Skip to content

Measurement-Device-Independent QKD

Measurement-device-independent quantum key distribution (MDI-QKD) is a QKD architecture in which Alice and Bob prepare quantum states and send them to an untrusted intermediate station that performs a joint measurement. The station, conventionally called Charles, publicly reports a Bell-state measurement outcome or failure. Alice and Bob use the successful reports, their private preparation choices, and authenticated classical postprocessing to distill a key.

The defining security move is to place the entire measurement station inside Eve’s domain. Its optics, detectors, timing logic, efficiency, dark counts, and classical outcome generator need not follow a trusted device model. A malicious station may suppress events, fabricate labels, or coordinate with the quantum channels. It may force an abort, but accepted data must still obey the security proof’s statistical tests before yielding a key.

MDI-QKD is not fully device-independent. Alice’s and Bob’s sources, random choices, laboratory isolation, phase randomization, intensity distributions, and state encoders remain characterized. It also needs the ordinary composable QKD contract, authentication, finite-key analysis, reconciliation, verification, and privacy amplification developed in Quantum Key Distribution. This page is the canonical home of the untrusted-relay protocol, its time-reversed entanglement interpretation, its two-source decoy equations, and its detector-versus-source trust boundary.

In standard prepare-and-measure BB84, the quantum channel terminates at Bob’s receiver. A security proof therefore needs a model of his basis selector, detection efficiencies, time gates, double-click rules, dead time, and all optical modes that influence acceptance. Real single-photon detectors have supported attacks based on efficiency mismatch, timing, wavelength response, bright-light control, afterpulsing, and other behavior absent from simplified POVM models.

MDI-QKD changes the interface rather than attempting to enumerate every detector imperfection. Both legitimate users become transmitters. Everything that receives their quantum signals is placed outside their trusted laboratories and may be operated by Eve. The security proof is conditioned on the relay’s public classical report, whatever physical process produced it.

This removes detector behavior from the trusted secrecy boundary, but not from performance. Poor detectors lower the successful-event rate and raise the observed error rate. Eve can always deny service by reporting failure. What she cannot do, under the source and protocol assumptions, is use hidden detector behavior to learn a key that passes the tests.

Alice and Bob send prepared optical pulses into an untrusted network and Bell-state measurement station, then distill a key from authenticated public data.

The MDI-QKD trust boundary. State preparation and private random choices stay inside Alice’s and Bob’s laboratories. Both quantum channels, the Bell analyzer, detectors, and outcome electronics are adversarial. The relay’s outcome must be fixed before basis and intensity disclosure; authenticated postprocessing then either produces a shared key or aborts.

Consider a polarization or time-bin BB84 implementation with phase-randomized weak coherent pulses. A precise finite protocol fixes all probabilities, acceptance windows, and abort rules in advance. One round has the following structure.

  1. Alice chooses a bit xAx_A, basis wA∈{Z,X}w_A\in\{Z,X\}, and intensity aa.
  2. Bob independently chooses xBx_B, wBw_B, and intensity bb.
  3. Each prepares the corresponding optical BB84 state, randomizes its global phase according to the source model, and sends it toward Charles.
  4. Charles announces an outcome z∈{Ψ−,Ψ+,∅}z\in\{\Psi^-,\Psi^+,\varnothing\}, where ∅\varnothing denotes failure. The supported Bell labels depend on the analyzer.
  5. Only after the outcome record is fixed do Alice and Bob disclose the basis and intensity labels over authenticated classical communication.
  6. They retain declared successful classes, apply a Bell-label-dependent bit correction, and separate key-generating data from parameter-estimation data.
  7. Two-source decoy analysis bounds single-photon-pair detections and their phase errors. Alice and Bob then reconcile, verify, and privacy-amplify.

The relay does not need an identity that Alice and Bob trust. In a network it may be a service provider, an intermediate user, or Eve herself. Alice and Bob do need a consistent authenticated transcript. If Charles sends different outcome lists to the two endpoints, transcript comparison or authentication must expose the inconsistency before key acceptance.

The time ordering matters. If basis, bit, or intensity information reaches the relay before its successful-event record is committed, the relay can postselect with knowledge that the proof treats as unavailable. Physical and software implementations therefore need a defined event boundary, not merely a diagram with arrows in the desired order.

The security intuition comes from a source-replacement construction. Imagine that Alice prepares ∣Φ+⟩AA′|\Phi^+\rangle_{AA'} and Bob prepares ∣Φ+⟩B′B|\Phi^+\rangle_{B'B}. They retain AA and BB while sending A′A' and B′B' to Charles. The entanglement-swapping identity is

∣Φ+⟩AA′∣Φ+⟩B′B=12(∣Φ+⟩AB∣Φ+⟩A′B′+∣Φ−⟩AB∣Φ−⟩A′B′+∣Ψ+⟩AB∣Ψ+⟩A′B′+∣Ψ−⟩AB∣Ψ−⟩A′B′).\begin{aligned} |\Phi^+\rangle_{AA'}|\Phi^+\rangle_{B'B} =\frac12\big(& |\Phi^+\rangle_{AB}|\Phi^+\rangle_{A'B'} +|\Phi^-\rangle_{AB}|\Phi^-\rangle_{A'B'}\\ &+|\Psi^+\rangle_{AB}|\Psi^+\rangle_{A'B'} +|\Psi^-\rangle_{AB}|\Psi^-\rangle_{A'B'} \big). \end{aligned}

An ideal Bell projection on A′B′A'B' therefore projects the retained systems ABAB into the corresponding Bell state. Alice and Bob could then measure AA and BB to obtain correlated bits. Because their local measurements commute with Charles’s remote operation, they may instead measure first. That early measurement remotely prepares the BB84 states sent in the actual prepare-and-measure implementation.

