Skip to main content An official website of the United States government Here's how you know Here's how you know Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( Lock Locked padlock icon ) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites. Search Log in Dashboard Publications Account settings Log out Search… Search NCBI Primary site navigation Search Logged in as: Dashboard Publications Account settings Log in Search PMC Full-Text Archive Search in PMC Journal List User Guide PERMALINK Copy As a library, NLM provides access to scientific literature. Inclusion in an NLM database does not imply endorsement of, or agreement with, the contents by NLM or the National Institutes of Health. Learn more: PMC Disclaimer | PMC Copyright Notice Sci Adv . 2026 Apr 10;12(15):eaed2420. doi: 10.1126/sciadv.aed2420 Search in PMC Search in PubMed View in NLM Catalog Add to search Secure quantum key distribution against correlated leakage source Jia-Xuan Li Jia-Xuan Li 1 Laboratory of Quantum Information, University of Science and Technology of China, Hefei, Anhui 230026, P. R. China. 2 CAS Center for Excellence in Quantum Information and Quantum Physics, University of Science and Technology of China, Hefei, Anhui 230026, P. R. China. 3 Anhui Province Key Laboratory of Quantum Network, University of Science and Technology of China, Hefei, Anhui 230026, P. R. China. Conceptualization, Data curation, Formal analysis, Funding acquisition, Investigation, Methodology, Resources, Software, Validation, Visualization, Writing - original draft, Writing - review & editing Find articles by Jia-Xuan Li 1, 2, 3 , Yang-Guang Shan Yang-Guang Shan 1 Laboratory of Quantum Information, University of Science and Technology of China, Hefei, Anhui 230026, P. R. China. 2 CAS Center for Excellence in Quantum Information and Quantum Physics, University of Science and Technology of China, Hefei, Anhui 230026, P. R. China. 3 Anhui Province Key Laboratory of Quantum Network, University of Science and Technology of China, Hefei, Anhui 230026, P. R. China. Conceptualization, Methodology, Software, Validation, Writing - review & editing Find articles by Yang-Guang Shan 1, 2, 3 , Rong Wang Rong Wang 4 School of Cyberspace, Hangzhou Dianzi University, Hangzhou, Zhejiang 310018, P. R. China. Validation Find articles by Rong Wang 4 , Feng-Yu Lu Feng-Yu Lu 1 Laboratory of Quantum Information, University of Science and Technology of China, Hefei, Anhui 230026, P. R. China. 2 CAS Center for Excellence in Quantum Information and Quantum Physics, University of Science and Technology of China, Hefei, Anhui 230026, P. R. China. 3 Anhui Province Key Laboratory of Quantum Network, University of Science and Technology of China, Hefei, Anhui 230026, P. R. China. 5 Hefei National Laboratory, University of Science and Technology of China, Hefei 230088, P. R. China. Data curation, Formal analysis, Funding acquisition, Investigation, Methodology, Project administration, Resources, Software, Validation Find articles by Feng-Yu Lu 1, 2, 3, 5 , Zhen-Qiang Yin Zhen-Qiang Yin 1 Laboratory of Quantum Information, University of Science and Technology of China, Hefei, Anhui 230026, P. R. China. 2 CAS Center for Excellence in Quantum Information and Quantum Physics, University of Science and Technology of China, Hefei, Anhui 230026, P. R. China. 3 Anhui Province Key Laboratory of Quantum Network, University of Science and Technology of China, Hefei, Anhui 230026, P. R. China. 5 Hefei National Laboratory, University of Science and Technology of China, Hefei 230088, P. R. China. Conceptualization, Data curation, Formal analysis, Funding acquisition, Investigation, Methodology, Project administration, Resources, Software, Supervision, Validation, Visualization, Writing - original draft, Writing - review & editing Find articles by Zhen-Qiang Yin 1, 2, 3, 5, * , Shuang Wang Shuang Wang 1 Laboratory of Quantum Information, University of Science and Technology of China, Hefei, Anhui 230026, P. R. China. 2 CAS Center for Excellence in Quantum Information and Quantum Physics, University of Science and Technology of China, Hefei, Anhui 230026, P. R. China. 3 Anhui Province Key Laboratory of Quantum Network, University of Science and Technology of China, Hefei, Anhui 230026, P. R. China. 5 Hefei National Laboratory, University of Science and Technology of China, Hefei 230088, P. R. China. Conceptualization, Data curation, Formal analysis, Funding acquisition, Investigation, Methodology, Project administration, Resources, Software, Supervision, Validation, Visualization, Writing - original draft, Writing - review & editing Find articles by Shuang Wang 1, 2, 3, 5, * , Wei Chen Wei Chen 1 Laboratory of Quantum Information, University of Science and Technology of China, Hefei, Anhui 230026, P. R. China. 2 CAS Center for Excellence in Quantum Information and Quantum Physics, University of Science and Technology of China, Hefei, Anhui 230026, P. R. China. 3 Anhui Province Key Laboratory of Quantum Network, University of Science and Technology of China, Hefei, Anhui 230026, P. R. China. 5 Hefei National Laboratory, University of Science and Technology of China, Hefei 230088, P. R. China. Funding acquisition, Project administration, Resources, Supervision Find articles by Wei Chen 1, 2, 3, 5 , De-Yong He De-Yong He 1 Laboratory of Quantum Information, University of Science and Technology of China, Hefei, Anhui 230026, P. R. China. 2 CAS Center for Excellence in Quantum Information and Quantum Physics, University of Science and Technology of China, Hefei, Anhui 230026, P. R. China. 3 Anhui Province Key Laboratory of Quantum Network, University of Science and Technology of China, Hefei, Anhui 230026, P. R. China. 5 Hefei National Laboratory, University of Science and Technology of China, Hefei 230088, P. R. China. Funding acquisition, Project administration, Resources, Supervision, Writing - review & editing Find articles by De-Yong He 1, 2, 3, 5 , Guang-Can Guo Guang-Can Guo 1 Laboratory of Quantum Information, University of Science and Technology of China, Hefei, Anhui 230026, P. R. China. 2 CAS Center for Excellence in Quantum Information and Quantum Physics, University of Science and Technology of China, Hefei, Anhui 230026, P. R. China. 3 Anhui Province Key Laboratory of Quantum Network, University of Science and Technology of China, Hefei, Anhui 230026, P. R. China. 5 Hefei National Laboratory, University of Science and Technology of China, Hefei 230088, P. R. China. Data curation, Funding acquisition, Project administration, Resources, Supervision Find articles by Guang-Can Guo 1, 2, 3, 5 , Zheng-Fu Han Zheng-Fu Han 1 Laboratory of Quantum Information, University of Science and Technology of China, Hefei, Anhui 230026, P. R. China. 2 CAS Center for Excellence in Quantum Information and Quantum Physics, University of Science and Technology of China, Hefei, Anhui 230026, P. R. China. 3 Anhui Province Key Laboratory of Quantum Network, University of Science and Technology of China, Hefei, Anhui 230026, P. R. China. 5 Hefei National Laboratory, University of Science and Technology of China, Hefei 230088, P. R. China. Data curation, Funding acquisition, Project administration, Resources, Supervision, Writing - review & editing Find articles by Zheng-Fu Han 1, 2, 3, 5 Author information Article notes Copyright and License information 1 Laboratory of Quantum Information, University of Science and Technology of China, Hefei, Anhui 230026, P. R. China. 2 CAS Center for Excellence in Quantum Information and Quantum Physics, University of Science and Technology of China, Hefei, Anhui 230026, P. R. China. 3 Anhui Province Key Laboratory of Quantum Network, University of Science and Technology of China, Hefei, Anhui 230026, P. R. China. 4 School of Cyberspace, Hangzhou Dianzi University, Hangzhou, Zhejiang 310018, P. R. China. 5 Hefei National Laboratory, University of Science and Technology of China, Hefei 230088, P. R. China. * Corresponding author. Email: [email protected] (Z.-Q.Y.); * Corresponding author. Email: [email protected] (S.W.) Roles Jia-Xuan Li : Conceptualization, Data curation, Formal analysis, Funding acquisition, Investigation, Methodology, Resources, Software, Validation, Visualization, Writing - original draft, Writing - review & editing Yang-Guang Shan : Conceptualization, Methodology, Software, Validation, Writing - review & editing Rong Wang : Validation Feng-Yu Lu : Data curation, Formal analysis, Funding acquisition, Investigation, Methodology, Project administration, Resources, Software, Validation Zhen-Qiang Yin : Conceptualization, Data curation, Formal analysis, Funding acquisition, Investigation, Methodology, Project administration, Resources, Software, Supervision, Validation, Visualization, Writing - original draft, Writing - review & editing Shuang Wang : Conceptualization, Data curation, Formal analysis, Funding acquisition, Investigation, Methodology, Project administration, Resources, Software, Supervision, Validation, Visualization, Writing - original draft, Writing - review & editing Wei Chen : Funding acquisition, Project administration, Resources, Supervision De-Yong He : Funding acquisition, Project administration, Resources, Supervision, Writing - review & editing Guang-Can Guo : Data curation, Funding acquisition, Project administration, Resources, Supervision Zheng-Fu Han : Data curation, Funding acquisition, Project administration, Resources, Supervision, Writing - review & editing Received 2025 Oct 21; Accepted 2026 Mar 6; Collection date 2026 Apr 10. Copyright © 2026 The Authors, some rights reserved; exclusive licensee American Association for the Advancement of Science. No claim to original U.S. Government Works. Distributed under a Creative Commons Attribution License 4.0 (CC BY). This is an open-access article distributed under the terms of the Creative Commons Attribution license , which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited. PMC Copyright notice PMCID: PMC13068060 PMID: 41961933 Abstract Quantum key distribution (QKD) provides information-theoretic security based on quantum mechanics, yet its implementation is hindered by source imperfections. Among these, correlations between transmitted pulses present a critical but underexplored threat to QKD’s theoretical security. We propose a general framework for QKD security under correlated sources, achieving the first finite-key analysis by extending and reorganizing QKD rounds using the generalized chain rule. Inspired by side-channel-secure QKD, we design a protocol secure against correlated leakage sources, requiring only the correlation range and lower bounds on the vacuum component of the prepared states. Our framework also applies to other QKD protocols, providing a general approach to address correlation-induced vulnerabilities. Simulations demonstrate the effectiveness of our protocol and its significantly superior tolerance to imperfections compared to existing protocols. This work provides a crucial step toward closing security loopholes in QKD, enhancing its practicality, and ensuring long-distance, high-performance secure communication