Pith. sign in

REVIEW 4 minor 44 references

Passive entanglement-based key distribution is secure even with biased basis choice, and matches active rates.

Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →

T0 review · grok-4.5

2026-07-14 10:09 UTC pith:BTXGKGE6

load-bearing objection Solid asymptotic security proof for biased passive BBM92/QCKA that closes a real open gap; virtual-qubit reduction is the genuine technical step and the numerics show the rate is essentially tight.

arxiv 2607.10659 v1 pith:BTXGKGE6 submitted 2026-07-12 quant-ph

Security of passive entanglement-based key distribution protocols

classification quant-ph PACS 03.67.Dd03.67.Hk42.50.Ex
keywords passive BBM92quantum conference key agreementbiased basis choicethreshold detectorsvirtual qubitphase error rateasymptotic securityentanglement-based QKD
verification ladder T0 review T1 audit T2 compute T3 formal T4 reserved

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

Entanglement-based key distribution (BBM92 for two parties, GHZ-based conference key agreement for many parties) is often implemented with passive beam-splitter measurements because they are simpler and avoid active switching losses. Security proofs for those passive setups have been missing when the basis choice is biased, because standard tools such as the squashing model do not apply. This paper closes that gap for the asymptotic regime. It introduces a virtual-qubit description that lets the passive protocols be reduced to known complementarity arguments, proves security for passive BBM92 and for passive multipartite QCKA, and shows numerically that the resulting key rates are essentially the same as those of the corresponding active protocols under realistic parametric-down-conversion sources. The practical consequence is that experimenters can keep the simpler passive hardware without sacrificing asymptotic key rate.

Core claim

In the asymptotic limit, the passive BBM92 protocol with biased basis choice is information-theoretically secure, and the same proof technique extends to passive GHZ-state quantum conference key agreement for any number of parties. The lower bounds on the secret-key rates (Theorems 1 and 2) are obtained by bounding the phase-error rate of the single-photon subspace via observed X-basis error rates and cross-click rates; under realistic source and detector parameters the passive rates are almost identical to the active ones.

What carries the argument

A virtual-qubit construction for receivers: for single-photon events the actual passive POVM is rewritten as a filter, a fixed CPTP map, and then an ideal active Z/X measurement; the phase-error rate on that virtual qubit is related by a simple probability factor to the observed X-basis error rate, allowing complementarity-based privacy amplification to be applied directly.

Load-bearing premise

All multi-photon and vacuum events are treated as having phase-error rate one-half and are therefore discarded through privacy amplification, so secret key is extracted only from the single-photon subspace.

What would settle it

Under the paper’s own PDC source model and detector parameters, compute the asymptotic key-rate lower bound of Theorem 1 for the passive protocol and the corresponding active-protocol bound; if they diverge by more than a few percent over typical fiber lengths, or if a tighter multi-photon analysis yields a higher rate than the single-photon-only bound, the claimed near-equivalence fails.

Watch this falsifier — get emailed when new claim-graph text bears on it.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, simulated authors' rebuttal, and a circularity audit.

Referee Report

0 major / 4 minor

Summary. The manuscript proves asymptotic security of passive entanglement-based key distribution with biased basis choice. For the two-party BBM92 protocol it introduces an equivalent virtual measurement (QND photon-number measurement followed by a lossless beam splitter with adjusted ratios and unit-efficiency detectors), defines a virtual qubit on Alice’s side via a filter-plus-CPTP map (Kraus operators that absorb dark counts), and bounds the phase-error rate of the single-photon subspace by the observed X-basis error rate via explicit POVM elements and Azuma’s inequality. Multi-photon and vacuum events are assigned phase-error rate 1/2 and discarded. The resulting key-rate lower bound (Theorem 1) is expressed solely in terms of observed click statistics. The same virtual-qubit construction is extended to GHZ-based QCKA for an arbitrary number of parties (Theorem 2). Closed-form expressions for the relevant yields under a PDC source are derived and used to show that the passive BBM92 rate is essentially identical to the active rate under realistic parameters.

