Secure score with coherent states
In quantum communication practice, using weak coherent states is much more convenient than using single-photon sources, as weak coherent states can be easily prepared by simply attenuating laser pulses. This approach offers two major advantages, insensitivity to losses in the sender’s devices and the ability to achieve high repetition rates. It is crucial for QPV, as the protocol is loss-sensitive and requires more than 106 rounds of repetition.
To facilitate security analysis, we use PR-WCS, which are mixed states of Fock states. Such sources are readily available, with phase randomization naturally achieved using gain-switched lasers. We proceed to derive Γ0 for the case of weak coherent states, taking into account statistical fluctuations due to the finite number of rounds, thereby establishing a rigorous security bound.
PR-WCS are mixed states of Fock states, that is, \(\int_{0}^{2\uppi }\left\vert \alpha {\rm{e}}^{\text{i}\theta }\right\rangle \left\langle \alpha {\rm{e}}^{\text{i}\theta }\right\vert\)\(=\mathop{\sum }\nolimits_{i = 1}^{\infty }{\rm{e}}^{-{| \alpha | }^{2}}\)\(\frac{{| \alpha | }^{i}}{i!}\left\vert i\right\rangle \left\langle i\right\vert\), where \(\left\vert \alpha {\rm{e}}^{\text{i}\theta }\right\rangle\) is the coherent state with a complex amplitude αeiθ, and \(\left\vert i\right\rangle\) is the i-photon Fock state. Therefore, each round of quantum state preparation can be categorized into three types, vacuum states, single-photon states and multiphoton states. For single-photon states, the same approach as in ref. 9 can be applied. Vacuum states contain no encoded information, so an adversary cannot obtain polarization information from them through measurement but can only guess the outcome. For multiphoton states, we adopt the most pessimistic scenario, assuming that the adversary can perfectly attack them. Then, Γ0 can be written as
$${\varGamma }_{0}={S}_{0}^{u}+{S}_{1}^{u}+{S}_{2+}^{u},$$
(1)
where S0, S1 and S2+ represent the scores corresponding to vacuum, single-photon and multiphoton states, respectively. The superscript u denotes the upper bound that a dishonest prover can achieved. We next analyse the upper bounds separately. In the following analysis, we use probabilistic inequalities with failure probability ϵ for five times. So the failure probability of the protocol is 5ϵ. In our experiment, we set ϵ = 10−10, so the total failure probability is 5 × 10−10. This means a dishonest prover cannot surpass the threshold Γ0 with a probability larger than 5 × 10−10.
Upper bound for vacuum states
For vacuum states, the adversary may either declare a no-response event or a response event. A no-response contributes to n⊥. A response event yields a correct outcome with 50% probability, thereby contributing to either nc or nI. Let N0 be the total number of vacuum-state rounds, x the number of rounds where the adversary declares a response, and the remaining N0 − x rounds correspond to no-response events. Let Yi denote the score obtained by the adversary in the ith round with a declared response. Then, for all rounds of vacuum states, the adversary’s total score, S0, is given by
$${S}_{0}=\mathop{\sum }\limits_{i=1}^{x}{Y}_{i}-\left({N}_{0}-x\right){\gamma }_{\perp }.$$
(2)
For any given response round, because the vacuum state does not reveal any encoded information, each round is independently and identically distributed, yielding a correct or incorrect response with equal probability of 50%. By normalizing Yi as a Bernoulli random variable \(\frac{{Y}_{i}+{\gamma }_{I}}{{\gamma }_{C}+{\gamma }_{I}}\) and applying the Chernoff bound30 for independent random variables, we obtain
$$\mathop{\sum }\limits_{i=1}^{x}{Y}_{i}\le \frac{{\gamma }_{C}-{\gamma }_{I}}{2}x+\frac{{\gamma }_{C}+{\gamma }_{I}}{2}\left(\ln \frac{1}{\epsilon }+\sqrt{{\ln }^{2}\frac{1}{\epsilon }+4\left(\ln \frac{1}{\epsilon }\right)x}\right),$$
(3)
