Pith. sign in

REVIEW 2 major objections 4 minor 31 references

Bounding light source side channels in QKD via Hong-Ou-Mandel interference

T0 review · 2 major / 4 minor · reviewed 2026-08-14 · deepseek-v4-flash

Pith's one-line read The paper shows that a single Hong-Ou-Mandel visibility measurement can upper-bound passive side-channel leakage from a QKD source and be folded into a BB84 decoy-state key-rate proof.

desk verdict Useful quantitative bridge from HOM visibility to QKD source side-channel bounds, but the 'total passive leakage' claim overstates what a single-bandwidth interference measurement can certify. read the letter →

arxiv 1908.04703 v1 pith:GDOF3FWB submitted 2019-08-13 quant-ph

classification quant-ph
keywords quantumkeydistributionsidechannelsHong-Ou-Mandelinterferenceweakcoherentpulsesdecoy-stateBB84fidelitybasisimbalancesourcecertification
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper claims that Hong-Ou-Mandel interference between two phase-randomized weak coherent pulses reveals their overall distinguishability, so one interference measurement can bound the passive side-channel information leaked by Alice's source without characterizing every degree of freedom separately. For small intensities, the paper derives a direct link between HOM visibility and quantum fidelity, $\sqrt{F}=\exp(\mu(\sqrt{2V}-1))$, and uses this link to bound the basis imbalance of BB84. It then incorporates that bound into a decoy-state key-rate formula and shows that realistic visibilities, even around 0.47, still allow positive secure key generation. If true, this turns source certification for QKD into a single interferometric test rather than a battery of independent parameter measurements.

What carries the argument

The central object is fourth-order Hong-Ou-Mandel interference, in which two pulses meeting on a 50:50 beamsplitter suppress coincidence clicks when they are indistinguishable; for phase-randomized weak coherent pulses the maximum visibility is 0.5. The paper's key identity is the exponential relation between this visibility and the fidelity of two pulses, $\sqrt{F}=\exp(\mu(\sqrt{2V}-1))$, and its key tool is the Bures-angle triangle inequality, which turns pairwise fidelities into an upper bound on the BB84 basis imbalance $\Delta$. That imbalance is then fed into the decoy-state error-rate formula, so a single measured visibility becomes a security parameter.

What would settle it

Build a source whose HOM visibility is near 0.5 but whose emitted state in some out-of-band degree of freedom, such as mid-infrared light or acoustic emission, is perfectly correlated with the encoded bit, and show that the actual secure key rate falls below the paper's lower bound computed from that visibility.

Watch

Extended reading notes

Core claim

The central claim is that the visibility of HOM interference between two of Alice's pulses measures the total mode mismatch in all non-operational degrees of freedom, and that this measured visibility can be used to upper-bound the information Eve gains from passive side channels. For phase-randomized weak coherent pulses with equal mean photon number $\mu$, the paper derives $\sqrt{F(\hat{\rho}_1,\hat{\rho}_2)}=\exp(\mu(\sqrt{2V}-1))$, where $V$ is the HOM visibility. Using the Bures angle as a metric, it bounds the BB84 basis imbalance $\Delta$ in terms of pairwise fidelities, then converts that bound into a corrected single-photon error rate and a lower bound on the secret key rate. With the best published PRWCP visibilities, all tested values still yield positive key rates, with visibilities near 0.499 nearly saturating the theoretical limit.

Load-bearing premise

The entire certificate rests on the assumption that every degree of freedom Eve can exploit changes the photonic mode overlap seen by the HOM detector, while the paper itself notes that out-of-wavelength and non-electromagnetic side channels are invisible to this method.

Editorial extensions

If this is right

  • A direct HOM measurement of a QKD source yields an upper bound on basis distinguishability, so the same optical setup can serve as a certification tool for existing systems without measuring every pulse parameter independently.
  • The derived relation between visibility and fidelity means that improving mode matching, for example by optical seeding, translates quantitatively into a higher secure key rate for decoy-state BB84.
  • The paper's simulations show that key generation remains possible for HOM visibilities as low as 0.47, placing current experimental values in a regime where the certification method is practically useful.
  • The method is not limited to BB84: the visibility-to-fidelity relation and the bounding technique can, according to the paper, be adapted to other QKD protocols.
  • Because the bound tightens as visibility approaches 0.5, the method sets a concrete design target for modulator-free multi-laser sources used in polarization-encoded QKD.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • If the visibility-to-fidelity relation is independent of the encoding basis, the same HOM setup could certify side-channel leakage in other prepare-and-measure protocols, including measurement-device-independent QKD, without new security-model work.
  • The paper derives the fidelity formula for equal-intensity pulses; a natural extension would be to test whether signal-versus-decoy distinguishability, which the paper leaves for future work, can be bounded by the same kind of interference measurement.
  • Because the certificate only sees degrees of freedom that affect optical detection, a complete practical certification would need to pair this test with a separate threat analysis for out-of-band and non-photonic channels.
  • The discussion of post-selection suggests a testable distinction: if emission-time jitter is genuinely quantum, removing poorly overlapping events tightens the bound, but if the jitter is classically driven, that post-selection would hide information Eve could use.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

2 major / 4 minor

Summary. The manuscript proposes a method to estimate passive side-channel information leakage in QKD sources by measuring Hong-Ou-Mandel (HOM) visibility between phase-randomized weak coherent pulses (PRWCPs). In Sec. 1 it connects HOM visibility of PRWCPs to the overlap of the single-photon components (Eq. (5)), with an applicability limit around μ ≲ 0.025 or, with correction, up to about 1 photon per pulse. In Sec. 2 it converts this visibility into a fidelity between the X and Z bases using a Bures-angle triangle inequality (Eqs. (10), (31)), yielding an upper bound on the basis imbalance Δ. In Sec. 3 the imbalance is inserted into the decoy-state BB84 key-rate formula and key rates are simulated for several visibility values. Sec. 4 compares with published HOM visibilities from MDI-QKD experiments and discusses limitations, including detector wavelength sensitivity and non-electromagnetic side channels.

Significance. The core idea is appealing: instead of characterizing every non-operational degree of freedom individually, one HOM visibility measurement could certify the overall mode overlap of the emitted signals. The derivation in Appendix A connecting fidelity to visibility (Eq. (22)) is analytically clean, and the Bures-angle construction in Appendix B is a sound way to turn pairwise fidelities into a bound on basis imbalance. The paper also produces concrete, falsifiable predictions: for realistic parameters, key rate degrades sharply below V = 0.5, and positive key rate survives down to about V = 0.47. This is useful for practical source certification. However, the significance is conditional: the method only witnesses side channels that actually reach and are detected in the HOM setup, and it does not yet cover distinguishability between signal and decoy intensity classes. These limitations directly affect the scope of the security claim.

