Pith. sign in

REVIEW 3 major objections 5 minor 106 references

An Overview of CV-MDI-QKD

T0 review · 3 major / 5 minor · reviewed 2026-08-10 · deepseek-v4-flash

Pith's one-line read This paper derives a composable finite-size key-rate formula for Gaussian-modulated CV-MDI-QKD and surveys its theory, networks, and experiments.

desk verdict A solid review of CV-MDI-QKD that overclaims the novelty of its composable finite-size formula, which is an undeveloped application of the authors' own earlier framework. read the letter →

arxiv 2501.09818 v3 pith:4Q7UOKOJ submitted 2025-01-16 quant-ph cond-mat.otherphysics.app-phphysics.optics

classification quant-phcond-mat.otherphysics.app-phphysics.optics MSC 81P9494A60 PACS 03.67.Dd
keywords CV-MDI-QKDcontinuous-variableQKDmeasurement-device-independentcomposablesecurityfinite-sizekeyrateGaussiancollectiveattackspost-selectionquantumdistributionnetworks
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This review of continuous-variable measurement-device-independent quantum key distribution (CV-MDI-QKD) aims to establish that the protocol can be given a rigorous composable finite-size security analysis: the most stringent key-rate formula for the Gaussian-modulated version follows from applying the general CV-QKD proof tools of Ref. [98], and the paper writes the resulting bound as Eq. (7). The motivation is practical: CV-MDI-QKD combines the hardware simplicity of continuous-variable systems with immunity to detector side channels at an untrusted relay, so a finite-size, composable bound is what a real deployment would need. The review also collects the asymptotic rate, post-selection variants, star-network extensions, and the main experiments. The net message is that CV-MDI-QKD offers a quantifiable security guarantee for short-to-moderate-distance, relay-based quantum key distribution.

What carries the argument

The load-bearing object is Eq. (7), a composable finite-size key-rate inequality, together with the total epsilon-security decomposition \(\epsilon\le\epsilon_{\rm cor}+\epsilon_s+\epsilon_h+\epsilon_{\rm ent}+n_{\rm pe}\epsilon_{\rm pe}\). The formula treats the MDI protocol as a general CV-QKD protocol in the framework of Ref. [98], so the relay-specific physics is isolated in the asymptotic rate \(\bar R^\infty_{\rm pe}\), which depends on worst-case estimators \(\$tau^{{\rm wc}}$_A\), \(\$tau^{{\rm wc}}$_B\), and \(\$Xi^{{\rm wc}}$\). The mechanism is that Alice and Bob estimate the channel parameters from a fraction of each block, use worst-case values to upper-bound Eve's Holevo information, and then subtract the finite-size penalties while keeping the overall epsilon parameter under control.

What would settle it

Recompute the Fig. 5 key rates under a correlated two-mode Gaussian attack with \(g=g'\neq0\) instead of the uncorrelated case \(g'=g=0\) used in the plots; if the composable key rate falls to zero at the claimed distances, or if a non-Gaussian attack is found that beats the Gaussian collective bound, the central claim would be falsified.

Watch

Extended reading notes

Core claim

The paper's central claim is that the composable finite-size secret-key rate of Gaussian-modulated CV-MDI-QKD is bounded by Eq. (7), \(R \le p_{\rm ec}[n_{\rm bks}\bar R^\infty_{\rm pe}-\sqrt n\,\delta_{\rm ent}-\sqrt n\,\delta_{\rm aep}+\$\theta$]/N\), where a session is divided into \(n_{\rm bks}\) blocks of \(N\) points, \(m\) of which are used for parameter estimation. The protocol-specific content enters only through \(\bar R^\infty_{\rm pe}\), the asymptotic rate computed from estimators of the two link transmissivities and the total excess noise, while Eve's Holevo information is evaluated with worst-case estimators. The finite-size corrections are the entropy-estimation penalty \(\delta_{\rm ent}\), the smoothing and hashing penalty \(\delta_{\rm aep}\), a correctness term \(\$\theta$\), and the error-correction success probability \(p_{\rm ec}\). The paper presents this as an improved formulation relative to earlier composable analyses, and its Fig. 5 shows that composable security reduces the asymmetric-configuration distance from about \(100\) km asymptotically to about \(25\) km for the plotted parameters.

Load-bearing premise

The load-bearing premise is that Eve's most general attack on the protocol reduces to a collective Gaussian attack on the two incoming links and that the composable finite-size proof for general CV-QKD from Ref. [98] applies to the MDI setting without modification; if either part fails, the bound in Eq. (7) is no longer a proven guarantee.

