Pith. sign in

REVIEW 4 major objections 3 minor 100 references

Zigzag approach to higher key rate of sending-or-not-sending twin field quantum key distribution with finite key effects

T0 review · 4 major / 3 minor · reviewed 2026-08-14 · deepseek-v4-flash

Pith's one-line read This paper establishes a finite-key upper bound on the phase-flip error rate of bits surviving odd-parity error rejection in sending-or-not-sending twin-field QKD, and shows the resulting key rates exceed the absolute repeater-less bound.

desk verdict The zigzag finite-key OPER analysis is the right problem and gives striking rates, but the central bound rests on an unproven de Finetti representation and an unproven pairing dominance step, so the result is conditional until those are fixed. read the letter →

arxiv 1908.05670 v3 pith:BA5OA4MS submitted 2019-08-15 quant-ph

classification quant-ph MSC 81P94 PACS 03.67.Dd
keywords twin-fieldquantumkeydistributionsending-or-not-sendingprotocolodd-parityerrorrejectionfinite-keysecurityphase-fliprateexponentialrepresentationtheoremMcDiarmidinequalityrepeater-lesskey-ratebound
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

Odd-parity error rejection (OPER) drastically improves the asymptotic key rate of sending-or-not-sending twin-field (SNS-TF) quantum key distribution, but no efficient finite-size treatment existed for the phase-flip error rate of the bits that survive the rejection step. This paper supplies one through a zigzag argument: it starts from the observed phase-error test on 2n raw pairs, uses an exponential representation of the post-test state as a mixture of nearly independent copies, and ends with the upper bound $e'^{\rm ph}_1 = M_s/n'_1$ on the post-OPER phase-flip error rate together with a failure probability. Inserting this bound into the full finite-key rate formula $R = (2/N)\{\cdots\}$ gives, in the paper's simulations, the highest non-asymptotic key rates among the compared SNS protocols at every distance, including rates that exceed the absolute repeater-less key-rate bound by up to 13 times with $10^{12}$ pulses. An improved concentration inequality for the phase-error estimate adds another 10 to 20 percent to the rate.

What carries the argument

The load-bearing identity is Lemma 3: for a two-qubit state $\sigma$ whose X-basis error probability is $\langle e_\sigma\rangle \le \bar e$, the probability of an X-basis error after odd-parity error rejection on $\sigma^{\otimes 2}$ is at most $\bar e(1-\bar e)$. The zigzag method combines this with two Bernoulli-tail facts (Lemmas 1 and 2) and the exponential almost-i.i.d. representation of the post-test state (Eqs. (4)-(5)). Phase-error test fixes $M$; Theorem 1 shows the weight of states with $\langle e_\sigma\rangle > \langle e_\tau\rangle$ is small; Theorem 2 uses $E_\tau = \langle e_\tau\rangle(1-\langle e_\tau\rangle)$ and a second Bernoulli tail to fix $M_s$ and its failure probability $\tilde\xi_\tau$, giving the final bound Eq. (35).

What would settle it

Compute $\|\rho_{2n} - \tilde\rho_{2n}\|$ for a concrete conditioned SNS state at the simulation parameters of Table I and compare it with $\varepsilon(r,k)$ from Eq. (4); exceeding the bound would invalidate Eq. (35). Alternatively, search over two-qubit states $\sigma$ with $\langle e_\sigma\rangle \le \bar e$ to see whether the post-OPER odd-parity phase-error probability can exceed $\bar e(1-\bar e)$, which would break Lemma 3.

Watch

Extended reading notes

Core claim

The central discovery is a way to bound the phase-flip error rate of the surviving untagged bits after OPER without paying the huge statistical cost of a collective-to-coherent lifting. For the virtual state of $2n$ raw pairs, the paper writes the post-test state as close, in trace distance, to a mixture of approximately i.i.d. states with a small exceptional part. Theorems 1 and 2 then convert the observed constraint that at most $M$ phase errors occur into a bound that far more than $M_s$ phase errors survive OPER; the bound is $e'^{\rm ph}_1 = M_s/n'_1$ with failure probability $\varepsilon_s$. With this quantity in Eq. (37), the reported non-asymptotic key rates are claimed secure: the protocol is $2\varepsilon_{\rm tol}$-secure with $\varepsilon_{\rm tol}=1.8\times10^{-9}$, and the simulated rates break the absolute repeater-less key-rate limit at $N=10^{11}$ and $N=10^{12}$ pulses.

Load-bearing premise

The argument assumes that the finite-size state left after the protocol's filtering is close, in total-variation distance, to a mixture of many identical independent copies, with the closeness decaying exponentially as stated in Eqs. (4)-(5); if that closeness statement fails for the conditioned SNS state, the phase-flip bound and the reported rates do not follow.

