Three-Setting QKD Protocol
- The three‐setting protocol is a quantum key distribution variant that uses three signal states instead of four to exploit mismatched measurement outcomes.
- It employs two orthonormal bases and retains non-key rounds for parameter estimation, enabling linear bounds on Eve’s attack operator overlaps.
- Its asymptotic security analysis under depolarizing channels yields an 11% error tolerance, matching the performance of standard BB84.
Searching arXiv for the specified protocol and closely related work. arxiv_search("(Krawec, 2016) three-state quantum cryptographic protocol BB84")
Searching for adjacent literature on three-state QKD and BB84 threshold analyses. arxiv_search("three-state BB84 asymptotic key rate mismatched measurement outcomes")
The three-setting protocol, as documented in the analysis of a three-state quantum cryptographic protocol, is a variant of BB84 quantum key distribution in which Alice transmits only three signal states rather than the four states of standard BB84, while Bob measures in one of two orthonormal bases and all non-key rounds are retained for channel estimation. Its defining technical feature is that mismatched measurement outcomes are not discarded but are used to infer linear bounds on overlaps in Eve’s attack operator, yielding an asymptotic lower bound on the key rate that remains positive up to an error rate of , matching the four-state BB84 threshold under the depolarizing-channel model (Krawec, 2016).
1. Protocol class and state space
The protocol is defined on a qubit Hilbert space with two orthonormal bases. The first is the computational, or -basis,
The second is a basis
parameterized by a public real number , with
In the special case , one recovers and (Krawec, 2016).
The protocol is “three-state” because Alice’s signal alphabet contains 0, 1, and 2, but not 3. This asymmetry distinguishes it from four-state BB84 while preserving a two-basis structure. A plausible implication is that the protocol seeks state-economy at the preparation stage without abandoning the basis-based estimation strategy characteristic of BB84.
2. Round structure and raw-key extraction
On each round, Alice chooses to send 4 or 5 each with probability 6, or 7 with probability 8. Bob chooses to measure in 9 with probability 0, and otherwise in 1. After public basis announcement, only the rounds in which Alice sent 2 or 3 and Bob measured in 4 contribute to the raw key (Krawec, 2016).
The classical raw-key variables 5 are characterized by the quantum bit error rate
6
All remaining rounds are retained for parameter estimation, including the deliberately preserved mismatched-basis events. This differs from a common simplification in which only matched-basis statistics are treated as relevant. Here, the mismatched data are structurally part of the security proof rather than merely auxiliary observations.
3. Mismatched-basis parameter estimation
Parameter estimation uses three classes of observed data:
- the raw-key basis error 7;
- the 8-basis error
9
- all mismatched-basis probabilities
0
for 1 (Krawec, 2016).
These observed frequencies are used to form linear bounds on real overlaps
2
associated with Eve’s attack operator 3. In particular,
4
5
and the Cauchy–Schwarz bound gives
6
Finally, these quantities are inserted into the expression for 7 to bound 8 (Krawec, 2016).
The significance of this step is methodological. The protocol does not treat Eve’s influence only through aggregate error rates; it reconstructs constraints on specific ancilla overlaps. This suggests that the informational content of mismatched events compensates for the missing fourth signal state.
4. Asymptotic security analysis and key-rate lower bound
The security proof is carried out under collective attacks in the asymptotic limit 9, with key rate
0
Conditioning on key rounds and assuming symmetric 1-basis error,
2
the argument establishes
3
where 4 and 5 are Eve-conditioned states corresponding respectively to no bit flip and bit flip in the 6-basis (Krawec, 2016).
The entropies satisfy
7
8
with
9
Since 0, the resulting lower bound is
1
where one may safely replace 2 by any 3 on 4 (Krawec, 2016).
For practical estimation, one sets
5
and then minimizes the bound over the allowed range of 6. The proof relies on lemmas concerning block-diagonal states and strong subadditivity, so the key-rate expression is not a heuristic approximation but the endpoint of an entropy-based lower-bound argument.
5. Depolarizing-channel specialization and comparison with BB84
For a depolarizing channel of parameter 7, symmetry yields
8
Numerically minimizing the asymptotic lower bound over
9
produces exactly the BB84 key-rate curve
0
which remains positive up to
1
Under this channel model, the three-state protocol therefore tolerates the same maximum noise as the four-state BB84 protocol once mismatched-basis parameter estimation is included (Krawec, 2016).
This equality of thresholds is the principal comparative result. It does not mean that the protocols are identical at the signal level; rather, it indicates that the reduced signal alphabet does not degrade the asymptotic depolarizing-channel threshold when the full observed data are exploited. A common misconception is that removing one signal state must necessarily reduce tolerable noise. The result shows that, in the asymptotic analysis presented, that conclusion does not follow.
6. Assumptions, scope, and interpretive boundaries
The security proof assumes collective attacks by Eve, modeled as an identical, independent unitary on each round, with extension to coherent attacks via standard de Finetti or post-selection arguments. It also assumes the asymptotic key rate
2
perfect qubits, and no side-channels. The symmetry conditions
3
may be optionally enforced for the 4-basis error model (Krawec, 2016).
These assumptions delimit the article’s scope. The result concerns asymptotic security rather than finite-key performance, and it abstracts away from implementation-level imperfections. It therefore establishes a lower bound in an idealized but standard cryptographic regime. Within that regime, the central conclusion is precise: by keeping and exploiting all mismatched measurement outcomes, one can bound the critical overlaps in Eve’s ancilla and derive a compact key-rate lower bound whose depolarizing-channel specialization coincides with the BB84 expression 5 (Krawec, 2016).