- Open Access
Sharp Finite Statistics for Quantum Key Distribution
Phys. Rev. Lett. 135, 020803 – Published 10 July, 2025
DOI: https://doi.org/10.1103/l735-x48g
Abstract
The performance of quantum key distribution (QKD) heavily depends on statistical inference. For a broad class of protocols, the central statistical task is a random sampling problem, customarily addressed using a hypergeometric tail bound due to Serfling. Here, we provide an alternative solution for this task of unprecedented tightness among QKD security analyses. As a by-product, confidence intervals for the average of nonidentical Bernoulli parameters follow too. These naturally fit in statistical analyses of decoy-state QKD and also outperform standard tools. Last, we show that, in a vast parameter regime, the use of tail bounds is not enforced because the cumulative mass function of the hypergeometric distribution is accurately computable. This sharply decreases the minimum block sizes necessary for QKD, and reveals the tightness of our analytical bounds when moderate-to-large blocks are considered.
Physics Subject Headings (PhySH)
Article Text
Supplemental Material
References (69)
- C. Portmann and R. Renner, Security in quantum cryptography, Rev. Mod. Phys. 94, 025008 (2022).
- F. Xu, X. Ma, Q. Zhang, H.-K. Lo, and J.-W. Pan, Secure quantum key distribution with realistic devices, Rev. Mod. Phys. 92, 025002 (2020).
- H.-K. Lo, M. Curty, and K. Tamaki, Secure quantum key distribution, Nat. Photonics 8, 595 (2014).
- C. H. Bennett and G. Brassard, Quantum cryptography: Public key distribution and coin tossing, in Proceedings of the 1984 IEEE International Conference on Computers, Systems & Signal Processing, Bangalore, India (IEEE, New York, 1984), pp. 175–179.
- M. Tomamichel and R. Renner, Uncertainty relation for smooth entropies, Phys. Rev. Lett. 106, 110506 (2011).
- P. J. Coles, M. Berta, M. Tomamichel, and S. Wehner, Entropic uncertainty relations and their applications, Rev. Mod. Phys. 89, 015002 (2017).
- C. H. Bennett, G. Brassard, and M. D. Mermin, Quantum cryptography without Bell’s theorem, Phys. Rev. Lett. 68, 557 (1992).
- M. Tomamichel and A. Leverrier, A largely self-contained and complete security proof for quantum key distribution, Quantum 1, 14 (2017).
- See Supplemental Material at http://link.aps.org/supplemental/10.1103/l735-x48g for a collection of appendices of this Letter, which includes Refs. [10–26].
- M. Tomamichel et al., Leftover hashing against quantum side information, IEEE Trans. Inf. Theory 57, 5524 (2011).
- V. Zapatero and M. Curty, Finite-key security of passive quantum key distribution, Phys. Rev. Appl. 21, 014018 (2024).
- A. Vitanov et al., Chain rules for smooth min-and max-entropies, IEEE Trans. Inf. Theory 59, 2603 (2013).
- C. Bonferroni, Teoria statistica delle classi e calcolo delle probabilita, Pubbl. Ist. Super. Sci. Economiche Commericiali Firenze 8, 3 (1936).
- V. Zapatero and M. Curty, Secure quantum key distribution with a subset of malicious devices, npj Quantum Inf. 7, 26 (2021).
- J. Neyman, On the problem of confidence intervals, Ann. Math. Stat. 6, 111 (1936).
- J. Neyman, Outline of a theory of statistical estimation based on the classical theory of probability, Phil. Trans. R. Soc. A 236, 333 (1937).
- J. D. Bancal, K. Redeker, P. Sekatski, W. Rosenfeld, and N. Sangouard, Self-testing with finite statistics enabling the certification of a quantum network link, Quantum 5, 401 (2021).
- S. Holmes, Stein’s method for birth and death chains, in Stein’s Method: Expository Lectures and Applications, Institute of Mathematical Statistics Lecture Notes—Monograph Series (Institute of Mathematical Statistics, Beachwood, Ohio, USA, 2004), Vol. 46, pp. 45–67, 10.1214/lnms/1196283792.
- E. Greene, Finite sampling exponential bounds, Doctoral dissertation, University of Washington, 2016.
- G. Bennett, Probability inequalities for the sum of independent random variables, J. Am. Stat. Assoc. 57, 33 (1962).