Editorial extensions

If this is right

  • The finite-key rate formula $R = \frac{2}{N}\{n'_1[1-h(e'^{\rm ph}_1)] - f n'_t h(E') - \log_2(2/\varepsilon_{\rm cor}) - 2\log_2(1/(\sqrt{2}\,\varepsilon_{PA}\hat\varepsilon))\}$ is secure with the zigzag phase-error bound, with total security parameter $\varepsilon_{\rm tol} = 1.8\times10^{-9}$.
  • At $10^{12}$ pulses the simulated rates reach more than 40 times the practical repeater-less bound and 13 times the absolute bound; at $10^{11}$ pulses the rates still clearly exceed the absolute bound.
  • Compared with prior SNS finite-key results, the new method improves key rates by factors of about 2 to 30 depending on distance and block size, and it keeps a clear advantage in the asymmetric setup with $L_A - L_B = 100$ km.
  • Using the improved concentration inequality for the phase-error numerator raises the finite-key rate by roughly 10% at $10^{12}$ pulses and 20% at $10^{11}$ pulses.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • Extension: the zigzag chain (observed error tail to i.i.d. tail to post-OPER tail) does not use SNS-specific counting formulas, so the same route should transfer to other post-selected QKD protocols whose pre-selection state admits the same exponential almost-i.i.d. representation.
  • Extension: the paper treats $\varepsilon(r,k)$, $\xi_\tau$, and $\tilde\xi_\tau$ as fixed small numbers; re-optimizing these parameters against the block size could shift the rate-versus-distance curves further and is a direct numerical follow-up.
  • Testable extension: sweeping misalignment error and dark-count rates around the Table I values at distances of 300 to 350 km should reproduce the stated 10-20% gain from the improved concentration estimate and would show where that gain saturates.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

4 major / 3 minor

Summary. The paper proposes a finite-key security analysis for the sending-or-not-sending twin-field (SNS-TF) QKD protocol with odd-parity error rejection (OPER/AOPP). The central idea is a 'zigzag' method: first constrain the number of phase errors in a virtual entangled-pair state from a phase-error test, then approximate the 2n-pair state by a de Finetti mixture via Eqs. (4)-(5), propagate the tail bound through OPER in Theorems 1 and 2, and finally obtain an upper bound e'ph_1 = M_s / n'_1 on the phase-flip error rate of surviving untagged bits, Eq. (35). This bound is inserted into the finite-key rate formula Eq. (37). Numerical simulations for N=10^11 and N=10^12 pulses report rates exceeding previous SNS analyses by factors of 2-30, and exceeding the absolute PLOB bound by up to 13 times; an improved McDiarmid inequality is used in method B to claim a further ~20% improvement.

Significance. If the proof were complete, the paper would be significant: it addresses the finite-key bottleneck of OPER-based SNS-TF QKD, gives concrete finite-size rates that surpass the absolute PLOB bound, and compares several prior analyses under shared experimental parameters. The numerical comparisons are explicit and reproducible in structure, which is a strength. The proposed finitization of the OPER phase-error bound is an important target for the community. However, the central proof currently rests on an unproven strong de Finetti representation and an unjustified pairing step in Theorem 2; until those are supplied, the numerical claims are not supported by the presented argument.

