58
4 Quantum Conference Key Agreement
which is an entangled state. Therefore, in an equivalent prepare-and-measure version
of the protocol, Alice would need to prepare the entangled state (4.2) and send it to
the Bobs in the rounds where she chooses the X basis.
However, the X -basis rounds are test rounds and are much less frequent than
the key-generation rounds. In the key-generation rounds the conditional state of the
Bobs, upon Alice measuring Z , is given by one of the two product states |0
⊗(N −1)
and |1
⊗(N −1) . Hence for key generation Alice can just prepare the same qubit state
N − 1 times and send each of them to the corresponding Bob.
4.1.1 Multipartite BB84 Protocol
The multipartite BB84 protocol [13] allows N parties to establish a secret conference
key by performing measurements in only two bases, the Z and the X basis.
The main idea is to view all the Bobs as one single Bob and define E X as the
error rate between the X outcomes of Alice (X A ) and the product of the X outcomes
of all Bobs (X B :=
N −1
i=1 X B i ), that is: E X = Pr[X A = X B ]. Then, in an ideal
implementation where the parties share the GHZ state (4.1), X A and X B are perfectly correlated
3 like in the BB84 protocol and the channel noise is zero: E X = 0.
Therefore, when the parties observe an error rate E X = 0, they conclude that Eve
might have tampered with the quantum channel and can quantify the knowledge she
acquired.
The N -party BB84 protocol comprises the following steps.
1. N qubits prepared in the GHZ state (4.1) are distributed to Alice and the Bobs
for M protocol rounds.
2. Each party measures the received qubit in the Z basis if the round is classified as
a key generation (KG) round, or in the X basis when it is a parameter estimation
(PE) round.
3. In the PE step, the parties reveal the outcomes of the PE rounds and estimate
the error rate E X . This information is then used in privacy amplification (PA) to
extract a secret conference key. They also reveal a random sample of KG outcomes
in order to estimate the error rate affecting their raw keys: E AB i = Pr[Z A = Z B i ].
Each party now holds a raw key of n < M bits.
4. The parties perform a one-way error correction (EC) procedure where Alice sends
sufficient information over the public channel for the Bobs to correct their raw
keys and match her key. The amount of information disclosed by Alice is estimated
from the error rates E AB i .
5. In PA the parties map their matching raw keys to a secret conference key by
applying the same two-universal hash function, which is randomly picked and
publicly broadcast by Alice.
3 This is due to the fact that the N -party GHZ state is an eigenstate of X ⊗N with eigenvalue 1, thus
the product of the X outcomes of all the parties must be equal to: X A X B = 1.
4 Quantum Conference Key Agreement
which is an entangled state. Therefore, in an equivalent prepare-and-measure version
of the protocol, Alice would need to prepare the entangled state (4.2) and send it to
the Bobs in the rounds where she chooses the X basis.
However, the X -basis rounds are test rounds and are much less frequent than
the key-generation rounds. In the key-generation rounds the conditional state of the
Bobs, upon Alice measuring Z , is given by one of the two product states |0
⊗(N −1)
and |1
⊗(N −1) . Hence for key generation Alice can just prepare the same qubit state
N − 1 times and send each of them to the corresponding Bob.
4.1.1 Multipartite BB84 Protocol
The multipartite BB84 protocol [13] allows N parties to establish a secret conference
key by performing measurements in only two bases, the Z and the X basis.
The main idea is to view all the Bobs as one single Bob and define E X as the
error rate between the X outcomes of Alice (X A ) and the product of the X outcomes
of all Bobs (X B :=
N −1
i=1 X B i ), that is: E X = Pr[X A = X B ]. Then, in an ideal
implementation where the parties share the GHZ state (4.1), X A and X B are perfectly correlated
3 like in the BB84 protocol and the channel noise is zero: E X = 0.
Therefore, when the parties observe an error rate E X = 0, they conclude that Eve
might have tampered with the quantum channel and can quantify the knowledge she
acquired.
The N -party BB84 protocol comprises the following steps.
1. N qubits prepared in the GHZ state (4.1) are distributed to Alice and the Bobs
for M protocol rounds.
2. Each party measures the received qubit in the Z basis if the round is classified as
a key generation (KG) round, or in the X basis when it is a parameter estimation
(PE) round.
3. In the PE step, the parties reveal the outcomes of the PE rounds and estimate
the error rate E X . This information is then used in privacy amplification (PA) to
extract a secret conference key. They also reveal a random sample of KG outcomes
in order to estimate the error rate affecting their raw keys: E AB i = Pr[Z A = Z B i ].
Each party now holds a raw key of n < M bits.
4. The parties perform a one-way error correction (EC) procedure where Alice sends
sufficient information over the public channel for the Bobs to correct their raw
keys and match her key. The amount of information disclosed by Alice is estimated
from the error rates E AB i .
5. In PA the parties map their matching raw keys to a secret conference key by
applying the same two-universal hash function, which is randomly picked and
publicly broadcast by Alice.
3 This is due to the fact that the N -party GHZ state is an eigenstate of X ⊗N with eigenvalue 1, thus
the product of the X outcomes of all the parties must be equal to: X A X B = 1.
