Pith. sign in

REVIEW 1 major objections 4 minor 34 references

Security of practical modulator-free quantum key distribution

T0 review · 1 major / 4 minor · reviewed 2026-08-12 · deepseek-v4-flash

Pith's one-line read Even small residual leakage from the intensity modulator severely degrades the secret-key rate of modulator-free decoy-state BB84; the paper proves security and fixes the required attenuation at roughly 70–90 dB.

desk verdict Useful paper on modulator-free QKD leakage, but the passive-transmitter section has a factor-sqrt(2) error in the fictitious-scenario reduction that needs fixing before its key-rate numbers can be trusted. read the letter →

arxiv 2411.15777 v1 pith:YXPULJ3M submitted 2024-11-24 quant-ph

classification quant-ph PACS 03.67.Dd
keywords quantumkeydistributionmodulator-freetransmitterinformationleakageintensitymodulatorextinctionratiodecoy-stateBB84quantum-coinargumentgeneralattacksasymptoticsecret-keyrate
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

Modulator-free quantum key distribution transmitters avoid active modulators, making them resistant to Trojan-horse attacks, but their residual pulses leak information about Alice's settings through the intensity modulator's finite extinction ratio. This paper proves security against general attacks for decoy-state BB84 with such transmitters, modelling the leakage as weak coherent pulses of intensity $\omega$ and deriving asymptotic secret-key-rate bounds in Eqs. (23) and (43). The numerical evaluation shows the key rate is severely degraded unless the modulator provides roughly 70–90 dB of attenuation, and it collapses below roughly 30 dB. In other words, the one leftover modulator is not a minor detail; it is the gatekeeper of the protocol's security.

What carries the argument

The central objects are the leakage modes tagged by $L$ (the odd time bins 1, 3, and 5 in the passive transmitter; the $P$ and $F$ modes in the injection-locked transmitter), described as coherent states with intensity $\omega = \eta_{\mathrm{IM}} \mu_{\max}$ (passive) or $\omega = \eta_{\mathrm{IM}} \mu_{\mathrm{in}}/2$ (injection-locked). The argument works by replacing the actual leakage state with a fictitious splitting into separate modes that is intended to be more advantageous for Eve, turning inter-round correlations into per-round local states. The mathematical engine is the quantum-coin argument, which converts fidelity bounds between photon-number states of different intensity settings into linear-program constraints on yields and bit-error rates; the final rates are the asymptotic formulas in Eqs. (23) and (43).

What would settle it

Directly compute the state obtained from $|\sqrt{\omega/2}\,e^{i\varphi_0}\rangle_{1'} \otimes |\sqrt{\omega/2}\,e^{i\varphi_1}\rangle_1$ through a 50:50 beamsplitter: the kept port contains $\sqrt{\omega/4}(e^{i\varphi_0}+e^{i\varphi_1})$, not the paper's claimed $\sqrt{\omega/2}(e^{i\varphi_0}+e^{i\varphi_1})$. If this check is confirmed, the key-rate lower bounds in Section II (and hence Fig. 3) need re-derivation before they can be quoted for the real transmitter.

Watch

Extended reading notes

Core claim

The paper's central claim is that the residual pulses emitted in modulator-free transmitters must be treated as a genuine side channel with finite intensity $\omega$, rather than as a negligible imperfection, and that a security proof can still go through by embedding those pulses as additional Fock modes and applying decoy-state and quantum-coin techniques. Concretely, for the fully passive post-selection transmitter and for the optical-injection-locking transmitter, the paper constructs fictitious scenarios in which the leakage modes are split into Eve-friendlier systems, computes post-selected $n$-photon density matrices in the enlarged Hilbert space, and uses linear programs to bound single-photon yields and phase-error rates. The resulting asymptotic key rates, Eqs. (23) and (43), show a sharp transition: an attenuation of about 70 dB recovers near-ideal performance, while an attenuation of 30 dB or less leaves essentially no key.

Load-bearing premise

The load-bearing premise is that a 50:50 beamsplitter can turn the two substituted leakage modes $|\sqrt{\omega/2}\,e^{i\varphi_0}\rangle_{1'} \otimes |\sqrt{\omega/2}\,e^{i\varphi_1}\rangle_1$ back into the original leakage state $|\sqrt{\omega/2}(e^{i\varphi_0}+e^{i\varphi_1})\rangle_1$; if this reconstruction fails, the simplified per-round security bounds are not automatically lower bounds for the actual device.

Editorial extensions

If this is right

  • Key rate approaches the ideal leakage-free value only when the intensity modulator attenuation is about 70 dB or more; below ~30 dB the protocol is practically unusable.
  • The security analysis applies to a broad family of passive post-selection decoy-state transmitters, not only to the specific time-bin BB84 example used for illustration.
  • For the injection-locking transmitter, the leakage state is identical for all signal-intensity $I_0$ rounds, making it less sensitive to leakage than the fully passive transmitter.
  • Because yields now depend on the intensity setting, the standard decoy-state analysis must be replaced by fidelity-based quantum-coin linear programs.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • If the beamsplitter reconstruction step in Section II B is corrected, the 70–90 dB requirement suggests that 'modulator-free' transmitters inherit a tight specification on the one remaining modulator, essentially trading Trojan-horse resistance for a demanded extinction ratio.
  • A finite-key version of the same parameterization would likely require even stronger attenuation, since statistical fluctuations widen the gap between the bound and the ideal rate.
  • The same leakage-modeling could be applied to measurement-device-independent QKD with modulator-free sources, where the leaked modes enter through an untrusted receiver rather than through Bob's basis choice.
  • A direct experimental test would be to measure the key-rate-vs-distance curve of a passive transmitter at 30, 50, and 70 dB IM attenuation and check whether it follows the sharp drop predicted in Fig. 3.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

1 major / 4 minor

Summary. The paper develops a security analysis for decoy-state BB84 QKD with two types of modulator-free transmitters: a fully passive post-selection transmitter and an optical-injection-locking (OIL) transmitter. It models the residual information leakage from the finite extinction ratio of an intensity modulator as a set of leaked coherent modes, then uses the quantum-coin argument together with decoy-state linear programs to derive asymptotic secret-key rate lower bounds. The central quantitative claim is that for both transmitters the key rate is severely degraded unless the leakage is attenuated by roughly 70–90 dB, and that security against general attacks is maintained in the asymptotic limit if this attenuation is included in the proof.

Significance. If the technical issue identified below is corrected, the paper makes a valuable contribution: it provides a general, explicit framework for incorporating residual leakage modes into security proofs for modulator-free sources, with detailed appendices and concrete linear programs for yield and phase-error estimation. The OIL transmitter analysis in Section III appears internally consistent and provides a useful comparison. The qualitative conclusion that finite extinction ratios must be accounted for in security proofs is important for practical implementations of passive and modulator-free QKD transmitters. The paper is careful in stating its modeling assumptions, and the numerical results give falsifiable predictions about the required attenuation levels.

major comments (1)
  1. [II B, Eq. (7)] The fictitious-scenario substitution in Eq. (7) is incorrect. The text claims that a 50:50 beamsplitter acting on the two modes |√(ω/2)e^{iφ0}⟩_{1'} and |√(ω/2)e^{iφ1}⟩_1 reconstructs the original leakage mode |√(ω/2)(e^{iφ0}+e^{iφ1})⟩_1. A 50:50 beamsplitter maps input amplitudes α and β to output amplitudes (α+β)/√2 and (α−β)/√2; with α = β = √(ω/2), the first output amplitude is √(ω/4)(e^{iφ0}+e^{iφ1}), not √(ω/2)(e^{iφ0}+e^{iφ1}). The correct input amplitudes would be √ω e^{iφ0} and √ω e^{iφ1}, which is exactly the substitution used in the analogous OIL analysis in Eq. (35) of Section III. As written, Eqs. (8), (16), and (17) underestimate the intensity of leakage modes 1 and 5 by a factor of two, so the fictitious scenario is not more advantageous for Eve and the lower-bound claim behind Fig. 3 (and the refined analysis in Appendix E) is not established. The passive-transmitter key rates and the quantitative attenuation thresholds must be re-derived with the corrected amplitudes.
minor comments (4)
  1. [V, Conclusions] The Conclusions state that the secret-key rate approaches the ideal leakage-free scenario when the attenuation exceeds ∼70 dB, but Fig. 3 for the passive transmitter shows that alignment with the ideal curve requires Att ≳ 90 dB. Please qualify which transmitter the 70 dB figure refers to, or otherwise reconcile the thresholds.
  2. [II A, step 1(d)] It is unclear whether the odd leakage pulses pass through the low-transmittance beamsplitter with the even signal pulses. The definition of ω in Eq. (6) suggests they do not; please clarify the optical path so that the relation between ω and the physical leakage intensity is unambiguous.
  3. [II D, Eq. (23)] The secret-key rate formula contains the prefactor p_{Z_B} p_{Ω^{I0}_Z}; the ordering of sifting (Bob announces detections and basis) and Alice's post-selection announcement should be stated explicitly so that the definitions of these probabilities are unambiguous.
  4. [Appendix D, Eq. (D4)] The final line of Eq. (D4) sets certain phases ξ to specific values for ω = 0; for the numerical implementation with ω > 0, please state which phase choices are used and whether they are optimized or fixed, since the inner product Re{⟨ψ^{ω,1}_{Z,I0}|ψ^{ω,1}_{X,I0}⟩} depends on them.

Circularity Check

0 steps flagged · score 2.0 of 10

No significant circularity: the key-rate bounds are derived from the stated state model and optimized linear programs, not from the target result; the Section II B beamsplitter substitution discrepancy is a correctness concern, not a circular reduction.

full rationale

The central claims—Eqs. (23) and (43)—are lower bounds assembled from independently stated ingredients: post-selected density matrices (Eqs. (10)-(19)), yields and error rates constrained by decoy-state equations and the quantum-coin argument (Eqs. (25)-(31)), and fidelities computed or bounded from the density matrices (Appendix C). The quantities Y and e are not fitted to the final key rate; they are solutions to linear programs whose constraints come from the channel model and the state characterization, so the rate is not an input to the derivation. The paper does invoke prior work by the same group (e.g., the passive transmitter of [17], the fidelity bounds of [26,32], and the fully passive security framework [14-16]), but these are published, independently checkable results used as tools, not self-justifying uniqueness theorems or ansatze. The most serious issue found is in Section II B: Eq. (7) substitutes two coherent states of amplitude sqrt(omega/2) and claims a 50:50 beamsplitter reconstructs a coherent state of amplitude sqrt(omega/2)(e^{i phi0}+e^{i phi1}); the beamsplitter output would have amplitude sqrt(omega/4)(e^{i phi0}+e^{i phi1}), a factor sqrt(2) smaller. This is a mathematical/correctness flaw in the claimed reduction, not a circularity: the subsequent bounds do not assume the conclusion they are trying to prove. Accordingly the circularity score is low (2), reflecting only the presence of self-citations that are not load-bearing for the main derivation.

Assumptions & free parameters 3 free parameters · 5 assumptions · 0 invented entities

No new physical degrees of freedom are postulated. The fictitious scenario introduces auxiliary optical modes 1' and 5' purely as a proof device.

free parameters (3)
  • μmax (passive transmitter) = optimized per distance in Fig. 3
    Maximum intensity per early/late mode; numerically optimized for each distance; enters the leakage intensity via ω = μmax ηIM and affects post-selection probabilities.
  • ΔθZ (passive transmitter) = optimized per distance in Fig. 3
    Z-basis post-selection threshold; optimized because it trades state fidelity against sifting probability.
  • X-basis decoy intensities (OIL transmitter) = two highest intensities optimized per distance; I2 = 1e-4 fixed
    In Fig. 4, decoy intensities are optimized per distance for the injection-locking transmitter.
assumptions (5)
  • ad hoc to paper The fictitious substitution in Section II B gives Eve at least as much information as the actual round-wise leakage state.
    Used to reduce the analysis to a per-round leakage state (Eq. 8). The amplitude bookkeeping in the beamsplitter argument is inconsistent as written.
  • domain assumption Bob's detection efficiency is basis-independent, so losses can be moved to Eve and ideal detectors assumed after a photon-number check.
    Invoked in Section II D and used to justify the key-rate expression Eq. (23).
  • domain assumption Alice's phases are uniformly random and independent.
    Required for the density-matrix averages in Eqs. (10)-(19) and for the decoy-state model.
  • domain assumption The intensity modulator operates independently of Alice's settings and Eve cannot extract extra information from it.
    Stated in Sections I and II B; otherwise the side channel would be different.
  • domain assumption Post-selection statistics f(θ,φ,μ) are unaffected by the leakage.
    Section II C states this because the CPM measures the classical signal before the IM and the leakage is in other time slots.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Security of practical modulator-free quantum key distribution." pith.science (2026). https://pith.science/paper/YXPULJ3M