under real-world constraints. Presenting a general finite-key framework and a secure QKD protocol, closing source correlation loopholes. INTRODUCTION With the rapid development and widespread adoption of the internet, information security has become one of the most critical issues in modern society. The modern cryptography, as the most widely used approach, ensures data privacy and security, but its security relies on computational complexity ( 1 ), which is threatened by advancing computing power, especially quantum computing ( 2 , 3 ). As countermeasures to the threats faced by modern cryptography, postquantum cryptography and quantum key distribution (QKD) ( 4 ) have been proposed. Among them, QKD is not based on computational hardness but instead relies on the fundamental principles of physics and, as a form of symmetric cryptography, can achieve theoretical security under appropriate assumptions. Consequently, QKD has attracted substantial attention as one of the major directions in the development of modern cryptography. QKD uses the principles of quantum mechanics to achieve information theoretic security in key agreement ( 5 – 8 ), which means that theoretically, even an eavesdropper with unlimited computational power cannot break its security. However, the theoretical security of QKD still faces challenges in practical deployments, especially when considering imperfections in real-world devices. Fortunately, all vulnerabilities related to measurement devices can be addressed using measurement device–independent QKD (MDI QKD) ( 9 – 11 ), as well as variants such as twin-field QKD (TF QKD) ( 12 – 15 ) and mode-pairing QKD (MP QKD) ( 16 ). However, the imperfections of the source still introduce potential security loopholes in practical QKD implementations, which require further resolution. The security loopholes caused by imperfect sources primarily stem from three aspects ( 17 ): state preparation flaws (SPFs) due to the limited modulation accuracy of the device, information leakage caused by side channels, and information leakage resulting from classical correlations between pulses. Here, we refer to a source exhibiting these three types of imperfections as correlated leakage source. Fortunately, several effective solutions for the SPF problem already exist ( 18 , 19 ). Moreover, based on the resolution of SPF, multiple approaches have also been proposed to address the side-channel issue ( 20 – 27 ). In particular, a recently proposed protocol, known as side-channel-secure QKD (SCS QKD) ( 28 – 31 ), is based on the sending-or-not-sending QKD (SNS QKD) ( 14 ) scheme. By imposing a lower bound constraint on the vacuum component of the transmitted states, SCS QKD is immune to all information leakage caused by any unknown side channels. Compared to device-independent QKD ( 32 ), SCS QKD is considered the only protocol secured under side channel that can be implemented with commercial devices while achieving long-distance transmission ( 33 ). However, compared to the well-studied side-channel problem, the impact of correlations on security remains less thoroughly investigated, leaving the QKD systems not completely secure under correlated leakage source. Now, the primary approaches for handling correlations include the postselection methods ( 34 – 36 ) and enhancing protocols ( 17 , 37 – 42 ), using mathematical techniques such as reference techniques ( 17 ) and quantum coin ( 42 ). Nevertheless, these methods have notable limitations, such as the inability of some protocols to handle high-order correlations, the need for complex modeling of the magnitude of correlation, and poor tolerance to existing device parameters. These factors make handling correlations in practice a challenging task, and only a few experiments have addressed the correlation problem for certain parameters ( 41 ). Moreover, none of these existing protocols provide a complete finite-key analysis, limiting their applicability in real-world QKD systems. To address these challenges, this paper makes two main contributions. First, we propose a security analysis framework for QKD under correlation. By extending and rearranging QKD rounds, using the generalized chain-rule result ( 43 ), we establish security constraints that allow for finite-key analysis in the presence of correlations. This security analysis framework applies to a broad class of protocols ranging from BB84 ( 4 – 8 ) to TF QKD ( 12 – 15 ), allowing correlation issues to be solved as the well-studied side-channel problems and providing a systematic approach toward fully resolving such issues. Second, we introduce a secure QKD against correlated leakage source based on the two-state SNS QKD ( 28 – 31 ). This protocol only assumes a bounded correlation range and a lower bound on the vacuum component of the prepared states, enabling secure key generation even in the presence of SPFs, side channels, and correlations. Compared to existing protocols, our security analysis framework is the first to enable finite-length analysis under correlation conditions, and this framework is not only applicable to our protocol but can also be easily extended to any protocol involving correlations. Moreover, our protocol does not require any characterization of the magnitude or the specific form of side channels and correlations. It can tolerate practical device imperfections and demonstrates strong robustness against high-order correlations. Simulation results show that our protocol can efficiently generate keys under realistic device parameters. When the correlation range is 5, it only loses 10 dB of the maximum attenuation, and it can tolerate a correlation range as high as 1000, far exceeding the maximum correlation range of 6 observed in existing experiments ( 44 ). This substantially enhances the security and practical feasibility of QKD systems under realistic physical constraints, marking a crucial step toward achieving loophole-free and high-performance QKD. RESULTS Security analysis framework addressing correlated sources In experiments, as summarized in Table 1 , correlations are commonly observed and can be characterized in terms of their range, form, and magnitude. Due to correlation, one of the most critical assumptions in QKD security proofs, independent distributed state preparation, is violated. This substantially complicates the security analysis, especially under finite-key conditions. In this work, we use the generalized chain-rule result ( 43 ) to prove the security equivalence between correlated sources and uncorrelated sources, effectively establishing a reduction from nonindependent scenarios to the independent case. Furthermore, through additional discussion, this equivalence can be extended to prove that any protocol with correlated leakage source, including correlations, side channels, and SPFs, can find a security bound to an independent and identically distributed (i.i.d.) protocol. Table 1. Current experimental measurement results on correlation of the real QKD systems. Range, correlation range, the maximum range to which the setting of one round can influence other rounds; Form, the specific form and dimensionality in which correlations manifest; Magnitude, the strength of the correlations, typically defined in terms of the relative deviation induced by correlations in quantities such as the inner product of quantum states or intensity. Range 1 ( 36 , 45 , 46 ) 2 ( 47 ) 3 ( 41 , 48 – 50 ) 6 ( 44 ) Form Intensity Intensity Intensity ( 41 , 48 – 50 ), phase ( 49 ), state ( 50 ) Intensity Magnitude O ( 10 − 1 ) ( 36 ), O ( 10 − 2 ) ( 45 , 46 ) O ( 10 − 2 ) O ( 10 − 2 ) ( 41 , 48 , 49 ), O ( 10 − 3 ) ( 50 ) O ( 10 − 2 ) Open in a new tab First, we give our basic assumption. We assume that the range of correlation is limited ( 17 , 36 – 41 ). The correlation range refers to the maximum number of previous rounds whose settings can influence the state preparation in a given round. This assumption has been validated as reasonable by some experiments ( 36 , 41 , 44 – 50 ). Thus, we introduce the first assumption. Assumption 1. The correlation is constrained within a maximum range ξ . The security of a QKD protocol can be characterized by the conditional smooth min-entropy H min ϵ ( Z A ∣ E ′ ) ρ , where Z A refers to the raw key of Alice, E ′ refers to the uncertainty system of the eavesdropper Eve, and ρ represents the quantum state shared in the protocol, which includes Eve’s optimal attack system. We divide Z A into several subsets Z A = Z A 1 Z A 2 … Z A ξ + 1 , where Z A i represents the key sequence generated in the k th rounds of the protocol, where k ∈ { i + n ( ξ + 1 ) ∣ n ∈ ℕ 0 , i + n ( ξ + 1 ) ≤ N } . Because the correlation range ξ ensures that two keys separated by ξ rounds do not influence each other, Z A i and Z A j are independent from each other if i ≠ j . By the generalized chain-rule result ( 43 ) and data processing inequality, we can use H min ϵ i ( Z A i ∣ ( ∁ Z A Z A i ) E ′ ) ρ to estimate a lower bound for H min ϵ ( Z A ∣ E ′ ) ρ , where ( ∁ Z A Z A i ) represents the part of set Z A excluding Z A i , denoted as Z A 1 Z A 2 … Z A i − 1 Z A i + 1 … Z A ξ + 1 . Furthermore, we can relax the condition ∁ Z A Z A i in H min ϵ i ( Z A i ∣ ( ∁ Z A Z A i ) E ′ ) ρ even more. Define all of Alice’s local systems [including the raw key, (potential) basis selection, intensity selection, as well as ancillas control random drifts and fluctuations] as D A , and, similar to Z A , we divide it into D A = D A 1 D A 2 … D A ξ + 1 , where D A i represents the data in the k th rounds of the protocol, where k ∈ { i + n ( ξ + 1 ) ∣ n ∈ ℕ 0 , i + n ( ξ + 1 ) ≤ N } . From the definitions, there is Z A i ∈ D A i , and, further, we can calculate that ( ∁ Z A Z A i ) ∈ ( ∁ D A D A i ) , where ( ∁ D A D A i ) represents the part of set D A excluding D A i , denoted as D A 1 D A 2 … D A i − 1 D A i + 1 … D A ξ + 1 . Using data processing inequality, we can calculate that H min ϵ i ( Z A i ∣ ( ∁ Z A Z A i ) E ′ ) ρ i ′ ≥ H min ϵ i ( Z A i ∣ ( ∁ D A D A i ) E ′ ) ρ i ′ , where ρ i ′ denotes the quantum state in the protocol that include the space Z A i , ( ∁ D A D A i ) . Analyzing the entropy conditioned on ∁ D A D A i rather than on ∁ Z A Z A i allows us to work with a simpler quantum state based on pure states in the subsequent analysis, thereby facilitating the derivations that follow. The schematic diagram of the process is shown in Fig. 1 , and, from this, we can give our first lemma. Lemma 1. The lower bound of the smooth min-entropy H min ϵ ( Z A ∣ E ′ ) ρ of an original protocol with a maximum correlation range ξ can be bound by the sum of the smooth min-entropies H min ϵ i ( Z A i ∣ ( ∁ D A D A i ) E ′ ) ρ i ′ , where each H min ϵ i ( Z A i ∣ ( ∁ D A D A i ) E ′ ) ρ i ′ corresponds to the rounds in the original protocol that share the same modulo- ( ξ + 1 ) remainder, under the condition that all other rounds are made public. This relation satisfies H min ϵ ( Z A ∣ E ′ ) ρ ≥ ∑ i = 1 ξ + 1 [ H min ϵ i ( Z A i ∣ ( ∁ D A D A i ) E ′ ) ρ i ′ ] − ∑ i = 1 ξ ( f i ) (1) where f 1 = 2 log 2 1 ϵ − 2 ϵ 1 − ϵ 1 ′ , f i = 2 log 2 1 ϵ i − 1 ′ − 2 ϵ i − ϵ i ′ if i ∈ [ 2 , ξ ] , ϵ ξ + 1 = ϵ ξ ′ . Fig. 1. Schematic diagrams of the original and new protocols. Open in a new tab ( A ) Each square represents a single round, with yellow, green, … , and blue indicating rounds mod ( ξ + 1 ) = 1 , 2 , … , ( ξ + 1 ) ( or 0 ) ; the rightward arrow represents the process of filtering raw key bits. The protocol proceeds from left to right for a total of N rounds, with each category being executed N i rounds. The definitions of D and Z are detailed in the “Security analysis framework addressing correlated sources” section. ( B ) Each square represents a single round, where colored squares indicate “key generation rounds,” and uncolored squares represent rounds where data are disclosed. Each pair of adjacent colored rounds is separated by ξ data disclosure rounds. Yellow, green, … , and blue correspond one to one with the rounds of the same colors in (A). The protocol proceeds from left to right, moving to the next row after completing one. A total of N ′ = N key generation rounds are executed, which corresponds to ( ξ + 1 ) N ′ rounds in total, with each category being executed N i ′ = N i rounds. The definitions of D ′ and Z ′ are detailed in the “Security analysis framework addressing correlated sources” section. Proof. See Materials and Methods for details. Lemma 1 shows that the smooth min-entropy of a protocol with correlation can be bounded by the sum of the smooth min-entropies of its uncorrelated subcomponents. However, Lemma 1 cannot be directly used to compute a lower bound on the smooth min-entropy of the original protocol, because the subcomponents are required to be conditioned on the disclosure of the other parts. To address this, it is necessary to construct an uncorrelated protocol such that a certain part of it has the same smooth min-entropy as H min ϵ i ( Z A i ∣ ( ∁ D A D A i ) E ′ ) ρ i ′ , and, for this, we repeat the original protocol ξ + 1 times to form a new protocol. Therefore, the new protocol actually executes ( 1 + ξ ) N rounds, which we refer to as physical rounds. We stipulate that the new protocol uses only k th physical rounds for the QKD process, which we call key generation rounds, where k ∈ { ( i − 1 ) N + i + n ( ξ + 1 ) ∣ i ∈ ℕ , n ∈ ℕ 0 , i + n ( ξ + 1 ) ≤ N } , to keep the number of key generation rounds remain N , the same as the original protocol, while the left ξ N physical rounds not only send the prepared quantum states through the channel but also publicly disclose all their data (all local ancillas or their measurement results, due to the requirements of the specific protocol), which we call leakage rounds. Similar to Z A , the raw key bits of Alice in the new protocol, denoted as Z A ′ , can be categorized into ξ types and represented as Z A ′ = Z A 1 ′ Z A 2 ′ … Z A ξ + 1 ′ , where Z A i ′ represents the key sequence generated in the k th key generation round of the protocol, where k ∈ { ( i − 1 ) N + i + n ( ξ + 1 ) ∣ n ∈ ℕ 0 , i + n ( ξ + 1 ) ≤ N } . From the above discussion, we can also obtain that Z A i and Z A i ′ correspond one to one. This correspondence is intuitively illustrated in Fig. 1 , where the rounds of the original protocol are marked with the same color as the key generation rounds in the new protocol, while the leakage rounds are marked in white. For clarity, in summary, we give the definition of the new protocol. Definition 1. For any original protocol with a maximum correlation range ξ , we define a corresponding new protocol by repeating the original protocol ξ + 1 times. In the i th repetition, only the rounds whose indices satisfy modulo ξ + 1 congruent to i (with the remainder ξ + 1 interpreted as 0 ) are used for key generation, while all other rounds are disclosed. The raw key of original protocol is denoted by Z A , the raw key of the i th repetition of the new protocol is denoted by Z A i ′ , and the raw key of the whole new protocol is denoted by Z A ′ . Similarly, define D A ′ = D A 1 ′ D A 2 ′ … D A ξ + 1 ′ as the data from all disclosed rounds, where D A i ′ denotes the data revealed in the public rounds during the i th repetition of the original protocol. In the new protocol, all information D A ′ is fully disclosed to treat these leakage rounds, together with their state preparation and auxiliary systems, as a side channel of the key generation rounds, thereby constructing the new protocol in which the local auxiliary systems contain only essential to the QKD process in the key generation rounds. Moreover, this construction is conducive to formulating a convenient pure state description for the analysis. In the new protocol, there exists an attack by Eve such that the joint density matrix of the raw key of the new protocol, the system of the leakage rounds and Eve’s system, satisfies ⊗ i = 1 ξ + 1 ρ i ″ , where ρ i ″ is the density matrix of the rounds that generalize Z A i ′ and satisfies ρ i ″ = ρ i ″ . Thus we have H min ϵ ˜ i ( Z A i ∣ ( ∁ D A D A i ) E ′ ) ρ i ′ = H min ϵ ˜ i ( Z A i ′ ∣ D A i ′ E ′ ) ρ i ″ . Recall that the new protocol to publicly disclose all ancillas (or their measurement results) in leakage rounds and Eve’s optimal attack will also yield a smaller smooth min-entropy. Thus, we can calculate that H min ϵ ˜ i ( Z A i ′ ∣ D A i ′ E ′ ) ρ i ″ ≥ H min ϵ ˜ i ( Z A i ′ ∣ E ′ ) ρ ′ , where ρ ′ denotes the total quantum state of the raw key of the new protocol and Eve’s system. Thus, we give our second Lemma. Lemma 2 The lower bound of the smooth min-entropy H min ϵ ( Z A ∣ E ′ ) ρ of an original protocol with a maximum correlation range ξ can be bound by the sum of the smooth min-entropy H min ϵ ˜ i ( Z A i ′ ∣ E ′ ) ρ ′ of parts of the new protocol, where the definition of new protocol is in Definition 1 . This relation satisfies H min ϵ ( Z A ∣ E ′ ) ρ ≥ ∑ i = 1 ξ + 1 [ H min ϵ i ( Z A i ′ ∣ E ′ ) ρ ′ ] − ∑ i = 1 ξ ( f i ) (2) where f 1 = 2 log 2 1 ϵ − 2 ϵ 1 − ϵ 1 ′ , f i = 2 log 2 1 ϵ i − 1 ′ − 2 ϵ i − ϵ i ′ if i ∈ [ 2 , ξ ] , ϵ ξ + 1 = ϵ ξ ′ . Proof. See Materials and Methods for details. Lemma 2 has already established a security constraint that connects a correlated protocol to an uncorrelated one. However, Lemma 2 requires estimating the smooth min-entropy of several subcomponents of the new protocol individually, which undoubtedly increases both the complexity and the impact of statistical fluctuations in the data. Therefore, a more effective approach is to further aggregate these parts and estimate them using the overall phase error rate. For most protocols, the smooth min-entropy can be estimated only for specific events, such as single-photon events in typical BB84 and MDI protocols, while multiphoton events cannot be directly estimated. Thus, it is necessary to apply the chain-rule result ( 43 ) once again to bound H min ϵ ˜ i ( Z A i ′ ∣ E ′ ) ρ ′ , using H min ϵ ˜ i ′ ( Z Z , A i ′ ∣ E ′ ) ρ ′ , where Z A i ′ = Z Z , A i ′ Z X , A i ′ , in which Z Z , A i ′ denotes the parts that can estimated and Z X , A i ′ denotes the parts that cannot. Further, from the uncertainty relation and the parameter estimation of the QKD process ( 51 ), we can bound the H min ϵ ˜ i ′ ( Z Z , A i ′ ∣ E ′ ) ρ ′ using h ( e i ¯ ϵ i U ) , where e i ¯ ϵ i U is the upper bound of the phase error rate e i and h ( x ) = − x log 2 ( x ) − ( 1 − x ) log 2 ( 1 − x ) . Because the smooth min-entropy is estimated using the phase error rate, its physical meaning lies in estimating based on a given phase error rate, with the failure probability bounded by the square of the smoothing parameter ( 43 ). Given the fact that, if each Z Z , A i ′ estimation fails, then the estimation of Z Z , A ′ as a whole must also fail (and likewise for success), and, combining this with the convexity of h ( x ) , we can use the total phase error rate and the overall failure probability to estimate the sum of the smooth min-entropies of each part. Consequently, together with Lemma 2 , we can estimate the smooth min-entropy of the original protocol using the phase error rate of the newly constructed protocol, which gives us another lemma. Proposition 1. The lower bound of the smooth min-entropy H min ϵ ( Z A ∣ E ′ ) ρ of an original protocol with a maximum correlation range ξ can be bound by the upper bound of the estimation of phase error rate e ¯ ϵ ˆ U of the new protocol, where the definition of new protocol is in Definition 1 . This relation satisfies H min ϵ ( Z A ∣ E ′ ) ρ ≥ n ( 1 − h ( e ¯ ϵ ˆ U ) ) − ξ f − ( ξ + 1 ) f ′ (3) where ϵ , ϵ ˆ , and f satisfy ϵ ˆ = ( ϵ − ξ 1 2 f / 2 2 ξ + 1 − 1 2 f ′ / 2 ) ξ + 1 . Proof. See Materials and Methods for details. It is worth noting that, if all components of Z A can be used to estimate the phase error, then further scaling of Z A i ′ to Z Z , A i ′ is unnecessary. In this special case, we simply need to delete all terms containing f ′ from the conclusions in Eq. 3 , which results in a more compact estimate of the smooth min-entropy. Moreover, it is worth noting that, although our security proof requires a rearrangement of rounds as illustrated in Fig. 1 , this rearrangement is not necessary in the actual data processing of the final protocol. Because the rounds are independent after the transformation, we are free to rearrangement them again to restore their original sequence. Secure QKD against correlated leakage source After completing the security analysis framework, we will construct a secure QKD against correlated leakage source based on the two-state SNS protocol ( 28 – 31 ). To analyze the security, we impose a lower bound constraint on the vacuum component of the state sent by the source into the channel ( 28 – 31 ). The same constraint can be achieved through precharacterization, limiting the upper bounds of pulse intensities or other methods, and it has already been experimentally implemented ( 33 ). The specific assumption is as follows. Assumption 2. For the two-state SNS-QKD protocol, the lower bound of the proportion of vacuum states in each round, under both the send and not-send scenarios, is known. Specifically, given the i th round and its preceding ξ rounds, the state sent into the channel during the current round ρ r i − ξ i , a i − ξ i A ( B ) satisfies min r i − ξ i − 1 ( min a i − ξ i ( ∣ 〈 0 ∣ ρ r i − ξ i , a i − ξ i A ( B ) ∣ 0 〉 ∣ ) ) ≥ V r i A ( B ) (4) where r i ∈ { 0 , 1 } denotes the encoding setting in i th round; a i denotes the set of ancillas in the system that are potentially related to rounds and can influence the transmitted state, which includes controls over SPF, correlation, side channel, and so on; V r i A ( B ) denotes the lower bound of the proportion of vacuum states; and the sequence from i th to the j th round for a and r is defined as a i j ≔ a j a j − 1 … a i and r i j ≔ r j r j − 1 … r i , respectively. Following the above approach, we construct an equivalent protocol. Furthermore, by applying a unitary mapping to the transmitted states, we establish the security equivalence between the equivalent protocol and an i.i.d. protocol. On the basis of this, we can estimate the secret key rate. Before introducing the protocol, we first outline some fundamental requirements and definitions for its implementation. The protocol involves two users, Alice and Bob, as well as an untrusted node, Charlie. In each round, Alice and Bob attempt to prepare either a coherent state with a known intensity or a vacuum state, following the sending-or-not-sending strategy ( 14 , 28 – 31 ). However, due to the limitations of their sources, they can only generate quantum states that satisfy Assumptions 1 and 2 . For the untrusted node Charlie, if honest, she performs an interference measurement shown in Fig. 2 . Additionally, she must compensate for channel fluctuations so that constructive interference occurs at the left detector and destructive interference at the right detector. After all transmissions and measurements are completed, Alice and Bob negotiate to select a subset of rounds with probability p PE , marked as parameter estimation rounds, for parameter estimation, while the remaining rounds are marked as key extraction rounds. Furthermore, we need to define certain events, a Z event occurs when exactly one of Alice or Bob chooses r i = 0 , an O event occurs when both Alice and Bob choose r i = 0 , and a B event occurs when both Alice and Bob choose r i = 1 . Based on these definitions, our protocol proceeds as follows. Fig. 2. The schematic diagram of the protocol. Open in a new tab D L and D R represent the left and right detectors, respectively. SPD, single-photon detector; BS, 50:50 beam splitter; SNS-source, a system comprising a weak coherent source and modulation devices, satisfying Assumptions 1 and 2 . 