{"id":"a99c06ad-729d-4445-9970-f456f5acb1a9","arxiv_id":"2606.01949","paper_version":1,"verdict":"UNVERDICTED","confidence":"LOW","novelty_score":5.0,"correctness_risk":"unknown","formal_verification":"none","parameter_count":0,"one_line_summary":"Two quantum protocols for secure blind decryption with two users preserve message and key secrecy, with the second also hiding the key index and remaining secure against post-protocol server collusion where the classical version fails.","lead":"The paper proposes two quantum protocols for blind decryption with two users and servers that keep the message secret from servers and keys secret from users, allowing User 2 to decrypt while adding key-index secrecy in the second protocol. A generalist might read it to see how quantum states could enable privacy in distributed decryption tasks where classical methods fail against post-protocol server communication.","discovery_kind":"new_method","skeptic_critique":{"model":"grok-4.3","headline":"Post-attack secrecy claim rests on unverified modeling that non-communication during execution plus quantum states suffices to block key-index recovery even after full later exchange","rationale":"The reader's weakest_assumption directly names the modeling choice that carries the post-attack secrecy claim. No additional internal inconsistency or missing step was identifiable from the abstract description of the claim; the full-text security argument would be required to test whether the quantum-classical distinction actually follows from the protocol steps. Therefore the existing UNVERDICTED verdict is left unchanged.","tokens_in":1644,"tokens_out":366,"duration_ms":24779,"concrete_test":"Locate the post-attack analysis section for the second protocol; extract the argument showing why the two servers cannot recover the key index after exchanging their measurement outcomes and classical messages. Re-derive whether that argument still holds if the servers are allowed to pool all information at the end; if the same argument applies verbatim to a suitably defined classical protocol, the claimed quantum advantage is not supported.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The strongest claim is that the second (quantum) protocol maintains secrecy of the key index under post-protocol server communication, while the classical counterpart does not. This requires that the protocol's use of two non-communicating servers during execution, combined with whatever quantum resources are employed, prevents the servers from jointly determining the index after they exchange all local data. The abstract states the modeling choice and the claimed quantum-classical difference, but the load-bearing step is whether the security argument in the full text actually demonstrates that no classical-style correlation or reconstruction becomes possible once communication is allowed post-facto; if the argument only shows security under the during-execution restriction without an explicit quantum no-go for the post-exchange case, the distinction collapses.","agreement_with_reader":"agree"},"referee_report":{"model":"grok-4.3","summary":"The manuscript proposes two quantum protocols for blind decryption involving two users and two servers. User 1 holds an encrypted ciphertext; the servers hold indexed keys, one of which encrypts the ciphertext. User 2 obtains the decrypted plaintext while the protocols are claimed to enforce (i) secrecy of the plaintext from the servers and (ii) secrecy of the keys from the users. The second protocol additionally claims to hide the key index from the servers by using two non-communicating servers during execution and asserts that this secrecy persists even when the servers later exchange all information, whereas the corresponding classical protocol fails.","tokens_in":1798,"tokens_out":420,"duration_ms":19679,"significance":"If the post-attack security argument is rigorous, the result would establish a quantum-classical separation in a collusion model where servers are isolated only during protocol execution but may collude afterward. This is a stronger security requirement than standard semi-honest or non-communicating server models and could be relevant to delegated decryption or multi-server cloud scenarios.","major_comments":[{"comment":"Abstract (post-attack analysis paragraph): the central claim that the quantum protocol maintains key-index secrecy after the servers exchange all local data rests on an unstated modeling assumption that the quantum resources used during the non-communication phase create an information-theoretic barrier that survives full subsequent classical communication. No explicit argument, security definition, or reduction is supplied in the abstract showing why reconstruction of the index becomes impossible for the quantum case while remaining possible classically; this is load-bearing for the stated quantum advantage.","section":"Abstract"},{"comment":"Abstract (second protocol description): the requirement that the two servers are 'non-commuting' is