REVIEW 3 major objections 4 minor 62 references
Analytic R\'enyi Entropy Bounds for Device-Independent Cryptography
T0 review · 3 major / 4 minor · reviewed 2026-08-06 · deepseek-v4-flash
Pith's one-line read The paper derives exact closed-form lower bounds on Rényi entropies from CHSH scores, and shows they improve finite-size DIQKD key rates by about a factor of three.
desk verdict The analytic Rényi rate functions are a genuine, well-proven contribution; the finite-size key-rate application is not rigorous until the numerical hα is certified. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The central object is the rate function $f_H(S) = \inf_\Lambda H(A|X=0,E)$ over all quantum strategies $\Lambda$ with expected CHSH score $S$. The paper proves this infimum is attained on a two-qubit strategy with a classical side-information register, and the proof routes through a canonical classical-quantum state $\sigma_{AE} = \frac12 |0\rangle\langle0| \otimes |\psi_=\rangle\langle\psi_=| + \frac12 |1\rangle\langle1| \otimes |\psi_{\ne}\rangle\langle\psi_{\ne}|$ with $|\langle\psi_=|\psi_{\ne}\rangle| = g_S = \sqrt{S^2/4-1}$. The load-bearing identity is that for this canonical state the sandwiched Rényi divergences evaluate exactly to the closed-form expression involving $\varphi_\mu(S)$. The other load-bearing mechanism is concavity, established in Appendix B6, of the functions $h_1(S) = [((1-g_S)/2)^{1/\alpha} + ((1+g_S)/2)^{1/\alpha}]^\alpha$ and $h_3(S) = ((1-g_S)/2)^{1/\alpha} + ((1+g_S)/2)^{1/\alpha}$, which lets the convex mixture over Eve's classical register be replaced by the value at the average score. A general replacement lemma (Lemma 7) guarantees that any two-input/two-output strategy has entropy at most that of the canonical state, so the bound is tight.
What would settle it
One concrete check: run a convergent semidefinite-programming relaxation of the infimum in Eq. (3) at some $\alpha>1$ and $S\in(2,2\sqrt{2})$ and compare with the closed-form formula; a value strictly below would falsify tightness, and for the finite-size claim a dual-certifying convex solver on Eq. (13) that returns an $h_\alpha$ below the paper's value would falsify the reported rates.
Extended reading notes
Core claim
The central discovery is that the optimization problem of minimizing a sandwiched Rényi conditional entropy over all quantum strategies with a fixed CHSH score is exactly solvable, and the minimizer is the same for every $\alpha>1$. Eve's optimal strategy prepares the state $\sqrt{P_+}|\phi^+\rangle|0\rangle_E + \sqrt{P_-}|\phi^-\rangle|1\rangle_E$ with $P_\pm = (1 \pm g_S)/2$ and $g_S=\sqrt{S^2/4-1}$, with Alice and Bob measuring the specific Pauli observables given in Eq. (9). For this strategy the sandwiched Rényi entropies evaluate exactly to $f_{\widetilde H^\uparrow_\alpha}(S) = 1 + \frac{2\alpha-1}{1-\alpha}\log \varphi_{\alpha/(2\alpha-1)}(S)$ and $f_{\widetilde H^\downarrow_\alpha}(S) = 1 + \frac{\alpha}{1-\alpha}\log \varphi_{1/\alpha}(S)$. The proof reduces arbitrary two-input/two-output strategies to qubit strategies, applies a general lemma showing the entropy is monotone under a canonical classical-quantum replacement with overlap $g_S$, and uses concavity of the map $S \mapsto ((1-g_S)/2)^{1/\alpha} + ((1+g_S)/2)^{1/\alpha}$ to collapse convex mixtures. The same machinery yields analytic rate functions for asymmetric CHSH inequalities and Petz-Rényi entropies, and a separate theorem incorporates noisy preprocessing.
Load-bearing premise
The load-bearing premise is that the numerical optimization defining $h_\alpha$ in Eq. (13) has actually found the global minimum: the paper argues this from coordinate-wise convexity, but that does not imply joint convexity, so if the reported value overestimates the true optimum, the factor-of-three improvement in finite-size rates would shrink.
