REVIEW 3 major objections 4 minor 1 cited by
Security of quantum key distribution with source and detector imperfections through phase-error estimation
T0 review · 3 major / 4 minor · reviewed 2026-08-06 · deepseek-v4-flash
Pith's one-line read The paper shows that any BB84-type quantum key distribution security proof that assumes basis-independent detection efficiency can be mechanically upgraded to also cover detector efficiency mismatches, giving finite-key security against…
desk verdict Sound main reduction but the decoy-state extension has a load-bearing gap; worth a careful referee. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The engine of the proof is a single 'global' phase-error estimation protocol (Fig. A1) in which Bob first applies a basis-independent filter $\{\tilde{F}, I-\tilde{F}\}$, announces which rounds pass, and only then decides whether to run the ideal detection scenario $S_{0,0}$ or the mismatch scenario $S_{\delta_1,\delta_2}$. In $S_{0,0}$ Bob's final measurement on key rounds applies the $X$-basis-dependent filter $\{F_X, I-F_X\}$ followed by the phase-error POVM $\{G^{(X)}_{\neq}, G^{(X)}_{=}\}$; in $S_{\delta_1,\delta_2}$ he applies the $Z$-basis-dependent filter $\{F_Z, I-F_Z\}$ instead. Two parameters from the companion detector-imperfections analysis control the gap: $\delta_1 = \bigl\| \sqrt{F_Z}\, G^{(X)}_{\neq}\sqrt{F_Z} - \sqrt{F_X}\, G^{(X)}_{\neq}\sqrt{F_X}\bigr\|_\infty$ quantifies how far the phase-error POVM elements are apart, and $\delta_2 = \|I - F_Z\|_\infty$ bounds the probability that a key round is discarded by the $Z$-filter but would have survived the $X$-filter. Two cited lemmas turn these operator bounds into statistical statements: with high probability the phase-error count in the mismatch scenario exceeds that in the ideal scenario by no more than $\tilde{n}_K \delta_1$ plus a binomial finite-size term, and the observed number of surviving key rounds $n_K$ is at least $\tilde{n}_K(1-\delta_2 - \gamma)$; the theorem then maximises the original bound over the unobserved intermediate sample size $\tilde{n}_K$. The monotonicity of $F_{0,0}(\vec{n}_X, n_K):=n_K E_{0,0}(\vec{n}_X, n_K)$ — established in Appendix D for the upgraded source-imperfect bound via an auxiliary monotonicity lemma for the function $G_+$ — lets the maximum in the bound be evaluated at a single point, yielding the simpler expression in Eq. (7).
What would settle it
A concrete way to test the central claim is to search numerically over small finite-dimensional source-replacement states and Bob POVMs that satisfy the definitions of $\delta_1$ and $\delta_2$, and check whether the phase-error rate under detection mismatch ever violates the bound $E_{\delta_1,\delta_2}$ with probability greater than $\varepsilon^2_{\mathrm{ind}}+\varepsilon^2_{\mathrm{dep-1}}+\varepsilon^2_{\mathrm{dep-2}}$; finding such a violation would show the borrowed lemmas do not hold for correlated global states, and finding none at large sample sizes would support the theorem.
Extended reading notes
Core claim
The central claim is a lifting theorem for phase-error estimation in BB84-type protocols. Given any phase-error-rate bound of the form $\Pr_{S_{0,0}}(e_{\mathrm{ph}} > E_{0,0}(\vec{n}_X, n_K)) \le \varepsilon^2_{\mathrm{ind}}$ that holds when Bob's detection efficiency is basis-independent, the paper constructs a bound for the scenario with detection efficiency mismatch parameterised by $\delta_1$ and $\delta_2$: $E_{\delta_1,\delta_2}(\vec{n}_X, n_K) = \frac{\max_{n \in W_{\delta_2}(n_K)} n E_{0,0}(\vec{n}_X,n)}{n_K} + \frac{\delta_1 + \gamma^{\varepsilon_{\mathrm{dep-1}}}_{\mathrm{bin}}(n_K,\delta_1)}{1 - \delta_2 - \gamma^{\varepsilon_{\mathrm{dep-2}}}_{\mathrm{bin}}(n_K,\delta_2)}$, with failure probability at most $\varepsilon^2_{\mathrm{ind}} + \varepsilon^2_{\mathrm{dep-1}} + \varepsilon^2_{\mathrm{dep-2}}$. Asymptotically this reduces to $e^{(S_{\delta_1,\delta_2})}_{\mathrm{ph}} \lesssim (e^{(S_{0,0})}_{\mathrm{ph}} + \delta_1)/(1-\delta_2)$. The proof works by embedding both detection scenarios into one global phase-error estimation protocol in which Bob fixes all observed statistics before choosing which scenario to run; the two scenarios differ only in a basis-dependent filter applied to the key rounds, and the parameters $\delta_1$ and $\delta_2$ control how much the phase-error count and the surviving-round count can change. The paper applies the theorem to the existing source-imperfect bound, proves the monotonicity condition its simplified form requires, and extends the same argument to decoy-state protocols, yielding the combined finite-key rate.
Load-bearing premise
The load-bearing premise is that two already-established technical facts — that the mismatch scenario's phase-error count exceeds the basis-independent one by at most $\delta_1$ per round, and that the number of surviving key rounds is at least $(1-\delta_2-\gamma)$ times the pre-filter count — remain valid for the fully general, round-correlated source-replacement states used in the global protocol, since the paper cites these lemmas from the companion analysis rather than proving them here.
Editorial extensions
If this is right
- Any phase-error bound for BB84-type protocols that assumes basis-independent detection efficiency — including bounds that already handle imperfect, partially characterised sources — can be upgraded to cover detection efficiency mismatch, with only two added finite-size failure terms.
- Asymptotically the detector penalty is a simple shift-and-scale of the source-imperfection penalty: $e^{(S_{\delta_1,\delta_2})}_{\mathrm{ph}} \lesssim (e^{(S_{0,0})}_{\mathrm{ph}}+\delta_1)/(1-\delta_2)$.
- The upgrade carries over to decoy-state BB84 protocols: both the lower bound on single-photon key rounds and the phase-error bound extend to detection mismatch, so the final secret-key length formula applies to double-imperfect decoy systems.
- The numerical simulation at $N=10^{12}$ signals shows the secret-key rate penalty with both flaws is close to the sum of the individual source and detector penalties, indicating the two imperfections do not create additional hidden losses in this framework.
Reading between the lines
- Because the theorem treats the input phase-error bound as a black box, future improvements to source-imperfection analyses (tighter tails, larger source classes) can be plugged in without re-working the detector side; the same modularity plausibly applies to three-state and other BB84-type variants that admit the same phase-error estimation structure.
- In practice the result means a QKD vendor need not characterise the full detector POVM to claim robustness against efficiency mismatch: coarse per-detector efficiency and dark-count tolerances suffice to bound $\delta_1$ and $\delta_2$, so the proof could be used with standard detector datasheet specifications.
- The observed near-additivity of source and detector penalties suggests a fast engineering rule of thumb — approximate the double-imperfect key rate by concatenating the two individual analyses — which could be verified at other parameter regimes (shorter blocks, higher dark counts) where the finite-size terms behave differently.
- Since the proof assumes active basis choice on Bob's side and all announcements after the quantum phase, extending the modular upgrade to passive basis choice or real-time announcements would likely require a separate argument rather than a direct copy of Theorem 1.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. This manuscript presents a modular method for extending phase-error-estimation security proofs for BB84-type protocols from the assumption of basis-independent detection efficiency to the case of detection efficiency mismatch. Given a bound of the form Pr_{S0,0}(e_ph > E_{0,0}(n_X,n_K)) ≤ ε²_ind, Theorem 1 (Appendix B) constructs a bound of the form Pr_{Sδ1,δ2}(e_ph > E_{δ1,δ2}(n_X,n_K)) ≤ ε²_ind + ε²_dep-1 + ε²_dep-2, using two lemmas from Ref. [15]. The paper further claims this extension applies to decoy-state protocols (Theorem 2, Appendix C) and applies the result to the source-imperfection analysis of Ref. [20], with finite-key numerical simulations. The main text also derives simplified formulas under monotonicity assumptions and proves monotonicity of the [20] bound in Appendix D.
Significance. The idea of composing a source-imperfection-tolerant phase-error bound with a detector-mismatch correction in a black-box fashion is attractive and, if correct, would be practically valuable: it would let existing source-side finite-key security proofs be upgraded to handle detector efficiency mismatches without redoing the full analysis. The main theorem is a clean reduction to Ref. [15]'s lemmas, and the paper is careful to specify the underlying virtual protocols. The manuscript also provides reproducible Mathematica code for a key monotonicity check and explicit numerical key-rate comparisons, which are useful. However, the decoy-state extension contains a serious gap (see Major Comment 1), and the main theorem's reliance on unstated lemmas from a preprint limits verifiability. The significance is therefore conditional on fixing these points.
major comments (3)
- [Appendix C, Eq. (C4)] The assertion that Eq. (C1) implies the analogous bound under Sδ1,δ2 because Eq. (C1) 'depends only on the outcomes of the Z POVM rounds' is not valid. Under Sδ1,δ2, Bob's Z-basis rounds pass through the basis-dependent filter FZ (Appendix A2) before the bit POVM, so the joint distribution of (nK,1, nZ) is not the same as in S0,0. A lower bound M(nZ) derived for basis-independent detection efficiency can overestimate the true number of single-photon key rounds when FZ is photon-number- or bit-dependent; for example, an FZ that preferentially rejects single-photon states leaves M(nZ)>0 while the true nK,1 is zero. This step is load-bearing for Theorem 2, Corollary 2, Eq. (24) in the End Matter, and the numerical results, which rely on the decoy-state extension.