where ϵ is the failure probability. So the upper bound of S0 is given by
$${S}_{0}\le \frac{{\gamma }_{C}-{\gamma }_{I}}{2}x+\frac{{\gamma }_{C}+{\gamma }_{I}}{2}\left({\rm{ln}}\frac{1}{\epsilon }+\sqrt{{\rm{ln}}^{2}\frac{1}{\epsilon }+4\left({\rm{ln}}\frac{1}{\epsilon }\right)x}\right)-\left({N}_{0}-x\right){\gamma }_{\perp }.$$
(4)
Noting that \(\mathop{\max }\nolimits_{x}\;(ax+b\sqrt{c+dx})\to x=-\frac{c}{d}+\frac{{b}^{2}d}{4{a}^{2}}\), the score S0 reaches its upper bound \({S}_{0}^{u}\) when \(x=-\frac{1}{4}\ln \frac{1}{\epsilon }+\frac{{({\gamma }_{C}+{\gamma }_{I})}^{2}}{{({\gamma }_{C}-{\gamma }_{I}+2{\gamma }_{\perp })}^{2}}\ln \frac{1}{\epsilon }\). So \({S}_{0}^{u}\) is given by
$$\begin{array}{l}{S}_{0}\le {S}_{0}^{u}=\displaystyle\frac{(7{\gamma }_{C}^{2}+4{\gamma }_{C}{\gamma }_{\perp }+4{\gamma }_{\perp }^{2}+10{\gamma }_{C}{\gamma }_{I}+12{\gamma }_{\perp }{\gamma }_{I}-{\gamma }_{I}^{2}){\rm{ln}}\frac{1}{\epsilon }}{8({\gamma }_{C}+2{\gamma }_{\perp }-{\gamma }_{I})}\\\qquad\qquad+({\gamma }_{C}+{\gamma }_{I})\sqrt{\frac{{({\gamma }_{C}+{\gamma }_{I})}^{2}{\rm{ln}}^{2}\displaystyle\frac{1}{\epsilon }}{{({\gamma }_{C}+2{\gamma }_{\perp }-{\gamma }_{I})}^{2}}}-{\gamma }_{\perp }{N}_{0}.\end{array}$$
(5)
In the case where γC + 2γ⊥ − γI < 0, it can be further simplified to
$${S}_{0}\le {S}_{0}^{u}=-\frac{{({\gamma }_{C}-2{\gamma }_{\perp }+3{\gamma }_{I})}^{2}\ln \frac{1}{\epsilon }}{8({\gamma }_{C}+2{\gamma }_{\perp }-{\gamma }_{I})}-{\gamma }_{\perp }{N}_{0}.$$
(6)
Upper bound for single-photon states
For single-photon states, we follow the same analysis as in ref. 9, which gives the following result. For a single-photon round, if we assume that the attackers output different responses to the two verifiers with a probability less than ξ, then semidefinite programming can be used to obtain a set of parameters {γC, γ⊥, γI}, such that the adversary’s expected score under these parameters does not exceed zero. The parameters in this work are selected using this approach. To ensure a reasonable choice of ξ, we note that in our experiment the honest prover always reports same responses. If the attackers adopt a strategy exceeding ξ in more than Nξ rounds, the probability of finding no different-response events would be less than \({(1-\xi )}^{{N}_{\xi }}\). Therefore, with a failure probability of ϵ, we can conclude that \({N}_{\xi }\le \ln \epsilon /\ln (1-\xi )\). Therefore, let N1 be the number of single-photon rounds, then there are less than \({N}_{\xi }\le \ln \epsilon /\ln (1-\xi )\) rounds that the attack is not included in the analysis of ref. 9. And there are more than \({N}_{1}-{N}_{\xi }\le \ln \epsilon /\ln (1-\xi )\) rounds that the expected scores of attackers are less than 0.
To give a worst-case analysis, we assume in \({N}_{\xi }\le \ln \epsilon /\ln (1-\xi )\) rounds, the attackers can perfectly attack the system, which means the attacks always give correct responses. The corresponding score upper bound is \({\gamma }_{C}{N}_{\xi }\le \ln \epsilon /\ln (1-\xi )\). For the rest \({N}_{1}-{N}_{\xi }\le \ln \epsilon /\ln (1-\xi )\) rounds, ref. 9 has proved the sequential repetition, and Azuma’s inequality31 can be used to bound the score upper bound. We still set the failure probability of the Azuma’s inequality to be ϵ, then the score upper bound is given by \(\sqrt{2\ln \frac{1}{\epsilon }({N}_{1}-\frac{\ln \epsilon }{\ln (1-\xi )})}\). This formula applies under the condition that \(\max \{\left\vert {\gamma }_{C}\right\vert ,\left\vert {\gamma }_{\perp }\right\vert ,\left\vert {\gamma }_{I}\right\vert \}\le 1.\)
Combining the above two case, the score upper bound is given by
$${S}_{1}^{u}={\gamma }_{C}\left\lceil \frac{\ln \epsilon }{\ln (1-\xi )}\right\rceil +\sqrt{2\ln \frac{1}{\epsilon }\left({N}_{1}-\left\lceil \frac{\ln \epsilon }{\ln (1-\xi )}\right\rceil \right)},$$
(7)
where we added the ceiling because the number of rounds should be an integer.
