4.2 Security of CKA
61
4.2.1 General CKA Protocol
The setup in which CKA takes place is a straightforward generalization of that
assumed for QKD (c.f. Chap. 3). Every party is linked to a quantum source (or
to Alice) by quantum channels. Both the source and the quantum channels may
be under Eve’s full control. The parties can also communicate over authenticated
classical public channels (e.g. phone calls) which may be wiretapped by Eve (see
Fig. 4.1).
Alice and N − 1 Bobs run a CKA protocol whose goal is to output a set of identical
keys (s A , s B 1 , . . . , s B N −1 ) for Alice and the Bobs, completely unknown to Eve. The
protocol could also abort and output the symbol: s A = s B 1 = · · · = s B N −1 =⊥.
The steps of a generic N -party CKA protocol read as follows.
1. A source distributes a multipartite entangled state to the N parties for M rounds.
From a security perspective, the state of the quantum signals over the M rounds
is unknown and given by ρ
M
AB 1 ...B N −1
. Eve holds its purification.
2. The parties perform local measurements on each received signal and collect the
outcomes. For each measurement, they can randomly choose among certain measurement settings according to the protocol’s specifications. Typically, one setting
is chosen with higher probability and is used for key generation, while the other(s)
form the test rounds. A short preshared key (see Remark 4.2) can indicate to each
party what type of measurement to perform in each round. Otherwise, the parties
Alice
Eve
Bob N-1
Bob 1
. . .
Fig. 4.1 Setup of a CKA protocol with an independent quantum source. Eve may be in control
of the source and distribute entangled quantum signals to the parties over quantum channels. Each
party locally measures the incoming signal and records the classical output. After the transmission
of quantum signals is over, the parties communicate via classical public channels to perform error
correction and privacy amplification
Précédent

- 73/163

Suivant