Pith. sign in

REVIEW 2 major objections 5 minor 73 references

The finite key effect of side-channel-secure quantum key distribution beyond post-selection technique

T0 review · 2 major / 5 minor · reviewed 2026-08-01 · deepseek-v4-flash

Pith's one-line read A side-channel-secure QKD proof that sets key length after error correction, slashing pulse needs.

desk verdict Solid, inventive proof of finite-key security for SCS QKD against coherent attacks without post-selection, but the headline after-EC 'actual leakage' key-length claim hinges on an unproven conditional-independence condition (Eq. 19 / Appendix A6). read the letter →

arxiv 2607.17465 v1 pith:IQ46N56M submitted 2026-07-20 quant-ph

classification quant-ph MSC 81P9494A60
keywords side-channel-secureQKDfinite-keysecuritycoherentattacksvariable-lengthkeyentropicuncertaintyrelationquantumleftoverhashlemmaphase-errorestimationpost-selectiontechnique
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper claims that the side-channel-secure (SCS) quantum key distribution protocol admits a composable finite-key security proof against coherent attacks without the post-selection technique, and that this cuts the required number of pulses by more than two orders of magnitude. The proof splits all time windows into two random halves and uses a virtual measurement on one half to bound a state, |φ2>, that never appears in the real protocol; this turns composable security into a statistical fluctuation bound on the phase-error count. Because untagged bits in the SCS protocol are free of bit-flip errors, Alice and Bob can run error correction first and then compute the final key length from the actual leakage λ_h rather than from a worst-case predetermination. The resulting key length is ℓ_i,h = max(0, n_Z,i[1−H(e_ph,i)] − λ_h − log2(2/ε_EC) − log2(1/(4ε_PA²))), with composable security parameter ε_com = 2ε_EC + ε_PA + 2√(5ε_p). A sympathetic reader would care because this makes the practical SCS protocol usable with 10^12 pulses over distances beyond 200 km, where earlier post-selection-based analyses needed 10^14 or more.

What carries the argument

Key machinery: splitting the time windows into two random halves, plus a virtual |φ2> observable on the estimation half. The estimation branch's 'balance' component has an i.i.d. minus-minus click probability p_D = p_x² c_2²/8, so the unobservable |φ2> counting rate is replaced by a Chernoff-level upper bound n^est,all_D = CU(p_x² c_2² N/8). This feeds the phase-error estimator ⟨N^est_ph⟩ = (p_o p_x/4)(√2/p_o²⟨n^est_O⟩ + √2/p_x²⟨n^est_B⟩ + √8/p_x²⟨n^est_D⟩)². After error correction, the key step is conditional independence Pr(λ_h|Z_A,Z_B,Ω_i,ξ_j,Ω_EV) = Pr(λ_h|Ω_i,ξ_j,Ω_EV), making the smooth min-entropy independent of λ_h.

What would settle it

Construct an explicit error-correction algorithm with variable leakage length for SCS raw keys and verify the conditional independence Pr(λ_h | Z_A,Z_B,Ω_i,ξ_j,Ω_EV) = Pr(λ_h | Ω_i,ξ_j,Ω_EV) for all raw-key strings consistent with the observed counts; the first pair of strings with differing leakage distributions falsifies Eq. (19) and invalidates the after-error-correction key-length formula.

Watch

Extended reading notes

Core claim

Central claim: composable security of the SCS protocol against coherent attacks reduces to the statistical fluctuation bound Δ = Σ_j Pr(ξ_j) Σ_i Pr(N_ph ≥ N^est_ph,i, Ω_i|ξ_j) ≤ 5ε_p. The proof splits time windows into two random halves and uses a virtual minus-minus measurement on the estimation half to bound the rate of a state |φ2> absent from the real protocol. That bound enters the phase-error estimator through |0√μ_B>+|√μ_A0> = |00>+|√μ_A√μ_B>+c_2|φ2>. A Cauchy–Schwarz/Jensen chain bounds expected phase errors by expected O, B, D counts; Kato's inequality converts observed counts to expectation bounds and controls the tail. The resulting key length gives per-half security ε_com = 2ε_EC

Load-bearing premise

The load-bearing premise is that an error-correction algorithm can be chosen so that, conditioned on the observed error count, the actual leakage λ_h is statistically independent of the raw key values; the paper asserts this is achievable but does not exhibit a concrete such algorithm.

