REVIEW 3 major objections 7 minor 45 references
Condition for the generation of the secret key in a BB84 like quantum key distribution protocol
T0 review · 3 major / 7 minor · reviewed 2026-08-16 · deepseek-v4-flash
Pith's one-line read A modified lower bound guarantees a positive secret key for BB84-like QKD within a specific fidelity-error window.
desk verdict The paper's central claim that the modified Woodhead bound always guarantees a positive key rate collapses on a numerically false logarithmic inequality; the advertised fidelity and error-rate ranges are unsupported. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The carrying object is the modified lower bound $R_{lb}$. Starting from $R=1-h(u)-h(\delta_z)$, where $h$ is the binary entropy function, $u=(1+F)/2$, and $F=F(\rho_E,\rho'_E)$ is the fidelity between the two states Eve obtains after cloning the two secret states, the paper uses $x/(1+x)\le \log(1+x)$ to replace $(1-\delta_z)\log(1-\delta_z)$ by $-\delta_z$, then uses a numerical bound for $\log\delta_z$ to produce the quadratic condition $\delta_z^2-2.5\delta_z+2.5a-1>0$ whose solution yields $F\in(0.8281,0.9922)$ and $\delta_z\in(0,\delta_{z1})$. The analysis of particular clones enters through the fidelity formulas $4\alpha^2(1-\alpha^2)$ for the state-dependent cloner and $4[\alpha^2(1-\alpha^2)(1-2\xi)^2+\xi(1-\xi)]$ for the modified symmetric cloner, which link Eve's overlap to Alice's state parameter and the cloning-machine parameter.
What would settle it
Evaluate the inequality at $\delta_z=0.2$: $\log(0.2)\approx -1.609$, while $0.2^2-2.5(0.2)=-0.46$; since $-1.609$ is not greater than $-0.46$, the inequality fails at a point inside the claimed range, so the quadratic condition and the derived fidelity and error windows do not follow from this derivation.
Extended reading notes
Core claim
The central claim is that the secret-key-rate lower bound can be modified so that $R_{lb}>0$ whenever the fidelity $F(\rho_E,\rho'_E)$ lies between 0.8281 and 0.9922 and the error rate $\delta_z$ lies in $(0,\delta_{z1})$ with $\delta_{z1}\in(0,0.305)$. The derivation starts from the cloning-based bound $R=1-h(u)-h(\delta_z)$ with $u=(1+F)/2$, applies elementary inequalities to the entropy terms, and reduces the positivity condition to a quadratic inequality in $\delta_z$. Solving that inequality gives the claimed ranges. For the state-dependent cloner the allowed secret-state parameter is $\alpha^2\in(0.293,0.456)$, while for the modified symmetric cloner, for each machine parameter $\xi\in(0,0.455)$ there are values of $\alpha^2\in(0,0.455)$ that keep $R_{lb}>0$. The paper also bounds Eve's cloning efficiency by relating fidelity to trace distance and the HS distance, giving an upper efficiency bound beyond which the protocol would be aborted.
Load-bearing premise
The load-bearing assumption is that the natural logarithm of the error rate satisfies $\log \delta_z > \delta_z^2 - 2.5\delta_z$ for every $\delta_z\in(0,0.305)$; this numerical inequality is what turns the lower bound into the quadratic condition that produces all the claimed fidelity and error ranges.
Editorial extensions
If this is right
- For each fidelity in $F\in(0.8281,0.9922)$, the protocol succeeds for every Z-basis error rate below the computed upper bound, so the abort condition is avoided across an explicit parameter window.
- For the state-dependent cloner, Alice's state parameter must stay in $\alpha^2\in(0.293,0.456)$; outside that window the modified lower bound can be negative and the protocol would fail.
- For the modified symmetric cloner, a range of machine parameters $\xi\in(0,0.455)$ admits values of $\alpha^2\in(0,0.455)$ for which the key remains positive, so the eavesdropper can remain hidden while a key is still distilled.
- The paper's efficiency analysis yields an upper bound on Eve's HS distance: a cloning machine that is too efficient would push the protocol into abort.
