{"id":"f0e92af9-ecfd-4659-ae9e-79aeba9d86e4","arxiv_id":"1909.02788","paper_version":3,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":4.0,"correctness_risk":"high","formal_verification":"none","parameter_count":2,"one_line_summary":"A mediated semi-quantum key distribution protocol using Bell states lets two classical users share a key through a dishonest third party while needing only Z-basis measurement and Hadamard gates.","lead":"This paper presents a protocol that lets two lightweight quantum users share a secret key through an untrusted third party, using entangled photon pairs sent in one direction. It claims to remove the need for expensive Trojan-horse detectors and to remain secure even though the third party is allowed to cheat.","discovery_kind":"extension","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Key-rate bound assumes Bell-diagonal state with equal QBER in both modes; this is not derived from the collective-attack model and is exactly what makes Q≤0.11 positive.","rationale":"The reader's weakest assumption is correct and is the most load-bearing point. The protocol's claimed advantage depends on the numerical threshold Q ≤ 0.11, which is obtained only after postulating a Bell-diagonal attacked state with identical error rates in the two measurement modes. The manuscript does not derive this state from the general unitary attack of §3.1.1, nor does it justify the equality of the two error rates; in a two-basis protocol these are a priori independent parameters. The robustness proof handles only the no-error limit and cannot be used to bound information leakage at finite QBER. A secondary but related gap is the absence of error correction: the protocol as written has Alice and Bob compare a subset of bits and then run privacy amplification, yet at Q > 0 their raw keys differ; an information-reconciliation step is needed before privacy amplification, and the cited key-rate bound assumes one. I therefore do not see a reason to move the reader's CONDITIONAL verdict. The paper could be made correct by adding a standard reconciliation step and by either deriving the Bell-diagonal reduction from the attack model or using a source-independent security proof such as entropic uncertainty with both error rates estimated. Neither task appears impossible, so rejection is not warranted; the existing conditional assessment stands.","tokens_in":11538,"tokens_out":9146,"duration_ms":103476,"concrete_test":"Take the general collective attack U in Eq. (3) with arbitrary coefficients a_i and probe states e_i. For a fixed observed error rate Q in the I,I mode, numerically maximize TP's Holevo information χ(U:E) subject to the constraint that the H,H mode error rate is also ≤ Q and to Alice/Bob's public-discussion statistics. Compare the maximum to 1−h(Q). If the maximum exceeds this quantity for any Q ≤ 0.11, then Eq. (13) is not a valid lower bound and the threshold is unsafe. A simpler analytical check is to recompute ρ_ABE from Eq. (3) without imposing Eq. (10) and verify whether Bell-diagonality and λ2 = λ3 actually hold; if not, re-derive S(U|E) and the key-rate expression.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central security claim is that the protocol lets two classical participants establish a key with a dishonest TP, with positive key rate for QBER Q ≤ 0.11. This rests on Eq. (10), which postulates that after TP's collective attack the Alice–Bob–TP state is Bell-diagonal, ρ = Σ λ_i |Φ_i⟩⟨Φ_i| ⊗ v_i, and that the QBER is exactly Q in both measurement modes (λ3+λ4=Q in Mode 1, λ2+λ4=Q in Mode 2). Neither statement follows from the attack unitary U in Eq. (3). The robustness analysis in §3.1.1 treats only the zero-error case; it shows an undetected attack leaves no correlation with TP's ancilla, but it gives no quantitative trade-off between QBER and Eve's information for 0 < Q < 0.11. The protocol measures in two mutually unbiased bases (Z after I, X after H), so an attack could in principle induce different error rates in the two modes; the phase-error rate relevant to privacy amplification is not observed directly and need not equal the bit-error rate. If λ2 ≠ λ3, or if the state is not Bell-diagonal, the entropy computation leading to Eq. (13) and the threshold Q ≤ 0.11 is unsupported. In addition, Step 4 specifies only privacy amplification, with no information-reconciliation step, so at nonzero QBER Alice and Bob would not even hold identical raw keys; the key-rate bound from Renner et al. assumes error correction is performed. These gaps are fixable, but as written the claimed security region is not established.