REVIEW 2 major objections 5 minor 43 references
Security of Quantum Conference Key Agreement with Two-Way Classical Communication
T0 review · 2 major / 5 minor · reviewed 2026-07-11 · grok-4.5
Pith's one-line read Iterated B-steps push the noise threshold of two-basis GHZ conference-key agreement past 20 percent.
desk verdict Clean analytic multi-B-step rates for two-basis GHZ QCKA that push the symmetric threshold past 20%; solid induction under the corner regime, modest novelty. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The recursive upper bound of Lemma 1 together with the corner-invariance statements of Lemmas 2 and 3, which together prove Theorem 1: the multi-step phase-error maximizer stays at the same geometric corner that solves the single-step problem.
What would settle it
Compute the five-step recursion of Eqs. (133)–(135) for the fully symmetric point s1=s2=s3=s4=0.20 and check whether the resulting key rate is still strictly positive; if it is negative, the claimed threshold is false.
Extended reading notes
Core claim
When the observed bit- and phase-error rates satisfy the corner condition max{s2+s3,s3+s4,s2+s4}<1-2s1, the worst-case phase-error rate after any number of B-steps equals the value obtained by always evaluating the B-map at the single corner point (s1+s2,s1+s3,s1+s4). Consequently the secure key rate after n B-steps (and any number of subsequent P-steps) is given by an elementary recursion that can be computed without further optimization, and this rate remains positive for symmetric errors larger than 20 percent.
Load-bearing premise
The multi-step analysis is restricted to the single geometric corner that alone yields a positive key rate for one B-step; the other seven analytic solutions of the single-step optimization are discarded after a numerical grid search rather than proved irrelevant for every number of iterations.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper derives an asymptotic secure key rate for tripartite GHZ-based quantum conference key agreement (QCKA) that uses only two measurement bases and two-way classical communication (iterated B-steps and P-steps). After formulating the worst-case phase-error optimization over the physically allowed (s5,s6,s7) region, the authors solve the single-B-step problem geometrically, obtaining eight closed-form candidate solutions (Table I). They then prove, under the corner condition max{s2+s3,s3+s4,s2+s4}<1−2s1, that the worst-case phase error after any number of B-steps (and subsequent P-steps) is given by a simple recursive evaluation at the corner point (Theorems 1–2, Lemmas 1–3). Numerical evaluation under the symmetric error model shows that five B-steps raise the tolerable error rate above 20 percent, improving on the ~11 percent (no two-way) and ~15 percent (single B-step) thresholds.
Significance. The work closes a long-standing gap between the three-basis analyses of multipartite two-way QCKA and the practically preferred two-basis setting. The analytic reduction of the multi-step optimization to a recursive single-step corner evaluation is a clear technical advance over the numerical single-B-step results of prior work. The demonstrated jump of the error threshold past 20 percent is of direct practical interest for noisy GHZ-based conference-key protocols. Strengths include fully analytic solutions for the single-step geometry, induction proofs that lift the corner solution to arbitrary n and m, and explicit verification that the corner solution remains inside the physical region (Appendices A–B).
major comments (2)
- Sec. IV C and the preamble to Theorem 1: the multi-step analysis is restricted to the single geometric case (Case 1 / corner) that alone produces a positive key rate for one B-step. This restriction is justified only by a finite grid search (450 704 points) rather than a proof that the other seven analytic solutions remain non-positive after further B-steps. While all thresholds plotted in Fig. 3 lie strictly inside the proved corner region of Theorem 1, a short analytic argument (or an explicit statement that the claimed >20 percent threshold is conditional on the initial parameters already satisfying the corner inequality) would remove any residual doubt about the scope of the multi-step claim.
- Sec. VII, asymptotic expansion around Eqs. (149)–(162): the conclusion that a subsequent P-step cannot improve the threshold is derived under the high-error regime sX≈1/2−ϵX, sZ≈ϵZ after many B-steps. It would strengthen the paper to confirm, at least numerically for a few moderate-error points, that no mixed ordering (e.g., BPBP or P after fewer B-steps) enlarges the positive-rate region relative to pure B-step iteration.
minor comments (5)
- Eq. (4) and the protocol description: the factor f·max{h(s2),h(s3)} is written without an explicit reference to the three-party error-correction cost; a one-sentence clarification that the same syndrome is used for both Bob and Charlie (or that the larger of the two binary entropies is taken) would help readers unfamiliar with the multipartite setting.
- Fig. 3 caption and main text: the colors of the solid curves (0–5 B-steps) are listed but not labeled on the figure itself; adding a legend would improve readability.
- Sec. II, step (6): the B-step and P-step are defined for the remaining Z-basis rounds, yet the update formulae for s5,s6,s7 appear only later. A forward reference to Eqs. (15) and (19) would make the protocol self-contained.