Significance. Passive biased-basis measurements are the practical default for entanglement-based QKD and QCKA, yet standard squashing and complementarity arguments do not apply. Closing this gap with a complete asymptotic security proof for both BBM92 and multipartite QCKA is therefore of clear practical and theoretical value. The virtual-qubit reduction is carefully constructed, the POVM derivations (Appendices B–C) and Azuma arguments (Appendix A) are explicit, and the numerical comparison (Fig. 5 together with the closed-form yields of Appendices E–F) demonstrates that the bound is essentially tight under realistic PDC parameters. These strengths make the work a solid foundation for passive implementations.

minor comments (4)
  1. In the statement of Theorem 2 the precondition still writes the two-party factor \bar p_Z^{2}\gamma/\bar p_X^{2} rather than the (N+1)-party factor that appears in the rate formula; the typographical inconsistency should be corrected for clarity.
  2. The definition of the virtual qubit for n_A=1 is deferred to the proof of Lemma 1; a brief forward reference or one-sentence summary in Sec. II B 2 would improve readability.
  3. Fig. 5 caption and the surrounding text could note more explicitly that the small long-distance gap is attributed to dark-count sensitivity (as already discussed for passive BB84) rather than looseness of the bound.
  4. A few minor typographical issues appear (e.g., “ralation” for “relation” near Eq. (90), occasional missing spaces around mathematical symbols).

Circularity Check

0 steps flagged

No significant circularity: asymptotic key-rate lower bounds follow from independent POVM/operator inequalities and complementarity, not from self-definition or fitted inputs.

full rationale

The central claims (Theorems 1–2) are obtained by (i) constructing an equivalent virtual protocol whose POVM elements are derived from first principles (Appendices B–C), (ii) defining a virtual qubit so that its Z outcomes reproduce the sifted key while its X outcomes define the phase-error rate, (iii) relating the single-photon phase-error operator to the observed X-error operator by a constant factor (Lemma 1 / Eq. (24)), (iv) bounding multi-photon contributions by cross-click operators via operator inequalities (Lemma 2), and (v) applying concavity of binary entropy plus Azuma’s inequality. None of these steps presupposes the final rate expression; the rate is a consequence of the bounds. Self-citations to the authors’ earlier passive-BB84 work and to standard complementarity papers are used only as black-box tools or motivational analogies; the present derivation re-derives the necessary operator relations for the entanglement setting and does not import an unverified uniqueness claim or a fitted parameter that is later re-labeled a prediction. Numerical key rates are simulations of the derived lower bound under a standard PDC model, not empirical predictions forced by a fit. The conservative assignment of phase-error rate 1/2 to multi-photon events is a deliberate worst-case choice that loosens the bound but does not create circularity. Hence the derivation chain is self-contained against its own inputs.

Axiom & Free-Parameter Ledger

5 free parameters · 4 axioms · 1 invented entities

The security theorems rest on standard quantum-information tools (complementarity, Azuma, POVM block-diagonality in photon number) plus one modelling choice (worst-case phase error 1/2 outside the single-photon subspace) and the usual asymptotic limit. Free parameters appear only in the numerical illustration, not in the security claims themselves. The virtual qubit is an invented bookkeeping device whose independent evidence is the equivalence of its Z-measurement statistics to the real sifted key.

free parameters (5)
  • dark-count probability d
    Fixed to 10^{-7} for numerics; enters the POVM elements and therefore the concrete rate curves, but the security theorems hold for any d.
  • detector efficiency η_Z_det = η_X_det
    Set to 0.7 for the simulation; overall transmittance η is a free experimental parameter.
  • misalignment/error rate e_d
    Fixed to 0.03 in the numerical model of bit-error rates.
  • error-correction efficiency factor
    Taken as 1.16 × h(e_Z) following a standard reference; multiplies the EC cost term.
  • signal intensity µ and basis probability p_Z
    Optimised numerically at each distance; free experimental knobs, not fitted to external data.
axioms (4)
  • standard math Azuma’s inequality implies asymptotic equality (or inequality) of observed frequencies whenever the corresponding POVM elements are proportional (or ordered).
    Invoked repeatedly (Appendix A) to convert operator relations into rate relations in the m_rep → ∞ limit.
  • domain assumption Complementarity security proof: the amount of privacy amplification is determined by the phase-error rate of a virtual X measurement on a virtual qubit whose Z measurement reproduces the sifted key.
    Taken from Koashi’s framework (cited); the paper’s contribution is to construct the required virtual qubit for passive receivers.
  • domain assumption POVM elements of threshold-detector measurements are block-diagonal in photon number, so a non-destructive photon-number measurement can be inserted without changing statistics.
    Standard optical fact used to justify the alternative protocol of Fig. 2.
  • ad hoc to paper For all events with photon number ≠ 1 the phase-error rate is taken to be 1/2 (worst-case).
    Explicit modelling choice stated in Sec. II B 2; makes the proof simple but discards potential key from multi-photon components.
invented entities (1)
  • Virtual qubit for entanglement-based receivers (especially the n = 1 case defined via filter + CPTP map of Kraus operators K_l) no independent evidence
    purpose: Provides a system on which a virtual X measurement can be defined so that the phase-error rate controls privacy amplification, mirroring the source-replacement qubit of BB84.
    The construction is internal to the proof; its only ‘evidence’ is the equivalence of its Z statistics to the real sifted key. No external prediction is made.

