44
3 Introducing Quantum Key Distribution
insecure
quantum channel
authenƟcated public channel
Alice
Eve
0101100…
Bob
1001110…
Fig. 3.1 Schematic representation of the setup of an entanglement-based QKD protocol, from a
security perspective. In each round, Eve may distribute a quantum signal to Alice and Bob through
the quantum channel. Alice and Bob locally measure the incoming signal with a randomly-chosen
measurement setting and record the classical output. After the transmission of quantum signals
is over, the parties communicate via the classical public channel to perform error correction and
privacy amplification
local measurements on each signal received and collect the classical outcomes.
Depending on the protocol, Alice and Bob can randomly choose among certain
measurement settings. Typically, one setting is chosen with higher probability
and is used for key generation, while the other(s) form the test rounds.
2. In PE, the parties reveal the settings and the outcomes of the test rounds, as well
as the outcomes of a random sample of key-generation rounds. This information
is used to estimate the noise in the quantum channel (and thus Eve’s knowledge).
If the noise is above a certain threshold, the protocol aborts.
3. At this point, both Alice and Bob hold a string of n < M partially correlated
key bits forming their raw key, denoted R
n
A and R
n
B , respectively. The parties
perform an EC procedure in order for Bob to compute a guess ˆ
R
n
A of Alice’s raw
key. In doing so, they reveal leak EC bits of information over the public channel.
In order to verify if EC was successful, Alice computes a hash h A (bitstring)
of length log(1/ε EC ) from her raw key R
n
A by applying a randomly-picked
two-universal hash function (Definition 2.11). She publicly announces the hash
function and h A . Bob uses Alice’s hash function to compute the hash h B from his
guess ˆ
R
n
A . If h A = h B , the protocol aborts. The total amount of information about
Alice’s raw key R
n
A revealed during EC is thus given by: leak EC + +log(1/ε EC ) ≤
leak EC + log(2/ε EC ).
4. In PA, Alice randomly picks another two-universal hash function and communicates it to Bob over the public channel. Both Alice and Bob apply the two-universal
hash function to their error-corrected keys R
n
A and ˆ
R
n
A and obtain shorter, secret
keys s A and s B of length . The final key length is chosen such that:
≤ H
ε
min (R
n
A |E) − leak EC − log
2
ε EC
− 2 log
1
2 ε PA
,
(3.27)
Précédent

- 56/163

Suivant