For this reason MDI-QKD is often called time-reversed entanglement-based QKD. No macroscopic reversal of time occurs. The phrase refers to exchanging the operational order of local state preparation and the middle Bell projection in an equivalent virtual protocol. The full algebra and Pauli frame of entanglement swapping remain canonical in Entanglement Swapping.

Why an untrusted projection can still help

Section titled “Why an untrusted projection can still help”

If Charles performs the advertised Bell measurement honestly, the virtual picture is literal. Security does not assume that honesty. A general attack replaces the Bell analyzer by an arbitrary quantum instrument controlled by Eve, with an arbitrary public output zz. Alice and Bob condition on zz and test the resulting correlations.

This is analogous to treating the quantum channel as adversarial in ordinary QKD, but the adversarial map now includes measurement and detection. The proof does not infer that Charles created entanglement merely because he said “Ψ−\Psi^-.” It bounds Eve’s information from the complete observed data and the trusted source states. Dishonest outcome labels either reproduce statistics compatible with a secure conditional state or reduce the certified key length.

Use

∣Ψ±⟩=∣01⟩±∣10⟩2,∣Φ±⟩=∣00⟩±∣11⟩2.|\Psi^\pm\rangle = \frac{|01\rangle\pm|10\rangle}{\sqrt2}, \qquad |\Phi^\pm\rangle = \frac{|00\rangle\pm|11\rangle}{\sqrt2}.

Many linear-optical analyzers report one or both Ψ\Psi outcomes. The following product-state decompositions make the classical correction rule transparent:

∣0⟩∣1⟩=∣Ψ+⟩+∣Ψ−⟩2,∣1⟩∣0⟩=∣Ψ+⟩−∣Ψ−⟩2,|0\rangle|1\rangle = \frac{|\Psi^+\rangle+|\Psi^-\rangle}{\sqrt2}, \qquad |1\rangle|0\rangle = \frac{|\Psi^+\rangle-|\Psi^-\rangle}{\sqrt2}, ∣+⟩∣+⟩=∣Φ+⟩+∣Ψ+⟩2,∣+⟩∣−⟩=∣Φ−⟩−∣Ψ−⟩2.|+\rangle|+\rangle = \frac{|\Phi^+\rangle+|\Psi^+\rangle}{\sqrt2}, \qquad |+\rangle|-\rangle = \frac{|\Phi^-\rangle-|\Psi^-\rangle}{\sqrt2}.

With bit 00 encoded as ∣0⟩|0\rangle or ∣+⟩|+\rangle and bit 11 as ∣1⟩|1\rangle or ∣−⟩|-\rangle, Bob can use this correction table:

Shared basisReported outcomeIdeal relation before correctionBob’s action
ZZΨ−\Psi^-opposite bitsflip
ZZΨ+\Psi^+opposite bitsflip
XXΨ−\Psi^-opposite bitsflip
XXΨ+\Psi^+equal bitsno flip

The table depends on Bell-state phases, bit encoding, detector labeling, and which party corrects. A real protocol must publish one convention and test it against known state pairs. Some implementations accept only Ψ−\Psi^-, which simplifies the rule at the cost of fewer successful outcomes.

After correction, an error is a disagreement between Alice’s bit and Bob’s corrected bit. Mismatched-basis events are normally discarded rather than forced into this table.

Practical MDI-QKD usually combines the untrusted measurement with decoy-state sources. If ρxA,wA(n)\rho_{x_A,w_A}^{(n)} is Alice’s encoded nn-photon state, then her phase-randomized pulse of intensity aa is

ρa,xA,wA=∑n=0∞pn(a)ρxA,wA(n).\rho_{a,x_A,w_A} = \sum_{n=0}^{\infty} p_n(a)\rho_{x_A,w_A}^{(n)}.

Alice’s pulse and Bob’s independently randomized pulse of intensity bb have the joint decomposition

ρa,xA,wA⊗ρb,xB,wB=∑n,m=0∞pn(a)pm(b)ρxA,wA(n)⊗ρxB,wB(m),\rho_{a,x_A,w_A}\otimes\rho_{b,x_B,w_B} = \sum_{n,m=0}^{\infty} p_n(a)p_m(b) \rho_{x_A,w_A}^{(n)}\otimes\rho_{x_B,w_B}^{(m)},

where

pn(a)=e−aann!,pm(b)=e−bbmm!.p_n(a)=e^{-a}\frac{a^n}{n!}, \qquad p_m(b)=e^{-b}\frac{b^m}{m!}.

