98
6 Beyond Point-to-Point Quantum Key Distribution
2. Every party sends her optical pulse a i to the relay via optical channels of transmittance
√
η. The transmittance between any two parties is thus η.
3. The relay applies a Bell-multiport beam splitter [27–30] with M input and M
output ports (where M ≥ N ) to the incoming pulses followed by a threshold
detector D i (i = 1, . . . , M) at each output port. If M > N , some inputs ports
receive the vacuum. The action of the multiport beam splitter (BS) is defined by
the following unitary transformation which reduces to the standard 50:50 BS for
M = 2:
a
†
in,i →
M
j=1
U i j a
†
out, j ,
(6.33)
where a
†
in,i (a
†
out, j ) are the creation operators of the incoming (outgoing) photons
and U i j are the coefficients of a unitary matrix defined as:
U i j =
1
√
M
e
i
2π
M (i−1)( j−1)
i, j ∈ {1, . . . , M}.
(6.34)
4. The relay broadcasts the outcome k j of every detector D j , with k j = 0 (k j = 1)
corresponding to a no-click (click) event. The round is discarded when
M
j=1 k j =
1, i.e. whenever single-photon interference did not occur. The probability that only
detector D j clicked is p D and is independent of the detector due to the symmetric
action of the multiport BS.
5. The round is classified either as a parameter-estimation (PE) round or as a keygeneration (KG) round.
3 In case of a PE round, every party measures her qubit in
the Z -basis. In case of a KG round, conditioned on detector D j clicking, Alice i
measures her qubit in the basis of the operator O XY (ϕ i ) = cos(ϕ i )X + sin(ϕ i )Y
(where X and Y are the Pauli operators), with ϕ i = arg(U i j ). Upon observing the
outcome x (where x = ±1 are the eigenvalues of Z and O XY (ϕ i )), Alice i records
the bit value b i with (−1)
b i = x.
6. The bits b i measured in KG rounds form Alice i ’s raw key, while those obtained
in PE are used to detect Eve’s action and quantify the information she gained on
Alice 1 ’s raw key.
After performing a suitable number of rounds, all the parties perform one-way error
correction to match their raw keys to Alice 1 ’s raw key. The parties then perform privacy amplification on their error-corrected keys to distil a shorter, secret, conference
key.
The error rates E Z and E A 1 A i devoted to quantify Eve’s knowledge and the information that Alice 1 needs to send for error correction are defined as follows:
3 The parties can know in advance the classification of each round from a preshared key they hold,
see Remark 4.2.
Précédent

- 109/163

Suivant