REVIEW ARTICLE future direc ons of free-space
QSDC are discussed. We propose
a prac cal and feasible route that
Free-Space Quantum Secure Direct can make immediate
Communica on: Basics, Progress, and Outlook Cita on: Pan D, Song XT, Long GL.
Free-Space Quantum Secure Direct
Dong Pan1, Xiao-Tian Song1, and Gui-Lu Long1,2,3,4* Communica on: Basics, Progress,
and Outlook. Adv. Devices Instrum.
1Beijing Academy of Quantum Informa on Sciences, Beijing 100193, China. 2State Key Laboratory of 2023;4:Ar cle 0004. h ps://doi.
org/10.34133/adi.0004
Lowdimensional Quantum Physics and Department of Physics, Tsinghua University, Beijing 100084,
China. 3Fron er Science Center for Quantum Informa on, Beijing 100084, China. 4Beijing Na onal Submi ed 7 December 2022
Accepted 20 February 2023
Research Center for Informa on Science and Technology, Beijing 100084, China. Published 12 April 2023
*Address correspondence to: gllong@[Link] Copyright © 2023 Dong Pan et al.
Exclusive Licensee Science and
Quantum secure direct communica on (QSDC) leverages quantum states to transmit informa on Beijing Ins tute of Aerospace Control
Devices. No claim to original U.S.
securely and reliably over a noisy, lossy, and wiretapped quantum channel. It has been proven to be
Government Works. Distributed
informa ontheore cally secure. Recent experiments show that QSDC can enable long-distance under a Crea ve Commons
communica on and large-scale networking with exis ng technologies. In par cular, free-space QSDC A ribu on License (CC BY 4.0).
has the unique advantages and prospects for prac cal large-scale applica on. Here, we review the
QSDC basics and the progress of free-space QSDC. The feasibility of satellite-based QSDC and the
applica on of QSDC in real life. distribution (QKD) [8,9], quantum secure direct
communication (QSDC) [10], quantum teleportation [11],
and quantum secret sharing [12,13] are the major paradigms
of quantum cryptography or quantum communication.
Introduc on QSDC utilizes quantum state as information carrier for
secure communication. No secret key is required in QSDC
Quantum information sciences provide novel ways of
[10,14–17]. It is a theory on secure and reliable
computation, precision measurement, and secure
communication via quantum physics. The numerous
communication. Remarkably, Shor’s algorithm in quantum
experimental works of QSDC have shown its feasibility and
computation can factorize large numbers in polynomial time
compelling application prospects [18–28]. The report of the
[1]. It threatens the security of a public key cryptosystem
Center for a New American Security notes that QSDC
such as the Rivest– Shamir–Adleman protocol [2].
improves the security and the value proposition of quantum
Furthermore, Grover’s algorithm [3,4] speeds up brute-force
communication in general [29]. By struggling tenaciously
attack to symmetric key cryptography such as Advanced
for more than 20 years, QSDC is gradually maturing and
Encryption Standard [5]. Recently, there appeared a sign that
exhibits great potential for next-generation secure
quantum algorithm may threaten Advanced Encryption
communication [30], and even in military applications [31].
Standard-like algorithms even more seriously than Grover’s
The free-space channel is a common link of
algorithm [6]. Some private information usually has a very
communication, which dispenses the laying of optical fibers
long confidentiality period, such as 10 years or even more.
In cryptography, the only algorithm that has been shown and can effectively break the limitation of communication
perfectly secure is the one-time pad [7]. Other protocols have distance and terrain. Optical signals transmitted in the free-
not been proven to be unconditionally secure. Therefore, for space channel with clear weather have a lower attenuation than
in optical fibers. Schmitt-Manderbach et al. [32] observed an
private information with long-time confidentiality
requirements, there exists the risk that eavesdropper may atmospheric loss of 0.07 dB/km at 2,400 m above sea level for
store the ciphertext now and wait to decipher it in the future quantum signal transmission. Quantum communication over a
when there are new methods and faster computers, such as vacuum channel above Earth’s atmosphere is virtually free of
absorption attenuations. Furthermore, the atmosphere channel
quantum computers. Quantum computers have become a
has almost no birefringence effects and is therefore very
realistic threat to secure communications relying on classical
cryptography even though they are inaccessible at the time friendly to polarized quantum state transmission.
of writing. Consequently, the satellite- based QSDC is an important way
to achieve global quantum communication. Based on free-
Fortunately, quantum physics has given other ways of
space QSDC, a flexible and maneuverable means of secure
achieving secure communication, and they are unbreakable
communication can be constructed. It can be used for both the
by even the fastest computers in principle. Quantum key
last meter and last mile access networks [33,34], namely,
Pan et al. 2023 | h ps://[Link]/10.34133/adi.0004 1
providing a solution to the last one-hop problem. Here, we where Cm and Cw are the capacities of the main channel and
focus on the overview of freespace QSDC, including both its the wiretap channel, respectively, while I(A : B) is the mutual
theoretical and experimental advancements. information between Alice and Bob, and I(A : E) is the
This paper is structured as follows. In the Basic Principle maximum information that Eve can obtain. If Cs has a
and Typical Protocols section, we introduce the basic principle positive value, then the secure-coding schemes with a coding
and typical protocol of QSDC. In the QSDC in Realistic rate of R ≤ Cs that consummates both secure and reliable
Channels section, a QSDC system for realistic channels is communication could be constructed. Typical secure coding
presented. In the Free-Space QSDC section, we describe the includes universal hashing families (UHF) [22,24,38] as well
characteristics of free-space channel and review the progress as joint encryption and error-control coding [39]. Note that
in free-space QSDC. Some important issues in free-space and the usage of hash function in QSDC is different from the
satellite-to- ground QSDC are discussed in the Issues in Free- privacy amplification of QKD.
Space and Satellite-to-Ground QSDC section. A future outlook Specifically, the secrecy capacity of the DL04 QSDC
is given in the Outlook section. We propose a scheme of protocol
classical- cryptography assured imperfect device (CAID) [15] is given by [22]
QSDC in the CAID QSDC section. Finally, the conclusions are
presented in the Conclusions section.
Cs = QBob[1 −h(e)−g ⋅ h(ex +ez)], (2) where QBob is
Basic Principle and Typical Protocols the signal gain of Bob and e is the quantum bit error rate
(QBER) in the second eavesdropping check, while ex and ez
Basic principle
As shown in Fig. 1, QSDC is a scheme for achieving secure are the first QBER of measurements using σx-basis and σz-
communication by utilizing quantum states. The message basis, respectively. Furthermore, g denotes the ratio of signal
sender Alice encodes the plaintext messages to the quantum gain between Bob and Eve, namely,
states, which are then transmitted to the receiver Bob through
a quantum channel. Bob can obtain the messages via decoding,
i.e., measuring the received quantum states. Secure g= QEve , (3)
communication is realized without the need to distribute secret
keys in advance. A classical authenticated channel is necessary QBob
for QSDC to finish eavesdropping detection and error where QEve is the receiving rate of Eve. The decoy-state
correction. The security of QSDC is based on the principles of method can be applied to QSDC for improving practical
quantum physics, making it impossible for an eavesdropper to performance [24,40–42].
obtain any useful information associated with the message.
QSDC can transmit many forms of information, such as text,
voice, video, and secret key. If QSDC is used to transmit the The evolu on of communica on protocols
secret key, both distribution of the deterministic secret key and QSDC was conceived by Long and Liu in 2000 [10].
negotiation of the random secret key can be actualized. Subsequently, other compelling schemes were proposed,
The peer-to-peer QSDC protocol has the following such as the 2-step protocol [14], the DL04 protocol [15], the
features: (a) QSDC completes secure communication without high-dimensional protocol [16], and so on. There are 2 basic
prior sharing of secret keys; (b) Bob can deterministically classes of QSDC protocols or quasi-QSDC protocols,
obtain the confidential messages by measuring the quantum discrete-variable protocols [17,19,23,43–50] and
states without the need for additional classical communication; continuous-variable protocols [51–54]. It is also feasible to
(c) QSDC can detect the presence of an eavesdropper in real implement measurement-device-independent (MDI) [55–62]
time. If there is a protocol that does not satisfy the above and device-independent (DI) QSDC [63,64]. As shown in
characteristics, we call it a quasi-QSDC protocol. Fig. 3, we present the evolution of QSDC protocols or quasi-
The information-theoretic security of QSDC has been QSDC protocols before reviewing some of them. The quasi-
proven based on Wyner’s wiretap channel theory [22,24,35– QSDC protocols are labeled by a checkered underlay in Fig.
38], and the finite-size effect on its secrecy capacity has been 3.
given by Wu et al. [38]. The wiretap channel model is shown
in Fig. 2, in which the quantum channel between a pair of Block data transmission and EPR-based efficient
legitimate users Alice and Bob is called the main channel,
protocol
while Eve eavesdrops information via a wiretap channel. The
secrecy capacity Cs of QSDC is defined as a maximum The first QSDC protocol was proposed by Long and Liu in
communication rate at which legitimate users can 2000 [10]. With the block transmission of EPR pairs, this
communicate securely in the presence of an eavesdropper, protocol enables the efficient transmission of predetermined
which is written as secret
Cs = Cm −Cw = I(A: B)−I(A: E), (1)
Pan et al. 2023 | h ps://[Link]/10.34133/adi.0004 2
Main channel, Cm
Encoding Transmitter Receiver Decoding
Alice Bob
Eve
Wiretap channel, Cw
Message Message
Encoding Quantum states Decoding
Classical authenticated channel
Alice Bob
Quantum channel
Fig. 1. Illustra on of the QSDC scheme.
Fig. 2. The wiretap channel model.