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper proposes a mediated semi-quantum key distribution (MSQKD) protocol in which a dishonest third party (TP) prepares Bell states and sends one qubit to each of two classical users, Alice and Bob. Alice and Bob each randomly apply either the identity or the Hadamard operation, measure in the Z basis, discard cases where their operations differ, use part of the remaining bits for public discussion, and perform privacy amplification on the rest. The authors claim that the protocol is secure against collective attacks, fake-photon attacks, and Trojan-horse attacks, and that the one-way communication structure removes the need for Trojan-horse detectors. They derive a key-rate bound and claim a positive secret-key rate for QBER up to Q = 0.11, and they compare the protocol with prior MSQKD schemes in terms of quantum capabilities, qubit efficiency, decoherence time, and detector requirements.","tokens_in":11842,"tokens_out":4335,"duration_ms":45171,"significance":"If the security proof were sound, the protocol would represent a meaningful practical advance in semi-quantum cryptography: it is positioned as the first MSQKD protocol to combine one-way quantum transmission, a dishonest TP, the absence of Trojan-horse detectors, and classical users requiring only Z-basis measurement and Hadamard operations. The paper also provides a clear comparison table with earlier protocols and borrows standard security-proof machinery rather than fitting constants to the desired result, so the approach is not circular. However, the central security claim currently rests on several unproven assumptions, so the significance is conditional on a substantial revision of the proof.","major_comments":[{"comment":"The attacked Alice–Bob–TP state is postulated to be Bell-diagonal with the same QBER Q in both measurement modes. This form is not derived from the collective-attack unitary in Eq. (3), and the key-rate expression in Eq. (13) and the threshold Q ≤ 0.11 depend exactly on this assumption. Since the attack amplitudes α_1 and α_2 can differ, the weights λ_2 and λ_3 need not be equal; the phase-error rate relevant to privacy amplification is not directly observed and need not equal the bit-error rate. The authors should derive the attacked state from their explicit attack model, or state and justify a physical symmetry assumption that forces the Bell-diagonal form with equal error rates.","section":"Section 3.1.2, Eq. (10)"},{"comment":"The protocol specifies only privacy amplification after the public-discussion step. At nonzero QBER, Alice and Bob's raw keys are not identical, so the key-rate bound from Ref. [57] cannot be applied without an explicit information-reconciliation step; without reconciliation the final keys may not even match. The authors must add an error-correction stage, analyze its cost, and include it in the key-rate formula before claiming a positive key rate for Q ≤ 0.11.","section":"Section 2, Step 4"},{"comment":"The robustness analysis treats only the zero-error case, showing that an undetected attack with a1 = a2 = 0 leaves no correlation with TP's ancilla. It does not provide a quantitative trade-off between the induced QBER and the information gained by TP for 0 < Q ≤ 0.11, so the claim that the protocol is secure for nonzero QBER is not supported by this analysis. The proof needs to bound Eve's information as a function of the observed QBER, not merely show that zero disturbance implies zero information.","section":"Section 3.1.1"},{"comment":"The fake-photon analysis considers only specific replacement states, such as |00> and an X-basis pair, and computes a detection probability for one example. It does not provide a complete characterization of TP's possible fake-photon strategies or prove that every such strategy is detected with the claimed probability. Since the protocol's security claim includes robustness against fake-photon attacks, the analysis should cover the full set of states TP could substitute.","section":"Section 3.2"}],"minor_comments":[{"comment":"Equation numbering is duplicated: Eq. (13) is used both for the key-rate bound and later for the qubit-efficiency definition; please renumber.","section":"Section 4 and Section 3.1.2"},{"comment":"Step 4 refers to 'Table 3' for the measurement-result relationship, but the relevant table is Table 4.","section":"Section 2, Step 4"},{"comment":"The text uses 'Model 1' and 'Mode 2' inconsistently; please use 'Mode 1' and 'Mode 2' throughout.","section":"Section 3.1.2"},{"comment":"There is a typo in 'Alice and Bos'; it should be 'Alice and Bob'.","section":"Section 2"},{"comment":"The definition of the attack unitary is not fully specified: the notation alternates between E and U, and the orthogonality and normalization of the ancilla states are stated only in words. Please make the definition precise.","section":"Eq. (3)"},{"comment":"The figures are referenced but not included in the manuscript text; the final submission must include Figures 1–3 and ensure that the key-rate plot is legible.","section":"General"}],"recommendation":"major_revision","confidential_remarks":"The main concern is that the central security claim is not yet established. The protocol idea is interesting and the paper is clearly structured, but the unproven Bell-diagonal form in Eq. (10) and the missing information-reconciliation step are load-bearing. If the authors cannot supply a rigorous derivation of the attacked state from the collective-attack model and include reconciliation in the key-rate analysis, the paper should not be accepted. I recommend major revision rather than immediate rejection because these gaps appear fixable within the paper's scope."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Colleague,\n\nThis paper combines two things from the authors' prior line of work: the lightweight one-way MSQKD design from their honest-TP protocol [26] and the dishonest-TP security setting from Krawec/Liu/Lin. The specific combination—Bell states, classical users limited to Z-basis measurement plus Hadamard, one-way transmission, no Trojan-horse detector, and a dishonest TP—is not in the cited literature, and the comparison table makes that point clearly. The protocol itself is easy to follow, and the idea that one-way transmission removes the Trojan-horse concern is sound. The paper also cites prior work honestly, including Krawec's proof machinery, and does not try to pass off the protocol as more than a practical variant of entanglement-based QKD with reduced user capabilities.\n\nThe central proof, however, has real soft spots. The key-rate bound rests on Eq. (10), which assumes that after the TP's collective attack the Alice–Bob–TP state is Bell-diagonal with QBER Q in both measurement modes. That does not follow from the unitary attack model in Eq. (3), and the robustness analysis only treats the zero-error case. Since the two modes use mutually unbiased bases, an attack could plausibly produce different error rates in the two modes; the phase-error rate is not observed and is not shown to equal the bit-error rate. If λ2 ≠ λ3, the entropy computation leading to Eq. (13) and the Q ≤ 0.11 threshold is unsupported. On top of that, Step 4 of the protocol specifies only privacy amplification, with no error-correction/reconciliation step. At nonzero QBER, Alice and Bob do not even hold identical raw keys, while the Renner et al. bound they cite explicitly assumes error correction is performed. The fake-photon analysis shows detectability but does not bound Eve's information below the QBER threshold, so it reinforces the same gap.\n\nThese are fixable issues, but as written the main security claim—that the TP cannot obtain any information—is not established. I would not call the paper circular or the authors insincere; serious_thinker is yes. It is a modest, clearly-scoped step in the MSQKD subfield, and the proof gaps are exactly the kind a careful referee can push the authors to close.\n\nWho is this for? Researchers working on semi-quantum protocols, especially those tracking the dishonest-TP setting. It deserves a serious referee—send it to review, but with an expectation of major revision on the security proof.\n\nRecommendation: conditional accept or major revision; do not desk reject.","headline":"A plausible lightweight MSQKD variant with a dishonest TP, but the security proof as written has load-bearing gaps around the Bell-diagonal attack assumption and a missing error-correction step.","tokens_in":12398,"tokens_out":671,"would_cite":false,"duration_ms":8292,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["81P94"],"pacs":["03.67.Dd"],"model":"deepseek-v4-flash","headline":"This paper claims that Bell states plus a one-way channel let two classical users share a secret key even when the mediating third party is dishonest and tries to learn it.","keywords":["mediated semi-quantum key distribution","dishonest third party","Bell states","Trojan horse attack","collective attack","quantum key rate","lightweight quantum protocol"],"falsifier":"Compute the full Alice-Bob-third-party state produced by the collective-attack unitary of Eq. (3) acting on the Bell state while Alice and Bob apply identity or Hadamard. If that state is not of the