Pith. sign in

REVIEW 3 major objections 5 minor 3 cited by

Improved finite-size effects in QKD protocols with applications to decoy-state QKD

T0 review · 3 major / 5 minor · reviewed 2026-08-08 · deepseek-v4-flash

Pith's one-line read Finite-size key rates for generic prepare-and-measure QKD can be pushed close to asymptotic by entry-wise acceptance constraints and by corrections that scale with sifted rounds rather than total signals.

desk verdict The main fixed-length theorem is unproven as written because Corollary 17 drops a normalization factor, but the paper's new techniques are worth a serious look. read the letter →

arxiv 2502.05382 v1 pith:SLJGXIAR submitted 2025-02-07 quant-ph

classification quant-ph MSC 81P9481P45 PACS 03.67.Dd03.67.Hk
keywords finite-sizesecurityquantumkeydistributiondecoy-stateprotocolssmoothmin-entropycollectiveattackspostselectiontechniquevariable-lengthentry-wiseacceptanceconstraints
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper claims that finite-size security proofs for prepare-and-measure quantum key distribution (QKD) can be made tighter with two changes: acceptance tests that constrain each observed frequency individually rather than through a single aggregate bound, and second-order correction terms that scale with the number of sifted, detected rounds instead of the total number of signals sent. The resulting key-length formula, Theorem 4, is proven secure against independent and identically distributed (IID) collective attacks and then extended to coherent attacks via the postselection technique and to variable-length protocols. Applied to qubit BB84, decoy-state BB84, and a decoy-state 4-6 protocol, the method essentially reaches the asymptotic key rate at $N = 10^{10}$ to $10^{11}$ signals on loss-only channels, where the 1-norm comparison method of Ref. [14] keeps positive rates only up to about 25 dB. A reader should care because finite-size penalties set the practical distance limit of real QKD links, and this proof targets exactly those penalties.

What carries the argument

Three objects carry the argument. The feasible set $S_\nu$ with its entry-wise acceptance test (Theorem 2): observed frequencies must each lie within a tolerated fluctuation of the expected values, and the variational bounds $\nu_k^{U/L}$ are fixed as the smallest $\nu$ for which the binomial cumulative probability (incomplete $\beta$ function) equals $\epsilon_{AT}$, bounding the accept probability of every state outside $S_\nu$ by $\epsilon_{AT}$. The sift-conditioning lemma (Lemma 3): conditioning the raw key on the detector labels $D_i$ that mark sifted rounds leaves a tensor-product state on the sifted subsystem, so the smooth min-entropy is bounded below by the min-entropy of the sifted rounds alone and the second-order AEP correction scales with $\lfloor n_{\mathrm{sift}} - N t_{\mathrm{sift}}\rfloor$. The leftover-hash lemma with partial conditioning (Corollary 17): this converts the min-entropy bound into the trace-distance secrecy statement of Theorem 4 while, as the paper claims, avoiding the full $1/\Pr[\Omega]$ normalization penalty for the composite event $\Omega = \Omega_1 \wedge \Omega_2$. For decoy-state and coherent-attack extensions, the same skeleton is reused with yield bounds from a linear program over photon-number subspaces and with the postselection dimension cost $g_{n,x}$.

What would settle it

Take a small classical-quantum example, say two rounds of qubit BB84 with a composite event $\Omega_1$ selecting sifted outcomes and $\Omega_2$ selecting acceptance with $\Pr[\Omega_2|\Omega_1] \approx 10^{-2}$, and compute both sides of inequality (A9) directly: the left side by explicit state construction and trace-norm evaluation, the right side by computing $H^{\epsilon}_{\min}(X|YD)_{\sigma|\Omega_1}$ with a semidefinite program over the smoothing ball. If the left side exceeds the right, Corollary 17 is false as stated and Theorem 4's formula would need an extra normalization penalty. A less explicit but decisive check is to re-derive the proof of Corollary 17 while keeping the factor $1/\Pr[\Omega_2|\Omega_1]$ and see whether the final key length picks up an additional $\log(1/\Pr[\Omega_2|\Omega_1])$ term.

