Decoy-State QKD
Decoy-state quantum key distribution is a parameter-estimation method for QKD transmitters that emit phase-randomized weak coherent pulses rather than deterministic single photons. Alice randomly changes the pulse intensity. The different intensity classes contain different known mixtures of vacuum, one-photon, and multiphoton emissions, yet a pulse containing exactly photons is required to have the same relevant quantum state regardless of the intensity label. Comparing the observed detection and error rates then bounds the yield and error rate of the one-photon sector.
That estimate repairs a specific inference problem. It does not make an optical implementation secure by itself. A complete protocol still requires the composable security contract, authenticated communication, basis-resolved parameter estimation, reconciliation, verification, privacy amplification, finite-size corrections, and a source-and-detector model described in Quantum Key Distribution. BB84 remains the canonical home of the four-state protocol and its bit-versus-phase error reasoning. This page owns the decoy-state photon-number model, analytic vacuum-plus-weak bounds, and the assumptions under which those bounds are valid.
The Practical Source Problem
Section titled “The Practical Source Problem”Weak laser pulses are not single photons
Section titled “Weak laser pulses are not single photons”An attenuated laser pulse is naturally modeled as a coherent state. If its mean photon number is , write its complex amplitude as . In the photon-number basis,
If Alice uniformly randomizes the global optical phase independently on every pulse and does not reveal it, averaging over removes the coherence between distinct photon-number sectors:
The pulse is therefore a classical Poisson mixture of photon-number states, not a coherent superposition between sectors for the security model being used. In particular,
Vacuum pulses do not normally carry Alice’s bit. One-photon pulses support the qubit security argument. Multiphoton pulses require special care because two or more copies of the same encoded optical state may leave the transmitter.
The photon-number-splitting warning
Section titled “The photon-number-splitting warning”Consider a highly lossy channel and suppose Alice and Bob inspect only the overall click probability and quantum bit error rate. An adversary can, as an illustrative attack, perform a quantum-nondemolition measurement of photon number, block selected vacuum and one-photon pulses, and remove one photon from a multiphoton pulse while forwarding the rest losslessly. Eve stores her photon until Alice announces the basis and then measures in that basis. On those forwarded multiphoton rounds she can learn the bit without introducing the intercept–resend error signature.
The point is not that every real attack literally uses a photon-number splitter. The point is non-identifiability. One overall detection rate can be explained by many different photon-number-dependent channel responses. A low observed error rate does not by itself show that enough detections came from the one-photon sector.
If every multiphoton emission is conservatively treated as tagged and known to Eve, the key-producing resource is the number of detected one-photon signals. Without additional observations, Alice and Bob cannot estimate that number tightly in a high-loss channel. Decoy intensities supply those observations.
The Decoy-State Principle
Section titled “The Decoy-State Principle”Alice chooses an intensity label at random for each pulse. A common three-intensity design uses
where is the signal intensity, is a weak decoy intensity, and is a vacuum decoy. The intensity label is normally disclosed over the authenticated public channel only after Bob has fixed his detection record.
The central security assumption is conditional indistinguishability:
Given that a pulse contains exactly photons, Eve cannot tell whether it came from the signal or decoy setting except through information already included in the proof model.
In the idealized model, changing changes only the Poisson probabilities . It does not change the encoded polarization, time-bin, spectrum, spatial mode, pulse shape, or any other side channel at fixed . Eve may know , control the channel, and later learn . She still has to apply the same conditional response to an -photon signal and an -photon decoy because their conditional states are identical when they enter her control.
This is why decoy pulses need not be secret forever. Random selection and delayed announcement prevent Eve from tailoring a channel action to a known label before Bob’s event record is fixed; state indistinguishability prevents her from learning the label from an unmodeled optical degree of freedom.
Decoy-state estimation is a constrained linear inverse problem. Vacuum, weak-decoy, and signal settings probe the same yields with different known Poisson weights. Error gains obey an analogous system with unknowns .
