{"id":"a958ffe8-ae38-429e-b780-2da7c9611a6e","arxiv_id":"2411.13943","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":7.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":2,"one_line_summary":"A field trial of twin-field QKD with independent optical frequency combs produced a finite-size secure key rate of 0.53 bit/s at 546 km and an asymptotic rate of 0.12 bit/s at 603 km over deployed fiber.","lead":"Researchers generated secure quantum keys over 546 km and 603 km of deployed telecom fiber using two independent optical frequency combs, with no shared laser frequency between the two ends. The field trial shows that twin-field QKD can work outside the lab in a network-friendly configuration, which is an important step toward long-haul quantum-secured communication links.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The 546-km finite-size key claim rests on SNS-AOPP security proofs that assume continuously phase-randomized WCSs, but the encoder uses 16 discrete phase slices; the paper supplies no bound on the resulting source deviation.","rationale":"I considered the unreported security parameters in Eq. A2 and the apparent Eq. A1 mismatch in the 452-km asymmetric run. The former is a disclosure gap; the latter affects a supporting claim, not the central 546/603-km results. The 16-slice phase source is the most load-bearing concern because it attacks the security argument underneath every reported SKR, including the 546-km finite-size rate. The paper is otherwise credible: it reports a field deployment with independent OFCs, an open quantum channel, detailed component loss tables, and good agreement between measured rates and simulations. However, the proof-to-implementation gap is real and unquantified: the experimental source is not the phase-randomized WCS assumed by the cited decoy-state bounds, and the finite key at 546 km is small enough that even a modest per-pulse deviation needs to be accounted for rather than asserted away. This is exactly the condition the reader attached, so the verdict remains CONDITIONAL.","tokens_in":17336,"tokens_out":17281,"duration_ms":184125,"concrete_test":"Re-derive the SNS-AOPP key rate for the actual 16-slice source, e.g. by computing rho_16's photon-number statistics or a numerical/analytical security proof for M=16 phase slices, and propagate the deviation through the decoy analysis and Eq. A2 using Tables V-VI parameters and explicit eps_cor, eps_PA, and eps_hat for the 546.61-km run. If the composable finite-size rate stays at or above 0.53 bit/s, the concern is resolved; if it is lower or negative, the 546-km headline claim is unsupported and the paper should be revised to use a compatible phase-randomization method or add the extra penalty.","verdict_should_be":"UNCHANGED","load_bearing_attack":"Central claim: finite-size SKR 0.53 bit/s at 546.61 km (Sec. IV, Table VI) is certified by the SNS-AOPP formula Eq. A2, whose decoy-state estimates for n'_1 and e'^ph_1 come from Refs. 25-28 and 37. Those proofs model each WCS as phase-randomized, rho = (1/2pi)∫ dtheta |sqrt(mu)e^{itheta}><sqrt(mu)e^{itheta}| = e^{-mu} Σ_n (mu^n/n!) |n><n|. The implementation (Sec. IV, App. B.2.b) instead draws each pulse phase uniformly from 16 values theta in {0, pi/8, ..., 15pi/8}. The actual source rho_16 = (1/16)Σ_k |sqrt(mu)e^{i pi k/8}><...| is not Fock-diagonal: it retains coherences rho_{n,n+16m} approximately e^{-mu} mu^{n+8m}/sqrt(n!(n+16m)!), e.g. |rho_{0,16}| ≈ 4.7e-10 at mu = 0.493. The cited decoy bounds therefore do not apply as written, and no trace-distance bound or adapted proof is given to show the induced error is covered by the finite-size terms in Eq. A2. This is a correctness gap, not just a missing parameter: the total finite key is only N·R ≈ 2.9e4 bits, and the per-pulse source deviation is not quantified against the security parameters.