7.3 From Bell Violation to Security
115
one can focus on proving the security of one protocol round by using the asymptotic
equipartition property (AEP) (c.f. (2.63)), which links the min-entropy of an i.i.d.
state to the von Neumann entropy of one of its copies.
However, the methods used in standard QKD are not applicable to DIQKD. Recall,
for instance, that the PST requires the knowledge of the Hilbert space dimension of
the parties’ systems, which is clearly not known in DIQKD.
Nevertheless, an important result named entropy accumulation theorem (EAT) [6,
33, 34] allows us to link the security of the whole DIQKD scheme to the security of
one round and can be seen as a generalization of the AEP valid for non-i.i.d. rounds.
In particular, the protocol rounds considered by EAT are such that the key bit R
(i)
A
generated in the i-th round can also depend on what happened in all the previous
rounds, but not on the future rounds, which is a meaningful assumption in sequential
DIQKD protocols. According to EAT, the amount of entropy accumulated during the
described sequential processes, i.e. the smooth min-entropy H
ε
min (R
n
A |E), is at least
n times the conditional von Neumann entropy of one round H (R A |E) evaluated over
the observed Bell violation (up to correction factors of order
√
n).
Therefore, our discussion will now focus on quantitatively connecting the conditional von Neumann entropy of one protocol round with the Bell violation observed
in the Bell test. In the next two Sections we explore this relationship in the context
of the simplest example of a DIQKD protocol.
Finally, we remark that these considerations similarly hold for DIRG protocols,
where a secret random bitstring is extracted from the collected outcomes of one party
or more parties, who can be co-located—e.g., located in the same laboratory.
7.4 Device-Independent QKD
In this Section we summarize the assumptions that still hold in any bipartite DI
protocol (the generalization to more parties is straightforward). We then illustrate
the most common DIQKD protocol, which is based on the violation of the CHSH
inequality [23]. In the next Section we prove the protocol’s security by deriving a
lower bound on the conditional von Neumann entropy of one round as a function of
the observed CHSH violation.
7.4.1 Assumptions
Despite the fact that in a DI scenario no assumption is made on the quantum state
shared by the parties, nor on its dimension and measurement, there are still some
unavoidable assumptions in place [35]. Here we list them:
115
one can focus on proving the security of one protocol round by using the asymptotic
equipartition property (AEP) (c.f. (2.63)), which links the min-entropy of an i.i.d.
state to the von Neumann entropy of one of its copies.
However, the methods used in standard QKD are not applicable to DIQKD. Recall,
for instance, that the PST requires the knowledge of the Hilbert space dimension of
the parties’ systems, which is clearly not known in DIQKD.
Nevertheless, an important result named entropy accumulation theorem (EAT) [6,
33, 34] allows us to link the security of the whole DIQKD scheme to the security of
one round and can be seen as a generalization of the AEP valid for non-i.i.d. rounds.
In particular, the protocol rounds considered by EAT are such that the key bit R
(i)
A
generated in the i-th round can also depend on what happened in all the previous
rounds, but not on the future rounds, which is a meaningful assumption in sequential
DIQKD protocols. According to EAT, the amount of entropy accumulated during the
described sequential processes, i.e. the smooth min-entropy H
ε
min (R
n
A |E), is at least
n times the conditional von Neumann entropy of one round H (R A |E) evaluated over
the observed Bell violation (up to correction factors of order
√
n).
Therefore, our discussion will now focus on quantitatively connecting the conditional von Neumann entropy of one protocol round with the Bell violation observed
in the Bell test. In the next two Sections we explore this relationship in the context
of the simplest example of a DIQKD protocol.
Finally, we remark that these considerations similarly hold for DIRG protocols,
where a secret random bitstring is extracted from the collected outcomes of one party
or more parties, who can be co-located—e.g., located in the same laboratory.
7.4 Device-Independent QKD
In this Section we summarize the assumptions that still hold in any bipartite DI
protocol (the generalization to more parties is straightforward). We then illustrate
the most common DIQKD protocol, which is based on the violation of the CHSH
inequality [23]. In the next Section we prove the protocol’s security by deriving a
lower bound on the conditional von Neumann entropy of one round as a function of
the observed CHSH violation.
7.4.1 Assumptions
Despite the fact that in a DI scenario no assumption is made on the quantum state
shared by the parties, nor on its dimension and measurement, there are still some
unavoidable assumptions in place [35]. Here we list them:
