Methods of operating a continuous-variable, CV, quantum key distribution, QKD, reconciliation protocol, as well as corresponding apparatuses.
A two-step error correction protocol with short and long blocklength codes enhances CV-QKD reconciliation efficiency, achieving higher secret key rates and longer link distances with reduced complexity.
Patent Information
- Application Number
- PCT/NL2025/050295
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-06-19
- Filing Date
- 2025-06-17
- Publication Date
- 2025-12-26
AI Technical Summary
The reconciliation efficiency in continuous-variable quantum key distribution (CV-QKD) systems is limited by complex low-rate error correction codes with long blocklengths, leading to slow decoding and lower information throughput, which restricts the achievable secret key rates and link distances.
A two-step error correction protocol using a short blocklength low-rate code and a long blocklength high-rate code, combined with a multi-dimensional reconciliation demapper and mapper, to achieve secret key rates beyond the Devetak-Winter bound, allowing for reconciliation efficiencies above 1 and reduced decoding complexity.
The proposed method enables reconciliation efficiencies of 1.4, significantly improving secret key rates and link distances while maintaining low decoding complexity, surpassing the performance of conventional protocols.
Smart Images

Figure NL2025050295_26122025_PF_FP_ABST
Abstract
Description
[0001]Title Methods of operating a continuous-variable, CV, Quantum Key Distribution, QKD, reconciliation protocol, as well as corresponding apparatuses. Technical Field The present disclosure relates to the field of quantum information theory, specifically reconciliation protocols. Background Quantum information theory explores how information can be stored, transmitted, and processed using principles from quantum mechanics. It extends classical information theory to deal with quantum systems, where information is carried by quantum states rather than classical bits. Concerns about data security have been growing in the past couple of years with the advent of quantum computing, and as a result quantum key distribution (QKD) has turned into a widely researched topic. Powerful enough quantum computers could break existing cryptography protocols using Shor’s algorithm. QKD allows for the sharing of unconditionally secure keys between two communicating parties, Alice and Bob, without an eavesdropper Eve being able to recover the keys, even if Eve were to have access to a powerful quantum computer. In general, QKD is categorised into two different streams, discrete- variable (DV), and continuous-variable (CV) QKD. The main difference lies in the transmission over the quantum channel, where in DV-QKD single photons are transmitted, while for CV-QKD a significantly attenuated coherent signal is sent. The advantage of CV-QKD is that standard telecommunication components can be used for the implementation, allowing for a more cost-effective product which is easier to fit into the current telecommunication network. On the other hand, for DV-QKD expensive single photon detectors are required. Where DV outshines CV, however, is in the complexity of the post-processing. Where for DV-QKD the post-processing is relatively simple, for CV-QKD it is one of the main bottlenecks of the system. An essential part of the post-processing for CV-QKD is the reconciliation. Reconciliation protocols refer to techniques used to resolve discrepancies or errors between quantum states shared by different parties. The quantum states can become corrupted due to noise, imperfections in the transmission channel, or eavesdropping by a malicious party. Reconciliation protocols aim to correct these errors and ensure that the parties involved share the same information reliably and securely. These protocols typically involve comparing quantum states using quantum measurements and applying corrective operations based on the outcomes of these measurements. The goal of reconciliation is for Alice and Bob to exchange bits using the transmitted and measured quantum states in a secure manner. These bits will be used to distil the key during privacy amplification. Multi-dimensional reconciliation is a popular choice for reconciliation as it performs well for long-distance links, while for shorter distance links, slice reconciliation is the preferred option. Other reconciliation protocols have been disclosed as well, such as a rate-adaptive protocol, one involving multiple decoding attempts, and a protocol using 45 random codebooks. To ensure that Alice’s and Bob’s bit strings are the same, error correction needs to be performed during reconciliation. These error correction codes are the reason why the reconciliation is a bottleneck, as they are low-rate codes with long blocklengths in order to ensure a high reconciliation efficiency. Low-rate low-density parity-check (LDPC) codes were designed for reconciliation, Raptor codes have been studied, Polar codes have been studied and recently LDPC codes concatenated with Polar codes have been proposed. The decoding of these codes is rather slow, and the information throughput is significantly lower compared to the rest of the CV-QKD system, hence limiting the practically achievable key rates. The secure key rates of the communication are typically limited by the reconciliation efficiency, this is because the reconciliation protocols are complex as mentioned above. Typically, error correction codes are attempted to be optimized within the standard coding regime, e.g., below the Shannon capacity, using long block length codes, which introduces said complexity. As