Papers
Topics
Authors
Recent
Search
2000 character limit reached

QCCC Key Agreement Overview

Updated 14 July 2026
  • QCCC key agreement is a multiparty quantum protocol enabling all users to share a common, information-theoretically secure secret key.
  • It employs architectures such as GHZ-based entanglement, twin-field interference, and measurement-device-independent schemes for robust key establishment.
  • Finite-key analysis and selective post-processing techniques ensure security against quantum attacks while adapting to diverse network trust models.

Searching arXiv for relevant QCKA/QCCC papers to ground the article. QCCC key agreement denotes quantum conference-call or conference-channel key agreement: a multiparty cryptographic task in which several users establish a single common secret key with information-theoretic security, rather than a collection of pairwise keys. In the literature this task is most commonly called quantum conference key agreement (QCKA) or quantum cryptographic conferencing (QCC), and the terminology is used interchangeably when the objective is that all honest parties hold the same final key while an adversary learns essentially nothing about it (Amer et al., 2022). Across the current research landscape, QCCC key agreement appears in several architectural forms: entanglement-based GHZ protocols, weak-coherent-pulse interference protocols inspired by twin-field QKD, measurement-device-independent constructions, source-independent schemes, bosonic broadcast-channel formulations, and controlled or anonymous variants (Amer et al., 2022, Carrara et al., 2022, Lu et al., 2024, Bao et al., 2024, Pereg et al., 2021, Hahn et al., 2020).

1. Definition and problem model

QCCC key agreement is the multi-party generalization of QKD. In the canonical formulation there are p+1p+1 honest users, one Alice and pp Bobs B1,,BpB_1,\dots,B_p, and the goal is that all p+1p+1 parties agree on the same secret key KK, uniformly random and information-theoretically secure against an unbounded adversary Eve (Amer et al., 2022). In the experimental and networking literature the same task is described as giving NN authenticated users a common key that any member can use to encrypt broadcast messages to all others, with correctness and secrecy defined in the usual composable sense (2002.01491).

The quantum resource depends on the protocol family. In entanglement-based QCKA, Alice may prepare and distribute multipartite GHZ states, or, in the security proof, Eve may be allowed to prepare an arbitrary global state ψAB1BpE\ket{\psi}_{AB_1\cdots B_pE} on the honest users and her side information (Amer et al., 2022). In prepare-and-measure and interference-based variants, the users instead send weak coherent pulses to an untrusted relay, and effective GHZ- or W-like correlations are reconstructed from central interference and public post-selection (Carrara et al., 2022, Lu et al., 2024, Li et al., 2024).

A central distinction from classical group key agreement is the security model. Classical conference key establishment is usually based on computational assumptions, whereas QCCC key agreement seeks information-theoretic security against arbitrary quantum attacks (Amer et al., 2022). A central distinction from standard two-party QKD is that security and post-processing must guarantee equality of the final key across all honest participants, while parameter estimation and reconciliation must cope with multiple error patterns rather than a single pairwise channel (Amer et al., 2022, Thomas et al., 4 May 2026).

The composable secrecy condition is typically stated in trace distance. For a classical key KK and Eve’s system EE, one requires

12ρKEτKρE1ε,\frac{1}{2}\Bigl\|\rho_{KE}-\tau_K\otimes \rho_E\Bigr\|_1 \le \varepsilon,

where pp0 is the perfectly uniform independent key state (Amer et al., 2022). Correctness in the multipartite setting requires that, except with probability pp1, all honest users’ key registers coincide (Amer et al., 2022).

2. GHZ-based entanglement protocols

The most direct formulation of QCCC key agreement uses multipartite GHZ states. In the high-dimensional protocol of "High-Dimensional Quantum Conference Key Agreement" (Amer et al., 2022), the ideal one-round source state is

pp2

where each subsystem is a qudit in pp3. Here “high-dimensional” means pp4, so each signal is a qudit rather than a qubit and contributes pp5 raw key bits when measured in the computational basis (Amer et al., 2022).

The protocol uses two mutually unbiased bases. The computational basis is

pp6

and the Fourier basis is

pp7

Rounds in the pp8 basis are used for key generation, while rounds in pp9 are used for parameter estimation (Amer et al., 2022). In ideal B1,,BpB_1,\dots,B_p0-basis rounds, Alice and all Bobs obtain perfectly correlated symbols. In ideal B1,,BpB_1,\dots,B_p1-basis rounds, only outcome tuples satisfying

B1,,BpB_1,\dots,B_p2

occur with nonzero probability, so nonzero modular sums are treated as test errors (Amer et al., 2022).

