Pith. sign in

REVIEW 3 major objections 7 minor 48 references

Open-destination measurement-device-independent quantum key distribution network

T0 review · 3 major / 7 minor · reviewed 2026-08-27 · deepseek-v4-flash

Pith's one-line read This paper claims that a quantum key distribution network built from one multipartite entangled source and one untrusted relay per user lets any two users distill a secure key, with the same security as measurement-device-independent QKD.

desk verdict A genuinely useful open-destination MDI-QKD network idea with a clean honest-run derivation, but the security claim for dishonest auxiliary users is asserted, not proved. read the letter →

arxiv 2009.13439 v2 pith:O6GHNEWA submitted 2020-09-28 quant-ph

classification quant-ph PACS 03.67.Dd03.67.Hk
keywords quantumkeydistributionmeasurement-device-independentQKDnetworkGHZstateopen-destinationteleportationuntrustedrelaydetectorside-channelattackconferenceagreement
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper proposes a quantum key distribution network in which any two users can generate a secure key with the help of the other users, while all measurement devices and relays may be untrusted. The scheme combines an $N$-partite GHZ state with Bell state measurements at each user's relay; after all measurements and public announcements, an arbitrary pair of users is left with correlated bits that can be distilled into a key. The central claim is that this 'open-destination' network reduces to standard measurement-device-independent QKD from the perspective of the two communicating users, so it inherits the same security against detector side channels and untrusted relays. The paper demonstrates the reduction in detail for a four-user network and reports simulated key rates under realistic source and detector imperfections. If correct, the scheme would allow a star network with one multipartite source and $N$ untrusted relays to serve any pair of users without reconfiguring the source.

What carries the argument

The load-bearing object is the post-selection identity that rewrites the GHZ state as a superposition over auxiliary $X$-basis outcomes: $|GHZ\rangle_N \propto \sum_\chi (|00\rangle_{12}+(-1)^{\sigma_\chi}|11\rangle_{12})|\chi\rangle_{3\dots N}$. Once auxiliary users announce their $X$-basis states and relays announce successful Bell state measurement (BSM) results, the remaining two photons are projected onto a known Bell state $\frac{1}{\sqrt{2}}(|00\rangle+(-1)^\tau|11\rangle)$, with $\tau$ determined by the announced outcomes. This maps the network to an equivalent MDI-QKD setup with a virtual Bell source and an effective BSM, which is what carries the security reduction and the bit-flip sifting rule.

What would settle it

Search for a deviation by one auxiliary user: suppose that auxiliary user prepares a state $\frac{1}{\sqrt{2}}(|+\rangle+e^{i\theta}|-\rangle)$ but announces $|+\rangle$, while all relays report successful BSMs. Compute whether the two communication users' phase-error estimate $e_{XX}$ can be made lower than the true value, or whether an eavesdropper's information exceeds the privacy-amplification bound. A concrete numerical search over such one-sided deviations, using the announced sifting rule, would settle whether the equivalence is security-preserving rather than merely correct on honest runs.

Watch

Extended reading notes

Core claim

The paper's central discovery is that an $N$-partite GHZ state, together with announced $X$-basis states from auxiliary users and successful Bell state measurements at every relay, acts as a resource that can project any chosen pair of communication users into a shared entangled state, effectively a virtual Bell state. Tracing out auxiliary users and relays converts the whole outside of the two users into a single untrusted measurement relay, so the protocol is reduced to standard measurement-device-independent QKD and has the same security. Because the identity of the two communicating users need not be fixed before the measurements, the network has an 'open destination': any pair can extract key from the same experimental run. The scheme also generalizes to $C$ simultaneous communication users, supporting conference key agreement and related multiparty tasks.

Load-bearing premise

The load-bearing premise is that the GHZ source, every relay's Bell state measurement, and every auxiliary user's preparation device can be lumped together as a single untrusted relay in the MDI-QKD security proof, which in particular requires that auxiliary users actually prepare the X-basis states they announce.

