{"id":"d49fd4d8-9440-4d65-9324-186f00ddacd7","arxiv_id":"1908.05073","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":5.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":5,"one_line_summary":"A security proof and simulation show that SNS twin-field QKD can be run with fully asymmetric source parameters while retaining security and substantially improving key rates on asymmetric channels.","lead":"This paper generalizes the sending-or-not-sending twin-field quantum key distribution protocol to allow Alice and Bob to use different laser intensities and sending probabilities, with a new ratio constraint that preserves security. The generalized protocol yields much higher key rates than the symmetric version when the two fiber channels have different losses, which is the common situation in quantum networks.","discovery_kind":"extension","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The security proof's decoy-state reduction is not validated for arbitrary adversarial channels; Eq. (40) may not bound the true phase error if a dishonest Charlie uses a phase-dependent, photon-number non-preserving attack after the phases are announced.","rationale":"The reader's weakest-assumption analysis correctly identifies the statistical equivalence and decoy-state isolation of |χ+⟩ as the load-bearing step. My review agrees and sharpens the concern: the simplest reading of the decoy-state reduction treats the phase-randomized, announced-phase coherent state as a mixture of total-photon-number components. That is mathematically legitimate for the specified beam-splitter measurement, but the paper's security claim is stated for an untrusted Charlie. If Charlie can store the signals and measure only after the phases are announced, the effective POVM can be phase-dependent and need not preserve total photon number. Then cross-photon-number coherences contribute to T_Δ, and the simple vacuum subtraction in Eq. (40) can under-estimate the phase error, invalidating the key-rate formula. This is not an external disagreement with the consensus; it is an internal gap between the stated security claim and the proof's unsupported decoy-state assumption. The numerical comparison and the relation to ref [78] are secondary: they affect novelty and performance claims, not the core security argument. I therefore do not recommend moving beyond the reader's conditional verdict; the protocol may well be secure, but the proof needs one more explicit step or a precise reference to where the arbitrary-channel case is handled.","tokens_in":17210,"tokens_out":47223,"duration_ms":509914,"concrete_test":"Re-derive Eq. (40) from the joint probability P(error, δA, δB) = Tr[E(|β1><β1|) Π_error(δA, δB)] for an arbitrary CPTP map E on the two optical modes, without assuming E commutes with total photon number. If the derivation requires an extra assumption such as phase-insensitive detection or photon-number preservation, that assumption should be stated in the protocol. Alternatively, simulate a specific non-photon-number-preserving adversarial channel (e.g., two-mode squeezing with a phase-dependent POVM) at a parameter point in Table II, compute the true Z1 phase error via the full virtual protocol, and check whether the value from Eq. (40) is an upper bound. A violation would show the security proof as written is incomplete.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central security claim depends on the reduction from the announced-phase coherent states used in ~X-windows back to the |χ+⟩ single-photon component, and then on the decoy-state bound in Eq. (40). The paper states in the Step 5 Note that 'decoy state method can applied to our protocol as if the phases δA and δB were not announced', citing ref [68], but does not reproduce or extend that argument to the asymmetric-parameter setting. The bound Eq. (40) subtracts only the vacuum contribution from the ~X error counting rate T_Δ, leaving all multi-photon and cross-photon-number contributions as nonnegative error terms. This is a valid upper bound if the effective channel plus Charlie's POVM is block-diagonal in total photon number, e.g., a passive beam-splitter measurement with phase-insensitive detectors. But the paper also claims security does not rely on Charlie's honesty. If Charlie delays measurement until after δA and δB are announced, he can choose a POVM that depends on the individual phase values. Such a POVM can have coherence between different total photon numbers, so the observed T_Δ is no longer a Poisson-weighted sum of photon-number yields. The asymmetric ratio Eq. (1) changes the weights µA1, µB1, so this is not automatically the already-proved symmetric case. Without an explicit proof that the decoy-state estimate remains one-sided under arbitrary CPTP maps, the central claim that Eq. (1) guarantees security has an unverified gap.