Yields, Gains, and Error Gains
Section titled “Yields, Gains, and Error Gains”Suppress the basis label temporarily. For an emitted -photon pulse, define the yield
Define the conditional error rate
For intensity , the experimentally accessible gain and error gain are
where is the observed QBER among detected rounds of that intensity. The Poisson mixture and conditional-indistinguishability assumption give
It is useful to remove the common Poisson factor:
These are exponential generating functions for the yields and error yields. With an ideal continuum of exactly known intensities near zero,
This infinite-decoy limit gives the clean intuition. A practical experiment uses only a few intensities and finite counts, so it obtains bounds rather than an exact inversion.
The same definitions are applied separately by basis in a modern proof. For example, and the number of detected single-photon -basis signals enter the key length, while -basis data help bound the corresponding phase error. Writing one basis-independent is an expository simplification, not permission to average incompatible data sets.
Vacuum-Plus-Weak Bounds
Section titled “Vacuum-Plus-Weak Bounds”The three settings already give a useful analytic estimate. For a true vacuum decoy,
Background detections are often modeled as random bits, giving . That value is a model choice to be checked against the receiver and its assignment rules; the vacuum data themselves estimate the background yield.
Lower bound on the one-photon yield
Section titled “Lower bound on the one-photon yield”Expand the weak and signal gains:
Form the combination
Because and , every term in the last line is nonpositive. The coefficient vanishes, and the coefficients for are negative. Therefore
Solving for gives the standard vacuum-plus-weak lower bound
An implementation clips an analytic estimate to the physical interval . In finite data, confidence bounds must be inserted with the directions that make smallest: a lower bound for and upper bounds for and in this expression. A composable proof should derive those substitutions within its chosen statistical framework rather than treat point estimates as exact probabilities.
The single-photon contribution to signal-intensity detections is then bounded by
Upper bound on the one-photon error rate
Section titled “Upper bound on the one-photon error rate”All error-yield terms are nonnegative, so the weak-decoy error gain satisfies
Consequently,
The numerator is made large and the denominator small when converting this formula into a finite-statistics bound. Physical clipping, zero denominators, and an apparently negative background-subtracted numerator need explicit handling. Many proofs cap a bit-error estimate at because larger values are no more useful for binary privacy amplification, but the permitted cap and its meaning belong to the proof being implemented.
These compact formulas are not the only decoy estimator. Linear or convex programs can incorporate more intensities, calibration intervals, basis dependence, and finite-count constraints without forcing each uncertainty through a hand-derived expression.
Worked Channel Example
Section titled “Worked Channel Example”Take an illustrative threshold-detector model with overall one-photon transmission-and-detection efficiency , background yield , background error probability , and optical misalignment error . A simple low-background model is
The second expression neglects the small overlap between a background event and a signal-origin event; it is a calculation model, not a detector security proof. Choose
The predicted signal and decoy observations are
Substitution in the analytic bounds gives
and hence
For comparison, the channel model’s actual one-photon yield is
The bound is lower, as it must be, but remains close enough to certify a substantial single-photon contribution. Without intensity variation, the same overall signal gain would not determine that contribution.
From a Yield Bound to a Key Rate
Section titled “From a Yield Bound to a Key Rate”In the asymptotic tagged-signal picture, multiphoton signal detections are treated as fully compromised and only single-photon detections contribute privacy. A widely used BB84 ledger is
where
is the binary entropy, describes reconciliation inefficiency, and is a declared signal-and-basis selection prefactor. In the traditional symmetric BB84 convention with an asymptotically negligible decoy fraction, . If signal intensity is chosen with probability and only - rounds make key, then a per-emitted-pulse ledger instead contains the corresponding factor .
For the numerical example, taking gives the bracketed quantity
Thus the conventional example yields approximately secret bits per emitted pulse before finite-key, authentication, and other implementation overheads. A positive asymptotic number is not a claim about a finite device run.
The formula also hides an important proof step. In BB84, privacy amplification depends on a single-photon phase-error rate. Under the symmetry and source assumptions of the relevant proof, conjugate-basis single-photon observations bound that phase error. One must not insert an arbitrary aggregate optical QBER into the privacy term merely because it has a similar numerical value.
