{"id":"a7832f3e-7ddc-4195-8e98-78b9e72b336c","arxiv_id":"2504.15528","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":5.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":4,"one_line_summary":"A fully passive source can be combined with RFI QKD, yielding a simulated secure distance of 167 km at 10^12 pulses with a 1 GHz source and more than half the key rate of ideal active-modulation QKD.","lead":"This paper proposes a reference-frame-independent QKD protocol that uses a fully passive source, removing active modulation and its associated side channels. It reports simulated secure key rates and distances, including 167 km at 10^12 pulses for zero misalignment.","discovery_kind":"extension","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Eq. (38) computes the lower bound on the RFI parameter C from the wrong end of the error-rate interval, overestimating C and thus the secure key rate.","rationale":"The reader's conditional verdict is based on the missing security proof for post-selected mixed states. I agree that this gap is serious, but the more immediately checkable internal error is in Eq. (38): the branch conditions for minimizing (1 - 2e)^2 are reversed. This is not a matter of consensus; it is a mathematical mistake that produces an invalid lower bound on C and therefore an overestimate of the key rate. The paper has no machine-checked proof or released code to offset this. Still, the flaw is repairable by correcting the endpoint selection and re-running the simulation, and the protocol concept may survive; so the appropriate outcome remains a major-revision conditional rather than outright acceptance. I therefore keep the reader's CONDITIONAL verdict unchanged.","tokens_in":17577,"tokens_out":13276,"duration_ms":120733,"concrete_test":"Recompute the optimization in Fig. 1 with C_L term-wise set to (1 - 2 e^{1,U})^2 when e^{1,U} <= 0.5, (1 - 2 e^{1,L})^2 when e^{1,L} >= 0.5, and 0 when the interval contains 0.5, keeping all other parameter-estimation steps unchanged. Then compare the resulting maximum distances and the ratio to ideal active QKD. If the distances fall below 167 km / 136 km or the ratio below 50%, the reversed endpoints in Eq. (38) are responsible for the inflated performance claim.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The key-rate formulas in Sec. II B, Eqs. (4)-(9), use C via I_E^1, and the finite-key analysis in Sec. II D needs a lower bound C_L on C. Eq. (38) defines C_L term-wise as (1 - 2 e^{1,U})^2 when e^{1,L} >= 0.5 and as (1 - 2 e^{1,L})^2 when e^{1,U} <= 0.5. This is backwards: on [0, 0.5] the function (1 - 2x)^2 decreases with x, so its minimum over [e^L, e^U] is at e^U, not e^L; on [0.5, 1] it increases, so the minimum is at e^L, not e^U. The only correct case is the middle branch (0 if the interval straddles 0.5). As written, both nonzero branches return an upper value instead of a lower value, so C_L is too large. Since I_E^1 in Eqs. (4)-(6) decreases with C, the protocol underestimates Eve's information and overestimates the secure key. This directly affects the main quantitative claims (167 km, 136 km, >50% of ideal active QKD in Fig. 1). Separately, the paper also applies the RFI bound to the post-selected mixed states without proof (the reader's concern), and Eq. (23) for f(I,theta) does not have the correct normalization; both add to the same conclusion that the current numbers are not justified.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The manuscript proposes a fully passive reference-frame-independent QKD protocol in which Alice uses a fully passive source to generate coherent pulses with random polarization and intensity, post-selects six intervals approximating the Z, X, and Y basis states, and uses Z-basis events for key while X/Y-basis events feed the RFI parameter C. The authors give a system model for gains and error rates, a finite-key analysis based on Kato's inequality and decoy-state linear programming, and numerical optimization of post-selection intervals and intensities. The central quantitative claims are that the asymptotic key rate exceeds 50% of ideal actively modulated QKD, and that with N=10^12 pulses the distance reaches 167 km for beta=0 and 136 km for beta=45 degrees.","tokens_in":17935,"tokens_out":16692,"duration_ms":140221,"significance":"The protocol idea is a sensible and potentially useful combination of two mature techniques: fully passive sources [45,48,49] and RFI key distillation [23]. The authors correctly identify that using the X/Y bases for eavesdropping estimation and the Z basis for key generation improves the utilization of passively generated states. The paper provides explicit formulas for gains, errors, and finite-key bounds, and the numerical work is transparent about parameters. If the security analysis is made rigorous for the actual non-ideal emitted states and the reported numerical bounds are corrected, the result would be a competitive fully passive RFI protocol. At present, however, the headline numbers are not supported by the analysis as written.","major_comments":[{"comment":"The lower bound on C is computed from the wrong end of the error-rate interval. For g(x)=(1-2x)^2, the function is decreasing on [0,0.5] and increasing on [0.5,1]. The lower bound on an interval [e^L,e^U] is therefore