Secret-key capacity of thermal attenuators and amplifiers
- Field
- Topics
Problem
What is the secret-key capacity of a thermal attenuator for every transmissivity and thermal noise level? Fix a transmissivity \(0<\eta<1\) and \(b\geq0\). The single-mode thermal attenuator \(\mathcal L_{\eta,b}\) is realized by a beam splitter with output annihilation operator
The independent input and environment modes obey \([a,a^\dagger]=[e,e^\dagger]=1\). The environment is a fresh independent thermal mode at each use, with mean photon number \(b\) and density operator
Here \(|n\rangle\) is the \(n\)-photon Fock state. The unused output mode is discarded. Equations (1) and (2) specify the channel on arbitrary input states. Protocols may use arbitrary adaptive local quantum operations and unlimited two-way public classical communication. The parties initially share no entanglement or secret key. There is no input-energy bound; the capacity is the supremum over finite mean input-energy budgets. The secret-key capacity \(K\) is the supremum of asymptotic secret bits per channel use. Correctness and secrecy errors must vanish. Secrecy is against an adversary holding a purification of the channel environment and the public transcript. An equivalent formulation asks for the secret-key capacity of a thermal amplifier. With the same thermal environment, define
Thus Eq. (3) identifies the two capacity functions after changing parameters. This identity uses unlimited two-way communication and the supremum over finite energy budgets.
Source
Pirandola et al., Eqs. (23)–(28), give nonmatching bounds for thermal attenuators and amplifiers [PLOB17]. Mele, Lami, and Giovannetti retain the exact-capacity problems while resolving their positivity regions; see Theorem 1 and Supplemental Material, Secs. V.1–V.2 [MLG25]. The reciprocal-channel identification in Eq. (3) is an editorial deduction from the Gaussian teleportation formula in Sec. 6, Eqs. (52)–(54), of Laurenza et al. [LLSBP18].
Progress
Writing \(g_2(x)=(x+1)\log_2(x+1)-x\log_2x\), with \(g_2(0)=0\), the basic bounds are
\begin{equation} \max\{0,-\log_2(1-\eta)-g_2(b)\}\leq K(\mathcal L_{\eta,b}) \leq-\log_2[(1-\eta)\eta^b]-g_2(b),\qquad b<\frac\eta{1-\eta}. \tag{4} \end{equation}At \(b=0\), Eq. (4) gives \(K(\mathcal L_{\eta,0})=-\log_2(1-\eta)\) [PLOB17].
Theorem 1 proves \(K(\mathcal L_{\eta,b})>0\) exactly when \(b<\eta/(1-\eta)\), even with any strictly positive finite input-energy budget. The capacity vanishes at and above that entanglement-breaking threshold. The recurrence-and-hashing construction improves lower bounds, including where reverse coherent information vanishes; explicit rates appear in Supplemental Theorems S19–S20 [MLG25].
The two formulations are equivalent by mutual simulation with reversed communication direction. Use covariance matrices with vacuum covariance \(I\). Send half of a two-mode squeezed vacuum, with local covariance \(\mu I\) and \(\mu>1\), through \(\mathcal L_{\eta,b}\). The resulting resource has scalar covariance blocks
\begin{equation} \begin{aligned} a_\mu&=\mu,\\ d_\mu&=\eta\mu+(1-\eta)(2b+1),\\ c_\mu&=\sqrt\eta\sqrt{\mu^2-1},\\ \epsilon_\mu&=\frac{\mu-\sqrt{\mu^2-1}}{1/\eta-1}. \end{aligned} \tag{5} \end{equation}The diagonal blocks are \(a_\mu I,d_\mu I\), and the cross block is \(c_\mu Z\), where \(Z=\operatorname{diag}(1,-1)\). Reverse-direction Braunstein–Kimble teleportation with gain \(1/\sqrt\eta\) produces the Gaussian channel \(\mathcal A_{1/\eta,b+\epsilon_\mu}\). This follows by substituting Eq. (5) into the noise formula \(g^2a+d-2gc\), with the resource parties interchanged. See Sec. 6, Eqs. (52)–(54) [LLSBP18]. Starting from an amplifier resource gives the reciprocal attenuator in the same way.
This channel simulation applies to arbitrary adaptive protocols. The simulated and target channels share a Gaussian dilation and differ only in their thermal environment. Their unconstrained diamond distance is at most \(\|\tau_{b+\epsilon_\mu}-\tau_b\|_1\), which tends to zero. An \(n\)-use adaptive protocol therefore has output error at most \(n\) times this quantity. For any desired achievable rate, first fix a sufficiently accurate finite block code. Next choose a finite resource energy that simulates that block accurately. Repeating this fixed block and applying key privacy amplification gives rates arbitrarily close to the target rate. The finite key alphabet controls the continuity error, and closeness to a private state ensures security against a purification. The resource energy stays fixed during this outer repetition. Reversing the simulation proves the opposite inequality in Eq. (3). This is an operational derivation, rather than an inference from matching upper or lower bounds.
Ortolano, Pirandola, and Banchi optimize a fully Gaussian protocol based on single-mode Gaussian measurements. For thermal attenuation and amplification, they establish optimality of earlier Gaussian rates within the restricted class they analyze; this neither improves the previously known thermal-attenuator lower bound nor proves optimality among arbitrary adaptive secret-key protocols [OPB25].
Comment
The exact value remains open for general nonzero noise below the entanglement-breaking threshold. The analytic lower bound displayed here is a baseline, and the cited distillation protocols improve it. The reciprocal amplifier is the same unconstrained key-capacity problem. Reciprocity does not assert equality at the same fixed input-energy budget. Unassisted quantum communication and two-way entanglement distribution remain different operational tasks.
References
- [PLOB17]
- S. Pirandola, R. Laurenza, C. Ottaviani, and L. Banchi, “Fundamental Limits of Repeaterless Quantum Communications,” Nature Communications 8, 15043 (2017).DOIarXiv
- [MLG25]
- F. A. Mele, L. Lami, and V. Giovannetti, “Maximum Tolerable Excess Noise in Continuous-Variable Quantum Key Distribution and Improved Lower Bound on Two-Way Capacities,” Nature Photonics 19, 329–334 (2025).DOIarXiv