REVIEW 4 minor 44 references
Passive entanglement-based key distribution is secure even with biased basis choice, and matches active rates.
Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →
T0 review · grok-4.5
2026-07-14 10:09 UTC pith:BTXGKGE6
load-bearing objection Solid asymptotic security proof for biased passive BBM92/QCKA that closes a real open gap; virtual-qubit reduction is the genuine technical step and the numerics show the rate is essentially tight.
Security of passive entanglement-based key distribution protocols
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
Core claim
In the asymptotic limit, the passive BBM92 protocol with biased basis choice is information-theoretically secure, and the same proof technique extends to passive GHZ-state quantum conference key agreement for any number of parties. The lower bounds on the secret-key rates (Theorems 1 and 2) are obtained by bounding the phase-error rate of the single-photon subspace via observed X-basis error rates and cross-click rates; under realistic source and detector parameters the passive rates are almost identical to the active ones.
What carries the argument
A virtual-qubit construction for receivers: for single-photon events the actual passive POVM is rewritten as a filter, a fixed CPTP map, and then an ideal active Z/X measurement; the phase-error rate on that virtual qubit is related by a simple probability factor to the observed X-basis error rate, allowing complementarity-based privacy amplification to be applied directly.
Load-bearing premise
All multi-photon and vacuum events are treated as having phase-error rate one-half and are therefore discarded through privacy amplification, so secret key is extracted only from the single-photon subspace.
What would settle it
Under the paper’s own PDC source model and detector parameters, compute the asymptotic key-rate lower bound of Theorem 1 for the passive protocol and the corresponding active-protocol bound; if they diverge by more than a few percent over typical fiber lengths, or if a tighter multi-photon analysis yields a higher rate than the single-photon-only bound, the claimed near-equivalence fails.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The manuscript proves asymptotic security of passive entanglement-based key distribution with biased basis choice. For the two-party BBM92 protocol it introduces an equivalent virtual measurement (QND photon-number measurement followed by a lossless beam splitter with adjusted ratios and unit-efficiency detectors), defines a virtual qubit on Alice’s side via a filter-plus-CPTP map (Kraus operators that absorb dark counts), and bounds the phase-error rate of the single-photon subspace by the observed X-basis error rate via explicit POVM elements and Azuma’s inequality. Multi-photon and vacuum events are assigned phase-error rate 1/2 and discarded. The resulting key-rate lower bound (Theorem 1) is expressed solely in terms of observed click statistics. The same virtual-qubit construction is extended to GHZ-based QCKA for an arbitrary number of parties (Theorem 2). Closed-form expressions for the relevant yields under a PDC source are derived and used to show that the passive BBM92 rate is essentially identical to the active rate under realistic parameters.
Significance. Passive biased-basis measurements are the practical default for entanglement-based QKD and QCKA, yet standard squashing and complementarity arguments do not apply. Closing this gap with a complete asymptotic security proof for both BBM92 and multipartite QCKA is therefore of clear practical and theoretical value. The virtual-qubit reduction is carefully constructed, the POVM derivations (Appendices B–C) and Azuma arguments (Appendix A) are explicit, and the numerical comparison (Fig. 5 together with the closed-form yields of Appendices E–F) demonstrates that the bound is essentially tight under realistic PDC parameters. These strengths make the work a solid foundation for passive implementations.
minor comments (4)
- In the statement of Theorem 2 the precondition still writes the two-party factor \bar p_Z^{2}\gamma/\bar p_X^{2} rather than the (N+1)-party factor that appears in the rate formula; the typographical inconsistency should be corrected for clarity.
- The definition of the virtual qubit for n_A=1 is deferred to the proof of Lemma 1; a brief forward reference or one-sentence summary in Sec. II B 2 would improve readability.
- Fig. 5 caption and the surrounding text could note more explicitly that the small long-distance gap is attributed to dark-count sensitivity (as already discussed for passive BB84) rather than looseness of the bound.
- A few minor typographical issues appear (e.g., “ralation” for “relation” near Eq. (90), occasional missing spaces around mathematical symbols).
