{"id":"2088b6a5-a3e2-4174-b981-f9a67ce3d0aa","arxiv_id":"2412.06325","paper_version":1,"verdict":"REJECT","confidence":"MODERATE","novelty_score":5.0,"correctness_risk":"high","formal_verification":"none","parameter_count":3,"one_line_summary":"Q-PnV adapts the classical PoV/PnV consensus for consortium blockchains into a quantum protocol that combines quantum voting, QKD identity authentication, QRNG-based leader selection, and hypergraph-state entanglement.","lead":"This paper proposes Q-PnV, a quantum version of the Proof-of-Vote consortium blockchain consensus, using quantum voting, quantum signatures, and quantum random number generators. It then links Q-PnV with a weighted-hypergraph quantum blockchain to argue that consortium blockchains can resist future quantum attacks.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The protocol's security claim assumes the rotating bookkeeper is an honest preparer of the quantum voting states; Section III.C gives no adversary model or security bound for a malicious bookkeeper, so the Section V claim that attackers cannot interfere with voting is unsupported even if the…","rationale":"The reader correctly identifies the practical quantum-network premise as load-bearing for deployment. My concern is different and more internal: even granting that premise, the security claim breaks down if the rotating bookkeeper is adversarial, because that node prepares the very quantum states on which the voting security rests. PoV's security model does not assume the current bookkeeper is honest (Section II.A.2 states only that one honest bookkeeper is needed for seamless operation), but Q-PnV silently upgrades the rotating bookkeeper to a trusted dealer. Section V provides only qualitative assertions, with no adversary model, no security parameter analysis, and no simulation; the conclusion explicitly says the scheme cannot yet be experimented with or simulated. This is not a disagreement with external consensus, but an internal gap: the protocol as written cannot substantiate its headline claims. The proposed simulation test would settle whether the trust assumption can be repaired or whether the protocol needs a different state-preparation arrangement (e.g., distributed or verifiable preparation). Since this concern reinforces the reader's REJECT verdict rather than changing it, I mark the verdict unchanged.","tokens_in":13917,"tokens_out":11722,"duration_ms":123485,"concrete_test":"Simulate (e.g., with Qiskit) the voting phase of Section III.C with the paper's example parameters n=4, δ0=δ1=1, but allow the rotating bookkeeper to prepare each ballot state as a purification of |X_n> and |S_n>, retaining the purifying registers. Run the security test many times and record (i) the fraction of accepted runs and (ii) the adversary's success rate in recovering the voters' vote vector from the published modified columns. If the success rate is materially above the 1/2 per-voter guessing probability while the test acceptance remains high, the Section V.A statement that attackers cannot interfere with the voting process is refuted for the given parameters.","verdict_should_be":"UNCHANGED","load_bearing_attack":"Section III.C (S1-S2) designates the rotating bookkeeper as the sole preparer and distributor of the |X_n> and |S_n> ballot states. Section V.A then asserts that attackers 'cannot tamper with the blocks or attack the consensus process' and that quantum voting prevents interference. But PoV's model (Section II.A.2) only requires one honest bookkeeper for liveness, not that the bookkeeper of the current round is trusted. A malicious rotating bookkeeper knows the column-to-voter mapping and could prepare the distributed states as purifications, keeping ancillas that correlate with voters' measurement outcomes. The statistical tests in S1 and S2 (with parameters δ0, δ1) are not analyzed here: the paper provides no bound on the adversary's cheating advantage as a function of δ0, δ1, n, and no composable security proof. Since the voters later publish their modified ballot columns, a bookkeeper who recovers the original ballot matrix can determine each voter's vote, breaking the fairness/anonymity claim. The paper's own conclusion admits the scheme cannot yet be simulated, so this gap is not empirically closed. Thus the central claim of resistance to quantum attacks is unsupported at the protocol level, independent of the network-availability premise.