REVIEW 2 major objections 4 minor 31 references
Bounding light source side channels in QKD via Hong-Ou-Mandel interference
T0 review · 2 major / 4 minor · reviewed 2026-08-14 · deepseek-v4-flash
Pith's one-line read The paper shows that a single Hong-Ou-Mandel visibility measurement can upper-bound passive side-channel leakage from a QKD source and be folded into a BB84 decoy-state key-rate proof.
desk verdict Useful quantitative bridge from HOM visibility to QKD source side-channel bounds, but the 'total passive leakage' claim overstates what a single-bandwidth interference measurement can certify. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The central object is fourth-order Hong-Ou-Mandel interference, in which two pulses meeting on a 50:50 beamsplitter suppress coincidence clicks when they are indistinguishable; for phase-randomized weak coherent pulses the maximum visibility is 0.5. The paper's key identity is the exponential relation between this visibility and the fidelity of two pulses, $\sqrt{F}=\exp(\mu(\sqrt{2V}-1))$, and its key tool is the Bures-angle triangle inequality, which turns pairwise fidelities into an upper bound on the BB84 basis imbalance $\Delta$. That imbalance is then fed into the decoy-state error-rate formula, so a single measured visibility becomes a security parameter.
What would settle it
Build a source whose HOM visibility is near 0.5 but whose emitted state in some out-of-band degree of freedom, such as mid-infrared light or acoustic emission, is perfectly correlated with the encoded bit, and show that the actual secure key rate falls below the paper's lower bound computed from that visibility.
Extended reading notes
Core claim
The central claim is that the visibility of HOM interference between two of Alice's pulses measures the total mode mismatch in all non-operational degrees of freedom, and that this measured visibility can be used to upper-bound the information Eve gains from passive side channels. For phase-randomized weak coherent pulses with equal mean photon number $\mu$, the paper derives $\sqrt{F(\hat{\rho}_1,\hat{\rho}_2)}=\exp(\mu(\sqrt{2V}-1))$, where $V$ is the HOM visibility. Using the Bures angle as a metric, it bounds the BB84 basis imbalance $\Delta$ in terms of pairwise fidelities, then converts that bound into a corrected single-photon error rate and a lower bound on the secret key rate. With the best published PRWCP visibilities, all tested values still yield positive key rates, with visibilities near 0.499 nearly saturating the theoretical limit.
Load-bearing premise
The entire certificate rests on the assumption that every degree of freedom Eve can exploit changes the photonic mode overlap seen by the HOM detector, while the paper itself notes that out-of-wavelength and non-electromagnetic side channels are invisible to this method.
Editorial extensions
If this is right
- A direct HOM measurement of a QKD source yields an upper bound on basis distinguishability, so the same optical setup can serve as a certification tool for existing systems without measuring every pulse parameter independently.
- The derived relation between visibility and fidelity means that improving mode matching, for example by optical seeding, translates quantitatively into a higher secure key rate for decoy-state BB84.
- The paper's simulations show that key generation remains possible for HOM visibilities as low as 0.47, placing current experimental values in a regime where the certification method is practically useful.
- The method is not limited to BB84: the visibility-to-fidelity relation and the bounding technique can, according to the paper, be adapted to other QKD protocols.
- Because the bound tightens as visibility approaches 0.5, the method sets a concrete design target for modulator-free multi-laser sources used in polarization-encoded QKD.
Reading between the lines
- If the visibility-to-fidelity relation is independent of the encoding basis, the same HOM setup could certify side-channel leakage in other prepare-and-measure protocols, including measurement-device-independent QKD, without new security-model work.
- The paper derives the fidelity formula for equal-intensity pulses; a natural extension would be to test whether signal-versus-decoy distinguishability, which the paper leaves for future work, can be bounded by the same kind of interference measurement.
- Because the certificate only sees degrees of freedom that affect optical detection, a complete practical certification would need to pair this test with a separate threat analysis for out-of-band and non-photonic channels.
