{"id":"01f925c4-73de-4d21-be21-a2e74520c778","arxiv_id":"2505.17502","paper_version":2,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":6,"one_line_summary":"A commercial QKD system inside a licensed research reactor encrypted reactor data at up to 320 kbps, with 82-140 km distances simulated by attenuators and a delay line.","lead":"Researchers installed a commercial quantum key distribution system inside Purdue's research reactor and used it to encrypt reactor signals in real time. The work is a first field-style test of QKD for nuclear facility communications, though the long distances were simulated with optical attenuators.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"All headline distances are emulated with attenuators plus a 32 km delay line, and the encrypted data path is a local LAN; without a real-fiber validation the 82/140 km and 54 km SKR/QBER claims do not yet support a complete end-to-end remote demonstration.","rationale":"The reader correctly identified the VOA-plus-delay-line emulation as the weakest assumption. I agree that this is the most load-bearing issue, and I would sharpen it: the encrypted data path itself is a local LAN, not the emulated fiber, so the claimed 'end-to-end' distance is even less directly supported. The authors do disclose the emulation equipment, so this is an overstatement in presentation rather than a fabrication. The core feasibility result - a commercial QKD system installed and operated in a reactor control room, with real-time encryption and decryption of reactor data - may still hold, because the QKD hardware did run locally and the software integration appears real. What does not yet hold is the specific quantitative claim that secure communications were demonstrated over 82-140 km of actual optical fiber under prototypic reactor conditions. That is why a conditional verdict is appropriate: the paper should either add a real-fiber validation or revise the abstract and conclusions to say 'attenuation-equivalent distance' and 'local data loop.' I therefore recommend no change to the reader's CONDITIONAL verdict.","tokens_in":26006,"tokens_out":7916,"duration_ms":68220,"concrete_test":"Run the same QKD-LD pair and workstations with QKD-Alice and QKD-Bob separated by a real 54 km and 82 km single-mode fiber link (spooled or installed campus fiber), keeping all other settings identical, and execute the full data loop (fetch, encrypt, transmit over that same real fiber or an equivalent WAN path, decrypt) for at least 24 hours. Compare the SKR and QBER distributions and the achieved OTP distance boundary with the emulator results. If QBER at 54 km stays within about 1 percentage point of 3.8% and SKR stays within about 20%, the emulation concern is resolved; otherwise the distance claims must be re-labeled as attenuation-equivalent and validated separately.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The headline distance claims are not measurements over deployed fiber. In Section 6, the 82/140 km channels are produced by combining a variable optical attenuator, two 10 dB fixed attenuators, and a 32 km GP800 delay line inserted between QKD-Alice and QKD-Bob; the paper reports no comparison with a real fiber link. A VOA adds loss but not the chromatic dispersion, polarization-mode dispersion, connector/backscatter losses, or slow polarization drift of 82-140 km of SMF. Phase-encoding decoy-state BB84 (T12) is sensitive to phase instability and QBER; the quoted 3.8% QBER at 54 km and 7.5% at 145 km are emulator values, so the secret-key-rate-versus-distance curve may not transfer to real deployment. Moreover, the encrypted reactor data did not travel over those fibers: WA and WB communicate over a regular TCP/IP LAN (Section 6, Figure 6), so 'real-time encryption and decryption of 2,000 signals over optic fiber distances up to 82 km' describes a local data loop with an emulated QKD channel, not an end-to-end remote link at that distance. The central 'complete end-to-end demonstration under prototypic conditions' therefore rests on an unvalidated surrogate for both the channel physics and the geographic remoteness.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper reports an experimental demonstration of a commercial phase-encoding decoy-state BB84 QKD system (Toshiba QKD-LD) installed at Purdue's PUR-1 research reactor. The authors measure secret key rate (SKR) and quantum bit error rate (QBER) over emulated fiber lengths using a variable optical attenuator, fixed attenuators, and a 32 km delay line, and they combine these measurements with a key-pool bookkeeping model to evaluate key availability, required QKD lead times, and post-failure secure uptimes for two reactor monitoring use cases (68 core signals and 2,000 signals) with OTP, AES-256, and ASCON encryption. They also report end-to-end latency measurements for encrypted reactor data exchanged between two workstations over a local TCP/IP LAN.","tokens_in":26304,"tokens_out":5984,"duration_ms":47534,"significance":"The paper's value lies in the system integration and operational characterization: a commercial QKD system was operated for 10-hour intervals in a reactor control room, with stable SKR/QBER records, a clearly formulated key-availability model that uses measured SKR data as inputs rather than fitting the target results, and extensive latency measurements for multiple ciphers. The bookkeeping model for the dynamic key pool and the lead-time calculations are useful engineering contributions. However, the headline distances (82 km, 135 km, 140 km) are emulated with attenuators plus a 32 km delay line, and the encrypted reactor data path is a local LAN, not a fiber link spanning those distances. As a result, the abstract's 'complete end-to-end demonstration' over those distances overstates what was actually measured, and the transferability of the SKR-versus-distance results to real deployed fiber remains unvalidated.","major_comments":[{"comment":"The distance claims are based on an emulated channel, not deployed fiber. The 82 km, 135 km, and 140 km points are produced by combining a variable optical attenuator, two fixed 10 dB attenuators, and a 32 km GP800 delay line inserted between QKD-Alice and QKD-Bob. The paper reports no comparison with a real single-mode fiber link. A VOA adds loss but does not reproduce the chromatic dispersion, polarization-mode dispersion, connector/backscatter losses, or slow polarization drift of 82–140 km of SMF. Phase-encoding decoy-state BB84 is sensitive to phase instability and QBER, so the quoted 3.8% QBER at 54 km and 7.5% at 145 km are emulator values. The abstract and conclusions should qualify these distances as emulated, or the authors should add a real-fiber validation, before claiming a complete end-to-end demonstration at those distances.","section":"Section 6, Figure 7"},{"comment":"The encrypted reactor data did not travel over the emulated fiber at all. Terminals W_A and W_B communicate via a regular TCP/IP non-dedicated LAN, while the quantum and classical QKD channels are separate fibers intercepted by the attenuation and delay equipment. Therefore, the statement in the abstract that the system executed 'real-time encryption and decryption of 2,000 signals over optic fiber distances up to 82 km' describes a local data loop with an emulated QKD channel, not an end-to-end remote link spanning 82 km. The geographic remoteness and any distance-dependent effects on the encrypted data path are not demonstrated; the wording should be corrected or the experiment should be extended to send encrypted data over the same fiber span used for key generation.","section":"Section 6, Figure 6"},{"comment":"The paper claims 'unconditional secure remote communications' and 'information-theoretic security' for the OTP use case, but the security analysis is not presented. The SKR and QBER are the outputs of the commercial Toshiba system's internal T12 implementation, and no finite-key security parameters, security proof assumptions, or device calibration details are reported. If the security claim is intended as a central contribution, the manuscript must either cite the specific security proof and parameter regime applicable to the deployed system or explicitly state that the security level is that implemented by the vendor. Without this, the 'quantum-secure' wording is stronger than what the paper itself establishes.","section":"Section 7.1 and Section 2"},{"comment":"No radiation dose or electromagnetic interference measurements are reported for the reactor environment. The installation is in the PUR-1 control room, and Section 3 correctly notes that 'it remains to be shown whether radiation environments would affect QKD performance'; this work does not close that gap. The phrase 'under prototypic conditions on PUR-1' in the abstract should therefore be limited to the control-room environment, and the conclusions should not imply that operation in more demanding radiation or EMI environments has been demonstrated.","section":"Section 5 and Section 6"}],"minor_comments":[{"comment":"The sentence 'Equations 26- 28 can be handful to determine...' contains a typo; 'handful' should be 'helpful'.","section":"Section 4.5"},{"comment":"The text refers to 'OPT' in 'unlike OPT, the block cipher defines a fixed key length'; this should be 'OTP'.","section":"Section 7.3"},{"comment":"Figure 7's x-axis starts at 60 km, but the text and Figure 