Source-linked AI summary

Device-independent quantum key distribution secure against collective attacks

Stefano Pironio, Antonio Acin, Nicolas Brunner, Nicolas Gisin, Serge Massar, Valerio Scarani

arXiv:0903.4460v1quant-ph

TL;DR

The paper addresses how to establish QKD security without trusting the internal workings or dimensions of the devices. It proves security for a modified Ekert protocol using quantum-theoretic analysis of CHSH violation, but only against collective attacks and subject to the need for genuine Bell violation.

  • Problem

    DIQKD must bound Eve’s information using only observed statistics when the source and measuring devices, including their dimensions, are untrusted.

  • Method

    The paper analyzes a modified Ekert protocol whose key uses A0 and B1, while other measurements estimate QBER and CHSH violation to bound Eve’s information.

  • Results

    The proof establishes a tight quantum-theoretic bound on Eve’s Holevo information as a function of CHSH violation and yields a key rate for observed Q and S.

  • Takeaways & Limitations

    Device-independent security is possible under a minimal set of assumptions when the observed outcomes genuinely violate a Bell inequality.

  • Takeaways & Limitations

    The proof covers collective attacks only, and DIQKD requires genuine Bell violation; whether collective-attack security extends to general device-independent attacks remains open.

Abstract

from arXiv · show

Device-independent quantum key distribution (DIQKD) represents a relaxation of the security assumptions made in usual quantum key distribution (QKD). As in usual QKD, the security of DIQKD follows from the laws of quantum physics, but contrary to usual QKD, it does not rely on any assumptions about the internal working of the quantum devices used in the protocol. We present here in detail the security proof for a DIQKD protocol introduced in [Phys. Rev. Lett. 98, 230501 (2008)]. This proof exploits the full structure of quantum theory (as opposed to other proofs that exploit the no-signalling principle only), but only holds again collective attacks, where the eavesdropper is assumed to act on the quantum systems of the honest parties independently and identically at each round of the protocol (although she can act coherently on her systems at any time). The security of any DIQKD protocol necessarily relies on the violation of a Bell inequality. We discuss the issue of loopholes in Bell experiments in this context.

1 Introduction

DIQKD seeks secure key generation without assumptions about quantum devices’ internal workings, using observed input-output statistics and Bell-inequality violations. The paper highlights reduced assumptions, the failure of device-dependent BB84 security under unknown dimensions, and a proof restricted to collective attacks.

  • 1 Introduction: DIQKD treats quantum apparatuses as black boxes and seeks security from observed classical input-output statistics rather than assumptions about their internal states or measurements.Alice and Bob use the observed relation between inputs and outputs to assess whether they can establish a key secure against a quantum eavesdropper.
  • 1 Introduction: Unlike usual QKD, DIQKD distrusts both the particle source and measuring devices, including their Hilbert-space dimension and measurement implementation.Eve may control or fabricate the devices, so security requires considering arbitrary-dimensional states and measurements compatible with the observations.
  • 1 Introduction: DIQKD relies on fewer device assumptions, retaining secure locations, trusted randomness and classical processing, an authenticated channel, and quantum physics.The paper presents these as the essential prerequisites beyond which no additional device assumptions are necessary.
  • 1 Introduction: The standard BB84 security analysis fails without its two-dimensional-system assumption, which is difficult to verify experimentally.The paper states that relaxing this assumption removes the security guarantee.
  • 1 Introduction: A genuine Bell-inequality violation is necessary for device-independent QKD security because it rules out the eavesdropper’s trivial strategy of copying a shared classical variable.The paper notes that BB84 does not satisfy this condition.
  • 1 Introduction: The paper proves security for a modified Ekert protocol against collective attacks using the quantum formalism and a CHSH-based bound on Eve’s information.The proof assumes independent and identical action on the honest parties’ systems at each round, while allowing coherent operations on Eve’s own systems.
  • 1 Introduction: Experimental loopholes remain central because existing nonlocality tests admit, in principle, local descriptions, while DIQKD requires genuine Bell violation.The paper discusses these loopholes specifically from the perspective of device-independent security.

2.1 The protocol

The protocol extracts raw key from A0 and B1, estimates classical errors with QBER, and bounds Eve’s information using CHSH correlations from additional measurements. Security requires a CHSH violation, while the protocol does not require trusting the specific qubit implementation.