- Appendix B: the case-by-case verification that the eight solutions satisfy the remaining physical inequalities is thorough but lengthy; a short summary table of which inequalities become equalities on each face/edge would aid navigation.
- References [13] and [14]: the arXiv identifiers or DOIs for the recent single-B-step works would help readers locate the numerical baselines that are compared in Fig. 3.
Circularity Check
No circularity: key-rate recursion and thresholds follow by induction from GHZ non-negativity and the B/P maps under an explicit corner condition.
full rationale
The secure-key formula is the standard asymptotic expression 1-f max{h(s2),h(s3)}-h(s1) after the Gottesman–Lo B/P maps. The only optimization is maximization of the phase-error rate over the convex set Tphys defined by non-negativity of the eight GHZ probabilities (Eqs. 22–33). For a single B-step the maximizer is obtained geometrically (closest point to (1/2,1/2,1/2) inside the pyramid); eight closed-form candidates are listed in Table I. Under the corner condition max{s2+s3,s3+s4,s2+s4}<1-2s1 the multi-step analysis reduces, by three elementary lemmas and induction (Theorem 1), to the same corner point evaluated under the explicit recursion (133)–(135). Subsequent P-steps preserve the same maximizer (Theorem 2). No free parameters are fitted to data; the numerical thresholds in Fig. 3 are direct evaluations of that recursion inside the proved corner regime. Prior citations supply the B/P maps and the single-step two-basis setting but are not load-bearing for the induction or the claimed >20 % threshold. The restriction of the multi-step theorems to Case 1 is a scope limitation motivated by a one-step grid search, not a circular reduction of the claimed rates.
Assumptions & free parameters
free parameters (1)
- error-correction efficiency f =
1
assumptions (4)
- domain assumption IID collective attacks (identical independent interaction of Eve with each copy)
- domain assumption Off-diagonal GHZ coherences can be set to zero without loss of generality for the two-way protocol
- ad hoc to paper Only the corner solution (Case 1) of the single-B-step optimization can produce a positive key rate
- domain assumption s1,s2,s3,s4 < 1/2
Cite this review
Pith. "Pith review of Security of Quantum Conference Key Agreement with Two-Way Classical Communication." pith.science (2026). https://pith.science/paper/L6VNDGGY
@misc{pith2026260704538,
author = {Pith},
title = {Pith review of: Security of Quantum Conference Key Agreement with Two-Way Classical Communication},
year = {2026},
howpublished = {\url{https://pith.science/paper/L6VNDGGY}},
note = {Machine review of arXiv:2607.04538}
}
read the original abstract
Quantum conference key agreement (QCKA) enables multiple users to establish a common secret key with information-theoretic security and is regarded as a key primitive for secure communication in future quantum networks. However, practical implementations of QCKA typically suffer from higher noise levels than conventional bipartite quantum key distribution (QKD), making the improvement of the tolerable error threshold an important challenge. Gottesman and Lo proposed two preprocessing procedures for QKD with two-way classical communication, known as the B-step and the P-step, which enhance the tolerable error threshold. In this paper, we analyze the asymptotic security of QCKA with tripartite GHZ states and two measurement bases using two-way classical communication, including multiple B-steps and P-steps. We derive the corresponding secure key rate analytically and demonstrate that iterative B-steps can increase the tolerable error threshold beyond 20%, significantly improving upon the approximately 11% threshold achievable without two-way classical communication and the approximately 15% threshold obtained with only a single B-step. Our results show that two-way classical communication can substantially enhance the robustness of practical QCKA protocols.
Figures
Reference graph
Works this paper leans on
-
[1]
is expressed through an optimization problem whose solution is only obtained numerically. In this paper, we derive an asymptotic secure key rate for QCKA with tripartite GHZ states and two measurement bases using two-way classical communication, including multiple B-steps and P-steps. In particular, we derive an analytical solution to the optimization pro...
arXiv 2026
-
[2]
Each party computes the parity of their two bits:p A =b (l) A ⊕b (m) A ,p B =b (l) B ⊕b (m) B ,p C =b (l) C ⊕b (m) C
-
[3]
They publicly compare (p A,p B,p C)
-
[4]
The pair is kept only ifp A =p B =p C, otherwise it is discarded
-
[5]
3 ·P-step:The parties randomly group the remainingZ-basis rounds into blocks of size three
From each surviving pair, only one bit (b(l) A ,b (l) B ,b (l) C ) is retained as the new key. 3 ·P-step:The parties randomly group the remainingZ-basis rounds into blocks of size three. For each block (l,m,n):
-
[6]
Each party computes the parity over the block: ˜pA =b (l) A ⊕b (m) A ⊕b (n) A , ˜pB =b (l) B ⊕b (m) B ⊕b (n) B , ˜pC =b (l) C ⊕b (m) C ⊕b (n) C
-
[7]
The B-step and P-step update the parameterss 1,s 2,s 3 ands 4, of which the expressions are shown in Sec
The resulting bits ( ˜pA,˜pB,˜pC) are defined as the new key. The B-step and P-step update the parameterss 1,s 2,s 3 ands 4, of which the expressions are shown in Sec. III. (7)Iteration of B- and P-steps: Step (6) is iterated with updateds 1,s 2,s 3 ands 4. The iteration sequence is optimized depending on the original observed error ratess 1,s 2,s 3 ands ...