Editorial extensions
If this is right
- The Rényi Entropy Accumulation Theorem [15] can now be applied to CHSH-based DIQKD with tight single-round entropy bounds, giving finite-size key rates about three times higher at the $n = 1.5\times10^6$ rounds of the recent experiment [27] and reducing the minimum $n$ for a nonzero rate by nearly a factor of three.
- The von Neumann rate function of [11] is recovered in the limit $\alpha\to1$, and the min-entropy rate function of [20] is recovered at $\alpha=2$, so the result unifies the previously known special cases.
- The same analytic framework extends to asymmetric CHSH inequalities [17] and to noisy preprocessing [16], providing further routes to higher rates and lower detection-efficiency thresholds.
- The rate functions extend by limits to $\alpha=\infty$ and $\alpha=2$ for the relevant families, with sharp discontinuity at the maximal score, showing the bounds remain tight at edge cases.
- Because the bounds are tight, future improvements in the finite-size rates must come from the accumulation theorem or protocol design rather than from tighter single-round entropy certificates.
Reading between the lines
- The closed-form nature of the rate functions may allow the Rényi parameter $\alpha$ in the finite-size key-length formula to be optimized analytically, potentially improving rates further without numerical search.
- The same reduction machinery—qubit reduction plus a canonical two-vector state—is likely to yield analytic Rényi bounds for other bipartite Bell inequalities whose extremal strategies are effectively qubit, giving a general tool for device-independent security.
- The numerical evaluation of $h_\alpha$ in Eq. (13) is the one non-certified ingredient in the finite-size claim; a convex solver returning dual bounds could either confirm or revise the reported factor-of-three improvement.
- The factor-of-three gain is specific to the experimental parameters and protocol choices of the comparison; the closed-form formulas now make it straightforward to map where Rényi EAT outperforms von Neumann EAT across the full range of CHSH scores.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. This paper derives closed-form, tight rate functions for conditional Rényi entropies of a binary output A given Eve's quantum side information, as a function of the expected CHSH score S. Theorem 2 gives formulas for f_eH↑_α(S) and f_eH↓_α(S) in terms of the function φ_μ(S), and Theorem 5 extends the statement to asymmetric CHSH scores and Petz-Rényi entropies. The proof proceeds via a qubit reduction (Lemma 7), an exact evaluation on a canonical two-vector state, and concavity/monotonicity arguments in Appendix B. The authors then apply the Rényi entropy accumulation theorem [15] to obtain finite-size DIQKD key rates, and compare them with the experiment of [27], reporting roughly a factor-of-three improvement at n = 1.5 × 10^6. The finite-size analysis depends on an optimization quantity h_α defined in Eq. (13) and evaluated numerically in Appendix D3 using a generic heuristic.
Significance. If the analytic rate-function theorem stands, it is a substantial contribution: it supplies the missing single-round Rényi entropy bound needed to use REAT for CHSH protocols, subsumes the von Neumann bound of [11] and the min-entropy bound of [20] as limits, and is proved by explicit calculation with tightness exhibited by a concrete attack family. The advertised finite-size improvement, however, rests on a numerical lower bound that is not certified. The analytic theorem and the finite-size application are separable; the former appears sound, while the latter requires either a rigorous certified computation of h_α or a softened statement of the improvement.
major comments (3)
- [Section III.B, Eq. (13), and Appendix D3] The inequality direction in Eq. (13) is inconsistent with Eq. (12). Eq. (12) lower-bounds the accumulated entropy by n h_α − (α/(α−1)) log(1/Pr[Ω_AT]), so a valid h_α must be no larger than the infimum in Eq. (13). The displayed inequality h_α ≥ inf has the opposite direction and, taken literally, makes the bound vacuous; if it is a typo for h_α ≤ inf, Appendix D3 still does not supply the required lower bound, because a feasible point obtained by minimization is an upper bound on the infimum. The values of h_α used for Figure 1 are therefore not certified, and the factor-of-three improvement over [27] is not a rigorous security statement.
- [Appendix D3] The global-optimality justification is invalid: coordinate-wise convexity does not imply joint convexity, and no dual feasible solution or explicit certificate is provided. Since the security proof requires a lower bound on h_α, the authors should either solve the optimization with a method that returns a certified lower bound (e.g., a convex dual or a rigorous branch-and-bound), or present the finite-size rates as heuristic estimates rather than proven key rates.
