Pith. sign in

REVIEW 3 major objections 5 minor 59 references

This paper reports the first BB84 QKD experiment whose finite-size security proof accounts for both imperfectly characterized detectors and a non-ideal single-photon source, yielding a secure key of about 2.16 million bits in 20 minutes.

Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →

T0 review · deepseek-v4-flash

2026-08-01 13:10 UTC pith:OYJAOVYJ

load-bearing objection A well-executed experimental BB84 paper whose headline security claim does not follow from the implementation as described, because the repeated random sequence breaks the independence assumption in the security proof. the 3 major comments →

arxiv 2607.19204 v1 pith:OYJAOVYJ submitted 2026-07-21 quant-ph

Experimental quantum cryptography with single photons and imperfect devices

classification quant-ph MSC 81P94 PACS 03.67.Dd
keywords quantum key distributionBB84single-photon sourcequantum dotdevice imperfectionsfinite-size securityentropic uncertainty relationpolarization encoding
verification ladder T0 review T1 audit T2 compute T3 formal T4 reserved

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

This paper reports a BB84 quantum key distribution experiment (the standard four-state prepare-and-measure QKD protocol) whose finite-size security proof accounts for imperfectly characterized receiver hardware and a non-ideal single-photon source at the same time. The authors use a semiconductor quantum-dot source with strong multiphoton suppression, dynamic polarization encoding, and a fully passive four-state detector. After 20 minutes at an 80 MHz clock rate, with a basis-averaged QBER of 3.51% over 1.07×10^11 attempted rounds, they prove a secure key length of 2.1579×10^6 bits. The result matters because real QKD devices are never perfectly characterized, and earlier experimental treatments either idealized detectors or ignored the error margins on their specifications; showing that such conservative accounting still leaves a viable key is the paper's contribution.

Core claim

Using a semiconductor quantum-dot single-photon source (multiphoton suppression g^(2)(0)=0.017±0.005, mean photon number 0.005±10%) and an electro-optic modulator for fast polarization-state encoding, the authors implement the BB84 protocol with a fully passive four-state SNSPD receiver. Their security proof, based on the entropic uncertainty relation and a phase-error estimation lemma for passive optics, treats beamsplitter ratio, detector efficiencies, and dark-count rates as known only within error margins (2.5%, 2.5%, and 50%), and the source's multiphoton probability as a range. After 20 minutes at an 80 MHz clock rate, with a basis-averaged QBER of 3.51% over 1.07×10^11 attempted round

What carries the argument

The proof rests on the entropic uncertainty relation (EUR), which converts a bound on the phase error rate—the error Alice and Bob would have seen had their Z-basis rounds been measured in the conjugate X basis—into a bound on Eve's information about the raw key. The phase-error bound (Lemma 1, quoted from a companion theory paper) uses separate estimates of the single-photon contribution to the key rounds (B_Single) and of the phase error (B_Error), expressed in observed counts, multiclick events, and X-basis errors, with device parameters a (basis-selection mismatch), δ (detector-efficiency mismatch), and qZ (dark-count contribution). Source maps absorb the real source's vacuum and multiph

Load-bearing premise

The load-bearing premise is that the phase-error bounds and the device parameters a, δ, and qZ quoted from the companion theory paper are correct and that the manuscript's mapping from the measured device ranges (2.5% beamsplitter, 2.5% efficiency, 50% dark-count uncertainty) into those parameters is valid; this mapping is not derived or numerically checked in the manuscript.

What would settle it

Re-evaluate Eq. (2) with a, δ, and qZ computed directly from the stated device ranges using an independent implementation of the companion paper's formulas (Eqs. D40, D41, E2). If the resulting B_Single and B_Error violate the observed click statistics, or if a Monte Carlo simulation placing the beamsplitter at 0.496-0.014, detector efficiencies at the edges of their 2.5% range, and dark counts at 1.5×10^-7 yields a phase-error bound that exceeds the experimental X-basis error rate, the claimed 2.16×10^6-bit key is unsupported.

Watch this falsifier — get emailed when new claim-graph text bears on it.

If this is right

  • A quantum-dot source with g^(2)(0) below 2% can run BB84 without decoy states and still be proven secure under conservative device assumptions.
  • The measured 2.16×10^6-bit key in 20 minutes shows that imperfect-device accounting, while reducing the rate by about an order of magnitude, does not make QD-based QKD impractical.
  • The security framework transfers to any passive linear-optics receiver whose beamsplitter and detector parameters are known within ranges, so the same proof can be reused for other hardware.
  • Because the phase-error bound is tightened by better device characterization, improved calibration of beamsplitter ratios and detector efficiencies translates directly into longer keys.
  • The experiment's dynamic polarization encoding removes one side channel (state-dependent intensity mismatch) without requiring multiple lasers or intensity modulators.

Where Pith is reading between the lines

These are editorial extensions of the paper, not claims the author makes directly.

