A D V E R T |
I S E M E N T |
| Math Sites: lean ages 13-∞ readme referees parents | >>> MAITH GAMES <<< | all 372 compute stand |
|
Entanglement with zero distillable secret key in local dimension ten
expertly designed by an internal OpenAI model · released 2026-09-27
· original PDF
IntroductionSecret-key distillation asks whether two distant laboratories can turn a shared noisy resource into identical random bits that an eavesdropper cannot predict. For a bipartite quantum state \(\rho_{AB}\), Alice and Bob act locally and exchange authenticated public classical messages. Eve holds a purification of the input and receives the complete public transcript. An ideal key of length \(\ell\) is uniform, agrees at the two laboratories, and is independent of Eve: its joint state has the form \[2^{-\ell}\sum_{z\in\{0,1\}^{\ell}} |z,z\rangle\langle z,z|\otimes\sigma_{E'}.\] We use the usual ideal-key security criterion [31, 53]. The input is the only shared private resource. Alice and Bob may process all copies jointly in their respective laboratories and use local auxiliaries and private randomness. They may also begin with a public random variable, independent of the input and its reference and recorded for Eve. Conditional on that public variable, the input-reference state and the two private auxiliary resources form a product, with fixed preparation kernels for every input. An admitted protocol has a finite or \(\mathbb N\)-indexed sequence of measurable local-instrument steps, after any supplied local aggregation. Its histories and terminal readouts must satisfy the reference-compatibility conditions of Definition 12. These include ordinary finite protocols with finite classical records obeying the preceding resource rules, as well as the specified countable processes. Eve retains the initial purification and the full public record, including speaker choices and stopping information. A protocol is completed on the actual input when both laboratories produce their prescribed outputs almost surely and the joint output is normalized. The distillable secret key \(K_D(\rho)\) is the supremum of \(\liminf_n\ell_n/n\) over admitted completed key-output sequences on \(\rho^{\otimes n}\) whose error from an ideal key tends to zero (Definition 15). All errors use the unhalved trace norm \(\left\lVert X\right\rVert_1=\operatorname{tr}\sqrt{X^*X}\). We construct an entangled state for which even one approximately secret bit is uniformly out of reach. A density operator is a positive matrix of trace one. It is separable if it is a finite sum of positive product matrices, and entangled otherwise. Theorem 1. There is an explicitly specified entangled density operator \(\rho\) on \(\mathbb C^{10}\otimes\mathbb C^{10}\) whose range contains no nonzero product vector and for which \(K_D(\rho)=0\). More precisely, let \(n\geq1\) and let \(\tau_{K_AK_BE'}\) be the normalized output of any admitted completed bit-output protocol of Definition 12 on \(\rho^{\otimes n}\), where \(E'\) retains an initial purification and the complete public transcript. For every state \(\sigma_{E'}\), \[ \left\lVert \tau_{K_AK_BE'}- \frac12\sum_{i=0}^1|i,i\rangle\langle i,i|\otimes\sigma_{E'} \right\rVert_1\geq\frac15. \tag{1}\] Thus the corresponding trace distance, with its conventional factor \(1/2\), is at least \(1/10\). There is no uniform bound on the amount of communication or the number of steps within the admitted model. Proposition 18 also gives separate consequences for public conditioning on an event of positive probability, vanishing abort probability, and trace-norm limits of completed outputs whose Eve registers retain or allow recovery of the purification and complete public record. The state comes from a construction for completely positive maps. A complex-linear map \(F:M_{a}(\mathbb C)\to M_{b}(\mathbb C)\) is completely positive (CP) when \(\mathrm{id}_k\otimes F\) preserves positive matrices for every \(k\geq1\). We call it PPT when both \(F\) and \(T_b\circ F\) are CP, where \(T_b\) is coordinate transposition. Write \(J(F)\) for the unnormalized input-first Choi matrix, defined in (3). A CP map is entanglement breaking when applying it to one subsystem of any positive bipartite input always gives a separable output. Equivalently, its Choi matrix is separable [33]; this cone formulation does not require trace preservation. Theorem 2. There are explicitly specified PPT maps \(\Phi_1,\Phi_2:M_{10}(\mathbb C)\to M_{10}(\mathbb C)\) for which \[Z=J(\Phi_2\circ\Phi_1)\] is nonzero and its range contains no nonzero product vector in \(\mathbb C^{10}\otimes\mathbb C^{10}\). In particular, the composition \(\Phi_2\circ\Phi_1\) is not entanglement breaking. The maps are given by (30), starting from the integer matrices in (36). They may differ, and the construction does not impose trace preservation or unitality. The state in Theorem 1 is \[ \rho=\frac{Z}{\operatorname{tr}Z}. \tag{2}\] The denominator is positive because \(Z\) is a nonzero positive Choi matrix. A separate construction supplies a trace-preserving example. Theorem 3. There is an explicitly specified trace-preserving PPT channel \(\Theta:M_{21}(\mathbb C)\to M_{21}(\mathbb C)\) whose square \(\Theta\circ\Theta\) is not entanglement breaking. The pair in Theorem 2 gives a negative answer to the unrestricted two-map PPT-composition conjecture of Christandl, Müller-Hermes, and Wolf [16]. The channel in Theorem 3 answers the channel question recorded in the 2012 BIRS workshop report [54], already with the same channel in both positions. We do not claim that either dimension is minimal. Entanglement and secrecy.Public discussion and privacy amplification are central to the classical theory of key agreement [9, 41, 7]. Entanglement purification provides a quantum route to secrecy: nearly pure shared entangled pairs decouple from a purifying adversary [8, 11, 19]. Bound entanglement showed that entanglement need not be distillable into singlets. In particular, PPT entangled states have zero distillable entanglement [32]. Some PPT entangled states nevertheless have positive distillable secret key [30]. Their private-state description explains how secrecy can persist in a quantum shield even when singlet distillation is impossible [31]. Separable states have zero key against a purifying Eve [17, 30]. The converse was posed explicitly as Problem 24, “Secret key from all entangled states,” in Krüger and Werner’s open-problem collection: the entry is dated 15 March 2005 and lists P. Horodecki as contact [40]. The question is also discussed in the private-state literature [31, 29]. One-way coding theorems give useful positive-key criteria [20], while Theorem 1 in particular rules out a positive key rate for a specific entangled state under ordinary finite two-way protocols, whose round count may grow with the input length. The distinction between secrecy needed to prepare correlations and key recoverable from them also matters: measurements of an entangled state can yield correlations with a positive secrecy formation cost without proving a positive distillation rate [26, 25, 1]. There are earlier quantitative obstructions near private bits. Kim and Sanders obtained a distance bound for PPT states under a Hermitian-block hypothesis [38], and Badziąg and coauthors removed that hypothesis [5]. Those bounds depend on the shield dimension, which may grow with a protocol. Our bound applies to the final classical bit registers and Eve’s complete public side information, with a constant independent of the input length and the local memories. Pauwels, Gisin, and Renner recently constructed a finite classical bipartite source with positive secrecy formation cost and zero asymptotic secret-key rate under finite-round authenticated public discussion, with the round count allowed to grow with block length [46]. Their revised paper also proves positive two-way distillable quantum key for the Horodecki two-qutrit states \(\sigma_\alpha\) with \(3<\alpha\leq5\), including the bound-entangled range \(3<\alpha\leq4\), against a purifying quantum Eve [46]. The state in Theorem 1 gives the quantum zero-key conclusion under the local quantum protocol model above. The operational obstruction.The first part of the proof concerns a class \(\mathscr C\) of states \(\omega\) on \(\mathbb C^a\otimes\mathbb C^b\) with a local representation \[\omega=(\mathcal L\otimes\mathcal M)(\chi\chi^*), \quad \chi\in\mathbb C^r\otimes\mathbb C^s,\quad \mathcal L:M_{r}(\mathbb C)\to M_{a}(\mathbb C),\quad \mathcal M:M_{s}(\mathbb C)\to M_{b}(\mathbb C),\] where \(\mathcal L,\mathcal L\circ T_r,\mathcal M,\mathcal M\circ T_s\) are CP. These input-transpose conditions are equivalent to the output-transpose PPT convention above, as Lemma 4 shows. The maps may be rectangular and need not preserve trace; only the output \(\omega\) has trace one. This condition persists under tensor powers. Relative to one common transcript measure, the four final bit branches have positive local effect densities \(X_i(t)\otimes Y_j(t)\) on the two local input spaces of the protocol for almost every complete transcript \(t\), with the same two local pairs for all \(i,j\in\{0,1\}\). To prove this, we run the protocol on auxiliary product probes. Their two local sampling tapes are conditionally independent given the complete public record. Informationally complete tests on untouched references turn that independence into common product factors, and a filter on the references transfers the factors to the actual input. For a state in \(\mathscr C\), a coherence inequality bounds the overlap between the \(00\) and \(11\) branches by the probabilities of disagreement. After integration over transcripts, let \(e\) be the total probability of different bits and let \(\mathfrak f\) be the root fidelity between Eve’s unnormalized \(00\) and \(11\) conditional states, summed over the public record. We prove \[\mathfrak f\leq\sqrt{e(1-e)}+e.\] If the output is at trace-norm distance \(\eta\) from an ideal bit, correctness and secrecy give, respectively, \[e\leq\frac\eta2, \qquad \mathfrak f\geq\frac{1-\eta}{2}.\] For \(\eta<1/5\), the right side of the first display is less than \(2/5\), whereas the second display requires more than \(2/5\). This proves the uniform gap. Taking the first bit of a longer ideal key is a trace-norm contraction, so no positive asymptotic key rate is possible. How the dimension-ten construction enters.For CP maps \(F:M_{a}(\mathbb C)\to M_{b}(\mathbb C)\) and \(G:M_{b}(\mathbb C)\to M_{c}(\mathbb C)\), define \(F^\sharp=T_a\circ F^\dagger\circ T_b\), where \(F^\dagger\) is the Hilbert–Schmidt adjoint. The transpose-adjoint Choi identity is \[J(G\circ F)=(F^\sharp\otimes G)(\Omega_b\Omega_b^*), \qquad \Omega_b=\sum_{i=1}^b e_i\otimes e_i.\] This identity and the local-product formulation are established machinery [16]; we prove the needed rectangular form and normalization in Lemma 9. When \(F\) and \(G\) are PPT and the Choi matrix is nonzero, division by its trace gives a state in \(\mathscr C\). Applying this observation to Theorem 2 proves that (2) belongs to the class covered by the operational obstruction. It remains to make this state entangled. A nonzero separable positive matrix has a nonzero product vector in its range, a necessary part of the range criterion [34]. We exclude such vectors directly. Start with a PPT map \(L:M_{4}(\mathbb C)\to M_{4}(\mathbb C)\) and twenty projective directions \([x]\) at which \(L(xx^*)\) is singular. No nonzero homogeneous quadratic in four variables vanishes at ten of these directions. The ten-dimensional symmetric square records the quadratic monomials of \(x\), and the six-dimensional exterior square converts rank loss into a product vector in \(\ker Z\). If \(\operatorname{ran}Z\) contained a product vector, its two factors would give two nonzero quadratics whose zero sets cover all twenty directions. Each can cover at most nine, and \(9+9<20\). A separate positive definite output of \(L\) ensures that \(Z\) is nonzero. This range argument is related to unextendible product bases [10], nonorthogonal product exclusion by linear independence [49], and polynomial evaluation methods [45]. The complementary-pair operation on the exterior square agrees with the four-dimensional fermionic duality of Schliemann, Loss, and MacDonald [55]. Our explicit \(L\) comes from a real integer \(6\)-by-\(4\) matrix pencil. Its rank-losing directions solve a bilinear system of the type appearing in the study of low-rank PPT states on \(\mathbb C^4\otimes\mathbb C^4\) [27]. Exact reductions at three primes prove that the relevant degree-twenty algebra is a field with normal-closure Galois group \(S_{20}\). This symmetry carries one nonzero quadratic evaluation determinant to every ten-point choice. The arithmetic certificate and its precise computational coverage are given in Appendix 11. The channel and the projection construction.The PPT-composition problem has important affirmative cases, including two maps on \(M_{3}(\mathbb C)\) [16]; see also [12]. Other cases include Gaussian channels [16] and diagonal unitary covariant or conjugate diagonal unitary covariant PPT maps [56]. Asymptotic approach to the entanglement-breaking cone was proved for iterates of unital or trace-preserving PPT maps [37]. Finite entanglement-breaking index was proved for unital PPT channels by Rahaman, Jaques, and Paulsen [52], and for PPT channels with a full-rank invariant state by Hanson, Rouzé, and Stilck França [28]. More recent results concern different scopes. An and Lee prove that a qutrit CP map whose Choi matrix is one-copy undistillable and a qutrit CP map whose Choi matrix has Schmidt number at most two compose to an entanglement-breaking map in either order [3]. Park’s preprint states eventual entanglement breaking for each CP and completely copositive endomap, with a map-dependent number of iterations [44]. A failure at the second iterate is compatible with such eventual behavior. To obtain Theorem 3, we rescale the two maps, alternate them between two coordinate blocks, and send the missing trace to an absorbing flag. The switch follows Christandl, Müller-Hermes, and Wolf [16]; the flag completion follows Filippov’s trace-preserving extension [21]. The Choi matrix of the square has a local corner equal to a positive multiple of \(Z\). Local compression preserves separability, so that corner certifies that the square is not entanglement breaking. The final part of the paper develops a second way to retain entanglement under two PPT maps. A rectangular criterion starts from real unit vectors and projective measurements, uses a block Gram matrix for positivity, and uses commutation for the partial-transpose property. A support argument using zero tensor-basis diagonal entries rules out separability over the complex field. We realize the criterion by a restricted-intersection construction [23, 2] and tensor products of the Mermin–Peres parity measurements [42, 47, 48]. Its dimensions are much larger, but the mechanism is independent of the twenty-direction geometry. Frankl and Rödl’s forbidden-intersection theory similarly forces fixed-size orthogonal families in large subsets of a sign cube [22]; our eight-point estimate is proved by a direct polynomial bound and an elementary tensor-power fiber argument. The real construction also gives an entangled output when the same trace-preserving rectangular PPT channel is applied to both halves of a maximally entangled state. This distinction between real matrices and complex separability matters: the real-field example of Chiribella, Davidson, Paulsen, and Rahaman has an entanglement-breaking complexification [13]. Organization.Section 2 establishes the common map conventions, represented class, and Choi transfer. Sections 3–5 prove the operational theorem. Sections 6 and 7 construct the dimension-ten pair, and Section 8 proves the state and channel consequences. Sections 9 and 10 give the independent projection and combinatorial method. The appendices give the exact certificate, the general algebraic facts used in its proof, and the supplementary finite checks of the explicit data. PPT maps and the represented classAll matrix algebras in the constructions are finite-dimensional over \(\mathbb C\), with fixed orthonormal bases and the induced product bases. We write \(X^*\) for conjugate transpose, \(\overline X\) for entrywise conjugation, and \(T_d(X)=X^{\mathsf T}\) for the complex-linear transpose on \(M_{d}(\mathbb C)\). For a linear map \(F\), its Hilbert–Schmidt adjoint \(F^\dagger\) is characterized by \(\operatorname{tr}(Y^*F(X))=\operatorname{tr}((F^\dagger(Y))^*X)\). If \(V\) is a matrix, then \(\operatorname{Ad}_V(X)=VXV^*\). For \(F:M_{a}(\mathbb C)\to M_{b}(\mathbb C)\) our Choi convention is \[ J(F)=\sum_{i,j=1}^a E_{ij}\otimes F(E_{ij}) =(\mathrm{id}_a\otimes F)(\Omega_a\Omega_a^*), \qquad \Omega_a=\sum_{i=1}^a e_i\otimes e_i. \tag{3}\] In particular, \(\left\lVert\Omega_a\right\rVert^2=a\); the vector is not normalized. The first tensor factor is the input reference. This convention fixes every dimension factor in the transfer and channel formulas below. It is the map–operator correspondence associated with Jamiołkowski and Choi [35, 15]. Lemma 4. Let \(F:M_{a}(\mathbb C)\to M_{b}(\mathbb C)\) be CP. Then \(F^\dagger\) and \(T_b\circ F\circ T_a\) are CP. Moreover, \[F\circ T_a\text{ is CP}\quad\Longleftrightarrow\quad T_b\circ F\text{ is CP}.\] If \(F\) is PPT, so are \(T_b\circ F\), \(F\circ T_a\), its adjoint, its simultaneous transpose \(T_b\circ F\circ T_a\), and its transpose-adjoint \(F^\sharp:=T_a\circ F^\dagger\circ T_b\). Tensor products of PPT maps are PPT. If \(P\) and \(Q\) are compatible CP maps, then \(Q\circ F\circ P\) is PPT whenever \(F\) is PPT. Proof. Choose Kraus matrices \(A_r\in\mathbb C^{b\times a}\) such that \(F(X)=\sum_r A_rXA_r^*\). Then \[F^\dagger(Y)=\sum_r A_r^*YA_r, \qquad (T_b\circ F\circ T_a)(X) =\sum_r\overline{A_r}X\overline{A_r}^{\,*},\] which proves both CP assertions. Applying the simultaneous-transpose assertion to \(F\circ T_a\) or to \(T_b\circ F\) proves their equivalence. This argument works with rectangular Kraus matrices. The operator-sum representation is standard [39, 15]. Transpose is self-adjoint for the Hilbert–Schmidt inner product. Hence, when \(F\) is PPT, \[T_a\circ F^\dagger=(F\circ T_a)^\dagger \quad\text{and}\quad F^\dagger\circ T_b=(T_b\circ F)^\dagger\] are CP. This proves the PPT assertion for the adjoint, and simultaneous transposition gives the simultaneous transpose and transpose-adjoint. The output transpose of \(T_b\circ F\) is \(F\), while that of \(F\circ T_a\) is \(T_b\circ F\circ T_a\); all these maps are CP. This proves the remaining PPT assertions. With product bases, \(T_{b_1b_2}=T_{b_1}\otimes T_{b_2}\), so the tensor-product assertion follows from closure of CP maps under tensor products. Finally, for \(P:M_{a'}(\mathbb C)\to M_{a}(\mathbb C)\) and \(Q:M_{b}(\mathbb C)\to M_{b'}(\mathbb C)\), \[T_{b'}\circ Q\circ F\circ P = (T_{b'}\circ Q\circ T_b)\circ(T_b\circ F)\circ P\] is a composition of CP maps. The untransposed composition is CP as well. ◻ The input- and output-transpose formulations of PPT will therefore be used interchangeably. No trace condition is included in this terminology. The elementary closure facts above are also recorded, in related forms, in [37]. Lemma 5. A linear map \(F:M_{a}(\mathbb C)\to M_{b}(\mathbb C)\) is CP if and only if \(J(F)\succeq0\). For a CP map, the following are equivalent:
Also, \[J(T_b\circ F)=(\mathrm{id}_a\otimes T_b)J(F),\qquad J(F\circ T_a)=(T_a\otimes\mathrm{id}_b)J(F).\] Proof. The forward CP implication follows from (3). Conversely, write a positive Choi matrix as \(J(F)=\sum_r v_rv_r^*\). There is a unique matrix \(A_r\in\mathbb C^{b\times a}\) with \(v_r=(I_a\otimes A_r)\Omega_a\). Comparison of the \((i,j)\) blocks gives \(F(E_{ij})=\sum_r A_rE_{ij}A_r^*\) and hence the Kraus representation of \(F\). This is Choi’s finite-dimensional criterion [15]. If \(J(F)\) is separable, spectral decompositions of its positive factors write it as \(\sum_r a_ra_r^*\otimes b_rb_r^*\). Comparison of blocks now gives the measure-and-prepare formula \[F(X)=\sum_r \operatorname{tr}\bigl[(a_ra_r^*)^{\mathsf T}X\bigr]b_rb_r^*.\] Put \(E_r=(a_ra_r^*)^{\mathsf T}\succeq0\). For \(W\succeq0\), each partial matrix \[\operatorname{tr}_a\bigl[(I_k\otimes E_r)W\bigr] =\operatorname{tr}_a\bigl[(I_k\otimes\sqrt{E_r})W (I_k\otimes\sqrt{E_r})\bigr]\] is positive. Thus \((\mathrm{id}_k\otimes F)(W)\) is a sum of positive products with second factors \(b_rb_r^*\). The converse follows by applying the asserted property to \(W=\Omega_a\Omega_a^*\). This proves the entanglement-breaking characterization [33] at the level of the CP cone. The two transpose identities follow directly by reindexing the matrix units in (3). ◻ Lemma 6. Every nonzero separable positive matrix has a nonzero product vector in its range. Consequently, a nonzero positive matrix whose range contains no nonzero product vector is nonseparable. Proof. Refine a separable decomposition by the spectral decompositions of its positive factors. It then has the form \(Z=\sum_r v_rv_r^*\) with product vectors \(v_r=a_r\otimes b_r\). Since \(\ker Z=\bigcap_r v_r^\perp\), every \(v_r\) lies in \((\ker Z)^\perp=\operatorname{ran}Z\). If \(Z\ne0\), at least one \(v_r\) is nonzero. ◻ This is the range condition we use from the range criterion [34]. It is only a necessary condition for separability; the dimension-ten construction below establishes its failure directly. Definition 7. A density operator \(\omega\) on \(\mathbb C^a\otimes\mathbb C^b\) belongs to the represented class \(\mathscr C\) if there are positive integers \(r,s\), a vector \(\chi\in\mathbb C^r\otimes\mathbb C^s\), and linear maps \(\mathcal L:M_{r}(\mathbb C)\to M_{a}(\mathbb C)\) and \(\mathcal M:M_{s}(\mathbb C)\to M_{b}(\mathbb C)\) such that \[ \omega=(\mathcal L\otimes\mathcal M)(\chi\chi^*), \qquad \mathcal L,\ \mathcal L\circ T_r,\ \mathcal M,\ \mathcal M\circ T_s \text{ are CP}. \tag{4}\] Only \(\omega\) is required to have trace one. The vector \(\chi\) may be unnormalized, and the maps need not preserve trace. This is a representation property, with no assumed physical implementation of the representing maps. Lemma 4 shows that the two maps are PPT also in the output convention. In particular the state itself has positive partial transpose, since, for example, \((T_a\otimes\mathrm{id}_b)(\omega)= ((T_a\circ\mathcal L)\otimes\mathcal M)(\chi\chi^*)\succeq0\). The operational proof will use the representing maps themselves, in addition to this partial-transpose consequence. Lemma 8. The class \(\mathscr C\) is closed under finite tensor products, after grouping all first-party systems and all second-party systems. In particular, \(\omega^{\otimes n}\in\mathscr C\) for every \(\omega\in\mathscr C\) and every \(n\geq1\). Proof. Tensor the representing vectors and the first-party maps separately from the second-party maps, and use the canonical local permutation unitaries to group the systems. Tensor products of CP maps are CP, and input transpose in the grouped product basis is the tensor product of the individual input transposes. Hence the four maps required in (4) remain CP. The output is the tensor product of the original states and has trace one. The local permutation unitaries and their conjugates are CP pre- and post-compositions, so they do not affect the conclusion. ◻ Lemma 9 (Choi transfer). Let \(F:M_{a}(\mathbb C)\to M_{b}(\mathbb C)\) and \(G:M_{b}(\mathbb C)\to M_{c}(\mathbb C)\) be CP maps, and set \(F^\sharp=T_a\circ F^\dagger\circ T_b\). Then \[ J(G\circ F)=(F^\sharp\otimes G)(\Omega_b\Omega_b^*). \tag{5}\] If \(F\) and \(G\) are PPT and \(Z=J(G\circ F)\ne0\), then \(\lambda:=\operatorname{tr}Z>0\) and \[ \frac{Z}{\lambda} =(F^\sharp\otimes G) \left(\frac{\Omega_b\Omega_b^*}{\lambda}\right)\in\mathscr C \quad\text{on }\mathbb C^a\otimes\mathbb C^c. \tag{6}\] Proof. Let \(A_r\in\mathbb C^{b\times a}\) and \(B_s\in\mathbb C^{c\times b}\) be Kraus matrices for \(F\) and \(G\). Transposing the adjoint formula gives \[F^\sharp(Y)=\sum_r A_r^{\mathsf T}Y\overline{A_r} =\sum_r A_r^{\mathsf T}Y(A_r^{\mathsf T})^*.\] Thus the Kraus matrices of \(F^\sharp:M_{b}(\mathbb C)\to M_{a}(\mathbb C)\) are the transposes \(A_r^{\mathsf T}\). For each pair of Kraus matrices, direct expansion in the fixed bases gives \[(A_r^{\mathsf T}\otimes B_s)\Omega_b =(I_a\otimes B_sA_r)\Omega_a.\] Summing the corresponding rank-one matrices proves (5). This is the rectangular CP form of the transpose-adjoint identity in [16]; its use for local products of PPT maps is discussed there in Section IV.B. Suppose now that \(F\) and \(G\) are PPT. Besides complete positivity of \(F^\sharp\) and \(G\), Lemma 4 gives \[F^\sharp\circ T_b=T_a\circ F^\dagger=(F\circ T_a)^\dagger \text{ CP}, \qquad G\circ T_b\text{ CP}.\] These are exactly the input-transpose conditions for the two local maps in Definition 7. Finally, \[Z=\sum_{r,s}|(I_a\otimes B_sA_r)\Omega_a\rangle \langle(I_a\otimes B_sA_r)\Omega_a|, \qquad \lambda=\sum_{r,s}\left\lVert B_sA_r\right\rVert_{\mathrm F}^{\,2}.\] The nonzero positive matrix \(Z\) has \(\lambda>0\). Taking \(\chi=\Omega_b/\sqrt\lambda\) in (4) proves (6). Its squared norm is \(b/\lambda\), which is allowed by the definition. No trace-preserving hypothesis or additional factor of \(b\) is used. ◻ A four-effect coherence boundThe first step in the operational argument is an inequality for four arbitrary positive local matrices. It compares the coherence between two equal-bit branches with the weights of branches in which the two bits differ. The matrices need not form measurements: later they will be densities at a fixed public transcript, where pointwise normalization is not required. We use the represented class \(\mathscr C\) of Definition 7. Thus, if \(\omega\in\mathscr C\) acts on \(\mathbb C^p\otimes\mathbb C^q\), then for some positive integers \(r,s\) it has a representation \[\omega=(\mathcal L\otimes\mathcal M)(\chi\chi^*), \qquad \chi\in\mathbb C^r\otimes\mathbb C^s,\] where \(\mathcal L:M_{r}(\mathbb C)\to M_{p}(\mathbb C)\) and \(\mathcal M:M_{s}(\mathbb C)\to M_{q}(\mathbb C)\) satisfy that \(\mathcal L,\mathcal L\circ T_r,\mathcal M,\mathcal M\circ T_s\) are completely positive. Only \(\omega\) has trace one; the vector and the rectangular maps have no normalization requirement. We will use that freedom to change coordinates on the input of \(\mathcal L\). Lemma 10 (Positive block estimate). Let \(H\) and \(J\) be square matrices, possibly of different sizes, and let \(Z\) have the corresponding rectangular size. If \[\begin{pmatrix}H&Z\\ Z^*&J\end{pmatrix}\succeq0,\] then \[\left\lVert Z\right\rVert_1\le\sqrt{\operatorname{tr}H\,\operatorname{tr}J}.\] This estimate includes singular \(H\) and \(J\). Proof. A spectral decomposition of the positive block matrix expresses it as a finite sum of outer products of block columns \(\binom{a_k}{b_k}\). Consequently \(H=\sum_k a_ka_k^*\), \(J=\sum_k b_kb_k^*\), and \(Z=\sum_k a_kb_k^*\). Since a rank-one matrix \(ab^*\) has trace norm \(\left\lVert a\right\rVert\,\left\lVert b\right\rVert\), the triangle inequality and Cauchy–Schwarz give \[\left\lVert Z\right\rVert_1 \le\sum_k\left\lVert a_k\right\rVert\,\left\lVert b_k\right\rVert \le\left(\sum_k\left\lVert a_k\right\rVert^2\right)^{1/2} \left(\sum_k\left\lVert b_k\right\rVert^2\right)^{1/2} =\sqrt{\operatorname{tr}H\,\operatorname{tr}J}.\] No inverse of a diagonal block is used. ◻ Lemma 11 (Four-effect inequality). Let \(\omega\in\mathscr C\) act on \(\mathbb C^p\otimes\mathbb C^q\). For arbitrary \(X_0,X_1\succeq0\) in \(M_{p}(\mathbb C)\) and \(Y_0,Y_1\succeq0\) in \(M_{q}(\mathbb C)\), put \[D_{ij}=X_i\otimes Y_j, \qquad p_{ij}=\operatorname{tr}(D_{ij}\omega), \qquad i,j\in\{0,1\}.\] Then \[ \left\lVert\sqrt{D_{00}}\,\omega\sqrt{D_{11}}\right\rVert_1 \le \sqrt{p_{00}p_{01}}+\sqrt{p_{10}p_{11}} +2\sqrt{p_{01}p_{10}}. \tag{7}\] There is no normalization assumption on \(X_0,X_1,Y_0,Y_1\). Proof. Fix a representation of \(\omega\) as above. Pull the four matrices back to the two input spaces by the Hilbert–Schmidt adjoints: \[A_i=\mathcal L^\dagger(X_i)\in M_{r}(\mathbb C), \qquad B_j=\mathcal M^\dagger(Y_j)\in M_{s}(\mathbb C).\] These matrices are positive. For instance, for every \(a\in\mathbb C^r\), \[a^*A_i a=\operatorname{tr}\bigl[X_i\mathcal L(aa^*)\bigr]\ge0.\] We first replace the representation by one in which \(A_0\) and \(A_1\) commute; the two complete-positivity conditions will then give complementary estimates for each off-diagonal term of the input. Normalization on the support.Set \(H=A_0+A_1\), and let \(\Pi\) be the orthogonal projection onto \(\operatorname{ran}H\). If \(a\in\ker H\), the nonnegative numbers \(a^*A_i a=\left\lVert\sqrt{A_i}a\right\rVert^2\) sum to zero, so each \(A_i\) annihilates \(\ker H\). It follows also that \(A_i=\Pi A_i\Pi\). Define \(S\) to be \(H^{-1/2}\) on \(\operatorname{ran}H\) and the identity on \(\ker H\). The matrix \(S\) is positive and invertible on all of \(\mathbb C^r\), including when \(H=0\). The two positive matrices \[A_i'=S^*A_iS\] are supported on \(\Pi\) and satisfy \(A_0'+A_1'=\Pi\). Hence they commute: \([A_0',A_1']=[A_0',\Pi-A_0']=0\). This congruence can be made inside the representation without changing \(\omega\). With \(\operatorname{Ad}_S(U)=SUS^*\), replace \[\mathcal L\quad\hbox{by}\quad\mathcal L'= \mathcal L\circ\operatorname{Ad}_S, \qquad \chi\quad\hbox{by}\quad\chi'=(S^{-1}\otimes I_s)\chi.\] The resulting output is the same, and the pullbacks of \(X_i\) are \(A_i'\). The new map is CP, and its input-transpose condition follows from \[\operatorname{Ad}_S\circ T_r=T_r\circ\operatorname{Ad}_{\overline S}, \qquad \mathcal L'\circ T_r=(\mathcal L\circ T_r) \circ\operatorname{Ad}_{\overline S}.\] Thus it remains a representation of the kind required by Definition 7. We now suppress the primes. The two block estimates.Let \(C=\mathcal L\otimes\mathcal M\). For input vectors \(u,z\in\mathbb C^r\otimes\mathbb C^s\), define \[\begin{split} p_{ij}(u)&=u^*(A_i\otimes B_j)u =\operatorname{tr}\bigl[D_{ij}C(uu^*)\bigr],\\ Z(u,z)&=\sqrt{D_{00}}\,C(uz^*)\sqrt{D_{11}}. \end{split}\] Complete positivity of \(C\) means that applying it entrywise to \[\begin{pmatrix}uu^*&uz^*\\ zu^*&zz^*\end{pmatrix} =\binom{u}{z}\binom{u}{z}^*\] gives a positive block matrix. Conjugate that matrix by \(\operatorname{diag}(\sqrt{D_{00}},\sqrt{D_{11}})\) and apply Lemma 10. The result is \[ \left\lVert Z(u,z)\right\rVert_1\le\sqrt{p_{00}(u)p_{11}(z)}. \tag{8}\] The second estimate concerns the same \(Z(u,z)\), but exchanges the two input vectors in the diagonal weights. In the product input basis the global input transpose is \(T_{rs}=T_r\otimes T_s\). The map \[C\circ T_{rs}=(\mathcal L\circ T_r)\otimes (\mathcal M\circ T_s)\] is CP. Apply the preceding block argument to this map, with the ordered pair \((\overline z,\overline u)\) and the same two output filters. The identities \[(\overline z\,\overline u^*)^\mathsf T=uz^*,\qquad (\overline z\,\overline z^*)^\mathsf T=zz^*,\qquad (\overline u\,\overline u^*)^\mathsf T=uu^*\] show that the off-diagonal output is unchanged while the two diagonal inputs are exchanged. We obtain \[ \left\lVert Z(u,z)\right\rVert_1\le\sqrt{p_{00}(z)p_{11}(u)}. \tag{9}\] It is the transpose on both input factors here that supplies this reverse estimate. Splitting the input vector.Choose a common orthonormal eigenbasis of the commuting \(A_0,A_1\). Let \(P\) be the projection onto the basis vectors on which the eigenvalue of \(A_0\) is at least the eigenvalue of \(A_1\), and set \[v=(P\otimes I_s)\chi,\qquad w=((I_r-P)\otimes I_s)\chi.\] Then \(\chi=v+w\). Because \(PA_i(I_r-P)=0\), the cross terms in the quadratic forms defining \(p_{ij}\) vanish. The eigenvalue comparison on the two subspaces, together with \(B_0,B_1\succeq0\), therefore gives \[ \begin{gathered} p_{ij}=p_{ij}(v)+p_{ij}(w),\\ p_{11}(v)\le p_{01}(v),\qquad p_{00}(w)\le p_{10}(w). \end{gathered} \tag{10}\] For example, \(A_0-A_1\) is positive on \(\operatorname{ran}P\), so its tensor product with \(B_1\) has nonnegative quadratic form on \(v\); the second comparison follows on \(\ker P\) using \(B_0\). We can now bound the four terms in the expansion of \(C(\chi\chi^*)\). For the diagonal terms, (8) and (10) give \[\begin{aligned} \left\lVert Z(v,v)\right\rVert_1 &\le\sqrt{p_{00}(v)p_{11}(v)} \le\sqrt{p_{00}p_{01}},\\ \left\lVert Z(w,w)\right\rVert_1 &\le\sqrt{p_{00}(w)p_{11}(w)} \le\sqrt{p_{10}p_{11}}. \end{aligned}\] For \(Z(v,w)\) use the reverse estimate (9); for \(Z(w,v)\) use the direct estimate (8). Both right sides become the same: \[\begin{aligned} \left\lVert Z(v,w)\right\rVert_1&\le\sqrt{p_{00}(w)p_{11}(v)} \le\sqrt{p_{10}p_{01}},\\ \left\lVert Z(w,v)\right\rVert_1&\le\sqrt{p_{00}(w)p_{11}(v)} \le\sqrt{p_{10}p_{01}}. \end{aligned}\] Finally, \[\sqrt{D_{00}}\,\omega\sqrt{D_{11}} =Z(v,v)+Z(v,w)+Z(w,v)+Z(w,w).\] The triangle inequality now yields (7). ◻ By Lemma 8, the same inequality applies to arbitrary joint positive matrices on all of Alice’s and all of Bob’s copies of a state in \(\mathscr C\). Its lack of any normalization condition is the feature that will let us apply it at each complete public transcript. Complete public transcriptsTo apply the four-effect inequality to a protocol, we must obtain \(X_i(t)\otimes Y_j(t)\) at each public transcript \(t\), with the same two local pairs for all four bit values. These matrices describe the effects of the entire protocol on its input. They are not the effects of just its last measurements. We first derive this form for finite classical records, then prove its measurable counterpart for the admitted protocols below. The transcript always retains every public message, public random draw, and public stopping decision. The finite-record mechanismLet \(R\) be the input state on finite-dimensional spaces \(A\otimes B\). In fixed product bases, Eve’s canonical purification is \[ |\Psi_R\rangle=\sum_h\sqrt R\,|h\rangle_{AB}|h\rangle_E, \qquad E\cong A\otimes B. \tag{11}\] For the moment suppose there are finitely many local-instrument and public steps, including the final readouts, every classical record is finite, and each party produces its prescribed bit almost surely on \(R\). Use the following resource rules: the recorded initial public variable \(C_0\) is independent of the input and reference; conditional on \(C_0\), that input-reference state and the two private auxiliary resources form a product. The initial public law and local preparation kernels are fixed when the input varies. All later public-source draws use fixed input-independent kernels of the preceding public record. Thus the input is the only shared private resource. Fix a complete public transcript \(t\). In Alice’s laboratory, compose the instrument branches consistent with \(t\) and final bit \(i\), retaining private memory until it is no longer used and summing private outcomes locally. This gives a CP map \(\mathcal A_i^t\) on her input. Bob obtains a CP map \(\mathcal B_j^t\) in the same way. At this fixed public record each local choice can depend on the preceding public messages but not on the other party’s unannounced private outcomes. The compatible private histories therefore sum independently within the two laboratories. Public-source weights are scalars fixed by \(t\); absorbing their product into either local map, the joint branch is \(\mathcal A_i^t\otimes\mathcal B_j^t\). Set \(X_i(t)=(\mathcal A_i^t)^\dagger(I)\) and \(Y_j(t)=(\mathcal B_j^t)^\dagger(I)\). These matrices are positive and the branch effect is \(D_{ij}(t)=X_i(t)\otimes Y_j(t)\). Tracing the final laboratory memories out of that branch leaves Eve with \[\tau_{ij}(t)=\bigl(\sqrt R\,D_{ij}(t)\sqrt R\bigr)^\mathsf T.\] Indeed, the \((h,k)\) matrix entry on Eve’s system is \(\operatorname{tr}[D_{ij}(t)\sqrt R|h\rangle\langle k|\sqrt R] =\langle k|\sqrt R D_{ij}(t)\sqrt R|h\rangle\). The same \(X_0,X_1\) and \(Y_0,Y_1\) occur in all four branches. Private instrument labels have been summed, not added to Eve’s transcript. No pointwise normalization is required at a fixed \(t\); normalization holds after summing all final bits and all transcripts. For a continuous transcript, a singleton may have probability zero, and with countably many steps an output may depend on the complete local history. The general statement will replace the preceding matrices by densities with respect to a single transcript measure. Its proof runs the protocol on a product of two local probes, each with an untouched reference. On that product input the local histories are independent conditional on the complete public record. Reference measurements recover common product matrix densities from this scalar independence, and a fixed filter on the references gives the blocks for \(R\). The admitted protocol modelThe instrument formalism originates with Davies and Lewis [18]. Chitambar, Leung, Mančinska, Ozols, and Winter [14] distinguish finite-round LOCC, infinite linked protocols, and topological closure. We specify the measurable model used here so that both its complete-history law and any terminal readout are part of the protocol data. Ordinary finite protocols obtain these laws by composition; a countable schedule requires the compatibility conditions below. Definition 12 (Admitted local protocols). Let \(A\) and \(B\) be finite-dimensional complex input spaces. An admitted protocol consists of local quantum instruments, local memories and randomness, and authenticated two-way public classical communication. Each party may process its whole input space jointly. Its data and their joint laws satisfy the following requirements.
