---
title: 'MDI-QKD: Measurement-Device-Independent QKD'
url: https://www.emergentmind.com/topics/measurement-device-independent-quantum-key-distribution-mdi-qkd
type: topic
---

# MDI-QKD: Measurement-Device-Independent QKD

Searching arXiv for foundational and recent MDI-QKD papers to support the article.
Measurement-device-independent quantum key distribution (MDI-QKD) is a class of discrete-variable QKD protocols in which Alice and Bob send independently prepared quantum states to an untrusted relay, typically called Charlie, who performs a Bell-state measurement (BSM) and publicly announces successful events. Its defining security feature is that the entire measurement apparatus is treated as a black box, so all detector-side loopholes are removed from the trust model. In the practical realizations summarized in the literature, Alice and Bob usually prepare BB84 states with phase-randomized weak coherent pulses and use decoy-state analysis to isolate the single-photon contribution that underwrites the secret key rate [1305.6965] [1209.6178] [1305.7396].

## 1. Protocol architecture and operating principle

In standard prepare-and-measure MDI-QKD, Alice and Bob independently choose a basis and a bit value, encode one of the BB84 states, and transmit their pulses to Charlie. Charlie interferes the two incoming optical fields on a \(50{:}50\) beam splitter and performs a partial BSM. Successful projections are typically identified with \(|\psi^{-}\rangle\) or, in some realizations, \(|\psi^{+}\rangle\) through two-click coincidence patterns in orthogonal detectors. Alice and Bob then keep only rounds in which they used compatible bases and Charlie reported a successful projection; after basis sifting, error correction, and privacy amplification, they extract a secret key [1209.6178] [1305.6965].

The protocol is commonly described as a time-reversed entanglement-based scheme. Operationally, this means that Charlie’s announcement post-selects correlations between Alice’s and Bob’s preparations without requiring Charlie to be trusted. In time-bin implementations, the \(Z\) basis is encoded in early and late temporal modes, while the \(X\) basis is encoded in relative phase \(0\) or \(\pi\) between the two bins. Polarization encodings and hybrid architectures are also represented in the literature [1501.07307] [1702.05155].

A central experimental difficulty is two-photon indistinguishability at Charlie. MDI-QKD requires overlap in arrival time, spectrum, polarization, and phase reference to sustain high-visibility Hong–Ou–Mandel interference. Several system designs therefore devote substantial resources to active timing, polarization, and spectral feedback. An alternative is Plug-and-Play MDI-QKD, where Charlie generates the pulses from a single laser and sends them to Alice and Bob before they are attenuated, encoded, and reflected back. In that setting, spectral indistinguishability is inherited from the common laser, polarization drift is automatically compensated by Faraday mirrors, and a common interferometer can provide the shared phase reference for time-bin encoding [1501.03344].

## 2. Decoy-state inference and secret-key rate formulas

Because practical sources are phase-randomized weak coherent pulses rather than ideal single-photon emitters, MDI-QKD is normally paired with the decoy-state method. The basic observables are the gain and the error-gain for each intensity pair \((\mu_i,\nu_j)\):
\[
Q_{\mu_i\nu_j}=\sum_{n,m=0}^{\infty} e^{-\mu_i-\nu_j}\frac{\mu_i^n\nu_j^m}{n!m!}Y_{nm},
\]
\[
Q_{\mu_i\nu_j}E_{\mu_i\nu_j}=\sum_{n,m=0}^{\infty} e^{-\mu_i-\nu_j}\frac{\mu_i^n\nu_j^m}{n!m!}Y_{nm}e_{nm}.
\]
Here \(Y_{nm}\) is the conditional probability that Charlie reports a successful BSM when Alice emits an \(n\)-photon pulse and Bob an \(m\)-photon pulse, and \(e_{nm}\) is the corresponding QBER [1305.7396].

