REVIEW 4 major objections 5 minor 26 references
Authentication of Continuous-Variable Quantum Messages
T0 review · 4 major / 5 minor · reviewed 2026-08-06 · deepseek-v4-flash
Pith's one-line read The paper introduces the first quantum authentication scheme for continuous-variable states and proves, in an idealized limit, that tampering is detected except with probability below n/(n+2z) raised to the power t+1.
desk verdict First CV trap-code QAS with a sound CV twirl, but Eq. (33)'s security bound is proved in an idealized limit; the finite-parameter gaps are real and unquantified. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing object is the CV twirl, the continuous-variable counterpart of the Pauli twirl: averaging a displaced state over Gaussian displacements $D(\gamma)$ produces the identity $$\int_\mathbb{C} \frac{$d^{2}$\gamma}{2\pi\$\Delta$^2} e^{-|\gamma|^2/(2\$\Delta$^2)} D^\dagger(\gamma)D(\$\beta$)\rho D^\dagger(\$\beta$')D(\gamma) = e^{-2\$\Delta$^2|\$\beta$-\$\beta$'|^2} D(\$\beta$)\rho D^\dagger(\$\beta$'),$$ whose Gaussian prefactor acts as a Dirac delta for large key variance $\Delta$. The second mechanism is the pair of indicator functions used in the proof: the real-world acceptance function $G(\pi,\vec\alpha)$, a product of error functions that is nearly a step function for strong squeezing $r\gg1$ and $\epsilon\gg e^{-r/2}$, and the simulator's ideal acceptance indicator $I(\pi^{-1}\vec\alpha\in D_F)$. The proof controls the difference $G-I$, which is nonzero only when all traps pass but more than $t$ message modes are displaced, and then bounds the permutation probability of that event.
What would settle it
Concretely: fix finite $\Delta$ and $r$, choose a displacement attack with $u=t+1$ noisy modes placed in the message register, and compute the trace distance between the real and simulator channels; a value above $(n/(n+2z))^{t+1}$ would show the idealized bound does not extend to that regime.
Extended reading notes
Core claim
On the paper's own terms, the discovery is that the discrete-variable trap-code authentication construction can be transplanted to continuous-variable modes and the transplant can be proven secure. Encoding interleaves the QECC-encoded message with $z$ position-squeezed and $z$ momentum-squeezed states, then randomizes by a secret permutation and a Gaussian-displacement quantum one-time pad. Decoding undoes these steps and accepts only if all trap quadratures lie within $\pm\epsilon$; the average over one-time-pad keys is evaluated by a new continuous-variable analogue of the Pauli twirl, whose Gaussian factor acts as a delta function for large key variance. Comparing the real channel with an EPR-based simulator reduces security to a counting problem: the only bad event is that all traps are intact while the message has uncorrectable noise, and a random permutation places the noisy modes into message positions with probability below $(n/(n+2z))^{t+1}$. The paper states this as satisfying the security definition with $\eta = (n/(n+2z))^{t+1}$.
Load-bearing premise
The security proof is valid only in an idealized limit: the twirl factor is treated as a perfect delta function, the trap check as an exact on-off step, and the error-correcting code is assumed to correct arbitrarily large displacements, none of which holds exactly with finite squeezing, finite key width, or finite-resource codes.
Editorial extensions
If this is right
- A sender and receiver sharing a classical key can authenticate a single-mode CV quantum message, with the security parameter tuned by the number $z$ of trap pairs; taking $n=1$ and $2z=2$ recovers the discrete-variable form $(1/3)^{t+1}$.
- The required operations--squeezed states, displacement operations, random permutations, and homodyne detection--are all realizable on current optical platforms, so the construction is candidate-implementable.
- The CV twirl derived for the proof is a standalone tool: any CV protocol whose security argument averages over a Gaussian one-time pad can reuse the identity directly.
- Multi-mode messages can be authenticated either by authenticating each mode separately or by encoding the multi-mode message into a larger QECC, extending the same security analysis blockwise.
Reading between the lines
- The paper leaves the finite-$\Delta$ and finite-$r$ corrections implicit; computing them would give an additive correction to $\eta$ rather than a structural change, and would state the security level that finite-resource implementations actually achieve.
- The CV twirl identity holds for arbitrary states, so the same delta-function technique could be exported to security proofs for other CV primitives, such as Gaussian private quantum channels or CV secret sharing, wherever a Gaussian one-time pad is averaged.
