What Is MDI-QKD and Why It Matters Now
The most paranoid protocol in quantum cryptography doesn’t trust its own hardware. Here’s why that matters – and how close it is to working.
Table of Contents
Introduction
Researchers have hacked commercially available quantum key distribution systems in controlled experiments. In the best-known demonstration, tailored bright illumination gave an eavesdropper remote control of the detectors in two commercial QKD products and allowed recovery of the full secret key without triggering the systems’ eavesdropping alarms.
This did not break the mathematics of BB84. It exposed a gap between the idealised detector assumed by the security proof and the detector implemented in the product. The detector-blinding attacks permanently retired the word “unhackable” from serious QKD literature.
Measurement-device-independent QKD (MDI-QKD) was designed to close that gap. First proposed by Lo, Curty, and Qi in 2012, MDI-QKD removes the measurement device from the trusted part of the security model. The relay and its detectors may be faulty or malicious. They can disrupt the protocol and prevent key generation, but they cannot make Alice and Bob accept a key known to the relay, provided the transmitter and protocol assumptions are satisfied. Here is how it works, where it stands globally, and why its descendant protocols have rewritten the QKD distance record books.
The Trust Spectrum
To understand where MDI-QKD sits, it helps to map the QKD trust spectrum. Each protocol family makes different assumptions about which components must be trusted, and each assumption is an attack surface.
Conventional DV-QKD (BB84, decoy-state variants) trusts both the source and the measurement device. The source must produce the states it claims to produce. The detectors must faithfully report what they detect. When the detector-blinding attacks showed that real detectors could be manipulated without alerting the protocol, the conditional broke. The protocol was secure; the implementation did not satisfy the assumptions under which security had been established.
MDI-QKD trusts the source but removes the measurement device from the security model. Alice and Bob each prepare and send quantum states to an untrusted third party (typically called Charlie, or the relay node), who performs a Bell-state measurement on the incoming photons and publicly announces the result. Charlie never learns the key. Even if Charlie is the adversary, or if every detector Charlie uses is compromised, the protocol generates a secure key between Alice and Bob. Charlie may report arbitrary results or perform no genuine measurement; this can force the protocol to abort, but it cannot yield an accepted, compromised key under the security proof.
Device-independent QKD (DI-QKD) goes further by removing the need to characterise either the source or the measurement device, certifying security through observed violations of Bell inequalities. It still assumes authenticated classical communications, private randomness, trusted post-processing, and secure laboratories. The price is extreme experimental difficulty. As of mid-2026, DI-QKD remains an early-laboratory-stage technology, with the furthest demonstration reaching 100 km with positive asymptotic key rates and finite-key extraction limited to 11 km.
MDI-QKD occupies the practical middle of this spectrum. It eliminates the attack class that has actually been demonstrated against real products (detector-side attacks), without requiring the experimental conditions that make DI-QKD a laboratory technology. As I wrote in Quantum Ready, the field’s response to the detector-blinding problem was structural rather than rhetorical: MDI-QKD removes the detector from the trust equation.
How MDI-QKD Works
In conventional QKD, Alice sends quantum states to Bob, who measures them. In MDI-QKD, both Alice and Bob send quantum states to a central measurement node (Charlie), which performs a joint Bell-state measurement on the two incoming photons and announces the outcome publicly. Neither Alice nor Bob performs any detection; all detection happens at Charlie’s node.
Charlie’s Bell-state measurement creates correlations between Alice’s and Bob’s states that allow them to generate a shared key through classical post-processing. Charlie learns the measurement outcome but cannot reconstruct the key from it. The security proof does not assume anything about Charlie’s measurement device, which is why the protocol closes all detector-side loopholes by design.
The architectural consequence is a hub-and-spoke network topology. Charlie sits at the centre, and many user pairs can generate keys through the same central node. This multi-user scaling property, combined with centralised (and untrusted) detection hardware, is one of MDI-QKD’s practical advantages over point-to-point protocols. Standard MDI-QKD remains constrained by fibre attenuation: successful key events require photons from both users to arrive at the relay, so the total-loss scaling with Alice-Bob distance is similar to direct transmission. The midpoint’s value is centralising untrusted detectors and enabling multi-user switching rather than extending range.
