{"id":"2498b063-7d6a-4f4d-b3a9-d50ff02061b7","arxiv_id":"2507.00625","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":5,"one_line_summary":"A two-laser, modulator-free transmitter prepares time-bin QKD states, and a decoy-free three-state protocol is analyzed, giving an estimated secure range near 40 km.","lead":"This paper describes and demonstrates a modulator-free laser transmitter for quantum key distribution in city networks. It claims secure key rates over tens of kilometers using a simpler three-state protocol without decoy states.","discovery_kind":"new_method","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The claimed 40 km secure range rests on Eq. (30), which extends the Fung–Lo bound to the mixed qutrit states of Eq. (27) by the assertion 'one can show'; if that extension fails, the decoy-free key rate is unsupported, independent of phase-randomness verification.","rationale":"The paper's experimental demonstration is real but does not include a full QKD run, so the security section is the load-bearing part. I checked the other quantitative pieces and found them plausible: the lower bound on Q_{0+1} via Q_μ - [1 - (1+μ)e^{-μ}] is a valid inequality, and the parameter choices are reasonable. The single genuinely unsupported step is the extension of the Fung–Lo bound to the mixed qutrit states of Eq. (27). This gap is independent of the phase-randomness issue: even granting uniform φ, r(ω,θ) is a theorem about the pure three-state protocol in [29], and the paper gives no proof that it remains valid for the vacuum-admixed states produced by the P0+P1 truncation. The vacuum component has zero key information and could invalidate the substitution of Q_{0+1} for Q1 in the privacy-amplification term. The paper's own wording ('one can show', 'briefly analyzed') flags the gap. My proposed SDP check would settle whether the missing derivation is a fillable technicality or a genuine overestimate. Because the reader already identified the same concerns and assigned a CONDITIONAL verdict, my stress-test does not change the verdict; it only sharpens the reason why the condition is essential.","tokens_in":15007,"tokens_out":12020,"duration_ms":155221,"concrete_test":"Compute the asymptotic key rate for the exact phase-averaged source in Eq. (10) under collective attacks using a numerical SDP security-analysis tool with the same channel and detector model as Eq. (31) and Table II, and compare the result with the no-decoy curve in Fig. 6. If the SDP key rate at 40 km is below the plotted rate, then Eq. (30) is not a valid lower bound and the asserted extension of [29] to Eq. (27) is not conservative.","verdict_should_be":"UNCHANGED","load_bearing_attack":"Section V.C computes the central result from Eq. (30): R = Q_L^{0+1} r(E_U^{Z,0+1}, E_U^{X,0+1}) - f_EC Q_μ h(E_μ). The states in Eq. (27) are mixed qutrit states: each tilde ρ_j is a classical mixture of vacuum and a single photon, and tilde ρ_+ contains the symmetric single-photon state. The Fung–Lo bound r(ω,θ) in Eqs. (24)–(25) was derived for the pure three-state protocol in [29]; the paper states only that 'one can show' it remains valid for the P0+P1-truncated states, without a derivation. This is not a minor technicality: the vacuum component carries no key information and should be treated as a tagged state, so replacing the single-photon gain by Q_{0+1} in the privacy-amplification term is not obviously conservative. Since Fig. 6 and the 40 km claim are numerical consequences of Eq. (30), a failure of this step would invalidate the quantitative central claim even if the transmitter and phase randomization are perfect. The conclusion also calls the security analysis 'briefly analyzed', acknowledging the gap.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper proposes a compact, modulator-free time-bin QKD transmitter based on pulsed optical injection between master and slave gain-switched lasers, with the master laser generating digital rectangular current pulses of two durations to prepare the Z-basis states and the single X-basis state. The authors validate the encoding principle with rate-equation simulations and an experimental demonstration using DFB lasers, a WDM filter, and an integrated Mach-Zehnder interferometer. They then analyze the security of a three-state BB84-type protocol without decoy states, projecting the phase-randomized coherent states onto the vacuum-plus-single-photon subspace (P0+P1) and using the Fung-Lo rate formula to obtain Eq. (30). From this formula they simulate secure key rates and claim secure key distribution over distances up to 40 km in metropolitan networks, with a key rate above 10^4 bit/s at 100 MHz state-preparation rate over up to 30 km.","tokens_in":15306,"tokens_out":7980,"duration_ms":97154,"significance":"If the security analysis were fully supported, the paper would make a useful contribution to low-cost QKD for metropolitan networks: the transmitter avoids external modulators, uses only digital drive signals, and the experimental data appear consistent with the proposed encoding principle. The paper is honest in labeling the security treatment as brief, and the explicit identification of the P0+P1 truncation as the step requiring justification is a strength. However, the central quantitative