Bell-diagonal form of Eq. (10), or gives different error rates in the two modes, the claimed positive key rate for $Q \\le 0.11$ and the protocol's abort threshold do not follow; an explicit attack producing such a state would settle the question.","tokens_in":11280,"feed_emoji":"🔐","tokens_out":7406,"duration_ms":74079,"temperature":0.7,"pith_summary":"The paper proposes a mediated semi-quantum key distribution protocol in which two classical participants, Alice and Bob, establish a secret key with the help of a third party that is assumed dishonest. The claim is that the third party can perform any attack and still learn nothing about the final key, because any attempt to read the key through ancillary qubits either raises the quantum bit error rate or leaves the key uncorrelated with the third party's probe. The protocol uses Bell states as the quantum resource and requires the classical users only to measure in the Z basis and to apply a Hadamard gate, with one-way transmission from the third party to the users. If the claim holds, this would be the first mediated semi-quantum scheme that combines a dishonest third party with no Trojan-horse detector and lightweight classical hardware.","feed_headline":"Classical users share a key while their quantum helper cheats","feed_subtitle":"Users need only a Z-basis measurement and a Hadamard gate, and the one-way channel removes the Trojan-horse defense cost","key_machinery":"The central object is the Bell state $|\\Phi^+\\rangle = (|00\\rangle + |11\\rangle)/\\sqrt{2}$ together with each user's choice of the identity operator $I$ or the Hadamard gate $H$. When both classical parties apply the same operator and then measure in the Z basis, their outcomes are perfectly correlated and pure-random; when they apply different operators, the outcomes are uncorrelated and are discarded. This relation turns one shared Bell state into one raw key bit, and the one-way third-party-to-users channel, with no return path, is what blocks Trojan-horse photons.","core_discovery":"By sending one qubit of a Bell state to each classical party and having each party independently decide to apply the identity or Hadamard before a Z-basis measurement, the protocol creates pure-random correlated bits whenever both parties choose the same operation, while opposite operations produce uncorrelated results and are discarded. The security claim is that a dishonest third party, even with arbitrary collective attacks, cannot obtain information about the raw key without being detected: the robustness analysis shows that passing the public-discussion check forces the third party's probe states to coincide, and the key-rate bound, computed under a Bell-diagonal attack model, is positive for a quantum bit error rate up to $Q = 0.11$. The paper further claims immunity to fake-photon attacks by the third party and, because transmission is one-way, immunity to Trojan-horse attacks without equipping the classical users with detectors.","pith_inferences":["The paper's positive key rate rests on assuming the attacked state has the Bell-diagonal form of Eq. (10); deriving the actual state from the unitary attack of Eq. (3) would determine whether the 11 percent error-rate threshold is real or an artifact of the assumption.","Because the security proof treats the attack as collective, an extension to coherent attacks across rounds would test whether the dishonest-third-party claim survives the strongest allowed strategies.","The same identity-or-Hadamard correlation on Bell states could be repurposed for multi-party group-key distribution, which the paper names as future work.","An experimental demonstration with two classical users and a simulated cheating third party would be the natural test; a useful benchmark is whether the observed error rate stays below the predicted threshold."],"forward_implications":["Classical participants can implement the protocol with only a Z-basis measurement and a Hadamard gate, both of which have been demonstrated in optical and quantum-computer experiments.","Because qubits travel only from the third party to the users, the users need no photon-number splitter or wavelength filter against Trojan-horse attacks, and the time qubits must be maintained against decoherence is roughly halved relative to two-way mediated protocols.","The protocol has a qubit efficiency of $1/8$, matching the best of the compared mediated semi-quantum schemes while allowing a dishonest third party.","A third party that substitutes fake photon pairs can be detected: any mismatch in the expected correlation appears in public discussion, and the detection probability