E91 and Entanglement-Based QKD
E91 is the entanglement-based quantum key distribution protocol proposed by Artur Ekert in 1991. A source distributes one system from each entangled pair to Alice and the other to Bob. They choose local measurement settings at random. Some setting pairs produce anticorrelated raw-key bits; other pairs estimate a Bell parameter that tests whether the observed correlations admit a Bell-local explanation.
The protocol does not turn a Bell violation directly into a finished key. Alice and Bob still need an authenticated classical channel, a declared trial and detection model, finite-sample parameter estimation, error correction, key verification, and privacy amplification. The operational contract is the usual QKD contract: either abort, or output matching strings that are close to uniform and independent of an adversary under a stated security model.
This page is the canonical home for the original three-setting E91 schedule, its singlet correlations, Bell-test calculation, key-round sifting, and the reason entanglement-based QKD is not automatically device-independent. Device-Independent QKD owns the black-box input-output model, Bell-to-entropy bounds, loophole control, event-ready heralding, and finite-key ledger. Quantum Key Distribution owns composable security definitions and finite-key bookkeeping. Bell Theorem and the CHSH Inequality own the foundational no-local-model result. Cryptography Case Studies owns optical loss budgets and experimental evidence.
Protocol Contract
Section titled “Protocol Contract”An E91 analysis must identify at least four interfaces.
- A pair source emits bipartite systems. It may sit with Alice, in the channel, or at a third station. A robust security model may grant Eve control of the source.
- Alice and Bob have local setting generators and measurement devices. How much of those devices is characterized separates device-dependent from device-independent protocols.
- The quantum links produce detections, losses, timing information, and possible side-channel data. The rule defining a trial cannot be chosen after seeing favorable outcomes.
- An authenticated but public classical channel carries detection announcements, setting choices, test data, reconciliation messages, and verification tags. Eve may read these messages but must not be able to alter them undetected.
The raw observations are therefore not just bit strings. A useful record for round is
where is any herald, and are settings, are outcomes when present, and record detection status, and contains timing information. Security depends on how this complete record is filtered into key rounds, test rounds, and discarded rounds.
Singlet Correlations
Section titled “Singlet Correlations”The ideal E91 resource is the two-qubit singlet
Bell States owns the full Bell basis and its local-Pauli relations. The property needed here is the singlet correlation tensor
Choose coplanar Bloch-sphere directions and define binary observables
Their eigenvalues are , with projectors
The ideal joint distribution is
The correlator is consequently
When the directions agree, : Alice and Bob always obtain opposite signs. Either party can apply a fixed relabeling so that these become matching raw-key bits. Each local marginal remains uniform,
so neither endpoint controls the ideal outcome in advance.
For polarization qubits, a physical linear-polarizer angle corresponds to half the equatorial Bloch angle because polarization probabilities contain a double angle. Stating which convention is in use prevents a common factor-of-two error when translating spin-direction formulas to optical analyzers.
Original Three-Setting Schedule
Section titled “Original Three-Setting Schedule”One convenient qubit form of the E91 schedule uses three settings per party:
| Party | Setting | Bloch angle | Principal role |
|---|---|---|---|
| Alice | Bell test | ||
| Alice | key with | ||
| Alice | key with and Bell test | ||
| Bob | key with and Bell test | ||
| Bob | key with | ||
| Bob | Bell test |
The nine setting pairs are classified as follows:
| test | discard | test | |
| key | discard | discard | |
| test | key | test |
“Discard” describes the canonical teaching schedule. A modern proof may use more of the observed data, but it must declare that estimator before looking at the transcript.
With independent uniform choices, the ideal classification probabilities are
The low key fraction is not fundamental. Biased setting probabilities can favor key settings while reserving enough randomly selected trials for a statistically sound Bell estimate.
E91 distributes singlet halves to independent local measurements. After an authenticated setting announcement, two same-direction pairs supply raw-key data and four pairs estimate the chosen CHSH expression. The source need not be trusted, but the trust assigned to the endpoint devices must be stated.
Bit convention
Section titled “Bit convention”For a key round, define
The sign in Bob’s map performs the fixed singlet anticorrelation flip. If , then . Other bit conventions are equally valid, but changing a convention requires changing the expected correlations consistently.
Protocol Transcript
Section titled “Protocol Transcript”A complete idealized run has the following stages.
- Authenticate and configure. Alice and Bob establish the protocol version, setting probabilities, trial definition, abort rules, error-correction method, privacy-amplification family, and authentication keys.
- Distribute pairs. The source emits candidate pairs. A herald, if used, must be generated in a way compatible with the security model.
- Choose settings locally. Alice samples and Bob samples using private random choices made at the required time.
- Measure and record every trial. They retain outcomes, no-clicks, double-clicks, timestamps, and other declared flags rather than silently deleting inconvenient events.
- Announce detections and settings. Over the authenticated public channel, they identify the setting pair and classify each eligible event.
- Estimate parameters. Test rounds estimate the Bell statistic. A randomly selected key-basis sample or an equivalent estimator bounds the key error. If a confidence region misses the acceptance set, they abort.
- Reconcile and verify. Error correction aligns the retained raw keys; the public leakage is recorded. A verification hash bounds the probability that unequal keys survive.
- Amplify privacy. A randomly selected universal hash compresses the reconciled string to the length justified by the proof and transcript.
The public discussion is not meant to be secret. Its integrity is essential, and every revealed syndrome, sample bit, tag, and protocol decision belongs in the leakage or failure-probability ledger.
Bell-Test Calculation
Section titled “Bell-Test Calculation”For a fixed setting pair, let be the number of eligible trials with outcomes . The empirical correlator is
For the angle table above, use the sign convention
The four ideal singlet correlators are
Therefore
Every Bell-local model in this two-setting, two-outcome scenario satisfies
whereas quantum theory permits . Relabeling one outcome or changing which CHSH term carries the minus sign may reverse the sign of without changing its physical content. A calculation should never combine correlators from one convention with a threshold from another.
Finite data produce a confidence interval, not an exact . The acceptance test must account for random setting counts, temporal correlations allowed by the model, heralding, and any stopping rule. Reporting only a point estimate and a Gaussian-looking error bar is not by itself a cryptographic proof.
From Anticorrelations to Raw Key
Section titled “From Anticorrelations to Raw Key”After Bob’s fixed outcome flip, define the key-basis quantum bit error rate by
For ideal singlets, . Noise, misalignment, multipair emission, detector effects, or Eve’s intervention can raise it. Alice and Bob do not reveal every key-round bit to estimate ; they either sacrifice a random sample or use a proof that bounds the relevant error from designated test statistics.
If key rounds survive and one-way reconciliation reveals bits, a schematic asymptotic ledger is
before finite-size, verification, and security-parameter deductions. The entire security problem lies in lower-bounding from the accepted statistics and assumptions.
Three Security Interpretations
Section titled “Three Security Interpretations”The phrase “security from Bell’s theorem” is used for several inequivalent claims. Keeping them separate is essential.
Original Bell-correlation intuition
Section titled “Original Bell-correlation intuition”If Eve replaces the source with pairs carrying locally preassigned outcomes, the resulting correlations obey a Bell inequality. A strong E91 violation therefore rules out that simple local strategy under the Bell assumptions. It also reflects a monogamy tradeoff: correlations that are nearly ideal between Alice and Bob cannot simultaneously be copied perfectly to Eve.
This is powerful intuition, but it is not a complete modern proof. Eve may use quantum systems, coherent attacks, device side channels, memory across rounds, or loss-dependent strategies. Bell-test sampling and classical postprocessing must be integrated into one theorem.
Device-dependent entanglement-based QKD
Section titled “Device-dependent entanglement-based QKD”In a standard entanglement-based proof, Eve may control the pair source and the channel while Alice’s and Bob’s measurement models are characterized. Security can be expressed through complementary bit and phase errors, an entropic uncertainty relation, or virtual entanglement distillation. A common asymptotic one-way bound per sifted key round is
where is the key-basis bit error and is the inferred phase error. Under a symmetric reduction ,
This security route need not observe a Bell violation. BBM92, for example, is an entanglement-based counterpart of BB84 that uses complementary-basis errors without making a Bell inequality the operational certificate.
Device-independent QKD
Section titled “Device-independent QKD”Device-independent QKD treats the endpoint measurement boxes primarily by their classical inputs and outputs rather than by a trusted internal Hilbert-space model. A loophole-aware Bell violation then bounds Eve’s information. This stronger conclusion still assumes authenticated communication, secure and isolated laboratories, sufficiently independent random settings, a valid trial structure, and no unauthorized output leakage.
The dedicated Device-Independent QKD page derives a representative asymptotic CHSH rate, then replaces its collective-attack assumptions with the sequential entropy-accumulation and finite-key ledger needed for modern claims. It also separates Bell-test detection thresholds from the stricter conditions for a positive secret key.
The trust distinction can be summarized as follows.
| Family | Source | Endpoint measurements | Bell violation required? |
|---|---|---|---|
| standard entanglement-based QKD | may be untrusted | characterized in the proof | not generally |
| original E91 presentation | may be placed in the channel | modeled qubit measurements | used as disturbance test |
| device-independent QKD | may be untrusted | inferred from input-output behavior, with laboratory assumptions | yes |
Entanglement-based does not mean device-independent. Moving the source outside the trusted boundary does not automatically remove assumptions about detectors, basis choices, isolation, or postselection.
Worked Noise Model: Werner Pairs
Section titled “Worked Noise Model: Werner Pairs”Consider the Bell-isotropic family
The white-noise component has zero correlators, so
On the same-direction key settings,
Thus Bell violation occurs when
That number is a Bell-violation boundary for this state and these settings, not a secret-key threshold. The simple symmetric device-dependent bound becomes positive only below approximately . A device-independent key threshold is stricter and protocol-dependent; it must come from the exact Bell-to-entropy and finite-key proof, not from the mere fact that .
For example, at ,
The illustrative device-dependent asymptotic fraction is
It is per sifted key round under idealized reconciliation assumptions and does not include the uniform-setting factor, pair-production rate, losses, finite statistics, authentication consumption, or detector effects. The same and can be entered into a particular DIQKD theorem only after its trial, loss, attack, and finite-data assumptions have been verified.
Authentication and Active Relay Attacks
Section titled “Authentication and Active Relay Attacks”Entanglement does not authenticate identities. Without an authenticated classical channel, Eve can run one protocol with Alice and a separate protocol with Bob. She can announce settings, fabricate test transcripts consistent with each separate link, reconcile two unrelated keys, and relay later traffic. Alice and Bob may each see excellent local statistics while sharing no key with one another.
QKD therefore expands a short initial authentication resource; it does not create authenticated identity from nothing. Authentication failure belongs in the composable failure budget, and refresh policies must reserve enough key material for future authenticated sessions.
Loss, No-Clicks, and Postselection
Section titled “Loss, No-Clicks, and Postselection”Loss is not automatically evidence of eavesdropping, but it changes what the observed sample can certify. An adversarial source may correlate whether a detector clicks with hidden variables and measurement settings. If Alice and Bob compute only from a favorable detected subset under an unjustified fair-sampling assumption, a local strategy can imitate a Bell violation. This is the detection loophole.
Two broad treatments must not be mixed.
- In device-dependent QKD, characterized source and detector models can place vacuum, loss, double-click, and efficiency terms inside a security proof. Detector side channels still have to match that model.
- In device-independent QKD, no-click behavior must be included in the input-output analysis, or an event-ready herald must define the trial before the private measurement settings are chosen. Outcome-dependent deletion is not legitimate postprocessing.
Coincidence windows also matter. A rule that pairs detections using timestamps can bias the sample if timing depends on setting or outcome. The protocol must predefine the window, resolve multiple detections, and include rejected events in the audit trail.
