Pith. sign in

REVIEW 1 major objections 4 minor 52 references

Phase-error estimation for quantum key distribution with leaky receivers

T0 review · 1 major / 4 minor · reviewed 2026-08-11 · deepseek-v4-flash

Pith's one-line read A fidelity bound makes leaky QKD receivers loss-tolerant.

desk verdict The loss-tolerant post-measurement leakage bound is real and useful, but the a priori basis-leakage section has a missing-system typo in Eq. (8) that needs fixing before the proof is relied upon. read the letter →

arxiv 2608.09674 v1 pith:DDT4F4XM submitted 2026-08-10 quant-ph

classification quant-ph
keywords quantumkeydistributionreceiversidechannelsdetectorbackflashTrojan-horseattackphase-errorestimationfinite-keysecuritylosstoleranceBB84protocol
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper proves finite-key security for prepare-and-measure BB84 quantum key distribution when Bob's receiver leaks information, for example through detector backflash or back-reflected Trojan-horse light. Its main result is that post-measurement leakage of the recorded bit only adds a penalty proportional to the number of detected rounds, so the security analysis is loss tolerant: the tolerable leakage does not shrink as the channel becomes lossy. It also treats leakage of Bob's basis choice before the measurement, a scenario no earlier proof covered, and shows this case carries a per-transmitted-round penalty set by a fidelity parameter. The whole proof needs only a bound on the distinguishability of the two leaked bit states in the $Z$ basis, stated as a fidelity $\gamma^2$.

What carries the argument

The load-bearing object is the leakage isometry $\hat{R}^u_\beta$ of Eq. (3): $|b_\beta\rangle \mapsto |b_\beta\rangle |e_{b,\beta}\rangle$ and $|\perp\rangle \mapsto |\perp\rangle |e_{\perp,\beta}\rangle$, with the leaked system $L_u$ given to Eve. Because this isometry commutes with Bob's projective measurement, the actual protocol is statistically identical to one where leakage happens before measurement, and because the sifted key only comes from $Z$-basis detections, only the two $Z$-outcome leakage states matter. Tracing $L_u$ out of the isometry produces a dephasing channel $E_\gamma(\rho) = \frac{1+\gamma}{2}\rho + \frac{1-\gamma}{2} Z\rho Z$ on the detection subspace; applying it to Bob's $X$-basis projectors in the virtual protocol gives the effective phase-error operator of Eq. (5). The parameter $\gamma$ is the only leakage quantity that has to be characterized, and it appears as an overlap, not a trace distance.

What would settle it

A direct test would characterize Bob's receiver after a 0-bit and a 1-bit $Z$-basis detection and measure the fidelity $F(\sigma^{(0,Z)}, \sigma^{(1,Z)})$; if it is below the assumed $\gamma^2$, or if the emitted light also depends on click multiplicity or on previous rounds beyond the gated window, Eq. (7)'s bound with that $\gamma$ is not valid and the key rate could be overestimated.

Watch

Extended reading notes

Core claim

The central discovery is that Bob's measurement and the receiver's leakage can be reordered without changing any observed statistics. The paper models the leakage by an isometry $\hat{R}^u_\beta$ that attaches a state $|e_{b,\beta}\rangle$ to the detected system before Bob measures it, and shows this commutes with an ideal qubit measurement. Tracing out the leaked system turns the virtual phase-error measurement into a dephased one: the effective phase-error operator is $\gamma \hat{E}_{\mathrm{ph}}^{AB} + \frac{1-\gamma}{2}\mathbb{1}_A\otimes\mathbb{1}_B^{\det}$, where $\gamma$ is the overlap of the two $Z$-basis leakage states. Summing the resulting conditional bound over detected rounds with Azuma's inequality gives $N_{\mathrm{ph}} \le \gamma \frac{p^A_Z p^B_Z}{p^A_X p^B_X} N_{x,\mathrm{er}} + p^A_Z p^B_Z \frac{1-\gamma}{2} N_{\det}$ plus finite-size fluctuation terms; the same logic with a fidelity parameter $\delta$ between pre-measurement basis-leakage states yields the per-transmitted-round bound for a priori leakage. This makes the post-measurement penalty depend on detected rounds only, which is precisely the loss-tolerant behavior previous analyses lacked.