- The idealized assumption of a QECC that corrects arbitrarily large displacements is not met by physical CV codes; re-running the argument with a finite correction radius would convert the theorem into a resource-counted statement with an explicit squeezing-to-security trade-off.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper proposes the first continuous-variable (CV) quantum message authentication scheme, adapting the discrete-variable trap-code construction of Broadbent et al. [1] and the simulator-based proof approach of Broadbent and Wainewright [2]. The scheme encodes a single-mode message into n modes using a CV-QECC, appends 2z squeezed trap states, applies a secret permutation and a Gaussian CV one-time pad, and verifies the traps by homodyne detection. The security proof introduces a CV analogue of the Pauli twirl (Lemma 4.1), compares the real channel with an ideal simulator based on EPR pairs, and concludes with the counting bound eta = (n/(n+2z))^(t+1) in Eq. (33). The authors state in Sec. 5 that a more rigorous treatment of the approximate step functions is left for future work.
Significance. If made rigorous, this would be a useful first step toward CV quantum message authentication: the construction is simple, the trade-off between the number of traps and the security parameter is explicit, and the CV twirl lemma is a reusable technical tool. The paper credibly transfers the DV trap-code idea to CV systems and identifies the main new obstacles, namely the approximate twirl, the approximate acceptance step, and finite-squeezing effects. The main limitation is that the headline claim, Eq. (33), is currently stronger than what is proven: the derivation passes through several ideal limits without quantified error bounds. Filling those gaps would turn a plausibly correct idealized proof into a rigorous security statement for the actual finite-parameter scheme.
major comments (4)
- [Sec. 4.3, Lemma 4.1 and Eq. (19)] The replacement of the Gaussian factor e^{-2Delta^2|beta-beta'|^2} by a Dirac delta is an unquantified idealization. For finite QOTP variance Delta^2, which the scheme explicitly allows (only Delta^2 >> 1 is required), Lemma 4.1 keeps off-diagonal terms with beta != beta'; dropping them changes the real-world channel from the exact expression preceding Eq. (19) to an approximate one. No trace-norm bound is provided for the distance between the finite-Delta channel and its Delta-to-infinity limit, and the final bound (33) contains no such error term. Consequently, Eq. (33) is not established for the finite-parameter scheme as described.
- [Sec. 4.5 and Sec. 5, Eqs. (18) and (30)] The acceptance function G defined in Eq. (18) is a product of error functions, not an exact indicator, and the paper explicitly states in Sec. 5 that a rigorous treatment of the step-function approximation is future work. Yet the derivation of Eq. (33) uses the claim, immediately after Eq. (30), that 'G - I evaluates either to 0 or 1' and Table 1, both of which hold only in the exact-step idealization. For finite e^{-r/2} << epsilon, G takes intermediate values, so |G - I| is not a 0/1-valued function and the counting argument (31) does not directly apply. An additive error term depending on epsilon and r must be included in eta, or the theorem must be restated with explicit bounds.
- [Sec. 4.3 and Sec. 4.4] The ideal channel in Sec. 4.4 uses the s -> infinity limit of the two-mode squeezed vacuum, which is a non-normalizable state; the derivation after Eq. (25) then uses Dirac delta functions such as delta(beta - pi^{-1} alpha). No error bound is given for finite s, and the trace distance between the real and ideal channels is not defined if the ideal channel is only a formal limit. This is another load-bearing idealization that needs either a rigorous limiting argument or a quantitative error term.
- [Sec. 4.3, attack expansion] The proof expands an arbitrary adversary unitary U_CR as integral over displacements, U_CR = integral d^2alpha chi(alpha) D_C(alpha) otimes U_R^alpha with integral |chi(alpha)|^2 = 1. In the DV setting this is justified by the finite Pauli basis, but in CV the displacement operators are unbounded and form only a distributional basis; the existence of a normalized coefficient function chi(alpha) for every unitary attack is not established. This expansion underlies the transition from Eq. (14) to Eq. (19) and from Eq. (24) to Eq. (26), so it is a central technical assumption that should be stated and justified.
minor comments (5)
- [Sec. 2.1] The definition of a CV-QECC that corrects arbitrarily large displacements would benefit from a citation; no reference is given for such codes, and the assumption is stronger than what standard CV codes provide.
