{"id":"593e460d-6647-4a02-8236-58ef5c4cdfac","arxiv_id":"2507.00095","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":3,"one_line_summary":"A trap-based quantum message authentication protocol for continuous-variable states is shown to be eta-secure with eta=(n/(n+2z))^(t+1).","lead":"This paper proposes the first message authentication scheme for continuous-variable quantum states, using hidden squeezed 'trap' states to detect tampering. It also derives a continuous-variable version of the Pauli twirl and proves a security bound for the scheme.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Finite-variance CV twirl and step-function trap acceptance are replaced by ideals without an error bound, so Eq. (33)'s eta is not established for the finite-parameter scheme.","rationale":"The most load-bearing point is not the existence of ideal resources but the status of the proof. The CV twirl lemma is correct as stated, and the counting argument is sound; the problem is the unquantified transition from a finite-variance Gaussian kernel to a Dirac delta. Because the scheme's encryption key has finite variance, this transition is part of the scheme, not a separate resource assumption. The same applies, more explicitly, to the G-approx-I step, which the authors themselves defer. Under these idealizations the proof works; hence the result is plausible and novel. But the security definition (2.3) is an exact statement about the real channel for the scheme as defined, and Eq. (33) asserts an upper bound without the missing error term. That justifies a conditional verdict: accept the contribution conditional on a rigorous finite-Delta and finite-squeezing error analysis. The reader's conditional verdict already captures this, so no change in verdict is needed.","tokens_in":11991,"tokens_out":7395,"duration_ms":95767,"concrete_test":"Re-derive the real-world channel (14)-(19) without replacing e^{-2 Delta^2 |alpha-alpha'|^2} by delta(alpha-alpha'). For a concrete attack, e.g. U_CR = (D(beta) tensor 1_R + D(beta') tensor U_R)/sqrt(2) with two displacement amplitudes, compute the exact trace distance to the ideal channel (26) as a function of Delta. Determine whether the extra term can be bounded by a function tending to 0 as Delta grows, uniformly over beta and beta'; if the bound depends on |beta-beta'| in a way that survives the attack's normalization, or if it cannot be made smaller than eta/2 while keeping epsilon_dec small, then Eq. (33) is not established for finite Delta.","verdict_should_be":"UNCHANGED","load_bearing_attack":"Eq. (33) states security with eta=(n/(n+2z))^(t+1), but the derivation passes through two unquantified idealizations. First, after Lemma 4.1 the text says 'We treat the Gaussian factor ... as a Dirac delta function.' For finite Delta (the QOTP variance, only required to be much larger than 1), Lemma 4.1 yields e^{-2 Delta^2 |alpha-alpha'|^2} D(alpha) rho D^dagger(alpha') with nonzero off-diagonal terms. Dropping them changes the real-world channel (19): the exact expression contains an integral over alpha, alpha' with the Gaussian kernel, and the subsequent replacement by |chi(alpha)|^2 is not an equality. No bound is given for the trace-norm distance between the finite-Delta channel and its Delta-to-infinity limit. Since the scheme explicitly uses finite Delta, this gap is internal to the proof, not merely a physical approximation. Second, G in (18) is a continuous product of error functions, not the indicator I; the paper assumes G approximately equals I and states in Sec. 5 that a rigorous treatment is future work. Yet Eq. (33) is stated without an added error term. The final claim therefore holds only for an idealized limit of the scheme; for the actual finite-parameter scheme the trace distance is at best bounded by eta plus an unspecified epsilon(Delta, r, epsilon, ...).","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper proposes the first continuous-variable (CV) quantum message authentication scheme, adapting the discrete-variable trap-code construction of Broadbent et al. [1] and the simulator-based proof approach of Broadbent and Wainewright [2]. The scheme encodes a single-mode message into n modes using a CV-QECC, appends 2z squeezed trap states, applies a secret permutation and a Gaussian CV one-time pad, and verifies the traps by