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper proposes a general version of the sending-or-not-sending (SNS) twin-field QKD protocol in which Alice and Bob are allowed to use different source intensities and sending probabilities, subject to the ratio constraint Eq. (1). The authors give a security proof via a sequence of virtual protocols, a four-intensity decoy-state parameter estimation, and a finite-key analysis using the Chernoff bound. Numerical simulations for asymmetric channel lengths show a large key-rate improvement over the original SNS protocol and over a 'modified SNS' protocol that adds extra loss to balance the channels.","tokens_in":17530,"tokens_out":18043,"duration_ms":176332,"significance":"If the security proof is correct, the protocol is a practically valuable extension: it removes the equal-source-parameter restriction of the original SNS protocol and substantially improves key rates in asymmetric channel deployments, which are common in real QKD networks. The design constraint Eq. (1) is simple and the finite-key formulas are provided. The paper is clearly written and follows the standard virtual-protocol structure that the authors and others have used for SNS/TFQKD proofs. The main unresolved issue is the rigor of the decoy-state reduction in the asymmetric-parameter setting, which is load-bearing for the central security claim.","major_comments":[{"comment":"The paper asserts that the decoy-state method can be applied 'as if the phases δA and δB were not announced' (Step 5 Note), but it does not prove this for the asymmetric-parameter case. The bound on the phase-flip error rate in Eq. (40) is obtained by subtracting the vacuum contribution from the observed error counting rate T_Δ; this is a valid one-sided bound only if the observed error rate is a Poisson-weighted sum over total-photon-number components, i.e., if Charlie's measurement is block-diagonal in total photon number. The protocol does not explicitly prevent Charlie from storing the pulses and performing a phase-dependent measurement after the phases δA, δB are announced. Under such a strategy, the POVM can have coherences between different total photon numbers and Eq. (40) may not hold. Because Eq. (1) changes the weights of the photon-number components relative to the symmetric SNS proof, the citation to Ref. [68] is not sufficient. The authors need to provide an explicit derivation of Eq. (40) under arbitrary adversarial channels, or modify the protocol/analysis to close this gap.","section":"Sec. III.C (Virtual Protocol 3, Reduction 3) and Step 5 Note, Sec. II; Appendix Eq. (40)"},{"comment":"In the asymmetric case, the real-photon states |χ0⟩ and |χ1⟩ are not orthogonal: their inner product is (μA1−μB1)/(μA1+μB1). The paper uses these states to define the phase-flip error rate and to relate the X-window data to the Z-window phase error, but it does not discuss how the non-orthogonality affects the estimates. The original SNS proof relies on the symmetric case where these states are orthogonal (μA1=μB1). The authors should justify that the formula for E(a,d) and the reductions leading to Eq. (31) remain valid when the two states are not orthogonal, or show explicitly why the non-orthogonality is irrelevant for the security argument.","section":"Sec. III.A, Eqs. (18)-(21)"},{"comment":"The decomposition of the phase-randomized coherent-state density matrix into the mixture {|ψ_l⟩} is stated without derivation and appears to be incorrect as written: the phase-randomized state is diagonal in the Fock basis, whereas the states |ψ_l⟩ in Eq. (33) contain coherences within each total-photon-number subspace. The decoy-state method requires well-defined yields for the components of the mixture. This decomposition is the basis for the claim that the single-photon component |ψ_1⟩ is exactly |χ+⟩ under Eq. (1), which is central to the security proof. The authors should provide a careful derivation of the decomposition and of the resulting decoy-state estimates, rather than citing Ref. [68] without addressing the asymmetric weights.","section":"Sec. III.C, Eq. (32)-(33)"}],"minor_comments":[{"comment":"Equation (4) contains a typographical issue: 'fn tH(EZ)' should read 'f n_t H(E_Z)' (i.e., f times n_t times H(E_Z)). Similar spacing issues appear in Eqs. (35) and (36).","section":"Sec. II, Eq. (4)"},{"comment":"The description of the bit values is confusing: 'she (he) decides to send ... and puts down a bit value 1 (0)' followed by the opposite for not sending. It would be clearer to define Alice's and Bob's bit values explicitly in a table or a short formula.","section":"Sec. II, Step 1"},{"comment":"The notation for lower bounds is ambiguous: in Eq. (37), the same symbol ⟨s^Z_1⟩ appears on both sides of the