{"id":"ca83f01f-1cda-4cf1-b0f5-4631d82865a9","arxiv_id":"2608.09793","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":2,"one_line_summary":"New analytical bounds give positive secret key rates for passive-basis-choice BB84 with large detection-efficiency mismatch, including a satellite QKD pass where prior analysis yielded zero.","lead":"This paper derives new analytical formulas for the secure key rate of BB84 quantum key distribution when the receiver uses a passive beamsplitter basis choice and four detectors with unequal efficiencies. The formulas give positive key rates for a Micius satellite-to-ground experiment where an earlier analysis gave zero, and the authors use them to estimate a secret key length of 310,400 bits.","discovery_kind":"extension","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Decoy-state rate formula Eq. (34) drops the p_a^2 weights present in Eq. (23), so the reported 310,400-bit key length is likely overstated by about a factor of 4.","rationale":"The reader's identified weakest assumption, the single-photon-Bob approximation, is a real and acknowledged limitation: it restricts Eve from sending multiphoton states to Bob, which is not the usual unrestricted-Eve security model. However, it is stated as a limitation in the Conclusion, and it does not by itself make the analytical derivations internally inconsistent. A more direct and checkable obstruction is the normalization mismatch between Eq. (23) and Eq. (34). In Eq. (23) each basis contributes p_a^2 p_pass,a, and p_pass = sum_a p_a^2 p_pass,a. The decoy-state estimates in Sections V inherit the same normalization as the simulated p_{a,alpha} in Eq. (37), which do not contain p_a^2. Therefore the decoy-state adaptation of Eq. (23) must keep p_a^2 in the first sum; Eq. (34) omits it. With p_z = p_x = 1/2 this changes the positive entropy term by a factor of 4. The 310,400-bit result is said to come from Eq. (34), so the primary quantitative claim is affected. The qualitative conclusion that the proposed method can give a nonzero rate where the Ref. [26] adaptation gives zero may still survive, since the corrected rate is lower but not necessarily zero. For this reason I do not recommend moving from the reader's CONDITIONAL verdict; I recommend treating the correction of Eq. (34) and re-running the numerical section as a required condition, and additionally resolving the single-photon-Bob limitation before claiming security against an unrestricted Eve.","tokens_in":18697,"tokens_out":21598,"duration_ms":208034,"concrete_test":"Re-derive Eq. (34) from Eq. (23) by substituting s1 p_{a,alpha} for p_{a,alpha} while keeping the prefactor p_a^2 and the definition p_pass = sum_a p_a^2 p_pass,a. Then recompute the integrated key length for the Micius-Zvenigorod parameters of Tables I and II using Eqs. (37)-(39). If the result is approximately one quarter of 310,400 bits (or otherwise differs by the missing p_a^2 factor), then Eq. (34) as printed is invalid and the headline numerical claim is overstated. If the authors intended s1 p_pass,a to include p_a^2, that redefinition must be stated explicitly and tracked through Eqs. (31)-(35).","verdict_should_be":"UNCHANGED","load_bearing_attack":"The decoy-state rate formula used to produce the headline 310,400 bits is not the decoy-state version of Theorem 1. In Eq. (23) each per-basis bracket is weighted by p_a^2 p_pass,a, and p_pass is defined as sum_a p_a^2 p_pass,a (Eq. 26). The observables in Eq. (19) are normalized by 1/p_a^2 (Eq. 18), so the quantities p_{a,alpha} are conditional on both Alice and Bob choosing basis a; Eq. (37) simulates nu p_{a,alpha} as p_{mu nu}/2 times a detection factor, again without the p_a^2 factor. The decoy estimates s1 p_{a,alpha} in Eq. (31) inherit this normalization. Replacing p_{a,alpha} by s1 p_{a,alpha} in Eq. (23) must therefore preserve the weights p_a^2, giving sum_a p_a^2 s1 p_pass,a [ h(...) - h(...) ]. Eq. (34), however, writes sum_a s1 p_pass,a [ h(...) - h(...) ], dropping p_a^2. For p_z = p_x = 1/2 (Table I), this multiplies the positive entropy contribution by 4 relative to the error-correction term -s p_pass f h(Q). The integrated key length 310,400 bits is computed from Eq. (34); restoring the missing factor changes it by about a factor of 4. This is an internal normalization inconsistency independent of the single-photon-Bob limitation, and it directly affects the central numerical claim.