---
title: 'SQKD: Advances in Protocol Design & Security'
url: https://www.emergentmind.com/topics/semi-quantum-key-distribution-sqkd
type: topic
---

# SQKD: Advances in Protocol Design & Security

Searching arXiv for recent and foundational SQKD papers to ground the article.
to=arxiv_search.search 官网群  qq上_json
{"query":"all:\"semi-quantum key distribution\" OR title:\"Semi-Quantum Key Distribution\"","max_results":10,"sort_by":"submittedDate","sort_order":"descending"}】【”】【
Found relevant arXiv records spanning finite-size security, lightweight/multiparty variants, experimental demonstrations, and resource-limited protocols, including [2509.25078], [2507.11188], [2405.07469], [2308.08910], [2308.08082], [2203.10567], [2101.02583], [2012.02127], [1907.11340], and [1812.04144].
Semi-Quantum Key Distribution (SQKD) denotes a class of key-establishment protocols in which at least one participant is restricted in quantum capability while the protocol still aims at information-theoretic security against an all-powerful adversary. In the literature, the restricted participant may be allowed only operations such as preparing or measuring states in the computational basis, reflecting signals, reordering qubits, or merely detecting the presence or absence of a photon; more recent variants also study “almost-classical” or “restricted quantum” users with carefully delimited operations. SQKD has therefore become a central testbed for the question of how little quantumness is sufficient for secure key distribution, and the field now includes two-party, mediated, high-dimensional, experimentally feasible, and multi-party constructions, together with asymptotic and finite-size security analyses [2308.08910][1509.04797].

## 1. Operational model and protocol vocabulary

Most SQKD protocols are organized around an asymmetric division of labor between a fully quantum user and a limited user. The fully quantum side typically prepares nonorthogonal states, chooses measurement bases, and performs the final parameter estimation and privacy amplification; the limited side is constrained to classical-basis operations such as **measure-and-resend**, **reflect**, **prepare in the $Z$ basis**, or, in some photonic protocols, mode-selective reflection and threshold detection. A recurrent terminology is the distinction between **SIFT** rounds, which contribute to raw key generation, and **CTRL** rounds, which are reserved for disturbance testing [1612.03087][2308.08910].

The canonical communication geometry in SQKD is a **two-way quantum channel**. A signal is sent from the quantum user to the limited user and then returned, allowing the restricted party either to act in the computational basis or to reflect the signal. This two-way structure is both a resource and a liability. It supplies extra observable statistics and, in some protocols, can be used to increase noise tolerance, but it also amplifies implementation complexity and channel loss [1812.04144][2012.02127].

The literature also contains two important architectural generalizations. In **mediated SQKD**, both end users may be classical or almost-classical while an untrusted quantum server prepares and measures states; the server is explicitly included in the adversarial model [1509.04797][2203.10567]. In **multi-party** settings, entangled resources such as GHZ-like states or cluster states are used to distribute separate keys or combine SQKD with semiquantum secret sharing [2308.08082][2507.11188].

## 2. Resource minimization as a design principle

A persistent theme in SQKD research is the progressive reduction of user-side quantum resources. From the perspective of resource theory, the field asks whether the same cryptographic task can be accomplished with fewer preparation bases, fewer measurement bases, less quantum memory, or no measurement capability on the “classical” side.

| Variant | Restricted capabilities | Representative result |
|---|---|---|
| Single-state SQKD | Alice always sends $|+\rangle$; Bob reflects or replaces with $|0\rangle$ and does not measure | Unconditionally secure; efficiency $\ell=\frac{1}{8}$; tolerable $e_Z \leq 3.46\%$ in the stated depolarizing example [1612.03087] |
| Limited-resource SQKD | Quantum user measures only in the $X$ basis and sends only $|0\rangle$, $|1\rangle$, or $|+\rangle$ | Unconditionally secure; noise tolerance up to $11\%$ for dependent channels and $7.9\%$ for independent depolarizing channels [1710.05076] |
| One-basis/no-measure classical-user SQKD | Bob prepares only $X$-basis states; Alice prepares only in $Z$, reflects, and reorders, but does not measure | First protocol combining both restrictions; asymptotic key-rate bound derived and unconditional security proved [2308.08910] |

The single-state line of work is especially important because it disentangles two different simplifications: reducing the number of transmitted signal states and removing measurement from the restricted participant. The B92-inspired single-state protocol of Zou et al. uses only $|+\rangle$ from the quantum side and only $|0\rangle$ from the classical side in SIFT rounds; it is described in the source material as a “semi-quantum B92” and improves efficiency relative to several earlier single-state constructions, albeit with lower tolerable noise than some more resource-rich SQKD protocols [1612.03087].

The 2017 limited-resource protocol tightens the model on the quantum side rather than the classical side. Its main conceptual result is that full quantum measurement capability is not necessary: a quantum user restricted to $X$-basis measurements can still achieve noise tolerance as high as the best-known fully quantum QKD protocols in the channel models analyzed, provided mismatched measurement statistics are incorporated into the proof [1710.05076].

The 2023 protocol pushes this minimization further by combining two restrictions that had previously appeared only separately. Bob prepares only in the $X$ basis, while Alice has no measurement capability at all and is limited to $Z$-basis preparation, reflection, and reordering. The protocol is explicitly presented as the first SQKD construction with both properties simultaneously [2308.08910]. A plausible implication is that the operational boundary between “quantum” and “classical” users in SQKD is not binary but protocol-dependent.

## 3. Security theory and proof techniques

The dominant asymptotic security framework in SQKD is the Devetak–Winter key-rate formalism. Depending on which party supplies the raw key variable, papers in the area write the asymptotic rate as either
$$
r = \inf \bigl(S(A|E)-H(A|B)\bigr)
$$
or
$$
r = \inf \bigl(S(B|E)-H(B|A)\bigr),
$$
where $S(\cdot|\cdot)$ is conditional von Neumann entropy and $H(\cdot|\cdot)$ is classical conditional entropy [1509.04797][1612.03087]. SQKD proofs then derive lower bounds on the quantum conditional entropy from directly observable statistics on SIFT and CTRL rounds.

Because SQKD is intrinsically two-way, the adversary is usually modeled as attacking both the forward and reverse channels. Protocol-specific analyses commonly begin with **collective attacks** and then extend to **general attacks** using symmetrization or permutation-invariance arguments. The 2023 one-basis/no-measure protocol explicitly follows this route: after raw-key symmetrization, security against collective attacks extends to arbitrary joint attacks, yielding unconditional security in the asymptotic regime [2308.08910].

A major technical development is the use of **mismatched measurement statistics**. In the 2017 limited-resource protocol, these statistics are not merely auxiliary; the source material states that they are essential for security, and without them the protocol is insecure. This result is methodologically significant because it shows that a sparse observable interface can still support a full entropy-based proof if the “wrong-basis” data are exploited carefully [1710.05076]. The 2018 high-noise-tolerance protocol generalizes this idea to two-way, multi-basis settings and develops new parameter-estimation techniques for two-way (S)QKD [1812.04144].

Mediated SQKD prompted a different proof strategy. In Krawec’s improved asymptotic key-rate bound, an auxiliary two-dimensional system is introduced to encode whether the users’ raw bits agree or disagree. Conditioning on this system and using strong subadditivity yields a tighter lower bound on $S(A|C)$, where $C$ is the adversarial server, improving the tolerable error rate over prior analyses [1509.04797]. This conditional-entropy technique also removed a symmetry assumption present in earlier evaluations.

Recent work has also brought **finite-size security** into focus. A 2025 study develops three complementary viewpoints: spectral disturbance under wrong-basis Lüders updates, operator-theoretic reduction of intercept-resend attacks to an effective depolarizing channel in $Z/Z$-sifted rounds, and entropic trade-offs based on Maassen–Uffink and memory-assisted uncertainty relations. The same study concludes with finite-size estimates based on concentration inequalities suitable for practical parameter estimation [2509.25078]. This suggests a shift from purely asymptotic SQKD analysis toward experimentally meaningful finite-key certification.

## 4. Efficiency, key-rate optimization, and noise tolerance

Efficiency in SQKD is often much lower than in one-way fully quantum QKD because many rounds are sacrificed to basis reconciliation, reflection tests, or the second pass through the channel. One line of work attacks this directly by altering action probabilities. In “Efficient semiquantum key distribution,” the users choose actions asymmetrically rather than with equal probabilities, and one protocol recycles X-SIFT bits that earlier protocols discarded. The paper states that the efficiency of its protocols can be made asymptotically close to $100\%$ and proves complete robustness against the most general attack [1811.03190].