- [Sec. 3, Eq. (9)] The square-root notation on the POVM elements is redundant because V^acc and V^rej are projectors; simplifying the expression would improve readability.
- [Sec. 4.4, Eq. (20)] The text says the EPR state can be represented as a '50/50 beamsplitter mixture' of two squeezed vacua; more precisely, the two-mode squeezed vacuum is obtained by applying a beamsplitter transformation to two squeezed vacua, not by a mixture.
- [Sec. 4.5, Eq. (31)] Writing the same factor u! in both numerator and denominator is confusing; defining P(u) directly as C(n,u)/C(n+2z,u) would be cleaner.
- [Sec. 3 and Sec. 4.5] The parameter conditions 'Delta^2 >> 1' and 'e^{-r/2} << epsilon' are used throughout without quantitative thresholds; these inequalities are exactly where the missing error terms in Eq. (33) originate, so indicative bounds would be helpful.
Circularity Check
No significant circularity: the security proof is a standard simulator-based argument, with admitted idealizations that are correctness gaps, not circular reductions.
full rationale
The paper derives its claimed bound eta = (n/(n+2z))^(t+1) through an explicit simulator construction and a combinatorial counting argument over secret permutations. The CV twirl (Lemma 4.1) is derived directly from the displacement commutation relation (Eq. (1)); the final security expression (33) follows from bounding the probability that a random permutation places all noisy modes in the message register (Eqs. (31)-(32)), not from fitting any parameter or from restating an assumption. The ideal channel's acceptance region DF is deliberately constructed to mirror the real trap POVM, in particular by setting delta = epsilon/sqrt(2) 'in order to obtain symmetry between all the modes'; this is legitimate because Definition 2.3 only requires existence of some simulator matching the real channel, and the simulator may choose its own acceptance rule. There is no load-bearing self-citation: the cited prior trap-code schemes [1,2] are by other authors, and the proof technique is followed as external prior work rather than smuggled in as an unverified assumption. Two genuine limitations are acknowledged in the text: in Sec. 4.3 the authors say 'We treat the Gaussian factor in the result of the Lemma as a Dirac delta function', replacing a finite-Delta integral by its infinite-Delta limit without an explicit trace-distance error bound; and in Sec. 5 they state that 'A more rigorous treatment of the approximate step functions (in which the difference between the I and G indicators ends up as a small addition to eta) is left for future work.' These are honest gaps between the finite-parameter scheme and the idealized proof, so they affect the rigor of Eq. (33) for finite Delta and finite squeezing, but they do not make any step definitionally circular or turn a fitted input into a prediction. The final bound is a counting result, independent of measured data, and the proof is self-contained modulo these stated approximations.
Assumptions & free parameters
free parameters (3)
- Acceptance threshold epsilon =
unspecified, satisfying e^{-r/2} << epsilon
- Squeezing parameter r =
large, e^{-r/2} << epsilon
- QOTP variance Delta^2 =
Delta >> 1, treated as infinite
assumptions (5)
- domain assumption Existence of a CV-QECC [[n,1,d]] that corrects arbitrarily large displacements in up to t = floor((d-1)/2) modes.
- ad hoc to paper The Gaussian factor e^{-2Delta^2|beta-beta'|^2} acts as a Dirac delta.
- ad hoc to paper The trap acceptance function G behaves as an exact step function for e^{-r/2} << epsilon.
- domain assumption Infinite-squeezed EPR states (s -> infinity) and perfect homodyne measurements are available.
- standard math Displacement operator Weyl relations (Lemma 2.1).
Cite this review
Pith. "Pith review of Authentication of Continuous-Variable Quantum Messages." pith.science (2026). https://pith.science/paper/3XLLUEPM
@misc{pith2026250700095,
author = {Pith},
title = {Pith review of: Authentication of Continuous-Variable Quantum Messages},
year = {2026},
howpublished = {\url{https://pith.science/paper/3XLLUEPM}},
note = {Machine review of arXiv:2507.00095}
}
read the original abstract
We introduce the first quantum authentication scheme for continuous-variable states. Our scheme is based on trap states, and is an adaptation of a discrete-variable scheme by Broadbent et al. (arXiv:1211.1080), but with more freedom in choosing the number of traps. We provide a security proof, mostly following the approach of Broadbent and Wainewright (arXiv:1607.03075). As a necessary ingredient for the proof we derive the continuous-variable analogue of the Pauli Twirl.
