REVIEW 2 major objections 5 minor 1 cited by
Experimental Semi-quantum Key Distribution With Classical Users
T0 review · 2 major / 5 minor · reviewed 2026-08-14 · deepseek-v4-flash
Pith's one-line read Fully classical users, with no quantum operations of their own, can exchange a provably secure quantum key by detecting or reflecting a single photon sent by an untrusted server.
desk verdict A genuinely new fully-classical-user QKD protocol with a serious finite-key analysis; the proof's truncation to ≤2 photons is not matched by the measured source statistics, so the realistic-security claim overreaches. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing mechanism is interaction-free measurement on a single photon in superposition. The server creates $\frac{1}{\sqrt{2}}(|A\rangle+|B\rangle)$ and later recombines reflected photons at a balanced beam splitter; each user’s two classical actions are to reflect the photon or send it to a local detector. The crucial step is that when one user detects and finds nothing, the photon’s location is inferred without absorbing it, which suppresses single-photon interference and lets the “forbidden” detector $D_1$ click, thereby encoding the other user’s action as a key bit. The security argument is carried by a conditional-entropy bound $S(A|C)$—how much uncertainty the adversary, including a dishonest server, has about Alice’s bit—computed from the post-selected state describing Alice’s and Bob’s apparatuses, the server’s announced messages, and the adversary’s ancilla, together with a finite-key formula that turns raw-key length, error-correction leakage, and privacy-amplification penalties into a secret key rate.
What would settle it
Measure the heralded source’s photon-number distribution at the protocol’s operating power with a number-resolving detector, then recompute the finite-key rate with the measured probability of three or more photons per round included; the observed $p_2=0.12$ already deviates from the Poisson value $p_2=0.043$, so a non-negligible higher-order term would directly test whether the $p_0+p_1+p_2\approx 1$ truncation supports the claimed security.
Extended reading notes
Core claim
On its own terms, the central discovery is that a shared secret key can be produced by parties who never prepare, manipulate, or measure a quantum state. The server sends a single photon in the state $\frac{1}{\sqrt{2}}(|A\rangle+|B\rangle)$; Alice and Bob independently choose detect ($D$) or reflect ($R$). When both reflect, single-photon interference sends the photon only to detector $D_0$; when exactly one user detects and sees nothing, the interaction-free measurement collapses the photon onto the other user’s location, making $D_0$ and $D_1$ equally likely, so a click at $D_1$ reveals the other user’s action and fixes the key bit. The practical analysis models a source emitting vacuum, one, or two non-simultaneous photons with probabilities $p_0$, $p_1$, $p_2$, incorporates measured detection efficiencies near 58%, and uses a finite-key conditional-entropy bound to show that the secret key rate is positive after roughly $4.9\times 10^6$ rounds for the implemented losses.
Load-bearing premise
The security analysis assumes the photon source emits at most two photons per round and treats three-or-more-photon emission as negligible; if that probability is not negligible for the actual source, the proven finite-key security may not cover the real implementation.
Editorial extensions
If this is right
- A QKD user’s quantum hardware reduces to a switch that either reflects a photon or routes it to a local detector; no state preparation, multi-basis measurement, or quantum memory is needed.
- The security proof is finite-key and includes imperfect sources and detectors, so the claimed security does not require asymptotic idealizations.
- Because the server is untrusted and may lie about its measurement results, the same analysis bounds both an eavesdropper and a dishonest server.
- Raw-key generation happens without a sifting stage, since the server’s $D_1$ announcement itself determines the bit value and reduces classical communication overhead.
- The finite-key security analysis transfers directly to other single-photon protocols, including counterfactual quantum cryptography and two-way communication with one photon.
Reading between the lines
- Beyond the paper: replacing the at-most-two-photons truncation with a full bound on higher-order emissions—for example via a decoy-state-style analysis—would make the claimed realistic-source security robust to the measured deviation of $p_2$ from its Poisson value.
- Beyond the paper: the architecture suggests a network model in which quantum capability exists only in infrastructure nodes and end users are classical optical terminals; testing this over deployed fiber or free-space links is a concrete next step.
- Beyond the paper: because no authenticated channel is used during raw-key generation, the protocol may require fewer authenticated-communication assumptions than standard sifting-based QKD; quantifying this saving would be a useful direct comparison.