- [Appendix B, Theorem 1] The proof of the main theorem is a reduction to Lemmas 3 and 4 of Ref. [15], but neither lemma is stated in this manuscript. Since Theorem 1 is the central result, the paper should reproduce the lemma statements (or the relevant special cases) and state explicitly the conditions under which they apply to the global source-replacement state of Eq. (1), which may be arbitrarily correlated across rounds. As written, the reader cannot verify that the lemmas' hypotheses are satisfied.
- [Appendix D] The monotonicity proof of F0,0 has a gap at the piecewise definition: when N_det_ZC=1 - ΔA(z) ≤ 0, the bound is replaced by the trivial nK, but the limiting value of the formula-based bound as the denominator tends to zero is not compared with nK. If that limit is less than nK, the piecewise function would have a downward jump and would not be non-decreasing. Since Corollary 1 and the simplified formula (7) are used in the numerical section, this gap affects the reported key rates if it cannot be closed.
minor comments (4)
- [Appendix B, Eq. (B16)] The second equality in the chain of Eq. (B16), which replaces nK(δ1+γ)/(1-δ2-γ) with max_{n~∈V} n~(δ1+γ), is generally not an equality because the floor in Vδ2 makes the maximum strictly smaller; it should be written as an inequality. The final bound remains valid, but the proof should be corrected.
- [End Matter] The global scenario in Appendix B defines the collection of nZ statistics only implicitly; for the decoy-state protocol, the manuscript should specify whether the Z-basis counts are recorded before or after the FZ filter in Sδ1,δ2. The current text leaves this ambiguous, which is directly connected to Major Comment 1.
- [Introduction, Eq. (7)] The inline formula for the simplified bound Eδ1,δ2 is missing parentheses: it should clearly indicate that the denominator (1-δ2-γ) applies to the entire numerator (E0,0 + δ1 + γ), consistent with the asymptotic expression in Eq. (8). The current notation is ambiguous.
- [Conclusion] The claim that this is 'the only work capable of computing explicit key rates in such scenarios' is difficult to verify and could be softened, especially given the open gaps in the decoy-state extension.
Circularity Check
No significant circularity: the main theorem is a conditional extension that transforms an input phase-error bound via prior detector-mismatch lemmas, adding explicit δ1/δ2 penalties; the decoy-state step in Appendix C contains an unproven assertion, but that is a correctness gap rather than a by-construction equivalence.
full rationale
The derivation chain is: given any basis-independent phase-error bound Pr_{S0,0}(e_ph > E_{0,0}(n_X,n_K)) ≤ ε_ind², Theorem 1 converts it into a bound under S_{δ1,δ2} with an explicit penalty E_{δ1,δ2} = (max_{n∈W_{δ2}(n_K)} n E_{0,0}(n_X,n) / n_K + δ1 + γ_bin)/(1 − δ2 − γ_bin). The output is not just the input renamed: it is a transformed expression with δ1, δ2, and finite-size binomial corrections, proved via conditional-probability relations from Ref. [15] (Lemmas 3 and 4). Those lemmas are prior results by overlapping authors, but they are used as external inputs with stated assumptions, not re-derived by renaming the target statement. The paper also explicitly notes that substituting Eq. (B25) into Eq. (B19) recovers Ref. [15, Eq. (36)], a consistency check, not a hidden reproduction. No fitted parameter is later called a prediction: E_{0,0} and M(n_Z) come from the input proof, and δ1/δ2 are bounded from detector-tolerance model parameters. The numerical results inherit the source bound from Ref. [20] and the detector bound from Ref. [15], and are compared against the ideal case. The one questionable step is the decoy-state transfer in Appendix C: the paper asserts Eq. (C1) implies Eq. (C4) because it depends only on outcomes of Z POVM rounds, but under S_{δ1,δ2} the Z measurement itself is preceded by the F_Z filter, so the joint distribution of (n_{K,1}, n_Z) changes and the transfer is not automatic; no proof is supplied. This is a potential correctness gap in the decoy-state extension, but it is not circular: the claimed decoy bound is not equivalent to its input by construction, and the main single-photon theorem is separate. Therefore no circular step is identified.