  • A natural next step is to close the gap the authors flag: combining source and detector imperfections in one EUR-based proof would likely recover a large part of the order-of-magnitude key-rate loss.
  • The proof assumes independent per-round basis choices, but the experiment drives the EOM with one precompiled 10^5-digit random sequence repeated over 1.1×10^11 rounds; testing whether any cyclic structure in that sequence leaks information, or proving security under such repetition, would harden the implementation.
  • The key number depends on a, δ, and qZ, whose formulas live in the companion paper; recomputing the key from the stated device ranges with an independent implementation of those formulas would settle whether 2.1579×10^6 bits is reproducible from this manuscript alone.
  • The same setup could be pushed to GHz clock rates as the authors note, and adding a Trojan-horse/light-injection analysis would address the remaining source-side attack they explicitly leave open.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, simulated authors' rebuttal, and a circularity audit.

Referee Report

3 major / 5 minor

Summary. This paper reports an implementation of BB84 using a quantum-dot single-photon source with dynamic polarization modulation and a passive four-state detector, and applies a finite-size security proof based on an entropic uncertainty relation. The proof imports detector-imperfection bounds from Ref. [1] and adds source-map bounds to account for multiphoton emission. For a 20-minute, 80-MHz run, the authors report 1.07×10^11 attempted rounds, 7.66×10^7 detections, a 3.51% basis-averaged QBER, and a computed key length of 2.1579×10^6 bits. The paper includes detailed device characterization, a blinking correction, and explicit security parameters.

Significance. If the security proof were valid for the implemented protocol, this would be a notable experimental step: a finite-size BB84 demonstration simultaneously accounting for imperfectly characterized passive detectors and non-negligible source multiphoton statistics, with a quantitative estimate of the cost of such accounting (roughly an order of magnitude in key rate). The experiment is described in unusual detail, including error margins on beamsplitter ratios, detector efficiencies, dark counts, and g^(2)(0), and the authors are candid about many limitations. However, the implementation's repeated QRNG basis sequence violates the independent-round randomness assumption of the proof, and the quantitative key-rate result depends on device-parameter mappings that are not stated in the manuscript. As a result, the central security and key-length claims are not currently established.

major comments (3)
  1. [Sec. II.A.2 and II.B; Appendix A.1.a] The implemented protocol does not satisfy the randomness assumption used in the security proof. The FPGA is fed a pre-compiled 10^5-quaternary-digit sequence from the ANU QRNG API, and Sec. II.B states that this sequence 'is repeated over the course of the protocol to obtain sufficient statistics' over 1.1×10^11 rounds. In Appendix A.1.a, the source-replacement scheme and the EUR bound treat each round's basis choice as independent with fixed probabilities p_A^Z and p_A^X (Eqs. A1-A2). With a repeated sequence, Eve can reconstruct the full basis sequence from the first period of public basis announcements and then knows the basis of every later round before transmission. She can intercept each photon, measure it in the known basis, record the bit, and resend a freshly prepared photon in that state. This attack introduces no additional QBER and can be combined with controlled loss to matc
  2. [Appendix A.2, Eqs. (A8)-(A10); Sec. II.B.1] The key-rate formula depends on parameters a, δ, and q_Z through Lemma 1, but the manuscript does not state their definitions or values. It refers only to 'Eq.'s D40, D41 and E2 respectively in Ref. [1]' (Sec. II.B.1) and says 'We refer to Ref. [1] for the exact expressions' (Appendix A.2). Ref. [1] is a co-authored preprint, not included in the manuscript, and no code or data reproducing it is shipped. The claimed secure key length is a direct numerical output of B_Single and B_Error with these parameters, so the calculation cannot be reproduced or independently checked from the information given. The authors should provide the explicit expressions (or an appendix derivation) and the numerical values used for the experimental run.
  3. [Sec. IIC, footnote 3; Sec. III (Conclusion)] The manuscript makes contradictory claims about what is proven. The abstract states that security is proven with source imperfections (finite g^(2)(0)) and receiver imperfections, while Sec. IIC, footnote 3 says 'The combination of source and detector imperfections for passive protocols in the EUR based approach is still open.' The Conclusion further says 'we are unable to account for source imperfections' while also saying the analysis accounts for 'source emission statistic imperfections.' These statements need to be reconciled. If the source-map argument in Appendix A.3 does cover multiphoton emission statistics, the wording of footnote 3 and the Conclusion is misleading; if it does not, the abstract overclaims the scope of the security proof. This ambiguity directly affects the paper's central claim.
minor comments (5)
  1. [Sec. II.B and Table I] The number of attempted rounds is given as '1.1·10^11 signal events' in Sec. II.B and as '1.07×10^11' in Table I; the notation '107364·10^6' in Table I is confusing. Please use a single consistent value and formatting.
  2. [Sec. II.A.3] There are typographical errors: 'associates s the this particular outcome with with' should read 'associates this particular outcome with'; 'contribue' should be 'contribute'; 'non-unital' in Appendix A.3 should probably be 'non-unit' or 'non-unit probability.'
  3. [Appendix B, Eq. (B1)] The blinking envelope function is written as C0 + m·e^{|τ+τ0|/τblink}, which appears to diverge for large |τ|; presumably a negative exponent was intended. Please correct the formula and ensure the fit parameters are consistent with the plot.
  4. [Sec. II.B.1, Fig. 4] The text says the simulation assumes lossless components in Bob's device, while the experiment has roughly 7 dB attenuation; the figure caption should clarify how the experimental data point is placed on the horizontal axis relative to the simulated loss scan.
  5. [Sec. II.A.2] The choice probabilities p_A^Z and p_A^X used in the proof are not reported for the implemented sequence. Since the 10^5-digit sequence may not contain exactly half Z and half X rounds, the actual basis statistics should be stated and checked against the values assumed in the security analysis.

