Multidimensional Reconciliation in Continuous-Variable QKD: Review, Coding Schemes, and Open Source Simulation Lucien Martial1,2 , Alexis Rosio2 , Eleni Diamanti2 , Adrien Cassagne2 , and Baptiste Gouraud1 1
2
Exail, F-25000, Besançon, France Sorbonne Université, CNRS, LIP6, F-75005 Paris, France
arXiv:2606.02323v1 [cs.IT] 1 Jun 2026
Abstract
bility, enabling high secret key rates and, in particular, eliminating the need for single-photon detectors used in DV-QKD. However, these advantages come with an increased complexity in the post-processing stages, particularly in the high-loss (long-distance) regime. While in DV-QKD data can be post-selected on photon detection events, in CV-QKD it is necessary to manage signals largely dominated by quantum vacuum noise. CV-QKD thus requires more sophisticated reconciliation, the error correction step which is essential to ensure that both parties ultimately share a key that is strictly identical. Multidimensional reconciliation has become the method of choice for long-distance CV-QKD. It was proposed in (Leverrier et al. 2008) as an alternative to slice reconciliation (Van Assche, Cardinal, and Cerf 2004), better suited in the large-SNR/short-distance regime. While slice reconciliation attempts to recover multiple bits per channel use, multidimensional reconciliation transforms the physical quantum channel into a virtual channel that approximates a binary input additive white Gaussian noise (BIAWGN) channel. Reconciliation consequently benefits from the extended research conducted on errorcorrection for classical communications on a BIAWGN channel. The core principle involves mapping a subvector of size d from the quantum channel data to a random vector of the same size later used to build the raw secret key. The overall information balance is then closer to optimality for a large dimension d. The technique exploits algebraic structures that simplify the mapping for dimensions 1, 2, 4 or 8, while other dimensions require to build a random transformation (Jouguet, Kunz-Jacques, and Leverrier 2011). In this work, we focus primarily on multidimensional reconciliation in high-dimensions, i.e. beyond dimension 8. The aim is to bring together critical elements currently scattered throughout the literature, while providing an educational overview of the fundamentals of reconciliation in CV-QKD. In order to illustrate our developments and actively contribute to the community, we have designed a dedicated open-source software, HDirac (HDirac 2026), which implements the most advanced approaches in multidimensional reconciliation, allowing us to simulate a CV-QKD channel with high multidimensional reconciliation. HDirac closely integrates with Aff3ct (Cassagne et al. 2019), a reference opensource library for the fast evaluation of error correction schemes. This allows for different reconciliation methods to be tested in a reproducible, efficient, and transparent framework. The source codes are freely accessible and easily modifiable, so that it is possible to experiment with
Continuous-variable quantum key distribution (CVQKD) requires highly efficient reconciliation techniques to operate at low signal-to-noise ratios and long distances. Multidimensional reconciliation addresses this challenge by transforming the physical Gaussian quantum channel into a virtual binary-input additive white Gaussian noise (BIAWGN) channel, enabling the use of modern errorcorrecting codes. In this work, we review the principles of multidimensional reconciliation, with a particular focus on high-dimensional constructions beyond the algebraic dimensions 1, 2, 4, 8. We describe the construction of the virtual channel, discuss practical coding schemes for reverse reconciliation, and analyse their integration with linear error-correcting codes. We also present an opensource simulation framework, HDirac, implementing multidimensional reconciliation for arbitrary dimensions, and use it to evaluate state-of-the-art LDPC codes. The results highlight key trade-offs between dimension, reconciliation efficiency, and frame error rate, providing practical guidance for CV-QKD system design. Keywords: CV-QKD Virtual Channel, Reverse reconciliation, High-dimensional reconciliation, LDPC, Aff3ct, Simulation tool
1
Introduction
Classical cryptography typically relies on hard computational problems and on the assumption that an adversary (Eve) has limited computational power and time. As a result, its long-term security cannot be ensured, given the steady progress of classical computing and the advent of quantum computing. In contrast, in the paradigm of information-theoretic security (ITS), the information accessible to Eve is bounded, even if Eve has unlimited computational power. A central example of an ITS cryptographic primitive is quantum key distribution (QKD), which enables two distant parties to establish a shared secret key based on the laws of quantum physics. QKD based on the encoding of information in continuous variables (CV-QKD) offers specific advantages over QKD based on encoding in single-photon properties, known as discrete variable quantum key distribution (DV-QKD). More specifically, in CV-QKD protocols, information is encoded in the quadratures of the electromagnetic field, usually via the modulation of the coherent states emitted by a laser. CV-QKD systems therefore use standard optical telecommunications components and techniques, benefiting from their low cost and high relia1
various error correction codes without having to worry about the implementation details of multidimensional reconciliation. This article also aims to promote closer ties between the CV-QKD and error-correcting code communities by providing detailed educational explanations to facilitate mutual understanding. In addition, the presented simulation results highlight various behaviours that have not been documented before. Our work complements other recent contributions from the research community. In particular (Cil and Schmalen 2024a) is a stand-alone open-source implementation of octonion-based reconciliation; (Gümüş et al. 2024) targets discrete modulations over a free-space link, but also contains a clear introduction to high-dimensional reconciliation; (Yang et al. 2023) is a general review of reconciliation for CV-QKD; and (Dai et al. 2025) proposes an alternative construction of high-dimensional reconciliation that reduces the communication overhead on the classical channel. First, we present in Section 2 a simplified version of a CV-QKD protocol, and discuss the important concepts required to work on reconciliation. In Section 3, we describe the construction of the virtual channel of multidimensional reconciliation. In Section 4 we discuss Figure 1: Overview of the general steps of a prepare-andvarious schemes used to combine linear error correction measure QKD protocol. codes with multidimensional construction, thus completing the reconciliation process. In Section 5, we present Gaussian distribution N (0, σa2 )1 , a QKD frame of L and discuss results obtained from open-source LDPC numbers ai in R that she encodes in pairs (x, p) into matrices representative of the state of the art (Cil and a complex number α = (x+j·p)/2 where j represents Schmalen 2024a), in order to compare performance across the imaginary unit. Alice modulates a laser pulse in the different dimensions and configurations studied. We the coherent state |α⟩, then transmits the laser pulse finally conclude this work. to Bob via the quantum communication channel.
2
2. Measure: Bob performs a heterodyne2 measurement of the received state: i.e. the received light is split in a 50/50 beam splitter, and the two outputs used to measure, respectively, the two quadratures x̂ and p̂. The measurement results, arranged in the same order as Alice, are noted bi .
CV-QKD Protocol Overview
We give here a simplified description of a CV-QKD protocol, with the purpose of providing the necessary background to understand the reconciliation process. The description focuses on the prepare-and-measure (PM) For an honest implementation of the protocol, i.e. protocol with heterodyne detection, reverse reconciliaif one can safely assume that no eavesdropper is tion and Gaussian modulation. Note however that the present, we assume the following linear and lossy results of this work are easily adapted to entanglement channel model: based protocols, homodyne detection and direct reconciliation. Other modulation formats would usually require different approaches for reconciliation. For completeness, bi = t · a i + z i (1) we briefly discuss notable protocol alternatives after the protocol description. where Following the tradition in cryptography, we refer to the two parties involved in the protocol as Alice and • T = t2 < 1 is the transmittance, including Bob, and to the eavesdropper as Eve. Alice and Bob can Bob’s device loss, communicate via a physical quantum channel, which may • zi ∼ N (0, σz2 ) is the total noise (quantum vacbe manipulated by Eve, but also on a classical errorless uum noise, device imperfections, and channel authenticated channel: Eve can listen to the classical noise). The channel signal-to-noise ratio is dechannel but is prevented from impersonating Alice or fined as SNR = T σa2 /σz2 . Bob. The individual steps of the protocol have names and general functions common to most prepare-and-measure 1 Noting N (0, σ 2 ) the normal distribution with mean zero and QKD protocols. They are illustrated in Figure 1 and standard deviation σ. 2 In this context, homodyne usually means detection of a single described below: quadrature, while heterodyne usually means simultaneous of both quadratures. In laser telecommunications, both are referred to as coherent detection.