Editorial extensions

If this is right

  • Any two users in the $N$-user star can establish a key from the same round of measurements, without knowing in advance which users will communicate.
  • Security holds even if all relays, the GHZ source, and all other users' preparation devices are untrusted; only the two communicating users need trusted state-preparation devices.
  • The scheme needs only $N$ untrusted relays, one per user, rather than $N(N-1)/2$ relays for pairwise MDI-QKD, at the cost of a multipartite GHZ source.
  • The same post-selection extends to $C$ communication users, enabling conference key agreement or secret sharing with only $4N$ detectors instead of $(2N-2)N$.
  • In simulation with a perfect GHZ source and single-photon sources, the four-user example tolerates more than 500 km of optical fiber, about 100 dB of loss, under the stated detector parameters.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • The paper supplies an honest-run equivalence to MDI-QKD, but a rigorous treatment of dishonest auxiliary users who deviate from their announced $X$-basis preparations would require a full security proof rather than just the reduction, because the post-selection assumes the announced state matches the actual state.
  • If auxiliary users are allowed to be malicious rather than merely untrusted-but-honest, the scheme may need a modified sifting rule or an additional verification step; testing this is a natural next step.
  • A practical scheduling advantage follows implicitly: the open-destination feature could let a single network run serve dynamically changing pairs of users, avoiding reconfiguration or time-division waiting.
  • The equivalent-detector parameters derived for the auxiliary BSM setups could guide relay placement and basis-bias optimization in asymmetric-loss networks, though the paper does not develop that optimization.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Request a human review

A listed scientist reviews the paper for a fee and the review publishes here regardless of verdict. See the reviewers or get listed.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 7 minor

Summary. The paper proposes an 'open-destination' measurement-device-independent quantum key distribution (MDI-QKD) network protocol. In the (N,2) scheme, N users are connected to a central GHZ source through N untrusted relays; two designated communication users prepare BB84 states, all relays perform Bell-state measurements, and the remaining auxiliary users prepare and announce X-basis states. The authors claim that, conditioned on all relays reporting successful BSM outcomes and all auxiliary users announcing X-basis states, the protocol reduces exactly to standard bipartite MDI-QKD, so arbitrary pairs of users can establish secret keys without trusting relays, the GHZ source, or the auxiliary users' preparation devices. The honest-run correctness is derived in Eqs. (2)-(6) and Appendix A, a GLLP-type key rate is given, and a four-user example with Werner-state source noise and experimental detector parameters is simulated. The paper also sketches a generalization to (N,C) conference key agreement.

Significance. If the security claim is rigorously established, the protocol would be a useful network architecture: it permits MDI-QKD between arbitrary pairs using only N untrusted relays, and it may reduce the number of detectors compared with running pairwise MDI-QKD. The honest-run derivation in Eqs. (4)-(6) and Appendix A is explicit and the simulation is transparent, using parameters from the literature. However, the central claim that the protocol has 'the same security' as standard MDI-QKD is currently supported only by a calculation for honest auxiliary users; no full adversary argument is supplied. The protocol idea is plausible, but the manuscript as written does not yet provide a complete security proof for the claimed setting.

major comments (3)
  1. [Section II.B, Eq. (6), Appendix A, Tables II-IV] The claimed security equivalence to standard MDI-QKD is not established. The derivation of the post-selected measurement M_{χ',υ}_{1'2'} assumes that each auxiliary user actually prepares the announced X-basis state |χ'_k> and that each relay performs the ideal Bell projection on that state. This is an honest-run calculation. A dishonest auxiliary user can prepare, for example, |0> while announcing '+', in which case the POVM on the corresponding GHZ mode is a Z-basis projector rather than the X-basis projector in Table II; Eq. (6) then no longer holds and the flip rule in Table IV is not justified. To support the statement that the GHZ source, all relays, and all auxiliary users can be treated as a single untrusted relay with the same security as MDI-QKD, the authors need either a formal reduction showing that arbitrary state preparations and announcements by auxiliary users are absorbed into the untrusted relay's arbitrary POVM within the standard MDI-QKD security model, including the exact sifting and flip procedure, or a self-contained security proof. Without this, the central claim that communication users 'need not trust these preparation devices of other users' is an assertion rather than a proved result.
  2. [Section IV, Eq. (11)] The (N,C) generalization to conference key agreement is asserted rather than proved. The paper shows that, for honest auxiliary users, the post-selected state is a C-qubit GHZ state, and then quotes the key-rate formula of Eq. (11) from multi-party entanglement-purification references [34,39,40,44-46]. It does not provide a security proof for the multiparty protocol under adversarial relays, auxiliary users, and GHZ source, nor does it show that the assumptions of the cited purification-based arguments are satisfied by the open-destination post-selection. Since the abstract claims that 'any users can accomplish key distribution under assistance of others,' the (N,C) case is part of the paper's central claim and needs either a proof or an explicit statement that it is a heuristic extension.
  3. [Section II.D and Section IV] The claim that all 2-party users 'generate their own secure keys independently and simultaneously' and that the scheme 'generates secure keys for any two-party users in one round' is not supported by the protocol as written. In the (N,2) protocol, an auxiliary user must prepare an X-basis state and announce it; that announced value is public, so it cannot simultaneously serve as a secret key bit, and a user who prepares a Z-basis state for their own key cannot serve as an auxiliary for another pair in the same round. A single round can therefore post-select at most one communication pair, namely the pair whose two members used key-basis states while all other users used and announced X-basis states. If 'open destination' means only that the communication pair can be chosen after the states are distributed but before the bases are announced, the text should say so explicitly and should not claim simultaneous key generation for all N(N-1)/2 pairs; if simultaneous multi-pair key generation is truly intended, a modified protocol with a corresponding security analysis is required.
minor comments (7)
  1. [Abstract] The word 'multi-partities' should be 'multipartite'.
  2. [Section II.A] The reference to 'Einsetin, Podolski and Rosen' contains typos; it should be 'Einstein, Podolsky, and Rosen.'
  3. [Section II.B] The notation σ_{χ'⊕υ~} is used without explicitly defining the XOR operation on strings of '+/-' symbols; please define '+' as 0 and '-' as 1 before Eq. (3).
  4. [Section III and Appendix C] The simulation assumes asymptotic single-photon sources and idealized decoy-state estimation, but this is stated only in Section III and Appendix C; the main text should carry this caveat near Eq. (7) and Figure 2 so that the reader is not misled about finite-size effects.
  5. [Appendix C, Eq. (C3)] The notation Q^{ZZ}_{μν} is confusing because μ and ν are not defined in Appendix C; since the single-photon-source limit gives Q^{ZZ}_{μν}=Q^{ZZ}_{11}=Y_{11}, the text should clarify that this is an asymptotic limit.
  6. [Section IV] The acronym 'MDI-QCC' is not defined; please spell it out at first use.
  7. [Section V] The word 'untrustful' should be 'untrusted'.

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity: correctness and key-rate derivations are self-contained; the security-reduction gap is a missing proof, not a circular equivalence.

full rationale

The central derivation is not circular. Correctness is established by the explicit algebra in Eqs. (2)-(6) and Appendix A: the post-selected operation on the communication users is computed from the GHZ state, the auxiliary X-basis preparations, and the BSM outcomes, and Eq. (6) follows from evaluating the overlaps in Eq. (5) rather than being imposed as the desired answer. The key rate formula (7) and the simulation in Appendix C use the standard GLLP method and published experimental parameters [35]; the source fidelity p is a chosen scenario parameter, not a fitted value later relabeled as a prediction. The security claim is a reduction to independently established MDI-QKD results [17,18,29], and such an external reduction is legitimate support if the equivalence holds. Even where self-citations appear ([29,34,40,47]), they refer to externally published, independently checkable results rather than to a loop in the present derivation. The paper's actual weakness is a missing proof, not circularity: Appendix A and Section II.B show the honest-run equivalence, but the statement that communication users 'need not trust these preparation devices of other users' would require a security analysis for dishonest auxiliary users who announce X basis while preparing other states; no such analysis is supplied. That omission is a correctness and security gap, and it does not make the derivation equivalent to its inputs, so it does not raise the circularity score.

Assumptions & free parameters 1 free parameters · 5 assumptions · 0 invented entities

The central claim rests on the security of standard MDI-QKD as an external building block, on the equivalence of the open-destination network to a single-relay MDI-QKD setup, and on trusted state preparation for the communication users. The simulation additionally assumes single-photon sources, an asymptotic limit, and a Werner-like noise model.

free parameters (1)
  • source fidelity p (Werner parameter) = 0.85, 0.9, 0.95, 1 (scenario sweep)
    Chosen by hand to model depolarizing noise on the GHZ source (Eq. 8). It directly controls the simulated key rate and is not fitted to data.
assumptions (5)
  • domain assumption Security of standard MDI-QKD is inherited when all parts outside the two communication users are treated as a single untrusted relay.
    Section II.B states the scheme 'is reduced to the MDI-QKD and the two has the same security', relying on Refs [17,18,29]. This is the load-bearing security step.
  • domain assumption The post-selected state on the communication users' photons is fully described by the public announcements (Eqs. (4)-(6)).
    The correctness and equivalence analysis assumes auxiliary users' X-basis states are as announced; malicious deviations are not analyzed.
  • domain assumption Communication users have trusted state-preparation devices.
    The paper states 'all users need only trusted state-preparation devices at hand'. This is standard for MDI-QKD but is an explicit security assumption.
  • domain assumption Simulation assumes single-photon sources and the asymptotic limit.
    Section III says 'the single-photon source and the asymptotic approximations are assumed', and decoy-state analysis is left to future work.
  • domain assumption The source noise is modeled as a Werner-like state p|GHZ><GHZ| + (1-p)I/16.
    This noise model (Eq. 8, Eq. C2) is chosen for the simulation, not derived from a physical source model.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Open-destination measurement-device-independent quantum key distribution network." pith.science (2026). https://pith.science/paper/O6GHNEWA

@misc{pith2026200913439,
  author       = {Pith},
  title        = {Pith review of: Open-destination measurement-device-independent quantum key distribution network},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/O6GHNEWA}},
  note         = {Machine review of arXiv:2009.13439}
}
read the original abstract

Quantum key distribution (QKD) networks hold promise for sharing secure randomness over multi-partities. Most existing QKD network schemes and demonstrations are based on trusted relays or limited to point-to-point scenario. Here, we propose a flexible and extensible scheme named as open-destination measurement-device-independent QKD network. The scheme enjoys security against untrusted relays and all detector side-channel attacks. Particularly, any users can accomplish key distribution under assistance of others in the network. As an illustration, we show in detail a four-user network where two users establish secure communication and present realistic simulations by taking into account imperfections of both sources and detectors.

Figures

Figures reproduced from arXiv: 2009.13439 by the authors.

Figure 1
Figure 1. FIG. 1: An optical diagram for the polarization-encoding [PITH_FULL_IMAGE:figures/full_fig_p003_1.png] view at source ↗
Figure 2
Figure 2. FIG. 2: Lower bound on the secret key rate [PITH_FULL_IMAGE:figures/full_fig_p005_2.png] view at source ↗
Figure 3
Figure 3. FIG. 3: ( [PITH_FULL_IMAGE:figures/full_fig_p008_3.png] view at source ↗
Figures from the paper (2 more)
Figure 4
Figure 4. Figure 4: FIG. 4: The BSM setup with polarization encoding. BS denotes beam splitter, PBS denotes polarization beam splitter, and [PITH_FULL_IMAGE:figures/full_fig_p009_4.png]
Figure 5
Figure 5. Figure 5: FIG. 5: Equivalent setup for Alice and Bob when tracing the BSM results of the auxiliary users. PBS denotes polarization beam splitter, PM [PITH_FULL_IMAGE:figures/full_fig_p011_5.png]

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

48 extracted references · 48 canonical work pages

  1. [39]

    Conference key agreement and quantum sharing of classical secrets with noisy GHZ states

    Chen, K.; Lo, H.K. Conference key agreement and quantum sharing of classical secrets with noisy GHZ states. In Proceedings of the International Symposium on Information Theory (ISIT 2005), Adelaide, SA, Australia, 4–9 September 2005; pp. 1607–1611. [CrossRef]

  2. [1]

    Quantum cryptography: Public key distribution and coin tossing

    Bennett, C.H.; Brassard, G. Quantum cryptography: Public key distribution and coin tossing. In Proceedings of IEEE International Conference on Computer System and Signal Processing ; IEEE: New York, NY , USA, 1984; p. 175

  3. [2]

    Quantum cryptography based on Bell’s theorem

    Ekert, A.K. Quantum cryptography based on Bell’s theorem. Phys. Rev. Lett. 1991, 67, 661–663. [CrossRef] [PubMed]

  4. [3]

    Quantum cryptography

    Gisin, N.; Ribordy, G.; Tittel, W.; Zbinden, H. Quantum cryptography. Rev. Mod. Phys. 2002, 74, 145–195. [CrossRef]

  5. [4]

    The security of practical quantum key distribution

    Scarani, V .; Bechmann-Pasquinucci, H.; Cerf, N.J.; Dušek, M.; Lütkenhaus, N.; Peev, M. The security of practical quantum key distribution. Rev. Mod. Phys. 2009, 81, 1301–1350. [CrossRef]

  6. [5]

    The DARPA quantum network

    Elliott, C. The DARPA quantum network. In Quantum Communications and Cryptography ; CRC Press: Boca Raton, FL, USA, 2005; pp. 83–102

  7. [6]

    The SECOQC quantum key distribution network in Vienna

    Peev, M.; Pacher, C.; Alléaume, R.; Barreiro, C.; Bouda, J.; Boxleitner, W.; Debuisschert, T.; Diamanti, E.; Dianati, M.; Dynes, J.; et al. The SECOQC quantum key distribution network in Vienna. New J. Phys. 2009, 11, 075001. [CrossRef]

  8. [7]

    Metropolitan all-pass and inter-city quantum communication network

    Chen, T.Y .; Wang, J.; Liang, H.; Liu, W.Y .; Liu, Y .; Jiang, X.; Wang, Y .; Wan, X.; Cai, W.Q.; Ju, L.; et al. Metropolitan all-pass and inter-city quantum communication network. Opt. Express 2010, 18, 27217–27225. [CrossRef]

Show all 48 references
  1. [8]

    Field test of quantum key distribution in the Tokyo QKD Network

    Sasaki, M.; Fujiwara, M.; Ishizuka, H.; Klaus, W.; Wakui, K.; Takeoka, M.; Miki, S.; Yamashita, T.; Wang, Z.; Tanaka, A.; et al. Field test of quantum key distribution in the Tokyo QKD Network. Opt. Express 2011, 19, 10387–10409. [CrossRef]

  2. [9]

    A quantum access network

    Fröhlich, B.; Dynes, J.F.; Lucamarini, M.; Sharpe, A.W.; Yuan, Z.; Shields, A.J. A quantum access network. Nature 2013, 501, 69. [CrossRef]

  3. [10]

    Quantum communications leap out of the lab

    Qiu, J. Quantum communications leap out of the lab. Nature (London) 2014, 508, 441. [CrossRef]

  4. [11]

