Entanglement Distillation
Entanglement distillation is the conversion of several imperfect entangled states shared by distant parties into fewer states closer to a chosen maximally entangled target, using local quantum operations and classical communication (LOCC). It trades quantity for quality. A successful branch can have higher Bell-state fidelity than any one input pair, but the inputs consumed, failed branches, communication rounds, and local imperfections remain part of the protocol cost.
The task is also called entanglement purification. Neither name means purifying a density operator by adjoining an abstract reference system. Here Alice and Bob physically process distributed pairs and aim to produce usable shared entanglement.
This page is the canonical home for recurrence purification, Bell-diagonal error propagation, hashing, finite-round yield accounting, and experimental claims about distilled links. Entanglement Measures owns the definition and general bounds for distillable entanglement . Network Case Studies owns architecture-level evidence and end-to-end service comparisons.
Operational Contract
Section titled “Operational Contract”Alice holds registers and Bob holds . Ideally, the input is an independent and identically distributed supply
An LOCC instrument produces a classical transcript , an accept or abort flag , and, on acceptance, output pairs. A complete claim states at least:
- the input state family or experimentally certified input data;
- the target state and fidelity convention;
- the local gates, measurements, memories, and communication direction;
- the acceptance event and its probability;
- the conditional output quality and uncertainty;
- the number of raw pairs, attempts, modes, and seconds consumed;
- whether the result is one-shot, finite-block, or asymptotic.
For the target
the accepted-state fidelity is
If , a two-to-one round has raw-pair yield
before source failures, memory expiration, readout loss, verification samples, and scheduling overhead are included. Reporting only hides the central tradeoff.
The asymptotic resource-theory statement has a different scale. A sequence of protocols distills at rate when
while the output error tends to zero. Optimizing gives for the specified class of one-way or two-way LOCC. A finite recurrence experiment is evidence for a particular achievable transformation, not a measurement of the optimal asymptotic rate. Here denotes one standard two-qubit ebit.
Bell-Diagonal Noise Model
Section titled “Bell-Diagonal Noise Model”Label the Bell basis by two error bits,
Here is a phase-error label and is a bit-parity label. In the order used below,
| Label | Bell state | Probability |
|---|---|---|
| $ | \Phi^+\rangle$ | |
| $ | \Phi^-\rangle$ | |
| $ | \Psi^+\rangle$ | |
| $ | \Psi^-\rangle$ |
A Bell-diagonal input is
The particularly symmetric family used for the first recurrence calculation is
This is often called a Werner state in purification discussions, although “Werner” and “isotropic” denote distinct invariant families in general dimension. Bell-isotropic state is the unambiguous name for the formula above. For two qubits it is entangled exactly when .
Twirling and what it costs
Section titled “Twirling and what it costs”A coordinated random bilateral unitary, followed by forgetting the random choice, can map an arbitrary two-qubit state to while preserving its overlap with the chosen Bell target. For , the continuous version averages operations of the form ; a finite shared Clifford ensemble is enough in practice.
Twirling is LOCC, but it is not a theorem that it helps every protocol. It erases Bell-basis asymmetries and coherences that a better-matched protocol might exploit. It also assumes Alice and Bob share the same target frame and coordinate the random choices. The symmetric model is valuable because it makes the recurrence transparent, not because all laboratory noise is depolarizing.
One BBPSSW Recurrence Round
Section titled “One BBPSSW Recurrence Round”The Bennett–Brassard–Popescu–Schumacher–Smolin–Wootters (BBPSSW) recurrence protocol consumes two shared pairs. Call pair 1 the source pair and pair 2 the target pair.
- Alice applies and Bob applies .
- Both parties measure their target qubit in the basis.
- They compare the two classical outcomes.
- They retain the source pair only when the outcomes agree.
- If another scalar recurrence round is wanted, they twirl the retained pair back to the Bell-isotropic family.
One recurrence round. The source pair survives only on the heralded even-parity branch. Under the ideal Bell-isotropic model and , its conditional fidelity is larger, while the raw-pair yield is .
