- The paper demonstrates a fiber-based, three-state BB84 implementation using time-bin encoding, one decoy level, and measured state-preparation flaws to certify security over 101–151 km of ultra-low-loss fiber.
- The adapted loss-tolerant analysis reconstructs the unavailable X-basis projection from accessible measurements, increasing the estimated phase-error rate to about 3.5–3.8% and reducing certified key rates by roughly 40–60%.
- The experiment achieves a 18.5 kbps secret key rate at 151 km against collective attacks, while revealing intensity–encoding correlations and other implementation limitations that require further security analysis.
This paper reports a fiber-based implementation of the simplified three-state BB84 protocol with time-bin encoding and a single decoy level, in which state preparation flaws (SPFs) are explicitly measured and incorporated into the security analysis. The work addresses a well-known gap between high-performance QKD demonstrations and implementation security: previous record-setting experiments with this protocol family assumed perfect state preparation, an assumption that is not verified at high clock rates. By combining a deliberately simplified transmitter with an adaptation of Tamaki et al.'s loss-tolerant (LT) method, the authors demonstrate secret key distribution over 151 km of ultra-low-loss (ULL) fiber that remains secure against collective attacks even when the actual, imperfect emitted states are used in the parameter estimation.
Protocol and experimental design
The implemented protocol is the three-state BB84 variant of Rusca et al. Alice prepares phase-randomized weak coherent pulses in time-bin encoding using only three states: ∣0Z⟩ and ∣1Z⟩ (single early or late pulses) for key generation, and ∣0X⟩ (equal superposition of both time bins) for parameter estimation. A one-decoy scheme alternates mean photon numbers μ0=0.5 and μ1=0.23. Bob performs passive basis choice via a 90/10 coupler: the Z basis measures arrival time directly on an SNSPD, while the X basis interferes the two time bins in a Michelson interferometer, yielding three detection slots — the middle bin projects onto ∣−⟩, and the side bins are equivalent to Z-basis measurements.
The transmitter uses a gain-switched distributed feedback laser at 1.25 GHz producing 37.5 ps FWHM pulses, split into pairs separated by 202 ps by a Faraday-mirror Michelson interferometer, followed by a 10 GHz intensity modulator that performs both qubit encoding and decoy selection. The receiver mirrors this architecture with a 198 ps interferometer. Notably, the authors intentionally reduce the repetition rate relative to prior implementations of the same protocol so that adjacent rounds do not overlap in Bob's X measurement. This costs throughput but enables direct characterization of SPFs from protocol statistics alone, without hardware modifications. Interferometric visibility was quantified as 98% end-to-end, with individual interferometer visibilities of 99.8% and 99.7%, and a measured delay mismatch of 4 ps (~11% of the pulse width). Error correction and privacy amplification were not run in real time; leaked bits are computed assuming an LDPC code with 33.3% leakage at QBER around 2%.
State characterization
Because the time bins of successive rounds are non-overlapping, the SPFs can be extracted simply by running the protocol and having Bob reveal all bit values to Alice during calibration. From the detection statistics conditioned on each prepared state A∈{0Z,1Z,0X} and decoy setting m, the polar angle θA,m follows from the ratio of early-to-late bin counts, and the azimuthal angle φA,m from the middle-bin interference count, with the visibility factor ∣1Z⟩0 folded in naturally. The same statistics yield intensity ratios across decoy levels.
Two findings deserve emphasis. First, the characterized angles remain essentially unchanged whether the states traverse 101–151 km of ULL fiber or a 25 dB attenuator, confirming that chromatic dispersion compensation is effective and that channel length does not inflate the SPFs. Second, and more consequentially, the characterization reveals correlations between the intensity levels and the bit-and-basis encoding: the estimated Bloch angles depend on which decoy level is active, and the effective intensities depend on which qubit is encoded. Both encodings are performed by the same intensity modulator, so memory effects couple them. Since the LT analysis adopted here does not model such correlations, the authors conservatively use only the signal-level (∣1Z⟩1) characterization in the key exchange. This is a stated limitation: the observed cross-correlations are left outside the security proof, though related side-channels have been treated independently elsewhere.
