7.2 Local, Quantum, No-Signaling and Causal Correlations
113
Finally, the set L of local correlations is characterized by probability distributions
that can be expressed in terms of an LHV model (7.6).
It is proved that every local correlation is also a quantum correlation, and that every
quantum correlation satisfies the no-signaling constraints [21], as mentioned earlier.
However, with the violation of the CHSH inequality (7.9), we have seen that there
are quantum correlations outside the set of local correlations. Moreover, there are
no-signaling correlations which are not quantum correlations. For instance, there are
no-signaling correlations whose CHSH value S CHSH achieves the algebraic bound of
the expression: S CHSH = 4. Conversely, it is shown [21] that any quantum correlation
leads to a CHSH value upper bounded by 2
√
2, which is called the Tsirelson bound.
Due to these observations, the following strict inclusions hold: L ⊂ Q ⊂ N S.
7.3 From Bell Violation to Security
Whenever a set of probability distributions, e.g., p(a, b|x, y) in the bipartite Bell
scenario, violates a Bell inequality, we talk about Bell violation and we call the
correlations generated by such distributions non-local. In this Section we clarify
the connection between Bell violation and the security of device-independent (DI)
quantum cryptographic protocols.
The security of DI protocols, such as DIQKD and DIRG, is guaranteed irrespective
of the trustworthiness of the devices used in their implementation. In a DI protocol,
each party holds a device modelled as black box producing an output upon receiving
an input from the party. By repeating this operation for several rounds, the parties
collect a series of outcomes, each related to the input that generated it.
A fraction of the collected outputs forms the secret key shared by the parties in
DIQKD and DICKA protocols, or the secret random bitstring in DIRG protocols.
The remaining outputs are used to test a Bell inequality with a Bell experiment like
the one described in Sect. 7.1.
Performing a Bell test during the execution of a device-independent (DI) protocol
is crucial to ensure its security. Indeed, upon observing a Bell violation, the parties
can certify that the random outcomes collected during the execution of the protocol
are (at least partially) secret, i.e. unknown to a potential eavesdropper (Eve). What
is the link between Bell violation and the privacy of the parties’ outcomes?
Firstly, observing a Bell violation rules out the possibility that the outcomes
collected by the parties have been generated by an LHV strategy (7.6). In particular,
this excludes the possibility that the outcomes have been predetermined by Eve
by setting up the systems such that the probabilities p(a|x, λ) and p(b|y, λ) are
deterministic functions of x, y and λ: p(a|x, λ), p(b|y, λ) ∈ {0, 1}. This ensures
that, even if the parties’ systems were fabricated by Eve, she could not have predicted
all the outcomes observed by the parties during the Bell experiment. This is a good
starting point to have a secret string of random bits.
As we discussed in Bell’s theorem proof (c.f. Sect. 7.1), quantum theory allows for
correlations violating a Bell inequality. Specifically, a Bell violation occurs only when
113
Finally, the set L of local correlations is characterized by probability distributions
that can be expressed in terms of an LHV model (7.6).
It is proved that every local correlation is also a quantum correlation, and that every
quantum correlation satisfies the no-signaling constraints [21], as mentioned earlier.
However, with the violation of the CHSH inequality (7.9), we have seen that there
are quantum correlations outside the set of local correlations. Moreover, there are
no-signaling correlations which are not quantum correlations. For instance, there are
no-signaling correlations whose CHSH value S CHSH achieves the algebraic bound of
the expression: S CHSH = 4. Conversely, it is shown [21] that any quantum correlation
leads to a CHSH value upper bounded by 2
√
2, which is called the Tsirelson bound.
Due to these observations, the following strict inclusions hold: L ⊂ Q ⊂ N S.
7.3 From Bell Violation to Security
Whenever a set of probability distributions, e.g., p(a, b|x, y) in the bipartite Bell
scenario, violates a Bell inequality, we talk about Bell violation and we call the
correlations generated by such distributions non-local. In this Section we clarify
the connection between Bell violation and the security of device-independent (DI)
quantum cryptographic protocols.
The security of DI protocols, such as DIQKD and DIRG, is guaranteed irrespective
of the trustworthiness of the devices used in their implementation. In a DI protocol,
each party holds a device modelled as black box producing an output upon receiving
an input from the party. By repeating this operation for several rounds, the parties
collect a series of outcomes, each related to the input that generated it.
A fraction of the collected outputs forms the secret key shared by the parties in
DIQKD and DICKA protocols, or the secret random bitstring in DIRG protocols.
The remaining outputs are used to test a Bell inequality with a Bell experiment like
the one described in Sect. 7.1.
Performing a Bell test during the execution of a device-independent (DI) protocol
is crucial to ensure its security. Indeed, upon observing a Bell violation, the parties
can certify that the random outcomes collected during the execution of the protocol
are (at least partially) secret, i.e. unknown to a potential eavesdropper (Eve). What
is the link between Bell violation and the privacy of the parties’ outcomes?
Firstly, observing a Bell violation rules out the possibility that the outcomes
collected by the parties have been generated by an LHV strategy (7.6). In particular,
this excludes the possibility that the outcomes have been predetermined by Eve
by setting up the systems such that the probabilities p(a|x, λ) and p(b|y, λ) are
deterministic functions of x, y and λ: p(a|x, λ), p(b|y, λ) ∈ {0, 1}. This ensures
that, even if the parties’ systems were fabricated by Eve, she could not have predicted
all the outcomes observed by the parties during the Bell experiment. This is a good
starting point to have a secret string of random bits.
As we discussed in Bell’s theorem proof (c.f. Sect. 7.1), quantum theory allows for
correlations violating a Bell inequality. Specifically, a Bell violation occurs only when
