1. Introduction
Optical fiber communications have been widely deployed in commercial core and metro communication networks, benefiting from their strong stability, high capacity, and long-haul transmission [
1]. However, driven by illegal interests, personal privacy and confidential information face tremendous security risks, hence security has been a non-neglected property in communication systems. Compared with traditional mathematical encryption algorithms, physical-layer secure encryption schemes have the unique advantage of resisting the attack of quantum computers [
2]. To improve the security of communication systems, physical-layer secure encryption schemes have attracted extensive attention [
3,
4].
Based on the Born rule principle, quantum noise from equipment in the optical communication system is unable to be eliminated in any way [
5]. The minimum Euclidean distance is an effective criterion for evaluating the bit error ratio (BER) performance [
6]. When the Euclidean distance between adjacent symbols in the constellation is small enough, they are confused by noise so much that they are incapable of being distinguished accurately. Therefore, the theoretical optimal BER performance is affected by quantum noise. Quantum noise stream cipher (QNSC) is a physical-layer secure encryption scheme taking advantage of unescapable quantum noise (e.g., shot noise) [
7]. In the QNSC system, the plaintext symbols, with low-order modulation format, are randomly mapped into the ciphertext symbols with ultra-high-order modulation format, so-called QNSC symbols. Due to the quantum noise masking effect, a QNSC symbol becomes indistinguishable from its surrounding QNSC symbols. The QNSC symbols can be transformed into low-order symbols in the same way as the plaintext symbols by legal parties with pre-shared secret keys, while the attacker (Eve) only demodulates the ultra-high-order QNSC symbols. This feature ensures that the QNSC system can resist eavesdropping attacks and protect the security of personal privacy and confidential information.
Recently, the major research purpose has focused on two aspects: security enhancement and transmission performance improvement. In terms of security enhancement, the security of QNSC is further discussed under correlation, known-plaintext, and quantization attacks [
8,
9,
10]. The masking effects of shot noise and amplified spontaneous emission (ASE) noise are theoretically analyzed under various average optical power and optical signal-to-noise ratio (OSNR) [
11]. A novel optical stealth communication scheme based on the ASE light source is proposed to improve the number of masked signals (NMS) [
12]. Based on randomized perturbation, an excellent NMS is guaranteed at the cost of transmission performance [
13]. The hyperchaotic system provides extra diffusion for security enhancement in QAM/QNSC [
14]. It is possible to achieve the integration of secure transmission and key distribution with the multi-bit mapping Y-00 protocol [
15]. In terms of improving transmission performance, an attractive work reaches ultra-long-haul digital coherent PSK/QNSC with 10,118 km fiber transmission [
16]. A 300 km fiber transmission without an intermediate amplifier is achieved, benefiting from the subtractive clustering method and optimized fuzzy C-means clustering algorithm in [
17]. A low encryption penalty LEO-to-Earth Secure Laser Communication Based on Quantum Noise Stream Cipher is proposed [
18]. Using end-to-end deep learning, a 400 Gbps QNSC is implemented over 1520 km fiber in a 21-channel WDM transmission system [
19]. The single-channel net rate in QAM/QNSC was higher than 200 Gbps in [
20,
21]. However, there is a trade-off between transmission performance and security, and that is, high security often sacrifices transmission performance as a cost. The encryption penalty in QAM/QNSC is demonstrated due to adding bases and expanding constellation space [
21].
Probabilistic shaping (PS) is an effective technique to approach the Shannon limit by adjusting the occurrence frequency of symbols [
22,
23,
24]. By optimizing the symbol distribution, the PS signal can achieve better BER performance than a uniformly distributed signal at the same OSNR. In previous work [
20], PS is applied to the payload constellation of 16QAM, while uniform bases are still used to construct QNSC symbols. However, since the encryption penalty in QNSC is inherently induced by adding bases, optimizing only the payload distribution cannot fundamentally mitigate the encryption penalty. Since the encryption penalty decreases with the increase in the plaintext modulation order [
21], 256QAM encryption can be achieved without the encryption penalty utilizing a delta sigma modulator [
25,
26,
27]. However, relatively low-order plaintext modulation formations still dominate practical applications. Therefore, it is worth studying new approaches to improve transmission performance and mitigate encryption penalty for relatively low plaintext modulation orders.
