{"id":"29914fca-1a96-44c9-9644-b2291868f052","arxiv_id":"2607.23413","paper_version":1,"verdict":"CONDITIONAL","confidence":"HIGH","novelty_score":5.0,"correctness_risk":"low","formal_verification":"none","parameter_count":3,"one_line_summary":"A board-level silicon-photonic QKD transmitter (~167×56×21 mm³) achieves 219.1 kbps secure key over 51.3 km fiber with full onboard protocol processing.","lead":"Researchers built a standalone quantum-key-distribution transmitter the size of a half-height PCIe card around a silicon photonic chip, packing lasers, encoding, random numbers, security, and protocol software into ~0.2 dm³. It delivered 219 kbps of secure key over 51 km of ordinary fiber, showing rack-scale QKD gear can shrink to board level without collapsing performance.","discovery_kind":"extension","skeptic_critique":{"model":"moonshotai/kimi-k3","headline":"The headline SKR rests on a composable finite-key calculation (Eq. 1) whose block size, security parameter ε, and correctness/secrecy correction terms are never stated — the finite-key numbers cannot be verified from the text.","rationale":"The reader's CONDITIONAL verdict is the right landing spot, but for a somewhat different reason than the one given. The reader's weakest assumption — that \"comparable performance\" is asserted without a same-link, same-receiver head-to-head baseline — is a fair observation but not load-bearing, because the paper's central contribution is system-level integration and form factor, which stands on its own measurements, and because the conservative receiver biases the SKR downward, making the comparability claim conservative rather than inflated. The more load-bearing gap is the unreported finite-key bookkeeping behind Eq. (1): block size, security parameter, and the absent-looking ε correction terms. This is a reporting/verifiability flaw rather than evidence of error — the authors cite a standard framework and say details follow [40], and the 12-hour stability data and theory/experiment agreement in Fig. 3(a) are consistent with a correct implementation — so it does not warrant REJECT. It does, however, justify keeping the CONDITIONAL verdict with an added condition: the paper should state the finite-key parameters (block size, ε_cor, ε_sec) explicitly alongside Eq. (1) so the headline SKR is independently reproducible. That condition slots naturally next to the reader's existing data-availability condition. Confidence in this assessment is moderate-high: it is possible the supplemental document already contains these parameters, in which case the concern reduces to a pointer that belongs in the main text.","tokens_in":9654,"tokens_out":1843,"duration_ms":67683,"concrete_test":"Request from the authors (or extract from the supplemental document) the sifted block size, ε budget, and raw detection/error counts for the 51.3 km point; then independently recompute M_1^L and e_1^pU with the fluctuation bounds of [38] (or [39]) and evaluate Eq. (1) including the standard ε_cor/ε_sec correction terms. If the recomputed key length per unit time reproduces 219.1 kbps within a few percent, the concern does not land; if it requires either dropping the correction terms or assuming a block size far larger than any stated accumulation interval, the headline SKR is overstated and must be restated with explicit finite-key parameters.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The strongest claim's quantitative content is \"composable finite-key secure rate of 219.1 kbps over 51.3 km and 17.9 kbps over 101.8 km.\" Those numbers depend entirely on Eq. (1) and the cited framework [36–40]. But the paper never reports the two parameters that most determine a finite-key rate: (i) the sifted-key block size (or accumulation time) per privacy-amplification run, which sets the statistical-fluctuation penalties in M_1^L and e_1^pU via [38,39]; and (ii) the total security parameter ε (and its ε_cor/ε_sec budget). Moreover, Eq. (1) as printed contains only the single-photon entropy terms minus leak_EC; the standard Tomamichel/Lim-style correction terms (e.g., 6·log2(21/ε_sec) + log2(2/ε_cor) bits) do not appear. If they are genuinely omitted rather than suppressed in notation, the key length is overestimated by roughly 100–200 bits per block — negligible for large blocks but material for small ones, and unverifiable either way without the block size. This is distinct from the reader's receiver-baseline concern, which I think partly misfires: the authors explicitly flag the two-detector TDM receiver as lossier and more afterpulse-prone (Sec. 3.1), so the reported SKR is a *conservative* bound on transmitter capability, and the \"comparable performance\" claim is if anything understated. The genuinely soft spot is the opacity of the finite-key arithmetic: \"219.1 kbps\" could correspond to a large-block asymptotic-like regime or a tight small-block regime, and the text does