- R. Bardenet and O. A. Maillard, Concentration inequalities for sampling without replacement, Bernoulli 21, 1361 (2015).
- L. Goldstein and Ü. Işlak, Concentration inequalities via zero bias couplings, Stat. Probab. Lett. 86, 17 (2014).
- S. Chatterjee, Stein’s method for concentration inequalities, Probab. Theory Relat. Fields 138, 305 (2007).
- https://ahlenotes.wordpress.com/2015/12/08/hypergeometric_tail/.
- S. Hui and C. J. Park, The representation of hypergeometric random variables using independent Bernoulli random variables, Commun. Stat. 43, 4103 (2014).
- J. Pitman, Probabilistic bounds on the coefficients of polynomials with only real zeros, J. Comb. Theory Ser. A 77, 279 (1997).
- W. Y. Hwang, Quantum key distribution with high loss: Toward global secure communication, Phys. Rev. Lett. 91, 057901 (2003).
- H.-K. Lo, X. Ma, and K. Chen, Decoy state quantum key distribution, Phys. Rev. Lett. 94, 230504 (2005).
- X.-B. Wang, Beating the photon-number-splitting attack in practical quantum cryptography, Phys. Rev. Lett. 94, 230503 (2005).
- C. C. W. Lim, M. Curty, N. Walenta, F. Xu, and H. Zbinden, Concise security bounds for practical decoy-state quantum key distribution, Phys. Rev. A 89, 022307 (2014).
- M. Tomamichel, C. C. W. Lim, N. Gisin, and R. Renner, Tight finite-key analysis for quantum cryptography, Nat. Commun. 3, 1 (2012).
- R. J. Serfling, Probability inequalities for the sum in sampling without replacement, Ann. Stat. 2, 39 (1974).
- C. C.-W. Lim, F. Xu, J.-W. Pan, and A. Ekert, Security analysis of quantum key distribution with small block length and its application to quantum space communications, Phys. Rev. Lett. 126, 100501 (2021).
- D. Hush and C. Scovel, Concentration of the hypergeometric distribution, Stat. Probab. Lett. 75, 127 (2005).
- W. Hoeffding, Probability inequalities for sums of bounded random variables, J. Am. Stat. Assoc. 58, 13 (1963).
- Z. Zhang, Q. Zhao, M. Razavi, and X. Ma, Improved key-rate bounds for practical decoy-state quantum-key-distribution systems, Phys. Rev. A 95, 012333 (2017).
- J. P. Buonaccorsi, A note on confidence intervals for proportions in finite populations, Am. Stat. 41, 215 (1987).
- T. Wright, Exact Confidence Bounds when Sampling from Small Finite Universes: An Easy Reference Based on the Hypergeometric Distribution (Springer Science & Business Media, New York, NY, 2012), Vol. 66, 10.1007/978-1-4612-3140-0.
- W. Wang, Exact optimal confidence intervals for hypergeometric parameters, J. Am. Stat. Assoc. 110, 1491 (2015).
- C. J. Clopper and E. S. Pearson, The use of confidence or fiducial limits illustrated in the case of the binomial, Biometrika 26, 404 (1934).
In a QKD security proof, any confidence interval must guarantee that its coverage is above its nominal value, a property known as exactness in the literature of statistical inference. As shown in [39], in the hypergeometric setting, the exact one-sided intervals that arise from the Clopper-Pearson method are length minimizing and thus optimal. Conversely, any tighter one-sided interval is necessarily not exact and thus unsuitable for QKD.
- H. Chernoff, A measure of asymptotic efficiency for tests of a hypothesis based on the sum of observations, Ann. Math. Stat. 23, 493 (1952).
- V. Chvátal, The tail of the hypergeometric distribution, Discrete Math. 25, 285 (1979).
- M. Hayashi and T. Tsurumaru, Concise and tight security analysis of the Bennett–Brassard 1984 protocol with finite key lengths, New J. Phys. 14, 093014 (2012).
- M. Hayashi and R. Nakayama, Security analysis of the decoy method with the Bennett–Brassard 1984 protocol for finite key lengths, New J. Phys. 16, 063009 (2014).
- F. Topsøe, Some bounds for the logarithmic function, in Inequality Theory and Applications (Nova Publishers, New York, 2007), Vol. 4, p. 137, ISBN: [Amazon][WorldCat].
