REVIEW 3 major objections 5 minor 59 references
This paper reports the first BB84 QKD experiment whose finite-size security proof accounts for both imperfectly characterized detectors and a non-ideal single-photon source, yielding a secure key of about 2.16 million bits in 20 minutes.
Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →
T0 review · deepseek-v4-flash
2026-08-01 13:10 UTC pith:OYJAOVYJ
load-bearing objection A well-executed experimental BB84 paper whose headline security claim does not follow from the implementation as described, because the repeated random sequence breaks the independence assumption in the security proof. the 3 major comments →
Experimental quantum cryptography with single photons and imperfect devices
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
Core claim
Using a semiconductor quantum-dot single-photon source (multiphoton suppression g^(2)(0)=0.017±0.005, mean photon number 0.005±10%) and an electro-optic modulator for fast polarization-state encoding, the authors implement the BB84 protocol with a fully passive four-state SNSPD receiver. Their security proof, based on the entropic uncertainty relation and a phase-error estimation lemma for passive optics, treats beamsplitter ratio, detector efficiencies, and dark-count rates as known only within error margins (2.5%, 2.5%, and 50%), and the source's multiphoton probability as a range. After 20 minutes at an 80 MHz clock rate, with a basis-averaged QBER of 3.51% over 1.07×10^11 attempted round
What carries the argument
The proof rests on the entropic uncertainty relation (EUR), which converts a bound on the phase error rate—the error Alice and Bob would have seen had their Z-basis rounds been measured in the conjugate X basis—into a bound on Eve's information about the raw key. The phase-error bound (Lemma 1, quoted from a companion theory paper) uses separate estimates of the single-photon contribution to the key rounds (B_Single) and of the phase error (B_Error), expressed in observed counts, multiclick events, and X-basis errors, with device parameters a (basis-selection mismatch), δ (detector-efficiency mismatch), and qZ (dark-count contribution). Source maps absorb the real source's vacuum and multiph
Load-bearing premise
The load-bearing premise is that the phase-error bounds and the device parameters a, δ, and qZ quoted from the companion theory paper are correct and that the manuscript's mapping from the measured device ranges (2.5% beamsplitter, 2.5% efficiency, 50% dark-count uncertainty) into those parameters is valid; this mapping is not derived or numerically checked in the manuscript.
What would settle it
Re-evaluate Eq. (2) with a, δ, and qZ computed directly from the stated device ranges using an independent implementation of the companion paper's formulas (Eqs. D40, D41, E2). If the resulting B_Single and B_Error violate the observed click statistics, or if a Monte Carlo simulation placing the beamsplitter at 0.496-0.014, detector efficiencies at the edges of their 2.5% range, and dark counts at 1.5×10^-7 yields a phase-error bound that exceeds the experimental X-basis error rate, the claimed 2.16×10^6-bit key is unsupported.
If this is right
- A quantum-dot source with g^(2)(0) below 2% can run BB84 without decoy states and still be proven secure under conservative device assumptions.
- The measured 2.16×10^6-bit key in 20 minutes shows that imperfect-device accounting, while reducing the rate by about an order of magnitude, does not make QD-based QKD impractical.
- The security framework transfers to any passive linear-optics receiver whose beamsplitter and detector parameters are known within ranges, so the same proof can be reused for other hardware.
- Because the phase-error bound is tightened by better device characterization, improved calibration of beamsplitter ratios and detector efficiencies translates directly into longer keys.
- The experiment's dynamic polarization encoding removes one side channel (state-dependent intensity mismatch) without requiring multiple lasers or intensity modulators.
Where Pith is reading between the lines
- A natural next step is to close the gap the authors flag: combining source and detector imperfections in one EUR-based proof would likely recover a large part of the order-of-magnitude key-rate loss.
- The proof assumes independent per-round basis choices, but the experiment drives the EOM with one precompiled 10^5-digit random sequence repeated over 1.1×10^11 rounds; testing whether any cyclic structure in that sequence leaks information, or proving security under such repetition, would harden the implementation.