A related qubit realization was demonstrated experimentally in "Experimental quantum conference key agreement" (2002.01491). That work implemented the B1,,BpB_1,\dots,B_p3-BB84 protocol for B1,,BpB_1,\dots,B_p4 users with the four-qubit GHZ state

B1,,BpB_1,\dots,B_p5

distributed over up to B1,,BpB_1,\dots,B_p6 km of fibre (2002.01491). Type-1 rounds used B1,,BpB_1,\dots,B_p7-basis measurements for raw key generation and Type-2 rounds used B1,,BpB_1,\dots,B_p8-basis measurements for phase-error estimation. Under finite-key analysis, the experiment established B1,,BpB_1,\dots,B_p9 bits of secure conference key and used p+1p+10 bits to one-time-pad encrypt an image shared among four users (2002.01491).

GHZ-based protocols are also the natural setting for variants such as anonymous QCKA and loss-resilient QCKA. "Anonymous Quantum Conference Key Agreement" (Hahn et al., 2020) formalizes anonymity for the multiparty key-agreement task and constructs an anonymous GHZ-based protocol in which the identities of sender and receivers are hidden from a realistic adversary. "Quantum Conference Key Agreement with Photon Loss" (Singkanipa et al., 2021) studies a loss-resilient GHZ protocol based on redundant encoding and error correction, showing a transmission success factor

p+1p+11

for the encoded scheme, compared with p+1p+12 for the non-encoded transmission stage, while also emphasizing the large source and gate overhead needed to realize the encoded state (Singkanipa et al., 2021).

3. Security proofs and finite-key analysis

A defining feature of the modern QCCC literature is the move from asymptotic or collective-attack claims to finite-key security against general attacks. The high-dimensional GHZ protocol of (Amer et al., 2022) proves information-theoretic security against arbitrary coherent attacks in the finite-key scenario by combining three ingredients: a Bouman–Fehr quantum sampling argument, a high-dimensional min-entropy bound, and standard privacy amplification.

The sampling stage chooses a random subset p+1p+13 of size p+1p+14 for testing in the p+1p+15 basis and uses the relative Hamming weight p+1p+16 of nonzero modular sums as the observed test statistic. The classical sampling deviation obeys

p+1p+17

and Bouman–Fehr’s lifting theorem yields an ideal-state approximation at trace distance p+1p+18 for a suitable choice of p+1p+19 (Amer et al., 2022).

The key operational quantity is the conditional quantum min-entropy of Alice’s raw key register given Eve. For the ideal state, the central entropy bound is

KK0

where KK1 is the KK2-ary entropy function (Amer et al., 2022). After accounting for one-way error correction leakage and privacy amplification, the final finite-key key length is bounded by

KK3

In the depolarizing-channel evaluation, this becomes an explicit observable-rate expression in terms of KK4 and KK5 (Amer et al., 2022).

Finite-key methodology also appears in prepare-and-measure tripartite protocols. "Finite-key Analysis for Quantum Conference Key Agreement with Asymmetric Channels" (Li et al., 2021) studies an SNS twin-field QCKA protocol under asymmetric channels and gives a composable finite-key key-length bound

KK6

with KK7, KK8, and KK9 obtained by decoy-state estimation, Chernoff bounds, and random sampling without replacement (Li et al., 2021). That work explicitly targets asymmetric fibre lengths and removes the symmetry-parameter restriction of earlier twin-field-inspired conference protocols through the constraint

NN0

which enforces equality of the single-photon density matrices in the NN1 and NN2 bases (Li et al., 2021).

In interference-based MDI conference protocols, finite-key composability is likewise explicit. "Repeater-like asynchronous measurement-device-independent quantum conference key agreement" (Lu et al., 2024) gives, for the three-user case, the finite-key lower bound

NN3

with the total security parameter written as NN4 (Lu et al., 2024).

4. Interference-based, twin-field, and MDI approaches

A major strand of QCCC research replaces direct GHZ distribution by central interference of weak coherent pulses. These schemes seek the long-distance advantages of twin-field QKD while keeping the task multiparty.

"Phase-Matching Quantum Cryptographic Conferencing" (Zhao et al., 2020) combines GHZ post-selection and twin-field ideas in an MDI architecture. Each of NN5 users sends a weak coherent state

NN6

to a central untrusted node. The node implements a chain of NN7 interference branches, each with a 50:50 beam splitter and two detectors, and a successful global event consists of exactly one click in each branch (Zhao et al., 2020). In the phase-sliced implementation, the asymptotic conference key rate is

NN8

The key claim is the scaling improvement from NN9 for earlier MDI-QCC based on GHZ post-selection to ψAB1BpE\ket{\psi}_{AB_1\cdots B_pE}0 for PM-QCC (Zhao et al., 2020).