The asymptotic secret-key rate used across multiple treatments takes the standard single-photon form
\[
R = Q_Z^{1,1}\bigl[1-H_2(e_X^{1,1})\bigr]-Q_Z\,f_e\,H_2(E_Z),
\]
where \(Q_Z\) and \(E_Z\) are the observed \(Z\)-basis gain and QBER, \(Q_Z^{1,1}=P^{1,1}Y_Z^{1,1}\) with \(P^{1,1}=\mu_a\mu_b e^{-(\mu_a+\mu_b)}\), \(e_X^{1,1}\) is the single-photon phase-error estimate from the \(X\) basis, \(f_e\) is the error-correction inefficiency, and \(H_2(x)=-x\log_2x-(1-x)\log_2(1-x)\) [1306.5814]. Equivalent notational variants appear throughout the experimental and modeling literature [1204.0738] [1501.07307].

A major technical result of early practical analysis was that only vacuum and one weak decoy state are sufficient to derive tight lower bounds on \(Y_{11}\) and upper bounds on \(e_{11}\). Numerical simulations in that setting showed that vacuum-plus-weak-decoy performance can asymptotically approach the infinite-decoy limit: for example, at total Alice–Bob transmission \(\eta_A=\eta_B=10^{-1}\), one finds \(Y_{11}^z \simeq 4.20\times 10^{-3}\) versus \(4.42\times 10^{-3}\), and \(e_{11}^x \simeq 2.7\%\) versus \(2.5\%\), with the secret key rate almost indistinguishable from the theoretical optimum and difference \(\lesssim 10\%\) [1305.7396].

Finite-size analysis replaces exact parameters by confidence intervals derived from concentration bounds. In the practical decoy-state analysis, finite statistics are handled by replacing the observed \(Q_{\mu_i\nu_j}^\omega\) and \(Q_{\mu_i\nu_j}^\omega E_{\mu_i\nu_j}^\omega\) with upper and lower confidence bounds parameterized by the number of standard deviations \(n_\alpha\); with \(10^{10}\) total pulses and \(n_\alpha=5\), the key rate remained positive up to \(\simeq 100\) km [1305.7396]. In the long-distance entangled-source analysis, finite-key corrections were applied at \(N=10^{15}\) signals with composable security parameter \(\epsilon=10^{-10}\) and two decoys [1306.5814].

## 3. Physical modeling and dominant error mechanisms

System modeling in MDI-QKD explicitly tracks source statistics, channel loss, mode overlap, and detector behavior. A channel of length \(L\) and attenuation \(\alpha\) is represented by a beam splitter of transmittance
\[
t = 10^{-\alpha L/10},
\]
and polarization misalignment is modeled by
\[
U(\theta)=
\begin{pmatrix}
\cos\theta & -\sin\theta\\
\sin\theta & \cos\theta
\end{pmatrix},
\qquad
e_d=\sin^2\theta\approx \theta^2.
\]
In more detailed descriptions, the full state-preparation model also includes imperfect modulation parameters, finite interference visibility, detector dark counts, and afterpulsing [1306.5814] [1204.0738].

The BSM model must treat vacuum, one-photon, and multiphoton inputs separately. In the general time-bin model, the beam splitter plus threshold detectors are analyzed by enumerating input–output photon-number configurations and weighting them with the Poissonian source distributions. Two-photon interference is incorporated through an observed visibility \(V\), interpolating between interfering and non-interfering cases. This modeling framework was shown to agree with laboratory and deployed-fiber data over three orders of magnitude and was then used to optimize mean photon numbers, identify rate-limiting components, and project future performance [1204.0738].

Across the practical analyses, the principal impairments are consistent. Polarization misalignment, temporal or spectral mode mismatch, detector dark counts, and finite detector efficiency dominate the QBER and the attainable distance. In one representative parameter set used for numerical studies, \(\eta_d=14.5\%\), \(e_d=1.5\%\), \(Y_0=6.02\times 10^{-6}\), \(f_e=1.16\), and \(e_m=2\%\) [1305.6965]. In long-distance entangled-source architectures, the dominant long-range factors are explicitly identified as detector efficiency and dark counts; in addition, polarization stabilization over four independent optical links requires active feedback or polarization-maintaining fiber, and high-speed operation with low timing jitter is needed to accumulate the required four-fold coincidences [1306.5814].

