REVIEW 3 major objections 5 minor 50 references
Quantum ($t$,$n$) Threshold Multi-Secret Sharing based on Cluster States
T0 review · 3 major / 5 minor · reviewed 2026-08-15 · deepseek-v4-flash
Pith's one-line read This paper proposes a (t,n) threshold multi-secret sharing protocol in which any t of n users reconstruct many quantum secrets at once.
desk verdict Neat construction, but the internal-attack security proof relies on a false identity, so the central security claim is not established. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing object is the two-particle cluster state $|T\rangle_u^j = CZ|+\rangle|+\rangle$ used with the proposed measurement basis $\{|0_{-\omega}\rangle, |1_{-\omega}\rangle\}$, where $|0_{-\omega}\rangle = R_X(-\omega)|0\rangle$ and $|1_{-\omega}\rangle = R_X(-\omega)|1\rangle$. Measuring one particle in this basis collapses the other to $|+_{\omega}\rangle$ or $|-_{\omega}\rangle$, so a user transfers an angle $\omega$ without preparing any state. The matching identity is the angle-sum relation $\gamma_D^j + \sum_{l=1}^t \gamma_l^j = 2\pi r$, produced by the Lagrange-interpolated shares $c_l = f(x_l)\prod_{v\ne l}(-x_v/(x_l-x_v)) \bmod q$, which makes the accumulated $R_X$ rotations equal to the identity up to a global phase.
What would settle it
Take $\delta_u = 0$ and $\gamma_u = \pi/2$ in that identity: the left side becomes $R_X(\pi/2)|+\rangle = |+\rangle$, while the right side becomes $R_Z(\pi/2)|+\rangle = |+_{\pi/2}\rangle$, a different state. A direct state-vector check of both sides settles the premise.
Extended reading notes
Core claim
The central claim, on the paper's own terms, is that multi-secret sharing with a $(t,n)$ threshold can be realized with cluster states and Lagrange interpolation. The dealer chooses a polynomial $f(x)$ of degree $t-1$, privately sends $f(x_i)$ to user $P_i$, and publishes a weight $w_j$ for each secret $|\psi\rangle_j$. The dealer and the $t$ cooperating users derive rotation angles $\gamma_D^j$ and $\gamma_l^j$ from these shares so that $\gamma_D^j + \sum_{l=1}^t \gamma_l^j = 2\pi r$. The dealer sends $R_X(\gamma_D^j)|\psi\rangle_j$ to the reconstructor, who builds a chain of two-qubit cluster states with the other users; each user measures in the new basis and publishes a correction angle. After the final rotation $R_X(\gamma_t^j)$, the accumulated angles cancel to the identity up to a global phase and the original secret is recovered. The same classical shares serve every $j$, so one set of shares reconstructs all $m$ secrets.
Load-bearing premise
The dishonest-reconstructor security proof assumes $R_X(\gamma_u + (-1)^{m'}\delta_u)R_Z(\delta_u)|+\rangle = R_Z(\gamma_u)|+\rangle$; this identity does not hold for general angles, and the argument depends on it.
Editorial extensions
If this is right
- Any $t$ of the $n$ users, rather than all $n$, can reconstruct the entire sequence of $m$ quantum secrets from one set of shares.
- The dealer can stop participating after the splitting phase; reconstruction is handled by the users alone.
- Participants other than the reconstructor never have to prepare quantum states; they only measure particles and publish classical angles.
- All required operations are standard gates ($H$, $CZ$, $R_X$, $R_Z$, $X$, $Z$), so the circuit can be run on current quantum hardware.
- Each user's private share stays private after reconstruction, because only derived angles are published.
Reading between the lines
- Editorial note: Sec. IV.A itself concedes that the delayed-measurement correctness argument from the adapted protocol does not directly apply once extra operations are present; the correctness claim is anchored in the two-particle cluster form and in the reported experiment.
- Editorial inference: the same rotation-angle cancellation could be adapted to share classical secrets with a $(t,n)$ structure, but the paper does not develop that direction.
