ConceptioArchivearXiv CS
arXiv CSopen access

Quantum Key Distribution Without Shared Reference Frame Under Unital Noise

Unknown · 2026 · arxiv_cs
arXiv CS · Papers · License: Open Access · 2026
Open Source ↗Direct PDF ↓
cryptography, security, privacy, cybersecurity

SUBMITTED TO ARXIV ON JUNE 23, 2026.

1

Quantum Key Distribution Without Shared Reference Frame Under Unital Noise

arXiv:2606.23239v1 [quant-ph] 22 Jun 2026

Junaid ur Rehman, Shehbaz Tariq, and Symeon Chatzinotas, Fellow, IEEE

Abstract—We consider a general and practical scenario of quantum key distribution (QKD) over an unknown, stationary, unital qubit channel. Furthermore, due to practical limitations, e.g., relative movement and rotation of communicating parties, a global shared reference frame cannot be established. This scenario can routinely appear in satellite QKD. We propose two methods to overcome the physical qubit noise and the lack of shared reference frame. The first proposed approach involves constructing the Pauli transfer matrix (PTM) description of the channel, which we achieve without requiring a shared reference frame, by absorbing the lack of shared reference frame in the channel definition. This is followed by the identification of singular vectors of PTM as the Bloch vectors for optimal signal states. In the optimized local bases, the resulting correlations are equivalent, up to outcome relabeling, to those of a Pauli channel, allowing us to show the optimality of the BB84 and six-state QKD protocols under these conditions. The second approach, called the sequential basis matching (SBM) involves sequentially identifying the channel-optimized local bases that enable QKD. We show that both of these approaches result in the same effective key exchange rate for QKD. Index Terms—Quantum key distribution, quantum process tomography, quantum states, quantum signals, secret key rate.

I. I NTRODUCTION Quantum key distribution (QKD) enables two distant parties to establish secret keys with security based on quantummechanical principles rather than computational hardness assumptions [1]–[4]. This distinction matters for long-term confidentiality, since information-theoretically secure keys are not compromised by future increases in computational power. Practical discrete-variable protocols such as BB84 [5], [6] and six-state QKD [7] encode qubits in mutually unbiased preparation and measurement bases. Their achievable key rates depend directly on the quantum bit error rates (QBERs) observed in those bases. Therefore, both the security analysis and practical performance of QKD depend on how accurately the physical system realizes the assumed bases and their relative alignment. J. ur Rehman is with the Department of Electrical Engineering, the Interdisciplinary Research Center for Advanced Quantum Computing, and the Interdisciplinary Research Center for Communication and System Sensing, King Fahd University of Petroleum and Minerals (KFUPM), Dhahran 31261, Saudi Arabia (e-mail:[email protected]). S. Tariq, and S. Chatzinotas are with Interdisciplinary Centre for Security, Reliability and Trust (SnT), University of Luxembourg, 1855 Luxembourg City, Luxembourg (e-mail: [email protected]; [email protected]). J. ur Rehman would like to acknowledge the support from the KFUPM through the Ibn Battuta Global Scholarship grant with number ISP2651. The work of Shehbaz Tariq and Symeon Chatzinotas was supported by the project LUQCIA Funded by the European Union – Next Generation EU, with the collaboration of the Department of Media, Connectivity and Digital Policy of the Luxembourgish Government in the framework of the RRF program. (Corresponding author: Junaid ur Rehman.)

Satellite QKD is a promising pathway toward global-scale quantum-secure communication because free-space optical links can mitigate the distance limitations imposed by fiber attenuation. Notably, the Micius quantum experiments in space [8] and the experimental quasi-single-photon transmission from satellite to Earth [9] demonstrate the feasibility of long-distance satellite-ground quantum optical links. However, satellite QKD also introduces practical challenges that are less prominent in fixed terrestrial links, including time-varying link geometry, acquisition-pointing-tracking constraints, atmospheric loss, detector noise, platform motion, and attitude drift [8]–[10]. For polarization-encoded satellite QKD, an important additional challenge is maintaining a common polarization reference frame between the transmitter and receiver [11]. Standard BB84 and six-state QKD implicitly assume that Alice’s preparation bases and Bob’s measurement bases are aligned. For BB84, this means that the two bases used for key generation and parameter estimation correspond to the same physical directions at Alice and Bob. For the six-state protocol, the assumption is stronger, since the full set of three mutually unbiased qubit bases must be consistently aligned between the two parties. Without a shared reference frame, Alice’s and Bob’s local qubit descriptions may be related by an unknown rotation, so a state prepared in one local basis may not be measured in the intended corresponding basis at the receiver [12], [13]. This problem appears naturally in polarizationencoded satellite links and in other platforms where the relative orientation between communicating parties is not fixed [14]. Several approaches have been proposed to mitigate reference-frame mismatch. In satellite links, polarization-basis tracking can be supported by orbit prediction and optical compensation, for example using an autorotatable half-wave plate [8], [9]. Reference-frame-independent QKD also reduces the need for active alignment by using measurement statistics that are insensitive to certain frame rotations [14]. These approaches address important aspects of basis mismatch. However, when the physical qubit channel is also unknown, the observed statistics reflect both reference-frame misalignment and physical qubit noise. In this setting, it is not enough to consider only how to restore a common reference frame; one must also determine how Alice and Bob should choose their local QKD bases when neither the reference frame nor the channel’s preferred noise directions are known. In this work, we consider an unknown, stationary, unital qubit channel. Unital channels preserve the maximally mixed state and include important qubit noise models such as random unitary channels and Pauli channels [15]–[17]. This assumption is natural for polarization-based optical commu-

