Pith. sign in

REVIEW 2 major objections 5 minor 102 references

Semi-device-independent quantum keys stay secure when you bound not only what Eve can identify about Alice’s states, but also what she can rule out.

Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →

T0 review · grok-4.5

2026-07-10 23:29 UTC pith:LE5VZNYF

load-bearing objection Solid SDI-QKD paper: exact classical frontiers plus exclusion-assisted bounds that actually push key rates to near-zero visibility, with validated SDP certificates. the 2 major comments →

arxiv 2607.06682 v1 pith:LE5VZNYF submitted 2026-07-07 quant-ph

Semi-Device-Independent Quantum Key Distribution from Operational Assumptions

classification quant-ph PACS 03.67.Dd03.67.Hk03.65.Ud
keywords semi-device-independent QKDoperational source assumptionsrandom-access codestate exclusionconditional min-entropyBrown–Fawzi–Fawzi boundprepare-and-measurequantum key distribution
verification ladder T0 review T1 audit T2 compute T3 formal T4 reserved

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

Standard semi-device-independent quantum key distribution trusts a limit on Alice’s source (often just Hilbert-space dimension) while leaving Bob’s measurements untrusted. This paper replaces that with four operational bounds on Alice’s four-state ensemble: how well anyone can guess the full label, how well they can guess its parity, and the same two tasks averaged with state exclusion. For the two-bit random-access code it derives the exact classical score ceilings under each bound, shows that BB84-type strategies give the largest quantum excess, and then certifies key rates with a three-setting protocol that tests the code on two settings and generates the raw key on a third. Because the task values cannot increase under input-independent channels, the same scalar bound applies to every Bob–Eve extension of the observed statistics. Exclusion-assisted bounds still give positive asymptotic rates at nearly vanishing preparation visibility—far below identification-only and earlier RAC-key thresholds—while under explicit label leakage the rates stay positive until the label is fully revealed. The practical message is that robust SDI security is governed by both identification and exclusion.

Core claim

Robust semi-device-independent security of the retained-key random-access-code protocol depends on operational source assumptions that constrain what Eve can exclude as well as what she can identify: under the composite bounds D⊕A or Π⊕A, dimension-independent min-entropy and PM-BFF certificates yield positive key rates down to near-zero preparation visibility, and under incomplete direct-sum label leakage all four rate bounds remain positive until full label revelation.

What carries the argument

Four scalar operational source tasks on Alice’s four-preparation ensemble—four-state discrimination D, parity discrimination Π, and the normalized composites D⊕A and Π⊕A—together with their exact classical RAC frontiers, data-processing lift to unrestricted Bob–Eve extensions, and a three-setting retained-key protocol certified by min-entropy guessing optimization and prepare-and-measure Brown–Fawzi–Fawzi entropy relaxations.

Load-bearing premise

The security proof trusts that a single scalar bound on Alice’s emitted ensemble is correct and cannot be increased by any later processing that Bob or Eve apply, so any side channel that reveals the label without raising that bound would leave the analysis incomplete.

What would settle it

Run the three-setting protocol on a preparation-depolarized BB84 ensemble at visibility well below the identification-only thresholds (for example ν ≈ 0.05) while enforcing an exclusion-assisted source bound; if the accepted min-entropy or PM-BFF certificates cannot produce a positive rate, or if an explicit incomplete-leakage ensemble yields zero certified rate before full label revelation, the central robustness claim fails.

Watch this falsifier — get emailed when new claim-graph text bears on it.

If this is right

  • SDI-QKD need not rely on a hard dimension bound; a trusted operational task bound on the emitted ensemble is enough for dimension-independent rate certificates.
  • Adding state exclusion to the source assumption removes adversarial extensions that pure identification bounds still allow, dramatically lowering the visibility needed for positive key.
  • The three-setting retained-key protocol removes the intrinsic RAC decoding penalty of earlier two-setting SDI constructions, improving rates even under the weak qubit-implied distinguishability ceiling D ≤ 1/2.
  • Physical models with a common vacuum or phase-randomized weak coherent states can be plugged in solely by converting photon-number or vacuum weight into a composite task bound.
  • Accepted PM-BFF dual certificates already supply affine one-round entropy lower bounds usable as min-tradeoff functions for future finite-key entropy-accumulation analyses.

Where Pith is reading between the lines

These are editorial extensions of the paper, not claims the author makes directly.

  • Self-testing of the ensemble geometry for the exclusion-assisted tasks could turn the trusted source bound into a partially certified feature rather than a pure hypothesis.
  • The same identification-versus-exclusion split may tighten other prepare-and-measure tasks such as semi-device-independent randomness generation and receiver-device-independent QKD.
  • Optical experiments that already calibrate vacuum probability or mean photon number are natural first platforms for the composite assumptions without needing a qubit-dimension claim.
  • If exclusion remains the dominant robustness source, protocol design should prioritize source models that jointly limit identification and exclusion rather than only improving entropy certificates on fixed feasible sets.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, simulated authors' rebuttal, and a circularity audit.

Referee Report

2 major / 5 minor

Summary. The manuscript reformulates semi-device-independent QKD by replacing a Hilbert-space dimension bound with a scalar operational upper bound on one of four tasks on Alice’s four-preparation ensemble: four-state discrimination D, parity discrimination Π, or the normalized composites D⊕A and Π⊕A with state exclusion. For the two-bit RAC it derives exact classical frontiers (Theorem 1), shows that BB84 attains the maximal quantum deviation from all four frontiers within numerical precision, and identifies complementary preparation-depolarized and direct-sum leakage families as the sampled arbitrary-dimensional quantum boundary for the exclusion-assisted tasks. Via data processing, the same scalar bound lifts to every Bob–Eve extension of the emitted ensemble. A three-setting retained-key protocol (RAC test on y=0,1; key generation on y=2 for the 00/11 branch) then yields two dimension-independent certificates over the feasible set FT(p,τ): a min-entropy bound from Eve’s optimized key-guessing probability, and a prepare-and-measure Brown–Fawzi–Fawzi (PM-BFF) lower bound on conditional von Neumann entropy. Numerically, exclusion-assisted assumptions certify positive asymptotic rates down to nearly vanishing preparation visibility, far below identification-only and earlier RAC-key thresholds; under direct-sum leakage all four independently optimized rates remain positive for incomplete leakage and vanish only at complete label revelation.

Significance. If the results hold, the paper substantially strengthens the SDI toolkit by showing that robust security is governed not only by what an adversary can identify but also by what she can exclude. Exact classical frontiers with explicit attaining strategies (Appendix A), a clean data-processing lift (Proposition 5), and dual validated finite-level certificates (min-entropy and PM-BFF) with stated residual tolerances and a reproducibility archive are genuine strengths. The three-setting retained-key protocol cleanly removes the intrinsic RAC-key reconciliation penalty of earlier constructions, and the separation of protocol, entropy certificate, and source assumption is carefully executed. The optical common-component route to exclusion-assisted bounds is a concrete experimental entry point. These contributions are of clear interest for prepare-and-measure QKD and operational quantum information.

major comments (2)
  1. [Sec. V.B, Proposition 5; Theorem 2] The security theorems (Theorem 2 and the rate bounds in Sec. V–VI) treat TQ(E)≤τ as a trusted, externally supplied scalar that is not re-certified from the observed three-setting table p. This is standard for SDI and is stated openly, but the main text should more explicitly separate (i) how τ is obtained from a physical model or independent calibration (Appendix H) from (ii) the adversarial optimization over FT(p,τ). A short protocol-level paragraph on independent estimation or certification of τ—without feeding the same data used for key generation—would close the only modelling soft spot the security reduction leaves open.
  2. [Abstract; Sec. VI; Appendix G] All reported rates are asymptotic i.i.d. rates per retained key round with ideal one-way reconciliation. Appendix G correctly shows that accepted PM-BFF duals supply affine min-tradeoff inputs for GEAT, but no finite-n rates, testing overhead, or error-correction leakage are evaluated. The abstract and Sec. VI should state more prominently that the near-zero visibility thresholds are asymptotic certificates, and that converting them into finite-key rates requires additional protocol-level choices not fixed in this work. This does not undermine the asymptotic claims but is load-bearing for how the numerical thresholds will be read.
minor comments (5)
  1. [Sec. IV.C, Result 2, Fig. 3] In Result 2 / Fig. 3, the arbitrary-dimensional D boundary remains unresolved over part of the intermediate range (d=3 see-saw exceeds depolarization; gap to Q3 remains). A one-sentence caveat in the main text that only the exclusion-assisted boundaries are claimed to be sampled would avoid over-reading panel (a).
  2. [Table III; Figs. 4–6; Appendix F] Table III and the critical-visibility stars in Figs. 4–6 are linear root estimates from nearest accepted samples of opposite sign (Appendix F). Marking them as estimates (e.g., “≈”) in the table caption and figure legends would match the careful wording already used in the appendix.
  3. [Sec. II.B, Eqs. (4)–(5), Fig. 2] Notation for the composite tasks switches between D⊕A / (D+A)/2 and the two-setting task language. A single consistent definition early in Sec. II.B (already almost present in Eqs. 5) would help readers who skip the figure.
  4. [Abstract; Sec. I] The phrase “four-state discrimination” in the abstract and introduction is later also called “full-label guessing.” Pick one primary term and use the other only as a parenthetical synonym on first occurrence.
  5. Minor typographical inconsistencies appear in a few places (e.g., spacing around νM, occasional “Bob–Eve” vs “Bob-Eve”). A final copy-edit pass would suffice.

Circularity Check

0 steps flagged

No significant circularity: classical frontiers, data-processing lift, and entropy certificates are derived independently of the reported key-rate thresholds; τ is an external trusted input.

full rationale

The load-bearing chain is self-contained. Theorem 1 (Appendix A) derives exact classical RAC frontiers from one-message posterior geometry on the unrestricted classical alphabet; the four frontiers are attained by elementary encodings and flagged mixtures, not fitted to quantum or security data. Proposition 5 lifts each scalar task bound TQ(E)≤τ to every Bob–Eve extension by data processing of input-independent channels—an operator fact independent of the later rate numbers. Security then minimizes H(K|E) (or pguess) over the lifted set FT(p,τ) via min-entropy moment relaxations and PM-BFF node programs (Appendices D–E), with explicit acceptance tolerances; the plotted critical visibilities are root estimates from accepted opposite-sign certificates, not parameters fitted to produce those thresholds. Physical models (phase-randomized vacuum weight, dimension, parity obliviousness) only motivate the external scalar π; they are not re-inserted into the adversarial optimization. Self-citations supply background tools (earlier SDI criteria, BFF variational bound, moment hierarchies) used as black boxes; none force the exclusion-assisted near-zero thresholds or the incomplete-leakage positivity by construction. No equation equates a claimed prediction to a fitted input or to a self-defined quantity.

