Device-Independent QKD
Device-independent quantum key distribution (DIQKD) is QKD whose secrecy proof treats the quantum source and endpoint measurement devices through their observed classical input-output behavior rather than through a trusted model of their Hilbert-space dimension, states, observables, efficiencies, or internal implementation. Alice and Bob repeatedly choose private inputs and , record outputs and , and test whether the conditional frequencies violate a Bell inequality. A loophole-aware violation can then lower-bound an adversary’s uncertainty about designated key outcomes.
The adjective device-independent does not mean assumption-free. The result still depends on quantum mechanics, authenticated classical communication, private and sufficiently independent input randomness, secure laboratories, trusted classical postprocessing, a causal trial definition, and a rule that prevents the two measurement boxes from exchanging their current inputs or outputs during a trial. Losses and no-clicks must be included without an unjustified fair-sampling assumption. An adversary may always make the protocol abort.
This page is the canonical home for the DIQKD input-output model, its exact trust boundary, the route from Bell violation to entropy, finite-key accumulation, loophole control, event-ready heralding, and experimental rate constraints. E91 and Entanglement-Based QKD owns Ekert’s original setting schedule and singlet calculation. The CHSH Inequality owns the local and quantum bounds. Certification of Entanglement owns the broader hierarchy of witnesses, steering, Bell certification, and self-testing. Network Verification owns source-independent network tests, topology assumptions, channel and service acceptance, and network audit transcripts without turning those results into a secrecy claim. The general composable key contract belongs to Quantum Key Distribution. Quantum Randomness owns the corresponding standalone task: certifying local private entropy, extracting random bits, and distinguishing randomness generation, expansion, and amplification without adding two-party key agreement.
What Is and Is Not Characterized
Section titled “What Is and Is Not Characterized”In a representative bipartite protocol, Alice’s box accepts an input and returns ; Bob’s box accepts and returns . The observed object is
The security proof does not need Alice and Bob to assert that the boxes contain qubits, Pauli measurements, polarizers, ion readout, or any fixed-dimensional system. A compatible quantum realization may instead use an unknown state and unknown measurement operators,
where neither the dimension nor the operators need be known to the users. Eve may have prepared the source, built the boxes, and retained the purifying system .
This freedom is constrained at the interface. Alice and Bob must know which input they supplied, receive one declared output for every eligible trial, and prevent unauthorized information from leaving their laboratories. During a trial, Alice’s current input and output cannot reach Bob’s box, and conversely. The boxes may retain memory of earlier trials unless the proof explicitly assumes otherwise, so security against a general sequential attack must allow the th response to depend on the entire permitted past.
Trust ledger
Section titled “Trust ledger”| Component or statement | DI treatment | Operational consequence |
|---|---|---|
| source state and source location | untrusted | Eve may distribute any quantum systems correlated with |
| measurement dimension and POVMs | uncharacterized | security uses observed input-output statistics, not a calibrated qubit model |
| detector efficiency and no-click behavior | uncharacterized but fully recorded | no favorable outcome-dependent deletion is allowed |
| private setting generators | trusted within a stated independence model | predictable or leaked inputs weaken or destroy the Bell inference |
| laboratory boundary | trusted or quantitatively leakage-bounded | boxes must not signal private data to Eve or to one another during a trial |
| classical postprocessing | trusted | parameter estimation, error correction, verification, and privacy amplification must implement the proved protocol |
| public channel | readable by Eve but authenticated | Eve may learn the transcript but may not forge or alter it undetected |
| availability | not guaranteed | Eve may block signals, corrupt statistics, or force abort |
The distinction is subtle but central: DIQKD removes detailed quantum-device models from the secrecy proof; it does not remove the trusted classical and causal envelope in which those devices are used.
The DIQKD trial contract. The source and the internals of both measurement boxes may be adversarial. The private inputs are chosen only after an optional event-ready herald defines an eligible trial; outputs then include every prescribed no-click or invalid event. The boxes cannot communicate during the trial, and the authenticated public transcript is processed only after the outputs are fixed.
