{"id":"3e326b1b-644b-4ee8-9874-e5937c4624c3","arxiv_id":"2508.06380","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":5.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":1,"one_line_summary":"A doctoral thesis presenting QIA protocols from QSDC structures, two weak-coherent-pulse QKD protocols, a controller-assisted QKA protocol, and a game-theoretic QBER bound for DL04 QSDC.","lead":"This thesis designs and analyzes several quantum communication protocols: authentication using single photons and entangled pairs, two key distribution protocols for commercial photon sources, a supervised key agreement protocol, and game-theoretic error bounds. It also provides a chronological review of quantum identity authentication.","discovery_kind":"extension","skeptic_critique":{"model":"deepseek-v4-flash","headline":"QKD key-rate improvement hinges on an unconstrained 'new variable δ'; without a derivation fixing δ from protocol statistics, the claimed threshold advantage over SARG04 is not established.","rationale":"The reader's CONDITIONAL verdict identifies the same load-bearing concern: the QKD security proof depends on a restricted threat model and on a key-rate threshold that uses a 'new variable δ' whose choice is unstated. I agree that this is the most load-bearing issue because it directly affects the abstract's SARG04 efficiency claim and the 'rigorously proven' assertion. The concern is internal to the derivation, not merely a disagreement with the field's stronger security standards: if δ is free, the plotted threshold improvement is not a valid lower bound; if it is constrained, the constraint is missing from the visible text. The proposed check—setting δ=0 and attempting to derive δ from observed statistics—would settle whether the improvement is real or an artifact. The reader's verdict remains appropriate: CONDITIONAL, pending this derivation check. I do not see a reason to escalate to REJECT, because the flaw is a concrete missing derivation that could be supplied; nor should it be ACCEPT, because the central security claim is not currently verifiable as written.","tokens_in":48519,"tokens_out":6815,"duration_ms":80976,"concrete_test":"Extract the key-rate formula behind Figure 3.1 from §3.3 and recompute the maximum tolerable QBER with δ set to 0. Then attempt to derive δ from the protocol's observable statistics—e.g., the sifted QBER, detection rates, or pre-processing probabilities. If the threshold improvement over the δ=0 case disappears, or if δ can be varied freely without violating the observed statistics, the claimed efficiency advantage over SARG04 is unsupported. If no such δ constraint is derived, the security bound is incomplete as written.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The abstract's central claim is that Protocols 3.1 and 3.2 are rigorously proven secure and more efficient than SARG04. The load-bearing step is the key-rate derivation in §3.3: Figure 3.1 plots the maximum tolerable QBER with and without the 'new variable δ', and the abstract credits this variable (or associated classical pre-processing) with improving the error threshold. The visible text does not state how δ is defined, what range it takes, or which observed channel statistics fix its value. If δ is merely an adjustable parameter, the plotted 'with δ' curves are not lower bounds on the secret-key rate; they are envelopes over a family of formulas, and the SARG04 efficiency comparison is vacuous. If δ is meant to be determined by the protocol, the missing derivation is exactly the part that carries the claimed advantage. This is compounded by the reader-noted internal inconsistency in the probability table used in the security evaluation, so the proof cannot currently be checked. The issue is not that the adversary model excludes coherent attacks per se—the abstract says 'certain collective attacks'—but that within even that model, the bound's improvement is not shown to be legitimate. The 'rigorously proven' language is therefore stronger than what the text supports.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The manuscript is a PhD thesis that collects and analyzes several discrete-variable quantum communication protocols. It proposes (i) single-photon and Bell-state quantum identity authentication (QIA) protocols, (ii) two QKD protocols claimed to be practical with weak coherent pulses and more efficient than SARG04, (iii) a controlled quantum key agreement (CQKA) protocol that does not require quantum memory, and (iv) a game-theoretic security analysis of the DL04 protocol using Nash equilibrium. The central claims are that the QIA protocols resist impersonation, intercept-resend, and fraudulent attacks; that the QKD protocols are rigorously proven secure against intercept-resend and certain collective attacks, with classical pre-processing improving the tolerable QBER threshold; and that the CQKA protocol is fair and secure without quantum memory. The thesis also includes a chronological review and classification of QIA protocols.","tokens_in":48785,"tokens_out":8913,"duration_ms":89453,"significance":"If fully established, the two new QKD protocols would be a practical contribution: they avoid entanglement and ideal single-photon sources, claim higher efficiency than SARG04, and are stated to have larger critical distances under PNS attacks. The CQKA protocol's avoidance of quantum memory and use of Bell and single-photon states is also a valuable step beyond GHZ-based