Bob perform homodyne or heterodyne detection on to estimate one or both quadrature components. The performance of the protocol will also depend on the symbol frequency. Denote by 𝑓𝑠𝑦𝑚 the number of symbols sent per second, the performance of the protocol that is the average amount of secret bits generated per second is thus related to the rate 𝑟by 𝐾=𝑓𝑠𝑦𝑚.𝑟 The theoretical rate of the discussed protocol is given by the Devetak-Winter formula Devetak and Winter [2005]: 𝑟=𝐼𝐴𝐵−𝜒𝐸𝐵 This formula is not too much surprising, as it is the difference of the number of shared bits between Alice and Bob, and the bits Eve has been able to find. Note that the Holevo information is calculated between Eve and Bob because of reverse reconciliation (it would be between Alice and Eve in direct reconciliation). It somewhat parallels the classic formula for the secret-key agreement: 𝑟=𝐼𝐴𝐵−𝐼𝐴𝐸 This rate however is theoretical and will be lower in practice, due to various reasons. First, the reconciliation efficiency is not perfect and depends on the chosen algorithm, so 𝐼𝐴𝐵 is replaced by 𝛽𝐼𝐴𝐵 where 𝛽≤1is the reconciliation efficiency. Second, there is a proportion of frames that are either discarded because of errors, or disclosed so they do not participate in the reconciliation. Say for example half of the frames are not used, then the previous rate should be divided by 2 in the previous formula. In the general if the proportion is 𝑒then the rate should be multiplied by (1−𝑒) 32 This gives us the realistic rate achieved by such a protocol: 𝑟=(1−𝐹𝐸𝑅)(1−𝜈)(𝛽𝐼𝐴𝐵−𝜒𝐸𝐵) 3.3.2 Calculation of the mutual information The mutual information is not difficult in the PM scenario (unlike the Holevo information, because). Since we have a signal affected by a Gaussian noise, we can use the usual Shannon formula: 𝐼𝐴𝐵 =𝜇 2log(1+𝑆𝑁𝑅)Here 𝜇refers to the bandwith and is 1 for homodyne detection and 2 for heterodyne detection. The variance of Bob´s outcome as shown before is 𝑉assuming no losses and noise. 3.3.3 Formal proof of equivalence of the PM and EB scenarios We want to prove that the PM and EB scenario are equivalent, so we can use the Holevo information calculated in EB case in our analysis of attacks even if the actual protocol carried out is PM. By equivalents, we mean that the random variables arising in both cases have the same joint distribution. Since they are Gaussian vectors, it suffices to show that they have the same covariance matrix, and mean vector. Denote by (𝐴1,𝐴2,𝐵)the random vector generated in the PM scenario. As explained before, 𝐴1and 𝐴2are generated classically by Alice, and 𝐵is the result of Bob’s homodyne/hetrodyne measurement. Similarly denote by (𝐴′1,𝐴′2,𝐵′)the random vector generated in the EB scenario. Its components are generated by Alice’s and Bob’s measurements on a three mode Gaussian state. Specifically, Alice measures the first two modes and Bob the last one, the order of measurement is in principle arbitrary since they are commuting operators. The apparent difficulty lays in the fact that the co-variances appearing in the EB covariance matrix aren’t a priori the covariances of random variables, but are formally defined by Cov(𝑀,𝑁)=1 2{𝑀,𝑁}: What we show is that the covariances of the r.v.s defined by Alice and Bob successive measurements in the EB scenario are identical to those operator covariances. Then if the EB matrix is equal to the PM matrix, this means that effectively, the r.v.s arising in the PM and EB scenarios are the same, since two random Gaussian vectors with the same mean and covariance must have the same distribution. Let us first explicit the covariance matrix in the PM case. This is a matrix of covariances in the classical sense. The variances were calculated before (which are 𝑉𝑚𝑜𝑑,𝑉𝑚𝑜𝑑,𝑉𝑚𝑜𝑑+1), it remains to calculate the covariances which are non null between, which can be done using the fact that Bob’s outcome is the sum of Alice’s outcome and a 𝒩(0,1): Cov( 𝑞𝐴, 𝑞𝐵)=⟨ 𝑞𝐴𝑞𝐵⟩=⟨( 𝑞𝐵− 𝑞𝐴) 𝑞𝐴⟩+⟨ 𝑞2 𝐴⟩ Then using the fact that ( 𝑞𝐵− 𝑞𝐴)is a 𝒩(0,1)independant from 𝑞𝐴all we are left with is ⟨ 𝑞2 𝐴⟩=𝑉𝑚𝑜𝑑. Now, we show that the covariances of (𝐴′1,𝐴′2,𝐵′)are those appearing the EB matrix. 33 It is clear that 𝐴′1is a Gaussian variable whose mean is 0 and variance V, using the fact that its distribution can be recovered by integrating the Wigner function of the TMVS. Indeed the distribution of any quadrature of any given mode can be recovered by integrating the Wigner function over the rest of the 2𝑁−1variables, and by definition of Gaussian states their Wigner function is Gaussian. For 𝐴′2and 𝐵′, this is also true even after Alice performs her measurement, since the quadratures of different modes are commuting (this is a basic property of quantum measurements, 𝑀⊗𝐼and 𝐼⊗𝑁commute for any two operators 𝑀and 𝑁and the result extends to any number of modes) therefore even if Bob performs homodyne detection on the post-measurement state, the overall distribution of the second quadrature stays the same as if Alice didn’t do anything. To make more precise the above statement that the mean and variance of the EB random vector is the same as the PM one, we used the following result: Let 𝑀and 𝑁be two commuting observables and 𝜌a state. The distribution of 𝑁applied to 𝜌is the same as the distribution of the outcome one gets by applying 𝑀first, discarding the result and applying 𝑁on the post-measurement state. This result stays true for 3 observables as in our case. Now we show that 𝐶𝑜𝑣(𝐴′1,𝐵′)=𝐶𝑜𝑣(𝐴1,𝐵). We know that 𝐶𝑜𝑣(𝐴′,𝐵′)=1 2{𝑞𝐴,𝑞𝐵}. We can use the following result: Let 𝑀,𝑁be two commuting operators with zero mean. Then if we measure using 𝑀on a state 𝜌, then measure using 𝑁on the post-measurement state, the (classical) covariance of the outcomes is exactly the covariance of the operators that is 1 2{𝑞𝐴,𝑞𝐵}. This is possible because two commuting operators can be considered a single operator(”we can measure both at the same time”) : We can find a common orthonormal basis |𝑐,𝑑⟩ where 𝑀|𝑐,𝑑⟩ = 𝑐|𝑐,𝑑⟩ and 𝑁|𝑐,𝑑⟩ = 𝑑|𝑐,𝑑⟩. So this shows that the covariance matrix of the operators is equal to the covariance matrix of the corresponding measurements Our EB matrix is identical to the PM one, except for a scale factor, so we can just rescale measurements: ⎛ ⎜ ⎜ ⎜ ⎜ ⎜ ⎝ 𝑉+1 212𝑉−1 212√1 2(𝑉2−1)𝜎𝑧 𝑉−1 212𝑉+1 212√1 2(𝑉2−1)𝜎𝑧 √1 2(𝑉2−1)𝜎𝑧√1 2(𝑉2−1)𝜎𝑧𝑉12 ⎞ ⎟ ⎟ ⎟ ⎟ ⎟ ⎠ Since covariance is bilinear (𝐶𝑜𝑣(𝑎𝑋+𝑌,𝑍) = 𝑎𝐶𝑜𝑣(𝑋,𝑍)+𝐶𝑜𝑣(𝑌,𝑍), Alice only needs to rescale her measurements so that both matrices become identical. 𝑞𝐴→√2(𝑉−1) 𝑉+1 𝑞𝐴(3) 𝑞𝐵→√2(𝑉−1) 𝑉+1 𝑝𝐴(4) 34 3.4 Possible attacks 3.4.1 Classification of attacks Attacks on a QKD are usually classified in three tiers depending on the attacker’s capabilities: • Individual attack: Eve’s has access to independent ancillae each of which interact with a single optical pulse. • Collective attack: Identical to the above, but Eve can measure her quantum state anytime, even after post-processing. • Coherent attack: The i.i.d assumption is dropped. Eve may have a multi mode ancilla, possibly not separable, and it can interact with the joint pulses of the signal. In general, analysis of attacks is made simpler by assuming that Eve holds a purification of Alice and Bob mutual state 𝜌𝐴𝐵. The exact purification does not matter, as all purifications are related by a unitary transformation (𝑈𝜌𝑈†) so the Holevo information, which is invariant by unitary transformation, is the same, and therefore the knowledge of Eve doesn’t depend on her purification. 3.4.2 Entangling cloner attack This attack is based on the fact that Alice and Bob are willing to tolerate a certain amount of noise (because their channel is assumed noisy), Eve can therefore replace the lossy channel between Alice and Bob by a noiseless channel, so Eve will get some ”room” to eavesdrop even if her intervention introduces noise, as long as the loss doesn’t attain the threshold of the assumed lossy channel. More precisely, the intervention consist of a beamsplitter that will mix one of Eve’s modes with Bob’s mode. It is an example of a collective attack, since she can measure anytime after postprocessing and by computing the Holevo information she will measures state by state. This attack uses the following result: Let 𝜌be a Gaussian state with covariance matrix Σ. A beamsplitter with transmission 𝑇applied to two modes of a Gaussian state will transform them according to the following matrix: (√𝑇𝟙2√1−𝑇𝟙2 √1−𝑇𝟙2√𝑇𝟙2) For a general 𝑁mode Gaussian state, we start with the identity matrix 𝟙2𝑁and plug the above 4×4matrix at the correct cells depending on the modes the beamsplitter is acting on so that the beamsplitter acting on modes 2 and 3 (i.e. Bob’s mode and the first of Eve’s modes) is: ⎛ ⎜ ⎜ ⎜ ⎜ ⎝ 𝟙20 0 0 0√𝑇𝟙2√1−𝑇𝟙20 0√1−𝑇𝟙2√𝑇𝟙20 0 0 0 𝟙2 ⎞ ⎟ ⎟ ⎟ ⎟ ⎠ So when applied to the second and third mode of the 4-modes Gaussian state 𝜌, the covariance matrix will transform the total state to become: 35 Σ𝐴𝐵𝐸1𝐸2=𝐵𝑆𝐵𝐸1Σ𝐴𝐵𝐸1𝐸2𝐵𝑆𝑇 𝐵𝐸1 =⎛ ⎜ ⎜ ⎜ ⎜ ⎝ 𝑉𝟙2√𝑇√𝑉2−1𝜎𝑧−√1−𝑇√𝑉2−1𝜎𝑧0 √𝑇√𝑉2−1𝜎𝑧(𝑇𝑉+[1−𝑇]𝑊)𝟙2√𝑇(1−𝑇)(𝑊−𝑉)𝟙2√1−𝑇√𝑊2−1 −√1−𝑇√𝑉2−1𝜎𝑧√𝑇(1−𝑇)(𝑊−𝑉)𝟙2([1−𝑇]𝑉+𝑇𝑊)𝟙2√𝑇√𝑊2−1𝜎𝑧 0√1−𝑇√𝑊2−1 √𝑇√𝑊2−1𝜎𝑧 ⎞ ⎟ ⎟ ⎟ ⎟ ⎠ So the covariance matrix between Alice and Bob (first two rows and first two columns) is: (𝑉𝟙2√𝑇√𝑉2−1𝜎𝑧 √𝑇√𝑉2−1𝜎𝑧(𝑇𝑉+[1−𝑇]𝑊)𝟙2) So if Eve chooses her variance to be related to the transmission as: 𝑊= 𝜉 1−𝑇+1 Then the covariance between Alice and Bob is: (𝑉𝟙2√𝑇√𝑉2−1𝜎𝑧 √𝑇√𝑉2−1𝜎𝑧(𝑇[𝑉−1]+1+𝜉)𝟙2) which corresponds to communication through a lossy channel with excess noise 𝜉without an eavesdropper. Even if Eve’s intervention is unnoticed, the attack is only useful if she can extract information, which prompts the calculation of her Holevo information: The von Neumann entropy depends on the symplectic eigenvalues of Eve’s substate which is: (𝑉𝟙2√𝑇√𝑉2−1𝜎𝑧 √𝑇√𝑉2−1𝜎𝑧(𝑇[𝑉−1]+1+𝜉)𝟙2) Denoting by 𝑎,𝑏and 𝑐the coefficient of the identity matrix and Pauli Z matrix in the above matrix, direct calculation of the symplectic eigenvalues immediately leads to 1 2(𝑧±[𝑏−𝑎]) where 𝑧=√(𝑎2+𝑏2−4𝑐2. These eigenvalues can be plugged in the formula giving the von Neumann entropy as function of the symplectic eigenvalue of the covariance matrix (see Laudenbach et al. [2018] B.14) 𝐻=∑𝑔(𝑣𝑖) with 𝑔(𝑣)=(𝑣+1 2)𝑙𝑜𝑔2(𝑣+1 2)−(𝑣−1 2)𝑙𝑜𝑔2(𝑣−1 2) and 𝑣𝑖being the symplectic eigenvalue of the covariance matrix of the state. In order to calculate 𝐻(𝐸|𝐵)𝜌, we need to know the post-measurement state, which is a Gaussian state. The covariance matrix of the post-measurement state doesn’t depend on the measurement outcome, it is similar to the formula for the conditional distribution of Gaussian vector: 𝜎𝐸|𝐵 =Σ𝐸−1 𝑉𝐵(([1−𝑇]𝑉+𝑇𝑊)𝟙2) 36 3.4.3 Purification In Laudenbach et al. [2018], the question of an universal analysis of purification attacks was considered. That is, all we assume is that Eve holds an ancilla that purifies Alice and Bob’s joint state 𝜌𝐴𝐵. This means that the total state is an element of the triple tensor product of Alice, Bob and Eve’s Hilbert spaces, not being necessarily separable, i.e not necessarily being the product of some element of the tensor product of Alice and Bob’s Hilbert spaces, with Eve’s Hilbert space. However the following holds: • The total state is pure: 𝜓=|𝜓⟩⟨𝜓| • The partial trace when tracing out Eve’s space is 𝜌𝐴𝐵. So the statistics of the state shared by Alice and Bob when they perform measurements, if Eve doesn’t do anything on her ancilla, are guaranteed to be identical to those obtained in a scenario without any eavesdropper where their state would literally be 𝜌𝐴𝐵. In this case, the Schmidt decomposition of a pure bipartite state turns out to be helpful. More precisely we see the total state as bipartite between the tensor product of Alice and Bob Hilbert space, that is the first space, and Eve’s Hilbert space, that is the second space. |𝜓⟩=∑√𝜆𝑖|𝑖⟩𝐴𝐵|𝑖⟩𝐸 The partial trace, once such decomposition is obtained, is trivial as we just eliminate Eve’s kets and square the components. This comes from the fact that we need to transform the above expression to a density matrix since the partial trace is defined for operators not state vectors hence the induced squaring of the Schmidt components. One might ask what would happen if we used another Schmidt decomposition, since the 𝜆𝑖 will be different and hence the Von Neumann entropy too, a priori. In fact, all purifications are related through a Unitary transform, and the Holevo information is invariant under such transforms. Therefore the Holevo information 𝐻(𝐸)is just 𝐻(𝐴,𝐵) Finally we need to calculate the second part of the Holevo information which is the Von Neuman entropy after Bob performs a measurement. We consider only homodyne detection for simplicity. This can be obtained using the general formula giving the covariance matrix of the remaining mode(s) of a Gaussian state, after the last one has been measured. Note that this post-measurement covariance matrix doesn’t depend on the outcome unlike the mean vector which actually does), a property of Gaussian states. Denoting by 𝑎,𝑏 and 𝑐the coefficient of the identity matrix and Pauli Z matrix in the covariance matrix of the shared state between Alice and Bob, the symplectic eigenvalue can be expressed as: √𝑎(𝑎−𝑐2 𝑏) 3.5 Basic numerical verification Using StrawberryFields[Killoran et al., 2019] and [Bromley et al., 2020], we can experimentally assess some of the previous formulas: 37 3.5.1 Variance and Mean in the PM scenario We simply generate samples from a Gaussian distribution with mean 0and variance  𝑉𝑚𝑜𝑑, which represent Alice’s 𝑞quadrature outcomes. Then each outcome gives rise to a coherent state (the other quadrature of this state is a random unused 𝑝). Bob then measures, always using 𝑞(In the actual protocol, we should choose one of the two quadratures at random). The mean should be 0and the variance should be 4 𝑉𝑚𝑜𝑑+1 which is the case here after 10000 trials where we have set  𝑉𝑚𝑜𝑑 =2: 3.5.2 Error on a fixed coherent state According to the theory, Bob’s mean outcome is zero (it is a centered random variable). We check this. We also check that the error (difference between Alice’s quadrature component and Bob’s estimation of it), is a 𝒩(0,1)Since the expectation of 𝑝is actually 2𝑝, we subtract this value from Bob’s outcome, i.e we calculate 𝐵−2𝑞 where 𝐵is the r.v representing Bob’s outcome. 