Pith. sign in

REVIEW 4 major objections 5 minor 46 references

Increasing the secret key rates and point-to-multipoint extension for experimental coherent-one-way quantum key distribution protocol

T0 review · 4 major / 5 minor · reviewed 2026-08-03 · deepseek-v4-flash

Pith's one-line read Two detectors on the receiver's data line raise coherent-one-way QKD secret-key rates by up to 80 percent and allow a single transmitter to serve two receivers via one-time-pad key combining.

desk verdict Real experimental rate gains from dual detectors on COW's data line, but the multi-user security part is built on a wrong secret-fraction formula. read the letter →

arxiv 2601.04543 v2 pith:ONSZIITY submitted 2026-01-08 quant-ph physics.optics

classification quant-phphysics.optics
keywords quantumkeydistributioncoherent-one-wayprotocoltime-binencodingsingle-photondetectorsdetectordeadtimepoint-to-multipointQKDcollectivebeam-splittingattackone-timepad
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper is trying to show that the detector dead-time bottleneck that limits coherent-one-way quantum key distribution can be loosened with a passive hardware change: split the receiver's data line into two single-photon detectors and merge their time-bin information. In experiments at 80, 100, and 120 km, this raises secure key rates by 80%, 60%, and 50% while keeping the error rate near the 5% detection threshold at low dead times. It then asks whether the same transmitter can serve two receivers at once and demonstrates a three-user version in which the two Bobs combine their separate keys through a one-time-pad XOR step. A numerical security analysis under a collective beam-splitting attack suggests that lower source intensity (µ=0.2) gives better long-distance secure rates than µ=0.5 in the two-receiver case. The methods are presented as general to time-bin QKD, not just to this one implementation.

What carries the argument

The workhorse is the time-bin information of two detectors on the data line: a 50:50 fiber splitter feeds two single-photon detectors whose detection times are merged, effectively relaxing the dead-time bottleneck. For multi-user sharing, key combining is done by XOR: Alice broadcasts k_A1 ⊕ k_A2, letting each Bob recover the other's key from his private key. The security analysis uses the collective beam-splitting attack, where Eve splits off a fraction of the signal and her accessible information is bounded by the binary-entropy expression h((1−e^{−µt_E})/2); the paper doubles this bound for the two-receiver case to model coherent access to both channels.

What would settle it

Evaluate the paper's Eq. (6) at zero channel loss and no eavesdropper (χ_E=0); the predicted secure key rate is zero, which is contradicted by any measured key. A corrected security expression should instead reproduce a positive rate at low loss.

Watch

Extended reading notes

Core claim

The paper's central experimental result is that placing two single-photon detectors behind a 50:50 splitter on Bob's data line—rather than one detector—raises both the sifted and secure key rates of coherent-one-way QKD by roughly 80% at 80 km, 60% at 100 km, and 50% at 120 km, while keeping QBER at or near the 5% threshold at low detector dead times. It then extends the protocol to three users: Alice sends the same modulated signal through two channels to two receivers, establishes separate keys with each, and publishes their XOR so both Bobs can derive a common key. Under a collective beam-splitting attack model, the paper argues that with two receivers a lower mean photon number (µ=0.2) g

Load-bearing premise

The whole two-receiver security analysis rests on a rate formula that yields zero secure key when no eavesdropper is present, so the hardware results stand but the security-bound derivation is the fragile link.

Editorial extensions

If this is right

  • At 80 to 120 km, switching from one to two detectors on the data line raises secure key rates by 50–80 percent at low dead times, with QBER staying near or below five percent.
  • A three-party COW network can be built by giving Alice a 50:50 splitter and having the two receivers combine their keys via one-time-pad XOR; the measured rates at 100 km are about 1.8 kbps per receiver at µ=0.5.
  • For point-to-multipoint operation, lower source intensity (µ=0.2) appears safer over long distances under a collective beam-splitting attack, trading short-distance rate for longer reach.
  • The receiver-side detector change is protocol-agnostic: it applies to other time-bin QKD implementations, including the 50:50 passive-basis-choice variant.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • A direct extension the paper does not test: adding more than two detectors behind a cascade of 50:50 splitters should push the dead-time bottleneck further, with each extra detector adding less because splitting also reduces per-detector photon flux.
  • Because the security model deliberately doubles Eve's information for the two-receiver case, real deployments with independent, imperfect channels would likely sit between the single- and dual-Bob curves; the paper's curves are a conservative envelope rather than a precise prediction.
  • The XOR key-combining step makes the three-party scheme a natural building block for a network; if chained segments work as advertised, the final key rate would scale with the longest segment rather than total network distance.
  • The numerical security-rate formula yields zero when the eavesdropper is absent, so the point-to-multipoint rate curves should be read as preliminary until that expression is corrected.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