claim rests on two load-bearing points that are not established: the validity of the Fung-Lo bound for the mixed qutrit ensemble in Eq. (27), and the correctness of the error-rate estimate in Eq. (29). Until these are resolved, the 40 km claim and the key-rate curves in Fig. 6 are not supported by the manuscript as written.","major_comments":[{"comment":"The claimed secure range of up to 40 km follows from Eq. (30), which is obtained by asserting that the Fung-Lo rate formula r(omega,theta) of Eqs. (24)-(25) remains valid for the mixed qutrit states in Eq. (27). The paper states only that 'one can show' this, without a derivation or a precise reference. This is a load-bearing step: the states in Eq. (27) are classical mixtures of vacuum and single-photon components, and the vacuum fraction should normally be treated as a tagged state in GLLP-type analyses, so replacing the single-photon gain Q1 by Q0+1 in the privacy-amplification term is not automatically conservative. Please provide a complete proof (or a citation to a theorem covering exactly this P0+P1-truncated ensemble, including the non-uniform state probabilities in Eq. (28)) before the numerical results in Fig. 6 can be accepted.","section":"Sec. V.C, Eq. (30)"},{"comment":"Equation (29) defines the upper-bound error rate as E_{0+1}^{Z,U} = E_mu Q_mu / Q_{0+1}^{Z,U}. An upper bound on the error rate of the zero-plus-single-photon events should be obtained by dividing the total error count by a lower bound on the gain, i.e., by Q_{0+1}^{Z,L}, not by an upper bound. With the formula as written, the denominator can only decrease the error estimate, which would artificially increase the key rate computed in Eq. (30). Please correct the formula (or define the notation precisely) and recompute the affected numerical results.","section":"Sec. V.C, Eq. (29)"},{"comment":"The security analysis assumes uniform phase randomization of every emitted pulse, citing the earlier study [24]. However, no phase-randomness measurement is reported for the present master-slave injection transmitter, and the X-basis phase relation is set by the master laser pulse. Since the protocol proof requires uniform phase randomization, the practical claim of secure key distribution is conditional on an unverified property of this specific implementation. The paper should either report a phase-randomness characterization for the transmitter described here or explicitly state that the security claim is conditional on this assumption.","section":"Sec. V.A and Sec. IV"}],"minor_comments":[{"comment":"The sentence 'In the middle of Fig. 3, the slave laser signal after the WDM filter is shown' appears to refer to the middle panel of Fig. 5, not Fig. 3; please correct the reference.","section":"Sec. IV, figure reference"},{"comment":"The explicit X-basis counterparts of the estimates in Eq. (29) are not written out; please provide them so that the reader can verify the denominator convention and the resulting X-basis error bound used in Eq. (30).","section":"Sec. V.C, X-basis error formula"},{"comment":"The interference traces are presented qualitatively; reporting a quantitative visibility or extinction ratio for the X0 states would strengthen the experimental evidence and allow comparison with simulation.","section":"Fig. 2 and Fig. 5, interference panels"},{"comment":"The key-rate curves in Fig. 6 are asymptotic; the paper should state clearly that finite-size effects, which can be significant for low-gain decoy-free protocols, are not included in the claimed rates and distances.","section":"Sec. V.C, finite-size effects"}],"recommendation":"major_revision","confidential_remarks":"The experimental transmitter work is within the journal's scope and has practical value, but the central security claim is currently unsupported because Eq. (30) relies on an unproved extension of the Fung-Lo bound and Eq. (29) appears to contain a non-conservative denominator. I would be willing to review a revision that supplies the missing derivation or a precise reference, and that corrects the error-rate estimate."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"The genuinely new thing here is a transmitter concept: time-bin encoding via pulsed optical injection where the master laser needs only rectangular digital drive pulses, because only one X-basis state is used. That, plus dropping decoy states for metropolitan distances, is a sensible engineering direction. The simulation and the proof-of-principle experiment hang together—frequency locking is clearly demonstrated, and the interference fringes for the X0 states behave as expected. I give the authors credit for being honest about the limits: they call the security analysis brief, and they acknowledge intersymbol interference and the need to avoid phase correlations.\n\nThe soft spot is load-bearing. Section V.C derives the central 40 km claim from Eq. (30), which substitutes the combined vacuum-plus-single-photon gain Q_{0+1} into the Fung–Lo rate formula r(ω,θ). But that formula was proven for the pure three-state protocol. The paper says only 'one can show' it remains valid for the mixed qutrit states of Eq. (27). The vacuum component carries no key information and is normally treated as a tagged state; replacing the single-photon gain with Q_{0+1} in the privacy-amplification term is not obviously conservative. If that extension fails, the quantitative key-rate curves and the 40 km range are unsupported, independent of the transmitter's behavior. The phase-randomness assumption is also imported from the authors' earlier paper rather than verified on this device; for a security argument that is a real gap, though a minor one compared to the proof issue.