Error-label propagation
Section titled “Error-label propagation”Let the two input Bell labels be and . Conjugating the Pauli labels through the bilateral CNOT gives
Computational-basis outcomes on a Bell state agree exactly when its parity label is zero. Acceptance therefore tests
without revealing the individual source parity. This is a distributed error check: the target pair is consumed to learn one syndrome bit about the pair labels.
For independent, identical Bell-diagonal inputs, the acceptance probability is
Conditioned on acceptance, the retained source has probabilities
These equations expose what the parity check does. Cases with mismatched bit labels are rejected. Within an accepted parity sector, equal phase labels map to phase label zero and unequal phase labels map to phase label one. A later round with local basis changes can exchange the roles of bit and phase errors.
Scalar fidelity map
Section titled “Scalar fidelity map”For the Bell-isotropic input, set
Then
and the retained pair has target fidelity
The gain factors as
Once the target Bell component has been chosen as the largest component, the relevant regime has . Thus the ideal scalar protocol improves the target fidelity for
The threshold is not merely an artifact of the recurrence formula: is separable at and below that value. LOCC cannot distill a Bell pair from separable inputs.
Numerical example
Section titled “Numerical example”For ,
The accepted pair is better by about , but one output attempt consumed two inputs. The expected raw-pair yield is therefore
This is the honest one-round result: higher conditional fidelity and fewer pairs.
Iteration and Yield
Section titled “Iteration and Yield”With an ideal twirl after every accepted round, define
Starting with raw pairs, the expected number after rounds is
For , ideal iteration gives:
| Rounds | Conditional fidelity | Expected outputs per raw pair |
|---|---|---|
| 0 | ||
| 1 | ||
| 2 | ||
| 3 | ||
| 4 |
The table is not a performance forecast. It assumes independent inputs, perfect local gates and measurements, no waiting-time decoherence, and an unlimited ability to pair outputs of the same round. It does show why “arbitrarily high fidelity” does not mean “at negligible cost.”
In a finite batch, pairing and postselection are stochastic. If one branch finishes early, its surviving pair may wait in memory for a partner. Nested rounds therefore need a scheduling policy: maximum pair age, timeout, re-pairing rule, and whether pairs from different calibration epochs may be combined.
DEJMPS and Other Recurrence Protocols
Section titled “DEJMPS and Other Recurrence Protocols”The Deutsch–Ekert–Jozsa–Macchiavello–Popescu–Sanpera (DEJMPS) protocol is a closely related two-to-one recurrence scheme. Local basis rotations are chosen before the bilateral CNOT so that the accepted branch suppresses both relevant error classes efficiently. For Bell-diagonal inputs, DEJMPS keeps the four Bell probabilities rather than forcing the state through a full isotropic twirl after every round.
That distinction matters when are unequal. Two states with the same target fidelity can have different recurrence performance because their remaining probability is distributed among different Bell errors. A scalar is then not a sufficient state description.
Protocol names alone do not fix an implementation. Authors may choose a singlet rather than as target, reverse the CNOT direction, permute Bell labels, or accept opposite rather than equal detector outcomes. These descriptions can be locally equivalent. A reproducible specification must give the Bell convention, circuit, accepted outcomes, and frame update.
Modern finite-block protocols optimize local Clifford circuits, code-based checks, or measurement-based implementations for a particular input model and hardware cost. They should be compared at fixed input ensemble, local-noise model, output target, and total success probability, not by fidelity alone.
Hashing: An Asymptotic Protocol
Section titled “Hashing: An Asymptotic Protocol”Recurrence tests a small number of parity relations and discards aggressively. Hashing acts jointly on a large block of Bell-diagonal pairs. Alice and Bob use random bilateral parity checks to learn the typical bit-and-phase error string, consuming measured pairs as syndrome carriers. Once the error string is known with vanishing failure probability, they correct the unmeasured pairs.
For Bell probabilities , define the Shannon entropy
The one-way hashing protocol achieves the asymptotic rate
when the right-hand side is positive. More carefully, it proves the achievable lower bound
it does not assert that hashing is optimal for every Bell-diagonal state.