-
[8]
the spherical nature of the level surface ofs (1) i (s5,s 6,s 7) with respect to (s5,s 6,s 7),
Show all 43 references
-
[9]
In the next section, we derive analytical solutions of the worst-case values of (s 5,s 6,s 7) for the optimization problem in Eq
the fact that the worst is attained ats 5 =s 6 =s 7 =1/2, the solution to the optimization problem can be rephrased as follows: The point(s 5,s 6,s 7)that maximizes s (1) i (s5,s 6,s 7)is the point closest to s 5 =s 6 =s 7 =1/2within the region T phys. In the next section, we ...
-
[10]
The covariant and contravariant vectors also satisfy the following relations, ei ·e j = 1 2 ,(56) ei ·e j =− 1 2 .(57) In the following analysis, the origin of the coordinates is taken asS. Then, the pointPcan be expressed in terms of the covariant and contravariant vectors as...
-
[11]
(90) Equations (89) and (90) imply that the accessible region of (s(n) 5 ,s (n) 6 ,s (n) 7 ) is contained inT (n) pyramid
independent of (s5,s 6,s 7), define the region T (n) pyramid B{(s ′ 5,s ′ 6,s ′ 7)| −s ′ 5 +s ′ 6 +s ′ 7 ≤s (n) 1,max −s (n) 2 +s (n) 3 +s (n) 4 , +s ′ 5 −s ′ 6 +s ′ 7 ≤s (n) 1,max +s (n) 2 −s (n) 3 +s (n) 4 , +s ′ 5 +s ′ 6 −s ′ 7 ≤s (n) 1,max +s (n) 2 +s (n) 3 −s (n) 4 }. (90...
-
[12]
First, we define the conditions in which this is the worst-case point
Case 2: Edgee 1 We consider the case where the worst-case point lies on the edge ofTpyramid, defined by the unit vectore 1. First, we define the conditions in which this is the worst-case point. This is equivalent to the condition when the pointPis closest to the considered ed...
-
[13]
Case 3: Edgee 2 The analysis for Edgee 2 is completely analogous to that for Edgee 1. By exchanging (e1,e 2)↔(e 2,e 1), the worst-case point is obtained as P′ = 1 2(1+s 2 −s 4) s1 +s 3 1 2(1−s 2 +s 4) ,(A14) provided that 1−2s 1 −s 2 −s 4 <0,(A15) 1−2s 1 +s...
-
[14]
Case 4: Edgee 3 The analysis for Edgee 3 is also completely analogous to that for Edgee 1. By exchanging (e1,e 3)↔(e 3,e 1), the worst-case point is obtained as P′ = 1 2(1+s 2 −s 3) 1 2(1−s 2 +s 3) s1 +s 4 ,(A20) provided that 1−2s 1 −s 2 −s 3 <0,(A21) 1−2s...
-
[15]
First, we define the conditions in which this is the worst case point
Case 5: Facee 1 We consider the case where the worst-case point lies on the face defined by the normale 1. First, we define the conditions in which this is the worst case point. This is equivalent to the condition when the pointPis closest to the considered face out of all oth...
-
[16]
Case 6: Facee 2 The analysis for Facee 2 is completely analogous to that for Facee 1. By exchanging (e1,e 2)↔(e 2,e 1), the worst-case point is obtained as P′ = 1 3 1+s 1 +s 2 −s 3 +s 4 2−s 1 −s 2 +s 3 −s 4 1+s 1 +s 2 −s 3 +s 4 ,(A39) provided that 1 2 −s 1...
-
[17]
Case 7: Facee 3 The analysis for Facee 3 is also completely analogous to that for Facee 1. By exchanging (e1,e 3)↔(e 3,e 1), the worst-case point is obtained as P′ = 1 3 1+s 1 +s 2 +s 3 −s 4 1+s 1 +s 2 +s 3 −s 4 2−s 1 −s 2 −s 3 +s 4 ,(A45) provided that 1 2...
-
[18]
In this case, the pointP=(1/2,1/2,1/2) T becomes the realizable worst case
Case 8: Within the pyramid We consider the case where the worst-case point lies withinT pyramid. In this case, the pointP=(1/2,1/2,1/2) T becomes the realizable worst case. In the coordinate space whereSis the origin, this is defined in terms of the aforementioned vectors as ∃...
