Skip to content

E91 and Entanglement-Based QKD

E91 is the entanglement-based quantum key distribution protocol proposed by Artur Ekert in 1991. A source distributes one system from each entangled pair to Alice and the other to Bob. They choose local measurement settings at random. Some setting pairs produce anticorrelated raw-key bits; other pairs estimate a Bell parameter that tests whether the observed correlations admit a Bell-local explanation.

The protocol does not turn a Bell violation directly into a finished key. Alice and Bob still need an authenticated classical channel, a declared trial and detection model, finite-sample parameter estimation, error correction, key verification, and privacy amplification. The operational contract is the usual QKD contract: either abort, or output matching strings that are close to uniform and independent of an adversary under a stated security model.

This page is the canonical home for the original three-setting E91 schedule, its singlet correlations, Bell-test calculation, key-round sifting, and the reason entanglement-based QKD is not automatically device-independent. Device-Independent QKD owns the black-box input-output model, Bell-to-entropy bounds, loophole control, event-ready heralding, and finite-key ledger. Quantum Key Distribution owns composable security definitions and finite-key bookkeeping. Bell Theorem and the CHSH Inequality own the foundational no-local-model result. Cryptography Case Studies owns optical loss budgets and experimental evidence.

An E91 analysis must identify at least four interfaces.

  1. A pair source emits bipartite systems. It may sit with Alice, in the channel, or at a third station. A robust security model may grant Eve control of the source.
  2. Alice and Bob have local setting generators and measurement devices. How much of those devices is characterized separates device-dependent from device-independent protocols.
  3. The quantum links produce detections, losses, timing information, and possible side-channel data. The rule defining a trial cannot be chosen after seeing favorable outcomes.
  4. An authenticated but public classical channel carries detection announcements, setting choices, test data, reconciliation messages, and verification tags. Eve may read these messages but must not be able to alter them undetected.

The raw observations are therefore not just bit strings. A useful record for round ii is

Ti=(hi,αi,ai,βi,bi,dA,i,dB,i,τi),T_i= \bigl( h_i,\alpha_i,a_i, \beta_i,b_i, d_{A,i},d_{B,i}, \tau_i \bigr),

where hih_i is any herald, αi\alpha_i and βi\beta_i are settings, ai,bi∈{−1,+1}a_i,b_i\in\{-1,+1\} are outcomes when present, dA,id_{A,i} and dB,id_{B,i} record detection status, and τi\tau_i contains timing information. Security depends on how this complete record is filtered into key rounds, test rounds, and discarded rounds.

The ideal E91 resource is the two-qubit singlet

∣Ψ−⟩=∣0⟩A∣1⟩B−∣1⟩A∣0⟩B2.\lvert\Psi^-\rangle = \frac{ \lvert0\rangle_A\lvert1\rangle_B - \lvert1\rangle_A\lvert0\rangle_B }{\sqrt2}.

Bell States owns the full Bell basis and its local-Pauli relations. The property needed here is the singlet correlation tensor

⟨Ψ−∣σj⊗σk∣Ψ−⟩=−δjk.\langle\Psi^-\rvert \sigma_j\otimes\sigma_k \lvert\Psi^-\rangle =-\delta_{jk}.

Choose coplanar Bloch-sphere directions and define binary observables

A(α)=cos⁡α σz+sin⁡α σx,B(β)=cos⁡β σz+sin⁡β σx.\begin{aligned} A(\alpha) &=\cos\alpha\,\sigma_z+\sin\alpha\,\sigma_x,\\ B(\beta) &=\cos\beta\,\sigma_z+\sin\beta\,\sigma_x. \end{aligned}

Their eigenvalues are a,b∈{−1,+1}a,b\in\{-1,+1\}, with projectors

Πa(α)=I+aA(α)2,Πb(β)=I+bB(β)2.\Pi_a(\alpha)=\frac{I+aA(\alpha)}2, \qquad \Pi_b(\beta)=\frac{I+bB(\beta)}2.

