Reuse & Permissions

It is not necessary to obtain permission to reuse this article or its components as it is available under the terms of the Creative Commons Attribution 4.0 International license. This license permits unrestricted use, distribution, and reproduction in any medium, provided attribution to the author(s) and the published article's title, journal citation, and DOI are maintained. Please note that some figures may have been included with permission from other third parties. It is your responsibility to obtain the proper permission from the rights holder directly for these figures.

Export citation

Export citation

Choose format for download:

Download Citation
  • Open Access

Incorporating Device Characterization into Security Proofs

Ernest Y.-Z. Tan and Shlok Nahar*

  • Institute for Quantum Computing and Department of Physics and Astronomy, University of Waterloo, Waterloo, Ontario N2L 3G1, Canada

  • *Contact author: sanahar@uwaterloo.ca

PRX Quantum 7, 020342 – Published 29 May, 2026

DOI: https://doi.org/10.1103/f42p-524t

Abstract

Typical security proofs for quantum key distribution (QKD) rely on having some model for the devices, with the security guarantees implicitly relying on the values of various parameters of the model, such as dark count rates or detector efficiencies. Hence to deploy QKD in practice, we must establish how to certify or characterize the model parameters of a manufacturer’s QKD devices. We present a rigorous framework for analyzing such procedures, laying out concrete requirements for both the security proofs and the certification or characterization procedures. In doing so, we describe various forms of conclusions that can and cannot be validly drawn from such procedures, addressing some potential misconceptions. We also discuss connections to composable security frameworks and some technical aspects that remain to be resolved in that direction.

View figure in article

Physics Subject Headings (PhySH)

Popular Summary

Article Text

References (39)

  1. S. Nahar, T. Upadhyaya, and N. Lütkenhaus, Imperfect phase randomization and generalized decoy-state quantum key distribution, Phys. Rev. Appl. 20, 064031 (2023).
  2. We choose to use the terms “approve”/“reject” in order to avoid confusion with the “accept”/“abort” decisions in QKD protocols themselves.
  3. R. Renner, Security of Quantum Key Distribution (ETH Zürich, 2005).
  4. D. Tupkary, E. Y. Z. Tan, S. Nahar, L. Kamin, and N. Lütkenhaus, QKD security proofs for decoy-state BB84: Protocol variations, proof techniques, gaps and limitations, arXiv:2502.10340 [quant-ph].
  5. M. A. Nielsen and I. L. Chuang, Quantum Computation and Quantum Information. 10th Anniversary Edition (Cambridge University, New York, 2010).
  6. M. Ben-Or, M. Horodecki, D. W. Leung, D. Mayers, and J. Oppenheim, Theory of Cryptography (Springer, Berlin, Heidelberg, 2005), pp. 386–406.
  7. M. Hayashi and T. Tsurumaru, Concise and tight security analysis of the Bennett–Brassard 1984 protocol with finite key lengths, New J. Phys. 14, 093014 (2012).
  8. C. Portmann and R. Renner, Security in quantum cryptography, Rev. Mod. Phys. 94, 025008 (2022).
  9. G. Chiribella, G. M. D’Ariano, and P. Perinotti, Theoretical framework for quantum networks, Phys. Rev. A 80, 022339 (2009).
  10. C. Portmann, C. Matt, U. Maurer, R. Renner, and B. Tackmann, Causal boxes: Quantum information-processing systems closed under composition, IEEE Trans. Inf. Theory 63, 3277 (2017).
  11. More generally, one might want to consider the possibility of some form of “mid-lifespan” certification of the QKD device. However, we leave a detailed analysis of this to be addressed in future work—for this work, we shall simply take the perspective that this could potentially be viewed as a “fresh” certification of the device for another number of QKD protocol instances.
  12. An alternative formalism could be to specify one attack Aj for each instance, but that can simply be considered a special case of the formalism we describe here, for instance by setting A=(A1,A2,…).
  13. C. Portmann, Key recycling in authentication, IEEE Trans. Inf. Theory 60, 4383 (2014).
  14. J. Barrett, R. Colbeck, and A. Kent, Memory attacks on device-independent quantum cryptography, Phys. Rev. Lett. 110, 010503 (2013).
  15. M. Curty and H.-K. Lo, Foiling covert channels and malicious classical post-processing units in quantum key distribution, npj Quantum Inf. 5, 1 (2019).
  16. F. G. Lacerda, J. M. Renes, and R. Renner, Classical leakage resilience from fault-tolerant quantum computation, J. Cryptol. 32, 1071 (2019).
  17. M. McKague and L. Sheridan, Information Theoretic Security, edited by C. Padró, Lecture Notes in Computer Science (Springer International Publishing, Cham, 2014), pp. 122–141.
  18. In this example we choose to specify the parameter to be an upper bound on the dark count rate rather than “the” dark count rate, since the latter may not be a well-defined single number if the detector behavior is not IID.
  19. In fact, from the proof it can be seen that the upper bound in Eq. (7) can be sharpened to ϵntotal=max{ϵcert,∑j=1nϵQKD}.
  20. U. Maurer and R. Renner, The Second Symposium on Innovations in Computer Science, ICS 2011 (Tsinghua University, 2011), pp. 1–21.
  21. A. Lenart, T. Islam, S. Sivasankaran, P. Neilson, B. Hidding, D. K. L. Oi, and A. Ling, Comparing a radiation damage model for avalanche photodiodes through in-situ observation of cubesat based devices, Commun. Phys. 8, 118 (2025).
  22. A. Vakhitov, V. Makarov, and D. R. Hjelme, Large pulse attack as a method of conventional optical eavesdropping in quantum cryptography, J. Mod. Opt. 48, 2023 (2001).
  23. M. Lucamarini, I. Choi, M. B. Ward, J. F. Dynes, Z. L. Yuan, and A. J. Shields, Practical security bounds against the Trojan-horse attack in quantum key distribution, Phys. Rev. X 5, 031030 (2015).
  24. A. Arqand, T. Metger, and E. Y. Z. Tan, Mutual information chain rules for security proofs robust against device imperfections, arXiv:2407.20396 [quant-ph].
  25. G. Currás-Lorenzo, S. Nahar, N. Lütkenhaus, K. Tamaki, and M. Curty, Security of quantum key distribution with imperfect phase randomisation, Quantum Sci. Technol. 9, 015025 (2024).
  26. G. Currás-Lorenzo, M. Pereira, G. Kato, M. Curty, and K. Tamaki, Security of high-speed quantum key distribution with imperfect sources, Quantum 3, 525 (2025).
  27. L. Kamin, J. Burniston, and E. Y. Z. Tan, Rényi security framework against coherent attacks applied to decoy-state QKD, arXiv:2504.12248 [quant-ph].
  28. A. Marwah and F. Dupuis, Proving security of BB84 under source correlations, arXiv:2402.12346 [quant-ph].
  29. S. Nahar, D. Tupkary, and N. Lütkenhaus, Imperfect detectors for adversarial tasks with applications to quantum key distribution, Quantum 10, 2044 (2026).
  30. X. Sixto, Á. Navarrete, M. Pereira, G. Currás-Lorenzo, K. Tamaki, and M. Curty, Quantum key distribution with imperfectly isolated devices, Quantum Sci. Technol. 10, 035034 (2025).
  31. D. Tupkary, S. Nahar, P. Sinha, and N. Lütkenhaus, Phase error rate estimation in QKD with imperfect detectors, Quantum 9, 1937 (2025).
  32. V. Zapatero, Á. Navarrete, K. Tamaki, and M. Curty, Security of quantum key distribution with intensity correlations, Quantum 5, 602 (2021).
  33. S. Nahar, A proof-technique-independent framework for detector imperfections in QKD, Ph.D. thesis, University of Waterloo, 2026.
  34. ETSI, Quantum Key Distribution (QKD); Component characterization: characterizing optical components for QKD systems (2016).
  35. W. Hoeffding, Probability inequalities for sums of bounded random variables, J. Am. Stat. Assoc. 58, 13 (1963).
  36. To see this: note that this event is equivalent to all fj+δ values lying below the true maximum dark count rate. Now focusing on the detector with the highest true dark count rate, this implies, in particular, that the fj+δ value for that detector lies below its true dark count rate, and thus this event has probability at most ϵcert.
  37. For the purposes of this work, we shall suppose that Λ can only take values in a countable set, to avoid technical issues with uncountably infinite sets. This should not be a significant restriction in practice, since real-life characterization procedures can typically only output values belonging to some countable set (for instance, finite-precision numbers of some form), even when estimating real-valued parameters.
  38. D. Tupkary, E. Y.-Z. Tan, and N. Lütkenhaus, Security proof for variable-length quantum key distribution, Phys. Rev. Res. 6, 023002 (2024).
  39. Strictly speaking, if the certification procedure involves interacting with these devices in some more general fashion, then these resources also need to be further generalized in order to allow such operations, but the overall conclusion remains.

Outline

Information

Sign In to Your Journals Account

Filter

Filter

Article Lookup

Enter a citation