\n\nThe engineering demonstration is solid, and the target audience—systems-oriented QKD researchers looking for low-cost metropolitan transmitters—will find the concept worth studying. The citation pattern is fine; the self-citations are for earlier modeling and phase-randomness work, which is legitimate. A serious referee should be engaged, because the concept is novel enough and the missing derivation may be fillable. I would send it to review with a clear request: either prove the Fung–Lo extension for the qutrit states, or restate the secure-range results as heuristic pending a full security proof.","headline":"A plausible, clearly demonstrated transmitter concept whose quantitative secure-range claim depends on an unproved security-proof extension.","tokens_in":15824,"tokens_out":2556,"would_cite":true,"duration_ms":31426,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":["03.67.Dd"],"model":"deepseek-v4-flash","headline":"This paper proposes a modulator-free, digitally driven two-laser transmitter that prepares time-bin quantum states by pulsed optical injection, and argues that the resulting decoy-free three-state protocol secures key distribution over…","keywords":["quantum key distribution","time-bin encoding","pulsed optical injection","modulator-free transmitter","decoy-free protocol","three-state BB84","gain-switched laser","metropolitan area network"],"falsifier":"Interference-measure the phase of each slave-laser pulse pair emitted under long-master-pulse injection and compare the distribution to uniform; if adjacent-pulse phases are correlated with the preceding bit pattern or with each other, the security proof's phase-randomization premise fails and the computed key rates no longer hold.","tokens_in":14778,"feed_emoji":"🔐","tokens_out":7141,"duration_ms":77885,"temperature":0.7,"pith_summary":"The paper is trying to establish that quantum key distribution over metropolitan-area distances can be done with a radically simpler transmitter: two gain-switched lasers, a circulator, and a WDM filter, driven only by digital pulses, with no electro-optic modulators and no decoy states. It proposes time-bin encoding in which the master laser's short pulses define early/late Z-basis states and a long pulse prepares the single X-basis state by locking the slave laser's phase. The accompanying security analysis of the decoy-free three-state protocol predicts secure key generation up to about 40 km with standard parameters, which would cover typical city-network node separations of 5–20 km. An experiment confirms that the filtering, time-bin formation, and X-basis constructive interference work as modeled.","feed_headline":"Two lasers, no modulators: secure keys out to 40 km","feed_subtitle":"A pulsed-optical-injection transmitter could make quantum key distribution cheap enough for city networks.","key_machinery":"The central mechanism is pulsed optical injection: a master-laser pulse temporarily forces the slave laser's emission wavelength to lock to the master's, so only injected slave pulses pass the WDM filter. A long master pulse covers two adjacent slave pulses and fixes their phase difference through the master field's phase, which is how the X basis is encoded without an external phase modulator. The security argument is carried by the projection $P_{\\rm sec} = P_0 + P_1$ onto the vacuum and single-photon subspaces of the two temporal modes: applying it to the phase-randomized coherent states produces an effective qutrit state (vacuum plus photon in early mode, late mode, or both), and the paper assumes the published three-state security proof's rate formula applies to these truncated states. The formula then yields the decoy-free key rate from gain and error-rate bounds on combined zero- and single-photon events.","core_discovery":"The paper proposes a time-bin encoding method in which a master laser and a slave laser, both gain-switched by rectangular electrical pulses, are joined through a circulator and a WDM filter. When the master injects a short pulse, the slave's corresponding pulse locks to the master wavelength and passes the filter, placing a pulse in the early or late time bin; that is the Z basis. When the master injects a long pulse covering two slave pulses, both pass and the phase difference between them is set by the master field's phase evolution, giving the single X-basis state. Since only three states are produced, the paper analyzes a three-state BB84-family protocol without decoy states and, using worst-case bounds on vacuum-plus-single-photon events, concludes that secure key distribution is possible over up to 40 km of standard fiber with typical detector parameters, and at more than $10^{4}$ bit/s up to 30 km at a 100 MHz preparation rate.","pith_inferences":["If the phase-randomization premise survives at higher clock rates, the demonstrated 312.5 MHz state rate is likely not the ceiling; improving the laser-driver impedance match could remove the intersymbol interference that currently forces the extra delay and lower rate.","The projector-truncation technique used here is a general recipe: any three-state protocol can be made decoy-free by counting vacuum and single-photon events together, and the same construction could be applied to four-state or measurement-device-independent protocols.","A direct measurement of the emitted phase distribution under long-pulse injection, not reported for this transmitter, would test the security analysis's key assumption and is a natural next experiment."],"forward_implications":["Metropolitan QKD terminals could be reduced to two laser diodes and a filter, with all modulation done digitally, which lowers cost and hardware complexity.","The single-X-state, no-decoy protocol turns vacuum events and single-photon events into useful key material, so the usual decoy-state intensity control is unnecessary for city distances.","At a 100 MHz state-preparation rate the predicted key rate exceeds 10^4 bit/s up to 30 km, and secure operation extends to about 40 km under typical assumptions.","Because there is no modulator, the transmitter presents no modulator-based Trojan-horse side channel to an eavesdropper.","Intersymbol interference, seen at 625 MHz, is managed by a short inter-state delay and does not noticeably affect Z-basis error levels."],"supporting_citations":[{"why":"Supplies the three-state security proof and the key-rate reduction function $r(\\omega, \\theta)$ that the decoy-free analysis adopts.","marker":"[29]"},{"why":"Provides the decoy-state gain and error estimation formulas, along with the channel model used to simulate key rates with and without decoy states.","marker":"[22]"},{"why":"Gives the theoretical model of phase modulation via optical injection, explaining how the master pulse sets the slave pulse phase difference.","marker":"[21]"},{"why":"Establishes the frequency-locking effect and laser dynamics used in the rate-equation model and in explaining why injected pulses pass the filter.","marker":"[23]"},{"why":"Supports the assumption that gain-switched laser pulses carry uniformly random phases, which the security proof relies on.","marker":"[24]"},{"why":"Introduced pulsed optical injection as a basis for modulator-free quantum state preparation, the technique the transmitter builds on.","marker":"[17]"}],"fun_headline_variants":["Laser injection QKD: 40 km keys without modulators","Two lasers, no modulators, no decoys: city QKD","Modulator-free transmitter brings QKD to city networks","Pulsed injection makes QKD transmitters simpler, cheaper","Secure city QKD with just two gain-switched lasers"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The whole 40 km secure-range claim rests on the assumption that the published three-state security proof, including its phase-error formula, still applies to the transmitter's truncated vacuum-plus-single-photon states, and that every emitted pulse has a uniformly random phase; neither point is directly proved in the paper.","fun_headline_variants_meta":{"raw":{"variants":["Laser injection QKD: 40 km keys without modulators","Two lasers, no modulators, no decoys: city QKD","Modulator-free transmitter brings QKD to city networks","Pulsed injection makes QKD transmitters simpler, cheaper","Secure city QKD with just two gain-switched lasers"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000196,"raw_usage":{"total_tokens":1323,"prompt_tokens":873,"completion_tokens":450,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":489,"completion_tokens_details":{"reasoning_tokens":365}},"tokens_in":489,"tokens_out":450,"duration_ms":5173,"temperature":1.0,"reasoning_tokens":365,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-06T21:10:11.903815+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Interference-measure the phase of each slave-laser pulse pair emitted under long-master-pulse injection and compare the distribution to uniform; if adjacent-pulse phases are correlated with the preceding bit pattern or with each other, the security proof's phase-randomization premise fails and the computed key rates no longer hold.","supporting_citations":[{"cited_title":"Curty, X","cited_arxiv_id":null,"evidence_quote":"Provides the decoy-state gain and error estimation formulas, along with the channel model used to simulate key rates with and without decoy states."},{"cited_title":"Shakhovoy, M","cited_arxiv_id":null,"evidence_quote":"Gives the theoretical model of phase modulation via optical injection, explaining how the master pulse sets the slave pulse phase difference."},{"cited_title":"mas- ter+slave","cited_arxiv_id":null,"evidence_quote":"Establishes the frequency-locking effect and laser dynamics used in the rate-equation model and in explaining why injected pulses pass the filter."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Supports the assumption that gain-switched laser pulses carry uniformly random phases, which the security proof relies on."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Introduced pulsed optical injection as a basis for modulator-free quantum state preparation, the technique the transmitter builds on."}],"review_version":1}