Measurement-Device-Independent QKD
Measurement-device-independent quantum key distribution (MDI-QKD) is a QKD architecture in which Alice and Bob prepare quantum states and send them to an untrusted intermediate station that performs a joint measurement. The station, conventionally called Charles, publicly reports a Bell-state measurement outcome or failure. Alice and Bob use the successful reports, their private preparation choices, and authenticated classical postprocessing to distill a key.
The defining security move is to place the entire measurement station inside Eve’s domain. Its optics, detectors, timing logic, efficiency, dark counts, and classical outcome generator need not follow a trusted device model. A malicious station may suppress events, fabricate labels, or coordinate with the quantum channels. It may force an abort, but accepted data must still obey the security proof’s statistical tests before yielding a key.
MDI-QKD is not fully device-independent. Alice’s and Bob’s sources, random choices, laboratory isolation, phase randomization, intensity distributions, and state encoders remain characterized. It also needs the ordinary composable QKD contract, authentication, finite-key analysis, reconciliation, verification, and privacy amplification developed in Quantum Key Distribution. This page is the canonical home of the untrusted-relay protocol, its time-reversed entanglement interpretation, its two-source decoy equations, and its detector-versus-source trust boundary.
Why Move the Measurement?
Section titled “Why Move the Measurement?”In standard prepare-and-measure BB84, the quantum channel terminates at Bob’s receiver. A security proof therefore needs a model of his basis selector, detection efficiencies, time gates, double-click rules, dead time, and all optical modes that influence acceptance. Real single-photon detectors have supported attacks based on efficiency mismatch, timing, wavelength response, bright-light control, afterpulsing, and other behavior absent from simplified POVM models.
MDI-QKD changes the interface rather than attempting to enumerate every detector imperfection. Both legitimate users become transmitters. Everything that receives their quantum signals is placed outside their trusted laboratories and may be operated by Eve. The security proof is conditioned on the relay’s public classical report, whatever physical process produced it.
This removes detector behavior from the trusted secrecy boundary, but not from performance. Poor detectors lower the successful-event rate and raise the observed error rate. Eve can always deny service by reporting failure. What she cannot do, under the source and protocol assumptions, is use hidden detector behavior to learn a key that passes the tests.
The MDI-QKD trust boundary. State preparation and private random choices stay inside Alice’s and Bob’s laboratories. Both quantum channels, the Bell analyzer, detectors, and outcome electronics are adversarial. The relay’s outcome must be fixed before basis and intensity disclosure; authenticated postprocessing then either produces a shared key or aborts.
Protocol Transcript
Section titled “Protocol Transcript”Consider a polarization or time-bin BB84 implementation with phase-randomized weak coherent pulses. A precise finite protocol fixes all probabilities, acceptance windows, and abort rules in advance. One round has the following structure.
- Alice chooses a bit , basis , and intensity .
- Bob independently chooses , , and intensity .
- Each prepares the corresponding optical BB84 state, randomizes its global phase according to the source model, and sends it toward Charles.
- Charles announces an outcome , where denotes failure. The supported Bell labels depend on the analyzer.
- Only after the outcome record is fixed do Alice and Bob disclose the basis and intensity labels over authenticated classical communication.
- They retain declared successful classes, apply a Bell-label-dependent bit correction, and separate key-generating data from parameter-estimation data.
- Two-source decoy analysis bounds single-photon-pair detections and their phase errors. Alice and Bob then reconcile, verify, and privacy-amplify.
The relay does not need an identity that Alice and Bob trust. In a network it may be a service provider, an intermediate user, or Eve herself. Alice and Bob do need a consistent authenticated transcript. If Charles sends different outcome lists to the two endpoints, transcript comparison or authentication must expose the inconsistency before key acceptance.
The time ordering matters. If basis, bit, or intensity information reaches the relay before its successful-event record is committed, the relay can postselect with knowledge that the proof treats as unavailable. Physical and software implementations therefore need a defined event boundary, not merely a diagram with arrows in the desired order.