Load-bearing premise

The load-bearing assumption is that the receiver's side-channel emission depends on the physical detection event only through the recorded outcome $b'$ and basis $\beta$, so it can be attached to the qutrit description by the isometry; if a real device leaks finer-grained information, such as whether a double click occurred, the phase-error bound does not apply.

Editorial extensions

If this is right

  • If Eq. (7) holds, a receiver whose leaked bit states have fidelity at least $\gamma^2$ adds only an additive, detection-count-scaled penalty to the phase-error budget, so the key rate stays useful over long distances where most rounds are lost.
  • For a priori basis leakage, Eq. (11) shows the penalty scales with transmitted rounds through $\delta$, so Eve can exploit it with strategies such as unambiguous state discrimination; this quantifies why basis-setting leakage is more dangerous than outcome leakage.
  • The dephasing substitution extends to non-projective qubit POVMs and to asymmetric passive receivers with detection-efficiency mismatch, where it becomes $\tilde{G}^{(1)}_{(X,\neq)} \mapsto E_\gamma(\tilde{G}^{(1)}_{(X,\neq)})$ and the parameter substitution $\delta \mapsto \delta_\gamma$ in existing detector-imperfection proofs.
  • Correlated leakage over a finite window $L_c$ can be handled by gating detectors or by post-processing discards, and the active-round fraction $\approx 1/(1+L_c p_{\det})$ stays close to one when detection is rare, preserving loss tolerance.
  • The analysis is modular with source-imperfection and decoy-state proofs, so the same fidelity characterization can be reused in broader prepare-and-measure implementations.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • The same $E_\gamma$ dephasing substitution should carry over to other prepare-and-measure and measurement-device-independent protocols whose security reduces to a phase-error estimate on detected rounds, although the paper only runs the BB84 numerics.
  • A practical certification procedure could measure only the overlap between the two $Z$-basis leaked states, for example by interferometric comparison of backflash or back-reflected light, rather than full tomography of all side-channel modes; the bound would then make detector-leakage testing a one-number check.
  • Because the a priori basis-leakage penalty depends on $\delta$, increasing the basis-choice randomness or using basis-independent detection hardware should reduce the per-round cost; a testable prediction is that key-rate-versus-distance curves stay nearly flat in $\gamma$ for all but near-orthogonal leakage states.
  • The double-click caveat suggests that receivers with squashing maps should be designed to randomize or hide double-click patterns from side channels; otherwise any leakage that resolves finer-grained detection patterns falls outside the proof.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

1 major / 4 minor

Summary. Prepare-and-measure BB84 with a receiver that leaks information about its measurement outcomes (post-measurement leakage) or about its basis choice (a priori leakage) is analyzed. The authors derive finite-key security bounds based on phase-error estimation. For post-measurement leakage, the phase-error penalty scales with the number of detected rounds, making the analysis loss tolerant. For a priori basis-choice leakage, the penalty scales with the number of transmitted rounds. The proof requires only a fidelity bound between the relevant leakage states and is modular, with extensions to non-projective qubit measurements and to receivers with detection-efficiency mismatch.

Significance. If correct, this is a significant advance: previous analyses of detector leakage imposed a penalty per transmitted round, which is overly pessimistic in high-loss regimes. The loss-tolerant bound is both conceptually and practically important. The a priori basis-choice leakage analysis is, to my knowledge, new. The paper is clearly structured, the main derivation is easy to follow, and the numerical results illustrate the expected performance. The modular combination with existing detector-imperfection analyses (Appendix B) and the finite-size concentration bounds are strengths.