- [Appendix B1 and Lemma 7] The proof restricts to two-input two-output projective measurements, while Definition 1 optimizes over all quantum strategies. The statement and proof of Lemma 7 assume rank-one projective measurements on a qubit, and the later derivations inherit this restriction. The manuscript should state explicitly why the infimum over general strategies (including POVMs and larger Hilbert spaces) is attained, or is lower-bounded, by this restricted class; otherwise the claimed tightness of the rate functions over all strategies is not fully established.
minor comments (4)
- [Appendix C, Theorem 20] The notation introducing the concave envelope is garbled: the text reads 'writing “h to denote the concave envelope of an arbitrary function h'. Please define the function ~h_H explicitly before using it.
- [Appendix D3] The numerical implementation used to evaluate h_α for Figure 1 is not described beyond the heuristic statement in Appendix D3; including the code or an explicit description of the discretization and stopping criteria would help reproducibility.
- [Throughout] The subscript/superscript placement in expressions such as 'f eH↓α' makes them difficult to read; introducing a named function for the quantity on the right-hand side of Eq. (13) would improve readability.
- [Eq. (D5)] The error-correction length ℓ_EC is estimated from simulations in [27] and is used to set the completeness parameter; the heuristic nature of this estimate is acknowledged in Appendix D1, but it should also be stated more prominently in the main text.
Circularity Check
No significant circularity: the analytic rate-function proof is self-contained and the REAT citation is independent support.
full rationale
Theorem 2 is derived from first principles rather than from the quantities it predicts. Lemma 7 reduces arbitrary strategies to canonical classical-quantum states using only properties that hold for the relevant Rényi entropies (local unitary invariance, classical linearity, and data processing), and the overlap bound is quoted from [17], an external published source. The explicit diagonalizations in Appendices B2 through B5 produce the closed-form expressions, concavity is proved in Appendix B6, and tightness is demonstrated by an explicit saturating strategy in Appendix B7. No parameter is fitted to the target key rates, and the α→1 and α=2 limits are consistency checks rather than inputs. The finite-size application invokes the Rényi EAT of [15], whose author list overlaps with two present authors; however, that theorem is a general entropy-accumulation result whose stated assumptions do not include the rate-function result proved here, so the citation is independent support rather than a circular load-bearing step. The numerical evaluation of hα in Appendix D3 is heuristic and the inequality direction in Eq. (13) appears inconsistent with the needed lower bound if read literally; these are correctness and certification concerns, not circularity, and they do not affect the analytic theorem. No circular step was found.
Assumptions & free parameters
free parameters (1)
- testing probability γ =
13/256 in Fig. 1a; optimized in units of 1/256 in Fig. 1b
assumptions (5)
- standard math Sandwiched and Petz Rényi divergences satisfy data processing for the alpha ranges used (alpha > 1 for sandwiched, 1 < alpha < 2 for Petz)
- standard math Jordan's lemma qubit reduction: for two-input two-output CHSH strategies, it suffices to consider single-qubit systems per block and classical register I
- domain assumption The bound |<psi=|psi_ne=>| >= g_S from [17, Eqs. (73) and (95)] extends to the Rényi divergences considered here
- domain assumption Rényi Entropy Accumulation Theorem (REAT) as proven in [15] is correct and applicable
- ad hoc to paper The numerical optimization for h_alpha over the acceptance set finds the global minimum
Cite this review
Pith. "Pith review of Analytic R\'enyi Entropy Bounds for Device-Independent Cryptography." pith.science (2026). https://pith.science/paper/R77Q74OA
@misc{pith2026250707365,
author = {Pith},
title = {Pith review of: Analytic R\'enyi Entropy Bounds for Device-Independent Cryptography},
year = {2026},
howpublished = {\url{https://pith.science/paper/R77Q74OA}},
note = {Machine review of arXiv:2507.07365}
}
read the original abstract
Device-independent (DI) cryptography represents the highest level of security, enabling cryptographic primitives to be executed safely on uncharacterized devices. Moreover, with successful proof-of-concept demonstrations in randomness expansion, randomness amplification, and quantum key distribution, the field is steadily advancing toward commercial viability. Critical to this continued progression is the development of tighter finite-size security proofs. In this work, we provide a simple method to obtain tighter finite-size security proofs for protocols based on the CHSH game, which is the nonlocality test used in all of the proof-of-concept experiments. We achieve this by analytically solving key-rate optimization problems based on R\'enyi entropies, providing a simple method to obtain tighter finite-size key rates.
