Pith. sign in

REVIEW 4 major objections 7 minor 59 references

Side-channel-secure quantum key distribution with correlated sources

T0 review · 4 major / 7 minor · reviewed 2026-08-06 · deepseek-v4-flash

Pith's one-line read Correlated sources no longer break QKD security proofs.

desk verdict A genuinely new grouping argument extends side-channel-secure QKD to correlated sources with known finite range, but the proof's validity hinges entirely on that range being exactly right. read the letter →

arxiv 2507.11243 v2 pith:ODCVG4H7 submitted 2025-07-15 quant-ph

classification quant-ph MSC 81P94
keywords quantumkeydistributionside-channelsecuritycorrelatedsourcesmeasurement-device-independentQKDfinite-keycoherentattacksphaseerrorestimationKatoinequality
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper proposes a quantum key distribution protocol that keeps its security proof even when the source's state preparation is imperfect in a way that correlates many rounds together. The claim is that the protocol is immune to all correlations of any dimension, as long as the correlations are non-entangled, have a known finite range, and the vacuum component of each emitted state has a known lower bound. Unlike earlier treatments, the strength of the correlation never has to be measured or bounded: only the range matters. The authors give a finite-key security analysis against coherent attacks and show numerically that a small correlation range barely costs performance, while even a range of 500 affected rounds still yields key over a 10 dB-loss channel. If correct, this removes a major practical obstacle between QKD theory and real modulators.

What carries the argument

The load-bearing object is the grouping of all rounds into $r_1+r_2+1$ residue classes modulo $r_1+r_2+1$, so that no two rounds in the same class lie within the correlation range of each other. Conditioned on the bit choices outside the class, measurements in the class factor, so a Chernoff bound can bound the number of $\lvert--\rangle$ signal events per class. Around this, the proof uses the vacuum decomposition $\lvert\phi_{s_A}\rangle_{Ap a_i}=\sqrt{P^i_{0A}}\lvert\mathrm{puri}_0\rangle_{Ap}\lvert0\rangle_{a_i}+\sqrt{1-P^i_{0A}}\lvert\phi_1\rangle_{Ap a_i}$ with $P^i_{0A}\ge P_{0A}$, Kato's inequality to pass from observed bit errors to phase-error expectations, and the uncertainty relation for smooth entropies to finish the key-length bound.

What would settle it

Find or build a source where flipping the encoding bit $s_i^A$ changes the emitted state at round $i+r_2+1$, one step beyond the declared forward range, with all other assumptions intact; then the grouping bound on $\lvert--\rangle$ signal events does not hold, so the claimed secrecy parameter is not justified. Experimentally, one could prepare a fixed bit pattern, flip one encoding, and measure a phase-sensitive observable of the pulse $r_2+1$ positions later.

Watch

Extended reading notes

Core claim

The central discovery is that grouping the rounds into $r_1+r_2+1$ residue classes modulo $r_1+r_2+1$ turns a correlated preparation into an effectively independent one for the purpose of bounding the number of $\lvert--\rangle$ signal events. Because encoding of round $u$ only affects rounds $u-r_1$ through $u+r_2$, rounds in the same class are separated by more than the correlation range, so conditioned on the bits outside a class, measurements inside the class are independent. This lets the authors bound $N^{--}_{\mathrm{sig}}$ by a Chernoff bound per class and sum the failure probabilities, and then use Kato's inequality plus the lower bound on vacuum projections to convert the observed bit-error count into an upper bound on phase errors. The result is a composable finite-key secrecy bound with security parameter $\epsilon_{\mathrm{tot}} = \epsilon_{\mathrm{cor}} + 2\sqrt{r_1+r_2+4}\,\epsilon + \tilde{\epsilon}$, and a key-length formula that depends on the correlation only through the sum $r_1+r_2$.

Load-bearing premise

The declared forward and backward correlation ranges $r_1$ and $r_2$ must truly cover every pulse a round's encoding can influence; if the real correlation reaches one step farther, the grouping argument no longer bounds $N^{--}_{\mathrm{sig}}$ and the security proof gives no guarantee.

