Source-linked AI summary
Semi-device-independent security of one-way quantum key distribution
Marcin Pawlowski, Nicolas Brunner
TL;DR
The paper asks whether one-way QKD can obtain stronger-than-standard security without characterized devices, despite fully device-independent security being impossible. It uses bounded-dimensional quantum systems together with dimension witnesses and random-access codes, showing security against individual attacks in a semi-device-independent scenario. The result is tied to observed data-table behavior, while bounded dimensionality and individual-attack assumptions remain scope boundaries.
Problem
The paper asks whether strong device-independent-style security can be established for one-way QKD when devices are non-characterized, given that full device-independent security is impossible without a dimension bound.
Method
The proof uses bounded-dimensional quantum systems, observed data tables, dimension witnesses, and their connection to random-access codes.
Results
Security against individual attacks is possible in the semi-device-independent setting, with security obtained when PB > 5+8 ≈0.8415.
Takeaways & Limitations
Semi-device-independent QKD can apply directly to one-way configurations without device assumptions beyond bounded dimension.
Takeaways & Limitations
The result is a proof of principle requiring bounded dimensionality and is not yet established for losses, detection imperfections, or more general attacks.
Abstract
from arXiv · showhide
By testing nonlocality, the security of entanglement-based quantum key distribution (QKD) can be enhanced to being 'device-independent'. Here we ask whether such a strong form of security could also be established for one-way (prepare and measure) QKD. While fully device-independent security is impossible, we show that security can be guaranteed against individual attacks in a semi-device-independent scenario. In the latter, the devices used by the trusted parties are non-characterized, but the dimensionality of the quantum systems used in the protocol is assumed to be bounded. Our security proof relies on the analogies between one-way QKD, dimension witnesses and random-access codes.
I. PRELIMINARIES
One-way QKD sends Alice’s encoded quantum systems to Bob for measurement, then uses estimated errors and classical post-processing to produce a key. In the semi-device-independent setting, devices are uncharacterized while Alice’s emitted systems have bounded dimension and specified leakage assumptions.
- Alice encodes classical information in quantum systems, sends them to Bob, and Bob measures them to decode information.
- After repeated runs, Alice and Bob estimate an error rate and apply error correction and privacy amplification to obtain a sifted key with arbitrarily small Eve information.
- The semi-device-independent model assumes known Hilbert-space dimension while treating Alice’s preparations and Bob’s measurements as non-characterized black boxes.
- Alice chooses among preparations ρa ∈ C^d, while Bob chooses measurements My and obtains outcomes b; Eve may know shared classical variables λ.
- Security can be inferred from the observed data table P(b|a, y), without knowing how it was generated beyond Alice’s bounded-dimensional quantum output.
- The security analysis restricts Eve to individual attacks and assumes no inputs or outputs of the devices leak to her.
II. DIMENSION WITNESSES
Dimension witnesses distinguish data tables produced by bounded-dimensional classical systems from those achievable with quantum systems. Applied to BB84, the observed table is classically reproducible, so the protocol is insecure in this setting.
- A semi-device-independent protocol requires that its quantum data table cannot be reproduced by classical systems of the same dimension.
- Without a dimension bound, every data table can be reproduced with sufficiently large classical systems, making full device-independent security impossible.
- Dimension witnesses provide lower bounds on the classical dimension needed to reproduce a data table and can be violated by quantum systems of the same dimension.
- The qubit analysis uses four preparations indexed by two bits and two binary measurements, producing eight correlators in each data table.
- The classical-bit data tables form an eight-dimensional polytope whose facets are tight two-dimensional classical witnesses.
- The main witness is used to assess the security of one-way QKD protocols and is connected to random-access codes.
- BB84 uses four qubit preparations based on the σz and σx eigenstates and Bob’s measurements M0 = σz and M1 = σx.
- S = 2 for the BB84 data table, which can be reproduced by sending one classical bit when Alice and Bob share randomness.
III. CONNECTION TO RANDOM-ACCESS CODES
The witness S is equivalent to a 2-to-1 random-access code: Bob guesses one of Alice’s two input bits from a received quantum system. Qubits outperform one-bit classical communication, producing a quantum violation linked to the protocol’s security construction.
- Random-access-code formulation: A 2-to-1 random-access code gives Alice two uniformly distributed bits and asks Bob to guess a randomly selected bit.With one classical bit, Bob’s optimal average success probability is 3/4.
- Random-access-code formulation: The witness S represents this code, with Alice’s preparations encoding each input pair and Bob’s measurement outcome serving as his guess for the selected bit.The coefficient relation w_a0a1,y = (−1)^a_y connects the witness to the guessing task.
- Classical bound: The value of S determines Bob’s success probability, with the classical bound S ≤ 2 equivalent to P_B ≤ 3/4.The relation can also be used in the reverse direction: success probability determines the witness value.
IV. SECURITY OF ONE-WAY QKD
The protocol uses optimal qubit preparations and measurements, estimates the data table and guessing probability, and derives security from mutual-information and random-access-code bounds. Security is obtained above a success probability of approximately 0.8415, slightly below the qubit optimum.
- Protocol: Alice sends qubit preparations encoding two random bits, while Bob randomly chooses a measurement and guesses the corresponding bit.After many repetitions, Alice and Bob publicly reveal part of their data to estimate the data table and compute P_B.
- Security criterion: The security proof uses the Csiszár–Körner condition I(A:B) > I(A:E) and a sufficient condition expressed through binary entropy.The basis choice y_j identifies which bit Bob attempts to guess, and h(p) denotes binary entropy.
- Eavesdropper disturbance: When Eve guesses a different bit from Bob, her measurement necessarily disturbs Bob’s statistics, yielding complementary bounds for the two bits.The argument applies symmetrically after interchanging a_0 and a_1.
V. DISCUSSION
The paper shows that one-way QKD can achieve semi-device-independent security against individual attacks using dimension witnesses and random-access codes. The result is a proof of principle whose practical scope remains limited by bounded-dimensionality assumptions and unaddressed imperfections and attack models.
- Security against individual attacks is possible for one-way QKD in a semi-device-independent context.The proof connects one-way QKD with dimension witnesses and random-access codes.
- The approach requires no device assumptions beyond Alice’s emitted preparations having bounded dimension.The authors describe this as a relaxation of standard QKD proof assumptions that applies directly to the one-way configuration.
- The result is currently a proof of principle requiring study of losses, detection efficiency, more general attacks, and tighter security bounds.The authors also leave open whether all data tables violating a classical dimension witness provide security.
- Bounded dimensionality is the main drawback because it excludes side-channels from which Eve could extract information.The authors suggest that protocols using more preparations might partly relax this requirement if qubits remain secure for higher-dimensional preparations.
- The connection between semi-device-independent one-way QKD and device-independent entanglement-based QKD remains an open foundational question.The proposed direction is motivated by the strong link between nonlocality and random-access codes.