    Satellite-Relayed Intercontinental Quantum Network

    Liao, S.K.; Cai, W.Q.; Handsteiner, J.; Liu, B.; Yin, J.; Zhang, L.; Rauch, D.; Fink, M.; Ren, J.G.; Liu, W.Y .; et al. Satellite-Relayed Intercontinental Quantum Network. Phys. Rev. Lett. 2018, 120, 030501. [CrossRef]

  5. [12]

    Time-shift Attack in Practical Quantum Cryptosystems

    Qi, B.; Fung, C.H.F.; Lo, H.K.; Ma, X. Time-shift Attack in Practical Quantum Cryptosystems. Quantum Inf. Comput. 2007, 7, 073

  6. [13]

    QZ, EX, EZ 12, and EZ 13 can be gotten directly from the experimental results

    is the marginal quantum bit error rate between user 1 and user 2 (3) in Z basis, EX is the overall quantum bit error rate in X basis, f is the error correction efficiency, and H(x) =−xlog2(x)− (1− x)log2(1− x) is the binary Shannon entropy function. QZ, EX, EZ 12, and EZ 13 can...

  7. [14]

    Quantum hacking: Experimental demonstration of time-shift attack against practical quantum-key-distribution systems

    Zhao, Y .; Fung, C.H.F.; Qi, B.; Chen, C.; Lo, H.K. Quantum hacking: Experimental demonstration of time-shift attack against practical quantum-key-distribution systems. Phys. Rev. A 2008, 78, 042333. [CrossRef]

  8. [15]

    Hacking commercial quantum cryptography systems by tailored bright illumination

    Lydersen, L.; Wiechers, C.; Wittmann, C.; Elser, D.; Skaar, J.; Makarov, V . Hacking commercial quantum cryptography systems by tailored bright illumination. Nat. Photonics 2010, 4, 686–689. [CrossRef]

  9. [16]

    Full-field implementation of a perfect eavesdropper on a quantum cryptography system

    Gerhardt, I.; Liu, Q.; Lamas-Linares, A.; Skaar, J.; Kurtsiefer, C.; Makarov, V . Full-field implementation of a perfect eavesdropper on a quantum cryptography system. Nat. Commun. 2011, 2, 349. [CrossRef] [PubMed]

  10. [17]

    Quantum eavesdropping without interception: An attack exploiting the dead time of single-photon detectors

    Weier, H.; Krauss, H.; Rau, M.; FÃijrst, M.; Nauerth, S.; Weinfurter, H. Quantum eavesdropping without interception: An attack exploiting the dead time of single-photon detectors. New J. Phys. 2011, 13, 073024. [CrossRef]

  11. [18]

    Measurement-Device-Independent Quantum Key Distribution.Phys

    Lo, H.K.; Curty, M.; Qi, B. Measurement-Device-Independent Quantum Key Distribution.Phys. Rev. Lett. 2012, 108, 130503. [CrossRef]

  12. [19]

    Side-Channel-Free Quantum Key Distribution

    Braunstein, S.L.; Pirandola, S. Side-Channel-Free Quantum Key Distribution. Phys. Rev. Lett. 2012, 108, 130502. [CrossRef]

  13. [20]

    Discrete and continuous variables for measurement-device-independent quantum cryptog- raphy

    Xu, F.; Curty, M.; Qi, B.; Qian, L.; Lo, H.K. Discrete and continuous variables for measurement-device-independent quantum cryptog- raphy. Nat. Photonics 2015, 9, 772. [CrossRef]

  14. [21]

    Reply to Discrete and continuous variables for measurement-device-independent quantum cryptography

    Pirandola, S.; Ottaviani, C.; Spedalieri, G.; Weedbrook, C.; Braunstein, S.L.; Lloyd, S.; Gehring, T.; Jacobsen, C.S.; Andersen, U.L. Reply to Discrete and continuous variables for measurement-device-independent quantum cryptography. Nat. Photonics 2015, 9, 773. [CrossRef]

  15. [22]

    Experimental measurement-device-independent quantum key distribution with imperfect sources