- The discussion of post-selection suggests a testable distinction: if emission-time jitter is genuinely quantum, removing poorly overlapping events tightens the bound, but if the jitter is classically driven, that post-selection would hide information Eve could use.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The manuscript proposes a method to estimate passive side-channel information leakage in QKD sources by measuring Hong-Ou-Mandel (HOM) visibility between phase-randomized weak coherent pulses (PRWCPs). In Sec. 1 it connects HOM visibility of PRWCPs to the overlap of the single-photon components (Eq. (5)), with an applicability limit around μ ≲ 0.025 or, with correction, up to about 1 photon per pulse. In Sec. 2 it converts this visibility into a fidelity between the X and Z bases using a Bures-angle triangle inequality (Eqs. (10), (31)), yielding an upper bound on the basis imbalance Δ. In Sec. 3 the imbalance is inserted into the decoy-state BB84 key-rate formula and key rates are simulated for several visibility values. Sec. 4 compares with published HOM visibilities from MDI-QKD experiments and discusses limitations, including detector wavelength sensitivity and non-electromagnetic side channels.
Significance. The core idea is appealing: instead of characterizing every non-operational degree of freedom individually, one HOM visibility measurement could certify the overall mode overlap of the emitted signals. The derivation in Appendix A connecting fidelity to visibility (Eq. (22)) is analytically clean, and the Bures-angle construction in Appendix B is a sound way to turn pairwise fidelities into a bound on basis imbalance. The paper also produces concrete, falsifiable predictions: for realistic parameters, key rate degrades sharply below V = 0.5, and positive key rate survives down to about V = 0.47. This is useful for practical source certification. However, the significance is conditional: the method only witnesses side channels that actually reach and are detected in the HOM setup, and it does not yet cover distinguishability between signal and decoy intensity classes. These limitations directly affect the scope of the security claim.
major comments (2)
- [Abstract; Sec. 4, 'Applications and discussion'] The abstract and introduction claim that the method estimates the 'total passive side-channel information leakage' from Alice's source and upper-bounds the influence of all side-channel effects. This is not supported by the paper's own limitation statement in Sec. 4: the method is limited by the single-photon detector wavelength sensitivity, and side channels outside that band or non-electromagnetic channels (such as the acoustic Pockels-cell leakage of Refs. [30,31]) are not detected. Such a side channel would not reduce the measured HOM visibility, so the key-rate bound in Sec. 3 would not upper-bound Eve's information. The claims should be restated to apply to optical side channels within the characterized spectral band, or supplemented with additional characterization that covers the remaining degrees of freedom.
- [Sec. 3, 'Key generation rate'; Appendix A, Eq. (22)] The security model is for the decoy-state BB84 protocol, but the derivation of the visibility-fidelity relation assumes two PRWCPs with equal mean photon number μ. The paper does not measure or bound distinguishability between signal and decoy intensity classes, or between different intensity settings; the sentence 'we assume that decoy-state method doesn't have any additional vulnerabilities' explicitly sets this aside, and the conclusion lists 'estimation of distinguishability between signal and decoy states' as future work. If Eve can exploit intensity-dependent mode mismatch, the decoy-state parameter estimation in Eq. (13) is compromised. The paper should either include a treatment of intensity correlations or restrict its security claim to basis/bit distinguishability at a fixed intensity.
minor comments (4)
- [Eqs. (2)-(4)] The notation 'e−µ2' is ambiguous; in Eq. (2) it should be e^{-μ}, and in Eqs. (3)-(4) it should be e^{-2μ}. In addition, the μ-term in Eq. (3) connecting |01⟩ and |10⟩ is not present in a phase-randomized mixture and should be removed or justified, even though it does not affect the two-photon coincidence analysis.
- [Sec. 4, Table 1] The literature visibilities in Table 1 are HOM visibilities measured in MDI-QKD experiments, where the interference is between Alice's and Bob's pulses at a central node. If these values are used to argue that the method would yield positive key rates for current sources, it should be stated explicitly whether the cited visibilities characterize Alice's source alone or the combined source/measurement setup; in the latter case, they are not directly a bound on Alice-side mode mismatch.
- [Sec. 4, post-selection paragraph] The discussion of post-selection in [29] is a useful caveat, but it could be made more precise: for a security proof, post-selection must be shown to be compatible with the adversarial model, i.e., Eve cannot influence which events are discarded.
- [Fig. 4] The key-rate axis in Fig. 4 appears garbled in the manuscript (the log-scale tick labels read '10 10 -5 -4 -3 10-2'); please check the plot formatting.
