REVIEW 2 major objections 6 minor 1 cited by
Asymmetric protocols for mode pairing quantum key distribution with finite-key analysis
T0 review · 2 major / 6 minor · reviewed 2026-08-11 · deepseek-v4-flash
Pith's one-line read This paper argues that asymmetric mode-pairing QKD should be run with independently optimized source intensities rather than extra attenuation, and provides a finite-key security analysis for that setting.
desk verdict Irreproducible simulation formulas and a sign error undermine the paper's central numerical claims, though the underlying idea is worth pursuing. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The argument is carried by the finite-key rate expression $R=2L/N$, with $L$ bounded by $M^Z_{11}\bigl[1-h(e^{Z,\mathrm{ph}}_{11})\bigr] - \lambda_{\mathrm{EC}} - \log_2(2/\varepsilon_{\mathrm{cor}}) - 2\log_2(1/\varepsilon_{\mathrm{sec}})$. Here $M^Z_{11}$ is the number of single-photon Z-pair events estimated from decoy-state yields $y^Z_{11}$, and $e^{Z,\mathrm{ph}}_{11}$ is the phase-error rate estimated from X-pair bit errors by random sampling without replacement. Around that formula the paper builds a source-parameter vector of 12 independent intensities and probabilities, a Chernoff-bound treatment of statistical fluctuations, and a modified particle-swarm optimizer that enforces physical constraints while searching the non-convex rate landscape. The simulation formulas in Appendix B give the average response probability and pair/error counts in terms of Bessel functions and channel transmittances.
What would settle it
Recompute the step from Eq. (5) to Eq. (6) with an independent derivation of the smooth-min-entropy bound: the paper prints $H_{\min}^{\epsilon}(Z|E) \le M^Z_{11}[1-h(e^{Z,\mathrm{ph}}_{11})]$, while a valid lower bound on $L$ requires $\ge$, so checking the sign settles the security claim. As a numerical cross-check, an independent implementation of the Appendix B formulas should reproduce point B of Table IV ($1.84\times10^{-5}$ bit/pulse at $L_A+L_B=200$ km, $\Delta L=50$ km).
Extended reading notes
Core claim
On the paper's own terms, the discovery is that the optimal response to channel asymmetry is not to equalize channels by attenuating the closer party but to let the two sources be genuinely asymmetric. The authors derive a finite-key rate formula for three-intensity decoy-state MP-QKD under the universal composability framework ($\epsilon=10^{-10}$), using Chernoff-bound statistical fluctuations and random sampling without replacement, and they maximize the rate over 12 independent source parameters with a modified particle swarm optimization. The numerical result is that this asymmetric-intensity strategy outperforms attenuation compensation at all tested distances: for $L_A+L_B=200$ km with $\Delta L=50$ km the rate is $1.84\times10^{-5}$ versus $5.71\times10^{-6}$ bit/pulse, and with $\Delta L=100$ km it is $5.89\times10^{-6}$ versus $6.37\times10^{-7}$. The optimized decoy intensities stay close to the rule $\eta_a \nu_a \approx \eta_b \nu_b$, whereas the signal intensities deviate substantially, and increasing the maximum pairing interval improves the rate but does not let the asymmetric finite-key rate surpass the PLOB bound.
Load-bearing premise
The security proof depends on the direction of the smooth-min-entropy bound: the final key-length formula uses the expression in Eq. (5) as a lower bound on the secret randomness remaining to Alice, so if that inequality actually runs the other way, the advertised key rates are not proven secure.
Editorial extensions
If this is right
- At $L_A+L_B=200$ km the asymmetric-intensity strategy gives $1.84\times10^{-5}$ bit/pulse with $\Delta L=50$ km and $5.89\times10^{-6}$ with $\Delta L=100$ km, versus $5.71\times10^{-6}$ and $6.37\times10^{-7}$ for extra attenuation.
- The optimized settings use unequal intensities: $\mu_a$ drops and $\mu_b$ rises as $\Delta L$ grows, so field deployments need not force $\eta_a \mu_a \approx \eta_b \mu_b$.
- The decoy intensities do approximately follow $\eta_a \nu_a \approx \eta_b \nu_b$, giving a practical rule of thumb for setting the decoy states in asymmetric links.
- Finite-key security at $\epsilon=10^{-10}$ is claimed for total pulse number $N=10^{13}$, so the rates are meant to be deployment-relevant rather than asymptotic idealizations.
- Raising the maximum pairing interval $l$ increases the rate, but in the asymmetric finite-key regime the rate stays below the symmetric-channel value and below the PLOB bound.
Reading between the lines
- The near-universal behavior of the decoy intensities ($\eta_a \nu_a \approx \eta_b \nu_b$) suggests a two-stage deployment recipe: fix $\nu_a,\nu_b$ by that rule and optimize the remaining signal intensities and probabilities, shrinking the live calibration problem.
- Because the optimization ignores the rule $\eta_a \mu_a \approx \eta_b \mu_b$ and still obtains high rates, the same independent-intensity approach may lift rates in other asymmetric two-photon-interference QKD schemes, such as twin-field variants, where that rule is often imposed.
- An independent re-derivation of the entropy inequality in Eq. (5) is the first checkpoint before hardware investment: a reversed sign would invalidate the finite-key rate values rather than merely shift them.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The manuscript derives a finite-key security analysis of asymmetric mode-pairing QKD with practical three-intensity decoy states and presents numerical key-rate simulations in which Alice's and Bob's source parameters are optimized independently by a modified particle swarm algorithm. The central quantitative claim is that this asymmetric-intensity optimization substantially improves the secure key rate relative to the strategy of adding extra attenuation to balance the channels, with representative numbers in Table IV (e.g., 1.84e-5 vs 5.71e-6 bit/pulse at 200 km total distance, Delta L = 50 km). The paper also studies how optimized intensities, probabilities, pairing intervals, and block sizes vary with distance.
Significance. The topic is timely: mode-pairing QKD is a leading protocol for moving beyond the repeaterless bound without global phase locking, and asymmetric network deployments need practical finite-key analyses. If the security bound and simulation formulas are correct, the contribution would be a useful engineering-oriented result, and the comparison with the attenuation strategy is a fair baseline. Credit is due for including the composable finite-key framework and for presenting the modified PSO approach; however, the two internal inconsistencies described below currently prevent the results from being taken as validated.
major comments (2)
- [Section II, Eq. (5)] The printed inequality H^epsilon_min(Z|E) <= M^Z_11 [1 - h(e^Z,ph_11)] has the wrong direction for the purpose of Eq. (6). A secure final key length bounded below by the right-hand side requires a lower bound on the conditional smooth min-entropy, i.e., H^epsilon_min(Z|E) >= M^Z_11 [1 - h(e^Z,ph_11)]. As printed, Eq. (5) is an upper bound, so Eq. (6) is not a valid lower bound on the secure key length. The finite-key security conclusion rests on this sign, and the derivation should be corrected to '>=' or otherwise justified.
- [Appendix B, Eqs. (B1)-(B7)] The pair-count prefactors are not consistent with the definitions given. The expected number of successful pairings per round is p [1 - (1-p)^l], and a click at a given round carries intensity label (k^a,k^b) with probability p_{k^a} p_{k^b} q_{k^a k^b} / p. Therefore the expected number of pairs with a specified intensity pair should scale as N [1 - (1-p)^l] / p times the product of the click-biased probabilities. Equations (B2)-(B3) instead define r_p = [1 - (1-p)^l]/p + 1/p and multiply by an additional p^2, yielding a prefactor of order p rather than 1/p. With p ~ 10^-3 and l = 2000, the printed formulas underestimate pair counts by roughly five orders of magnitude and cannot produce the count rates underlying Table IV. The simulation formulas must be corrected, and the reported numbers must be reconciled with the corrected formulas or accompanied by the simulation code.
minor comments (6)
- [Section II, Eq. (7)] The text refers to 'the upper chi and lower chi bounds' but prints both as the same symbol chi; introducing overline{chi} and underline{chi} would make the decoy-state formulas that use these bounds much easier to follow.
