Feasibility of satellite-to-ground continuous-variable quantum key distribution

Establishing secure communication links at a global scale is a major potential application of quantum information science but also extremely challenging for the underlying technology. While milestone experiments using satellite-to-ground links and exploiting singe-photon encoding for implementing quantum key distribution have shown recently that this goal is achievable, it is still necessary to further investigate practical solutions compatible with classical optical communication systems. Here we examine the feasibility of establishing secret keys in a satellite-to-ground downlink configuration using continuous-variable encoding, which can be implemented using standard telecommunication components certified for space environment and able to operate at high symbol rates. Considering a realistic channel model and state-of-the-art technology, and exploiting an orbit subdivision technique for mitigating fluctuations in the transmission efficiency, we find positive secret key rates for a low-Earth-orbit scenario, while finite-size effects can be a limiting factor for higher orbits. Our analysis determines regions of values for important experimental parameters where secret key exchange is possible and can be used as a guideline for experimental efforts in this direction.


Introduction
Quantum key distribution (QKD) exploits fundamental principles of physics to exchange cryptographic keys between two parties. It can guarantee information-theoretic security, in the sense that the security of the protocol does not depend on the complexity of some mathematical problem and hence the computational power of a possible adversary does not have to be bounded. QKD represents today one of the most successful applications of quantum information [1,2].
The rapid evolution in QKD implementations has resulted in extending the communication range from few centimeters of the first test to several hundreds of kilometers obtained with modern technology [3][4][5][6]. However, this evolution in ground-based implementations faces a fundamental limitation related to the attenuation of the quantum signal in optical fibers, which increases exponentially with the distance. With this scaling law, covering several thousands of kilometers, as required for the realization of an intercontinental QKD link, would be impossible even with the most advanced technology.
To overcome this limitation, a possible solution is the use of orbiting terminals to distribute cryptographic keys among ground stations. Studies investigating the feasibility of quantum communication using satellites have been ongoing for a decade [7][8][9][10][11][12][13], but a milestone was reached recently with the first complete satellite-toground QKD implementations realized with the Chinese * daniele.dequal@asi.it † eleni.diamanti@lip6.fr satellite Micius [14,15]. Soon after these demonstrations, the satellite was used for the realization of the first intercontinental quantum-secured communication [16], thus opening the era of satellite QKD. While these results represent a major step in the field, several issues still need to be addressed for the realization of a global QKD network based on satellite communication. In this framework, an important aspect is related to the development of high performance space-qualified terminals that will allow for stable, high throughput QKD links from a constellation of satellites to a network of ground stations. To this end, a possible breakthrough may come from the implementation of continuous-variable QKD protocols (CV-QKD) [17][18][19][20]. These protocols have the main advantage of using standard telecommunication components, such as IQ or amplitude and phase modulators for state preparation and coherent receivers for state detection, thus allowing to exploit the heritage of classical optical communication both in terms of high speed components and of their space qualification. The possibility of free-space and satellite CV-QKD has been investigated theoretically [21][22][23] and some preliminary experimental studies have been performed on signal transmission along free-space and satellite-to-ground links [24,25], however whether this technology can be used for secret key generation in a realistic satellite-based scenario remains an open question.
Here we present a feasibility study of satellite-toground CV-QKD, taking into consideration state-ofthe-art technology for the quantum state generation, transmission and detection, a realistic channel model and various orbit configurations. Our analysis follows the trusted node approach, where the satellite establishes a separate QKD link with each ground station and hence has access to the keys [14], rather than the untrusted one, where entangled photons are provided by the satellite to the ground stations which subsequently establish the secret key [15]. Furthermore, we calculate the secret key rate in the downlink scenario, where the emitter is on the satellite and the receiver on the ground, as it is more favorable for the optical signal transmission. The receiver uses a coherent detector with a free running local oscillator (local LO) and reference symbols are transmitted for phase recovery. Adopting a technique based on orbit subdivision to mitigate the effects of transmission fluctuations, we find that continuous-variable technology is a viable option for satellite QKD on low Earth orbits and identify experimental parameter regions that allow for secret key exchange. For higher orbits, the key generation is affected by finite size effects due to the limited number of symbols exchanged in a single satellite pass for such high-loss channels. These may be mitigated by achieving higher transmission rates or by considering multiple satellite passes.

