REVIEW 2 major objections 4 minor 60 references
Computing secure key rates for quantum key distribution with untrusted devices
T0 review · 2 major / 4 minor · reviewed 2026-08-14 · deepseek-v4-flash
Pith's one-line read A semidefinite-programming framework computes lower bounds on device-independent QKD key rates from full measurement statistics, without restricting to CHSH.
desk verdict A genuinely new SDP framework for DI von Neumann entropy bounds; central proof sits in the missing supplement, so the claim is credible but unverifiable without it. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing mechanism is the entropy-production bound behind Theorem 1: for a channel $T$, the inequality $H(T[\rho])-H(\rho) \ge \langle L\rangle_\rho - \ln\langle K\rangle_\rho$ holds for any decomposition $L=\sum_k \tilde L_k$, with $K = T^*T\big[\int_{\mathbb{R}} dt\,\beta(t) \big|\prod_k e^{\frac{1+it}{2}\tilde L_k}\big|^2\big]$ and $\beta(t)=(\pi/2)(\cosh(\pi t)+1)^{-1}$. The paper's key step is to choose $\tilde L_{xy} = \sum_{abj}\lambda_j c^{(j)}_{abxy} P_{a|x}\otimes P_{b|y}$ for each pair $(x,y)$, so that the product over $k$ becomes a product over measurement pairs of exponentials of local Bell operators; the resulting $K$ is a non-commutative polynomial in the projectors. That polynomial form is what makes the NPA hierarchy applicable, since the hierarchy relaxes polynomial optimization over projectors to a converging sequence of semidefinite programs. The same identity also explains why the method extends from $H(A_0|E)$ to $H(A_0B_0|E)$: only the pinching channel and the environmental register change, not the underlying operator bound.
What would settle it
Take a specific finite-dimensional state and projective measurements that satisfy the constraints in a simple two-input, two-output scenario, compute $H(A_0|E)$ exactly by diagonalizing the conditional states, and compare it with the Theorem 1 lower bound evaluated through the NPA hierarchy at high level. Finding any state for which the claimed lower bound exceeds the exact $H(A_0|E)$ would falsify the central claim; the same test could be applied to the Supplement's derivation by checking whether the operator inequality holds term by term.
Extended reading notes
Core claim
On its own terms, the central result is Theorem 1: for a device-independent scenario, the minimum of $H(A_0|E)$ subject to constraints $\langle L_j\rangle_{\rho_{AB}} = l_j$, with $L_j = \sum_{abxy} c^{(j)}_{abxy} P_{a|x}\otimes P_{b|y}$, is lower-bounded by $\sup_{\vec\lambda}\big[\sum_j \lambda_j l_j - \ln\big(\sup_{\rho_{AB},P} \langle K\rangle_{\rho_{AB}}\big)\big]$, where $K$ is the operator displayed in Eq. (4), built from a product of exponentials of the local Bell operators and averaged over a pinching channel $T$. The discovery is that this bound is computable exactly when it is needed most: although $\langle K\rangle$ is not directly accessible, $K$ is a non-commutative polynomial in the projectors, so its expectation can be bounded from above by the NPA hierarchy. The optimization over $\vec\lambda$ is a supremum, so any choice of $\vec\lambda$ gives a valid secure lower bound without solving that outer problem exactly. This converts the non-convex, dimension-unbounded problem of bounding $H(A_0|E)$ into a standard SDP feasibility check, and the same machinery extends to $H(A_0B_0|E)$ and to one-sided device-independent constraints.
Load-bearing premise
The proof that the particular choice of operators $\tilde L_{xy}$ turns the generalized Golden-Thompson inequality into the explicit factored form of $K$ in Eq. (4) is stated in the main text but deferred to the Supplement; if that algebraic reduction fails for some state satisfying the constraints, the claimed lower bound would not follow.
Editorial extensions
If this is right
- Any DIQKD protocol whose statistics are fixed by linear constraints $\langle L_j\rangle = l_j$ can in principle have its asymptotic key rate lower-bounded, so protocol design is no longer restricted to CHSH or to binary-input/binary-output Bell inequalities.