Editorial extensions

If this is right

  • If the proof is right, SCS QKD no longer needs the post-selection technique for coherent-attack security, so its finite-key rates are governed by the actual observed statistics rather than by the total pulse number raised to a large penalty exponent.
  • At N = 10^12 pulses, the protocol reaches positive key rates over distances beyond 200 km in the paper's simulation; this is a quantitative claim a field experiment could test directly.
  • Protocols whose untagged bits are free of bit-flip errors can determine the final key length after error correction from the realized leakage λ_h, so runs with cheaper reconciliation produce longer keys within the same security guarantee.
  • For variable-length QKD, the paper fixes which concentration inequalities are legitimate: Kato's inequality and its inverse may be used, but the (a,b) parameters must be fixed in advance for each observable class and cannot be optimized from the observed data.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • Extension: the split-half virtual-observable trick may transplant to other MDI-type protocols with error-free untagged bits, potentially removing the post-selection penalty from SNS and phase-matching analyses without changing the experimental setup.
  • Extension: the practical gain hangs on whether a concrete error-correction code with variable leakage satisfying the conditional-independence condition actually exists; until one is exhibited, a conservative implementation would fall back to a fixed maximum leakage and lose part of the reported improvement while keeping the rest of the proof intact.
  • Extension: the paper's four-step recipe — define expectations, relate phase-error expectation to observable expectations, invert a concentration bound, then forward-bound the tail — is a reusable template for parameter estimation in other variable-length QKD protocols.
  • Extension: the i.i.d. probability p_D for the virtual |φ2> measurement is a structural fact that could be exploited to derive closed-form Chernoff bounds for other virtual states in future source-characterization proofs.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

2 major / 5 minor

Summary. The manuscript develops a finite-key security proof for the side-channel-secure (SCS) QKD protocol against coherent attacks without invoking the post-selection technique. The proof is built on an entropic-uncertainty-relation/quantum-leftover-hash-lemma framework and introduces a virtual |φ2⟩-state observable to estimate phase errors. A central feature is that the final key length is computed after error correction using the actual error-correction leakage λ_h, justified by a conditional-independence condition (Eq. (19) and Appendix A, condition A6). Numerical simulations indicate an improvement of more than two orders of magnitude in pulse requirements over post-selection-based analyses.

Significance. If the derivation is correct, the paper makes a valuable contribution to finite-key QKD security: it extends direct coherent-attack security proofs to the SCS protocol, removing the costly post-selection overhead, and it provides a rigorous basis for the common engineering practice of using the actual EC leakage in the key-rate formula. The virtual-observable phase-error estimator and the careful treatment of Kato/Chernoff bounds are nontrivial and likely useful beyond this specific protocol. The numerical results are plausible and support the claimed practical advantage.

major comments (2)
  1. [Eq. (19) and Appendix A, condition A6] The after-EC key-length formula rests on the assertion that the EC leakage λ_h is independent of the raw key values given Ω_i. The one-sentence justification is too compressed: the random permutation alone would not suffice; it is the combination of the random bit-flip and the random permutation that makes the processed strings uniformly distributed over all pairs with a fixed Hamming distance, independent of the raw key and Eve. The paper should state and prove this as a lemma, since as written the reader cannot distinguish the argument from the incorrect claim that permutation alone guarantees the required independence.
  2. [Sec. II.C, Eq. (41) and Appendix C] The Chernoff bound on n_D^all assumes that each round independently contributes a D outcome with probability p_D. This is true for the unconditional local state because U_ES acts only on S and E and the marginal on I,L1,L2 remains a product state, but the paper does not supply this argument. In addition, Eq. (37) replaces n_D^all by n_D in the Kato threshold term, which requires the inverse-Kato function f(x)=x+[b+a(2x/M_s−1)]√M_s to be nondecreasing in x; the conditions on a,b should be stated to guarantee this monotonicity, or the argument should be adjusted.
minor comments (5)
  1. [Appendix F] The text refers to Eqs. (D24)–(D26), but Appendix D contains no such numbered equations. Please correct the cross-reference.
  2. [Table I] The caption mentions μo, but the table lists μA and μB. Please align the notation.
  3. [Appendix D, Eq. (D3)] The definition of a and b in Eq. (D3) is hard to parse; in particular, the role of the prior empirical value ~O_Ms should be clarified, and it should be stated explicitly that ~O_Ms must be chosen independently of the observed data.
  4. [Appendix A and B] The notation for the security parameter and the indices (h vs k) is inconsistent between Appendix A, Eq. (A6), and Appendix B, Eq. (B3). Please unify the notation.
  5. [Step 4, Sec. II.A] The protocol should explicitly state that the random bit-flip and permutation are chosen uniformly and independently of the raw key strings and of Eve's information; this is assumed in the proof but not stated in the protocol description.