The ideal joint distribution is

P(a,b∣α,β)=Tr⁡ ⁣[∣Ψ−⟩ ⁣⟨Ψ−∣Πa(α)⊗Πb(β)]=14[1−abcos⁡(α−β)].\begin{aligned} P(a,b\mid\alpha,\beta) &= \operatorname{Tr}\!\left[ \lvert\Psi^-\rangle\!\langle\Psi^-\rvert \Pi_a(\alpha)\otimes\Pi_b(\beta) \right]\\ &=\frac14 \left[1-ab\cos(\alpha-\beta)\right]. \end{aligned}

The correlator is consequently

E(α,β)=∑a,b=±1ab P(a,b∣α,β)=−cos⁡(α−β).E(\alpha,\beta) =\sum_{a,b=\pm1}ab\,P(a,b\mid\alpha,\beta) =-\cos(\alpha-\beta).

When the directions agree, E(α,α)=−1E(\alpha,\alpha)=-1: Alice and Bob always obtain opposite signs. Either party can apply a fixed relabeling so that these become matching raw-key bits. Each local marginal remains uniform,

P(a∣α)=P(b∣β)=12,P(a\mid\alpha)=P(b\mid\beta)=\frac12,

so neither endpoint controls the ideal outcome in advance.

For polarization qubits, a physical linear-polarizer angle corresponds to half the equatorial Bloch angle because polarization probabilities contain a double angle. Stating which convention is in use prevents a common factor-of-two error when translating spin-direction formulas to optical analyzers.

One convenient qubit form of the E91 schedule uses three settings per party:

PartySettingBloch anglePrincipal role
Aliceα1\alpha_100Bell test
Aliceα2\alpha_2π/4\pi/4key with β1\beta_1
Aliceα3\alpha_3π/2\pi/2key with β2\beta_2 and Bell test
Bobβ1\beta_1π/4\pi/4key with α2\alpha_2 and Bell test
Bobβ2\beta_2π/2\pi/2key with α3\alpha_3
Bobβ3\beta_33π/43\pi/4Bell test

The nine setting pairs are classified as follows:

β1\beta_1β2\beta_2β3\beta_3
α1\alpha_1testdiscardtest
α2\alpha_2keydiscarddiscard
α3\alpha_3testkeytest

“Discard” describes the canonical teaching schedule. A modern proof may use more of the observed data, but it must declare that estimator before looking at the transcript.

With independent uniform choices, the ideal classification probabilities are

pkey=29,ptest=49,pdiscard=39.p_{\mathrm{key}}=\frac29, \qquad p_{\mathrm{test}}=\frac49, \qquad p_{\mathrm{discard}}=\frac39.

The low key fraction is not fundamental. Biased setting probabilities can favor key settings while reserving enough randomly selected trials for a statistically sound Bell estimate.

E91 source, local measurements, and the three-by-three key and Bell-test setting matrix

E91 distributes singlet halves to independent local measurements. After an authenticated setting announcement, two same-direction pairs supply raw-key data and four pairs estimate the chosen CHSH expression. The source need not be trusted, but the trust assigned to the endpoint devices must be stated.

For a key round, define

x=1−a2,y=1+b2.x=\frac{1-a}{2}, \qquad y=\frac{1+b}{2}.

The sign in Bob’s map performs the fixed singlet anticorrelation flip. If b=−ab=-a, then x=yx=y. Other bit conventions are equally valid, but changing a convention requires changing the expected correlations consistently.

A complete idealized run has the following stages.

  1. Authenticate and configure. Alice and Bob establish the protocol version, setting probabilities, trial definition, abort rules, error-correction method, privacy-amplification family, and authentication keys.
  2. Distribute pairs. The source emits candidate pairs. A herald, if used, must be generated in a way compatible with the security model.
  3. Choose settings locally. Alice samples αi\alpha_i and Bob samples βj\beta_j using private random choices made at the required time.
  4. Measure and record every trial. They retain outcomes, no-clicks, double-clicks, timestamps, and other declared flags rather than silently deleting inconvenient events.
  5. Announce detections and settings. Over the authenticated public channel, they identify the setting pair and classify each eligible event.
  6. Estimate parameters. Test rounds estimate the Bell statistic. A randomly selected key-basis sample or an equivalent estimator bounds the key error. If a confidence region misses the acceptance set, they abort.
  7. Reconcile and verify. Error correction aligns the retained raw keys; the public leakage is recorded. A verification hash bounds the probability that unequal keys survive.
  8. Amplify privacy. A randomly selected universal hash compresses the reconciled string to the length justified by the proof and transcript.