- Editorial inference: because the dishonest-reconstructor security step in Sec. IV.B.2.a uses a rotation identity that is not generally valid, the internal-attack claim should be read as conditional on a corrected proof.
- Editorial inference: the new measurement basis could serve other quantum communication tasks that require one party to transfer an angle without preparing a particle, such as remote state preparation.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The manuscript proposes a (t,n) threshold quantum multi-secret sharing protocol. A dealer encrypts m quantum states by single-qubit rotations RX(γ_D^j) and distributes classical Shamir shares of a secret s_D; any t users cooperate so that one designated reconstructor can decrypt all m secrets by using two-qubit cluster states and rotated-basis measurements by the other users. The paper claims this is the first quantum (t,n) threshold multi-secret sharing scheme, claims theoretical security against several external and internal attacks, and reports an IBM Q experiment supporting correctness.
Significance. The protocol design is interesting and the correctness algebra in Sec. IV.A is coherent, with a useful worked (3,4) example and a hardware demonstration. If the security claims were valid, the work would be a meaningful step toward multi-secret threshold quantum sharing. However, the central security analysis is not valid: the internal-attack proof rests on a false operator identity, and the external-attack argument does not establish confidentiality of arbitrary quantum states. Since the paper's contribution is precisely the claimed security guarantee, the current manuscript does not meet the standard for publication.
major comments (3)
- [IV.B.2.a] The proof that a dishonest reconstructor cannot extract the share angles γ_u assumes the operator identity RX(γ_u + (-1)^{m'} δ_u) RZ(δ_u)|+> = RZ(γ_u)|+>. This identity is false; for δ_u = 0 and γ_u = π/2 the left-hand side is proportional to |+> whereas the right-hand side is |+_{π/2}>. This identity is the only step in the argument that would allow the reconstructor to strip δ_u from |Δ>_u and expose γ_u, so the claimed security against internal reconstructor attacks is not established.
- [IV.B.1] The external-attack analysis asserts that an eavesdropper who obtains the encrypted states |Ψ>^j = RX(γ_D^j)|ψ>^j 'cannot steal any useful information' because she does not know the original secret. This is not a valid confidentiality argument: the family {RX(θ)} does not form a quantum one-time pad, and for a secret such as |ψ> = |+> the ciphertext is unchanged up to a global phase for every γ_D, so Eve can recover the secret without touching the decoy particles. The probability calculation (3/4)^{d1+d2} only addresses a specific intercept-resend strategy on decoys and does not bound information leakage from undetected measurements of the data qubits.
- [IV.B.2.b and IV.B.2.c] The internal-attack discussions for dishonest non-reconstructor users and collusions consist of assertions that public information does not reveal shares and that Pt never publishes his share, with no adversary model or information-theoretic argument. In particular, the distribution of the random angles δ_u is never specified, so the claim that σ'_u = γ_u + (-1)^{m'}δ_u hides γ_u cannot be assessed; if δ_u is not uniform and independent per secret, the published angles leak information about the shares. A rigorous security proof must quantify this.
minor comments (5)
- [Throughout] 'Lagrangian interpolation' should be 'Lagrange interpolation', and 'IMB Q' should be 'IBM Q'.
- [Section III] In the participants list, the phrase 'P1, P1, ..., Pn' should read 'P1, P2, ..., Pn'.
- [IV.A] The paragraph discussing Ref. [44] and delayed measurements is tangential to the correctness proof and should be moved or removed.
- [Eqs. (13), (17), (18)] Notation for the angles is inconsistent between γ^j_k and γ_k; the superscript j should be carried consistently.
- [V] The experimental section does not report the number of shots or the noise model used on the IBM Q platform, which is needed for reproducibility.
