Relativistic position verification with coherent states
MIT gains a proof-of-concept for scalable quantum security, while DOE and NSF validate public investment in foundational quantum tech. The tie-up accelerates trustworthy digital identity frameworks, bridging theory and real-world deployment.

Understand this faster with AI
MainSince the Internet became ubiquitous, activities such as remote transactions, online communication and digital governance have reshaped how societies function. However, as global connectivity has accelerated, the ability to trust where information originates has not kept pace. In a world where identities, assets and autonomous agents interact remotely, the absence of verifiable position leaves a critical gap in digital trust. Establishing whether an entity is physically present at a claimed position has therefore become a crucial security credential for identity authentication1,2,3.Despite its importance, securely verifying position is fundamentally challenging. A typical position verification protocol4 uses multiple verifiers that send coordinated challenge messages to a prover, who must derive a credential from all received messages and return it. Because the round-trip time is constrained by the relativistic light-speed limit, the verifiers can determine the prover’s position by checking both the credential and its arrival time5. However, classical position verification has been proven insecure in the untrusted-prover setting without additional assumptions such as preshared secret keys1,6, because classical information can be copied and relayed without detection, allowing a dishonest prover to deploy collaborating adversaries that intercept and forward the messages, generate the correct credential without added delay and thereby deceive the verifiers about its position.Guarding against dishonest provers cannot rely solely on relativistic spacetime relations. Encoding classical information into qubits makes interception and resending detectable, forming the basis of quantum-secure communication7. Integrating qubits into position verification therefore offers a physically grounded way to overcome the classical impossibility of secure positioning8,9,10,11,12,13,14. Adopting this approach by constructing challenge messages consisting of n classical bits and a single qubit, recent protocols8,9, under unitary attack models, show that a successful attack requires auxiliary quantum resources whose size scales as O(n). The work in ref. 15 shows, under the assumption of perfect security, a linear lower bound on entanglement. As well, all known attack constructions16,17,18,19 require entanglement that grows with the classical input size. Both lines of work suggest entanglement must grow with classical input size to attack these schemes. Subsequent work20 further shows that quantum gates can also serve as a resource that limits the adversary’s capability, proving that a successful attack requires quantum gate resources that scale linearly with the classical input size. As increasing the size of the classical input is substantially simpler than scaling up quantum resources, this design satisfies the fundamental asymmetry principle of cryptography, which demands that passing the verifiers’ checks be easy for an honest prover but hard for any adversary attempting impersonation.Although conceptually appealing, qubit-based position verification protocols are extremely challenging to realize due to stringent requirements on latency, computational capability and loss. First, relativistic constraints make the verification process extraordinarily sensitive to delay. Typical millisecond-scale excess latency in modern communication translates into position errors of hundreds of kilometres at the speed of light, which eliminates the practical viability of the protocol. In addition, within the information-theoretic framework, refs. 8,9 require the prover to uniformly select one credential-computing function from a function set of size \({2}^{{2}^{n}}\) for each verification task, where larger n corresponds to stronger security. This scale imposes prohibitive computational demands and leads to substantial computation latency associated with evaluating such complex Boolean functions. Finally, the protocol utilizing quantum optics requires single-photon sources, high repetition rates and a total loss not exceeding 3 dB including modulation, transmission and detection. Each one poses substantial practical difficulty, and satisfying them simultaneously is even more demanding. In this context, both experimental and theoretical efforts have been pursued4, including the experimental investigation of quantum-dot single-photon sources21 and the theoretical exploration of coherent-state sources—such as continuous-variable encoding22 and decoy-state techniques23—and the effective reduction of computational requirements20. More recently, both this work and ref. 24 present more complete experimental demonstrations of quantum position verification (QPV).We realize a complete QPV by experimentally combining quantum optics with relativity within an information-theoretic framework. The implementation builds upon and extends the f-BB84 scheme proposed in ref. 8 and the partially loss-tolerant protocol with two bases introduced in ref. 9. By implementing high repetition rate, low-loss quantum communication together with large-scale, low-latency classical communication, we achieve a building-scale verification precision better than 75 m over a distance of 2 km, comparable to typical secure-zone dimensions. This work fills the gap in experimental studies of QPV implementations, featuring a practical scheme and achieving performance metrics of practical relevance. On the quantum side, we improve loss tolerance by proposing a coherent-state approach and suppress errors by designing a Sagnac encoding scheme based on a micro-assembled component, whereas a high-speed basis-selection optical switch driven by high-voltage electronics is used to increase the system repetition rate. On the classical side, we implement random Boolean functions with large input sizes and low latency using dense-wavelength-division-multiplexed on–off keying (DWDM-OOK) encoding with PIN detection and hardware-based lookup tables, and further reduce channel latency by using hollow-core fibre.Specifically, we establish a security framework based on phase-randomized weak coherent states (PR-WCS), which resolves the multiphoton security issue and eliminates the need for