Reuse & Permissions

It is not necessary to obtain permission to reuse this article or its components as it is available under the terms of the Creative Commons Attribution 4.0 International license. This license permits unrestricted use, distribution, and reproduction in any medium, provided attribution to the author(s) and the published article's title, journal citation, and DOI are maintained. Please note that some figures may have been included with permission from other third parties. It is your responsibility to obtain the proper permission from the rights holder directly for these figures.

Export citation

Export citation

Choose format for download:

Download Citation
  • Open Access

Generalized Rényi Entropy Accumulation Theorem and Generalized Quantum Probability Estimation

Amir Arqand1, Thomas A. Hahn2, and Ernest Y.-Z. Tan1

Phys. Rev. X 15, 041013 – Published 28 October, 2025

DOI: https://doi.org/10.1103/pgrn-mz9j

Abstract

The entropy accumulation theorem—and its subsequent generalized version—is a powerful tool in the security analysis of many device-dependent and device-independent cryptography protocols. However, it has the drawback that the finite-size bounds it yields are not necessarily optimal; furthermore, it relies on the construction of an affine min-tradeoff function, which can often be challenging to construct optimally in practice. In this work, we address both of these challenges simultaneously by deriving a new entropy accumulation bound. Our bound yields significantly better finite-size performance and can be computed as an intuitively interpretable convex optimization, without any specification of affine min-tradeoff functions. Furthermore, it can be applied directly at the level of Rényi entropies if desired, yielding fully-Rényi security proofs. Our proof techniques are based on elaborating on a connection between entropy accumulation and the frameworks of quantum probability estimation or f-weighted Rényi entropies; in the process, we obtain some new results with respect to those frameworks as well. In particular, those findings imply that our bounds apply to prepare-and-measure protocols without the virtual tomography procedures or repetition-rate restrictions previously required for entropy accumulation.

View figure in article

Physics Subject Headings (PhySH)

Popular Summary

Article Text

References (113)

  1. F. Dupuis, O. Fawzi, and R. Renner, Entropy accumulation, Commun. Math. Phys. 379, 867 (2020).
  2. F. Dupuis and O. Fawzi, Entropy accumulation with improved second-order term, IEEE Trans. Inf. Theory 65, 7596 (2019).
  3. T. Metger, O. Fawzi, D. Sutter, and R. Renner, Generalised entropy accumulation, in 2022 IEEE 63rd Annual Symposium on Foundations of Computer Science (FOCS) (2022), pp. 844–850, 10.1109/FOCS54457.2022.00085.
  4. T. Metger, O. Fawzi, D. Sutter, and R. Renner, Generalised entropy accumulation, Commun. Math. Phys. 405, 261 (2024).
  5. I. George, J. Lin, T. van Himbeeck, K. Fang, and N. Lütkenhaus, Finite-key analysis of quantum key distribution with characterized devices using entropy accumulation, arXiv:2203.06554v1.
  6. M. Tomamichel and A. Leverrier, A largely self-contained and complete security proof for quantum key distribution, Quantum 1, 14 (2017).
  7. Charles Ci-Wen Lim, F. Xu, J.-W. Pan, and A. Ekert, Security analysis of quantum key distribution with small block length and its application to quantum space communications, Phys. Rev. Lett. 126, 100501 (2021).
  8. While intermediate steps in the entropy accumulation proofs of Refs. [1, 2, 4] involve bounds of a roughly similar form, the critical difference is that, in those bounds, the value on the right-hand side is a minimization over all possible single-round states, which results in trivial bounds if directly applied in a protocol.

  9. In fact, the [α/(α−1)]log[1/(Pr[Ω])] term does not affect the final key rates in sufficiently “simple” protocols, as discussed in Refs. [10, 11]; however, other O(1) corrections arise when considering, e.g., privacy amplification theorems.

  10. F. Dupuis, Privacy amplification and decoupling without smoothing, IEEE Trans. Inf. Theory 69, 7784 (2023).
  11. L. Kamin, A. Arqand, I. George, N. Lütkenhaus, and Ernest Y.-Z. Tan, Finite-size analysis of prepare-and-measure and decoy-state quantum key distribution via entropy accumulation, PRX Quantum 6, 020342 (2025).
  12. S. Pironio and S. Massar, Security of practical private randomness generation, Phys. Rev. A 87, 012336 (2013).
  13. R. Jain, C. A. Miller, and Y. Shi, Parallel device-independent quantum key distribution, IEEE Trans. Inf. Theory 66, 5567 (2020).
  14. T. Vidick, Parallel DIQKD from parallel repetition, arXiv:1703.08508.
  15. R. Jain and S. Kundu, A direct product theorem for quantum communication complexity with applications to device-independent cryptography, SIAM J. Comput. 54, 964 (2025).
  16. A caveat here is that if the security proof uses a constant Rényi parameter independent of n, then the hα^ term in our result is also independent of n—thus, even at large n, it does not converge to exactly the minimum Rényi entropy over single-round states compatible with the accept condition. This finding likely reflects the general principle that Rényi entropies have “worse” chain rules as compared to von Neumann entropy. However, for the purposes of security proofs, we can overcome this issue in various ways by tuning the Rényi parameters as a function of n; we discuss this case further in Sec. 7c.