Circularity Check
No significant circularity: asymptotic key-rate lower bounds follow from independent POVM/operator inequalities and complementarity, not from self-definition or fitted inputs.
full rationale
The central claims (Theorems 1–2) are obtained by (i) constructing an equivalent virtual protocol whose POVM elements are derived from first principles (Appendices B–C), (ii) defining a virtual qubit so that its Z outcomes reproduce the sifted key while its X outcomes define the phase-error rate, (iii) relating the single-photon phase-error operator to the observed X-error operator by a constant factor (Lemma 1 / Eq. (24)), (iv) bounding multi-photon contributions by cross-click operators via operator inequalities (Lemma 2), and (v) applying concavity of binary entropy plus Azuma’s inequality. None of these steps presupposes the final rate expression; the rate is a consequence of the bounds. Self-citations to the authors’ earlier passive-BB84 work and to standard complementarity papers are used only as black-box tools or motivational analogies; the present derivation re-derives the necessary operator relations for the entanglement setting and does not import an unverified uniqueness claim or a fitted parameter that is later re-labeled a prediction. Numerical key rates are simulations of the derived lower bound under a standard PDC model, not empirical predictions forced by a fit. The conservative assignment of phase-error rate 1/2 to multi-photon events is a deliberate worst-case choice that loosens the bound but does not create circularity. Hence the derivation chain is self-contained against its own inputs.
Axiom & Free-Parameter Ledger
free parameters (5)
- dark-count probability d
- detector efficiency η_Z_det = η_X_det
- misalignment/error rate e_d
- error-correction efficiency factor
- signal intensity µ and basis probability p_Z
axioms (4)
- standard math Azuma’s inequality implies asymptotic equality (or inequality) of observed frequencies whenever the corresponding POVM elements are proportional (or ordered).
- domain assumption Complementarity security proof: the amount of privacy amplification is determined by the phase-error rate of a virtual X measurement on a virtual qubit whose Z measurement reproduces the sifted key.
- domain assumption POVM elements of threshold-detector measurements are block-diagonal in photon number, so a non-destructive photon-number measurement can be inserted without changing statistics.
- ad hoc to paper For all events with photon number ≠ 1 the phase-error rate is taken to be 1/2 (worst-case).
invented entities (1)
-
Virtual qubit for entanglement-based receivers (especially the n = 1 case defined via filter + CPTP map of Kraus operators K_l)
no independent evidence
read the original abstract
Entanglement-based key distribution protocols, such as the Bennett-Brassard-Mermin 1992 (BBM92) protocol and quantum conference key agreement (QCKA), are promising applications of quantum networks. In practical implementations, passive measurement setups are widely adopted because of their simplicity. However, the security analysis of passive protocols with biased basis choice is highly nontrivial, since standard proof techniques for threshold detectors are generally not applicable in this setting. In this work, we establish the security of passive entanglement-based key distribution protocols in the asymptotic regime. Specifically, we prove the security of passive BBM92 with biased basis choice and extend the proof to passive QCKA with an arbitrary number of parties. In addition, we numerically show that the key generation rate of passive BBM92 is almost identical to that of the corresponding active protocol. Our results provide a theoretical foundation for practical passive implementations of entanglement-based key distribution protocols.
Figures
Reference graph
Works this paper leans on
-
[1]
This alternative protocol is defined by replacing step (2) of the actual protocol with the following: (2’)Measurement: As shown in Fig
Alternative protocol Our starting point is to introduce an alternative protocol which is equivalent to the actual protocol from the viewpoint of an eavesdropper, Eve. This alternative protocol is defined by replacing step (2) of the actual protocol with the following: (2’)Measurement: As shown in Fig. 2, Alice performs a polarization-independent QND measu...
-
[2]
Phase error and privacy amplification In this paper, we adopt the security proof with complemen- tarity, in which the ‘phase error’ rate is bounded by observed quantities in the actual protocol [24, 25]. To consider the amount of privacy amplification for the sifted key obtained whenW A =W B =Z, we need to define a virtual qubit on sys- temAsuch that bits...
-
[3]
(8), it suffices to derive an upper bound onfPA in order to obtain the secure key rate from the observed quanti- tiesQ Z,E X,Q ⊥A,ZB andQ ZA,⊥B
Main theorem From Eq. (8), it suffices to derive an upper bound onfPA in order to obtain the secure key rate from the observed quanti- tiesQ Z,E X,Q ⊥A,ZB andQ ZA,⊥B. The result is summarized in Theorem 1. The proof of the theorem is based on three lem- mas. Lemma 1 provides an upper bound on the phase error rate appearing in the last term of Eq. (12). Le...