Axiom & Free-Parameter Ledger

0 free parameters · 5 axioms · 2 invented entities

The central security claim rests on standard quantum prepare-and-measure theory, the data-processing monotonicity of the four operational tasks, the trusted scalar bound τ on Alice's emitted ensemble, unrestricted Bob-Eve Hilbert spaces, asymptotic i.i.d. collective attacks, and the validity of the finite-level noncommutative SDP outer approximations. No free parameters are fitted to produce the key-rate curves; visibility and leakage are scan parameters of honest families. The operational tasks themselves are invented as the paper's organizing language but are standard discrimination/exclusion quantities.

axioms (5)
  • domain assumption Quantum prepare-and-measure model with unrestricted Hilbert-space dimension for Bob and Eve; classical strategies are commuting special cases.
    Stated in Sec. II.A and used throughout the security optimization.
  • standard math Operational task values D, Π, A (and composites) are nonincreasing under any input-independent quantum channel (data processing).
    Proposition 5; lifts the trusted source bound to every Bob-Eve extension.
  • domain assumption The scalar bound TQ(E)≤τ is a trusted property of Alice's emitted ensemble (including all side systems) and is not adversarially chosen after the fact.
    Core SDI modeling choice; physical origins (phase randomization, vacuum weight, dimension, parity obliviousness) only motivate τ (Appendix H).
  • domain assumption Asymptotic i.i.d. collective-attack regime; Devetak-Winter direct reconciliation applies.
    Theorem 2 and Sec. V; finite-key reduction is only sketched via affine dual certificates (Appendix G).
  • standard math Finite-level noncommutative moment relaxations (degree 3) and PM-BFF node functionals with sharp localizers and Eve-side Sylvester constraints are valid outer approximations.
    Appendices B, D, E; acceptance at residual 5e-6.
invented entities (2)
  • Four operational source tasks D, Π, D⊕A, Π⊕A as scalar SDI assumptions independent evidence
    purpose: Replace dimension or overlap assumptions by single-number bounds on identification and exclusion that lift to Bob-Eve extensions.
    Standard discrimination/exclusion probabilities, but their use as the sole trusted SDI source language and the composite two-setting tasks are introduced here.
  • Three-setting retained-key protocol (RAC test + y=2 key branch on 00/11) independent evidence
    purpose: Remove intrinsic RAC decoding error from the raw key while keeping Bob uncharacterized.
    Protocol design choice of the paper; ideal BB84 has QZ=0 on the retained branch.

pith-pipeline@v1.1.0-grok45 · 44105 in / 3116 out tokens · 44496 ms · 2026-07-10T23:29:20.563404+00:00 · methodology

0 comments
read the original abstract

Semi-device-independent quantum key distribution leaves the measurement devices uncharacterized while placing a trusted assumption on Alice's source. We formulate this source assumption operationally on Alice's four-preparation ensemble as a scalar bound on one of four physically motivated source tasks: full-label guessing, parity guessing, or their normalized composites with label exclusion. For the two-bit random-access code, we derive the exact classical frontier for each of the four source assumptions. Numerically, the BB84 strategy attains the maximal quantum deviation from all four frontiers, while the preparation-depolarized BB84 family and the direct-sum label-leakage family trace complementary branches of the arbitrary-dimensional quantum boundary for the two exclusion-assisted assumptions. Because all four task values are monotone under input-independent quantum channels, the same scalar source bound constrains every Bob--Eve extension compatible with the complete observed behavior. Using a three-setting extension that separates RAC testing from key generation, we obtain two dimension-independent security certificates over this feasible set: lower bounds on the conditional min-entropy and conditional von Neumann entropy, obtained respectively by direct optimization of Eve's key-guessing probability and by prepare-and-measure semidefinite relaxations based on the Brown--Fawzi--Fawzi variational bound. The exclusion-assisted assumptions certify positive key rates down to nearly vanishing preparation visibility, far beyond full-label or parity guessing alone. Under direct-sum label leakage, all four independently optimized rate bounds remain positive at every sampled incomplete-leakage point and vanish only at complete label revelation. These results show that robust semi-device-independent security depends not only on what Eve can identify, but also on what she can exclude.

Figures

Figures reproduced from arXiv: 2607.06682 by Anubhav Chaturvedi, Debashis Saha, Ekta Panwar, Giuseppe Viola, Tushita Prasad.

Figure 1
Figure 1. Figure 1: FIG. 1. Three-setting retained-key protocol under an opera [PITH_FULL_IMAGE:figures/full_fig_p001_1.png] view at source ↗
Figure 2
Figure 2. Figure 2: FIG. 2. Operational source tasks and their relations. Boxes are [PITH_FULL_IMAGE:figures/full_fig_p004_2.png] view at source ↗
Figure 3
Figure 3. Figure 3: FIG. 3. Quantum deviation from the exact classical frontiers. Gray circles are level- [PITH_FULL_IMAGE:figures/full_fig_p009_3.png] view at source ↗
Figure 4
Figure 4. Figure 4: FIG. 4. Fixed distinguishability benchmark [PITH_FULL_IMAGE:figures/full_fig_p013_4.png] view at source ↗
Figure 5
Figure 5. Figure 5: FIG. 5. Source-depolarized BB84 key-rate lower bounds under four operational source assumptions. Dashed blue curves with [PITH_FULL_IMAGE:figures/full_fig_p014_5.png] view at source ↗
Figure 6
Figure 6. Figure 6: FIG. 6. Receiver-side depolarization. For each receiver-side [PITH_FULL_IMAGE:figures/full_fig_p015_6.png] view at source ↗
Figure 7
Figure 7. Figure 7: FIG. 7. Direct-sum leakage. The four operational source as [PITH_FULL_IMAGE:figures/full_fig_p015_7.png] view at source ↗

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.