Results
In our study we first provide a general model of the satellite-to-ground transmission channel, taking into account the beam propagation as well as the satellite orbit. We then examine the effect of channel fluctuations in CV-QKD and derive an equation for the secret key rate over generic fading channels. We subsequently use this equation for estimating the key rate in the case of downlink transmission, both in the asymptotic limit and considering finite size effects.
Channel model. We start our analysis by investigating the statistical properties of the satellite-to-ground transmission channel, which are critical for the assessment of the possibility to establish a QKD link in this configuration. In the downlink scenario that we are considering here, the beam travels from the satellite to the ground station and undergoes the disturbance and loss effects due to the atmosphere at the end of its path, resulting in a more favorable situation for key generation with respect to an uplink configuration [26]. There are several such disturbance effects, which can be classified as systematic or of random nature.
The systematic effects are theoretically predictable physical processes that perturb and attenuate the signal, and they include the refraction of the beam in the different atmospheric layers and the extinction of light due to absorption or scattering by air molecules or aerosols. The former is due to the variation in the optical refractive index of the atmosphere as a function of altitude and it causes the light to deviate from a straight line, resulting in an elongation of its physical path. Reference [27] provides a detailed calculation of the elongation factor -the ratio of the total length of the beam trajectory to the geometric path length -as a function of the apparent elevation angle of the satellite, i.e., the angle with respect to the horizon at which the satellite appears due to refraction and which differs from the real elevation angle. In this work, we restrict our analysis to elevation angles above 20 degrees, where the elongation factor remains close to 1 and therefore this effect can be neglected. The latter effect, namely extinction due to absorption and scattering, depends on the link length and on the molecule and aerosol distribution model [27]. It also strongly depends on the sky condition and the transmission wavelength. Here, for simplicity, we quantify this effect with a fixed attenuation of the channel of 2 dB, which is a conservative estimate for a cloudless sky and a 1550 nm transmission wavelength [28].
In addition to such systematic effects, random variations in the atmospheric temperature lead to fluctuations in the refractive index that have the statistical properties of turbulent scalar fields. The most important consequence of this atmospheric turbulence are intensity fluctuations (scintillation), beam wandering and beam broadening, which induce fading, namely fluctuations in the received optical power and hence in the transmissivity of the channel. The strength of these effects also depends on the altitude and hence on the elevation angle, as discussed in detail in Ref. [27]. The atmospheric turbulence is also responsible for the deformation of the beam profile. This is crucial, especially in the context of CV-QKD, where mode matching between the received signal and the phase reference (local oscillator) is important for the coherent detection [25]. To avoid mode mismatch, we assume the use of single mode fibers as spatial-mode filters of the incoming beam, together with an advanced adaptive optics system [29] to improve the coupling efficiency of the incoming light into the single mode fiber core. We remark that recent advances in this field have experimentally demonstrated a coupling efficiency in a single mode fibre exceeding 50% for a large aperture telescope [30].
Besides turbulence effects, the beam propagation is affected by wandering due to the limited pointing error of the satellite. This is characterized by the angle θ p , which is defined as the standard deviation of the angle between the direction of the center of the beam and the imaginary line joining the emitter and receiver telescopes, so that in the case of no pointing error we would have θ p = 0 µrad. A pointing error of the order of 1 µrad has been obtained in low-Earth-orbit (LEO) satellite-to-ground communication links [14]. This is used as a nominal value in our analysis. Similarly, the divergence of the beam is characterized by the angle θ d , for which we use the nominal value of 10 µrad which has been demonstrated with a 300 mm aperture telescope on-board of the Micius satellite.
We are now ready to analyse the statistical properties of our channel, which will be necessary for assessing the effect of fading on the CV-QKD link, under the above assumptions. To do this, we follow the approach of Ref. [21] and calculate the probability distribution of the transmission efficiency (PDTE), as it characterizes completely the statistics of the quantum channel for a given satellite orbit. Indeed, the transmission of coherent states of light through the atmosphere can be modeled by the input/output relation of the annihilation operators, a out/in . The transformation should preserve the commutation relation, so that we can write: whereĉ are environmental modes and T is the transmission coefficient (with the transmission efficiency being τ = T 2 ). Within this model, we can obtain the P -function characterizing the statistics of the quantum state; it is then possible to show that the PDTE is sufficient to characterize the state at the receiving telescope [21]. In the following, we first calculate the probability distribution obtained at a fixed distance between the satellite and the ground station, and then we take into account the satellite's orbit to compute the total probability distribution, i.e., the PDTE of the entire orbit.
