126
7 Device-Independent Quantum Cryptography
Definition 7.1 The GHZ basis is composed of the following 2
N states:
|ψ σ,u =
1
√
2
(|0|u + (−1)
σ
|1| ¯
u) ,
(7.57)
where σ ∈ {0, 1} while u ∈ {0, 1}
N −1 and ¯
u = 1 ⊕ u are (N − 1)-bit strings.
We can now state the generalization of Theorem 7.1 to an (N , 2, 2) Bell scenario.
Theorem 7.3 ([42]). Consider N parties testing an (N , 2, 2) full-correlator Bell
inequality. It is not restrictive to assume that, in each round, Eve distributes a mixture
α p α ρ α of N -qubit states ρ α , together with a flag |α (known to her) which
determines the measurements performed on ρ α given the parties’ inputs. Without
loss of generality, the measurements performed by each device on ρ α are rank-one
binary projective measurements in the (x, y)-plane of the Bloch sphere. Moreover,
each state ρ α is diagonal in the GHZ basis, except for some purely imaginary offdiagonal terms:
ρ α =
u∈{0,1} N −1
λ
α
0u |ψ 0,u ψ 0,u | + λ
α
1u |ψ 1,u ψ 1,u | + is
α
u
|ψ 0,u ψ 1,u | − |ψ 1,u ψ 0,u |
.
(7.58)
Finally, N arbitrary off-diagonal terms s
α
u can be assumed to be zero and the corresponding diagonal elements (λ
α
0u , λ
α
1u ) can be arbitrarily ordered (e.g., λ
α
0u ≥ λ
α
1u ).
We remark that Theorem 7.3 reduces to Theorem 7.1 when one considers the
CHSH Bell scenario (N = 2).
The second main tool to derive conditional entropy bounds is an analytical expression for the maximal violation of the considered Bell inequality achievable by a given
state (e.g., Theorem 7.2 in Sect. 7.5). In [42] we derive such a result for a specific
(N , 2, 2) full-correlator inequality, namely the Mermin-Ardehali-Belinskii-Klyshko
(MABK) inequality [46–48]. The MABK inequality is a multiparty generalization
of the CHSH inequality and is obtained on the following MABK operator.
Definition 7.2 The MABK operator M N is defined by recursion [49, 50]:
M 2 = G CHSH (A
(1)
0 , A
(1)
1 , A
(2)
0 , A
(2)
1 )
≡ A
(1)
0 ⊗ A
(2)
0 + A
(1)
0 ⊗ A
(2)
1 + A
(1)
1 ⊗ A
(2)
0 − A
(1)
1 ⊗ A
(2)
1
M N =
1
2
G CHSH (M N −1 , M N −1 , A
(N )
0 , A
(N )
1 ),
(7.59)
where A
(i)
x (i = 0, 1) is the x-th binary observable of Alice i and where M l is the
operator obtained from M l by replacing every observable A
(i)
x with A
(i)
1−x .
7 Device-Independent Quantum Cryptography
Definition 7.1 The GHZ basis is composed of the following 2
N states:
|ψ σ,u =
1
√
2
(|0|u + (−1)
σ
|1| ¯
u) ,
(7.57)
where σ ∈ {0, 1} while u ∈ {0, 1}
N −1 and ¯
u = 1 ⊕ u are (N − 1)-bit strings.
We can now state the generalization of Theorem 7.1 to an (N , 2, 2) Bell scenario.
Theorem 7.3 ([42]). Consider N parties testing an (N , 2, 2) full-correlator Bell
inequality. It is not restrictive to assume that, in each round, Eve distributes a mixture
α p α ρ α of N -qubit states ρ α , together with a flag |α (known to her) which
determines the measurements performed on ρ α given the parties’ inputs. Without
loss of generality, the measurements performed by each device on ρ α are rank-one
binary projective measurements in the (x, y)-plane of the Bloch sphere. Moreover,
each state ρ α is diagonal in the GHZ basis, except for some purely imaginary offdiagonal terms:
ρ α =
u∈{0,1} N −1
λ
α
0u |ψ 0,u ψ 0,u | + λ
α
1u |ψ 1,u ψ 1,u | + is
α
u
|ψ 0,u ψ 1,u | − |ψ 1,u ψ 0,u |
.
(7.58)
Finally, N arbitrary off-diagonal terms s
α
u can be assumed to be zero and the corresponding diagonal elements (λ
α
0u , λ
α
1u ) can be arbitrarily ordered (e.g., λ
α
0u ≥ λ
α
1u ).
We remark that Theorem 7.3 reduces to Theorem 7.1 when one considers the
CHSH Bell scenario (N = 2).
The second main tool to derive conditional entropy bounds is an analytical expression for the maximal violation of the considered Bell inequality achievable by a given
state (e.g., Theorem 7.2 in Sect. 7.5). In [42] we derive such a result for a specific
(N , 2, 2) full-correlator inequality, namely the Mermin-Ardehali-Belinskii-Klyshko
(MABK) inequality [46–48]. The MABK inequality is a multiparty generalization
of the CHSH inequality and is obtained on the following MABK operator.
Definition 7.2 The MABK operator M N is defined by recursion [49, 50]:
M 2 = G CHSH (A
(1)
0 , A
(1)
1 , A
(2)
0 , A
(2)
1 )
≡ A
(1)
0 ⊗ A
(2)
0 + A
(1)
0 ⊗ A
(2)
1 + A
(1)
1 ⊗ A
(2)
0 − A
(1)
1 ⊗ A
(2)
1
M N =
1
2
G CHSH (M N −1 , M N −1 , A
(N )
0 , A
(N )
1 ),
(7.59)
where A
(i)
x (i = 0, 1) is the x-th binary observable of Alice i and where M l is the
operator obtained from M l by replacing every observable A
(i)
x with A
(i)
1−x .