Two additional costs accompany the security gain. With the standard passive linear-optical Bell-state measurement used in most implementations, at most two of the four photonic Bell states can be unambiguously distinguished, giving a maximum nominal success probability of 50%, which reduces the effective key rate. And the protocol requires two-photon interference between independently prepared photons from separate sources, demanding precise spectral, temporal, and polarisation matching.
From 2012 Paper to 1,002 km
MDI-QKD’s most consequential legacy may be the protocol family it spawned.
The original Lo-Curty-Qi protocol was experimentally demonstrated within a year of publication. Distance records followed: 200 km with standard telecom fibre and superconducting single-photon detectors (Tang et al., 2014), then a 404 km record for conventional two-photon MDI-QKD using ultralow-loss fibre and an optimised four-intensity decoy-state method (Yin et al., 2016). Chinese groups, particularly USTC’s quantum communication teams, drove much of this progress.
Then, in 2018, Toshiba’s Cambridge Research Laboratory proposed twin-field QKD (TF-QKD), a closely related measurement-device-independent protocol that retains an untrusted intermediate measurement node but extracts key information from first-order (single-photon) interference rather than two-photon coincidences. TF-QKD changes the loss scaling: because it relies on single-photon detection rather than two-photon coincidence, it achieves a repeater-like rate-distance advantage that breaks through the fundamental rate-loss limit binding conventional point-to-point QKD, including standard MDI-QKD.
The distance records fell fast. In 2022, Chinese researchers demonstrated TF-QKD over 833.8 km of fibre. In 2023, a USTC-led team extended the asymptotic result to 1,002 km of ultra-low-loss spooled fibre, while a subsequent finite-key analysis of the same experimental data yielded a secure rate of 3.11 × 10⁻¹² per pulse pair at the full 1,002 km, approximately 0.001 bit/s. No trusted relays. No satellites. But this was a laboratory fibre-spool record; no deployed backbone link has achieved it. At shorter distances the same platform produced 111.74 kbit/s at 202 km, illustrating why operational suitability must be evaluated at the actual link loss and key-consumption profile rather than the headline distance.
In April 2025, Toshiba and GÉANT demonstrated TF-QKD over a 254 km deployed commercial telecommunications link in Germany using non-cryogenically cooled detectors. Earlier TF-QKD field experiments had used deployed fibre, but this was presented as the first integration of coherent quantum communications into commercial telecom infrastructure outside a dedicated metropolitan system. And in 2026, a Peking University team reported a laboratory TF-QKD network built from 20 integrated transmitter chips operating across ten wavelength channels, each tested over up to 370 km of spooled fibre, published in Nature. The authors reported an aggregate “networking capability” of 3,700 km calculated across the twenty users; the network did not physically span that distance, but the result is evidence of integration and repeatable chip fabrication pointing toward scalability.
Global Deployment Picture
Q*Bird and the EuroQCI Portfolio
Q*Bird (Delft, Netherlands), founded in January 2022 as a spin-off from QuTech at TU Delft, describes itself as the world’s only commercial provider of MDI-QKD. Its Falqon® Series (MQX4000 hub, MQS4000 switch, MQT4000 user nodes) implements MDI-QKD in a hub-and-spoke, multi-tenant architecture.
QBird’s publicly documented field deployments and live research networks as of mid-2026 include: the Port of Rotterdam, Europe’s largest port, where a trial deployment in partnership with Eurofiber, Cisco, and Single Quantum was highlighted by the World Economic Forum as a case study in securing critical infrastructure; a 132 km cross-border Benelux link between Belgium and Luxembourg; MDI-QKD across major Dutch data centres under the Eurofiber QUEST project; Spain’s first multi-node MDI-QKD network connecting INTA and Ministry of Interior sites in Madrid; and Ireland’s first MDI-QKD network under the €10 million IrelandQCI project, with nodes deployed across Dublin. In June 2026, the Quantum Communication Fieldlab Rotterdam launched with QBird, Cisco, Eurofiber, CGI, and INSPIR8ION as founding partners.
A 2022 field deployment paper in Communications Physics, from the QuTech/TU Delft group that spawned Q*Bird, demonstrated MDI-QKD coexisting with over 10 Gb/s classical data across three Dutch cities. Coexistence with production network traffic is essential for any QKD technology that aspires to deployment beyond dedicated dark fibre.
