3.2 The BB84 Protocol
41
D 1 = X ⊗ X ; D 2 = Z ⊗ Z .
(3.12)
One can easily verify that the resulting state ˜
ρ AB received by Alice and Bob:
˜
ρ AB = (D 1 ◦ D 2 ) ρ AB =
1
4
[ρ AB + (Z ⊗ Z )ρ AB (Z ⊗ Z )
+(X ⊗ X )ρ AB (X ⊗ X ) + (Y ⊗ Y )ρ AB (Y ⊗ Y )]
(3.13)
is diagonal in the Bell basis {|ψ i j }
1
i, j=0 of two qubits, with the same diagonal coefficients of the original state ρ AB . We can thus express ˜
ρ AB in the Bell basis as:
˜
ρ AB =
1
i, j=0
λ i j |ψ i j ψ i j |
(3.14)
for some eigenvalues 0 ≤ λ i j ≤ 1 such that
i, j λ i j = 1, where the states of the Bell
basis read:
|ψ i j =
|0, j + (−1)
i
|1, 1 − j
√
2
,
i, j ∈ {0, 1}.
(3.15)
The assumption that Alice and Bob are given the Bell-diagonal state (3.14) is not
restrictive due to two reasons. First, since the state ˜
ρ AB is prepared by Eve, she
also holds its purification and one can show that her uncertainty on Alice’s key is
not increased when she distributes ˜
ρ AB in place of ρ AB : H (R A |E) ρ ≥ H (R A |E) ˜
ρ .
The interested reader can find the proof of this fact in the Appendix of this Chapter
(Sect. 3.5). The second reason is that from the point of view of the parties, the action
of D 1 ◦ D 2 corresponds to a simultaneous flip of both Alice’s and Bob’s bits, which
occurs with probability 1 /2. This implies that the marginal distributions of Alice’s and
Bob’s raw key bits are symmetrized. However, the observed QBERs are unaffected
4
as well as the correlation of the raw keys of Alice and Bob. Therefore, the only
visible effect is the symmetrization of the marginals. This could be directly enforced
by the parties by agreeing on flipping their outcomes with probability 1 /2, while
communicating over the public channel. Thus Eve would be aware of the flipping.
For the above arguments, Eve distributes w.l.o.g. the state (3.14) to Alice and Bob.
Recall the definitions of the QBERs E Z and E X in terms of probabilities: The
QBER E Z (E X ) is the probability that the Z (X ) measurement outcomes of Alice
and Bob differ. Given that the parties share the state ˜
ρ AB in (3.14), it holds:
E Z = Tr[(P |0 ⊗ P |1 + P |1 ⊗ P |0 ) ˜
ρ AB ] = λ 01 + λ 11
(3.16)
E X = Tr[(P |++ ⊗ P |−− + P |−− ⊗ P |++ ) ˜
ρ AB ] = λ 10 + λ 11 .
(3.17)
4 This is due to the fact that either both Alice’s and Bob’s bits are flipped, or none is.
Précédent

- 53/163

Suivant