2

nication when the dominant impairments are random polarization transformations, depolarization, or anisotropic Paulitype polarization noise. However, a Pauli-channel description normally assumes that the Pauli error directions are defined with respect to a known reference frame [18]. When no shared reference frame is available, the channel may still have preferred noise directions, but Alice and Bob do not know how those directions are oriented relative to their local Pauli frames. Related works address parts of this setting from different directions. Communication without a shared reference frame has been studied in [12], [13], and reference-frame-independent QKD was proposed in [14]. Mismatched-basis statistics and tomography have been used to improve QKD analysis or relax assumptions on the source and channel [19], [20]. QKD under asymmetric noise has also been analyzed, showing that basis-dependent QBERs can strongly affect the achievable key rate [21]. The problem addressed here is the joint one: how to identify channel-adapted local bases for BB84 and sixstate QKD when both the reference-frame mismatch and the stationary unital qubit channel are unknown. Our main idea is to treat the unknown reference-frame mismatch as part of the channel observed by Alice and Bob. Rather than separately estimating Alice’s local frame, Bob’s local frame, and the physical noise process, the parties characterize the effective transformation from Alice’s local preparations to Bob’s local measurements. This effectivechannel viewpoint allows the reference-frame mismatch and the unital qubit noise to be handled jointly, using only experimentally accessible preparation-and-measurement statistics. The formal channel model and its Pauli transfer matrix (PTM) representation are introduced in the following sections. Using this effective-channel description, we develop optimized local signaling bases for QKD. One method reconstructs the effective PTM and uses singular value decomposition (SVD) to identify the local preparation and measurement directions that best match the channel. A second method, called sequential basis matching (SBM), finds the same bases operationally through a sequential search over mutually unbiased directions. In the optimized bases, the observed correlations are equivalent, up to outcome relabeling, to those of a Pauli channel. The resulting asymmetric QBERs are then used to evaluate the asymptotic key rates of BB84 and six-state QKD. We also propose a second method, called SBM, which provides an operational alternative to explicit PTM reconstruction and decomposition. Instead of first estimating the effective PTM, SBM adaptively searches for the local preparation and measurement bases that maximize the probability that Bob obtains the measurement outcome associated with Alice’s prepared state. Equivalently, the search identifies bases that minimize the corresponding basis-dependent QBER. The procedure identifies one optimized basis at a time while preserving the mutually unbiased structure required for BB84 and six-state QKD. Under exact channel estimation and successful convergence of the search, SBM yields the same optimized QBERs and asymptotic secret key rates as the PTM/SVDbased method. The key contributions of this paper are:

SUBMITTED TO ARXIV ON JUNE 23, 2026.

We formulate QKD without a shared reference frame over an unknown, stationary, unital qubit channel, motivated by satellite QKD and other moving-platform quantum communication scenarios. We show that the referenceframe mismatch and physical qubit noise can be absorbed into a single effective Alice-to-Bob channel. • We develop two basis-optimization methods, namely the PTM/SVD method and SBM, for identifying local mutually unbiased preparation and measurement bases adapted to this effective channel. • We show that, in the optimized bases, the nontrivial Bloch block of the effective channel is diagonal, so the resulting correlations are equivalent, up to outcome relabeling, to those of a Pauli channel. • We evaluate BB84 and six-state QKD under the resulting asymmetric QBERs and show through numerical examples that optimized signaling can recover positive asymptotic key rates in regimes where standard localbasis signaling may fail. The remainder of this paper is organized as follows. Section II presents the required preliminaries and system model. Section III develops the proposed optimized-signaling methods based on PTM/SVD and SBM. Section IV provides numerical examples for random unitary channels and compares optimized signaling with standard BB84 and six-state QKD. Section V concludes the paper and outlines future directions. •

II. P RELIMINARIES & S YSTEM M ODEL A. Preliminaries A quantum state ρ is a unit-trace positive semidefinite operator, i.e., density operator, on the Hilbert space H. We denote by D (H), the convex set of density operators. The extremal points of this set are the pure states ρ = |ψ⟩⟨ψ| and can be equivalently represented by the state vector |ψ⟩ ∈ H. A quantum state ρ can be decomposed in Pauli basis 1 (1) ρ = (I + rx X + rY Y + rz Z) , 2 where I is the identity matrix and       0 1 0 −i 1 0 , Y = , and Z = (2) X= 1 0 i 0 0 −1 are the well-known Pauli matrices. The vector ⃗r = [1, rX , rY , rZ ] is called the Pauli state-vector [22, Suppelemntal Material]. A quantum channel N (·) is a trace-preserving completely positive map N : B (H) 7→ B (H),

(3)

where B (H) is the set of bounded operators on H. Clearly D (H) ⊂ B (H). A convenient representation of quantum channels is the well-known Kraus operator-sum representation [15], [16] X N (ρ) = Ki ρKi† , (4) i

P where the Kraus operators Ki satisfy i Ki† Ki = I. In this work, we are particularly interested in unital quantum channels

UR REHMAN: QUANTUM KEY DISTRIBUTION WITHOUT SHARED REFERENCE FRAME UNDER UNITAL NOISE

interpreted as the probability that the state is ρ would pass a test for being the same as σ or vice versa [17]. The following elementary property of unital channels will be helpful in our later discussion.

TABLE I L IST OF N OTATIONS AND S YMBOLS Symbol

Definition

H D(H) B(H) ρ |ψ⟩ ⃗ r

Hilbert Space and States Hilbert space of a qubit Convex set of density operators on H Set of bounded operators on H Density operator Pure state vector Pauli state vector of a qubit state; its nonidentity components form the Bloch vector

Pauli Operators and Pauli Transfer Matrix I, X, Y, Z Identity operator and Pauli operators Pj Pauli basis operator, with P0 = I, P1 = X, P2 = Y , and P3 = Z RN PTM representation of the channel N N Ri,j (i, j)-th entry of the PTM of channel N A→B R Effective PTM from Alice’s local frame to Bob’s local frame Quantum Channel and Reference Frames N Unital qubit channel Ki Kraus operators of N UA , U B Unknown local-frame unitaries associated with Alice and Bob pI , pX , pY , pZ Pauli-channel error probabilities OA , O B

Σ σ1 ≥ σ2 ≥ σ3 θ, ϕ

Qz , Q x , Q y h(x) H({pi }) RBB84 Rsix-state λi,j

SVD and Basis Optimization Orthogonal matrices whose columns define Alice’s preparation directions and Bob’s measurement directions, respectively Diagonal matrix of singular values obtained from the SVD step applied to RA→B Ordered nontrivial singular values used to define the optimized basis-dependent QBERs Polar and azimuthal angles parameterizing a pure qubit state QKD Performance QBERs in the Z, X, and Y bases Binary Shannon entropy P Shannon entropy, − i pi log2 pi Asymptotic BB84 secret key rate in bits per sifted detected signal Asymptotic six-state QKD secret key rate in bits per sifted detected signal Eigenvalue parameters in the six-state key-rate expression

that by their property N (I) = I, by satisfying P are defined † i Ki Ki = I. Physically, these maps do not “unmix” a mixed density operator [23]. Special examples of unital maps include √ random unitary channels, Ki = pi Ui with unitaries Ui and probability vector [pi ]i . A Pauli channel is a special case of the random unitary channel where the channel unitaries are the Pauli operators (2): NP (ρ) = pI ρ + pX XρX † + pY Y ρY † + pZ ZρZ † .