A CHSH-Based Protocol Skeleton
Section titled “A CHSH-Based Protocol Skeleton”Many DIQKD proofs use variants rather than one universal protocol. The following skeleton isolates the common logic.
- Initialize the classical envelope. Alice and Bob authenticate their public channel, allocate private random seeds, fix a trial clock and outcome alphabet, and commit to all acceptance thresholds before collecting data.
- Define an eligible trial. In a direct experiment every clocked attempt may count. In an event-ready architecture, a flag announces that entanglement distribution succeeded. Crucially, is fixed before the private inputs are generated.
- Choose a round type. A private selector marks a test round or a generation round. Test rounds sample Bell settings. Generation rounds use a strongly correlated setting pair that produces raw key.
- Query the boxes. Alice supplies , Bob supplies , and each box must return exactly one output under the protocol’s alphabet and timeout rule. A no-click is an outcome or is deterministically mapped to one; it is not silently erased.
- Fix the transcript. The outputs are committed before settings, round types, or test outcomes are disclosed. This ordering prevents the boxes from tailoring outputs to later public information.
- Estimate behavior. Alice and Bob reveal test data, calculate the Bell score, estimate the key-basis error rate, and abort unless both lie in the proved acceptance region.
- Distill the key. They reconcile the retained raw strings, verify agreement, and apply privacy amplification at a length justified by the entropy bound and every disclosed bit.
A common CHSH layout gives Alice two test inputs and Bob two test inputs . Bob has an additional setting aligned with Alice’s setting for key generation. Other protocols use two key bases, biased inputs, asymmetric Bell inequalities, or full-distribution estimators. Those changes alter the rate and finite-size proof, not the basic contract.
The Bell-Test Statistic
Section titled “The Bell-Test Statistic”Map binary outputs to signs,
and define the test-round correlators
With one standard sign convention, the CHSH expression is
Bell-local correlations obey , while quantum theory allows . Equivalently, Alice and Bob win the CHSH game when . For uniformly distributed test inputs,
after choosing output labels so that . The local and quantum limits are
The complete conditional distribution contains more information than one scalar . Modern numerical analyses can minimize conditional entropy over all quantum realizations compatible with the observed frequencies, often using semidefinite relaxations related to the Navascués–Pironio–Acín hierarchy. CHSH remains the cleanest analytic example and the most common experimental benchmark.
Why Nonlocality Can Imply Privacy
Section titled “Why Nonlocality Can Imply Privacy”A Bell violation rules out a shared deterministic instruction list that explains the accepted data while respecting the trial’s causal constraints. Quantum nonlocality also obeys monogamy: correlations that are close to the maximal bipartite CHSH value cannot be simultaneously shared with Eve in a way that lets her predict the key output perfectly. A security proof makes this intuition quantitative by minimizing an entropy over every quantum realization compatible with the data.
For a classical key symbol and quantum side information , conditional min-entropy has the operational meaning
where is Eve’s optimal probability of identifying . Privacy amplification converts a string with sufficiently large smooth conditional min-entropy into a shorter string close to uniform and independent of Eve. A Bell score is useful because it supplies a device-independent lower bound on that entropy.
A Bell violation alone is not yet a key. Alice and Bob also need correlated generation outcomes, enough finite data to exclude a weaker underlying score, an analysis valid against the allowed temporal correlations, an accounting of the public reconciliation transcript, and a composable extractor statement.
Representative Asymptotic CHSH Rate
Section titled “Representative Asymptotic CHSH Rate”The classic analytic calculation considers a particular CHSH-based protocol, asymptotically many rounds, binary outputs, one-way reconciliation, and collective attacks. Let be the bit-error probability of the key setting after the declared relabeling, and define the binary entropy
The observed CHSH value bounds Eve’s Holevo information by
Combining this with the asymptotic reconciliation cost gives
for . At the local boundary, the privacy penalty is one full bit and this expression cannot produce key. At the Tsirelson bound, the privacy penalty vanishes. Errors still incur reconciliation cost.