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper proposes Q-PnV, a quantum consensus mechanism for consortium blockchains that combines quantum voting (based on Wang et al.'s |Xn> and |Sn> entangled states), QKD-based identity authentication, and QRNG-based rotating-bookkeeper selection, and integrates this with a weighted-hypergraph quantum blockchain. The authors claim that, compared to classical PoV/PnV, the resulting scheme resists quantum attacks and significantly improves security and fairness. The protocol is described step-by-step and illustrated with a four-voter toy example, but the analysis section (Section V) is only two short qualitative paragraphs with no adversary model, no security proof, and no simulation.","tokens_in":14153,"tokens_out":4191,"duration_ms":43382,"significance":"If the security and fairness claims were rigorously established, Q-PnV would be a useful design blueprint for quantum-native consortium blockchains, filling a gap in the literature. The paper's concrete protocol description and worked example are valuable as a starting point. However, the central claims are asserted rather than demonstrated: there is no formal threat model, no analysis of the security tests, and no quantitative comparison with the classical baselines. The paper also explicitly assumes a practical distributed quantum network and trusted QRNGs, which limits its immediate applicability. As it stands, the contribution is a protocol sketch with unverified security properties, so the significance is moderate at best until the analysis is supplied.","major_comments":[{"comment":"The security analysis is not a derivation but a qualitative summary. It asserts that attackers 'cannot tamper with the blocks or attack the consensus process' and that quantum voting prevents interference, but it provides no adversary model (e.g., which nodes may be malicious, what computational or quantum capabilities are assumed, whether the adversary can corrupt the rotating bookkeeper or voters), no concrete security bound, and no simulation or experimental validation. Since the paper's own conclusion states that 'the proposed scheme cannot yet be experimented with or simulated,' the central security claim is entirely unsupported and must be considered an open question.","section":"Section V.A"},{"comment":"The rotating bookkeeper is the sole preparer and distributor of the ballot states |Xn> and |Sn>, and the protocol implicitly trusts that this node is honest in its preparation. However, the PoV model described in Section II.A.2 only requires at least one honest bookkeeper for liveness, not that the current rotating bookkeeper is trusted. A malicious rotating bookkeeper can prepare these states as purifications, keeping ancilla qubits that correlate with voters' subsequent measurement outcomes. The security tests in S1 and S2 use parameters δ0 and δ1, but the paper provides no bound on the adversary's cheating advantage as a function of δ0, δ1 and n, and no composable security proof. Without such a bound, the fairness and anonymity claims in Section V.B are not established: a dishonest bookkeeper could use the ancillas to recover each voter's ballot matrix after the voters publish their modified columns, thereby determining individual votes.","section":"Section III.C (S1-S2)"},{"comment":"The voting verification step only checks that a block's phase satisfies θp ∈ (0, π/2) and that the sum of phases is less than π/2, but it does not verify the equiproportionality condition of Eq. (6), θpi = 2^{-(i-1)} θp1. The numerical example in Section IV.B does follow Eq. (6), yet the general protocol does not enforce or verify this condition. Without this constraint, even if the sum condition holds, the phase angles may not correspond to a valid weighted-hypergraph state, and the claimed entanglement-based tamper detection may fail. The protocol should either require and verify Eq. (6) or prove that the weaker conditions are sufficient for the hypergraph-state construction.","section":"Section IV.A S2 and IV.B"}],"minor_comments":[{"comment":"There is a typo in the abstract: 'better suit-ed' should be 'better suited'.","section":"Abstract"},{"comment":"The subsection numbering is inconsistent: 'Quantum Internet' has no number, while the following subsection is labeled '2) Two Types of Quantum Multiparticle Entangled States in Voting Process', skipping '1)'.","section":"Section III.A"},{"comment":"The summation condition 'Pn−1 i=0 ji mod m=0' is ambiguous; it should be written as \\(\\sum_{i=0}^{n-1} j_i \\equiv 0 \\pmod{m}\\) to be clear.","section":"Eq. (7)"},{"comment":"The subsection title 'Determining the Rotating Bookkeeper' duplicates the title of Section III.D; the Section IV.A title should instead describe the construction of quantum blocks.","section":"Section IV.A"},{"comment":"The table headers are confusing: the last column 'R' is not defined in the caption, and the entries for r'_{0,k} etc. mix notation with inline mod-2 computations; a separate column showing the final row sums would improve readability.","section":"Table I"}],"recommendation":"reject","confidential_remarks":"The paper's central security and fairness claims rest on assertions rather than analysis, and the identified malicious-bookkeeper issue is a concrete gap that cannot be patched with minor edits. The authors also rely heavily on their own prior work (PoV/PnV) and on external quantum voting results without providing a comparative evaluation. Given the journal's standards, the manuscript would need a full adversary model, a security proof or at least a rigorous attack analysis, and ideally a simulation or experiment, which go well beyond the current scope."