Within EuroQCI, MDI-QUEEN is the dedicated MDI-QKD industrial project. Q*Bird has also secured €2.5 million grant plus €5 million equity through the EIC Accelerator 2025, and participates in Photonics for Quantum (P4Q), a €50 million European pilot line.
China’s MDI-QKD Research
Chinese groups, led by USTC and Tsinghua, have produced many of the foundational MDI-QKD experimental results, including the 404 km fibre distance record and significant work on MDI-QKD network architectures. The closely related TF-QKD distance records (833 km, 1,002 km) and the 2026 chip-based 20-user TF-QKD network are also Chinese results.
China’s deployed carrier-grade network, however, uses conventional decoy-state BB84 on the backbone and Gaussian-modulated CV-QKD in metropolitan segments, with trusted relay nodes connecting the links. MDI-QKD and TF-QKD remain primarily in the research pipeline. That may change: the 2026 chip-based TF-QKD network demonstrated integration and repeatable fabrication at a scale that points toward deployment readiness.
Toshiba and Twin-Field QKD
Toshiba’s Cambridge Research Laboratory proposed TF-QKD in 2018 and has driven its progression from proposal through laboratory demonstrations to real-network integration. The April 2025 trial was the first demonstration of TF-QKD integrated into commercial telecom infrastructure outside a dedicated metropolitan system. Toshiba’s QKD technology also powers Orange Quantum Defender, described by Orange and Toshiba as France’s first commercial quantum-safe networking service (launched June 2025 in Paris, with an unnamed French financial-services company among its first customers).
Other Regions
South Korea, Japan (including Toshiba’s domestic QKD deployments), and Singapore (which published a financial-sector QKD sandbox report) all maintain QKD programmes, though MDI-QKD-specific commercial deployments in these regions are not publicly documented as of mid-2026.
What MDI-QKD Does Not Solve
MDI-QKD removes the measurement device from the trusted part of the security model. It does not remove every other constraint that applies to QKD in general.
Source trust remains. Alice and Bob must trust their own state preparation. A 2023 experiment published in Optica demonstrated an attack against an MDI-QKD implementation through correlations and distinguishability in its source states, confirming that source-side vulnerabilities are real, not theoretical. Full device-independent QKD goes further by removing the need to characterise either source or measurement device, subject to its remaining assumptions about secure laboratories, randomness, authentication, and classical processing.
Distance limitations remain. Standard MDI-QKD’s range is constrained by fibre photon loss like all QKD, with no scaling advantage from the midpoint placement. TF-QKD extends reach to backbone distances (1,002 km demonstrated on spooled fibre), but at the record distance the finite-key rate was only about 0.001 bit/s. At shorter, operationally relevant distances, TF-QKD rates are orders of magnitude higher.
Availability remains a concern. A QKD channel that aborts when disturbed is a channel an adversary can disrupt at will.
Authentication still requires classical cryptography. The classical channel must be authenticated. Pre-shared symmetric authentication preserves information-theoretic security; PQC signatures provide a computationally secure bootstrap. QKD does not authenticate itself.
Certification is still emerging. ETSI has produced a Common Criteria protection profile for pairs of point-to-point prepare-and-measure QKD modules, but its scope does not directly cover MDI-QKD network architectures. The Nostradamus project is establishing an independent EuroQCI testing and evaluation facility at JRC Ispra with a view to future certification; operational activity is planned from 2026 onward.
What This Means For You
If you are a CISO or security architect evaluating QKD, MDI-QKD answers the single most damaging objection raised against commercial QKD systems: that the detectors can be attacked. It does so with hardware that has moved from a 2012 protocol proposal to commercial products operating over real European fibre in field deployments, live research networks, and testbeds.
The five evaluation questions from Quantum Ready apply to MDI-QKD as to any modality: what authenticates the classical channel, where keys exist outside quantum protection, the demonstrated key rate at your operating distance, the availability model when the channel is disrupted, and which specific risk this addresses that hybrid post-quantum key establishment leaves open and at what marginal cost.
Your immediate priority remains PQC migration. The regulatory deadlines are already set. But MDI-QKD has crossed the gap from protocol proposal to deployed hardware in thirteen years. Know what it solves. Know what it does not.