1. Prepare: Alice randomly generates, according to a 2
Lost light is assumed to be accessible to Eve, and quantum physics dictates that any measurement performed on the transmitted light likely introduces additional noise.
larger is usually targeted (Jouguet et al. 2013). This has important consequences in the design of the reconciliation method and code, as discussed in further detail in this work.
3. Reconciliation: At this stage, Alice and Bob share random correlated data. Together, they use error 2.1 Protocol Alternatives correction techniques to build the same common bit As mentioned earlier, common protocol alternatives are string (called the raw key). In reverse (respectively the following: direct) reconciliation, the original bit string must • Direct reconciliation (Grosshans and Grangier be built purely from Bob (resp. Alice) quantum 2002a), much more intuitive than reverse reconciliachannel data and local random number generator; tion, limits QKD protocols to 50% channel loss (or additional data may be revealed by Bob (resp. Alice) ≈ 15 km of standard telecom fibre): for further loss, on an authenticated channel to enable an efficient because all lost light is assumed in Eve’s hands, Eve error correction by Alice (resp. Bob). always has a better picture of Alice data than Bob. 4. Verification: Correction is complemented by a verifiCV-QKD was thus considered unpractical until the cation step to ensure that the bit strings are identical realisation that reverse reconciliation has no such (otherwise, the protocol is aborted). For ITS, this is limitation (Grosshans and Grangier 2002b). Direct usually done by disclosing and comparing the output reconciliation does not introduce more complexity of a function chosen randomly from a universal hash than presented in this work. family3 . • While Gaussian modulation benefits from simpler 5. Parameter Estimation: A bound is estimated on the theoretical proofs and is the most strongly estabamount of information that Eve could maximally lished (Leverrier 2017; Pirandola and Papanastahold on the raw key. If Eve could have acquired siou 2024), discrete modulations (i.e. quadrature more information than mutually available to Alice amplitude modulation (QAM) with discrete consteland Bob, the protocol is aborted. lations) are also being explored. Small constellations would typically require different reconciliation methThis estimation is built on a comparison of Alice and ods, while large constellations tend to approximate Bob data and the fact that any measurement by Eve the Gaussian case and can use the same reconciliaon the channel would likely introduce a disturbance. tion methods. In CV-QKD this means that worst-case estimates are computed on the channel parameters: for the most • First implementations of CV-QKD used homodyne simple protocols, directly the channel transmittance detection: Bob measures one of the two quadraand added noise. Parameter estimation may be tures chosen randomly, the measurement choice is performed before reconciliation and may involve the disclosed, and the other quadrature discarded from disclosure (and discarding) of a random subset of Alice data. Homodyne detection is now less comthe quantum channel data. mon in CV-QKD because it usually required Alice to transmit the local oscillator (the reference laser for 6. Privacy Amplification: This final step involves apthe detection) through an optical channel, which inplying a hash function to the raw key. This process troduced security vulnerabilities (Ferenczi, Grangier, allows Alice and Bob to obtain a perfectly secret bit and Grosshans 2007). string from their partially secret raw key. Again, for ITS, universal hashing is generally used. • Prepare and measure QKD protocols typically have an entanglement based (EB) counterpart: an enFor the purpose of reconciliation, we can safely astangled state is first generated, its components dissume the model of equation (1) – also called additive tributed to Alice and Bob, and both parties perform white Gaussian noise (AWGN) channel: The honest ima local measurement. From the theoretical security plementation noise is largely dominated by the Gaussian analysis point of view, the EB description is equivavacuum fluctuations, and other important technical noise lent and thus widely used. An entanglement based sources (such as thermal noise at the detector) are close implementation although more challenging has its to Gaussian. On the other hand, in the presence of Eve, interests, and some more complex EB protocols canthe additional noise tolerated by the protocol is usually not be reduced to a PM scenario. too small to have a significant impact on error correction. However, for the theoretical security analysis and the parameter estimation process, it is in general not safe to 2.2 Secret Key Rate make any such assumption on the quantum channel. In order to achieve long distances, finite size theoret- The secret key rate (SKR) established between Alice and ical analysis reveals that using long frames is essential. Bob is easier to express first in the theoretical asymptotic The uncertainty of parameter estimation, in particular, regime, i.e. assuming infinitely large frames (L → ∞): must be limited with a large choice of L. L ≈ 109 or
SKR∞ = pqkd · (βIAB − χ).
3 The function is chosen randomly by either Alice or Bob. The
IAB , χ quantify maximal available information:
choice is then revealed on the classical channel.
3
(2)
• IAB is the classical mutual information between Alice and Bob – for additive white Gaussian noise, the mutual information is maximal (Shannon capacity) for Gaussian modulation and IAB = 12 log2 (1 + SNR).
estimation, or the exact value if the raw key is generated by an ideal random number generator), minus the number of bits of this raw key revealed on the classical channel (for reconciliation and verification). This quantity is then reduced further by L · χ and L · ∆ to give the length of the secret key l. Finally, l, L and the raw key are used as the inputs of privacy amplification.
• χ, the Holevo bound, is the maximum amount of information that Eve could have on the raw key. It is computed from the result of parameter estimation and is more precisely noted χBE for reverse reconciliation (or χAE for direct reconciliation). See (Fossier 2.3 Subframing et al. 2009) for asymptotic expressions of χ. Up to now, we assumed that reconciliation works on the full frame. However, the target QKD frame size The parameters β, pqkd quantify imperfections of the (e.g. L ≈ 109 ) is larger than practical error correction reconciliation process: frame size (up to L ≈ 107 ). The main QKD frame can thus be divided into smaller subframes. The subframing • β ≤ 1 is the reconciliation efficiency, defined as the strategy, mostly unmentioned in the current literature, quantity of actually retrieved information divided has security consequences and must be chosen with care. by the Shannon bound IAB (see also Section 4), While the security analysis of subframing in general is • pqkd is the probability, given a specific level of noise, ongoing research work (Johnson et al. 2017; Pirandola that reconciliation corrects all errors (linked to the and Papanastasiou 2024; Jaksch et al. 2024), we describe here three simple methods. Frame Error Rate by 1 − FERqkd ). We assume the QKD frame divided evenly in ζ error At this level, while pqkd is only a scaling factor, β correction (EC) subframes of length n (L = ζ · n). The is critical and should be close to 100%: At the system code has a probability pec = 1 − FERec to correct a performance limits, IAB and χ are of similar scale such subframe without error. Strict subframing: In this first method, the whole that a small degradation of β is enough to shift from a QKD frame (composed of ζ subframes) is viewed by the positive to a negative result (without secret key). Two different unit choices are popular for SKR, IAB protocol as a single reconciliation frame: verification and χ: either bits per laser pulse (with a total of L/2 is performed with a universal hash on the full frame laser pulses), more common and preferred when study- and the protocol aborts if error correction failed on a ing the physics (implementation or theory), or bits per single subframe. In this case, equation (2) becomes quadrature (L quadratures) preferred when studying the (3) and is valid without further security analysis. Also ζ post-processing which directly works on the list of quadra- pqkd = (pec ) ≈ 1 − ζFERec , where the approximation is ture values (we chose this latter convention in this work). for small FERec . The tolerance to non-zero pec or small Care should be taken when comparing formulas from dif- subframes is quite limited: FERec should be of order 1/ζ ferent references or for homodyne/heterodyne protocols. at most. Another naming convention is bits per complex symbol SKRstrict = (pec )ζ · (βIAB − χ) (3) as opposed to bits per real symbol. The actual protocol has finite L, and the theoretical For the two other strategies, additional verification SKR typically requires the following modifications (de- is performed at the subframe level. For each subframe, pending on the variant of protocol and security proof – Alice estimates whether the decoding was successful and see e.g. (Leverrier, Grosshans, and Grangier 2010; Lever- publicly reveals this information. This estimation can be rier 2017; Pirandola and Papanastasiou 2024)): based on the decoder output itself (e.g. Did the decoder converge to the correct syndrome? – more in Section 4), and complemented via hashing (Bob discloses a regular hash computed for each subframe. Alice applies the same hash function and compares the result. The number of bits of the revealed hashes is subtracted from the final key length.). For simplicity, we assume here that this estimation never fails: in practice a reasonable hash size enables a very small probability of failure while revealing a small amount of data. Reveal-on-error subframing: For this subframing method, if a subframe was not decoded correctly, Bob reveals the corresponding raw key data. From the protocol point of view, there is still a single frame and verification is performed on this whole frame (with universal hashing). Because raw key data are revealed, the key rate is now of the form
• The Holevo bound χ(ϵP E , LP E ) now depends on a small security parameter ϵP E and the number of symbols LP E used for parameter estimation. As mentioned above, long distances mandate precise estimation and thus large LP E . • The subtraction of an information penalty ∆(ϵ, L). ϵ is a small and composite security parameter (richer theoretical analysis includes more components to √ ϵ). ∆ has a dominant contribution in 1/ L and a typically negligible contribution in 1/L linked to the usage of universal hashing for privacy amplification. • While the SKR is useful for theoretical and system analysis, the protocol implementation doesn’t use a rate, but rather a number of bits, i.e. quantities proportional to L · SKR. βIAB is replaced by the entropy of the raw key (either via a worst-case
SKRreveal = pec βIAB − χ. 4
(4)
3
pec now plays a similar role as β: only a small deviation from 100% is acceptable. However, the result can be better than strict subframing. Here, FERqkd = (FERec )ζ , and was directly assumed negligible when writing the SKR equation. Discard-on-error subframing: In this case, the erroneous subframes are discarded from the raw key. The inputs of verification and privacy amplification are thus post-selected depending on Alice error correction results. The hypothesis of reverse reconciliation is broken and a richer security proof is required. One can hope for a SKR of the form SKRdiscard = pec (βIAB − χ − δdiscard ).
