Chip-Based QKD Has a Glow Problem: VOA Luminescence Creates a Side Channel That Standard Security Analyses Miss
Table of Contents
9 Sep 2026 – A team led by Kejin Wei at Guangxi University has published what the authors describe as the first systematic investigation of parasitic luminescence from p–n junction variable optical attenuators (VOAs) as a security vulnerability in integrated quantum key distribution (QKD) transmitters. The peer-reviewed paper, published in npj Quantum Information on 9 September 2026, demonstrates that forward-biased p–n junction VOAs (widely used in silicon photonic QKD transmitters to control photon intensity) emit spontaneous luminescence centered around 1107 nm when electrically biased. An earlier preprint appeared on arXiv on 20 April 2026.
The emission wavelength is well outside the C-band (~1550 nm) used for quantum signals, which means an attacker equipped with a wavelength-division multiplexer could in principle separate the parasitic photons from the quantum channel without disturbing the encoded states. The researchers term this a “wavelength-resolved side channel” and present both a theoretical model and single-photon-level interferometric measurements confirming the emission. Their interferometric technique yielded a measured center wavelength of approximately 1078 nm, consistent with the ~1107 nm predicted by silicon’s 1.12 eV indirect bandgap.
The paper models two threat scenarios depending on the VOA’s position in the transmitter architecture.
When the VOA is placed before the encoding module, the parasitic photons pass through the encoder and acquire the same modulation as the signal – giving an eavesdropper, in the authors’ model, access to encoded key information on a separate wavelength. The authors call this a “passive Trojan-horse attack,” because the leakage photons originate from the device’s own physics rather than from an injected probe. Simulations of a two-decoy-state BB84 protocol quantify the modeled damage for this architecture. In the worst-case driving conditions (2.0 V bias, 1.6 ns pulse width), the maximum secure transmission distance drops from roughly 320 km to 19 km under the conventional GLLP analysis, with the key rate falling by more than an order of magnitude.
When the VOA is placed after the encoder, the parasitic photons reach the receiver unencoded, inflating Bob’s measured gain and biasing the parameter estimation that decoy-state security proofs rely on. The authors term this the “dual-source flaw.” The modeled impact in this configuration is less dramatic but still significant at short range: roughly 50% key-rate reduction in the worst-case driving conditions, declining rapidly with distance and becoming negligible beyond approximately 15 km because fiber attenuation at the parasitic wavelength (~0.8 dB/km at ~1078 nm) is roughly four times higher than at 1550 nm.
The test chip was fabricated on a standard 200 mm silicon-on-insulator wafer using CompoundTek’s commercial 90 nm CMOS-compatible silicon photonics process – a foundry platform used in several published chip-based QKD demonstrations. The published supplement reports that a second VOA, fabricated on AMF’s platform with a longer interaction length of 318 µm, shows similar voltage-dependent luminescence – evidence that this is a general characteristic of forward-biased silicon p–n junction VOAs, not an artifact of one foundry.
My Analysis
If a chip-based QKD transmitter’s security analysis assumes that its VOA only attenuates light, an unaccounted emission channel can invalidate the bounds that analysis produces. That is the central result here, and it deserves attention.
This paper is a textbook demonstration of the gap I keep returning to – the gap between protocol security and implementation security. QKD’s theoretical security is grounded in physics. No one disputes that. But every real QKD system runs on semiconductor components that leak in ways the security model may not have anticipated.
So what is new here and what is not? Frameworks for bounding transmitter imperfections already exist – Tamaki, Curty, and Lucamarini published their leaky-source analysis in 2018, and subsequent work addresses state-preparation information loss more generally. The analytical tools to bound transmitter emissions are available. What this paper contributes is the identification of a specific, previously unrecognized physical emission mechanism in a ubiquitous integrated component, along with quantitative measurements and a security analysis showing the mechanism cannot be safely ignored. Knowing how to model leakage in principle and knowing that a particular component leaks are different problems. This paper solves the second one for VOAs.
Why this matters beyond VOAs
The mechanism is basic semiconductor physics. A VOA built on a forward-biased p–i–n junction injects carriers to induce absorption via the plasma dispersion effect. That same carrier injection produces radiative electron-hole recombination – the mechanism that makes LEDs emit light. Silicon’s indirect bandgap makes the emission too dim for a standard photodiode, but the researchers used single-photon-sensitive instrumentation and confirmed photon rates on the order of $$10^7$$ counts per second at typical operating voltages. In a system designed to encode one photon at a time, millions of unaccounted photons per second give an eavesdropper a readable signal.
