Time-Bin BB84 QKD System Using Indium Phosphide
and Silicon Nitride Photonic Integrated Circuits

Denis Fatkhiev, Alexander Grebenchukov, João dos Reis Frazão,
Gleb Nazarikov, Chigo Okonkwo, and Idelfonso Tafur Monroy


Electro-Optical Communication Group, Eindhoven University of Technology, The Netherlands

We demonstrate a dual-chip InP-SiN photonic QKD system with on-chip pulse generation and reconfigurable decoding, implementing time-bin BB84 with finite-key security against coherent attacks. The system sustains a QBER below 4 % and delivers secret keys at kbps rates over 150–250 km of fiber. ©  2026 The Authors

1 Introduction↩︎

Figure 1: (a) System-level schematic showing experimental setup. (b) Microscope image of the InP PIC (Alice). (c) Microscope image of the SiN PIC (Bob).

Unlike public-key cryptography, whose security is based on computational hardness assumptions increasingly challenged by quantum computing [1][4], derives its security from the fundamental laws of physics. The uncertainty principle and the no-cloning theorem guarantee that any eavesdropping on the key exchange produces detectable errors, thereby providing information-theoretic security against both present and future adversaries.

The practical deployment of requires scalable and cost-effective hardware, making a compelling foundation [5]. -based has been demonstrated in silicon [6],  [7],  [8], and lithium niobate [9], yet no single platform delivers active sources, high-speed modulation, and low-loss passive circuitry, motivating hybrid approaches that combine complementary strengths [10].

In this work, we present an InP-SiN dual-chip system that implements the three-state time-bin BB84 protocol with one decoy state. Pairing active on-chip state generation in with reconfigurable low-loss decoding in leverages the complementary strengths of both platforms, eliminates the long transmitter delay line required by interferometric time-bin schemes, and exposes a tunable basis-selection ratio for protocol optimization. The key rates are evaluated under a finite-key security analysis against coherent attacks [11], demonstrating secure operation across metropolitan- and intercity-scale fiber distances.

2 Experimental Setup↩︎

The experimental setup is illustrated in 1 (a), with Alice and Bob shown in 1 (b) and 1 (c), respectively, along with supporting electronics and detection equipment. Alice prepares weak coherent pulses on the and transmits to Bob over a spooled single-mode fiber link, where they are decoded by the reconfigurable receiver and registered by .

The transmitter comprises a directly modulated laser, a , and a . Optical pulses are generated at a repetition rate of 1.065 GHz at 1550 nm, driven by an operating at 20 GS/s with 14-bit resolution. The is gain-switched to produce phase-randomized pulses, the provides coarse on-chip attenuation, and the carves the time bins encoding the protocol states while setting the relative signal and decoy intensities, bringing the output down to the single-photon level. The transmitter is biased with a multichannel .

Figure 2: Time-bin histograms of the states recorded at the receiver: (a) Z_0 and (b) Z_1 on the Z path, (c) X_0 on the Z path, and (d) X_0 on the X path, showing destructive interference in the central slot. The green shaded region indicates the active detection time-slot. Z-basis states on the X path are omitted as the single-pulse inputs do not produce interference.

A polarization controller at the receiver input aligns the incoming polarization to the waveguide axis. The receiver  [12] incorporates two -based tunable couplers and an with a delay line matching the 940 ps time-bin separation. Each tunable coupler is implemented as a symmetric with a in one arm, enabling precise control over the coupling ratio through thermo-optic phase tuning. The first tunable coupler sets the splitting ratio between the \(Z\) and \(X\) basis paths, while the second compensates for the loss imbalance introduced by the delay line, maximizing its extinction ratio. An additional in the short arm of the enables fine-tuning of the relative phase for \(X\) basis demodulation. All phase shifters are independently actuated by a second .

Photons are detected by two channels of a Single Quantum Eos 800 CS system, serving the \(Z\) and \(X\) basis outputs. The system offers 80 % system detection efficiency and 21 ps timing jitter at 1550 nm, with dark count rates below 10 cps per channel. Detection events are timestamped by a Time Tagger, synchronized to the via a shared reference clock; in deployment, this synchronization would be carried by a classical service channel or recovered from the quantum signal.