3

(5)

The overlap of a quantum state ρ with another state σ is given by tr(ρσ). In case of at least one of ρ or σ being pure, this quantity is same as the state fidelity and can be interpreted as the component of one of the states in the direction of the other. In the communication scenario, this can also be

Property 1. For two orthogonal qubit states |ψ0 ⟩, |ψ1 ⟩, and the unital channel N Tr{|ψ0 ⟩⟨ψ0 | N (|ψ1 ⟩⟨ψ1 |)} = Tr{|ψ1 ⟩⟨ψ1 | N (|ψ0 ⟩⟨ψ0 |)}. (6) Proof. We have Tr{|ψ0 ⟩⟨ψ0 | N (|ψ1 ⟩⟨ψ1 |)}

(7)

= Tr{(I − |ψ1 ⟩⟨ψ1 |) N (I − |ψ0 ⟩⟨ψ0 |)}

(8)

= Tr{|ψ1 ⟩⟨ψ1 | N (|ψ0 ⟩⟨ψ0 |)}.

(10)

= Tr{(I − |ψ1 ⟩⟨ψ1 |) (N (I) − N (|ψ0 ⟩⟨ψ0 |))}

(9)

The first equality is due to the completeness of the orthonormal basis, i.e., |ψ0 ⟩⟨ψ0 | + |ψ1 ⟩⟨ψ1 | = I. The second equality is due to the linearity of N . The last equality is due to the linearity of trace operator, the unital property of the channel N (I) = I, and the fact that the trace of a density operator is unity. This means that the component of |ψ0 ⟩ introduced by the unital channel when acting on |ψ1 ⟩ is the same the other way round as well. Communicating classical/digital data over quantum channels often employs such sets of orthogonal states for communication. Then, we can define and interpret pex,y = Tr{|ψx ⟩⟨ψx | N (|ψy ⟩⟨ψy |)}, x ̸= y as the probability of error when states {|ψ0 ⟩ , |ψ1 ⟩} are employed for communication and projected in the same basis on the decoder’s side. The Property 1 establishes that the errors are symmetric, i.e., pe0,1 = pe1,0 = ϵ, and this setting of basis states as input and projection on the same basis at the output simulates a binary symmetric channel. B. Pauli Transfer matrix An equivalent representation of quantum channels is via PTM [22]. The entries of PTM of a quantum channel N N are defined as Ri,j = 21 Tr{Pi N (Pj )}, where P0 = I and P1 , P2 , P3 are the Pauli matrices X, Y , and Z, respectively. The PTM representation makes several of the quantum channel properties explicit and simple [24], [25]. For example, the map N is trace preserving if and only if the first row of RN is the vector [1, 0, 0, 0] [24]. Similarly, the map is unital if the first column has the same structure. Property 2 ( [24]). The composition of multiple channels become matrix multiplication of their respective PTMs, i.e., if two quantum channels operate one after the other N ◦ M (·), then the PTM of the composite channel is the matrix multiplication of two PTMs, i.e., RN ◦M = RN RM . A powerful consequence of the PTM representation of quantum channels is the ability to construct the description of the channel with fewer experimental configurations if some knowledge/probable assumption about the channel is known. This is in contrast to general quantum process tomography where d4 experimental configurations are needed to obtain

4

SUBMITTED TO ARXIV ON JUNE 23, 2026.

the complete classical description of a d-dimensional channel [26]. For example, the direct reconstruction of PTM of a d2 dimensional unital channel can be achieved with d2 − 1 experimental configurations [26]. Indeed, with some effort N = we can see that for i, j ̸= 0 we can simplify Ri,j Tr{Pi N (|λj ⟩⟨λj |)} for a unital N , where |λj ⟩ is the eigenstate of Pj with eigenvalue +1. Thus, each nontrivial entry of PTM can be estimated with a single experimental configuration. It can be verified that for the case of Pauli channel, the PTM is diagonal with entries R0,0 = 1

(11)

R1,1 = pI + pX − pY − pZ

(12)

R3,3 = pI − pX − pY + pZ .

(14)

R2,2 = pI − pX + pY − pZ

(13)

We can observe that the last these entries are related to the QBERs when using the X, Y , and Z basis states for classical communication under Pauli channel [27]. Indeed, the error rate in the X basis 1 − R1,1 Qx = pY + pZ = , (15) 2 where we have used the fact that pI + pX + pY + pZ = 1. Similarly, we can write 1 − R2,2 (16) 2 1 − R3,3 Qz = pX + pY = . (17) 2 Finally, the PTM enables the direct mapping between the Pauli state-vectors of channel input and output. That is, the Pauli state-vector ⃗s of channel output is related to the Pauli state-vector ⃗r by the PTM R of the channel: ⃗s = R ⃗r [22, Supplementary Material]. Qy = pX + pZ =

C. System Model The system model, exemplified by a satellite link, is illustrated in Fig. 1. We consider a transmitter, denoted by Alice, and a receiver, denoted by Bob, who are spatially separated and aim to perform QKD. Due to practical limitations, such as relative motion, rotation, and imperfect polarization alignment, Alice and Bob do not share a common qubit reference frame. That is, the Pauli directions associated with their respective local systems do not coincide [12], [13]. The lack of a shared reference frame is a common practical challenge in polarization-encoded satellite quantum communication and path-encoded chip-to-chip quantum communication [14]. The communication link is assumed to be noisy and unknown. More specifically, over a given estimation and keygeneration block, it is modeled as an unknown, stationary, unital qubit channel N . The channel noise may possess a preferred basis that is not known to either party. For example, a Pauli-channel model typically specifies the error operators with respect to fixed Pauli axes, and therefore assumes that the Pauli error axes are known in the chosen reference frame [18]. In this work, this assumption is not made because Alice and

Fig. 1. The system model. The transmitter and receiver lack a shared reference frame, which is exemplified as a satellite-to-ground quantum communication link where the local frames of reference do not coincide with the global reference. Polarization encoding of photons in global reference frame does not translate to the same in either of the local references.