Assumptions & free parameters
assumptions (4)
- domain assumption Bob's measurement can be decomposed into a basis-independent filter, a basis choice, and a two-outcome POVM (Appendix A); when efficiencies are mismatched, a common upper-bound filter tild_F to F_Z and F_X exists.
- domain assumption Validity of Refs. [15, Lemma 3 and Lemma 4] relating phase-error and key-round statistics between S0,0 and S_delta1_delta2.
- standard math Standard concentration inequalities (Azuma, Chernoff, Hoeffding, Serfling) and the source-replacement/phase-error estimation framework, plus EUR+LHL for key length.
- domain assumption For the numerical section, Alice's source states satisfy the fidelity bound <phi_j|rho^(k)_j|phi_j> >= 1 - epsilon (Eq. 11) from Ref. [20], and Bob's detectors are parameterized by Eq. (13).
Cite this review
Pith. "Pith review of Security of quantum key distribution with source and detector imperfections through phase-error estimation." pith.science (2026). https://pith.science/paper/AKY7WWW7
@misc{pith2026250703549,
author = {Pith},
title = {Pith review of: Security of quantum key distribution with source and detector imperfections through phase-error estimation},
year = {2026},
howpublished = {\url{https://pith.science/paper/AKY7WWW7}},
note = {Machine review of arXiv:2507.03549}
}
read the original abstract
Quantum key distribution (QKD) promises information-theoretic security based on quantum mechanics, but practical implementations face security vulnerabilities due to device imperfections. Recent advances have separately addressed source and detector imperfections in phase-error-estimation based security proof frameworks, but this is not enough to protect real-world QKD systems suffering from both types of imperfections simultaneously. In this work, we show that existing techniques for BB84-type protocols can be combined to construct a unified security proof that simultaneously accounts for both source and detector imperfections. Our approach thus represents a significant step towards closing the gap between theoretical security proofs and practical QKD implementations.
Figures
Forward citations
Cited by 1 Pith paper
-
Experimental quantum cryptography with single photons and imperfect devices
A 20-minute BB84 run with a quantum-dot single-photon source yields ≈2.2×10^6 finite-size secure bits under a security proof that explicitly includes beamsplitter, detector-efficiency, dark-count, and multiphoton unce...
Reference graph
Works this paper leans on
-
[15]
For each round in ˜NZ , Alice attempts a projection onto the subspace spanned by{|0⟩A , |1⟩A}. Let ˜NK be the subset of rounds for which this projection is successful, and let ˜nK be the random variable associated to the size of ˜NK
-
[20]
Boundary z(xb) = 0. Let xb > 0 satisfy z(xb) = 0. • As x → x− b : We have z(x) < 0, so we are in the “otherwise” branch where G+(y, z(x)) = 1. Thus f (x) = x and limx→x− b f (x) = xb. • At x = xb: Since z(xb) = 0 fails the condition z >0, we have G+(y, z(xb)) = 1 and f (xb) = xb. • As x → x+ b : We have z(x) → 0+. For any y >0, there exists a right-neighb...
-
[1]
This implies that Bob could have substituted his actual measurement by the following:
Basis-independent detection efficiency In this case, Bob performs two POVMs Z = {Γ(Z) 0 , Γ(Z) 1 , Γ(Z) ⊥ } and X = {Γ(X ) 0 , Γ(X ) 1 , Γ(X ) ⊥ } whose op- erators corresponding to an undetected round are the same for both bases, i.e., Γ (Z) ⊥ = Γ(X ) ⊥ . This implies that Bob could have substituted his actual measurement by the following:
-
[2]
For each round, apply the filtering POVM { ˜F ,I − ˜F }, where ˜F = Γ(Z) 0 + Γ(Z) 1 = Γ(X ) 0 + Γ(X ) 1
-
[4]
Measure these states using the two-outcome POVM {G(β) 0 , G(β) 1 }, where G(β) b := p ˜F + Γ(β) b p ˜F + + P (β) b , (A1) with ˜F + denoting the pseudoinverse of ˜F , and P (β) b any positive operators satisfying P b∈{0,1} P (β) b = I − Π ˜F , where Π ˜F denotes the projector onto the support of ˜F . As explained in the main text, thanks to this equivalen...
-
[5]
Basis-dependent detection efficiency In this case, the operators corresponding to an unde- tected round are in general not equal, i.e., Γ (Z) ⊥ ̸= Γ(X ) ⊥ . Here, we can define the basis dependent filters ˜FZ = Γ(Z) 0 + Γ(Z) 1 and ˜FX = Γ(X ) 0 + Γ(X ) 1 and assume the fol- lowing equivalent scenario for Bob:
-
[6]
For each round, decide his basis choice β ∈ {Z, X }
-
[7]
For each round, apply the filter ˜Fβ corresponding to the selected basis β
Show all 73 references
-
[8]
Again, thanks to this equivalence, we can assume that Alice and Bob learn which subset of Z rounds are used to generate the key before learning their bit values
For the rounds that pass the filter, measure using the two-outcome POVM {G(β) 0 , G(β) 1 }, where G(β) b := q ˜F + β Γ(β) b q ˜F + β + P (β) b , (A2) with P (β) b being any positive operators satisfyingP b∈{0,1} P (β) b = I − Π ˜Fβ . Again, thanks to this equivalence, we can a...