Circularity Check
No significant circularity; the reconstruction is constructed from standard Lagrange and cluster-state identities, and the security proof's false operator identity is a correctness flaw, not a circular reduction.
full rationale
The paper is a protocol construction rather than an empirical fit. The only equations that make reconstruction work are definitions: Eq. (9) is the standard Lagrange interpolation identity; Eq. (10) follows from f(0)=q-s_D; Eq. (11) defines rotation angles; Eq. (12) is then an algebraic consequence, not a fitted constraint. Eq. (14), RX(sum angles)=I up to global phase, is therefore true by construction. The cluster-state part uses the elementary identity CZ|+>|+> = ... (Eq. (7)/(15)) and the commutation relations (Eq. (8)), all stated as axioms and standard. The claimed new measurement basis is RX(-omega)|0>,|1> and is used to rewrite that identity; this is a design choice, not a renamed result. The only self-citation (Ref. [44]) appears in Sec. IV.A as a side comment comparing correctness proofs; nothing in the reconstruction or security argument is imported from that reference. The glaring problem in Sec. IV.B.2.a is not circularity but an incorrect operator identity: the paper assumes RX(gamma+(-1)^m delta)RZ(delta)|+> = RZ(gamma)|+>, which is false. That invalidates the internal-attack security argument, but it is an unsupported assertion/mathematical error, not a derivation that reduces to its own inputs. Therefore no circularity step can be identified under the required evidentiary standard.
Assumptions & free parameters
assumptions (5)
- standard math Lagrange interpolation over GF(q) yields a secret s_D from t shares, equivalently (s_D + Σ c_l) mod q = 0.
- standard math The cluster-state stabilizer equation K|C> = |C> and the two-qubit identity CZ|+>|+> = (1/√2)(|0_{-ω}>|+_ω> + |1_{-ω}>|-_ω>) hold.
- domain assumption Decoy particles in BB84 states detect an external eavesdropper with probability approaching 1 as the number of decoys grows.
- domain assumption All quantum operations (RX, RZ, CZ, H, measurements) are ideal and noiseless, and classical channels are authenticated.
- ad hoc to paper The internal-attack security proof assumes the identity RX(γ+δ)|+δ> = RZ(γ)|+> for reconstructor attacks.
Cite this review
Pith. "Pith review of Quantum ($t$,$n$) Threshold Multi-Secret Sharing based on Cluster States." pith.science (2026). https://pith.science/paper/HS7GMB27
@misc{pith2026250509317,
author = {Pith},
title = {Pith review of: Quantum ($t$,$n$) Threshold Multi-Secret Sharing based on Cluster States},
year = {2026},
howpublished = {\url{https://pith.science/paper/HS7GMB27}},
note = {Machine review of arXiv:2505.09317}
}
abstract
Quantum secret sharing is an encryption technique based on quantum mechanics, which utilizes uncertainty principle to achieve security in transmission. Most protocols focus on the study of quantum ($n,n$) or ($t,n$) threshold single secret sharing. In this paper, the first quantum ($t,n$) threshold multi-secret sharing protocol based on Lagrangian interpolation and cluster states is proposed, which requires only $t$ instead of $n$ participants to reconstruct multiple quantum secrets. The protocol exploits the security properties of the cluster state to transmit shared information in two parts, quantum and classical, where the shares remain private after reconstructing quantum secrets. Meanwhile, extending the new measurement basis in cluster states enables participants to transmit quantum information without preparing particles. In the presented protocol, the dealer can be offline after sending secrets. And required quantum operations are all common quantum operations, thus the protocol is practical under the current technical conditions. It is proven to be theoretically secure against external and internal attacks by analyzing the protocol under several common external attacks and internal attacks. In addition, experiments on IMB Q prove that the protocol satisfies correctness and feasibility.
Figures
Figures from the paper (3 more)
Reference graph
Works this paper leans on
-
[1]
Here, V is the set of all nodes in graph G, and E is the set of all edges. In graph G, each node represents a qubit in the state |+⟩ = H|0⟩ = 1/ √ 2(|0⟩+ |1⟩), and each edge rep- resents a controlled-Z operation CZ, where operations H and CZ are shown in the following equations, FIG. 1. Graphical representation of the cluster state. H = 1√ 2 [ 1 1 1 −1 ] ...
