Next Article in Journal
Existence and Blow-Up of Compressible Spherically Symmetric Euler Equations with Vacuum Free Boundary
Previous Article in Journal
Bayesian Estimation for α-Mixture Survival Models
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

High-Efficiency Lightweight Quantum Key Agreement Scheme Based on Bell State Entanglement

1
School of Cyber Science and Engineering, Xizang Minzu University, Xianyang 712082, China
2
Key Laboratory of Optical Information Processing and Visualization Technology of Xizang Autonomous Region, Xianyang 712082, China
3
School of Cyber Science and Engineering, Southeast University, Nanjing 211189, China
*
Author to whom correspondence should be addressed.
Mathematics 2026, 14(10), 1774; https://doi.org/10.3390/math14101774
Submission received: 28 April 2026 / Revised: 17 May 2026 / Accepted: 19 May 2026 / Published: 21 May 2026

Abstract

To address the low qubit efficiency and high user-side operational complexity in existing quantum key agreement schemes, this paper proposes a high-efficiency and lightweight quantum key agreement scheme based on Bell states. The scheme is constructed upon a time-reversed EPR architecture, in which a quantum server performs entangled-state preparation and Bell state measurement. Furthermore, a bidirectional decoy photon mechanism is incorporated into the architecture to achieve eavesdropping detection. By exploiting the completeness and orthogonality of the Bell basis, the scheme introduces an encoding mechanism based on local Pauli operations, enabling a single Bell state to carry 2 bits of key information and thereby realizing dense coding, which improves qubit efficiency. Meanwhile, users are only required to perform single-qubit operations, which reduces the quantum operational requirements on the user side. Based on the properties of Bell states, this paper derives the mapping relationship between local Pauli operations and Bell state measurement outcomes. Experimental results on the SpinQ Gemini quantum computing platform are consistent with the theoretical analysis, verifying the feasibility of the proposed scheme. In addition, security analysis shows that, owing to the bidirectional decoy photon mechanism, the scheme can resist various quantum attacks. The proposed scheme combines high efficiency with a lightweight implementation, reducing quantum hardware requirements on the user side and network deployment costs, thereby providing a cost-effective solution for practical quantum key agreement.

1. Introduction

In modern cryptographic systems, the key is the core element of secure communication, and its confidentiality directly determines the security of the entire system. According to Kerckhoffs’ principle [1,2], the security of a cryptosystem should rely on the secrecy of the key rather than the algorithm itself. However, with the development of quantum computing, classical cryptographic schemes based on mathematical hardness assumptions are facing fundamental challenges. Grover’s algorithm [3] poses an accelerated threat to symmetric cryptography, while Shor’s algorithm [4] can solve integer factorization and discrete logarithm problems in polynomial time, thereby undermining the security foundation of mainstream public-key cryptosystems. Recent studies further indicate that approximately 10 4 reconfigurable atomic qubits are sufficient to support the execution of Shor’s algorithm at a cryptographically relevant scale [5], thereby accelerating the transition of this theoretical threat toward practical relevance. These advances suggest that traditional cryptosystems relying on assumptions about computational complexity are unlikely to provide long-term security in a quantum computing environment. In contrast, quantum cryptography, grounded in the fundamental principles of quantum mechanics, offers a new approach to addressing this security challenge [6]. On the one hand, the quantum no-cloning theorem [7] ensures information-theoretic security in key distribution, as any eavesdropping attempt inevitably introduces detectable disturbances. On the other hand, the nonlocal properties of quantum entanglement [8,9] enable a new paradigm for secure communication, allowing communicating parties to establish strongly correlated keys without pre-shared secrets.
Since Bennett and Brassard proposed the first quantum key distribution (QKD) protocol, BB84 [10], in 1984, quantum cryptography has developed rapidly and given rise to various secure communication models, including quantum secret sharing (QSS) [11], quantum secure direct communication (QSDC) [12] and quantum key agreement (QKA) [13]. Subsequently, driven by theories of quantum entanglement and non-local correlations, a framework for entanglement-based QKA schemes gradually emerged. QKA represents a significant extension of QKD, emphasizing that both communication parties jointly generate a shared key on the basis of equal participation [13], thereby making the key generation process more interactive. Despite these theoretical advantages, existing QKA schemes still face dual limitations in practical applications, namely efficiency and user-side implementation complexity.
Existing QKA schemes still have room for improvement in terms of efficiency, which is mainly reflected in two aspects. First, with respect to qubit efficiency, in most schemes [14,15,16] each quantum carrier can typically convey only one bit of effective key information, resulting in limited qubit efficiency. Second, in terms of quantum resource utilization, many schemes [14,17,18] require sacrificing a certain proportion of entangled resources or increasing transmission rounds to perform eavesdropping detection, resulting in a relatively low proportion of quantum resources being used for actual key generation.
The implementation complexity at the user side is also a key factor restricting the practical deployment of QKA schemes. Most existing schemes [15,16,18] assume that users possess relatively complete quantum operation capabilities, such as entangled-state preparation, Bell state measurement (BSM), and multi-qubit gate operations. These operations impose high requirements on device stability, coherence time, and control precision, significantly increasing system cost and engineering complexity. It is also worth noting that, with recent experimental advances, including high-fidelity collinear transmission over 30 km commercial optical fiber achieved by Northwestern University in 2024 [19], as well as the classical-decision-based quantum internet architecture proposed and implemented by Chinese research teams [20], future quantum networks are showing a structural trend of centralized quantum nodes and lightweight user terminals, where complex quantum operations are concentrated at high-stability core nodes, while end users only need to perform limited and relatively simple single-qubit operations.
Based on the above background, this paper proposes a high-efficiency and lightweight QKA scheme based on Bell state entanglement. The main contributions of this paper are as follows:
1.
By fully exploiting the completeness and orthogonality of Bell states, an encoding mechanism based on local Pauli operations is designed, enabling a single Bell state to carry 2 bits of effective key information and realizing dense coding, thereby significantly improving qubit efficiency and quantum resource utilization.
2.
Inspired by the basic idea of semi-quantum cryptography [21], a quantum server (QS) is introduced to decouple complex quantum operations from the user side. Legitimate users, Alice and Bob, are only required to perform basic single-qubit operations such as Pauli operations, which significantly reduces the quantum capability requirements on the user side and enhances the practical deployment potential of the scheme.
3.
Based on the completeness and orthogonality of Bell states, the evolution of Bell states as well as the mapping relationship between local Pauli operations and BSM outcomes are derived. Meanwhile, a bidirectional decoy photon mechanism is introduced for eavesdropping detection, and a complete information-isolation mechanism is designed. Security analysis shows that the proposed scheme can resist a series of typical quantum attacks, including intercept-resend attacks and entanglement attacks. In addition, experimental results on the SpinQ Gemini quantum computing platform are consistent with the theoretical analysis, verifying the feasibility of the proposed scheme.
The remainder of this paper is organized as follows. Section 2 reviews the development of quantum cryptography and QKA; Section 3 presents the implementation of the proposed QKA scheme; Section 4 analyzes its correctness, security, and efficiency, and provides comparisons with representative QKA schemes; Section 5 reports experimental results; and Section 6 concludes the paper and discusses future research directions.