-
[9]
For each round, apply the basis-independent filter- ing POVM { ˜F ,I − ˜F }
-
[10]
For the rounds that pass the filter, decide his basis choice β ∈ {Z, X }
-
[11]
(A3) Note that this is equivalent since applying first the filter ˜F and then the filter FZ (FX ) is equivalent to apply- ing the overall filter ˜FZ ( ˜FX )
Perform the second basis-dependent filtering POVM {Fβ, I − Fβ}, where Fβ := p ˜F + ˜Fβ p ˜F + + I − Π ˜F . (A3) Note that this is equivalent since applying first the filter ˜F and then the filter FZ (FX ) is equivalent to apply- ing the overall filter ˜FZ ( ˜FX ). This allows ...
-
[12]
Alice prepares her global source-replacement state in Eq. (1)
-
[13]
Let ˜N be the set of rounds that pass this filter
Bob applies the basis independent filter { ˜F ,I − ˜F }. Let ˜N be the set of rounds that pass this filter
-
[14]
Let ˜NZ ( ˜NX ) be the subset of ˜N for which Bob chooses the Z (X ) POVM
For each round in ˜N , Bob chooses the Z or X POVM, but does not perform any measurement yet. Let ˜NZ ( ˜NX ) be the subset of ˜N for which Bob chooses the Z (X ) POVM
-
[16]
For each round in ˜NX , Bob applies the X -basis- dependent filter {FX , I − FX }. Then, for the rounds that pass the filter, Alice performs a projection onto {|j⟩A}j∈{0,1,...}, learning her set- ting choice, while Bob performs the two-outcome POVM {G(X ) 0 , G(X ) 1 }, learni...
-
[17]
Then, for each round in ˜NK: If S0,0: Bob applies the X -dependent filter {FX , I − FX }; If Sδ1,δ2 : Bob applies the Z-dependent filter {FZ , I − FZ }
Bob decides whether to run basis independent (S0,0) or the basis dependent ( Sδ1,δ2 ) scenario. Then, for each round in ˜NK: If S0,0: Bob applies the X -dependent filter {FX , I − FX }; If Sδ1,δ2 : Bob applies the Z-dependent filter {FZ , I − FZ }. Let NK be the subset of roun...
-
[18]
For each round in NK, Alice and Bob measure {G(X) ̸= , G(X) = }
Let {G(X) ̸= , G(X) = } be Alice and Bob’s joint two-outcome X-basis POVM, i.e., G(X) ̸= = |+⟩ ⟨+|A ⊗ G(X ) 1 + |−⟩ ⟨−|A ⊗ G(X ) 0 . For each round in NK, Alice and Bob measure {G(X) ̸= , G(X) = }. Let nph be the R V associated to the number of events in which they obtain the ...
-
[19]
Consider the function f (x) ≡ f (x; y, a, c, p) for any fixed value of (y, a, c, p) such that (0, y, a, c, p) ∈ D, where f (x; y, a, c, p) is defined in Eq
Proof of Lemma 1 Lemma 1. Consider the function f (x) ≡ f (x; y, a, c, p) for any fixed value of (y, a, c, p) such that (0, y, a, c, p) ∈ D, where f (x; y, a, c, p) is defined in Eq. (D7). The function f (x) is non-decreasing in x for x ≥ 0. Proof. Let z(x) = 1 − a p(x+c) , su...
-
[21]
Let xb > 0 satisfy z(xb) = √y for y ∈ (0, 1)
Boundary z(xb)2 = y. Let xb > 0 satisfy z(xb) = √y for y ∈ (0, 1). • As x → x− b : We have z(x)2 < y, so G+(y, z(x)) = 1 and f (x) = x. Thus lim x→x− b f (x) = xb. • As x → x+ b : We have z(x) > √y, entering the main branch. Computing the limit: lim z→√y+ G+(y, z) = y + (1 − y...
-
[22]
This requires z(xb) = 1, which occurs only when a = 0
Boundary z(xb)2 = 1. This requires z(xb) = 1, which occurs only when a = 0. In this case, z(x) = 1 for all x, obtaining f (x) = xy (if y <1) or f (x) = x (if y = 1), both continuous. Since f (x) is continuous at all transition points, it is continuous on [0 , ∞). 19 2: Non-neg...