Bob do not share a common qubit reference frame. The only structural assumption imposed on the qubit noise is unitality. The unital qubit channel represents the polarization/noise transformation conditioned on a successful detection event. Propagation loss, background counts, detector dark counts, and detector-efficiency mismatch are not modeled explicitly in the present asymptotic qubit-channel analysis. Consequently, the secret key rates reported here are expressed per sifted detected signal. Although the physical channel N and the local-frame unitaries UA and UB are unknown individually, Alice and Bob can estimate the statistics of the effective Alice-to-Bob channel from their preparation and measurement data. The optimized bases are then selected using this effective channel, without requiring a separate reconstruction of the physical noise process or the individual frame rotations. III. O PTIMIZING THE QKD S IGNALING Mathematically, the lack of shared reference frame can be modeled by an unknown arbitrary but fixed rotation. More concretely, we assume that the global reference frame is fixed by the Pauli operators of (2) and the states shown at the bottom right in Fig.1. We model the Alice’s and Bob’s rotated local reference frames by the unitaries UA and UB , respectively. That is, when Alice prepares a state |ψ⟩A locally, this state in the global reference is UA |ψ⟩A . Similarly, when Bob locally measures a received state by the projector system  B ΠB 0 ,nΠ1 , the measurement o in the global reference is in

† B † fact UB ΠB 0 UB , UB Π1 UB . After the noisy transmission through N , the probability of obtaining measurement outcome ‘0’ is: n  o † † p0 = Tr UB ΠB U N U |ψ⟩⟨ψ| U . (18) A 0 B A A

In the case of UA and UB being known, Alice and Bob can compensate for the misalignment by applying UA† and UB† after local preparation and before locally measuring, respectively. In the case of UA = UB = U , but U being unknown, they cannot recover the statistics of ideal system, i.e., all reference frames coincide with the global reference. Indeed, generally   Tr U Π0 U † N U |ψ⟩⟨ψ| U † ̸= Tr{Π0 N (|ψ⟩⟨ψ|)} unless N (·) is covariant with respect to U [28]. In this work, UA ̸= UB and both being unknown is what we consider. In the following, we offer two approaches to perform QKD under this setting.

UR REHMAN: QUANTUM KEY DISTRIBUTION WITHOUT SHARED REFERENCE FRAME UNDER UNITAL NOISE

A. Approach 1: Direct Construction of PTM The first approach amounts to first performing a direct construction of PTM, followed by identifying an optimal set of mutually unbiased bases for QKD that maximizes the sifted key rate. Since the Alice’s and Bob’s local reference frames do not match, it seems challenging to estimate the PTM. We overcome this challenge by absorbing the unitaries UA and UB to † extend the definition of channel from N (·) to UB ◦N ◦UA (·). Essentially, we completely ignore the mismatched local reference frames and execute the PTM construction protocol [26]. In order to estimate the nontrivial (i, j ̸= 0) entries of the total map between Alice and Bob, Alice prepares the eigenstate corresponding to the positive eigenvalue of her local PjA and sends it thought he channel. Due to the reference mismatch with the  global reference the channel output is  N UA |λj ⟩⟨λj |A UA† . Upon reception, Bob measures the B Pauli operator PiB = ΠB 0,i − Π1,i in his local frame. Due to global mismatch, the measurement in global reference is † † B UB PiB UB† = UB ΠB 0,i UB − UB Π1,i UB . Thus, the entry Ri,j that they measure is n  o A→B Ri,j = Tr UB PiB UB† N UA |λj ⟩⟨λj |A UA† (19) n   o = Tr PiB UB† N UA |λj ⟩⟨λj |B UA† UB (20) n o  † ◦ N ◦ UA |λj ⟩⟨λj |A = Tr PiB UB (21) U † ◦N ◦UA

= Ri,jB

.

(22)

The first equality is from Born’s rule. The second equality is due to the cyclic property of trace. The third equality is defining the composition of UA , N , and UB† as a composite channel. At the end of PTM estimation procedure, the com† municating parties obtain the estimated PTM RUB ◦N ◦UA . † The matrix RA→B = RUB ◦N ◦UA defines the PTM mapping from Alice’s local reference frame followed by noise to the Bob’s local reference frame. This matrix can be decomposed via the SVD to obtain RA→B = OB ΣOA , where OB , OA are the orthogonal matrices containing left and right singular vectors as their columns, and Σ is the diagonal matrix containing † the singular values of RUB ◦N ◦UA . A→B The SVD of R simultaneously solves the challenge of absence of reference frame as well as that of the unknown preferred basis of the channel. This is a consequence of absorbing the lack of reference frame, cahracterized by UA and UB in the channel definition. Now, if Alice wants to transmit a state corresponding to the Bloch vector ⃗r, she instead ⊤ prepares the state corresponding to the Bloch vector OA ⃗r. Similarly Bob, after receiving the channel output, transforms ⊤ it by multiplying its Bloch vector with OB . Thus, the output ⊤ ⊤ ⃗r = Σ⃗r. Bloch vector of the channel is ⃗s = OB OB ΣOA OA Thus, by employing the OA and OB at the transmitter and receiver, respectively, the effective channel noise and the lack of reference frame is reduced to the noise characterized by a diagonal PTM Σ, i.e., a Pauli channel. Due to the unitality of noise and the corresponding structure of RA→B , the first right and left singular vectors, corresponding to the singular value σ0 = 1, are trivial and correspond to

5

the Bloch vector of maximally mixed state. Furthermore, since the columns of orthogonal matrices are orthogonal (Bloch) vectors, they correspond to the elements of mutually unbiased basis of the two-dimensional Hilbert space. This observation gives us the following recipe of QKD in the considered scenario of absence of shared reference frames and unital noise. Z basis communication is defined by Alice preparing the second right singular vector in her local reference and send it to Bob through the channel. Upon receiving, Bob measures the second left singular vector in his local reference. This will 1 result in error rate Qz = 1−σ 2 . The same procedure with the third and fourth singular vectors define communication in X 2 and Y bases with corresponding error rates Qx = 1−σ and 2 3 1 Qy = 1−σ . 2 We follow the notation that σ1 ≥ σ2 ≥ σ3 . For the BB84 protocol, Alice and Bob utilize X and Z basis, which allows them the asymptotic key rate of [21], [29], [30] RBB84 = 1 − h (Qz ) − h (Qx ) ,