For a finite protocol whose instruments and public steps satisfy clauses [protocol:initial]–[protocol:public], composition of those instruments supplies the prefix laws and any finite terminal refinement in clauses [protocol:reference]–[protocol:terminal]. The separate complete-history and terminal-process requirements matter when a countable schedule or an aggregated subroutine is used. There is no uniform bound on the amount of communication, the size of a standard Borel message, or the number of rounds within this scope. In particular, a terminal classical bit can depend on an entire infinite record. Common effects at a complete transcriptLemma 13 (Common local factors for a complete transcript). Let \(R\) be a density operator on finite-dimensional complex spaces \(A\otimes B\), and let an admitted protocol produce bits \(i,j\in\{0,1\}\) almost surely on \(R\). Give Eve the canonical purification (11), and let her retain \(E\) and the complete public transcript \(T\) with value \(t\) in its standard Borel space \(\mathsf T\). There exist a finite positive measure \(\mu\) on \(\mathsf T\) and measurable positive matrices \(X_0(t),X_1(t)\) on \(A\) and \(Y_0(t),Y_1(t)\) on \(B\) such that the positive matrix-valued measure of Eve in bit branch \((i,j)\) has the density \[ \tau_{ij}(t)= \bigl(\sqrt R\,[X_i(t)\otimes Y_j(t)]\sqrt R\bigr)^\mathsf T \quad\text{with respect to }\mu. \tag{12}\] The same \(X_i(t)\) and \(Y_j(t)\) work for all four branches outside one \(\mu\)-null set, and \[\sum_{i,j=0}^1\int_{\mathsf T}\operatorname{tr}\tau_{ij}(t)\,d\mu(t)=1.\] The transpose in (12) is in the product basis identifying \(E\) with \(A\otimes B\). No invertibility of \(R\) is assumed. Proof. Write \(a=\dim A\) and \(b=\dim B\), and attach untouched finite references \(A_0\cong A\) and \(B_0\cong B\). Run the protocol on the product of the normalized local probes \[ |\Phi_a\rangle_{AA_0}\otimes|\Phi_b\rangle_{BB_0}, \qquad |\Phi_a\rangle=a^{-1/2}\sum_{r=1}^{a}|r,r\rangle, \qquad |\Phi_b\rangle=b^{-1/2}\sum_{s=1}^{b}|s,s\rangle. \tag{13}\] The protocol need not produce both bits on this auxiliary input. For this experiment assign bit zero in a laboratory if its prescribed bit is never produced, and retain a bit that has already been produced. The assignment is a measurable local rule. It does not replace the other laboratory’s output when only one output is missing. We will remove the contribution of these auxiliary defaults after recovering the actual input. The proof has three steps. First, clauses [protocol:initial]–[protocol:public] give conditional independence of the two local sampling tapes on the product probes, given the complete public transcript. Next, clauses [protocol:reference]–[protocol:terminal] give positive reference measures; informationally complete tests turn the scalar independence into product matrix densities. Finally, a filter on the untouched references prepares (11) and transfers those densities to Eve’s actual blocks. Conditional independence on the product probes.The scalar factorization has the finite private-coin rectangle property as a classical antecedent [6]. We prove the complete-history version needed here before recovering its matrix-valued factors. Choose a finite informationally complete POVM on each reference. One explicit construction in dimension \(d\) starts with the projections onto the basis vectors and onto \[(|r\rangle+|s\rangle)/\sqrt2, \qquad (|r\rangle+\mathrm i|s\rangle)/\sqrt2 \quad (r<s).\] These projections span the real vector space of Hermitian matrices. If they are \(P_1,\ldots,P_N\), the \(2N\) effects \(P_k/N\) and \((I-P_k)/N\) form a POVM with the same spanning property. Call the two resulting POVMs \((E_r)_r\) and \((G_s)_s\). Because the references are untouched, these tests commute with all laboratory operations. Their joint statistics with the transcript and final bits can therefore be computed with the tests performed at the start. In this tested product-probe experiment, sample \(C_0\) with the same fixed law as in the actual run. Conditional on \(C_0\), all local outcomes can be sampled using independent local random tapes \(U\) for Alice and \(V\) for Bob. The tapes may be taken as countable products of uniform variables, with coordinates reserved for the reference tests and any terminal readouts. They are chosen before the sampling; the local outcome histories are then functions of these tapes and the public record. At each local instrument, sample its conditional outcome law using a fresh uniform variable on that laboratory’s tape and apply the stipulated conditional state update. The tested input and private ancillas are a product across laboratories conditional on \(C_0\), and each local update changes only its own local state. At a public-source step, sample \(\kappa_m(T_m,dc)\) using a fresh public uniform variable independent of the private tapes and all prior sampling variables; only the recorded draw enters the transcript. This step leaves the quantum registers unchanged. Induction over the specified finite prefixes therefore shows that this sampling has the genuine joint finite-prefix laws. For a standard Borel outcome space a probability kernel has such a jointly measurable sampler: one may code the space by a Borel subset of \([0,1]\) and use the measurable kernel-sampling theorem [36]. The initial reference tests and each specified local terminal quantum readout are sampled in the same way. Their stated local compatible refinements give the genuine tested laws on the complete histories. A terminal classical readout is already a measurable function of its records. Each defaulted bit and each reference-test result is consequently a measurable function of that laboratory’s tape and the complete public transcript. This sampling describes the auxiliary product input; the actual input \(R\) need not have a product simulation. Let \(T_m\) consist of \(C_0\) and the first \(m\) subsequent public records, and let \(\mathcal F_m=\sigma(T_m)\). At a step sent by Alice the new record is measurable with respect to \(\sigma(U)\vee\mathcal F_m\); at a step sent by Bob the analogous statement holds with \(V\). At a public-source step with new draw \(C\), the sampling construction gives \[\mathbb P(C\in dc\mid\sigma(U,V)\vee\mathcal F_m)=\kappa_m(T_m,dc).\] We show by induction that \(U\) and \(V\) are conditionally independent given \(\mathcal F_m\). The assertion at \(m=0\) follows from the product initial resources and independent private tapes conditional on \(C_0\). Suppose it holds at \(m\) and Alice sends the next record. For bounded measurable functions \(u\) and \(v\), conditional independence gives \[\mathbb E[v(V)\mid\sigma(U)\vee\mathcal F_m] =\mathbb E[v(V)\mid\mathcal F_m].\] As \(\mathcal F_{m+1}\subseteq\sigma(U)\vee\mathcal F_m\), conditioning this equality on \(\mathcal F_{m+1}\) shows that \[\mathbb E[v(V)\mid\mathcal F_{m+1}] =\mathbb E[v(V)\mid\mathcal F_m].\] Using the same equality inside the conditional expectation of \(u(U)v(V)\) gives \[ \mathbb E[u(U)v(V)\mid\mathcal F_{m+1}] =\mathbb E[u(U)\mid\mathcal F_{m+1}] \mathbb E[v(V)\mid\mathcal F_{m+1}]. \tag{14}\] The Bob step is symmetric. For a public-source step, let \(\varphi\) be a bounded measurable function of its new draw \(C\), and write \((\kappa_m\varphi)(T_m)=\int\varphi(c)\,\kappa_m(T_m,dc)\). The kernel condition and the induction hypothesis give \[\mathbb E[u(U)v(V)\varphi(C)\mid\mathcal F_m] =(\kappa_m\varphi)(T_m) \mathbb E[u(U)\mid\mathcal F_m]\, \mathbb E[v(V)\mid\mathcal F_m].\] Testing against bounded \(\mathcal F_m\)-measurable factors times \(\varphi(C)\) and applying the monotone class theorem identifies conditional expectations on \(\mathcal F_{m+1}=\mathcal F_m\vee\sigma(C)\). Taking \(v=1\) or \(u=1\) shows that the respective conditional marginal is unchanged; taking both functions gives their product. Thus the same factorization (14) holds after the public-source step. The rules for speaker and stopping records are among these sender and public-source steps. If two messages were simultaneous, ordering them preserves the required measurability for the second, because it still depends only on its original earlier record. Fixed padding after a public stop also preserves the claim. Set \(\mathcal F_\infty=\sigma(\bigcup_m\mathcal F_m)=\sigma(T)\), the sigma field of the actual complete transcript. The auxiliary sampling uniforms for later public draws are not adjoined. If \(Z\) is bounded, then \[\mathbb E[Z\mid\mathcal F_m]\longrightarrow \mathbb E[Z\mid\mathcal F_\infty]\quad\text{in }L^2.\] Indeed, these are the orthogonal projections of \(Z\) onto increasing closed subspaces of \(L^2\). Their limit is the projection onto the closure of the union. Indicators of finite-prefix events belong to that union, and the monotone class theorem shows that their span is dense in \(L^2(\mathcal F_\infty)\). The limiting projection is therefore the indicated conditional expectation. For bounded \(u,v\), the two conditional expectations on the right of (14) converge in \(L^2\) and remain bounded. Cauchy–Schwarz applied to the difference of their products gives convergence in \(L^1\). Passing to the limit in (14) proves \[\mathbb E[u(U)v(V)\mid\mathcal F_\infty] =\mathbb E[u(U)\mid\mathcal F_\infty] \mathbb E[v(V)\mid\mathcal F_\infty].\] The tape spaces and \(\mathsf T\) are standard Borel. They admit regular conditional probability kernels and conditional integration of functions depending on \(t\) [36]. Apply the last factorization to indicators from countable generating algebras for the two tape spaces, including the whole spaces, and discard the union of the resulting null sets. Their product rectangles form a \(\pi\)-system generating the product sigma field. Uniqueness of probability measures on that \(\pi\)-system then yields, on a single set of full transcript measure, \[ \mathsf P_{U,V\mid T=t} =\mathsf P_{U\mid T=t}\otimes\mathsf P_{V\mid T=t}. \tag{15}\] In particular this law factors the conditional expectations of any bounded measurable function of \((U,t)\) and any bounded measurable function of \((V,t)\). Thus the pair consisting of Alice’s defaulted bit and her reference-test result is conditionally independent of the corresponding pair for Bob, given \(t\). Positive reference measures and their densities.Return to the experiment in which the probes are retained and the reference tests are not performed. We first construct its reference matrix measure on the space of all genuine classical instrument histories, including private histories. The fixed initial law of \(C_0\) and the specified finite-prefix instruments give a positive reference matrix measure at every prefix. Summing the next local outcome recovers the preceding reference measure because the total instrument is trace preserving. Integrating a public-source outcome does the same because its scalar kernel has total mass one and acts as the identity on the quantum registers. These measures are therefore consistent on finite cylinders. Here is the countable extension in finite-dimensional terms. For a positive reference test, its scalar finite-prefix laws are consistent finite measures; after normalization, or by adjoining the complementary test outcome, the countable product extension theorem applies [36]. It supplies a finite scalar measure on the countable standard Borel history space. Recover matrix entries from finitely many rank-one reference tests by polarization. For an arbitrary reference vector \(z\), extend also its positive rank-one test. On finite cylinders the resulting scalar measure equals the quadratic form \(z^*W(\,\cdot\,)z\) of the recovered matrix measure. Uniqueness of finite measures on cylinders extends this equality to the entire history sigma field. Thus \(z^*W(S)z\ge0\) for every measurable \(S\) and every \(z\), so \(W\) is a positive matrix-valued measure. This argument constructs a measure for the untouched finite references; it asks for no limiting state of unused quantum memory. Measurable terminal classical readouts and the local default rule now give measurable events in the history space. If a terminal quantum readout is used, the incoming local process stipulated in Definition 12, on those same instrument histories and with an untouched finite reference, together with its specified local instrument gives the bit-conditioned positive reference measures. Each instrument is selected from its own laboratory’s history and \(T\); their joint refinement is obtained by the two local operations. Include the missing or noninvoked tag among the outcomes, so summing both local outcomes recovers the reference measure on the complete history. This terminal operation is a separate extension of that history; its outcome is included in the enlarged history before the classical readout. This is where clauses [protocol:reference]–[protocol:terminal] supply the needed locality, prefix compatibility, and reference stability. Write \(\widehat W\) for the resulting positive reference measure on the enlarged history space. Its marginal on the preterminal history is \(W\); when no readout is used, identify \(\widehat W\) with \(W\) using trivial terminal tags. The construction uses the genuine instrument records; the tapes above were only a sampling device for their tested scalar laws. Let \(W_{ij}(S)\) be the restriction and pushforward of \(\widehat W\) to the defaulted bit pair \((i,j)\) and transcript in a measurable set \(S\subseteq\mathsf T\). Define the probe transcript law \[\mu(S)=\sum_{i,j=0}^1\operatorname{tr}W_{ij}(S).\] It is a probability measure: the probe is normalized, the instrument totals preserve trace, and the defaults assign a pair on every history. For each \(i,j\), positivity and \(\operatorname{tr}W_{ij}(S)\le\mu(S)\) imply absolute continuity of every matrix entry with respect to \(\mu\). Hence there are entrywise Radon–Nikodym densities \(W_{ij}(t)\). Only the dominated finite-measure case is needed here. For completeness, if \(0\le\nu\le c\mu\), the functional \(g\mapsto\int g\,d\nu\) on simple functions is bounded in \(L^2(\mu)\) by Cauchy–Schwarz. Its Hilbert space representing vector is a density, and indicator tests show that the density lies between \(0\) and \(c\). Apply this fact to the finitely many polarization tests for the matrix entries. Testing the densities on a countable dense set of reference vectors shows that \(W_{ij}(t)\succeq0\) outside one null set. The equality defining \(\mu\) also gives \[\sum_{i,j}\operatorname{tr}W_{ij}(t)=1\quad\text{for $\mu$-almost every }t.\] Put \[U_i(t)=\sum_j\operatorname{tr}_{B_0}W_{ij}(t), \qquad V_j(t)=\sum_i\operatorname{tr}_{A_0}W_{ij}(t).\] Both local pairs are positive, and \(\sum_i\operatorname{tr}U_i(t)=\sum_j\operatorname{tr}V_j(t)=1\) almost everywhere. The conditional scalar statistics of the reference tests are the traces against these densities. Their local marginals are \(\operatorname{tr}[E_rU_i(t)]\) and \(\operatorname{tr}[G_sV_j(t)]\), because the other POVM sums to the identity. Conditional independence from (15) therefore gives \[\operatorname{tr}[(E_r\otimes G_s)W_{ij}(t)] =\operatorname{tr}[E_rU_i(t)]\,\operatorname{tr}[G_sV_j(t)]\] for every \(i,j,r,s\), outside one null set. The tensor products \(E_r\otimes G_s\) span the Hermitian matrices on \(A_0\otimes B_0\). Equality against that spanning family proves \[ W_{ij}(t)=U_i(t)\otimes V_j(t) \quad\text{for all }i,j\text{ and $\mu$-almost every }t. \tag{16}\] We have obtained the same two local matrix pairs for all four branches, without conditioning on a positive-probability singleton transcript and without making private instrument labels public. Recovering the actual purification.Identify \(A_0\otimes B_0\) with \(E\) in the product basis and define \[K=\sqrt{ab}\,(\sqrt R)^\mathsf T.