major comments (1)
  1. [A priori leakage of the basis choice, Eq. (8)] Equation (8) is not well-formed: the isometry Û_u is defined with domain H_{E_{u-1}} ⊗ H_{L_{u-1}} ⊗ H_{L'_u} and codomain H_{E_u} ⊗ H_{B_u}, and the input state is ρ^{F_{u-1}}_{A_uE_{u-1}L_{u-1}} ⊗ σ^{β_u}_{L'_u}. In the entanglement-based protocol Alice prepares |Φ+>_{A_u C_u} and sends C_u to Bob, so Eve's attack must act on C_u in order to produce B_u. As printed, the outgoing system B_u is not obtained from any incoming signal. The definition of ρ^{β_u,F_{u-1}}_{A_uB_u} is therefore undefined, and the subsequent identification of ρ^Z and ρ^X as outputs of the same CPTP map—which is needed for the fidelity bound F(ρ^Z, ρ^X) ≥ δ and for the derivation of Eq. (9)—is unsupported. This is more than a typographical issue; the map does not type-check. The authors should include C_u in both the domain of Û_u and the pre-interaction state (with A_u and C_u in the entangled state |Φ+>).
minor comments (4)
  1. [A priori leakage of the basis choice, after Eq. (9)] The text contains unresolved citation placeholders "[?]" in the paragraph beginning "This type of strategy has previously been used to accommodate source imperfections" ; these should be replaced with actual references.
  2. [A priori leakage of the basis choice, Eq. (8)] Equation (8) is stated only for 1 < u ≤ N, leaving the initial round u=1 undefined; the definition of ρ^{F_0} should be provided for completeness.
  3. [Results] In the secret-key-rate formula, the symbol N_ph is used for the upper bound on the number of phase errors, but it should be distinguished from the actual phase-error count (e.g., N_ph^{UB}) to avoid notational confusion.
  4. [Leakage model] The manuscript would benefit from a brief discussion of how the fidelity bounds in Eq. (2) and in the a priori-leakage section can be certified experimentally in a practical QKD implementation.

Circularity Check

0 steps flagged · score 1.0 of 10

No significant circularity: gamma and delta are input fidelity bounds, and the phase-error derivation does not assume its conclusion.

full rationale

The central derivation is self-contained relative to its stated assumptions. The post-measurement leakage bound starts from the leak-isometry in Eq. (3), whose overlap gamma is an assumed device-fidelity input (Eq. (2)), not a fitted or target quantity. The phase-error operator in Eq. (5) is obtained by applying the resulting dephasing channel E_gamma to the standard phase-error operator, and Eq. (6)/Eq. (7) follow by algebra plus Azuma's inequality; nowhere is the final bound inserted as an assumption. The a priori leakage analysis introduces delta as a lower bound on the fidelity of the leaked basis-choice states, uses data processing to transfer it to the conditional states, and then applies a previously published data-processing inequality from Ref. [39] to relate phase-error and bit-error probabilities. That cited inequality is external, published evidence and does not include the present leaky-receiver result among its assumptions, so the self-citation is not load-bearing in a circular sense. Several other self-citations ([19], [24], [37]) are used only as modular building blocks or alternative tail bounds, not as the source of the new phase-error estimate. The paper also explicitly flags a genuine limitation of the squashing-model route (leakage depending on finer-grained patterns such as double clicks is outside the model), which is an honest scope restriction rather than a circular move. A separate correctness/typing concern exists around Eq. (8), where the displayed map omits the signal system C_u; however, that is a rigor or correctness issue, not a circularity issue, because the derivation would still rely on an assumed isometry rather than on its own conclusion. Overall, no step reduces by construction to its inputs, and the central claims have independent content.

