---
title: Three-Setting QKD Protocol
url: https://www.emergentmind.com/topics/three-setting-protocol
type: topic
---

# Three-Setting QKD Protocol

Searching arXiv for the specified protocol and closely related work.
arxiv_search("1601.00185 three-state quantum cryptographic protocol BB84")

Searching for adjacent literature on three-state QKD and BB84 threshold analyses.
arxiv_search("three-state BB84 asymptotic key rate mismatched measurement outcomes")

The three-setting protocol, as documented in the analysis of a three-state quantum cryptographic protocol, is a variant of BB84 quantum key distribution in which Alice transmits only three signal states rather than the four states of standard BB84, while Bob measures in one of two orthonormal bases and all non-key rounds are retained for channel estimation. Its defining technical feature is that mismatched measurement outcomes are not discarded but are used to infer linear bounds on overlaps in Eve’s attack operator, yielding an asymptotic lower bound on the key rate that remains positive up to an error rate of \(11\%\), matching the four-state BB84 threshold under the depolarizing-channel model [1601.00185].

## 1. Protocol class and state space

The protocol is defined on a qubit Hilbert space \(\mathcal{H}\) with two orthonormal bases. The first is the computational, or \(Z\)-basis,
\[
\mathcal{B}=\{\ket{0},\ket{1}\}.
\]
The second is a basis
\[
\mathcal{A}=\{\ket{a},\ket{\bar a}\}
\]
parameterized by a public real number \(\alpha\in(0,1)\), with
\[
\ket{a}=\alpha\ket{0}+\beta\ket{1},\qquad
\ket{\bar a}=\beta\ket{0}-\alpha\ket{1},\qquad
\beta\equiv\sqrt{1-\alpha^2}.
\]
In the special case \(\alpha=1/\sqrt2\), one recovers \(\ket{a}=\ket{+}\) and \(\ket{\bar a}=\ket{-}\) [1601.00185].

The protocol is “three-state” because Alice’s signal alphabet contains \(\ket{0}\), \(\ket{1}\), and \(\ket{a}\), but not \(\ket{\bar a}\). This asymmetry distinguishes it from four-state BB84 while preserving a two-basis structure. A plausible implication is that the protocol seeks state-economy at the preparation stage without abandoning the basis-based estimation strategy characteristic of BB84.

## 2. Round structure and raw-key extraction

On each round, Alice chooses to send \(\ket{0}\) or \(\ket{1}\) each with probability \(p/2\), or \(\ket{a}\) with probability \(1-p\). Bob chooses to measure in \(\mathcal{B}\) with probability \(q\), and otherwise in \(\mathcal{A}\). After public basis announcement, only the rounds in which Alice sent \(\ket{0}\) or \(\ket{1}\) and Bob measured in \(\mathcal{B}\) contribute to the raw key [1601.00185].

The classical raw-key variables \((A,B)\) are characterized by the quantum bit error rate
\[
Q=\Pr[B\neq A\mid \text{both used }\mathcal B].
\]
All remaining rounds are retained for parameter estimation, including the deliberately preserved mismatched-basis events. This differs from a common simplification in which only matched-basis statistics are treated as relevant. Here, the mismatched data are structurally part of the security proof rather than merely auxiliary observations.

## 3. Mismatched-basis parameter estimation

Parameter estimation uses three classes of observed data:

- the raw-key basis error \(Q\);
- the \(\mathcal{A}\)-basis error
  \[
  Q_{\mathcal A}
  =\Pr[\text{Bob outcome}=\ket{\bar a}\mid \text{Alice sent }\ket{a},\,\text{Bob used }\mathcal A];
  \]
- all mismatched-basis probabilities
  \[
  p_{x,y}=\Pr[\text{Bob measures }\ket y\mid \text{Alice sent }\ket x],
  \]
  for \((x,y)\in\{0,1,a\}\times\{0,1,a,\bar a\}\) [1601.00185].

These observed frequencies are used to form linear bounds on real overlaps
\[
R_{i,j}=\Re\langle e_i|e_j\rangle
\]
associated with Eve’s attack operator \(U\). In particular,
\[
R_{0,1}
=\frac{p_{0,a}-\alpha^2(1-Q)-\beta^2Q}{2\alpha\beta},\qquad
R_{2,3}
=\frac{p_{1,a}-\alpha^2Q-\beta^2(1-Q)}{2\alpha\beta},
\]
\[
R_{0,2}
=\frac{p_{a,0}-\alpha^2(1-Q)-\beta^2Q}{2\alpha\beta},\qquad
R_{1,3}=-R_{0,2},
\]
and the Cauchy–Schwarz bound gives
\[
|R_{1,2}|\le Q.
\]
Finally, these quantities are inserted into the expression for \(Q_{\mathcal A}\) to bound \(R_{0,3}\) [1601.00185].

The significance of this step is methodological. The protocol does not treat Eve’s influence only through aggregate error rates; it reconstructs constraints on specific ancilla overlaps. This suggests that the informational content of mismatched events compensates for the missing fourth signal state.

## 4. Asymptotic security analysis and key-rate lower bound

The security proof is carried out under collective attacks in the asymptotic limit \(N\to\infty\), with key rate
\[
r=\inf_{\text{attacks}} \bigl[S(A|E)-H(A|B)\bigr].
\]
Conditioning on key rounds and assuming symmetric \(Z\)-basis error,
\[
\langle e_0|e_0\rangle=\langle e_3|e_3\rangle=1-Q,\qquad
\langle e_1|e_1\rangle=\langle e_2|e_2\rangle=Q,
\]
the argument establishes
\[
S(A|E)\ge (1-Q)\,S(A|E)_\rho + Q\,S(A|E)_\sigma,
\]
where \(\rho_{AE}\) and \(\sigma_{AE}\) are Eve-conditioned states corresponding respectively to no bit flip and bit flip in the \(Z\)-basis [1601.00185].

The entropies satisfy
\[
S(AE)_\rho=S(AE)_\sigma=1,
\]
\[
S(E)_\rho=h\bigl(\lambda_+^\rho\bigr),\qquad
S(E)_\sigma=h\bigl(\lambda_+^\sigma\bigr),
\]
with
\[
\lambda_+^\rho
=\tfrac12+\tfrac{|\langle e_0|e_3\rangle|}{2(1-Q)},\qquad
\lambda_+^\sigma
=\tfrac12+\tfrac{|\langle e_1|e_2\rangle|}{2Q}.
\]
Since \(H(A|B)=h(Q)\), the resulting lower bound is
\[
r\ge 1-(1-Q)\,h\!\bigl(\lambda^\rho\bigr)-Q\,h\!\bigl(\lambda^\sigma\bigr)-h(Q),
\]
where one may safely replace \(\lambda_+^{(\cdot)}\) by any \(\lambda^{(\cdot)}\le \lambda_+^{(\cdot)}\) on \([1/2,1]\) [1601.00185].

For practical estimation, one sets
\[
\lambda^\rho=\tfrac12+\frac{|R_{0,3}|}{2(1-Q)},\qquad
\lambda^\sigma=\tfrac12+\frac{|R_{1,2}|}{2Q},
\]
and then minimizes the bound over the allowed range of \(R_{1,2}\). The proof relies on lemmas concerning block-diagonal states and strong subadditivity, so the key-rate expression is not a heuristic approximation but the endpoint of an entropy-based lower-bound argument.

## 5. Depolarizing-channel specialization and comparison with BB84

For a depolarizing channel of parameter \(Q\), symmetry yields
\[
R_{0,1}=R_{2,3}=R_{0,2}=0,\qquad Q_{\mathcal A}=Q,\qquad R_{0,3}=1-2Q-R_{1,2}.
\]
Numerically minimizing the asymptotic lower bound over
\[
R_{1,2}\in[-Q,Q]
\]
produces exactly the BB84 key-rate curve
\[
r_{\rm BB84}=1-2h(Q),
\]
which remains positive up to
\[
Q_{\max}\approx 11\%.
\]
Under this channel model, the three-state protocol therefore tolerates the same maximum noise as the four-state BB84 protocol once mismatched-basis parameter estimation is included [1601.00185].

This equality of thresholds is the principal comparative result. It does not mean that the protocols are identical at the signal level; rather, it indicates that the reduced signal alphabet does not degrade the asymptotic depolarizing-channel threshold when the full observed data are exploited. A common misconception is that removing one signal state must necessarily reduce tolerable noise. The result shows that, in the asymptotic analysis presented, that conclusion does not follow.

## 6. Assumptions, scope, and interpretive boundaries

The security proof assumes collective attacks by Eve, modeled as an identical, independent unitary on each round, with extension to coherent attacks via standard de Finetti or post-selection arguments. It also assumes the asymptotic key rate
\[
r=\lim_{N\to\infty}\ell/N,
\]
perfect qubits, and no side-channels. The symmetry conditions
\[
\braket{e_0|e_0}=\braket{e_3|e_3},\qquad
\braket{e_1|e_1}=\braket{e_2|e_2}
\]
may be optionally enforced for the \(Z\)-basis error model [1601.00185].

These assumptions delimit the article’s scope. The result concerns asymptotic security rather than finite-key performance, and it abstracts away from implementation-level imperfections. It therefore establishes a lower bound in an idealized but standard cryptographic regime. Within that regime, the central conclusion is precise: by keeping and exploiting all mismatched measurement outcomes, one can bound the critical overlaps in Eve’s ancilla and derive a compact key-rate lower bound whose depolarizing-channel specialization coincides with the BB84 expression \(1-2h(Q)\) [1601.00185].

Source: https://www.emergentmind.com/topics/three-setting-protocol