Circularity Check

1 steps flagged

Central security bound is imported from an unverified, co-authored prior preprint (Ref. [1]), making the key-rate calculation load-bearing on a self-citation; otherwise the derivation is not circular.

specific steps
  1. self citation load bearing [Sec. II.B.1 Eq. (2); Appendix A Sec. 2, Lemma 1 (after Eq. A10)]
    "Lemma 1 (Bounds on Phase Error Rate and Single Photon Detections with Passive Optics, Theorem 1 of [1].)... We refer to Ref. [1] for the exact expressions of a, δ and qZ (Eq.'s D40, D41 and E2, respectively)."

    The key length (Eq. 2) is computed from B_Single_{qZ} and B_Error_{a,δ,qZ}, which are exactly the bounds quoted in Lemma 1. Rather than deriving these bounds, the paper cites 'Theorem 1 of [1]' and sends the reader to Ref. [1] for the definitions of a, δ and qZ. Ref. [1] (arXiv:2508.21486) is co-authored by two of the present authors (Z. Wang and D. Tupkary), and the paper ships no machine-checked proof or code to reproduce those expressions. The central security claim thus rests on an unverified self-citation rather than on a self-contained derivation; if Lemma 1 or the a/δ/qZ mapping is wrong, the 2.1579e6-bit key is unsupported.

full rationale

The core computation is an evaluation, not a circular prediction: observed counts, QBER, µ and g^(2)(0) are fed into standard EUR bounds, and the key length is the output; no fitted parameter is renamed as a prediction. The main circularity concern is the import of Lemma 1 from Ref. [1], a same-author preprint whose theorem and parameter expressions are not re-derived or machine-checked, making the proof-of-security claim load-bearing on a self-citation. This is partially circular (score 4) rather than fully so, because the experimental implementation, device characterization, blinking correction, and source-map estimation are independent contributions and the cited Lemma 1 is a general statistical bound, not an equation identical to the paper's data. Separate non-circular correctness risks: (i) the FPGA repeats a pre-compiled public 10^5-quaternary-digit QRNG sequence over 1.07e11 rounds, violating the independent-basis assumption of the source-replacement/EUR proof (Sec. II.A.2 and II.B; Appendix A.1.a); (ii) Appendix A says 'proof in full detail' but omits a,δ,q_Z, leaving the mapping from device uncertainty ranges to the key length unverifiable from this paper. These are omitted-support/assumption-violation issues, not additional circular steps.

Axiom & Free-Parameter Ledger

4 free parameters · 8 axioms · 1 invented entities

The central claim (a 2.16×10^6-bit finite-size secure key under stated device uncertainties) rests on measured device parameters treated as bounded inputs (μ, g^(2)(0), beamsplitter ratio, detector efficiencies, dark counts); on statistical bounds and the a, δ, q_Z mappings delegated to self-cited preprint Ref [1]; and on acknowledged idealizations (perfect polarization states, no light injection, vanishing photon-number coherence via same-group Ref [26]). The g^(2)(0) input itself depends on a 4-parameter blinking-correction fit. The ε_i and pTest values are hand-chosen protocol parameters. No new physical entities are introduced — the multiphoton 'flag states' are a proof device. Net: the paper contributes the experiment and the application of the framework; it is not a self-contained derivation.