Finite-Key Estimation
Section titled “Finite-Key Estimation”A real block supplies counts, not exact probabilities. For each intensity and basis class, let
The observed ratios are
Composable finite-key analysis replaces these ratios by simultaneous confidence bounds whose failure probabilities are included in the total security budget. One convenient abstract form is
Subject to and , Alice and Bob minimize the desired single-photon count and maximize the relevant error parameter. A numerical linear program truncates the photon number at and accounts for the known Poisson tail
The tail cannot simply be discarded; it must be assigned in the adverse direction allowed by the constraints.
A typical finite-key result has the structure
where bounds detected one-photon key-basis events, bounds their phase-error rate, is the actual reconciliation leakage, and collects verification, smoothing, privacy amplification, and declared failure-probability terms. The exact coefficients depend on the proof. The finite-key analysis of Lim et al. is one important composable construction against general attacks; one-decoy analyses require their own bounds and allocation choices.
Why more decoys can still mean less key
Section titled “Why more decoys can still mean less key”Additional intensity settings add constraints, but finite samples must be divided among more classes. A very weak decoy is informative about only if it produces enough detections to control fluctuations. A vacuum setting measures background directly but produces few useful events by design. The signal intensity, decoy intensities, basis biases, and selection probabilities therefore need joint optimization for the expected channel, block duration, detector behavior, and security target.
Rules of thumb such as and are useful starting points for some fiber links, not protocol constants. At long distance, the best allocation may devote a substantial fraction of pulses to parameter estimation. In a changing channel, an optimization based on a favorable past block can also bias the analysis unless adaptation is specified in advance or covered by the proof.
Source Assumptions That Carry the Proof
Section titled “Source Assumptions That Carry the Proof”Phase randomization
Section titled “Phase randomization”The Poisson mixture follows from averaging a uniformly random global phase. Attenuation alone does not perform that average. Gain-switching a laser may produce substantial phase randomization under characterized operating conditions, but it is not a mathematical guarantee for every pulse. Residual phase coherence can let Eve distinguish or coherently combine states in ways excluded by the photon-number-channel model. A transmitter should actively randomize or otherwise validate the phase model used by its proof.
Protocols with nonrandom or partially known phase can still have security proofs, but the proof and state decomposition are different. The standard decoy equations must not be imported unchanged.
Intensity calibration and fluctuations
Section titled “Intensity calibration and fluctuations”The symbols and represent physical photon-number distributions, not merely digital control values. Modulator calibration, laser power drift, finite extinction, pulse-shape changes, and monitor uncertainty produce intervals or correlations in the actual intensities. A sound analysis either bounds the emitted distribution pulse by pulse or uses a security proof that explicitly tolerates the characterized fluctuation model.
Replacing an uncertain by its nominal value can move Poisson weights in the favorable direction and overestimate . The conservative endpoint is not always the same for every coefficient, so blindly inserting one worst intensity into every term is not generally valid.
No intensity side channel at fixed photon number
Section titled “No intensity side channel at fixed photon number”Signal and decoy pulses can differ in spectrum, timing, chirp, spatial mode, polarization, pulse duration, or back-reflected light. If Eve can infer the intensity class before acting on the pulse, the correct variables are rather than shared . The standard system then loses its cross-intensity constraint.
This issue is especially important when separate lasers generate signal and decoy pulses. A single laser followed by a characterized intensity modulator can reduce some differences, but the modulator itself can introduce chirp or pattern dependence. Optical isolation, filtering, watchdog monitoring, and Trojan-horse bounds address parts of the engineering problem; their residual assumptions still belong in the security statement.
Correlations and detector behavior
Section titled “Correlations and detector behavior”Dead time, afterpulsing, modulator memory, feedback control, and thermal drift can correlate neighboring rounds. A proof based on independent and identically distributed trials is not automatically valid for such a source or receiver. Modern analyses may use martingale, entropy-accumulation, or explicit source-memory methods, but the observed data must match the chosen model.
Decoy states do not remove detector side channels. Detector blinding, efficiency mismatch, time-shift attacks, and mode-dependent acceptance remain receiver-model questions. Measurement-Device-Independent QKD combines two-source decoy estimation with an untrusted measurement station to move that particular trust boundary; it still relies on source characterization and decoy-state assumptions.
Protocol Variants
Section titled “Protocol Variants”Vacuum plus weak decoy
Section titled “Vacuum plus weak decoy”The signal, weak-decoy, and vacuum settings used above are often called a two-decoy protocol because there are two nonsignal intensities. It gives simple analytic bounds and can approach the asymptotic performance of an ideal many-decoy protocol under the standard source model.
One-decoy protocols
Section titled “One-decoy protocols”A signal plus one nonzero decoy removes the dedicated vacuum setting. The background yield must then be bounded indirectly or through other data. This can simplify high-speed hardware and improve finite allocation in some regimes, but it changes the estimator. A vacuum-plus-weak formula with an unmeasured must not be presented as a one-decoy result.
Biased-basis and four-intensity designs
Section titled “Biased-basis and four-intensity designs”Efficient BB84 strongly favors the key basis and reserves the conjugate basis for phase-error estimation. Some practical protocols choose intensities with basis-dependent probabilities or use a dedicated intensity in each basis. The resulting rate can improve, but basis and intensity labels must remain in the parameter-estimation bookkeeping. Pooling all gains into one basis-free table may erase exactly the distinction the security proof needs.
Passive decoys and heralded sources
Section titled “Passive decoys and heralded sources”Instead of actively modulating each pulse, a transmitter can infer intensity classes from a correlated local measurement or passive optical network. Heralded parametric sources lead to related photon-number conditioning. These schemes can reduce active modulation leakage, but the conditional source states and monitor detector must be modeled explicitly; they are not automatically equivalent to Poissonian active decoys.
What Decoy States Do Not Establish
Section titled “What Decoy States Do Not Establish”| Claim | What decoy analysis actually provides | What remains |
|---|---|---|
| “The source is now a single-photon source.” | A bound on detections attributable to the one-photon sector. | Vacuum and multiphoton pulses are still emitted. |
| “Photon-number splitting is impossible.” | A rate that remains secure while multiphoton rounds may be tagged. | The proof still needs valid source indistinguishability and statistics. |
| “A low QBER proves secrecy.” | Error gains help bound one-photon errors. | Phase errors, finite-size terms, leakage, and authentication remain. |
| “Detector attacks are closed.” | Nothing about an unmodeled receiver follows from changing source intensity. | Detector characterization, hardening, or a different trust architecture is required. |
| “Nominal intensities are enough.” | Known Poisson weights make the inverse problem possible. | Calibration uncertainty, drift, correlations, and side channels must be bounded. |
| “An asymptotic positive rate means this run made a key.” | The formula diagnoses an ideal large-block regime. | The actual transcript needs a finite-key proof and positive final length. |
Common Mistakes
Section titled “Common Mistakes”Treating as the one-photon gain
Section titled “Treating QμQ_\muQμ as the one-photon gain”includes vacuum-background, one-photon, and multiphoton detections. The quantity entering the untagged privacy term is , bounded through all intensity classes.
Forgetting the exponential factor
Section titled “Forgetting the exponential factor”The linear generating function is , not . Omitting changes every coefficient and invalidates the analytic bound.
Reversing the inequality in the derivation
Section titled “Reversing the inequality in the Y1Y_1Y1 derivation”For , . The discarded tail makes smaller, so the resulting inequality is an upper bound on and therefore a lower bound on .
Using point estimates in a finite run
Section titled “Using point estimates in a finite run”fluctuates. Substituting it directly for silently claims an infinite sample. Confidence failures must be allocated and composed with the other security errors.
Assuming the intensity label is the only difference
Section titled “Assuming the intensity label is the only difference”That is the hypothesis to validate, not a consequence of naming a pulse “decoy.” At fixed photon number, any exploitable spectral, temporal, spatial, or polarization difference can make the shared-yield equations false.
Exercises
Section titled “Exercises”1. Phase averaging
Section titled “1. Phase averaging”Starting from the coherent-state expansion, prove that uniform phase randomization produces a diagonal Poisson mixture.
