Improving the Maximum Transmission Distance of Self-Referenced Continuous-Variable Quantum Key Distribution Using a Noiseless Linear Amplifier

We show that a noiseless linear amplifier (NLA) can be placed properly at the receiver’s end to improve the performance of self-referenced (SR) continuous variable quantum key distribution (CV-QKD) when the reference pulses are weak. In SR CV-QKD, the imperfections of the amplitude modulator limit the maximal amplitude of the reference pulses, while the performance of SR CV-QKD is positively related to the amplitude of the reference pulses. An NLA can compensate the impacts of large phase noise introduced by the weak reference pulses. Simulation results derived from collective attacks show that this scheme can improve the performance of SR CV-QKD with weak reference pulses, in terms of extending maximum transmission distance. An NLA with a gain of g can increase the maximum transmission distance by the equivalent of 20log10g dB of losses.


Introduction
Quantum key distribution (QKD) is the state-of-the-art application of quantum technologies, which is able to establish a secret key between two distant legal communicators, usually called Alice and Bob, through an insecure classical channel or quantum channel [1][2][3][4]. QKD has three major branches, the first is the discrete variable (DV) QKD based on manipulating and detecting the single photon state (polarization or phase), the second is the continuous variable (CV) QKD based on preparing and measuring coherent state or EPR state [5][6][7][8], and the last one is the differential phase reference (DPR) QKD [9][10][11]. With the depth of research in recent years, CV-QKD has fully demonstrated its major merits, such as high detection efficiency and low experimental cost. Most importantly, it can be implemented by using the existing commercial fibre communication networks, so it has attracted much attention and given many meaningful research results [12][13][14][15][16].
Generally, the most studied CV-QKD protocol is the GG02 protocol [5] and its unconditional security has been conducted in theory [17][18][19]. However, recent studies show that the imperfections in the Gaussian CV-QKD experimental system setups will cause a series of new severe security loopholes [20][21][22]. Furthermore, in Gaussian CV-QKD protocols, a high-brightness classical beam called local oscillator (LO) is co-transmitted with the weak quantum signal. The LO is indispensable because it can provide phase reference when Bob performs coherent detection on the received quantum signals. Some side-channel attacks aiming at LO have been confirmed , which can greatly reduce the overall security of the Gaussian CV-QKD protocol [23,24]. Fortunately, a novel scheme named self-referenced (SR) CV-QKD that could generate real "local" LO at Bob's end has been proposed very recently [25][26][27] and shows its robustness in allusion to these attacks. However, due to the limited dynamic modulation range of the amplitude modulator, the amplitude of the reference pulses cannot be too large in practical. Besides, the imperfections in Alice's modulator will create an extra excess noise proportional to the amplitude of reference pulses. This further limits the maximum amplitude of the reference pulses [28]. Since the secret key rate and the maximum transmission distance of SR CV-QKD scheme is positively correlated with the amplitude of the reference pulses, the weak reference pulses can degrade the performance of SR CV-QKD greatly.
Recently, some works have shown that a noiseless linear amplifier (NLA) [29][30][31][32][33][34][35][36] could be properly embedded in CV-QKD to fight against channel loss and improve maximum transmission distance [37][38][39][40][41]. In our paper, we consider the use of an NLA inserted before the detection stage in an SR CV-QKD scheme to improve the transmission distance when the reference pulses are weak. Usually, an NLA can amplify the amplitude of input coherent probabilistically while retaining the original level of channel noise [29]. This is very important for the SR CV-QKD because it is very sensitive to the phase noise. When we only take the successful runs of an NLA into account, it can compensate the adverse effects of high phase noise introduced by weak self-referenced pulse and attain a much longer transmission distance. Besides, the impact of the probability that the NLA successfully amplified the quantum signal may be inconspicuous because it is the gain of NLA g that influences the maximum transmission distance primarily rather than the success rate, which is always lower than 1/g 2 [37].
This article is organized as follows. In Section 2, we review the SR CV-QKD scheme, and then we introduce the NLA SR CV-QKD schme. In Section 3, we analyze the secret key rate of our proposed scheme and demonstrate the maximum transmission distance improvement. Finally, we summarize our paper in Section 4. Figure 1a illustrates the steps of the conventional Gaussian CV-QKD scheme. The LO and modulated quantum signals are co-transmitted by adapting techniques like time-division multiplexing (TDM), wavelength-division multiplexing (WDM) and polarization encoding. After receiving the multiplexed signals, Bob uses a demultiplexer to split the LO and quantum signals. As mentioned above, the nature of LO would cause side-channel attacks and it is knotty to multiplex and demultiplex two kinds of signals that differ greatly in amplitude.  The SR CV-QKD scheme [25][26][27] described in Figure 1b has removed the demand of transporting LO successfully. In SR CV-QKD scheme, Alice sends a Gaussian modulated coherent state to Bob just like performed in conventional CV-QKD scheme at first, in the next time bin, she prepares another coherent state as the reference pulse and sends to Bob. The amplitude of the reference pulse, E R , is few times larger than the variance of the quantum signal, V A .

The SR CV-QKD Scheme & Our Proposed Scheme
The reference pulse is used to estimate the deviation angleθ between Alice and Bob's reference frame. Theθ = θ + φ, where θ is the actual deviation angle and φ is the measurement error mainly caused by the quantum uncertainty. We can easily deduce the value ofθ from some simple geometric calculations and find the correlations between the quadratures of sent quantum states and the quadratures of received quantum states.
Since the system performance of SR CV-QKD is positively related to the amplitude of the reference pulses E R , the authors choose arbitrary large E R to attain a longer transmission distances and a higher secret key rate. However, due to the limited dynamic modulation range of the amplitude modulator (AM), the value of E R cannot be too large in practical terms. Besides, the imperfections existing in Alice's AM will introduce an extra excess noise that can be approximated as [28] where E max is the maximal amplitude to be modulated and the d dB represents the dynamic modulation range of the AM. Since the extra excess noise is proportional to the amplitude E max , and d dB has a finite value, this imperfection further limits the amplitude of reference pulses. However, the weaker the reference pulse, the larger the measurement error for θ caused by the quantum uncertainty, and the greater the phase noise variance, ultimately resulting in degrading the performance of SR CV-QKD.
In the case of transporting weak reference pulses (E R /V A = 20, V A = 40), the maximum transmission distance of SR CV-QKD is less than 15 km [25]. Therefore, the range of applications of the original SR CV-QKD scheme may be limited. The NLA has been proven to be a useful tool to extend the maximum transmission distance of Gaussian CV-QKD [37][38][39]. In this paper, an NLA is placed at Bob's end before the coherent detection described in Figure 2 to increase the maximum transmission distance of SR CV-QKD when reference pulses are weak. As usual, we will use the entangle-based (EB) version to describe and analyze our scheme and start with analysing the covariance matrix of the state ρ AB shared between Alice and Bob before any measurement. In a conventional CV-QKD scheme, the covariance matrix γ AB has the following form: where I = ( 1 0 0 1 ) and σ z = ( 1 0 0 −1 ), V(λ) = 1+λ 2 1−λ 2 is the variance of the thermal state Tr A |λ λ| related to the modulation variance and λ is the parameter of squeezed state, the B = 1−T T refer to the noise introduced by the channel loss, the ε is the channel excess noise. When an NLA is inserted into a conventional CV-QKD, only when the NLA works on its successful runs, the exchanged quantum signals will be used for extracting the secret key. Therefore, the scheme of CV-QKD added an NLA is very similar to those CV-QKD schemes with postselection [42]. Since the output of the NLA remains in the Gaussian regime, we can use an equivalent EPR scheme without NLA to analyse the impacts of an NLA on the original scheme. It is shown in Figure 3 that the covariance matrix γ AB (λ, T, ε) is equivalent to the covariance matrix γ e(AB) (ζ, η, ε g , g = 1) (g = 1 indicates no NLA). These equivalent parameters are given by [37] It is clear that the parameters (ζ, η, ε g ) are equal to the parameters (λ, T, ε) respectively when g = 1.
