Pith. sign in

REVIEW 3 major objections 4 minor 47 references

Security of quantum key distribution with passive basis choice and detection-efficiency mismatch for a realistic satellite setup

T0 review · 3 major / 4 minor · reviewed 2026-08-11 · deepseek-v4-flash

Pith's one-line read The paper proves a lower bound on the BB84 secret key rate that stays positive under large detector-efficiency mismatches and estimates 310,400 secret bits for a satellite-to-ground pass where an earlier bound gave zero.

desk verdict Useful analytical extension for passive-basis BB84 with detection-efficiency mismatch; the central bound looks plausible, the decoy-state normalization issue is likely a non-issue but needs explicit clarification, and the numerical key rate should be treated as provisional because it rests on fitted detector efficiencies. read the letter →

arxiv 2608.09793 v1 pith:QLDEWGBW submitted 2026-08-10 quant-ph

classification quant-ph MSC 81P94 PACS 03.67.Dd
keywords quantumkeydistributionBB84protocolpassivebasischoicedetection-efficiencymismatchdecoystatemethodsatelliteQKDsecretratethresholddetectors
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper addresses a practical flaw in BB84 quantum key distribution: four threshold detectors on the receiving side have unequal efficiencies, and the measurement basis is chosen passively by a beam splitter rather than by an active random number generator. The authors aim to prove a useful security bound that stays positive under large efficiency mismatches, which existing analytical passive-basis proofs do not. They derive an analytical lower bound on the asymptotic secret key rate, Eq. (23), together with two simplified versions and a decoy-state adaptation, Eq. (34), and apply it to the satellite-to-ground experiment considered in the paper, obtaining 310,400 secret bits for one 220-second pass. In the same scenario, adapting the earlier approach of Ref. [26] yields zero bits. The value of the result, if correct, is that a short satellite pass can be processed quickly enough for real-time privacy amplification despite significant detector inhomogeneity.

What carries the argument

The central object is the symmetrized sifted state: after the virtual measurement and basis sifting, the state is block diagonal in the basis register, with each block a $4\times4$ real matrix whose off-diagonal terms are controlled by the detector efficiencies. The paper uses positive trace-preserving maps that commute with sifting and with the decoherence defining Alice's bit, restricting the optimization over all initial states compatible with the observed click and error statistics to states of this symmetric form. The conditional entropy term in the secret-key-rate formula is then obtained from the eigenvalues of the blocks, and the two parameters $\delta_{a,a}$ and $\bar{\delta}_{a,a}$ carry the physics: the first is the normalized difference of Bob's bit probabilities in basis $a$, and the second is the efficiency-weighted difference between correct and erroneous single-photon detection probabilities. Monotonicity of the quantum relative entropy under these maps makes the reduction legitimate, and the same monotonicity under scaling each $\eta_{a,\alpha}$ gives the practical rule that lower bounds on the efficiencies suffice.

What would settle it

Measure the rate of double clicks at the four detectors during the satellite pass analyzed in the paper: if the fraction of accepted events with simultaneous clicks in two or more detectors is not negligible, the single-photon Bob assumption fails and the 310,400-bit estimate may not be a valid lower bound. Alternatively, construct an Eve strategy that sends two-photon pulses, matches the observed single-detector click and error statistics, and yields a genuine key rate below Eq. (23).

Watch

Extended reading notes

Core claim

Under the single-photon Bob assumption, the paper establishes the lower bound $$K \ge \sum_{a\in\{x,z\}} $p_a^{2}$ p_{\mathrm{pass},a}\left[h\left(\frac{1-\delta_{a,a}}{2}\right)-h\left(\frac{1-\sqrt{\delta_{a,a}^2+\bar{\delta}_{a,a}^2}}{2}\right)\right]-p_{\mathrm{pass}} f h(Q)$$ for BB84 with passive basis choice and four threshold detectors, where $\delta_{a,a}$ is the normalized bit imbalance and $\bar{\delta}_{a,a}$ is the efficiency-weighted error imbalance in basis $a$. The same quantities appear in the decoy-state version, Eq. (34), where raw single-photon rates are replaced by decoy-estimated bounds. The proof reduces the required supremum over Eve-compatible initial states to a small symmetric family whose conditional entropy is computed in closed form, and it shows that the bound is monotone in each detector efficiency. For the experimental parameters of the satellite pass, Eq. (34) gives 310,400 secret bits, while the earlier analytical passive-basis treatment adapted in Appendix C gives zero.

