40
3 Introducing Quantum Key Distribution
3.2.1 Secret Key Rate
The asymptotic secret key rate of any QKD protocol with one-way EC is given by
the Devetak-Winter rate [8]:
r DW = H (R A : R B ) − H (R A : E),
(3.8)
which can be recast in the more familiar form [9–11]:
r = H (R A |E) − H (R A |R B ),
(3.9)
by using the definition of mutual information (c.f. Sect. 2.6). Recall that R A and R B
are the random variables representing Alice’s and Bob’s raw key bit.
An intuitive explanation of the key rate expression (3.8) is the following. The
fraction of secret bits shared by Alice and Bob per round is quantified by the amount
of information that their raw key bits have in common H (R A : R B ) minus the information that Eve gained on Alice’s key bit H (R A : E).
We now compute explicitly the key rate in (3.9) for the BB84 protocol, in terms of
the observed quantities E Z and E X . For simplicity, in the computation we consider
an asymmetric version of the BB84 protocol where the raw key is only extracted
from Z basis measurements, while the X outcomes are used for PE (together with a
fraction of Z outcomes).
The entropies in the key rate expression are computed on the c.c.q. state ρ R A R B E
resulting after Alice and Bob measured their qubit in the Z basis to generate the
raw key bits R A and R B , respectively. Alice and Bob’s projective measurements are
represented by the quantum maps E R A and E R B such that the state ρ R A R B E reads:
ρ R A R B E = (E R A ⊗ E R B ⊗ 1 E )|φ AB E φ AB E |
=
1
a,b=0
(P |a ⊗ P |b ⊗ 1 E )|φ AB E φ AB E |(P |a ⊗ P |b ⊗ 1 E ),
(3.10)
where P |a = |aa | and similarly P |b are rank-one projectors on the Z basis, i.e.
|a, |b ∈ {|0, |1}. We remark that we restricted without loss of generality to collective attacks where |φ AB E represents the global state in a generic round of the
protocol.
We start the key rate computation by assuming without loss of generality (w.l.o.g.)
that, before distributing the state ρ AB to the parties, Eve applies to it the maps D 1
and D 2 , defined by:
D i (ρ AB ) =
1
2
ρ AB +
1
2
D i ρ AB D
†
i
i = 1, 2,
(3.11)
where the operators D i read:
3 Introducing Quantum Key Distribution
3.2.1 Secret Key Rate
The asymptotic secret key rate of any QKD protocol with one-way EC is given by
the Devetak-Winter rate [8]:
r DW = H (R A : R B ) − H (R A : E),
(3.8)
which can be recast in the more familiar form [9–11]:
r = H (R A |E) − H (R A |R B ),
(3.9)
by using the definition of mutual information (c.f. Sect. 2.6). Recall that R A and R B
are the random variables representing Alice’s and Bob’s raw key bit.
An intuitive explanation of the key rate expression (3.8) is the following. The
fraction of secret bits shared by Alice and Bob per round is quantified by the amount
of information that their raw key bits have in common H (R A : R B ) minus the information that Eve gained on Alice’s key bit H (R A : E).
We now compute explicitly the key rate in (3.9) for the BB84 protocol, in terms of
the observed quantities E Z and E X . For simplicity, in the computation we consider
an asymmetric version of the BB84 protocol where the raw key is only extracted
from Z basis measurements, while the X outcomes are used for PE (together with a
fraction of Z outcomes).
The entropies in the key rate expression are computed on the c.c.q. state ρ R A R B E
resulting after Alice and Bob measured their qubit in the Z basis to generate the
raw key bits R A and R B , respectively. Alice and Bob’s projective measurements are
represented by the quantum maps E R A and E R B such that the state ρ R A R B E reads:
ρ R A R B E = (E R A ⊗ E R B ⊗ 1 E )|φ AB E φ AB E |
=
1
a,b=0
(P |a ⊗ P |b ⊗ 1 E )|φ AB E φ AB E |(P |a ⊗ P |b ⊗ 1 E ),
(3.10)
where P |a = |aa | and similarly P |b are rank-one projectors on the Z basis, i.e.
|a, |b ∈ {|0, |1}. We remark that we restricted without loss of generality to collective attacks where |φ AB E represents the global state in a generic round of the
protocol.
We start the key rate computation by assuming without loss of generality (w.l.o.g.)
that, before distributing the state ρ AB to the parties, Eve applies to it the maps D 1
and D 2 , defined by:
D i (ρ AB ) =
1
2
ρ AB +
1
2
D i ρ AB D
†
i
i = 1, 2,
(3.11)
where the operators D i read:
