Ultra‑Low‑Rate Information Reconciliation:
Repetition Coding or Dedicated Codes?


Abstract

We compare repetition‑based ultra‑low‑rate information reconciliation with dedicated ultra‑low‑rate codes for CV‑QKD. Repetition coding offers a favorable performance–complexity trade‑off, incurring only a moderate error‑rate penalty while reducing decoding complexity by \(2\times\), making it attractive for implementation‑constrained systems.

1 Introduction↩︎

In continuous variable-quantum key distribution (CV-QKD), information reconciliation (IR) directly limits both secret-key rate and achievable distance [1]. At low signal-to-noise ratios (SNRs), secret-key extraction is only possible if the reconciliation efficiency remains very close to \(1\), consequently, high-performance ultra-low-rate error correction is required.

Two competing approaches exist for ultra-low-rate error correction. The first uses dedicated ultra-low-rate low-density parity check (LDPC) codes [2], [3], which can achieve a good frame error rate (FER) performance but typically require long block lengths and many decoding iterations; for some designs, decoding complexity increases further as the rate decreases [2]. The second uses repetition-based IR [4], which maps a higher-rate mother code to lower effective rates through repeated frames while naturally enabling rate adaptivity.

The practical question is not only which approach gives the best FER, but which approach gives the best FER-complexity operating point under implementation constraints (decoder throughput, latency and hardware cost).

In this paper, we explain the repetition coding within the multidimensional reconciliation (MDR) [1] framework and compare repetition-based and dedicated ultra-low-rate designs at the same target rate. Our results show that dedicated codes provide the best FER, while repetition-based schemes can substantially reduce decoding complexity with only a moderate FER penalty.

2 Rate Extension by Repetition Coding↩︎

Throughout this paper, underlined symbols represent column vectors, and \(\odot\) represents the Hadamard product.

2.1 Protocol↩︎

We assume reverse reconciliation with MDR [1]. For the first frame, Alice sends quantum states \(\underline{x}^{(1)}\), and Bob measures \(\underline{y}^{(1)}\). Bob draws a binary raw key \(\underline{u}^{(1)}\), computes the LDPC syndrome \(\underline{s}^{(1)}=\mathbf{H}\underline{u}^{(1)}\) using the parity-check matrix \(\mathbf{H}\) of an LDPC code with rate \(R_\mathrm{LDPC}\) and derives MDR rotations \(\underline{\phi}^{(1)}\) from \(\underline{y}^{(1)}\) and \(\underline{u}^{(1)}\). He then transmits \(\underline{s}^{(1)}\) and \(\underline{\phi}^{(1)}\) over the classical channel.

Each subsequent frame replicates the first through repetition coding. For the frame \(\ell\in\{2,\dots,N_{\mathrm{rep}}\}\), Bob draws an independent key \(\underline{u}^{(\ell)}\), binary summation of the keys \(\underline{s}^{(\ell)}=\underline{u}^{(\ell)} \oplus \underline{u}^{(1)}\) and transmits \(\underline{s}^{(\ell)}\) together with rotations \(\underline{\phi}^{(\ell)}\) computed from fresh measurements \(\underline{y}^{(\ell)}\) and \(\underline{u}^{(\ell)}\). This yields the repetition rate \(R_\mathrm{rep}=1/N_{\mathrm{rep}}\).

To decode, Alice firstly computes the log-likelihood ratio of the symbols in the \(i\)th frame \(\underline{L}^{(i)}\) for \(i \in \{1,\dots,N_{\mathrm{rep}}\}\), and decoding starts from \[\underline{L}_\mathrm{init} = \underline{L}^{(1)} + \sum_{\ell=2}^{N_{\mathrm{rep}}} (-2\underline{s}^{(\ell)}+1) \odot\underline{L}^{(\ell)} . \label{eqn:repetition}\tag{1}\] Repetition effectively creates a virtual channel seen by the higher-rate decoder. The reconciliation efficiency \(\beta\) can be written as \[\beta = \frac{R}{C} = \frac{R_\mathrm{rep}R_\mathrm{LDPC}}{C} = \beta_\mathrm{rep}\beta_\mathrm{LDPC},\] where \(\beta_\mathrm{LDPC}\) is the reconciliation efficiency of the LDPC code. For an SNR \(x\), the channel capacity is \(C=\frac{1}{2}\log_2(1+x)\), and \(\beta_\mathrm{rep}=\log_2(1+N_\mathrm{rep}x)/(N_\mathrm{rep}\log_2(1+x))\) captures the asymptotic efficiency loss due to repetition [4]. Fig. [fig:beta95rep] illustrates \(\beta_\mathrm{rep}\) for the representative case \(R=0.005\).