This formula is a useful diagnostic, not a universal DIQKD theorem. It is per retained generation round under its specified asymptotic model. It omits test allocation, imperfect reconciliation, finite-statistical margins, authentication consumption, heralding probability, source repetition rate, and protocol-dependent constant terms. General attacks require a sequential proof such as entropy accumulation.
Worked asymptotic ledger
Section titled “Worked asymptotic ledger”Suppose a representative experiment estimates
Then
and
The representative fraction is therefore
secret bits per retained key round. If only of heralded trials are generation rounds, error correction leaks more than the Shannon limit, and the herald succeeds once in attempts, the physical rate is nowhere near bits per attempt. The statistical and optical ledgers must be kept separate.
General Attacks and Entropy Accumulation
Section titled “General Attacks and Entropy Accumulation”An uncharacterized box may have memory. It can change strategy with time and correlate the current output with every earlier input, output, and public message it is allowed to know. Treating the data as independent and identically distributed merely because the histogram looks stationary is not a DI argument.
The entropy accumulation theorem (EAT) exploits a weaker structure: trials occur sequentially, so the future cannot influence the past. A protocol constructs a min-tradeoff function that lower-bounds the conditional von Neumann entropy produced by one admissible round as a function of its test statistics. Conditioned on passing the parameter-estimation test, a schematic EAT statement has the form
where:
- is Alice’s raw key string;
- is the public and permitted classical side information;
- is a conservative Bell-test parameter or frequency region obtained from the observations and a one-sided statistical margin;
- contains finite-size terms, typically with leading behavior of order for a fixed protocol and error budget.
Neither nor is universal. They depend on the Bell game, input distribution, key map, output alphabet, acceptance event, entropy version, and proof technique. A complete implementation should use the exact theorem and software corresponding to its protocol, including finite-precision rounding and failure allocation.
After parameter estimation, a representative key-length ledger is
Here counts all reconciliation disclosure, includes verification and any other transcript costs, and is the extractor failure allocation. Exact constants vary with convention. The central rule does not: every public bit correlated with the raw key and every failure event must appear in the composable ledger.
Finite Data, Completeness, and Soundness
Section titled “Finite Data, Completeness, and Soundness”A protocol must distinguish two guarantees.
- Completeness bounds the probability that an honest implementation with declared noise and loss aborts.
- Soundness bounds the probability that the protocol accepts but outputs incorrect or nonsecret key against the specified adversary.
Completeness is about usefulness; soundness is about security. Eve can always lower completeness by blocking the channel. A protocol is not insecure merely because she can force an abort, but it may be operationally useless.
For intuition only, suppose independent CHSH test rounds give empirical win fraction . Hoeffding’s inequality supplies the one-sided margin
At and ,
That reduction can materially change the entropy near threshold. This simple bound is not valid for an arbitrary memory-bearing device; an EAT-compatible or martingale analysis supplies the corresponding sequential confidence statement. It illustrates why reporting only the point estimate is inadequate.
The security parameter is assembled from parameter estimation, smoothing, error correction, verification, privacy amplification, and authentication. The Trace Distance gives the operational metric used in the secrecy criterion. Security claims should state whether they are asymptotic, collective-attack, finite-key, or composable against general quantum attacks.
Detection Loophole and No-Clicks
Section titled “Detection Loophole and No-Clicks”Suppose an adversarial box carries a local hidden variable and chooses whether to report a click as a function of its local input and . If Alice and Bob retain only double-click trials, the surviving subset can be highly nonrepresentative. The device can suppress outcomes that would reduce the desired correlation and make a Bell-local strategy look nonlocal. This is the detection loophole.
A valid DI treatment uses one of three proof-compatible approaches:
- retain no-click as an explicit output;
- map every no-click deterministically or randomly according to a committed rule and include the result in the Bell statistics;
- use an event-ready herald to define an eligible trial before the private settings are generated, then include every post-herald outcome.
Coincidence windows are part of the same issue. If a pairing rule is chosen after looking at detection times, or if setting-dependent timing changes which events are paired, postselection can open a loophole. Clock windows, timeout rules, double-click maps, and data exclusions must be fixed before the run.