To enable phase-error estimation, the phase is tuned via its to produce destructive interference in the central slot of the \(X\) channel for the \(X_0\) state. In a three-state protocol, Alice never sends \(X_1\), so any counts in that slot directly reflect phase errors, providing the most sensitive estimate of the phase error rate. The prepared quantum states are verified by recording time-bin histograms on the Time Tagger, as shown in 2.

3 Protocol Details↩︎

We implement the three-state time-bin BB84 protocol with one decoy state [13]. Alice randomly encodes one of two \(Z\)-basis states, \(Z_0\) or \(Z_1\), as a pulse in the early or late time bin, or the \(X\)-basis state \(X_0\), an equal superposition of both time bins with zero relative phase. Each pulse is additionally assigned a random signal or decoy intensity [14]. Bob passively selects the measurement basis via the \(Z\)/\(X\) splitting ratio, which sets the basis-selection probabilities \(P_Z\) and \(P_X = 1 - P_Z\) and can be adapted to channel conditions and decoy settings [15], [16]. The photon arrival time in the \(Z\) path yields the raw key bit, while the central interference slot of the \(X\) path estimates the phase error rate bounding Eve’s information.

These protocol requirements shape the chip-level design in two places: the transmitter time-bin generation and the receiver \(X\)-basis projection. At the transmitter, the 940 ps time bins are generated electronically by the -driven rather than through interference, avoiding a delay line on that would be prohibitive in both loss and footprint. At the receiver, the delay line required for \(X\)-basis projection is well within reach on thanks to its low propagation loss, which also hosts the on-chip tunability discussed above and allows the protocol to be optimized across different operating regimes.

We estimate the extractable secret key length \(L\) following the finite-key security analysis of [11]. The key is distilled from the sifted \(Z\)-basis detections, with its secure length determined by the vacuum and single-photon yields, the phase error rate estimated in the \(X\) basis, and the information leaked during classical post-processing, giving \[\begin{align} L \;=\;\, &s^{L}_{Z_{0}} + s^{L}_{Z_{1}}\bigl(1 - h(\Lambda^{u}_{X}+\gamma)\bigr) - \mathrm{leak}_{\mathrm{EC}} \\ &- \log_2\!\tfrac{2}{\epsilon_{\mathrm{cor}}} - 4\log_2\!\tfrac{15}{\epsilon^{\prime}_{\mathrm{sec}} \sqrt[4]{2}}. \end{align} \label{eq:skl}\tag{1}\] Here, \(s^{L}_{Z_{0}}\) and \(s^{L}_{Z_{1}}\) are lower bounds on the vacuum and single-photon contributions to the sifted key, obtained via the decoy-state method. The term \(\Lambda^{u}_{X}\) places an upper-bound on the single-photon in the \(X\) basis, and \(\gamma\) is the Serfling correction [17] accounting for finite-sample estimation of the phase error rate. The error-correction leakage is \(\mathrm{leak}_{\mathrm{EC}} = f_{\mathrm{EC}}\,N_Z\,h(q_Z)\), with \(N_Z\) the number of sifted \(Z\)-basis detections, \(h(\cdot)\) the binary entropy, \(q_Z\) the \(Z\)-basis , and \(f_{\mathrm{EC}} = 1.16\) the reconciliation inefficiency. The secrecy and correctness parameters are \(\epsilon^{\prime}_{\mathrm{sec}} = \epsilon_{\mathrm{cor}} = 10^{-12}\).

4 Results↩︎

Figure 3: Optimization and performance of the QKD system versus channel loss. (a) Optimal selection probabilities for the Z basis and the signal state. (b) Optimal mean photon numbers of the signal and decoy states. (c) Secret key rate for three values of the sifted Z-basis block size N_Z. Panels (a) and (b) are shown for a fixed N_Z = 10^{8}.

