Three-State Simplified BB84 Protocol
- The three-state simplified BB84 protocol is a quantum key distribution method that uses two computational basis states and one conjugate state for monitoring, reducing state-preparation complexity.
- It retains basis-mismatched outcomes for parameter estimation, achieving an 11% QBER threshold similar to the standard four-state BB84 under symmetric channel conditions.
- Finite-key proofs and hardware implementations, including decoy-state techniques, demonstrate its practical viability and effectiveness in mitigating state-preparation flaws.
Searching arXiv for relevant work on three-state simplified BB84, including asymptotic, finite-key, and implementation/security-with-imperfections results. {"query":"three-state simplified BB84 protocol asymptotic finite-key implementation state preparation flaws", "max_results": 10} {"query":"all:three-state BB84 simplified protocol", "max_results": 10} The Three-State Simplified BB84 Protocol is a prepare-and-measure quantum key distribution scheme obtained by restricting standard BB84 so that Alice transmits only three states rather than four: two key-generating states in the computational basis and one monitoring state in the conjugate basis. In the formulation analyzed asymptotically in “Asymptotic Analysis of a Three State Quantum Cryptographic Protocol” (Krawec, 2016), Alice never prepares one of the conjugate-basis states, yet the protocol can still attain the same asymptotic quantum bit error rate threshold as four-state BB84 when basis-mismatched outcomes are retained for parameter estimation rather than discarded. Subsequent work developed finite-key, reduced-measurement, decoy-state, and implementation-oriented variants, including time-bin and polarization realizations (Rusca et al., 2018).
1. Protocol definition and reduction from standard BB84
In the 2016 asymptotic treatment, the computational basis is denoted and the conjugate basis is , with
where is public. When , reduces to the basis with . Alice prepares and sends one of three states, , 0, or 1, with respective probabilities 2, 3, and 4; notably, she cannot prepare 5. Bob measures in 6 with probability 7 and otherwise in 8. A raw key bit is kept only if both used 9, so the sifted fraction per transmitted signal is 0 (Krawec, 2016).
This restriction differentiates the protocol from standard BB84, which employs all four states 1. In the three-state version, the omitted signal is 2 in the usual 3 case. The immediate consequence is that some cross-basis channel parameters are no longer directly observable from matched-basis data alone. The central technical idea of the modern analysis is therefore not merely state reduction, but state reduction combined with retention of basis-mismatched outcomes for channel estimation.
Later practical formulations typically specialize the signal set to 4. In the finite-key time-bin variant, Alice prepares the two 5-basis states 6 and 7 for data generation and the single 8-basis state 9 for monitoring, while Bob may employ a reduced 0-basis measurement that resolves only the outcome orthogonal to 1, namely 2, together with no-detection (Rusca et al., 2018). This suggests that “three-state simplified BB84” names a family of protocols whose defining feature is the omission of one conjugate-basis preparation state, while preserving BB84-style key extraction from the computational basis.
2. Security model and the role of mismatched outcomes
The asymptotic security analysis is stated first against collective attacks, with the key rate defined as
3
where 4 is the conditional von Neumann entropy and 5 is the conditional Shannon entropy, the infimum being taken over attacks consistent with the observed statistics. Owing to permutation invariance and the postselection technique, the resulting bound also applies against general attacks. The device model assumes ideal single-photon qubits, trusted state preparation and measurement, an authenticated classical channel, and no side channels; decoy states and weak-coherent-pulse implementations are not part of that analysis (Krawec, 2016).
Conditioning on rounds that contribute to the raw key, Eve’s collective attack can be written as a unitary 6 on the transit qubit and her ancilla, initialized to 7, such that
8
Under a symmetric 9-basis error model,
0
where 1 is the observed QBER in 2 (Krawec, 2016).
The decisive innovation is the use of basis-mismatched outcomes. Define
3
with 4 and 5, and define 6. Then several overlaps of Eve’s ancilla states become directly expressible through mismatched probabilities. Writing 7,
8
9
0
while the Cauchy–Schwarz inequality gives 1 (Krawec, 2016).
The observable conjugate-basis error
2
then supplies an additional linear relation involving 3, 4, 5, 6, 7, and 8. This is the mechanism by which the protocol compensates for Alice’s inability to prepare 9: mismatched outcomes impose enough constraints to bound 0, the overlap that is crucial for controlling phase errors and Eve’s information. Previous three-state bounds that discarded mismatched outcomes were strictly weaker; in symmetric channels the older bound remained positive only up to approximately 1 QBER, whereas the refined analysis reaches 2 (Krawec, 2016).
3. Entropic analysis, computable key-rate bound, and the 3 threshold
After Bob’s 4-basis measurement, the joint post-measurement state yields an 5 marginal of the form
6
Using strong subadditivity via an auxiliary classical register and a convexity argument, one obtains
7
Because 8 for both components, this becomes
9
The reduced Eve states are
0
with eigenvalues
1
Hence
2
where 3 (Krawec, 2016).
The asymptotic key-rate lower bound per sifted bit is therefore
4
Since 5 decreases for 6, the absolute overlaps may be replaced safely by the absolute real parts,
7
which yields the computable bound
8
All quantities on the right-hand side are determined by the observed 9, 0, and mismatched probabilities 1, together with unitarity and Cauchy–Schwarz constraints (Krawec, 2016).
Under the symmetric depolarizing channel model
2
one has
3
which implies
4
with 5. Optimizing over 6 makes the bound coincide with the four-state BB84 expression
7
which is positive for 8 (Krawec, 2016).
The worked example given for 9, 0, and 1 illustrates the scale of the bound. With 2, one finds
3
bits per sifted bit, and therefore
4
bits per transmitted signal (Krawec, 2016).
4. Finite-key formulations and reduced receiver measurements
A major subsequent development was the finite-key proof for a simplified BB84-like protocol in which the receiver uses fewer measurement operators. In that formulation, Alice prepares 5, 6, and 7, while Bob’s reduced measurement in the 8 basis resolves only the 9 outcome plus a no-detection event. In the time-bin implementation, this is equivalent to monitoring only one output port of the interferometer and resolving three time bins 00, 01, and 02, with POVM elements
03
together with a no-detection element 04 (Rusca et al., 2018).
Within that framework, the phase error rate can be exactly bounded from measurable probabilities despite the absence of direct 05 preparation and direct 06 detection. In the simplest three-state formula,
07
where 08 and 09 is the conditional detection probability. The paper shows the equivalence of this estimator to the ideal BB84 phase-error estimator under the collective-attack model and basis-independent detection efficiency. A monitoring-only time-bin estimator and an efficient overlapped-bin estimator are also given, together with one-decoy finite-key inequalities for lower and upper bounds on single-photon detection contributions (Rusca et al., 2018).
The same work adopts composable security with correctness and secrecy parameters 10 and 11, and gives a finite-key secret key length
12
The one-decoy method uses two intensities 13 with probabilities 14 and Hoeffding concentration bounds for finite-size estimation (Rusca et al., 2018).
Later security developments broadened the attack model. One abstract reports a security proof against coherent attack that simultaneously removes the basis-independent detection efficiency condition and introduces a simple phase error rate formula (Yin et al., 2020). Another abstract states finite-key security bounds for decoy-state simplified BB84 against coherent attacks in the universally composable framework, with simulation results showing almost the same performance as standard BB84 even when the total number of pulses is as low as 15 (Lu et al., 2020). Taken together, these works indicate a progression from asymptotic collective-attack analysis, through finite-key proofs with reduced measurements, to coherent-attack formulations adapted to practical decoy-state operation.
5. Implementations and hardware simplification
The protocol’s practical appeal is its reduction in state-preparation complexity. In polarization encoding, “Simple and high-speed polarization-based QKD” implemented a three-state BB84 protocol with only three quantum states and one decoy-state level, using a single pulsed laser “in order to reduce possible side-channel attacks.” The system operated at a repetition rate of 16 MHz and achieved a secret bit rate of 17 bps over 18 km of standard fiber (Grünenfelder et al., 2018). In that realization, Alice chose the 19 basis with probability 20 and the 21 basis with probability 22, Bob used a passive 23 beamsplitter, and only the 24–25 events contributed to the raw key.