Bell-test efficiency is not key-generating efficiency
Section titled “Bell-test efficiency is not key-generating efficiency”In an ideal symmetric CHSH experiment with maximally entangled states, no background, and the standard assignment of missed events, the familiar threshold for any Bell violation is
Eberhard-type tests with nonmaximally entangled states can approach in an ideal low-background limit. Neither number is a universal DIQKD detector threshold. Producing positive key is stricter than merely crossing the local bound. For the original CHSH-based DIQKD protocol under a commonly studied detector-loss model, perfect Bell-state preparation still requires about detection efficiency for a positive asymptotic key; alternative postprocessing can improve that particular number. Noise, dark counts, input bias, finite data, and the chosen proof all move the boundary.
Event-Ready Heralding
Section titled “Event-Ready Heralding”An event-ready architecture separates channel loss from the Bell trial. A central station attempts entanglement generation or swapping and emits a flag . The valid causal order is
If , no Bell trial has begun. If , Alice and Bob choose fresh private inputs and every resulting output counts. The herald may depend on the adversarial source and its past, but not on future settings or post-herald outcomes. Channel loss before a valid herald reduces the event rate rather than allowing outcome-dependent selection. Detection failure after the herald still belongs to the output alphabet.
Matter qubits are attractive in this architecture because photons can herald remote entanglement while local atomic or ionic states are read out with high efficiency. Entanglement Swapping develops the conditional state update. DIQKD adds the stronger requirements that the heralding interface be causally ordered, the local measurements close the detection loophole, and the full transcript enter a key-security proof.
Locality, Input Independence, and Leakage
Section titled “Locality, Input Independence, and Leakage”Bell’s factorization assumption is only excluded when its causal premises match the experiment. Three interfaces deserve separate attention.
Communication during a trial
Section titled “Communication during a trial”If Bob’s box learns before choosing , the two boxes can reproduce any desired correlation by ordinary communication. Spacelike separation of input choice and remote output is the cleanest enforcement. Cryptographic DIQKD may instead assume shielded laboratories and timing controls that prevent cross-talk during the measurement interval. The latter is an explicit engineering assumption, not a conclusion derived from the Bell score.
Freedom of choice
Section titled “Freedom of choice”In the ideal model, the settings are sufficiently independent of Eve’s hidden information,
Perfect uniformity is not always necessary; specialized proofs can tolerate bounded bias or partial input leakage. But a device that predicts the settings well enough can prearrange favorable answers. The random generator, its seeding, timing, electronic fan-out, and electromagnetic leakage therefore remain inside the trusted boundary.
Laboratory leakage
Section titled “Laboratory leakage”An untrusted box can know old inputs and outputs. If it can modulate outgoing light, radio-frequency emission, timing, power draw, acoustic signals, or a later public output, it may exfiltrate raw key without contradicting the Bell statistics. Alice and Bob need secure laboratory boundaries or a quantitative leakage model. Device independence protects against an incorrect internal measurement model; it does not make an open side channel harmless.
Memory Across Trials and Sessions
Section titled “Memory Across Trials and Sessions”Within one run, entropy accumulation is designed to tolerate sequential memory: round may depend on all allowed earlier information. This is different from reusing a malicious device across protocol sessions. A box can store an earlier key and encode it into outcomes that will later be publicly revealed for parameter estimation. Such a memory attack can compromise composition even if each session’s within-run statistics look acceptable.
Countermeasures are protocol-specific. They can include isolating or securely retiring devices after a session, preventing a reused box from accessing old private registers, separating devices used with different counterparties, constraining future public communication, or using a composable architecture proved for reuse. “The EAT allows memory” does not by itself settle this cross-session leakage problem.
Physical Rate Ledger
Section titled “Physical Rate Ledger”The secret fraction is only one factor in throughput. For an event-ready system, a useful decomposition is
where is the entanglement-attempt rate, the valid herald probability, the fraction assigned to key generation and surviving protocol filters, and the finite-key secret fraction per retained generation outcome.