(23)

bits per sifted detected signal, where we have defined the binary Shannon entropy h (x) = −x log2 x − (1 − x) log2 (1 − x). Similarly, for the six-state protocol where all three mutually unbiased bases are used, Alice and Bob may obtain the asymptotic key rate of [21] Rsix-state = 1 − H ({λi , j}) , (24) P where H ({pi }) = − i pi log2 pi is the Shannon entropy and

Qx + Qy + Qz (25) 2 Qx + Qy − Qz λ0,1 = (26) 2 −Qx + Qy + Qz (27) λ1,0 = 2 Qx − Qy + Qz λ1,1 = . (28) 2 The optimality follows from the fact that (i) every unital channel is unitarily equivalent to a Pauli channel [31], (ii) the chosen bases choice has transformed the overall noise into the effective Pauli noise and (iii) the Pauli bases (where the PTM is diagonal) are optimal for QKD under Pauli noise [32]. λ0,0 = 1 −

B. Approach 2: Sequential Basis Matching The second approach that we propose here involves variational modeling of Alice’s preparation and Bob’s measurement directions and sequentially identifying the appropriate Z, X, and Y directions for the QKD. More concretely, an arbitrary pure qubit state can be parameterized by two angles θ ∈ [0, π] and ϕ ∈ [0, 2π] as θ θ |0⟩ + eiϕ sin |1⟩ . (29) 2 2 Alice and Bob utilize this parameterization and perturb these parameters variationally to identify the appropriate local directions that they locally define as Z. The proposed SBM protocol operates as follows: |ψ⟩ = cos

1 The labeling of X, Y , and Z direction can be arbitrary. We choose Z, X, and Y in the increasing order of QBER.

6

SUBMITTED TO ARXIV ON JUNE 23, 2026.

0.6

0.4

0.2

0.0 0.25

0.50 0.75 Channel Parameter ϵ

1.00

0.8

1.0 SS-QKD (opt) SS-QKD (std)

Secret Key Rate (bit/sifted bit)

0.8

1.0 BB84 (opt) BB84 (std)

Secret Key Rate (bit/sifted bit)

Secret Key Rate (bit/sifted bit)

1.0

0.6

0.4

0.2

0.0 0.25

(a)

0.50 0.75 Channel Parameter ϵ

1.00

BB84 (opt) SS-QKD (opt)

0.8

0.6

0.4

0.2

0.0 0.25

(b)

0.50 0.75 Channel Parameter ϵ

1.00

(c)

Fig. 2. Secret key rate (bits per sifted detected signal) as a function of channel parameter ϵ. The optimized signaling, as proposed in the main text, compensates well for the absence of shared reference frame, as evidenced by the ideal secret key rate for the unitary/noiseless channel up to an unknown rotation, i.e., ϵ = 1.

1) Z Basis Search: a) Alice generates a parameter vector θ⃗Z = [θA , ϕA , θB , ϕB ], prepares several copies of the state |ψ⟩A = cos

θA θA |0⟩A + eiϕA sin |1⟩A , 2 2

(30)

and sends them to Bob through the quantum channel. On the classical channel, she sends to Bob the parameter values θB and ϕB . b)  Bob measures the received states with projectors B B ΠB 0 , I − Π0 , where Π0 = |ψ⟩⟨ψ|B with |ψ⟩B = cos

θB θB |0⟩B + eiϕB sin |1⟩B . 2 2

(31)

B He obtains the outcome  B corresponding to Π0 with probability p0 = Tr Π0 N (|ψ⟩⟨ψ|A ) , which he can empirically estimate from the measurement outcomes. c) Bob transmits the estimated p0 to Alice, who employs an optimizer to maximize this values by varying the parameter vector appropriately. d) Alice and Bob repeat above three steps until they reach the maximum value of the estimated p0 . The identified directions in terms of their parameterized states define the Z basis with the QBER: Qz = 1 − p0 . e) They locally redefine |0⟩A = |ψ ∗ ⟩A and |0⟩B = |ψ ∗ ⟩B , where |ψ ∗ ⟩A and |ψ ∗ ⟩B are the states (30) and (31), respectively, with the optimal parameters. 2) X Basis Search: a) Alice generates another parameter vector θ⃗X = [ϕA , ϕB ], prepares several copies of the state

|+⟩A =

|0⟩A + eiϕA |1⟩A √ , 2

(32)

and sends them to Bob through the quantum channel. On the classical channel, she sends to Bob the parameter value ϕB .

b) Bob the received states with projectors  B measures B Π+ , I − ΠB + , where Π+ = |+⟩⟨+|B with |+⟩B =

|0⟩B + eiϕB |1⟩B √ . 2

(33)

B He obtains the outcome  B corresponding to Π+ with probability p+ = Tr Π+ N (|+⟩⟨+|A ) , which he can empirically estimate from the measurement outcomes. c) Bob transmits the estimated p+ to Alice, who employs an optimizer to maximize this values by varying the parameter vector appropriately. d) Alice and Bob repeat above three steps until they reach the maximum value of the estimated p+ . The identified directions in terms of their parameterized states define the X basis with the QBER: Qx = 1 − p+ . e) They locally redefine |+⟩A = |+∗ ⟩A and |+⟩B = |+∗ ⟩B , where |+∗ ⟩A and |+∗ ⟩B are the states (32) and (33), respectively, with the optimal parameters. 3) Y Basis Definition: a) Alice and Bob locally define ∗

|i+⟩A =

|0⟩A + ei(ϕA +π/2) |1⟩A √ 2

(34)

and ∗

|0⟩B + ei(ϕB +π/2) |1⟩B √ |i+⟩B = , 2

(35)

where ϕ∗A and ϕ∗B are the optimal parameters found in the X basis search for defining the X direction. b) Alice and Bob estimate the Y basis QBER Qy by Alice sending several copies of |i+⟩A and Bob measuring them with the projectors defined by the direction |i+⟩B . At the end of SBM, Alice and Bob have local sets of mutually unbiased basis that they can use for BB84 or sixstate QKD. In particular, the achieved QBER and the secret key rate by employing the SBM is the same as the one obtained by the direct construction of the PTM. This can be seen by recalling that it is not possible to obtain a lower