homodyne detection. The security proof introduces a CV analogue of the Pauli twirl (Lemma 4.1), compares the real channel with an ideal simulator based on EPR pairs, and concludes with the counting bound eta = (n/(n+2z))^(t+1) in Eq. (33). The authors state in Sec. 5 that a more rigorous treatment of the approximate step functions is left for future work.","tokens_in":12327,"tokens_out":8147,"duration_ms":83773,"significance":"If made rigorous, this would be a useful first step toward CV quantum message authentication: the construction is simple, the trade-off between the number of traps and the security parameter is explicit, and the CV twirl lemma is a reusable technical tool. The paper credibly transfers the DV trap-code idea to CV systems and identifies the main new obstacles, namely the approximate twirl, the approximate acceptance step, and finite-squeezing effects. The main limitation is that the headline claim, Eq. (33), is currently stronger than what is proven: the derivation passes through several ideal limits without quantified error bounds. Filling those gaps would turn a plausibly correct idealized proof into a rigorous security statement for the actual finite-parameter scheme.","major_comments":[{"comment":"The replacement of the Gaussian factor e^{-2Delta^2|beta-beta'|^2} by a Dirac delta is an unquantified idealization. For finite QOTP variance Delta^2, which the scheme explicitly allows (only Delta^2 >> 1 is required), Lemma 4.1 keeps off-diagonal terms with beta != beta'; dropping them changes the real-world channel from the exact expression preceding Eq. (19) to an approximate one. No trace-norm bound is provided for the distance between the finite-Delta channel and its Delta-to-infinity limit, and the final bound (33) contains no such error term. Consequently, Eq. (33) is not established for the finite-parameter scheme as described.","section":"Sec. 4.3, Lemma 4.1 and Eq. (19)"},{"comment":"The acceptance function G defined in Eq. (18) is a product of error functions, not an exact indicator, and the paper explicitly states in Sec. 5 that a rigorous treatment of the step-function approximation is future work. Yet the derivation of Eq. (33) uses the claim, immediately after Eq. (30), that 'G - I evaluates either to 0 or 1' and Table 1, both of which hold only in the exact-step idealization. For finite e^{-r/2} << epsilon, G takes intermediate values, so |G - I| is not a 0/1-valued function and the counting argument (31) does not directly apply. An additive error term depending on epsilon and r must be included in eta, or the theorem must be restated with explicit bounds.","section":"Sec. 4.5 and Sec. 5, Eqs. (18) and (30)"},{"comment":"The ideal channel in Sec. 4.4 uses the s -> infinity limit of the two-mode squeezed vacuum, which is a non-normalizable state; the derivation after Eq. (25) then uses Dirac delta functions such as delta(beta - pi^{-1} alpha). No error bound is given for finite s, and the trace distance between the real and ideal channels is not defined if the ideal channel is only a formal limit. This is another load-bearing idealization that needs either a rigorous limiting argument or a quantitative error term.","section":"Sec. 4.3 and Sec. 4.4"},{"comment":"The proof expands an arbitrary adversary unitary U_CR as integral over displacements, U_CR = integral d^2alpha chi(alpha) D_C(alpha) otimes U_R^alpha with integral |chi(alpha)|^2 = 1. In the DV setting this is justified by the finite Pauli basis, but in CV the displacement operators are unbounded and form only a distributional basis; the existence of a normalized coefficient function chi(alpha) for every unitary attack is not established. This expansion underlies the transition from Eq. (14) to Eq. (19) and from Eq. (24) to Eq. (26), so it is a central technical assumption that should be stated and justified.","section":"Sec. 4.3, attack expansion"}],"minor_comments":[{"comment":"The definition of a CV-QECC that corrects arbitrarily large displacements would benefit from a citation; no reference is given for such codes, and the assumption is stronger than what standard CV codes provide.","section":"Sec. 2.1"},{"comment":"The square-root notation on the POVM elements is redundant because V^acc and V^rej are projectors; simplifying the expression would improve readability.","section":"Sec. 