"Overcoming fundamental bounds on quantum conference key agreement" (Carrara et al., 2022) generalizes twin-field QKD to arbitrary ψAB1BpE\ket{\psi}_{AB_1\cdots B_pE}1 users with a balanced beam splitter network at an untrusted central relay. Each round uses either coherent states ψAB1BpE\ket{\psi}_{AB_1\cdots B_pE}2 in key-generation mode or phase-randomized coherent states ψAB1BpE\ket{\psi}_{AB_1\cdots B_pE}3 in decoy mode. Conditioning on single-click events ψAB1BpE\ket{\psi}_{AB_1\cdots B_pE}4, the asymptotic key rate takes the form

ψAB1BpE\ket{\psi}_{AB_1\cdots B_pE}5

where ψAB1BpE\ket{\psi}_{AB_1\cdots B_pE}6 is a decoy-state upper bound on the phase error and ψAB1BpE\ket{\psi}_{AB_1\cdots B_pE}7 are observed marginal error rates (Carrara et al., 2022). In the high-loss regime the protocol achieves ψAB1BpE\ket{\psi}_{AB_1\cdots B_pE}8 scaling, while the compared multicast repeaterless bounds scale as ψAB1BpE\ket{\psi}_{AB_1\cdots B_pE}9, and the simulations show rate regions that exceed those bounds for realistic parameters (Carrara et al., 2022).

Tripartite twin-field adaptations also include "Coherent one-way quantum conference key agreement based on twin field" (Cao et al., 2021), which uses coherent states with intensities KK0 and KK1, removes phase randomization and multiple intensity modulation, and derives the asymptotic conference key rate

KK2

with

KK3

That protocol is asymptotic, secure against a large class of collective attacks through a reduction to coherent one-way QKD, and is notable for explicit KK4 scaling with total efficiency (Cao et al., 2021).

A more recent interference-based direction emphasizes implementation security. "Fully Passive Quantum Conference Key Agreement" (Li et al., 2024) combines an interference-based prepare-and-measure CKA with fully passive source design. Its asymptotic key rate is written as

KK5

or, in the refined version that sums over all slice combinations, as a slice-averaged expression over KK6 combinations in the four-user case (Li et al., 2024). The stated purpose is to eliminate source-modulation side channels while retaining the detector-side robustness of the MDI architecture (Li et al., 2024).

5. Network models, source assumptions, and practical variants

A striking feature of the field is the diversity of trust and network models. At one extreme are device-dependent GHZ protocols with trusted measurement devices and an untrusted source (Amer et al., 2022). At another are MDI schemes in which the entire central measurement node is under Eve’s control, while the users trust only their own preparation devices (Lu et al., 2024, Carrara et al., 2022, Li et al., 2024). Source-independent schemes invert that assumption by allowing the source to be uncharacterized or malicious while users trust their local measurements (Bao et al., 2024).

"Efficient source-independent quantum conference key agreement" (Bao et al., 2024) proposes a source-independent protocol over an entangled photon-pair distribution network that uses Bell-pair post-matching to synthesize virtual GHZ-type correlations. For a symmetric star network, the conference key rate scaling improves from KK7 for direct KK8-photon entanglement to KK9, where EE0 is the transmittance from the entanglement source to one participant (Bao et al., 2024). The asymptotic key rate is

EE1

and the finite-key key length is

EE2

(Bao et al., 2024). This suggests a practical route for QCCC over pair-entanglement distribution networks when direct GHZ generation is rate-limited.

"Repeater-like asynchronous measurement-device-independent quantum conference key agreement" (Lu et al., 2024) attacks a different bottleneck: the need for synchronous GHZ detection. Its ring-interference topology uses EE3 two-user interference ports and groups EE4 single-click events from different time bins, within a coherence window EE5, into one effective asynchronous GHZ measurement (Lu et al., 2024). The pairing probability behaves as EE6 in the high-rate regime, independent of user number, leading to repeater-like linear-in-EE7 scaling and intercity distances exceeding EE8 km in the asymptotic simulations (Lu et al., 2024).

At the information-theoretic network level, "Key Assistance, Key Agreement, and Layered Secrecy for Bosonic Broadcast Channels" (Pereg et al., 2021) studies a different but related model: key agreement over bosonic broadcast channels. Instead of multipartite entanglement distribution or central interference, the object is a broadcast channel EE9 and a state 12ρKEτKρE1ε,\frac{1}{2}\Bigl\|\rho_{KE}-\tau_K\otimes \rho_E\Bigr\|_1 \le \varepsilon,0. The paper defines a conference-style key-agreement task in which Alice, Bob, and Eve distill a public key 12ρKEτKρE1ε,\frac{1}{2}\Bigl\|\rho_{KE}-\tau_K\otimes \rho_E\Bigr\|_1 \le \varepsilon,1 and a secret key 12ρKEτKρE1ε,\frac{1}{2}\Bigl\|\rho_{KE}-\tau_K\otimes \rho_E\Bigr\|_1 \le \varepsilon,2, and gives the regularized capacity region