Bell Projection and Time Reversal
Section titled “Bell Projection and Time Reversal”Virtual entanglement-based description
Section titled “Virtual entanglement-based description”The security intuition comes from a source-replacement construction. Imagine that Alice prepares and Bob prepares . They retain and while sending and to Charles. The entanglement-swapping identity is
An ideal Bell projection on therefore projects the retained systems into the corresponding Bell state. Alice and Bob could then measure and to obtain correlated bits. Because their local measurements commute with Charles’s remote operation, they may instead measure first. That early measurement remotely prepares the BB84 states sent in the actual prepare-and-measure implementation.
For this reason MDI-QKD is often called time-reversed entanglement-based QKD. No macroscopic reversal of time occurs. The phrase refers to exchanging the operational order of local state preparation and the middle Bell projection in an equivalent virtual protocol. The full algebra and Pauli frame of entanglement swapping remain canonical in Entanglement Swapping.
Why an untrusted projection can still help
Section titled “Why an untrusted projection can still help”If Charles performs the advertised Bell measurement honestly, the virtual picture is literal. Security does not assume that honesty. A general attack replaces the Bell analyzer by an arbitrary quantum instrument controlled by Eve, with an arbitrary public output . Alice and Bob condition on and test the resulting correlations.
This is analogous to treating the quantum channel as adversarial in ordinary QKD, but the adversarial map now includes measurement and detection. The proof does not infer that Charles created entanglement merely because he said “.” It bounds Eve’s information from the complete observed data and the trusted source states. Dishonest outcome labels either reproduce statistics compatible with a secure conditional state or reduce the certified key length.
Bell Labels and Bit Correction
Section titled “Bell Labels and Bit Correction”Use
Many linear-optical analyzers report one or both outcomes. The following product-state decompositions make the classical correction rule transparent:
With bit encoded as or and bit as or , Bob can use this correction table:
| Shared basis | Reported outcome | Ideal relation before correction | Bob’s action |
|---|---|---|---|
| opposite bits | flip | ||
| opposite bits | flip | ||
| opposite bits | flip | ||
| equal bits | no flip |
The table depends on Bell-state phases, bit encoding, detector labeling, and which party corrects. A real protocol must publish one convention and test it against known state pairs. Some implementations accept only , which simplifies the rule at the cost of fewer successful outcomes.
After correction, an error is a disagreement between Alice’s bit and Bob’s corrected bit. Mismatched-basis events are normally discarded rather than forced into this table.
Two-Source Decoy Estimation
Section titled “Two-Source Decoy Estimation”Practical MDI-QKD usually combines the untrusted measurement with decoy-state sources. If is Alice’s encoded -photon state, then her phase-randomized pulse of intensity is
Alice’s pulse and Bob’s independently randomized pulse of intensity have the joint decomposition
where
For basis , define the pair yield
and the corrected error rate
The measured gain and error gain for intensity pair are
The security-relevant sector has one photon from Alice and one from Bob:
For signal intensities and , its gain is
The shared-yield assumption now applies independently to both transmitters. Given and Alice’s encoded state, her signal and decoy pulses must be indistinguishable in every unmodeled degree of freedom; the analogous statement holds for Bob. Otherwise the correct unknown is , and cross-intensity constraints can fail.
A two-dimensional inverse problem
Section titled “A two-dimensional inverse problem”Removing the Poisson factors gives
In an ideal continuum-intensity limit,
Finite protocols use a few intensity pairs and statistical intervals. They minimize and maximize the relevant subject to all gain and error-gain constraints, physical bounds, intensity calibration, and Poisson tails. This is the two-source extension of the estimator derived in Decoy-State QKD, not two unrelated one-dimensional fits.
Vacuum settings are especially useful because and data separate background and one-sided emissions from true two-sided interference. Efficient designs may use different signal and decoy intensities in the two bases, but the resulting basis-intensity table must be kept intact in the proof.
Asymptotic Key-Rate Ledger
Section titled “Asymptotic Key-Rate Ledger”For a common efficient BB84 convention, a representative asymptotic rate per emitted pulse pair is
Here
is the probability that both users select the signal intensity and key basis; is the lower bound on signal-pair gain from one photon on each side; bounds the corresponding phase error under the stated proof; and the second term pays error-correction leakage on all accepted signal-pair data. As usual,
The formula is a ledger, not a universal theorem with interchangeable inputs. Some proofs use an explicit phase-error symbol , different normalizations, several Bell labels, or basis-dependent yields. The chosen proof determines how -basis observations bound the -basis phase error and which finite-size terms must be subtracted.
A numerical ledger check
Section titled “A numerical ledger check”Suppose an analysis reports
The quantity inside braces is
If , then secret bits per emitted pulse pair in this asymptotic ledger. Finite-key penalties, authentication cost, source-monitoring overhead, and any unused Bell outcomes still have to be included before interpreting an experimental run.
Finite-Key Form
Section titled “Finite-Key Form”For each basis , intensity pair , and accepted Bell label , Alice and Bob record
the numbers of emitted pulse pairs, accepted announcements, and corrected bit errors. The observed gain and error gain are
Simultaneous confidence regions replace these frequencies by bounds on their unknown expectations. A decoy optimization then applies constraints such as
Photon-number truncation requires adverse treatment of both Poisson tails. Statistical failure probabilities must be allocated across all intensity, basis, and Bell-label classes. Optimizing each class independently and then combining individually extreme values can be unnecessarily loose or even inconsistent; joint constraints preserve relations among observations.
A composable final-length statement has the schematic form
where is a lower bound on accepted key-basis events with one photon from each user, is their phase-error bound, is the actual reconciliation leakage, and contains verification, privacy-amplification, and declared security-parameter terms. Curty et al. gave a composable finite-key analysis against general attacks; later protocols refine estimation and intensity allocation. A paper’s exact formula should be implemented as a whole rather than assembled from favorable terms taken from different proofs.
Optical Bell-State Measurement
Section titled “Optical Bell-State Measurement”An honest relay overlaps Alice’s and Bob’s photons at a balanced beam splitter and resolves output modes with threshold or number-resolving detectors. For two pure single-photon wave packets and , an ideal Hong–Ou–Mandel experiment has coincidence probability
Perfect mode overlap suppresses the coincidence associated with distinguishable photons. In an MDI analyzer, beam-splitter interference plus polarization, phase, or time-bin resolution maps selected coincidence patterns to Bell labels. Standard passive linear optics with vacuum ancillas cannot deterministically distinguish all four dual-rail Bell states; a familiar analyzer identifies at most two and has an intrinsic average success probability no greater than under that model. The detailed hardware boundary belongs to Photonic Qubits.
Alice and Bob use independent lasers, so the arriving pulses must be matched in all degrees of freedom that drive two-photon interference:
- arrival time and pulse duration;
- optical frequency and spectral shape;
- polarization or interferometric reference frame;
- spatial mode and beam-splitter coupling;
- intensity statistics and phase-randomization behavior.
Feedback may track delay, frequency offset, polarization, and interferometer phase. Those controls improve the honest-system QBER but can also create side-channel or correlation assumptions at the sources. A high interference visibility is necessary for performance, not sufficient for security. Weak coherent pulses also include vacuum and multiphoton events, so their raw Hong–Ou–Mandel visibility has a different ideal limit from two deterministic single photons.
Loss and Rate Scaling
Section titled “Loss and Rate Scaling”Let and be channel transmittances from Alice and Bob to the relay, let be the efficiency of each required detector, and let denote the analyzer’s intrinsic accepted-outcome factor. Ignoring background and mismatch, the one-photon-pair yield scales as
For a standard two-state linear-optical analyzer, in the idealized dual-rail model. Consider of fiber on each side. Then
With and ,
For symmetric signal intensities ,
so the idealized signal-pair single-photon gain is
This is a physical scaling check, not a secret-key prediction. Background coincidences, multiphoton terms, mismatch, basis and intensity probabilities, finite statistics, and postprocessing all remain.
For fixed total endpoint separation in uniform fiber, equals the end-to-end channel transmittance. Standard MDI-QKD therefore has repeaterless scaling, with extra Bell-measurement and two-detector costs. It is chosen for a better detector trust boundary, not because it generically beats the pure-loss capacity. Twin-field and phase-matching families use a different single-photon-interference structure to target scaling; they should not be relabeled as ordinary two-photon MDI-QKD.
Asymmetric Links and Networks
Section titled “Asymmetric Links and Networks”A central relay naturally supports a star network: users need transmitters, while expensive detectors can be concentrated at one site that need not be trusted for secrecy. Any pair of users can send to the relay during assigned slots and run independent authenticated postprocessing.
Real networks are asymmetric. If , equal launched intensities generally produce unequal photon fluxes at the beam splitter, reducing interference quality and changing the best decoy constraints. Alice and Bob can choose distinct intensities and probabilities so the arriving single-photon amplitudes and finite samples are useful. Adding attenuation to the shorter arm can restore balance but discards events; joint optimization usually gives a better tradeoff.
Moving the relay changes detector count rates and background balance, but in uniform loss it does not change the product for fixed total distance. Relay placement is therefore a system optimization involving fiber routes, synchronization, detector saturation, background, user access, and operations, not a free change to the asymptotic exponent.
Exact Trust Boundary
Section titled “Exact Trust Boundary”| Component or assumption | Trusted in standard MDI-QKD? | Consequence |
|---|---|---|
| quantum channels to Charles | no | Eve may replace, delay, block, or correlate signals |
| Bell analyzer and detectors | no | any POVM, efficiency, dark count, or fabricated outcome is included in Eve’s operation |
| Alice’s and Bob’s encoded states | yes, within a stated model | basis dependence and preparation flaws must be bounded |
| phase randomization and intensity distributions | yes, within calibration bounds | two-source decoy equations depend on these models |
| random bit, basis, and intensity choices | yes | predictability or leakage can invalidate sampling and secrecy |
| endpoint laboratory isolation | yes | Trojan-horse probes and modulation leakage remain relevant |
| classical channel | public but authenticated | Eve may read it but cannot undetectably alter endpoint transcripts |
| finite-key software and arithmetic | yes | the implemented estimator must match the proved protocol |
| availability of the relay | no | Charles can always cause denial of service |
The phrase “all detector side channels are removed” means that detectors in the untrusted measurement station need not satisfy a secrecy-relevant model. It does not mean every component called a detector anywhere in the system is irrelevant. A source monitor inside Alice’s transmitter, for example, can influence intensity estimates or leak settings and is part of her trusted source apparatus.
Nor does MDI-QKD stop an optical probe from entering an endpoint laboratory. Isolation, filtering, watchdog monitors, and energy bounds are still needed to support the claim that the emitted states match the source model. A relay that sends bright light backward toward the users is already covered as adversarial behavior, but security follows only if the endpoint model bounds the resulting response.
Comparison with Neighboring Protocols
Section titled “Comparison with Neighboring Protocols”| Protocol family | Source trust | Measurement trust | Bell violation required? | Characteristic role |
|---|---|---|---|---|
| decoy-state BB84 | Alice’s source characterized | Bob’s receiver characterized | no | efficient point-to-point prepare-and-measure QKD |
| entanglement-based QKD | source may be untrusted in suitable proofs | endpoint measurements characterized | no, in general | source in channel; users detect locally |
| MDI-QKD | both endpoint sources characterized | central measurement entirely untrusted | no | removes relay-detector side channels |
| device-independent QKD | minimal internal source and measurement characterization | endpoint boxes treated by input-output behavior | yes | secrecy certified from loophole-controlled nonlocality under laboratory assumptions |
MDI-QKD does not use a Bell-inequality violation. “Bell-state measurement” is the name of a joint quantum measurement; “Bell test” is a statistical test of Bell-local models. Confusing them makes MDI-QKD sound device-independent when its security still rests on characterized preparations.
The relay is also not a trusted repeater. It does not learn or reconstruct the final key, and it need not maintain quantum memory. A trusted-relay network, by contrast, extends keys hop by hop through nodes that may handle key material and must remain uncompromised.
Variants and Extensions
Section titled “Variants and Extensions”- Polarization encoding uses actively stabilized polarization states and a polarization Bell analyzer. It makes state geometry direct but requires control of fiber polarization drift.
- Time-bin or phase encoding is naturally compatible with fiber but needs timing alignment and interferometric phase control. Detector click patterns and correction rules depend on the exact analyzer.
