[Paper Review] Misconception in Theory of Quantum Key Distribution -Reply to Renner-
This paper challenges the foundational security interpretation in quantum key distribution (QKD) theory, arguing that the use of trace distance as a security criterion—particularly its misinterpretation as a failure probability—lacks operational meaning in cryptology. It contends that the current theory, rooted in Shor-Preskill and Renner’s frameworks, fails to properly evaluate security using Shannon’s operational criteria, such as success probability of key estimation by an eavesdropper, and thus may not guarantee actual security, even at extremely low trace distance levels like 10⁻²⁰.
It has been pointed out by Yuen that the security theory of quantum key distribution(QKD) guided by Shor-Preskill theory has serious defects, in particular their key rate theory is not correct. Theory groups of QKD tried to improve several defects. Especially, Renner employed trace distance and quantum leftover Hash Lemma. However, the present theory encountered a problem of a quantitative evaluation of security. To cope with it, he uses a wrong interpretation on the trace distance and its level epsilon_{sec}, and justifies the unconditional security of own system when epsilon_{sec} is 10^{-6 } ~ 10^{-20}. In this paper, we discuss the following problems. What is the origin of the misconception of the present theory? How does the present theory lead to the misconception?. To show their process toward the misconception, Koashi-Preskill's theory which has a typical misconception is examined. A main point of our comment is that QKD theory ignores the security requirement against attacker which is necessary to compare whole encryption schemes from classical to quantum. To clarify it, we emphasize that the trace distance itself cannot have any operational meaning such as failure probability, and it is only mathematical tool as a measure of closeness. As a result, it is given that the security with above values derived from their formulation means nothing in the general cryptological sense. In addition, I point out that a comment by Bennett and Riedel on unconditional security of QKD is not correct. Also, I point out that the experimental systems of groups of Los Alamos, Toshiba-UK, NICT, and others cannot have security guarantee even in future.
Motivation & Objective
- To identify the core misconception in current QKD security theory, particularly the misinterpretation of trace distance as failure probability.
- To challenge the validity of Renner’s security framework, which justifies unconditional security at trace distance levels like 10⁻²⁰ by treating it as a physical probability.
- To argue that current QKD theory ignores Shannon’s operational security criteria—specifically, the success probability of Eve’s key estimation—leading to potentially insecure systems.
- To demonstrate that the iid assumption and active attacks invalidate the security claims of current QKD protocols, even with privacy amplification.
- To call for a return to Shannon’s original information-theoretic security framework, grounded in operational definitions of security.
Proposed method
- Analyzes Koashi-Preskill’s QKD theory as a canonical example of the misconception, focusing on its reliance on trace distance without operational grounding.
- Re-expresses the relationship between trace distance and Shannon’s success probability of key estimation using Eq. (5), showing that trace distance alone cannot quantify security.
- Critically evaluates Renner’s use of trace distance as a failure probability, demonstrating that this interpretation is mathematically invalid under probability theory.
- Highlights that privacy amplification reduces mutual information but does not eliminate Eve’s knowledge or improve her estimation success probability.
- Argues that experimental QKD systems (e.g., Los Alamos, Toshiba-UK, NICT) lack quantitative security evaluation and are independent of theoretical advances.
- Reassesses Bennett and Riedel’s claim of unconditional security in QKD, showing it is unjustified due to flawed theoretical foundations.
Experimental results
Research questions
- RQ1Why is the trace distance in QKD theory incorrectly interpreted as a failure probability, and what are the consequences of this misinterpretation?
- RQ2How does the current QKD security framework fail to meet Shannon’s operational definition of information-theoretic security?
- RQ3What is the true relationship between trace distance and the success probability of an eavesdropper’s key estimation?
- RQ4Why is the iid assumption invalid in realistic QKD scenarios involving active attacks, and how does this undermine current security proofs?
- RQ5Can experimental QKD systems be considered secure if they lack quantitative security evaluation and are disconnected from theoretical advances?
Key findings
- The trace distance used in QKD security proofs is a mathematical measure of closeness between quantum states and cannot be interpreted as a failure probability, contradicting Renner’s justification of security at levels like 10⁻²⁰.
- The current theory ignores Shannon’s operational criterion of security—success probability of key estimation by Eve—rendering its security claims meaningless in a practical cryptological context.
- Even with trace distances as low as 10⁻²⁰, the security of QKD systems is not operationally meaningful because trace distance does not correspond to any measurable failure rate.
- The protocol based on post-processing and privacy amplification cannot ensure uniformity of the key sequence against an active attacker, especially when the iid assumption fails.
- Experimental QKD systems from Los Alamos, Toshiba-UK, and NICT do not provide quantitative security guarantees and are not evaluated against theoretical security standards.
- Bennett and Riedel’s claim of unconditional security for QKD is unjustified, as no proof exists under the current theoretical framework, which lacks operational grounding.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.