free parameters (4)
  • Blinking envelope fit parameters (C0, m, τ0, τblink) = C0=52.2±0.3; m=18.5±3.7; τ0=(-0.90±2.72) ns; τblink=(25.9±6.0) ns
    Four-parameter fit to the raw HBT histogram (Eq. B1, Table III); the corrected g^(2)(0)=0.017 used in the security analysis is obtained by dividing the HBT data by this fitted envelope (Appendix B).
  • g^(2)(0) multiphoton suppression value = 0.017 ± 0.005 (30%) in Table I; ±0.001 (stat.) in Appendix B
    Sets the multiphoton probability p_>1A = ½μ²g^(2)(0) in the source map and drives the Clopper-Pearson bound on n_Z,1A. Treated as a characterized input with uncertainty, but its value depends on the blinking-correction fit, and the two stated uncertainties are not reconciled.
  • Security parameters ε_i = 10^-9 for ε_PNE, ε_a, ε_b, ε_0, ε_AT, ε_PA, ε_EV
    Chosen by hand (Fig. 4 caption); set the overall security parameter (ε_sec ≈ 6×10^-9) but do not affect the functional form of the key rate.
  • Z-basis testing fraction pTest = 1%
    Chosen fraction of Z rounds revealed for e_Z estimation (Fig. 4 caption); trades error-correction cost against testing statistics.
axioms (8)
  • domain assumption Theorem 1 of Ref [1] (quoted as Lemma 1 here): the bounds B_Single and B_Error hold for a passive linear-optical BB84 analyzer with imperfect, bounded detector parameters
    The entire security analysis in Appendix A.2 is a recap of this result; the exact device-to-parameter mappings a, δ, q_Z are cited to Ref [1] (Eqs. D40/D41/E2) and not reproduced. The proof is delegated to a self-cited unreviewed preprint that is neither machine-checked nor accompanied by shipped code here.
  • domain assumption The QD source's emitted state is block-diagonal in Fock space (vanishing photon-number coherence)
    Invoked in Appendix A.1 ('single-mode threshold detectors are blind to photon number coherence...') and claimed for the excitation scheme via self-cited Ref [26] (Sec. II.A.1); required for the source-replacement/QND reduction and for treating multiphoton events as orthogonal flag states.
  • domain assumption Per-round emissions are independent and identically distributed with p_>1A = ½μ²g^(2)(0) (binomial statistics)
    Used in Appendix A.3.b for the Clopper-Pearson bound on n_>1A. The source's measured blinking (τ_blink ≈ 26 ns, Appendix B) means emission statistics are time-varying; the i.i.d. binomial model is asserted without justification for a blinking source.
  • domain assumption Alice's prepared polarization states are exactly the four ideal BB84 states
    Section II.D: 'Polarization states are assumed to be perfect at Alice's output'; the conclusion states source-side imperfections including polarization preparation are not considered. No quantified error margin is fed into the proof.
  • domain assumption Alice's laboratory is isolated from Eve (no Trojan-horse / light-injection attacks)
    Section II.D; the paper explicitly lists Trojan-horse/light-injection attacks as an open problem for SPS-based QKD (Section III).
  • standard math Entropic Uncertainty Relation (Tomamichel–Renner) and the uncertainty-relation security reduction
    External, established result (Refs [11,12]); standard framework in the field.
  • standard math The source-map channel Σ can be absorbed into Eve's channel without compromising security
    Standard source-map argument (Refs [28,41,43]); externally established technique, used in Appendix A.3.a.
  • domain assumption Device characterization ranges (beamsplitter 2.5%, efficiencies 2.5%, dark counts 50%) are valid upper/lower bounds for the entire 20-minute run
    Section II.D; the parameters a, δ, q_Z are computed from these ranges via Ref [1]; drift outside the stated ranges during the run would void the claimed security parameter.
invented entities (1)
  • Orthogonal flag states for multiphoton emission rounds no independent evidence
    purpose: Mathematical device in the security proof: multiphoton rounds are modeled as flagged states so an eavesdropper's PNS attack on those rounds is treated as fully leaked (Appendix A.3.a).
    Not a physical entity — a proof construction (Ref [28], Sec. 4.6.1). No falsifiable handle, and none needed; it adds no physical assumptions.

pith-pipeline@v1.3.0-alltime-deepseek · 17507 in / 36875 out tokens · 356316 ms · 2026-08-01T13:10:25.656516+00:00 · methodology

0 comments
read the original abstract

Quantum key distribution (QKD) allows for provably secure key distribution between two trusted parties. Because the security and performance of QKD protocols rely on devices that behave according to specific assumptions, idealized or inaccurate assumptions about device behavior can introduce security loopholes. Real devices can never be perfectly characterized, and their performance metrics are always subject to certain error margins, which must be accounted for in a rigorous theoretical analysis. Only recently have rigorous finite-size results allowed for imperfect characterizations of devices (where device parameter have uncertainty margins) - an advance yet to be considered in experimental implementations of the BB84 protocol. In this work, we prove the security and analyze the performance of an implementation of the BB84 protocol using single photons generated by a semiconductor quantum dot light source in combination with dynamic polarization-state encoding. We consider the presence of incompletely characterized devices by accounting for imperfections in the single-photon source (in terms of finite g(2)(0)) as well as the receiver (non-ideal beam-splitters, finite detector efficiencies, and dark counts), all with error margins. The resulting protocol implementation shows competitive performance, paving the way towards practical and loop-hole free implementations of QKD.