a. Probability distribution at a fixed satellite distance: We consider a fixed distance R between the satellite and the ground station. The overall transmission efficiency can be divided into a fixed and a time varying term. We estimate the fixed attenuation term to be 5.8 dB, including 3 dB of losses for fiber coupling, 2 dB of losses for atmospheric attenuation due to scattering and absorption, and an additional 0.8 dB for taking into account the fact that we are only considering the main peak of the Airy diffraction pattern. As discussed previously, the main dynamic effects affecting the transmission in our analysis are the pointing error of the satellite and the divergence of the beam, characterized by the angles θ p and θ d , respectively. Following Ref. [21], to calculate the PDTE we first consider the deflection distance, r, and its standard deviation, σ r . As shown in Fig. 1(a), r is the instantaneous distance between the center of the receiving telescope and the center of the beam. Its standard deviation depends on the pointing and on the atmospheric turbulence as: where σ 2 turb 1.919C 2 n z 3 (2W 0 ) −1/3 is the variance of the beam size due to turbulence, which depends on the distance traveled by the beam in the atmosphere, z, and on the beam waist when entering the atmosphere, W 0 [28]. The parameter C 2 n is the refractive index structure parameter which characterizes the strength of the atmospheric turbulence. In case of moderate turbulence and considering a wavelength of 1550 nm we have C 2 n 10 −15 − 10 −14 m −2/3 , which gives σ 2 turb 10 −4 m 2 << (Rθ p ) 2 10 −1 m 2 , corresponding to a pointing error of 1 µrad and a satellite altitude of 300 km. This justifies the approximation in the right hand side of Eq. (2) for all satellite altitudes above 300 km. Under this approximation, the probability distribution of the deflection distance follows the Weibull distribution: An example of this distribution is shown in Fig. 1(c). Given now a distance r, the transmission coefficient can be obtained from geometrical considerations. An approximate but sufficiently accurate analytic relation between r and T can be calculated as [21]: where T 0 is the maximum transmission coefficient possible, and S and λ are the scale and shape parameters respectively. All three are given functions of the beam waist on the ground, W = Rθ d > 4 m for satellites above 400 km, and of the telescope aperture radius, a, here considered 0.75 m. Hence, we can write T 0 = T 0 (W, a), λ = λ(W, a), and S = S(W, a). The relation between T and r/a for these values is shown in Fig. 1 We can then substitute Eq. (4) into Eq. (3) and use the chain rule to obtain the probability distribution of the transmission coefficient, PDTC. The PDTE is obtained from the PDTC using the chain rule with τ = T 2 . Fig. 1(d) gives an example of the characterization of an atmospheric channel of fixed distance following our model for the same parameters as discussed above.
b. Probability distribution for orbit: We now obtain the PDTE for the entire satellite pass. In our analysis, we consider circular orbits that are passing at the zenith of the ground station (which is assumed not to move during the pass). We can write the radius of such orbits as R O = R E + h s , were R E is the Earth's radius and h s the satellite's altitude with respect to the ground. The angular velocity of the satellite is where M T is the Earth's mass and G is the gravitational constant. The distance between the satellite and the ground station during the satellite's visibility time, that we denote R(t), then reads: We then proceed as follows: • The orbit is divided into a set of points defined by the position of the satellite at a certain time, R(t i ) (i runs with the number of points), given by the orbital equation, Eq. (5).
• For each one of these points, both the PDTE(R(t i )) and the time difference between consecutive points of the orbit, denoted ∆t i = t i −t i−1 , are computed. The value PDTE(R(t i )) · ∆t i gives the distribution of the times with different transmission efficiencies inside the computed interval.
• Therefore, if we sum PDTE·∆t i over all the points we obtain the final distribution for the time spent by the satellite with a certain transmission efficiency τ . Indeed, we are mimicking the integral over the flight time: where the flight time, FT, is the normalization factor. Because we are considering circular orbits, we can label each orbit with its altitude, which is the minimum distance of the orbit, coinciding with the moment at which the satellite is exactly above the ground station. For such orbits and following the procedure described above, we show in Fig. 2 the probability distribution of the transmission efficiency (PDTE) for three different orbits of increasing altitude for a telescope with aperture radius a = 0.75 m. We remark that for higher orbits the variance of the distribution decreases. As described in the following, this fact has an impact on the noise introduced in time varying channels. We note that the conclusions that we have drawn for the downlink characterization are in agreement with the recent analysis of Ref. [31]. Interestingly however the authors there use the elliptical model rather than the circular one, which means that the ellipticity does not affect the probability distributions. For completeness, we also show in Fig. 3 the average attenuation encountered in a pass as a function of the satellite altitude.