@misc{pith2026241115777,
  author       = {Pith},
  title        = {Pith review of: Security of practical modulator-free quantum key distribution},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/YXPULJ3M}},
  note         = {Machine review of arXiv:2411.15777}
}
read the original abstract

Recent advancements in quantum key distribution have led to the development of various modulator-free transmitters. Among their advantages, these transmitters offer enhanced security against Trojan-horse attacks. However, practical implementations emit residual pulses that, while not used in the quantum communication, still carry information about Alice's settings. While the intensity of these pulses can be attenuated with an intensity modulator, the extinction ratio of these devices is always finite, and therefore it remains crucial to account for the residual information leakage at the security-proof level. In this work, we analyze the security of these transmitters and evaluate their performance. We find that the secret-key rate of the protocol is severely affected when the information leakage is not sufficiently attenuated, which highlights the importance of accounting for such type of imperfections.

Figures

Figures reproduced from arXiv: 2411.15777 by the authors.

Figure 1
Figure 1. (a) Schematic representation of the passive transmitter proposed in [17]. The laser diode (LD) emits a train of [PITH_FULL_IMAGE:figures/full_fig_p003_1.png] view at source ↗
Figure 2
Figure 2. Schematic representation of the modulator-free transmitter proposed in [22]. Two lasers are placed in an optical [PITH_FULL_IMAGE:figures/full_fig_p010_2.png] view at source ↗
Figure 3
Figure 3. Asymptotic secret-key rate vs distance for the fully passive transmitter based on post-selection described in Section II [PITH_FULL_IMAGE:figures/full_fig_p013_3.png] view at source ↗
Figures from the paper (2 more)
Figure 4
Figure 4. Figure 4: Asymptotic secret-key rate vs distance for the modulator-free transmitter proposed in [22] as a function of the [PITH_FULL_IMAGE:figures/full_fig_p013_4.png]
Figure 5
Figure 5. Figure 5: Asymptotic secret-key rate vs distance for the fully passive transmitter based on post-selection described in Section II, [PITH_FULL_IMAGE:figures/full_fig_p022_5.png]

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

34 extracted references · 33 canonical work pages

  1. [22]

    Simplified intensity-and phase-modulated transmitter for modulator-free decoy-state quantum key distribution,

    Y. Lo, R. Woodward, N. Walk, M. Lucamarini, I. De Marco, T. Para ¨ ıso, M. Pittaluga, T. Roger, M. Sanzaro, Z. Yuan, et al. , “Simplified intensity-and phase-modulated transmitter for modulator-free decoy-state quantum key distribution,” APL Photonics , vol. 8, no. 3, p. 036111, 2023

  2. [1]

    Secure quantum key distribution,

    H.-K. Lo, M. Curty, and K. Tamaki, “Secure quantum key distribution,” Nature Photonics , vol. 8, no. 8, pp. 595–604, 2014

  3. [2]

    Secure quantum key distribution with realistic devices,

    F. Xu, X. Ma, Q. Zhang, H.-K. Lo, and J.-W. Pan, “Secure quantum key distribution with realistic devices,” Reviews of Modern Physics, vol. 92, no. 2, p. 025002, 2020

  4. [3]

    Advances in quantum cryptography,

    S. Pirandola, U. L. Andersen, L. Banchi, M. Berta, D. Bunandar, R. Colbeck, D. Englund, T. Gehring, C. Lupo, C. Ot- taviani, et al. , “Advances in quantum cryptography,” Advances in Optics and Photonics , vol. 12, no. 4, pp. 1012–1236, 2020

  5. [4]

    Implementation security in quantum key distribution,

    V. Zapatero, ´A. Navarrete, and M. Curty, “Implementation security in quantum key distribution,” Advanced Quantum Technologies, p. 2300380, 2024

  6. [5]

    Implementation attacks against QKD systems,

    C. Marquardt, U. Seyfarth, S. Bettendorf, M. Bohmann, A. Buchner, M. Curty, D. Elser, S. Eul, T. Gehring, N. Jain, T. Klocke, M. Reinecke, N. Sieber, R. Ursin, M. Wehling, and H. Weier, “Implementation attacks against QKD systems,” tech. rep., German Federal Office for Information Security (BSI), 2024. Available at https://www.bsi.bund.de/EN/ Service-Navi...