major comments (4)
  1. [Section II, Eqs. (4)-(5)] The exponential de Finetti representation is asserted in a form that is not derived and is not shown to apply to the conditioned post-selected state of the SNS protocol. The cited standard theorem concerns permutation-invariant states, but the protocol description in Section III contains no random-permutation/symmetrization step, and no argument is given that conditioning on the untagged/tagged classification and on the X-window statistics preserves permutation invariance of the 2n-pair state. The specific form with finite r non-i.i.d. systems and error term 3 k d e^{-rk/(2n+k)} is also not a direct quote of the cited references. Since Eq. (5) is the first input to Theorems 1 and 2, a proof or a precise theorem statement with all hypotheses is required; without it, Eq. (35) and the rates in Tables II and III do not follow.
  2. [Section II, proof of Theorem 2 (Eq. (27))] The proof of Theorem 2 assumes that OPER on the block-diagonal de Finetti state rho_{2n}^sigma can be treated as independent OPER on sigma^{otimes(2n-2r)} and on sigma^{otimes r} tensor rho~_sigma^r. In the actual protocol the 2n systems are paired uniformly at random, so pairs generally cross the i.i.d./non-i.i.d. boundary; no coupling or stochastic-dominance argument is supplied to show that the aligned pairing used in the proof bounds the tail probability of the actual random pairing. Note also that the i.i.d. block in Eq. (5) has 2n-r systems, while the Bernoulli block in Theorem 2 has only 2n-2r systems; the extra r systems are silently reassigned to the non-i.i.d. block. This step is load-bearing for the bound M_s, so it must be proved explicitly.
  3. [Section III, Eqs. (29)-(34)] There is an internal inconsistency between the de Finetti error bound in Eq. (4) and the formula for r in Eq. (34). If Eq. (4) is taken literally with d=2 and epsilon(r,k)=10^{-13}, solving gives r = ((2n+k)/k) ln(6k/10^{-13}), whereas Eq. (34) states r = ((2n+k)/k) ln(3k^2/10^{-13}). The manuscript should clarify whether Eq. (4) or Eq. (34) contains a typo, and should state the correct relation, because r enters the claimed security parameter epsilon(r,k) used in Eq. (35).
  4. [Appendix B, Eqs. (B1)-(B3)] The derivation of the McDiarmid bound is garbled as written. In Eq. (B1), the target expression <T_X1> - e^{-mu1-mu'1}<S_oo'>/2 is rewritten with the N_X1 sum absent from the displayed right-hand side, and the equality with the final sum W_j expression is not correct as displayed. The definitions n_T=m_X1+n_oo' and S_T=n_T/(N_X1+N_oo') do not match a sum over N_X1+N_oo' terms, and the normalization in Eq. (B3) is inconsistent with the standard McDiarmid tail used in the text. Since this appendix is the basis for the 'method B' rates and the claimed 20% improvement, it must be corrected before those numerical improvements can be assessed.
minor comments (3)
  1. [Abstract and Introduction] There are repeated words and typos, e.g., 'the the absolute bound' in the abstract and 'finial key' in the Introduction; these should be corrected.
  2. [Section II, page 3] 'de Finettis' should read 'de Finetti'; also, the factor 2 in Eq. (7) should be checked against the convention used for the trace distance in Eq. (4), since the two conventions differ by a factor of 2.
  3. [Appendix B] The random variables W_j and W'_j are not defined with their ranges and dependencies before being used in the McDiarmid inequality; adding explicit definitions and the bounded-difference ranges would improve readability.

Circularity Check

0 steps flagged · score 2.0 of 10

No significant circularity: the finite-key OPER phase-error bound is derived from independently observed X-window statistics via Chernoff/McDiarmid bounds and an external de Finetti representation; the predicted quantity is not used as an input.

full rationale

The central derivation chain for e'_ph1 = M_s/n'_1 (Eq. 35) starts from observed X-window error counts and decoy-state yields. The parameter M is obtained from the estimated pre-OPER phase-flip rate with a Chernoff bound (Eq. 33, Appendices A and B), and M_s is then computed from binomial tail equations (Eq. 29) without using the final key rate or e'_ph1 itself. Theorems 1 and 2 are proved in the paper starting from the exponential de Finetti representation (Eqs. 4-5), which is cited to Renner [85,86], not to the authors' own work. Lemma 3 is re-proved in the text (Eqs. 20-25). The AOPP-to-OPER equivalence is taken from the authors' prior Ref. [20], and some SNS parameter-estimation formulas are also self-cited, but these are prior external results rather than fitted parameters or definitional identities. The main vulnerability is whether the de Finetti representation applies to the conditioned, post-selected untagged-pair state of the actual SNS protocol; that is a correctness gap, not circularity.

Assumptions & free parameters 2 free parameters · 5 assumptions · 0 invented entities

The central claim rests on one strong analytic assumption (the de Finetti full-state form), a set of protocol-equivalence assumptions inherited from prior work, and standard tail bounds. The numerical headline rates also depend on source parameters that are optimized but not tabulated. No new physical entities are introduced.

free parameters (2)
  • source parameters p_z, p_0, p_1, mu1, mu2, mu_z, epsilon (and Bob's counterparts) = not reported, numerically optimized per distance
    The claimed key rates are maxima over these parameters; different choices give different rates, so the headline numbers depend on them. This is standard in QKD protocol analysis and does not affect the security proof.
  • security parameters xi_tau, xi~_tau, epsilon(r,k) = 10^-2, 10^-10, 10^-13
    Chosen by hand to control failure probabilities in the zigzag bound; they affect e'^{ph}_1 and hence the key rate.
assumptions (5)
  • domain assumption The exponential de Finetti representation of Eq. (5): rho~_{2n} = integral P_sigma sigma^{otimes(2n-r)} otimes rho~^r_sigma dsigma with trace-distance bound (4)
    Invoked in Sec. II A and used for Theorems 1 and 2; not proved in the paper, and the standard theorem in the cited references bounds a reduced state rather than the full state with arbitrary junk systems.
  • domain assumption Permutation-invariance of the 2n-pair state after the phase-flip error test and parameter estimation
    Required for any de Finetti theorem; the paper does not describe a symmetrization step, relying on the virtual protocol structure.
  • domain assumption Equivalence between active OPER (AOPP) and virtual OPER with random pairing, including the factor u = n_g/n_odd (Eq. 30)
    Taken from the authors' prior work Ref. [20]; the finite-key version assumes this equivalence holds after finite sampling.
  • domain assumption Linear optical channel model for the numerical simulation of observed counts S_{kappa zeta}
    Used in Sec. V and Appendix C to produce simulated counts; the claimed rates are only as trustworthy as this model.
  • standard math Chernoff bound and McDiarmid inequality tail bounds
    Used for converting expected values to observed values and estimating the phase-error numerator; standard results, but Eq. (B3) appears to misapply the McDiarmid constant.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Zigzag approach to higher key rate of sending-or-not-sending twin field quantum key distribution with finite key effects." pith.science (2026). https://pith.science/paper/BA5OA4MS

@misc{pith2026190805670,
  author       = {Pith},
  title        = {Pith review of: Zigzag approach to higher key rate of sending-or-not-sending twin field quantum key distribution with finite key effects},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/BA5OA4MS}},
  note         = {Machine review of arXiv:1908.05670}
}
abstract

Odd-parity error rejection (OPER) can drastically improve the asymptotic key rate of sending-or-not-sending twin-field (SNS-TF) quantum key distribution (QKD). However, in practice, the finite key effects have to be considered for security. Here, we propose a zigzag approach to verify the phase-flip error of the survived bits after OPER. Based on this, we can take all the finite key effect efficiently in calculating the non-asymptotic key rate. Numerical simulation shows that our method here produces the highest key rate over all distances among all existing methods, improving the key rate by more than $100\%$ to $3000\%$ in comparison with different prior art methods with typical experimental setting. Also, we show that with the method here, the SNS-TF QKD can by far break the the absolute bound of repeater-less key rate with whatever detection efficiency. We can even reach a non-asymptotic key rate more than $40$ times of the practical bound and $13$ times of the absolute bound with $10^{12}$ pulses. Besides, we apply the McDiarmid inequality to estimate the phase flip error rate, further improving the key rate by more than $20\%$.

Figures

Figures reproduced from arXiv: 1908.05670 by the authors.

Figure 2
Figure 2. The key rates show that the method of this work improve [PITH_FULL_IMAGE:figures/full_fig_p010_2.png] view at source ↗
Figure 1
Figure 1. FIG. 1: The optimal key rates (per pulse) versus transmissio [PITH_FULL_IMAGE:figures/full_fig_p011_1.png] view at source ↗
Figure 2
Figure 2. FIG. 2: The optimal key rates (per pulse) versus transmissio [PITH_FULL_IMAGE:figures/full_fig_p011_2.png] view at source ↗
Figures from the paper (2 more)
Figure 3
Figure 3. Figure 3: FIG. 3: The optimal key rates (per pulse) versus transmissio [PITH_FULL_IMAGE:figures/full_fig_p012_3.png]
Figure 4
Figure 4. Figure 4: FIG. 4: The optimal key rates (per pulse) versus transmissio [PITH_FULL_IMAGE:figures/full_fig_p012_4.png]

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

100 extracted references · 74 canonical work pages

  1. [1]

    The protocol itself must be secure

  2. [2]

    A reasonable finite size of the key should be assumed and the finite k ey effects should be considered in calculation

  3. [3]

    For this goal, we need to consider the finite key effects and we need t o show a high key rate exceeding the absolute PLOB bound

    The actual key rate should break the absolute PLOB bound [80], wh ich upper bounds the repeater-less key rate given whatever local devices, including the perfect detection devic es. For this goal, we need to consider the finite key effects and we need t o show a high key rate exceeding the absolute PLOB bound. Before going into further details, let us first ...

  4. [4]

    On the other hand, this probability is just ∑ m≥ M pm

    According to the phase-flip error test in the very beginning [19, 6 7, 88], we can find that the probability for m ≥ ¯M is less than εe, where m is the number of phase-flip errors from those 2 n pairs in state ρ2n. On the other hand, this probability is just ∑ m≥ M pm. Therefore we can constrain values of {pm} by Pr {pm} (m ≥ M ) ≤ εe. (9)

  5. [5]

    (7) and (9), we can further restrict values of {qm} by Pr {qm} (m ≥ M ) ≤ εe + 2ε(r, k)

    Since the trace distance between ρ2n and its associate state ˜ ρ2n is small, with Eqs. (7) and (9), we can further restrict values of {qm} by Pr {qm} (m ≥ M ) ≤ εe + 2ε(r, k). (10)

  6. [6]

    With this, we can constrain values of {q′ ms} based on the fact that ˜ρ2n is the probabilistic mixture of approximate i.i.d. state. Suppose we have Pr {q′ms } (ms ≥ Ms) ≤ ˜εs, (11) where Ms is an estimated value and ˜ εs is the corresponding failure probability

