Survey
* Your assessment is very important for improving the work of artificial intelligence, which forms the content of this project
* Your assessment is very important for improving the work of artificial intelligence, which forms the content of this project
Quantum Key Distribution
and de Finetti’s Theorem
Matthias Christandl
Institute for Theoretical Physics, ETH Zurich
June 2010
Matthias Christandl
Quantum Key Distribution and de Finetti’s Theorem
Overview
Introduction to Quantum Key Distribution
Two tools for proving security:
De Finetti’s Theorem
Post-Selection Technique
Summary
Matthias Christandl
Quantum Key Distribution and de Finetti’s Theorem
Quantum Key Distribution
Alice und Bob want to communicate in secrecy, but their
phone is tapped.
Eve
phone
Alice
Matthias Christandl
Bob
Quantum Key Distribution and de Finetti’s Theorem
Quantum Key Distribution
Alice und Bob want to communicate in secrecy, but their
phone is tapped.
Eve
phone
Alice
Bob
If they share key (string of secret random numbers),
Eve
Alice
message
+key
-------------cipher
Bob
cipher
- key
-------------message
cipher is random and message secure (Vernam, 1926)
Matthias Christandl
Quantum Key Distribution and de Finetti’s Theorem
Quantum Key Distribution
key is as long as the message
Shannon (1949): this is optimal /
secret communication =
ˆ key distribution
Matthias Christandl
Quantum Key Distribution and de Finetti’s Theorem
Quantum Key Distribution
key is as long as the message
Shannon (1949): this is optimal /
secret communication =
ˆ key distribution
possible key distribution schemes:
Alice and Bob meet ⇒ impractical
Weaker level of security
assumptions on speed of Eve’s computer
(public key cryptography)
assumptions on size of Eve’s harddrive
(bounded storage model)
Use quantum mechanical effects
(Bennett & Brassard 1984, Ekert 1991)
Matthias Christandl
Quantum Key Distribution and de Finetti’s Theorem
Quantum Key Distribution
Quantum mechanics governs atoms and photons
Spin- 21 system: points on the sphere
cos θ
iϕ
e sin θ
= cos θ|0i + e iϕ sin θ|1i ∈ C2
unit of information, the quantum bit or ”qubit”
Matthias Christandl
Quantum Key Distribution and de Finetti’s Theorem
Quantum Key Distribution
Quantum mechanics governs atoms and photons
Spin- 21 system: points on the sphere
cos θ
iϕ
e sin θ
= cos θ|0i + e iϕ sin θ|1i ∈ C2
unit of information, the quantum bit or ”qubit”
we measure a qubit along a basis
if basis is {|0i, |1i}, we obtain ’0’ with probability cos2 θ.
in general: express qubit in basis and consider
|amplitude|2 .
Matthias Christandl
Quantum Key Distribution and de Finetti’s Theorem
Quantum Key Distribution
The state of two qubits: |ψi ∈ C2 ⊗ C2 , hψ||ψi = 1
|ψi = ψ00 |0i ⊗ |0i + ψ01 |0i ⊗ |1i + ψ10 |1i ⊗ |0i + ψ11 |1i ⊗ |1i
= ψ00 |0i|0i + ψ01 |0i|1i + ψ10 |1i|0i + ψ11 |1i|1i
each qubit is measured in basis {|0i, |1i}
measurement basis {|0i|0i, |0i|1i, |1i|0i, |1i|1i}
obtain ’ij’ with probability |ψij |2 .
Matthias Christandl
Quantum Key Distribution and de Finetti’s Theorem
Quantum Key Distribution
Entangled state of two qubits
Matthias Christandl
√1 (|0iA |0iB
2
+ |1iA |1iB )
Quantum Key Distribution and de Finetti’s Theorem
Quantum Key Distribution
Entangled state of two qubits √12 (|0iA |0iB + |1iA |1iB )
New basis
1
1
|+i = √ (|0i + |1i) |−i = √ (|0i − |1i)
2
2
easy calculation
1
1
√ (|0iA |0iB + |1iA |1iB ) = √ (|+iA |+iB + |−iA |−iB )
2
2
Matthias Christandl
Quantum Key Distribution and de Finetti’s Theorem
Quantum Key Distribution
Entangled state of two qubits √12 (|0iA |0iB + |1iA |1iB )
New basis
1
1
|+i = √ (|0i + |1i) |−i = √ (|0i − |1i)
2
2
easy calculation
1
1
√ (|0iA |0iB + |1iA |1iB ) = √ (|+iA |+iB + |−iA |−iB )
2
2
Alice and Bob measure in basis {|0i, |1i} ⇒ same result
Alice and Bob measure in basis {|+i, |−i} ⇒ same result
Converse is true, too:
same measurement result ⇒ they have state
√1 (|0iA |0iB + |1iA |1iB )
2
Alice and Bob can test whether or not they have the
state √12 (|0iA |0iB + |1iA |1iB )!