mentioned before, the reconciliation efficiency plays a big role in the performance of a CV-QKD system. The reconciliation efficiency is a measure of how close the error correction performance is to the Shannon capacity. It is defined as the rate of the code divided by the capacity of the channel, and is therefore bounded by 1 under normal circumstances, as it is not possible to transmit information at a higher rate than the Shannon capacity. Both the bounding of the reconciliation efficiency and the complexity of the low-rate codes with long blocklengths is a concern for fast information secret key sharing. Summary It would be advantageous to achieve a method of operating a reconciliation protocol, comprising a low rate short blocklength error correction code and a high rate long blocklength error correction code, such that the complexity of reconciliation error correction is reduced. It would be further advantageous if such a system is flexible, and further allowing for a longer link range. In the first aspect of the present disclosure, there is provided a method of operating a continuous-variable, CV, Quantum Key Distribution, QKD, reconciliation protocol, performed by a first location, comprising the steps of: a) providing, by a Multi-dimensional Reconciliation Demapper, MRD, a plurality log-likelihood ratios (l1…lK) based on a plurality of sequences of modulated symbols (m1…mK), received over a classical channel, and a plurality of sequences of symbols (x1...xK) to a Short Blocklength Decoder, SBD, at the first location; b) providing, by the SBD, a plurality of estimated information bits (ŝ1…ŝK) of an estimated codeword based on (l1…lK) to a Codeword Selection, CS, at the first location; c) providing, by the CS, a plurality of selected estimated information bits (ŝ^ௗ௫భ... ŝ^ௗ௫^∙ಲಷೃ) of the estimated codeword to a first LongBlocklength Decoder, LBD, at the first location, and providing a plurality of indices (idx1…idxK.AFR) corresponding to the selected estimated codewords to a Codeword Discarding, CD, at a second location, over the classical channel; d) providing, by the first LBD, a first concatenated sequence of bits by concatenating the plurality of selected estimated information bits (- ŝ^ௗ௫భ... ŝ^ௗ௫^∙ಲಷೃ) and providing a one-time pad encrypted syndrome pof the first concatenated sequence of bits to a second LBD, at the second location. In a second aspect of the present disclosure, there is provided a method of operating a continuous-variable, CV, Quantum Key Distribution, QKD, reconciliation protocol, performed by the second location, comprising the steps of: A) providing, by a Multi-dimensional Reconciliation Mapper, MRM, a plurality of sequences of modulated symbols (m1…mK) based on a plurality of codewords (c1…cK) and a plurality of sequences of noisy symbols (y1…yK) to the MRD at the first location, over the classical channel; B) providing, by a Short Blocklength Encoder, SBE, the plurality codewords (c1…cK) based on a plurality of sequences of bits (s1…sK); C) providing, by the CD, a plurality of selected sequences of bits (s^ௗ௫భ... ^^ௗ௫^∙ಲಷೃ) of the plurality of sequences of bits (s1…sK), basedon a plurality of indices of selected estimated sequences of bits, to the LBD; D) providing, by the second LBD, a second concatenated sequence of bits by concatenating the plurality of selected sequences of bits (s^ௗ௫భ... ^^ௗ௫^∙ಲಷೃ) and wherein the LBD providing a second syndrome,based on the second concatenated sequence of bits. E) Equalizing the second concatenated sequence of bits to the first concatenated sequence of bits using the syndrome p and the second syndrome; The ensuing sections are about the first and the second aspect of the present disclosure. The continuous-variable, CV, Quantum Key Distribution, QKD, reconciliation protocol may comprise a Multi-dimensional Reconciliation Demapper, MRD, at a first location and a Multi-dimensional Reconciliation Mapper, MRM, at a second location. Herein the MRM is arranged to provide plurality of sequence of modulated symbols, which is based on a codeword provided by a Short Blocklength Encoder, SBE, and it is based on a sequence of noisy symbols. These noisy symbols are created when sequences of symbols are transferred through a quantum communication channel, where noise is added to a sequence of symbols which is sent to the MRD directly at the first location. The present disclosure is directed to a reconciliation protocol involving the use of a two-step error correction protocol with a short blocklength low-rate code and a long blocklength high-rate code. By using this two-step decoding method, it is possible to achieve secret key rates beyond the Devetak-Winter bound. In an example, the plurality of sequences of symbols (x1…xK) is modulated using a plurality of sequences of random numbers (qi…qK) generated in a quantum number generator at the first location and wherein the plurality of sequences of bits (s1…sK) is generated in a quantum number generator at the second location. As mentioned, this plurality of sequences of symbols is transferred over a quantum channel and therefore noise is added, finally obtaining the plurality of sequences of noisy symbols (y1…yK). In an example, providing by the MRM of step A) comprises the steps of: - receiving the plurality of codewords (c1…cK) from the SBE and the plurality of sequences of noisy symbols (y1…yK) from the first location; - calculating the plurality of sequences of mapped symbols (m1…mK), using the plurality of codewords (c1…cK) and the plurality of sequences of noisy symbols (y1…yK) through a quantum channel; and - transmitting the plurality of sequences of mapped symbols (m1…mK) to