- Beyond the paper: the entropy-bound method is not tied to the folded interferometer, so applying it to counterfactual and two-way single-photon schemes, as the paper itself suggests, is a direct test of the method’s scope.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The manuscript reports an experimental demonstration and security analysis of a QKD protocol in which Alice and Bob are fully classical users: they only choose to detect or reflect a photon sent by an untrusted server, and they extract a raw key from rounds in which the server announces outcome "1" while neither user detects a photon. The paper provides a finite-key security analysis based on the Scarani-Renner bound in Eq. (C.1) and a Krawec-style conditional-entropy bound, applies it to data from about 10^5 experimental rounds, and reports a positive secret key rate for sufficiently large N, becoming positive after about 4.9 x 10^6 rounds in the implemented configuration. Both direct and indirect parameter-estimation procedures are described, with measured values p_key = 1.55(3) x 10^-2 and p_err = 7.5(8) x 10^-4 per round.
Significance. If the security analysis is accepted, the work is a valuable step in reducing the quantum requirements for QKD users: it demonstrates experimentally that two parties who perform only detection/reflection operations can establish a key with the help of an untrusted quantum server, and it attempts a finite-key security treatment under imperfect devices. The manuscript is transparent about its model, gives detailed derivations of the entropy bound and parameter-estimation formulas, presents two estimation methods, and reports uncertainties on the measured quantities. These are genuine strengths. However, the central claim that information-theoretic security is proven for the actual implemented source is not yet supported, because the security analysis excludes higher-order photon-number terms without bounding them, and the finite-key confidence interval used in the rate calculation is assumed rather than derived from the sample size.
major comments (2)
- [E.1 / E.3 / Section C] The security proof is restricted to source states with at most two photons, but the implemented source is not shown to satisfy this. Section E.1 states that 'the probability to emit higher numbers of photons is considered negligible and therefore not included in the analysis, i.e., p0 + p1 + p2 ≈ 1', and the Fock-space decomposition in Section C explicitly separates F^f_k for k > 2 from the analyzed subspace. Yet the verification procedure in Section E.3 reports p0 = 0.72, p1 = 0.16, p2 = 0.12 for a source with average 0.35 photons per round, whereas Poisson statistics would give p2 = 0.043; no bound on p3 or on higher-order terms is provided. Because the server is untrusted, any non-negligible weight on states with more than two photons lies outside the security analysis, and the estimators in Eqs. (E.38)-(E.41) explicitly assume at most two photons. As written, Eq. (C.1) cannot be read as a proven lower bound for the implemented source.
- [E.2.1 / Eqs. (C.1)-(C.2)] The finite-key parameter-estimation step is not justified. The text sets epsilon_PE = 10^-11 and delta = 10^-4 'given our experimental errors', with mu = 1620 sacrificed key rounds, but no concentration bound is used to relate delta to mu and epsilon_PE. For example, a Hoeffding bound would require on the order of 10^9 samples to achieve delta = 10^-4 at confidence level 1 - 10^-11. Without a derivation of delta from the sample size, the confidence interval entering the minimization in Eq. (C.1) is an unquantified free parameter, and the finite-key security level claimed for the plotted rates is not established.
minor comments (5)
- [Throughout] The text repeatedly uses 'semi column' where 'semicolon' is intended; please correct these occurrences.
- [Abstract/Introduction] The introduction contains the typographical artifact '´ınformation-theoretic' in the first paragraph; this should be cleaned up.
- [E.2.1, Eq. (E.28)] In the displayed formula for p_{1,1}, the final term appears as p(D_c D'_c, R ; 1), but by symmetry it should presumably be p(R, D_c D'_c ; 1); please check and correct the labeling.
- [E.2.1 / Figure 5] The text says 'the amount of keys wasted' where 'the number of key bits' is meant; also, the figure captions should state explicitly that r is the secret key rate per round.
- [Section C] The phrase 'server's ancilla system by C, spanned by the Hilbert space H_C' is imprecise; it should read that the ancilla states belong to H_C.