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper reports a field trial of twin-field quantum key distribution (TF-QKD) in which Alice and Bob are equipped with independent optical frequency combs and no optical frequency dissemination channel is used. Over a deployed 427 km fiber link extended with spools, the authors report a finite-size secure key rate of 0.53 bit/s at 546.61 km (100.13 dB total loss), an asymptotic rate of 0.12 bit/s at 603.87 km, and a finite-size rate of 16.06 bit/s over an asymmetric 452.46 km link. The protocol is a four-intensity sending-or-not-sending (SNS) variant with actively odd-parity pairing (AOPP) and zig-zag post-processing. The experimental sections provide detailed stabilization data for phase, frequency, timing, and polarization, and the rate calculations use the published SNS-AOPP formula with measured counts and error rates.","tokens_in":17688,"tokens_out":6107,"duration_ms":63450,"significance":"If the security claim is valid, this is a significant experimental advance: it is, to my knowledge, the first field demonstration of TF-QKD with independent combs and an open quantum channel, it exceeds 100 dB link loss in the field, and it shows tolerance to 44 km channel asymmetry. The reported stabilization results, the detailed count tables, and the use of a published key-rate formula are strengths that make the experimental part largely reproducible. The main uncertainty is the security certification of the finite-size key rates, which rests on closing a gap between the implemented source and the assumptions of the cited security proofs and on specifying the composable security parameters.","major_comments":[{"comment":"The encoder randomizes each quantum pulse phase over 16 discrete values, theta in {0, pi/8, ..., 15pi/8}, described as meeting the phase-randomization requirement. However, the SNS-AOPP security proofs cited for Eq. A2 (Refs. 25-28, 37) model each weak coherent pulse as continuously phase-randomized, which yields a Fock-diagonal mixture. The actual 16-slice source retains off-diagonal Fock coherences, e.g., between |0> and |16> for mu=0.493. The manuscript provides no trace-distance bound, no adapted proof, and no citation to a result showing that this discrete phase randomization is covered by the finite-size terms in Eq. A2. Because the finite-size key rate at 546.61 km is computed from the cited formulas, this is a load-bearing gap in the security claim. Please either supply a quantitative bound on the source deviation and show that it is absorbed into the security parameters, or revise the security argument accordingly.","section":"Section IV and Appendix B.2.b"},{"comment":"The finite-size key-rate formula contains security parameters epsilon_cor, epsilon_PA, and epsilon_hat, but their numerical values are never stated in the paper. The reported finite-size rates (0.53 bit/s at 546.61 km and 16.06 bit/s at 452.46 km) cannot be independently checked or associated with a composable security level without these values. Please state the chosen parameters and, if a specific overall security parameter is claimed, explain how the individual epsilons combine to yield it.","section":"Appendix A, Eq. A2"}],"minor_comments":[{"comment":"The notation \"Detected AB ab\" is confusing: the first two letters are meant to denote Alice's and Bob's bases and the digits the intensity indices, but the caption's explanation \"where 'A' ('B') indicates the X (Z) basis\" is ambiguous because A and B are also the user labels. Please clarify with an explicit example, e.g., \"Detected XX20 means Alice uses the X basis with intensity mu_2 and Bob uses the X basis with intensity mu_0.\"","section":"Table VI caption and Section IV"},{"comment":"Several SKR entries are left blank (e.g., asymptotic for 546.61 and 452.46 km, finite-size for 603.87 km). Please mark unavailable entries with an explicit dash or footnote, and state in the text why they are not reported (for example, that the finite-size calculation was not performed for 603.87 km because the data set was limited by fiber access time).","section":"Table VI"},{"comment":"The sentence comparing the achieved phase-drift reduction factor with the theoretical prediction of lambda_c / |lambda_c - lambda_q| about 1900 would benefit from a brief derivation or a pointer to the cited work, as the reader is expected to infer the origin of the factor.","section":"Section III"},{"comment":"The closing statement that the encoder is capable of supporting all TF-QKD protocols is an unsupported generalization; please restrict it to the protocols actually demonstrated or to the technical features relevant to this work.","section":"Appendix B.2.b"}],"recommendation":"major_revision","confidential_remarks":"The paper's experimental achievement is substantial and the data presentation is detailed. The main technical risk is the security certification: the discrete 16-slice phase randomization is a real deviation from the continuous phase-randomization assumption of the cited proofs, and the missing epsilon parameters prevent an independent check of the finite-size rates. These are fixable with additional analysis and parameter disclosure, so I do not recommend rejection, but the revision must address them explicitly before the finite-size key-rate claims can be considered fully supported."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Short version: this is the first field trial of TF-QKD with independent optical frequency combs and no frequency dissemination, over deployed fiber, reaching 546 km with finite-size key and breaking the 100 dB loss barrier. The engineering is credible, and the paper honestly reports its stabilization numbers. The main soft spot is that the finite-size security claim rests on a source assumption the implementation doesn't quite meet, and the paper doesn't quantify the difference.\n\nThe genuinely new thing is the open-channel architecture with independent OFCs at sites 300 km apart. Prior field trials needed a common laser frequency, periodic recalibration, or a closed-loop dissemination fiber. Here the two combs are locked to local rubidium references, and dual-band stabilization keeps the residual phase at 0.20 rad and timing jitter at 8.4 ps. The 44 km asymmetry result addresses a real network question, and the measured rates exceed the PLOB bound by healthy margins. The data in Table VI are internally consistent. This is an important milestone for real-world TF-QKD.\n\nThe soft spots are about verification, not about the core experiment. First, the encoder uses 16 discrete phase slices, while the cited SNS-AOPP proofs assume continuously phase-randomized sources. The paper states that 16 slices meet the requirement but gives no trace-distance bound or reference to a security proof for a discretized source. The stress-test numbers are right: the leading coherence term is around 5e-10 at mu_Z = 0.493, so the deviation is tiny, but 'tiny' is not a proof. As written, this is a real gap in the finite-size key claim, though a simple bound would close it. Second, the security parameters in Eq. A2 (epsilon_cor, epsilon_PA, epsilon_hat) are not given values, so the 0.53 bit/s rate cannot be independently checked against a composable security statement. Third, there are no error bars or raw data for the headline rates. These are gaps a serious referee would want closed, but they are not demonstrated errors.\n\nBottom line: this paper deserves peer review and likely publication after revision. I'd send it to a referee who knows TF-QKD security proofs and ask for the phase-randomization justification and the missing security parameters. For the community, it's a reading-group paper and citable for the field-trial milestone, though I'd wait for the revised security analysis before quoting the exact finite-size rate.","headline":"A credible field first for OFC-based TF-QKD without frequency dissemination, but the finite-size key claim needs a phase-randomization patch.","tokens_in":18285,"tokens_out":3879,"would_cite":true,"duration_ms":38727,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["81P94"],"pacs":["03.67.Dd"],"model":"deepseek-v4-flash","headline":"A field trial shows twin-field QKD can work over 546 km with independent optical frequency combs and no shared frequency reference.","keywords":["twin-field quantum key distribution","optical frequency comb","field trial","open quantum channel","sending-not-sending protocol","finite-size key rate","100 dB link loss","fiber asymmetry"],"falsifier":"Take the emitted phase values from the encoder and compute the statistical distance between their distribution and a continuous uniform phase; if that distance exceeds the tolerance allowed by the composable security proof, then the 0.53 bit/s finite-size rate at 546 km is not supported. A simpler check is to recompute Eq. (A2) with the actual values of $\\epsilon_{\\mathrm{cor}}$, $\\epsilon_{\\mathrm{PA}}$ and $\\hat{\\epsilon}$; the claimed key rate stands only if the result remains positive.","tokens_in":17114,"feed_emoji":"🔐","tokens_out":11269,"duration_ms":102040,"temperature":0.7,"pith_summary":"This paper reports a field trial of twin-field quantum key distribution (TF-QKD) in which two independent