{"id":"09f4d15a-d8ca-4101-9382-a165a7c750ee","arxiv_id":"2507.00972","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":3,"one_line_summary":"A frequency-bin-entangled quantum key distribution network is demonstrated with qutrit (d=3) encoding, achieving 1374 bit/s secure key rate and an estimated 295 km range with qubits.","lead":"Researchers demonstrate a quantum key distribution (QKD) setup that uses high-dimensional frequency states of light (qutrits) on a silicon chip to securely generate encryption keys, and report secure key rates above 1 kbit/s across 21 parallel frequency channels. The work is a step toward scalable, fiber-compatible quantum networks that could one day connect many users with higher data rates and longer ranges.","discovery_kind":"extension","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The SKR in Eq. (5) is not a demonstrated BBM92 secure key rate because the X-basis projections are measured one at a time, without the per-round random basis choice the security proof requires.","rationale":"I read the paper as an experimental proof-of-principle whose central claim is that a frequency-bin entanglement-based BBM92 network with qutrits and qubits has been demonstrated, with secure key rates of about 1 kbit/s and an estimated 295 km range. The measured coincidence statistics, QBERs below threshold, and the 21-hour stability data are internally consistent and support a correlation-level demonstration. The reader correctly flagged the 295 km extrapolation and the sequential X-basis measurement. Between these, I judge the sequential X-basis measurement to be the more load-bearing concern because it attacks the word 'secure' in the central claim at all distances, not only in the long-range extrapolation. Eq. (5) is a security bound that assumes random, independent MUB choices per round; when the experiment fixes one projection for long intervals, the recorded QBER does not by itself imply the same bound. The paper itself states this limitation, so the concern is not speculative, but the appropriate response is not rejection: the authors could fix the protocol with random switching or simultaneous X-basis measurement, or they could provide a security proof adapted to block-sequential basis choices and relabel the result as a correlation-based proof of principle. For those reasons I would keep a conditional verdict rather than accepting the secure-key claim as stated. The 295 km range is also a model extrapolation, but it is explicitly an estimate and depends on the chosen dark count rate; the basis-randomness issue is more fundamental because it affects every reported secure key rate. My proposed test is therefore to repeat or re-analyze with per-pulse random basis selection and a finite-key proof; if the secure rate disappears or changes substantially, the paper's central claim must be revised.","tokens_in":16667,"tokens_out":16112,"duration_ms":248967,"concrete_test":"Implement true random basis selection by adding the time-bin conversion stage of Refs. [41,42] so all X projections can be measured simultaneously, and drive the Z/X basis choice with a fast true random source on a per-pulse basis; then recompute the SKR with a finite-key BBM92 security proof. If the resulting secure key rate is comparable to Fig. 3, the sequential-projection objection is resolved; if it is much lower or zero, the headline secure key rates are not supported by the present experiment.","verdict_should_be":"CONDITIONAL","load_bearing_attack":"The central quantity, the secure key rate SKR from Eq. (5), is a lower bound only for BBM92 when Alice and Bob choose the Z and X bases randomly and independently for each emitted pair. In the implemented setup, however, the PF-EOM-PF configuration measures only one projection at a time; Section II explicitly states that the configuration 'allows for the projection of a photon onto only one state of the superposition basis at a given time,' and the Discussion repeats this limitation. With a fixed and potentially knowable measurement schedule, the X-basis QBER no longer certifies security: an eavesdropper who knows the current projection can adapt her attack, and the Cerf/Sheridan-Scarani security bound used in Eq. (5) is not directly applicable to this block-sequential variant without a dedicated proof. Consequently, the reported 1024 bit/s and 1374 bit/s rates are raw correlation-derived throughputs, not demonstrated secure key rates, and the 295 km range estimate and 21-channel network figures inherit this problem because they all use the same SKR formula. The manuscript also uses the asymptotic infinite-key approximation without a finite-key analysis. This is a missing-support concern rather than an internal mathematical contradiction: the data may well be correct, but the claim that a BBM92 QKD network with secure key rates has been demonstrated is not yet supported.