The public discussion is not meant to be secret. Its integrity is essential, and every revealed syndrome, sample bit, tag, and protocol decision belongs in the leakage or failure-probability ledger.

For a fixed setting pair, let Nab(α,β)N_{ab}(\alpha,\beta) be the number of eligible trials with outcomes a,b∈{−1,+1}a,b\in\{-1,+1\}. The empirical correlator is

E^(α,β)=N+++N−−−N+−−N−+N+++N−−+N+−+N−+.\widehat E(\alpha,\beta) = \frac{ N_{++}+N_{--}-N_{+-}-N_{-+} }{ N_{++}+N_{--}+N_{+-}+N_{-+} }.

For the angle table above, use the sign convention

S=E(α1,β1)−E(α1,β3)+E(α3,β1)+E(α3,β3).S= E(\alpha_1,\beta_1) -E(\alpha_1,\beta_3) +E(\alpha_3,\beta_1) +E(\alpha_3,\beta_3).

The four ideal singlet correlators are

E(α1,β1)=−12,E(α1,β3)=+12,E(α3,β1)=−12,E(α3,β3)=−12.\begin{aligned} E(\alpha_1,\beta_1)&=-\frac1{\sqrt2},& E(\alpha_1,\beta_3)&=+\frac1{\sqrt2},\\ E(\alpha_3,\beta_1)&=-\frac1{\sqrt2},& E(\alpha_3,\beta_3)&=-\frac1{\sqrt2}. \end{aligned}

Therefore

SΨ−=−22.S_{\Psi^-}=-2\sqrt2.

Every Bell-local model in this two-setting, two-outcome scenario satisfies

∣S∣≤2,\lvert S\rvert\leq2,

whereas quantum theory permits ∣S∣≤22\lvert S\rvert\leq2\sqrt2. Relabeling one outcome or changing which CHSH term carries the minus sign may reverse the sign of SS without changing its physical content. A calculation should never combine correlators from one convention with a threshold from another.

Finite data produce a confidence interval, not an exact SS. The acceptance test must account for random setting counts, temporal correlations allowed by the model, heralding, and any stopping rule. Reporting only a point estimate and a Gaussian-looking error bar is not by itself a cryptographic proof.

After Bob’s fixed outcome flip, define the key-basis quantum bit error rate by

Q=Pr⁡(x≠y∣key)=Pr⁡(a=b∣same direction).Q = \Pr(x\neq y\mid\mathrm{key}) = \Pr(a=b\mid\mathrm{same\ direction}).

For ideal singlets, Q=0Q=0. Noise, misalignment, multipair emission, detector effects, or Eve’s intervention can raise it. Alice and Bob do not reveal every key-round bit to estimate QQ; they either sacrifice a random sample or use a proof that bounds the relevant error from designated test statistics.

If nsiftn_{\mathrm{sift}} key rounds survive and one-way reconciliation reveals leakEC\mathrm{leak}_{\mathrm{EC}} bits, a schematic asymptotic ledger is

ℓ≲nsift H(X∣E)−leakEC,\ell \lesssim n_{\mathrm{sift}}\,H(X\mid E) -\mathrm{leak}_{\mathrm{EC}},

before finite-size, verification, and security-parameter deductions. The entire security problem lies in lower-bounding H(X∣E)H(X\mid E) from the accepted statistics and assumptions.

The phrase “security from Bell’s theorem” is used for several inequivalent claims. Keeping them separate is essential.

If Eve replaces the source with pairs carrying locally preassigned outcomes, the resulting correlations obey a Bell inequality. A strong E91 violation therefore rules out that simple local strategy under the Bell assumptions. It also reflects a monogamy tradeoff: correlations that are nearly ideal between Alice and Bob cannot simultaneously be copied perfectly to Eve.

This is powerful intuition, but it is not a complete modern proof. Eve may use quantum systems, coherent attacks, device side channels, memory across rounds, or loss-dependent strategies. Bell-test sampling and classical postprocessing must be integrated into one theorem.

