REVIEW 3 major objections 6 minor 39 references
Enhancing the security of coherent one-way quantum key distribution using CHSH correlations
T0 review · 3 major / 6 minor · reviewed 2026-07-30 · grok-4.5
Pith's one-line read Monitoring Bell correlations instead of pulse coherence lets COW quantum key distribution reach about 259 km with linear rate scaling.
desk verdict Modest hardware tweak plus CHSH monitoring gives COW nice simulated range, but the qubit entropy bound is applied to coherent states without a real reduction. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The Woodhead–Pironio min-entropy bound Hmin(A|E) ≥ 1 - log2(1 + √(2 - S²/4)), which converts the observed CHSH parameter S into a lower bound on Eve’s uncertainty and thereby into the key-rate formula R ≥ Qz [1 - log2(1 + √(2 - S²/4)) - fEC h(Ez)].
What would settle it
Run the modified protocol over a calibrated loss channel and check whether the measured CHSH value S and QBER produce a positive asymptotic key rate that continues to scale linearly with transmittance out to distances well beyond 20 km; any systematic failure of S to stay above 2, or a return to quadratic scaling, would falsify the claim.
Extended reading notes
Core claim
Replacing adjacent-pulse coherence monitoring in COW-QKD with a CHSH Bell test (plus one extra decoy state and a retuned Mach–Zehnder interferometer) yields an asymptotic secret-key rate that scales linearly with channel transmittance and extends the simulated secure distance to approximately 259 km.
Load-bearing premise
The security bound that links CHSH violation to secret-key rate is assumed to apply directly to this infinite-dimensional coherent-state protocol once the weak-pulse X-basis states are treated as approximate qubits.
Editorial extensions
If this is right
- Existing COW hardware can be upgraded to longer secure distances by adding one decoy intensity/phase setting and retuning the monitoring interferometer to 85:15 plus a switchable phase.
- Secret-key rate recovers linear scaling with channel transmittance (reported R ≈ 0.002 η), matching the scaling of decoy-state BB84 rather than earlier unconditional COW analyses.
- Zero-error attacks that preserve pulse coherence but break Bell correlations become detectable through the CHSH monitor.
- The same CHSH-monitoring idea can be ported, with only minor optical changes, to other coherent-state or distributed-phase-reference QKD schemes.
Reading between the lines
- Because the security argument rests on an effective qubit bound, any experimental demonstration must also verify that multi-photon and higher-dimensional leakage remain negligible under the chosen mean photon number.
- Finite-key analysis and composable security proofs for the CHSH-monitored COW variant are natural next steps before field deployment.
- If the linear scaling holds under realistic detector dark counts and misalignment, metropolitan and short-haul backbone links become realistic targets for upgraded COW systems.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The manuscript proposes a modified coherent-one-way (COW) QKD protocol in which adjacent-pulse coherence monitoring is replaced by a CHSH test in Bob’s monitoring line, together with one additional X-basis decoy state on Alice’s side. Bob’s Mach–Zehnder interferometer is retuned (50:50 + 85:15 beam splitters and a 0/π phase) so that the monitoring line implements the CHSH observables B1=(\sigma z+\sigma x)/√2 and B2=(\sigma z−\sigma x)/√2. Security is argued via the Woodhead–Pironio prepare-and-measure min-entropy bound Hmin(A|E)≥1−log2(1+√(2−S²/4)) (Eq. 15), yielding the asymptotic rate R≥Qz[1−log2(1+√(2−S²/4))−fEC h(Ez)] (Eq. 16). Simulations with ea=1%, dark-count probability 10−8 and ηd=90% report linear scaling R≈0.002η and a maximum secure distance of ~259 km, substantially beyond recent COW bounds that scale as O(η²).