Load-bearing premise

The load-bearing premise is the single-photon Bob assumption: Eve cannot add photons, so a single-photon pulse from Alice produces at most one photon at Bob's receiver and double clicks never have to be analysed; if Eve can send multiphoton states, the key-rate bound in Eq. (23) may overestimate the secure key.

Editorial extensions

If this is right

  • With Eq. (23) or its decoy-state form Eq. (34), a passive-basis BB84 receiver keeps a positive asymptotic key rate for detector-efficiency ratios as large as about 2.7 to 1, the regime of the satellite experiment.
  • Because the bound is monotone in every detector efficiency, users only need trusted lower bounds on $\eta_{a,\alpha}$ rather than exact calibration values.
  • The simplified formulas Eq. (27) and Eq. (29) use aggregated statistics; on the satellite data they lose less than 10% and 0.1% of the key rate, respectively, so fast online processing is feasible.
  • Adapting the decoy-state method makes the bound applicable to weak coherent pulse sources, which are the realistic source type in satellite QKD.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • A natural extension not developed in the paper is to count double clicks and redo the derivation without the single-photon Bob assumption; the size of the resulting reduction in the 310,400-bit estimate could be measured directly from the experimental data.
  • The same symmetrization machinery should extend to dark-count-rate mismatch and to detection efficiencies that drift during a pass; a testable prediction is that the key-rate penalty stays small whenever the efficiency ratios remain in the 0.5 to 1 range.
  • A sharper falsification would be to search numerically for a two-photon Eve attack that matches the observed single-detector click and error statistics but yields a key rate below Eq. (23); finding one would show that the stated bound depends critically on the single-photon assumption.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 4 minor

Summary. The paper derives analytical lower bounds on the asymptotic secret-key rate of BB84 with passive basis choice and four threshold detectors exhibiting detection-efficiency mismatch. The central formula is Eq. (23), with simplified variants in Eqs. (27) and (29), and a decoy-state adaptation in Eq. (34). The method is applied to the Micius–Zvenigorod satellite QKD experiment, with the reported integrated key length of 310,400 bits. The appendices contain the main derivations, including a symmetry reduction and relative-entropy monotonicity argument, as well as a comparison with the approach of Ref. [26].

Significance. If the derivation is sound under its stated assumptions, the paper offers a useful analytical alternative to numerical security proofs for passive-basis BB84 with detector-efficiency mismatch, and it explicitly identifies a regime where the earlier analytical approach of Ref. [26] gives zero key rate. The authors are also transparent about two important limitations: the single-photon-Bob assumption and the fact that the detector efficiencies are fitted, not directly measured. However, the decoy-state formula in Eq. (34) contains a normalization inconsistency with Theorem 1, and the single-photon-Bob assumption is not a valid security assumption for the claimed satellite application. These issues affect the central numerical claim and must be addressed before the results can be accepted as a security statement for the described experiment.

major comments (3)
  1. [Sec. V, Eq. (34)] Equation (34) is not the decoy-state version of Theorem 1. In Eq. (23) the per-basis entropy bracket is weighted by p_a^2 p_pass,a, and p_pass is defined in Eq. (26) as sum_a p_a^2 p_pass,a. The observables in Eq. (19) are normalized by 1/p_a^2 in Eq. (18), so the quantities p_{a,alpha} entering Eq. (23) are conditional on both Alice and Bob choosing basis a. Replacing p_{a,alpha} by s1 p_{a,alpha} therefore preserves the weights p_a^2, giving sum_a p_a^2 s1 p_pass,a [h(...)-h(...)] - s1 p_pass f h(Q). Equation (34) as printed omits the p_a^2 factor in the first sum. For p_z=p_x=1/2 the positive entropy contribution is inflated by a factor of 4 relative to the error-correction term. The reported 310,400-bit key length, computed from Eq. (34), is consequently not a reliable bound and needs to be recomputed with the correct normalization.
  2. [Sec. I and Sec. VII] The paper relies on the single-photon-Bob assumption throughout Secs. II–V: if Alice emits a single-photon pulse, Bob receives at most one photon, so Eve cannot send multiphoton states to Bob. For a lossy satellite channel controlled by Eve, this is not a security assumption; an arbitrary Eve can send multiphoton states and induce double clicks. The authors state this limitation in the Conclusion and suggest that counting double clicks would overcome it, but they do not implement that extension. As a result, Eqs. (23), (27), (29), and (34) bound the key rate only for a restricted adversarial model. The abstract and the application to the Micius–Zvenigorod experiment present the result as security for a realistic setup, which is not justified without treating multiphoton arrivals at Bob.
  3. [Sec. VI A, Eqs. (37) and (38)] The normalization convention for the simulated click probabilities is unclear and appears internally inconsistent. Since Eq. (18) defines the constraints with explicit factors 1/p_a^2, the probabilities p_{a,alpha} in Eq. (23) are conditional on both parties selecting basis a. Equation (37) contains no p_a^2 factor, and Eq. (38) defines nu p_pass as a simple sum over bases and bits without p_a^2, which is inconsistent with Eq. (26). If nu p_{a,alpha} is meant to be conditional, then the count-rate formula in Eq. (40) and the comparison with experimental data in Fig. 1 should include p_a^2. If nu p_{a,alpha} is meant to be absolute, then Eq. (37) misses a factor p_a^2. Either way, the fitted detector efficiencies in Table II and all derived key-rate numbers depend on which convention is used, and the paper does not specify it clearly.
minor comments (4)
  1. [Sec. V, Eq. (34)] The minimization notation 'mins1pa,alpha,s1qa,alpha' is unclear: the variable s1 q_{a,alpha} is not defined before Eq. (34), and the text elsewhere uses s1 p_{a,(1-alpha)alpha} for single-photon error probabilities.
  2. [Sec. VII] The sentence 'this limitation can overcome be counting these clicks' contains a typo; it should read 'this limitation can be overcome by counting these clicks'.
  3. [Appendix B, Eq. (B2)] The index alpha is used both for the detector label and as the summation index in the definition of G_{z,alpha}, which is confusing; a different summation index would improve readability.
  4. [Fig. 3] The horizontal axis label 'Mismatch parameter, ' is missing the symbol eta; it should read 'Mismatch parameter, eta'.

Circularity Check

0 steps flagged · score 2.0 of 10

No significant circularity: the key-rate bound is derived from Devetak-Winter and the entropic uncertainty relation, not from its inputs; self-citations in the decoy-state section are not load-bearing in a circular sense.

full rationale

The central result, Eq. (23), is obtained by solving the optimization problem in Eq. (21) over the feasible set S defined by the observed constraints (18)-(19), using the entropic uncertainty relation and monotonicity of the quantum relative entropy. The proof is carried out in Appendix A rather than imported by assumption. The decoy-state adaptation in Sec. V does refer to the authors' prior work [16,17] for decoy formulas, but those references are externally published, peer-reviewed results and the underlying estimates are standard decoy-state bounds; the paper explicitly says that [16,17] prove that the decoy formulas do not assume detector balance, which is a testable mathematical claim, not an assertion of the present paper's conclusion. Proposition 1, while similar to a result in Ref. [17], is proved in the appendix. The use of fitted detector efficiencies in Sec. VI is openly acknowledged in the Conclusion as fitting rather than direct measurement; this weakens the empirical validation but does not make the key-rate bound an identity with the fitted data. The supposed dropped p_a^2 factors between Eq. (23) and Eq. (34) would be an internal normalization error affecting the numerical result, but it is not a circular reduction because the rate formula is not defined by the simulation output. Under the requested standard, the correct finding is no significant circularity; the minor self-citations are not load-bearing.