Physical Rate Ledger
Section titled “Physical Rate Ledger”Let be the attempted-trial rate, the probability of an accepted herald, and the total local detection efficiencies conditioned on that herald, and the setting probability assigned to key rounds. A first raw-rate estimate is
This equation is a ledger, not a security theorem. Real implementations also track at least:
- multipair emission and source brightness;
- spectral, temporal, and polarization distinguishability;
- basis-choice speed and randomness quality;
- coupling, transmission, and detector efficiency;
- dark counts, afterpulsing, dead time, and double clicks;
- synchronization, coincidence windows, and drift;
- setting-dependent loss and electromagnetic or optical leakage;
- the number of trials assigned to key estimation and Bell estimation;
- reconciliation efficiency and all public leakage.
The first entangled-photon QKD demonstrations in 2000 established key material over separated optical stations and explicitly tested eavesdropping strategies. Later experiments moved Bell-certified key generation toward the device-independent regime. These achievements have different trust contracts, loss budgets, and finite-data claims; they should not be compared by distance or raw bit rate alone.
Relation to BB84 and BBM92
Section titled “Relation to BB84 and BBM92”E91, BBM92, and BB84 are close mathematically but not identical operational protocols.
| Protocol picture | Quantum preparation | Main test data | Characteristic point |
|---|---|---|---|
| E91 | distributed entangled pairs | key-basis errors and Bell correlators | Bell test is built into the transcript |
| BBM92 | distributed entangled pairs | complementary-basis errors | entanglement-based counterpart of BB84 |
| BB84 | four prepared single-qubit states | matched-basis errors | implemented as prepare and measure |
| source-replaced BB84 | virtual entangled pairs | bit and phase errors | proof representation, not necessarily hardware |
If Alice measures one half of and thereby remotely prepares Bob’s conditional state, an entanglement-based description can be reduced to a prepare-and-measure description. Bennett, Brassard, and Mermin used this relation to show that Bell’s theorem is not necessary for the security logic of an EPR-based counterpart to BB84.
The equivalence is proof- and protocol-dependent. It does not imply that a laboratory with a middle entangled-pair source has the same loss pattern, side channels, or trust boundary as a transmitter that prepares BB84 states.
Common Mistakes
Section titled “Common Mistakes”- Saying that any entangled state violates CHSH.
- Treating an observed as a complete finite-key proof.
- Calling every entanglement-based protocol device-independent.
- Forgetting Bob’s deterministic bit flip for singlet anticorrelations.
- Mixing spin-space angles with physical linear-polarizer angles.
- Estimating the Bell parameter after deleting no-clicks without a justified trial model.
- Using the Werner-state Bell boundary as a generic QKD threshold.
- Counting a raw coincidence rate as a secret-key rate.
- Assuming an untrusted source removes the need to characterize endpoint leakage and setting generation.
- Omitting authentication because the quantum channel uses entanglement.
Exercises
Section titled “Exercises”1. Derive the singlet joint distribution
Section titled “1. Derive the singlet joint distribution”Starting from , derive
Solution
Expand the product of projectors:
The singlet’s local Bloch vectors vanish, so the middle two terms have zero expectation. Its correlation tensor gives
Substitution yields the stated probability. Summing over either outcome gives , and setting leaves only with nonzero probability.
2. Check every CHSH sign
Section titled “2. Check every CHSH sign”Evaluate all four correlators in the page’s definition of and verify .
Solution
Using ,
The second correlator enters with a minus sign, so all four contributions to equal . Their sum is . The magnitude is the invariant comparison with the local bound.
3. Setting probabilities
Section titled “3. Setting probabilities”Let Alice choose with probabilities and Bob choose with probabilities . Find the probabilities of key and CHSH test rounds. Recover the uniform values.
Solution
The key cells are and , so
The CHSH cells are , , , and , giving
For , these become and . The remaining probability is .
4. Werner-state boundaries
Section titled “4. Werner-state boundaries”For , derive the QBER and find the largest QBER compatible with a CHSH violation in the stated settings.
Solution
White noise gives equal probability to all four outcome pairs. On a same-axis round it therefore produces the wrong, equal-sign outcomes with probability , while the singlet never does. Hence
Because , violation requires . Eliminating gives
This is not yet a positive-key condition.