2. Related Work

2.1. From Classical Key Agreement to Quantum Cryptography

In classical cryptography, the Diffie–Hellman (DH) protocol [22] and the Rivest–Shamir–Adleman (RSA) algorithm [23] provide the foundation for public-key key agreement and transmission, enabling two parties to establish secure communication without pre-shared secrets. However, with the development of quantum computing theory, results such as Shor’s algorithm [4] and Grover’s algorithm [3] have demonstrated that classical cryptographic schemes based on computational hardness assumptions are no longer secure under the quantum computing model. In contrast, quantum cryptography does not rely on computational complexity assumptions; instead, it derives security directly from the fundamental laws of quantum mechanics, thereby providing information-theoretic security and offering a new paradigm for constructing long-term secure key systems.
QKD is one of the earliest and most extensively studied branches of quantum cryptography. Since the introduction of the BB84 protocol [10] based on single photons in 1984, several improved schemes have been proposed, including decoy-state BB84 [24] and the six-state protocol [25,26], aiming to enhance security and practicality under realistic channel conditions. Subsequently, in 1991, Ekert proposed the E91 protocol [17] based on quantum entanglement, which to some extent overcomes the asymmetry inherent in prepare-and-measure (P&M) frameworks, reduces the reliance on a single trusted sender, and provides a basis for extensions to networked scenarios. Later, Biham proposed the time-reversed EPR scheme [27], in which a central node performs Bell state projection or joint measurements on quantum states transmitted from different users. By establishing quantum correlations among users within a measurement-driven framework, the scheme further provided a new topological approach for the construction of quantum cryptographic networks.

2.2. Development and Challenges of Quantum Key Agreement

Although QKD enables information-theoretically secure key distribution, the generated key is typically dominated by a single party, and the two communicating parties do not have symmetric control over the key. In application scenarios such as multiparty collaborative computation and decentralized networks, this asymmetry may lead to issues related to fairness and controllability. To address this limitation, QKA [13], as a cryptographic primitive distinct from QKD, has attracted increasing attention since its introduction. QKA requires that all legitimate participants contribute to the final shared key, and that no single party can independently determine or predict the key outcome [13].
Existing QKA schemes can be broadly classified into three categories according to the type of quantum resources employed. Schemes based on single-particle states [28,29] are relatively simple in structure; however, they typically require multiple rounds of quantum communication, and the amount of effective key information carried by each quantum state is limited, thereby restricting overall efficiency. Schemes based on multipartite entangled states (e.g., GHZ states) [15] exhibit favorable symmetry and consistency in theory, but impose stringent requirements on the preparation, distribution, and preservation of multipartite entanglement, leading to increased implementation complexity and experimental difficulty. In contrast, Bell-state-based QKA schemes [14,16,18] achieve a relative balance among communication rounds, efficiency, and implementation complexity, and have therefore become one of the main directions in current research.
Nevertheless, existing Bell-state-based QKA schemes still face several limitations in practical applications. First, due to limited encoding efficiency, a single Bell state can typically carry only 1 bit of effective key information. In addition, part of the entangled resources must be allocated to the eavesdropping detection process, thereby reducing both qubit efficiency and quantum resource utilization. Second, most schemes require end users to perform BSM or other multi-qubit operations, imposing relatively high demands on the capabilities of user-side quantum devices.

3. Proposed QKA Scheme

3.1. Preliminaries

This subsection briefly reviews the fundamental concepts of quantum mechanics relevant to the proposed scheme, providing the necessary mathematical descriptions for the subsequent design and analysis.
The two-qubit Bell states (EPR pairs) are defined as follows:
| Φ + A B = 1 2 ( | 00 + | 11 ) A B , | Φ A B = 1 2 ( | 00 | 11 ) A B , | Ψ + A B = 1 2 ( | 01 + | 10 ) A B , | Ψ A B = 1 2 ( | 01 | 10 ) A B .
The four unitary Pauli operations used for encoding are described as follows:
U 00 = 1 0 0 1 , U 01 = 0 1 1 0 , U 10 = 1 0 0 1 , U 11 = 0 1 1 0 .
When local unitary operations U i are performed on each of the two particles of the initial state | Φ + A B , the resulting BSM outcomes are summarized in Table 1.

3.2. Participants and Adversary Model

To facilitate an accurate description of the execution procedure and a rigorous security analysis, this subsection first specifies the roles of the entities involved in the proposed scheme, and then establishes the corresponding adversary model [30,31] and security assumptions.
The communication framework of the proposed scheme consists of the following three types of entities:
  • QS: Responsible for preparing and distributing maximally entangled Bell state pairs; generating and inserting decoy photons (with preparation bases randomly chosen from the Z- and X-bases); performing eavesdropping detection; conducting BSM on the returned quantum states; and publicly announcing the BSM outcomes.
  • Legitimate users Alice and Bob: Act as symmetric participants in the communication process; perform eavesdropping detection; apply local Pauli operations to the received quantum states; prepare and insert decoy photons (with preparation bases randomly chosen from the Z- and X-bases); return the updated quantum sequence to the QS; and complete the key agreement process by combining their local operations with the measurement results announced by the QS.
  • Eavesdropper Eve: Does not participate in the schemes execution but is assumed to possess full quantum capabilities. Eve may perform passive eavesdropping or active attacks on both the quantum and classical channels, attempting to recover the shared key by acquiring or inferring intermediate information.
The proposed scheme adopts a semi-trusted QS adversary model. Specifically, the QS is assumed to be honest-but-curious, meaning that it follows the prescribed scheme steps without deviation, does not interrupt the key agreement process, and does not collude with the external eavesdropper Eve. However, it may attempt to infer partial information about the shared key from the data available to it. Eve is regarded as an active attacker, and the corresponding attack strategies or attack models considered in this paper will be further specified in the relevant subsections. To resist the above potential threats, a bidirectional decoy photon mechanism is introduced for eavesdropping detection, and the security of the quantum channel is evaluated by calculating the quantum bit error rate ( Q BER ).
In addition, it is assumed that all classical information exchanged during the scheme (including quantum state receipt acknowledgments, the positions and preparation bases of decoy photons, and the announcement of BSM outcomes) is transmitted over an authenticated public channel. This effectively prevents man-in-the-middle attacks, message forgery, and tampering.