In previous work, we have proposed a PS-assisted base precoding QNSC (PSABP QNSC) scheme and utilized non-uniform bases to effectively mitigate encryption penalties [
28]. In this paper, we further extend previous work from the following aspects:
- (i)
Theory: We theoretically analyze the gain mechanism with Gaussian bases and explore the effect of various shaping rate parameters on the minimum Euclidean distance in the QAM/QNSC system. PS gains are systematically evaluated across QNSC ciphertext constellations, with comparative analysis of QPSK and 16QAM plaintext symbol configurations. Compared with the traditional QNSC signal, our proposed scheme realizes an achievement in alleviating the encryption penalty and improving BER performance.
- (ii)
Experiment: We set up an experimental platform of a coherent optical transmission system and measure the BER performance curves of 160 km standard single-mode fiber (SSMF). The shaping rate parameter
and block length
are set to satisfy the code rate of
, which
is the total number of bits of a basis for the I or Q component. Experimental results demonstrate that the proposed PSABP QNSC schemes achieve encryption penalties of 0.16 dB and 0.14 dB for QPSK and 16QAM, respectively, corresponding to reductions of 0.44 dB and 0.27 dB, at the 15% overhead soft-decision forward error correction (SD-FEC) threshold over a 160 km SSMF transmission link. The comparison between this scheme and other schemes is shown in
Table 1.
- (iii)
Security: We investigate the effect of Gaussian distributed bases on the security of QNSC. The effective bases and effective ciphertext symbol points are proposed to optimize the calculation expression of NMS. The NMS and detection failure probability (DFP) are discussed at the eavesdropping point. Furthermore, we evaluate the mutual information of Eve in terms of quantum noise and all noise. The mutual information leakage is bits for QPSK, compared to bits for 16QAM. The results demonstrate that the PSABP QNSC scheme can effectively resist eavesdropping by Eve.
3. Transmission Performance Analysis
In our work, the two PRNGs and two sets of seed keys generate two sets of running keys. To simplify the analysis process, the running keys1 is used for the XOR operation, and the running keys2 is used for bases. The linear feedback shift register (LFSR) is usually used to generate pseudorandom numbers. Two LFSRs with lengths of 128 bits and 256 bits are employed as PRNG1 and PRNG2, respectively, each with a distinct seed key and primitive polynomial. For I or Q components, the probability of the QNSC symbol is expressed by the joint probability of bases
and symbol
The subscripts
and
stand for the position of the element in the symbol sets
and
. According to Equation (5), the mean power of QNSC symbols (
) can be calculated as follows:
When
becomes sufficiently larger,
approaches an upper bound determined by the maximum amplitude in the I or Q component [
18]. In this paper, the probability of bases is an MB distribution rather than a uniform distribution, which is
CCDM is employed to code the bases. The bases before CCDM coding are referred to as the original bases, whereas those after encoding are termed the encoded bases. The mean power of the PSABP QNSC symbols (
) is lower than that of uniform QNSC symbols (
). Therefore, when the launch power remains unchanged, the minimum Euclidean distance of the PSABP QNSC symbol (
) increases accordingly. Traditional QNSC employs rectangular QAM modulation with a minimum Euclidean distance two. Therefore,
is calculated as follows:
The QNSC signal’s BER is naturally the plaintext’s BER. The effective minimum Euclidean distance (
) is given in [
21], which is the minimum Euclidean distance of QAM/QNSC signals under the same basis. Due to the expansion of constellation space, the
deteriorates compared with the plaintext symbol, and the QNSC signal has the encryption penalty. The
can be expressed as follows:
where
is the maximal scalar value after power normalization in the I or Q component of the QNSC symbol. The
is written as follows:
where
is the mean power of the plaintext symbol and
.
depends exclusively on two parameters:
(bit length of a plaintext symbol) and
(bit length of a basis). For example, the plaintext is modulated using QPSK, whereas the QNSC constellation is 256QAM (
,
,
). The mean powers of QPSK and 256QAM are 2 and 170, respectively (
,
). For the I component, the range of amplitude is
in 256QAM.
represents the amplitude of QNSC. Thus,
is 15. According to Equation (10),
. Given a fixed value of
,
is directly proportional to
, and approaches its theoretical upper bound as
m becomes sufficiently large. The relational conclusions are also shown in [
21].
The ratio of
between QAM/QSNC and plaintext symbol is
as a scalar and given by
Taking into account shaping gain, the final
(
) is given by
In the standard constellation of rectangular QAM, it can be observed that
. For example, in 256QAM,
is 15, and
. Therefore, using Equation (10),
is rewritten as follows:
Equations (5)–(8) distinctly imply that the increase in
provided by the shaping gain is inherently limited. It is a reasonable assumption that
has an upper bound. When
, only the central encoded bases with the highest probabilities are retained. Since each encoded basis remains unique, effective noise masking can still be achieved. Then, the encoded bases are used to encrypt plaintext symbols. It must be noted that each encoded basis must be composed of
bits are used to ensure the noise masking effects. Because noise with the same OSNR has different effects on 1101 and 1100000001, the lowest bit of the latter is more easily masked by noise. After being expanded into high-order ciphertext space, the shaped ciphertext symbol (
) is expressed as follows:
Note that all shaping ciphertext symbols are equiprobable occurrences in this case, according to Equation (5). Hence, the limit of
is written as follows:
Then, the bounds of
and
can be calculated.
Figure 4a shows this trend between the
and
when
and
, whose plaintext symbol formats are QPSK and 16QAM, respectively, and QNSC symbol format is
QAM. Here, the theoretical bounds of
and
are
and
in QPSK. The bounds of
and
are
and
in 16QAM. In the other cases, the theoretical bounds of
approach two as
increases, as demonstrated in
Figure 4b. From
Figure 4, it is clearly seen that the proposed scheme can improve transmission performance and reduce the encryption penalty in the QNSC system.
4. Experimental Setup
We built an experimental setup for a coherent orthogonal frequency division multiplexing (OFDM) optical transmission, and
Figure 5 shows the diagram of the experimental setup and DSP flows. Note that the single carrier system can also be used to demonstrate the feasibility of the proposed scheme. An external cavity laser (ECL) is applied to supply a stable laser with 10 dBm of power and 1550 nm of wavelength, and the linewidth is 32 kHz. An arbitrary waveform generator (AWG) with 10 GSa/s of sampling rate and 12 bits of resolution generates an electrical signal. The electrical signal, which is amplified by modulator drivers (MD), is loaded into the optical domain with an IQ modulator (IQ Mod.), and the output optical power is about −15 dBm. An erbium-doped fiber amplifier (EDFA) is used for maintaining the launch power of 0 dBm. After 160 km fiber link transmission, another EDFA is used to compensate for the power loss, which is 32 dB. To adjust the OSNR of the system, an EDFA offers extra ASE noise. A coherent receiver is adopted to recover the electrical signal. The local optical signal power is 10 dBm, which is provided by another ECL. A digital oscilloscope (DSO) captures the electrical signal at a sampling rate of 20 GSa/s. Two Eavesdropping points are placed in the output port of the IQ Modulator and the first EDFA to wiretap the optical signal with 100%, named points A and B. Specifically, point A denotes the eavesdropping position with the least ASE noise, while point B denotes the eavesdropping position with the highest optical signal power. Point B is the best eavesdropping point because of the highest optical power.
