3.3 Finite-Key Security
47
In order to prove this statement, one first shows that the general QKD protocol
described earlier is ε EC -correct. This is guaranteed by the fact that Alice and Bob
verify the success of EC by computing and comparing hashes of length log(1/ε EC ).
The second step is to show that the protocol is at least (2ε + ε PA )-secret by employing
the Quantum Leftover Hash Lemma (c.f. Lemma 2.1), which is at the core of finitekey QKD security. We provide the full proof of Lemma 3.1 in the Appendix of this
Chapter (Sect. 3.6).
3.3.3 Reduction to Asymptotic Key Rate
We emphasize that the non-asymptotic secret key rate in (3.28), computed with the
key length in (3.27) of a generic QKD protocol, reduces to the asymptotic key rate
given in (3.9) in the limit M → ∞ of infinitely many rounds. This fact shows that the
results presented in this Section properly generalize QKD key rates to the scenario
of finite resources.
In order to prove the reduction of (3.28) to (3.9), we make use of an important
tool called the postselection technique (PST) [14], valid for discrete-variable QKD
protocols where the dimension d = dim(H A ⊗ H B ) of the quantum systems held
by Alice and Bob can be characterized. The PST states that if a QKD protocol of M
rounds is ε tot -secure against collective attacks, then it is also (M + 1)
d
2 −1
ε tot -secure
against coherent attacks if the secret key length (3.27) (the output of PA) is shortened
by 2(d
2
− 1) log(M + 1) bits.
Recall that in case of collective attacks, the state shared by the parties in the M
rounds is the i.i.d. state ρ
⊗M
AB , while for coherent attacks—as we consider in this
finite-key analysis—the shared state is the more general ρ
M
AB .
Since in the asymptotic limit (M → ∞, and ε tot → 0 exponentially fast) the
corrections to the secret key rate introduced by the PST are negligible, proving the
security of a generic QKD protocol against coherent attacks reduces to proving the
security of the same protocol against collective attacks [6, 14, 15]. In other words,
we can assume without loss of generality that the state distributed to the parties by
Eve is an i.i.d. state ρ
⊗M
AB . As a consequence, the smooth min-entropy term in (3.27)
is now computed on the state ρ
⊗n
R A E : H
ε
min (R
n
A |E) ρ
⊗n
R A E
.
Moreover, by recalling the operational meaning of the smooth max-entropy (c.f.
Sect. 2.6), the minimum amount of leakage in (3.27) is quantified by leak EC ≈
H
ε
max (R
n
A |R
n
B ), where we neglected terms that tend to zero in the asymptotic limit.
In case of collective attacks, the smooth-max entropy is evaluated on the i.i.d. state
ρ
⊗n
R A R B
and reads: H
ε
max (R
n
A |R
n
B ) ρ
⊗n
R A R B
.
Finally, by applying the AEP (2.63) and (2.64) on the smooth entropy terms
appearing in (3.27), we reduce them to the correspondent von Neumann entropies:
H (R A |E) and H (R A |R B ). In this way (3.9) is recovered.
Note that the PST has been fundamental for the application of the AEP, since the
latter only holds for i.i.d. quantum states.
Précédent

- 59/163

Suivant