For the Bell-isotropic distribution,
The hashing rate becomes positive at
This does not conflict with the recurrence threshold . Two-way recurrence can first raise fidelity above the hashing threshold, after which a large surviving block can be hashed. Such recurrence-plus-hashing schemes trade several low-yield purification rounds for a positive asymptotic finishing rate.
Hashing is an asymptotic coding theorem. At finite blocklength, the number of checks must include statistical margins, target failure probability, and protocol overhead. Simply substituting an estimated distribution into is not a certified finite-batch yield.
Relation to Neighboring Tasks
Section titled “Relation to Neighboring Tasks”Pure-state concentration
Section titled “Pure-state concentration”Entanglement concentration starts from pure but nonmaximally entangled pairs, for example
In the many-copy limit, Bell pairs can be extracted reversibly at the entropy of entanglement. Mixed-state distillation includes noise and is generally irreversible. The words are sometimes used broadly enough to overlap, so the input state class should always be named.
Quantum error correction
Section titled “Quantum error correction”Distillation and quantum error correction extract the same syndrome logic in different operational arrangements. A one-way entanglement-purification protocol for Bell pairs sent through a channel can be converted into a quantum error-correcting code for that channel, and conversely. Stabilizer hashing checks are the distributed counterpart of code syndromes.
The protocols are not interchangeable at the hardware level. Recurrence uses two-way messages and postselection on already shared pairs. A quantum code encodes an unknown state and normally aims for deterministic logical recovery. Why Quantum Error Correction Is Possible develops that protection task.
Magic-state distillation
Section titled “Magic-state distillation”Magic State Distillation purifies nonstabilizer resource states inside a fault-tolerant computer. Entanglement distillation purifies a nonlocal resource shared across a bipartition. Both consume many noisy resources to produce fewer better ones, but their free operations, targets, thresholds, and applications differ.
QKD privacy amplification
Section titled “QKD privacy amplification”Entanglement-based security proofs can imagine Alice and Bob distilling nearly perfect private Bell pairs before measuring them for a key. This viewpoint connects phase-error correction to privacy amplification. An implemented QKD system usually performs classical error correction and privacy amplification rather than building a universal quantum computer at each endpoint. Quantum Key Distribution owns the composable security contract and finite-key accounting. BB84 makes the Shor–Preskill bridge concrete by relating virtual phase-error correction to privacy amplification in a prepare-and-measure protocol.
Fundamental Boundaries
Section titled “Fundamental Boundaries”Separability and PPT obstruction
Section titled “Separability and PPT obstruction”LOCC maps separable states to separable states, even conditionally. No distillation protocol can create entanglement from an actually separable input. For bipartite states, positive partial transpose is a stronger obstruction: PPT states remain PPT under LOCC, whereas a two-qubit Bell pair is NPT. Therefore every PPT entangled state has zero ordinary distillable entanglement.
For two qubits, PPT is equivalent to separability, and every entangled state is distillable in the asymptotic sense. In larger local dimensions, PPT entangled states exist and provide established examples of bound entanglement. See Negativity and PPT Criterion for the partial-transpose calculation.
Whether every NPT state is distillable remains an open problem as of August 2026. Two independent July 2026 preprints settled the two-copy distillability boundary for Werner states, but two-copy undistillability does not prove undistillability for arbitrarily many copies. The general existence of NPT bound entanglement is therefore not established.
No input-independent improvement guarantee
Section titled “No input-independent improvement guarantee”Fidelity improvement is model and target dependent. There is no input-independent finite-copy LOCC protocol guaranteed to return an output whose target fidelity is no worse than every input for every two-qubit entangled state. Characterization, symmetry assumptions, calibration, or a protocol matched to a restricted state family is essential.
Imperfect local operations
Section titled “Imperfect local operations”The ideal recurrence assumes its local operations are cleaner than the links being purified. With a noisy local instrument and acceptance map , the physical output is
Gate, readout, reset, leakage, and memory errors can reduce the gain, move the input threshold, and produce a fidelity ceiling below one. No universal “purification threshold” exists without a specified noise channel and protocol.
Correlated and drifting inputs
Section titled “Correlated and drifting inputs”The tensor-power model excludes temporal drift, common-mode phase noise, source afterpulsing, crosstalk, and adversarial correlations. A protocol may still work under weaker exchangeability or security assumptions, but the proof must say so. Random permutation can enforce useful symmetry; it does not magically make physical trials independent.