3, Eq. (9)"},{"comment":"The text says the EPR state can be represented as a '50/50 beamsplitter mixture' of two squeezed vacua; more precisely, the two-mode squeezed vacuum is obtained by applying a beamsplitter transformation to two squeezed vacua, not by a mixture.","section":"Sec. 4.4, Eq. (20)"},{"comment":"Writing the same factor u! in both numerator and denominator is confusing; defining P(u) directly as C(n,u)/C(n+2z,u) would be cleaner.","section":"Sec. 4.5, Eq. (31)"},{"comment":"The parameter conditions 'Delta^2 >> 1' and 'e^{-r/2} << epsilon' are used throughout without quantitative thresholds; these inequalities are exactly where the missing error terms in Eq. (33) originate, so indicative bounds would be helpful.","section":"Sec. 3 and Sec. 4.5"}],"recommendation":"major_revision","confidential_remarks":"The manuscript is original and the idealized proof is plausible, but the central security claim as stated exceeds what is proven. The authors themselves acknowledge the step-function gap in Sec. 5, and the finite-Delta twirl gap is likewise internal to the proof. These are fixable by adding explicit error terms or by restating the theorem with an additive epsilon(Delta, r, epsilon). I would not recommend rejection; the construction and the CV twirl are valuable contributions once the idealizations are quantified."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Two things to know. First, this is a genuine first: a message authentication scheme for continuous-variable states, built from trap states with a variable number of traps. Second, the headline bound in Eq. (33), eta = (n/(n+2z))^(t+1), is proved for an idealized limit of the scheme, and the authors themselves flag part of the idealization in Sec. 5. The proof has a real gap, but the paper deserves a serious referee.\n\nWhat is genuinely new: the CV adaptation of the trap code, the variable trap number, and the CV displacement twirl. Lemma 4.1 is a correct Gaussian integral and is the right tool for the CV setting. The simulator construction follows Broadbent--Wainewright but the translation to EPR pairs, the POVM, and the counting argument are done cleanly. The counting bound is transparent and not circular. Citation practice is fine; prior trap and QAS work is credited.\n\nThe soft spots are in the two idealizations, and the stress-test note lands. First, after Lemma 4.1 the paper treats the Gaussian factor e^{-2 Delta^2 |alpha-alpha'|^2} as a Dirac delta. For finite Delta, the real-world channel keeps off-diagonal terms in alpha, alpha'; replacing them with |chi(alpha)|^2 is not an equality, and no trace-norm bound is supplied. Since the scheme explicitly uses finite Delta, this is an internal proof gap, not just a physical approximation. Second, G in (18) is a product of error functions, not the indicator I; the paper assumes the step-function regime and Sec. 5 says a rigorous treatment is future work. Yet Eq. (33) is stated without an added error term. So as written, the security guarantee holds for the ideal channel/simulator, not for the finite-parameter protocol. There is also the standing assumption of a CV-QECC correcting arbitrarily large displacements in up to t modes, which no finite-resource code achieves; this is an idealization inherited from the DV-style proof and should be stated as such.\n\nNone of this kills the contribution. The scheme is plausible and the proof scaffolding is sound enough for a first CV construction. The fix is also clear: quantize the finite-Delta and step-function errors, or state the result explicitly as security in the ideal limit with a separate epsilon(Delta, r, epsilon). I would bring this to a reading group and would cite it as the first CV QAS, with the caveat noted.