Significance. If the security reduction holds, the work would restore linear transmittance scaling for a practically relevant DPR protocol and push the simulated secure distance from the sub-20 km / ~100 km regime of recent unconditional analyses to ~259 km, with only modest hardware changes. The optical construction of the CHSH bases (Appendix A) and the explicit ideal correlators giving S=2√2 (Appendix B) are carefully done, and the authors release simulation code and data on Zenodo, which supports reproducibility. The conceptual move—importing a prepare-and-measure CHSH monitor into COW—is interesting and could be useful more broadly. The significance, however, is conditional on a rigorous justification that the qubit-bounded entropy formula applies to the actual coherent-state implementation.
major comments (3)
- [Security Analysis, Eqs. (15)–(16)] Eqs. (15)–(16) and the citation to Woodhead–Pironio (Ref. 37): the min-entropy bound is proven under an explicit qubit (or bounded-dimension) assumption on Alice’s preparations. The protocol prepares weak coherent time-bin states (Eqs. 2, 6–7), with X states only informally approximated by “∼” for α≪1. The manuscript never quantifies the weight outside the single-photon early/late subspace, the multi-photon component, or the resulting degradation of Hmin(A|E). Without a dimension-reduction or leakage argument, an observed monitoring-line S does not, by the cited theorem, lower-bound Eve’s uncertainty on the data-line key, nor does it automatically rule out zero-error-class attacks that exploit the larger Hilbert space. This reduction is load-bearing for the linear-rate and 259 km claims and must be supplied or the security statement appropriately weakened.
- [Introduction; Security Analysis; Conclusion] Protocol description / Security Analysis: the text frames the scheme as semi-device-independent and claims detection of a “broader class of potential attacks,” including those that leave adjacent-pulse coherence intact. Under collective i.i.d. attacks the rate formula is standard once Hmin(S) is granted, but the manuscript does not show that CHSH monitoring in the modified line excludes the known zero-error attack of Trenyi–Curty (or analogous attacks) when multi-photon and vacuum components are present. A concrete argument—either a reduction to the qubit case with explicit error terms, or a direct attack analysis under the optical model—is needed to support the central security claim.
- [simulation Results, Figs. 3–4] Simulation Results and Figs. 3–4: the reported R≈0.002η and 259 km are obtained by feeding the simulated S(Q) directly into Eq. (16). Because that step inherits the unproven qubit reduction, the numerical comparison with Refs. 28 and 32 (which aim at unconditional or tighter COW analyses) is not yet on equal footing. Either the reduction must be established with quantitative bounds that remain valid at the simulated μ and distances, or the figures should be clearly labeled as performance under the qubit-SDI assumption rather than as an unconditional improvement of COW.
minor comments (6)
- [Protocol description, Eq. (2)] Eq. (2): the symbol “∼” for the X-basis states should be replaced by an explicit fidelity or trace-distance bound in α, even if only in an appendix, so that the approximation error is trackable.
- [Fig. 1; §0.3] Fig. 1 caption and main text: the decoy labels |f1⟩, |f2⟩ vs |0x⟩, |1x⟩ are used interchangeably; unify notation.
- [Modified Protocol; simulation Results] The security thresholds S0 and Q0 are mentioned but never specified numerically for the simulations; state the values used to declare a positive key rate out to 259 km.
- [§0.4 secret key rate formula] Finite-key analysis is outlined (smooth min-entropy, leftover hash) but the reported rates are purely asymptotic. A short remark on how finite-size corrections would affect the 259 km figure would help the reader.
- [Conclusion; References] Typos / style: “notably,” mid-sentence in the Conclusion; “ass-block” in Ref. 24; inconsistent spacing in |α/√2⟩ kets. Also arXiv id 2607.26856 looks nonstandard (year 2607)—verify metadata.
- [Appendix A] Appendix A: the cyclic identification a′3→a′1 for the virtual mode is fine for vacuum, but a one-line remark that no physical amplitude occupies that mode under the protocol’s two-bin inputs would remove any ambiguity.
