{"id":"ef5e3cd4-2929-4af2-883b-26ea7151d29a","arxiv_id":"2507.11243","paper_version":2,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":8.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":3,"one_line_summary":"A finite-correlation-secure QKD protocol generates key under arbitrary finite-range source correlations using only a known vacuum probability bound.","lead":"This paper introduces a quantum key distribution protocol that remains provably secure even when the source's state preparation is imperfect and correlated across many rounds, as long as the correlations have a known finite range and the states are not entangled. A generalist should care because it removes the need to fully characterize source correlations, a major practical security hurdle, and the simulations suggest useful key rates over long distances.","discovery_kind":"new_method","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The known finite correlation range is the load-bearing assumption: if the actual range exceeds the declared r1+r2, the grouping argument behind Eq. (31) fails and the security proof collapses.","rationale":"I read the paper in good faith and found the central construction internally coherent under its stated assumptions. The source-replacement state, the round-by-round virtual measurement, the POVM treatment of Eve, and the use of Kato/Chernoff inequalities all follow the standard finite-key framework. The protocol's independence argument for N^{--}_{sig} is a legitimate and non-obvious step: Alice and Bob's local ancilla statistics are independent of Eve's channel because the channel acts only on the traced-out pulses. The proof's genuinely load-bearing requirement is that the correlation range r1 and r2 are known and correct. The grouping period r1+r2+1 is engineered so that each emitted pulse is influenced by at most one group round; if the real range is even one longer, the factorization in Eq. (24) and the Chernoff bound in Eq. (29) have no basis, and the bound on N^{--}_{sig} in Eq. (31) can be violated. The reader's verdict identified exactly this as the weakest assumption, and I agree. I did not find a separate internal mathematical contradiction in the proof as written. The other flagged issues (missing simulation parameters, ideal-click-rate assumption, no code) are real but secondary to the security claim itself. Therefore the appropriate verdict remains CONDITIONAL, and my stress-test does not move it: the paper should be accepted with the requirement that the finite-range assumption be stated precisely and, ideally, supplemented by an independent verification of the grouping bound or an explicit error analysis for underestimated ranges.","tokens_in":18751,"tokens_out":39517,"duration_ms":556407,"concrete_test":"Build a source satisfying all assumptions except with correlation range r1+r2+2 rather than r1+r2. Recompute the grouping in Sec. IV: show that two group blocks contain a common emitted pulse, so Eq. (24) is no longer a tensor product over group rounds. Then run a small numerical simulation with a two-level correlated classical source and measure N^{--}_{sig}; check whether it exceeds the bound from Eq. (31) more often than the nominal failure probability (r1+r2+1)eps_2. If it does, the grouping bound is confirmed to rely critically on exact range knowledge and the key-rate formula is invalid for sources with slightly underestimated range.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The proof's key step is bounding N^{--}_{sig} by grouping rounds every L = r1+r2+1 rounds. This works only because the declared correlation range implies that each emitted pulse is influenced by bits from at most one group round, giving the product structure in Eq. (24) and the Chernoff bound in Eq. (29). If the true range is larger than assumed, two neighboring group blocks overlap: a pulse in the overlap region is influenced by group bits from two different groups, the tensor-product factorization in Eq. (24) is false, and the conditioned measurement results are no longer independent. Then the union-bound/Chernoff argument leading to Pr[N^{--}_{sig} >= \\bar N^{--}_{sig}] <= (r1+r2+1)eps_2 in Eq. (31) is invalid. Since the N^{--} term is the only non-observed quantity in the phase-error bound of Eq. (32), an underestimated range directly invalidates the composable key-rate formula (35). The abstract's phrasing 'immune to all correlations' must therefore be read as 'immune to arbitrary correlation strength, provided the correlation extent is finite and exactly bounded by the supplied r1 and r2.' For unbounded correlations the protocol yields no key, and even for large finite L the term (1 - P0^{r1+r2+1}) degrades rapidly, so performance claims are sensitive to this assumption. This is not an internal inconsistency in the proof, but it is the most load-bearing condition on the central claim.