3.3. High-Efficiency Lightweight Quantum Key Agreement Scheme Based on Bell State Entanglement

Under the aforementioned adversary model and security assumptions, the specific execution flow of the proposed QKA scheme is outlined as follows:
Step 1
QS distributes quantum pairs: The QS prepares n pairs of maximally entangled Bell states | Φ + A B n . The first qubits of each Bell state form an ordered sequence S A , while the second qubits form sequence S B . Subsequently, the QS randomly inserts decoy photons (with preparation bases randomly chosen from the Z- and X-bases) into both sequences, and transmits S A to Alice and S B to Bob through quantum channels.
Step 2
First eavesdropping detection: Upon receiving the sequences, Alice and Bob send arrival acknowledgments to the QS via a classical broadcast channel. The QS then publicly announces the positions and preparation bases of the decoy photons. Alice and Bob measure the corresponding qubits using the announced bases and compare the outcomes with the initial states. Q BER is then evaluated. If Q BER is below a predefined threshold determined by channel noise characteristics [32], the key agreement proceeds; otherwise, it is aborted immediately.
Step 3
User operations: Alice and Bob discard all decoy photons. Alice randomly selects n unitary operations U i ( i { 00 , 01 , 10 , 11 } ) to apply to the remaining particles in S A , records her choices, and generates a new sequence S A . Similarly, Bob independently and randomly selects n operations U j to process S B , obtaining sequence S B . Alice and Bob then independently insert new decoy photons (with preparation bases randomly chosen from the Z- and X-bases) into their respective sequences S A and S B at random positions and send them back to the QS.
Step 4
Second eavesdropping detection: Similar to the first eavesdropping detection process, QS performs a second eavesdropping detection based on the respective decoy photon positions and preparation bases published by the users. If the detection passes, the key agreement continues; otherwise, it terminates immediately.
Step 5
BSM: The QS discards the decoy photons and performs BSM on the particles at corresponding positions in S A and S B , then records the measurement results as an ordered sequence R, and announces them via the broadcast channel, as shown in Table 1, R = { r i } i = 1 n ( r i { | Φ + , | Φ , | Ψ + , | Ψ } ).
Step 6
Key extraction and recovery: According to the encoding rules outlined in Table 2, each Pauli operation corresponds to a 2-bit initial key. Alice and Bob derive their respective initial keys K A = { a 1 , a 2 , , a 2 n } and K B = { b 1 , b 2 , , b 2 n } based on the Pauli operations recorded in Step 3. Subsequently, based on the BSM results r i broadcast by the QS, Alice or Bob corrects the i-th group of bits in K A or K B as follows:
  • If r i = | Φ + , Alice and Bob perform no operation;
  • If r i = | Φ , Bob performs no operation, and Alice flips the first bit of this group: a 2 i 1 = a 2 i 1 ¯ ;
  • If r i = | Ψ + , Alice performs no operation, and Bob flips the second bit of this group: b 2 i = b 2 i ¯ ;
  • If r i = | Ψ , Alice flips the first bit of this group: a 2 i 1 = a 2 i 1 ¯ ; simultaneously, Bob flips the second bit of this group: b 2 i = b 2 i ¯ .
After these corrections, K A = K B , meaning both parties successfully negotiate an identical 2 n -bit shared key K.

4. Analysis

4.1. Correctness Analysis

The main key agreement process of the proposed scheme is illustrated in Figure 1. After the first eavesdropping detection is successfully completed, Alice and Bob randomly select Pauli operations and apply them to the quantum sequences S A and S B , respectively, thereby generating the updated sequences S A and S B , while recording their corresponding operation choices. Subsequently, the QS performs BSM on S A and S B and publicly announces the measurement outcomes. All possible combinations of operations and their corresponding results are summarized in Table 1.
According to the encoding rule shown in Table 2, both parties then map each measurement outcome r i to their respective initial keys K A and K B . Finally, both parties correct the corresponding bits in K A and K B according to r i , such that K A = K B . In this way, Alice and Bob negotiate an identical shared key K.
Table 3 exhaustively enumerates the Bell state evolution results under all sixteen possible combinations of Pauli operations performed by Alice and Bob. It further presents the corresponding key mapping and correction procedures, thereby verifying the completeness of the encoding and correction processes in the proposed scheme.

4.2. Security Analysis

Under the adversary model and security assumptions described above, this section provides a rigorous security analysis of the proposed QKA scheme. The security of the scheme is grounded in the fundamental principles of quantum mechanics. By incorporating an information isolation mechanism and two rounds of eavesdropping detection, the scheme can effectively resist various potential attacks launched by both the honest-but-curious QS and an external eavesdropper Eve with full quantum capabilities. Under the established security assumptions, the analysis is carried out from multiple perspectives, including information leakage, external attacks, and potential threats related to the QS. This demonstrates that the proposed scheme remains secure within the defined adversary model.

4.2.1. Information Leakage Analysis

This subsection analyzes and evaluates the potential impact of publicly broadcast information over classical channels on the security of the shared key. It is assumed that the Pauli operations of Alice and Bob are chosen independently and with equal probability from the set P = { U 00 , U 01 , U 10 , U 11 } , and that all publicly broadcast information is transmitted through an authenticated channel. The security analysis is presented as follows:
In Step 5 of the proposed scheme, after performing the BSMs, the QS broadcasts the measurement results R = { r i } i = 1 n ( r i { | Φ + , | Φ , | Ψ + , | Ψ } ) to Alice and Bob. Let R denote the random variable representing the measurement results. Because the initial state is | Φ + and the Pauli operations applied by the users map this Bell state to the four Bell states with equal probability, the values of R are uniformly distributed, which can be expressed as
P ( R = r i ) = 1 4 , r i R .
Therefore, the prior entropy of the BSM results is given by
H ( R ) = k = 1 4 1 4 log 2 1 4 = 2 .
Suppose Eve or other malicious users acquire or eavesdrop on the BSM results through certain channels. Since these results are jointly determined by the combined operations of Alice and Bob, rather than being uniquely determined by a single party’s operation, the individual Pauli operations of Alice and Bob remain uniformly distributed under this condition:
P ( A = j R = r i ) = 1 4 , j P .
Consequently, the conditional entropies are
H ( A R ) = 2 , H ( B R ) = 2 .
The corresponding mutual information is calculated as follows:
I ( A ; R ) = H ( A ) H ( A R ) = 0 ,
I ( B ; R ) = H ( B ) H ( B R ) = 0 .
Because the final key K is the result of the joint mapping of both parties’ operations, it similarly holds that
I ( K ; R ) = 0 .
Therefore, the BSM results broadcast by the QS via the classical channel in Step 5 do not leak any information regarding the users’ local Pauli operations or the final key.