- [Section III, Eq. (9)] The notation n^Z_{(ka,kb)} is used for both the upper and lower Chernoff bounds in the printed equation, even though the two must generally take different values; please use distinct symbols, e.g., overline{n} and underline{n}.
- [Appendix A, Algorithm 1] Line 25 of Algorithm 1 uses a quantity R_new(Gbest) that is never defined; the termination criterion should be specified precisely, along with the numerical values of N_PSO, T, w_init, w_final, c1 ranges, c2 ranges, h, and zeta needed to reproduce the optimization.
- [Section III, discussion after Table IV] The statement that the asymmetric-intensity strategy gives 'approximately an order of magnitude' improvement at LA+LB = 200 km is not supported for Delta L = 50 km, where Table IV shows a factor of 3.2; the factor is about 9.2 for Delta L = 100 km. The claim should be made quantitative and split by Delta L.
- [Figure 1 and general notation] The label 'total distance (LA+LB) between Alice and Bob' is imprecise, since LA and LB are the Alice-Charlie and Bob-Charlie distances and Charlie is not necessarily on the direct Alice-Bob path; please rephrase to 'sum of Alice-Charlie and Bob-Charlie distances'.
- [Appendix B, Eqs. (B6)-(B7)] The factor 2 Delta / pi in the X-pair formulas is introduced without explaining whether Delta is measured in radians or how the phase-slice acceptance condition maps to the postselection window; please define this explicitly.
Circularity Check
No circularity: the finite-key analysis and asymmetric-strategy comparison derive from external entropic-uncertainty, decoy-state, and random-sampling results, and the optimization is not a fitted prediction.
full rationale
The derivation chain is self-contained and not circular. The final key-length expression in Eq. (6) is assembled from standard min-entropy, chain-rule, and leftover-hash results cited to external work [22-25], while the decoy-state estimates in Eqs. (8)-(13) follow external published methods [27-32]. The asymmetric-versus-attenuation comparison in Fig. 1 and Table IV uses one common simulation model (Appendix B) with independently optimized source parameters, so the improvement is a genuine optimization result rather than a fitted quantity renamed as a prediction. Self-citations [13,14] only motivate the practicality of MP-QKD and are not load-bearing for the security derivation; under the hard rules, non-load-bearing self-citation is not circularity. Two non-circular correctness risks should nevertheless be weighed separately: (i) Eq. (5) prints H_min^epsilon(Z|E) <= M^Z_11[1-h(e^Z,ph_11)], but substituting that upper bound into Eq. (6) cannot yield a lower bound on L; the printed inequality direction invalidates the key-length derivation as written. (ii) The pair-count prefactors in Eqs. (B1)-(B3) appear inconsistent with the reported Table IV rates, since a click-pairing count per round is of order p[1-(1-p)^l], whereas the printed prefactor p^2 r_p is of order p for the stated parameters; this suggests the published formulas are not the formulas used for the central quantitative claims. Neither issue is a circular reduction of the conclusion to its inputs, so the circularity score remains 0.
Assumptions & free parameters
free parameters (5)
- Z-pair misalignment eZ_d =
1e-6
- X-pair misalignment eX_d =
0.1
- Error correction efficiency f =
1.1
- Total pulse number N =
1e13
- Maximum pairing interval l =
2000
assumptions (5)
- standard math Smooth min-entropy uncertainty relation lower-bounds conditional entropy from single-photon counts and phase error rate (used in Eq. 5).
- standard math Chernoff bound governs statistical fluctuations of observed counts (Eq. 7).
- domain assumption Decoy-state method yields lower bounds on single-photon yields and phase error rates (Eqs. 8 to 12).
- domain assumption Channel model with independent phase-randomized coherent states, fixed loss alpha, detector dark counts pd and efficiency eta_d (Appendix B).