Editorial extensions

If this is right

  • A real CV-MDI-QKD deployment can quote a finite-size, composable security parameter; for the plotted parameters the asymmetric configuration supports a positive composable key rate up to about \(25\) km.
  • The symmetric configuration remains the weak point: under pure loss the asymptotic rate is already limited to about \(4\) km, and post-selection extends the positive-rate distance to about \(6\) km while lowering short-range rates.
  • In star networks, the maximum radius of positive key rate scales roughly as \(2/N\) for \(N\) users, so the protocol is best suited to a few users around a central relay.
  • Recent experiments reach symbol rates of \(20\) Mbaud and report finite-size key generation, with rates around \(0.1\) bits per relay use, indicating the composable bounds are relevant to built systems.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • If Eq. (7) is correct, the same proof pipeline should carry over to the surveyed variants, including post-selection, squeezed states, and free-space links, by recomputing the asymptotic rate and its estimators; the paper does not supply those derivations.
  • The numerical plots assume an uncorrelated two-mode attack (\(g'=g=0\)); recomputing the rates for correlated Gaussian attacks with \(g,g'\neq0\) would show whether the claimed distances are stable against Eve's more general collective attacks.
  • A testable extension is to study how the bound degrades for block sizes much smaller than \(10^7\), where the \(\delta_{\rm aep}\) term grows and the comparison between asymptotic and composable rates changes.
Share X Bluesky LinkedIn Reddit HN

Formalized claims in Lean

  1. Claim #1: The paper's central claim is that the composable finite-size secret-key rate of Gaussian-modulated CV-MDI-QKD is bounded by Eq. (7), \(R \le p_{\rm ec}[n_{\rm bks}\bar R^\infty_{\rm pe}-\sqrt n\,\delta_{\rm ent}-\sqrt n\,\delta_{\rm aep}+\$\theta$]/N\), where a session is divided into \(n_{\rm bks}\) blocks of \(N\) points, \(m\) of which are used for parameter estimation. The protocol-specific co

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 5 minor

Summary. The paper is a review of continuous-variable measurement-device-independent quantum key distribution (CV-MDI-QKD). It describes the protocol in both prepare-and-measure and entanglement-based representations, reviews the asymptotic security analysis under Gaussian collective attacks, discusses post-selection variants, presents a composable finite-size key rate formula in Section IV, extends the discussion to star-network and three-user configurations, and surveys four experimental implementations. The central new-looking element is the composable finite-size rate expression in Eq. (7), which the authors claim to be the most rigorous such formula for the basic Gaussian-modulated protocol and which they say they obtain using the tools of Ref. [98].

Significance. If the composable finite-size formula in Section IV were fully supported, it would be a practically relevant contribution, as finite-size composable security is the standard required for real deployments. However, as presented, the formula is a restatement of Ref. [98] with the MDI asymptotic rate inserted, and the reduction of the two-link relay protocol to the one-way setting of Ref. [98] is not shown. The review's descriptive parts, including the experimental survey and the network extensions, are useful and appear consistent with the cited literature. The paper also honestly correlates numerical rates with the uncorrelated-attack assumption g'=g=0, which is a strength. The main weakness is that the load-bearing security claim in Section IV is not substantiated within the manuscript.

