56
4 Quantum Conference Key Agreement
mentioning that the conference key rates achievable in a given network configuration are upper bounded by recently-derived fundamental limits, which depend on the
network topology [17–20].
4.1 Extending QKD to Multiple Parties
In this Section we introduce the first discrete-variable CKA protocols by providing
an intuitive explanation of their development.
Consider a scenario where Alice and N − 1 Bobs, denoted B 1 , B 2 up to B N −1 ,
want to establish a secret conference key with a generalization of the BB84 protocol
[21] presented in Sect. 3.2. In this multipartite scenario the conference key is extracted
from Alice’s raw key, hence during error correction every Bob attempts to correct
his raw key to match Alice’s. As a consequence, even in CKA protocols the main
quantity to be estimated is the smooth min-entropy H
ε
min (R
n
A |E) of Alice’s raw key
conditioned on Eve’s information (see Remark 3.1).
A naive approach to generalize the BB84 protocol would be to reproduce its
prepare-and-measure description, where Alice now sends a state |φ k (k = 1, . . . , 4)
out of the four states {|0, |1, |++, |−−} to every Bob (|±± = (|0 ± |1)/
√
2). This
means that in each round of the protocol the product state |φ k
⊗(N −1) is sent through
the quantum channel. Since Eve is in control of the whole quantum channel, she
can attempt to distinguish the four product states |φ k
⊗(N −1) , whose overlap (inner
product) is either 0 or (1/
√
2)
N −1 . As N increases, the four states become more
distinguishable since their trace distance increases (c.f. Sect. 2.11), thus allowing
Eve to retrieve more information about the key without being noticed. This leads to
a dramatic decrease of the secret key rate eventually making the protocol useless,
even assuming a flawless implementation.
The described CKA does not rely on entangled states (like the original BB84
protocol) and has actually been investigated for N = 3 in [22]. However, the idea is
clearly not scalable to larger numbers of parties.
In order to devise a generalization of the BB84 protocol which would work with
an arbitrary number of parties, we resort to its entanglement-based description. In
the ideal implementation of the BB84 protocol, Alice and Bob measure their qubit in
either the Z or X basis and obtain perfectly correlated and random outcomes since
their qubits have been prepared in the Bell state |
+
. Typically, the outcomes of the
Z basis are used for key generation and those of the X basis are used to estimate the
noise E X in the channel and thus Eve’s knowledge.
In generalizing this idea to N ≥ 3 parties we encounter a fundamental problem.
The only N -qubit state which leads to perfectly correlated and random outcomes in
one measurement basis —necessary condition for generating a shared key— is the
N -party GHZ state:
|GHZ N =
1
√
2
|0
⊗N
+ |1
⊗N
,
(4.1)
4 Quantum Conference Key Agreement
mentioning that the conference key rates achievable in a given network configuration are upper bounded by recently-derived fundamental limits, which depend on the
network topology [17–20].
4.1 Extending QKD to Multiple Parties
In this Section we introduce the first discrete-variable CKA protocols by providing
an intuitive explanation of their development.
Consider a scenario where Alice and N − 1 Bobs, denoted B 1 , B 2 up to B N −1 ,
want to establish a secret conference key with a generalization of the BB84 protocol
[21] presented in Sect. 3.2. In this multipartite scenario the conference key is extracted
from Alice’s raw key, hence during error correction every Bob attempts to correct
his raw key to match Alice’s. As a consequence, even in CKA protocols the main
quantity to be estimated is the smooth min-entropy H
ε
min (R
n
A |E) of Alice’s raw key
conditioned on Eve’s information (see Remark 3.1).
A naive approach to generalize the BB84 protocol would be to reproduce its
prepare-and-measure description, where Alice now sends a state |φ k (k = 1, . . . , 4)
out of the four states {|0, |1, |++, |−−} to every Bob (|±± = (|0 ± |1)/
√
2). This
means that in each round of the protocol the product state |φ k
⊗(N −1) is sent through
the quantum channel. Since Eve is in control of the whole quantum channel, she
can attempt to distinguish the four product states |φ k
⊗(N −1) , whose overlap (inner
product) is either 0 or (1/
√
2)
N −1 . As N increases, the four states become more
distinguishable since their trace distance increases (c.f. Sect. 2.11), thus allowing
Eve to retrieve more information about the key without being noticed. This leads to
a dramatic decrease of the secret key rate eventually making the protocol useless,
even assuming a flawless implementation.
The described CKA does not rely on entangled states (like the original BB84
protocol) and has actually been investigated for N = 3 in [22]. However, the idea is
clearly not scalable to larger numbers of parties.
In order to devise a generalization of the BB84 protocol which would work with
an arbitrary number of parties, we resort to its entanglement-based description. In
the ideal implementation of the BB84 protocol, Alice and Bob measure their qubit in
either the Z or X basis and obtain perfectly correlated and random outcomes since
their qubits have been prepared in the Bell state |
+
. Typically, the outcomes of the
Z basis are used for key generation and those of the X basis are used to estimate the
noise E X in the channel and thus Eve’s knowledge.
In generalizing this idea to N ≥ 3 parties we encounter a fundamental problem.
The only N -qubit state which leads to perfectly correlated and random outcomes in
one measurement basis —necessary condition for generating a shared key— is the
N -party GHZ state:
|GHZ N =
1
√
2
|0
⊗N
+ |1
⊗N
,
(4.1)
