{"id":"d6a095e7-251f-430c-bef1-2b1b7d93fd28","arxiv_id":"2505.10868","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":5.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":2,"one_line_summary":"A decoy-state mode-pairing QKD protocol with a tunable round-filtering pairing strategy increases simulated secret key rates by over 65% in the asymptotic case and extends reach in the finite case.","lead":"This paper proposes a flexible pairing strategy for decoy-state mode-pairing quantum key distribution and proves its security with an entanglement model. Simulations show secret key rate improvements over the original scheme of more than 65% at distances up to 375 km in the asymptotic case and more than 50% up to 400 km in the finite case.","discovery_kind":"extension","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The security proof depends on a prose-only equivalence chain from the entanglement scheme to the prepare-and-measure scheme; if any commutation step fails, the claimed security of Box 1 is unsupported.","rationale":"The reader identified the same load-bearing concern: the claimed equivalence between the entanglement scheme and the prepare-and-measure scheme is argued only in prose, with no formal proof of the key simplifications. I agree that this is the central risk. The phase-gate removal and the advancement of the ancilla measurement are the two steps that actually connect Box 3 to Box 1; if either is invalid, the security proof does not cover the implemented protocol. The paper's other elements, such as the decoy-state parameter-estimation formulas and the simulation method, follow standard forms and are not where the proof is most fragile. The abstract's 'all distances' claim is overstated relative to Fig. 8, and the absence of a benchmark against Refs. [50,54] weakens the performance comparison, but these are secondary to the security argument. Since the concern is addressable by a formal operator-level proof and does not by itself demonstrate a false result, the conditional verdict is appropriate.","tokens_in":20353,"tokens_out":31490,"duration_ms":336391,"concrete_test":"Formalize the transition from Box 5 to Box 6 with explicit operator identities. For a single round, let M_a be the ancilla measurement in basis {|x>} and let Phi be Charlie's effective POVM on the transmitted systems. Compute the post-selected state after measuring M_a conditioned on Charlie's click and compare it with the state obtained by measuring M_a before the channel and then discarding the no-click rounds. Concretely, evaluate the trace distance between these two bipartite states for an arbitrary (or adversarial) channel Phi and for all a in {0,1,2}. If the trace distance is nonzero for any Phi, the equivalence chain is broken.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The security of the actual protocol in Box 1 is established only by a chain of claimed equivalences through Boxes 3-7, argued in prose rather than by a formal proof. Two steps carry the entire argument. First, the phase gate U_delta in Box 3(v) is asserted to have no physical observability and is dropped; this is plausible because U_delta is diagonal in the subsequent measurement basis, but the paper does not show that the phase-error estimation derived from the X-basis pairs remains valid after this removal. Second, and more critically, the measurement of the ancillary system in Box 6(iii''') is said to commute with Eve's evolution on the practical systems because it is 'not based on Charlie's operators.' In the original entanglement scheme, however, the ancilla measurement is performed only on effective rounds, i.e., post-selected on Charlie's announced detection result. Moving this measurement earlier turns a post-selected measurement into an unconditional measurement followed by post-selection. That transformation is likely valid because the ancilla and the transmitted optical system are separate, but the equivalence is not demonstrated. If the commutation or the post-selection equivalence fails for some Eve operation, the entanglement-based proof does not apply to the prepare-and-measure protocol, and the central security claim collapses even though the simulation numbers are unchanged. The paper contains no machine-checked proof and no explicit operator identity for these transitions.