Pith. sign in

REVIEW 3 major objections 4 minor 40 references

Improved finite-size analysis for measurement-device-independent quantum digital signature

T0 review · 3 major / 4 minor · reviewed 2026-08-10 · deepseek-v4-flash

Pith's one-line read Signing many bits from a single key pool sharply improves the finite-size signature rate of measurement-device-independent quantum digital signatures.

desk verdict Practical MDI-QDS rate boost from multi-bit signing, but the missing multi-message security composition is the crux a referee must press. read the letter →

arxiv 2501.04957 v1 pith:6VWYEBXZ submitted 2025-01-09 quant-ph

classification quant-ph MSC 81P94 PACS 03.67.Dd
keywords quantumdigitalsignaturesmeasurement-device-independentQDSfinite-sizeanalysisparameterestimationdecoy-statemethodsignaturerateSerflinginequality
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper tackles the finite-size effect that dominates the performance of measurement-device-independent quantum digital signatures (MDI-QDS). It proposes two new parameter-estimation models, SMB1-PE and SMB2-PE, that sign multiple bits from one key pool instead of one bit at a time, and compares them with the previously used SOB-PE model on a two-decoy MDI-QDS protocol. Numerical simulations show that the SMB1-PE model is the least affected by finite-size effects and achieves the best signature rate and transmission distance among the three. This matters because raising the rate and reach of MDI-QDS brings information-theoretic signatures closer to practical deployment.

What carries the argument

The load-bearing object is the parameter-estimation model that converts raw detection data into the single-photon pair counts and error rates used in the security bounds. In SMB1-PE the key step is estimating the Z-basis single-photon error rate as $e_{Z,1} = \min\{\lceil n_{Z,1} e_{X,1}/n_{X,1} + (n_{Z,1}+n_{X,1})\gamma(n_{Z,1}, n_{X,1}, \varepsilon''')\rceil, n_{Z,1}\}$, then converting it to the per-signature quantities $n_{L,1}$ and $e_{L,1}$ through Serfling-fluctuation bounds, and finally setting $R = n_{\rm pool}/(2NL)$. The mechanism that carries the improvement is amortization: instead of reserving the Z-basis key material for a single bit, the whole key pool is used to sign multiple messages, spreading the finite-size estimation overhead over many signatures.

What would settle it

Recompute the signature rate of SMB1-PE under a complete multi-message composition argument, for instance by multiplying the per-message failure probabilities by the number of signed messages, and check whether the claimed rates at $N = 10^{12}$ and distance 150 km still satisfy the declared security level $\varepsilon = 10^{-5}$; if they do not, the reported improvement is an artifact of the missing composition step.

Watch

Extended reading notes

Core claim

The central claim of the paper is that, for a two-decoy MDI-QDS protocol with security level $10^{-5}$ and pulse numbers $N = 10^{12}, 10^{14}, 10^{16}$, the SMB1-PE model -- which estimates single-photon pair counts directly from Z-basis data and then uses the entire kept key pool to sign $n_{\rm bits} = n_{\rm pool}/(2L)$ messages -- delivers the highest signature rate at every transmission distance and is the least affected by finite-size effects. The SMB2-PE model, which infers $n_{Z,1}$ from X-basis counts through a Serfling bound, also outperforms the SOB-PE baseline at all but the farthest distance. At the maximum distance the SMB1-PE and SOB-PE rates converge, since both effectively sign only one bit. The authors conclude that the proposed multi-bit estimation models improve the signature rate and transmission distance of MDI-QDS and are applicable to other QDS protocols.

Load-bearing premise

The security bounds in Eqs. (4)-(7) are derived for a single signed message, but the protocol signs $n_{\rm bits} = n_{\rm pool}/(2L)$ messages from one key pool and reports $R = n_{\rm pool}/(2NL)$ without proving that the total failure probability stays below $\varepsilon$ across all messages.