These parameters must meet with the physical meaning limits of 0 ζ < 1, 0 η < 1 and ε g 0, and the maximum value of the gain g max is given by [37] g  Figure 3. The CV-QKD scheme added an NLA with parameters (λ, T, ε, g) is equivalent to the scheme without using an NLA with parameters (ζ, η, ε g , g = 1).
In the SR CV-QKD scheme, the removal of LO will not change the relevant parameters of the channel. Therefore, our proposed scheme can be regarded as an equivalent SR CV-QKD scheme without inserting an NLA, while the equivalent parameters are consistent with the parameters in Equation (3). When we take the phase-space rotations due to the reference frame misalignment into account, the density matrix of the state shared by Alice and Bob in the equivalent SR CV-QKD scheme without using NLA is [25] with where U A(B) represents the phase-space rotation operator, P (φ) is the probability distribution function of random variable φ. While the stateρ e(AB) maintains Gaussian, the covariance matrixγ e(AB) can be expressed as follows [25] with the U A(B) is the symplectic representation of the rotation operator U A(B) . In our scheme, during each time of successful amplification, the NLA can be regarded as an operatorĈ. It can amplify a coherent state from |α toĈ|α = e |α| 2 2 (g 2 −1) |gα probabilistically [37], where g is the gain of NLA. In other words, the NLA can increase the variance of the original quantum signals and improve the channel transmittance. This can offset the adverse effects of the large phase noise incurred by the weak reference pulses and extend the maximum transmission distance of SR CV-QKD. In the next section, we will use numerical simulations to illuminate this improvement in detail.

Performance Analysis
In SR CV-QKD, the modulation process for the quantum signal and reference pulse is time independent. When the AM only modulates the reference pulses, the large E R and the finite dynamic modulation range d dB would introduce a large ε AM . So, we need to set a reasonable and realistic value for reference pulse amplitude to eliminate the effect of ε AM on its measurement result. When the AM only modulates the quantum signals, the extra excess noise ε AM in Equation (1) is independent of E R , but is related to the amplitude of quantum signals. Considering that the intensity E 2 max of modulated quantum signal is just few times larger than V A [43], the value of resulting excess ε AM is tiny (ε AM ∼ 10 −3 for V A = 4, E 2 max = 10V A , and d dB = 40). Compared to the noise introduced by the Gaussian channel (B + ε), the influence of ε AM introduced by the quantum signals on the system performance could be ignored.
The secret key rate of SR CV-QKD scheme under collective attacks with reverse reconciliation is [3,25,44] where I AB is the mutual information between Alice's and Bob's measurements and it can be expressed as where ξ = 1 − (cos φ) 2 . Presuming that the distribution interval of P (φ) is symmetrical and very narrow, namely |φ| ∼ 0, then we get ξ ≈ φ 2 . When the rate of pulse generation is much greater than the fluctuation frequency of phase difference θ, the value of θ can be treated as a specific constant. Therefore, the variance of estimated phase differenceθ is Vθ = V φ = φ 2 . If P(φ) is rapidly monotonically decreasing in the interval [0, |φ| max ], the variance Vθ can be regarded as a tight up bound of ξ, which means ξ Vθ. The expression of Vθ is as follows [25] So, the lower bound of I AB is The χ BE is the Holevo bound denotes for Eve's maximum accessible information, which can be derived from the following formula: where G(x) = (x + 1) log 2 (x + 1) − x log 2 (x) is the Von Neumann entropy of a thermal state. The eigenvalues λ 1 and λ 2 are obtained from where we have used the notations The square of symplectic eigenvalue λ 3 reads We can notice that the χ BE is monotonically increasing with increasing ξ. When we replace the ξ in Equations (15) and (16) with Vθ, the lower bound of K is acquired. As mentioned earlier, our scheme of SR CV-QKD with an NLA has parameters (λ, T, ε, g) and can be treated as one-way SR CV-QKD without NLA having parameters (ζ, η, ε g , g = 1). When our scheme works on the successful runs, the secret information in Equation (9) could be acquired by adopting the equivalent parameters ∆K g SR (λ, T, ε, β) = ∆K SR (ζ, η, ε g , β).