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper proposes a flexible pairing strategy for decoy-state mode-pairing QKD. Compared with the original adjacent-round pairing of Ref. [43], the new strategy first discards rounds that cannot contribute to Z-basis key pairs and retains rounds useful for parameter estimation with probability p_save, then pairs adjacent kept rounds within a maximum interval. The authors claim a security proof via an entanglement-based virtual protocol and an equivalence chain reducing that protocol to the prepare-and-measure scheme. They estimate key rates with decoy-state formulas adapted to the new pairing probabilities, and their simulations report improvements over the original scheme: greater than 65% within 375 km in the asymptotic case and greater than 50% within 400 km in the finite-size case, together with extended achievable distance for small block lengths. The simulation method in Appendix A is explicit, the comparison baseline is clearly identified, and p_save is optimized rather than fitted to data.","tokens_in":20657,"tokens_out":4422,"duration_ms":45391,"significance":"If the security reduction is made rigorous, the contribution is a useful practical improvement: the flexible pairing strategy is simple to implement, introduces no new hardware requirements, and the reported gains are substantial across a wide range of distances and block lengths. The paper also offers a virtual entanglement framework for decoy-state MP-QKD that could support future security analyses. The strengths of the work are the explicit simulation equations in Appendix A, the internally consistent decoy-state parameter estimation, and the clearly specified comparison with Ref. [43]. The main weakness is that the security proof is presented as a prose equivalence chain rather than as formal operator identities or a theorem; this is the load-bearing point that currently prevents the central claim from being fully established.","major_comments":[{"comment":"The equivalence between Box 6 and Box 7 is the critical step connecting the entanglement scheme to the prepare-and-measure scheme. The text asserts that the measurement of the ancillary system A'_k in step (iii''') can be commuted with Eve's evolution because it is 'not based on Charlie's operators.' In Box 3, however, that measurement is performed only on effective rounds, i.e., after post-selection on Charlie's announced detection result L_k⊕R_k=1. Moving the measurement to the state-preparation step turns a post-selected measurement into an unconditional measurement followed by post-selection. These two procedures do not commute in general. Please provide an explicit operator identity showing that measuring the ancilla before the channel and Charlie's announcement yields the same joint state and the same final statistics as measuring it after post-selection. Without this identity, the proof does not cover the actual protocol in Box 1.","section":"Sec. 3.1, transition from Box 6 to Box 7"},{"comment":"The phase gate U_delta in Eq. (7) is dropped on the grounds that it 'has no physical observability' on the subsequent measurement in the basis {|xy>}. Because U_delta is diagonal in the computational basis on the two-ancilla subspace, its effect on the raw key bit statistics is indeed trivial, but the claim that it does not affect the phase-error estimate requires a formal argument. The X-basis pairs in Box 3 are the pairs with label 2 in step (iii), on which U_delta is not applied, while the Z-basis pairs are measured in the computational basis; the manuscript should show explicitly that the definition of the phase-error events in step (v), the sifting conditions, and the estimate of e^x_11 are invariant under the removal of U_delta. As written, the proof skips this verification.","section":"Sec. 3.1, Box 3(v) to Box 4"},{"comment":"The parameter-estimation formulas are the second load-bearing part of the security claim. The bounds for n^z_11 and m_11 are introduced with the statement 'as [54]' and the finite-size analysis is also delegated to cited Chernoff and random-sampling results. Since the flexible pairing changes the probabilities p[τa,τb] through p_save, the reader needs a self-contained derivation of Eqs. (24)-(33), or at minimum an explicit statement of which theorem in Ref. [54] remains valid after replacing the pairing probabilities. In particular, the two-case split of [νa,νb] in Eq. (23) and the linear combinations n_ν and m_2ν in Eqs. (25) and (30) should be justified under the new pairing rule, so that it is clear the bounds are not merely adapted by analogy.","section":"Sec. 3.2, Eqs. (24)-(33)"}],"minor_comments":[{"comment":"The code comment 'Keeping this round with practicality psave' should read 'with probability psave'.","section":"Box 2"},{"comment":"The expressions for p[νa,νb]' and p[νa,νb]'' are written without explicit multiplication symbols, which makes them hard to read; for example, '2 ps psavepνapoapνbpob' should use parentheses or product signs.","section":"Eq. (23)"},{"comment":"The sentence 'Since the lower bound of n11;[2νa,2νb] can be obtained