Device description and operating principle

A conceptual device layout is shown in Fig. 1a. It consists of two main stages, arranged in a cascaded configuration. The first stage is a high-speed balanced Mach-Zehnder modulator (MZM), realized by long and efficient EO phase modulators included in each arm of the interferometer, and exhibiting a broad modulation bandwidth (3-dB bandwidth exceeding 30 GHz; see Fig. 2b). It also includes two thermal phase shifters (TPS), one on each arm of the interferometer, to control the bias operating point while ensuring optical symmetry and extended phase tuning range. The second stage is an unbalanced Mach-Zehnder interferometer (MZI), where the relative temporal path delay is set to 100 ps, obtained by a geometrical path unbalance of 1.31 cm. It includes a broadband EO phase modulator and a TPS, both placed in the longer arm of the interferometer, while the shorter arm incorporates a 2% power-splitter monitor. This component allows for bias monitoring of the MZM and serves to partially compensate for the propagation loss in the longer arm.

Fig. 1: Conceptual schematicFig. 1: Conceptual schematicThe alternative text for this image may have been generated using AI.

a Schematic of the integrated optical circuit. The evolution of the input photon state is illustrated for the three configurations: (i) the first-stage MZM is biased at quadrature with no RF modulation; (ii) the MZM is driven such that early (late) time-bin photons are routed into the longer (shorter) path of the unbalanced MZI; (iii) the RF modulation is inverted, routing early (late) photons into the shorter (longer) path. b The integrated quantum receiver can implement an arbitrary time-bin state projector. When operated in configuration a.ii, it projects into the equator of the Bloch sphere (blue); when operated in a.iii, it projects into the poles of the Bloch sphere

Fig. 2: Fabricated deviceFig. 2: Fabricated deviceThe alternative text for this image may have been generated using AI.

a Simulated transverse component (parallel to the extraordinary optical axis) of the RF and optical electric field in the MZM cross-section. 1: Metal electrodes, 2: Lithium niobate, 3: Silica. b Measured EO response of the balanced MZM stage and of the c unbalanced MZI stage. d Image of the realized integrated photonic circuit with e final packaging. FAU fiber array unit

The device is designed to operate on a generic qubit encoded in the time-bin basis, schematically depicted on the Bloch sphere in Fig. 1b, and mathematically described as:

$$| \phi \rangle =\alpha | 0\rangle +\beta {e}^{i{\theta }_{S}}| 1\rangle$$

(1)

where \(| 0\rangle\) corresponds to the photon state in the early time-bin, \(| 1\rangle\) to the photon state in the late time-bin, θS is the relative phase between the two bins, and α, β are real-valued probability amplitudes.

As illustrated in Fig. 1a.i, when the MZM is biased at the quadrature point (mode 1), it acts as a 50:50 beam splitter. In this configuration, injecting a generic optical field that encodes the time-bin state \(| \phi \rangle\) into the device results, heuristically, in a superposition of photons traveling through either the longer or shorter arms of the unbalanced interferometer. Photons taking the longer path experience a delay of 100 ps relative to those in the shorter path, resulting in a three-peak detection pattern as a function of arrival time after recombination. Interference arises only in the central peak, where there is the temporal overlap between the early and late time bins that travel relatively along the longer and shorter paths. More rigorously, this configuration implements the positive operator-valued measurement (POVM):

$${\widehat{\Pi }}_{\pm }(\theta )=\frac{1}{4}\,\widehat{{\mathbb{I}}}+\frac{1}{2}\,{\widehat{P}}_{\pm }(\theta )$$

(2)

where \(\widehat{{\mathbb{I}}}=| 0\rangle \langle 0| +| 1\rangle \langle 1|\) is the identity operator representing non-interfering paths (outer peaks), and:

$${\widehat{P}}_{\pm }(\theta )=\frac{1}{2}\,(| 0\rangle \pm {e}^{i\theta }| 1\rangle )(\langle 0| \pm {e}^{-i\theta }\langle 1| )$$

(3)

is the projector describing the interferometric contribution, associated with the central peak and controlled by the phase θ applied in the unbalanced MZI. The signs ± account for the dependence on the two output ports of the unbalanced MZI stage, which exhibit a relative phase shift of π.

The device’s innovative aspect arises from its ability to operate the MZM to act as a fast optical switch (mode 2): photons in the early (late) time-bin can be deterministically routed into the longer (shorter) arm of the unbalanced interferometer (Fig. 1a.ii). In this way, the input photons belonging to the two time-bin slots are temporally overlapped at the output of the second interferometer. This leads to a single interference peak in the detection pattern over time, whereas all photons contribute coherently to the interference pattern. In these conditions, the implemented POVM is \({\widehat{P}}_{\pm }(\theta )\), as defined in Eq. (3). Indeed, by varying the phase θ in the longer arm of the unbalanced MZI, either via the TPS or the EO modulator, it is possible to project the time-bin state into any equatorial state of the Bloch sphere (Fig. 1b) without any temporal post-selection on the detected events, i.e., discarding contributions from the lateral peaks. Moreover, the projections can be executed with a high degree of precision from static conditions (tens of hours) with the TPS, and up to GHz speeds with the EO phase modulator.

A third operating condition (mode 3) is possible when the modulation signal applied to the optical switch is phase-shifted by 180°, thus reversing the photon routing (Fig. 1a.iii). In this configuration, at the output of the device, it is possible to perform a measurement in the computational basis by post-selecting events in the early or late time bins, as now the POVM is \(\widehat{{\mathbb{I}}}/2\). In this configuration, the time-bin separation at the output doubles from 100 ps to 200 ps due to the propagation of the late (early) pulse through the longer (shorter) interferometer path. The doubled temporal separation relaxes the requirements on the temporal resolution of the detection system, improving compatibility with detectors exhibiting moderate timing jitter.

By comparing the operating conditions of mode 1 and mode 2, we can see that there is a fundamental difference in the achievable interference visibility if no post-selection is applied to the detected photons. When a generic time-bin encoded pure state \(| \phi \rangle\) is injected into the device, the maximum interference visibility at the output increases from a maximum of 50% in mode 1 to 100% in mode 2 thanks to the optical switching configuration. This distinction becomes even more relevant in the context of time-bin entangled photon pairs. Considering a maximally entangled Φ-type Bell state:

$$| {\Phi }^{+}\rangle =\frac{| 00\rangle +| 11\rangle }{\sqrt{2}}$$

(4)

If each photon of the pair is sent to two separate devices operating in mode 1 and no temporal post-selection is applied, the resulting two-photon interference visibility is limited to 25%29. With this low visibility, the Bell and Clauser–Horne–Shimony–Holt (CHSH) inequalities cannot be violated30, opening a PSL that affects local-realistic tests of quantum mechanics, and thus hindering the security of QKD protocols26. Even in the presence of high-resolution single-photon detectors, by performing temporal post-selection, the number of coincidence events contributing to quantum interference is reduced to 1/4 of the total, reducing the SKR potentially achievable. In contrast, when both devices operate in mode 2, the time-bin components are deterministically overlapped, enabling maximum quantum interference. This configuration closes the PSL and produces a single interference peak in the time-resolved coincidence histogram, with visibility up to 100%, while increasing throughput due to the lack of discarded events. As a result, it becomes possible to certify entanglement and support secure QKD with a four-fold increase in the SKR.

