---
title: List Privacy Amplification (LPA) in QKD
url: https://www.emergentmind.com/topics/list-privacy-amplification-lpa
type: topic
---

# List Privacy Amplification (LPA) in QKD

Searching arXiv for the cited LPA papers to ground the article in current preprint metadata.
List Privacy Amplification (LPA) is a relaxation of the final privacy-amplification step in quantum key distribution (QKD) in which Alice and Bob extract a list of \(L\) candidate keys from a raw string \(X\) correlated with an eavesdropper Eve, with the guarantee that at least one key is perfectly secret while Eve cannot identify which entry is secure [2603.18097]. In the formal setting introduced in “One Key Good, L Keys Better: List Decoding Meets Quantum Privacy Amplification” [2603.18097], LPA preserves the standard adversarial model of privacy amplification with quantum side information, retains smooth min-entropy as the relevant entropy measure, but changes the task from unique-key extraction to list extraction. This relaxation is explicitly compared to the passage from unique decoding to list decoding in coding theory: allowing a short list of outputs exposes an additive \(\log L\) gain in extractable key length [2603.18097]. Related work on list privacy outside QKD studies list-based privacy under utility constraints, but in a different operational model centered on function recoverability rather than composable secret-key extraction [2307.05828].

## 1. Formal definition and ideal functionality

In the LPA setting, after sifting, error correction, and parameter estimation, Alice and Bob share an \(n\)-bit classical string \(X \in \{0,1\}^n\) that is partially known to Eve, who holds a quantum system \(E\) correlated with \(X\). The joint state is a CQ state
\[
\rho_{XE} = \sum_{x \in \{0,1\}^n} p_x\, |x\rangle\!\langle x|_X \otimes \rho_E^x.
\]
Instead of extracting a single secret key, LPA requires that Alice and Bob produce \(L\) candidate keys such that at least one is information-theoretically secret from Eve and Eve cannot determine which one [2603.18097].

The formalization is given in the abstract cryptography framework as a resource construction from a noisy resource \((X,E)\) and an authenticated classical channel to an ideal list-key functionality \(\mathsf{LK}_{L,\ell}\) [2603.18097]. This functionality outputs \(L\) independently uniform \(\ell\)-bit strings \(K_1,\dots,K_L\), chooses a secret index \(I\in[L]\) uniformly at random, gives Alice and Bob the entire list together with \(I\), and gives Eve only the off-list keys \(\{K_j\}_{j\neq I}\), without revealing either \(I\) or \(K_I\) [2603.18097]. When \(L=1\), the functionality reduces exactly to the standard unique-key resource [2603.18097].

The ideal joint state is written as
\[
\rho^{\mathsf{LK} = \frac{1}{L}\sum_{i=1}^L  |i,i\rangle\!\langle i,i|_{A_I B_I} \;\otimes\; \bigotimes_{j=1}^L \tau^{K_j}_{A_j B_j} \;\otimes\; \bigotimes_{j \ne i} \tau^{K_j}_{E},
\]
where each \(\tau^{K_j}\) is maximally mixed on \(\ell\) bits [2603.18097]. The real-world protocol samples \(L\) independent strongly two-universal hash functions \(F_1,\dots,F_L : \{0,1\}^n \to \{0,1\}^\ell\), computes \(K_j = F_j(X)\), and then samples the secret index \(I \sim \mathrm{Unif}([L])\) after hashing and independently of \(X\) and \(E\) [2603.18097].

Security is defined by trace-distance indistinguishability from the ideal list-key resource:
\[
\tfrac12 \bigl\| \rho^\pi_{K_{1:L}, I, E} - \rho^{\mathsf{LK}_{K_{1:L}, I, E} \bigr\|_1 \le \varepsilon.
\]
This list-\(\varepsilon\)-security notion is composable: no environment can distinguish the real protocol from \(\mathsf{LK}_{L,\ell}\) except with advantage \(\varepsilon\) [2603.18097]. Operationally, this means that there is, up to \(\varepsilon\), exactly one index \(I\) for which \(K_I\) is uniform and independent of Eve, while Eve’s view does not reveal which position is the good one [2603.18097].