  7. [6]

    Trojan-horse attacks on quantum-key-distribution systems,

    N. Gisin, S. Fasel, B. Kraus, H. Zbinden, and G. Ribordy, “Trojan-horse attacks on quantum-key-distribution systems,” Physical Review A , vol. 73, p. 022320, 2006

  8. [7]

    Large pulse attack as a method of conventional optical eavesdropping in quantum cryptography,

    A. Vakhitov, V. Makarov, and D. R. Hjelme, “Large pulse attack as a method of conventional optical eavesdropping in quantum cryptography,” J. Mod. Opt. , vol. 48, p. 2023, 2001

Show all 34 references
  1. [8]

    Trojan-horse attacks threaten the security of practical quantum cryptography,

    N. Jain, E. Anisimova, I. Khan, V. Makarov, C. Marquardt, and G. Leuchs, “Trojan-horse attacks threaten the security of practical quantum cryptography,” New Journal of Physics , vol. 16, no. 12, p. 123030, 2014

  2. [9]

    Invisible Trojan-horse attack,

    S. Sajeed, C. Minshull, N. Jain, and V. Makarov, “Invisible Trojan-horse attack,” Scientific Reports, vol. 7, no. 1, p. 8403, 2017

  3. [10]

    Practical security bounds against the Trojan-horse attack in quantum key distribution,

    M. Lucamarini, I. Choi, M. B. Ward, J. F. Dynes, Z. Yuan, and A. J. Shields, “Practical security bounds against the Trojan-horse attack in quantum key distribution,” Physical Review X , vol. 5, no. 3, p. 031030, 2015

  4. [11]

    Decoy-state quantum key distribution with a leaky source,

    K. Tamaki, M. Curty, and M. Lucamarini, “Decoy-state quantum key distribution with a leaky source,” New Journal of Physics, vol. 18, no. 6, p. 065008, 2016

  5. [12]

    Finite-key security analysis for quantum key distribution with leaky sources,

    W. Wang, K. Tamaki, and M. Curty, “Finite-key security analysis for quantum key distribution with leaky sources,” New Journal of Physics , vol. 20, no. 8, p. 083027, 2018

  6. [13]

    Improved finite-key security analysis of quantum key distribution against Trojan-horse attacks,

    ´A. Navarrete and M. Curty, “Improved finite-key security analysis of quantum key distribution against Trojan-horse attacks,” Quantum Science and Technology, vol. 7, no. 3, p. 035021, 2022

  7. [14]

    A fully passive transmitter for decoy-state quantum key distribution,

    V. Zapatero, W. Wang, and M. Curty, “A fully passive transmitter for decoy-state quantum key distribution,” Quantum Science and Technology, vol. 8, no. 2, p. 025014, 2023

  8. [15]

    Fully passive quantum key distribution,

    W. Wang, R. Wang, C. Hu, V. Zapatero, L. Qian, B. Qi, M. Curty, and H.-K. Lo, “Fully passive quantum key distribution,” Physical Review Letters, vol. 130, no. 22, p. 220801, 2023

  9. [16]

    Finite-key security of passive quantum key distribution,

    V. Zapatero and M. Curty, “Finite-key security of passive quantum key distribution,” Physical Review Applied , vol. 21, no. 1, p. 014018, 2024

  10. [17]

    Ex- perimental demonstration of fully passive quantum key distribution,

    F.-Y. Lu, Z.-H. Wang, V. Zapatero, J.-L. Chen, S. Wang, Z.-Q. Yin, M. Curty, D.-Y. He, R. Wang, W. Chen, et al., “Ex- perimental demonstration of fully passive quantum key distribution,” Physical Review Letters, vol. 131, no. 11, p. 110802, 2023

  11. [18]

    Proof-of-principle demonstration of fully passive quantum key distribution,

    C. Hu, W. Wang, K.-S. Chan, Z. Yuan, and H.-K. Lo, “Proof-of-principle demonstration of fully passive quantum key distribution,” Physical Review Letters, vol. 131, no. 11, p. 110801, 2023. 24

  12. [19]

    Non-poissonian statistics from poissonian light sources with application to passive decoy state quantum key distribution,