Circularity Check
No significant circularity: the key rate is derived from measured statistics using independent finite-key and entropy bounds; the source truncation is an explicit limitation, not a circular reduction.
full rationale
The derivation chain is a standard QKD security pipeline rather than a circular reduction. The raw-key and error probabilities (pkey, perr) are measured experimental inputs, and the finite-key formula (C.1) is taken from the independent Scarani-Renner framework [32]. The conditional-entropy lower bound S(A|C) is taken from Krawec [33], which is a self-citation but is a published, parameter-free mathematical bound on conditional entropy for arbitrary channels; its assumptions do not include the security of the present protocol, and it is applied as an inequality to states derived from the protocol model rather than fitted to the final key rate. The parameter-estimation equations (E.28)-(E.29) convert observable click statistics into the required probabilities p00, p11, p01 and p10, and the secret key rate is then evaluated from these measured values, so no fitted quantity is renamed as a prediction. The ideal-case and experimental-case analyses are internally consistent, and the only load-bearing external ingredients are standard finite-key and entropy theorems. The appendix explicitly truncates the source model to at most two photons, stating in Section E.1 that 'p0 + p1 + p2 ≈ 1', and Section E.3 reports a measured p2 = 0.12 that deviates from the assumed Poisson value; this is a security-gap or robustness limitation, not a circular step, because the analysis does not assume the rate it claims to prove. No uniqueness claim, ansatz-by-citation, or renaming of a known result is used to force the conclusion, so the paper's central derivation is self-contained apart from independently verifiable external theorems.
Assumptions & free parameters
free parameters (3)
- p0, p1, p2 (source photon-number probabilities) =
p0=0.705, p1=0.247, p2=0.043 (model); measured p0=0.72, p1=0.16, p2=0.12
- detection efficiencies pA_d, pB_d =
0.58 each (loss 0.42)
- confidence interval delta =
10^-4
assumptions (4)
- ad hoc to paper The source emits at most two photons per round (p0+p1+p2=1).
- domain assumption The untrusted server's attack is modeled as a general isometry on the returning photons (Eq. E.7).
- standard math The finite-key security bound and the conditional entropy bound from Refs. [32,33] are valid.
- domain assumption Users' detectors have no dark counts and their switching is ideal.
Cite this review
Pith. "Pith review of Experimental Semi-quantum Key Distribution With Classical Users." pith.science (2026). https://pith.science/paper/7KSPSCUS
@misc{pith2026190801780,
author = {Pith},
title = {Pith review of: Experimental Semi-quantum Key Distribution With Classical Users},
year = {2026},
howpublished = {\url{https://pith.science/paper/7KSPSCUS}},
note = {Machine review of arXiv:1908.01780}
}
read the original abstract
Quantum key distribution, which allows two distant parties to share an unconditionally secure cryptographic key, promises to play an important role in the future of communication. For this reason such technique has attracted many theoretical and experimental efforts, thus becoming one of the most prominent quantum technologies of the last decades. The security of the key relies on quantum mechanics and therefore requires the users to be capable of performing quantum operations, such as state preparation or measurements in multiple bases. A natural question is whether and to what extent these requirements can be relaxed and the quantum capabilities of the users reduced. Here we demonstrate a novel quantum key distribution scheme, where users are fully classical. In our protocol, the quantum operations are performed by an untrusted third party acting as a server, which gives the users access to a superimposed single photon, and the key exchange is achieved via interaction-free measurements on the shared state. We also provide a full security proof of the protocol by computing the secret key rate in the realistic scenario of finite-resources, as well as practical experimental conditions of imperfect photon source and detectors. Our approach deepens the understanding of the fundamental principles underlying quantum key distribution and, at the same time, opens up new interesting possibilities for quantum cryptography networks
Figures
Figures from the paper (2 more)
Forward citations
Cited by 1 Pith paper
-
Lightweight Mediated Semi-Quantum Key Distribution Protocol with a Dishonest Third Party based on Bell States
A mediated semi-quantum key distribution protocol using Bell states lets two classical users share a key through a dishonest third party while needing only Z-basis measurement and Hadamard gates.