major comments (3)
  1. [Section IV, Eq. (7)] Equation (7) is presented as an 'improved formulation' of the composable finite-size key rate for CV-MDI-QKD, obtained using the tools of Ref. [98]. However, no derivation is provided: the equation coincides with Eq. (68) of Ref. [98] after substituting the asymptotic rate R^pe_∞. The manuscript does not show how the CV-MDI-QKD protocol, with two independent links and an untrusted relay, is reduced to the one-way CV-QKD setting analyzed in Ref. [98]. In particular, the structure of the conditional state shared by Alice and Bob after the relay's Bell measurement is not analyzed, and the i.i.d. and Markov-chain conditions required for the application of the asymptotic equipartition property (AEP) in Eqs. (8)-(9) are not checked. Without this reduction, Eq. (7) is an unsupported restatement rather than an improved formulation, and the claim 'the most rigorous formula' is not justified.
  2. [Section III A and Section IV] The security analysis is restricted to collective Gaussian attacks, and the numerical rates further assume an uncorrelated two-mode attack with g'=g=0 (Eq. (12)). The paper cites Ref. [75] for the reduction of the most general attack to a Gaussian attack in the asymptotic setting, but this reduction is not established for the composable finite-size framework. The statement 'Assuming collective Gaussian attacks' before Eq. (7) is not sufficient, because the AEP-based terms δ_ent and δ_aep require that the conditional state be i.i.d. and satisfy the relevant Markov-chain conditions; these conditions are not verified for the two-link, relay-based MDI protocol. The manuscript should either provide the reduction or explicitly label Eq. (7) as an application of Ref. [98] under additional assumptions.
  3. [Section IV, Eq. (11) and text below] The asymptotic rate R^pe_∞ is defined in Eq. (11) using estimators and worst-case estimators for three parameters (τ_A, τ_B, Ξ), but the paper does not specify how these estimators are constructed, how the worst-case bound is obtained, or how the parameter-estimation error probability ϵ_pe enters the bound. The reference to Ref. [97] is not sufficient for a self-contained review that claims to provide an improved formulation. This missing step is load-bearing, since the composability statement (6) depends on the failure probabilities of all post-processing steps, and the numerical results in Fig. 5 rely on this unstated construction.
minor comments (5)
  1. [Section III A, Eq. (12)] In the definition of ζ_k, the denominator should be τ_k, not the unsubscripted τ; as written, the formula is dimensionally inconsistent and does not match the text.
  2. [Section V B, Eq. (14)] In Eq. (14), the integrand uses γ_p but the integration variable and the distribution p(QQQ, γ_q) use γ_q; this appears to be a typo, and the intended integration variable should be used consistently.
  3. [Section IV, first paragraph] The notation n_bks for the number of blocks is introduced without a definition, and the later use 'n_bks' is not further explained; please define it explicitly.
  4. [Section IV, opening claim] The sentence 'The most rigorous formula ... can be derived using the tools developed in Ref. [98]' is a strong claim that is not supported by a comparison with Refs. [96, 97]; the authors should either specify the improvement or soften the claim to avoid overstatement.
  5. [Section II and III A] The transmissivity labels are inconsistent: Section II uses τ_A and τ_B for the links, while the attack description in Section III A uses τ_1 and τ_2. Please unify the notation.

Circularity Check

1 steps flagged · score 4.0 of 10

Section IV's composable finite-size formula is effectively Eq. (68) of the authors' own Ref. [98] with the MDI asymptotic rate inserted; the paper does not derive the reduction, so the 'improved formulation' is self-citation load-bearing rather than an independent derivation.

  1. self citation load bearing [Section IV, Eq. (7), with the surrounding text 'The most rigorous formula ...' and '[see Eq. (68) of [98]]']
    "The most rigorous formula for the composable finite-size key rate of the basic, Gaussian-modulated version of CV-MDI-QKD can be derived using the tools developed in Ref. [98] for the security of general CV-QKD protocols. Here we use these tools to provide an improved formulation. ... Assuming collective Gaussian attacks, the key rate is upper bounded by [see Eq. (68) of [98]] R≤ pec[n bRpe∞ −nδent −√nδaep +θ]/N ... It is in the specific expression of bRpe∞ that enters the features of the CV-MDI-QKD protocol. In particular, this is given by bRpe∞ = bξ bIAB −[IE]wc."

    The claimed derivation of the composable bound for CV-MDI-QKD is not carried out in the paper: Eq. (7) is quoted directly from Eq. (68) of Ref. [98], whose authors (Pirandola and Papanastasiou) are also authors of this paper. The only protocol-specific ingredient is bRpe∞, which is then defined as the estimators-based version of the same asymptotic rate already used in Section III. Thus the 'improved formulation' reduces by construction to inserting the authors' own asymptotic MDI rate into their own general formula; no proof is supplied that the finite-size entropy terms in Eqs. (8)-(9) apply to the two-link MDI conditional state, and the restriction to collective Gaussian attacks with g'=g=0 is carried over as an assumption.

full rationale

Most of the review's descriptive and experimental content is independently sourced (e.g., Refs. [99]-[101] for experiments and Refs. [45], [64], [93] for background), and I find no fitted-parameter-called-prediction or self-definitional circularity in the asymptotic-rate and post-selection sections. The circularity concern is concentrated in Section IV: the paper's strongest new-looking claim, the 'most rigorous' composable finite-size key-rate formula, is a direct restatement of Eq. (68) of Ref. [98], a self-citation, with the asymptotic MDI rate substituted. Because the paper does not demonstrate that the AEP-based finite-size terms of Ref. [98] apply unchanged to the relay-based two-link protocol, and because the estimator expressions are taken from Ref. [97] (same group), the central formula is self-citation load-bearing rather than an independent derivation. This warrants a moderate score of 4; the remaining sections give the review independent content.

Assumptions & free parameters 0 free parameters · 4 assumptions · 0 invented entities

The review introduces no new free parameters or entities. The key rate calculations use parameters such as block size and excess noise chosen for illustration, not fitted. The load-bearing assumptions are the reduction of attacks to collective Gaussian attacks on the links and the transferability of the composable security framework from Ref. [98] to the MDI setting.

assumptions (4)
  • domain assumption Eve's most general attack on an MDI-QKD protocol can be reduced to the case where the detector is operated correctly and Eve attacks the incoming links.
    Invoked in Section III A to restrict the security analysis; cited from Ref. [75], not proven in this paper.
  • domain assumption The most powerful collective attack on a Gaussian CV protocol is a Gaussian attack.
    Section III A relies on this from Ref. [93] to justify considering only Gaussian attacks, a standard but unproven assumption for MDI settings.
  • ad hoc to paper The composable finite-size security framework of Ref. [98] applies directly to CV-MDI-QKD.
    Section IV assumes this without derivation; the framework is for general CV-QKD but its adaptation to the MDI protocol and its estimators is not demonstrated.
  • standard math The asymptotic key rate formula R = I_AB - I_E with unit reconciliation efficiency is valid for the protocol.
    Section III A states this as a simplified asymptotic formula, which is standard in CV-QKD but relies on the assumptions above.

how reviews work

0 comments
Cite this review

Pith. "Pith review of An Overview of CV-MDI-QKD." pith.science (2026). https://pith.science/paper/4Q7UOKOJ

@misc{pith2026250109818,
  author       = {Pith},
  title        = {Pith review of: An Overview of CV-MDI-QKD},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/4Q7UOKOJ}},
  note         = {Machine review of arXiv:2501.09818}
}
read the original abstract

As quantum key distribution (QKD) emerges as a robust defense against quantum computer threats, significant advancements have been realized by researchers. A pivotal focus has been the development of protocols that not only simplify hardware implementation like the use of continuous-variable (CV) systems, but also negate the necessity for trusted nodes, as seen with the measurement-device independent (MDI) approach. This paper delves into the integration of these methodologies in the CV-MDI-QKD protocol, offering an in-depth exploration of its evolution, primary characteristics, and the latest advancements in both theory and experiment.

Figures

Figures reproduced from arXiv: 2501.09818 by the authors.

Figure 1
Figure 1. FIG. 1 [PITH_FULL_IMAGE:figures/full_fig_p003_1.png] view at source ↗
Figure 2
Figure 2. FIG. 2. Asymptotic key rate (bits/use) of the symmetric CV-MDI [PITH_FULL_IMAGE:figures/full_fig_p003_2.png] view at source ↗
Figure 3
Figure 3. FIG. 3. Asymptotic key rate (bits/use) of CV-MDI-QKD in the asym [PITH_FULL_IMAGE:figures/full_fig_p004_3.png] view at source ↗
Figures from the paper (5 more)
Figure 4
Figure 4. Figure 4: FIG. 4. Comparative rate-distance performance of CV-MDI-QKD [PITH_FULL_IMAGE:figures/full_fig_p005_4.png]
Figure 5
Figure 5. Figure 5: FIG. 5 [PITH_FULL_IMAGE:figures/full_fig_p006_5.png]
Figure 8
Figure 8. Figure 8: FIG. 8. 3-user CV-MDI-QKD star network in post-selection. Two [PITH_FULL_IMAGE:figures/full_fig_p007_8.png]
Figure 9
Figure 9. Figure 9: FIG. 9. Rate of the 3-user CV-MDI-QKD network in post-selection [PITH_FULL_IMAGE:figures/full_fig_p007_9.png]
Figure 10
Figure 10. Figure 10: FIG. 10. Experimental CV-MDI-QKD based on Gaussian-modulated coherent states. (a) [ [PITH_FULL_IMAGE:figures/full_fig_p009_10.png]

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

106 extracted references · 71 canonical work pages

  1. [98]

    Pirandola and P

    S. Pirandola and P. Papanastasiou, Phys. Rev. Res.6, 023321 (2024)

  2. [75]

    asymmetric Free space 4 dB 100 kHz 0.1 Asymptotic

  3. [97]

    Papanastasiou, A

    P. Papanastasiou, A. Mountogiannakis, and S. Pirandola, Sci. Rep.13, 11636 (2023)

  4. [1]