4 major / 5 minor

Summary. The paper reports an experimental study of the coherent-one-way (COW) QKD protocol, focusing on two hardware/post-processing modifications. First, it replaces the single single-photon detector on Bob's data line by two detectors behind a 50:50 beam splitter and combines their time-bin information; experiments at 80, 100, and 120 km show increased sifted and secure key rates with a modest QBER increase. Second, it extends the protocol to point-to-multipoint operation by splitting Alice's signal to two receivers, combining the two pairwise keys with an XOR operation, and claims improved aggregate secret-key rates. The paper also derives purported secure-key-rate bounds under a collective beam-splitting attack, concluding that a lower mean photon number (µ=0.2) gives better long-distance rates than µ=0.5 for the dual-receiver configuration.

Significance. If the experimental and security claims were correct, the dual-detector receiver would be a simple, broadly applicable way to mitigate detector dead-time bottlenecks, and the point-to-multipoint extension would be a valuable step toward multi-user COW networks. The raw experimental data for the dual-detector rate increase are directly measured and the dead-time model is plausible. However, the central security analysis is invalid as written: the secret-fraction formula in Eq. (6) is not a Devetak–Winter rate, the doubling of Eve's Holevo information in Eq. (7) is unsupported and generally impossible, and the proposed three-party key-agreement step publicly transmits the purported final key. Since the paper's main quantitative conclusions—including the µ=0.2 optimisation and the 'security margins' in Fig. 9—rest on these unsupported formulas, the significance of the theoretical contribution is currently not established.

major comments (4)
  1. [Sec. 2.2.1, Eq. (6)] The secret-fraction expression is malformed. Eq. (6) sets r_B = (1/2)(1−e^{−µt_Bη}) h(1−χ_E^COW). Since binary entropy is symmetric, h(1−x)=h(x), the rate vanishes both at χ_E=0 (no eavesdropper) and at χ_E=1, and peaks at intermediate χ_E. No legitimate secret-key rate behaves this way. The correct asymptotic Devetak–Winter expression for a binary key with bit-error rate Q and Eve's Holevo information χ is 1 − h(Q) − χ (or 1 − χ when Q=0). Thus the numerical curves in Fig. 9, including the claim that µ=0.2 outperforms µ=0.5 for the dual-Bob case, are not reliable secure-key-rate bounds. The text even refers to a 'factor [1−χ_E^COW]' that is not what Eq. (6) contains.
  2. [Sec. 2.2.1, Eq. (7)] The two-receiver bound χ_E^COW = 2χ_BE is asserted without derivation and is not generally valid. For a single transmitted bit, Eve's Holevo information about that bit cannot exceed 1 bit, even if she accesses correlations between two copies of the same signal; 2χ_BE can exceed 1 when χ_BE > 0.5, making h(1−χ_E^COW) undefined. A proper treatment must derive the joint state available to Eve in the two-channel broadcast and compute its Holevo quantity. The claimed 'conservative' doubling is therefore not a valid upper bound.
  3. [Sec. 2.2, OTP key combination] The three-party key agreement step is logically flawed. Alice publicly sends k_A12 = k_A1 ⊕ k_A2 to both Bobs. Bob 1 can then recover k_A2 and Bob 2 can recover k_A1, but k_A12 itself has been transmitted in the clear. It cannot serve as a secret key among Alice, Bob 1, and Bob 2, since an eavesdropper who observes the classical channel also obtains k_A12. The text calls this 'OTP encrypted', but no secret key is used to encrypt k_A12. The final key k_A12 is therefore public. This undermines the entire point-to-multipoint key-distribution claim.
  4. [Figs. 4–6, Table 1] The experimental rate increases are reported without error bars, confidence intervals, or repeat measurements. Given that the claimed improvements are 50–80%, the central experimental conclusion requires at least an estimate of statistical or systematic uncertainty. This is especially important because the dual-detector QBER approaches the 5% threshold at several settings, and the improvement is not uniform across all reported conditions.
minor comments (5)
  1. [Table 1] The percentage increases stated in the text (80%, 60%, 50% for L=80,100,120) do not match the table: for η=0.15 they are approximately 76%, 64%, 40%, and for η=0.20 they are 79%, 61%, 50%. Please report the exact computed percentages.
  2. [Sec. 2.2.2] The network-extension text refers to 'Fig. 9' when describing the N=5 network in Fig. 10. Also, the rate claim about dependence only on the longest nearest-neighbor distance is not derived; if it is a known result, a citation and precise statement are needed.
  3. [Sec. 2.2, notation] The sentence 'If |k_A1|,|k_A2|, then ||k_A1|−|k_A2|| bits...' is garbled; rewrite to clearly describe key-length equalization.
  4. [Sec. 2.2.1, Eq. (6)] h(x) is defined only for x∈[0,1]; with the unsupported Eq. (7), h(1−χ_E^COW) can be evaluated outside this domain. Please add the domain restriction or avoid the doubling assumption.
  5. [Sec. 2.1] The statement 'the monitoring line will remain unperturbed due to our modifications' is physically plausible, but the security analysis should state explicitly that omitting the monitoring line removes a parameter-estimation channel and discuss what attack constraints are lost.