Reference graph

Works this paper leans on

102 extracted references · 102 canonical work pages · 4 internal anchors

  1. [1]

    Since the value ofxs are sampled uniformly, the probability of the messageλis µλ= 1 4 ∑ x∈X p(λ|x).(A1) Equation (A1) is just the law of total probability with priorp(x) = 1/4

    From messages to posteriors A classical source is specified by conditional probabil- ities p(λ|x), where x∈Xis Alice’s stringx and λis the message received by Bob. Since the value ofxs are sampled uniformly, the probability of the messageλis µλ= 1 4 ∑ x∈X p(λ|x).(A1) Equation (A1) is just the law of total probability with priorp(x) = 1/4. It is the weight...

  2. [2]

    (A7) The absolute values encode Bob’s freedom to decide which bit value is more likely for each question

    A normal form for one posterior The RAC score can be written as a chance value plus the two optimal bit biases: r(q) = 1 2 + 1 4 ( |q00 +q 01−q10−q11| +|q00 +q 10−q01−q11| ) . (A7) The absolute values encode Bob’s freedom to decide which bit value is more likely for each question. Flipping either bit value only relabels the posterior entries; it does not ...

  3. [3]

    Sinceα,β,γ≤d, normalization implies δ= 1−α−β−γ≥1−3d.(A13) Since no posterior atom exceedsd, normalization forces the fourth atom to satisfyδ≥1−3d

    The four-state-discrimination frontier Let d= max{α,β,γ,δ}.(A12) This is the one-message value of four-state discrimination. Sinceα,β,γ≤d, normalization implies δ= 1−α−β−γ≥1−3d.(A13) Since no posterior atom exceedsd, normalization forces the fourth atom to satisfyδ≥1−3d. Usingα≤dand Eq. (A13) in Eq. (A10) gives r(q)≤1 2 + d−(1−3d) 2 = 2d.(A14) This is the...

  4. [4]

    Sinceπ≥α+δ, and δ≥0, α−δ≤α+δ≤π.(A17) Substituting this into the normal form Eq

    The parity frontier Let π= max{α+δ, β+γ}.(A16) This is the one-message value of parity discrimination: the two entries in the maximum are the posterior weights of the even and odd parity classes. Sinceπ≥α+δ, and δ≥0, α−δ≤α+δ≤π.(A17) Substituting this into the normal form Eq. (A10) yields r(q)≤1 2 + π 2 = 1 +π 2 .(A18) Averaging over messages givesR≤(1 + Π...

  5. [5]

    Combiningα≤dwithδ≥mgives α−δ≤d−m.(A20) Using Eq

    The four-state-discrimination-with-exclusion frontier Let m= min{α,β,γ,δ}, a= 1−m.(A19) The least posterior weightm is the value ofx one should exclude, so a is the one-message exclusion probability. Combiningα≤dwithδ≥mgives α−δ≤d−m.(A20) Using Eq. (A10), this gives r(q)≤1 2 + d−m 2 = d+a 2 .(A21) Writingt =D⊕A= (D +A)/2, averaging over messages gives R≤t...

  6. [6]

    The first one-message constraint is r(q)≤π+a 2 .(A23) To prove it, Eq.(A10) shows that it is enough to bound α−δbyπ−m

    The parity-with-exclusion frontier The parity-with-exclusion frontier is the lower envelope of two affine constraints. The first one-message constraint is r(q)≤π+a 2 .(A23) To prove it, Eq.(A10) shows that it is enough to bound α−δbyπ−m. Sinceπ≥α+δandδ≥m, π−m≥α+δ−m≥α−δ.(A24) This proves Eq. (A23). The second one-message constraint is r(q)≤π+a−3 4.(A25) Us...

  7. [7]

    To see that they are exact frontiers, it remains to exhibit classical sources that attain every exposed segment

    Tightness and the four extremal sources The preceding subsections prove upper bounds. To see that they are exact frontiers, it remains to exhibit classical sources that attain every exposed segment. Four sources suffice: N: (R,D,Π,A) = (1 2, 1 4, 1 2, 3 4 ) , E: (R,D,Π,A) = (2 3, 1 3, 2 3,1 ) , B: (R,D,Π,A) = (3 4, 1 2, 1 2,1 ) , F: (R,D,Π,A) = (1,1,1,1)....

  8. [8]

    The six posterior inequalities sur- vive averaging independently, and therefore hold simulta- neously for every classical strategy

    Simultaneous affine bounds The proof above gives more than the four single- assumption frontiers. The six posterior inequalities sur- vive averaging independently, and therefore hold simulta- neously for every classical strategy. Corollary 1(Simultaneous affine bounds).Every classi- cal strategy satisfies R≤min { 2D, 1 +D 2 , 1 + Π 2 , D+A 2 ,Π +A− 3 4, Π...

  9. [9]

    Operator families and moment matrices LetWk be the reduced words of degree at mostk in the two binary RAC projectorsM0,M 1, withMy = M† y = M2 y. For every positive operator familyF appearing in the optimization, define LF (w) := Tr(Fw),(B1) and the moment matrix ΓF u,v =L F (u†v), u,v∈W k.(B2) Every quantum realization givesΓ F ⪰0because LF (q†q)≥0for al...

  10. [10]

    Source-task covers The task certificates are represented through positive cover slacks. For distinguishability, ΓσD−ρx/4⪰0∀x.(B4) For parity, ΓσΠ−(ρ00+ρ11)/4⪰0,Γ σΠ−(ρ01+ρ10)/4⪰0.(B5) For exclusion, Γ σA−1 4 ∑ x̸=zρx ⪰0∀z.(B6) At the operator level, the minimum certificate traces equal the source-task values in Eq.(23); the finite moment covers provide th...