Different hardware architectures fail in different columns:
| Architecture | Main advantage | Dominant bottleneck |
|---|---|---|
| direct entangled photons | high optical repetition rate | channel loss enters the loophole-free trial unless arrival is heralded |
| all-photonic heralding or qubit amplification | can flag successful delivery before basis choice | ancillary-source quality, Bell-measurement success, coupling, and detector efficiency |
| remote matter memories | efficient local readout after heralding | very low remote-entanglement probability and communication-limited repetition |
| multiplexed memory network | parallel attempts can hide propagation latency | hardware scale, switching, memory coherence, mode matching, and control complexity |
If an architecture must wait for a herald across a total signaling path before reusing the same memory, its single-mode attempt rate is limited on the scale of , where is the speed of light in fiber. A simple round-trip path has , but the exact path is architecture-dependent. Multiplexing can launch many attempts before earlier heralds return, at the cost of more memories, modes, switching, and classical bookkeeping.
Experimental Status and Claim Boundaries
Section titled “Experimental Status and Claim Boundaries”DIQKD has moved beyond Bell tests into proof-of-principle key-distribution experiments, but it remains far from the rates and deployment maturity of ordinary QKD. In 2022, memory-based experiments reported Bell-certified QKD between separated matter qubits; one produced a positive finite key, while another demonstrated distant users with an asymptotic analysis. A separate photonic experiment verified the ingredients against a collective-attack model but did not yet produce a positive finite key.
In 2026, Liu and collaborators reported long-lived remote ion–ion entanglement and, as an application, a proof-of-principle DIQKD demonstration with finite-size analysis over of spooled fiber. The same work reported a positive key rate beyond in the asymptotic limit. These are different claims: a finite-size demonstration at does not establish a positive finite key at . Cryptography Case Studies keeps the detailed experiment ledger, rates, durations, and residual assumptions.
A trustworthy report should distinguish:
- Bell violation from positive asymptotic key;
- positive asymptotic key from positive finite key;
- bits per herald from bits per attempt and bits per second;
- spooled fiber from a field-deployed link;
- laboratory isolation from spacelike-separated measurement events;
- a collective-attack analysis from composable security against general sequential attacks.
Comparison with Neighboring Trust Models
Section titled “Comparison with Neighboring Trust Models”| Protocol family | Source model | Measurement model | Nonlocality requirement |
|---|---|---|---|
| standard entanglement-based QKD | source may be untrusted | endpoint measurements characterized by the proof | Bell violation not generally required |
| one-sided-device-independent QKD | source untrusted | one party’s measurement trusted, the other inferred through steering | steering demonstration rather than full Bell nonlocality |
| measurement-device-independent QKD | endpoint sources characterized | central measurement entirely untrusted | no Bell violation required |
| device-independent QKD | source and endpoint quantum internals uncharacterized | behavior inferred from loophole-aware statistics inside secure labs | Bell violation required |
MDI-QKD and DIQKD solve different interface problems. MDI-QKD is engineered to remove detector-side attacks at an untrusted relay while retaining precise source assumptions; it is compatible with lossy optical channels and mature decoy-state methods. DIQKD relaxes source and endpoint measurement models more radically, but pays for that reduction with stringent efficiency, isolation, randomness, and finite-data requirements.
One-sided-device-independent protocols occupy a useful middle ground. A steering inequality can certify the untrusted party’s behavior when the other party’s measurement model is trusted. This often tolerates more loss than full DIQKD, but the resulting claim is not fully device-independent.
Protocol Variants and Active Directions
Section titled “Protocol Variants and Active Directions”The field is developing, so a page should not freeze one CHSH formula into a definition of DIQKD. Important directions include:
- biased test allocation and random key bases that improve noise tolerance or finite-block efficiency;
- noisy preprocessing and two-way advantage distillation;
- asymmetric or generalized CHSH inequalities tailored to detector imbalance;
- full-statistics entropy optimization instead of a single Bell score;
- photonic heralding, routed Bell tests, quantum nondemolition detection, and memory multiplexing for longer links;
- higher-dimensional and multipartite Bell games;
- leakage-tolerant, partially device-independent, and computationally assisted models with explicitly different assumptions.
