{"id":"abbf2231-711f-434a-ac82-994c3fad5f53","arxiv_id":"2411.11299","paper_version":1,"verdict":"REJECT","confidence":"MODERATE","novelty_score":5.0,"correctness_risk":"high","formal_verification":"none","parameter_count":3,"one_line_summary":"A single-photon-based receiver-device-independent QSDC protocol is proposed, with claimed efficiency and distance advantages over DI QSDC, but the security proof is incomplete.","lead":"This paper proposes a quantum secure direct communication protocol that uses a trusted single-photon source and treats the receiver's devices as black boxes. The authors claim it matches measurement-device-independent security with far higher efficiency than device-independent QSDC, but the security proof only covers a specific attack.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The Step 3/5 security check is degenerate: with secret random bases the theoretical P1(g=0) is always ~1/2, so a classical fair-coin device passes and the claimed black-box certification is vacuous.","rationale":"The central claim is that RDI QSDC reaches MDI-level security using only observed statistics from black-box receiver devices. For that claim, the Step 3/5 statistical tests must imply a bound on Eve's information about the encoded message. The analysis in Sec. III only treats the blinding attack and explicitly requires P1(g=0) to deviate from 0.5 to be sensitive; Sec. IV simulates P1 as low as 0.001. But under the protocol's own random selection of secret preparation bases and announced random measurement bases, the theoretical P1(g=0) is centered at 1/2, so the required operating points are not available without revealing the bases, which would destroy security. This is not merely a question of stronger attacks; the one statistic used for certification is degenerate. My concern coincides with the reader's weakest_assumption: the average-statistics comparison cannot certify device behavior. The paper's experimental and efficiency arguments, even if correct, do not repair this, because the security premise is what makes them meaningful. A concrete simulation or analytic calculation of Eq. (3) under the stated random rules would settle the issue. The reader's rejection is therefore supported, and no verdict adjustment is needed.","tokens_in":18550,"tokens_out":16481,"duration_ms":179756,"concrete_test":"Implement the protocol exactly as written in Sec. II for n=6, 8, 10 and r=10^6: draw Alice's bases uniformly, draw Bob's bases uniformly without revealing {X1}, and compute P1(g=0) from Eq. (3). If the sample values are within statistical error of 1/2 for all n, then simulate an adversarial receiver device that outputs g=0/1 as an independent fair coin on all test rounds; verify that the Step 3 and Step 5 checks pass for the paper's own threshold convention, while the device's outputs carry no information about the received states. This settles whether the observed statistics can certify the receiving devices; they cannot.","verdict_should_be":"UNCHANGED","load_bearing_attack":"Section II.A Steps 3 and 5 compare the observed P(g=0) with the theoretical value computed from the actual basis pairs (a_i,w_i)/(b_i,d_i). Section III and Fig. 3 treat P1(g=0) as a tunable parameter (0.001, 0.1, ..., 0.5) and claim deviations from 0.5 make Eve's attacks detectable. But in the protocol, Alice's preparation bases {X1} are never announced, and Bob chooses {Y1} uniformly at random. For fixed θ=π/4, the per-photon term in Eq. (3) is cos^2(π(a_i-w_i)/n), and (1/n) Σ_w cos^2(π(a-w)/n) = 1/2 for every n. Hence for large r, E[P1(g=0)] = 1/2 independent of Alice's marginal distribution and of n. The test therefore reduces to checking that the outputs are roughly 50/50. A completely classical receiving device that ignores the photons and emits fair random bits passes this check with high probability. The protocol never certifies that the devices perform the assumed projective measurements, and no steering/Bell inequality or entropy accumulation argument connects the observed statistic to a bound on Eve's information about the S3 message photons. The blinding-attack analysis in Sec. III relies on an operating point P1(g=0) ≠ 0.5 that the protocol's own random-basis procedure cannot produce. This is an internal inconsistency, not merely a missing generality, and it breaks the central claim of MDI-equivalent security.