REVIEW 3 major objections 5 minor 3 cited by
Improved finite-size effects in QKD protocols with applications to decoy-state QKD
T0 review · 3 major / 5 minor · reviewed 2026-08-08 · deepseek-v4-flash
Pith's one-line read Finite-size key rates for generic prepare-and-measure QKD can be pushed close to asymptotic by entry-wise acceptance constraints and by corrections that scale with sifted rounds rather than total signals.
desk verdict The main fixed-length theorem is unproven as written because Corollary 17 drops a normalization factor, but the paper's new techniques are worth a serious look. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
Three objects carry the argument. The feasible set $S_\nu$ with its entry-wise acceptance test (Theorem 2): observed frequencies must each lie within a tolerated fluctuation of the expected values, and the variational bounds $\nu_k^{U/L}$ are fixed as the smallest $\nu$ for which the binomial cumulative probability (incomplete $\beta$ function) equals $\epsilon_{AT}$, bounding the accept probability of every state outside $S_\nu$ by $\epsilon_{AT}$. The sift-conditioning lemma (Lemma 3): conditioning the raw key on the detector labels $D_i$ that mark sifted rounds leaves a tensor-product state on the sifted subsystem, so the smooth min-entropy is bounded below by the min-entropy of the sifted rounds alone and the second-order AEP correction scales with $\lfloor n_{\mathrm{sift}} - N t_{\mathrm{sift}}\rfloor$. The leftover-hash lemma with partial conditioning (Corollary 17): this converts the min-entropy bound into the trace-distance secrecy statement of Theorem 4 while, as the paper claims, avoiding the full $1/\Pr[\Omega]$ normalization penalty for the composite event $\Omega = \Omega_1 \wedge \Omega_2$. For decoy-state and coherent-attack extensions, the same skeleton is reused with yield bounds from a linear program over photon-number subspaces and with the postselection dimension cost $g_{n,x}$.
What would settle it
Take a small classical-quantum example, say two rounds of qubit BB84 with a composite event $\Omega_1$ selecting sifted outcomes and $\Omega_2$ selecting acceptance with $\Pr[\Omega_2|\Omega_1] \approx 10^{-2}$, and compute both sides of inequality (A9) directly: the left side by explicit state construction and trace-norm evaluation, the right side by computing $H^{\epsilon}_{\min}(X|YD)_{\sigma|\Omega_1}$ with a semidefinite program over the smoothing ball. If the left side exceeds the right, Corollary 17 is false as stated and Theorem 4's formula would need an extra normalization penalty. A less explicit but decisive check is to re-derive the proof of Corollary 17 while keeping the factor $1/\Pr[\Omega_2|\Omega_1]$ and see whether the final key length picks up an additional $\log(1/\Pr[\Omega_2|\Omega_1])$ term.
Extended reading notes
Core claim
The paper's central claim is a finite-size security statement for generic prepare-and-measure QKD: under an IID collective attack the protocol is $\epsilon_{\mathrm{sec}} = \epsilon_{EV} + \max\{\epsilon_{AT}, \epsilon_{PA} + 2\bar{\epsilon}\}$-secure if the final key length $l$ obeys $$l \leq \lfloor n_{\mathrm{sift}} - N t_{\mathrm{sift}}\rfloor \min_{\rho \in S_\nu} \frac{H(Z|EC)_\rho}{\Pr(\mathrm{sift})} - \lambda_{EC} - \log(2/\epsilon_{EV}) - \sqrt{\lfloor n_{\mathrm{sift}} - N t_{\mathrm{sift}}\rfloor\,\$\Delta$(\bar{\epsilon})} - 2\log(1/(2\epsilon_{PA})).$$ Two parts of the construction deliver the improvement. Theorem 2 defines the acceptance set $Q = Q_1 \cap Q_2$ by entry-wise tolerances on the test-round frequencies together with a tolerance on the number of sifted rounds, and sets the variational bounds $\nu_k^{U/L}$ through binomial tail probabilities (the incomplete $\beta$ function), so any state outside the feasible set $S_\nu$ is accepted with probability at most $\epsilon_{AT}$. Lemma 3 then shows the smooth min-entropy of the raw key can be evaluated on the sifted subsystem alone, so the asymptotic equipartition property contributes a correction proportional to $\sqrt{\lfloor n_{\mathrm{sift}} - N t_{\mathrm{sift}}\rfloor}$ rather than $\sqrt{N}$. The same skeleton is reused for decoy-state protocols, where the feasible set is expressed through photon-number yields bounded by a linear program, and for variable-length protocols, where the correction terms depend on the observed number of sifted rounds $N^{\mathrm{obs}}_{\mathrm{sift}}$; coherent attacks are handled by applying the postselection technique with the dimension cost $g_{n,x}$.