    C. H. Bennett,Proceedings of IEEE International Conference on Computers Systems and Signal Processing, , 175 (1984)

  5. [2]

    C. H. Bennett and G. Brassard, Theor. Comput. Sci.560, 7 (2014)

  6. [3]

    Pirandola, U

    S. Pirandola, U. L. Andersen, L. Banchi, M. Berta, D. Bunan- dar, R. Colbeck, D. Englund, T. Gehring, C. Lupo, C. Otta- viani, J. L. Pereira, M. Razavi, J. S. Shaari, M. Tomamichel, V . C. Usenko, G. Vallone, P. Villoresi, and P. Wallden, Adv. Opt. Photon.12, 1012 (2020)

  7. [4]

    Colbeck and R

    R. Colbeck and R. Renner, Nature Physics8, 450–453 (2011)

  8. [5]

    Gallego, L

    R. Gallego, L. Masanes, G. D. L. Torre, C. Dhara, L. Aolita, and A. Ac´ın, Nature Communications4, 2654 (2013)

Show all 106 references
  1. [6]

    M. W. Mitchell, C. Abellan, and W. Amaya, Phys. Rev. A91, 012314 (2015)

  2. [7]

    Lunghi, J

    T. Lunghi, J. B. Brask, C. C. W. Lim, Q. Lavigne, J. Bowles, A. Martin, H. Zbinden, and N. Brunner, Phys. Rev. Lett.114, 150501 (2015)

  3. [8]

    F. G. S. L. Brand ˜ao, R. Ramanathan, A. Grudka, K. Horodecki, M. Horodecki, P. Horodecki, T. Szarek, and H. Wojew´odka, Nature Communications7, 11345 (2016)

  4. [9]

    X. Ma, X. Yuan, Z. Cao, B. Qi, and Z. Zhang, npj Quantum Information2, 16021 (2016)

  5. [10]

    Ac ´ın and L

    A. Ac ´ın and L. Masanes, Nature540, 213–219 (2016)

  6. [11]

    Herrero-Collantes and J

    M. Herrero-Collantes and J. C. Garcia-Escartin, Rev. Mod. Phys.89, 015004 (2017)

  7. [12]

    Hillery, V

    M. Hillery, V . Buˇzek, and A. Berthiaume, Phys. Rev. A59, 1829 (1999)

  8. [13]

    Cleve, D

    R. Cleve, D. Gottesman, and H.-K. Lo, Phys. Rev. Lett.83, 648 (1999)

  9. [14]

    Ribeiro, G

    J. Ribeiro, G. Murta, and S. Wehner, Phys. Rev. A97, 022307 (2018)

  10. [15]

    A. Keet, B. Fortescue, D. Markham, and B. C. Sanders, Phys. Rev. A82, 062315 (2010)

  11. [16]

    Ottaviani, C

    C. Ottaviani, C. Lupo, R. Laurenza, and S. Pirandola, Com- munications Physics2, 118 (2019)

  12. [17]

    Grasselli, H

    F. Grasselli, H. Kampermann, and D. Bruß, New Journal of Physics21, 123002 (2019)

  13. [18]

    Pirandola, IET Quantum Communication1, 22 (2020)

    S. Pirandola, IET Quantum Communication1, 22 (2020)

  14. [19]

    Gottesman and I

    D. Gottesman and I. Chuang, quant-ph/0105032 (2001)

  15. [20]

    P. J. Clarke, R. J. Collins, V . D. andErika Andersson, J. Jeffers, and G. S. Buller, Nature Communications3, 1174 (2012)

  16. [21]

    R. J. Collins, R. J. Donaldson, V . Dunjko, P. Wallden, P. J. Clarke, E. Andersson, J. Jeffers, and G. S. Buller, Phys. Rev. Lett.113, 040502 (2014)

  17. [22]

    Dunjko, P

    V . Dunjko, P. Wallden, and E. Andersson, Phys. Rev. Lett. 112, 040502 (2014)

  18. [23]

    Wallden, V

    P. Wallden, V . Dunjko, A. Kent, and E. Andersson, Phys. Rev. A91, 042304 (2015)

  19. [24]

    Croal, C

    C. Croal, C. Peuntinger, B. Heim, I. Khan, C. Marquardt, G. Leuchs, P. Wallden, E. Andersson, and N. Korolkova, Phys. Rev. Lett.117, 100503 (2016)

  20. [25]