Assumptions & free parameters 2 free parameters · 5 assumptions · 0 invented entities

The theorem rests on standard QKD security tools and on two strong domain assumptions: single-photon Bob and constant, known detector efficiencies. The application layer adds fitted detector efficiencies and optical error probabilities. No new physical entities are introduced.

free parameters (2)
  • Detector efficiencies eta_z0, eta_z1, eta_x0, eta_x1 = 14.6%, 8.6%, 11.1%, 5.4%
    Chosen as best fit to experimental count rates in Sec. VI A (Fig. 1) and then used for the key-rate estimate. Monotonicity (Appendix B) would allow lower bounds, but no certified lower bounds are provided.
  • Optical error probabilities e_z0, e_z1, e_x0, e_x1 = 0.62%, 0.50%, 1.11%, 1.03%
    Averaged values from the experiment used in the channel model; they set the error statistics in Eqs. (37)-(39) and affect the QBER term in the key rate.
assumptions (5)
  • standard math Devetak-Winter theorem, entropic uncertainty relation, and monotonicity of quantum relative entropy under positive maps
    Invoked in Sec. III Eqs. (13)-(16) and Appendix A Eq. (A3); standard results in QKD security proofs.
  • domain assumption Single-photon Bob: Eve cannot add photons, so Bob receives at most one photon when Alice sends one
    Sec. I, Sec. II, and Conclusion; critical for validity of the POVM model and the absence of double-click analysis.
  • domain assumption Constant detection efficiencies, known to Eve but not manipulable; all receiver-side losses are absorbed into the efficiencies
    Sec. II around Eq. (5), Sec. VI B, and Conclusion; used to define the POVM and to compute the key rate.
  • domain assumption Passive basis choice is a beamsplitter modeled by quantum coin registers in a fixed superposition with probabilities p_z and p_x
    Sec. II Eq. (3); this is the passive-basis model that generates the sifting map.
  • domain assumption Decoy-state estimation formulas from Refs. [16,17,36-38] remain valid for per-detector statistics under efficiency mismatch
    Sec. V; the paper adapts these formulas without re-deriving them.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Security of quantum key distribution with passive basis choice and detection-efficiency mismatch for a realistic satellite setup." pith.science (2026). https://pith.science/paper/QLDEWGBW

@misc{pith2026260809793,
  author       = {Pith},
  title        = {Pith review of: Security of quantum key distribution with passive basis choice and detection-efficiency mismatch for a realistic satellite setup},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/QLDEWGBW}},
  note         = {Machine review of arXiv:2608.09793}
}
read the original abstract

Detection-efficiency mismatch is a common problem in realistic quantum key distribution (QKD) systems. The existing security proofs for the case of the passive basis choice provide a nonzero secret key rate only for a small detection-efficiency mismatch. Unfortunately, in realistic setups, the detection-efficiency mismatch can be significant. Here we present a more precise estimation of the secret key rate for the BB84 protocol with the passive basis choice, which accounts for the detection-efficiency mismatch between four threshold detectors as well as an adaptation of the decoy-state method. The suggested approach is used to estimate the secret key rate in a QKD experiment between the Micius satellite and the Zvenigorod ground station.

Figures

Figures reproduced from arXiv: 2608.09793 by the authors.

Figure 1
Figure 1. The photon count rates for four receiving channels [PITH_FULL_IMAGE:figures/full_fig_p007_1.png] view at source ↗
Figure 3
Figure 3. The ratio of the key generation rate with and with [PITH_FULL_IMAGE:figures/full_fig_p007_3.png] view at source ↗

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

47 extracted references · 38 canonical work pages

  1. [26]

    Zhang, P

    Y. Zhang, P. J. Coles, A. Winick, J. Lin, and N. L¨ utken- haus, Security proof of practical quantum key distribu- tion with detection-efficiency mismatch, Physical Review Research3, 013076 (2021)

  2. [1]

    (23) To derive Eq

    Key rate Eq. (23) To derive Eq. (23) for the key rate we use Eq. (21) with the supremum over matricesρ AB eA eB ∈S, which have the form given by Eq. (A10). Eq. (19) requires the density matrixeρ sifted XAB eB after the decoherence in Alice’s subsystem [see Eq. (15)]. For con- venience, in order to express the values of Alice’s regis- ter as 0/1 rather tha...

  3. [2]

    The receiver, Bob, detects pulses with one photon

    The first state in each basis corresponds to the encoded bit 0 and the sec- ond one to bit 1. The receiver, Bob, detects pulses with one photon. Here, we consider a scenario in which Eve is unable to add photons into pulses, so that, if Alice’s output is single-photon, Bob’s input is at most single- photon too. Then, Bob’s Hilbert space is spanned by the ...