the MRD of the first location through the classical channel. The MRM requires a plurality of codewords to be transmitted by the SBD, also at the second location. These codewords are typically of a short blocklength, therefore the rate of which these steps are performed may be at least relatively high. In another example of the present disclosure, the step of providing by the SBE of step B) comprises the steps of: - receiving the plurality of sequences of bits from the second location; - construing the plurality of codewords (c1…cK); - transmitting the plurality of codewords (c1…cK) to the MRM. A plurality of codewords is provided, by the SBE, to a MRM, wherein a mapping of the noisy sequence of bits and the plurality of codewords is performed and wherein the plurality of sequences of mapped symbols (m1…mK) are transmitted through a classical channel to the MRD at the first location. In a further example, the step of providing by the MRD of step a) comprises the steps of: - receiving the plurality of sequences of symbols (x1...xK) from the first location and the plurality of sequences of mapped symbols (m1…mK) from the second location; - calculating the plurality of log-likelihood ratios (l1…lK) using (x1...xK) and (m1…mK); - transmitting the plurality of log-likelihood ratios (l1…lK) to the SBD. The MRD uses the plurality of modulated sequences of symbols (m1…mK), which it has obtained / received from the MRM, located at the second location, over the classical channel and which it has subsequently de-mapped, and plurality of sequences of symbols (x1...xK) to calculate a plurality of log-likelihood ratios, LLRs, (l1…lK). Further, the LLRs are sent to the SBD, which decodes the plurality of LLRs to get an estimate of the codewords (ĉ1… ĉk). The codewords are construed with a sequence of estimated information bits. In yet another example, the step of providing by the SBD of step b) comprises the steps of: - receiving the plurality of log-likelihood ratios (l1…lK); - construing a plurality of estimated information bits using (l1…lK); and - transmitting the plurality of estimated information bits (ŝ1…ŝK) to the CS. The estimate of the codewords may be checked in order to verify whether the obtained codewords are the same as the codeword constructed by the SBE. This is done by utilizing a first long blocklength high-rate decoder, LBD. This first LBD concatenates a selection of the sequences of bits. To minimize large errors, a plurality of sequences of bits are selected by the Codeword Selection, CS. In yet another example, the step of providing by the CS of step c) comprises the steps of: - receiving the plurality of estimated information bits (ŝ1…ŝK) from the SBD; - selecting plurality of estimated information bits (ŝ1…ŝK) based on the plurality of SBD soft information output; and - transmitting the plurality of indices (idx1…idxK.AFR) of the plurality ofselected estimated information bits (ŝ^ௗ௫భ... ŝ^ௗ௫^∙ಲಷೃ) to the CD at the second locationand the plurality of selected estimated information bits (ŝ^ௗ௫భ... ŝ^ௗ௫^∙ಲಷೃ) to the first LBD.The CS selects a plurality of the estimated sequences of bits. This depends on the certainty q of the correctness of the codeword. The certainty q is calculated by using the output of the SBD. The higher q is, the more certain the decoder is about the correctness of the decoded codeword. After sorting the codewords based on q, only a fraction of the codewords with the highest q are selected. This fraction is the accepted frame rate, AFR, which is equivalent to 1- FER, where FER is the frame error rate. The cut-off value qcfor which to accept or reject decoded codewords to obtain a given AFR may be determined through simulations. Then, all decoded codewords for which ^ ≤ ^care accepted / selected, while the others are discarded. The indices of the selected estimated sequences of bits are sent / transmitted to the second location over the classical channel to the CD. It is noted that all codewords are independent from each other. By rejecting most frames, it is possible to increase the distance of CV- QKD links by operating at reconciliation efficiencies above 1, while having less decoding complexity compared to the state-of-the-ar. Further, the plurality of selected estimated information bits are sent to the first LBD. In another example, the step of providing by the first LBD of step d) comprises the steps of: - receiving the plurality of selected estimated information bits(ŝ^ௗ௫భ... ŝ^ௗ௫^∙ಲಷೃ) from the CS;- construing the first concatenated sequence of bits, chr, byconcatenating the plurality of selected estimated information bits calculating the syndrome p of the LBE codeword using theconcatenated selected estimated information bits ൫ŝ^ௗ௫భ … ŝ^ௗ௫^∙ಲಷೃ൯ and a parity checkmatrix Hhr; and - transmitting a one-time pad encrypted syndrome of the first concatenated sequence of bits to the LBD The accepted frames are not necessarily decoded correctly. Therefore, a correction of the residual bit errors which are still in the accepted information bits is needed. To achieve this, a first LBD concatenates all the selected estimated information bits to create one long string of bits chr. Herein, the syndrome of this codeword is calculated using the parity check matrix Hhrof the high-rate code of the first LBD. A one-time padded version of this syndrome pA is sent to a second LBD. At the second location, first the CD is performed, wherein sequences of bits with indices not equal to the indices obtained from the first location are discarded. In yet another example, the step of providing by the CD of step C) comprises the steps of: - receiving the plurality of indices of the plurality