  7. [7]

    (8) and (11), which is Pr {p′ ms } (ms ≥ Ms) ≤ ˜εs + 2ε(r, k) = εs

    Again, since the trace distance between ρ2n and its associate state ˜ρ2n is small, with the bounded result in step 3, we can now restrict values of {p′ ms} by Eqs. (8) and (11), which is Pr {p′ ms } (ms ≥ Ms) ≤ ˜εs + 2ε(r, k) = εs. (12)

  8. [8]

    Among all values and failure probability appeared in Eqs

    Finally, with constraint on {p′ ms} in step 4, we can get the upper bound of the phase-flip error rate e′ph 1 with a failure probability εs, which is e′ph 1 = Ms n′ 1 , (13) where n′ 1 is the number of survived pairs after OPER. Among all values and failure probability appeared in Eqs. (7-11), M and εe could be get from the phase-flip error test in the very...

Show all 100 references
  1. [9]

    0 × 10−8 3% 30 . 0% 1 . 1 0 . 2 TABLE I: List of experimental parameters used in numerical s imulations. Here pd is the dark count rate of Charlie’s detectors; ed is the misalignment-error probability; ηd is the detection efficiency of Charlie’s detectors; f is the error correct...

  2. [10]

    , (A2) ⟨s10 ⟩ = µ2 2eµ 1⟨Sxo′ ⟩ − µ2 1eµ 2⟨Syo′ ⟩ − (µ2 2 − µ2 1)⟨Soo′⟩ µ2µ1(µ2 − µ1) . (A3) 14 Then we can get the lower bound of the expected value of the count ing rate of untagged photons ⟨s1⟩ = µ1 µ1 + µ′ 1 ⟨s10 ⟩ + µ′ 1 µ1 + µ′ 1 ⟨s01 ⟩, (A4) and ⟨n10⟩ = N pzp′ zǫ(1 − ǫ′...

  3. [11]

    C. H. Bennett and G. Brassard, in Proceedings of the IEEE International Conference on Comput ers, Systems, and Signal Processing (1984), pp. 175–179

  4. [12]

    Gisin, G

    N. Gisin, G. Ribordy, W. Tittel, and H. Zbinden, Reviews o f modern physics 74, 145 (2002)

  5. [13]

    Gisin and R

    N. Gisin and R. Thew, Nature photonics 1, 165 (2007)

  6. [14]

    Scarani, H

    V. Scarani, H. Bechmann-Pasquinucci, N. J. Cerf, M. Duˇ s ek, N. L¨ utkenhaus, and M. Peev, Reviews of modern physics 81, 1301 (2009)

  7. [15]

    P. W. Shor and J. Preskill, Physical review letters 85, 441 (2000)

  8. [16]

    Koashi, New Journal of Physics 11, 045018 (2009)

    M. Koashi, New Journal of Physics 11, 045018 (2009)

  9. [17]

    Tamaki, M

    K. Tamaki, M. Koashi, and N. Imoto, Physical review lette rs 90, 167904 (2003)

  10. [18]

    Kraus, N

    B. Kraus, N. Gisin, and R. Renner, Physical review letter s 95, 080501 (2005). 16

  11. [19]

    Lucamarini, Z

    M. Lucamarini, Z. L. Yuan, J. F. Dynes, and A. J. Shields, N ature 557, 400 (2018)

  12. [20]

    Wang, Z.-W

    X.-B. Wang, Z.-W. Yu, and X.-L. Hu, Physical Review A 98, 062323 (2018)

  13. [21]

    Tamaki, H.-K

    K. Tamaki, H.-K. Lo, W. Wang, and M. Lucamarini, arXiv pr eprint arXiv:1805.05511 (2018)

  14. [22]

    X. Ma, P. Zeng, and H. Zhou, Physical Review X 8, 031043 (2018)

  15. [23]

    Lin and N

    J. Lin and N. L¨ utkenhaus, Physical Review A 98, 042332 (2018)

  16. [24]

    Cui, Z.-Q

    C. Cui, Z.-Q. Yin, R. Wang, W. Chen, S. Wang, G.-C. Guo, an d Z.-F. Han, Physical Review Applied 11, 034053 (2019)

  17. [25]

    Curty, K

    M. Curty, K. Azuma, and H.-K. Lo, npj Quantum Informatio n 5, 64 (2019)

  18. [26]

    Yu, X.-L

    Z.-W. Yu, X.-L. Hu, C. Jiang, H. Xu, and X.-B. Wang, Scien tific Reports 9, 3080 (2019)

  19. [27]

    Maeda, T

    K. Maeda, T. Sasaki, and M. Koashi, Nature communicatio ns 10, 3140 (2019)

  20. [28]