- The key number depends on a, δ, and qZ, whose formulas live in the companion paper; recomputing the key from the stated device ranges with an independent implementation of those formulas would settle whether 2.1579×10^6 bits is reproducible from this manuscript alone.
- The same setup could be pushed to GHz clock rates as the authors note, and adding a Trojan-horse/light-injection analysis would address the remaining source-side attack they explicitly leave open.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. This paper reports an implementation of BB84 using a quantum-dot single-photon source with dynamic polarization modulation and a passive four-state detector, and applies a finite-size security proof based on an entropic uncertainty relation. The proof imports detector-imperfection bounds from Ref. [1] and adds source-map bounds to account for multiphoton emission. For a 20-minute, 80-MHz run, the authors report 1.07×10^11 attempted rounds, 7.66×10^7 detections, a 3.51% basis-averaged QBER, and a computed key length of 2.1579×10^6 bits. The paper includes detailed device characterization, a blinking correction, and explicit security parameters.
Significance. If the security proof were valid for the implemented protocol, this would be a notable experimental step: a finite-size BB84 demonstration simultaneously accounting for imperfectly characterized passive detectors and non-negligible source multiphoton statistics, with a quantitative estimate of the cost of such accounting (roughly an order of magnitude in key rate). The experiment is described in unusual detail, including error margins on beamsplitter ratios, detector efficiencies, dark counts, and g^(2)(0), and the authors are candid about many limitations. However, the implementation's repeated QRNG basis sequence violates the independent-round randomness assumption of the proof, and the quantitative key-rate result depends on device-parameter mappings that are not stated in the manuscript. As a result, the central security and key-length claims are not currently established.
major comments (3)
- [Sec. II.A.2 and II.B; Appendix A.1.a] The implemented protocol does not satisfy the randomness assumption used in the security proof. The FPGA is fed a pre-compiled 10^5-quaternary-digit sequence from the ANU QRNG API, and Sec. II.B states that this sequence 'is repeated over the course of the protocol to obtain sufficient statistics' over 1.1×10^11 rounds. In Appendix A.1.a, the source-replacement scheme and the EUR bound treat each round's basis choice as independent with fixed probabilities p_A^Z and p_A^X (Eqs. A1-A2). With a repeated sequence, Eve can reconstruct the full basis sequence from the first period of public basis announcements and then knows the basis of every later round before transmission. She can intercept each photon, measure it in the known basis, record the bit, and resend a freshly prepared photon in that state. This attack introduces no additional QBER and can be combined with controlled loss to matc
- [Appendix A.2, Eqs. (A8)-(A10); Sec. II.B.1] The key-rate formula depends on parameters a, δ, and q_Z through Lemma 1, but the manuscript does not state their definitions or values. It refers only to 'Eq.'s D40, D41 and E2 respectively in Ref. [1]' (Sec. II.B.1) and says 'We refer to Ref. [1] for the exact expressions' (Appendix A.2). Ref. [1] is a co-authored preprint, not included in the manuscript, and no code or data reproducing it is shipped. The claimed secure key length is a direct numerical output of B_Single and B_Error with these parameters, so the calculation cannot be reproduced or independently checked from the information given. The authors should provide the explicit expressions (or an appendix derivation) and the numerical values used for the experimental run.
- [Sec. IIC, footnote 3; Sec. III (Conclusion)] The manuscript makes contradictory claims about what is proven. The abstract states that security is proven with source imperfections (finite g^(2)(0)) and receiver imperfections, while Sec. IIC, footnote 3 says 'The combination of source and detector imperfections for passive protocols in the EUR based approach is still open.' The Conclusion further says 'we are unable to account for source imperfections' while also saying the analysis accounts for 'source emission statistic imperfections.' These statements need to be reconciled. If the source-map argument in Appendix A.3 does cover multiphoton emission statistics, the wording of footnote 3 and the Conclusion is misleading; if it does not, the abstract overclaims the scope of the security proof. This ambiguity directly affects the paper's central claim.
minor comments (5)
- [Sec. II.B and Table I] The number of attempted rounds is given as '1.1·10^11 signal events' in Sec. II.B and as '1.07×10^11' in Table I; the notation '107364·10^6' in Table I is confusing. Please use a single consistent value and formatting.