Solution
Expand the projector:
Uniform averaging uses
Only remains, giving
2. Multiphoton probability
Section titled “2. Multiphoton probability”Show that . Find its leading behavior for and evaluate it at .
Solution
Subtract the vacuum and one-photon probabilities from unity:
Using gives
At ,
Thus roughly nine percent of emitted signal pulses are multiphoton in this source model, even though loss makes the detected fraction quite different.
3. Derive the one-photon yield bound
Section titled “3. Derive the one-photon yield bound”For , derive the vacuum-plus-weak lower bound on by forming . State where nonnegativity is used.
Solution
The combination is
The tail is nonpositive because and . Dropping it therefore increases the right-hand side. Rearranging the resulting inequality and inserting gives
4. Derive the error bound
Section titled “4. Derive the error bound”Starting from , derive an upper bound on . Explain why replacing by a lower bound is conservative.
Solution
Nonnegative multiphoton error yields imply
Therefore
For a nonnegative numerator, decreasing the denominator increases the ratio. Using therefore preserves an upper bound. A finite analysis separately bounds each observed quantity and handles an unfavorable or statistically negative background-subtracted numerator according to its optimization procedure.
5. Reproduce the channel estimate
Section titled “5. Reproduce the channel estimate”Use the worked-example parameters to calculate , , and . Compare the yield bound with the model value .
Solution
The gains and error rates are
Substitution gives
and
The model value is , so the analytic lower bound is about of the actual value in this noiseless, asymptotic calculation.
6. Infinite-decoy reconstruction
Section titled “6. Infinite-decoy reconstruction”Suppose is known exactly for all in a neighborhood of zero. Show how to reconstruct , , and .
Solution
Define . Its series is
Hence
In general . Exact differentiation is only an intuition for the infinite-data, continuous-intensity limit; numerical differentiation of noisy experimental gains would be unstable.
7. A distinguishable-decoy failure
Section titled “7. A distinguishable-decoy failure”Suppose weak-decoy pulses are delayed by relative to signal pulses, and Eve can resolve that delay before deciding whether to forward a pulse. Identify the failed equation and explain what extra evidence or analysis is needed.
Solution
At fixed photon number, Eve can infer the class from arrival time. The shared yield model fails: one must allow
Then comparing and no longer constrains one common . Alice needs source characterization showing that the delay is absent or bounded strongly enough for a proof with distinguishable states, or she needs a protocol and security analysis that explicitly includes the leaked timing information. Relabeling the pulses does not repair the model.
8. Finite-key resource allocation
Section titled “8. Finite-key resource allocation”Alice can reduce the weak-decoy probability to send more signal pulses. Give one benefit and two costs of doing so in a fixed-duration experiment.
Solution
The benefit is a larger expected number of signal-and-key-basis detections, which can increase the raw material for the final key. The costs are fewer weak-decoy detections and therefore wider confidence intervals for and . A looser lower bound on or a looser upper bound on the phase error can erase the gain or force abort. The best probability is therefore a finite-block optimization, not “as few decoys as possible.” Channel drift can add a third cost if the smaller sample no longer diagnoses nonstationarity.
Further Connections
Section titled “Further Connections”- Quantum Key Distribution supplies the composable secrecy, authentication, distillation, and finite-key contract around this estimator.
- BB84 develops the four-state transcript and the single-photon bit–phase error relation used by the privacy term.
- Measurement-Device-Independent QKD generalizes the gain equations to photon-number pairs and moves all relay detectors outside the trusted boundary.
- Photon-Number States develops Fock states, number statistics, and optical detection language.
- Coherent States derives coherent-state amplitudes and their Poisson number distribution.
- Photonic Qubits owns source, encoding, loss, mode, and detector hardware considerations.
- Cryptography Case Studies applies decoy estimation inside a concrete lossy-fiber rate and distance ledger.
- Trace Distance explains the operational metric behind composable secrecy.
References
Section titled “References”- W.-Y. Hwang, “Quantum Key Distribution with High Loss: Toward Global Secure Communication,” Physical Review Letters 91, 057901 (2003), doi:10.1103/PhysRevLett.91.057901.