Reference graph
Works this paper leans on
-
[1]
Charles H. Bennett and Gilles Brassard. Quantum cryptography: Public key distribution and coin tossing. In Proceedings of IEEE International Conference on Computers, Systems and Signal Processing, volume 175. New York, 1984
work page 1984
-
[2]
S. Pirandola et al. Advances in quantum cryptography. arXiv preprint arXiv:1906.01645 , 2019
arXiv 1906
-
[3]
Quantum cryptog- raphy: key distribution and beyond
Akshata Shenoy-Hejamadi, Anirban Pathak, and Srikanth Radhakrishna. Quantum cryptog- raphy: key distribution and beyond. Quanta, 6(1):1–47, 2017
work page 2017
-
[4]
Quantum key distribution and beyond: introduction
Mohsen Razavi, Anthony Leverrier, Xiongfeng Ma, Bing Qi, and Zhiliang Yuan. Quantum key distribution and beyond: introduction. J. Opt. Soc. Am. B , 36(3):QKD1–QKD2, 2019
work page 2019
-
[5]
Quantum cryptog- raphy with realistic devices
Feihu Xu, Xiongfeng Ma Qiang Zhang, Hoi-Kwong Lo, and Jian-Wei Pan. Quantum cryptog- raphy with realistic devices. arXiv preprint arXiv:1903.09051 , 2019
arXiv 1903
-
[6]
Quantum key distribution with classical bob
Michel Boyer, Dan Kenigsberg, and Tal Mor. Quantum key distribution with classical bob. Phys. Rev. Lett., 99:140501, Oct 2007
2007
-
[7]
Semiquantum key distribution
Michel Boyer, Ran Gelles, Dan Kenigsberg, and Tal Mor. Semiquantum key distribution. Phys. Rev. A , 79:032341, Mar 2009
2009
-
[8]
Experimentally feasible protocol for semiquantum key distribution
Michel Boyer, Matty Katz, Rotem Liss, and Tal Mor. Experimentally feasible protocol for semiquantum key distribution. Phys. Rev. A , 96(6):062335, 2017
work page 2017
Show all 34 references
-
[9]
Semiquantum-key distribution using less than four quantum states
Xiangfu Zou, Daowen Qiu, Lvzhou Li, Lihua Wu, and Lvjun Li. Semiquantum-key distribution using less than four quantum states. Phys. Rev. A , 79(5):052312, 2009
2009
-
[10]
Walter O. Krawec. Mediated semiquantum key distribution. Phys. Rev. A, 91(3):032323, 2015. 7
2015
-
[11]
Mediated semi-quantum key distribution without invoking quantum measurement
Zhi-Rou Liu and Tzonelih Hwang. Mediated semi-quantum key distribution without invoking quantum measurement. Ann. Phys., 530(4):1700206, 2018
2018
-
[12]
Walter O. Krawec. Security proof of a semi-quantum key distribution protocol. In Information Theory (ISIT), 2015 IEEE International Symposium on , pages 686–690. IEEE, 2015
2015
-
[13]
Security of a single-state semi-quantum key distribution protocol
Wei Zhang, Daowen Qiu, and Paulo Mateus. Security of a single-state semi-quantum key distribution protocol. Quantum Inf. Process., 17:1–21, 2018
2018
-
[14]
Robert H. Dicke. Interaction-free quantum measurements: A paradox? Am. J. Phys. , 49(10):925–930, 1981
1981
-
[15]
Elitzur and Lev Vaidman
Avshalom C. Elitzur and Lev Vaidman. Quantum mechanical interaction-free measurements. Found. Phys., 23(7):987–997, Jul 1993
1993
-
[16]
Kasevich
Paul Kwiat, Harald Weinfurter, Thomas Herzog, Anton Zeilinger, and Mark A. Kasevich. Interaction-free measurement. Phys. Rev. Lett., 74:4763–4766, Jun 1995
1995
-
[17]
Loredo, Raphael A
Francesco Lenzini, Ben Haylock, Juan C. Loredo, Raphael A. Abrah˜ ao, Nor A. Zakaria, Sachin Kasture, Isabelle Sagnes, Aristide Lemaitre, Hoang-Phuong Phan, Dzung Viet Dao, et al. Active demultiplexing of single photons from a solid-state source. Laser Photonics Rev., 11(3):16...