Distillation Inside a Network
Section titled “Distillation Inside a Network”Quantum Repeaters owns the complete architecture, waiting-time policy, generation taxonomy, and system resource ledger. This section isolates where distillation enters that architecture and how its pair yield differs from a delivered network rate.
Swapping and distillation solve different problems:
- entanglement swapping extends the endpoints of a link and normally degrades quality;
- distillation consumes parallel links to improve the conditional quality of a surviving link.
A first-generation repeater nests the two operations. Elementary segments are generated and possibly distilled, neighboring segments are swapped, and the longer links may be distilled again. Every level introduces waiting-time and classical-latency costs.
For a two-to-one round, is the correct yield per already available raw pair. It is generally not the network output rate. If is the random time required to hold two compatible pairs and is the probability that an accepted pair also passes age and quality policies, a schematic service rate is
This expression is only a ledger, not a universal rate law. Pair generation may be parallel or sequential; failed local measurements may consume one or both links; memories age while a second pair is prepared; and may include a round-trip classical signal. A useful simulation must implement the actual queueing and retry policy.
Reading Experimental Claims
Section titled “Reading Experimental Claims”Experiments have demonstrated pieces of the distillation contract in photonic, trapped-ion, and solid-state network systems. Their achievements are not interchangeable:
- optical experiments established postselected purification with linear optics, often through multi-photon coincidence events;
- trapped-ion work produced a retained atomic pair available after a nondestructive purification step;
- solid-state network nodes combined remote heralded generation, memory storage, local two-qubit gates, and single-shot acceptance.
For any platform, ask:
- Were the two inputs independent physical pairs, two degrees of freedom of one carrier, or repeated preparations reconstructed statistically?
- Was acceptance heralded online, or selected retrospectively from detection records?
- Did the output pair remain available for another task, or was it destroyed during verification?
- Was fidelity estimated by full tomography, a witness, stabilizer correlations, or a model-dependent estimator?
- Were accidental counts, detector loss, and readout errors included or subtracted?
- How many raw generation attempts and wall-clock seconds produced one usable output?
- Did the confidence interval establish improvement over the input under the same reference plane?
A higher reconstructed conditional fidelity is important evidence, but it is not by itself a repeater advantage, a positive secret-key rate, or an asymptotic distillation rate.
Common Mistakes
Section titled “Common Mistakes”- Calling any local filtering event distillation without reporting its success probability.
- Using as the only performance metric and omitting the factor of two in raw-pair consumption.
- Applying the scalar BBPSSW formula to a state that has not been justified as Bell-isotropic.
- Assuming twirling is free of information loss or automatically optimal.
- Confusing Bell-state fidelity with an entanglement monotone for arbitrary states.
- Iterating the ideal map while ignoring local-gate and memory noise.
- Calling every NPT state distillable in arbitrary dimension.
- Treating a finite successful experiment as a measurement of .
- Confusing entanglement distillation with density-matrix purification, pure state concentration, error correction, or magic-state distillation.
- Quoting a network rate without pairing, timeout, classical-latency, and verification costs.
Exercises
Section titled “Exercises”1. Derive the acceptance probability
Section titled “1. Derive the acceptance probability”For independent Bell-diagonal inputs with probabilities , show that equal target measurement outcomes occur with probability
Solution
The target Bell parity after the bilateral CNOT is . Equal outcomes require this bit to vanish, so the two input parity labels must agree. The probability that both have is ; the probability that both have is . These events are disjoint, giving
2. Check the Bell-label map
Section titled “2. Check the Bell-label map”Conditioned on acceptance, derive and for the retained source pair.
Solution
For the accepted sector, the source phase label is . It vanishes for the two input combinations and , whose probabilities are and . It equals one for and , with total probability . Normalizing by gives
The calculation similarly gives and .
3. Fidelity and yield at one round
Section titled “3. Fidelity and yield at one round”Evaluate , , and expected outputs per raw input pair for a Bell-isotropic input with .