Editorial extensions

If this is right

  • An implementation never needs to measure how strong the correlation is; declaring an upper bound on its range is sufficient for the security proof.
  • The protocol inherits measurement-device independence, so detector-side loopholes are covered without sacrificing source-side immunity.
  • Finite-key security against coherent attacks holds with a security parameter that grows only as the square root of the correlation range.
  • A small correlation range costs little performance: the simulation gives a maximal transmission loss above 60 dB, while even $r_1+r_2=500$ still yields key over a 10 dB-loss channel.
  • For $r_1+r_2=0$ the protocol reduces to phase-coding side-channel-secure QKD, so the new protocol is a strict generalization.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • The paper does not report a direct experimental calibration of $r_1$ and $r_2$; a concrete test would be to flip one encoding bit and look for changes in the emitted state exactly $r_2+1$ rounds later, then run the protocol with that measured range.
  • The proof implicitly exposes a trade-off between the vacuum lower bound and the correlation range, since the phase-error bound scales through a factor like $1-P_{0A}^{r_1+r_2+1}$; tuning the operating point to maximize this factor is an optimization the simulations only partially explore.
  • A natural extension, beyond what the paper considers, would allow unbounded but decaying correlations by introducing a cutoff range and paying a small extra failure probability for the tail that crosses the cutoff.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

4 major / 7 minor

Summary. The paper presents a measurement-device-independent QKD protocol (FCS-QKD) designed to remain secure when the source states are imperfectly prepared with correlations across rounds. The security model assumes that, for each round, Alice's and Bob's emitted states are product states over rounds (no entanglement), that the correlation range is finite and known (backward range r1, forward range r2), and that the vacuum component of each emitted state is at least P0. The main technical contribution is a finite-key security proof against coherent attacks. The proof upper-bounds the phase-error rate by relating phase errors to observed bit errors and to the unobserved number of |--⟩ signal events; the latter is bounded by grouping rounds into r1+r2+1 classes and using the vacuum lower bound together with Chernoff and Kato concentration inequalities. Numerical simulations are reported for different correlation ranges, claiming maximal tolerable loss above 60 dB for small ranges and secure key at 10 dB loss for a range of 500.

Significance. If the proof is correct, the protocol is a significant advance over previous correlated-source QKD analyses (e.g., refs. [34-36]), because it does not require characterizing the correlation strength, only its finite range and a vacuum-probability lower bound. The security argument is non-circular: the phase-error bound is derived from the vacuum component and the correlation range without fitted parameters. The composable finite-key statement against coherent attacks is a useful and nontrivial result. The main caveats are that the performance claims rest on an idealized simulation with under-specified parameters, and that the advertised 'immunity to all correlations' requires the finite-range and non-entanglement assumptions to hold exactly.

major comments (4)
  1. [Sec. V, Table I and Fig. 1] The numerical simulation omits several quantities that enter the key-rate formula (35) and the security bound (32): the mean photon number μ, the parameter-estimation probability P_est, the abort thresholds n_est,tol and n_sig,tol, and the vacuum-probability lower bound P0. Without these, the curves in Fig. 1 and the headline numbers (60 dB, 30 dB, 10 dB) are not reproducible. Please report the values, the optimization procedure, and the resulting optimal parameters for at least one representative setting.
  2. [Abstract and Sec. I] The statement that the protocol is 'immune to all correlations of all dimensions' overstates the result. The security proof requires the correlation range to be finite and known, and the prepared states to be non-entangled product states across rounds (Sec. III). If the true range exceeds r1 or r2, the grouping argument in Sec. IV—specifically the factorization in Eq. (24) and the bound in Eq. (31)—does not apply, and the security proof collapses. The text should consistently state 'immune to arbitrary correlation strength for a known finite range' and explicitly warn that a wrong range declaration invalidates the guarantee.
  3. [Sec. IV, Eq. (24)] The factorization in Eq. (24) is the load-bearing step of the N^{--}_{sig} bound, but the justification given in the text is too terse. Please show explicitly that for every pulse a_m in the block [g+kL-r1, g+kL+r2], the set of encoding bits that can influence it is [m-r2, m+r1], and that this interval lies strictly between the neighboring group-g bits g+(k-1)L and g+(k+1)L, so that after conditioning on s^{∼g}_A the block state depends on no group-g bit other than s_{g+kL}. Without this calculation, the reader cannot verify the claimed product structure.
  4. [Sec. V, simulation model] The simulation assumes that 'correlation and state preparation inaccuracy do not influence the click rates a lot' and computes key rates with ideal weak coherent states. This is an optimistic estimate, not a guaranteed rate for all states satisfying the security assumptions. Since the security proof allows arbitrary non-vacuum components, the actual key rate depends on the observed click statistics; the paper should state this limitation explicitly and, ideally, provide a sensitivity analysis (e.g., varying μ and P0) to indicate how robust the performance claims are.
minor comments (7)
  1. [Sec. IV, after Eq. (8)] The sentence says a bit error from a right click corresponds to '|00⟩ or |00⟩'; this should be '|00⟩ or |11⟩'.
  2. [Sec. IV, Eq. (20)] Eq. (20) and the surrounding text are difficult to parse because of the typesetting of the sums and projections; please rewrite with a clearer notation, e.g., explicitly defining the traced-out state and the conditioning on s^{∼g}_A, s^{∼g}_B.
  3. [Sec. IV, Eq. (23)] The block state |φ^{r1+r2+1}_{s_A}⟩_{Apag,k} should carry an explicit label indicating that it is defined for fixed values of the outside bits s^{∼g}_A; otherwise the expression looks ambiguous.
  4. [Sec. V, Fig. 1] Fig. 1 appears to lack axis labels and a caption in the provided text; the curves should be clearly labeled with the corresponding r1+r2 values.
  5. [Sec. V, Table I] Table I lists the detector dark count d, misalignment e_mis, error-correction efficiency f, total security parameter ε_tot, and number of rounds N, but does not list the vacuum-probability bound P0. If the simulation uses ideal coherent states, P0 = e^{-μ}, but this should be stated.
  6. [Appendix A] The parameter ε in Appendix A is used both as the security parameter and as the failure probability in Kato's inequality; please rename one of them to avoid confusion.
  7. [References] Reference [29] is cited as an arXiv preprint; if a published version exists, please update the citation.

