Papers
Topics
Authors
Recent
Search
2000 character limit reached

Experimental Quantum Key Distribution in an Indefinite Causal Order

Published 13 Aug 2026 in quant-ph | (2608.13561v1)

Abstract: In quantum physics the order in which different operations occur can be placed in superposition. The resulting processes have an indefinite causal order and are both of fundamental interest and can be viewed as a novel quantum resource that enables a variety of new protocols. Here we report an experimental implementation of one such protocol, where we perform BB84-like quantum cryptography by placing Alice and Bob's measurement-and-preparation operations in a photonic quantum SWITCH. By embedding Alice and Bob within the quantum SWITCH, the protocol achieves an average eavesdropper detection probability of 0.15±0.020.15 \pm 0.02 per shared qubit, with eavesdropper detection performed through measurements of the control qubit rather than by comparing the key. Unlike the standard BB84 and related schemes, which detect eavesdropping by publicly revealing and discarding a fraction of the raw key, our approach requires no disclosure of key material: every retained qubit can, in principle, be tested for eavesdropping while remaining available for key generation. The experiment relies on a new measurement technique that allows the polarization of a photon to be measured inside the quantum SWITCH without destroying path coherence. Although the present implementation does not yet constitute a secure quantum key distribution protocol, owing to the post-selection required for measurements within the quantum SWITCH, it provides a proof of principle that indefinite causal order can be exploited to detect eavesdropping without sacrificing key bits.

Summary

  • The paper demonstrates proof-of-principle QKD in a photonic quantum SWITCH, achieving a 0.964 ± 0.004 key-generation probability and detecting eavesdropping through control-state interference.
  • The experiment uses path-encoded control, polarization-encoded photons, and a time-delocalized ancilla measurement to preserve coherence while recording Bob’s measurement outcome inside the SWITCH.
  • The results show an average detection probability of 0.15 ± 0.02 against an ideal 0.125, but post-selection, imperfect visibility, and limited attack models mean composable security remains unproven.

Overview

This paper reports an experimental proof-of-principle demonstration of quantum key distribution (QKD) performed inside a photonic quantum SWITCH, implementing the protocol proposed by Spencer-Wood [spencer2025indefinite]. The central departure from BB84 and its variants is the mechanism of eavesdropper detection: rather than publicly revealing and discarding a subset of the raw key to estimate the quantum bit error rate, Alice and Bob monitor the control qubit of the quantum SWITCH. An eavesdropper acting between their operations disturbs the interference between the two alternative causal orders, leaving a measurable signature in the control degree of freedom while every retained qubit remains available for key generation. This removes the intrinsic trade-off between parameter estimation and key rate, which is particularly consequential in finite-size regimes [Tomamichel2012, Diamanti2016].

Protocol and theory

The protocol embeds both Alice's and Bob's measurement-and-preparation operations — modeled as identical random BB84 measurement channels M\mathcal{M} with uniformly random basis choice μ{0,1}\mu \in \{0,1\} — inside a quantum SWITCH controlled by a qubit prepared in +c\ket{+}_c. After basis reconciliation, only rounds with μ=μ\mu = \mu' are retained; on this subensemble the relevant Kraus operators commute, so the control qubit is left invariant and perfect correlations between the parties' outcomes are guaranteed. Formally, the reconciled channel factorizes as ωc(b,μPb(μ)ρsPb(μ))\omega_c \otimes (\sum_{b,\mu} P_b^{(\mu)} \rho_s P_b^{(\mu)}), i.e., honest operation leaves the control in +c\ket{+}_c.

Eavesdropping is detected through generalized commutators [Pb(μ),Ek,Pb(μ)]=Pb(μ)EkPb(μ)Pb(μ)EkPb(μ)[P_b^{(\mu)}, E_k, P_{b'}^{(\mu)}] = P_b^{(\mu)}E_kP_{b'}^{(\mu)} - P_{b'}^{(\mu)}E_kP_b^{(\mu)}: for an identity channel these vanish identically, whereas any nontrivial Eve channel can make them nonzero, populating the orthogonal control state c\ket{-}_c. The paper also notes that the architecture admits two distinct insertion points for attacks (Eve between Alice's operations and Yves at the second access point), and cites prior work showing that coordinated two-eavesdropper attacks cannot extract key information without inducing a nonzero c\ket{-}_c population; the experiment implements only the single-Eve case.

Experimental implementation

The platform encodes the control qubit in the path of a single photon and the target qubit in its polarization, following standard photonic quantum-SWITCH techniques. The principal technical obstacle is that Bob must obtain a classical record of his polarization outcome inside the SWITCH without destroying path coherence or the photon itself. The authors employ the time-delocalized ancilla measurement scheme of Ref. [valibouse2026time]: a post-selected PBS interaction between the system photon and an ancilla photon reproduces a CNOT gate, transferring the polarization outcome onto the ancilla. Crucially, the system and ancilla photons are pre-entangled in path via SPDC so that the ancilla coherently accompanies both causal-order branches; after the measurement interaction, interferometric recombination of the ancilla paths erases which-order information and restores the ICO.

After Bob's measurement, the logical control states become two-photon path Bell states (Φ+\ket{\Phi^+} and μ{0,1}\mu \in \{0,1\}0), distinguished by correlated versus anti-correlated port detections. These control outcomes can be disclosed publicly without revealing key information. Eve is simulated with polarizers at angle μ{0,1}\mu \in \{0,1\}1 (and μ{0,1}\mu \in \{0,1\}2) inserted in both branches, emulating a projective measure-and-reprepare attack; a genuine local readout for Eve would require an additional ancilla and was not implemented.

Results

In the absence of an eavesdropper, Alice and Bob establish a shared key bit with probability μ{0,1}\mu \in \{0,1\}3, with a false-positive detection probability of μ{0,1}\mu \in \{0,1\}4, attributed to finite interference visibility of the SWITCH.

With Eve present, the measured detection probabilities follow the theoretical prediction μ{0,1}\mu \in \{0,1\}5. For the representative case of μ{0,1}\mu \in \{0,1\}6 preparation and Eve measuring in the diagonal basis, theory predicts 25% and the experiment yields μ{0,1}\mu \in \{0,1\}7. Averaged over all four BB84 states, the detection probability is μ{0,1}\mu \in \{0,1\}8 per shared qubit against the ideal value of μ{0,1}\mu \in \{0,1\}9, with the excess consistent with the false-positive floor.

The mutual-information analysis shows that, averaged over the four BB84 states, +c\ket{+}_c0 bits, independent of Eve's angle, while Eve's information is maximized at +c\ket{+}_c1. Modeling partial attacks with strength +c\ket{+}_c2, the threshold at which Eve's information exceeds the legitimate mutual information is +c\ket{+}_c3, corresponding to a detection probability of approximately +c\ket{+}_c4. This means an attack must be detectable with probability above roughly 10% before it becomes informationally dominant — a concrete operating point for future security analyses.

Limitations and open questions

The authors are explicit that the present implementation does not constitute a QKD protocol with proven security. The entangling gates are probabilistic linear-optical operations relying on post-selection, leaving the post-selection loophole open; closing it would require deterministic photon–photon interactions via nonlinear light–matter interfaces such as cavity QED. Additionally, the security analysis covers only intercept-resend-type projective attacks within the SWITCH, not general coherent attacks, and the experimental Eve is a passive polarizer emulation rather than a full measure-and-reprepare device with local readout. Whether the control-qubit detection mechanism retains its advantage over key-sacrifice parameter estimation under composable finite-key security proofs, and what secret-key rates are achievable given the ~3% false-positive floor from imperfect SWITCH visibility, remain open questions.

Conclusion

This work provides the first experimental demonstration of QKD in an indefinite causal order, achieving a 96.4(4)% key-generation success probability upon post-selection and an average eavesdropper detection probability of +c\ket{+}_c5 per qubit, in agreement with the theoretical 0.125. Its distinctive contribution is showing that eavesdropper detection can be shifted entirely onto the control degree of freedom of a quantum SWITCH, eliminating the need to sacrifice raw key bits for parameter estimation. The result establishes indefinite causal order as an operational resource for quantum cryptography, pending resolution of the post-selection and general-security limitations inherent to the current photonic implementation.

Paper to Video (Beta)

No one has generated a video about this paper yet.

Whiteboard

No one has generated a whiteboard explanation for this paper yet.

Tweets

Sign up for free to view the 1 tweet with 0 likes about this paper.