  11. [11]

    RAC objective and finite-level upper bounds The RAC objective is the linear functional R= 1 8 ∑ x,y { Lρx(My), x y = 0, 1−Lρx(My), x y = 1. (B7) On each affine branchFT (t) = ct +b, the relaxation maximizes R−cT−bwith the branch interval imposed on the corresponding source-task value: TrσD, TrσΠ, (TrσD + TrσA)/2, or( TrσΠ + TrσA)/2. Since every arbitrary-...

  12. [12]

    For fixed states,My is the Helstrom projector of the RAC contrast

    Finite-dimensional see-saw lower bounds The see-saw is used only to construct feasible points. For fixed states,My is the Helstrom projector of the RAC contrast. For fixed projectors, the state update is an SDP over ρx and the task certificates with an upper bound on the chosen source-task value. After convergence, the attained task value is recomputed by...

  13. [13]

    The Hilbert spaces are unrestricted

    General prepare-and-measure realization For each value ofx x∈{00, 01, 10, 11}, the adversarial realization is described by a normalized positive operator ϱBE x ⪰0,Trϱ BE x = 1.(C1) This is the minimal object needed for the security proof: system B is the system measured by Bob, and systemE is retained by Eve. The Hilbert spaces are unrestricted. Bob has t...

  14. [14]

    (C5) This definition is forced by the measurement post- processing: Bob’s classical outcome is kept, and the post- measurement quantum system on Eve’s side is traced over B

    Key map and cq state The retained branch is the fixed map 0↦→00,1↦→11.(C4) After Bob performs setting2, Eve’s subnormalized state for Alice’s key valuekand Bob’s outputbis ωE kb = TrB [ (Bb|2⊗IE)ϱBE xZ(k) ] , B 0|2=B 2, B 1|2=I B−B2. (C5) This definition is forced by the measurement post- processing: Bob’s classical outcome is kept, and the post- measurem...

  15. [15]

    Operator form of the source assumptions The optimized source tasks are imposed through their dual covers. For distinguishability, a single certificateσD must dominate each weighted preparation: σD−1 4ϱBE x ⪰0∀x.(C10) Taking the trace and minimizingTrσD is precisely the dual of the four-state discrimination problem. For parity, the two effective parity pre...

  16. [16]

    After a Naimark dilation it is enough to take E=E †=E 2,[E,B y] = 0 (y= 0,1,2).(D1) The commutation in Eq.(D1) is only the Bob–Eve tensor- product commutation

    Exact operator problem Let E denote Eve’s effect for the guessK = 0. After a Naimark dilation it is enough to take E=E †=E 2,[E,B y] = 0 (y= 0,1,2).(D1) The commutation in Eq.(D1) is only the Bob–Eve tensor- product commutation. It does not impose any commu- tation between Bob’s settings. For fixed feasible states, Eve’s probability of guessing the retain...

  17. [17]

    The degree- three row set is W(3) min ={red(w) :w∈{B0,B 1,B 2,E}∗,|w|≤3}.(D6) The production implementation verifies that this set con- tains32reduced words

    Reduced word algebra Let Amin be the unital ∗-algebra generated by B0,B 1,B 2,E, reduced only by B2 y =B y, E 2 =E, EB y =B yE.(D5) Different Bob settings are never reordered. The degree- three row set is W(3) min ={red(w) :w∈{B0,B 1,B 2,E}∗,|w|≤3}.(D6) The production implementation verifies that this set con- tains32reduced words. Its product closure con...

  18. [18]

    Thus, ΓσD−1 4Γϱx⪰0, ΓσΠ−1 4(Γϱ00 + Γϱ11)⪰0, ΓσΠ−1 4(Γϱ01 + Γϱ10)⪰0, ΓσA−1 4 ∑ x̸=z Γϱx⪰0

    Lifted source covers and observed behavior The source covers from Appendix C are lifted by re- placing each operator by its moment matrix. Thus, ΓσD−1 4Γϱx⪰0, ΓσΠ−1 4(Γϱ00 + Γϱ11)⪰0, ΓσΠ−1 4(Γϱ01 + Γϱ10)⪰0, ΓσA−1 4 ∑ x̸=z Γϱx⪰0. (D12) Only the covers required by the chosen task are active. For a composite task, the only scalar restriction is the trace- su...

  19. [19]

    At an active quadrature node0 < t <1, the BFF variational objective becomes βt = inf Z0,Z1 1 2 1∑ k=0 { Tr [ ηk(Zk +Z† k) ] + (1−t) Tr ( ηkZ† kZk ) +tTr ( ΩZkZ† k )}

    Node functional, stationarity, and sharp norm For the retained-key cq state, setηk = ρE k andΩ = η0 +η1. At an active quadrature node0 < t <1, the BFF variational objective becomes βt = inf Z0,Z1 1 2 1∑ k=0 { Tr [ ηk(Zk +Z† k) ] + (1−t) Tr ( ηkZ† kZk ) +tTr ( ΩZkZ† k )} . (E1) The two variablesZ0,Z 1 act only on Eve’s system. The first two terms are branc...

  20. [20]

    The algebra is generated byB 0,B 1,B 2,z 0,d 0,z 1,d 1, with B2 y =B y,[B y,zk] = [By,dk] = 0, d k =z† k

    Noncommutative operator algebra and exact word set Writezk =Zk and dk =Z† k. The algebra is generated byB 0,B 1,B 2,z 0,d 0,z 1,d 1, with B2 y =B y,[B y,zk] = [By,dk] = 0, d k =z† k. (E7) Distinct Bob settings are never reordered, and no com- mutation is imposed between the two Eve branches. The implemented PM-BFF word set is stated explicitly. First defi...