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper presents a measurement-device-independent QKD protocol (FCS-QKD) designed to remain secure when the source states are imperfectly prepared with correlations across rounds. The security model assumes that, for each round, Alice's and Bob's emitted states are product states over rounds (no entanglement), that the correlation range is finite and known (backward range r1, forward range r2), and that the vacuum component of each emitted state is at least P0. The main technical contribution is a finite-key security proof against coherent attacks. The proof upper-bounds the phase-error rate by relating phase errors to observed bit errors and to the unobserved number of |--⟩ signal events; the latter is bounded by grouping rounds into r1+r2+1 classes and using the vacuum lower bound together with Chernoff and Kato concentration inequalities. Numerical simulations are reported for different correlation ranges, claiming maximal tolerable loss above 60 dB for small ranges and secure key at 10 dB loss for a range of 500.","tokens_in":19073,"tokens_out":23615,"duration_ms":273982,"significance":"If the proof is correct, the protocol is a significant advance over previous correlated-source QKD analyses (e.g., refs. [34-36]), because it does not require characterizing the correlation strength, only its finite range and a vacuum-probability lower bound. The security argument is non-circular: the phase-error bound is derived from the vacuum component and the correlation range without fitted parameters. The composable finite-key statement against coherent attacks is a useful and nontrivial result. The main caveats are that the performance claims rest on an idealized simulation with under-specified parameters, and that the advertised 'immunity to all correlations' requires the finite-range and non-entanglement assumptions to hold exactly.","major_comments":[{"comment":"The numerical simulation omits several quantities that enter the key-rate formula (35) and the security bound (32): the mean photon number μ, the parameter-estimation probability P_est, the abort thresholds n_est,tol and n_sig,tol, and the vacuum-probability lower bound P0. Without these, the curves in Fig. 1 and the headline numbers (60 dB, 30 dB, 10 dB) are not reproducible. Please report the values, the optimization procedure, and the resulting optimal parameters for at least one representative setting.","section":"Sec. V, Table I and Fig. 1"},{"comment":"The statement that the protocol is 'immune to all correlations of all dimensions' overstates the result. The security proof requires the correlation range to be finite and known, and the prepared states to be non-entangled product states across rounds (Sec. III). If the true range exceeds r1 or r2, the grouping argument in Sec. IV—specifically the factorization in Eq. (24) and the bound in Eq. (31)—does not apply, and the security proof collapses. The text should consistently state 'immune to arbitrary correlation strength for a known finite range' and explicitly warn that a wrong range declaration invalidates the guarantee.","section":"Abstract and Sec. I"},{"comment":"The factorization in Eq. (24) is the load-bearing step of the N^{--}_{sig} bound, but the justification given in the text is too terse. Please show explicitly that for every pulse a_m in the block [g+kL-r1, g+kL+r2], the set of encoding bits that can influence it is [m-r2, m+r1], and that this interval lies strictly between the neighboring group-g bits g+(k-1)L and g+(k+1)L, so that after conditioning on s^{∼g}_A the block state depends on no group-g bit other than s_{g+kL}. Without this calculation, the reader cannot verify the claimed product structure.","section":"Sec. IV, Eq. (24)"},{"comment":"The simulation assumes that 'correlation and state preparation inaccuracy do not influence the click rates a lot' and computes key rates with ideal weak coherent states. This is an optimistic estimate, not a guaranteed rate for all states satisfying the security assumptions. Since the security proof allows arbitrary non-vacuum components, the actual key rate depends on the observed click statistics; the paper should state this limitation explicitly and, ideally, provide a sensitivity analysis (e.g., varying μ and P0) to indicate how robust the performance claims are.","section":"Sec. V, simulation model"}],"minor_comments":[{"comment":"The sentence says a bit error from a right click corresponds to '|00⟩ or |00⟩'; this should be '|00⟩ or |11⟩'.","section":"Sec. IV, after Eq. (8)"},{"comment":"Eq. (20) and the surrounding text are difficult to parse because of the typesetting of the sums and projections; please rewrite with a clearer notation, e.g., explicitly defining the traced-out state and the conditioning on s^{∼g}_A, s^{∼g}_B.","section":"Sec. IV, Eq. (20)"},{"comment":"The block state |φ^{r1+r2+1}_{s_A}⟩_{Apag,k} should