  17. T. van Himbeeck and P. Brown, Tight and general finite-size security of quantum key distribution (2025), presented at QCrypt 2023 and QIP 2024 (to be published).
  18. Y. Zhang, H. Fu, and E. Knill, Efficient randomness certification by quantum probability estimation, Phys. Rev. Res. 2, 013016 (2020).
  19. R. Arnon-Friedman and J.-D. Bancal, Device-independent certification of one-shot distillable entanglement, New J. Phys. 21, 033010 (2019).
  20. S. Bäuml, C. Pascual-García, V. Wright, O. Fawzi, and A. Acín, Security of discrete-modulated continuous-variable quantum key distribution, Quantum 8, 1418 (2024).
  21. T. Metger and R. Renner, Security of quantum key distribution from generalised entropy accumulation, Nat. Commun. 14, 1 (2023).
  22. C. H. Bennett, G. Brassard, and N. D. Mermin, Quantum cryptography without Bell’s theorem, Phys. Rev. Lett. 68, 557 (1992).
  23. A. Ferenczi and N. Lütkenhaus, Symmetries in quantum key distribution and the connection between optimal attacks and optimal cloning, Phys. Rev. A 85, 052310 (2012).
  24. R. Renner, Security of quantum key distribution, Ph.D. thesis, Swiss Federal Institute of Technology Zurich (ETH Zurich), 2005, diss. ETH No. 16242.
  25. M. A. Nielsen and I. L. Chuang, Quantum Computation and Quantum Information (Cambridge University Press, New York, 2010).
  26. S. Boyd and L. Vandenberghe, Convex Optimization (Cambridge University Press, Cambridge, England, 2004).
  27. H.-K. Lo, M. Curty, and B. Qi, Measurement-device-independent quantum key distribution, Phys. Rev. Lett. 108, 130503 (2012).
  28. J. Lin and N. Lütkenhaus, Simple security analysis of phase-matching measurement-device-independent quantum key distribution, Phys. Rev. A 98, 042332 (2018).
  29. R. Arnon-Friedman, R. Renner, and T. Vidick, Simple and tight device-independent security proofs, SIAM J. Comput. 48, 181 (2019).
  30. M. Tomamichel, Quantum Information Processing with Finite Resources (Springer International Publishing, New York, 2016).
  31. R. L. Frank and E. H. Lieb, Monotonicity of a relative Rényi entropy, J. Math. Phys. (N.Y.) 54, 122201 (2013).
  32. M. Müller-Lennert, F. Dupuis, O. Szehr, S. Fehr, and M. Tomamichel, On quantum Rényi entropies: A new generalization and some properties, J. Math. Phys. (N.Y.) 54, 122203 (2013).
  33. S. Beigi, Sandwiched Rényi divergence satisfies data processing inequality, J. Math. Phys. (N.Y.) 54, 122202 (2013).
  34. M. Mosonyi and T. Ogawa, Quantum hypothesis testing and the operational interpretation of the quantum Rényi relative entropies, Commun. Math. Phys. 334, 1617 (2014).
  35. In that model, the En register will usually also contain a copy of C^1n, but this does not affect any of the final bounds.

  36. E. Y.-Z. Tan, P. Sekatski, J.-D. Bancal, R. Schwonnek, R. Renner, N. Sangouard, and C. C.-W. Lim, Improved DIQKD protocols with finite-size analysis, Quantum 6, 880 (2022).
  37. E. Cervero-Martín and M. Tomamichel, Device independent security of quantum key distribution from monogamy-of-entanglement games, Quantum 9, 1652 (2025).
  38. This definition could likely be extended to α∈{0,1,∞} by taking the respective limits. However, our subsequent discussions suggest that, for instance, the α=∞ case would essentially correspond to H∞ conditional entropies, which are simply zero in many circumstances (unlike H∞↑) and hence unlikely to be of much interest. Furthermore, in Theorem V.1, the [1/(α^−1)] factor would be zero at α^=∞, which makes the result somewhat trivial; see the discussion in Sec. 5b.