optical frequency combs, installed at sites 300 km apart in a straight line, drive the protocol over a deployed 427 km fiber link without any shared optical frequency reference. The authors claim that this open-channel setup delivers a finite-size secure key rate of 0.53 bit/s at 546 km and an asymptotic rate of 0.12 bit/s at 603 km, making it the first field trial to exceed 100 dB of link loss. They also demonstrate operation with 44 km of fiber asymmetry. The significance is that earlier long-distance TF-QKD field tests needed a frequency-dissemination channel between users; this design removes that requirement, which is what a scalable, switchable quantum network would need.","feed_headline":"First field quantum-key test to break the 100 dB fiber-loss barrier","feed_subtitle":"Independent optical frequency combs deliver 0.53 bit/s at 546 km without any shared frequency link.","key_machinery":"The central mechanism is coherent dual-band phase stabilization—locking the phase of a strong classical reference tone at one wavelength and transferring that lock to the quantum signal at a different wavelength—so that two remote lasers interfere as if they shared a frequency reference. Each user's independent electro-optic comb provides three phase-coherent lines: a quantum wavelength, a strong channel reference, and a timing wavelength. Charlie uses the strong reference for a fast phase-locking loop and a slow loop on the quantum wavelength, while rubidium-referenced comb spacing, automated time alignment, and polarization feedback keep the interference stable. The protocol layer is the SNS-AOPP scheme with four intensities, 16 discrete phase slices for phase randomization, and the zig-zag finite-size key-rate formula (Eq. A2).","core_discovery":"Using the sending-not-sending (SNS) variant of twin-field QKD with four pulse intensities, actively odd-parity pairing (AOPP), and the zig-zag finite-size analysis, the authors establish that TF-QKD works in the field over an open quantum channel: each user generates an electro-optic optical frequency comb locked to a local rubidium clock, and no optical frequency is disseminated between the users. Over a deployed 427 km fiber link they measure a finite-size secure key rate of 0.53 bit/s at 546.61 km (100.13 dB loss) and an asymptotic rate of 0.12 bit/s at 603.87 km (108.59 dB loss), and at 452.46 km with 44 km fiber asymmetry they obtain an asymptotic rate of 24.28 bit/s and a finite-size rate of 16.06 bit/s. All measured rates beat the repeaterless PLOB bound, and the 546.61 km point is claimed as the first field trial to break the 100 dB link-loss barrier for QKD.","pith_inferences":["If the 16-slice phase randomization is later shown to meet the continuous-phase assumption in the security proof, the same hardware could plausibly be pushed to longer distances, since the asymptotic rate at 603 km is still positive.","This open-channel design implies that TF-QKD nodes could be added to an existing fiber route by installing local frequency combs, without laying a parallel frequency-dissemination fiber; that would cut the infrastructure cost of multi-city quantum networks.","Swapping the rubidium clocks for references with higher accuracy should reduce the residual phase drift and improve the X-basis error rate, which would raise the secure key rate at a fixed distance.","A direct independent check of the paper's finite-size claim would be to recalculate the key rate once the numerical values of $\\epsilon_{\\mathrm{cor}}$, $\\epsilon_{\\mathrm{PA}}$ and $\\hat{\\epsilon}$ are supplied; until then, the 0.53 bit/s number is best read as conditional on those unpublished parameters."],"forward_implications":["Twin-field QKD can operate over an open quantum channel with only local frequency references, eliminating the closed-loop fiber configuration that earlier long-distance field trials required.","The finite-size key rate of 0.53 bit/s at 546 km exceeds the repeaterless PLOB bound by a factor of 7.57, showing the repeater-like scaling survives in the field.","At 452 km with 44 km fiber asymmetry, the system still produces a finite-size key rate of 16.06 bit/s, so unequal network arms need not block deployment.","A positive asymptotic key rate of 0.12 bit/s at 603 km extends the demonstrated field reach of TF-QKD beyond the previous 511 km field