134
7 Device-Independent Quantum Cryptography
The observables of Alice 2 and Alice 3 , A
( j)
x = α
( j)
x · σ (where j = 2, 3 and σ =
(X, Y, Z )), are qubit projective measurements
11 whose directions in the Bloch sphere
are identified by the unit vectors α
( j)
x . Then, the non-normalized observables A
( j)
+
and A
( j)
− read:
A
( j)
± = α
( j)
± · σ , α
( j)
± :=
α
( j)
0 ± α
( j)
1
2
(7.71)
and are characterized by orthogonal measurement directions α
( j)
+ ⊥ α
( j)
− and by normalizations which depend on each other:
α
( j)
+
2 +
α
( j)
−
2 = 1. These constraints
must be taken into account when looking for the optimal observables leading to a
maximal violation of (7.69).
Starting from the form of the inequality in (7.69), we can easily guess the optimal
measurements to be performed on the GHZ state. In doing so, we follow the principle
(see Eq. 7.22) that the resulting inequality should be only composed of correlators of
the GHZ stabilizers (7.70). Note that the terms in (7.69) which are not full-correlators
allow us to use the GHZ stabilizers containing the Z and the identity operator, without
introducing the identity as one of the parties’ observables. In this way we can impose
that one of Alice 1 ’s optimal observables is Z , which is necessary to achieve perfect
correlations with the other parties in the KG rounds.
For the arguments above, we choose the following optimal observables:
A
(1)
0 = Z , A
(1)
1 = X
A
( j)
− = −
1
2
Z , A
( j)
+ =
√
3
2
X ( j = 2, 3),
(7.72)
where A
( j)
+ and A
( j)
− have orthogonal directions and Alice 1 ’s optimal observable A
(1)
0
is the Z operator. By substituting the optimal observables in (7.69) we obtain the
maximal quantum violation:
3
4
X X X +
1
2
Z Z +
1
2
Z Z −
1
4
Z Z =
3
2
> 1
(7.73)
where all the terms of the inequality are indeed proportional to correlators of the
GHZ stabilizers, which yield the value 1 when evaluated on the GHZ state.
The authors in [10] investigate the performance of the DICKA protocol based
on the illustrated inequality. The security of the protocol is proven by bounding
the single-round von Neumann entropy H (R A |E) as a function of the violation with
rather loose numerical techniques [4, 39]. This inevitably leads to a poor performance
of the conference key rate. A solution to this problem would be to derive tighter
analytical bound on H (R A |E) similarly to what is done in [42] and possibly using
11 We can restrict to qubit projective measurements since the Bell inequality has two inputs with
binary outputs for each party.
7 Device-Independent Quantum Cryptography
The observables of Alice 2 and Alice 3 , A
( j)
x = α
( j)
x · σ (where j = 2, 3 and σ =
(X, Y, Z )), are qubit projective measurements
11 whose directions in the Bloch sphere
are identified by the unit vectors α
( j)
x . Then, the non-normalized observables A
( j)
+
and A
( j)
− read:
A
( j)
± = α
( j)
± · σ , α
( j)
± :=
α
( j)
0 ± α
( j)
1
2
(7.71)
and are characterized by orthogonal measurement directions α
( j)
+ ⊥ α
( j)
− and by normalizations which depend on each other:
α
( j)
+
2 +
α
( j)
−
2 = 1. These constraints
must be taken into account when looking for the optimal observables leading to a
maximal violation of (7.69).
Starting from the form of the inequality in (7.69), we can easily guess the optimal
measurements to be performed on the GHZ state. In doing so, we follow the principle
(see Eq. 7.22) that the resulting inequality should be only composed of correlators of
the GHZ stabilizers (7.70). Note that the terms in (7.69) which are not full-correlators
allow us to use the GHZ stabilizers containing the Z and the identity operator, without
introducing the identity as one of the parties’ observables. In this way we can impose
that one of Alice 1 ’s optimal observables is Z , which is necessary to achieve perfect
correlations with the other parties in the KG rounds.
For the arguments above, we choose the following optimal observables:
A
(1)
0 = Z , A
(1)
1 = X
A
( j)
− = −
1
2
Z , A
( j)
+ =
√
3
2
X ( j = 2, 3),
(7.72)
where A
( j)
+ and A
( j)
− have orthogonal directions and Alice 1 ’s optimal observable A
(1)
0
is the Z operator. By substituting the optimal observables in (7.69) we obtain the
maximal quantum violation:
3
4
X X X +
1
2
Z Z +
1
2
Z Z −
1
4
Z Z =
3
2
> 1
(7.73)
where all the terms of the inequality are indeed proportional to correlators of the
GHZ stabilizers, which yield the value 1 when evaluated on the GHZ state.
The authors in [10] investigate the performance of the DICKA protocol based
on the illustrated inequality. The security of the protocol is proven by bounding
the single-round von Neumann entropy H (R A |E) as a function of the violation with
rather loose numerical techniques [4, 39]. This inevitably leads to a poor performance
of the conference key rate. A solution to this problem would be to derive tighter
analytical bound on H (R A |E) similarly to what is done in [42] and possibly using
11 We can restrict to qubit projective measurements since the Bell inequality has two inputs with
binary outputs for each party.
