Continuous-Variable Quantum Access Networks
- Continuous-variable quantum access networks are multiuser quantum systems that encode information in optical-field quadratures to enable secure key and entanglement distribution.
- They exploit passive optical splitting and coherent detection, underpinning diverse architectures like broadcast, TDM, and relay-mediated network designs.
- Experimental demonstrations show Mbit/s-level secure key rates over commercial fibers, highlighting scalability challenges and finite-size security considerations.
Continuous-variable quantum access networks are multiuser quantum communication systems that extend continuous-variable quantum key distribution and entanglement distribution from point-to-point links to access-network topologies such as passive optical networks, hub-and-spoke repeater networks, and relay-mediated star networks. They encode information in optical-field quadratures, rely on coherent detection, and exploit the fact that a coherently prepared optical field can be passively split and measured concurrently by many receivers. As a result, the subject now spans downstream broadcast access, upstream time-division access, passive simultaneous multiuser PONs, round-trip and multiband schemes, entanglement-in-the-middle networks, thermal-state and frequency-comb broadcast systems, and CV quantum switches for multi-flow entanglement service (Usenko et al., 22 Jan 2025, Hajomer et al., 2024, Tillman et al., 2022).
1. Physical basis and channel description
Continuous-variable quantum networking is built on bosonic modes whose information-bearing observables are the Hermitian quadrature operators. One widely used convention writes
with , while much of the CV-QKD literature normalizes vacuum shot noise to $1$ SNU by choosing (Tillman et al., 2022, Usenko et al., 22 Jan 2025). Gaussian states dominate access-network proposals because they are compatible with telecom lasers, electro-optic modulation, and homodyne or heterodyne detection. In the phase-space description, a coherent state has covariance , a squeezed state has , and a two-mode squeezed vacuum is
with the Fock-basis form
used as the canonical entangled resource in repeater-oriented architectures (Usenko et al., 22 Jan 2025, Tillman et al., 2022).
The access-network relevance of CV encodings is twofold. First, by “virtue of the infinite dimensionality of the associated Hilbert space,” CV states “can enable higher communication rates compared to single photon-based qubit encodings” (Tillman et al., 2022). Second, passive optical splitting is deterministic for coherent-state CV signals. In downstream broadcast models, a beamsplitter with user-port ratio gives an effective per-user transmittance , or 0 for cascaded stages, with 1 and equal 2-way splitting incurring 3 dB loss per user (Huang et al., 2021). In passive-broadcast PONs, the received quadrature can therefore be modeled as
4
which is the elementary relation underpinning downstream CV-QKD and simultaneous multiuser CV-QPON protocols (Hajomer et al., 2024).
For entanglement distribution rather than key distribution, the pure-loss benchmark remains fundamental. Direct transmission with TMSV states over a channel of transmissivity 5 achieves
6
with 7 for 8. The CV repeater architecture used in the CV quantum switch replaces this scaling by end-to-end rates 9 through multiplexed TMSV generation, quantum-scissors noiseless linear amplification, and dual-homodyne entanglement swapping (Tillman et al., 2022).
2. Architectural families
A central architectural divide is between downstream broadcast, upstream aggregation, and relay- or entanglement-based access. In downstream CV-QKD, the transmitter is centralized at the optical line terminal and broadcasts Gaussian-modulated coherent states through a passive optical distribution network to multiple optical network units. The ODN requires only passive beamsplitters or couplers, no active switching, and either a transmitted LO or a local LO can be used at the receivers. A security reduction based on a strengthened Eve allows key extraction with one activated ONU at a time using only OLT–ONU data, while passive broadcast remains deterministic for coherent-state CV signals (Huang et al., 2021). A different downstream model, the continuous-variable quantum passive optical network, uses the same modulated optical field for all users and exploits “the inherent wave-like property of coherent states split at a beam splitter and electric-field quadrature measurements” to achieve deterministic and simultaneous secret-key generation for all users (Hajomer et al., 2024).
Upstream CV access reverses the terminal roles. In the first experimental upstream transmission quantum access network, each ONU hosts a GG02 transmitter and sends a polarization-multiplexed signal and transmitted LO toward a single centralized OLT receiver through a shared ODN, with time-division multiplexing used to avoid slot collisions (Wang et al., 2023). A round-trip variant centralizes even more hardware: the quantum line terminal launches a continuous-wave carrier, each quantum network unit is a simple plug-in modulator node, and all returned signals are recombined onto a single fiber and measured by one coherent receiver at the QLT. Multiuser separation is then performed in the RF domain by assigning each user a distinct subcarrier band on the same optical carrier (Xu et al., 2023).
Relay and entanglement-based architectures widen the access-network design space. In the untrusted-relay model, two end-users send Gaussian-modulated coherent states to a central access point that performs a CV Bell detection and broadcasts the result; security is maintained even when the relay is fully untrusted and the links are insecure (Pirandola et al., 2013). In a more connected star architecture, an entangled optical frequency comb generated by a type-II OPO sits at a central node and routes signal-idler comb teeth to user pairs, yielding a fully connected multi-user CVQKD network in which simultaneous pairwise keys are limited by the number $1$0 of usable entangled pairs and full connectivity requires $1$1 (Zhong et al., 31 Dec 2025). At larger scale, a passive thermal-state QAN replaces active Gaussian modulation by a broadband ASE thermal source, slices it into $1$2 frequency modes, and then broadcasts each slice through $1$3 power branches, creating $1$4 user channels from a single source (Xu et al., 19 May 2026).