The authors note that phase modulators, on-chip photodiodes, and other integrated photonic components use the same carrier-injection mechanism. If a VOA emits parasitic light under forward bias, every other carrier-injection device on the same chip is a natural next target for characterization. The paper provides no emission data for those components – only the call for future work – but the shared p–n junction physics makes the question urgent.
The AMF-platform replication in the supplement adds weight. Two foundries and two VOA interaction lengths produced the same voltage-dependent luminescence, confirming the emission is inherent to the junction physics.
Implementation attacks keep accumulating
This result extends a long and growing lineage of QKD implementation attacks. Detector blinding, which demonstrated full key recovery against commercial QKD systems by manipulating single-photon detectors, was the result that permanently retired the word “unhackable” from serious QKD literature. Trojan-horse attacks, where an eavesdropper injects probe light into the transmitter and reads the back-reflections, target the source side directly. Laser damage attacks reduce VOA attenuation by physically degrading the component. The photorefractive-effect attack demonstrated by Ye et al. in 2023 showed that injecting light into lithium niobate waveguide modulators alters their operating point. In every case, the device’s physical behavior deviated from the idealized model the security proof assumed.
The analogy extends beyond QKD. KyberSlash, a timing vulnerability in deployed ML-KEM implementations, demonstrated that mathematically sound PQC designs can leak private keys through implementation details the specification never modeled.
An older and closer parallel is backflash. Avalanche photodiodes in discrete QKD receivers can emit light during detection events, creating a passive optical leakage channel that an eavesdropper can monitor. That vulnerability was identified in bulk-optics QKD systems years ago. What the VOA result adds is a new transmitter-side emission mechanism specific to integrated photonics, on a different wavelength, through different physics – but the broad category of “your optical security device emits light it shouldn’t” is not new to the field.
Protocol responses and their limits
The field’s response to detector-side attacks has been structural. Measurement-device-independent QKD removes the measurement station’s detectors from the trust boundary, closing all detector-side vulnerabilities. But MDI-QKD does not address leakage from the users’ state-preparation equipment – the transmitter, including its VOAs, is still within the trust perimeter.
Device-independent QKD makes a different and stronger promise: security without detailed characterization of the internal quantum devices, certified by observed Bell-inequality violations. But DI-QKD still requires assumptions, among them that no information leaks from the users’ laboratories to the eavesdropper outside the quantum and classical channels the protocol controls. A VOA that emits photons at ~1078 nm, well outside the spectral range the protocol monitors, is the kind of side channel that violates that isolation assumption. The paper’s BB84 analysis does not directly establish an attack against DI-QKD, but it identifies a physical mechanism that any DI-QKD deployment on integrated silicon photonics would need to address – most likely through spectral filtering at the transmitter’s output.
What this means for the chip-based QKD push
The timing is great. The commercial QKD roadmap depends heavily on photonic integration. Chip-based transmitters and receivers are a primary path to cost reduction, miniaturization, and mass production – everything needed to move QKD from laboratory demonstrations to the kind of metropolitan and national networks that China, EuroQCI, and others are building.
The mitigations the authors suggest are engineering solutions, not fundamental obstacles: spectral filtering to block the parasitic wavelength, careful selection of VOA drive voltage and pulse width to minimize emission, and calibration protocols that explicitly account for the dual-source contribution. Operationally, any chip-based QKD system should now characterize its VOAs for parasitic luminescence as part of the security evaluation, at a minimum. The fact that the leaky-source security proof framework already exists means the residual leakage, once measured, can be bounded and incorporated into the key-rate calculation.
As I have argued in my Quantum Ready coverage, the attack surface is the implementation. It applies to PQC implementations and it applies to QKD implementations. No amount of information-theoretic security at the protocol level survives a component that emits key-correlated photons on a wavelength the security analysis never measured.
For organizations evaluating QKD products, the question to ask vendors just got one item longer: does your transmitter’s security evaluation include characterization of parasitic optical emissions from every active component on the chip, including VOAs, phase modulators, and carrier-injection devices? If the vendor cannot bound those emissions or show how the security analysis accounts for them, the assurance case leaves this mechanism unresolved.