- [Sec. II.A.3] There are typographical errors: 'associates s the this particular outcome with with' should read 'associates this particular outcome with'; 'contribue' should be 'contribute'; 'non-unital' in Appendix A.3 should probably be 'non-unit' or 'non-unit probability.'
- [Appendix B, Eq. (B1)] The blinking envelope function is written as C0 + m·e^{|τ+τ0|/τblink}, which appears to diverge for large |τ|; presumably a negative exponent was intended. Please correct the formula and ensure the fit parameters are consistent with the plot.
- [Sec. II.B.1, Fig. 4] The text says the simulation assumes lossless components in Bob's device, while the experiment has roughly 7 dB attenuation; the figure caption should clarify how the experimental data point is placed on the horizontal axis relative to the simulated loss scan.
- [Sec. II.A.2] The choice probabilities p_A^Z and p_A^X used in the proof are not reported for the implemented sequence. Since the 10^5-digit sequence may not contain exactly half Z and half X rounds, the actual basis statistics should be stated and checked against the values assumed in the security analysis.
Circularity Check
Central security bound is imported from an unverified, co-authored prior preprint (Ref. [1]), making the key-rate calculation load-bearing on a self-citation; otherwise the derivation is not circular.
specific steps
-
self citation load bearing
[Sec. II.B.1 Eq. (2); Appendix A Sec. 2, Lemma 1 (after Eq. A10)]
"Lemma 1 (Bounds on Phase Error Rate and Single Photon Detections with Passive Optics, Theorem 1 of [1].)... We refer to Ref. [1] for the exact expressions of a, δ and qZ (Eq.'s D40, D41 and E2, respectively)."
The key length (Eq. 2) is computed from B_Single_{qZ} and B_Error_{a,δ,qZ}, which are exactly the bounds quoted in Lemma 1. Rather than deriving these bounds, the paper cites 'Theorem 1 of [1]' and sends the reader to Ref. [1] for the definitions of a, δ and qZ. Ref. [1] (arXiv:2508.21486) is co-authored by two of the present authors (Z. Wang and D. Tupkary), and the paper ships no machine-checked proof or code to reproduce those expressions. The central security claim thus rests on an unverified self-citation rather than on a self-contained derivation; if Lemma 1 or the a/δ/qZ mapping is wrong, the 2.1579e6-bit key is unsupported.
full rationale
The core computation is an evaluation, not a circular prediction: observed counts, QBER, µ and g^(2)(0) are fed into standard EUR bounds, and the key length is the output; no fitted parameter is renamed as a prediction. The main circularity concern is the import of Lemma 1 from Ref. [1], a same-author preprint whose theorem and parameter expressions are not re-derived or machine-checked, making the proof-of-security claim load-bearing on a self-citation. This is partially circular (score 4) rather than fully so, because the experimental implementation, device characterization, blinking correction, and source-map estimation are independent contributions and the cited Lemma 1 is a general statistical bound, not an equation identical to the paper's data. Separate non-circular correctness risks: (i) the FPGA repeats a pre-compiled public 10^5-quaternary-digit QRNG sequence over 1.07e11 rounds, violating the independent-basis assumption of the source-replacement/EUR proof (Sec. II.A.2 and II.B; Appendix A.1.a); (ii) Appendix A says 'proof in full detail' but omits a,δ,q_Z, leaving the mapping from device uncertainty ranges to the key length unverifiable from this paper. These are omitted-support/assumption-violation issues, not additional circular steps.
Axiom & Free-Parameter Ledger
free parameters (4)
- Blinking envelope fit parameters (C0, m, τ0, τblink) =
C0=52.2±0.3; m=18.5±3.7; τ0=(-0.90±2.72) ns; τblink=(25.9±6.0) ns
- g^(2)(0) multiphoton suppression value =
0.017 ± 0.005 (30%) in Table I; ±0.001 (stat.) in Appendix B
- Security parameters ε_i =
10^-9 for ε_PNE, ε_a, ε_b, ε_0, ε_AT, ε_PA, ε_EV
- Z-basis testing fraction pTest =
1%
axioms (8)
- domain assumption Theorem 1 of Ref [1] (quoted as Lemma 1 here): the bounds B_Single and B_Error hold for a passive linear-optical BB84 analyzer with imperfect, bounded detector parameters
- domain assumption The QD source's emitted state is block-diagonal in Fock space (vanishing photon-number coherence)
- domain assumption Per-round emissions are independent and identically distributed with p_>1A = ½μ²g^(2)(0) (binomial statistics)
- domain assumption Alice's prepared polarization states are exactly the four ideal BB84 states
- domain assumption Alice's laboratory is isolated from Eve (no Trojan-horse / light-injection attacks)
- standard math Entropic Uncertainty Relation (Tomamichel–Renner) and the uncertainty-relation security reduction
- standard math The source-map channel Σ can be absorbed into Eve's channel without compromising security
- domain assumption Device characterization ranges (beamsplitter 2.5%, efficiencies 2.5%, dark counts 50%) are valid upper/lower bounds for the entire 20-minute run
invented entities (1)
-
Orthogonal flag states for multiphoton emission rounds
no independent evidence
read the original abstract
Quantum key distribution (QKD) allows for provably secure key distribution between two trusted parties. Because the security and performance of QKD protocols rely on devices that behave according to specific assumptions, idealized or inaccurate assumptions about device behavior can introduce security loopholes. Real devices can never be perfectly characterized, and their performance metrics are always subject to certain error margins, which must be accounted for in a rigorous theoretical analysis. Only recently have rigorous finite-size results allowed for imperfect characterizations of devices (where device parameter have uncertainty margins) - an advance yet to be considered in experimental implementations of the BB84 protocol. In this work, we prove the security and analyze the performance of an implementation of the BB84 protocol using single photons generated by a semiconductor quantum dot light source in combination with dynamic polarization-state encoding. We consider the presence of incompletely characterized devices by accounting for imperfections in the single-photon source (in terms of finite g(2)(0)) as well as the receiver (non-ideal beam-splitters, finite detector efficiencies, and dark counts), all with error margins. The resulting protocol implementation shows competitive performance, paving the way towards practical and loop-hole free implementations of QKD.
Figures
Reference graph
Works this paper leans on
-
[1]
Single Photon Generation For the generation of single photons Alice uses a deterministic single-photon source (SPS) based on a pre-selected InAs QD embedded in a hybrid circular Bragg grating cavity featuring pronounced Purcell enhancement [22]. The source emitting at about 920 nm is operated in a cryogenic environment at 4 K and is excited quasi-resonant...
-
[2]
Dynamic Polarization Modulation Alice dynamically and randomly prepares the polarization states to be sent to Bob using a customized fiber-coupled EOM controlled by a custom-built arbitrary waveform generator consisting of a field programmable gate array (FPGA) evolution board and a 16-bit digital to analog converter (DAC). The FPGA is fed with a pre-comp...
-
[3]
State detection Polarization encoded photons are detected in a four-state polarization analyzer comprised of a 50:50 beamsplitter at the input of the free space channel which steers photons towards either theXorZbasis detectors completely passively. Each basis detection is comprised of a polarizing beamsplitter polarized in the respective basis, followed ...
-
[4]
factor out
Key Rate Performance During the performance of the protocol Alice and Bob generate an array of observed data statistics, which we collectively denote as⃗ nobs. This includes all of the click patterns (including no-clicks) observed during the run of the experiment, which we can sift through to compute the number of conclusive detections in each basis and t...