Watch

Extended reading notes

Core claim

The paper's central claim is a finite-size security statement for generic prepare-and-measure QKD: under an IID collective attack the protocol is $\epsilon_{\mathrm{sec}} = \epsilon_{EV} + \max\{\epsilon_{AT}, \epsilon_{PA} + 2\bar{\epsilon}\}$-secure if the final key length $l$ obeys $$l \leq \lfloor n_{\mathrm{sift}} - N t_{\mathrm{sift}}\rfloor \min_{\rho \in S_\nu} \frac{H(Z|EC)_\rho}{\Pr(\mathrm{sift})} - \lambda_{EC} - \log(2/\epsilon_{EV}) - \sqrt{\lfloor n_{\mathrm{sift}} - N t_{\mathrm{sift}}\rfloor\,\$\Delta$(\bar{\epsilon})} - 2\log(1/(2\epsilon_{PA})).$$ Two parts of the construction deliver the improvement. Theorem 2 defines the acceptance set $Q = Q_1 \cap Q_2$ by entry-wise tolerances on the test-round frequencies together with a tolerance on the number of sifted rounds, and sets the variational bounds $\nu_k^{U/L}$ through binomial tail probabilities (the incomplete $\beta$ function), so any state outside the feasible set $S_\nu$ is accepted with probability at most $\epsilon_{AT}$. Lemma 3 then shows the smooth min-entropy of the raw key can be evaluated on the sifted subsystem alone, so the asymptotic equipartition property contributes a correction proportional to $\sqrt{\lfloor n_{\mathrm{sift}} - N t_{\mathrm{sift}}\rfloor}$ rather than $\sqrt{N}$. The same skeleton is reused for decoy-state protocols, where the feasible set is expressed through photon-number yields bounded by a linear program, and for variable-length protocols, where the correction terms depend on the observed number of sifted rounds $N^{\mathrm{obs}}_{\mathrm{sift}}$; coherent attacks are handled by applying the postselection technique with the dimension cost $g_{n,x}$.

Load-bearing premise

The key-length formula of Theorem 4 stands on Corollary 17 in Appendix A, a leftover-hash inequality for composite events $\Omega = \Omega_1 \wedge \Omega_2$ that claims the normalization by $\Pr[\Omega]$ costs nothing beyond the conditioning on $\Omega_1$, although the proof appears to drop a factor of $1/\Pr[\Omega_2|\Omega_1]$ when comparing normalized and subnormalized trace norms.

Editorial extensions

If this is right

  • Qubit BB84 with a perfect source essentially reaches its asymptotic key rate already at $N = 10^{10}$ signals, while the 1-norm method of Ref. [14] keeps positive rates only up to roughly 25 dB of loss (Figs. 3-4).
  • Decoy-state BB84 with two decoy intensities recovers the asymptotic limit up to about 40 dB loss with $N = 10^{11}$ signals, optimizing both the testing probability and the signal intensity per data point (Fig. 5).
  • Because the security proof starts from a generic prepare-and-measure statement, it covers protocols that the entropic-uncertainty-relation route handles poorly, including active-basis protocols with passive detection setups and different intensities per signal state.
  • Variable-length protocols inherit the same gain: in Theorem 8 and Corollary 9 the correction terms depend on the observed number of sifted rounds $N^{\mathrm{obs}}_{\mathrm{sift}}$ instead of $N$, so high-loss key rates degrade much more slowly as the block length shrinks.
  • Against coherent attacks, the decoy-state 4-6 protocol with one decoy intensity and unequal per-symbol intensities yields non-zero key rates from $N = 10^9$ signals and reaches 25 dB at $N = 10^{12}$ (Fig. 6).

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • A consequence the paper leaves implicit: if the sifted-round scaling holds, the fair resource for comparing QKD implementations at high loss shifts from total pulses sent to sifted detections, since protocols with better detection or sifting efficiency gain twice - once in the entropy prefactor and once in the correction terms - and plots like Fig. 3 should nearly collapse when re-drawn against th
  • The entry-wise-versus-aggregate distinction is transferable: other QKD settings whose feasible sets are already defined by individual observation bounds, such as measurement-device-independent and discrete-modulated continuous-variable protocols, could adopt the same binomial-tail acceptance tests and inherit a comparable reduction of statistical slack.
  • The expected-key-rate analysis using Fr\'echet inequalities offers a template for deployments where the honest channel is known only coarsely: rather than assuming a point model for the accepted frequencies, one can bracket the worst-case key rate between the upper and lower Fr\'echet bounds and choose the acceptance tolerances accordingly.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 5 minor

Summary. The paper develops a finite-size security proof for generic prepare-and-measure QKD protocols against IID collective attacks, with extensions to coherent attacks via the postselection technique and to variable-length protocols. The two claimed improvements are (i) entry-wise acceptance constraints based on binomial tail bounds, and (ii) second-order correction terms that scale with the number of sifted rounds rather than the total number of protocol rounds. The framework is applied to qubit BB84, decoy-state BB84, and a decoy-state 4-6 protocol with unequal intensities, and numerical key rates are compared with the 1-norm approach of Ref. [14].

Significance. If the central theorem were valid, the framework would be a valuable contribution: it avoids the basis-independence assumptions of EUR-based proofs, handles active basis choices and passive detection setups, and the numerical examples suggest substantially improved finite-size rates over the 1-norm approach of Ref. [14]. The paper is detailed and self-contained in many respects, with appendices covering technical tools such as binomial confidence bounds for very small security parameters, and the authors commit to releasing code. However, the central fixed-length theorem depends on a flawed normalization step in Corollary 17, so the quantitative claims are currently not supported.

major comments (3)
  1. [Appendix A, Corollary 17, Eqs. (A9)–(A11)] The proof of Corollary 17 drops a normalization factor. From Eq. (A11) and Pr[Ω] = Pr[Ω1]Pr[Ω2|Ω1], the left-hand side of Eq. (A9) equals ‖N‖_1 / (2 Pr[Ω1] Pr[Ω2|Ω1]^2), where N = (ω_{KSHYD|Ω1})_{∧Ω2} − χ_K ⊗ (ω_{SHYD|Ω1})_{∧Ω2}. The proof's first inequality instead claims this is ≤ (1/2)‖N‖_1, which would require Pr[Ω1]Pr[Ω2|Ω1]^2 ≥ 1. For any non-trivial events this product is strictly less than 1, so the inequality has the wrong direction. Consequently the advertised bound (A9) is not established; the correct bound would contain an extra factor 1/(Pr[Ω1]Pr[Ω2|Ω1]^2) multiplying the right-hand side, i.e., an additional key-length penalty of at least 2 log(1/Pr[Ω1]) + 4 log(1/Pr[Ω2|Ω1]) or an equivalent inflation of the security parameter.
  2. [Theorem 4, Eq. (49) and proof around Eq. (57)] The key-length formula in Theorem 4 relies directly on Corollary 17 to pass from the security distance conditioned on Ω_acc to the smooth min-entropy conditioned only on Ω_sift. Since Corollary 17 is not established, Eq. (57) does not follow, and hence Eq. (49) is not proven as stated. The numerical key-rate curves in Figs. 3–6 and the claimed improvements over Ref. [14] are computed from this formula, so they are unsupported until the normalization issue is repaired and propagated through Theorem 4 and Corollaries 5–6.
  3. [Theorem 4, Eq. (49); Corollaries 5–6] A corrected version of Corollary 17 will introduce terms depending on Pr[Ω_sift] and Pr[Ω'_AT|Ω_sift]. The paper provides no lower bounds on these probabilities for states in the feasible set S_ν, and these probabilities can be small for adversarial states near the boundary of S_ν. The authors should either bound these event probabilities or restructure the acceptance test so that the resulting penalties are controlled; without this, the claimed reduction of second-order corrections to scale with the number of sifted rounds is not justified.
minor comments (5)
  1. [Corollary 6, Eq. (94)] The term “− 2 log(1/2ε_PA)” should read “− 2 log(1/(2ε_PA))”; the same typo appears in Corollary 9 and in the text after Eq. (58).
  2. [Theorem 2 proof, Eq. (18)] The inequality “Pr[F_obs ∈ Q] ≤ Pr[|F_obs^k − Fbar^k| ≤ t_k] ∀k ∈ Σ” should be stated separately for each k before taking the maximum; as written it suggests an invalid simultaneous bound.
  3. [Notation throughout] The sets S∘ and S• are used somewhat interchangeably; for example, Corollary 17 states σ ∈ S∘(XYD) but then discusses subnormalized states, which should be in S•. Clarifying this would help the reader.
  4. [Lemma 3, Eq. (34)] The notation τ^sift_{Z_sift Y_sift C_sift E_sift|D=1} is introduced but the conditioning on the register D is not explicitly reflected in the right-hand side of Eq. (34); a short clarification would improve readability.
  5. [Eq. (83), Corollary 5] The fraction in the first term of the key-rate expression lacks parentheses: it should read (1/(Fbar_sift + t_sift + ν^U_sift)) times the sum over n, rather than the ambiguous inline expression currently printed.