Reference graph
Works this paper leans on
-
[1]
In: Advances in Cryptology – CRYPTO 2013, Part II
Broadbent, A., Gutoski, G., Stebila, D.: Quantum one-time programs. In: Advances in Cryptology – CRYPTO 2013, Part II. Lecture Notes in Com- puter Science, vol. 8043, pp. 344–360. Springer, Berlin, Heidelberg (2013). https: //doi.org/10.1007/978-3-642-40084-1 20
-
[2]
Broadbent, A., Wainewright, E.: Efficient simulation for Quantum message authentication. In: Information Theoretic Security: 9th International Conference, ICITS 2016, Tacoma, W A, USA, August 9–12, 2016, Revised Selected Papers. Lecture Notes in Computer Science, vol. 10015, pp. 72–91. Springer, Cham (2016). https://doi.org/10.1007/978-3-319-49175-2 4
-
[3]
Theoretical Computer Science560, 7–11 (2014)
Bennett, C.H., Brassard, G.: Quantum cryptography: Public key distribution and coin tossing. Theoretical Computer Science560, 7–11 (2014). Originally presented 13 at IEEE International Conference on Computers, Systems and Signal Processing, 1984
work page 2014
-
[4]
All´ eaume, R., L¨ utkenhaus, N., Renner, R., Grangier, P., Debuisschert, T., Ribordy, G., Gisin, N., Painchault, P., Pornin, T., Slavail, L., et al.: Quantum key distribution and cryptography: a survey (2010)
work page 2010
-
[5]
npj Quantum Information 2(1), 1–12 (2016)
Diamanti, E., Lo, H.-K., Qi, B., Yuan, Z.: Practical challenges in quantum key distribution. npj Quantum Information 2(1), 1–12 (2016)
work page 2016
-
[6]
IEEE Communications Surveys & Tutorials 24(2), 839–894 (2022)
Cao, Y., Zhao, Y., Wang, Q., Zhang, J., Ng, S.X., Hanzo, L.: The evolution of quantum key distribution networks: On the road to the qinternet. IEEE Communications Surveys & Tutorials 24(2), 839–894 (2022)
work page 2022
-
[7]
In: 41st Annual Symposium on Foundations of Computer Science, pp
Ambainis, A., Mosca, M., Tapp, A., Wolf, R.: Private quantum channels. In: 41st Annual Symposium on Foundations of Computer Science, pp. 547–553 (2000). IEEE
work page 2000
-
[8]
In: Annual Symposium on Foundations of Computer Science, pp
Ambainis, A., Mosca, M., Tapp, A., Wolf, R.: Private quantum channels. In: Annual Symposium on Foundations of Computer Science, pp. 547–553 (2000)
work page 2000
Show all 26 references
-
[9]
Boykin, P.O., Roychowdhury, V.: Optimal encryption of quantum bits. Phys. Rev. A 67(4), 042317 (2003)
2003
-
[10]
Physical Review A—Atomic, Molecular, and Optical Physics 72(4), 042313 (2005)
Br´ adler, K.: Continuous-variable private quantum channel. Physical Review A—Atomic, Molecular, and Optical Physics 72(4), 042313 (2005)
2005
-
[11]
Scientific Reports 5(1), 13974 (2015)
Jeong, K., Kim, J., Lee, S.-Y.: Gaussian private quantum channel with squeezed coherent states. Scientific Reports 5(1), 13974 (2015)
2015
-
[12]
npj Quantum Information 9(1), 92 (2023)
Liu, S., Lu, Z., Wang, P., Tian, Y., Wang, X., Li, Y.: Experimental demonstra- tion of multiparty quantum secret sharing and conference key agreement. npj Quantum Information 9(1), 92 (2023)
2023
-
[13]
Physical review letters 83(3), 648 (1999)
Cleve, R., Gottesman, D., Lo, H.-K.: How to share a quantum secret. Physical review letters 83(3), 648 (1999)
1999
-
[14]
In: Proceedings of the 43rd Annual IEEE Symposium on Foundations of Computer Science (FOCS), pp
Barnum, H., Cr´ epeau, C., Gottesman, D., Smith, A., Tapp, A.: Authentication of Quantum messages. In: Proceedings of the 43rd Annual IEEE Symposium on Foundations of Computer Science (FOCS), pp. 449–458 (2002). https://doi.org/ 10.1109/SFCS.2002.1181969 . IEEE
2002 arXiv
-
[15]
arXiv preprint arXiv:1704.04487 (2017)
Aharonov, D., Ben-Or, M., Eban, E., Mahadev, U.: Interactive proofs for quantum computations. arXiv preprint arXiv:1704.04487 (2017)
2017 arXiv
-
[16]
In: 47th Annual IEEE Symposium on Foundations of Computer Science (FOCS 2006), pp
Ben-Or, M., Cr´ epeau, C., Gottesman, D., Hassidim, A., Smith, A.: Secure mul- tiparty quantum computation with (only) a strict honest majority. In: 47th Annual IEEE Symposium on Foundations of Computer Science (FOCS 2006), pp. 14 249–260. IEEE, Berkeley, CA, USA (2006). https...
