Papers
Topics
Authors
Recent
Search
2000 character limit reached

Three-State Simplified BB84 Protocol

Updated 16 July 2026
  • The three-state simplified BB84 protocol is a quantum key distribution method that uses two computational basis states and one conjugate state for monitoring, reducing state-preparation complexity.
  • It retains basis-mismatched outcomes for parameter estimation, achieving an 11% QBER threshold similar to the standard four-state BB84 under symmetric channel conditions.
  • Finite-key proofs and hardware implementations, including decoy-state techniques, demonstrate its practical viability and effectiveness in mitigating state-preparation flaws.

Searching arXiv for relevant work on three-state simplified BB84, including asymptotic, finite-key, and implementation/security-with-imperfections results. {"query":"three-state simplified BB84 protocol asymptotic finite-key implementation state preparation flaws", "max_results": 10} {"query":"all:three-state BB84 simplified protocol", "max_results": 10} The Three-State Simplified BB84 Protocol is a prepare-and-measure quantum key distribution scheme obtained by restricting standard BB84 so that Alice transmits only three states rather than four: two key-generating states in the computational basis and one monitoring state in the conjugate basis. In the formulation analyzed asymptotically in “Asymptotic Analysis of a Three State Quantum Cryptographic Protocol” (Krawec, 2016), Alice never prepares one of the conjugate-basis states, yet the protocol can still attain the same asymptotic quantum bit error rate threshold as four-state BB84 when basis-mismatched outcomes are retained for parameter estimation rather than discarded. Subsequent work developed finite-key, reduced-measurement, decoy-state, and implementation-oriented variants, including time-bin and polarization realizations (Rusca et al., 2018).

1. Protocol definition and reduction from standard BB84

In the 2016 asymptotic treatment, the computational basis is denoted B={0,1}\mathcal{B}=\{\lvert 0\rangle,\lvert 1\rangle\} and the conjugate basis is A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}, with

a=α0+1α21,aˉ=1α20α1,\lvert a\rangle=\alpha\lvert 0\rangle+\sqrt{1-\alpha^2}\lvert 1\rangle,\qquad \lvert \bar a\rangle=\sqrt{1-\alpha^2}\lvert 0\rangle-\alpha\lvert 1\rangle,

where α(0,1)\alpha\in(0,1) is public. When α=1/2\alpha=1/\sqrt{2}, A\mathcal{A} reduces to the XX basis {+,}\{\lvert +\rangle,\lvert -\rangle\} with ±=(0±1)/2\lvert \pm\rangle=(\lvert 0\rangle\pm\lvert 1\rangle)/\sqrt{2}. Alice prepares and sends one of three states, 0\lvert 0\rangle, A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}0, or A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}1, with respective probabilities A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}2, A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}3, and A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}4; notably, she cannot prepare A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}5. Bob measures in A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}6 with probability A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}7 and otherwise in A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}8. A raw key bit is kept only if both used A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}9, so the sifted fraction per transmitted signal is a=α0+1α21,aˉ=1α20α1,\lvert a\rangle=\alpha\lvert 0\rangle+\sqrt{1-\alpha^2}\lvert 1\rangle,\qquad \lvert \bar a\rangle=\sqrt{1-\alpha^2}\lvert 0\rangle-\alpha\lvert 1\rangle,0 (Krawec, 2016).

This restriction differentiates the protocol from standard BB84, which employs all four states a=α0+1α21,aˉ=1α20α1,\lvert a\rangle=\alpha\lvert 0\rangle+\sqrt{1-\alpha^2}\lvert 1\rangle,\qquad \lvert \bar a\rangle=\sqrt{1-\alpha^2}\lvert 0\rangle-\alpha\lvert 1\rangle,1. In the three-state version, the omitted signal is a=α0+1α21,aˉ=1α20α1,\lvert a\rangle=\alpha\lvert 0\rangle+\sqrt{1-\alpha^2}\lvert 1\rangle,\qquad \lvert \bar a\rangle=\sqrt{1-\alpha^2}\lvert 0\rangle-\alpha\lvert 1\rangle,2 in the usual a=α0+1α21,aˉ=1α20α1,\lvert a\rangle=\alpha\lvert 0\rangle+\sqrt{1-\alpha^2}\lvert 1\rangle,\qquad \lvert \bar a\rangle=\sqrt{1-\alpha^2}\lvert 0\rangle-\alpha\lvert 1\rangle,3 case. The immediate consequence is that some cross-basis channel parameters are no longer directly observable from matched-basis data alone. The central technical idea of the modern analysis is therefore not merely state reduction, but state reduction combined with retention of basis-mismatched outcomes for channel estimation.