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"The short version: Q-PnV is a concrete composition of known quantum building blocks into a consortium-blockchain consensus protocol. The construction is spelled out and the four-voter example is internally consistent. What's missing is any derivation of the security and fairness claims; Section V is qualitative, and the paper itself admits the scheme cannot yet be simulated.\n\nWhat's actually new: no earlier paper tailors a quantum consensus mechanism to consortium blockchains using this particular combination of Wang et al.'s self-tallying quantum voting, QRNG-based rotating bookkeeper selection, and a weighted-hypergraph quantum blockchain. The authors don't claim to invent the components, and the citation to Wang et al. [27] is appropriate. The writing is refreshingly clear about the network premise: they assume a distributed interconnected quantum network already works and that state preparation/distribution is practical. The protocol steps S1-S3 are detailed enough to reason about.\n\nThe main problem is the security analysis. Section V.A asserts attackers cannot tamper with blocks or interfere with voting, but gives no adversary model, no security bound, no proof. The stress-test note is on point: the rotating bookkeeper prepares and distributes the |Xn> and |Sn> states, and the protocol does not analyze a malicious bookkeeper who purifies those states or keeps ancillas. Since the ballot matrix is eventually published, a bookkeeper who learns the pre-vote measurement outcomes could de-anonymize voters. The statistical tests with parameters delta_0 and delta_1 are not analyzed as security parameters; there is no cheating-advantage bound as a function of them, n, or the test structure. That is a load-bearing gap, not a minor omission. The QRNG trust assumption is also an assumption, though the consortium supervision model makes it more palatable. The fairness argument is similarly qualitative.\n\nThat said, this is not nonsense. The composition is plausible, and the authors are honest about limitations. The final sentence in the conclusion—'the proposed scheme cannot yet be experimented with or simulated'—is a real admission, not a buried one. But it means the paper is a design sketch with an unverified security story.\n\nWho this is for: readers working on quantum blockchain proposals, especially in the niche of consortium/permissioned settings. It can serve as a starting point for a rigorous security treatment. I'd send it to peer review rather than desk reject—a serious referee can ask for an adversary model, a reduction of the cheating advantage to the properties of |Xn> and |Sn> and the test parameters, and a simulation on classical hardware. I'd expect heavy revision. I won't cite it in my own work until the security claims are grounded.","headline":"A concrete quantum-consensus composition for consortium blockchains, but the security claims are asserted, not derived, and the honest limitation note doesn't fill the gap.","tokens_in":14744,"tokens_out":2149,"would_cite":false,"duration_ms":21601,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"Q-PnV makes consortium-blockchain consensus quantum-safe by putting votes in entangled states and leader choice in QRNGs.","keywords":["quantum blockchain","consortium blockchain","quantum consensus mechanism","quantum voting","proof of vote","QRNG","weighted hypergraph states","QKD identity authentication"],"falsifier":"Run the paper's four-voter example on a real or simulated quantum device under honest conditions and check the two security tests: the parity and equality checks on |Xn> and the permutation check on |Sn>. If even a small amount of noise makes the tests fail too often for a vote to complete, or if a single dishonest bookkeeper can choose the prepared states so that voters' choices are recoverable from the public tally, the protocol's claimed security and fairness would be disproved.","tokens_in":13673,"feed_emoji":"⚛️","tokens_out":6599,"duration_ms":66210,"temperature":0.7,"pith_summary":"Q-PnV is an attempt to make consortium blockchains quantum-native: it takes the classical Proof-of-Vote consensus, which already has low latency and high throughput, and replaces the pieces a quantum computer would break. Votes become measurements on entangled states that self-tally in public, identity