Circularity Check
No circularity: HOM visibility is an experimentally measured input, and the key-rate bound is a forward calculation from it; the stated detector-bandwidth limitation is a scope caveat, not a circular step.
full rationale
The derivation chain is a forward calculation: measured HOM visibility V enters Eq. (5) to fix the single-photon mode overlap, Appendix A converts that overlap into a fidelity estimate via Eq. (22), Appendix B bounds the bases imbalance via triangle inequalities, and Sec. 3 inserts the imbalance into a standard decoy-state key-rate formula. No parameter is fitted to a target key rate, no prediction is defined in terms of the quantity it is supposed to predict, and no load-bearing claim is supported by a self-citation by the authors. The relation sqrt(F) = exp(mu(sqrt(2V)-1)) is derived from an explicit mode-overlap parameterization, not assumed as the answer. The paper's own Sec. 4 limitation—that side channels outside the detector's wavelength sensitivity or non-electromagnetic channels are not detected—is an honest scope restriction on the adversarial model, but it does not make the derivation circular: the bound is conditional on the measured visibility. The abstract's 'total leakage' wording is stronger than the Sec. 4 caveat, which is a correctness/scope concern rather than a circularity concern. Accordingly, the circularity score is 0.
Assumptions & free parameters
assumptions (5)
- domain assumption Two PRWCPs with equal intensity mu and mode overlap gamma have HOM visibility V = gamma/2 (for small mu).
- domain assumption The HOM visibility measurement is performed on all degrees of freedom that can leak information to Eve.
- standard math Bures angle is a metric on density matrices, enabling the triangle inequality in Eq. (10).
- domain assumption The security model of Lucamarini et al. [3] for Trojan-horse attacks applies to passive side channels.
- domain assumption The decoy-state method has no additional vulnerabilities beyond those modeled.
Cite this review
Pith. "Pith review of Bounding light source side channels in QKD via Hong-Ou-Mandel interference." pith.science (2026). https://pith.science/paper/GDOF3FWB
@misc{pith2026190804703,
author = {Pith},
title = {Pith review of: Bounding light source side channels in QKD via Hong-Ou-Mandel interference},
year = {2026},
howpublished = {\url{https://pith.science/paper/GDOF3FWB}},
note = {Machine review of arXiv:1908.04703}
}
read the original abstract
Side-channel attacks on practical quantum key distribution systems compromise its security. Although some of these attacks can be taken into account, the general recipe of how to eliminate all side-channel flaws is still missing. In this work, we propose a method for estimation of the total passive side-channel information leakage from the Alice's light source. The method relies on Hong-Ou-Mandel interference between different signals emitted by Alice, which reveals their overall mode mismatch without the necessity to measure all individual degrees of freedom independently. We include experimental values of interference visibility in the security proof for the decoy-state BB84 protocol, and lower-bound the secure key rate for realistic light sources. The obtained results provide a tool that can be used for certification of the current QKD systems and pave the way towards the loophole-free design of the future ones.