Circularity Check

0 steps flagged · score 0.0 of 10

No load-bearing circularity; the main caveat (Eq. 19 / condition A6) is an unproven sufficiency condition, not a derivation that reduces to its inputs.

full rationale

The derivation chain is self-contained against the claimed targets. Eq. (3) is obtained by inserting the phase-error upper bound e_ph,i from Eqs. (4), (C14)-(C22) into the EUR/QLHL bound (B3)-(B4); no parameter appearing in the key-rate formula is fitted to the numerical key rates, and the virtual |φ2> bound (C13)-(C18), (41)-(42) is computed from the prepared state, not from the result. The self-citations [52,53,56] supply the SCS protocol definition and the perfect-protocol equivalence; these are inputs, not conclusions, and the new post-selection-free coherent-attack argument is carried out here via Kato/Chernoff bounds. The one substantive weakness is the conditional independence of EC leakage, Eq. (19) and condition A6: the paper asserts that random permutation/bit-flip makes lambda_h depend only on Omega_i, but a general variable-length EC algorithm's length may depend on syndrome values, and no concrete algorithm satisfying A6 is exhibited. This is a completeness/correctness gap, not circularity: A6 is not equivalent to the key-rate formula, and the proof could fall back on a predetermined lambda_max without re-deriving the phase-error analysis. No equation in the paper reduces to its own input by construction.

Assumptions & free parameters 4 free parameters · 6 assumptions · 1 invented entities

The central security proof relies on standard QKD tools (EUR, QLHL, concentration inequalities) and on the SCS protocol's source-overlap assumptions. The novel after-EC feature adds an explicit, unproven condition on the error-correction algorithm. No new physical entities are introduced; the virtual |φ2⟩ observable is a mathematical device.

free parameters (4)
  • po = optimized per distance
    Probability Alice/Bob choose the o source; optimized in the numerical simulation to maximize key rate. Security proof holds for any values satisfying po ≥ px.
  • px = 1-po
    Probability of choosing the x source.
  • μA, μB = optimized per distance
    Intensities of the coherent states in the perfect protocol; optimized in simulation. Bound by the actual source overlap via Eq. (7).
  • Kato parameters a, b = chosen via Eq. (D3) from expected counts
    For each observable class (n_O, n_B, n_D), the pair (a,b) in the Kato estimator IKU must be fixed in advance; the manuscript sets them using an empirical prior (Eq. D3). These influence the tightness of the phase-error bound, not the security claim itself.
assumptions (6)
  • standard math EUR (Tomamichel-Renner) and QLHL hold as stated
    Used in Eq. (B4) to lower-bound the smooth min-entropy of the raw key from the phase-error rate. Cited as [64] and [39].
  • standard math Kato's inequality and Chernoff bounds (forward and inverse) as stated
    Used throughout Sec. II C and Appendices D-E. Cited from [59,60,61].
  • domain assumption No bit-dependent correlation between emitted pulses; Eve cannot enter the laboratory
    Stated in Section II A; the authors note the method of Ref. [55] can remove these.
  • domain assumption Source states have vacuum overlap ≥ 0.5 (Eq. 1) and po ≥ px
    Defines the SCS protocol regime; po ≥ px is needed for the |φr⟩ normalization in Eq. (9).
  • domain assumption Perfect protocol maps to real protocol via attenuation/unitary (source-replacement), and the entanglement-based protocol is equivalent to the real protocol
    Standard SCS/QKD proof technique from [53]; used in Sec. II B.
  • ad hoc to paper Error-correction leakage independence: Pr(λh|ZA,ZB,Ωi,ξj,ΩEV) = Pr(λh|Ωi,ξj,ΩEV) for all ZA,ZB consistent with Ωi
    Eq. (19) and condition (A6). This is the load-bearing, unproven condition enabling the after-error-correction key-length formula. The paper does not exhibit a concrete EC algorithm with genuinely variable λh satisfying it.
invented entities (1)
  • Virtual |φ2⟩ state and the virtual observables n_D, n_all_D
    purpose: To upper-bound the phase-error rate via Cauchy-Schwarz decomposition (Eqs. C7-C10), using the fact that |0√μB⟩+|√μA0⟩ = |00⟩+|√μA√μB⟩+c2|φ2⟩.
    |φ2⟩ appears only in the virtual measurement of balance estimation windows; n_D and n_all_D are not observable in the real protocol (stated in Sec. II C and Appendix C). This is a proof device, not a new physical entity.

how reviews work

0 comments
Cite this review

Pith. "Pith review of The finite key effect of side-channel-secure quantum key distribution beyond post-selection technique." pith.science (2026). https://pith.science/paper/IQ46N56M

@misc{pith2026260717465,
  author       = {Pith},
  title        = {Pith review of: The finite key effect of side-channel-secure quantum key distribution beyond post-selection technique},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/IQ46N56M}},
  note         = {Machine review of arXiv:2607.17465}
}
read the original abstract

By applying the framework of entropic uncertainty relation (EUR) and the Quantum Leftover Hash Lemma (QLHL), we introduce a security-proof method for variable-length side-channel-secure (SCS) quantum key distribution (QKD) against coherent attacks. This method reframes composable security as a statistical fluctuation problem of phase errors, enabling direct proofs against coherent attacks through observables and virtual observables. It yields tight key rates for the SCS protocol and reduces pulse requirements by over two orders of magnitude compared to prior works that employ the post-selection technique. We prove that the secure key length for the SCS protocol can be determined after error correction by exploiting the fact that untagged bits are free from bit-flip errors, using the actual information leakage during error correction and the post-error-correction statistics of each state to calculate the final key rate. We further identify sufficient conditions under which the final key length may be determined after error correction in a broader class of QKD protocols. Under the framework of EUR and QLHL, we clarify the applicability of several commonly used concentration bounds to variable-length QKD and the appropriate manner of their implementation. This work enhances the practical value of the SCS protocol and clarifies the security justification of key-rate formulas used in practical variable-length QKD implementations.

Figures

Figures reproduced from arXiv: 2607.17465 by the authors.

Figure 1
Figure 1. FIG. 1. Comparison of key rates with different [PITH_FULL_IMAGE:figures/full_fig_p011_1.png] view at source ↗
Figure 2
Figure 2. FIG. 2. Comparison of key rates with different [PITH_FULL_IMAGE:figures/full_fig_p011_2.png] view at source ↗

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

73 extracted references · 2 linked inside Pith

  1. [1]

    C. H. Bennett and G. Brassard, Quantum cryptography: Pub lic key distribution and coin tossing, in Proceedings of the IEEE International Conference on Computers, Systems, and S ignal Processing (1984) pp. 175–179

  2. [2]

    (41) Thus Pr(nall D ≥nest,all D ) = Pr ( nall D ≥ CU(p2 x 8 c2 2N ) ) ≤εp, (42) where we have applied nest,all D = CU( p2 x 8 c2 2N ) and Eqs. (E1-E4). Finally, by setting 5εp =ε, we obtains Eq. (25). D. Numerical simulation To evaluate the performance of our improved security-proof met hod for the SCS protocol, we conducted numerical simulations using a ...

  3. [3]

    Gisin, G

    N. Gisin, G. Ribordy, W. Tittel, and H. Zbinden, Quantum c ryptography, Reviews of Modern Physics 74, 145 (2002)

  4. [4]

    F. Xu, X. Ma, Q. Zhang, H.-K. Lo, and J.-W. Pan, Secure quan tum key distribution with realistic devices, Reviews of Modern Physics 92, 025002 (2020)

  5. [5]

    Pirandola, U

    S. Pirandola, U. L. Andersen, L. Banchi, M. Berta, D. Buna ndar, R. Colbeck, D. Englund, T. Gehring, C. Lupo, C. Otta- viani, J. Pereira, M. Razavi, J. S. Shaari, M. Tomamichel, V. C. Usenko, G. Vallone, P. Villoresi, and P. Wallden, Advance s in quantum cryptography, Advances in Optics and Photonics 12, 1012 (2020)

  6. [6]

    Scarani, H

    V. Scarani, H. Bechmann-Pasquinucci, N. J. Cerf, M. Duˇ s ek, N. L¨ utkenhaus, and M. Peev, The security of practical quantum key distribution, Reviews of Modern Physics 81, 1301 (2009)

  7. [7]

    Lucamarini, Z

    M. Lucamarini, Z. L. Yuan, J. F. Dynes, and A. J. Shields, O vercoming the rate–distance limit of quantum key distribut ion without quantum repeaters, Nature 557, 400 (2018)

  8. [8]

    Wang, Z.-W

    X.-B. Wang, Z.-W. Yu, and X.-L. Hu, Twin-field quantum key distribution with large misalignment error, Physical Revi ew A 98, 062323 (2018)

Show all 73 references
  1. [9]

    X. Ma, P. Zeng, and H. Zhou, Phase-matching quantum key di stribution, Physical Review X 8, 031043 (2018)

  2. [10]

    Lin and N

    J. Lin and N. L¨ utkenhaus, Simple security analysis of ph ase-matching measurement-device-independent quantum ke y distribution, Physical Review A 98, 042332 (2018)

  3. [11]

    Curty, K

    M. Curty, K. Azuma, and H.-K. Lo, Simple security proof o f twin-field type quantum key distribution protocol, NPJ Quantum Information 5, 64 (2019)

  4. [12]

    Cui, Z.-Q

    C. Cui, Z.-Q. Yin, R. Wang, W. Chen, S. Wang, G.-C. Guo, an d Z.-F. Han, Twin-field quantum key distribution without phase postselection, Physical Review Applied 11, 034053 (2019)

  5. [13]

    Liu, W.-J

    Y. Liu, W.-J. Zhang, C. Jiang, J.-P. Chen, C. Zhang, W.-X . Pan, D. Ma, H. Dong, J.-M. Xiong, C.-J. Zhang, et al. , Experimental twin-field quantum key distribution over 1000 km fiber distance, Physical Review Letters 130, 210801 (2023)

  6. [14]

    Liu, W.-J

    Y. Liu, W.-J. Zhang, C. Jiang, J.-P. Chen, D. Ma, C. Zhang , W.-X. Pan, H. Dong, J.-M. Xiong, C.-J. Zhang, et al. , 1002 km twin-field quantum key distribution with finite-key analy sis, Quantum Frontiers 2, 16 (2023)

  7. [15]

    Pittaluga, Y

    M. Pittaluga, Y. S. Lo, A. Brzosko, R. I. Woodward, D. Sca lcon, M. S. Winnel, T. Roger, J. F. Dynes, K. A. Owen, S. Ju´ arez,et al. , Long-distance coherent quantum communications in deploy ed telecom networks, Nature 640, 911 (2025)

  8. [16]

    Pittaluga, M

    M. Pittaluga, M. Minder, M. Lucamarini, M. Sanzaro, R. I . Woodward, M.-J. Li, Z. Yuan, and A. J. Shields, 600-km repeater-like quantum communications with dual-band stab ilization, Nature Photonics 15, 530 (2021)

  9. [17]

    J.-P. Chen, C. Zhang, Y. Liu, C. Jiang, W.-J. Zhang, Z.-Y . Han, S.-Z. Ma, X.-L. Hu, Y.-H. Li, H. Liu, F. Zhou, H.-F. Jiang, T.-Y. Chen, H. Li, L.-X. You, Z. Wang, X.-B. Wang, Q. Zh ang, and J.-W. Pan, Twin-field quantum key distribution over 511 km optical fiber linking two dis...

  10. [18]

    H. Liu, C. Jiang, H.-T. Zhu, M. Zou, Z.-W. Yu, X.-L. Hu, H. Xu, S. Ma, Z. Han, J.-P. Chen, Y. Dai, S.-B. Tang, W. Zhang, H. Li, L. You, Z. Wang, Y. Hua, H. Hu, H. Zhang, F. Zhou, Q. Zhang , X.-B. Wang, T.-Y. Chen, and J.-W. Pan, Field test of twin-field quantum key distribution...

  11. [19]

    Wang, Z.-Q

    S. Wang, Z.-Q. Yin, D.-Y. He, W. Chen, R.-Q. Wang, P. Ye, Y . Zhou, G.-J. Fan-Yuan, F.-X. Wang, W. Chen, Y.-G. Zhu, P. V. Morozov, A. V. Divochiy, Z. Zhou, G.-C. Guo, and Z.-F. Ha n, Twin-field quantum key distribution over 830-km fibre, Nature Photonics 16, 154 (2022)

  12. [20]

    L. Zhou, J. Lin, Y. Jing, and Z. Yuan, Twin-field quantum k ey distribution without optical frequency dissemination, nature communications 14, 928 (2023)

  13. [21]

    L. Zhou, J. Lin, C. Ge, Y. Fan, Z. Yuan, H. Dong, Y. Liu, D. M a, J.-P. Chen, C. Jiang, et al. , Independent-optical- frequency-comb-powered 546-km field test of twin-field quan tum key distribution, Physical Review Applied 22, 064057 (2024)

  14. [22]

    J.-P. Chen, F. Zhou, C. Zhang, C. Jiang, F.-X. Chen, J. Hu ang, H. Li, L.-X. You, X.-B. Wang, Y. Liu, et al. , Twin-field quantum key distribution with local frequency reference, P hysical Review Letters 132, 260802 (2024)

  15. [23]

    J.-P. Chen, C. Zhang, Y. Liu, C. Jiang, D.-F. Zhao, W.-J. Zhang, F.-X. Chen, H. Li, L.-X. You, Z. Wang, Y. Chen, X.-B. Wang, Q. Zhang, and J.-W. Pan, Quantum key distribution over 658 km fiber with distributed vibration sensing, Physical Review Letters 128, 180502 (2022)

  16. [24]

    X.-T. Fang, P. Zeng, H. Liu, M. Zou, W. Wu, Y.-L. Tang, Y.- J. Sheng, Y. Xiang, W. Zhang, H. Li, Z. Wang, L. You, M.-J. Li, H. Chen, Y.-A. Chen, Q. Zhang, C.-Z. Peng, X. Ma, T.- Y. Chen, and J.-W. Pan, Implementation of quantum key distribution surpassing the linear rate-trans...

