116
7 Device-Independent Quantum Cryptography
Isolated laboratories No information flows in or out Alice’s and Bob’s labs except
for what is established by the protocol, i.e. the state distribution in each round and
the public classical communication between Alice and Bob.
Isolated source The preparation of the states is independent of the measurements
performed on them.
Trusted classical post-processing The classical communication is performed
over a public authenticated channel and the data is processed with trusted computers.
Trusted random number generators Alice and Bob independently possess a
trusted random number generator whose outcomes are only known to the owner.
Note that the complete removal of any of the above assumptions would lead to a
strategy where the key is leaked to Eve [35].
7.4.2 DIQKD Based on the CHSH Inequality
Consider the following DIQKD protocol whose security is based on testing the CHSH
inequality [3, 6]. Alice holds an uncharacterised device with two inputs x ∈ {0, 1} and
two outputs for each input: a x ∈ {−1, 1}. Ideally, upon receiving an input, the device
performs a measurement on Alice’s portion of an entangled state that she shares
with Bob and provides the outcome of the measurement. We emphasize, however,
that we do not specify the implementation when proving the protocol’s security.
Similarly, Bob holds a device with three inputs y ∈ {0, 1, 2} and two outputs per
input b y ∈ {−1, 1}.
Before initiating the protocol, Alice and Bob agree on a set of parameters: the
total number of rounds M, the probability p t ∈ (0, 1) with which they perform a
test round, the expected CHSH value S exp ∈ (2, 2
√
2] and its tolerated statistical
fluctuation δ ∈ (0, 2
√
2 − 2).
The protocol comprises the following steps
3 [36]:
1. Alice and Bob perform a test round with probability p t or a key-generation (KG)
round with probability 1 − p t . The information on which round to perform can
be provided to them by a short preshared key (c.f. Remark 4.2). The total number
of rounds is M.
2. In a test round Alice (Bob) randomly selects an input x ∈ {0, 1} (y ∈ {0, 1}) on
her (his) device and collects the output a x (b y ), i.e. the parties test the CHSH
inequality. In a KG round, Alice (Bob) selects the predefined input x = 1 (y = 2)
and records the output—her (his) raw key bit—in the random variable R A (R B ).
3. In parameter estimation (PE) the parties reveal the inputs and outputs of every
test round to compute the observed CHSH value S:
3 We remark that there exist more sophisticated versions of the same scheme with an improved secret
key rate [6]. However, since we are not interested in investigating the protocol’s performance, we
consider this simplified version.
7 Device-Independent Quantum Cryptography
Isolated laboratories No information flows in or out Alice’s and Bob’s labs except
for what is established by the protocol, i.e. the state distribution in each round and
the public classical communication between Alice and Bob.
Isolated source The preparation of the states is independent of the measurements
performed on them.
Trusted classical post-processing The classical communication is performed
over a public authenticated channel and the data is processed with trusted computers.
Trusted random number generators Alice and Bob independently possess a
trusted random number generator whose outcomes are only known to the owner.
Note that the complete removal of any of the above assumptions would lead to a
strategy where the key is leaked to Eve [35].
7.4.2 DIQKD Based on the CHSH Inequality
Consider the following DIQKD protocol whose security is based on testing the CHSH
inequality [3, 6]. Alice holds an uncharacterised device with two inputs x ∈ {0, 1} and
two outputs for each input: a x ∈ {−1, 1}. Ideally, upon receiving an input, the device
performs a measurement on Alice’s portion of an entangled state that she shares
with Bob and provides the outcome of the measurement. We emphasize, however,
that we do not specify the implementation when proving the protocol’s security.
Similarly, Bob holds a device with three inputs y ∈ {0, 1, 2} and two outputs per
input b y ∈ {−1, 1}.
Before initiating the protocol, Alice and Bob agree on a set of parameters: the
total number of rounds M, the probability p t ∈ (0, 1) with which they perform a
test round, the expected CHSH value S exp ∈ (2, 2
√
2] and its tolerated statistical
fluctuation δ ∈ (0, 2
√
2 − 2).
The protocol comprises the following steps
3 [36]:
1. Alice and Bob perform a test round with probability p t or a key-generation (KG)
round with probability 1 − p t . The information on which round to perform can
be provided to them by a short preshared key (c.f. Remark 4.2). The total number
of rounds is M.
2. In a test round Alice (Bob) randomly selects an input x ∈ {0, 1} (y ∈ {0, 1}) on
her (his) device and collects the output a x (b y ), i.e. the parties test the CHSH
inequality. In a KG round, Alice (Bob) selects the predefined input x = 1 (y = 2)
and records the output—her (his) raw key bit—in the random variable R A (R B ).
3. In parameter estimation (PE) the parties reveal the inputs and outputs of every
test round to compute the observed CHSH value S:
3 We remark that there exist more sophisticated versions of the same scheme with an improved secret
key rate [6]. However, since we are not interested in investigating the protocol’s performance, we
consider this simplified version.