In this section, we describe the construction of the virtual channel in dimension d, focusing on a subframe of size n and assuming that n is a multiple of d. The full picture is then completed in Section 4 and Figure 3, adding the usage of error correction codes. We succinctly discuss the usage of Cayley-Dickson algebras for d ∈ {1, 2, 4, 8} and proceed with a more detailed discussion for high dimensions. The process starts with the generation of the virtual channel input: Bob generates the raw key as a random binary string, and from the raw key derives the codeword ⃗c ∈ {0, 1}n . We will see in Section 4 how the codeword is derived from the raw key. Bob then builds4 ⃗u ∈ {1, −1}n via ui = (−1)ci . The output is then built with the quantum channel data arranged in blocks of size d. A vector ⃗x ∈ Ωn (where Ω is either R or {1, −1}) is partitioned with the following notation, for i in (1, . . . , n/d) :
(5)
An overall pec factor reflects the fact that a portion of the subframes is discarded; now even a small value is tolerable. This comes at the cost of an additional penalty δdiscard in the information balance. The validity of this equation depends on the security framework and is the subject of ongoing research, beyond the scope of this work (Johnson et al. 2017; Pirandola and Papanastasiou 2024; Jaksch et al. 2024).
2.4
xi = (x(i−1)d+1 , . . . , xid ) ∈ Ωd d⃗ The prescript d denotes the fact that the corresponding vector lives in dimension d.
Tuning the Protocol SNR
3.1
Given a CV-QKD implementation on a specific link, the main tunable parameter is Alice modulation variance σa2 which directly affects the SNR at the reveiver. Choosing a suitable σa2 is a system-level engineering problem and the resulting SNR is central to the reconciliation design. We give here a simplified description: The main inputs are the target security parameter ϵ (10−10 here), the achievable frame size L, the excess noise measured on the physical link as a function of SNR, and the achieved β as a function of SNR. One may then simply plot the key rate as a function of SNR and choose the maximum. For concreteness, typical values are given in Table 1. Improvements cannot be considered in isolation and must be coordinated across parameters. For example, starting from a balanced system, a one-order-of-magnitude improvement in excess noise yields substantial benefits when combined with a two-order-of-magnitude increase in frame size. As illustrated in the Table 1, the higher the system performance, the lower the required SNR: hence the extended research by the CV-QKD community on low SNR reconciliation. An improved β is also linked to a small increase of optimal SNR.
106 10−2 90%
108 10−3 90%
108 10−3 95%
1010 10−4 95%
Achievable losses Optimal SNR
3 dB 0.8
11 dB 0.08
12 dB 0.10
16 dB 0.035
Cayley-Dickson Algebras
Up to d = 8, Cayley-Dickson algebras allow for a simplified construction of the virtual channel. These four algebras are the real and complex numbers (d = 1 and 2), the quaternions (d = 4) and the octonions (d = 8) which in particular have a multiplicative inverse: for a non-zero vector d ⃗x ∈ Rd there is a unique inverse d ⃗x−1 satisfying x · d ⃗x −1 = d ⃗x −1 · d ⃗x = d 1, d⃗ where d 1 is the multiplicative identity. The output of the virtual channel is obtained with these steps, with ⃗a and ⃗b defined in equation (1): 1. Bob computes a vector ⃗r ∈ Rn , with for each i ∈ (1, . . . , n/d): ri = d ⃗ui · d⃗bi . d⃗ 2. Bob discloses ⃗r on the classical channel. 3. Alice computes the output ⃗v of the virtual channel: vi = d⃗ri · d⃗ai d⃗
−1
.
4. ⃗v is a noisy and rescaled version of the raw key as we show below. Alice can thus proceed with error correction (Section 4) to retrieve the raw key.
Table 1: Example system parameters, achievable loss and optimal SNR. The excess noise is given as measured by Bob in shot noise units. Achievable loss are often converted to distance in standard telecom single mode fibre with 0.2 dB/km loss.
L Excess noise β
Virtual Channel
⃗v can be rearranged as: ⃗
vi = (d ⃗ui · d bi ) · d⃗ai d⃗
−1
(6)
= (d ⃗ui · (t · d⃗ai + d ⃗zi )) · d⃗ai = t · d ⃗ui + (d ⃗ui · d ⃗zi ) · d⃗ai
−1
−1
(7) (8)
In the last line, we used distributivity and (xy)y −1 = x(yy −1 ) = x, although our algebra is not associative. 4 In this article and Figure 3 we use the common "BPSK" convention mapping bits x ∈ {0, 1} to (−1)x ∈ {1, −1}.
5
3.2
Figure 2 displays the numerically computed βd = Id /IAB as a function of SNR, showing how the virtual channel mapping intrinsically loses information from the physical channel, but with negligible penalty for large enough d or small enough SNR. Independently of our specific virtual channel mapping, there is also an information loss from the approximation of the physical channel – which may carry an infinite amount of information per symbol at large SNR – by a binary input channel – which naturally saturates at 1 bit per symbol. This is illustrated by the plot of IBIAWGN /IAB in Figure 2, materializing the limit of multi-dimensional reconciliation for large d.
High-Dimensional Reconciliation
In higher dimensions, the virtual channel output is computed as follows: 1. Bob generates random orthogonal transformations d 5 ⃗ ⃗ d ⃗ui d Ri of R with the constraint d Ri (d bi ) = ∥d bi ∥ √d . 2. Bob discloses {d Ri } and {∥d⃗bi ∥} on the classical channel. 3. Alice computes the output ⃗v of the virtual channel: vi = d Ri (d⃗ai ). d⃗
(9)
4. ⃗v is again a noisy and rescaled version of the raw key.