    Lu, Z.-Q

    F.-Y. Lu, Z.-Q. Yin, R. Wang, G.-J. Fan-Yuan, S. Wang, D. -Y. He, W. Chen, W. Huang, B.-J. Xu, G.-C. Guo, et al., New Journal of Physics 21, 123030 (2019)

  21. [29]

    Jiang, Z.-W

    C. Jiang, Z.-W. Yu, X.-L. Hu, and X.-B. Wang, Physical Re view Applied 12, 024061 (2019)

  22. [30]

    Xu, Z.-W

    H. Xu, Z.-W. Yu, C. Jiang, X.-L. Hu, and X.-B. Wang, arXiv preprint arXiv:1904.06331 (2019)

  23. [31]

    X.-L. Hu, C. Jiang, Z.-W. Yu, and X.-B. Wang, Phys. Rev. A 100, 062337 (2019)

  24. [32]

    Zhang, C.-M

    C.-H. Zhang, C.-M. Zhang, and Q. Wang, Optics letters 44, 1468 (2019)

  25. [33]

    Zhou, C.-H

    X.-Y. Zhou, C.-H. Zhang, C.-M. Zhang, and Q. Wang, Physi cal Review A 99, 062316 (2019)

  26. [34]

    Huttner, N

    B. Huttner, N. Imoto, N. Gisin, and T. Mor, Physical Revi ew A 51, 1863 (1995)

  27. [35]

    H. P. Yuen, Quantum and Semiclassical Optics: Journal o f the European Optical Society Part B 8, 939 (1996)

  28. [36]

    Brassard, N

    G. Brassard, N. L¨ utkenhaus, T. Mor, and B. C. Sanders, P hysical Review Letters 85, 1330 (2000)

  29. [37]

    L¨ utkenhaus, Physical Review A 61, 052304 (2000)

    N. L¨ utkenhaus, Physical Review A 61, 052304 (2000)

  30. [38]

    L¨ utkenhaus and M

    N. L¨ utkenhaus and M. Jahma, New Journal of Physics 4, 44 (2002)

  31. [39]

    Lydersen, C

    L. Lydersen, C. Wiechers, C. Wittmann, D. Elser, J. Skaa r, and V. Makarov, Nature photonics 4, 686 (2010)

  32. [40]

    Gerhardt, Q

    I. Gerhardt, Q. Liu, A. Lamas-Linares, J. Skaar, C. Kurt siefer, and V. Makarov, Nature communications 2, 349 (2011)

  33. [41]

    Scarani and R

    V. Scarani and R. Renner, Physical review letters 100, 200501 (2008)

  34. [42]

    Hwang, Physical Review Letters 91, 057901 (2003)

    W.-Y. Hwang, Physical Review Letters 91, 057901 (2003)

  35. [43]

    Wang, Physical Review Letters 94, 230503 (2005)

    X.-B. Wang, Physical Review Letters 94, 230503 (2005)

  36. [44]

    H.-K. Lo, X. Ma, and K. Chen, Physical review letters 94, 230504 (2005)

  37. [45]

    X.-B. Wang, T. Hiroshima, A. Tomita, and M. Hayashi, Phy sics reports 448, 1 (2007)

  38. [46]

    Adachi, T

    Y. Adachi, T. Yamamoto, M. Koashi, and N. Imoto, Physica l review letters 99, 180503 (2007)

  39. [47]

    Wang, C.-Z

    X.-B. Wang, C.-Z. Peng, and J.-W. Pan, Applied physics l etters 90, 031110 (2007)

  40. [48]

    Wang, C.-Z

    X.-B. Wang, C.-Z. Peng, J. Zhang, L. Yang, and J.-W. Pan, Physical Review A 77, 042311 (2008)

  41. [49]

    X.-B. Wang, L. Yang, C.-Z. Peng, and J.-W. Pan, New Journ al of Physics 11, 075006 (2009)

  42. [50]

    Yu, Y.-H

    Z.-W. Yu, Y.-H. Zhou, and X.-B. Wang, Physical Review A 93, 032307 (2016)

  43. [51]

    H. F. Chau, Phys. Rev. A 97, 040301 (2018)

  44. [52]

    Rosenberg, J

    D. Rosenberg, J. W. Harrington, P. R. Rice, P. A. Hiskett , C. G. Peterson, R. J. Hughes, A. E. Lita, S. W. Nam, and J. E. Nordholt, Physical review letters 98, 010503 (2007)

  45. [53]

    Schmitt-Manderbach, H

    T. Schmitt-Manderbach, H. Weier, M. F¨ urst, R. Ursin, F . Tiefenbacher, T. Scheidl, J. Perdigues, Z. Sodnik, C. Kurt siefer, J. G. Rarity, et al., Physical Review Letters 98, 010504 (2007)

  46. [54]