  17. [25]

    Liao, W.-Q

    S.-K. Liao, W.-Q. Cai, W.-Y. Liu, L. Zhang, Y. Li, J.-G. R en, J. Yin, Q. Shen, Y. Cao, Z.-P. Li, F.-Z. Li, X.-W. Chen, L.-H. Sun, J.-J. Jia, J.-C. Wu, X.-J. Jiang, J.-F. Wang, Y.-M . Huang, Q. Wang, Y.-L. Zhou, L. Deng, T. Xi, L. Ma, T. Hu, Q. Zhang, Y.-A. Chen, N.-L. Liu, X....

  18. [26]

    Li, W.-Q

    Y. Li, W.-Q. Cai, J.-G. Ren, C.-Z. Wang, M. Yang, L. Zhang , H.-Y. Wu, L. Chang, J.-C. Wu, B. Jin, H.-J. Xue, X.-J. Li, H. Liu, G.-W. Yu, X.-Y. Tao, T. Chen, C.-F. Liu, W.-B. Luo, J. Zhou, H.-L. Yong, Y.-H. Li, F.-Z. Li, C. Jiang, H.-Z. Chen, C. Wu, X.-H. Tong, S.-J. Xie, F. Z...

  19. [27]

    Zapatero, ´A

    V. Zapatero, ´A. Navarrete, and M. Curty, Implementation security in quan tum key distribution, Advanced Quantum Technologies 8, 2300380 (2025)

  20. [28]

    Hwang, Quantum key distribution with high loss: t oward global secure communication, Physical Review Letter s 91, 057901 (2003)

    W.-Y. Hwang, Quantum key distribution with high loss: t oward global secure communication, Physical Review Letter s 91, 057901 (2003)

  21. [29]

    Wang, Beating the photon-number-splitting atta ck in practical quantum cryptography, Physical Review Lett ers 94, 230503 (2005)

    X.-B. Wang, Beating the photon-number-splitting atta ck in practical quantum cryptography, Physical Review Lett ers 94, 230503 (2005)

  22. [30]

    H.-K. Lo, X. Ma, and K. Chen, Decoy state quantum key dist ribution, Physical Review Letters 94, 230504 (2005)

  23. [31]

    H.-K. Lo, M. Curty, and B. Qi, Measurement-device-inde pendent quantum key distribution, Physical Review Letters 108, 130503 (2012)

  24. [32]

    S. L. Braunstein and S. Pirandola, Side-channel-free q uantum key distribution, Physical Review Letters 108, 130502 (2012)

  25. [33]

    Pereira, G

    M. Pereira, G. Kato, A. Mizutani, M. Curty, and K. Tamaki , Quantum key distribution with correlated sources, Sci. Ad v. 6, eaaz4487 (2020)

  26. [34]

    Zapatero, ´A

    V. Zapatero, ´A. Navarrete, K. Tamaki, and M. Curty, Security of quantum ke y distribution with intensity correlations, Quantum 5, 602 (2021)

  27. [35]

    Li, F.-Y

    J.-X. Li, F.-Y. Lu, Z.-H. Wang, V. Zapatero, M. Curty, S. Wang, Z.-Q. Yin, W. Chen, D.-Y. He, G.-C. Guo, et al., Quantum key distribution overcoming practical correlated intensi ty fluctuations, npj Quantum Information 11, 106 (2025)

  28. [36]

    Curr´ as-Lorenzo, M

    G. Curr´ as-Lorenzo, M. Pereira, G. Kato, . T. . M. Curty, and K. Tamaki, Security framework for quantum key distribut ion with imperfect sources, Optica Quantum 3, 525 (2025)

  29. [37]

    Tupkary, S

    D. Tupkary, S. Nahar, P. Sinha, and N. L¨ utkenhaus, Phase error rate estimation in qkd with imperfect detectors, Qua ntum 9, 1937 (2025)

  30. [38]

    Nahar, D

    S. Nahar, D. Tupkary, and N. L¨ utkenhaus, Imperfect det ectors for adversarial tasks with applications to quantum k ey distribution, Quantum 10, 2044 (2026)