-
[5]
Z. Wang, D. Tupkary, and S. Nahar, Phase error estimation for passive detection setups with imperfections and memory effects (2025), arXiv:2508.21486 [quant-ph]
arXiv 2025
- [6]
-
[7]
Nahar,A proof-technique-independent framework for detector imperfections in QKD, Ph.D
S. Nahar,A proof-technique-independent framework for detector imperfections in QKD, Ph.D. thesis, University of Waterloo (2026)
2026
- [8]
-
[9]
G. Currás-Lorenzo, M. Pereira, S. Nahar, and D. Tupkary, Security of quantum key distribution with source and detector imperfections through phase-error estimation (2025), arXiv:2507.03549 [quant-ph]
Pith/arXiv arXiv 2025
-
[10]
Currás-Lorenzo, M
G. Currás-Lorenzo, M. Pereira, G. Kato, M. Curty, and K. Tamaki, Security framework for quantum key distribution with imperfect sources, Optica Quantum3, 525 (2025)
2025
-
[11]
G. Currás-Lorenzo, M. Pereira, K. Tamaki, and M. Curty, Rigorous phase-error-estimation security framework for qkd with correlated sources (2026), arXiv:2601.08417 [quant-ph]
arXiv 2026
-
[12]
F. Xu, X. Ma, Q. Zhang, H.-K. Lo, and J.-W. Pan, Secure quantum key distribution with realistic devices, Reviews of Modern Physics92, 10.1103/revmodphys.92.025002 (2020)
-
[13]
V. Zapatero, A. Navarrete, and M. Curty, Implementation security in quantum key distribution, Advanced Quantum Technologies8, 2300380 (2025), https://advanced.onlinelibrary.wiley.com/doi/pdf/10.1002/qute.202300380
-
[14]
J.-X. Li, F.-Y. Lu, Z.-H. Wang, V. Zapatero, M. Curty, S. Wang, Z.-Q. Yin, W. Chen, D.-Y. He, G.-C. Guo, and Z.- F. Han, Quantum key distribution overcoming practical correlated intensity fluctuations, npj Quantum Information11, 10.1038/s41534-025-01059-0 (2025)
-
[15]
Tomamichel and R
M. Tomamichel and R. Renner, Uncertainty relation for smooth entropies, Physical review letters106, 110506 (2011)
2011
-
[16]
Tomamichel and A
M. Tomamichel and A. Leverrier, A largely self-contained and complete security proof for quantum key distribution, Quantum1, 14 (2017). 10
2017
-
[17]
Huttner, N
B. Huttner, N. Imoto, N. Gisin, and T. Mor, Quantum cryptography with coherent states, Physical Review A51, 1863 (1995)
1995
-
[18]
J. Calsamiglia, S. M. Barnett, and N. Lütkenhaus, Conditional beam-splitting attack on quantum key distribution, Physical Review A65, 10.1103/physreva.65.012312 (2001)
-
[19]
Hwang, Quantum key distribution with high loss: toward global secure communication, Physical review letters91, 057901 (2003)
W.-Y. Hwang, Quantum key distribution with high loss: toward global secure communication, Physical review letters91, 057901 (2003)
2003
-
[20]
H.-K. Lo, X. Ma, and K. Chen, Decoy state quantum key distribution, Phys. Rev. Lett.94, 230504 (2005)
2005
-
[21]
Wang, Beating the photon-number-splitting attack in practical quantum cryptography, Phys
X.-B. Wang, Beating the photon-number-splitting attack in practical quantum cryptography, Phys. Rev. Lett.94, 230503 (2005)
2005
-
[22]
X. Ding, Y.-P. Guo, M.-C. Xu, R.-Z. Liu, G.-Y. Zou, J.-Y. Zhao, Z.-X. Ge, Q.-H. Zhang, H.-L. Liu, L.-J. Wang, M.-C. Chen, H. Wang, Y.-M. He, Y.-H. Huo, C.-Y. Lu, and J.-W. Pan, High-efficiency single-photon source above the loss-tolerant threshold for efficient linear optical quantum computing (2023), arXiv:2311.08347 [quant-ph]
