6.3 Twin-Field QKD Without Phase Post-selection
87
3. The central relay applies a 50:50 beam splitter to the incoming pulses followed
by two threshold detectors D c and D d (i.e. unable to distinguish the detection of
one or more photons).
4. The relay broadcasts the outcomes k c and k d of detector D c and D d , where k c =
0 and k c = 1 (k d = 0 and k d = 1) correspond to a no-click and a click event,
respectively.
5. With probability p X Alice (Bob) measures her (his) qubit in the X basis given
by {|±± A(B) = (|0 A(B) ± |1 A(B) )/
√
2}, while with probability 1 − p X she (he)
measures the qubit in the Z basis. Upon obtaining the outcome x, where x = ±1
are the eigenvalues of the X and Z operators, Alice (Bob) records the bit value
b A (b B ) with (−1)
b A = x ((−1)
b B = x).
6. The bits b A and b B ⊕ k d , collected by Alice and Bob in the rounds where they
measured in the X basis and where the relay announced k c ⊕ k d = 1 (i.e. only one
detector clicked), form their raw keys. The bits collected in the Z -basis rounds
where k c ⊕ k d = 1 are instead used for PE. All the other rounds are discarded.
To understand why the protocol enables the parties to distil a secret key, imagine
that we choose 1 − q 1 in the state preparation. This means that both parties
prepare their signals strongly unbalanced towards the vacuum. For this reason, in the
relevant events where only one detector clicked, the detection is likely to be caused
by the sending and arrival of just one photon coming from either Alice or Bob.
However, the beam splitter creates a coherent superposition of these two possibilities,
implying that either Alice’s or Bob’s qubit are in state |1, but not both of them.
The conditional state of the parties’ qubits is thus well approximated by the Bell
states: |ψ k d 1 AB = (|01 + (−1)
k d |10)/
√
2 (k d = 0, 1). The parties then measure
their respective qubit in either the X or Z basis. From here, the protocol can be
regarded as an entanglement-based BB84 protocol whose security is proved Chap. 3.
Any deviation from the described picture can be detected by computing appropriate
error rates.
The states |ψ k d 1 prompt us to define the following error rates in the X and Z
basis:
E X = p X X [b A = b B ⊕ k d |k c ⊕ k d = 1]
(6.5)
E Z = p Z Z [b A = b B |k c ⊕ k d = 1],
(6.6)
where p X X [] ( p Z Z []) is the probability that the event occurred given that both
Alice and Bob measured in the X (Z ) basis. The two error rates are zero if the parties
share the Bell state |ψ 01 or |ψ 11 .
According to the above explanation, ideally the relevant detections are caused by
the sending and arrival of just one photon. This shows that the protocol is based on
single-photon interference events, thus producing a key rate that scales with
√ η (the
transmittance of one of the two channels) as the original TF-QKD scheme.
We can support this statement with more analytical grounds, by first computing
the conditional state of the parties’ qubits, given that only detector D c (k d = 0) or
only detector D d (k d = 1) clicked:
87
3. The central relay applies a 50:50 beam splitter to the incoming pulses followed
by two threshold detectors D c and D d (i.e. unable to distinguish the detection of
one or more photons).
4. The relay broadcasts the outcomes k c and k d of detector D c and D d , where k c =
0 and k c = 1 (k d = 0 and k d = 1) correspond to a no-click and a click event,
respectively.
5. With probability p X Alice (Bob) measures her (his) qubit in the X basis given
by {|±± A(B) = (|0 A(B) ± |1 A(B) )/
√
2}, while with probability 1 − p X she (he)
measures the qubit in the Z basis. Upon obtaining the outcome x, where x = ±1
are the eigenvalues of the X and Z operators, Alice (Bob) records the bit value
b A (b B ) with (−1)
b A = x ((−1)
b B = x).
6. The bits b A and b B ⊕ k d , collected by Alice and Bob in the rounds where they
measured in the X basis and where the relay announced k c ⊕ k d = 1 (i.e. only one
detector clicked), form their raw keys. The bits collected in the Z -basis rounds
where k c ⊕ k d = 1 are instead used for PE. All the other rounds are discarded.
To understand why the protocol enables the parties to distil a secret key, imagine
that we choose 1 − q 1 in the state preparation. This means that both parties
prepare their signals strongly unbalanced towards the vacuum. For this reason, in the
relevant events where only one detector clicked, the detection is likely to be caused
by the sending and arrival of just one photon coming from either Alice or Bob.
However, the beam splitter creates a coherent superposition of these two possibilities,
implying that either Alice’s or Bob’s qubit are in state |1, but not both of them.
The conditional state of the parties’ qubits is thus well approximated by the Bell
states: |ψ k d 1 AB = (|01 + (−1)
k d |10)/
√
2 (k d = 0, 1). The parties then measure
their respective qubit in either the X or Z basis. From here, the protocol can be
regarded as an entanglement-based BB84 protocol whose security is proved Chap. 3.
Any deviation from the described picture can be detected by computing appropriate
error rates.
The states |ψ k d 1 prompt us to define the following error rates in the X and Z
basis:
E X = p X X [b A = b B ⊕ k d |k c ⊕ k d = 1]
(6.5)
E Z = p Z Z [b A = b B |k c ⊕ k d = 1],
(6.6)
where p X X [] ( p Z Z []) is the probability that the event occurred given that both
Alice and Bob measured in the X (Z ) basis. The two error rates are zero if the parties
share the Bell state |ψ 01 or |ψ 11 .
According to the above explanation, ideally the relevant detections are caused by
the sending and arrival of just one photon. This shows that the protocol is based on
single-photon interference events, thus producing a key rate that scales with
√ η (the
transmittance of one of the two channels) as the original TF-QKD scheme.
We can support this statement with more analytical grounds, by first computing
the conditional state of the parties’ qubits, given that only detector D c (k d = 0) or
only detector D d (k d = 1) clicked:
