REVIEW 3 major objections 4 minor 40 references
Improved finite-size analysis for measurement-device-independent quantum digital signature
T0 review · 3 major / 4 minor · reviewed 2026-08-10 · deepseek-v4-flash
Pith's one-line read Signing many bits from a single key pool sharply improves the finite-size signature rate of measurement-device-independent quantum digital signatures.
desk verdict Practical MDI-QDS rate boost from multi-bit signing, but the missing multi-message security composition is the crux a referee must press. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing object is the parameter-estimation model that converts raw detection data into the single-photon pair counts and error rates used in the security bounds. In SMB1-PE the key step is estimating the Z-basis single-photon error rate as $e_{Z,1} = \min\{\lceil n_{Z,1} e_{X,1}/n_{X,1} + (n_{Z,1}+n_{X,1})\gamma(n_{Z,1}, n_{X,1}, \varepsilon''')\rceil, n_{Z,1}\}$, then converting it to the per-signature quantities $n_{L,1}$ and $e_{L,1}$ through Serfling-fluctuation bounds, and finally setting $R = n_{\rm pool}/(2NL)$. The mechanism that carries the improvement is amortization: instead of reserving the Z-basis key material for a single bit, the whole key pool is used to sign multiple messages, spreading the finite-size estimation overhead over many signatures.
What would settle it
Recompute the signature rate of SMB1-PE under a complete multi-message composition argument, for instance by multiplying the per-message failure probabilities by the number of signed messages, and check whether the claimed rates at $N = 10^{12}$ and distance 150 km still satisfy the declared security level $\varepsilon = 10^{-5}$; if they do not, the reported improvement is an artifact of the missing composition step.
Extended reading notes
Core claim
The central claim of the paper is that, for a two-decoy MDI-QDS protocol with security level $10^{-5}$ and pulse numbers $N = 10^{12}, 10^{14}, 10^{16}$, the SMB1-PE model -- which estimates single-photon pair counts directly from Z-basis data and then uses the entire kept key pool to sign $n_{\rm bits} = n_{\rm pool}/(2L)$ messages -- delivers the highest signature rate at every transmission distance and is the least affected by finite-size effects. The SMB2-PE model, which infers $n_{Z,1}$ from X-basis counts through a Serfling bound, also outperforms the SOB-PE baseline at all but the farthest distance. At the maximum distance the SMB1-PE and SOB-PE rates converge, since both effectively sign only one bit. The authors conclude that the proposed multi-bit estimation models improve the signature rate and transmission distance of MDI-QDS and are applicable to other QDS protocols.
Load-bearing premise
The security bounds in Eqs. (4)-(7) are derived for a single signed message, but the protocol signs $n_{\rm bits} = n_{\rm pool}/(2L)$ messages from one key pool and reports $R = n_{\rm pool}/(2NL)$ without proving that the total failure probability stays below $\varepsilon$ across all messages.
Editorial extensions
If this is right
- The SMB1-PE model yields higher signature rates than SOB-PE across all distances, with the largest gain at intermediate distances.
- The SMB2-PE model also improves the signature rate except at the farthest distance, where it lags slightly behind SOB-PE.
- Both proposed models reduce the finite-size penalty at fixed pulse number, allowing shorter key pools for the same security level.
- The estimation approach is protocol-agnostic and can be applied to other QDS schemes such as BB84-QDS and twin-field QDS.
- Combining the multi-bit models with one-time universal hashing (OTUH) can further raise the signature rate, as noted in the conclusion.
Reading between the lines
- If the multi-message composition of the security bounds holds, the SMB1-PE gain should also appear in experimental MDI-QDS systems, so a proof-of-principle experiment comparing SOB-PE and SMB1-PE at $10^{14}$ pulses would be a direct test.
- The SMB1-versus-SMB2 gap suggests that estimating $n_{Z,1}$ directly from Z-basis data is statistically more efficient than inferring it from X-basis counts; a hybrid scheme that switches models by distance might capture the best of both.
- For a rigorous deployment claim, the per-message bounds in Eqs. (4)-(7) must be composed over the $n_{\rm bits}$ messages signed from one pool; that missing proof is the main thing standing between the simulated rates and a secure rate statement.