record."],"supporting_citations":[{"why":"Introduces twin-field QKD and the repeater-like rate-loss scaling that this field trial is designed to test.","marker":"[12]"},{"why":"Supplies the dual-band stabilization method used here to lock the differential phase over hundreds of kilometers.","marker":"[16]"},{"why":"Demonstrates electro-optic comb based TF-QKD without optical frequency dissemination in the lab; this paper's open-channel field configuration builds directly on it.","marker":"[18]"},{"why":"Earlier 511 km field trial linking two cities; provides the deployed-fiber distance record and automated time alignment this experiment extends.","marker":"[23]"},{"why":"Defines the sending-not-sending protocol, the variant of TF-QKD used for key generation.","marker":"[25]"},{"why":"Extends SNS to asymmetric source parameters, supporting the 44 km fiber-asymmetry result.","marker":"[26]"},{"why":"Supplies actively odd-parity pairing, which the post-processing uses to lower the bit-flip error rate.","marker":"[27]"},{"why":"Provides the zig-zag finite-size analysis used to compute the finite-size secure key rates.","marker":"[28]"},{"why":"Gives the repeaterless PLOB bound that the measured rates are compared against to show repeater-like behavior.","marker":"[29]"},{"why":"Provides the composable security proof for the SNS-AOPP post-processing, the basis for claiming the generated keys are secure.","marker":"[37]"}],"fun_headline_variants":["Field QKD breaks 100 dB loss with independent combs","546 km field QKD without shared frequency link","Open-channel QKD: 546 km, no optical frequency dissemination","Independent combs power field QKD past 100 dB"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The load-bearing premise is that the published security proof for the sending-not-sending protocol with continuous random phase still applies to this transmitter, which randomizes the phase in 16 discrete steps and does not report the numerical values of its finite-size security parameters.","fun_headline_variants_meta":{"raw":{"variants":["Field QKD breaks 100 dB loss with independent combs","546 km field QKD without shared frequency link","Open-channel QKD: 546 km, no optical frequency dissemination","Independent combs power field QKD past 100 dB"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000978,"raw_usage":{"total_tokens":4154,"prompt_tokens":946,"completion_tokens":3208,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":562,"completion_tokens_details":{"reasoning_tokens":3140}},"tokens_in":562,"tokens_out":3208,"duration_ms":20034,"temperature":1.0,"reasoning_tokens":3140,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-12T15:42:54.657869+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Take the emitted phase values from the encoder and compute the statistical distance between their distribution and a continuous uniform phase; if that distance exceeds the tolerance allowed by the composable security proof, then the 0.53 bit/s finite-size rate at 546 km is not supported. A simpler check is to recompute Eq. (A2) with the actual values of $\\epsilon_{\\mathrm{cor}}$, $\\epsilon_{\\mathrm{PA}}$ and $\\hat{\\epsilon}$; the claimed key rate stands only if the result remains positive.","supporting_citations":[{"cited_title":"Bersin, M","cited_arxiv_id":null,"evidence_quote":"Introduces twin-field QKD and the repeater-like rate-loss scaling that this field trial is designed to test."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Demonstrates electro-optic comb based TF-QKD without optical frequency dissemination in the lab; this paper's open-channel field configuration builds directly on it."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Earlier 511 km field trial linking two cities; provides the deployed-fiber distance record and automated time alignment this experiment extends."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Provides the zig-zag finite-size analysis used to compute the finite-size secure key rates."},{"cited_title":"Clivati, A","cited_arxiv_id":null,"evidence_quote":"Gives the repeaterless PLOB bound that the measured rates are compared against to show repeater-like behavior."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Provides the composable security proof for the SNS-AOPP post-processing, the basis for claiming the generated keys are secure."}],"review_version":1}