Circularity Check

0 steps flagged · score 1.0 of 10

No significant circularity: the finite-key security bound is derived from the stated assumptions via an explicit concentration argument; the only self-citation is a non-load-bearing protocol template.

full rationale

The paper's security claim is derived, not assumed. The phase-error bound in Eq. (32) follows from (i) the inequality chain of Eqs. (7)-(13) relating phase-error probabilities to observed bit errors, (ii) the grouping decomposition of Eqs. (19)-(24), which uses only the declared finite correlation range (each round's encoding influences at most the neighboring r1+r2+1 rounds, giving the tensor-product structure within each group), and (iii) the vacuum lower bound P0 of Eq. (2), which yields the per-round probability bound P^-_A <= 1-(P0)^(r1+r2+1) in Eq. (28). The unobserved quantity N^{--}_{sig} is bounded in Eq. (31) by a union bound over r1+r2+1 groups, each handled by a Chernoff argument conditioned on fixed outside bits (Eq. (21)); Kato's inequality (Appendix A) converts observed counts into expectation bounds. No parameter in the phase-error bound is fitted to the security claim, and the key-rate formula of Eq. (35) depends only on the stated inputs (P0, r1, r2, Pest) and observed counts (nest,bit, nsig). The abstract's 'immune to all correlations' is qualified in the body by the three explicit assumptions: product states, known finite correlation range, and bounded vacuum probability; the proof does not covertly assume its own conclusion. The only self-citation is reference [29], the authors' prior SCS protocol, used as the protocol template ('The flow of the FCS protocol is almost the same as the phase-coding SCS protocol [29]') and as the r1+r2=0 limiting case in Sec. V; the correlated-case security analysis is re-derived from first principles in this paper and does not reduce to any result imported from [29]. The finite-range assumption is the most delicate condition: if the true correlation extends beyond the declared r1 and r2, the factorization in Eq. (24) fails and the bound in Eq. (31) collapses. This is a stated assumptions-sensitivity issue affecting robustness and the scope of the 'immune to all correlations' claim, not circularity. The numerical section explicitly models click rates with ideal weak coherent states, and the security proof is independent of that simulation choice, so no fitted input is renamed as a prediction.