Pith/arXiv arXiv 2023
-
[23]
N. Tomm, A. Javadi, N. O. Antoniadis, D. Najer, M. C. Löbl, A. R. Korsch, R. Schott, S. R. Valentin, A. D. Wieck, A. Ludwig, and R. J. Warburton, A bright and fast source of coherent single photons, Nature Nanotechnology16, 399–403 (2021)
2021
-
[24]
Somaschi, V
N. Somaschi, V. Giesz, L. De Santis, J. C. Loredo, M. P. Almeida, G. Hornecker, S. L. Portalupi, T. Grange, C. An- tón, J. Demory, C. Gómez, I. Sagnes, N. D. Lanzillotti-Kimura, A. Lemaítre, A. Auffeves, A. G. White, L. Lanco, and P. Senellart, Near-optimal single-photon sources in the solid state, Nature Photonics10, 340–345 (2016)
2016
-
[25]
L. Schweickert, K. D. Jöns, K. D. Zeuner, S. F. Covre da Silva, H. Huang, T. Lettner, M. Reindl, J. Zichi, R. Trotta, A. Rastelli, and V. Zwiller, On-demand generation of background-free single photons from a solid-state source, Applied Physics Letters112, 10.1063/1.5020038 (2018)
-
[26]
Rickert, D
L. Rickert, D. A. Vajner, M. von Helversen, J. Schall, S. Rodt, S. Reitzenstein, H. Liu, S. Li, H. Ni, Z. Niu, and T. Hein- del, High purcell enhancement in quantum-dot hybrid circular bragg grating cavities for ghz clock rate generation of indistinguishable photons, ACS Photonics12, 464–475 (2024)
2024
-
[27]
Rickert, K
L. Rickert, K. Żołnacz, D. A. Vajner, M. von Helversen, S. Rodt, S. Reitzenstein, H. Liu, S. Li, H. Ni, P. Wyborski, G. Sęk, A. Musiał, Z. Niu, and T. Heindel, A fiber-pigtailed quantum dot device generating indistinguishable photons at ghz clock-rates, Nanophotonics14, 1795–1808 (2025)
2025
-
[28]
J.L.O’Brien,Opticalquantumcomputing,Science318,1567(2007),https://www.science.org/doi/pdf/10.1126/science.1142892
-
[29]
M. Pereira, G. Currás-Lorenzo, Álvaro Navarrete, A. Mizutani, G. Kato, M. Curty, and K. Tamaki, Modified bb84 quantum key distribution protocol robust to source imperfections (2022), arXiv:2210.11754 [quant-ph]
Pith/arXiv arXiv 2022
-
[30]
D. A. Vajner, K. Kaymazlar, F. Drauschke, L. Rickert, M. von Helversen, H. Liu, S. Li, H. Ni, Z. Niu, A. Pappa, and T. Heindel, Single-photon advantage in quantum cryptography beyond qkd, Nature Communications17, 2074 (2026)
2074
-
[31]
https://qrng.anu.edu.au/,
-
[32]
D. Tupkary, E. Y. Z. Tan, S. Nahar, L. Kamin, and N. Lütkenhaus, Qkd security proofs for decoy-state bb84: protocol variations, proof techniques, gaps and limitations (2025), arXiv:2502.10340 [quant-ph]
Pith/arXiv arXiv 2025
-
[33]
D. Tupkary, S. Nahar, and E. Y. Z. Tan, Authentication in security proofs for quantum key distribution (2026), arXiv:2601.17960 [quant-ph]
arXiv 2026
-
[34]
D. Tupkary, S. Nahar, A. Arqand, E. Y. Z. Tan, and N. Lütkenhaus, A rigorous and complete security proof of decoy-state bb84 quantum key distribution (2026), arXiv:2601.18035 [quant-ph]
arXiv 2026
-
[35]
Zahidy, M
M. Zahidy, M. T. Mikkelsen, R. Müller, B. Da Lio, M. Krehbiel, Y. Wang, N. Bart, A. D. Wieck, A. Ludwig, M. Galili, et al., Quantum key distribution using deterministic single-photon sources over a field-installed fibre link, npj Quantum Information10, 2 (2024)
2024
-
[36]
C. L. Morrison, R. G. Pousa, F. Graffitti, Z. X. Koong, P. Barrow, N. G. Stoltz, D. Bouwmeester, J. Jeffers, D. K. Oi, B. D. Gerardot,et al., Single-emitter quantum key distribution over 175 km of fibre with optimised finite key rates, Nature Communications14, 3573 (2023)