approaches 1 as the number of check bits grows.","The key-rate bound supplies the abort threshold: the participants terminate the protocol when the public-discussion error rate exceeds the value at which the secret-key rate is no longer positive."],"supporting_citations":[{"why":"Supplies the design concept of using entangled states without a Bell measurement, which the authors say they follow.","marker":"[5]"},{"why":"Defines the mediated semi-quantum setting with a dishonest third party and is the baseline this protocol improves.","marker":"[21]"},{"why":"An entanglement-swapping mediated protocol used as a comparison baseline for efficiency and hardware requirements.","marker":"[24]"},{"why":"A single-photon mediated protocol used as a comparison baseline for hardware and Trojan-horse requirements.","marker":"[25]"},{"why":"The lightweight one-way mediated protocol that assumed an honest third party, the gap this paper aims to close.","marker":"[26]"},{"why":"Provides the information-theoretic secret-key-rate bound formula that the security proof applies.","marker":"[57]"},{"why":"Supplies the BB84-style evaluation method for the two measurement modes used in the key-rate calculation.","marker":"[58]"},{"why":"Defines Trojan-horse attacks; the one-way design's immunity claim is measured against these attacks.","marker":"[59, 60]"}],"fun_headline_variants":["Bell states let classical users outsmart a deceitful mediator","No detectors, cheating mediator: still a secure key?","Key sharing with a cheating quantum assistant and no extra gear","Two quantum tricks suffice when the mediator is dishonest","Classical parties, dishonest TP, Bell states yield key"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The key-rate calculation assumes that after the third party attacks, the joint state of everyone has a specific symmetrical form whose error rate is the same in both measurement modes, but the paper never derives that form from the attack it models.","fun_headline_variants_meta":{"raw":{"variants":["Bell states let classical users outsmart a deceitful mediator","No detectors, cheating mediator: still a secure key?","Key sharing with a cheating quantum assistant and no extra gear","Two quantum tricks suffice when the mediator is dishonest","Classical parties, dishonest TP, Bell states yield key"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.001083,"raw_usage":{"total_tokens":4504,"prompt_tokens":895,"completion_tokens":3609,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":511,"completion_tokens_details":{"reasoning_tokens":3530}},"tokens_in":511,"tokens_out":3609,"duration_ms":24328,"temperature":1.0,"reasoning_tokens":3530,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-14T04:41:55.259865+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Compute the full Alice-Bob-third-party state produced by the collective-attack unitary of Eq. (3) acting on the Bell state while Alice and Bob apply identity or Hadamard. If that state is not of the Bell-diagonal form of Eq. (10), or gives different error rates in the two modes, the claimed positive key rate for $Q \\le 0.11$ and the protocol's abort threshold do not follow; an explicit attack producing such a state would settle the question.","supporting_citations":[{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Supplies the design concept of using entangled states without a Bell measurement, which the authors say they follow."},{"cited_title":"Quantum Inf","cited_arxiv_id":null,"evidence_quote":"Defines the mediated semi-quantum setting with a dishonest third party and is the baseline this protocol improves."},{"cited_title":"H., Zhang, S.: Semiquantum key distribution with secure delegated quantum computation","cited_arxiv_id":null,"evidence_quote":"An entanglement-swapping mediated protocol used as a comparison baseline for efficiency and hardware requirements."},{"cited_title":"Annalen der Physik 530(4), 1700206 (2018)","cited_arxiv_id":null,"evidence_quote":"A single-photon mediated protocol used as a comparison baseline for hardware and Trojan-horse requirements."},{"cited_title":"Annalen der Physik 531(8), 1800347 (2019)","cited_arxiv_id":null,"evidence_quote":"The lightweight one-way mediated protocol that assumed an honest third party, the gap this paper aims to close."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Provides the information-theoretic secret-key-rate bound formula that the security proof applies."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Supplies the BB84-style evaluation method for the two measurement modes used in the key-rate calculation."}],"review_version":1}