    Tang, Z.; Wei, K.; Bedroya, O.; Qian, L.; Lo, H.K. Experimental measurement-device-independent quantum key distribution with imperfect sources. Phys. Rev. A 2016, 93, 042308. [CrossRef]

  16. [23]

    Multi-partite entanglement can speed up quantum key distribution in networks

    Epping, M.; Kampermann, H.; Macchiavello, C.; Bruß, D. Multi-partite entanglement can speed up quantum key distribution in networks. New J. Phys. 2017, 19, 093012. [CrossRef]

  17. [24]

    Experimental demonstration of five-photon entanglement and open-destination teleportation

    Zhao, Z.; Chen, Y .A.; Zhang, A.N.; Yang, T.; Briegel, H.J.; Pan, J.W. Experimental demonstration of five-photon entanglement and open-destination teleportation. Nature 2004, 430, 54–58. [CrossRef] [PubMed]

  18. [25]

    Multiparticle generalization of entanglement swapping.Phys

    Bose, S.; Vedral, V .; Knight, P.L. Multiparticle generalization of entanglement swapping.Phys. Rev. A 1998, 57, 822–829. [CrossRef]

  19. [26]

    Can Quantum-Mechanical Description of Physical Reality Be Considered Complete? Phys

    Einstein, A.; Podolsky, B.; Rosen, N. Can Quantum-Mechanical Description of Physical Reality Be Considered Complete? Phys. Rev. 1935, 47, 777. [CrossRef]

  20. [27]

    Quantum Key Distribution with High Loss: Toward Global Secure Communication

    Hwang, W.Y . Quantum Key Distribution with High Loss: Toward Global Secure Communication. Phys. Rev. Lett. 2003, 91, 057901. [CrossRef]

  21. [28]

    Decoy State Quantum Key Distribution

    Lo, H.K.; Ma, X.; Chen, K. Decoy State Quantum Key Distribution. Phys. Rev. Lett. 2005, 94, 230504. [CrossRef]

  22. [29]

    Beating the Photon-Number-Splitting Attack in Practical Quantum Cryptography

    Wang, X.B. Beating the Photon-Number-Splitting Attack in Practical Quantum Cryptography. Phys. Rev. Lett. 2005, 94, 230503. [CrossRef] 13

  23. [30]

    Long distance measurement-device-independent quantum key distribution with entangled photon sources

    Xu, F.; Qi, B.; Liao, Z.; Lo, H.K. Long distance measurement-device-independent quantum key distribution with entangled photon sources. Appl. Phys. Lett. 2013, 103, 061101. [CrossRef]

  24. [31]

    Monogamy of quantum entanglement and other correlations

    Koashi, M.; Winter, A. Monogamy of quantum entanglement and other correlations. Phys. Rev. A 2004, 69, 022309. [CrossRef]

  25. [32]

    General Monogamy Inequality for Bipartite Qubit Entanglement

    Osborne, T.J.; Verstraete, F. General Monogamy Inequality for Bipartite Qubit Entanglement. Phys. Rev. Lett. 2006, 96, 220503. [CrossRef]

  26. [33]

    Proper monogamy inequality for arbitrary pure quantum states

    Ou, Y .C.; Fan, H.; Fei, S.M. Proper monogamy inequality for arbitrary pure quantum states. Phys. Rev. A 2008, 78, 012311. [CrossRef]

  27. [34]

    Security of quantum key distribution with imperfect devices.Quantum Inf

    Gottesman, D.; Lo, H.K.; Lütkenhaus, N.; Preskill, J. Security of quantum key distribution with imperfect devices.Quantum Inf. Comput. 2004, 4, 325

  28. [35]

    Multi-partite quantum cryptographic protocols with noisy GHZ states

    Chen, K.; Lo, H.K. Multi-partite quantum cryptographic protocols with noisy GHZ states. Quantum Inf. Comput. 2007, 7, 689

  29. [36]