schemes. The game-theoretic QBER-bound analysis is an original methodological angle. The manuscript is honest in restricting the QKD adversary to 'certain collective attacks,' and it provides detailed protocol descriptions, explicit attack analyses, noise models, and comparative tables. However, several load-bearing derivations and security analyses are incomplete or internally inconsistent in the version provided, so the significance is conditional on those points being repaired.","major_comments":[{"comment":"The central efficiency claim rests on Figure 3.1, which shows that the tolerable QBER threshold increases when a 'new variable δ' is incorporated. The manuscript does not define δ, state its domain, or show how it is fixed by protocol statistics (e.g., sifted key, error correction, or a concrete classical pre-processing map). If δ is a free parameter, the 'with δ' curves are envelopes over a family of formulas rather than lower bounds on the secret-key rate, and the claimed threshold advantage over SARG04 does not follow. An explicit definition of δ and a derivation of the plotted curves are required before this claim can be evaluated.","section":"§3.3, Fig. 3.1"},{"comment":"The P(B|A) table has two entries both labeled 'identical basis with distinct outcomes' but with different values (1/8 and 3/8), and a third entry for 'different basis' with value 0. The subsequent entropy calculation uses P(correct)=3/4 and P(wrong)=1/4, which is inconsistent with the table and suggests the table mixes joint and conditional probabilities. Because the security claim for Protocols 2.1/2.2 is based on the resulting mutual information values I(A:B)=1.0 and I(A:E)=0.311, this inconsistency must be corrected and the calculation redone or the security claim retracted.","section":"§2.2.4.3"},{"comment":"Section 1.5.1.2 promises that the new single-qubit QIA protocols 'address vulnerabilities, including key space reduction attacks.' Sections 2.2.4.1–2.2.4.6 analyze impersonation, measurement-resend, and impersonated-fraudulent attacks, but contain no analysis of key-space-reduction attacks. This is a missing defense for a stated design goal; either add the analysis or remove the claim.","section":"§1.5.1.2 / §2.2.4"},{"comment":"The abstract states that the QKD protocols are 'rigorously proven to be secure against various attacks, including intercept-resend and certain collective attacks.' The security analysis in Chapter 3 is restricted to a specified set of attacks (intercept-resend, PNS, IRUD, and some collective strategies) and does not provide a composable or finite-key argument. This is acceptable as an explicitly stated threat model, but the abstract and conclusions should state clearly that security holds only within that restricted, asymptotic model; otherwise 'rigorously proven' overstates the result.","section":"Abstract / §3.3–3.4"}],"minor_comments":[{"comment":"P(B|A) is described as a joint probability but written as a conditional; use one convention consistently throughout the table and the surrounding text.","section":"§2.2.4.3"},{"comment":"The text says Protocol 2.1 requires a minimum of 6 pre-shared classical bits and Protocol 2.2 at least 10, while the formulas use n particles (2n or 4n bits). Clarify whether n denotes bits, bit pairs, or particles; the figure axis should match.","section":"§2.2.4.1–2.2.4.2 / Fig. 2.1"},{"comment":"The condition 'I(A;B) ≥ χ(ρ)' is not the standard use of the Holevo bound: χ upper-bounds Eve's accessible information, so the security condition should relate I(A;E) to χ and then compare I(A;B) with I(A;E).","section":"§2.3.3.2, Eq. (2.9)"},{"comment":"There are many OCR-type artifacts and inconsistent symbols (e.g., in the P(B|A) table and in the quantum-state equations). A careful proofreading pass is needed before publication.","section":"Throughout"}],"recommendation":"major_revision","confidential_remarks":"This is a PhD thesis text rather than a standard journal article, and most chapters are declared to report the author's already-published work. If the underlying publications contain the missing δ derivation and the corrected probability table, the revision may be straightforward; otherwise the central QKD efficiency claim and the QIA security claims are not supported as they stand. I therefore recommend major revision rather than rejection, provided the authors supply the missing definitions and fix the internal inconsistencies."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Two things to know. First, this is not a single new research paper; it's a PhD thesis compilation where Chapters 2–5 are the author's own published papers, restated. Second, the part worth keeping from this is the Chapter 1 review and classification of quantum identity authentication—that's a solid, well-organized taxonomy that students and researchers new to QIA will actually use.\n\nThe good bits: the chronological review of QIA protocols, organized by resources and tasks, is careful and complete, and the table of key features (pre-shared key, third party, quantum memory) is a handy reference. Protocol 2.3, the Bell-state controlled QIA with permutation, is a plausible new construction, and the security analysis against impersonation is fine as far as it goes. The CQKA protocol without quantum memory is a practical improvement over Tang et al., and the comparison table makes that concrete. The game-theoretic Nash equilibrium analysis of DL04 is a nice piece of applied game theory: it honestly finds no Pareto-optimal Nash equilibrium and derives mixed-strategy bounds, which is a reasonable outcome. The author is also straight about the chapters being published work, so the compilation itself is not hiding its provenance.