- The straight-line behavior of SOB-PE in Fig. 6 indicates that its rate is set by a fixed per-bit cost, so it cannot benefit from larger pulse numbers; the SMB models convert additional pulses into higher rates.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The manuscript analyzes finite-size effects in two-decoy measurement-device-independent quantum digital signature (MDI-QDS) by comparing three parameter-estimation models: the previously used SOB-PE model and two new models, SMB1-PE and SMB2-PE, which sign multiple bits from a single key pool. The paper gives estimators for single-photon counts and error rates, states per-message security bounds for robustness, repudiation, and forging, and presents numerical simulations showing that SMB1-PE yields the highest signature rate and longest transmission distance.
Significance. If the security claims can be rigorously established, the paper offers a practically useful improvement: SMB1-PE reuses the generated key pool for multiple signed bits and thereby raises the finite-size signature rate of MDI-QDS. The comparison of three estimation models with full parameter optimization is a useful contribution. The main obstacle is that the security bounds used to set the thresholds are for a single signed message, while the improved rate is obtained by signing many messages; without a proof that the failure probability composes over messages, the headline rates are not yet established. There is also a dimensional inconsistency in the definition of e_{Z,1} that affects the SMB1 estimator itself.
major comments (3)
- [II.C, Eqs. (4)-(7) and (14)-(15)] The security bounds in Eqs. (4)-(7) are stated for a single signed message, but in the SMB1-PE and SMB2-PE models the key pool is used to sign nbits = npool/(2L) messages and the rate is computed as R = npool/(2NL). The manuscript does not provide a union bound, a sequential composition argument, or a statement of whether epsilon = 10^-5 is a per-message or total security level. Since the thresholds sa and sv are determined from these single-message bounds, the total failure probability could be up to nbits times epsilon; restoring a total epsilon would require replacing epsilon by epsilon/nbits in Eqs. (3)-(6), which would change L and hence the rates in Figs. 5 and 6. Because the claimed advantage of SMB1-PE over SOB-PE derives exactly from signing many bits, this missing composition step is load-bearing.
- [II.C, Eq. (11) and Eq. (13)] In Eq. (11), e_{Z,1} is defined as min{ ceil(n_{Z,1}e_{X,1}/n_{X,1} + (n_{Z,1}+n_{X,1})\gamma(...)), n_{Z,1} }, which has the units of a count, while in Eq. (13) e_{Z,1} is used as an error rate to which a fluctuation term is added. If e_{Z,1} is intended to be an error count, Eq. (13) should employ e_{Z,1}/n_{Z,1}; if it is intended to be a rate, the expression in Eq. (11) is missing a division by n_{Z,1}. The SMB1-PE simulation curves depend on this definition and should be recomputed with the corrected expression.
- [II.C, Eq. (14)] The size npool of the key pool is not defined in the text; Fig. 3 labels it but no formula is given relating npool to N, the Z-basis fraction, and the error-test fraction r_ET. Without this definition, Eqs. (14)-(15) and the numerical rates in Fig. 5 cannot be reproduced. Please provide the explicit expression for npool used in the simulations.
minor comments (4)
- [Throughout] The phrase "expect with error probability" should read "except with error probability" in several places, including after Eqs. (3), (11), (A4), (A5), and (A7).
- [Section I] In the Introduction, "non-negativity of data transmission" should be "non-repudiation of data transmission."
- [Figure 5] The axis labels and tick labels in Fig. 5 are not legible in the provided version; the figure should be regenerated with readable labels so that the numerical results can be assessed.
- [II.C, Eq. (11)] Equation (11) introduces three error-probability parameters epsilon'_k,e, epsilon''_k,e, and epsilon'''_k,e, but only epsilon'''_k,e appears in the displayed expression; the roles of the other two parameters are not explained.
Circularity Check
No significant circularity: the finite-size parameter-estimation models are compared by simulation using standard security bounds, and the SMB1 rate advantage follows from a stated multi-bit signing count rather than from fitting targets to the output curves.