A further practical complication is asymmetry. When the Alice–Charlie and Bob–Charlie transmittances differ, equal source intensities are not generally optimal. The asymmetric analysis showed that the true optimum depends on the transmittance ratio \(x=t_a/t_b\), and numerical examples yielded approximately \(80\%\) higher rate than a naive “symmetric gain” choice for \(x=0.1\) [1305.6965]. This asymmetry problem is structurally important for network deployments, where user-to-relay distances are rarely identical.

## 4. Security scope, source assumptions, and relaxed-trust variants

The core security claim of MDI-QKD is narrow but strong: detector-side attacks are removed because Charlie’s measurement device is untrusted by design. A recurrent misunderstanding is to extend this conclusion to the source side. The later literature is explicit that conventional MDI-QKD security proofs still require assumptions on Alice’s and Bob’s transmitters, and that uncharacterized side channels in state preparation can compromise security if left untreated [2107.07803] [1508.03562].

One route addresses imperfect but characterized sources. The first experimental MDI-QKD demonstration incorporating state-preparation flaws used the loss-tolerant proof of Tamaki et al., under the assumption that the prepared states remain in a two-dimensional subspace. With imperfect polarization preparation taken into account through measured density matrices and Stokes vectors, secure keys were distributed over fiber links up to \(40\) km; at \(10\) km with finite key \((\epsilon=10^{-3}, N=6\times10^{11})\), the experiment reported \(Q_Z^{\mu\mu}=6.31\times10^{-5}\), \(E_Z^{\mu\mu}=1.78\%\), \(Q_Z^{11,L}=3.96\times10^{-5}\), \(e_X^{11,U}=18.9\%\), and \(R\approx 2.48\times10^{-6}\) bit/pulse [1508.03562].

A stricter relaxation is uncharacterized-source MDI-QKD. In the three-state method, the only source assumption is that the prepared states lie in a bidimensional Hilbert space, and mismatched-basis events are used to bound the phase-error rate. A proof-of-principle implementation over \(170\) km reported \(Y_{11}=7.68\times10^{-5}\), \(E_{uu}^{ZZ}=0.21\%\), \(e_p=27\%\), \(Q_{uu}^{ZZ}=7.53\times10^{-6}\), and final key rate \(R=7.06\times10^{-8}\) per pulse, with \(10^{13}\) pulses per side and finite-size correction applied [2002.04944].

An even broader framework treats arbitrary source imperfection and side channels through a reference-technique formalism. In that description, the actual transmitted state is decomposed into an ideal BB84 component and an orthogonal leakage component with parameter \(\epsilon_{j_\alpha,s_\beta}\). The asymptotic rate becomes
\[
R \ge Y_{ZZ}\,[1-h(e_{XX})-f_{\rm ec}h(e_{ZZ})],
\]
and the phase-error estimate is obtained by bounding the virtual error numerator \(\Omega\) via fidelity-based inequalities. Simulations with single-photon sources showed that source insecurity can sharply reduce range: with \(\epsilon=10^{-6}\), a positive key remains up to \(\simeq 8\) dB only, whereas with \(\epsilon=0\) one reaches \(\sim 22\) dB [2107.07803]. This suggests that detector-independence does not by itself imply full implementation security.

Other relaxed-trust models sit between standard MDI-QKD and stronger device-independence. One-sided MDI-QKD assumes Bob’s encoder is trusted while Alice’s is uncharacterized but emits qubit-dimensional, basis-independent states; its asymptotic key-rate bound is written as \(R\ge 1-h(e_Z)-h(e_X)\), and practical WCP realizations with analytical two-decoy bounds were proposed [1704.04371]. In a different direction, MDI-QKD with an untrusted source places the laser at Charles and compensates with spectral/spatial filtering, pulse-energy monitoring, and active phase randomization; asymptotically, the paper reports rates close to initial MDI-QKD in the asymptotic setting, while finite-size monitoring overhead reduces range [1508.00970]. Plug-and-Play MDI-QKD simplifies indistinguishability, but its own treatment notes that source-side attacks such as Trojan-horse and phase-remapping remain possible and must be countered by standard Plug-and-Play techniques [1501.03344].