carry an explicit label indicating that it is defined for fixed values of the outside bits s^{∼g}_A; otherwise the expression looks ambiguous.","section":"Sec. IV, Eq. (23)"},{"comment":"Fig. 1 appears to lack axis labels and a caption in the provided text; the curves should be clearly labeled with the corresponding r1+r2 values.","section":"Sec. V, Fig. 1"},{"comment":"Table I lists the detector dark count d, misalignment e_mis, error-correction efficiency f, total security parameter ε_tot, and number of rounds N, but does not list the vacuum-probability bound P0. If the simulation uses ideal coherent states, P0 = e^{-μ}, but this should be stated.","section":"Sec. V, Table I"},{"comment":"The parameter ε in Appendix A is used both as the security parameter and as the failure probability in Kato's inequality; please rename one of them to avoid confusion.","section":"Appendix A"},{"comment":"Reference [29] is cited as an arXiv preprint; if a published version exists, please update the citation.","section":"References"}],"recommendation":"major_revision","confidential_remarks":"The central security proof appears internally sound to me; the main weaknesses are the under-specified numerical simulation and the overbroad wording of the central claim. The paper's contribution relative to [34-36] is a different security model (finite correlation range, no strength characterization), and the proof is independent of the authors' prior SCS work [29]. The editor may wish to ask the authors to provide the simulation details and to temper the abstract before publication."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Bottom line: this paper deserves a serious referee. It's the first finite-key, coherent-attack security analysis I know for QKD with correlated sources where you don't have to characterize the correlation strength—only its range and a vacuum bound. That's a real step forward.\n\nThe core idea is clever and works as far as I can tell. They partition rounds into r1+r2+1 groups so that, conditioned on the bits outside a group, the rounds inside are independent. Then they use a per-round bound P_-^A ≤ 1−(P0)^(r1+r2+1), which follows validly from the vacuum-projection assumption, and Chernoff to bound the count of |−−⟩ signal rounds. The phase-error derivation is coherent; I don't see a circular step or fitted constants. The self-citation to their earlier SCS protocol [29] is legitimate—the protocol reduces to it when r1+r2=0.\n\nThe soft spots are real but manageable. The load-bearing assumption is that the true correlation extent is at most r1+r2. If it's larger, the product structure in Eq. (24) fails, the conditioned rounds are dependent, and the Chernoff argument collapses. That doesn't make the proof wrong; it makes the 'immune' claim over-broad. Read it as 'immune to arbitrary correlation strength, not arbitrary correlation extent.' The abstract says 'almost all,' which partly covers them, but the limitation deserves to be stated explicitly.\n\nThe simulation is the weakest section. They assume correlation and state-preparation inaccuracy don't affect click rates, and key parameters (μ, P_est, abort thresholds) are unstated. The 60 dB/500-round numbers are therefore illustrative, not reproducible. That should be fixed in revision, but it doesn't touch the security proof.\n\nI agree with the conditional verdict: the security argument is plausible and worth taking seriously, but I'd want the grouping step verified independently and the simulation made transparent before relying on the protocol. This is a genuine contribution for QKD security people, especially those dealing with patterning effects.","headline":"A genuinely new grouping argument extends side-channel-secure QKD to correlated sources with known finite range, but the proof's validity hinges entirely on that range being exactly right.","tokens_in":19593,"tokens_out":2196,"would_cite":false,"duration_ms":26012,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["81P94"],"pacs":[],"model":"deepseek-v4-flash","headline":"Correlated sources no longer break QKD security proofs.","keywords":["quantum key distribution","side-channel security","correlated sources","measurement-device-independent QKD","finite-key security","coherent attacks","phase error estimation","Kato inequality"],"falsifier":"Find or build a source where flipping the encoding bit $s_i^A$ changes the emitted state at round $i+r_2+1$, one step beyond the declared forward range, with all other assumptions intact; then the grouping bound on $\\lvert--\\rangle$ signal events does not hold, so the claimed secrecy parameter is not justified. Experimentally, one could prepare a fixed bit pattern, flip one encoding, and measure a phase-sensitive observable of the pulse $r_2+1$ positions later.","tokens_in":18540,"feed_emoji":"🔐","tokens_out":5530,"duration_ms":63338,"temperature":0.7,"pith_summary":"This