1) State preparation: In the i th round ( i = 1 , 2 , … , N ), Alice and Bob each independently choose a bit setting r i ∈ R = { 0 , 1 } . Then, on the basis of the value of r i , they send the prepared quantum state with a known lower bound on its vacuum component (satisfying Assumptions 1 and 2 ) into the quantum channel, where they will be measured by an untrusted nod Charlie. 2) Measurement: If honest, the untrusted nod Charlie performs an interference measurement on the states sent by Alice and Bob in the i th round. If only the right detector clicks, Charlie records this event as a successful measurement. Charlie public whether each round is successful. 3) Parameter estimation: Through classical communication, Alice and Bob confirm the number of Z , O , and B events, denoted as n Z PE , n O PE , and n B PE , among all successful and parameter estimation rounds. They then determine the quantum bit error rate e bit and estimate the upper bound of phase error rate n ¯ ph and the lower bound of the number of Z n ¯ Z in the key extraction rounds (using method below). 4) Key distillation: Alice and Bob perform error correction and privacy amplification based on the results of the parameter estimation step and then use the data in the successful rounds to generate the secret keys. We consider the entanglement-equivalent protocol for N rounds. If there is an ideal source, then the protocol can be write as ∣ Φ 〉 ide = ∣ Φ 〉 A ide ⊗ ∣ Φ 〉 B ide ⊗ ∣ Φ 〉 PE (5) where ∣ Φ 〉 PE = [ ∑ m 1 N ( ∏ i = 1 N p m i PE ) ( ⊗ i = 1 N ∣ m i 〉 PE i ) ] denotes a set of auxiliaries used to determine whether a given round is selected for parameter estimation, m i = 1 indicates that the i th round is used for parameter estimation, while m i = 0 means it is not, and p 1 PE = 1 − p 0 PE = p PE ∣ Φ 〉 A ide = [ ∑ r 1 N ( ∏ i = 1 N p r i ) ( ⊗ i = 1 N ∣ r i 〉 A i ∣ ψ r i ide 〉 C i ) ] (6) where p r i is the probability of selecting r i , ∣ ψ r i ide 〉 C i denotes the ideal encoded coherent state with selected state r i to be send into channel, and ∣ Φ 〉 B ide is similar to Eq. 6 . However, in the following discussion, we omit ∣ Φ 〉 PE , as it is an auxiliary tag negotiated by Alice and Bob after state transmission that introduces no imperfections and is tensor producted with the remaining transmitted part; therefore, all transformations do not involve this component. For the protocol is ideal, we have that ∣ ψ 0 ide 〉 C i = ∣ 0 〉 and ∣ ψ 1 ide 〉 C i = ∣ μ 〉 , where ∣ 0 〉 and ∣ μ 〉 denote the ideal coherent state without any imperfections. Protocols like those in Eq. 6 have been proved secure ( 28 – 31 ); however, if the source is imperfect, then the form will be more complex. As we have discussed in Assumption 2 , instead of ∣ ψ r i ide 〉 C i , Alice’s source send ρ r i − ξ i , a i − ξ i A . Consider a protocol that sends the purification ψ r i − ξ i , a i − ξ i imp C i of ρ r i − ξ i , a i − ξ i A into the channel, the security of this protocol can ensure the security of the protocol that sends ρ r i − ξ i , a i − ξ i A . Thus, if the source is imperfect, then the entanglement-equivalent protocol of Alice’s side Eq. 6 will become ∣ Φ 〉 A = [ ∑ r 1 N a 1 N ( ∏ i = 1 N p r i q a i ) ( ⊗ i = 1 N ∣ r i 〉 A i ∣ a i 〉 A i ″ ∣ ψ r i − ξ i , a i − ξ i imp 〉 C i ) ] (7) where q a i is the probability of selecting a i . Treat the protocol in Eq. 7 as the original protocol described in the “Security analysis framework addressing correlated sources” section, and, then, the new protocol without correlation can be expressed as ∣ Φ 〉 A new = ∑ r ′ 1 ξ N ∑ a 1 ( 1 + ξ ) N ( ∏ i = 1 ξ N p r i ′ ∏ j = 1 ( 1 + ξ ) N q a j ) ( ⊗ i = 1 ξ N ∣ r i ′ 〉 A i ′ ⊗ j = 1 ( 1 + ξ ) N ∣ a j 〉 A j ″ ) ⊗ [ ∑ r 1 N ( ∏ i = 1 N p r i ) ( ⊗ i = 1 N ∣ r i 〉 A i ∣ ψ r i , r ′ ( i , ξ ) , a ( i , ξ ) imp ′ 〉 C i ′ ) ] (8) where r ′ ( i , ξ ) denotes the local ancilla in the previous ξ physical rounds and the following ξ physical rounds of the i th key generation round, a ( i , ξ ) denotes the system ancilla of the up mentioned physical rounds and the i th key generation round, and ∣ ψ r i , r ′ ( i , ξ ) , a ( i , ξ ) imp ′ 〉 C i ′ denotes the state sent into the channel in the i th key generation round and the following ξ physical rounds (detailed in Materials and Methods and Supplementary Text). As we have discussed, the new protocol reveals all physical rounds except the key generation rounds. Furthermore, because the security of the original protocol is constrained by that of the new protocol, we can relax the assumptions on the new protocol. Therefore, we further disclose the ancilla in the space A i ″ for all physical rounds and assume that Alice sends additional quantum states into the channel. Thus, for any additional state ∣ ψ r i , r ′ ( i , ξ ) , a ( i , ξ ) add 〉 C i ″ sent into the channel, we have a protocol ∣ Φ 〉 A new 2 that, based on ∣ Φ 〉 A new sending ∣ ψ r i , r ′ ( i , ξ ) , a ( i , ξ ) imp ′ 〉 C i ′ in Eq. 8 , instead sends ∣ ψ r i , r ′ ( i , ξ ) , a ( i , ξ ) imp ′ 〉 C i ′ ∣ ψ r i , r ′ ( i , ξ ) , a ( i , ξ ) add 〉 C i ″ . Then, the security of protocol ∣ Φ 〉 A new in Eq. 8 can be guaranteed by protocol ∣ Φ 〉 A new 2 . Further, we can prove that there exist a set of additional state ∣ ψ r i , r ′ ( i , ξ ) , a ( i , ξ ) add 〉 C i ″ and a unitary mapping U acting in space ⊗ i = 1 ξN A i ′ ⊗ j = 1 ( 1 + ξ ) N A j ″ ⊗ i = 1 N C i ′ C i ″ that makes protocol ∣ Φ 〉 A new 2 become an equivalent protocol ∣ Φ 〉 A equ , which is i.i.d. and ( ⊗ i = 1 ξ N ∣ r i ′ 〉 A i ′ ⊗ j = 1 ( 1 + ξ ) N ∣ a j 〉 A j ″ ) no longer appears entangled within the protocol but instead appears in a tensor product form. Thus, because r ′ and a no longer play any role, we simplify the equivalent protocol ∣ Φ 〉 A equ by removing them. The final equivalent protocol then satisfies ∣ Φ 〉 A equ = [ ∑ r 1 N ( ∏ i = 1 N p r i ) ( ⊗ i = 1 N ∣ r i 〉 A i ∣ ψ r i equ 〉 C i ‴ ) ] (9) where ∣ ψ 0 equ 〉 C i ‴ = ∣ 0 〉 and ∣ ψ 1 equ 〉 C i ‴ = ∣ μ equ 〉 , where ∣ 0 〉 is the vacuum state and ∣ μ equ 〉 is the coherent state with an average number of photons equals to μ equ , satisfies e − μ equ = [ V 0 A , ξ V 1 A , ξ − ( 1 − V 0 A , ξ ) ( 1 − V 1 A , ξ ) ] 2 and V r i A , ξ = V r i A ( p 0 V 0 A + p 1 V 1 A ) 2 ξ (detailed in Materials and Methods and Supplementary Text). The above analysis is also applicable to Bob’s side. In this case, we can conclude that a two-state SNS-QKD protocol satisfying Assumptions 1 and 2 , including the presence of SPFs, side channels, and correlations, has its minimum smooth entropy constrained by the phase error rate of the equivalent protocol under the same measurement outcomes. In addition, the equivalent protocol ultimately satisfies ∣ Φ 〉 equ = [ ∑ r 1 N ( ∏ i = 1 N p r i ) ( ⊗ i = 1 N ∣ r i 〉 A i ∣ ψ r i Aequ 〉 C i A ) ] ⊗ [ ∑ r 1 N ( ∏ i = 1 N p r i ) ( ⊗ i = 1 N ∣ r i 〉 B i ∣ ψ r i Bequ 〉 C i B ) ] ⊗ ∣ Φ 〉 PE (10) where ∣ ψ 0 A ( B ) equ 〉 C i A ( B ) = ∣ 0 〉 , ∣ ψ 1 A ( B ) equ 〉 C i A ( B ) = ∣ μ equ A ( B ) 〉 , and e − μ equ A ( B ) = [ V 0 A ( B ) , ξ V 1 A ( B ) , ξ − ( 1 − V 0 A ( B ) , ξ ) ( 1 − V 1 A ( B ) , ξ ) ] 2 , V r i A ( B ) , ξ = V r i A ( B ) ( p 0 V 0 A ( B ) + p 1 V 1 A ( B ) ) 2 ξ , and, at this step, we recall the auxiliary particle ∣ Φ 〉 PE , which indicates whether the rounds are selected for parameter estimation. After completing the above analysis, from Proposition 1 , we still need to estimate the phase error rate of the equivalent protocol ∣ Φ 〉 equ to derive our final key rate formula. Now, the security of protocols similar to that in Eq. 10 has already been proven within the framework of SCS QKD ( 28 – 31 , 52 ). We choose to use postselection security analysis ( 31 , 53 ). For a two-state SNS QKD described in Eq. 10 , under collective attack, we can calculate the upper bound of phase error probability P ph , satisfies P ph ≤ p 1 p 0 2 c 0 2 P O ( p 0 ) 2 + c 1 2 P B ( p 1 ) 2 + c ¯ 2 2 + 2 c 0 c 1 P O P B ( p 0 ) 2 ( p 1 ) 2 + c 0 c ¯ 2 P O ( p 0 ) 2 + c 1 c ¯ 2 P B ( p 1 ) 2 (11) where P O and P B are the probabilities of the O event and the B event of key extraction rounds (detailed in Materials and Methods). Noting that obtaining Eq. 11 requires the assumption that Eve’s attack is a collective attack, we can conclude that the measurement outcome probabilities are identical for all rounds. Moreover, we cannot directly obtain the number n O and n B of the O events and the B events in the key extraction rounds; instead, we can only calculate n O PE and n B PE . In addition, because of Eve performs a collective attack, P O / ( 1 − p PE ) and P B / ( 1 − p PE ) are equal to the corresponding portions from the parameter estimation rounds, which are denoted as P O PE / p PE and P B PE / p PE . Therefore, using the Chernoff bound ( 54 , 55 ), we can separately estimate their upper bounds such that P O = ( ( 1 − p PE ) / p PE ) P O PE ≤ ( ( 1 − p PE ) / p PE ) Cher ¯ ( n O PE , ϵ ph ) / N , P B = ( ( 1 − p PE ) / p PE ) P B PE ≤ P B = ( ( 1 − p PE ) / p PE ) P B PE ≤ ( ( 1 − p PE ) / p PE ) Cher ¯ ( n B PE , ϵ ph ) / N , where Cher ¯ ( ⋅ , ϵ ) is the upper bound of the expectation estimated from the observation with a failure probability ϵ ( 31 ) and satisfies Cher ¯ ( X , ϵ x ) = X + ln 1 ϵ x + ln 2 1 ϵ x + 2 X ln 1 ϵ x , Cher ¯ ( X , ϵ x ) = X + 1 2 ln 1 ϵ x − 1 2 ln 2 1 ϵ x + 8 X ln 1 ϵ x . Consequently, the phase error number satisfies n ph ≤ n ¯ ph = cher ¯ ( NP ph , ϵ ph ) , where cher ¯ ( ⋅ , ϵ ) is the upper bound of the observation estimated from the expectation with a failure probability ϵ ( 31 ) and satisfies cher ¯ ( E , ϵ x ) = E + 1 2 ln 1 ϵ x + 1 2 ln 2 1 ϵ x + 8 E ln 1 ϵ x , cher ¯ ( E , ϵ x ) = E − 2 E ln 1 ϵ x . Then, by using the de Finetti reduction with fixed marginal ( 56 ), we can extend the phase error estimation to the case of Eve’s coherent attacks by appropriately increasing the failure probability of the estimation of n ¯ ph ( 31 ). Specifically, in the case of Eve’s coherent attacks, the upper bound of the phase error with the failure probability ϵ ph satisfies n ¯ ph c , ϵ ph = cher ¯ ( NP ph , ϵ ph 3 g N , 64 ) (12) where g N , x = ( N + x − 1 N ) ≤ ( e ( N + x − 1 ) x − 1 ) x − 1 ( 56 ), and x is the square of the dimension of Alice, Bob, and Charlie, which here we choose x = d A 2 d B 2 d C 2 d PE 2 = 2 2 × 2 2 × 2 2 × 2 2 = 256 ( 31 ). Moreover, we cannot directly measure the number n Z of Z events and in the key extraction rounds. Instead, we estimate them using the corresponding occurrences in the parameter estimation rounds. By applying the Chernoff bound ( 54 , 55 ), we can calculate p PE ( n Z + n Z PE ) ≥ Cher ¯ ( n Z PE , ϵ Z ) . Thus, the lower bound of n Z with failure probability ϵ Z satisfies n ¯ Z ϵ Z = Cher ¯ ( n Z PE , ϵ Z ) p PE − n Z PE (13) Recall the original protocol, because of the property of the two-universal hash function ( 57 ), if the secure key have a length l with ϵ tot secure, then l = H min ϵ ( Z ∣ E ) − 2 log 2 1 2 ϵ ¯ with ϵ tot = 2 ϵ + ϵ ¯ . Next, consider the error correction process. Suppose fn Z h ( e bit ) classical bits are consumed during error correction, where f is the efficiency of the error correction. If the key is ϵ cor correct, then a hash with length log 2 2 ϵ cor must be announced for error correction. Then, the key length become l = H min ϵ ( Z ∣ E ′ ) − fn Z h ( e bit ) − log 2 2 ϵ cor − 2 log 2 1 2 ϵ ¯ (14) where ϵ tot = 2 ϵ + ϵ ¯ + ϵ cor and E is Eve’s system before the error correction ( 51 ). Due to the conclusion in Eq. 14 , the final key rate length is transformed into an estimation problem for the smooth min-entropy of Z in the original protocol. We can apply the conclusions from Proposition 1 to convert this problem into an estimation of phase errors in the equivalent protocol, completing the key rate estimation. From Eqs. 12 and 13 and according to Eq. 3 , we can obtain that H min ϵ ( Z ∣ E ′ ) ≥ n ¯ Z ϵ 0 ( 1 − h ( n ¯ ph c , ( ϵ 1 ) 2 n ¯ Z ϵ 0 ) ) − 2 ξ log 2 1 ϵ 2 − 2 ( ξ + 1 ) log 2 1 ϵ 3 (15) then we can calculate the key length l max that satisfies l max = n ¯ Z ϵ 0 ( 1 − h ( n ¯ ph c , ( ϵ 1 ) 2 n ¯ Z ϵ 0 ) ) − fn Z h ( e bit ) − log 2 2 ϵ cor − 2 log 2 1 2 ϵ ¯ − 2 ξ log 2 1 ϵ 2 − 2 ( ξ + 1 ) log 2 1 ϵ 3 (16) where n ¯ ph c , ( ϵ 1 ) 2 satisfies Eq. 12 , n ¯ Z ϵ 0 satisfies Eq. 13 , and ϵ tot = 2 ϵ + ϵ ¯ + ϵ cor + ϵ 0 and ϵ 1 = ( ϵ − ξ ϵ 2 2 ξ + 1 − ϵ 3 ) ξ + 1 . Simulation result of correlated leakage source secure QKD Through simulations, we can verify the performance of our protocol. Specifically, we set the misalignment error rate to 1%, the detector dark count rate to p d = 10 − 9 bit per pulse, the error correction efficiency to f = 1.16 , the extinction ratio between sending and nonsending intensities to 1/1000 ( 45 , 46 ), and the security parameter to ϵ tot = 10 − 10 . For the specific security parameters, we set ϵ = ϵ ¯ = ϵ cor = ϵ 0 = ϵ tot / 5 and ϵ 2 = ϵ 3 = ϵ 2 . Further, we assume that the attenuation from Alice and Bob to the interference node is identical, and they have the same upper bound of the intensity, the range of correlations, as well as the sending probabilities. By optimizing the sending probability and upper bound of intensity, we obtain the attenuation-key rate curves for different correlation ranges ξ . Figures 3 and 4 show the numerical simulations results of our protocol. In Fig. 3 , we consider two common scenarios where the total number of pulses sent by Alice or Bob, N , which leads to the finite-length effect, is set to 10 12 and 10 14 , corresponding to Fig. 3 (A and B) , respectively. In both cases, we observe that, when there is no correlation (i.e., ξ = 0 ), our protocol, according to the analysis in our manuscript, reduces to the existing SCS-QKD protocol, and the simulation results align with those of SCS-QKD. Additionally, we find that the smaller the correlation range ξ , the greater its impact on the key rate and the maximal transmission attenuation. For N = 10 12 , increasing the correlation range from ξ = 0 to 1 results in a maximum attenuation loss of about 9 dB, while increasing the correlation range from ξ = 1 to 5 also leads to an additional 9 dB too. Furthermore, in the cases of N = 10 12 and 10 14 , we simulate correlation ranges up to ξ = 100 and 500, respectively. In Fig. 4 , we consider a scenario with a larger N . By setting N = 2 × 10 15 , we find that our protocol can still generate keys even when the correlation range is very large, reaching up to ξ = 1000 . Fig. 3. The simulation result of the performance of our protocol. Open in a new tab We set the misalignment error rate to 1%, detector dark count rate to p d = 10 − 9 bit per pulse, the error correction efficiency to f = 1.16 , the extinction ratio between sending and nonsending intensities to 1/1000, and the security parameter to ϵ tot = 10 − 10 . ( A ) Secret key rate when N = 10 12 . ( B ) Secret key rate when N = 10 14 . Fig. 4. The simulation result of the performance of our protocol when N = 2 × 10 15 . Open in a new tab We set the misalignment error rate to 1%, detector dark count rate to p d = 10 − 9 bit per pulse, the error correction efficiency to f = 1.16 , the extinction ratio between sending and nonsending intensities to 1/1000, and the security parameter to ϵ tot = 10 − 10 . DISCUSSION We have addressed a critical security challenge in practical QKD with correlated leakage source. We first proposed a security analysis framework that allows for finite-key analysis in the presence of correlations by extending and rearranging QKD rounds and applying the generalized chain rule. Furthermore, we introduced a secure QKD against correlated leakage source, extending SCS QKD to scenarios where SPFs, side channels, and correlations coexist. By characterizing the correlation range ξ and imposing a lower bound on the vacuum component of the transmitted states of the correlated leakage source, we effectively address the security loopholes introduced by source imperfections. Unlike existing approaches, our protocol does not require explicit characterization or magnitudes of correlation and side channel, making it more practical for real-world QKD systems. Our simulation results demonstrate the protocol’s strong robustness, effectiveness, and reliability, especially against very high order correlations. From the simulation results, we can see that our protocol substantially improves tolerance to correlation range compared to existing protocols. Most existing protocols require prior knowledge of not only the correlation range but also the further characterization of both correlation and side channel before conducting security analysis ( 17 , 36 – 41 ). Even for very small correlation levels, the analyzable correlation range typically does not exceed ξ = 10 . Moreover, existing experiments that measure correlation generally suggest that the correlation range ξ is primarily concentrated between 1 and 3 ( 36 , 41 , 45 – 50 ), with the worst case scenarios reaching only up to ξ = 6 ( 44 ). Simulation results show that our protocol can handle a correlation range far beyond that of existing protocols and can encompass all now measured correlation parameters of real devices and systems. Under practical device parameters ( 36 , 41 , 44 – 50 , 58 , 59 ), most existing protocols struggle to generate secure keys, with only a few achieving this through correlation suppression, special encoding structures, or source monitor module ( 41 ). In contrast, our protocol only requires characterization of the correlation range without the need for complex additional steps. Furthermore, current correlation analysis protocols have not yet incorporated finite-length effects, whereas our protocol is the first to achieve this. Compared to existing solutions, our framework and protocol substantially enhance the security and feasibility of QKD under realistic device imperfections. To avoid explicitly characterizing the magnitude and specific form of the SPF, side channel, and correlation, our protocol deliberately incurs the cost of a linear secret key rate scaling. While the underlying security analysis framework is, in principle, extensible to protocols such as MP QKD and TF QKD ( 12 – 16 ), surpassing the linear bound would require additional characterization of correlations across multiple source degrees of freedom tailored for those protocols. In addition, it seems that there are few experimental works on the source characterization for MP QKD and TF QKD, as far as we know. Therefore, retaining a linear key-rate scaling (not covering MP QKD and TF QKD) represents a reasonable and necessary trade-off at the present stage. However, once certain improvements are made to the existing characterization methods for characterizing correlation and side channel ( 36 , 41 , 44 – 50 ) (or example, by providing a complete and simultaneous quantification of the correlation magnitudes in the intensity, phase, and state preparation degrees), our framework also holds the potential to address such issues beyond the linear bound. Moreover, once characterization techniques are incorporated, both our protocol and prospective improved variants for TF QKD can be implemented under current experimental conditions, enabling a final treatment of correlation problems. As modern society’s demand for data security continues to grow, ensuring the secure deployment of QKD has become an urgent challenge. By adopting our security analysis framework, the final security barrier, correlations, can now be effectively addressed under finite-key conditions. Furthermore, with our correlated leakage source secure protocol, all security loopholes in QKD can be closed through a simple characterization of the source, paving the way for practical and truly secure QKD implementations. This represents an important advancement toward closing security loopholes in QKD and achieving high-performance, real-world implementations. Future research could further explore optimizing key rates under correlated conditions and extending the framework to other QKD protocols to enhance their practical security. MATERIALS AND METHODS Proof of Lemma 1 and 2 Recall the definitions in the “Security analysis framework addressing correlated sources” section in Results; by the generalized chain-rule result ( 43 ) and data processing inequality, we can obtain that H min ϵ ( Z A ∣ E ′ ) ρ = H min ϵ ( Z A 1 Z A 2 … Z A ξ + 1 ∣ E ′ ) ρ ≥ H min ϵ 1 ( Z A 1 ∣ Z A 2 Z A 3 … Z A ξ + 1 E ′ ) ρ + H min ϵ 1 ′ ( Z A 2 … Z A ξ + 1 ∣ E ′ ) ρ − f 1 ≥ H min ϵ 1 ( Z A 1 ∣ Z A 2 Z A 3 … Z A ξ + 1 E ′ ) ρ + H min ϵ 1 ′ ( Z A 2 … Z A ξ + 1 ∣ Z A 1 E ′ ) ρ − f 1 ≥ H min ϵ 1 ( Z A 1 ∣ Z A 2 Z A 3 … Z A ξ + 1 E ′ ) ρ − f 1 + H min ϵ 2 ( Z A 2 ∣ Z A 1 Z A 3 Z A 4 … Z A ξ + 1 E ′ ) ρ − f 2 + H min ϵ 2 ′ ( Z A 3 Z A 4 … Z A ξ + 1 ∣ Z A 1 Z A 2 E ′ ) ρ ≥ … ≥ ∑ i = 1 ξ + 1 [ H min ϵ i ( Z A i ∣ ( ∁ Z A Z A i ) E ′ ) ρ ] − ∑ i = 1 ξ ( f i ) (17) where f 1 = 2 log 2 1 ϵ − 2 ϵ 1 − ϵ 1 ′ , f i = 2 log 2 1 ϵ i − 1 ′ − 2 ϵ i − ϵ 1 ′ if i ∈ [ 2 , ξ ] , ϵ ξ + 1 = ϵ ξ ′ . Because ( ∁ Z A Z A i ) ∈ ( ∁ D A D A i ) , using data processing inequality, we can calculate that H min ϵ i ( Z A i ∣ ( ∁ Z A Z A i ) E ′ ) ρ = H min ϵ i ( Z A i ∣ ( ∁ Z A Z A i ) E ′ ) ρ i ′ ≥ H min ϵ i ( Z A i ∣ ( ∁ D A D A i ) E ′ ) ρ i ′ (18) where ρ i ′ denotes the quantum state in the protocol that include the space Z A i , ( ∁ D A D A i ) , and E ′ , and ρ = Tr ( ∁ ( ∁ D A D A i ) ( ∁ Z A Z A i ) ) ρ i ′ . Thus, we can prove that, in the original protocol, there is H min ϵ ( Z A ∣ E ′ ) ρ ≥ ∑ i = 1 ξ + 1 [ H min ϵ i ( Z A i ∣ ( ∁ D A D A i ) E ′ ) ρ i ′ ] − ∑ i = 1 ξ ( f i ) (19) In addition, this leads us to Lemma 1 . Combined with the fact that H min ϵ ˜ i ( Z A i ′ ∣ D A i ′ E ′ ) ρ i ″ ≥ H min ϵ ˜ i ( Z A i ′ ∣ E ′ ) ρ ′ , we can calculate H min ϵ ( Z A ∣ E ′ ) ρ ≥ ∑ i = 1 ξ + 1 [ H min ϵ i ( Z A i ′ ∣ E ′ ) ρ ′ ] − ∑ i = 1 ξ ( f i ) (20) where f 1 = 2 log 2 1 ϵ − 2 ϵ 1 − ϵ 1 ′ , f i = 2 log 2 1 ϵ i − 1 ′ − 2 ϵ i − ϵ i ′ if i ∈ [ 2 , ξ ] , ϵ ξ + 1 = ϵ ξ ′ , and this leads us to Lemma 2 . Proof of Proposition 1 As we have discussed in the “Security analysis framework addressing correlated sources” section in Results, for most protocols, the smooth min-entropy can be estimated only for specific events in Z . In this case, by applying the chain-rule result ( 43 ) once again, we can obtain H min ϵ ˜ i ( Z A i ′ ∣ E ′ ) ρ ′ ≥ H min ϵ ˜ i ′ ( Z Z , A i ′ ∣ E ′ ) ρ ′ + H min ϵ ˜ i ″ ( Z X , A i ′ ∣ Z Z , A i ′ E ′ ) ρ ′ + f i ′ ≥ H min ϵ ˜ i ′ ( Z Z , A i ′ ∣ E ′ ) ρ ′ + f i ′ (21) where Z A i ′ = Z Z , A i ′ Z X , A i ′ , in which Z Z , A i ′ denotes the parts that can estimated and Z X , A i ′ denotes the parts that cannot; by setting ϵ ˜ i ″ = 0 , f i ′ then satisfies f i ′ = 2 log 2 1 ϵ ˜ i − ϵ ˜ i ′ . From the uncertainty relation and the parameter estimation of the QKD process ( 51 ), it is known that H min ϵ ˜ i ′ ( Z Z , A i ′ ∣ E ′ ) ρ ′ ≥ n i ( 1 − h ( e i ¯ ϵ ˜ i ′ U ) ) (22) where h ( x ) = − x log 2 ( x ) − ( 1 − x ) log 2 ( 1 − x ) , n i is the number of bits in Z Z , A i ′ , and e i ¯ ϵ i U is the upper bound of the phase error rate e i with the probability p fail i of phase errors exceeding this bound that satisfies p fail i = ( ϵ ˜ i ′ ) 2 . For Z A i ′ , let it contain n = ∑ i = 1 ξ + 1 n i bits, and let the phase error rate be e , satisfying e = ( ∑ i = 1 ξ + 1 n i e i ) / ( ∑ i = 1 ξ + 1 n i ) . Also, let p fail be the probability of phase error rate e exceeding the bound ( ∑ i = 1 ξ + 1 n i e i ¯ ϵ ˜ i ′ U ) / ( ∑ i = 1 ξ + 1 n i ) . Through discussions related to probability theory, we find that, if each e i exceeds its upper bound, then e must exceed its upper bound; conversely, if none of the e i ’s exceed their upper bound, then e must also not exceed its upper bound. Therefore, we can derive the relationship between these probabilities as ∏ p fail i ≤ p fail ≤ 1 − ∏ ( 1 − p fail i ) . Therefore, because e ¯ ϵ U is monotonically decreasing with respect to ϵ , we can conclude that e ¯ ∏ i = 1 ξ + 1 ϵ ˜ i ′ U ≥ ∑ i = 1 ξ + 1 n i e i ¯ ϵ ˜ i ′ U ∑ i = 1 ξ + 1 n i (23) Thus, combined with the concavity of the h ( x ) function, we can obtain that ∑ i = 1 ξ + 1 H min ϵ ˜ i ′ ( Z Z , A i ′ ∣ E ′ ) ρ ′ ≥ ( ∑ i = 1 ξ + 1 n i ) ( 1 − h ( ∑ i = 1 ξ + 1 n i e i ¯ ϵ ˜ i ′ U ∑ i = 1 ξ + 1 n i ) ) ≥ n ( 1 − h ( e ¯ ϵ ′ U ) ) (24) where ϵ ′ = ∏ i = 1 ξ + 1 ϵ ˜ i ′ . Combining Lemma 2 and Eqs. 21 and 24 and without loss of generality taking ϵ ˜ i = ϵ i , f i = f j , ϵ ˜ i ′ = ϵ ˜ j ′ , and ϵ i = ϵ j , we can conclude that the minimum smooth entropy of the original protocol and the upper bound of the phase error estimated in the new protocol satisfy H min ϵ ( Z A ∣ E ′ ) ρ ≥ n ( 1 − h ( e ¯ ϵ ˆ U ) ) − ξ f − ( ξ + 1 ) f ′ (25) where ϵ , ϵ ˆ , and f satisfy ϵ ˆ = ( ϵ − ξ 1 2 f / 2 2 ξ + 1 − 1 2 f ′ / 2 ) ξ + 1 , and this leads us to Proposition 1 . Proof that ∣ Φ 〉 A equ ensures the security of ∣ Φ 〉 A The key of the secure proof of the secure QKD against correlated leakage source is to prove that ∣ Φ 〉 A equ ensures the security of ∣ Φ 〉 A . We begin by considering the simplest case, where the correlation range ξ = 1 , and the total number of rounds N is even. The more general case is discussed in the Supplementary Text. First, we will remove the correlation with the conclusion mentioned in Proposition 1 . Treat the protocol in Eq. 7 as the original protocol described in Proposition 1 , and, then, the new protocol without correlation can be expressed as ∣ Φ 〉 A new = ∣ Φ 〉 A 1 ⊗ ∣ Φ 〉 A 2 (26) where ∣ Φ 〉 A 1 = ∑ r 1 N 2 r ′ 1 N 2 a 1 N ( ∏ i = 1 N 2 p r i p r i ′ ∏ j = 1 N q a j ) ( ⊗ i = 1 N 2 ∣ r i ′ 〉 A i ′ ⊗ j = 1 N ∣ a i 〉 A i ′ ′ ) ⊗ i = 1 N 2 ∣ r i 〉 A i ∣ ψ r i , r ′ ( i , 1 ) , a ( i , 1 ) imp ′ 〉 C i ′ denotes the entanglement-equivalent protocol for the first time of N QKD rounds and ∣ Φ 〉 A 2 = ∑ r N 2 + 1 N r ′ N 2 + 1 N a n + 1 2 N ∏ i = N 2 + 1 N p r i p r i ′ ∏ j = N + 1 2 N q a j ⊗ N 2 + 1 N ∣ r i ′ 〉 A i ′ ⊗ j = N + 1 2 N ∣ a i 〉 A i ′ ′ ⊗ N 2 + 1 N ∣ r i 〉 A i ∣ ψ r i , r ′ ( i , 1 ) , a ( i , 1 ) imp ′ 〉 C i ′ denotes the entanglement-equivalent protocol for the next time of N QKD rounds, where r i denotes the encoding ancilla in i th key generation rounds, r i ′ denotes the encoding ancilla in i th leakage rounds, a i denotes the purified ancilla in the i th physical rounds, and ∣ ψ r i , r ′ ( i , ξ ) , a ( i , ξ ) imp ′ 〉 C i ′ denotes the state sent into the channel in the i th key generation round and the following ξ physical rounds, where, in case ∣ Φ 〉 A 1 , r ′ ( i , 1 ) = r ′ i − 1 i , a ( i , 1 ) = a 2 i − 2 2 i , and, in case ∣ Φ 〉 A 2 , r ′ ( i , 1 ) = r ′ i i + 1 , a ( i , 1 ) = a 2 i − 1 2 i + 1 , satisfies ∣ ψ r i , r ′ ( i , 1 ) , a ( i , 1 ) imp ′ 〉 C i ′ = ∣ ψ r i r i − 1 ′ , a 2 i − 2 2 i − 1 imp 〉 C 2 i − 1 ∣ ψ r i ′ r i , a 2 i − 1 2 i imp 〉 C 2 i , in case ∣ Φ 〉 A 1 ∣ ψ r i r i ′ , a 2 i − 1 2 i imp 〉 C 2 i ∣ ψ r i + 1 ′ r i , a 2 i 2 i + 1 imp 〉 C 2 i + 1 , in case ∣ Φ 〉 A 2 (27) and where ∣ ψ r i − ξ i , a i − ξ i imp 〉 C i is denoted in Eq. 7 . As discussed in Proposition 1 , the new protocol can reveal all r i ′ and a j to Eve. To further ensure that the new protocol is not only independently distributed but also i.i.d., we additionally require Alice to send an auxiliary quantum state ∣ ψ r i , r ′ ( i , 1 ) , a ( i , 1 ) add ⟩ c i ″ in the c i ″ space for each r i . We denote this modified protocol as ∣ Φ ⟩ A new 2 . For any ∣ ψ r i , r ′ ( i , 1 ) , a ( i , 1 ) add ⟩ c i ″ , protocol ∣ Φ ⟩ A new 2 guarantees the security of ∣ Φ ⟩ A new in Eq. 26 . Thus, combined with Eq. 26 , ∣ Φ ⟩ A new 2 satisfies ∣ Φ 〉 A new 2 = ∑ r 1 ′ N ∑ a 1 2 N ( ∏ i − 1 N p r i ′ ∏ j = 1 2 N q a j ) ( ⊗ i = 1 N ∣ r i ′ 〉 A i ′ ⊗ j = 1 2 N ∣ a j 〉 A i ″ ) ⊗ [ ∑ r 1 N ( ∏ i = 1 N p r i ) ( ⊗ i = 1 N ∣ r i 〉 A i ∣ ψ r i , r ′ ( i , 1 ) , a ( i , 1 ) imp ′ 〉 C i ′ ∣ ψ r i , r ′ ( i , 1 ) , a ( i , 1 ) add 〉 C i ″ ) ] (28) After adding additional states ∣ ψ r i , r ′ ( i , 1 ) , a ( i , 1 ) add ⟩ c i ″ , our goal is to prove that there exist a choice of those states that can make the protocol i.i.d. after acting an unitary mapping on ∣ Φ ⟩ A new 2 . To achieve this, first, we should isolate the terms related to the i th coding ancilla r i in Eq. 28 , denoted as ∣ Φ ⟩ A , iso r i new 2 , i , which satisfies ∣ Φ 〉 A , iso r i new 2 , i = { ∑ r ′ ( i , ξ ) ∑ a ( i , ξ ) ( ∏ j = i − 1 i p r j ′ ∏ k = 2 i − 2 2 i p a k ) ( ⊗ j = i − 1 i ∣ r j ′ 〉 A j ′ ⊗ k = 2 i − 2 i ∣ a k 〉 A k ″ ) ⊗ ∣ ψ r i , r ′ ( i , ξ ) , a ( i , ξ ) im p ′ 〉 C i ′ ∣ ψ r i , r ′ ( i , ξ ) , a ( i , ξ ) add 〉 C i ″ , i ≤ N 2 , ∑ r ′ ( i , ξ ) ∑ a ( i , ξ ) ( ∏ j = i i + 1 p r j ′ ∏ k = 2 i − 1 2 i + 1 p a k ) ( ⊗ j = i i + 1 ∣ r j ′ 〉 A j ′ ⊗ k = 2 i − 1 2 i + 1 ∣ a k 〉 A k ″ ) ⊗ ∣ ψ r i , r ′ ( i , ξ ) , a ( i , ξ ) imp ′ 〉 C i ′ ∣ ψ r i , r ′ ( i , ξ ) , a ( i , ξ ) add 〉 C i ″ , i 〉 N 2 (29) In the following discussion, we will take the case of i ≤ N /2, namely, the case ∣ Φ 〉 A 1 as an example. The analysis for the other case proceeds analogously. Because ∣ ψ r i , r ′ ( i , 1 ) , a ( i , 1 ) add 〉 C i ″ is arbitrary, we can transfer part of its phase to ∣ ψ r i , r ′ ( i , 1 ) , a ( i , 1 ) imp ′ 〉 C i ′ to form ∣ ψ r i , r ′ ( i , 1 ) , a ( i , 1 ) imp ″ 〉 C i ′ and ∣ ψ r i , r ′ ( i , 1 ) , a ( i , 1 ) add ′ 〉 C i ″ , such that 〈 0 ∣ ψ r i , r ′ ( i , 1 ) , a ( i , 1 ) imp ″ 〉 C i ′ is real and positive, where ∣ 0 〉 C i ′ = ∣ 0 〉 C 2 i − 1 ∣ 0 〉 C 2 i and ∣ 0 〉 C j is the vacuum state in the 𝑗th physical rounds. For further analysis, we additionally define two states, respectively, satisfying ∣ Φ 〉 A , iso r i new , i = [ ∑ r ′ ( i , ξ ) ∑ a ( i , ξ ) ( ∏ j = i − 1 i p r j ′ ∏ k = 2 i − 2 2 i p a k ) ( ⊗ j = i − 1 i ∣ r j ′ 〉 A j ′ ⊗ k = 2 i − 2 2 i ∣ a k 〉 A k ″ ) ∣ ψ r i , r ′ ( i , ξ ) , a ( i , ξ ) imp ″ 〉 C i ′ ] ∣ Φ 〉 A , vac new , i = [ ∑ r ′ ( i , ξ ) ∑ a ( i , ξ ) ( ∏ j = i − 1 i p r j ′ ∏ k = 2 i − 2 2 i p a k ) ( ⊗ j = i − 1 i ∣ r j ′ 〉 A j ′ ⊗ k = 2 i − 2 2 i ∣ a k 〉 A k ″ ) ∣ 0 〉 C i ′ ] (30) Thus, due to Assumption 2 , which further leads to min r i − ξ i − 1 min a i − ξ i ( 〈 0 ∣ ψ r i − ξ i , a i − ξ i imp 〉 〈 ψ r i − ξ i , a i − ξ i imp ∣ C i ∣ 0 〉 ) ≥ V r i A , the two intermediate states defined in Eq. 30 satisfy 〈 Φ ∣ A , iso r i new , i ∣ Φ 〉 A , vac new , i = ∣ ∑ r ′ ( i , ξ ) ∑ a ( i , ξ ) ( ∏ j = i − 1 i p r j ′ ∏ k = 2 i − 2 2 i p a k ) ψ r i , r ′ ( i , ξ ) , a ( i , ξ ) imp ″ ∣ 0 〉 C i ′ ∣ ≥ ∑ r ′ ( i , ξ ) ∑ a ( i , ξ ) ( ∏ j = i − 1 i p r j ′ ∏ k = 2 i − 2 2 i p a k ) ( V r i A ∏ j = i − 1 i V r i ′ A ) = V r i A ( p 0 V 0 A + p 1 V 1 A ) ≕ V r i A , 1 (31) Because Eq. 31 satisfies for both 𝑟 𝑖 = 0 and 1, we can find that ∣ 〈 Φ ∣ A , iso 0 new , i ∣ Φ 〉 A , iso 1 new , i ∣ ≥ V 0 A , 1 V 1 A , 1 − ( 1 − V 0 A , 1 ) ( 1 − V 1 A , 1 ) (32) In addition, from Eqs. 29 and 31 , we have that 〈 Φ ∣ A , iso 0 ne w 2 , i ∣ Φ 〉 A , iso 1 ne w 2 , i = ∑ r ′ ( i , ξ ) ∑ a ( i , ξ ) ( ∏ j = i − 1 i p r j ′ ∏ k = 2 i − 2 2 i p a k ) ψ 0 , r ′ ( i , ξ ) , a ( i , ξ ) imp ″ ψ 1 , r ′ ( i , ξ ) , a ( i , ξ ) imp ″ C i ′ ψ 0 , r ′ ( i , ξ ) , a ( i , ξ ) add ′ ψ 1 , r ′ ( i , ξ ) , a ( i , ξ ) add ′ C i ″ 〈 Φ ∣ A , iso 0 new , i ∣ Φ 〉 A , iso 1 new , i = ∑ r ′ ( i , ξ ) ∑ a ( i , ξ ) ( ∏ j = i − 1 i p r j ′ ∏ k = 2 i − 2 2 i p a k ) ψ 0 , r ′ ( i , ξ ) , a ( i , ξ ) imp ″ ψ 1 , r ′ ( i , ξ ) , a ( i , ξ ) imp ″ C i ′ (33) Because ∣ 〈 ψ 0 , r ′ ( i , ξ ) , a ( i , ξ ) add ′ ∣ ψ 1 , r ′ ( i , ξ ) , a ( i , ξ ) add ′ 〉 C i ″ ∣ ≤ 1 , combined with Eq. 32 , we can select a specific set of ∣ ψ r i , r ′ ( i , ξ ) , a ( i , ξ ) add ′ 〉 C i ″ such that 〈 Φ ∣ A , iso 0 new 2 , i ∣ Φ 〉 A , iso 1 new 2 , i = V 0 A , 1 V 1 A , 1 − ( 1 − V 0 A , 1 ) ( 1 − V 1 A , 1 ) (34) and same proof satisfies when satisfies when 𝑖 > 𝑁/2. Then, we will prove that this set of ∣ ψ r i , r ′ ( i , ξ ) , a ( i , ξ ) add ′ 〉 C i ″ can make the protocol i.i.d. Specifically, we construct this i.i.d. protocol as equivalent protocol ∣ Φ 〉 A equ , which