REVIEW 5 minor 38 references
Discarding the detector clicks that mix neighbouring time bins is enough to restore product (and IID) measurement structure for standard QKD security proofs.
Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →
T0 review · grok-4.5
2026-07-30 21:31 UTC pith:VGFIPVX4
load-bearing objection Clean post-processing fix that restores product/IID Bob POVMs for time-bin QKD without the vacuum-pulse rate hit or Eve restriction.
Enforcing IID structure on time-bin encoded QKD protocols via coarse-graining
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
Core claim
Classical coarse-graining over the detector outcomes that couple neighbouring rounds is sufficient to make Bob’s effective measurement a tensor product across rounds (and IID when the single-round setup is identical each round). The argument needs only two structural conditions: the kept detector channel is round-local, and the coarse-grained output POVM is round-memoryless. For ordinary linear-optical threshold setups those conditions reduce to mode transformations that do not mix kept modes across rounds and to detectors whose memory effects do not cross round boundaries. The construction therefore lets standard security proofs apply to common time-bin receivers without hardware changes or
What carries the argument
Theorem II.3: if the detector channel on the kept detectors is round-local and the coarse-grained output-space POVM is round-memoryless, then the coarse-grained input POVM factors as a tensor product over rounds (and is IID when the single-round pieces are identical). Coarse-graining itself is ordinary classical discarding of the inter-round-sensitive click patterns.
Load-bearing premise
After the inter-round detectors are ignored, the remaining detectors must show no correlations that reach from one protocol round into another; if real afterpulsing or dead-time tails still cross rounds, the product structure fails.
What would settle it
Characterise a real threshold-detector train with the paper’s inter-round delay (or post-click discard rule) and check whether the joint click statistics of kept detectors still factor across rounds; residual cross-round correlations would falsify the round-memoryless premise and block Theorem II.3.
If this is right
- Mach–Zehnder and three-state/COW-style time-bin receivers can be analysed with ordinary product/IID security proofs after classical post-processing alone.
- The extra vacuum pulse used in prior analyses is unnecessary, removing both the 2/3 rate penalty and the assumption that Eve forwards that pulse.
- Post-selection and entropy-accumulation techniques become directly applicable to these interferometric receivers once the kept data are retained.
- The same coarse-graining argument extends to active basis choice and to higher-dimensional multi-bin variants when kept modes stay round-local.
Where Pith is reading between the lines
- Any other interferometric QKD layout whose ‘bad’ detectors are exactly the ones that straddle round boundaries should admit the same classical fix without redesigning the optics.
- Experimental groups can treat inter-round delay (or post-click discard) as a tunable security parameter that trades rate against residual detector memory, rather than as an all-or-nothing hardware constraint.
- Once product structure is free, numerical key-rate SDPs that previously assumed vacuum padding can be re-run on the denser single-round data to quantify the actual rate gain.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper shows that classical coarse-graining of Bob’s detector outcomes—discarding clicks from modes that mix neighbouring time-bin rounds—recovers a multi-round product measurement POVM for common time-bin QKD receivers. Under two explicit conditions (a round-local detector channel on the kept modes, Definition II.1, and a round-memoryless output POVM, Definition II.2), Theorem II.3 proves that the coarse-grained input POVM factorises across rounds and is IID when the single-round setup is repeated. Corollaries II.4–II.5 specialise this to passive and actively switched lossy linear optics via coherent-state overcompleteness. The framework is applied to the Mach–Zehnder interferometer and the three-state/COW-style receiver (§III), removing the extra vacuum pulse used in prior analyses and the associated restriction that Eve must forward that vacuum.