Later practical formulations typically specialize the signal set to a=α0+1α21,aˉ=1α20α1,\lvert a\rangle=\alpha\lvert 0\rangle+\sqrt{1-\alpha^2}\lvert 1\rangle,\qquad \lvert \bar a\rangle=\sqrt{1-\alpha^2}\lvert 0\rangle-\alpha\lvert 1\rangle,4. In the finite-key time-bin variant, Alice prepares the two a=α0+1α21,aˉ=1α20α1,\lvert a\rangle=\alpha\lvert 0\rangle+\sqrt{1-\alpha^2}\lvert 1\rangle,\qquad \lvert \bar a\rangle=\sqrt{1-\alpha^2}\lvert 0\rangle-\alpha\lvert 1\rangle,5-basis states a=α0+1α21,aˉ=1α20α1,\lvert a\rangle=\alpha\lvert 0\rangle+\sqrt{1-\alpha^2}\lvert 1\rangle,\qquad \lvert \bar a\rangle=\sqrt{1-\alpha^2}\lvert 0\rangle-\alpha\lvert 1\rangle,6 and a=α0+1α21,aˉ=1α20α1,\lvert a\rangle=\alpha\lvert 0\rangle+\sqrt{1-\alpha^2}\lvert 1\rangle,\qquad \lvert \bar a\rangle=\sqrt{1-\alpha^2}\lvert 0\rangle-\alpha\lvert 1\rangle,7 for data generation and the single a=α0+1α21,aˉ=1α20α1,\lvert a\rangle=\alpha\lvert 0\rangle+\sqrt{1-\alpha^2}\lvert 1\rangle,\qquad \lvert \bar a\rangle=\sqrt{1-\alpha^2}\lvert 0\rangle-\alpha\lvert 1\rangle,8-basis state a=α0+1α21,aˉ=1α20α1,\lvert a\rangle=\alpha\lvert 0\rangle+\sqrt{1-\alpha^2}\lvert 1\rangle,\qquad \lvert \bar a\rangle=\sqrt{1-\alpha^2}\lvert 0\rangle-\alpha\lvert 1\rangle,9 for monitoring, while Bob may employ a reduced α(0,1)\alpha\in(0,1)0-basis measurement that resolves only the outcome orthogonal to α(0,1)\alpha\in(0,1)1, namely α(0,1)\alpha\in(0,1)2, together with no-detection (Rusca et al., 2018). This suggests that “three-state simplified BB84” names a family of protocols whose defining feature is the omission of one conjugate-basis preparation state, while preserving BB84-style key extraction from the computational basis.

2. Security model and the role of mismatched outcomes

The asymptotic security analysis is stated first against collective attacks, with the key rate defined as

α(0,1)\alpha\in(0,1)3

where α(0,1)\alpha\in(0,1)4 is the conditional von Neumann entropy and α(0,1)\alpha\in(0,1)5 is the conditional Shannon entropy, the infimum being taken over attacks consistent with the observed statistics. Owing to permutation invariance and the postselection technique, the resulting bound also applies against general attacks. The device model assumes ideal single-photon qubits, trusted state preparation and measurement, an authenticated classical channel, and no side channels; decoy states and weak-coherent-pulse implementations are not part of that analysis (Krawec, 2016).

Conditioning on rounds that contribute to the raw key, Eve’s collective attack can be written as a unitary α(0,1)\alpha\in(0,1)6 on the transit qubit and her ancilla, initialized to α(0,1)\alpha\in(0,1)7, such that

α(0,1)\alpha\in(0,1)8

Under a symmetric α(0,1)\alpha\in(0,1)9-basis error model,

α=1/2\alpha=1/\sqrt{2}0

where α=1/2\alpha=1/\sqrt{2}1 is the observed QBER in α=1/2\alpha=1/\sqrt{2}2 (Krawec, 2016).

