Papers
Topics
Authors
Recent
Search
2000 character limit reached

Point-to-Multipoint COW QKD Protocol

Updated 10 January 2026
  • The paper demonstrates a point-to-multipoint extension of the COW QKD protocol that enables simultaneous secret key distribution to multiple receivers using an efficient XOR key combination.
  • It employs dual-SPD and dual-receiver configurations along with precise fiber-optic attenuation and optimized detector settings to enhance secret key rates while keeping QBER below 6%.
  • The security analysis underscores that reducing photon intensity to around 0.2 mitigates collective beam-splitting attacks, supporting robust secure group communications.

The point-to-multipoint extension of the Coherent-One-Way (COW) Quantum Key Distribution (QKD) protocol is an experimentally validated architecture enabling a single quantum transmitter to distribute secret keys simultaneously to multiple receivers over separate channels. By leveraging component and post-processing optimizations, this protocol addresses experimental bottlenecks arising from detector limitations, while extending standard two-party QKD to a network regime suitable for secure group communication. Security analysis, implementation details, and empirical benchmarks demonstrate the protocol’s viability under realistic device constraints and collective attack models (Abhignan et al., 8 Jan 2026).

1. Fundamentals of the COW QKD Protocol

The Coherent-One-Way (COW) protocol encodes logical bits using time-bin qubits, where Alice—serving as the transmitter—sends either

∣0⟩t∣μ⟩t−τ(bit 1)\ket{0}_t\ket{\sqrt\mu}_{t-\tau} \quad(\text{bit } 1)

or

∣μ⟩t∣0⟩t−τ(bit 0)\ket{\sqrt\mu}_t\ket{0}_{t-\tau} \quad(\text{bit } 0)

in consecutive time bins tt and t−τt-\tau. With probability ff, Alice introduces "decoy" states ∣μ⟩t∣μ⟩t−τ\ket{\sqrt\mu}_t\ket{\sqrt\mu}_{t-\tau} to enable quantum channel monitoring. Here, μ\mu is the mean photon number per pulse, and τ=1/F\tau = 1/F, with FF the system repetition rate.

After transmission, Bob(s) announce detected pulses (time bins), Alice identifies decoys, and sifting yields a sifted-basis rate SZS_Z (bits/s). The quantum bit error rate (QBER) is defined as

∣μ⟩t∣0⟩t−τ(bit 0)\ket{\sqrt\mu}_t\ket{0}_{t-\tau} \quad(\text{bit } 0)0

With error correction inefficiency ∣μ⟩t∣0⟩t−τ(bit 0)\ket{\sqrt\mu}_t\ket{0}_{t-\tau} \quad(\text{bit } 0)1 (e.g., ∣μ⟩t∣0⟩t−τ(bit 0)\ket{\sqrt\mu}_t\ket{0}_{t-\tau} \quad(\text{bit } 0)2), the asymptotic Devetak–Winter bound gives the secure key rate: ∣μ⟩t∣0⟩t−τ(bit 0)\ket{\sqrt\mu}_t\ket{0}_{t-\tau} \quad(\text{bit } 0)3 where ∣μ⟩t∣0⟩t−τ(bit 0)\ket{\sqrt\mu}_t\ket{0}_{t-\tau} \quad(\text{bit } 0)4 is the binary entropy and ∣μ⟩t∣0⟩t−τ(bit 0)\ket{\sqrt\mu}_t\ket{0}_{t-\tau} \quad(\text{bit } 0)5 is the privacy amplification penalty.

2. Experimental Apparatus and Detector Enhancement

The experimental setup features a 1550.12 nm CW laser carved by an intensity modulator controlled at ∣μ⟩t∣0⟩t−τ(bit 0)\ket{\sqrt\mu}_t\ket{0}_{t-\tau} \quad(\text{bit } 0)6 GHz, stabilized via a 1% bias-controller loop, and followed by two variable optical attenuators (VOA∣μ⟩t∣0⟩t−τ(bit 0)\ket{\sqrt\mu}_t\ket{0}_{t-\tau} \quad(\text{bit } 0)7, VOA∣μ⟩t∣0⟩t−τ(bit 0)\ket{\sqrt\mu}_t\ket{0}_{t-\tau} \quad(\text{bit } 0)8) to set ∣μ⟩t∣0⟩t−τ(bit 0)\ket{\sqrt\mu}_t\ket{0}_{t-\tau} \quad(\text{bit } 0)9. The attenuation tt0 is determined by

tt1

where tt2 is modulator output, tt3 nm.

Bob, the receiver, employs a 90:10 fiber beamsplitter (BS) to route 90% of incoming photons to the data line and 10% to a monitoring interferometer (not used for this improvement). On the data line, an additional tt4 (50:50) splitter feeds two InGaAs/InP single-photon detectors (SPDs), labeled SPDtt5 and SPDtt6, each characterized by quantum efficiency tt7 and dead time tt8.

Theoretical per-detector count rates (accounting for fiber loss tt9 dB/km and distance t−τt-\tau0) are given by

t−τt-\tau1

Factoring in detector dead time,

t−τt-\tau2

Experimental rates t−τt-\tau3 approach t−τt-\tau4 for a single SPD and t−τt-\tau5 for dual SPDs before saturation, thus the data line split between two SPDs mitigates the throughput limit imposed by detector dead time.

3. Point-to-Multipoint Network Architecture

Point-to-multipoint extension involves distributing Alice’s modulated quantum pulse train to two independent receivers (Bobs), establishing two parallel COW QKD channels. Post-attenuation, a 50:50 BS splits the modulated sequence, and each branch passes through individual attenuator chains and fiber spools of length t−τt-\tau6. Synchronized by a shared FPGA clock (or calibrated with fixed delay), both Bobs maintain time alignment for coherent state detection.