Editorial extensions

If this is right

  • The SMB1-PE model yields higher signature rates than SOB-PE across all distances, with the largest gain at intermediate distances.
  • The SMB2-PE model also improves the signature rate except at the farthest distance, where it lags slightly behind SOB-PE.
  • Both proposed models reduce the finite-size penalty at fixed pulse number, allowing shorter key pools for the same security level.
  • The estimation approach is protocol-agnostic and can be applied to other QDS schemes such as BB84-QDS and twin-field QDS.
  • Combining the multi-bit models with one-time universal hashing (OTUH) can further raise the signature rate, as noted in the conclusion.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • If the multi-message composition of the security bounds holds, the SMB1-PE gain should also appear in experimental MDI-QDS systems, so a proof-of-principle experiment comparing SOB-PE and SMB1-PE at $10^{14}$ pulses would be a direct test.
  • The SMB1-versus-SMB2 gap suggests that estimating $n_{Z,1}$ directly from Z-basis data is statistically more efficient than inferring it from X-basis counts; a hybrid scheme that switches models by distance might capture the best of both.
  • For a rigorous deployment claim, the per-message bounds in Eqs. (4)-(7) must be composed over the $n_{\rm bits}$ messages signed from one pool; that missing proof is the main thing standing between the simulated rates and a secure rate statement.
  • The straight-line behavior of SOB-PE in Fig. 6 indicates that its rate is set by a fixed per-bit cost, so it cannot benefit from larger pulse numbers; the SMB models convert additional pulses into higher rates.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 4 minor

Summary. The manuscript analyzes finite-size effects in two-decoy measurement-device-independent quantum digital signature (MDI-QDS) by comparing three parameter-estimation models: the previously used SOB-PE model and two new models, SMB1-PE and SMB2-PE, which sign multiple bits from a single key pool. The paper gives estimators for single-photon counts and error rates, states per-message security bounds for robustness, repudiation, and forging, and presents numerical simulations showing that SMB1-PE yields the highest signature rate and longest transmission distance.

Significance. If the security claims can be rigorously established, the paper offers a practically useful improvement: SMB1-PE reuses the generated key pool for multiple signed bits and thereby raises the finite-size signature rate of MDI-QDS. The comparison of three estimation models with full parameter optimization is a useful contribution. The main obstacle is that the security bounds used to set the thresholds are for a single signed message, while the improved rate is obtained by signing many messages; without a proof that the failure probability composes over messages, the headline rates are not yet established. There is also a dimensional inconsistency in the definition of e_{Z,1} that affects the SMB1 estimator itself.

major comments (3)
  1. [II.C, Eqs. (4)-(7) and (14)-(15)] The security bounds in Eqs. (4)-(7) are stated for a single signed message, but in the SMB1-PE and SMB2-PE models the key pool is used to sign nbits = npool/(2L) messages and the rate is computed as R = npool/(2NL). The manuscript does not provide a union bound, a sequential composition argument, or a statement of whether epsilon = 10^-5 is a per-message or total security level. Since the thresholds sa and sv are determined from these single-message bounds, the total failure probability could be up to nbits times epsilon; restoring a total epsilon would require replacing epsilon by epsilon/nbits in Eqs. (3)-(6), which would change L and hence the rates in Figs. 5 and 6. Because the claimed advantage of SMB1-PE over SOB-PE derives exactly from signing many bits, this missing composition step is load-bearing.
  2. [II.C, Eq. (11) and Eq. (13)] In Eq. (11), e_{Z,1} is defined as min{ ceil(n_{Z,1}e_{X,1}/n_{X,1} + (n_{Z,1}+n_{X,1})\gamma(...)), n_{Z,1} }, which has the units of a count, while in Eq. (13) e_{Z,1} is used as an error rate to which a fluctuation term is added. If e_{Z,1} is intended to be an error count, Eq. (13) should employ e_{Z,1}/n_{Z,1}; if it is intended to be a rate, the expression in Eq. (11) is missing a division by n_{Z,1}. The SMB1-PE simulation curves depend on this definition and should be recomputed with the corrected expression.
  3. [II.C, Eq. (14)] The size npool of the key pool is not defined in the text; Fig. 3 labels it but no formula is given relating npool to N, the Z-basis fraction, and the error-test fraction r_ET. Without this definition, Eqs. (14)-(15) and the numerical rates in Fig. 5 cannot be reproduced. Please provide the explicit expression for npool used in the simulations.
minor comments (4)
  1. [Throughout] The phrase "expect with error probability" should read "except with error probability" in several places, including after Eqs. (3), (11), (A4), (A5), and (A7).
  2. [Section I] In the Introduction, "non-negativity of data transmission" should be "non-repudiation of data transmission."
  3. [Figure 5] The axis labels and tick labels in Fig. 5 are not legible in the provided version; the figure should be regenerated with readable labels so that the numerical results can be assessed.
  4. [II.C, Eq. (11)] Equation (11) introduces three error-probability parameters epsilon'_k,e, epsilon''_k,e, and epsilon'''_k,e, but only epsilon'''_k,e appears in the displayed expression; the roles of the other two parameters are not explained.