In the off-line DSP, the rate parameter
and block length
are served as pre-shared parameters between Alice and Bob to initialize CCDM module. Due to satisfy
code rate, we set suitable
and
, according to
Table 2.
and
constitute tunable parameters that enable transmission performance-security optimization in deployment scenarios. All original bases are regarded as a whole and then divided into different pieces according to
. The original bases with uniform distribution are encoded as encoded bases with a Gaussian distribution. In the first step of encryption, the plaintext bit is encrypted by the XOR operation in a bit-by-bit manner. Whereafter, QAM symbols with QPSK or 16QAM are modulated. In the second step of encryption, the encoded bases are added to the QPSK or 16QAM symbols. A 256-point FFT/IFFT is used for OFDM modulation. Only 128 subcarriers carry data, while 109 subcarriers for high frequency and 19 subcarriers for low frequency have zero padding to improve transmission performance [
31]. Eight pilot subcarriers are inserted into an OFDM symbol to compensate phase noise of the lasers. The average value of the phase noise of eight pilot subcarriers is regarded as the phase noise of an OFDM symbol. Each 50 OFDM symbols used five training sequences. A total of 100 OFDM symbols are regarded as transmitted data, and the extra 10 OFDM symbols are used for channel estimation and equalization. Applying a cyclic prefix (CP) with 1/16 OFDM symbol length eliminates the inter-symbol interference caused by chromatic dispersion. An IQ match with the Gram–Schmidt orthogonalization (GSO) algorithm is adopted to solve the IQ imbalance [
32]. After performing symbol timing synchronization, frequency offset estimation (FOE), channel estimation and equalization, and phase noise compensation (PNC) are remedies for alleviating the influence of noise from the channel, transmitter, and receiver [
33,
34,
35]. Then, the encoded basis is subtracted from the QNSC symbol, and an XOR is performed to recover the plaintext bit after QAM demodulation.
In the transmission experiment in our work, there is an assumption that a 15% overhead soft-decision forward error correction (SD-FEC) is employed. The symbol rate is , and the net data rate is for QPSK and for 16QAM (: fraction of payload data subcarriers; : OFDM frame efficiency excluding the extra 10 OFDM training sequences; : CP efficiency for a CP length of ; : net coding efficiency after FEC overhead).
6. Security Analysis
In the QNSC system, there is a common attack assumption that Eve, without a pre-shared secret key, only demodulates ultra-high order QNSC symbols. Noise masking degrades Eve’s decoding capability for QNSC symbols, manifesting as elevated symbol error ratios (SER). This SER serves as a key security indicator, with metrics including NMS and DFP characterizing the achievable security level. Elevated NMS and DFP values correspond to reduced mutual information at Eve, thereby enhancing system security. Considering the two-dimensional additive Gaussian white noise, the scope of the noise mask is a circle [
36]. The NMS is defined as follows:
where
and
represent noise standard deviation I and Q components. The minimum Euclidean distance of QSNC after normalizing
is also expressed by [
21]
The theoretical security stems from quantum noise, and the NMS of quantum noise is calculated by [
21]
where
is signal bandwidth;
is the power of the optical signal; and
is the electric charge.
The above analysis is the calculation process of NMS of quantum noise in traditional QNSC. Compared with traditional QNSC, PSABP QSNC has a multi-peak Gaussian distribution, and the evaluation of NMS is more complex. On the one hand, PS affects the distance of adjacent ciphertext symbol points. On the other hand, some ciphertext symbol points may disappear. As shown in
Figure 8, PS may reduce the number of constellation points. For example, 10 points with uniform distribution are shaped into six points with a Gaussian distribution. Only symbols with a small middle amplitude are retained. Particularly in practical systems, the frame length is limited, and therefore some symbol points with low occurrence probabilities may be absent. Therefore, constellation points that do not appear should not be considered in the NMS calculation for PSABP QNSC. Therefore, the calculation of NMS should be divided into two steps in PSABP QNSC.
First step: Only the influence of Δ variation on the NMS is considered. In this step, it is assumed that applying PS only enlarges Δ while preserving all QNSC symbols. The first reason is that the signal power must remain invariant before and after PS, and the second reason is that a QNSC symbol still consists of 2
bits.
in PSABP QNSC is calculated by
Therefore, Equation (20) in PSABP QNSC can be expressed by
Second step: The impact of the disappeared QNSC symbols on the NMS is evaluated. The disappeared QNSC symbols should be removed after Equation (22), which causes NMS to be overestimated in PSABP QNSC.
