REVIEW 3 major objections 6 minor 2 cited by
Modeling and Characterization of Arbitrary Order Pulse Correlations for Quantum Key Distribution
T0 review · 3 major / 6 minor · reviewed 2026-08-15 · deepseek-v4-flash
Pith's one-line read A step-response measurement bounds all QKD pulse correlations.
desk verdict Clean LTI-step-response derivation of exponential pulse-correlation bounds, with a real gap between the fitted model and a certified security bound — worth serious review. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing object is the step-response error function $g(t)$, defined by writing the LTI system's step response as $\vartheta(t)=G_0[1+g(t)]\theta(t)$. For a low-pass system, $g(t)$ is a sum of damped oscillations, and the key technical step is replacing it by the global exponential envelope $|g(t)|\le A e^{-bt}$. Because the output is a superposition of shifted step responses, the phase difference between two $N$-pulse sequences that differ only in round $N-l$ collapses to $\Delta_{N-l}[g(t_0+lT)-g(t_0+(l-1)T)]$, which the envelope bounds term by term; the fidelity bounds for qubit phases and Poissonian intensity distributions then convert that into the exponential correlation bounds. This machinery is what reduces an exponential-in-$l$ characterization problem to two fitted parameters, $A$ and $b$.
What would settle it
Generate long random setting sequences and directly measure, for many large separations $l$, how much flipping the $(N-l)$-th setting changes the phase or intensity of pulse $N$; if any measured strength exceeds the corresponding exponential bound from Eq. (14) or Eq. (15), the model is falsified. A cheaper check is to record the actual step response over many time constants and test whether $|g(t)|\le A e^{-bt}$ holds everywhere, since the fitted envelope in the paper is only compared with one five-pulse sequence.
Extended reading notes
Core claim
The central claim is that for a transmitter whose memory is captured by an LTI low-pass system with step-response error satisfying $|g(t)| \le A e^{-bt}$, the setting-choice-dependent pulse correlations are bounded by $\epsilon_l^\phi(t_0) = \frac{1}{4} A^2 \Delta_{\max}^2 e^{-2bt_0}(1+e^{-bT})^2 e^{-2bT(l-1)}$ for phase encoding and $\epsilon_l^\mu(t_0) = \frac{\mu_0}{2} A \Delta_{\max} e^{-bt_0}(1+e^{-bT}) e^{-bT(l-1)}$ for intensity encoding. These are exactly the exponential form $\epsilon_l \le \epsilon_1 e^{-C(l-1)}$ that the unbounded-correlation security analysis of [23] requires, with $C^\phi=2bT$ and $C^\mu=bT$. Therefore a single step-response measurement---or, as done experimentally, the same data already acquired for short-range characterization---determines the effective maximum correlation length $l_e$, and existing finite-length proofs can be applied as if correlations beyond $l_e$ were zero, paying only a small security-parameter increase. The paper validates the model by fitting one measured five-pulse sequence from a 50 MHz transmitter and using the fitted filter to estimate $l_e^\phi=6$ and $l_e^\mu=11$ for $N=10^{12}$ emitted signals.
Load-bearing premise
The whole chain depends on the transmitter's memory being representable by a single linear low-pass system whose step-response error stays inside one exponential envelope $|g(t)|\le A e^{-bt}$ for all times; if the real device has nonlinear behavior that is not dominated by this linear response, or if the fitted $A$ and $b$ underestimate the true tail of $g(t)$, the exponential bounds on correlations are not guaranteed.
Editorial extensions
If this is right
- The characterization burden for arbitrary-order pulse correlations drops from generating and processing exponentially many setting sequences to measuring one step response and fitting two parameters.
- For the experimental 50 MHz transmitter with $N=10^{12}$, the effective correlation length is $l_e^\phi=6$ for phase correlations and $l_e^\mu=11$ for intensity correlations, so existing security proofs for finite $l_c$ apply with those values and a small security-parameter penalty.