Significance. The result is a clean, load-bearing structural lemma for time-bin QKD security proofs. It lets standard product/IID techniques (postselection, EAT, numerical SDP key rates) apply to interferometric receivers without hardware changes or an extra vacuum slot that costs a d/(d+1) duty-cycle factor and constrains Eve. The derivation is short and standard (adjoint of partial trace plus product channels), the optical conditions are directly checkable by mode inspection, and the paper is explicit about the remaining modelling assumption on detector memory (Remark 1). That combination is useful and publishable even without new numerical key rates.
minor comments (5)
- [Abstract; §I; §III.1] Abstract and §I claim “recovering better key rates” while §III.1 states that key rates are not computed. A brief qualitative comparison (vacuum duty-cycle loss d/(d+1) versus fraction of outer-bin clicks discarded under coarse-graining) would make the performance claim precise without a full SDP.
- [Definition II.2; Remark 1] Definition II.2 and Remark 1 correctly flag cross-round afterpulsing/dead-time as the non-automatic assumption. A sentence pointing to how existing detector-imperfection analyses (e.g. the cited discarding-after-click recipes) compose with the coarse-grained product POVM would help practitioners.
- [§II D.1; Corollary II.4] In Corollary II.4 the appeal to coherent-state overcompleteness is standard but terse. One line recalling that the channel is determined by its action on coherent states (or citing a standard reference) would help non-optics readers follow why mode locality implies channel locality.
- [§III A–B] Figures 1–2 are described in captions but the kept versus discarded modes could be labelled more explicitly in the text of §III A–B (e.g. which physical time slots map to Kj) so the mode-locality check is fully self-contained.
- [§II D; §III; §II A] Typos/style: “V erifying” and “APPLICA TIONS” show stray spaces in headings; “lnatural” in §II A; consistent spelling of Lütkenhaus in the author line and bibliography.
Circularity Check
No circularity: product POVM follows from two explicit structural assumptions by a short adjoint/partial-trace argument, not by construction from the claim.
full rationale
The central result (Theorem II.3) states that if the kept-detector channel is round-local (Def. II.1) and the coarse-grained output POVM is round-memoryless (Def. II.2), then the input-space coarse-grained POVM factors as a tensor product over rounds. The proof is a four-line chain (Eqs. 14–18) using only the definitions of adjoint, partial trace, and the two structural conditions; none of those conditions is defined in terms of the product conclusion. Optical round-locality for kept modes is checked by direct mode inspection (Cor. II.4–II.5; §III A–B), not fitted or smuggled. Round-memoryless detectors are an open modeling assumption (Remark 1), remedied operationally by inter-round delay or post-click discarding, not asserted by self-citation. Citations to prior author work supply background security-proof tools and detector-imperfection context; none is used to force the product structure. There are no fitted parameters renamed as predictions, no uniqueness theorems imported from the authors, and no renaming of a known empirical pattern. The derivation is self-contained against its stated premises.
Axiom & Free-Parameter Ledger
axioms (6)
- standard math Coarse-grained POVM elements on the input equal the adjoint channel applied to coarse-grained output POVM elements: χ_y = Φ†(M_y).
- standard math Adjoint of partial trace over discarded detector spaces is tensoring with identity on those spaces.
- domain assumption Lossy passive linear optics maps coherent states to coherent states; coherent states are overcomplete for operators, so mode-local action on coherent states implies a product channel on all operators.
- domain assumption Threshold detectors exhibit no correlations (dead time, afterpulsing) across protocol rounds after the chosen timing or post-selection.
- domain assumption For kept detectors assigned to round j, output modes depend only on input modes of round j (and, if active, only on Θ_j), not on other rounds.
- domain assumption Active basis-choice random variables Θ_j are mutually independent across rounds when basis choice is active.
invented entities (2)
-
Round-local detector channel (Definition II.1)
independent evidence
-
Round-memoryless detectors (Definition II.2)
independent evidence
read the original abstract
Many security proofs for quantum key distribution (QKD) require Bob's measurement to have a tensor-product structure across protocol rounds, with some techniques requiring the stronger independent-and-identically-distributed (IID) condition. Time-bin encoded protocols often rely on interferometers whose detector outcomes depend on the interference between optical modes from neighbouring rounds, obstructing the direct application of such proofs. We show that classical post-processing of Bob's measurement data --- specifically, discarding the outcomes of detectors sensitive to inter-round coherence --- is sufficient to recover a product measurement positive operator-valued measure (POVM) (which is IID when the same single-round setup is used in every round). Applied to the Mach-Zehnder interferometer and the IID variant of the COW detection setup, this removes the need for the additional vacuum pulse introduced in prior analyses to establish tensor product structure of the measurement POVM, recovering better key rates without placing any restriction on Eve's attack.