4.2.2. Quantum Attacks

Intercept-measure attack.
This type of attack represents a typical active eavesdropping strategy. In this analysis, Eve is assumed to adopt the standard intercept–measurement attack model, in which she independently and randomly chooses the Z basis or X basis to measure each intercepted particle, attempting to infer key information from the measurement outcomes. However, quantum measurement inevitably introduces disturbances to the quantum states, and such disturbances will be detected during the two rounds of eavesdropping detection, thereby causing the key agreement process to be aborted.
Specifically, since the positions and preparation bases of the decoy photons are randomly selected and kept secret during transmission, Eve cannot distinguish decoy photons from payload particles. Consequently, her measurement behavior increases the Q BER and can be detected by the eavesdropping detection mechanism. Furthermore, since the shared key is jointly determined by the local encoding operations of Alice and Bob, measurements performed by Eve on individual particles cannot reveal meaningful key information. Even if Eve attempts to intercept both particles at the same position, the measurement and subsequent loss of particles will reduce the number of received qubits, which can be directly detected through particle number consistency checking.
Therefore, the intercept–measure attack not only fails to provide useful information to Eve, but also leads to detectable discrepancies in Q BER and particle counts, enabling effective detection by the proposed scheme.
Intercept-resend attack.
The intercept–resend attack is an extension of the intercept–measure attack. In this scenario, Eve intercepts quantum states, performs measurements, and then prepares and resends new quantum states according to the measurement outcomes, attempting to conceal her eavesdropping behavior. To counter this attack, the proposed scheme employs a decoy photon mechanism, whose detection principle is similar to that used in the BB84 protocol [10]. Specifically, the sender randomly inserts decoy photons into the quantum sequence, with preparation bases randomly chosen from the Z- and X-bases. Each decoy photon is therefore randomly prepared in one of the four states { | 0 , | 1 , | + , | } . After the receiver confirms the receipt of the quantum sequence, the sender announces the positions and preparation bases of the decoy photons, and the receiver performs corresponding measurements to evaluate the Q BER .
In this security analysis, Eve is assumed to adopt the standard BB84-type intercept-resend attack model, in which Eve independently and randomly chooses either the Z basis or the X basis to measure each intercepted decoy photon, and then re-prepares the corresponding quantum state according to the measurement result before sending it to the legitimate receiver. Under this attack model, Eve chooses the correct measurement basis with probability 1 / 2 , in which case no error is introduced; Eve chooses the wrong measurement basis with probability 1 / 2 , and under the wrong basis, the probability that the receiver detects an error is 1 / 2 . Therefore, for a single decoy photon, the probability that Eve’s attack remains undetected is given by
P single - undetected = 1 1 2 × 1 2 = 3 4 .
For a sequence containing k decoy photons, the probability that Eve’s intercept-resend attack is completely detected is
P detected = 1 3 4 k .
As the number of decoy photons k increases, the probability that Eve’s attack remains undetected decreases exponentially and approaches zero. Considering practical device imperfections and channel noise, a reasonable Q BER threshold [32] is introduced in the proposed scheme to evaluate channel security during the two rounds of eavesdropping detection. Therefore, the proposed scheme can effectively resist this type of attack.
Entanglement Attack.
In this type of attack, Eve introduces an ancilla particle | e and performs a unitary operation U E to entangle the ancilla with the transmitted particle | φ i n . Through this interaction, Eve attempts to obtain information about the secret key without being detected. In the proposed scheme, the transmitted quantum states belong to { | 0 , | 1 , | + , | } .
The action of U E on the computational basis states can be described as follows:
U E ( | 0 | e ) = ϵ 00 | 0 | e 00 + ϵ 01 | 1 | e 01 ,
U E ( | 1 | e ) = ϵ 10 | 0 | e 10 + ϵ 11 | 1 | e 11 .
For the X-basis states | + and | , the corresponding linear transformations are:
U E ( | + | e ) = 1 2 ϵ 00 | 0 | e 00 + ϵ 01 | 1 | e 01 + ϵ 10 | 0 | e 10 + ϵ 11 | 1 | e 11 ,
U E ( | | e ) = 1 2 ϵ 00 | 0 | e 00 + ϵ 01 | 1 | e 01 ϵ 10 | 0 | e 10 ϵ 11 | 1 | e 11 .
Here, | e i , j ( i , j { 0 , 1 } ) denotes the normalized pure state of the ancillary particle after interaction, satisfying:
e i , j | e i , j = 1 .
Meanwhile, according to the unitarity condition U E U E = I , we have:
| ϵ 00 | 2 + | ϵ 01 | 2 = 1 , | ϵ 10 | 2 + | ϵ 11 | 2 = 1 .
Therefore, if Eve attempts to measure the ancillary particle without introducing any disturbance, the final state of the composite system must remain a product state. It can then be strictly derived that
| ϵ 00 | 2 = | ϵ 11 | 2 , | ϵ 10 | 2 = | ϵ 01 | 2 .
At this point, the state of the ancillary particle becomes completely independent of the signal state, implying that Eve cannot obtain any useful information. This demonstrates that the proposed scheme is resistant to entanglement attacks.

4.2.3. Security Analysis Against the QS

In the adversary model of the proposed scheme, the QS is assumed to be an honest-but-curious entity. That is, it strictly executes the scheme procedures and does not collude with external eavesdroppers or any user, but it may attempt to infer the shared key using the information available to it.
During the scheme execution, the QS is responsible for the preparation and distribution of Bell states, as well as performing BSMs. It directly obtains the measurement results R = { r i } i = 1 n ( r i { | Φ + , | Φ , | Ψ + , | Ψ } ). Therefore, compared to external eavesdroppers, the QS can directly acquire all measurement results R, gaining an advantage through the complete observation of this random variable. However, similar to the analysis in Section 4.2.1, the QS cannot derive the specific types of Pauli operations applied by the users or the key information from the BSM results. Specifically, the BSM results R are uniformly distributed; thus, the prior entropy of the QS is given by
H ( R ) = k = 1 4 1 4 log 2 1 4 = 2 .
Even under the condition that the QS knows the measurement results R, the individual Pauli operations of Alice and Bob remain uniformly distributed from the perspective of the QS. Therefore, the conditional entropies satisfy
H ( A R ) = 2 , H ( B R ) = 2 .
The corresponding mutual information is calculated as follows:
I ( A ; R ) = H ( A ) H ( A R ) = 0 ,
I ( B ; R ) = H ( B ) H ( B R ) = 0 .
Because the final key K is the result of the joint mapping of both parties’ operations, it similarly holds that
I ( K ; R ) = 0 .
This theoretically proves that the QS cannot derive the users’ specific types of Pauli operations or the final key information from the BSM results. Furthermore, even in practical non-ideal systems, if the QS somehow obtains a very small fraction of the sifted key bits, subsequent classical post-processing steps, such as information reconciliation and privacy amplification, can effectively eliminate this potential security threat.

