4.2 Security of CKA
63
Pr[] T (ρ S A E tot | , ω S A ⊗ ρ E tot | ) ≤ ε sec ,
(4.10)
where ρ S A E tot | is the state that describes the correlation between Alice’s final secret
key S A and the total information available to Eve E tot given that the protocol did not
abort, while ω S A =
1
|S|
s∈S |ss | is the maximally mixed state over all the possible
realizations of Alice’s key and T (·, ·) is the trace distance (Definition 2.13).
Definition 4.3 (Security) A CKA protocol is said to be ε tot -secure if it is ε cor -correct
and ε sec -secret, with ε tot ≥ ε cor + ε sec .
The correctness definition implies that the protocol always outputs a set of identical keys for all participating parties (s A = s B 1 = · · · = s B N −1 ), except for probability
at most ε cor . The secrecy and security statements are the same used for QKD protocols (c.f. Chap. 3). An ε tot -secure CKA protocol is indistinguishable from an ideal
protocol, i.e. one that outputs a set of identical keys unknown to Eve or aborts, except
for a probability at most ε tot .
Note that a trivial protocol that always aborts is secure according to the above
definition. Thus, another important feature of a CKA protocol is its completeness, i.e.
the existence of an honest implementation of the protocol such that the probability
of not aborting is Pr[] ≥ 1 − ε c , for some small ε c .
We also remark that the CKA security definition is composable. This means that
when a CKA protocol is composed with another cryptographic task, the security of
their combination can be inferred based on their individual security proofs and does
not require a separate new proof.
Lemma 4.1 (Security of CKA) The general CKA protocol of Sect. 4.2.1 is ε tot -
secure, with ε tot ≥ ε EC + 2ε + ε PA .
In order to prove this statement, one first shows that the general CKA protocol
described earlier is ε EC -correct. This is guaranteed by the fact that the parties verify
the success of EC by computing and comparing hashes of length log((N − 1)/ε EC ).
The second step is to show that the protocol is at least (2ε + ε PA )-secret by employing
the Quantum Leftover Hash Lemma (c.f. Lemma 2.1), also used to prove the security
of QKD protocols. We provide the full proof of Lemma 4.1 in the Appendix of this
Chapter (Sect. 4.4).
4.3 Experimental CKA
The first experimental implementation of a CKA protocol has been recently carried
out [26], enabling four parties to establish a secret conference key. We also report the
realization of a three-party anonymous CKA [27], where the identity of the parties
establishing the conference key is kept secret from external observers and from each
other (except for the initiator of the protocol).
63
Pr[] T (ρ S A E tot | , ω S A ⊗ ρ E tot | ) ≤ ε sec ,
(4.10)
where ρ S A E tot | is the state that describes the correlation between Alice’s final secret
key S A and the total information available to Eve E tot given that the protocol did not
abort, while ω S A =
1
|S|
s∈S |ss | is the maximally mixed state over all the possible
realizations of Alice’s key and T (·, ·) is the trace distance (Definition 2.13).
Definition 4.3 (Security) A CKA protocol is said to be ε tot -secure if it is ε cor -correct
and ε sec -secret, with ε tot ≥ ε cor + ε sec .
The correctness definition implies that the protocol always outputs a set of identical keys for all participating parties (s A = s B 1 = · · · = s B N −1 ), except for probability
at most ε cor . The secrecy and security statements are the same used for QKD protocols (c.f. Chap. 3). An ε tot -secure CKA protocol is indistinguishable from an ideal
protocol, i.e. one that outputs a set of identical keys unknown to Eve or aborts, except
for a probability at most ε tot .
Note that a trivial protocol that always aborts is secure according to the above
definition. Thus, another important feature of a CKA protocol is its completeness, i.e.
the existence of an honest implementation of the protocol such that the probability
of not aborting is Pr[] ≥ 1 − ε c , for some small ε c .
We also remark that the CKA security definition is composable. This means that
when a CKA protocol is composed with another cryptographic task, the security of
their combination can be inferred based on their individual security proofs and does
not require a separate new proof.
Lemma 4.1 (Security of CKA) The general CKA protocol of Sect. 4.2.1 is ε tot -
secure, with ε tot ≥ ε EC + 2ε + ε PA .
In order to prove this statement, one first shows that the general CKA protocol
described earlier is ε EC -correct. This is guaranteed by the fact that the parties verify
the success of EC by computing and comparing hashes of length log((N − 1)/ε EC ).
The second step is to show that the protocol is at least (2ε + ε PA )-secret by employing
the Quantum Leftover Hash Lemma (c.f. Lemma 2.1), also used to prove the security
of QKD protocols. We provide the full proof of Lemma 4.1 in the Appendix of this
Chapter (Sect. 4.4).
4.3 Experimental CKA
The first experimental implementation of a CKA protocol has been recently carried
out [26], enabling four parties to establish a secret conference key. We also report the
realization of a three-party anonymous CKA [27], where the identity of the parties
establishing the conference key is kept secret from external observers and from each
other (except for the initiator of the protocol).