- ad hoc to paper Modified PSO converges to the global optimum of R(g).
Cite this review
Pith. "Pith review of Asymmetric protocols for mode pairing quantum key distribution with finite-key analysis." pith.science (2026). https://pith.science/paper/VRSIHJU5
@misc{pith2026241212593,
author = {Pith},
title = {Pith review of: Asymmetric protocols for mode pairing quantum key distribution with finite-key analysis},
year = {2026},
howpublished = {\url{https://pith.science/paper/VRSIHJU5}},
note = {Machine review of arXiv:2412.12593}
}
read the original abstract
The mode pairing quantum key distribution (MP-QKD) protocol has attracted considerable attention for its capability to ensure high secure key rates over long distances without requiring global phase locking. However, ensuring symmetric channels for the MP-QKD protocol is challenging in practical quantum communication networks. Previous studies on the asymmetric MP-QKD protocol have relied on ideal decoy state assumptions and infinite-key analysis, which are unattainable for real-world deployment. In this paper, we conduct a security analysis of asymmetric MP-QKD protocol with the finite-key analysis, where we discard the previously impractical assumptions made in the decoy-state method. Combined with statistical fluctuation analysis, we globally optimized the 12 independent parameters in the asymmetric MP-QKD protocol by employing our modified particle swarm optimization. The simulation results demonstrate that our work can achieve significantly enhanced secure key rates and transmission distances compared to the original strategy with adding extra attenuation. We further investigate the relationship between the intensities and probabilities of signal, decoy, and vacuum states with transmission distance, facilitating its more efficient deployment in future quantum networks.
Figures
Forward citations
Cited by 1 Pith paper
-
Security Analysis of Mode-Pairing Quantum Key Distribution with Flexible Pairing Strategy
A decoy-state mode-pairing QKD protocol with a tunable round-filtering pairing strategy increases simulated secret key rates by over 65% in the asymptotic case and extends reach in the finite case.
Reference graph
Works this paper leans on
-
[1]
It is reasonable and intuitive to expect that the particles, after initialization, should satisfy Eq
Lines 1- 11 initialize the position, velocity, individual best, and global best of the particle swarm. It is reasonable and intuitive to expect that the particles, after initialization, should satisfy Eq. ( III). An often overlooked detail is that the intermediate parameters must also adhere to 7 their physical significance as shown below 0 < n Z (ka,kb), ...
-
[2]
Addition- ally, from Fig. 2, it can be observed that the value of ηaµa ηbµb is significantly distant from 1, largely deviating from the condition ηaµa ≈ ηbµb. The reason for this phenomenon is that the signal state is primarily used for key gener- ation, where the intensity µa (µb) not only impacts the quantum bit error rate but also influences the probabil...
work page 2000
-
[3]
A. K. Ekert, Quantum cryptography based on bell’s the- orem, Physical Review Letters 67, 661 (1991)
1991
-
[4]
Lo and H
H.-K. Lo and H. F. Chau, Unconditional security of quan- tum key distribution over arbitrarily long distances, Sci- ence 283, 2050 (1999)
1999
-
[5]
P. W. Shor and J. Preskill, Simple proof of security of the bb84 quantum key distribution protocol, Physical Review Letters 85, 441 (2000)
work page 2000
-
[6]
C. H. Bennett and G. Brassard, Quantum cryptography: Public key distribution and coin tossing, in Proceedings of IEEE International Conference on Computers, Systems, and Signal Processing (1984) p. 175
work page 1984
-
[7]
S. Pirandola, R. Laurenza, C. Ottaviani, and L. Banchi, Fundamental limits of repeaterless quantum communica- tions, Nature Communications 8, 1 (2017)
work page 2017
-
[8]
Lucamarini, Z
M. Lucamarini, Z. L. Yuan, J. F. Dynes, and A. J. Shields, Overcoming the rate–distance limit of quantum key distribution without quantum repeaters, Nature 557, 400 (2018)
2018
Show all 39 references
-
[9]
Pittaluga, M
M. Pittaluga, M. Minder, M. Lucamarini, M. San- zaro, R. I. Woodward, M.-J. Li, Z. Yuan, and A. J. Shields, 600-km repeater-like quantum communications with dual-band stabilization, Nature Photonics 15, 530 (2021)
2021
-
[10]
Liu, W.-J
Y. Liu, W.-J. Zhang, C. Jiang, J.-P. Chen, C. Zhang, W.- X. Pan, D. Ma, H. Dong, J.-M. Xiong, C.-J. Zhang, et al., Experimental twin-field quantum key distribution over 1000 km fiber distance, Physical Review Letters 130, 210801 (2023)
2023
-
[11]
P. Zeng, H. Zhou, W. Wu, and X. Ma, Mode-pairing quantum key distribution, Nature Communications 13, 3903 (2022)
2022
-
[12]
Xie, Y.-S
Y.-M. Xie, Y.-S. Lu, C.-X. Weng, X.-Y. Cao, Z.-Y. Jia, Y. Bao, Y. Wang, Y. Fu, H.-L. Yin, and Z.-B. Chen, 9 Breaking the rate-loss bound of quantum key distribution with asynchronous two-photon interference, PRX Quan- tum 3, 020315 (2022)
2022
-
[13]
H.-T. Zhu, Y. Huang, H. Liu, P. Zeng, M. Zou, Y. Dai, S. Tang, H. Li, L. You, Z. Wang, et al. , Experimental mode-pairing measurement-device-independent quantum key distribution without global phase locking, Physical Review Letters 130, 030801 (2023)
2023
-
[14]
L. Zhou, J. Lin, Y.-M. Xie, Y.-S. Lu, Y. Jing, H.-L. Yin, and Z. Yuan, Experimental quantum communica- tion overcomes the rate-loss limit without global phase tracking, Physical Review Letters 130, 250801 (2023)
2023
-
[15]
H.-T. Zhu, Y. Huang, W.-X. Pan, C.-W. Zhou, J. Tang, H. He, M. Cheng, X. Jin, M. Zou, S. Tang, et al. , Field test of mode-pairing quantum key distribution, Optica 11, 883 (2024)
2024
-
[16]
Z. Li, T. Dou, M. Cheng, Y. Liu, and J. Tang, Field ex- perimental mode-pairing quantum key distribution with intensity fluctuations, Optics Letters 49, 6609 (2024)
2024
-
[17]
Tang, H.-L
Y.-L. Tang, H.-L. Yin, Q. Zhao, H. Liu, X.-X. Sun, M.- Q. Huang, W.-J. Zhang, S.-J. Chen, L. Zhang, L.-X. You, et al. , Measurement-device-independent quantum key distribution over untrustful metropolitan network, Physical Review X 6, 011024 (2016)
2016
-
[18]
Rubenok, J
A. Rubenok, J. A. Slater, P. Chan, I. Lucio-Martinez, and W. Tittel, Real-world two-photon interference and proof-of-principle quantum key distribution immune to detector attacks, Physical Review Letters 111, 130501 (2013)
2013
-
[19]
Z. Lu, G. Wang, C. Li, and Z. Cao, Asymmetric mode- pairing quantum key distribution, Physical Review A 109, 012401 (2024)
2024
-
[20]
M¨ uller-Quade and R
J. M¨ uller-Quade and R. Renner, Composability in quan- tum cryptography, New Journal of Physics 11, 085006 (2009)
2009
-
[21]
Chau, Security of finite-key-length measurement- device-independent quantum key distribution using an arbitrary number of decoys, Physical Review A 102, 012611 (2020)
H. Chau, Security of finite-key-length measurement- device-independent quantum key distribution using an arbitrary number of decoys, Physical Review A 102, 012611 (2020)
2020
-
[22]
Jiang, Z.-W