Security analysis
The original security proof for this protocol assumes ideal states; the LT method accommodates SPFs but assumes Bob can project onto both X-basis eigenstates, whereas here only the ∣1Z⟩2 projection is available. The central theoretical contribution is to close this gap. Using the POVM identity ∣1Z⟩3, the missing ∣1Z⟩4 statistics are reconstructed as linear combinations of experimentally accessible yields. Solving the resulting linear system gives the transmission coefficients ∣1Z⟩5 (∣1Z⟩6), from which the virtual yields of Tamaki et al.'s entanglement-based construction — and hence the single-photon phase error rate ∣1Z⟩7 — are obtained. The virtual-state traces and Bloch vectors are computed explicitly from the characterized angles ∣1Z⟩8. In the limit of perfect state preparation, the derivation reduces exactly to the Rusca et al. result, providing a consistency check.
The single-photon phase error rate is then promoted to weak coherent pulses via the one-decoy finite-key analysis, with Hoeffding-type corrections and vacuum-event estimation from empty time bins, yielding the final phase error rate ∣1Z⟩9. The proof covers collective attacks only; extension to coherent attacks via Azuma's inequality or de Finetti techniques, and inclusion of a squashing map, are acknowledged as outstanding.
Simulations accompanying the proof show instructive structure: when the X state is perfect, the phase error rate stays minimal along the direction where the Z-state imperfections are symmetric (∣0X⟩0), because the virtual X states remain ideal in that case; asymmetric Z errors degrade it monotonically. Under the perfect-preparation assumption, by contrast, the analysis is blind to these effects entirely.
Secret key exchange results
Keys were exchanged over 101.4 km, 112.6 km, and 151.0 km of ULL fiber (0.17 dB/km) with block size ∣0X⟩1, ∣0X⟩2, and ∣0X⟩3. The comparison between the perfect-state analysis and the LT analysis is the paper's principal quantitative result:
| QC length (km) |
QBER∣0X⟩4 (%) |
∣0X⟩5 (%) |
SKR (bps) |
∣0X⟩6 (%) |
SKR∣0X⟩7 (bps) |
| 101.4 |
2.35 |
2.49 |
∣0X⟩8 |
3.77 |
∣0X⟩9 |
| 112.6 |
1.89 |
3.03 |
μ0=0.50 |
3.52 |
μ0=0.51 |
| 151.0 |
1.73 |
2.30 |
μ0=0.52 |
3.74 |
μ0=0.53 |
Including the measured SPFs raises the estimated phase error rate substantially — by roughly 50–60% in relative terms — and correspondingly reduces the certified secret key rate. At 151 km the penalty is under 40%, leaving approximately 18.5 kbps of provably secure key rate against collective attacks. The implication is direct: analyses that assume perfect state preparation overestimate the secret key rate in real high-speed transmitters, and the magnitude of the overestimation is large enough to matter for system certification. The absolute rates are modest compared to prior demonstrations with the same protocol (which reached ~60 Mbps and 421 km), but those figures relied on the unverified perfect-preparation assumption; the contribution here is the verified-secure operating point rather than raw performance.
Limitations and open questions
Several caveats bound the results. The security proof addresses collective attacks only and lacks a squashing map, so full composable security against coherent attacks remains open. The LT framework assumes the three states are mutually linearly independent and treats each decoy level separately; the measured intensity–qubit correlations induced by the shared modulator are excluded from the analysis, and combining them with other known side-channels (intensity correlations, bit-and-basis correlations) into a single proof is identified by the authors as an urgent unresolved problem. The characterization itself must be performed in a trusted setting inaccessible to Eve; the paper proposes practical schemes (calibration in the lab before deployment, a replica receiver, or dual transceivers) but relies on the assumption that SPFs remain stable between calibration and operation. Finally, dark counts are assumed negligible in the characterization formulas, and EC/PA are simulated rather than executed.
Conclusion
This work demonstrates that a deliberately simplified three-state BB84 system can be operated with security grounded in measured device behavior rather than idealized assumptions. The combination of overlap-free timing for in-protocol state tomography, reconstruction of the unavailable μ0=0.54 projection via POVM linearity, and the adapted loss-tolerant analysis yields finite-size secure keys over metropolitan-to-long-haul distances with a quantified, bounded cost from SPFs. The measured intensity–encoding correlations underscore that transmitter characterization and implementation-aware proofs are necessary complements to raw key-rate optimization in practical QKD.