single-photon sources. Immediate advantages are that coherent-state sources are readily available, insensitive to modulation loss and naturally compatible with high repetition rates. This enables a high-speed, low-loss polarization-encoding scheme, implemented using a Sagnac architecture constructed from a micro-assembled rotated circulating splitter (RCS) to achieve high-fidelity polarization-state preparation. On the detection side, we develop a high-frequency, high-voltage-driven optical switch combined with superconducting detectors to realize low-loss polarization analysis. The overall quantum-optical efficiency reaches 70%, while maintaining an error rate of 0.27%.To address the latency associated with n-bit classical messages, we further develop dedicated classical links based on DWDM-OOK signal generation, anti-resonant hollow-core fibre (AR-HCF) transmission and high-speed PIN photodiode detection. This minimal parallel transmission-detection design, together with the high-bandwidth, near-light-speed channel, enables scalable n with negligible excess latency. Finally, we implement large-n high-speed credential computation using a hardware lookup table built on a field-programmable gate array (FPGA) and double data rate (DDR) memory array, enabling fast mapping with a computation latency below 118 ns over a function space exceeding 10330985980541, corresponding to n = 40, with each function supporting 240 possible inputs.ProtocolThe mechanism of QPV is that the prover performs the required operations based on the information provided by the verifiers and returns the outcome for verification. When the prover behaves honestly, the round-trip time of the information exchange can be used to bound the prover’s position. Accordingly, a quantum position verification protocol can be organized into three components: (1) message preparation, (2) credential generation and (3) position inference. In the message-preparation component, the verifiers create and send challenge messages composed of classical bits and a qubit to the prover. Credential generation then takes place at the prover, who applies the agreed rule to produce the credential and returns it immediately. Finally, after repeating these steps for N rounds, the verifiers perform position inference based on the correctness of the N credentials, while the largest excess latency relative to the light-speed limit across the rounds determines the uncertainty of the inferred position.Figure 1a illustrates the structure of the protocol, consisting of two verifiers, V1 and V2, and a prover P, together with the flows of classical and quantum information, shown in orange and blue arrows, respectively. The verifiers jointly send n classical bits to the prover, each contributing n/2 bits, denoted as {0, 1}n/2. In addition, V1 sends a coherent state \(\left\vert {\alpha }_{b,c}\right\rangle\) to the prover, and b, c ∈ {0, 1} jointly determine the polarization of the state. The bit b specifies one of the two eigenbases, and c specifies one of the two eigenvalues. The value of b is determined through a Boolean function f: {0, 1}n → b, which is also the operation carried out by the prover, as indicated by f in Fig. 1a. The operation \({\mathscr{ \mathcal M }}\) at the prover represents a projective measurement on the received quantum state in the inferred eigenbasis, yielding the outcome c. This value c serves as the credential returned to the verifiers for verification.Fig. 1: QPV protocol using coherent states.Full size imageThe position of the prover, P, is verified by two spatially separated verifiers, V1 and V2. a, Information flow in a single round of position verification. V1 and V2 each send n/2 classical bits to P. Simultaneously, V1 sends a coherent state \(\left\vert {\alpha }_{b,c}\right\rangle\) with mean photon number ∣α∣2, whose polarization is determined by eigenbasis b and eigenvalue c. P evaluates the Boolean function f: {0, 1}n → b to obtain b, measures (\({\mathcal{M}}\)) the polarization of the quantum state accordingly and returns the result \({c}^{{\prime} }\) as a credential to the verifiers for verification. b, Light-cone interpretation of position precision. Without any delay, P is precisely located at the intersection of the light cones from V1 and V2. An excess delay Δt allows all events within a range Δr to satisfy the verification condition, so the position of P is constrained within Δr.Before the protocol begins, the verifiers agree on the total number of rounds N, the classical string {0, 1}n and the bits b and c for each round, and they also agree with the prover on a Boolean function. This Boolean function is selected uniformly at random from the set of all possible mappings, of which there are \({2}^{{2}^{n}}\) for input length n.Message preparationFor the classical part of the message, the verifiers each send the agreed-upon {0, 1}n/2 string for the current round and record the time at which their respective classical message enters the channel, denoted as t1 and t2. For the quantum part, V1 prepares a weak coherent state \(\left\vert \alpha \right\rangle\) and modulates its polarization according to b and c, after which the state is sent to the prover.Credential generationUpon receiving the two {0, 1}n/2 strings from the verifiers, the prover combines them into an n-bit input and applies the Boolean function to obtain b. The prover then measures the quantum state sent by V1 in the basis specified by b, yielding an outcome \({c}^{{\prime} }\). This value \({c}^{{\prime} }\) is subsequently returned to the verifiers. Note that V1 can adjust the transmission time of the quantum state so that it arrives exactly when the prover performs the measurement, thereby avoiding any need for quantum memory. Due to imperfections in state preparation and measurement, \({c}^{{\prime} }\) may differ from c. Moreover, because of optical loss and finite detection efficiency, the prover may occasionally obtain no measurement outcome, denoted as ⊥, so that \({c}^{{\prime} }\in \{0,1,\perp \}\).Position inferenceThe verifiers receive the value \({c}^{{\prime} }\) and record its arrival times as \({c}^{{\prime} }\) and \({t}_{2}^{{\prime} }\), respectively. If \({c}^{{\prime} }=c\), the event is classified as a correct event. If \({c}^{{\prime} }=c\), the event is counted as an incorrect and discard event. If the prover obtains no measurement outcome, the event is recorded as a no-response event. After N rounds, the number of correct events is denoted as nc, the number of incorrect and discard events as nI, and the number of no-response events as n⊥. The verification decision is made by setting a scoring scheme and threshold such that an honest P can exceed the threshold, whereas a dishonest P cannot. The score is calculated as Γ = γCnc − γ⊥n⊥ − γInI, where the coefficients for each term are obtained by semidefinite programming9,25. Let Γ0 be the threshold. With an appropriate choice of Γ0, the probability that a dishonest prover’s score exceeds this threshold can be exponentially small, while an honest prover’s score can almost certainly surpass it. Therefore, if Γ ≥ Γ0, P is considered to have passed the verification, and its possible position region is given by the intersection of the two areas centred at the two verifiers, with radii \(({t}_{1}^{{\prime} }-{t}_{1}){c}_{0}/2\) and \(({t}_{2}^{{\prime} }-{t}_{2}){c}_{0}/2\), respectively, where c0 denotes the speed of light in vacuum.Figure 1b illustrates the relationship between latency and the admissible position range using a light-cone representation. Suppose the verifiers observe a round-trip time of 2δT for receiving the credential, that is, a one-way time of \(\delta T=({t}_{1}^{{\prime} }-{t}_{1})/2=({t}_{2}^{{\prime} }-{t}_{2})/2\). Under the light-speed limit, each verifier’s admissible region corresponds to the blue and orange areas within its respective light cone, and the intersection of these regions specifies where the prover could be located. If no additional latency δt is present, the two regions become tangent, allowing the prover to be localized to a single point. Once extra latency arises, the prover’s position is instead constrained within a range of size δr = c0δt.Compared with previous protocols8,9, the key distinction of our protocol is the use of coherent states instead of single photons. Coherent states can be readily generated by laser sources and do not degrade under attenuation, making them particularly suitable for the realization of QPV. However, their multiphoton components allow undetectable polarization-state cloning via beamsplitting attacks and thus introduce security concerns, whereas the vacuum component carries no information and reduces the verification efficiency.To address these issues, we construct a coherent-state version of Γ0 based on analysing different photon-number components separately and determining an upper bound on Γ0 under adversarially optimal conditions. Specifically, we use phase-randomized coherent states. A coherent state \(\left\vert \alpha \right\rangle\), after phase randomization, can be described as a mixture of Fock states: \(\rho =\int_{0}^{2\uppi }\frac{{d}{\phi}}{2\uppi }\,\left\vert \alpha {\rm{e}}^{i\phi }\right\rangle \left\langle \alpha {\rm{e}}^{i\phi }\right\vert =\mathop{\sum }\nolimits_{n = 0}^{\infty }\frac{{\mu }^{n}{\rm{e}}^{-\mu }}{n!}\,\left\vert n\right\rangle \left\langle n\right\vert\), where n denotes the photon number and μ = ∣α∣2 is the mean photon number of the coherent state. Under this representation, PR-WCS emit a Fock state in each round, with the photon number following a Poisson distribution P(∣α∣2). V1 then encodes information in the polarization degree of freedom.For single-photon states, we adopt the approach used in previous protocols. For vacuum states, an adversary may declare a no-response event or may produce a correct event with probability one half. By enumerating all possibilities, we derive the vacuum-state contribution to the upper bound of Γ0. For multiphoton states, we assume the worst case in which the adversary can always mount a perfect attack, yielding only correct events. Combining all photon-number contributions yields the desired upper bound on Γ0.Moreover, although the probabilities of the three photon-number cases are known, finite rounds introduce statistical fluctuations. Using the Chernoff bound, we obtain a rigorous finite-size upper bound on Γ0. By inversely optimizing the mean photon number that maximizes the honest prover’s score, we further enhance the robustness of the verification. The analysis of the Γ0 upper bound, together with the treatment of statistical fluctuations and coherent-state parameter optimization, is presented in detail in the ‘Secure score with coherent states’ section in Methods.The protocol not only resolves the key practical bottlenecks in availability and operability but also establishes finite-size secure bounds and introduces a parameter-optimization method that enhance the robustness. These contributions elevate QPV from a theoretically defined concept to a practically realizable level and lay the foundation for subsequent experimental implementations.ImplementationThe experimental system follows the protocol architecture shown in Fig. 2, with the quantum-state modulation setup detailed in Fig. 3. V1 consists of three parts, a classical bits preparation unit and a quantum state preparation unit (QPU) for message preparation and a credential receive unit for position inference. V2 has the same structure as V1 except it does not include a QPU. P contains a Boolean function unit and a quantum state measurement unit (QMU) for credential generation. In the implementation, the loss and error rate of quantum state transmission and measurement determine whether the protocol can be successfully executed, and the excess latency from classical bits transmission and prover operations affects the precision of position verification. The use of coherent states eliminates the impact of quantum state preparation loss.Fig. 2: Experimental setup for QPV.Full size imageFrom left to right are V1, P and V2, spaced approximately 0.98 km apart in sequence. The classical bits preparation unit (CPU) and QPU of the verifiers implement the message preparation step of the protocol, whereas the credential receive unit (CRU) implements the position inference step. The prover’s Boolean function unit (BFU) and QMU implement the credential generation step. The quantum states are prepared in the \(\left\vert H\right\rangle +{\rm{e}}^{i\phi }\left\vert V\right\rangle\) polarizations using a Sagnac interferometer including a phase modulator (PM) and a micro-assembled RCS and transmitted to P through ultralow-loss fibre (ULL-F). All classical signals are sent using a laser array in DWDM-OOK and received by high-speed PIN detectors, transmitted near the speed of light through an AR-HCF. The BFU is implemented using table lookups and logic computations on an FPGA with 1-Tb DDR memory, where the PIN array signals serve as addresses and