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity: the finite-size parameter-estimation models are compared by simulation using standard security bounds, and the SMB1 rate advantage follows from a stated multi-bit signing count rather than from fitting targets to the output curves.

full rationale

The paper's central comparison is between three parameter-estimation models (SOB-PE, SMB1-PE, SMB2-PE) for finite-size MDI-QDS. The security framework in Eqs. (1)-(7) is imported from prior QDS work and is not re-derived here, but that is ordinary reliance on established results, not a circular definition. The claimed rate improvement of SMB1-PE comes from Eqs. (14)-(15), nbits = npool/(2L) and R = npool/(2NL), which is a counting identity for reusing a key pool over multiple signed bits; it is a protocol design choice, not a fitted parameter renamed as a prediction. The parameter-estimation formulas (11)-(18) use Serfling and Hoeffding inequalities as external statistical facts. There is no self-citation chain that forces the conclusion, and no equation reduces to its own input. The main weakness is a missing security composition proof: Eqs. (4)-(7) bound probabilities for a single signed message, while the SMB1/SMB2 rate formulas sign nbits messages from one pool without an explicit union bound or per-message epsilon allocation. This is an omitted proof or correctness risk, not a circular step, because the security bounds are not defined in terms of the final signature rate; it therefore does not raise the circularity score.

Assumptions & free parameters 4 free parameters · 4 assumptions · 0 invented entities

The paper contributes no new physical entities. Its central numerical claim rests on the standard MDI-QKD security framework plus the unproven assumption that signing multiple messages from one key pool preserves the single-message security bounds. The optimized intensities are free parameters in the simulation, not derived values.

free parameters (4)
  • signal intensity a_s and decoy intensity a_d1 = optimized via LSA; values not reported in text
    The simulation performs 'full parameter optimization' over intensities to maximize signature rate; the reported curves depend on these optimized values.
  • intensity selection probabilities P_as, P_ad1, P_ad2 = optimized via LSA; values not reported
    These probabilities determine the fraction of pulses in signal and decoy states and are optimized; they affect the finite-size bounds through N_{z,ab} and N_{x,ab}.
  • weak decoy intensity a_d2 = 5e-4
    Fixed by hand in the simulation; the choice affects the decoy-state estimation.
  • error test ratio r_ET = 5.5%
    Chosen in Table I; it trades key pool size against the accuracy of the error-rate estimate in Eq. (3).
assumptions (4)
  • standard math Serfling and Hoeffding concentration inequalities provide valid finite-size bounds for the estimated counts and error rates.
    Used in Eqs. (3), (12)-(13), (16)-(18); cited as Refs. [37,38].
  • domain assumption The decoy-state MDI-QKD security analysis of Curty et al. [36] applies to the KGP stage, and the min-entropy bound in Eq. (1) correctly lower-bounds the secret key length.
    The paper imports this security result without re-deriving it; it is the foundation for Eqs. (1)-(2).
  • domain assumption The channel and devices satisfy the MDI-QKD assumptions: Alice, Bob, and Charlie's encoders are trusted, the channels are lossy and noisy, and Eve controls the measurement but not the encoding.
    Standard MDI-QDS model; stated implicitly in Section II.A and Fig. 1.
  • ad hoc to paper The security bounds in Eqs. (4)-(7), derived for a single signed message, compose over the nbits messages without increasing the total failure probability beyond epsilon.
    The paper assumes multi-bit signing is secure as a whole but provides no composition proof; this is the weakest load-bearing premise.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Improved finite-size analysis for measurement-device-independent quantum digital signature." pith.science (2026). https://pith.science/paper/6VWYEBXZ

