128
7 Device-Independent Quantum Cryptography
7.6.1 Conditional Entropy Bounds for Three Parties
Equipped with the results of Theorems 7.3 and 7.4, we are able to obtain analytical
bounds on conditional von Neumann entropies that are relevant for the security of
certain multipartite DI protocols [42].
Specifically, we consider the (3, 2, 2) Bell scenario depicted in Fig. 7.3 where
Alice, Bob and Charlie test the tripartite MABK inequality in order to certify the
privacy of some of their outcomes, by deriving lower bounds on suitable conditional
von Neumann entropies. In particular, we obtain bounds on the conditional von
Neumann entropies H (R A |E) and H (R A R B |E) as a function of the observed MABK
violation S. The bounds derivation is similar to the one described in Sect. 7.5 for two
parties, although it presents additional difficulties due to the increased number of
parties and outcomes [42].
We recall that the entropy H (R A |E) determines the asymptotic rate of secret
random bits generated at Alice’s location by a multiparty DIRG or DICKA protocol
7
[33, 52]. Similarly, the bound on the entropy H (R A R B |E) can represent the rate
at which co-located parties generate DI global randomness from Alice and Bob’s
outcomes [33, 53].
In Fig. 7.4 we plot the lower bounds on H (R A |E) and H (R A R B |E) as a function
of the observed MABK violation S. The analytical expressions corresponding to the
plotted curves are given by [42]:
H (R A |E) ≥ 1 − h
1
2
+
1
2
S 2
8
− 1
(7.63)
H (R A R B |E) ≥ 2 − H ({1 − 3 f (S), f (S), f (S), f (S)}) ,
(7.64)
where h(x) is the binary entropy (c.f. Eq. 2.46), H ({ p x }) is the Shannon entropy of
the probability distribution p x and f (S) is defined as:
f (S) :=
1
4
−
√
3
24
S 2 − 4.
(7.65)
Some comments are due. From Fig. 7.4 we observe that the lower bound on
H (R A |E) is null for violations of the tripartite MABK inequality below the GME
threshold. In [42] we additionally present a lower bound on H (R A |E) when an
arbitrary number of parties N test the N -partite MABK inequality. Even the N -party
bound is null for violations below the N -partite GME threshold.
Given that the bounds on H (R A |E) are tight at the GME threshold, we deduce that
GME is necessary to certify the privacy of a party’s outcome in any DI scenario based
on the MABK inequality. Being the latter a prerequisite of any DICKA protocol (not
necessarily based on the MABK inequality), it is an open question whether GME is
7 In a DICKA protocol, the asymptotic conference key rate is given by H (R A |E) from which one
subtracts the information leaked during error correction.
Précédent

- 139/163

Suivant