    C.-Z. Peng, J. Zhang, D. Yang, W.-B. Gao, H.-X. Ma, H. Yin , H.-P. Zeng, T. Yang, X.-B. Wang, and J.-W. Pan, Physical review letters 98, 010505 (2007)

  47. [55]

    Liao, W.-Q

    S.-K. Liao, W.-Q. Cai, W.-Y. Liu, L. Zhang, Y. Li, J.-G. R en, J. Yin, Q. Shen, Y. Cao, Z.-P. Li, et al., Nature 549, 43 (2017)

  48. [56]

    M. Peev, C. Pacher, R. All´ eaume, C. Barreiro, J. Bouda, W. Boxleitner, T. Debuisschert, E. Diamanti, M. Dianati, J. Dynes, et al., New Journal of Physics 11, 075001 (2009)

  49. [57]

    T.-Y. Chen, J. Wang, H. Liang, W.-Y. Liu, Y. Liu, X. Jiang , Y. Wang, X. Wan, W.-Q. Cai, L. Ju, et al., Optics express 18, 27217 (2010)

  50. [58]

    Sasaki, M

    M. Sasaki, M. Fujiwara, H. Ishizuka, W. Klaus, K. Wakui, M. Takeoka, S. Miki, T. Yamashita, Z. Wang, A. Tanaka, et al., Optics express 19, 10387 (2011)

  51. [59]

    Fr¨ ohlich, J

    B. Fr¨ ohlich, J. F. Dynes, M. Lucamarini, A. W. Sharpe, Z . Yuan, and A. J. Shields, Nature 501, 69 (2013)

  52. [60]

    Boaron, G

    A. Boaron, G. Boso, D. Rusca, C. Vulliez, C. Autebert, M. Caloz, M. Perrenoud, G. Gras, F. Bussi` eres, M.-J. Li, et al. , Physical review letters 121, 190502 (2018)

  53. [61]

    Q. Wang, W. Chen, G. Xavier, M. Swillo, T. Zhang, S. Sauge , M. Tengner, Z.-F. Han, G.-C. Guo, and A. Karlsson, Physical Review Letters 100, 090501 (2008)

  54. [62]

    F. Xu, Y. Zhang, Z. Zhou, W. Chen, Z. Han, and G. Guo, Physi cal Review A 80, 062309 (2009)

  55. [63]

    Sasaki, Y

    T. Sasaki, Y. Yamamoto, and M. Koashi, Nature 509, 475 (2014)

  56. [64]

    Takesue, T

    H. Takesue, T. Sasaki, K. Tamaki, and M. Koashi, Nature P hotonics 9, 827 (2015)

  57. [65]

    S. L. Braunstein and S. Pirandola, Physical Review Lett ers 108, 130502 (2012)

  58. [66]

    H.-K. Lo, M. Curty, and B. Qi, Physical Review Letters 108, 130503 (2012)

  59. [67]

    Wang, Physical Review A 87, 012320 (2013)

    X.-B. Wang, Physical Review A 87, 012320 (2013)

  60. [68]

    Rubenok, J

    A. Rubenok, J. A. Slater, P. Chan, I. Lucio-Martinez, an d W. Tittel, Physical Review Letters 111, 130501 (2013)

  61. [69]

    Liu, T.-Y

    Y. Liu, T.-Y. Chen, L.-J. Wang, H. Liang, G.-L. Shentu, J . Wang, K. Cui, H.-L. Yin, N.-L. Liu, L. Li, et al., Physical Review Letters 111, 130502 (2013)

  62. [70]

    Z. Tang, Z. Liao, F. Xu, B. Qi, L. Qian, and H.-K. Lo, Physi cal Review Letters 112, 190503 (2014)

  63. [71]

    Tang, H.-L

    Y.-L. Tang, H.-L. Yin, S.-J. Chen, Y. Liu, W.-J. Zhang, X . Jiang, L. Zhang, J. Wang, L.-X. You, J.-Y. Guan, et al., 17 Physical Review Letters 113, 190501 (2014)

  64. [72]

    Wang, X.-T

    C. Wang, X.-T. Song, Z.-Q. Yin, S. Wang, W. Chen, C.-M. Zh ang, G.-C. Guo, and Z.-F. Han, Physical Review Letters 115, 160502 (2015)

  65. [73]

    Comandar, M

    L. Comandar, M. Lucamarini, B. Fr¨ ohlich, J. Dynes, A. S harpe, S.-B. Tam, Z. Yuan, R. Penty, and A. Shields, Nature Photonics 10, 312 (2016)

  66. [74]

    Yin, T.-Y

    H.-L. Yin, T.-Y. Chen, Z.-W. Yu, H. Liu, L.-X. You, Y.-H. Zhou, S.-J. Chen, Y. Mao, M.-Q. Huang, W.-J. Zhang, et al., Physical Review Letters 117, 190501 (2016)