Fabrication and classical characterization

The integrated device was fabricated on an X-cut lithium niobate on insulator (LNOI) wafer. The single-mode optical waveguide (propagation loss around 0.2 dB cm−1) is combined with radio-frequency (RF) traveling-wave coplanar waveguides for EO modulation (Fig. 2a). The optical and RF field profiles are engineered to maximize the modulation efficiency, with a measured VπLπ ≈ 3.37 V cm (at 1 MHz). Figure 2b shows the EO modulation spectrum for the MZM (optimized for high-frequency operation) and Fig. 2c for the unbalanced MZI stage, with a 3 dB bandwidth as high as 30 GHz and 1 GHz, respectively. The reduced bandwidth of the second-stage interferometer reflects the fact that this stage was not optimized for high-frequency operation. In particular, compared to the MZM, few differences account for the limited bandwidth performance: it does not include the integrated 50 Ω termination, leaving the electrodes open, and it is not connectorized with a high-speed RF connector. The combined effect of the electrodes’ capacitance and the long wire bonds introduces inductive and capacitive parasitic effects that result in peaking around 500 MHz and a limited bandwidth. Comparable performance can be achieved in future iterations by adopting the same design and packaging solution for the MZI as for the MZM. Further details are provided in the “Materials and methods” section.

The fabricated photonic chips were packaged for ease of handling, as illustrated in Fig. 2d, e, and connectorized with optical, RF, and low-frequency interconnections for the respective components.

The final device has a footprint of 9.6 × 26 mm. We stress that a key advantage of the TFLN platform lies in the exceptional EO properties of lithium niobate, combined with the high spatial mode confinement of both the optical and electrical fields (see Fig. 2a), enabled by the integrated photonic design. Additional details on the device design, fabrication, and linear characterization are provided in the “Materials and methods” section. For the experimental demonstrations described in the following sections, one or more devices (all exhibiting comparable performances) were combined in complex experimental setups, where they were employed either as quantum receivers, for projection on the time-bin basis, or as pump tailoring stages at the input of an entangled photon source. Each one was only stabilized in temperature via thermo-electric coolers (TEC), without the need for further active feedback to compensate for interferometers’ bias phase drift, already minimized through the thermal stabilization and the isolation provided by the package.

Entanglement certification

We now investigate the suitability of the device, designed as a building block for complex systems involving multipartite states, to manipulate a biphoton time-bin entangled state. As a first demonstration of its functionality, we certify entanglement by violating both Bell9,11 and CHSH31 inequalities using two spatially separated devices acting as analyzer interferometers while closing the PSL. The simplified experimental setup is illustrated in Fig. 3a. Optical pulses emitted by an actively mode-locked laser are coupled to one of the fabricated devices, used for pump tailoring. By tuning the bias operating point of the balanced MZM, it is possible to generate a pair of twin pulses separated by 100 ps, with arbitrary relative amplitudes. These pulses are injected into a 16 mm long integrated silicon waveguide and, under appropriate pump power conditions (see Supplementary Note 4), time-bin entangled photon pairs are generated via spontaneous four-wave mixing (SFWM)32. The resulting quantum state can be expressed as \(| \phi \rangle =\alpha | 00\rangle +\beta {e}^{i{\theta }_{S}}| 11\rangle\), where all the parameters can be freely tuned through the device settings: the probability amplitudes α and β by tuning the bias of the first-stage MZM, and the relative phase θS by tuning the phase applied in the second-stage MZI. In the following, we set \(\alpha =\beta =1/\sqrt{2}\) and θS = 0, which prepares the Bell state \(| {\Phi }^{+}\rangle\), defined by Eq. (4). The output photons are demultiplexed using commercial 100 GHz DWDM filters (ITU channel 28-1554.94 nm for the signal and channel 38-1546.92 nm for the idler) and routed to two of the developed devices, hereafter referred to as Alice and Bob. Each quantum receiver operates in active switching (mode 2), as shown in Fig. 1a.ii, ensuring that all of the input photons contribute to quantum interference. The two complementary outputs of each interferometer are routed to superconducting nanowire single-photon detectors (SNSPDs), where detection events are recorded using a digital time tagger.