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity: the key-rate derivation is self-contained and does not reduce to its inputs.

full rationale

The central security claims (Theorem 4 and its decoy corollaries) are derived from the asymptotic equipartition property, the leftover-hash lemma, concentration inequalities for binomial statistics, and the protocol's acceptance-set construction. The key-rate expression is not fitted to the data it later predicts; parameters such as the testing probability and intensities are optimized under an assumed channel model, and the numerical curves are evaluations of the proven bound, not fits. The many references to prior work from the same group ([12], [14], [16], [27]) are used as published external building blocks: the postselection lift is imported from [12] and the variable-length framework from [16], but these are separate peer-reviewed results with stated assumptions independent of the present paper's claims, so they do not make the argument circular. A potential issue raised by the manuscript's own Appendix A (Corollary 17) concerns a normalization factor in a trace-norm inequality; that is a proof-correctness risk, not a self-referential reduction, and therefore does not affect the circularity score.

Assumptions & free parameters 5 free parameters · 6 assumptions · 0 invented entities

The proof itself does not fit any data; the free parameters listed are protocol design choices and numerical optimization variables that affect the reported key-rate curves. The axioms are the standard QKD modeling assumptions, plus the AEP and postselection theorems imported from the literature. No new physical entities are introduced.

free parameters (5)
  • Testing probability p(test) = optimized per data point in the numerical examples
    The protocol accepts arbitrary p(test), but the reported key rates in Figs. 3-6 optimize p(test) for each channel loss and N; changes in p(test) strongly affect the key rates.
  • Signal intensity mu_s in decoy examples = not fixed, optimized per data point in Section VII B
    In the decoy-state BB84 example, mu_s is a free protocol parameter optimized jointly with testing probability to maximize key rate; it is not derived from first principles.
  • Tolerances t_k and t_sift = optimized in Section VI to maximize expected key rate
    The acceptance set width t is a free design choice. Security holds for any t, but the expected key rate and the abort probability depend on it; too small t leads to frequent abort, too large t loosens the feasible set.
  • Security parameter split epsilon_PA, epsilon_bar, epsilon_AT = chosen via heuristic derivative Eq. (104), not a closed formula
    The total epsilon_sec is fixed, but the distribution among epsilon_AT, epsilon_PA, and epsilon_bar is chosen to optimize key rate; this is a hand-tuned optimization, not a prediction.
  • Photon number cutoffs Nph and NB = Nph = 2, NB = 1 in the examples
    Chosen by hand for the numerical examples to make the postselection dimension x finite; the security proof depends on these cutoffs.
assumptions (6)
  • domain assumption Each round is independent and identically distributed under the collective attack: rho_ABE = sigma_ABE^otimes N
    Invoked after Eq. (7) and in all fixed-length theorems; the coherent-attack extension later uses postselection to relax this, but only for permutation-invariant protocols.
  • domain assumption Eve has no access to Alice's lab, so the marginal of the single-round state satisfies rho_A = Tr_A'[|psi><psi|], Eq. (8)
    Used to define the feasible set S_nu and the source replacement scheme; if Alice's source has uncharacterized side channels, the security proof does not apply.
  • domain assumption The source is fully phase-randomized WCP, making the state block-diagonal in photon number and the n-photon yields independent of intensity
    Used throughout Section IV and the decoy-state examples (Eqs. (63)-(69), Ref. [26]); violation breaks the decoy-state yield equations.
  • domain assumption Valid squashing maps exist for Bob's detectors (passive BB84 squashing and flag-state squasher for 4-6)
    Invoked in Section VII B and IX A to reduce optical POVMs to finite-dimensional qubit POVMs, and in the computation of the postselection dimension x; the security proof inherits these assumptions.
  • standard math Entropy accumulation theorem / AEP bound [24, Cor. 4.10]
    Used in Theorem 4 proof Eq. (61) to convert smooth min-entropy of product states into von Neumann entropy plus sqrt(n) correction; also Renyi versions in Appendix D.
  • standard math Postselection technique of Christandl-Koenig-Renner, as improved by [12, Cor. 4.1]
    Used to lift IID security to coherent attacks in Section IX; this is a theorem imported from the cited literature, not proved here.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Improved finite-size effects in QKD protocols with applications to decoy-state QKD." pith.science (2026). https://pith.science/paper/SLJGXIAR