8 report data at 50 km and 54 km; please clarify the exact set of replicated distances plotted in Figure 7.","section":"Section 7.1, Figures 7 and 8"},{"comment":"Equation (3) uses g(E) without an explicit definition in the main text; the surrounding text describes error correction and privacy amplification, but a formal definition of g would improve readability.","section":"Section 2, Equation (3)"},{"comment":"The use-case results depend on the selection of 68 core signals and the assumption of 32-bit precision, both of which are motivated by domain knowledge; the manuscript should briefly state how sensitive the maximum achievable distances are to these choices, since a different signal set or precision would change the key consumption rates.","section":"Section 5 and Tables 4–8"}],"recommendation":"major_revision","confidential_remarks":"The manuscript's engineering content is sound and the key-pool model is clearly presented, but the framing overstates the end-to-end nature of the demonstration. The emulated distances and local LAN data path are described transparently in Section 6, so I do not see an integrity issue, but the abstract and conclusions need to be aligned with what was actually measured. If the authors add a real-fiber comparison or explicitly re-scope the claims to 'emulated distances' and 'local data loop', the paper could be suitable for publication. I would not recommend rejection because the core measurements and modeling are useful to the nuclear cybersecurity community."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"The one thing to know: this is the first experimental QKD run inside a licensed reactor, and the authors have honest, consistent performance data. The caveat: all long-distance numbers come from attenuators plus a 32 km delay line, and the encrypted data never traveled over those fibers. So the 82/140 km 'end-to-end' claim is an overstatement as written.\n\nWhat is genuinely new: the nuclear QKD literature so far is simulations and concept studies. The 10-hour runs at each distance, with SKR/QBER statistics and time traces, are solid. The key-pool and lead-time model is a sensible engineering tool, and the latency benchmarks across OTP/AES/ASCON are useful. The self-citations to the simulator and feasibility study are appropriate and do not force the result; the measurement is the core contribution.\n\nThe load-bearing weakness is the emulator. A VOA adds loss but no chromatic dispersion, PMD, connector backscatter, or slow polarization drift, and phase-encoding decoy-state BB84 is sensitive to exactly those. No validation against a real fiber spool is reported. The reactor control room is presumably a benign environment, but no radiation dose or EMI measurements are given, so 'prototypic conditions' is not established. Also, the encrypted data path is a local TCP/IP LAN, so the real-time encryption loop did not cross the emulated distance; that distinction should be explicit. Minor: labeling ASCON-80pq as 'post-quantum' is an overclaim; it is a lightweight AEAD with some margin, not a NIST PQC finalist. Raw data and code are not released, which limits independent checking, though the numbers are internally consistent and align with the system's 30 dB loss design.\n\nThis paper will be cited as the first QKD-in-reactor demonstration. For reactor cybersecurity and QKD field-deployment readers, it is worth reading. For a QKD specialist, the distance claims are not yet validated. It deserves a serious referee, but the revision should either validate the emulated link against real fiber or clearly separate 'demonstrated in the lab at 54 km' from 'system supports up to 140 km in emulation.' Send it to peer review with that condition attached.","headline":"First QKD-in-reactor deployment with usable data, but the headline distances are emulated and the 'end-to-end' claim outruns the setup.","tokens_in":26850,"tokens_out":1817,"would_cite":false,"duration_ms":21443,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"A quantum key distribution system encrypted live reactor data in a working nuclear reactor at 320 kbps.","keywords":["quantum key distribution","BB84","decoy state","nuclear reactor cybersecurity","one-time pad","AES-256","secret key rate","latency measurement"],"falsifier":"Set up the same QKD hardware on a true 54 km and a true 140 km single-mode fiber link (or an installed dark-fiber route), compare the measured SKR and QBER against the attenuator-plus-delay-line data, and simultaneously log radiation dose and electromagnetic interference at the QKD rack during reactor operation to see whether QBER tracks those levels.","tokens_in":25798,"feed_emoji":"⚛️","tokens_out":8853,"duration_ms":93397,"temperature":0.7,"pith_summary":"This