2023
-
[37]
J. Yang, Z. Jiang, F. Benthin, J. Hanel, T. Fandrich, R. Joos, S. Bauer, S. Kolatschek, A. Hreibi, E. P. Rugeramigabo,et al., High-rate intercity quantum key distribution with a semiconductor single-photon source, Light: Science & Applications 13, 150 (2024)
2024
-
[38]
Tamaki, M
K. Tamaki, M. Curty, G. Kato, H.-K. Lo, and K. Azuma, Loss-tolerant quantum cryptography with imperfect sources, Physical Review A90, 052314 (2014)
2014
-
[39]
Tupkary, S
D. Tupkary, S. Nahar, P. Sinha, and N. Lütkenhaus, Phase error rate estimation in qkd with imperfect detectors, Quantum 9, 1937 (2025)
1937
-
[40]
Dennis,Photodetectors: an introduction to current technology(Springer Science & Business Media, 2012)
P. Dennis,Photodetectors: an introduction to current technology(Springer Science & Business Media, 2012). 11
2012
-
[41]
MizutaniandG.Kato,Securityofround-robindifferential-phase-shiftquantum-key-distributionprotocolwith correlated light sources, Physical Review A104, 062611 (2021)
A. MizutaniandG.Kato,Securityofround-robindifferential-phase-shiftquantum-key-distributionprotocolwith correlated light sources, Physical Review A104, 062611 (2021)
2021
-
[42]
R. Behrends, L. Rickert, N. D. Kewitz, M. v. Helversen, P. K. Saha, M. Lach, J. Kaupp, Y. Reum, Tobias-Huber- Loyola, S. Höfling, A. Pfenning, and T. Heindel, Gigahertz-clocked generation of highly indistinguishable photons at c-band wavelengths, arXiv (2026), arXiv:2603.26651 [cond-mat.mes-hall]
arXiv 2026
-
[43]
Ferenczi and N
A. Ferenczi and N. Lütkenhaus, Symmetries in quantum key distribution and the connection between optimal attacks and optimal cloning, Phys. Rev. A85, 052310 (2012)
2012
-
[44]
Tomamichel, C
M. Tomamichel, C. C. W. Lim, N. Gisin, and R. Renner, Tight finite-key analysis for quantum cryptography, Nature communications3, 634 (2012)
2012
-
[45]
D. Gottesman, H.-K. Lo, N. Lütkenhaus, and J. Preskill, Security of quantum key distribution with imperfect devices (2004), arXiv:quant-ph/0212066 [quant-ph]
Pith/arXiv arXiv 2004
-
[46]
J. C. Loredo, C. Antón, B. Reznychenko, P. Hilaire, A. Harouri, C. Millet, H. Ollivier, N. Somaschi, L. De Santis, A. Lemaître, I. Sagnes, L. Lanco, A. Auffèves, O. Krebs, and P. Senellart, Generation of non-classical light in a photon- number superposition, Nature Photonics13, 803–808 (2019)
2019
-
[47]
Nahar, D
S. Nahar, D. Tupkary, Y. Zhao, N. Lütkenhaus, and E. Y.-Z. Tan, Postselection technique for optical quantum key distribution with improved de finetti reductions, PRX Quantum5, 040315 (2024)
2024
-
[48]
C. J. Clopper and E. S. Pearson, The use of confidence or fiducial limits illustrated in the case of the binomial, Biometrika 26, 404 (1934)
1934
-
[49]
Szekely,Statistics for the 21st Century: Methodologies for Applications of the Future(CRC Press, 2000)
G. Szekely,Statistics for the 21st Century: Methodologies for Applications of the Future(CRC Press, 2000). Appendix A: Entropic Uncertainty Relation Security Proof The security of QKD protocols depends on formalizing the idea that an eavesdropper is limited in how much information she can learn about the produced key [28]. To do so, it is necessary to spe...