## 5. Experimental realizations and performance benchmarks

The experimental trajectory of MDI-QKD has moved along several axes simultaneously: longer distance, higher clock rate, reduced complexity, relaxed source assumptions, and non-fiber deployment. Representative results are summarized below.

| Implementation | Configuration | Reported benchmark |
|---|---|---|
| Liu et al. [1209.6178] | First experimental MDI-QKD over fiber | More than \(25\) kbit secure key over a \(50\)-km fiber link |
| Valivarthi et al. [1501.07307] | Application-oriented fiber system | QKD over a channel featuring \(60\) dB loss, and more than \(600\) bits of secret key per second over a \(16\) dB loss channel |
| Comandar et al. [1702.05155] | Cost-effective FPGA/DFB architecture | \(R\approx 0.1\) kbps at \(80\) km total distance; star-type topology extending over more than \(100\) km |
| Cao et al. [2006.05088] | Free-space urban MDI-QKD | \(19.2\)-km urban atmospheric channel; final secure key \(295\) kbit, corresponding to \(6.11\) bits s\(^{-1}\) |
| “Experimental Three-State MDI-QKD with Uncharacterized Sources” [2002.04944] | Finite-size, uncharacterized sources | \(170\) km; final key rate \(R=7.06\times10^{-8}\) per pulse |
| “Gigahertz MDI-QKD using directly modulated lasers” [2105.06748] | \(1\) GHz direct-modulation design | \(8\) bps at \(54\) dB channel loss; \(2.0\) kbps in the finite-size regime for \(30\) dB channel loss |

The early experimental systems established that detector-side loopholes could be removed without sacrificing practical decoy-state operation. The \(50\)-km demonstration used up-conversion detectors with total system detection efficiency \(\simeq 20\%\), dark-count rate \(\simeq 1\) kHz per detector, and \(59.5\) hours of run time; the measured \(Z\)-basis QBER stayed below \(0.5\%\) for all non-vacuum intensity pairs, and the upper bound on the single-photon phase error was \(e_{11}\approx 24.6\%\) [1209.6178].

Application-oriented engineering quickly shifted attention to deployed fiber, detector technology, and hardware cost. The application study compared InGaAs SPDs with SNSPDs, showing secure operation up to \(\sim 16\) dB and \(\sim 20\) dB total loss for id201 and id210, respectively, and up to \(\sim 60\) dB with SNSPDs, corresponding to \(\sim 300\) km. The same work reported that integrating the system into FPGA-based hardware instead of arbitrary waveform generators did not impact performance [1501.07307]. The cost-effective system built around commercial DFB lasers and FPGA qubit generation reached a two-photon interference visibility of \(46.4\pm 0.5\%\) over \(2\times 40\) km of spooled fiber, in agreement with the theoretical model, and extrapolated to \(>10\) kbps at \(80\) km for \(2\) GHz modulation [1702.05155].

Later work targeted the finite-size bottleneck directly. The double-scanning method, experimentally incorporated into MDI-QKD at \(50\) MHz, achieved secure transmission over \(150\) km with only \(10^{10}\) pulses, with final secret key rates \(43.54\) bps at \(120\) km and \(0.059\) bps at \(150\) km. The same report states that \(150\) km was impossible with all former methods under the same pulse budget [2105.09587]. In parallel, direct laser modulation and injection locking were used to eliminate spectral and phase feedback between independent lasers at \(1\) GHz, yielding long-term \(Z\)-basis QBER \(=0.55\%\pm 0.08\%\) and \(X\)-basis \(=26.6\%\pm 0.39\%\) over \(48\) h [2105.06748].

The free-space experiment constitutes a separate milestone. Over a \(19.2\)-km urban atmospheric channel, adaptive optics, high-precision synchronization, and molecular-absorption-based frequency locking enabled the first long-distance free-space MDI-QKD, exceeding the effective atmospheric thickness and opening a path toward satellite-based MDI-QKD [2006.05088].