satisfies ∣ Φ 〉 A equ = ( ∏ i = 1 N U j ) ∣ Φ 〉 A new 2 = ∑ r ′ 1 ξ N ∑ a 1 ( 1 + ξ ) N ( ∏ i = 1 N p r i ′ ∏ j = 1 2 N q a j ) ( ⊗ i = 1 N ∣ r i ′ 〉 A i ′ ⊗ j = 1 2 N ∣ a i 〉 A i ″ ) ⊗ ∑ r 1 N ( ∏ i = 1 N p r i ′ ) ( ⊗ i = 1 N ∣ r i 〉 A i ∣ ψ r i equ 〉 C i ‴ ) (35) where U 𝑖 is an unitary mapping from the space ∪ j = i − 1 i A j ′ ∪ 2 i − 2 2 i A ′ k ″ ∪ C i ′ ∪ C i ″ into ∪ j = i − 1 i A j ′ ∪ 2 i − 2 2 i A k ″ ∪ C i ‴ when 𝑖 ≤ 𝑁/2 and unitary mapping from the space ∪ j = i i + 1 A j ′ ∪ 2 i − 2 2 i + 1 A k ″ ∪ C i ′ C i ″ into ∪ j = i i + 1 A j ′ ∪ 2 i − 1 2 i + 1 A k ″ ∪ C i ‴ when 𝑖 ≤ 𝑁/2, which satisfies U i ∣ Φ 〉 A , iso r i new 2 , i = ∑ r ′ ( i , ξ ) ∑ a ( i , ξ ) ( ∏ j = i − 1 i p r i ′ ∏ k = 2 i − 2 2 i p a k ) ( ⊗ j = i − 1 i ∣ r i ′ 〉 A j ′ ⊗ k = 2 i − 2 2 i ∣ a k 〉 A k ″ ) ∣ ψ r i equ 〉 C i ‴ , i ≤ N 2 ∑ r ′ ( i , ξ ) ∑ a ( i , ξ ) ( ∏ j = i i + 1 p r i ′ ∏ k = 2 i − 1 2 i + 1 p a k ) ( ⊗ j = i i + 1 ∣ r i ′ 〉 A j ′ ⊗ k = 2 i − 1 2 i + 1 ∣ a k 〉 A k ″ ) ∣ ψ r i equ 〉 C i ‴ , i 〉 N 2 (36) In both two cases, ∣ ψ r i equ 〉 C i ‴ in Eq. 36 has no relation with r j ′ and a k , so it is clear that 〈 Φ ∣ A , iso 0 new 2 , i U i U i † ∣ Φ 〉 A , iso 1 new 2 , i = 〈 ψ 0 equ ∣ ψ 1 equ 〉 C i ‴ . Thus, U i exists if and only if 〈 Φ ∣ A , iso 0 new 2 , i ∣ Φ 〉 A , iso 1 new 2 , i = 〈 ψ 0 equ ∣ ψ 1 equ 〉 C i ‴ . Without loss of generality, we assume that ∣ ψ 0 equ 〉 C i ‴ = ∣ 0 〉 , ∣ ψ 1 equ 〉 C i ‴ = ∣ μ equ 〉 , where ∣ 0 〉 is the vacuum state and ∣ μ equ 〉 is the coherent state with an average number of photons equals to μ equ . Combined with Eq. 34 , we can calculate that μ equ satisfies e − μequ = [ V 0 A , 1 V 1 A , 1 − ( 1 − V 0 A , 1 ) ( 1 − V 1 A , 1 ) ] 2 (37) Furthermore, observing that, in protocol ∣ Φ 〉 A equ , r ′ and a no longer play any role, we simplify the equivalent protocol ∣ Φ 〉 A equ by removing them. The final equivalent protocol then satisfies ∣ Φ 〉 A equ = [ ∑ r 1 N ( ∏ i = 1 N p r i ) ( ⊗ i = 1 N ∣ r i 〉 A i ∣ ψ r i equ 〉 C i ‴ ) ] (38) The above analysis similarly applies to more general values of ξ, and the detailed procedure can be found in the Supplementary Text. Ultimately, this leads to a conclusion of the form presented in Eq. 9 . Phase error estimation of secure QKD against correlated leakage source In the protocol described by Eq. 10 , similar to the original protocol, a Z event occurs when exactly one of Alice or Bob chooses r i = 0 , an O event occurs when both Alice and Bob choose r i = 0 , and a B event occurs when both Alice and Bob choose r i = 1 . In this case, we define the phase error for a Z event as ∣ + + 〉 A i B i = ( ∣ 0 〉 A i + ∣ 1 〉 A i 2 ) ⊗ ( ∣ 0 〉 B i + ∣ 1 〉 B i 2 ) and ∣ − − 〉 A i B i = ( ∣ 0 〉 A i − ∣ 1 〉 A i 2 ) ⊗ ( ∣ 0 〉 B i − ∣ 0 〉 B i 2 ) . Specifically, a phase error is said to occur when Alice and Bob measure the state ∣ + + 〉 A i B i − ∣ − − 〉 A i B i 2 = ∣ 0 〉 A i ∣ 1 〉 B i + ∣ 1 〉 A i ∣ 0 〉 B i 2 ( 30 , 31 ). Because we do not assume Charlie to be trusted, we can further consider the case where Charlie is entirely controlled by Eve. In this scenario, Eve’s attack and Charlie’s measurement can be treated jointly. For simplicity, we refer to this combined operation as Eve’s positive operator-valued measurement (PVOM) M c 0 N E in the following discussion, where c 0 N = c 0 c 1 … c N denotes the measurement result announced by Charlie over total n rounds, where c i ∈ { 0 , 1 } represents the measurement result in the i th round, where 1 indicates a successful measurement and 0 indicates other measurement results, including successful measurement and conclusive results. First, consider a collective attack. In this scenario, Eve’s measurement can be represented as M c 0 N E = ⊗ i = 1 N M c i E , i , where M c i E , i is a Eve’s PVOM in the i th round, and ∀ i , j ∈ [ 0 , N ] , if c i = c j , M c i E , i = M c j E , j . It is worth noting that Eve does not have access to the encoding ancilla spaces of Alice and Bob. Therefore, the phase error probability P ph can be shown as P ph = Tr ( ( P [ ∣ 0 〉 A i ∣ 1 〉 B i + ∣ 1 〉 A i ∣ 0 〉 B i 2 ] ⊗ M 1 E , i ) ⊗ P [ ∣ Φ 〉 i equ ] ⊗ ∣ 0 〉 〈 0 ∣ PE i ) = p 0 p 1 ( 1 − p PE ) 2 Tr ( M 1 E , i P [ ∣ ψ 0 Aequ 〉 C i A ∣ ψ 1 Bequ 〉 C i B + ∣ ψ 1 Aequ 〉 C i A ∣ ψ 0 Bequ 〉 C i B ] ) (39) where P [ ∣ ⋅ 〉 ] = ∣ ⋅ 〉 〈 ⋅ ∣ and ∣ Φ 〉 i equ = [ ∑ r i ∈ { 0 , 1 } p r i ∣ r 〉 i A i ∣ ψ r i Aequ 〉 C i A ] ⊗ [ ∑ r i ∈ { 0 , 1 } p r i ∣ r i 〉 B i ∣ ψ r i Bequ 〉 C i B ] ⊗ [ ∑ m i p m i PE ∣ m i 〉 PE i ] denotes the entanglement-equivalent protocol in the i th round, which satisfies P [ ∣ Φ 〉 equ ] = ⊗ i = 1 N P [ ∣ Φ 〉 i equ ] . Similarly, we can calculate the probabilities of the O event and the B event, denoted as P O and P B , which satisfy P O = Tr ( ( P [ ∣ 0 〉 A i ∣ 0 〉 B i ] ⊗ M 1 E , i ) ⊗ P [ ∣ Φ 〉 i equ ] ) = ( 1 − p PE ) ( p 0 ) 2 Tr ( M 1 E , i P [ ∣ ψ 0 Aequ 〉 C i A ∣ ψ 0 Bequ 〉 C i B ] ) P B = Tr ( ( P [ ∣ 1 〉 A i ∣ 1 〉 B i ] ⊗ M 1 E , i ) ⊗ P [ ∣ Φ 〉 i equ ] ) = ( 1 − p PE ) ( p 1 ) 2 Tr ( M 1 E , i P [ ψ ∣ ψ 1 Aequ 〉 C i A ∣ ψ 1 Bequ 〉 C i B ] ) (40) As calculated in the existing works ( 28 – 31 ), the actually transmitted state satisfies ∣ ψ 0 Aequ 〉 C i A ∣ ψ 1 Bequ 〉 C i B + ∣ ψ 1 Aequ 〉 C i A ∣ ψ 0 Bequ 〉 C i B = c 0 ∣ ψ 0 Aequ 〉 C i A ∣ ψ 0 Bequ 〉 C i B + c 1 ∣ ψ 1 Aequ 〉 C i A ∣ ψ 1 Bequ 〉 C i B + c ¯ 2 ∣ ϕ 2 〉 (41) from Eq. 10 , where c 0 , c 1 〉 0 , c 0 c 1 = 1 , c ¯ 2 = ( c 0 + c 1 − 2 e − μ equ A 2 ) ( c 0 + c 1 − 2 e − μ equ B 2 ) , and ∣ ϕ 2 〉 is a normalized state that keep Eq. 41 holds. Although the values of c 0 and c 1 can be optimized to improve the protocol’s performance, we assume c 0 = e − ( μ equ A + μ equ B ) / 4 and c 1 = 1 / c 0 to simplify the analysis. For M 1 E , i to be positive, we can expand its eigenvalues and rewrite it as M 1 E , i = ∑ j P [ ∣ 1 〉 j E , i ] , where ∣ 1 〉 j E , i is a nonnormalized eigenvector and Tr ( P [ ∣ 1 〉 j E , i ] ) is the corresponding eigenvalue, which satisfies Tr ∑ j ( P [ ∣ 1 〉 j E , i ] ) = Tr ( M 1 E , i ) ≤ 1 . Then, Eq. 40 can be rewritten as P O = ( 1 − p PE ) ( p 0 ) 2 ∑ j ∣ 〈 1 ∣ j E , i ∣ ψ 0 Aequ 〉 C i A ∣ ψ 0 Bequ 〉 C i B ∣ 2 P B = ( 1 − p PE ) ( p 1 ) 2 ∑ j ∣ 〈 1 ∣ j E , i ∣ ψ 1 Aequ 〉 C i A ∣ ψ 1 Bequ 〉 C i B ∣ 2 (42) Combining Eqs. 39 and 41 , we can calculate that 2 P ph p 0 p 1 ( 1 − p PE ) = ∑ j ∣ 〈 1 ∣ j E , i ( c 0 ∣ ψ 0 Aequ 〉 C i A ∣ ψ 0 Bequ 〉 C i B + c 1 ∣ ψ 1 Aequ 〉 C i A ∣ ψ 1 Bequ 〉 C i B + c ¯ 2 ∣ ϕ 2 〉 ) ∣ 2 ≤ ∑ j c 0 2 ∣ 〈 1 ∣ j E , i ∣ ψ 0 Aequ 〉 C i A ∣ ψ 0 Bequ 〉 C i B ∣ 2 + c 1 2 ∣ 〈 1 ∣ j E , i ∣ ψ 1 Aequ 〉 C i A ∣ ψ 1 Bequ 〉 C i B ∣ 2 + c ¯ 2 2 ∣ 〈 1 ∣ j E , i c ¯ 2 ∣ ϕ 2 〉 ∣ 2 + 2 c 0 c 1 ∣ 〈 1 ∣ j E , i ∣ ψ 0 Aequ 〉 C i A ∣ ψ 0 Bequ 〉 C i B ∣ ∣ 〈 1 ∣ j E , i ∣ ψ 1 Aequ 〉 C i A ∣ ψ 1 Bequ 〉 C i B ∣ + 2 c 0 c ¯ 2 ∣ 〈 1 ∣ j E , i ∣ ψ 0 Aequ 〉 C i A ∣ ψ 0 Bequ 〉 C i B ∣ ∣ 〈 1 ∣ j E , i c ¯ 2 ∣ ϕ 2 〉 ∣ + 2 c 1 c ¯ 2 ∣ 〈 1 ∣ j E , i ∣ ψ 1 Aequ 〉 C i A ∣ ψ 1 Bequ 〉 C i B ∣ ∣ 〈 1 ∣ j E , i c ¯ 2 ∣ ϕ 2 〉 ∣ (43) From Cauchy-Schwarz inequality, we can see that ( ∑ i x i y i ) 2 ≤ ( ∑ i x i ) 2 ( ∑ i y i ) 2 ; then, combined with the fact that ∑ j ∣ 〈 1 ∣ j E , i c ¯ 2 ∣ ϕ 2 〉 ∣ 2 ≤ 1 , from Eqs. 42 and 43 , we can calculate the upper bound of P ph , which satisfies ( 28 , 31 ) P ph ≤ p 1 p 0 2 ( c 0 2 P O ( p 0 ) 2 + c 1 2 P B ( p 1 ) 2 + c ¯ 2 2 + 2 c 0 c 1 P O P B ( p 0 ) 2 ( p 1 ) 2 + c 0 c ¯ 2 P O ( p 0 ) 2 + c 1 c ¯ 2 P B ( p 1 ) 2 ) (44) and this leads us to Eq. 11 . Acknowledgments Funding: This work was supported by the National Natural Science Foundation of China (grant nos. 62425507, 62531023, 62271463, 62301524, and 62371437); Quantum Science and Technology-National Science and Technology Major Project, 2021ZD0300701; and Fundamental Research Funds for the Central Universities under grant WK2030250122. R.W. is supported by the Hangzhou Dianzi University start-up grant. Author contributions: Conceptualization: J.-X.L., Y.-G.S., Z.-Q.Y., and S.W. Methodology: J.-X.L., Y.-G.S., F.-Y.L., Z.-Q.Y., and S.W. Software: J.-X.L., Y.-G.S., F.-Y.L., Z.-Q.Y., and S.W. Validation: J.-X.L., Y.-G.S., R.W., F.-Y.L., Z.-Q.Y., and S.W. Formal analysis: J.-X.L., F.-Y.L., Z.-Q.Y., and S.W. Investigation: J.-X.L., F.-Y.L., Z.-Q.Y., and S.W. Resources: J.-X.L., F.-Y.L., Z.-Q.Y., S.W., W.C., D.-Y.H., G.-C.G., and Z.-F.H. Data curation: J.-X.L., F.-Y.L., Z.-Q.Y., S.W., G.-C.G., and Z.-F.H. Writing—original draft: J.-X.L., Z.-Q.Y., and S.W. Writing—review and editing: J.-X.L., Y.-G.S., Z.-Q.Y., S.W., D.-Y.H., and Z.-F.H. Visualization: J.-X.L., F.-Y.L., Z.-Q.Y., and S.W. Supervision: Z.-Q.Y., S.W., W.C., D.-Y.H., G.-C.G., and Z.-F.H. Project administration: F.-Y.L., Z.-Q.Y., S.W., W.C., D.-Y.H., G.-C.G., and Z.-F.H. Funding acquisition: J.-X.L., F.-Y.L., Z.-Q.Y., S.W., W.C., D.-Y.H., G.-C.G., and Z.-F.H. Competing interests: The authors declare that they have no competing interests. Data, code, and materials availability: All data and code needed to evaluate and reproduce the results in the paper are present in the paper and/or the Supplementary Materials. This study did not generate new materials. Supplementary Materials This PDF file includes: Supplementary Text sciadv.aed2420_sm.pdf (403.5KB, pdf) REFERENCES 1. Shannon C. E., A mathematical theory of communication. Bell Syst. Tech. J. 27, 379–423 (1948). [ Google Scholar ] 2. P. Shor, “Algorithms for quantum computation: Discrete logarithms and factoring,” in Proceedings 35th Annual Symposium on Foundations of Computer Science (IEEE, 1994), pp. 124–134; 10.1109/SFCS.1994.365700. [ DOI ] [ Google Scholar ] 3. M. Stevens, E. Bursztein, P. Karpman, A. Albertini, Y. Markov, “The first collision for full SHA-1,” in Advances in Cryptology – CRYPTO 2017, J. Katz, H. Shacham, Eds. (Springer International Publishing, 2017), pp. 570–596; https://link.springer.com/chapter/10.1007/978-3-319-63688-7_19 . [ Google Scholar ] 4. C. H. Bennett, G. Brassard, “Quantum cryptography: Public key distribution and coin tossing,” in Proceedings of the International Conference on Computers, Systems and Signal Processing (IEEE, 1984), pp. 175–179; 10.1016/j.tcs.2014.05.025. [ DOI ] [ Google Scholar ] 5. Lo H.-K., Chau H. F., Unconditional security of quantum key distribution over arbitrarily long distances. Science 283, 2050–2056 (1999). [ DOI ] [ PubMed ] [ Google Scholar ] 6. Shor P. W., Preskill J., Simple proof of security of the BB84 quantum key distribution protocol. Phys. Rev. Lett. 85, 441–444 (2000). [ DOI ] [ PubMed ] [ Google Scholar ] 7. Scarani V., Bechmann-Pasquinucci H., Cerf N. J., Dušek M., Lütkenhaus N., Peev M., The security of practical quantum key distribution. Rev. Mod. Phys. 81, 1301–1350 (2009). [ Google Scholar ] 8. Renner R., Security of quantum key distribution. Int. J. Quantum Inf. 06, 1–127 (2008). [ Google Scholar ] 9. Braunstein S. L., Pirandola S., Side-channel-free quantum key distribution. Phys. Rev. Lett. 108, 130502 (2012). [ DOI ] [ PubMed ] [ Google Scholar ] 10. Lo H.-K., Curty M., Qi B., Measurement-device-independent quantum key distribution. Phys. Rev. Lett. 108, 130503 (2012). [ DOI ] [ PubMed ] [ Google Scholar ] 11. Curty M., Xu F., Cui W., Lim C. C. W., Tamaki K., Lo H. K., Finite-key analysis for measurement-device-independent quantum key distribution. Nat. Commun. 