Circularity Check
No significant circularity: the asymptotic rate is an external CHSH min-entropy bound applied to independently computed monitoring statistics, not a quantity forced by its own inputs.
full rationale
The load-bearing security formula (Eq. 16) is R ≥ Qz [1 − log2(1+√(2−S²/4)) − fEC h(Ez)], obtained by substituting the Woodhead–Pironio prepare-and-measure CHSH bound Hmin(A|E) ≥ 1−log2(1+√(2−S²/4)) (Eq. 15, citing Ref. 37) into a standard leftover-hashing asymptotic rate. S is defined from detector click counts (Eq. 17) and, in the ideal case, is derived from the MZI transfer matrix and coherent-state amplitudes in Appendix B, yielding S=2√2 by direct calculation rather than by assuming the key rate. The simulation then evaluates S(L) and Q(L) under a channel/detector model and plugs those values into Eq. 16; it does not fit a free parameter to a target rate and re-label the fit as a prediction. Ref. 37 is by different authors (Woodhead & Pironio), so there is no self-citation chain. The α≪1 qubit approximation and the applicability of the qubit-bounded entropy inequality to infinite-dimensional coherent states are modeling/correctness assumptions, not circular reductions of the claimed derivation to its inputs. No step reduces Eq. 16 or the 259 km figure to a tautology or a fitted input renamed as output.
Assumptions & free parameters
free parameters (6)
- misalignment ea =
1%
- dark-count probability =
1e-8 (main); 1e-7 (comparison)
- detector efficiency ηd =
90% / 99%
- error-correction inefficiency fEC =
1.1
- decoy fraction f, mean photon number μ, data-line transmittance tB
- security thresholds S0, Q0
assumptions (6)
- domain assumption Woodhead–Pironio bound: Hmin(A|E) ≥ 1 − log2(1 + sqrt(2 − S^2/4)) for prepare-and-measure CHSH with a qubit dimension constraint.
- domain assumption X-basis coherent states approximate qubit superpositions when α ≪ 1 (|0x⟩,|1x⟩ in Eq. 2).
- domain assumption Asymptotic i.i.d. collective attacks suffice for the claimed rate and scaling (smooth min-entropy → n Hmin).
- domain assumption Quantum channel acts as a beamsplitter loss channel with constant misalignment; detections are Poissonian with given dark counts.
- ad hoc to paper CHSH correlators estimated from monitoring-line clicks (Eq. 17) with DM1/DM2 mapped to ±1 certify the same S that enters the entropy bound.
- standard math Standard leftover-hashing / cascade EC leakage bounds in the asymptotic limit (Eqs. 8–14).
invented entities (1)
-
Modified COW monitoring line realizing B1=(σz+σx)/√2 and B2=(σz−σx)/√2 via 50:50 + 85:15 MZI and phase 0/π
Cite this review
Pith. "Pith review of Enhancing the security of coherent one-way quantum key distribution using CHSH correlations." pith.science (2026). https://pith.science/paper/YCQYVGSF
@misc{pith2026260726856,
author = {Pith},
title = {Pith review of: Enhancing the security of coherent one-way quantum key distribution using CHSH correlations},
year = {2026},
howpublished = {\url{https://pith.science/paper/YCQYVGSF}},
note = {Machine review of arXiv:2607.26856}
}
read the original abstract
The coherent one-way (COW) protocol is a quantum key distribution scheme that has attracted significant attention, leading to the development and commercialization of practical implementations. Despite this progress, the security of the COW protocol has remained a fundamental challenge since its introduction. Numerous studies have investigated its security, and several security proofs have been proposed over the years. More recently, a number of works have questioned the security of this protocol. In particular, one of the latest studies introduced an attack that severely limits the security of COW-QKD and reported a maximum secure distance of less than 20km. In this work, we introduce minimal alteration to the COW protocol that can enhance its security. Specifically, instead of monitoring the coherence between successive pulses, we propose to monitor quantum correlations through the violation of Bell inequalities. This approach enables the detection of a broader class of potential attacks. Our simulation results indicate that, by employing this method, the maximum secure distance of the protocol can be extended to approximately 259km.