0.6 0.5

0.4

0.8

0.3

0.6

0.2

0.4

0.1

0.2

1.0 0.9 0.8 0.7 0.6 0.5

Qx (BB84 opt)

0.7

1.0

Channel Parameter 

0.8

Qx (BB84 std)

Channel Parameter 

0.9

0.5

Secret Key Rate (bit/sifted bit)

1.0

7

0.5

1.0

0.4

0.8

0.3

0.6

0.2

0.4

0.1

0.2

RBB84 = 0

0.4

0.0 0.0

0.1

0.2 0.3 Qz (BB84 std)

0.4

Secret Key Rate (bit/sifted bit)

UR REHMAN: QUANTUM KEY DISTRIBUTION WITHOUT SHARED REFERENCE FRAME UNDER UNITAL NOISE

RBB84 = 0

0.5

0.0

(a)

0.4

0.0 0.0

0.1

0.2 0.3 Qz (BB84 opt)

0.4

0.5

0.0

(b)

Fig. 3. Secret key rate (bits per sifted detected signal) as a function of QBERs in Z and X basis. The scatter points show the QBERs of numerical simulations with (a) standard, i.e., without basis optimization, and (b) optimized basis BB84 in random unitary channels.

QBER than Qz = pX + pY in a Pauli channel, thus the Z basis search in SBM by minimizing the QBER results in the same Qz as the one obtained via the direct construction of the PTM. The X basis search is in the plane that is mutually unbiased to the identified Z basis. This is equivalent to searching the orthogonal plane in the Bloch sphere. From Approach 1, we know that the lowest achievable QBER in this plane is Qx of Approach 1. Thus, the optimization in SBM should converge to the same value. Finally, fixing any two mutually unbiased bases in the two-dimensional Hilbert space automatically identifies the third basis. Thus, the achieved QBER and the secret key rate by employing the SBM is the same as the one obtained by the direct construction of the PTM. IV. N UMERICAL E XAMPLES In this section, we provide numerical examples of our work by simulating the system model and proposed approaches.2 We simulate the lack of shared reference frame by generating two Haar random unitaries UA and UB and rotate the Alice’s and Bob’s states/measurement with these, respectively. In order to simulate a unital channel, we simulate a random unitary channel N (ρ) =

4 X

pi Ui ρUi† ,

(36)

i=1

where Ui are Haar random unitaries and p1 = ϵ and p2 = p3 = p4 = 1−ϵ 3 . In Fig. 2, we plot the secret key rate (bits per sifted detected signal) for BB84 and six-state QKD as a function of channel parameter ϵ. In Fig. 2(a), we plot the secret key rate for BB84 with and without optimization. The solid red line shows the average secret key rate of 103 runs for each ϵ value, and the red shaded region denotes one standard deviation of the data. The dashed black line shows the corresponding average 2 The simulation code is available under MIT License at the Github respository: https://github.com/junaid572/QKD No Reference Unital Noise.

for standard BB84, i.e., without finding the optimal bases. We can see that the optimized signaling clearly outperforms the standard BB84 signaling, even for the unitary/noiseless channel up to an unknown rotation, i.e., ϵ = 1. In Fig. 2(b), we plot the secret key rate for six-state QKD on the same set of channels, where the solid blue line and blue shaded region denote the optimized average and its standard deviation, and the dashed black line denotes the standard six-state signaling. Fig. 2(c) compares the optimized secret key rates of the two protocols, with the solid red line for BB84 and the dashed blue line for six-state QKD. We observe that the two QKD protocols result in a very similar secret key rate. This is not the typical behavior in the symmetric QBER case, where sixstate QKD always outperforms BB84. This is a consequence of our modeling where we have assigned the Y basis to be the most noisy. Thus, including the third basis in QKD does not provide a significant added advantage. In the background (gray scale) of Fig. 3, we plot the asymptotic key exchange rate as a function of Qz and Qx for BB84 QKD. The green solid line shows the boundary outside of which (towards right) the secret key rate is zero. In the foreground of Fig. 3(a) and Fig. 3(b), we plot the achieved QBER set (Qz , Qx ) for standard and optimized signaling QKD with the same set of random unitary channels, respectively. For the standard BB84 in this setting, we observe that a majority of achieved QBER lie outside the boundary of positive secret key rate. In other words, the majority of system realizations fail to achieve any QKD. The proposed optimized signaling, however, manages to achieve a positive secret key rate for the same set of random unitary channels. These numerical examples demonstrate the effectiveness of the proposed approach for QKD without shared reference frame and in the presence of unital noise. The robustness of the optimized signaling is further characterized in Fig. 4. Fig. 4(a) shows the positive-key probability, Pr{R > 0}, estimated over the random unitary channel ensemble as a function of the channel parameter ϵ. This quantity measures the fraction of random channel realizations

8

SUBMITTED TO ARXIV ON JUNE 23, 2026.

1

0.6

0.4

0.2

0.6 0.4 0.2 0

0.50 0.75 Channel Parameter ϵ

(a)

1.00

10

1

10

2

3

10

10

0.4 0.3 0.2 0.1 0

SS-QKD

−0.1

BB84

0.0 0.25

Asymptotic = 0.2565 Finite sample (RMSE) Achieved (RMSE)

0.5

Asymptotic = 0.2516 Finite sample (RMSE) Achieved (RMSE)

0.8

Secret key rate (bit/sifted bit)

0.8

BB84 (opt) BB84 (std) SS-QKD (opt) SS-QKD (std)

Secret key rate (bit/sifted bit)

Positive Key Probability

1.0

4

10

1

2

10

10

3

104

Shots Ns

Shots Ns

(b)

(c)

Fig. 4. Robustness checks for the optimized signaling. (a) Positive-key probability, Pr{R > 0}, over the random unitary channel ensemble as a function of the channel parameter ϵ. (b) Finite-sample PTM-based basis estimation for BB84 at ϵ = 0.8, shown as a function of the number of shots per PTM entry, Ns . (c) Corresponding finite-sample PTM-based basis estimation for six-state QKD at ϵ = 0.8. In (b) and (c), the dashed line denotes the exact-PTM asymptotic rate, the finite-sample curve denotes the rate computed from the noisy estimated PTM, and the achieved-rate curve denotes the rate obtained when the finite-sample optimized bases are applied to the underlying simulated channel. Shaded bands denote the root-mean-square error (RMSE).

