Superactivation of distillable secret key
- Fields
- Topics
Problem
Can two bipartite quantum states with zero distillable secret key yield positive distillable secret key when used jointly? Let \(\rho_{AB}\) and \(\sigma_{A'B'}\) be arbitrary finite-dimensional bipartite quantum states. For a state \(\omega\), let \(K_D(\omega)\) denote its asymptotic distillable secret key, in secret bits per copy. Alice and Bob may apply arbitrary local quantum operations to \(\omega^{\otimes n}\) and use unlimited authenticated two-way public communication; Eve holds a purification of \(\omega^{\otimes n}\) and receives the entire public transcript. A rate is achievable when the joint state of Alice’s key, Bob’s key, and Eve’s systems converges in trace distance to that of identical, uniformly distributed keys independent of Eve, and \(K_D(\omega)\) is the supremum of achievable rates. No initial secret key of positive rate, entanglement assistance, or catalyst is supplied. The question is whether there is a pair satisfying
where the joint rate in Eq. (1) is taken across the bipartition \(AA':BB'\).
Source
Horodecki, Sikorski, Das, and Wilde explicitly state in Sec. 1 that it remains open whether entangled but key-undistillable states exist, and in Sec. 13 describe their results as assuming faithfulness of distillable key [HSDW26]. The question in Eq. (1) is derived from that documented gap as a question about tensor-product closure of the zero-key set; it is not stated verbatim in the cited papers.
Progress
Zero distillable entanglement does not certify zero key. Horodecki, Horodecki, Horodecki, and Oppenheim construct bound-entangled states \(\omega\) with positive partial transpose for which
\begin{equation} D_{\leftrightarrow}(\omega)=0<K_D(\omega), \tag{2} \end{equation}where \(D_{\leftrightarrow}\) is the two-way LOCC distillable entanglement [HHHO05]. By Eq. (2), neither bound entanglement nor positivity of the partial transpose alone makes a factor in Eq. (1) key-undistillable.
Let Alice measure her share of a purification of \(\omega_{AB}\), producing a classical–quantum–quantum state \(\eta_{XBE}\) with classical outcome \(X\). The one-way protocol of Devetak and Winter achieves
\begin{equation} K_D(\omega)\geq\max\{0,\,I(X:B)_\eta-I(X:E)_\eta\}, \tag{3} \end{equation}where \(I\) is the quantum mutual information [DW05]. A nonpositive right-hand side in Eq. (3) for a particular measurement gives no upper bound on \(K_D(\omega)\), which optimizes over arbitrary block protocols with two-way public interaction.
Separable states are useless for key distillation, as recalled in Sec. 1 of [HSDW26]. A separable state can be prepared by local operations and public communication, and a purifying adversary can reproduce the announced preparation record, so appending it does not change the key rate:
\begin{equation} K_D(\omega\otimes\tau)=K_D(\omega) \qquad\text{for every }\tau\in\mathrm{SEP}, \tag{4} \end{equation}where \(\mathrm{SEP}\) denotes the separable states on the relevant bipartition. Both factors of any pair satisfying Eq. (1) must therefore be entangled and individually key-undistillable. Eq. (4) is a direct resource-theoretic consequence, not an activation theorem.
Horodecki, Sikorski, Das, and Wilde develop the resource theory of private key under the assumption that distillable key is faithful, and state in Sec. 1 that the following implication remains unresolved [HSDW26]:
\begin{equation} \omega\notin\mathrm{SEP}\quad\Longrightarrow\quad K_D(\omega)>0. \tag{5} \end{equation}If Eq. (5) holds, the zero-key set equals \(\mathrm{SEP}\), which is closed under tensor products, so no pair satisfies Eq. (1). Conversely, a pair satisfying Eq. (1) would disprove Eq. (5). Existence of a single entangled zero-key state would not by itself provide an activating pair.
Comment
The unresolved alternatives are an explicit pair satisfying Eq. (1) or a proof that the set of states with \(K_D=0\) is closed under tensor products. Even the necessary existence of an entangled state with \(K_D=0\) remains open. Activating a particular key-distribution protocol, or increasing the key rate of a state that already has positive key, does not answer the question.
The record Secret key from every entangled state asks whether Eq. (5) holds. An affirmative answer there would rule out the pair sought here, and such a pair would give a negative answer there. The two questions are not claimed to be equivalent: an entangled zero-key state need not activate with any other zero-key state. The record Superactivation of two-way secret-key capacity asks the corresponding question for quantum channels. Literature checked through 15 September 2026.