{"id":"a763695a-7269-4c33-9b55-404ade1fd826","arxiv_id":"2505.09317","paper_version":1,"verdict":"REJECT","confidence":"HIGH","novelty_score":6.0,"correctness_risk":"high","formal_verification":"none","parameter_count":0,"one_line_summary":"The authors present a (t,n) threshold quantum multi-secret sharing protocol based on cluster states and Lagrange interpolation, but the security proof for dishonest reconstructors relies on an incorrect identity.","lead":"This paper proposes a quantum protocol that lets any t of n participants reconstruct multiple quantum secrets using cluster states and Lagrange interpolation. The claim of being the first of its kind is undercut by a false algebraic step in the internal-security proof.","discovery_kind":"new_method","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Sec. IV.B.2.a's internal-attack proof uses the false identity RX(γ+δ)RZ(δ)|+> = RZ(γ)|+>; the claimed proof of security against internal attacks is therefore unsupported.","rationale":"I read the paper as proposing a protocol whose central advertised value is the combination of (t,n) threshold multi-secret sharing with a proof of security against external and internal attacks. The protocol construction and the correctness derivation in Sec. IV.A are internally consistent for ideal operations: the accumulation of RX(γ_k) rotations via the cluster-state teleportation works if all operations are as specified. The IBM Q experiment is illustrative but, lacking error bars and raw statistics, it does not by itself establish correctness; however, that is secondary. The decisive issue is the security proof. The reader's weakest assumption is precisely the false algebraic identity in the dishonest-reconstructor attack. I verified the counterexample: with δ=0 and γ=π/2, RX(π/2)|+> = e^{-iπ/4}|+> (a global phase), while RZ(π/2)|+> = (e^{-iπ/4}|0> + e^{iπ/4}|1>)/√2; these are not proportional. The paper gives no other basis for concluding that the dishonest reconstructor learns nothing from the fake-measurement attack, and the abstract explicitly claims proven security against internal attacks. Thus the central claim as stated is not established. This is a scientific error in the argument, not a disagreement with consensus, so it warrants rejection or, at minimum, major revision with a corrected security proof. I therefore agree with the reader's verdict and recommend no change.","tokens_in":15430,"tokens_out":9575,"duration_ms":94649,"concrete_test":"Compute the fidelity F = |<+| RZ(-γ) RX(γ+δ) RZ(δ) |+>|^2 for δ=0 and γ=π/2. If F < 1 (it equals 1/2), the claimed identity in Sec. IV.B.2.a is disproved, and the internal-attack security proof must be rewritten or the security claim withdrawn.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The security proof for a dishonest reconstructor (Sec. IV.B.2.a) claims that after publishing a fake measurement result m', the reconstructor can apply RX(σ'_u) with σ'_u = γ_u + (-1)^{m'}δ_u to the qubit |∆>_u = |+_{δ_u}> = RZ(δ_u)|+> and obtain |∆''>_u = RZ(γ_u)|+>. This requires RX(γ_u+(-1)^{m'}δ_u) RZ(δ_u)|+> = RZ(γ_u)|+> up to a global phase. The identity is false. For δ_u=0 and γ_u=π/2, the left side is proportional to |+>, while the right side is |+_{π/2}>, with fidelity 1/2. Geometrically, RX rotates the equatorial Bloch vector |+_{δ}> out of the x-y plane unless the rotation angle is 0 or π, whereas RZ(γ)|+> lies in the equator. This false step is the only argument that a dishonest reconstructor cannot use fake measurement results to strip δ_u and expose the share-related angle γ_u. Since the abstract and Sec. IV.B advertise security against internal attacks, and this is the load-bearing derivation for that claim, the central security statement is not established by the paper.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The manuscript proposes a (t,n) threshold quantum multi-secret sharing protocol. A dealer encrypts m quantum states by single-qubit rotations RX(γ_D^j) and distributes classical Shamir shares of a secret s_D; any t users cooperate so that one designated reconstructor can decrypt all m secrets by using two-qubit cluster states and rotated-basis measurements by the other users. The paper claims this is the first quantum (t,n) threshold multi-secret sharing scheme, claims theoretical security against several external and internal attacks, and reports an IBM Q experiment supporting correctness.","tokens_in":15623,"tokens_out":17913,"duration_ms":158785,"significance":"The protocol design is interesting and the correctness algebra in Sec. IV.A is coherent, with a useful worked (3,4) example and a hardware demonstration. If the security claims were valid, the work would be a meaningful step toward multi-secret threshold quantum sharing. However, the central security analysis is not valid: the internal-attack proof rests on a false operator