4.3. Efficiency Analysis and Comparison

To objectively evaluate the performance advantages of the proposed scheme, this section first derives its theoretical efficiency and then presents a multidimensional comparison with several representative QKD and QKA schemes.
The qubit efficiency proposed by Adán Cabello is one of the most widely used metrics for evaluating the performance of quantum key agreement schemes. It is defined as follows [33]:
η = b s q t + b t ,
where b s denotes the number of final key bits that are successfully generated and proven secure, q t represents the number of quantum resources consumed during the execution of the scheme (measured in qubits or entangled pairs), and b t denotes the number of classical bits exchanged for key mapping or decoding. Classical communication used for eavesdropping detection is typically not included in this term.

4.3.1. Efficiency of the Proposed Scheme

In the proposed scheme, the QS distributes n pairs of Bell states to the users, from which 2 n key bits are generated. During the key extraction phase, the QS broadcasts n groups of BSM results. Since each measurement outcome corresponds to one of four possible Bell states, each result conveys 2 classical bits. Therefore, the total classical communication overhead required for key decoding is 2 n bits. Accordingly,
b s = 2 n , q t = n , b t = 2 n .
Under these parameter settings, the performance of the proposed scheme can be analyzed as follows.
(1) Qubit efficiency. Substituting the above parameters into the efficiency formula yields
η = b s q t + b t = 2 n n + 2 n = 2 3 66.7 % .
Although the key extraction process introduces the necessary classical communication overhead for broadcasting RSM results, the efficiency remains significantly higher than that of comparable entanglement-based QKA schemes due to the adopted encoding mechanism.
(2) Channel capacity. By exploiting the nonlocal correlations of Bell states, the proposed scheme enables each Bell pair to carry 2 classical bits through four random local Pauli operations. Therefore, the channel capacity reaches 2 bits per Bell state. From a physical perspective, this is equivalent to surpassing the single-qubit transmission bound described by the Holevo bound [34], thereby realizing quantum dense coding.
(3) Quantum resource utilization. Unlike the BB84 protocol [10], in which quantum resources are partially discarded due to basis mismatches, all transmitted Bell states in the proposed scheme—except for those used as decoy photons for channel security verification—directly contribute to valid key generation. Consequently, the qubit utilization rate reaches 100%.
In summary, by introducing a superdense coding mechanism, the proposed scheme enhances the information capacity and utilization of each quantum resource under strict security guarantees, thereby improving the overall efficiency of the scheme.

4.3.2. Comprehensive Comparison with Other Schemes

To further evaluate the performance advantages of the proposed scheme, we compare it with several representative QKD schemes, including the BB84 protocol [10] and the E91 protocol [17], as well as several recently proposed QKA schemes. The comparison results are summarized in Table 4. The comparison dimensions include the type of quantum resources, the required quantum capabilities of users, the utilization efficiency of quantum resources, and the qubit efficiency.
To ensure comparability among different schemes under a unified information-theoretic framework, the efficiency metrics listed in Table 4 are recalculated according to the aforementioned definition. In this calculation, one Bell pair or one GHZ state is regarded as a single quantum resource unit, and the consumption of decoy photons used solely for eavesdropping detection is not included. This evaluation method highlights the influence of scheme structure on key generation efficiency; therefore, some values may differ from those presented in the original references.
The BB84 protocol [10] and E91 protocol [17] are representative QKD schemes, whose objective is secure key distribution rather than fair key agreement. As a result, their qubit efficiency and quantum resource utilization are constrained by the random selection and matching probability of measurement bases. In contrast, most existing QKA schemes exploit entanglement correlations to generate shared keys; however, the amount of information carried by each quantum resource is limited, leaving room for improvement in overall efficiency. In the proposed scheme, dense encoding is achieved by applying local Pauli operations on Bell states, enabling each entangled pair to carry 2 bits of information. Under a unified efficiency metric, the scheme attains a qubit efficiency of approximately 66.7 % and a quantum resource utilization of 100 % , outperforming the related schemes in [14,15,18].
Compared with schemes based on multipartite entangled states (e.g., GHZ states) [15], the proposed scheme employs Bell states as the quantum carrier, leading to improved feasibility in state preparation and manipulation. Moreover, by delegating Bell state preparation and BSM to the QS, the user side is only required to perform single-qubit operations, thereby reducing implementation requirements and enabling a lightweight design. It should be noted that, while the introduction of the QS simplifies user-side operations, it increases the complexity on the server side and relies on a semi-trusted third-party assumption.
Overall, the proposed scheme achieves a balanced trade-off among qubit efficiency, quantum resource utilization, and implementation complexity.

5. Experiments

5.1. Experimental Environment

In this study, the Gemini nuclear magnetic resonance (NMR) quantum computing experimental system developed by SpinQ is employed as the experimental verification platform. The Gemini system is based on the principles of NMR quantum computing and provides stable radio-frequency control and high system reproducibility, enabling the execution of real quantum computing experiments. The system contains two qubits and features high gate fidelity (two-qubit gate fidelity > 99 % ) and long coherence times (average T 1 = 10 s and average T 2 = 1.2 s).
Based on the SpinQit programming framework, the key quantum operations and measurement procedures involved in the proposed quantum key agreement scheme are implemented on this experimental system. The experimentally measured quantum relaxation time is approximately T 1 6 s, indicating that the influence of quantum decoherence on the execution of the scheme remains controllable within the experimental time scale. These results effectively demonstrate the feasibility and practical performance of the proposed scheme on real quantum hardware.

