Pith. sign in

REVIEW 2 major objections 7 minor 37 references

Deployment of Entanglement-Based QKD in Financial Infrastructure

T0 review · 2 major / 7 minor · reviewed 2026-07-14 · grok-4.5

Pith's one-line read A fully automated entanglement-based QKD system ran for four months over real bank dark fiber, continuously producing secure keys that were used to open a VPN tunnel.

desk verdict Solid multi-month field demo of automated polarization eQKD in live financial data centers with real KMS/VPN use; security model is incomplete but openly flagged and not load-bearing for the feasibility claim. read the letter →

arxiv 2607.11252 v1 pith:MZFJEYBD submitted 2026-07-13 quant-ph

classification quant-ph
keywords entanglement-basedQKDpolarizationentanglementfinancialinfrastructuredarkfiberBBM92activecontrolkeymanagementsystemVPN
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper shows that polarization-entanglement quantum key distribution can be installed as ordinary infrastructure between two operational data centers of a financial institution. Over 22 km of existing dark fiber with 8 dB loss, the system generated post-processed secret keys at an average 63.8 kb/s for four months and handed them to a key-management system that established a live VPN tunnel. Polarization drifts were corrected automatically from the quantum bit-error rate alone, and the two sites stayed synchronized by using only the arrival-time correlations of the entangled photon pairs; no polarized guide lasers or external high-precision clocks were required. Total uptime reached 93.7 percent, with none of the downtime caused by the quantum optics. The result is concrete evidence that this form of QKD has left the laboratory and can already serve high-security operational networks.

What carries the argument

Active three-axis fiber polarization compensation driven only by real-time QBER feedback, together with coincidence-histogram timing recovery from the intrinsic temporal correlations of the entangled pairs; these two closed loops keep QBER below 2 percent for 97.4 percent of the time and timing precision under 300 ps without auxiliary classical reference signals.

What would settle it

An independent cryptographic audit of the keys stored in the KMS, or of the VPN traffic they protected, that demonstrated residual information leakage larger than the privacy-amplification bound (for example from the computational authentication tags or from basis imbalance) would falsify the claim of practical secure integration.

Watch

Extended reading notes

Core claim

Entanglement-based QKD using polarization-entangled photon pairs can operate as a fully automated, production-grade service on real metropolitan dark fiber between financial data centers, continuously delivering error-corrected and privacy-amplified keys at tens of kilobits per second for months while relying solely on the pairs themselves for polarization control and timing synchronization.

Load-bearing premise

The security numbers rest on a finite-key proof that assumes information-theoretic authentication, a characterized quantum random-number source, and perfectly balanced detectors—none of which the deployed system fully supplies.

Editorial extensions

If this is right

  • Financial institutions can already consume entanglement-generated keys through standard key-management systems and VPN protocols on existing dark fiber.
  • The same source architecture supports multi-user metropolitan networks by wavelength-division multiplexing up to roughly ten users.
  • Coexistence of quantum and classical traffic on shared fiber is the immediate next engineering step the design anticipates.
  • Passively stable SPDC sources remove the need for frequent optical realignment inside data-center racks.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • Closing the remaining security gaps (information-theoretic tags and a characterized QRNG) would let the identical hardware claim fully composable security at the demonstrated rates.
  • Intrinsic-pair timing recovery could eliminate costly external clock distribution in other fiber quantum networks.
  • Banks that already own dark-fiber rings could add eQKD as a software-managed service layer without new civil works.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

2 major / 7 minor

Summary. The manuscript reports a four-month field deployment of a fully automated polarization-entanglement BBM92 QKD system over a 22 km / 8 dB dark-fiber link between two operational financial data centers. The system continuously produced post-processed keys at a reported average rate of 63.78 ± 1.02 kb/s with 93.7% uptime (no quantum-optical downtime), kept QBER below 2% for 97.4% of the time via QBER-feedback polarization control only, and achieved sub-300 ps timing synchronization from intrinsic pair correlations without external time references or polarized guide lasers. Keys were handed to a KMS and consumed to establish a VPN tunnel (SKIP) and via an ETSI GS QKD 014 interface. Optical source metrics (visibility ≥ 99.4%, heralding ≥ 65%, spectral brightness), PAM splitting ratios, SNSPD performance, chromatic-dispersion budget, LDPC parameters (n = 10^5, m = 28 000, f_FER ≈ 1.16 at 4% QBER), and Circulant privacy amplification are specified, with finite-key security discussed under the Tomamichel–Leverrier framework as a reference model.

Significance. If the operational claims hold, this is a concrete maturity milestone for entanglement-based QKD: multi-month hands-off operation inside real financial infrastructure, with keys actually consumed by production networking equipment, and with autonomy features (QBER-only polarization control; pair-correlation timing; no guide lasers or external clocks) that matter for scalable deployment. The long-term rate, QBER, uptime, clock-drift, and polarization-control datasets over ~2800 h, together with explicit attribution of downtime causes and optical budgets, are stronger evidence than typical short field trials. The multi-user WDM path noted via prior source work further increases practical interest. The incomplete composable-security stack is disclosed rather than hidden, which is appropriate for a feasibility demonstration.

major comments (2)
  1. Abstract, Fig. 2 caption, and §IV call 63.78 ± 1.02 kb/s the “secure key rate” Rs, yet §IV states that the PA output length was fixed to 52 552 bits per block “in order to characterize the throughput of the deployed post-processing pipeline,” while §III.B’s finite-key reference model only quotes ε ≈ 10^{-20} (17 000 bits) and ε ≈ 10^{-7} (25 000 bits). Under that model the reported Rs is not a secret-key rate at the stated security parameters; the abstract and main quantitative claim therefore overstate what was demonstrated. Report both the pipeline throughput and the rate under the cited finite-key lengths (or recompute ε for 52 552 bits), and align terminology (“post-processed key rate” vs “secret key rate under [30]”) throughout abstract, Fig. 2, and conclusion.
  2. §III.B explicitly uses computationally secure MA/EV tags, does not supply post-processing randomness from a characterized QRNG, and relies on measurement assumptions (equal detection efficiencies in both bases; exact 50/50 splitter) that the authors state are not fully met and are left for a future composable upgrade. That disclosure is good, but the abstract and conclusion still speak of “secure keys” without any qualifier. Add a short, prominent caveat (abstract or opening of §IV/V) that the distilled keys are evaluated under a reference finite-key model with the listed computational and measurement assumptions, so readers do not take the deployment as a claim of information-theoretic composable security.
minor comments (7)
  1. §III.A: PAM splitting ratios are given as 49.6%/50.4% (Alice) and 49.9%/50.1% (Bob). Briefly state how these were measured and whether any residual bias is folded into the QBER or PE analysis.
  2. Fig. 2 yellow-shaded interval: QBER was “not recorded” during the eight-day unstable period. Clarify whether polarization control was still running and how the reduced Rs in that window was computed if QBER feedback was unavailable.
  3. §IV / Fig. 4: clock re-synchronization is triggered at 500 µs relative drift. State the coincidence-window width used for sifting and how residual drift within a block affects accidental coincidences and QBER.
  4. Eq. (5)–(6): f_FER ≈ 1.16 is given from “decoding simulations” at 4% QBER. Add the simulated FER value (or a short table) so the efficiency number is reproducible.
  5. Introduction and conclusion cite multi-user WDM scalability to ~10 users via [15,16]. A single sentence on how many ITU channels the present source actually supports under the deployed filtering (C21/C23) would make that claim more concrete.
  6. Typographical/formatting: “EV ALUA TION” in the §IV heading; inconsistent spacing in “63.78 ±1.02” vs “63.78 ± 1.02”; arXiv-style “Tech. Rep.” entries for Grover/Shor could be completed with standard bibliographic details.
  7. Fig. 1(a) map caption notes the red line is illustrative only; consider stating the actual fiber route length vs geographic distance if available, since 22 km / 8 dB already implies non-ideal loss.

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity: multi-month rates, QBER, uptime and timing are measured field quantities, not forced by definition, fit, or self-citation uniqueness.

full rationale

This is an experimental field-deployment paper. The load-bearing claims (63.78±1.02 kb/s average secure key rate, 93.7% uptime with zero quantum-optical downtime, QBER <2% for 97.4% of the time, sub-300 ps timing from pair correlations, KMS/VPN consumption) are reported as measured operational statistics over ~2800 h, not as quantities derived from a fitted parameter renamed as a prediction or from a self-definitional identity. Polarization compensation (Eqs. 3–4) is a standard control loop that uses QBER as feedback to minimize QBER; that is closed-loop engineering, not a circular derivation of a claimed first-principles result. Timing synchronization is obtained from the measured coincidence peak of the same pairs used for keying; the peak location is an empirical observable, not a quantity defined to equal the reported precision. Finite-key length estimates cite the external Tomamichel–Leverrier framework as a reference model while explicitly disclosing unmet assumptions (computational MA/EV, uncharacterized post-processing randomness, imperfect 50/50 and equal-efficiency detectors); that is an incomplete security claim, not circularity. Self-citations ([15,16,26] and related source/network work) supply component technology and multi-user scalability context; they do not define or force the four-month financial-link result. No uniqueness theorem, ansatz smuggled via prior author work, or renaming of a known empirical pattern appears in the derivation chain. Score 0 is therefore appropriate.