Figures

Figures reproduced from arXiv: 2607.19204 by Aodh\'an Corrigan, Daniel Vajner, Devashish Tupkary, Haiqiao Ni, Hanqing Liu, Koray Kaymazlar, Lucas Rickert, Martin von Helversen, Shulun Li, Tobias Heindel, Zhichuan Niu, Zhiyao Wang.

Figure 1
Figure 1. Figure 1: FIG. 1. Experimental setup for our BB84 implementation. Alice prepares single photons using a deterministic single photon [PITH_FULL_IMAGE:figures/full_fig_p003_1.png] view at source ↗
Figure 2
Figure 2. Figure 2: FIG. 2. a) Emission spectrum of the QD microcavity device under quasi-resonant (p-shell) excitation. The strongly Purcell [PITH_FULL_IMAGE:figures/full_fig_p003_2.png] view at source ↗
Figure 3
Figure 3. Figure 3: FIG. 3. (a) Example of the employed random sequence for a 200 ns long excerpt containing 16 bits of given voltage level [PITH_FULL_IMAGE:figures/full_fig_p004_3.png] view at source ↗
Figure 4
Figure 4. Figure 4: FIG. 4. Simulated key rate plot for experimental parameters, as well as key rate computed from experimental run. Simulation [PITH_FULL_IMAGE:figures/full_fig_p007_4.png] view at source ↗
Figure 5
Figure 5. Figure 5: FIG. 5. (a): Measured (raw) second order autocorrelation [PITH_FULL_IMAGE:figures/full_fig_p018_5.png] view at source ↗

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.

Reference graph

Works this paper leans on

59 extracted references · 2 canonical work pages

  1. [1]

    Single Photon Generation For the generation of single photons Alice uses a deterministic single-photon source (SPS) based on a pre-selected InAs QD embedded in a hybrid circular Bragg grating cavity featuring pronounced Purcell enhancement [22]. The source emitting at about 920 nm is operated in a cryogenic environment at 4 K and is excited quasi-resonant...

  2. [2]

    Dynamic Polarization Modulation Alice dynamically and randomly prepares the polarization states to be sent to Bob using a customized fiber-coupled EOM controlled by a custom-built arbitrary waveform generator consisting of a field programmable gate array (FPGA) evolution board and a 16-bit digital to analog converter (DAC). The FPGA is fed with a pre-comp...

  3. [3]

    State detection Polarization encoded photons are detected in a four-state polarization analyzer comprised of a 50:50 beamsplitter at the input of the free space channel which steers photons towards either theXorZbasis detectors completely passively. Each basis detection is comprised of a polarizing beamsplitter polarized in the respective basis, followed ...

  4. [4]

    factor out

    Key Rate Performance During the performance of the protocol Alice and Bob generate an array of observed data statistics, which we collectively denote as⃗ nobs. This includes all of the click patterns (including no-clicks) observed during the run of the experiment, which we can sift through to compute the number of conclusive detections in each basis and t...

  5. [5]

    Z. Wang, D. Tupkary, and S. Nahar, Phase error estimation for passive detection setups with imperfections and memory effects (2025), arXiv:2508.21486 [quant-ph]

  6. [6]

    Nahar, D

    S. Nahar, D. Tupkary, and N. Lütkenhaus, Imperfect detectors for adversarial tasks with applications to quantum key distribution (2025), arXiv:2503.06328 [quant-ph]

  7. [7]

    Nahar,A proof-technique-independent framework for detector imperfections in QKD, Ph.D

    S. Nahar,A proof-technique-independent framework for detector imperfections in QKD, Ph.D. thesis, University of Waterloo (2026)

  8. [8]

    Kamin, J

    L. Kamin, J. Burniston, and E. Y. Z. Tan, Rényi security framework against coherent attacks applied to decoy-state qkd (2025), arXiv:2504.12248 [quant-ph]

  9. [9]

    Currás-Lorenzo, M

    G. Currás-Lorenzo, M. Pereira, S. Nahar, and D. Tupkary, Security of quantum key distribution with source and detector imperfections through phase-error estimation (2025), arXiv:2507.03549 [quant-ph]

  10. [10]

    Currás-Lorenzo, M

    G. Currás-Lorenzo, M. Pereira, G. Kato, M. Curty, and K. Tamaki, Security framework for quantum key distribution with imperfect sources, Optica Quantum3, 525 (2025)

  11. [11]

    Currás-Lorenzo, M

    G. Currás-Lorenzo, M. Pereira, K. Tamaki, and M. Curty, Rigorous phase-error-estimation security framework for qkd with correlated sources (2026), arXiv:2601.08417 [quant-ph]

  12. [12]

    F. Xu, X. Ma, Q. Zhang, H.-K. Lo, and J.-W. Pan, Secure quantum key distribution with realistic devices, Reviews of Modern Physics92, 10.1103/revmodphys.92.025002 (2020)