g(e^U) when e^U<=0.5 and g(e^L) when e^L>=0.5. Eq. (38) does the opposite in both nonzero branches, producing upper values rather than lower values; only the 'otherwise' branch is correct. Since I_E^1 in Eqs. (4)-(6) decreases with C, this makes the protocol underestimate Eve's information and overestimate the key rate. This error directly affects the main claims (the >50% ratio, 167 km, and 136 km), so the branch assignment must be corrected and all simulations rerun.","section":"Sec. II D, Eq. (38)"},{"comment":"The RFI security bound of Ref. [23] is applied to states that are not the six ideal states. Because of post-selection, the actual emitted states are mixtures over the intervals in Eqs. (1)-(2), and the paper substitutes error rates estimated for these mixed states directly into the C parameter and the bound I_E^1. No proof is given that the Laing et al. security statement remains valid for such non-ideal preparations. A source-flaw security analysis along the lines of Ref. [25] (which the manuscript cites but does not use) is necessary before the key-rate formula in Eq. (8) can be considered a valid lower bound. Without this, the claimed secure key rates are not established.","section":"Sec. II B, Eqs. (4)-(8)"},{"comment":"The probability density used for the passive source appears to be incorrect. With phi uniformly distributed over [0,2pi), the marginal density is 1/(2pi), not 1/(2Delta_phi); the latter is a conditional density on the post-selected interval and would make <P> in Eq. (22) identically 1. In addition, the stated f(I,theta) has square roots in the numerator, whereas the density derived from the arcsine-distributed sin^2 half-differences (the fully passive source model of Ref. [48]) has an inverse-square-root form. Since <Q> and <E> in Eqs. (20)-(21) are weighted by this density, every numerical result depends on it. The authors should re-derive the density from the source model in Appendix A and recompute the simulations.","section":"Sec. II C, Eq. (23)"},{"comment":"The definition of <P(I,n)> is inconsistent with its use. As printed, Eq. (31) is an unconditional average over the interval: integral over S of (I^n e^{-I}/n!) f(I,theta,phi) dI dtheta dphi. In that case, multiplying by <P> in Eqs. (8) and (30) double counts the interval probability. If the authors intended a conditional average, Eq. (31) is missing the division by <P>. The same issue affects the constraints in Eqs. (34) and (43). This is not a notational nuance: it changes the single-photon count M^L_{S_s ZZ,1} and hence the final key length, so the inconsistency must be resolved and the numerics redone.","section":"Sec. II C, Eq. (31) and Sec. II D, Eq. (30)"}],"minor_comments":[{"comment":"The title contains a typo ('dist ribution'), and the abstract uses '10 12' instead of 10^12.","section":"Title and abstract"},{"comment":"Eq. (39) writes the bounds for e^1_{xiA xiB} with subscripts S_s ZZB,1 for all basis combinations; if this is literal, it would make the X/Y-basis error bounds depend on Z-basis counts. The subscript should presumably be S_s^{xiA xiB},1.","section":"Sec. II D, Eq. (39)"},{"comment":"The caption and main text are ambiguous about colors: the text says the red curve is the ideal case and also lists red as one of the three finite-N curves; please clarify the color assignment for each N and each beta value.","section":"Fig. 1"},{"comment":"The comparison with actively modulated QKD would be clearer if the authors stated explicitly how the active protocol's key rate is defined (per pulse or per second) and which optimization constraints are imposed on its intensities.","section":"Sec. III, R_s definition"}],"recommendation":"major_revision","confidential_remarks":"The protocol is an incremental combination of existing ideas, but it is a reasonable one for this field. The main blockers are technical and, in principle, correctable: the reversed inequality in Eq. (38), the missing source-flaw proof, and the source-density model errors. I therefore recommend major revision rather than rejection. The authors should be asked to redo the security analysis and all performance simulations before the paper can be accepted."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"The paper's central claims are not supported: the lower bound on C in Eq. (38) is computed from the wrong end of the error interval, and the RFI security bound is applied to post-selected mixed states without proof. Both flaws inflate the reported key rates, so the headline numbers (167 km, 136 km, >50% of active QKD) are optimistic.\n\nWhat is actually new: the combination of a fully passive source with RFI QKD. The authors use X/Y basis emissions for parameter estimation and Z for key generation, which sensibly avoids discarding the Y-basis states. The system model follows the established fully passive source analysis, and the finite-key treatment uses Kato's inequality in the standard way. The citation pattern is appropriate; the relevant fully passive and RFI papers are cited. As a protocol design, this is a reasonable contribution.