\] The elementary identity \((I\otimes S^\mathsf T)\sum_h|h,h\rangle=(S\otimes I)\sum_h|h,h\rangle\) shows that applying \(I_{AB}\otimes K\) to the product probes (13) gives exactly \(|\Psi_R\rangle\). This joint filter on the references is an algebraic preparation of the input purification; the laboratories are not required to implement it. It need not be trace preserving or a contraction. The same independent law of \(C_0\) and the same \(C_0\)-conditioned local auxiliary resources are used on the probes and on the actual input. Consequently the filter also prepares the full initial joint law, including \(C_0\) and those resources. On each finite cylinder of genuine histories, the reference matrix for this filtered input is \(K W(\,\cdot\,)K^*\), because the references are untouched and the filter commutes with every local instrument. Every public-source update also commutes with the filter: at a given public record it multiplies both laws by the same scalar kernel and acts as the identity on the reference. The scalar entries on both sides are finite measures, so uniqueness extends their equality from cylinders to the full history sigma field. The same commutation holds for any appended terminal instrument by clause [protocol:terminal]. Thus the filtered law on the enlarged history is \(K\widehat W(\,\cdot\,)K^*\), and the identity holds for the bit-conditioned measures as well. Let \(N\) be the event in this enlarged history space that at least one prescribed local bit is missing before the default rule. The event may depend on private records. On the actual input its probability is zero by hypothesis, so positivity gives \[\operatorname{tr}[K\widehat W(N)K^*]=0, \qquad K\widehat W(N)K^*=0.\] Every subevent of \(N\) has a positive filtered matrix bounded by this zero matrix. It therefore also contributes zero. Thus the local defaults leave the actual output measure unchanged, even though they may occur on the probes. The argument was made on full histories before discarding private records, so \(N\) need not be public. It follows from (16) that the actual Eve density in branch \((i,j)\) is \(K(U_i(t)\otimes V_j(t))K^*\). The matrix \((\sqrt R)^\mathsf T\) is Hermitian. Hence direct multiplication gives \[\begin{aligned} K(U_i\otimes V_j)K^* &=ab(\sqrt R)^\mathsf T(U_i\otimes V_j)(\sqrt R)^\mathsf T\\ &=\bigl(\sqrt R\,[aU_i^\mathsf T\otimes bV_j^\mathsf T]\sqrt R\bigr)^\mathsf T. \end{aligned}\] Take \(X_i(t)=aU_i(t)^\mathsf T\) and \(Y_j(t)=bV_j(t)^\mathsf T\), redefining them on a null set if necessary. Transposition preserves positivity, so these are measurable positive local matrices. The filtered total trace is one because \(R\) is normalized, and (12) follows. No inverse of \(R\) appears anywhere in the construction. ◻ The canonical purification is convenient for the formula, but it does not restrict the adversary or the ideal comparison law. The following observation will let the secret-bit proof use that formula for every purifying space. Lemma 14 (Recovery from another purifying space). Let \(R\) and \(|\Psi_R\rangle\) be as in Lemma 13, and let \(|\psi\rangle\in A\otimes B\otimes\widetilde E\) be any purification of \(R\). There is a channel \(\mathcal R\) from \(\widetilde E\) to \(E\) that recovers the canonical purification. If Alice and Bob run the same admitted protocol and Eve retains her purification and the full transcript, \(\mathcal R\) acting on the purifying register and the identity acting on the transcript recover the canonical output of Lemma 13. Moreover this channel maps every ideal secret-bit law with Eve in \(\widetilde E T\) to an ideal secret-bit law with Eve in \(ET\). Proof. Let \(\mathcal S=\operatorname{supp}(R^\mathsf T)\subseteq E\). Schmidt decomposition gives an isometry \(V:\mathcal S\to\widetilde E\) with \(|\psi\rangle=(I_{AB}\otimes V)|\Psi_R\rangle\); the canonical vector is supported on \(\mathcal S\) in its purifying factor. Choose any density operator \(\zeta\) on \(E\), and define, with the compression term included into \(E\) from \(\mathcal S\), \[\mathcal R(\xi)=V^*\xi V+ \operatorname{tr}[(I_{\widetilde E}-VV^*)\xi]\,\zeta.\] Compression is CP, as is the positive trace functional followed by preparation of \(\zeta\). Their sum preserves trace, so \(\mathcal R\) is a channel. Its first term inverts \(V\) on the actual purifying support, and the second term vanishes there. Local operations on \(A,B\) keep each conditional purifying state supported in \(\operatorname{ran}V\), and public-source steps act as the identity on that register, so recovery is exact in every transcript and bit branch. The same formula is valid when \(\widetilde E\) is larger than the finite purifying support, acting on trace-class inputs. An ideal bit has the form \(\frac12\sum_{i=0}^1|i,i\rangle\langle i,i|\otimes\sigma\). Applying \(\mathcal R\otimes\mathrm{id}_T\) to its Eve factor replaces \(\sigma\) by another normalized state and leaves that form intact. This includes ideal states with mass outside \(\operatorname{ran}V\). Thus trace-norm contraction transfers any lower bound proved for the canonical output and every canonical ideal law to the output for the arbitrary purification and every ideal law in its larger space. ◻ Separation from an ideal secret bitWe now combine the common factors at a complete transcript with the four-effect inequality. A nearly correct bit has little weight in the \(01\) and \(10\) branches. A nearly uniform secret bit requires Eve’s \(00\) and \(11\) blocks to be close and to carry nearly half the total weight each. Root fidelity makes these two requirements comparable, and the resulting estimates give a uniform numerical gap. Throughout the paper the trace norm is unhalved: \[\left\lVert H\right\rVert_1=\operatorname{tr}\sqrt{H^*H}.\] For a classical standard Borel register with a finite-dimensional quantum register, a state is a positive matrix-valued measure of total trace one. If a Hermitian difference of such measures has density \(H(t)\) with respect to a common finite dominating measure \(\lambda\), its trace norm is \(\int\left\lVert H(t)\right\rVert_1\,d\lambda(t)\). This value is independent of the chosen dominating measure by homogeneity. The usual trace distance between normalized states is one half of this norm. We use trace-norm contraction on Hermitian differences under channels, including classical readouts. In finite dimensions it follows directly from duality: the adjoint of a trace-preserving positive map is unital and positive, so it sends each Hermitian contraction \(Q\), with \(-I\preceq Q\preceq I\), to another Hermitian contraction. Taking the supremum of \(\operatorname{tr}(QH)\) over such \(Q\) proves contraction. The same argument applies to trace-class quantum registers and classical matrix-valued measures through their bounded observables. Definition 15 (Distillable secret key). Let \(\omega\) be a bipartite state, with Eve initially holding a purification. A key-distillation sequence uses an admitted protocol of Definition 12 on each \(\omega^{\otimes n}\), allowing each party to process all its \(n\) copies jointly. The normalized classical output at each party is a string of a fixed length \(\ell_n\in\mathbb Z_{\ge0}\) for that \(n\). Eve’s output register \(E'\) retains the initial purification and the complete public transcript. For any normalized state or classical-quantum law \(\sigma_{E'}\), define the ideal length-\(\ell\) key by \[\gamma^{(\ell)}_\sigma =2^{-\ell}\sum_{z\in\{0,1\}^{\ell}} |z,z\rangle\langle z,z|\otimes\sigma_{E'}.\] The sequence is secure if there are normalized comparison laws \(\sigma_{E'}^{(n)}\) such that \[ \left\lVert\tau^{(n)}_{K_AK_BE'}- \gamma^{(\ell_n)}_{\sigma^{(n)}}\right\rVert_1\longrightarrow0. \tag{17}\] Its asymptotic lower rate is \(\liminf_{n\to\infty}\ell_n/n\). The distillable secret key \(K_D(\omega)\) is the supremum of these rates over secure sequences, including the zero rate obtained by producing the empty key. A positive rate therefore requires \(\ell_n\ge1\) for all sufficiently large \(n\). For positive matrices define the unnormalized root fidelity by \[f(H,J)=\left\lVert\sqrt H\sqrt J\right\rVert_1.\] In particular \(f(cH,cJ)=c f(H,J)\) for \(c\ge0\). The next facts hold at singular matrices as well as invertible ones. The lower comparison is the unnormalized form associated with the Powers–Størmer inequality [50]; for normalized states it is the lower Fuchs–van de Graaf bound [24]. We give the short matrix proof needed at our exact normalization. Lemma 16 (Root fidelity and trace norm). For arbitrary square complex matrices \(A,B\) of the same size, \[ f(A^*A,B^*B)=\left\lVert AB^*\right\rVert_1. \tag{18}\] For positive matrices \(H,J\) of the same size, \[ f(H,J)\ge \frac{\operatorname{tr}H+\operatorname{tr}J-\left\lVert H-J\right\rVert_1}{2}. \tag{19}\] Also \(f(H^\mathsf T,J^\mathsf T)=f(H,J)\). Proof. Extend the partial isometries in the polar decompositions of the square matrices to unitaries, writing \(A=U\sqrt{A^*A}\) and \(B=V\sqrt{B^*B}\). Then \(AB^*=U\sqrt{A^*A}\sqrt{B^*B}V^*\), and unitary invariance of the trace norm proves (18). This extension is available even when either matrix is singular. For (19), put \(A=\sqrt H\), \(B=\sqrt J\), and \(Z=A-B\). The matrix \(Z\) is Hermitian and \(H-J=ZA+BZ\). The spectral sign \(\operatorname{sgn}(Z)\) is a Hermitian contraction. Trace-norm duality and cyclicity therefore give \[\left\lVert H-J\right\rVert_1 \ge\operatorname{tr}[\operatorname{sgn}(Z)(H-J)] =\operatorname{tr}[|Z|(A+B)].\] In a unit eigenvector of \(Z\) with eigenvalue \(z\), positivity of \(A,B\) implies \[\langle A+B\rangle\ge|\langle A-B\rangle|=|z|.\] Summing in an eigenbasis of \(Z\) shows \(\operatorname{tr}[|Z|(A+B)]\ge\operatorname{tr}Z^2\). Finally, \[\operatorname{tr}Z^2=\operatorname{tr}H+\operatorname{tr}J-2\operatorname{tr}(AB), \qquad 0\le\operatorname{tr}(AB)\le\left\lVert AB\right\rVert_1=f(H,J).\] Combining these inequalities proves the lower bound. No commutation of \(H\) and \(J\) was used. For the transpose identity, functional calculus gives \(\sqrt{H^\mathsf T}=(\sqrt H)^\mathsf T\). The product of the two transposed square roots is \((\sqrt J\sqrt H)^\mathsf T\); transpose and adjoint preserve trace norm, proving \(f(H^\mathsf T,J^\mathsf T)=f(H,J)\). ◻ Theorem 17 (Uniform obstruction to a secret bit). Let \(\omega\in\mathscr C\). For every integer \(n\ge1\), let an admitted completed protocol on \(\omega^{\otimes n}\) produce normalized bit registers \(K_A,K_B\), and let its output \(\tau_{K_AK_BE'}\) retain in \(E'\) an initial purification held by Eve and the complete public transcript. The purification may be arbitrary. For every normalized state or classical-quantum law \(\sigma_{E'}\), \[ \left\lVert\tau_{K_AK_BE'}- \frac12\sum_{i=0}^1|i,i\rangle\langle i,i|\otimes\sigma_{E'} \right\rVert_1\ge\frac15. \tag{20}\] Thus the conventional trace distance is at least \(1/10\), and \(K_D(\omega)=0\) in Definition 15. Proof. Group all of Alice’s factors and all of Bob’s factors, and set \(R=\omega^{\otimes n}\). Lemma 8 gives \(R\in\mathscr C\). First apply the classical readout of Eve’s retained complete public transcript, leaving her initial purifying register unchanged, and discard any extra retained registers. On the actual output this produces the full classical transcript together with the purification. On any ideal bit comparison state it produces an ideal bit with a classical-quantum comparison law. Next, Lemma 14 supplies a channel from the retained purifying space to the canonical one, leaving the transcript unchanged. It recovers the actual canonical output and again sends every ideal law to an ideal law. Trace-norm contraction under these Eve-side channels therefore reduces the claim to the canonical purification (11) and the full classical transcript \(T\). Apply Lemma 13 to obtain a finite transcript measure \(\mu\), the positive factors \(X_i(t),Y_j(t)\), and the Eve densities \(\tau_{ij}(t)\) of (12). Fix any normalized positive matrix-valued comparison law \(\sigma_{ET}\) on the same transcript space. Let \(\nu\) be the transcript law of \(\sigma_{ET}\), namely \(\nu(S)=\operatorname{tr}\sigma_{ET}(S)\), and use the common finite measure \(\lambda=\mu+\nu\). If \(h=d\mu/d\lambda\), replace each actual density by \(h(t)\tau_{ij}(t)\) and both \(X_i(t)\) by \(h(t)X_i(t)\), leaving the \(Y_j(t)\) unchanged. Equation (12) then still holds, including where \(h=0\). The ideal law has a positive density \(\sigma(t)\) with respect to \(\lambda\) and \(\int\operatorname{tr}\sigma(t)\,d\lambda(t)=1\). Homogeneity preserves all actual probabilities and root-fidelity integrals in this change of measure. We now denote \(\lambda\) again by \(\mu\). This common measure keeps singular parts of either original transcript law; there is no assumption that the ideal and actual laws have the same support. For these common densities set \[D_{ij}(t)=X_i(t)\otimes Y_j(t),\qquad p_{ij}(t)=\operatorname{tr}\tau_{ij}(t)=\operatorname{tr}[D_{ij}(t)R],\qquad P_{ij}=\int p_{ij}(t)\,d\mu(t).\] All \(P_{ij}\) are nonnegative and \(\sum_{i,j}P_{ij}=1\). With \(A=\sqrt{D_{00}(t)}\sqrt R\) and \(B=\sqrt{D_{11}(t)}\sqrt R\), the transpose invariance and (18) give \[ \begin{aligned} f(\tau_{00}(t),\tau_{11}(t)) &=f\bigl(\sqrt R D_{00}(t)\sqrt R, \sqrt R D_{11}(t)\sqrt R\bigr)\\ &=\left\lVert\sqrt{D_{00}(t)}R\sqrt{D_{11}(t)}\right\rVert_1. \end{aligned} \tag{21}\] The privacy interpretation of an off-diagonal coherence norm as the fidelity of conditional Eve states is also used in the private-state approach [30]. Here the identity is applied to unnormalized branches at each complete transcript. Its proof includes singular \(R\) and singular effects. Apply Lemma 11 at almost every \(t\). Scalar Cauchy–Schwarz after integration gives \[ \begin{split} \mathfrak f &:=\int f(\tau_{00}(t),\tau_{11}(t))\,d\mu(t)\\ &\le\sqrt{P_{00}P_{01}}+\sqrt{P_{10}P_{11}} +2\sqrt{P_{01}P_{10}}. \end{split} \tag{22}\] For example, \(\int\sqrt{p_{00}(t)p_{01}(t)}\,d\mu(t)\) is at most \(\sqrt{P_{00}P_{01}}\). The factors need only be positive; no pointwise POVM normalization was used. We next express what small distance from the fixed ideal bit would require of this same \(\mathfrak f\). Let \(\eta\) be the unhalved trace-norm distance after the common transcript readout, and define \[\begin{split} e&=P_{01}+P_{10},\\ q&=\int\left\lVert\tau_{00}(t)-\tau_{11}(t)\right\rVert_1\,d\mu(t),\\ a_i&=\int\left\lVert\tau_{ii}(t)-\tfrac 12\sigma(t)\right\rVert_1\,d\mu(t) \quad(i=0,1). \end{split}\] The unequal-bit blocks of the ideal state are zero. Additivity of the trace norm across the classical bit blocks, and then the triangle inequality within the two equal-bit blocks, give \[ \eta=e+a_0+a_1,\qquad q\le a_0+a_1=\eta-e. \tag{23}\] Trace conservation gives one further inequality that is needed for the uniform constant. The actual equal-bit blocks have total trace \(1-e\), whereas the corresponding ideal blocks have total trace one. Thus \[a_0+a_1 \ge\left|\sum_{i=0}^1\int \operatorname{tr}\bigl(\tau_{ii}(t)-\tfrac12\sigma(t)\bigr)\,d\mu(t)\right| =e,\] and (23) implies \[ e\le\frac\eta2. \tag{24}\] Integrating (19) gives \[\mathfrak f\ge\frac{P_{00}+P_{11}-q}{2} =\frac{1-e-q}{2}\ge\frac{1-\eta}{2}.\] On the other hand, Cauchy–Schwarz on the first two terms of (22) and the arithmetic–geometric mean inequality on the last give \[\begin{aligned} \sqrt{P_{00}P_{01}}+\sqrt{P_{10}P_{11}} &\le\sqrt{(P_{00}+P_{11})(P_{01}+P_{10})} =\sqrt{e(1-e)},\\ 2\sqrt{P_{01}P_{10}}&\le e. \end{aligned}\] The two estimates have the exact combined form \[ \frac{1-\eta}{2}\le\mathfrak f\le\sqrt{e(1-e)}+e, \qquad e\le\frac\eta2. \tag{25}\] If \(\eta<1/5\), then \(e<1/10\). On \(0\le e\le1/10\) the function \(\sqrt{e(1-e)}+e\) is increasing and has value \(2/5\) at \(e=1/10\). The right side of (25) is therefore strictly less than \(2/5\), while its left side is strictly greater than \(2/5\). This contradiction proves (20), uniformly in \(n\), the represented state, the protocol, and the ideal comparison law. Finally suppose a secure key-distillation sequence had \(\ell_n\ge1\) for infinitely many \(n\). Along those indices, the local classical channels that retain the first bit of each string and discard the other bits, while retaining \(E'\), map \(\gamma^{(\ell_n)}_{\sigma^{(n)}}\) to an ideal bit: exactly half the uniform strings have either first bit. Trace-norm contraction would make the resulting bit-output error tend to zero, contradicting (20). Thus every secure sequence has \(\ell_n=0\) for all sufficiently large \(n\). In particular its asymptotic lower rate is zero. The empty key achieves rate zero, so \(K_D(\omega)=0\). ◻ The proof also yields the retained conditioning and limiting forms of the obstruction. These statements specify how normalization and Eve’s complete information are preserved. Proposition 18 (Conditioning, aborts, and completed-output limits). Consider inputs \(\omega^{\otimes n}\) with \(\omega\in\mathscr C\) and \(n\ge1\), and admitted protocols whose normalized completed outputs retain in Eve’s register an arbitrary initial purification and the complete public transcript. The following statements extend the gap in Theorem 17; in item 2, the completed local output alphabet may include an abort symbol.