  21. [21]

    For example, ∆ D,x =σD−1 4ϱx,∆ A,z =σA−1 4 ∑ x̸=z ϱx.(E11) The parity covers are defined analogously when the parity bound is not the exact endpointΠ = 1 /2

    Source covers and sharp localizers Every source cover is represented by a positive slack. For example, ∆ D,x =σD−1 4ϱx,∆ A,z =σA−1 4 ∑ x̸=z ϱx.(E11) The parity covers are defined analogously when the parity bound is not the exact endpointΠ = 1 /2. Moment positivity and norm localizers are imposed on every active slack. A separate PSD block forσD,σΠ, orσA ...

  22. [22]

    Its product closure contains190 reduced Bob words, grouped into106adjoint orbits

    Complete physical hierarchy for Bob’s settings The entropy basis is supplemented by the complete Bob degree-three word set WB,3 ={red(w) :w∈{B0,B 1,B 2}∗,|w|≤3}.(E14) This set has22rows. Its product closure contains190 reduced Bob words, grouped into106adjoint orbits. The 89orbit representatives not already present in the PM- BFF closure are introduced as...

  23. [23]

    For the K = 0branch and the K = 1branch the implemented equations are 0 =L ϱ00(A†) + (1−t)Lϱ00(A†z0) +tLϱ00+ϱ11(z0A†), 0 =L ϱ11(A†) + (1−t)Lϱ11(A†z1) +tLϱ00+ϱ11(z1A†)

    Weak Sylvester system and node objective The weak Sylvester equations are imposed only on Eve- side test words visible in the product closure. For the K = 0branch and the K = 1branch the implemented equations are 0 =L ϱ00(A†) + (1−t)Lϱ00(A†z0) +tLϱ00+ϱ11(z0A†), 0 =L ϱ11(A†) + (1−t)Lϱ11(A†z1) +tLϱ00+ϱ11(z1A†). (E16) The production closure gives11complex eq...

  24. [24]

    dual fam

    Block counts and numerical validation Each positive family or source-cover slack carries three kinds of constraints: the64×64PM-BFF moment block, thecomplete22×22Bobdegree-threeblock, andthesharp localizers generated by the retained auxiliary suffixes. The same 64-word PM-BFF basis, Bob block, localizer sectors, and Eve-only Sylvester equations are used f...

  25. [25]

    A bound on the mean value of a trusted observable pro- vides a natural alternative to a Hilbert-space dimension assumption

    Photon-number constraints and phase-randomized weak coherent sources We assume trusted complete randomization of the global optical phase, with the random phase and every corresponding record unavailable to the receiver and Eve. A bound on the mean value of a trusted observable pro- vides a natural alternative to a Hilbert-space dimension assumption. In o...

  26. [26]

    For a phase-randomized source whose non-vacuum con- tribution satisfies Tr [( I−|vac⟩⟨vac| ) ρx ] ≤ω∀x,(H9) the common vacuum weight obeysq≥1−ω

    The operational source assumption constrains only the corresponding normalized sum and does not impose the component bounds separately. For a phase-randomized source whose non-vacuum con- tribution satisfies Tr [( I−|vac⟩⟨vac| ) ρx ] ≤ω∀x,(H9) the common vacuum weight obeysq≥1−ω. Equa- tion (H7) then yields (D⊕A)Q(E)≤1 +ω 2 .(H10) 29 A mean-photon-number ...

  27. [27]

    Optimizing over the POVM givesD≤d/4

    Dimension implies a guessing bound For four equiprobable states ρx supported on a d- dimensional Hilbert space and any four-state discrimi- nation POVM{Nx}, 1 4 ∑ x Tr(ρxNx)≤1 4 ∑ x TrNx = d 4,(H17) because0 ⪯ρx⪯Id and∑ xNx =Id. Optimizing over the POVM givesD≤d/4. This implication is one-way: the operational source assumption does not require a dimension...

  28. [28]

    Bell remote preparation implies parity obliviousness Consider a tripartite stateρABE and binary measure- ments{Aa|s}1 a=0 on Alice’s system. Her eventa|sre- motely prepares the subnormalized Bob–Eve state σBE a|s= TrA[(Aa|s⊗IBE)ρABE].(H18) No-signalling is the operator identity ∑ a σBE a|0= ∑ a σBE a|1.(H19) For unbiased outcomes defineϱBE a|s= 2σBE a|san...

  29. [29]

    A. Acín, N. Brunner, N. Gisin, S. Massar, S. Pironio, and V. Scarani, Device-independent security of quantum cryptography against collective attacks, Physical Review Letters98, 230501 (2007)

  30. [30]

    Pironio, A

    S. Pironio, A. Acín, N. Brunner, N. Gisin, S. Massar, and V. Scarani, Device-independent quantum key distribution secure against collective attacks, New Journal of Physics 11, 045021 (2009)

  31. [31]

    Masanes, S

    L. Masanes, S. Pironio, and A. Acín, Secure device- independent quantum key distribution with causally inde- pendent measurement devices, Nature Communications 2, 238 (2011)

  32. [32]

    Vazirani and T

    U. Vazirani and T. Vidick, Fully device-independent quan- tum key distribution, Physical Review Letters113, 140501 (2014)

  33. [33]

    Arnon-Friedman, F

    R. Arnon-Friedman, F. Dupuis, O. Fawzi, R. Renner, and T. Vidick, Practical device-independent quantum cryptog- raphy via entropy accumulation, Nature Communications 9, 459 (2018)

  34. [34]