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity: experimental rates are measured and security bounds are imported from external literature or explicit conservative assumptions.

full rationale

The central experimental claims (Sec. 2.1, Figs. 4-6, Table 1; Sec. 2.2, Fig. 8) are direct measurements of counts, sifted key rates, and QBER, compared against a theoretical count model (Eqs. (2)-(3)) whose parameters are independent experimental values; no fitted parameter is renamed as a prediction. The security analysis in Sec. 2.2.1 takes the beam-splitting attack and Eq. (5) from the external references [30] and [34], not from the authors' own work. Eq. (7) is explicitly introduced as a conservative assumption ('we therefore impose'), and the resulting comparison of µ=0.2 versus µ=0.5 is a conditional model output, not a circular derivation. The only self-citations, [44] and [45], appear in the conclusion as related-work remarks and are not load-bearing. The conclusion also explicitly limits the security claims by saying theoretical bounds must be re-evaluated against zero-error and other coherent attacks, which is a stated limitation, not a circular step. The suspicious h(1−χ_E) expression in Eq. (6) and the doubling in Eq. (7) are mathematical-validity concerns, not instances of a claim reducing to its own inputs, so they do not raise the circularity score.

Assumptions & free parameters 5 free parameters · 7 assumptions · 0 invented entities

The experimental rate gains depend mostly on the dead-time model and hardware parameters. The multi-user security claims rest on two unproven ad hoc assumptions: the doubled Holevo bound and the h(1−χ) formula, the latter being internally inconsistent. No new physical entities are introduced.

free parameters (5)
  • mean photon number µ = 0.5 and 0.2
    Source intensity chosen for the measurements; no optimization procedure is given. The dual-Bob recommendation µ=0.2 over µ=0.5 is based on this choice.
  • detector quantum efficiency η = 0.15 and 0.20
    SPD efficiency settings; swept in the dual-detector experiment and fixed at 0.2 in the multi-user experiment.
  • detector dead time t_d = 15–100 µs (swept)
    Detector parameter used in Eq. (3) and varied across figures; values are hardware settings, not fitted.
  • disclosure rate DR and compression ratio CR = DR=10%, CR=90%
    Chosen post-processing parameters that set the final secure key rates in Table 1; other values would change the quoted 50–80% gains.
  • fiber attenuation α_d = 0.22 dB/km
    Standard telecom fiber loss used to map spool+attenuator loss to L=80–120 km.
assumptions (7)
  • domain assumption Detector count rate follows C_th = C_0/(1+t_d C_0) (Eq. 3)
    Standard dead-time model; used to predict single and dual detector counts.
  • domain assumption Beam-splitting attack bounds from Branciard et al. [30] apply to COW and yield χ_AE = h((1−γ_E)/2)
    External security model; the paper does not re-derive it for its exact states.
  • ad hoc to paper In the two-receiver setup, Eve's Holevo information is exactly 2χ_BE (Eq. 7)
    Asserted as conservative without deriving the joint state for the identical-signal broadcast; if correlations give Eve more (or non-additive) information, the bound changes.
  • ad hoc to paper The secure fraction is h(1−χ_E) in Eq. (6)
    As written this vanishes for χ_E=0, so the formula is internally inconsistent; a correct Devetak-Winter expression would involve 1−χ_E−h(Q) or similar.
  • ad hoc to paper The monitoring line can be omitted because the dual-detector modification leaves it unperturbed
    No visibility/coherence monitoring is performed in the experiment, yet security is claimed against attacks that are undetectable by QBER alone.
  • ad hoc to paper Final key k_A12 = k_A1⊕k_A2 is secure via OTP
    OTP is secure only if the two padded keys are independent and secret; here both derive from the same optical signal, so Eve attacking both channels may learn correlations.
  • domain assumption Network key rate depends only on the longest nearest-neighbor distance (Sec. 2.2.2)
    Taken from [35]; no proof is given for concatenating segments with XOR.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Increasing the secret key rates and point-to-multipoint extension for experimental coherent-one-way quantum key distribution protocol." pith.science (2026). https://pith.science/paper/ONSZIITY