Assumptions & free parameters 0 free parameters · 8 assumptions · 0 invented entities

No numbers are fitted: gamma and delta are externally supplied device-fidelity bounds, and the protocol probabilities are optimized, not adjusted to force the desired conclusion. The proof leans on standard mathematical facts and on prior security frameworks, but the leakage analysis itself is self-contained. No new physical entities are introduced; the leakage and ancilla systems are modeling devices.

assumptions (8)
  • domain assumption The received system B_u is block diagonal as a qutrit: vacuum plus a qubit detection subspace, Eq. (1).
    Needed for a qubit description of Bob's measurement; justified by conditioning on single photons or by a squashing model, and relaxed in Appendices A and B.
  • domain assumption Bob's detected-round measurement is an ideal projective qubit measurement in the chosen basis.
    Assumed in the main text; Appendix A extends the analysis to two-outcome qubit POVMs.
  • domain assumption Post-measurement leakage depends on (b', beta) only and is generated by the commuting isometry Eq. (3).
    Central leakage model; for squashing, finer-grained double-click leakage is outside scope, as the text states.
  • domain assumption The input state of B_u is independent of Bob's basis choice in the post-measurement leakage scenario.
    Required to swap the leakage isometry before Bob's measurement without changing the statistics.
  • domain assumption Fidelity lower bound F(sigma^(0,Z), sigma^(1,Z)) >= gamma^2 holds for all rounds, Eq. (2).
    This is the only leakage characterization required; if uncertified, the phase-error bound fails.
  • domain assumption A priori basis leakage state sigma^beta_{L'} has fidelity at least delta between basis choices and enters Eve's interaction as in Eq. (8).
    Needed for the data-processing bound leading to Eq. (11).
  • domain assumption When combined with detector-imperfection analyses, detectors are taken memoryless (Appendix B, footnote 42).
    The authors note that a rigorous combination with correlated-detector analysis is outside the scope of this work.
  • standard math Azuma-Hoeffding, Uhlmann's theorem, and the data-processing inequality are used.
    Standard tools invoked in Eqs. (7), (11), and Appendices D and E.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Phase-error estimation for quantum key distribution with leaky receivers." pith.science (2026). https://pith.science/paper/DDT4F4XM

@misc{pith2026260809674,
  author       = {Pith},
  title        = {Pith review of: Phase-error estimation for quantum key distribution with leaky receivers},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/DDT4F4XM}},
  note         = {Machine review of arXiv:2608.09674}
}
read the original abstract

Practical quantum key distribution (QKD) receivers may leak information about their measurement outcomes and settings to the channel (e.g., through detector backflashes or back-reflected Trojan-horse light) that could compromise the protocol's security. Here we present a simple finite-key security proof based on phase-error estimation for prepare-and-measure QKD in the presence of either a priori information leakage about the basis choices and/or a posteriori information leakage about the measurement outcomes. The proof requires only a bound on the distinguishability of the side-channel states. Furthermore, the analysis is modular and compatible with existing security proofs that address detector and source imperfections, making it applicable to a wide range of practical QKD implementations.

Figures

Figures reproduced from arXiv: 2608.09674 by the authors.

Figure 1
Figure 1. The isometry modeling the information leakage is designed to commute with Bob’s measurement, and therefore their [PITH_FULL_IMAGE:figures/full_fig_p002_1.png] view at source ↗
Figure 2
Figure 2. Secret-key rate per signal as a function of the dis [PITH_FULL_IMAGE:figures/full_fig_p005_2.png] view at source ↗

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

52 extracted references · 41 canonical work pages

  1. [39]

    , nA indexes then A states|φ i⟩C , emitted with probabilityp i

    To analyze more general sources, one could instead con- sider the entangled state P i √pi |i⟩A |φi⟩C , wherei= 0,1, . . . , nA indexes then A states|φ i⟩C , emitted with probabilityp i

  2. [1]

    Bob can therefore reproduce the outcome bof his POVM{G (Z) 0 , G(Z) 1 }by measuring{P j}j, learn- ingj, and assigning a bitbby classical post-processing

    Step 1: Simulating the POVM by a projective measurement plus randomness SinceG (Z) 0 is Hermitian and acts on a qubit, it admits the decomposition G(Z) 0 =λ 0P0 +λ 1P1, P 0 +P 1 =1,(A1) with eigenvaluesλ j ∈[0,1] and orthogonal rank-1 projec- tors{P 0, P1}; consequentlyG (Z) 1 =1−G (Z) 0 is diagonal in the same basis. Bob can therefore reproduce the outco...