of selected estimated information bits (idx1…idxK.AFR) from the first location over the classical channel and receiving the plurality of sequences of bits (s1…sK) from the second location; - discarding any of the sequence of bits (s1…sK) with an index not equal to any of the received plurality of indices of the plurality of selected estimated information bits (idx1…idxK.AFR); and -transmitting the plurality of selected sequences of bits (s^ௗ௫భ... ^^ௗ௫^∙ಲಷೃ)to the LBD. As mentioned before, in the CD a process controlled by the CS is performed, which mirrors the process at the CS, though now the sequence of bits directly generated in a quantum number generated at the second location are selected. As said, the indices not equal to the indices obtained from the first location are discarded. In a further example, the step of providing by the second LBD of step D) comprises the steps of:- receiving the plurality of selected sequence of bits ൫s^ௗ௫భ... ^^ௗ௫^∙ಲಷೃ൯from the CD at the second location and receiving the one-time pad encrypted syndrome from the first location over the classical channel; - recovering the syndrome p from the one-time pad encrypted syndrome and a shared secret key; - construing the second concatenated sequence of bits and calculating a second syndrome based on the second concatenated sequence of bits. - equalizing the second concatenated sequence of bits with the first concatenated sequence of bits by using the syndrome p and the second syndrome. The remaining selected sequences of bits are sent to the second LBD. At the second LBD, the selected sequences of bits are also concatenated to create c′hr. Here, also the syndrome of this bit string is calculated, after which an xor operation is performed with the obtained one time pad syndrome. The result indicates the bit difference between the two sequences of bits. By decoding this syndrome, it is possible for the second DPB to obtain ê, which is an estimate of e. Here the estimate of e is applied it c’hrto get ĉhr, which is an estimate of chr. Herein, the concatenated sequences of bits are at least equalized, as the errors are reduced. Using the syndrome obtained from the first location and the second syndrome to perform error correction on the second concatenated sequence of bits to remove any bitflips between the first and second concatenated sequence. The magnitude of the error may be chosen as the FER of the second step is chosen to be very low (FER < 10-9), such that the first location and the second location are at least significantly sure that the (concatenated) bit strings are the same. Therefore, an additional hashing step to confirm the correctness of the decoding is not necessary but could optionally be done. Using the method of operating the proposed protocol, a reconciliation efficiency of 1.4 can be achieved. A protocol in accordance with the prior art would result in a reconciliation efficiency of 1.09. This last result is obtained while using a low AFR of 0.0001, which is typically not practical for a CV-QVD system. This may be because when the AFR is low, almost all frames are discarded, meaning that only the most certain frames are considered, this highly decreases the secret key rate, SKR. The SKR, which is a measure that may be of importance for the performance of the reconciliation, representing the rate at which secret keys can be exchanged. The SKR is influenced by the error correction, namely by the rate of the code and its FER. The SKR of the present disclosure can be calculated by 1where, - AFR is the accepted frame rate; - FERଶis the frame error rate of the second LBD ; - is the reconciliation efficiency of the first decoding step ; - βଶis the reconciliation efficiency of the second decoding step ; - h is the binary entropy function; - BER^^is the bit error rate of the accepted frames; - I^^is the mutual information between the first location and the second location; - χ^^is the Holevo information; - Δa is the leakage caused by revealing which codewords are accepted when β1> 1 In an example, the AFR may be freely chosen, wherein the AFR is the fraction of selected information sequences of bits to the total information bits in the CS or CD. In an example, the total reconciliation efficiency, β௧^௧, can take values below 1, but can be larger than 1 as well. It is given by β௧^௧ = β^βଶ(1 − h(BER^^))In a third aspect of the present disclosure, there is provided an apparatus, at the first location, arranged for performed the method according to the present disclosure. In a fourth aspect of the present disclosure, there is provided an apparatus, at the second location, arranged for performed the method according to the present disclosure. In accordance with the present disclosure, the apparatus may be a quantum computer, quantum-based communication device, a user equipment, or anything alike. In a fifth aspect of the present disclosure, there is provided a computer program product comprising a computer readable medium having instructions stored thereon which, when executed by an apparatus, cause said apparatus to implement a method in accordance with any of the examples provided above. It is noted that the advantages as explained with reference to the first and second aspect of the present disclosure are also applicable to the third and fourth aspect of the present disclosure. The present disclosure is described in conjunction with the appended figures. It is emphasized that, in accordance with the standard practice in the industry, various features are not drawn to scale. In fact, the dimensions of the various features may be arbitrarily increased or reduced for clarity of discussion. In the appended figures, similar