Assumptions & free parameters 3 free parameters · 8 assumptions · 0 invented entities

The central security proof rests on three main domain assumptions: product-state correlation, known finite range, and a known vacuum probability lower bound. These are physically motivated but not independently verified by the paper. The simulation adds an ad hoc assumption that correlation does not change click statistics. No new physical entities are introduced; the ancillas and the parameter estimation flag are mathematical tools.

free parameters (3)
  • P_est (parameter estimation probability) = not stated
    Appears in the phase error bound and key rate formula (Eqs. 32, 35). The simulation does not give its value, but the result depends on it.
  • μ (mean photon number of signal) = not stated
    The simulation uses ideal weak coherent states with an implied intensity μ, but the value is not specified. The key rate and loss tolerance depend on μ.
  • Abort thresholds n_est,tol and n_sig,tol = not stated
    These thresholds determine when the protocol aborts. Their values are not given in the simulation, affecting the key rate and security parameters.
assumptions (8)
  • domain assumption For a fixed bit string s_A, the prepared state is a product state over rounds: |φ_{s_A}⟩_{a1} ⊗ ... ⊗ |φ_{s_A}⟩_{aN} (non-entangled correlation).
    Invoked in Sec. III (state preparation description). This excludes quantum correlations across rounds; the paper argues laser sources and modulators cannot practically create entanglement.
  • domain assumption The encoding s_i^A only influences rounds i-r1 to i+r2, with known bounds r1 and r2 (finite correlation range).
    Stated in Sec. III and used in the grouping argument in Sec. IV (Eqs. 20-31). If the correlation range is underestimated, the N^{--}_{sig} bound and thus the phase-error bound fail.
  • domain assumption For every round, the projection probability onto the vacuum state is lower bounded: tr(|φ_{s_A}⟩⟨φ_{s_A}|_{Apa_i}|0⟩⟨0|_{a_i}) ≥ P0A (and similarly P0B).
    Invoked in Sec. III (Eq. 2) and used to bound P_-^A in Eq. 28. If the bound is wrong, the phase-error estimate is too optimistic.
  • domain assumption Alice and Bob choose their bits uniformly at random from {0,1}^N.
    Protocol requirement stated in Sec. III; needed for the virtual phase-error estimation and the random sampling argument.
  • domain assumption Alice's and Bob's state preparations are independent: |Φ⟩_A ⊗ |Φ⟩_B.
    Stated in Sec. IV before Eq. 4. This is reasonable for separate devices, but if a common cause correlates Alice's and Bob's sources, the proof would need modification.
  • standard math Kato's inequality and the Chernoff bound are valid as stated in Appendix A.
    Used in Eqs. 12, 17, 29 to convert conditional expectations into bounds on observed counts with controlled failure probabilities.
  • standard math The leftover hashing lemma and the smooth entropy uncertainty relation (Refs. [9,11,40-43]) are valid.
    Used in Sec. IV (Eqs. 33-35) to convert the phase-error bound into a secret key length with composable security.
  • ad hoc to paper In the simulation, correlation and state preparation inaccuracy do not affect the click rates; key rates are computed with ideal weak coherent states.
    Stated in Sec. V. This is a performance modeling assumption, not part of the security proof, and it underlies the claimed 60 dB and 30 dB loss figures.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Side-channel-secure quantum key distribution with correlated sources." pith.science (2026). https://pith.science/paper/ODCVG4H7

@misc{pith2026250711243,
  author       = {Pith},
  title        = {Pith review of: Side-channel-secure quantum key distribution with correlated sources},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/ODCVG4H7}},
  note         = {Machine review of arXiv:2507.11243}
}
read the original abstract

Quantum key distribution (QKD) offers theoretical security guarantees for sharing secure key, but its practical systems face challenges due to the imperfections of devices. Widespread quantum state preparation imperfections, such as correlations between multiple rounds, significantly undermine the real-world security of QKD. In this paper, we propose a protocol that is immune to almost all kinds of state-preparation imperfections over multiple correlated rounds arising from both encoding and unknown non-encoding dimensions. The protocol relies only on three assumptions: the imperfect encoding produces unknown product states rather than entangled ones, a lower bound on the vacuum components is known, and the correlation has a finite range. The proposed protocol is also measurement-device-independent, ensuring high security at both the source and measurement sides. We provide the finite-key security analysis against coherent attacks and conduct numerical simulations to see the performance. The results show that for small correlation ranges, the protocol achieves excellent performance with a maximal transmission loss exceeding 60 dB (>300 km in standard fiber). Even for extreme cases, where one encoding affects up to 500 neighboring rounds, the protocol can still generate secret keys over a 10 dB-loss channel.

Figures

Figures reproduced from arXiv: 2507.11243 by the authors.