Upper bound for multiphoton states
For multiphoton states, the worst case is that the adversary can perform a perfect attack, always producing correct responses. Thus, the score is given by
$${S}_{2+}^{u}={N}_{2+}{\gamma }_{C},$$
(8)
where N2+ is the number of rounds containing two or more photons.
Γ
0 under statistical fluctuations
The photon-number distribution of PR-WCS follows a Poisson distribution with mean photon number μ = ∣α∣2. However, given a total of N rounds, the actual numbers of vacuum, single-photon and multiphoton events, denoted by N0, N1 and N2+, are subject to statistical fluctuations. These fluctuations should be taken into account when computing Γ0.
According to equations (6)–(8), the score contributed by N0 is negative, while those from N1 and N2+ are positive. Thus, the upper bound of Γ0 is given by \({\varGamma }_{0}^{u}={\varGamma }_{0}({N}_{0}^{l},\,{N}_{1}^{u},\,{N}_{2+}^{u})\), where the superscripts u and l indicate the upper and lower bounds, respectively. These bounds can be obtained using the Chernoff bound,
$${N}_{1}\le {N}_{1}^{u}=N{\rm{e}}^{-\mu }\mu +\frac{1}{2}\left(\ln \frac{1}{\epsilon }+\sqrt{{\ln }^{2}\frac{1}{\epsilon }+8\left(\ln \frac{1}{\epsilon }\right)N{\rm{e}}^{-\mu }\mu }\right)$$
(9)
$$\begin{array}{l}{N}_{2+}\le {N}_{2+}^{u}=N(1-{{\rm{e}}}^{-\mu }-{{\rm{e}}}^{-\mu }\mu )\,+\\\;\displaystyle\frac{1}{2}\left({\rm{ln}}\displaystyle\frac{1}{\epsilon }+\sqrt{\rm{ln}^{2}\displaystyle\frac{1}{\epsilon }+8\left({\rm{ln}}\displaystyle\frac{1}{\epsilon }\right)N(1-{{\rm{e}}}^{-\mu }-{{\rm{e}}}^{-\mu }\mu )}\right)\end{array}$$
(10)
$${N}_{0}\ge {N}_{0}^{l}=N-{N}_{1}^{u}-{N}_{2+}^{u}.$$
(11)
Experimental optimization
In practice, it is important to ensure that an honest prover can pass the verification despite potential misalignment in its measurement system. Let pe denote the misalignment error and η denote the transmittance. The problem reduces to finding an optimal mean photon number μ that maximizes Γ − Γ0, where the expected score of an honest prover is given by
$$\varGamma =N\left({\gamma }_{C}(1-{{\rm{e}}}^{-\eta \mu })(1-{p}_{{\rm{e}}})-{\gamma }_{\perp }{{\rm{e}}}^{-\eta \mu }-{\gamma }_{I}(1-{{\rm{e}}}^{-\eta \mu }){p}_{{\rm{e}}}\right).$$
(12)
Based on the normalized parameters γC = 0.04275, γ⊥ = 0.05019 and γI = 1 obtained via semidefinite programming in ref. 9, when ξ = 0.001, along with the experimental parameters pe = 0.3% and η = 70%, the average photon number is optimized to μ = 0.52 for N = 107. In this case, Γ0 is calculated as −242,972.
High-fidelity quantum state preparationCoherent-state source
The coherent-state source is a gain-switched laser driven by narrow electrical pulses. To obtain a stable and reliable high-speed picosecond source, the key is to generate ultrashort and repeatable pump excitation. We use fast electronics to produce ultranarrow electrical pulses to drive the gain-switched laser in the relaxation oscillation regime. Specifically, the input 2-MHz periodic signal is processed through a sequence of high-speed electronic operations, including comparison, fan-out, inversion, delay, logical AND and amplification. This converts the signal into ultranarrow electrical pulses with the same repetition rate of 2 MHz and fast rising and falling edges. The resulting electrical signal has a root mean square jitter of 4 ps.