components and / or features may have the same reference label. Further, various components of the same type may be distinguished by following the reference label by a dash and a second label that distinguishes among the similar components. If only the first reference label is used in the specification, the description is applicable to any one of the similar components having the same first reference label irrespective of the second reference label. The above and other aspects of the disclosure will be apparent from and elucidated with reference to the examples described hereinafter. Brief description of the figures Fig.1 depicts a reconciliation protocol according to the prior art Fig. 2 depicts a reconciliation protocol according to the present disclosure Fig. 3 depicts an overview of a CV-QKD system with the reconciliation protocol according to the present disclosure. Detailed description It is noted that in the description of the figures, same reference numerals refer to the same of similar components performing a same of essentially similar function. A more detailed description is made with reference to particular examples, some of which are illustrated in the appended drawings, such that the features of the present disclosure may be understood in more detail. It is noted that the drawings only illustrate typical examples and are therefore not to be considered to limit the scope of the subject matter of the claims. The drawings are incorporated for facilitating an understanding of the disclosure and are thus not necessarily drawn to scale. Advantages of the subject matter as claimed will become apparent to those skilled in the art upon reading the description in conjunction with the accompanying drawings. The ensuing description above provides preferred exemplary embodiment(s) only, and is not intended to limit the scope, applicability, or configuration of the disclosure. Rather, the ensuing description of the preferred exemplary embodiment(s) will provide those skilled in the art with an enabling description for implementing a preferred exemplary embodiment of the disclosure, it being understood that various changes may be made in the function and arrangement of elements, including combinations of features from different embodiments, without departing from the scope of the disclosure. Unless the context clearly requires otherwise, throughout the description and the claims, the words "comprise," "comprising," and the like are to be construed in an inclusive sense, as opposed to an exclusive or exhaustive sense; that is to say, in the sense of "including, but not limited to." As used herein, the terms "connected," "coupled," or any variant thereof means any connection or coupling, either direct or indirect, between two or more elements; the coupling or connection between the elements can be physical, logical, electromagnetic, or a combination thereof. Additionally, the words "herein," "above," "below," and words of similar import, when used in this application, refer to this application as a whole and not to any particular portions of this application. Where the context permits, words in the Detailed Description using the singular or plural number may also include the plural or singular number respectively. The word "or" in reference to a list of two or more items, covers all the following interpretations of the word: any of the items in the list, all of the items in the list, and any combination of the items in the list. These and other changes can be made to the technology considering the following detailed description. While the description describes certain examples of the technology, and describes the best mode contemplated, no matter how detailed the description appears, the technology can be practiced in many ways. Details of the system may vary considerably in its specific implementation, while still being encompassed by the technology disclosed herein. In figure 1, the quantum key distribution, QKD, protocol is depicted, which describes a method of sharing secret keys between a first channel and a second channel securely. Specifically, a continuous variable, CV-QKD is depicted. Quantum states may be prepared by the first location 10, which may be called Alice 10, which transmits these quantum states, through a quantum channel, to the second location 11, which may be called Bob 11. During the transmission of the quantum states through the quantum channel, noise may be added to the quantum states. Bob may then receive quantum states with added noise. These quantum states will be used for the secure transmission of a sequence of bits over the quantum channel, and the added noise will create a noisy sequence of bits. A reconciliation protocol is designed to ensure the accurate transmission of quantum states over noisy channels. The sequence of bits and the noisy sequence of bits are received by a demapper 102 and a mapper 101 respectively. The mapper 101 uses a function to create a sequence of mapped symbols, which it transmits to the demapper 102 over the classical channel. The demapper 102 uses the sequence of bits and the sequence of mapped symbols and sends it to a LLR calculation 104, which calculates a log- likelihood ratio which it sends to a decoder 106. On the other side, the mapper 101 uses a codeword supplied by an encoder 103 to use in the function to create a sequence of modulated symbols. The encoder 103 needs a random sequence of bits supplied by a quantum random number generator 105. This random sequence of bits is also used by Bob 11 for hashing later. The decoder 106, which is used by Alice 10, constructs an estimated codeword from the log-likelihood ratio. This