  39. Earlier versions of this work referred to Hαf as a QES entropy; we have chosen to update the terminology to bring it more in line with Ref. [17].

  40. There is no danger of ambiguity in having used ρ to denote all states in this lemma since a read-and-prepare channel always simply extends a state without “disturbing” any registers.

  41. In fact, this M term can be entirely avoided if we first use the “normalization property” in Lemma IV.7 below to shift all the f values to negative values, allowing us to choose M=0. Alternatively, M=0 could be achieved by modifying our construction to instead follow Ref. [1] and generate a pair of quantum registers DD¯, and then use the fact that Hα(D|D¯) can be assigned negative values to obtain Hα(DQC¯|D¯C^Q′)ρ=Hαf(QC¯|C^Q′)ρ. However, in that case, it might not straightforwardly hold that Hα(D|D¯)=Hα↑(D|D¯).

  42. F. Dupuis, Chain rules for quantum Rényi entropies, J. Math. Phys. (N.Y.) 56, 022203 (2015).
  43. It may appear strange to make the Q register trivial since, in some protocols, it corresponds to the raw “secret data,” but the idea is that in Ref. [18] and follow-up works, the QEF analysis is applied in such a way that the C¯ register itself contains all the raw “secret data.” Our results can be viewed as slightly extending their approach by also allowing for an additional, possibly quantum Q (for the case where Q is classical, it can still be basically accommodated in their approach by incorporating it into the C¯ register but choosing a QES/QEF that is independent of its value).

  44. To avoid potential confusion, we highlight that, for each j, we have multiple different QESs, which are indexed by the values c¯1j−1c^1j−1. We also highlight that each such QES is a function on the alphabet of C¯jC^j only not the “preceding” registers C¯1j−1C^1j−1. Of course, by the equivalence between k-tuples and functions on a discrete set of size k, in principle, we could view the tuple of values {f|c¯1j−1c^1j−1(c¯jc^j)}c¯1jc^1j as being a function on the alphabet of C¯1jC^1j, but for this theorem statement, it is more convenient to use the presented form. (In other contexts, it can be convenient to view it as such a function, but we defer that discussion to later work.)

  45. M. Berta, O. Fawzi, and M. Tomamichel, On variational expressions for quantum relative entropies, Lett. Math. Phys. 107, 2239 (2017).
  46. W.-Z. Liu, M.-H. Li, S. Ragy, S.-R. Zhao, B. Bai, Y. Liu, P. J. Brown, J. Zhang, R. Colbeck, J. Fan, Q. Zhang, and J.-W. Pan, Device-independent randomness expansion against quantum side information, Nat. Phys. 17, 448 (2021).
  47. While the resulting lower bound on Hα′f^full(S1n|C¯1nC^1nEn)ρ is not zero, this is easily addressed by either using Lemma IV.7 to “normalize” the lower bound to zero or, equivalently, just modifying the analysis to hash to a shorter key.

  48. We write this condition in this form to highlight that Ω does not have to be an event defined entirely on the state ρ itself, which allows more flexibility in applications. This is also why we use a separate symbol Ω˜ to denote the set of values c¯1nc^1n such that ρ|Ω(c¯1nc^1n)>0.

  49. Strictly speaking, the convex range is not fully defined by only the channels Ej since one also has to specify the various embeddings. However, all of our subsequent results hold for any choice of embeddings, so we will usually not specify this explicitly.

  50. The potential exception here would be for protocols where one has a priori knowledge that some rounds would behave differently from others, for instance, in satellite QKD where the photon losses are likely to vary over the course of the protocol. In that case, there are potential benefits to be gained from the more general “adaptive” analysis described in the previous section, though, as mentioned, such an analysis would be more elaborate than the results we present in this section.

  51. This assumption does not affect its applicability to DI security proofs (at least, assuming that the dimensions are finite but unbounded) because, in such security proofs, we can suppose that M acts on systems of finite but unknown dimension and say that the bounds we derive are independent of this dimension and hence valid for any such M [36].

  52. A. Winick, N. Lütkenhaus, and P. J. Coles, Reliable numerical key rates for quantum key distribution, Quantum 2, 77 (2018).
  53. In fact, rather than Hα′ specifically, for the purposes of this argument, we can discuss any Rényi entropy H satisfying Hmin≤H≤H because, for any classical-quantum state ρCQ, we have H(C|Q)ρ=0 for some such H if and only if H(C|Q)ρ=0 for all such H [since H(C|Q)ρ=0 implies Hmin(C|Q)ρ=0, which implies the conditional states ρQ|c are all perfectly distinguishable and hence H(C|Q)ρ=0 as well].