pith-pipeline@v1.1.0-grok45 · 40119 in / 2909 out tokens · 36196 ms · 2026-07-14T10:09:02.855935+00:00 · methodology

0 comments
read the original abstract

Entanglement-based key distribution protocols, such as the Bennett-Brassard-Mermin 1992 (BBM92) protocol and quantum conference key agreement (QCKA), are promising applications of quantum networks. In practical implementations, passive measurement setups are widely adopted because of their simplicity. However, the security analysis of passive protocols with biased basis choice is highly nontrivial, since standard proof techniques for threshold detectors are generally not applicable in this setting. In this work, we establish the security of passive entanglement-based key distribution protocols in the asymptotic regime. Specifically, we prove the security of passive BBM92 with biased basis choice and extend the proof to passive QCKA with an arbitrary number of parties. In addition, we numerically show that the key generation rate of passive BBM92 is almost identical to that of the corresponding active protocol. Our results provide a theoretical foundation for practical passive implementations of entanglement-based key distribution protocols.

Figures

Figures reproduced from arXiv: 2607.10659 by Koichi Takasugi, Koji Azuma, Shun Kawakami.

Figure 1
Figure 1. Figure 1: FIG. 1. Actual setups for passive basis choice with a beam splitter [PITH_FULL_IMAGE:figures/full_fig_p002_1.png] view at source ↗
Figure 2
Figure 2. Figure 2: FIG. 2. Virtual setup equivalent to Fig. 1. The QND measurement of [PITH_FULL_IMAGE:figures/full_fig_p003_2.png] view at source ↗
Figure 3
Figure 3. Figure 3: FIG. 3. Intermediate virtual setup obtained from Fig. 1 by absorbing [PITH_FULL_IMAGE:figures/full_fig_p004_3.png] view at source ↗
Figure 4
Figure 4. Figure 4: FIG. 4. Intermediate virtual setup in the derivation of Fig. 2, equiva [PITH_FULL_IMAGE:figures/full_fig_p004_4.png] view at source ↗
Figure 5
Figure 5. Figure 5: FIG. 5. Secure key rate per round as a function of the fiber length [PITH_FULL_IMAGE:figures/full_fig_p008_5.png] view at source ↗

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.

Reference graph

Works this paper leans on

44 extracted references · 1 canonical work pages

  1. [1]

    This alternative protocol is defined by replacing step (2) of the actual protocol with the following: (2’)Measurement: As shown in Fig

    Alternative protocol Our starting point is to introduce an alternative protocol which is equivalent to the actual protocol from the viewpoint of an eavesdropper, Eve. This alternative protocol is defined by replacing step (2) of the actual protocol with the following: (2’)Measurement: As shown in Fig. 2, Alice performs a polarization-independent QND measu...

  2. [2]

    Phase error and privacy amplification In this paper, we adopt the security proof with complemen- tarity, in which the ‘phase error’ rate is bounded by observed quantities in the actual protocol [24, 25]. To consider the amount of privacy amplification for the sifted key obtained whenW A =W B =Z, we need to define a virtual qubit on sys- temAsuch that bits...

  3. [3]

    (8), it suffices to derive an upper bound onfPA in order to obtain the secure key rate from the observed quanti- tiesQ Z,E X,Q ⊥A,ZB andQ ZA,⊥B

    Main theorem From Eq. (8), it suffices to derive an upper bound onfPA in order to obtain the secure key rate from the observed quanti- tiesQ Z,E X,Q ⊥A,ZB andQ ZA,⊥B. The result is summarized in Theorem 1. The proof of the theorem is based on three lem- mas. Lemma 1 provides an upper bound on the phase error rate appearing in the last term of Eq. (12). Le...