  13. [13]

    Zapatero, A

    V. Zapatero, A. Navarrete, and M. Curty, Implementation security in quantum key distribution, Advanced Quantum Technologies8, 2300380 (2025), https://advanced.onlinelibrary.wiley.com/doi/pdf/10.1002/qute.202300380

  14. [14]

    Li, F.-Y

    J.-X. Li, F.-Y. Lu, Z.-H. Wang, V. Zapatero, M. Curty, S. Wang, Z.-Q. Yin, W. Chen, D.-Y. He, G.-C. Guo, and Z.- F. Han, Quantum key distribution overcoming practical correlated intensity fluctuations, npj Quantum Information11, 10.1038/s41534-025-01059-0 (2025)

  15. [15]

    Tomamichel and R

    M. Tomamichel and R. Renner, Uncertainty relation for smooth entropies, Physical review letters106, 110506 (2011)

  16. [16]

    Tomamichel and A

    M. Tomamichel and A. Leverrier, A largely self-contained and complete security proof for quantum key distribution, Quantum1, 14 (2017). 10

  17. [17]

    Huttner, N

    B. Huttner, N. Imoto, N. Gisin, and T. Mor, Quantum cryptography with coherent states, Physical Review A51, 1863 (1995)

  18. [18]

    Calsamiglia, S

    J. Calsamiglia, S. M. Barnett, and N. Lütkenhaus, Conditional beam-splitting attack on quantum key distribution, Physical Review A65, 10.1103/physreva.65.012312 (2001)

  19. [19]

    Hwang, Quantum key distribution with high loss: toward global secure communication, Physical review letters91, 057901 (2003)

    W.-Y. Hwang, Quantum key distribution with high loss: toward global secure communication, Physical review letters91, 057901 (2003)

  20. [20]

    H.-K. Lo, X. Ma, and K. Chen, Decoy state quantum key distribution, Phys. Rev. Lett.94, 230504 (2005)

  21. [21]

    Wang, Beating the photon-number-splitting attack in practical quantum cryptography, Phys

    X.-B. Wang, Beating the photon-number-splitting attack in practical quantum cryptography, Phys. Rev. Lett.94, 230503 (2005)

  22. [22]

    Ding, Y.-P

    X. Ding, Y.-P. Guo, M.-C. Xu, R.-Z. Liu, G.-Y. Zou, J.-Y. Zhao, Z.-X. Ge, Q.-H. Zhang, H.-L. Liu, L.-J. Wang, M.-C. Chen, H. Wang, Y.-M. He, Y.-H. Huo, C.-Y. Lu, and J.-W. Pan, High-efficiency single-photon source above the loss-tolerant threshold for efficient linear optical quantum computing (2023), arXiv:2311.08347 [quant-ph]

  23. [23]

    N. Tomm, A. Javadi, N. O. Antoniadis, D. Najer, M. C. Löbl, A. R. Korsch, R. Schott, S. R. Valentin, A. D. Wieck, A. Ludwig, and R. J. Warburton, A bright and fast source of coherent single photons, Nature Nanotechnology16, 399–403 (2021)

  24. [24]

    Somaschi, V

    N. Somaschi, V. Giesz, L. De Santis, J. C. Loredo, M. P. Almeida, G. Hornecker, S. L. Portalupi, T. Grange, C. An- tón, J. Demory, C. Gómez, I. Sagnes, N. D. Lanzillotti-Kimura, A. Lemaítre, A. Auffeves, A. G. White, L. Lanco, and P. Senellart, Near-optimal single-photon sources in the solid state, Nature Photonics10, 340–345 (2016)

  25. [25]

    Schweickert, K

    L. Schweickert, K. D. Jöns, K. D. Zeuner, S. F. Covre da Silva, H. Huang, T. Lettner, M. Reindl, J. Zichi, R. Trotta, A. Rastelli, and V. Zwiller, On-demand generation of background-free single photons from a solid-state source, Applied Physics Letters112, 10.1063/1.5020038 (2018)

  26. [26]

    Rickert, D

    L. Rickert, D. A. Vajner, M. von Helversen, J. Schall, S. Rodt, S. Reitzenstein, H. Liu, S. Li, H. Ni, Z. Niu, and T. Hein- del, High purcell enhancement in quantum-dot hybrid circular bragg grating cavities for ghz clock rate generation of indistinguishable photons, ACS Photonics12, 464–475 (2024)

  27. [27]

    Rickert, K

    L. Rickert, K. Żołnacz, D. A. Vajner, M. von Helversen, S. Rodt, S. Reitzenstein, H. Liu, S. Li, H. Ni, P. Wyborski, G. Sęk, A. Musiał, Z. Niu, and T. Heindel, A fiber-pigtailed quantum dot device generating indistinguishable photons at ghz clock-rates, Nanophotonics14, 1795–1808 (2025)

  28. [28]

    J.L.O’Brien,Opticalquantumcomputing,Science318,1567(2007),https://www.science.org/doi/pdf/10.1126/science.1142892

  29. [29]

    Pereira, G

    M. Pereira, G. Currás-Lorenzo, Álvaro Navarrete, A. Mizutani, G. Kato, M. Curty, and K. Tamaki, Modified bb84 quantum key distribution protocol robust to source imperfections (2022), arXiv:2210.11754 [quant-ph]

  30. [30]

    D. A. Vajner, K. Kaymazlar, F. Drauschke, L. Rickert, M. von Helversen, H. Liu, S. Li, H. Ni, Z. Niu, A. Pappa, and T. Heindel, Single-photon advantage in quantum cryptography beyond qkd, Nature Communications17, 2074 (2026)

  31. [31]

    https://qrng.anu.edu.au/,

  32. [32]

    Tupkary, E

    D. Tupkary, E. Y. Z. Tan, S. Nahar, L. Kamin, and N. Lütkenhaus, Qkd security proofs for decoy-state bb84: protocol variations, proof techniques, gaps and limitations (2025), arXiv:2502.10340 [quant-ph]

  33. [33]

    Tupkary, S

    D. Tupkary, S. Nahar, and E. Y. Z. Tan, Authentication in security proofs for quantum key distribution (2026), arXiv:2601.17960 [quant-ph]

  34. [34]

    Tupkary, S

    D. Tupkary, S. Nahar, A. Arqand, E. Y. Z. Tan, and N. Lütkenhaus, A rigorous and complete security proof of decoy-state bb84 quantum key distribution (2026), arXiv:2601.18035 [quant-ph]

  35. [35]

    Zahidy, M

    M. Zahidy, M. T. Mikkelsen, R. Müller, B. Da Lio, M. Krehbiel, Y. Wang, N. Bart, A. D. Wieck, A. Ludwig, M. Galili, et al., Quantum key distribution using deterministic single-photon sources over a field-installed fibre link, npj Quantum Information10, 2 (2024)

  36. [36]

    C. L. Morrison, R. G. Pousa, F. Graffitti, Z. X. Koong, P. Barrow, N. G. Stoltz, D. Bouwmeester, J. Jeffers, D. K. Oi, B. D. Gerardot,et al., Single-emitter quantum key distribution over 175 km of fibre with optimised finite key rates, Nature Communications14, 3573 (2023)

  37. [37]

    J. Yang, Z. Jiang, F. Benthin, J. Hanel, T. Fandrich, R. Joos, S. Bauer, S. Kolatschek, A. Hreibi, E. P. Rugeramigabo,et al., High-rate intercity quantum key distribution with a semiconductor single-photon source, Light: Science & Applications 13, 150 (2024)

  38. [38]

    Tamaki, M

    K. Tamaki, M. Curty, G. Kato, H.-K. Lo, and K. Azuma, Loss-tolerant quantum cryptography with imperfect sources, Physical Review A90, 052314 (2014)

  39. [39]

    Tupkary, S

    D. Tupkary, S. Nahar, P. Sinha, and N. Lütkenhaus, Phase error rate estimation in qkd with imperfect detectors, Quantum 9, 1937 (2025)

  40. [40]

    Dennis,Photodetectors: an introduction to current technology(Springer Science & Business Media, 2012)

    P. Dennis,Photodetectors: an introduction to current technology(Springer Science & Business Media, 2012). 11

  41. [41]

    MizutaniandG.Kato,Securityofround-robindifferential-phase-shiftquantum-key-distributionprotocolwith correlated light sources, Physical Review A104, 062611 (2021)

    A. MizutaniandG.Kato,Securityofround-robindifferential-phase-shiftquantum-key-distributionprotocolwith correlated light sources, Physical Review A104, 062611 (2021)

  42. [42]

    Behrends, L

    R. Behrends, L. Rickert, N. D. Kewitz, M. v. Helversen, P. K. Saha, M. Lach, J. Kaupp, Y. Reum, Tobias-Huber- Loyola, S. Höfling, A. Pfenning, and T. Heindel, Gigahertz-clocked generation of highly indistinguishable photons at c-band wavelengths, arXiv (2026), arXiv:2603.26651 [cond-mat.mes-hall]

  43. [43]

    Ferenczi and N

    A. Ferenczi and N. Lütkenhaus, Symmetries in quantum key distribution and the connection between optimal attacks and optimal cloning, Phys. Rev. A85, 052310 (2012)

  44. [44]

    Tomamichel, C

    M. Tomamichel, C. C. W. Lim, N. Gisin, and R. Renner, Tight finite-key analysis for quantum cryptography, Nature communications3, 634 (2012)

  45. [45]

    Gottesman, H.-K

    D. Gottesman, H.-K. Lo, N. Lütkenhaus, and J. Preskill, Security of quantum key distribution with imperfect devices (2004), arXiv:quant-ph/0212066 [quant-ph]