not let a reader tell which. The form-factor/integration claim, by contrast, is well supported (measured dimensions, Table 1, 12-hour run) and survives regardless.","agreement_with_reader":"partial"},"referee_report":{"model":"moonshotai/kimi-k3","summary":"The manuscript reports a standalone decoy-state BB84 QKD transmitter built around a commercial-process SOI encoding chip, integrating optical pulse generation, on-chip attenuation/decoy/polarization encoding, Trojan-horse isolation (>160 dB), a hardware TRNG, synchronization optics, an SoC executing the full real-time post-processing stack (authentication, sifting, Winnow error correction, CRC-64 verification, Toeplitz privacy amplification), and thermal management in 167×56×21 mm³ (~0.2 dm³), >30× smaller than a 1U rack unit. Paired with a discrete-component two-detector TDM receiver, it achieves finite-key secure rates of 219.1 kbps over 51.3 km and 17.9 kbps over 101.8 km of standard fiber at 625 MHz, with a 12-hour stability run and good agreement between measured SKR and simulation.","tokens_in":10034,"tokens_out":3546,"duration_ms":115546,"significance":"If the numbers hold up, this is a meaningful step for the field: most prior integrated-QKD work stops at the photonic chip or requires a rack instrument plus an external PC, whereas here the complete transmitter chain is demonstrated in a board-level module with measured (not extrapolated) finite-key rates at metropolitan distances and a 12-hour continuous stability run. The claims are concrete and falsifiable: stated intensities and probabilities, a stated clock rate, a standard security framework, and an explicit receiver-loss budget. The use of a deliberately conservative two-detector receiver, openly acknowledged in §3.1, strengthens rather than weakens the transmitter claim. The work does not advance QKD theory or photonic-device performance, but it credibly establishes system-level integration as the next milestone for deployable QKD hardware.","major_comments":[{"comment":"The headline figures (219.1 kbps at 51.3 km; 17.9 kbps at 101.8 km) are stated to be composable finite-key rates against general attacks [36–40], but the two quantities that most determine a finite-key rate are never reported: (i) the sifted-key block size per privacy-amplification run (or accumulation time), which sets the statistical-fluctuation penalties in M_1^L and e_1^pU via [38, 39]; and (ii) the total security parameter ε and its ε_cor/ε_sec budget. Furthermore, Eq. (1) contains only the single-photon entropy terms minus leak_EC; the standard correctness/secrecy terms of the Tomamichel/Lim-type analysis (e.g., log2(2/ε_cor) and the privacy-amplification leftover-hash terms such as 2 log2(1/ε_PA) or 6 log2(21/ε_sec)) do not appear. If these are suppressed in notation rather than omitted from the computation, the text must say so explicitly. The measured QBER and leak_EC (or error-","section":"§3.3, Eq. (1)"},{"comment":"The claim of 'performance comparable to conventional discrete-component implementations [28, 29]' is not supported by any same-link or normalized comparison. Reference [29] is a field trial of QKD-secured coherent transport over trusted-node links, not a discrete-component transmitter benchmark; reference [28] is a Sagnac time-bin system at a different encoding and clock rate. The authors do acknowledge (§3.1) that the two-detector TDM receiver is lossier and more afterpulse-prone than a four-detector receiver, which makes the reported SKR conservative — this is commendable and partly mitigates the concern — but 'comparable' remains an unquantified assertion. A short table or sentence comparing SKR-at-distance against [28, 29] (and ideally the 1U systems of Table 1), with the receiver caveat stated, would suffice; alternatively, soften the wording to 'rates consistent with metropolitan-s","section":"§3.3 and §3.1 (comparison to [28, 29])"},{"comment":"The motivation throughout (§1, §4) is deployment on size/weight/power-constrained platforms (UAVs, small satellites, PON access), yet total power consumption of the module is never reported. This is conspicuous given that the thermal-management assembly (heat sink plus three fans, §2.1) is said to occupy 'a substantial fraction of the module volume', implying a non-trivial thermal load. A single number (typical and peak draw) and the operating temperature range over which the 12-hour stability was demonstrated would substantially strengthen the deployment claim, which is the paper's main contribution.","section":"§2.1 / §4 — power consumption not reported"}],"minor_comments":[{"comment":"Grammar: 'after basis sift' should read 'after basis sifting', and 'detailed calculated following [40]' should read 'calculated in detail following [40]'.","section":"§3.3"},{"comment":"The QBER trace is shown in Fig. 3(b) but no numerical value or range is quoted in the text; please state the average QBER