Solution
Using the scalar formulas,
The expected output count per raw pair is
4. Fixed points and stability
Section titled “4. Fixed points and stability”Find the fixed points of the scalar recurrence in and determine the direction of flow in the physically targeted regime .
Solution
The factorization
shows fixed points at , , and . The denominator is positive. For , the map decreases toward ; for , it increases toward . The point is the unstable threshold separating the two behaviors under the ideal twirled model.
5. Hashing threshold
Section titled “5. Hashing threshold”Show numerically that Bell-isotropic hashing first has positive rate near . What is the rate at ?
Solution
Solve
The solution in is
At ,
so the ideal asymptotic hashing rate is
Bell pairs per input pair.
6. Why PPT states cannot be distilled
Section titled “6. Why PPT states cannot be distilled”Give a short partial-transpose argument that an LOCC protocol cannot distill a PPT input into a two-qubit Bell pair.
Solution
Every LOCC branch is a separable operation with product Kraus operators. Such operations preserve positivity of the partial transpose, including after tensoring copies and conditioning on a nonzero-probability branch. A Bell pair has a negative partial transpose. Therefore a PPT input cannot be mapped by LOCC to a Bell pair, even asymptotically with vanishing error. PPT entangled states are consequently bound entangled under ordinary LOCC distillation.
7. Monotonicity and postselection
Section titled “7. Monotonicity and postselection”Why does an accepted branch with more entanglement than one input pair not contradict LOCC monotonicity?
Solution
Selective LOCC monotonicity constrains the branch-weighted average,
It does not forbid one conditional branch from having greater entanglement than one input copy. The protocol started with two copies, and the favorable branch occurs only probabilistically; rejected resources are consumed or degraded. Ignoring those branches is the apparent paradox.
8. Network timing ledger
Section titled “8. Network timing ledger”A node obtains the first raw pair after on average and then waits another for a compatible second pair. Local operations and the classical comparison take . If and of accepted pairs pass the age policy, estimate the schematic usable-pair rate.
Solution
The mean two-pair preparation time is and the LOCC step adds . Thus
This estimate is valid only for the stated average-time ledger. A real rate calculation needs the waiting-time distribution, timeout behavior, retries, and any correlations between pair age and acceptance.
Further Connections
Section titled “Further Connections”- Resource Theories distinguishes exact from approximate, deterministic from probabilistic, and one-shot from asymptotic claims while exposing catalysts and side resources; this page owns the LOCC protocol and yield ledger.
- Entanglement Measures defines , , one-way and two-way rates, and converse bounds.
- LOCC Preview develops the branch structure and average monotonicity behind probabilistic purification.
- Bell States fixes the basis and local-Pauli relationships used in the recurrence derivation.
- Entanglement in Quantum Information places distillation in the broader resource-theory picture.
- Entanglement Swapping owns link extension and Bell-measurement success accounting.
- Quantum Teleportation is a principal consumer of a distilled Bell pair.
- Quantum Key Distribution connects virtual entanglement purification to classical privacy amplification and composable keys.
- BB84 gives the canonical prepare-and-measure realization of the virtual entanglement-purification argument.
- Stabilizer Formalism supplies the syndrome language behind hashing and code-based distillation.
- Quantum Memories owns lifetime, efficiency, multimode capacity, and synchronization constraints.
- Network Case Studies evaluates purification as one primitive inside complete network demonstrations.
References
Section titled “References”- C. H. Bennett, G. Brassard, S. Popescu, B. Schumacher, J. A. Smolin, and W. K. Wootters, “Purification of Noisy Entanglement and Faithful Teleportation via Noisy Channels,” Physical Review Letters 76, 722–725 (1996), doi:10.1103/PhysRevLett.76.722.
- C. H. Bennett, D. P. DiVincenzo, J. A. Smolin, and W. K. Wootters, “Mixed-State Entanglement and Quantum Error Correction,” Physical Review A 54, 3824–3851 (1996), doi:10.1103/PhysRevA.54.3824.
- D. Deutsch, A. Ekert, R. Jozsa, C. Macchiavello, S. Popescu, and A. Sanpera, “Quantum Privacy Amplification and the Security of Quantum Cryptography over Noisy Channels,” Physical Review Letters 77, 2818–2821 (1996), doi:10.1103/PhysRevLett.77.2818.