For basis ww, define the pair yield

Ynmw:=Pr⁡(accepted Bell report∣n,m,w),Y_{nm}^{w} := \Pr(\text{accepted Bell report}\mid n,m,w),

and the corrected error rate

enmw:=Pr⁡(bit error∣n,m,w,accepted).e_{nm}^{w} := \Pr(\text{bit error}\mid n,m,w,\text{accepted}).

The measured gain and error gain for intensity pair (a,b)(a,b) are

Qabw=∑n,m=0∞pn(a)pm(b)Ynmw,Q_{ab}^{w} = \sum_{n,m=0}^{\infty} p_n(a)p_m(b)Y_{nm}^{w}, Tabw:=EabwQabw=∑n,m=0∞pn(a)pm(b)Ynmwenmw.T_{ab}^{w} := E_{ab}^{w}Q_{ab}^{w} = \sum_{n,m=0}^{\infty} p_n(a)p_m(b)Y_{nm}^{w}e_{nm}^{w}.

The security-relevant sector has one photon from Alice and one from Bob:

(n,m)=(1,1).(n,m)=(1,1).

For signal intensities sAs_A and sBs_B, its gain is

Q11w=sAe−sAsBe−sBY11w.Q_{11}^{w} = s_Ae^{-s_A}s_Be^{-s_B}Y_{11}^{w}.

The shared-yield assumption now applies independently to both transmitters. Given nn and Alice’s encoded state, her signal and decoy pulses must be indistinguishable in every unmodeled degree of freedom; the analogous statement holds for Bob. Otherwise the correct unknown is Ynm,abwY_{nm,ab}^{w}, and cross-intensity constraints can fail.

Removing the Poisson factors gives

Sabw:=ea+bQabw=∑n,m=0∞ann!bmm!Ynmw.S_{ab}^{w} := e^{a+b}Q_{ab}^{w} = \sum_{n,m=0}^{\infty} \frac{a^n}{n!}\frac{b^m}{m!}Y_{nm}^{w}.

In an ideal continuum-intensity limit,

Ynmw=∂n+mSabw∂an∂bm∣a=b=0.Y_{nm}^{w} = \left. \frac{\partial^{n+m}S_{ab}^{w}} {\partial a^n\partial b^m} \right|_{a=b=0}.

Finite protocols use a few intensity pairs and statistical intervals. They minimize Y11wY_{11}^{w} and maximize the relevant e11we_{11}^{w} subject to all gain and error-gain constraints, physical bounds, intensity calibration, and Poisson tails. This is the two-source extension of the estimator derived in Decoy-State QKD, not two unrelated one-dimensional fits.

Vacuum settings are especially useful because (0,b)(0,b) and (a,0)(a,0) data separate background and one-sided emissions from true two-sided interference. Efficient designs may use different signal and decoy intensities in the two bases, but the resulting basis-intensity table must be kept intact in the proof.

For a common efficient BB84 convention, a representative asymptotic rate per emitted pulse pair is

R≥q{Q11Z,L[1−h2 ⁣(e11X,U)]−QsAsBZfECh2 ⁣(EsAsBZ)}.R \ge q\left\{ Q_{11}^{Z,\mathrm L} \left[1-h_2\!\left(e_{11}^{X,\mathrm U}\right)\right] -Q_{s_As_B}^{Z} f_{\mathrm{EC}}h_2\!\left(E_{s_As_B}^{Z}\right) \right\}.

Here

q=psApsBpZApZBq = p_{s_A}p_{s_B}p_Z^Ap_Z^B

is the probability that both users select the signal intensity and key basis; Q11Z,LQ_{11}^{Z,\mathrm L} is the lower bound on signal-pair gain from one photon on each side; e11X,Ue_{11}^{X,\mathrm U} bounds the corresponding phase error under the stated proof; and the second term pays error-correction leakage on all accepted signal-pair data. As usual,

h2(x)=−xlog⁡2x−(1−x)log⁡2(1−x).h_2(x) = -x\log_2x-(1-x)\log_2(1-x).

The formula is a ledger, not a universal theorem with interchangeable inputs. Some proofs use an explicit phase-error symbol ϕ11Z\phi_{11}^{Z}, different normalizations, several Bell labels, or basis-dependent yields. The chosen proof determines how XX-basis observations bound the ZZ-basis phase error and which finite-size terms must be subtracted.

Suppose an analysis reports

Q11Z,L=2.30×10−4,e11X,U=0.015,Q_{11}^{Z,\mathrm L}=2.30\times10^{-4}, \qquad e_{11}^{X,\mathrm U}=0.015, QsAsBZ=3.00×10−4,EsAsBZ=0.020,fEC=1.16.Q_{s_As_B}^{Z}=3.00\times10^{-4}, \qquad E_{s_As_B}^{Z}=0.020, \qquad f_{\mathrm{EC}}=1.16.

The quantity inside braces is

Q11Z,L[1−h2(e11X,U)]−QsAsBZfECh2(EsAsBZ)=1.54936×10−4.\begin{aligned} &Q_{11}^{Z,\mathrm L} \left[1-h_2(e_{11}^{X,\mathrm U})\right] -Q_{s_As_B}^{Z}f_{\mathrm{EC}}h_2(E_{s_As_B}^{Z})\\ &\qquad= 1.54936\times10^{-4}. \end{aligned}

If q=1/4q=1/4, then R≥3.87339×10−5R\ge3.87339\times10^{-5} secret bits per emitted pulse pair in this asymptotic ledger. Finite-key penalties, authentication cost, source-monitoring overhead, and any unused Bell outcomes still have to be included before interpreting an experimental run.

