{"id":"3597d815-8f21-48fa-819b-e028afdecbb3","arxiv_id":"1908.01780","paper_version":4,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":7.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":3,"one_line_summary":"A QKD protocol lets two fully classical users establish a secure key using only detection or reflection of a single photon supplied by an untrusted quantum server, with a finite-key security proof and a proof-of-principle experiment.","lead":"This paper demonstrates a quantum key distribution protocol in which the two users only need to detect or reflect single photons, while an untrusted server supplies a quantum superposed state and performs the measurement. The authors provide a finite-key security proof with imperfect devices and report a proof-of-principle experiment with a positive expected key rate after millions of rounds.","discovery_kind":"new_method","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Security proof truncates the source to at most two photons without bounding higher-order terms; measured source statistics deviate from the assumed model, so the finite-key claim is not established for the actual implementation.","rationale":"The reader's conditional verdict rests on exactly this gap: the security proof truncates the photon-number space at two, while the measured source statistics deviate from the assumed model and the verification does not certify a bound on higher-order emissions. I agree that this is the most load-bearing concern. For the central claim to hold, the finite-key security statement must cover all states the untrusted server can send that are consistent with the users' verification checks. The current proof instead removes the k > 2 subspace by fiat, calling it negligible, and the experimental verification cannot rule out adversarial or even benign occupation of that subspace. The reported p2 = 0.12 versus the Poisson expectation of 0.043 makes the assumption particularly fragile, since it shows the source is not well characterized by the simple model used in the proof. I am not claiming the protocol is insecure; the concern is that the proof, as written, does not establish the claimed security for the demonstrated implementation. The paper does provide real experimental data and a detailed algebraic security analysis, but no machine-checked proof or independent formal verification, so the missing higher-order analysis is not compensated elsewhere. The appropriate response is to require the authors to either extend the proof to cover k >= 3 emissions or provide a measured, verified bound showing such emissions are negligible at the target security level. Since this matches the reader's conditional verdict, no change to that verdict is needed.","tokens_in":27306,"tokens_out":11892,"duration_ms":141535,"concrete_test":"Extend the security analysis to include photon-number terms with a+b = 3 in Eqs. E.2-E.8, and recompute the key rate r(N) under the measured p0, p1, p2 and a worst-case p3 consistent with an independent photon-number-resolving characterization of the source (or with p3 = 1 - p0 - p1 - p2 if the stated normalization is not enforced). Check whether r remains positive at N = 4.9e6 rounds. If it does not, or if the verification equations in E.3 cannot be used to bound p3, the finite-key security claim is unsupported for the source actually used.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central claim requires the security proof to cover the realistic source actually used. Section E.1 explicitly restricts the analysis, stating: 'In our particular implementation, the probability to emit higher numbers of photons is considered negligible and therefore not included in the analysis, i.e., p0 + p1 + p2 ≈ 1.' The model in Eqs. E.2-E.8 then contains only states with a+b <= 2, and the verification procedure in E.3 estimates p0, p1, p2 using expressions, such as Eqs. E.38-E.41, that themselves assume at most two photons. But the reported measured values are p0 = 0.72, p1 = 0.16, p2 = 0.12, whereas a Poisson source with the stated mean 0.35 would give p2 = 0.043. The source therefore deviates strongly from the assumed statistics, and no bound on emissions of three or more photons is provided. Because the server is untrusted and may choose the emitted state, any non-negligible weight on F_k^f with k > 2 lies outside the security proof. A malicious or imperfect source producing such terms could create '1' announcements not covered by the computed S(A|C), so the finite-key rate from Eq. C.1 is not a proven lower bound for the implemented experiment.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The manuscript reports an experimental demonstration and security analysis of a QKD protocol in which Alice and Bob are fully classical users: they only choose to detect or reflect a photon sent by an untrusted server, and they extract a raw key from rounds in which the server announces outcome \"1\" while neither user detects a photon. The paper provides a finite-key security analysis based on the Scarani-Renner bound in Eq. (C.1) and a Krawec-style conditional-entropy bound, applies it to data from about 10^5 experimental rounds, and reports a positive secret key rate for sufficiently large N, becoming positive after about 4.9 x 10^6 rounds in the implemented configuration. Both direct and indirect parameter-estimation procedures are described, with measured values p_key = 1.55(3) x 10^-2 and p_err = 7.5(8) x 10^-4 per round.","tokens_in":27591,"tokens_out":8919,"duration_ms":97881,"significance":"If