120
7 Device-Independent Quantum Cryptography
By the argument above,
4 we can be express the conditional entropy H (R A |E tot )
as follows:
H (R A |E tot ) =
α
p α H (R A |E = α)
=
α
p α H (R A |E) ρ α ,
(7.34)
where H (R A |E) ρ α is the conditional entropy of Alice’s raw key bit given that Eve
distributed the state ρ α . Similarly, the observed violation S can be written as:
S =
α
p α S α ,
(7.35)
where S α is the violation that the parties would observe if they were given the state
ρ α in each round.
We can then focus on deriving a lower bound on H (X |E) ρ α :
H (R A |E) ρ α ≥ F(S α ),
(7.36)
where F is a convex function of the violation S α . Indeed, by combining (7.34), (7.35),
(7.36) and the convexity of F, we get the desired lower bound on H (R A |E tot ) as a
function of the observed violation S:
H (R A |E tot ) ≥ F(S).
(7.37)
Remark 7.1 The task is reduced to minimizing the conditional entropy H (R A |E) ρ α
over all the states ρ α of the form (7.31) (Theorem 7.1), whose CHSH violation S α is
upper bounded by (7.33) (Theorem 7.2). In doing so, we obtain an explicit expression
for F(S α ) in (7.36).
We start by providing Eve with the maximum amount of side information (as
in every QKD protocol) by assuming that the state on H A ⊗ H B ⊗ H E is pure, i.e.
Eve holds the purifying system of ρ α . Considering that ρ α is written in its spectral
decomposition in (7.31), we have the following pure state on H A ⊗ H B ⊗ H E :
|φ
α
AB E =
1
i, j=0
λ
α
i j |ψ i j ⊗ |e i j ,
(7.38)
where {|e i j }
1
i, j=0 is an orthonormal basis in H E .
4 As a matter of fact, the quantum state on which H (R A |E tot ) is computed is a c.q. state derived from
(7.76), which is given in the proof of Theorem 7.1. Recall the formula to compute the conditional
entropy of c.q. states: (2.52).
7 Device-Independent Quantum Cryptography
By the argument above,
4 we can be express the conditional entropy H (R A |E tot )
as follows:
H (R A |E tot ) =
α
p α H (R A |E = α)
=
α
p α H (R A |E) ρ α ,
(7.34)
where H (R A |E) ρ α is the conditional entropy of Alice’s raw key bit given that Eve
distributed the state ρ α . Similarly, the observed violation S can be written as:
S =
α
p α S α ,
(7.35)
where S α is the violation that the parties would observe if they were given the state
ρ α in each round.
We can then focus on deriving a lower bound on H (X |E) ρ α :
H (R A |E) ρ α ≥ F(S α ),
(7.36)
where F is a convex function of the violation S α . Indeed, by combining (7.34), (7.35),
(7.36) and the convexity of F, we get the desired lower bound on H (R A |E tot ) as a
function of the observed violation S:
H (R A |E tot ) ≥ F(S).
(7.37)
Remark 7.1 The task is reduced to minimizing the conditional entropy H (R A |E) ρ α
over all the states ρ α of the form (7.31) (Theorem 7.1), whose CHSH violation S α is
upper bounded by (7.33) (Theorem 7.2). In doing so, we obtain an explicit expression
for F(S α ) in (7.36).
We start by providing Eve with the maximum amount of side information (as
in every QKD protocol) by assuming that the state on H A ⊗ H B ⊗ H E is pure, i.e.
Eve holds the purifying system of ρ α . Considering that ρ α is written in its spectral
decomposition in (7.31), we have the following pure state on H A ⊗ H B ⊗ H E :
|φ
α
AB E =
1
i, j=0
λ
α
i j |ψ i j ⊗ |e i j ,
(7.38)
where {|e i j }
1
i, j=0 is an orthonormal basis in H E .
4 As a matter of fact, the quantum state on which H (R A |E tot ) is computed is a c.q. state derived from
(7.76), which is given in the proof of Theorem 7.1. Recall the formula to compute the conditional
entropy of c.q. states: (2.52).