  4. [4]

    [33], which as- sumes a parametric down-conversion (PDC) source pumped by a pulsed laser

    Physical models and expressions for observed quantities One of the most widely adopted models for entanglement- based QKD is the model described in Ref. [33], which as- sumes a parametric down-conversion (PDC) source pumped by a pulsed laser. Although we also adopt this model, we mod- ify the expressions for the observed parameters to account for the pass...

  5. [5]

    Simulation results We present the results of numerical calculation of the key rateRper round given by Eq. (55). In the simulation shown in Fig. 5, we assume detectors’ quantum efficiencyηZ det =η X det = 0.7 and dark count probabilityd=10 −7, which are achievable with commercial SSPDs [35]. The channel transmittance of the optical fiberη ch connecting the...

  6. [6]

    With a notation ˆN(1) ξ B ˆξ† |vac⟩ ⟨vac|ZX ˆξ,(B1) forξ∈ {z H,z V ,x D,x ¯D}, the POVM elements in systemZX under the condition that the outcome of QND measurement is nA =1 are described as follows: ˆF(1) Z0 = ˆN(1) zH (1−d) 3, ˆF(1) Z1 = ˆN(1) zV (1−d) 3, ˆF(1) Z,double =d( ˆN(1) zH + ˆN(1) zV )(1−d) 2, ˆF(1) X0 = ˆN(1) xD (1−d) 3, ˆF(1) X1 = ˆN(1) x ¯D...

  7. [7]

    Azuma, S

    K. Azuma, S. E. Economou, D. Elkouss, P. Hilaire, L. Jiang, H.-K. Lo, and I. Tzitrin, Rev. Mod. Phys.95, 045006 (2023)

  8. [8]

    C. H. Bennett, G. Brassard, and N. D. Mermin, Phys. Rev. Lett. 68, 557 (1992)

  9. [9]

    Lo and H

    H.-K. Lo and H. F. Chau, Science283, 2050 (1999)

  10. [10]

    P. W. Shor and J. Preskill, Phys. Rev. Lett.85, 441 (2000)

  11. [11]

    Tsurumaru and K

    T. Tsurumaru and K. Tamaki, Phys. Rev. A78, 032302 (2008)

  12. [12]

    Koashi, Y

    M. Koashi, Y . Adachi, T. Yamamoto, and N. Imoto, arXiv:0804.0891 (2008)

  13. [13]

    C. C.-W. Lim, F. Xu, J.-W. Pan, and A. Ekert, Phys. Rev. Lett. 126, 100501 (2021)

  14. [14]

    Mannalath, V

    V . Mannalath, V . Zapatero, and M. Curty, Phys. Rev. Lett.135, 020803 (2025)

  15. [15]

    Jennewein, C

    T. Jennewein, C. Simon, G. Weihs, H. Weinfurter, and A. Zeilinger, Phys. Rev. Lett.84, 4729 (2000)

  16. [16]

    Tittel, J

    W. Tittel, J. Brendel, H. Zbinden, and N. Gisin, Phys. Rev. Lett. 84, 4737 (2000)

  17. [17]

    Ursin, F

    R. Ursin, F. Tiefenbacher, T. Schmitt-Manderbach, H. Weier, T. Scheidl, M. Lindenthal, B. Blauensteiner, T. Jennewein, J. Perdigues, P. Trojek, B. ¨Omer, M. F ¨urst, M. Meyen- burg, J. Rarity, Z. Sodnik, C. Barbieri, H. Weinfurter, and A. Zeilinger, Nature Physics3, 481 (2007)

  18. [18]

    Honjo, S

    T. Honjo, S. W. Nam, H. Takesue, Q. Zhang, H. Kamada, Y . Nishida, O. Tadanaga, M. Asobe, B. Baek, R. Hadfield, S. Miki, M. Fujiwara, M. Sasaki, Z. Wang, K. Inoue, and Y . Ya- mamoto, Opt. Express16, 19118 (2008)

  19. [19]

    Erven, X

    C. Erven, X. Ma, R. Laflamme, and G. Weihs, New Journal of Physics11, 045025 (2009). 22

  20. [20]

    Fitzke, L

    E. Fitzke, L. Bialowons, T. Dolejsky, M. Tippmann, O. Niki- forov, T. Walther, F. Wissel, and M. Gunkel, PRX Quantum3, 020341 (2022)

  21. [21]