## 2. Relation to standard privacy amplification and list-based privacy

Standard privacy amplification with a quantum adversary is governed by the Quantum Leftover Hash Lemma (QLHL). For a CQ state \(\rho_{XE}\), a strongly two-universal family \(F\), and \(K=F(X)\), the QLHL states that
\[
\mathbb{E}_F\!\bigl[\tfrac12\|\rho_{K E} - \tau_\ell \otimes \rho_E\|_1\bigr] \le \varepsilon,
\]
provided
\[
\ell \le H_{\min}^\varepsilon(X|E)_{\rho} - 2\log\frac{1}{\varepsilon} - 2.
\]
Thus one may extract approximately \(k - 2\log(1/\varepsilon)\) nearly uniform bits when \(k = H_{\min}^\varepsilon(X|E)\), and this bound is tight in the unique-key setting [2603.18097].

LPA keeps the same adversarial model and the same smooth min-entropy measure, but replaces the requirement of a unique secret output by the weaker requirement that one element of a list be secret and hidden among the other entries [2603.18097]. The comparison to list decoding is explicit: unique decoding outputs a single codeword, list decoding outputs a short list of candidates; analogously, standard privacy amplification outputs one key, whereas LPA outputs a list and thereby exceeds the standard QLHL bound [2603.18097].

The broader notion of list privacy appears in other contexts. “List Privacy Under Function Recoverability” [2307.05828] studies a finite-alphabet setting in which a user releases a randomized response subject to a \(\rho\)-recoverability constraint for a function \(f(X)\), while minimizing the probability that a querier can place \(X\) inside a list of prescribed size \(l\). In that model, the privacy criterion is
\[
\pi_{\rho}^{(l)}(W) \triangleq \min_{g:\,\mathcal{Z}\to\mathcal{L}_l} \Pr\bigl(X \notin g(F(X))\bigr),
\]
and the optimal tradeoff curve is
\[
\pi^{(l)}(\rho) \triangleq \max_{W:\,W(f(x)\mid x)\ge\rho} \pi_{\rho}^{(l)}(W)
\]
[2307.05828]. This is not the same task as LPA in QKD, but it provides a related list-based privacy perspective in which privacy is measured by adversarial list failure under a utility constraint [2307.05828]. A plausible implication is that LPA belongs to a wider family of privacy notions where the object of protection is not unique reconstruction but ambiguity over a small candidate set.

## 3. Quantum List Leftover Hash Lemma

The central theorem of LPA is the Quantum List Leftover Hash Lemma (QLLHL) [2603.18097]. Let
\[
k = H^\varepsilon_{\min}(X|E)_\rho.
\]
If Alice and Bob sample \(L\) independent strongly two-universal hashes \(F_1,\dots,F_L\), define \(K_j = F_j(X)\), and then sample a secret index \(I \sim \mathrm{Unif}([L])\) independently of everything else, then the protocol is list-\(4\varepsilon\)-secure whenever
\[
\ell \le k + \log L - 2\log\frac{1}{\varepsilon} - 3.
\]
This is Theorem 3.1 of [2603.18097]. Relative to the standard QLHL bound
\[
\ell \le k - 2\log(1/\varepsilon) - 2,
\]
the list version yields an additive gain of \(\log L - 1\), with the main asymptotic gain equal to \(\log L\) [2603.18097].

The paper attributes this gain to the hidden index \(I\), which is selected after hashing and is initially hidden from Eve [2603.18097]. The joint variable \((I,K_I)\) derives entropy from both \(X\) and the independent randomness of \(I\), so one obtains schematically
\[
H_{\min}((I,K_I)|E) \gtrsim H_{\min}(X|E) + \log L.
\]
Applying the standard QLHL to the \((\log L+\ell)\)-bit pair \((I,K_I)\) then yields the list-extraction bound [2603.18097]. The paper describes this as the hidden index effectively contributing \(\log L\) bits of entropy [2603.18097].