estimated codeword is checked at a codeword check 108 whether the syndrome of this estimated codeword is zero or non- zero. If it is non-zero then the parity bits of the estimated codewords are discarded 112. If it is zero, then this new codeword is hashed 110 and transmitted to Bob 11 . Bob 11 hashes 110 the random sequence of bits and compares the hashed new codeword sent by Alice with the hash 109 of the random sequence of bits. If they are the same then Alice is notified and she will keep her new codeword 114. Bob is notified if the syndrome at Alice is non-zero, if so, he will perform a frame error discarding 111. In Figure 2, the reconciliation protocol according to the present disclosure is depicted. In the reconciliation protocol, a first reconciliation protocol 200 is performed at least once using a short blocklength low rate code. This first reconciliation protocol 200 comprises a Short Blocklength Encoder, SBE, together with a Multi-dimensional Reconciliation Mapper, MRM, in 201, which is used by Bob 10. The first reconciliation protocol 200 further comprises a Short Blocklength Decoder, SBD, together with a Multi-dimensional Reconciliation Demapper, MRD in 202 which is used by Alice 11. The MRM maps noisy sequences of symbols with a codeword, creating a modulated sequence of symbols and the MRD tries to demap the modulated sequence of symbols. Output from 202 is estimated information bits and log likelihood ratios, LLRs, of the estimated information bits. Further, the reconciliation protocol comprises a selection and discarding of frames, wherein the selection is performed by Alice at a Codeword Selection, CS, 204, while the discarding is performed by Bob at a Codeword Discarding, CD, 203. Note that the names may be deceiving, but at the CS 204, a selection of the estimated information bits is performed, using the LLRs, after which the unused sequences are discarded. At the CD 203 the indices of the selected estimated information bits are used to discard any of the sequences of bits that is not equal to any of the received indices. The selected frames then are processed by a long blocklength high rate code. At a first Long Blocklength Decoder, LBD, 206 the selected estimated information bits are concatenated to create a codeword, of this codeword a syndrome p is calculated which is transmitted as a one-time pad encrypted syndrome to a second LBD 205. At the second LBD 205, a second syndrome is calculated from concatenated selected sequence of bits. The syndrome p is recovered from the one-time pad encrypted syndrome, after which an equalizing of the second concatenated sequence of bits with the first concatenated sequence of bits by using the syndrome p and the second syndrome is done. In Figure 3 the reconciliation protocol depicted in Figure 2 is integrated in a CV-QKD, herein the MRM 201 and MRD 202 are separated from the SBE 207 and SBD 208 to clarify their independence. Further, a quantum channel is depicted, wherein noise 303 is added to the sequence of symbols 302, thereby obtaining noisy sequence of symbols 304 which are received by a Coherent Quantum Receiver 213 and fed through a Parameter Estimation 214 to the MRM 201. The MRM further obtains codewords 307 from the SBE 207, which are based on a sequence of bits 309 generated by a quantum random number generator 210. The sequence of symbols is obtained first from generating a sequence of random numbers 301 by a quantum random number generator 210, then the sequence of random numbers 301 is given in a modulation format, thereby obtaining the sequence of symbols 302. This sequence of symbols is sent to the MRD, which calculates a LLR 306, which is used by the SBD 208 to obtain a estimated information bits 308. Then at the CS, a selection of the estimated information bits is performed, obtaining the selected estimated information bits 312. The indices of the selected estimated information bits 310 are transmitted over the classical channel to the CD 203. At the CD 203 the indices of the selected estimated information bits 310 are used to discard any of the sequences of bits 309, obtained from a quantum random number generator 210 that is not equal to any of the received indices 310, thereby obtaining selected sequence of bits 311. These are sent to the second LBD 205. The CS 204 sends the selected estimated information bits 312 to the first LBD 206. At the first LBD 206 the selected estimated information bits are concatenated to create a codeword, of this codeword a syndrome p 312 is calculated which is transmitted as a one-time pad encrypted syndrome 312 to a second LBD 205. At the second LBD a second syndrome is calculated from concatenated selected sequence of bits. The syndrome p is recovered from the one-time pad encrypted syndrome, after which an equalizing of the second concatenated sequence of bits 313 with the first concatenated sequence of bits 314 by using the syndrome p 312 and the second syndrome is done. As noted above, particular terminology used when describing certain features or aspects of the technology should not be taken to imply that the terminology is being redefined herein to be restricted to any specific characteristics, features, or aspects of the technology with which that terminology is associated. In general, the terms used in the following claims should not be construed to limit the technology to the specific examples disclosed in the specification, unless the Detailed Description section explicitly defines such terms. Accordingly, the actual scope of the technology encompasses not only the disclosed examples, but also all equivalent ways of practicing or implementing the technology under the claims.
