132
7 Device-Independent Quantum Cryptography
The above argument implies that in an honest implementation of a DICKA protocol, the distributed quantum state and the chosen Bell inequality are such that the
parties can have highly correlated outputs while violating the Bell inequality. Ideally, in an error-free implementation, it should be possible to maximally violate the
Bell inequality and at the same time observe perfect correlations of the parties’ raw
keys. Indeed, this would maximize the protocol’s asymptotic secret key rate (7.68)
to: r DICKA = 1.
Let us now consider a DICKA protocol based on the violation of a full-correlator
Bell inequality with two binary observables per party. Here we heuristically argue
that, for such DICKA protocols, it is forbidden to simultaneously have maximal Bell
violation in the test rounds and perfect correlations in the KG rounds.
Given that the Bell inequality under consideration has two binary observables per
party, we can restrict the analysis to multi-qubit states (c.f. Sect. 7.5). Then, we recall
from Sect. 4.1 that the only multi-qubit state leading to perfectly correlated outcomes
is the GHZ state (4.1) where every party measures the Pauli operator Z . If a party
instead measures the operator X or Y , she would obtain a completely uncorrelated
outcome. Therefore, we assume that the parties share a GHZ state and in the KG
rounds every party measures the observable Z . In particular, this fixes one of Alice 1 ’s
test-round observables to be Z .
In [44], the authors show that every full-correlator Bell inequality with two binary
observables per party is maximally violated by the GHZ state. However, we argue that
in order to achieve maximal violation, the measurements must be chosen such that
the resulting inequality (after simplifications) is only composed of expectation values
of GHZ stabilizers (e.g., Eq. 7.22). Indeed, they acquire the extremal value 1 when
evaluated on the GHZ state. Moreover, the stabilizers appearing in the inequality
cannot contain the identity operator since that would not generate maximal violation.
We identify these stabilizers as “full-stabilizers”.
Unfortunately, all the observables of every N -partite GHZ state full-stabilizer
(with N odd) are either the X or Y Pauli operators [24]. Therefore, in order to
maximally violate the inequality, Alice 1 ’s test-round observables lie in the (x, y)plane of the Bloch sphere and have null Z component. This requirement collides with
the fact that one of Alice 1 ’s two observables is fixed to Z in order to have perfect
correlations in KG rounds. A similar argument can be made for the N even case.
9
Apparently, perfect correlations and maximal Bell violation are mutually exclusive conditions in any DICKA protocol based on a full-correlator Bell inequality with
two binary observables per party, even for an ideal implementation of the protocol.
We emphasize that this argument, even if proven to be true, does not rule out the
existence of implementations where the parties observe an adequate Bell violation
while having reasonably correlated raw keys. However, it is an open question whether
such implementations exist and lead to non-zero conference key rates.
9 The N = 2 case includes the CHSH inequality that can be violated with Alice measuring Z , as
we have seen in Sect. 7.4.2. However this is a degenerate case due to the low number of parties, as
discussed in [42].
7 Device-Independent Quantum Cryptography
The above argument implies that in an honest implementation of a DICKA protocol, the distributed quantum state and the chosen Bell inequality are such that the
parties can have highly correlated outputs while violating the Bell inequality. Ideally, in an error-free implementation, it should be possible to maximally violate the
Bell inequality and at the same time observe perfect correlations of the parties’ raw
keys. Indeed, this would maximize the protocol’s asymptotic secret key rate (7.68)
to: r DICKA = 1.
Let us now consider a DICKA protocol based on the violation of a full-correlator
Bell inequality with two binary observables per party. Here we heuristically argue
that, for such DICKA protocols, it is forbidden to simultaneously have maximal Bell
violation in the test rounds and perfect correlations in the KG rounds.
Given that the Bell inequality under consideration has two binary observables per
party, we can restrict the analysis to multi-qubit states (c.f. Sect. 7.5). Then, we recall
from Sect. 4.1 that the only multi-qubit state leading to perfectly correlated outcomes
is the GHZ state (4.1) where every party measures the Pauli operator Z . If a party
instead measures the operator X or Y , she would obtain a completely uncorrelated
outcome. Therefore, we assume that the parties share a GHZ state and in the KG
rounds every party measures the observable Z . In particular, this fixes one of Alice 1 ’s
test-round observables to be Z .
In [44], the authors show that every full-correlator Bell inequality with two binary
observables per party is maximally violated by the GHZ state. However, we argue that
in order to achieve maximal violation, the measurements must be chosen such that
the resulting inequality (after simplifications) is only composed of expectation values
of GHZ stabilizers (e.g., Eq. 7.22). Indeed, they acquire the extremal value 1 when
evaluated on the GHZ state. Moreover, the stabilizers appearing in the inequality
cannot contain the identity operator since that would not generate maximal violation.
We identify these stabilizers as “full-stabilizers”.
Unfortunately, all the observables of every N -partite GHZ state full-stabilizer
(with N odd) are either the X or Y Pauli operators [24]. Therefore, in order to
maximally violate the inequality, Alice 1 ’s test-round observables lie in the (x, y)plane of the Bloch sphere and have null Z component. This requirement collides with
the fact that one of Alice 1 ’s two observables is fixed to Z in order to have perfect
correlations in KG rounds. A similar argument can be made for the N even case.
9
Apparently, perfect correlations and maximal Bell violation are mutually exclusive conditions in any DICKA protocol based on a full-correlator Bell inequality with
two binary observables per party, even for an ideal implementation of the protocol.
We emphasize that this argument, even if proven to be true, does not rule out the
existence of implementations where the parties observe an adequate Bell violation
while having reasonably correlated raw keys. However, it is an open question whether
such implementations exist and lead to non-zero conference key rates.
9 The N = 2 case includes the CHSH inequality that can be violated with Alice measuring Z , as
we have seen in Sect. 7.4.2. However this is a degenerate case due to the low number of parties, as
discussed in [42].