C. Jiang, Z.-W. Yu, X.-L. Hu, and X.-B. Wang, Higher key rate of measurement-device-independent quantum key distribution through joint data processing, Physical Review A 103, 012402 (2021)
2021
-
[23]
J. L. Carter and M. N. Wegman, Universal classes of hash functions, in Proceedings of the ninth annual ACM symposium on Theory of computing (1977) pp. 106–112
1977
-
[24]
Tomamichel, C
M. Tomamichel, C. C. W. Lim, N. Gisin, and R. Ren- ner, Tight finite-key analysis for quantum cryptography, Nature Communications 3, 634 (2012)
2012
-
[25]
Tomamichel and R
M. Tomamichel and R. Renner, Uncertainty relation for smooth entropies, Physical Review Letters 106, 110506 (2011)
2011
-
[26]
Renner, Security of quantum key distribution, Inter- national Journal of Quantum Information 6, 1 (2008)
R. Renner, Security of quantum key distribution, Inter- national Journal of Quantum Information 6, 1 (2008)
2008
-
[27]
Curty, F
M. Curty, F. Xu, W. Cui, C. C. W. Lim, K. Tamaki, and H.-K. Lo, Finite-key analysis for measurement-device- independent quantum key distribution, Nature commu- nications 5, 3732 (2014)
2014
-
[28]
Yin, M.-G
H.-L. Yin, M.-G. Zhou, J. Gu, Y.-M. Xie, Y.-S. Lu, and Z.-B. Chen, Tight security bounds for decoy-state quan- tum key distribution, Scientific Reports 10, 1 (2020)
2020
-
[29]
Wang, Beating the photon-number-splitting attack in practical quantum cryptography, Physical Review Let- ters 94, 230503 (2005)
X.-B. Wang, Beating the photon-number-splitting attack in practical quantum cryptography, Physical Review Let- ters 94, 230503 (2005)
2005
-
[30]
H.-K. Lo, X. Ma, and K. Chen, Decoy state quantum key distribution, Physical Review Letters 94, 230504 (2005)
2005
-
[31]
F. Xu, M. Curty, B. Qi, and H.-K. Lo, Practical aspects of measurement-device-independent quantum key distri- bution, New Journal of Physics 15, 113007 (2013)
2013
-
[32]
C.-H. F. Fung, X. Ma, and H. Chau, Practical issues in quantum-key-distribution postprocessing, Physical Re- view A—Atomic, Molecular, and Optical Physics 81, 012318 (2010)
2010
-
[33]
C. C. W. Lim, M. Curty, N. Walenta, F. Xu, and H. Zbinden, Concise security bounds for practical decoy- state quantum key distribution, Physical Review A 89, 022307 (2014)
2014
-
[34]
Chau, Decoy-state quantum key distribution with more than three types of photon intensity pulses, Physi- cal Review A 97, 040301 (2018)
H. Chau, Decoy-state quantum key distribution with more than three types of photon intensity pulses, Physi- cal Review A 97, 040301 (2018)
2018
-
[35]
W. Wang, F. Xu, and H.-K. Lo, Asymmetric protocols for scalable high-rate measurement-device-independent quantum key distribution networks, Physical Review X 9, 041012 (2019)
2019
-
[36]
Wang and H.-K
W. Wang and H.-K. Lo, Simple method for asymmet- ric twin-field quantum key distribution, New Journal of Physics 22, 013020 (2020)
2020
-
[37]
F. Xu, H. Xu, and H.-K. Lo, Protocol choice and param- eter optimization in decoy-state measurement-device- independent quantum key distribution, Physical Review A 89, 052333 (2014)
2014
-
[38]
F. Xu, B. Qi, and H.-K. Lo, Experimental demonstration of phase-remapping attack in a practical quantum key distribution system, New Journal of Physics 12, 113026 (2010)
2010
-
[39]
Kennedy, Particle swarm optimization, in Encyclopedia of Machine Learning , edited by C
J. Kennedy, Particle swarm optimization, in Encyclopedia of Machine Learning , edited by C. Sam- mut and G. I. Webb (Springer US, Boston, MA, 2010) pp. 760–766. Test Figure Wide Test Figure
2010
Reviewed August 11, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.