Continuous-Variable Quantum Key Distribution Robust Against Polarization-Dependent Loss

: Polarization is one of the physical characteristics of optical waves, and the polarization-division-multiplexing (PDM) scheme has gained much attraction thanks to its capability of achieving high transmission rate. In the PDM-based quantum key distribution (QKD), the key information could be encoded independently by the optical ﬁelds E x and E y , where the 2-dimensional modulation and orthogonal polarization multiplexing usually result in two-fold channel capacity. Unfortunately, the non-negligible polarization-dependent loss (PDL) caused by the crystal dichroism in optical devices may result in the signal distortion, leading to an imbalanced optical signal-to-noise ratio. Here, we present a polarization-pairwise coding (PPC) scheme for the PDM-based continuous-variable (CV) QKD systems to overcome the PDL problem. Numerical simulation results indicate that the PDL-induced performance degradation can be mitigated. In addition, the PPC scheme, tailored to be robust against a high level of PDL, offers a suitable solution to improve the performance of the PDM-based CVQKD in terms of the secret key rate and maximal transmission distance.


The PDM-Based CVQKD Scheme
We consider a discretely modulated CVQKD protocol since it is suitable for long-distance transmission [29]. In order to increase the transmission capacity, the PDM scheme can be applied in modulation. In Figure 1a, we show the schematic diagram in the PDM-based CVQKD system. At Alice's side, the light beam from laser is encoded and modulated, resulting in PDM signals. We will elaborate on this specific process after we put forward the coding scheme. A polarization beam splitter is used for splitting the signals into two polarizations, and the two polarizations are recombined by using a polarization beam combiner after modulation. At destination, Bob demultiplexes the incoming signals and measures one of them with homodyne detector. The transmission of two polarizations with PDL is shown in Figure 1b. There is a component projection on the corresponding channel, leading to the crosstalk between channels. The transmission of signals in optical fiber through a single beam is involved in the PDM-based CVQKD system, which can be described as follows: Step 1: Alice randomly picks up a random variable x k ∈ {1, 2, 3, 4} and encodes a coherent state |α k ∈ {|α 1 = | − r + ri , |α 2 = |r + ri , |α 3 = | − r − ri , |α 4 = |r − ri }, where r is a positive real number depending on Bob's signal-to-noise ratio (SNR) and k denotes the index of time slot-and sends it through a quantum channel with loss and noise interference. After perfect PDM, there will be two mutually delayed polarization signal lights from the same beam of light.
Step 2: Alice sends the prepared coherent states through a quantum channel to Bob. Bob receives quantum states from two polarizations separated by a PBS. Bob's detection process of quantum states on two channels is similar. Then, Bob randomly selects the measurement basis through the decoding system and measures the components. Through the classical authentication channel, the selected measurement basis is published. Alice and Bob will discard the wrong measurement basis.
Step 3: Bob identifies and extracts effective coherent state signals and derives the phase of the coherent state including serial information. He performs the demodulating and decoding operations, and finally establishes a shared key with Alice after the error correction and privacy amplification processing.

The PDL-Involved CVQKD System
The noise of CVQKD system can be divided into two kinds. One is the scattered noise caused by channel loss, which is incompressible. The other is the excess noise introduced by optical devices, electrical noise of circuits, etc., which can be compressed by improved designs as much as possible. In the PDM-based CVQKD system, several optical characteristics such as chromatic dispersion, polarization mode dispersion, and even nonlinear distortions would cause excess noise, but can be compensated for achieving high-tolerance [30,31]. However, it is difficult to realize the perfect compensation for PDL due to its nonunitary nature. We will analyze the source of PDL and the effect of PDL on the secret key rate in the PDM-based CVQKD system, and find a way to solve it.

Polarization-Dependent Loss in Communication
In most of birefringent crystals inside, the polarized light absorptions of two orthogonal polarizations are the same. Nevertheless, some of the crystals will have different absorbing ability due to their dichroism. Dichroism is a phenomenon associated with polarization states of input light, which is generated within a crystal. And then it produces the PDL that interfere with the system's performance. For the single-mode optical fiber containing SiO 2 , the effect of PDL is very weak. But in optical devices, such as multiplexers, splitters, etc., it should not be ignored since it may make optical signals undergo different losses in different polarization directions. PDL describes the maximum and minimum value of the transmission of light through a device or communication system, in the presence of polarization. It can be expressed as the ratio of power, i.e., 10 log(γ max /γ min (dB), in consequence, where γ is the optical power taken over by the entire polarization state. The output light power will vary between the maximum and minimum values due to the influence of different polarization states. Thus, PDL could be viewed as polarization selective fading. The impact on system performance is the increased signal distortion [21,32]. Figure 2a shows that PDL causes the destruction of orthogonality of the PDM-based system, where two polarizations lose their orthogonality after transmission with the different loss in their polarization direction. As the signal polarization is not limited to the optical fiber network, the insertion loss of the device varies with the polarization state. This effect increases uncontrollably along the transmission link and has an impact on transmission quality. PDL of individual devices can cause large power fluctuations in the system, thus raising the error rate and causing network failure. PDL may be the main source of pulse distortion and diffusion. The PDL-distributed model is shown in Figure 2b. There are some PDL emulators (PDLE), and the amplified spontaneous emission (ASE) noise depolarized by PDL is loaded, both of which are distributed along a link [33]. Usually, several polarization controllers are inserted before the PDLE to obtain the PDL penalty at a special polarization.

The Effect of PDL on Orthogonal Components
Due to the effect of PDL, an angle between two channels decreases with the increasing loss. Therefore, there is a component projection on the corresponding channel, eventually leading to the crosstalk between channels. Figure 3a reveals the effect on components of the electric field. The right panel shows the state of the electric field vectors before entering the component with PDL, while the left panel shows these vectors after propagating through the component with PDL.
When two polarizations enter the optical devices, a and b are the angles of the electric field with the corresponding outputs a and b . For τ ∈ {a, b} and τ ∈ {a , b }, we have [25] where 0 • ≤ a ≤ 90 • and 0 • ≤ b ≤ 90 • . The relative angle of two nonorthogonal polarizations is given by ϕ = |a − b |, which experiences a periodic variation dependent on a and b.
Let µ be the relative PDL factor between two polarizations and ζ is the incident angle, which is the angle between one of these channels and the X-axis, then, we have With the variable relative loss factor µ, the orthogonality between two originally orthogonal channels may be lost, where µ ∈ {0.1, 0.5, 1.0}. As shown in Figure 3b, for the decreased µ, the orthogonality becomes worse.

The PDL-Involved CVQKD System
The quantum state received at Bob's side can be denoted by the quadratures (X,P) which satisfy where X A and P A are the modulated values with variance X 2 A = P 2 A = V A , and δX A (δP A ) and δX c (δP c ) are originated from the shot noise and channel excess noise, which satisfy δX 2 A = δP 2 A = 1 and δX 2 c = δP 2 c = ε c in shot noise units, respectively. Here, we show the derivation of the excess noise due to the effect of PDL. Under the perfect detection, we denote the quadratures of the output mode of quantum channel as (X t , P t ). The quadratures without phase compensation can be expressed as where X dpl , P pdl are the added quadratures arising from the phase error φ due to lack of orthogonality, which satisfy X pdl = |α|sinφ and P pdl = |α|cosφ, and α is the parameter of coherent states. It can be regarded as a phase shift operation U(δφ) = exp(iδφa † a) on Bob's measurement results, and δφ follows a probability of p(δφ).