full rationale
The paper's central comparison is between three parameter-estimation models (SOB-PE, SMB1-PE, SMB2-PE) for finite-size MDI-QDS. The security framework in Eqs. (1)-(7) is imported from prior QDS work and is not re-derived here, but that is ordinary reliance on established results, not a circular definition. The claimed rate improvement of SMB1-PE comes from Eqs. (14)-(15), nbits = npool/(2L) and R = npool/(2NL), which is a counting identity for reusing a key pool over multiple signed bits; it is a protocol design choice, not a fitted parameter renamed as a prediction. The parameter-estimation formulas (11)-(18) use Serfling and Hoeffding inequalities as external statistical facts. There is no self-citation chain that forces the conclusion, and no equation reduces to its own input. The main weakness is a missing security composition proof: Eqs. (4)-(7) bound probabilities for a single signed message, while the SMB1/SMB2 rate formulas sign nbits messages from one pool without an explicit union bound or per-message epsilon allocation. This is an omitted proof or correctness risk, not a circular step, because the security bounds are not defined in terms of the final signature rate; it therefore does not raise the circularity score.
Assumptions & free parameters
free parameters (4)
- signal intensity a_s and decoy intensity a_d1 =
optimized via LSA; values not reported in text
- intensity selection probabilities P_as, P_ad1, P_ad2 =
optimized via LSA; values not reported
- weak decoy intensity a_d2 =
5e-4
- error test ratio r_ET =
5.5%
assumptions (4)
- standard math Serfling and Hoeffding concentration inequalities provide valid finite-size bounds for the estimated counts and error rates.
- domain assumption The decoy-state MDI-QKD security analysis of Curty et al. [36] applies to the KGP stage, and the min-entropy bound in Eq. (1) correctly lower-bounds the secret key length.
- domain assumption The channel and devices satisfy the MDI-QKD assumptions: Alice, Bob, and Charlie's encoders are trusted, the channels are lossy and noisy, and Eve controls the measurement but not the encoding.
- ad hoc to paper The security bounds in Eqs. (4)-(7), derived for a single signed message, compose over the nbits messages without increasing the total failure probability beyond epsilon.
Cite this review
Pith. "Pith review of Improved finite-size analysis for measurement-device-independent quantum digital signature." pith.science (2026). https://pith.science/paper/6VWYEBXZ
@misc{pith2026250104957,
author = {Pith},
title = {Pith review of: Improved finite-size analysis for measurement-device-independent quantum digital signature},
year = {2026},
howpublished = {\url{https://pith.science/paper/6VWYEBXZ}},
note = {Machine review of arXiv:2501.04957}
}
read the original abstract
Quantum digital signatures (QDS), based on the principles of quantum mechanics, provide information-theoretic security, ensuring the integrity, authenticity, and non-repudiation of data transmission. With present QDS protocols, measurement-device-independent QDS (MDI-QDS) can resist all attacks on detections, yet it suffers from finite-size effect. In this work, we present and compare three parameter estimation models for finite-size analysis of two-decoy MDI-QDS. The first model is a commonly used model in previous schemes, and we propose two new models to improve the performance. Subsequently, we perform numerical simulations to evaluate the performance of the three models. The results demonstrate that the proposed methods are less affected by finite-size effect, thereby effectively enhancing the signature rate. This work contributes to the practical development of QDS.
Figures
Reference graph
Works this paper leans on
-
[1]
Experimental quantum e-commerce
X.-Y. Cao, B.-H. Li, Y. Wang, Y. Fu, H.-L. Yin, and Z.-B. Chen, "Experimental quantum e-commerce", Sci. Adv. vol. 10, eadk3258, 2024
work page 2024
-
[2]
Demonstration of quantum-digital payments
P. Schiansky, J. Kalb, E. Sztatecsny, M.-C. Roehsner, T. Guggemos, A. Trenti, M. Bozzio, and P. Walther, "Demonstration of quantum-digital payments", Nat. Commun., vol. 14, pp. 3849, 2023
work page 2023
-
[3]
A tricky path to quantum-safe encryp- tion,
N. Wolchover, “A tricky path to quantum-safe encryp- tion,” Quanta Mag., Sept. 2015
work page 2015
-
[4]
Unconditionally secure quantum signatures
R. Amiri and E. Andersson, "Unconditionally secure quantum signatures", Entropy, vol. 17, pp. 5635, 2015
work page 2015
-
[5]
System parameters used in numerical simulations
Here, we use 5 Table I. System parameters used in numerical simulations. α is the loss coefficient of fiber at telecommunication waveleng th, ηd and Pdc are the detection efficiency and the dark count rate of detecto rs, respectively; ed is the optical misalignment error; rET is the ratio of keys used for the error test; ǫP E and ǫSF are the failure probabilit...