the security analysis is accepted, the work is a valuable step in reducing the quantum requirements for QKD users: it demonstrates experimentally that two parties who perform only detection/reflection operations can establish a key with the help of an untrusted quantum server, and it attempts a finite-key security treatment under imperfect devices. The manuscript is transparent about its model, gives detailed derivations of the entropy bound and parameter-estimation formulas, presents two estimation methods, and reports uncertainties on the measured quantities. These are genuine strengths. However, the central claim that information-theoretic security is proven for the actual implemented source is not yet supported, because the security analysis excludes higher-order photon-number terms without bounding them, and the finite-key confidence interval used in the rate calculation is assumed rather than derived from the sample size.","major_comments":[{"comment":"The security proof is restricted to source states with at most two photons, but the implemented source is not shown to satisfy this. Section E.1 states that 'the probability to emit higher numbers of photons is considered negligible and therefore not included in the analysis, i.e., p0 + p1 + p2 ≈ 1', and the Fock-space decomposition in Section C explicitly separates F^f_k for k > 2 from the analyzed subspace. Yet the verification procedure in Section E.3 reports p0 = 0.72, p1 = 0.16, p2 = 0.12 for a source with average 0.35 photons per round, whereas Poisson statistics would give p2 = 0.043; no bound on p3 or on higher-order terms is provided. Because the server is untrusted, any non-negligible weight on states with more than two photons lies outside the security analysis, and the estimators in Eqs. (E.38)-(E.41) explicitly assume at most two photons. As written, Eq. (C.1) cannot be read as a proven lower bound for the implemented source.","section":"E.1 / E.3 / Section C"},{"comment":"The finite-key parameter-estimation step is not justified. The text sets epsilon_PE = 10^-11 and delta = 10^-4 'given our experimental errors', with mu = 1620 sacrificed key rounds, but no concentration bound is used to relate delta to mu and epsilon_PE. For example, a Hoeffding bound would require on the order of 10^9 samples to achieve delta = 10^-4 at confidence level 1 - 10^-11. Without a derivation of delta from the sample size, the confidence interval entering the minimization in Eq. (C.1) is an unquantified free parameter, and the finite-key security level claimed for the plotted rates is not established.","section":"E.2.1 / Eqs. (C.1)-(C.2)"}],"minor_comments":[{"comment":"The text repeatedly uses 'semi column' where 'semicolon' is intended; please correct these occurrences.","section":"Throughout"},{"comment":"The introduction contains the typographical artifact '´ınformation-theoretic' in the first paragraph; this should be cleaned up.","section":"Abstract/Introduction"},{"comment":"In the displayed formula for p_{1,1}, the final term appears as p(D_c D'_c, R ; 1), but by symmetry it should presumably be p(R, D_c D'_c ; 1); please check and correct the labeling.","section":"E.2.1, Eq. (E.28)"},{"comment":"The text says 'the amount of keys wasted' where 'the number of key bits' is meant; also, the figure captions should state explicitly that r is the secret key rate per round.","section":"E.2.1 / Figure 5"},{"comment":"The phrase 'server's ancilla system by C, spanned by the Hilbert space H_C' is imprecise; it should read that the ancilla states belong to H_C.","section":"Section C"}],"recommendation":"major_revision","confidential_remarks":null},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"The paper delivers a genuinely new protocol. For the first time, both users are fully classical – they don't prepare states, just detect or reflect – and the paper provides a finite-key security proof that explicitly accounts for detection efficiency and multi-photon emission. The experimental implementation is honest proof-of-principle work: 10^5 rounds, raw key probabilities consistent with the model, and a clear extrapolation showing positive secret key rate after roughly 4.9×10^6 rounds. The security analysis is substantial and the lower-bound computation is careful, using the standard finitary framework from Scarani–Renner and an entropy bound from one of the authors that is being applied, not fitted to the target result; I don't see a circularity problem.\n\nSoft spots are real but not equal in size. The bigger one is the photon-number truncation. Section E.1 restricts the Fock space to at most two photons, with p0+p1+p2≈1, and the verification in E.3 estimates p0,p1,p2 using two-photon expressions. But the measured p2=0.12 deviates strongly from the Poisson value 0.043, and the paper does not bound emissions of three or more photons. Since the server is untrusted and the source sits in the server's lab, that is not a cosmetic omission: the security proof does not cover the actual implementation unless a higher-order bound is proven. The claim of security under realistic imperfect devices is therefore too strong as written. The protocol is still secure for a source that is proven to emit at most two photons, which is a meaningful idealization, but the finite-key claim for this experiment is not established.\n\nSmaller issue: the confidence interval δ=10^-4 is simply asserted, not derived from the sample size and ε_PE. That is a minor gap in the finite-key formalism, likely fixable.\n\nWho gets value? Anyone working on semi-quantum or server-mediated QKD. The protocol concept is likely to be influential, and the analysis offers a template for finite-key bounds in this setting. I would take it to reading group and would accept it for peer review: the gaps are fixable and the core idea is worth refereeing. My own verdict would be conditional acceptance, not rejection.","headline":"A genuinely new fully-classical-user QKD protocol with a serious finite-key analysis; the proof's truncation to ≤2 photons is not matched by the measured source statistics, so the realistic-security claim overreaches.","tokens_in":28064,"tokens_out":2479,"would_cite":true,"duration_ms":26191,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":["03.67.Dd"],"model":"deepseek-v4-flash","headline":"Fully classical users, with no quantum operations of their own, can exchange a provably secure quantum key by detecting or reflecting a single photon sent by an untrusted server.","keywords":["quantum key distribution","semi-quantum key distribution","classical users","interaction-free measurement","finite-key security","untrusted quantum server","single-photon interference","experimental quantum cryptography"],"falsifier":"Measure the heralded source’s photon-number distribution at the protocol’s operating power with a number-resolving detector, then recompute the finite-key rate with the measured probability of three or more photons per round included; the observed $p_2=0.12$ already deviates from the Poisson value $p_2=0.043$, so a non-negligible higher-order term would directly test whether the $p_0+p_1+p_2\\approx 1$ truncation supports the claimed security.","tokens_in":27137,"feed_emoji":"🔐","tokens_out":10301,"duration_ms":93390,"temperature":0.7,"pith_summary":"The paper’s central claim is that quantum key distribution does not require quantum users: two fully classical parties can exchange an information-theoretically secure key. The protocol delegates all quantum work to an untrusted server, which sends a single photon in a superposition of the two users’ locations; each user’s only actions are to detect or reflect the photon. A click at the server’s $D_1$ detector, enabled by interaction-free measurement, establishes one raw key bit, with no sifting step. The paper proves finite-key security under realistic device conditions—imperfect detectors, lossy channels, and a source emitting zero, one, or two photons per round—and reports a proof-of-principle experiment whose key rate turns positive after about $4.9\\times 10^6$ rounds. If the claim holds, quantum hardware can move entirely out of the users’ hands, which would make QKD practical for classically equipped endpoints.","feed_headline":"Secure quantum key exchange works for fully classical users","feed_subtitle":"An untrusted server supplies a superposed photon; users only detect or reflect, and finite-key security is proven.","key_machinery":"The load-bearing mechanism is interaction-free measurement on a single photon in superposition. The server creates $\\frac{1}{\\sqrt{2}}(|A\\rangle+|B\\rangle)$ and later recombines reflected photons at a balanced beam splitter; each user’s two classical actions are to reflect the photon or send it to a local detector. The crucial step is that when one user detects and finds nothing, the photon’s location is inferred without absorbing it, which suppresses single-photon interference and lets the “forbidden” detector $D_1$ click, thereby encoding the other user’s action as a key bit. The security argument is carried by a conditional-entropy bound $S(A|C)$—how much uncertainty the adversary, including a dishonest server, has about Alice’s bit—computed from the post-selected state describing Alice’s and Bob’s apparatuses, the server’s announced messages, and the adversary’s ancilla, together with a finite-key formula that turns raw-key length, error-correction leakage, and privacy-amplification penalties into a secret key rate.","core_discovery":"On its own terms, the central discovery is that a shared secret key can be produced by parties who never prepare, manipulate, or measure a quantum state. The server sends a single photon in the state $\\frac{1}{\\sqrt{2}}(|A\\rangle+|B\\rangle)$; Alice and Bob independently choose detect ($D$) or reflect ($R$). When both reflect, single-photon interference sends the photon only to detector $D_0$; when exactly one user detects and sees nothing, the interaction-free measurement collapses the photon onto the other user’s location, making $D_0$ and $D_1$ equally likely, so a click at $D_1$ reveals the other user’s action and fixes the key bit. The practical analysis models a source emitting vacuum, one, or two non-simultaneous photons with probabilities $p_0$, $p_1$, $p_2$, incorporates measured detection efficiencies near 58%, and uses a finite-key conditional-entropy bound to show that the secret key rate is positive after roughly $4.9\\times 10^6$ rounds for the implemented losses.","pith_inferences":["Beyond the paper: replacing the at-most-two-photons truncation with a full bound on higher-order emissions—for example via a decoy-state-style analysis—would make the claimed realistic-source security robust to the measured deviation of $p_2$ from its Poisson value.","Beyond the paper: the architecture suggests a network model in which quantum capability exists only in infrastructure nodes and end users are classical optical terminals; testing this over deployed fiber or free-space