@misc{pith2026260104543,
  author       = {Pith},
  title        = {Pith review of: Increasing the secret key rates and point-to-multipoint extension for experimental coherent-one-way quantum key distribution protocol},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/ONSZIITY}},
  note         = {Machine review of arXiv:2601.04543}
}
read the original abstract

Using quantum key distribution (QKD) protocols, a secret key is created between two distant users (transmitter and receiver) at a particular key rate. Quantum technology can facilitate secure communication for cryptographic applications, combining QKD with one-time-pad (OTP) encryption. In order to ensure the continuous operation of QKD in real-world networks, efforts have been concentrated on optimizing the use of experimental components and effective QKD protocols to improve secret key rates and increase the transmission between multiple users. Generally, in experimental implementations, the secret key rates are limited by single-photon detectors, which are used at the receivers of QKD and create a bottleneck due to their limited detection rates (detectors with low detection efficiency and high detector dead-time). We experimentally show that secret key rates can be increased by combining the time-bin information of two such detectors on the data line of the receiver for the coherent-one-way (COW) QKD protocol with a minimal increase in quantum bit error rate (QBER, the proportion of erroneous bits). Further, we implement a point-to-multipoint COW QKD protocol, introducing an additional receiver module. The three users (one transmitter and two receivers) share the secret key in post-processing, relying on OTP encryption. Typically, the dual-receiver extension can improve the combined secret key rates of the system; however, one has to optimise the experimental parameters to achieve this within security margins. These methods are general and can be applied to any implementation of the COW protocol.

Figures

Figures reproduced from arXiv: 2601.04543 by the authors.

Figure 1
Figure 1. Experimental architecture of COW QKD. Furthermore, we are interested in a simple experimental implementation to show how the protocol can be extended to three users by concurrently sharing the key between Alice and the dual Bob modules (Bob 1 and Bob 2, similar to a point-to-multipoint QKD [25, 26]). From an information-theoretic standpoint, fundamental upper limits on multi-user key rates have been established. TGW… view at source ↗
Figure 2
Figure 2. COW QKD: Alice module. (MBC-DG-BOARD-A1) as feedback to IM through a 99:1 fiber beam splitter (FBS) for tuning the bias and stabilizing the operating point of IM. Further, these pulses are attenuated by α (dB) by a set of variable optical attenuators (VOA1 and VOA2) to generate weak coherent pulses with a photon number µ. The average power of these pulses is given by Pf = µFhc/λ (measured in watts, W) where h is Pla… view at source ↗
Figure 3
Figure 3. COW QKD: Bob module. 3 [PITH_FULL_IMAGE:figures/full_fig_p003_3.png] view at source ↗
Figures from the paper (7 more)
Figure 4
Figure 4. Figure 4: Comparing the key rates with single detector and dual detectors on the data line for distance [PITH_FULL_IMAGE:figures/full_fig_p005_4.png]
Figure 5
Figure 5. Figure 5: Comparing the key rates with single detector and dual detectors on the data line for distance [PITH_FULL_IMAGE:figures/full_fig_p006_5.png]
Figure 6
Figure 6. Figure 6: Comparing the key rates with single detector and dual detectors on the data line for distance [PITH_FULL_IMAGE:figures/full_fig_p006_6.png]
Figure 7
Figure 7. Figure 7: Concurrent COW QKD: Alice module and dual Bob modules [PITH_FULL_IMAGE:figures/full_fig_p007_7.png]
Figure 8
Figure 8. Figure 8: Comparing the key rates and QBER for Bob 1 module and Bob 2 module for distance [PITH_FULL_IMAGE:figures/full_fig_p008_8.png]
Figure 9
Figure 9. Figure 9: Secure key rates per pulse as a function of distance [PITH_FULL_IMAGE:figures/full_fig_p010_9.png]
Figure 10
Figure 10. Figure 10: A simple network having N = 5 parties and n = 2 concurrent COW implementation between {1, 2, 3} and {3, 4, 5}. Vertices 2 and 4 act as Alice, with 1, 3 being Bob 1 and 3, 5 being Bob 2. The key rate depends only on the longest nearest￾neighbor distance, in this exampl…