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The manuscript reports an entanglement-based BBM92-type QKD demonstration using frequency-bin encoded photonic qubits and qutrits generated by a silicon microresonator with a 21.23 GHz FSR. The authors optimize pump power and coincidence window, measure SKR and QBER across 21 manually selected frequency channels, characterize distance scaling by applying symmetric attenuation, simulate a maximum communication range of 295 km (59 dB at 0.2 dB/km), and show stable operation over 21 hours. The headline results are an average qutrit SKR of 1024 bit/s with a maximum of 1374 bit/s and an average qubit SKR of 456 bit/s at 0 dB attenuation. The experimental core is a set of coincidence-rate and QBER measurements; the SKR values are obtained from Eq. (5), the standard asymptotic BBM92 lower bound, and the 295 km range is a simulation extrapolation rather than a measured fiber distance.","tokens_in":16961,"tokens_out":6525,"duration_ms":78077,"significance":"If the security claims were fully supported, this would be a significant proof-of-principle: it would be among the first frequency-bin entanglement-based QKD demonstrations with qutrits, and the 21-channel frequency multiplexing, kbit/s-level raw rates, and 21-hour stability compare favorably with prior frequency-bin QKD work. The paper has genuine strengths: a high-brightness CMOS-compatible source, direct joint-spectral-intensity characterization, systematic optimization of pump power and coincidence window, QBER values below the ideal thresholds, and a clear comparison with earlier frequency-bin implementations. However, the central 'secure key rate' claim currently rests on an unproven application of the BBM92 security proof to a sequential projection scheme, on an asymptotic infinite-key formula, and on a simulated range with a chosen dark-count rate. These issues are load-bearing for the main conclusions and must be resolved before the results can be taken as demonstrated secure key distribution.","major_comments":[{"comment":"The secure key rate is computed with Eq. (5), the standard BBM92 lower bound from [9, 44], which assumes that Alice and Bob choose the Z and X bases randomly and independently in each round. The implemented PF-EOM-PF configuration measures only one superposition-basis projection at a time, as explicitly stated in Section II: 'this configuration allows for the projection of a photon onto only one state of the superposition basis at a given time.' The Discussion repeats this limitation. With a known, deterministic measurement schedule, the X-basis QBER does not certify security in the same way: an eavesdropper aware of the schedule can adapt her attack, and no proof is given that the Sheridan-Scarani bound applies to this block-sequential variant. The headline rates (1024 bit/s average and 1374 bit/s maximum) are therefore not demonstrated BBM92 secure key rates but raw correlation-derived throughputs under an assumed security model. This is the central claim of the paper and must be addressed, either by implementing randomized or simultaneous basis measurements (the latter as in refs. [41, 42]) or by providing a dedicated security proof for the sequential protocol and relabeling the reported quantity accordingly.","section":"II and V (Eq. (5))"},{"comment":"The 295 km (59 dB) communication range is an extrapolation, not a measured quantity. The simulation uses a Voigt-profile fit to the coincidence histogram (Eq. (8)), a fitted scaling of true and accidental coincidences with pump power, and a detector dark-count rate of 350 Hz per detector that is 'chosen' by the authors. The range is the point where the simulated SKR crosses zero, so it depends sensitively on the dark-count assumption and on the fitted scaling at large attenuation. No sensitivity analysis or uncertainty bounds are provided, and the measured dots in Fig. 4 are not quantitatively compared with the simulation at the highest attenuations. The authors should either validate the model at 55-59 dB against measured SKR/QBER or present the range as an illustrative estimate with explicit error bars and a discussion of how the dark-count rate and fitting parameters affect the result.","section":"VII C and Fig. 4"},{"comment":"Eq. (5) is an asymptotic, infinite-key lower bound. The paper reports 'secure key rates' without a finite-key analysis, even though the integration intervals and per-channel block sizes are finite; the 21-hour stability run in Fig. 4c appears to concern a single channel, and the per-channel measurement times are not specified. For a claim of demonstrated secure key distribution, finite-size corrections are required, and at the reported rates and block lengths they may be non-negligible. The authors should either perform a finite-key calculation or clearly state that the quoted rates are asymptotic estimates under the infinite-key approximation.","section":"IV, Eq. (5)"},{"comment":"The 21-channel network claim needs clarification. The experimental description indicates that measurements are performed on one channel at a time with a single PF-EOM-PF chain, and the 21 channels are manually selected channels whose SKRs are averaged in Fig. 3a. The paper does not appear to demonstrate