Figures
Figures from the paper (2 more)
Reference graph
Works this paper leans on
-
[15]
ZL Yuan, M Lucamarini, JF Dynes, B Fr¨ ohlich, MB Ward, and AJ Shields. Interference of short optical pulses from independent gain-switched laser diodes for quantum secure communications. Physical Review Applied , 2(6):064006, 2014
work page 2014
-
[1]
Information leakage via side channels in freespace bb84 quantum cryptography
Sebastian Nauerth, Martin F¨ urst, Tobias Schmitt-Manderbach, Henning Weier, and Harald Wein- furter. Information leakage via side channels in freespace bb84 quantum cryptography. New Journal of Physics , 11(6):065001, 2009
work page 2009
-
[2]
M Koashi. Simple security proof of quantum key distribution based on complementarity.New Journal of Physics , 11(4):045018, 2009
work page 2009
-
[3]
Practical security bounds against the trojan-horse attack in quantum key distribution
Marco Lucamarini, Iris Choi, Martin B Ward, James F Dynes, ZL Yuan, and Andrew J Shields. Practical security bounds against the trojan-horse attack in quantum key distribution. Physical Review X, 5(3):031030, 2015
work page 2015
-
[4]
Decoy-state quantum key distribution with a leaky source
Kiyoshi Tamaki, Marcos Curty, and Marco Lucamarini. Decoy-state quantum key distribution with a leaky source. New Journal of Physics , 18(6):065008, 2016
work page 2016
-
[5]
Practical free-space quantum key distribution over 10 km in daylight and at night
Richard J Hughes, Jane E Nordholt, Derek Derkacs, and Charles G Peterson. Practical free-space quantum key distribution over 10 km in daylight and at night. New journal of physics , 4(1):43, 2002
work page 2002
-
[6]
Ex- perimental demonstration of free-space decoy-state quantum key distribution over 144 km
Tobias Schmitt-Manderbach, Henning Weier, Martin F¨ urst, Rupert Ursin, Felix Tiefenbacher, Thomas Scheidl, Josep Perdigues, Zoran Sodnik, Christian Kurtsiefer, John G Rarity, et al. Ex- perimental demonstration of free-space decoy-state quantum key distribution over 144 km. Physical Review Letters, 98(1):010504, 2007
work page 2007
-
[7]
High- speed free-space quantum key distribution system for urban daylight applications
MJ Garc´ ıa-Mart´ ınez, Natalia Denisenko, D Soto, D Arroyo, AB Orue, and V Fernandez. High- speed free-space quantum key distribution system for urban daylight applications. Applied optics , 52(14):3311–3317, 2013
work page 2013
Show all 31 references
-
[8]
Free-space quantum key distribution by rotation-invariant twisted photons
Giuseppe Vallone, Vincenzo D’Ambrosio, Anna Sponselli, Sergei Slussarenko, Lorenzo Marrucci, Fabio Sciarrino, and Paolo Villoresi. Free-space quantum key distribution by rotation-invariant twisted photons. Physical review letters , 113(6):060503, 2014
2014
-
[9]
Experimental long-distance decoy-state quantum key distribution based on polarization encoding
Cheng-Zhi Peng, Jun Zhang, Dong Yang, Wei-Bo Gao, Huai-Xin Ma, Hao Yin, He-Ping Zeng, Tao Yang, Xiang-Bin Wang, and Jian-Wei Pan. Experimental long-distance decoy-state quantum key distribution based on polarization encoding. Physical review letters , 98(1):010505, 2007
2007
-
[10]
Experimental quantum digital signature over 102 km
Hua-Lei Yin, Yao Fu, Hui Liu, Qi-Jie Tang, Jian Wang, Li-Xing You, Wei-Jun Zhang, Si-Jing Chen, Zhen Wang, Qiang Zhang, et al. Experimental quantum digital signature over 102 km. Physical Review A, 95(3):032334, 2017
2017
-
[11]
Nature of wavelength chirping in directly modulated semicon- ductor lasers
Thomas L Koch and John E Bowers. Nature of wavelength chirping in directly modulated semicon- ductor lasers. Electronics Letters, 20(25):1038–1040, 1984
1984
-
[12]
Quantum mechanics and path integrals [by] RP Feynman [and] AR Hibbs
Richard Phillips Feynman and Albert R Hibbs. Quantum mechanics and path integrals [by] RP Feynman [and] AR Hibbs . McGraw-Hill, 1965
1965
-
[13]
Measurement of subpicosecond time intervals between two photons by interference
Chong-Ki Hong, Zhe-Yu Ou, and Leonard Mandel. Measurement of subpicosecond time intervals between two photons by interference. Physical review letters , 59(18):2044, 1987. 11
1987
-
[14]
On the purity and indistinguishability of down- converted photons
CI Osorio, N Sangouard, and Robert Thomas Thew. On the purity and indistinguishability of down- converted photons. Journal of Physics B: Atomic, Molecular and Optical Physics , 46(5):055501, 2013
2013
-
[16]
Characteri- zation of phase-averaged coherent states
Alessia Allevi, Maria Bondani, Paulina Marian, Tudor A Marian, and Stefano Olivares. Characteri- zation of phase-averaged coherent states. JOSA B , 30(10):2621–2627, 2013
2013
-
[17]
Secure quantum key distribution with an uncharacterized source
Masato Koashi and John Preskill. Secure quantum key distribution with an uncharacterized source. Physical review letters , 90(5):057902, 2003
2003
-
[18]
transition probability
Armin Uhlmann. The “transition probability” in the state space of a*-algebra. Reports on Mathe- matical Physics, 9(2):273–279, 1976
1976
-
[19]
Fidelity for mixed quantum states
Richard Jozsa. Fidelity for mixed quantum states. Journal of modern optics , 41(12):2315–2323, 1994
1994
-
[20]
Fidelity induced distance measures for quantum states
Zhihao Ma, Fu-Lin Zhang, and Jing-Ling Chen. Fidelity induced distance measures for quantum states. Physics Letters A , 373(38):3407–3409, 2009
2009
-
[21]
Practical decoy state for quantum key distri- bution
Xiongfeng Ma, Bing Qi, Yi Zhao, and Hoi-Kwong Lo. Practical decoy state for quantum key distri- bution. Physical Review A , 72(1):012326, 2005
2005
-
[22]
Security of quantum key distribution with arbitrary individual imperfections
Øystein Marøy, Lars Lydersen, and Johannes Skaar. Security of quantum key distribution with arbitrary individual imperfections. Physical Review A , 82(3):032337, 2010
2010
-
[23]
Secure detection in quantum key distribution by real-time calibration of receiver
Øystein Marøy, Vadim Makarov, and Johannes Skaar. Secure detection in quantum key distribution by real-time calibration of receiver. Quantum Science and Technology , 2(4):044013, 2017
2017
-
[24]
Quantum key distribution with distin- guishable decoy states
Anqi Huang, Shi-Hai Sun, Zhihong Liu, and Vadim Makarov. Quantum key distribution with distin- guishable decoy states. Physical Review A , 98(1):012330, 2018
2018
-
[25]
Proof-of-principle demonstration of measurement-device-independent quantum key distribution using polarization qubits
T Ferreira Da Silva, D Vitoreti, GB Xavier, GC Do Amaral, GP Temporao, and JP Von Der Weid. Proof-of-principle demonstration of measurement-device-independent quantum key distribution using polarization qubits. Physical Review A , 88(5):052303, 2013
2013
-
[26]
Real- world two-photon interference and proof-of-principle quantum key distribution immune to detector attacks
Allison Rubenok, Joshua A Slater, Philip Chan, Itzel Lucio-Martinez, and Wolfgang Tittel. Real- world two-photon interference and proof-of-principle quantum key distribution immune to detector attacks. Physical review letters , 111(13):130501, 2013
2013
-
[27]
Experimental demon- stration of polarization encoding measurement-device-independent quantum key distribution
Zhiyuan Tang, Zhongfa Liao, Feihu Xu, Bing Qi, Li Qian, and Hoi-Kwong Lo. Experimental demon- stration of polarization encoding measurement-device-independent quantum key distribution. Phys- ical review letters , 112(19):190503, 2014
2014
-
[28]
Quantum key distribution without detector vulnerabilities using optically seeded lasers
LC Comandar, M Lucamarini, B Fr¨ ohlich, JF Dynes, AW Sharpe, SW-B Tam, ZL Yuan, RV Penty, and AJ Shields. Quantum key distribution without detector vulnerabilities using optically seeded lasers. Nature Photonics, 10(5):312, 2016
2016
-
[29]
Near perfect mode overlap between independently seeded, gain-switched lasers
LC Comandar, M Lucamarini, B Fr¨ ohlich, JF Dynes, ZL Yuan, and AJ Shields. Near perfect mode overlap between independently seeded, gain-switched lasers. Optics express , 24(16):17849–17859, 2016
2016
-
[30]
Experimental quantum cryptography
Charles H Bennett, Fran¸ cois Bessette, Gilles Brassard, Louis Salvail, and John Smolin. Experimental quantum cryptography. Journal of cryptology , 5(1):3–28, 1992. 12
1992
-
[31]
Brief history of quantum cryptography: A personal perspective
Gilles Brassard. Brief history of quantum cryptography: A personal perspective. In IEEE Information Theory Workshop on Theory and Practice in Information-Theoretic Security, 2005. , pages 19–23. IEEE, 2005. 13
2005
Reviewed August 14, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.