  4. [3]

    (27) Consider the positive trace-preserving linear map Φ3(ρ) = 1 2 ρ+R Φ,3ρR+ Φ,3 , (A21) where RΦ,3 = |z⟩ eA⟨z| ⊗XA +|x⟩ eA⟨x| ⊗ZA ⊗ |z⟩ eB⟨z| ⊗XB +|x⟩ eB⟨x| ⊗ZB

    Simplified key rate Eq. (27) Consider the positive trace-preserving linear map Φ3(ρ) = 1 2 ρ+R Φ,3ρR+ Φ,3 , (A21) where RΦ,3 = |z⟩ eA⟨z| ⊗XA +|x⟩ eA⟨x| ⊗ZA ⊗ |z⟩ eB⟨z| ⊗XB +|x⟩ eB⟨x| ⊗ZB . (A22) This projector does not satisfy the commutation condi- tion Eq. (A1) of Proposition 1. However, using the mono- tonicity of the quantum relative entropy in Eq. (2...

  5. [4]

    (29) The derivation of Eq

    Simplified key rate Eq. (29) The derivation of Eq. (29) is similar to that for Eq. (27), but with an additional symmetry applied. In addition to Φ 1 −Φ 3, we introduce the projector that ag- gregates statistics over different bases and has the follow- ing form: Φ4(ρ) = 1 2 ρ+R Φ,4ρR+ Φ,4 , (A29) 11 where RΦ,4 = |z⟩ eA⟨x| ⊗HA +|x⟩ eA⟨z| ⊗HA ⊗ |z⟩ eB⟨x| ⊗HB...

  6. [5]

    C. H. Bennett and G. Brassard, Quantum cryptogra- phy: Public key distribution and coin tossing, Theoreti- cal Computer Science560, 7 (2014), (First publication: 1984)

  7. [6]

    Mayers, Unconditional security in quantum cryptog- raphy, Journal of the ACM48, 351 (2001)

    D. Mayers, Unconditional security in quantum cryptog- raphy, Journal of the ACM48, 351 (2001)

  8. [7]

    P. W. Shor and J. Preskill, Simple proof of security of the BB84 quantum key distribution protocol, Physical Review Letters85, 441 (2000)

Show all 47 references
  1. [8]

    Renner, Security of quantum key distribution, Inter- national Journal of Quantum Information6, 1 (2008)

    R. Renner, Security of quantum key distribution, Inter- national Journal of Quantum Information6, 1 (2008)

  2. [9]

    Koashi, Simple security proof of quantum key dis- tribution based on complementarity, New Journal of Physics11, 045018 (2009)

    M. Koashi, Simple security proof of quantum key dis- tribution based on complementarity, New Journal of Physics11, 045018 (2009)

  3. [10]

    Tomamichel and A

    M. Tomamichel and A. Leverrier, A largely self-contained and complete security proof for quantum key distribu- tion, Quantum1, 14 (2017)

  4. [11]

    Gisin, G

    N. Gisin, G. Ribordy, W. Tittel, and H. Zbinden, Quan- tum cryptography, Review of Modern Physics74, 145 (2002)

  5. [12]

    F. Xu, X. Ma, Q. Zhang, H.-K. Lo, and J.-W. Pan, Secure quantum key distribution with realistic devices, Review of Modern Physics92, 025002 (2020)

  6. [13]

    Diamanti, H.-K

    E. Diamanti, H.-K. Lo, B. Qi, and Z. Yuan, Practical challenges in quantum key distribution, npj Quantum In- formation2, 16025 (2016)

  7. [14]

    Reutov, A

    A. Reutov, A. Tayduganov, V. Mayboroda, and O. Fat’yanov, Security of the decoy-state BB84 proto- col with imperfect state preparation, Entropy25, 1556 (2023)

  8. [15]

    Makarov, A

    V. Makarov, A. Anisimov, and J. Skaar, Effects of de- tector efficiency mismatch on security of quantum cryp- tosystems, Physical Review A74, 022313 (2006)

  9. [16]

    N. Jain, B. Stiller, I. Khan, D. Elser, C. Marquardt, and G. Leuchs, Attacks on practical quantum key distribu- tion systems (and how to prevent them), Contemporary Physics57, 366 (2016)