5.2. Experimental Results and Analysis

We designed and conducted a series of systematic experiments to verify the feasibility and correctness of the proposed scheme under realistic physical conditions. To illustrate the performance of the scheme under different user operation patterns, two representative cases are analyzed in detail: one in which both parties apply identical operations, and another in which they apply different operations. The corresponding experimental configurations, BSM outcomes, and key agreement processes are summarized in Table 5.
Case 1.
In this experiment, both Alice and Bob apply the operation U 01 , and the BSM outcome is | Φ + . To evaluate the correctness of the proposed scheme, the Bell state | Φ + is prepared and measured in the single-qubit Z-basis, and the fidelity is used as the evaluation metric. Figure 2a illustrates the complete quantum circuit, including state initialization, entanglement preparation, and user encoding. Figure 2b presents the experimentally obtained probability distribution, where the probabilities of | 00 and | 11 are 0.459 and 0.448 , respectively, while small non-ideal components | 01 and | 10 appear with probabilities 0.042 and 0.051 . Figure 2c shows the theoretical density matrix of | Φ + , whose nonzero elements correspond strictly to the | 00 and | 11 components.
The measured fidelity between the experimental state and the ideal | Φ + state is 0.907 , which is slightly lower than the theoretical value of 1. This deviation is mainly attributed to non-ideal factors in the experimental system, including quantum gate imperfections, limited photon detection efficiency, and decoherence effects in the quantum channel. Nevertheless, the | 00 and | 11 components remain dominant in the experimental data, and the probabilities of the error terms are below 5 % , indicating good agreement with the theoretical predictions.
Case 2.
In this experiment, Alice applies the operation U 00 while Bob applies U 11 , and the BSM outcome is | Ψ . To evaluate the effectiveness of the proposed scheme under asymmetric user operations, the Bell state | Ψ is prepared and measured in the single-qubit Z-basis, and the fidelity is used as the evaluation metric. Figure 3a illustrates the corresponding quantum circuit, including state initialization, entanglement preparation, and the distinct encoding operations performed by the two users. Figure 3b shows the experimentally obtained probability distribution, where the probabilities of | 01 and | 10 are 0.458 and 0.466 , respectively, while small non-ideal components | 00 and | 11 appear with probabilities 0.041 and 0.035 . Figure 3c presents the theoretical density matrix of the corresponding ideal state, whose nonzero elements are concentrated on the | 01 and | 10 components.
The measured fidelity between the experimental state and the ideal | Ψ state is 0.924 , which is slightly lower than the theoretical value of 1. This deviation is mainly attributed to additional phase disturbances introduced by the asymmetric encoding operations, as well as non-ideal factors in the experimental system, including quantum gate control errors and limited photon detection efficiency. Notably, despite the difference in user operations, the | 01 and | 10 components remain dominant, and the probabilities of the error terms are below 5 % , indicating good agreement with theoretical expectations.
The analysis of the above two cases shows that the experimental results are consistent with the theoretical predictions. The observed deviations are mainly caused by experimental noise rather than theoretical limitations. In particular, even under asymmetric user operations, the system maintains a relatively high entanglement fidelity, thereby validating the feasibility and correctness of the proposed scheme under realistic physical conditions.

6. Conclusions

This paper proposes a high-efficiency and lightweight QKA scheme based on Bell state entanglement. The scheme reduces the quantum resources and communication rounds required for effective key generation, while also lowering the quantum operational requirements on the user side, making it more suitable for a quantum network architecture consisting of centralized quantum nodes and lightweight user terminals. Within this framework, the proposed scheme holds potential value across a variety of practical application scenarios. In metropolitan quantum communication networks and quantum IoT systems, which are currently in their early stages of development, user-side quantum capabilities are limited, whereas core nodes possess strong quantum processing capabilities. This scheme ensures negotiation efficiency while requiring users to perform only simple single-qubit operations, facilitating large-scale, low-cost access. Furthermore, in quantum-classical hybrid communication environments, this scheme can serve as a key agreement module, integrated with classical cryptographic systems to enhance the overall security and scalability of the system.
Future work will be carried out in several directions. First, under more realistic high-noise quantum channel conditions, the effects of entanglement decoherence and operational errors on the correctness and efficiency of the proposed scheme will be systematically analyzed, and corresponding performance evaluation models will be established. On this basis, the scheme will be further extended to multiparty communication scenarios by incorporating GHZ states to construct a multiparty quantum key agreement mechanism, while analyzing the resulting changes in communication complexity and fairness. Finally, considering the current scheme’s reliance on a semi-trusted QS, future research will further investigate how to resist potential attacks from malicious QS, such as preparing incorrect quantum states, retaining ancillary entangled systems, or forging BSM results. In addition, measurement-device-independent (MDI) architectures will be explored for integration into the proposed scheme, thereby gradually reducing the trust dependence on centralized quantum nodes and further enhancing the security of the scheme.

Author Contributions

Conceptualization, C.Z. and Y.J.; validation, Y.L.; data curation, S.Z.; writing—original draft preparation, C.Z. and Y.L.; writing—review and editing, Y.J. and Y.L.; supervision, Y.J.; project administration, Y.J.; funding acquisition, Y.J. All authors have read and agreed to the published version of the manuscript.

Funding

This research was funded by the Science and Technology Projects of Xizang Autonomous Region (Grant No. XZ202501ZY0094), the Natural Science Foundation of Xizang (Grant No. XZ202401ZR0030), the Natural Science Foundation of Xizang Minzu University (Grant No. 25MDY22), and the Postgraduate Research Innovation and Practice Project of Xizang Minzu University (Grant No. Y2026127).

Institutional Review Board Statement

Not applicable.

Informed Consent Statement

Not applicable.

Data Availability Statement

The original contributions presented in this study are included in the article. Further inquiries can be directed to the corresponding author.

Conflicts of Interest

The authors declare no conflicts of interest.