5, 3732 (2014). [ DOI ] [ PubMed ] [ Google Scholar ] 12. Lucamarini M., Yuan Z. L., Dynes J. F., Shields A. J., Overcoming the rate–distance limit of quantum key distribution without quantum repeaters. Nature 557, 400–403 (2018). [ DOI ] [ PubMed ] [ Google Scholar ] 13. Ma X., Zeng P., Zhou H., Phase-matching quantum key distribution. Phys. Rev. X 8, 031043 (2018). [ Google Scholar ] 14. Wang X.-B., Yu Z.-W., Hu X.-L., Twin-field quantum key distribution with large misalignment error. Phys. Rev. A 98, 062323 (2018). [ Google Scholar ] 15. Cui C., Yin Z. Q., Wang R., Chen W., Wang S., Guo G. C., Han Z. F., Twin-field quantum key distribution without phase postselection. Phys. Rev. Appl. 11, 034053 (2019). [ Google Scholar ] 16. Zeng P., Zhou H., Wu W., Ma X., Mode-pairing quantum key distribution. Nat. Commun. 13, 3903 (2022). [ DOI ] [ PMC free article ] [ PubMed ] [ Google Scholar ] 17. Pereira M., Kato G., Mizutani A., Curty M., Tamaki K., Quantum key distribution with correlated sources. Sci. Adv. 6, eaaz4487 (2020). [ DOI ] [ PMC free article ] [ PubMed ] [ Google Scholar ] 18. Tamaki K., Curty M., Kato G., Lo H.-K., Azuma K., Loss-tolerant quantum cryptography with imperfect sources. Phys. Rev. A 90, 052314 (2014). [ Google Scholar ] 19. Yin Z.-Q., Fung C. H. F., Ma X., Zhang C. M., Li H. W., Chen W., Wang S., Guo G. C., Han Z. F., Mismatched-basis statistics enable quantum key distribution with uncharacterized qubit sources. Phys. Rev. A 90, 052319 (2014). [ Google Scholar ] 20. D. Gottesman, H.-K. Lo, N. Lutkenhaus, J. Preskill, “Security of quantum key distribution with imperfect devices,” in Proceedings of the IEEE International Symposium on Information Theory (ISIT 2004) (IEEE, 2004), p. 136; 10.1109/ISIT.2004.1365172. [ DOI ] [ Google Scholar ] 21. Lo H.-K., Preskill J., Security of quantum key distribution using weak coherent states with nonrandom phases. Quantum Inf. Comput. 7, 431–458 (2007). [ Google Scholar ] 22. Koashi M., Simple security proof of quantum key distribution based on complementarity. New J. Phys. 11, 045018 (2009). [ Google Scholar ] 23. Coles P. J., Metodiev E. M., Lütkenhaus N., Numerical approach for unstructured quantum key distribution. Nat. Commun. 7, 11712 (2016). [ DOI ] [ PMC free article ] [ PubMed ] [ Google Scholar ] 24. Wang Y., Primaatmaja I. W., Lavie E., Varvitsiotis A., Lim C. C. W., Characterising the correlations of prepare-and-measure quantum networks. npj Quantum Inf. 5, 17 (2019). [ Google Scholar ] 25. Winick A., Lütkenhaus N., Coles P. J., Reliable numerical key rates for quantum key distribution. Quantum 2, 77 (2018). [ Google Scholar ] 26. Pereira M., Curty M., Tamaki K., Quantum key distribution with flawed and leaky sources. npj Quantum Inf. 5, 62 (2019). [ Google Scholar ] 27. Sixto X., Navarrete Á., Pereira M., Currás-Lorenzo G., Tamaki K., Curty M., Quantum key distribution with imperfectly isolated devices. Quantum Sci. Technol. 10, 035034 (2025). [ Google Scholar ] 28. Wang X.-B., Hu X.-L., Yu Z.-W., Practical long-distance side-channel-free quantum key distribution. Phys. Rev. Appl. 12, 054034 (2019). [ Google Scholar ] 29. Jiang C., Yu Z.-W., Hu X.-L., Wang X.-B., Side-channel-secure quantum key distribution with imperfect vacuum sources. Phys. Rev. Appl. 19, 064003 (2023). [ Google Scholar ] 30. Jiang C., Hu X.-L., Yu Z.-W., Wang X.-B., Side-channel security of practical quantum key distribution. Phys. Rev. Res. 6, 013266 (2024). [ Google Scholar ] 31. Y.-G. Shan, Z.-Q. Yin, S. Wang, W. Chen, D.-Y. He, G.-C. Guo, Z.-F. Han, Improved postselection security analysis of phase error estimation in quantum key distribution. arXiv:2409.19538 [quant-ph] (2024). 32. Acín A., Brunner N., Gisin N., Massar S., Pironio S., Scarani V., Device-independent security of quantum cryptography against collective attacks. Phys. Rev. Lett. 98, 230501 (2007). [ DOI ] [ PubMed ] [ Google Scholar ] 33. Zhang C., Hu X. L., Jiang C., Chen J. P., Liu Y., Zhang W., Yu Z. W., Li H., You L., Wang Z., Wang X. B., Zhang Q., Pan J. W., Experimental side-channel-secure quantum key distribution. Phys. Rev. Lett. 128, 190503 (2022). [ DOI ] [ PubMed ] [ Google Scholar ] 34. Nagamatsu Y., Mizutani A., Ikuta R., Yamamoto T., Imoto N., Tamaki K., Security of quantum key distribution with light sources that are not independently and identically distributed. Phys. Rev. A 93, 042325 (2016). [ Google Scholar ] 35. Mizutani A., Kato G., Azuma K., Curty M., Ikuta R., Yamamoto T., Imoto N., Lo H. K., Tamaki K., Quantum key distribution with setting-choice-independently correlated light sources. npj Quantum Inf. 5, 8 (2019). [ Google Scholar ] 36. Yoshino K., Fujiwara M., Nakata K., Sumiya T., Sasaki T., Takeoka M., Sasaki M., Tajima A., Koashi M., Tomita A., Quantum key distribution with an efficient countermeasure against correlated intensity fluctuations in optical pulses. npj Quantum Inf. 4, 8 (2018). [ Google Scholar ] 37. Zapatero V., Navarrete Á., Tamaki K., Curty M., Security of quantum key distribution with intensity correlations. Quantum 5, 602 (2021). [ Google Scholar ] 38. Sixto X., Zapatero V., Curty M., Security of decoy-state quantum key distribution with correlated intensity fluctuations. Phys. Rev. Appl. 18, 044069 (2022). [ Google Scholar ] 39. Pereira M., Currás-Lorenzo G., Navarrete Á., Mizutani A., Kato G., Curty M., Tamaki K., Modified BB84 quantum key distribution protocol robust to source imperfections. Phys. Rev. Res. 5, 023065 (2023). [ Google Scholar ] 40. Currás-Lorenzo G., Nahar S., Lütkenhaus N., Tamaki K., Curty M., Security of quantum key distribution with imperfect phase randomisation. Quantum Sci. Technol. 9, 015025 (2024). [ Google Scholar ] 41. Li J.-X., Lu F. Y., Wang Z. H., Zapatero V., Curty M., Wang S., Yin Z. Q., Chen W., He D. Y., Guo G. C., Han Z. F., Quantum key distribution overcoming practical correlated intensity fluctuations. npj Quantum Inf. 11, 106 (2025). [ Google Scholar ] 42. G. Currás-Lorenzo, M. Pereira, G. Kato, M. Curty, K. Tamaki, A security framework for quantum key distribution implementations. arXiv:2305.05930v2 [quant-ph] (2024). 43. Vitanov A., Dupuis F., Tomamichel M., Renner R., Chain rules for smooth min- and max-entropies. IEEE Trans. Inf. Theory 59, 2603–2612 (2013). [ Google Scholar ] 44. Trefilov D., Sixto X., Zapatero V., Huang A., Curty M., Makarov V., Intensity correlations in decoy-state BB84 quantum key distribution systems. Optica Quantum 3, 417–431 (2025). [ Google Scholar ] 45. Roberts G. L., Pittaluga M., Minder M., Lucamarini M., Dynes J. F., Yuan Z. L., Shields A. J., Patterning-effect mitigating intensity modulator for secure decoy-state quantum key distribution. Opt. Lett. 43, 5110–5113 (2018). [ DOI ] [ PubMed ] [ Google Scholar ] 46. Lu F.-Y., Lin X., Wang S., Fan-Yuan G. J., Ye P., Wang R., Yin Z. Q., He D. Y., Chen W., Guo G. C., Han Z. F., Intensity modulator for secure, stable, and high-performance decoy-state quantum key distribution. npj Quantum Inf. 7, 75 (2021). [ Google Scholar ] 47. Lu F.-Y., Wang Z. H., Wang S., Yin Z. Q., Chen J. L., Kang X., He D. Y., Chen W., Fan-Yuan G. J., Guo G. C., Han Z. F., Intensity tomography method for secure and high-performance quantum key distribution. J. Lightwave Technol. 41, 4895–4900 (2023). [ Google Scholar ] 48. Kang X., Lu F. Y., Wang S., Chen J. L., Wang Z. H., Yin Z. Q., He D. Y., Chen W., Fan-Yuan G. J., Guo G. C., Han Z. F., Patterning-effect calibration algorithm for secure decoy-state quantum key distribution. J. Lightwave Technol. 41, 75–82 (2023). [ Google Scholar ] 49. Marcomini A., Currás-Lorenzo G., Rusca D., Valle A., Tamaki K., Curty M., Characterising higher-order phase correlations in gain-switched laser sources with application to quantum key distribution. EPJ Quantum Technol. 12, 38 (2025). [ Google Scholar ] 50. F.-Y. Lu, J.-X. Li, Z.-H. Wang, S. Wang, Z.-Q. Yin, A. Navarrete, M. Curty, W. Chen, D.-Y. He, G.-C. Guo, Z.-F. Han, Breaking the system-frequency limitation of quantum key distribution. arXiv:2509.00438 [quant-ph] (2025). 51. Tomamichel M., Lim C. C. W., Gisin N., Renner R., Tight finite-key analysis for quantum cryptography. Nat. Commun. 3, 634 (2012). [ DOI ] [ PMC free article ] [ PubMed ] [ Google Scholar ] 52. Y.-G. Shan, Z.-Q. Yin, S. Wang, W. Chen, D.-Y. He, G.-C. Guo, Z.-F. Han, Practical phase-coding side-channel-secure quantum key distribution. arXiv:2305.13861 [quant-ph] (2023). 53. Matsuura T., Yamano S., Kuramochi Y., Sasaki T., Koashi M., Tight concentration inequalities for quantum adversarial setups exploiting permutation symmetry. Quantum 8, 1540 (2024). [ Google Scholar ] 54. Chernoff H., A measure of asymptotic efficiency for tests of a hypothesis based on the sum of observations. Ann. Math. Stat. 23, 493–507 (1952). [ Google Scholar ] 55. M. Mitzenmacher, E. Upfal, Probability and Computing: Randomized Algorithms and Probabilistic Analysis (Cambridge Univ. Press, 2005); 10.1017/cbo9780511813603. [ DOI ] [ Google Scholar ] 56. Nahar S., Tupkary D., Zhao Y., Lütkenhaus N., Tan E. Y.-Z., Postselection technique for optical quantum key distribution with improved de finetti reductions. PRX Quantum 5, 040315 (2024). [ Google Scholar ] 57. Tomamichel M., Schaffner C., Smith A., Renner R., Leftover hashing against quantum side information. IEEE Trans. Inf. Theory 57, 5524–5535 (2011). [ Google Scholar ] 58. Xie H.-B., Li Y., Jiang C., Cai W. Q., Yin J., Ren J. G., Wang X. B., Liao S. K., Peng C. Z., Optically injected intensity-stable pulse source for secure quantum key distribution. Opt. Express 27, 12231–12240 (2019). [ DOI ] [ PubMed ] [ Google Scholar ] 59. Huang A., Mizutani A., Lo H.-K., Makarov V., Tamaki K., Characterization of state-preparation uncertainty in quantum key distribution. Phys. Rev. Appl. 19, 014048 (2023). [ Google Scholar ] Associated Data This section collects any data citations, data availability statements, or supplementary materials included in this article. Supplementary Materials Supplementary Text sciadv.aed2420_sm.pdf (403.5KB, pdf) Data Availability Statement All data and code needed to evaluate and reproduce the results in the paper are present in the paper and/or the Supplementary Materials. This study did not generate new materials. Articles from Science Advances are provided here courtesy of American Association for the Advancement of Science ACTIONS View on publisher site PDF (1.6 MB) Cite Collections Permalink PERMALINK Copy RESOURCES Similar articles Cited by other articles Links to NCBI Databases Cite Copy Download .nbib .nbib Format: AMA APA MLA NLM Add to Collections Create a new collection Add to an existing collection Name your collection * Choose a collection Unable to load your collection due to an error Please try again Add Cancel Follow NCBI NCBI on X (formerly known as Twitter) NCBI on Facebook NCBI on LinkedIn NCBI on GitHub NCBI RSS feed Connect with NLM NLM on X (formerly known as Twitter) NLM on Facebook NLM on YouTube National Library of Medicine 8600 Rockville Pike Bethesda, MD 20894 Web Policies FOIA HHS Vulnerability Disclosure Help Accessibility Careers NLM NIH HHS USA.gov Back to Top