3.3 Finite-Key Security
45
for some ε, ε EC , ε PA > 0 which depend on the required level of security (see
Subsect. 3.3.2).
The length of the secret key (3.27) is determined by the smooth min-entropy
of Alice’s raw key, as discussed in Sect. 2.10, from which one subtracts the
information leaked to Eve during EC.
The (non-asymptotic) secret key rate of the described protocol is given by:
r = τ
M
,
(3.28)
where τ is the repetition rate of the experimental setup, i.e. the inverse of the time
needed to perform one round of the protocol (distribution of quantum signal and
measurements). In this book we always consider τ = 1.
Remark 3.1 (Min-entropy estimation) We emphasize that the secret key length in
(3.27) is valid for an arbitrary QKD protocol. However, the smooth min-entropy
term appearing in its expression cannot be directly computed since Eve’s action is
unknown, i.e. the state ρ
n
R A E representing Alice’s raw key and Eve’s quantum side
information is not known. Hence, the challenge of every QKD protocol is to estimate
the min-entropy term in the tightest way possible, by relying on the observed data
employed for PE.
3.3.2 Security Definition and Proof
We now define what it means for a QKD protocol to be “secure” and subsequently
prove the security of the general QKD protocol outlined above.
Definition 3.1 (Correctness) A QKD protocol is said to be ε cor -correct if:
Pr[s A = s B ] ≤ ε cor .
(3.29)
Definition 3.2 (Secrecy) A QKD protocol is said to be ε sec -secret if, for being the
event that the protocol does not abort, the following inequality holds:
Pr[] T (ρ S A E tot | , ω S A ⊗ ρ E tot | ) ≤ ε sec ,
(3.30)
where ρ S A E tot | is the state that describes the correlation between Alice’s final secret
key S A and the total information available to Eve E tot given that the protocol did not
abort, while ω S A =
1
|S|
s∈S |ss | is the maximally mixed state over all the possible
realizations of Alice’s key and T (·, ·) is the trace distance (Definition 2.13).
Précédent

- 57/163

Suivant