Assumptions & free parameters 6 free parameters · 6 assumptions · 0 invented entities

The central feasibility claim rests on standard QKD and SPDC physics plus several engineering thresholds chosen for this deployment (QBER control/accept limits, block sizes, PA lengths). Security length estimates invoke an external finite-key framework under assumptions the authors themselves mark as incomplete. No new physical entities are postulated.

free parameters (6)
  • QBER polarization-control threshold = 2%
    Controller is activated when QBER ≥ 2%; chosen as an operational compromise, not derived from first principles.
  • QBER block-acceptance threshold = 4%
    Raw blocks discarded if PE QBER > 4%; sets LDPC design point and secret-key yield.
  • sifted-key PE fraction and raw block length n = n=1e5, ~10% PE
    Roughly 10% of sifted bits revealed for PE; remaining raw block fixed at n = 10^5 for post-processing.
  • LDPC syndrome length m = 28000
    m = 28 000 bits for n = 10^5, designed for reliable decoding up to 4% QBER (f_FER ≈ 1.16).
  • PA output length for throughput characterization = 52552 bits
    Fixed to 52 552 bits per block for long-term rate reporting; differs from security-parameter example lengths (17k / 25k).
  • clock re-synchronization drift threshold = 500 µs
    Re-sync initiated when relative time drift reaches 500 µs; engineering choice producing the sawtooth coincidence pattern.
assumptions (6)
  • domain assumption BBM92 entanglement-based QKD security: eavesdropping is bounded by observed QBER on entangled pairs without trusting state preparation.
    Protocol choice stated in II and III; security of distilled keys is interpreted under this standard model.
  • domain assumption Tomamichel–Leverrier finite-key framework can be used as a reference model for secret-key length given PE, EC, EV, PA.
    Invoked in III.B; authors note it requires extra measurement assumptions and that their MA/EV/QRNG implementation is not fully information-theoretic.
  • domain assumption Type-0 SPDC in a passively stable interferometric module produces high-visibility polarization-entangled pairs in the telecom C-band with stated rates and efficiencies.
    Source performance (6.8 Mcps/mW/nm, visibility ≥ 99.4%, heralding ≥ 65%) is taken as measured and stable (III.A).
  • standard math Identity (U_A ⊗ U_B)|Φ+⟩ = (U_A U_B^T ⊗ I)|Φ+⟩ allows single-sided polarization compensation on Alice only.
    Used in III.A Eqs. (3)–(4) to justify the three-axis controller placement.
  • domain assumption Chromatic dispersion of 18.55 ps/nm/km over 22 km (≈293 ps spread) plus ~35 ps detector jitter is tolerable without CD compensation given pair rate and filtering.
    III.A argues CD compensation would add loss and is unnecessary for resolving coincidence peaks.
  • ad hoc to paper Computationally secure hash tags for MA and EV are acceptable for the deployed reference security estimate.
    Explicitly stated in III.B as a current implementation choice, with full composable upgrade left to future work.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Deployment of Entanglement-Based QKD in Financial Infrastructure." pith.science (2026). https://pith.science/paper/MZFJEYBD

@misc{pith2026260711252,
  author       = {Pith},
  title        = {Pith review of: Deployment of Entanglement-Based QKD in Financial Infrastructure},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/MZFJEYBD}},
  note         = {Machine review of arXiv:2607.11252}
}
read the original abstract

We demonstrate the feasibility of entanglement-based quantum key distribution (eQKD) in high-security financial infrastructure over a 22 km fiber link with 8 dB loss between two data centers using polarization entanglement. The fully automated system continuously generated secure keys for four months at an average rate of 63.8 kb/s, which were stored into a key management system and consumed to establish a VPN tunnel. The setup achieved 93.7% total up-time, with no downtime caused by the quantum optical components. Active polarization control kept the quantum bit error rate below 2% for 97.4% of the time and timing synchronization based on the entangled photon pairs' intrinsic temporal correlations achieved sub-300 ps precision. Our standalone system requires neither polarized guide lasers nor external high-precision time references. These results show practical integration of eQKD into operational financial infrastructure.

