{"id":"0aee5367-08ad-45c3-a4b5-87512bad1439","arxiv_id":"2501.04957","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":5.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":4,"one_line_summary":"Two new parameter estimation models for finite-size analysis of two-decoy MDI-QDS are proposed; numerical simulations show the SMB1 model improves signature rate and transmission distance.","lead":"This paper compares three ways to estimate quantum signals in a measurement-device-independent quantum digital signature protocol, and proposes two new estimation models that sign many bits at once. Simulations show one of the new models, SMB1, gives a higher signature rate and longer distance than the previous one-bit-at-a-time approach.","discovery_kind":"extension","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Multi-message composition of the security bounds is not proven; since the SMB1 gain comes from signing nbits messages from one pool, total failure may scale by nbits and the rates in Fig. 5 may be overestimates.","rationale":"The reader's weakest-assumption identification is correct and points to the most load-bearing gap in the paper. The central claim is not that SMB1-PE has a better estimator in isolation, but that signing multiple bits from one key pool improves the finite-size signature rate while preserving the stated security level. Since Eqs. (4)-(7) are explicitly single-message bounds, extending them to nbits messages requires a composition argument, and none is given. This is a genuine omission rather than a disagreement with consensus: standard QDS security statements are per-signed-message, and multi-use security normally requires either a union bound or a per-use epsilon definition. The proposed concrete test is computationally straightforward because the simulation already optimizes over L and the other parameters; adding the nbits-dependent epsilon_m changes the optimization but not its structure. I do not recommend rejecting the paper outright because the gap is fixable and the numerical methodology is otherwise plausible. The verdict CONDITIONAL remains appropriate, pending a composition proof or a clear per-message security statement. I also note a secondary issue: Eq. (16) appears to use (as + bs)e^{-as-bs} for the single-photon pair contribution, whereas the correct single-photon pair probability is as*bs*e^{-as-bs}; this affects SMB2-PE but not the primary SMB1-PE claim, so I have not made it the headline concern.","tokens_in":11564,"tokens_out":8737,"duration_ms":94426,"concrete_test":"Re-run the parameter optimization and reproduce Fig. 5 with a self-consistent union bound: set the total security level to epsilon_total = 10^-5, use per-message epsilon_m = epsilon_total/nbits in Eqs. (4)-(7), and solve nbits = npool(epsilon_m)/(2L(epsilon_m)) iteratively for each transmission distance and N. If SMB1-PE still achieves a higher rate than SOB-PE under this composition, the central claim survives; if the curves cross or the advantage vanishes, the headline improvement is an artifact of the missing multi-message security proof.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The security analysis in Eqs. (4)-(7) bounds the probabilities P(Robust), P(Repudiation), and P(Forge) for a single signed message, as explicitly stated in the protocol description and in the cited QDS security framework. Section II.C then introduces SMB1-PE, in which the key pool is reused to sign nbits = npool/(2L) messages consecutively, with rate R = npool/(2NL). No union bound, composition theorem, or per-message epsilon allocation is supplied. For the stated security level epsilon = 10^-5 to hold over all signed messages, each of the nbits messages would need to meet a per-message bound of roughly epsilon/nbits, which changes the thresholds sa and sv through Eqs. (5)-(6) and hence changes the required block length L and the claimed rate. Because the advertised improvement of SMB1-PE over SOB-PE comes precisely from signing multiple bits from one key pool, omitting this composition step is load-bearing: if the total failure probability is nbits times the single-message bound, the SMB1 rate advantage in Fig. 5 may shrink or disappear. The manuscript does not state that epsilon is a per-message rather than total security level, and the simulation sets a single security level epsilon = 10^-5 without qualifying it by nbits.