Figure 1
Figure 1. FIG. 1. The simulation result of the FCS protocol under differ [PITH_FULL_IMAGE:figures/full_fig_p011_1.png] view at source ↗

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

59 extracted references · 56 canonical work pages

  1. [29]

    Diamanti, H.-K

    E. Diamanti, H.-K. Lo, B. Qi, and Z. Yuan, Practical chal lenges in quantum key distribution, npj Quantum Informatio n 2, 1 (2016)

  2. [1]

    In the i-th round, Alice (Bob) chooses to select the modulation bit si A (si B) from {0, 1} uniformly at random

    State preparation. In the i-th round, Alice (Bob) chooses to select the modulation bit si A (si B) from {0, 1} uniformly at random. We define sA = {s1 A,s 2 A,... } and similar for sB. Then she (he) tries to prepare the state |φsA ⟩ai = ⏐ ⏐ ⏐√ µeiπsi A ⟩ (|φsB ⟩bi = ⏐ ⏐ ⏐√ µeiπsi B ⟩ ), which is a coherent state with an intensity µ and a phase πsi A (πsi B...

  3. [2]

    If Charlie is honest, the two pulses from Alice and Bob will interfere on a beam splitter

    State measurement. If Charlie is honest, the two pulses from Alice and Bob will interfere on a beam splitter. Then Charlie uses two single-photon detectors to detect the two o utputs of the interference. We assume the left detector corresponds to the constructive interference an d the right detector corresponds to the destructive interference. If only one...

  4. [3]

    After N rounds of state preparation and the click announcement of Charlie , sA and sB of clicked rounds are kept as sifted key bits

    Sifting. After N rounds of state preparation and the click announcement of Charlie , sA and sB of clicked rounds are kept as sifted key bits. For the right-clicked rounds, B ob should flip his key bit sB

  5. [4]

    Alice and Bob randomly reveal the key bits of some rounds and count the number of bit errors of these rounds as nest,bit

    Parameter estimation. Alice and Bob randomly reveal the key bits of some rounds and count the number of bit errors of these rounds as nest,bit. Each round is independently selected for this parameter estimatio n with a probability Pest. For the remaining rounds which are not selected for parameter es timation, Alice and Bob count the number of clicks as n...

  6. [5]

    Alice and Bob conduct error correction and private amplification to the raw key bits to generate the final secure key bits

    Postprocessing. Alice and Bob conduct error correction and private amplification to the raw key bits to generate the final secure key bits. III. STATE PREP ARATION DESCRIPTION In Sec. II, we have described the ideal states that Alice and Bob wa nt to prepare. However, we do not need an accurate description of the states to keep security. In the fo llowing, ...

  7. [6]

    This is because for ideal state preparation, |++⟩AiBi and |−−⟩AiBi correspond to the cases of even-photon, which are expected to cause few clicks

    For both left and right clicks, we define that a phase error corresponds to a measurement result o f |++⟩AiBi or |−−⟩AiBi. This is because for ideal state preparation, |++⟩AiBi and |−−⟩AiBi correspond to the cases of even-photon, which are expected to cause few clicks. In this hypothetical measurement, the signal rounds are measur ed on the X basis and the...

  8. [7]

    Thus the conditional probability of finding the u-th round to be a 5 parameter estimation round with a bit error is shown in the following. P u est,bit = ∑ x tr ( (|est⟩ peu ⟨ est|peu ) [ P{(|++⟩ AuBu − |−−⟩ AuBu )/ √ 2} + P{(|+−⟩ AuBu − |− +⟩ AuBu )/ √ 2} ] |L⟩ ⟨ L|Cu P { (⨂ u−1 i=1 M AB i )√Fx |Φ ⟩ | LROx ⟩ N C } ) ∑ x tr ( P { (⨂ u−1 i=1 M AB i )√Fx |Φ ...

Show all 59 references
  1. [8]

    Alice and Bob measure their ancillas round by round, which means be fore they measure the ancillas Au,B u, peu and Cu, they have finished the measurement on Ai,B i, pei and Ci for all i ∈ {1, 2,...,u − 1}

  2. [9]

    Note that the order of measurements in different rounds d o not influence measurement results

    Alice and Bob measure the ancillas pe i and if they find a |sig⟩pei they measure AiBi on the X basis of this round. Note that the order of measurements in different rounds d o not influence measurement results. After the above measurement, Alice and Bob measure the rest ancillas....