  54. Technically, to complete the argument we must rule out the possibility of a sequence of feasible values limiting to zero. To do so, we can follow the steps described in the proof of Lemma V.4 to replace SΩ with its closure by a continuity argument, in which case, for finite-dimensional Q˜, we obtain a continuous optimization over a compact set and hence the infimum is attained (and hence strictly positive). An alternative prospect is to introduce another convex optimization infq∈SΩinfω∈S=(Q˜)Hα′(SC¯|C^EE˜)νω subject to the constraint ∥q−νC¯C^ω∥1≤δ, which matches the “simplistic” optimization in Eq. (83) when picking δ=0. It seems likely that one could prove the optimal value of this optimization is continuous with respect to δ≥0 (for instance, by modifying the arguments in Ref. [55]); if so, then, by continuity, there exists some δ⋆>0 such that this optimization is lower bounded by, say, h⋆/2. Thus, we can conclude the desired property that every feasible (q,ω) in our bound Eq. (82) is bounded away from zero since for every such point we either have ∥q−νC¯C^ω∥1≤δ⋆ and thus Hα′(SC¯|C^EE˜)νω≥h⋆/2>0 or D(q∥νC¯C^ω)≥δ⋆2/(2ln2)>0 by Pinsker’s inequality. This prospective approach has the advantage that, in the DI case, it seems plausible that we still have continuity with respect to δ even after later proof steps where we further minimize over the GEATT channels themselves (to accommodate all possible measurements and dimensions). However, we leave a rigorous proof of these continuity claims for future work since here we only aim to give a plausibility argument that hα^ is “usually” nonzero.

  55. R. J. Duffin, Clark’s Theorem on linear programs holds for convex programs, Proc. Natl. Acad. Sci. U.S.A. 75, 1624 (1978).
  56. S. Pironio, A. Acín, S. Massar, A. B. de la Giroday, D. N. Matsukevich, P. Maunz, S. Olmschenk, D. Hayes, L. Luo, T. A. Manning, and C. Monroe, Random numbers certified by Bell’s theorem, Nature (London) 464, 1021 (2010).
  57. L. Masanes, S. Pironio, and A. Acín, Secure device-independent quantum key distribution with causally independent measurement devices, Nat. Commun. 2, 238 (2011).
  58. G. Murta, S. B. van Dam, J. Ribeiro, R. Hanson, and S. Wehner, Towards a realization of device-independent quantum key distribution, Quantum Sci. Technol. 4, 035011 (2019).
  59. The latter bound holds whenever C¯ has the property that it can be “projectively reconstructed” from SC^E in the sense of Lemma B.7 of Ref. [1], by simply observing that, in that case, the lemma gives us Hα(SC¯|C^EE˜)=Hα(S|C^EE˜) and H(SC¯|C^EE˜)=H(S|C^EE˜), so we can apply the continuity bound of Lemma B.9 of Ref. [1] without including C¯.

  60. Similar to Ref. [2], this choice is just to demonstrate a possible scaling; for the best finite-size bounds, one should optimize the Rényi parameter choices numerically for each n.

  61. One can tune α′ and α′′ in other ways; e.g., if we fix one as a constant and set the other to 1+μ, then we can obtain α^,α=1+μ+O(μ2), but this approach sacrifices the option to bring the constant one closer to 1.

  62. We highlight that this loss comes inherently from the Lemma V.1 bound rather than the subsequent bound in Eq. (92) since the latter is an equality in such scenarios.

  63. T. A. Hahn, E. Y.-Z. Tan, and P. Brown, Bounds on Petz-Rényi divergences and their applications for device-independent cryptography, arXiv:2408.12313v1.
  64. Alternatively, one can directly show that this expression is jointly convex in (t,ν˘ω(c¯c^)) by using the fact that the function xlog(x/y) is jointly convex on (x,y)∈R≥02. However, this case ignores any “coupling” with the prefactors of the entropy terms in, e.g., Lemma V.1.