Matthias Christandl
Quantum Key Distribution and de Finetti’s Theorem
Quantum Key Distribution
Assume that Alice and Bob have the state
|φiAB = √12 (|0iA |0iB + |1iA |1iB )
and measure in the same basis.
Can someone else guess the result?
Matthias Christandl
Quantum Key Distribution and de Finetti’s Theorem
Quantum Key Distribution
Assume that Alice and Bob have the state
|φiAB = √12 (|0iA |0iB + |1iA |1iB )
and measure in the same basis.
Can someone else guess the result?
No! The measurement result is secure!
Total state of Alice, Bob and Eve
|ψiABE = |φiAB ⊗ |φiE ,
because Alice and Bob have a pure state
Eve is not at all correlated with Alice and Bob!
Monogamy of entanglement
Matthias Christandl
Quantum Key Distribution and de Finetti’s Theorem
Quantum Key Distribution
The Quantum Key Distribution Protocol
Distribution
Alice
1
Matthias Christandl
Eve
glass fibre
1
Bob
1
Quantum Key Distribution and de Finetti’s Theorem
Quantum Key Distribution
The Quantum Key Distribution Protocol
Distribution
Alice
1
2
Matthias Christandl
Eve
glass fibre
1
2
Bob
1
2
Quantum Key Distribution and de Finetti’s Theorem
Quantum Key Distribution
The Quantum Key Distribution Protocol
Distribution
Eve
Alice
1
2
n
Matthias Christandl
glass fibre
1
2
n
Bob
1
2
n
Quantum Key Distribution and de Finetti’s Theorem
Quantum Key Distribution
The Quantum Key Distribution Protocol
Distribution
Eve
Alice
1
2
n
1
glass fibre
2
n
Bob
1
2
n
Measurement with {|0i, |1i} or {|+i, |−i}
0
1
1
Matthias Christandl
0
0
1
Quantum Key Distribution and de Finetti’s Theorem
Quantum Key Distribution
The Quantum Key Distribution Protocol
Distribution
Eve
Alice
1
2
n
1
2
glass fibre
n
Bob
1
2
n
Measurement with {|0i, |1i} or {|+i, |−i}
0
1
1
?
Error-free? |φiAB =
√1 (|0iA |0iB
2
0
0
1
+ |1iA |1iB )
phone
Matthias Christandl
Quantum Key Distribution and de Finetti’s Theorem
Quantum Key Distribution
The Quantum Key Distribution Protocol
Distribution
Eve
Alice
1
2
n
1
2
glass fibre
n
Bob
1
2
n
Measurement with {|0i, |1i} or {|+i, |−i}
0
1
1
?
Error-free? |φiAB =
√1 (|0iA |0iB
2
0
0
1
+ |1iA |1iB )
phone
If YES: key. If NO: no key
Matthias Christandl
Quantum Key Distribution and de Finetti’s Theorem
Quantum Key Distribution
Proof works as long as |ΨinABC = |ψi⊗n
ABE .
Alice
Matthias Christandl
Bob
Quantum Key Distribution and de Finetti’s Theorem
Quantum Key Distribution
Proof works as long as |ΨinABC = |ψi⊗n
ABE .
Alice
Bob
But why should Eve prepare such a state?
Why not the following?
Alice
Bob
We can assume: π|ΨinABC = |ΨinABC for all π ∈ Sn .
Matthias Christandl
Quantum Key Distribution and de Finetti’s Theorem
Quantum Key Distribution
Proof works as long as |ΨinABC = |ψi⊗n
ABE .
Alice
Bob
But why should Eve prepare such a state?
Why not the following?
Alice
Bob
We can assume: π|ΨinABC = |ΨinABC for all π ∈ Sn .
Goal: two methods that reduce second to first case!
Matthias Christandl
Quantum Key Distribution and de Finetti’s Theorem
De Finetti’s Theorem
De Finetti’s Theorem (Diaconis and Freedman, 1980)
Drawing balls from an urn with or without replacement results
in almost the same probability distribution.
If k are drawn out of n, then
||P k −
X
i
k
pi Qi×k ||1 ≤ const .
n
Matthias Christandl
Quantum Key Distribution and de Finetti’s Theorem
De Finetti’s Theorem
Quantum generalisations by Størmer, Hudson & Moody, and
Werner et al.. (n = ∞)
Quantum De Finetti Theorem
Christandl, König, Mitchison, Renner, Comm. Math. Phys. 273, 473498 (2007)
Let |Ψin be a permutation-invariant state: π|Ψin = |Ψin for
all π ∈ Sn , then
||ρk −
X
pi |ψihψ|⊗k
i ||1 ≤ const
i
Matthias Christandl
k
n
Quantum Key Distribution and de Finetti’s Theorem
De Finetti’s Theorem
Alice and Bob select a random sample of pairs
(after pairs have been distributed!)