-
[2]
Internal Attacks In this subsection, we will analyze three types of in- ternal attacks, the reconstructor attacks, the other user attacks and the collusion attacks. Regarding collusion attacks, we will consider two extreme cases where only one participant is honest, only the reconstructor P t is honest and only one non-reconstructor user is honest. a. Rec...
-
[3]
L. Z. Qin, B. Liu, F. Gao, W. Huang, B. J. Xu and Y . Li, Decoy-state quantum private query protocol with two-way communication, Physica A: Statistical Mechanics and its Applications 633, 129427 (2024)
work page 2024
-
[4]
P t publishes the measurement re- sult m j k to the user P k
Then P t measures the first particle of the cluster state in Figure 4 (i.e., the particle denoted as |∆′⟩j k−1) in the basis {|+⟩, |−⟩}. P t publishes the measurement re- sult m j k to the user P k. P k calculates the rotation angle σ j k = (−1)m j k+1δ j k + γ j k based on m j k and publishes it to Pt . P t then performs the operation RX (σ j k )HX m j k ...
-
[5]
Here, number k ranges over the set {2, 3, ...,t − 1}
Next, the secret reconstructor P t entangles |∆′⟩j k−1 and |∆⟩j k into the cluster states |C⟩j k−1,k by performing the op- eration CZk−1,k. Here, number k ranges over the set {2, 3, ...,t − 1}. The secret reconstructor P t measures the first particle of |C⟩j k−1,k in the basis {|+⟩, |−⟩} and publishes the measurement results m j k to the user P k. After ob...
-
[6]
She can first choose to intercept the particles sent by Dealer, i.e., |Ψ⟩j, where j ∈ {1, 2, ...,m}
External Attacks Suppose there is an external eavesdropper Eve who at- tempts to eavesdrop on the quantum secrets. She can first choose to intercept the particles sent by Dealer, i.e., |Ψ⟩j, where j ∈ {1, 2, ...,m}. But due to the decoy particles, Eve’s eavesdropping will introduce errors in the detec- tion. Assuming that the number of decoy particles in X...
-
[7]
C. H. Bennett and B. Gilles, Quantum cryptog- raphy: Public key distribution and coin tossing, Theoretical Computer Science 560, 1 (2014)
work page 2014
-
[8]
N. R. Zhou, G. H. Zeng and J. Xiong, Quantum key agree- ment protocol, Electronics Letters 40, 18 (2004)
work page 2004
Show all 50 references
-
[9]
D. R. Simon, On the power of quantum computation, SIAM Journal on Computing 26, 5 (1997)
1997
-
[10]
A. W. Harrow, A. Hassidim and S. Lloyd, Quan- tum algorithm for linear systems of equations, Physical Review Letters 103, 150502 (2009)
2009
-
[11]
Dealer encrypts quantum secrets {|ψ⟩1, |ψ⟩2} as {|Ψ⟩1 = RX (γ 1 D)|ψ⟩1, |Ψ⟩2 = RX (γ 2 D)|ψ⟩2}, and sends them to the secret reconstructor Charlie
as γ 1 D = 8π/7, γ 1 A = 12π/7, γ 1 B = 4π/7 , γ 1 C = 4π/7 and γ 2 D = 16π/7, γ 2 A = 24π/7, γ 2 B = 8π/7 , γ 2 C = 8π/7. Dealer encrypts quantum secrets {|ψ⟩1, |ψ⟩2} as {|Ψ⟩1 = RX (γ 1 D)|ψ⟩1, |Ψ⟩2 = RX (γ 2 D)|ψ⟩2}, and sends them to the secret reconstructor Charlie. Alice ...