-
[4]
[33], which as- sumes a parametric down-conversion (PDC) source pumped by a pulsed laser
Physical models and expressions for observed quantities One of the most widely adopted models for entanglement- based QKD is the model described in Ref. [33], which as- sumes a parametric down-conversion (PDC) source pumped by a pulsed laser. Although we also adopt this model, we mod- ify the expressions for the observed parameters to account for the pass...
-
[5]
Simulation results We present the results of numerical calculation of the key rateRper round given by Eq. (55). In the simulation shown in Fig. 5, we assume detectors’ quantum efficiencyηZ det =η X det = 0.7 and dark count probabilityd=10 −7, which are achievable with commercial SSPDs [35]. The channel transmittance of the optical fiberη ch connecting the...
-
[6]
With a notation ˆN(1) ξ B ˆξ† |vac⟩ ⟨vac|ZX ˆξ,(B1) forξ∈ {z H,z V ,x D,x ¯D}, the POVM elements in systemZX under the condition that the outcome of QND measurement is nA =1 are described as follows: ˆF(1) Z0 = ˆN(1) zH (1−d) 3, ˆF(1) Z1 = ˆN(1) zV (1−d) 3, ˆF(1) Z,double =d( ˆN(1) zH + ˆN(1) zV )(1−d) 2, ˆF(1) X0 = ˆN(1) xD (1−d) 3, ˆF(1) X1 = ˆN(1) x ¯D...
-
[7]
Azuma, S
K. Azuma, S. E. Economou, D. Elkouss, P. Hilaire, L. Jiang, H.-K. Lo, and I. Tzitrin, Rev. Mod. Phys.95, 045006 (2023)
2023
-
[8]
C. H. Bennett, G. Brassard, and N. D. Mermin, Phys. Rev. Lett. 68, 557 (1992)
1992
-
[9]
Lo and H
H.-K. Lo and H. F. Chau, Science283, 2050 (1999)
2050
-
[10]
P. W. Shor and J. Preskill, Phys. Rev. Lett.85, 441 (2000)
2000
-
[11]
Tsurumaru and K
T. Tsurumaru and K. Tamaki, Phys. Rev. A78, 032302 (2008)
2008
-
[12]
M. Koashi, Y . Adachi, T. Yamamoto, and N. Imoto, arXiv:0804.0891 (2008)
Pith/arXiv arXiv 2008
-
[13]
C. C.-W. Lim, F. Xu, J.-W. Pan, and A. Ekert, Phys. Rev. Lett. 126, 100501 (2021)
2021
-
[14]
Mannalath, V
V . Mannalath, V . Zapatero, and M. Curty, Phys. Rev. Lett.135, 020803 (2025)
2025
-
[15]
Jennewein, C
T. Jennewein, C. Simon, G. Weihs, H. Weinfurter, and A. Zeilinger, Phys. Rev. Lett.84, 4729 (2000)
2000
-
[16]
Tittel, J
W. Tittel, J. Brendel, H. Zbinden, and N. Gisin, Phys. Rev. Lett. 84, 4737 (2000)
2000
-
[17]
Ursin, F
R. Ursin, F. Tiefenbacher, T. Schmitt-Manderbach, H. Weier, T. Scheidl, M. Lindenthal, B. Blauensteiner, T. Jennewein, J. Perdigues, P. Trojek, B. ¨Omer, M. F ¨urst, M. Meyen- burg, J. Rarity, Z. Sodnik, C. Barbieri, H. Weinfurter, and A. Zeilinger, Nature Physics3, 481 (2007)
2007
-
[18]
Honjo, S
T. Honjo, S. W. Nam, H. Takesue, Q. Zhang, H. Kamada, Y . Nishida, O. Tadanaga, M. Asobe, B. Baek, R. Hadfield, S. Miki, M. Fujiwara, M. Sasaki, Z. Wang, K. Inoue, and Y . Ya- mamoto, Opt. Express16, 19118 (2008)
2008
-
[19]
Erven, X
C. Erven, X. Ma, R. Laflamme, and G. Weihs, New Journal of Physics11, 045025 (2009). 22
2009
-
[20]
Fitzke, L
E. Fitzke, L. Bialowons, T. Dolejsky, M. Tippmann, O. Niki- forov, T. Walther, F. Wissel, and M. Gunkel, PRX Quantum3, 020341 (2022)