  31. [39]

    Renner, Security of quantum key distribution , Ph.D

    R. Renner, Security of quantum key distribution , Ph.D. thesis, SWISS FEDERAL INSTITUTE OF TECHNOLOGY ZURICH (2005)

  32. [40]

    Tomamichel, C

    M. Tomamichel, C. C. W. Lim, N. Gisin, and R. Renner, Tigh t finite-key analysis for quantum cryptography, Nature Communications 3, 634 (2012)

  33. [41]

    C. C. W. Lim, M. Curty, N. Walenta, F. Xu, and H. Zbinden, C oncise security bounds for practical decoy-state quantum key distribution, Physical Review A 89, 022307 (2014)

  34. [42]

    Curty, F

    M. Curty, F. Xu, W. Cui, C. C. W. Lim, K. Tamaki, and H.-K. L o, Finite-key analysis for measurement-device-independe nt quantum key distribution, Nature Communications 5, 4732 (2014)

  35. [43]

    Jiang, Z.-W

    C. Jiang, Z.-W. Yu, X.-L. Hu, and X.-B. Wang, Unconditio nal security of sending or not sending twin-field quantum key distribution with finite pulses, Physical Review Applied 12, 024061 (2019)

  36. [44]

    Curr´ as-Lorenzo, ´A

    G. Curr´ as-Lorenzo, ´A. Navarrete, K. Azuma, G. Kato, M. Curty, and M. Razavi, Tigh t finite-key security for twin-field quantum key distribution, npj Quantum Information 7, 1 (2021)

  37. [45]

    P. Zeng, W. Wu, and X. Ma, Symmetry-protected privacy: b eating the rate-distance linear bound over a noisy channel, Physical Review Applied 13, 064013 (2020)

  38. [46]

    P. Zeng, H. Zhou, W. Wu, and X. Ma, Mode-pairing quantum k ey distribution, Nature Communications 13, 3903 (2022)

  39. [47]

    Xie, Y.-S

    Y.-M. Xie, Y.-S. Lu, C.-X. Weng, X.-Y. Cao, Z.-Y. Jia, Y. Bao, Y. Wang, Y. Fu, H.-L. Yin, and Z.-B. Chen, Breaking the rate-loss bound of quantum key distribution with asynchron ous two-photon interference, Prx Quantum 3, 020315 (2022)

  40. [48]

    Tupkary, E

    D. Tupkary, E. Y.-Z. Tan, and N. L¨ utkenhaus, Security proof for variable-length quantum key distribution, Physic al Review Research 6, 023002 (2024)

  41. [49]

    Hayashi and R

    M. Hayashi and R. Nakayama, Security analysis of the dec oy method with the bennett–brassard 1984 protocol for finite key lengths, New Journal of Physics 16, 063009 (2014)

  42. [50]

    Kanitschar and M

    F. Kanitschar and M. Huber, Composable finite-size secu rity of high-dimensional quantum-key-distribution proto cols, Physical Review Applied 24, 054028 (2025)

  43. [51]

    Christandl, R

    M. Christandl, R. K¨ onig, and R. Renner, Postselection technique for quantum channels with applications to quantu m cryptography, Physical Review Letters 102, 020504 (2009)

  44. [52]

    Nahar, D

    S. Nahar, D. Tupkary, Y. Zhao, N. L¨ utkenhaus, and E. Y.- Z. Tan, Postselection technique for optical quantum key distribution with improved de finetti reductions, PRX Quant um 5, 040315 (2024)

  45. [53]

    Wang, X.-L

    X.-B. Wang, X.-L. Hu, and Z.-W. Yu, Practical long-dist ance side-channel-free quantum key distribution, Physica l Review Applied 12, 054034 (2019)

  46. [54]

    Jiang, X.-L

    C. Jiang, X.-L. Hu, Z.-W. Yu, and X.-B. Wang, Side-chann el security of practical quantum key distribution, Physica l Review Research 6, 013266 (2024)

  47. [55]

    Kamin, D

    L. Kamin, D. Tupkary, and N. L¨ utkenhaus, Improved finit e-size effects in qkd protocols with applications to decoy-s tate qkd, arXiv preprint arXiv:2502.05382 (2025)

  48. [56]

    Jiang, X.-L

    C. Jiang, X.-L. Hu, Z.-W. Yu, H. Xu, and X.-B. Wang, Side- channel-secure quantum key distribution with state-depen dent correlated errors and trojan-horse attack, Optics Express 33, 51715 (2025). 15

  49. [57]