simultaneous key exchange between 21 user pairs. If the channels were characterized sequentially, the claim should be rephrased as '21 addressable frequency channels' rather than a simultaneously operating network, or the parallel operation of multiple channels should be demonstrated experimentally.","section":"IV"}],"minor_comments":[{"comment":"The generalized entropy formula contains a typo: 'log((x/d - 1))' should be 'log2(x/(d-1))', and the logarithm base should be stated explicitly.","section":"Eq. (7)"},{"comment":"There is a typo: 'wihch' should be 'which' in the description of the power received on the power meter.","section":"Methods VII B"},{"comment":"The channel labels in Fig. 3a contain an apparent typo '1 1' among the channel numbers; please check the axis labeling.","section":"Fig. 3"},{"comment":"The axes in Fig. 2 should clarify the units and whether the experimental SKR values are absolute or in arbitrary units, since the experimental insets are described as 'SKR (a.u.)' while the simulations are presumably in absolute units.","section":"Fig. 2"},{"comment":"The sentence 'We manually select 21 63-GHz-wide (3 FSRs) to constitute a QKD network' is grammatically incomplete; it should read '21 channels, each 63 GHz wide'.","section":"Section IV"},{"comment":"The 295 km range should be described in the abstract and conclusions as a simulated estimate based on a specific dark-count rate and loss model, not as a directly measured communication distance.","section":"Abstract and Conclusions"}],"recommendation":"major_revision","confidential_remarks":"The main concern for the editor is that the paper's central claim of demonstrated BBM92 secure key rates is not yet supported: the sequential X-basis projection scheme lacks a security proof, and Eq. (5) is applied in the asymptotic regime without finite-key analysis. This is a missing-support problem rather than an internal contradiction, and the experimental data may well be correct. I would encourage a revision that either implements randomized/simultaneous basis measurements or rigorously rescopes the claims to 'effective key rates under an assumed security model,' together with a finite-key analysis and a more cautious presentation of the 295 km range. The 21-channel 'network' also appears to be sequential channel characterization rather than simultaneous multi-user operation, and this should be clarified."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Quick take: this is a useful experimental paper on frequency-bin entangled qutrits and multiplexed channels, but the central \"secure key rate\" claims are not supported as stated. The X-basis measurements run one projection at a time, and the paper itself says so. BBM92 security requires random, independent basis choice per emitted pair; a fixed or known measurement schedule lets an eavesdropper adapt her attack, and the Sheridan-Scarani bound in Eq. (5) is not proven for this block-sequential variant. So the 1374 bit/s and 295 km numbers are raw correlation-derived throughputs, not demonstrated secure key rates, and the range estimate inherits that problem.\n\nWhat is good: the source engineering is careful, the loss budget is detailed, the parameter optimization (power, coincidence window) is systematic, and the multiplexing of 21 channels on the same hardware is a nice step. To my knowledge, qutrit BBM92 with frequency bins is new. The measured QBERs below threshold are plausible, and the 21-hour stability plot on one channel is nice.\n\nSoft spots: besides the security issue, the abstract claims 21 channels stable over 21 hours, but the stability measurement is on a single channel. The 295 km range is a model extrapolation using a chosen dark count rate and fitted coincidence scaling, so it is an estimate even setting the security concern aside. The 21 channels are manually selected, and the coincidence window is optimized post hoc, with no error bars on the reported rates. There is no finite-key analysis, so the asymptotic SKR is optimistic. These are the usual proof-of-principle caveats, but they stack up.\n\nThe authors are not hiding the sequential measurement; they mention it in Section II and the Discussion. What they don't do is connect that limitation to the security claim. That's the missing support. I'd trust the raw data, but not the headline key rates.\n\nThis paper deserves peer review, but it should not be accepted as is. A referee should ask for either a demonstration of fast random basis switching or a rewrite that clearly states the security proof is for a subsequent implementation, and presents the measured rates as raw correlation rates. It would also help to release the data.