Polarization-Pairwise Coding Scheme
On account of the polarization states whose relative orientations are random and time dependent, the overall instantaneous PDL varies randomly, both in frequency and in time. As a result, it is a corresponding randomization of the received optical signal noise ratio (OSNR). In what follows, we propose a PPC scheme to mitigate the involved PDL, leading to the increased secret key rate of the PDM-based CVQKD system. As shown in Figure 4, The continuous light emitted by the light source is divided into two groups of light carriers with mutually orthogonal polarization through the polarization splitter. Then, the random code of quantum random number generator (QRNG) is modulated into the corresponding driving signal through the level generator and modulator driver. Two Stokes parameter encoders are the key to the realization of phase modulators in each polarization direction. Finally, the optical signals of these two groups of orthogonal polarization are synthesized into one group using PBC, so as to obtain the optical signals. As shown in Figure 5a, when interleaving the real (I) and imaginary (Q) components of both polarizations, only the I or Q of each polarization suffers the worse SNR. Whereas the other signal component has a better SNR, resulting in the improved performance of both polarizations. The PPC scheme is used for improving the CVQKD system without encoding processing in a wide range of worst cases of PDL. Modulator Driver  The polarization-pairwise pre-coding scheme is shown in Figure 5. Two polarizations are mapped to quadrature amplitude modulation (QAM) symbols X n = X 0 + P 0 j and Y n = X 1 + P 1 j, respectively. After a constant phase shift, θ, is applied to the related symbols, we obtain X θ,n and Y θ,n , respectively. The optimal rotation angle, θ opt , can be derived analytically for QPSK [26]: where λ = SNR defines the OSNR difference induced by PDL between two polarizations by SNR = OSNR good /OSNR bad , and this rotation angle is used for minimizing the error rate e ab for a given SNR between two polarizations. After the angular rotation, I/Q component interleaving is used for generating signals for two polarizations. The processing can also be described as where and denote the I and Q parts of signals, respectively. Figure 4a indicates the PPC-based CVQKD system with PDM-QPSK for the rotation angle θ opt = 45 • . The I/Q interleaving and angular rotation can be rewritten as We note that the above-derived transform matrix is orthogonal, and, hence, such a coding scheme will not involve extra sensitivity penalty in comparison to conventional QAM modulation without PDL. When the PDL is present, intuitively, after receiver I/Q deinterleaving, the SNR between two polarizations is converted into the SNR imbalance between the I and Q components of two polarizations. Then, the angular rotation can maximize the system performance and the optimal angle is 45 • , which is derived on the basis of the minimum-error-rate search. The trade-off for practical implementations has been considered in pertinent literature [26].
In this scheme, the total SNR is given by Appendix B and the average symbol power of QPSK modulation is 2. Then, the SNR between two polarizations is derived as SNR dB = |10 log 10 ( 1+γ 1−γ )|, where γ is the power factor with γ ∈ (−1, 1), as shown in Figure 6. Practically, SNR has a random distribution [34]. With the total PDL value L, the lowest and highest possible SNRs are 0 and L, corresponding to the best and worst PDLs, respectively. In the following, we focus on the effect of SNR on system performance. The performance improvement with SNR > 0 can be regarded as an increased tolerance of PDL.  Figure 6. Signal-to-noise ratio (SNR) difference between two polarizations due to PDL.
At the receiver, we implement the signal processing, which includes correction, clock recovery, channel compensation, and carrier recovery. The equalized pairwise symbols Eq x /Eq y are decoded, as shown in Figure 4b. More details are described in Appendix A.