paper tries to establish that a commercial phase-encoding decoy-state BB84 QKD system can be installed in a working nuclear reactor's control room, generate secret keys at a practical rate, and encrypt real instrumentation signals in real time with acceptable latency. If true, future remote-operated microreactors and fission batteries could protect real-time control and monitoring data against quantum-capable attackers, reaching information-theoretic security with OTP or stronger key refresh with AES-256 and lightweight ciphers. The authors build a communication model with latency and key-availability conditions and validate it with ten-hour runs at each replicated distance: a stable 320 kbps secret key rate and 3.8% quantum bit error rate at 54 km, OTP encryption of 2,000 signals out to 82 km, 68 core signals out to 135 km, and AES-256 out to 140 km.","feed_headline":"Quantum keys encrypt live reactor data at 320 kbps","feed_subtitle":"A decoy-state BB84 system held a 3.8% error rate at 54 km and secured reactor signals with OTP out to 135 km.","key_machinery":"The carrying object is the phase-encoding decoy-state BB84 protocol in the T12 variant, which mixes signal states with one decoy and a vacuum state using asymmetric basis selection. The system is analysed with the standard secret key rate decomposition $SKR = R_{raw}\\eta_{sift}g(E)$, where the raw rate comes from source repetition, detector efficiency, and channel transmissivity $t_{chan}=10^{-al/10}$, and the decoy states allow a lower bound on single-photon contributions. Around that hardware, the paper builds a communication model with eight parameters (signal count, sampling and reporting rates, precision, key-reusability factor, channel length, QBER, autonomy), three constraint conditions (latency inequality, key-availability inequality, post-failure uptime inequality), and a dynamic key pool whose size is updated by key contributions minus consumption. The model converts a fixed QKD measurement into operational decisions: whether a use case is feasible, how much lead time is needed, and how long secure communication survives a key-distribution failure.","core_discovery":"The paper's central claim is that QKD is compatible with the operational constraints of a fully digital nuclear reactor's instrumentation and control environment. Using a commercial long-distance phase-encoding decoy-state BB84 QKD system, the authors report end-to-end real-time encryption and decryption of reactor data with a stable secret key rate of approximately 320 kbps and a QBER of about 3.8% at 54 km over a ten-hour period. The same setup encrypted 2,000 signals with OTP out to approximately 82 km, and the 68 core reactor signals out to approximately 135 km at 1 Hz; with AES-256 the distance reaches 140 km. The paper also derives and applies a dynamic key-pool model showing that a short QKD lead time removes the dead time at long distances, and that switching from OTP to AES-256 after a QKD failure extends encrypted uptime from under an hour to several hours or more.","pith_inferences":["Because distance was emulated with attenuators and a delay line, the headline distance figures would hold for real deployment only if that emulation faithfully reproduces fiber dispersion and polarization drift; the authors do not validate this against a physical link.","If the emulation is faithful, the same eight-parameter model could be reused to size key pools and lead times for other critical infrastructure, such as power grids, dams, or remote industrial facilities, with minimal adaptation.","The OTP-to-AES failover strategy suggests a graceful-degradation path for reactor communications that does not require reactor shutdown, which aligns with the stated nuclear-sector requirement of avoiding plant trips.","A natural next experiment would be to run the same QKD hardware over a real dark fiber of comparable length and to log radiation dose and EMI in the reactor room, checking whether QBER tracks those environmental variables."],"forward_implications":["At 54 km the system sustained a 320 kbps secret key rate with a 3.8% error rate over ten hours, which is enough to encrypt the reactor's core signals in real time at 1 Hz.","OTP encryption of all 2,000 reactor signals is feasible up to about 82 km, and 68 core signals up to about 135 km at 1 Hz, with no key shortage once a short lead time is applied.","AES-256 raises the maximum distance to 140 km for data-heavy use cases and, after a QKD failure, keeps encrypted communication available for hundreds of hours at short distances and at least tens of minutes at the longest distances.","QKD key request and delivery dominates end-to-end