Key rate estimation. Let us now describe the procedure we follow to estimate the key rate over a fading channel in the asymptotic regime, i.e., when no finitesize effects are taken into account. For this estimation we consider the no-switching CV-QKD protocol [32] in its prepare and measure version (PM). Alice starts by sampling 2N real random variables X 1 , ..., X 2N according to a Gaussian distribution with variance V A , that is, X k ∼ N (0, V A ) and prepares the corresponding N coher- Each of these states is sent through the quantum channel to Bob, who performs measurements in both quadratures simultaneously (heterodyne detection) [33]. For the k th use of the channel, he obtains two results Y 2k−1 and Y 2k which are supposed to be correlated to X 2k−1 and X 2k . The string Y = (Y 1 , . . . Y 2N ) forms the raw key since we consider the reverse reconciliation setting [34] which is advantageous in case of low transmission efficiency. Note that in a practical protocol, Bob will discretize his data, for instance by dividing the real axis into bins of small width. Asymptotic values are obtained in the limit N → ∞.
The standard formula to compute the asymptotic value of the secret key rate, in the case of reverse reconciliation, is the so-called Devetak-Winter bound [35]: where βI AB quantifies the correlations between Alice and Bob's data (here, the imperfect efficiency of the error correction procedure is taken into account thanks to parameter β ≤ 1) and χ BE quantifies how much information the adversary holds about the raw key corresponding to Bob's string. The Devetak-Winter bound is valid against collective attacks and remains true even against general attacks for QKD protocols with sufficient symmetry, including for the no-switching protocol, more precisely when de Finetti reductions are applicable [36][37][38].
In order to assess the performance of a protocol for a given quantum channel, one simply needs to estimate the value of βI AB and χ BE . For the first term, since we are dealing with the reverse reconciliation scenario, one should provide a model of the classical channel {Y k → X k } as well as an error correction procedure allowing Alice to recover the value of Y k from her observations and from additional side-information sent by Bob. In order to obtain χ BE , one should similarly model the parameter estimation procedure and compute the expected value that Alice and Bob would observe for our specific channel model. While these computations are fairly standard in the case of a fixed Gaussian channel with constant transmission efficiency and excess noise, the situation becomes more subtle in the case of a fading quantum channel and indeed conflicting results have appeared in the literature [39,40] (see Methods for details).
Here, we find it useful to recall the derivation of the asymptotic secret key rate from the non-asymptotic case. According to Refs. [38,41], the protocol we are considering is secure against general attacks, even in the finite size regime, and the asymptotic secret key rate is given by N ) ). (8) In this expression, H(Y (N ) ) refers to the empirical entropy of the string Y (N ) and the superscript N is explicitly written to emphasize that each of these quantities depends on the block length. Since we are only interested in the asymptotic behaviour of the secret key rate, we neglect discretization effects here. The quantity leak EC is the number of bits that are leaked in the error correction procedure during which Bob sends some side information to Alice to help her guess the value of Y. The term f (Γ (N ) ) quantifies the information available to Eve and will be described later.
The advantage of Eq. (8) is that it tells us how to compute βI AB and χ BE in the Devetak-Winter bound, namely Let us first consider the first term. Here we model the quantum channel between Alice and Bob as a phaseinsensitive noisy bosonic channel with transmission efficiency given by a random variable τ k ∈ [0, 1], whose probability distribution is the one calculated previously. The channel noise will be treated with the so-called excess noise, ξ, whose full derivation will be given in the following. We will additionally model the imperfections in Bob's detectors by two parameters: their detection efficiency η and the electronic noise ν el . In particular, this implies that the random variables X k corresponding to Alice's inputs and Y k for Bob's measurement results satisfy: where T k is the overall transmission coefficient for the k th channel use, T 2 k = τ k , and Z k ∼ N (0, σ 2 ) is a Gaussian noise of variance σ 2 assumed to be constant.
