Source-linked AI summary

A de Finetti representation theorem for infinite dimensional quantum systems and applications to quantum cryptography

Renato Renner, J. Ignacio Cirac

arXiv:0809.2243v1quant-ph

TL;DR

Quantum de Finetti reductions traditionally require a subsystem dimension bounded relative to the number of systems, limiting their use for infinite-dimensional quantum information carriers. The paper establishes an experimentally testable extension for permutation-invariant states and uses it to obtain general-attack security for relevant QKD protocols.

  • Problem

    Standard de Finetti-based security reductions are restricted to low-dimensional signals, while QKD may use infinite-dimensional carriers such as continuous-variable signals or weak coherent pulses.

  • Method

    The paper extends the de Finetti representation to possibly infinite-dimensional permutation-invariant states when measurements on a few subsystems produce bounded outcomes, using approximation by almost i.i.d. states.

  • Results

    Under the stated conditions, qualifying QKD protocols secure against collective attacks are secure against general attacks.

  • Takeaways & Limitations

    The result enables full security proofs for continuous-variable QKD and schemes using weak coherent pulses when the signal-space dimension may be unbounded.

Abstract

from arXiv · show

According to the quantum de Finetti theorem, if the state of an N-partite system is invariant under permutations of the subsystems then it can be approximated by a state where almost all subsystems are identical copies of each other, provided N is sufficiently large compared to the dimension of the subsystems. The de Finetti theorem has various applications in physics and information theory, where it is for instance used to prove the security of quantum cryptographic schemes. Here, we extend de Finetti's theorem, showing that the approximation also holds for infinite dimensional systems, as long as the state satisfies certain experimentally verifiable conditions. This is relevant for applications such as quantum key distribution (QKD), where it is often hard - or even impossible - to bound the dimension of the information carriers (which may be corrupted by an adversary). In particular, our result can be applied to prove the security of QKD based on weak coherent states or Gaussian states against general attacks.

I. INTRODUCTION

Permutation symmetry simplifies analyses of large quantum systems by enabling approximation with almost i.i.d. states, but standard de Finetti reductions require finite, sufficiently low subsystem dimension. The paper extends this reduction to possibly infinite-dimensional systems under experimentally verifiable measurement conditions and applies it to QKD security.

  • I. INTRODUCTION: Large composite quantum systems are difficult to analyze because their state spaces and parameter counts grow exponentially with the number of subsystems.This is especially important for security proofs that must cover adversarially generated states.
  • I. INTRODUCTION: Permutation-invariant multipartite states can be approximated by convex combinations of states with i.i.d. structure, which are characterized by a single-subsystem state.Permutation symmetry can often be assumed in QKD because signals may be randomly reordered without changing the protocol.
  • I. INTRODUCTION: Standard de Finetti reductions for QKD apply only to low-dimensional signals because the subsystem dimension must be sufficiently smaller than the number of subsystems.The representation generally fails in infinite-dimensional spaces, where reduced states can remain highly entangled.
  • I. INTRODUCTION: The paper proves that, for permutation-invariant states on possibly infinite-dimensional systems, a reduced state is approximated by a mixture of i.i.d.-structured states when measurements on a few subsystems yield bounded outcomes.For H = L2(R), the condition is that measurements of canonical observables X and Y have small absolute values.
  • I. INTRODUCTION: The criterion is often experimentally verifiable because continuous-variable QKD protocols already measure the two canonical observables X and Y.The result targets practical schemes using continuous-variable signals and unbounded signal spaces.
  • I. INTRODUCTION: The paper applies the extended theorem to show that qualifying QKD protocols secure against collective attacks are secure against general attacks.The reduction proceeds through almost i.i.d. states and the corresponding smooth min-entropy argument.

C. Measurements

The section develops measurement-based bounds that transfer low outcome frequencies between measurements on parts of a permutation-invariant state. These bounds support restricting infinite-dimensional systems to a finite-dimensional subspace before applying de Finetti-type arguments.