\n\nThe soft spots. The biggest is Chapter 3's 'new variable δ.' The abstract and Section 3.3 claim that classical pre-processing with δ raises the tolerable error threshold, but the text never defines δ, its range, or what physical statistics fix its value. Figure 3.1 plots curves with and without δ, but without a derivation, the 'with δ' curve is an envelope over free parameters, not a lower bound—so the claimed efficiency advantage over SARG04 is not established. Second, the P(B|A) table in Section 2.2.4.3 is internally inconsistent: the same row says 1/8 and 3/8 for the same condition. Third, the promised defense against key-space-reduction attacks for Protocols 2.1/2.2 is announced in Section 1.5.1.2 but never delivered in Section 2.2.4—and given Zawadzki's protocol was broken by exactly that attack, this is a gap the authors need to fill. Fourth, the QKD security analysis is limited to intercept-resend and selected collective attacks, with no finite-size or composable analysis, so 'rigorously proven' in the abstract overshoots.\n\nVerdict: worth a serious referee. A referee can demand the δ derivation, fix the table, and require the missing key-space-reduction argument. The QIA review alone justifies engaging with it. I'd send it to peer review expecting major revision. Reading group: only if someone is surveying QIA; the protocol chapters need pinning down first.","headline":"A thesis compilation whose QIA survey is genuinely useful, but the QKD security claims rest on an undefined parameter δ and a wobbly probability table.","tokens_in":49295,"tokens_out":3261,"would_cite":false,"duration_ms":33965,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["81P94","91A10"],"pacs":["03.67.Dd"],"model":"deepseek-v4-flash","headline":"This thesis proposes two QKD protocols that run on commercial photon sources and claims they beat SARG04 in efficiency and PNS critical distance while staying secure against named attacks.","keywords":["quantum key distribution","quantum identity authentication","photon-number-splitting attack","Bell states","controlled quantum key agreement","Nash equilibrium","quantum secure direct communication","discrete-variable protocols"],"falsifier":"Construct a collective attack outside the named menu, for example Eve storing all signals in a quantum memory and performing a joint measurement after sifting, or entangling her probes across multiple signals, and compute Eve's accessible information against Protocol 3.1 or 3.2. If her information exceeds the claimed bound while Bob's observed QBER stays below the tolerable threshold, the restricted-adversary assumption is violated and the security claim fails as stated.","tokens_in":48359,"feed_emoji":"🔐","tokens_out":5882,"duration_ms":63340,"temperature":0.7,"pith_summary":"The thesis argues that quantum communication can be made more practical by shifting more of the burden from classical announcements onto quantum resources. Its central contribution is a pair of QKD protocols that avoid the need for ideal single-photon sources, using instead weaker and commercially available photon states, and that are claimed to be secure against intercept-resend, photon-number-splitting, and a stated class of collective attacks. The thesis derives key-rate bounds in which a new variable raises the tolerable error threshold, and it computes critical distances under photon-number-splitting attacks that exceed those of BB84 and SARG04. Around this core, it also contributes Bell-state quantum identity authentication schemes, a controlled quantum key agreement protocol that does not require quantum memory, and a game-theoretic QBER bound for the DL04 quantum secure direct communication protocol.","feed_headline":"Two QKD protocols beat SARG04 without ideal single photons","feed_subtitle":"Higher efficiency, stronger PNS resilience, and practical photon sources—plus memory-free key agreement.","key_machinery":"The carrying mechanism is the information-partitioning split: the transmitted information is divided between a classical announcement and a quantum state, and the new QKD protocols reduce the classical announcement relative to SARG04 while encoding more in two-particle quantum correlations. The formal expression of this claim is the key-rate bound in which the new variable δ raises the tolerable error threshold. For the QIA schemes, the central objects are Bell-state correlations and the key-to-Pauli mapping (00→I, 01→X, 10→iY, 11→Z), reinforced by decoy sequences; for the CQKA protocol, the mechanism is a one-way channel using Bell and single-photon states; for the game-theoretic result, mi","core_discovery":"The central claim is that the efficiency and resilience of QKD can be improved by reducing the classical component of the information split and increasing the quantum component. The two proposed protocols, 3.1 and 3.2, use two-particle encoding rather than ideal single photons, and the thesis proves security against intercept-resend, PNS, IRUD, and specific collective attacks. It establishes key-rate bounds showing that a new variable, δ, raises the tolerable QBER, and it reports that the protocols achieve higher efficiency than SARG04 at the cost of using more quantum resources. For the