-
[6]
A single quantum cannot be cloned,
W.-K. Wootters, W.-H. Zurek, "A single quantum cannot be cloned," Nature, vol. 299, no. 5886, pp. 802–803, 1982
work page 1982
-
[7]
Unconditional security of quantum key distribution over arbitrarily long distances,
H.-K. Lo and H.-F. Chau, “Unconditional security of quantum key distribution over arbitrarily long distances,” Science, vol. 283, pp. 2050–2056, 1999
work page 1999
-
[8]
The security of practical quantum key distribution,
V. Scarani, H. Bechmann-Pasquinucci, N.-J. Cerf, M. Dusek, N. Lutkenhaus, and M. Peev, "The security of practical quantum key distribution," Rev. Mod. Phys. , vol. 81, no. 3, pp. 1301–1350, Sept. 2009
work page 2009
Show all 40 references
-
[9]
Quantum digital signa- tures,
D. Gottesman, and I. Chuang, "Quantum digital signa- tures," ArXiv:quant-ph/0105032, 2001
2001 arXiv
-
[10]
Realization of quantum digital signatures without the requirement of quantum memory
R.-J. Collins, R.-J. Donaldson, V. Dunjko, P. Wallden, P.-J. Clarke, E. Andersson, J. Jeffers, and G.-S. Buller, "Realization of quantum digital signatures without the requirement of quantum memory", Phys. Rev. Lett. , vol. 113, no. 5, pp. 040502, 2014
2014
-
[11]
Practical quantum digital signature
H.-L. Yin, Y. Fu, and Z.-B. Chen, "Practical quantum digital signature", Phys. Rev. A , vol. 93, no. 12, pp. 032316, Mar. 2016
2016
-
[12]
Efficient quantum digital signatures without symmetrization step,
Y.-S. Lu, X.-Y. Cao, C.-X. Weng, J. Gu, Y.-M. Xie, M.- G. Zhou, H.-L. Yin, and Z.-B. Chen, "Efficient quantum digital signatures without symmetrization step," Opt. Express, vol. 29, pp. 10162-10171, 2021. 7
2021
-
[14]
Se- cure quantum signatures using insecure quantum chan- nels,
R. Amiri, P. Wallden, A. Kent, and E. Andersson, "Se- cure quantum signatures using insecure quantum chan- nels," Phys. Rev. A , vol. 93, no. 9, pp. 032325, 2016
2016
-
[15]
Measurement-device-independent quantum digital signatures,
I.-V. Puthoor, R. Amiri, P. Wallden, M. Curty, and E. Andersson, "Measurement-device-independent quantum digital signatures," Phys. Rev. A, vol. 94, no. 11, pp. 022328, Aug. 2016
2016
-
[16]
Asynchronous measurement-device-independent quantum digital signatures
J.-W. Bian, B.-H. Li, Y.-M. Xie, H.-L. Yin, and Z.-B. Chen, "Asynchronous measurement-device-independent quantum digital signatures", Phys. Rev. A, vol. 110, no. 15, pp. 012609, Jul. 2024
2024
-
[17]
Twin-field quantum digital signatures,
C.-H. Zhang, X.-Y. Zhou, C.-M. Zhang, J. Li, and Q. Wang, "Twin-field quantum digital signatures," Opt. Lett., vol. 46, no. 15, pp. 3757-3760, Aug. 2021
2021
-
[18]
Practical long-distace twin-field quantum digital signatures,
M.-H. Zhang, J.-H. Xie, J.-Y. Wu, L.-Y. Yue, C. He, Z.-W. Cao, J.-Y. Peng, "Practical long-distace twin-field quantum digital signatures," Quantum Inf. Process , vol. 21, pp. 150, Apr. 2022
2022
-
[19]
Sending-or-not-sending twin-field quantum key distri- bution: Breaking the direct transmission key rate,
H. Xu, Z.-W. Yu, C. Jiang, X.-L. Hu, and X.-B. Wang, "Sending-or-not-sending twin-field quantum key distri- bution: Breaking the direct transmission key rate," Phys. Rev. A , vol. 101, no. 10, pp. 042330, Apr. 2020
2020
-
[20]
Quan- tum Digital Signatures with Random Pairing,
