REVIEW 3 major objections 4 minor 43 references
Beating the repeaterless bound with adaptive measurement-device-independent quantum key distribution
T0 review · 3 major / 4 minor · reviewed 2026-08-14 · deepseek-v4-flash
Pith's one-line read Adaptive MDI-QKD cannot beat the repeaterless bound with PDC sources.
desk verdict A neat necessary-condition argument with a PDC no-go corollary, but the impossibility claim rests on an unproven upper-bound status of a lower-bound key-rate formula. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing object is a full-mode model of the protocol in which every rate is reduced to Fock-basis click probabilities for the QND, $Z/X$-measurement, and Bell-state-measurement modules. The central identity is the secret-key rate formula $R = p_Z^2\, p_s\, p_{\mathrm{BSM}}\,[1 - f\,h(e_Z) - h(e_X)]$, where $p_s$ appears linearly rather than quadratically because BSMs are performed only on signals that survive the channel. The analytical condition comes from comparing the ideal-efficiency rate $R[\eta_{\mathrm{det}}=1,\tau=0] = \frac{3 p_1 q_1^2 \eta_{\mathrm{ch}}^2}{8 q_2 + 4(3q_1 - 2q_2)\eta_{\mathrm{ch}}}$ with the first term $1.44\,\eta_{\mathrm{ch}}^2$ of the Taylor expansion of the repeaterless bound.
What would settle it
Measure the photon-number statistics of a PDC source and check whether $q_2 \le \min\!\left(\frac{25}{96}\, p_1 q_1^2,\, 1-q_1\right)$; since PDC statistics force the transformed inequality to require a value above $36/25$ while the maximum possible left-hand side is $4/27$, any PDC source satisfying the condition, or any PDC-based AMDI-QKD experiment that exceeds the repeaterless bound under the paper's stated assumptions, would disprove the corollary.
Extended reading notes
Core claim
For entanglement sources with photon-number statistics $p_n$ and $q_m$, beating the repeaterless bound requires $q_2 \le \min\!\left(\frac{25}{96}\, p_1 q_1^2,\, 1-q_1\right)$ when detectors are ideal. With the statistics of type-II PDC sources, $p_n = \frac{(n+1)\lambda^n}{(1+\lambda)^{n+2}}$ and $q_m = \frac{(m+1)\mu^m}{(1+\mu)^{m+2}}$, this necessary condition reduces to an impossible inequality: PDC statistics can never satisfy the requirement, so PDC sources cannot be used to beat the repeaterless bound. The result holds even with photon-number-resolving detectors, and finite detector efficiency only tightens the required source quality.
Load-bearing premise
The secret-key rate formula from the idealized protocol remains valid when the ideal sources are replaced by the realistic photon-number mixture of Eq. (2); if that security proof does not extend, the necessary condition would not apply to the actual protocol.
Editorial extensions
If this is right
- A PDC-based AMDI-QKD setup, even with ideal photon-number-resolving detection and no feedforward loss, has secret-key rate scaling at most $O(\eta_{\mathrm{ch}})$, so it cannot deliver the square-root improvement in rate over distance.
- Any entanglement source intended for AMDI-QKD must satisfy $q_2 \le \min\!\left(\frac{25}{96}\, p_1 q_1^2,\, 1-q_1\right)$; violating this necessary condition excludes beating the repeaterless bound.
- Lower detector efficiency makes the required source quality stricter, and the simulations show the tolerable two-photon probability drops by roughly an order of magnitude per efficiency step in the studied range.
- The Hadamard gates placed before the final Bell-state measurement suppress a specific class of errors coming from two-photon components of the QND sources, but that suppression does not rescue PDC photon-number statistics.
Reading between the lines
- Beyond the paper's claims: the necessary condition reads as a source-design criterion, suggesting that only sources with strongly sub-Poissonian multi-pair emission, such as deterministic single-photon or quantum-dot-like sources, could plausibly let AMDI-QKD surpass the repeaterless bound.
- Beyond the paper's claims: the same full-mode counting method could be applied to other adaptive or memory-assisted QKD proposals to quantify how multi-pair source components degrade their advertised rate-distance scaling.