Load-bearing premise
The key-length formula of Theorem 4 stands on Corollary 17 in Appendix A, a leftover-hash inequality for composite events $\Omega = \Omega_1 \wedge \Omega_2$ that claims the normalization by $\Pr[\Omega]$ costs nothing beyond the conditioning on $\Omega_1$, although the proof appears to drop a factor of $1/\Pr[\Omega_2|\Omega_1]$ when comparing normalized and subnormalized trace norms.
Editorial extensions
If this is right
- Qubit BB84 with a perfect source essentially reaches its asymptotic key rate already at $N = 10^{10}$ signals, while the 1-norm method of Ref. [14] keeps positive rates only up to roughly 25 dB of loss (Figs. 3-4).
- Decoy-state BB84 with two decoy intensities recovers the asymptotic limit up to about 40 dB loss with $N = 10^{11}$ signals, optimizing both the testing probability and the signal intensity per data point (Fig. 5).
- Because the security proof starts from a generic prepare-and-measure statement, it covers protocols that the entropic-uncertainty-relation route handles poorly, including active-basis protocols with passive detection setups and different intensities per signal state.
- Variable-length protocols inherit the same gain: in Theorem 8 and Corollary 9 the correction terms depend on the observed number of sifted rounds $N^{\mathrm{obs}}_{\mathrm{sift}}$ instead of $N$, so high-loss key rates degrade much more slowly as the block length shrinks.
- Against coherent attacks, the decoy-state 4-6 protocol with one decoy intensity and unequal per-symbol intensities yields non-zero key rates from $N = 10^9$ signals and reaches 25 dB at $N = 10^{12}$ (Fig. 6).
Reading between the lines
- A consequence the paper leaves implicit: if the sifted-round scaling holds, the fair resource for comparing QKD implementations at high loss shifts from total pulses sent to sifted detections, since protocols with better detection or sifting efficiency gain twice - once in the entropy prefactor and once in the correction terms - and plots like Fig. 3 should nearly collapse when re-drawn against th
- The entry-wise-versus-aggregate distinction is transferable: other QKD settings whose feasible sets are already defined by individual observation bounds, such as measurement-device-independent and discrete-modulated continuous-variable protocols, could adopt the same binomial-tail acceptance tests and inherit a comparable reduction of statistical slack.
- The expected-key-rate analysis using Fr\'echet inequalities offers a template for deployments where the honest channel is known only coarsely: rather than assuming a point model for the accepted frequencies, one can bracket the worst-case key rate between the upper and lower Fr\'echet bounds and choose the acceptance tolerances accordingly.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper develops a finite-size security proof for generic prepare-and-measure QKD protocols against IID collective attacks, with extensions to coherent attacks via the postselection technique and to variable-length protocols. The two claimed improvements are (i) entry-wise acceptance constraints based on binomial tail bounds, and (ii) second-order correction terms that scale with the number of sifted rounds rather than the total number of protocol rounds. The framework is applied to qubit BB84, decoy-state BB84, and a decoy-state 4-6 protocol with unequal intensities, and numerical key rates are compared with the 1-norm approach of Ref. [14].
Significance. If the central theorem were valid, the framework would be a valuable contribution: it avoids the basis-independence assumptions of EUR-based proofs, handles active basis choices and passive detection setups, and the numerical examples suggest substantially improved finite-size rates over the 1-norm approach of Ref. [14]. The paper is detailed and self-contained in many respects, with appendices covering technical tools such as binomial confidence bounds for very small security parameters, and the authors commit to releasing code. However, the central fixed-length theorem depends on a flawed normalization step in Corollary 17, so the quantitative claims are currently not supported.