- The correlation decay rate is set by the ratio of system bandwidth to repetition rate: $C^\phi=2bT$ and $C^\mu=bT$, so correlations grow when the protocol is run faster relative to the device bandwidth.
- Secret-key-rate simulations for BB84 with unbounded phase correlations show that using the LTI-model bounds, rather than raw experimental short-range strengths, preserves higher rates because state-preparation flaws are not counted as correlations.
Reading between the lines
- A natural testable prediction of the model is parameter transferability: the same fitted filter should predict correlations at other repetition rates, since $T$ enters the exponents explicitly, so re-running the characterization at 25 MHz and 100 MHz would check the model directly.
- If finite-key security proofs for intensity correlations become available, the same $A$ and $b$ parameters would immediately yield $l_e^\mu$ and unlock finite-key decoy-state rates under unbounded intensity correlations; the paper stops short of this because current intensity-correlation proofs are asymptotic.
- One could use the exponential envelope as a design tool before building a link: a single step-response measurement of candidate modulators would predict whether a chosen repetition rate is safely below the memory-dominated regime, guiding the bandwidth-versus-rate trade-off.
- The same LTI-envelope reasoning should transfer to other encoding degrees of freedom, such as polarization modulation through a birefringent phase modulator, because the underlying phase modulation is still a linear response to the applied field.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper introduces an LTI low-pass model for setting-choice-dependent (SCD) pulse correlations in QKD transmitters. It shows that if the step-response error satisfies |g(t)| ≤ A e^{-bt} (Eq. 13), then phase and intensity correlation strengths at any order l obey the exponential bounds (14) and (15), with parameters given in Eqs. (16)-(17). These bounds are of the form required by the security framework of Pereira et al. [23], allowing an effective maximum correlation length l_e (Eq. 11) to be computed. The authors measure short-range correlations up to fourth order for a 50-MHz intensity modulator driven by a 150-MHz AWG, fit a three-pole transfer function to one measured sequence (Fig. 7 and Table I), and use the fitted parameters to estimate l_e and to simulate secret-key rates for unbounded correlations (Fig. 9).
Significance. Conditional on Eq. (13), the paper provides a clean and useful analytical result: arbitrary-order correlation strengths can be bounded from a single step-response measurement, and the exponential decay rate is expressed through physically meaningful parameters. The derivation in Appendix D is internally consistent, and the bridge to the security analysis of [23] is clearly made. The experimental demonstration, including the characterization of all 243 five-pulse sequences and the distinction between correlations and state-preparation flaws, is valuable and clearly presented. However, the current experimental evidence does not certify that Eq. (13) is a true upper bound for the real device, and the intensity bounds are derived under a Dirac-delta pulse approximation that is not fully reconciled with the finite-width pulses used in the experiment. The significance of the paper would be substantially strengthened by a demonstration that the fitted parameters are conservative, e.g., via direct step-response measurement, uncertainty bounds, or validation on multiple sequences.
major comments (3)
- [Section IV.B and Eq. (13)] The central assumption that |g(t)| ≤ A e^{-bt} is a genuine upper bound for the real transmitter is not experimentally established. The parameters A=1.60 and b=318.7 Mrad/s come from a least-squares fit of a three-pole transfer function to a single five-pulse sequence (Fig. 7 and Table I); no uncertainty, residual analysis, or validation on independent sequences is provided. Because Eqs. (14)-(15) and the resulting l_e (Eq. 11) scale directly with A and e^{-bT(l-1)}, any underestimation of A or b, or any unmodeled nonlinearity, invalidates the claimed exponential bound for all l. The statement that nonlinearities are "still dominated by its linear behavior" is an assumption without supporting evidence. Please provide a certified upper bound on the true step response (via direct measurement, conservative fitting, or worst-case analysis) and validate it on multiple sequences.