    Pollyceno, A

    L. Pollyceno, A. Chaturvedi, C. Raj, P. R. Dieguez, and M. Pawłowski, Security of device-independent quantum key distribution via monogamy relations from multipartite information causality, Physical Review A112, 042201 (2025)

  35. [35]

    Giustinaet al., Significant-loophole-free test of bell’s theorem with entangled photons, Physical Review Letters 115, 250401 (2015)

    M. Giustinaet al., Significant-loophole-free test of bell’s theorem with entangled photons, Physical Review Letters 115, 250401 (2015)

  36. [36]

    L. K. Shalmet al., Strong loophole-free test of local realism, Physical Review Letters115, 250402 (2015)

  37. [37]

    Hensenet al., Loophole-free bell inequality violation using electron spins separated by 1.3 kilometres, Nature 526, 682 (2015)

    B. Hensenet al., Loophole-free bell inequality violation using electron spins separated by 1.3 kilometres, Nature 526, 682 (2015)

  38. [38]

    Murta, S

    G. Murta, S. B. van Dam, J. Ribeiro, R. Hanson, and S. Wehner, Towards a realization of device-independent quantum key distribution, Quantum Science and Technol- ogy4, 035011 (2019)

  39. [39]

    Zapatero, T

    V. Zapatero, T. van Leent, R. Arnon-Friedman, W.-Z. Liu, Q. Zhang, H. Weinfurter, and M. Curty, Advances in device-independent quantum key distribution, npj Quan- tum Information9, 10 (2023)

  40. [40]

    Miklin, A

    N. Miklin, A. Chaturvedi, M. Bourennane, M. Pawłowski, and A. Cabello, Exponentially decreasing critical detec- tion efficiency for any bell inequality, Physical Review Letters129, 230403 (2022)

  41. [41]

    Chaturvedi, G

    A. Chaturvedi, G. Viola, and M. Pawłowski, Extending loophole-free nonlocal correlations to arbitrarily large distances, npj Quantum Information10, 7 (2024)

  42. [42]

    Gigena, E

    N. Gigena, E. Panwar, G. Scala, M. Araújo, M. Farkas, and A. Chaturvedi, Self-testing tilted strategies for maxi- mal loophole-free nonlocality, npj Quantum Information 11, 82 (2025)

  43. [43]

    Pawłowski and N

    M. Pawłowski and N. Brunner, Semi-device-independent security of one-way quantum key distribution, Physical Review A84, 010302 (2011)

  44. [44]

    Chaturvedi, M

    A. Chaturvedi, M. Ray, R. Veynar, and M. Pawłowski, On the security of semi-device-independent qkd protocols, Quantum Information Processing17, 131 (2018)

  45. [45]

    Chaturvedi, M

    A. Chaturvedi, M. Pawłowski, and K. Horodecki, Random access codes and nonlocal resources, Physical Review A 96, 022125 (2017)

  46. [46]

    C. Raj, T. Prasad, A. Chaturvedi, L. Pollyceno, D. Spegel- Lexne, S. Gómez, J. Argillander, A. Alarcón, G. B. Xavier, M. Pawłowski, and P. R. Dieguez, Certifying semi-device- independent security via wave-particle duality experi- ments, npj Quantum Information12, 7 (2026)

  47. [47]

    Woodhead and S

    E. Woodhead and S. Pironio, Secrecy in prepare-and- measure clauser-horne-shimony-holt tests with a qubit bound, Physical Review Letters115, 150501 (2015)

  48. [48]

    Li, Z.-Q

    H.-W. Li, Z.-Q. Yin, Y.-C. Wu, X.-B. Zou, S. Wang, W. Chen, G.-C. Guo, and Z.-F. Han, Semi-device- independent random-number expansion without entangle- ment, Physical Review A84, 034301 (2011)

  49. [49]

    H.-W. Li, M. Pawłowski, Z.-Q. Yin, G.-C. Guo, and Z.-F. Han, Semi-device-independent randomness certification using n→1quantum random access codes, Physical Review A85, 052308 (2012)

  50. [50]

    Lunghi, J

    T. Lunghi, J. B. Brask, C. W. Lim, Q. Lavigne, J. Bowles, A. Martin, H. Zbinden, and N. Brunner, Self-testing quan- tum random number generator, Physical Review Letters 114, 150501 (2015)

  51. [51]

    Pollyceno, D

    L. Pollyceno, D. Freudenheim, J. Nogueira, A. Chaturvedi, R. Rabelo, and M. Pawłowski, Communication-constrained nonlocal correlations (2026), arXiv:2603.08610 [quant-ph]

  52. [52]

    Van Himbeeck, E

    T. Van Himbeeck, E. Woodhead, N. J. Cerf, R. García- Patrón, and S. Pironio, Semi-device-independent frame- work based on natural physical assumptions, Quantum1, 33 (2017)

  53. [53]

    Gallego, N

    R. Gallego, N. Brunner, C. Hadley, and A. Acín, Device- independent tests of classical and quantum dimensions, Physical Review Letters105, 230501 (2010)

  54. [54]

    Brunner, M

    N. Brunner, M. Navascués, and T. Vértesi, Dimension witnesses and quantum state discrimination, Physical Review Letters110, 150501 (2013)

  55. [55]

    Bowles, M

    J. Bowles, M. T. Quintino, and N. Brunner, Certifying the dimension of classical and quantum systems in a prepare- and-measure scenario with independent devices, Physical Review Letters112, 140407 (2014)

  56. [56]

    Pauwels, S

    J. Pauwels, S. Pironio, E. Woodhead, and A. Tavakoli, Al- most qudits in the prepare-and-measure scenario, Physical Review Letters129, 250504 (2022)

