60
4 Quantum Conference Key Agreement
One can interpret the inequality (4.5) as the finite version of the equality (3.25)
linking the conditional von Neumann entropy of two random variables to their error
probability. By combining (4.4) and (4.5) we obtain:
H
ε
min (Z
n
A |E) ≥ n(1 − h(E X + (n, ε))).
(4.6)
An important aspect in any CKA protocol is the information leakage during EC.
In the N -party BB84 protocol we require every Bob to correct his raw key to match
Alice’s. By employing one-way EC, Alice needs to publicly broadcast enough information such that even the Bob with the largest amount of errors can correct his key.
Since the information leak i she would send to each B i only depends on the estimated Z -basis error rate E AB i but otherwise it’s independent of B i , by broadcasting
max i leak i we ensure that every Bob will be able to correct his raw key. In other
words, the leakage of one-way EC in a multipartite QKD protocol is equivalent to
that of a bipartite protocol performed with the worst-case Bob.
The asymptotic secret key rate of the N -partite BB84 protocol can be heuristically
inferred starting from the secret key length of a bipartite QKD protocol in (3.27).
We use Eq. (4.6) to bound the min-entropy term, while we replace the leakage term
with max i leak i according to the argument above. Analogously to Sect. 3.3.3, we
estimate the minimum leakage relative to B i as leak i ≈ H
ε
max (R
n
A |R
n
B i
) and bound
the max-entropy with a version of the bound (4.5) where the relevant error rate is
the Z -basis error rate E AB i . Finally, by taking the asymptotic limit of infinitely many
rounds we remove all the corrections due to statistical fluctuations and obtain
4 :
r N -BB84 = 1 − h(E X ) − max
1≤i≤N −1
h(E AB i ).
(4.7)
Notably, the resulting key rate reads exactly like the BB84 key rate in (3.26), except
for a maximization on the QBERs in the Z basis and a more general definition of
E X .
4.2 Security of CKA
In this Section we describe the functioning of a generic CKA protocol and subsequently prove its security. The content of this Section is mainly drawn from
[9, 13].
4 A formal derivation of (4.7) can be found in [13].
Précédent

- 72/163

Suivant