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper derives analytical lower bounds on the asymptotic secret-key rate of BB84 with passive basis choice and four threshold detectors exhibiting detection-efficiency mismatch. The central formula is Eq. (23), with simplified variants in Eqs. (27) and (29), and a decoy-state adaptation in Eq. (34). The method is applied to the Micius–Zvenigorod satellite QKD experiment, with the reported integrated key length of 310,400 bits. The appendices contain the main derivations, including a symmetry reduction and relative-entropy monotonicity argument, as well as a comparison with the approach of Ref. [26].","tokens_in":19066,"tokens_out":9344,"duration_ms":87599,"significance":"If the derivation is sound under its stated assumptions, the paper offers a useful analytical alternative to numerical security proofs for passive-basis BB84 with detector-efficiency mismatch, and it explicitly identifies a regime where the earlier analytical approach of Ref. [26] gives zero key rate. The authors are also transparent about two important limitations: the single-photon-Bob assumption and the fact that the detector efficiencies are fitted, not directly measured. However, the decoy-state formula in Eq. (34) contains a normalization inconsistency with Theorem 1, and the single-photon-Bob assumption is not a valid security assumption for the claimed satellite application. These issues affect the central numerical claim and must be addressed before the results can be accepted as a security statement for the described experiment.","major_comments":[{"comment":"Equation (34) is not the decoy-state version of Theorem 1. In Eq. (23) the per-basis entropy bracket is weighted by p_a^2 p_pass,a, and p_pass is defined in Eq. (26) as sum_a p_a^2 p_pass,a. The observables in Eq. (19) are normalized by 1/p_a^2 in Eq. (18), so the quantities p_{a,alpha} entering Eq. (23) are conditional on both Alice and Bob choosing basis a. Replacing p_{a,alpha} by s1 p_{a,alpha} therefore preserves the weights p_a^2, giving sum_a p_a^2 s1 p_pass,a [h(...)-h(...)] - s1 p_pass f h(Q). Equation (34) as printed omits the p_a^2 factor in the first sum. For p_z=p_x=1/2 the positive entropy contribution is inflated by a factor of 4 relative to the error-correction term. The reported 310,400-bit key length, computed from Eq. (34), is consequently not a reliable bound and needs to be recomputed with the correct normalization.","section":"Sec. V, Eq. (34)"},{"comment":"The paper relies on the single-photon-Bob assumption throughout Secs. II–V: if Alice emits a single-photon pulse, Bob receives at most one photon, so Eve cannot send multiphoton states to Bob. For a lossy satellite channel controlled by Eve, this is not a security assumption; an arbitrary Eve can send multiphoton states and induce double clicks. The authors state this limitation in the Conclusion and suggest that counting double clicks would overcome it, but they do not implement that extension. As a result, Eqs. (23), (27), (29), and (34) bound the key rate only for a restricted adversarial model. The abstract and the application to the Micius–Zvenigorod experiment present the result as security for a realistic setup, which is not justified without treating multiphoton arrivals at Bob.","section":"Sec. I and Sec. VII"},{"comment":"The normalization convention for the simulated click probabilities is unclear and appears internally inconsistent. Since Eq. (18) defines the constraints with explicit factors 1/p_a^2, the probabilities p_{a,alpha} in Eq. (23) are conditional on both parties selecting basis a. Equation (37) contains no p_a^2 factor, and Eq. (38) defines nu p_pass as a simple sum over bases and bits without p_a^2, which is inconsistent with Eq. (26). If nu p_{a,alpha} is meant to be conditional, then the count-rate formula in Eq. (40) and the comparison with experimental data in Fig. 1 should include p_a^2. If nu p_{a,alpha} is meant to be absolute, then Eq. (37) misses a factor p_a^2. Either way, the fitted detector efficiencies in Table II and all derived key-rate numbers depend on which convention is used, and the paper does not specify it clearly.","section":"Sec. VI A, Eqs. (37) and (38)"}],"minor_comments":[{"comment":"The minimization notation 'mins1pa,alpha,s1qa,alpha' is unclear: the variable s1 q_{a,alpha} is not defined before Eq. (34), and the text elsewhere uses s1 p_{a,(1-alpha)alpha} for single-photon error probabilities.","section":"Sec. V, Eq. (34)"},{"comment":"The sentence 'this limitation can overcome be counting these clicks' contains a typo; it should read 'this limitation can be overcome by counting these clicks'.","section":"Sec. VII"},{"comment":"The index alpha is used both for the detector label and as the summation index in the definition of G_{z,alpha}, which is confusing; a different summation index would improve readability.","section":"Appendix B, Eq. (B2)"},{"comment":"The horizontal axis label 'Mismatch parameter, ' is missing the symbol eta; it should read 'Mismatch parameter, eta'.","section":"Fig. 3"}],"recommendation":"major_revision","confidential_remarks":"The factor-of-four issue in Eq. (34) is real and load-bearing for the numerical claim. The single-photon-Bob restriction is a more fundamental concern for the claim of security in a realistic satellite setup, though the authors do flag it. If the paper is reframed as a security analysis under the explicit single-photon-Bob restriction, and the normalization in the decoy formula and simulation model is corrected, the mathematical core may be publishable; the current numerical application is not trustworthy."