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper proposes a single-photon-based receiver-device-independent quantum secure direct communication (RDI QSDC) protocol. Alice prepares single photons in one of n equator states, sends them to Bob, who stores them and later encodes a message with U0/U1; two rounds of security checking (S1 and S2) are intended to certify the receiving devices as black boxes from the observed measurement statistics, and the message photons S3 are then decoded by Alice. The authors claim that the protocol offers the same security level as MDI QSDC while using only a trusted single-photon source, and they simulate its secrecy message capacity in noisy channels, reporting much longer secure distances and higher efficiencies than DI QSDC.","tokens_in":18819,"tokens_out":4893,"duration_ms":48445,"significance":"If the security claim were established, the protocol would be a practically important step, since it would avoid entangled sources and Bell-state measurements while retaining one-sided device independence, and the reported detection-efficiency thresholds are far below DI QSDC's requirement. The paper also gives a concrete linear-optics implementation and a numerical framework, and it explicitly identifies the blinding attack as a relevant threat. However, the central security argument is not made: the statistical test is not device-independent, and the protocol as specified cannot produce the operating points used in the simulations. The claimed equivalence to MDI QSDC is therefore unsupported.","major_comments":[{"comment":"The security check does not certify the receiving devices. Since the preparation bases {X1} and the measurement bases {Y1} are chosen uniformly at random, and Bob announces {Y1} only after the measurements, the expected value of P1(g=0) over the random basis choices is, for theta=pi/4, (1/n) sum_w cos^2(pi(a-w)/n) = 1/2 for every n and every a. For large r the theoretical distribution that Alice computes in Eq. (3) is therefore approximately the fair-coin distribution. A receiving device that ignores the photons and outputs fair random bits passes the check with high probability, so the protocol never verifies that the devices implement the assumed projective measurements. A Bell inequality, a steering inequality, or an equivalent entropic certificate would be needed, and none is present.","section":"Section II.A, Steps 3 and 5; Eqs. (3) and (6)"},{"comment":"The claimed detection of the blinding attack is based on the premise that the theoretical P1(g=0) deviates from 0.5, but under the protocol's random-basis procedure the expected P1(g=0) is 0.5. The blinding parameter p1p2 only shifts the observed rate toward 1/2, which is indistinguishable from the already expected fair-coin rate. The paper's own admission that the n=4 case is insecure because P1(g=0)=0.5 applies to all n once the bases are averaged. Thus the internal inconsistency is load-bearing: the security check cannot detect the described blinding attack.","section":"Section III, Eq. (7)"},{"comment":"The paper claims that RDI QSDC provides the same security level as MDI QSDC and is immune to all possible attacks on the receiving devices, but the analysis only treats the specific blinding/fake-state attack. There is no security proof for arbitrary adversarial receiving devices: no Bell inequality, no steering inequality, no min-entropy bound, and no composable security definition. Equations (8)-(10) bound Eve's information using ad hoc wiretap-style mutual information expressions, but those bounds depend on error-rate estimates that are not device-independent. This is a missing proof of the central claim, not a presentation issue.","section":"Section III and Section IV, Eqs. (8)-(10)"},{"comment":"Alice's decoding of the message uses her own measurement device, which the protocol treats as a black box. If that device is malicious, it can report arbitrary outcomes while still passing the statistical checks in Steps 3 and 5; the protocol contains no mechanism for Alice to verify that an individual decoded bit is correct. Therefore the protocol does not achieve secure direct communication under its stated assumptions.","section":"Section II.A, Step 6"},{"comment":"The numerical simulation treats P1(g=0) as a free parameter (0.001, 0.1, ..., 0.5) and sets P1(g=0)=P2(g=0), but in the actual protocol this quantity is fixed to approximately 1/2 by the random basis procedure. Consequently the claimed thresholds (e.g., 95.81 km at P1(g=0)=0.001) and the 26x distance and 3415x efficiency comparisons are not attainable under the protocol as described. The numerical results simulate a different, unphysical operating point.","section":"Section IV, Fig. 3 and Eq. (20)"}],"minor_comments":[{"comment":"The phrase 'close to 100 $' should read 'close to 100%'; the percent symbol is missing.","section":"Section V"},{"comment":"The notation 'P1(b = 0)' is inconsistent with the protocol variable 'P1(g = 0)'; please correct the axis labels and text.","section":"Figs. 4 and 5 and accompanying text"},{"comment":"'If the derivation exceeds the tolerable threshold' should be 'If the deviation exceeds the tolerable threshold.'","section":"Section II.A, Step 5"},{"comment":"Equation (7) is typeset unclearly: the notation 'P(1−p1)r' is ambiguous, and the probabilities p1 and p2 are not defined precisely; please rewrite with explicit sums and definitions.","section":"Section III, Eq. (7)"},{"comment":"Equation (16) places an absolute value over the entire expression, which is not how a signed error rate should be defined; the sign of cos(...)[1-sin(...)] matters in the subsequent calculation of total error rates.","section":"Section IV, Eq. (16)"}],"recommendation":"reject","confidential_remarks":"The central problem is not a missing proof that could be patched by adding a Bell inequality: the protocol's own statistical test reduces to a coin-flip test, so a different protocol structure is needed. The claimed operating points in the simulations are not reachable under the protocol's random-basis procedure. I recommend rejection, with the possibility of a fresh submission if the authors can supply a genuine steering- or entropy-based security proof for a modified protocol."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"First, the two things you need to know. The protocol is a legitimate new combination: applying the RDI QKD idea of Ioannou et al. to QSDC with a trusted single-photon source, with a two-round blocking scheme and a concrete all-optical storage loop. That part is coherent and worth reading. Second, the load-bearing security claim—matching MDI security—is not supported, and the check as written is degenerate.\n\nThe paper does several things well. It picks a practical setup (single photons, SPM, storage loop) and gives a numerical method for rate/distance estimates, including a noise model via δθ. The comparison to DI QSDC is a useful sanity check, even if the absolute numbers depend on simplified assumptions.\n\nThe soft spots are serious. Section III only analyzes the blinding attack combined with a fake-state attack, then jumps to 'immune to all possible attacks.' There is no Bell/steering inequality, no entropy accumulation argument, no reduction to a known security proof. The observation is just that the blinding attack changes the average P(g=0), which is only meaningful if the protocol could actually produce a P1(g=0) different from 0.5.\n\nThat is where the trouble is. In Step 3, Alice's preparation bases and Bob's measurement bases are chosen uniformly and independently. For any photon pair, the per-shot probability of g=0 is cos^2(π(a_i-w_i)/n). The average over the random basis choices is 1/2 for every n≥2. So for large r the theoretical P1(g=0) is essentially 1/2, with fluctuations of order 1/√r. The security check therefore reduces to 'is the empirical rate of g=0 close to 50/50?' A fully classical receiving device that outputs fair random bits independent of the incoming light passes this test. The paper's own simulations treat P1(g=0) as a tunable parameter (0.001, 0.1, ..., 0.5), but the protocol does not allow that: the basis-selection procedure fixes the expected value at 1/2. That is an internal inconsistency in the security argument, not a missing technical lemma. The same issue applies to the second round.\n\nThere are smaller issues too: the tolerable threshold is never defined, and the message-fraction factor in the efficiency comparison (1/4 in Eq. 23 versus the surrounding text) is inconsistent.\n\nBottom line: this is a paper for QSDC specialists. The protocol idea is worth engaging with, and a serious referee should see it, but the current version's central claim is not supported by the analysis. The authors would need a real security proof—likely based on steering or entropy accumulation on the observed statistics—before the efficiency and distance comparisons mean anything. My recommendation: send it to review, but expect heavy revision or rejection.","headline":"New protocol combination, but the security check is degenerate and the MDI-level claim is unsupported.","tokens_in":19421,"tokens_out":5010,"would_cite":false,"duration_ms":46050,"reading_group":"maybe","serious_thinker":"no","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":["03.67.Dd","03.67.Hk"],"model":"deepseek-v4-flash","headline":"Single-photon QSDC claims MDI-level security, untrusted receivers.","keywords":["quantum secure direct communication","receiver-device-independent","single-photon source","device-independent