@misc{pith2026250205382,
  author       = {Pith},
  title        = {Pith review of: Improved finite-size effects in QKD protocols with applications to decoy-state QKD},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/SLJGXIAR}},
  note         = {Machine review of arXiv:2502.05382}
}
read the original abstract

We present a finite-size security proof for generic quantum key distribution protocols against independent and identically distributed collective attacks and extend it to coherent attacks using the postselection technique. This work introduces two significant improvements over previous results. First, we achieve tighter finite-size key rates by employing refined concentration inequalities in the acceptance testing phase. Second, we improve second-order correction terms in the key rate expression, by reducing them to scale with the number of sifted rounds rather than the total number of protocol rounds. We apply these advancements to compute finite-size key rates for a qubit and decoy-state BB84 protocol, accommodating arbitrary protocol parameters. Finally, we extend our finite-size security proof to coherent attacks and variable-length protocols and present our results for the decoy-state 4-6 protocol incorporating imperfections such as unequal intensity settings.

Figures

Figures reproduced from arXiv: 2502.05382 by the authors.

Figure 1
Figure 1. FIG. 1: One dimensional representation of the [PITH_FULL_IMAGE:figures/full_fig_p004_1.png] view at source ↗
Figure 2
Figure 2. FIG. 2: Plot of upper, lower and independent bounds [PITH_FULL_IMAGE:figures/full_fig_p013_2.png] view at source ↗
Figure 3
Figure 3. FIG. 3: Secret key rate for [PITH_FULL_IMAGE:figures/full_fig_p014_3.png] view at source ↗
Figures from the paper (2 more)
Figure 5
Figure 5. Figure 5: FIG. 5: Secret key rate for [PITH_FULL_IMAGE:figures/full_fig_p015_5.png]
Figure 6
Figure 6. Figure 6: FIG. 6: Comparison between secret key rates for [PITH_FULL_IMAGE:figures/full_fig_p019_6.png]

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. The finite key effect of side-channel-secure quantum key distribution beyond post-selection technique

    quant-ph 2026-07 conditional novelty 6.0 of 10

    A security proof for variable-length side-channel-secure QKD against coherent attacks, bypassing post-selection and allowing the key rate to be computed after error correction from the actual leakage.

  2. Security proofs for practical QKD: variations, techniques, gaps, and limitations

    quant-ph 2025-02 accept novelty 6.0 of 10

    A critical review of decoy-state BB84 security proofs identifies common gaps and shows that no current proof meets the full standard of completeness, modularity, and verifiability.

  3. Drone- and Vehicle-Based Quantum Key Distribution

    quant-ph 2025-05 conditional novelty 5.0 of 10

    First demonstrations of drone-to-drone, drone-to-vehicle, and vehicle-to-vehicle quantum key distribution, with finite-key secure rates of 1.6 to 20 kbps over short free-space links.

Reference graph

Works this paper leans on

55 extracted references · 46 canonical work pages · cited by 3 Pith papers

  1. [14]

    George, J

    I. George, J. Lin, and N. L¨ utkenhaus, Numerical Calcula- tions of Finite Key Rate for General Quantum Key Dis- tribution Protocols, Physical Review Research 3, 013274 (2020)

  2. [16]

    Tupkary, E

    D. Tupkary, E. Y.-Z. Tan, and N. L¨ utkenhaus, Security proof for variable-length quantum key distribution, Phys. Rev. Res. 6, 023002 (2024)

  3. [1]

    X. Ma, B. Qi, Y. Zhao, and H.-K. Lo, Practical decoy state for quantum key distribution, Physical Review A 72, 012326 (2005)

  4. [2]

    H.-K. Lo, X. Ma, and K. Chen, Decoy State Quantum Key Distribution, Physical Review Letters 94, 230504 (2004)

  5. [3]

    W. Y. Hwang, Quantum Key Distribution with High Loss: Toward Global Secure Communication, Physical Review Letters 91, 057901 (2002)

  6. [4]

    Wang, Beating the Photon-Number-Splitting At- tack in Practical Quantum Cryptography, Phys

