4.1 Extending QKD to Multiple Parties
57
when measured in the Z basis. However, the authors in [11] prove that even bipartite
perfect correlations are forbidden in any other basis, contrary to what happens with
the Bell state |
+
for N = 2.
Therefore, in an ideal N -party BB84 protocol Alice and the Bobs share an N -party
GHZ state and measure in the Z basis for key generation.
1 However, they cannot
estimate the channel’s noise by a pairwise comparison of the X outcomes (or any
other basis), since they would be uncorrelated even in the ideal scenario. How can
we still estimate Eve’s knowledge in the multipartite scenario?
Recall that the goal is to find a lower bound on the min-entropy H
ε
min (R
n
A |E), or
on the von Neumann entropy H (R A |E) in the asymptotic scenario, of Alice’s raw
key given Eve’s side information (c.f. Chap. 3).
One possible solution is provided in [11] for the asymptotic scenario. It basically
consists in requiring the parties to measure their qubit in one of three bases, namely
the X , Y or Z basis. In doing so, the parties can sufficiently characterize the state
ρ R A E describing Alice’s raw key and Eve’s quantum side information, to the extent
that H (R A |E) is completely fixed by the measurement statistics. This solution can be
interpreted as the N -party generalization of the six-state QKD protocol [23], where
Alice and Bob are required to measure in the same three bases.
Alternatively, the security of a multipartite QKD scheme based on the GHZ state
can also be ensured with just two measurement bases, making the protocol a multipartite version of the BB84 protocol. In this case, the parties measure in the Z basis
for key generation and in the X basis to estimate Eve’s knowledge of Alice’s raw
key [13]. We discuss in detail the multipartite BB84 protocol in the next Subsection.
In [13], the finite-key security of both the multipartite BB84 protocol and the
multipartite six-state protocol introduced in [11] is proven,
2 and their performance
is compared. As expected, the multipartite six-state protocol outperforms the multipartite BB84 protocol in the asymptotic limit of infinitely many rounds due to a
more complete characterization of Eve’s information. However, for lower number
of rounds, the latter protocol provides higher secret key rates thanks to its tighter
security analysis.
Remark 4.1 (Entanglement is necessary) We emphasize that both the N -party six
state protocol and the N -party BB84 protocol require the generation of entangled
states even in their prepare-and-measure version. This contrasts with the bipartite
BB84 protocol where Alice sends simple qubits to Bob.
Indeed, in the entanglement-based view of the two multipartite QKD protocols, the
parties are given the N -partite GHZ state (4.1). Now note that the conditional state
of the Bobs, given that Alice measured X on the GHZ state and obtained outcome a
(a = ±1), reads:
|ψ a B 1 ...B N −1 =
1
√
2
|0
⊗(N −1)
+ a|1
⊗(N −1)
,
(4.2)
1 We remark that CKA is also possible with other resource states, such as the W state (Chap. 6).
2 In Sect. 4.2 we rigorously define the security of CKA protocols by providing analogous definitions
to those presented in Sect. 3.3.
Précédent

- 69/163

Suivant