the stored data as the output measurement basis. The QMU uses high-voltage driven a low-loss optical switch (OS) to select a measurement basis and superconducting detectors (DET) for detection. V1 and V2 use time-to-digital converters (TDCs) to capture the returned measurement signals and record the latency. ATT, attenuator; PC, polorization controller; BS, beam splitter.The quantum part including QPU and QMU needs to be efficient enough to meet the given security threshold. On the one hand, it is necessary to control losses and error rates to enable the honest prover to achieve a higher score. On the other hand, the bit rate needs to be increased to raise the threshold of quantum resources required for attacks. We adopt the lowest-loss solutions for each loss-sensitive component. The channel uses the ultralow-loss fibre with attenuation of 0.142 dB km−1, basis selection is implemented using optical switches with 0.6-dB insertion loss, and detection is performed using superconducting single-photon detectors with 90% efficiency. As a result, the overall system transmission efficiency reaches 70%.However, low-loss optical switches typically operate at only kilohertz frequency, which limits the bit rate. To overcome this, we developed a fast-response high-voltage driver that enables the switch to operate at 2 MHz, thereby raising the security resource threshold to 2(n/4 − 5) Mbps. Finally, to prepare quantum states with low error, we use a Sagnac-based setup to generate four polarization states of \(\left\vert H\right\rangle +{\rm{e}}^{i\phi }\left\vert V\right\rangle\), ϕ ∈ {0, π, π/2, 3π/2}. The beam splitter in the Sagnac is a micro-assembled rotator, circulator and polarizing beam splitter (PBS), named RCS. This enables simple and stable state encoding with a quantum bit error rate lower than 0.27%. The specific details are provided in the ‘High-fidelity quantum state preparation’ section in Methods.The latency is measured from the moment a verifier sends the basis information to the moment it receives the measurement result. Ideally, the total delay should closely match the round-trip flight time at the speed of light in vacuum. Unfortunately, the transmission of classical bits and credential, the execution of the Boolean function and the basis selection and detection of the quantum state all introduce additional delay. A more challenging aspect is that the Boolean function requires a large n, and the quantum measurement demands high efficiency, which often conflicts with the goal of low latency.We primarily focus on the implementation of the Boolean function, as it directly impacts both the delay and n. To avoid the prohibitive computational resource and latency requirements associated with large-scale Boolean functions, and noting that a Boolean function is uniquely specified by its truth table, we implement random Boolean functions using a lookup-table approach rather than explicit computation. This converts the requirement for logic-gate resources into a demand for memory, which is more practical to realize for large input size. We design a circuit based on FPGA and DDR memory to implement Boolean functions, where the basis information is used as the data address input, and the corresponding stored bit serves as the output. Different random bit sequences filling the DDR correspond to different Boolean function mappings. The total DDR capacity is 1 Tb = 240 bits, which corresponds to n = 40. By leveraging parallelism and combinational logic, the Boolean function operates with a delay of 117.3 ns, primarily due to DDR access latency. The specific details are provided in the ‘Large-scale and rapid Boolean function’ section in Methods.Next, we address the transmission delay, especially for the 40-bit basis information. By using 978.4-m and 981.2-m AR-HCF links between the verifiers and the prover, along with DWDM-OOK encoding for simultaneous bit transmission, the excess delays from V1 and V2 to P are substantially reduced to 22.05 ns and 22.39 ns, respectively. The remaining latency arises from the single-mode pigtails of the hollow-core fibre and also includes a contribution from the finite propagation speed in the fibre, which is slightly below the speed of light in vacuum. Then, the high-voltage driver for the low-loss optical switch is based on GaN, enabling 400-V peak-to-peak voltage switching within 50 ns. A delay of approximately 17.7 ns is introduced by the single-photon detector due to its internal wiring. The remaining delay of about 20 ns is caused by the unavoidable fibre and cable connections between components. Detailed explanations of these two parts are provided in the ‘Near-light-speed channel’ and ‘Low-delay and low-loss quantum measurement’ sections in Methods.In the experiment, a random bit sequence is loaded into the memory of the Boolean function circuit, representing the selected function. The two verifiers send verification streams to the prover at a frequency of 2 MHz, while V1 simultaneously sends qubits to the prover at the same rate. The prover decodes the basis information and measures the qubit accordingly, then immediately sends the single-photon detector results back to each verifier. The number of rounds N required for successful verification and the intensity of the transmitted weak coherent states are 107 and 0.52, respectively, in our experiment. These parameters are optimized based on the error rate and transmittance of the quantum subsystem.Table 1 presents the theoretical and experimental values for each type of event, where the theoretical score corresponds to the threshold Γ0. Note that, due to the presence of vacuum and multiphoton components in weak coherent states, an overall response rate of \(\left({n}_{c}+{n}_{I}\right)/N < 30 \%\) does not imply a violation of the theoretical requirement that the transmittance be no less than 50%. The results show that the score obtained in all five experimental trials exceeded Γ0, thereby achieving successful verification. The average score of the verification system is −232,824.32 ± 199.80, well above Γ0, demonstrating the robustness of the system enabled by the optimal selection of coherent states. The prover’s maximum response delay is 247.8 ns, corresponding to a verification range of 74.3 m, achieving a level of practical relevance.Table 1 Experimental resultsFull size tableConclusion and discussionWe demonstrate secure position verification grounded in both relativistic and quantum principles. Given two verifiers with known coordinates, the