Figures

Figures reproduced from arXiv: 2607.11252 by the authors.

Figure 1
Figure 1. FIG. 1 [PITH_FULL_IMAGE:figures/full_fig_p002_1.png] view at source ↗
Figure 2
Figure 2. FIG. 2 [PITH_FULL_IMAGE:figures/full_fig_p003_2.png] view at source ↗
Figure 3
Figure 3. FIG. 3 [PITH_FULL_IMAGE:figures/full_fig_p005_3.png] view at source ↗
Figures from the paper (1 more)
Figure 4
Figure 4. Figure 4: FIG. 4 [PITH_FULL_IMAGE:figures/full_fig_p006_4.png]

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

37 extracted references · 3 linked inside Pith

  1. [30]

    & Leverrier, A

    Tomamichel, M. & Leverrier, A. A largely self-contained and complete security proof for quantum key distribution. Quantum1, 14 (2017)

  2. [1]

    Grover, L. K. A fast quantum mechanical algorithm for database search. Tech. Rep

  3. [2]

    Shor, P. W. Polynomial-time algorithms for prime factor- ization and discrete logarithms on a quantum computer. Tech. Rep. (1997). Publication Title: Society for Indus- trial and Applied Mathematics Volume: 26 Issue: 5

  4. [3]

    Quantum algorithms: An overview.npj Quantum Information2(2016)

    Montanaro, A. Quantum algorithms: An overview.npj Quantum Information2(2016). ArXiv: 1511.04206

  5. [4]

    Boixo, S.et al.Characterizing quantum supremacy in near-term devices.Nature Physics14, 595–600 (2018)

  6. [5]

    W., Hassidim, A

    Harrow, A. W., Hassidim, A. & Lloyd, S. Quantum Algorithm for Linear Systems of Equations.Physical Review Letters103, 150502 (2009)

  7. [6]

    & Pan, J.-W

    Xu, F., Ma, X., Zhang, Q., Lo, H.-K. & Pan, J.-W. Secure quantum key distribution with realistic devices.Reviews of Modern Physics92, 025002 (2020)

  8. [7]

    & Tamaki, K

    Lo, H.-K., Curty, M. & Tamaki, K. Secure quantum key distribution.Nature Photonics8, 595–604 (2014)

Show all 37 references
  1. [8]

    Ekert, A. K. Quantum cryptography based on Bell’s theorem.Physical Review Letters67, 661–663 (1991)

  2. [9]

    H., Brassard, G

    Bennett, C. H., Brassard, G. & Mermin, N. D. Quantum cryptography without Bell’s theorem.Physical Review Letters68, 557–559 (1992)

  3. [10]

    Physical Review Applied20, 044006 (2023)

    Pelet, Y.et al.Operational entanglement-based quantum key distribution over 50 km of field-deployed optical fibers. Physical Review Applied20, 044006 (2023)

  4. [11]

    N.et al.Automated Distribution of Polarization-Entangled Photons Using Deployed New York City Fibers.PRX Quantum5, 030330 (2024)

    Craddock, A. N.et al.Automated Distribution of Polarization-Entangled Photons Using Deployed New York City Fibers.PRX Quantum5, 030330 (2024)

  5. [12]

    ArXiv: 2404.04958

    Kucera, S.et al.Demonstration of quantum network protocols over a 14-km urban fiber link (2024). ArXiv: 2404.04958

  6. [13]

    Sena, M.et al.High-fidelity quantum entanglement distri- bution in metropolitan fiber networks with co-propagating classical traffic.Journal of Optical Communications and Networking17, 1072 (2025)

  7. [14]

    Erste Group setzt neue Maßst¨ abe in der Quantenverschl¨ usselung (2026)

    Erste Group. Erste Group setzt neue Maßst¨ abe in der Quantenverschl¨ usselung (2026). Press release, 23 February 2026

  8. [15]

    K., Steinlechner, F., H¨ ubel, H

    Wengerowsky, S., Joshi, S. K., Steinlechner, F., H¨ ubel, H. & Ursin, R. An entanglement-based wavelength- multiplexed quantum communication network.Nature 564, 225–228 (2018)

  9. [16]

    K.et al.A trusted node–free eight-user metropoli- tan quantum communication network.SCIENCE AD- VANCES(2020)