at 51.3 km and 101.8 km. Also, the axis labels and legend in the published figure are small and crowded; consider increasing font size for the final version.","section":"Fig. 3"},{"comment":"The 'Security' column mixes two distinct properties (authentication and Trojan-horse protection) into one entry, and 'NR' dominates the table. Defining the column explicitly, and perhaps adding a row-level note on whether each reference implements finite-key composable security, would make the comparison more informative.","section":"Table 1"},{"comment":"Only a bound w < 0.003 is given for the vacuum intensity. Please state the measured value and how the bound is established (e.g., monitor-PIN calibration), since the vacuum yield enters the decoy bounds in Eq. (1).","section":"§3.1 — decoy intensities"},{"comment":"The synchronization laser at 1569.59 nm is only ~19.5 nm from the quantum channel at 1550.12 nm. Please state the measured suppression of sync light at the receiver quantum port (and any Raman-scattering assessment), as out-of-band noise is a common SKR limiter in co-propagating sync schemes.","section":"§2.2 — synchronization path"},{"comment":"'Data not publicly available but may be obtained from the authors upon reasonable request' is weaker than the journal's usual expectation for experimental papers; a supplementary table of the raw count data underlying Fig. 3 would address this and simultaneously support Major Comment 1.","section":"Data Availability Statement"}],"recommendation":"major_revision","confidential_remarks":"Two points for the editor only. First, the author list includes multiple QuantumCTek employees, and the integrated TRNG is identified as a QuantumCTek product (QCTWNG); the statement \"The authors declare no conflicts of interest\" may warrant a follow-up under the journal's disclosure policy. Second, the finite-key opacity in §3.3 (my Major Comment 1) is the one point where the headline numbers rest on unverifiable arithmetic; I expect it is a reporting omission rather than a methodological error, and it should be straightforward for the authors to fix."},"author_rebuttal":null,"desk_editor":{"model":"grok-4.5","letter":"The one thing worth knowing is that they actually built a standalone transmitter—optics, TRNG, authentication, thermal stack, and real-time decoy BB84 post-processing—into ~0.2 dm³ and got 219 kbps at 51 km and 18 kbps at 102 km under a composable finite-key claim. That form-factor jump relative to 1U and lab prototypes is the paper.\n\nWhat is new is system consolidation, not a new protocol or a better chip alone. Table 1 is fair: prior SOI/InP work stopped at PIC or PIC+EIC lab/1U boxes; this one puts Auth + THP + onboard protocol + cooling on a board and runs for 12 hours with stable QBER/SKR. The hybrid optical path (gain-switched DFB + SOI attenuation/decoy/polarization + isolators/WDM) and the SoC+TRNG electronics are described at a level you can follow. They are also honest that the two-detector TDM receiver is lossier and more afterpulse-prone than a four-detector lab box, so the reported rates are a conservative read on the transmitter.\n\nSoft spots, in proportion. The stress-test point lands: Eq. (1) is written without the usual finite-key correction terms, and they never state block size or ε. You cannot recompute 219.1 kbps from the text; that is a real opacity for a headline number, even if large blocks would make the missing bits negligible. The “comparable to discrete-component” claim is literature-only, not same-link head-to-head—minor given they already flag the receiver as conservative. Data and firmware are closed, which is normal for this industry but limits reproduction. None of that breaks the hardware demonstration.\n\nThis is for people building or deploying QKD hardware, UAV/satellite terminals, or multi-user access architectures. Theory readers will skim. It deserves a serious referee; the integration result is concrete and the experimental backbone (rates, stability, parameters) is there. I would engage, push them to put block size and ε in the camera-ready, and move on.","headline":"Real board-level full-stack QKD transmitter at PCIe-card scale with metropolitan finite-key rates; integration is the result, finite-key arithmetic is under-specified.","tokens_in":11219,"tokens_out":552,"would_cite":true,"duration_ms":21399,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"grok-4.5","headline":"A standalone QKD transmitter the size of a half-height PCIe card delivers practical secure keys over metropolitan fiber.","keywords":["quantum key distribution","silicon photonics","integrated transmitter","decoy-state BB84","board-level QKD","SOI","secure key rate","Trojan-horse protection"],"falsifier":"Run this board transmitter and a conventional discrete transmitter back-to-back over the same fiber spool into the same four-detector receiver and check whether the secure key rates