The decisive innovation is the use of basis-mismatched outcomes. Define

α=1/2\alpha=1/\sqrt{2}3

with α=1/2\alpha=1/\sqrt{2}4 and α=1/2\alpha=1/\sqrt{2}5, and define α=1/2\alpha=1/\sqrt{2}6. Then several overlaps of Eve’s ancilla states become directly expressible through mismatched probabilities. Writing α=1/2\alpha=1/\sqrt{2}7,

α=1/2\alpha=1/\sqrt{2}8

α=1/2\alpha=1/\sqrt{2}9

A\mathcal{A}0

while the Cauchy–Schwarz inequality gives A\mathcal{A}1 (Krawec, 2016).

The observable conjugate-basis error

A\mathcal{A}2

then supplies an additional linear relation involving A\mathcal{A}3, A\mathcal{A}4, A\mathcal{A}5, A\mathcal{A}6, A\mathcal{A}7, and A\mathcal{A}8. This is the mechanism by which the protocol compensates for Alice’s inability to prepare A\mathcal{A}9: mismatched outcomes impose enough constraints to bound XX0, the overlap that is crucial for controlling phase errors and Eve’s information. Previous three-state bounds that discarded mismatched outcomes were strictly weaker; in symmetric channels the older bound remained positive only up to approximately XX1 QBER, whereas the refined analysis reaches XX2 (Krawec, 2016).

3. Entropic analysis, computable key-rate bound, and the XX3 threshold

After Bob’s XX4-basis measurement, the joint post-measurement state yields an XX5 marginal of the form

XX6

Using strong subadditivity via an auxiliary classical register and a convexity argument, one obtains

XX7

Because XX8 for both components, this becomes

XX9

The reduced Eve states are

{+,}\{\lvert +\rangle,\lvert -\rangle\}0

with eigenvalues

{+,}\{\lvert +\rangle,\lvert -\rangle\}1

Hence

{+,}\{\lvert +\rangle,\lvert -\rangle\}2

where {+,}\{\lvert +\rangle,\lvert -\rangle\}3 (Krawec, 2016).

The asymptotic key-rate lower bound per sifted bit is therefore

{+,}\{\lvert +\rangle,\lvert -\rangle\}4

Since {+,}\{\lvert +\rangle,\lvert -\rangle\}5 decreases for {+,}\{\lvert +\rangle,\lvert -\rangle\}6, the absolute overlaps may be replaced safely by the absolute real parts,

{+,}\{\lvert +\rangle,\lvert -\rangle\}7

which yields the computable bound

{+,}\{\lvert +\rangle,\lvert -\rangle\}8

All quantities on the right-hand side are determined by the observed {+,}\{\lvert +\rangle,\lvert -\rangle\}9, ±=(0±1)/2\lvert \pm\rangle=(\lvert 0\rangle\pm\lvert 1\rangle)/\sqrt{2}0, and mismatched probabilities ±=(0±1)/2\lvert \pm\rangle=(\lvert 0\rangle\pm\lvert 1\rangle)/\sqrt{2}1, together with unitarity and Cauchy–Schwarz constraints (Krawec, 2016).

Under the symmetric depolarizing channel model

±=(0±1)/2\lvert \pm\rangle=(\lvert 0\rangle\pm\lvert 1\rangle)/\sqrt{2}2

one has

±=(0±1)/2\lvert \pm\rangle=(\lvert 0\rangle\pm\lvert 1\rangle)/\sqrt{2}3

which implies

±=(0±1)/2\lvert \pm\rangle=(\lvert 0\rangle\pm\lvert 1\rangle)/\sqrt{2}4

with ±=(0±1)/2\lvert \pm\rangle=(\lvert 0\rangle\pm\lvert 1\rangle)/\sqrt{2}5. Optimizing over ±=(0±1)/2\lvert \pm\rangle=(\lvert 0\rangle\pm\lvert 1\rangle)/\sqrt{2}6 makes the bound coincide with the four-state BB84 expression

±=(0±1)/2\lvert \pm\rangle=(\lvert 0\rangle\pm\lvert 1\rangle)/\sqrt{2}7

which is positive for ±=(0±1)/2\lvert \pm\rangle=(\lvert 0\rangle\pm\lvert 1\rangle)/\sqrt{2}8 (Krawec, 2016).

The worked example given for ±=(0±1)/2\lvert \pm\rangle=(\lvert 0\rangle\pm\lvert 1\rangle)/\sqrt{2}9, 0\lvert 0\rangle0, and 0\lvert 0\rangle1 illustrates the scale of the bound. With 0\lvert 0\rangle2, one finds

0\lvert 0\rangle3

bits per sifted bit, and therefore

0\lvert 0\rangle4

bits per transmitted signal (Krawec, 2016).

4. Finite-key formulations and reduced receiver measurements

A major subsequent development was the finite-key proof for a simplified BB84-like protocol in which the receiver uses fewer measurement operators. In that formulation, Alice prepares 0\lvert 0\rangle5, 0\lvert 0\rangle6, and 0\lvert 0\rangle7, while Bob’s reduced measurement in the 0\lvert 0\rangle8 basis resolves only the 0\lvert 0\rangle9 outcome plus a no-detection event. In the time-bin implementation, this is equivalent to monitoring only one output port of the interferometer and resolving three time bins A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}00, A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}01, and A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}02, with POVM elements

A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}03

together with a no-detection element A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}04 (Rusca et al., 2018).

Within that framework, the phase error rate can be exactly bounded from measurable probabilities despite the absence of direct A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}05 preparation and direct A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}06 detection. In the simplest three-state formula,

A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}07

where A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}08 and A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}09 is the conditional detection probability. The paper shows the equivalence of this estimator to the ideal BB84 phase-error estimator under the collective-attack model and basis-independent detection efficiency. A monitoring-only time-bin estimator and an efficient overlapped-bin estimator are also given, together with one-decoy finite-key inequalities for lower and upper bounds on single-photon detection contributions (Rusca et al., 2018).

The same work adopts composable security with correctness and secrecy parameters A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}10 and A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}11, and gives a finite-key secret key length

A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}12

The one-decoy method uses two intensities A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}13 with probabilities A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}14 and Hoeffding concentration bounds for finite-size estimation (Rusca et al., 2018).

Later security developments broadened the attack model. One abstract reports a security proof against coherent attack that simultaneously removes the basis-independent detection efficiency condition and introduces a simple phase error rate formula (Yin et al., 2020). Another abstract states finite-key security bounds for decoy-state simplified BB84 against coherent attacks in the universally composable framework, with simulation results showing almost the same performance as standard BB84 even when the total number of pulses is as low as A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}15 (Lu et al., 2020). Taken together, these works indicate a progression from asymptotic collective-attack analysis, through finite-key proofs with reduced measurements, to coherent-attack formulations adapted to practical decoy-state operation.

5. Implementations and hardware simplification

The protocol’s practical appeal is its reduction in state-preparation complexity. In polarization encoding, “Simple and high-speed polarization-based QKD” implemented a three-state BB84 protocol with only three quantum states and one decoy-state level, using a single pulsed laser “in order to reduce possible side-channel attacks.” The system operated at a repetition rate of A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}16 MHz and achieved a secret bit rate of A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}17 bps over A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}18 km of standard fiber (Grünenfelder et al., 2018). In that realization, Alice chose the A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}19 basis with probability A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}20 and the A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}21 basis with probability A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}22, Bob used a passive A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}23 beamsplitter, and only the A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}24–A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}25 events contributed to the raw key.

A more recent time-bin implementation combined one decoy state, passive basis choice, and an explicit state-characterization program in the presence of state-preparation flaws. Alice used phase-randomized weak coherent states, selected the A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}26 basis with probability A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}27, the A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}28 basis with probability A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}29, and chose between signal and decoy intensities A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}30 and A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}31. Bob used a passive A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}32 coupler, so that A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}33 and A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}34, and the finite-key analysis employed a block size A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}35. The loss-tolerant method was adapted to the simplified time-bin POVMs in order to incorporate measured state-preparation flaws directly into the phase-error estimate (Agulleiro et al., 7 Jul 2026).