identity, and the external-attack argument does not establish confidentiality of arbitrary quantum states. Since the paper's contribution is precisely the claimed security guarantee, the current manuscript does not meet the standard for publication.","major_comments":[{"comment":"The proof that a dishonest reconstructor cannot extract the share angles γ_u assumes the operator identity RX(γ_u + (-1)^{m'} δ_u) RZ(δ_u)|+> = RZ(γ_u)|+>. This identity is false; for δ_u = 0 and γ_u = π/2 the left-hand side is proportional to |+> whereas the right-hand side is |+_{π/2}>. This identity is the only step in the argument that would allow the reconstructor to strip δ_u from |Δ>_u and expose γ_u, so the claimed security against internal reconstructor attacks is not established.","section":"IV.B.2.a"},{"comment":"The external-attack analysis asserts that an eavesdropper who obtains the encrypted states |Ψ>^j = RX(γ_D^j)|ψ>^j 'cannot steal any useful information' because she does not know the original secret. This is not a valid confidentiality argument: the family {RX(θ)} does not form a quantum one-time pad, and for a secret such as |ψ> = |+> the ciphertext is unchanged up to a global phase for every γ_D, so Eve can recover the secret without touching the decoy particles. The probability calculation (3/4)^{d1+d2} only addresses a specific intercept-resend strategy on decoys and does not bound information leakage from undetected measurements of the data qubits.","section":"IV.B.1"},{"comment":"The internal-attack discussions for dishonest non-reconstructor users and collusions consist of assertions that public information does not reveal shares and that Pt never publishes his share, with no adversary model or information-theoretic argument. In particular, the distribution of the random angles δ_u is never specified, so the claim that σ'_u = γ_u + (-1)^{m'}δ_u hides γ_u cannot be assessed; if δ_u is not uniform and independent per secret, the published angles leak information about the shares. A rigorous security proof must quantify this.","section":"IV.B.2.b and IV.B.2.c"}],"minor_comments":[{"comment":"'Lagrangian interpolation' should be 'Lagrange interpolation', and 'IMB Q' should be 'IBM Q'.","section":"Throughout"},{"comment":"In the participants list, the phrase 'P1, P1, ..., Pn' should read 'P1, P2, ..., Pn'.","section":"Section III"},{"comment":"The paragraph discussing Ref. [44] and delayed measurements is tangential to the correctness proof and should be moved or removed.","section":"IV.A"},{"comment":"Notation for the angles is inconsistent between γ^j_k and γ_k; the superscript j should be carried consistently.","section":"Eqs. (13), (17), (18)"},{"comment":"The experimental section does not report the number of shots or the noise model used on the IBM Q platform, which is needed for reproducibility.","section":"V"}],"recommendation":"reject","confidential_remarks":"The main obstacle is not style but the absence of a valid security proof. The false identity in Sec. IV.B.2.a and the insufficient external-attack argument affect the paper's core claim. Repairing this would require a substantially new security analysis, and the external attack may reveal a genuine vulnerability (e.g., X-eigenstate secrets are not concealed by RX encryption). I therefore recommend rejection rather than major revision."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Quick take: this is a coherent protocol paper with a broken security proof. The construction—Lagrange-interpolated multi-secret sharing over cluster states—is new in this form, and the correctness derivation in Sec. IV.A checks out. But the internal-attack argument in Sec. IV.B.2.a uses the identity RX(γ+δ)RZ(δ)|+> = RZ(γ)|+>, which is false; a simple counterexample (δ=0, γ=π/2) shows the left side is |+> and the right side is |+_{π/2}>. Since that identity is the only step showing a dishonest reconstructor can't strip the user's private angle from the quantum state, the paper's advertised claim of proven security against internal attacks is not established.\n\nWhat the paper does well: it identifies a real gap (no (t,n) threshold multi-secret sharing in quantum), the protocol itself is clean and the Lagrange part is standard, the teleportation-like reconstruction using the rotated measurement basis is a nice trick, and the worked (3,4) example makes the mechanics transparent. The external attack analysis is standard decoy reasoning and is fine as far as it goes.\n\nThe soft spots are in proportion: the false identity is load-bearing, so it's a major flaw. The collusion attack section is thin—saying 'this reduces to the previous internal attack' when t-1 colluders plus the reconstructor are missing exactly one share is a non-argument without a detailed analysis. The IBM Q experiment is a single run with no error bars, no compiled code, and no statistical backing; it demonstrates the circuit but proves little. Minor: the paper claims the shares remain private after reconstruction, but doesn't formally define the privacy notion.\n\nWho's this for: researchers working on quantum secret sharing protocols. They'd read it to see the construction, not to rely on the security proof. As submitted, the central claim fails, so it shouldn't be accepted. But the error is a specific algebraic slip, not a conceptual dead end. If the authors replace the attacker analysis with a correct argument—or show that a dishonest reconstructor genuinely cannot extract information from RX(σ')|+δ>—the protocol could be a valid contribution. I'd send it to peer review, mostly so a referee can pin down the exact flaw and the authors can repair it.","headline":"Neat construction, but the internal-attack security proof relies on a false identity, so the central security claim is not established.","tokens_in":16212,"tokens_out":8684,"would_cite":false,"duration_ms":78360,"reading_group":"no","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["81P94","81P68"],"pacs":["03.67.Dd"],"model":"deepseek-v4-flash","headline":"This paper proposes a (t,n) threshold multi-secret sharing protocol in which any t of n users reconstruct many quantum secrets at once.","keywords":["quantum secret sharing","multi-secret sharing","threshold cryptography","cluster states","Lagrange interpolation","measurement basis","quantum cryptography","qubit rotations"],"falsifier":"Take $\\delta_u = 0$ and $\\gamma_u = \\pi/2$ in that identity: the left side becomes $R_X(\\pi/2)|+\\rangle = |+\\rangle$, while the right side becomes $R_Z(\\pi/2)|+\\rangle = |+_{\\pi/2}\\rangle$, a different state. A direct state-vector check of both sides settles the premise.","tokens_in":15133,"feed_emoji":"🔐","tokens_out":12740,"duration_ms":110245,"temperature":0.7,"pith_summary":"Quantum secret sharing usually handles one secret at a time and often needs all n participants. This paper claims to present the first quantum $(t,n)$ threshold multi-secret sharing protocol, where any $t$ of $n$ users can reconstruct a sequence of quantum secrets from one set of shares. The construction combines Lagrange interpolation with cluster states: the dealer encrypts each secret by an $R_X$ rotation whose angle is tied to a random polynomial, and the cooperating users contribute compensating angles so the total rotation cancels. The paper argues that the dealer can be offline after distribution, that non-reconstructor users only measure particles in a new basis instead of preparing them, and that common external and internal attacks are ineffective; it also reports a cloud-quantum experiment on a $(3,4)$ example.","feed_headline":"First quantum multi-secret scheme needs only t of n users","feed_subtitle":"Cluster-state measurements and Lagrange interpolation let one set of shares unlock every secret.","key_machinery":"The load-bearing object is the two-particle cluster state $|T\\rangle_u^j = CZ|+\\rangle|+\\rangle$ used with the proposed measurement basis $\\{|0_{-\\omega}\\rangle, |1_{-\\omega}\\rangle\\}$, where $|0_{-\\omega}\\rangle = R_X(-\\omega)|0\\rangle$ and $|1_{-\\omega}\\rangle = R_X(-\\omega)|1\\rangle$. Measuring one particle in this basis collapses the other to $|+_{\\omega}\\rangle$ or $|-_{\\omega}\\rangle$, so a user transfers an angle $\\omega$ without preparing any state. The matching identity is the angle-sum relation $\\gamma_D^j + \\sum_{l=1}^t \\gamma_l^j = 2\\pi r$, produced by the Lagrange-interpolated shares $c_l = f(x_l)\\prod_{v\\ne l}(-x_v/(x_l-x_v)) \\bmod q$, which makes the accumulated $R_X$ rotations equal to the identity up to a global phase.","core_discovery":"The central claim, on the paper's own terms, is that multi-secret sharing with a $(t,n)$ threshold can be realized with cluster states and Lagrange interpolation. The dealer chooses a polynomial $f(x)$ of degree $t-1$, privately sends $f(x_i)$ to user $P_i$, and publishes a weight $w_j$ for each secret $|\\psi\\rangle_j$. The dealer and the $t$ cooperating users derive rotation angles $\\gamma_D^j$ and $\\gamma_l^j$ from these shares so that $\\gamma_D^j + \\sum_{l=1}^t \\gamma_l^j = 2\\pi r$. The dealer sends $R_X(\\gamma_D^j)|\\psi\\rangle_j$ to the reconstructor, who builds a chain of two-qubit cluster states with the other users; each user measures in the new basis and publishes a correction angle. After the final rotation $R_X(\\gamma_t^j)$, the accumulated angles cancel to the identity up to a global phase and the original secret is recovered. The same classical shares serve every $j$, so one set of shares reconstructs all $m$ secrets.","pith_inferences":["Editorial note: Sec. IV.A itself concedes that the delayed-measurement correctness argument from the adapted protocol does not directly apply once extra operations are present; the