\n\nFor whom: frequency-bin QKD and high-dimensional entanglement groups will want to read it. I'd bring it to a reading group to discuss the gap between implemented and proven security, but I wouldn't cite it as a secure QKD demonstration.","headline":"Solid frequency-bin qutrit source and multiplexing demonstration, but the headline secure key rates are not backed by the implemented protocol because basis choice is sequential, not random.","tokens_in":17519,"tokens_out":4099,"would_cite":false,"duration_ms":47124,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"This paper reports a 21-channel BBM92 quantum key distribution network built on frequency-bin entangled qutrits and qubits from a silicon microresonator, with average secure key rates above 1 kbit/s and an estimated 295 km range for qubits.","keywords":["quantum key distribution","frequency-bin encoding","qudits","qutrits","BBM92 protocol","spontaneous four wave mixing","silicon microresonator","telecom wavelength"],"falsifier":"Run the same source and detection chain with a calibrated attenuator at 59 dB on the quantum channel and measure QBER and secure key rate for the qubit protocol; if QBER exceeds the 11% threshold, or the key rate drops to zero, before that attenuation is reached, the claimed range is not attainable. A complementary check is to compare the simulated secure key rate with measurements at intermediate attenuations such as 40 and 50 dB.","tokens_in":16487,"feed_emoji":"🔑","tokens_out":5214,"duration_ms":52786,"temperature":0.7,"pith_summary":"The paper aims to show that frequency-bin encoding, using the photon frequency modes of a silicon microresonator comb, can support a practical entanglement-based QKD network in higher dimensions. It generates Bell states of dimension $d=2$ and $d=3$ by spontaneous four-wave mixing, and runs the BBM92 protocol over 21 parallel frequency channels with a single programmable-filter and electro-optic-modulator setup. The authors report an average secure key rate of 1024 bit/s for qutrits, with a maximum of 1374 bit/s, and 456 bit/s for qubits, with error rates below the security thresholds, and estimate a qubit communication range of 295 km at 59 dB attenuation. If correct, this makes frequency-bin qutrits a viable path for metropolitan quantum networks that mix short high-capacity links with longer qubit links.","feed_headline":"Qutrit QKD network hits 21 channels and 1 kbit/s","feed_subtitle":"A silicon-chip source of entangled qutrits and qubits runs 21 parallel BBM92 channels, with qubit reach estimated at 295 km.","key_machinery":"The load-bearing object is the frequency-bin Bell state generated by spontaneous four-wave mixing in a silicon spiral microresonator with a 21.23 GHz free spectral range. Each channel uses either two or three adjacent resonance modes to form the qubit state $(|I_{n-1}S_{n-1}\rangle+|I_{n+1}S_{n+1}\rangle)/\\sqrt{2}$ or the qutrit state $(|I_{n-1}S_{n-1}\rangle+|I_nS_n\rangle+|I_{n+1}S_{n+1}\rangle)/\\sqrt{3}$. The measurement hardware is a programmable filter plus electro-optic modulator (PF-EOM-PF): the filter separates signal and idler and applies phases, while the EOM driven at the free spectral range mixes the frequency bins into one common frequency channel, realizing the $X$-basis projections. The secure key rate is computed from the generalized entropy formula $SKR \\ge \\frac{1}{2}R_{\\rm raw}[\\log_2 d - fH_d(\\epsilon_Z)-H_d(\\epsilon_X)]$, with the factor $1/2$ coming from basis sifting.","core_discovery":"The central claim is that a low free-spectral-range silicon spiral microresonator, pumped continuously, produces spectrally entangled photon pairs whose frequency bins can be used as qudits for BBM92 QKD, and that this platform is reconfigurable enough to serve both $d=3$ qutrit and $d=2$ qubit channels in parallel. Using a programmable filter to project in the natural basis and an electro-optic modulator that mixes frequency bins onto a common channel for the superposition basis, the authors demonstrate 21 simultaneous quantum channels at 0 dB applied attenuation, with QBERs averaging 8.4% for qutrits and 4.7% for qubits, below the 15.9% and 11% thresholds. They optimize the pump power and coincidence window separately for each dimension and report maximum secure key rates of 1374 bit/s for qutrits and 642 bit/s for qubits, stable over more than 21 hours. They also estimate, by simulation calibrated to measured coincidences, that the qubit protocol tolerates 59 dB of total attenuation, corresponding to 295 km at 0.2 dB/km, and they partially explore $d=5$ states up to 18 dB.","pith_inferences":["The 295 km figure is a modeled extrapolation, not a measured fiber link; a field demonstration over a spooled or metropolitan fiber would be needed to confirm that the assumed 350 Hz dark-count rate and coincidence scaling hold at 59 dB attenuation.","Because the $X$-basis measurement is performed one projection at a time rather than with active random switching, the current proof-of-principle approximates BBM92's random-basis condition; converting frequency bins to time bins, as the paper notes, would allow simultaneous superposition-basis measurement and a stricter protocol realization.","The channel structure suggests a wavelength-routed network topology: each 63 GHz channel is an independent QKD link, so a frequency-selective switch could connect different pairs of users without changing the source.","If the reported loss budget of 17.5 dB per user were reduced by integrated components, the secure key rate could rise by roughly two orders of magnitude, bringing frequency-bin entanglement QKD into the range of polarization and time-bin implementations."],"forward_implications":["Frequency-bin encoding can carry entanglement-based QKD in dimension $d=3$, not just qubits, on standard telecom fiber and with off-the-shelf fibered components.","A single reconfigurable hardware can simultaneously operate qutrit channels for short, high-rate links and qubit channels for longer links, letting a network assign dimensionality per user.","The same 5 THz comb window could host 38 qubit-only channels by narrowing each channel to two resonances, roughly doubling the demonstrated channel count.","With higher-modulation-index electro-optic modulators driven by multiple radio-frequency tones, the same architecture should support $d=12$ states, increasing the per-photon information capacity."],"supporting_citations":[{"why":"Defines the BBM92 entanglement-based QKD protocol that the paper implements.","marker":"[2]"},{"why":"Supplies the qudit QKD security thresholds (15.9% for $d=3$, 11% for $d=2$) and the secure key rate formula used in the analysis.","marker":"[9]"},{"why":"Demonstrates frequency-bin qudits up to $d=8$ and provides the residual-spectral-phase framework used to describe the comb state.","marker":"[26]"},{"why":"Shows programmable-filter and electro-optic-modulator manipulation of frequency-bin states, the measurement approach the paper adapts.","marker":"[27]"},{"why":"The authors' earlier frequency-bin qubit QKD demonstration with 12 channels, which this work extends to qutrits and more channels.","marker":"[38]"},{"why":"A competing frequency-bin BBM92 network with 3 channels whose 9 bit/s rate and 51.5 dB simulated range serve as baseline comparisons.","marker":"[41]"},{"why":"A frequency-bin BBM92 demonstration through a fiber spool with 110 bit/s at 0 km and 30 km estimated range, used as another baseline.","marker":"[42]"},{"why":"Supplies the continuous-wave SPDC model for true and accidental coincidences that the paper adapts to SFWM in cavity.","marker":"[45]"}],"fun_headline_variants":["Qudit QKD network: 21 channels, 295 km qubit reach","21 parallel qudit QKD channels from a silicon chip","Qutrit QKD on 21 channels at 1.37 kbit/s","Entangled qudit QKD stable for 21 hours on chip"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The 295 km communication range is an estimate from a simulation that assumes a 350 Hz dark-count rate per detector and a fitted scaling of true and accidental coincidences with pump power, extrapolated to 59 dB attenuation, not a measured distance over fiber.","fun_headline_variants_meta":{"raw":{"variants":["Qudit QKD network: 21 channels, 295 km qubit reach","21 parallel qudit QKD channels from a silicon chip","Qutrit QKD on 21 channels at 1.37 kbit/s","Entangled qudit QKD stable for 21 hours on chip"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000858,"raw_usage":{"total_tokens":3776,"prompt_tokens":1050,"completion_tokens":2726,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":666,"completion_tokens_details":{"reasoning_tokens":2645}},"tokens_in":666,"tokens_out":2726,"duration_ms":24266,"temperature":1.0,"reasoning_tokens":2645,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-06T21:01:44.482189+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Run the same source and detection chain with a calibrated attenuator at 59 dB on the quantum channel and measure QBER and secure key rate for the qubit protocol; if QBER exceeds the 11% threshold, or the key rate drops to zero, before that attenuation is reached, the claimed range is not attainable. A complementary check is to compare the simulated secure key rate with measurements at intermediate attenuations such as 40 and 50 dB.","supporting_citations":[{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Demonstrates frequency-bin qudits up to $d=8$ and provides the residual-spectral-phase framework used to describe the comb state."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Shows programmable-filter and electro-optic-modulator manipulation of frequency-bin states, the measurement approach the paper adapts."},{"cited_title":"Henry, D","cited_arxiv_id":null,"evidence_quote":"The authors' earlier frequency-bin qubit QKD demonstration with 12 channels, which this work extends to qutrits and more channels."},{"cited_title":"Khodadad Kashi and M","cited_arxiv_id":null,"evidence_quote":"A competing frequency-bin BBM92 network with 3 channels whose 9 bit/s rate and 51.5 dB simulated range serve as baseline comparisons."},{"cited_title":"Tagliavacche, M","cited_arxiv_id":null,"evidence_quote":"A frequency-bin BBM92 demonstration through a fiber spool with 110 bit/s at 0 km and 30 km estimated range, used as another baseline."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Supplies the continuous-wave SPDC model for true and accidental coincidences that the paper adapts to SFWM in cavity."}],"review_version":1}