Fig. 3: Biphoton state analysisFig. 3: Biphoton state analysisThe alternative text for this image may have been generated using AI.

a Simplified experimental setup used for data acquisition. b Measured quantum interference curves without accidental subtraction obtained by varying the unbalanced MZI bias of the first quantum receiver while keeping the second one fixed on the top panel, and vice versa for the bottom panel. V denotes the visibility of quantum interference. c JTI of the output biphoton state for selected projective measurement configurations used for quantum state tomography. d Experimental density matrix of the generated quantum state computed by the maximum likelihood reconstruction algorithm, with projective measurements performed using the TFLN receivers

The quantum interference curves retrieved from the coincidence detection patterns for all four detector combinations are shown in Fig. 3b. In the top panel, the phase θA on Alice’s device is scanned while Bob’s phase θB is kept fixed. In the bottom panel, θB is scanned while θA remains constant. This measurement effectively implements a Franson-type test of the Bell inequality, mathematically corresponding to a projective measurement operated on the state \(| {\Phi }^{+}\rangle\). The expected coincidence rate for outputs at the same side of the second MZI is given by:

$$\begin{array}{ll}R\propto {{\mathrm{Tr}}}[({\widehat{P}}_{\pm}({\theta}_{A})\otimes {\widehat{P}}_{\pm}({\theta}_{B}))| {\Phi}^{+}\rangle \langle {\Phi}^{+}|]\\ =\dfrac{1+\cos ({\theta}_{A}+{\theta}_{B})}{2}\end{array}$$

(5)

A π shift is applied to the above expression in the case of detections at opposite output ports of the two MZIs. By fitting the number of accumulated coincidence counts as a function of the applied MZI TPS power with a sinusoidal function, we extract high-visibility two-photon interference fringes, defined as \(V=\frac{\max (R)-\min (R)}{\max (R)+\min (R)}\), which is \((93.5\pm 0.6) \%\) on average across all four detector combinations without accidental subtraction. For all cases, the fitted visibility exceeds the \(1/\sqrt{2}\) threshold required to violate the Bell inequality by at least 38 standard deviations, thus certifying entanglement without any temporal post-selection on the detection events. We also performed the CHSH inequality test by evaluating coincidences at the specific phase settings that maximize the S-parameter (θA = { − π/4, π/4}, θB = {0, π/2} for all 4 possible combinations). We recorded a value of S = 2.54 ± 0.04, exceeding the classical bound (S = 2) by more than 13 standard deviations. We stress that the experiment so performed serves at the same time as a test of entanglement, given the violation of the classical bound, and of quantum nonlocality, given the use of two distinct devices, albeit not space-like in the present demonstration. Moreover, both proofs are free of the PSL. The close match between the experimental data and fits, the similar π-phase shift powers, and the high fringe visibility across the two devices confirm their stability and reliability.

Quantum state tomography

A full tomography of the generated state at the output of the integrated silicon waveguide can be performed by setting the appropriate phase conditions on both integrated quantum receivers simultaneously over a sequence of steps. A complete quantum state characterization requires projective measurements on the three orthogonal bases for each qubit33. In this work, since each quantum receiver can measure the two orthogonal states of a selected basis simultaneously within a single configuration, three measurement configurations were used per device. Permuting the settings between Alice and Bob resulted in a total of 9 combinations, allowing the complete set of 36 projective measurements required for full two-qubit quantum state tomography to be acquired. In particular, projections onto the equatorial bases \(X=\{| +\rangle ,| -\rangle \}\) and \(Y=\{| R\rangle ,| L\rangle \}\) are performed by operating the MZM to overlap the time bins into a single time slot (mode 2, Fig. 1a.ii) and by adjusting the phase of the unbalanced MZI according to Eq. (5), with θA,B = 0 and π/2, respectively. In the computational basis \(Z=\{| 0\rangle ,| 1\rangle \}\), the projection is implemented by operating the device optical switch reversely (mode 3, Fig. 1a.iii).