Distance SKR, perfect-state assumption SKR, LT with SPFs
A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}36 km A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}37 bps A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}38 bps
A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}39 km A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}40 bps A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}41 bps
A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}42 km A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}43 bps A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}44 bps

At the same distances, the corresponding reported A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}45-basis QBERs were A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}46, A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}47, and A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}48, while the phase-error estimates increased when state-preparation flaws were included: at A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}49 km, A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}50 rose from A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}51 under the perfect-state assumption to A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}52; at A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}53 km, from A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}54 to A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}55; and at A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}56 km, from A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}57 to A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}58 (Agulleiro et al., 7 Jul 2026). These figures make explicit that the hardware simplification of three-state BB84 is compatible with nontrivial finite-key operation, but also that the security margin depends sensitively on how faithfully the emitted states are characterized.

A recurrent misconception is that omitting one conjugate-basis state necessarily causes an intrinsic asymptotic loss relative to four-state BB84. The asymptotic analysis shows that this is not true under the symmetric conditions studied there: once mismatched outcomes are retained and used to constrain Eve’s ancilla overlaps, the three-state protocol achieves the same A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}59 QBER threshold as four-state BB84 (Krawec, 2016). A different misconception is the converse claim that the simplification is always cost-free. The literature does not support that stronger statement.

First, the foundational A={a,aˉ}\mathcal{A}=\{\lvert a\rangle,\lvert \bar a\rangle\}60 result is asymptotic and assumes ideal single-photon qubits, trusted state preparation and measurement, an authenticated classical channel, and no side channels; finite-key effects are explicitly outside its scope and “could lower the practical QBER threshold” (Krawec, 2016). Second, practical finite-key proofs often require additional assumptions or refined estimation machinery. In the 2018 reduced-measurement proof, the core derivation assumes collective attacks, treats no-detection conservatively under Eve’s control, and requires basis-independent detection efficiency (Rusca et al., 2018). Later work specifically targeted the removal of that efficiency assumption and the treatment of coherent attacks (Yin et al., 2020).

Third, imperfect-source scenarios alter the comparative picture. “Modified BB84 quantum key distribution protocol robust to source imperfections” compares the achievable secret-key rate of modified four-state BB84 with that of the three-state loss-tolerant protocol and states that the addition of a fourth state, while redundant in ideal conditions, “significantly improves the estimation of the leaked information in the presence of source imperfections, resulting in a better performance.” The source imperfections considered there include state preparation flaws and side channels, such as Trojan-horse attacks, mode dependencies, and classical correlations between emitted pulses (Pereira et al., 2022). This suggests that the three-state restriction is best understood as a resource trade-off rather than a universally dominant replacement criterion.

The implementation literature reinforces the same point. The 2026 time-bin experiment reported correlations between intensity levels and bit/basis encoding due to a single intensity modulator performing both qubit and intensity encoding, and therefore used only signal-level characterization for the loss-tolerant analysis because the original proof assumes independence between qubit encoding and intensity (Agulleiro et al., 7 Jul 2026). The resulting gap between “perfect-state” and flaw-aware secret key rates highlights the importance of characterization and implementation security. In related work beyond aligned BB84, the same three-state reduction has been extended to reference-frame-independent QKD, where transmitting three states was reported to be sufficient to obtain comparable secret key rates and covered distances even when coherent-attack security with finite-key fluctuations is considered (Liu et al., 2018).

The contemporary understanding of three-state simplified BB84 is therefore structurally stable. Its defining insight is that a missing preparation state does not by itself preclude tight security bounds, provided the protocol retains enough auxiliary statistics—especially basis-mismatched outcomes—to reconstruct the parameters that govern phase error and Eve’s information. Its practical significance lies in reduced transmitter and receiver complexity, but its ultimate performance is contingent on the attack model, the finite-key regime, the measurement architecture, and the fidelity with which source imperfections are incorporated into parameter estimation.

Topic to Video (Beta)

No one has generated a video about this topic yet.

Whiteboard

No one has generated a whiteboard explanation for this topic yet.

Follow Topic

Get notified by email when new papers are published related to Three-State Simplified BB84 Protocol.