68
4 Quantum Conference Key Agreement
The CKA secrecy is proved by the Quantum Leftover Hash Lemma [31, 32]
exactly like in QKD, since it only concerns the secrecy of Alice’s key. The following
upper bound holds [31, 32]:
1
2
ρ S A E tot | − ω S A ⊗ ρ E tot |
≤ 2ε +
1
2
2 −H
ε
min (R
n
A |C E) ,
(4.14)
where is the length of Alice’s key after PA and where we emphasize E tot being
the total information available to Eve. This comprises her purifying system E, the
classical communication C occurred during EC and the knowledge F of the hash
function used in PA: E tot = FC E.
We now employ the following chain-rule for the min-entropy [25]:
H
ε
min (R
n
A |C E) ≥ H
ε
min (R
n
A |E) − log |C|
= H
ε
min (R
n
A |E) − leak EC − log
2(N − 1)
ε EC
,
(4.15)
where log |C| quantifies all the information revealed during EC and is given by
leak EC + log(2(N − 1)/ε EC ) (see the CKA description).
By inserting Eq. (4.15) into (4.14) we obtain the following chain of inequalities:
1
2
ρ S A E tot | − ω S A ⊗ ρ E tot |
≤ 2ε +
1
2
2 −(H
ε
min (R
n
A |E)−leak EC −log(2(N −1)/ε EC ))
≤ 2ε +
1
2
2 log(2 ε PA ) 2
= 2ε + ε PA ,
(4.16)
where we used the key length expression (4.8) in the second inequality. We have
thus proven that the protocol is ε sec -secret (Definition 4.2), with ε sec ≥ 2ε + ε PA . By
combining this with the correctness proof (4.13), we have shown that the protocol
is ε tot -secure, with ε tot ≥ 2ε + ε PA + ε EC . This concludes the proof.
References
1. Epping, M., Kampermann, H., & Bruß, D. (2016a). Large-scale quantum networks based on
graphs. New Journal of Physics, 18(5), 053036.
2. Epping, M., Kampermann, H., & Bruß, D. (2016b). Robust entanglement distribution via
quantum network coding. New Journal of Physics, 18(10), 103052.
3. Pirker, A., Wallnöfer, J., & Dür, W. (2018). Modular architectures for quantum networks. New
Journal of Physics, 20(5), 053054.
4. Hahn, F., Pappa, A., & Eisert, J. (2019). Quantum network routing and local complementation.
npj Quantum Information, 5(1), 76.
Précédent

- 80/163

Suivant