Reading between the lines
- If the claimed parameter window is correct, the same entropy-bounding step could be applied to other prepare-and-measure QKD protocols whose security bounds take the form $1-h(\cdot)-h(\cdot)$, converting a continuous abort-or-not condition into explicit success windows.
- A direct experimental test would be to implement the modified protocol with a controllable cloner, measure $F(\rho_E,\rho'_E)$ and $\delta_z$, and check whether the measured key rate stays positive exactly where the quadratic condition predicts.
- The paper leaves asymmetric cloning machines open; repeating the derivation with fidelity formulas that depend on two machine parameters would replace the one-dimensional success interval with a higher-dimensional success region, a testable extension of the same construction.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. This paper considers a BB84-like QKD protocol in which the key is distilled from Z-basis rounds, with an eavesdropper who intercepts Alice's qubit and applies a quantum cloning machine. The authors start from Woodhead's lower bound r ≥ 1 − h(u) − h(δz), u = (1 + F(ρE,ρ'E))/2 (Eq. (15)), rewrite it as an expression R in the fidelity F and the Z-basis error rate δz (Eq. (16)), and claim to derive a sufficient condition for positivity of R by applying elementary inequalities, culminating in the quadratic condition (22) and the claimed windows F ∈ (0.8281, 0.9922) and δz ∈ (0, δz1) with δz1 ∈ (0, 0.305). They then compute the fidelity induced by the Wootters–Zurek and a modified Buzek–Hillery cloner (Eqs. (33) and (42)), tabulate parameter ranges for which they claim key distillation succeeds (Tables I–III), and use Hilbert–Schmidt distance inequalities to bound the cloners' efficiency (Section V). The stated goal is a lower bound that guarantees the protocol never aborts.
Significance. If valid, the paper would provide a simple sufficient condition for positivity of a previously known lower bound and would show that two specific state-dependent cloning attacks cannot prevent key distillation. The manuscript has some strengths: the circuit construction of Alice's state in Section II is explicit and algebraically consistent, the fidelity computations in Appendix A (Eqs. (33) and (42)) are correct for the commuting states under consideration, and the starting point in Woodhead's bound is properly attributed. However, the central derivation rests on a numerically false inequality, the attack analysis never verifies that the error rates induced by the cloners lie within the claimed success window, and the efficiency bound (50) is violated by the paper's own WZ example. The main claim and the QCM conclusions are therefore not established, and several of the specific numerical claims are inconsistent with the protocol model as defined. The paper provides no code, data, or machine-checked verification artifacts.
major comments (3)
- [Section III, Eqs. (20)–(22)] The transition from (20) to (21) invokes the inequality log δz > δz² − 2.5δz for δz ∈ (0, 0.305). This inequality is false in the stated direction on the entire interval; for example, at δz = 0.2 one has ln δz = −1.609 while δz² − 2.5δz = −0.46, and the reverse inequality holds throughout the interval. Since δz log δz enters (20) with a positive coefficient, substituting a quantity that is larger than log δz yields an upper bound on R_lb, not the lower bound asserted in (21). Consequently the quadratic positivity condition (22), the derived ranges F ∈ (0.8281, 0.9922) and δz ∈ (0, δz1) with δz1 ∈ (0, 0.305), and the central claim that the key rate is positive on these ranges are unsupported. Because this is the step that converts the entropy expression into an algebraic condition, the paper's main result fails as derived.
- [Section IV, Tables I–II] The analysis of the cloning attacks treats δz as a free parameter and never computes the Z-basis error rate that the cloners actually induce. For the WZ cloner, Bob's reduced state after the attack is ρB = α²|0⟩⟨0| + β²|1⟩⟨1| (the B-mode marginal of (28)), so a Z-basis measurement by Bob yields δz = 2α²(1 − α²) = F/2. For the paper's advertised fidelity range F ∈ (0.8281, 0.9922), this gives δz ∈ (0.414, 0.496), entirely above the claimed threshold δz1 ≤ 0.305. For the modified BH cloner the induced error is δz = ξ + 2(1 − 2ξ)α²(1 − α²), which for the parameters of Table I lies in the range ≈ 0.39–0.50; the first row of Table I (ξ = 0.1, α² = 0.241) lists the window δz ∈ (0, 0.0003) while the induced error is ≈ 0.39. Thus the conclusion that Alice and Bob can distill a secret key in the presence of these specific attacks is not supported; under the paper's own model these attacks produce error rates above the success threshold.