5. Separate Bell evidence from a key ledger
Section titled “5. Separate Bell evidence from a key ledger”At , calculate , , the symmetric device-dependent fraction , and explain why these values do not by themselves establish a positive finite device-independent key.
Solution
The observed parameters are
Using gives
The value excludes Bell-local correlations only under a valid trial and causal model. A finite DIQKD claim additionally needs a protocol-specific entropy tradeoff, a one-sided statistical margin, treatment of no-clicks and memory, reconciliation leakage, verification, privacy amplification, and authentication. The point estimates alone do not supply that ledger.
6. Untrusted source versus untrusted devices
Section titled “6. Untrusted source versus untrusted devices”Explain why allowing Eve to control the pair source does not make a standard entanglement-based protocol device-independent.
Solution
A source-untrusted proof can model the incoming bipartite state as arbitrary and correlated with Eve, yet still rely on calibrated endpoint measurements, known dimensions or squashing maps, characterized detection behavior, and isolated setting generators. Device independence removes much of the internal measurement model and replaces it with constraints inferred from observed input-output correlations. It therefore needs a loophole-aware Bell test and stronger laboratory, randomness, trial, and leakage assumptions.
7. Authentication attack
Section titled “7. Authentication attack”Construct a man-in-the-middle attack against an otherwise ideal E91 exchange when the public classical channel is not authenticated.
Solution
Eve impersonates Bob to Alice and Alice to Bob. She distributes or receives separate entangled systems on the two links, substitutes every classical message, and conducts independent setting disclosure, Bell testing, reconciliation, and privacy amplification with each endpoint. Alice and Bob each obtain a valid key, but both keys are shared with Eve rather than with one another. Eve can decrypt, modify, and re-encrypt later traffic. Quantum correlations do not reveal the identity substitution.
8. Why postselected CHSH can fail
Section titled “8. Why postselected CHSH can fail”Suppose the devices may output as well as . Why is it unsafe to delete every event and compute CHSH only from double clicks in a device-independent claim?
Solution
A local hidden-variable device can decide whether to click as a function of its local setting and hidden variable. It can suppress trials whose outcomes would weaken the desired correlation, leaving a detected subset with an apparent CHSH violation. This is the detection loophole. A valid DI treatment assigns outcomes to no-clicks, includes them in a suitable inequality, or uses an event-ready herald that defines an eligible trial before the private settings are selected.
Further Connections
Section titled “Further Connections”- Quantum Key Distribution supplies the composable correctness, secrecy, authentication, and finite-key contract.
- BB84 gives the canonical prepare-and-measure protocol and its source-replacement bridge.
- Bell States develops the singlet and its correlation tensor.
- Bell Theorem states the factorization and setting-independence assumptions excluded by Bell violations.
- CHSH Inequality owns the local and Tsirelson bounds.
- Certification of Entanglement treats loopholes, finite-data inference, witnesses, and self-testing.
- Device-Independent QKD owns the black-box protocol model, Bell-to-entropy rate, event-ready trial order, memory assumptions, and finite-key ledger.
- Entanglement Distillation develops the virtual purification picture used in security proofs.
- No-Cloning and No-Signaling separates Bell nonlocality from operational faster-than-light signaling.
- Cryptography Case Studies tracks entanglement-based links through loss, experiments, and claim boundaries.
- Trace Distance gives the operational metric used in composable secrecy statements.
References
Section titled “References”- A. K. Ekert, “Quantum Cryptography Based on Bell’s Theorem,” Physical Review Letters 67, 661–663 (1991), doi:10.1103/PhysRevLett.67.661.
- J. F. Clauser, M. A. Horne, A. Shimony, and R. A. Holt, “Proposed Experiment to Test Local Hidden-Variable Theories,” Physical Review Letters 23, 880–884 (1969), doi:10.1103/PhysRevLett.23.880.
- C. H. Bennett, G. Brassard, and N. D. Mermin, “Quantum Cryptography without Bell’s Theorem,” Physical Review Letters 68, 557–559 (1992), doi:10.1103/PhysRevLett.68.557.