based on Eq. (26)' is misleading: Eq. (26) directly gives the lower bound for n11;[µa,µb], and Eq. (32) is a separate scaling relation. Please rephrase to avoid implying that Eq. (26) itself bounds the [2νa,2νb] term.","section":"Sec. 3.2, Eq. (32)"},{"comment":"The vertical axis of Fig. 8 is labeled only with numbers (0, 50, 100, 150, 200); add units or a percent sign so the improvement axis is unambiguous.","section":"Fig. 8"}],"recommendation":"major_revision","confidential_remarks":"The paper is a performance-oriented follow-up with a credible simulation study, but the claimed security proof is currently a sketch. The authors should either supply a formal proof of the Box 3-to-Box 7 equivalence or explicitly weaken the abstract's claim to a security reduction that is conjectural pending the missing identities. The parameter-estimation section should also be made self-contained enough that the adaptation of Ref. [54] to the new pairing probabilities is verifiable."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Dear colleague,\n\nThis is a useful, incremental improvement to mode-pairing QKD, and the central idea holds up. The flexible pairing strategy — save label-1 and label-3 rounds with probability psave, discard label-2 rounds, always keep label-0 rounds — is genuinely new, and the entanglement model in Box 3 is a reasonable way to analyze it. The simulation results, with >65% asymptotic improvement within 375 km and >50% finite improvement within 400 km, are plausible and the appendix is clear enough to reproduce.\n\nThe soft spots are mostly about presentation rather than substance. The security proof is a sketched equivalence chain from the entanglement scheme to the prepare-and-measure protocol. The stress-test worry about commuting the ancilla measurement with Eve's operation does not land: the ancillas are never touched by Eve, so measuring them early or late cannot change the joint statistics. The phase gate drop is also fine, since the subsequent measurement is in the computational basis and the X-basis phase error estimation is not affected. Still, the paper should say this in one or two sentences instead of leaving it to the reader. 'Prove rigorously' is stronger than what the text delivers.\n\nTwo other issues matter more. The abstract claims the SKR is 'enhanced among all distances,' but Fig. 8 shows the improvement goes negative in the final few kilometers when misalignment is included. That should be qualified. And the paper only benchmarks against the original MP-QKD scheme, not against the closest decoy-state MP-QKD variants (Refs. [50,54]) that also reduce useless pairs. The improvement claim would be more convincing with that comparison.\n\nOverall, the paper is honest about its limitations in the main text, the math in the appendix is internally consistent, and the parameter optimization of psave is legitimate. I'd send it to peer review. The referee should ask for a formal statement of the equivalence steps, a qualified abstract, and a comparison with Ref. [54]. With those revisions, it's a solid contribution to the MP-QKD literature.\n\nBest,","headline":"A solid, incremental MP-QKD improvement with a plausible but sketched security proof; worth peer review with requests for formal lemmas and a fairer abstract.","tokens_in":21183,"tokens_out":5481,"would_cite":false,"duration_ms":52643,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"A flexible pairing strategy is proven secure and lifts MP-QKD key rates by over 65 percent.","keywords":["mode-pairing quantum key distribution","decoy-state method","entanglement model","flexible pairing strategy","secret key rate","finite-size analysis","security proof"],"falsifier":"A decisive check would be to re-derive the protocol's single-photon yield and phase-error bounds by simulating the prepare-and-measure protocol directly, without using the entanglement-model reductions, and compare them with the bounds obtained from Box 3; a systematic mismatch would show the claimed equivalence does not hold. An operator-level proof that the ancillary measurement commutes with Eve's evolution in the Box 5-to-Box 6 step would also settle the question.","tokens_in":20165,"feed_emoji":"🔐","tokens_out":8167,"duration_ms":73678,"temperature":0.7,"pith_summary":"Mode-pairing quantum key distribution (MP-QKD) forms key-carrying pairs from detection rounds chosen after Charlie's announcement, easing the photon-coincidence demand and giving a secret key rate that scales as $O(\\sqrt{\\eta})$ with channel transmission. This paper proposes a flexible pairing strategy in which effective rounds are kept or discarded according to a tunable save probability $p_{\\rm save}$ that depends on the round's label, increasing the fraction of Z-basis pairs used for key generation while reserving enough X-basis pairs for parameter estimation. The authors prove the security of the decoy-state version by constructing an entanglement model for MP-QKD and showing its equivalence to the actual prepare-and-measure protocol. Their simulations report that the secret key rate is improved at all distances, by more than 65% within 375 km in the asymptotic case and by more than 50% within 400 km in the finite-size case, with an extended achievable distance when block lengths are small. The entanglement model is offered as a general framework for future security and performance analysis of decoy-state MP-QKD.","feed_headline":"Flexible pairing boosts MP-QKD key rates by 65 percent","feed_subtitle":"New decoy-state protocol with an entanglement-based proof also extends reach when block lengths are small.","key_machinery":"The carrying object is the entanglement model for decoy-state MP-QKD together with the save probability $p_{\\rm save}$. In Box 3, Alice and Bob attach a virtual ancillary system to each phase-randomized coherent state, so the intensity choice is purified; after Charlie's announced detection they measure the ancillas collectively with the projectors $M_0,\\dots,M_3$ to reproduce the protocol's round labels. In the Z basis, a phase gate $U_\\delta=|01\\rangle\\langle01|+e^{i\\delta}|10\\rangle\\langle10|$ aligns the encoded phases, turning the single-photon component into the entangled state $(|01\\rangle|01\\rangle+e^{i\\delta}|10\\rangle|10\\rangle)/\\sqrt{2}$, from which key bits can be tagged. The argument then commutes, combines, and moves these ancillary operations earlier in the protocol (Boxes 4–7) until the scheme coincides with the prepare-and-measure protocol. The filter probability $p_{\\rm save}$ is the second mechanism: by replacing the effective-round label $C_i$ with a filtered $C'_i$, it removes rounds that would form useless pairs and probabilistically keeps others, which shifts the balance toward Z-basis pairs.","core_discovery":"The central claim, in the paper's own framing, is that deliberately filtering effective rounds before pairing improves the efficiency of Z-basis pairs and thereby raises the secret key rate without weakening security. In the labeling of Box 1, rounds with label $L_i=2$ are always discarded, label-$0$ rounds are always kept, and labels $1$ and $3$ are kept with probability $p_{\\rm save}$; optimizing $p_{\\rm save}$ balances the number of key-generation pairs against the number of parameter-estimation pairs. Security is argued through an entanglement model (Box 3) in which each coherent state is purified by a virtual ancillary system, the ancillas are measured collectively with operators $M_0,\\dots,M_3$, and a phase gate $U_\\delta$ is applied in Z-basis pairs; the authors prove that this virtual scheme reduces step by step to the prepare-and-measure protocol of Box 1. On that basis the decoy-state parameter estimation gives lower bounds on the single-photon yield $n^z_{11}$ and upper bounds on the phase error rate $e^x_{11}$, and the simulated secret key rate exceeds that of the original pairing strategy at every distance considered.","pith_inferences":["An implementation could tune $p_{\\rm save}$ online from the observed channel loss and pair counts, rather than fixing it from a precomputed distance, to keep the protocol near its optimum under fluctuating conditions.","If the Box 3–7 equivalence is formalized as a full operator-level proof, the same entanglement construction may transfer to other post-measurement pairing protocols, including asynchronous measurement-device-independent variants with different label filters.","The reported gains are computed against the adjacent-round strategy of the original protocol; combining the flexible filter with X-basis re-pairing or wavelength-division multiplexing could be tested to see whether the improvements add.","A direct next test would be to run the same simulations with asymmetric Alice–Bob channel losses, since the paper assumes symmetric links, to see how the optimal $p_{\\rm save}$ shifts."],"forward_implications":["In the asymptotic limit, the flexible pairing strategy yields a secret key rate more than 65% higher than the original MP-QKD strategy within 375 km of standard fiber.","In the finite-size regime, the improvement is greater than 50% within 400 km, and the achievable distance is extended, particularly at small block lengths.","The secret key rate is improved at all simulated distances under the stated detector, dark-count, and fiber-loss parameters, with the largest relative gains at close range.","The optimal save probability $p_{\\rm save}$ decreases