We evaluate the system performance in two steps. First, the protocol parameters are jointly optimized against the finite-key bound as a function of channel loss. Second, the and extractable are estimated at loss values representative of metropolitan and long-haul deployment scenarios. Figures 3 (a) and 3 (b) show the loss-dependent values of the tunable parameters that maximize the . The strong bias toward the \(Z\) basis is characteristic of the efficient-BB84 regime [18], where the \(Z\) basis dominates key generation while the \(X\) basis is used sparingly for phase-error estimation. The optimal values also depend on the sifted block size \(N_Z\), since larger blocks tighten the statistical estimates and shift the optimal bias. 3 (c) accordingly shows the for three values of \(N_Z\), with the finite-size penalty shrinking and the secure distance extending as \(N_Z\) approaches the asymptotic regime.

We assessed the system at channel losses of 30 dB, 40 dB, and 50 dB, corresponding to 150 km, 200 km, and 250 km of standard single-mode fiber. The \(Z\)-basis remained near 3 % at the shorter distances and increased to just under 4 % at 250 km, consistent with the reduced signal-to-noise margin at higher channel loss. The residual floor at low loss is set by a combination of state-preparation imperfections, finite extinction, and detector timing jitter leaking into adjacent slots. The corresponding estimated , evaluated at a sifted block size of \(N_Z = 10^{7}\), are 16, 1.5, and 0.13 kbps, respectively.

5 Conclusions↩︎

We have reported a dual-chip –photonic integrated system implementing the three-state time-bin BB84 protocol with one decoy state, with its security assessed under a finite-key analysis against coherent attacks. The architecture exploits the strengths of the two platforms: pulse generation and time-bin carving in , and low-loss reconfigurable decoding with a tunable \(Z\)/\(X\) splitting ratio in . The system sustained values below 4 % and delivered estimated of 16, 1.5, and 0.13 kbps over 150, 200, and 250 km of standard single-mode fiber. However, several directions remain open: tighter hybrid integration of active, modulation, and passive functionalities – together with low-loss co-packaging into a transceiver module, higher clock rates to boost raw key generation, the incorporation of compact on-chip single-photon detectors [19] to eliminate the cryogenic footprint of the current stage, and active thermal and polarization stabilization for continuous unattended operation in the field. In parallel, quantifying source side-channels such as pattern-dependent leakage from the gain-switched and residual intensity correlations between adjacent pulses [20] is an essential next step for certifying integrated transmitters. Together, these steps would bring chip-scale closer to the compactness, cost, and scalability required for field deployment.

6 Acknowledgements↩︎

This work was supported by the Dutch Ministry of Economic Affairs and Climate Policy (EZK) through the PhotonDelta National Growth Fund Programme on Photonics and the Quantum Delta NL National Growth Fund Programme on Quantum Technology, by NWO Quantum Delta NL project AL1 (NGF.1623.23.007), and by the Horizon EU ALLEGRO project (GA 101092766).