The unitary evolution imparted by the receivers to the biphoton state for such operational modes can be effectively visualized through a measurement of the joint temporal intensity (JTI)34,35,36 at the output of the devices. Figure 3c shows the measured JTI of four projective measurements out of a total of nine, for one possible pair of detectors (A0-B0) out of a total of four. In the three projective measurements \(| ++\rangle \langle ++|\), \(| +R\rangle \langle +R|\), and \(| RR\rangle \langle RR|\), we observe a strong suppression of coincidence counts in the outer time bins (i.e., when photons are detected in the earlier or later arrival time slot windows at Alice or Bob), resulting in a well-localized overlap in the central time-bin where interference occurs. Compared with Eq. (5), the first and third projectors correspond respectively to the maximum and minimum of the two-photon interference pattern. In the fourth JTI plot, the projections onto the \(| 00\rangle\) and \(| 11\rangle\) states are represented according to which of the two areas, delimited by the dashed lines, the coincidence events belong to. Note that, while this measurement requires higher temporal resolution to discriminate the outcome, here the separation of the coincidence peaks is increased by 100 ps, leading to a total temporal separation of 200 ps and thus relaxing the requirement of detector resolution by a factor of 2.

From the experimental data, we reconstructed the density matrix of the biphoton entangled state through a maximum likelihood estimation algorithm33. The result, shown in Fig. 3d, exhibits a purity of 93% and a fidelity of 95% with respect to the Bell state \(| {\Phi }^{+}\rangle\). A closer analysis of the density matrix reveals that the generated state deviates slightly from the ideal one. Specifically, the probability amplitude of the \(| 00\rangle\) component is greater than that of \(| 11\rangle\), and the imaginary part suggests a slight phase shift relative to the Bell state \(| {\Phi }^{+}\rangle\). From the reconstructed density matrix, we provide a further characterization of entanglement beyond the Bell-curve visibility and the S-parameter reported in the previous section. First, we evaluate the entanglement of formation37 to be as high as 87%. Then, we assess the von Neumann entropy of the reduced subsystems, defined as \(E({\rho }_{A,B})=-Tr[{\rho }_{A,B}{\log }_{2}({\rho }_{A,B})]\). This yields values of E(ρA) = 0.976 and E(ρB) = 0.978 for Alice and Bob, respectively, approaching the theoretical maximum of 1, expected for a maximally mixed qubit state. These high entropy values indicate a strong degree of mixedness in the reduced states, which, when combined with the high purity of the two-qubit state, represent a clear signature of bipartite entanglement2.

Quantum key distribution: passive-basis selection

The integrated TFLN device can serve as a receiver stage for implementing the Bennett-Brassard-Mermin (BBM92) entanglement-based QKD (EBQKD) protocol5. This is achieved using the same photon-pair source configuration used for entanglement certification and quantum state tomography, with a slight modification introduced at the user stations, as shown in Fig. 4a. Specifically, once the photons are demultiplexed and routed toward Alice and Bob, a passive fiber 50:50 beam splitter is placed. At one output port, the incoming photons are sent directly to an SNSPD; at the other port, photons are routed to the input of a TFLN device. Here, the device is configured with the optical switching activated (mode 2), such that the early and late time bins are temporally overlapped at the output (Fig. 1a.ii). The unbalanced MZI is held at a fixed phase θA,B = 0, enabling projective measurements in the X basis. In this configuration, coincidence detection events are maximized between specific detector pairs (e.g., A0-B0 and A1-B1) when the input state is the maximally entangled Bell state \(| {\Phi }^{+}\rangle\) (Eq. (4)).

