{"id":"ff35e147-60e0-4ac3-8e50-ee39a603d8f0","arxiv_id":"2501.09568","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":4,"one_line_summary":"A quantum Diffie-Hellman key exchange protocol based on symmetric coherent states is introduced, with security analyzed against minimum-error-discrimination and photon-number-splitting attacks.","lead":"This paper proposes a quantum version of Diffie-Hellman key exchange using weak coherent light pulses. Two parties each add a secret phase shift and end up sharing an unknown quantum state they can use to exchange key bits, and the authors analyze its security against two specific quantum attacks.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Security rests on an unproven optimality conjecture for Eve's attack; a joint measurement on the two intercepted states may beat the individual minimum-error strategy and shrink the claimed min-entropy.","rationale":"The reader's weakest assumption already identifies the same load-bearing concern: the protocol's security and secret-key length depend on the conjecture in Sec. III D that Eve's individual minimum-error-discrimination attack is optimal. My stress-test sharpens this to a concrete gap: the paper only analyzes one specific two-stage strategy, and it never proves, or even numerically tests, that a joint measurement on the pair of intercepted states cannot yield a higher guessing probability for the encoded bit. This is not a disagreement with an external consensus; it is an internal completeness problem in the security argument. The paper does contain useful elements: the symmetric coherent-state construction, the explicit calculation of the sifting probabilities, and the identification of a parameter regime where the map is close to an ideal one-way function under the tested attack. Those contributions are real. But the central claim that the encoded bit remains practically unknown to Eve, and hence that the final key is essentially as long as the sifted key, is only as strong as the unproven optimality conjecture. A numerical SDP for the joint state would give a definite answer for the specific parameter values considered, and if it shows a higher success probability, the min-entropy and key-length conclusions would need to be revised. For these reasons the existing CONDITIONAL verdict is appropriate; no change is needed until the joint-measurement question is resolved.","tokens_in":17135,"tokens_out":7514,"duration_ms":90330,"concrete_test":"Run a semidefinite program to compute the optimal guessing probability for k = a XOR b from the two intercepted copies, i.e. maximize (1/N) sum_{a,b} Tr[M_{a XOR b} |psi_a><psi_a| tensor |psi_b><psi_b|] over POVMs {M_k}, for the symmetric coherent states of Eq. (8) with N = 20 and mu = 0.01, 0.02, 0.05, truncating the Fock basis at n_max = ceil(mu + 6 sqrt(mu)). Compare the resulting p_guess(k) with the probability that the individual square-root measurements from Sec. III B give the correct XOR. If the joint p_guess(k) exceeds the individual-combination value, the Sec. III D conjecture fails for this attack class and Eq. (36) overestimates Hmin. A stronger variant is to optimize a POVM directly on |psi_a> tensor |psi_b> tensor |psi_cipher> for guessing s, where |psi_cipher> depends on a, tilde_b, and s; this settles whether the p_E(cor) used in Fig. 7 is maximal.","verdict_should_be":"UNCHANGED","load_bearing_attack":"In Sec. III D the paper computes Hmin(s_j|tilde_s_j) = -log2[p_E(cor)] using p_E(cor) from the specific two-stage attack of Sec. III B: individual square-root measurements on |psi_a> and |psi_b>, followed by an X-quadrature decision on the rotated cipher state. The text explicitly conjectures that this p_E(cor) is maximal. This conjecture is load-bearing because Eq. (35) turns Hmin approximately 1 into a secret-key length close to |s|, which is the quantitative form of the central claim that the encoded bit is well protected. The supporting argument that independent preparation makes collective attacks useless is not a proof: a and b are independent, but the quantity Eve needs is k = a XOR b, a function of the joint state |psi_a> tensor |psi_b>. A joint POVM can be designed to estimate k directly, or to decide s after receiving the cipher state, without first committing to individual estimates of a and b. Nothing in Sec. II rules out such a measurement: the Holevo and Fano bounds bound information about a single state, not about a function of a pair of states. If a joint measurement yields, for example, p_E(cor) = 0.55 at mu = 0.02, the min-entropy in Fig. 7(b) drops from about 0.96 to about 0.86, and the extractable key length in Eq. (35) shrinks accordingly. Thus the central security claim is conditional on a nontrivial optimality statement that is neither proven nor numerically tested.