References

  1. Kerckhoffs, A. La Cryptographie Militaire. J. Des. Sci. Mil. 1883, IX, 5–38. [Google Scholar]
  2. Shannon, C.E. Communication Theory of Secrecy Systems. Bell Syst. Tech. J. 1949, 28, 656–715. [Google Scholar] [CrossRef]
  3. Grover, L.K. A fast quantum mechanical algorithm for database search. In Proceedings of the 28th Annual ACM Symposium on Theory of Computing (STOC’96), Philadelphia, PA, USA, 22–24 May 1996; pp. 212–219. [Google Scholar]
  4. Shor, P.W. Algorithms for quantum computation: Discrete logarithms and factoring. In Proceedings of the 35th Annual Symposium on Foundations of Computer Science, Santa Fe, NM, USA, 20–22 November 1994; pp. 124–134. [Google Scholar]
  5. Cain, M.; Xu, Q.; King, R.; Picard, L.R.B.; Levine, H.; Endres, M.; Preskill, J.; Huang, H.Y.; Bluvstein, D. Shor’s Algorithm Is Possible with as Few as 10,000 Reconfigurable Atomic Qubits. arXiv 2026, arXiv:2603.28627. [Google Scholar]
  6. Gisin, N.; Ribordy, G.; Tittel, W.; Zbinden, H. Quantum cryptography. Rev. Mod. Phys. 2002, 74, 145–195. [Google Scholar] [CrossRef]
  7. Wootters, W.K.; Zurek, W.H. A single quantum cannot be cloned. Nature 1982, 299, 802–803. [Google Scholar] [CrossRef]
  8. Einstein, A.; Podolsky, B.; Rosen, N. Can Quantum-Mechanical Description of Physical Reality Be Considered Complete? Phys. Rev. 1935, 47, 777–780. [Google Scholar] [CrossRef]
  9. Bell, J.S. On the Einstein Podolsky Rosen paradox. Phys. Phys. Fiz. 1964, 1, 195–200. [Google Scholar] [CrossRef]
  10. Bennett, C.H.; Brassard, G. Quantum cryptography: Public key distribution and coin tossing. In Proceedings of the IEEE International Conference on Computers, Systems and Signal Processing, Bangalore, India, 10–12 December 1984; pp. 175–179. [Google Scholar]
  11. Hillery, M.; Bužek, V.; Berthiaume, A. Quantum secret sharing. Phys. Rev. A 1999, 59, 1829–1834. [Google Scholar] [CrossRef]
  12. Long, G.L.; Liu, X.S. Theoretically efficient high-capacity quantum key distribution scheme. Phys. Rev. A 2002, 65, 032302. [Google Scholar] [CrossRef]
  13. Zhou, N.; Zeng, G.; Xiong, J. Quantum key agreement protocol. Electron. Lett. 2004, 40, 1149–1150. [Google Scholar] [CrossRef]
  14. Wu, Y.; Chang, H.; Guo, G.; Lin, S. Multi-party quantum key agreement protocol with authentication. Int. J. Theor. Phys. 2021, 60, 4066–4077. [Google Scholar] [CrossRef]
  15. Yang, H.; Cai, D.; Qian, L.; Zhang, R.; Lu, S.; Sun, C. Single-State Multi-Party Quantum Key Agreement with Single-Particle Measurement. Entropy 2025, 27, 405. [Google Scholar] [CrossRef] [PubMed]
  16. Yang, Y.G.; Li, B.R.; Li, D.; Zhou, Y.H.; Shi, W.M. New quantum key agreement protocols based on Bell states. Quantum Inf. Process. 2019, 18, 322. [Google Scholar] [CrossRef]
  17. Ekert, A.K. Quantum cryptography based on Bell’s theorem. Phys. Rev. Lett. 1991, 67, 661–663. [Google Scholar] [CrossRef] [PubMed]
  18. Yang, H.; Yi, Z.; Lu, S.; Wang, M. Mutual authentication quantum key agreement protocol with single-particle measurement. Front. Phys. 2025, 13, 1563674. [Google Scholar] [CrossRef]
  19. Thomas, J.M.; Yeh, F.I.; Chen, J.H.; Mambretti, J.J.; Kohlert, S.J.; Kanter, G.S.; Kumar, P. Quantum teleportation coexisting with classical communications in optical fiber. Optica 2024, 11, 1700. [Google Scholar] [CrossRef]
  20. He, B.; Zhang, D.; Loke, S.W.; Lin, S.; Lu, L. Building a Hierarchical Architecture and Communication Model for the Quantum Internet. IEEE J. Sel. Areas Commun. 2024, 42, 1919–1935. [Google Scholar] [CrossRef]
  21. Boyer, M.; Kenigsberg, D.; Mor, T. Quantum Key Distribution with Classical Bob. In Proceedings of the 1st International Conference on Quantum, Nano and Micro Technologies; IEEE: New York, NY, USA, 2007; p. 10. [Google Scholar]
  22. Diffie, W.; Hellman, M. New directions in cryptography. IEEE Trans. Inf. Theory 1976, 22, 644–654. [Google Scholar] [CrossRef]
  23. Rivest, R.L.; Shamir, A.; Adleman, L. A method for obtaining digital signatures and public-key cryptosystems. Commun. ACM 1978, 21, 120–126. [Google Scholar] [CrossRef]
  24. Lo, H.K.; Ma, X.; Chen, K. Decoy State Quantum Key Distribution. Phys. Rev. Lett. 2005, 94, 230504. [Google Scholar] [CrossRef]
  25. Bruß, D. Optimal Eavesdropping in Quantum Cryptography with Six States. Phys. Rev. Lett. 1998, 81, 3018–3021. [Google Scholar] [CrossRef]
  26. Bechmann-Pasquinucci, H.; Gisin, N. Incoherent and coherent eavesdropping in the six-state protocol of quantum cryptography. Phys. Rev. A 1999, 59, 4238–4248. [Google Scholar] [CrossRef]
  27. Biham, E.; Huttner, B.; Mor, T. Quantum cryptographic network based on quantum memories. Phys. Rev. A 1996, 54, 2651–2658. [Google Scholar] [CrossRef]
  28. Yang, H.; Lu, S.; Zhou, Q.; Wang, M.; Feng, B.; Zhou, X. Efficient single-state multi-party quantum key agreement. Quantum Inf. Process. 2024, 23, 150. [Google Scholar] [CrossRef]
  29. Tang, R.H.; Zhang, C.; Long, D.Y. An efficient circle-type multiparty quantum key agreement protocol with single particles. Int. J. Mod. Phys. B 2020, 34, 2050199. [Google Scholar] [CrossRef]
  30. Dolev, D.; Yao, A. On the security of public key protocols. IEEE Trans. Inf. Theory 1983, 29, 198–208. [Google Scholar] [CrossRef]
  31. Bellare, M.; Rogaway, P. Entity Authentication and Key Distribution. In Advances in Cryptology—CRYPTO’93; Springer: Berlin/Heidelberg, Germany, 1994; pp. 232–249. [Google Scholar]
  32. Mayers, D. Quantum Key Distribution and String Oblivious Transfer in Noisy Channels. In Advances in Cryptology—CRYPTO’96; Springer: Berlin/Heidelberg, Germany, 1996; pp. 343–357. [Google Scholar]
  33. Cabello, A. Quantum Key Distribution in the Holevo Limit. Phys. Rev. Lett. 2000, 85, 5635–5638. [Google Scholar] [CrossRef] [PubMed]
  34. Bennett, C.H.; Wiesner, S.J. Communication via one- and two-particle operators on Einstein-Podolsky-Rosen states. Phys. Rev. Lett. 1992, 69, 2881–2884. [Google Scholar] [CrossRef]
Figure 1. Main steps of the proposed QKA scheme. (a) The QS distributes the quantum sequence to the users. After the users confirm receipt, the QS announces the positions and preparation bases of the decoy photons, and the users perform the first eavesdropping detection. (b) The users encode the quantum sequence using random Pauli operations and return the updated sequence to the QS. After the QS confirms receipt, the users announce the positions and preparation bases of the decoy photons, and the QS performs the second eavesdropping detection.
Figure 1. Main steps of the proposed QKA scheme. (a) The QS distributes the quantum sequence to the users. After the users confirm receipt, the QS announces the positions and preparation bases of the decoy photons, and the users perform the first eavesdropping detection. (b) The users encode the quantum sequence using random Pauli operations and return the updated sequence to the QS. After the QS confirms receipt, the users announce the positions and preparation bases of the decoy photons, and the QS performs the second eavesdropping detection.
Mathematics 14 01774 g001
Figure 2. Experimental verification for the case where Alice and Bob both apply U 01 . (a) Quantum circuit for the case where both Alice and Bob apply U 01 . (b) Experimental fidelity distribution obtained via single-photon measurements in the Z-basis. (c) Theoretical density matrix corresponding to the Bell state outcome | Φ + .
Figure 2. Experimental verification for the case where Alice and Bob both apply U 01 . (a) Quantum circuit for the case where both Alice and Bob apply U 01 . (b) Experimental fidelity distribution obtained via single-photon measurements in the Z-basis. (c) Theoretical density matrix corresponding to the Bell state outcome | Φ + .
Mathematics 14 01774 g002
Figure 3. Experimental verification for the case where Alice applies U 00 and Bob applies U 11 . (a) Quantum circuit for the case the case where Alice applies U 00 and Bob applies U 11 . (b) Experimental fidelity distribution obtained via single-photon measurements in the Z-basis. (c) Theoretical density matrix corresponding to the Bell state outcome | Ψ .
Figure 3. Experimental verification for the case where Alice applies U 00 and Bob applies U 11 . (a) Quantum circuit for the case the case where Alice applies U 00 and Bob applies U 11 . (b) Experimental fidelity distribution obtained via single-photon measurements in the Z-basis. (c) Theoretical density matrix corresponding to the Bell state outcome | Ψ .
Mathematics 14 01774 g003
Table 1. BSM results after applying U i to each particle of | Φ + A B .
Table 1. BSM results after applying U i to each particle of | Φ + A B .
AliceBob
U 00 U 01 U 10 U 11
U 00 | Φ + | Ψ + | Φ | Ψ
U 01 | Ψ + | Φ + | Ψ | Φ
U 10 | Φ | Ψ | Φ + | Ψ +
U 11 | Ψ | Φ | Ψ + | Φ +
Table 2. Mapping between Pauli operations and key bits.
Table 2. Mapping between Pauli operations and key bits.
Pauli Matrix U 00 U 01 U 10 U 11
{ x 2 i 1 , x 2 i } 00011011
Table 3. Key agreement process under the 16 combinations of Pauli operations.
Table 3. Key agreement process under the 16 combinations of Pauli operations.
Alice’s Pauli U 00 U 01 U 10 U 11 U 00 U 01 U 10 U 11 U 00 U 01 U 10 U 11 U 00 U 01 U 10 U 11
K A 00011011000110110001101100B1011
Bob’s Pauli U 00 U 00 U 00 U 00 U 01 U 01 U 01 U 01 U 10 U 10 U 10 U 10 U 11 U 11 U 11 U 11
K B 00000000010101011010101011111111
BSM result Φ + Ψ + Φ Ψ Ψ + Φ + Ψ Φ Φ Ψ Φ + Ψ + Ψ Φ Ψ + Φ +
Alice corrects  K A 1 ¯ 0 1 ¯ 1 1 ¯ 0 1 ¯ 1 0 ¯ 0 0 ¯ 1 0 ¯ 0 0 ¯ 1
K A 00010001000100011011101110111011
Bob corrects  K B 0 0 ¯ 0 0 ¯ 0 1 ¯ 0 1 ¯ 1 0 ¯ 1 0 ¯ 1 1 ¯ 1 1 ¯
K B 00010001000100011011101110111011
Note: For the sake of brevity, the Dirac notation (e.g., |Φ+〉) is omitted for the BSM results.
Table 4. Performance comparison between the proposed scheme and representative QKD and QKA schemes.
Table 4. Performance comparison between the proposed scheme and representative QKD and QKA schemes.
SchemeTypeQuantum ResourceRequired Usesr Quantum CapabilitiesResource UtilizationQubit Efficiency ( η )
BB84 [10]QKDSingle photonSPP, SPM≈50%≈25%
E91 [17]QKDBell statesSPM 22.2 % 22.2 %
Ref. [18]QKAGHZ statesGP, SPM≈50%≈12.5%
Ref. [16]QKABell statesBP, BSM, SPP 100 % 40 %
Ref. [14]QKABell statesSPM, PO≈50%≈25%
Ref. [15]QKABell statesBP, SPM 25 % 20 %
ProposedQKABell statesSPP, SPM, PO100%≈66.7%
Abbreviations: SPP: Single-photon preparation; BP: Bell state preparation; GP: GHZ-state preparation; SPM: Single-photon measurement; BSM: Bell state measurement; GSM: GHZ-state measurement; PO: Pauli operation.
Table 5. Comparison of experimental parameters and results including correction operations.
Table 5. Comparison of experimental parameters and results including correction operations.
UserCase 1 Case 2
Op.
( U )
Init.
( K ini )
BSM
Res.
Corr.Final
( K )
Op.
( U )
Init.
( K ini )
BSM
Res.
Corr.Final
( K )
Alice U 01 01 | Φ + 01 U 00 00 | Ψ Flip 1st10
Bob U 01 01 U 11 11Flip 2nd
Note: Op. denotes the Pauli operation; K i n i and K represent the initial and final shared keys, respectively.
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.

Share and Cite

MDPI and ACS Style

Zhang, C.; Liu, Y.; Jiang, Y.; Zheng, S. High-Efficiency Lightweight Quantum Key Agreement Scheme Based on Bell State Entanglement. Mathematics 2026, 14, 1774. https://doi.org/10.3390/math14101774

AMA Style

Zhang C, Liu Y, Jiang Y, Zheng S. High-Efficiency Lightweight Quantum Key Agreement Scheme Based on Bell State Entanglement. Mathematics. 2026; 14(10):1774. https://doi.org/10.3390/math14101774

Chicago/Turabian Style

Zhang, Chunyu, Yanbing Liu, Yinghua Jiang, and Sen Zheng. 2026. "High-Efficiency Lightweight Quantum Key Agreement Scheme Based on Bell State Entanglement" Mathematics 14, no. 10: 1774. https://doi.org/10.3390/math14101774

APA Style

Zhang, C., Liu, Y., Jiang, Y., & Zheng, S. (2026). High-Efficiency Lightweight Quantum Key Agreement Scheme Based on Bell State Entanglement. Mathematics, 14(10), 1774. https://doi.org/10.3390/math14101774

Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details here.

Article Metrics

Back to TopTop