  3. [2]

    Step 2: Simulating the leakage We now suppose that Bob runs the alternative sce- nario where he measures the projectors{P j}j and leaks, instead of|e b,Z⟩L, both the (classical) value ofRand a state|f j⟩L that carries information about the projective outcomej, chosen such that ⟨f1|f0⟩=⟨e 1,Z|e0,Z⟩=γ.(A5) Becauseγis real, there exist isometriesV I , VF suc...

  4. [3]

    (3), restricted to the detection subspace, and sendsLto Eve; (2) he drawsRand sends it to Eve; (3) he measures{P j}j on systemB, learningj; (4) he computesbfrom (j, R)

    Step 3: Isometry and dephasing channel Now, similarly to the main text, consider that Bob implements the following scenario, which is equivalent to the scenario just described in Step 2: (1) he applies the isometry ˆRZ |ψ⟩B =P 0 |ψ⟩B |f0⟩L +P 1 |ψ⟩B |f1⟩L ,(A9) which is the analogue of the isometry ˆRu Z in Eq. (3), restricted to the detection subspace, a...

  5. [4]

    four- state Bob

    Phase-error relation SinceM− E γ(M) = (1−γ)M off , whereM off is the off-diagonal part ofMin the{ | ˜0⟩,| ˜1⟩}basis, and ∥Moff ∥∞ =|M ˜0˜1| ≤ 1 2 for any qubit POVMM, with M˜0˜1 :=⟨ ˜0|M| ˜1⟩, we obtain the state-independent bound ∥M− Eγ(M)∥ ∞ ≤ 1−γ 2 .(A12) In this case, the unmodified phase-error operator has the form ˆEph AB =|0 X ⟩ ⟨0X |A ⊗G (X) 1 +|1...

  6. [5]

    (F6) Now, note that Eve’s round-udecision on the state that is forwarded to Bob is independent of his settings (β, r)

    Then, conditioned on the recordF u−1, withρ≡ ρFu−1 AuBuDuRu being the round-uconditional state, the con- ditional phase-error andX-basis-error probabilities are given by Pr χu ph|Fu−1 =p A ZpB Z Tr h ˆOph ABDR ρ i , Pr χu x,er|Fu−1 =p A X pB X Tr h ˆOx ABDR ρ i . (F6) Now, note that Eve’s round-udecision on the state that is forwarded to Bob is independen...

  7. [6]

    (F8)) we can divide by Tr (1AB ⊗ ¯ED)σ in both sides of Eq

    Moreover, since the detection probability is ba- sis independent (see Eq. (F8)) we can divide by Tr (1AB ⊗ ¯ED)σ in both sides of Eq. (F9) and mul- tiply by the basis-choice probabilities, leading, for every detected roundu, to Pr χu ph|Fu−1,D u ≤ pA ZpB Z pA X pB X Pr χu x,er|Fu−1,D u +p A ZpB Z 1−γ 2 , (F10) 11 whereD u represents the detection event. S...

  8. [7]

    C. H. Bennett and G. Brassard, inProc. IEEE Int. Conf. Computers, Systems and Signal Processing(Bangalore, India, 1984) pp. 175–179

Show all 52 references
  1. [8]

    H.-K. Lo, M. Curty, and K. Tamaki, Nat. Photonics8, 595 (2014)

  2. [9]

    Pirandola, U

    S. Pirandola, U. L. Andersen, L. Banchi, M. Berta, D. Bunandar, R. Colbeck, D. Englund, T. Gehring, C. Lupo, C. Ottaviani,et al., Adv. Opt. Photonics12, 1012 (2020)

  3. [10]

    F. Xu, X. Ma, Q. Zhang, H.-K. Lo, and J.-W. Pan, Rev. Mod. Phys.92, 025002 (2020)

  4. [11]

    Gottesman, H.-K

    D. Gottesman, H.-K. Lo, N. L¨ utkenhaus, and J. Preskill, Quantum Inf. Comput.4, 325 (2004)

  5. [12]

    Marquardt, U

    C. Marquardt, U. Seyfarth, S. Bettendorf, M. Bohmann, A. Buchner, M. Curty, D. Elser, S. Eul, T. Gehring, N. Jain, T. Klocke, M. Reinecke, N. Sieber, R. Ursin, M. Wehling, and H. Weier,Implemen- tation attacks against QKD systems, Tech. Rep. (German Federal Office for Informat...