Figures
Reference graph
Works this paper leans on
-
[15]
Generalized Rényi entropy accumulation theorem and 6 generalized quantum probability estimation,
Amir Arqand, Thomas A. Hahn, and Ernest Y.Z. Tan, “Generalized Rényi entropy accumulation theorem and 6 generalized quantum probability estimation,” (2024), arXiv:2405.05912v3
arXiv 2024
-
[27]
Experi- mental quantum key distribution certified by Bell's the- orem,
D. P. Nadlinger, P. Drmota, B. C. Nichol, G. Araneda, D. Main, R. Srinivas, D. M. Lucas, C. J. Ballance, K. Ivanov, E. Y.-Z. Tan, P. Sekatski, R. L. Urbanke, R. Renner, N. Sangouard, and J.-D. Bancal, “Experi- mental quantum key distribution certified by Bell's the- orem,” Nature607, 682–686 (2022)
work page 2022
-
[11]
Device- independent quantum key distribution secure against collective attacks,
Stefano Pironio, Antonio Acín, Nicolas Brunner, Nico- las Gisin, Serge Massar, and Valerio Scarani, “Device- independent quantum key distribution secure against collective attacks,” New Journal of Physics11, 045021 (2009)
work page 2009
-
[20]
Secure device-independent quantum key distribution with causally independent measurement devices
Lluis Masanes, Stefano Pironio, and Antonio Acín, “Se- cure device-independent quantum key distribution with causallyindependentmeasurementdevices,” Naturecom- munications 2, 238 (2011), 1009.1567
work page Pith review arXiv 2011
-
[1]
Qubit Reductions This section contains several known results, which are necessary for future calculations. When both honest parties are restricted to two-input two-output projective measurements, Jordan’s lemma, see e.g. [11], can be used to claim that it is sufficient to consider states and projective measurements of the form ρIQ AQB = X i Pr [I = i] |i⟩...
-
[2]
(Classical linearity): For any stateρABC = P c Pr[C = c]ρc AB ⊗ |c⟩⟨c|C classical onC, we haveQ(A|BC )ρABC =P c Pr[C = c]Q(A|B)ρc AB
-
[3]
(Data processing): For anyρABC ∈ S=(ABC ) we have Q(A|BC )ρABC ≥ Q(A|B)ρAB. Let |ψ⟩ ∈QAQBE with QA and QB being qubit systems, let{Ma}a be a rank-one projective measurement onQA and let ρAE = X a |a⟩⟨a|A ⊗ ρa E (B19) be the post-measurement state such thatgS ≥ 0. Then there exists a state σAE = 1 2 |0⟩⟨0| ⊗ |ψ=⟩⟨ψ=| + 1 2 |1⟩⟨1| ⊗ |ψ̸=⟩⟨ψ̸=| (B20) 10 such...
-
[4]
1 2α−1 1 − gS 2 2−α + 1 2α−1 1 + gS 2 2−α# (B82) = 1 + 1 1 − α log
Derivation of f ¯H↓ α (Sβ) Theorem 12. Let α ∈ (1, 2), |β| ≥1, and Sβ ∈ h 2|β|, 2 p 1 + β2 i . Then f ¯H ↓ α (Sβ) = 1 + 1 1 − α log " 1 − gS 2 2−α + 1 + gS 2 2−α# , (B75) where gS = q S2 β 4 − β2. Proof. For any ρIAE of the form given by Eq. (B14), we first prove that Alice’s measurement outcome after a key- generation measurement satisfies ¯H ↓ α(A|X = 0...
Show all 62 references
-
[5]
2 1−α α 1 − gS 2 1 α + 1 + gS 2 1 α !# (B95) = 1 + α 1 − α log
Derivation of f ¯H↑ α (Sβ) Theorem 13. Let α ∈ (1, 2), |β| ≥1, and Sβ ∈ h 2|β|, 2 p 1 + β2 i . Then f ¯H ↑ α (Sβ) = 1 + α 1 − α log " 1 − gS 2 1 α + 1 + gS 2 1 α # , (B90) where gS = q S2 β 4 − β2. Proof. From [34, Lemma 5.1], we know that ¯H ↑ α (A|E)σ = α 1 − α log h Tr h Tr...