2006 doi
-
[17]
In: Advances in Cryptology – CRYPTO 2012
Dupuis, F., Nielsen, J.B., Salvail, L.: Actively secure two-party evaluation of any quantum operation. In: Advances in Cryptology – CRYPTO 2012. Lecture Notes in Computer Science, vol. 7417, pp. 794–811. Springer, Berlin, Heidelberg (2012)
2012
-
[18]
In: Annual International Con- ference on the Theory and Applications of Cryptographic Techniques, pp
Dulek, Y., Grilo, A.B., Jeffery, S., Majenz, C., Schaffner, C.: Secure multi-party quantum computation with a dishonest majority. In: Annual International Con- ference on the Theory and Applications of Cryptographic Techniques, pp. 729–758 (2020). Springer
2020
-
[19]
arXiv preprint arXiv:1610.09434 (2016)
Hayden, P., Leung, D.W., Mayers, D.: The universal composable security of quan- tum message authentication with key recycling. arXiv preprint arXiv:1610.09434 (2016)
2016 arXiv
-
[20]
Physical Review A 72(4), 042309 (2005) https://doi.org/10.1103/PhysRevA.72.042309
Oppenheim, J., Horodecki, M.: How to reuse a one-time pad and other notes on authentication, encryption, and protection of quantum information. Physical Review A 72(4), 042309 (2005) https://doi.org/10.1103/PhysRevA.72.042309
2005 doi
-
[21]
In: Advances in Cryptology–CRYPTO 2017: 37th Annual International Cryptology Conference, Santa Barbara, CA, USA, August 20–24, 2017, Proceedings, Part II 37, pp
Garg, S., Yuen, H., Zhandry, M.: New security notions and feasibility results for authentication of quantum data. In: Advances in Cryptology–CRYPTO 2017: 37th Annual International Cryptology Conference, Santa Barbara, CA, USA, August 20–24, 2017, Proceedings, Part II 37, pp. 3...
2017
-
[22]
Portmann, C.: Quantum authentication with key recycling. In: Advances in Cryp- tology – EUROCRYPT 2017: 36th Annual International Conference on the The- ory and Applications of Cryptographic Techniques, Paris, France, April 30–May 4, 2017, Proceedings, Part III. Lecture Notes ...
2017 doi
-
[23]
In: 13th Conference on the Theory of Quantum Computation, Communication and Cryptography (TQC 2018)
Dulek, Y., Speelman, F.: Quantum ciphertext authentication and key recycling with the trap code. In: 13th Conference on the Theory of Quantum Computation, Communication and Cryptography (TQC 2018). Leibniz International Proceed- ings in Informatics (LIPIcs), vol. 111, pp. 1–11...
2018 arXiv
-
[24]
IACR Communications in Cryptology 1(4) (2025) https://doi.org/10.62056/ah2i5w7sf
Dulek, Y., Muguruza, G., Speelman, F.: An efficient combination of quantum error correction and authentication. IACR Communications in Cryptology 1(4) (2025) https://doi.org/10.62056/ah2i5w7sf
2025 doi
-
[25]
Springer, Berlin, Heidelberg (1994)
Walls, D.F., Milburn, G.J.: Quantum Optics. Springer, Berlin, Heidelberg (1994)
1994
-
[26]
Physical Review A 61(5), 052101 (2000) 15
Jeong, H., Lee, J., Kim, M.: Dynamics of nonlocality for a two-mode squeezed state in a thermal environment. Physical Review A 61(5), 052101 (2000) 15
2000
Reviewed August 6, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.