136
7 Device-Independent Quantum Cryptography
not fixed, we can assume without loss of generality (w.l.o.g.) that Alice and Bob
perform binary projective measurements on their share of the quantum state.
Now we make use of a preliminary result derived in [3], which we extend and
detail in [42]. The result states that the Hilbert space on which Alice’s two projective
measurements, corresponding to inputs x = 0, 1, are acting can be decomposed into
the following direct sum (indicated by ⊕) of Hilbert spaces:
H = ⊕ α H
2
α ,
(7.75)
where every subspace H
2
α is two-dimensional (qubit space) and both Alice’s measurements act within H
2
α as rank-one projective measurements.
12 Therefore, from
Alice’s perspective, the measurement process in one round consists of a projection
in one of the two-dimensional subspaces H
2
α , followed by a projective measurement
in that subspace selected according to her input. For this reason, we can think that Eve
is effectively distributing to Alice a direct sum of qubits at every round. Moreover,
since Eve fabricates the measurement devices, she can preprogram the projective
measurements that Alice can select on every qubit. By repeating the same argument
for Bob, we deduce that Eve effectively distributes a direct sum of two-qubit states
in each round.
Now, consider that it cannot be detrimental for Eve to learn the value α corresponding to the two-qubit space selected in a particular round by Alice’s and Bob’s
measurements. Hence, we can assume that Eve directly sends to the parties the twoqubit state ρ α relative to the two-qubit space the parties would select. Since the
selection of the two-qubit space can be random, Eve sends a statistical mixture of
states ρ α . Furthermore, since she could have preprogrammed the devices to perform
specific measurements upon selecting a given subspace, together with the state ρ α she
sends a flag |α to Alice and Bob’s devices to instruct them on which measurement
to perform on the state ρ α . In conclusion, in every round Eve prepares the following
mixture of two-qubit states ρ α :
ρ AB =
α p α ρ α ⊗ |αα | ξ A ⊗ |αα | ξ B ,
(7.76)
where the two ancillae := {ξ A , ξ B } fix the qubit measurements that Alice and
Bob can select on ρ α . This can be modelled for instance by defining Alice’s qubit
measurement A x as follows (and similarly Bob’s):
A x =
α
x,α
+1 −
x,α
−1
⊗ |αα | ξ A ,
(7.77)
12 Note that a binary projective measurement on a qubit can also be of rank-two and corresponds to
the identity as observable. In this case one outcome has probability 1 to occur and the other outcome
never occurs. This possibility was originally neglected in [3] since measuring the identity cannot
lead to a CHSH violation, as pointed out by [43]. However, the identity might lead to violations of
multipartite Bell inequalities such as the MABK inequality we consider in [42]. In [42] we show
how one can restrict to rank-one projective measurements, thus excluding the identity, without loss
of generality.
Précédent

- 147/163

Suivant