Proof. For the first assertion, use the canonical factors from Lemma 13. Restrict their measure \(\mu\) to \(A\) and replace both \(X_0(t),X_1(t)\) by \(X_0(t)/r,X_1(t)/r\), leaving the \(Y_j(t)\) unchanged. Each of the four blocks in (12) is divided by \(r\), and its integral over \(A\) is the corresponding normalized accepted block. All probabilities and the root fidelity scale by the same factor \(1/r\). The accepted total trace is one, so the proof of (25), including \(e\le\eta/2\), applies without change. The recovery and common-measure arguments cover arbitrary purifications and arbitrary ideal laws for the accepted output. No positive lower bound on \(r\) was used. For the second assertion, let \(\delta_k\) be the probability of at least one abort, let \(\tau_k^{\mathrm{ok}}\) be the normalized non-aborting state when \(\delta_k<1\), and let \(\xi_k\) be the normalized state on the aborting part when \(\delta_k>0\). The completed state is the sum of these two positive classical parts with weights \(1-\delta_k\) and \(\delta_k\). Let \(\mathcal Q\) be the product of the two local classical channels sending each party’s own abort symbol to zero and fixing its bit values. It is defined on every completed output and preserves each non-aborting ideal bit \(\gamma_k\). Since the trace-norm distance between normalized states is at most two, \[\left\lVert\mathcal Q(\tau_k)-\gamma_k\right\rVert_1 \le (1-\delta_k)\left\lVert\tau_k^{\mathrm{ok}}-\gamma_k\right\rVert_1 +2\delta_k.\] The right side tends to zero under the stated hypotheses. This contradicts Theorem 17 for the completed bit-output protocol with the local replacement appended. The replacement uses only abort symbols actually available to the respective laboratories. For the third assertion, denote the recovery channel for the \(k\)th embedding by \(\mathcal R_k\). For any ideal bit \(\gamma_\sigma\) in the common space, applying this channel to Eve maps it to the ideal bit \(\gamma_{\mathcal R_k(\sigma)}\) on the \(k\)th output space and recovers \(\tau_k\) from \(\widehat\tau_k\). Contraction and the per-protocol gap therefore give \[\left\lVert\widehat\tau_k-\gamma_\sigma\right\rVert_1 \ge\left\lVert\tau_k-\gamma_{\mathcal R_k(\sigma)}\right\rVert_1 \ge\frac15.\] The triangle inequality now yields \[\left\lVert\tau-\gamma_\sigma\right\rVert_1 \ge\frac15-\left\lVert\widehat\tau_k-\tau\right\rVert_1 \longrightarrow\frac15.\] Only the completed actual outputs need converge. The embeddings must retain and permit recovery of the full purification and public records, so they do not coarse-grain that information. The argument requires no convergence on the auxiliary probe inputs and no factorization statement for the limit itself. In particular, it does not assume that finite padded transcript laws converge in trace norm to a law of an infinite transcript. ◻ Tensor geometry from singular directionsWe now construct the PPT pair in Theorem 2. The geometric step uses a map on \(M_{4}(\mathbb C)\) with twenty specified singular outputs. It turns each singular output into a product vector in the kernel of a Choi matrix on \(\mathbb C^{10}\otimes\mathbb C^{10}\). A condition on quadratic evaluations then excludes product vectors from the range. For a vector \(x\), write \(P_x=xx^*\), without normalizing it. A projective direction \([x]\) is the complex line spanned by a nonzero vector \(x\). Proposition 19 (Tensor criterion). Let \(L:M_{4}(\mathbb C)\to M_{4}(\mathbb C)\) be PPT. Suppose that \(\mathcal X=\{x_1,\ldots,x_{20}\}\subset\mathbb C^4\setminus\{0\}\) represents twenty distinct projective directions and has the following properties:
Then there are PPT maps \(\Phi_1,\Phi_2:M_{10}(\mathbb C)\to M_{10}(\mathbb C)\), constructed explicitly from \(L\), such that \[Z=J(\Phi_2\circ\Phi_1)\ne0,\qquad \operatorname{ran}Z\cap\{u\otimes v:u,v\in\mathbb C^{10}\}=\{0\}.\] In particular, \(\Phi_2\circ\Phi_1\) is not entanglement breaking. Section 7 supplies an integer construction of \(L\) with these properties. We prove the criterion by using the symmetric square to record quadratic monomials and the exterior square to detect rank loss. Proof. Symmetric and exterior tensors. Index an orthonormal basis of \(\mathbb C^{10}\) by pairs \(0\leq i\leq j<4\), and an orthonormal basis of \(\mathbb C^6\) by pairs \(0\leq i<j<4\), both in lexicographic order. Define isometries \(U:\mathbb C^{10}\to\mathbb C^4\otimes\mathbb C^4\) and \(V:\mathbb C^6\to\mathbb C^4\otimes\mathbb C^4\) by \[\begin{align*} Ue_{ii}&=e_i\otimes e_i,& Ue_{ij}&=\frac{e_i\otimes e_j+e_j\otimes e_i}{\sqrt2}\quad(i<j), \\ Ve_{ij}&=\frac{e_i\otimes e_j-e_j\otimes e_i}{\sqrt2}\quad(i<j). \tag{26}\end{align*}\] Their ranges are the symmetric and antisymmetric tensor subspaces. Put \[ \widehat x=U^*(x\otimes x) =\sum_i x_i^2e_{ii}+\sqrt2\sum_{i<j}x_ix_je_{ij} \qquad(x\in\mathbb C^4). \tag{27}\] Thus \(U\widehat x=x\otimes x\) and \(UP_{\widehat x}U^*=P_x\otimes P_x\). The coordinates of \(\widehat x\) are the ten quadratic monomials with nonzero normalization factors. Hence the quadratic hypothesis is equivalent to the assertion that any ten vectors among \(\{\widehat x:x\in\mathcal X\}\) span \(\mathbb C^{10}\): a failure to span would give a nonzero vector \(u\) with \(u^*\widehat x=0\) at those ten points, and \(u^*\widehat x\) is a nonzero homogeneous quadratic. Identify \(\mathbb C^6\) with \(\bigwedge^2\mathbb C^4\) by \(e_{ij}=e_i\wedge e_j\), with this basis orthonormal. Under this identification, \[V(a\wedge b)=\frac{a\otimes b-b\otimes a}{\sqrt2}.\] For \(i<j\), let \(k<l\) be the complementary indices, and let \(\epsilon_{ijkl}\) be the sign of the ordering \((i,j,k,l)\) of \((0,1,2,3)\). Define the real signed permutation \(K\) on \(\mathbb C^6\) by \[ Ke_{ij}=\epsilon_{ijkl}e_{kl}. \tag{28}\] Explicitly, \[(Ke_{01},Ke_{02},Ke_{03},Ke_{12},Ke_{13},Ke_{23}) =(e_{23},-e_{13},e_{12},e_{03},-e_{02},e_{01}),\] so \(K=K^*=K^{-1}\). The conjugate operation \(w\mapsto K\overline w\) is the complementary-pair exterior dual also used by Schliemann, Loss, and MacDonald for two fermions in a four-dimensional one-particle space [55]. Define \(S,R:M_{10}(\mathbb C)\to M_{6}(\mathbb C)\) by \[ S(A)=V^*(L\otimes L)(UAU^*)V,\qquad R(A)=K\,S(A)^{\mathsf T}K^*. \tag{29}\] The embeddings and compressions are CP, so Lemma 4 makes \(S\) PPT. The map \(T_6\circ S\) is CP by this PPT property, and its output transpose is \(S\), which is CP. Thus \(T_6\circ S\) is PPT, and the CP conjugation by \(K\) makes \(R\) PPT. The composite Choi matrix. The rectangular maps give an endomorphism \(R^\dagger\circ S\circ T_{10}\) of \(M_{10}(\mathbb C)\). To express it as the composition of two maps on that algebra, let \(E:\mathbb C^6\to\mathbb C^{10}\) be the real coordinate inclusion into the first six positions and define \[ \Phi_1(A)=E\,S(A^{\mathsf T})E^*,\qquad \Phi_2(B)=R^\dagger(E^*BE). \tag{30}\] For \(\Phi_1\), Lemma 4 makes \(S\circ T_{10}\) CP by input/output transpose equivalence, and makes its output transpose \(T_6\circ S\circ T_{10}\) CP by simultaneous transposition of \(S\). Thus \(S\circ T_{10}\) is PPT, and the CP embedding by \(E\) preserves that property. The adjoint and CP-composition clauses of the same lemma make \(\Phi_2\) PPT. The formulas determine both maps explicitly once \(L\) is given. For example, if \(L(A)=\sum_r Q_rAQ_r^*\), the adjoints in the construction are \[\begin{align*} L^\dagger(Y)&=\sum_r Q_r^*YQ_r,\\ S^\dagger(Y)&=U^*(L^\dagger\otimes L^\dagger)(VYV^*)U,\\ R^\dagger(Y)&=S^\dagger\bigl((K^*YK)^{\mathsf T}\bigr). \end{align*}\] Since \(E^*E=I_6\), \(\Phi_2\circ\Phi_1=R^\dagger\circ S\circ T_{10}\). Its Choi matrix \(Z\) is positive. The convention (3) gives, for arbitrary matrices \(a,b\) of the appropriate sizes, \[\operatorname{tr}\bigl[(a\otimes b)J(F)\bigr]=\operatorname{tr}\bigl[bF(a^{\mathsf T})\bigr].\] For Hermitian \(a,b\in M_{10}(\mathbb C)\), the Hilbert–Schmidt adjoint identity therefore gives \[ \operatorname{tr}\bigl[(a\otimes b)Z\bigr] =\operatorname{tr}\bigl[bR^\dagger(S(a))\bigr] =\operatorname{tr}\bigl[R(b)S(a)\bigr]. \tag{31}\] The Choi transpose has canceled the input transpose in (30). We will prove that the right side vanishes at \(a=b=P_{\widehat x}\) for each singular direction. Positivity of \(Z\) will then give the kernel vector \(\widehat x\otimes\widehat x\). The positive definite output will separately show that \(Z\) is nonzero. Singular outputs and kernel products. For any operator \(B\) on \(\mathbb C^4\), \[V^*(B\otimes B)V=\bigwedge\nolimits^2B.\] Both sides send \(a\wedge b\) to \(Ba\wedge Bb\). If \(B_x=L(P_x)\succeq0\) and \(W_x=\operatorname{ran}B_x\), it follows that \[ S(P_{\widehat x})=\bigwedge\nolimits^2B_x,\qquad \operatorname{ran}S(P_{\widehat x})=\bigwedge\nolimits^2W_x. \tag{32}\] Indeed, in an orthonormal eigenbasis of \(B_x\), the exterior eigenvalues are \(\lambda_i\lambda_j\) for \(i<j\). This proves both positivity and the range identity. A Hermitian matrix \(D\) satisfies \(D^{\mathsf T}=\overline D\), so transposition conjugates its range. Consequently \[ \operatorname{ran}R(P_{\widehat x})=K\overline{\bigwedge\nolimits^2W_x}. \tag{33}\] For exterior two-vectors \(w,u\), let \([w\wedge u]_{0123}\) denote the coefficient of \(e_0\wedge e_1\wedge e_2\wedge e_3\). With the Hermitian inner product conjugate-linear in its first argument, the definition of \(K\) gives \[ \langle K\overline w,u\rangle =\sum_{i<j}w_{ij}\epsilon_{ijkl}u_{kl} =[w\wedge u]_{0123}. \tag{34}\] Here \(k<l\) is complementary to \(i<j\) in each term. If \(w,u\in\bigwedge^2W\) and \(\dim W<4\), then \(w\wedge u\in\bigwedge^4W=0\). Equations (32)–(34) show that \(S(P_{\widehat x})\) and \(R(P_{\widehat x})\) have orthogonal ranges for every \(x\in\mathcal X\). This includes \(\dim W_x<2\), when both exterior ranges are zero. The conjugation in (34) is essential for this conclusion over complex subspaces. For \(x\in\mathcal X\), orthogonality of the two positive output ranges gives \[(\widehat x\otimes\widehat x)^*Z(\widehat x\otimes\widehat x) =\operatorname{tr}\bigl[R(P_{\widehat x})S(P_{\widehat x})\bigr]=0.\] For a positive matrix, \(v^*Zv=0\) implies \(Zv=0\). Hence \[ \widehat x\otimes\widehat x\in\ker Z\qquad(x\in\mathcal X). \tag{35}\] For the input \(y\) in the second hypothesis, \(S(P_{\widehat y})=\bigwedge^2(L(P_y))\) is positive definite, and so is \(R(P_{\widehat y})=K S(P_{\widehat y})^{\mathsf T}K^*\). The trace of their product is strictly positive. Equation (31) at \(a=b=P_{\widehat y}\) therefore proves \(Z\ne0\). Excluding product vectors from the range. It remains to exclude a product vector from the range. The following zero-set argument uses the product-exclusion principle of Bennett and coauthors [10], in the nonorthogonal form given by Pittenger [49], and is related to Parthasarathy’s polynomial interpolation construction [45]. Suppose that a nonzero product \(u\otimes v\) belongs to \(\operatorname{ran}Z\). Since \(Z\) is Hermitian, its range is the orthogonal complement of its kernel. Equation (35) implies \[p_u(x)p_v(x)=0\quad(x\in\mathcal X),\qquad p_u(x)=u^*\widehat x,\quad p_v(x)=v^*\widehat x.\] For example, \[p_u(x)=\sum_i\overline{u_{ii}}x_i^2 +\sqrt2\sum_{i<j}\overline{u_{ij}}x_ix_j.\] This is a homogeneous quadratic in \(x\); only its fixed coefficients are conjugated. Its distinct monomials make it nonzero when \(u\ne0\). The same holds for \(p_v\), since \(v\ne0\). Each polynomial therefore vanishes on at most nine members of \(\mathcal X\). Their zero sets cannot cover all twenty members, because \(9+9<20\). This contradiction proves that \(\operatorname{ran}Z\) contains no nonzero product vector. By Lemma 6, the nonzero positive matrix \(Z\) is nonseparable. Lemma 5 then shows that the composite is not entanglement breaking. ◻ An integer pencil and its exact certificateThis section verifies every hypothesis of Proposition 19 for an explicit map \(L:M_{4}(\mathbb C)\to M_{4}(\mathbb C)\). Four integer \(6\)-by-\(4\) matrices \(M_0,\ldots,M_3\) define \(L\) and the pencil \(M(x)=\sum_{i=0}^3x_iM_i\). The maximal minors of this pencil identify all singular projective directions. Exact reductions at three primes, together with the quotient and Galois arguments below, control quadratic evaluations on every ten of those directions. The explicit matrix pencilUse indices \(0,1,2,3\) and define real \(6\)-by-\(4\) matrices \[ \begin{aligned} M_0&=\begin{pmatrix} 6&0&0&0\\0&6&0&0\\0&0&6&0\\0&0&0&6\\0&0&0&0\\0&0&0&0 \end{pmatrix},& M_1&=\begin{pmatrix} -12&0&0&0\\0&-6&0&0\\0&0&6&0\\0&0&0&12\\-6&0&6&6\\-6&-6&6&0 \end{pmatrix},\\[2mm] M_2&=\begin{pmatrix} 0&6&-2&0\\6&6&0&2\\-2&0&10&0\\0&2&0&24\\0&0&0&6\\0&-6&6&-6 \end{pmatrix},& M_3&=\begin{pmatrix} 0&0&-4&-3\\0&-2&-3&-4\\-4&-3&11&6\\-3&-4&6&25\\6&6&0&0\\0&-6&6&6 \end{pmatrix}. \end{aligned} \tag{36}\] For \(x=(x_0,x_1,x_2,x_3)\in\mathbb C^4\), put \(M(x)=\sum_{i=0}^3x_iM_i\) and define the complex-linear map \(L\) on matrix units by \[ L(E_{ij})=M_i^{\mathsf T}M_j\qquad(0\leq i,j<4). \tag{37}\] Lemma 20. The map \(L:M_{4}(\mathbb C)\to M_{4}(\mathbb C)\) in (37) is PPT. For every \(x\in\mathbb C^4\), \[ L(P_x)=M(x)^{\mathsf T}\overline{M(x)}=M(x)^*M(x),\qquad \operatorname{rank}L(P_x)=\operatorname{rank}M(x). \tag{38}\] Moreover, \(L(P_{e_0})=36I_4\). Proof. Direct integer multiplication gives \[ M_i^{\mathsf T}M_j=M_j^{\mathsf T}M_i\qquad(0\leq i,j<4). \tag{39}\] The exact checker in Appendix 11 verifies these equalities. For each row \(r\), let \(Q_r\) be the \(4\)-by-\(4\) matrix whose \(i\)th column is the transpose of row \(r\) of \(M_i\). Comparing entries gives \(L(A)=\sum_{r=1}^6Q_rAQ_r^*\), so \(L\) is CP. Equation (39) also makes every \(M_i^{\mathsf T}M_j\) symmetric. Therefore \(T_4\circ L=L\), proving the PPT property. For complex \(x\), expansion of (37) gives \[L(P_x)=\sum_{i,j}x_i\overline{x_j}M_i^{\mathsf T}M_j =M(x)^{\mathsf T}\overline{M(x)}.\] Interchanging \(i,j\) and using (39) gives the second expression in (38). Since \(v^*M(x)^*M(x)v=\left\lVert M(x)v\right\rVert^2\), the kernel of this Gram matrix is \(\ker M(x)\), which proves the rank equality. Finally, \(M_0^{\mathsf T}M_0=36I_4\). ◻ The positive-definite input required by the tensor criterion is now available. The remaining assertion concerns every complex rank-loss direction of the pencil. Proposition 21 (Twenty rank-loss directions with independent quadratic evaluations). The projective directions \([x]\in\mathbb P^3(\mathbb C)\) for which \(\operatorname{rank}M(x)<4\) consist of exactly twenty distinct points. Each has a unique representative \(x=(1,t_1,t_2,t_3)\). Every nonzero homogeneous quadratic in \(\mathbb C[x_0,x_1,x_2,x_3]\) vanishes on at most nine of these representatives. The equation \(M(x)y=0\) with \(x,y\ne0\) is related to the bilinear kernel geometry studied by Hansen, Hauge, Myrheim, and Sollid for \(4\)-by-\(4\) PPT states whose matrix and partial transpose both have rank six [27]. Their generic count concerns twenty product rays \(x\otimes y\). The quadratic condition here concerns the vectors \(x\otimes x\) for this specific pencil, and the following argument proves it from exact data. Proof of Proposition 21. The maximal-minor relations first show that the affine quotient is nonzero and spanned by twenty monomials. We then construct a formal multiplication matrix. Its irreducible characteristic polynomial, certified modulo \(41\), proves that the spanning monomials are independent and that the quotient is a degree-twenty field. This identifies all twenty complex directions. Finally, reductions at \(131\) and \(139\) give the full symmetric Galois action, which transports one independent set of ten quadratic evaluations to every such set. The three general algebraic facts used along the way are stated at their uses; their proofs are collected in Appendix 11.2. The checker in Appendix 11 supplies the integer block identities and the finite modular data used in these stages. It does not enumerate the twenty complex directions or their ten-point determinants. The quotient, projective, and Galois deductions are proved below. The maximal minors and a nonzero quotientBecause \(M(x)\) has four columns, the condition \(\operatorname{rank}M(x)<4\) is equivalent to simultaneous vanishing of its fifteen maximal minors. For each four-element subset \(\rho\subset\{1,\ldots,6\}\), taken in lexicographic order with its rows in increasing order, let \(\Delta_\rho(x)\) be the determinant of those rows of \(M(x)\). Put \(p_\rho(t)=\Delta_\rho(1,t_1,t_2,t_3)\) and define \[I=(p_\rho)_\rho\subset\mathbb Q[t_1,t_2,t_3],\qquad \mathcal A=\mathbb Q[t_1,t_2,t_3]/I.\] These equations describe the singular directions in the chart \(x_0=1\). We have not yet proved that \(I\) is proper, or that this chart contains all the singular directions. Order monomials first by increasing total degree \(d\) and, within degree \(d\), by the exponent triples \[ (a,b,d-a-b),\qquad a=0,\ldots,d,\quad b=0,\ldots,d-a, \tag{40}\] in the displayed nested order. Let \(v\) be the column of the twenty monomials of degree at most three, and let \(w\) be the column of the fifteen monomials of degree four. The coefficients of the minors define integer matrices \(D,H\) by \[ (p_\rho(t))_\rho=Dv(t)+Hw(t),\qquad D\in\mathbb Z^{15\times20},\quad H\in\mathbb Z^{15\times15}. \tag{41}\] The exact coefficient calculation in Appendix 11 gives \(\det H\equiv40\pmod{41}\), so \(H\) is invertible over \(\mathbb Q\). Define \(C=-H^{-1}D\). In the quotient \(\mathcal A\), Equation (41) gives the relations \(w=Cv\), expressing each degree-four monomial as a linear combination of the twenty lower monomials. The relations \(w=Cv\) must describe a nonzero quotient before they can be used to count its points. We first verify this and show that the low monomials span. The existence argument uses the following intersection fact for \(\mathbb P^3\times\mathbb P^3\). Lemma 22 (Six bilinear equations). Any six complex bilinear forms on \(\mathbb C^4\times\mathbb C^4\) have a common zero \((x,y)\) with \(x\ne0\) and \(y\ne0\). The proof is given in Appendix 11.2. Apply the lemma to the six rows of \(M(x)y\). It gives \(x,y\ne0\) with \(M(x)y=0\), so all \(\Delta_\rho(x)\) vanish. The homogeneous degree-four part of \(p_\rho(t)\) is \(\Delta_\rho(0,t_1,t_2,t_3)\). Equation (41) therefore gives \[\bigl(\Delta_\rho(0,t)\bigr)_\rho=Hw(t).\] If a common zero had \(x_0=0\), invertibility of \(H\) would imply \(w(t)=0\). The entries \(t_1^4,t_2^4,t_3^4\) occur in \(w\), so \(t=0\), contradicting \(x\ne0\). Thus every projective common zero lies in the chart \(x_0=1\). Rescaling the zero furnished by the lemma gives an affine common zero of the \(p_\rho\), proving that \(I\) is proper and \(\mathcal A\ne0\). The same argument has excluded all points at infinity. In \(\mathcal A\), the relations \(w=Cv\) show that the twenty low monomials span. In a monomial of total degree at least four, substitute for any degree-four factor. Each resulting term has strictly smaller total degree. Induction reduces every monomial to a linear combination of the low monomials; this proves spanning without assuming unique reductions. A formal multiplication operatorMultiplication matrices are a standard way to encode finite polynomial systems; see Sottile [57]. The quotient \(\mathcal A\) is now known to be nonzero and spanned by the twenty low monomials, but their independence remains to be proved. Take a formal twenty-dimensional rational vector space with basis \(e_\alpha\) indexed by exponent triples \(|\alpha|\leq3\), in the order (40). Define an endomorphism \(N\) of this formal space and its characteristic polynomial by \[ Ne_\alpha= \begin{cases} e_{\alpha+(1,0,0)},&|\alpha|\leq2,\\[1mm] \displaystyle\sum_{|\beta|\leq3} C_{\alpha+(1,0,0),\beta}e_\beta,&|\alpha|=3, \end{cases} \qquad f(z)=\det(zI_{20}-N). \tag{42}\] The row index of \(C\) in the second line is the indicated degree-four monomial. Let \(\pi:\mathbb Q^{20}\to\mathcal A\) send \(e_\alpha\) to the class of \(t^\alpha\), and let \(\mu_1\) be multiplication by the class of \(t_1\). The spanning result makes \(\pi\) surjective. By the definition of \(N\), \[ \pi N=\mu_1\pi. \tag{43}\] In particular, \(\ker\pi\) is an \(N\)-invariant rational subspace. We will use irreducibility of \(f\) to show that this kernel is zero, which will identify \(N\) with multiplication by \(t_1\). For a prime \(p\) with \(\det H\not\equiv0\pmod p\), set \[\mathbb Z_{(p)}=\{a/b:a,b\in\mathbb Z,\ p\nmid b\}.\] The identity \(H^{-1}=\operatorname{adj}(H)/\det H\) shows that the entries of \(C,N\) and the coefficients of the monic polynomial \(f\) lie in \(\mathbb Z_{(p)}\). In particular their denominators are units at \(p\), and reduction gives \(\overline f=\det(zI_{20}-\overline N)\in\mathbb F_p[z]\). This is a statement of integrality at the specified prime; no global integrality of the coefficients of \(f\) is needed. For \(k\geq1\), put \[d_p(k)=\deg\gcd(\overline f,z^{p^k}-z).\] The exact calculation in Appendix 11 gives the computed columns of Table 1. Its output also records all twenty-one characteristic coefficients and all twenty gcd degrees at each prime.