    M. Curty, T. Moroder, X. Ma, and N. L¨ utkenhaus, “Non-poissonian statistics from poissonian light sources with application to passive decoy state quantum key distribution,” Optics Letters, vol. 34, no. 20, pp. 3238–3240, 2009

  13. [20]

    Passive decoy-state quantum key distribution with practical light sources,

    M. Curty, X. Ma, B. Qi, and T. Moroder, “Passive decoy-state quantum key distribution with practical light sources,” Physical Review A , vol. 81, no. 2, p. 022310, 2010

  14. [21]

    Passive sources for the Bennett-Brassard 1984 quantum-key-distribution protocol with practical signals,

    M. Curty, X. Ma, H.-K. Lo, and N. L¨ utkenhaus, “Passive sources for the Bennett-Brassard 1984 quantum-key-distribution protocol with practical signals,” Physical Review A , vol. 82, no. 5, p. 052325, 2010

  15. [23]

    Security of quantum key distribution with imperfect devices,

    D. Gottesman, H.-K. Lo, N. L¨ utkenhaus, and J. Preskill, “Security of quantum key distribution with imperfect devices,” Quantum Inf. Comput. , vol. 4, pp. 325–360, 2004

  16. [24]

    Security of quantum key distribution using weak coherent states with nonrandom phases,

    H.-K. Lo and J. Preskill, “Security of quantum key distribution using weak coherent states with nonrandom phases,” Quantum Information and Computation , vol. 7, 11 2006

  17. [25]

    Discrete-phase-randomized coherent state source and its application in quantum key distribution,

    Z. Cao, Z. Zhang, H.-K. Lo, and X. Ma, “Discrete-phase-randomized coherent state source and its application in quantum key distribution,” New Journal of Physics , vol. 17, no. 5, p. 053014, 2015

  18. [26]

    Security of quantum key distribution with imperfect phase randomisation,

    G. Curr´ as-Lorenzo, S. Nahar, N. L¨ utkenhaus, K. Tamaki, and M. Curty, “Security of quantum key distribution with imperfect phase randomisation,” Quantum Science and Technology, vol. 9, no. 1, p. 015025, 2023

  19. [27]

    Simple security proof of quantum key distribution based on complementarity,

    M. Koashi, “Simple security proof of quantum key distribution based on complementarity,”New Journal of Physics, vol. 11, no. 4, p. 045018, 2009

  20. [28]

    Quantum key distribution over 122 km of standard telecom fiber,

    C. Gobby, Z. Yuan, and A. Shields, “Quantum key distribution over 122 km of standard telecom fiber,” Applied Physics Letters, vol. 84, no. 19, pp. 3762–3764, 2004

  21. [29]

    Practical decoy state for quantum key distribution,

    X. Ma, B. Qi, Y. Zhao, and H.-K. Lo, “Practical decoy state for quantum key distribution,” Physical Review A , vol. 72, no. 1, p. 012326, 2005

  22. [30]

    A security framework for quantum key distribution implementations,

    G. Curr´ as-Lorenzo, M. Pereira, G. Kato, M. Curty, and K. Tamaki, “A security framework for quantum key distribution implementations,” preprint arXiv:2305.05930, 2023

  23. [31]

    Security of quantum key distribution with intensity correlations,

    V. Zapatero, ´A. Navarrete, K. Tamaki, and M. Curty, “Security of quantum key distribution with intensity correlations,” Quantum, vol. 5, p. 602, 2021

  24. [32]

    Secret key rate bounds for quantum key distribution with faulty active phase randomization,

    X. Sixto, G. Curr´ as-Lorenzo, K. Tamaki, and M. Curty, “Secret key rate bounds for quantum key distribution with faulty active phase randomization,” EPJ Quantum Technology, vol. 10, no. 1, pp. 1–26, 2023

  25. [33]

    Estimates for practical quantum cryptography,

    N. L¨ utkenhaus, “Estimates for practical quantum cryptography,”Physical Review A , vol. 59, no. 5, p. 3301, 1999

  26. [34]

    Security against individual attacks for realistic quantum key distribution,

    N. L¨ utkenhaus, “Security against individual attacks for realistic quantum key distribution,” Physical Review A , vol. 61, no. 5, p. 052304, 2000

Pith tools

Reviewed August 12, 2026 · model on record in the stance chip above.