is authenticated with quantum-key-distribution-derived keys, and the rotating block producer is chosen by a quantum random number generator instead of by inverting a hash. Valid blocks are linked into a weighted-hypergraph quantum blockchain, where tampering with one block destroys the entanglement of the whole chain. The paper argues that this combination resists quantum attacks and improves fairness compared with classical PoV and PnV. The paper also states that the scheme cannot yet be implemented or simulated, so the payoff is conditional on future quantum-network hardware.","feed_headline":"Quantum ballots and QRNGs harden consortium blockchains","feed_subtitle":"Q-PnV replaces hash-based voting with entangled-state ballots, so quantum computers cannot forge votes or predict block producers.","key_machinery":"The engine of Q-PnV is the self-tallying quantum anonymous voting protocol based on two multipartite entangled states: |Xn>, whose n computational-basis outcomes sum to 0 modulo m while its Fourier-basis outcomes are all identical, and |Sn>, whose outcomes form a random permutation of the set {0,...,n-1} in either basis. These states serve as the ballot matrix and the ballot index: the first makes tampering detectable through parity and equality checks, and the second lets each voter hide which row of their ballot they modify. Around this engine, the protocol uses QKD-derived keys for identity authentication, a consortium-maintained QRNG for rotating-bookkeeper selection, and weighted-hypergraph states, in which qubits are vertices and multi-qubit Controlled-Z gates are weighted hyperedges, to entangle successive block qubits; the optimized hypergraph circuit from the quantum-blockchain literature supplies the actual entanglement operation.","core_discovery":"The central claim, stated on the paper's own terms, is that consensus can be made quantum-safe by moving the security burden from number-theoretic cryptography to entanglement and measurement. In Q-PnV, a rotating bookkeeper prepares n-particle states |Xn> and |Sn> and distributes one particle to each voter; voters verify the states with parity and permutation tests, then cast an anonymous ballot by adding their choice modulo 2 to the row selected by a private |Sn> index. Because the tally is computed from the public matrix, the protocol is self-tallying and no voter's choice can be traced, while forged or altered states fail the security tests. The next bookkeeper is chosen by a consortium-supervised QRNG rather than by a hash of signatures and timestamps, and QKD-based identity authentication keeps impersonators out. Blocks whose qubits pass the voting threshold are entangled into the existing weighted-hypergraph chain, so the security argument rests on physical tamper-evidence rather than computational hardness.","pith_inferences":["Editorial inference: the same |Xn> and |Sn> ballot machinery could be applied to other permissioned voting tasks inside a consortium, such as parameter changes or membership votes, without changing the consensus core.","Editorial inference: the paper does not argue security against a dishonest state-preparing bookkeeper, so a practical deployment would need distributed preparation or verification that the bookkeeper cannot bias the |Xn> states before they are distributed.","Editorial inference: because consortium networks are small and their operators are well-resourced, Q-PnV-type designs may be the first quantum-blockchain family to meet the quantum Internet's early-stage constraints, which is exactly where the paper positions its contribution.","Editorial inference: a natural first test is a noisy few-qubit simulation of the paper's four-voter example, checking how often the parity and permutation tests pass; the paper's own conclusion acknowledges that no such experiment or simulation is yet available."],"forward_implications":["A consortium blockchain running Q-PnV no longer needs classical digital signatures or hash-based randomness for its consensus path, removing the two attack surfaces that Shor's and Grover's algorithms target.","If the QRNG is trusted and consortium-supervised, no coalition of bookkeepers can predict or manipulate the rotation order, so block-production rights stay fair across tenure cycles.","Block tampering becomes physically evident: because blocks are entangled into a weighted-hypergraph state, altering one block's encoded phase disrupts the correlations of the whole chain.","Voters can independently recount votes from the public ballot matrix, so a dishonest bookkeeper cannot silently alter the outcome of block validation or bookkeeper election."],"supporting_citations":[{"why":"Supplies the self-tallying quantum anonymous voting protocol with |Xn> and |Sn> states that Q-PnV uses for all voting.","marker":"[27]"},{"why":"Defines Proof of Vote, the classical consortium consensus whose tenure-cycle structure and role model Q-PnV inherits.","marker":"[15]"},{"why":"Defines PnV, the parallel proof-and-voting enhancement that Q-PnV is named after and whose throughput it preserves.","marker":"[17]"},{"why":"Provides the weighted-hypergraph quantum blockchain construction into which Q-PnV entangles each valid block.","marker":"[7]"},{"why":"Supplies the optimized quantum circuit that links blocks into a hypergraph chain, used in the paper's three-block example.","marker":"[9]"},{"why":"Establishes the quantum-Internet roadmap and the readiness assumptions that the protocol's network model depends on.","marker":"[26]"},{"why":"Backs the QRNG component by reviewing available quantum random number generators and their implementation challenges.","marker":"[28]"},{"why":"Names Shor's algorithm, the threat that motivates replacing classical signatures in the consensus process.","marker":"[1]"}],"fun_headline_variants":["Entangled-state voting: quantum shield for consortium chains","Self-tallying quantum votes defeat quantum hackers","Q-PnV: quantum consensus with tamper-evident ballots","QRNG-chosen leaders and quantum votes secure consensus","From hash-based to entanglement-based: quantum-proof consensus"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The whole protocol assumes a working quantum network already exists, one that can reliably create and send the interlinked quantum particles that votes and blocks are made of; without that, Q-PnV cannot be deployed at all.","fun_headline_variants_meta":{"raw":{"variants":["Entangled-state voting: quantum shield for consortium chains","Self-tallying quantum votes defeat quantum hackers","Q-PnV: quantum consensus with tamper-evident ballots","QRNG-chosen leaders and quantum votes secure consensus","From hash-based to entanglement-based: quantum-proof consensus"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000638,"raw_usage":{"total_tokens":2912,"prompt_tokens":892,"completion_tokens":2020,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":508,"completion_tokens_details":{"reasoning_tokens":1942}},"tokens_in":508,"tokens_out":2020,"duration_ms":14460,"temperature":1.0,"reasoning_tokens":1942,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-11T19:46:31.336273+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Run the paper's four-voter example on a real or simulated quantum device under honest conditions and check the two security tests: the parity and equality checks on |Xn> and the permutation check on |Sn>. If even a small amount of noise makes the tests fail too often for a vote to complete, or if a single dishonest bookkeeper can choose the prepared states so that voters' choices are recoverable from the public tally, the protocol's claimed security and fairness would be disproved.","supporting_citations":[{"cited_title":"Self-tallying quantum anonymous voting,","cited_arxiv_id":null,"evidence_quote":"Supplies the self-tallying quantum anonymous voting protocol with |Xn> and |Sn> states that Q-PnV uses for all voting."},{"cited_title":"PoV: An Efficient V oting-Based Consensus Algorithm for Consortium Blockchains,","cited_arxiv_id":null,"evidence_quote":"Defines Proof of Vote, the classical consortium consensus whose tenure-cycle structure and role model Q-PnV inherits."},{"cited_title":"PnV: An Efficient Parallel Consensus Protocol Integrating Proof and V oting,","cited_arxiv_id":null,"evidence_quote":"Defines PnV, the parallel proof-and-voting enhancement that Q-PnV is named after and whose throughput it preserves."},{"cited_title":"Quantum blockchain using weighted hypergraph states,","cited_arxiv_id":null,"evidence_quote":"Provides the weighted-hypergraph quantum blockchain construction into which Q-PnV entangles each valid block."},{"cited_title":"Improving the implementation of quantum blockchain based on hypergraphs,","cited_arxiv_id":null,"evidence_quote":"Supplies the optimized quantum circuit that links blocks into a hypergraph chain, used in the paper's three-block example."},{"cited_title":"Quantum internet: A vision for the road ahead,","cited_arxiv_id":null,"evidence_quote":"Establishes the quantum-Internet roadmap and the readiness assumptions that the protocol's network model depends on."},{"cited_title":"Quantum Internet—Applications, Functionalities, Enabling Technologies, Challenges, and Research Directions,","cited_arxiv_id":null,"evidence_quote":"Backs the QRNG component by reviewing available quantum random number generators and their implementation challenges."},{"cited_title":"Algorithms for quantum computation: discrete logarithms and factoring,","cited_arxiv_id":null,"evidence_quote":"Names Shor's algorithm, the threat that motivates replacing classical signatures in the consensus process."}],"review_version":1}