2.11 Distances and Distinguishability Between Quantum States
29
ρ f (K )E =
s∈S
|ss | ⊗ ρ
s
E , ρ
s
E =
k∈ f −1 (s)
p k ρ
k
E .
(2.73)
Let = log |S| be the number of bits of the secret key S generated by Alice
when applying PA on the state ρ K E . Then the Quantum Leftover Hash Lemma [16]
provides an upper bound on the trace distance between the real state ρ SE F and the
ideal state ω S ⊗ ρ E F as a function of and of the smooth min-entropy of the original
state
4
ρ K E .
Lemma 2.1 (Quantum Leftover Hash Lemma [16]) Let ρ K E be a c.q. state of the
form (2.57). Let ρ SE F be the state (2.72) obtained from ρ K E by applying a random
two-universal hash function on K . Then for every ε
it holds:
T (ρ SE F , ω S ⊗ ρ E F ) ≤ 2ε
+
1
2
2 −H
ε
min (K |E) .
(2.74)
By combining the above Lemma with the requirement that the PA outcome is εindistinguishable from an ideal one (2.70), one obtains an upper bound on the length
of the secret key S in terms of the smooth min-entropy of the original state ρ K E :
≤ H
ε
min (K |E) + 2 − 2 log
1
ε − 2ε ,
(2.75)
The bound (2.75) can be optimized over ε
, with ε
∈ [0, ε/2).
As anticipated, the smooth min entropy possesses an important operational meaning in the field of quantum cryptography (2.75).
Let ρ K E be a c.q. state describing an insecure key K and the eavesdropper’s
quantum side information E. The smooth min-entropy H
ε
min (K |E) quantifies
the bit-length of the ε-indistinguishable secret key extracted from K by PA,
up to corrections of order O(log 1/ε).
Both EC and PA are fundamental tasks in any quantum key distribution (QKD)
protocol. Indeed, as we shall see in the next Chapter, the final secret key length
of a generic QKD protocol is determined by a combination of smooth min- and
max-entropy.
4 We remark that the result in [16] is actually weaker and provides an upper bound on
min σ E F T (ρ SE F , ω S ⊗ σ E F ). Nevertheless, the result stated in Lemma 2.1 is also valid and can
be proven with analogous steps to those of [16].
Précédent

- 42/163

Suivant