2.7 Min- and Max-Entropy
25
2.7.1 Operational Meaning of Min-Entropy
The following operational interpretation of the min-entropy suggests the importance
of this entropy measure for quantum cryptography.
Consider the following adversarial scenario. An honest party, Alice, is in possess
of a random key K that she would like to keep secret. An adversary, Eve, wants to
learn Alice’s key. In order to do so, Eve holds a quantum system E whose state is
correlated with the value of Alice’s key K . This scenario is represented by the c.q.
state:
ρ K E =
k∈K
p k |kk | ⊗ ρ
k
E ,
(2.57)
where {|k} is a orthonormal set of vectors representing Alice’s possible keys
2 and
{ p k } is their probability distribution. Eve attempts to learn the value k of the key by
performing a suitable measurement on her system in state ρ
k
E . Let p guess (K |E) be
the probability that Eve correctly guesses K when using an optimal measurement
strategy, i.e.:
p guess (K |E) = max
{E k }
k∈K
p k Tr[E k ρ
k
E ],
(2.58)
where {E k } are POVM elements of a generic quantum measurement on system E.
Then, the min-entropy of the state (2.57) is related to Eve’s guessing probability
p guess (K |E) by [12]:
H min (K |E) ρ = − log p guess (K |E).
(2.59)
Note that if one removes the conditioning on E, the min-entropy reads H min (K ) =
− log max k p k and can still be linked to the optimal guessing probability. Indeed, in
absence of side information on K , the best guess one can make on its value is the
key k occurring with the highest probability, that is max k p k .
How could Alice use the information on Eve’s guessing probability, i.e. the
min-entropy H min (K |E), in order to increase the secrecy of her key?
We are going to provide the complete answer in Sect. 2.10 with privacy amplification.
Nevertheless, here we provide an intuitive and informal answer.
Assume that the adversarial scenario described above is replicated many times,
where each instance is described by the same c.q. state (2.57). Then, in some cases
Eve correctly guesses Alice’s key K , and in others she does not. In this setting,
the guessing probability p guess (K |E) may be interpreted as the frequency of Eve’s
2 Alice’s keys are encoded in orthogonal states since they are classical bitstrings and therefore
perfectly distinguishable (see Sect. 2.11).
Précédent

- 38/163

Suivant