|q⟩ Bad Qubits

advanced · Physics · Quantum Cryptography & QKD

Security from Bell Violation

E91 certifies security by a Bell-inequality violation. This lesson makes that link rigorous: why does seeing S>2|S| > 2 guarantee that an eavesdropper learned nothing? The answer rests on two pillars — the CHSH inequality as a bound on any classical (local-hidden-variable) strategy, and the monogamy of entanglement, which forbids Eve from sharing in correlations that are already maximal between Alice and Bob.

The CHSH inequality

Consider two parties, each choosing one of two ±1\pm1-valued measurements: Alice A0,A1A_0, A_1 and Bob B0,B1B_0, B_1. Define

S=A0B0+A0B1+A1B0A1B1.S = \langle A_0 B_0\rangle + \langle A_0 B_1\rangle + \langle A_1 B_0\rangle - \langle A_1 B_1\rangle.

If outcomes are governed by any local hidden variable λ\lambda — pre-existing values ai(λ),bj(λ){±1}a_i(\lambda), b_j(\lambda) \in \{\pm1\} that the choice of setting merely reveals — then the algebraic identity

a0b0+a0b1+a1b0a1b1=a0(b0+b1)+a1(b0b1)=±2a_0 b_0 + a_0 b_1 + a_1 b_0 - a_1 b_1 = a_0(b_0 + b_1) + a_1(b_0 - b_1) = \pm 2

holds for every λ\lambda (one bracket is ±2\pm2, the other 00). Averaging over λ\lambda gives the CHSH inequality

S2.|S| \le 2.

This is the most an adversary armed with a classical, pre-agreed strategy — including a script prepared by Eve — can achieve. Any predetermined outcomes obey it.

Tsirelson's bound

Quantum mechanics violates CHSH but not without limit. For any quantum state and any observables,

S222.828,|S| \le 2\sqrt2 \approx 2.828,

Tsirelson's bound, saturated by a maximally entangled pair with the optimal measurement angles of the previous lesson. The hierarchy 2<22<42 < 2\sqrt2 < 4 separates three worlds: classical/local (2\le2), quantum (22\le 2\sqrt2), and the algebraic maximum (44, reached only by hypothetical "super-quantum" no-signalling boxes). E91's measured SS tells Alice and Bob which world their data lives in.

Monogamy of entanglement

The security punchline is monogamy: entanglement cannot be freely shared. If Alice's and Bob's qubits are maximally entangled, neither can be entangled with — or even classically correlated with — any third system. Formally, the CHSH correlations Alice–Bob, Alice–Eve, and (by symmetry) the relevant pairings obey a monogamy relation of the form

SAB2+SAE28.S_{AB}^2 + S_{AE}^2 \le 8.

If Alice and Bob observe SAB=22S_{AB} = 2\sqrt2, then SAB2=8S_{AB}^2 = 8 forces SAE=0S_{AE} = 0 in this bound — Eve's CHSH correlation with Alice is driven to zero, well below even the classical value of 22. A near-maximal violation thus quantitatively caps how much Eve can know: her uncertainty about the key approaches the maximum as SAB22S_{AB} \to 2\sqrt2.

From violation to a key rate

Real channels are noisy, so S<22S < 2\sqrt2. Security proofs turn the observed SS into a bound on Eve's Holevo information χE\chi_{E}, and hence into a positive secret-key rate via the Devetak–Winter formula rI(A:B)χ(A:E)r \ge I(A{:}B) - \chi(A{:}E). As SS falls from 222\sqrt2 toward 22, the tolerable eavesdropper information rises and the key rate shrinks to zero at a threshold violation. Below it, the data is consistent with a purely classical strategy and no secret key can be certified.

Why this is deeper than BB84

In BB84 the devices are trusted: security follows from the assumed quantum optics of well-behaved preparations and measurements. Bell-violation security depends only on the observed correlations, not on what is inside the boxes. That is the conceptual seed of device-independent QKD, where even adversarially manufactured hardware cannot fake a genuine violation — the subject of a later lesson.

Sign in on the full site to ask questions and join the discussion.