118
7 Device-Independent Quantum Cryptography
estimated device-independently as a function of the observed CHSH violation. This
is the content of the next Section.
In a similar fashion, the asymptotic rate of secret bits generated by a DIRG protocol
reads:
r = H (R A |E),
(7.30)
where the term due to EC is removed since the only goal is to produce a secret random
bitstring in one specific location.
7.5 Conditional Entropy Bound
We derive an analytical lower bound on the conditional von Neumann entropy
H (R A |E), relative to the DIQKD protocol of Sect. 7.4, for a given CHSH violation S. This result yields a lower bound on the protocol’s secret key rate both in the
finite-key and asymptotic regimes.
The analytical lower bound on H (R A |E) was first derived in [3]. This fundamental
result allows for analytical expressions of the secret key rates (secret randomness
generation rates) of all the DIQKD (DIRG) protocols based on the CHSH inequality
or reducible to a CHSH violation (e.g., the DICKA protocol in [9]). Indeed, there is
no analytical DIQKD key rate which does not rely on the bound derived in [3].
There are other ways to lower bound H (R A |E) in terms of the violation of a given
Bell inequality, which are employed when an analytical lower bound is not available.
A common procedure is to numerically compute the min-entropy H min (R A |E) [38–
41] and use the fact that the min-entropy is a lower bound of the von Neumann
entropy (see Eq. 2.56). However the bounds derived in this way are fairly loose,
leading to poorly-performing DIQKD schemes.
The critical result derived in [3] is the reduction of the state shared by Alice and
Bob in one round of the protocol to a two-qubit state which is diagonal in the Bell basis
(3.15). Note that this result is derived assuming i.i.d. rounds in the DIQKD protocol
above, i.e. Eve performs collective attacks. Nevertheless, as we discussed, the result
can be applied to proving the protocol’s security in the most general scenario thanks
to EAT.
Theorem 7.1 ([3]). Let Alice and Bob perform the DIQKD protocol described in
Sect. 7.4.2. It is not restrictive to assume that, in each round, Eve distributes a
mixture
α p α ρ α of two-qubit states ρ α , together with a flag |α (known to her) which
determines the measurements performed on ρ α given the parties’ inputs. Without loss
of generality, the measurements performed by Alice’s and Bob’s devices on ρ α are
rank-one binary projective measurements in the (x, y)-plane of the Bloch sphere.
Moreover, each state ρ α is diagonal in the Bell basis (3.15) and reads:
Précédent

- 129/163

Suivant