    R. J. Collins, R. Amiri, M. Fujiwara, T. Honjo, K. Shimizu, K. Tamaki, M. Takeoka, E. Andersson, G. S. Buller, and M. Sasaki, Opt. Lett.41, 4883 (2016)

  21. [26]

    G. L. Roberts, M. Lucamarini, Z. L. Yuan, J. F. Dynes, L. C. Comandar, A. W. Sharpe, A. J. Shields, M. Curty, I. V . Puthoor, and E. Andersson, Nature Communications8, 1098 (2017)

  22. [27]

    Mayers, Phys

    D. Mayers, Phys. Rev. Lett.78, 3414 (1997)

  23. [28]

    Lo and H

    H.-K. Lo and H. Chau, Physica D: Nonlinear Phenomena120, 177 (1998), proceedings of the Fourth Workshop on Physics and Consumption

  24. [29]

    Buhrman, M

    H. Buhrman, M. Christandl, P. Hayden, H.-K. Lo, and S. Wehner, Phys. Rev. A78, 022316 (2008)

  25. [30]

    Chailloux and I

    A. Chailloux and I. Kerenidis, in2011 IEEE 52nd Annual Symposium on F oundations of Computer Science(2011) pp. 354–362

  26. [31]

    Kent, Phys

    A. Kent, Phys. Rev. Lett.109, 130501 (2012)

  27. [32]

    Broadbent, J

    A. Broadbent, J. Fitzsimons, and E. Kashefi, in2009 50th Annual IEEE Symposium on F oundations of Computer Science (2009) pp. 517–526

  28. [33]

    S. Barz, E. Kashefi, A. Broadbent, J. F. Fitzsimons, A. Zeilinger, and P. Walther, Science335, 303 (2012)

  29. [34]

    S. Barz, J. F. Fitzsimons, E. Kashefi, and P. Walther, Nature Physics9, 727–731 (2013)

  30. [35]

    J. F. Fitzsimons and E. Kashefi, Phys. Rev. A96, 012303 (2017)

  31. [36]

    Kashefi and A

    E. Kashefi and A. Pappa, Cryptography1, 2 (2017)

  32. [37]

    H. J. Kimble, Nature453, 1023 (2008)

  33. [38]

    Azuma, A

    K. Azuma, A. Mizutani, and H.-K. Lo, Nature Communica- tions7, 13523 (2016)

  34. [39]

    Pirandola and S

    S. Pirandola and S. L. Braunstein, Nature532, 169 (2016)

  35. [40]

    Wehner, D

    S. Wehner, D. Elkouss, and R. Hanson, Science362, 6412 (2018)

  36. [41]

    Azuma, De Physicus, pages: 52-54 (2019)

    K. Azuma, De Physicus, pages: 52-54 (2019)

  37. [42]

    A. K. Ekert, Phys. Rev. Lett.67, 661 (1991). 11

  38. [43]

    C. H. Bennett, Phys. Rev. Lett.68, 3121 (1992)

  39. [44]

    Bruß, Phys

    D. Bruß, Phys. Rev. Lett.81, 3018 (1998)

  40. [45]

    Weedbrook, S

    C. Weedbrook, S. Pirandola, R. Garc´ıa-Patr´on, N. J. Cerf, T. C. Ralph, J. H. Shapiro, and S. Lloyd, Rev. Mod. Phys.84, 621 (2012)

  41. [46]

    T. C. Ralph, Phys. Rev. A61, 010303 (1999)

  42. [47]

    Hillery, Phys

    M. Hillery, Phys. Rev. A61, 022309 (2000)

  43. [48]

    M. D. Reid, Phys. Rev. A62, 062308 (2000)

  44. [49]

    Grosshans and P

    F. Grosshans and P. Grangier, Phys. Rev. Lett.88, 057902 (2002)

  45. [50]

    Grosshans, G

    F. Grosshans, G. Van Assche, J. Wenger, R. Brouri, N. J. Cerf, and P. Grangier, Nature421, 238 (2003)

  46. [51]

    Filip, Phys

    R. Filip, Phys. Rev. A77, 022310 (2008)

  47. [52]

    V . C. Usenko and R. Filip, Phys. Rev. A81, 022318 (2010)

  48. [53]

    Weedbrook, S

    C. Weedbrook, S. Pirandola, S. Lloyd, and T. C. Ralph, Phys. Rev. Lett.105, 110501 (2010)

  49. [54]

    Weedbrook, S

    C. Weedbrook, S. Pirandola, and T. C. Ralph, Phys. Rev. A 86, 022318 (2012)

  50. [55]