\n\nThe problems are in the security analysis and the numerics. Eq. (38) is backwards. The function (1-2x)^2 decreases on [0, 0.5] and increases on [0.5, 1]. A lower bound should be (1-2 e^U)^2 when the interval lies below 0.5, and (1-2 e^L)^2 when it lies above. The paper does the opposite in both branches, so C_L is actually an upper bound on C. Since the RFI key rate formula gives Eve less information when C is larger, the protocol overestimates the secure key. That directly affects the central quantitative claims.\n\nSecond, the paper uses Laing et al.'s RFI bound (Ref. [23]) for the ideal six states, but Alice's emitted states are mixtures over the post-selection intervals. No proof is given that the C parameter computed from observed error rates still bounds Eve's information for these mixed states. This is exactly the situation addressed by source-flaw analyses such as Ref. [25], which is cited but not used. The authors need to either prove the bound for their states or adopt a conservative analysis.\n\nThird, the probability density f(I,θ) in Eq. (23) appears mis-normalized. I did not compute the full integral, but the form does not obviously integrate to 1 over the domain. If it is wrong, all gains and rates are off. The reader flagged this, and it deserves checking before any numbers are quoted.\n\nThese are not minor issues. The protocol idea is fine, but the performance numbers are currently unjustified. I would send this to peer review because the topic is timely and the flaws are addressable: fix the C_L calculation, add a proper security argument for mixed states, and recheck the normalization. The likely outcome should be major revision, not acceptance. The reader's conditional verdict is fair.","headline":"The fully-passive/RFI combination is worth taking seriously, but the key-rate numbers are inflated by a backwards lower-bound in Eq. (38) and an unproven security argument.","tokens_in":18451,"tokens_out":4430,"would_cite":false,"duration_ms":38958,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":["03.67.Dd"],"model":"deepseek-v4-flash","headline":"A fully passive source can run reference-frame-independent quantum key distribution without active modulation, retaining more than half the ideal key rate and reaching 167 km at $10^{12}$ pulses.","keywords":["fully passive QKD","reference-frame-independent QKD","side-channel suppression","finite-key analysis","decoy-state method","post-selection interval","quantum key distribution","passive state preparation"],"falsifier":"Run the decoy-state finite-key analysis with a source-flaw security proof, replacing the ideal-state RFI bound by a bound valid for the worst-case mixture inside each post-selection interval; a substantial drop below 50% of the active-modulation rate would refute the paper's central claim. Experimentally, characterizing the actual distribution of emitted states and comparing the worst-case $C$ to the observed $C$ would show whether Eve can exploit the interval-induced deviations.","tokens_in":17390,"feed_emoji":"🔑","tokens_out":9692,"duration_ms":77708,"temperature":0.7,"pith_summary":"The paper proposes a reference-frame-independent quantum key distribution protocol whose transmitter is a fully passive source, removing the active modulation that creates side-channel vulnerabilities in earlier RFI-QKD implementations. It claims that by optimizing post-selection intervals and source intensities, the protocol reaches a secure key transmission rate above 50% of an ideal actively modulated QKD, and that with $10^{12}$ source pulses it achieves maximum distances of 167 km for aligned reference frames and 136 km for a 45-degree misalignment. The point is to show that passive-state generation and RFI's relaxed alignment requirement are compatible without sacrificing practical performance.","feed_headline":"Fully passive RFI QKD keeps over half of ideal key rate","feed_subtitle":"A passive source removes active-modulation side channels while reaching 167 km at 10^12 pulses","key_machinery":"The load-bearing object is the fully passive source plus the post-selection intervals: the source emits coherent pulses with random intensity and random Bloch-sphere angles, and intervals $S^y_Z$, $S^y_X$, $S^y_Y$ filter the pulses into approximate $Z$, $X$, and $Y$ basis states for the vacuum/decoy/signal intensity classes. Around that sits the RFI security parameter $C = \\langle X_AX_B\\rangle^2 + \\langle X_AY_B\\rangle^2 + \\langle Y_AX_B\\rangle^2 + \\langle Y_AY_B\\rangle^2$, which is independent of the reference-frame misalignment and, through the RFI security bound, bounds Eve's information from the observed single-photon error rates. The finite-key part uses decoy-state linear programming with concentration inequalities to bound single-photon yields and errors, and the protocol is optimized over the post-selection interval widths and source intensities.","core_discovery":"The central claim is that a fully passive source, which produces randomly distributed coherent states without active modulation, can replace Alice's six-state active preparation in RFI QKD while using the X and Y measurement correlations to bound Eve through the reference-frame-independent parameter $C$. The paper establishes a system model for the gain and error rate as integrals over the post-selected state intervals, optimizes the interval widths and intensities, and applies a decoy-state finite-key analysis based on a martingale concentration bound. On that basis it finds that the fully passive