-
[6]
Experimental quantum key distribu- tion certified by Bell’s theorem,
David P Nadlinger, Peter Drmota, Bethan C Nichol, Gabriel Araneda, Dougal Main, Raghavendra Srinivas, David M Lucas, Christopher J Ballance, Kirill Ivanov, EY-Z Tan, et al., “Experimental quantum key distribu- tion certified by Bell’s theorem,” Nature 607, 682–686 (2022)
2022
-
[7]
Toward a Photonic Demonstration of Device-Independent Quantum Key Distribution,
Wen-Zhao Liu, Yu-Zhe Zhang, Yi-Zheng Zhen, Ming- Han Li, Yang Liu, Jingyun Fan, Feihu Xu, Qiang Zhang, and Jian-Wei Pan, “Toward a Photonic Demonstration of Device-Independent Quantum Key Distribution,” Physi- cal Review Letters129, 050502 (2022)
2022
-
[8]
Advances in device- independent quantum key distribution,
Víctor Zapatero, Tim van Leent, Rotem Arnon- Friedman, Wen-Zhao Liu, Qiang Zhang, Harald We- infurter, and Marcos Curty, “Advances in device- independent quantum key distribution,” npj quantum in- formation 9, 10 (2023)
2023
-
[9]
Security of device-independent quantum key distri- bution protocols: a review,
Ignatius W Primaatmaja, Koon Tong Goh, Ernest Y-Z Tan, John T-F Khoo, Shouvik Ghorai, and Charles C-W Lim, “Security of device-independent quantum key distri- bution protocols: a review,” Quantum7, 932 (2023)
2023
-
[10]
Proposed Experiment to Test Local Hidden- Variable Theories,
John Clauser, Michael Horne, Abner Shimony, and R. Holt, “Proposed Experiment to Test Local Hidden- Variable Theories,” Phys. Rev. Lett.23, 880–884 (1969)
1969
-
[12]
En- tropy Accumulation,
Frédéric Dupuis, Omar Fawzi, and Renato Renner, “En- tropy Accumulation,” Communications in Mathematical Physics 379, 867–913 (2020)
2020
-
[13]
Entropy accumulation with improved second-order term,
F. Dupuis and O. Fawzi, “Entropy accumulation with improved second-order term,” IEEE Transactions on In- formation Theory , 1–1 (2019), 1805.11652
2019 arXiv
-
[14]
Generalised entropy accumulation,
Tony Metger, Omar Fawzi, David Sutter, and Renato Renner, “Generalised entropy accumulation,” in 2022 IEEE 63rd Annual Symposium on Foundations of Com- puter Science (FOCS) (2022) pp. 844–850
2022
-
[16]
Noisy Preprocessing Facilitates a Photonic Realization of Device-Independent Quantum Key Distribution,
M Ho, P Sekatski, EY-Z Tan, R Renner, J-D Ban- cal, and N Sangouard, “Noisy Preprocessing Facilitates a Photonic Realization of Device-Independent Quantum Key Distribution,” Physical Review Letters124, 230502 (2020)
2020
-
[17]
Device-independent quantum key distribution with asymmetric CHSH inequalities,
Erik Woodhead, Antonio Acín, and Stefano Piro- nio, “Device-independent quantum key distribution with asymmetric CHSH inequalities,” Quantum5, 443 (2021)
2021
-
[18]
Quantum generalizations of Bell’s inequality,
Boris S Cirel’son, “Quantum generalizations of Bell’s inequality,” Letters in Mathematical Physics4, 93–100 (1980)
1980
-
[19]
Practical device- independent quantum cryptography via entropy accumu- lation,
Rotem Arnon-Friedman, Frédéric Dupuis, Omar Fawzi, Renato Renner, and Thomas Vidick, “Practical device- independent quantum cryptography via entropy accumu- lation,” Nature Communications9, 459 (2018)
2018
-
[21]
On quantum Rényi entropies: A new generalization and some properties,
Martin Müller-Lennert, Frédéric Dupuis, Oleg Szehr, Serge Fehr, and Marco Tomamichel, “On quantum Rényi entropies: A new generalization and some properties,” Journal of Mathematical Physics54 (2013), 1306.3142
2013 arXiv
-
[22]
Strong converse for the classical capacity of entanglement-breaking and Hadamard channels via a sandwiched Rényi relative entropy,
Mark M Wilde, Andreas Winter, and Dong Yang, “Strong converse for the classical capacity of entanglement-breaking and Hadamard channels via a sandwiched Rényi relative entropy,” Communications in Mathematical Physics331, 593–622 (2014)
2014
-
[23]
Quasi-entropies for finite quantum sys- tems,
Dénes Petz, “Quasi-entropies for finite quantum sys- tems,” Reports on Mathematical Physics 23, 57–65 (1986)
1986
-
[24]
Towards a realization of device-independent quantum key distribution,