- Because every choice of $\vec\lambda$ yields a valid bound, practitioners can obtain secure certificates without solving the outer supremum.
- The same machinery bounds the joint entropy $H(A_0B_0|E)$, improving key rates for device-independent randomness expansion and slightly improving the DIQKD rates in the entropy-accumulation proof.
- Combined with the entropy accumulation theorem, the bounds cover finite-size and non-IID effects, so the toolbox yields finite key lengths against general attacks.
- In the limited-detection-efficiency scenario the full-distribution bound beats the CHSH-only bound, indicating that maximizing the CHSH value is not always the right experimental target.
Reading between the lines
- Beyond the paper, the entropy-production inequality is stated for a general channel $T$, so the same operator bound could be adapted to protocols whose post-processing is not a single projective measurement, such as coherent or continuous-variable schemes with suitable polynomial constraints.
- Beyond the paper, the fact that any feasible $\vec\lambda$ gives a bound suggests using the right-hand side of Theorem 1 directly as an objective when searching over possible protocols; one could numerically optimize measurement settings against the computed key rate rather than against a Bell parameter.
- Beyond the paper, the equality of the one-sided six-state and BB84 rates is one data point; testing the same method across larger sets of uncharacterized measurements would show whether extra measurement settings are generally redundant for one-sided device-independent key rates.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The manuscript introduces a semi-definite programming framework for lower-bounding the asymptotic secret key rate of QKD protocols with untrusted devices. The central theoretical result, Theorem 1, states that the minimum of H(A0|E) subject to linear constraints <Lj>=lj is lower-bounded by an expression of the form sup_lambda [ sum_j lambda_j l_j - ln sup <K> ], where K is defined in Eq. (4) through a product of exponentials of measurement-projector polynomials and is then bounded using the NPA hierarchy. The authors apply the method to two-input/two-output DIQKD scenarios under depolarizing noise and limited detection efficiency, to a one-sided device-independent six-state protocol, and to the joint entropy H(A0B0|E) relevant for randomness expansion. They report rates that are close to or better than existing CHSH-based bounds.
Significance. If Theorem 1 is correct, the paper solves an important open problem: it provides a general, SDP-computable way to bound the von Neumann entropy directly in device-independent settings, going beyond CHSH-specific qubit reductions and beyond indirect guessing-probability bounds. The method's dual ansatz is a genuine strength: any choice of Lagrange multipliers lambda gives a valid lower bound, with no curve fitting to the data, and the final computation rests on the standard NPA hierarchy. The numerical demonstrations, especially for two-party entropy H(A0B0|E), indicate that the approach can outperform existing techniques. The main weakness is that the decisive proof step is deferred to the Supplement, which is not part of the reviewed manuscript, leaving the central theorem unverifiable from the submitted text.
major comments (2)
- [Methods, Eqs. (4), (10) and Theorem 1] The load-bearing step from Eq. (10) to Theorem 1 is explicitly deferred: the text states "By setting Ltilde_xy = ... we obtain (see [37]) Theorem 1", and the Supplement is not included in the review package. This step is not a routine substitution, because the operators Ltilde_xy for different (x,y) need not commute: Alice's projectors for different inputs, and Bob's projectors for different inputs, need not commute. Consequently the product over xy in Eq. (4) is not a well-defined operator unless an ordering convention is specified, and the scalar weight beta(t)=(pi/2)(cosh(pi*t)+1)^{-1} appears to correspond to the two-term multivariate Golden-Thompson inequality, whereas a two-input/two-output protocol has four (x,y) terms. If the correct multivariate weight or a nontrivial reduction is missing, Eq. (4) can overestimate <K>, which would invalidate the lower bound in Theorem 1. The proof, or at least the exact statement of the multivariate Golden-Thompson inequality used, must be provided in the manuscript or in a Supplement that is part of the reviewed material.