major comments (3)
- [Appendix A, Corollary 17, Eqs. (A9)–(A11)] The proof of Corollary 17 drops a normalization factor. From Eq. (A11) and Pr[Ω] = Pr[Ω1]Pr[Ω2|Ω1], the left-hand side of Eq. (A9) equals ‖N‖_1 / (2 Pr[Ω1] Pr[Ω2|Ω1]^2), where N = (ω_{KSHYD|Ω1})_{∧Ω2} − χ_K ⊗ (ω_{SHYD|Ω1})_{∧Ω2}. The proof's first inequality instead claims this is ≤ (1/2)‖N‖_1, which would require Pr[Ω1]Pr[Ω2|Ω1]^2 ≥ 1. For any non-trivial events this product is strictly less than 1, so the inequality has the wrong direction. Consequently the advertised bound (A9) is not established; the correct bound would contain an extra factor 1/(Pr[Ω1]Pr[Ω2|Ω1]^2) multiplying the right-hand side, i.e., an additional key-length penalty of at least 2 log(1/Pr[Ω1]) + 4 log(1/Pr[Ω2|Ω1]) or an equivalent inflation of the security parameter.
- [Theorem 4, Eq. (49) and proof around Eq. (57)] The key-length formula in Theorem 4 relies directly on Corollary 17 to pass from the security distance conditioned on Ω_acc to the smooth min-entropy conditioned only on Ω_sift. Since Corollary 17 is not established, Eq. (57) does not follow, and hence Eq. (49) is not proven as stated. The numerical key-rate curves in Figs. 3–6 and the claimed improvements over Ref. [14] are computed from this formula, so they are unsupported until the normalization issue is repaired and propagated through Theorem 4 and Corollaries 5–6.
- [Theorem 4, Eq. (49); Corollaries 5–6] A corrected version of Corollary 17 will introduce terms depending on Pr[Ω_sift] and Pr[Ω'_AT|Ω_sift]. The paper provides no lower bounds on these probabilities for states in the feasible set S_ν, and these probabilities can be small for adversarial states near the boundary of S_ν. The authors should either bound these event probabilities or restructure the acceptance test so that the resulting penalties are controlled; without this, the claimed reduction of second-order corrections to scale with the number of sifted rounds is not justified.
minor comments (5)
- [Corollary 6, Eq. (94)] The term “− 2 log(1/2ε_PA)” should read “− 2 log(1/(2ε_PA))”; the same typo appears in Corollary 9 and in the text after Eq. (58).
- [Theorem 2 proof, Eq. (18)] The inequality “Pr[F_obs ∈ Q] ≤ Pr[|F_obs^k − Fbar^k| ≤ t_k] ∀k ∈ Σ” should be stated separately for each k before taking the maximum; as written it suggests an invalid simultaneous bound.
- [Notation throughout] The sets S∘ and S• are used somewhat interchangeably; for example, Corollary 17 states σ ∈ S∘(XYD) but then discusses subnormalized states, which should be in S•. Clarifying this would help the reader.
- [Lemma 3, Eq. (34)] The notation τ^sift_{Z_sift Y_sift C_sift E_sift|D=1} is introduced but the conditioning on the register D is not explicitly reflected in the right-hand side of Eq. (34); a short clarification would improve readability.
- [Eq. (83), Corollary 5] The fraction in the first term of the key-rate expression lacks parentheses: it should read (1/(Fbar_sift + t_sift + ν^U_sift)) times the sum over n, rather than the ambiguous inline expression currently printed.
Circularity Check
No significant circularity: the key-rate derivation is self-contained and does not reduce to its inputs.
full rationale
The central security claims (Theorem 4 and its decoy corollaries) are derived from the asymptotic equipartition property, the leftover-hash lemma, concentration inequalities for binomial statistics, and the protocol's acceptance-set construction. The key-rate expression is not fitted to the data it later predicts; parameters such as the testing probability and intensities are optimized under an assumed channel model, and the numerical curves are evaluations of the proven bound, not fits. The many references to prior work from the same group ([12], [14], [16], [27]) are used as published external building blocks: the postselection lift is imported from [12] and the variable-length framework from [16], but these are separate peer-reviewed results with stated assumptions independent of the present paper's claims, so they do not make the argument circular. A potential issue raised by the manuscript's own Appendix A (Corollary 17) concerns a normalization factor in a trace-norm inequality; that is a proof-correctness risk, not a self-referential reduction, and therefore does not affect the circularity score.
Assumptions & free parameters
free parameters (5)
- Testing probability p(test) =
optimized per data point in the numerical examples
- Signal intensity mu_s in decoy examples =
not fixed, optimized per data point in Section VII B
- Tolerances t_k and t_sift =
optimized in Section VI to maximize expected key rate
- Security parameter split epsilon_PA, epsilon_bar, epsilon_AT =
chosen via heuristic derivative Eq. (104), not a closed formula
- Photon number cutoffs Nph and NB =
Nph = 2, NB = 1 in the examples
assumptions (6)
- domain assumption Each round is independent and identically distributed under the collective attack: rho_ABE = sigma_ABE^otimes N
- domain assumption Eve has no access to Alice's lab, so the marginal of the single-round state satisfies rho_A = Tr_A'[|psi><psi|], Eq. (8)
- domain assumption The source is fully phase-randomized WCP, making the state block-diagonal in photon number and the n-photon yields independent of intensity
- domain assumption Valid squashing maps exist for Bob's detectors (passive BB84 squashing and flag-state squasher for 4-6)
- standard math Entropy accumulation theorem / AEP bound [24, Cor. 4.10]
- standard math Postselection technique of Christandl-Koenig-Renner, as improved by [12, Cor. 4.1]
Cite this review
Pith. "Pith review of Improved finite-size effects in QKD protocols with applications to decoy-state QKD." pith.science (2026). https://pith.science/paper/SLJGXIAR
@misc{pith2026250205382,
author = {Pith},
title = {Pith review of: Improved finite-size effects in QKD protocols with applications to decoy-state QKD},
year = {2026},
howpublished = {\url{https://pith.science/paper/SLJGXIAR}},
note = {Machine review of arXiv:2502.05382}
}
read the original abstract
We present a finite-size security proof for generic quantum key distribution protocols against independent and identically distributed collective attacks and extend it to coherent attacks using the postselection technique. This work introduces two significant improvements over previous results. First, we achieve tighter finite-size key rates by employing refined concentration inequalities in the acceptance testing phase. Second, we improve second-order correction terms in the key rate expression, by reducing them to scale with the number of sifted rounds rather than the total number of protocol rounds. We apply these advancements to compute finite-size key rates for a qubit and decoy-state BB84 protocol, accommodating arbitrary protocol parameters. Finally, we extend our finite-size security proof to coherent attacks and variable-length protocols and present our results for the decoy-state 4-6 protocol incorporating imperfections such as unequal intensity settings.
Figures
Forward citations
Cited by 3 Pith papers
-
The finite key effect of side-channel-secure quantum key distribution beyond post-selection technique
A security proof for variable-length side-channel-secure QKD against coherent attacks, bypassing post-selection and allowing the key rate to be computed after error correction from the actual leakage.
-
Security proofs for practical QKD: variations, techniques, gaps, and limitations
A critical review of decoy-state BB84 security proofs identifies common gaps and shows that no current proof meets the full standard of completeness, modularity, and verifiability.
-
Drone- and Vehicle-Based Quantum Key Distribution
First demonstrations of drone-to-drone, drone-to-vehicle, and vehicle-to-vehicle quantum key distribution, with finite-key secure rates of 1.6 to 20 kbps over short free-space links.