- T. Jennewein, C. Simon, G. Weihs, H. Weinfurter, and A. Zeilinger, “Quantum Cryptography with Entangled Photons,” Physical Review Letters 84, 4729–4732 (2000), doi:10.1103/PhysRevLett.84.4729.
- D. S. Naik, C. G. Peterson, A. G. White, A. J. Berglund, and P. G. Kwiat, “Entangled State Quantum Cryptography: Eavesdropping on the Ekert Protocol,” Physical Review Letters 84, 4733–4736 (2000), doi:10.1103/PhysRevLett.84.4733.
- H.-K. Lo and H. F. Chau, “Unconditional Security of Quantum Key Distribution over Arbitrarily Long Distances,” Science 283, 2050–2056 (1999), doi:10.1126/science.283.5410.2050.
- P. W. Shor and J. Preskill, “Simple Proof of Security of the BB84 Quantum Key Distribution Protocol,” Physical Review Letters 85, 441–444 (2000), doi:10.1103/PhysRevLett.85.441.
- M. Koashi and J. Preskill, “Secure Quantum Key Distribution with an Uncharacterized Source,” Physical Review Letters 90, 057902 (2003), doi:10.1103/PhysRevLett.90.057902.
- I. Devetak and A. Winter, “Distillation of Secret Key and Entanglement from Quantum States,” Proceedings of the Royal Society A 461, 207–235 (2005), doi:10.1098/rspa.2004.1372.
- A. Acín, N. Gisin, and L. Masanes, “From Bell’s Theorem to Secure Quantum Key Distribution,” Physical Review Letters 97, 120405 (2006), doi:10.1103/PhysRevLett.97.120405.
- A. Acín, N. Brunner, N. Gisin, S. Massar, S. Pironio, and V. Scarani, “Device-Independent Security of Quantum Cryptography against Collective Attacks,” Physical Review Letters 98, 230501 (2007), doi:10.1103/PhysRevLett.98.230501.
- U. Vazirani and T. Vidick, “Fully Device-Independent Quantum Key Distribution,” Physical Review Letters 113, 140501 (2014), doi:10.1103/PhysRevLett.113.140501.
- R. Arnon-Friedman, F. Dupuis, O. Fawzi, R. Renner, and T. Vidick, “Practical Device-Independent Quantum Cryptography via Entropy Accumulation,” Nature Communications 9, 459 (2018), doi:10.1038/s41467-017-02307-4.
- D. P. Nadlinger, P. Drmota, B. C. Nichol, et al., “Experimental Quantum Key Distribution Certified by Bell’s Theorem,” Nature 607, 682–686 (2022), doi:10.1038/s41586-022-04941-5.
- W. Zhang, T. van Leent, K. Redeker, et al., “A Device-Independent Quantum Key Distribution System for Distant Users,” Nature 607, 687–691 (2022), doi:10.1038/s41586-022-04891-y.
- V. Scarani, H. Bechmann-Pasquinucci, N. J. Cerf, et al., “The Security of Practical Quantum Key Distribution,” Reviews of Modern Physics 81, 1301–1350 (2009), doi:10.1103/RevModPhys.81.1301.
- C. Portmann and R. Renner, “Security in Quantum Cryptography,” Reviews of Modern Physics 94, 025008 (2022), doi:10.1103/RevModPhys.94.025008.
Summary
Section titled “Summary”E91 distributes entangled pairs and separates its measurement transcript into same-direction key rounds and Bell-test rounds. For the ideal singlet, , the retained key outcomes are perfectly anticorrelated, and the stated CHSH convention gives .
A Bell violation excludes Bell-local explanations under its assumptions, but it is not by itself a complete security proof. Standard entanglement-based QKD may allow an untrusted source while retaining characterized endpoint devices; device-independent QKD uses loophole-aware input-output correlations to relax that measurement model. Both still require authenticated communication, declared treatment of losses and no-clicks, finite statistical bounds, reconciliation, verification, and privacy amplification.