12ρKEτKρE1ε,\frac{1}{2}\Bigl\|\rho_{KE}-\tau_K\otimes \rho_E\Bigr\|_1 \le \varepsilon,3

with single-letter region

12ρKEτKρE1ε,\frac{1}{2}\Bigl\|\rho_{KE}-\tau_K\otimes \rho_E\Bigr\|_1 \le \varepsilon,4

In the pure-loss bosonic broadcast case, the paper shows that for 12ρKEτKρE1ε,\frac{1}{2}\Bigl\|\rho_{KE}-\tau_K\otimes \rho_E\Bigr\|_1 \le \varepsilon,5, confidentiality solely relies on key-assisted one-time-pad encryption, expressed as

12ρKEτKρE1ε,\frac{1}{2}\Bigl\|\rho_{KE}-\tau_K\otimes \rho_E\Bigr\|_1 \le \varepsilon,6

(Pereg et al., 2021). This formulation is not a GHZ protocol, but it provides a capacity-theoretic perspective on conference and layered key agreement in optical networks.

6. Post-processing, variants, and open design directions

Beyond the quantum layer, the literature increasingly treats QCCC key agreement as a problem of optimizing multipartite post-processing. A recent example is "S-CAD: Selective Classical Advantage Distillation for Quantum Conference Key Agreement" (Thomas et al., 4 May 2026), which augments the Grasselli GHZ protocol with selective classical advantage distillation. Each Bob chooses whether to enable CAD through a public flag vector

12ρKEτKρE1ε,\frac{1}{2}\Bigl\|\rho_{KE}-\tau_K\otimes \rho_E\Bigr\|_1 \le \varepsilon,7

and accepted two-bit blocks are those for which all CAD-enabled Bobs’ parities match Alice’s broadcast parity (Thomas et al., 4 May 2026). The acceptance probability is

12ρKEτKρE1ε,\frac{1}{2}\Bigl\|\rho_{KE}-\tau_K\otimes \rho_E\Bigr\|_1 \le \varepsilon,8

and the asymptotic per-signal key rate becomes

12ρKEτKρE1ε,\frac{1}{2}\Bigl\|\rho_{KE}-\tau_K\otimes \rho_E\Bigr\|_1 \le \varepsilon,9

with pp00 bounded by an optimization over phase-error allocations pp01 constrained by pp02 (Thomas et al., 4 May 2026). The central operational message is that CAD should not be treated as an all-or-nothing primitive: in heterogeneous star networks it can be advantageous to enable it only on the noisiest links, while in larger homogeneous networks it is often best disabled entirely (Thomas et al., 4 May 2026).

Controlled and anonymous variants show that the conference-key primitive supports richer functionality than shared randomness alone. "Collective attack free controlled quantum key agreement without quantum memory" (Dutta et al., 2023) studies controlled quantum key agreement using Bell states and single photons rather than GHZ states, with fairness, correctness, no quantum memory, and an explicit collective-attack analysis culminating in a tolerable QBER of about pp03 in the orthogonal-ancilla case (Dutta et al., 2023). "Anonymous Quantum Conference Key Agreement" (Hahn et al., 2020) adds participant anonymity to GHZ-based conference key generation, motivated by settings such as anonymous whistle-blowing.

A common misconception is that all QCCC protocols require distributed GHZ sources. The current literature shows several non-equivalent alternatives. GHZ-based protocols remain the cleanest for composable multiparty security analysis (Amer et al., 2022), but source-independent Bell-pair post-matching (Bao et al., 2024), twin-field and phase-matching interference (Carrara et al., 2022, Zhao et al., 2020), coherent one-way reductions (Cao et al., 2021), and asynchronous MDI ring topologies (Lu et al., 2024) all realize the same conference-key task under different trust and hardware assumptions. Another misconception is that higher dimensionality merely simulates parallel qubit protocols. The explicit comparison in (Amer et al., 2022) states that for pp04 the key rate substantially dominates that of pp05 even when doubling the number of qubit rounds, because the security proof exploits global high-dimensional structure rather than only raw-bit throughput.

A plausible implication is that QCCC key agreement is best understood not as a single protocol family but as a design space organized by three axes: the quantum resource used to induce group correlations, the trust assumptions placed on source and measurement devices, and the structure of multipartite post-processing. The published record shows that progress along any one axis can change both performance and security characterizations materially, which is why the field now spans high-dimensional GHZ security proofs (Amer et al., 2022), repeater-like MDI architectures (Lu et al., 2024), source-independent pair-distribution protocols (Bao et al., 2024), and selective classical post-processing layers (Thomas et al., 4 May 2026).

Topic to Video (Beta)

No one has generated a video about this topic yet.

Whiteboard

No one has generated a whiteboard explanation for this topic yet.

Follow Topic

Get notified by email when new papers are published related to QCCC Key Agreement.