-
[23]
This occurs when z(x) ≤ 0 or when 0 < z(x) ≤ 1 with z(x)2 ≤ y
Case 1: G+(y, z(x)) = 1. This occurs when z(x) ≤ 0 or when 0 < z(x) ≤ 1 with z(x)2 ≤ y. Here f (x) = x, so f ′(x) = 1 > 0
-
[24]
This occurs when 0 ≤ y < z(x)2 ≤ 1 and z(x) > 0
Case 2: G+(y, z(x)) follows the main branch. This occurs when 0 ≤ y < z(x)2 ≤ 1 and z(x) > 0. The derivative is f ′(x) = G+(y, z(x)) + x ∂G+ ∂z (y, z(x)) · z′(x). (D20) A symbolic check in Mathematica under ( x, y, a, c, p) ∈ Dand z(x) > 0 confirms that this derivative is neve...
-
[25]
C. H. Bennett and G. Brassard, Quantum cryptography: Public key distribution and coin tossing, in Proc. IEEE Int. Conf. Comput. Syst. Signal Process. (1984) pp. 175– 179
1984
-
[26]
F. Xu, X. Ma, Q. Zhang, H.-K. Lo, and J.-W. Pan, Se- cure quantum key distribution with realistic devices, Rev. Mod. Phys. 92, 025002 (2020)
2020
-
[27]
Federal Office for Information Security (BSI), Germany, A study on implementation attacks against QKD systems (2023)
2023
-
[28]
Quantum key distribution (QKD) and quantum cryp- tography (QC), https://www.nsa.gov/Cybersecurity/ Quantum-Key-Distribution-QKD-and-Quantum-Cryptography-QC/
-
[29]
ANSSI, BSI, NLNCSA, and Swedish Armed Forces, Position paper on quantum key distribution, https://www.bsi.bund.de/SharedDocs/Downloads/ EN/BSI/Crypto/Quantum_Positionspapier.pdf?__ blob=publicationFile&v=4, accessed: 2025-02-26
2025
-
[30]
Gottesman, H.-K
D. Gottesman, H.-K. Lo, N. L¨ utkenhaus, and J. Preskill, Security of quantum key distribution with imperfect de- vices, Quantum Inf. Comput. 4, 325 (2004)
2004
-
[31]
C.-H. F. Fung, K. Tamaki, B. Qi, H.-K. Lo, and X. Ma, Security proof of quantum key distribution with detec- tion efficiency mismatch, Quantum Inf. Comput. 9, 131 (2009)
2009
-
[32]
Marøy, L
Ø. Marøy, L. Lydersen, and J. Skaar, Security of quan- tum key distribution with arbitrary individual imperfec- tions, Physical Review A—Atomic, Molecular, and Op- tical Physics 82, 032337 (2010)
2010
-
[33]
Lydersen and J
L. Lydersen and J. Skaar, Security of quantum key dis- tribution with bit and basis dependent detector flaws (2010), arXiv:0807.0767 [quant-ph]
2010 arXiv
-
[34]
Trushechkin, Security of quantum key distribution with detection-efficiency mismatch in the multiphoton case, Quantum 6, 771 (2022)
A. Trushechkin, Security of quantum key distribution with detection-efficiency mismatch in the multiphoton case, Quantum 6, 771 (2022)
2022
-
[35]
M. K. Bochkov and A. S. Trushechkin, Security of quan- tum key distribution with detection-efficiency mismatch in the single-photon case: Tight bounds, Physical Review A 99, 032308 (2019)
2019
-
[36]
Zapatero, ´A
V. Zapatero, ´A. Navarrete, K. Tamaki, and M. Curty, Security of quantum key distribution with intensity cor- relations, Quantum 5, 602 (2021)
2021
-
[37]
Pereira, G
M. Pereira, G. Curr´ as-Lorenzo, ´A. Navarrete, A. Mizu- tani, G. Kato, M. Curty, and K. Tamaki, Modified BB84 quantum key distribution protocol robust to source im- perfections, Phys. Rev. Res. 5, 023065 (2023)
2023
-
[38]
Tamaki, M
K. Tamaki, M. Curty, G. Kato, H.-K. Lo, and K. Azuma, Loss-tolerant quantum cryptography with imperfect sources, Phys. Rev. A 90, 052314 (2014)
2014
-
[39]
Tupkary, S