J.-Q. Qin, C. Jiang, Y.-L. Yu, and X.-B. Wang, "Quan- tum Digital Signatures with Random Pairing," Phys. Rev. Appl. , vol. 17, no. 15, pp. 044047, Apr. 2022
2022
-
[21]
Secret key agreement by public discus- sion from common information,
U.-M. Maurer, "Secret key agreement by public discus- sion from common information," IEEE Trans. Inform. Theory, vol. 39, no. 3, pp. 733–742, May 1993
1993
-
[22]
Asymmetric measurement-device-independent quantum key distribution through advantage distilla- tion,
K. Zhang, J. Liu, H. Ding, X. Zhou, C. Zhang, and Q. Wang, "Asymmetric measurement-device-independent quantum key distribution through advantage distilla- tion," Entropy, vol. 25, no. 8, pp. 1174, Aug. 2023
2023
-
[23]
Sending-or-not-sending twin-field quantum key distri- bution with advantage distillation
Y. Zhou, R.-Q. Wang, C.-M. Zhang, Z.-Q. Yin, Z.-H. Wang, S. Wang, W. Chen, G.-C. Guo, and Z.-F. Han, "Sending-or-not-sending twin-field quantum key distri- bution with advantage distillation", Phys. Rev. Appl. , vol. 21, no. 9, pp. 014036, Jan. 2024
2024
-
[24]
Experimental quan- tum digital signature over 102 km,
H.-L. Yin, Y. Fu, H. Liu, Q.-J. Tang, J. Wang, L.-X. You, W.-J. Zhang, S.-J. Chen, Z. Wang, Q. Zhang, T.-Y. Chen, Z.-B. Chen, and J.-W. Pan, "Experimental quan- tum digital signature over 102 km," Phys. Rev. A , vol. 95, no. 9, pp. 032334, Mar. 2017
2017
-
[25]
Proof-of-principle demonstration of passive decoy-state quantum digital signatures over 200 km
C.-H. Zhang, X.-Y. Zhou, H.-J. Ding, C.-M. Zhang, G.-C. Guo, and Q. Wang, "Proof-of-principle demonstration of passive decoy-state quantum digital signatures over 200 km", Phys. Rev. Appl. , vol. 10, no. 8, pp. 034033, 2018
2018
-
[26]
Practical quantum digital signature with a gigahertz BB84 quantum key dis- tribution system,
X.-B. An, H. Zhang, C.-M. Zhang, W. Chen, S. Wang, Z.-Q. Yin, Q. Wang, D.-Y. He, P.-L. Hao, S.-F. Liu, X.- Y. Zhou, G.-C. Guo, and Z.-F. Han, "Practical quantum digital signature with a gigahertz BB84 quantum key dis- tribution system," Opt. Lett., vol. 44, pp. 139-142, 2019
2019
-
[27]
Experimental measurement-device-independent quantum digital signa- tures
G.-L. Roberts, M. Lucamarini, Z.-L. Yuan, J.-F. Dynes, L.-C. Comandar, A.-W. Sharpe, A.-J. Shields, M. Curty, I.-V. Puthoor, and E. Andersson, "Experimental measurement-device-independent quantum digital signa- tures", Nat. Commun. , vol. 8, pp. 1, Oct. 2017
2017
-
[28]
280-km experimental demonstration of a quantum digital signature with one decoy state,
H.-J. Ding, J.-J. Chen, L. Ji, X.-Y. Zhou, C.-H. Zhang, C.-M. Zhang, and Q. Wang, "280-km experimental demonstration of a quantum digital signature with one decoy state," Opt. Lett., vol. 45, pp. 1711-1714, 2020
2020
-
[29]
Experimen- tal quantum secure network with digital signatures and encryption
H.-L. Yin, Y. Fu, C.-L. Li, C.-X. Weng, B.-H. Li, J. Gu, Y.-S. Lu, S. Huang, and Z.-B. Chen, "Experimen- tal quantum secure network with digital signatures and encryption", National Science Review, vol. 10, Apr. 2023, nwac228
2023
-
[30]
High-rate quantum digital signatures network with in- tegrated silicon photonics
Y.-Q. Du, B.-H. Li, X. Hua, X.-Y. Cao, Z.-G. Zhao, F. Xie, Z.-R. Zhang, H.-L. Yin, X. Xiao, and K.-J. Wei, "High-rate quantum digital signatures network with in- tegrated silicon photonics", ArXiv:quant-ph/2407.07513, 2024