major comments (2)
  1. [Abstract; Sec. 4, 'Applications and discussion'] The abstract and introduction claim that the method estimates the 'total passive side-channel information leakage' from Alice's source and upper-bounds the influence of all side-channel effects. This is not supported by the paper's own limitation statement in Sec. 4: the method is limited by the single-photon detector wavelength sensitivity, and side channels outside that band or non-electromagnetic channels (such as the acoustic Pockels-cell leakage of Refs. [30,31]) are not detected. Such a side channel would not reduce the measured HOM visibility, so the key-rate bound in Sec. 3 would not upper-bound Eve's information. The claims should be restated to apply to optical side channels within the characterized spectral band, or supplemented with additional characterization that covers the remaining degrees of freedom.
  2. [Sec. 3, 'Key generation rate'; Appendix A, Eq. (22)] The security model is for the decoy-state BB84 protocol, but the derivation of the visibility-fidelity relation assumes two PRWCPs with equal mean photon number μ. The paper does not measure or bound distinguishability between signal and decoy intensity classes, or between different intensity settings; the sentence 'we assume that decoy-state method doesn't have any additional vulnerabilities' explicitly sets this aside, and the conclusion lists 'estimation of distinguishability between signal and decoy states' as future work. If Eve can exploit intensity-dependent mode mismatch, the decoy-state parameter estimation in Eq. (13) is compromised. The paper should either include a treatment of intensity correlations or restrict its security claim to basis/bit distinguishability at a fixed intensity.
minor comments (4)
  1. [Eqs. (2)-(4)] The notation 'e−µ2' is ambiguous; in Eq. (2) it should be e^{-μ}, and in Eqs. (3)-(4) it should be e^{-2μ}. In addition, the μ-term in Eq. (3) connecting |01⟩ and |10⟩ is not present in a phase-randomized mixture and should be removed or justified, even though it does not affect the two-photon coincidence analysis.
  2. [Sec. 4, Table 1] The literature visibilities in Table 1 are HOM visibilities measured in MDI-QKD experiments, where the interference is between Alice's and Bob's pulses at a central node. If these values are used to argue that the method would yield positive key rates for current sources, it should be stated explicitly whether the cited visibilities characterize Alice's source alone or the combined source/measurement setup; in the latter case, they are not directly a bound on Alice-side mode mismatch.
  3. [Sec. 4, post-selection paragraph] The discussion of post-selection in [29] is a useful caveat, but it could be made more precise: for a security proof, post-selection must be shown to be compatible with the adversarial model, i.e., Eve cannot influence which events are discarded.
  4. [Fig. 4] The key-rate axis in Fig. 4 appears garbled in the manuscript (the log-scale tick labels read '10 10 -5 -4 -3 10-2'); please check the plot formatting.

Circularity Check

0 steps flagged · score 0.0 of 10

No circularity: HOM visibility is an experimentally measured input, and the key-rate bound is a forward calculation from it; the stated detector-bandwidth limitation is a scope caveat, not a circular step.

full rationale

The derivation chain is a forward calculation: measured HOM visibility V enters Eq. (5) to fix the single-photon mode overlap, Appendix A converts that overlap into a fidelity estimate via Eq. (22), Appendix B bounds the bases imbalance via triangle inequalities, and Sec. 3 inserts the imbalance into a standard decoy-state key-rate formula. No parameter is fitted to a target key rate, no prediction is defined in terms of the quantity it is supposed to predict, and no load-bearing claim is supported by a self-citation by the authors. The relation sqrt(F) = exp(mu(sqrt(2V)-1)) is derived from an explicit mode-overlap parameterization, not assumed as the answer. The paper's own Sec. 4 limitation—that side channels outside the detector's wavelength sensitivity or non-electromagnetic channels are not detected—is an honest scope restriction on the adversarial model, but it does not make the derivation circular: the bound is conditional on the measured visibility. The abstract's 'total leakage' wording is stronger than the Sec. 4 caveat, which is a correctness/scope concern rather than a circularity concern. Accordingly, the circularity score is 0.

Assumptions & free parameters 0 free parameters · 5 assumptions · 0 invented entities

The paper introduces no new physical entities. Its free parameters are none; the key inputs (visibility, mu, channel parameters) are measured or chosen from literature. The main assumptions are the small-mu approximation and the completeness of the characterized modes.

assumptions (5)
  • domain assumption Two PRWCPs with equal intensity mu and mode overlap gamma have HOM visibility V = gamma/2 (for small mu).
    Derived in Sec. 1 under the approximation that terms higher than second order in mu are negligible. Numerical simulation shows it holds for mu < 0.025 and approximately up to 0.25, but not for mu > 1.
  • domain assumption The HOM visibility measurement is performed on all degrees of freedom that can leak information to Eve.
    The method only detects side channels within the SPD wavelength sensitivity. Sec. 4 states that out-of-band or non-electromagnetic side channels are not detected.
  • standard math Bures angle is a metric on density matrices, enabling the triangle inequality in Eq. (10).
    Standard result used in Appendix B to bound base fidelity.
  • domain assumption The security model of Lucamarini et al. [3] for Trojan-horse attacks applies to passive side channels.
    The paper uses Eq. (14) and (15) from [3] to convert bases imbalance into an error-rate correction.
  • domain assumption The decoy-state method has no additional vulnerabilities beyond those modeled.
    Stated in Sec. 3: 'Here we assume that decoy-state method doesn't have any additional vulnerabilities.'

how reviews work

0 comments
Cite this review

Pith. "Pith review of Bounding light source side channels in QKD via Hong-Ou-Mandel interference." pith.science (2026). https://pith.science/paper/GDOF3FWB

@misc{pith2026190804703,
  author       = {Pith},
  title        = {Pith review of: Bounding light source side channels in QKD via Hong-Ou-Mandel interference},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/GDOF3FWB}},
  note         = {Machine review of arXiv:1908.04703}
}
read the original abstract

Side-channel attacks on practical quantum key distribution systems compromise its security. Although some of these attacks can be taken into account, the general recipe of how to eliminate all side-channel flaws is still missing. In this work, we propose a method for estimation of the total passive side-channel information leakage from the Alice's light source. The method relies on Hong-Ou-Mandel interference between different signals emitted by Alice, which reveals their overall mode mismatch without the necessity to measure all individual degrees of freedom independently. We include experimental values of interference visibility in the security proof for the decoy-state BB84 protocol, and lower-bound the secure key rate for realistic light sources. The obtained results provide a tool that can be used for certification of the current QKD systems and pave the way towards the loophole-free design of the future ones.

Figures

Figures reproduced from arXiv: 1908.04703 by the authors.

Figure 1
Figure 1. Typical setup for HOM experiment (on the left). Two single-photon pulses enter a beamsplit [PITH_FULL_IMAGE:figures/full_fig_p002_1.png] view at source ↗
Figure 2
Figure 2. Simulation results for HOM visibility of phase randomized weak coherent pulses (PRWCPs), [PITH_FULL_IMAGE:figures/full_fig_p004_2.png] view at source ↗
Figure 3
Figure 3. Concept of a possible optical scheme, that can be used for HOM-based basis test of polarization-encoding system. One of the interferometer arms is delayed, so that two consequent pulses are matched on a beam-splitter. Half-wave plate is used for polarization matching of two states. Finally, we establish a connection between visibility and fidelity. In Appendix A we derive an equation to calculate fidelity for two ar… view at source ↗
Figures from the paper (2 more)
Figure 4
Figure 4. Figure 4: Key generation rate depending on the communication distance for different values of HOM [PITH_FULL_IMAGE:figures/full_fig_p007_4.png]
Figure 5
Figure 5. Figure 5: Scheme of bases fidelity estimation. A pair of auxiliary matrices for each basis allow to bound [PITH_FULL_IMAGE:figures/full_fig_p010_5.png]

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

31 extracted references · 31 canonical work pages

  1. [15]

    Interference of short optical pulses from independent gain-switched laser diodes for quantum secure communications

    ZL Yuan, M Lucamarini, JF Dynes, B Fr¨ ohlich, MB Ward, and AJ Shields. Interference of short optical pulses from independent gain-switched laser diodes for quantum secure communications. Physical Review Applied , 2(6):064006, 2014

  2. [1]

    Information leakage via side channels in freespace bb84 quantum cryptography

    Sebastian Nauerth, Martin F¨ urst, Tobias Schmitt-Manderbach, Henning Weier, and Harald Wein- furter. Information leakage via side channels in freespace bb84 quantum cryptography. New Journal of Physics , 11(6):065001, 2009

  3. [2]

    Simple security proof of quantum key distribution based on complementarity.New Journal of Physics , 11(4):045018, 2009

    M Koashi. Simple security proof of quantum key distribution based on complementarity.New Journal of Physics , 11(4):045018, 2009

  4. [3]

    Practical security bounds against the trojan-horse attack in quantum key distribution

    Marco Lucamarini, Iris Choi, Martin B Ward, James F Dynes, ZL Yuan, and Andrew J Shields. Practical security bounds against the trojan-horse attack in quantum key distribution. Physical Review X, 5(3):031030, 2015

  5. [4]

    Decoy-state quantum key distribution with a leaky source

    Kiyoshi Tamaki, Marcos Curty, and Marco Lucamarini. Decoy-state quantum key distribution with a leaky source. New Journal of Physics , 18(6):065008, 2016