  6. [13]

    Zapatero, ´A

    V. Zapatero, ´A. Navarrete, and M. Curty, Adv. Quantum Technol.8, 2300380 (2025)

  7. [14]

    Marcomini, A

    A. Marcomini, A. Mizutani, F. Gr¨ unenfelder, M. Curty, and K. Tamaki, Quantum Sci. Technol.10, 035002 (2025)

  8. [15]

    C.-H. F. Fung, K. Tamaki, B. Qi, H.-K. Lo, and X. Ma, Quantum Inf. Comput.9, 131 (2009)

  9. [16]

    Lydersen, C

    L. Lydersen, C. Wiechers, C. Wittmann, D. Elser, J. Skaar, and V. Makarov, Nat. Photonics4, 686 (2010)

  10. [17]

    Vakhitov, V

    A. Vakhitov, V. Makarov, and D. R. Hjelme, J. Mod. Opt.48, 2023 (2001)

  11. [18]

    N. Jain, E. Anisimova, I. Khan, V. Makarov, C. Mar- quardt, and G. Leuchs, New J. Phys.16, 123030 (2014)

  12. [19]

    H.-K. Lo, M. Curty, and B. Qi, Phys. Rev. Lett.108, 130503 (2012)

  13. [20]

    Lucamarini, Z

    M. Lucamarini, Z. L. Yuan, J. F. Dynes, and A. J. Shields, Nature557, 400 (2018)

  14. [21]

    Tupkary, S

    D. Tupkary, S. Nahar, P. Sinha, and N. L¨ utkenhaus, Quantum9, 1937 (2025)

  15. [22]

    Z. Wang, D. Tupkary, and S. Nahar, preprint arxiv:2508.21486 (2025)

  16. [23]

    Nahar, D

    S. Nahar, D. Tupkary, and N. L¨ utkenhaus, Quantum10, 2044 (2026)

  17. [24]

    Curr´ as-Lorenzo, M

    G. Curr´ as-Lorenzo, M. Pereira, S. Nahar, and D. Tup- kary, npj Quantum Inf.12, 129 (2026)

  18. [25]

    Navarrete, G

    ´A. Navarrete, G. Curr´ as-Lorenzo, M. Pereira, and M. Curty, preprint arxiv:2605.12984 (2026)

  19. [26]

    Kurtsiefer, P

    C. Kurtsiefer, P. Zarda, S. Mayer, and H. Weinfurter, J. Mod. Opt.48, 2039 (2001)

  20. [27]

    P. V. P. Pinheiro, P. Chaiwongkhot, S. Sajeed, R. T. Horn, J.-P. Bourgoin, T. Jennewein, N. L¨ utkenhaus, and V. Makarov, Opt. Express26, 21020 (2018)

  21. [28]

    Marøy, L

    Ø. Marøy, L. Lydersen, and J. Skaar, Phys. Rev. A82, 032337 (2010)

  22. [29]

    Arqand, T

    A. Arqand, T. Metger, and E. Y.-Z. Tan, preprint arxiv:2407.20396 (2024)

  23. [30]

    Curr´ as-Lorenzo, M

    G. Curr´ as-Lorenzo, M. Pereira, G. Kato, M. Curty, and K. Tamaki, Optica Quantum3, 525 (2025)

  24. [31]

    Hwang, Phys

    W.-Y. Hwang, Phys. Rev. Lett.91, 057901 (2003)

  25. [32]

    H.-K. Lo, X. Ma, and K. Chen, Phys. Rev. Lett.94, 230504 (2005)

  26. [33]

    Wang, Phys

    X.-B. Wang, Phys. Rev. Lett.94, 230503 (2005)