Alice
Bob
Alice
Bob
Quantum de Finetti
⇒ can use proof from before (tensor product)
⇒ proof of the security of Quantum Key Distribution!
Matthias Christandl
Quantum Key Distribution and de Finetti’s Theorem
De Finetti’s Theorem
Closer look: deviation from perfect key (due to quantum
de Finetti theorem)
≈ k/n
n: number of pairs that Eve distributed
k: number of bits of key
Matthias Christandl
Quantum Key Distribution and de Finetti’s Theorem
De Finetti’s Theorem
Closer look: deviation from perfect key (due to quantum
de Finetti theorem)
≈ k/n
n: number of pairs that Eve distributed
k: number of bits of key
key rate r ≈ k/n ≈ ≈ 0 ⇒ not good enough
need replacement for de Finetti theorem
Renner’s exp. de Finetti theorem, involved, non-optimal
Matthias Christandl
Quantum Key Distribution and de Finetti’s Theorem
Post-Selection Technique
Statistical process Λ
Input: n-bit string
Output: success or failure
Lemma
If for any i.i.d. distribution
Prob[failure] ≤ ,
then
Prob[failure] ≤ (n + 1)
for any permutation-invariant distribution.
Typically, ≈ 2−αn , in information-theoretic tasks.
Matthias Christandl
Quantum Key Distribution and de Finetti’s Theorem
Post-Selection Technique
Proof: P permutation-invariant distribution on n bits:
P=
n
X
pk Q k .
k=0
Qk equal probability for all strings with k zeros.
Take P as n-fold i.i.d distribution, where ’0’ has probability r .
p_k
r*n
k
Certainly, prn ≥ 1/(n + 1) ⇒ Qrn ≤ (n + 1)Pr .
Matthias Christandl
Quantum Key Distribution and de Finetti’s Theorem
Post-Selection Technique
Qrn ≤ (n + 1)Pr .
Prob[failure]P =
X
pk Prob[failure]Qk
k
≤
X
pk (n + 1)Prob[failure]Pk/n
k
≤ (n + 1)
2
Matthias Christandl
Quantum Key Distribution and de Finetti’s Theorem
Post-Selection Technique
Quantum operation Λ
Input: n-qubit state
Output: success or failure (classical bit)
Post-selection Technique
Christandl, König, Renner, Phys. Rev. Lett. 102, 020504 (2009)
For any input |Ψin = |ψi⊗n
Prob[failure] ≤ ,
then
Prob[failure] ≤ n3 for any state permutation-invariant state |Ψi.
Typically, ≈ 2−αn , in information-theoretic tasks.
Matthias Christandl
Quantum Key Distribution and de Finetti’s Theorem
Post-Selection Technique
The Quantum Key Distribution Protocol
Distribution |ΨinABC = |ψi⊗n
ABE
Eve
Alice
1
2
1
glass fibre
n
2
n
Bob
1
2
n
Measurement with {|0i, |1i} or {|+i, |−i}
Error-free?
0
1
1
0
0
1
phone
If YES: key. If NO: no key
By assumption: Prob[failure] ≤ Matthias Christandl
Quantum Key Distribution and de Finetti’s Theorem
Post-Selection Technique
The Quantum Key Distribution Protocol
Distribution |ΨinABC permutation-invariant (or general)
Eve
Alice
1
2
n
1
glass fibre
2
n
Bob
1
2
n
Measurement with {|0i, |1i} or {|+i, |−i}
Error-free?
0
1
1
0
0
1
phone
If YES: key. If NO: no key
Post-selection tech.: Prob[failure] ≤ poly (n) ≈ poly (n)2−δ
Matthias Christandl
2n
Quantum Key Distribution and de Finetti’s Theorem
Post-Selection Technique
security proof against the most general attacks
optimal security parameters
relevant in current experiments (since n ≈ 105 )
Eve’s best attack |ΨnABE i = |ψABE i⊗n
conceptual and technical simplification of security proofs
Other applications: Quantum Reverse Shannon Theorem
Berta, Christandl and Renner, arXiv:0912.3805
Matthias Christandl
Quantum Key Distribution and de Finetti’s Theorem
Summary
Quantum Key Distribution
Alice
Bob
Alice
Bob
Quantum de Finetti
De Finetti’s Theorem
Post-Selection Technique
optimal security parameters
applications outside quantum cryptography:
quantum Shannon theory and quantum tomography
Matthias Christandl
Quantum Key Distribution and de Finetti’s Theorem