Fig. 4: Passive basis selection QKDFig. 4: Passive basis selection QKDThe alternative text for this image may have been generated using AI.

a Simplified experimental setup for QKD with passive-basis selection. b Comparison between the Chernoff and Serfling SKR bounds as a function of the block size. c In red, the SKR in the finite-key regime (106 block length) for both the Chernoff and Serfling bounds. In blue, the QBER of the X and Z bases. d Experimental data (dots) and theoretical estimation (lines) of the SKR and QBER for the two measurement bases as a function of the channel link loss. The equivalent fiber length is computed considering 0.2 dB km−1

For photons routed directly to the SNSPDs (bypassing the quantum receiver), a time of arrival analysis distinguishes early (\(| 00\rangle\)) and late (\(| 11\rangle\)) time-bin events, corresponding to projective measurements on the Z basis. This configuration enables the implementation of the BBM92 protocol, where both users perform measurements in two mutually unbiased bases, X and Z. The basis choice is intrinsically random due to the passive beam splitter, and the randomness of the measurement outcomes is ensured by the entangled photon-pair source, as demonstrated in the previous section. For a comprehensive review of quantum cryptography and the various steps involved in QKD protocols, we refer the reader to ref.38.

In this QKD configuration, there is an asymmetry in detection rates between the X and Z bases due to the additional optical losses caused by the presence of the device in the measurement path of the X basis. The maximum measured coincidence rate is 959 Hz for the X basis and 62 kHz for the Z basis, with respective optical losses of 13.3 dB (15.3 dB) and 5.9 dB (6.3 dB) for the signal (idler) photons from the entangled photon pairs source to SNSPDs input. Despite this asymmetry, the QKD protocol can still be successfully implemented by adopting an efficient information reconciliation scheme39. Under these conditions, the sifting factor q — defined as the probability that both users perform projections in the same basis — is significantly improved, approaching unity. This maximizes the key rate by minimizing the number of discarded events during the sifting process. Such an asymmetric basis choice is advantageous, provided that a minimum number of measurements are still performed in the less probable basis (the X basis), to ensure sufficient statistics for detecting potential eavesdropping attempts and thereby guaranteeing the security of the protocol.

To estimate the finite-size SKR, it is required to find an upper bound on the probability of failure on the parameter estimation (PE) step. To do so, we resorted to two different statistical bounds: one based on the Serfling inequality, presented by Tomamichel et al.40 and from here on referred to as the Serfling bound, and a more recent one based on the Chernoff inequality, presented by Mannalath et al.41 and from here on referred to as the Chernoff bound (see Supplementary Note 1). Since this work represents the first experimental implementation of the BBM92 protocol using the Chernoff bounds, we opted to show the SKR analysis done with both bounds to further showcase the advantage of using this new bound with respect to the Serfling one, widely used in literature. The resulting experimental finite-size SKR as a function of the sifted bit block length is shown in Fig. 4b. Compared to the Serfling bound, the Chernoff bound requires considerably smaller sample sizes for its statistical test to be considered relevant. This allows Alice and Bob to generate a secret key at much smaller block lengths, which is especially beneficial for EBQKD, where coincidence rates are usually low.

A long-duration measurement, exceeding 12 h, was performed running our QKD setup, at 0.5 dB channel losses. The SKR always exceeds 18.8 kbit s−1, with a maximum value of 25.4 kbit s−1 in the finite-size regime using the Chernoff bound, with its asymptotic limit value being ~14% higher, and its finite-size regime using the Serfling bound ~13.5% lower. The quantum bit error rate (QBER) for the two measurement bases and the SKR are reported in Fig. 4c. The QBER in the Z basis is mainly limited by the timing jitter of the SNSPDs, which is ~50 ps full width half maximum (FWHM), compared to a time-bin separation of 100 ps. The detection time window used to distinguish between early and late time bins was optimized to maximize the SKR in the Z basis (see Supplementary Note 2). The QBER in the X basis depends on the interferometric performance of the projection implemented by the device. Here, an average QBER of 3.76% was recorded, consistent with the measured visibility reported in the entanglement certification section, according to the relation QBER = (1 − V)/238. The small variations observed in the QBER in the interferometric basis are mainly attributed to phase drift in the interferometer, which causes deviations of the applied projection from the ideal one. These fluctuations are reflected in the temporal evolution of the SKR and can be mitigated in practical implementations by standard interferometric stabilization techniques or by periodic protocol interruption and realignment procedures. Note that other contributions to noise, such as accidental and dark detections, are negligible in the present experimental conditions.

