{"id":"965ee6dc-8e46-42db-9caf-63a6a79b9b30","arxiv_id":"1908.11372","paper_version":4,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":8.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"This paper derives an SDP-based lower bound on the von Neumann entropy for device-independent QKD, enabling key-rate computations for arbitrary protocols via the NPA hierarchy.","lead":"A new computational framework computes lower bounds on secure key rates for quantum key distribution with untrusted devices, using a hierarchy of semi-definite programs. It extends device-independent security proofs from CHSH-based protocols to arbitrary measurement scenarios and Bell inequalities.","discovery_kind":"new_method","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The unverified Golden–Thompson reduction in Eq. (10) is load-bearing: non-commuting \\(\\tilde L_{xy}\\) leave Eq. (4) ambiguous and the multivariate kernel/ordering must be checked before Theorem 1 is sound.","rationale":"The reader's conditional verdict correctly identifies the deferred proof of the Golden-Thompson reduction as the main risk. I agree that this is the single load-bearing step: every numerical curve and the claim of applicability to arbitrary DI protocols depends on Theorem 1, whose proof is not in the reviewed text. My pass sharpens the concern in two ways. First, Eq. (4) as printed contains a product of noncommuting operator-valued factors with no ordering convention, so the object K is not formally well-defined. Second, the generalized Golden-Thompson inequality in the form used must be the multivariate version for \\(m>2\\) (or applied with care to \\(\\ln\\tau+\\sum_{xy}\\tilde L_{xy}\\)); the weight \\(\\beta(t)\\) and the order of the factors are exactly the details that determine whether the bound holds. These are not merely missing citations; they are mathematical conditions that can be checked directly against [57] and, if violated, would invalidate the central claim. The paper has strengths: the entropy-production identity and the SDP/NPA bounding strategy are standard and plausible, the numerical comparison with known CHSH-based bounds is reassuring, and no internal inconsistency is apparent in the rest of the argument. But because the crucial reduction is deferred and formally ambiguous, the appropriate verdict remains conditional pending a complete, checkable derivation of Theorem 1 and, ideally, released code or data. No change to the reader's verdict is required.","tokens_in":10100,"tokens_out":30173,"duration_ms":283717,"concrete_test":"Independently derive Eq. (10) from [57] for the non-commuting decomposition \\(L=\\sum_{xy}\\tilde L_{xy}\\) with \\(XY=4\\), including the term \\(\\ln\\tau\\): verify whether the generalized Golden-Thompson weight is \\(\\beta(t)=(\\pi/2)(\\cosh\\pi t+1)^{-1}\\) or a different \\(\\beta_m(t)\\), and whether a fixed ordering of the product can be chosen so that the inequality holds. Then recompute the Fig. 3 depolarizing-noise lower bound at q=0.1 with the verified K; if it moves above the known bound of Ref. [1], Theorem 1 is falsified, while exact reproduction of Eq. (4) with the stated beta would resolve the concern.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central claim is Theorem 1: Eq. (3)-(4) give a valid SDP lower bound on H(A0|E). The decisive step is the Methods reduction from Eq. (9)-(10) to Theorem 1, deferred to Supplement [37]. The operators \\(\\tilde L_{xy}=\\sum_{abj}\\lambda_j c^{(j)}_{abxy}P_{a|x}\\otimes P_{b|y}\\) for different (x,y) generally do not commute, because Alice's projectors for different inputs and Bob's for different inputs need not commute. Consequently (i) the product \\(\\prod_{xy}\\sum_{ab}e^{\\kappa_{abxy}P_{a|x}\\otimes P_{b|y}}\\) in Eq. (4) is not a well-defined operator unless an ordering convention is specified; and (ii) replacing \\(e^{(1+it)L/2}\\) by \\(\\prod_{xy}e^{(1+it)\\tilde L_{xy}/2}\\) is not an identity, so the generalized Golden-Thompson inequality must be applied to the multivariate sum \\(\\ln\\tau+\\sum_{xy}\\tilde L_{xy}\\). The main text fixes \\(\\beta(t)=(\\pi/2)(\\cosh\\pi t+1)^{-1}\\) without indicating whether this is the correct weight for the relevant number of terms or how the order enters. If the correct multivariate weight differs or an ordering condition is missing, Eq. (4) can overestimate \\(\\langle K\\rangle\\), breaking the lower bound. Since the numerical results and the claimed universality rest entirely on this reduction, the proof must be supplied and checked.