    Jiang, Z.-W

    C. Jiang, Z.-W. Yu, X.-L. Hu, and X.-B. Wang, Side-chann el-secure quantum key distribution with imperfect vacuum sources, Physical Review Applied 19, 064003 (2023)

  50. [58]

    Metger and R

    T. Metger and R. Renner, Security of quantum key distrib ution from generalised entropy accumulation, Nature Commu - nications 14, 5272 (2023)

  51. [59]

    Y.-H. Li, T. Zeng, M.-Y. Wang, C. Jiang, J. Lin, H.-B. Fu, X.-Y. Zheng, J.-P. Chen, Z.-S. Lin, C.-L. Li, et al. , Free-space twin-field quantum key distribution, Nature Photonics 20, 783 (2026)

  52. [60]

    Kato, Concentration inequality using unconfirmed kn owledge, arXiv preprint arXiv:2002.04357 (2020)

    G. Kato, Concentration inequality using unconfirmed kn owledge, arXiv preprint arXiv:2002.04357 (2020)

  53. [61]

    Chernoff, A measure of asymptotic efficiency for tests o f a hypothesis based on the sum of observations, The Annals of Mathematical Statistics 23, 493 (1952)

    H. Chernoff, A measure of asymptotic efficiency for tests o f a hypothesis based on the sum of observations, The Annals of Mathematical Statistics 23, 493 (1952)

  54. [62]

    Zhang, Q

    Z. Zhang, Q. Zhao, M. Razavi, and X. Ma, Improved key-rat e bounds for practical decoy-state quantum-key-distribut ion systems, Physical Review A 95, 012333 (2017)

  55. [63]

    R. J. Serfling, Probability inequalities for the sum in s ampling without replacement, The Annals of Statistics , 39 ( 1974)

  56. [64]

    Tomamichel, Quantum information processing with finite resources: math ematical foundations, Vol

    M. Tomamichel, Quantum information processing with finite resources: math ematical foundations, Vol. 5 (Springer, 2015)

  57. [65]

    Tomamichel and R

    M. Tomamichel and R. Renner, Uncertainty relation for s mooth entropies, Physical Review Letters 106, 110506 (2011)

  58. [66]

    J. L. W. V. Jensen, Sur les fonctions convexes et les in´ e galit´ es entre les valeurs moyennes, Acta mathematica 30, 175 (1906)

  59. [67]

    Shan, Z.-Q

    Y.-G. Shan, Z.-Q. Yin, S. Wang, W. Chen, D.-Y. He, G.-C. G uo, and Z.-F. Han, Improved finite-key analysis for side- channel-secure quantum key distribution with de finetti red uction, Physica Scripta 100, 115117 (2025)

  60. [68]

    Mannalath, V

    V. Mannalath, V. Zapatero, and M. Curty, Sharp finite sta tistics for quantum key distribution, Physical Review Lett ers 135, 020803 (2025). Appendix A: Determine the secure final key length after error correction for variable-length QKD against coherent attacks An entanglement-...

  61. [69]

    The Serfling’s inequality was employed in Ref

    The Serfling’s inequality The finite-key effects in the qubit BB84 protocol have been extens ively studied. The Serfling’s inequality was employed in Ref. [39] to tightly bound the finite-key effects for the fi xed-length qubit BB84 protocol. Through a straightforward generalization,...

  62. [70]

    The inverse Chernoff bound The inverse Chernoff bound was first introduced and proven to be le gitimately applicable in the decoy-state pa- rameter estimation of QKD in Ref. [61]. In this part, we shall use the s ecurity framework for variable-length QKD to prove its correctness....

  63. [71]

    II C, we have rigorously shown that Kato’s inequality applies t o variable-length QKD protocols

    The Kato’s inequality In Sec. II C, we have rigorously shown that Kato’s inequality applies t o variable-length QKD protocols. We now explain the restriction on parameters a and b when constructing the estimator in Eq. (D2) to upper-bound the expectation from the observed valu...

  64. [72]

    The failure probability is ultimately evaluated using the original (non -inverted) form of the concentration inequality, Eqs. (D1,D5,E1,E2), even when we use the inverse form of the concentration inequality, i.e., to construct the estimator to upper-bound or lower-bound the ex...

  65. [73]

    (D24)–(D26)

    The Chernoff bound admits a fictitious multi-step measurement su ch that the relevant expectation is fully determined by prior outcomes, making it deterministic when condition ed on earlier measurements and allowing the conditioning trick of Eqs. (D24)–(D26). In contrast, the ex...

Pith tools

Reviewed August 1, 2026 · model on record in the stance chip above.