Figures
Figures from the paper (2 more)
Reference graph
Works this paper leans on
-
[1]
Bennett, C. H. & Brassard, G. Quantum cryptography: Public key distribution and coin tossing.Proc. IEEE Int. Conf. on Comput.Systems and Signal Processing, 175–179, DOI: https://doi.org/10.1016/j.tcs.2014.05.025 (1984)
-
[2]
Ekert, A. K. Quantum cryptography based on bell’s theorem.Phys. Rev. Lett.67, 661, DOI: https://doi.org/10.1103/ PhysRevLett.67.661 (1991)
1991
-
[3]
Scarani, V .et al.The security of practical quantum key distribution.Rev. Mod. Phys.81, 1301, DOI: https://doi.org/10. 1103/RevModPhys.81.1301 (2009)
2009
-
[4]
Xu, F., Ma, X., Zhang, Q., Lo, H.-K. & Pan, J.-W. Secure quantum key distribution with realistic devices.Rev. Mod. Phys. 92, 025002, DOI: https://doi.org/10.1103/RevModPhys.92.025002 (2020)
-
[5]
Pirandola, S.et al.Advances in quantum cryptography.Adv. Opt. Photon.12, 1012, DOI: https://doi.org/10.1364/AOP. 361502 (2020)
doi:10.1364/aop 2020
-
[6]
Lütkenhaus, N. & Jahma, M. Quantum key distribution with realistic states: photon-number statistics in the photon-number splitting attack.New J. Phys.4, 344, DOI: https://doi.org/10.1088/1367-2630/4/1/344 (2002)
-
[7]
Quantum key distribution with high loss: toward global secure communication.Phys
Hwang, W.-Y . Quantum key distribution with high loss: toward global secure communication.Phys. Rev. Lett.91, 057901, DOI: https://doi.org/10.1103/PhysRevLett.91.057901 (2003)
-
[8]
& Chen, K
Lo, H.-K., Ma, X. & Chen, K. Decoy state quantum key distribution.Phys. Rev. Lett.94, 230503, DOI: https://doi.org/10. 1103/PhysRevLett.94.230504 (2005)
2005
Show all 39 references
-
[9]
Unconditional security of coherent-state quantum key distribution with strong phase-reference pulse.Phys
Koashi, M. Unconditional security of coherent-state quantum key distribution with strong phase-reference pulse.Phys. Rev. Lett.93, 120501, DOI: https://doi.org/10.1103/PhysRevLett.93.120501 (2004)
2004 doi
-
[10]
& Gisin, N
Scarani, V ., Acin, A., Ribordy, G. & Gisin, N. Quantum cryptography protocols robust against photon number splitting attacks for weak laser pulses implementations.Phys. Rev. Lett.92, 057901, DOI: https://doi.org/10.1103/PhysRevLett.92. 057901 (2004)
2004 doi
-
[11]
& Yamamoto, Y
Inoue, K., Waks, E. & Yamamoto, Y . Differential phase shift quantum key distribution.Phys. Rev. Lett.89, 037902, DOI: https://doi.org/10.1103/PhysRevLett.89.037902 (2002)
2002 doi
-
[12]
& Yamamoto, Y
Inoue, K., Waks, E. & Yamamoto, Y . Differential-phase-shift quantum key distribution using coherent light.Phys. Rev. A 68, 022317, DOI: https://doi.org/10.1103/PhysRevA.68.022317 (2003)
2003 doi
-
[14]
& Koashi, M
Sasaki, T., Yamamoto, Y . & Koashi, M. Practical quantum key distribution protocol without monitoring signal disturbance. Nature509, 475, DOI: https://doi.org/10.1038/nature13303 (2014)
2014 doi
-
[15]
& Tamaki, K
Hatakeyama, Y ., Mizutani, A., Kato, G., Imoto, N. & Tamaki, K. Differential-phase-shift quantum-key-distribution protocol with a small number of random delays.Phys. Rev. A95, 042301, DOI: https://doi.org/10.1103/PhysRevA.95.042301 (2017)
2017 doi
-
[16]
& Zbinden, H
Stucki, D., Brunner, N., Gisin, N., Scarani, V . & Zbinden, H. Fast and simple one-way quantum key distribution.Appl. Phys. Lett.87, 194108, DOI: https://doi.org/10.1063/1.2126792 (2005)
2005 doi
-
[17]
Express17, 13326, DOI: https://doi.org/10.1364/OE.17.013326 (2009)
Stucki, D.et al.Continuous high speed coherent one-way quantum key distribution.Opt. Express17, 13326, DOI: https://doi.org/10.1364/OE.17.013326 (2009)
2009 doi
-
[18]
Phys.11, 075003, DOI: https://doi.org/10.1088/1367-2630/11/7/075003 (2009)
Stucki, D.et al.High rate, long-distance quantum key distribution over 250 km of ultra low loss fibres.New J. Phys.11, 075003, DOI: https://doi.org/10.1088/1367-2630/11/7/075003 (2009)
2009 doi
-
[19]
Phys.16, 013047, DOI: https://doi.org/10.1088/1367-2630/16/1/013047 (2014)
Walenta, N.et al.A fast and versatile quantum key distribution system with hardware key distillation and wavelength multiplexing.New J. Phys.16, 013047, DOI: https://doi.org/10.1088/1367-2630/16/1/013047 (2014)
2014 doi
-
[20]
Photonics9, 163, DOI: https://doi.org/10.1038/nphoton.2014.327 (2015)
Korzh, B.et al.Provably secure and practical quantum key distribution over 307 km of optical fibre.Nat. Photonics9, 163, DOI: https://doi.org/10.1038/nphoton.2014.327 (2015)
2014 doi
-
[21]
Commun.8, 2041, DOI: https://doi.org/10.1038/ncomms13984 (2017)
Sibson, P.et al.Chip-based quantum key distribution.Nat. Commun.8, 2041, DOI: https://doi.org/10.1038/ncomms13984 (2017)
-
[22]
Sibson, P.et al.Integrated silicon photonics for high-speed quantum key distribution.Optica4, 179, DOI: https: //doi.org/10.1364/OPTICA.4.000172 (2017). 14/15
2017 doi
-
[23]
L.et al.Manipulating photon coherence to enhance the security of distributed phase reference quantum key distribution.Appl
Roberts, G. L.et al.Manipulating photon coherence to enhance the security of distributed phase reference quantum key distribution.Appl. Phys. Lett.111, 261106, DOI: https://doi.org/10.1063/1.5004488 (2017)
2017 doi
-
[24]
& Yang, L
Dai, J., Zhang, L., Fu, X., Zheng, X. & Yang, L. ass-block architecture for distributed-phase-reference quantum key distribution using silicon photonics.Opt. Lett.45, 2014, DOI: https://doi.org/10.1364/OL.388654 (2020)
2014 doi
-
[25]
IEEE Access13, 66752, DOI: https://doi.org/10.1109/ACCESS.2025.3558944 (2025)
Dadahkhani, A.et al.Experimental implementation of enhanced security coherent one-way quantum key distribution. IEEE Access13, 66752, DOI: https://doi.org/10.1109/ACCESS.2025.3558944 (2025)
2025
-
[26]
Phys.11, 075001, DOI: https://doi.org/10
Peev, M.et al.The secoqc quantum key distribution network in vienna.New J. Phys.11, 075001, DOI: https://doi.org/10. 1088/1367-2630/11/7/075001 (2009)
2009
-
[27]
& Scarani, V
Branciard, C., Gisin, N. & Scarani, V . Upper bounds for the security of two distributed-phase reference protocols of quantum cryptography.New J. Phys.10, 013031, DOI: https://doi.org/10.1088/1367-2630/10/1/013031 (2008)
2008 doi
-