- Beyond the paper's claims: Eq. (9) could be used directly as a source-characterization test: measure $p_1$, $q_1$, and $q_2$ of a candidate source and check the inequality before attempting a full protocol implementation.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The manuscript examines a realistic implementation of the adaptive measurement-device-independent QKD (AMDI-QKD) protocol of Azuma et al. [34], replacing the ideal entanglement and single-photon sources with sources of the form Eq. (2), including type-II PDC sources, and replacing threshold detectors with photon-number-resolving detectors. The paper derives a simple analytical necessary condition, Eq. (9), on the photon-number statistics of the sources for beating the repeaterless bound, and uses it to prove a corollary that PDC sources cannot beat this bound with AMDI-QKD. It then presents a numerical study of a tighter necessary condition for non-unit detector efficiencies and finite switching latency, based on a full-mode calculation of the relevant probabilities in Appendix B.
Significance. If the corollary were rigorously established, it would be a useful no-go result: the most common entangled-photon source technology would be excluded from the AMDI-QKD approach to beating the repeaterless bound, even with ideal PNR detectors. The paper's analytical derivation of Eq. (8), the Taylor-bound argument leading to Eq. (9), and the PDC contradiction are clean and are supported by a substantial full-mode probability calculation. The main reservation is that the key-rate formula Eq. (1) is used as an exact expression for the rate with multiphoton sources, whereas in the QKD literature it is normally a lower bound for the idealized protocol; the paper does not establish the upper-bound statement that a necessary-condition argument requires. The result is therefore best viewed as a strong conditional statement about the rate formula of Ref. [34], rather than a complete impossibility proof for actual PDC-based implementations.
major comments (3)
- [Sec. II.B / Sec. IV.A] The proof of the Claim and the Corollary treats Eq. (1) as the exact secret key rate for the realistic sources of Eq. (2). In standard QKD security proofs, Eq. (1) is a lower bound on the achievable key rate for the idealized single-photon protocol of Ref. [34], not an upper bound. A necessary-condition argument requires an upper bound (or an exact expression) on the true rate after the ideal sources are replaced by multiphoton sources with PNR detectors. The paper does not supply such an upper bound: the full-mode calculations in Appendices B.2–B.4 compute detection probabilities, but they do not prove that the complementarity reasoning behind h(eZ)+h(eX) remains valid for postselected events in which the retained modes are not qubit pairs. Without this upper-bound statement, Eq. (8) is not established as a necessary condition, and the contradiction in the Corollary shows only that the heuristic rate formula cannot beat the bound, not that PDC sources cannot.
- [Appendix B.4 / Sec. IV.B] The manuscript states that the identities pX_c=pZ_c and pX_nc=pZ_nc are supported only by strong numerical evidence and not by an analytical proof. These quantities enter the phase-error rate eX in Eq. (B5), so the numerical necessary condition in Sec. IV.B (Fig. 5) depends on an unproven identity. If the same identity is also used in Appendix B.5 to obtain the ideal-detector rate Eq. (8), then the analytical necessary condition likewise lacks a fully demonstrated derivation. Please provide an analytical proof of these identities, or explicitly restrict the numerical and analytical claims to the regime in which they are proven.
- [Sec. IV.A, p.6] The monotonicity argument that R(ηdet=1,τ=0) is the best case is physically plausible because lossy detectors can be simulated by perfect detectors preceded by a beamsplitter, but the paper does not prove this for the specific postselected key-rate expression. Since the whole necessary condition relies on comparing the ideal-efficiency rate with the actual rate, this step should be stated as an explicit assumption or proven from the device model.
minor comments (4)
- [Eq. (9)] The notation q2 ≤ min(25/96 p1 q1^2, 1−q1) is ambiguous; it should read q2 ≤ min( (25/96) p1 q1^2, 1−q1 ).
- [Sec. II.B] The simplification pZ^2 ≈ 1 is used without a precise justification; please state the condition on pZ under which the simulations remain valid.
- [Sec. IV.A, p.6] The sentence claiming that 'we can actually beat the repeaterless bound in this limit' refers to the heuristic rate formula Eq. (8) under the assumption of ideal detectors and negligible dark counts; this context should be made explicit to avoid overstatement.