2022
-
[21]
Zhuang, B
S.-C. Zhuang, B. Li, M.-Y . Zheng, Y .-X. Zeng, H.-N. Wu, G.-B. Li, Q. Yao, X.-P. Xie, Y .-H. Li, H. Qin, L.-X. You, F. Xu, J. Yin, Y . Cao, Q. Zhang, C.-Z. Peng, and J.-W. Pan, Phys. Rev. Lett. 134, 230801 (2025)
2025
-
[22]
Tagliavacche, M
N. Tagliavacche, M. Borghi, G. Guarda, D. Ribezzo, M. Lisci- dini, D. Bacco, M. Galli, and D. Bajoni, npj Quantum Infor- mation11, 60 (2025)
2025
-
[23]
Grasselli, H
F. Grasselli, H. Kampermann, and D. Bruß, New Journal of Physics20, 113014 (2018)
2018
-
[24]
Proietti, J
M. Proietti, J. Ho, F. Grasselli, P. Barrow, M. Malik, and A. Fedrizzi, Science Advances7, eabe0395 (2021)
2021
-
[25]
Pickston, J
A. Pickston, J. Ho, A. Ulibarrena, F. Grasselli, M. Proietti, C. L. Morrison, P. Barrow, F. Graffitti, and A. Fedrizzi, npj Quantum Information9, 82 (2023)
2023
-
[26]
Zou, B.-C
M. Zou, B.-C. Li, S. Zhao, Y . Mao, D. Qin, X. Jiang, T.-Y . Chen, and J.-W. Pan, Phys. Rev. Lett.136, 020801 (2026)
2026
-
[27]
H.-K. Lo, H. Chau, and M. Ardehali, Journal of Cryptology 18(2), 133 (2004)
2004
-
[28]
N. J. Beaudry, T. Moroder, and N. L¨utkenhaus, Phys. Rev. Lett. 101, 093601 (2008)
2008
-
[29]
Kamin and N
L. Kamin and N. L¨utkenhaus, Phys. Rev. Res.6, 043223 (2024)
2024
-
[30]
Koashi, arXiv:quant-ph/0609180 (2006)
M. Koashi, arXiv:quant-ph/0609180 (2006)
Pith/arXiv arXiv 2006
-
[31]
Koashi, New J
M. Koashi, New J. Phys.11, 045018 (2009)
2009
-
[32]
Tomamichel and R
M. Tomamichel and R. Renner, Phys. Rev. Lett.106, 110506 (2011)
2011
-
[33]
D. Tupkary, E. Y . Z. Tan, S. Nahar, L. Kamin, and N. L¨utkenhaus, arXiv:2502.10340 (2025)
Pith/arXiv arXiv 2025
-
[34]
C. H. Bennett and G. Brassard, inProceedings of IEEE Interna- tional Conference on Computers, Systems and Signal Process- ing, V ol. 175, Bangalore, India (IEEE Press, New York, 1984)
1984
-
[35]
Kawakami, A
S. Kawakami, A. Taniguchi, Y . Tonomura, K. Takasugi, and K. Azuma, Phys. Rev. Appl.24, 054070 (2025)
2025
-
[36]
Mizutani, S
A. Mizutani, S. Kawakami, and G. Kato, Quantum Science and Technology11, 015010 (2025)
2025
-
[37]
Z. Wang, D. Tupkary, and S. Nahar, arXiv:2508.21486 (2025)
arXiv 2025
-
[38]
Azuma, Tohoku Math
K. Azuma, Tohoku Math. J.19, 357 (1967)
1967
-
[39]
Ma, C.-H
X. Ma, C.-H. F. Fung, and H.-K. Lo, Phys. Rev. A76, 012307 (2007)
2007
-
[40]
Pan, Z.-B
J.-W. Pan, Z.-B. Chen, C.-Y . Lu, H. Weinfurter, A. Zeilinger, and M. ˙Zukowski, Rev. Mod. Phys.84, 777 (2012)
2012
-
[41]
Sanari, A
Y . Sanari, A. Taniguchi, M. Miura, H. Takahashi, K. Takasugi, H.-P. Lo, T. Ikuta, T. Honjo, and H. Takesue, in2024 Con- ference on Lasers and Electro-Optics Pacific Rim (CLEO-PR) (Optica Publishing Group, 2024)
2024
-
[42]
Y . Luo, X. Cheng, H.-K. Mao, and Q. Li, Mathematics12 (2024), 10.3390/math12142243
- [43]
- [44]
discussion (0)
Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.