D. Tupkary, S. Nahar, P. Sinha, and N. L¨ utkenhaus, Phase error rate estimation in QKD with imperfect de- tectors (2024), arXiv:2408.17349
2024
-
[40]
Grasselli, G
F. Grasselli, G. Chesi, N. Walk, H. Kampermann, A. Widomski, M. Ogrodnik, M. Karpi´ nski, C. Macchi- 20 avello, D. Bruß, and N. Wyderka, Quantum Key Dis- tribution with Basis-Dependent Detection Probability (2024), arXiv:2411.19874 [quant-ph]
2024 arXiv
-
[41]
Marcomini, A
A. Marcomini, A. Mizutani, F. Gr¨ unenfelder, M. Curty, and K. Tamaki, Loss-tolerant quantum key distri- bution with detection efficiency mismatch (2024), arXiv:2412.09684 [quant-ph]
2024 arXiv
-
[42]
Sixto, ´A
X. Sixto, ´A. Navarrete, M. Pereira, G. Curr´ as-Lorenzo, K. Tamaki, and M. Curty, Quantum key distribution with imperfectly isolated devices, Quantum Sci. Technol. 10, 035034 (2025)
2025
-
[43]
Curr´ as-Lorenzo, ´A
G. Curr´ as-Lorenzo, ´A. Navarrete, J. N´ u˜ nez-Bon, M. Pereira, and M. Curty, Numerical security analysis for quantum key distribution with partial state charac- terization, Quantum Sci. Technol. 10, 035031 (2025)
2025
-
[44]
Curr´ as-Lorenzo, M
G. Curr´ as-Lorenzo, M. Pereira, G. Kato, M. Curty, and K. Tamaki, Security of high-speed quantum key distri- bution with imperfect sources (2025), arXiv:2305.05930 [quant-ph]
2025
-
[45]
Arqand, T
A. Arqand, T. Metger, and E. Y.-Z. Tan, Mutual infor- mation chain rules for security proofs robust against de- vice imperfections (2024), arXiv:2407.20396 [quant-ph]
2024 arXiv
-
[46]
Marwah and F
A. Marwah and F. Dupuis, Proving security of BB84 un- der source correlations (2024), arXiv:2402.12346 [quant- ph]
2024 arXiv
-
[47]
Nahar and N
S. Nahar and N. L¨ utkenhaus, Imperfect detectors for ad- versarial tasks with applications to quantum key distri- bution (2025), arXiv:2503.06328 [quant-ph]
2025
-
[48]
Kamin, J
L. Kamin, J. Burniston, and E. Y.-Z. Tan, R´ enyi secu- rity framework against coherent attacks applied to decoy- state QKD (2025), arXiv:2504.12248 [quant-ph]
2025
-
[49]
Sun and F
S. Sun and F. Xu, Security of quantum key distribution with source and detection imperfections, New J. Phys. 23, 023011 (2021)
2021
-
[50]
The approach in [23] requires bounding the weight out- side the preserved subspace for the flag-state squasher [50], which remains an open problem when the detection efficiency is not perfectly characterized. While this tech- nique shows promise and could potentially be combin...
-
[51]
Often, security proofs assume that both Alice’s setting choices and the states she emits are IID, i.e., pj1...jN = pj1 ...pjN and |ψj1...jN ⟩a1...aN = |ψj1 ⟩a1 ... |ψjN ⟩aN ; how- ever, our result is general and could be applied to proofs that do not require such IID assumptio...
-
[52]
Boileau, K
J.-C. Boileau, K. Tamaki, J. Batuwantudawe, R. Laflamme, and J. M. Renes, Unconditional Se- curity of a Three State Quantum Key Distribution Protocol, Phys. Rev. Lett. 94, 040503 (2005)
2005
-
[53]
To define a three-outcome POVM, double-click events must be assigned to a bit value
Note that in an active polarization-encoded BB84 de- tector setup, Bob’s actual POVMs actually have four elements: no click, click in detector 0, click in detec- tor 1, and double-click event. To define a three-outcome POVM, double-click events must be assigned to a bit value....