that support a strictly positive asymptotic secret key rate. For optimized signaling, the positive-key probability approaches unity as ϵ increases, whereas it remains low for standard local-basis signaling because the standard bases do not adapt to the effective reference-frame rotation or to the channel’s preferred noise directions. Fig. 4(b) and Fig. 4(c) illustrate the effect of finite-sample PTM estimation at ϵ = 0.8 for BB84 and six-state QKD, respectively. Here, Ns denotes the number of measurement shots used to estimate each nontrivial PTM entry. For each value of Ns , the optimized bases are selected from the finite-sample estimate of the effective PTM. The finite-sample key-rate estimate is computed from the QBERs inferred from this estimated PTM, while the achieved rate is computed by applying the same finite-sample optimized bases to the underlying simulated channel. For BB84, the finite-sample key-rate estimate can be biased upward at small Ns . This occurs because BB84 uses only two of the three optimized directions, so selecting the two most favorable estimated bases can make statistical fluctuations appear beneficial. This is a finite-sample selection effect, not an actual improvement of the underlying channel. The achieved-rate curve removes this optimistic estimation effect by evaluating the selected bases on the true simulated channel, and it converges to the exact-PTM asymptotic rate as Ns increases. For six-state QKD, all three optimized bases enter the keyrate expression. Therefore, there is no analogous best-twobasis selection step, and finite-sample fluctuations affect all three basis-dependent QBERs jointly. In the simulated regime, the finite-sample key-rate estimate is therefore less biased upward and initially lies below the exact-PTM asymptotic value. As Ns increases, both the finite-sample estimate and the achieved rate converge to the exact-PTM optimized rate. These results demonstrate the statistical robustness of the proposed basis-estimation method, but they should not be interpreted as a finite-key security analysis.

V. C ONCLUSION In this work, we investigated QKD in the absence of a shared qubit reference frame, a condition that naturally arises in satellite and moving-platform quantum communication links. Rather than treating reference-frame alignment and channel-noise characterization as separate tasks, we formulated the problem through an effective Alice-to-Bob channel that jointly captures both effects. This perspective allows Alice and Bob to adapt their local signaling bases using only operationally accessible preparation and measurement statistics. We proposed two approaches for this basis adaptation: a PTM/SVD-based method and an operational SBM method. Both methods identify local mutually unbiased bases that align the observed correlations with the principal directions of the effective unital channel. In these optimized bases, the resulting asymmetric QBERs can be used directly in the asymptotic keyrate analysis of BB84 and six-state QKD. Numerical results for random unitary channels show that such optimized signaling can substantially improve key-generation performance and can recover positive key rates in cases where standard local-basis signaling fails. The results highlight the importance of treating basis choice as part of the QKD design problem when a shared reference frame is unavailable. The proposed framework provides a step toward more adaptive QKD implementations for dynamic quantum links, where both alignment and noise conditions may be difficult to characterize in advance. Future work may extend the approach beyond unital qubit channels and develop a finitekey security analysis that accounts for statistical uncertainty in the estimated channel parameters, optimized bases, and QBERs. R EFERENCES [1] V. Scarani, H. Bechmann-Pasquinucci, N. J. Cerf, M. Dušek, N. Lütkenhaus, and M. Peev, “The security of practical quantum key distribution,” Rev. Mod. Phys., vol. 81, no. 3, pp. 1301–1350, Sep. 2009. doi: 10.1103/RevModPhys.81.1301 .

UR REHMAN: QUANTUM KEY DISTRIBUTION WITHOUT SHARED REFERENCE FRAME UNDER UNITAL NOISE

[2] N. Gisin, G. Ribordy, W. Tittel, and H. Zbinden, “Quantum cryptography,” Rev. Mod. Phys., vol. 74, no. 1, pp. 145–195, Mar. 2002. doi: 10.1103/RevModPhys.74.145 . [3] S. Pirandola, U. L. Andersen, L. Banchi, M. Berta, D. Bunandar, R. Colbeck, D. Englund, T. Gehring, C. Lupo, C. Ottaviani, J. L. Pereira, M. Razavi, J. S. Shaari, M. Tomamichel, V. C. Usenko, G. Vallone, P. Villoresi, and P. Wallden, “Advances in quantum cryptography,” Adv. Opt. Photon., AOP, vol. 12, no. 4, pp. 1012–1236, Dec. 2020. doi: 10.1364/AOP.361502 . [4] C. Portmann and R. Renner, “Security in quantum cryptography,” Rev. Mod. Phys., vol. 94, no. 2, p. 025008, Jun. 2022. doi: 10.1103/RevModPhys.94.025008 . [5] C. H. Bennett and G. Brassard, “Quantum cryptography: Public key distribution and coin tossing,” Theoretical Computer Science, vol. 560, pp. 7–11, Dec. 2014. doi: 10.1016/j.tcs.2014.05.025 . [6] ——, “Quantum cryptography: Public-key distribution and coin tossing,” in Proc IEEE Int Conf Comput. Syst. Signal Process. Bangalore, India: IEEE, 1984, pp. 175–179. [7] D. Bruß, “Optimal eavesdropping in quantum cryptography with six states,” Phys. Rev. Lett., vol. 81, no. 14, pp. 3018–3021, Oct. 1998. doi: 10.1103/PhysRevLett.81.3018 . [8] C.-Y. Lu, Y. Cao, C.-Z. Peng, and J.-W. Pan, “Micius quantum experiments in space,” Rev. Mod. Phys., vol. 94, no. 3, p. 035001, Jul. 2022. doi: 10.1103/RevModPhys.94.035001 . [9] J. Yin, Y. Cao, S.-B. Liu, G.-S. Pan, J.-H. Wang, T. Yang, Z.-P. Zhang, F.-M. Yang, Y.-A. Chen, C.-Z. Peng, and J.-W. Pan, “Experimental quasi-single-photon transmission from satellite to Earth,” Opt. Express, OE, vol. 21, no. 17, pp. 20 032–20 040, Aug. 2013. doi: 10.1364/OE.21.020032 . [10] E. Diamanti, H.-K. Lo, B. Qi, and Z. Yuan, “Practical challenges in quantum key distribution,” npj Quantum Inf, vol. 2, no. 1, p. 16025, Nov. 2016. doi: 10.1038/npjqi.2016.25 . [11] O. Klicnik, A. Zannotti, Y. Folwill, O. de Vries, P. Munster, and T. Horvath, “Real-time polarization control for satellite QKD with liquid-crystal beacon stabilization,” Sci. Rep., Jun. 2026. doi: 10.1038/s41598-026-55812-2 . [Online]. Available: https://www.nature. com/articles/s41598-026-55812-2 [12] S. D. Bartlett, T. Rudolph, and R. W. Spekkens, “Classical and quantum communication without a shared reference frame,” Phys. Rev. Lett., vol. 91, no. 2, p. 027901, Jul. 2003. doi: 10.1103/PhysRevLett.91.027901 . [13] S. J. van Enk, “Quantum communication, reference frames, and gauge theory,” Phys. Rev. A, vol. 73, no. 4, p. 042306, Apr. 2006. doi: 10.1103/PhysRevA.73.042306 . [14] A. Laing, V. Scarani, J. G. Rarity, and J. L. O’Brien, “Reference-frameindependent quantum key distribution,” Phys. Rev. A, vol. 82, no. 1, p. 012304, Jul. 2010. doi: 10.1103/PhysRevA.82.012304 . [15] K. Kraus, A. Böhm, J. D. Dollard, and W. H. Wootters, Eds., States, Effects, and Operations Fundamental Notions of Quantum Theory, ser. Lecture Notes in Physics. Berlin, Heidelberg: Springer Berlin Heidelberg, 1983, vol. 190. doi: 10.1007/3-540-12732-1 . [16] M. A. Nielsen and I. L. Chuang, Quantum Computation and Quantum Information, 10th ed. Cambridge: Cambridge university press, 2010. doi: 10.1017/CBO9780511976667 .