@misc{pith2026250104957,
  author       = {Pith},
  title        = {Pith review of: Improved finite-size analysis for measurement-device-independent quantum digital signature},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/6VWYEBXZ}},
  note         = {Machine review of arXiv:2501.04957}
}
read the original abstract

Quantum digital signatures (QDS), based on the principles of quantum mechanics, provide information-theoretic security, ensuring the integrity, authenticity, and non-repudiation of data transmission. With present QDS protocols, measurement-device-independent QDS (MDI-QDS) can resist all attacks on detections, yet it suffers from finite-size effect. In this work, we present and compare three parameter estimation models for finite-size analysis of two-decoy MDI-QDS. The first model is a commonly used model in previous schemes, and we propose two new models to improve the performance. Subsequently, we perform numerical simulations to evaluate the performance of the three models. The results demonstrate that the proposed methods are less affected by finite-size effect, thereby effectively enhancing the signature rate. This work contributes to the practical development of QDS.

Figures

Figures reproduced from arXiv: 2501.04957 by the authors.

Figure 1
Figure 1. FIG. 1. Schematic of the MDI-QDS protocol. Alice-Bob and [PITH_FULL_IMAGE:figures/full_fig_p002_1.png] view at source ↗
Figure 2
Figure 2. FIG. 2. The relationships of different data blocks and the [PITH_FULL_IMAGE:figures/full_fig_p003_2.png] view at source ↗
Figure 3
Figure 3. FIG. 3. The relationships of different data blocks and the [PITH_FULL_IMAGE:figures/full_fig_p003_3.png] view at source ↗
Figures from the paper (2 more)
Figure 4
Figure 4. Figure 4: Fig.4. The signature mode is the same as the SMB1-PE [PITH_FULL_IMAGE:figures/full_fig_p004_4.png]
Figure 5
Figure 5. Figure 5: FIG. 5. The signature rate of three parameter estimation [PITH_FULL_IMAGE:figures/full_fig_p005_5.png]

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

40 extracted references · 39 canonical work pages

  1. [1]

    Experimental quantum e-commerce

    X.-Y. Cao, B.-H. Li, Y. Wang, Y. Fu, H.-L. Yin, and Z.-B. Chen, "Experimental quantum e-commerce", Sci. Adv. vol. 10, eadk3258, 2024

  2. [2]

    Demonstration of quantum-digital payments

    P. Schiansky, J. Kalb, E. Sztatecsny, M.-C. Roehsner, T. Guggemos, A. Trenti, M. Bozzio, and P. Walther, "Demonstration of quantum-digital payments", Nat. Commun., vol. 14, pp. 3849, 2023

  3. [3]

    A tricky path to quantum-safe encryp- tion,

    N. Wolchover, “A tricky path to quantum-safe encryp- tion,” Quanta Mag., Sept. 2015

  4. [4]

    Unconditionally secure quantum signatures

    R. Amiri and E. Andersson, "Unconditionally secure quantum signatures", Entropy, vol. 17, pp. 5635, 2015

  5. [5]

    System parameters used in numerical simulations

    Here, we use 5 Table I. System parameters used in numerical simulations. α is the loss coefficient of fiber at telecommunication waveleng th, ηd and Pdc are the detection efficiency and the dark count rate of detecto rs, respectively; ed is the optical misalignment error; rET is the ratio of keys used for the error test; ǫP E and ǫSF are the failure probabilit...