-
[12]
Rebentrost, A
P . Rebentrost, A. Steffens, I. Marvian and S. Lloyd, Quan- tum singular-value decomposition of nonsparse low-rank matrices, Physical Review A 97, 012327 (2018)
2018
-
[13]
Y . Q. Song, Y . S. Wu, S. Y . Wu, D. D. Li, Q. Y . Wen, S. J. Qin and F. Gao, A quantum fed- erated learning framework for classical clients, Science China Physics, Mechanics & Astronomy 67, 250311 (2024)
2024
-
[14]
P . W. Shor, Polynomial-time algorithms for prime factor- ization and discrete logarithms on a quantum computer, SIAM Journal on Computing 26, 5 (1997)
1997
-
[15]
L. K. Grover, A fast quantum me- chanical algorithm for database search, Symposium on the Theory of Computing (1996)
1996
-
[16]
Hillery, V
M. Hillery, V . Bužek and A. Berthiaume, Quantum secret sharing, Physical Review A 59, 1829 (1999)
1999
-
[17]
G. R. Blakley, Safeguarding cryptographic keys, International Workshop on Managing Requirements Knowledg e (1979)
1979
-
[18]
Shamir, How to share a secret, Communications of the ACM 22, 11 (1979)
A. Shamir, How to share a secret, Communications of the ACM 22, 11 (1979)
1979
-
[19]
M. H. Dehkordi and E. Fattahi, Threshold quan- tum secret sharing between multiparty and mul- tiparty using Greenberger–Horne–Zeilinger state, Quantum Information Processing 12 (2013)
2013
-
[20]
H. Qin, X. Zhu and Y . Dai, (t, n) Threshold quan- tum secret sharing using the phase shift operation, Quantum Information Processing 14 (2015)
2015
-
[21]
Sutradhar and H
K. Sutradhar and H. Om, Enhanced (t, n) threshold d-level quantum secret sharing, Scientific Reports 11, 17083 (2021)
2021
-
[22]
Y . Wang, X. P . Lou, Z. Fan, S. Wang and G. Huang, V erifiable multi-dimensional (t, n) thresh- old quantum secret sharing based on quantum walk, International Journal Of Theoretical Physics 61, 24 (2022)
2022
-
[23]
F. Li, T. Chen and S. Zhu, Dynamic (t, n) threshold quantum secret sharing based on d-dimensional Bell state, Physica A: Statistical Mechanics and its Applications 606, 128122 (2022)
2022
-
[24]
Rathi and S
D. Rathi and S. Kumar, A d-level quantum secret sharing scheme with cheat-detection (t, m) threshold, Quantum Information Processing 22, 183 (2023)
2023
-
[25]
F. Guan, J. Guo and L. Li, Two ( w, ω, n) weighted threshold quantum secret sharing schemes on d-level sin- gle quantum systems, Physica Scripta 98, 12 (2023)
2023
-
[26]
S. K. Singh and R. Srikanth, Generalized quantum secret sharing, Physical Review A 71, 012328 (2005)
2005
-
[27]
C. H. Yan, Z. H. Li, L. Liu and D. J. Lu, Cheating iden- tifiable (k, n) threshold quantum secret sharing scheme, Quantum Information Processing 21, 8 (2022)
2022
-
[28]
X. L. Song, Y . B. Liu, H. Y . Deng and Y . G. Xiao, (t, n) threshold d-level quantum secret sharing, Scientific Reports 7, 6366 (2017)
2017
-
[29]
F. L. Li, H. Hu, S. X. Zhu, J. Y . Yan and J. Ding, A verifiable (k, n) thresh- old dynamic quantum secret sharing scheme, Quantum Information Processing 21, 259 (2022)
2022
-
[30]
F. G. Deng, X. H. Li, C. Y . Li, P . Zhou and H. Y . Zhou, Multiparty quantum-state sharing of an arbitrary two-particle state with Einstein-Podolsky-Rosen pairs, Physical Review A 72, 044301 (2005)
2005
-
[31]
L. Xiao, G. H. Long, F. G. Deng and J. W. Pan, Efficient multiparty quantum-secret-sharing schemes, Physical Review A 69, 052307 (2004)
2004
-
[32]
