130
7 Device-Independent Quantum Cryptography
necessary for a successful implementation of a DICKA protocol. Conversely, it has
been shown that GME is not necessary to perform a device-dependent CKA protocol
[54].
The lower bound on the von Neumann entropy H (R A R B |E) is plotted in Fig. 7.4
together with a tight lower bound on the correspondent min-entropy
8 H min (R A R B |E),
given by [53]:
H min (R A R B |E) ≥ − log p
↑
guess (R A R B |E)
(7.66)
where p
↑
guess (R A R B |E) is a tight upper bound on Eve’s joint guessing probability of
R A and R B :
p
↑
guess (R A R B |E) =
3
4
−
S
8
+
√
3
S
8
1
2
−
S
8
if S > 3
3
2
−
S
4
if S ≤ 3.
(7.67)
Fig. 7.4 confirms that there is a significant improvement in certifying the privacy of
Alice and Bob’s outcomes, from a given MABK violation, with the bound on the von
Neumann entropy (7.64), as opposed to using the more accessible min-entropy (7.66).
This has a direct impact on the performance of DI (global) randomness generation
protocols, since it increases the fraction of generated random bits proved to be secret.
The last observation demonstrates the potential of the analytical approach [42]
in bounding the von Neumann entropies of interest in DI protocols. In particular,
the developed techniques could pave the way for similar results valid for the Bell
inequalities employed in the existing DICKA protocols [9, 10]. In this context, the
derivation of tight analytical bounds on the von Neumann entropy would translate
to tight security proofs—which are still missing—and to increased protocol performance.
7.7 Device-Independent Conference Key Agreement
In this Section we argue on the potential applicability of the conditional entropy
bounds of Sect. 7.6 to the security proofs of DI conference key agreement (DICKA)
protocols. In particular, we investigate the relationship between the structure of fullcorrelator Bell inequalities and the task of DICKA. We conclude the Chapter by
providing an example of multipartite Bell inequality suited to DICKA protocols
[10].
8 We remark that the min-entropy is often used to lower bound the von Neumann entropy in DI
protocols, since it can be directly estimated from the observed statistics of the Bell test [38–41] and
since Eq. (2.56) holds.
Précédent

- 141/163

Suivant