The result is also accompanied by a converse. Theorem 4.1 of [2603.18097] shows that for any \(k,L,\varepsilon\) there exists a worst-case source \(\rho_{XE}\) for which any list-\(\varepsilon\)-secure protocol must satisfy
\[
\ell \le k + \log L + O(\log(1/\varepsilon)).
\]
The converse uses a syndrome source in which Eve learns a linear projection \(S(X)\) of dimension \(n-k\), leaving \(X\) uniform on a coset of size \(2^k\) [2603.18097]. In that case, conditioning on Eve leaves effective support size at most \(2^k\), and the independent index contributes at most another \(\log L\) [2603.18097]. This establishes that the additive \(\log L\) gain is optimal up to lower-order terms.

## 4. Security interpretation, composability, and authentication

The phrase “at least one key is perfectly secret” has a precise meaning in the ideal functionality \(\mathsf{LK}_{L,\ell}\): the index \(I\) is uniformly random and known only to Alice and Bob, the key \(K_I\) is uniform and independent of Eve’s quantum system \(E\) and all off-list keys, and Eve’s view consists only of \(E\) together with the \(L-1\) off-list keys [2603.18097]. Because the real protocol is \(\varepsilon\)-close to the ideal resource, these properties hold except with probability at most \(\varepsilon\) [2603.18097].

Within abstract cryptography, a protocol \(\pi\) \(\varepsilon\)-constructs an ideal resource \(\mathsf{F}\) if, for every environment \(\mathcal{Z}\),
\[
\left| \Pr[\mathcal{Z}(\pi \circ \mathsf{R})=1] - \Pr[\mathcal{Z}(\mathsf{F})=1] \right| \le \varepsilon.
\]
For LPA, the protocol constructs \(\mathsf{LK}_{L,\ell}\) with error \(4\varepsilon\), and standard composition theorems then imply additive accumulation of failure parameters across error correction, privacy amplification, and authentication [2603.18097]. The total QKD security parameter is written as
\[
\varepsilon_{\text{total} = \varepsilon_{\mathrm{PA} + \varepsilon_{\mathrm{EC} + \varepsilon_{\mathrm{auth},
\]
where \(\varepsilon_{\mathrm{PA}} \approx 4\varepsilon\) comes from list privacy amplification [2603.18097].

After generating the list, Alice must reveal \(I\) to Bob so that both can use the same final key. The paper proposes Wegman–Carter authentication for this step: Alice sends \(I\) together with a MAC tag using a short pre-shared key, and Eve cannot forge or modify \(I\) except with probability \(\varepsilon_{\mathrm{auth}}\) [2603.18097]. The authentication cost is stated as only \(O(\log L + \log(1/\varepsilon_{\mathrm{auth}))\) bits of pre-shared key usage [2603.18097]. Once \(I\) is authenticated, both parties use \(K_I\) as an ordinary unique secret key, and the list structure disappears for subsequent cryptographic use [2603.18097]. This is the basis for the claim that LPA is fully composable with standard QKD and with primitives that consume a unique session key [2603.18097].

## 5. Application to BB84-type QKD

For BB84, after sifting, Alice and Bob share \(n'\) bits with bit error rate \(e_b\) and phase error rate \(e_p\). Finite-key analysis gives
\[
H^\varepsilon_{\min}(X|E)_\rho \;\ge\; n'\bigl(1 - h(e_p) - h(e_b)\bigr) - \Delta(n',\varepsilon),
\]
where \(\Delta\) is a finite-size correction term of order \(O(\sqrt{n'}\log(1/\varepsilon))\) [2603.18097]. Standard privacy amplification then gives an asymptotic key rate
\[
r_{\mathrm{std} \approx 1 - h(e_p) - h(e_b),
\]
which vanishes when \(h(e_p)+h(e_b)\ge 1\); for symmetric channels this corresponds to the familiar \(\approx 11\%\) phase-error threshold [2603.18097].