- [Methods, Eq. (4) and numerical results] The claim that K is a non-commutative polynomial whose integral can be evaluated in closed form and then bounded via the NPA hierarchy is not substantiated in the main text. The explicit polynomial in the measurement projectors, its degree, the operator ordering, and the NPA level used for the computations in Figs. 3-5 are all absent. Without this information the numerical results cannot be reproduced or independently checked, and the practical scope of the method cannot be assessed. This material should appear in the main text or in a Supplement that is part of the review package.
minor comments (4)
- [Introduction, first paragraph] The phrase "the the Navascués-Pironio-Acín hierarchy" contains a duplicated article and should be corrected.
- [Methods, entropy production derivation] The text "By Stinepring's theorem" is a typo for "Stinespring's theorem".
- [Data Availability] For a computational methods paper, "available from the corresponding authors upon reasonable request" is insufficient for reproducibility; please provide the code and data in a public repository.
- [Figs. 3-5] The captions do not state the NPA hierarchy level, solver tolerances, or the exact form of the polynomial K used; adding these details would significantly improve reproducibility.
Circularity Check
No circularity found: the central bound is a dual optimization over Lagrange multipliers, benchmarked against independent external results, and the deferred Golden-Thompson reduction is a missing-proof issue, not a circular fit.
full rationale
The derivation chain is free of circularity. Theorem 1 is a dual-style lower bound: for any Lagrange multipliers lambda, the expression sum_j lambda_j l_j - ln sup_{rho,P} <K> is claimed to be a valid lower bound on H(A0|E) under the constraints <L_j> = l_j. The multipliers are optimized, not fitted to the target value, and the optimization is a supremum, so any feasible lambda already gives a secure bound. The non-commutative polynomial K is constructed via the generalized Golden-Thompson inequality from the independent external reference [57], and the NPA hierarchy [38] provides an outer approximation, which is the correct direction for a lower bound. The numerical scenarios are defined by explicit states and measurements and are compared against external benchmarks [1,42]; no parameter is fitted to the H(A0|E) values being predicted. The central reduction from Eq. (10) to Theorem 1 is deferred to the authors' supplement with the sentence 'By setting L~_xy = ... we obtain (see [37]) Theorem 1', but this is an omitted-proof or verifiability concern about non-commuting operator orderings, not a circular equivalence of inputs and outputs. No load-bearing premise depends on a self-citation by the present authors; the cited prior works by the authors are contextual and the external uniqueness-type results come from other groups. Accordingly, no circular step is identified and the circularity score is 0.
Assumptions & free parameters
assumptions (5)
- domain assumption Devetak-Winter formula: asymptotic key rate r∞ = max{ H(A0|E) - H(A0|B0), 0 } for one-way error correction under IID attacks.
- standard math Generalized Golden-Thompson inequality (Sutter, Berta, Tomamichel, Ref. [57]) holds for the decomposition L = Σ_k L̃_k used here.
- standard math NPA hierarchy provides certified upper bounds on expectation values ⟨K⟩ over all finite-dimensional quantum states consistent with the algebraic constraints.
- standard math The key-measurement channel T is the pinching channel, which is self-adjoint and idempotent for projective measurements, so T*T = T in the DI scenario.
- domain assumption The proof considers finite-dimensional systems, with the stated bounds independent of dimension.
Cite this review
Pith. "Pith review of Computing secure key rates for quantum key distribution with untrusted devices." pith.science (2026). https://pith.science/paper/O73OU6ZT
@misc{pith2026190811372,
author = {Pith},
title = {Pith review of: Computing secure key rates for quantum key distribution with untrusted devices},
year = {2026},
howpublished = {\url{https://pith.science/paper/O73OU6ZT}},
note = {Machine review of arXiv:1908.11372}
}
read the original abstract
Device-independent quantum key distribution (DIQKD) provides the strongest form of secure key exchange, using only the input-output statistics of the devices to achieve information-theoretic security. Although the basic security principles of DIQKD are now well-understood, it remains a technical challenge to derive reliable and robust security bounds for advanced DIQKD protocols that go beyond the previous results based on violations of the CHSH inequality. In this work, we present a framework based on semi-definite programming that gives reliable lower bounds on the asymptotic secret key rate of any QKD protocol using untrusted devices. In particular, our method can in principle be utilized to find achievable secret key rates for any DIQKD protocol, based on the full input-output probability distribution or any choice of Bell inequality. Our method also extends to other DI cryptographic tasks.