  3. [10]

    (26) 9 Recall the assumption of the states in eq

    (25) Then the probability of finding a |−⟩Ag+k(r1 +r2+1) is shown as P − A = 1 4 ‖ ‖ ‖ ‖ ‖ ⏐ ⏐ ⏐ ⏐φr1+r2+1 sA(sg+k(r1 +r2+1) A =0) ⟩ Apag,k − ⏐ ⏐ ⏐ ⏐φr1+r2+1 sA(sg+k(r1 +r2+1) A =1) ⟩ Apag,k ‖ ‖ ‖ ‖ ‖ 2 . (26) 9 Recall the assumption of the states in eq. (3) and the definition i...

  4. [11]

    Kato’s inequality

    Kato’s inequality Kato’s inequality [44] is an improved version of Azuma’s inequality [45], w hich has been widely used in the security analysis of quantum key distribution. Kato’s inequality . Let {Xm} be a list of random variables, and Fm be the measurement result of the ran...

  5. [12]

    Multiplicative Chernoff bound

    Chernoff bound In our security analysis, we use the Chernoff bound [47] to get the upper bound of measurement result for inde- pendent random variables. Multiplicative Chernoff bound. Suppose X1,X 2,...,X n are independent random variables taking values in {0, 1}. Let X =X1 +X2 +...

  6. [13]

    C. H. Bennett and G. Brassard, Quantum cryptography: pub lic key distribution and coin tossing int, in Conf. on Com- puters, Systems and Signal Processing (Bangalore, India, D ec. 1984) (1984) pp. 175–179

  7. [14]

    Wang, Z.-Q

    S. Wang, Z.-Q. Yin, D.-Y. He, W. Chen, R.-Q. Wang, P. Ye, Y. Zhou, G.-J. Fan-Yuan, F.-X. Wang, W. Chen, et al. , Twin-field quantum key distribution over 830-km fibre, Natur e photonics 16, 154 (2022)

  8. [15]

    Liu, W.-J

    Y. Liu, W.-J. Zhang, C. Jiang, J.-P. Chen, C. Zhang, W.-X. Pan, D. Ma, H. Dong, J.-M. Xiong, C.-J. Zhang, et al. , Experimental twin-field quantum key distribution over 1000 km fiber distance, Physical Review Letters 130, 210801 (2023)

  9. [16]

    Liu, W.-J

    Y. Liu, W.-J. Zhang, C. Jiang, J.-P. Chen, D. Ma, C. Zhang, W.-X. Pan, H. Dong, J.-M. Xiong, C.-J. Zhang, et al. , 1002 km twin-field quantum key distribution with finite-key analy sis, Quantum Frontiers 2, 16 (2023)

  10. [17]

    W. Li, L. Zhang, H. Tan, Y. Lu, S.-K. Liao, J. Huang, H. Li, Z . Wang, H.-K. Mao, B. Yan, et al. , High-rate quantum key distribution exceeding 110 mb s–1, Nature photonics 17, 416 (2023)

  11. [18]

    Gr¨ unenfelder, A

    F. Gr¨ unenfelder, A. Boaron, G. V. Resta, M. Perrenoud, D . Rusca, C. Barreiro, R. Houlmann, R. Sax, L. Stasi, S. El- Khoury, et al. , Fast single-photon detectors and real-time key distillat ion enable high secret-key-rate quantum key distri- bution systems, Nature Photonics...

  12. [19]

    P. W. Shor and J. Preskill, Simple proof of security of the bb84 quantum key distribution protocol, Physical review le tters 85, 441 (2000)

  13. [20]

    Mayers, Unconditional security in quantum cryptogra phy, Journal of the ACM (JACM) 48, 351 (2001)

    D. Mayers, Unconditional security in quantum cryptogra phy, Journal of the ACM (JACM) 48, 351 (2001)

  14. [21]

    Renner, Security of quantum key distribution, Intern ational Journal of Quantum Information 6, 1 (2008)

    R. Renner, Security of quantum key distribution, Intern ational Journal of Quantum Information 6, 1 (2008)

  15. [22]

    Tomamichel, C

    M. Tomamichel, C. C. W. Lim, N. Gisin, and R. Renner, Tigh t finite-key analysis for quantum cryptography, Nature communications 3, 634 (2012)

  16. [23]

    Tomamichel and A

    M. Tomamichel and A. Leverrier, A largely self-contain ed and complete security proof for quantum key distribution , Quantum 1, 14 (2017)

  17. [24]