In this Letter, we contemplate the equality sign following the criterion of [8]. With this criterion, “0” and “1” do not provide trivial confidence bounds on the population parameter, forcing us to take the looser values given in Eqs. (2) and (3).
For instance, it is straightforward to show that setting suffices to assure that for all . This condition on is unrestrictive for all practical purposes.
The statistic we introduce here does not exactly match—but is trivially determined by—the one presented in [37, 38]. Precisely, they are related by a “one-unit shift.” The discrepancy arises because we contemplate the equality sign in the bounds, requesting rather than .
One can speedup the computation of by exploring the complementary set of potential ’s (namely, ), by carefully selecting the starting for the iterations (e.g., based on existing analytical bounds), or by applying a binary search or an interpolation algorithm.
Precisely, computing the CMF to a precision beyond the th digit suffices.
- J. D. Bancal and P. Sekatski, Simple Buehler-optimal confidence intervals on the average success probability of independent Bernoulli trials, arXiv:2212.12558.
- L. Mattner and C. Tasto, Confidence intervals for average success probabilities, arXiv:1403.0229.
- M. Lucamarini et al., Efficient decoy-state quantum key distribution with quantified security, Opt. Express 21, 24550 (2013).
- M. Lucamarini, J. F. Dynes, B. Fröhlich, Z. Yuan, and A. J. Shields, Security bounds for efficient decoy-state quantum key distribution, IEEE J. Sel. Top. Quantum Electron. 21, 197 (2015).
- J. Yin et al., Entanglement-based secure quantum cryptography over 1,120 kilometres, Nature (London) 582, 501 (2020).
- M. Curty, F. Xu, W. Cui, C. C. W. Lim, K. Tamaki, and H.-K. Lo, Finite-key analysis for measurement-device-independent quantum key distribution, Nat. Commun. 5, 3732 (2014).
A novelty of our protocol with respect to [30] is that, in the PE step, the parties evaluate suitable decoy-state bounds for the single-photon security parameters (e.g., the number of single-photon counts and their phase-error rate). If these bounds do not fulfill predetermined acceptance thresholds, the protocol aborts. Otherwise, a fixed-length output key matching the acceptance thresholds is extracted. Furthermore, a finer-grained PE test is devised when considering the tool of [33], in order to adapt this tool to the decoy-state setting [9].
- N. Walenta et al., Sine gating detector with simple filtering for low-noise infra-red single photon detection at room temperature, J. Appl. Phys. 112, 063106 (2012).
Note that we use different variables for the correctable QBER in the BBM92 and the BB84 protocols, respectively given by and . For consistency, is set to the expected QBER of the considered channel model.
The total number of error terms contributing to varies depending on the random sampling tool under consideration [9].
- J. S. Sidhu, T. Brougham, D. McArthur, R. G. Pousa, and D. K. Oi, Finite key effects in satellite quantum key distribution, npj Quantum Inf. 8, 18 (2022).
- T. Roger et al., Real-time gigahertz free-space quantum key distribution within an emulated satellite overpass, Sci. Adv. 9, eadj5873 (2023).
- R. Bedington, J. M. Arrazola, and A. Ling, Progress in satellite quantum key distribution, npj Quantum Inf. 3, 30 (2017).
- J.-Y. Liu, X. Ma, H.-J. Ding, C.-H. Zhang, X.-Y. Zhou, and Q. Wang, Experimental demonstration of five-intensity measurement-device-independent quantum key distribution over 442 km, Phys. Rev. A 108, 022605 (2023).
- G. Currás-Lorenzo, A. Navarrete, K. Azuma, G. Kato, M. Curty, and M. Razavi, Tight finite-key security for twin-field quantum key distribution, npj Quantum Inf. 7, 22 (2021).
- Y. Liu, W.-J. Zhang, C. Jiang, J.-P. Chen, C. Zhang, W.-X. Pan, D. Ma, H. Dong, J.-M. Xiong, C.-J. Zhang et al., Experimental twin-field quantum key distribution over 1000 km fiber distance, Phys. Rev. Lett. 130, 210801 (2023).
- S. Bernstein, On a modification of Chebyshev’s inequality and of the error formula of Laplace, Ann. Sci. Inst. Sav. Ukraine Sect. Math 1, 38 (1924).
- E. Greene and J. A. Wellner, Exponential bounds for the hypergeometric distribution, Bernoulli 23, 1911 (2017).