For each basis ww, intensity pair (a,b)(a,b), and accepted Bell label zz, Alice and Bob record

Nabw,z,nabw,z,mabw,z,N_{ab}^{w,z}, \qquad n_{ab}^{w,z}, \qquad m_{ab}^{w,z},

the numbers of emitted pulse pairs, accepted announcements, and corrected bit errors. The observed gain and error gain are

Q^abw,z=nabw,zNabw,z,T^abw,z=mabw,zNabw,z.\widehat Q_{ab}^{w,z} = \frac{n_{ab}^{w,z}}{N_{ab}^{w,z}}, \qquad \widehat T_{ab}^{w,z} = \frac{m_{ab}^{w,z}}{N_{ab}^{w,z}}.

Simultaneous confidence regions replace these frequencies by bounds on their unknown expectations. A decoy optimization then applies constraints such as

Q‾abw,z≤∑n,mpn(a)pm(b)Ynmw,z≤Q‾abw,z,\underline Q_{ab}^{w,z} \le \sum_{n,m}p_n(a)p_m(b)Y_{nm}^{w,z} \le \overline Q_{ab}^{w,z}, T‾abw,z≤∑n,mpn(a)pm(b)Ynmw,zenmw,z≤T‾abw,z.\underline T_{ab}^{w,z} \le \sum_{n,m}p_n(a)p_m(b)Y_{nm}^{w,z}e_{nm}^{w,z} \le \overline T_{ab}^{w,z}.

Photon-number truncation requires adverse treatment of both Poisson tails. Statistical failure probabilities must be allocated across all intensity, basis, and Bell-label classes. Optimizing each class independently and then combining individually extreme values can be unnecessarily loose or even inconsistent; joint constraints preserve relations among observations.

A composable final-length statement has the schematic form

ℓ≤s11,ZL[1−h2 ⁣(ϕ11,ZU)]−λEC−Δsec,\ell \le s_{11,Z}^{\mathrm L} \left[1-h_2\!\left(\phi_{11,Z}^{\mathrm U}\right)\right] -\lambda_{\mathrm{EC}} -\Delta_{\mathrm{sec}},

where s11,ZLs_{11,Z}^{\mathrm L} is a lower bound on accepted key-basis events with one photon from each user, ϕ11,ZU\phi_{11,Z}^{\mathrm U} is their phase-error bound, λEC\lambda_{\mathrm{EC}} is the actual reconciliation leakage, and Δsec\Delta_{\mathrm{sec}} contains verification, privacy-amplification, and declared security-parameter terms. Curty et al. gave a composable finite-key analysis against general attacks; later protocols refine estimation and intensity allocation. A paper’s exact formula should be implemented as a whole rather than assembled from favorable terms taken from different proofs.

An honest relay overlaps Alice’s and Bob’s photons at a balanced beam splitter and resolves output modes with threshold or number-resolving detectors. For two pure single-photon wave packets ∣u⟩|u\rangle and ∣v⟩|v\rangle, an ideal Hong–Ou–Mandel experiment has coincidence probability

Pcoin=12(1−∣⟨u∣v⟩∣2).P_{\mathrm{coin}} = \frac12\left(1-|\langle u|v\rangle|^2\right).

Perfect mode overlap suppresses the coincidence associated with distinguishable photons. In an MDI analyzer, beam-splitter interference plus polarization, phase, or time-bin resolution maps selected coincidence patterns to Bell labels. Standard passive linear optics with vacuum ancillas cannot deterministically distinguish all four dual-rail Bell states; a familiar analyzer identifies at most two and has an intrinsic average success probability no greater than 1/21/2 under that model. The detailed hardware boundary belongs to Photonic Qubits.

Alice and Bob use independent lasers, so the arriving pulses must be matched in all degrees of freedom that drive two-photon interference:

  • arrival time and pulse duration;
  • optical frequency and spectral shape;
  • polarization or interferometric reference frame;
  • spatial mode and beam-splitter coupling;
  • intensity statistics and phase-randomization behavior.

Feedback may track delay, frequency offset, polarization, and interferometer phase. Those controls improve the honest-system QBER but can also create side-channel or correlation assumptions at the sources. A high interference visibility is necessary for performance, not sufficient for security. Weak coherent pulses also include vacuum and multiphoton events, so their raw Hong–Ou–Mandel visibility has a different ideal limit from two deterministic single photons.

Let ηA\eta_A and ηB\eta_B be channel transmittances from Alice and Bob to the relay, let ηd\eta_d be the efficiency of each required detector, and let cBSMc_{\mathrm{BSM}} denote the analyzer’s intrinsic accepted-outcome factor. Ignoring background and mismatch, the one-photon-pair yield scales as

Y11∼cBSMηAηBηd2.Y_{11} \sim c_{\mathrm{BSM}}\eta_A\eta_B\eta_d^2.