Figures
Figures from the paper (4 more)
Reference graph
Works this paper leans on
-
[37]
J. D. Bekenstein, Phys. Rev. D7, 2333 (1973)
1973
-
[1]
S. Pironio, A. Acin, N. Brunner, N. Gisin, S. Massar, and V. Scarani, New J. Phys.11, 045021 (2009). 6 For the DI scenario, the channelT is self-adjoint and idempotent, so T∗T = T
work page 2009
-
[2]
on the Werner 3 For QKD purposes, Bob will need to perform a third measurement for key generation, corresponding toB0 in Eq. (1), but we do not use this when boundingH(A0|E) state (1− 2q)|Φ+⟩⟨Φ+| + (q/2)I, where |Φ+⟩ is the Bell state (|00⟩ +|11⟩)/ √ 2 and Z and X are Pauli operators. The second scenario is a limited-detection-efficiency model parametrized ...
work page 2019
-
[3]
Vazirani and T
U. Vazirani and T. Vidick, Phys. Rev. Lett.113, 140501 (2014)
2014
-
[4]
Arnon-Friedman, F
R. Arnon-Friedman, F. Dupuis, O. Fawzi, R. Renner, and T. Vidick, Nat. Commun.9, 459 (2018)
2018
-
[5]
J. S. Bell, Physics1, 195 (1964)
1964
-
[6]
Brunner, D
N. Brunner, D. Cavalcanti, S. Pironio, V. Scarani, and S. Wehner, Rev. Mod. Phys.86, 419 (2014)
2014
-
[7]
Horodecki, P
R. Horodecki, P. Horodecki, M. Horodecki, and K. Horodecki, Rev. Mod. Phys.81, 865 (2009)
2009
Show all 60 references
-
[8]
Curty, M
M. Curty, M. Lewenstein, and N. Lütkenhaus, Phys. Rev. Lett. 92, 217903 (2004)
2004
-
[9]
Acin and N
A. Acin and N. Gisin, Phys. Rev. Lett.94, 020501 (2005)
2005
-
[10]
Barrett, A
J. Barrett, A. Kent, and S. Pironio, Phys. Rev. Lett.97, 170409 (2006)
2006
-
[11]
P. J. Coles, E. M. Metodiev, and N. Lütkenhaus, Nat. Commun. 7, 11712 (2016)
2016
-
[12]
Winick, N
A. Winick, N. Lütkenhaus, and P. J. Coles, Quantum2, 77 (2018)
2018
-
[13]
J. Lin, T. Upadhyaya, and N. Lütkenhaus, arXiv preprint arXiv:1905.10896v1 (2019)
2019 arXiv
-
[14]
Y. Wang, I. W. Primaatmaja, E. Lavie, A. Varvitsiotis, and C. C. W. Lim, npj Quantum Information5, 17 (2019)
2019
-
[15]
I. W. Primaatmaja, E. Lavie, K. T. Goh, C. Wang, and C. C. W. Lim, Phys. Rev. A99, 062332 (2019)
2019
-
[16]
Masanes, S
L. Masanes, S. Pironio, and A. Acín, Nature communica- tions 2, 238 (2011)
2011
-
[17]
Bancal, L
J.-D. Bancal, L. Sheridan, and V. Scarani, New J. Phys. 16, 033011 (2014)
2014
-
[18]
Nieto-Silleras, S
O. Nieto-Silleras, S. Pironio, and J. Silman, New J. Phys. 16, 013035 (2014)
2014
-
[19]
Advances in quantum cryptography,
S. Pirandola, U. L. Andersen, L. Banchi, M. Berta, D. Bunandar, R. Colbeck, D. Englund, T. Gehring, C. Lupo, C. Ottaviani, J. Pereira, M. Razavi, J. S. Shaari, M. Tomamichel, V. C. Usenko, G. Vallone, P. Villoresi, and P. Wallden, “Advances in quantum cryptography,” (2019), ar...
2019 arXiv
-
[20]
Branciard, E
C. Branciard, E. G. Cavalcanti, S. P. Walborn, V. Scarani, and H. M. Wiseman, Phys. Rev. A85, 010301 (2012)
2012
-
[21]
Tomamichel, S
M. Tomamichel, S. Fehr, J. Kaniewski, and S. Wehner, New J. Phys.15, 103002 (2013)
2013
-
[22]
Acín and L
A. Acín and L. Masanes, Nature540, 213 (2016)
2016
-
[23]
Pironio, A
S. Pironio, A. Acín, S. Massar, A. B. de La Giroday, D. N. Matsukevich, P. Maunz, S. Olmschenk, D. Hayes, L. Luo, T. A. Manning,et al., Nature 464, 1021 (2010)
2010
-
[24]
Colbeck, Quantum And Relativistic Protocols For Se- cure Multi-Party Computation, Ph.D
R. Colbeck, Quantum And Relativistic Protocols For Se- cure Multi-Party Computation, Ph.D. thesis, University of Cambridge (2006)
2006
-
[25]
Liu, M.-H
W.-Z. Liu, M.-H. Li, S. Ragy, S.-R. Zhao, B. Bai, Y. Liu, P. J. Brown, J. Zhang, R. Colbeck, J. Fan, Q. Zhang, and J.-W. Pan, arXiv preprint arXiv:1912.11159 (2019)
2019 arXiv
-
[26]
L. K. Shalm, Y. Zhang, J. C. Bienfang, C. Schlager, M. J. Stevens, M. D. Mazurek, C. Abellán, W. Amaya, M. W. Mitchell, M. A. Alhejji, H. Fu, J. Ornstein, R. P. Mirin, S. W. Nam, and E. Knill, arXiv preprint arXiv:1912.11158 (2019)
2019 arXiv
-
[27]
Vértesi, S
T. Vértesi, S. Pironio, and N. Brunner, Physical Review Letters 104, 060401 (2010)
2010
-
[28]
Froissart, Il Nuovo Cimento B (1971-1996) 64, 241 (1981)
M. Froissart, Il Nuovo Cimento B (1971-1996) 64, 241 (1981)
1981
-
[29]
Śliwa, Physics Letters A317, 165 (2003)
C. Śliwa, Physics Letters A317, 165 (2003)
2003
-
[30]
Collins and N
D. Collins and N. Gisin, Journal of Physics A: Mathemati- cal and General37, 1775 (2004)
2004
-
[31]
Gisin, in Quantum Reality, relativistic causality, and closing the epistemic circle(Springer, 2009) pp
N. Gisin, in Quantum Reality, relativistic causality, and closing the epistemic circle(Springer, 2009) pp. 125–138
2009
-
[32]
Ribeiro, G
J. Ribeiro, G. Murta, and S. Wehner, Physical Review A 97, 022307 (2018). 7
2018
-
[33]
Reeb and M
D. Reeb and M. M. Wolf, New Journal of Physics 16, 103011 (2014)
2014
-
[34]
Jarzynski, Annu
C. Jarzynski, Annu. Rev. Condens. Matter Phys. 2, 329 (2011)
2011
-
[35]
Weimer, M
H. Weimer, M. J. Henrich, F. Rempp, H. Schröder, and G. Mahler, Europhys. Lett.83, 30008 (2008)
2008
-
[36]
Clausius,The Mechanical Theory of Heat – with its Ap- plications to the Steam Engine and to Physical Properties of Bodies(London: John van der Voorst, 1867)
R. Clausius,The Mechanical Theory of Heat – with its Ap- plications to the Steam Engine and to Physical Properties of Bodies(London: John van der Voorst, 1867)
-
[38]
See Supplementary Information
-
[39]
Navascués, S