- [Section V.A, Eqs. (48)–(50)] The bound (50) is derived by imposing condition (49), DHS(ρE,ρid) ≤ DHS(ρE,ρ'E), which is not a consequence of the triangle inequality but an additional assumption, and it is violated by the paper's own WZ example: for α² = 0.293 one finds DHS(ρE,ρid) = 2α²(1 − α²) ≈ 0.414 while DHS(ρE,ρ'E) = 2(α² − (1 − α²))² ≈ 0.343, so (49) fails and the claimed consequence DHS(ρE,ρid) ≤ 2D(ρE,ρ'E)² also fails numerically (0.414 > 0.343). The efficiency bounds in Tables II–III therefore do not follow from the stated derivation.
minor comments (7)
- [Title] The title inside the manuscript, 'Achieving the positivity of the secret key in a BB84 like quantum key distribution protocol', differs from the title under which the paper is posted on arXiv; the two should be reconciled.
- [Section III, Eq. (16)] The base of the logarithm is used inconsistently: (15) is expressed with log2 through h(x), while (16) uses natural log with the conversion implicit in the prefactor 1/log 2; a sentence explicitly defining log as the natural logarithm would help.
- [Abstract and Introduction] The abstract and introduction say that the secret key is 'always generated', but the result is conditional on the fidelity and error-rate ranges derived in Section III; the wording should be qualified.
- [Section IV.B] The question posed at the end of Section IV.A, whether there exists a cloner for which Alice may choose α² in (0,1), is answered in Section IV.B only for α² ∈ (0, 0.455); the text should explicitly state that the question is answered only partially.
- [Appendix A, Eq. (A1)] The fidelity formula (A1) is stated in terms of the eigenvalues of ρσ; this is valid for the commuting states used here, since ρE and ρ'E are co-diagonal, but the formula is not valid for general states, where the Uhlmann fidelity requires the trace of the square root of √ρ σ √ρ; the appendix should state this restriction.
- [Section V.A, Eq. (46)] The inequality (46) is actually an equality for qubit states, DHS = 2D²; noting this would clarify why the bounds in Tables II–III are loose and would simplify the derivation.
- [Figure 2] In Fig. 2 the y-axis is labeled 'r' while the caption refers to the lower bound Rlb; the plotted quantity should be labeled explicitly.
Circularity Check
No significant circularity: the key-rate analysis is an algebraic consequence of Woodhead's externally cited bound, and the QCM fidelities are derived from explicit cloning maps.
full rationale
The paper's central derivation starts from Woodhead's lower bound [20], R = 1 - h(u) - h(delta_z), an external, independently published result. The 'modified' bound R_lb is obtained by a sequence of algebraic lower-bound steps: replacing (1-delta_z) log(1-delta_z) with -delta_z via inequality (19), and then imposing R_lb > 0 to solve for allowed ranges of fidelity and delta_z. No parameter is fitted to data and then relabeled as a prediction; delta_z and F enter as free variables. The QCM fidelities in Eqs. (33) and (42) are computed explicitly from the stated cloning transformations, not imported from the authors' own prior results. The self-citations ([3] and [32]) are background references for existing QKD protocols and for the Hilbert-Schmidt distance; they are not load-bearing for the main derivation. There is no uniqueness theorem or ansatz smuggled in via self-citation, and no known result is merely renamed. The paper does contain a serious mathematical error: the inequality log(delta_z) > delta_z^2 - 2.5 delta_z is false on (0, 0.305), so Eqs. (21)-(23) and the advertised ranges F in (0.8281, 0.9922) and delta_z1 in (0, 0.305) are not established. However, that is a correctness defect, not circularity: the derivation does not assume the conclusion it claims to prove, and the central external input remains Woodhead's independent bound.