2000
-
[50]
We explain how these are used in proving QKD security
In Section 1, we begin by specifying the entropic uncertainty relation as well as the source replacement scheme, two integral components to proving security of our QKD implementation. We explain how these are used in proving QKD security
-
[51]
[1], which provides statistical bounds on the required quantities for proving security
In Section 2, we then recap work done in Ref. [1], which provides statistical bounds on the required quantities for proving security. We further specify how these bounds change in the presence of imperfect single photon sources
-
[52]
In Section 3, we elaborate on how to compute the needed multiphoton event bounds described in the above subsection by specifying source maps
-
[53]
In Section 4, we finally compute the final key rate and security parameters, as well as recap the appendix
-
[54]
Source Replacement Schemes and the Entropic Uncertainty Relation a. Source Replacement Scheme In order to prove the security of prepare and measure (P&M) protocols, it is often more convenient to reformulate these as entanglement based protocols via the source replacement scheme [39]. Instead of Alice preparing a state in every round and sending through a...
-
[55]
(A5), there are two quantities which must be estimated from the measured protocol quantities, namelyn Z,1 A,1B ande Ph
Passive Protocol EUR Bounds Clearly, in Eq. (A5), there are two quantities which must be estimated from the measured protocol quantities, namelyn Z,1 A,1B ande Ph. Z,1 A,1B. Statistical bounds must be rigorously proven in the presence of finite size effects, device imperfections and the possibility of receiving more than a single photon in Bob’s detectors...
-
[56]
one that always emits single photons
Imperfect source bounds and source maps Lemma 1 can be easily applied if it is assumed Alice is in possession of a perfect single photon source, i.e. one that always emits single photons. In a practical QKD implementation, Alice does not have access to such a source but instead emits single photons with some non-unital probability, while emitting zero or ...
-
[57]
(Lower bound onnZ,1 A) : In order to compute this bound, we first remark thatnZ,1 A =n Z −n Z,>1 A, so the problem can be reformulated as finding a high probability upper bound onnZ,>1 A. We do so in steps, and the first trivial bound is of the formPr[nZ,>1 A ≤n >1A ] = 1, which implies X n>1A Pr[n>1A =n >1A ]Pr[nZ,>1 A ≤n >1A ] = Pr[nZ,>1 A ≤n >1A ] = 1,...
-
[58]
Code for this implementation in order to judge the differences in performance is available in the included GitHub repository
(Upper bounds onn X,1 A,n mc,1A andN obs X,1 A) : Since we cannot make any type of statement on how little, if any, of theXbasis rounds came from multiphoton emissions, we only get a trivial bound of the form Pr[nX,1 A ≤n X ] = 1,(A22) these vacuum emissions directly with other statistical bounds, but these complicate the analysis. Code for this implement...
-
[59]
We find that the updated bounds, which are now computable in terms of observed protocol quantities, are Pr nZ,1 A,1B ≤ BSingle qZ nZ −J −1 pU >1A ,n(ε2 Z,1 A ), nmc,1A ∨ ePh
Combining Bounds and Key Rate Calculation The combinations of the above bounds are trivial via a simple application of union bounds. We find that the updated bounds, which are now computable in terms of observed protocol quantities, are Pr nZ,1 A,1B ≤ BSingle qZ nZ −J −1 pU >1A ,n(ε2 Z,1 A ), nmc,1A ∨ ePh. Z,1 A,1B ≥ BError a,δ,qZ nX , nZ −J −1 pU >1A ,n(...
discussion (0)
Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.