3.5.3 Variances in the EB scenario We have seen in 3.2 that the EB scenario is based on the preparation of a 3 mode Gaussian state by Alice, who measures the first two modes to get her two classical outcomes, and sends the last mode to Bob who measures it. The outcomes will have the same joint distribution as in the PM scenario, if Alice rescales her measurements. We prepare the required 3 mode Gaussian state in the following way: We start with three vacuuas. We then apply a two modes squeezing gate (S2 gate) with parameter 𝑟to modes 38 1 and 3. The result of this gate is a TMSVS of variance 𝑉 =cosh(2𝑟)in modes 1 and 3. Then a beamsplitter is inserted between modes 1 and 2 (which is still a vacuum). According to the theory, the variance of the first mode should be 𝑉+1 2Here 𝑟=3, so 𝑉 =cosh(6)≈202, so the variance should be �101 The variance of the 3rd mode (Bob’s mode) which according to 3.2 should be 𝑉is also checked: In a similar fashion, we could also check the whole covariance matrix 3.3.3 (interpreted as a covariance matrix of random variables) by calculating the empiricial covariance. It is a 6×6matrix(two quadratures for each of the three modes), but since we cannot measure both quadratures, we consider the following 3×3submatrices: • Covariances of the 𝑞quadrature on all 3 modes. • Covariances of 𝑞,𝑝and 𝑞(which is what is done in the EB protocol) The result are shown below. Note that the only line of code that changes is the 16th. The results are consistant with 3.3.3 (when taking 𝑉 =cosh(6)≈202) 39 Figure 3: Covariances of the 𝑞quadrature on all 3 modes. Figure 4: Covariances of 𝑞1,𝑝2and 𝑞3 . 40 4 Conclusions CV-QKD is without doubt a strong alternative to the conventional discrete QKD, despite its relatively young age. We have seen that using standard telecommunication equipment such as photodiodes, beamsplitters and fibers is sufficient to implement a CVQKD protocol, a major advantage when compared to discrete QKD. We have reviewed the most known protocol based on coherent states and homodyne detection with Gaussian modulation, GG02, proven the equivalence of both scenarios (Prepare-and-Measure and Entanglement Based), numerically assessed some properties related to this equivalence, and reviewed two general attacks. Some experimental challenges remain, such as increasing the key rate and the communication distance. Among the current focus of research, new paradigms for security proofs such as composable security seek to establish security proofs that are more general. Although more effort is required to understand the security of CVQKD better, the existing proofs encompass a broad range of attack models. The Gaussian modulated protocol we reviewed has the property that its security against coherent attacks can only be proven asymptotically, whereas proofs of security against attacks are only possible if attacks are restricted to be collective, a weaker kind of attack. New directions focus on finite-size security. We mention the recent paper by Matsuura et al. [2021] that establish a provably secure finite-size CVQKD protocol. Another development in the continuous variable realm consist of cryptography primitives such as entanglement certification, where we mention the recent paper byAbiuso et al. [2021]. 41