Entanglement-service access networks also admit a hub-and-spoke repeater interpretation. The CV quantum switch is a central repeating switch that attempts heralded CV entanglement generation on each spoke, stores successful elementary links for one time step, and performs dual-homodyne entanglement swapping across selected ports under a Max-Weight scheduler. The same hub-and-spoke logic underlies multi-flow access service for bipartite entanglement requests, rather than secret-key generation alone (Tillman et al., 2022).
3. Security models and rate formulas
The dominant security framework is reverse-reconciled CV-QKD under collective Gaussian attacks. A generic asymptotic key rate is
$1$5
with $1$6 the reconciliation efficiency, $1$7 the classical mutual information, and $1$8 Eve’s Holevo information. For coherent-state CV-QKD, standard expressions include
$1$9
and the input-referred total noise is often written as
0
(Huang et al., 2021). In broadcast field trials with heterodyne detection and local LO reception, the per-user formulas are written as
1
with the shared modulation variance 2 set before passive splitting and therefore common to all users (Zhang et al., 17 Jun 2026).
Multiuser access modifies the adversary model. In downstream passive broadcast, other ONUs and all non-activated ODN outputs can be absorbed into a strengthened Eve 3, so that the Holevo term is computed from the two-mode covariance matrix 4 between Alice and the activated ONU, while secrecy against honest-but-curious or malicious in-network parties follows by monotonicity of the Holevo bound (Huang et al., 2021). In untrusted-relay networks, any joint attack compatible with the observed statistics can be reduced to a scenario in which the relay performs the proper CV Bell detection and Eve attacks only the links, which is the continuous-variable measurement-device-independent reduction for this topology (Pirandola et al., 2013). In CV-QPON, the untrusted broadcast protocol conservatively places the other 5 users inside Eve’s system, whereas the trusted broadcast protocol hierarchically moves selected users into a trusted subsystem, reducing 6 without changing 7 (Hajomer et al., 2024).
Finite-size and composable analyses are no longer peripheral. In the active 8 multi-user CV-QN, the composable finite-size key length for user 9 is written as
0
and the paper also introduces a chain-rule decomposition of the joint network key into per-user increments without double counting shared correlations (Zhang et al., 30 Apr 2026). The field QTTH trial remains asymptotically secure in its main results, but its composable simulation makes the block-length challenge explicit: for User 1 under a 1 split, positive composable SKR requires 2 symbols under the chosen security parameters (Zhang et al., 17 Jun 2026).
4. Multiple access, scheduling, and routing
Once CV links are shared, access-network control becomes a resource-allocation problem. In the entanglement-service setting, requests of type 3 arrive at a switch with mean 4, and a matching vector 5 is feasible only if no user participates in more than one served request in the same time step. The CV quantum switch chooses
6
where 7 is the request backlog, 8 is link availability, and 9 is the swapping success probability; in the model with dual homodyne swapping, 0. Under one-time-step switch memories, Max-Weight stabilizes all arrival rates in the capacity region, and explicit request-rate regions were computed for contending, partially disjoint, and fully disjoint three-flow networks (Tillman et al., 2022).
Broadcast QKD access networks face a different control problem because the same modulation variance must serve heterogeneous users. The field QTTH study formulates this through the 1-fair utility
2
with the shared-variance choice 3. The limits 4 and 5 recover sum-rate maximization and max-min fairness, respectively; in the reported field trial, the max-min solution selected 6 SNU (Zhang et al., 17 Jun 2026).
At the physical and MAC layers, several multiple-access schemes have been proposed. AMQD-MQA divides each user’s Gaussian-modulated input into Gaussian subcarrier CVs via an inverse CVQFT and dynamically assigns subcarriers and quadratures through a binary rate-selection matrix 7. In the low-SNR regime characteristic of long-distance CV-QKD, it is capacity-achieving with constant per-subcarrier modulation variance and only partial channel side information (Gyongyosi et al., 2013). A different approach, q-CDMA-based CV-QKD, uses chaotic phase shifters and synchronization so that the intended user survives decoding with gain 8, whereas the cross-user term is suppressed by 9, with 0 determined by the chaotic phase spectrum (Ali et al., 13 Feb 2025).
Routing and network design also appear in entanglement-distribution models. For CV graph-state networks, the squeezing cost
1
is determined by the adjacency spectrum, and homodyne routing along parallel paths can boost end-to-end entanglement; for diamond networks with 2 parallel paths,
3
after measuring the central nodes in 4 (Centrone et al., 2021). In heterogeneous fiber/free-space CVQKD networks, dynamic routing has been formulated through the link-capacity metric
5
which treats secret-key distribution as a graph problem over time-varying access and backbone links (Sayat et al., 17 Feb 2025). A complementary monitoring layer is provided by capacity-detection methods that certify non-zero quantum capacity of CV channels and memories without full process tomography, using either finitely squeezed states and homodyne measurements or coherent states and heterodyne detection (Wu et al., 2021).