Assumptions & free parameters
free parameters (3)
- alpha^2 (Alice's state parameter) =
(0.293, 0.456) for WZ QCM; various (0,1) for modified BH QCM
- xi (modified BH QCM parameter) =
(0, 0.455)
- 2.5 coefficient in the log(delta_z) inequality =
2.5 (chosen constant)
assumptions (4)
- domain assumption Woodhead's key-rate bound r >= 1 - h(u) - h(delta_z) for BB84-like protocols under collective attacks
- standard math The inequality x/(1+x) <= ln(1+x) for x > -1
- standard math Fidelity and trace distance satisfy D(rho,sigma)^2 <= 1 - F(rho,sigma)
- domain assumption Cloning transformations for the WZ and BH QCMs with unitarity conditions
Cite this review
Pith. "Pith review of Condition for the generation of the secret key in a BB84 like quantum key distribution protocol." pith.science (2026). https://pith.science/paper/SPKJI32E
@misc{pith2026250416434,
author = {Pith},
title = {Pith review of: Condition for the generation of the secret key in a BB84 like quantum key distribution protocol},
year = {2026},
howpublished = {\url{https://pith.science/paper/SPKJI32E}},
note = {Machine review of arXiv:2504.16434}
}
read the original abstract
Woodhead [Phys. Rev. A 88, 012331 (2013)] derived the lower bound of the secret key rate for a Bennett-Brassard (BB84) like quantum key distribution protocol under collective attacks. However, this lower bound does not always assure the generation of the secret key and thus the protocol may have to be aborted sometimes. Thus, we modify the Woodhead's lower bound of the secret key rate in such a way that the secret key is always generated in a BB84 like quantum key distribution protocol. We show the non-linear relationship between the lower bound of the secret key rate with the error rate and fidelity. Exploiting the obtained modified lower bound of the secret key rate, we analyze two state dependent quantum cloning machines such as (i) Wootters-Zurek QCM and (ii) Modified Buzek-Hillery QCM constructed by fixing the cloning machine parameters of Buzek Hillery quantum cloning machine (QCM), which may be used by the eavesdropper to extract information from the intercepted state. We, thereafter, show that it is possible for the communicating parties to distill a secret key, even in the presence of an eavesdropper. Moreover, we also discuss the effect of the efficiency of the QCM on the generation of the secret key for a successful key distribution protocol.
Figures
Reference graph
Works this paper leans on
-
[1]
Efficiency of WZ QCM in successful QKD protocol The efficiency of WZ QCM for Rlb > 0 can be analyzed by the table (II) given below. α 2 FW Z(ρE, ρ ′ E) D(ρE, ρ ′ E)2 DW Z HS (ρE, ρ id) 0.293 0.8286 [0,0.3134) [0,0.6268) 0.30 0.84 [0,0.2944) [0,0.5888) 0.35 0.91 [0,0.1719) [0,0.3438) 0.40 0.96 [0,0.0784) [0,0.1568) 0.45 0.99 [0,0.0199) [0,0.0398) 0.456 0.9922 ...
-
[2]
305), the expression of Rlb given in (20) further 5 reduces to Rlb > 1 log 2 [ a + δ2 z − 1
5δz for δz ∈ (0, 0. 305), the expression of Rlb given in (20) further 5 reduces to Rlb > 1 log 2 [ a + δ2 z − 1
-
[3]
5 −δz ] (21) For Rlb > 0, we have to find the values of fidelity F (ρE,ρ ′ E) and δz for which the right hand side of (21) is positive, i.e., a + δ2 z − 1
-
[4]
Simplifying this condition, we get a quadratic equation in δz, which is given by δ2 z − 2
5 −δz > 0 holds. Simplifying this condition, we get a quadratic equation in δz, which is given by δ2 z − 2. 5δz + 2. 5a − 1> 0 (22) Solving the inequality (22), we get 0<δ z < 2. 5 − √10. 25 − 10a 2 (23) and
-
[5]
25 − 10a 2 <δ z (24) Since, in general, δz ∈ (0, 1), so we eliminate (24)
5 + √10. 25 − 10a 2 <δ z (24) Since, in general, δz ∈ (0, 1), so we eliminate (24). Therefore, the inequality (23) holds for F (ρE,ρ ′ E) ∈ (0. 8281, 0. 9922). Substitute a in terms of F (ρE,ρ ′ E) in the inequality (23) and solving, we find that for a given F (ρE,ρ ′ E), δz ∈ (0,δ z1), where δz1 ∈ (0, 0. 305). Therefore, the in- equality 0 < Rlb < R holds...