introduced without a formal definition in terms of quantum channels, measurement operators, or no-signaling conditions. It is therefore unclear whether the claimed secrecy follows from standard quantum information constraints or from an additional ad-hoc restriction on the protocol execution.","section":"Abstract"}],"minor_comments":[],"recommendation":"major_revision","confidential_remarks":null},"author_rebuttal":{"model":"grok-4.3","summary":"We thank the referee for the careful reading of the manuscript and the constructive comments on the abstract. We address each major comment below and will revise the abstract accordingly to improve clarity and self-containment while preserving the core claims.","responses":[{"response":"We agree that the abstract, as a concise summary, does not spell out the full security definition or reduction. The main text contains the detailed post-attack analysis showing that the quantum resources (entanglement and measurements performed under the non-communication constraint) create an information-theoretic barrier that prevents index reconstruction even after full classical communication between servers, while the classical protocol allows it. To address the concern, we will revise the abstract to include a brief statement of the modeling assumption and the reason the quantum case differs from the classical one.","revision_made":"yes","referee_comment":"[Abstract] Abstract (post-attack analysis paragraph): the central claim that the quantum protocol maintains key-index secrecy after the servers exchange all local data rests on an unstated modeling assumption that the quantum resources used during the non-communication phase create an information-theoretic barrier that survives full subsequent classical communication. No explicit argument, security definition, or reduction is supplied in the abstract showing why reconstruction of the index becomes impossible for the quantum case while remaining possible classically; this is load-bearing for the stated quantum advantage."},{"response":"We accept that a formal definition is required for precision. The term 'non-commuting' is intended to mean that the servers are restricted to local operations and measurements with no quantum or classical communication during protocol execution, which enforces the no-signaling condition. We will add an explicit definition in the revised abstract (and ensure it is stated clearly in the main text) in terms of quantum channels and the no-signaling principle, confirming that the secrecy follows from standard quantum information constraints rather than an ad-hoc rule.","revision_made":"yes","referee_comment":"[Abstract] Abstract (second protocol description): the requirement that the two servers are 'non-commuting' is introduced without a formal definition in terms of quantum channels, measurement operators, or no-signaling conditions. It is therefore unclear whether the claimed secrecy follows from standard quantum information constraints or from an additional ad-hoc restriction on the protocol execution."}],"tokens_in":1350,"tokens_out":485,"duration_ms":21465,"standing_objections":[]},"desk_editor":{"model":"grok-4.3","letter":"The main points are the two protocols for two-user quantum blind decryption. User 1 supplies ciphertext, servers hold indexed keys, User 2 receives the plaintext, and the usual secrecy conditions on text and keys are maintained. The second protocol adds key-index secrecy by requiring two non-commuting servers that cannot talk during execution, then analyzes what happens when they communicate afterward.\n\nThe constructions lay out the steps clearly and the post-attack analysis is the element that goes beyond standard during-execution security. The claim that the quantum version satisfies secrecy under later server communication while the classical version does not is the specific new angle.\n\nThe soft spot is exactly the load-bearing modeling choice in the post-attack case. The argument needs to show that the quantum states plus the during-execution non-communication rule actually block the servers from recovering the index once they exchange all local data. If the proof only rules out attacks under the non-communication restriction and does not explicitly demonstrate why no classical-style reconstruction becomes possible after the fact, the quantum-classical difference does not follow. The abstract states the outcome but leaves that step to be checked in the full text.\n\nThis is a narrow but concrete piece for people working on quantum secure computation and blind protocols. It deserves a serious referee so the security proofs can be examined directly.","headline":"The paper gives two explicit blind decryption protocols and claims the quantum version with non-communicating servers keeps key-index secrecy even after post-protocol exchange while classical fails, but that distinction rests on the unverified modeling step.","tokens_in":2276,"tokens_out":350,"would_cite":false,"duration_ms":23114,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"grok-4.3","headline":"A quantum protocol for blind decryption with two servers keeps the message and key index secret even after the servers later communicate.","keywords":["quantum secure blind decryption","two users","non-commuting servers","post-attack secrecy","quantum cryptography","blind decryption","key index secrecy","quantum protocols"],"falsifier":"An explicit strategy allowing the servers, after exchanging their post-protocol information, to recover either the plaintext or the index of the used key from the quantum states they received during execution.","tokens_in":2540,"feed_emoji":"🔐","tokens_out":651,"duration_ms":18462,"temperature":0.7,"pith_summary":"The paper introduces two quantum protocols where one user holds an encrypted message, servers hold indexed keys, and a second user obtains the decryption while servers learn nothing about the message and users learn nothing about the keys. The second protocol additionally hides which key was used and relies on two servers that cannot communicate during the run. Analysis shows the quantum version maintains all secrecy requirements even when the servers exchange information afterward, whereas the classical version loses secrecy under the same post-protocol communication.","feed_headline":"Quantum blind decryption stays secret after servers exchange data","feed_subtitle":"Two servers that cannot talk during the run let a user decrypt without revealing the message or key index, and the secrecy survives later co","key_machinery":"Two non-commuting servers that are forbidden from communicating during protocol execution, whose quantum states enforce secrecy of the message, keys, and key index.","core_discovery":"The protocols achieve blind decryption such that User 2 recovers the plaintext while servers gain no information on the plaintext and users gain no information on the keys or, in the second protocol, on the key index; the second protocol uses two non-commuting servers and remains secure against their post-protocol communication, a property that fails for the corresponding classical protocol.","pith_inferences":["The non-communication requirement during execution could be realized by placing the servers in physically separated locations connected only by quantum channels.","The same separation principle might apply to other multi-party quantum tasks that need privacy against later information pooling.","Scaling the protocol to additional users or larger key sets would require checking whether the non-communication condition can still be maintained.","Classical protocols might recover security by adding extra assumptions such as computational hardness, but the paper shows they fail under the stated information-theoretic post-attack model."],"forward_implications":["User 2 obtains the decrypted text without servers learning any information about it.","Servers' keys remain unknown to both users throughout the protocol.","In the second protocol the index identifying the encryption key stays hidden from the servers.","All secrecy properties hold after the servers communicate with each other following protocol completion.","The corresponding classical protocol loses secrecy of the plaintext and key index once the servers communicate afterward."],"fun_headline_variants":["Quantum blind decryption secure after servers communicate post-protocol","Two-user quantum decryption hides data from servers despite later comms","Quantum blind decryption with noncommuting servers resists post-attack leaks","Blind decryption protocol quantum secure even after server data exchange"],"cache_read_input_tokens":64,"weakest_assumption_plain":"The two servers are unable to communicate with each other while the protocol runs, even if they may communicate afterward.","fun_headline_variants_meta":{"raw":{"variants":["Quantum blind decryption secure after servers communicate post-protocol","Two-user quantum decryption hides data from servers despite later comms","Quantum blind decryption with noncommuting servers resists post-attack leaks","Blind decryption protocol quantum secure even after server data exchange"]},"model":"grok-4.3","cost_usd":0.00633,"raw_usage":{"total_tokens":2859,"prompt_tokens":600,"num_sources_used":0,"completion_tokens":64,"cost_in_usd_ticks":63303000,"prompt_tokens_details":{"text_tokens":600,"audio_tokens":0,"image_tokens":0,"cached_tokens":64},"completion_tokens_details":{"audio_tokens":0,"reasoning_tokens":2195,"accepted_prediction_tokens":0,"rejected_prediction_tokens":0}},"tokens_in":600,"tokens_out":64,"duration_ms":18493,"temperature":1.0,"reasoning_tokens":2195,"cache_read_input_tokens":64,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-06-28T14:05:07.538198+00:00","model_set":{"reader":"grok-4.3"},"falsifier":"An explicit strategy allowing the servers, after exchanging their post-protocol information, to recover either the plaintext or the index of the used key from the quantum states they received during execution.","supporting_citations":[],"review_version":1}