A more recent time-bin implementation combined one decoy state, passive basis choice, and an explicit state-characterization program in the presence of state-preparation flaws. Alice used phase-randomized weak coherent states, selected the 26 basis with probability 27, the 28 basis with probability 29, and chose between signal and decoy intensities 30 and 31. Bob used a passive 32 coupler, so that 33 and 34, and the finite-key analysis employed a block size 35. The loss-tolerant method was adapted to the simplified time-bin POVMs in order to incorporate measured state-preparation flaws directly into the phase-error estimate (Agulleiro et al., 7 Jul 2026).
| Distance | SKR, perfect-state assumption | SKR, LT with SPFs |
|---|---|---|
| 36 km | 37 bps | 38 bps |
| 39 km | 40 bps | 41 bps |
| 42 km | 43 bps | 44 bps |
At the same distances, the corresponding reported 45-basis QBERs were 46, 47, and 48, while the phase-error estimates increased when state-preparation flaws were included: at 49 km, 50 rose from 51 under the perfect-state assumption to 52; at 53 km, from 54 to 55; and at 56 km, from 57 to 58 (Agulleiro et al., 7 Jul 2026). These figures make explicit that the hardware simplification of three-state BB84 is compatible with nontrivial finite-key operation, but also that the security margin depends sensitively on how faithfully the emitted states are characterized.
6. Limits, misconceptions, and related research directions
A recurrent misconception is that omitting one conjugate-basis state necessarily causes an intrinsic asymptotic loss relative to four-state BB84. The asymptotic analysis shows that this is not true under the symmetric conditions studied there: once mismatched outcomes are retained and used to constrain Eve’s ancilla overlaps, the three-state protocol achieves the same 59 QBER threshold as four-state BB84 (Krawec, 2016). A different misconception is the converse claim that the simplification is always cost-free. The literature does not support that stronger statement.
First, the foundational 60 result is asymptotic and assumes ideal single-photon qubits, trusted state preparation and measurement, an authenticated classical channel, and no side channels; finite-key effects are explicitly outside its scope and “could lower the practical QBER threshold” (Krawec, 2016). Second, practical finite-key proofs often require additional assumptions or refined estimation machinery. In the 2018 reduced-measurement proof, the core derivation assumes collective attacks, treats no-detection conservatively under Eve’s control, and requires basis-independent detection efficiency (Rusca et al., 2018). Later work specifically targeted the removal of that efficiency assumption and the treatment of coherent attacks (Yin et al., 2020).
Third, imperfect-source scenarios alter the comparative picture. “Modified BB84 quantum key distribution protocol robust to source imperfections” compares the achievable secret-key rate of modified four-state BB84 with that of the three-state loss-tolerant protocol and states that the addition of a fourth state, while redundant in ideal conditions, “significantly improves the estimation of the leaked information in the presence of source imperfections, resulting in a better performance.” The source imperfections considered there include state preparation flaws and side channels, such as Trojan-horse attacks, mode dependencies, and classical correlations between emitted pulses (Pereira et al., 2022). This suggests that the three-state restriction is best understood as a resource trade-off rather than a universally dominant replacement criterion.
The implementation literature reinforces the same point. The 2026 time-bin experiment reported correlations between intensity levels and bit/basis encoding due to a single intensity modulator performing both qubit and intensity encoding, and therefore used only signal-level characterization for the loss-tolerant analysis because the original proof assumes independence between qubit encoding and intensity (Agulleiro et al., 7 Jul 2026). The resulting gap between “perfect-state” and flaw-aware secret key rates highlights the importance of characterization and implementation security. In related work beyond aligned BB84, the same three-state reduction has been extended to reference-frame-independent QKD, where transmitting three states was reported to be sufficient to obtain comparable secret key rates and covered distances even when coherent-attack security with finite-key fluctuations is considered (Liu et al., 2018).
The contemporary understanding of three-state simplified BB84 is therefore structurally stable. Its defining insight is that a missing preparation state does not by itself preclude tight security bounds, provided the protocol retains enough auxiliary statistics—especially basis-mismatched outcomes—to reconstruct the parameters that govern phase error and Eve’s information. Its practical significance lies in reduced transmitter and receiver complexity, but its ultimate performance is contingent on the attack model, the finite-key regime, the measurement architecture, and the fidelity with which source imperfections are incorporated into parameter estimation.