Claims
CLAIMS 1. A method of operating a continuous-variable, CV, Quantum Key Distribution, QKD, reconciliation protocol, performed at a first location, comprising the steps of: a) providing, by a Multi-dimensional Reconciliation Demapper, MRD, a plurality log-likelihood ratios (l1…lK) based on a plurality of sequences of modulated symbols (m1…mK), received over a classical channel, and a plurality of sequences of symbols (x1...xK) to a Short Blocklength Decoder, SBD, at the first location; b) providing, by the SBD, a plurality of estimated information bits (ŝ1…ŝK) of an estimated codeword based on (l1…lK) to a Codeword Selection, CS, at the first location; c) providing, by the CS, a plurality of selected estimated information bits (ŝ^ௗ௫భ... ŝ^ௗ௫^∙ಲಷೃ) of the estimated codeword to a first LongBlocklength Decoder, LBD, at the first location, and providing a plurality of indices (idx1…idxK.AFR) corresponding to the selected estimated codewords to a Codeword Discarding, CD, at a second location, over the classical channel; d) providing, by the first LBD, a first concatenated sequence of bits by concatenating the plurality of selected estimated information bits (- ŝ^ௗ௫భ... ŝ^ௗ௫^∙ಲಷೃ) and providing a one-time pad encrypted syndrome pof the first concatenated sequence of bits to a second LBD, at the second location.
2. A method of operating a continuous-variable, CV, Quantum Key Distribution, QKD, reconciliation protocol, performed by the second location, comprising the steps of: A) providing, by a Multi-dimensional Reconciliation Mapper, MRM, a plurality of sequences of modulated symbols (m1…mK) based on a plurality of codewords (c1…cK) and a plurality of sequences of noisy symbols (y1…yK) to the MRD at the first location, over the classical channel;B) providing, by a Short Blocklength Encoder, SBE, the plurality codewords (c1…cK) based on a plurality of sequences of bits (s1…sK); C) providing, by the CD, a plurality of selected sequences of bits (s^ௗ௫భ... ^^ௗ௫^∙ಲಷೃ) of the plurality of sequences of bits (s1…sK), basedon a plurality of indices of selected estimated sequences of bits, to the LBD; D) providing, by the second LBD, a second concatenated sequence of bits by concatenating the plurality of selected sequences of bits (s^ௗ௫భ... ^^ௗ௫^∙ಲಷೃ) and wherein the LBD providing a second syndrome,based on the second concatenated sequence of bits. E) Equalizing the second concatenated sequence of bits to the first concatenated sequence of bits using the syndrome p and the second syndrome; 3. The method of operating a CV-QKD reconciliation protocol according to claim 1, wherein the providing by the MRD of step a) comprises the steps of: - receiving the plurality of sequences of symbols (x1...xK) from the first location and the plurality of sequences of mapped symbols (m1…mK) from the second location; - calculating the plurality of log-likelihood ratios (l1…lK) using (x1...xK) and (m1…mK); - transmitting the plurality of log-likelihood ratios (l1…lK) to the SBD.
4. The method of operating a CV-QKD reconciliation protocol according to any of the claim 1 and 3, wherein the providing by the SBD of step b) comprises the steps of: - receiving the plurality of log-likelihood ratios (l1…lK); - construing a plurality of estimated information bits using (l1…lK); and - transmitting the plurality of estimated information bits (ŝ1…ŝK) to the CS.
5. The method of operating a CV-QKD reconciliation protocol according to any of the claim 1 and 3-4 , wherein the providing by the CS of step c) comprises the steps of: - receiving the plurality of estimated information bits (ŝ1…ŝK) from the SBD; - selecting plurality of estimated information bits (ŝ1…ŝK) based on the plurality of log-likelihood ratios; and - transmitting the plurality of indices (idx1…idxK.AFR) of the plurality ofselected estimated information bits (ŝ^ௗ௫భ... ŝ^ௗ௫^∙ಲಷೃ) to the CD at the second locationand the plurality of selected estimated information bits (ŝ^ௗ௫భ... ŝ^ௗ௫^∙ಲಷೃ) to the first LBD.
6. The method of operating a CV-QKD reconciliation protocol according to any of the claim 1 and 3-5, wherein the providing by the first LBD of step d) comprises the steps of: - receiving the plurality of selected estimated information bits(ŝ^ௗ௫భ... ŝ^ௗ௫^∙ಲಷೃ) from the CS;- construing the first concatenated sequence of bits, chr, byconcatenating the plurality of selected estimated information bits ൫ŝ^ௗ௫భ … ŝ^ௗ௫^∙ಲಷೃ൯, andcalculating the syndrome p of the LBE codeword using theconcatenated selected estimated information bits ൫ŝ^ௗ௫భ … ŝ^ௗ௫^∙ಲಷೃ൯ and a parity checkmatrix Hhr; and - transmitting a one-time pad encrypted syndrome of the first concatenated sequence of bits to the LBD.