For a standard two-state linear-optical analyzer, cBSM≤1/2c_{\mathrm{BSM}}\le1/2 in the idealized dual-rail model. Consider 50 km50\ \mathrm{km} of 0.20 dB/km0.20\ \mathrm{dB/km} fiber on each side. Then

ηA=ηB=10−10/10=0.1.\eta_A=\eta_B=10^{-10/10}=0.1.

With ηd=0.8\eta_d=0.8 and cBSM=1/2c_{\mathrm{BSM}}=1/2,

Y11≈12(0.1)(0.1)(0.8)2=3.2×10−3.Y_{11} \approx \frac12(0.1)(0.1)(0.8)^2 = 3.2\times10^{-3}.

For symmetric signal intensities sA=sB=0.4s_A=s_B=0.4,

p1(0.4)2=(0.4e−0.4)2≈7.19×10−2,p_1(0.4)^2 = \left(0.4e^{-0.4}\right)^2 \approx 7.19\times10^{-2},

so the idealized signal-pair single-photon gain is

Q11≈2.30×10−4.Q_{11} \approx 2.30\times10^{-4}.

This is a physical scaling check, not a secret-key prediction. Background coincidences, multiphoton terms, mismatch, basis and intensity probabilities, finite statistics, and postprocessing all remain.

For fixed total endpoint separation in uniform fiber, ηAηB\eta_A\eta_B equals the end-to-end channel transmittance. Standard MDI-QKD therefore has O(η)O(\eta) repeaterless scaling, with extra Bell-measurement and two-detector costs. It is chosen for a better detector trust boundary, not because it generically beats the pure-loss capacity. Twin-field and phase-matching families use a different single-photon-interference structure to target O(η)O(\sqrt\eta) scaling; they should not be relabeled as ordinary two-photon MDI-QKD.

A central relay naturally supports a star network: users need transmitters, while expensive detectors can be concentrated at one site that need not be trusted for secrecy. Any pair of users can send to the relay during assigned slots and run independent authenticated postprocessing.

Real networks are asymmetric. If ηA≠ηB\eta_A\ne\eta_B, equal launched intensities generally produce unequal photon fluxes at the beam splitter, reducing interference quality and changing the best decoy constraints. Alice and Bob can choose distinct intensities and probabilities so the arriving single-photon amplitudes and finite samples are useful. Adding attenuation to the shorter arm can restore balance but discards events; joint optimization usually gives a better tradeoff.

Moving the relay changes detector count rates and background balance, but in uniform loss it does not change the product ηAηB\eta_A\eta_B for fixed total distance. Relay placement is therefore a system optimization involving fiber routes, synchronization, detector saturation, background, user access, and operations, not a free change to the asymptotic exponent.

Component or assumptionTrusted in standard MDI-QKD?Consequence
quantum channels to CharlesnoEve may replace, delay, block, or correlate signals
Bell analyzer and detectorsnoany POVM, efficiency, dark count, or fabricated outcome is included in Eve’s operation
Alice’s and Bob’s encoded statesyes, within a stated modelbasis dependence and preparation flaws must be bounded
phase randomization and intensity distributionsyes, within calibration boundstwo-source decoy equations depend on these models
random bit, basis, and intensity choicesyespredictability or leakage can invalidate sampling and secrecy
endpoint laboratory isolationyesTrojan-horse probes and modulation leakage remain relevant
classical channelpublic but authenticatedEve may read it but cannot undetectably alter endpoint transcripts
finite-key software and arithmeticyesthe implemented estimator must match the proved protocol
availability of the relaynoCharles can always cause denial of service

The phrase “all detector side channels are removed” means that detectors in the untrusted measurement station need not satisfy a secrecy-relevant model. It does not mean every component called a detector anywhere in the system is irrelevant. A source monitor inside Alice’s transmitter, for example, can influence intensity estimates or leak settings and is part of her trusted source apparatus.

Nor does MDI-QKD stop an optical probe from entering an endpoint laboratory. Isolation, filtering, watchdog monitors, and energy bounds are still needed to support the claim that the emitted states match the source model. A relay that sends bright light backward toward the users is already covered as adversarial behavior, but security follows only if the endpoint model bounds the resulting response.

Protocol familySource trustMeasurement trustBell violation required?Characteristic role
decoy-state BB84Alice’s source characterizedBob’s receiver characterizednoefficient point-to-point prepare-and-measure QKD
entanglement-based QKDsource may be untrusted in suitable proofsendpoint measurements characterizedno, in generalsource in channel; users detect locally
MDI-QKDboth endpoint sources characterizedcentral measurement entirely untrustednoremoves relay-detector side channels
device-independent QKDminimal internal source and measurement characterizationendpoint boxes treated by input-output behavioryessecrecy certified from loophole-controlled nonlocality under laboratory assumptions

MDI-QKD does not use a Bell-inequality violation. “Bell-state measurement” is the name of a joint quantum measurement; “Bell test” is a statistical test of Bell-local models. Confusing them makes MDI-QKD sound device-independent when its security still rests on characterized preparations.

The relay is also not a trusted repeater. It does not learn or reconstruct the final key, and it need not maintain quantum memory. A trusted-relay network, by contrast, extends keys hop by hop through nodes that may handle key material and must remain uncompromised.