\n\nRecommendation: send to peer review. With a serious referee asking for the missing error bounds, this can become a solid paper.","headline":"First CV trap-code QAS with a sound CV twirl, but Eq. (33)'s security bound is proved in an idealized limit; the finite-parameter gaps are real and unquantified.","tokens_in":12777,"tokens_out":2044,"would_cite":true,"duration_ms":26477,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["81P94","81P45","94A60"],"pacs":["03.67.Dd"],"model":"deepseek-v4-flash","headline":"The paper introduces the first quantum authentication scheme for continuous-variable states and proves, in an idealized limit, that tampering is detected except with probability below n/(n+2z) raised to the power t+1.","keywords":["continuous-variable quantum authentication","trap codes","CV twirl","quantum message authentication","quantum one-time pad","continuous-variable quantum error correction","security proof","squeezed states"],"falsifier":"Concretely: fix finite $\\Delta$ and $r$, choose a displacement attack with $u=t+1$ noisy modes placed in the message register, and compute the trace distance between the real and simulator channels; a value above $(n/(n+2z))^{t+1}$ would show the idealized bound does not extend to that regime.","tokens_in":11806,"feed_emoji":"🔐","tokens_out":10306,"duration_ms":100062,"temperature":0.7,"pith_summary":"This paper claims to give the first message-authentication scheme for continuous-variable (CV) quantum states, a gap in the literature because earlier quantum authentication protocols were built for discrete-variable qubit systems. The scheme encodes a one-mode message with a CV quantum error-correcting code, inserts $2z$ squeezed trap modes, applies a secret permutation and a Gaussian-displacement one-time pad, and accepts only if homodyne checks on all traps pass. Its central result is a simulator-based security proof bounding the probability that any tampering goes undetected by $\\eta = (n/(n+2z))^{t+1}$. That result matters because CV states are the natural fit for existing optical communication, and authentication protects the quantum data itself rather than only classical keys. The proof is carried out in an idealized limit--the CV twirl factor becomes a delta function and the trap acceptance becomes a step function--with finite-resource corrections left for future work.","feed_headline":"Trap states authenticate continuous-variable quantum messages","feed_subtitle":"First security proof for CV quantum authentication; failure chance below (n/(n+2z))^(t+1).","key_machinery":"The load-bearing object is the CV twirl, the continuous-variable counterpart of the Pauli twirl: averaging a displaced state over Gaussian displacements $D(\\gamma)$ produces the identity\n$$\\int_\\mathbb{C} \\frac{$d^{2}$\\gamma}{2\\pi\\$\\Delta$^2} e^{-|\\gamma|^2/(2\\$\\Delta$^2)} D^\\dagger(\\gamma)D(\\$\\beta$)\\rho D^\\dagger(\\$\\beta$')D(\\gamma) = e^{-2\\$\\Delta$^2|\\$\\beta$-\\$\\beta$'|^2} D(\\$\\beta$)\\rho D^\\dagger(\\$\\beta$'),$$\nwhose Gaussian prefactor acts as a Dirac delta for large key variance $\\Delta$. The second mechanism is the pair of indicator functions used in the proof: the real-world acceptance function $G(\\pi,\\vec\\alpha)$, a product of error functions that is nearly a step function for strong squeezing $r\\gg1$ and $\\epsilon\\gg e^{-r/2}$, and the simulator's ideal acceptance indicator $I(\\pi^{-1}\\vec\\alpha\\in D_F)$. The proof controls the difference $G-I$, which is nonzero only when all traps pass but more than $t$ message modes are displaced, and then bounds the permutation probability of that event.","core_discovery":"On the paper's own terms, the discovery is that the discrete-variable trap-code authentication construction can be transplanted to continuous-variable modes and the transplant can be proven secure. Encoding interleaves the QECC-encoded message with $z$ position-squeezed and $z$ momentum-squeezed states, then randomizes by a secret permutation and a Gaussian-displacement quantum one-time pad. Decoding undoes these steps and accepts only if all trap quadratures lie within $\\pm\\epsilon$; the average over one-time-pad keys is evaluated by a new continuous-variable analogue of the Pauli twirl, whose Gaussian factor acts as a delta function for large key variance. Comparing the real channel with an EPR-based simulator reduces security to a counting problem: the only bad event is that all traps are intact while the message has uncorrectable noise, and a random permutation places the noisy modes into message positions with probability below $(n/(n+2z))^{t+1}$. The paper states this as satisfying the security definition with $\\eta = (n/(n+2z))^{t+1}$.","pith_inferences":["The paper leaves the finite-$\\Delta$ and finite-$r$ corrections implicit; computing them would give an additive correction to $\\eta$ rather than a structural change, and would state the security level that finite-resource