Reference graph
Works this paper leans on
- [14]
-
[16]
D. Tupkary, E. Y.-Z. Tan, and N. L¨ utkenhaus, Security proof for variable-length quantum key distribution, Phys. Rev. Res. 6, 023002 (2024)
work page 2024
-
[1]
X. Ma, B. Qi, Y. Zhao, and H.-K. Lo, Practical decoy state for quantum key distribution, Physical Review A 72, 012326 (2005)
work page 2005
-
[2]
H.-K. Lo, X. Ma, and K. Chen, Decoy State Quantum Key Distribution, Physical Review Letters 94, 230504 (2004)
work page 2004
-
[3]
W. Y. Hwang, Quantum Key Distribution with High Loss: Toward Global Secure Communication, Physical Review Letters 91, 057901 (2002)
work page 2002
-
[4]
Wang, Beating the Photon-Number-Splitting At- tack in Practical Quantum Cryptography, Phys
X.-B. Wang, Beating the Photon-Number-Splitting At- tack in Practical Quantum Cryptography, Phys. Rev. Lett. 94, 230503 (2005)
work page 2005
-
[5]
Tomamichel and R
M. Tomamichel and R. Renner, Uncertainty Relation for Smooth Entropies, Phys. Rev. Lett. 106, 110506 (2011)
2011
-
[6]
C. C. W. Lim, M. Curty, N. Walenta, F. Xu, and H. Zbinden, Concise security bounds for practical decoy- 20 state quantum key distribution, Physical Review A 89, 022307 (2014)
work page 2014
Show all 55 references
-
[7]
Rusca, A
D. Rusca, A. Boaron, F. Gr¨ unenfelder, A. Martin, and H. Zbinden, Finite-key analysis for the 1-decoy state QKD protocol, Applied Physics Letters 112, 171104 (2018)
2018
-
[8]
Koashi, Simple security proof of quantum key dis- tribution based on complementarity, New Journal of Physics 11, 045018 (2009)
M. Koashi, Simple security proof of quantum key dis- tribution based on complementarity, New Journal of Physics 11, 045018 (2009)
2009
-
[9]
Hayashi and R
M. Hayashi and R. Nakayama, Security analysis of the decoy method with the bennett–brassard 1984 protocol for finite key lengths, New Journal of Physics 16, 063009 (2014)
2014
-
[10]
Tomamichel and A
M. Tomamichel and A. Leverrier, A largely self-contained and complete security proof for quantum key distribu- tion, Quantum 1, 14 (2017)
2017
-
[11]
Tupkary, S
D. Tupkary, S. Nahar, P. Sinha, and N. L¨ utkenhaus, Phase error rate estimation with basis-efficiency mis- match for decoy-state bb84 (2024), arXiv:2408.17349 [quant-ph]
2024
-
[12]
Nahar, D
S. Nahar, D. Tupkary, Y. Zhao, N. L¨ utkenhaus, and E. Y.-Z. Tan, Postselection technique for optical quan- tum key distribution with improved de finetti reductions, PRX Quantum 5, 040315 (2024)
2024
-
[13]
Christandl, R
M. Christandl, R. K¨ onig, and R. Renner, Postselection Technique for Quantum Channels with Applications to Quantum Cryptography, Phys. Rev. Lett. 102, 020504 (2009)
2009
-
[15]
Kanitschar, I
F. Kanitschar, I. George, J. Lin, T. Upadhyaya, and N. L¨ utkenhaus, Finite-Size Security for Discrete- Modulated Continuous-Variable Quantum Key Distribu- tion Protocols, PRX Quantum 4, 040306 (2023)
2023
-
[17]
Laing, V
A. Laing, V. Scarani, J. G. Rarity, and J. L. O’Brien, Reference-frame-independent quantum key distribution, Phys. Rev. A 82, 012304 (2010)
2010
-
[18]
Portmann and R
C. Portmann and R. Renner, Security in quantum cryp- tography, Rev. Mod. Phys. 94, 025008 (2022)
2022
-
[19]
Renner, Security of Quantum Key Distribution (2006), arxiv:quant-ph/0512258
R. Renner, Security of Quantum Key Distribution (2006), arxiv:quant-ph/0512258
2006 arXiv
-
[20]
In an exper- imental implementation this step is not required if the techniques from [16] are used
This is done to maintain a fixed length string going into privacy amplification for technical reasons. In an exper- imental implementation this step is not required if the techniques from [16] are used. In particular, Alice and Bob may discard rounds as long as the positions o...