In a standard entanglement-based proof, Eve may control the pair source and the channel while Alice’s and Bob’s measurement models are characterized. Security can be expressed through complementary bit and phase errors, an entropic uncertainty relation, or virtual entanglement distillation. A common asymptotic one-way bound per sifted key round is

rEB≥1−h2(eb)−h2(ep),r_{\mathrm{EB}} \geq 1-h_2(e_b)-h_2(e_p),

where ebe_b is the key-basis bit error and epe_p is the inferred phase error. Under a symmetric reduction eb=ep=Qe_b=e_p=Q,

rEB≥1−2h2(Q).r_{\mathrm{EB}}\geq1-2h_2(Q).

This security route need not observe a Bell violation. BBM92, for example, is an entanglement-based counterpart of BB84 that uses complementary-basis errors without making a Bell inequality the operational certificate.

Device-independent QKD treats the endpoint measurement boxes primarily by their classical inputs and outputs rather than by a trusted internal Hilbert-space model. A loophole-aware Bell violation then bounds Eve’s information. This stronger conclusion still assumes authenticated communication, secure and isolated laboratories, sufficiently independent random settings, a valid trial structure, and no unauthorized output leakage.

The dedicated Device-Independent QKD page derives a representative asymptotic CHSH rate, then replaces its collective-attack assumptions with the sequential entropy-accumulation and finite-key ledger needed for modern claims. It also separates Bell-test detection thresholds from the stricter conditions for a positive secret key.

The trust distinction can be summarized as follows.

FamilySourceEndpoint measurementsBell violation required?
standard entanglement-based QKDmay be untrustedcharacterized in the proofnot generally
original E91 presentationmay be placed in the channelmodeled qubit measurementsused as disturbance test
device-independent QKDmay be untrustedinferred from input-output behavior, with laboratory assumptionsyes

Entanglement-based does not mean device-independent. Moving the source outside the trusted boundary does not automatically remove assumptions about detectors, basis choices, isolation, or postselection.

Consider the Bell-isotropic family

ρv=v∣Ψ−⟩ ⁣⟨Ψ−∣+(1−v)I44,0≤v≤1.\rho_v =v\lvert\Psi^-\rangle\!\langle\Psi^-\rvert +(1-v)\frac{I_4}{4}, \qquad 0\leq v\leq1.

The white-noise component has zero correlators, so

Ev(α,β)=−vcos⁡(α−β),∣Sv∣=22 v.E_v(\alpha,\beta)=-v\cos(\alpha-\beta), \qquad \lvert S_v\rvert=2\sqrt2\,v.

On the same-direction key settings,

Qv=1−v2.Q_v=\frac{1-v}{2}.

Thus Bell violation occurs when

v>12⟺Qv<1−1/22≈14.64%.v>\frac1{\sqrt2} \quad\Longleftrightarrow\quad Q_v<\frac{1-1/\sqrt2}{2} \approx14.64\%.

That 14.64%14.64\% number is a Bell-violation boundary for this state and these settings, not a secret-key threshold. The simple symmetric device-dependent bound becomes positive only below approximately 11.00%11.00\%. A device-independent key threshold is stricter and protocol-dependent; it must come from the exact Bell-to-entropy and finite-key proof, not from the mere fact that ∣S∣>2\lvert S\rvert>2.

For example, at v=0.9v=0.9,

Q=0.05,∣S∣=1.82≈2.546.Q=0.05, \qquad \lvert S\rvert=1.8\sqrt2\approx2.546.

The illustrative device-dependent asymptotic fraction is

rEB≈0.427.r_{\mathrm{EB}}\approx0.427.

It is per sifted key round under idealized reconciliation assumptions and does not include the 2/92/9 uniform-setting factor, pair-production rate, losses, finite statistics, authentication consumption, or detector effects. The same QQ and SS can be entered into a particular DIQKD theorem only after its trial, loss, attack, and finite-data assumptions have been verified.