Noise tolerance has developed along several distinct trajectories, and direct numerical comparisons must be made with care because the cited results use different channel models, dimensionalities, and parameter-estimation assumptions. Still, several benchmark values are repeatedly emphasized in the literature.

| Protocol family | Representative reported tolerance or efficiency | Reference |
|---|---|---|
| Efficient asymmetric SQKD | Efficiency can be made asymptotically close to $100\%$ | [1811.03190] |
| Mirror protocol | Secure up to $11\%$ in the dependent noise model and $7.9\%$ in the independent noise model | [2012.02127] |
| Two-way high-noise SQKD | MODE-3 tolerates $26.0\%$ noise in dependent channels and $17.8\%$ in independent symmetric channels | [1812.04144] |
| Qutrit-based SQKD | For $\Phi_1=\mathcal{A}\cup\mathcal{T}$, up to $19.1\%$ dependent-channel noise and $6.1\%$ independent-channel noise | [2101.02583] |
| High-dimensional SQKD | For very large dimension, noise tolerance approaches about $30\%$ when $Q=Q_F$ or about $26\%$ when $Q_F=2Q(1-Q)$ | [1907.11340] |

The 2018 high-noise-tolerance protocol is notable because it treats the two-way channel as an advantage rather than only a handicap. In MODE-3, where all three Pauli bases are used, it reports the highest noise tolerance among the SQKD protocols compared in the source material and relates its behavior to BB84 with Classical Advantage Distillation (CAD) [1812.04144].

High-dimensionality offers a second route. The qutrit protocol proves unconditional security for a three-dimensional system and reports substantially improved noise tolerance over earlier qubit-based SQKD when the $\Phi_1=\mathcal{A}\cup\mathcal{T}$ encoding set is used [2101.02583]. A broader high-dimensional construction based on $n$ qubits per signal, effectively dimension $d=2^n$, derives a rate bound of the form
$$
r \ge n(1-\Delta) - (1+\Delta)H\!\left(\frac{\Delta}{1+\Delta}\right)
- (Q+Q_F)\log_2(2^n-1) - H(Q)-H(Q_F),
$$
and states that increasing dimension improves both key rate and noise tolerance in SQKD, much as in fully quantum QKD [1907.11340].

Capacity can also be increased without moving to entangled or truly high-dimensional carriers by exploiting multiple degrees of freedom of a single photon. Protocols using polarization and spatial-mode degrees of freedom allow one photon to carry two private bits, and one efficient design reports a quantum communication efficiency of $11.11\%$, compared with $8.33\%$ for earlier cited baselines [2110.03456]. A related 2022 protocol likewise emphasizes that each SIFT photon can encode two classical bits and that only a single kind of initial quantum state is needed [2205.06813].

## 5. Experimental realizations and practical constraints

A major practical obstacle in early SQKD was the insecure or technologically unrealistic implementation of the classical party’s SIFT operation. The 2017 **Mirror protocol**, “Classical Alice with a controllable mirror,” addresses this by replacing measure-and-resend with operations realizable in photonic systems using a controllable mirror and four-level Fock-space states. The protocol works with operations denoted CTRL, SWAP-10, SWAP-01, and SWAP-ALL, and was proposed as experimentally feasible with current technology [1701.07044].

The practical importance of the Mirror design became clearer when a simplified version was attacked. The 2018 attack paper proves the simplified Mirror protocol completely non-robust and presents two explicit attacks, one of which gives Eve full information at the price of severe CTRL losses, and another weaker parameterized attack that can equalize loss rates while still leaking a fraction of the key. The conclusion drawn in the source is that the omitted SWAP-ALL operation is at least partly necessary for robustness [1806.06213]. This is one of the clearest demonstrations in SQKD that reducing operational complexity can destroy security rather than enhance practicality.

A later security proof establishes the Mirror protocol against collective attacks in realistic, photon-based settings and evaluates its noise and loss tolerance. In the no-loss case, it matches the asymptotic BB84 threshold of $11\%$ in the dependent noise model and reaches $7.9\%$ in the independent model; under loss, however, the two-way channel causes faster degradation, and the source gives the concrete comparison that Mirror at $10\,\text{km}$ matches BB84 at $50\,\text{km}$ for the stated fiber-loss example [2012.02127]. The practical picture is therefore mixed: the protocol closes the tagging-attack loophole associated with naive photonic SIFT implementations, but two-way transmission remains costly.

Direct experimental realization has advanced beyond proof-of-principle photonic architectures. A 2024 phase-encoded SQKD system based on the Single-state Protocol and **selective modulation** operates at a frequency of $100\,\text{MHz}$ and average photon number $0.1$, achieving $96.52\%$ interference contrast, average QBER $1.19\%$, and raw key rate $88\,\text{kbps}$ [2405.07469]. In this realization, the classical user requires only two optical devices, a phase modulator and a Faraday mirror, because selective modulation replaces measurement-resend for SIFT operations. The same paper formalizes the modulation as a unitary rotation $\hat R_y(\delta)$ and argues, through quantum-state evolution, that attacks on the encoded states induce detectable disturbances.

Other experimentally oriented proposals emphasize hardware simplicity rather than fielded systems. Single-photon protocols using both polarization and spatial-mode degrees of freedom state that preparation and measurement with present quantum technologies are straightforward and require only standard linear-optical components, while preserving complete robustness or resistance to the listed active attacks [2205.06813][2110.03456]. This line of work treats physical feasibility and communication capacity as coequal design objectives.

## 6. Mediated, multiparty, and adjacent semi-quantum primitives

SQKD has expanded beyond the original two-party quantum–classical setting. In **mediated SQKD**, two end users may both be almost-classical while relying on a quantum server that is itself untrusted. Krawec’s 2015 analysis derives an improved asymptotic lower bound on the key rate and reports positive key rates up to $22.05\%$ noise for a semi-honest server and up to $12.5\%$ for a fully adversarial server in the scenarios analyzed [1509.04797]. An improved protocol for two almost-classical users later introduced a second sub-round that recycles rounds previously discarded on a server announcement of “0”, increasing both effective key rate and phase-error tolerance from $8.9\%$ to $9.8\%$ in the cited comparison [2203.10567].

Multi-party extensions use entanglement to combine SQKD with other cryptographic tasks. A 2023 hybrid protocol based on GHZ-like states simultaneously establishes two different private keys between one quantum party and two semiquantum parties and enables semiquantum secret sharing, with the relation
$$
K_A = K_B \oplus \overline{K_C}.
$$
The same work states that delay lines, Pauli operations, Hadamard gates, entanglement swapping, and quantum memory are not required for the semiquantum parties, and it analyzes Trojan horse, entangle-measure, double-CNOT, measure-resend, and intercept-resend attacks [2308.08082].

A different multiparty trajectory replaces two-way or circular transmission with one-way delivery in a restricted quantum environment. The 2025 lightweight three-party protocol based on a four-particle cluster state allows a fully quantum user to establish two separate keys with two restricted users who can perform only the Hadamard operation and $Z$-basis measurements. It reports qubit efficiency $\eta=\frac{1}{8}$ and a noise tolerance of $9.68\%$, described as very close to the $11\%$ threshold of BB84 [2507.11188]. Because transmission is one-way, the protocol also claims that the classical users do not need costly devices to defend against Trojan horse attacks.

Adjacent semiquantum primitives have also emerged by importing SQKD security mechanisms into broader secure-communication tasks. Semi-quantum dialogue protocols based on single photons use complete robustness results from SQKD, classical one-time-pad encryption, decoy-photon checks, and randomization to secure bidirectional message exchange while requiring only one fully quantum party [2205.05568]. This suggests that SQKD is no longer only a narrow key-distribution model but a methodological core for a wider semiquantum cryptographic toolkit.

A recurrent misconception is that “classical” in SQKD means entirely non-quantum behavior. The literature instead uses the term operationally: depending on the protocol, the limited user may reflect qubits, measure or prepare only in the $Z$ basis, reorder particles, detect presence or absence, or, in restricted quantum environments, apply $H$ and then measure in $Z$ [2308.08910][2507.11188]. Another misconception is that simpler protocols are automatically more practical; the non-robustness of the simplified Mirror protocol shows that omitted operations can be security-critical [1806.06213]. The cumulative record of the field therefore points to a structured tradeoff rather than a monotone one: reducing quantum resources can preserve unconditional security and sometimes even improve deployability, but only when the reduced operation set remains compatible with a sound parameter-estimation interface and a robust physical implementation.

Source: https://www.emergentmind.com/topics/semi-quantum-key-distribution-sqkd