These electrical pulses are then used to drive the gain-switched laser. Under short-pulse excitation, carriers rapidly accumulate in the laser and trigger photon emission. When the electrical pulse is switched off, carrier injection stops and drops below the lasing threshold, turning off the laser. This process confines photon emission within 200 ps, yielding optical pulses with a full width at half maximum (FWHM) of 47 ps. Due to the intrinsic dynamics of gain switching, the root mean square jitter of the output optical pulses is 19 ps.
In addition, because the laser wavelength is sensitive to environmental temperature and driving current, we use a high-precision proportional–integral–derivative feedback loop to stabilize the laser temperature within 1 mK. Together with a constant-current driver, this ensures wavelength stability (±2.5 pm over 30 min). At 25 °C, the central wavelength is 1,549.65 nm, with a 3-dB spectral linewidth of 0.06 nm.
Polarization encoding module
The principle of polarization-state preparation is to split an initial polarization state into two components, introduce a relative phase by adjusting the phase of one component and then recombine them orthogonally to generate the state \(\left\vert H\right\rangle +{\rm{e}}^{i\phi }\left\vert V\right\rangle\). Here, we adopt a Sagnac structure. After the initial polarization state is divided into two parts, they propagate clockwise and counterclockwise in the Sagnac loop. A phase modulator placed at an off-centre position selectively modulates the phase of only one propagation direction, thereby introducing a relative phase difference.
The key advantage of this structure is that the clockwise and counterclockwise pulses traverse the same fibre, so their relative phase does not drift due to path-length differences. This yields high stability and is favourable for high-fidelity quantum state preparation. However, conventional Sagnac schemes based on beam splitters cannot be used for polarization-state preparation because they do not support orthogonal recombination. Using a PBS would require rotating the initial polarization by 45° with a polarization controller, which compromises stability.
To address this limitation, we design a micro-assembled RCS that integrates a rotator, a circulator and a PBS. The micro-assembly process enables precise polarization rotation and accurate 50:50 splitting, while the inclusion of the circulator suppresses reflections associated with the Sagnac loop.
Figure 3 illustrates the structure of the Sagnac interferometer and the micro-assembled RCS component. In the RCS, the rotator is implemented by rotating the polarization-maintaining fibre pigtail by 45°, while the circulator is a single-mode device. A phase modulator is placed in the Sagnac loop at a position where the clockwise and counterclockwise paths differ by 8.5 ns in arrival time.
The input light enters the RCS along the slow axis of the polarization-maintaining fibre and is aligned at 45° with respect to the circulator before reaching the PBS. This 45° alignment ensures a 50:50 splitting ratio at the PBS. After splitting, the two orthogonal polarization components both propagate along the slow axis of polarization-maintaining fibres and arrive at the phase modulator sequentially from the clockwise and counterclockwise directions, with a relative delay of 8.5 ns. The phase modulator applies different phase shifts to the two components, thereby introducing a relative phase difference ϕ between them. They then return to the PBS and recombine into \(\left\vert H\right\rangle +{\rm{e}}^{i\phi }\left\vert V\right\rangle\) and are finally emitted from another port of the circulator.
As a result, this design achieves high-fidelity polarization-state preparation with a measured fidelity of 99.73%. The correspondingly low error rate allows the protocol to tolerate higher losses and enables the prover to attain higher scores, which constitutes one of the key factors for the successful operation of the system.
Large-scale and rapid Boolean function
The prover obtains the basis choice by performing a Boolean function evaluation f({0, 1}n) → {0, 1}, which is a key step in the f-BB84 protocol. The method of computation and the input size n determine the security, while the computation speed also affects the overall latency. Unfortunately, the required Boolean function is not a simple fixed mapping that could be readily implemented and simplified using logic circuits, truth tables or Karnaugh maps. Instead, it is a uniformly random Boolean function.
For an input size of n bits, there are 2n possible inputs, and each input can map to either 0 or 1, giving a total of \({2}^{{2}^{n}}\) possible Boolean functions. Experimentally, one Boolean function is selected uniformly at random from the set of all possible functions and is kept fixed across all N rounds within a single verification task.
To achieve large-scale and rapid random Boolean function computation, we use a lookup-table approach implemented with a custom FPGA and DDR-based circuit. Although fast computation typically relies on logic gates, we use a lookup-table method because logic gates are impractical in terms of both resource consumption and delay. On one hand, the state space of Boolean functions is \({2}^{{2}^{n}}\). Assuming each logic gate can represent m states, the required number of gates is \({\log }_{m}({2}^{{2}^{n}})\), which grows exponentially with n and far exceeds the capacity of current FPGAs. On the other hand, logic gates inevitably introduce circuit delays. When multiplied by an exponential number of gates, the resulting delay becomes prohibitive.