Discussion (0). Sign in to comment.

Reference graph

Works this paper leans on

46 extracted references · 2 linked inside Pith

  1. [1]

    Quantum cryptography,

    N. Gisin, G. Ribordy, W. Tittel, and H. Zbinden, “Quantum cryptography,”Rev. Mod. Phys., vol. 74, pp. 145–195, Mar 2002

  2. [2]

    The security of practical quantum key distribution,

    V . Scarani, H. Bechmann-Pasquinucci, N. J. Cerf, M. Dušek, N. Lütkenhaus, and M. Peev, “The security of practical quantum key distribution,”Rev. Mod. Phys., vol. 81, pp. 1301–1350, Sep 2009

  3. [3]

    Secure quantum key distribution,

    H.-K. Lo, M. Curty, and K. Tamaki, “Secure quantum key distribution,”Nature Photonics, vol. 8, pp. 595–604, Aug 2014

  4. [4]

    Secure quantum key distribution with realistic devices,

    F. Xu, X. Ma, Q. Zhang, H.-K. Lo, and J.-W. Pan, “Secure quantum key distribution with realistic devices,”Rev. Mod. Phys., vol. 92, p. 025002, May 2020

  5. [5]

    Advances in quantum cryptography,

    S. Pirandola, U. L. Andersen, L. Banchi, M. Berta, D. Bunandar, R. Colbeck, D. Englund, T. Gehring, C. Lupo, C. Ottaviani, J. L. Pereira, M. Razavi, J. S. Shaari, M. Tomamichel, V . C. Usenko, G. Val- lone, P. Villoresi, and P. Wallden, “Advances in quantum cryptography,”Adv. Opt. Photon., vol. 12, pp. 1012–1236, Dec 2020

  6. [6]

    Security in quantum cryptography,

    C. Portmann and R. Renner, “Security in quantum cryptography,”Rev. Mod. Phys., vol. 94, p. 025008, Jun 2022. 11

  7. [7]

    Fast and simple one-way quantum key distribution,

    D. Stucki, N. Brunner, N. Gisin, V . Scarani, and H. Zbinden, “Fast and simple one-way quantum key distribution,”Applied Physics Letters, vol. 87, p. 194108, 11 2005

  8. [8]

    Continuous high speed coherent one-way quantum key distribution,

    D. Stucki, C. Barreiro, S. Fasel, J.-D. Gautier, O. Gay, N. Gisin, R. Thew, Y . Thoma, P. Trinkler, F. Vannel, and H. Zbinden, “Continuous high speed coherent one-way quantum key distribution,” Opt. Express, vol. 17, pp. 13326–13334, Aug 2009

Show all 46 references
  1. [9]

    Quantum cryptography: Public key distribution and coin tossing,

    C. H. Bennett and G. Brassard, “Quantum cryptography: Public key distribution and coin tossing,” Theoretical Computer Science, vol. 560, pp. 7–11, 2014. Theoretical Aspects of Quantum Cryptog- raphy – celebrating 30 years of BB84

  2. [10]

    High rate, long-distance quantum key distribution over 250 km of ultra low loss fibres,