  6. [6]

    A single quantum cannot be cloned,

    W.-K. Wootters, W.-H. Zurek, "A single quantum cannot be cloned," Nature, vol. 299, no. 5886, pp. 802–803, 1982

  7. [7]

    Unconditional security of quantum key distribution over arbitrarily long distances,

    H.-K. Lo and H.-F. Chau, “Unconditional security of quantum key distribution over arbitrarily long distances,” Science, vol. 283, pp. 2050–2056, 1999

  8. [8]

    The security of practical quantum key distribution,

    V. Scarani, H. Bechmann-Pasquinucci, N.-J. Cerf, M. Dusek, N. Lutkenhaus, and M. Peev, "The security of practical quantum key distribution," Rev. Mod. Phys. , vol. 81, no. 3, pp. 1301–1350, Sept. 2009

Show all 40 references
  1. [9]

    Quantum digital signa- tures,

    D. Gottesman, and I. Chuang, "Quantum digital signa- tures," ArXiv:quant-ph/0105032, 2001

  2. [10]

    Realization of quantum digital signatures without the requirement of quantum memory

    R.-J. Collins, R.-J. Donaldson, V. Dunjko, P. Wallden, P.-J. Clarke, E. Andersson, J. Jeffers, and G.-S. Buller, "Realization of quantum digital signatures without the requirement of quantum memory", Phys. Rev. Lett. , vol. 113, no. 5, pp. 040502, 2014

  3. [11]

    Practical quantum digital signature

    H.-L. Yin, Y. Fu, and Z.-B. Chen, "Practical quantum digital signature", Phys. Rev. A , vol. 93, no. 12, pp. 032316, Mar. 2016

  4. [12]

    Efficient quantum digital signatures without symmetrization step,

    Y.-S. Lu, X.-Y. Cao, C.-X. Weng, J. Gu, Y.-M. Xie, M.- G. Zhou, H.-L. Yin, and Z.-B. Chen, "Efficient quantum digital signatures without symmetrization step," Opt. Express, vol. 29, pp. 10162-10171, 2021. 7

  5. [14]

    Se- cure quantum signatures using insecure quantum chan- nels,

    R. Amiri, P. Wallden, A. Kent, and E. Andersson, "Se- cure quantum signatures using insecure quantum chan- nels," Phys. Rev. A , vol. 93, no. 9, pp. 032325, 2016

  6. [15]

    Measurement-device-independent quantum digital signatures,

    I.-V. Puthoor, R. Amiri, P. Wallden, M. Curty, and E. Andersson, "Measurement-device-independent quantum digital signatures," Phys. Rev. A, vol. 94, no. 11, pp. 022328, Aug. 2016

  7. [16]

    Asynchronous measurement-device-independent quantum digital signatures

    J.-W. Bian, B.-H. Li, Y.-M. Xie, H.-L. Yin, and Z.-B. Chen, "Asynchronous measurement-device-independent quantum digital signatures", Phys. Rev. A, vol. 110, no. 15, pp. 012609, Jul. 2024

  8. [17]

    Twin-field quantum digital signatures,

    C.-H. Zhang, X.-Y. Zhou, C.-M. Zhang, J. Li, and Q. Wang, "Twin-field quantum digital signatures," Opt. Lett., vol. 46, no. 15, pp. 3757-3760, Aug. 2021

  9. [18]

    Practical long-distace twin-field quantum digital signatures,

    M.-H. Zhang, J.-H. Xie, J.-Y. Wu, L.-Y. Yue, C. He, Z.-W. Cao, J.-Y. Peng, "Practical long-distace twin-field quantum digital signatures," Quantum Inf. Process , vol. 21, pp. 150, Apr. 2022

  10. [19]

    Sending-or-not-sending twin-field quantum key distri- bution: Breaking the direct transmission key rate,

    H. Xu, Z.-W. Yu, C. Jiang, X.-L. Hu, and X.-B. Wang, "Sending-or-not-sending twin-field quantum key distri- bution: Breaking the direct transmission key rate," Phys. Rev. A , vol. 101, no. 10, pp. 042330, Apr. 2020

  11. [20]

    Quan- tum Digital Signatures with Random Pairing,

    J.-Q. Qin, C. Jiang, Y.-L. Yu, and X.-B. Wang, "Quan- tum Digital Signatures with Random Pairing," Phys. Rev. Appl. , vol. 17, no. 15, pp. 044047, Apr. 2022

  12. [21]

    Secret key agreement by public discus- sion from common information,

    U.-M. Maurer, "Secret key agreement by public discus- sion from common information," IEEE Trans. Inform. Theory, vol. 39, no. 3, pp. 733–742, May 1993