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"The paper closes a real gap: an analytical key-rate bound for passive-basis BB84 that survives a 2.7x detection-efficiency mismatch, where Ref. [26] gives zero. Eq. (23) and its decoy adaptation Eq. (34) are plausible, and the appendices give a reasonably careful derivation via relative-entropy monotonicity and symmetry reductions. The application to the Micius–Zvenigorod pass is well chosen, and the authors are honest about the main limitations: the single-photon-Bob assumption, the asymptotic analysis, and the fact that the detector efficiencies are fitted rather than directly measured.\n\nThe soft spots are real but proportionate. The single-photon-Bob assumption is a genuine restriction — it rules out multiphoton attacks on Bob's side — and the authors flag it but do not implement the double-click counting fix. The numerical 310,400-bit claim also depends on efficiencies that are best-fit values, so a cautious reader should treat that number as indicative, not definitive.\n\nI checked the stress-test concern that Eq. (34) drops a p_a^2 factor present in Eq. (23). On reading, I think that concern does not land. The decoy-estimated quantities s1 p_{a,\\alpha} are obtained from the observed click rates of Eq. (37), which are raw per-pulse probabilities; the per-basis term in Eq. (23) is homogeneous of degree one in the conditional probabilities, so replacing conditional probabilities with raw rates and omitting the explicit p_a^2 weight gives the same numerical value. The p_a^2 is already absorbed in the raw rates. The paper's notation is nevertheless confusing: it calls s1 p_{a,\\alpha} \"detection probabilities\" without specifying whether they are conditional or raw, and the instruction to \"replace p_{a,\\alpha} in Eq. (23)\" invites exactly this misinterpretation. The authors should add a sentence clarifying the normalization.\n\nThis paper is for researchers working on practical satellite QKD security proofs, especially those needing fast analytical bounds for real-time privacy amplification. It deserves a serious referee. I would send it to peer review with a request to clarify the decoy-state normalization and to add a short sensitivity note for the fitted efficiencies.","headline":"Useful analytical extension for passive-basis BB84 with detection-efficiency mismatch; the central bound looks plausible, the decoy-state normalization issue is likely a non-issue but needs explicit clarification, and the numerical key rate should be treated as provisional because it rests on fitted detector efficiencies.","tokens_in":19593,"tokens_out":28635,"would_cite":true,"duration_ms":236369,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["81P94"],"pacs":["03.67.Dd"],"model":"deepseek-v4-flash","headline":"The paper proves a lower bound on the BB84 secret key rate that stays positive under large detector-efficiency mismatches and estimates 310,400 secret bits for a satellite-to-ground pass where an earlier bound gave zero.","keywords":["quantum key distribution","BB84 protocol","passive basis choice","detection-efficiency mismatch","decoy state method","satellite QKD","secret key rate","threshold detectors"],"falsifier":"Measure the rate of double clicks at the four detectors during the satellite pass analyzed in the paper: if the fraction of accepted events with simultaneous clicks in two or more detectors is not negligible, the single-photon Bob assumption fails and the 310,400-bit estimate may not be a valid lower bound. Alternatively, construct an Eve strategy that sends two-photon pulses, matches the observed single-detector click and error statistics, and yields a genuine key rate below Eq. (23).","tokens_in":18521,"feed_emoji":"🔐","tokens_out":14221,"duration_ms":110533,"temperature":0.7,"pith_summary":"This paper addresses a practical flaw in BB84 quantum key distribution: four threshold detectors on the receiving side have unequal efficiencies, and the measurement basis is chosen passively by a beam splitter rather than by an active random number generator. The authors aim to prove a useful security bound that stays positive under large efficiency mismatches, which existing analytical passive-basis proofs do not. They derive an analytical lower bound on the asymptotic secret key rate, Eq. (23), together with two simplified versions and a decoy-state adaptation, Eq. (34), and apply it to the satellite-to-ground experiment considered in the paper, obtaining 310,400 secret bits for one 220-second pass. In the same scenario, adapting the earlier approach of Ref. [26] yields zero bits. The value of the result, if correct, is that a short satellite pass can be processed quickly enough for real-time privacy amplification despite significant detector inhomogeneity.","feed_headline":"New bound yields 310,400 secret bits despite detector mismatch","feed_subtitle":"A tighter passive-basis BB84 key-rate bound survives efficiency gaps up to 2.7x that zero out earlier proofs.","key_machinery":"The central object is the symmetrized sifted state: after the virtual measurement and basis sifting, the state is block diagonal in the basis register, with each block a $4\\times4$ real matrix whose off-diagonal terms are controlled by the detector efficiencies. The paper uses positive trace-preserving maps that commute with sifting and with the decoherence defining Alice's bit, restricting the optimization over all initial states compatible with the observed click and error statistics to states of this symmetric form. The conditional entropy term in the secret-key-rate formula is then obtained from the eigenvalues of the blocks, and the two parameters $\\delta_{a,a}$ and $\\bar{\\delta}_{a,a}$ carry the physics: the first is the normalized difference of Bob's bit probabilities in basis $a$, and the second is the efficiency-weighted difference between correct and erroneous single-photon detection probabilities. Monotonicity of the quantum relative entropy under these maps makes the reduction legitimate, and the same monotonicity under scaling each $\\eta_{a,\\alpha}$ gives the practical rule that lower bounds on the efficiencies suffice.","core_discovery":"Under the single-photon Bob assumption, the paper establishes the lower bound $$K \\ge \\sum_{a\\in\\{x,z\\}} $p_a^{2}$ p_{\\mathrm{pass},a}\\left[h\\left(\\frac{1-\\delta_{a,a}}{2}\\right)-h\\left(\\frac{1-\\sqrt{\\delta_{a,a}^2+\\bar{\\delta}_{a,a}^2}}{2}\\right)\\right]-p_{\\mathrm{pass}} f h(Q)$$ for BB84 with passive basis choice and four threshold detectors, where $\\delta_{a,a}$ is the normalized bit imbalance and $\\bar{\\delta}_{a,a}$ is the efficiency-weighted error imbalance in basis $a$. The same quantities appear in the decoy-state version, Eq. (34), where raw single-photon rates are replaced by decoy-estimated bounds. The proof reduces the required supremum over Eve-compatible initial states to a small symmetric family whose conditional entropy is computed in closed form, and it shows that the bound is monotone in each detector efficiency. For the experimental parameters of the satellite pass, Eq. (34) gives 310,400 secret bits, while the earlier analytical passive-basis treatment adapted in Appendix C gives zero.","pith_inferences":["A natural extension not developed in the paper is to count double clicks and redo the derivation without the single-photon Bob assumption; the size of the resulting reduction in the 310,400-bit estimate could be measured directly from the experimental data.","The same symmetrization machinery should extend to dark-count-rate mismatch and to detection efficiencies that drift during a pass; a testable prediction is that the key-rate penalty stays small whenever the efficiency ratios remain in the 0.5 to 1 range.","A sharper falsification would be to search numerically for a two-photon Eve attack that matches the observed single-detector click and error statistics but yields a key rate below Eq. (23); finding one would show that the stated bound depends critically on the single-photon assumption."],"forward_implications":["With Eq. (23) or its decoy-state form Eq. (34), a passive-basis BB84 receiver keeps a positive asymptotic key rate for detector-efficiency ratios as large as about 2.7 to 1, the regime of the satellite experiment.","Because the bound is monotone in every detector efficiency, users only need trusted lower bounds on $\\eta_{a,\\alpha}$ rather than exact calibration values.","The simplified formulas Eq. (27) and Eq. (29) use aggregated statistics; on the satellite data they lose less than 10% and 0.1% of the key rate, respectively, so fast online processing is feasible.","Adapting the decoy-state method makes the bound applicable to weak coherent pulse sources, which are the realistic source type in satellite QKD."],"supporting_citations":[{"why":"Supplies