M. Navascués, S. Pironio, and A. Acín, New J. Phys.10, 073013 (2008)
2008
-
[40]
P. W. Shor and J. Preskill, Phys. Rev. Lett.85, 441 (2000)
2000
-
[41]
C. H. Bennett, G. Brassard, and N. D. Mermin, Phys. Rev. Lett. 68, 557 (1992)
1992
-
[42]
Devetak and A
I. Devetak and A. Winter, P. Roy. Soc. A: Math Phy.461, 207 (2005)
2005
-
[43]
P. H. Eberhard, Phys. Rev. A47, R747 (1993)
1993
- [44]
-
[45]
P. J. Brown, S. Ragy, and R. Colbeck, arXiv preprint arXiv:1810.13346 (2018)
2018 arXiv
-
[46]
A. Acín, S. Massar, and S. Pironio, Phys. Rev. Lett.108, 100402 (2012)
2012
-
[47]
Briët and P
J. Briët and P. Harremoës, Phys. Rev. A79, 052311 (2009)
2009
-
[48]
Hensen, H
B. Hensen, H. Bernien, A. E. Dréau, A. Reiserer, N. Kalb, M. S. Blok, J. Ruitenberg, R. F. L. Vermeulen, R. N. Schouten, C. Abellán, W. Amaya, V. Pruneri, M. W. Mitchell, M. Markham, D. J. Twitchen, D. Elkouss, S. Wehner, T. H. Taminiau, and R. Hanson, Nature526, 682 (2015)
2015
-
[49]
Giustina, M
M. Giustina, M. A. M. Versteegh, S. Wengerowsky, J. Handsteiner, A. Hochrainer, K. Phelan, F. Steinlechner, J. Kofler, J.-A. Larsson, C. Abellán, W. Amaya, V. Pruneri, M. W. Mitchell, J. Beyer, T. Gerrits, A. E. Lita, L. K. Shalm, S. W. Nam, T. Scheidl, R. Ursin, B. Wittmann, a...
2015
-
[50]
L. K. Shalm, E. Meyer-Scott, B. G. Christensen, P. Bier- horst, M. A. Wayne, M. J. Stevens, T. Gerrits, S. Glancy, D. R. Hamel, M. S. Allman, K. J. Coakley, S. D. Dyer, C. Hodge, A. E. Lita, V. B. Verma, C. Lambrocco, E. Tor- torici, A. L. Migdall, Y. Zhang, D. R. Kumor, W. H....
2015
-
[51]
Rosenfeld, D
W. Rosenfeld, D. Burchardt, R. Garthoff, K. Redeker, N. Ortegel, M. Rau, and H. Weinfurter, Phys. Rev. Lett. 119, 010402 (2017)
2017
-
[52]
Murta, S
G. Murta, S. B. van Dam, J. Ribeiro, R. Hanson, and S. Wehner, Quantum Science and Technology 4, 035011 (2019)
2019
-
[53]
Bruß, Phys
D. Bruß, Phys. Rev. Lett.81, 3018 (1998)
1998
-
[54]
K. T. Goh, J.-D. Bancal, and V. Scarani, New J. Phys.18, 045022 (2016)
2016
-
[55]
Tavakoli, D
A. Tavakoli, D. Rosset, and M.-O. Renou, Phys. Rev. Lett. 122, 070501 (2019)
2019
-
[56]
W. F. Stinespring, P. Am. Math. Soc.6, 211 (1955)
1955
-
[57]
P. J. Coles, Phys. Rev. A85, 042103 (2012)
2012
-
[58]
Sutter, M
D. Sutter, M. Berta, and M. Tomamichel, Commun. Math. Phys. 352, 37 (2017)
2017
-
[59]
Löfberg, in Proceedings of the CACSD Conference (Taipei, Taiwan, 2004)
J. Löfberg, in Proceedings of the CACSD Conference (Taipei, Taiwan, 2004)
2004
-
[60]
Version 8.1.(2019)
MOSEK ApS,The MOSEK optimization toolbox for MAT- LAB manual. Version 8.1.(2019)
2019
Reviewed August 14, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.