2024 arXiv
-
[31]
Multi-party ring quantum digital sig- natures
W. Qu, Y. Zhang, H. Liu, T. Dou, J. Wang, Z. Li, S. Yang, and H. Ma, "Multi-party ring quantum digital sig- natures", J. Opt. Soc. Am. B , vol. 36, pp. 1335-1341, 2019
2019
-
[32]
Secure and practical multiparty quantum digital signatures,
C.-X. Weng, Y.-S. Lu, R.-Q. Gao, Y.-M. Xie, J. Gu, C.- L. Li, B.-H. Li, H.-L. Yin, and Z.-B. Chen, "Secure and practical multiparty quantum digital signatures," Opt. Express, vol. 29, pp. 27661-27673, 2021
2021
-
[33]
Unconditionally secure digital signatures implemented in an eight-user quantum network
Y. Pelet, I. V. Puthoor, N. Venkatachalam, S. Wengerowsky, M. Loncari /caron.ts1 c, S. P. Neumann, B. Liu, Željko Samec, M. Stip /acute.ts1 cevi /caron.ts1 c,/acute.ts1R. Ursin, E. Andersson, J. G. Rarity, D. Aktas, and S. K. Joshi, "Unconditionally secure digital signatures i...
2022
-
[34]
Experimental quan- tum digital signature based on heralded single-photon sources,
L. Zhan, C. H. Zhang, N. Lu, X. R. Qian, H. J. Ding, J. Y. Liu, X. Y. Zhou, and Q. Wang, "Experimental quan- tum digital signature based on heralded single-photon sources," Quantum Inf. Process , vol. 23, pp. 25, 2024
2024
-
[35]
Free-Space Quantum Signatures Using Het- erodyne Measurements
C. Croal, C. Peuntinger, B. Heim, I. Khan, C. Mar- quardt, G. Leuchs, P. Wallden, E. Andersson, and N. Korolkova, "Free-Space Quantum Signatures Using Het- erodyne Measurements", Phys. Rev. Lett. , vol. 117, no. 5, pp. 100503, Sep. 2016
2016
-
[36]
Exper- imental measurement-device-independent quantum digi- tal signatures over a metropolitan network
H.-L. Yin, W.-L. Wang, Y.-L. Tang, Q. Zhao, H. Liu, X.-X. Sun, W.-J. Zhang, H. Li, I.-V. Puthoor, L.-X. You, E. Andersson, Z. Wang, Y. Liu, X. Jiang, X.-F. Ma, Q. Zhang, M. Curty, T.-Y. Chen, and J.-W. Pan, "Exper- imental measurement-device-independent quantum digi- tal signa...
2017
-
[37]
Finite-key analysis for measurement-device- independent quantum key distribution,
M. Curty, F.-H. Xu, W. Cui, C.-C.-W. Lim, K. Tamaki, H.-K. Lo, "Finite-key analysis for measurement-device- independent quantum key distribution," Nat. Commun. , vol. 5, pp. 3732, Apr. 2014
2014
-
[38]
Probability Inequalities for the Sum in Sampling without Replacement
R.-J. Serfling, "Probability Inequalities for the Sum in Sampling without Replacement", The Annals of Statis- tics, vol. 2, no. 1, pp. 39, 1974
1974
-
[39]
Probability inequalities for sums of bounded random variables
W. Hoeffding, "Probability inequalities for sums of bounded random variables", Journal of the American Statistical Association, vol. 58, no. 301, pp. 13, 1963
1963
-
[40]
Protocol choice and parameter optimization in decoy-state measurement- device-independent quantum key distribution
F.-H. Xu, H. Xu, and H.-K. Lo, "Protocol choice and parameter optimization in decoy-state measurement- device-independent quantum key distribution", Phys. Rev. A , vol. 89, pp. 052333, 2014
2014
-
[41]
One-time universal hashing quan- tum digital signatures without perfect keys
B.-H. Li, Y.-M. Xie, X.-Y. Cao, C.-L. Li, Y. Fu, H.-L. Yin, and Z.-B. Chen, "One-time universal hashing quan- tum digital signatures without perfect keys", Phys. Rev. Appl., vol. 20, pp. 044011, 2023
2023
Reviewed August 10, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.