Entanglement does not authenticate identities. Without an authenticated classical channel, Eve can run one protocol with Alice and a separate protocol with Bob. She can announce settings, fabricate test transcripts consistent with each separate link, reconcile two unrelated keys, and relay later traffic. Alice and Bob may each see excellent local statistics while sharing no key with one another.

QKD therefore expands a short initial authentication resource; it does not create authenticated identity from nothing. Authentication failure belongs in the composable failure budget, and refresh policies must reserve enough key material for future authenticated sessions.

Loss is not automatically evidence of eavesdropping, but it changes what the observed sample can certify. An adversarial source may correlate whether a detector clicks with hidden variables and measurement settings. If Alice and Bob compute SS only from a favorable detected subset under an unjustified fair-sampling assumption, a local strategy can imitate a Bell violation. This is the detection loophole.

Two broad treatments must not be mixed.

  • In device-dependent QKD, characterized source and detector models can place vacuum, loss, double-click, and efficiency terms inside a security proof. Detector side channels still have to match that model.
  • In device-independent QKD, no-click behavior must be included in the input-output analysis, or an event-ready herald must define the trial before the private measurement settings are chosen. Outcome-dependent deletion is not legitimate postprocessing.

Coincidence windows also matter. A rule that pairs detections using timestamps can bias the sample if timing depends on setting or outcome. The protocol must predefine the window, resolve multiple detections, and include rejected events in the audit trail.

Let ftryf_{\mathrm{try}} be the attempted-trial rate, php_h the probability of an accepted herald, ηA\eta_A and ηB\eta_B the total local detection efficiencies conditioned on that herald, and pkeyp_{\mathrm{key}} the setting probability assigned to key rounds. A first raw-rate estimate is

Rraw≈ftryphηAηBpkey.R_{\mathrm{raw}} \approx f_{\mathrm{try}}p_h\eta_A\eta_Bp_{\mathrm{key}}.

This equation is a ledger, not a security theorem. Real implementations also track at least:

  • multipair emission and source brightness;
  • spectral, temporal, and polarization distinguishability;
  • basis-choice speed and randomness quality;
  • coupling, transmission, and detector efficiency;
  • dark counts, afterpulsing, dead time, and double clicks;
  • synchronization, coincidence windows, and drift;
  • setting-dependent loss and electromagnetic or optical leakage;
  • the number of trials assigned to key estimation and Bell estimation;
  • reconciliation efficiency and all public leakage.

The first entangled-photon QKD demonstrations in 2000 established key material over separated optical stations and explicitly tested eavesdropping strategies. Later experiments moved Bell-certified key generation toward the device-independent regime. These achievements have different trust contracts, loss budgets, and finite-data claims; they should not be compared by distance or raw bit rate alone.

E91, BBM92, and BB84 are close mathematically but not identical operational protocols.

Protocol pictureQuantum preparationMain test dataCharacteristic point
E91distributed entangled pairskey-basis errors and Bell correlatorsBell test is built into the transcript
BBM92distributed entangled pairscomplementary-basis errorsentanglement-based counterpart of BB84
BB84four prepared single-qubit statesmatched-basis errorsimplemented as prepare and measure
source-replaced BB84virtual entangled pairsbit and phase errorsproof representation, not necessarily hardware

If Alice measures one half of ∣Φ+⟩\lvert\Phi^+\rangle and thereby remotely prepares Bob’s conditional state, an entanglement-based description can be reduced to a prepare-and-measure description. Bennett, Brassard, and Mermin used this relation to show that Bell’s theorem is not necessary for the security logic of an EPR-based counterpart to BB84.

The equivalence is proof- and protocol-dependent. It does not imply that a laboratory with a middle entangled-pair source has the same loss pattern, side channels, or trust boundary as a transmitter that prepares BB84 states.

  • Saying that any entangled state violates CHSH.
  • Treating an observed ∣S∣>2\lvert S\rvert>2 as a complete finite-key proof.
  • Calling every entanglement-based protocol device-independent.
  • Forgetting Bob’s deterministic bit flip for singlet anticorrelations.
  • Mixing spin-space angles with physical linear-polarizer angles.
  • Estimating the Bell parameter after deleting no-clicks without a justified trial model.
  • Using the 14.64%14.64\% Werner-state Bell boundary as a generic QKD threshold.
  • Counting a raw coincidence rate as a secret-key rate.
  • Assuming an untrusted source removes the need to characterize endpoint leakage and setting generation.
  • Omitting authentication because the quantum channel uses entanglement.