  10. [17]

    Marcomini, A

    A. Marcomini, A. Mizutani, F. Gr¨ unenfelder, M. Curty, and K. Tamaki, Loss-tolerant quantum key distribution with detection efficiency mismatch, Quantum Science and Technology10, 035002 (2025)

  11. [18]

    H.-K. Lo, M. Curty, and B. Qi, Measurement-device- independent quantum key distribution, Physical Review Letters108, 130503 (2012)

  12. [19]

    Tamaki, H.-K

    K. Tamaki, H.-K. Lo, C.-H. F. Fung, and B. Qi, Phase encoding schemes for measurement-device-independent quantum key distribution with basis-dependent flaw, Physical Review A85, 042307 (2012)

  13. [20]

    M. K. Bochkov and A. S. Trushechkin, Security of quan- tum key distribution with detection-efficiency mismatch in the single-photon case: Tight bounds, Physical Review A99, 032308 (2019)

  14. [21]

    Trushechkin, Security of quantum key distribution with detection-efficiency mismatch in the multiphoton case, Quantum6, 771 (2022)

    A. Trushechkin, Security of quantum key distribution with detection-efficiency mismatch in the multiphoton case, Quantum6, 771 (2022)

  15. [22]

    Tupkary, S

    D. Tupkary, S. Nahar, P. Sinha, and N. L¨ utkenhaus, Phase error rate estimation in QKD with imperfect de- tectors, Quantum9, 1937 (2025). 13

  16. [23]

    Grasselli, G

    F. Grasselli, G. Chesi, N. Walk, H. Kampermann, A. Widomski, M. Ogrodnik, M. Karpi´ nski, C. Macchi- avello, D. Bruß, and N. Wyderka, Quantum key distribu- tion with basis-dependent detection probability, Physical Review Applied23, 044011 (2025)

  17. [24]

    Winick, N

    A. Winick, N. L¨ utkenhaus, and P. J. Coles, Reliable nu- merical key rates for quantum key distribution, Quantum 2, 77 (2018)

  18. [25]

    P. J. Coles, E. M. Metodiev, and N. L¨ utkenhaus, Numer- ical approach for unstructured quantum key distribution, Nature Communications7, 11712 (2016)

  19. [27]

    Nahar, D

    S. Nahar, D. Tupkary, and N. L¨ utkenhaus, Imperfect de- tectors for adversarial tasks with applications to quantum key distribution, Quantum10, 2044 (2026)

  20. [28]

    Liao, W.-Q

    S.-K. Liao, W.-Q. Cai, W.-Y. Liu, L. Zhang, Y. Li, J.-G. Ren, J. Yin, Q. Shen, Y. Cao, Z.-P. Li, F.-Z. Li, X.-W. Chen, L.-H. Sun, J.-J. Jia, J.-C. Wu, X.-J. Jiang, J.-F. Wang, Y.-M. Huang, Q. Wang, Y.-L. Zhou, L. Deng, T. Xi, L. Ma, T. Hu, Q. Zhang, Y.-A. Chen, N.-L. Liu, X.-B...

  21. [29]

    Li, H.-X

    Y. Li, H.-X. Cai, Wen-Qi dan Yao, X.-D. Yu, Y. Ju, M. Qi, J. Lin, X. Huang, J.-C. Wang, H.-Y. Chen, Y.- L. Hu, P. Xu, J. Xie, J.-S. Lin, R.-S. Liang, K. Zhang, H. Liang, J.-R. Liu, Y.-Z. Li, F. Zhou, Y. Guo, S.-M. Zou, W. Chen, Q. Shen, Q. Zhang, C.-Z. Peng, X.-B. Wang, S.-K. ...

  22. [30]

    Z. Wang, D. Tupkary, and S. Nahar, Phase error estima- tion for passive detection setups with imperfections and memory effects (2025), arXiv:2508.21486 [quant-ph]

  23. [31]

    Khmelev, A

    A. Khmelev, A. Duplinsky, R. Bakhshaliev, E. Ivchenko, L. Pismeniuk, V. Mayboroda, I. Nesterov, A. Chernov, A. Trushechkin, E. Kiktenko, V. Kurochkin, and A. Fe- dorov, Eurasian-scale experimental satellite-based quan- tum key distribution with detector efficiency mismatch ana...