links is a concrete next step.","Beyond the paper: because no authenticated channel is used during raw-key generation, the protocol may require fewer authenticated-communication assumptions than standard sifting-based QKD; quantifying this saving would be a useful direct comparison.","Beyond the paper: the entropy-bound method is not tied to the folded interferometer, so applying it to counterfactual and two-way single-photon schemes, as the paper itself suggests, is a direct test of the method’s scope."],"forward_implications":["A QKD user’s quantum hardware reduces to a switch that either reflects a photon or routes it to a local detector; no state preparation, multi-basis measurement, or quantum memory is needed.","The security proof is finite-key and includes imperfect sources and detectors, so the claimed security does not require asymptotic idealizations.","Because the server is untrusted and may lie about its measurement results, the same analysis bounds both an eavesdropper and a dishonest server.","Raw-key generation happens without a sifting stage, since the server’s $D_1$ announcement itself determines the bit value and reduces classical communication overhead.","The finite-key security analysis transfers directly to other single-photon protocols, including counterfactual quantum cryptography and two-way communication with one photon."],"supporting_citations":[{"why":"Defines the original QKD task and the quantum state-preparation and measurement requirements that this protocol removes.","marker":"[1]"},{"why":"Introduces the semi-quantum setting with one classical user, the setting this work extends to fully classical users.","marker":"[6]"},{"why":"Shows a mediated protocol with a third party in which users still need quantum resources; this work removes that requirement.","marker":"[10]"},{"why":"Supplies the interaction-free measurement effect used to turn a non-detection into a raw key bit.","marker":"[15]"},{"why":"Provides the practical interaction-free measurement scheme behind the folded interferometer.","marker":"[16]"},{"why":"Gives the finite-key security criterion and key-rate formula used to compute the secret key rate.","marker":"[32]"},{"why":"Provides the conditional-entropy bound on the adversary’s uncertainty about Alice’s key bit.","marker":"[33]"}],"fun_headline_variants":["Classical users share secure keys via interaction-free quantum tricks","Quantum key without quantum users: experiment shows it works","Secure keys for classical users: untrusted server does quantum work","Classical clients, secure key: interaction-free measurement proven","No quantum gear needed: classical users share secure keys"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The security analysis assumes the photon source emits at most two photons per round and treats three-or-more-photon emission as negligible; if that probability is not negligible for the actual source, the proven finite-key security may not cover the real implementation.","fun_headline_variants_meta":{"raw":{"variants":["Classical users share secure keys via interaction-free quantum tricks","Quantum key without quantum users: experiment shows it works","Secure keys for classical users: untrusted server does quantum work","Classical clients, secure key: interaction-free measurement proven","No quantum gear needed: classical users share secure keys"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000601,"raw_usage":{"total_tokens":2827,"prompt_tokens":982,"completion_tokens":1845,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":598,"completion_tokens_details":{"reasoning_tokens":1765}},"tokens_in":598,"tokens_out":1845,"duration_ms":12902,"temperature":1.0,"reasoning_tokens":1765,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-14T15:04:33.894670+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Measure the heralded source’s photon-number distribution at the protocol’s operating power with a number-resolving detector, then recompute the finite-key rate with the measured probability of three or more photons per round included; the observed $p_2=0.12$ already deviates from the Poisson value $p_2=0.043$, so a non-negligible higher-order term would directly test whether the $p_0+p_1+p_2\\approx 1$ truncation supports the claimed security.","supporting_citations":[{"cited_title":"Bennett and Gilles Brassard","cited_arxiv_id":null,"evidence_quote":"Defines the original QKD task and the quantum state-preparation and measurement requirements that this protocol removes."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Shows a mediated protocol with a third party in which users still need quantum resources; this work removes that requirement."},{"cited_title":"Elitzur and Lev Vaidman","cited_arxiv_id":null,"evidence_quote":"Supplies the interaction-free measurement effect used to turn a non-detection into a raw key bit."},{"cited_title":"Kasevich","cited_arxiv_id":null,"evidence_quote":"Provides the practical interaction-free measurement scheme behind the folded interferometer."},{"cited_title":"Quantum cryptography with ﬁnite resources: Uncondi- tional security bound for discrete-variable protocols with one-way postprocessing","cited_arxiv_id":null,"evidence_quote":"Gives the finite-key security criterion and key-rate formula used to compute the secret key rate."},{"cited_title":"horizontal","cited_arxiv_id":null,"evidence_quote":"Provides the conditional-entropy bound on the adversary’s uncertainty about Alice’s key bit."}],"review_version":1}