To analyze the protocol’s security, we obtain an equivalent compact formulation by stacking the frames into \(\tilde{\underline{a}}=( (\underline{a}^{(1)})^T \cdots (\underline{a}^{(N_\mathrm{rep})})^T)^T\). Then Alice sends \(\tilde{\underline{x}}\), Bob measures \(\tilde{\underline{y}}\), and Bob computes \(\tilde{\underline{s}}=\tilde{\mathbf{H}}\tilde{\underline{u}}\) with \[\tilde{\mathbf{H}}=\begin{bmatrix} {\mathbf{H}} & \mathbf{0} \\ {\mathbb{I}} & \mathbb{I} \end{bmatrix}.\]

Here, \(\mathbb{I}\) and \(\mathbf{0}\) denote the identity and zero matrices, and the resulting rate is \(R=R_\mathrm{rep}R_\mathrm{LDPC}\). Bob also transmits MDR rotations \(\tilde{\underline{\phi}}\) derived from \(\tilde{\underline{y}}\) and \(\tilde{\underline{u}}\). Under collective attacks, \(\tilde{\underline{x}}\) and \(\tilde{\underline{y}}\) are i.i.d., and \(\tilde{\underline{u}}\) is uniform i.i.d. and independent of \(\tilde{\underline{y}}\); therefore, the security proof of [1] remains applicable.

2.2 Decoding Complexity↩︎

We estimate the complexity of iterative belief-propagation decoding by counting message updates in the Tanner graph. On a per-information-bit basis, this scales with (average variable node (VN) degree) \(\times\) (average number of iterations) for the code constructions we use [5]. Because degree-1 VNs do not participate in message updates, they are excluded when computing the average VN degree. In repetition-based decoding, the preprocessing in (1 ) adds negligible overhead compared with iterative decoding, so it is omitted from the complexity metric.

3 Simulation Results↩︎

We target an overall rate of \(R=0.005\). Following [2], we optimize protographs for \(R_\mathrm{LDPC}=0.005,0.01,0.02,0.1\) (markers in Fig. [fig:beta95rep]). The lifted block length is chosen such that, after repetition, the effective block length is approximately \(2\cdot 10^6\). We assume the four-state protocol [4] and use flooding-schedule sum-product decoding up to 200 iterations.

Figure [fig:FER] shows the FER curves for the unrepeated designs (\(N_\mathrm{rep}=1\), dashed lines). We then apply repetition factors \(N_\mathrm{rep}=2,4,20\) to the \(R_\mathrm{LDPC}=0.01,0.02,0.1\) codes, respectively, to obtain the same overall rate \(R=0.005\) (solid lines). As expected, the FER degrades with a larger number of repetitions; the penalty is most pronounced for \(R_\mathrm{LDPC}=0.1\) and decreases for lower mother-code rates, consistent with the \(\beta_\mathrm{rep}\) behavior in Fig. [fig:beta95rep].

Overall, the dedicated \(R_\mathrm{LDPC}=0.005\) code achieves the best FER. However, repetition coding on \(R_\mathrm{LDPC}=0.01\) or \(0.02\) incurs only a moderate FER penalty while reducing decoding complexity by about \(2\times\) and \(4\times\), respectively (Fig. [fig:complexity]). Therefore, in the high-FER operating region relevant to long-distance CV-QKD, repetition-based reconciliation offers a compelling implementation trade-off.

Figure 1: Repetition efficiency \beta_\mathrm{rep}, frame error rate and average decoding complexity for LDPC mother-code rates R_\mathrm{LDPC} and reconciliation efficiency \beta. In subfigures (b) and (c), dashed curves correspond to no repetition (N_\mathrm{rep}=1), while solid curves correspond to the repetition factors indicated in subfigure (a) to obtain an overall rate of R=0.005.

4 Conclusion↩︎

Dedicated ultra-low-rate codes provide the best FER, but repetition-based schemes offer a stronger practical FER-complexity trade-off. When decoder complexity, throughput, or latency is the dominant constraint, repetition-based IR is the more compelling option.

References↩︎

[1]
A. Leverrier, R. Alléaume, J. Boutros, G. Zémor, and P. Grangier, “Multidimensional reconciliation for a continuous-variable quantum key distribution,” Phys. Rev. A, vol. 77, p. 042325, Apr. 2008, doi: 10.1103/PhysRevA.77.042325.
[2]
K. Gumus and L. Schmalen, “Low rate protograph-based LDPC codes for continuous variable quantum key distribution,” in Proc. 17th international symposium on wireless communication systems (ISWCS), Sep. 2021, doi: 10.1109/iswcs49558.2021.9562244.
[3]
H. Mani, T. Gehring, P. Grabenweger, B. Ömer, C. Pacher, and U. L. Andersen, “Multiedge-type low-density parity-check codes for continuous-variable quantum key distribution,” Phys. Rev. A, vol. 103, p. 062419, Jun. 2021, doi: 10.1103/PhysRevA.103.062419.
[4]
A. Leverrier, Theoretical study of continuous-variable quantum key distribution,” PhD thesis, Télécom ParisTech, 2009.
[5]
B. Smith, M. Ardakani, W. Yu, and F. R. Kschischang, “Design of irregular LDPC codes with optimized performance-complexity tradeoff,” IEEE Transactions on Communications, vol. 58, no. 2, pp. 489–499, 2010, doi: 10.1109/TCOMM.2010.02.080193.