Under LPA, the extractable list-key length satisfies
\[
\ell \le H^\varepsilon_{\min}(X|E)_\rho + \log L - 2\log(1/\varepsilon) - 3,
\]
and therefore, after substituting the BB84 min-entropy lower bound,
\[
\ell \le n'\bigl(1 - h(e_p) - h(e_b)\bigr) + \log L - 2\log(1/\varepsilon) - 3 - \Delta(n',\varepsilon).
\]
Requiring \(\ell>0\) yields
\[
e_p < h^{-1}\!\left(1 - h(e_b) + \frac{\log L - 2\log(1/\varepsilon) - \Delta(n',\varepsilon) -3}{n'}\right)
\]
[2603.18097]. For list size \(L = 2^{\alpha n'}\) and \(\varepsilon = 2^{-\Omega(n')}\), this becomes asymptotically
\[
e_p < h^{-1}\!\bigl(1 - h(e_b) + \alpha\bigr),
\]
which the paper summarizes as a threshold shift from
\[
h^{-1}\bigl(1 - h(e_b)\bigr)
\quad\to\quad
h^{-1}\bigl(1 - h(e_b) + \alpha\bigr)
\]
[2603.18097].

According to [2603.18097], this means that standard BB84 with unique-key privacy amplification cannot extract positive key beyond roughly \(11\%\) phase error, whereas BB84 with LPA can tolerate strictly larger phase error for any \(\alpha>0\). The paper also proves tightness in the QKD setting via a matching intercept–resend attack: the attack can be tuned so that the bit and phase error rates lie exactly at the threshold predicted by QLLHL, and beyond the shifted threshold even list privacy amplification cannot generate key [2603.18097]. This shows that the increased tolerable phase-error threshold is not merely an artefact of analysis.

## 6. Explicit constructions and computational complexity

The QLLHL is stated for any strongly two-universal family, and [2603.18097] gives two explicit constructions.

The first is a polynomial inner-product hash over \(\mathbb{F}_{2^m}\). Assuming \(m\mid n\) and \(m\mid \ell\), the input \(x\in\{0,1\}^n\) is represented as \(\mathbf{x}\in\mathbb{F}_{2^m}^{n/m}\). For each list position \(j\), one samples \(a_j \in \mathbb{F}_{2^m}^{n/m}\) and \(b_j \in \mathbb{F}_{2^m}^{\ell/m}\), computes
\[
t_j = \sum_{i=1}^{n/m} a_{j,i} \cdot x_i,
\]
and sets
\[
K_j = t_j + b_j
\]
before encoding as an \(\ell\)-bit string [2603.18097]. The family is strongly two-universal, yields list-\(4\varepsilon\)-security under the QLLHL bound, uses \(n+\ell\) random bits per hash, and runs in \(O(nL)\) bit operations overall, with \(O(n+\ell)\) working memory per hash and \(O(L\ell)\) storage for all keys [2603.18097].

The second construction is Toeplitz-based and operates over \(\mathbb{F}_2\). For each list element \(j\), one samples a Toeplitz generator \(r_j\in\{0,1\}^{n+\ell-1}\), defining an \(\ell\times n\) Toeplitz matrix \(T_j\), samples an offset \(b_j\in\{0,1\}^\ell\), and computes
\[
K_j = T_j x \oplus b_j
\]
using convolution and FFT-based acceleration [2603.18097]. Toeplitz hashing is also strongly two-universal, satisfies the same list-\(4\varepsilon\) guarantee, uses \(n+2\ell-1\) random bits per list element, and has total running time \(O(Ln\log n)\) for \(N=n+\ell-1\), with \(O(N)\) FFT workspace and \(O(L\ell)\) key storage [2603.18097].