paper proposes a quantum key distribution protocol that keeps its security proof even when the source's state preparation is imperfect in a way that correlates many rounds together. The claim is that the protocol is immune to all correlations of any dimension, as long as the correlations are non-entangled, have a known finite range, and the vacuum component of each emitted state has a known lower bound. Unlike earlier treatments, the strength of the correlation never has to be measured or bounded: only the range matters. The authors give a finite-key security analysis against coherent attacks and show numerically that a small correlation range barely costs performance, while even a range of 500 affected rounds still yields key over a 10 dB-loss channel. If correct, this removes a major practical obstacle between QKD theory and real modulators.","feed_headline":"QKD proof survives correlations of up to 500 rounds","feed_subtitle":"Only the correlation range must be known, not its strength—and finite-key security still holds.","key_machinery":"The load-bearing object is the grouping of all rounds into $r_1+r_2+1$ residue classes modulo $r_1+r_2+1$, so that no two rounds in the same class lie within the correlation range of each other. Conditioned on the bit choices outside the class, measurements in the class factor, so a Chernoff bound can bound the number of $\\lvert--\\rangle$ signal events per class. Around this, the proof uses the vacuum decomposition $\\lvert\\phi_{s_A}\\rangle_{Ap a_i}=\\sqrt{P^i_{0A}}\\lvert\\mathrm{puri}_0\\rangle_{Ap}\\lvert0\\rangle_{a_i}+\\sqrt{1-P^i_{0A}}\\lvert\\phi_1\\rangle_{Ap a_i}$ with $P^i_{0A}\\ge P_{0A}$, Kato's inequality to pass from observed bit errors to phase-error expectations, and the uncertainty relation for smooth entropies to finish the key-length bound.","core_discovery":"The central discovery is that grouping the rounds into $r_1+r_2+1$ residue classes modulo $r_1+r_2+1$ turns a correlated preparation into an effectively independent one for the purpose of bounding the number of $\\lvert--\\rangle$ signal events. Because encoding of round $u$ only affects rounds $u-r_1$ through $u+r_2$, rounds in the same class are separated by more than the correlation range, so conditioned on the bits outside a class, measurements inside the class are independent. This lets the authors bound $N^{--}_{\\mathrm{sig}}$ by a Chernoff bound per class and sum the failure probabilities, and then use Kato's inequality plus the lower bound on vacuum projections to convert the observed bit-error count into an upper bound on phase errors. The result is a composable finite-key secrecy bound with security parameter $\\epsilon_{\\mathrm{tot}} = \\epsilon_{\\mathrm{cor}} + 2\\sqrt{r_1+r_2+4}\\,\\epsilon + \\tilde{\\epsilon}$, and a key-length formula that depends on the correlation only through the sum $r_1+r_2$.","pith_inferences":["The paper does not report a direct experimental calibration of $r_1$ and $r_2$; a concrete test would be to flip one encoding bit and look for changes in the emitted state exactly $r_2+1$ rounds later, then run the protocol with that measured range.","The proof implicitly exposes a trade-off between the vacuum lower bound and the correlation range, since the phase-error bound scales through a factor like $1-P_{0A}^{r_1+r_2+1}$; tuning the operating point to maximize this factor is an optimization the simulations only partially explore.","A natural extension, beyond what the paper considers, would allow unbounded but decaying correlations by introducing a cutoff range and paying a small extra failure probability for the tail that crosses the cutoff."],"forward_implications":["An implementation never needs to measure how strong the correlation is; declaring an upper bound on its range is sufficient for the security proof.","The protocol inherits measurement-device independence, so detector-side loopholes are covered without sacrificing source-side immunity.","Finite-key security against coherent attacks holds with a security parameter that grows only as the square root of the correlation range.","A small correlation range costs little performance: the simulation gives a maximal transmission loss above 60 dB, while even $r_1+r_2=500$ still yields key over a 10 dB-loss channel.","For $r_1+r_2=0$ the protocol reduces to phase-coding side-channel-secure QKD, so the new protocol is a strict generalization."],"supporting_citations":[{"why":"This reference supplies the phase-coding side-channel-secure protocol that the new scheme generalizes; the correlated protocol reduces to it when $r_1+r_2=0$.","marker":"[29]"},{"why":"This reference is the previous correlated-source QKD analysis that requires characterizing the correlation strength, which the new protocol is designed to avoid.","marker":"[34]"},{"why":"This reference gives an earlier security analysis