100 98
d (%)
This process involves finding the orthogonal transformations that map the vectors d⃗bi to d ⃗ui , but picking 96 deterministically any transformation would reveal too IBIAWGN/IAB I16/IAB much information to Eve. The transformation must thus 94 I1/IAB I32/IAB be picked randomly. (Jouguet, Kunz-Jacques, and LeverI2/IAB I64/IAB 92 I4/IAB I128/IAB rier 2011) propose two constructions that we present in I8/IAB Appendix A. The first is in complexity O(d3 ) and can use 90 the QR decomposition readily implemented in popular 0.0 0.2 0.4 0.6 0.8 1.0 linear algebra libraries. The second is a modified version SNR of Householder method for QR decomposition, better suited to our particular problem: it has an improved Figure 2: Intrinsic reconciliation efficiency of the virtual O(d2 ) complexity. channel as a function of SNR. More explicitly, we show in Appendix B how the virtual channel output distribution given d ⃗ui and the public d Ri and ∥d⃗bi ∥ can be written as d BIAWGN channels:
4 Error Correction ! 2 ⃗ SNR ∥d bi ∥ d ⃗ui SNR σz √ , I . vi | d ⃗ui ∼ N d⃗ Once the virtual channel data are built, Alice and Bob 1 + SNR t d 1 + SNR T can adapt and use standard error correction techniques. (10) Several types of error-correcting codes have been explored The input of a modern coding decoder is generally a for CV-QKD: polar codes (Jouguet and Kunz-Jacques binary log-likelihood ratio (LLR): For a channel input 2014; Cao et al. 2023), raptor codes (Shirvanimoghaddam, Johnson, and Lance 2015; Zhou et al. 2019), Multi-Edge x ∈ {0, 1} and measured value y, Type LDPC codes (Jouguet, Kunz-Jacques, and LeverP (y|x = 0) LLR = ln . (11) rier 2011; Mani et al. 2021), Hadamard LDPC (Xing P (y|x = 1) et al. 2025), spatially coupled LDPC (Jiang et al. 2018), protograph based LDPC (Gümüş and Schmalen 2021; Cil In particular, for a BIAWGN channel with y = (−1)x + and Schmalen 2024b) repeat-accumulate LDPC (JohnN (0, σ 2 ), LLRBIAWGN = 2y/σ 2 . son, Chandrasetty, and Lance 2015), also, but to a lesser We can therefore write after proper scaling: extent spinal code (Wen et al. 2020). All these codes can have different variants in terms of construction, decoding −−→ 2t∥d⃗bi ∥ d⃗vi algorithm, and hardware or software implementation (for √ LLR = . d i d σz2 example LDPC codes can be quasi-cyclic (Milicevic et al. −−→ 2018), rate adaptative (Liu and Lamare 2014)). Alice can use the full vector LLR as the input of her In this section, we describe various schemes – illusdecoder. trated in Figure 3 – allowing to use error correction codes We also show in the Appendix B that the mutual on the virtual channel, restricting for simplicity the disinformation of the virtual channel is cussion to binary linear block codes. This includes LDPC λ codes which are the most studied for CV-QKD. See for exId = Eλ∼χ2d IBIAWGN SNR d ample (Lodewyck 2006) for early insights on the schemes described here. Later, in the simulation section, we use where IBIAWGN (1/σ 2 ), is the mutual information of the LDPC codes provided by (Cil and Schmalen 2024a), and BIAWGN channel for a given signal-to-noise ratio 1/σ 2 . a popular decoder when both complexity and reconcilia5 Since orthogonal transformations preserve distances, the factor tion efficiency matter: namely Belief Propagation (BP) ∥d⃗ b ∥ √ i ensures the transformed vector maintains its correct norm. with the Sum-Product Algorithm (SPA). d 6
Figure 3: Linear block coding schemes for multidimensional reverse reconciliation. The physical layer (prepare and measure steps of the protocol) is highlighted in green, the multidimensional mapping in red, (virtual) channel coding in blue, and bit generation/mapping in black. QRNG: Quantum Random Number Generator (or any true random number generator). Refer to sections 3 and 4 for a description of the individual components.
Decoding, performed on receiver side, aims to detect and correct bit errors introduced by disturbances during the transmission of the codeword. A matrix called the parity check matrix H of size (n − k) × n, is generally used. It represents a set of parity equations H⃗c = ⃗0 imposed during the encoding and is derived from G by solving HGT = 0. A noisy codeword will usually have a non-zero syndrome ⃗s = H⃗c In "modern coding" (Richardson and Urbanke 2008) the decoder does not work directly on binary bits, but on LLRs (as defined in equation (11)). Using this "soft"
Classical Coding Classical coding relies directly on the standard usage of linear codes. Consider a message m ⃗ ∈ {0, 1}k ; channel coding adds redundancy to this message before transmission on a noisy channel. Linear block codes define a binary generator matrix G of size k × n. Encoding consists in multiplying the (transposed) generator matrix by the message to obtain the codeword ⃗c = GT m ⃗ ∈ {0, 1}n . The code rate is defined as the density of information R = k/n in a codeword. 7
information, the decoder attempts to satisfy the parity equations. This is typically done via an iterative algorithm, called message passing, or belief propagation which gradually updates the LLRs according to the code constraints. At each iteration, the confidence levels evolve to make the received word increasingly consistent with the parity equations. This process can be interpreted as an attempt to make the estimated codeword converge towards a zero syndrome, i.e. towards a situation where H⃗c = ⃗0. Once the algorithm has converged, the decoder makes a hard decision on the updated LLRs to produce a final binary estimate of the codeword. The correct message must then be computed from the codeword. In our context, a code is chosen in advance. Bob generates randomly the raw key in {0, 1}k which is simply used as the message m ⃗ (see Figure 3). The overall reconciliation efficiency is given by:
correction and in particular systematic codes. It also highlights how a classical decoder can be tricked into performing coset decoding. From a base code with parity check matrix H of size r × n, a larger systematic code is built by concatenating to a message m ⃗ ∈ {0, 1}n the "parity bits" p⃗ = H m ⃗ into a codeword ⃗c = [ m ⃗ | p⃗ ] ∈ {0, 1}n+r . This larger code is in systematic form, meaning that the message can be read directly from the codeword (here by selecting the first n bits), and has generator and parity check matrices
Coset Coding
The result is again:
G′ = In | H T and H ′ = [ H | Ir ] .
For reconciliation, the raw key is m ⃗ and is transmitted on the virtual channel, while the parity bits p⃗ are transmitted on the errorless classical channel. The full codeword is thus transmitted on a composite channel. Alice may then use a classical decoder for the code H ′ : Raw key bits k the first n LLRs are computed from the virtual channel βIAB = = . formula, and the last r LLRs, from the errorless channel, Virtual channel bits n have values ±∞ corresponding to perfect knowledge. Hence, While this technique allows to use a standard decoder R β= . without modification, it requires the processing of an IAB n + r LLRs instead of n. This is a significant penalty in Note that this formula is often presented as a defini- the context of CV-QKD and its low code-rate regime. tion of β. Here, we defined β as an information ratio The reconciliation efficiency is now given by: independent of the coding technique. We show in this section how β is related to the code rate with the same Raw key bits - Revealed bits n−r k formula β = R/IAB for all the presented schemes. βIAB = = = . Virtual channel bits n n In coset coding, Bob directly generates the raw key as a random bit string ⃗c of size n and computes the non-zero syndrome ⃗s = H⃗c. ⃗c is not indeed a codeword of our linear code with parity check matrix H, but a codeword from the coset defined, for a fixed ⃗s, by {⃗c ∈ {0, 1}n : ⃗s = H⃗c}. Bob sends ⃗c on the virtual channel and the syndrome ⃗s on the classical channel: r = n − k bits of information from the raw key are revealed. When Alice attempts to decode ⃗c, she seeks convergence to the parity equations of the coset code, namely H⃗c = ⃗s. This requires a minor, but non-standard, modification of the decoding algorithm. This method has the key advantage that the encoding process is completely eliminated. In particular, while H is typically a sparse matrix (hence the name Low Density Parity Check code – LDPC), G is a large and dense matrix which is unpractical to build, store and use. Here, the overall reconciliation efficiency is given by: βIAB =
β=
IAB
.
Note that it is the rate R of the base code that matters, n and not the rate R′ = n+r of the larger systematic code.
5
Simulation
5.1
Simulation Framework
5.1.1
Aff3ct Toolbox
The open-source simulation software we have developed, HDirac, is based on Aff3ct (Cassagne et al. 2019), which is open source and licensed under the MIT licence. It is dedicated to simulating error correction systems. Written in C++11, it supports a wide range of correction codes. Its architecture is organised around two main abstractions:
Raw key bits - Revealed bits n−r k = = . Virtual channel bits n n
• Modules, which represent computational entities (e.g. a modulator or a channel).
The result is the same as for classical coding: β=
R
• Tasks, which correspond to operations performed within a module (e.g. modulation, demodulation, or addition of Gaussian noise).
R . IAB
Syndrome-Concatenation Coding
This architecture is based on StreamPU (Cassagne Syndrome concatenation is an alternative – mathemat- et al. 2023), a domain-specific embedded language dediically equivalent – presentation of coset coding, but it cated to software-defined radio. It enables the concise will be more familiar to the reader experienced in error description of parallel dataflow graphs and efficiently 8
exploits multicore architectures through pipelining and • Coding scheme (Accessible in HDirac: classical, replication parallelisms. coset, syndrome-concatenation). Our initial implementations relied directly on the built• Code rate R (accessible in HDirac). in decoder using syndrome-concatenation coding. We subsequently developed a new decoder supporting coset • Codeword size n (accessible in HDirac). decoding (which is not natively available in Aff3ct), together with less aggressive mathematical approxima• SNR, or equivalently, reconciliation efficiency β (actions – the original decoder is optimised for high-speed cessible in HDirac)6 . operation in standard telecommunications scenarios, alSome output of the simulation are input parameters beit at the cost of reduced reconciliation efficiency in the CV-QKD regime. The decoder implements a flood- of the protocol: ing sum-product algorithm (SPA). The results presented • Frame error rate (FER), or more precisely number here are obtained using this new decoder for both coset of frames simulated and number of errors (main coding and syndrome-concatenation coding. result of our simulation). 5.1.2
• Throughput and latency (results of the simulation, with various possible units).
Eigen Library
HDirac also relies on the Eigen library (Guennebaud and Jacob 2010), a C++ library for linear algebra that provides decompositions, numerical solvers and algorithms for matrix and vector operations. In our implementation, Eigen is used to handle linear algebra required in the Householder O(d3 ) implementation of the virtual channel.
As an illustrative example, consider a code with rate R ≈ 0.1 using a coset decoder with a maximum of 500 iterations. For parameters d = 64, k = 20000, n = 204800 and β = 93%, the simulation takes approximately one minute (on a single thread) to decode 100 frames, with no observed frame errors. In the results presented in this paper, we fix the max5.1.3 LDPC Codes imum number of SPA iterations to 500, and stop the We performed simulations using the parity check ma- simulation at the7 earliest of 100 frame errors or 1000 trices (H) published in (Cil and Schmalen 2024a). simulated frames . Typical simulator performances are given in Table 2. These are LDPC matrices constructed from protographs, The throughput8 for a virtual channel of dimension d = with adaptable code rates, presenting a state-of-the-art β/FER trade-off. Decoding was limited to syndrome con- 64 and coset coding are measured on eight threads (AMD catenation and coset approaches (as generator matrices Ryzen AI 9 HX 370 CPU) with 32 GiB of RAM (quadG were unavailable). Given its improved β performance channel LPDDR5x). The simulations were performed on without approximations, coset decoding was adopted as Dalek (Cassagne, Amiot, and Bouyer 2025), a cluster the primary method for CV-QKD simulations. These dedicated to emerging architectures and energy-aware. simulations allowed us to compare frame error rates as The results are reported for different values of n, while a function of β, for different dimensions and for several keeping k = 20000 fixed (R ≈ 0.2, 0.1 and 0.02). Two relevant code rates for CV-QKD with multidimensional regimes of β are considered: one corresponding to a frame error rate (FER) of approximately 100% (β = 100%), reconciliation. and another corresponding to a near-zero FER regime (β = 90%). 5.1.4 Simulation Parameters Comparing the performance of various codes applied to CV-QKD reconciliation requires specifying a number of parameters. We list here the most important parameters and highlight those which are accessible in HDirac.
R ≈ 0.2 ≈ 0.1 ≈ 0.02
n 102400 204800 1024000
β = 100% 126 43 6
β = 90% 281 130 25
• Type of error correction code (e.g., LDPC, polar, Table 2: Throughput (kb/s of processed information bits) raptor, ...). Decoding algorithm (e.g., horizontal with a decoder parallelised on eight threads (k = 20000). layered SPA, successive cancellation) and its parameters (number of iterations, implementation variants and hardware). Construction of the code. 5.2 Simulation Results This work focuses on a specific LDPC code and Figure 4 shows the coupled behaviour of the two reconcilflooding SPA, but HDirac can directly be used iation parameters of the CV-QKD SKR (Equation (2)): with other LDPC codes and can easily be adapted the reconciliation efficiency β and the FER. The figure to other type of codes thanks to its integration with 6 Note that the computation of β depends on the simulated Aff3ct. channel.
7 This explains why the error area is larger in regions with a • Simulated channel (e.g. BIAWGN, virtual for a high FER. given d, slice reconciliation channel). HDirac im8 The throughput is defined here as the number of information plements the BIAWGN and virtual channels with (k) bits processed – possibly leaving uncorrected errors – per unit various constructions and arbitrary dimension d. time.
9
FER 1.0 0.8 0.6 0.4
BIAWGN d=1 d=2 d=4 d=8 d=8 Hous. d=16 Hous. d=32 Hous. d=64 Hous. d=128 Hous.
0.2 0.0 80.0
82.5
85.0
87.5
90.0
92.5
95.0
97.5
100.0
Figure 4: FER as a function of β for R ≈ 0.1 (k = 20000, n = 204800) and coset coding.
illustrates the typical transition from the high SNR/low β regime with no decoding errors, to the low SNR regime with high error rates. With equations (3) and (4) the optimal regime corresponds to the highest β while maintaining the constraint FER ≈ 0%. Equation (5) allows for higher FER and thus higher β. The measurements are performed for various dimensions d, showing how increasing the dimension of the virtual channel improves the performance. As we can see, for this code rate R ≈ 0.1, using d = 8 (octonions) is already a large (> 10%) improvement from d = 1. β can be further improved (1.3%) with d increased to 64, with a result almost indistinguishable from the code performance on the BIAWGN channel. For d ≤ 8, Cayley-Dickson algebra are used while for d ≥ 8, the Householder method is used. No significant difference is observed at d = 8 for the octonion implementation and the Householder implementation (labelled Hous.). Figure 5 shows similar curves for various code rates R and fixed k = 20000. The figure illustrates that as R, and thus the SNR, is reduced, the virtual channel tends to a better approximation of the BIAWGN channel, even with low dimension d. We can also see that for this set of codes with fixed k, the BIAWGN channel curve only marginally depends on R. Figure 6 compares coset coding and syndrome concatenation coding. It confirms that the error rate is similar for these two methods. However, the information throughput is reduced for syndrome-concatenation coding because a larger amount of LLR nodes must be processed (larger by a ratio n+r n , so ≈ 2 for our low code rates). Finally, Figure 7 shows that the number of information bits (k) has a significant impact on the performance of a LDPC code. Here, the codes from (Cil and Schmalen 2024a) were expanded by a factor q with a quasi-cyclic construction. As k increases towards infinity, the "waterfall" curve observed in a β as a function of FER plot becomes steeper. In fact, it pivots around a FER of approximately 80% here and also for the other code constructions that we have tested. In these examples,
increasing the code size allows to achieve a better reconciliation efficiency as soon as the target FER is smaller than 80%, but at the cost of increasingly unpractical implementations.
6
Conclusion
In this work, we have presented a detailed review of multidimensional reconciliation in continuous-variable quantum key distribution, with a focus on high-dimensional constructions relevant to long-distance and low-SNR regimes. We have discussed the generalisation from algebraic constructions to arbitrary dimensions, and how it relies on random orthogonal transformations to preserve secrecy while enabling efficient decoding. Building on this virtual channel, we reviewed several practical schemes that allow linear error-correcting codes to be deployed in CV-QKD systems, highlighting their equivalence in terms of reconciliation efficiency and their different implementation trade-offs. A key contribution of this work is the introduction of HDirac, an open-source simulation platform designed to be both flexible and reproducible. By integrating tightly with the Aff3ct library and leveraging recent protograph-based LDPC codes, the simulator enables performance comparisons across dimensions, code rates, and reconciliation schemes. The results confirm that high-dimensional reconciliation can improve performance in the low-SNR regime, while also revealing non-trivial dependencies between the reconciliation dimension, frame error rate, and achievable efficiency. These observations underline the importance of jointly optimizing the reconciliation dimension, coding strategy, and system parameters rather than considering them in isolation. Beyond simulation, this article aims to lower the barrier between the CV-QKD and errorcorrection communities by providing explicit derivations, clear terminology, and practical implementation insights. As CV-QKD systems move towards higher symbol rates, longer distances, and real-time operation, reconciliation will remain a central performance bottleneck. Ongoing work in the research community naturally extends to-
10
R 0.1526, n=131072 1.0
BIAWGN d=8 d=64
0.8
FER
R=0.05, n=400000
0.6 0.4 0.2 0.0 92
94
96
98
100
92
94
96
98
100
92
R 0.0244, n=819200
94
96
98
100
94
96
98
100
R 0.0153, n=1310720
1.0
FER
0.8 0.6 0.4 0.2 0.0 92
Figure 5: FER as a function of β for various R, fixed k = 20000 and coset coding.
FER
Throughput (kb/s) FER 1.0
1.0
200
0.8
150
0.6
100
0.4
0.2
50
0.2
0.0
0
0.8 Synd-Cnct Coset FER Throughput
0.6 0.4
93
94
95
96
97
98
99
100
n=204800, q=1 n=409600, q=2 n=819200, q=4 n=1638400, q=8
0.0 92
93
94
95
96
97
98
99
100
Figure 6: FER and processed information throughput on the Figure 7: FER on the BIAWGN channel as a function of β BIAWGN channel for R ≈ 0.1 (k = 20000, n = 204800) and for R ≈ 0.1, coset coding and quasi-cyclic expansion of the either syndrome-concatenation or coset coding. The decoder code size by a factor q. was parallelised on eight CPU threads on the Dalek cluster, under the same conditions as for Table 2.
Acknowledgements wards tighter finite-size security analyses incorporating subframing strategies, improved modelling of the virtual channel noise, hardware-aware decoder optimisations, and the exploration of alternative coding paradigms. By consolidating existing knowledge and proposing practical tools, we hope that this work will contribute to the continued maturation and deployment of high-performance CV-QKD systems.
This work was supported by the European Commission under the project QKISS, grant agreement no. 101091448, and the project QSNP, grant agreement no. 101114043. The authors also acknowledge the support of the CIFRE PhD grant of Lucien Martial. The authors would like to thank Philippe Grangier for initiating this collaboration and for fruitful discussions.
11
A
Householder Methods
A.3
In (Stewart 1980), Stewart describes another method to generate a random orthogonal transformation in dimension d. A slightly modified version is the following: For each dimension i from d to 2, generate a random Householder transformation by drawing a random normal vector i⃗n (draw i coefficients from a standard normal distribution, and normalise the resulting vector), and extend this transformation to the whole space. For i = 1, pick randomly a transformation that multiplies the input by ±1 (0⃗n ∈ {0, 1}). Compose these d transformations for i from 1 to d. Noting that this construction is closely related the Householder QR decomposition of a matrix (which uses iteratively Householder transformations for dimensions d to 2), Stewart shows that the resulting transformation is uniformly distributed for the Haar measure in the orthogonal group O(d). Furthermore, the complexity of this method is O(d2 ) (both in time and space).
We describe here the methods proposed in (Jouguet, Kunz-Jacques, and Leverrier 2011) to adapt the Householder QR decomposition method, and the statistical analysis of (Stewart 1980) for multidimensional transformations in O(d3 ) and O(d2 ) complexity.
A.1
Householder Transformation
The reflection in Rd with respect to a hyperplane containing the origin is defined entirely by a unit normal vector ±⃗n. Such a transformation is also called a Householder transformation as is illustrated in Fig. 8. The transformation from ⃗x to ⃗y is given by the formula: ⃗y = ⃗x − 2(⃗x · ⃗n)⃗n Note in particular that the complexity of this transformation is O(d), while a general orthogonal transformation has complexity O(d2 ). Reversely, given two distinct vectors ⃗x and ⃗y of the same norm, there exists a unique Householder transformation that maps ⃗x to ⃗y , described by the normal vector −⃗ y ±⃗n = ∥⃗⃗xx−⃗ y∥ . If d = 1, the unique Householder transformation transforms x to −x. For the purpose of this appendix we use a modified definition of a Householder transformation, allowing ⃗n = ⃗0 to describe the identity. hyperplane ⃗x ⃗n
A.4
Adding the Constraints of Multidimensional Reconciliation
The second method of Jouguet et al. (Jouguet, KunzJacques, and Leverrier 2011) adds the required constraints for multidimensional reconciliation on top of Stewart method: the built random transformation must map Bob’s quantum channel data ⃗b to the input of privacy amplification ⃗u, and the description of the transformation (disclosed on the classical channel) must not reveal additional data to Eve. We use the following notations: • The algorithm takes as input normalised vectors ⃗b and ⃗u in Rd .
−2(⃗x · ⃗n) ⃗n
• For i from d to 1, the vector i⃗n ∈ Ri describes a (modified) Householder transformation i H̃ in the subspace composed of the last i coordinates of Rd . d i H is its extension to the whole space R .
⃗y O
• i Q = d H ◦ d−1 H ◦ . . . i H is the composition of the transformations from i to d.
Figure 8: Householder Transformation.
A.2
Stewart Method
• d ⃗u = ⃗u, and for i < d, i ⃗u is the last i coordinates of u). (i ⃗u can be computed only once the i H from i Q(⃗ previous iterations are known.)
QR Decomposition Method
The first method proposed in (Jouguet, Kunz-Jacques, and Leverrier 2011) and described in more detail in (Gümüş et al. 2024) is the following. Given two normalised vectors ⃗b and ⃗u in Rd , our goal is to build a random orthogonal transformation R such that R(⃗b) = ⃗u. • Generate a d × d matrix by drawing randomly each of its elements from N (0, 1). Compute the QR decomposition (complexity O(d3 )) of this matrix. Keep the Q component: Q is a random orthogonal matrix (Stewart 1980).
