90
6 Beyond Point-to-Point Quantum Key Distribution
Alice
Untrusted relay
WCP
Amp-M
Bob
WCP
Amp-M
BS
D c
D d
Fig. 6.1 Schematic setup of the practical TF-QKD protocol introduced in [13]. In every round,
each party selects the X (Z ) basis with probability p X (1 − p X ). When selecting the X basis, Alice
(Bob) prepares a WCP whose phase encodes her (his) random key bit b A (b B ). When the Z basis
is selected, she (he) prepares a phase-randomized WCP to implement the decoy state method. Both
parties send their pulses to the central relay through channels of transmittance
√
η A for Alice and
√
η B for Bob. Here, the incoming pulses are combined into a 50:50 BS followed by two threshold
detectors at its output ports. The relay announces the results of the detection k c , k d . The parties
only keep those rounds in which they chose the same basis and k c ⊕ k d = 1, all the other rounds
are discarded. The bits b A and b B ⊕ k d form the parties’ raw keys
whose intensity μ i is randomly drawn from a set {μ i }. Analogously, Bob prepares a
phase-randomized WCP ρ ν i with intensity ν i randomly drawn from the set {ν i }. The
two sets of intensities can be different for Alice and Bob.
Remark 6.1 We stress the fact that the TF-QKD protocol of [13], instead of requiring a global phase post-selection like the original TF-QKD scheme [12], requires a
global phase pre-selection which fixes the phases of the coherent states in the X -basis
rounds. This can be achieved if the parties share a phase-reference that can also be
controlled by Eve. The feasibility of this solution has been experimentally proved
[18–20, 22]. Conversely, in the Z -basis rounds the phase-reference is not needed
as the parties prepare locally phase-randomized WCPs. This makes the TF-QKD
protocol of [13] quite robust against potential phase misalignments, since they only
affect the X -basis rounds.
6.3.3 Error Rates Estimation
When performing the practical TF-QKD protocol outlined above, the quantities that
Alice and Bob observe, after revealing their inputs in a fraction of the rounds, are
the gains p X X (k c , k d |b A , b B ) and p Z Z (k c , k d |μ i , ν j ). The former is the probability
that the relay announces the detection pattern k c , k d given that Alice (Bob) prepared
|(−1)
b A α A (|(−1)
b B α B ), while the latter is the probability that the relay announces
the detection pattern k c , k d given that Alice (Bob) prepared ρ μ i (ρ ν j ).
6 Beyond Point-to-Point Quantum Key Distribution
Alice
Untrusted relay
WCP
Amp-M
Bob
WCP
Amp-M
BS
D c
D d
Fig. 6.1 Schematic setup of the practical TF-QKD protocol introduced in [13]. In every round,
each party selects the X (Z ) basis with probability p X (1 − p X ). When selecting the X basis, Alice
(Bob) prepares a WCP whose phase encodes her (his) random key bit b A (b B ). When the Z basis
is selected, she (he) prepares a phase-randomized WCP to implement the decoy state method. Both
parties send their pulses to the central relay through channels of transmittance
√
η A for Alice and
√
η B for Bob. Here, the incoming pulses are combined into a 50:50 BS followed by two threshold
detectors at its output ports. The relay announces the results of the detection k c , k d . The parties
only keep those rounds in which they chose the same basis and k c ⊕ k d = 1, all the other rounds
are discarded. The bits b A and b B ⊕ k d form the parties’ raw keys
whose intensity μ i is randomly drawn from a set {μ i }. Analogously, Bob prepares a
phase-randomized WCP ρ ν i with intensity ν i randomly drawn from the set {ν i }. The
two sets of intensities can be different for Alice and Bob.
Remark 6.1 We stress the fact that the TF-QKD protocol of [13], instead of requiring a global phase post-selection like the original TF-QKD scheme [12], requires a
global phase pre-selection which fixes the phases of the coherent states in the X -basis
rounds. This can be achieved if the parties share a phase-reference that can also be
controlled by Eve. The feasibility of this solution has been experimentally proved
[18–20, 22]. Conversely, in the Z -basis rounds the phase-reference is not needed
as the parties prepare locally phase-randomized WCPs. This makes the TF-QKD
protocol of [13] quite robust against potential phase misalignments, since they only
affect the X -basis rounds.
6.3.3 Error Rates Estimation
When performing the practical TF-QKD protocol outlined above, the quantities that
Alice and Bob observe, after revealing their inputs in a fraction of the rounds, are
the gains p X X (k c , k d |b A , b B ) and p Z Z (k c , k d |μ i , ν j ). The former is the probability
that the relay announces the detection pattern k c , k d given that Alice (Bob) prepared
|(−1)
b A α A (|(−1)
b B α B ), while the latter is the probability that the relay announces
the detection pattern k c , k d given that Alice (Bob) prepared ρ μ i (ρ ν j ).