Each variant needs its own acceptance test, entropy tradeoff, causal model, and finite-key theorem. A better asymptotic curve does not automatically imply a practical finite-key improvement once heralding, detector noise, test allocation, and numerical proof cost are included.
Implementation Audit
Section titled “Implementation Audit”Before calling a protocol device-independent, verify all of the following.
- The exact input and output alphabets, including no-clicks, timeouts, and double clicks, are specified before data collection.
- The event-ready herald, if used, is fixed before private inputs and cannot depend on post-herald outcomes.
- Current inputs cannot travel between boxes before outputs are fixed.
- Random settings satisfy the independence model used in the proof.
- The laboratory boundary prevents unauthorized leakage to Eve.
- The proof permits the actual sequential memory and device-reuse policy.
- Bell and error estimators use all eligible trials with valid finite-data confidence bounds.
- The key-length calculation includes reconciliation, verification, authentication, smoothing, and privacy-amplification costs.
- Numerical optimization and finite-precision rounding are validated and fail closed.
- The result is labeled accurately as collective-attack, asymptotic, finite-key, or composable general-attack security.
Common Mistakes
Section titled “Common Mistakes”- Saying device-independent means no assumptions or no trusted components.
- Calling every entanglement-based protocol device-independent.
- Treating as a complete key-security proof.
- Computing CHSH only on coincident detections without a justified trial model.
- Confusing the ideal CHSH detection threshold with a universal positive-key threshold.
- Choosing a herald, timeout, coincidence window, or data exclusion after settings or outcomes are known.
- Applying an i.i.d. confidence interval to an arbitrary memory-bearing box.
- Saying entropy accumulation prevents every cross-session memory attack.
- Quoting secret bits per herald as secret bits per optical attempt or per second.
- Reporting a positive asymptotic rate as if a positive finite key had been generated.
- Assuming the Bell test authenticates Alice and Bob’s identities.
- Forgetting that Eve may always force abort and deny service.
Exercises
Section titled “Exercises”1. Convert a CHSH win fraction
Section titled “1. Convert a CHSH win fraction”In uniformly sampled test rounds, Alice and Bob observe . Convert this to the corresponding point estimate . Does it violate the local bound?
Solution
Using ,
Because , the point estimate violates CHSH. A finite-data security claim must still replace this point estimate by a one-sided confidence bound and verify the other protocol conditions.
2. Evaluate the representative rate
Section titled “2. Evaluate the representative rate”Use the collective-attack asymptotic expression to calculate the secret fraction at and .
Solution
The Bell-dependent argument is
Numerically,
Therefore
This is per retained key round and inherits every assumption of the stated asymptotic collective-attack formula.
3. Apply a finite-sample margin
Section titled “3. Apply a finite-sample margin”For independent test rounds and , calculate the illustrative Hoeffding margin on and the resulting reduction in .
Solution
The one-sided margin is
Since , the Bell-score reduction is
Thus a point estimate becomes the illustrative lower bound . A general sequential device needs a proof-compatible non-i.i.d. estimator rather than this elementary bound.
4. Diagnose postselected no-clicks
Section titled “4. Diagnose postselected no-clicks”Why can deleting every no-click and evaluating CHSH only on double-click events create a false device-independent claim?
Solution
A local box can make its probability of clicking depend on its input and a shared hidden variable. It reports outcomes only on rounds favorable to the target correlation and suppresses unfavorable rounds. The retained double-click subset can then violate CHSH even though the complete behavior is Bell-local. A valid protocol includes no-clicks under a committed output rule or defines trials with a pre-input event-ready herald.
5. Check a heralding timeline
Section titled “5. Check a heralding timeline”Consider two timelines:
Which one supports ordinary event-ready postselection, and why?
