Robust One-Sided Device-Independent Quantum Key Distribution via High-Dimensional Steering
Source: arXiv:2607.08709 · Published 2026-07-09 · By Monika Mothsara, Suraj Goel, Bohnishikha Ghosh, Vatshal Srivastav, Will McCutcheon, Mehul Malik et al.
TL;DR
This work addresses practical limitations in quantum key distribution (QKD), specifically targeting noise, losses, and device imperfections, by proposing a high-dimensional (HD) one-sided device-independent QKD (1sDI-QKD) protocol. Leveraging quantum steering, the authors develop a systematic security analysis that quantifies secret key rates under realistic noise and loss conditions, showing that increasing the Hilbert space dimension enhances robustness and achievable secret key rates. They experimentally demonstrate key building blocks using photons entangled in the transverse-spatial degree of freedom with programmable multi-outcome measurement devices operating up to dimension 11. Positive key rates are observed across all tested dimensions under the fair-sampling assumption, peaking at dimension 7. They also discuss practical steps necessary to close detection loopholes and enable real-world HD 1sDI-QKD despite realistic device imperfections.
Key findings
- Using reverse reconciliation, the HD 1sDI-QKD protocol achieves positive asymptotic key rates up to dimension d=7, with key rate increasing approximately as log2(d) under low noise.
- Critical detection efficiency threshold for secure key generation in the two-basis protocol remains at η > 50% for all d under perfect visibility, matching the theoretical minimum limit.
- The maximum tolerable noise (depicted by critical visibility νcr) increases significantly with dimension, enabling higher noise tolerance in HD steering-based QKD compared to qubit systems (Fig. 3).
- For the spot-checking protocol (d+1 bases), loss tolerance improves slightly with increasing dimension, while multi-key-basis protocols exhibit somewhat degraded loss tolerance at higher dimension but better noise resilience.
- The extra-outcome strategy for no-click events (treating losses as an additional outcome) outperforms random or deterministic loss-assignment strategies for handling detection losses.
- Reverse reconciliation consistently yields higher secret key rates than direct reconciliation, with the advantage growing in higher dimensions (Fig. 2).
- Semidefinite programming formulations allow numerical optimization of Eve's guessing probability constrained by observed steering violations in multi-basis protocols.
- Experimental setup using multi-plane light converters (MPLCs) achieves high-dimensional multi-outcome projective measurements in mutually unbiased bases (MUBs) up to d=11.
Threat model
The adversary (Eve) is assumed to have full control over the quantum source distributing entangled states and can manufacture or manipulate Alice’s untrusted measurement device. Bob’s measurement device is trusted and fully characterized. Eve aims to gain information about the secret key shared between Alice and Bob. Eve cannot tamper with Bob’s measurement outcomes or devices and cannot influence Bob’s choices. The adversary’s information is encoded in a quantum system E correlated with the distributed state. The model assumes collective attacks and independent, identically distributed rounds.
Methodology — deep read
The protocol adopts a 1sDI-QKD framework involving two parties, Alice and Bob, sharing bipartite entangled states from an untrusted source. Alice's measurement device is untrusted, while Bob's is fully characterized and trusted. The adversary Eve controls the source and potentially Alice's device but cannot access Bob's. Alice performs one of m possible measurements with d possible outcomes plus an additional no-click outcome to represent losses, modeled as an extra outcome in a d+1 outcome POVM. Bob performs projective measurements in d-dimensional mutually unbiased bases (MUBs).
The data consists of n rounds where Alice and Bob randomly select measurement settings, record outcomes, and sift data by basis matching. For parameter estimation, a subset of rounds is compared to evaluate correlations and test steering inequalities. The authors consider three protocol variants: (1) two-basis protocol for key generation and parameter estimation, (2) d+1-basis spot-checking protocol with one key basis and d+1 parameter estimation bases, and (3) d+1-basis multi-key-basis protocol using all bases for key generation and parameter estimation.
Security proofs employ two complementary approaches. For two-basis protocols, entropic uncertainty relations (EUR) bounded by overlap c=1/d between MUBs allow deriving tight asymptotic key rate lower bounds incorporating losses and noise without relying on data post-selection. For d+1-basis protocols, min-entropy bounds are computed via semidefinite programs (SDPs) that optimize Eve's guessing probability under observed steering violation constraints and no-signalling conditions. Losses are modeled by Alice's detection efficiency η affecting POVM elements through the extra-outcome strategy.
Noise is introduced as depolarizing noise characterized by visibility ν on maximally entangled d-dimensional isotropic states shared between Alice and Bob. Alice's overall detection efficiency η models combined channel and detector losses, explicitly included as a separate no-click measurement outcome.
Training consists of simulating asymptotic key rates under various noise visibilities and detection efficiencies across dimensions d=2,3,5,7,9,11, and measurement configurations. The SDPs are solved numerically to obtain Eve's guessing probabilities, plugged into analytic key rate formulas with leakage terms estimated from a depolarizing-loss model.
Experimentally, the authors implement a proof-of-principle setup at telecom wavelengths using transverse-spatially entangled photon pairs and programmable multi-plane light converters (MPLCs) to realize multi-outcome projective MUB measurements in dimensions up to 11. Measured two-photon correlations and steering inequalities validate the theoretical predictions and demonstrate positive key rates under the fair-sampling assumption.
Evaluation metrics include asymptotic secret key rate per round r∞, minimum detection efficiency thresholds ηcr, maximum noise tolerance visibility νcr, and steering functional violation values βobs compared to local hidden state bounds βLHS. Multiple protocol variants and loss handling strategies are compared systematically.
Reproducibility is supported by detailed SDP formulations, model assumptions, and mappings between theoretical parameters and experiment; however, code and data release status is not explicitly stated in the excerpt. Finite-size effects and coherent attacks are not treated extensively but suggested as future extensions.
Technical innovations
- Application of quantum steering in high-dimensional Hilbert spaces to certify 1sDI-QKD security leveraging reverse reconciliation.
- Development of loss-tolerant steering inequalities incorporating no-click events as an extra measurement outcome to close detection loopholes.
- Use of semidefinite programming to numerically bound Eve's guessing probability constrained by observed steering violation in multi-basis protocols.
- Implementation of high-dimensional, fully programmable multi-outcome measurement using multi-plane light converters in spatial photonic degrees of freedom.
Baselines vs proposed
- Two-basis protocol (Protocol Ia): minimum detection efficiency ηcr > 50% under noiseless conditions vs spot-checking protocol slightly improving ηcr with dimension
- Direct reconciliation vs reverse reconciliation: key rates rise with dimension and noise tolerance only under reverse reconciliation (Fig.2)
- For d=7, reverse reconciliation key rate nearly approaches log2(7) bits in high visibility regime vs lower key rates in smaller dimensions
- Comparison of loss-handling strategies: extra-outcome method consistently outperforms random and deterministic outcome assignments (Appendix A)
Figures from the paper
Figures are reproduced from the source paper for academic discussion. Original copyright: the paper authors. See arXiv:2607.08709.

Fig 1: A schematic representation of a high-dimensional

Fig 6: (a) Schematic representation of the experimental setup. A pair of spatially entangled photons at telecom wave-

Fig 15: shows measured two-photon correlations in all MUBs in d = 2, 3, 5, 9, 11. For any dimension d, each of the
Limitations
- Security analysis validated primarily in the asymptotic regime assuming collective attacks; finite-key effects and coherent attacks are not fully analyzed.
- Fair-sampling assumption made for experimental results; loophole-free (detection-loophole-free) implementations require future work.
- No demonstration or discussion of performance under general adversarial side-channel or implementation-specific attacks beyond standard noise/loss models.
- Experimental implementation limited to proof-of-principle; practical deployment requires scaling detector efficiencies and lowering losses in realistic channels.
- Min-entropy bounds used for d+1-basis protocols are not tight; key rate estimates may be conservative compared to achievable performance.
Open questions / follow-ons
- How to extend the security analysis to finite-size regimes and security against general coherent attacks using methods such as the entropy accumulation theorem?
- Development of loophole-free, detection-loophole resilient HD 1sDI-QKD implementations that experimentally close the fair-sampling assumption.
- Investigation of practical side-channel attacks on high-dimensional steering-based QKD and countermeasures.
- Optimization of multi-outcome HD measurement devices for higher efficiency and lower noise in real-world fiber or free-space channels.
Why it matters for bot defense
The results in this work offer valuable insights for bot-defense engineers looking to understand adversarial scenarios with partial device trust and asymmetric knowledge. The 1sDI model parallels practical security settings where one party may operate untrusted or low-cost devices subject to manipulation. The demonstrated robustness of high-dimensional protocols against noise and loss points to architectural benefits in designing interactive challenges or verification schemes that leverage richer, high-dimensional state spaces.
Although the domain is fundamentally quantum cryptography rather than classical CAPTCHA schemes, the techniques of leveraging asymmetry, multi-outcome measurement strategies, and careful modeling of partial trust could inspire analogous designs in bot-deterrence. The rigorous framework for closing detection loopholes and handling imperfect/noisy devices also parallels the challenges in deploying robust verification tests under adversarial conditions. Thus, engineers focused on bot defense or CAPTCHA design can view this work as an advanced conceptual and technical resource highlighting tradeoffs between device trust, dimension, noise tolerance, and achievable security guarantees.
Cite
@article{arxiv2607_08709,
title={ Robust One-Sided Device-Independent Quantum Key Distribution via High-Dimensional Steering },
author={ Monika Mothsara and Suraj Goel and Bohnishikha Ghosh and Vatshal Srivastav and Will McCutcheon and Mehul Malik and Gláucia Murta },
journal={arXiv preprint arXiv:2607.08709},
year={ 2026 },
url={https://arxiv.org/abs/2607.08709}
}