References↩︎

[1]
P. W. Shor, “Algorithms for quantum computation: Discrete logarithms and factoring,” in Proceedings 35th annual symposium on foundations of computer science, 1994, pp. 124–134, doi: 10.1109/SFCS.1994.365700.
[2]
R. Acharya et al., “Quantum error correction below the surface code threshold,” Nature, vol. 638, no. 8052, pp. 920–926, 2025, doi: 10.1038/s41586-024-08449-y.
[3]
M. Cain et al., “Shor’s algorithm is possible with as few as 10,000 reconfigurable atomic qubits,” arXiv preprint arXiv:2603.28627, 2026, doi: 10.48550/arXiv.2603.28627.
[4]
R. Babbush et al., “Securing elliptic curve cryptocurrencies against quantum vulnerabilities: Resource estimates and mitigations,” arXiv preprint arXiv:2603.28846, 2026, doi: 10.48550/arXiv.2603.28846.
[5]
L. Labonté et al., “Integrated Photonics for Quantum Communications and Metrology,” PRX Quantum, vol. 5, no. 1, p. 010101, 2024, doi: 10.1103/PRXQuantum.5.010101.
[6]
W. Luo, L. Cao, H. Cai, M. F. Karim, L. C. Kwek, and A. Q. Liu, “A Silicon Photonic Chip-based System for 2.5-GHz Quantum Key Distribution (QKD),” in Optical Fiber Communication Conference (OFC), 2024, p. Th2A.9, doi: 10.1364/OFC.2024.Th2A.9.
[7]
P. Sibson et al., “Chip-based quantum key distribution,” Nat. Commun., vol. 8, no. 1, p. 13984, 2017, doi: 10.1038/ncomms13984.
[8]
T. K. Paraïso et al., “A photonic integrated quantum secure communication system,” Nat. Photonics, vol. 15, no. 11, pp. 850–856, 2021, doi: 10.1038/s41566-021-00873-0.
[9]
Z. Lin et al., “Integrated lithium niobate photonics for high-speed quantum key distribution,” Opt. Quantum, vol. 3, no. 2, pp. 195–200, 2025, doi: 10.1364/OPTICAQ.551726.
[10]
J. A. Dolphin, T. K. Paraïso, H. Du, R. I. Woodward, D. G. Marangon, and A. J. Shields, “A hybrid integrated quantum key distribution transceiver chip,” npj Quantum Inf., vol. 9, no. 1, pp. 1–8, 2023, doi: 10.1038/s41534-023-00751-3.
[11]
J. Wiesemann, J. Krause, D. Tupkary, N. Lütkenhaus, D. Rusca, and N. Walenta, “A consolidated and accessible security proof for finite-size decoy-state quantum key distribution,” Quantum, vol. 10, p. 2037, 2026, doi: 10.22331/q-2026-03-23-2037.
[12]
D. Fatkhiev et al., “A Reconfigurable Chip-Scale Quantum Key Distribution Receiver Based on Silicon Nitride,” in European Conference on Optical Communication (ECOC), 2024, p. Tu3A.4.
[13]
A. Boaron et al., “Simple 2.5 GHz time-bin quantum key distribution,” Appl. Phys. Lett., vol. 112, no. 17, p. 171108, 2018, doi: 10.1063/1.5027030.
[14]
M. A. Pereira et al., Quantum key distribution over a metropolitan network using an integrated photonics based prototype,” arXiv preprint arXiv:2602.17227, 2026, doi: 10.48550/arXiv.2602.17227.
[15]
D. Rusca, A. Boaron, F. Grünenfelder, A. Martin, and H. Zbinden, “Finite-key analysis for the 1-decoy state QKD protocol,” Appl. Phys. Lett., vol. 112, no. 17, p. 171104, 2018, doi: 10.1063/1.5023340.
[16]
H. Liu et al., “Experimental 4-intensity decoy-state quantum key distribution with asymmetric basis-detector efficiency,” Phys. Rev. A, vol. 100, no. 4, p. 042313, 2019, doi: 10.1103/PhysRevA.100.042313.
[17]
R. J. Serfling, “Probability inequalities for the sum in sampling without replacement,” Ann. Stat., pp. 39–48, 1974, doi: 10.1214/aos/1176342611.
[18]
H.-K. Lo, H. F. Chau, and M. Ardehali, “Efficient quantum key distribution scheme and a proof of its unconditional security,” J. Cryptol., vol. 18, no. 2, pp. 133–165, 2005, doi: 10.1007/s00145-004-0142-y.
[19]
F. Beutel, H. Gehring, M. A. Wolff, C. Schuck, and W. Pernice, “Detector-integrated on-chip QKD receiver for GHz clock rates,” npj Quantum Inf., vol. 7, no. 1, p. 40, 2021, doi: 10.1038/s41534-021-00373-7.
[20]
K. Yoshino et al., “Quantum key distribution with an efficient countermeasure against correlated intensity fluctuations in optical pulses,” npj Quantum Inf., vol. 4, no. 1, p. 8, 2018, doi: 10.1038/s41534-017-0057-8.