- [Appendix B] The full-mode formulas in Appendices B.2–B.4 are extremely long and nested; given that Fig. 5 is generated numerically, the authors should provide either the numerical code or a statement about numerical precision and cross-checks of the sums.
Circularity Check
No significant circularity: the PDC-impossibility corollary follows from an externally supplied rate formula, a full-mode probability calculation, and algebraic comparison to the external repeaterless bound; no step is defined in terms of its conclusion.
full rationale
The derivation chain is: Eq. (1) from Ref. [34] supplies the asymptotic key-rate expression; the paper computes pQND, pZ_c, pZ_nc, pX_c, and pX_nc from the stated source and detector models; Eq. (8) follows by setting eta_det=1 and tau=0; the Claim derives a necessary condition by comparing Eq. (8) with a Taylor lower bound on the repeaterless bound [5]; and the Corollary substitutes PDC statistics into Eq. (9) and obtains a contradiction. No parameter is fitted to data and no conclusion is used as an input. The only imported protocol-specific ingredient is Eq. (1), a published, parameter-free rate formula from Ref. [34] with one author overlap, while the new content is the full-mode probability evaluation for realistic sources, which is independent of the PDC-impossibility conclusion. The paper itself flags the unproven equality pX_c=pZ_c and pX_nc=pZ_nc in Appendix B.4, supported only by "strong numerical evidence," and Eq. (1)'s security proof was for idealized devices; whether Eq. (9) is a genuine necessary condition for the actual protocol is therefore a correctness or assumption risk, not a circularity. Consequently, no circular step is present and the score is 0.
Assumptions & free parameters
assumptions (4)
- domain assumption Secret key rate formula R = pZ^2 ps pBSM [1 - f h(eZ) - h(eX)] from Ref. [34] applies to the realistic device models introduced in Sec. III.
- domain assumption The entanglement sources are described by the photon-number distribution in Eq. (2) with states |phi_n> as defined, and the PDC distribution in Eq. (4) is the correct model for type-II PDC.
- domain assumption Secret key rate is monotonically non-increasing as detection efficiency eta_det decreases and feedforward time tau increases, so the idealized eta_det=1, tau=0 case provides a valid necessary condition for the realistic case.
- standard math The repeaterless bound of Pirandola et al. [5] is the correct fundamental limit for point-to-point QKD.
Cite this review
Pith. "Pith review of Beating the repeaterless bound with adaptive measurement-device-independent quantum key distribution." pith.science (2026). https://pith.science/paper/EZP4KUNA
@misc{pith2026190804539,
author = {Pith},
title = {Pith review of: Beating the repeaterless bound with adaptive measurement-device-independent quantum key distribution},
year = {2026},
howpublished = {\url{https://pith.science/paper/EZP4KUNA}},
note = {Machine review of arXiv:1908.04539}
}
read the original abstract
Surpassing the repeaterless bound is a crucial task on the way towards realizing long-distance quantum key distribution. In this paper, we focus on the protocol proposed by Azuma et al. in [Nature Communications 6, 10171 (2015)], which can beat this bound with idealized devices. We investigate the robustness of this protocol against imperfections in realistic setups, particularly the multiple-photon pair components emitted by practical entanglement sources. In doing so, we derive necessary conditions on the photon-number statistics of the sources in order to beat the repeaterless bound. We show, for instance, that parametric down-conversion sources do not satisfy the required conditions and thus cannot be used to outperform this bound.
