62
4 Quantum Conference Key Agreement
can implement a sifting step and select the rounds where they all performed the
same type of measurement.
3. For PE the parties reveal the settings and the outcomes of the test rounds, as well
as the outcomes of a random sample of key-generation rounds. This information
is used to estimate the noise in the quantum channel (Eve’s knowledge) and the
correlations of their key bits. If the noise is above a certain threshold, the protocol
aborts. After this step, Alice and the Bobs hold a string of n < M key-generation
outcomes forming their raw key, denoted R
n
A and R
n
B i
, respectively.
4. In the EC step, each Bob B i corrects his raw key to match Alice’s by computing
a guess ˆ
R
n
A i
of Alice’s raw key. In doing so, the parties reveal leak EC bits of
information over the public channel. In order to verify if EC was successful, Alice
computes a hash h A (bitstring) of length log((N − 1)/ε EC ) from her raw key
R
n
A by applying a randomly-picked two-universal hash function (Definition 2.11).
She publicly announces the hash function and h A . Each Bob uses Alice’s hash
function to compute the hash h B i from his guess ˆ
R
n
A i
. If h A = h B i for at least
one Bob, the protocol aborts. The total amount of information about Alice’s raw
key R
n
A revealed during EC is thus given by: leak EC + +log((N − 1)/ε EC ) ≤
leak EC + log(2(N − 1)/ε EC ).
5. In PA Alice randomly picks another two-universal hash function and broadcasts
it. Alice and all the Bobs apply the two-universal hash function on their errorcorrected keys and obtain secret conference keys s A and s B i (for i = 1, . . . , N − 1)
of length . The length is chosen such that:
≤ H
ε
min (R
n
A |E) − leak EC − log
2(N − 1)
ε EC
− 2 log
1
2 ε PA
,
(4.8)
for some ε, ε EC , ε PA > 0 which depend on the required level of security (see
Sect. 4.2.2).
The crucial task of every CKA protocol is to estimate the smooth min-entropy term
in (4.8) with the PE data, as we showed for the multipartite BB84 protocol with (4.6).
In the next Subsection we rigorously define the security of CKA and prove that
the general CKA protocol described above is secure.
4.2.2 Security Definition and Proof
Definition 4.1 (Correctness) A CKA protocol is said to be ε cor -correct if:
Pr[∪
N −1
i=1 s A = s B i ] ≤ ε cor .
(4.9)
Definition 4.2 (Secrecy) A CKA protocol is said to be ε sec -secret if, for being the
event that the protocol does not abort, the following inequality holds:
4 Quantum Conference Key Agreement
can implement a sifting step and select the rounds where they all performed the
same type of measurement.
3. For PE the parties reveal the settings and the outcomes of the test rounds, as well
as the outcomes of a random sample of key-generation rounds. This information
is used to estimate the noise in the quantum channel (Eve’s knowledge) and the
correlations of their key bits. If the noise is above a certain threshold, the protocol
aborts. After this step, Alice and the Bobs hold a string of n < M key-generation
outcomes forming their raw key, denoted R
n
A and R
n
B i
, respectively.
4. In the EC step, each Bob B i corrects his raw key to match Alice’s by computing
a guess ˆ
R
n
A i
of Alice’s raw key. In doing so, the parties reveal leak EC bits of
information over the public channel. In order to verify if EC was successful, Alice
computes a hash h A (bitstring) of length log((N − 1)/ε EC ) from her raw key
R
n
A by applying a randomly-picked two-universal hash function (Definition 2.11).
She publicly announces the hash function and h A . Each Bob uses Alice’s hash
function to compute the hash h B i from his guess ˆ
R
n
A i
. If h A = h B i for at least
one Bob, the protocol aborts. The total amount of information about Alice’s raw
key R
n
A revealed during EC is thus given by: leak EC + +log((N − 1)/ε EC ) ≤
leak EC + log(2(N − 1)/ε EC ).
5. In PA Alice randomly picks another two-universal hash function and broadcasts
it. Alice and all the Bobs apply the two-universal hash function on their errorcorrected keys and obtain secret conference keys s A and s B i (for i = 1, . . . , N − 1)
of length . The length is chosen such that:
≤ H
ε
min (R
n
A |E) − leak EC − log
2(N − 1)
ε EC
− 2 log
1
2 ε PA
,
(4.8)
for some ε, ε EC , ε PA > 0 which depend on the required level of security (see
Sect. 4.2.2).
The crucial task of every CKA protocol is to estimate the smooth min-entropy term
in (4.8) with the PE data, as we showed for the multipartite BB84 protocol with (4.6).
In the next Subsection we rigorously define the security of CKA and prove that
the general CKA protocol described above is secure.
4.2.2 Security Definition and Proof
Definition 4.1 (Correctness) A CKA protocol is said to be ε cor -correct if:
Pr[∪
N −1
i=1 s A = s B i ] ≤ ε cor .
(4.9)
Definition 4.2 (Secrecy) A CKA protocol is said to be ε sec -secret if, for being the
event that the protocol does not abort, the following inequality holds:
