3.5 Eve’s Uncertainty Is Non-increasing Under Symmetrization
51
ρ
t
R A E =
1
a=0
|aa | ⊗
λ,σ
√
λσ Tr B
a||λ
t
σ
t
||a
|e λ e σ |
=
1
a=0
|aa | ⊗
λ,σ
√
λσ Tr B [a|(X ⊗ X )|λσ |(X ⊗ X )|a] |e λ e σ |
=
1
a=0
|aa | ⊗
λ,σ
√
λσ Tr B [ ¯
a||λσ || ¯
a] |e λ e σ |
=
1
a=0
| ¯
a ¯
a | ⊗
λ,σ
√
λσ Tr B [a||λσ ||a] |e λ e σ |
=:
1
a=0
| ¯
a ¯
a | ⊗ ρ
a
E ,
(3.44)
where in the third equality we used the cyclic property of the trace and the fact
that Alice measures in the Z basis {|0, |1}, hence the Pauli operator X flips its
eigenstates: X |a = |¯ a. In the fourth equality we relabelled the classical outcomes:
a ↔ ¯
a. Finally, by comparing (3.44) with the state ρ R A E obtained in an analogous
way from the original state ρ AB :
ρ R A E = (E R A ⊗ 1 E ) Tr B [|φ AB E φ AB E |]
=
1
a=0
|aa | ⊗
λ,σ
√
λσ Tr B [a||λσ||a] |e λ e σ |
=
1
a=0
|aa | ⊗ ρ
a
E ,
(3.45)
we observe that ρ
t
R A E and ρ R A E are the same state up to a permutation of the classical
outcomes, thus their conditional entropies coincide:
H (R A |E) ρ t = H (R A |E) ρ ∀ t.
(3.46)
In conclusion, by combining Eqs. (3.46), (3.40) and (3.38), we prove the claim in
Eq. (3.37). This concludes the proof.
3.6 Finite-Key Security of QKD
Here we prove Lemma 3.1, following the lines of [9, 12].
Proof We start by showing that the protocol is ε EC -correct.
51
ρ
t
R A E =
1
a=0
|aa | ⊗
λ,σ
√
λσ Tr B
a||λ
t
σ
t
||a
|e λ e σ |
=
1
a=0
|aa | ⊗
λ,σ
√
λσ Tr B [a|(X ⊗ X )|λσ |(X ⊗ X )|a] |e λ e σ |
=
1
a=0
|aa | ⊗
λ,σ
√
λσ Tr B [ ¯
a||λσ || ¯
a] |e λ e σ |
=
1
a=0
| ¯
a ¯
a | ⊗
λ,σ
√
λσ Tr B [a||λσ ||a] |e λ e σ |
=:
1
a=0
| ¯
a ¯
a | ⊗ ρ
a
E ,
(3.44)
where in the third equality we used the cyclic property of the trace and the fact
that Alice measures in the Z basis {|0, |1}, hence the Pauli operator X flips its
eigenstates: X |a = |¯ a. In the fourth equality we relabelled the classical outcomes:
a ↔ ¯
a. Finally, by comparing (3.44) with the state ρ R A E obtained in an analogous
way from the original state ρ AB :
ρ R A E = (E R A ⊗ 1 E ) Tr B [|φ AB E φ AB E |]
=
1
a=0
|aa | ⊗
λ,σ
√
λσ Tr B [a||λσ||a] |e λ e σ |
=
1
a=0
|aa | ⊗ ρ
a
E ,
(3.45)
we observe that ρ
t
R A E and ρ R A E are the same state up to a permutation of the classical
outcomes, thus their conditional entropies coincide:
H (R A |E) ρ t = H (R A |E) ρ ∀ t.
(3.46)
In conclusion, by combining Eqs. (3.46), (3.40) and (3.38), we prove the claim in
Eq. (3.37). This concludes the proof.
3.6 Finite-Key Security of QKD
Here we prove Lemma 3.1, following the lines of [9, 12].
Proof We start by showing that the protocol is ε EC -correct.
