{"id":"bb315ca4-81e7-460b-9d10-2ade69af7e5b","arxiv_id":"2607.11252","paper_version":1,"verdict":"ACCEPT","confidence":"HIGH","novelty_score":5.0,"correctness_risk":"low","formal_verification":"none","parameter_count":6,"one_line_summary":"Entanglement-based QKD over a 22 km, 8 dB financial fiber link produced 63.8 kb/s average secure keys for four months at 93.7% uptime and fed a live KMS/VPN.","lead":"A fully automated entanglement-based QKD system ran for four months between two bank data centers over 22 km of fiber, delivering 63.8 kb/s average secure keys into a live key-management system and VPN. It shows that polarization-entanglement QKD can operate hands-off in real financial infrastructure without external timing references or guide lasers.","discovery_kind":"new_application","skeptic_critique":{"model":"grok-4.5","headline":"No significant objection identified","rationale":"The Reader correctly identifies the incomplete security model as the weakest technical premise, yet also correctly judges that it does not break the paper’s actual claim of practical, long-term eQKD integration into financial infrastructure. The experimental metrics, control loops, and system autonomy are independently documented and consistent with the hardware description; the security caveats are stated openly rather than hidden. Consequently no adjustment to the ACCEPT verdict is warranted. The suggested concrete test is a simple consistency check that would still be worth performing but is not expected to overturn the result.","tokens_in":10546,"tokens_out":485,"duration_ms":5439,"concrete_test":"Cross-check the reported average secure-key rate against the raw coincidence statistics implied by the source brightness (6.8 Mcps/mW/nm), 100 GHz filtering, 8 dB channel loss, ≥70 % SNSPD efficiency and the fixed PA output of 52 552 bits per 10^5-bit block; if the measured 63.8 kb/s cannot be recovered within ~20 % under those parameters, the throughput claim would need re-examination.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The paper’s central claim is operational feasibility of a fully automated polarization-entanglement eQKD system in real financial data-center fiber (22 km / 8 dB), with multi-month continuous key generation, active polarization control from QBER feedback alone, intrinsic-pair timing synchronization, and actual KMS/VPN consumption. That claim is supported by the reported rates (63.78 ± 1.02 kb/s), 93.7 % uptime with zero quantum-optical downtime, QBER < 2 % for 97.4 % of the time, and the explicit system architecture (source metrics, PAM splitting ratios, SNSPD jitter, CD budget, LDPC parameters). The incomplete finite-key model (computational MA/EV tags, uncharacterized post-processing randomness, and imperfect 50/50 + equal-efficiency assumptions left for a future upgrade) is already disclosed in §III.B and does not undercut the feasibility demonstration; the authors never claim information-theoretic composable security for the produced keys. No other internal inconsistency or unsupported quantitative assertion appears load-bearing for the stated claim.","agreement_with_reader":"agree"},"referee_report":{"model":"grok-4.5","summary":"The manuscript reports a four-month field deployment of a fully automated polarization-entanglement BBM92 QKD system over a 22 km / 8 dB dark-fiber link between two operational financial data centers. The system continuously produced post-processed keys at a reported average rate of 63.78 ± 1.02 kb/s with 93.7% uptime (no quantum-optical downtime), kept QBER below 2% for 97.4% of the time via QBER-feedback polarization control only, and achieved sub-300 ps timing synchronization from intrinsic pair correlations without external time references or polarized guide lasers. Keys were handed to a KMS and consumed to establish a VPN tunnel (SKIP) and via an ETSI GS QKD 014 interface. Optical source metrics (visibility ≥ 99.4%, heralding ≥ 65%, spectral brightness), PAM splitting ratios, SNSPD performance, chromatic-dispersion budget, LDPC parameters (n = 10^5, m = 28 000, f_FER ≈ 1.16 at 4% QBER), and Circulant privacy amplification are specified, with finite-key security discussed under the Tomamichel–Leverrier framework as a reference model.","tokens_in":10827,"tokens_out":1379,"duration_ms":27089,"significance":"If the operational claims hold, this is a concrete maturity milestone for entanglement-based QKD: multi-month hands-off operation inside real financial infrastructure, with keys actually consumed by production networking equipment, and with autonomy features (QBER-only polarization control; pair-correlation timing; no guide lasers or external clocks) that matter for scalable deployment. The long-term rate, QBER, uptime, clock-drift, and polarization-control datasets over ~2800 h, together with explicit attribution of downtime causes and optical budgets, are stronger evidence than typical short field trials. The multi-user WDM path noted via prior source work further increases practical interest. The incomplete composable-security stack is disclosed rather than hidden, which is appropriate for a feasibility demonstration.","major_comments":[{"comment":"Abstract, Fig. 2 caption, and §IV call 63.78 ± 1.02 kb/s the “secure key rate” Rs, yet §IV states that the PA output length was fixed to 52 552 bits per block “in order to characterize the throughput of the deployed post-processing pipeline,” while §III.B’s finite-key reference model only quotes ε ≈ 10^{-20} (17 000 bits) and ε ≈ 10^{-7} (25 000 bits). Under that model the reported Rs is not a secret-key rate at the stated security parameters; the abstract and main quantitative claim therefore overstate what was demonstrated. Report both the pipeline throughput