claimed position of a remote prover can be authenticated within 75 m of accuracy in only a few seconds, enabled by an overall system latency in the nanosecond regime. The security of the scheme relies on the light-speed limit and the non-reciprocity between classical and auxiliary resources. With a classical input size of n = 40, the adversary requires at least five bits of auxiliary resources per round, and the 2-MHz repetition rate further amplifies this requirement by forcing these resources to be sustained at a correspondingly high rate, thereby increasing the practical difficulty of an attack. This implies an effective requirement of ~10-MHz auxiliary resources. Assuming this auxiliary resource must be entanglement, as suggested by refs. 15,16,17,18,19, and using entanglement-based communication as a reference, the rate exceeds current capabilities by more than two orders of magnitude26,27,28,29. This establishes a milestone in elevating QPV from a theoretical concept to a practically deployable technology.Our experiment builds on and extends refs. 8,9, while subsequent developments in this direction have led to several advances that provide promising directions for future exploration. On the one hand, security frameworks oriented towards practical implementation are expected to further improve system performance. For example, ref. 20 shows that inner product functions can also resist adversaries with resources scaling linearly with the input size, which is advantageous for achieving larger n and lower latency, and perhaps, this can be combined with the approach in ref. 10 to enable loss tolerance. On the other hand, implementing the quantum component of QPV based on entanglement offers a complementary technological route. The quantum component of QPV is closely analogous to that of quantum key distribution. In quantum key distribution, both prepare-and-measure and entanglement-based implementations are well-established paradigms. Motivated by this analogy, entanglement-based approaches may also admit viable solutions for QPV. The key difference is that the prover is required to perform operations on the quantum states according to the verifiers’ instructions, such as performing measurements in different bases or routing the states to different verifiers. Reference 24 formulates QPV as a device-independent statistical test based on Bell-type inequalities, achieving minimal trust assumptions on quantum devices and substantially strengthening the security guarantees of the system, thereby establishing a research perspective distinct from our high-performance prepare-and-measure QPV approach with practical relevance. Furthermore, more variant approaches may be possible. For example, the verifiers may both send qubits to the prover for Bell-state measurements, and the prover may subsequently send quantum states back to the verifiers. In such settings, the prover can use the measurement outcomes to control when and what states to emit. Such approaches require a rigorous security analysis. These two directions capture complementary aspects of quantum cryptography, jointly advancing QPV from both practical and foundational perspectives.In real life, position is a fundamental element of human activity. Our method provides a solution for position-based authentication scenarios, where certain actions are permitted only when a user is physically present at a specific position. For example, allowing transactions only near an automated teller machine, granting database access only inside an office, unlocking tickets only at a concert venue or enabling vehicle access only beside a rental car. In addition, this method can be applied to the position tracking of critical targets, such as individuals in disaster relief, high-value goods and military assets such as weapons and ammunition.Fig. 3: Structure of the Sagnac Interferometer and the RCS component.Full size imageThe red lines denote polarization-maintaining fibre and the green line denotes single-mode fibre. CIR, circulator; PM, phase modulator.MethodsSecure score with coherent statesIn quantum communication practice, using weak coherent states is much more convenient than using single-photon sources, as weak coherent states can be easily prepared by simply attenuating laser pulses. This approach offers two major advantages, insensitivity to losses in the sender’s devices and the ability to achieve high repetition rates. It is crucial for QPV, as the protocol is loss-sensitive and requires more than 106 rounds of repetition.To facilitate security analysis, we use PR-WCS, which are mixed states of Fock states. Such sources are readily available, with phase randomization naturally achieved using gain-switched lasers. We proceed to derive Γ0 for the case of weak coherent states, taking into account statistical fluctuations due to the finite number of rounds, thereby establishing a rigorous security bound.PR-WCS are mixed states of Fock states, that is, \(\int_{0}^{2\uppi }\left\vert \alpha {\rm{e}}^{\text{i}\theta }\right\rangle \left\langle \alpha {\rm{e}}^{\text{i}\theta }\right\vert\)\(=\mathop{\sum }\nolimits_{i = 1}^{\infty }{\rm{e}}^{-{| \alpha | }^{2}}\)\(\frac{{| \alpha | }^{i}}{i!}\left\vert i\right\rangle \left\langle i\right\vert\), where \(\left\vert \alpha {\rm{e}}^{\text{i}\theta }\right\rangle\) is the coherent state with a complex amplitude αeiθ, and \(\left\vert i\right\rangle\) is the i-photon Fock state. Therefore, each round of quantum state preparation can be categorized into three types, vacuum states, single-photon states and multiphoton states. For single-photon states, the same approach as in ref. 9 can be applied. Vacuum states contain no encoded information, so an adversary cannot obtain polarization information from them through measurement but can only guess the outcome. For multiphoton states, we adopt the most pessimistic scenario, assuming that the adversary can perfectly attack them. Then, Γ0 can be written as$${\varGamma }_{0}={S}_{0}^{u}+{S}_{1}^{u}+{S}_{2+}^{u},$$ (1) where S0, S1 and S2+ represent the scores corresponding to vacuum, single-photon and multiphoton states, respectively. The superscript u denotes the upper bound that a dishonest prover can achieved. We next analyse the upper bounds separately. In the following analysis, we use probabilistic inequalities with failure probability ϵ for five times. So the failure probability of the protocol is 5ϵ. In our experiment, we set ϵ = 10−10, so the total failure probability is 5 × 10−10. This means a dishonest prover cannot surpass the threshold Γ0 with a probability larger than 5 × 10−10.Upper bound for vacuum statesFor vacuum states, the adversary may either declare a no-response event or a response event. A no-response contributes to n⊥. A response event yields a correct outcome with 50% probability, thereby contributing to either nc or nI. Let N0 be the total number of vacuum-state rounds, x the number of rounds where the adversary declares a response, and the remaining N0 − x rounds correspond to no-response events. Let Yi denote the score obtained by the adversary in the ith round with a declared response. Then, for all rounds of vacuum states, the adversary’s total score, S0, is given by$${S}_{0}=\mathop{\sum }\limits_{i=1}^{x}{Y}_{i}-\left({N}_{0}-x\right){\gamma }_{\perp }.$$ (2) For any given response round, because the vacuum state does not reveal any encoded information, each round is independently and identically distributed, yielding a correct or incorrect response with equal probability of 50%. By normalizing Yi as a Bernoulli random variable \(\frac{{Y}_{i}+{\gamma }_{I}}{{\gamma }_{C}+{\gamma }_{I}}\) and applying the Chernoff bound30 for independent random variables, we obtain$$\mathop{\sum }\limits_{i=1}^{x}{Y}_{i}\le \frac{{\gamma }_{C}-{\gamma }_{I}}{2}x+\frac{{\gamma }_{C}+{\gamma }_{I}}{2}\left(\ln \frac{1}{\epsilon }+\sqrt{{\ln }^{2}\frac{1}{\epsilon }+4\left(\ln \frac{1}{\epsilon }\right)x}\right),$$ (3) where ϵ is the failure probability. So the upper bound of S0 is given by$${S}_{0}\le \frac{{\gamma }_{C}-{\gamma }_{I}}{2}x+\frac{{\gamma }_{C}+{\gamma }_{I}}{2}\left({\rm{ln}}\frac{1}{\epsilon }+\sqrt{{\rm{ln}}^{2}\frac{1}{\epsilon }+4\left({\rm{ln}}\frac{1}{\epsilon }\right)x}\right)-\left({N}_{0}-x\right){\gamma }_{\perp }.$$ (4) Noting that \(\mathop{\max }\nolimits_{x}\;(ax+b\sqrt{c+dx})\to x=-\frac{c}{d}+\frac{{b}^{2}d}{4{a}^{2}}\), the score S0 reaches its upper bound \({S}_{0}^{u}\) when \(x=-\frac{1}{4}\ln \frac{1}{\epsilon }+\frac{{({\gamma }_{C}+{\gamma }_{I})}^{2}}{{({\gamma }_{C}-{\gamma }_{I}+2{\gamma }_{\perp })}^{2}}\ln \frac{1}{\epsilon }\). So \({S}_{0}^{u}\) is given by$$\begin{array}{l}{S}_{0}\le {S}_{0}^{u}=\displaystyle\frac{(7{\gamma }_{C}^{2}+4{\gamma }_{C}{\gamma }_{\perp }+4{\gamma }_{\perp }^{2}+10{\gamma }_{C}{\gamma }_{I}+12{\gamma }_{\perp }{\gamma }_{I}-{\gamma }_{I}^{2}){\rm{ln}}\frac{1}{\epsilon }}{8({\gamma }_{C}+2{\gamma }_{\perp }-{\gamma }_{I})}\\\qquad\qquad+({\gamma }_{C}+{\gamma }_{I})\sqrt{\frac{{({\gamma }_{C}+{\gamma }_{I})}^{2}{\rm{ln}}^{2}\displaystyle\frac{1}{\epsilon }}{{({\gamma }_{C}+2{\gamma }_{\perp }-{\gamma }_{I})}^{2}}}-{\gamma }_{\perp }{N}_{0}.\end{array}$$ (5) In the case where γC + 2γ⊥ − γI < 0, it can be further simplified to$${S}_{0}\le {S}_{0}^{u}=-\frac{{({\gamma }_{C}-2{\gamma }_{\perp }+3{\gamma }_{I})}^{2}\ln \frac{1}{\epsilon }}{8({\gamma }_{C}+2{\gamma }_{\perp }-{\gamma }_{I})}-{\gamma }_{\perp }{N}_{0}.$$ (6) Upper bound for single-photon statesFor single-photon states, we follow the same analysis as in ref. 9, which gives the following result. For a single-photon round, if we assume that the attackers output different responses to the two verifiers with a probability less than ξ, then semidefinite programming can be used to obtain a set of parameters {γC, γ⊥, γI}, such that the adversary’s expected score under these parameters does not exceed zero. The parameters in this work are selected using this approach. To ensure a reasonable choice of ξ, we note that in our experiment the honest prover always reports same responses. If the attackers adopt a strategy exceeding ξ in more than Nξ rounds, the probability of finding no different-response events would be less than \({(1-\xi )}^{{N}_{\xi }}\). Therefore, with a failure probability of ϵ, we can conclude that \({N}_{\xi }\le \ln \epsilon /\ln (1-\xi )\). Therefore, let N1 be the number of single-photon rounds, then there are less than \({N}_{\xi }\le \ln \epsilon /\ln (1-\xi )\) rounds that the attack is not included in the analysis of ref. 9. And there are more than \({N}_{1}-{N}_{\xi }\le \ln \epsilon /\ln (1-\xi )\) rounds that the expected scores of attackers are less than 0.To give a worst-case analysis, we assume in \({N}_{\xi }\le \ln \epsilon /\ln (1-\xi )\) rounds, the attackers can perfectly attack the system, which means the attacks always give correct responses. The corresponding score upper bound is \({\gamma }_{C}{N}_{\xi }\le \ln \epsilon /\ln (1-\xi )\). For the rest \({N}_{1}-{N}_{\xi }\le \ln \epsilon /\ln (1-\xi )\) rounds, ref. 9 has proved the sequential repetition, and Azuma’s inequality31 can be used to bound the score upper bound. We still set the failure probability of the Azuma’s inequality to be ϵ, then the score upper bound is given by \(\sqrt{2\ln \frac{1}{\epsilon }({N}_{1}-\frac{\ln \epsilon }{\ln (1-\xi )})}\). This formula applies under the condition that \(\max \{\left\vert {\gamma }_{C}\right\vert ,\left\vert {\gamma }_{\perp }\right\vert ,\left\vert {\gamma }_{I}\right\vert \}\le 1.\)Combining the above two case, the score upper bound is given by$${S}_{1}^{u}={\gamma }_{C}\left\lceil \frac{\ln \epsilon }{\ln (1-\xi )}\right\rceil +\sqrt{2\ln \frac{1}{\epsilon }\left({N}_{1}-\left\lceil \frac{\ln \epsilon }{\ln (1-\xi )}\right\rceil \right)},$$ (7) where we added the ceiling because the number of rounds should be an integer.Upper bound for multiphoton statesFor multiphoton states, the worst case is that the adversary can perform a perfect attack, always producing correct responses. Thus, the score is given by$${S}_{2+}^{u}={N}_{2+}{\gamma }_{C},$$ (8) where N2+ is the number of rounds containing two or more photons. Γ 0 under statistical fluctuationsThe photon-number distribution of PR-WCS follows a Poisson distribution with mean photon number μ = ∣α∣2. However, given a total of N rounds, the actual numbers of vacuum, single-photon and multiphoton events, denoted by N0, N1 and N2+, are subject to statistical fluctuations. These fluctuations should be taken into account when computing Γ0.According to equations (6)–(8), the score contributed by N0 is negative, while those from N1 and N2+ are positive. Thus, the upper bound of Γ0 is given by \({\varGamma }_{0}^{u}={\varGamma }_{0}({N}_{0}^{l},\,{N}_{1}^{u},\,{N}_{2+}^{u})\), where the superscripts u and l indicate the upper and lower bounds, respectively. These bounds can be obtained using the Chernoff bound,$${N}_{1}\le {N}_{1}^{u}=N{\rm{e}}^{-\mu }\mu +\frac{1}{2}\left(\ln \frac{1}{\epsilon }+\sqrt{{\ln }^{2}\frac{1}{\epsilon }+8\left(\ln \frac{1}{\epsilon }\right)N{\rm{e}}^{-\mu }\mu }\right)$$ (9) $$\begin{array}{l}{N}_{2+}\le {N}_{2+}^{u}=N(1-{{\rm{e}}}^{-\mu }-{{\rm{e}}}^{-\mu }\mu )\,+\\\;\displaystyle\frac{1}{2}\left({\rm{ln}}\displaystyle\frac{1}{\epsilon }+\sqrt{\rm{ln}^{2}\displaystyle\frac{1}{\epsilon }+8\left({\rm{ln}}\displaystyle\frac{1}{\epsilon }\right)N(1-{{\rm{e}}}^{-\mu }-{{\rm{e}}}^{-\mu }\mu )}\right)\end{array}$$ (10) $${N}_{0}\ge {N}_{0}^{l}=N-{N}_{1}^{u}-{N}_{2+}^{u}.