| Construction | Seed usage per list element | Time |
|---|---:|---:|
| Polynomial inner-product hash over \(\mathbb{F}_{2^m}\) | \(n+\ell\) bits | \(O(nL)\) total |
| Toeplitz-based list hash | \(n+2\ell-1\) bits | \(O(Ln\log n)\) total |

Both constructions satisfy the strong two-universality required by QLLHL [2603.18097]. The paper characterizes the trade-off as one between conceptual simplicity and FFT-based asymptotic acceleration: inner-product hashing is simpler and linear-time in \(nL\), whereas the Toeplitz construction is more implementation-intensive but benefits from convolution-based computation [2603.18097].

## 7. Conceptual significance, neighboring frameworks, and limitations

The stated reason for the \(\log L\) gain is index-hiding entropy. In standard privacy amplification, the key is a function \(K=F(X)\) of the source alone, so all usable entropy must come from \(X\). In LPA, Alice and Bob derive many outputs \(K_1,\dots,K_L\), then choose the index \(I\) afterwards and keep it hidden from Eve. The pair \((I,K_I)\) therefore draws entropy both from \(X\) and from the independent uniform index \(I\), yielding the additional \(\log L\) term [2603.18097]. The analogy with list decoding is structural rather than metaphorical: relaxing uniqueness opens degrees of freedom that are unavailable in the standard formulation [2603.18097].

The paper explicitly contrasts LPA with classical fuzzy and list fuzzy extractors. Those constructions concern noisy inputs and classical adversaries, whereas LPA addresses a clean classical source \(X\) entangled with arbitrary quantum side information and provides a composable security statement in a quantum setting [2603.18097]. It states that LPA is the first approach to be simultaneously quantum, list-output, composable, and tight [2603.18097].

Other forms of privacy amplification by list-like outputs exist in different settings. “Privacy Amplification via Shuffled Check-Ins” [2206.03151] studies a shuffle-model protocol in which each round outputs an unordered list of locally randomized reports from independently self-sampled users. There, privacy amplification arises from random participation and shuffling, and the RDP analysis is expressed as a binomial mixture over all possible list sizes \(k\) [2206.03151]. This is not LPA in the QKD sense, but it shows that list-structured outputs also play a central role in differential privacy and shuffle-model amplification [2206.03151]. This suggests a broader methodological theme: privacy gains can emerge when the released object is a list whose latent structure conceals the identity or status of a privileged element.

The limitations recorded in [2603.18097] are concrete. The model assumes authenticated classical communication and trusted local devices; it is not device-independent. Finite-size corrections \(\Delta(n',\varepsilon)\) may substantially reduce the asymptotic gain for small block lengths. For very large \(L = 2^{\alpha n'}\), the authentication cost of transmitting \(I\) scales as \(\alpha n'\) bits of pre-shared key, which can materially reduce net key rate; accordingly, the paper suggests small constant list sizes such as \(L\in\{4,8,16\}\) as more realistic [2603.18097]. It also does not treat device-independent QKD, continuous-variable QKD, or entropy accumulation frameworks, and identifies low-seed list privacy amplification as an open problem, asking whether nearly optimal seed length can be achieved while remaining information-theoretic [2603.18097].

In summary, LPA is a composable reformulation of privacy amplification in which secrecy is attached not to a unique hash output but to a hidden position within a list. The resulting Quantum List Leftover Hash Lemma establishes that the secret index contributes an additive \(\log L\) to the extractable key length, the converse shows that this gain is tight, and the BB84 analysis shows that the effect translates into a genuine increase in tolerable phase error [2603.18097]. Within the technical landscape of list-based privacy notions, LPA is distinguished by its quantum adversarial model, its AC-level composability, and its explicit identification of hidden index entropy as a cryptographic resource [2603.18097].

Source: https://www.emergentmind.com/topics/list-privacy-amplification-lpa