- H.-K. Lo, X. Ma, and K. Chen, “Decoy State Quantum Key Distribution,” Physical Review Letters 94, 230504 (2005), doi:10.1103/PhysRevLett.94.230504.
- X.-B. Wang, “Beating the Photon-Number-Splitting Attack in Practical Quantum Cryptography,” Physical Review Letters 94, 230503 (2005), doi:10.1103/PhysRevLett.94.230503.
- X. Ma, B. Qi, Y. Zhao, and H.-K. Lo, “Practical Decoy State for Quantum Key Distribution,” Physical Review A 72, 012326 (2005), doi:10.1103/PhysRevA.72.012326.
- D. Gottesman, H.-K. Lo, N. Lütkenhaus, and J. Preskill, “Security of Quantum Key Distribution with Imperfect Devices,” Quantum Information and Computation 4, 325–360 (2004), doi:10.26421/QIC4.5-1.
- H.-K. Lo and J. Preskill, “Security of Quantum Key Distribution Using Weak Coherent States with Nonrandom Phases,” Quantum Information and Computation 7, 431–458 (2007), doi:10.26421/QIC7.5-6-2.
- C. C. W. Lim, M. Curty, N. Walenta, F. Xu, and H. Zbinden, “Concise Security Bounds for Practical Decoy-State Quantum Key Distribution,” Physical Review A 89, 022307 (2014), doi:10.1103/PhysRevA.89.022307.
- D. Rusca, A. Boaron, F. Grünenfelder, A. Martin, and H. Zbinden, “Finite-Key Analysis for the 1-Decoy State QKD Protocol,” Applied Physics Letters 112, 171104 (2018), doi:10.1063/1.5023340.
- V. Scarani, H. Bechmann-Pasquinucci, N. J. Cerf, et al., “The Security of Practical Quantum Key Distribution,” Reviews of Modern Physics 81, 1301–1350 (2009), doi:10.1103/RevModPhys.81.1301.
- F. Xu, X. Ma, Q. Zhang, H.-K. Lo, and J.-W. Pan, “Secure Quantum Key Distribution with Realistic Devices,” Reviews of Modern Physics 92, 025002 (2020), doi:10.1103/RevModPhys.92.025002.
- D. Rosenberg, J. W. Harrington, P. R. Rice, et al., “Long-Distance Decoy-State Quantum Key Distribution in Optical Fiber,” Physical Review Letters 98, 010503 (2007), doi:10.1103/PhysRevLett.98.010503.
- T. Schmitt-Manderbach, H. Weier, M. Fürst, et al., “Experimental Demonstration of Free-Space Decoy-State Quantum Key Distribution over 144 km,” Physical Review Letters 98, 010504 (2007), doi:10.1103/PhysRevLett.98.010504.
- C.-Z. Peng, J. Zhang, D. Yang, et al., “Experimental Long-Distance Decoy-State Quantum Key Distribution Based on Polarization Encoding,” Physical Review Letters 98, 010505 (2007), doi:10.1103/PhysRevLett.98.010505.
- A. Boaron, G. Boso, D. Rusca, et al., “Secure Quantum Key Distribution over 421 km of Optical Fiber,” Physical Review Letters 121, 190502 (2018), doi:10.1103/PhysRevLett.121.190502.
- K. Tamaki, M. Curty, G. Kato, H.-K. Lo, and K. Azuma, “Loss-Tolerant Quantum Cryptography with Imperfect Sources,” Physical Review A 90, 052314 (2014), doi:10.1103/PhysRevA.90.052314.
Summary
Section titled “Summary”Phase randomization turns a weak coherent pulse of mean photon number into the Poisson mixture
Random signal and decoy intensities apply different known weights to the same conditional yields and error yields . Their measured gains therefore bound the one-photon signal contribution even when Eve controls the lossy channel. Vacuum-plus-weak data give analytic bounds on and ; finite protocols replace exact gains by confidence regions and convert the result into a bound on single-photon key events and phase errors.
The method is only as trustworthy as its source model. Phase randomization, intensity calibration, fixed- indistinguishability, side-channel control, correlation treatment, detector assumptions, and the complete composable postprocessing ledger all remain part of the security claim.