Pan et al. 2023 | h ps://[Link]/10.34133/adi.0004 3
Efficient protocol, 2000
Two-step protocol, 2003
Entanglement High-dimensional protocol, 2005
DI protocol, 2019
MDI protocol, 2018
Discrete
Single photon DL04 protocol, 2004
variable
RECON protocol, 2004
(It requires secret keys)
QSDC
protocols Coherent QKPC protocol, 2021
or optical field (No online eavesdropping detection)
quasi-QSDC
protocols
Discrete QLPI protocol, 2019
modulation (It requires secret keys)
Continuous
variable
Gaussian
Gaussian mapping protocol, 2021
modulation
Fig. 3. The evolu on of QSDC protocols. This development path includes the following representa ve QSDC protocols: efficient protocol [10]; 2-step protocol [14];
highdimensional protocol [16]; DI protocol [63]; MDI protocol [55,56]; DL04 protocol [15]; REpeatable Classical ONe- me-pad (RECON) protocol [43]; quantum keyless
private communica on (QKPC) protocol [44]; quantum low probability of intercept (QLPI) protocol [51]; and Gaussian mapping protocol [52].
information over a quantum channel. There is a pair of users receiver, respectively, as shown in Fig. 4. The efficient
Alice and Bob who are the information transmitter and protocol consists of the following steps:
Pan et al. 2023 | h ps://[Link]/10.34133/adi.0004 4
Step 1, states preparation. Alice prepares a sequence of EPR was used for the first eavesdropping check. Bob measures the
pairs according to the transmitted message bits and check bits, corresponding photons in (b)-sequence using the same
and each of them is in 1 of 4 Bell states. This sequence can be measurement bases as Alice. They compare their
expressed as a set LA = {|Ψ1⟩, |Ψ2⟩, |Ψ3⟩, …, |ΨN⟩}, in which measurement results via an authenticated classical channel to
|Ψi⟩ ∈ {|ψ+⟩, |ψ−⟩, |ϕ+⟩, |ϕ−⟩} (i = 1, 2, 3, …, N). The 4 Bell states determine the QBER. If the QBER is below a certain
are expressed as threshold, the next step is executed. Otherwise, they
terminate the communication.
Step 4, information decoding and the second check. Alice
𝜙 , sends the remaining photons of (a)-sequence to Bob. Bob
(4)
measures them to read out the message and the rest of check
bits by using Bell-basis measurement. Then, Alice announces
the positions and the encoded values of second-checking
𝜙 , photons. Bob compares these values with his own
(5)
corresponding measurements to derive the QBER to check
the reliability of the communication. If this QBER is
tolerable, the communication is successful.
𝜓 ,
(6)
Alice Bob Alice Bob Alice Bob Alice Bob
Step 1 Step 2 Step 3 Step 4
Fig. 4. Schema c diagram of the efficient QSDC protocol.
DL04 protocol
𝜓 , Deng and Long created a QSDC protocol in 2004 by utilizing
(7)
single photons for information transmission [15]. The
and they carry bits 00, 01, 10, and 11, respectively. As shown illustration of the protocol is shown in Fig. 5, which contains
in Fig. 4, the pair of balls in orange, green, black, and purple the following steps:
represent the Bell states of |ϕ+⟩, |ϕ−⟩, |ψ+⟩, and |ψ−⟩, respectively.
Step 1, states preparation and transmission. Bob prepares
Then, Alice divides this sequence into 2 sequences (a) and (b).
Each EPR pair contains 2 photons, and 1 photon is in the (a)- a sequence of qubits containing N single photons and sends it
sequence, while the other photon belongs to the (b)- sequence.
to Alice. This sequence is denoted by a set LB = {|Φ1⟩, |Φ2⟩,
It should be noted that the check bits are randomly interspersed
in the message bit sequence. The third and sixth are check bits |Φ3⟩, …, |ΦN⟩}, where each |Φi⟩ (i = 1, 2, 3, …, N) is randomly
in Fig. 4.
in one of the 4 states, |0are eigenstates of − = 1∕√⟩σ, |1z-
Step 2, qubits transmission. Alice transmits the (b)-sequence
to Bob. −
2basis, while (⟩, |0+⟩⟩−, and |1⟩ +⟩. Furtherm= 1∕√o2re,
Step 3, the first eavesdropping check. Alice randomly
chooses either the σz-basis or σx-basis to measure the ⟩ ⟩
checking photons held by her. She tells Bob about the |0(0⟩ and |1+ 1⟩ ) and ⟩ ) are eigenstates of ⟩ σx-basis.
positions of the photons she has measured and the
measurement bases. As shown in Fig. 4, the third EPR pair
Pan et al. 2023 | h ps://[Link]/10.34133/adi.0004 5
Beam Classical
Switch splitter authenticated channel
Single-photon
Optical Quantum channel source
delay
Information Eavesdropping
encoding detection
Quantum channel
Measurement
Alice Bob
Step 2, eavesdropping detection. Alice randomly selects Step 4, measurement. After receiving the photons returned
some of the photons received from Bob for eavesdropping from Alice, Bob reads out the classical information bits
detection encoded by Alice based on his preparation bases. Alice
Fig. 5. Illustra on of the DL04 QSDC protocol. announces the positions of the photons encoded random
numbers, and both parties estimate the QBER of the second
transmission. The second QBER estimation mainly tests the
by employing a beam splitter. These photons can be denoted integrity of information transmission, and if it is below a
by a subset LC ⊂ LB with a size |LC| = nC. To complete the certain threshold, the transmission is successful.
step of eavesdropping detection, each photon in the subset is
measured in either σz-basis or σx-basis. Alice informs Bob of The eavesdroppers have no access to secret information in the
the positions of the photons in subset LC, the measurement QSDC relying on block-based transmission of qubits [10,14–
bases she has chosen, and the corresponding measurement 17], which is also called quantum one-time pad [15].
results. Alice and Bob estimate the first QBER (it is called
detection bit error rate [DBER], as distinguished in Pan et al. Other protocols
[24]). If the QBER is below a predetermined threshold, they
These protocols are not exactly QSDC in the strict sense. They
move to the next step. Otherwise, this transmission is bear some similarities to QSDC, such as transmitting secret
discarded. messages using the quantum channel. However, they do not
The remaining photons that are not selected for satisfy the 3 characteristics of peer-to-peer QSDC protocol
eavesdropping detection form another subset LE ≡ LB − LC, described in the Basic Principle and Typical Protocols section,
with |LE| = N − nC, and they are stored in an optical delay to and therefore they are called quasi-QSDC protocols. For
wait for the result of eavesdropping detection. It should be completeness, we also list 3 of them here.
noted that a noiseless transmission is considered here.
RECON protocol
Step 3, information encoding. Alice encodes the secret
message onto the remaining single photons and returns them
A single-photon QSDC protocol relying on repeatable
classical one-time pad was proposed in 2004 [43,65], and it is
to Bob. She utilizes the unitary operation U0 = I = |0⟩⟨0| +
called the RECON protocol. As shown in Fig. 6, the
|1⟩⟨1| and U1 = iσy = |0⟩⟨1| − |1⟩⟨0| for mapping classical bits
operational steps of this protocol can be described as follows:
0 and 1 onto a single photon, respectively. Distinctly, the
operation U1 only flips the single-photon state in both Step 1, secret key presharing. Alice and Bob generate 2
measurement bases, which can be written as mutually shared secret keys in advance. It can be realized by
BB84 QKD [8], or by presharing when they are in contact.
U0⟩ =− 1⟩, U1⟩ = 0⟩, (8) Step 2, message and test sequence preparation. Alice
prepares a sequence of binary random numbers with a length
of nr and she randomly inserts these random numbers into a
U + ⟩ = − ⟩, U − ⟩ =− + ⟩ (9) secret message sequence that is to be transmitted. Hence, a
message-test sequence with the length of nm + nr is generated,
where nm is the length of secret message sequence. For
To estimate the reliability of the second transmission, Alice example, there is a message-test sequence 1001101001, in
randomly chooses some photons of LE to encode random which the default texts are binary secret messages, while the
numbers 0 or 1. It means that the vast majority of single italicized texts are random numbers.
photons in LE carry secret information, while a small number
of single photons are encoded random numbers for
estimating the second QBER.
Pan et al. 2023 | h ps://[Link]/10.34133/adi.0004 6
Classical
authenticated channel
Single-photon Quantum channel
source Measurement
Alice Bob
Step 3, state preparation. Alice invokes a secret-key sequence schematic of QLPI is shown in Fig. 7, and its operating steps
with the length of 2(nm + nr) to prepare single photons; the rules are as follows:
for preparation is Step 1, state preparation and transmission. A low-
brightness, broadband, amplified spontaneous emission (ASE)
00 → 0⟩, 11 → 1⟩, 01 → + ⟩, 10 → − ⟩. (10)
light is transmitted from the information receiver to the
Fig. 6. RECON protocol.
transmitter, and the remaining high-brightness ASE light is
stored in the delay line of the information receiver.
For example, if the secret-key sequence is 0001111001, then Step 2, information encoding. The information transmitter
the single photons |0⟩, |+⟩, |1⟩, |−⟩, and |+⟩ would be prepared encrypts the plaintext to get ciphertext, which is transformed
successively. into a codeword by a forward error correction (FEC) encoder.
Step 4, information encoding. Alice encodes the binary The codeword will be mapped onto the light by binary
message-test sequence to single photons via 2 operations U0 = phaseshift keying modulation.
I and U1 = iσy, which encode 0 and 1, respectively. The single
Step 3, state transmission. The modulated light is passed
photon sequence is transmitted to Bob one by one. Here, block
through a high-gain optical amplifier and then returned to the
data transmission is not required.
information receiver.
Step 5, measurement and decryption. Bob measures each of
Step 4, information decoding and decrypting. The
the received photons in an appropriate basis according to their
information receiver combines the returned light and the
preshared secret key, following the corresponding rules of Step
stored high-brightness ASE light, which is actually a local
3, which is given by
oscillator for broadband homodyne detection. The
measurement results are restored to plaintext after FEC
00 and 11 →𝜎z, 01 and 10 →𝜎x. (11) decoding and decrypting.