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper proposes a quantum version of Diffie-Hhellman key exchange. Alice and Bob independently choose random integers a_j and b_j, encode them as symmetric coherent states |ψ_a⟩ and |ψ_b⟩, and exchange them. Each party applies his/her own phase shift to the received state, obtaining a common quantum key |ψ_{a⊕b}⟩. Alice then encodes a secret bit s_j by a phase flip and sends the cipher state to Bob, who compares it with his local key by interference on a beam splitter. The paper analyzes the protocol's operation under realistic losses and phase drift, introduces a quantitative criterion for when the map x ↦ |ψ_x⟩ acts as a quantum one-way function, and studies two attacks: a minimum-error-discrimination attack and a photon-number-splitting attack. It concludes that for mean photon number μ ≲ 0.02 and sufficiently many phase slices N, the encoded bit s_j is well protected (H_min ≥ 0.96) and any such attack induces a high error rate (~0.5) in the sifted key, so the protocol would abort.","tokens_in":17533,"tokens_out":8766,"duration_ms":94687,"significance":"If rigorously established, the protocol would be a genuinely new construction: a Diffie-Hellman-like key agreement whose security is based on a quantum one-way function rather than on standard QKD principles. The paper contains useful concrete results: a quantitative QOWF criterion (Eq. (7) with D ≤ ε), analytical formulas for the detection and error probabilities (Eqs. (19)-(26), (30)-(33)), and a clear analysis of why the PNS attack is not directly useful. The numerical simulations and figures are reproducible from the given formulas. However, the strongest security claim is explicitly conditional on a conjecture about the optimality of the analyzed attack. Because this conjecture is load-bearing for the central claim, the current manuscript does not yet provide a complete security proof but does supply a substantial analytic and numerical basis for the protocol's behavior under specific attacks.","major_comments":[{"comment":"The central claim that the encoded bit is well protected, quantified by H_min(s_j|tilde s_j) ≈ 1 and hence by a secret-key length close to |s| in Eq. (35), relies on the conjecture stated in the text that the two-stage minimum-error-discrimination attack of Sec. III B maximizes p_E(cor). This conjecture is load-bearing. The supporting argument that independent preparation of a_j and b_j makes collective attacks useless is not a proof: the relevant quantity is k_j = a_j ⊕ b_j, which is a function of the joint state |ψ_a⟩⊗|ψ_b⟩. A joint POVM could estimate k_j directly, or decide s_j after seeing the cipher state, without first committing to individual estimates of a_j and b_j. The Holevo and Fano bounds in Sec. II bound the information about a single state, not about a function of a pair of states. Nothing in the manuscript rules out such a joint measurement, so the numerical values in Fig. 7 and the key-length estimate in Eq. (35) are conditional on an unproven optimality statement.","section":"Sec. III D, Eqs. (35)-(36)"},{"comment":"The security analysis does not establish the trade-off between Eve's information and the induced error rate, which is the basis for the abort decision. The paper computes p_E(cor) and H_min for a specific, unconstrained attack, and separately computes the error rate (~0.5) that this attack induces. It does not show that any attack that is consistent with the observed error rate (i.e., q ≤ P_err^max = 0.2) leaves H_min at the values used in Eq. (35). For example, Eve could deliberately guess s_j less aggressively, or use a correlated strategy across rounds, to reduce the induced error rate while still gaining some information about s_j. Without a bound of the form H_min ≥ f(q) relating the min-entropy to the observed error rate, the protocol's secret-key length is not proven secure even against the family of attacks considered.","section":"Sec. III B and Step 8 of Definition 1"},{"comment":"The equality H_min(s|tilde s) = |s| H_min(s_j|tilde s_j) is stated without proof and is not generally exact for conditional min-entropy of finite-size strings. For i.i.d. rounds, the conditional min-entropy of the joint string is only asymptotically equal to n times the single-round value, up to smoothing and finite-size corrections. The Chernoff-bound sample size in Eq. (34) is not connected to the key-length estimate in Eq. (35). As written, the extractable key length may be overstated. The authors should either state that Eq. (35) is an asymptotic expression (with corrections) or perform a proper finite-key analysis.","section":"Sec. III D, line after Eq. (35)"}],"minor_comments":[{"comment":"There