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The manuscript introduces a semi-definite programming framework for lower-bounding the asymptotic secret key rate of QKD protocols with untrusted devices. The central theoretical result, Theorem 1, states that the minimum of H(A0|E) subject to linear constraints <Lj>=lj is lower-bounded by an expression of the form sup_lambda [ sum_j lambda_j l_j - ln sup <K> ], where K is defined in Eq. (4) through a product of exponentials of measurement-projector polynomials and is then bounded using the NPA hierarchy. The authors apply the method to two-input/two-output DIQKD scenarios under depolarizing noise and limited detection efficiency, to a one-sided device-independent six-state protocol, and to the joint entropy H(A0B0|E) relevant for randomness expansion. They report rates that are close to or better than existing CHSH-based bounds.","tokens_in":10330,"tokens_out":7911,"duration_ms":79776,"significance":"If Theorem 1 is correct, the paper solves an important open problem: it provides a general, SDP-computable way to bound the von Neumann entropy directly in device-independent settings, going beyond CHSH-specific qubit reductions and beyond indirect guessing-probability bounds. The method's dual ansatz is a genuine strength: any choice of Lagrange multipliers lambda gives a valid lower bound, with no curve fitting to the data, and the final computation rests on the standard NPA hierarchy. The numerical demonstrations, especially for two-party entropy H(A0B0|E), indicate that the approach can outperform existing techniques. The main weakness is that the decisive proof step is deferred to the Supplement, which is not part of the reviewed manuscript, leaving the central theorem unverifiable from the submitted text.","major_comments":[{"comment":"The load-bearing step from Eq. (10) to Theorem 1 is explicitly deferred: the text states \"By setting Ltilde_xy = ... we obtain (see [37]) Theorem 1\", and the Supplement is not included in the review package. This step is not a routine substitution, because the operators Ltilde_xy for different (x,y) need not commute: Alice's projectors for different inputs, and Bob's projectors for different inputs, need not commute. Consequently the product over xy in Eq. (4) is not a well-defined operator unless an ordering convention is specified, and the scalar weight beta(t)=(pi/2)(cosh(pi*t)+1)^{-1} appears to correspond to the two-term multivariate Golden-Thompson inequality, whereas a two-input/two-output protocol has four (x,y) terms. If the correct multivariate weight or a nontrivial reduction is missing, Eq. (4) can overestimate <K>, which would invalidate the lower bound in Theorem 1. The proof, or at least the exact statement of the multivariate Golden-Thompson inequality used, must be provided in the manuscript or in a Supplement that is part of the reviewed material.","section":"Methods, Eqs. (4), (10) and Theorem 1"},{"comment":"The claim that K is a non-commutative polynomial whose integral can be evaluated in closed form and then bounded via the NPA hierarchy is not substantiated in the main text. The explicit polynomial in the measurement projectors, its degree, the operator ordering, and the NPA level used for the computations in Figs. 3-5 are all absent. Without this information the numerical results cannot be reproduced or independently checked, and the practical scope of the method cannot be assessed. This material should appear in the main text or in a Supplement that is part of the review package.","section":"Methods, Eq. (4) and numerical results"}],"minor_comments":[{"comment":"The phrase \"the the Navascués-Pironio-Acín hierarchy\" contains a duplicated article and should be corrected.","section":"Introduction, first paragraph"},{"comment":"The text \"By Stinepring's theorem\" is a typo for \"Stinespring's theorem\".","section":"Methods, entropy production derivation"},{"comment":"For a computational methods paper, \"available from the corresponding authors upon reasonable request\" is insufficient for reproducibility; please provide the code and data in a public repository.","section":"Data Availability"},{"comment":"The captions do not state the NPA hierarchy level, solver tolerances, or the exact form of the polynomial K used; adding these details would significantly improve reproducibility.","section":"Figs. 3-5"}],"recommendation":"major_revision","confidential_remarks":"The central theorem of the manuscript is not self-contained: the decisive reduction using the generalized Golden-Thompson inequality is deferred to the Supplement. I recommend that the editor require the Supplement to be included in the review materials before a final decision. If the Supplement resolves the operator-ordering and integration-weight issues raised above, the paper is likely to be acceptable after revision."