  24. [32]

    Ivchenko, A

    E. Ivchenko, A. Trushechkin, A. Khmelev, and V. Kurochkin, Secrecy of quantum key distribution in case passive basis choice with detection efficiency mis- match, J. Opt. Technol.92, 468 (2025)

  25. [33]

    Zhang and N

    Y. Zhang and N. L¨ utkenhaus, Entanglement verification with detection-efficiency mismatch, Physical Review A 95, 042319 (2017)

  26. [34]

    Devetak and A

    I. Devetak and A. Winter, Distillation of secret key and entanglement from quantum states, Proceedings of the Royal Society A461, 207 (2005)

  27. [35]

    Berta, M

    M. Berta, M. Christandl, R. Colbeck, J. M. Renes, and R. Renner, The uncertainty principle in the presence of quantum memory, Nature Physics6, 659 (2010)

  28. [36]

    P. J. Coles, L. Yu, V. Gheorghiu, and R. B. Griffiths, Information-theoretic treatment of tripartite systems and quantum channels, Physical Review A83, 062338 (2011)

  29. [37]

    Duˇ sek, M

    M. Duˇ sek, M. Jahma, and N. L¨ utkenhaus, Unambiguous state discrimination in quantum cryptography with weak coherent states, Physical Review A62, 022306 (2000)

  30. [38]

    L¨ utkenhaus and M

    N. L¨ utkenhaus and M. Jahma, Quantum key distribu- tion with realistic states: photon-number statistics in the photon-number splitting attack, New Journal of Physics 4, 44 (2002)

  31. [39]

    Wang, Beating the photon-number-splitting attack in practical quantum cryptography, Physical Review Let- ters94, 230503 (2005)

    X.-B. Wang, Beating the photon-number-splitting attack in practical quantum cryptography, Physical Review Let- ters94, 230503 (2005)

  32. [40]

    H.-K. Lo, X. Ma, and K. Chen, Decoy state quantum key distribution, Physical Review Letters94, 230504 (2005)

  33. [41]

    X. Ma, B. Qi, Y. Zhao, and H.-K. Lo, Practical decoy state for quantum key distribution, Physical Review A 72, 012326 (2005)

  34. [42]

    Zhang, Q

    Z. Zhang, Q. Zhao, M. Razavi, and X. Ma, Improved key-rate bounds for practical decoy-state quantum-key- distribution systems, Physical Review A95, 012333 (2017)

  35. [43]

    A. V. Khmelev, E. I. Ivchenko, A. V. Miller, A. V. Du- plinsky, V. L. Kurochkin, and Y. V. Kurochkin, Semi- empirical satellite-to-ground quantum key distribution model for realistic receivers, Entropy25, 670 (2023)

  36. [44]

    Zhao, C.-H

    Y. Zhao, C.-H. F. Fung, B. Qi, C. Chen, and H.-K. Lo, Quantum hacking: Experimental demonstration of time- shift attack against practical quantum-key-distribution systems, Physical Review A78, 042333 (2008)

  37. [45]

    Sajeed, P

    S. Sajeed, P. Chaiwongkhot, J.-P. Bourgoin, T. Jen- newein, N. L¨ utkenhaus, and V. Makarov, Security loop- hole in free-space quantum key distribution due to spatial-mode detector-efficiency mismatch, Physical Re- view A91, 062301 (2015)

  38. [46]

    Pirandola, U

    S. Pirandola, U. L. Andersen, L. Banchi, M. Berta, D. Bunandar, R. Colbeck, D. Englund, T. Gehring, C. Lupo, C. Ottaviani, J. L. Pereira, M. Razavi, J. S. Shaari, M. Tomamichel, V. C. Usenko, G. Vallone, P. Vil- loresi, and P. Wallden, Advances in quantum cryptogra- phy, Adv. ...

  39. [47]

    M¨ uller-Hermes and D

    A. M¨ uller-Hermes and D. Reeb, Monotonicity of the quantum relative entropy under positive maps, Annales Henri Poincar´ e18, 1777 (2017)

Pith tools

Reviewed August 11, 2026 · model on record in the stance chip above.