Starting from Πa(α)=[I+aA(α)]/2\Pi_a(\alpha)=[I+aA(\alpha)]/2, derive

P(a,b∣α,β)=14[1−abcos⁡(α−β)].P(a,b\mid\alpha,\beta) =\frac14[1-ab\cos(\alpha-\beta)].
Solution

Expand the product of projectors:

Πa⊗Πb=14[I⊗I+aA⊗I+bI⊗B+abA⊗B].\Pi_a\otimes\Pi_b =\frac14\left[ I\otimes I +aA\otimes I +bI\otimes B +abA\otimes B \right].

The singlet’s local Bloch vectors vanish, so the middle two terms have zero expectation. Its correlation tensor gives

⟨A(α)⊗B(β)⟩=−cos⁡(α−β).\langle A(\alpha)\otimes B(\beta)\rangle =-\cos(\alpha-\beta).

Substitution yields the stated probability. Summing over either outcome gives 1/21/2, and setting α=β\alpha=\beta leaves only a=−ba=-b with nonzero probability.

Evaluate all four correlators in the page’s definition of SS and verify S=−22S=-2\sqrt2.

Solution

Using E(α,β)=−cos⁡(α−β)E(\alpha,\beta)=-\cos(\alpha-\beta),

E(0,π/4)=−1/2,E(0,3π/4)=+1/2,E(π/2,π/4)=−1/2,E(π/2,3π/4)=−1/2.\begin{aligned} E(0,\pi/4)&=-1/\sqrt2,\\ E(0,3\pi/4)&=+1/\sqrt2,\\ E(\pi/2,\pi/4)&=-1/\sqrt2,\\ E(\pi/2,3\pi/4)&=-1/\sqrt2. \end{aligned}

The second correlator enters with a minus sign, so all four contributions to SS equal −1/2-1/\sqrt2. Their sum is −22-2\sqrt2. The magnitude is the invariant comparison with the local bound.

Let Alice choose αi\alpha_i with probabilities pip_i and Bob choose βj\beta_j with probabilities qjq_j. Find the probabilities of key and CHSH test rounds. Recover the uniform values.

Solution

The key cells are (α2,β1)(\alpha_2,\beta_1) and (α3,β2)(\alpha_3,\beta_2), so

pkey=p2q1+p3q2.p_{\mathrm{key}}=p_2q_1+p_3q_2.

The CHSH cells are (α1,β1)(\alpha_1,\beta_1), (α1,β3)(\alpha_1,\beta_3), (α3,β1)(\alpha_3,\beta_1), and (α3,β3)(\alpha_3,\beta_3), giving

ptest=p1q1+p1q3+p3q1+p3q3.p_{\mathrm{test}} =p_1q_1+p_1q_3+p_3q_1+p_3q_3.

For pi=qj=1/3p_i=q_j=1/3, these become 2/92/9 and 4/94/9. The remaining probability is 1/31/3.

For ρv\rho_v, derive the QBER and find the largest QBER compatible with a CHSH violation in the stated settings.

Solution

White noise gives equal probability to all four outcome pairs. On a same-axis round it therefore produces the wrong, equal-sign outcomes with probability 1/21/2, while the singlet never does. Hence

Qv=1−v2.Q_v=\frac{1-v}{2}.

Because ∣Sv∣=22v\lvert S_v\rvert=2\sqrt2v, violation requires v>1/2v>1/\sqrt2. Eliminating vv gives

Qv<1−1/22≈0.14645.Q_v<\frac{1-1/\sqrt2}{2}\approx0.14645.

This is not yet a positive-key condition.

5. Separate Bell evidence from a key ledger

Section titled “5. Separate Bell evidence from a key ledger”

At v=0.9v=0.9, calculate QQ, ∣S∣\lvert S\rvert, the symmetric device-dependent fraction 1−2h2(Q)1-2h_2(Q), and explain why these values do not by themselves establish a positive finite device-independent key.