J Zhang and Z
Z. J Zhang and Z. X Man, Multiparty quantum secret shar- ing of classical messages based on entanglement swap- ping, Physical Review A 72, 022303 (2005)
2005
-
[33]
I. C. Y u, F. L. Lin and C. Y . Huang, Quantum se- cret sharing with multilevel mutually (un) biased bases, Physical Review A 78, 012344 (2008)
2008
-
[34]
A. Keet, B. Fortescue and D. Markham, Quan- tum secret sharing with qudit graph states, Physical Review A 82, 062315 (2010)
2010
-
[35]
Tavakoli, I
A. Tavakoli, I. Herbauts, M. ˙Zukowski and M. Bouren- nane, Secret sharing with a single d-level quantum sys- tem, Physical Review A 92, 030302 (2015)
2015
-
[36]
Pinnell, I
J. Pinnell, I. Nape, M. Oliveira, N. TabeBordbar and A. Forbes et al, Experimental demonstration of 11-dimensional 10-party quantum secret sharing, Laser & Photonics Reviews 14, 9 (2020)
2020
-
[37]
X. Yi, C. Cao, L. Fan and R. Zhang, Quan- tum secure multi-party summation protocol based on blind matrix and quantum Fourier transform, Quantum Information Processing 20, 249 (2021)
2021
-
[38]
C. M. Bai, S. Zhang and L. Liu, V erifiable quantum secret sharing scheme using d-dimensional GHZ state, International Journal of Theoretical Physics 60, 3993-4005 (2021)
2021
-
[39]
Mashhadi, V erifiable quantum secret sharing with multi access structures, Optik 270, 169896 (2022)
S. Mashhadi, V erifiable quantum secret sharing with multi access structures, Optik 270, 169896 (2022) . 9
2022
-
[40]
S. Ma, J. Jiang and X. Yan, Hierarchical quantum infor- mation splitting of an arbitrary m-qudit state with multi- party, Quantum Information Processing 22, 263 (2023)
2023
-
[41]
Blundo, A
C. Blundo, A. D. Santis, G. D. Crescenzo, A. G. Gaggia and U. V accaro, Multi-secret sharing schemes, Advances in Cryptology - CRYPTO (1994)
1994
-
[42]
H. Y . Chien, J. K. Jan and Y . M. Tseng, A practical (t, n) multi-secret sharing scheme, IEICE Transactions on Fundamentals of Electronics, Commun ications and Computer Sciences 83, 12 (2000)
2000
-
[43]
C. C. Yang, T. Y . Chang and M. S. Hwang, A (t, n) multi-secret sharing scheme, Applied Mathematics and Computation 151, 2 (2004)
2004
-
[44]
J. Zhao, J. Zhang and R. Zhao, A prac- tical verifiable multi-secret sharing scheme, Computer Standards & Interfaces 29, 1 (2007)
2007
-
[45]
M. H. Dehkordi and S. Mashhadi, An effi- cient threshold verifiable multi-secret sharing, Computer Standards & Interfaces 30, 3 (2008)
2008
-
[46]
R. L. Rivest, A. Shamir and L. Adleman L, A method for obtaining digital signatures and public-key cryptosys - tems, Communications of the ACM 21, 2 (1978)
1978
-
[47]
H. J. Briegel and R. Raussendorf, Persistent en- tanglement in arrays of interacting particles, Physical Review Letters 86, 910 (2001)
2001
-
[48]
Raussendorf and H
R. Raussendorf and H. J. Briegel, A one-way quantum computer, Physical Review Letters 86, 5188 (2001)
2001
-
[49]
M. A. Nielsen, Cluster-state quantum computation, arXiv preprint quant-ph/0504097 (2005)
2005 arXiv
-
[50]
R. H. Ma, F. Gao, B. B. Cai and S. Lin, Quantum Secret Reconstruction, Advanced Quantum Technologies 7, 2 (2024) . 10 TABLE I. Concrete process of the example Concrete process of the example Quantum state of system 1 Quantum state of system 2 Alice, Bob and Charlie cooperate t...
2024
Reviewed August 15, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.