Note that we only briefly highlight the information
Bob can obtain the encoded message and test bits on every single
photon. transmission process in QLPI, while its channel monitoring
to defend against active eavesdropping by using low-
Step 6, eavesdropping detection. Alice publicly announces brightness photon pairs generated from spontaneous
the positions and values of the test single photons. Bob parametric downconverter can be found in the original
compares them with his measurement results associated with literature [51].
these photons and determines the QBER. If the QBER is below
a certain threshold, they conclude that no eavesdropper exists
Quantum keyless private communica on protocol
and they move to the next step. Otherwise, they abort the
Zbinden’s group put forward the protocol called quantum
protocol. Once Alice publicly announces that the positions of
keyless private communication (QKPC) to achieve direct
single photons encoded random numbers, the transmitted
private communication over the quantum channel in 2021
secret messages are available for Bob. The information has [44]. It can be regarded as a quasi-QSDC protocol. This
been transmitted. protocol contains the following steps (as shown in Fig. 8):
Step 7, updating the secret key. Alice and Bob discard the Step 1, encoding. Alice encodes the message into a codeword
secret key bits mapped to the photons that have been used for via a stochastic wiretap encoder.
encoding random numbers. The remaining secret keys will be
Step 2, state preparation and transmission. Alice prepares
devoted to the next round of transmission.
a vacuum state |0⟩ or a coherent state |α⟩ according to the
codeword and transmits it to Bob. Specifically, a vacuum
Quantum low probability of intercept protocol state is emitted from Alice when the codeword is 0, and a
The quantum low probability of intercept (QLPI) protocol is coherent state is emitted in the case of codeword 1. This is
advocated by Shapiro et al. [51] in 2019. It directly transmits known as on–off keying modulation.
the ciphertext over a quantum channel to prevent the
eavesdropper from obtaining valuable information. The Step 3, measurement. Bob obtains the received codeword by
measuring the arriving signal.
Pan et al. 2023 | h ps://[Link]/10.34133/adi.0004 7
Step 4, decoding. Bob enters the received codeword into a transmission, a certain number of quantum states are
decoder to get the transmitted information. transmitted as a block, and some of the quantum states in the
block are randomly sampled for eavesdropping detection.
The information is encoded onto the remaining quantum
Comparison states after confirming the security of the block transmission.
There is a twice or 2-way transmission of qubits in the efficient Hence, a quantum memory is required for storing the
protocol, DL04 protocol, and QLPI protocol. As the 2-way photons when 2 parties wait for the results of eavesdropping
Fig. 8. The quantum keyless private communica on protocol [44]. detection. As shown in Fig. 7, the quantum memory can be
simplified as an optical delay line—a common way of
storing photons in QSDC [21,22,24].
transmission of QSDC, it theoretically has half of the By contrast, the RECON protocol and QKPC protocol only
tolerance of the one-way protocol to channel loss. The one- entail one-way transmission for qubits. The qubits are sent and
way protocols [43,65] have the same capacity to resist loss measured one by one and no quantum memory is required.
as that of the BB84. Distributing secret keys is necessary before implementing a
The efficient protocol and the DL04 protocol use the confidential message transmission in the RECON protocol and
block data transmission for secure transmission. In block
Pan et al. 2023 | h ps://[Link]/10.34133/adi.0004 8
QLPI protocol. However, the step of eavesdropping detection coding layer. A transmitter of a specific QSDC protocol sends
is not available in the QKPC protocol [44]. the codeword to the QSDC receiver, says Bob.
The efficient protocol, DL04 protocol, and QKPC protocol Correspondingly, the decoding layer of Bob transforms the
achieve secure communication without the process of codeword into plaintext, which is then deposited to the
distributing a secret key; thus, no encryption and no decryption information sink. Hence, QSDC transforms the traditional 2-
are required. No resources are needed for key management. channel structure of secure communications [66–68] into a
Table 1 provides a comparison between the above protocols. single-channel structure and achieves both the security and the
reliability of communication [67].
Error correction code could be selected in the classical
QSDC in Realis c Channels domain, e.g., low-density parity check (LDPC) code
Some of the protocols in the Basic Principle and Typical [22,24,69], Bose–Chaudhuri–Hocquenghem code [26], polar
Protocols section are described under an ideal channel, which code [70,71], and so on. Single photons are so fragile that
does not take into account the noise and loss. For this reason, they are very easily lost in the channel, resulting in a very low
we will introduce the QSDC in the realistic channel and it is reception rate for the receiver. Although classical error
general for fiber-based and free-space systems. The correction code has the ability to resist lossy transmission, the
characteristics of the free-space channel will be presented loss of quantum channel exceeds its tolerant limit. One can
later. concatenate the error correction code and the maximum
The secret information in QSDC, which could be in linear feedback shift register sequence [72] for the sake of
multiple formats, such as text, image, voice, video, secret key, anti-loss. The FEC codes and anti-loss encoding
and so on, is encoded onto the quantum states and transmitted efficaciously help QSDC to fight against channel loss and
directly over the quantum channel from Alice to Bob. The achieve reliable information transmission. This is very
noiseless transmission is assumed in the original protocol. different from QKD, where lost bits in the channel have no
However, users cannot bear the expense of losing meaningful contribution to the final secret key, and could be ignored
messages that are transmitted over the actual quantum channel. completely.
The practical QSDC system is shown in Fig. 9. The The coding and decoding layers that have been
information source of Alice contains the plaintext to be implemented in experiments [22,24] are illustrated in Fig. 10.
transmitted. The real quantum channel is confronted with The UHF serve as secure coding, and it is a wiretap channel
eavesdropping, noise, and loss; thus, coding is essential for coding intending to information-theoretic security [73]. In
fighting against these detrimental factors. This coding layer such a coding method, the sender Alice generates a sequence
comprises 3 modules, including an FEC code encoder, an anti- of local random bits of a certain length first. She then uses
loss encoder, and a secure-coding encoder. Alice obtains the the reverse UHF (UHF–1)
transmitted codeword after passing plaintext through the
Table 1. Comparison of protocols.
Protocol Transmission Quantum memory Secret key Eavesdropping
detec on
Efficient protocol Twice Required Not required Yes
DL04 protocol Two-way Required Not required Yes
RECON protocol One-way Not required Required Yes
QLPI protocol Two-way Required Required Yes
QKPC protocol One-way Not required Not required Not available
Pan et al. 2023 | h ps://[Link]/10.34133/adi.0004 9
Fig. 9. QSDC structure in real channels. The classical authen cated channel for eavesdropping detec on and error correc on is omi ed here. ECC, error correc on
code.
Alice Secure coding encoder ECC encoder Anti-loss encoder
Plaintext UHF–1 LDPC Mapping
encoder
Local random
numbers Public
random seed
Coding
Noisy, lossy, and wiretapped quantum channel
Bob Secure coding decoder ECC decoder Anti-loss decoder
Plaintext UHF LDPC De-mapping
decoder
Public random seed
Decoding
Fig. 10. The coding and decoding in prac cal QSDC experiment [22]. the length of shared secure key sequence for the next round
of communicating and coding efficiency are bound by the
to process the message together with the local random secrecy capacity estimated from the QBER of this round of
numbers and the public random seed, which achieves transmission. It realizes simultaneous secure-sequence
randomization of the secret message and generates a new negotiation and ciphertext transmission [67]. The
vector. This vector is encoded by LDPC code and confidential information mapped onto quantum states is
subsequently mapped to a transmitted codeword. After protected by a shared secure key sequence; thus, it could be
receiving the codeword, Bob can obtain the secret message sent using a one-by-one prepare-and-measure process,
via appropriate steps of de-mapping, ECC decoding, and removing the constraint of block-based transmission of
UHF. Eve cannot infer the secret message in the case of a photons. It has been experimentally demonstrated that
partially stolen transmitted codeword. This secure coding quantum-memory-free QSDC [39,74] over the fiber channel
scheme does not require any change to the traditional coding with a distance of 100 km is feasible [26].
structure. It can be followed by arbitrary error correction The eavesdropper Eve in QSDC is consistently assumed to
codes and anti-loss codes to enhance reliable communication have the eavesdropping capabilities allowed by quantum
capability. The mapping invoked here is the maximum linear mechanics. For instance, she can employ a noiseless quantum
feedback shift register sequence [72] to resist high channel for eavesdropping. It means that the capacity of the
transmission loss of the quantum channel. To elaborate wiretap channel will be large, making it difficult to achieve a
further, the LDPC codeword is mapped into a longer pseudo- positive secrecy capacity. Against this background, a scheme
random sequence for transmission [22,39]. of increasing channel capacity using masking (INCUM) has
The original DL04 protocol necessitates quantum been designed by the work of Long and Zhang [75]. Alice
memory, whereas quantum memory is in the infant stage at masks the encoded codewords using her local random numbers
present. Quantum-memory-free QSDC scheme [39,43 before they are transmitted, and transmits them to Bob, who
,65,74] can address this challenge. The quantum-memory- can only receive a small fraction of the photons due to channel
free DL04 protocol is actually a secure-coding scheme based loss. Bob announces the positions of only the successfully
on Wyner’s wiretap channel theory. The plaintext to be detected photons. Subsequently, Alice tells him the value of
transmitted is converted into ciphertext using a shared secure local random number associated with the photons detected by
transmission sequence in this scheme, and the generated Bob. The rest of the local random numbers will never be
ciphertext will be encoded by error correction code and anti- disclosed. This solution severs the connection between the lost
noise code for transmission over the quantum channel. Both photons and the photons received by Bob, and the information
Pan et al. 2023 | h ps://[Link]/10.34133/adi.0004 10
of the lost photons was completely masked by Alice’s local Free-Space QSDC
random numbers. Eve cannot obtain any valid information
from the lost photons. Two legitimate communication parties Channel characteris c
could take advantage of this solution for limiting Eve with the As shown in Fig. 11, we summarize the main characteristics of
same reception rate as Bob, resulting in g = 1 in Eq. 3. In fact, the free-space channel and their impacts on optical signal
the INCUM increases the channel capacity greatly and transmission. The beam-spreading occurs due to diffraction
enhances the tolerable noise level of the wiretap channel. when a light beam propagates through the atmosphere [76].
In 2016, the first 2-way QSDC experiment over a fiber The turbulence in the atmospheric channel would cause beam-
channel was conducted on an optical platform in the laboratory spreading, beam-wandering, and scintillation [76,77]. Gases,
[18]. The 2-way QSDC has achieved a practical tiny particles, and various weather conditions are the source of
communication distance of 102.2 km [26] this year. It is not absorption and scattering of light, which will attenuate the
the end but an intermediate node of journey. The optical signals. Sunlight is the background noise for quantum
communication performance could be further improved by communication, reducing the signal-to-noise ratio (SNR) of
using one-way QSDC protocol and even the expected twin- communication. These channel characteristics are the focus of
field protocol. attention or noise for free-space QSDC, and we will detail
some related issues and advances in subsequent sections.
We have already introduced several QSDC protocols or
quasi- QSDC protocols in the Basic Principle and Typical
Protocols section. The 1-way transmission protocols
(RECON protocol and QKPC protocol) may be more
advantageous than the 2-way protocols for long-distance
Pan et al. 2023 | h ps://[Link]/10.34133/adi.0004 11
free-space communication due to the multiple factors in the
free-space channel that would affect communication.
Furthermore, the RECON protocol and
Pan et al. 2023 | h ps://[Link]/10.34133/adi.0004 12
QKPC protocol do not require 2-way classical Fiber and free-space hybrid op cal networking
communication for reconciliation, and thus, they are suitable experiment
for satellite communication [44]. However, the RECON
protocol comes with the issue of replenishing secret keys. The exponential attenuation of photons in optical fibers limits
The continuous-variable protocol (QLPI protocol) has the the communication distance of QSDC. A quantum network
advantages of being robust to background light, achieving a relying on the classical secure repeater scheme was proposed
high information transmission rate, and facilitating free- in 2022 [27]. Communication users of secure repeater
space channel estimation [76]. networks use QSDC to transmit the ciphertext generated by
the post-quantum cryptography, realizing doubly protected
information transmission and secure repeater node. The
Theore cal perspec ve ciphertext can be relayed for long-distance transmission
In 2019, Shapiro et al. [51] proposed a scheme dubbed QLPI through the classical intermediate nodes. Thanks to the
to realize QSDC. If the line of sight is monitored by Alice protection of post-quantum cryptography at each relay node,
and Bob in free-space implementation of this scheme, Eve classical relay nodes are not required to be trusted. One can
will be limited to passive eavesdropping, and an improved use current technologies to build largescale quantum secure
performance of communication would be obtained networks when quantum repeaters are still unavailable. It
considering such a realistic constraint. could be a near-term quantum network without quantum
In order to mitigate reference-frame misalignment and repeaters. The secure repeater scheme shows that there is a
rotational noise of the free-space channel, a QSDC protocol tight combination between QSDC and post- quantum
based on decoherence-free space was designed in Ref. [78]. cryptography, since the organic integration of these 2 solutions
Turbulence is a detrimental factor affecting quantum allows for end-to-end security in quantum network [27]
communication in free space. Some works have modeled As Fig. 13 shows, a secure classical-repeater-based fiber
turbulent channels for QSDC [79,80]. Adaptive optics [81] and free-space hybrid optical network was experimentally
and quantum error correction [82] can be used to protect the implemented in [27]. This 3-node secure network comprises a
information transmission of orbital-angular-momentum- 10-km fiber link and a 2-m free-space link. An image file is
based QSDC [83] in a turbulent channel. QSDC directly transmitted from Alice to relay R and then to Bob.
transmits classical information over a noisy quantum
channel. Lindsey [84] studied the quantum noise channel Issues in Free-Space and Satellite-to-Ground
model where the quantum atmospheric turbulence was
carefully included. QSDC
Most recently, the group of Zbinden conceived a protocol Communica on wavelength
with on–off keying of coherent states and they named it
QKPC [44]. They present a comprehensive model to As introduced in the Free-Space QSDC section, the
estimate the communication performance by using the atmospheric channel consists of various gases and other
parameter setting derived from Micius satellite [85]. The suspended particles (e.g., aerosols, dust, smoke, etc). In
results indicate that this protocol has a better performance addition, weather variations such as rainfall, haze, snow, and
for satellite-to-ground communication. fog exist in the atmosphere. Both the absorption of light by gas
Fig. 12. Schema c diagram of free-space QSDC [24]. Reprinted/adapted with permission from Ref. [24] © The Chinese Laser
Press.
Experimental demonstra on molecules and Rayleigh scattering as well as Mie scattering of
The experimental implementation of free-space DL04 QSDC light [86] will attenuate the optical signal transmitted over the
was reported in 2020 [24], where the schematic is shown in atmospheric channel [87]. Choosing proper communication
Fig. 12. It achieved an information transmission rate of 500 wavelengths can reduce the impact of atmospheric absorption
bps over the 10-m free-space channel with a low QBER of and scatter in optical communication. The optical signal with
0.49% ± 0.27%. Based on the channel characteristics of free a wavelength of 1,550 nm has a higher transmittance over the
space and this experimental system, we will cover the issues, atmospheric channel than that of 810 nm [88]. Some results
including the selection of communication wavelength, coding show that the transmission of 1,550-nm photons over the
and decoding, photon-encoding strategy, and security analysis atmospheric channel with foggy and rainy weather is less lossy
in the next section. than transmitting 785-nm photons [89,90]. For instance, the
As shown in Fig. 12, the phase-encoding strategy is used by simulation results of Ref. [90] reported that 785-nm light
the experimental demonstration of free-space QSDC [24]. To suffers from a higher attenuation of 12.38 dB/km in light rain,
create 4 different phase-encoded quantum states, Bob whereas 1,550 nm has a lower attenuation of 6.27 dB/km.
randomly adds 1 of 4 phases {0, π/2, π, 3π/2} to each pulse Atmospheric scattering not only causes attenuation of
passing through the long arm. Alice has 2 optical paths, one is optical signals but also is a major cause of sky radiation,
devoted to checking security, and the other is applied to encode which is the scattering of solar photons as they travel through
information. As for eavesdropping detection, Alice will the atmosphere [87]. Sunlight is the background for the free-
modulate the pulse with 2 phases 0 or π/2 before detecting. In space QSDC system. It will become the noise source of the
another part of the optical path, she encodes information bits 0 communication system when sunlight is collected together
or 1 to each pulse by adding phase 0 or π, respectively. Finally, with the signal into the receiver for detection, which will
Bob decodes the information bits by modulating the phase of reduce the SNR of QSDC. The scattering of sunlight on the
returned pulses. link between the satellite and the ground is mainly because
Pan et al. 2023 | h ps://[Link]/10.34133/adi.0004 13
of Rayleigh scattering, which has a cross-sectional area of nm [91]. The divergence angles resulting from the
[89] transmitting telescope and the turbulence are proportional to
the wavelength λ in free-space quantum communication [92].
8𝜋3(n2−1)2 It means that the receiving end needs a larger-diameter
collecting telescope to reduce loss for the
𝜎= 24 , quantum communication via 1,550 nm. The experimental
(12) system shown in Fig. 12 adopts 1,550 nm as communication
3𝜌 m 𝜆 wavelength due to its various advantages.
where n is refractive index and ρm is the volumetric density Photon-encoding strategy
of the molecules. Obviously, Rayleigh scattering is The atmosphere channel has no birefringence effect for
proportional to 1/λ4. The background noise resulting from optical wavelengths and thus the polarization of the photon
sunlight in the 800-nm band is stronger than that in the 1,550- can be well maintained in free-space quantum
nm band [88]. The experiment test has revealed that the noise communication. A large number of free-space QKD have
count rate of 850 nm is 22.5 times larger than that of 1,550 been demonstrated, relying on polarization-encoding
nm when pointing a telescope at the sky [88]. As summarized schemes [93]. However, it is also worth exploring the
in Table 2, 1,550 nm as a communication wavelength has feasibility of free-space quantum communication based on
advantages in transmittance and reducing the effects of phase encoding. The polarization-encoding strategy is
weather and background noise. usually not the first choice for quantum communication over
Furthermore, the transceivers of the free space QSDC are optical fibers, since both the birefringence effect and
made of optical fiber devices, which are easy to integrate, dispersion effect of fiber would affect the transmission of
package, and maintain stability. Some mature optical fiber polarization quantum states. Phase encoding is a scheme
devices are set at 1,550 nm, which is an important factor for widely adopted by optical-fiber-based quantum
the practical application and commercialization of quantum communication. The advancement of free-space quantum
communication. Hence, 1,550 nm as communication communication based on phase encoding opens the door for
wavelength has an advantage in terms of compatibility with the construction of a simplified space–air–ground integrated
mature optical fiber devices. However, the single photons network. In such a network, there will be no need to lay both
with a wavelength of 800 nm are detected by Si avalanche polarization-encoding and phase-encoding communication
photodiodes, which have a higher detection efficiency over systems. The quantum state transmitted via a free-space
the single-photon detection at 1,550 nm using an InGaAs/InP channel can continue to be transmitted along the fiber after
avalanche photodiode. The detection efficiency of 800 nm coupling it into the fiber. This will enable direct access to the
typically reaches 50%, while it is only around 15% at 1,550
Table 2. Performance comparison of different communica on wavelengths. The marked wavelength is a be er op on than the other
one under the specific compara ve indicators.