Each Bob's measurement setup mirrors the single-receiver configuration: a 90:10 BS, a 50:50 splitter, and two SPDs. This two-channel extension is directly compatible with generic COW protocol deployments.

4. Secret-Key Generation and Post-Processing Workflow

The secret-key generation process for the dual-receiver architecture comprises the following steps:

  • Sifting: Each Bob t−τt-\tau7 records counts t−τt-\tau8 in non-decoy time bins; decoy bins are excluded. Sifted key rate is t−τt-\tau9 (minus decoys).
  • Error Correction: A disclosure ratio ff0 of sifted bits estimates ff1. Error correction—via low-density parity-check codes—leaks ff2 bits.
  • Privacy Amplification: With compression ratio ff3 (up to 90%), the final SKR per Bob is

ff4

  • Key Combination: Alice aligns key lengths ff5 and broadcasts the XOR ff6 using one-time pad. Bob 1 can reconstruct ff7; Bob 2 reconstructs ff8, and all three share ff9 of length ∣μ⟩t∣μ⟩t−τ\ket{\sqrt\mu}_t\ket{\sqrt\mu}_{t-\tau}0.
  • Aggregate Key Rate: Since one raw key is sacrificed by XOR, the end-user shared SKR is

∣μ⟩t∣μ⟩t−τ\ket{\sqrt\mu}_t\ket{\sqrt\mu}_{t-\tau}1

5. Empirical Performance Benchmarks

Experimental benchmarking demonstrates efficiency gains from both dual-SPD and dual-Bob approaches:

Channel Length (∣μ⟩t∣μ⟩t−τ\ket{\sqrt\mu}_t\ket{\sqrt\mu}_{t-\tau}2) ∣μ⟩t∣μ⟩t−τ\ket{\sqrt\mu}_t\ket{\sqrt\mu}_{t-\tau}3 ∣μ⟩t∣μ⟩t−τ\ket{\sqrt\mu}_t\ket{\sqrt\mu}_{t-\tau}4 (∣μ⟩t∣μ⟩t−τ\ket{\sqrt\mu}_t\ket{\sqrt\mu}_{t-\tau}5s) 1 SPD SKR (kb/s) 2 SPDs SKR (kb/s) QBER (%)
80 km 0.15 15 2.1 3.7 3–5
100 km 0.20 20 1.8 2.9 4–6
120 km – – – 50–80% gain <6

In the dual-Bob scenario at ∣μ⟩t∣μ⟩t−τ\ket{\sqrt\mu}_t\ket{\sqrt\mu}_{t-\tau}6 km:

  • For ∣μ⟩t∣μ⟩t−τ\ket{\sqrt\mu}_t\ket{\sqrt\mu}_{t-\tau}7, each Bob achieves SKR ∣μ⟩t∣μ⟩t−τ\ket{\sqrt\mu}_t\ket{\sqrt\mu}_{t-\tau}8 kb/s, QBER ∣μ⟩t∣μ⟩t−τ\ket{\sqrt\mu}_t\ket{\sqrt\mu}_{t-\tau}9\%.
  • For μ\mu0, SKR μ\mu1 kb/s per Bob with improved QBER.
  • The shared-key rate μ\mu2 reflects μ\mu3; aggregate SKR μ\mu4 kb/s.

6. Security Analysis and Parameter Optimization

The security proof utilizes the asymptotic, collective-attack model (Devetak–Winter bound). The principal threat modeled is the collective beam-splitting attack (BSA), where Eve replaces the transmission line by a lossless channel and a beamsplitter of transmission μ\mu5, retaining a mode with amplitude μ\mu6 and inter-bit overlap μ\mu7. The Holevo information per pulse is

μ\mu8

and Bob’s per-pulse detection probability is μ\mu9. The per-pulse secure rate is

Ï„=1/F\tau = 1/F0

In the dual-Bob configuration, a worst-case scenario is assumed: Eve attacks both branches coherently, doubling her Holevo gain Ï„=1/F\tau = 1/F1.

Optimizing τ=1/F\tau = 1/F2 is crucial: higher τ=1/F\tau = 1/F3 raises Bob’s click rate but increases τ=1/F\tau = 1/F4, reducing long-distance security. For τ=1/F\tau = 1/F5 km in the dual-Bob scenario, τ=1/F\tau = 1/F6 offers superior security rates relative to τ=1/F\tau = 1/F7. Detector settings (τ=1/F\tau = 1/F8s, τ=1/F\tau = 1/F9) are adjusted to optimize throughput against QBER and loss constraints.

7. Conclusion and Practical Implications

By (i) splitting each data line into two SPDs to bypass detector saturation limits, and (ii) constructing a three-party shared key via the XOR of two independently generated keys, the point-to-multipoint COW QKD protocol demonstrates substantial increases in achievable secret-key rates and user scalability. Experimentally, QBER remains within the established threshold (FF06%), and the approach is generalizable to further COW implementations. Both empirical observation and theoretical BSA-derived limits confirm that lower FF1 values (around 0.2) are optimal under broadcast-channel and collective attack security conditions (Abhignan et al., 8 Jan 2026).

Definition Search Book Streamline Icon: https://streamlinehq.com
References (1)

Topic to Video (Beta)

No one has generated a video about this topic yet.

Whiteboard

No one has generated a whiteboard explanation for this topic yet.

Follow Topic

Get notified by email when new papers are published related to Point-to-Multipoint COW QKD Protocol.