-
[21]
C. H. Bennett, G. Brassard, and N. D. Mermin, Quantum cryptography without Bell’s theorem, Phys. Rev. Lett. 68, 557 (1992)
1992
-
[22]
Ferenczi and N
A. Ferenczi and N. L¨ utkenhaus, Symmetries in quan- tum key distribution and the connection between optimal attacks and optimal cloning, Phys. Rev. A 85, 052310 (2012)
2012
-
[23]
Tomamichel, Quantum Information Processing with Finite Resources , SpringerBriefs in Mathemati- cal Physics, Vol
M. Tomamichel, Quantum Information Processing with Finite Resources , SpringerBriefs in Mathemati- cal Physics, Vol. 5 (Springer International Publishing, Cham, 2016)
2016
-
[24]
Dupuis, O
F. Dupuis, O. Fawzi, and R. Renner, Entropy Accumu- lation, Commun. Math. Phys. 379, 867 (2020)
2020
-
[25]
Horodecki, M
K. Horodecki, M. Horodecki, P. Horodecki, and J. Op- penheim, General Paradigm for Distilling Classical Key From Quantum States, IEEE Transactions on Informa- tion Theory 55, 1898 (2009)
2009
-
[26]
N. K. H. Li and N. L¨ utkenhaus, Improving key rates of the unbalanced phase-encoded BB84 protocol using the flag-state squashing model, Phys. Rev. Research 2, 043172 (2020)
2020
-
[27]
Kamin and N
L. Kamin and N. L¨ utkenhaus, Improved decoy-state and flag-state squashing methods, Physical Review Research 6, 043223 (2024)
2024
-
[28]
Wang and N
W. Wang and N. L¨ utkenhaus, Numerical security proof for the decoy-state BB84 protocol and measurement- device-independent quantum key distribution resistant against large basis misalignment, Phys. Rev. Res. 4, 043097 (2022)
2022
-
[29]
Winick, N
A. Winick, N. L¨ utkenhaus, and P. J. Coles, Reliable nu- merical key rates for quantum key distribution, Quantum 2, 77 (2018)
2018
-
[30]
Fr´ echet, G´ en´ eralisation du th´ eor` eme des probabilit´ es totales, Fundamenta Mathematicae 25, 379 (1935)
M. Fr´ echet, G´ en´ eralisation du th´ eor` eme des probabilit´ es totales, Fundamenta Mathematicae 25, 379 (1935)
1935
-
[31]
C. H. Bennett and G. Brassard, Quantum cryptogra- phy: Public key distribution and coin tossing, Theoreti- cal Computer Science 560, 7 (2014)
2014
-
[32]
N. J. Beaudry, T. Moroder, and N. L¨ utkenhaus, Squash- ing Models for Optical Measurements in Quantum Com- munication, Physical Review Letters 101, 093601 (2008)
2008
-
[33]
Gittsovich, N
O. Gittsovich, N. J. Beaudry, V. Narasimhachar, R. R. Alvarez, T. Moroder, and N. L¨ utkenhaus, Squashing model for detectors and applications to quantum-key- distribution protocols, Physical Review A 89, 012325 (2014)
2014
-
[34]
Hayashi and T
M. Hayashi and T. Tsurumaru, Concise and tight secu- rity analysis of the Bennett–Brassard 1984 protocol with finite key lengths, New Journal of Physics 14, 093014 (2012)
2012
-
[35]
Curr´ as-Lorenzo, ´A
G. Curr´ as-Lorenzo, ´A. Navarrete, K. Azuma, G. Kato, M. Curty, and M. Razavi, Tight finite-key security for twin-field quantum key distribution, npj Quantum Infor- mation 7, 1 (2021)
2021
-
[36]
Kawakami, Security of Quantum Key Distribution with Weak Coherent Pulses, Ph.D
S. Kawakami, Security of Quantum Key Distribution with Weak Coherent Pulses, Ph.D. thesis
-
[37]
C. J. Clopper and E. S. Pearson, The Use of Confidence or Fiducial Limits Illustrated in the Case of the Binomial, Biometrika 26, 404 (1934), 2331986
1934
-
[38]
C. R. Rao, G. J. Sz´ ekely, and Alfr´ ed R´ enyi Institute of Mathematics, eds., Statistics for the 21st Century: Methodologies for Applications of the Future, Statistics, Textbooks and Monographs No. v. 161 (Marcel Dekker, New York, 2000)
2000
-
[39]
These intervals can be easily constructed using prein- stalled functions in MATLAB
-
[40]
Kamin and N
L. Kamin and N. L¨ utkenhaus, Improved Decoy-state and Flag-state Squashing Methods, arXiv:2405.05069 [quant- ph] (2024)
2024 arXiv
-
[41]
J. Lin, T. Upadhyaya, and N. L¨ utkenhaus, Asymptotic Security Analysis of Discrete-Modulated Continuous- Variable Quantum Key Distribution, Phys. Rev. X 9, 041064 (2019)
2019
-
[42]
Zhang, P
Y. Zhang, P. J. Coles, A. Winick, J. Lin, and N. L¨ utkenhaus, Security proof of practical quantum key 21 distribution with detection-efficiency mismatch, Physical Review Research 3, 013076 (2021)
2021
-
[43]
Dupuis, Privacy Amplification and Decoupling With- out Smoothing, IEEE Transactions on Information The- ory 69, 7784 (2023)
F. Dupuis, Privacy Amplification and Decoupling With- out Smoothing, IEEE Transactions on Information The- ory 69, 7784 (2023)
2023
-
[44]
Instead of considering a sum over events that only cor- respond to different output key lengths, we are allowed to sum over events with different output key lengths or error-correction lengths or number of sifted signals. This can be shown using basic properties of the trace n...
-
[45]
A. M. Zubkov and A. A. Serov, A Complete Proof of Universal Inequalities for the Distribution Function of the Binomial Law, Theory Probab. Appl. 57, 539 (2013)
2013
-
[46]
Thulin, The cost of using exact confidence intervals for a binomial proportion, Electronic Journal of Statistics 8, 10.1214/14-ejs909 (2014)
M. Thulin, The cost of using exact confidence intervals for a binomial proportion, Electronic Journal of Statistics 8, 10.1214/14-ejs909 (2014). Appendix A: T echnical Definitions and Lemmas Definition 11 (Normalised and sub-normalised condi- tional states) . Let ρ ∈ S•(DX ) b...
2014 doi
-
[47]
Qubit BB84 In the main text, we set pB z = pB x = 1/2, but for gen- erality, we provide the Kraus operators for arbitrary ba- sis choices. Given a perfect qubit protocol, Bob’s qubit 23 POVM elements are M B (Z,0) = pB z 0 0 0 0 1 0 0 0 0 , MB (Z,1) = pB z 0 0 0 0 ...
-
[48]
In the main text, we set pB z = pB x = 1/2, but for generality, we provide the Kraus operators for arbitrary basis choices
Decoy BB84 After applying the squashing map from [32, 33], Bob’s measurements act on a qubit again. In the main text, we set pB z = pB x = 1/2, but for generality, we provide the Kraus operators for arbitrary basis choices. The resulting POVM elements coincide with the ones fo...
-
[49]
variable-length decision
4-6 Protocol As described in the main text, see Section IX A, we chose a photon number cut-off for Bob as NB = 1. After 24 applying the flag-state squasher of [42] with this choice, the POVM elements on Bob’s ≤ 1-photon subspace are ˜M B (Z,0) = pB z 0 0 0 0 1 0 0 0 0 ...
-
[50]
From public announcements ⃗C, Alice and Bob com- pute F obs and bstat(F obs)
-
[51]
, λmax} is some predeter- mined function
They compute λEC(F obs), the number of bits to be used for error-correction information, where λEC(·) : F → {0, 1, . . . , λmax} is some predeter- mined function
-
[52]
, lmax} is a function defined as l(F obs) := max 0, bstat(F obs) − λEC(F obs) − θ(εPA, εEV) , θ(εPA, εEV) := α α − 1 log 1 4εPA + 2 α + log 2 εEV
They compute l(F obs), the length of the final key to be produced, where l(·) : F → {0, 1, . . . , lmax} is a function defined as l(F obs) := max 0, bstat(F obs) − λEC(F obs) − θ(εPA, εEV) , θ(εPA, εEV) := α α − 1 log 1 4εPA + 2 α + log 2 εEV . (E6) We setup a partition of F b...
-
[53]
Hα( ⃗Z| ⃗C ⃗E)ρ|Ωm ≥ l1 + λ1 + θ(εPA, εEV)
-
[54]
lj + λj + θ(εPA, εEV) ≥ Hα( ⃗Z| ⃗C ⃗E)ρ|Ωm ≥ lj+1 + λj+1 + θ(εPA, εEV) for some j ∈ {1, ..., M− 1}
-
[55]
We will prove the secrecy claim separately for each case
lM + λM + θ(εPA, εEV) ≥ Hα( ⃗Z| ⃗C ⃗E)ρ|Ωm . We will prove the secrecy claim separately for each case. Suppose that for every value of m, ρ is such that it sat- isfies case 2, for some value j∗ m. In this case, the secrecy bound can be obtained by splitting up the sum into two...
Reviewed August 8, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.