- M. Horodecki, P. Horodecki, and R. Horodecki, “Mixed-State Entanglement and Distillation: Is There a ‘Bound’ Entanglement in Nature?” Physical Review Letters 80, 5239–5242 (1998), doi:10.1103/PhysRevLett.80.5239.
- W. Dür, H.-J. Briegel, J. I. Cirac, and P. Zoller, “Quantum Repeaters Based on Entanglement Purification,” Physical Review A 59, 169–181 (1999), doi:10.1103/PhysRevA.59.169.
- R. Horodecki, P. Horodecki, M. Horodecki, and K. Horodecki, “Quantum Entanglement,” Reviews of Modern Physics 81, 865–942 (2009), doi:10.1103/RevModPhys.81.865.
- P. G. Kwiat, S. Barraza-Lopez, A. Stefanov, and N. Gisin, “Experimental Entanglement Distillation and ‘Hidden’ Non-locality,” Nature 409, 1014–1017 (2001), doi:10.1038/35059017.
- J.-W. Pan, C. Simon, Č. Brukner, and A. Zeilinger, “Entanglement Purification for Quantum Communication,” Nature 410, 1067–1070 (2001), doi:10.1038/35074041.
- J.-W. Pan, S. Gasparoni, R. Ursin, G. Weihs, and A. Zeilinger, “Experimental Entanglement Purification of Arbitrary Unknown States,” Nature 423, 417–422 (2003), doi:10.1038/nature01623.
- R. Reichle, D. Leibfried, E. Knill, et al., “Experimental Purification of Two-Atom Entanglement,” Nature 443, 838–841 (2006), doi:10.1038/nature05146.
- N. Kalb, A. A. Reiserer, P. C. Humphreys, et al., “Entanglement Distillation between Solid-State Quantum Network Nodes,” Science 356, 928–932 (2017), doi:10.1126/science.aan0070.
- S. Krastanov, V. V. Albert, and L. Jiang, “Optimized Entanglement Purification,” Quantum 3, 123 (2019), doi:10.22331/q-2019-02-18-123.
- M. Zwerger, H. J. Briegel, and W. Dür, “Universal and Optimal Error Thresholds for Measurement-Based Entanglement Purification,” Physical Review Letters 110, 260503 (2013), doi:10.1103/PhysRevLett.110.260503.
- K. Fang and Z.-W. Liu, “No-Go Theorems for Quantum Resource Purification,” Physical Review Letters 125, 060405 (2020), doi:10.1103/PhysRevLett.125.060405.
- A. Zang, X. Chen, E. Chitambar, M. Suchara, and T. Zhong, “No-Go Theorems for Universal Entanglement Purification,” Physical Review Letters 134, 190803 (2025), doi:10.1103/PhysRevLett.134.190803.
- J. Fu, L. Gao, and S.-J. Park, “A Solution to 2-Copy Distillability of Werner States,” arXiv:2607.21367 (2026), arXiv:2607.21367.
- Z. Song and L. Chen, “A Partial-Trace Matrix Inequality and Werner-State Distillability,” arXiv:2607.23416 (2026), arXiv:2607.23416.
- M. A. Nielsen and I. L. Chuang, Quantum Computation and Quantum Information, 10th anniversary ed., Cambridge University Press (2010), doi:10.1017/CBO9780511976667.
Summary
Section titled “Summary”Entanglement distillation is an LOCC resource-conversion protocol, not a fidelity filter with free postselection. In a BBPSSW recurrence round, bilateral CNOTs transfer a parity relation to a consumed target pair. Equal measurement outcomes herald a retained source pair whose Bell distribution is updated by an explicit nonlinear map. For Bell-isotropic inputs with , the conditional fidelity rises, while the expected pair count falls by per round.
Hashing replaces repeated two-pair checks with asymptotic syndrome extraction and achieves for suitable Bell-diagonal inputs. Real systems must additionally account for imperfect local operations, memories, correlated inputs, communication latency, and verification. The trustworthy claim reports state quality, acceptance, resource yield, and delivered rate together.