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Colleague,\n\nMy take: this paper deserves a serious referee, but the version we have is not self-contained. The theorem that does the work is proved only in a supplement we cannot see.\n\nWhat is genuinely new: they connect entropy production (via a multivariate Golden–Thompson inequality) to DIQKD and show that the von Neumann entropy H(A0|E) can be lower-bounded by an SDP over the NPA hierarchy. That is a real step forward; previous DI bounds were either qubit-specific (CHSH) or only bounded min-entropy. The trick of choosing the L~xy so the bound becomes a non-commutative polynomial is clever, and the numerical results, while not spectacular, show the method is competitive in regimes that matter. The two-party entropy results for randomness expansion are clearly stronger than existing approaches. The paper is also honest about scaling limitations.\n\nThe soft spots: the main text gives a sketch, but the reduction from Eq. (10) to Eq. (4) is the entire ballgame, and that reduction lives in the supplement. The stress-test worry about non-commuting L~xy does not convince me, because the generalized Golden–Thompson inequality is a multivariate statement and the product order is presumably arbitrary; but without the supplement I cannot confirm the operator ordering and the weight beta(t) are handled correctly. So the issue is not a known flaw; it is a missing proof. Also, no code or data is shipped, so the numerics are not independently reproducible, though a motivated reader could reimplement the method from the description.\n\nThe central argument is plausible and the framework is likely correct. I would send this to peer review; the referee must receive the supplement. The paper is for quantum cryptographers, especially those working on DI protocols beyond CHSH. I'd also bring it to reading group to work through the ansatz, even without the supplement.\n\nRecommendation: engage with it, but require the full proof and ideally a code release.","headline":"A genuinely new SDP framework for DI von Neumann entropy bounds; central proof sits in the missing supplement, so the claim is credible but unverifiable without it.","tokens_in":10953,"tokens_out":2107,"would_cite":true,"duration_ms":21527,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["81P45","81P94","90C22"],"pacs":["03.67.Dd"],"model":"deepseek-v4-flash","headline":"A semidefinite-programming framework computes lower bounds on device-independent QKD key rates from full measurement statistics, without restricting to CHSH.","keywords":["device-independent quantum key distribution","semidefinite programming","NPA hierarchy","von Neumann entropy","entropy production","Golden-Thompson inequality","one-sided device-independent","randomness expansion"],"falsifier":"Take a specific finite-dimensional state and projective measurements that satisfy the constraints in a simple two-input, two-output scenario, compute $H(A_0|E)$ exactly by diagonalizing the conditional states, and compare it with the Theorem 1 lower bound evaluated through the NPA hierarchy at high level. Finding any state for which the claimed lower bound exceeds the exact $H(A_0|E)$ would falsify the central claim; the same test could be applied to the Supplement's derivation by checking whether the operator inequality holds term by term.","tokens_in":9850,"feed_emoji":"🔐","tokens_out":10199,"duration_ms":91511,"temperature":0.7,"pith_summary":"The paper establishes a universal computational method for lower-bounding the asymptotic secret key rate of quantum key distribution with untrusted devices, covering fully device-independent and one-sided device-independent scenarios. The key rate is governed by $H(A_0|E)$, Eve's uncertainty about Alice's raw key; the authors prove that this entropy can be bounded from below by an expression involving only the observed expectation values $\\langle L_j\\rangle = l_j$ and an operator $K$ that is a non-commutative polynomial in the measurement projectors. Because $K$ is such a polynomial, its expectation value can be upper-bounded using the NPA hierarchy of semidefinite programs, turning an intractable optimization over unknown states and measurements into a sequence of computable relaxations. This gives, for the first time in this generality, direct von Neumann entropy bounds from the full input-output distribution of any DIQKD protocol, rather than only from CHSH violations or from min-entropy guesses. The practical payoff is that reliable lower bounds on key rates can now be computed for protocols and noise regimes that were previously out of reach.","feed_headline":"One toolbox computes secure key rates for untrusted-device QKD","feed_subtitle":"Bounds Eve's uncertainty directly from full measurement statistics, beating CHSH-only and guessing-probability approaches.","key_machinery":"The load-bearing mechanism is the entropy-production bound behind Theorem 1: for a channel $T$, the inequality $H(T[\\rho])-H(\\rho) \\ge \\langle L\\rangle_\\rho - \\ln\\langle K\\rangle_\\rho$ holds for any decomposition $L=\\sum_k \\tilde L_k$, with $K = T^*T\\big[\\int_{\\mathbb{R}} dt\\,\\beta(t) \\big|\\prod_k e^{\\frac{1+it}{2}\\tilde L_k}\\big|^2\\big]$ and $\\beta(t)=(\\pi/2)(\\cosh(\\pi t)+1)^{-1}$. The paper's key step is to choose $\\tilde L_{xy} = \\sum_{abj}\\lambda_j c^{(j)}_{abxy} P_{a|x}\\otimes P_{b|y}$ for each pair $(x,y)$, so that the product over $k$ becomes a product over measurement pairs of exponentials of local Bell operators; the resulting $K$ is a non-commutative polynomial in the projectors. That polynomial form is what makes the NPA hierarchy applicable, since the hierarchy relaxes polynomial optimization over projectors to a converging sequence of semidefinite programs. The same identity also explains why the method extends from $H(A_0|E)$ to $H(A_0B_0|E)$: only the pinching channel and the environmental register change, not the underlying operator bound.","core_discovery":"On its own terms, the central result is Theorem 1: for a device-independent scenario, the minimum of $H(A_0|E)$ subject to constraints $\\langle L_j\\rangle_{\\rho_{AB}} = l_j$, with $L_j = \\sum_{abxy} c^{(j)}_{abxy} P_{a|x}\\otimes P_{b|y}$, is lower-bounded by $\\sup_{\\vec\\lambda}\\big[\\sum_j \\lambda_j l_j - \\ln\\big(\\sup_{\\rho_{AB},P} \\langle K\\rangle_{\\rho_{AB}}\\big)\\big]$, where $K$ is the operator displayed in Eq. (4), built from a product of exponentials of the local Bell operators and averaged over a pinching channel $T$. The discovery is that this bound is computable exactly when it is needed most: although $\\langle K\\rangle$ is not directly accessible, $K$ is a non-commutative polynomial in the projectors, so its expectation can be bounded from above by the NPA hierarchy. The optimization over $\\vec\\lambda$ is a supremum, so any choice of $\\vec\\lambda$ gives a valid secure lower bound without solving that outer problem exactly. This converts the non-convex, dimension-unbounded problem of bounding $H(A_0|E)$ into a standard SDP feasibility check, and the same machinery extends to $H(A_0B_0|E)$ and to one-sided device-independent constraints.","pith_inferences":["Beyond the paper, the entropy-production inequality is stated for a general channel $T$, so the same operator bound could be adapted to protocols whose post-processing is not a single projective measurement, such as coherent or continuous-variable schemes with suitable polynomial constraints.","Beyond the paper, the fact that any feasible $\\vec\\lambda$ gives a bound suggests using the right-hand side of Theorem 1 directly as an objective when searching over possible protocols; one could numerically optimize measurement settings against the computed key rate rather than against a Bell parameter.","Beyond the paper, the equality of the one-sided six-state and BB84 rates is one data point; testing the same method across larger sets of uncharacterized measurements would show whether extra measurement settings are generally redundant for one-sided device-independent key rates."],"forward_implications":["Any DIQKD protocol whose statistics are fixed by linear constraints $\\langle L_j\\rangle = l_j$ can in principle have its asymptotic key rate lower-bounded, so protocol design is no longer restricted to CHSH or to binary-input/binary-output Bell inequalities.","Because every choice of $\\vec\\lambda$ yields a valid bound, practitioners can obtain secure certificates without solving the outer supremum.","The same machinery bounds the joint entropy $H(A_0B_0|E)$, improving key rates for device-independent randomness expansion and slightly improving the DIQKD rates in the entropy-accumulation