    Zhuang, B

    S.-C. Zhuang, B. Li, M.-Y . Zheng, Y .-X. Zeng, H.-N. Wu, G.-B. Li, Q. Yao, X.-P. Xie, Y .-H. Li, H. Qin, L.-X. You, F. Xu, J. Yin, Y . Cao, Q. Zhang, C.-Z. Peng, and J.-W. Pan, Phys. Rev. Lett. 134, 230801 (2025)

  22. [22]

    Tagliavacche, M

    N. Tagliavacche, M. Borghi, G. Guarda, D. Ribezzo, M. Lisci- dini, D. Bacco, M. Galli, and D. Bajoni, npj Quantum Infor- mation11, 60 (2025)

  23. [23]

    Grasselli, H

    F. Grasselli, H. Kampermann, and D. Bruß, New Journal of Physics20, 113014 (2018)

  24. [24]

    Proietti, J

    M. Proietti, J. Ho, F. Grasselli, P. Barrow, M. Malik, and A. Fedrizzi, Science Advances7, eabe0395 (2021)

  25. [25]

    Pickston, J

    A. Pickston, J. Ho, A. Ulibarrena, F. Grasselli, M. Proietti, C. L. Morrison, P. Barrow, F. Graffitti, and A. Fedrizzi, npj Quantum Information9, 82 (2023)

  26. [26]

    Zou, B.-C

    M. Zou, B.-C. Li, S. Zhao, Y . Mao, D. Qin, X. Jiang, T.-Y . Chen, and J.-W. Pan, Phys. Rev. Lett.136, 020801 (2026)

  27. [27]

    H.-K. Lo, H. Chau, and M. Ardehali, Journal of Cryptology 18(2), 133 (2004)

  28. [28]

    N. J. Beaudry, T. Moroder, and N. L¨utkenhaus, Phys. Rev. Lett. 101, 093601 (2008)

  29. [29]

    Kamin and N

    L. Kamin and N. L¨utkenhaus, Phys. Rev. Res.6, 043223 (2024)

  30. [30]

    Koashi, arXiv:quant-ph/0609180 (2006)

    M. Koashi, arXiv:quant-ph/0609180 (2006)

  31. [31]

    Koashi, New J

    M. Koashi, New J. Phys.11, 045018 (2009)

  32. [32]

    Tomamichel and R

    M. Tomamichel and R. Renner, Phys. Rev. Lett.106, 110506 (2011)

  33. [33]

    Tupkary, E

    D. Tupkary, E. Y . Z. Tan, S. Nahar, L. Kamin, and N. L¨utkenhaus, arXiv:2502.10340 (2025)

  34. [34]

    C. H. Bennett and G. Brassard, inProceedings of IEEE Interna- tional Conference on Computers, Systems and Signal Process- ing, V ol. 175, Bangalore, India (IEEE Press, New York, 1984)

  35. [35]

    Kawakami, A

    S. Kawakami, A. Taniguchi, Y . Tonomura, K. Takasugi, and K. Azuma, Phys. Rev. Appl.24, 054070 (2025)

  36. [36]

    Mizutani, S

    A. Mizutani, S. Kawakami, and G. Kato, Quantum Science and Technology11, 015010 (2025)

  37. [37]

    Z. Wang, D. Tupkary, and S. Nahar, arXiv:2508.21486 (2025)

  38. [38]

    Azuma, Tohoku Math

    K. Azuma, Tohoku Math. J.19, 357 (1967)

  39. [39]

    Ma, C.-H

    X. Ma, C.-H. F. Fung, and H.-K. Lo, Phys. Rev. A76, 012307 (2007)

  40. [40]

    Pan, Z.-B

    J.-W. Pan, Z.-B. Chen, C.-Y . Lu, H. Weinfurter, A. Zeilinger, and M. ˙Zukowski, Rev. Mod. Phys.84, 777 (2012)

  41. [41]

    Sanari, A

    Y . Sanari, A. Taniguchi, M. Miura, H. Takahashi, K. Takasugi, H.-P. Lo, T. Ikuta, T. Honjo, and H. Takesue, in2024 Con- ference on Lasers and Electro-Optics Pacific Rim (CLEO-PR) (Optica Publishing Group, 2024)

  42. [42]

    Y . Luo, X. Cheng, H.-K. Mao, and Q. Li, Mathematics12 (2024), 10.3390/math12142243

  43. [43]

    Kato, arXiv:2002.04357 (2020)

    G. Kato, arXiv:2002.04357 (2020)

  44. [44]

    Ye, arXiv:2607.04186 (2026)

    Z. Ye, arXiv:2607.04186 (2026)