Figures
Reference graph
Works this paper leans on
-
[1]
The detector channel Φ from the input Hilbert space to the output Hilbert space: Φ :B(H in)− → B(Kout).(3)
-
[2]
The POVM{N ⃗ x}⃗ x∈{0,1}t ⊂Pos(K out) acting on the output space. Thus, we have Γ⃗ x= Φ†(N⃗ x)∀⃗ x∈ {0,1}t.(4) In general, we will use Greek letters (Γ, χ, µ) to denote POVM elements acting on the input Hilbert space and Latin letters (M,N,S) to denote POVM elements acting on the output Hilbert space. B. Coarse-graining Coarse-grainingover a subset D⊂ [t]...
-
[3]
Given a set K of detector indices that will be kept, we assign each of the kept detectors to a roundj:K= Sn j=1 Kj
Passive linear optical detection setups We first consider passive linear optical detection setups with threshold detectors. Given a set K of detector indices that will be kept, we assign each of the kept detectors to a roundj:K= Sn j=1 Kj. The round-memoryless detector condition is equivalent to the statement that the threshold detectors have no correlati...
-
[5]
for every detector r∈K j, the corresponding output mode does not depend on the input modes of any other round i̸=j. Then the coarse-grained POVM obtained by discarding the outcomes of the detectors not in K factorises across rounds: χ⃗ y= nO j=1 µ(j) ⃗ yj ,(19) where {µ(j) ⃗ yj }⃗ yj is a single-round POVM on Hj. If, in addition, identical mode transforma...
-
[6]
Let K = Sn j=1 Kj be the set of kept detectors, and suppose that in round j an independent random variable Θj is drawn from some distribution
Active basis choice We now extend the above to settings where the linear optical mode transformation in each round depends on a classical random variable, as is the case for detection setups where the measurement basis is chosen based on a classical random variable instead of a passive beam splitter. Let K = Sn j=1 Kj be the set of kept detectors, and sup...
-
[7]
,Θn are mutually independent
the random variablesΘ 1, . . . ,Θn are mutually independent
-
[8]
due to dead time or afterpulsing); and
the threshold detectors exhibit no correlations across rounds (e.g. due to dead time or afterpulsing); and
-
[9]
middle” detections interferee j andl j within the same protocol round. The crossed-out “outer
for every detector r∈K j, the corresponding output mode does not depend on the input modes of any other round i̸=j, nor onΘ i fori̸=j. 6 Then the coarse-grained POVM obtained by discarding the outcomes of the detectors not in K factorises across rounds: χ⃗ y= nO j=1 ¯µ(j) ⃗ yj ,(22) where {µ(j) ⃗ yj (θj)}⃗ yj is the single-round POVM conditional onΘ j = θ...
-
[10]
For example, Ref
QKD key rate analysis After enforcing product structure — and IID structure when the same single-round POVM is used in every round — one can apply standard security-proof techniques. For example, Ref. [ 15] uses the postselection technique [ 5, 6] to reduce the analysis to proving security against IID attacks, and then numerically computes the error rate ...