  • Measurement criteria: γ_U→V(δ) is the maximum V-outcome probability over states whose U-outcome probability is at most δ.For POVM elements U and V, it quantifies how small U outcomes constrain V outcomes.
  • Measurement statistics: If k measured subsystems yield few U outcomes equal to 1, permutation invariance implies that the remaining n subsystems have few V outcomes equal to 1 as well.Lemma III.1 formalizes this transfer for n ≥ 2k and bounds the relevant relative frequencies.
  • Canonical observables: For canonical observables X and Y, the method bounds the probability that X^2 + Y^2 exceeds a threshold using an auxiliary operator W_1 and coherent-state representations.The proof relates the predicate for large X^2 + Y^2 to measurement predicates involving X^2 or Y^2.
  • Canonical observables: The coherent-state construction uses a beam splitter operator and identifies the relevant states with coherent states parameterized by α = x + iy.The annihilation operators act on the two systems, enabling the coherent-state representation used to analyze W_1.
  • Finite-dimensional restriction: The finite-dimensional subspace used in the later analysis must satisfy d ≤ O(δ^-3), and it may depend on δ.This dimension bound is an explicit scope condition for the subsequent considerations.

C. Purification in restricted symmetric subspaces

This section extends the symmetric-subspace de Finetti construction to general permutation-invariant density operators by purifying them in a larger symmetric space. The purification preserves the restricted support needed for the argument.

  • Purification construction: A permutation-invariant state supported in a restricted subspace admits a purification lying in a corresponding symmetric subspace of an enlarged Hilbert space.The purification is constructed using a basis of the original Hilbert space and the restricted subspace.
  • Symmetry: Permutation invariance of the density operator ensures that the constructed purification is itself symmetric under permutations of the enlarged subsystems.The proof verifies invariance under every permutation before checking the restricted support.
  • Support preservation: Because the original state has restricted support, the purification sum can be limited to basis tuples with at most k entries outside the restricted subspace.This support property places the purification in the required projected subspace.

D. An extended de Finetti-type theorem

The paper extends de Finetti-type approximations to permutation-invariant states with possibly infinite-dimensional subsystems by restricting relevant states to a finite-dimensional subspace and quantifying approximation through fidelity.

  • Approximation measure: The approximation uses overlap, equivalently fidelity, rather than trace distance to quantify closeness.The paper notes that the earlier result can be recovered by tracing out the auxiliary system and converting fidelity to trace distance.
  • Finite-dimensional lemma: The finite-dimensional lemma embeds symmetric states into an auxiliary Hilbert space and approximates them by superpositions with k+n i.i.d. subsystems.A finite set of unit vectors indexes the auxiliary basis, and the approximation can be made arbitrarily accurate through an appropriate finite construction.
  • Normalization: The constructed approximant may initially be subnormalized, but normalization preserves or increases its overlap with the target unit vector.This allows the statement to be formulated for unit vectors after the approximation is constructed.
  • Theorem III.7: The theorem approximates reduced permutation-invariant states by convex combinations of almost i.i.d. states on most subsystems.The construction applies after tracing out part of a symmetric state and produces components supported on subspaces with repeated single-subsystem vectors.
  • Infinite-dimensional extension: For infinite-dimensional systems, the proof decomposes symmetric vectors according to finite-subspace and orthogonal-complement components before applying the finite-dimensional lemma.The resulting components contain sufficiently many subsystems in the finite-dimensional subspace, enabling the theorem’s application componentwise.

E. Properties of almost i.i.d. states

Almost i.i.d. states retain useful information-theoretic structure: their entropy and smooth min-entropy can be related to corresponding quantities for i.i.d. states under the theorem’s stated conditions.

  • Entropy properties: The theorem states that almost i.i.d. states have properties resembling those of perfect i.i.d. states, including approximately matching entropy.This motivates using the approximation for information-theoretic analyses.
  • Smooth min-entropy: Smooth min-entropy quantifies uniform randomness extractable from a classical variable conditioned on quantum side information.Two-universal hashing extracts this randomness, while the smoothness parameter measures closeness to ideal uniform independent randomness.
  • Asymptotic relation: For large N, smooth min-entropy approaches the conditional von Neumann entropy.The relation is expressed as H_min^ε(X|B) asymptotically approaching S(X|B).
  • Extension to almost i.i.d. states: The paper invokes an earlier theorem extending one direction of this asymptotic relation to almost i.i.d. states.The supplied passage identifies this result as Theorem III.8.

A. Putting things together

The technical results are combined into an infinite-dimensional approximation by measuring a small sample, inferring finite-subspace support for the remainder, and applying the extended de Finetti theorem.

  • Measurement setup: For H = L2(R), the construction measures k subsystems using the canonical observables X and Y and accepts outcomes within a bounded range.The example sets N = m^4 and k = m^3 and uses a finite subspace determined by an energy threshold.
  • Finite-subspace reduction: Accepted measurement outcomes imply that the remaining state is almost certainly contained in a finite-dimensional subspace.This converts the infinite-dimensional problem into one to which the structural lemmas apply.
  • Applying Theorem III.7: A purification of the remaining state is constructed in a symmetric subspace, after which Theorem III.7 yields a mixture of almost i.i.d. components.The components are parametrized by vectors in the finite subspace and are exponentially close to the reduced state.
  • Result: The final reduced state is approximated by states with i.i.d. structure on most subsystems.The stated retained fraction is (1 − µ − µ′)N, with µ = 5N^-1.

B. Application to QKD

The extended theorem enables QKD security reductions beyond finite-dimensional signals: under three protocol conditions, security against general attacks follows from security against collective attacks.

  • Motivation: QKD security proofs must account for arbitrary adversarial manipulation of the signals exchanged over an insecure channel.Permutation symmetry and de Finetti methods simplify this analysis when the protocol meets the required conditions.
  • Protocol conditions: The QKD reduction assumes permutation invariance, classical reconciliation and privacy amplification, and a sample measurement that certifies finite relevant dimension.The third condition is imposed by requiring sample outcomes to lie in a set associated with a finite-dimensional subspace.
  • Permutation reduction: Randomly permuting the signals allows the shared state to be treated as permutation invariant without changing security.The argument then applies the infinite-dimensional approximation to a reduced state containing almost i.i.d. structure.
  • Entropy reduction: The smooth min-entropy of measured data conditioned on the adversary’s information is the relevant quantity for the final security argument.Theorem III.8 relates this quantity for almost i.i.d. states to the corresponding entropy for i.i.d. states.
  • Security consequence: Protocols satisfying the three conditions are secure against general attacks whenever they are secure against collective attacks.The reduction applies to continuous-variable settings where the signal space may be infinite-dimensional.

V. CONCLUSIONS

The paper extends the de Finetti approximation to large permutation-invariant systems under experimentally verifiable bounded-observable conditions, including unbounded-dimensional QKD settings. This enables security proofs against general attacks and removes the need for i.i.d. assumptions in relevant protocols.

  • V. CONCLUSIONS: Permutation-invariant states are approximated by convex combinations of states that are almost i.i.d., provided measurements of a few subsystems yield bounded values.Only an arbitrarily small fraction of subsystems need be excluded from the almost-i.i.d. description.
  • V. CONCLUSIONS: The same approximation has experimental implications because state tomography can be used without assuming i.i.d. structure.The passage identifies this implication for permutation-invariant states and relates it to earlier low-dimensional work.
  • V. CONCLUSIONS: The result enables full security proofs for QKD when the signal-space dimension is unbounded.This is especially relevant to continuous-variable protocols and schemes implemented with weak coherent pulses.
  • V. CONCLUSIONS: QKD security can therefore be established against all possible attacks rather than only collective attacks, provided suitable tests are performed on sampled transmitted signals.For continuous-variable protocols, one possible test checks that measurements of two canonical observables produce small outcomes.

APPENDIX A: PROOF OF LEMMA III.1

The appendix proves Lemma III.1 by reducing permutation-invariant quantum measurements to a classical binary-sampling problem, then bounding deviations using frequency estimates, binomial approximations, and standard inequalities.

  • APPENDIX A: PROOF OF LEMMA III.1: A permutation-invariant binary distribution allows observations of k values among k+n values to estimate the distribution of remaining values.This sampling statement is formulated as Lemma A.1 for n ≥ k.
  • APPENDIX A: PROOF OF LEMMA III.1: The proof bounds conditional-probability deviations through expectation values and Markov’s inequality.Permutation invariance identifies an individual binary outcome with the expected frequency of the full tuple.
  • APPENDIX A: PROOF OF LEMMA III.1: Permutation-invariant distributions are decomposed into fixed-frequency components, reducing the remaining estimates to explicit frequency calculations.The proof then bounds the relevant binomial terms using an approximation involving binary entropy and g(p) = p(1 − p).
  • APPENDIX A: PROOF OF LEMMA III.1: Standard analysis combines the binomial bounds with the preceding estimates to establish the sampling inequality and complete Lemma III.1.The argument also uses the union bound when applying the lemma to conditioned measurements on part of the state.
  • APPENDIX A: PROOF OF LEMMA III.1: Lemma A.2 applies the classical sampling result to a binary POVM measured on k subsystems of a permutation-invariant quantum state.The remaining single-subsystem state is conditioned on the observed outcome sequence.
Loading 0809.2243v1…