implementations actually achieve.","The CV twirl identity holds for arbitrary states, so the same delta-function technique could be exported to security proofs for other CV primitives, such as Gaussian private quantum channels or CV secret sharing, wherever a Gaussian one-time pad is averaged.","The idealized assumption of a QECC that corrects arbitrarily large displacements is not met by physical CV codes; re-running the argument with a finite correction radius would convert the theorem into a resource-counted statement with an explicit squeezing-to-security trade-off."],"forward_implications":["A sender and receiver sharing a classical key can authenticate a single-mode CV quantum message, with the security parameter tuned by the number $z$ of trap pairs; taking $n=1$ and $2z=2$ recovers the discrete-variable form $(1/3)^{t+1}$.","The required operations--squeezed states, displacement operations, random permutations, and homodyne detection--are all realizable on current optical platforms, so the construction is candidate-implementable.","The CV twirl derived for the proof is a standalone tool: any CV protocol whose security argument averages over a Gaussian one-time pad can reuse the identity directly.","Multi-mode messages can be authenticated either by authenticating each mode separately or by encoding the multi-mode message into a larger QECC, extending the same security analysis blockwise."],"supporting_citations":[{"why":"Supplies the discrete-variable trap-code construction that this scheme adapts to continuous variables.","marker":"[1]"},{"why":"Supplies the simulator-based security proof structure and the security definition the paper follows.","marker":"[2]"},{"why":"Establishes the quantum authentication setting and the security definitions the paper modifies.","marker":"[14]"},{"why":"Provides the displacement-operator commutation relation used to derive the CV twirl identity.","marker":"[25]"},{"why":"Provides the two-mode squeezed vacuum form of the EPR state used in the simulator's ideal channel.","marker":"[26]"}],"fun_headline_variants":["First CV quantum authentication with security proof","Trap-state authentication for CV quantum messages","CV quantum message authentication via trap states","Secure quantum messages in CV with trap states"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The security proof is valid only in an idealized limit: the twirl factor is treated as a perfect delta function, the trap check as an exact on-off step, and the error-correcting code is assumed to correct arbitrarily large displacements, none of which holds exactly with finite squeezing, finite key width, or finite-resource codes.","fun_headline_variants_meta":{"raw":{"variants":["First CV quantum authentication with security proof","Trap-state authentication for CV quantum messages","CV quantum message authentication via trap states","Secure quantum messages in CV with trap states"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000687,"raw_usage":{"total_tokens":3062,"prompt_tokens":839,"completion_tokens":2223,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":455,"completion_tokens_details":{"reasoning_tokens":2170}},"tokens_in":455,"tokens_out":2223,"duration_ms":17584,"temperature":1.0,"reasoning_tokens":2170,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-06T21:33:23.006670+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Concretely: fix finite $\\Delta$ and $r$, choose a displacement attack with $u=t+1$ noisy modes placed in the message register, and compute the trace distance between the real and simulator channels; a value above $(n/(n+2z))^{t+1}$ would show the idealized bound does not extend to that regime.","supporting_citations":[{"cited_title":"In: Advances in Cryptology – CRYPTO 2013, Part II","cited_arxiv_id":null,"evidence_quote":"Supplies the discrete-variable trap-code construction that this scheme adapts to continuous variables."},{"cited_title":"Springer, Berlin, Heidelberg (1994)","cited_arxiv_id":null,"evidence_quote":"Provides the displacement-operator commutation relation used to derive the CV twirl identity."},{"cited_title":"Physical Review A 61(5), 052101 (2000) 15","cited_arxiv_id":null,"evidence_quote":"Provides the two-mode squeezed vacuum form of the EPR state used in the simulator's ideal channel."}],"review_version":1}