  57. [57]

    Roch i Carceller, J

    C. Roch i Carceller, J. Pauwels, S. Pironio, and A. Tavakoli, Prepare-and-measure scenarios with photon- number constraints, Physical Review Letters135, 140802 (2025)

  58. [58]

    J. B. Brask, A. Martin, W. Esposito, R. Houlmann, J. Bowles, H. Zbinden, and N. Brunner, Megahertz-rate semi-device-independent quantum random number gener- atorsbasedonunambiguousstatediscrimination,Physical Review Applied7, 054018 (2017)

  59. [59]

    W. Shi, Y. Cai, J. B. Brask, H. Zbinden, and N. Brun- ner, Semi-device-independent characterization of quan- 31 tum measurements under a minimum overlap assumption, Physical Review A100, 042108 (2019)

  60. [60]

    Ioannou, M

    M. Ioannou, M. A. Pereira, D. Rusca, F. Grünenfelder, A. Boaron, M. Perrenoud, A. A. Abbott, P. Sekatski, J.-D. Bancal, N. Maring, H. Zbinden, and N. Brunner, Receiver-device-independent quantum key distribution, Quantum6, 718 (2022)

  61. [61]

    Ioannou, P

    M. Ioannou, P. Sekatski, A. A. Abbott, D. Rosset, J.- D. Bancal, and N. Brunner, Receiver-device-independent quantum key distribution protocols, New Journal of Physics24, 063006 (2022)

  62. [62]

    Tavakoli, Semi-device-independent framework based on restricted distrust in prepare-and-measure experiments, Physical Review Letters126, 210503 (2021)

    A. Tavakoli, Semi-device-independent framework based on restricted distrust in prepare-and-measure experiments, Physical Review Letters126, 210503 (2021)

  63. [63]

    J. B. Brask, N. Brunner, J. Pauwels, D. Rusca, and A. Tavakoli, Quantum correlations in prepare-and- measure scenarios and their semi-device-independent ap- plications (2026), arXiv:2603.23604 [quant-ph]

  64. [64]

    Tavakoli, E

    A. Tavakoli, E. Zambrini Cruzeiro, J. B. Brask, N. Gisin, and N. Brunner, Informationally restricted quantum cor- relations, Quantum4, 332 (2020)

  65. [65]

    Tavakoli, E

    A. Tavakoli, E. Zambrini Cruzeiro, E. Woodhead, and S. Pironio, Informationally restricted correlations: a gen- eral framework for classical and quantum systems, Quan- tum6, 620 (2022)

  66. [66]

    Pauwels, S

    J. Pauwels, S. Pironio, and A. Tavakoli, Information ca- pacity of quantum communication under natural physical assumptions, Quantum9, 1637 (2025)

  67. [67]

    R. W. Spekkens, D. H. Buzacott, A. J. Keehn, B. Toner, and G. J. Pryde, Preparation contextuality powers parity- oblivious multiplexing, Physical Review Letters102, 010401 (2009)

  68. [68]

    Chailloux, I

    A. Chailloux, I. Kerenidis, S. Kundu, and J. Sikora, Op- timal bounds for parity-oblivious random access codes, New Journal of Physics18, 045003 (2016)

  69. [69]

    Ambainis, M

    A. Ambainis, M. Banik, A. Chaturvedi, D. Kravchenko, and A. Rai, Parity oblivious d-level random access codes and class of noncontextuality inequalities, Quantum In- formation Processing18, 111 (2019)

  70. [70]

    Chaturvedi, M

    A. Chaturvedi, M. Farkas, and V. J. Wright, Charac- terising and bounding the set of quantum behaviours in contextuality scenarios, Quantum5, 484 (2021)

  71. [71]

    Saha and A

    D. Saha and A. Chaturvedi, Preparation contextuality as an essential feature underlying quantum communication advantage, Physical Review A100, 022108 (2019)

  72. [72]

    Vaisakh, R

    M. Vaisakh, R. K. Patra, M. Janpandit, S. Sen, M. Banik, and A. Chaturvedi, Mutually unbiased balanced functions and generalized random access codes, Physical Review A 104, 012420 (2021)

  73. [73]

    V. J. Wright and M. Farkas, Invertible map between bell nonlocal and contextuality scenarios, Physical Review Letters131, 220202 (2023)

  74. [74]

    C. M. Caves, C. A. Fuchs, and R. Schack, Conditions for compatibility of quantum-state assignments, Physical Review A66, 062111 (2002)

  75. [75]

    Bandyopadhyay, R

    S. Bandyopadhyay, R. Jain, J. Oppenheim, and C. Perry, Conclusive exclusion of quantum states, Physical Review A89, 022336 (2014)

  76. [76]

    M. F. Pusey, J. Barrett, and T. Rudolph, On the reality of the quantum state, Nature Physics8, 475 (2012)

  77. [77]

    M. S. Leifer, Is the quantum state real? an extended review ofψ-ontology theorems, Quanta3, 67 (2014)

  78. [78]

    M. S. Leifer and C. Duarte, Noncontextuality inequali- ties from antidistinguishability, Physical Review A101, 062113 (2020)

  79. [79]

    Srikumar, S

    M. Srikumar, S. D. Bartlett, and A. Karanjai, How con- textuality and antidistinguishability are related, Physical Review Letters136, 080203 (2026)

  80. [80]

    Johnston, V

    N. Johnston, V. Russo, and J. Sikora, Tight bounds for antidistinguishability and circulant sets of pure quantum states, Quantum9, 1622 (2025)

Showing first 80 references.