  6. [5]

    Practical free-space quantum key distribution over 10 km in daylight and at night

    Richard J Hughes, Jane E Nordholt, Derek Derkacs, and Charles G Peterson. Practical free-space quantum key distribution over 10 km in daylight and at night. New journal of physics , 4(1):43, 2002

  7. [6]

    Ex- perimental demonstration of free-space decoy-state quantum key distribution over 144 km

    Tobias Schmitt-Manderbach, Henning Weier, Martin F¨ urst, Rupert Ursin, Felix Tiefenbacher, Thomas Scheidl, Josep Perdigues, Zoran Sodnik, Christian Kurtsiefer, John G Rarity, et al. Ex- perimental demonstration of free-space decoy-state quantum key distribution over 144 km. Physical Review Letters, 98(1):010504, 2007

  8. [7]

    High- speed free-space quantum key distribution system for urban daylight applications

    MJ Garc´ ıa-Mart´ ınez, Natalia Denisenko, D Soto, D Arroyo, AB Orue, and V Fernandez. High- speed free-space quantum key distribution system for urban daylight applications. Applied optics , 52(14):3311–3317, 2013

Show all 31 references
  1. [8]

    Free-space quantum key distribution by rotation-invariant twisted photons

    Giuseppe Vallone, Vincenzo D’Ambrosio, Anna Sponselli, Sergei Slussarenko, Lorenzo Marrucci, Fabio Sciarrino, and Paolo Villoresi. Free-space quantum key distribution by rotation-invariant twisted photons. Physical review letters , 113(6):060503, 2014

  2. [9]

    Experimental long-distance decoy-state quantum key distribution based on polarization encoding

    Cheng-Zhi Peng, Jun Zhang, Dong Yang, Wei-Bo Gao, Huai-Xin Ma, Hao Yin, He-Ping Zeng, Tao Yang, Xiang-Bin Wang, and Jian-Wei Pan. Experimental long-distance decoy-state quantum key distribution based on polarization encoding. Physical review letters , 98(1):010505, 2007

  3. [10]

    Experimental quantum digital signature over 102 km

    Hua-Lei Yin, Yao Fu, Hui Liu, Qi-Jie Tang, Jian Wang, Li-Xing You, Wei-Jun Zhang, Si-Jing Chen, Zhen Wang, Qiang Zhang, et al. Experimental quantum digital signature over 102 km. Physical Review A, 95(3):032334, 2017

  4. [11]

    Nature of wavelength chirping in directly modulated semicon- ductor lasers

    Thomas L Koch and John E Bowers. Nature of wavelength chirping in directly modulated semicon- ductor lasers. Electronics Letters, 20(25):1038–1040, 1984

  5. [12]

    Quantum mechanics and path integrals [by] RP Feynman [and] AR Hibbs

    Richard Phillips Feynman and Albert R Hibbs. Quantum mechanics and path integrals [by] RP Feynman [and] AR Hibbs . McGraw-Hill, 1965

  6. [13]

    Measurement of subpicosecond time intervals between two photons by interference

    Chong-Ki Hong, Zhe-Yu Ou, and Leonard Mandel. Measurement of subpicosecond time intervals between two photons by interference. Physical review letters , 59(18):2044, 1987. 11

  7. [14]

    On the purity and indistinguishability of down- converted photons

    CI Osorio, N Sangouard, and Robert Thomas Thew. On the purity and indistinguishability of down- converted photons. Journal of Physics B: Atomic, Molecular and Optical Physics , 46(5):055501, 2013

  8. [16]

    Characteri- zation of phase-averaged coherent states

    Alessia Allevi, Maria Bondani, Paulina Marian, Tudor A Marian, and Stefano Olivares. Characteri- zation of phase-averaged coherent states. JOSA B , 30(10):2621–2627, 2013

  9. [17]

    Secure quantum key distribution with an uncharacterized source

    Masato Koashi and John Preskill. Secure quantum key distribution with an uncharacterized source. Physical review letters , 90(5):057902, 2003

