{"id":"df7b73e3-3c5e-4d8c-8add-467df8618589","arxiv_id":"1908.09169","paper_version":2,"verdict":"REJECT","confidence":"MODERATE","novelty_score":5.0,"correctness_risk":"high","formal_verification":"none","parameter_count":2,"one_line_summary":"The WCWZ protocol leaks at least m bits per round and on average more for larger block sizes, but He's proposed replacement is incorrectly specified because X does not flip X-basis qubits.","lead":"Guang Ping He calculates how much private information the WCWZ quantum private comparison protocol leaks and finds it can be worse than his earlier protocol. He then proposes a bit-by-bit protocol that avoids entanglement and quantum memory, but that protocol is flawed for X-basis code qubits.","discovery_kind":"extension","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Improved protocol's bit encoding fails for X-basis code qubits: X acts as identity (up to phase) on |+> and |->, so step vi misreads hB_i=1 as 0 in about half of kept rounds.","rationale":"The reader's weakest assumption correctly identifies the load-bearing flaw. I verified it directly from the protocol text: step ii-1 specifies all four BB84 states; step ii-2 specifies X=|1><0|+|0><1|; step ii-5 keeps only matching-basis rounds; and step vi infers the bit from whether the state changed. Since X is the bit-flip in the Z basis but acts as identity (up to phase) in the X basis, the inference is impossible for X-basis code qubits. The protocol does not restrict to the Z basis and does not use a basis-independent encoding such as applying different unitaries whose actions are distinguishable in both bases. Therefore the central claim—that the improved protocol can compare privately and correctly—fails. This is an internal inconsistency, not a disagreement with external consensus. The cryptanalysis of the WCWZ protocol in Section III, especially Eq. (6), is a separate contribution and appears sound, but the proposed improved protocol is the main new result and its invalidity justifies rejection. A simple exhaustive simulation over the four BB84 states and both measurement bases would settle the concern. Since the reader already recommended REJECT and my analysis confirms that recommendation, the verdict should remain unchanged.","tokens_in":11760,"tokens_out":4592,"duration_ms":49272,"concrete_test":"Run the protocol's encoding subroutine for a single bit with k=0: choose SA in {|0>, |1>, |+>, |->}, set hB_i=1, apply X, measure in the preparation basis, and compare with SA to infer the bit. Repeat for all four states and both bases. The check should record that for SA=|+> or |-> and βA={|+>, |->}, the inferred bit is 0 with certainty, violating step vi. If the protocol is repaired by restricting code qubits to the Z basis or by using a basis-independent encoding, this test should pass.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central claim is that the improved protocol in Sec. IV achieves better security and feasibility. For that claim to hold, step vi must correctly recover hB_i from the code qubit. Step ii-2 encodes hB_i by applying X (if hB_i=1) or I (if 0) to SA, and step ii-5 keeps only rounds in which Alice's measurement basis βA equals the basis in which SA was prepared. This works for Z-basis code qubits: X|0>=|1> and X|1>=|0>. It fails for X-basis code qubits: X|+>=|+> and X|->=-|->, so the measured state is identical to the original (up to a global phase) whether X or I was applied. Step ii-1 prepares code qubits randomly among |0>, |1>, |+>, and |->; hence among retained rounds roughly half have X-basis code qubits, and in those rounds Alice inevitably infers hB_i=0 even when Bob encoded 1. The same error occurs in the reverse direction for hA_i. This is not a subtle security leak but a correctness failure of the proposed protocol, and it undermines the paper's headline advantages. Section V's security analysis assumes the encoding is recoverable, so it does not repair the flaw. The cryptanalysis of the WCWZ protocol (Eq. 6 and the feasibility discussion) appears independent and may stand, but the proposed improved protocol is invalid as written.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The manuscript presents a cryptanalysis of the Wu-Cai-Wu-Zhang (WCWZ) quantum private comparison protocol and proposes an improved protocol that avoids entanglement and quantum memory. The cryptanalysis derives an average information-leakage formula (Eq. (6)) for the WCWZ protocol and argues that it leaks more than the author's earlier protocol in certain regimes. The proposed improved protocol encodes each hash bit by applying X or I to a qubit randomly prepared in one of the four BB84 states, with the receiver measuring in the same basis and inferring the bit from whether the state changed. The central claim is that the improved protocol is more secure and more feasible than WCWZ. However, the encoding step is incorrect for X-basis states: X acts as the identity (up to a global phase) on |+> and |->, so the receiver cannot distinguish X from I for those states. As a result, the improved protocol fails to recover the encoded bits in roughly half of the retained rounds, invalidating the proposed protocol and the security analysis built upon it.","tokens_in":12061,"tokens_out":7835,"duration_ms":73737,"significance":"The information-leakage calculation for the WCWZ protocol in Section III.C is a self-contained analytic derivation with no fitted parameters, and the identification of the grouping typo and the simultaneity issue are useful observations. If the improved protocol were correct, it would indeed offer a practical two-party quantum private comparison without a third party, entanglement, or quantum memory. However, the fatal X-basis encoding error means the central contribution of the paper is not achieved. The cryptanalysis alone, while reasonably sound, is incremental and does not by itself support the paper's headline claims. The manuscript as submitted is therefore not acceptable for publication.","major_comments":[{"comment":"The encoding of hB_i (and symmetrically hA_i) is invalid for X-basis code qubits. Since X|+> = |+> and X|-> = -|->, applying X or I to a code qubit prepared in the X basis leaves the qubit in the same basis state up to a global phase. In Step vi, Alice compares her measurement result with the original state of SA to decide whether hB_i = 0 or 1; for an X-basis code qubit, this comparison always yields 'unchanged' and therefore hB_i = 0, regardless of Bob's actual bit. Step ii-1 randomly prepares all qubits in one of the four BB84 states, and Step ii-5 retains exactly the rounds in which the preparation basis equals the measurement basis beta_A. Among those retained rounds, the code qubit is equally likely to be in the Z or X basis, so about half of all successful rounds produce a wrong hB_i (and similarly for hA_i). The statement in Step ii-5 that the measurement basis is 'also the eigenbasis for S_A'' after Bob applied his unitary transformation X or I' is only correct for Z-basis code qubits. Consequently, the improved protocol does not perform private comparison, and the security analysis in Sections V.A and V.B, which presumes that the encoded bit is recoverable, does not apply.","section":"Section IV, Step ii-2 and Step vi"},{"comment":"The comparison of information leakage between the improved protocol (and the WCWZ protocol) and the author's previous protocol [5] is not rigorous because the former are exact average values computed from Eq. (6), while the latter are called 'loose upper bounds' in the text (Eqs. (7)-(8) of [5]). Showing that a loose upper bound lies above an exact average does not establish that the actual leakage of [5] is lower; the true leakage could be well below the bound. Therefore, the conclusion that the WCWZ protocol is 'always less secure' for n <= 10, and the statement that the criticism in [12] is 'obviously wrong', are not supported by the presented calculations.","section":"Section VI.A and Fig. 2"}],"minor_comments":[{"comment":"The step numbering is inconsistent: after Steps i-iii, the text introduces 'Step vi' (announcing the states of D''_A/D''_B), then 'Step v' (announcing the code-qubit positions), then another 'Step vi' (comparing measurement results). The first of these should be Step iv, and the subsequent labels should be adjusted accordingly.","section":"Section IV, overall"},{"comment":"The security analysis against external eavesdropping considers only a specific intercept-and-resend strategy and computes a detection probability for that strategy. It does not provide a general security proof against arbitrary coherent attacks. For a protocol that aims to achieve security against external eavesdropping, a more rigorous treatment is needed.","section":"Section V.A"},{"comment":"The proposed 'trivial fix' for the grouping typo—repeating the protocol for each m-bit block—is not described with enough detail to verify that the repeated rounds are independent. In particular, the protocol should specify whether the hash values H(a) and H(b) are recomputed or the same blocks are reused, and how the abort decisions carry over between rounds.","section":"Section III.A"},{"comment":"The phrase '1-to-1 classical hash function H : {0,1}^n -> {0,1}^n' is better described as a permutation or bijection; the term 'hash function' usually implies a many-to-one mapping. This terminology could confuse readers about the security properties of the comparison.","section":"Abstract and Introduction"}],"recommendation":"reject","confidential_remarks":"The manuscript relies heavily on self-citations and the comparison with the author's own earlier protocol is favorable but based on loose bounds. The cryptanalysis portion could potentially be salvaged as a short note about the WCWZ protocol, but the improved protocol as submitted is nonfunctional. The X-basis encoding error is a clear mathematical mistake that undermines the central contribution."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Colleague,\n\nHere's the short version: the paper's real contribution is the information-leakage analysis of the WCWZ protocol, and that part is sound. The improved protocol it advertises is broken as written.\n\nThe new result is Eq. (6), a closed-form average leakage under a random-hash model, which the original WCWZ paper did not provide. The derivation is straightforward and convincing; it also correctly shows that the WCWZ protocol leaks more for m≥14 than the author's earlier bit-by-bit protocol, and that for short strings it does worse even for m=2. The paper also correctly flags that the WCWZ protocol's step 3 only exchanges m Bell states while the hash strings are n bits, so the protocol as originally stated only compares the first m bits. That's a genuine, if trivial, flaw.