• We also note i⃗e1 the first vector of the canonical basis of Ri and i⃗b the last i coordinates of ⃗b.. The algorithm is then the following. For i from d to 2: 1. Build a random unit vector i⃗g ∈ Ri such that i⃗g ·i ⃗u = ⃗ i e⃗1 · i b = bd−i+1 . A detailed method is given at the end of this section. 2. Find H̃i the Householder transformation that maps ⃗g − i⃗e1 g to i⃗e1 : i⃗n = i . i⃗ ∥ i⃗g − i⃗e1 ∥
For i = 1, pick the transformation that multiplies by • Find H, the Householder transformation such that sign( u/bd ): 1⃗n ∈ {0, 1}. 1⃗ H(Q.⃗u) = ⃗b. In the multidimensional reconciliation context, Bob • Our result is the transformation R = H ◦ Q. disclose the vectors i⃗n to Alice, who iteratively apply the 12
d transformations on here quantum channel data ⃗a to By orthogonal invariance of isotropic Gaussians, the compute her noisy version of ⃗u. term in R(⃗z) is a vector of d independent variables distributed as N (0, σz2 ). For given ∥⃗a∥ and proper scaling, Building i⃗g we thus recognise a BIAWGN channel. 1. Generate a random vector i⃗h ∈ Ri by drawing i Noting IBIAWGN (ζ) the mutual information of the BIcoefficients from a standard normal distribution. AWGN channel with signal-to-noise ratio ζ, the mutual 2. Find i α ∈ R such that i ⃗u · (i⃗h + i α i ⃗u) = bd−i+1 ∥ i⃗h + information of the virtual channel is u∥. i α i⃗ 1 By squaring it, the equation can be written as Id = I(⃗u; ⃗v | R, ∥⃗a∥) (14) d 2 2 2 + i α (Y − bd−i+1 Y ) T ∥⃗a∥2 1 = E∥ ⃗a ∥2 ∼χ2 dIBIAWGN (15) 2 d + d σa dσz2 i α(2XY − 2bd−i+1 X) λ (X 2 − b2 Z) =0 = Eλ∼χ2d IBIAWGN SNR . (16) d where: Reverse reconciliation: In the reverse scenario, ⃗z and • X = i ⃗u · i⃗h = i⃗h · i ⃗u, ∥⃗b∥ are correlated and we cannot directly conclude. Instead, using equation (1) and manipulating Gaussian • Y = ∥ i ⃗u∥2 , distributions for the individual components ai and bi , we • Z = ∥ i⃗h∥2 . may write 9 This quadratic equation can have two solutions. σa2 σz2 tσa2 ⃗ However, since it is obtained by squaring the origib, I . ⃗a | ⃗b ∼ N T σa2 + σz2 T σa2 + σz2 nal constraint, the sign information is lost. Hence, only one of the two solutions satisfies the original Because the covariance is isotropic, the result is similar afequation. The valid solution is the one such that ter an orthogonal transformation (recall that ⃗v = R(⃗a)): ! sign i ⃗u · (i⃗h + α i ⃗u) = sign(bd−i+1 ), 2 2 2 ⃗ σ σ tσ ∥ b∥ ⃗ u z a a √ , I . ⃗v | ⃗b, R ∼ N T σa2 + σz2 d T σa2 + σz2 Therefore, the appropriate root must be chosen according to the sign of bd−i+1 . In practice, Given R, knowledge of ⃗b is equivalent to knowledge of √ {⃗u, ∥⃗b∥}. Consequently, −B + ∆ , if bd−i+1 ≥ 0, ! 2A√ iα = tσa2 ∥⃗b∥ ⃗u σa2 σz2 ⃗ −B − ∆ , otherwise, √ , I . ⃗v | ⃗u, R, ∥b∥ ∼ N T σa2 + σz2 d T σa2 + σz2 2A where:
For the individual components vi , we can again identify a BIAWGN channel with
• A = Y 2 − b2d−i+1 Y, • B = 2XY − 2b2d−i+1 X,
2t∥⃗b∥ vi LLR = √ d σz2
• C = X − b Z, 2
2
• ∆ = B 2 − 4AC.
i
B
i
∥⃗b∥2 SNR T σa2 + σz2 d
SNRd,∥⃗b∥ =
⃗h + α ⃗u i i . g is then defined as i⃗g = i i⃗ ⃗ ∥ h + α ⃗u∥
Because ∥⃗b∥2 /(T σa2 + σz2 ) is χ2d distributed, the mutual information of the virtual channel is again
i
Virtual channel mutual infor1 mation Id = I(⃗u; ⃗v | R, ∥⃗b∥) = E
λ∼χ2d
d
IBIAWGN
λ SNR d
We give in this appendix more details on the mathematical description of the virtual channel. We work directly 9 More explicitly, in Rd and simplify the notation dropping d and i: d ⃗xi is a2i (bi − tai )2 noted ⃗x. p(ai | bi ) ∝ p(bi | ai )p(ai ) ∝ exp − − . 2σz2 2σa2 Direct reconciliation: Consider first the direct scenario. Here, ⃗u and R are generated by Alice, with R(⃗a) = Expanding the exponent and completing the square yields 2 ! ∥⃗a∥ √⃗ud . The virtual channel output is 2 p(ai | bi ) ∝ exp −
⃗v = R(⃗b) = R(t⃗a + ⃗z) ⃗u = t∥⃗a∥ √ + R(⃗z). d
(12)
1 2 2σa|b
where
(13)
13
2 σa|b =
ai −
tσa bi T σa2 + σz2
σa2 σz2 . T σa2 + σz2
,
.
References
Guennebaud, G and B Jacob (2010). Eigen v3. http://eigen.tuxfamily.org. Cao, Z, X Chen, G Chai, K Liang, and Y Yuan (Apr. Gümüş, K, J Frazão, V Vliet, S Heide, M Hout, G Liga, 2023). “Rate-Adaptive Polar-Coding-Based ReconciliYC Gultekin, A Albores-Mejia, T Bradley, A Alvarado, ation for Continuous-Variable Quantum Key Distribuand C Okonkwo (Aug. 2024). Rate-adaptive Recontion at Low Signal-to-Noise Ratio”. Phys. Rev. Appl. ciliation for Experimental Continuous-variable Quan19 (4), p. 044023. doi: 10.1103/PhysRevApplied.19. tum Key Distribution with Discrete Modulation over a 044023. Free-space Optical Link. doi: 10.48550/arXiv.2408. Cassagne, A, N Amiot, and M Bouyer (2025). “Dalek: 12522. An Unconventional and Energy-Aware Heterogeneous Gümüş, K and L Schmalen (2021). “Low Rate Cluster”. ArXiv abs/2508.10481. doi: https://doi. Protograph-Based LDPC Codes for Continuous Variorg/10.48550/arXiv.2508.10481. able Quantum Key Distribution”. 2021 17th InternaCassagne, A, O Hartmann, M Léonardon, K He, C Lertional Symposium on Wireless Communication Sysoux, R Tajan, O Aumage, D Barthou, T Tonnellier, tems (ISWCS), pp. 1–6. doi: 10.1109/ISWCS49558. V Pignoly, B Le Gal, and C Jégo (2019). “AFF3CT: A 2021.9562244. Fast Forward Error Correction Toolbox!” SoftwareX HDirac (June 2026). Version v1.0.0. url: https : / / 10, p. 100345. issn: 2352-7110. doi: https : / / doi . github.com/aff3ct/HDirac. org/10.1016/j.softx.2019.100345. Jaksch, K et al. (Oct. 2024). Composable free-space Cassagne, A, R Tajan, O Aumage, C Leroux, D Barthou, continuous-variable quantum key distribution using disand C Jégo (2023). “StreamPU: A DSEL for high crete modulation. arXiv: 2410.12915 [quant-ph]. throughput and low latency software-defined radio Jiang, XQ, S Yang, P Huang, and G Zeng (2018). “Highon multicore CPUs”. Concurrency and Computation: Speed Reconciliation for CVQKD Based on Spatially Practice and Experience 35.23, e7820. doi: https : Coupled LDPC Codes”. IEEE Photonics Journal 10.4, //doi.org/10.1002/cpe.7820. pp. 1–10. doi: 10.1109/JPHOT.2018.2853736. Cil, EE and L Schmalen (Sept. 2024a). “An open-source Johnson, SJ, AM Lance, L Ong, M Shirvanimoghaddam, library for information reconciliation in continuousTC Ralph, and T Symul (Feb. 2017). “On the probvariable QKD”. Proc. International Conference on lem of non-zero word error rates for fixed-rate error Quantum Cryptography (QCRYPT). poster presentacorrection codes in continuous variable quantum key tion, https://arxiv.org/abs/2408.00569. Vigo, Spain. distribution”. New Journal of Physics 19.2, p. 023003. Cil, EE and L Schmalen (2024b). “Rate-Adaptive doi: 10.1088/1367-2630/aa54d7. Protograph-Based Raptor-Like LDPC Code for Johnson, SJ, VA Chandrasetty, and AM Lance (2015). Continuous-Variable Quantum Key Distribution”. AdRepeat-Accumulate Codes for Reconciliation in Convanced Photonics Congress 2024. Optica Publishing tinuous Variable Quantum Key Distribution. arXiv: Group, JTu1A.51. doi: 10.1364/BGPP.2024.JTu1A. 1510.03510 [cs.IT]. 