-
[11]
Cybersecurity in an era with quantum computers: will we be ready?IEEE Security & Privacy, 16(5):38–41, 2018
Michele Mosca. Cybersecurity in an era with quantum computers: will we be ready?IEEE Security & Privacy, 16(5):38–41, 2018
2018
-
[12]
Masato Koashi. Simple security proof of quantum key distribution via uncertainty principle.arXiv preprint quant-ph/0505108, 2005
Pith/arXiv arXiv 2005
-
[13]
M. Koashi. Simple security proof of quantum key distribution based on complementarity.New Journal of Physics, 11(4):045018, April 2009
2009
-
[14]
Uncertainty Relation for Smooth Entropies.Physical Review Letters, 106(11):110506, March 2011
Marco Tomamichel and Renato Renner. Uncertainty Relation for Smooth Entropies.Physical Review Letters, 106(11):110506, March 2011
2011
-
[15]
Matthias Christandl, Robert Koenig, and Renato Renner. Post-selection technique for quantum channels with applications to quantum cryptography.Physical Review Letters, 102(2):020504, January 2009. arXiv:0809.3019 [quant-ph]
Pith/arXiv arXiv 2009
-
[16]
Shlok Nahar, Devashish Tupkary, Yuming Zhao, Norbert L¨ utkenhaus, and Ernest Tan. Postselection technique for optical Quantum Key Distribution with improved de Finetti reductions, March 2024. arXiv:2403.11851 [math-ph, physics:physics, physics:quant-ph]
Pith/arXiv arXiv 2024
-
[17]
Amir Arqand and Ernest Y.-Z. Tan. Marginal-constrained entropy accumulation theorem, April 2025. arXiv:2502.02563 [quant-ph]
Pith/arXiv arXiv 2025
-
[18]
Entropy Accumulation.Communications in Mathematical Physics, 379(3):867–913, November 2020
Fr´ ed´ eric Dupuis, Omar Fawzi, and Renato Renner. Entropy Accumulation.Communications in Mathematical Physics, 379(3):867–913, November 2020
2020
-
[19]
Security of quantum key distribution from generalised entropy accumulation.Nature Communications, 14(1):5272, August 2023
Tony Metger and Renato Renner. Security of quantum key distribution from generalised entropy accumulation.Nature Communications, 14(1):5272, August 2023. Publisher: Nature Publishing Group
2023
-
[20]
Devashish Tupkary, Ernest Y-Z Tan, Shlok Nahar, Lars Kamin, and Norbert L¨ utkenhaus. Qkd security proofs for decoy-state BB84: protocol variations, proof techniques, gaps and limitations.arXiv preprint arXiv:2502.10340, 2025
Pith/arXiv arXiv 2025
-
[21]
product” or “independent
Throughout this paper, “product” or “independent” means that the multi-round POVM elements factor as tensor products over rounds. We reserve “IID” for the stronger case in which thesamesingle-round POVM is used in every round. The postselection technique [5, 6] requires this stronger identical-round assumption
-
[22]
Security of differential phase shift qkd from relativistic principles.Quantum, 9:1611, 2025
Martin Sandfuchs, Marcus Haberland, Venkatesh Vilasini, and Ramona Wolf. Security of differential phase shift qkd from relativistic principles.Quantum, 9:1611, 2025
2025
-
[23]
Differential Phase Shift Quantum Key Distribution.Physical Review Letters, 89(3):037902, June 2002
Kyo Inoue, Edo Waks, and Yoshihisa Yamamoto. Differential Phase Shift Quantum Key Distribution.Physical Review Letters, 89(3):037902, June 2002. Publisher: American Physical Society
2002
-
[24]
Fast and simple one-way quantum key distribution.Applied Physics Letters, 87(19):194108, November 2005
Damien Stucki, Nicolas Brunner, Nicolas Gisin, Valerio Scarani, and Hugo Zbinden. Fast and simple one-way quantum key distribution.Applied Physics Letters, 87(19):194108, November 2005
2005
-
[25]
Emilien Lavie and Charles C.-W. Lim. Improved Coherent One-Way Quantum key Distribution for High-Loss Channels. Physical Review Applied, 18(6):064053, December 2022
2022
-
[26]
Eisenberg, Yaron Bromberg, and Michael Ben-Or
Kfir Sulimany, Guy Pelc, Rom Dudkiewicz, Simcha Korenblit, Hagai S. Eisenberg, Yaron Bromberg, and Michael Ben-Or. High-dimensional coherent one-way quantum key distribution.npj Quantum Information, 11(1):16, Jan 2025
2025
-
[27]
The improvement therefore shrinks as the number of pulses per round grows
This fraction is d/(d + 1), where d is the number of pulses sent per protocol round. The improvement therefore shrinks as the number of pulses per round grows
-
[28]
In that more general setting, one would work with dit strings rather than bit strings
Strictly speaking, our results do not require the detectors to have binary outcomes; it suffices that each detector have a finite number of outcomes. In that more general setting, one would work with dit strings rather than bit strings. For pedagogical clarity, however, we restrict our attention to binary-outcome detectors and therefore use bit strings throughout
-
[29]
If the number of detectors are less than the number of rounds, we would formally require some of these sets Kj to be empty sets. However, for any practically relevant case we would expect that the number of detectors is at least as large as the number of rounds and so we do not comment on this edge case beyond this footnote
-
[30]
As each detector is assigned to a single round, the setsK j are pairwise disjoint
-
[31]
PhD thesis, University of Waterloo, 2026
Shlok Nahar.A proof-technique-independent framework for detector imperfections in QKD. PhD thesis, University of Waterloo, 2026
2026
-
[32]
Phase error rate estimation in qkd with imperfect detectors.Quantum, 9:1937, 2025
Devashish Tupkary, Shlok Nahar, Pulkit Sinha, and Norbert L¨ utkenhaus. Phase error rate estimation in qkd with imperfect detectors.Quantum, 9:1937, 2025. 9
1937
-
[33]
Zhiyao Wang, Devashish Tupkary, and Shlok Nahar. Phase error estimation for passive detection setups with imperfections and memory effects.arXiv preprint arXiv:2508.21486, 2025
arXiv 2025
-
[34]
Secure Quantum Key Distribution over 421 km of Optical Fiber.Physical Review Letters, 121(19):190502, November 2018
Alberto Boaron, Gianluca Boso, Davide Rusca, C´ edric Vulliez, Claire Autebert, Misael Caloz, Matthieu Perrenoud, Ga¨ etan Gras, F´ elix Bussi` eres, Ming-Jun Li, Daniel Nolan, Anthony Martin, and Hugo Zbinden. Secure Quantum Key Distribution over 421 km of Optical Fiber.Physical Review Letters, 121(19):190502, November 2018. Publisher: American Physical Society
2018
-
[35]
Versatile security analysis of measurement-device-independent quantum key distribution.Physical Review A, 99(6):062332, 2019
Ignatius William Primaatmaja, Emilien Lavie, Koon Tong Goh, Chao Wang, and Charles Ci Wen Lim. Versatile security analysis of measurement-device-independent quantum key distribution.Physical Review A, 99(6):062332, 2019
2019
-
[36]
Adam Winick, Norbert L¨ utkenhaus, and Patrick J. Coles. Reliable numerical key rates for quantum key distribution. Quantum, 2:77, July 2018. arXiv:1710.05511 [quant-ph]
Pith/arXiv arXiv 2018
-
[37]
Numerical calculations of the finite key rate for general quantum key distribution protocols.Phys
Ian George, Jie Lin, and Norbert L¨ utkenhaus. Numerical calculations of the finite key rate for general quantum key distribution protocols.Phys. Rev. Res., 3:013274, Mar 2021
2021
-
[38]
Tan, and Norbert L¨ utkenhaus
Devashish Tupkary, Ernest Y.-Z. Tan, and Norbert L¨ utkenhaus. Security proof for variable-length quantum key distribution. Physical Review Research, 6(2):023002, April 2024. Publisher: American Physical Society
2024
-
[39]
Devashish Tupkary, Shlok Nahar, Amir Arqand, Ernest Y-Z Tan, and Norbert L¨ utkenhaus. A rigorous and complete security proof of decoy-state bb84 quantum key distribution.arXiv preprint arXiv:2601.18035, 2026
arXiv 2026
discussion (0)
Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.