In order to compute the key rate of Eq. (8), it is important to understand how fast the fading process is. The main idea here is that this process is much faster than the time needed to distill a secret key, in other words the channel transmission coefficient fluctuates significantly over N uses of the channel, but this coefficient is relatively stable over consecutive uses of the channel. As a consequence, Alice and Bob can exploit classical signals to roughly monitor the current transmission value of the channel and adapt their error correction procedure accordingly. This implies notably that for the error correction procedure, we can assume that Alice and Bob know (approximately) the value of T k . This allows them to use good error correcting techniques developed for the fading channel where the fading process T k is known to the receiver. In particular, the Gaussian modulation permits to achieve the capacity of this channel up to a reconciliation efficiency factor β and one expects [42] βI AB = βE log 2 1 + where E[·] is the expectation with respect to the fading process. Here and in the following, we write T instead of T k and replace averages of the form 1 N N k=1 by the expectation E for simplicity. Note that since the log function is concave, the value we find for βI AB is smaller than the one computed for a channel with a fixed transmittance E[T 2 ]. To numerically compute the value of Eq. (11) it is possible to use the expressions given in Ref. [43] for a fixed transmission channel, and take their expectation value. Let us now turn to the second term of Eq. (8), namely f (Γ (N ) ), which quantifies the information available to Eve. More precisely, Γ (N ) is a worst case estimate of the (average) covariance matrix of the state Alice and Bob would share in the entanglement-based version of the protocol and the function f is defined as where g is the entropy function g(z) = z+1 2 log 2 z+1 2 − z−1 2 log 2 z−1 2 , ν 1 and ν 2 are the symplectic eigenvalues of Γ (N ) and ν 3 and ν 4 are the symplectic eigenvalues of the matrix describing Eve's system conditional on Bob's measurement outcome [44]. The interpretation of the function f is that it coincides with the Holevo information between the raw key and Eve's quantum memory computed for a Gaussian state ρ G ABE with covariance matrix coinciding with Γ (N ) on Alice and Bob's systems.
In order to compute the covariance matrix Γ (N ) that Alice and Bob would infer from their data, we note first that for a fixed transmittance value T , the covariance matrix of the bipartite quantum state they would hold in the entanglement-based version of the protocol reads with V = V A + 1, 1 2 = diag(1, 1) and σ Z = diag(1, −1).
As observed in Ref. [39], when the fluctuation of the transmission efficiency is considered, the resulting state is a mixture of the individual fixed-transmission states, giving an overall covariance matrix equal to Γ (N ) = E[Γ(T )], that is: If we compare the covariance terms in Eqs. (13) and (14) we can identify an effective transmission for the fading channel equal to E[T ] 2 . In particular, the variance of Bob's system can be written  [3] (corresponding to the so-called additive white Gaussian noise channel), some research will be needed to obtain similar performances for fading channels. fixed case with an effective transmission efficiency and excess noise, it is possible to use the equations reported in Ref. [43] for calculating the eigenvalues in Eq. (12). To summarize, by putting together the two terms of Eq. (8), our expression for the secret key rate in the presence of fading becomes: Simulation results. We are now ready to use the results derived above to estimate the expected key rate achievable for a satellite-to-ground CV-QKD link under our assumptions. To properly account for the expected noise, we include in our modeling the noise contribution related to the phase recovery between the signals generated by Alice and measured by Bob. The technique that we consider here has been proposed in Refs. [45,46] and consists in sending periodic reference symbols (pilots) along with the quantum signal. At the receiver side, Bob uses a free running local oscillator, which must be tuned to compensate for the Doppler frequency shift introduced by the satellite motion, to measure both the pilot and the quantum signals, in a so-called 'local' local oscillator configuration. As described in the Methods section,two noise contributions arise from this technique, which are due to laser instability and shot noise. The overall excess noise ξ, here referred to the channel input, is given by the above mentioned contributions, the fading noise, described in the previous section, and an additional fixed contribution due to experimental imperfections, ξ fix , which includes also other possible errors in the phase correction.
The main experimental parameters that influence the key rate generation are summarized in Table I, together with their reference values. The reference values considered for the ground station and the satellite are similar to those reported in Ref. [14] and represent a high performance satellite optical communication system. A detailed analysis of the effect of individual parameters on the key rate is given in the Methods. Regarding the signal variance V A , for each satellite altitude and for each set of parameters we choose the value that maximizes the key rate. These values are in general between 2 and 4 shot noise units (S.N.U.), depending on the configuration. Figure 4 shows the fading noise given by the PDTE that we obtain for orbits going from 400 km to 22000 km. As we see, an increase of the noise is present for LEO. This is due to the fact that in such orbits the variation of the slant range is more pronounced thus introducing a higher variance on τ (as we observe in Fig. 2). Moreover, it is worth noting that when the pointing error is much smaller than the beam divergence, the fading effect is mainly due to the variation on the satellite distance.