$$ (11) Experimental optimizationIn practice, it is important to ensure that an honest prover can pass the verification despite potential misalignment in its measurement system. Let pe denote the misalignment error and η denote the transmittance. The problem reduces to finding an optimal mean photon number μ that maximizes Γ − Γ0, where the expected score of an honest prover is given by$$\varGamma =N\left({\gamma }_{C}(1-{{\rm{e}}}^{-\eta \mu })(1-{p}_{{\rm{e}}})-{\gamma }_{\perp }{{\rm{e}}}^{-\eta \mu }-{\gamma }_{I}(1-{{\rm{e}}}^{-\eta \mu }){p}_{{\rm{e}}}\right).$$ (12) Based on the normalized parameters γC = 0.04275, γ⊥ = 0.05019 and γI = 1 obtained via semidefinite programming in ref. 9, when ξ = 0.001, along with the experimental parameters pe = 0.3% and η = 70%, the average photon number is optimized to μ = 0.52 for N = 107. In this case, Γ0 is calculated as −242,972.High-fidelity quantum state preparationCoherent-state sourceThe coherent-state source is a gain-switched laser driven by narrow electrical pulses. To obtain a stable and reliable high-speed picosecond source, the key is to generate ultrashort and repeatable pump excitation. We use fast electronics to produce ultranarrow electrical pulses to drive the gain-switched laser in the relaxation oscillation regime. Specifically, the input 2-MHz periodic signal is processed through a sequence of high-speed electronic operations, including comparison, fan-out, inversion, delay, logical AND and amplification. This converts the signal into ultranarrow electrical pulses with the same repetition rate of 2 MHz and fast rising and falling edges. The resulting electrical signal has a root mean square jitter of 4 ps.These electrical pulses are then used to drive the gain-switched laser. Under short-pulse excitation, carriers rapidly accumulate in the laser and trigger photon emission. When the electrical pulse is switched off, carrier injection stops and drops below the lasing threshold, turning off the laser. This process confines photon emission within 200 ps, yielding optical pulses with a full width at half maximum (FWHM) of 47 ps. Due to the intrinsic dynamics of gain switching, the root mean square jitter of the output optical pulses is 19 ps.In addition, because the laser wavelength is sensitive to environmental temperature and driving current, we use a high-precision proportional–integral–derivative feedback loop to stabilize the laser temperature within 1 mK. Together with a constant-current driver, this ensures wavelength stability (±2.5 pm over 30 min). At 25 °C, the central wavelength is 1,549.65 nm, with a 3-dB spectral linewidth of 0.06 nm.Polarization encoding moduleThe principle of polarization-state preparation is to split an initial polarization state into two components, introduce a relative phase by adjusting the phase of one component and then recombine them orthogonally to generate the state \(\left\vert H\right\rangle +{\rm{e}}^{i\phi }\left\vert V\right\rangle\). Here, we adopt a Sagnac structure. After the initial polarization state is divided into two parts, they propagate clockwise and counterclockwise in the Sagnac loop. A phase modulator placed at an off-centre position selectively modulates the phase of only one propagation direction, thereby introducing a relative phase difference.The key advantage of this structure is that the clockwise and counterclockwise pulses traverse the same fibre, so their relative phase does not drift due to path-length differences. This yields high stability and is favourable for high-fidelity quantum state preparation. However, conventional Sagnac schemes based on beam splitters cannot be used for polarization-state preparation because they do not support orthogonal recombination. Using a PBS would require rotating the initial polarization by 45° with a polarization controller, which compromises stability.To address this limitation, we design a micro-assembled RCS that integrates a rotator, a circulator and a PBS. The micro-assembly process enables precise polarization rotation and accurate 50:50 splitting, while the inclusion of the circulator suppresses reflections associated with the Sagnac loop.Figure 3 illustrates the structure of the Sagnac interferometer and the micro-assembled RCS component. In the RCS, the rotator is implemented by rotating the polarization-maintaining fibre pigtail by 45°, while the circulator is a single-mode device. A phase modulator is placed in the Sagnac loop at a position where the clockwise and counterclockwise paths differ by 8.5 ns in arrival time.The input light enters the RCS along the slow axis of the polarization-maintaining fibre and is aligned at 45° with respect to the circulator before reaching the PBS. This 45° alignment ensures a 50:50 splitting ratio at the PBS. After splitting, the two orthogonal polarization components both propagate along the slow axis of polarization-maintaining fibres and arrive at the phase modulator sequentially from the clockwise and counterclockwise directions, with a relative delay of 8.5 ns. The phase modulator applies different phase shifts to the two components, thereby introducing a relative phase difference ϕ between them. They then return to the PBS and recombine into \(\left\vert H\right\rangle +{\rm{e}}^{i\phi }\left\vert V\right\rangle\) and are finally emitted from another port of the circulator.As a result, this design achieves high-fidelity polarization-state preparation with a measured fidelity of 99.73%. The correspondingly low error rate allows the protocol to tolerate higher losses and enables the prover to attain higher scores, which constitutes one of the key factors for the successful operation of the system.Large-scale and rapid Boolean functionThe prover obtains the basis choice by performing a Boolean function evaluation f({0, 1}n) → {0, 1}, which is a key step in the f-BB84 protocol. The method of computation and the input size n determine the security, while the computation speed also affects the overall