  13. [22]

    Asymmetric measurement-device-independent quantum key distribution through advantage distilla- tion,

    K. Zhang, J. Liu, H. Ding, X. Zhou, C. Zhang, and Q. Wang, "Asymmetric measurement-device-independent quantum key distribution through advantage distilla- tion," Entropy, vol. 25, no. 8, pp. 1174, Aug. 2023

  14. [23]

    Sending-or-not-sending twin-field quantum key distri- bution with advantage distillation

    Y. Zhou, R.-Q. Wang, C.-M. Zhang, Z.-Q. Yin, Z.-H. Wang, S. Wang, W. Chen, G.-C. Guo, and Z.-F. Han, "Sending-or-not-sending twin-field quantum key distri- bution with advantage distillation", Phys. Rev. Appl. , vol. 21, no. 9, pp. 014036, Jan. 2024

  15. [24]

    Experimental quan- tum digital signature over 102 km,

    H.-L. Yin, Y. Fu, H. Liu, Q.-J. Tang, J. Wang, L.-X. You, W.-J. Zhang, S.-J. Chen, Z. Wang, Q. Zhang, T.-Y. Chen, Z.-B. Chen, and J.-W. Pan, "Experimental quan- tum digital signature over 102 km," Phys. Rev. A , vol. 95, no. 9, pp. 032334, Mar. 2017

  16. [25]

    Proof-of-principle demonstration of passive decoy-state quantum digital signatures over 200 km

    C.-H. Zhang, X.-Y. Zhou, H.-J. Ding, C.-M. Zhang, G.-C. Guo, and Q. Wang, "Proof-of-principle demonstration of passive decoy-state quantum digital signatures over 200 km", Phys. Rev. Appl. , vol. 10, no. 8, pp. 034033, 2018

  17. [26]

    Practical quantum digital signature with a gigahertz BB84 quantum key dis- tribution system,

    X.-B. An, H. Zhang, C.-M. Zhang, W. Chen, S. Wang, Z.-Q. Yin, Q. Wang, D.-Y. He, P.-L. Hao, S.-F. Liu, X.- Y. Zhou, G.-C. Guo, and Z.-F. Han, "Practical quantum digital signature with a gigahertz BB84 quantum key dis- tribution system," Opt. Lett., vol. 44, pp. 139-142, 2019

  18. [27]

    Experimental measurement-device-independent quantum digital signa- tures

    G.-L. Roberts, M. Lucamarini, Z.-L. Yuan, J.-F. Dynes, L.-C. Comandar, A.-W. Sharpe, A.-J. Shields, M. Curty, I.-V. Puthoor, and E. Andersson, "Experimental measurement-device-independent quantum digital signa- tures", Nat. Commun. , vol. 8, pp. 1, Oct. 2017

  19. [28]

    280-km experimental demonstration of a quantum digital signature with one decoy state,

    H.-J. Ding, J.-J. Chen, L. Ji, X.-Y. Zhou, C.-H. Zhang, C.-M. Zhang, and Q. Wang, "280-km experimental demonstration of a quantum digital signature with one decoy state," Opt. Lett., vol. 45, pp. 1711-1714, 2020

  20. [29]

    Experimen- tal quantum secure network with digital signatures and encryption

    H.-L. Yin, Y. Fu, C.-L. Li, C.-X. Weng, B.-H. Li, J. Gu, Y.-S. Lu, S. Huang, and Z.-B. Chen, "Experimen- tal quantum secure network with digital signatures and encryption", National Science Review, vol. 10, Apr. 2023, nwac228

  21. [30]

    High-rate quantum digital signatures network with in- tegrated silicon photonics

    Y.-Q. Du, B.-H. Li, X. Hua, X.-Y. Cao, Z.-G. Zhao, F. Xie, Z.-R. Zhang, H.-L. Yin, X. Xiao, and K.-J. Wei, "High-rate quantum digital signatures network with in- tegrated silicon photonics", ArXiv:quant-ph/2407.07513, 2024

  22. [31]