  • Polarization encoding uses actively stabilized polarization states and a polarization Bell analyzer. It makes state geometry direct but requires control of fiber polarization drift.
  • Time-bin or phase encoding is naturally compatible with fiber but needs timing alignment and interferometric phase control. Detector click patterns and correction rules depend on the exact analyzer.
  • Four-intensity and biased-basis protocols decouple signal generation from parameter-estimation intensities and improve finite-block allocation. Their gains must not be pooled into a simpler protocol’s formulas.
  • Asymmetric MDI-QKD gives Alice and Bob independent intensities and probabilities to handle unequal channels and multiuser networks.
  • Continuous-variable MDI-QKD sends optical quadrature states to an untrusted Gaussian measurement. Its state model, covariance estimation, and rate formulas are distinct from the discrete-variable protocol here.
  • Memory-assisted and multiplexed variants try to avoid requiring two photons to arrive in the same narrow clock window. They add memory loading, heralding, scheduling, and trust assumptions.

Only the measurement device is removed from the trusted quantum model. Sources, random choices, laboratories, authentication, and classical postprocessing remain assumptions.

The relay’s label is data supplied by Eve. Security comes from conditioned statistics and source characterization, not from accepting the label as a certificate that a physical Bell projection occurred.

MDI gains mix photon numbers from two transmitters. The relevant unknown is YnmY_{nm}, and all intensity-pair constraints form one two-dimensional estimation problem.

Good two-photon interference lowers honest-system errors. It does not verify phase randomization, close source side channels, authenticate the transcript, or replace finite-key analysis.

Standard two-photon MDI-QKD scales with ηAηB=η\eta_A\eta_B=\eta for a direct end-to-end transmittance η\eta. Its principal gain is detector-side-channel removal. Twin-field protocols use a different interference mechanism to change the ideal scaling.

Failure probability is part of the rate. Postselection on a Bell outcome is legitimate because it is declared and security-analyzed, but quoting only the conditional QBER or fidelity omits most emitted pulse pairs.

Expand ∣Φ+⟩AA′∣Φ+⟩B′B|\Phi^+\rangle_{AA'}|\Phi^+\rangle_{B'B} in the computational basis and verify the Bell-basis identity used above.

Solution

In the order A,A′,B′,BA,A',B',B,

∣Φ+⟩AA′∣Φ+⟩B′B=12(∣0000⟩+∣0011⟩+∣1100⟩+∣1111⟩).|\Phi^+\rangle_{AA'}|\Phi^+\rangle_{B'B} = \frac12 \left(|0000\rangle+|0011\rangle+|1100\rangle+|1111\rangle\right).

Expanding each product ∣β⟩AB∣β⟩A′B′|\beta\rangle_{AB}|\beta\rangle_{A'B'} and summing over β∈{Φ+,Φ−,Ψ+,Ψ−}\beta\in\{\Phi^+,\Phi^-,\Psi^+,\Psi^-\} cancels all terms except those four, with the same coefficient. The prefactor 1/21/2 then gives the normalized identity.

Using the four BB84 product states in each matched basis, determine whether Alice’s and Bob’s bits are equal or opposite when the relay reports Ψ−\Psi^- or Ψ+\Psi^+.

Solution

In the ZZ basis, only opposite-bit products ∣01⟩|01\rangle and ∣10⟩|10\rangle overlap the Ψ\Psi subspace, so either Ψ\Psi label means opposite bits. In the XX basis,

∣++⟩,∣−−⟩overlap ∣Ψ+⟩,|++\rangle,|--\rangle \quad\text{overlap }|\Psi^+\rangle,

whereas

∣+−⟩,∣−+⟩overlap ∣Ψ−⟩.|+-\rangle,|-+\rangle \quad\text{overlap }|\Psi^-\rangle.

Thus Ψ+\Psi^+ means equal XX bits and Ψ−\Psi^- means opposite XX bits. With the convention in the article, Bob flips for both ZZ outcomes and for X,Ψ−X,\Psi^-, but not for X,Ψ+X,\Psi^+.

Reproduce the 100 km100\ \mathrm{km} symmetric-link estimate with ηA=ηB=0.1\eta_A=\eta_B=0.1, ηd=0.8\eta_d=0.8, and cBSM=1/2c_{\mathrm{BSM}}=1/2. Then find Q11Q_{11} for sA=sB=0.4s_A=s_B=0.4.

Solution

The accepted yield conditioned on one photon from each side is

Y11≈12(0.1)(0.1)(0.8)2=0.0032.Y_{11} \approx \frac12(0.1)(0.1)(0.8)^2 = 0.0032.

Each source emits one photon with probability p1(0.4)=0.4e−0.4≈0.26813p_1(0.4)=0.4e^{-0.4}\approx0.26813. Therefore

Q11=p1(0.4)2Y11≈(0.26813)2(0.0032)=2.30×10−4.Q_{11} = p_1(0.4)^2Y_{11} \approx (0.26813)^2(0.0032) = 2.30\times10^{-4}.

This excludes background, mismatch, and multiphoton events and is therefore only a scaling check.

Show that the mixed derivative of Sab=ea+bQabS_{ab}=e^{a+b}Q_{ab} at a=b=0a=b=0 gives Y11Y_{11}.