    Joshi, S. K.et al.A trusted node–free eight-user metropoli- tan quantum communication network.SCIENCE AD- VANCES(2020)

  10. [17]

    L., Shamir, A

    Rivest, R. L., Shamir, A. & Adleman, L. A method for obtaining digital signatures and public-key cryptosystems 21(1978)

  11. [18]

    & Leverrier, A

    Diamanti, E. & Leverrier, A. Distributing Secret Keys with Quantum Continuous Variables: Principle, Security and Implementations.Entropy17, 6072–6092 (2015)

  12. [19]

    Liu, H.et al.Experimental Demonstration of High-Rate Measurement-Device-Independent Quantum Key Distri- bution over Asymmetric Channels.Physical Review Let- ters122, 160501 (2019)

  13. [20]

    Berrevoets, R. C.et al.Deployed measurement-device independent quantum key distribution and Bell-state mea- surements coexisting with standard internet data and networking equipment.Communications Physics5, 186 (2022)

  14. [21]

    Wang, S.et al.Twin-field quantum key distribution over 830-km fibre.Nature Photonics16, 154–161 (2022)

  15. [22]

    Liu, Y.et al.Experimental Twin-Field Quantum Key Dis- tribution over 1000 km Fiber Distance.Physical Review Letters130, 210801 (2023)

  16. [23]

    & Yamamoto, Y

    Waks, E., Zeevi, A. & Yamamoto, Y. Security of quantum key distribution with entangled photons against individual attacks.Physical Review A65, 052310 (2002)

  17. [24]

    Bennett, C. H. & Brassard, G. Quantum cryptography: Public key distribution and coin tossing. InProceedings of the IEEE International Conference on Computers, Sys- tems and Signal Processing, 175–179 (Bangalore, India, 1984)

  18. [25]

    Shor, P. W. & Preskill, J. Simple proof of security of the bb84 quantum key distribution protocol.Physical Review Letters85, 441–444 (2000)

  19. [26]

    Neumann, S.et al.Model for optimizing quantum key dis- tribution with continuous-wave pumped entangled-photon sources.Physical Review A104(2021)

  20. [27]

    Ortega, E. A.et al.Spatial and spectral characterization of photon pairs at telecommunication wavelengths from type-0 spontaneous parametric downconversion.Journal of the Optical Society of America B40, 165 (2023)

  21. [28]

    Spectral grids for WDM applications: DWDM frequency grid

    International Telecommunication Union. Spectral grids for WDM applications: DWDM frequency grid. Tech. Rep. Recommendation G.694.1, ITU-T (2020). URL https: //www.itu.int/rec/T-REC-G.694.1-202010-I/en

  22. [29]

    & Guo, G

    Zhang, C., Huang, Y., Liu, B., Li, C. & Guo, G. Spon- taneous Parametric Down-Conversion Sources for Multi- photon Experiments.Advanced Quantum Technologies4, 2000132 (2021)

  23. [31]

    & Nahar, S

    Wang, Z., Tupkary, D. & Nahar, S. Phase error estima- tion for passive detection setups with imperfections and memory effects (2025). 2508.21486

  24. [32]

    Gallager, R. G. Low-density parity-check codes.IRE Transactions on Information Theory8, 21–28 (1962)

  25. [33]

    & Arnold, D.-m

    Hu, X.-y., Eleftheriou, E. & Arnold, D.-m. Regular and irregular progressive edge-growth tanner graphs.IEEE Trans Inf Theory51(2002)

  26. [34]

    & Dholakia, A

    Hu, X.-Y., Eleftheriou, E., Arnold, D.-M. & Dholakia, A. Efficient implementations of the sum-product algorithm for decoding ldpc codes. InGLOBECOM’01. IEEE Global Telecommunications Conference (Cat. No.01CH37270), vol. 2, 1036–1036E vol.2 (2001). 8

  27. [35]

    2408.15758

    M¨ uller, R.et al.Performance of cascade and ldpc-codes for information reconciliation on industrial quantum key distribution systems (2024). 2408.15758

  28. [36]

    & Curchod, F

    Foreman, C., Yeung, R., Edgington, A. & Curchod, F. J. Cryptomite: A versatile and user-friendly library of ran- domness extractors.Quantum9, 1584 (2025)

  29. [37]

    Van Assche, G.Quantum Cryptography and Secret-Key Distillation(Cambridge University Press, Cambridge, UK, 2006)

Pith tools

Reviewed July 14, 2026 · model on record in the stance chip above.