    D. Stucki, N. Walenta, F. Vannel, R. T. Thew, N. Gisin, H. Zbinden, S. Gray, C. R. Towery, and S. Ten, “High rate, long-distance quantum key distribution over 250 km of ultra low loss fibres,”New Journal of Physics, vol. 11, p. 075003, jul 2009

  3. [11]

    Provably secure and practical quantum key distribution over 307 km of optical fibre,

    B. Korzh, C. C. W. Lim, R. Houlmann, N. Gisin, M. J. Li, D. Nolan, B. Sanguinetti, R. Thew, and H. Zbinden, “Provably secure and practical quantum key distribution over 307 km of optical fibre,” Nature Photonics, vol. 9, pp. 163–168, Mar 2015

  4. [12]

    Implementation of coherent one way protocol for quantum key distribution up to an effective distance of 145 km,

    P. Malpani, S. Kumar, and A. Pathak, “Implementation of coherent one way protocol for quantum key distribution up to an effective distance of 145 km,”Optical and Quantum Electronics, vol. 56, p. 1369, Jul 2024

  5. [13]

    A fast and versatile quantum key distribution system with hardware key distillation and wavelength multiplexing,

    N. Walenta, A. Burg, D. Caselunghe, J. Constantin, N. Gisin, O. Guinnard, R. Houlmann, P. Junod, B. Korzh, N. Kulesza, M. Legré, C. W. Lim, T. Lunghi, L. Monat, C. Portmann, M. Soucarros, R. T. Thew, P. Trinkler, G. Trolliet, F. Vannel, and H. Zbinden, “A fast and versatile qu...

  6. [14]

    Chip-based quantum key distribution,

    P. Sibson, C. Erven, M. Godfrey, S. Miki, T. Yamashita, M. Fujiwara, M. Sasaki, H. Terai, M. G. Tanner, C. M. Natarajan, R. H. Hadfield, J. L. O’Brien, and M. G. Thompson, “Chip-based quantum key distribution,”Nature Communications, vol. 8, p. 13984, Feb 2017

  7. [15]

    Integrated silicon photonics for high-speed quantum key distribution,

    P. Sibson, J. E. Kennard, S. Stanisic, C. Erven, J. L. O’Brien, and M. G. Thompson, “Integrated silicon photonics for high-speed quantum key distribution,”Optica, vol. 4, pp. 172–177, Feb 2017

  8. [16]

    Modulator- free coherent-one-way quantum key distribution,

    G. L. Roberts, M. Lucamarini, J. F. Dynes, S. J. Savory, Z. L. Yuan, and A. J. Shields, “Modulator- free coherent-one-way quantum key distribution,”Laser&Photonics Reviews, vol. 11, no. 4, p. 1700067, 2017

  9. [17]

    Pass-block architecture for distributed-phase- reference quantum key distribution using silicon photonics,

    J. Dai, L. Zhang, X. Fu, X. Zheng, and L. Yang, “Pass-block architecture for distributed-phase- reference quantum key distribution using silicon photonics,”Opt. Lett., vol. 45, pp. 2014–2017, Apr 2020

  10. [18]

    Upper security bounds for coherent-one-way quantum key distribution,

    J. González-Payo, R. Trényi, W. Wang, and M. Curty, “Upper security bounds for coherent-one-way quantum key distribution,”Phys. Rev. Lett., vol. 125, p. 260510, Dec 2020

  11. [19]

    Zero-error attack against coherent-one-way quantum key distribution,

    R. Trényi and M. Curty, “Zero-error attack against coherent-one-way quantum key distribution,”New Journal of Physics, vol. 23, p. 093005, sep 2021

  12. [20]

    Hacking coherent-one-way quantum key distribution with present-day technology,

    J. Rey-Domínguez, Álvaro Navarrete, P. van Loock, and M. Curty, “Hacking coherent-one-way quantum key distribution with present-day technology,”Quantum Science and Technology, vol. 9, p. 035044, jun 2024. 12

  13. [21]

    Improved coherent one-way quantum key distribution for high-loss channels,

    E. Lavie and C. C.-W. Lim, “Improved coherent one-way quantum key distribution for high-loss channels,”Phys. Rev. Appl., vol. 18, p. 064053, Dec 2022

  14. [22]