latency. Unfortunately, the required Boolean function is not a simple fixed mapping that could be readily implemented and simplified using logic circuits, truth tables or Karnaugh maps. Instead, it is a uniformly random Boolean function.For an input size of n bits, there are 2n possible inputs, and each input can map to either 0 or 1, giving a total of \({2}^{{2}^{n}}\) possible Boolean functions. Experimentally, one Boolean function is selected uniformly at random from the set of all possible functions and is kept fixed across all N rounds within a single verification task.To achieve large-scale and rapid random Boolean function computation, we use a lookup-table approach implemented with a custom FPGA and DDR-based circuit. Although fast computation typically relies on logic gates, we use a lookup-table method because logic gates are impractical in terms of both resource consumption and delay. On one hand, the state space of Boolean functions is \({2}^{{2}^{n}}\). Assuming each logic gate can represent m states, the required number of gates is \({\log }_{m}({2}^{{2}^{n}})\), which grows exponentially with n and far exceeds the capacity of current FPGAs. On the other hand, logic gates inevitably introduce circuit delays. When multiplied by an exponential number of gates, the resulting delay becomes prohibitive.The lookup-table approach transforms the scalability challenge into a memory-space problem. We implement the Boolean function using DDR chips with a total capacity of 1 Tb = 240 bits, corresponding to n = 40. Once the FPGA receives 40 bits, it uses them as an address to access the corresponding bit stored in the DDR memory and outputs the result as the basis selection signal. By writing different truth-table outputs in DDR memory, different Boolean functions can be implemented, enabling support for the full set of \({2}^{{2}^{40}}\) possible Boolean functions. The truth-table outputs can be selected uniformly at random using a random number generator, satisfying the protocol’s requirement for uniform randomness. The truth table is preloaded before the protocol begins and therefore does not contribute to the latency, although the DDR write speed is also high.Due to the inherent delay of the FPGA and the random-access performance of the DDR memory, this part introduces a delay of approximately 117.3 ns. Among these, the DDR readout latency is approximately 93.32 ns, while the input/output latency accounts for about 18.98 ns.Near-light-speed channelBoth the basis information and the measurement results are classical bits and can be transmitted using the same method. The main difference is that the basis information contains n/2 bits, while the measurement result is a single bit. To enable rapid transmission of classical information, we adopt a simple communication scheme based on amplitude shift keying, where a high-intensity signal represents ‘1’ and a low-intensity signal represents ‘0’. We implement intensity modulation using direct modulated laser, which eliminates the need for an external intensity modulator and reduces system complexity and cost. To avoid additional jitter caused by oscillations, we do not use gain switching as in the quantum source. Instead, the laser operates in continuous emission.Specifically, the drive current is set slightly above the threshold current, resulting in weak emission with an optical power of about 0.2 mW, corresponding to bit ‘0’. To encode bit ‘1’, the drive current is increased to about 40 mA, yielding an optical power of about 4 mW. The high-current signal is maintained for 2 ns. Therefore, when encoding bit ‘1’, the laser outputs a 2-ns optical pulse, while it remains in the low-power mode otherwise. The rise and fall times of the driving signal are about 300 ps. As the laser operates in continuous emission, additional timing jitter is negligible.A further challenge is that if each bit is transmitted with a cycle duration of τ, sending n/2 bits will introduce a delay of (n/2 − 1)τ, which is unfavourable for Boolean functions with large n. We use dense-wavelength division multiplexing with independent lasers at different wavelengths to send specific bits simultaneously. The frequency grid is 100 GHz, in accordance with the ITU-T G.694.1 standard. The laser array at the verifier occupies 20 wavelength channels from 1,559.794 nm to 1,544.526 nm, corresponding to DWDM channels C22-C41. This enables the parallel transmission of n/2 bits, eliminating delay dependence on n. The optical signals are detected using high-speed PIN photodiodes and directly fed into subsequent circuits for discrimination.Signal transmission through the channel also takes time. To minimize this delay, we use an AR-HCF with an air-filled core, enabling light to propagate at nearly the speed of light in vacuum. Combined with low dispersion, the additional delay is limited to approximately 22 ns.Low-delay and low-loss quantum measurementThe loss in quantum state measurement primarily originates from the insertion loss of the basis selection device and the detection efficiency of the photon detector. To mitigate this, we use low-loss optical switches and superconducting nanowire single-photon detectors. In addition, polarization-maintaining fusion splicing is used to reduce connector loss. As a result, the overall insertion loss is approximately 0.96 dB, mainly due to the insertion loss of the optical switch (about 0.6 dB). The detection efficiency reaches 90%, leading a transmission efficiency of 72%.However, this configuration introduces delay challenges. High-speed, low-loss optical switches require a driving voltage exceeding 400 V and cannot directly interface with the digital outputs of the Boolean function circuit. In addition, the weak click signal from the detectors cannot be directly transmitted over long distances to the verifiers. Signal conversion inevitably introduces delay. To address this, we develop a GaN-based high-voltage driver that converts digital signals into high-voltage signals within 50 ns, enabling fast response of the optical switch. In parallel, we design an integrated signal processing unit for the detectors that performs amplification, discrimination and on–off keying encoding to reduce the return delay of detection signals. These measures lead to a substantial reduction in delay, without compromising low-loss and high repetition rate.
Tags
Source Information
Discussion
0 professional contributions
Sign in to join this professional discussion.
Be the first to add a constructive contribution.
