Parameter Estimation

PUBLISHED
DURATION 11 min read
MODIFIED
Table of Contents

The Goal of Parameter Estimation

We assume that each lost photon or noise was actively caused by Eve while manipulating quantum states.

The goal is to perfectly bound Eve’s maximum possible knowledge so that we can distill a mathematically secret key, as far as the laws of physics permit.

Outputs of Parameter Estimation

The untrusted quantum channel is entirely defined by just two physical parameters:

  1. Transmittance (): The linear scaling factor representing how much signal survives after passing through the quantum channel.
  2. Excess Noise (): The additional variance injected into the channel by Eve that cannot be explained by fundamental vacuum shot noise or hardware.

Only two parameters suffice because of the Gaussian Optimality theorem. In a Gaussian modulated protocol like ours, the prepared states are Gaussian and it has been proven that Eve’s most powerful attack is to use a Gaussian operator.

We completely know about a zero-mean Gaussian distribution, if we have its covariance matrix. The matrix in our case consists of the two above mentioned unknowns. (We’ll see later how).

The Covariance Matrix

To calculate the worst-case bound for Eve’s information, physicists use the Entanglement-Based Model. Even though Alice physically modulates a continuous wave laser, the security proofs assume she generates a Two-Mode Squeezed Vacuum (TMSV) entangled state, keeping Mode A and sending Mode B to Bob.

The covariance matrix () completely characterizes this imaginary entangled bipartite state.

Path to the Secret Key Rate

This process converges on the **Devetak-Winter Formula:**

Here,

The Exact Outputs of Parameter Estimation

After the PE stage concludes, it outputs two definite real numbers:

The Linear Regression Model

To extract the estimators for and , we treat the quantum channel as a classical linear regression mapping Alice’s sent array and Bob’s received array .

The correlated pairs are modelled as:

Here,

ML Estimators

The hardware uses MLE to find the best fit line through a scatter plot of pulses.

The empirical slope estimator is calculated as:

The empirical noise variance estimator is calculated from the residuals as:

These are just the point estimators, to find the worst case values, we must calculate the standard deviations of these estimators to establish the confidence intervals and .

Variation in Slope

Here and are treated as fixed constants, then,

Because each sample is independent, the variance of sum is equal to the sum of variances

We know that . We also know that sum of all squared sent values is the total prepared variance of pulses, or . This gives:

To obtain the worst-case boundary , we calculate the standard deviation and scale it by the confidence interval multiplier , substituting empirical noise in place of unknown true noise.

Variation in Noise

The random noise is empirically given by the residual term .

We know that summing the squares of independent standard normal variables yields a Chi-squared distribution with degrees of freedom.

For very large , the CLT says that this heavily approximates a Gaussian distribution. The fourth central moment of a distribution is . Using this property, the theoretical variance for the simple noise estimator simplifies to:

The standard deviation is therefore . Scaling this by the confidence multiplier and substituting empirical variance gives the worst-case noise fluctuation limit:

Calculating Worst-Case Parameters

To minimize the assured mutual information between Alice and Bob, we force the channel efficiency to the bottom of the confidence interval:

Conversely, to maximize Eve’s Holevo Bound , we force the noise to the top of the Chi-squared confidence interval:

Using the theoretical noise model , we isolate Eve’s specific specific excess noise by subtracting the trusted vacuum and electronic noise and dividing by the minimum compounded transmittance:

Reconstructing the worst-case covariance matrix

For the zero-mean Gaussian states, the covariance matrix completely defines the bipartite quantum state shared by Alice and Bob.

Let the total variance of Alice’s source be , where is the fundamental vacuum shot noise. The matrix is constructed as a block matrix of sub-matrices:

Then, .

Symplectic Transformation and Williamson’s Theorem

To calculate the quantum entropy, we need the eigenvalues of . But standard linear algebra is meaningless here as it does not preserve the Heisenberg Uncertainty Principle .

We rely on Williamson’s Theorem, which proves that any valid symmetric, positive-definite covariance matrix can be diagonalized by a symplectic transformation into a diagonal matrix . Physically, this uncouples our complicated entangled state into two independent, uncoupled quantum harmonic oscillators in thermal states, with variance and . These are called the symplectic eigenvalues.

Deriving the Symplectic Eigenvalues

We solve the characteristic polynomial of the symplectic matrix product, which strictly reduces to a bi-quadratic equation:

Here, and are symplectic invariants, values that never change regardless of what operations Alice and Bob perform. We derive them directly from the determinants of our matrix blocks.

Let use define scalars , , Then,

The first invariant is defined as:

The second invariant is the square root of covariance matrix:

Solving for the Symplectic Eigenvalues

Use the Sridharacharya formula, we find the roots of the bi-quadratic equation. Because symplectic eigenvalues are strictly positive (), we get the solution as:

Now, we can calculate the global entropy of Alice and Bob’s shared state, .

The Purification Theorem and The Holevo Bound

The Holevo Bound gives Eve’s maximum accessible information. Her knowlowdge is defined as her uncertainty before Bob’s measurement minus her remaining uncertainty after Bob’s measurement:

We use the **Purification Assumption** to calculate Eve’s unknown physical memory as it is impossible to evaluate experimentally.

We assume the entire universe (Alice, Bob and Eve) forms an isolated, perfectly pure quantum state . Because this global state is pure, its total von Neumann entropy is zero i.e. .

Using the Schmidt Decomposition of pure bipartite states, splitting this universe in half dictates that the entropy of both halves are equal.

This implies Eve’s entropy matches Alice and Bob’s joint entropy:

When Bob does his measurement , he projects the remaining unmeasured system into a new pure state . Applying the same decomposition:

This allows us to rewrite Eve’s information entirely using measurable parameters:

The Bosonic von Neumann Entropy Function

To convert the symplectic eigenvalues () into entropy (), we associate the eigenvalues (which represent variance in SNUs) to average photon number of a thermal of a thermal state:

Substituting this into the standard statistical entropy formula , we derive as:

The global entropy becomes:

The Gaussian State Collapse

When Bob performs a homodyne measurement (say on the -quadrature), the continuous-variable entangled state does not collapse into a discrete eigenstate, but into a conditional state that is still Gaussian.

For Alice, her covariance matrix is derived using Schur Complement:

Where,

  1. is the projection matrix for an -homodyne measurement: .
  2. denotes the Moore-Penrose pseudo-inverse.

Let’s compute the matrices using the scalars , and :

  1. Project Bob;s subsystem: . Its pseudo inverse is .
  2. Correlation reduction: multiply the inverse projection by cross correlation matrices :

  3. Subtract from Alice’s initial state:

    This result has a deep physical interpretation: Bob’s measurement on the -quadrature collapses and reduces Alice’s uncertainty in her own quadrature by exactly . Because Bob gathered zero information about the -quadrature, Alice’s -variance remains unchanged at .

We see that the conditional variance relies strictly on the matrix properties (, , ) and independent of Bob’s actual measured voltage .

The Conditional Symplectic Eigenvalue

This is becuase is a single-mode covariance matrix. Hence Alice’s conditional entropy is

The Final Secret Key Rate

Substituting the entropies back into the Holevo Bound yields Eve’s maximum information:

The mutual information is calculated using the Shannon-Hartley theorem based on the classical SNR of worst case parameters. Combining this with the reconciliation efficiency of the LDPC error-correction decoders, we arrice at the finite-size unconditionally secure key rate:

Here, represents the fraction of pulses used for key generation, discarding the pulses sacrificed strictly for parameter estimation.

If , the channel is compromised or too noisy, and the communication must abort.

Else, if , the remaining key is theoretically secure against any physical permitted adversary.