Solution

The generating function is

Sab=∑n,m=0∞ann!bmm!Ynm.S_{ab} = \sum_{n,m=0}^{\infty} \frac{a^n}{n!}\frac{b^m}{m!}Y_{nm}.

Differentiating once in each variable gives

∂2Sab∂a∂b=∑n,m≥1an−1(n−1)!bm−1(m−1)!Ynm.\frac{\partial^2S_{ab}}{\partial a\partial b} = \sum_{n,m\ge1} \frac{a^{n-1}}{(n-1)!} \frac{b^{m-1}}{(m-1)!}Y_{nm}.

At a=b=0a=b=0, only n=m=1n=m=1 survives, so the result is Y11Y_{11}.

Using the numerical ledger values in the article and q=1/4q=1/4, calculate the rate per emitted pulse pair. Which term would change if reconciliation became less efficient?

Solution

The binary entropies are

h2(0.015)=0.112361,h2(0.020)=0.141441.h_2(0.015)=0.112361, \qquad h_2(0.020)=0.141441.

The privacy contribution minus reconciliation leakage is

2.30×10−4(1−0.112361)−(3.00×10−4)(1.16)(0.141441)=1.54936×10−4.2.30\times10^{-4}(1-0.112361) -(3.00\times10^{-4})(1.16)(0.141441) = 1.54936\times10^{-4}.

Multiplying by q=1/4q=1/4 gives

R=3.87339×10−5R = 3.87339\times10^{-5}

secret bits per emitted pulse pair. Worse reconciliation increases fECf_{\mathrm{EC}} and therefore increases the magnitude of the negative second term.

Charles reports success only when an internal rule predicts low error. Why is this not automatically a break, and what ordering constraint prevents him from selecting after learning the users’ settings?

Solution

The security model already lets Charles choose which rounds succeed as part of Eve’s arbitrary quantum instrument. Alice and Bob estimate security on the conditioned accepted sample, including its rate and basis-intensity statistics. Selective reporting can lower the key rate or cause abort without revealing an accepted key beyond the proof’s bound.

Charles must commit the event and Bell-label record before Alice and Bob disclose basis and intensity choices. Authenticated transcript comparison must also prevent inconsistent lists. If the settings leak first, the sampling model changes and the stated proof no longer applies.

Alice’s signal pulses are 30 ps30\ \mathrm{ps} longer than her decoy pulses at fixed photon number. Explain why untrusted detectors do not make this harmless.

Solution

The pulse duration lets Eve, who controls the channel and relay, distinguish Alice’s intensity class before announcing an outcome. The shared-yield assumption can fail:

Ynm,abw≠Ynm,a′bw.Y_{nm,a b}^{w} \ne Y_{nm,a' b}^{w}.

MDI-QKD removes the need to model the relay’s detector response; it does not remove Alice’s source model. Alice must eliminate or characterize the timing leak and use a proof that includes the resulting distinguishability.

Alice’s channel has 6 dB6\ \mathrm{dB} more loss than Bob’s. Compare adding 6 dB6\ \mathrm{dB} attenuation to Bob’s arm with optimizing the two launched intensities independently.

Solution

Extra attenuation can balance the arriving mean powers and improve interference, but it deliberately discards Bob’s photons and lowers successful counts. Independent intensities can instead reduce Bob’s launched intensity or increase Alice’s within source and security limits, while preserving more useful finite-sample data. The best choice also depends on multiphoton probabilities, detector saturation, backgrounds, and decoy constraints, so it requires joint rate optimization. Neither strategy changes the fact that the single-photon-pair yield contains the product ηAηB\eta_A\eta_B.