  65. This claim is, in fact, somewhat delicate. First, note that for n IID instances of a Bernoulli random variable with expectation pexp, if we write the observed success frequency as Qobs, then the probability that |Qobs−pexp| exceeds some value δ can be shown to be at most 2e−δ2n3pexp by a Chernoff bound argument. Thus (focusing only on the ⊥⊥ term and ignoring contributions from other test-round outcomes), we can choose δγ=δγ′=(3γ/n)log(2/ϵcom) while still ensuring an accept probability of at least 1−O(ϵcom) on honest IID behavior (by applying the Chernoff bound argument with pexp=γ, viewing a single-round “success” as the event that ⊥⊥ did not occur). In that case, if we pick the scaling of γ with n to be any function that goes to zero more slowly than 1/n (as is indeed the case in the subsequent analysis), we see that δγ and δγ′ would indeed become arbitrarily small compared to γ. However, if we pick γ∝1/n exactly, this argument does not work, just as in Ref. [2]. We leave a more detailed analysis [perhaps preserving the D(r∥s) term to avoid invoking an explicit lower bound on γq] for future work.

  66. The KL divergence term is already convex, so it suffices to show convexity of this entropy term alone. Still, it is true that, in principle, there may be situations where the sum of the KL divergence term and entropy term is convex even if the latter is not convex by itself—considering this possibility might help in tackling the issue we shall shortly discuss regarding the full linear combination ∑c¯c^q(c¯c^)H(S|EE˜)ν|c¯c^ω. However, we leave this more elaborate possibility for future work, if it is relevant.

  67. If Z and G are not trace preserving, care is needed to ensure consistency with the definition in Eq. (16) we chose here for Umegaki divergence.

  68. Note that in the Gα,ρ* formula, the first case can still take a value +∞ for some values of λ due to the D(λ∥ρC¯C^) term. Specifically, this happens whenever supp(λ)⊆supp(ρC¯C^).

  69. In this lemma, Lagrange dual problems are defined in the sense described in, e.g., Ref. [26]. Since the constraints are equality constraints, there is an arbitrary sign convention to pick when defining the dual variables; see the last line of Eq. (112) for the sign convention we used.

  70. In this paragraph, we informally refer to “the” best choice of f, though this is technically a misnomer because it is necessarily nonunique—given any QES f in Corollary V.1, inspecting the bound shows that f+κ for any κ∈R yields an identical bound since the κ dependence “cancels off.” (Loosely speaking, this nonuniqueness seems to arise from the implicit normalization constraint in the domains SΩ and PC¯C^, though we leave further analysis for future work.) Furthermore, it might potentially be possible that the optimal f is not attained, as we discuss later. However, this nonuniqueness or nonattainability does not have any effects on our actual proofs of Lemma V.4 or Theorem V.1; we are merely highlighting a technicality in our informal statements here.

  71. For our proofs, let us say continuity and closedness are defined with respect to the topology induced by, say, the 1-norm.

  72. This is because we have argued above that the expressions in Eqs. (78) and (79) are equal for any choice of purifying function, which means that the latter is independent of the choice of purifying function. Thus, we can focus on any specific choice without loss of generality; in particular, under the finite-dimensionality assumption, we can pick the one shown in Eq. (29), which is indeed continuous (this can be seen by, e.g., computing the fidelity between purifications of δ-close states under that formula and then applying Fuchs–van de Graaf to convert to 1-norm distance).

  73. An alternative approach, similar to the convexity argument above: After noting that νω is continuous in ω, observe that Gα^,νω(f)=−Hα^f(SC¯|C^EE˜)νω=M−Hα^(DSC¯|C^EE˜)νω for a suitable extending channel as defined in Lemma IV.1, so Gα^,νω(f) is continuous in ω (by the continuity of conditional Rényi entropy with respect to the state). This implies that Gα^,νω*(λ) is lower semicontinuous with respect to (λ,ω) since it is a supremum over a family of functions λ·f−Gα^,νω(f) that are each lower semicontinuous with respect to (λ,ω). Thus, we have lower semicontinuity of Gα^,νω*(λ)+(q−λ)·f with respect to (q,λ,ω), which suffices to apply the version of our subsequent argument based on Sion’s minimax theorem (which only requires semicontinuity rather than continuity).

  74. S. Khatri and M. M. Wilde, Principles of quantum communication theory: A modern approach, arXiv:2011.04672.
  75. The registers A˜ in these statements are intended to include shield systems as well, if required by the security proof.

  76. While we also applied Lemma B.5 of Ref. [1] to account for conditioning on Ω, note that when applying the Rényi privacy amplification theorem of Ref. [10], the [α/(α−1)]log[1/(Pr[Ω])] term essentially does not affect the final key rates—see, e.g., Refs. [10, 11] or Secs. 7b and 7c of this work.