G Murta, S B van Dam, J Ribeiro, R Hanson, and S Wehner, “Towards a realization of device-independent quantum key distribution,” Quantum Science and Tech- nology 4, 035011 (2019)
2019
-
[25]
Improved DIQKD protocols with finite-size analysis,
Ernest Y.-Z. Tan, Pavel Sekatski, Jean-Daniel Bancal, René Schwonnek, Renato Renner, Nicolas Sangouard, and Charles C.-W. Lim, “Improved DIQKD protocols with finite-size analysis,” Quantum6, 880 (2022)
2022
-
[26]
Bounds on Petz-Rényi Divergences and their Applica- tions for Device-Independent Cryptography,
Thomas A. Hahn, Ernest Y. Z. Tan, and Peter Brown, “Bounds on Petz-Rényi Divergences and their Applica- tions for Device-Independent Cryptography,” (2024), arXiv:2408.12313
2024 arXiv
-
[28]
Cover and Joy A
Thomas M. Cover and Joy A. Thomas,Elements of In- formation Theory 2nd Edition (Wiley Series in Telecom- munications and Signal Processing) (Wiley-Interscience, 2006)
2006
-
[29]
Tight and general finite-size security of quantum key distribution,
Thomas van Himbeeck and Peter Brown, “Tight and general finite-size security of quantum key distribution,” (2025), in preparation
2025
-
[30]
Additivity and chain rules for quantum entropies via multi-index Schatten norms,
Omar Fawzi, Jan Kochanowski, Cambyse Rouzé, and Thomas Van Himbeeck, “Additivity and chain rules for quantum entropies via multi-index Schatten norms,” (2025), arXiv:2502.01611
2025 arXiv
-
[31]
Marginal- constrained entropy accumulation theorem,
Amir Arqand and Ernest Y. Z. Tan, “Marginal- constrained entropy accumulation theorem,” (2025), arXiv:2502.02563
2025 arXiv
-
[32]
Quantum Conditional Entropies,
Roberto Rubboli, Milad M. Goodarzi, and Marco Tomamichel, “Quantum Conditional Entropies,” (2024), arXiv:2410.21976v1 [quant-ph]
2024 arXiv
-
[33]
Device-independent quantum key distribution from generalized CHSH inequalities,
Pavel Sekatski, Jean-Daniel Bancal, Xavier Valcarce, Ernest Y.-Z. Tan, Renato Renner, and Nicolas San- gouard, “Device-independent quantum key distribution from generalized CHSH inequalities,” Quantum 5, 444 (2021)
2021
-
[34]
Marco Tomamichel, Quantum Information Processing with Finite Resources (SpringerInternationalPublishing, 2016)
2016
-
[35]
Hildebrand, Introduction to Numerical Analysis (McGraw-Hill, 1956)
F.B. Hildebrand, Introduction to Numerical Analysis (McGraw-Hill, 1956)
1956
-
[36]
Continuity of quantum entropic quantities via almost convexity,
Andreas Bluhm, Ángela Capel, Paul Gondolf, and An- tonio Pérez-Hernández, “Continuity of quantum entropic quantities via almost convexity,” IEEE Transactions on Information Theory69, 5869–5901 (2023)
2023
-
[37]
Information-theoretic security proof for quantum-key- distribution protocols,
Renato Renner, Nicolas Gisin, and Barbara Kraus, “Information-theoretic security proof for quantum-key- distribution protocols,” Phys. Rev. A72, 012332 (2005)
2005
-
[38]
VHASH Security,
Wei Dai and Ted Krovetz, “VHASH Security,” Cryptol- ogy ePrint Archive, Paper 2007/338 (2007)
2007
-
[39]
Security in quantum cryptography,
Christopher Portmann and Renato Renner, “Security in quantum cryptography,” Reviews of Modern Physics94, 025008 (2022), 2102.00021
2022 arXiv
-
[40]
Privacy Amplification and Decoupling Without Smoothing,
Frédéric Dupuis, “Privacy Amplification and Decoupling Without Smoothing,” IEEE Transactions on Information Theory 69, 7784–7792 (2023)
2023
-
[41]
Trevisan’s Extractor in the Pres- ence of Quantum Side Information,
Anindya De, Christopher Portmann, Thomas Vidick, and Renato Renner, “Trevisan’s Extractor in the Pres- ence of Quantum Side Information,” SIAM Journal on Computing 41, 915–940 (2012)
2012
-
[42]
A modular framework for ran- domness extraction based on Trevisan’s construction,
Wolfgang Mauerer, Christopher Portmann, and Volkher B. Scholz, “A modular framework for ran- domness extraction based on Trevisan’s construction,” (2012), arXiv:1212.0520. 7 Appendix A: Notation and definitions We begin by introducing the notation that we will be using. Quantu...