is an empty citation after 'the secure key length that can be extracted from s' (the brackets contain no reference).","section":"Sec. III D, first paragraph"},{"comment":"The caption lists '(b) μ = 0.02, N = 20. (c) μ = 0.05, N = 20. (b) μ = 0.1, N = 20'; the last panel should be labeled (d).","section":"Fig. 5 caption"},{"comment":"The notation ⊖ for subtraction modulo N is used in some equations (e.g., Eq. (8d)) but not defined as explicitly as ⊕; a short notational clarification would improve readability.","section":"Throughout"},{"comment":"The choice ε = 2 × 10^{-2} is presented as a security parameter, but the paper does not discuss how this value relates to a concrete security level (e.g., a lower bound on the adversary's error probability). A brief remark that ε is a design choice and what its magnitude implies would be helpful.","section":"Sec. II B and Fig. 1"}],"recommendation":"major_revision","confidential_remarks":"The paper's main weakness is the unproven optimality conjecture for the eavesdropping strategy, which is load-bearing for the security claim. If the authors can either prove that the described minimum-error-discrimination attack is optimal (or at least give strong evidence), or substantially soften the claim to 'security against the two analyzed attacks' and clearly state that general security is open, the manuscript could be acceptable. The analytical work is otherwise careful and the numerical results are useful. I would not recommend rejection because the gaps are fixable within the scope of the manuscript."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Let me give you the short version: the paper is a real construction, not a repackaging. It defines a quantum analogue of Diffie-Hellman using symmetric coherent states, where Alice and Bob each apply a random phase shift and the shared key is the sum of their secrets. The analysis of the two specific attacks—minimum-error discrimination and photon-number splitting—is careful and internally consistent. The derivations of detection probabilities and error rates check out, and the parameter regime where the mapping behaves as a quantum one-way function is quantified with a concrete criterion.\n\nThe main soft spot is exactly where the author puts it: the security analysis is conditional on the conjecture that the individual minimum-error discrimination attack is optimal for Eve. This conjecture is load-bearing. The secret-key length in Eq. (35) uses H_min based on the guessing probability from that attack. If a joint measurement on the two intercepted states can estimate a⊕b directly, without first committing to estimates of a and b, the guessing probability could be higher, and the min-entropy would drop. The paper's argument that independent preparation makes collective attacks useless is not a proof; independence of a and b does not prevent a joint POVM on the pair. The author explicitly acknowledges this conjecture in Sec. III D and again in the conclusions, so the limitation is not hidden. But it means the central security claim is not yet established.\n\nThe practical side is also modest: small mean photon number gives low key rate, and the error-rate threshold limits range to tens of kilometers. The paper acknowledges these constraints. The citation pattern is fine; prior quantum DH protocols are cited and their lack of security analysis is noted.\n\nWho should read it: researchers working on continuous-variable QKD and proposals for quantum key exchange with weak coherent states. The construction is worth discussing, and the honest treatment of its own limitation is a point in its favor. My recommendation: send it to peer review. The referee should ask for either a proof of the optimality conjecture or a revised claim that limits security to the specific attacks analyzed. The paper is a fair candidate for publication after that condition is addressed.","headline":"A genuinely new coherent-state key-exchange protocol with careful attack analysis, whose full security claim rests on a conjecture the author openly states.","tokens_in":18000,"tokens_out":2592,"would_cite":true,"duration_ms":27510,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["81P94","94A60"],"pacs":["03.67.Dd"],"model":"deepseek-v4-flash","headline":"A quantum version of Diffie-Hellman key exchange can be built by encoding integers as weak coherent states, and for mean photon numbers below about 0.02 the encoding hides the shared key from an eavesdropper's best analyzed attack.","keywords":["quantum key exchange","Diffie-Hellman","quantum one-way function","coherent states","minimum-error discrimination","photon-number-splitting attack","min-entropy","twin-field QKD"],"falsifier":"Find a concrete joint or collective measurement on Eve's collected copies of |ψ_a⟩ and |ψ_b⟩ from many rounds that achieves a guessing probability for s_j exceeding $2^{{-H_min}}$ at μ = 0.02, N = 20; a numerical search over joint POVMs on the tensor-product states would settle whether the conjectured optimality holds.","tokens_in":16943,"feed_emoji":"🔑","tokens_out":9203,"duration_ms":84823,"temperature":0.7,"pith_summary":"Diffie-Hellman key exchange is the workhorse of ephemeral secret-key agreement: two parties each send a public value derived from their private exponent, and commutation of exponentials lets both compute the same shared key. This paper asks whether the same logic can be moved into the quantum domain, where the 'exponent' is a random integer encoded in the phase of a coherent state and the 'commutation' is the fact that phase-shift operators commute. The central claim is that the map from integers to a set of N symmetric coherent states with mean photon number μ is a quantum one-way function when μ is small (≲0.02) and N is large enough: preparing the state is easy, but inverting it with the optimal minimum-error measurement is within 2% of random guessing. For these parameters the proposed protocol gives Alice and Bob a shared quantum state that neither knows, and an encoded bit that Eve's best analyzed attack—independent minimum-error discrimination of the two intercepted states—can guess only with probability close to 1/2. The paper therefore identifies a concrete, experimentally accessible regime in which a Diffie-Hellman-style quantum key exchange can offer information-theoretic protection of the encoded bit against the attacks it considers.","feed_headline":"Low-photon coherent states shield a quantum Diffie-Hellman key","feed_subtitle":"Below 0.02 mean photons, Eve's best measured guess is a coin flip, yielding nearly one secret bit per round.","key_machinery":"The central object is the set S_N of N symmetric single-mode coherent states |ψ_x⟩ = |√μ $e^{{i x 2π/N}}$⟩, together with the elementary phase-shift operator U = $e^{{i 2π a†a/N}}$. The map x ↦ |ψ_x⟩ is the proposed quantum one-way function; the operators U^x form a cyclic group that commutes and adds modulo N, providing the quantum analogue of exponentiation modulo a prime. The security analysis hinges on the minimum-error probability of the square-root measurement for these states, computed from the Poisson photon statistics and leading to the criterion D ≤ ε for closeness to an ideal one-way function.","core_discovery":"The paper's central discovery is that the algebraic structure of phase-shift operations on a fixed coherent state replicates the two properties that make classical Diffie-Hellman work: any two phase shifts commute, and their combined action adds modulo N. Encoding Alice's and Bob's private integers as states |ψ_x⟩ = U^x|ψ_0⟩ drawn from the publicly known set S_N of symmetric coherent states, the protocol lets each user apply their own shift to the state received from the other, so both arrive at the common state |ψ_{a⊕b}⟩ with neither knowing the key value. The security claim is that for μ ≲ 0.02 and N ≥ N*(μ) the encoding acts as a quantum one-way function: the square-root measurement, which is optimal for minimum-error discrimination of these states, yields a success probability that is within ε = 2×$10^{{-2}}$ of random guessing, and the conditional min-entropy of the encoded bit against this attack satisfies H_min(s_j|s~_j) ≥ 0.96 bits. The paper further argues that the photon-number-splitting attack is not a threat, because Eve would need multiphoton pulses from both exchanged states (probability at most $μ^{4}$/4) and would then face the same discrimination problem. On this basis it conjectures that the best eavesdropping strategy is the independent minimum-error-discrimination attack, and derives a secret-key length via the leftover-hash bound.","pith_inferences":["The paper leaves open the security against collective or joint measurements across multiple intercepted states; a proof that such measurements do not beat the independent minimum-error-discrimination guessing probability would turn the conjectured optimality into a theorem, but no such proof is given.","The protocol's dependence on a common phase reference and low phase drift means its secure distance is limited by phase coherence; phase-stabilization techniques from twin-field QKD could extend the reach, though the paper does not quantify this.","A natural generalization is to encode more than one bit per state (for example by using multiple phase-shift values for the bit), with the per-round min-entropy then set by the discrimination error; the framework presented here could be extended in that direction.","If the central security