- Four-intensity and biased-basis protocols decouple signal generation from parameter-estimation intensities and improve finite-block allocation. Their gains must not be pooled into a simpler protocol’s formulas.
- Asymmetric MDI-QKD gives Alice and Bob independent intensities and probabilities to handle unequal channels and multiuser networks.
- Continuous-variable MDI-QKD sends optical quadrature states to an untrusted Gaussian measurement. Its state model, covariance estimation, and rate formulas are distinct from the discrete-variable protocol here.
- Memory-assisted and multiplexed variants try to avoid requiring two photons to arrive in the same narrow clock window. They add memory loading, heralding, scheduling, and trust assumptions.
Common Mistakes
Section titled “Common Mistakes”Calling MDI-QKD assumption-free
Section titled “Calling MDI-QKD assumption-free”Only the measurement device is removed from the trusted quantum model. Sources, random choices, laboratories, authentication, and classical postprocessing remain assumptions.
Trusting the Bell announcement
Section titled “Trusting the Bell announcement”The relay’s label is data supplied by Eve. Security comes from conditioned statistics and source characterization, not from accepting the label as a certificate that a physical Bell projection occurred.
Applying one-source decoy equations twice
Section titled “Applying one-source decoy equations twice”MDI gains mix photon numbers from two transmitters. The relevant unknown is , and all intensity-pair constraints form one two-dimensional estimation problem.
Equating mode visibility with secrecy
Section titled “Equating mode visibility with secrecy”Good two-photon interference lowers honest-system errors. It does not verify phase randomization, close source side channels, authenticate the transcript, or replace finite-key analysis.
Claiming improved rate-loss scaling
Section titled “Claiming improved rate-loss scaling”Standard two-photon MDI-QKD scales with for a direct end-to-end transmittance . Its principal gain is detector-side-channel removal. Twin-field protocols use a different interference mechanism to change the ideal scaling.
Ignoring failed events
Section titled “Ignoring failed events”Failure probability is part of the rate. Postselection on a Bell outcome is legitimate because it is declared and security-analyzed, but quoting only the conditional QBER or fidelity omits most emitted pulse pairs.
Exercises
Section titled “Exercises”1. Entanglement-swapping identity
Section titled “1. Entanglement-swapping identity”Expand in the computational basis and verify the Bell-basis identity used above.
Solution
In the order ,
Expanding each product and summing over cancels all terms except those four, with the same coefficient. The prefactor then gives the normalized identity.
2. Construct the correction table
Section titled “2. Construct the correction table”Using the four BB84 product states in each matched basis, determine whether Alice’s and Bob’s bits are equal or opposite when the relay reports or .
Solution
In the basis, only opposite-bit products and overlap the subspace, so either label means opposite bits. In the basis,
whereas
Thus means equal bits and means opposite bits. With the convention in the article, Bob flips for both outcomes and for , but not for .
3. Ideal one-photon-pair yield
Section titled “3. Ideal one-photon-pair yield”Reproduce the symmetric-link estimate with , , and . Then find for .
Solution
The accepted yield conditioned on one photon from each side is
Each source emits one photon with probability . Therefore
This excludes background, mismatch, and multiphoton events and is therefore only a scaling check.
4. Infinite-decoy derivative
Section titled “4. Infinite-decoy derivative”Show that the mixed derivative of at gives .
Solution
The generating function is
Differentiating once in each variable gives
At , only survives, so the result is .
5. Evaluate the asymptotic rate
Section titled “5. Evaluate the asymptotic rate”Using the numerical ledger values in the article and , calculate the rate per emitted pulse pair. Which term would change if reconciliation became less efficient?
Solution
The binary entropies are
The privacy contribution minus reconciliation leakage is
Multiplying by gives
secret bits per emitted pulse pair. Worse reconciliation increases and therefore increases the magnitude of the negative second term.
6. A dishonest relay
Section titled “6. A dishonest relay”Charles reports success only when an internal rule predicts low error. Why is this not automatically a break, and what ordering constraint prevents him from selecting after learning the users’ settings?
Solution
The security model already lets Charles choose which rounds succeed as part of Eve’s arbitrary quantum instrument. Alice and Bob estimate security on the conditioned accepted sample, including its rate and basis-intensity statistics. Selective reporting can lower the key rate or cause abort without revealing an accepted key beyond the proof’s bound.
Charles must commit the event and Bell-label record before Alice and Bob disclose basis and intensity choices. Authenticated transcript comparison must also prevent inconsistent lists. If the settings leak first, the sampling model changes and the stated proof no longer applies.
7. Source leakage at one endpoint
Section titled “7. Source leakage at one endpoint”Alice’s signal pulses are longer than her decoy pulses at fixed photon number. Explain why untrusted detectors do not make this harmless.
Solution
The pulse duration lets Eve, who controls the channel and relay, distinguish Alice’s intensity class before announcing an outcome. The shared-yield assumption can fail:
MDI-QKD removes the need to model the relay’s detector response; it does not remove Alice’s source model. Alice must eliminate or characterize the timing leak and use a proof that includes the resulting distinguishability.
8. Asymmetric channels
Section titled “8. Asymmetric channels”Alice’s channel has more loss than Bob’s. Compare adding attenuation to Bob’s arm with optimizing the two launched intensities independently.
Solution
Extra attenuation can balance the arriving mean powers and improve interference, but it deliberately discards Bob’s photons and lowers successful counts. Independent intensities can instead reduce Bob’s launched intensity or increase Alice’s within source and security limits, while preserving more useful finite-sample data. The best choice also depends on multiphoton probabilities, detector saturation, backgrounds, and decoy constraints, so it requires joint rate optimization. Neither strategy changes the fact that the single-photon-pair yield contains the product .
Further Connections
Section titled “Further Connections”- Quantum Key Distribution supplies the composable secrecy definition, authenticated channel, and complete distillation pipeline.
- BB84 owns the four-state preparation alphabet and bit–phase error logic used at the endpoints.
- Decoy-State QKD derives phase-randomized weak-coherent-pulse mixtures and the one-source yield-estimation method generalized here.
- Entanglement Swapping derives the Bell-projection identity, outcome record, and physical success-probability ledger.
- E91 and Entanglement-Based QKD separates source-untrusted, measurement-device-independent, and fully device-independent trust models.
- Device-Independent QKD gives the contrasting Bell-certified black-box model, its stronger laboratory assumptions, and its finite-key entropy ledger.
- Bell States develops Bell-basis correlations and local Pauli conventions.
- Beam Splitters gives the optical mode transformation behind two-photon interference.
- Photon Counting owns detector response, timing, dark events, and number-resolution models as hardware physics, even though the MDI secrecy proof treats relay detectors as untrusted.
- Photonic Qubits develops mode matching, encoding, source, loss, and linear-optical Bell-analyzer constraints.
- Cryptography Case Studies compares detector trust, optical loss, demonstrated rates, and network claims in deployed contexts.
References
Section titled “References”- H.-K. Lo, M. Curty, and B. Qi, “Measurement-Device-Independent Quantum Key Distribution,” Physical Review Letters 108, 130503 (2012), doi:10.1103/PhysRevLett.108.130503.
- S. L. Braunstein and S. Pirandola, “Side-Channel-Free Quantum Key Distribution,” Physical Review Letters 108, 130502 (2012), doi:10.1103/PhysRevLett.108.130502.
- X. Ma, C.-H. F. Fung, and M. Razavi, “Statistical Fluctuation Analysis for Measurement-Device-Independent Quantum Key Distribution,” Physical Review A 86, 052305 (2012), doi:10.1103/PhysRevA.86.052305.
- F. Xu, M. Curty, B. Qi, and H.-K. Lo, “Practical Aspects of Measurement-Device-Independent Quantum Key Distribution,” New Journal of Physics 15, 113007 (2013), doi:10.1088/1367-2630/15/11/113007.
- M. Curty, F. Xu, W. Cui, C. C. W. Lim, K. Tamaki, and H.-K. Lo, “Finite-Key Analysis for Measurement-Device-Independent Quantum Key Distribution,” Nature Communications 5, 3732 (2014), doi:10.1038/ncomms4732.