Solution
Timeline A supports event-ready postselection. The flag defines eligibility before either private setting exists, so channel failure cannot select a setting-dependent subset. In timeline B, the heralding device can know the settings and announce success only for favorable pairs. Treating rounds as nonexistent would then open a detection or selection loophole unless a specialized proof explicitly models that dependence.
6. Compare MDI-QKD and DIQKD
Section titled “6. Compare MDI-QKD and DIQKD”An experiment uses well-characterized decoy-state transmitters at Alice and Bob and sends both pulses to an entirely untrusted Bell analyzer. Is this device-independent QKD?
Solution
It is measurement-device-independent QKD. The relay and all detectors are outside the trusted boundary, but the proof still relies on models of the endpoint sources, including phase randomization, intensity statistics, and state encoding. Full DIQKD would infer secrecy from loophole-aware nonlocal input-output behavior without trusting those source and endpoint measurement models.
7. Separate secrecy from availability
Section titled “7. Separate secrecy from availability”Eve blocks every entanglement attempt whenever Alice and Bob begin a DIQKD session. Has she violated the secrecy theorem?
Solution
No. QKD security guarantees that an accepted key is correct and secret within the stated failure budget; it does not guarantee that the protocol accepts. Blocking the quantum channel forces abort and is a denial-of-service attack. Availability requires separate network monitoring, redundancy, and incident response.
8. Identify a cross-session memory attack
Section titled “8. Identify a cross-session memory attack”A malicious box stores Alice’s first-session raw key. During a later session, it encodes those old bits into outputs selected for public parameter estimation. Why does within-run entropy accumulation not automatically stop this attack?
Solution
Entropy accumulation can permit temporal correlations while lower-bounding entropy for one causally ordered execution. It does not erase the box’s memory or forbid a later public transcript from carrying information about an earlier session. Composable reuse needs an additional device-reuse architecture, isolation of old private registers, constraints on later communication, or secure retirement of the device.
References
Section titled “References”- A. K. Ekert, “Quantum cryptography based on Bell’s theorem,” Physical Review Letters 67, 661–663 (1991), doi:10.1103/PhysRevLett.67.661.
- D. Mayers and A. Yao, “Quantum cryptography with imperfect apparatus,” in Proceedings of the 39th Annual Symposium on Foundations of Computer Science, 503–509 (1998), doi:10.1109/SFCS.1998.743501.
- J. Barrett, L. Hardy, and A. Kent, “No signaling and quantum key distribution,” Physical Review Letters 95, 010503 (2005), doi:10.1103/PhysRevLett.95.010503.
- A. Acín, N. Brunner, N. Gisin, S. Massar, S. Pironio, and V. Scarani, “Device-independent security of quantum cryptography against collective attacks,” Physical Review Letters 98, 230501 (2007), doi:10.1103/PhysRevLett.98.230501.
- S. Pironio, A. Acín, N. Brunner, N. Gisin, S. Massar, and V. Scarani, “Device-independent quantum key distribution secure against collective attacks,” New Journal of Physics 11, 045021 (2009), doi:10.1088/1367-2630/11/4/045021.
- L. Masanes, S. Pironio, and A. Acín, “Secure device-independent quantum key distribution with causally independent measurement devices,” Nature Communications 2, 238 (2011), doi:10.1038/ncomms1244.
- U. Vazirani and T. Vidick, “Fully device-independent quantum key distribution,” Physical Review Letters 113, 140501 (2014); erratum 116, 089901 (2016), doi:10.1103/PhysRevLett.113.140501.
- R. Arnon-Friedman, F. Dupuis, O. Fawzi, R. Renner, and T. Vidick, “Practical device-independent quantum cryptography via entropy accumulation,” Nature Communications 9, 459 (2018), doi:10.1038/s41467-017-02307-4.
- F. Dupuis, O. Fawzi, and R. Renner, “Entropy accumulation,” Communications in Mathematical Physics 379, 867–913 (2020), doi:10.1007/s00220-020-03839-5.
- R. Arnon-Friedman, R. Renner, and T. Vidick, “Simple and tight device-independent security proofs,” SIAM Journal on Computing 48, 181–225 (2019), doi:10.1137/18M1174726.