If we regard QNSC symbol as QAM, the constellation can be divided into regions. The effect of adding bits bases is to make QAM randomly shift within its respective region. When the bases with Gaussian distribution are added to the QAM symbols, the QNSC symbols of each region also appear in a Gaussian distribution. Overall, the constellation presents a multi-peaked Gaussian-like distribution.
Here, we conservatively assume that symbols near the region boundary remain within the original region despite the influence of quantum noise. Because quantum noise is a small noise. In each region, the maximum number of noise masked symbols is equal to the region’s symbol count, which is the same as the number of base points. The effective base (
) is used to represent the number of base points with a Gaussian distribution for I or Q components. The
is defined as bases with a frequency greater than one in a CCDM block length
:
where
is the sum of an array; and
return one when left value is not less than right value, or return zero. If the frequency of a base point within a block is less than one, this base point is considered absent and is excluded from the NMS calculation. The value of
lies in the range from 2 to
. Considering that there are I and Q components, the effective ciphertext symbol points (
) is given by
The is defined as the number of bases remaining after the removal of QNSC symbol points that have disappeared. It serves the purpose of preventing the overestimation of NMS. Even under the effect of noise with large variance, the NMS remains within the bounds of . For example, if is 256 in traditional QNSC, whereas it is 10 in PSABP QNSC. When the variance of quantum noise is large, the NMS of quantum noise is 200 in traditional QNSC, whereas it is only 10 in PSABP QNSC. When the variance of quantum noise is small, the NMS of quantum noise is 5 in traditional QNSC, whereas it may be 4 in PSABP QNSC, according to Equation (22). The NMS of quantum noise in PSABP QNSC should be determined jointly by quantum noise, the modulation format of QNSC symbol and .
The
curves with different shaping rate parameter
are shown in
Figure 9. In PSABP QPSK/QNSC, the shaping rate parameter
is 0.00011 and
is nine. Then,
is 392 and
is 153,664. Similarly, in PSABP 16QAM/QNSC,
is 0.000464 and
is eight. Then,
is 206 and
is 42,436.
Finally, combining Equations (22) and (24), we can obtain the NMS of quantum noise in PSABP QNSC:
When is small, some high probability bases may not be contained in a block, thus constraining the upper bound of NMS calculated by Equation (25). To avoid this drawback as possible, should be large enough to contain as many high probability bases in a block. Considering the specific scenario where the bases exhibit a uniform distribution, characterized by , the expected should be . Consequently, to satisfy this requirement, the satisfies the condition .
In
Figure 10, the NMS curves of quantum noise with different
are shown according to Equation (25). In traditional QSNC, the NMS merely depends on the quantum noise and the modulation format of QNSC. Thus, the traditional QPSK/QNSC and 16QAM/QNSC have a same NMS in our experiment. The signal bandwidth
is 10 GHz; the modulation format of QNSC is
QAM, and the powers of optical signal are −15 dBm at point A and 0 dBm at point B. The NMSs of PSABP 16QAM/QNSC reach
only when the optical power is below −44 dBm. Because the effect of basis precoding is more evident in QPSK/QNSC, the corresponding decrease in NMS is more pronounced compared with that in 16QAM/QNSC. In
Table 3, we record the NMS of all signals at point A and point B. At point A, the NMS induced by quantum noise is 53.18 for the PSABP 16QAM/QNSC signal and 44.35 for the PSABP QPSK/QNSC signal. At point B, the corresponding values decrease to 1.68 and 1.41, respectively. Therefore, the signals are effectively masked by quantum noise. It should be noted that the present experiments are limited by the optical signal power and signal bandwidth. Consequently, the NMS induced by quantum noise is lower than that reported in existing works.
In the limit case of PS with , the is four. Therefore, the range of the NMS of PSABP QNSC is 0~4. If the power of the optical signal is attenuated to a small amount, the NMS of quantum noise is only four, but when the power of the optical signal is large enough, the NMS of quantum noise is reduced to zero. Although the limit case of PS has the best transmission performance, it is obviously less secure compared with traditional QNSC.