Measurements simulating a variable-length fiber link were performed by adjusting the attenuation in Bob’s fiber link through a variable optical attenuator (VOA). A more realistic proof-of-principle was then performed with fiber spools of different lengths, and could be further extended to a metropolitan-area field test. We note that in these scenarios, appropriate dispersion compensation strategies should be put in place to mitigate the effect of chirp for link lengths exceeding 8 km (see Supplementary Note 3). Indeed, group velocity dispersion in standard telecom fibers broadens the time-bin wavepackets, thereby degrading the temporal confinement required for proper device switching and reducing the distinguishability between early and late time bins. Figure 4d shows the measured (dots) and theoretical SKR (dashed line) in the asymptotic regime and for a finite block size of 9 × 104. The corresponding QBER values for the two measurement bases are also shown. Note that QKD is feasible for equivalent fiber lengths exceeding 100 km (0.2 dB km−1 loss). The main limitation in this configuration arises from the signal-to-noise ratio (SNR) of the coincidence counts in the X basis: at high channel attenuation, detector dark counts significantly reduce the visibility of the interference, thus increasing the QBER. In contrast, the associated Z basis QBER is almost unaffected by dark counts in the attenuation sweep, due to a higher SNR. An additional important consideration for real-world implementations involving physically separated stations is the requirement for precise timing synchronization between the users and the pulsed source. Such synchronization is crucial to accurately discriminate the received time-bin slots and to correctly align the modulation and switching signals for proper routing within the receivers. Efficient synchronization techniques achieving picosecond-level precision have been demonstrated up to 50 km link length, even without the need for additional communication channels42,43,44. We note that this synchronization requirement only concerns the technical implementation and does not, in itself, limit or compromise the security of the QKD protocol, whose security relies on entanglement. However, the security of the present implementation is not device-independent, since the detection loophole remains open45. Closing this loophole is a well-known experimental challenge that goes beyond the scope of this work. Nevertheless, the proposed overcoming of the temporal PSL represents a necessary step toward the deployment of loophole-free time-bin architectures.

Quantum key distribution: active basis selection

The BBM92 QKD protocol can also be implemented using an alternative user receiver setup whose schematic configuration is shown in Fig. 5a. Compared to the previous configuration, which relied on passive-basis selection, this configuration removes the beam splitter and directs all the photons toward the device, where measurements are performed by actively selecting the applied projector. Precisely, the projective measurements are performed in the two mutually unbiased X and Y bases, both of which exhibit quantum interference for all incoming photons without post-selection due to the active time-bin switching (mode 2) operated by the first-stage MZM.

Fig. 5: Active basis selection QKDFig. 5: Active basis selection QKDThe alternative text for this image may have been generated using AI.

a Simplified schematic used for the experimental data acquisition. b Time trace of the SKR in the asymptotic regime and QBER of the tested QKD protocol implementation. c Eye diagram of a single device obtained by applying a modulation to the unbalanced MZI with a PRBS at a 1 GHz clock rate and peak-to-peak voltage Vπ. d Theoretical estimation (lines) of the SKR and QBER for the two measurement bases as a function of the channel link loss, based on the experimental acquisition (dots) without added optical fiber stretches. The equivalent fiber length is computed considering 0.2 dB km−1

The device applies the POVM defined in Eq. (3), corresponding to either \({\widehat{P}}_{+}(\theta )\) or \({\widehat{P}}_{-}(\theta )\), depending on the device output port. The phase θ determines the measurement basis and is physically implemented by the unbalanced MZI as a combination of two contributions:

$$\theta ={\theta }_{TPS}+{\theta }_{RF}$$

(6)

where θTPS is a phase set by the TPS, and θRF is the phase modulation applied by the EO modulator.