Performance Analysis
The four-state protocol has higher data reconciliation efficiency, and thus can be used for lengthening the transmission distance of the CVQKD system [35,36]. Alice sends a random coherent state |α k =|α exp[i(2k + 1)/4] , ∀ k ∈ {0, 1, 2, 3}, to Bob, where α is a real number that can be optimized to maximize the security code rate. In what follows, we show the secure communication code rate of the four-state protocol.
In order to facilitate the security analysis, it is often used to consider the equivalent preparation-measurement scheme. Due to the nonideal modulation in the preparation-measurement scheme and the noise of the light source, the two-mode entangled state produced by Alice is not a pure coherent state, but a mixed state with mixed noise. Due to the symmetry, it is assumed that the mixed state has the same noise as the input of the X component and the P component. The noise will not be used by Eve and can be introduced as a neutral Charlie. Considering the existence of the neutral Charlie, the equivalent entanglement scheme of the case becomes the tripartite subsystems, involving Alice, Bob, and Charlie, which constitutes a pure entangled state.
Assuming the attacker is strong enough, we can replace the actual channel between Alice and Bob with a perfect channel and pure the state ρ ABC . So, the total system |ψ ABEC is a pure state. If Eve can use the state in Charlie s hand, she can get more information. Therefore, the lowest minimum of the security key rate can be obtained.
where β is the key extraction efficiency and I(a : b) is the mutual information between Alice and Bob. For the binary symmetric system, I(a : b) can be completely decided by the SNR of Bob [37] (more details in Appendix B): where h(p) = −p log 2 (p) − (1 − p) log 2 (1 − p) is the binary entropy function and Combining with the above-mentioned PPC scheme, we can obtain the decreased error rate, as shown in Figure 7, where the dashed line shows the transitional four-state protocol and the solid line indicates the PPC-based protocol. The error rate changes with SNR for SNR = 3 dB. It can be observed that the pairwise coded signals achieve a lower error rate to the same SNR extent. In Figure 8 I(a : b). Subsequently, the Holevo boundary χ b:EC is defined as Before Bob's measurement, the state |ψ ABEC is a pure state, resulting in S(ρ EC ) = S(ρ AB ). After Bob s measurement, the state ρ AEC collapses into the form of the |ψ b AEC , which is still a pure state. Therefore, we have S(ρ b EC ) = S(ρ b A ). In addition, because the value of S(ρ b A ) is independent of b, we can achieve  Consequently, the lowest minimum of the secret key rate can be calculated as

Tranditional protocol PDM-based protocol PDM-PPC-based protocol
Assume that the channel transmittance between Alice and Bob is T 0 and the excess noise is ε 0 . When Alice sends ρ B0 to Bob, it evolves to be ρ B , and the covariance matrix γ AB of the ρ AB is derived as where V M = 2α 2 is the modulation variance of Alice, I is the identity matrix, Z is the correlation function, source noise is δε, and σ z = diag(1, −1). The covariance matrix of the output of the state ρ AB after the phase shift operation U(δφ) is then derived as where Then, the state affected by the phase noise is a classical mixture of states with random phase shifts [7] ρ AB = (I A ⊗ U B (δφ))ρ AB (I A ⊗ U B (δφ))p(δφ)dδφ, (17) which corresponds to the covariance matrix where we assumed that the distribution δφ is symmetric. More specifically, δφ satisfies p(δφ)sinδφdδφ = 0 and k = ( p(δφ)cosδφdδφ) 2 = (E[cosδφ]) 2 , where E[X] denotes the expectation of the random variable X. Therefore, the equivalent transmittance T k 0 and the excess noise ε k 0 of quantum channel after PPC scheme can be expressed as Subsequently, the excess noise ε pdl due to lack of orthogonality is given by According to the optimality of Gaussian attacks, when the covariance matrix is equal, ρ AB is the Gaussian state, leading to the minimum K. For the Gaussian modulation protocol, when the channel transmittance is T and the excess noise is ε, the mixed state covariance matrix of Alice and Bob is given by To make γ G AB = γ AB , we obtain Therefore, for the discrete modulation scheme with a modulation variance V M , source noise δε, channel transmittance T 0 , and excess noise ε 0 , the lowest minimum of the secret key rate can be obtained by the secret key rate of the Gaussian modulation scheme. The transmittance T and excess noise ε of the equivalent Gaussian modulation scheme are derived by (15). Combining with (6), the secret key rate can be obtained. And the main parameters of the CVQKD protocol in the security analysis are shown in Table 1.
In Figure 9, we demonstrate the secret key rate as a function of modulation variance V M or excess noise ε with transmission distance d = 100km, ∀ ε ∈ {0.003, 0.005, 0.008, 0, 01}. We can achieve the maximum secret key rate for V M = 0.35 in condition of the variational excess noise. In Figure 10, we show the secret key rate as a function of transmission distance, where the dotted line represents the original four-state protocol, the dashed line denotes the PDM-based scheme with discrete modulation, and the solid line is the PDM-based scheme of the four-state protocol with PPC. We find that the secret key rate of the multiplexing scheme is two times higher than that of the conventional four-state protocol. Using the PPC scheme, we can improve the performance of the PDM-based CVQKD system compared with the other schemes.