[28]
Moroder, T.et al.Security of distributed-phase-reference quantum key distribution.Phys. Rev. Lett.109, 260501, DOI: https://doi.org/10.1103/PhysRevLett.109.260501 (2012)
2012 doi
-
[29]
& Chen, Z
Li, M., Cao, X., Xie, Y ., Yin, H. & Chen, Z. Finite-key analysis for coherent one-way quantum key distribution.Phys. Rev. Res.6, 013022, DOI: https://doi.org/10.1103/PhysRevResearch.6.013022 (2024)
2024 doi
-
[30]
M.et al.Real-time operation of a multi-rate, multi-protocol quantum key distribution transmitter.Optica8, 911, DOI: https://doi.org/10.1364/OPTICA.423517 (2021)
Innocenzo, D. M.et al.Real-time operation of a multi-rate, multi-protocol quantum key distribution transmitter.Optica8, 911, DOI: https://doi.org/10.1364/OPTICA.423517 (2021)
2021 doi
-
[31]
& Curty, M
Trenyi, R. & Curty, M. Zero-error attack against coherent-one-way quantum key distribution.New J. Phys.23, 093005, DOI: https://doi.org/10.1088/1367-2630/ac1e41 (2021)
2021 doi
-
[32]
Express30, 23783, DOI: https://doi.org/10.1364/OE.461669 (2022)
Gao, R.-Q.et al.Simple security proof of coherent-one-way quantum key distribution.Opt. Express30, 23783, DOI: https://doi.org/10.1364/OE.461669 (2022)
2022 doi
-
[33]
Acin, A.et al.Device-independent security of quantum cryptography against collective attacks.Phys. Rev. Lett.98, 230501, DOI: https://doi.org/10.1103/PhysRevLett.98.230501 (2007)
2007 doi
-
[34]
& Acin, A
Masanes, L., Pironio, S. & Acin, A. Secure device-independent quantum key distribution with causally independent measurement devices.Nat. Commun.2, 238, DOI: https://doi.org/10.1038/ncomms1244 (2011)
2011 doi
-
[35]
& Brunner, N
Pawlowski, M. & Brunner, N. Semi-device-independent security of one-way quantum key distribution.Phys. Rev. A84, 010302, DOI: https://doi.org/10.1103/PhysRevA.84.010302 (2011)
2011 doi
-
[36]
& Pironio, S
Woodhead, E. & Pironio, S. Semi-device-independent qkd based on bb84 and a chsh-type estimation. 107–115, DOI: https://doi.org/10.1007/978-3-642-35656-8_9 (2013)
2013 doi
-
[37]
& Pironio, S
Woodhead, E. & Pironio, S. Secrecy in prepare-and-measure chsh tests with a qubit bound.Phys. Rev. Lett.115, 150501, DOI: https://doi.org/10.1103/PhysRevLett.115.150501 (2015). 38.Singh, A.et al.Photonic quantum information with time-bins, DOI: https://doi.org/10.48550/arXiv.2...
-
[39]
& Renner, R
Tomamichel, M., Schaffner, C., Smith, A. & Renner, R. Leftover hashing against quantum side information.IEEE Trans. Inf. Theory57, 5524, DOI: https://doi.org/10.1109/TIT.2011.2158473 (2011)
2011
-
[40]
& Schaffner, C
Konig, R., Renner, R. & Schaffner, C. The operational meaning of min- and max-entropy.IEEE Trans. Inf. Theory55, 4337, DOI: https://doi.org/10.1109/TIT.2009.2025545 (2009)
2009
-
[41]
Security of quantum key distribution.ETH ZurichPhD thesis, DOI: https://doi.org/10.48550/arXiv.quant-ph/ 0512258 (2008)
Renner, R. Security of quantum key distribution.ETH ZurichPhD thesis, DOI: https://doi.org/10.48550/arXiv.quant-ph/ 0512258 (2008). 15/15
2008 doi
Reviewed July 30, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.