The determinant residues justify all three local reductions. The primes exceed twenty, so the divisions in the Newton identities used to compute the characteristic polynomials are valid. Their primality follows by trial division by the primes at most eleven. We explain the last column of the table. Over \(\mathbb F_p\) the polynomial \(z^{p^k}-z\) is squarefree, since its derivative is \(-1\). Its irreducible factors are precisely the monic irreducible polynomials whose degrees divide \(k\): a root of an irreducible polynomial of degree \(s\) has a Frobenius orbit of length \(s\). Hence \(d_p(k)\) is the sum of the degrees of the distinct irreducible factors of \(\overline f\) whose degrees divide \(k\). At \(p=41\), a factor of degree \(s<20\) would make \(d_{41}(s)\) positive, so \(\overline f\) is irreducible of degree twenty. At \(p=131\), the three displayed values force one factor of degree one, one of degree two, and one of degree seventeen. These degrees already sum to twenty, so there are no further or repeated factors. The two values at \(p=139\) similarly force one factor of degree one and one of degree nineteen, without repetition. All three reductions are squarefree. The following elementary reduction lemma lets us infer rational irreducibility without assuming that \(f\) has integer coefficients. Its \(p\)-adic form is used in the proof of Lemma 24 in Appendix 11.2. Lemma 23 (Monic local reduction). Let \(p\) be a prime, and let the coefficient field and its valuation ring be one of the pairs \[(\mathbb L,R_p)=(\mathbb Q,\mathbb Z_{(p)}) \quad\text{or}\quad (\mathbb L,R_p)=(\mathbb Q_p,\mathbb Z_p).\] If a monic polynomial \(P\in R_p[z]\) factors as \(P=gh\) with monic \(g,h\in\mathbb L[z]\), then \(g,h\in R_p[z]\), and their reductions modulo \(p\) retain their degrees, including degree zero. Consequently, if \(P\) has positive degree and irreducible reduction in \(\mathbb F_p[z]\), then \(P\) is irreducible over \(\mathbb L\). The proof is given in Appendix 11.2. Applying the lemma to \(f\in\mathbb Z_{(41)}[z]\) and its irreducible reduction proves that \(f\) is irreducible over \(\mathbb Q\). The coordinate field and its twenty pointsWe can now prove independence of the twenty spanning monomials. An endomorphism with irreducible characteristic polynomial has no nonzero proper invariant subspace: a basis adapted to such a subspace makes the matrix block triangular and factors its characteristic polynomial into those of the restriction and quotient. Since \(\pi\) is surjective and \(\mathcal A\ne0\), its kernel is proper. Irreducibility of \(f\) forces \(\ker\pi=0\). The twenty low monomials are therefore a basis of \(\mathcal A\), and \(N\) is its multiplication matrix for \(t_1\). By Cayley–Hamilton the minimal polynomial of \(N\) divides \(f\). It is nonconstant, so irreducibility of \(f\) makes it equal to \(f\). In a nonzero unital algebra, a polynomial in an element vanishes exactly when the same polynomial in its multiplication operator vanishes; the reverse implication follows by applying the operator to \(1\). Hence the subalgebra generated by \(t_1\) is \(\mathbb Q[z]/(f)\) and has dimension twenty. It is already all of \(\mathcal A\): \[ \mathcal A\simeq\mathbb Q[z]/(f),\qquad z\longmapsto t_1. \tag{44}\] In particular \(\mathcal A\) is a field. Write the classes of \(t_2,t_3\) as \(h_2(t_1),h_3(t_1)\) with \(h_2,h_3\in\mathbb Q[z]\) of degree below twenty. The irreducible polynomial \(f\) is separable in characteristic zero. Let its distinct complex roots be \(\lambda_1,\ldots,\lambda_{20}\). Extending scalars in (44) and applying the Chinese remainder theorem gives \[ \mathbb C[t_1,t_2,t_3]/I\mathbb C[t_1,t_2,t_3] \simeq\mathbb C[z]/(f)\simeq\prod_{j=1}^{20}\mathbb C. \tag{45}\] The factors are evaluations at the distinct triples \[ t^{(j)}=(\lambda_j,h_2(\lambda_j),h_3(\lambda_j)). \tag{46}\] Conversely, any complex common zero of the \(p_\rho\) defines a unital \(\mathbb C\)-algebra homomorphism from the left side of (45) to \(\mathbb C\), and such a homomorphism selects one factor of the product. Thus the triples in (46) are all the affine common zeros. The product of fields also shows that the complex ideal is radical, so these twenty points are reduced. Together with the exclusion of \(x_0=0\), this identifies all complex projective singular directions of the pencil. Local Frobenius and quadratic evaluationsIt remains to prove that no nonzero quadratic vanishes on ten of the directions. We will show that the Galois group of the splitting field permutes the twenty roots arbitrarily. This transports independence for one set of ten evaluations to every set of ten. The following is the locally integral form of the Frobenius factorization principle, often called Dedekind’s theorem. Milne states the monic integer case [43]. We give the local rational argument needed for the coefficients of \(f\). Lemma 24 (Locally integral Frobenius). Let \(F\in\mathbb Q[z]\) be monic, separable, and of positive degree, with coefficients in \(\mathbb Z_{(p)}\). If its reduction in \(\mathbb F_p[z]\) is squarefree with irreducible-factor degrees \(s_1,\ldots,s_h\), then the Galois group of its rational splitting field contains an element with cycle lengths \(s_1,\ldots,s_h\) on the roots. The proof is given in Appendix 11.2. Let \(\mathbb K\subset\mathbb C\) be a splitting field of \(f\), and let \(G=\operatorname{Gal}(\mathbb K/\mathbb Q)\) act on its twenty roots. Applying Lemma 24 to the reductions at \(131\) and \(139\) gives elements of cycle types \((1,2,17)\) and \((1,19)\). Irreducibility of \(f\) makes this action transitive. A nineteen-cycle fixes one root and is transitive on the other nineteen, so the stabilizer of that root is transitive on its complement. Transitivity conjugates this property to every point stabilizer; hence \(G\) is transitive on ordered pairs of distinct roots, or two-transitive. The seventeenth power of an element of type \((1,2,17)\) is a transposition. Two-transitivity sends its two entries to any ordered pair, and conjugation therefore gives every transposition. Thus \[ G=S_{20}. \tag{47}\] This is the elementary permutation criterion recorded in Milne [43]. The group in (47) is the splitting-field group acting on the twenty roots. Form the \(20\)-by-\(10\) evaluation matrix over \(\mathbb K\) \[\mathcal E_{j,\alpha}=(t^{(j)})^\alpha,\qquad 1\leq j\leq20,\quad |\alpha|\leq2.\] Its entries lie in \(\mathbb K\) by (46). The ten column monomials belong to the basis of \(\mathcal A\) already proved above. They remain independent after scalar extension to \(\mathbb K\), where the split algebra is \(\mathbb K^{20}\) through evaluation at the twenty triples. Hence \(\mathcal E\) has column rank ten over \(\mathbb K\), so some ten-row square submatrix has nonzero determinant. Every \(\sigma\in G\) permutes the triples in (46) according to its permutation of the roots, since \(h_2,h_3\) have rational coefficients. In particular \(\sigma(\mathcal E_{j,\alpha})=\mathcal E_{\sigma(j),\alpha}\). The group \(S_{20}\) is transitive on ten-element subsets. Applying a suitable \(\sigma\) to the known nonzero determinant therefore gives, up to a row-order sign, the determinant for any prescribed ten rows. A field automorphism preserves nonzero elements, so every such determinant is nonzero in \(\mathbb K\) and hence in \(\mathbb C\). The Galois action has been used only on algebraic determinants; their nonvanishing gives invertibility for arbitrary complex coefficient vectors. Every homogeneous quadratic has a unique expression \[q(x_0,x_1,x_2,x_3)=\sum_{|\alpha|\leq2} a_\alpha x_0^{2-|\alpha|} x_1^{\alpha_1}x_2^{\alpha_2}x_3^{\alpha_3}.\] Its dehomogenization \(q(1,t)\) is nonzero exactly when \(q\) is nonzero. If it vanished at ten triples, the corresponding invertible evaluation matrix would force every \(a_\alpha=0\). Thus it vanishes on at most nine triples. The identification of all common zeros above, the exclusion of \(x_0=0\), and the equivalence between vanishing of the maximal minors and \(\operatorname{rank}M(x)<4\) now prove Proposition 21. ◻ Proof of Theorem 2. Take \(L\) from (37). Lemma 20 supplies its PPT property, the rank identity, and the positive-definite input \(L(P_{e_0})=36I_4\). Proposition 21 supplies the twenty distinct directions and the quadratic bound. Proposition 19 therefore applies, with the explicit maps in (30) determined by the integer matrices (36). The positive test also gives an exact nonzero Choi value. Since \(\widehat{e_0}=e_{00}\), Equations (29) and (31) yield \[S(P_{e_{00}})=R(P_{e_{00}})=36^2I_6,\qquad (e_{00}\otimes e_{00})^*Z(e_{00}\otimes e_{00}) =6\cdot36^4=10{,}077{,}696>0.\] Thus the constructed pair has the asserted nonzero product-free composite Choi range, and its composite is not entanglement breaking. ◻ The state and a trace-preserving channelWe now combine the two independent inputs to the main state theorem: the operational obstruction for the represented class and the product-free Choi range of the explicit dimension-ten pair. Proof of Theorem 1. Take \(\Phi_1,\Phi_2\) from (30) and put \(Z=J(\Phi_2\circ\Phi_1)\). Theorem 2 proves that \(Z\) is nonzero and that its range contains no nonzero product vector. It is positive because \(\Phi_2\circ\Phi_1\) is CP. Thus \(\lambda=\operatorname{tr}Z>0\), and \(\rho=Z/\lambda\) is a density operator on \(\mathbb C^{10}\otimes\mathbb C^{10}\) with the same range as \(Z\). Lemma 6 makes \(\rho\) entangled. Both maps are PPT. Lemma 9, with \(a=b=c=10\), gives \[\rho=(\Phi_1^\sharp\otimes\Phi_2) \left(\frac{\Omega_{10}\Omega_{10}^*}{\lambda}\right) \in\mathscr C.\] In particular, the representing vector is \(\Omega_{10}/\sqrt{\lambda}\); normalization is by the actual Choi trace. Theorem 17 now gives (1) for every \(n\geq1\) and every protocol and ideal bit in its stated scope, including the purification and complete public record. The same theorem gives \(K_D(\rho)=0\). All matrices defining \(\rho\) are specified by (36) and (30), so the state is explicit. ◻ The maps \(\Phi_1,\Phi_2\) need not preserve trace. The next proposition converts any square PPT pair into a trace-preserving PPT channel, while retaining the pair’s composite Choi matrix in a local corner. The two-block switch follows Christandl, Müller-Hermes, and Wolf [16]. The enlarged-input absorbing flag follows Filippov’s trace-preserving extension [21]. Proposition 25. Let \(\Psi_1,\Psi_2:M_{m}(\mathbb C)\to M_{m}(\mathbb C)\) be PPT maps. There are explicitly defined constants \(c_1,c_2>0\), a trace-preserving PPT channel \(\Theta:M_{2m+1}(\mathbb C)\to M_{2m+1}(\mathbb C)\), and a real coordinate isometry \(W_0:\mathbb C^m\to\mathbb C^{2m+1}\) such that \[ (W_0^*\otimes W_0^*)J(\Theta\circ\Theta)(W_0\otimes W_0) =c_1c_2J(\Psi_2\circ\Psi_1). \tag{48}\] If \(J(\Psi_2\circ\Psi_1)\) is nonseparable, then \(\Theta\circ\Theta\) is not entanglement breaking. Proof. Define \[ A_i=\Psi_i^\dagger(I_m),\qquad c_i=\frac{1}{1+\operatorname{tr}A_i},\qquad F_i=I_m-c_iA_i \quad (i=1,2). \tag{49}\] The adjoint of a CP map is CP, so \(A_i\succeq0\). Since \(A_i\preceq(\operatorname{tr}A_i)I_m\), we have \(F_i\succeq(1-c_i\operatorname{tr}A_i)I_m=c_iI_m\succ0\). The adjoint identity, using that \(A_i\) is Hermitian, gives \[\operatorname{tr}\Psi_i(B)=\operatorname{tr}(A_iB),\qquad \operatorname{tr}B-c_i\operatorname{tr}\Psi_i(B)=\operatorname{tr}(F_iB)\] for every complex matrix \(B\). Hence \(c_i\Psi_i\) is trace nonincreasing on positive inputs, and the positive effect \(F_i\) records the missing trace. Use the standard-coordinate decomposition \[\mathbb C^{2m+1}=\mathbb C^m_0\oplus\mathbb C^m_1\oplus\mathbb Ce_\star,\] and let \(W_0,W_1\) be the real coordinate inclusions. For \(X\in M_{2m+1}(\mathbb C)\) write \(X_{jj}=W_j^*XW_j\), \(x_\star=e_\star^*Xe_\star\), and \(P_\star=e_\star e_\star^*\). Set \[\begin{align*} \Theta(X)={}&c_2W_0\Psi_2(X_{11})W_0^* +c_1W_1\Psi_1(X_{00})W_1^* \\ &+\bigl(\operatorname{tr}(F_1X_{00})+\operatorname{tr}(F_2X_{11})+x_\star\bigr)P_\star . \tag{50}\end{align*}\] The formula discards the off-diagonal input blocks. The two moving branches are CP compositions. For the flag branches, take spectral decompositions \(F_i=\sum_r\lambda_{ir}v_{ir}v_{ir}^*\) and set \[K_{ir}=\sqrt{\lambda_{ir}}\,e_\star v_{ir}^*W_{i-1}^* \quad(i=1,2).\] Then \(\operatorname{tr}(F_iX_{i-1,i-1})P_\star=\sum_r K_{ir}XK_{ir}^*\). The remaining flag term is \(P_\star XP_\star\). Thus \(\Theta\) is CP. Since \(c_iA_i+F_i=I_m\), for every complex \(X\), \[\begin{align*} \operatorname{tr}\Theta(X) &=\operatorname{tr}\bigl[(c_1A_1+F_1)X_{00}\bigr] +\operatorname{tr}\bigl[(c_2A_2+F_2)X_{11}\bigr]+x_\star\\ &=\operatorname{tr}X_{00}+\operatorname{tr}X_{11}+x_\star=\operatorname{tr}X. \end{align*}\] The discarded blocks have zero trace, so \(\Theta\) is trace preserving. Because \(W_0,W_1,e_\star\) have real coordinates, output transposition in [eq:channel] replaces \(\Psi_i\) by \(T_m\circ\Psi_i\) in the moving branches and fixes the flag output. Coordinate transpose is complex-linear: it does not conjugate the possibly complex scalar multiplying \(P_\star\). The effects \(F_i\) need not be real. Each transposed moving branch is CP by the PPT hypothesis, and the flag branches are CP as shown above. Therefore \(T_{2m+1}\circ\Theta\) is CP, proving that \(\Theta\) is PPT. The flag is absorbing: \(\Theta(P_\star)=P_\star\). Applying [eq:channel] twice to an input on the first block gives, for every \(B\in M_{m}(\mathbb C)\), \[\begin{align*} \Theta^2(W_0BW_0^*) ={}&c_1c_2W_0\Psi_2(\Psi_1(B))W_0^*\\ &+\bigl(\operatorname{tr}(F_1B)+c_1\operatorname{tr}(F_2\Psi_1(B))\bigr)P_\star . \end{align*}\] Compression to that block consequently gives \[ W_0^*\Theta^2(W_0BW_0^*)W_0 =c_1c_2\Psi_2(\Psi_1(B)). \tag{51}\] Expanding in the coordinate matrix units of the input turns (51) into (48). The coordinate qualification fixes the reference factor: for general complex isometries \(W,V\) and a compatible map \(\Gamma\), \[J\bigl(B\mapsto V^*\Gamma(WBW^*)V\bigr) =(W^{\mathsf T}\otimes V^*)J(\Gamma)(\overline W\otimes V).\] Here \(W_0\) is real, so the reference factor is exactly the one displayed in (48). Local compression preserves separability, since it takes a positive product \(A\otimes B\) to \((W_0^*AW_0)\otimes(W_0^*BW_0)\). Thus separability of \(J(\Theta^2)\) would imply separability of the positive multiple \(c_1c_2J(\Psi_2\circ\Psi_1)\) in (48). This proves the last assertion. ◻ Proof of Theorem 3. Apply Proposition 25 with \(m=10\) and \(\Psi_i=\Phi_i\) from (30). Their composite Choi matrix is nonseparable by Theorem 2 and Lemma 6. Formula [eq:channel] therefore gives the required PPT channel on \(M_{21}(\mathbb C)\). ◻ The product-free range assertion is used for the compressed matrix \(Z\). The full channel Choi matrix has a product contribution from the absorbing flag: since \(\Theta\) annihilates off-diagonal blocks involving \(e_\star\) and \(\Theta(P_\star)=P_\star\), the matrix \(P_\star\otimes P_\star\) is a direct summand of \(J(\Theta^2)\). The channel conclusion is the nonseparability of the full Choi matrix, certified by its entangled corner. An alternative construction from projection overlapsThe dimension-ten construction is complete. Sections 9 and 10 now produce another entangled member of \(\mathscr C\) in much larger finite dimensions. The real construction has an additional symmetry: the same trace-preserving rectangular PPT channel acts on both halves of a maximally entangled state. These are parallel local actions on two subsystems, distinct from the self-composition of a square channel in Theorem 3. The mechanism also differs from the dimension-ten range obstruction. The input consists of real unit vectors and projective measurements. The vectors produce a large sum of correlations, whereas zero trace overlaps among the projections restrict the supports of the product vectors in a hypothetical separable decomposition. These two bounds will conflict. Trace Gram matrices of positive factors also occur in completely positive semidefinite factorizations [51]; here the zero pattern of such trace pairings supplies the support restriction. For self-adjoint projections \(E,F\), their trace overlap is always a nonnegative real number: \[ \operatorname{tr}(EF)=\operatorname{tr}(FEF)=\operatorname{tr}\bigl((EF)^*EF\bigr)\geq0. \tag{52}\] In particular, it vanishes exactly when \(EF=0\). This fact does not require \(E\) and \(F\) to commute. Proposition 26 (Rectangular projection criterion). Let \(Q,K,D\) be positive integers, let \(\mathcal Q\) be a set of \(Q\) elements, and let \(u_q\in\mathbb R^K\), \(q\in\mathcal Q\), be unit vectors. Put \(c_{qr}=u_q^{\mathsf T}u_r\). For each \(q\), let \(\{P_i:i\in\mathcal I_q\}\) be a finite projective measurement on \(\mathbb C^D\): its members are self-adjoint projections, they are mutually orthogonal, and their sum is \(I_D\). Zero projections are allowed. Take the label sets \(\mathcal I_q\) disjoint, put \(\mathcal I=\bigsqcup_{q\in\mathcal Q}\mathcal I_q\), and set \(n=|\mathcal I|\). Suppose that
After ordering \(\mathcal I\), define the complex-linear map \(\Psi:M_{n}(\mathbb C)\to M_{D}(\mathbb C)\) on matrix units by \[ H_{ij}=c_{qr}P_iP_j,\qquad \Psi(E_{ij})=H_{ij} \quad(i\in\mathcal I_q,\ j\in\mathcal I_r). \tag{53}\] Then \(\Psi\) and its Hilbert–Schmidt adjoint \(\Psi^\dagger:M_{D}(\mathbb C)\to M_{n}(\mathbb C)\) are PPT. Moreover, \[ C:=J(\Psi^\dagger\circ\Psi) \quad\text{is nonseparable over }\mathbb C^n\otimes\mathbb C^n, \qquad \operatorname{tr}C=Q^2D. \tag{54}\] Proof. We first prove that \(\Psi\) is PPT. To establish nonseparability, let \(B\) be the compression of \(C\) to the span of the vectors \(e_i\otimes e_i\), expressed in that basis, and let \(\mathbf1=(1,\ldots,1)^\mathsf T\). We will compare two bounds on the sum of its entries. The vector Gram matrix gives \[\mathbf1^*B\mathbf1\geq\frac QK\operatorname{tr}B,\] whereas the zero tensor-basis diagonal entries would force a separable decomposition of \(C\) to satisfy \(\mathbf1^*B\mathbf1\leq\kappa\operatorname{tr}B\). We will also have \(\operatorname{tr}B=QD>0\), so the strict inequality \(\kappa<Q/K\) will make these bounds incompatible. The block Gram matrix and its partial transposes. Regard each \(u_q\) also as a vector in \(\mathbb C^K\). For arbitrary \(w_i\in\mathbb C^D\), self-adjointness of the projections gives \[ \sum_{i,j\in\mathcal I}\langle w_i,H_{ij}w_j\rangle = \left\| \sum_{q\in\mathcal Q}\sum_{i\in\mathcal I_q}u_q\otimes P_iw_i \right\|^2\geq0. \tag{55}\] Thus the block matrix \(H=[H_{ij}]_{i,j\in\mathcal I}=J(\Psi)\) is positive semidefinite. Lemma 5 implies that \(\Psi\) is CP. Since \(c_{qr}=c_{rq}\) is real, the first hypothesis gives \[ H_{ij}=H_{ji}=H_{ij}^*. \tag{56}\] Indeed, if \(c_{qr}\ne0\), the two projections commute; if \(c_{qr}=0\), both blocks vanish and no commutation is needed. Let \(\Gamma_1=T_n\otimes\mathrm{id}_D\) and \(\Gamma_2=\mathrm{id}_n\otimes T_D\) denote the partial transposes on the input and output Choi factors. Block symmetry gives \[ H^{\Gamma_1}=H,\qquad H^{\Gamma_2}=H^{\mathsf T}\succeq0. \tag{57}\] For the second identity, full transpose is the product of the two partial transposes. Full transpose preserves complex positive semidefiniteness: from \(H=R^*R\) we get \(H^{\mathsf T}=(\overline R)^*\overline R\). The Choi identities in Lemma 5 now show that \(T_D\circ\Psi\) is CP. Hence \(\Psi\) is PPT. Lemma 4 gives complete positivity and the PPT property for \(\Psi^\dagger\). We will also use a more specific identity. Testing the defining adjoint relation on matrix units gives, for every \(A\in M_{D}(\mathbb C)\), \[ [\Psi^\dagger(A)]_{ij}=\operatorname{tr}(H_{ij}^*A). \tag{58}\] Equation (56) therefore yields \[ T_n\circ\Psi^\dagger=\Psi^\dagger \tag{59}\] on all complex matrices, including non-Hermitian ones. The tensor-basis diagonal and a compression. The composition \(\Psi^\dagger\circ\Psi\) is CP, so \(C\succeq0\). Index its rows and columns by \(\mathcal I\times\mathcal I\). Equation (58) gives the fully indexed formula \[ C_{(i,a),(j,b)}=\operatorname{tr}(H_{ab}^*H_{ij}). \tag{60}\] Since \(c_{qq}=1\) and \(P_i^2=P_i\), we have \(H_{ii}=P_i\). The diagonal entries with indices \((i,j)\), and the entries of the compression \(B\), are consequently \[\begin{align*} C_{(i,j),(i,j)}&=\operatorname{tr}(P_iP_j), \tag{61}\\ B_{ij}:=C_{(i,i),(j,j)} &=\operatorname{tr}(H_{ij}^*H_{ij}) =c_{qr}^{\,2}\operatorname{tr}(P_iP_j) \quad(i\in\mathcal I_q,\ j\in\mathcal I_r). \tag{62}\end{align*}\] The last equality follows from \(\operatorname{tr}(P_jP_iP_iP_j)=\operatorname{tr}(P_iP_j)\), by idempotence and cyclicity of trace. It remains valid without commutation and when \(c_{qr}=0\). For each pair \(q,r\), completeness of the two measurements gives \[\sum_{i\in\mathcal I_q}\sum_{j\in\mathcal I_r}\operatorname{tr}(P_iP_j) =\operatorname{tr}\!\left[ \left(\sum_{i\in\mathcal I_q}P_i\right) \left(\sum_{j\in\mathcal I_r}P_j\right) \right]=D.\] Summing (61) proves \(\operatorname{tr}C=Q^2D\). The same identity and (62) give \[ \operatorname{tr}B=QD,\qquad \mathbf1^*B\mathbf1 =D\sum_{q,r\in\mathcal Q}c_{qr}^{\,2} \geq\frac{DQ^2}{K}. \tag{63}\] To see the inequality, set \(M=\sum_{q\in\mathcal Q}u_qu_q^{\mathsf T}\), a positive semidefinite \(K\)-by-\(K\) real matrix. Then \(\operatorname{tr}M=Q\) and \(\operatorname{tr}(M^2)=\sum_{q,r}c_{qr}^2\). Cauchy–Schwarz applied to its \(K\) nonnegative eigenvalues yields \(\operatorname{tr}(M^2)\geq(\operatorname{tr}M)^2/K=Q^2/K\). Equivalently, the vector Gram matrix has rank at most \(K\). The support bound forced by separability. Suppose that \(C\) is separable over \(\mathbb C^n\otimes\mathbb C^n\). Spectrally decomposing its local positive factors and absorbing positive weights into the vectors gives a finite decomposition \[C=\sum_\ell (x^{(\ell)}\otimes y^{(\ell)}) (x^{(\ell)}\otimes y^{(\ell)})^*, \qquad x^{(\ell)},y^{(\ell)}\in\mathbb C^n.\] Whenever \(\operatorname{tr}(P_iP_j)=0\), the corresponding tensor-basis diagonal entry is \[0=C_{(i,j),(i,j)} =\sum_\ell |x_i^{(\ell)}y_j^{(\ell)}|^2.\] Each summand is nonnegative, so \(x_i^{(\ell)}y_j^{(\ell)}=0\) for every \(\ell\). For one summand put \(z_i=x_i y_i\). If distinct \(i,j\) lie in \(\operatorname{supp}z\), then \(x_i y_j\ne0\). The preceding implication and (52) force \(\operatorname{tr}(P_iP_j)>0\). The second hypothesis therefore gives \(|\operatorname{supp}z|\leq\kappa\). Compressing the separable decomposition to the diagonal tensor subspace gives \(B=\sum_\ell z^{(\ell)}(z^{(\ell)})^*\). Complex Cauchy–Schwarz on each support now yields \[ \begin{aligned} \mathbf1^*B\mathbf1 &=\sum_\ell\left|\sum_i z_i^{(\ell)}\right|^2 \leq \kappa\sum_\ell\|z^{(\ell)}\|^2 =\kappa\operatorname{tr}B\\ &<\frac{Q}{K}\operatorname{tr}B =\frac{DQ^2}{K}. \end{aligned} \tag{64}\] The inequality is also valid for a zero \(z^{(\ell)}\), whose support is empty. The strict step uses \(\kappa<Q/K\) and \(\operatorname{tr}B=QD>0\). This contradicts (63) and proves nonseparability. ◻ The complex criterion has a state interpretation without the reality assumption. By (59), Lemma 9 gives \[ C= \bigl((\Psi^\dagger\circ T_D)\otimes\Psi^\dagger\bigr) (\Omega_D\Omega_D^*). \tag{65}\] Both local maps in this formula satisfy the input-transpose CP conditions, as the transfer lemma asserts for the PPT pair \(\Psi,\Psi^\dagger\). Thus \(C/(Q^2D)\in\mathscr C\) also in the complex case, and Theorem 17 and Proposition 18 apply to it. The two local maps in (65) may differ; the reality assumption is what gives the same channel in (67). Corollary 27 (The same local channel for real projections). Under the hypotheses of Proposition 26, suppose that every \(P_i\) is real symmetric in the fixed basis of \(\mathbb C^D\), and put \(\Lambda=\Psi^\dagger:M_{D}(\mathbb C)\to M_{n}(\mathbb C)\). Then, on all complex inputs, \[ \Lambda\circ T_D=\Lambda=T_n\circ\Lambda, \qquad \operatorname{tr}\Lambda(A)=Q\,\operatorname{tr}A. \tag{66}\] In particular, \(\Lambda/Q\) is a trace-preserving PPT channel. For \(\Phi_D=\Omega_D/\sqrt D\), the normalized maximally entangled vector on \(\mathbb C^D\otimes\mathbb C^D\), one has \[ \frac{C}{Q^2D} = \left(\frac{\Lambda}{Q}\otimes\frac{\Lambda}{Q}\right) (\Phi_D\Phi_D^*). \tag{67}\] This is an entangled density operator on \(\mathbb C^n\otimes\mathbb C^n\) in \(\mathscr C\). Proof. Reality and (56) give the additional identity \(H_{ij}^{\mathsf T}=H_{ij}\). Equation (58) therefore becomes \[[\Lambda(A)]_{ij}=\operatorname{tr}(H_{ij}A),\qquad [\Lambda(T_D(A))]_{ij}=\operatorname{tr}(H_{ij}^{\mathsf T}A)=\operatorname{tr}(H_{ij}A).\] This proves the first transpose invariance; the second is (59). Also, \[\operatorname{tr}\Lambda(A)=\sum_i\operatorname{tr}(H_{ii}A) =\sum_{q\in\mathcal Q}\sum_{i\in\mathcal I_q}\operatorname{tr}(P_iA) =Q\,\operatorname{tr}A.\] Since \(\Lambda\) is CP and PPT by the proposition, \(\Lambda/Q\) is a trace-preserving PPT channel with input size \(D\) and output size \(n\). Apply Lemma 9 to the pair \(\Psi,\Lambda\). Its first local factor is \[\Psi^\sharp=T_n\circ\Lambda\circ T_D=\Lambda\] by the two invariances. Thus \[ G:=(\Lambda\otimes\Lambda)(\Omega_D\Omega_D^*)=C. \tag{68}\] Dividing this identity by \(Q^2D\) gives (67). Proposition 26 gives \(\operatorname{tr}C=Q^2D>0\) and complex nonseparability. Finally, \(\Lambda/Q\) and \((\Lambda/Q)\circ T_D\) are CP, so (67) is a representation of the form in Definition 7. This proves the assertion. ◻ The two channel uses in (67) act on separate subsystems. We next embed the rectangular maps into one matrix algebra to obtain a composition of square PPT maps. Corollary 28 (Square embedding). Under the hypotheses of Proposition 26, suppose in addition that \(n\geq D\), and let \(U:\mathbb C^D\to\mathbb C^n\) be the real coordinate isometry onto the first \(D\) coordinates. Define \[ \Xi_1=\operatorname{Ad}_U\circ\Psi,\qquad \Xi_2=\Psi^\dagger\circ\operatorname{Ad}_{U^*} =\Xi_1^\dagger . \tag{69}\] Then \(\Xi_1,\Xi_2:M_{n}(\mathbb C)\to M_{n}(\mathbb C)\) are PPT and \[\Xi_2\circ\Xi_1=\Psi^\dagger\circ\Psi.\] Their composition is not entanglement breaking. Proof. Embedding and compression by \(U\) are CP. The PPT composition stability in Lemma 4 therefore applies to both maps. Directly, the reality of \(U\) also gives \(T_n(UAU^*)=U T_D(A)U^*\), while (59) fixes the output transpose of the second map. The adjoint identity follows by reversing the two factors, and \(U^*U=I_D\) gives the composite identity. Its Choi matrix is the nonseparable \(C\) of Proposition 26; the characterization in Lemma 5 proves the last assertion. ◻ The dimension comparison in this corollary is used only to choose the isometry \(U\). The rectangular criterion itself has no such comparison. The displayed square maps need not preserve trace or be unital. A finite combinatorial realizationWe construct data satisfying Proposition 26. A restricted-intersection bound gives real unit vectors such that every sufficiently large subfamily contains an orthogonal pair. The fiber argument for threefold tensor products strengthens this conclusion to eight mutually orthogonal members in every sufficiently large subfamily. Six of these eight vectors will index the six measurements in a parity obstruction; the remaining two receive a trivial measurement. Tensoring these measurements over the eight-subsets gives the projections required by the criterion. Because the projections are real, the resulting state is produced by the same trace-preserving PPT channel on both halves of a maximally entangled state. Vectors with forced orthogonalitySet \(p=257\), \(k=4p=1028\), and \([k]=\{1,\ldots,k\}\). Define \[ \begin{gathered} \mathcal U=\{A\subseteq[k]: |A|=2p,\ 1\in A\},\\ b=|\mathcal U|=\binom{1027}{513} =\frac12\binom{4p}{2p},\\ s_A=\frac{1}{\sqrt k} \bigl(2\mathbf1_{\{h\in A\}}-1\bigr)_{h=1}^k \in\mathbb R^k \quad(A\in\mathcal U). \end{gathered} \tag{70}\] Each \(s_A\) is a unit vector. Since \(|A\mathbin{\triangle}B|=4p-2|A\cap B|\), counting agreeing and disagreeing coordinates gives \[ s_A^{\mathsf T}s_B =\frac{k-2|A\mathbin{\triangle}B|}{k} =\frac{|A\cap B|}{p}-1. \tag{71}\] Thus two base vectors are orthogonal exactly when their sets intersect in \(p\) elements. Put \[ a_0=\sum_{j=0}^{p-1}\binom{k}{j} =\sum_{j=0}^{256}\binom{1028}{j}, \qquad \delta=\frac{a_0}{b}. \tag{72}\] Frankl and Rödl’s theory of forbidden intersections also forces orthogonal families of a prescribed size in large subsets of a sign cube [22]. Here the precise bound follows from a direct polynomial argument and the fiber amplification below. Lemma 29 (Restricted intersections). If \(\mathcal F\subseteq\mathcal U\) contains no two distinct sets whose associated vectors are orthogonal, then \(|\mathcal F|\leq a_0=\delta b\). Proof. The restricted-intersection estimate belongs to the Frankl–Wilson theory [23]. The proof below uses the multilinear-polynomial approach of Alon, Babai, and Suzuki [2]. We give the needed specialization in full. The integer \(257\) is prime: the primes at most \(\sqrt{257}\) are \(2,3,5,7,11,13\), and the respective remainders are \(1,2,2,5,4,10\). For distinct \(A,B\in\mathcal F\), their common element \(1\) and their equal sizes give \(1\leq|A\cap B|\leq2p-1\). Equation (71) excludes the value \(p\). Hence \(|A\cap B|\) is nonzero modulo \(p\), whereas \(|A\cap A|=2p\) is zero modulo \(p\). Over the field \(\mathbb F_p\), define \[f_A(x_1,\ldots,x_k) =1-\left(\sum_{h\in A}x_h\right)^{p-1} \quad(A\in\mathcal F).\] For every nonzero \(a\in\mathbb F_p\), multiplication by \(a\) permutes the nonzero field elements; comparing their products gives \(a^{p-1}=1\). Therefore, on the indicator vectors of the members of \(\mathcal F\), \[f_A(\mathbf1_B)= \begin{cases} 1,&A=B,\\ 0,&A\ne B. \end{cases}\] Replace every positive power of each variable in every monomial by its first power. This preserves all evaluations on Boolean vectors and leaves degree at most \(p-1\). The resulting multilinear polynomials remain linearly independent: evaluating a linear relation at each \(\mathbf1_B\) makes every coefficient zero. The space of multilinear polynomials of degree at most \(p-1\) has a basis consisting of the \(a_0\) squarefree monomials of those degrees. Thus \(|\mathcal F|\leq a_0\). ◻ Lemma 30 (Fiber amplification). For \(t=1,2,3\), associate to \((A_1,\ldots,A_t)\in\mathcal U^t\) the unit vector \(s_{A_1}\otimes\cdots\otimes s_{A_t}\). If \(\mathcal R\subseteq\mathcal U^t\) contains no collection of \(2^t\) distinct tuples whose associated vectors are pairwise orthogonal, then \[|\mathcal R|\leq t\delta b^t.\] Proof. The case \(t=1\) is Lemma 29. For \(t=2\) or \(3\), write \[\mathcal R_A =\{(A_2,\ldots,A_t):(A,A_2,\ldots,A_t)\in\mathcal R\}, \qquad A\in\mathcal U.\] Let \(\mathcal G\) consist of those \(A\) for which \(\mathcal R_A\) contains \(2^{t-1}\) tuples with pairwise orthogonal tensor vectors in the last \(t-1\) factors. If distinct \(A,B\in\mathcal G\) had \(s_A\perp s_B\), choose one such collection in each fiber. Within either lifted collection, orthogonality comes from the last factors; between the two collections, it comes from the first factors. The two fibers are disjoint, so this would produce \(2^t\) distinct tuples forbidden by the hypothesis. Thus \(\mathcal G\) has no orthogonal base pair, and \(|\mathcal G|\leq a_0=\delta b\) by the preceding lemma. Each fiber in \(\mathcal G\) has at most \(b^{t-1}\) elements. Each other fiber has at most \((t-1)\delta b^{t-1}\) elements by the induction hypothesis. Summing these bounds and using at most \(b\) fibers of the latter kind gives \[|\mathcal R| \leq (\delta b)b^{t-1} +b(t-1)\delta b^{t-1} =t\delta b^t.\] ◻ Use triples as measurement indices, called questions: \[ \begin{gathered} \mathcal Q=\mathcal U^3,\qquad Q=b^3,\qquad K=k^3=1028^3=1086373952,\\ u_q=s_{A_1}\otimes s_{A_2}\otimes s_{A_3}\in\mathbb R^K \quad\bigl(q=(A_1,A_2,A_3)\bigr). \end{gathered} \tag{73}\] The scalar target is \(3\delta<1/K\): the support bound \(3\delta Q\) must be strictly below \(Q/K\) for the projection criterion. These vectors are unit vectors. If \(q=(A_1,A_2,A_3)\) and \(r=(B_1,B_2,B_3)\), their inner product is the rational number \[ c_{qr}=u_q^{\mathsf T}u_r =\prod_{h=1}^3\left(\frac{|A_h\cap B_h|}{257}-1\right). \tag{74}\] An orthogonal eight-set will mean an eight-element subset of \(\mathcal Q\) whose associated vectors are pairwise orthogonal. By Lemma 30, with \(t=3\), every \(\mathcal R\subseteq\mathcal Q\) containing no orthogonal eight-set satisfies \[ |\mathcal R|\leq\kappa,\qquad \kappa:=3\delta Q=3a_0b^2. \tag{75}\] The next analytic estimate is what makes this bound strict enough for Proposition 26. The central coefficient is largest among the \(4p+1\) coefficients of \((1+1)^{4p}\), so \[b=\frac12\binom{4p}{2p}\geq\frac{16^p}{2(4p+1)}.\] The binomial coefficients increase up to the central one, and the degree-\(p\) term in the expansion of \((1+1/3)^{4p}\) is no greater than the full sum. Hence \[a_0\leq p\binom{4p}{p} \leq p(4/3)^{4p}3^p =p(256/27)^p <p\,12^p.\] It follows that \[ \delta<2p(4p+1)(3/4)^p<2^{-65}. \tag{76}\] For the last inequality, use \(2p(4p+1)=528906<2^{20}\), \(p=3\cdot85+2\), and \((3/4)^3=27/64<1/2\); the remaining factor \((3/4)^2\) is less than one. Also \(1028<2^{11}\), so \[K<2^{33},\qquad 3\delta<3\cdot2^{-65}<2^{-33}<\frac1K.\] Combining this with (75) proves \[ \kappa=3a_0b^2<\frac QK. \tag{77}\] The proof has now supplied the vector and cardinality ingredients. We next construct measurements that turn every orthogonal eight-set into a forbidden positive-overlap choice. Six parity measurementsOn \(\mathbb C^2\), let \[X=\begin{pmatrix}0&1\\1&0\end{pmatrix},\qquad Z=\begin{pmatrix}1&0\\0&-1\end{pmatrix},\qquad Y=\begin{pmatrix}0&-\mathrm i\\ \mathrm i&0\end{pmatrix}.