3.2 The BB84 Protocol
39
transmission of a quantum state through the quantum channel. The secret key rate
generally depends on the total number of rounds M performed.
In the following we compute the secret key rate of the BB84 protocol in the asymptotic scenario of infinitely many rounds: M → ∞. This is, of course, an unrealistic
assumption, but it greatly simplifies the math. Moreover, the asymptotic key rate is
often used as a benchmark for the performance of a newly-developed QKD protocol.
The protocol above is presented in prepare-and-measure form, since one party
prepares and sends quantum states while the other measures them. This is typically
what happens in real-life implementations of many QKD protocols. However, when
proving the security of a QKD protocol or computing its key rate, an equivalent
entanglement-based description is much more convenient.
Ideally, in every round of the entanglement-based BB84 protocol the two-qubit
Bell state
|
+
AB =
|00 + |11
√
2
=
| + ++ + | − −−
√
2
(3.7)
is generated, and the two qubits are distributed to Alice and Bob through the quantum
channel. Alice and Bob then measure the received qubit in either the Z or X basis,
obtaining the same outcome if they chose the same basis. This scenario is equivalent
to the prepare-and-measure one since the state Bob receives, conditioned on Alice
measuring e.g., X and obtaining outcome x, is exactly |x where x ∈ {+, −}.
However, in reality Eve could be in total in control of the quantum channel,
distributing a mixed state ρ AB to the parties in every protocol round. We assign to
Eve all the information that can be correlated with the mixed state ρ AB by assuming
that she holds the purifying system E (recall Sect. 2.4.1). That is, the state on A, B
and E is pure: |φ AB E . In this scenario we say that Eve performs a collective attack
and the quantum state representing Alice and Bob’s qubits in the M protocol rounds
is the i.i.d. state ρ
⊗M
AB . The parties detect the presence of Eve from the errors (E Z and
E X ) in the outcomes generated by measuring ρ AB at every round.
There is even a more general scenario where Eve directly distributes the state ρ
M
AB
describing all the M qubit pairs to be measured, of which she holds the purifying
system E, i.e. ρ
M
AB E is pure. In this case Eve is performing a coherent attack, which
is generally more powerful than collective attacks since the states shared by Alice
and Bob in each round can be correlated with past and future rounds—formally, it
holds: ρ
M
AB = ρ
⊗M
AB .
We address the case of coherent attacks in the next Section, where we investigate
the security of QKD when the number of protocol rounds is finite. Conversely, in the
asymptotic regime discussed here, the two attacks are proven to be equivalent (c.f.
Sect. 3.3.3), hence we restrict to collective attacks and focus on one specific protocol
round.
39
transmission of a quantum state through the quantum channel. The secret key rate
generally depends on the total number of rounds M performed.
In the following we compute the secret key rate of the BB84 protocol in the asymptotic scenario of infinitely many rounds: M → ∞. This is, of course, an unrealistic
assumption, but it greatly simplifies the math. Moreover, the asymptotic key rate is
often used as a benchmark for the performance of a newly-developed QKD protocol.
The protocol above is presented in prepare-and-measure form, since one party
prepares and sends quantum states while the other measures them. This is typically
what happens in real-life implementations of many QKD protocols. However, when
proving the security of a QKD protocol or computing its key rate, an equivalent
entanglement-based description is much more convenient.
Ideally, in every round of the entanglement-based BB84 protocol the two-qubit
Bell state
|
+
AB =
|00 + |11
√
2
=
| + ++ + | − −−
√
2
(3.7)
is generated, and the two qubits are distributed to Alice and Bob through the quantum
channel. Alice and Bob then measure the received qubit in either the Z or X basis,
obtaining the same outcome if they chose the same basis. This scenario is equivalent
to the prepare-and-measure one since the state Bob receives, conditioned on Alice
measuring e.g., X and obtaining outcome x, is exactly |x where x ∈ {+, −}.
However, in reality Eve could be in total in control of the quantum channel,
distributing a mixed state ρ AB to the parties in every protocol round. We assign to
Eve all the information that can be correlated with the mixed state ρ AB by assuming
that she holds the purifying system E (recall Sect. 2.4.1). That is, the state on A, B
and E is pure: |φ AB E . In this scenario we say that Eve performs a collective attack
and the quantum state representing Alice and Bob’s qubits in the M protocol rounds
is the i.i.d. state ρ
⊗M
AB . The parties detect the presence of Eve from the errors (E Z and
E X ) in the outcomes generated by measuring ρ AB at every round.
There is even a more general scenario where Eve directly distributes the state ρ
M
AB
describing all the M qubit pairs to be measured, of which she holds the purifying
system E, i.e. ρ
M
AB E is pure. In this case Eve is performing a coherent attack, which
is generally more powerful than collective attacks since the states shared by Alice
and Bob in each round can be correlated with past and future rounds—formally, it
holds: ρ
M
AB = ρ
⊗M
AB .
We address the case of coherent attacks in the next Section, where we investigate
the security of QKD when the number of protocol rounds is finite. Conversely, in the
asymptotic regime discussed here, the two attacks are proven to be equivalent (c.f.
Sect. 3.3.3), hence we restrict to collective attacks and focus on one specific protocol
round.