The basis choice for each user is applied at the repetition rate of the pulsed pump laser (1 GHz) to ensure a random and independent selection for every entangled photon pair. In our setup, the EO modulator of the unbalanced MZI is driven by an arbitrary waveform generator (AWG) programmed with a PRBS. To improve the security of the protocol, these could, in principle, be replaced by quantum random number generators (QRNG), even integrated on the same chip46,47. Alice and Bob use PRBS sequences of lengths 27 − 1 and 29 − 1, respectively, both operating at a 1 GHz bit rate. This configuration ensures that the joint basis-choice pattern repeats every 127 × 511 = 64,897 clock periods, effectively emulating a non-repeating sequence. The modulation signals have a peak-to-peak voltage of Vpp = Vπ/2. To ensure the switching between desired X and Y measurement bases, the TPS is statically set to apply a phase θTPS = π/4 when no voltage is applied to the EO modulator. This ensures toggling the total phase θ between 0 and π/2 every clock cycle. An eye diagram showing the continuous-wave light modulation of the unbalanced MZI, driven by the PRBS sequence, is shown in Fig. 5c.

As for the previous case, we conducted a long-duration measurement exceeding 12 h continuously without any interruption and without the use of active stabilization, apart from maintaining the device package at a constant temperature. Once again, both Serfling and Chernoff bounds were used to obtain and compare the secret key rates. The time traces of the SKR for both bounds, along with the QBER values for the X and Y bases, are shown in Fig. 5b. A maximum SKR of 1.024 kbit s−1 was recorded, with an average of 0.805 kbit s−1 over the measurement period. The average QBER value for the Y basis over time is 4.02%, while the X basis exhibits a higher value of 6.1%. For the Y basis, the marginal increase in QBER compared to the previous configuration is primarily attributed to non-ideal AWG modulation, as the basis projection is switched every nanosecond. The increased QBER observed in the X basis—beyond the limitation affecting the Y basis—is additionally attributed to an initial offset in the operating point, for which the initial QBER was 5.5%, together with larger phase-drift variations over time. Nevertheless, given the high modulation speed, the observed QBER values confirm the excellent device performance under fast, active operation. Compared to the passive QKD system, the SKR is reduced since both measurement bases are now implemented passing through the device, and thus the total optical losses are higher: 12.15 dB for Alice and 10.1 dB for Bob from the entangled photon pairs source to the SNSPDs input. Additionally, the sifting factor q is no longer close to 1, but reduced to 0.5, due to the equal probability of selecting each basis. This high-loss scenario better showcases the difference between the two bounds used to estimate the SKR, as block lengths are smaller.

An estimation of the SKR as a function of channel loss is reported in Fig. 5d for both the asymptotic regime and finite block size of 4 × 104, where using the Chernoff bound provides an increase of 33.2% on the secret key generation when compared with the Serfling bound generation. At the measured coincidence rate, a block of key is generated approximately every 25 s. If fast key generation is required, we note that an average of 450 bit s−1 of secret key was generated even using a block length of 104, where the secret key generated using the Chernoff bound becomes 122.3% higher with respect to the Serfling bound. At high channel loss, the QBER is primarily limited by detector dark counts. In this configuration, compared to the passive one, the QBER degradation for the interferometric bases is expected to occur at slightly longer fiber length, as the receiver coincidence rate increases due to the removal of the beam splitter, which in the previous setup introduced an additional 3 dB loss.

Overall, we emphasize that this configuration, although the SKR is reduced due to the additional optical losses introduced by the quantum receiver and the slight QBER increase arising from the added complexity of the phase modulation, not only removes the PSL as in the passive QKD case, but also eliminates the need to resolve the separation between individual time bins. Indeed, only the separation between successive time-bin states must be distinguished. This relaxed detection requirement makes it possible to increase the SKR by simply raising the pump laser repetition rate and reducing the time-bin separation.