- [Section IV.A and Appendix D, Eq. (15)] The intensity-correlation bound (15) is derived using the Dirac-delta pulse approximation leading to Eq. (D13). The experimental intensity characterization, however, uses Gaussian pulses of FWHM 1 ns (Eq. 9) integrated over Δt = 2 FWHM (Eq. 8). The paper does not show that Eq. (15) remains a valid upper bound for finite-width pulses, nor does it provide a finite-pulse correction. Since the experimental parameters, including the chosen t0 values, are defined for the finite-pulse case, this gap directly affects the applicability of the intensity-correlation results. Please provide a derivation for finite pulse shapes or demonstrate that the delta approximation is conservative for the measured pulse parameters.
- [Section V, Fig. 9] The model's best-case prediction ϵ_total = 3.83e-10 is orders of magnitude below the directly measured value 1.94e-3. The authors attribute this difference to SPFs and noise, but they do not provide a quantitative comparison of the model's predicted ϵ_l with the measured correlation strengths (Fig. 3 vs Fig. 8), nor do they demonstrate that the exponential bound (14) envelopes the measured short-range values. As written, the security claim rests on the unverified assumption that the model captures all SCD correlations. Please add a direct comparison of model predictions and experimental ϵ_l for l=1,...,4 and discuss explicitly whether the fitted bound is conservative with respect to those measured values.
minor comments (6)
- [Section IV.B] The word "dtermine" should be "determine".
- [Section IV.A] The notation ϵϕ_l(t0) is used both for the actual measured correlation strength and for the upper bound (e.g., Eq. (14)); consider using a distinct symbol such as ϵ̄ϕ_l(t0) for the bound to avoid confusion.
- [Section IV.B and Table I] Report uncertainties for the fitted parameters A and b and propagate them to Cϕ and Cµ; the current values are given without error bars.
- [Section V] The yellow lines in Fig. 9 assume ideal BB84 states with zero SPFs, but this is only stated in Appendix B; the main text should say so explicitly for clarity.
- [Appendix E, Eq. (E9)] Clarify that the bounds plotted in Fig. 7 are computed from the fitted transfer function, not directly from the measured waveform; a data-derived envelope would provide stronger evidence for Eq. (13).
- [Section III, experimental setup] It should be stated whether the measured V_AWG(t) includes the oscilloscope's 4-GHz bandwidth response, which could affect the fitted filter parameters.
Circularity Check
No significant circularity: the exponential correlation bound is derived from the LTI step-response model, and A,b are calibrated to a measured waveform rather than to the predicted correlation strengths.
full rationale
The derivation chain is self-contained. Section IV.A introduces the LTI low-pass assumption, defines the step-response error g(t) in Eq. (12), and assumes the exponentially decaying bound |g(t)| <= A e^{-bt} in Eq. (13). Appendix D then derives, from linearity alone, the exact phase difference in Eq. (D6), and bounds it with Eq. (D9); the fidelity inequalities in Eqs. (D11) and (D19) convert this into the exponential correlation bounds of Eqs. (14) and (15). The exponential-in-l form is therefore a consequence of the model, not an input imported from [23]. The experimentally fitted A and b in Table I are obtained from a least-squares fit to one measured V_AWG(t) waveform (Section IV.B), not to the measured correlation strengths epsilon_l of Section III, so the long-range predictions are genuine extrapolations rather than refittings of the target quantity. Although [23] shares several authors and supplies the formula for l_e, the present paper does not cite [23] to justify the exponential decay; it derives that decay independently and uses [23] only to convert the bound into an effective correlation length. The residual concern that a single fitted three-pole filter may not constitute a true conservative upper bound for the real transmitter is an assumption/validation gap, not a circular step.
Assumptions & free parameters
free parameters (2)
- Filter parameters A and b (via G0, nu1, nu2, alpha1) =
A=1.60, b=318.7 MHz (Table I)
- mu0 =
0.3
assumptions (5)
- domain assumption Devices with memory effects can be modeled as an LTI low-pass system; nonlinearities are dominated by the linear response.
- domain assumption The step-response error satisfies |g(t)| ≤ A e^{-bt} for all t ≥ 0.
- domain assumption Laser pulses are narrow enough to be approximated as Dirac deltas for intensity correlations.