    Portmann and R

    C. Portmann and R. Renner, Security in quantum cryptogr aphy, Reviews of Modern Physics 94, 025008 (2022)

  18. [25]

    F. Xu, X. Ma, Q. Zhang, H.-K. Lo, and J.-W. Pan, Secure qua ntum key distribution with realistic devices, Rev. Mod. Phys. 92, 025002 (2020)

  19. [26]

    Brassard, N

    G. Brassard, N. L¨ utkenhaus, T. Mor, and B. C. Sanders, L imitations on practical quantum cryptography, Physical re view letters 85, 1330 (2000)

  20. [27]

    L¨ utkenhaus and M

    N. L¨ utkenhaus and M. Jahma, Quantum key distribution w ith realistic states: photon-number statistics in the phot on- number splitting attack, New Journal of Physics 4, 44 (2002). 14

  21. [28]

    Scarani, H

    V. Scarani, H. Bechmann-Pasquinucci, N. J. Cerf, M. Duˇ sek, N. L¨ utkenhaus, and M. Peev, The security of practical quantum key distribution, Reviews of modern physics 81, 1301 (2009)

  22. [30]

    Kang, F.-Y

    X. Kang, F.-Y. Lu, S. Wang, J.-L. Chen, Z.-H. Wang, Z.-Q. Yin, D.-Y. He, W. Chen, G.-J. Fan-Yuan, G.-C. Guo, et al. , Patterning-effect calibration algorithm for secure decoy- state quantum key distribution, Journal of Lightwave Techn ology 41, 75 (2022)

  23. [31]

    Mayers and A

    D. Mayers and A. Yao, Quantum cryptography with imperfe ct apparatus, in Proceedings 39th Annual Symposium on Foundations of Computer Science (Cat. No. 98CB36280) (IEEE, 1998) pp. 503–509

  24. [32]

    Ac ´ ın, N

    A. Ac ´ ın, N. Brunner, N. Gisin, S. Massar, S. Pironio, and V. Scarani, Device-independent security of quantum crypt ography against collective attacks, Physical Review Letters 98, 230501 (2007)

  25. [33]

    S. L. Braunstein and S. Pirandola, Side-channel-free q uantum key distribution, Phys. Rev. Lett. 108, 130502 (2012)

  26. [34]

    H.-K. Lo, M. Curty, and B. Qi, Measurement-device-inde pendent quantum key distribution, Phys. Rev. Lett. 108, 130503 (2012)

  27. [35]

    Hwang, Quantum key distribution with high loss: t oward global secure communication, Physical review letter s 91, 057901 (2003)

    W.-Y. Hwang, Quantum key distribution with high loss: t oward global secure communication, Physical review letter s 91, 057901 (2003)

  28. [36]

    H.-K. Lo, X. Ma, and K. Chen, Decoy state quantum key dist ribution, Phys. Rev. Lett. 94, 230504 (2005)

  29. [37]

    Wang, Beating the photon-number-splitting atta ck in practical quantum cryptography, Physical review lett ers 94, 230503 (2005)

    X.-B. Wang, Beating the photon-number-splitting atta ck in practical quantum cryptography, Physical review lett ers 94, 230503 (2005)

  30. [38]

    Wang, X.-L

    X.-B. Wang, X.-L. Hu, and Z.-W. Yu, Practical long-dist ance side-channel-free quantum key distribution, Physica l Review Applied 12, 054034 (2019)

  31. [39]

    Jiang, Z.-W

    C. Jiang, Z.-W. Yu, X.-L. Hu, and X.-B. Wang, Side-chann el-secure quantum key distribution with imperfect vacuum sources, Physical Review Applied 19, 064003 (2023)

  32. [40]

    Jiang, X.-L

    C. Jiang, X.-L. Hu, Z.-W. Yu, and X.-B. Wang, Side-chann el security of practical quantum key distribution, Physica l Review Research 6, 013266 (2024)

  33. [41]

    Shan, Z.-Q

    Y.-G. Shan, Z.-Q. Yin, S. Wang, W. Chen, D.-Y. He, G.-C. G uo, and Z.-F. Han, Practical phase-coding side-channel-se cure quantum key distribution, arXiv preprint arXiv:2305.1386 1 (2023)

  34. [42]

    Kobayashi, A

    T. Kobayashi, A. Tomita, and A. Okamoto, Evaluation of t he phase randomness of a light source in quantum-key- distribution systems with an attenuated laser, Phys. Rev. A 90, 032320 (2014)