    X.-B. Wang, Beating the Photon-Number-Splitting At- tack in Practical Quantum Cryptography, Phys. Rev. Lett. 94, 230503 (2005)

  7. [5]

    Tomamichel and R

    M. Tomamichel and R. Renner, Uncertainty Relation for Smooth Entropies, Phys. Rev. Lett. 106, 110506 (2011)

  8. [6]

    C. C. W. Lim, M. Curty, N. Walenta, F. Xu, and H. Zbinden, Concise security bounds for practical decoy- 20 state quantum key distribution, Physical Review A 89, 022307 (2014)

Show all 55 references
  1. [7]

    Rusca, A

    D. Rusca, A. Boaron, F. Gr¨ unenfelder, A. Martin, and H. Zbinden, Finite-key analysis for the 1-decoy state QKD protocol, Applied Physics Letters 112, 171104 (2018)

  2. [8]

    Koashi, Simple security proof of quantum key dis- tribution based on complementarity, New Journal of Physics 11, 045018 (2009)

    M. Koashi, Simple security proof of quantum key dis- tribution based on complementarity, New Journal of Physics 11, 045018 (2009)

  3. [9]

    Hayashi and R

    M. Hayashi and R. Nakayama, Security analysis of the decoy method with the bennett–brassard 1984 protocol for finite key lengths, New Journal of Physics 16, 063009 (2014)

  4. [10]

    Tomamichel and A

    M. Tomamichel and A. Leverrier, A largely self-contained and complete security proof for quantum key distribu- tion, Quantum 1, 14 (2017)

  5. [11]

    Tupkary, S

    D. Tupkary, S. Nahar, P. Sinha, and N. L¨ utkenhaus, Phase error rate estimation with basis-efficiency mis- match for decoy-state bb84 (2024), arXiv:2408.17349 [quant-ph]

  6. [12]

    Nahar, D

    S. Nahar, D. Tupkary, Y. Zhao, N. L¨ utkenhaus, and E. Y.-Z. Tan, Postselection technique for optical quan- tum key distribution with improved de finetti reductions, PRX Quantum 5, 040315 (2024)

  7. [13]

    Christandl, R

    M. Christandl, R. K¨ onig, and R. Renner, Postselection Technique for Quantum Channels with Applications to Quantum Cryptography, Phys. Rev. Lett. 102, 020504 (2009)

  8. [15]

    Kanitschar, I

    F. Kanitschar, I. George, J. Lin, T. Upadhyaya, and N. L¨ utkenhaus, Finite-Size Security for Discrete- Modulated Continuous-Variable Quantum Key Distribu- tion Protocols, PRX Quantum 4, 040306 (2023)

  9. [17]

    Laing, V

    A. Laing, V. Scarani, J. G. Rarity, and J. L. O’Brien, Reference-frame-independent quantum key distribution, Phys. Rev. A 82, 012304 (2010)

  10. [18]

    Portmann and R

    C. Portmann and R. Renner, Security in quantum cryp- tography, Rev. Mod. Phys. 94, 025008 (2022)

  11. [19]

    Renner, Security of Quantum Key Distribution (2006), arxiv:quant-ph/0512258

    R. Renner, Security of Quantum Key Distribution (2006), arxiv:quant-ph/0512258

  12. [20]

    In an exper- imental implementation this step is not required if the techniques from [16] are used

    This is done to maintain a fixed length string going into privacy amplification for technical reasons. In an exper- imental implementation this step is not required if the techniques from [16] are used. In particular, Alice and Bob may discard rounds as long as the positions o...

  13. [21]

    C. H. Bennett, G. Brassard, and N. D. Mermin, Quantum cryptography without Bell’s theorem, Phys. Rev. Lett. 68, 557 (1992)

  14. [22]

    Ferenczi and N

    A. Ferenczi and N. L¨ utkenhaus, Symmetries in quan- tum key distribution and the connection between optimal attacks and optimal cloning, Phys. Rev. A 85, 052310 (2012)

  15. [23]

    Tomamichel, Quantum Information Processing with Finite Resources , SpringerBriefs in Mathemati- cal Physics, Vol

    M. Tomamichel, Quantum Information Processing with Finite Resources , SpringerBriefs in Mathemati- cal Physics, Vol. 5 (Springer International Publishing, Cham, 2016)

  16. [24]

    Dupuis, O

    F. Dupuis, O. Fawzi, and R. Renner, Entropy Accumu- lation, Commun. Math. Phys. 379, 867 (2020)

  17. [25]

    Horodecki, M

    K. Horodecki, M. Horodecki, P. Horodecki, and J. Op- penheim, General Paradigm for Distilling Classical Key From Quantum States, IEEE Transactions on Informa- tion Theory 55, 1898 (2009)

  18. [26]

    N. K. H. Li and N. L¨ utkenhaus, Improving key rates of the unbalanced phase-encoded BB84 protocol using the flag-state squashing model, Phys. Rev. Research 2, 043172 (2020)

  19. [27]

    Kamin and N

    L. Kamin and N. L¨ utkenhaus, Improved decoy-state and flag-state squashing methods, Physical Review Research 6, 043223 (2024)

  20. [28]

    Wang and N

    W. Wang and N. L¨ utkenhaus, Numerical security proof for the decoy-state BB84 protocol and measurement- device-independent quantum key distribution resistant against large basis misalignment, Phys. Rev. Res. 4, 043097 (2022)

  21. [29]

    Winick, N

    A. Winick, N. L¨ utkenhaus, and P. J. Coles, Reliable nu- merical key rates for quantum key distribution, Quantum 2, 77 (2018)

  22. [30]

    Fr´ echet, G´ en´ eralisation du th´ eor` eme des probabilit´ es totales, Fundamenta Mathematicae 25, 379 (1935)

    M. Fr´ echet, G´ en´ eralisation du th´ eor` eme des probabilit´ es totales, Fundamenta Mathematicae 25, 379 (1935)

  23. [31]

    C. H. Bennett and G. Brassard, Quantum cryptogra- phy: Public key distribution and coin tossing, Theoreti- cal Computer Science 560, 7 (2014)

  24. [32]

    N. J. Beaudry, T. Moroder, and N. L¨ utkenhaus, Squash- ing Models for Optical Measurements in Quantum Com- munication, Physical Review Letters 101, 093601 (2008)

  25. [33]

    Gittsovich, N

    O. Gittsovich, N. J. Beaudry, V. Narasimhachar, R. R. Alvarez, T. Moroder, and N. L¨ utkenhaus, Squashing model for detectors and applications to quantum-key- distribution protocols, Physical Review A 89, 012325 (2014)

  26. [34]

    Hayashi and T

    M. Hayashi and T. Tsurumaru, Concise and tight secu- rity analysis of the Bennett–Brassard 1984 protocol with finite key lengths, New Journal of Physics 14, 093014 (2012)

  27. [35]

    Curr´ as-Lorenzo, ´A

    G. Curr´ as-Lorenzo, ´A. Navarrete, K. Azuma, G. Kato, M. Curty, and M. Razavi, Tight finite-key security for twin-field quantum key distribution, npj Quantum Infor- mation 7, 1 (2021)

  28. [36]

    Kawakami, Security of Quantum Key Distribution with Weak Coherent Pulses, Ph.D

    S. Kawakami, Security of Quantum Key Distribution with Weak Coherent Pulses, Ph.D. thesis

  29. [37]

    C. J. Clopper and E. S. Pearson, The Use of Confidence or Fiducial Limits Illustrated in the Case of the Binomial, Biometrika 26, 404 (1934), 2331986

  30. [38]

    C. R. Rao, G. J. Sz´ ekely, and Alfr´ ed R´ enyi Institute of Mathematics, eds., Statistics for the 21st Century: Methodologies for Applications of the Future, Statistics, Textbooks and Monographs No. v. 161 (Marcel Dekker, New York, 2000)

  31. [39]

    These intervals can be easily constructed using prein- stalled functions in MATLAB

  32. [40]

    Kamin and N

    L. Kamin and N. L¨ utkenhaus, Improved Decoy-state and Flag-state Squashing Methods, arXiv:2405.05069 [quant- ph] (2024)

  33. [41]

    J. Lin, T. Upadhyaya, and N. L¨ utkenhaus, Asymptotic Security Analysis of Discrete-Modulated Continuous- Variable Quantum Key Distribution, Phys. Rev. X 9, 041064 (2019)

  34. [42]

    Zhang, P

    Y. Zhang, P. J. Coles, A. Winick, J. Lin, and N. L¨ utkenhaus, Security proof of practical quantum key 21 distribution with detection-efficiency mismatch, Physical Review Research 3, 013076 (2021)

  35. [43]

    Dupuis, Privacy Amplification and Decoupling With- out Smoothing, IEEE Transactions on Information The- ory 69, 7784 (2023)

    F. Dupuis, Privacy Amplification and Decoupling With- out Smoothing, IEEE Transactions on Information The- ory 69, 7784 (2023)

  36. [44]

    Instead of considering a sum over events that only cor- respond to different output key lengths, we are allowed to sum over events with different output key lengths or error-correction lengths or number of sifted signals. This can be shown using basic properties of the trace n...