  • Quantum Key Distribution supplies the composable secrecy definition, authenticated channel, and complete distillation pipeline.
  • BB84 owns the four-state preparation alphabet and bit–phase error logic used at the endpoints.
  • Decoy-State QKD derives phase-randomized weak-coherent-pulse mixtures and the one-source yield-estimation method generalized here.
  • Entanglement Swapping derives the Bell-projection identity, outcome record, and physical success-probability ledger.
  • E91 and Entanglement-Based QKD separates source-untrusted, measurement-device-independent, and fully device-independent trust models.
  • Device-Independent QKD gives the contrasting Bell-certified black-box model, its stronger laboratory assumptions, and its finite-key entropy ledger.
  • Bell States develops Bell-basis correlations and local Pauli conventions.
  • Beam Splitters gives the optical mode transformation behind two-photon interference.
  • Photon Counting owns detector response, timing, dark events, and number-resolution models as hardware physics, even though the MDI secrecy proof treats relay detectors as untrusted.
  • Photonic Qubits develops mode matching, encoding, source, loss, and linear-optical Bell-analyzer constraints.
  • Cryptography Case Studies compares detector trust, optical loss, demonstrated rates, and network claims in deployed contexts.
  1. H.-K. Lo, M. Curty, and B. Qi, “Measurement-Device-Independent Quantum Key Distribution,” Physical Review Letters 108, 130503 (2012), doi:10.1103/PhysRevLett.108.130503.
  2. S. L. Braunstein and S. Pirandola, “Side-Channel-Free Quantum Key Distribution,” Physical Review Letters 108, 130502 (2012), doi:10.1103/PhysRevLett.108.130502.
  3. X. Ma, C.-H. F. Fung, and M. Razavi, “Statistical Fluctuation Analysis for Measurement-Device-Independent Quantum Key Distribution,” Physical Review A 86, 052305 (2012), doi:10.1103/PhysRevA.86.052305.
  4. F. Xu, M. Curty, B. Qi, and H.-K. Lo, “Practical Aspects of Measurement-Device-Independent Quantum Key Distribution,” New Journal of Physics 15, 113007 (2013), doi:10.1088/1367-2630/15/11/113007.
  5. M. Curty, F. Xu, W. Cui, C. C. W. Lim, K. Tamaki, and H.-K. Lo, “Finite-Key Analysis for Measurement-Device-Independent Quantum Key Distribution,” Nature Communications 5, 3732 (2014), doi:10.1038/ncomms4732.
  6. A. Rubenok, J. A. Slater, P. Chan, I. Lucio-Martinez, and W. Tittel, “Real-World Two-Photon Interference and Proof-of-Principle Quantum Key Distribution Immune to Detector Attacks,” Physical Review Letters 111, 130501 (2013), doi:10.1103/PhysRevLett.111.130501.
  7. T. Ferreira da Silva, D. Vitoreti, G. B. Xavier, G. C. do Amaral, G. P. Temporão, and J. P. von der Weid, “Proof-of-Principle Demonstration of Measurement-Device-Independent Quantum Key Distribution Using Polarization Qubits,” Physical Review A 88, 052303 (2013), doi:10.1103/PhysRevA.88.052303.
  8. Y. Liu, T.-Y. Chen, L.-J. Wang, et al., “Experimental Measurement-Device-Independent Quantum Key Distribution,” Physical Review Letters 111, 130502 (2013), doi:10.1103/PhysRevLett.111.130502.
  9. Z. Tang, Z. Liao, F. Xu, B. Qi, L. Qian, and H.-K. Lo, “Experimental Demonstration of Polarization Encoding Measurement-Device-Independent Quantum Key Distribution,” Physical Review Letters 112, 190503 (2014), doi:10.1103/PhysRevLett.112.190503.
  10. Y.-L. Tang, H.-L. Yin, S.-J. Chen, et al., “Measurement-Device-Independent Quantum Key Distribution over 200 km,” Physical Review Letters 113, 190501 (2014), doi:10.1103/PhysRevLett.113.190501.
  11. H.-L. Yin, T.-Y. Chen, Z.-W. Yu, et al., “Measurement-Device-Independent Quantum Key Distribution over a 404 km Optical Fiber,” Physical Review Letters 117, 190501 (2016), doi:10.1103/PhysRevLett.117.190501.
  12. L. C. Comandar, M. Lucamarini, B. Fröhlich, et al., “Quantum Key Distribution without Detector Vulnerabilities Using Optically Seeded Lasers,” Nature Photonics 10, 312–315 (2016), doi:10.1038/nphoton.2016.50.
  13. Y.-H. Zhou, Z.-W. Yu, and X.-B. Wang, “Making the Decoy-State Measurement-Device-Independent Quantum Key Distribution Practically Useful,” Physical Review A 93, 042324 (2016), doi:10.1103/PhysRevA.93.042324.
  14. R. Valivarthi, I. Lucio-Martinez, P. Chan, et al., “Measurement-Device-Independent Quantum Key Distribution: From Idea towards Application,” Journal of Modern Optics 62, 1141–1150 (2015), doi:10.1080/09500340.2015.1021725.
  15. J. Calsamiglia and N. Lütkenhaus, “Maximum Efficiency of a Linear-Optical Bell-State Analyzer,” Applied Physics B 72, 67–71 (2001), doi:10.1007/s003400000484.
  16. C. K. Hong, Z. Y. Ou, and L. Mandel, “Measurement of Subpicosecond Time Intervals between Two Photons by Interference,” Physical Review Letters 59, 2044–2046 (1987), doi:10.1103/PhysRevLett.59.2044.
  17. F. Xu, X. Ma, Q. Zhang, H.-K. Lo, and J.-W. Pan, “Secure Quantum Key Distribution with Realistic Devices,” Reviews of Modern Physics 92, 025002 (2020), doi:10.1103/RevModPhys.92.025002.

MDI-QKD turns both users into trusted state preparers and moves the complete measurement apparatus into an untrusted relay. A virtual Bell projection on the traveling systems explains the protocol as time-reversed entanglement-based QKD, while the actual security proof permits the relay to perform any quantum instrument and announce arbitrary outcomes.

With phase-randomized weak coherent pulses, observed intensity-pair gains obey

Qabw=∑n,mpn(a)pm(b)Ynmw.Q_{ab}^{w} = \sum_{n,m}p_n(a)p_m(b)Y_{nm}^{w}.

Two-source decoy estimation bounds the one-photon-pair yield Y11Y_{11} and phase error that supply the privacy term. The architecture removes relay detectors from the trusted secrecy model, but it retains source characterization, private randomness, endpoint isolation, mode matching, authentication, finite statistics, and correct postprocessing. Its standard two-photon form scales with ηAηB\eta_A\eta_B and improves the trust boundary, not the repeaterless loss exponent.