the analytical single-photon detection-efficiency-mismatch key-rate method and the symmetrization approach that the paper generalizes to passive basis choice.","marker":"[16]"},{"why":"Extends the method to multiphoton pulses and shows that the decoy-state estimates can be applied separately for each basis and outcome, which the paper adopts.","marker":"[17]"},{"why":"The prior analytical passive-basis result that the paper compares against; its adapted formula gives zero key rate for the experimental parameters considered here.","marker":"[26]"},{"why":"The satellite-to-ground experiment that provides the data, channel model, and detector-efficiency values used in the numerical application.","marker":"[27]"},{"why":"Provides the asymptotic secret-key-rate formula that the paper starts from in Eq. (13).","marker":"[30]"},{"why":"Gives the entropic uncertainty relation used to bound Eve's ignorance and eliminate her subsystem.","marker":"[31]"},{"why":"Supplies the practical decoy-state estimation formulas, applied per basis and per bit to bound single-photon count and error rates.","marker":"[37]"},{"why":"Provides the semi-empirical satellite-to-ground channel transmission model used in Eq. (36).","marker":"[39]"}],"fun_headline_variants":["Satellite QKD: new bound gets 310k bits despite 2.7x detector gap","QKD security proof: 310,400 bits even with detector mismatch","Passive-basis QKD: tighter bound beats efficiency mismatch","New QKD bound gives 310k bits despite 2.7x detector mismatch"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The load-bearing premise is the single-photon Bob assumption: Eve cannot add photons, so a single-photon pulse from Alice produces at most one photon at Bob's receiver and double clicks never have to be analysed; if Eve can send multiphoton states, the key-rate bound in Eq. (23) may overestimate the secure key.","fun_headline_variants_meta":{"raw":{"variants":["Satellite QKD: new bound gets 310k bits despite 2.7x detector gap","QKD security proof: 310,400 bits even with detector mismatch","Passive-basis QKD: tighter bound beats efficiency mismatch","New QKD bound gives 310k bits despite 2.7x detector mismatch"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000858,"raw_usage":{"total_tokens":3708,"prompt_tokens":911,"completion_tokens":2797,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":527,"completion_tokens_details":{"reasoning_tokens":2711}},"tokens_in":527,"tokens_out":2797,"duration_ms":18097,"temperature":1.0,"reasoning_tokens":2711,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-11T10:39:46.084634+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Measure the rate of double clicks at the four detectors during the satellite pass analyzed in the paper: if the fraction of accepted events with simultaneous clicks in two or more detectors is not negligible, the single-photon Bob assumption fails and the 310,400-bit estimate may not be a valid lower bound. Alternatively, construct an Eve strategy that sends two-photon pulses, matches the observed single-detector click and error statistics, and yields a genuine key rate below Eq. (23).","supporting_citations":[{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Supplies the analytical single-photon detection-efficiency-mismatch key-rate method and the symmetrization approach that the paper generalizes to passive basis choice."},{"cited_title":"Marcomini, A","cited_arxiv_id":null,"evidence_quote":"Extends the method to multiphoton pulses and shows that the decoy-state estimates can be applied separately for each basis and outcome, which the paper adopts."},{"cited_title":"Zhang, P","cited_arxiv_id":null,"evidence_quote":"The prior analytical passive-basis result that the paper compares against; its adapted formula gives zero key rate for the experimental parameters considered here."},{"cited_title":"Nahar, D","cited_arxiv_id":null,"evidence_quote":"The satellite-to-ground experiment that provides the data, channel model, and detector-efficiency values used in the numerical application."},{"cited_title":"Khmelev, A","cited_arxiv_id":null,"evidence_quote":"Gives the entropic uncertainty relation used to bound Eve's ignorance and eliminate her subsystem."},{"cited_title":"Duˇ sek, M","cited_arxiv_id":null,"evidence_quote":"Supplies the practical decoy-state estimation formulas, applied per basis and per bit to bound single-photon count and error rates."},{"cited_title":"Wang, Beating the photon-number-splitting attack in practical quantum cryptography, Physical Review Let- ters94, 230503 (2005)","cited_arxiv_id":null,"evidence_quote":"Provides the semi-empirical satellite-to-ground channel transmission model used in Eq. (36)."}],"review_version":1}