7. The method of operating a CV-QKD reconciliation protocol according to claim 2, wherein the providing by the MRM of step A) comprises the steps of: - receiving the plurality of codewords (c1…cK) from the SBE and the plurality of sequences of noisy symbols (y1…yK) from the first location through a quantum channel; - calculating the plurality of sequences of mapped symbols (m1…mK), using the plurality of codewords (c1…cK) and the plurality of sequences of noisy symbols (y1…yK); and- transmitting the plurality of sequences of mapped symbols (m1…mK) to the MRD of the first location through the classical channel.
8. The method of operating a CV-QKD reconciliation protocol according to any of the claims 2 and 7, wherein the providing by the SBE of step B) comprises the steps of: - receiving the plurality of sequences of bits from the second location; - construing the plurality of codewords (c1…cK); - transmitting the plurality of codewords (c1…cK) to the MRM.
9. The method of operating a CV-QKD reconciliation protocol according to any of the claims 2 and 7-8, wherein the providing by the CD of step C) comprises the steps of: - receiving the plurality of indices of the plurality of selected estimated information bits (idx1…idxK.AFR) from the first location over the classical channel and receiving the plurality of sequences of bits (s1…sK) from the second location; - discarding any of the sequence of bits (s1…sK) with an index not equal to any of the received plurality of indices of the plurality of selected estimated information bits (idx1…idxK.AFR); and -transmitting the plurality of selected sequences of bits (s^ௗ௫భ... ^^ௗ௫^∙ಲಷೃ)to the LBD.
10. The method of operating a CV-QKD reconciliation protocol according to any of the claims 2 and 7-9, wherein the providing by the second LBD of step D) comprises the steps of: -receiving the plurality of selected sequence of bits ൫s^ௗ௫భ... ^^ௗ௫^∙ಲಷೃ൯from the second location and receiving the one-time pad encrypted syndrome of from the first location over the classical channel; - recovering the syndrome p from the one-time pad encrypted syndrome and a shared secret key; - construing the second concatenated sequence of bits and calculating a second syndrome based on the second concatenated sequence of bits.- equalizing the second concatenated sequence of bits with the first concatenated sequence of bits by using the syndrome p and the second syndrome.
11. The method of operating a CV-QKD reconciliation protocol according to any of the previous claims, wherein the plurality of sequences of symbols (x1…xK) is modulated using a plurality of sequences of random numbers (qi…qK) generated in a quantum number generator at the first location and wherein the plurality of sequences of bits (s1…sK) is generated in a quantum number generator at the second location.
12. The method of operating a CV-QKD reconciliation protocol according to any of the previous claims, wherein the secret key ratio, SKR, of the CV-QKD reconciliation protocol is: SKR = AFR ⋅ (1 − FERଶ) ⋅ (β^βଶ(1 − h(BER^^)) ⋅ I^^ − χ^^), if β^ ≤ 1SKR = AFR ⋅ (1 − FERଶ) ⋅ (β^βଶ(1 − h(BER^^)) ⋅ I^^ − χ^^ − Δa), if β^ >1 where, - AFR is the accepted frame rate; - FERଶis the frame error rate of the LBD ; - β^is the reconciliation efficiency of the first decoding step ; - βଶis the reconciliation efficiency of the second decoding step ; - h is the binary entropy function; - BER^^is the bit error rate of the accepted frames; - I^^is the mutual information between the first location and the second location; - χ^^is the Holevo information - Δa is the leakage caused by revealing which codewords are accepted when β1> 1.
13. The method of operating a CV-QKD reconciliation protocol according to claim 12, wherein AFR may be freely chosen, wherein the AFR is the fraction of selected information sequences of bits to the total information bits in the CS or CD.
14. The method of operating a CV-QKD reconciliation protocol according to any of the claims 12-13, wherein the total reconciliation efficiency, β௧^௧, is given as, β௧^௧ = β^βଶ(1 − h(BER^^))15. Apparatus, at the first location, arranged for performed the method according to claim 1.
16. Apparatus, at the second location, arranged for performed the method according to claim 2.
17. A computer program product comprising a computer readable medium having instruction stored there which, when executed by an apparatus, cause said apparatus to implement a method in accordance with any of the claims 1 – 2.
Citation Information
Patent Citations
High throughput communication system
US20180323914A1
Systems and Methods for Communicating Using Short Messages
US20240154721A1