6.3 Twin-Field QKD Without Phase Post-selection
89
entangled state (6.4). In doing so, we turn the protocol into a prepare-and-measure
scheme where Alice, upon choosing the X basis, prepares an optical pulse a in the
state:
|X b A a :=
√
q|0 a + (−1)
b A
1 − q|1 a ,
(6.12)
depending on the value of a bit b A , chosen at random. Instead, when Alice chooses
the Z basis, she prepares the pulse in the Fock state:
|Z b A a := |b A a
(6.13)
where the vacuum |0 a (b A = 0) is selected with probability q and the single-photon
state |1 a (b A = 1) is selected with probability 1 − q. Bob prepares his optical signal
in analogous states. The other steps of the protocol remain unchanged.
We remark that this prepare-and-measure scheme is equivalent to the
entanglement-based idealized protocol from the point of view of the security and
achieved key rate. However, it does not require the generation of entanglement
between a local qubit and an optical signal, which might be experimentally demanding. We now replace the states prepared in the current prepare-and-measure scheme
with more practical ones, while leaving all the other protocol steps unchanged. In
this way we come to the final TF-QKD protocol of [13], which is summed up in
Fig. 6.1.
The form of the states (6.12) prepared when the X basis is chosen, combined with
the fact that the optimal value for q is close to one, suggest much more practical states
to prepare an optical pulse in, namely coherent states |(−1)
b A α of low intensity |α|
2 .
Indeed, by recalling that a coherent state can be expressed as a superposition of Fock
states (5.1), one notices that the states in (6.12) can be well approximated by the
WCP:
X basis: |(−1)
b A α A ,
(6.14)
with an appropriate amplitude α A and where b A is a random bit. Bob prepares a
coherent state analogous to (6.14) whose amplitude α B can differ from Alice’s.
The Z -basis states (6.13) are Fock states of fixed photon number. Thus, the corresponding error rate E Z is linked to the probabilities that Alice and Bob send a
certain number of photons to the relay and the detection is successful. We have
seen (c.f. Sect. 5.2) that such probabilities can be estimated by using the decoy-state
method. Now, since the Z -basis rounds do not contribute to key generation, the states
prepared in these rounds have the only purpose of quantifying E Z . Therefore, we
can replace them with the more practical phase-randomized WCPs, and estimate
E Z with the decoy-state method. Thus, upon choosing the Z basis, Alice prepares a
phase-randomized WCP:
Z basis: ρ μ i =
∞
n=0
e
−μ i
μ
n
i
n!
|nn |,
(6.15)
89
entangled state (6.4). In doing so, we turn the protocol into a prepare-and-measure
scheme where Alice, upon choosing the X basis, prepares an optical pulse a in the
state:
|X b A a :=
√
q|0 a + (−1)
b A
1 − q|1 a ,
(6.12)
depending on the value of a bit b A , chosen at random. Instead, when Alice chooses
the Z basis, she prepares the pulse in the Fock state:
|Z b A a := |b A a
(6.13)
where the vacuum |0 a (b A = 0) is selected with probability q and the single-photon
state |1 a (b A = 1) is selected with probability 1 − q. Bob prepares his optical signal
in analogous states. The other steps of the protocol remain unchanged.
We remark that this prepare-and-measure scheme is equivalent to the
entanglement-based idealized protocol from the point of view of the security and
achieved key rate. However, it does not require the generation of entanglement
between a local qubit and an optical signal, which might be experimentally demanding. We now replace the states prepared in the current prepare-and-measure scheme
with more practical ones, while leaving all the other protocol steps unchanged. In
this way we come to the final TF-QKD protocol of [13], which is summed up in
Fig. 6.1.
The form of the states (6.12) prepared when the X basis is chosen, combined with
the fact that the optimal value for q is close to one, suggest much more practical states
to prepare an optical pulse in, namely coherent states |(−1)
b A α of low intensity |α|
2 .
Indeed, by recalling that a coherent state can be expressed as a superposition of Fock
states (5.1), one notices that the states in (6.12) can be well approximated by the
WCP:
X basis: |(−1)
b A α A ,
(6.14)
with an appropriate amplitude α A and where b A is a random bit. Bob prepares a
coherent state analogous to (6.14) whose amplitude α B can differ from Alice’s.
The Z -basis states (6.13) are Fock states of fixed photon number. Thus, the corresponding error rate E Z is linked to the probabilities that Alice and Bob send a
certain number of photons to the relay and the detection is successful. We have
seen (c.f. Sect. 5.2) that such probabilities can be estimated by using the decoy-state
method. Now, since the Z -basis rounds do not contribute to key generation, the states
prepared in these rounds have the only purpose of quantifying E Z . Therefore, we
can replace them with the more practical phase-randomized WCPs, and estimate
E Z with the decoy-state method. Thus, upon choosing the Z basis, Alice prepares a
phase-randomized WCP:
Z basis: ρ μ i =
∞
n=0
e
−μ i
μ
n
i
n!
|nn |,
(6.15)