    Multi-party ring quantum digital sig- natures

    W. Qu, Y. Zhang, H. Liu, T. Dou, J. Wang, Z. Li, S. Yang, and H. Ma, "Multi-party ring quantum digital sig- natures", J. Opt. Soc. Am. B , vol. 36, pp. 1335-1341, 2019

  23. [32]

    Secure and practical multiparty quantum digital signatures,

    C.-X. Weng, Y.-S. Lu, R.-Q. Gao, Y.-M. Xie, J. Gu, C.- L. Li, B.-H. Li, H.-L. Yin, and Z.-B. Chen, "Secure and practical multiparty quantum digital signatures," Opt. Express, vol. 29, pp. 27661-27673, 2021

  24. [33]

    Unconditionally secure digital signatures implemented in an eight-user quantum network

    Y. Pelet, I. V. Puthoor, N. Venkatachalam, S. Wengerowsky, M. Loncari /caron.ts1 c, S. P. Neumann, B. Liu, Željko Samec, M. Stip /acute.ts1 cevi /caron.ts1 c,/acute.ts1R. Ursin, E. Andersson, J. G. Rarity, D. Aktas, and S. K. Joshi, "Unconditionally secure digital signatures i...

  25. [34]

    Experimental quan- tum digital signature based on heralded single-photon sources,

    L. Zhan, C. H. Zhang, N. Lu, X. R. Qian, H. J. Ding, J. Y. Liu, X. Y. Zhou, and Q. Wang, "Experimental quan- tum digital signature based on heralded single-photon sources," Quantum Inf. Process , vol. 23, pp. 25, 2024

  26. [35]

    Free-Space Quantum Signatures Using Het- erodyne Measurements

    C. Croal, C. Peuntinger, B. Heim, I. Khan, C. Mar- quardt, G. Leuchs, P. Wallden, E. Andersson, and N. Korolkova, "Free-Space Quantum Signatures Using Het- erodyne Measurements", Phys. Rev. Lett. , vol. 117, no. 5, pp. 100503, Sep. 2016

  27. [36]

    Exper- imental measurement-device-independent quantum digi- tal signatures over a metropolitan network

    H.-L. Yin, W.-L. Wang, Y.-L. Tang, Q. Zhao, H. Liu, X.-X. Sun, W.-J. Zhang, H. Li, I.-V. Puthoor, L.-X. You, E. Andersson, Z. Wang, Y. Liu, X. Jiang, X.-F. Ma, Q. Zhang, M. Curty, T.-Y. Chen, and J.-W. Pan, "Exper- imental measurement-device-independent quantum digi- tal signa...

  28. [37]

    Finite-key analysis for measurement-device- independent quantum key distribution,

    M. Curty, F.-H. Xu, W. Cui, C.-C.-W. Lim, K. Tamaki, H.-K. Lo, "Finite-key analysis for measurement-device- independent quantum key distribution," Nat. Commun. , vol. 5, pp. 3732, Apr. 2014

  29. [38]

    Probability Inequalities for the Sum in Sampling without Replacement

    R.-J. Serfling, "Probability Inequalities for the Sum in Sampling without Replacement", The Annals of Statis- tics, vol. 2, no. 1, pp. 39, 1974

  30. [39]

    Probability inequalities for sums of bounded random variables

    W. Hoeffding, "Probability inequalities for sums of bounded random variables", Journal of the American Statistical Association, vol. 58, no. 301, pp. 13, 1963

  31. [40]

    Protocol choice and parameter optimization in decoy-state measurement- device-independent quantum key distribution

    F.-H. Xu, H. Xu, and H.-K. Lo, "Protocol choice and parameter optimization in decoy-state measurement- device-independent quantum key distribution", Phys. Rev. A , vol. 89, pp. 052333, 2014

  32. [41]

    One-time universal hashing quan- tum digital signatures without perfect keys

    B.-H. Li, Y.-M. Xie, X.-Y. Cao, C.-L. Li, Y. Fu, H.-L. Yin, and Z.-B. Chen, "One-time universal hashing quan- tum digital signatures without perfect keys", Phys. Rev. Appl., vol. 20, pp. 044011, 2023

Pith tools

Reviewed August 10, 2026 · model on record in the stance chip above.