  35. [43]

    G. L. Roberts, M. Pittaluga, M. Minder, M. Lucamarini, J . F. Dynes, Z. L. Yuan, and A. J. Shields, Patterning-effect mitigating intensity modulator for secure decoy-state qua ntum key distribution, Opt. Lett. 43, 5110 (2018)

  36. [44]

    Yoshino, M

    K.-i. Yoshino, M. Fujiwara, K. Nakata, T. Sumiya, T. Sas aki, M. Takeoka, M. Sasaki, A. Tajima, M. Koashi, and A. Tomit a, Quantum key distribution with an efficient countermeasure ag ainst correlated intensity fluctuations in optical pulses, npj Quantum Information 4, 8 (2018)

  37. [45]

    Curr´ as-Lorenzo, S

    G. Curr´ as-Lorenzo, S. Nahar, N. L¨ utkenhaus, K. Tamak i, and M. Curty, Security of quantum key distribution with imperfect phase randomisation, Quantum Science and Techno logy 9, 015025 (2023)

  38. [46]

    Pereira, G

    M. Pereira, G. Kato, A. Mizutani, M. Curty, and K. Tamaki , Quantum key distribution with correlated sources, Scienc e Advances 6, eaaz4487 (2020)

  39. [47]

    Zapatero, ´A

    V. Zapatero, ´A. Navarrete, K. Tamaki, and M. Curty, Security of quantum ke y distribution with intensity correlations, Quantum 5, 602 (2021)

  40. [48]

    Sixto, V

    X. Sixto, V. Zapatero, and M. Curty, Security of decoy-s tate quantum key distribution with correlated intensity flu ctuations, Phys. Rev. Appl. 18, 044069 (2022)

  41. [49]

    Ben-Or and D

    M. Ben-Or and D. Mayers, General security definition and composability for quantum & classical protocols, arXiv pre print quant-ph/0409062 (2004)

  42. [50]

    Unruh, Simulatable security for quantum protocols, arXiv preprint quant-ph/0409125 (2004)

    D. Unruh, Simulatable security for quantum protocols, arXiv preprint quant-ph/0409125 (2004)

  43. [51]

    M¨ uller-Quade and R

    J. M¨ uller-Quade and R. Renner, Composability in quant um cryptography, New Journal of Physics 11, 085006 (2009)

  44. [52]

    Tomamichel, C

    M. Tomamichel, C. Schaffner, A. Smith, and R. Renner, Lef tover hashing against quantum side information, IEEE Trans - actions on Information Theory 57, 5524 (2011)

  45. [53]

    Tomamichel, Quantum information processing with finite resources: math ematical foundations, Vol

    M. Tomamichel, Quantum information processing with finite resources: math ematical foundations, Vol. 5 (Springer, 2015)

  46. [54]

    Tomamichel, A framework for non-asymptotic quantum information theory, arXiv preprint arXiv:1203.2142 (2012 )

    M. Tomamichel, A framework for non-asymptotic quantum information theory, arXiv preprint arXiv:1203.2142 (2012 )

  47. [55]

    Tomamichel and R

    M. Tomamichel and R. Renner, Uncertainty relation for s mooth entropies, Physical review letters 106, 110506 (2011)

  48. [56]

    Kato, Concentration inequality using unconfirmed kn owledge, arXiv preprint arXiv:2002.04357 (2020)

    G. Kato, Concentration inequality using unconfirmed kn owledge, arXiv preprint arXiv:2002.04357 (2020)

  49. [57]

    Azuma, Weighted sums of certain dependent random var iables, Tohoku Mathematical Journal, Second Series 19, 357 (1967)

    K. Azuma, Weighted sums of certain dependent random var iables, Tohoku Mathematical Journal, Second Series 19, 357 (1967)

  50. [58]

    Curr´ as-Lorenzo, ´A

    G. Curr´ as-Lorenzo, ´A. Navarrete, K. Azuma, G. Kato, M. Curty, and M. Razavi, Tigh t finite-key security for twin-field quantum key distribution, npj Quantum Information 7, 22 (2021)

  51. [59]

    Mitzenmacher and E

    M. Mitzenmacher and E. Upfal, Probability and computing: Randomization and probabilist ic techniques in algorithms and data analysis (Cambridge university press, 2017)

Pith tools

Reviewed August 6, 2026 · model on record in the stance chip above.