Solution

The observed parameters are

Q=0.05,∣S∣=22(0.9)≈2.5456.Q=0.05, \qquad \lvert S\rvert=2\sqrt2(0.9)\approx2.5456.

Using h2(0.05)≈0.28640h_2(0.05)\approx0.28640 gives

rEB=1−2h2(0.05)≈0.4272.r_{\mathrm{EB}} =1-2h_2(0.05) \approx0.4272.

The value ∣S∣>2\lvert S\rvert>2 excludes Bell-local correlations only under a valid trial and causal model. A finite DIQKD claim additionally needs a protocol-specific entropy tradeoff, a one-sided statistical margin, treatment of no-clicks and memory, reconciliation leakage, verification, privacy amplification, and authentication. The point estimates alone do not supply that ledger.

6. Untrusted source versus untrusted devices

Section titled “6. Untrusted source versus untrusted devices”

Explain why allowing Eve to control the pair source does not make a standard entanglement-based protocol device-independent.

Solution

A source-untrusted proof can model the incoming bipartite state as arbitrary and correlated with Eve, yet still rely on calibrated endpoint measurements, known dimensions or squashing maps, characterized detection behavior, and isolated setting generators. Device independence removes much of the internal measurement model and replaces it with constraints inferred from observed input-output correlations. It therefore needs a loophole-aware Bell test and stronger laboratory, randomness, trial, and leakage assumptions.

Construct a man-in-the-middle attack against an otherwise ideal E91 exchange when the public classical channel is not authenticated.

Solution

Eve impersonates Bob to Alice and Alice to Bob. She distributes or receives separate entangled systems on the two links, substitutes every classical message, and conducts independent setting disclosure, Bell testing, reconciliation, and privacy amplification with each endpoint. Alice and Bob each obtain a valid key, but both keys are shared with Eve rather than with one another. Eve can decrypt, modify, and re-encrypt later traffic. Quantum correlations do not reveal the identity substitution.

Suppose the devices may output ∅\varnothing as well as ±1\pm1. Why is it unsafe to delete every ∅\varnothing event and compute CHSH only from double clicks in a device-independent claim?

Solution

A local hidden-variable device can decide whether to click as a function of its local setting and hidden variable. It can suppress trials whose outcomes would weaken the desired correlation, leaving a detected subset with an apparent CHSH violation. This is the detection loophole. A valid DI treatment assigns outcomes to no-clicks, includes them in a suitable inequality, or uses an event-ready herald that defines an eligible trial before the private settings are selected.

