7.4 Device-Independent QKD
117
S = =a 0 b 0 + +a 0 b 1 + +a 1 b 0 − −a 1 b 1 .
(7.27)
If S < S exp − δ, the protocol aborts. The parties additionally reveal a fraction of
the KG outcomes to estimate the QBER E AB :
E AB = Pr[R A = R B ]
(7.28)
4. The parties perform one-way error correction (EC): Alice discloses some information on her raw key by communicating it to Bob via the classical public
channel. With the information received from Alice, Bob computes a guess of her
raw key. If the EC scheme fails, the protocol aborts.
5. The parties distil two secret keys from their error-corrected raw keys by applying
a privacy amplification (PA) procedure.
In an ideal implementation of the above scheme, the CHSH inequality is maximally violated, implying that Eve has no information on the generated secret key
(Sect. 7.5). In order for this to happen, the parties can e.g.. share the pure Bell state
|
+
(7.15) in each round of the protocol. The measurements of Alice and Bob in
the test rounds are given by (7.21) and are the same used to maximally violate the
CHSH inequality in the example of Sect. 7.1.
In the DIQKD protocol, Bob has an additional setting y = 2 that is only used for
KG. In order for Bob to have his raw key bits R B perfectly correlated with Alice’s,
he must measure the same observable B 2 = Z that Alice measures in a KG round.
Indeed, in a KG round Alice measures A 1 = Z (according to (7.21)) and the outcomes
of two local Z measurements on the Bell state |
+
are perfectly correlated.
As explained in Sect. 7.3, thanks to EAT the security proof of the described DIQKD
protocol in the finite-key scenario is reduced to the computation of the conditional
von Neumann entropy H (R A |E), relative to one protocol round, as a function of the
observed CHSH violation S. Note that, since without violation (S ≤ 2) the estimation
of the entropy H (R A |E) would be H (R A |E) = 0 (see Sect. 7.5), from now one we
refer to S as the CHSH violation rather than the CHSH value.
We point out that the security of the protocol is composable in the sense of the
definition given in Sect. 3.3. However this is true only as far as the devices are not
reused in another run of the protocol [35, 36].
In the asymptotic limit (M → ∞) the finite-key effects become negligible and the
asymptotic secret key rate constitutes an upper bound on the secret key rate achieved
with finite resources [37]. The asymptotic secret key rate of the described DIQKD
protocol coincides with the one of standard QKD protocols (3.9) and reads:
r = H (R A |E) − H (R A |R B ).
(7.29)
The second term in (7.29) is due to the classical information leaked during EC and can
be estimated analogously to standard QKD in terms of the QBER E AB (see (3.25)).
However, differently from standard QKD schemes, here the entropy H (R A |E) is
Précédent

- 128/163

Suivant