Conclusions
We have proposed a PDM-based CVQKD system over the optical fiber channel, where the key information could be encoded independently by the optical fields E x and E y . By applying the PDM scheme in the system, the 2-dimensional modulation and polarization multiplexing achieve two-fold channel capacity without the need of additional bandwidth resources. Nevertheless, the crosstalk induced by the PDL of each polarization causes the signal distortion, leading to an imbalanced optical signal-to-noise ratio for two polarizations. In order to mitigate the performance decrease, we adopt an improved PPC scheme to overcome the PDL problem. The theoretical analysis shows the performance of the scheme and demonstrates its availability in the system. By selecting the original information symbols and interleaving the X and P components between two polarizations of a given channel, the decoded signals of two polarizations can achieve a lower error rate. In addition, the numerical simulation results indicate that the required SNR is lower than that of the uncoded method when the same error level is reached in the PPC scheme. Besides, the proposed method enhances the overall system performance and is robust against a wide range of PDL without any coding overhead. It reduces the PDL-induced error rate, and thereby increases the secret key rate of the PDM-based CVQKD system.

Conflicts of Interest:
The authors declare no conflict of interest.

Appendix A. The Calculation of BER
First of all, the SNR estimation is applied to each polarization by using the statistical moments method [38]. In order to calculate, the total SNR is supposed to be 1/σ 2 and the average symbol power of QPSK modulation is 2. Subsequently, we rescale the equalized signals differently according to the SNR of two polarizations. Particularly, the SNR varies due to the statistical PDL, and therefore the SNR estimation and rescaling should be updated periodically. The I/Q components are then deinterleaved, and the yielded I/Q parts suffer different noise levels. Subsequently, we apply the maximum likelihood detection (MLD) method to symbol decision: where C k is the constellation alphabet, i.e., [1 + j1 − j − 1 + 1j − 1 − 1j] for QPSK modulation, and D k are the rotated and rescaled constellation points. The decisions are finally used for BER calculation. Then, the BER of optical pairwise-coded signals can be written as Compared with the unpaired coding scheme, the average BER can be approximated to In Figure A1, we demonstrate the single-channel OSNR versus. SNR for the rotation angle 45 • , where interleaving and deinterleaving the I/Q components are performed at the transmitter and receiver, respectively. With the increased SNR between two polarizations, the PPC scheme increases the performance of the system in terms of BER compared with the unpaired signals. For SNR = 0, there is no penalty, and the performance is the same as that of unpaired signals. Whereas for SNR = 3/6/9 dB, we find the pairwise coded signals require the lower SNR to achieve BER to the same extent.

Appendix B. The Calculation of SNR
In order to obtain e ab , we have to calculate the practical SNR of Bob, and the final result is combined with Appendix A. When the quantum channel is introduced with some excess thermal noise, Bob's noise is actually made up of three different parts. The first part is the vacuum noise V S , whose variance is always 1 4 . The second part is the electronic noise, whose variance is V el . The third part is the thermal noise. The variance of the thermal noise depends on τ, which is the squeezing factor of Eve's EPR source, and η, which is the quantum efficiency of the channel. The signal-to-noise ratio then reads [37] where u i = { √ ηη m α i } is Bob's average value of S quadrature when Alice sent α i . η m is the detection efficiency of the homodyne detector. When we get the analytical expression for the secret key rate between Alice and Bob for the case where there is no excess noise, we have Now, we consider the excess noise. Let the average thermal photon number be n th . We have Then, Bob's noise variance reads Combing Equation (A7) with Equation (A4), we can get the expression for signal-to-noise ratio for the case with excess noise, which is