  27. [34]

    Koashi, Y

    M. Koashi, Y. Adachi, T. Yamamoto, and N. Imoto, Se- curity of entanglement-based quantum key distribution with practical detectors (2008), arXiv:0804.0891 [quant- ph]

  28. [35]

    Moroder, M

    T. Moroder, M. Curty, and N. L¨ utkenhaus, New Journal of Physics11, 045008 (2009)

  29. [36]

    Kawakami, A

    S. Kawakami, A. Taniguchi, Y. Tonomura, K. Takasugi, and K. Azuma, Physical Review Applied24, 054070 (2025), arXiv:2507.04248 [quant-ph]

  30. [37]

    N. J. Beaudry, T. Moroder, and N. L¨ utkenhaus, Phys. Rev. Lett.101, 093601 (2008)

  31. [38]

    Gittsovich, N

    O. Gittsovich, N. J. Beaudry, V. Narasimhachar, R. Romero Alvarez, T. Moroder, and N. L¨ utkenhaus, Phys. Rev. A89, 012325 (2014)

  32. [40]

    Koashi, New J

    M. Koashi, New J. Phys.11, 045018 (2009)

  33. [41]

    Azuma, Tohoku Math

    K. Azuma, Tohoku Math. J.19, 357 (1967)

  34. [42]

    Kato, preprint arxiv:2002.04357 (2020)

    G. Kato, preprint arxiv:2002.04357 (2020)

  35. [43]

    Mannalath, V

    V. Mannalath, V. Zapatero, K. Tamaki, and M. Curty, preprint arXiv:2607.17690 (2026)

  36. [44]

    Importantly, no such restriction is required here, since the necessary sequential structure arises by construction (see Fig

    This type of strategy has previously been used to accom- modate source imperfections [?], where a sufficiently low repetition rate had to be imposed to enforce a specific sequential structure on Eve’s attack and thereby ensure that all relevant operators appearing in the calcu...

  37. [45]

    Curr´ as-Lorenzo, S

    G. Curr´ as-Lorenzo, S. Nahar, N. L¨ utkenhaus, K. Tamaki, and M. Curty, Quantum Sci. Technol.9, 015025 (2024)

  38. [46]

    Pittaluga, M

    M. Pittaluga, M. Minder, M. Lucamarini, M. Sanzaro, R. I. Woodward, M.-J. Li, Z. Yuan, and A. J. Shields, Nature Photonics15, 530 (2021)

  39. [47]

    (11) accounts for both leakage mechanisms simultaneously, and therefore depends onγandδ

    Note that Eq. (11) accounts for both leakage mechanisms simultaneously, and therefore depends onγandδ. For the “Pre” curves in Fig. 2, however, whether one sets ε= 1−γ 2 = 1−δ—i.e. one considers that both types of leakage are present with the same strength—or removes the post-...

  40. [48]

    We remark that Ref. [16] also extends its analysis to de- tectors with memory effects, by discarding detections in rounds preceded by another detection within the correla- tion length and reducing the security analysis of the non- detected rounds to the memoryless case. Since ...

  41. [49]

    , u+Lc once the valuebis recorded

    As in the main text, this isometry is not an actual step of the protocol, but a rewriting of the window dynamics in the controlled form ˆSu = P b |bZ ⟩ ⟨bZ |Bu ⊗ ˆKb, where ˆKb collects everything that happens in roundsu, . . . , u+Lc once the valuebis recorded. This includes ...

  42. [50]

    Uhlmann, Rep

    A. Uhlmann, Rep. Math. Phys.9, 273 (1976)

  43. [51]

    Makarov, A

    V. Makarov, A. Anisimov, and J. Skaar, Phys. Rev. A 74, 022313 (2006)

  44. [52]

    Qi, C.-H

    B. Qi, C.-H. F. Fung, H.-K. Lo, and X. Ma, Quantum Information and Computation7, 73 (2007)

Pith tools

Reviewed August 11, 2026 · model on record in the stance chip above.