\] Use the Mermin–Peres square [42, 47, 48]; its interpretation in the setting of quantum magic games is discussed by Arkhipov [4]. The margins in the following array give the products of the three observables in each row and column: \[ \renewcommand{\arraystretch}{1.25} \begin{array}{ccc|c} X\otimes I_2&I_2\otimes X&X\otimes X&+I_4\\ I_2\otimes Z&Z\otimes I_2&Z\otimes Z&+I_4\\ X\otimes Z&Z\otimes X&Y\otimes Y&+I_4\\\hline +I_4&+I_4&-I_4& \end{array} \tag{78}\] All nine entries are real symmetric involutions. In particular, if \(J=\begin{psmallmatrix}0&-1\\1&0\end{psmallmatrix}\), then \(Y=\mathrm iJ\) and \(Y\otimes Y=-J\otimes J\), a real integral symmetric matrix. Order the six contexts as the three rows followed by the three columns, each read left to right or top to bottom. In context \(t\), write the three observables as \((O_1,O_2,O_3)\). The first two commute and \[ O_3=e_tO_1O_2,\qquad (e_1,e_2,e_3,e_4,e_5,e_6)=(1,1,1,1,1,-1). \tag{79}\] These identities follow from \(XZ=-\mathrm iY\) and \(ZX=\mathrm iY\). For example, the first two entries of the last row multiply, in either order, to \(Y\otimes Y\); those of the last column multiply, in either order, to \(-Y\otimes Y\). Since \(O_3\) is a signed product of the first two, all three commute. Let \(\mathcal A=\{-1,+1\}^2\). The four outcomes of context \(t\) are the matrices \[ h_t(\alpha,\beta) =\frac14(I_4+\alpha O_1)(I_4+\beta O_2), \qquad (\alpha,\beta)\in\mathcal A. \tag{80}\] The two factors divided by two are commuting spectral projections. Their products are therefore self-adjoint projections. Distinct outcomes are orthogonal, and the four products sum to \(I_4\). They are real symmetric with rational entries, and their ranges have the three context eigensigns \((\alpha,\beta,e_t\alpha\beta)\). Lemma 31 (Parity obstruction). There is no choice of one projection from each of the six measurements in (80) such that the trace overlap of every two chosen projections from distinct contexts is strictly positive. Proof. Suppose there were such a choice. All six selected projections would be nonzero. Let a selected row projection \(E\) and column projection \(F\) assign eigensigns \(a,b\in\{-1,+1\}\) to their shared observable \(O\). The eigenspace identities and self-adjointness give \[aEF=EOF=bEF.\] If \(a\ne b\), then \(EF=0\) and their overlap is zero, contrary to the hypothesis. Thus the row and column assignments agree at each of the nine entries of the square. The choice would consequently give nine consistent signs. The product of the three signs in context \(t\) is \(e_t\), by (79). Multiplying the three row constraints gives product \(+1\) for the nine signs; multiplying the three column constraints gives product \(-1\). This is a contradiction. The argument applies to eigenspaces in the complex Hilbert space \(\mathbb C^4\). ◻ Tensor assembly and consequencesWe now impose the six-context obstruction on every orthogonal eight-set of questions. Each such set receives its own tensor factor. Six of its questions use the six parity measurements on that factor, while all other questions use the trivial measurement with one outcome \(I_4\) and three zero outcomes. Thus any positive-overlap choice containing the eight-set violates parity on its factor. This arrangement also ensures the commutation needed in the projection criterion: two distinct questions with nonzero vector inner product cannot both have nontrivial measurements on any one factor. For a uniform index set, include a factor carrying only trivial measurements for every nonorthogonal eight-subset as well. Let \[ \begin{gathered} \mathcal S=\{S\subseteq\mathcal Q:|S|=8\},\qquad L=|\mathcal S|=\binom Q8,\\ \mathcal H=\bigotimes_{S\in\mathcal S}\mathbb C^4\cong\mathbb C^D,\qquad D=4^L. \end{gathered} \tag{81}\] To fix all bases, order subsets of \([k]\) by their increasing lists, then order tuples lexicographically, and order the eight-subsets by their increasing lists in that order. Use the corresponding order for the tensor factors, the standard tensor-product basis in each \(\mathbb C^4=\mathbb C^2\otimes\mathbb C^2\), and the lexicographic order on sign pairs with \(-1<+1\). For \(S\in\mathcal S\) and \(q\in\mathcal Q\), define a four-outcome measurement \(h_{S,q}\) on the factor indexed by \(S\). If \(S\) is an orthogonal eight-set and \(q\) is its \(t\)-th element with \(1\leq t\leq6\), set \(h_{S,q}=h_t\). In every other case, set \[ h_{S,q}(+1,+1)=I_4,\qquad h_{S,q}(\alpha,\beta)=0 \quad\text{when }(\alpha,\beta)\ne(+1,+1). \tag{82}\] Thus the last two questions in an orthogonal eight-set use the trivial measurement, as do all questions outside that set and all questions on a nonorthogonal factor. Every decision of whether a factor is orthogonal is determined by the rational numbers in (74). For each \(q\), retain an outcome string on every factor and define \[ \mathcal I_q=\{q\}\times\mathcal A^{\mathcal S},\qquad P_{q,\lambda} =\bigotimes_{S\in\mathcal S}h_{S,q}(\lambda_S) \quad\bigl(\lambda\in\mathcal A^{\mathcal S}\bigr). \tag{83}\] Order these outcome strings lexicographically using the stated factor and sign-pair orders, and order the full labels first by question and then by outcome string. This is the standard basis order used for the concrete maps. The matrices \(P_{q,\lambda}\) are real symmetric projections. For a fixed \(q\), two distinct strings differ in some factor, where their local projections have zero product; hence their global projections are orthogonal. Summing over all strings factors as \(\bigotimes_S\sum_{\alpha,\beta}h_{S,q}(\alpha,\beta)=I_D\). Keeping every outcome string, including those whose projection is zero, gives a uniform label set: there are exactly \(4^L=D\) labels for every question. Hence \[ m:=\left|\bigsqcup_{q\in\mathcal Q}\mathcal I_q\right|=QD. \tag{84}\] In particular \(m\geq D\), as required for the square embedding in Corollary 28. Lemma 32. The vectors (73) and measurements (83) satisfy the two hypotheses of Proposition 26 with \(n=m=QD\) and \(\kappa=3a_0b^2<Q/K\). Proof. If \(q=r\), projections with those labels belong to one projective measurement and commute. Suppose that \(q\ne r\) and \(c_{qr}\ne0\). They cannot both receive nontrivial contexts on any one factor: that would place them together in an orthogonal eight-set, forcing \(c_{qr}=0\). On each factor at least one of the two selected local projections is consequently \(0\) or \(I_4\). They commute on each factor, so their tensor products commute. This proves the first hypothesis. Now let \(J\) be a label set with strictly positive trace overlap between every distinct pair. Distinct labels for one question have zero product, so \(J\) contains at most one label per question. The trace overlap of any two global projections factors as \[ \operatorname{tr}(P_{q,\lambda}P_{r,\mu}) = \prod_{S'\in\mathcal S} \operatorname{tr}\bigl(h_{S',q}(\lambda_{S'}) h_{S',r}(\mu_{S'})\bigr). \tag{85}\] Every local factor is nonnegative by (52), whether or not the two local projections commute. Thus strict positivity of this finite product implies strict positivity of each factor. If the questions represented by \(J\) contained an orthogonal eight-set \(S\), take the selected labels for its first six questions. At the factor indexed by \(S\), equation (85) would give strictly positive overlap for each pair of the six selected context projections. Lemma 31 forbids this. The represented questions therefore contain no orthogonal eight-set, and (75) gives \(|J|\leq\kappa\). For completeness, the pairwise condition on a singleton is vacuous even when its projection is zero; it still satisfies the bound because \(a_0,b\geq1\) and \(\kappa=3a_0b^2\geq3\). The strict inequality \(\kappa<Q/K\) is (77). ◻ Theorem 33 (Finite combinatorial construction). Set \[ \begin{gathered} p=257,\qquad k=1028,\qquad b=\binom{1027}{513},\qquad a_0=\sum_{j=0}^{256}\binom{1028}{j},\\ Q=b^3,\qquad K=1086373952,\qquad \kappa=3a_0b^2<\frac QK,\\ L=\binom Q8,\qquad D=4^L,\qquad m=QD. \end{gathered} \tag{86}\] Use the vectors in (73), the \(D\) labels per question and projections in (83), and the map \(\Psi:M_{m}(\mathbb C)\to M_{D}(\mathbb C)\) in (53). Put \(\Lambda=\Psi^\dagger\) and \(\Phi_D=\Omega_D/\sqrt D\).
Proof. Lemma 32 verifies the hypotheses of Proposition 26. Its composite \(C=J(\Psi^\dagger\circ\Psi)\) is positive and nonseparable over \(\mathbb C^m\otimes\mathbb C^m\), with \(\operatorname{tr}C=Q^2D\). The projections are real symmetric, so Corollary 27 proves (87), the channel assertion, and membership in \(\mathscr C\). Theorem 17 and Proposition 18 give the stated operational conclusions. Since \(m=QD\geq D\), Corollary 28 applies to the displayed coordinate isometry and gives the square PPT pair. Its composite is \(\Psi^\dagger\circ\Psi\), and the real identification (68) gives (88). Applying Proposition 25 to this pair gives the channel on \(M_{2m+1}(\mathbb C)\) and its exact corner (89). The corner is nonseparable, so that proposition also proves that the channel square is not entanglement breaking. ◻ All these objects are given by finite exact formulas. The normalized sign vectors \(s_A\) have coordinates \(\pm1/\sqrt{1028}=\pm1/(2\sqrt{257})\), which are irrational because \(257\) is prime. The Gram entries of the question vectors in (74), rather than the vector coordinates, enter the Choi blocks. Those Gram entries are rational; all nine local observables are integral, and all local and global projections are rational. Consequently every block \(H_{ij}\), every coefficient of \(\Psi,\Lambda,\Phi_1^{\mathrm{comb}},\Phi_2^{\mathrm{comb}}\), and every entry of \(\rho_{\mathrm{comb}}\) is rational in the specified bases. The completion also has rational coefficients: its positive scalings and flag matrices in Proposition 25 are formed from the rational square maps using traces and rational operations. Appendix 12 describes supplementary exact checks of the small arithmetic and six-context calculations. Details of the dimension-ten certificateFinite arithmeticThis subsection gives the exact arithmetic support for the block identities (39) and the finite-field data in Section 7. The Python 3 program below uses only the standard library and integer arithmetic. Its input matrix entries are those of (36), with zero-based row indices in the code. The function The code variable For \(f(z)=z^{20}+c_1z^{19}+\cdots+c_{20}\), with \(c_0=1\), the program uses the Newton identities \[k c_k=-\sum_{i=0}^{k-1}c_i\operatorname{tr}(N^{k-i})\qquad(1\leq k\leq20).\] Division by \(k\) is valid at each of \(41,131,139\). Repeated \(p\)th powers modulo \(\overline f\) then give the residues of \(z^{p^k}\), and the polynomial Euclidean algorithm gives \(d_p(k)\). All inverses are taken in the stated prime field. No floating-point approximation or heuristic search is involved. The program asserts the integer block identities and prints the modular data. Verification of the modular certificate includes comparing the printed output with the recorded values below. The operator, projective, and Galois deductions are proved in Sections 6 and 7, using the algebraic facts proved in the next subsection. The program does not perform a general elimination or Galois-group computation. From the paper directory, run The listing uses an identical build copy of the verification source; its line numbers refer to that source file. The file
Algebraic factsWe prove the three general lemmas used in Section 7. The first supplies a common zero used to prove the affine quotient nonzero; the second accommodates rational coefficients with denominators prime to \(p\); the third converts squarefree modular factor degrees into Galois permutations. Proof of Lemma 22. Let \(X_0,\ldots,X_3,Y_0,\ldots,Y_3\) be indeterminates, put \(u_{ij}=X_iY_j\), and consider the finitely generated complex algebra \[\mathcal R=\mathbb C[u_{ij}:0\leq i,j<4] \subset\mathbb C[X_0,\ldots,X_3,Y_0,\ldots,Y_3].\] It is a Noetherian domain. Its closed complex points are exactly the matrices of rank at most one. Indeed, the identities \(u_{ij}u_{k\ell}=u_{i\ell}u_{kj}\) force the values at any point to have rank at most one, and every such matrix is \(xy^{\mathsf T}\) and defines an evaluation of \(\mathcal R\). The maximal ideal \(\mathfrak m=(u_{ij}:0\leq i,j<4)\) corresponds to the zero matrix. For \(1\leq a,b\leq4\), put \(P_{a,b}=(u_{ij}:i\geq a\text{ or }j\geq b)\). The quotient by \(P_{a,b}\) is the domain \(\mathbb C[X_iY_j:0\leq i<a,\ 0\leq j<b]\). To justify the identification, use the monomial basis \(X^\alpha Y^\beta\) with \(|\alpha|=|\beta|\) for \(\mathcal R\): a monomial containing an excluded variable factors by an excluded generator, while the remaining monomials stay distinct. Hence \[0=P_{4,4}\subsetneq P_{3,4}\subsetneq P_{2,4}\subsetneq P_{1,4} \subsetneq P_{1,3}\subsetneq P_{1,2}\subsetneq P_{1,1} \subsetneq\mathfrak m\] is a strict chain of prime ideals. In particular, \(\operatorname{ht}\mathfrak m\geq7\). Let \(\ell_1,\ldots,\ell_6\in\mathcal R\) be the linear combinations of the \(u_{ij}\) representing the six bilinear forms, and put \(\mathfrak a=(\ell_1,\ldots,\ell_6)\). If the only common zero on the rank-at-most-one matrices were the zero matrix, the Hilbert Nullstellensatz for the finite-type complex algebra \(\mathcal R\) would give \(\sqrt{\mathfrak a}=\mathfrak m\). The prime \(\mathfrak m\) would then be minimal over an ideal generated by six elements. Krull’s height theorem bounds the height of such a prime in a Noetherian ring by six, contradicting the chain above [58]. Thus a nonzero rank-one matrix \(xy^{\mathsf T}\) annihilates all six forms. Both factors are nonzero. ◻ Proof of Lemma 23. Normalize the valuation by \(v_p(p)=1\). In either pair its values on nonzero elements are integers, and \(R_p/pR_p=\mathbb F_p\). For a nonzero polynomial \(a(z)=\sum_i a_i z^i\) over \(\mathbb L\), put \(\nu(a)=\min_{a_i\ne0}v_p(a_i)\). Scaling nonzero polynomials \(a,b\) by \(p^{-\nu(a)}\) and \(p^{-\nu(b)}\) makes their coefficients integral with least valuation zero. Their reductions are nonzero and have nonzero product in the domain \(\mathbb F_p[z]\). Thus \[\nu(ab)=\nu(a)+\nu(b).\] For monic \(g,h\) one has \(\nu(g),\nu(h)\leq0\), whereas the monic \(P\in R_p[z]\) has \(\nu(P)=0\). Additivity forces \(\nu(g)=\nu(h)=0\), so all coefficients of both factors are integral. Their leading coefficients remain one after reduction, which preserves their degrees; a monic constant factor is \(1\) and retains degree zero. Any factorization of \(P\) into two positive-degree polynomials over \(\mathbb L\) can be normalized to monic factors, whose reductions would still have positive degree. This contradicts irreducibility of the reduction of \(P\). ◻ Proof of Lemma 24. Embed the coefficients of \(F\) into \(\mathbb Z_p\) and put \(s=\operatorname{lcm}(s_1,\ldots,s_h)\). Choose a monic irreducible \(\overline g\in\mathbb F_p[X]\) of degree \(s\) and a monic coefficient lift \(g\in\mathbb Z_p[X]\); we use the standard finite-field fact that an irreducible polynomial of every positive degree exists. Lemma 23 for \((\mathbb Q_p,\mathbb Z_p)\) shows that \(g\) is irreducible over \(\mathbb Q_p\). If \(\alpha\) is a root, put \[E=\mathbb Q_p(\alpha),\qquad \mathcal O=\mathbb Z_p[\alpha]\simeq\mathbb Z_p[X]/(g).\] The ring \(\mathcal O\) is free of rank \(s\) over \(\mathbb Z_p\), hence complete and separated for the \(p\)-adic topology, and \(\mathcal O/p\mathcal O\simeq\mathbb F_{p^s}\). Every element with nonzero residue is a unit: lift an inverse modulo \(p\) and correct it by a convergent geometric series. Every simple residue root of a polynomial in \(\mathbb Z_p[z]\) lifts uniquely to a root in \(\mathcal O\). To see this, suppose \(r_n\) is a root modulo \(p^n\) whose derivative has nonzero residue. The first-order Taylor congruence gives a unique residue class of \(c\) such that \(r_{n+1}=r_n+p^nc\) is a root modulo \(p^{n+1}\). Completeness gives a limiting root. If two roots have the same simple residue, the polynomial difference factorization writes their difference times a unit as zero; the roots therefore coincide. Every root of \(\overline F\) lies in \(\mathbb F_{p^s}\) and is simple. Lifting them gives \(\deg F\) distinct roots of \(F\) in \(\mathcal O\), hence all the roots. Finite fields are perfect, so \(\overline\alpha^{\,p}\) is a simple root of \(\overline g\). Lift it to a root \(\beta\in\mathcal O\) of \(g\). Sending \(\alpha\) to \(\beta\) defines a \(\mathbb Q_p\)-embedding \(E\to E\), because \(g\) is irreducible. This embedding is an automorphism \(\sigma\), as \(E\) is finite-dimensional over \(\mathbb Q_p\). Since \(\beta\in\mathcal O\), we have \(\sigma(\mathcal O)\subseteq\mathcal O\). The induced residue map fixes \(\mathbb F_p\) and sends \(\overline\alpha\) to \(\overline\alpha^{\,p}\), so it is Frobenius on \(\mathbb F_{p^s}\). In a \(\mathbb Z_p\)-basis of \(\mathcal O\), the matrix of this endomorphism reduces to an invertible residue matrix. Its determinant is a \(p\)-adic unit, and therefore \(\sigma(\mathcal O)=\mathcal O\). If \(\rho_r\) is the lifted root of \(F\) with residue \(r\), uniqueness of lifting gives \(\sigma(\rho_r)=\rho_{r^p}\). Thus the permutation of the lifted roots has exactly the Frobenius cycle lengths on their residues, namely \(s_1,\ldots,s_h\). The subfield of \(E\) generated over \(\mathbb Q\) by these roots is a rational splitting field of \(F\). The automorphism \(\sigma\) permutes its generating roots and hence preserves this subfield. Its restriction is the required rational Galois automorphism. A \(\mathbb Q\)-isomorphism transports the statement to any chosen splitting field. ◻ Supplementary exact checksThe construction in Section 10 is proved by finite formulas and analytic inequalities. The four accompanying files in The program The program From the paper directory the outputs can be regenerated by
Run these commands with Python assertions enabled: do not use
|
| ||||||||
|