106
7 Device-Independent Quantum Cryptography
capable or willing to do it. Indeed, in most cases QKD users are laymen who simply
want to purchase a service which guarantees a high level of security, without bothering
to verify the claimed security.
Quite astonishingly, secure QKD is still possible even when the whole
experimental apparatus is untrusted and potentially under the control of the eavesdropper.
1 Indeed, by exploiting the non-local properties of quantum correlations,
device-independent (DI) QKD protocols [1–6] and DI conference key agreement
(DICKA) protocols [7–10] deliver the same secret key to a group of two or more
parties, respectively, where the security of the key is independent of the actual functioning of the employed devices.
In a similar fashion, in DI randomness generation (DIRG) protocols [11–16], the
intrinsic randomness generated by quantum mechanical processes is proven to be
private upon the observation of certain non-local correlations. Note that secret true
randomness is one of the prerequisites of most quantum cryptographic protocols.
7.1 Bell’s Theorem
Bell’s theorem [17, 18] states that there exist predictions of quantum theory that
cannot be explained by any local theory, i.e. a theory based on the assumption of
locality. In this Section we clarify our definition of locality and prove Bell’s theorem.
The proof critically relies on the introduction of a Bell inequality [18], that is an
inequality involving a linear combination of correlators which is satisfied by every
local theory but is violated by quantum mechanics.
In the literature one can find several versions of Bell’s theorem’s proof, leveraging
on different assumptions. Here we mainly follow the proofs presented in [19–22] that
make use of the Clauser-Horne-Shimony-Holt (CHSH) inequality [23], arguably the
most popular Bell inequality.
Let us consider the following Bell experiment, depicted in Fig. 7.1. Two physical
systems, which could have interacted in the past, are now far apart and are individually
measured by two parties, Alice and Bob. No information is given on the systems,
which are thus treated as black boxes. Each box (system) is equipped with two inputs
corresponding to the measurement choices of the parties, and generates a binary
output upon selecting an input. Hence, the measurement process consists in Alice
(Bob) selecting an input x ∈ {0, 1} (y ∈ {0, 1}) on her (his) system and collecting
the output a ∈ {−1, 1} (b ∈ {−1, 1}). We assume that the measurement processes of
Alice and Bob are spacelike separated events.
By repeating the experiment several times, the parties can roughly estimate the
probability distribution p(a, b|x, y) governing the occurrence of the outcomes a
and b, given the inputs x and y. In general, the outcomes recorded by Alice and Bob
1 Minimal requirements on the devices are still in place, such as the isolation of the trusted parties’
labs. Without this requirement, the devices could simply broadcast the established secret key upon
completing the protocol.
Précédent

- 117/163

Suivant