  37. [45]

    A. M. Zubkov and A. A. Serov, A Complete Proof of Universal Inequalities for the Distribution Function of the Binomial Law, Theory Probab. Appl. 57, 539 (2013)

  38. [46]

    Thulin, The cost of using exact confidence intervals for a binomial proportion, Electronic Journal of Statistics 8, 10.1214/14-ejs909 (2014)

    M. Thulin, The cost of using exact confidence intervals for a binomial proportion, Electronic Journal of Statistics 8, 10.1214/14-ejs909 (2014). Appendix A: T echnical Definitions and Lemmas Definition 11 (Normalised and sub-normalised condi- tional states) . Let ρ ∈ S•(DX ) b...

  39. [47]

    Qubit BB84 In the main text, we set pB z = pB x = 1/2, but for gen- erality, we provide the Kraus operators for arbitrary ba- sis choices. Given a perfect qubit protocol, Bob’s qubit 23 POVM elements are M B (Z,0) = pB z   0 0 0 0 1 0 0 0 0   , MB (Z,1) = pB z   0 0 0 0 ...

  40. [48]

    In the main text, we set pB z = pB x = 1/2, but for generality, we provide the Kraus operators for arbitrary basis choices

    Decoy BB84 After applying the squashing map from [32, 33], Bob’s measurements act on a qubit again. In the main text, we set pB z = pB x = 1/2, but for generality, we provide the Kraus operators for arbitrary basis choices. The resulting POVM elements coincide with the ones fo...

  41. [49]

    variable-length decision

    4-6 Protocol As described in the main text, see Section IX A, we chose a photon number cut-off for Bob as NB = 1. After 24 applying the flag-state squasher of [42] with this choice, the POVM elements on Bob’s ≤ 1-photon subspace are ˜M B (Z,0) = pB z   0 0 0 0 1 0 0 0 0   ...

  42. [50]

    From public announcements ⃗C, Alice and Bob com- pute F obs and bstat(F obs)

  43. [51]

    , λmax} is some predeter- mined function

    They compute λEC(F obs), the number of bits to be used for error-correction information, where λEC(·) : F → {0, 1, . . . , λmax} is some predeter- mined function

  44. [52]

    , lmax} is a function defined as l(F obs) := max 0, bstat(F obs) − λEC(F obs) − θ(εPA, εEV) , θ(εPA, εEV) := α α − 1 log 1 4εPA + 2 α + log 2 εEV

    They compute l(F obs), the length of the final key to be produced, where l(·) : F → {0, 1, . . . , lmax} is a function defined as l(F obs) := max 0, bstat(F obs) − λEC(F obs) − θ(εPA, εEV) , θ(εPA, εEV) := α α − 1 log 1 4εPA + 2 α + log 2 εEV . (E6) We setup a partition of F b...

  45. [53]

    Hα( ⃗Z| ⃗C ⃗E)ρ|Ωm ≥ l1 + λ1 + θ(εPA, εEV)

  46. [54]

    lj + λj + θ(εPA, εEV) ≥ Hα( ⃗Z| ⃗C ⃗E)ρ|Ωm ≥ lj+1 + λj+1 + θ(εPA, εEV) for some j ∈ {1, ..., M− 1}

  47. [55]

    We will prove the secrecy claim separately for each case

    lM + λM + θ(εPA, εEV) ≥ Hα( ⃗Z| ⃗C ⃗E)ρ|Ωm . We will prove the secrecy claim separately for each case. Suppose that for every value of m, ρ is such that it sat- isfies case 2, for some value j∗ m. In this case, the secrecy bound can be obtained by splitting up the sum into two...

Pith tools

Reviewed August 8, 2026 · model on record in the stance chip above.