\n\nThe soft spot is load-bearing. The improved protocol encodes hB_i by applying X or I to a qubit that Alice prepared in one of the four BB84 states. In step ii-5, rounds are kept only if Alice's measurement basis equals the preparation basis. For Z-basis qubits, X flips the bit and the encoding works. For X-basis qubits, X|+⟩=|+⟩ and X|−⟩=−|−⟩, so the state is unchanged up to a global phase. The receiver therefore sees the same measurement outcome whether Bob applied X or I, and will read hB_i=0 even when Bob sent 1. Since roughly half of the kept rounds have X-basis code qubits, the protocol fails as a correctness matter, not a subtle security leak. The same problem appears in the reverse direction for hA_i. Neither the security analysis in Section V nor the comparison in Section VI addresses this; they both assume the encoding is recoverable.\n\nA fix exists: restrict code qubits to the Z basis (or use a basis-independent encoding) and keep the decoy states as the only basis-randomized elements. That would be a modest revision. But as submitted, the central claim of the paper—that the improved protocol is both more secure and more feasible—is false.\n\nThe cryptanalysis of WCWZ stands independently and is worth preserving. The paper deserves a serious referee, because the leakage result is real and the protocol flaw is fixable, but I would not cite the improved protocol in its present form. If you work on quantum private comparison, the Eq. (6) analysis is worth knowing.\n\nRecommendation: send to peer review, with the expectation of substantial revision to the protocol section.","headline":"The leakage calculation for the WCWZ protocol is new and sound, but the proposed improved protocol fails as written because X does not flip X-basis code qubits.","tokens_in":12552,"tokens_out":2257,"would_cite":true,"duration_ms":19505,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":["03.67.Dd","03.67.Ac"],"model":"deepseek-v4-flash","headline":"A leaner two-party quantum private comparison protocol needs no entanglement and no quantum memory, and leaks less information than the WCWZ scheme.","keywords":["quantum private comparison","cryptanalysis","information leakage","BB84 states","decoy states","quantum cryptography","two-party secure computation","no quantum memory"],"falsifier":"Prepare a code qubit as |+>, set Bob's bit to 1 so he applies X, and have Alice measure in the {|+>,|->} basis: the measured state is |+>, identical to the original, so Alice infers bit 0 and the comparison of an unequal pair comes out equal. This single round contradicts the improved protocol's claimed correctness.","tokens_in":11535,"feed_emoji":"⚛️","tokens_out":5547,"duration_ms":51362,"temperature":0.7,"pith_summary":"This paper re-examines the Wu-Cai-Wu-Zhang (WCWZ) quantum private comparison protocol and calculates how much information it actually leaks to the participants. It finds that the WCWZ protocol always leaks more than the author's earlier protocol when a grouping parameter m≥14, and also leaks more for short strings at lower m. The paper then proposes an improved protocol that compares the hash values bit by bit (m=1), using only single qubits prepared in BB84 states, with no Bell pairs and no quantum memory. The claimed result is better security and much greater feasibility: the improved protocol leaks less than WCWZ for any string length, and can be implemented with current technology.","feed_headline":"Quantum private comparison without entanglement or memory","feed_subtitle":"A new protocol compares secret bits one at a time and claims to leak less than rival schemes.","key_machinery":"The mechanism that carries the improved protocol is a decoy-protected, bit-by-bit comparison of hash values. For each bit i, Alice sends a qubit randomly chosen from |0>, |1>, |+>, or |->; Bob measures k of the qubits immediately as decoys and applies the Pauli X gate (for h_i=1) or the identity (for h_i=0) to the remaining code qubit, then returns it with fresh decoys. Alice measures all returned qubits in the same basis she used to prepare the original state, and infers the bit by checking whether the code qubit changed. The security argument is that an external eavesdropper cannot know which qubit is the code qubit and is detected by decoy checks with probability that drops as (7/8)^{$\\alpha$ k}; the internal-attack argument relies on simultaneity in step v to keep the probability of h_i equal to 1/2.","core_discovery":"The central claim is that the WCWZ protocol's information leakage, quantified in Eq. (6), is unnecessarily high and that a bit-by-bit variant removes the gap. Concretely, when Alice and Bob compare m hash bits at once, they always learn m bits of each other's data; with probability 1-$2^{{-m}}$ they abort after the first round and have leaked m bits, and with probability $2^{{-m}}$ they continue, so the expected leakage is the sum in Eq. (6). Setting m=1 gives the improved protocol's leakage, which is below the WCWZ value for every m≥2 and every string length. The paper also identifies two correctness issues in WCWZ: it compares only the first m bits unless modified, and it requires simultaneous announcement, which the author argues is an unstated assumption.","pith_inferences":["The