- domain assumption Phase-randomized weak coherent pulses remain Poissonian conditioned on the actual intensity, and phase randomization is perfect.
- domain assumption The temporal distribution of phase-encoded states is sufficiently narrow to ignore the time-dependent encoding side-channel.
Cite this review
Pith. "Pith review of Modeling and Characterization of Arbitrary Order Pulse Correlations for Quantum Key Distribution." pith.science (2026). https://pith.science/paper/FXIM6RGZ
@misc{pith2026250618684,
author = {Pith},
title = {Pith review of: Modeling and Characterization of Arbitrary Order Pulse Correlations for Quantum Key Distribution},
year = {2026},
howpublished = {\url{https://pith.science/paper/FXIM6RGZ}},
note = {Machine review of arXiv:2506.18684}
}
read the original abstract
In quantum key distribution (QKD) implementations, memory effects caused by the limited bandwidth of modulators and/or other active devices can leak information about previous setting choices. Security proofs addressing this imperfection require the characterization of pulse correlations, which, in principle, can be of an arbitrary order, even unbounded. Experimentally, this is very hard (if not impossible) to achieve. Here, we solve this pressing problem by introducing a simple linear model to explain pulse correlations. In so doing, we can derive upper bounds on the correlation strength of arbitrary order from the study of the step response of the system. Importantly, this is what is needed to ensure the security of QKD in the presence of pulse correlations of unbounded length. We experimentally characterize short-range correlations and apply the proposed method to account for long-range correlations to an infinite order.
Figures
Figures from the paper (10 more)
Forward citations
Cited by 2 Pith papers
-
Fault-Tolerant Quantum Key Distribution: Enabling Overclocked Modulation
An overclocked QKD protocol that accounts for cross-correlations between intensity and bit/basis encoding, demonstrated at 1 GHz with double the secret key rate of a 250 MHz baseline.
-
Simplified quantum key distribution implementation secure in the presence of state preparation flaws
A three-state BB84 QKD system with time-bin encoding achieves secure key distribution over 151 km by adapting the loss-tolerant method to account for measured state preparation flaws.
Reference graph
Works this paper leans on
-
[23]
Pereira, G
M. Pereira, G. Kato, A. Mizutani, M. Curty, and K. Tamaki, Quantum key distribution with correlated sources, Science Advances 6, eaaz4487 (2020)
2020
-
[1]
Renner, Security of Quantum Key Distribution , Ph.D
R. Renner, Security of Quantum Key Distribution , Ph.D. thesis, ETH Zurich (2005)
work page 2005
-
[2]
For the BB84 protocol (∆max = 3π/2), the results are ϵϕ 1(tb
= 2 .0× 10−4 and ϵϕ 1(tw 0 ) = 7 .2× 10−4 for the three-state protocol (∆ max =π). For the BB84 protocol (∆max = 3π/2), the results are ϵϕ 1(tb
-
[3]
= 4.5× 10−4 and ϵϕ 1(tw 0 ) = 1.6× 10−3. Estimated upper bound for intensity correlations For intensity correlations, using Eq. (17a) and the found parameters for the filter displayed in Table I in Appendix E, we find that Cµ≈ 6.4. The predicted effec- tive first order correlation strength, however, depends on both the simulated mean photon number of a si...
-
[4]
= 3.8× 10−3 andϵµ 1(tw 0 ) = 5.3× 10−3. If we consider N = 10 12 emitted signals and a failure probability of d = 10−10, this yields an effective maxi- mum correlation length of lµ e = 11 for both values of t0 considered. 11 0 5 10 15 20 t0 (ns) 0.0 0.5 1.0 1.5 2.0 ϵφ total(t0) 12 14 16 180.0000 0.0002 0.0004 three-state BB84 FIG. 8: Plot of ϵϕ total(t0) ...