- A. Rubenok, J. A. Slater, P. Chan, I. Lucio-Martinez, and W. Tittel, “Real-World Two-Photon Interference and Proof-of-Principle Quantum Key Distribution Immune to Detector Attacks,” Physical Review Letters 111, 130501 (2013), doi:10.1103/PhysRevLett.111.130501.
- T. Ferreira da Silva, D. Vitoreti, G. B. Xavier, G. C. do Amaral, G. P. Temporão, and J. P. von der Weid, “Proof-of-Principle Demonstration of Measurement-Device-Independent Quantum Key Distribution Using Polarization Qubits,” Physical Review A 88, 052303 (2013), doi:10.1103/PhysRevA.88.052303.
- Y. Liu, T.-Y. Chen, L.-J. Wang, et al., “Experimental Measurement-Device-Independent Quantum Key Distribution,” Physical Review Letters 111, 130502 (2013), doi:10.1103/PhysRevLett.111.130502.
- Z. Tang, Z. Liao, F. Xu, B. Qi, L. Qian, and H.-K. Lo, “Experimental Demonstration of Polarization Encoding Measurement-Device-Independent Quantum Key Distribution,” Physical Review Letters 112, 190503 (2014), doi:10.1103/PhysRevLett.112.190503.
- Y.-L. Tang, H.-L. Yin, S.-J. Chen, et al., “Measurement-Device-Independent Quantum Key Distribution over 200 km,” Physical Review Letters 113, 190501 (2014), doi:10.1103/PhysRevLett.113.190501.
- H.-L. Yin, T.-Y. Chen, Z.-W. Yu, et al., “Measurement-Device-Independent Quantum Key Distribution over a 404 km Optical Fiber,” Physical Review Letters 117, 190501 (2016), doi:10.1103/PhysRevLett.117.190501.
- L. C. Comandar, M. Lucamarini, B. Fröhlich, et al., “Quantum Key Distribution without Detector Vulnerabilities Using Optically Seeded Lasers,” Nature Photonics 10, 312–315 (2016), doi:10.1038/nphoton.2016.50.
- Y.-H. Zhou, Z.-W. Yu, and X.-B. Wang, “Making the Decoy-State Measurement-Device-Independent Quantum Key Distribution Practically Useful,” Physical Review A 93, 042324 (2016), doi:10.1103/PhysRevA.93.042324.
- R. Valivarthi, I. Lucio-Martinez, P. Chan, et al., “Measurement-Device-Independent Quantum Key Distribution: From Idea towards Application,” Journal of Modern Optics 62, 1141–1150 (2015), doi:10.1080/09500340.2015.1021725.
- J. Calsamiglia and N. Lütkenhaus, “Maximum Efficiency of a Linear-Optical Bell-State Analyzer,” Applied Physics B 72, 67–71 (2001), doi:10.1007/s003400000484.
- C. K. Hong, Z. Y. Ou, and L. Mandel, “Measurement of Subpicosecond Time Intervals between Two Photons by Interference,” Physical Review Letters 59, 2044–2046 (1987), doi:10.1103/PhysRevLett.59.2044.
- F. Xu, X. Ma, Q. Zhang, H.-K. Lo, and J.-W. Pan, “Secure Quantum Key Distribution with Realistic Devices,” Reviews of Modern Physics 92, 025002 (2020), doi:10.1103/RevModPhys.92.025002.
Summary
Section titled “Summary”MDI-QKD turns both users into trusted state preparers and moves the complete measurement apparatus into an untrusted relay. A virtual Bell projection on the traveling systems explains the protocol as time-reversed entanglement-based QKD, while the actual security proof permits the relay to perform any quantum instrument and announce arbitrary outcomes.
With phase-randomized weak coherent pulses, observed intensity-pair gains obey
Two-source decoy estimation bounds the one-photon-pair yield and phase error that supply the privacy term. The architecture removes relay detectors from the trusted secrecy model, but it retains source characterization, private randomness, endpoint isolation, mode matching, authentication, finite statistics, and correct postprocessing. Its standard two-photon form scales with and improves the trust boundary, not the repeaterless loss exponent.