    Weedbrook, C

    C. Weedbrook, C. Ottaviani, and S. Pirandola, Phys. Rev. A 89, 012309 (2014)

  51. [56]

    Ottaviani, M

    C. Ottaviani, M. Woolley, M. Erementchouk, J. Federici, P. Mazumder, S. Pirandola, and C. Weedbrook, IEEE Jour- nal on Selected Areas in Communications38, 483 (2020)

  52. [57]

    Weedbrook, A

    C. Weedbrook, A. M. Lance, W. P. Bowen, T. Symul, T. C. Ralph, and P. K. Lam, Phys. Rev. Lett.93, 170504 (2004)

  53. [58]

    Leverrier and P

    A. Leverrier and P. Grangier, Phys. Rev. Lett.102, 180504 (2009)

  54. [59]

    Pirandola, S

    S. Pirandola, S. Mancini, S. Lloyd, and S. L. Braunstein, Na- ture Physics4, 726–730 (2008)

  55. [60]

    I. B. Djordjevic, IEEE Photonics Journal12, 1 (2020)

  56. [61]

    I. B. Djordjevic, IEEE Access10, 23284 (2022)

  57. [62]

    I. W. Primaatmaja, C. C. Liang, G. Zhang, J. Y . Haw, C. Wang, and C. C.-W. Lim, Quantum6, 613 (2022)

  58. [63]

    M. E. Mycroft, T. McDermott, A. Buraczewski, and M. Stobi´nska, Phys. Rev. A107, 012607 (2023)

  59. [64]

    Pirandola, R

    S. Pirandola, R. Laurenza, C. Ottaviani, and L. Banchi, Nat. Commun.8, 15043 (2017)

  60. [65]

    Pirandola, R

    S. Pirandola, R. Garc´ıa-Patr´on, S. L. Braunstein, and S. Lloyd, Phys. Rev. Lett.102, 050503 (2009)

  61. [66]

    Pirandola, Commun

    S. Pirandola, Commun. Phys.2, 51 (2019), see also preprint arXiv:1601.00966 (2016)

  62. [67]

    Pirandola, Quantum Science and Technology4, 045006 (2019)

    S. Pirandola, Quantum Science and Technology4, 045006 (2019)

  63. [68]

    S. L. Braunstein and S. Pirandola, Phys. Rev. Lett.108, 130502 (2012)

  64. [69]

    H.-K. Lo, M. Curty, and B. Qi, Phys. Rev. Lett.108, 130503 (2012)

  65. [70]

    Liu, T.-Y

    Y . Liu, T.-Y . Chen, L.-J. Wang, H. Liang, G.-L. Shentu, J. Wang, K. Cui, H.-L. Yin, N.-L. Liu, L. Li, X. Ma, J. S. Pelc, M. M. Fejer, C.-Z. Peng, Q. Zhang, and J.-W. Pan, Phys. Rev. Lett.111, 130502 (2013)

  66. [71]

    Curty, F

    M. Curty, F. Xu, W. Cui, C. C. W. Lim, K. Tamaki, and H.-K. Lo, Nature Communications5, 3732 (2014)

  67. [72]

    Lucamarini, Z

    M. Lucamarini, Z. L. Yuan, J. F. Dynes, and A. J. Shields, Nature557, 397 (2018)

  68. [73]

    Minder, M

    M. Minder, M. Pittaluga, G. L. Roberts, M. Lucamarini, J. F. Dynes, Z. L. Yuan, and A. J. Shields, Nature Photonics13, 334–338 (2019)

  69. [74]

    Pirandola, C

    S. Pirandola, C. Ottaviani, G. Spedalieri, C. Weedbrook, and S. L. Braunstein, arXiv:1312.4104v1 (2013)

  70. [76]

    Ma, S.-H

    X.-C. Ma, S.-H. Sun, M.-S. Jiang, M. Gui, and L.-M. Liang, Phys. Rev. A89, 042335 (2014)

  71. [77]

    Li, Y .-C

    Z. Li, Y .-C. Zhang, F. Xu, X. Peng, and H. Guo, Phys. Rev. A 89, 052301 (2014)

  72. [78]

    Y . Zhao, Y . Zhang, B. Xu, S. Yu, and H. Guo, Phys. Rev. A 97, 042328 (2018)

  73. [79]

    Pirandola, C

    S. Pirandola, C. Ottaviani, G. Spedalieri, C. Weedbrook, S. L. Braunstein, S. Lloyd, T. Gehring, C. S. Jacobsen, and U. L. Andersen, Nature Photonics9, 397 (2015)

