114
7 Device-Independent Quantum Cryptography
the parties share a quantum entangled state and their measurements are described by
non-commuting observables (e.g., [A 0 , A 1 ] = 0) [21]. One can thus interpret Bell
inequalities—and violation thereof—as device-independent entanglement witnesses
[3].
An important property of entanglement, called monogamy of entanglement [31,
32], states that if the quantum systems of two parties, say Alice and Bob, are strongly
entangled, then a third quantum system shares little entanglement with them. Thanks
to this property, upon observing a Bell violation, Alice and Bob are sure that Eve was
poorly entangled with their systems and thus has little information on their outcomes.
Hence the secrecy of the parties’ outcomes is granted. Notably, the monogamy of
correlations is not specific to quantum theory, rather it is present in any no-signaling
theory leading to non-local correlations [21].
7.3.1 DIQKD Security Under Coherent Attacks
Let us now formalize the intuition provided above on the security of DI protocols.
Here we focus on DIQKD protocols, but analogous considerations hold for DICKA
and DIRG protocols.
The Bell violation estimated by the parties while running a DIQKD protocol
only describes, on average, the amount of non-locality characterizing one protocol
round, and in particular a round devoted to the generation of the secret key. This
is enough to make a security statement for one round of the protocol. In particular,
given the observed Bell violation, one can bound the conditional von Neumann
entropy H (R A |E) of Alice’s raw key bit R A given Eve’s side information E, which
we already encountered when computing the secret key rates of QKD protocols (c.f.
Chap. 3). The quantitative trade-off between Bell violation and conditional entropy
is illustrated in Sect. 7.5 for the simplest DIQKD protocol.
However, the validity of the security statement for one round cannot be directly
extended to the whole DI protocol and to all its outputs. The reason is that we consider
the most general scenario where Eve performs coherent attacks, meaning that she
can act differently in the various rounds and so can the devices. In fact, the security of
DIQKD follows the same definitions and results reported in Sect. 3.3 for the security
of general QKD schemes, where the main quantity to be estimated is the smooth minentropy H
ε
min (R
n
A |E) of Alice’s bits R
n
A given the side information available to Eve
(see (3.27)). Here, Eve’s side information includes her quantum system correlated
with the initial state distributed to the parties’ devices, but also the additional side
information generated by the untrusted devices during the process.
In standard QKD,
2 we have discussed the existence of methods —such as the
postselection technique (PST)—which reduce the security proof against coherent
attacks to one against collective attacks, i.e. when the behaviour of the devices and
the state distributed by Eve is the same in every round (c.f. Sect. 3.3.3). In this case,
2 In this context, standard QKD refers to non-DI QKD.
7 Device-Independent Quantum Cryptography
the parties share a quantum entangled state and their measurements are described by
non-commuting observables (e.g., [A 0 , A 1 ] = 0) [21]. One can thus interpret Bell
inequalities—and violation thereof—as device-independent entanglement witnesses
[3].
An important property of entanglement, called monogamy of entanglement [31,
32], states that if the quantum systems of two parties, say Alice and Bob, are strongly
entangled, then a third quantum system shares little entanglement with them. Thanks
to this property, upon observing a Bell violation, Alice and Bob are sure that Eve was
poorly entangled with their systems and thus has little information on their outcomes.
Hence the secrecy of the parties’ outcomes is granted. Notably, the monogamy of
correlations is not specific to quantum theory, rather it is present in any no-signaling
theory leading to non-local correlations [21].
7.3.1 DIQKD Security Under Coherent Attacks
Let us now formalize the intuition provided above on the security of DI protocols.
Here we focus on DIQKD protocols, but analogous considerations hold for DICKA
and DIRG protocols.
The Bell violation estimated by the parties while running a DIQKD protocol
only describes, on average, the amount of non-locality characterizing one protocol
round, and in particular a round devoted to the generation of the secret key. This
is enough to make a security statement for one round of the protocol. In particular,
given the observed Bell violation, one can bound the conditional von Neumann
entropy H (R A |E) of Alice’s raw key bit R A given Eve’s side information E, which
we already encountered when computing the secret key rates of QKD protocols (c.f.
Chap. 3). The quantitative trade-off between Bell violation and conditional entropy
is illustrated in Sect. 7.5 for the simplest DIQKD protocol.
However, the validity of the security statement for one round cannot be directly
extended to the whole DI protocol and to all its outputs. The reason is that we consider
the most general scenario where Eve performs coherent attacks, meaning that she
can act differently in the various rounds and so can the devices. In fact, the security of
DIQKD follows the same definitions and results reported in Sect. 3.3 for the security
of general QKD schemes, where the main quantity to be estimated is the smooth minentropy H
ε
min (R
n
A |E) of Alice’s bits R
n
A given the side information available to Eve
(see (3.27)). Here, Eve’s side information includes her quantum system correlated
with the initial state distributed to the parties’ devices, but also the additional side
information generated by the untrusted devices during the process.
In standard QKD,
2 we have discussed the existence of methods —such as the
postselection technique (PST)—which reduce the security proof against coherent
attacks to one against collective attacks, i.e. when the behaviour of the devices and
the state distributed by Eve is the same in every round (c.f. Sect. 3.3.3). In this case,
2 In this context, standard QKD refers to non-DI QKD.