The lookup-table approach transforms the scalability challenge into a memory-space problem. We implement the Boolean function using DDR chips with a total capacity of 1 Tb = 240 bits, corresponding to n = 40. Once the FPGA receives 40 bits, it uses them as an address to access the corresponding bit stored in the DDR memory and outputs the result as the basis selection signal. By writing different truth-table outputs in DDR memory, different Boolean functions can be implemented, enabling support for the full set of \({2}^{{2}^{40}}\) possible Boolean functions. The truth-table outputs can be selected uniformly at random using a random number generator, satisfying the protocol’s requirement for uniform randomness. The truth table is preloaded before the protocol begins and therefore does not contribute to the latency, although the DDR write speed is also high.
Due to the inherent delay of the FPGA and the random-access performance of the DDR memory, this part introduces a delay of approximately 117.3 ns. Among these, the DDR readout latency is approximately 93.32 ns, while the input/output latency accounts for about 18.98 ns.
Near-light-speed channel
Both the basis information and the measurement results are classical bits and can be transmitted using the same method. The main difference is that the basis information contains n/2 bits, while the measurement result is a single bit. To enable rapid transmission of classical information, we adopt a simple communication scheme based on amplitude shift keying, where a high-intensity signal represents ‘1’ and a low-intensity signal represents ‘0’. We implement intensity modulation using direct modulated laser, which eliminates the need for an external intensity modulator and reduces system complexity and cost. To avoid additional jitter caused by oscillations, we do not use gain switching as in the quantum source. Instead, the laser operates in continuous emission.
Specifically, the drive current is set slightly above the threshold current, resulting in weak emission with an optical power of about 0.2 mW, corresponding to bit ‘0’. To encode bit ‘1’, the drive current is increased to about 40 mA, yielding an optical power of about 4 mW. The high-current signal is maintained for 2 ns. Therefore, when encoding bit ‘1’, the laser outputs a 2-ns optical pulse, while it remains in the low-power mode otherwise. The rise and fall times of the driving signal are about 300 ps. As the laser operates in continuous emission, additional timing jitter is negligible.
A further challenge is that if each bit is transmitted with a cycle duration of τ, sending n/2 bits will introduce a delay of (n/2 − 1)τ, which is unfavourable for Boolean functions with large n. We use dense-wavelength division multiplexing with independent lasers at different wavelengths to send specific bits simultaneously. The frequency grid is 100 GHz, in accordance with the ITU-T G.694.1 standard. The laser array at the verifier occupies 20 wavelength channels from 1,559.794 nm to 1,544.526 nm, corresponding to DWDM channels C22-C41. This enables the parallel transmission of n/2 bits, eliminating delay dependence on n. The optical signals are detected using high-speed PIN photodiodes and directly fed into subsequent circuits for discrimination.
Signal transmission through the channel also takes time. To minimize this delay, we use an AR-HCF with an air-filled core, enabling light to propagate at nearly the speed of light in vacuum. Combined with low dispersion, the additional delay is limited to approximately 22 ns.
Low-delay and low-loss quantum measurement
The loss in quantum state measurement primarily originates from the insertion loss of the basis selection device and the detection efficiency of the photon detector. To mitigate this, we use low-loss optical switches and superconducting nanowire single-photon detectors. In addition, polarization-maintaining fusion splicing is used to reduce connector loss. As a result, the overall insertion loss is approximately 0.96 dB, mainly due to the insertion loss of the optical switch (about 0.6 dB). The detection efficiency reaches 90%, leading a transmission efficiency of 72%.
However, this configuration introduces delay challenges. High-speed, low-loss optical switches require a driving voltage exceeding 400 V and cannot directly interface with the digital outputs of the Boolean function circuit. In addition, the weak click signal from the detectors cannot be directly transmitted over long distances to the verifiers. Signal conversion inevitably introduces delay. To address this, we develop a GaN-based high-voltage driver that converts digital signals into high-voltage signals within 50 ns, enabling fast response of the optical switch. In parallel, we design an integrated signal processing unit for the detectors that performs amplification, discrimination and on–off keying encoding to reduce the return delay of detection signals. These measures lead to a substantial reduction in delay, without compromising low-loss and high repetition rate.