7.7 Device-Independent Conference Key Agreement
131
7.7.1 Full-Correlator Bell Inequalities and DICKA
All the results presented in Sect. 7.6 stem from the consideration of a Bell scenario
with two distinctive features: every party can measure two binary observables and
the Bell inequality is only composed of full-correlators. These two features can be
exploited—as in [42]—to drastically simplify the state shared by the parties without
loss of generality and in a DI fashion. While the first feature allows the reduction to
qubits, the second enables further simplifications on the multi-qubit state shared by
the parties (for a reference, see Sect. 7.5).
Here we would like to provide an argument suggesting that any multipartite fullcorrelator Bell inequality with two binary measurements per party—e.g.. the MABK
inequality—seems to be incompatible with the task of DICKA. We stress the fact
that this is still an open question in the scientific community and there is not yet a
formal proof which confirms or disproves the above statement. More details on this
argument can be found in [42].
The secret conference key rate yielded by a generic N -partite DICKA protocol
performed by Alice 1 , …, Alice N , in the asymptotic limit, reads [10, 50]:
r DICKA = H (R A 1 |E) − max
2≤i≤N
H (R A 1 |R A i ).
(7.68)
The second term in (7.68) is due to EC (see Sect. 4.1) and represents the fact that Alice i
for i = 2, . . . , N corrects her raw key to match Alice 1 ’s raw key. The conditional
entropy H (R A 1 |E) quantifies Eve’s uncertainty on Alice 1 ’s key bits, which compose
the secret conference key shared by all the parties after error correction and privacy
amplification. As we discussed in the previous Section, the entropy H (R A 1 |E) can
be bounded when the parties observe a violation of an N -partite Bell inequality.
In light of the key rate expression (7.68), a DICKA protocol is successful (it can
yield a positive key rate) when the following two events take place. The test-round
data leads to a significant violation of a multiparty Bell inequality (H (R A 1 |E) is
large) and the parties’ raw keys are sufficiently correlated (H (R A 1 |R A i ) are small).
In the DIQKD protocol based on the CHSH inequality and illustrated in Sect. 7.4.2,
one of the two test inputs of Alice is also used for key generation (KG), while Bob
has a third additional input only devoted to KG. This fact is necessary in any DIQKD
or DICKA protocol [10, 25]. In a DICKA protocol, we consider that Alice 1 plays
the role of Alice, i.e. she is the only party without an input (observable) exclusively
dedicated to KG.
If even Alice 1 had an additional setting only for KG, Eve—who manufactures
the devices—would be able to distinguish a test round from a KG round on all
the devices. Then, she could equip the devices with a maximally entangled state
and suitable test-round measurements so that the parties would observe a maximal
violation of the Bell inequality under test. Additionally, Eve could preprogram the
devices to always output the same bit when the parties use their KG inputs, so that
they would also have perfectly correlated raw keys. In doing so, Eve would be able
to learn the whole conference key without being noticed.
131
7.7.1 Full-Correlator Bell Inequalities and DICKA
All the results presented in Sect. 7.6 stem from the consideration of a Bell scenario
with two distinctive features: every party can measure two binary observables and
the Bell inequality is only composed of full-correlators. These two features can be
exploited—as in [42]—to drastically simplify the state shared by the parties without
loss of generality and in a DI fashion. While the first feature allows the reduction to
qubits, the second enables further simplifications on the multi-qubit state shared by
the parties (for a reference, see Sect. 7.5).
Here we would like to provide an argument suggesting that any multipartite fullcorrelator Bell inequality with two binary measurements per party—e.g.. the MABK
inequality—seems to be incompatible with the task of DICKA. We stress the fact
that this is still an open question in the scientific community and there is not yet a
formal proof which confirms or disproves the above statement. More details on this
argument can be found in [42].
The secret conference key rate yielded by a generic N -partite DICKA protocol
performed by Alice 1 , …, Alice N , in the asymptotic limit, reads [10, 50]:
r DICKA = H (R A 1 |E) − max
2≤i≤N
H (R A 1 |R A i ).
(7.68)
The second term in (7.68) is due to EC (see Sect. 4.1) and represents the fact that Alice i
for i = 2, . . . , N corrects her raw key to match Alice 1 ’s raw key. The conditional
entropy H (R A 1 |E) quantifies Eve’s uncertainty on Alice 1 ’s key bits, which compose
the secret conference key shared by all the parties after error correction and privacy
amplification. As we discussed in the previous Section, the entropy H (R A 1 |E) can
be bounded when the parties observe a violation of an N -partite Bell inequality.
In light of the key rate expression (7.68), a DICKA protocol is successful (it can
yield a positive key rate) when the following two events take place. The test-round
data leads to a significant violation of a multiparty Bell inequality (H (R A 1 |E) is
large) and the parties’ raw keys are sufficiently correlated (H (R A 1 |R A i ) are small).
In the DIQKD protocol based on the CHSH inequality and illustrated in Sect. 7.4.2,
one of the two test inputs of Alice is also used for key generation (KG), while Bob
has a third additional input only devoted to KG. This fact is necessary in any DIQKD
or DICKA protocol [10, 25]. In a DICKA protocol, we consider that Alice 1 plays
the role of Alice, i.e. she is the only party without an input (observable) exclusively
dedicated to KG.
If even Alice 1 had an additional setting only for KG, Eve—who manufactures
the devices—would be able to distinguish a test round from a KG round on all
the devices. Then, she could equip the devices with a maximally entangled state
and suitable test-round measurements so that the parties would observe a maximal
violation of the Bell inequality under test. Additionally, Eve could preprogram the
devices to always output the same bit when the parties use their KG inputs, so that
they would also have perfectly correlated raw keys. In doing so, Eve would be able
to learn the whole conference key without being noticed.