Transmi ance Non-ideal weather Resis ng background noise
∼1,550 nm ✓ ✓ ✓
∼800 nm
Compa bility Detec on efficiency Divergence angle
∼1,550 nm ✓
∼800 nm ✓ ✓
Pan et al. 2023 | h ps://[Link]/10.34133/adi.0004 14
Fig. 13. The experimental implementa on of secure repeater by concatena ng fiber-based QSDC and free-space QSDC [27], reprinted with permission from IEEE. LAC,
network for mobile communication facilities and simplify coding of QSDC can be optimized considering channel
the interaction of free space and fiber. Otherwise, if a characteristics. For the turbulent atmospheric channel, a
mixture of polarization encoding and phase encoding is used dynamical and adaptive LDPC coding scheme may be more
in the network, the signal transmitted over a free-space appropriate [104]. A practical performance analysis of
channel has to be decoded and retransmitted to the optical- freespace QSDC should ponder the finite-size effect [38] and
fiber channel due to the change of the communication carrier the characteristics of the atmospheric channel [105–109]. The
and the communication equipment. Two sets of ability of eavesdroppers is in fact limited by the line-of-sight
communication equipment must be built at the same wiretap channel model [110] that describes free-space QSDC.
communication node in this scenario. Hence, the phase- As a consequence, a higher and more pragmatic secrecy
encoding free-space QSDC has the advantages of network capacity could be deduced in this relaxed condition.
flexibility and ease of deployment, once it becomes fully Feasibility of satellite-based QSDC
developed. The satellite-based QSDC has not yet been implemented. We
The classical bits are encoded onto the relative phase will discuss its feasibility on the basis of associated work. The
difference of 2 pulses in phase encoding and they would typical experiments of transmitting polarization-encoded and
interfere on the receiving side. Effective interference time-bin encoded quantum states between satellite and ground
depends on the phase difference of the 2 pulses, regardless are shown in Fig. 14. In 2015, an Italian group realized the
of their drastic changes of the wavefronts across the channel. transmission of polarization-encoding photons from satellite-
The asymmetric Mach–Zehnder interferometer is a to-ground link with a QBER of 4.6% [111], as shown in Fig.
frequently used infrastructure for realizing phase-encoding 14A. Subsequently, the Italian group demonstrated time-bin
strategy [94], which depends on the relative phase difference encoded qubits transmission over a ground–satellite–ground
between the early and late pulses [95]. These 2 pulses will be link, and they observed single-photon interference at a ground
transmitted from Alice to Bob over an atmospheric channel. station with a visibility up to 67% [97], as illustrated in Fig.
We should note that the time scales for turbulence-induced 14B. The distances of 2-way transmission ranged from 2,200
phase changing are on the order of 10 to 100 ms [96], while to 5,000 km in their experimental demonstration [97]. As seen
the bin width between the early and late pulses is typically in Fig. 14C, a Chinese group reported the transmission of
on the order of nanoseconds. Therefore, the phase of each polarization-encoded photons from geosynchronous
pulse would have an identical phase shift after passing Earthorbiting satellite to ground station in 2021. At a distance
through a turbulent atmosphere channel. They will cancel of more than 36,000 km, the link loss is between 100 and 110
each other in the relative phase difference and, hence, do not dB and the QBER of transmission is between 2% and 8%
affect the bit encoding. The bits could also be encoded onto [112]. These satisfied the security criteria of QKD and QSDC
the early and late pulses directly, and be decoded by [112]. All these experiments imply the feasibility of satellite-
measuring their time of arrival. Such a photon-encoding based QSDC.
strategy called time-bin encoding is more robust against Figure 15 gives an overview of the application scenarios of
errors caused by the turbulent atmosphere. Some works have the QSDC protocols introduced in the Basic Principle and
shown that time-bin or phase-encoding qubits are a good fit Typical Protocols section for satellite-to-ground
for free-space transmission [24,97–102]. communication. The DL04 QSDC protocol and QLPI protocol
Note that the same phase-encoding QSDC terminal can achieve secret information transmission from Alice to Bob
transmit secret information through either fiber [22] or after finishing a round-trip transmission of qubits between Bob
freespace [24] channel. Phase-encoding QSDC is used in the 2 and Alice, as shown in Fig. 15A. Hence, their satellite-to-
transmission segments in a secure repeater network [27]. In ground QSDC requires satellite uplink and downlink. Observe
practice, there is the flexibility to choose all phase encoding or in Fig. 15B that twice satellite downlink is necessary for
phase and time-bin encoding in quantum network satellite-to-ground QSDC relying on the efficient protocol. In
configurations according to the specific network services comparison, the RECON protocol and QKPC protocol only
requirements. By combining optical switches [103], the secure require a downlink channel in satellite-to-ground
repeater network [27] is capable of realizing the multiuser’s communication, as shown in Fig. 14C. Surprisingly, the QKPC
wide-area information interchange using existing technology. protocol showed better performance over the BB84 QKD in
terms of rate and noise resistance in all cases of low, medium,
Novel free-space QSDC protocols and geostationary earth orbits [44].
The design of novel free-space QSDC protocols helps to The comparison shows that the channel attenuation of the
produce an excellent QSDC system with low hardware DL04 protocol, QLPI protocol, and efficient protocol have
complexity and high secrecy capacity. The traditional 2-way double that of the RECON protocol and QKPC protocol,
QSDC protocols [10,14,15] have exhibited difficulty in which makes their implementation challenging in the
improving communication distance for fiber-based scenario of satellite– ground communication. For instance,
communications [21,25,26]. This is also the case for free the interference visibility of pioneering work [97] must be
space. One solution is to design a one-way QSDC protocol, improved drastically so as to achieve DL04 QSDC, because
where the protocols in Refs. [19, 43,44] deserve more the QBER could be estimated by QBER = (1−)∕2 [24,113],
attention. The desired protocol has to satisfy the following where is the interference visibility, whereas the 2-way
requirements: no need for quantum memory, no information QSDC protocol is an efficient secure communication without
leakage, and eavesdropping detection in real time. Toward basis comparison, and this protocol may be probably good
secure and reliable communication, secure coding, FEC for short-range connections at the ground.
coding, and better security analysis are also of interest. FEC
Pan et al. 2023 | h ps://[Link]/10.34133/adi.0004 15
Outlook Long-distance free-space QSDC
Free-space QSDC is still in its infancy. There remains much Atmospheric extinction, diffraction, turbulence, pointing error,
work to be done before free-space and satellite-to-ground and background noise of free-space channels will endanger the
QSDC becomes practical. We will discuss some directions
for future research in the field of free-space QSDC in this
section.
Fig. 14. Overview of the experimental demonstra ons of qubits transmission between satellite and ground. (A) Transmission of photonic polariza on states [111],
reprinted with permission from the American Physical Society. (B) Transmission of photonic me-bin states [97], reprinted with permission from the American Physical
Society. (C) Transmission of photonic polariza on states [112], reprinted with permission from John Wiley and Sons.
Alice Alice Alice
Bob Bob Bob
A B C
Fig. 15. Comparison of satellite-to-ground QSDC based on some specific protocols: (A) the DL04 protocol and QLPI protocol; (B) the efficient protocol; and (C) the RECON
protocol and QKPC protocol. communication in the presence of deviations existing in the
reference frames of both communicating parties.
transmission of secret information. Information transmission Space-to-ground integrated QSDC network
is susceptible to loss and distortion in the face of various It is an ambitious long-term goal to develop QSDC into
losses and noise. The implementation of long-distance free- practical applications by building a space–air–ground–sea
space QSDC requires better coding and decoding schemes integrated QSDC network. All the satellites, drones, ships,
and acquiring, pointing, and tracking (APT) technologies. In terrestrial optical networks [22,25–27,118], peer-to-peer
the terrestrial network, free-space QSDC terminals with the atmospheric channels [24], and mobile platforms are the key
capability for long-distance communication can be a components of QSDC. A first step has been taken to simplify
complementary means of secure communication to fiber- the direct interaction between free space and optical fiber by
optic communication. It increases the service capacity of means of phase-encoded QSDC [24]. However, this solution
communication while reducing the traffic load of fiber requires a high matching of interferometers for different
network without expanding its infrastructure [114]. QSDC terminators.
Mobile-pla orm-based QSDC CAID QSDC
The mobile-platform-based QSDC via free-space links, such We propose a scheme that serves to facilitate faster application
as satellites, drones, ships, vehicles, and so on, could be a development of QSDC in this subsection. This scheme is easy
flexible and fast configurable means of secure to implement and it is applicable to both fiber- and free-
communication. One of the challenges in satellite-based spacebased QSDC.
QSDC is the background noise resulting from the scattered Quantum cryptography and quantum communications can
sunlight that would be collected by a large telescope together theoretically achieve unconditionally secure communications.
with the quantum signal. The SNR of communication will be However, unconditional security is difficult to achieve due to
decreased. It requires that solutions for all-day QSDC are the imperfections of practical devices. There are specific
found. Taking the QKD as an example, its satellite can only attacks on the actual components of quantum-secured
work at nighttime [85]. Entanglement distribution between 2 information transmission systems [91,119]. It is difficult and
ground locations via drones [115,116] lays the foundation for time-consuming to characterize all security loopholes that
drone-based QSDC [10,14,67]. The difficulty here is the result from imperfect devices and remove them. Some
development of a precise, rapid, and stable APT module as protocols that try to balance security and practicability, such as
well as the miniaturization of the QSDC module. Similar to the MDI protocol [55,56 ,120–125] and twin field protocol
QKD, mobile-platform-based QSDC has a calibration [126,127], have been proposed. However, the MDI protocol
requirement of reference [117]. Designing the reference- also has security problems arising from imperfect light
frame-independent protocol will enable secure and reliable sources. Finally, one tends to place their hopes on DI protocols
Pan et al. 2023 | h ps://[Link]/10.34133/adi.0004 16
[63,128,129], which is quite hard to implement level of communication security by combining with classical
experimentally. Such a development path would hardly allow cryptography or post-quantum cryptography. Given the
for practical applications of quantum cryptography and quantum nature of communication of QSDC, it will provide a
quantum communication in the near future. way of quantum interconnection in the future quantum Internet
The ability of the eavesdropper Eve is assumed to be only [27,130–133].
limited by quantum mechanics. Meanwhile, Eve’s powerful
attacks are difficult to achieve with the existing technology.