- J. Barrett, R. Colbeck, and A. Kent, “Memory attacks on device-independent quantum cryptography,” Physical Review Letters 110, 010503 (2013), doi:10.1103/PhysRevLett.110.010503.
- P. H. Eberhard, “Background level and counter efficiencies required for a loophole-free Einstein–Podolsky–Rosen experiment,” Physical Review A 47, R747–R750 (1993), doi:10.1103/PhysRevA.47.R747.
- W. Rosenfeld et al., “Event-ready Bell test using entangled atoms simultaneously closing detection and locality loopholes,” Physical Review Letters 119, 010402 (2017), doi:10.1103/PhysRevLett.119.010402.
- R. Schwonnek et al., “Device-independent quantum key distribution with random key basis,” Nature Communications 12, 2880 (2021), doi:10.1038/s41467-021-23147-3.
- P. Brown, H. Fawzi, and O. Fawzi, “Computing conditional entropies for quantum correlations,” Nature Communications 12, 575 (2021), doi:10.1038/s41467-020-20018-1.
- D. P. Nadlinger et al., “Experimental quantum key distribution certified by Bell’s theorem,” Nature 607, 682–686 (2022), doi:10.1038/s41586-022-04941-5.
- W. Zhang et al., “A device-independent quantum key distribution system for distant users,” Nature 607, 687–691 (2022), doi:10.1038/s41586-022-04891-y.
- W.-Z. Liu et al., “Toward a photonic demonstration of device-independent quantum key distribution,” Physical Review Letters 129, 050502 (2022), doi:10.1103/PhysRevLett.129.050502.
- V. Zapatero et al., “Advances in device-independent quantum key distribution,” npj Quantum Information 9, 10 (2023), doi:10.1038/s41534-023-00684-x.
- W.-Z. Liu et al., “Long-lived remote ion–ion entanglement for scalable quantum repeaters,” Nature 652, 51–57 (2026), doi:10.1038/s41586-026-10177-4.
- C. Portmann and R. Renner, “Security in quantum cryptography,” Reviews of Modern Physics 94, 025008 (2022), doi:10.1103/RevModPhys.94.025008.
Further Connections
Section titled “Further Connections”- Quantum Key Distribution gives the composable correctness, secrecy, authentication, and finite-key contract shared by all QKD families.
- E91 and Entanglement-Based QKD derives the original singlet protocol and explains why an untrusted source alone does not imply device independence.
- CHSH Inequality derives the local bound, Tsirelson bound, and optimal qubit settings used here as inputs.
- Bell Theorem states the factorization and setting-independence assumptions excluded by a valid Bell violation.
- Certification of Entanglement compares trusted witnesses, steering, Bell tests, self-testing, and their finite-data loopholes.
- Measurement-Device-Independent QKD develops the distinct untrusted-relay architecture and its two-source decoy equations.
- Entanglement Swapping gives the state-update and Bell-outcome ledger behind event-ready remote entanglement.
- Cryptography Case Studies tracks experimental rates, distances, finite-key claims, and residual trust assumptions.
- Quantum Information Roadmap places DIQKD after Bell nonlocality, composable QKD, entanglement-based protocols, and finite-resource entropy.
Summary
Section titled “Summary”DIQKD obtains secrecy from loophole-aware nonlocal input-output behavior rather than from detailed models of the source and measurement devices. The Bell score constrains Eve’s uncertainty, but a secure key emerges only after a protocol-specific entropy bound, finite-data analysis, reconciliation, verification, privacy amplification, and authentication.
The remaining assumptions are concrete: private inputs, causal trial order, no within-trial communication between boxes, secure laboratory boundaries, trusted classical processing, and complete treatment of losses and memory. Event-ready heralding can move channel loss outside the Bell trial, but its success probability then dominates the physical rate. Current experiments establish important proof-of-principle milestones; practical DIQKD remains a developing technology whose finite-key, distance, rate, and trust claims must be reported separately.