    Simple security proof of coherent-one-way quantum key distribution,

    R.-Q. Gao, Y .-M. Xie, J. Gu, W.-B. Liu, C.-X. Weng, B.-H. Li, H.-L. Yin, and Z.-B. Chen, “Simple security proof of coherent-one-way quantum key distribution,”Opt. Express, vol. 30, pp. 23783– 23795, Jun 2022

  15. [23]

    Finite-key analysis for coherent one- way quantum key distribution,

    M.-Y . Li, X.-Y . Cao, Y .-M. Xie, H.-L. Yin, and Z.-B. Chen, “Finite-key analysis for coherent one- way quantum key distribution,”Phys. Rev. Res., vol. 6, p. 013022, Jan 2024

  16. [24]

    Experimental implementation of enhanced security coherent one-way quantum key distribution,

    A. Dadahhani, S. Hajibaba, H. Asgari, M. Khodabandeh, F. Rezazadeh, A. Mani, and S. A. Madani, “Experimental implementation of enhanced security coherent one-way quantum key distribution,” IEEE Access, vol. 13, pp. 66752–66760, 2025

  17. [25]

    Quantum cryptography on multiuser optical fibre networks,

    P. D. Townsend, “Quantum cryptography on multiuser optical fibre networks,”Nature, vol. 385, pp. 47–49, Jan 1997

  18. [26]

    A quantum access network,

    B. Fröhlich, J. F. Dynes, M. Lucamarini, A. W. Sharpe, Z. Yuan, and A. J. Shields, “A quantum access network,”Nature, vol. 501, pp. 69–72, Sep 2013

  19. [27]

    Fundamental rate-loss tradeofffor optical quantum key distribution,

    M. Takeoka, S. Guha, and M. M. Wilde, “Fundamental rate-loss tradeofffor optical quantum key distribution,”Nature Communications, vol. 5, p. 5235, Oct 2014

  20. [28]

    Unconstrained capacities of quantum key dis- tribution and entanglement distillation for pure-loss bosonic broadcast channels,

    M. Takeoka, K. P. Seshadreesan, and M. M. Wilde, “Unconstrained capacities of quantum key dis- tribution and entanglement distillation for pure-loss bosonic broadcast channels,”Phys. Rev. Lett., vol. 119, p. 150501, Oct 2017

  21. [29]

    Bounds on entanglement distillation and secret key agreement for quantum broadcast channels,

    K. P. Seshadreesan, M. Takeoka, and M. M. Wilde, “Bounds on entanglement distillation and secret key agreement for quantum broadcast channels,”IEEE Transactions on Information Theory, vol. 62, no. 5, pp. 2849–2866, 2016

  22. [30]

    Upper bounds for the security of two distributed-phase reference protocols of quantum cryptography,

    C. Branciard, N. Gisin, and V . Scarani, “Upper bounds for the security of two distributed-phase reference protocols of quantum cryptography,”New Journal of Physics, vol. 10, p. 013031, jan 2008

  23. [31]

    Two-dimensional distributed-phase-reference protocol for quantum key distribution,

    D. Bacco, J. B. Christensen, M. A. U. Castaneda, Y . Ding, S. Forchhammer, K. Rottwitt, and L. K. Oxenløwe, “Two-dimensional distributed-phase-reference protocol for quantum key distribution,” Scientific Reports, vol. 6, p. 36756, Dec 2016

  24. [32]

    Quantum soft filtering for the improved security analysis of the coherent one-way quantum-key-distribution protocol,

    D. A. Kronberg, A. S. Nikolaeva, Y . V . Kurochkin, and A. K. Fedorov, “Quantum soft filtering for the improved security analysis of the coherent one-way quantum-key-distribution protocol,”Phys. Rev. A, vol. 101, p. 032334, Mar 2020

  25. [33]

    High-rate point-to-multipoint quantum key distribution using coherent states,

    Y . Bian, Y .-C. Zhang, C. Zhou, S. Yu, Z. Li, and H. Guo, “High-rate point-to-multipoint quantum key distribution using coherent states,”arXiv2302.02391, 2023

  26. [34]

    Distillation of secret key and entanglement from quantum states,

    I. Devetak and A. Winter, “Distillation of secret key and entanglement from quantum states,” Proceedings of the Royal Society A: Mathematical, Physical and Engineering Sciences, vol. 461, no. 2053, pp. 207–235, 2005