at 51 km and 102 km agree within experimental uncertainty.","tokens_in":10885,"feed_emoji":"🔐","tokens_out":883,"duration_ms":29716,"temperature":0.7,"pith_summary":"The paper sets out to show that the remaining barrier to deployable quantum key distribution is system-level integration, not photonic chips alone. The authors pack optical pulse generation, silicon-photonic state encoding, true random numbers, authentication, thermal control, and real-time decoy-state BB84 post-processing into a single board of 167×56×21 mm³—more than thirty times smaller than a conventional 1U rack transmitter. Paired with an ordinary discrete receiver, that board still produces 219.1 kbps of composable secure key over 51.3 km of standard fiber and 17.9 kbps over 101.8 km. A sympathetic reader cares because the result moves QKD transmitters from rack equipment toward board-level modules that can fit size- and weight-limited platforms and multi-user access networks.","feed_headline":"QKD transmitter shrinks to PCIe-card size, still keys 51 km fiber","feed_subtitle":"Board packs silicon photonics, random numbers, and full protocol stack into 0.2 liters—over 30× smaller than a 1U rack","key_machinery":"Hybrid board-level architecture: a silicon photonic chip that performs attenuation, decoy-state intensity modulation, and polarization encoding, driven by a single programmable system-on-chip that also hosts the hardware TRNG, secure element, and real-time BB84 protocol stack.","core_discovery":"A complete standalone QKD transmitter built around a commercial silicon-on-insulator encoding chip, integrating every essential practical function in roughly 0.2 dm³, achieves secure key rates of 219.1 kbps over 51.3 km and 17.9 kbps over 101.8 km of standard single-mode fiber under a composable finite-key decoy-state analysis, with performance the authors judge comparable to conventional discrete-component transmitters.","pith_inferences":["If commercial SOI multi-project-wafer yields hold, unit cost could fall enough for commodity board modules rather than specialty instruments.","Thermal management still occupies a large share of the volume; further shrinkage likely depends on lower-power modulators or denser heat sinking, not photonics alone.","The authors’ choice of a two-detector TDM receiver already anticipates receiver miniaturization; pairing this transmitter with a similarly integrated receiver is the natural next system test."],"forward_implications":["QKD transmitters can shrink from 1U racks to half-height half-width PCIe-card scale while still serving metropolitan fiber links.","Size- and weight-constrained platforms such as UAVs and small satellites become more realistic hosts for QKD transmitters.","Multi-user access networks can place many compact transmitters that share one centralized receiver.","System-level co-integration of photonics, electronics, and protocol processing—not photonic chips alone—is the next practical integration step."],"fun_headline_variants":["Standalone QKD transmitter fits half-height PCIe card volume","Silicon photonics packs full QKD transmitter into 0.2 dm³","Compact QKD board keys 219 kbps over 51 km fiber","QKD transmitter shrinks 30× yet matches discrete-component rates","Board-level QKD transmitter hits 17.9 kbps at 102 km"],"cache_read_input_tokens":128,"weakest_assumption_plain":"The claim of performance comparable to ordinary discrete transmitters rests on literature figures rather than a same-link head-to-head test, and the rates were measured with a two-detector receiver the authors themselves call lossier than a standard four-detector lab receiver.","fun_headline_variants_meta":{"raw":{"variants":["Standalone QKD transmitter fits half-height PCIe card volume","Silicon photonics packs full QKD transmitter into 0.2 dm³","Compact QKD board keys 219 kbps over 51 km fiber","QKD transmitter shrinks 30× yet matches discrete-component rates","Board-level QKD transmitter hits 17.9 kbps at 102 km"]},"model":"grok-4.5","effort":"low","cost_usd":0.002112,"raw_usage":{"total_tokens":925,"prompt_tokens":805,"num_sources_used":0,"completion_tokens":100,"cost_in_usd_ticks":21124000,"prompt_tokens_details":{"text_tokens":805,"audio_tokens":0,"image_tokens":0,"cached_tokens":128},"completion_tokens_details":{"audio_tokens":0,"reasoning_tokens":20,"accepted_prediction_tokens":0,"rejected_prediction_tokens":0}},"tokens_in":805,"tokens_out":100,"duration_ms":2455,"temperature":1.0,"reasoning_tokens":20,"cache_read_input_tokens":128,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-07-30T22:54:27.732512+00:00","model_set":{"reader":"grok-4.5"},"falsifier":"Run this board transmitter and a conventional discrete transmitter back-to-back over the same fiber spool into the same four-detector receiver and check whether the secure key rates at 51 km and 102 km agree within experimental uncertainty.","supporting_citations":[],"review_version":1}