6.2 Twin-Field QKD: Original Protocol
85
6.2 Twin-Field QKD: Original Protocol
In 2018, Lucamarini et al. [12] proposed a new QKD scheme which is based on the
same working principle of MDI-QKD: a central untrusted relay measures the pulses
sent by Alice and Bob. The measurement outcome reveals the parity of Alice and
Bob’s bits, but not their values. However, opposed to MDI-QKD, it is based on singlephoton interference events. Thanks to this feature, it naturally retains the square-root
improvement in the key rate scaling since the successful events are exactly those
where only one photon arrived, sent either from Alice or Bob. This removes the
necessity of sophisticated systems to adapt the Bell-state measurements to photon
losses.
The protocol in [12] takes the name of twin-field (TF) QKD and its original
formulation goes as follows. Alice (Bob) generates phase-randomized WCPs by
picking a random phase value ρ a (ρ b ) in the interval [0, 2π). The phase interval is
split into M phase slices k = 2π k/M (k = 0, . . . , M − 1) and the selected random
phase necessarily falls into one of them: k(a) ( k(b) ). Alice (Bob) then encodes a
secret bit and a secret basis in another phase ϕ a (ϕ b ) which is added to the phase
of the pulse. The pulses are then sent to a central station where they are combined
in a 50:50 beam splitter with single-photon detectors at its output ports. After the
detection outcome is announced, the parties publicly reveal the slices k(a) , , k(b)
and the encoded bases, and keep only the rounds with matching values. Indeed, the
optical fields whose random phase falls in the same slice are “twins” and can be
used to generate a secret key. The detection outcome combined with the revealed
information indicate to Bob whether he needs to flip his bit or not, in order to match
it with Alice’s.
Since the first TF-QKD protocol has been published, an intense research activity
led to several variants of the original scheme [13–17] and to many experimental
demonstrations [18–22]. In particular, experimentalists managed to obtain secret key
rates surpassing the limit imposed by the PLOB bound, thus proving the improved
scaling of TF-QKD.
In the following, we are going to focus on the TF-QKD protocol proposed by
Curty et al. [13], which is simpler and arguably better-performing than many other
TF-QKD variants. Before moving on, we briefly mention a couple of drawbacks of
the original TF scheme in [12].
Firstly, the random phases of a pair of twin fields are not identical and differ by
less than 2π/M. This induces an intrinsic QBER that tends to zero for M → ∞.
However, the probability of having matching slices scales as 1/M, thus increasing
M leads to more discarded rounds. There exists an optimal value for M that can be
determined by appropriately modelling the experimental setup and optimizing the
key rate. The authors in [12] obtained an optimal value of M opt = 16. In any case,
the use of locally randomized phases by Alice and Bob and the post-selection of the
matching ones causes a consistent amount of rounds to be discarded.
85
6.2 Twin-Field QKD: Original Protocol
In 2018, Lucamarini et al. [12] proposed a new QKD scheme which is based on the
same working principle of MDI-QKD: a central untrusted relay measures the pulses
sent by Alice and Bob. The measurement outcome reveals the parity of Alice and
Bob’s bits, but not their values. However, opposed to MDI-QKD, it is based on singlephoton interference events. Thanks to this feature, it naturally retains the square-root
improvement in the key rate scaling since the successful events are exactly those
where only one photon arrived, sent either from Alice or Bob. This removes the
necessity of sophisticated systems to adapt the Bell-state measurements to photon
losses.
The protocol in [12] takes the name of twin-field (TF) QKD and its original
formulation goes as follows. Alice (Bob) generates phase-randomized WCPs by
picking a random phase value ρ a (ρ b ) in the interval [0, 2π). The phase interval is
split into M phase slices k = 2π k/M (k = 0, . . . , M − 1) and the selected random
phase necessarily falls into one of them: k(a) ( k(b) ). Alice (Bob) then encodes a
secret bit and a secret basis in another phase ϕ a (ϕ b ) which is added to the phase
of the pulse. The pulses are then sent to a central station where they are combined
in a 50:50 beam splitter with single-photon detectors at its output ports. After the
detection outcome is announced, the parties publicly reveal the slices k(a) , , k(b)
and the encoded bases, and keep only the rounds with matching values. Indeed, the
optical fields whose random phase falls in the same slice are “twins” and can be
used to generate a secret key. The detection outcome combined with the revealed
information indicate to Bob whether he needs to flip his bit or not, in order to match
it with Alice’s.
Since the first TF-QKD protocol has been published, an intense research activity
led to several variants of the original scheme [13–17] and to many experimental
demonstrations [18–22]. In particular, experimentalists managed to obtain secret key
rates surpassing the limit imposed by the PLOB bound, thus proving the improved
scaling of TF-QKD.
In the following, we are going to focus on the TF-QKD protocol proposed by
Curty et al. [13], which is simpler and arguably better-performing than many other
TF-QKD variants. Before moving on, we briefly mention a couple of drawbacks of
the original TF scheme in [12].
Firstly, the random phases of a pair of twin fields are not identical and differ by
less than 2π/M. This induces an intrinsic QBER that tends to zero for M → ∞.
However, the probability of having matching slices scales as 1/M, thus increasing
M leads to more discarded rounds. There exists an optimal value for M that can be
determined by appropriately modelling the experimental setup and optimizing the
key rate. The authors in [12] obtained an optimal value of M opt = 16. In any case,
the use of locally randomized phases by Alice and Bob and the post-selection of the
matching ones causes a consistent amount of rounds to be discarded.