authentication part, the thesis presents controlled QIA protocols based on Bell states and Pauli operatio","pith_inferences":["Editorial extension: the security claims rest on a restricted attack menu; if the same two-particle encoding were analyzed under fully general coherent attacks, the improved δ threshold might or might not survive, and that analysis is the natural next check.","Editorial extension: because the thesis treats δ as a given parameter rather than optimizing it, treating δ as a free variable and scanning it against QBER would produce a practical operating curve for the protocols.","Editorial extension: the Bell-state entanglement-swapping pattern used in the controlled QIA protocol could be adapted into a device-independent authentication test, since it already relies on Bell correlations, though the thesis does not take that step.","Editorial extension: the game-theoretic method for bounding QBER in DL04 could be transferred to other two-way quantum secure direct communication protocols, giving a unified way to set error thresholds, but the thesis applies it only to DL04."],"forward_implications":["QKD could be implemented with the kind of attenuated laser sources already available commercially, rather than requiring ideal single-photon sources.","The proposed protocols would offer higher sifted-key efficiency than SARG04 while resisting PNS attacks, so they could be a practical alternative in lossy channels.","The critical distance under PNS attacks would exceed both BB84 and SARG04 under comparable conditions, extending the usable range of secure key distribution.","Classical pre-processing with the new variable δ would allow the key rate to remain positive at higher error rates, improving noise tolerance.","The controlled QKA protocol would remove the quantum-memory requirement that impedes many existing key-agreement schemes, making them easier to realize with current technology."],"supporting_citations":[{"why":"Provides the original BB84 framework and the single-photon-source assumption that the new QKD protocols are designed to avoid.","marker":"[15]"},{"why":"Defines the photon-number-splitting attack that the proposed QKD protocols are engineered to resist and against which critical distances are computed.","marker":"[170]"},{"why":"Introduces SARG04, the protocol whose efficiency and PNS resilience the thesis claims to surpass.","marker":"[172]"},{"why":"Supplies the Holevo bound used to cap Eve's accessible information in the intercept-resend and key-rate security analyses.","marker":"[274]"},{"why":"Is the DL04 QSDC protocol analyzed in Chapter 5, for which the thesis establishes vulnerability to Pavičić's attack and derives QBER bounds.","marker":"[238]"},{"why":"Is the existing controlled QKA protocol that the proposed CQKA protocol improves upon by avoiding quantum memory and using Bell and single-photon states instead of GHZ states.","marker":"[214]"}],"fun_headline_variants":["Two QKD protocols beat SARG04 using practical photon sources","QKD without ideal single photons: proof against collective attacks","New QKD protocols: practical sources, secure against PNS attacks","Higher QKD efficiency with new key-rate bounds, no ideal photons"],"cache_read_input_tokens":2816,"weakest_assumption_plain":"The load-bearing premise is that Eve's power is limited to the attack menu named in the proofs—intercept-resend, photon-number splitting, unambiguous discrimination, and collective attacks with independent errors—so the claimed key-rate and QBER thresholds do not follow for a general adversary.","fun_headline_variants_meta":{"raw":{"variants":["Two QKD protocols beat SARG04 using practical photon sources","QKD without ideal single photons: proof against collective attacks","New QKD protocols: practical sources, secure against PNS attacks","Higher QKD efficiency with new key-rate bounds, no ideal photons"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000693,"raw_usage":{"total_tokens":2990,"prompt_tokens":776,"completion_tokens":2214,"prompt_tokens_details":{"cached_tokens":256},"prompt_cache_hit_tokens":256,"prompt_cache_miss_tokens":520,"completion_tokens_details":{"reasoning_tokens":2142}},"tokens_in":520,"tokens_out":2214,"duration_ms":16190,"temperature":1.0,"reasoning_tokens":2142,"cache_read_input_tokens":256,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-05T22:45:58.576649+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Construct a collective attack outside the named menu, for example Eve storing all signals in a quantum memory and performing a joint measurement after sifting, or entangling her probes across multiple signals, and compute Eve's accessible information against Protocol 3.1 or 3.2. If her information exceeds the claimed bound while Bob's observed QBER stays below the tolerable threshold, the restricted-adversary assumption is violated and the security claim fails as stated.","supporting_citations":[{"cited_title":"Bounds for the quantity of information transmitted by a quantum commu- nication channel,","cited_arxiv_id":null,"evidence_quote":"Supplies the Holevo bound used to cap Eve's accessible information in the intercept-resend and key-rate security analyses."},{"cited_title":"Secure direct communication with a quantum one-time pad,","cited_arxiv_id":null,"evidence_quote":"Is the DL04 QSDC protocol analyzed in Chapter 5, for which the thesis establishes vulnerability to Pavičić's attack and derives QBER bounds."}],"review_version":1}