  • The protocol uses three binary-outcome measurements for Alice, A0, A1, A2, and two for Bob, B1, B2, on particles from an entangled source.
  • The raw key comes from A0 and B1, while Q = P(a ≠ b|01) estimates correlations and the communication needed for error correction.
  • Alice and Bob use A1, A2, B1, and B2 on a subset of particles to estimate CHSH correlations that bound Eve’s information and govern privacy amplification.
  • Q and the CHSH value S are separate observed parameters used to estimate Eve’s information, with no a priori relation between them.
  • A qubit realization using a noisy two-qubit Werner state is illustrative only: Alice and Bob need not assume those measurements or dimension when bounding Eve’s information.

Most general attacks

The general model allows Eve to control the source and measuring devices, including their dimensions, classical memories, and potentially quantum memories. The paper then restricts the proof to memoryless, identical collective attacks and bounds the key rate using Devetak–Winter quantities.

  • Eve may fabricate both measuring devices, so Alice and Bob use only observed input-output relations to bound her knowledge.
  • In the general model, the shared state spans unknown-dimensional spaces fixed by Eve, and each measurement may depend on the current input and stored classical information.
  • The devices can retain all previous inputs and outputs in classical memory, while quantum memory can be passed between rounds and similarly retained by Bob’s device.
  • For collective attacks, the shared state is an identical product across rounds and measurements depend only on the current input, making the devices memoryless and identically independent.
  • The asymptotic one-way key rate from Bob to Alice is lower-bounded by the Devetak–Winter expression, combining Alice-Bob mutual information with Eve-Bob Holevo information.
  • Eve’s reduced and outcome-conditioned states determine the Holevo term, and the optimal collective attack uses a purification of Alice and Bob’s shared state.
  • Because χ(A0 : E) ≥ χ(B1 : E), Bob-to-Alice public postprocessing gives the advantageous rate used for the protocol.

2.3 Security of our protocol against collective attacks

The protocol derives a tight collective-attack bound on Eve’s Holevo information from the observed QBER Q and CHSH violation S, and gives an explicit attack that saturates it. For depolarizing-channel correlations, the device-independent key-rate threshold is lower than in the standard scenario.

  • Security bound: The main theorem yields a key-rate expression for fixed observed Q and S after bounding Eve’s Holevo information.The theorem is proved in the following subsection, and its bound is tight via an explicit attack.
  • Key-rate comparison: The key rate is evaluated without assuming the particular state or qubit measurements used to generate the illustrated correlations.The comparison uses the same correlations under device-independent and standard apparatus-control assumptions.
  • Key-rate comparison: For correlations satisfying S = 2(1 − 2Q), the device-independent critical QBER is 7.1%, compared with 11% under usual QKD assumptions.The plotted correlations arise from a Bell state transmitted through a depolarizing channel.
  • Optimal attack: The optimal collective attack uses a Bell-diagonal two-qubit state and measurements whose choices depend explicitly on the observed Q and S.This dependence makes the attack unavailable under the usual assumption that Alice and Bob control their apparatuses.
  • Optimal attack: Eve’s attack saturates the Holevo-information bound, while the optimal state achieves the observed CHSH violation with minimal Alice–Bob entanglement.The construction exploits entanglement monogamy to maximize Eve’s correlations with the honest parties.

2.4 Proof of upper bound on the Holevo quantity

The proof reduces arbitrary measurement and state descriptions to structured low-dimensional forms, then bounds Eve’s Holevo information using Bell-diagonal states and CHSH violation. Lemmas identify the measurement optimization and the maximal CHSH violation needed to establish the upper bound.

  • Reduction to two-qubit states: The proof is divided into four steps and begins by reducing Eve’s ensemble to mixtures of two-qubit states with a classical label.The label determines which measurements are applied, allowing state-dependent measurements in the device-independent setting.
  • Reduction to two-qubit states: Because CHSH uses two binary settings per party, Alice’s measurement operators decompose into invariant subspaces of dimension at most two.This follows from the unitary product of the two Hermitian ±1 observables and reduces the analysis to two-dimensional blocks.
  • Bell-diagonal normal form: Symmetrization removes coherences between the two eigenspaces of σy ⊗ σy, permitting a Bell-diagonal mixture without reducing Eve’s relevant information.The resulting state retains the nonzero elements needed for the statistics while satisfying the required symmetry.
  • Holevo-information optimization: The remaining bound combines entropy inequalities with the maximal CHSH violation achievable by the Bell-diagonal state.The maximal violation is characterized by Lemma 7, completing the ingredients for the Holevo-information upper bound.
  • Holevo-information optimization: For Bell-diagonal states with measurements in the (x, z) plane, Eve’s information is maximized when Bob uses B1 = σz.The choice minimizes the relevant entropy term under the imposed ordering of Bell-state eigenvalues.

2.5 Derivation of the bound (13) in the standard scenario

In the standard scenario, Eve’s information is bounded using the Z-basis error rate and an X-basis error parameter. For the considered correlations, the CHSH value supplies the latter parameter and yields the usual key-rate expression.

  • Standard-scenario bound: In standard BB84 analysis, Eve’s information is bounded from the error rates εz and εx when the Z basis generates the key.The entropy expression follows the conventional unconditional-security calculation.
  • Standard-scenario bound: For this protocol, εz = Q, while the average CHSH value S replaces εx as the parameter used to infer Eve’s information.Evaluating S on the Bell-diagonal state links the two descriptions.
  • Derivation: The Bell-diagonal parametrization gives λ1 − λ4 = 1 − εz − εx, establishing the relation between the CHSH value and the error parameters.This relation is obtained by substituting the parametrized eigenvalues into the CHSH expression.
  • Derivation: Using h(εx) = h(1 − εx) yields the standard-scenario bound in equation (13).The binary-entropy symmetry completes the derivation.

3 Loopholes in Bell experiments and DIQKD

Bell-test loopholes constrain DIQKD because security requires genuine Bell-inequality violation, but they are treated as technological challenges rather than failures of the DIQKD concept. Detection inefficiency is especially important because untrusted devices invalidate fair-sampling assumptions and require all outcomes to be included.

  • DIQKD security relies on Bell-inequality violation, so loopholes that permit local descriptions directly affect security tests.
  • Locality loophole: The locality loophole arises when measurement choices or outputs can be connected by sub-luminal influences or predetermined settings.Closing it for DIQKD requires preventing quantum signals from traveling between Alice’s and Bob’s devices, rather than enforcing full space-like separation.
  • Detection loophole: The detection loophole exploits setting-dependent no-detection events, allowing local models to reproduce apparent non-local correlations below an inequality-specific efficiency threshold.For CHSH, the required detector efficiency is η > 82.8%.
  • Experimental status: All Bell experiments discussed suffer from at least one major loophole: photonic experiments lack sufficient detection efficiency, whereas ion experiments have inadequate locality.
  • DIQKD implications: Loopholes do not undermine DIQKD in principle because their closure can be checked from classical input-output relations and timing without characterizing device internals.Present-day technology may nevertheless make it difficult to construct devices that pass these security tests.
  • Detection inefficiency: A positive key rate in the illustrated ideal-correlation scenario requires detector efficiency η = 0.924.The analysis treats no-detection events as a −1 outcome, converting a three-output device into an effective two-output device.
  • Detection loophole: Fair sampling is unjustified for DIQKD because untrusted devices may correlate particle states with detection probabilities, making detection-loophole closure crucial.Some experiments have closed this loophole, but not yet over distances relevant for QKD.
  • Implementation boundaries: Alternative implementation proposals distinguish line losses, attributed to Eve in security analysis, from detector losses that may motivate trusted or separately calibrated detectors.Treating detectors as trusted creates an intermediate setting between usual QKD and fully device-independent QKD.

4 Discussion and open questions

The discussion identifies DIQKD as secure under a minimal set of assumptions for collective attacks, while highlighting practical Bell-test loopholes and several theoretical extensions. Open questions concern stronger attack models, alternative correlations, dimensionality, reconciliation, and partial setting information.

  • Discussion and open questions: DIQKD security requires only secure locations, trusted randomness and classical processing, an authenticated channel, and the validity of quantum theory in the collective-attack setting.The proof establishes secure DIQKD for the restricted scenario of collective attacks.
  • Discussion and open questions: Bell-test loopholes, particularly the detection loophole, are an important applied concern because Bell-inequality violation is necessary for secure DIQKD.The detection loophole therefore has implications for cryptography, not only for foundational experiments.
  • Discussion and open questions: Future work includes DIQKD protocols using other Bell inequalities, larger alphabets, and more general bounds on Eve’s information.The discussion also asks how these choices compare with standard QKD.
  • Discussion and open questions: The two-qubit reduction underlying the proof may not extend to more complex measurement scenarios, while one-way reconciliation remains the analyzed setting.Open questions concern finite-dimensional realizations, two-way reconciliation, and partially known measurement settings; no-signalling approaches currently have impractical rates and noise resistance for quantum correlations.
  • Discussion and open questions: Extending the proof beyond collective attacks remains open because device behavior may depend on previous inputs and outputs through memory effects.It is unresolved whether general attacks can outperform collective, memoryless attacks.
Loading 0903.4460v1…