correctness claim is anchored in the two-particle cluster form and in the reported experiment.","Editorial inference: the same rotation-angle cancellation could be adapted to share classical secrets with a $(t,n)$ structure, but the paper does not develop that direction.","Editorial inference: because the dishonest-reconstructor security step in Sec. IV.B.2.a uses a rotation identity that is not generally valid, the internal-attack claim should be read as conditional on a corrected proof.","Editorial inference: the new measurement basis could serve other quantum communication tasks that require one party to transfer an angle without preparing a particle, such as remote state preparation."],"forward_implications":["Any $t$ of the $n$ users, rather than all $n$, can reconstruct the entire sequence of $m$ quantum secrets from one set of shares.","The dealer can stop participating after the splitting phase; reconstruction is handled by the users alone.","Participants other than the reconstructor never have to prepare quantum states; they only measure particles and publish classical angles.","All required operations are standard gates ($H$, $CZ$, $R_X$, $R_Z$, $X$, $Z$), so the circuit can be run on current quantum hardware.","Each user's private share stays private after reconstruction, because only derived angles are published."],"supporting_citations":[{"why":"Provides the BB84 quantum key distribution and decoy-particle detection used to distribute shares and check the quantum channel.","marker":"[1]"},{"why":"Introduces the multi-secret sharing model that motivates reconstructing several secrets from one set of shares.","marker":"[35]"},{"why":"Supplies the classical Lagrange-interpolation multi-secret sharing scheme whose angle-splitting construction is quantized here.","marker":"[37]"},{"why":"Defines cluster states, their stabilizer property and measurement-based processing, which form the entanglement resource.","marker":"[41–43]"},{"why":"Gives the delayed-measurement result for cluster-state computation invoked when adapting the correctness proof.","marker":"[43]"},{"why":"Supplies the two-particle cluster-state secret reconstruction process that the protocol adapts for correctness and for the experiment.","marker":"[44]"}],"fun_headline_variants":["First (t,n) threshold multi-secret quantum sharing","Cluster states and Lagrange interpolation enable t-of-n multi-secret sharing","Multi-secret sharing: t cooperating users reconstruct all secrets","Quantum secrets shared among t users with cluster-state measurements"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The dishonest-reconstructor security proof assumes $R_X(\\gamma_u + (-1)^{m'}\\delta_u)R_Z(\\delta_u)|+\\rangle = R_Z(\\gamma_u)|+\\rangle$; this identity does not hold for general angles, and the argument depends on it.","fun_headline_variants_meta":{"raw":{"variants":["First (t,n) threshold multi-secret quantum sharing","Cluster states and Lagrange interpolation enable t-of-n multi-secret sharing","Multi-secret sharing: t cooperating users reconstruct all secrets","Quantum secrets shared among t users with cluster-state measurements"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.00026,"raw_usage":{"total_tokens":1600,"prompt_tokens":965,"completion_tokens":635,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":581,"completion_tokens_details":{"reasoning_tokens":567}},"tokens_in":581,"tokens_out":635,"duration_ms":5559,"temperature":1.0,"reasoning_tokens":567,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-15T21:34:59.437793+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Take $\\delta_u = 0$ and $\\gamma_u = \\pi/2$ in that identity: the left side becomes $R_X(\\pi/2)|+\\rangle = |+\\rangle$, while the right side becomes $R_Z(\\pi/2)|+\\rangle = |+_{\\pi/2}\\rangle$, a different state. A direct state-vector check of both sides settles the premise.","supporting_citations":[{"cited_title":"secret recon- structor","cited_arxiv_id":null,"evidence_quote":"Provides the BB84 quantum key distribution and decoy-particle detection used to distribute shares and check the quantum channel."},{"cited_title":"Tavakoli, I","cited_arxiv_id":null,"evidence_quote":"Introduces the multi-secret sharing model that motivates reconstructing several secrets from one set of shares."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Supplies the classical Lagrange-interpolation multi-secret sharing scheme whose angle-splitting construction is quantized here."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Gives the delayed-measurement result for cluster-state computation invoked when adapting the correctness proof."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Supplies the two-particle cluster-state secret reconstruction process that the protocol adapts for correctness and for the experiment."}],"review_version":1}