124
7 Device-Independent Quantum Cryptography
state distributed in each round to Alice and Bob is the Bell state |
+
for both
protocols (see (7.15) and (3.7)). In a more realistic scenario, the pure state |
+
undergoes a depolarizing channel (c.f. Sect. 2.5.1) generating the following mixed
state:
ρ AB = q|
+
+
| + (1 − q)
1 A ⊗ 1 B
4
.
(7.53)
We thus assume that in both protocols the state in (7.53) is distributed to Alice and
Bob in every round. Then, in the DIQKD protocol the observed Bell violation reads
S = 2
√
2q when the parties perform the measurements given in (7.21) which are
optimal
6 for the Bell state |
+
.
This leads to the following conditional entropy bound (7.52) for the DIQKD
protocol:
H (R A |E) DIQKD = 1 − h
1
2
+
1
2
2q 2 − 1
.
(7.54)
In the entanglement-based BB84 protocol described in Sect. 3.2, Alice and Bob
perform measurements in the Z basis for key generation and in the X basis to estimate
Eve’s knowledge. The QBER in the X basis, given that they share the state in (7.53),
reads: E X = (1 − q)/2. This leads to the following conditional entropy bound (3.24)
for the BB84 protocol:
H (R A |E) BB84 = 1 − h
1 − q
2
.
(7.55)
We emphasize that DIQKD removes most of the assumptions on the measurement
devices that typically hold in a BB84 protocol, where the additional assumptions need
to be verified experimentally. However, the price to pay is a reduced capability of
certifying the privacy of Alice’s bit compared to the BB84 protocol, given that the
parties share the same quantum state.
This is clear from Fig. 7.2, where we plot the conditional entropy bound of the
DIQKD protocol (7.54) and of the BB84 protocol (7.55) as a function of the mixing parameter q of the depolarizing channel. Indeed, in the BB84 protocol Eve’s
uncertainty on Alice’s bit is non-zero as soon as a fraction of the shared state is an
entangled state. Conversely, in the DIQKD protocol Eve’s uncertainty is only certified in the presence of a CHSH violation, which requires a much larger fraction of
entanglement in the shared state (q > 1/
√
2).
6 Note that the maximally mixed state
1 A ⊗1 B
4
in (7.53) does not contribute to the violation S.
7 Device-Independent Quantum Cryptography
state distributed in each round to Alice and Bob is the Bell state |
+
for both
protocols (see (7.15) and (3.7)). In a more realistic scenario, the pure state |
+
undergoes a depolarizing channel (c.f. Sect. 2.5.1) generating the following mixed
state:
ρ AB = q|
+
+
| + (1 − q)
1 A ⊗ 1 B
4
.
(7.53)
We thus assume that in both protocols the state in (7.53) is distributed to Alice and
Bob in every round. Then, in the DIQKD protocol the observed Bell violation reads
S = 2
√
2q when the parties perform the measurements given in (7.21) which are
optimal
6 for the Bell state |
+
.
This leads to the following conditional entropy bound (7.52) for the DIQKD
protocol:
H (R A |E) DIQKD = 1 − h
1
2
+
1
2
2q 2 − 1
.
(7.54)
In the entanglement-based BB84 protocol described in Sect. 3.2, Alice and Bob
perform measurements in the Z basis for key generation and in the X basis to estimate
Eve’s knowledge. The QBER in the X basis, given that they share the state in (7.53),
reads: E X = (1 − q)/2. This leads to the following conditional entropy bound (3.24)
for the BB84 protocol:
H (R A |E) BB84 = 1 − h
1 − q
2
.
(7.55)
We emphasize that DIQKD removes most of the assumptions on the measurement
devices that typically hold in a BB84 protocol, where the additional assumptions need
to be verified experimentally. However, the price to pay is a reduced capability of
certifying the privacy of Alice’s bit compared to the BB84 protocol, given that the
parties share the same quantum state.
This is clear from Fig. 7.2, where we plot the conditional entropy bound of the
DIQKD protocol (7.54) and of the BB84 protocol (7.55) as a function of the mixing parameter q of the depolarizing channel. Indeed, in the BB84 protocol Eve’s
uncertainty on Alice’s bit is non-zero as soon as a fraction of the shared state is an
entangled state. Conversely, in the DIQKD protocol Eve’s uncertainty is only certified in the presence of a CHSH violation, which requires a much larger fraction of
entanglement in the shared state (q > 1/
√
2).
6 Note that the maximally mixed state
1 A ⊗1 B
4
in (7.53) does not contribute to the violation S.