2012 arXiv
-
[43]
(Local unitary invariance): For any unitaryV on A we have Q(A|B)ρAB = Q(A|B)V ρAB V †
-
[44]
1 − gS 2 1 α |v1⟩⟨v1|E − 1 − g2 S 4 1 2α (|v1⟩⟨v2|E + |v2⟩⟨v1|E) + 1 + gS 2 1 α |v2⟩⟨v2|E # + 1 2 |1⟩⟨1|A ⊗
Derivation of f eH↓ α (Sβ) Theorem 10. Let α ∈ (1, ∞), |β| ≥1, and Sβ ∈ h 2|β|, 2 p 1 + β2 i . Then f eH ↓ α (Sβ) = 1 + α 1 − α log " 1 − gS 2 1 α + 1 + gS 2 1 α # , (B34) where gS = q S2 β 4 − β2. Proof. For any ρIAE of the form given by Eq. (B14), we first prove that Alice’s...
-
[45]
1 − gS 2 1 α′ + 1 + gS 2 1 α′ # (B64) = 1 + α′ 1 − α′ log
Derivation of f eH↑ α (Sβ) Theorem 11. Let α ∈ (1, ∞), |β| ≥1, and Sβ ∈ h 2|β|, 2 p 1 + β2 i . Then f eH ↑ α (Sβ) = f eH ↓ 2− 1 α (Sβ) . (B53) Proof. For anyρIAE of the form given by Eq. (B14), we first consider Alice’s and Eve’s bipartite state for someI = i. Due to Eq. (A4),...
-
[46]
Monotonicity and Concavity Properties In this section, we aim to prove the monotonicity and concavity of the following three functions for certain regions of α >1 and |β| ≥1: h1(Sβ) = " 1 − gS 2 1 α + 1 + gS 2 1 α #α (B103) h2(Sβ) = 1 − gS 2 2−α + 1 + gS 2 2−α (B104) h3(Sβ) = ...
-
[47]
Tightness of Rate Bounds It can be shown that all inequalities are tight by considering the following attack which saturates the bound. First, it is easy to verify that measuring that state p P+ |ϕ+⟩QAQB |0⟩E + p P− |ϕ−⟩QAQB |1⟩E , (B159) where P± = 1 2 (1 ± gS) and gS = q S2 ...
-
[48]
As briefly mentioned previously, some of the resulting formulas are discontinuous with respect toSβ (for |β| ≥1)
Discontinuity Behavior for Edge Cases In this subsection, we justify the claim that the Theorem 5 bounds can be extended to the right-endpoints of the α ranges by taking the respective limits from below. As briefly mentioned previously, some of the resulting formulas are disco...
-
[49]
Finally, we note that the functionsf eH ↑ α (Sβ) and f ¯H ↑ α (Sβ) have no discontinuities forα >1 (within their respective domains of validity, i.e.α ≤ 2 for the latter)
-
[50]
h eH ↓ α (Sβ) i (C6) for all α ∈ (1, ∞), where h eH ↓ α (Sβ) = 1 2α+1
Alternative Concavity Proofs Proposition 18. For all x ∈ [0, 1], the function f3(x) = 1 − √x 1 α + 1 + √x 1 α (B188) is concave forα ∈ (1, 2). Proof. Due to continuity arguments, it is sufficient to considerx ∈ (0, 1). To prove that Eq. (B188) is concave, we need to calculate ...