5. Experimental realizations and reported regimes
Representative demonstrations already span passive broadcast, centralized upstream reception, active finite-size networks, and high-capacity passive thermal broadcasting.
| System | Topology | Reported result |
|---|---|---|
| Downstream CV-QKD access | OLT to passive ODN to ONUs | Up to 64 ONUs feasible at 30 km (Huang et al., 2021) |
| Upstream CV-QKD access | Two ONUs to one OLT via TDM | 390 kbps aggregate at 5 MHz; scaling analysis to 8 ONUs with 25 ns slots (Wang et al., 2023) |
| CV-QPON | 6 passive broadcast, 11 km per user | 1.5 Mbit/s untrusted and 2.1 Mbit/s trusted total network key generation (Hajomer et al., 2024) |
| Round-trip multi-band QAN | Single QLT laser/receiver, three simultaneous QNUs | 600–800 bits/s per user under 30 km standard fiber (Xu et al., 2023) |
| Active 7 finite-size CV-QN | 10 km backbone + 1 km last-mile | Total about 8 bits/channel use (Zhang et al., 30 Apr 2026) |
| Field QTTH broadcast CV-QAN | 9 commercial-fiber deployment | Per-user asymptotic SKRs 0–1 Mbit/s; 2 Mbit/s over six analyzed users (Zhang et al., 17 Jun 2026) |
| Thermal-state passive QAN | 19 frequency slices 3 16 branches | 13.76 Gbps @ 304 users over 5 km asymptotic; 3.60 Gbps finite-size (Xu et al., 19 May 2026) |
These demonstrations illustrate several distinct operating regimes. First, passive broadcast can already support deterministic simultaneous service over standard access fibers, with the untrusted and trusted CV-QPON protocols showing how the assumed trust hierarchy directly changes aggregate network rate (Hajomer et al., 2024). Second, centralized-receiver designs remain viable in both upstream and round-trip form, but their rates are constrained by slotting, detector bandwidth, and crosstalk control (Wang et al., 2023, Xu et al., 2023). Third, field-deployed broadcast CV-QANs have reached Mbit/s-level per-user asymptotic secure key rates over commercial fiber while explicitly confronting link asymmetry and shared-parameter optimization (Zhang et al., 17 Jun 2026). Fourth, passive broadcast can scale well beyond tens of users when Gaussian randomness is supplied by a single broadband thermal source instead of per-channel modulators and QRNGs (Xu et al., 19 May 2026).
A separate experimental direction emphasizes connectivity rather than fan-out. The entangled optical frequency-comb network is designed for simultaneous fully connected pairwise CVQKD, is analyzed asymptotically, and is reported to be feasible for short-distance deployment when loss and noise are tightly controlled; in that setting, loss is identified as the main performance limiter (Zhong et al., 31 Dec 2025).
6. Limitations, trust assumptions, and open directions
The main constraints are now well characterized. In passive broadcast systems, splitting loss lowers per-user SNR, and in downstream security models the strengthened-Eve treatment of other ONUs increases the Holevo penalty as user count grows (Huang et al., 2021). Field deployments add asymmetry in drop-fiber length, splitter-port imbalance, and insertion loss, so a single shared 4 cannot simultaneously optimize all users; larger splits such as 5 and 6 therefore demand lower-noise coherent receivers, higher detector efficiency, stronger coding, and tighter environmental stabilization (Zhang et al., 17 Jun 2026). The CV quantum switch analysis assumes unconstrained quantum resources, synchronized clocks, and one-step switch memories; the same work explicitly identifies limited hardware, memory-fidelity decay, and longer switch-memory lifetimes as open issues (Tillman et al., 2022). The frequency-comb architecture scales in spectral resources but requires 7 LO generation and is limited by modulator bandwidth and waveshaper spacing (Zhong et al., 31 Dec 2025). Thermal-state broadcasting removes hundreds of active modulators and QRNGs, but its multimode security analysis must track residual broadcast-induced correlations and finite-size penalties (Xu et al., 19 May 2026). CV-QPON itself still lacks a dedicated multiuser finite-size theory for broadcast operation (Hajomer et al., 2024).
Network-level operation raises a second set of questions. Capacity-detection methods can certify or monitor the quantum capacity of CV channels and memories without full tomography, even in finite-use, correlated, and adversarial scenarios (Wu et al., 2021). Dynamic global CVQKD studies, by contrast, model secret-key distribution as a spatiotemporal graph problem and use link capacity as a routing metric across fiber, satellite-to-ground, inter-satellite, and underwater segments (Sayat et al., 17 Feb 2025). Graph-state analyses add a complementary resource perspective in which star and diamond topologies have low squeezing rank and parallel-path routing can increase delivered entanglement (Centrone et al., 2021). This suggests a unified future direction in which CV access networks are co-designed across physical-layer cost, trust model, finite-size security, and dynamic routing, rather than treated as isolated QKD links.