To reduce the effect of fading excess noise, a natural strategy is to reduce the variance of the fading process. This can be achieved as follows: Alice and Bob can approximately monitor the value of the transmission efficiency of the channel seen by the quantum symbols τ k by multiplexing in some degree of freedom an intense optical signal that serves as beacon and experiences a transmission efficiency τ b . An intensity detection of the beacon at Bob's, sampled at rates higher than the atmospheric coherence time (typically ∼ 1 kHz), can provide an accurate estimation of the channel transmittance evolution with time τ b (t). This information can be used to classify the detected quantum symbols in groups as a function of the expected transmittance so that for each group g the PDTE is reduced to a transmittance interval PDTE(g) for which the contribution of the fading is less detrimental. The CV-QKD protocol can be performed independently for each of these groups to obtain a secret key rate per symbol K fad (PDTE(g)) and an aggregated secret key rate per symbol of K agg = g P (τ b ∈ PDTE(g))K fad (PDTE(g)). (17) The classical beacon does not transport information related to the quantum signal and K fad (PDTE(g)) is obtained using only the quantum symbols. For this reason, if the signal is tampered with in order to falsify the group classification (alter the correlation between τ k and τ b ) only a denial of service would be experienced, since the secret key rate would be reduced, as the manipulated group would suffer higher fading and more excess noise would be estimated.
In order to reduce the effect of fading, narrow PDTE intervals are desirable, but this can magnify finite size effects, since the number of symbols per group will be reduced. This compromise between PDTE interval width and number of symbols per group can be taken into account in order to optimize the division of the PDTE so that K agg is maximal for a given PDTE and orbit duration. Technical restrictions such as the resolution available for determining τ b can also play a role in the ideal division of the PDTE in groups.
In our analysis we have chosen a uniform division of the PDTE and we do not treat the problem of the PDTE division optimization. We divided the whole range of transmission values in equally spaced intervals, going from a single group (corresponding to analyzing the data all together) to 100 intervals (i.e., close to the asymptotic limit). The results are reported in Fig. 5 for a satellite at 400 km and for three values of fixed excess noise. We note that without channel subdivision no key would be possible for a 400 km orbit. To analyze the effect of the channel subdivision for all the orbits, we selected subdivisions of 3, 10 and 100 intervals for all the satellite altitudes. As shown in Fig. 6, the division of the channel transmission efficiency in 10 groups gives a total rate close to the asymptotic limit for all satellite altitudes.
Finite size analysis. We complete our analysis by considering the issue of finite size effects on the estimation of parameters. It is worth noting that in satellite communication the maximum amount of time for a transmission is given by the orbital parameters and can range from few minutes to hours, depending on the satellite altitude. Moreover, as discussed previously an optimization is required if we consider the subdivision of the channel transmission efficiency for reducing the fading noise. A denser subdivision will decrease the fading noise, but will result in less populated groups, thus making the finite size effects more detrimental.
Here, we consider the uncertainty of the parameter estimation due to the limited statistics. As described in Ref. [47], it is possible to account for this effect by considering a lower bound on the transmission coefficient T = √ τ and an upper bound of the parameter where m is the number of symbols used for parameter estimation and z P E /2 is a parameter related to the failing probability of the parameter estimation P E . Here we consider P E = 10 −10 , which gives z P E /2 = √ 2 erf −1 (1− P E ) = 6.5, where erf −1 is the inverse error function. We consider the situation in which half of the symbols are used for parameter estimation and the orbit is divided in 10 intervals. This choice is not optimized and should be tailored to a specific experimental setup, however such an optimization is beyond the scope of this work.
The results for the given parameters are shown in Fig. 7 and highlight how the finite size effects have a remarkable impact on higher orbits, effectively precluding CV-QKD operation beyond 2000 km when the key distillation is performed on a single satellite pass. For lower orbits, below 800 km, the effect is only limited to a drop in the key rate. The finite size effects could be reduced increasing the transmission rate and optimizing the orbit subdivision, as well as accumulating multiple satellite passes.