51. Jouguet, P and S Kunz-Jacques (Mar. 2014). “High perDai, J, XQ Jiang, T Wang, P Huang, and G Zeng (Aug. formance error correction for quantum key distribution 2025). “Arbitrarily-high-dimensional reconciliation via using polar codes”. Quantum Info. Comput. 14.3-4, cross-rotation for continuous-variable quantum key pp. 329–338. issn: 1533-7146. distribution”. Phys. Rev. A 112 (2), p. 022610. doi: Jouguet, P, S Kunz-Jacques, and A Leverrier (Dec. 2011). 10.1103/q3s4-ht52. “Long-distance continuous-variable quantum key distriFerenczi, A, P Grangier, and F Grosshans (2007). “Calbution with a Gaussian modulation”. Phys. Rev. A 84 ibration Attack and Defense in Continuous Variable (6), p. 062317. doi: 10.1103/PhysRevA.84.062317. Quantum Key Distribution”. 2007 European Confer- Jouguet, P, S Kunz-Jacques, A Leverrier, P Grangier, ence on Lasers and Electro-Optics and the Internaand E Diamanti (2013). “Experimental demonstration tional Quantum Electronics Conference, pp. 1–1. doi: of long-distance continuous-variable quantum key dis10.1109/CLEOE-IQEC.2007.4386772. tribution”. Nature Photonics 7.5, pp. 378–381. issn: Fossier, S, E Diamanti, T Debuisschert, R Tualle1749-4893. doi: 10.1038/nphoton.2013.63. Brouri, and P Grangier (May 2009). “Improvement of Leverrier, A (May 2017). “Security of Continuouscontinuous-variable quantum key distribution systems Variable Quantum Key Distribution via a Gaussian by using optical preamplifiers”. Journal of Physics de Finetti Reduction”. Phys. Rev. Lett. 118 (20), B: Atomic, Molecular and Optical Physics 42.11, p. 200501. doi: 10.1103/PhysRevLett.118.200501. p. 114014. doi: 10.1088/0953-4075/42/11/114014. Leverrier, A, R Alléaume, J Boutros, G Zémor, and P Grosshans, F and P Grangier (Jan. 2002a). “ContinuGrangier (Apr. 2008). “Multidimensional reconciliaous Variable Quantum Cryptography Using Cohertion for a continuous-variable quantum key distribuent States”. Phys. Rev. Lett. 88 (5), p. 057902. doi: tion”. Physical Review A 77.4. issn: 1094-1622. doi: 10.1103/PhysRevLett.88.057902. 10.1103/physreva.77.042325. – (Apr. 2002b). “Reverse reconciliation protocols for Leverrier, A, F Grosshans, and P Grangier (June 2010). quantum cryptography with continuous variables”. “Finite-size analysis of a continuous-variable quantum Proceedings of the 6th International Conference on key distribution”. Phys. Rev. A 81 (6), p. 062343. doi: Quantum Communications, Measurement, and Com10.1103/PhysRevA.81.062343. puting.
14
Liu, J and RC de Lamare (2014). Rate-Compatible LDPC Codes Based on Puncturing and Extension Techniques for Short Block Lengths. arXiv: 1407.5136 [cs.IT]. Lodewyck, J (Dec. 2006). “Dispositif de distribution quantique de clé avec des états cohérents à longueur d’onde télécom”. Theses. Université Paris Sud - Paris XI. url: https : / / pastel . hal . science / tel 00130680. Mani, H, T Gehring, P Grabenweger, B Ömer, C Pacher, and UL Andersen (June 2021). “Multiedge-type lowdensity parity-check codes for continuous-variable quantum key distribution”. Phys. Rev. A 103 (6), p. 062419. doi: 10.1103/PhysRevA.103.062419. Milicevic, M, C Feng, LM Zhang, and PG Gulak (2018). “Quasi-cyclic multi-edge LDPC codes for long-distance quantum cryptography”. npj Quantum Information 4.1, p. 21. issn: 2056-6387. doi: 10 . 1038 / s41534 018-0070-6. Pirandola, S and P Papanastasiou (June 2024). “Improved composable key rates for CV-QKD”. Phys. Rev. Res. 6 (2), p. 023321. doi: 10.1103/PhysRevResearch. 6.023321. Richardson, TJ and RL Urbanke (2008). Modern Coding Theory. Cambridge University Press. url: https:// doi.org/10.1017/CBO9780511791338. Shirvanimoghaddam, M, SJ Johnson, and AM Lance (2015). “Design of Raptor codes in the low SNR regime with applications in quantum key distribution”. 2016 IEEE International Conference on Communications (ICC), pp. 1–6. url: https://api.semanticscholar. org/CorpusID:12529894. Stewart, GW (1980). “The Efficient Generation of Random Orthogonal Matrices with an Application to Condition Estimators”. SIAM Journal on Numerical Analysis 17.3, pp. 403–409. issn: 00361429. url: http://www.jstor.org/stable/2156882 (visited on 03/19/2026). Van Assche, G, J Cardinal, and N Cerf (2004). “Reconciliation of a quantum-distributed Gaussian key”. IEEE Transactions on Information Theory 50.2, pp. 394–400. doi: 10.1109/TIT.2003.822618. Wen, X, Q Li, H Mao, Y Luo, B Yan, and F Huang (2020). “Novel reconciliation protocol based on spinal code for continuous-variable quantum key distribution”. Quantum Information Processing 19.10, p. 350. doi: 10.1007/s11128-020-02853-9. Xing, L, C Zhou, J Ma, Z Chen, S Yu, and X Wang (July 2025). “Information reconciliation with extremely low signal-to-noise ratio for continuous-variable quantum key distribution with LDPC-Hadamard codes”. Phys. Rev. Appl. 24 (1), p. 014018. doi: 10.1103/mgpn-j9g2. Yang, S, Z Yan, H Yang, Q Lu, Z Lu, L Cheng, X Miao, and Y Li (Oct. 2023). “Information reconciliation of continuous-variables quantum key distribution: principles, implementations and applications”. EPJ Quantum Technology 10, p. 40. doi: 10.1140/epjqt/ s40507-023-00197-8. Zhou, C, X Wang, Y Zhang, Z Zhang, S Yu, and H Guo (Nov. 2019). “Continuous-Variable Quantum Key Distribution with Rateless Reconciliation Protocol”. Phys. Rev. Appl. 12 (5), p. 054013. doi: 10 . 1103 / PhysRevApplied.12.054013. 15