-
[51]
1 − gx 2 1 α |v1⟩⟨v1|E + 1 − g2 x 4 1 2α (q − ¯q) (|v1⟩⟨v2|E + |v2⟩⟨v1|E) + 1 + gx 2 1 α |v2⟩⟨v2|E # + 1 2 |1⟩⟨1|A ⊗
Proof of Theorem 20 Proof. For anyσIAE of the form given by Eq. (C2), we first consider Alice’s and Eve’s bipartite state for someI = i. For anyσAE as in Eq. (C3), Eve’s reduced density matrix is given by σE = 1 − gx 2 |v1⟩⟨v1| + 1 + gx 2 |v2⟩⟨v2| , (C12) where gx = | ⟨ψ=|ψ̸=⟩...
-
[52]
Proposition 21
Monotonicity Properties In this section, we show that all three functions“hH(Sβ) described in Theorem 20 are monotonically decreasing in the score, Sβ (for α, β in the appropriate ranges). Proposition 21. For all α ∈ (1, ∞) and q ∈ [0, 1], the function “h eH ↓ α (Sβ) is monoto...
-
[53]
Error correction and error verification: In error correction, Alice sends a stringLEC (of some fixed lengthℓEC) to Bob, who uses it to produce a guess for Alice’s stringAn
-
[54]
Bob then computes the corresponding hash of his guess and aborts if it does not match
Then in error verification, Alice draws some choice of hash function HEV from a δ-almost-universal hash family [38] (with fixed output lengthℓEV), then applies it to An 1 and sends the resulting valueLEV to Bob, along with the choice of hash functionHEV. Bob then computes the ...
-
[55]
32 When designing a protocol for the finite-size regime, there are two critical “overall” parameters that should be considered
Privacy amplification: Alice applies a privacy amplification procedure toAn 1 to produce a final key of length ℓkey, and Bob does the same to his guess forAn 1. 32 When designing a protocol for the finite-size regime, there are two critical “overall” parameters that should be ...
-
[56]
Thecompleteness parameter ϵcom: this is an upper bound on the probability that the honest behavior aborts. Since this protocol might abort during either the acceptance test or the error verification step, it is convenient to construct upper boundsϵAT com and ϵEV com on the abo...
-
[57]
security
Thesoundness parameter ϵsound: informally, this quantifies the “security” of the final key; refer to [27, 39] for a rigorous definition. As discussed in those works, to analyze this parameter it suffices to separately consider a correctness parameter ϵcorr and a secrecy parame...
-
[58]
correlator
Completeness To discuss completeness, we need to specify some honest behavior for the devices. We suppose that the honest behavior is IID, and each round produces some distributionqhon on the register ¯Cj for that round. For our protocol, this distribution would have the form ...
-
[59]
We leave this aspect entirely unchanged, which suffices to ensure a correctness parameter ofϵcorr = 2−61 as proven in [27]
Correctness In [27], error verification was performed using aδ-almost-universal hash with δ = 2 −61 and ℓEV = 64 (under the condition that the message length in bits is at most264 ≈ 1019, which is indeed the case here). We leave this aspect entirely unchanged, which suffices t...
-
[60]
factor off
Secrecy Thisisthepartofouranalysisthatdiffersthemostfrom[27], inthatapartfromimprovingtheentropyaccumulation bound, we simplify or improve a number of other steps in the analysis. We shall show that to achieve a desired secrecy parameter ϵsecret, it suffices to take the length...
-
[61]
projectively reconstructed
on the left side of the conditioning. To address these points, we first handle the conditioning on ΩEV, and remove the error-correction and error- verification registers from the conditioning: eH ↑ α An 1 | ¯Bn 1 LECLEVHEVX n 1 Y n 1 T n 1 E ρ|ΩA T∧ΩEV ≥ eH ↑ α An 1 | ¯Bn 1 LE...
-
[62]
sacrificing
Possible modifications Finally, we make some informal comments regarding some potential for slightly sharpening the above analysis. Namely, the way we computed the lower bound onhα is slightly suboptimal, in that we were effectively “sacrificing” entropy contributions from tes...
Reviewed August 6, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.