toward zero as the asymptotic limit is approached, while finite-size statistics require larger $p_{\\rm save}$ to keep enough X-basis pairs.","The entanglement model provides a reusable route for analyzing the security and performance of other decoy-state MP-QKD variants."],"supporting_citations":[{"why":"Defines the original MP-QKD protocol and its adjacent-round pairing strategy, which serves as the baseline for all rate comparisons.","marker":"[43]"},{"why":"Supplies the mode-pairing/asynchronous measurement-device-independent formulation that justifies post-measurement pairing and the $O(\\sqrt{\\eta})$ scaling.","marker":"[44]"},{"why":"Provides the decoy-state parameter-estimation bounds and linear-combination method that Sec. 3.2 adapts to the flexible pairing strategy.","marker":"[54]"},{"why":"Gives the practical detector, intensity, and misalignment parameters used in the simulations and the model for phase misalignment.","marker":"[50]"},{"why":"Supplies the Chernoff-bound concentration inequalities used for finite-size statistical fluctuation in Eqs. (36)–(37).","marker":"[65]"},{"why":"Introduces phase slicing for X-basis sifting, adopted in the key-mapping step to balance error rate and pair count.","marker":"[30]"},{"why":"Supports the random-sampling-without-replacement argument that guarantees security in the finite-size regime.","marker":"[66]"}],"fun_headline_variants":["Flexible pairing boosts MP-QKD key rates by 65%","Flexible pairing strategy lifts MP-QKD key rates by 65%","Flexible pairing boosts MP-QKD rates 65% and extends reach","Flexible pairing enhances MP-QKD key rate and distance"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The load-bearing premise is that the virtual entanglement version of the protocol is exactly equivalent to the real prepare-and-measure version, so a security proof on the virtual version transfers to the implemented one; the paper argues this equivalence through a chain of simplifications described in prose rather than formal derivation, and if any simplification fails the proof does not cover the actual protocol.","fun_headline_variants_meta":{"raw":{"variants":["Flexible pairing boosts MP-QKD key rates by 65%","Flexible pairing strategy lifts MP-QKD key rates by 65%","Flexible pairing boosts MP-QKD rates 65% and extends reach","Flexible pairing enhances MP-QKD key rate and distance"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000604,"raw_usage":{"total_tokens":2851,"prompt_tokens":1010,"completion_tokens":1841,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":626,"completion_tokens_details":{"reasoning_tokens":1766}},"tokens_in":626,"tokens_out":1841,"duration_ms":12858,"temperature":1.0,"reasoning_tokens":1766,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-15T21:01:58.716178+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"A decisive check would be to re-derive the protocol's single-photon yield and phase-error bounds by simulating the prepare-and-measure protocol directly, without using the entanglement-model reductions, and compare them with the bounds obtained from Box 3; a systematic mismatch would show the claimed equivalence does not hold. An operator-level proof that the ancillary measurement commutes with Eve's evolution in the Box 5-to-Box 6 step would also settle the question.","supporting_citations":[{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Defines the original MP-QKD protocol and its adjacent-round pairing strategy, which serves as the baseline for all rate comparisons."},{"cited_title":"Xie, Y.S","cited_arxiv_id":null,"evidence_quote":"Supplies the mode-pairing/asynchronous measurement-device-independent formulation that justifies post-measurement pairing and the $O(\\sqrt{\\eta})$ scaling."},{"cited_title":"Xie, J.L","cited_arxiv_id":null,"evidence_quote":"Provides the decoy-state parameter-estimation bounds and linear-combination method that Sec. 3.2 adapts to the flexible pairing strategy."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Gives the practical detector, intensity, and misalignment parameters used in the simulations and the model for phase misalignment."},{"cited_title":"Zhang, Q","cited_arxiv_id":null,"evidence_quote":"Supplies the Chernoff-bound concentration inequalities used for finite-size statistical fluctuation in Eqs. (36)–(37)."},{"cited_title":"Lucamarini, Z.L","cited_arxiv_id":null,"evidence_quote":"Introduces phase slicing for X-basis sifting, adopted in the key-mapping step to balance error rate and pair count."},{"cited_title":"Curty, F","cited_arxiv_id":null,"evidence_quote":"Supports the random-sampling-without-replacement argument that guarantees security in the finite-size regime."}],"review_version":1}