inequality, which is confusing. The authors should use distinct notations for the quantity and its lower bound (e.g., an underline or superscript L), as is common in the decoy-state literature.","section":"Appendix A, Eqs. (37)-(39)"},{"comment":"The table header 'Nt ed d ηd fe ξ α' is hard to parse; it would be clearer to separate the two dark-count-related parameters as 'e_d' and 'd' explicitly in the header, matching the caption.","section":"Sec. IV, Table I"},{"comment":"The conclusion states that 'the intensities and the probabilities for sending' should satisfy Eq. (1), but Eq. (1) is a constraint on the intensities only; the sending probabilities appear in the ratio but are not independently constrained. The sentence should be phrased more precisely.","section":"Sec. V"}],"recommendation":"major_revision","confidential_remarks":"The proposed protocol is practical and the numerical results are compelling, but the security proof has a genuine gap in the justification of the decoy-state reduction in the asymmetric setting. This is not a minor oversight: the central claim that Eq. (1) 'guarantees the security' depends on it. The authors should be asked to provide a self-contained proof of the decoy-state bound (or a clear reference to a proof covering the asymmetric case) and to address the non-orthogonality of |χ0⟩ and |χ1⟩. Given the authors' track record and the standard structure of the proof, I would expect this to be fixable, which is why I recommend major revision rather than rejection. The paper should also engage with independent closely related work (e.g., ref. [75]) on asymmetric TFQKD to clarify the novelty."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Xu — quick take on Hu et al. 1908.05073. The real content is a single constraint, Eq (1), that lets Alice and Bob use different intensities and sending probabilities in SNS twin-field QKD while keeping the single-photon components of the Z and X windows aligned. The extension is non-obvious, and it pays off: for a 100 km channel imbalance the key rate jumps by tens to hundreds of times compared to the original or loss-modulated variant. The numerical comparisons are honest and finite-size formulas are included.\n\nWhat's genuinely new is the security proof for asymmetric parameters. It follows the standard virtual-protocol chain — tagged model, quasi-purification, decoy-state estimation — and the appendix gives the four-intensity formulas. The mathematics looks plausible, a solid within-subfield contribution. The connection to ref [78] is mishandled: the authors cite a 2019 PRA that likely covers the same asymmetric scenario and never say what is added. That needs to be fixed; if ref [78] truly subsumes the result, the novelty claim collapses.\n\nThe soft spot that matters is the decoy-state step. The paper says in Step 5 that the method applies 'as if the phases δA and δB were not announced' and points to ref [68], but it does not reproduce the argument or adapt it to the asymmetric ratio. The stress-test note raises the worry that Charlie could use a phase-dependent POVM after the phases are announced. I don't think that attack works as stated, because the protocol has Charlie announce his measurement result before the phases are revealed, so his POVM is fixed and cannot depend on the private phases. But the deeper concern is not timing; it's that the post-selected X-window ensemble (the tilde-X windows) is not a phase-randomized mixture of Fock states. Observed error counts in that set are not automatically Poisson-weighted sums of photon-number yields. The proof needs an explicit statement of why the decoy-state linearity survives post-selection. The original ref [68] may cover it, but the paper only cites it. A referee should ask for a self-contained argument or a precise quotation of the relevant theorem.\n\nOverall, the central idea is clean and the numbers make it worth reading. The gaps are presentational and verification-level, not a clear fatal flaw. I'd bring it to a reading group and I'd want it peer-reviewed, with the authors pushed on the ref [78] overlap and the decoy-state justification.","headline":"A clean generalization of SNS twin-field QKD to asymmetric source parameters with a simple ratio constraint; the main open question is whether the decoy-state step in the proof is fully justified in the post-selected setting.","tokens_in":18108,"tokens_out":11983,"would_cite":true,"duration_ms":130246,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":["03.67.Dd","42.81.Gs","03.67.Hk"],"model":"deepseek-v4-flash","headline":"The paper claims that sending-or-not-sending twin-field QKD stays secure under asymmetric source parameters when a single ratio condition holds, and that this gives large key-rate gains on unbalanced channels.","keywords":["twin-field quantum key distribution","sending-or-not-sending protocol","asymmetric source parameters","decoy-state method","security proof","phase-flip error rate","asymmetric channels","finite-key analysis"],"falsifier":"Prepare single-photon-level states directly in the $|\\chi^+\\rangle$ form and send them through a realistic asymmetric channel, then compare their observed error rate with the upper bound inferred from the four-intensity decoy analysis under Eq. (1); if the inferred phase-flip rate systematically underestimates the directly measured error rate of the $Z_1$ events, the equivalence at the center of the proof fails. A numerical search over channel models with intensity-dependent loss that preserves the decoy counting rates while changing the single-photon component would settle the same question.","tokens_in":16964,"feed_emoji":"🔐","tokens_out":7799,"duration_ms":74763,"temperature":0.7,"pith_summary":"This paper extends the sending-or-not-sending (SNS) twin-field quantum key distribution protocol to let Alice and Bob use different source intensities and different sending probabilities. Its main claim is that the protocol stays secure provided the source parameters satisfy the single ratio condition $\\mu_{Ak}/\\mu_{Bk} = [\\epsilon_A(1-\\epsilon_B)\\mu'_A e^{-\\mu'_A}]/[\\epsilon_B(1-\\epsilon_A)\\mu'_B e^{-\\mu'_B}]$ for each decoy intensity $k>0$. The condition makes the single-photon part of the signal windows match the $|\\chi^+\\rangle$ state controlled by the decoy windows, so the decoy-state and tagged-model arguments from the original protocol carry over. The practical consequence is for channels whose two arms differ: numerical simulation with a 100 km length difference gives key rates tens to hundreds of times higher than the original SNS protocol applied to the same setup. The paper also supplies a four-intensity decoy-state parameter-estimation method and finite-key formulas, so the generalization is directly usable in experiments.","feed_headline":"One ratio condition secures asymmetric twin-field QKD","feed_subtitle":"With unequal channels, key rates leap tens to hundreds of times over the old symmetric setup.","key_machinery":"The load-bearing mechanism is the ratio-matching condition of Eq. (1), placed on the source parameters so that, for every decoy intensity $k>0$, the ratio $\\mu_{Ak}/\\mu_{Bk}$ equals the ratio of the single-photon weights $\\epsilon_A(1-\\epsilon_B)\\mu'_A e^{-\\mu'_A}$ and $\\epsilon_B(1-\\epsilon_A)\\mu'_B e^{-\\mu'_B}$. This makes the single-photon component of the effective Z-window state coincide with the $|\\chi^+\\rangle$ state in the X-window decomposition, a two-mode superposition of exactly one photon on Alice's side or Bob's side. With that match, the tagged-model decomposition $\\Omega=\\sum_r q_r\\Omega_r$ reduces security of the full mixed source state to security of its single-photon part, and the decoy-state method estimates the phase-flip error rate $e^{ph}_1$ from X-window data. The final key length is then $N_f = n_1[1-H(e^{ph}_1)] - f n_t H(E_Z)$, with $n_1$ the estimated number of single-photon effective events and $E_Z$ the bit-flip error rate in signal windows.","core_discovery":"The central claim is that symmetric source parameters are not needed for secure sending-or-not-sending twin-field QKD; what is needed is one ratio condition on the two users' intensities and sending probabilities. Under that condition, the single-photon component of the signal-window state is proportional to $\\mu_{A1}|10\\rangle\\langle10|\\otimes|10\\rangle\\langle10| + \\mu_{B1}|01\\rangle\\langle01|\\otimes|01\\rangle\\langle01|$, which is exactly the $|\\chi^+\\rangle$ component controlled by the decoy-window analysis. The security proof proceeds through virtual protocols and reductions that connect the effective Z-window state to the X-window decoy states, so the phase-flip error rate of the key bits can be bounded from observed decoy data. Finite-key formulas are then given, and numerical simulation shows large key-rate gains for asymmetric channel losses.","pith_inferences":["My inference: the ratio condition can be read as an impedance-matching condition between the two arms, and the same construction could be carried over to related twin-field variants that currently assume identical sources by identifying their analogous single-photon component.","My inference: an adaptive implementation could recompute source intensities in real time to keep Eq. (1) satisfied as channel losses drift, which would make the protocol more robust in field deployment than fixed symmetric settings.","My inference: the numerical gap over the approach of adding compensating loss to the shorter channel grows with channel asymmetry, so the protocol is most valuable precisely when the two arms are very