-
[54]
Tomamichel and R
M. Tomamichel and R. Renner, Uncertainty Relation for Smooth Entropies, Phys. Rev. Lett. 106, 110506 (2011)
2011
-
[55]
Tomamichel, C
M. Tomamichel, C. C. W. Lim, N. Gisin, and R. Renner, Tight finite-key analysis for quantum cryptography, Nat Commun 3, 634 (2012)
2012
-
[56]
Tomamichel and A
M. Tomamichel and A. Leverrier, A largely self-contained and complete security proof for quantum key distribu- tion, Quantum 1, 14 (2017)
2017
-
[57]
Koashi, Simple security proof of quantum key dis- tribution based on complementarity, New J
M. Koashi, Simple security proof of quantum key dis- tribution based on complementarity, New J. Phys. 11, 045018 (2009)
2009
-
[58]
Curr´ as-Lorenzo, ´A
G. Curr´ as-Lorenzo, ´A. Navarrete, K. Azuma, G. Kato, M. Curty, and M. Razavi, Tight finite-key security for twin-field quantum key distribution, npj Quantum Inf 7, 22 (2021)
2021
-
[59]
Hayashi and T
M. Hayashi and T. Tsurumaru, Concise and tight secu- rity analysis of the Bennett–Brassard 1984 protocol with finite key lengths, New J. Phys. 14, 093014 (2012)
2012
-
[60]
Kawakami, Security of Quantum Key Distribution with Weak Coherent Pulses , Ph.D
S. Kawakami, Security of Quantum Key Distribution with Weak Coherent Pulses , Ph.D. thesis
-
[61]
Ben-Or, M
M. Ben-Or, M. Horodecki, D. W. Leung, D. Mayers, and J. Oppenheim, The universal composable security of quantum key distribution, in Theory Cryptogr. Conf. , Vol. 3378 (Springer, 2005) pp. 386–406
2005
-
[62]
Pittaluga, M
M. Pittaluga, M. Minder, M. Lucamarini, M. San- zaro, R. I. Woodward, M.-J. Li, Z. Yuan, and A. J. Shields, 600-km repeater-like quantum communications with dual-band stabilization, Nat. Photon. 15, 530 (2021)
2021
-
[63]
H.-K. Lo, X. Ma, and K. Chen, Decoy State Quantum Key Distribution, Phys. Rev. Lett. 94, 230504 (2005)
2005
-
[64]
X. Ma, B. Qi, Y. Zhao, and H.-K. Lo, Practical decoy state for quantum key distribution, Phys. Rev. A 72, 012326 (2005)
2005
-
[65]
Hwang, Quantum key distribution with high loss: Toward global secure communication, Phys
W.-Y. Hwang, Quantum key distribution with high loss: Toward global secure communication, Phys. Rev. Lett. 91, 057901 (2003)
2003
-
[66]
Z. Cao, Z. Zhang, H.-K. Lo, and X. Ma, Discrete-phase- randomized coherent state source and its application in quantum key distribution, New J. Phys. 17, 053014 (2015)
2015
-
[67]
Sixto, G
X. Sixto, G. Curr´ as-Lorenzo, K. Tamaki, and M. Curty, Secret key rate bounds for quantum key distribution with faulty active phase randomization, EPJ Quantum Tech- nol. 10, 1 (2023)
2023
-
[68]
Tamaki, M
K. Tamaki, M. Curty, and M. Lucamarini, Decoy-state quantum key distribution with a leaky source, New J. Phys. 18, 065008 (2016)
2016
-
[69]
Wiesemann, F
J. Wiesemann, F. Gr¨ unenfelder, A. Bl´ azquez Co ´ ıdo, N. Walenta, and D. Rusca, Evaluation of quantum key distribution systems against injection-locking attacks, APL Photonics 10, 066112 (2025)
2025
-
[70]
Yoshino, M
K.-i. Yoshino, M. Fujiwara, K. Nakata, T. Sumiya, T. Sasaki, M. Takeoka, M. Sasaki, A. Tajima, M. Koashi, and A. Tomita, Quantum key distribution with an effi- cient countermeasure against correlated intensity fluctu- 21 ations in optical pulses, npj Quantum Inf 4, 1 (2018)
2018
-
[71]
Curr´ as-Lorenzo, S
G. Curr´ as-Lorenzo, S. Nahar, N. L¨ utkenhaus, K. Tamaki, and M. Curty, Security of quantum key distribution with imperfect phase randomisation, Quantum Sci. Technol. 9, 015025 (2023)
2023
-
[72]
Marcomini, G
A. Marcomini, G. Curr´ as-Lorenzo, D. Rusca, A. Valle, K. Tamaki, and M. Curty, Characterising higher- order phase correlations in gain-switched laser sources with application to quantum key distribution (2024), arXiv:2412.03738 [quant-ph]
2024 arXiv
-
[73]
(D21) where the states τmN 1 ,jN 1 ,µN 1 are possibly mixed
Even more generally, one can consider any decomposition of the form ρjN 1 ,µN 1 = X mN 1 pmN 1 |jN 1 ,µN 1 τmN 1 ,jN 1 ,µN 1 . (D21) where the states τmN 1 ,jN 1 ,µN 1 are possibly mixed. In this case, one can simply consider purifications |ψmN 1 ,jN 1 ,µN 1 ⟩aN 1 SN 1 , where...
-
[74]
Zhang, P
Y. Zhang, P. J. Coles, A. Winick, J. Lin, and N. L¨ utken- haus, Security proof of practical quantum key distribu- tion with detection-efficiency mismatch, Phys. Rev. Re- search 3, 013076 (2021)
2021
Reviewed August 6, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.