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The manuscript analyzes finite-size effects in two-decoy measurement-device-independent quantum digital signature (MDI-QDS) by comparing three parameter-estimation models: the previously used SOB-PE model and two new models, SMB1-PE and SMB2-PE, which sign multiple bits from a single key pool. The paper gives estimators for single-photon counts and error rates, states per-message security bounds for robustness, repudiation, and forging, and presents numerical simulations showing that SMB1-PE yields the highest signature rate and longest transmission distance.","tokens_in":11869,"tokens_out":7979,"duration_ms":76761,"significance":"If the security claims can be rigorously established, the paper offers a practically useful improvement: SMB1-PE reuses the generated key pool for multiple signed bits and thereby raises the finite-size signature rate of MDI-QDS. The comparison of three estimation models with full parameter optimization is a useful contribution. The main obstacle is that the security bounds used to set the thresholds are for a single signed message, while the improved rate is obtained by signing many messages; without a proof that the failure probability composes over messages, the headline rates are not yet established. There is also a dimensional inconsistency in the definition of e_{Z,1} that affects the SMB1 estimator itself.","major_comments":[{"comment":"The security bounds in Eqs. (4)-(7) are stated for a single signed message, but in the SMB1-PE and SMB2-PE models the key pool is used to sign nbits = npool/(2L) messages and the rate is computed as R = npool/(2NL). The manuscript does not provide a union bound, a sequential composition argument, or a statement of whether epsilon = 10^-5 is a per-message or total security level. Since the thresholds sa and sv are determined from these single-message bounds, the total failure probability could be up to nbits times epsilon; restoring a total epsilon would require replacing epsilon by epsilon/nbits in Eqs. (3)-(6), which would change L and hence the rates in Figs. 5 and 6. Because the claimed advantage of SMB1-PE over SOB-PE derives exactly from signing many bits, this missing composition step is load-bearing.","section":"II.C, Eqs. (4)-(7) and (14)-(15)"},{"comment":"In Eq. (11), e_{Z,1} is defined as min{ ceil(n_{Z,1}e_{X,1}/n_{X,1} + (n_{Z,1}+n_{X,1})\\gamma(...)), n_{Z,1} }, which has the units of a count, while in Eq. (13) e_{Z,1} is used as an error rate to which a fluctuation term is added. If e_{Z,1} is intended to be an error count, Eq. (13) should employ e_{Z,1}/n_{Z,1}; if it is intended to be a rate, the expression in Eq. (11) is missing a division by n_{Z,1}. The SMB1-PE simulation curves depend on this definition and should be recomputed with the corrected expression.","section":"II.C, Eq. (11) and Eq. (13)"},{"comment":"The size npool of the key pool is not defined in the text; Fig. 3 labels it but no formula is given relating npool to N, the Z-basis fraction, and the error-test fraction r_ET. Without this definition, Eqs. (14)-(15) and the numerical rates in Fig. 5 cannot be reproduced. Please provide the explicit expression for npool used in the simulations.","section":"II.C, Eq. (14)"}],"minor_comments":[{"comment":"The phrase \"expect with error probability\" should read \"except with error probability\" in several places, including after Eqs. (3), (11), (A4), (A5), and (A7).","section":"Throughout"},{"comment":"In the Introduction, \"non-negativity of data transmission\" should be \"non-repudiation of data transmission.\"","section":"Section I"},{"comment":"The axis labels and tick labels in Fig. 5 are not legible in the provided version; the figure should be regenerated with readable labels so that the numerical results can be assessed.","section":"Figure 5"},{"comment":"Equation (11) introduces three error-probability parameters epsilon'_k,e, epsilon''_k,e, and epsilon'''_k,e, but only epsilon'''_k,e appears in the displayed expression; the roles of the other two parameters are not explained.","section":"II.C, Eq. (11)"}],"recommendation":"major_revision","confidential_remarks":"The main technical gap is the missing multi-message composition of the single-message security bounds. This is a standard and potentially fixable issue, but it must be addressed before the paper can be accepted. The dimensional inconsistency in Eq. (11) also needs correction. If the authors provide a rigorous composition argument (or clearly state per-message security and adjust the rates accordingly), the paper could be publishable."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Quick take: this is a modest but useful engineering paper. It takes finite-key parameter estimation from MDI-QKD and applies it to two-decoy MDI-QDS in a new arrangement: SMB1-PE estimates Z-basis single-photon counts directly from Z data and signs multiple bits from one sifted key pool; SMB2-PE estimates Z counts from X counts. The comparison is well organized and the simulation shows a consistent rate/distance improvement over the standard SOB-PE model, especially for SMB1. No parameter is fitted to the target rate curves, and the security framework is imported from prior QDS work in a straightforward, legitimate way.\n\nThe soft spots are real, and the main one is the one the stress-test flags. Equations (4)-(7) bound robustness, repudiation, and forging for a single signed message, while SMB1/SMB2 sign nbits = npool/(2L) messages from the same pool and report R = npool/(2NL). No union bound or per-message epsilon allocation is given. If the total security level is meant to be epsilon across all nbits signatures, the per-message threshold should be about epsilon/nbits, which changes sa and sv and the required L; the claimed SMB1 advantage may shrink. This is the crux because the improvement comes from multi-bit signing. The authors need to state whether epsilon is per message or total and prove the composition.\n\nThe second soft spot is presentational: Eq. (11) is garbled, Eq. (16) has a bracket mismatch, and Eqs. (12)-(13) mix error counts and rates (eZ,1). These are typos, not conceptual errors, but they prevent full verification.\n\nNovelty is modest: this is a translation of known MDI-QKD finite-key techniques to the QDS setting, not a new primitive. That is fine for a practical paper, but it should be framed as an incremental efficiency gain.\n\nFor a reader in QDS: the paper is worth reading for the rate comparison and for the identification of the multi-bit signing inefficiency. It should go to a serious referee, not be desk-rejected. I would require a clean composition proof and a corrected appendix before accepting; I would not cite the current arXiv version as a secure protocol until that is fixed.","headline":"Practical MDI-QDS rate boost from multi-bit signing, but the missing multi-message security composition is the crux a referee must press.","tokens_in":12415,"tokens_out":6237,"would_cite":false,"duration_ms":66488,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["81P94"],"pacs":["03.67.Dd"],"model":"deepseek-v4-flash","headline":"Signing many bits from a single key pool sharply improves the finite-size signature rate of measurement-device-independent quantum digital signatures.","keywords":["quantum digital signatures","measurement-device-independent QDS","finite-size analysis","parameter estimation","decoy-state method","signature rate","Serfling inequality"],"falsifier":"Recompute the signature rate of SMB1-PE under a complete multi-message composition argument, for instance by multiplying the per-message failure probabilities by the number of signed messages, and check whether the claimed rates at $N = 10^{12}$ and distance 150 km still satisfy the declared security level $\\varepsilon = 10^{-5}$; if they do not, the reported improvement is an artifact of the missing composition step.","tokens_in":11332,"feed_emoji":"🔐","tokens_out":6312,"duration_ms":52627,"temperature":0.7,"pith_summary":"The paper tackles the finite-size effect that dominates the performance of measurement-device-independent quantum digital signatures (MDI-QDS). It proposes two new parameter-estimation models, SMB1-PE and SMB2-PE, that sign multiple bits from one key pool instead of one bit at a time, and compares them with the previously used SOB-PE model on a two-decoy MDI-QDS protocol. Numerical simulations show that the SMB1-PE model is the least affected by finite-size effects and achieves the best signature rate and transmission distance among the three. This matters because raising the rate and reach of MDI-QDS brings information-theoretic signatures closer to practical deployment.","feed_headline":"New method lifts quantum signature rate and range","feed_subtitle":"Signing multiple bits per key pool cuts finite-size penalties in MDI-QDS, extending usable distance.","key_machinery":"The load-bearing object is the parameter-estimation model that converts raw detection data into the single-photon pair counts and error rates used in the security bounds. In SMB1-PE the key step is estimating the Z-basis single-photon error rate as $e_{Z,1} = \\min\\{\\lceil n_{Z,1} e_{X,1}/n_{X,1} + (n_{Z,1}+n_{X,1})\\gamma(n_{Z,1}, n_{X,1}, \\varepsilon''')\\rceil, n_{Z,1}\\}$, then converting it to the per-signature quantities $n_{L,1}$ and $e_{L,1}$ through Serfling-fluctuation bounds, and finally setting $R = n_{\\rm pool}/(2NL)$. The mechanism that carries the improvement is amortization: instead of reserving the Z-basis key material for a single bit, the whole key pool is used to sign multiple messages, spreading the finite-size estimation overhead over many signatures.","core_discovery":"The central claim of the paper is that, for a two-decoy MDI-QDS protocol with security level $10^{-5}$ and pulse numbers $N = 10^{12}, 10^{14}, 10^{16}$, the SMB1-PE model -- which estimates single-photon pair counts directly from Z-basis data and then uses the entire kept key pool to sign $n_{\\rm bits} = n_{\\rm pool}/(2L)$ messages -- delivers the highest signature rate at every transmission distance and is the least affected by finite-size effects. The SMB2-PE model, which infers $n_{Z,1}$ from X-basis counts through a Serfling bound, also outperforms the SOB-PE baseline at all but the farthest distance. At the maximum distance the SMB1-PE and SOB-PE rates converge, since both effectively sign only one bit. The authors conclude that the proposed multi-bit estimation models improve the signature rate and transmission distance of MDI-QDS and are applicable to other QDS protocols.","pith_inferences":["If the multi-message composition of the security bounds holds, the SMB1-PE gain should also appear in experimental MDI-QDS systems, so a proof-of-principle experiment comparing SOB-PE and SMB1-PE at $10^{14}$ pulses