Imagine you and a friend each have half of a combination lock where the digits on your half always sum to an even number, and so do theirs — but neither of you chose the combination. The lock was manufactured that way. If someone intercepts one half, the even-sum rule tells them nothing about the other half's specific digits. That's the parity constraint at the heart of this paper: each party holds a random codeword from a classical [3,2,2] even-parity code, and entanglement locks the two codewords together without either party ever communicating their values. The committed claim: the authors experimentally generate asymmetric (public/private) cryptographic keys from the parity structure of a six-qubit two-photon entangled state, replacing the computational-hardness assumptions of RSA and elliptic-curve cryptography with physics-based guarantees. This is not QKD (which produces symmetric keys); it's an attempt to build public-key infrastructure on quantum correlations. The distinction matters — public-key crypto is the backbone of internet authentication, not just encryption. The physical setup uses a Sagnac-loop type-II SPDC source to produce polarization-entangled photon pairs. Each photon then carries three qubits: one polarization and two path degrees of freedom, for six qubits total. The state is engineered into an equal superposition of eight of the sixty-four possible six-qubit basis states, chosen so each photon's triple forms a valid [3,2,2] codeword. The Bell-CHSH parameter measured is S = 2.798 ± 0.008, comfortably violating the classical bound of 2 and close to the Tsirelson bound of 2√2 ≈ 2.828. The parity constraint acts as a local stabilizer: each party checks parity every round and discards bit-flip errors from detector dark counts or multi-photon events before they contaminate the raw key. Key reconstruction works elegantly. A single bit, chosen randomly from one of the path qubits, is announced publicly. Because the parity structure locks the two triples together, that one bit — combined with the recipient's own triple — is enough to reconstruct the sender's full triple. An eavesdropper holding neither triple gains nothing from a single parity-consistent bit. For a t-bit key string built over multiple rounds, brute-force recovery requires O(2^t) runs on a t-qubit quantum system — exponential cost without the private key. The integrity picture is mixed. This is a real tabletop experiment, not a simulation, which earns credibility. But the scale is tiny (six qubits, two photons), the key length per round is effectively a few bits, and no comparison is made to any existing QKD protocol's key rate or error performance. The Bell-CHSH violation confirms entanglement quality but doesn't benchmark the scheme against BB84, E91, or any post-quantum classical candidate. The error-correction mechanism (parity check and discard) is elegant in principle but its overhead at scale is uncharacterized. The milestone gap is significant. Six qubits suffices for a proof of concept. A practical key-generation system would need to scale to hundreds or thousands of qubits per round to produce keys of cryptographically useful length at reasonable rates, which means multiplexing many photon pairs or moving to different physical platforms. The authors do not discuss key rates, latency, or how the parity-based approach compares to existing quantum or post-quantum classical key-exchange protocols in practical throughput. The obvious next experiment is scaling beyond six qubits — either by increasing the number of entangled photon pairs processed in parallel or by encoding more qubits per photon using additional degrees of freedom (orbital angular momentum, time-bin). The authors likely didn't run this because the optical setup for even six qubits in a Sagnac interferometer is already alignment-intensive. Scaling to 12 or 18 qubits would require substantially more complex optical networks or a different photonic platform entirely. This is a compute/hardware limitation, not a conceptual one.