correctness of the improved protocol depends on the encoding being basis-dependent: applying X to |+> or |-> does not flip the state to its orthogonal partner, so for code qubits prepared in the X basis Alice would infer the wrong bit. Restricting code qubits to the Z basis would restore correctness at the cost of discarding half the rounds.","The same X-flip assumption is already implicit in the WCWZ protocol's steps 6 and 8; any security or leakage comparison between the two protocols should be re-run after fixing this encoding issue.","The leakage formula assumes hash bits are independent and uniformly random; for real secrets with structure, the expected leakage could differ, though the rank order of the protocols may persist.","If simultaneity is truly available, the appendix's coin-flipping argument suggests the no-go theorems would be violated, so the practical availability of the protocol's step v is itself a nontrivial physical assumption."],"forward_implications":["If the improved protocol is correct, two-party quantum private comparison no longer requires Bell states or long-term quantum memory; only single-qubit preparation and immediate measurement are needed.","The leakage formula Eq. (6) implies that grouping hash bits (m≥2) never helps: the minimal leakage for the WCWZ-style approach is at m=1.","For m≥14 the WCWZ protocol is strictly worse than the author's 2017 protocol for any string length; for short strings the same is true even for m=2 and m=13.","With bit-by-bit comparison, the average information leaked saturates at about 2 bits, independent of the string length n.","The protocol still requires simultaneous announcement in step v; if simultaneity is unavailable, the leakage increases, as the author notes."],"supporting_citations":[{"why":"The WCWZ protocol under cryptanalysis; supplies the steps whose leakage and correctness are examined.","marker":"[12]"},{"why":"The author's earlier two-party protocol, used as the baseline for leakage comparisons and as the source of the loose upper bound.","marker":"[5]"},{"why":"Lo's impossibility result for unconditionally secure two-party quantum computation, which frames why protocols are only required to resist internal attacks.","marker":"[2]"},{"why":"Colbeck's impossibility result, cited alongside [2] to justify the two-party security model.","marker":"[3]"},{"why":"Lo-Chau no-go theorem for quantum coin flipping, used to argue that simultaneity is a nonstandard assumption.","marker":"[13]"}],"fun_headline_variants":["Quantum comparison without entanglement or memory reduces leak","Bit-wise quantum private comparison: less data leak, no memory","Improved quantum private comparison: no entanglement, lower leak","Quantum protocol fix: bit-by-bit comparison cuts info leak","New quantum private comparison: simpler setup, less info leak"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The protocol's bit-inference rule assumes that applying X to the code qubit always flips it to the orthogonal state within the preparation basis; this holds for |0> and |1> but not for |+> and |->, so rounds with X-basis code qubits give wrong comparison results.","fun_headline_variants_meta":{"raw":{"variants":["Quantum comparison without entanglement or memory reduces leak","Bit-wise quantum private comparison: less data leak, no memory","Improved quantum private comparison: no entanglement, lower leak","Quantum protocol fix: bit-by-bit comparison cuts info leak","New quantum private comparison: simpler setup, less info leak"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000309,"raw_usage":{"total_tokens":1705,"prompt_tokens":825,"completion_tokens":880,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":441,"completion_tokens_details":{"reasoning_tokens":802}},"tokens_in":441,"tokens_out":880,"duration_ms":8759,"temperature":1.0,"reasoning_tokens":802,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-14T11:21:10.781701+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Prepare a code qubit as |+>, set Bob's bit to 1 so he applies X, and have Alice measure in the {|+>,|->} basis: the measured state is |+>, identical to the original, so Alice infers bit 0 and the comparison of an unequal pair comes out equal. This single round contradicts the improved protocol's claimed correctness.","supporting_citations":[{"cited_title":"Kent, Phys","cited_arxiv_id":null,"evidence_quote":"The WCWZ protocol under cryptanalysis; supplies the steps whose leakage and correctness are examined."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"The author's earlier two-party protocol, used as the baseline for leakage comparisons and as the source of the loose upper bound."},{"cited_title":"X⌈ n m ⌉−1 = {hA ⌈ n m ⌉∗m+1, ..., h A n−1}","cited_arxiv_id":null,"evidence_quote":"Lo's impossibility result for unconditionally secure two-party quantum computation, which frames why protocols are only required to resist internal attacks."},{"cited_title":"publish the positions and the measurement 3 bases of D′ A and D′ B simultaneously","cited_arxiv_id":null,"evidence_quote":"Colbeck's impossibility result, cited alongside [2] to justify the two-party security model."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Lo-Chau no-go theorem for quantum coin flipping, used to argue that simultaneity is a nonstandard assumption."}],"review_version":1}