  77. M. Tomamichel, M. Berta, and M. Hayashi, Relating different quantum generalizations of the conditional Rényi entropy, J. Math. Phys. (N.Y.) 55, 082206 (2014).
  78. Since the test rounds are only measured in the X basis, in this formula, we could instead view Qthresh as only being the “phase error rate” rather than the QBER with respect to multiple bases. However, since the error-correction term λEC instead depends on error rates in generation rounds (i.e., the Z-basis error rate), for simplicity, in this analysis we view Qthresh as a single QBER parameter that characterizes error rates in any basis; thus, we can use it in the formula in Eq. (133) for λEC.

  79. M. Berta, M. Christandl, R. Colbeck, J. M. Renes, and R. Renner, The uncertainty principle in the presence of quantum memory, Nat. Phys. 6, 659 (2010).
  80. In other words, after they have XOR’d their outcomes with the symmetrization bit F. Note that, strictly speaking, in order to apply EURs to the values S, X, and X˜ (which are produced after symmetrization, i.e., not the raw outcomes of X or Z measurements), we are implicitly applying a standard argument [81] that the same overall state (including all side information) could instead be produced by just taking the raw outcomes of measurements on some other initial state, essentially by “commuting” the symmetrization with the measurements by reexpressing it as a rotation on the premeasurement qubits. An alternative option would be to omit the symmetrization step and instead use, e.g., Fano’s inequality to write H(X|X˜)ν|C^≠⊥≤hbin(Pr[X≠X˜]|C^≠⊥) for the purposes of the bound in Eq. (135), but this would require more steps to extend to the Rényi EUR bound in Eq. (142).

  81. R. Renner, N. Gisin, and B. Kraus, Information-theoretic security proof for quantum-key-distribution protocols, Phys. Rev. A 72, 012332 (2005).
  82. Note that this event is a stricter condition than just the acceptance test accepting (which would be the event freqc^1n∈SΩ), so it remains the case that every distribution c^1n with nonzero probability in the conditional state ρ|Ω satisfies freqc^1n∈SΩ; i.e., the first condition on SΩ in Theorem V.1 indeed holds. Also note that we are implicitly exploiting the fact that, in Theorem V.1, Ω does not have to be an event defined entirely on the C^1n registers, as discussed in Corollary IV.1.

  83. The parameter ϵEV here is denoted as ϵKV in Ref. [21]; we have used different notation simply because we refer to the relevant step as “error verification” instead of “key validation.”

  84. C. Portmann and R. Renner, Security in quantum cryptography, Rev. Mod. Phys. 94, 025008 (2022).
  85. To obtain this result, we have basically added the correctness and secrecy parameters from Ref. [21], except that the secrecy parameter in that work is rescaled by a factor of 2 as compared to Refs. [6, 84], so we have first adjusted it accordingly. We have also removed the dependence of the secrecy parameter in that work on ϵEV because, for our protocol, we perform the acceptance test directly on the C^1n registers rather than guessing; see Ref. [11].

  86. S. Arimoto, Information measures and capacity of order alpha for discrete memoryless channels, Topics Inf. Theor. 17, 41 (1977), https://cir.nii.ac.jp/crid/1570854175661265024.
  87. It would have been cleaner if we could directly “accumulate” H∞↑; however, it can be seen that our bounds for the EAT or GEAT scenarios involve Hα rather than Hα↑ in the single-round terms, and therefore, we cannot directly make use of a bound on single-round H∞↑ without first converting it to H2. (For the Ref. [17] scenario though, the bounds we presented in Sec. 6b are indeed based on single-round Hα↑, which would indeed allow us to directly accumulate min-entropy.) In any case, for the CHSH game, in particular, Ref. [58] showed that the bound in Eq. (148) is, in fact, tight for both H2 and H∞↑, so there is no loss of tightness in considering the former instead for this particular protocol.

  88. Again, we could instead convert to Hminϵs and apply the corresponding privacy amplification theorem (under the current state of results in privacy amplification, this may be necessary if the protocol uses Trevisan’s extractor instead of 2-universal hashing). However, in that case, we find no improvement in nmin over Eq. (150), though we can at least obtain about nmin=3×1010, which is still better than Ref. [46]. The issue basically seems to be that, for security proofs based on our Hminϵs bound rather than our Hα↑ bound, one has to pick a “threshold” value ϵa and split the analysis into cases where pΩ is above or below ϵa; this introduces additional finite-size corrections, and the resulting ℓkey formula then fails to reduce to Eq. (150) in the α→2 limit.

  89. In fact, another potential question is whether we would actually obtain better nmin values via this von Neumann entropy approach; we leave this question for future work. One point that may be worth highlighting is that, similar to the advantage of Eq. (143) over Eq. (136) in the previous section, working with the collision-entropy bound in Eq. (148) ensures that the optimization for the “first-order term” always returns a strictly positive value, unlike the relaxation to von Neumann entropy via the continuity bound in Eq. (86), which may yield a negative value if α′ is not sufficiently close to 1. Hence, it seems likely that the collision-entropy approach will indeed be better for small n, where the optimal Rényi parameters are further from 1.

  90. D. Tupkary, Ernest Y.-Z. Tan, and N. Lütkenhaus, Security proof for variable-length quantum key distribution, Phys. Rev. Res. 6, 023002 (2024).
  91. M. Christandl, R. König, and R. Renner, Postselection technique for quantum channels with applications to quantum cryptography, Phys. Rev. Lett. 102, 020504 (2009).
  92. S. Nahar, D. Tupkary, Y. Zhao, N. Lütkenhaus, and Ernest Y.-Z. Tan, Postselection technique for optical quantum key distribution with improved de Finetti reductions, PRX Quantum 5, 040315 (2024).
  93. For readers familiar with Ref. [90], we highlight that, in principle, Theorem V.1 in this work could be used to bound the Rényi entropy conditioned on any particular frequency distribution observed on the C¯1nC^1n registers, which roughly satisfies the requirements for applying the analysis in Ref. [90], except that the bound has an explicit dependence on pΩ. Therefore, a direct calculation along the same lines as in that work would result in the final security parameter being multiplied by the number of possible frequency distributions. This result is somewhat undesirable; however, in principle, it is described by a combinatorial coefficient that “only” increases polynomially in n. This outcome may be tolerable in practice, as suggested by proofs based on the postselection technique that introduce such polynomial factors [91, 92], albeit based on the dimensions of the quantum systems rather than the classical outcomes (the approach suggested here would hence be superior to the postselection technique for DI protocols or other contexts where the dimension dependence is improved via this approach).

  94. We could obtain a similar result by instead using the chain rule from Ref. [42] here to extract a H1/2↑(Z1n|T1n)ρ|Ω term, but this would have a (fairly minor) disadvantage of causing a small “higher-order” change in Rényi parameter, comparable to Eq. (64). Note that even with this, our approach would still differ slightly from Ref. [5] due to how we bound the H1/2↑(Z1n|T1n)ρ|Ω term in the subsequent steps.

  95. Furthermore, in our bound the subtracted term simply has the form γmaxnlog|Z|, where γmax only needs to be chosen to be sufficiently large for the honest IID behavior to accept with high probability. In comparison, the subtracted terms in Refs. [5, 29, 36, 58] were roughly of the form γnlog|Z|+O(n), where the O(n) term accommodated potential non-IID behavior. It seems likely that the former value is smaller, though we do not aim to prove this rigorously. (We briefly highlight, however, that Ref. [37] introduced an approach in which the subtracted term was also roughly of the form γmaxnlog|Z|, though there was still a change of smoothing parameter.)

  96. While Nj performs a pinching channel on C¯1j−1C^1j−1 in contrast to Mj, which acts as an identity on those registers, it does not make a difference for states produced by applying those channels in sequence because Nj−1∘…∘N1[ω0] is always already classical on C¯1j−1C^1j−1. Similarly, the second and third steps performed by Nj do not disturb the classical registers they act on.

  97. In this step, let us take E˜ to be of large enough dimension to be a purifying register for the input registers in the Nj scenario as well, which can be achieved without loss of generality by expanding its dimension as necessary.

  98. For strict technical accuracy in the following steps, these conditional states should be interpreted to still include the registers C¯1j−1C^1j−1, though with those registers simply taking the fixed value c¯1j−1c^1j−1.

  99. While the QES f|c¯1j−1c^1j−1 depends on c¯1j−1c^1j−1, its value is fixed by the initial choices in the theorem, not by the state.

  100. Pedantically, to ensure there are no issues involving the dependence of the summation domain in Eq. (b28) on ω, we should first note that we can extend the summation domain to the full alphabet C¯×C^ without changing the value of Gα′,α′′,νω(f) (in this case, there are no divergence terms in the sum, so we do not encounter any technical issues).

  101. An alternative approach for the purposes of our analysis would be to simply restrict the alphabet of the registers C¯C^ to CM rather than C¯×C^ since the values outside CM will never occur and thus have no “physical relevance.” However, this approach would result in the slightly unpleasant side effect that the resulting alphabet is not guaranteed to have a Cartesian-product form.