  10. [18]

    transition probability

    Armin Uhlmann. The “transition probability” in the state space of a*-algebra. Reports on Mathe- matical Physics, 9(2):273–279, 1976

  11. [19]

    Fidelity for mixed quantum states

    Richard Jozsa. Fidelity for mixed quantum states. Journal of modern optics , 41(12):2315–2323, 1994

  12. [20]

    Fidelity induced distance measures for quantum states

    Zhihao Ma, Fu-Lin Zhang, and Jing-Ling Chen. Fidelity induced distance measures for quantum states. Physics Letters A , 373(38):3407–3409, 2009

  13. [21]

    Practical decoy state for quantum key distri- bution

    Xiongfeng Ma, Bing Qi, Yi Zhao, and Hoi-Kwong Lo. Practical decoy state for quantum key distri- bution. Physical Review A , 72(1):012326, 2005

  14. [22]

    Security of quantum key distribution with arbitrary individual imperfections

    Øystein Marøy, Lars Lydersen, and Johannes Skaar. Security of quantum key distribution with arbitrary individual imperfections. Physical Review A , 82(3):032337, 2010

  15. [23]

    Secure detection in quantum key distribution by real-time calibration of receiver

    Øystein Marøy, Vadim Makarov, and Johannes Skaar. Secure detection in quantum key distribution by real-time calibration of receiver. Quantum Science and Technology , 2(4):044013, 2017

  16. [24]

    Quantum key distribution with distin- guishable decoy states

    Anqi Huang, Shi-Hai Sun, Zhihong Liu, and Vadim Makarov. Quantum key distribution with distin- guishable decoy states. Physical Review A , 98(1):012330, 2018

  17. [25]

    Proof-of-principle demonstration of measurement-device-independent quantum key distribution using polarization qubits

    T Ferreira Da Silva, D Vitoreti, GB Xavier, GC Do Amaral, GP Temporao, and JP Von Der Weid. Proof-of-principle demonstration of measurement-device-independent quantum key distribution using polarization qubits. Physical Review A , 88(5):052303, 2013

  18. [26]

    Real- world two-photon interference and proof-of-principle quantum key distribution immune to detector attacks

    Allison Rubenok, Joshua A Slater, Philip Chan, Itzel Lucio-Martinez, and Wolfgang Tittel. Real- world two-photon interference and proof-of-principle quantum key distribution immune to detector attacks. Physical review letters , 111(13):130501, 2013

  19. [27]

    Experimental demon- stration of polarization encoding measurement-device-independent quantum key distribution

    Zhiyuan Tang, Zhongfa Liao, Feihu Xu, Bing Qi, Li Qian, and Hoi-Kwong Lo. Experimental demon- stration of polarization encoding measurement-device-independent quantum key distribution. Phys- ical review letters , 112(19):190503, 2014

  20. [28]

    Quantum key distribution without detector vulnerabilities using optically seeded lasers

    LC Comandar, M Lucamarini, B Fr¨ ohlich, JF Dynes, AW Sharpe, SW-B Tam, ZL Yuan, RV Penty, and AJ Shields. Quantum key distribution without detector vulnerabilities using optically seeded lasers. Nature Photonics, 10(5):312, 2016

  21. [29]

    Near perfect mode overlap between independently seeded, gain-switched lasers

    LC Comandar, M Lucamarini, B Fr¨ ohlich, JF Dynes, ZL Yuan, and AJ Shields. Near perfect mode overlap between independently seeded, gain-switched lasers. Optics express , 24(16):17849–17859, 2016

  22. [30]

    Experimental quantum cryptography

    Charles H Bennett, Fran¸ cois Bessette, Gilles Brassard, Louis Salvail, and John Smolin. Experimental quantum cryptography. Journal of cryptology , 5(1):3–28, 1992. 12

  23. [31]

    Brief history of quantum cryptography: A personal perspective

    Gilles Brassard. Brief history of quantum cryptography: A personal perspective. In IEEE Information Theory Workshop on Theory and Practice in Information-Theoretic Security, 2005. , pages 19–23. IEEE, 2005. 13

Pith tools

Reviewed August 14, 2026 · model on record in the stance chip above.