would be a direct test.","The SMB1-versus-SMB2 gap suggests that estimating $n_{Z,1}$ directly from Z-basis data is statistically more efficient than inferring it from X-basis counts; a hybrid scheme that switches models by distance might capture the best of both.","For a rigorous deployment claim, the per-message bounds in Eqs. (4)-(7) must be composed over the $n_{\\rm bits}$ messages signed from one pool; that missing proof is the main thing standing between the simulated rates and a secure rate statement.","The straight-line behavior of SOB-PE in Fig. 6 indicates that its rate is set by a fixed per-bit cost, so it cannot benefit from larger pulse numbers; the SMB models convert additional pulses into higher rates."],"forward_implications":["The SMB1-PE model yields higher signature rates than SOB-PE across all distances, with the largest gain at intermediate distances.","The SMB2-PE model also improves the signature rate except at the farthest distance, where it lags slightly behind SOB-PE.","Both proposed models reduce the finite-size penalty at fixed pulse number, allowing shorter key pools for the same security level.","The estimation approach is protocol-agnostic and can be applied to other QDS schemes such as BB84-QDS and twin-field QDS.","Combining the multi-bit models with one-time universal hashing (OTUH) can further raise the signature rate, as noted in the conclusion."],"supporting_citations":[{"why":"Defines the MDI-QDS protocol that this work analyzes and improves.","marker":"[14]"},{"why":"Supplies the QDS security framework and threshold conditions used in Eqs. (4)-(7).","marker":"[13]"},{"why":"Provides the finite-key analysis for MDI-QKD that underpins the single-photon estimation approach.","marker":"[36]"},{"why":"Serfling inequality used in the fluctuation bounds of Eqs. (3), (12)-(13), and (18).","marker":"[37]"},{"why":"Hoeffding inequality used for the fluctuation term g(x,y) in the SMB2-PE model.","marker":"[38]"},{"why":"Local search algorithm used for full parameter optimization in the numerical simulations.","marker":"[39]"}],"fun_headline_variants":["Finite-size fix boosts MDI-QDS rates and reach","Multi-bit signing reduces finite-size loss for MDI-QDS","Improved finite-size analysis lifts MDI-QDS performance","New estimation models cut finite-size penalties in QDS","MDI-QDS gets faster signing with multi-bit pools"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The security bounds in Eqs. (4)-(7) are derived for a single signed message, but the protocol signs $n_{\\rm bits} = n_{\\rm pool}/(2L)$ messages from one key pool and reports $R = n_{\\rm pool}/(2NL)$ without proving that the total failure probability stays below $\\varepsilon$ across all messages.","fun_headline_variants_meta":{"raw":{"variants":["Finite-size fix boosts MDI-QDS rates and reach","Multi-bit signing reduces finite-size loss for MDI-QDS","Improved finite-size analysis lifts MDI-QDS performance","New estimation models cut finite-size penalties in QDS","MDI-QDS gets faster signing with multi-bit pools"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000809,"raw_usage":{"total_tokens":3522,"prompt_tokens":891,"completion_tokens":2631,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":507,"completion_tokens_details":{"reasoning_tokens":2550}},"tokens_in":507,"tokens_out":2631,"duration_ms":17560,"temperature":1.0,"reasoning_tokens":2550,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-10T21:21:15.072478+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Recompute the signature rate of SMB1-PE under a complete multi-message composition argument, for instance by multiplying the per-message failure probabilities by the number of signed messages, and check whether the claimed rates at $N = 10^{12}$ and distance 150 km still satisfy the declared security level $\\varepsilon = 10^{-5}$; if they do not, the reported improvement is an artifact of the missing composition step.","supporting_citations":[{"cited_title":"Se- cure quantum signatures using insecure quantum chan- nels,","cited_arxiv_id":null,"evidence_quote":"Defines the MDI-QDS protocol that this work analyzes and improves."},{"cited_title":"Exper- imental measurement-device-independent quantum digi- tal signatures over a metropolitan network","cited_arxiv_id":null,"evidence_quote":"Provides the finite-key analysis for MDI-QKD that underpins the single-photon estimation approach."},{"cited_title":"Finite-key analysis for measurement-device- independent quantum key distribution,","cited_arxiv_id":null,"evidence_quote":"Serfling inequality used in the fluctuation bounds of Eqs. (3), (12)-(13), and (18)."},{"cited_title":"Probability Inequalities for the Sum in Sampling without Replacement","cited_arxiv_id":null,"evidence_quote":"Hoeffding inequality used for the fluctuation term g(x,y) in the SMB2-PE model."},{"cited_title":"Probability inequalities for sums of bounded random variables","cited_arxiv_id":null,"evidence_quote":"Local search algorithm used for full parameter optimization in the numerical simulations."}],"review_version":1}