for QKD with intensity correlations that the paper contrasts with its parameter-free treatment.","marker":"[35]"},{"why":"Kato's concentration inequality is the tool the proof uses to go from observed bit errors to bounds on phase-error expectations.","marker":"[44]"},{"why":"This reference provides the composable finite-key security framework and phase-error estimation method used to derive the key-length formula.","marker":"[11]"},{"why":"This reference establishes the tight finite-key analysis and phase-error approach that the security proof builds on.","marker":"[10]"},{"why":"This reference defines measurement-device-independent QKD, the framework that gives the protocol immunity to measurement-side loopholes.","marker":"[22]"},{"why":"This reference introduces the side-channel-secure source model whose vacuum-bound assumption is extended here to correlated rounds.","marker":"[26]"},{"why":"This reference supplies the uncertainty relation for smooth entropies that converts the phase-error bound into a min-entropy bound and hence a key length.","marker":"[43]"}],"fun_headline_variants":["QKD proof survives up to 500 correlated rounds","Correlated sources don't undermine QKD security","Finite-key QKD with correlated sources works","QKD immune to unknown source correlations"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The declared forward and backward correlation ranges $r_1$ and $r_2$ must truly cover every pulse a round's encoding can influence; if the real correlation reaches one step farther, the grouping argument no longer bounds $N^{--}_{\\mathrm{sig}}$ and the security proof gives no guarantee.","fun_headline_variants_meta":{"raw":{"variants":["QKD proof survives up to 500 correlated rounds","Correlated sources don't undermine QKD security","Finite-key QKD with correlated sources works","QKD immune to unknown source correlations"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000347,"raw_usage":{"total_tokens":1914,"prompt_tokens":971,"completion_tokens":943,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":587,"completion_tokens_details":{"reasoning_tokens":885}},"tokens_in":587,"tokens_out":943,"duration_ms":11375,"temperature":1.0,"reasoning_tokens":885,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-06T17:15:05.724368+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Find or build a source where flipping the encoding bit $s_i^A$ changes the emitted state at round $i+r_2+1$, one step beyond the declared forward range, with all other assumptions intact; then the grouping bound on $\\lvert--\\rangle$ signal events does not hold, so the claimed secrecy parameter is not justified. Experimentally, one could prepare a fixed bit pattern, flip one encoding, and measure a phase-sensitive observable of the pulse $r_2+1$ positions later.","supporting_citations":[{"cited_title":"Diamanti, H.-K","cited_arxiv_id":null,"evidence_quote":"This reference supplies the phase-coding side-channel-secure protocol that the new scheme generalizes; the correlated protocol reduces to it when $r_1+r_2=0$."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"This reference is the previous correlated-source QKD analysis that requires characterizing the correlation strength, which the new protocol is designed to avoid."},{"cited_title":"Hwang, Quantum key distribution with high loss: t oward global secure communication, Physical review letter s 91, 057901 (2003)","cited_arxiv_id":null,"evidence_quote":"This reference gives an earlier security analysis for QKD with intensity correlations that the paper contrasts with its parameter-free treatment."},{"cited_title":"Yoshino, M","cited_arxiv_id":null,"evidence_quote":"Kato's concentration inequality is the tool the proof uses to go from observed bit errors to bounds on phase-error expectations."},{"cited_title":"Kato’s inequality","cited_arxiv_id":null,"evidence_quote":"This reference provides the composable finite-key security framework and phase-error estimation method used to derive the key-length formula."},{"cited_title":"(26) 9 Recall the assumption of the states in eq","cited_arxiv_id":null,"evidence_quote":"This reference establishes the tight finite-key analysis and phase-error approach that the security proof builds on."},{"cited_title":"Tomamichel, C","cited_arxiv_id":null,"evidence_quote":"This reference defines measurement-device-independent QKD, the framework that gives the protocol immunity to measurement-side loopholes."},{"cited_title":"Brassard, N","cited_arxiv_id":null,"evidence_quote":"This reference introduces the side-channel-secure source model whose vacuum-bound assumption is extended here to correlated rounds."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"This reference supplies the uncertainty relation for smooth entropies that converts the phase-error bound into a min-entropy bound and hence a key length."}],"review_version":1}