9

[17] M. M. Wilde, Quantum Information Theory, 2nd ed. Cambridge: Cambridge University Press, 2017. doi: 10.1017/9781316809976 . [18] J. ur Rehman and H. Shin, “Entanglement-free parameter estimation of generalized Pauli channels,” Quantum, vol. 5, p. 490, Jul. 2021. doi: 10.22331/q-2021-07-01-490 . [19] Z.-Q. Yin, C.-H. F. Fung, X. Ma, C.-M. Zhang, H.-W. Li, W. Chen, S. Wang, G.-C. Guo, and Z.-F. Han, “Mismatched-basis statistics enable quantum key distribution with uncharacterized qubit sources,” Phys. Rev. A, vol. 90, no. 5, p. 052319, Nov. 2014. doi: 10.1103/PhysRevA.90.052319 . [20] S. Watanabe, R. Matsumoto, and T. Uyematsu, “Tomography increases key rates of quantum-key-distribution protocols,” Phys. Rev. A, vol. 78, no. 4, p. 042316, Oct. 2008. doi: 10.1103/PhysRevA.78.042316 . [21] G. Murta, F. Rozpedek, J. Ribeiro, D. Elkouss, and S. Wehner, “Key rates for quantum key distribution protocols with asymmetric noise,” Phys. Rev. A, vol. 101, no. 6, p. 062321, Jun. 2020. doi: 10.1103/PhysRevA.101.062321 . [22] J. M. Chow, J. M. Gambetta, A. D. Córcoles, S. T. Merkel, J. A. Smolin, C. Rigetti, S. Poletto, G. A. Keefe, M. B. Rothwell, J. R. Rozen, M. B. Ketchen, and M. Steffen, “Universal quantum gate set approaching fault-tolerant thresholds with superconducting qubits,” Phys. Rev. Lett., vol. 109, no. 6, p. 060501, Aug. 2012. doi: 10.1103/PhysRevLett.109.060501 . [23] E. Nielsen, J. K. Gamble, K. Rudinger, T. Scholten, K. Young, and R. Blume-Kohout, “Gate set tomography,” Quantum, vol. 5, p. 557, Oct. 2021. doi: 10.22331/q-2021-10-05-557 . [24] S. T. Merkel, J. M. Gambetta, J. A. Smolin, S. Poletto, A. D. Córcoles, B. R. Johnson, C. A. Ryan, and M. Steffen, “Self-consistent quantum process tomography,” Phys. Rev. A, vol. 87, no. 6, p. 062119, Jun. 2013. doi: 10.1103/PhysRevA.87.062119 . [25] D. Greenbaum, “Introduction to quantum gate set tomography,” Sep. 2015. doi: 10.48550/arXiv.1509.02921 . [26] S. Roncallo, L. Maccone, and C. Macchiavello, “Pauli transfer matrix direct reconstruction: Channel characterization without full process tomography,” Quantum Sci. Technol., vol. 9, no. 1, p. 015010, Jan. 2024. doi: 10.1088/2058-9565/ad04e7 . [27] J. ur Rehman, Y. Jeong, J. S. Kim, and H. Shin, “Holevo capacity of discrete weyl channels,” Sci Rep, vol. 8, no. 1, p. 17457, Nov. 2018. doi: 10.1038/s41598-018-35777-7 . [28] K. Siudzińska and D. Chruściński, “Quantum channels irreducibly covariant with respect to the finite group generated by the Weyl operators,” J. Math. Phys., vol. 59, no. 3, p. 033508, Mar. 2018. doi: 10.1063/1.5013604 . [29] P. W. Shor and J. Preskill, “Simple proof of security of the bb84 quantum key distribution protocol,” Phys. Rev. Lett., vol. 85, no. 2, pp. 441–444, Jul. 2000. doi: 10.1103/PhysRevLett.85.441 . [30] R. Renner, “Security of quantum key distribution,” Int. J. Quantum Inform., vol. 06, no. 01, pp. 1–127, Feb. 2008. doi: 10.1142/S0219749908003256 . [31] Z. Puchała, Ł. Rudnicki, and K. Życzkowski, “Pauli semigroups and unistochastic quantum channels,” Physics Letters A, vol. 383, no. 20, pp. 2376–2381, Jul. 2019. doi: 10.1016/j.physleta.2019.04.057 . [32] J. Bae and A. Acı́n, “Key distillation from quantum channels using twoway communication protocols,” Phys. Rev. A, vol. 75, no. 1, p. 012334, Jan. 2007. doi: 10.1103/PhysRevA.75.012334 .

Record · ID 299816 · SHA-256 2abb6314d961ab63
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.