  • Quantum Key Distribution supplies the composable correctness, secrecy, authentication, and finite-key contract.
  • BB84 gives the canonical prepare-and-measure protocol and its source-replacement bridge.
  • Bell States develops the singlet and its correlation tensor.
  • Bell Theorem states the factorization and setting-independence assumptions excluded by Bell violations.
  • CHSH Inequality owns the local and Tsirelson bounds.
  • Certification of Entanglement treats loopholes, finite-data inference, witnesses, and self-testing.
  • Device-Independent QKD owns the black-box protocol model, Bell-to-entropy rate, event-ready trial order, memory assumptions, and finite-key ledger.
  • Entanglement Distillation develops the virtual purification picture used in security proofs.
  • No-Cloning and No-Signaling separates Bell nonlocality from operational faster-than-light signaling.
  • Cryptography Case Studies tracks entanglement-based links through loss, experiments, and claim boundaries.
  • Trace Distance gives the operational metric used in composable secrecy statements.
  1. A. K. Ekert, “Quantum Cryptography Based on Bell’s Theorem,” Physical Review Letters 67, 661–663 (1991), doi:10.1103/PhysRevLett.67.661.
  2. J. F. Clauser, M. A. Horne, A. Shimony, and R. A. Holt, “Proposed Experiment to Test Local Hidden-Variable Theories,” Physical Review Letters 23, 880–884 (1969), doi:10.1103/PhysRevLett.23.880.
  3. C. H. Bennett, G. Brassard, and N. D. Mermin, “Quantum Cryptography without Bell’s Theorem,” Physical Review Letters 68, 557–559 (1992), doi:10.1103/PhysRevLett.68.557.
  4. T. Jennewein, C. Simon, G. Weihs, H. Weinfurter, and A. Zeilinger, “Quantum Cryptography with Entangled Photons,” Physical Review Letters 84, 4729–4732 (2000), doi:10.1103/PhysRevLett.84.4729.
  5. D. S. Naik, C. G. Peterson, A. G. White, A. J. Berglund, and P. G. Kwiat, “Entangled State Quantum Cryptography: Eavesdropping on the Ekert Protocol,” Physical Review Letters 84, 4733–4736 (2000), doi:10.1103/PhysRevLett.84.4733.
  6. H.-K. Lo and H. F. Chau, “Unconditional Security of Quantum Key Distribution over Arbitrarily Long Distances,” Science 283, 2050–2056 (1999), doi:10.1126/science.283.5410.2050.
  7. P. W. Shor and J. Preskill, “Simple Proof of Security of the BB84 Quantum Key Distribution Protocol,” Physical Review Letters 85, 441–444 (2000), doi:10.1103/PhysRevLett.85.441.
  8. M. Koashi and J. Preskill, “Secure Quantum Key Distribution with an Uncharacterized Source,” Physical Review Letters 90, 057902 (2003), doi:10.1103/PhysRevLett.90.057902.
  9. I. Devetak and A. Winter, “Distillation of Secret Key and Entanglement from Quantum States,” Proceedings of the Royal Society A 461, 207–235 (2005), doi:10.1098/rspa.2004.1372.
  10. A. Acín, N. Gisin, and L. Masanes, “From Bell’s Theorem to Secure Quantum Key Distribution,” Physical Review Letters 97, 120405 (2006), doi:10.1103/PhysRevLett.97.120405.
  11. A. Acín, N. Brunner, N. Gisin, S. Massar, S. Pironio, and V. Scarani, “Device-Independent Security of Quantum Cryptography against Collective Attacks,” Physical Review Letters 98, 230501 (2007), doi:10.1103/PhysRevLett.98.230501.
  12. U. Vazirani and T. Vidick, “Fully Device-Independent Quantum Key Distribution,” Physical Review Letters 113, 140501 (2014), doi:10.1103/PhysRevLett.113.140501.
  13. R. Arnon-Friedman, F. Dupuis, O. Fawzi, R. Renner, and T. Vidick, “Practical Device-Independent Quantum Cryptography via Entropy Accumulation,” Nature Communications 9, 459 (2018), doi:10.1038/s41467-017-02307-4.
  14. D. P. Nadlinger, P. Drmota, B. C. Nichol, et al., “Experimental Quantum Key Distribution Certified by Bell’s Theorem,” Nature 607, 682–686 (2022), doi:10.1038/s41586-022-04941-5.
  15. W. Zhang, T. van Leent, K. Redeker, et al., “A Device-Independent Quantum Key Distribution System for Distant Users,” Nature 607, 687–691 (2022), doi:10.1038/s41586-022-04891-y.
  16. V. Scarani, H. Bechmann-Pasquinucci, N. J. Cerf, et al., “The Security of Practical Quantum Key Distribution,” Reviews of Modern Physics 81, 1301–1350 (2009), doi:10.1103/RevModPhys.81.1301.
  17. C. Portmann and R. Renner, “Security in Quantum Cryptography,” Reviews of Modern Physics 94, 025008 (2022), doi:10.1103/RevModPhys.94.025008.

E91 distributes entangled pairs and separates its measurement transcript into same-direction key rounds and Bell-test rounds. For the ideal singlet, E(α,β)=−cos⁡(α−β)E(\alpha,\beta)=-\cos(\alpha-\beta), the retained key outcomes are perfectly anticorrelated, and the stated CHSH convention gives S=−22S=-2\sqrt2.

A Bell violation excludes Bell-local explanations under its assumptions, but it is not by itself a complete security proof. Standard entanglement-based QKD may allow an untrusted source while retaining characterized endpoint devices; device-independent QKD uses loophole-aware input-output correlations to relax that measurement model. Both still require authenticated communication, declared treatment of losses and no-clicks, finite statistical bounds, reconciliation, verification, and privacy amplification.