  74. [80]

    Zhang, Z

    Y . Zhang, Z. Li, C. Weedbrook, K. Marshall, S. Pirandola, S. Yu, and H. Guo, Entropy17, 4547 (2015)

  75. [81]

    P. Wang, X. Wang, and Y . Li, Phys. Rev. A99, 042309 (2019)

  76. [82]

    Ghalaii and S

    M. Ghalaii and S. Pirandola, Phys. Rev. A108, 042621 (2023)

  77. [83]

    H.-X. Ma, P. Huang, D.-Y . Bai, S.-Y . Wang, W.-S. Bao, and G.-H. Zeng, Phys. Rev. A97, 042329 (2018)

  78. [84]

    D. Bai, P. Huang, H. Ma, T. Wang, and G. Zeng, Journal of Physics B: Atomic, Molecular and Optical Physics52, 135502 (2019)

  79. [85]

    D. Bai, P. Huang, Y . Zhu, H. Ma, T. Xiao, T. Wang, and G. Zeng, Quantum Information Processing19(2019)

  80. [86]

    H.-X. Ma, P. Huang, D.-Y . Bai, T. Wang, S.-Y . Wang, W.-S. Bao, and G.-H. Zeng, Phys. Rev. A99, 022322 (2019)

  81. [87]

    Zhang, Z

    Y .-C. Zhang, Z. Li, S. Yu, W. Gu, X. Peng, and H. Guo, Phys. Rev. A90, 052325 (2014)

  82. [88]

    Papanastasiou, C

    P. Papanastasiou, C. Ottaviani, and S. Pirandola, Phys. Rev. A 96, 042332 (2017)

  83. [89]

    A. G. Mountogiannakis, P. Papanastasiou, and S. Pirandola, Phys. Rev. A106, 042606 (2022)

  84. [90]

    K. N. Wilkinson, P. Papanastasiou, C. Ottaviani, T. Gehring, and S. Pirandola, Phys. Rev. Research2, 033424 (2020)

  85. [91]

    Q. Liao, Y . Wang, D. Huang, and Y . Guo, Opt. Express26, 19907 (2018)

  86. [92]

    Ghalaii, P

    M. Ghalaii, P. Papanastasiou, and S. Pirandola, npj Quantum Inf8, 105 (2022)

  87. [93]

    Garc ´ıa-Patr´on and N

    R. Garc ´ıa-Patr´on and N. J. Cerf, Phys. Rev. Lett.97, 190503 (2006)

  88. [94]

    Fletcher, PhD Thesis, University of York (2023)

    A. Fletcher, PhD Thesis, University of York (2023)

  89. [95]

    A. I. Fletcher and S. Pirandola, Sci Rep12, 17329 (2022)

  90. [96]

    C. Lupo, C. Ottaviani, P. Papanastasiou, and S. Pirandola, Phys. Rev. A97, 052327 (2018)

  91. [99]

    asymmetric Fiber 2.02 dB 500 kHz 0.19 Asymptotic

  92. [100]

    asymmetric VOA 2 dB 5 MHz 0.12 Asymptotic

  93. [101]

    Quan- tum Security Networks Partnership

    asymmetric Fiber 2.5 dB 20 MHz 0.13 Finite-size still lag behind the state-of-the-art in prepare-and-measure coherent-state QKD systems [102]. This limitation arises pri- marily from two factors: (1) bandwidth constraints in the high-efficiency relay, particularly in the reado...

  94. [102]

    Silberhorn, T

    C. Silberhorn, T. C. Ralph, N. L ¨utkenhaus, and G. Leuchs, Physical Review Letters89, 167901 (2002)

  95. [103]

    Y . Tian, P. Wang, J. Liu, S. Du, W. Liu, Z. Lu, X. Wang, and Y . Li, Optica9, 492 (2022)

  96. [104]

    A. A. Hajomer, H. Q. Nguyen, and T. Gehring, arXiv preprint arXiv:2210.07576 (2022)

  97. [105]

    A. A. Hajomer, U. L. Andersen, and T. Gehring, arXiv preprint arXiv:2303.01611 (2025)

  98. [106]

    A. A. Hajomer, C. Bruynsteen, I. Derkach, N. Jain, A. Bomhals, S. Bastiaens, U. L. Andersen, X. Yin, and T. Gehring, Optica11, 1197 (2024)

Pith tools

Reviewed August 10, 2026 · model on record in the stance chip above.