and the rate under the cited finite-key lengths (or recompute ε for 52 552 bits), and align terminology (“post-processed key rate” vs “secret key rate under [30]”) throughout abstract, Fig. 2, and conclusion.","section":null},{"comment":"§III.B explicitly uses computationally secure MA/EV tags, does not supply post-processing randomness from a characterized QRNG, and relies on measurement assumptions (equal detection efficiencies in both bases; exact 50/50 splitter) that the authors state are not fully met and are left for a future composable upgrade. That disclosure is good, but the abstract and conclusion still speak of “secure keys” without any qualifier. Add a short, prominent caveat (abstract or opening of §IV/V) that the distilled keys are evaluated under a reference finite-key model with the listed computational and measurement assumptions, so readers do not take the deployment as a claim of information-theoretic composable security.","section":null}],"minor_comments":[{"comment":"§III.A: PAM splitting ratios are given as 49.6%/50.4% (Alice) and 49.9%/50.1% (Bob). Briefly state how these were measured and whether any residual bias is folded into the QBER or PE analysis.","section":null},{"comment":"Fig. 2 yellow-shaded interval: QBER was “not recorded” during the eight-day unstable period. Clarify whether polarization control was still running and how the reduced Rs in that window was computed if QBER feedback was unavailable.","section":null},{"comment":"§IV / Fig. 4: clock re-synchronization is triggered at 500 µs relative drift. State the coincidence-window width used for sifting and how residual drift within a block affects accidental coincidences and QBER.","section":null},{"comment":"Eq. (5)–(6): f_FER ≈ 1.16 is given from “decoding simulations” at 4% QBER. Add the simulated FER value (or a short table) so the efficiency number is reproducible.","section":null},{"comment":"Introduction and conclusion cite multi-user WDM scalability to ~10 users via [15,16]. A single sentence on how many ITU channels the present source actually supports under the deployed filtering (C21/C23) would make that claim more concrete.","section":null},{"comment":"Typographical/formatting: “EV ALUA TION” in the §IV heading; inconsistent spacing in “63.78 ±1.02” vs “63.78 ± 1.02”; arXiv-style “Tech. Rep.” entries for Grover/Shor could be completed with standard bibliographic details.","section":null},{"comment":"Fig. 1(a) map caption notes the red line is illustrative only; consider stating the actual fiber route length vs geographic distance if available, since 22 km / 8 dB already implies non-ideal loss.","section":null}],"recommendation":"minor_revision","confidential_remarks":"The central feasibility claim is well supported by long-term operational data and is suitable for a high-quality applied quantum-optics / quantum-communications venue. The only load-bearing presentation issue is the mismatch between the advertised “secure key rate” and the PA length used for the finite-key reference model; that is fixable by clarification and dual reporting of rates, which is why I recommend minor_revision rather than major_revision. No evidence of circularity or fabricated metrics. Fit to a serious quant-ph / applied-physics journal is good; pure theory venues would be a weaker match."},"author_rebuttal":null,"desk_editor":{"model":"grok-4.5","letter":"This is a clean operational result: four months of hands-off polarization-entanglement QKD over a real 22 km / 8 dB dark fiber between financial data centers, average post-processed rate 63.8 kb/s, 93.7 % uptime with zero quantum-optical downtime, QBER held under 2 % for 97.4 % of the time by QBER-only feedback, and keys actually handed to a KMS and used for a VPN tunnel. No guide lasers, no external high-precision clocks—only intrinsic pair correlations for sub-300 ps timing. That combination is the new content.\n\nPrior field eQKD (Pelet 50 km, Craddock NYC, Joshi multi-user) already exists and is properly cited. What this paper adds is the duration, the financial-institution constraints, the full automation, the intrinsic-only sync, and the live consumption path. The data are concrete: source metrics (visibility ≥99.4 %, heralding ≥65 %), CD budget (293 ps, no compensation needed), PAM ratios, SNSPD jitter, LDPC parameters (n=10^5, m=28k, f_FER≈1.16), clock-drift sawtooth, and polarization-controller voltages over a day. Downtime causes are attributed and none are optical. Figures match the claims.\n\nThe soft spot is exactly the one the authors flag in III.B: they invoke Tomamichel–Leverrier as a reference model while using only computational MA/EV tags, uncharacterized post-processing randomness, and imperfect 50/50 + equal-efficiency assumptions. They do not claim full composable security; they leave that for a future upgrade. That is honest and does not undercut the feasibility demonstration. Free parameters (QBER thresholds, PE fraction, PA length for throughput) are engineering choices, not hidden knobs that manufacture the result.\n\nThis is for people who care about whether eQKD can sit in a real rack and keep producing usable keys under data-center conditions. Math and citations look solid; no circularity. I would send it to referees without hesitation—it is a well-supported deployment paper, not a protocol or proof paper. Worth reading if you work on metro QKD or critical-infrastructure crypto; skip if you only want new theory.","headline":"Solid multi-month field demo of automated polarization eQKD in live financial data centers with real KMS/VPN use; security model is incomplete but openly flagged and not load-bearing for the feasibility claim.","tokens_in":11472,"tokens_out":585,"would_cite":true,"duration_ms":6417,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"grok-4.5","headline":"A fully automated entanglement-based QKD system ran for four months over real bank dark fiber, continuously producing secure keys that were used to open a VPN tunnel.","keywords":["entanglement-based QKD","polarization entanglement","financial infrastructure","dark fiber","BBM92","active polarization control","key management system","VPN"],"falsifier":"An independent cryptographic audit of the keys stored in the KMS, or of the VPN traffic they protected, that demonstrated residual information leakage larger than the privacy-amplification bound (for example from the computational authentication tags or from basis imbalance) would falsify the claim of practical secure integration.","tokens_in":11439,"feed_emoji":"🔐","tokens_out":820,"duration_ms":20107,"temperature":0.7,"pith_summary":"The paper shows that polarization-entanglement quantum key distribution can be installed as ordinary infrastructure between two operational data centers of a financial institution. Over 22 km of existing dark fiber with 8 dB loss, the system generated post-processed secret keys at an average 63.8 kb/s for four months and handed them to a key-management system that established a live VPN tunnel. Polarization drifts were corrected automatically from the quantum bit-error rate alone, and the two sites stayed synchronized by using only the arrival-time correlations of the entangled photon pairs; no polarized guide lasers or external high-precision clocks were required. Total uptime reached 93.7 percent, with none of the downtime caused by the quantum optics. The result is concrete evidence that this form of QKD has left the laboratory and can already serve high-security operational networks.","feed_headline":"Bank data centers ran entanglement QKD for four months","feed_subtitle":"63.8 kb/s secure keys over 22 km fiber, no external clocks or guide lasers","key_machinery":"Active three-axis fiber polarization compensation driven only by real-time QBER feedback, together with coincidence-histogram timing recovery from the intrinsic temporal correlations of the entangled pairs; these two closed loops keep QBER below 2 percent for 97.4 percent of the time and timing precision under 300 ps without auxiliary classical reference signals.","core_discovery":"Entanglement-based QKD using polarization-entangled photon pairs can operate as a fully automated, production-grade service on real metropolitan dark fiber between financial data centers, continuously delivering error-corrected and privacy-amplified keys at tens of kilobits per second for months while relying solely on the pairs themselves for polarization control and timing synchronization.","pith_inferences":["Closing the remaining security gaps (information-theoretic tags and a characterized QRNG) would let the identical hardware claim fully composable security at the demonstrated rates.","Intrinsic-pair timing recovery could eliminate costly external clock distribution in other fiber quantum networks.","Banks that already own dark-fiber rings could add eQKD as a software-managed service layer without new civil works."],"forward_implications":["Financial institutions can already consume entanglement-generated keys through standard key-management systems and VPN protocols on existing dark fiber.","The same source architecture supports multi-user metropolitan networks by wavelength-division multiplexing up to roughly ten users.","Coexistence of quantum and classical traffic on shared fiber is the immediate next engineering step the design anticipates.","Passively stable SPDC sources remove the need for frequent optical realignment inside data-center racks."],"fun_headline_variants":["Banks ran entanglement QKD four months over 22 km fiber","eQKD supplied 63.8 kb/s keys to bank data centers for months","Standalone polarization eQKD linked financial centers 22 km","Automated eQKD ran 4 months on bank dark fiber without clocks","Entangled-photon QKD served financial VPN keys continuously"],"cache_read_input_tokens":128,"weakest_assumption_plain":"The security numbers rest on a finite-key proof that assumes information-theoretic authentication, a characterized quantum random-number source, and perfectly balanced detectors—none of which the deployed system fully supplies.","fun_headline_variants_meta":{"raw":{"variants":["Banks ran entanglement QKD four months over 22 km fiber","eQKD supplied 63.8 kb/s keys to bank data centers for months","Standalone polarization eQKD linked financial centers 22 km","Automated eQKD ran 4 months on bank dark fiber without clocks","Entangled-photon QKD served financial VPN keys continuously"]},"model":"grok-4.5","effort":"low","cost_usd":0.006836,"raw_usage":{"total_tokens":1664,"prompt_tokens":691,"num_sources_used":0,"completion_tokens":94,"cost_in_usd_ticks":68360000,"prompt_tokens_details":{"text_tokens":691,"audio_tokens":0,"image_tokens":0,"cached_tokens":256},"completion_tokens_details":{"audio_tokens":0,"reasoning_tokens":879,"accepted_prediction_tokens":0,"rejected_prediction_tokens":0}},"tokens_in":691,"tokens_out":94,"duration_ms":8333,"temperature":1.0,"reasoning_tokens":879,"cache_read_input_tokens":256,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-07-14T05:59:25.667614+00:00","model_set":{"reader":"grok-4.5"},"falsifier":"An independent cryptographic audit of the keys stored in the KMS, or of the VPN traffic they protected, that demonstrated residual information leakage larger than the privacy-amplification bound (for example from the computational authentication tags or from basis imbalance) would falsify the claim of practical secure integration.","supporting_citations":[],"review_version":1}