Herein, the effect of prior probabilities on the decision threshold is ignored because the probabilities of adjacent symbols are similar. Therefore, we can also calculate the DFP by [
7]
The DFP curves with different
are drawn in
Figure 11. Because
is zero dBm at point B, the DFP are 69.72%, 63.77%, and 68.66% for traditional QNSC, PSABP QPSK/QNSC, and PSABP 16QAM/QNSC, respectively. However, due to the greater quantum noise, the DFP of all signals increases significantly at point A, both exceeding 98%. The results show that, compared with the traditional QNSC scheme, the PSABP-QNSC scheme exhibits a slight reduction in security, as reflected by NMS decreases of 0.34 and 0.07, respectively. However, it still maintains effective resistance to eavesdropping and can protect the information.
Assuming that Eve can eavesdrop under ideal conditions and remove all noise other than quantum noise, the NMS induced by quantum noise can be regarded as the theoretical security level, corresponding to the lower bound of system security. In practice, Eve’s eavesdropping conditions are constraining. The other noise (e.g., ASE noise, thermal noise and quantization noise) can also mask signals to provide certain security. Therefore, it is harder for Eve to eavesdrop on useful information. The NMS of all noise can be calculated by Equations (18) and (19). Taking PSABP 16QAM/QNSC, for example, we measure the standard deviation of all noise
, and
at point B, as shown in
Figure 12. Therefore, the NMS is 2808.84, and the DPF is 99.97% under the effects of all noise.
It is non-negligible that the QNSC system combines physical encryption and mathematical encryption, which are masking effect of noise and XOR operation [
7]. The NMS and DFP represent physical factors. To intercept a plaintext bit, Eve must accurately XOR operation. Information leakage in PSABP QNSC systems can be quantified through mutual information analysis, providing a theoretical foundation for security evaluation. The mutual information of Eve can be calculated by [
37]
Under noise masking, the lowest bit of each symbol experiences distortion, rendering it inherently resistant to accurate detection by Eve. When only quantum noise is considered, the symbol error probability
for either I or Q component is given by:
Considering that the lowest bits of adjacent symbols alternate between zero and one. When Eve detects symbols with error probability
, the probability of correctly detecting the lowest bit reduces to 0.5, statistically equivalent to random guessing. On the contrary, when Eve detects symbols with correct probability
, the probability that Eve obtains the correct lowest bit is 1. Therefore, the detection correct probability of the lowest bit is
, and the detection error probability of the lowest bit is
. The lowest bit is used to XOR with high bit of a QNSC symbol. Where only quantum noise is taken into account, the BER can be approximately regarded as
. Given the independence of I/Q components, the overall BER is determined by the average of the individual component BERs. The overall BER is
. Therefore, under the masking effect of quantum noise, the mutual information of Eve can be expressed by
It should be noted that Equation (29) is an idealized analytical result, since it does not include practical channel impairments such as phase noise, ASE noise, and fiber nonlinearities, which may introduce joint error propagation and correlation. We record the mutual information of Eve versus power
with different schemes in
Figure 13. The results reveal that PSABP QPSK/QNSC exhibits the highest information leakage (0.28 bit), exceeding traditional QNSC (0.231 bit), while the leakage of PSABP 16QAM/QNSC with 0.239 bit shows a marginal difference from traditional QNSC. In practice, phase noise, ASE noise, and fiber nonlinearities may introduce error correlation and joint propagation effects, so that Eve’s practical BER may deviate from the idealized value
. Therefore, we measure the BER of Eve at point B, and the mutual information is calculated by Equation (27), as
bits,
bits and
bits, which are, respectively, traditional QNSC, PSABP 16QAM/QNSC, and PSABP QPSK/QNSC. The results can reflect the practical security performance of the proposed schemes under realistic transmission conditions. In [
37], the mutual information leakage is less than
bit, while our results only exhibit a slight difference compared with this value.