Discussion
In this work we analyzed the feasibility of CV-QKD from satellite to a ground station. By modeling the transmission channel along a complete circular orbit, it has been possible to obtain the probability distribution of the transmission efficiency (PDTE) of the quantum channel, from which we derived the secret key generation rate both in the asymptotic case and when finite size effects are considered in the parameter estimation. To cope with channel fluctuations, typical of the satellite signal transmission, we proposed a method of data analysis based on orbit subdivision and proved its effectiveness in improving secret key generation. The analysis provides an estimate of the expected key rate of satellite-to-ground CV-QKD and allows to constraint the experimental parameters for its realization. The obtained results show that coherent state modulation and detection is a viable option for quantum communication with LEO satellites.
The communication with higher orbits, achievable in the asymptotic limit, can be affected by finite size effects if the transmission rate is low or the orbit subdivision is not optimized. We note however that by merging multiple satellite passes, or with the implementation of higher repetition rate systems, it would be possible to extend the communication range beyond 2000 km. Further work is required for the comparison of the key rates achievable with continuous and discrete variable encodings in different communication scenarios.

Methods
Parameter analysis. Here we analyze the dependence of the secret key rate on several parameters, to obtain a better insight into which parameters affect the most the overall performance. To reduce the complexity of this multiparameter analysis, we consider here the key rate that can be obtained if the instantaneous value of the transmission efficiency is known. This case occurs when a sufficient number of symbols is exchanged within the timescale of the channel fluctuation (typically of the order of few ms) and it upper bounds the rate given by Eq. (16). Such a situation is unrealistic in practice, however it will give us a reference for estimating the efficiency of the realistic scenario.
In this scenario, the key rate can be calculated as a weighted average, considering as weight the PDTE calculated from our channel model analysis: The parameters will be changed one by one, keeping the others to their reference values, expressed in Table I. The color code reflects the value of the fixed excess noise and is the same used in the main text: red, blue and green for ξ fix = 1, 3, 5% (in S.N.U.), respectively.
In Fig. 8 we vary the electronic noise of the detectors from 0.01 to 0.1 S.N.U. We notice that even with one order of magnitude increase in noise, the key rate is almost unaffected for all cases. This is mainly due to the fact that in this analysis we consider the so called "trusted" or "calibrated" scenario, in which the electronic noise is known to Bob via a constant calibration and cannot be exploited by Eve.
The second effect considered is the energy of the reference symbols used for phase recovery. We will illustrate the problem considering a simple phase estimation scheme operating at 1 Gsymbol/s with alternating signal and reference symbols. The time between two such symbols, ∆t = 1 ns, gives rise to a noise contribution ξ t = V A 2π∆t∆f , where ∆f energy. The effects for different reference symbol energies is shown in Fig. 9. While the effect for LEO satellites is negligible for energies above 10 pJ, for higher orbits stronger values of the reference are required to avoid any detrimental effect due to the phase alignment uncertainty, which might impose restrictions in the dynamic range of the modulators, since the optimal variance V A decreases as attenuation increases.
Finally we consider the impact of the downlink beam characteristics, namely the pointing error and the beam divergence, on the final key rate. As expected, these values have a strong impact in all the configurations shown in Fig. 10, underlying the importance of a high quality beam propagation for satellite CV-QKD.
Previous treatment of fading in the literature. Reference [40] considers two scenarios: slow fading where the transmission efficiency fluctuates at a slower rate than the key establishment rate, and fast fading where the transmission value fluctuates significantly during a single key extraction procedure. The second scenario is similar to ours, but the expression of the authors for the secret key rate differs since they obtain K fast fading = βI A B ηmin − dτ P τ χ(E; y), where the transmission efficiency τ = T 2 is uniformly distributed with distribution P τ over some interval [τ min , τ max ]. In other words, they take the most pessimistic value of I AB (corresponding to the lowest transmission value) and consider the average of the Holevo information between Eve and the raw key, over the possible fading values.
In contrast, we agree with the estimate for the Holevo information from Ref. [39] but take a more conservative value for the mutual information I AB since their value is computed for a Gaussian modulation that would yield the same covariance matrix. We have instead argued that one needs to carefully consider the classical channel mapping Y to X (in the reverse reconciliation procedure). This is a fading channel where one can take advantage of the pilot signals to get a rough estimate of the fading coefficient. This implies that one can approximate the capacity of that channel with the average of the capacities of an AWGN channel over the value of the fading parameter.