-
[5]
Planes Complementarios de I+D+I con las Co- munidades Autonomas
= 1 .94× 10−3. Lastly, in yellow we plot the results obtained when using a hybrid method in which the exponential bounds are assumed for long-range cor- relations, while for short-range we use the correlation strengths that are estimated from analytical results given by the LTI model. More concretely, we directly calculate φjN|˜jN−1 (t0)−φjN|jN−1(t0) with...
-
[6]
X.-B. Wang, Beating the Photon-Number-Splitting Attack in Practical Quantum Cryptography, Physical Review Letters 94, 230503 (2005)
work page 2005
-
[7]
P. W. Shor and J. Preskill, Simple Proof of Security of the BB84 Quantum Key Distribution Protocol, Physical Review Letters 85, 441 (2000)
2000
Show all 32 references
-
[8]
Gottesman and H.-K
D. Gottesman and H.-K. Lo, Proof of security of quantum key distribution with two-way classical communications, IEEE Transactions on Information Theory 49, 457 (2003)
2003
-
[9]
Trefilov et al
by directly observing the polarization and intensity of the states conditioned on the previous setting choice with a polarimeter and an optical oscilloscope, respec- tively. Trefilov et al. characterized intensity correlations up to the sixth order and showed that higher-order...
2025 arXiv
-
[10]
Hwang, Quantum Key Distribution with High Loss: Toward Global Secure Communication, Physical Review Letters 91, 057901 (2003)
W.-Y. Hwang, Quantum Key Distribution with High Loss: Toward Global Secure Communication, Physical Review Letters 91, 057901 (2003)
2003
-
[11]
H.-K. Lo, X. Ma, and K. Chen, Decoy state quantum key distribution, Physical Review Letters 94, 230504 (2005)
2005
-
[12]
Gottesman, H.-K
D. Gottesman, H.-K. Lo, N. L¨ utkenhaus, and J. Preskill, Security of quantum key distribution with imperfect devices, Quantum Information and Computation 4, 325 (2004)
2004
-
[13]
Tamaki, M
K. Tamaki, M. Curty, G. Kato, H.-K. Lo, and K. Azuma, Loss-tolerant quantum cryptography with imperfect sources, Physical Review A 90, 052314 (2014)
2014
-
[14]
Gr¨ unenfelder, A
F. Gr¨ unenfelder, A. Boaron, D. Rusca, A. Martin, and H. Zbinden, Performance and security of 5 GHz repetition rate polarization-based Quantum Key Distribution, Applied Physics Letters 117, 144003 (2020)
2020
-
[15]
W. Li, L. Zhang, H. Tan, Y. Lu, S.-K. Liao, J. Huang, H. Li, Z. Wang, H.-K. Mao, B. Yan, Q. Li, Y. Liu, Q. Zhang, C.-Z. Peng, L. You, F. Xu, and J.-W. Pan, High-rate quantum key distribution exceeding 110 Mb s –1, Nature Photonics 17, 416 (2023)
2023
-
[16]
Gr¨ unenfelder, A
F. Gr¨ unenfelder, A. Boaron, G. V. Resta, M. Perrenoud, D. Rusca, C. Barreiro, R. Houlmann, R. Sax, L. Stasi, S. El- Khoury, E. H¨ anggi, N. Bosshard, F. Bussi` eres, and H. Zbinden, Fast single-photon detectors and real-time key distillation enable high secret-key-rate quant...