For example, the QSDC protocol based on quantum data
Acknowledgments
locking was established considering that there is no quantum Funding: This work was supported by the National Natural
memory for Eve to store quantum information for an Science Foundation of China [grant numbers 12205011 and
arbitrarily long time [19]. Such protocols have their realistic 11974205]; the Open Research Fund Program of the State Key
security for secure communication with realistic constraints on Laboratory of Low-Dimensional Quantum Physics [grant
Eve’s attack capability. number KF202205]; the Key R&D Program of Guangdong
Here, we advocate the CAID QSDC. This developing route province [grant number 2018B030325002]; Beijing Advanced
for QSDC does not have to wait for QSDC to be Innovation Center for Future Chip (ICFC); and Tsinghua
unconditionally secure before pushing it to practical University Initiative Scientific Research Program. Author
applications. In a secure repeater scheme [27], classical post- contributions: D.P., X.-T.S., and G.-L.L. wrote the
quantum cryptography helps to achieve end–end security of manuscript together. G.-L.L. supervised the project.
the quantum network. Communication users of secure repeater Competing interests: The authors declare that they have no
networks use QSDC to transmit information encrypted by competing interests.
classical cryptography or post-quantum cryptography. Here,
using CAID QSDC, information transmission is doubly Data Availability
protected by both quantum and classical approaches. When
All data are presented in the paper. Please contact G.L.L. for
QSDC is employed for secure communication, one can
additional information.
combine QSDC using imperfect devices with classical
cryptography or post-quantum cryptography, wherein using References
QSDC transmits the ciphertext encrypted by classical 1. Shor PW. Algorithms for quantum computation: Discrete
cryptography or post-quantum cryptography. For classical logarithms and factoring. Paper presented at IEEE: Proceedings
cryptography, CAID-QSDC deprives Eve’s capability to of the 35th Annual Symposium on Foundations of Computer
access the ciphertext; hence, there is no “store now, decrypt Science; 1994 Nov 20–22; Santa Fe, NM.
later” worry anymore. In QSDC with imperfect devices, 2. Rivest RL, Shamir A, Adleman L. A method for obtaining
classical cryptography provides an assurance of the security of digital signatures and public-key cryptosystems. Commun
information if QSDC fails in the very unlikely case. Hence, ACM. 1978;21(2):120–126.
CAID-QSDC will provide the highest security with existing 3. Grover LK, A fast quantum mechanical algorithm for database
technology. search. Paper presented at: Proceedings of The Twenty-Eighth
This developing route is extremely easy to implement Annual ACM Symposium on Theory of Computing ACM;
thanks to QSDC’s compatibility with existing classic 1996 July; Philadelphia, PA.
networks. The cryptographic layer of a confidential 4. Long G-L. Grover algorithm with zero theoretical failure rate.
communication system can continue to be strengthened, such Phys Rev A. 2001;64(2):022307.
as upgrading to post-quantum cryptography. By replacing the 5. Daemen J, Rijmen V. AES proposal: Rijndael. Paper presented
communication modules in the classical network with QSDC at: First Advanced Encryption Standard (AES) Conference;
modules or adding deployments, quantum-enhanced Aug 1998; Ventura, CA.
confidential communications can be achieved noninductively 6. Wang Z, Wei S, Long G-L, Hanzo L. Variational quantum
for communication users. Hence, the CAID QSDC can be attacks threaten advanced encryption standard based symmetric
quickly applied in real life right now. cryptography. Sci China Inf Sci. 2022;65(10):200503.
7. Vernam GS. Secret signaling system. U.S. Patent, July 22,
Conclusions 1919, uS1310719A.
We have introduced the basic principle of QSDC using 8. Bennett CH, Brassard G. Quantum cryptography: Public key
representative protocols in a step-by-step manner. The distribution and coin tossing. Paper presented at: Proceedings
mechanisms of QSDC for resisting channel noise, loss, and of the IEEE International Conference on Computers, Systems
eavesdropping, as well as its provable information-theoretic and Signal Processing; 1984 Dec; Bangalore, India.
security, are also highlighted. Considering the compelling 9. Kwek L-C, Cao L, Luo W, Wang Y, Sun S, Wang X, Liu AQ.
application prospects of free-space communications, we Chip-based quantum key distribution. AAPPS Bull. 2021;31:15.
overviewed the theoretical and experimental progress of free- 10. Long G-L, Liu X-S. Theoretically efficient high-capacity
space QSDC. Furthermore, the experimental demonstrations quantum-key-distribution scheme. Phys Rev A.
of transmitting encoded qubits between satellites and ground 2002;65(3):032302.
have suggested the feasibility of satellite-based QSDC. As 11. Bennett CH, Brassard G, Crépeau C, Jozsa R, Peres A,
long as the control hardwares that execute the QSDC protocol Wootters WK. Teleporting an unknown quantum state via dual
are added to these satellites, the satellite-to-ground QSDC can classical and Einstein-Podolsky-Rosen channels. Phys Rev
be realized. QSDC has shown its maturity for practical Lett. 1993;70(13):1895–1899.
applications, especially the fact that it could achieve a higher
Pan et al. 2023 | h ps://[Link]/10.34133/adi.0004 17
12. Hillery M, Bužek V, Berthiaume A. Quantum secret sharing. technologies, and new paradigm shifts. Sci China Inf Sci.
Phys Rev A. 1999;59(3):1829–1834. 2021;64:110301.
13. Xiao L, Long GL, Deng F-G, Pan J-W. Efficient multiparty 31. Krelina M. Quantum technology for military applications.
quantum-secret-sharing schemes. Phys Rev A. EPJ Quantum Technol. 2021;8:24.
2004;69(5):052307. 32. Schmitt-Manderbach T, Weier H, Fürst M, Ursin R,
14. Deng F-G, Long GL, Liu X-S. Two-step quantum direct Tiefenbacher F, Scheidl T, Perdigues J, Sodnik Z, Kurtsiefer
communication protocol using the Einstein-Podolsky-Rosen C, Rarity JG, et al. Experimental demonstration of free-space
pair block. Phys Rev A. 2003;68(4):042317. decoy-state quantum key distribution over 144 km. Phys Rev
15. Deng F-G, Long GL. Secure direct communication with a Lett. 2007;98(1):010504.
quantum one-time pad. Phys Rev A. 2004;69(5):052319. 33. Pesek P, Zvánovec S, Chvojka P, Ghassemlooy Z, Haigh PA.
16. Wang C, Deng F-G, Li Y-S, Liu X-S, Long GL. Quantum Demonstration of a hybrid FSO/VLC link for the last mile
secure direct communication with high-dimension quantum and last meter networks. IEEE Photonics J.
superdense coding. Phys Rev A. 2005;71(4):044305. 2018;11(1):7900307. 34. Abadi MM, Ghassemlooy Z,
17. Wang C, Deng FG, Long GL. Multi-step quantum secure direct Mohan N, Zvanovec S, Bhatnagar MR, Hudson R.
communication using multi-particle Green–Horne– Zeilinger Implementation and evaluation of a gigabit ethernet FSO link
state. Opt Commun. 2005;253(1-3):15–20. for ’the last metre and last mile access network’. Paper
18. Hu J-Y, Yu B, Jing M-Y, Xiao L-T, Jia S-T, Qin G-Q, Long G- presented at: IEEE: Proceedings of the 2019 IEEE
L. Experimental quantum secure direct communication with International Conference on Communications Workshops
single photons. Light Sci Appl. 2016;5:e16144. (ICC Workshops); 2019 May 20–24; Shanghai, China.
19. Lum DJ, Howell JC, Allman M, Gerrits T, Verma VB, 35. Wyner AD. The wire-tap channel. Bell Syst Tech J.
Nam SW, Lupo C, Lloyd S. Quantum enigma machine: 1975;54(8):1355–1387.
Experimentally demonstrating quantum data locking. 36. Wu J, Lin Z, Yin L, Long G-L. Security of quantum secure
Phys Rev A. 2016;94(2):022315. direct communication based on Wyner’s wiretap channel
20. Zhang W, Ding D-S, Sheng Y-B, Zhou L, Shi B-S, Guo G-C. theory. Quantum Eng. 2019;1(4):e26.
Quantum secure direct communication with quantum memory. 37. Ye Z-D, Pan D, Sun Z, Du C-G, Yin L-G, Long G-L. Generic
Phys Rev Lett. 2017;118(22):220501. security analysis framework for quantum secure direct
21. Zhu F, Zhang W, Sheng Y, Huang Y. Experimental longdistance communication. Front Phys. 2021;16:21503.
quantum secure direct communication. Sci Bull. 38. Wu J, Long G-L, Hayashi M. Quantum secure direct
2017;62(22):1519–1524. communication with private dense coding using a general
22. Qi R, Sun Z, Lin Z, Niu P, Hao W, Song L, Huang Q, Gao J, preshared quantum state. Phys Rev Appl. 2022;17(6):064011.
Yin L, Long G-L. Implementation and security analysis of 39. Sun Z, Song L, Huang Q, Yin L, Long G, Lu J, Hanzo L.
practical quantum secure direct communication. Light Sci Appl. Toward practical quantum secure direct communication: A
2019;8:22. quantum-memory-free protocol and code design. IEEE Trans
23. Massa F, Moqanaki A, Baumeler Ä, Del Santo F, Kettlewell Commun. 2020;68(9):5778–5792.
JA, Dakić B, Walther P. Experimental two-way communication 40. Yang L, Wu J, Lin Z, Yin L, Long G. Quantum secure direct
with one photon. Adv Quantum Technol. 2019;2(11):1900050. communication with entanglement source and single-photon
24. Pan D, Lin Z, Wu J, Zhang H, Sun Z, Ruan D, Yin L, Long measurement. Sci China Phys Mech Astron.
GL. Experimental free-space quantum secure direct 2020;63(11):110311. 41. Liu X, Li Z, Luo D, Huang C, Ma
communication and its security analysis. Photonics Res. D, Geng M, Wang J, Zhang Z, Wei K. Practical decoy-state
2020;8(9):1522–1531. quantum secure direct communication. Sci China Phys Mech
25. Qi Z, Li Y, Huang Y, Feng J, Zheng Y, Chen X. A 15-user Astron. 2021;64(12):120311.
quantum secure direct communication network. Light Sci 42. Qi R, Zhang H, Gao J, Yin L, Long G-L. Loophole-free plug-
Appl. 2021;10:183. and-play quantum key distribution. New J Phys.