  67. [75]

    Wang, Z.-Q

    C. Wang, Z.-Q. Yin, S. Wang, W. Chen, G.-C. Guo, and Z.-F. Han, Optica 4, 1016 (2017)

  68. [76]

    F. Xu, M. Curty, B. Qi, and H.-K. Lo, New Journal of Physic s 15, 113007 (2013)

  69. [77]

    Curty, F

    M. Curty, F. Xu, W. Cui, C. C. W. Lim, K. Tamaki, and H.-K. L o, Nature communications 5, 3732 (2014)

  70. [78]

    F. Xu, H. Xu, and H.-K. Lo, Physical Review A 89, 052333 (2014)

  71. [79]

    Yu, Y.-H

    Z.-W. Yu, Y.-H. Zhou, and X.-B. Wang, Physical Review A 91, 032318 (2015)

  72. [80]

    Zhou, Z.-W

    Y.-H. Zhou, Z.-W. Yu, and X.-B. Wang, Physical Review A 93, 042324 (2016)

  73. [81]

    Jiang, Z.-W

    C. Jiang, Z.-W. Yu, and X.-B. Wang, Physical Review A 95, 032325 (2017)

  74. [82]

    Takeoka, S

    M. Takeoka, S. Guha, and M. M. Wilde, Nature communicati ons 5, 5235 (2014)

  75. [83]

    Pirandola, R

    S. Pirandola, R. Garc ´ ıa-Patr´ on, S. L. Braunstein, and S. Lloyd, Physical review letters 102, 050503 (2009)

  76. [84]

    Minder, M

    M. Minder, M. Pittaluga, G. Roberts, M. Lucamarini, J. D ynes, Z. Yuan, and A. Shields, Nature Photonics 13, 334 (2019)

  77. [85]

    Liu, Z.-W

    Y. Liu, Z.-W. Yu, W. Zhang, J.-Y. Guan, J.-P. Chen, C. Zha ng, X.-L. Hu, H. Li, C. Jiang, J. Lin, et al., Physical Review Letters 123, 100505 (2019)

  78. [86]

    Wang, D.-Y

    S. Wang, D.-Y. He, Z.-Q. Yin, F.-Y. Lu, C.-H. Cui, W. Chen , Z. Zhou, G.-C. Guo, and Z.-F. Han, Physical Review X 9, 021046 (2019)

  79. [87]

    Zhong, J

    X. Zhong, J. Hu, M. Curty, L. Qian, and H.-K. Lo, Physical Review Letter 123, 100506 (2019)

  80. [88]

    X.-T. Fang, P. Zeng, H. Liu, M. Zou, W. Wu, Y.-L. Tang, Y.- J. Sheng, Y. Xiang, W. Zhang, H. Li, et al., arXiv preprint arXiv:1908.01271 (2019)

  81. [89]

    Chau and K

    H. Chau and K. Ng, arXiv preprint arXiv:1906.12115 (acc epted by New J. Phys.) (2019)

  82. [90]

    Pirandola, R

    S. Pirandola, R. Laurenza, C. Ottaviani, and L. Banchi, Nature communications 8, 15043 (2017)

  83. [91]

    H. F. Chau, Physical Review A 66, 060302 (2002)

  84. [92]

    Gottesman and H.-K

    D. Gottesman and H.-K. Lo, IEEE Transactions on Informa tion Theory 49, 457 (2003)

  85. [93]

    Kraus, C

    B. Kraus, C. Branciard, and R. Renner, Physical Review A 75, 012316 (2007)

  86. [94]

    Christandl, R

    M. Christandl, R. K¨ onig, and R. Renner, Physical revie w letters 102, 020504 (2009)

  87. [95]

    Renner, Ph.D

    R. Renner, Ph.D. thesis, SWISS FEDERAL INSTITUTE OF TEC HNOLOGY ZURICH (2005)

  88. [96]

    Renner, Nature Physics 3, 645 (2007)

    R. Renner, Nature Physics 3, 645 (2007)

  89. [97]

    M. A. Nielsen and I. Chuang, Quantum computation and quantum information (2002)

  90. [98]

    Tomamichel, C

    M. Tomamichel, C. C. W. Lim, N. Gisin, and R. Renner, Natu re communications 3, 634 (2012)

  91. [99]

    Vitanov, F

    A. Vitanov, F. Dupuis, M. Tomamichel, and R. Renner, IEE E Transactions on Information Theory 59, 2603 (2013)

  92. [100]

    Chernoff et al., The Annals of Mathematical Statistic s 23, 493 (1952)

    H. Chernoff et al., The Annals of Mathematical Statistic s 23, 493 (1952)

Pith tools

Reviewed August 14, 2026 · model on record in the stance chip above.