  27. [35]

    Phase- matching quantum cryptographic conferencing,

    S. Zhao, P. Zeng, W.-F. Cao, X.-Y . Xu, Y .-Z. Zhen, X. Ma, L. Li, N.-L. Liu, and K. Chen, “Phase- matching quantum cryptographic conferencing,”Phys. Rev. Appl., vol. 14, p. 024010, Aug 2020

  28. [36]

    Time-encoded photonic quantum states: Genera- tion, processing, and applications,

    H. Yu, A. O. Govorov, H.-Z. Song, and Z. Wang, “Time-encoded photonic quantum states: Genera- tion, processing, and applications,”Applied Physics Reviews, vol. 11, p. 041318, 11 2024. 13

  29. [37]

    Progress in integrated and fiber optics for time-bin based quantum information processing,

    N. Montaut, A. George, M. Monika, F. Nosrati, H. Yu, S. Sciara, B. Crockett, U. Peschel, Z. Wang, R. Lo Franco,et al., “Progress in integrated and fiber optics for time-bin based quantum information processing,”Advanced Optical Technologies, vol. 14, p. 1560084, 2025

  30. [38]

    Photonic quantum information with time-bins: Principles and applications,

    A. Singh, A. Sethia, L. Esmaeilifar, R. Valivarthi, N. Sinclair, M. Spiropulu, and D. Oblak, “Photonic quantum information with time-bins: Principles and applications,”arXiv 2507.08102, 2025

  31. [39]

    Energy-time and time-bin entanglement: past, present and future,

    G. B. Xavier, J.-Å. Larsson, P. Villoresi, G. Vallone, and A. Cabello, “Energy-time and time-bin entanglement: past, present and future,”npj Quantum Information, vol. 11, no. 1, p. 129, 2025

  32. [40]

    High-dimensional coherent one-way quantum key distribution,

    K. Sulimany, G. Pelc, R. Dudkiewicz, S. Korenblit, H. S. Eisenberg, Y . Bromberg, and M. Ben-Or, “High-dimensional coherent one-way quantum key distribution,”npj Quantum Information, vol. 11, p. 16, 2025

  33. [41]

    The influence of an eavesdropper in point-to-multipoint QKD based on passive beam splitters on the photon number yields,

    M. R. D. Stephan, F. Klingmann, R. Kirrbach, and A. Noack, “The influence of an eavesdropper in point-to-multipoint QKD based on passive beam splitters on the photon number yields,” inQuantum Communications and Quantum Imaging XXII(K. S. Deacon and R. E. Meyers, eds.), vol. 13...

  34. [42]

    Coherent one-way quantum conference key agreement based on twin field,

    X.-Y . Cao, J. Gu, Y .-S. Lu, H.-L. Yin, and Z.-B. Chen, “Coherent one-way quantum conference key agreement based on twin field,”New Journal of Physics, vol. 23, no. 4, p. 043002, 2021

  35. [43]

    Overcoming the rate–distance limit of quantum key distribution without quantum repeaters,

    M. Lucamarini, Z. L. Yuan, J. F. Dynes, and A. J. Shields, “Overcoming the rate–distance limit of quantum key distribution without quantum repeaters,”Nature, vol. 557, pp. 400–403, May 2018

  36. [44]

    Twin-field-based multi-party quantum key agreement,

    V . Abhignan and R. Srikanth, “Twin-field-based multi-party quantum key agreement,”J. Opt. Soc. Am. B, vol. 42, pp. 267–279, Feb 2025

  37. [45]

    Simulations of distributed- phase-reference quantum key distribution protocols,

    V . Abhignan, A. Jamunkar, G. Nair, M. Mittal, and M. Shrivastava, “Simulations of distributed- phase-reference quantum key distribution protocols,”Physica Scripta, vol. 99, p. 105131, sep 2024

  38. [46]

    Backflash attack on coherent one-way quantum key distribution,

    A. K. Singh, N. Sharma, V . P. Singh, and A. Prabhakar, “Backflash attack on coherent one-way quantum key distribution,”IEEE Photonics Journal, 2025. 14

Pith tools

Reviewed August 3, 2026 · model on record in the stance chip above.