protocol reaches more than half the key rate of ideal actively modulated QKD, and its maximum distance can slightly exceed the active protocol in the infinite-key limit (215 km vs 214 km), with finite-key distances of 167 km and 136 km for misalignments of 0 and 45 degrees at $10^{12}$ pulses.","pith_inferences":["A security proof that accounts for the non-ideal emitted states (treating them as source flaws rather than ideal six states) would be needed to confirm the key-rate numbers; until then the reported rates assume the ideal-state RFI bound extends to the post-selected mixtures.","The performance dip at 45-degree misalignment suggests an adaptive strategy that rebalances the choice of $X$ and $Y$ bases or shrinks the post-selection windows could recover some of that lost rate; this is a testable extension.","The same fully passive transmitter could be nested inside measurement-device-independent or twin-field setups, where removing active-modulation side channels would combine with different distance advantages; the paper does not analyze that combination.","Since the finite-key bounds rely on trace distances between neighboring post-selection intervals, a tighter characterization of those intervals would directly improve the estimated key rate without changing the protocol."],"forward_implications":["The key rate of fully passive RFI QKD can exceed half that of ideal active-modulation QKD, making passive transmitters practical for RFI-type protocols.","At $10^{12}$ pulses the protocol reaches 167 km with aligned frames and 136 km at 45-degree misalignment, and a GHz source can accumulate this data in minutes.","Because the Z basis is reserved for key while X and Y bases are used for parameter estimation, the protocol uses the passively generated states more fully than earlier fully passive QKD.","The protocol removes the active-modulation side-channel attack surface (e.g., trojan-horse and unambiguous-state-discrimination attacks) on the source without requiring device-independent assumptions.","In the infinite-key limit the maximum distance (215 km) slightly exceeds that of the actively modulated RFI protocol (214 km), because the RFI bound constrains Eve more tightly."],"supporting_citations":[{"why":"Supplies the RFI security bound: the C parameter and Eve's information formula used in the key-rate equations.","marker":"[23]"},{"why":"Introduces the fully passive source that generates random states and intensities without active modulation.","marker":"[45]"},{"why":"Provides the probability-density model for the passive source output used in the gain and error-rate integrals.","marker":"[48]"},{"why":"Gives the finite-key security framework, decoy-state linear programming and concentration bounds used for parameter estimation.","marker":"[49]"},{"why":"Supplies the martingale concentration inequality used for the statistical fluctuation bounds in the finite-key analysis.","marker":"[56]"}],"fun_headline_variants":["Fully passive RFI QKD hits 167 km without active modulation","Passive source RFI QKD keeps 50% key rate, kills side channels","Fully passive QKD: no modulation, 167 km key distribution","RFI QKD goes passive: side-channel free, 167 km reach","Passive RFI QKD covers 167 km with half ideal key rate"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The key-rate formula assumes the reference-frame-independent security bound derived for six ideal states still limits Eve when Alice's emitted states are mixtures averaged over the post-selection intervals; if this bound fails for those imperfect states, the central security claim collapses.","fun_headline_variants_meta":{"raw":{"variants":["Fully passive RFI QKD hits 167 km without active modulation","Passive source RFI QKD keeps 50% key rate, kills side channels","Fully passive QKD: no modulation, 167 km key distribution","RFI QKD goes passive: side-channel free, 167 km reach","Passive RFI QKD covers 167 km with half ideal key rate"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000197,"raw_usage":{"total_tokens":1375,"prompt_tokens":966,"completion_tokens":409,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":582,"completion_tokens_details":{"reasoning_tokens":308}},"tokens_in":582,"tokens_out":409,"duration_ms":3803,"temperature":1.0,"reasoning_tokens":308,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-16T11:25:02.273580+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Run the decoy-state finite-key analysis with a source-flaw security proof, replacing the ideal-state RFI bound by a bound valid for the worst-case mixture inside each post-selection interval; a substantial drop below 50% of the active-modulation rate would refute the paper's central claim. Experimentally, characterizing the actual distribution of emitted states and comparing the worst-case $C$ to the observed $C$ would show whether Eve can exploit the interval-induced deviations.","supporting_citations":[{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Supplies the RFI security bound: the C parameter and Eve's information formula used in the key-rate equations."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Gives the finite-key security framework, decoy-state linear programming and concentration bounds used for parameter estimation."}],"review_version":1}