2017
-
[18]
Artur K. Ekert. Quantum cryptography based on Bell’s theorem. Phys. Rev. Lett., 67:661–663, 1991
1991
-
[19]
Zhong, M
X. Zhong, M. Hu, Qian L., and Lo H.-K. Proof-of-principle experimental demonstration of twin-field type quantum key distribution. arXiv preprint arXiv:1902.10209 , 2019
1902
-
[20]
Counterfactual quantum cryptography
Tae-Gon Noh. Counterfactual quantum cryptography. Phys. Rev. Lett., 103:230501, Dec 2009
2009
-
[21]
Experimental demonstration of counterfactual quantum key distribution
Min Ren, Guang Wu, E Wu, and Heping Zeng. Experimental demonstration of counterfactual quantum key distribution. Laser Phys., 21(4):755–760, 2011
2011
-
[22]
Experimental realization of counterfactual quantum cryptography
Giorgio Brida, Andrea Cavanna, Ivo Pietro Degiovanni, Marco Genovese, and Paolo Traina. Experimental realization of counterfactual quantum cryptography. Laser Phys. Lett., 9(3):247, 2012
2012
-
[23]
Experimental demonstration of counterfactual quantum communication
Yang Liu, Lei Ju, Xiao-Lei Liang, Shi-Biao Tang, Guo-Liang Shen Tu, Lei Zhou, Cheng- Zhi Peng, Kai Chen, Teng-Yun Chen, Zeng-Bing Chen, and Jian-Wei Pan. Experimental demonstration of counterfactual quantum communication. Phys. Rev. Lett. , 109:030501, Jul 2012
2012
-
[24]
Direct counterfactual communication via quantum zeno effect
Yuan Cao, Yu-Huai Li, Zhu Cao, Juan Yin, Yu-Ao Chen, Hua-Lei Yin, Teng-Yun Chen, Xiongfeng Ma, Cheng-Zhi Peng, and Jian-Wei Pan. Direct counterfactual communication via quantum zeno effect. Proc. Natl. Acad. Sci. U.S.A. , 114(19):4920–4924, 2017
2017
-
[25]
Two-way communication with a single quantum particle
Flavio Del Santo and Borivoje Daki´ c. Two-way communication with a single quantum particle. Phys. Rev. Lett., 120:060503, Feb 2018. 8
2018
-
[26]
Experimental two-way communication with one photon
Francesco Massa, Amir Moqanaki, Baumeler ´’Amin, Flavio Del Santo, Kettlewell Joshua A., Borivoje Daki´ c, and Philip Walther. Experimental two-way communication with one photon. arXiv:1802.05102v3, 2018
2018 arXiv
-
[27]
High-performance semiconductor quantum-dot single-photon sources
Pascale Senellart, Glenn Solomon, and Andrew White. High-performance semiconductor quantum-dot single-photon sources. Nat. Nanotechnol., 12(11):1026, 2017
2017
-
[28]
Dauler, Matthew E
Eric A. Dauler, Matthew E. Grein, Andrew J. Kerman, Francesco Marsili, Shigehito Miki, Sae Woo Nam, Matthew D. Shaw, Hirotaka Terai, Varun B. Verma, and Taro Yamashita. Review of superconducting nanowire single-photon detector system design options and demon- strated performan...
2014
-
[29]
Taehyun Kim, Marco Fiorentino, and Franco N. C. Wong. Phase-stable source of polarization- entangled photons using a polarization sagnac interferometer. Phys. Rev. A , 73(1):012316, 2006
2006
-
[30]
Optical coherence and quantum optics
Leonard Mandel and Emil Wolf. Optical coherence and quantum optics. Cambridge university press, 1995
1995
-
[31]
Eisaman, Jingyun Fan, Alan Migdall, and Sergey V
Matthew D. Eisaman, Jingyun Fan, Alan Migdall, and Sergey V. Polyakov. Invited review article: Single-photon sources and detectors. Rev. Sci. Instrum. , 82(7):071101, 2011
2011
-
[32]
Quantum cryptography with finite resources: Uncondi- tional security bound for discrete-variable protocols with one-way postprocessing
Valerio Scarani and Renato Renner. Quantum cryptography with finite resources: Uncondi- tional security bound for discrete-variable protocols with one-way postprocessing. Phys. Rev. Lett., 100(20):200501, 2008
2008
-
[33]
horizontal
Walter O. Krawec. Quantum key distribution with mismatched measurements over arbitrary channels. Quantum Information and Computation , 17(3 and 4):209–241, 2017. APPENDIX A The experimental set-up After setting its polarization to “horizontal”(H), that is parallel to the optic...
2017
-
[34]
1” was announced without any clicks at Alice’s and Bob’s detectors), we can use the remaining rounds (when “0
In the RR case, the server is supposed to always announce “0”. The cases where this does not happen lead to errors in the key. The error rate can then be estimated by Alice and Bob and used to obtain the secure key rate. E Security Analysis - Experimental Implementation E.1 Ex...
Reviewed August 14, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.