2023
-
[17]
Yoshino, M
K.-I. Yoshino, M. Fujiwara, K. Nakata, T. Sumiya, T. Sasaki, M. Takeoka, M. Sasaki, A. Tajima, M. Koashi, and A. Tomita, Quantum key distribution with an efficient countermeasure against correlated intensity fluctuations in optical pulses, npj Quantum Information 4, 8 (2018)
2018
-
[18]
F.-Y. Lu, X. Lin, S. Wang, G.-J. Fan-Yuan, P. Ye, R. Wang, Z.-Q. Yin, D.-Y. He, W. Chen, G.-C. Guo, and Z.-F. Han, Intensity modulator for secure, stable, and high-performance decoy-state quantum key distribution, npj Quantum Information 7, 75 (2021)
2021
-
[19]
Kang, F.-Y
X. Kang, F.-Y. Lu, S. Wang, J.-L. Chen, Z.-H. Wang, Z.-Q. Yin, D.-Y. He, W. Chen, G.-J. Fan-Yuan, G.-C. Guo, and Z.-F. Han, Patterning-Effect Calibration Algorithm for Secure Decoy-State Quantum Key Distribution, Journal of Lightwave Technology 41, 75 (2023)
2023
-
[20]
Lu, Z.-H
F.-Y. Lu, Z.-H. Wang, S. Wang, Z.-Q. Yin, J.-L. Chen, X. Kang, D.-Y. He, W. Chen, G.-J. Fan-Yuan, G.-C. Guo, and Z.-F. Han, Intensity Tomography Method for Secure and High-Performance Quantum Key Distribution, Journal of Lightwave Technology 41, 4895 (2023)
2023
-
[21]
Zapatero, A
V. Zapatero, A. Navarrete, K. Tamaki, and M. Curty, Security of quantum key distribution with intensity correlations, Quantum 5, 602 (2021)
2021
-
[22]
Sixto, V
X. Sixto, V. Zapatero, and M. Curty, Security of decoy-state quantum key distribution with correlated intensity fluctuations, Physical Review Applied 18, 044069 (2022). 25
2022
-
[24]
Curr´ as-Lorenzo, M
G. Curr´ as-Lorenzo, M. Pereira, G. Kato, M. Curty, and K. Tamaki, Security of high-speed quantum key distribution with imperfect sources (2025), preprint arXiv:2305.05930
2025
-
[25]
Curr´ as-Lorenzo, S
G. Curr´ as-Lorenzo, S. Nahar, N. L¨ utkenhaus, K. Tamaki, and M. Curty, Security of quantum key distribution with imperfect phase randomisation, Quantum Science and Technology 9, 015025 (2023)
2023
-
[26]
Pereira, G
M. Pereira, G. Curr´ as-Lorenzo, A. Navarrete, A. Mizutani, G. Kato, M. Curty, and K. Tamaki, Modified BB84 quantum key distribution protocol robust to source imperfections, Physical Review Research 5, 023065 (2023)
2023
-
[27]
Li, F.-Y
J.-X. Li, F.-Y. Lu, Z.-H. Wang, V. Zapatero, M. Curty, S. Wang, Z.-Q. Yin, W. Chen, D.-Y. He, G.-C. Guo, and Z.-F. Han, Quantum key distribution overcoming practical correlated intensity fluctuations (2025), preprint arXiv:2501.13482
2025 arXiv
-
[28]
Pereira, G
M. Pereira, G. Curr´ as-Lorenzo, A. Mizutani, D. Rusca, M. Curty, and K. Tamaki, Quantum key distribution with un- bounded pulse correlations, Quantum Science and Technology 10, 015001 (2025)
2025
-
[29]
Trefilov, X
D. Trefilov, X. Sixto, V. Zapatero, A. Huang, M. Curty, and V. Makarov, Intensity correlations in decoy-state BB84 quantum key distribution systems (2024), preprint arXiv:2411.00709
2024 arXiv
-
[30]
T. Xing, J. Liu, L. Zhang, M.-Y. Wang, Y.-H. Li, R. Liu, Q. Peng, D. Wang, Y. Wang, H. Liu, W. Li, Y. Cao, and A. Huang, Characterization of intensity correlation via single-photon detection in quantum key distribution, Optics Express32, 31767 (2024)
2024
-
[31]
Gnanapandithan, L
A. Gnanapandithan, L. Qian, and H.-K. Lo, Hidden multidimensional modulation side channels in quantum protocols, Physical Review Letters 134, 130802 (2025)
2025
-
[32]
Mizutani, Y
A. Mizutani, Y. Takeuchi, and K. Tamaki, Finite-key security analysis of differential-phase-shift quantum key distribution, Physical Review Research 5, 023132 (2023)
2023
Reviewed August 15, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.