security","measurement-device-independent","blinding attack","quantum memory","secrecy capacity"],"falsifier":"A concrete test would be to search for an explicit receiving-device model that reproduces the theoretical distributions $P_1(g=0)$ and $P_2(g=0)$ on all test bases but still gives Eve information about Bob's encoded message; finding such a model would show the claimed MDI-level security does not follow from the statistics check.","tokens_in":18271,"feed_emoji":"🔐","tokens_out":8051,"duration_ms":68564,"temperature":0.7,"pith_summary":"This paper proposes a quantum secure direct communication (QSDC) protocol in which the message is sent directly over the quantum channel without first sharing a key, and the receiving equipment of both parties is treated as untrusted black boxes. The only trusted component is the single-photon source, which the authors argue is nearly on-demand with current technology. Security is claimed to follow solely from comparing the observed statistics of the receivers' measurement outputs with the statistics expected from ideal projective measurements. The paper develops a numerical method for noisy channels and reports that this receiver-device-independent (RDI) protocol reaches the same security level as measurement-device-independent QSDC while offering roughly 26 times the secure distance and about 3415 times the practical communication efficiency of device-independent QSDC.","feed_headline":"Single-photon QSDC claims MDI-level security, untrusted receivers","feed_subtitle":"Protocol treats detectors and memories as black boxes, then beats DI QSDC by 26x distance and 3415x rate.","key_machinery":"The load-bearing object is the basis-dependent measurement-statistics check: Alice prepares each photon in one of $n$ states $|\\psi_{x_i}\\rangle = \\cos\\theta|0\\rangle + e^{i2\\pi x_i/n}\\sin\\theta|1\\rangle$ with $\\theta=\\pi/4$ and $n\\geq3$, $n\\neq4$, and Bob measures with projectors $M_{w_m}=|\\psi_{w_m}\\rangle\\langle\\psi_{w_m}|$. The theoretical distributions (Eqs. (3) and (6)) give the expected probability of outcome $g=0$ for each preparation-measurement basis pair, and the protocol certifies the black-box receiving devices by comparing these with the observed frequencies. The same two-round statistics, together with the assignment of no-click events to the more probable outcome, feed the error rates $E_{AB}$ and $E_{ABA}$ used in the secrecy-capacity simulation.","core_discovery":"The paper's central claim is that RDI QSDC can provide MDI-level security using only a trusted single-photon source, with all receiving devices in both laboratories regarded as black boxes. The parties run two rounds of security checking: Bob measures one subset of photons in randomly chosen bases and Alice later measures another subset in her original preparation bases, and the observed probabilities $P_1(g=0)$ and $P_2(g=0)$ are compared with the theoretical distributions given by Eqs. (3) and (6). Any significant deviation ends the communication; the paper argues that the blinding-plus-fake-state attack shifts these distributions toward 50% and is therefore detectable. Using the secrecy capacity $C_S = I(A:B) - I(B:E)$ from wiretap channel theory, the paper simulates noisy channels and finds, for example, that with $P_1(g=0)=0.1$ the protocol sustains secure communication to about 14.72 km while DI QSDC reaches about 0.561 km, and at 0.5 km the practical efficiency is about 3415 times that of DI QSDC.","pith_inferences":["An unstated implication is that the security proof must bound per-photon leaked information, not just average statistics; a memory that mimics the test distributions while leaking on message photons would be a concrete adversary to exclude.","A testable extension is to repeat the simulation with a finite number of photons and composable security definitions, since the reported capacities assume asymptotic statistics and a uniform channel error.","If the protocol is combined with decoy states or passive sources, the efficiency advantage over entanglement-based QSDC would likely shrink but still persist; quantifying that would require a new simulation."],"forward_implications":["If the security claim holds, QSDC can achieve MDI-level security without entanglement or Bell-state measurements, using only single-photon sources and single-photon measurements.","The protocol detects the blinding attack combined with a fake-state attack, because the attack pushes the outcome statistics toward 50%.","The all-optical storage-loop quantum memory makes the full two-round protocol implementable with current linear-optical technology.","With $P_1(g=0)=0.1$, the simulated secure distance is about 14.72 km, roughly 26 times that of DI QSDC, and the practical communication efficiency at 0.5 km is about 3415 times higher.","There is a trade-off: choosing $P_1(g=0)$ closer to 0.5 improves noise robustness but raises the required detection-efficiency threshold."],"supporting_citations":[{"why":"Introduces the receiver-device-independent QKD framework that this protocol adapts to direct communication.","marker":"[47]"},{"why":"Provides the experimental proof-of-principle of RDI QKD, supporting the practical feasibility of black-box receivers.","marker":"[48]"},{"why":"Defines the DI QSDC protocol whose detection-efficiency threshold, noise tolerance, distance, and efficiency are used as the main comparison baseline.","marker":"[23]"},{"why":"Defines MDI QSDC, the protocol whose security level RDI QSDC claims to match.","marker":"[21]"},{"why":"Describes the blinding attack on single-photon detectors that the protocol analyzes and claims to detect.","marker":"[57]"},{"why":"Supplies the all-optical polarization-insensitive storage-loop quantum memory used in the proposed implementation.","marker":"[56]"},{"why":"Provides the wiretap-channel capacity expression underlying the secrecy-capacity formula.","marker":"[58]"},{"why":"Gives the practical QSDC security analysis whose mutual-information expressions are used for $I(A:B)$ and $I(B:E)$.","marker":"[14]"}],"fun_headline_variants":["Single-photon QSDC hits MDI security, 26x distance over DI","RDI QSDC: 3415x faster than DI, with untrusted detectors","Black-box receivers make QSDC practical: 26x range boost","Trusted source, untrusted detectors: QSDC gets a speedup","MDI-level security from a single photon, no device trust needed"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The protocol's security rests on the assumption that comparing the average measurement outcomes with the expected ideal statistics is enough to confirm the receiving devices are trustworthy; a device that reproduces those averages on the tested bases while leaking information about the message photons would escape detection.","fun_headline_variants_meta":{"raw":{"variants":["Single-photon QSDC hits MDI security, 26x distance over DI","RDI QSDC: 3415x faster than DI, with untrusted detectors","Black-box receivers make QSDC practical: 26x range boost","Trusted source, untrusted detectors: QSDC gets a speedup","MDI-level security from a single photon, no device trust needed"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000278,"raw_usage":{"total_tokens":1731,"prompt_tokens":1099,"completion_tokens":632,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":715,"completion_tokens_details":{"reasoning_tokens":529}},"tokens_in":715,"tokens_out":632,"duration_ms":5803,"temperature":1.0,"reasoning_tokens":529,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-12T18:41:20.930445+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"A concrete test would be to search for an explicit receiving-device model that reproduces the theoretical distributions $P_1(g=0)$ and $P_2(g=0)$ on all test bases but still gives Eve information about Bob's encoded message; finding such a model would show the claimed MDI-level security does not follow from the statistics check.","supporting_citations":[{"cited_title":"Pironio, A","cited_arxiv_id":null,"evidence_quote":"Introduces the receiver-device-independent QKD framework that this protocol adapts to direct communication."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Provides the experimental proof-of-principle of RDI QKD, supporting the practical feasibility of black-box receivers."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Defines the DI QSDC protocol whose detection-efficiency threshold, noise tolerance, distance, and efficiency are used as the main comparison baseline."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Defines MDI QSDC, the protocol whose security level RDI QSDC claims to match."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Describes the blinding attack on single-photon detectors that the protocol analyzes and claims to detect."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Supplies the all-optical polarization-insensitive storage-loop quantum memory used in the proposed implementation."},{"cited_title":"Somaschi, V","cited_arxiv_id":null,"evidence_quote":"Provides the wiretap-channel capacity expression underlying the secrecy-capacity formula."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Gives the practical QSDC security analysis whose mutual-information expressions are used for $I(A:B)$ and $I(B:E)$."}],"review_version":1}