  46. [46]

    J. C. Loredo, C. Antón, B. Reznychenko, P. Hilaire, A. Harouri, C. Millet, H. Ollivier, N. Somaschi, L. De Santis, A. Lemaître, I. Sagnes, L. Lanco, A. Auffèves, O. Krebs, and P. Senellart, Generation of non-classical light in a photon- number superposition, Nature Photonics13, 803–808 (2019)

  47. [47]

    Nahar, D

    S. Nahar, D. Tupkary, Y. Zhao, N. Lütkenhaus, and E. Y.-Z. Tan, Postselection technique for optical quantum key distribution with improved de finetti reductions, PRX Quantum5, 040315 (2024)

  48. [48]

    C. J. Clopper and E. S. Pearson, The use of confidence or fiducial limits illustrated in the case of the binomial, Biometrika 26, 404 (1934)

  49. [49]

    Szekely,Statistics for the 21st Century: Methodologies for Applications of the Future(CRC Press, 2000)

    G. Szekely,Statistics for the 21st Century: Methodologies for Applications of the Future(CRC Press, 2000). Appendix A: Entropic Uncertainty Relation Security Proof The security of QKD protocols depends on formalizing the idea that an eavesdropper is limited in how much information she can learn about the produced key [28]. To do so, it is necessary to spe...

  50. [50]

    We explain how these are used in proving QKD security

    In Section 1, we begin by specifying the entropic uncertainty relation as well as the source replacement scheme, two integral components to proving security of our QKD implementation. We explain how these are used in proving QKD security

  51. [51]

    [1], which provides statistical bounds on the required quantities for proving security

    In Section 2, we then recap work done in Ref. [1], which provides statistical bounds on the required quantities for proving security. We further specify how these bounds change in the presence of imperfect single photon sources

  52. [52]

    In Section 3, we elaborate on how to compute the needed multiphoton event bounds described in the above subsection by specifying source maps

  53. [53]

    In Section 4, we finally compute the final key rate and security parameters, as well as recap the appendix

  54. [54]

    Source Replacement Schemes and the Entropic Uncertainty Relation a. Source Replacement Scheme In order to prove the security of prepare and measure (P&M) protocols, it is often more convenient to reformulate these as entanglement based protocols via the source replacement scheme [39]. Instead of Alice preparing a state in every round and sending through a...

  55. [55]

    (A5), there are two quantities which must be estimated from the measured protocol quantities, namelyn Z,1 A,1B ande Ph

    Passive Protocol EUR Bounds Clearly, in Eq. (A5), there are two quantities which must be estimated from the measured protocol quantities, namelyn Z,1 A,1B ande Ph. Z,1 A,1B. Statistical bounds must be rigorously proven in the presence of finite size effects, device imperfections and the possibility of receiving more than a single photon in Bob’s detectors...

  56. [56]

    one that always emits single photons

    Imperfect source bounds and source maps Lemma 1 can be easily applied if it is assumed Alice is in possession of a perfect single photon source, i.e. one that always emits single photons. In a practical QKD implementation, Alice does not have access to such a source but instead emits single photons with some non-unital probability, while emitting zero or ...

  57. [57]

    (Lower bound onnZ,1 A) : In order to compute this bound, we first remark thatnZ,1 A =n Z −n Z,>1 A, so the problem can be reformulated as finding a high probability upper bound onnZ,>1 A. We do so in steps, and the first trivial bound is of the formPr[nZ,>1 A ≤n >1A ] = 1, which implies X n>1A Pr[n>1A =n >1A ]Pr[nZ,>1 A ≤n >1A ] = Pr[nZ,>1 A ≤n >1A ] = 1,...

  58. [58]

    Code for this implementation in order to judge the differences in performance is available in the included GitHub repository

    (Upper bounds onn X,1 A,n mc,1A andN obs X,1 A) : Since we cannot make any type of statement on how little, if any, of theXbasis rounds came from multiphoton emissions, we only get a trivial bound of the form Pr[nX,1 A ≤n X ] = 1,(A22) these vacuum emissions directly with other statistical bounds, but these complicate the analysis. Code for this implement...

  59. [59]

    We find that the updated bounds, which are now computable in terms of observed protocol quantities, are Pr nZ,1 A,1B ≤ BSingle qZ nZ −J −1 pU >1A ,n(ε2 Z,1 A ), nmc,1A ∨ ePh

    Combining Bounds and Key Rate Calculation The combinations of the above bounds are trivial via a simple application of union bounds. We find that the updated bounds, which are now computable in terms of observed protocol quantities, are Pr nZ,1 A,1B ≤ BSingle qZ nZ −J −1 pU >1A ,n(ε2 Z,1 A ), nmc,1A ∨ ePh. Z,1 A,1B ≥ BError a,δ,qZ nX , nZ −J −1 pU >1A ,n(...