Device-Independent QKD Closer to Real-World Deployment
17 August 2026
Researchers Michele Masini and Shubhayan Sarkar, from the Laboratoire d’Information Quantique at the Université libre de Bruxelles and the University of Gdańsk, have published a new result in New Journal of Physics that tackles one of the most stubborn obstacles in quantum key distribution (QKD): the trade-off between security guarantees and the detection efficiency required to make a protocol practical.
Their paper addresses a well-known dilemma in the field. Fully device-independent (DI) QKD offers the strongest possible security guarantees, a secret key whose safety relies only on the laws of quantum mechanics, with no need to trust the internal workings of the hardware. But this comes at a high price: DI protocols demand detection efficiencies that today’s best superconducting detectors, even cooled to cryogenic temperatures, struggle to reach, and they are extremely sensitive to photon loss over distance.
A middle ground with a theoretical edge
The authors work in a “one-sided” device-independent (1SDI) scenario, where one party’s measurement device (call it Alice’s) is trusted, while the other party’s device (Bob’s) and the source of quantum states remain completely untrusted. This setting, based on quantum steering, resembles a common real-world situation: a user connecting to a server. The server, run by an organization with the resources to test and certify its equipment, can be reasonably trusted, however, the user’s device, potentially compromised, cannot.
Within this framework, the study resolves three open questions that had persisted in nonlocality-based QKD. First, it shows that when each party uses only two measurement settings (the minimal number needed to observe steering or nonlocality) a secure key can be extracted with a detection efficiency on the untrusted side as low as 50.1%. This is, in practice, the theoretical floor: it is already known that no protocol using two untrusted measurements can be secure below a 50% threshold, so the result is optimal. Previous 1SDI protocols fell well short of this limit.
Second, and critically, the security proof holds against coherent attacks rather than being restricted to the weaker collective-attack model that limited many earlier analyses. This was made possible by avoiding post-selection on the untrusted side and instead analyzing the protocol through the generalised entropy accumulation theorem (GEAT), retaining all of Bob’s outcomes, including non-detection events, in the data used to build the key.
Third, the authors show that placing the untrusted photon source close to Bob’s laboratory rather than in the middle, as is standard in fully DI setups, minimizes losses on the side that matters most for security. Combined with realistic noise parameters drawn from a state-of-the-art DI-QKD experiment (99% visibility, dark-count probability of 10⁻⁶), this configuration allows the protocol to remain secure over distances of roughly 247 km, a figure comparable to conventional, device-dependent QKD implementations, and far beyond what fully DI protocols can currently achieve.
Why it matters?
Detection efficiency is often the biggest barrier preventing DI-QKD from moving out of proof-of-principle demonstrations and into deployable infrastructure. As the authors note, even leading detector technology tops out around 70–80% efficiency. A protocol that reaches security at just above 50% using only two measurement settings, while resisting the most powerful class of attacks, lowers the bar for practical implementation without giving up the promise of device independence on the more exposed side of the link.
The result is also relevant to the broader push toward quantum-safe communication. As quantum computers threaten to break public-key cryptography, QKD offers an alternative based in physical laws rather than computational hardness, with the added benefit of intrinsic eavesdropping detection. The 1SDI model proposed here is particularly well suited to client-server style deployments like securing communications between a user and a bank, hospital, or government service, where the server-side infrastructure can be professionally secured while the user’s device cannot.
What’s next?
The authors point to two directions for future work. On the experimental side, achieving these results in a loophole-free implementation remains an important challenge. On the theoretical side, the numerical techniques used to bound the adversary’s information are computationally demanding, and extending them beyond the simplest two-setting case is an open problem. Finding more efficient numerical methods, or a tight analytical approach for more general protocols, would open the door to even lower experimental requirements for both one-sided and fully device-independent QKD.
Source
One-sided DI-QKD secure against coherent attacks over long distances
Michele Masini and Shubhayan Sarkar
2026 New J. Phys. 28 064503
DOI 10.1088/1367-2630/ae6def

Plot of the key rate as a function of Bob’s detection efficiency computed using different techniques as explained in the main text. As Alice is trusted, only the detected rounds with Alice are utilised for obtaining the statistics and the key.