-
[19]
These solutions are derived so as to satisfy the three constraints, Eqs
Summary of the eight cases In summary, we have shown that there exist eight analytical solutions, depending on the conditions satisfied bys 1,s 2,s 3,s 4. These solutions are derived so as to satisfy the three constraints, Eqs. (23), (25) and (27), among the eight physical con...
-
[20]
Case 1: Corner We consider the case where the solution is given by the corner of the pyramidS, corresponding to the case discussed in Sec. IV B. For Eq. (22), substitution of the solution in Eq. (67) to the left-hand side gives s5 +s 6 −s 7 =s 1 +s 2 +s 1 +s 3 −s 1 −s 4 =s 1 +...
-
[21]
Case 2-4: Edgee 1,e 2,e 3 We first consider the case where the solution is on the edge specified by the vectore 1, corresponding to Case 2 discussed in Sec. A 1. For Eq. (22), substitution of the solution in Eq. (A8) to the left-hand side gives s5 +s 6 −s 7 =s 1 +s 2 + 1 2(1+s...
-
[22]
Case 5-7: Facee 1,e 2,e 3 We consider the case where the solution is on the face specified by the vectore1, corresponding to Case 5 discussed in Sec. A 4. For Eq. (22), substitution of the solution in Eq. (A33) to the left-hand side gives s5 +s 6 −s 7 = 1 3(2−s 1 +s 2 −s 3 −s ...
-
[23]
Case 8: Within the pyramid We consider the case where the solution lies within the pyramidTpyramid and is given byP, corresponding to the case discussed in Sec. A 7. For Eq. (22), substitution of the solution in Eq. (A52) allows the constraint to be written in terms ofs 1,s 2,...
-
[24]
H. J. Kimble, Nature453, 1023 (2008)
2008
-
[25]
Wehner, D
S. Wehner, D. Elkouss, and R. Hanson, Science362, eaam9288 (2018)
2018
-
[26]
D. M. Greenberger, M. A. Horne, and A. Zeilinger, Going beyond bell’s theorem, inBell’s Theorem, Quantum Theory and Conceptions of the Universe, edited by M. Kafatos (Springer Netherlands, Dordrecht, 1989) pp. 69–72
1989
-
[27]
Grasselli, H
F. Grasselli, H. Kampermann, and D. Bruß, New Journal of Physics20, 113014 (2018)
2018
-
[28]
Proietti, J
M. Proietti, J. Ho, F. Grasselli, P. Barrow, M. Malik, and A. Fedrizzi, Science Advances7, eabe0395 (2021). 31
2021
-
[29]
Pickston, J
A. Pickston, J. Ho, A. Ulibarrena, F. Grasselli, M. Proietti, C. L. Morrison, P. Barrow, F. Graffitti, and A. Fedrizzi, npj Quantum Informa- tion9, 82 (2023)
2023
-
[30]
Zou, B.-C
M. Zou, B.-C. Li, S. Zhao, Y . Mao, D. Qin, X. Jiang, T.-Y . Chen, and J.-W. Pan, Phys. Rev. Lett.136, 020801 (2026)
2026
-
[31]
Gottesman and H.-K
D. Gottesman and H.-K. Lo, IEEE Transactions on Information Theory49, 457 (2003)
2003
-
[32]
Maurer, IEEE Transactions on Information Theory39, 733 (1993)
U. Maurer, IEEE Transactions on Information Theory39, 733 (1993)
1993
-
[33]
C. H. Bennett and G. Brassard, inProceedings of IEEE International Conference on Computers, Systems and Signal Processing, V ol. 175, Bangalore, India (IEEE Press, New York, 1984)
1984
-
[34]
C. H. Bennett, G. Brassard, and N. D. Mermin, Phys. Rev. Lett.68, 557 (1992)
1992
-
[35]
Chen and H.-K
K. Chen and H.-K. Lo, Quantum Info. Comput.7, 689–715 (2007)
2007
-
[36]
W. O. Krawec, Discover Networks1, 5 (2025)
2025
- [37]
- [38]
-
[39]
Z. Du, G. Liu, X. Zhang, and X. Ma, Quantum Science and Technology10, 015050 (2024)
2024
-
[40]
N. J. Beaudry, T. Moroder, and N. L¨utkenhaus, Phys. Rev. Lett.101, 093601 (2008)
2008
-
[41]
Tsurumaru and K
T. Tsurumaru and K. Tamaki, Phys. Rev. A78, 032302 (2008)
2008
-
[42]
Renner, Nature Physics3, 645 (2007)
R. Renner, Nature Physics3, 645 (2007)
2007
-
[43]
Christandl, R
M. Christandl, R. K ¨onig, and R. Renner, Phys. Rev. Lett.102, 020504 (2009)
2009
Reviewed July 11, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.