claim holds, the same coherent-state map could serve as a building block for other public-key-style quantum protocols, since it provides a physical one-way function with a clear group structure."],"forward_implications":["For μ ≲ 0.02 and N ≥ N*, an eavesdropper using the minimum-error-discrimination attack can guess the encoded bit with probability close to 1/2, giving a conditional min-entropy of at least 0.96 bits per raw bit.","At these parameters, a minimum-error-discrimination attack drives the error rate in Alice's and Bob's sifted keys to roughly 0.5, so a threshold of P_err_max = 0.2 provides a clear detection signal.","The photon-number-splitting attack is ineffective because it succeeds only when both intercepted states contain at least two photons (probability at most μ^4/4), and even then it reduces to the same minimum-error-discrimination problem.","The protocol does not require a third party and can be implemented with existing coherent-state technology, including phase modulators, beam splitters, and single-photon detectors.","The security parameter ε = 2×10^{-2} defines the threshold N*(μ), which grows with μ; for μ = 0.02, N = 20 lies within the secure regime.","If the conjectured optimality of the independent minimum-error-discrimination attack holds, the protocol yields a secret-key length governed by the leftover-hash bound, with the min-entropy term essentially equal to the raw key length."],"supporting_citations":[{"why":"Introduces the symmetric coherent-state map and its use as a quantum one-way function.","marker":"[6–8]"},{"why":"Establishes that the square-root measurement is optimal for minimum-error discrimination among symmetric coherent states, giving the minimum error probability.","marker":"[9, 10]"},{"why":"Provides the Holevo bound and Fano inequality used to define the quantum one-way function criterion.","marker":"[11]"},{"why":"Supplies the twin-field QKD framework and experimental parameter values used to estimate the protocol's performance and phase-drift behavior.","marker":"[12, 14–16]"},{"why":"Provides the phase-diffusion model and diffusion coefficient used to model phase drift over distance.","marker":"[13]"},{"why":"Defines the photon-number-splitting attack and its limitations, which the paper argues do not apply beneficially to this protocol.","marker":"[21]"},{"why":"Gives the leftover-hash and min-entropy bounds that relate Eve's guessing probability to the extractable secret-key length.","marker":"[22–24]"}],"fun_headline_variants":["Quantum Diffie-Hellman with coherent states: security at low photon flux","Low-photon coherent states make quantum key exchange safe","Quantum one-way function from symmetric coherent states","Diffie-Hellman goes quantum with faint light pulses","Quantum Diffie-Hellman secure when Eve gets only coin flips"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"Eve's optimal attack is the individual minimum-error-discrimination measurement on each intercepted state, so the guessing probability p_E(cor) used in the min-entropy bound is maximal.","fun_headline_variants_meta":{"raw":{"variants":["Quantum Diffie-Hellman with coherent states: security at low photon flux","Low-photon coherent states make quantum key exchange safe","Quantum one-way function from symmetric coherent states","Diffie-Hellman goes quantum with faint light pulses","Quantum Diffie-Hellman secure when Eve gets only coin flips"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000736,"raw_usage":{"total_tokens":3309,"prompt_tokens":988,"completion_tokens":2321,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":604,"completion_tokens_details":{"reasoning_tokens":2237}},"tokens_in":604,"tokens_out":2321,"duration_ms":17866,"temperature":1.0,"reasoning_tokens":2237,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-10T19:53:44.597380+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Find a concrete joint or collective measurement on Eve's collected copies of |ψ_a⟩ and |ψ_b⟩ from many rounds that achieves a guessing probability for s_j exceeding $2^{{-H_min}}$ at μ = 0.02, N = 20; a numerical search over joint POVMs on the tensor-product states would settle whether the conjectured optimality holds.","supporting_citations":[{"cited_title":"Phase-noise measurements in long-fiber interferometers for quantum-repeater applications,","cited_arxiv_id":null,"evidence_quote":"Provides the phase-diffusion model and diffusion coefficient used to model phase drift over distance."},{"cited_title":"Limi- tations on practical quantum cryptography,","cited_arxiv_id":null,"evidence_quote":"Defines the photon-number-splitting attack and its limitations, which the paper argues do not apply beneficially to this protocol."}],"review_version":1}