## 6. Variants, network architectures, and long-distance extensions

Several major variants extend the baseline protocol. One of the most important is MDI-QKD with a single entangled photon source in the middle. In this architecture, Charles emits a Type-II PDC state and two independent BSMs are performed, one on Alice–Charles’s photon and one on Bob–Charles’s photon. The general model predicts that, with practical existing detectors \((\eta_d=14.5\%, Y_0=6.02\times10^{-6}, e_d=3\%, \alpha=0.21\,{\rm dB/km})\), the asymptotic key rate tolerates up to \(77\) dB total loss, corresponding to \(367\) km standard fiber or \(481\) km ultra-low-loss fiber. With state-of-the-art detectors \((\eta_d=93\%, Y_0=1\times10^{-6})\), the asymptotic loss tolerance increases to \(140\) dB, corresponding to \(667\) km standard fiber; in the finite-key regime with \(N=10^{15}\), \(\epsilon=10^{-10}\), and two decoys, the tolerable loss is \(60\) dB, corresponding to \(286\) km [1306.5814].

Plug-and-Play MDI-QKD addresses mode matching rather than ultimate distance. By generating all pulses from Charlie’s single laser, it removes active frequency locking, automatically compensates polarization drift via Faraday mirrors, and uses a common interferometer for the time-bin phase reference. The reported proof-of-principle experiment used a continuous-wave \(780\) nm diode laser, bulk optics, four Si-APDs of \(\approx 50\%\) efficiency, and observed raw visibilities \(\approx 30\)–\(31\%\) in two-photon interference, \(E_Z \simeq 0.3\)–\(0.4\%\), and \(E_X \simeq 26.5\)–\(26.7\%\). The paper does not report secret-key-rate versus distance [1501.03344].

Phase-encoded variants modify the coding alphabet and the error structure. Differential phase encoded MDI-QKD uses a single photon in a linear superposition of three orthogonal time-bin states, with key information carried by phase differences. Its prepare-and-measure version has sifted-key rate
\[
R_{\rm sift}=\tfrac{4}{9},
\]
and its security proof establishes the phase-error bound \(e_p\le e_b\). In the decoy-state version, the authors combine weak coherent states with phase post-selection; for \(N=16\) phase slices, the intrinsic error is reduced from about \(34\%\) to \(\sim 1\%\) [1905.11153].

Another line of work targets source-modulation side channels by removing active decoy modulation. Passive decoy-state MDI-QKD based on heralded single-photon sources uses local click patterns to tag passive “signal” and “decoy” settings. Under the parameters in that study, the passive protocol yielded positive keys down to \(N_t\approx 10^8\) and exceeded the compared active schemes whenever \(N_t\lesssim 4\times 10^9\) at fixed \(50\) km [1902.05243]. Fully passive MDI-QKD goes further, replacing both encoding and decoy modulation with linear optics and post-selection. In the asymptotic simulations, the fully passive protocol achieved \(\sim 100\times\) lower rate than an active three-intensity MDI-QKD at short distances, but still extended to \(\gtrsim 100\) km with SNSPDs and to \(\sim 80\) km with SPADs [2309.07576]. The practical implication is a different trade-off: lower raw performance in exchange for reduced source-modulator leakage surfaces.

At the network level, MDI-QKD is naturally aligned with star-type topologies. Charlie hosts the costly BSM module, SNSPDs, clock distribution, and feedback hardware, while user nodes require only transmitters. This architecture is emphasized both in application-oriented and cost-effective studies, which argue that expensive central resources can be amortized across multiple users and that the same framework can operate over deployed fiber outside the laboratory [1501.07307] [1702.05155]. The long-distance entangled-source architecture and the untrusted-source network model both reinforce this network-centric view by explicitly placing complex source or measurement functionality at an untrusted middle node [1306.5814] [1508.00970].

In aggregate, the literature presents MDI-QKD not as a single protocol instance but as a protocol family. Its invariant feature is detector-side-channel immunity through an untrusted measurement node; its active research front concerns how much of the remaining implementation stack—source calibration, decoy modulation, interferometric stabilization, clocking, and network hardware—can be simplified or untrusted without sacrificing rigorous security.

Source: https://www.emergentmind.com/topics/measurement-device-independent-quantum-key-distribution-mdi-qkd