    Measurement-Device- Independent Quantum Key Distribution over 200 km

    Tang, Y .L.; Yin, H.L.; Chen, S.J.; Liu, Y .; Zhang, W.J.; Jiang, X.; Zhang, L.; Wang, J.; You, L.X.; Guan, J.Y .; et al. Measurement-Device- Independent Quantum Key Distribution over 200 km. Phys. Rev. Lett. 2014, 113, 190501. [CrossRef] [PubMed]

  30. [37]

    Finite-key analysis for measurement-device- independent quantum key distribution

    Curty, M.; Xu, F.; Cui, W.; Lim, C.C.W.; Tamaki, K.; Lo, H.K. Finite-key analysis for measurement-device- independent quantum key distribution. Nat. Commun. 2014, 5, 3732. [CrossRef]

  31. [38]

    Protocol choice and parameter optimization in decoy-state measurement-device- independent quantum key distribution

    Xu, F.; Xu, H.; Lo, H.K. Protocol choice and parameter optimization in decoy-state measurement-device- independent quantum key distribution. Phys. Rev. A 2014, 89, 052333. [CrossRef]

  32. [40]

    Long-Distance Measurement-Device-Independent Multiparty Quantum Communication.Phys

    Fu, Y .; Yin, H.L.; Chen, T.Y .; Chen, Z.B. Long-Distance Measurement-Device-Independent Multiparty Quantum Communication.Phys. Rev. Lett. 2015, 114, 090501. [CrossRef]

  33. [41]

    Phase-Matching Quantum Cryptographic Conferencing

    Zhao, S.; Zeng, P.; Cao, W.F.; Xu, X.Y .; Zhen, Y .Z.; Ma, X.; Li, L.; Liu, N.L.; Chen, K. Phase-Matching Quantum Cryptographic Conferencing. Phys. Rev. Appl. 2020, 14, 024010. [CrossRef]

  34. [42]

    Quantum secret sharing

    Hillery, M.; Bužek, V .; Berthiaume, A. Quantum secret sharing. Phys. Rev. A 1999, 59, 1829–1834. [CrossRef]

  35. [43]

    How to Share a Quantum Secret

    Cleve, R.; Gottesman, D.; Lo, H.K. How to Share a Quantum Secret. Phys. Rev. Lett. 1999, 83, 648–651. [CrossRef]

  36. [44]

    Experimental Quantum Secret Sharing and Third-Man Quantum Cryptography

    Chen, Y .A.; Zhang, A.N.; Zhao, Z.; Zhou, X.Q.; Lu, C.Y .; Peng, C.Z.; Yang, T.; Pan, J.W. Experimental Quantum Secret Sharing and Third-Man Quantum Cryptography. Phys. Rev. Lett. 2005, 95, 200502. [CrossRef]

  37. [45]

    Unconditional security of quantum key distribution over arbitrarily long distances

    Lo, H.K.; Chau, H.F. Unconditional security of quantum key distribution over arbitrarily long distances. Science 1999, 283, 2050–2056. [CrossRef] [PubMed]

  38. [46]

    Simple proof of security of the BB84 quantum key distribution protocol.Phys

    Shor, P.W.; Preskill, J. Simple proof of security of the BB84 quantum key distribution protocol.Phys. Rev. Lett. 2000, 85, 441. [CrossRef] [PubMed]

  39. [47]

    Improved two-party and multi-party purification protocols

    Maneva, E.N.; Smolin, J.A. Improved two-party and multi-party purification protocols. Contemp. Math. 2002, 305, 203–212

  40. [48]

    Asymmetric Protocols for Scalable High-Rate Measurement-Device-Independent Quantum Key Distribution Networks

    Wang, W.; Xu, F.; Lo, H.K. Asymmetric Protocols for Scalable High-Rate Measurement-Device-Independent Quantum Key Distribution Networks. Phys. Rev. X 2019, 9, 041012. [CrossRef]

Pith tools

Reviewed August 27, 2026 · model on record in the stance chip above.