latency (about 245 ms), so the tested OTP, AES-256, and ASCON schemes all satisfy a 1 Hz reporting deadline, while 10 Hz reporting remains marginal.","A dynamic key pool with a small QKD lead time removes the startup dead time observed at long distances and provides a reserve that can be drawn down during outages."],"supporting_citations":[{"why":"introduces BB84, the protocol family whose phase-encoding decoy-state variant is used in the demonstration.","marker":"[19]"},{"why":"defines the T12 phase-encoding decoy-state protocol and the secret-key-rate model used to analyse the measured system.","marker":"[44]"},{"why":"supplies the efficient decoy-state protocol with quantified security that the commercial QKD hardware implements.","marker":"[70]"},{"why":"introduces the decoy-state technique that lets practical imperfect sources approach ideal QKD security.","marker":"[45]"},{"why":"defines the REST-based key delivery API used by the key management servers to hand keys to the encryption workstations.","marker":"[71]"},{"why":"provides the 0.2 dB/km attenuation figure used to convert measured loss into equivalent fiber distance.","marker":"[72]"},{"why":"specifies AES-256, the alternate encryption mode used for extended distance and post-failure scenarios.","marker":"[73]"}],"fun_headline_variants":["Quantum key distribution secures nuclear reactor data","QKD protects reactor signals over 135 km","BB84 quantum encryption tested on live reactor","Nuclear reactor data encrypted with quantum keys at 320 kbps","Quantum-secure link works in reactor environment"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The load-bearing premise is that a bench of attenuators and a 32 km delay line reproduces what happens over 82–140 km of real single-mode fiber in terms of attenuation, dispersion, and polarization drift, and that the reactor control room's unmeasured radiation and electromagnetic environment is representative of future deployments.","fun_headline_variants_meta":{"raw":{"variants":["Quantum key distribution secures nuclear reactor data","QKD protects reactor signals over 135 km","BB84 quantum encryption tested on live reactor","Nuclear reactor data encrypted with quantum keys at 320 kbps","Quantum-secure link works in reactor environment"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000463,"raw_usage":{"total_tokens":2369,"prompt_tokens":1058,"completion_tokens":1311,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":674,"completion_tokens_details":{"reasoning_tokens":1239}},"tokens_in":674,"tokens_out":1311,"duration_ms":10427,"temperature":1.0,"reasoning_tokens":1239,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-07T14:45:08.250214+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Set up the same QKD hardware on a true 54 km and a true 140 km single-mode fiber link (or an installed dark-fiber route), compare the measured SKR and QBER against the attenuator-plus-delay-line data, and simultaneously log radiation dose and electromagnetic interference at the QKD rack during reactor operation to see whether QBER tracks those levels.","supporting_citations":[{"cited_title":"Quantum cryptography: Public key distribution and coin tossing,","cited_arxiv_id":null,"evidence_quote":"introduces BB84, the protocol family whose phase-encoding decoy-state variant is used in the demonstration."},{"cited_title":"10-Mb/s Quantum Key Distribution,","cited_arxiv_id":null,"evidence_quote":"defines the T12 phase-encoding decoy-state protocol and the secret-key-rate model used to analyse the measured system."},{"cited_title":"Efficient decoy-state quantum key distribution with quantified security,","cited_arxiv_id":null,"evidence_quote":"supplies the efficient decoy-state protocol with quantified security that the commercial QKD hardware implements."},{"cited_title":"Quantum Key Distribution with High Loss: Toward Global Secure Communication","cited_arxiv_id":"quant-ph/0211153","evidence_quote":"introduces the decoy-state technique that lets practical imperfect sources approach ideal QKD security."},{"cited_title":"ETSI GS QKD 014: Quantum Key Distribution (QKD); Protocol and data format of REST-based key delivery API,","cited_arxiv_id":null,"evidence_quote":"defines the REST-based key delivery API used by the key management servers to hand keys to the encryption workstations."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"provides the 0.2 dB/km attenuation figure used to convert measured loss into equivalent fiber distance."},{"cited_title":"Advanced Encryption Standard (AES),","cited_arxiv_id":null,"evidence_quote":"specifies AES-256, the alternate encryption mode used for extended distance and post-failure scenarios."}],"review_version":1}