  102. An alternative option is as follows: Since the mapping ω→νC¯C^ω is a quantum-to-classical channel, one can show that it must be of the form ω→∑c¯c^TrΓc¯c^ω[|c¯c^⟩⟨c¯c^|] for some POVM elements Γc¯c^; furthermore, we must have Γc¯c^≠0 for all c¯c^∉CM. Thus, we can show that any full-support ωQ˜ yields a distribution νC¯C^ω with full support on CM (at least assuming countable dimensions; the argument should generalize further in some fashion but we do not consider this here), giving the desired result.

  103. Here, we did not simply try to apply Slater’s condition to the original constrained optimization in Eq. (109) because it would require the existence of some ω in the relative interior of the effective domain of Gα^,νω*(λ) (i.e., the domain on which it takes finite values), which is more subtle in the infinite-dimensional case. However, for the finite-dimensional case, in our above proof of the finiteness of Jα^, we argued that Gα^,νω*(λ) is finite over all full-support ω, and hence any full-support ω yields such an interior point.

  104. However, this proof method still does not immediately certify dual attainment, despite using Slater’s condition, because, when transforming the optimizations, we only focused on preserving the optimal value rather than other properties such as dual attainment. We leave a more extensive analysis of such aspects for future work, if it should become important.

  105. For the c¯c^∉CM terms, there is no need to include any “δ tolerances” here because zero-probability events (on a finite alphabet) would never occur. There is a technical issue that the supporting alphabets induced by Mj versus M might be different, in principle, but we do not expect this situation to arise in practice.

  106. The data-processing inequality for Petz entropies is usually only stated for α∈(0,2]; here, we extend it to α=0 by noting that, by definition, the value of D¯0 is given by the α→0 limit, and thus we indeed have D¯0(ρ∥σ)−D¯0(E[ρ]∥E[σ])=limα→0(D¯α(ρ∥σ)−D¯α(E[ρ]∥E[σ]))≥0.

  107. Qualitatively, this condition states that Vj does not signal from Ej−1 to RjC¯jC^jFj. Also note that the choice of Stinespring dilation can be arbitrary here due to isometric equivalence of purifications.

  108. Formally, this means we suppose that Ej is isomorphic to C^jTjEj−1, so we can define an “identity channel” idC^jTjEj−1→Ej and say that Mj has the form idC^jTjEj−1→Ej∘M˜j for some M˜j:  Rj−1→SjC¯jC^jTjRj.

  109. For instance, it seems potentially useful to instead consider Hβ^(DjSjC¯¯j|C¯1j−1C^1j−1RjF1jG1jE˜)ν′ in Eq. (e12) and then try to lower bound it with minc¯1j−1c^1j−1Hβ^(DjSjC¯¯j|RjF1jG1jE˜)ν|c¯1j−1c^1j−1′, but the issue is that C¯1j−1C^1j−1 might not be classical in the state νDjSjC¯¯jC¯1j−1C^1j−1RjF1jG1jE˜′, and hence ν|c¯1j−1c^1j−1′ is less easily defined.

  110. A. Marwah and F. Dupuis, Smooth min-entropy lower bounds for approximation chains, Commun. Math. Phys. 405, 211 (2024).
  111. Strictly speaking, that result is only stated for β∈(0,∞), but we can first suppose that α>1/2 so that β<∞; then, to obtain our desired result for α=1/2, we can take the α→1/2 limit at the end, exploiting continuity of the sandwiched Rényi divergences with respect to α (Corollary 4.2 of Ref. [30] together with the fact that convex functions are continuous on the interior of their domain).

  112. N. Datta, Min- and max-relative entropies and a new entanglement monotone, IEEE Trans. Inf. Theory 55, 2816 (2009).
  113. Technically, for β>1 (i.e., α<1), we have supp(ρA1C)⊆supp(IA1⊗σC) since, by definition, the state σ satisfies Dβ(ρA1C∥IA1⊗σC)≤Dβ(ρA1C∥IA1⊗ρC)<+∞. From the definition of νA1C, it can then be seen that, in fact, supp(ρA1C) and supp(νA1C) are equal in this case; thus, the implication indeed holds in both directions, and we obtain the equality H∞(A2|A1C)ν=H∞(A2|A1C)ρ. However, this argument seems less straightforward to generalize to the β<1 regime, where Dβ(ρA1C∥IA1⊗σC)<+∞ does not imply supp(ρA1C)⊆supp(IA1⊗σC); in fact, in that regime, we generally have supp(σC)⊆supp(ρC) instead (Sec. III B in Ref. [32]).

Outline

Information

Sign In to Your Journals Account

Filter

Filter

Article Lookup

Enter a citation