7.7 Device-Independent Conference Key Agreement
133
We point out that in [25] the authors have already discussed the apparent incompatibility of the tripartite MABK inequality with the task of DICKA. Indeed, they
show that there exists no implementation such that the parties’ outcomes are perfectly correlated and concurrently the MABK inequality is violated above the GME
threshold, which is a necessary condition to ensure the privacy of the established key
(c.f. Sect. 7.6.1).
In conclusion, the conditional entropy bounds presented in Sect. 7.6 are not likely
to find direct application in the security of DICKA protocols. Nevertheless, since in
DIRG the requirement of perfect correlations is dropped, they can still be employed
in security proofs of DIRG protocols. Moreover, the techniques that led to the entropy
bounds can inspire similar derivations which are relevant for the Bell inequalities
used in current DICKA protocols [9, 10].
7.7.2 A Bell Inequality Tailored to DICKA
We conclude the Chapter by presenting a multipartite Bell inequality specifically
designed to achieve both perfect correlations and maximal violation in an error-free
implementation of a DICKA protocol. The Bell inequality is characterized by two
binary observables per party, like in all the other cases discussed in this book. For
the argument of the previous Subsection, the inequality is not exclusively composed
of full-correlators.
The inequality under consideration has been introduced in [10] for the general
case of N parties and its structure allows it to be maximally violated by an N -partite
GHZ state where one of Alice 1 ’s optimal observables is Z . In this way, Alice 1 ’s
outcomes are perfectly correlated with the other parties’ outcomes, when every party
measures Z in the KG rounds and the parties share a GHZ state.
10
Here we focus on the N = 3 case for simplicity, where we denote the parties as
Alice 1 , Alice 2 and Alice 3 with observables A
(i)
x i
for i = 1, 2, 3 and x i = 0, 1. The
Bell inequality in this case reads:
A
(1)
1 A
(2)
+ A
(3)
+ − −A
(1)
0 A
(2)
− − −A
(1)
0 A
(3)
− − −A
(2)
− A
(3)
− ≤ 1,
(7.69)
where we defined non-normalized observables A
( j)
± = (A
( j)
0 ± A
( j)
1 )/2 for j = 2, 3.
The maximal quantum violation is given by 3/2 and is achieved on the tripartite
GHZ state (2.30). The density operator relative to the tripartite GHZ state |GHZ 3
can be expressed in terms of all its stabilizers, similarly to (7.16), as follows [24]:
|GHZ 3 GHZ 3 | =
1
8
(1 ⊗ 1 ⊗ 1 + Z ⊗ Z ⊗ 1 + Z ⊗ 1 ⊗ Z + 1 ⊗ Z ⊗ Z
+X ⊗ X ⊗ X − X ⊗ Y ⊗ Y − Y ⊗ X ⊗ Y − Y ⊗ Y ⊗ X ) .
(7.70)
10 We recall that all the parties except for Alice 1 are equipped with a third measurement setting only
used for KG.
133
We point out that in [25] the authors have already discussed the apparent incompatibility of the tripartite MABK inequality with the task of DICKA. Indeed, they
show that there exists no implementation such that the parties’ outcomes are perfectly correlated and concurrently the MABK inequality is violated above the GME
threshold, which is a necessary condition to ensure the privacy of the established key
(c.f. Sect. 7.6.1).
In conclusion, the conditional entropy bounds presented in Sect. 7.6 are not likely
to find direct application in the security of DICKA protocols. Nevertheless, since in
DIRG the requirement of perfect correlations is dropped, they can still be employed
in security proofs of DIRG protocols. Moreover, the techniques that led to the entropy
bounds can inspire similar derivations which are relevant for the Bell inequalities
used in current DICKA protocols [9, 10].
7.7.2 A Bell Inequality Tailored to DICKA
We conclude the Chapter by presenting a multipartite Bell inequality specifically
designed to achieve both perfect correlations and maximal violation in an error-free
implementation of a DICKA protocol. The Bell inequality is characterized by two
binary observables per party, like in all the other cases discussed in this book. For
the argument of the previous Subsection, the inequality is not exclusively composed
of full-correlators.
The inequality under consideration has been introduced in [10] for the general
case of N parties and its structure allows it to be maximally violated by an N -partite
GHZ state where one of Alice 1 ’s optimal observables is Z . In this way, Alice 1 ’s
outcomes are perfectly correlated with the other parties’ outcomes, when every party
measures Z in the KG rounds and the parties share a GHZ state.
10
Here we focus on the N = 3 case for simplicity, where we denote the parties as
Alice 1 , Alice 2 and Alice 3 with observables A
(i)
x i
for i = 1, 2, 3 and x i = 0, 1. The
Bell inequality in this case reads:
A
(1)
1 A
(2)
+ A
(3)
+ − −A
(1)
0 A
(2)
− − −A
(1)
0 A
(3)
− − −A
(2)
− A
(3)
− ≤ 1,
(7.69)
where we defined non-normalized observables A
( j)
± = (A
( j)
0 ± A
( j)
1 )/2 for j = 2, 3.
The maximal quantum violation is given by 3/2 and is achieved on the tripartite
GHZ state (2.30). The density operator relative to the tripartite GHZ state |GHZ 3
can be expressed in terms of all its stabilizers, similarly to (7.16), as follows [24]:
|GHZ 3 GHZ 3 | =
1
8
(1 ⊗ 1 ⊗ 1 + Z ⊗ Z ⊗ 1 + Z ⊗ 1 ⊗ Z + 1 ⊗ Z ⊗ Z
+X ⊗ X ⊗ X − X ⊗ Y ⊗ Y − Y ⊗ X ⊗ Y − Y ⊗ Y ⊗ X ) .
(7.70)
10 We recall that all the parties except for Alice 1 are equipped with a third measurement setting only
used for KG.
