An arXiv pre print reports a four party quantum key run at 750 ± 10 bits per second, with a security proof that holds against a cheating participant and composes with other cryptographic tools.
A group, not a pair, just got a measured quantum-secured key on real hardware.
In a pre-print posted to arXiv this month, Russell Brooks and colleagues built a four-party version of quantum key distribution, the cryptographic technique that lets two parties share random bits whose security rests on physics rather than computational hardness. The twist: instead of one sender and one receiver, four parties share a single key, and the security guarantee holds even when one of the four is the adversary.
The experiment runs over 20 kilometres of standard optical fibre arranged in a star topology, with one central node distributing a four-qubit entangled state to the four endpoints. That state is a so-called Greenberger-Horne-Zeilinger, or GHZ, state, a cousin of the better-known Bell pair that ties two particles together: a GHZ state ties four together so that measuring any one of them forces the others into a correlated outcome. The team builds those four-photon states by combining two entangled photon pair sources running above 5×10³ fourfold events per second, the rate at which the experiment actually produces the four-party resource it needs.
Through that 20 km star, the authors report a maximum asymptotic secret key rate of 750 ± 10 bits per second, the highest figure they record in the long, infinitely keyed limit. From the measured event rates and error statistics they then project a composable finite-key lower bound of 8.7 megabits for a randomised 24-hour run, using an optimised basis probability. "Composable" here is the term of art: the key can be fed into any downstream cryptographic protocol, and the security of the combined system still holds, rather than the key being safe only for the specific task for which it was generated.
Multipartite quantum secret sharing has been demonstrated before, but the proofs were usually asymptotic or were limited to outside eavesdroppers. The new pre-print pins three properties at the four-party level on real fibre at once: security against general attacks, security against participant attacks where one of the four legitimate parties is the cheater, and a composable finite-key bound. That is the engineering shape multi-party quantum protocols for distributed computing, joint signing, or voting-style primitives will eventually need, and prior fibre results did not put all three on the same plot.
There are three honest limits to put on the result.
First, the source is a single arXiv pre-print with no peer review and no independent confirmation. The 750 bps number is measured; the 8.7 Mbit figure is inferred from those measurements under a finite-key security analysis, not run for 24 hours end-to-end.
Second, the demonstration is a four-party ceiling in a 20 km lab star. The team does not show that the same protocol keeps working at five, ten, or twenty parties, and they do not claim a metropolitan- or wide-area run. The fibre is real fibre, not a metropolitan network, and the 20 km is the entire optical path, not a single hop.
Third, the 8.7 Mbit projection assumes the lab's device statistics stay stationary for the full 24-hour window. Real devices drift, photon sources age, and polarisation in installed fibre wanders with temperature. Whether the same bound holds when a real-world source is left running overnight is the next experiment the protocol will have to clear, not the one this pre-print clears.
The cryptographic shape of four-party key distribution on fibre, with composable security against an insider, is now a measured primitive rather than a theoretical sketch. The next bottleneck is the device, not the proof. The 8.7 Mbit number is asking the next setup to clear a 24-hour run on a source that actually drifts.
The team has not announced a follow-up run, and there is no public schedule for a five-party or metropolitan-scale test.