26. Zhang H, Sun Z, Qi R, Yin L, Long G-L, Lu J. Realization of 2021;23(6):063058.
quantum secure direct communication over 100 km fiber 43. Deng F-G, Long GL, Repeatable classical one-time-pad
with time-bin and phase quantum states. Light Sci Appl. crypto-system with quantum mechanics. arXiv. 2019.
2022;11:83. [Link]
27. Long G-L, Pan D, Sheng Y-B, Xue Q, Lu J, Hanzo L. An 44. Vázquez-Castro A, Rusca D, Zbinden H. Quantum keyless
evolutionary pathway for the quantum internet relying on private communication versus quantum key distribution for
secure classical repeaters. IEEE Netw. 2022;36(3):82–88. space links. Phys Rev Appl. 2021;16(1):014006.
28. Liu X, Luo D, Lin G, Chen Z, Huang C, Li S, Zhang C, 45. Del Santo F, Dakić B. Two-way communication with a single
Zhang Z, Wei K. Fiber-based quantum secure direct quantum particle. Phys Rev Lett. 2018;120(6):060503.
communication without active polarization compensation. Sci 46. Chen S-S, Zhou L, Zhong W, Sheng Y-B. Three-step
China Phys Mech Astron. 2022;65(12):120311. threeparty quantum secure direct communication. Sci China
29. Kania EB, Costello JK. Quantum hegemony? China’s Phys Mech Astron. 2018;61(9):090312.
ambitions and the challenge to U.S. innovation leadership. 47. Li T, Long G-L. Quantum secure direct communication based
Washington, DC: Center for New American Security; 2018. on single-photon Bell-state measurement. New J Phys.
30. You X, Wang C-X, Huang J, Gao X, Zhang Z, Wang M, 2020;22(6):063017.
Huang Y, Zhang C, Jiang Y, Wang J, et al. Towards 6G 48. Chandra D, Cacciapuoti AS, Caleffi M, Hanzo L. Direct
wireless communication networks: Vision, enabling quantum communications in the presence of realistic noisy
entanglement. IEEE Trans Commun. 2021;70(1):469–484.
Pan et al. 2023 | h ps://[Link]/10.34133/adi.0004 18
49. Gao C-Y, Guo P-L, Ren B-C. Efficient quantum secure direct communication relying on Einstein-Podolsky-Rosen pairs.
communication with complete Bell-state measurement. IEEE Access. 2020;8:121146–121161.
Quantum Eng. 2021;3(4):e83. 68. Cao Y, Zhao Y, Wang Q, Zhang J, Ng SX, Hanzo L. The
50. Sheng Y-B, Zhou L, Long G-L. One-step quantum secure evolution of quantum key distribution networks: On the road
direct communication. Sci Bull. 2022;67(4):367–374. to the Qinternet. IEEE Commun Surv Tutor. 2022;24(2):839–
51. Shapiro JH, Boroson DM, Dixon PB, Grein ME, Hamilton 894.
SA. 69. Kiktenko EO, Trushechkin AS, Lim CCW, Kurochkin YV,
Quantum low probability of intercept. J Opt Soc Am B. Fedorov AK. Symmetric blind information reconciliation for
2019;36(3):B41–B50. quantum key distribution. Phys Rev Appl. 2017;8(4):044017.
52. Cao Z, Wang L, Liang K, Chai G, Peng J. Continuous- 70. Harrison WK, Almeida J, Bloch MR, McLaughlin SW, Barros
variable quantum secure direct communication based on J. Coding for secrecy: An overview of error-control coding
Gaussian mapping. Phys Rev Appl. 2021;16(2):024012. techniques for physical-layer security. IEEE Signal Process
53. Shapiro JH, Zhang Z, Wong FN. Secure communication via Mag. 2013;30(5):41–50.
quantum illumination. Quantum Inf Process. 71. Zhou H, Tang B-Y, Li S-C, Yu W-R, Chen H, Yu H-C, Liu B.
2014;13(10):2171–2193. Appending information reconciliation for quantum key
54. Zhuang Q, Zhang Z, Dove J, Wong FN, Shapiro JH. distribution. Phys Rev Appl. 2022;18(4):044022.
Ultrabroadband quantum-secured communication. 72. Chen C. Linear dependencies in linear feedback shift
arXiv.2015. [Link] registers. IEEE Comput Archit Lett. 1986;35(12):1086–1088.
55. Zhou Z, Sheng Y, Niu P, Yin L, Long G, Hanzo L. 73. Tyagi H, Vardy A. Universal hashing for informationtheoretic
Measurement-device-independent quantum secure direct security. Proc IEEE. 2015;103(10):1781–1795.
communication. Sci China Phys Mech Astron. 74. Sun Z, Qi R, Lin Z, Yin L, Long G, Lu J. Design and
2020;63(3):230362. implementation of a practical quantum secure direct
56. Niu P-H, Zhou Z-R, Lin Z-S, Sheng Y-B, Yin L-G, Long G-L. communication system. Paper presented at: IEEE:
Measurement-device-independent quantum communication Proceedings of the 2018 IEEE Globecom Workshops (GC
without encryption. Sci Bull. 2018;63(20):1345–1350. Wkshps); 2018 Dec 9–13; Abu Dhabi, United Arab Emirates.
57. Niu P-H, Wu J-W, Yin L-G, Long G-L. Security analysis of 75. Long G-L, Zhang H. Drastic increase of channel capacity in
measurement-device-independent quantum secure direct quantum secure direct communication using masking. Sci
communication. Quantum Inf Process. 2020;19:356. Bull. 2021;66(13):1267–1269.
58. Gao Z, Li T, Li Z. Long-distance measurement-device– 76. Hosseinidehaj N, Babar Z, Malaney R, Ng SX, Hanzo L.
independent quantum secure direct communication. Satellite-based continuous-variable quantum communications:
Europhys Lett. 2019;125(4):40004. State-of-the-art and a predictive outlook. IEEE Commun Surv
59. Liu L, Niu J-L, Fan C-R, Feng X-T, Wang C. Tutor. 2018;21(1):881–919.
Highdimensional measurement-device-independent quantum 77. Pirandola S. Limits and security of free-space quantum
secure direct communication. Quantum Inf Process. communications. Phys Rev Res. 2021;3(1):013279.
2020;19:404. 78. Gao Z, Ma M, Liu T, Long J, Li T, Li Z. Free-space quantum
60. Zou Z-K, Zhou L, Zhong W, Sheng Y-B. secure direct communication based on decoherence-free
Measurementdevice–independent quantum secure direct space. J Opt Soc Am B. 2020;37(10):3028–3033.
communication of multiple degrees of freedom of a single 79. Yuan R, Cheng J. Free-space optical quantum
photon. Europhys Lett. 2020;131(4):40005. communications in turbulent channels with receiver diversity.
61. Ying J-W, Zhou L, Zhong W, Sheng Y-B. IEEE Trans Commun. 2020;68(9):5706–5717.
Measurementdevice-independent one-step quantum secure 80. Niu J, Liu X-C. The analysis of efficiency for
direct communication. Chin Phys B. 2022;31(12):120303. highdimensional quantum secure direct communications
62. Li X-J, Pan D, Long G-L, Hanzo L. Single-photon-memory under atmospheric turbulence. Europhys Lett.
measurement-device-independent quantum secure direct 2022;139(3):38001.
communication. arXiv. 2022. 81. Zhu K, Lin Z, Yin L, Wang C, Long G. Entanglement
[Link] protection of Ince-Gauss modes in atmospheric turbulence
63. Zhou L, Sheng Y-B, Long G-L. Device-independent quantum using adaptive optics. Opt Express. 2020;28(25):38366–
secure direct communication against collective attacks. Sci 38375.
Bull. 2020;65(1):12–20. 82. Zhu K, Yin L, Wang C, Long G. Protecting the orbital angular
64. Zhou L, Xu B-W, Zhong W, Sheng Y-B. Device-independent momentum of photonic qubits using quantum error correction.
quantum secure direct communication with single-photon Europhys Lett. 2021;132(5):50005.
sources. Phys Rev Appl. 2023;19(1):014036. 83. Mi S, Wang T-j, Jin G-s, Wang C. High-capacity quantum
65. Wen K, Deng F-G, Long GL. Reusable vernam cipher with secure direct communication with orbital angular momentum
quantum media. arXiv. 2007. of photons. IEEE Photonics J. 2015;7(5):7600108.
[Link] 84. Lindsey WC. Transmission of classical information over
66. Yin L, Pan D, Long G-L. Quantum secure direct noisy quantum channels—A spectrum approach. IEEE J Sel
communication: A survey of basic principle and recent Areas Commun. 2020;38(3):427–438.
development. J Fiz Malaysia. 2018;39(2):10001–10006. 85. Liao S-K, Cai W-Q, Liu W-Y, Zhang L, Li Y, Ren J-G, Yin J,
67. Pan D, Li K, Ruan D, Ng SX, Hanzo L. Single- Shen Q, Cao Y, Li Z-P, et al. Satellite-to-ground quantum key
photonmemory two-step quantum secure direct distribution. Nature. 2017;549(7670):43–47.
Pan et al. 2023 | h ps://[Link]/10.34133/adi.0004 19
86. Bao X, Wang Y. Recent advancements in rayleigh scattering- 104. López-Leyva JA, Arvizu-Mondragon A, Santos-Aguilar J,
based distributed fiber sensors. Adv Dev Instrum. Ramos-Garcia R. Improved performance of the cryptographic
2021;2021:8696571. key distillation protocol of an FSO/CV-QKD system on a
87. Kaushal H, Jain V, Kar S. Free space optical communication. turbulent channel using an adaptive LDPC encoder. Rev Mex
New Delhi, India: Springer; 2017. Fís.
88. Liao S-K, Yong H-L, Liu C, Shentu G-L, Li D-D, Lin J, Dai 2017;63(3):268–274.
H, Zhao S-Q, Li B, Guan J-Y, et al. Long-distance free-space 105. Vasylyev DY, Semenov A, Vogel W. Toward global quantum
quantum key distribution in daylight towards inter-satellite communication: Beam wandering preserves nonclassicality.
communication. Nat Photonics. 2017;11(8):509–514. Phys Rev Lett. 2012;108(22):220501.
89. Alkholidi AG, Altowij KS. Free space optical 106. Vasylyev D, Semenov A, Vogel W. Atmospheric quantum
communications—Theory and practices. In: Khatib M, editor. channels with weak and strong turbulence. Phys Rev Lett.
Contemporary issues in wireless communications. Rijeka: 2016;117(9):090501.
IntechOpen; 2014. Chapter 5. 107. Vasylyev D, Semenov A, Vogel W, Günthner K, Thurn A,
90. Fadhil HA, Amphawan A, Shamsuddin HA, Abd TH, Al- Bayraktar Ö, Marquardt C. Free-space quantum links under
Khafaji HM, Aljunid S, Ahmed N. Optimization of free space diverse weather conditions. Phys Rev A. 2017;96(4):043856.
optics parameters: An optimum solution for bad weather 108. Vasylyev D, Vogel W, Semenov A. Theory of atmospheric
conditions. Optik. 2013;124(19):3969–3973. quantum channels based on the law of total probability. Phys
91. Lo H-K, Curty M, Tamaki K. Secure quantum key Rev A. 2018;97(6):063852.
distribution. Nat Photonics. 2014;8:595–604. 109. Vasylyev D, Vogel W, Moll F. Satellite-mediated quantum
92. Aspelmeyer M, Jennewein T, Pfennigbauer M, Leeb WR, atmospheric links. Phys Rev A. 2019;99(5):053830.
Zeilinger A. Long-distance quantum communication with 110. Pan Z, Seshadreesan KP, Clark W, Adcock MR, Djordjevic
entangled photons using satellites. IEEE J Sel Top Quantum IB, Shapiro JH, Guha S. Secret-key distillation across a
Electron. 2003;9(6):1541–1551. quantum wiretap channel under restricted eavesdropping.
93. Xu F, Ma X, Zhang Q, Lo H-K, Pan J-W. Secure quantum key Phys Rev Appl. 2020;14(2):024044.
distribution with realistic devices. Rev Mod Phys. 111. Vallone G, Bacco D, Dequal D, Gaiarin S, Luceri V, Bianco
2020;92(2):025002. G, Villoresi P. Experimental satellite quantum
94. Li X, Wang L-L, Zhang J-s, Chen W, Wang Y, Wu D, An J-M. communications.
Quantum key distribution transmitter chip based on Phys Rev Lett. 2015;115(4):040502.
hybridintegration of silica and lithium niobates. Chin Phys B. 112. Wang X-f, Sun X-j, Liu Y-x, Wang W, Kan B-x, Dong P, Zhao
2022;31(6):064212. L-l. Transmission of photonic polarization states from
95. Ham BS. A nonclassical Sagnac interferometer using geosynchronous earth orbit satellite to the ground. Quantum
coherence de Broglie waves. Adv Dev Instrum. Eng. 2021;3(3):e73.
2021;2021:9862831. 113. Scarani V, Bechmann-Pasquinucci H, Cerf NJ, Dušek M,
96. Gisin N, Ribordy G, Tittel W, Zbinden H. Quantum Lütkenhaus N, Peev M. The security of practical quantum key
cryptography. Rev Mod Phys. 2002;74(1):145–195. distribution. Rev Mod Phys. 2009;81(3):1301–1350.
97. Vallone G, Dequal D, Tomasin M, Vedovato F, Schiavon M, 114. Aburakawa Y, Otsu T, Yamao Y. Fiber and free-space hybrid
Luceri V, Bianco G, Villoresi P. Interference at the single optical networking for new generation mobile radio access
photon level along satellite-ground channels. Phys Rev Lett. network. Paper presented at: IEEE: Proceedings of the 5th
2016;116(25):253601. International Symposium on Wireless Personal Multimedia
98. Jin J, Agne S, Bourgoin J-P, Zhang Y, Lütkenhaus N, Communications; 2002 Oct 27–30; Honolulu, HI.
Jennewein T. Demonstration of analyzers for multimode 115. Liu H-Y, Tian X-H, Gu C, Fan P, Ni X, Yang R, Zhang J-N,
photonic time-bin qubits. Phys Rev A. 2018;97(4):043847. Hu M, Guo J, Cao X, et al. Drone-based entanglement
99. Cahall C, Islam NT, Gauthier DJ, Kim J. Multimode distribution towards mobile quantum networks. Natl Sci Rev.
timedelay interferometer for free-space quantum 2020;7(5):921–928.
communication. 116. Liu H-Y, Tian X-H, Gu C, Fan P, Ni X, Yang R, Zhang J-N,
Phys Rev Appl. 2020;13(2):024047. Hu M, Guo J, Cao X, et al. Optical-relayed entanglement
100. Jin J, Bourgoin J-P, Tannous R, Agne S, Pugh CJ, Kuntz KB, distribution using drones as mobile nodes. Phys Rev Lett.
Higgins BL, Jennewein T. Genuine time-bin-encoded 2021;126(2):020503.
quantum key distribution over a turbulent depolarizing 117. Laing A, Scarani V, Rarity JG, O’Brien JL. Referenceframe-
freespace channel. Opt Express. 2019;27(26):37214–37223. independent quantum key distribution. Phys Rev A.
101. Chen H, Wang J, Tang B, Li Z, Liu B, Sun S. Field 2010;82(1):012304.
demonstration of time-bin reference-frame-independent 118. Paparelle I, Paris M, Zavatta A. Implementation and security
quantum key distribution via an intracity free-space link. analysis of continuous variable quantum secure direct
Opt Lett. 2020;45(11):3022–3025. communication protocols. Il Nuovo Cimento C. 2022;45(6):1–
102. Sajeed S, Jennewein T. Observing quantum coherence from 4.
photons scattered in free-space. Light Sci Appl. 2021;10:121. 119. Huang A, Barz S, Andersson E, Makarov V. Implementation
103. Niu P-H, Zhang F-H, Chen X-W, Wang M, Long G-L. QNUS: vulnerabilities in general quantum cryptography. New J Phys.
Reducing terminal resources in quantum secure direct 2018;20(10):103016.
communication network using switches. Quantum Eng. 120. Braunstein SL, Pirandola S. Side-channel-free quantum key
2022;2022:6345981. distribution. Phys Rev Lett. 2012;108(13):130502.
Pan et al. 2023 | h ps://[Link]/10.34133/adi.0004 20
121. Lo H-K, Curty M, Qi B. Measurement-deviceindependent
quantum key distribution. Phys Rev Lett.
2012;108(13):130503.
122. Pan D, Ng SX, Ruan D, Yin L, Long G, Hanzo L.
Simultaneous two-way classical communication and
measurement-device-independent quantum key distribution
with coherent states. Phys Rev A. 2020;101(1):012343.
123. Fan-Yuan G-J, Lu F-Y, Wang S, Yin Z-Q, He D-Y, Zhou Z,
Teng J, Chen W, Guo G-C, Han Z-F. Measurement-
deviceindependent quantum key distribution for
nonstandalone networks. Photonics Res. 2021;9(10):1881–
1891.
124. Tang G-Z, Li C-Y, Wang M. Polarization discriminated time-
bin phase-encoding measurement-deviceindependent quantum
key distribution. Quantum Eng.
2021;3(4):e79.
125. Fan-Yuan G-J, Lu F-Y, Wang S, Yin Z-Q, He D-Y, Chen W,
Zhou Z, Wang Z-H, Teng J, Guo G-C, et al. Robust and
adaptable quantum key distribution network without trusted
nodes. Optica. 2022;9(7):812–823.
126. Lucamarini M, Yuan ZL, Dynes JF, Shields AJ. Overcoming
the rate–distance limit of quantum key distribution without
quantum repeaters. Nature.
2018;557(7705):400–403.
127. Wang S, Yin Z-Q, He D-Y, Chen W, Wang R-Q, Ye P, Zhou Y,
Fan-Yuan G-J, Wang F-X, Chen W, et al. Twin-field quantum
key distribution over 830-km fibre. Nat Photonics.
2022;16(2):154–161.
128. Acín A, Brunner N, Gisin N, Massar S, Pironio S, Scarani V.
Device-independent security of quantum cryptography against
collective attacks. Phys Rev Lett.
2007;98(23):230501.
129. Zhou L, Sheng Y-B. One-step device-independent quantum
secure direct communication. Sci China Phys Mech Astron.
2022;65(5):250311.
130. Kimble HJ. The quantum internet. Nature.
2008;453(7198):1023–1030.
131. Illiano J, Caleffi M, Manzalini A, Cacciapuoti AS. Quantum
internet protocol stack: A comprehensive survey. Comput
Netw. 2022;213:109092.
132. Zhang H, Li Y, Zhang C, Huang T. Connection-oriented and
connectionless quantum internet considering quantum
repeaters. arXiv. 2022.
[Link]
133. Cao Y, Zhao Y, Zhang J, Wang Q, Niyato D, Hanzo L. From
single-protocol to large-scale multi-protocol quantum
networks. IEEE Netw. 2022;36(5):14–22.
Pan et al. 2023 | h ps://[Link]/10.34133/adi.0004 21