different."],"forward_implications":["Alice and Bob can choose source intensities matched to their own channel losses instead of being forced to use identical settings.","On a 100 km difference between the two channel lengths, the optimized key rate is tens to hundreds of times higher than the original SNS protocol in the paper's simulations.","The four-intensity decoy-state formulas give explicit lower and upper bounds for the single-photon counting rate and phase-flip error rate, so the protocol is implementable with finite data.","Setting Alice's and Bob's parameters equal recovers the original SNS protocol as a special case.","Because the security reduction does not depend on the untrusted third party's honesty, the measurement-device-independent character of SNS twin-field QKD is preserved in the asymmetric-source version."],"supporting_citations":[{"why":"the original SNS protocol whose security structure and real protocol this work generalizes to asymmetric parameters.","marker":"[68]"},{"why":"introduces twin-field QKD and the measurement-device-independent setup that makes square-root-of-transmittance key rates possible.","marker":"[67]"},{"why":"supplies the tagged-model reduction used to pass from security of the full mixed source state to security of its single-photon component.","marker":"[10]"},{"why":"provides the tagged-model security framework used to bound the contribution of non-single-photon events in Z windows.","marker":"[11]"},{"why":"the decoy-state method that lets the protocol estimate single-photon counting rates and phase-flip errors from observed multi-intensity data.","marker":"[13]"},{"why":"the finite-data SNS analysis whose formulas for lower-bounding counting rates and upper-bounding phase errors are adapted to the four-intensity method.","marker":"[84]"},{"why":"the finite-key-size analysis that supplies the secret-key length formula with composable security parameters.","marker":"[85]"},{"why":"the large-deviation bound used to pass from observed counts to expected values in finite-size parameter estimation.","marker":"[86]"},{"why":"the universally composable security definition used for the final finite-key security statement.","marker":"[87]"}],"fun_headline_variants":["Asymmetric twin-field QKD: one ratio condition unlocks gains","General SNS protocol: asymmetric sources, higher key rates","Drop symmetric-source rule: ratio condition secures TFQKD","Twin-field QKD goes asymmetric with a single condition"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The proof depends on the assumption that the single-photon component of the signal windows is statistically interchangeable with the $|\\chi^+\\rangle$ state used in the decoy windows, so that the phase error rate measured on decoy data genuinely bounds the phase error of the key bits.","fun_headline_variants_meta":{"raw":{"variants":["Asymmetric twin-field QKD: one ratio condition unlocks gains","General SNS protocol: asymmetric sources, higher key rates","Drop symmetric-source rule: ratio condition secures TFQKD","Twin-field QKD goes asymmetric with a single condition"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000526,"raw_usage":{"total_tokens":2466,"prompt_tokens":797,"completion_tokens":1669,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":413,"completion_tokens_details":{"reasoning_tokens":1600}},"tokens_in":413,"tokens_out":1669,"duration_ms":12518,"temperature":1.0,"reasoning_tokens":1600,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-14T13:24:48.722544+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Prepare single-photon-level states directly in the $|\\chi^+\\rangle$ form and send them through a realistic asymmetric channel, then compare their observed error rate with the upper bound inferred from the four-intensity decoy analysis under Eq. (1); if the inferred phase-flip rate systematically underestimates the directly measured error rate of the $Z_1$ events, the equivalence at the center of the proof fails. A numerical search over channel models with intensity-dependent loss that preserves the decoy counting rates while changing the single-photon component would settle the same question.","supporting_citations":[{"cited_title":"Pirandola, C","cited_arxiv_id":null,"evidence_quote":"the original SNS protocol whose security structure and real protocol this work generalizes to asymmetric parameters."},{"cited_title":"Wang, X.-T","cited_arxiv_id":null,"evidence_quote":"introduces twin-field QKD and the measurement-device-independent setup that makes square-root-of-transmittance key rates possible."},{"cited_title":"Grasselli and M","cited_arxiv_id":null,"evidence_quote":"the finite-data SNS analysis whose formulas for lower-bounding counting rates and upper-bounding phase errors are adapted to the four-intensity method."}],"review_version":1}