100
6 Beyond Point-to-Point Quantum Key Distribution
Indeed, the measurements that the parties perform in KG rounds (see protocol
description) are chosen to minimize the key-bit error rate E A 1 A i between Alice 1
and any other party. In particular, one could view the measurement of Alice i in the
eigenbasis of cos[arg(U i j )]X + sin[arg(U i j )]Y as composed of two steps. First she
rotates her X operator in the (x, y)-plane of the Bloch sphere by an angle arg(U i j ),
in order to remove the effect of the complex phase
√
MU i j introduced by the BS
when D j clicked. Then she measures in the eigenbasis of the rotated operator.
The resulting error rate E A 1 A i (6.36) the parties would observe if their qubits were
exactly in the state (6.38) is given by:
E A 1 A i =
1
2
−
1
N
.
(6.39)
This intrinsic error rate affecting the parties’ raw key bits is unavoidable due to the
fact that they are measuring a W -class state, instead of a GHZ state. Conversely, the
error rate E Z (6.35) computed in PE is null on the state (6.38), confirming that in
ideal conditions Eve does not gain any information.
We have thus argued that multipartite QKD can also be implemented on a W
state, instead of the conventional GHZ state used in the majority of cases, e.g., with
the multiparty BB84 and six-state protocols (c.f. Chap. 4). Despite presenting the
drawback of the intrinsic error rate (6.39), the CKA based on the W state becomes
dramatically advantageous in high-loss scenarios.
Indeed, the W state is post-selected when single-photon interference occurred at
the relay. This implies that the resulting conference key rate (6.37) scales linearly
with the transmittance
√ η of one of the channels linking the parties to the relay.
Let us now consider a generic optical implementation of a CKA based on an
N -qubit GHZ state, where the qubit state is encoded in one of the photon’s degrees
of freedom (e.g., the polarization). The N photons described by an N -qubit GHZ
state are distributed from a central untrusted node to the N parties through the same
quantum channels with transmittance
√
η. The conference key rate of this protocol
cannot scale better than ∼ (
√
η)
N , since all the photons are required to arrive in order
to have a successful round.
Clearly, in a high-loss scenario (
√
η → 0) the conference key rate of our CKA
based on single-photon interference will outperform any CKA based on GHZ states
implemented as described above.
Remark 6.2 (Impossibility of prepare-and-measure CKA). We emphasize that the
measurements performed by the parties in the KG rounds do not commute with the
operations of the relay, inasmuch as they depend on which detector clicked. This
means that the CKA cannot be turned into a prepare-and-measure scheme where
each party prepares some optical signal depending on a random bit and on the basis
choice. For this reason, it cannot be regarded as an MDI-QKD protocol since the
parties still need to perform trusted measurements on their qubits.
This contrasts with the TF-QKD idealized protocol presented in Sect. 6.3.1, which
is recovered here for N = M = 2. The bipartite case is special since the complex
6 Beyond Point-to-Point Quantum Key Distribution
Indeed, the measurements that the parties perform in KG rounds (see protocol
description) are chosen to minimize the key-bit error rate E A 1 A i between Alice 1
and any other party. In particular, one could view the measurement of Alice i in the
eigenbasis of cos[arg(U i j )]X + sin[arg(U i j )]Y as composed of two steps. First she
rotates her X operator in the (x, y)-plane of the Bloch sphere by an angle arg(U i j ),
in order to remove the effect of the complex phase
√
MU i j introduced by the BS
when D j clicked. Then she measures in the eigenbasis of the rotated operator.
The resulting error rate E A 1 A i (6.36) the parties would observe if their qubits were
exactly in the state (6.38) is given by:
E A 1 A i =
1
2
−
1
N
.
(6.39)
This intrinsic error rate affecting the parties’ raw key bits is unavoidable due to the
fact that they are measuring a W -class state, instead of a GHZ state. Conversely, the
error rate E Z (6.35) computed in PE is null on the state (6.38), confirming that in
ideal conditions Eve does not gain any information.
We have thus argued that multipartite QKD can also be implemented on a W
state, instead of the conventional GHZ state used in the majority of cases, e.g., with
the multiparty BB84 and six-state protocols (c.f. Chap. 4). Despite presenting the
drawback of the intrinsic error rate (6.39), the CKA based on the W state becomes
dramatically advantageous in high-loss scenarios.
Indeed, the W state is post-selected when single-photon interference occurred at
the relay. This implies that the resulting conference key rate (6.37) scales linearly
with the transmittance
√ η of one of the channels linking the parties to the relay.
Let us now consider a generic optical implementation of a CKA based on an
N -qubit GHZ state, where the qubit state is encoded in one of the photon’s degrees
of freedom (e.g., the polarization). The N photons described by an N -qubit GHZ
state are distributed from a central untrusted node to the N parties through the same
quantum channels with transmittance
√
η. The conference key rate of this protocol
cannot scale better than ∼ (
√
η)
N , since all the photons are required to arrive in order
to have a successful round.
Clearly, in a high-loss scenario (
√
η → 0) the conference key rate of our CKA
based on single-photon interference will outperform any CKA based on GHZ states
implemented as described above.
Remark 6.2 (Impossibility of prepare-and-measure CKA). We emphasize that the
measurements performed by the parties in the KG rounds do not commute with the
operations of the relay, inasmuch as they depend on which detector clicked. This
means that the CKA cannot be turned into a prepare-and-measure scheme where
each party prepares some optical signal depending on a random bit and on the basis
choice. For this reason, it cannot be regarded as an MDI-QKD protocol since the
parties still need to perform trusted measurements on their qubits.
This contrasts with the TF-QKD idealized protocol presented in Sect. 6.3.1, which
is recovered here for N = M = 2. The bipartite case is special since the complex
