Chapter 4
Quantum Conference Key Agreement
Abstract Quantum conference key agreement (CKA) extends the notion of quantum
key distribution (QKD) to the multipartite scenario. We introduce CKA in Sect. 4.1
and present the multipartite generalization of the BB84 protocol, including insight
on its security proof and asymptotic key rate. In Sect. 4.2 we describe the functioning
of a general CKA protocol and define its security, which is proven in Sect. 4.4 of the
Appendix. We conclude the Chapter by discussing the first experimental implementations of CKA (Sect. 4.3).
The rapid development of quantum technologies allows us to foresee quantum networks [1–4] as one of its near-future applications. Quantum networks could be composed of matter-based quantum nodes where quantum information can be processed
and stored, linked together by quantum channels where light distributes entangled
states. Successful experiments on matter-light entanglement [5, 6] bring us closer to
realizing such networks. The ultimate vision for quantum networks is building the
quantum internet [7, 8].
A more accessible application of quantum networks is the generalization of the
task of quantum key distribution (QKD) to a multiparty scenario, in what is called
multipartite QKD or quantum conference key agreement (CKA). Here, N parties in
a quantum network wish to establish a common secret key —a conference key— and
use it to securely broadcast messages within the network. The first complete review
on this topic is given in [9].
A CKA could be carried out by simply performing bipartite QKD schemes
between pairs of parties, and then employing the established keys to securely distribute the conference key to all involved parties. However, such a solution would
not exploit the possibility offered by quantum networks of distributing multipartite
entangled states across several network nodes.
Conversely, it is possible to devise CKA protocols which make use of the correlations arising in multipartite entangled states in order to establish a conference key
among several users [10–15]. This type of truly multipartite schemes can outperform
the solution based on the iteration of bipartite schemes in certain network configurations (e.g. networks with bottlenecks) [11] and noise regimes [16]. It is worth
© The Author(s), under exclusive license to Springer Nature Switzerland AG 2021
F. Grasselli, Quantum Cryptography, Quantum Science and Technology,
https://doi.org/10.1007/978-3-030-64360-7_4
55
Quantum Conference Key Agreement
Abstract Quantum conference key agreement (CKA) extends the notion of quantum
key distribution (QKD) to the multipartite scenario. We introduce CKA in Sect. 4.1
and present the multipartite generalization of the BB84 protocol, including insight
on its security proof and asymptotic key rate. In Sect. 4.2 we describe the functioning
of a general CKA protocol and define its security, which is proven in Sect. 4.4 of the
Appendix. We conclude the Chapter by discussing the first experimental implementations of CKA (Sect. 4.3).
The rapid development of quantum technologies allows us to foresee quantum networks [1–4] as one of its near-future applications. Quantum networks could be composed of matter-based quantum nodes where quantum information can be processed
and stored, linked together by quantum channels where light distributes entangled
states. Successful experiments on matter-light entanglement [5, 6] bring us closer to
realizing such networks. The ultimate vision for quantum networks is building the
quantum internet [7, 8].
A more accessible application of quantum networks is the generalization of the
task of quantum key distribution (QKD) to a multiparty scenario, in what is called
multipartite QKD or quantum conference key agreement (CKA). Here, N parties in
a quantum network wish to establish a common secret key —a conference key— and
use it to securely broadcast messages within the network. The first complete review
on this topic is given in [9].
A CKA could be carried out by simply performing bipartite QKD schemes
between pairs of parties, and then employing the established keys to securely distribute the conference key to all involved parties. However, such a solution would
not exploit the possibility offered by quantum networks of distributing multipartite
entangled states across several network nodes.
Conversely, it is possible to devise CKA protocols which make use of the correlations arising in multipartite entangled states in order to establish a conference key
among several users [10–15]. This type of truly multipartite schemes can outperform
the solution based on the iteration of bipartite schemes in certain network configurations (e.g. networks with bottlenecks) [11] and noise regimes [16]. It is worth
© The Author(s), under exclusive license to Springer Nature Switzerland AG 2021
F. Grasselli, Quantum Cryptography, Quantum Science and Technology,
https://doi.org/10.1007/978-3-030-64360-7_4
55