-
[6]
Here ξ and η denotes the cloning transformation parameters. It can be noted here that if we choose ξ = 0, then it implies η = 0 also, and BH cloning transformation reduces to WZ QCM. So, here we modify the BH QCM by choosing η = 0 and ξ ⁄= 0. In this case, BH QCM will become a state dependent QCM. Let us assume that Eve uses the modified QCM for cloning th...
work page 2019
-
[7]
Efficiency of modified BH QCM in successful QKD protocol ξ α 2 FBH (ρE, ρ ′ E) D(ρE, ρ ′ E)2 DBH HS (ρid, ρ E) 0.1 0.241 0.8283 [0,0.3139) [0,0.6279) 0.30 0.8976 [0,0.1943) [0,0.3886) 0.35 0.9424 [0,0.1118) [0,0.2237) 0.40 0.9744 [0,0.0504) [0,0.1009) 0.445 0.9936 [0,0.0154) [0,0.0308) 0.2 0.155 0.8286 [0,0.3134) [0,0.6268) 0.20 0.8704 [0,0.2424) [0,0.4848) ...
work page 1943
- [8]
Show all 45 references
-
[9]
C. H. Bennett, and G. Brassard, In: Proceedings of the IEEE International Conference on Computers, Sys- tems, and Signal Processing, Bangalore, India (IEEE, New York, 1984), pp. 175-179
1984
-
[10]
Jain, and S
R. Jain, and S. Adhikari, Eu. Phys. J. D 78, 145 (2024)
2024
-
[11]
A. K. Ekert, Phys. Rev. Lett. 67, 661 (1991)
1991
-
[12]
A. R. Dixon, and H. Sato, Sci. Rep. 4, 7275 (2014)
2014
-
[13]
V. A. Pastushenko, and D. A. Kronberg, Entropy 25, 956 (2023)
2023
-
[14]
Horvath, L
T. Horvath, L. B. Kish, and J. Scheuer, Europhy. Lett. 94 28002, (2011)
2011
-
[15]
B. Y. Tang, B. Liu, Y. P. Zhai, C. Q. Wu, and W. R. Yu, Sci. Rep. 9, 15733 (2019)
2019
-
[16]
Pirandola, et al., Adv
S. Pirandola, et al., Adv. Opt. Photonics 12, 1012 (2020)
2020
-
[17]
Biham, M
E. Biham, M. Boyer,G. Brassard, J. V. Graaf, and T. Mor, Algorithmica, 34, 372 (2002)
2002
-
[18]
Renner, Arxiv preprint arXiv:0512258 (2005)
R. Renner, Arxiv preprint arXiv:0512258 (2005)
2005
-
[19]
Gottesman, H.-K
D. Gottesman, H.-K. Lo, N. L /dieresis.ts1utkenhaus, and J. Preskill, Quant. Inf. Comp. 4, 325 (2004)
2004
-
[20]
Devetak and A
I. Devetak and A. Winter, Proc. R. Soc. A 461, 207 (2005)
2005
-
[21]
Kraus, N
B. Kraus, N. Gisin, and R. Renner, Phys. Rev. Lett. 95, 080501 (2005)
2005
-
[22]
Marøy, L
Ø. Marøy, L. Lydersen, and J. Skaar, Phys.Rev.A 82, 032337 (2010)
2010
-
[23]
Koashi, New J
M. Koashi, New J. Phys. 11, 045018 (2009)
2009
-
[24]
Curty, T
M. Curty, T. Moroder, X. Ma, H. K. Lo, and N. Lutken- haus, Phys. Rev. A 79, 032335 (2009)
2009
-
[25]
E. Kaur, K. Horodecki, and S. Das, Phys. Rev. App. 18, 054033 (2022)
2022
-
[26]
Zhang, Q
Z. Zhang, Q. Zhao, M. Razavi, and X. Ma, Phys. Rev. A 95, 012333 (2017)
2017
-
[27]
Woodhead, Phys