proof.","Combined with the entropy accumulation theorem, the bounds cover finite-size and non-IID effects, so the toolbox yields finite key lengths against general attacks.","In the limited-detection-efficiency scenario the full-distribution bound beats the CHSH-only bound, indicating that maximizing the CHSH value is not always the right experimental target."],"supporting_citations":[{"why":"Provides the CHSH-based bound on $H(A_0|E)$ used as the comparison baseline in Figs. 3 and 4.","marker":"[1]"},{"why":"Entropy accumulation theorem that turns the asymptotic IID bounds into finite-size, general-attack key rates.","marker":"[3]"},{"why":"Prior SDP method for device-dependent QKD key rates, whose entropy-production ansatz this work generalizes to DI and 1sDI settings.","marker":"[10]"},{"why":"Guessing-probability approach for DIQKD that serves as the main alternative general method and is compared against in the numerical results.","marker":"[15]"},{"why":"Navascués-Pironio-Acín hierarchy used to upper-bound $\\langle K\\rangle$ via semidefinite programs.","marker":"[38]"},{"why":"Devetak-Winter formula $r_\\infty = H(A_0|E)-H(A_0|B_0)$ that defines the asymptotic key rate being bounded.","marker":"[41]"},{"why":"Identifies $H(A_0|E)$ with the entropy production $H(T[\\rho])-H(\\rho)$ through Stinespring dilation and the pinching channel.","marker":"[56]"},{"why":"Generalized Golden-Thompson inequality from which the operator $K$ is constructed.","marker":"[57]"}],"fun_headline_variants":["SDP framework computes DIQKD key rates from any Bell inequality","Full statistics yield tighter DIQKD key rates than CHSH-only","Unified SDP bounds secret key rates for any untrusted-device protocol","Compute DIQKD key rates with any Bell inequality via SDP","From full statistics to secure key rates for untrusted QKD"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The proof that the particular choice of operators $\\tilde L_{xy}$ turns the generalized Golden-Thompson inequality into the explicit factored form of $K$ in Eq. (4) is stated in the main text but deferred to the Supplement; if that algebraic reduction fails for some state satisfying the constraints, the claimed lower bound would not follow.","fun_headline_variants_meta":{"raw":{"variants":["SDP framework computes DIQKD key rates from any Bell inequality","Full statistics yield tighter DIQKD key rates than CHSH-only","Unified SDP bounds secret key rates for any untrusted-device protocol","Compute DIQKD key rates with any Bell inequality via SDP","From full statistics to secure key rates for untrusted QKD"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000732,"raw_usage":{"total_tokens":3293,"prompt_tokens":983,"completion_tokens":2310,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":599,"completion_tokens_details":{"reasoning_tokens":2218}},"tokens_in":599,"tokens_out":2310,"duration_ms":13992,"temperature":1.0,"reasoning_tokens":2218,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-14T10:16:58.750884+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Take a specific finite-dimensional state and projective measurements that satisfy the constraints in a simple two-input, two-output scenario, compute $H(A_0|E)$ exactly by diagonalizing the conditional states, and compare it with the Theorem 1 lower bound evaluated through the NPA hierarchy at high level. Finding any state for which the claimed lower bound exceeds the exact $H(A_0|E)$ would falsify the central claim; the same test could be applied to the Supplement's derivation by checking whether the operator inequality holds term by term.","supporting_citations":[{"cited_title":"Pironio, A","cited_arxiv_id":null,"evidence_quote":"Provides the CHSH-based bound on $H(A_0|E)$ used as the comparison baseline in Figs. 3 and 4."},{"cited_title":"Barrett, A","cited_arxiv_id":null,"evidence_quote":"Prior SDP method for device-dependent QKD key rates, whose entropy-production ansatz this work generalizes to DI and 1sDI settings."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Guessing-probability approach for DIQKD that serves as the main alternative general method and is compared against in the numerical results."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Identifies $H(A_0|E)$ with the entropy production $H(T[\\rho])-H(\\rho)$ through Stinespring dilation and the pinching channel."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Generalized Golden-Thompson inequality from which the operator $K$ is constructed."}],"review_version":1}