Since the NLA could retain the original level of channel noise, the random variables θ and φ will not be affected, so that we could use the method stated in [25] to handle them. Finally, we can use the covariance matrixγ e(AB) to figure out ∆K SR (ζ, η, ε g , β). Before starting the simulation, we need to take the successful amplification probability P SS of the NLA into account. The actual value of P SS is related to the experimental setups and it is not important to our study because on the one hand we mainly focus on the maximum distance, and on the other hand, it is only a proportional coefficient and cannot transform a negative secret key into a positive one. Besides, The P SS could be treated as constant if the NLA has sufficient dynamics to neglect distortions [37]. Then we can get the secret key rate with NLA by multiplying ∆K SR by the P SS the P SS for an NLA with a gain of g is upper bounded to 1/g 2 , which will be used in the later analysis. As mentioned above, the amplitude of the reference pulses E R is critical to the performance of the SR CV-QKD scheme. The larger the value of E R , the smaller the variance of the measurement error for θ and the higher the secret key rate. Figure 4a shows the relationship between variance Vθ and transmission distance and the secret key rate at different values of E R . In contrast to an ideal value like 500V A , when E R is given a more reasonable value such as 20V A , the value of Vθ is approximately doubled. Figure 4b illustrates the secret key rate and the maximum transmission distance of SR CV-QKD when E R takes ideal and reasonable values, respectively. When the reference pulses are weak (E R /V A = 20), the maximum transmission distance is limited to about 10 km, which is less than half of the transmission distance in the LO scheme . At this point, the SR CV-QKD scheme is only suitable for short-range communications and cannot even be used in urban communication networks.  Another important point in our scheme is the gain of NLA. The value of g max in Equation (4) only depends on the channel parameters (T, ε). In Figure 5a, we display the correlation between the g max and transmission distance, while the excess noise ε is 0.01. The simulations of ∆K NLA with the same channel parameters are shown Figure 5b. In this figure, we set the value of g to 3, which is lower than the g max in Figure 5a. We can see that the NLA with a gain of g can help increase the distance by the equivalent 20 log 10 g dB of losses (100 log 10 g km when the fibre attenuation coefficient α = 0.2 dB/km). However, increasing the value of g will increase the transmission distance intuitively but the secret key rate may become negative. There are two reasons for this, one is the possibility P SS , and the other is the excess noise ε g will increase as well. In Figure 6a, we can see that when the transmission distance is determined, the secret key rate will increase as the gain increases to a certain value. As the gain continues to increase, the secret key rate drops rapidly and eventually becomes negative. In addition, the maximum tolerable excess noise of SR CV-QKD against transmission distance with different gain g is shown in Figure 6b. It has clearly demonstrated that our scheme can tolerate a much higher excess noise while the secret key rate remains positive. We should note that the simulation results displayed above may not correspond to the results of the practical experiment, because the possibility of P SS being a tunable parameter depends on the facilities configuration. However, they have clearly illustrated the effects of an NLA on the maximum transmission distance and secret key rate.

Conclusions
In SR CV-QKD, when the reference pulses are weak, the large phase noise shows a conspicuous adverse effect on its performance, which means a shorter transmission distance and a lower key rate. We show that an NLA can help to improve the performance of SR CV-QKD with weak reference pulses. The NLA can compensate the impacts of extra phase noise by enhancing the original quantum signals and increasing the channel transmittance. Our proposed scheme demonstrates that the NLA can help increase the distance by the equivalent 20 log 10 g dB of losses (g = 3 for 47 km) and the secret key rate is still acceptable. However, it should be mentioned here that we have only conducted theoretical analysis; the gap between practical implementations and theoretical models should also be considered. Any imperfection that exists in the actual experiment would introduce more complex parameters. This issue is not within the scope of our current consideration, and deserves further investigation.