E. Woodhead, Phys. Rev. A 88, 012331 (2013)
2013
-
[28]
Dogra, K
S. Dogra, K. Dorai, and Arvind, Phys. Rev. A. 91, 022312 (2015)
2015
-
[29]
Zhang, Z
P.Wang, Y. Zhang, Z. Lu, X. Wang and Y. Li, New J. Phys. 25, 023019 (2023)
2023
-
[30]
Ecker, L
P.Sohr, S. Ecker, L. Bulla, M. Bohmann and R. Ursin, Phy. Rev. App. 22, 024059 (2024)
2024
-
[31]
Shor and J
P.W. Shor and J. perskill, Phys. Rev. Lett. 85, 441 (2000)
2000
-
[32]
T. M. Cover, Elements of information theory. John Wiley & Sons (1999)
1999
-
[33]
W. K. Wooters, and W. H. Zurek, Nature London, 299, 802, (1982)
1982
- [34]
-
[35]
Buˇ zek, and M
V. Buˇ zek, and M. Hillery, Phys. Rev. A 54, 1844 (1996)
1996
-
[36]
Dodonov, O.V
V.V. Dodonov, O.V. Man’ko, V.I. Man’ko & A. W¨ unsche, Jour. Mod. Opt.47, 633 (2000)
2000
-
[37]
Witte, and M
C. Witte, and M. Trucks, Phys. Lett. A 257, 14 (1999)
1999
-
[38]
Ozawa, Entanglement measures and the Hilbert- Schmidt distance, Phys
M. Ozawa, Entanglement measures and the Hilbert- Schmidt distance, Phys. Lett. A 268, 158 (2000)
2000
-
[39]
Jain, and S
R. Jain, and S. Adhikari, Phys. Scr. 100, 035113 (2025)
2025
-
[40]
Cincio, Y
L. Cincio, Y. Subasi, A. T. Sornborger, and P. J. Coles, New J. Phys. 20, 113022 (2018)
2018
-
[41]
J. Lee, M. S. Kim, and C. Brukner, Phys. Rev. Lett. 91, 087902 (2003)
2003
-
[42]
M. A. Nielsen, and I. L. Chuang, Quantum Computation and Quantum Information. Cambridge University Press, New Delhi (2008)
2008
-
[43]
Coles, M
P. Coles, M. Cerezo, and L. Cincio, Phys. Rev. A 100, 022103 (2019). Appendix A: Fidelity between ρ and σ In this section, we will calculate the fidelity between two density matrices ρ and σ . The fidelity F (ρ,σ ) is given by [27] F (ρ,σ ) = ( ∑ i √ λ i(ρσ ) ) 2 (A1) where λ i ...
2019
-
[44]
There- fore, substituting these values in (A1), we get FW Z(ρE,ρ ′ E) = ( √ α 2β 2 + √ α 2β 2 ) 2 = ( 2 √ α 2β 2 ) 2 = 4α 2β 2 (A3)
Fidelity of WZ QCM for |φ ⟩ and |φ ′⟩ The fidelity between the density matrices ρE and ρ′ E given in (29-31) maybe calculated as ρEρ′ E = [ α 2β 2 0 0 α 2β 2 ] (A2) The eigenvalues ofρEρ′ E are given by α 2β 2,α 2β 2. There- fore, substituting these values in (A1), we get FW Z(...
-
[45]
Fidelity of the modified BH QCM The eigenvalues of the product of the density matrices ρE and ρ′ E obtained by Eve after applying the cloning transformation (34) and tracing out Bob’s bits, can be given by {(α 2 + ξ(β 2 − α 2))(β 2 + ξ(α 2 − β 2)), (α 2 + ξ(β 2 −α 2))(β 2 +ξ(α ...
Reviewed August 16, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.