Figures
Figures from the paper (5 more)
Reference graph
Works this paper leans on
- [34]
- [1]
-
[2]
V. Scarani, H. B.-Pasquinucci, N. J. Cerf, M. Duˇ sek, N. L¨ utkenhaus and M. Peev: The security of practical quantum key distribution, Reviews of Modern Physics 81, 1301 (2009)
work page 2009
-
[3]
H.-K. Lo, M. Curty and K. Tamaki: Secure quantum key distribution, Nature Photonics 8, 595-604 (2014)
work page 2014
-
[4]
M. Takeoka, S. Guha, and M. M. Wilde: Fundamental rate-loss tradeoff for optical quantum key distribution, Nature Communications 5, 5235 (2014)
work page 2014
-
[5]
S. Pirandola, R. Laurenza, C. Ottaviani and L. Banchi: Fundamental limits of repeaterless quantum communica- tions, Nature Communications 8, 15043 (2017)
work page 2017
-
[6]
M. M. Wilde, M. Tomamichel and M. Berta: Con- verse Bounds for Private Communication Over Quantum Channels IEEE Transactions on Information Theory 63, 1792-1817 (2017)
work page 2017
-
[7]
H.-J. Briegel, W. D¨ ur, J. I. Cirac and P. Zoller: Quantum repeaters: the role of imperfect local operations in quan- tum communication, Physical Review Letters 81, 5932 (1998)
work page 1998
Show all 43 references
-
[8]
L.-M. Duan, M. D. Lukin, J. I. Cirac and P. Zoller: Long- distance quantum communication with atomic ensembles and linear optics, Nature 414, 413-418 (2001)
2001
-
[9]
P. Kok, C. P. Williams and J. P. Dowling: Construction of a quantum repeater with linear optics, Physical Review A 68, 022301 (2003)
2003
-
[10]
van Loock et al
P. van Loock et al. : Hybrid Quantum Repeater Us- ing Bright Coherent Light, Physical Review Letters 96, 240501 (2006)
2006
-
[11]
Jiang, J
L. Jiang, J. M. Taylor, K. Nemoto, W. J. Munro, R. Van Meter and M. D. Lukin: Quantum repeater with encoding, Physical Review A 79, 032325 (2009)
2009
-
[12]
Sangouard, C
N. Sangouard, C. Simon, H. de Riedmatten and N. Gisin: Quantum repeaters based on atomic ensembles and linear optics, Reviews of Modern Physics 83, 33 (2011)
2011
-
[13]
Azuma, H
K. Azuma, H. Takeda, M. Koashi and N. Imoto: Quan- tum repeaters and computation by a single module: Re- mote nondestructive parity measurement, Physical Re- view A 85, 062309 (2012)
2012
-
[14]
W. J. Munro, A. M. Stephens, S. J. Devitt, K. A. Har- rison and K. Nemoto: Quantum communication without the necessity of quantum memories, Nature Photonics 6, 777-781 (2012)
2012
-
[15]
Azuma, K
K. Azuma, K. Tamaki and H.-K. Lo: All-photonic quan- tum repeaters, Nature Communications 6, 6787 (2015)
2015
-
[16]
Sangouard: A future without long memories?, Nature Photonics 6, 722-724 (2012)
N. Sangouard: A future without long memories?, Nature Photonics 6, 722-724 (2012)
2012
-
[17]
Lucamarini, Z
M. Lucamarini, Z. L. Yuan, J. F. Dynes and A. J. Shields: Overcoming the rate-distance limit of quantum key dis- tribution without quantum repeaters, Nature 557, 400- 403 (2018)
2018
-
[18]
Tamaki, H.-K
K. Tamaki, H.-K. Lo, W. Wang and M. Lucamarini: In- formation theoretic security of quantum key distribution overcoming the repeaterless secret key capacity bound, preprint arXiv:1805.05511v3 (2018)
2018 arXiv
-
[19]
X. Ma, P. Zeng and H. Zhou: Phase-Matching Quantum Key Distribution, Physical Review X 8, 031043 (2018)
2018
-
[20]
Wang, Z.-W
X.-B. Wang, Z.-W. Yu and X.-L. Hu: Twin-field quan- tum key distribution with large misalignment error, Physical Review A 98, 062323 (2018)
2018
-
[21]
Lin and N
J. Lin and N. L¨ utkenhaus: Simple security analysis of phase-matching measurement-device-independent quan- tum key distribution, Physical Review A 98, 042332 (2018)
2018
-
[22]
Cui et al
C. Cui et al. : Twin-field quantum key distribution with- out phase post-selection, Physical Review Applied 11, 034053 (2019)
2019
-
[23]
Yin and Y
H.-L. Yin and Y. Fu: Measurement-Device-Independent Twin-Field Quantum Key Distribution, Scientific Re- ports 9, 3045 (2019)
2019
-
[24]
Curty, K
M. Curty, K. Azuma and H.-K. Lo: Simple security proof of twin-field type quantum key distribution protocol, npj Quantum Information 5, 64 (2019)
2019
-
[25]
Zhong, J
X. Zhong, J. Hu, M. Curty, L. Qian and H.-K. Lo: Proof-of-principle experimental demonstration of twin-field type quantum key distribution, preprint arXiv:1902.10209v1 (2019)
2019
-
[26]
Minder et al
M. Minder et al. : Experimental quantum key distribu- tion beyond the repeaterless secret key capacity, Nature 21 Photonics 13, 334-338 (2019)
2019
-
[27]
Liu et al
Y. Liu et al. : Experimental Twin-Field Quantum Key Distribution Through Sending-or-Not-Sending, preprint arXiv:1902.06268v1 (2019)
2019 arXiv
-
[28]
Wang et al
S. Wang et al. : Beating the Fundamental Rate-Distance Limit in a Proof-of-Principle Quantum Key Distribution System, Physical Review X 9, 021046 (2019)
2019
-
[29]
H.-K. Lo, M. Curty, and B. Qi: Measurement-Device- Independent Quantum Key Distribution, Physical Re- view Letters 108, 130503 (2012)
2012
-
[30]
Luong, L
D. Luong, L. Jiang, J. Kim and N. L¨ utkenhaus: Over- coming lossy channel bounds using a single quantum re- peater node, Applied Physics B 122, 96 (2016)
2016
-
[31]
Abruzzo, H
S. Abruzzo, H. Kampermann and D. Bruß: Measurement-device-independent quantum key dis- tribution with quantum memories, Physical Review A 89, 012301 (2014)
2014
-
[32]
Panayi, M
C. Panayi, M. Razavi, X. Ma and N. L¨ utkenhaus: Memory-assisted measurement-device-independent quantum key distribution, New Journal of Physics 16, 043005 (2014)
2014
-
[33]
Tr´ enyi and N
R. Tr´ enyi and N. L¨ utkenhaus: Beating direct transmis- sion bounds for quantum key distribution with a multiple quantum memory station. 8th International Conference on Quantum Cryptography, Shanghai, China (2018)
2018
-
[35]
P. Kok, H. Lee, and J. P. Dowling: Single-photon quantum-nondemolition detectors constructed with lin- ear optics and projective measurements, Physical Review A 66, 063814 (2002)
2002
-
[36]
Zhao, Z.-B
B. Zhao, Z.-B. Chen, Y.-A. Chen, J. Schmiedmayer and J.-W. Pan: Robust creation of entanglement between re- mote memory qubits, Physical Review Letters 98, 240502 (2007)
2007
-
[37]
N. L. Piparo, M. Razavi and C. Panayi: Measurement- Device-Independent Quantum Key Distribution With Ensemble-Based Memories, IEEE Journal of Selected Topics in Quantum Electronics 21, 6601010 (2015)
2015
-
[38]
X. Ma, C. H. F. Fung and H.-K. Lo: Quantum key distri- bution with entangled photon sources, Physical Review A 76, 012307 (2007)
2007
-
[39]
C. H. Bennett, G. Brassard, C. Crepeau: Teleporting an unknown quantum state via dual classical and Einstein- Podolsky-Rosen channels, Physical Review Letters 70, 1895-1899 (1993)
1993
-
[40]
W. P. Grice: Arbitrarily complete Bell-state measure- ment using only linear optical elements, Physical Review A 84, 042331 (2011)
2011
-
[41]
Ewert and P
F. Ewert and P. van Loock: 3/4-efficient Bell measure- ment with passive linear optics and unentangled ancillae, Physical Review Letters 113, 140403 (2014)
2014
-
[42]
Prevedel et al
R. Prevedel et al. : High-speed linear optics quantum computing using active feed-forward, Nature 445, 65-69 (2007)
2007
-
[43]
Zotter, J
X.-song Ma, S. Zotter, J. Kofler, T. Jennewein and A. Zeilinger: Experimental generation of single photons via active multiplexing, Physical Review A 83, 043814 (2011)
2011
Reviewed August 14, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.