Standard telecom fiber loses about 0.2 dB of optical power per kilometer at 1550 nm. Over 200 km that is 40 dB, which means roughly one photon in ten thousand survives the trip. On a classical link we solve this with an amplifier every 80 km or so. On a quantum link we can’t, because the no-cloning theorem forbids copying an unknown quantum state, and an amplifier is a copier.
Almost every hard problem in quantum networking descends from those two facts. Entanglement distribution is the work of getting a shared entangled state into two distant places anyway, and there are three mechanisms available: direct transmission, entanglement swapping, and entanglement purification. Each one buys distance or quality at a price, and the price is what an architect has to budget for.
This guide treats those three mechanisms at design level. The physics appears only as far as it constrains engineering choices, and every number given here is one you can put into a link budget.
The Resource Being Moved
The unit of currency in a quantum network is the Bell pair, also called an EPR pair. It is a two-qubit entangled state, and there are four of them:
|Φ+⟩ = (|00⟩ + |11⟩)/√2
|Φ−⟩ = (|00⟩ − |11⟩)/√2
|Ψ+⟩ = (|01⟩ + |10⟩)/√2
|Ψ−⟩ = (|01⟩ − |10⟩)/√2
Alice holds one qubit, Bob holds the other, and their measurement outcomes are correlated in a way no classical shared randomness can reproduce. That correlation is the whole product. Quantum key distribution turns it into key material, teleportation turns it into a channel for quantum data, and distributed quantum computing turns it into a two-qubit gate between processors that are not in the same room.
Two properties of this resource shape network design more than anything else. It is single-use, because reading the correlation destroys it, and teleporting one qubit consumes exactly one Bell pair. And it is perishable, because a stored qubit decoheres, so a pair sitting in memory is losing value the whole time it waits.
The word you will see attached to every entangled pair in a specification is fidelity. Fidelity is the overlap between the state you actually have and the ideal Bell state you wanted, on a scale from 0 to 1. A perfect pair has fidelity 1. For the common noise model used in link budgets, a pair stops being entangled at all below fidelity 0.5, so 0.5 is a floor rather than a target. Useful protocols want considerably more.
Most photonic entanglement sources today use spontaneous parametric down-conversion (SPDC), in which a pump laser passing through a nonlinear crystal occasionally splits one photon into an entangled pair. The word “occasionally” decides the budget. SPDC is probabilistic, and turning the pump up to get more pairs also raises the chance of emitting two pairs at once, which corrupts the state. Quantum dot sources aim at on-demand emission instead, and that is one of the live hardware races.
Direct Transmission and Where It Stops
The simplest architecture puts a source between two nodes and sends one photon each way. Nothing to trust, nothing to store, nothing to schedule. It works, and it does not scale.
Loss in fiber is exponential in distance, so a midpoint source over a total span L gives a coincidence probability of about 10^(−0.02L) at 0.2 dB/km. That produces a short and unforgiving table:
| Total span | Loss | Pairs surviving |
|---|---|---|
| 50 km | 10 dB | 1 in 10 |
| 100 km | 20 dB | 1 in 100 |
| 200 km | 40 dB | 1 in 10,000 |
| 300 km | 60 dB | 1 in 1,000,000 |
Raw survival is not the binding constraint at the far end of that table. Detector noise is. Every single-photon detector fires occasionally with no photon present, and once the signal rate falls toward the dark-count rate, the coincidences you record stop being real. Superconducting nanowire single-photon detectors (SNSPDs) push the noise floor down far enough to matter, at the cost of a cryostat at every receiver. That is a facility line item, not a component line item.
The published records tell the same story. Ursin and colleagues distributed entanglement across 144 km of free space between La Palma and Tenerife in 2007. Neumann and colleagues reported continuous entanglement distribution over a 248 km transnational deployed fiber link in Nature Communications in 2022, using ultralow-loss fiber and careful polarization stabilization. Both are real achievements and neither is a network. Somewhere between 50 and 100 km, direct fiber transmission stops delivering a rate anyone can build a service on.
Free space changes the arithmetic because vacuum does not absorb. China’s Micius satellite beamed entangled photon pairs to two ground observatories about 1,200 km apart in 2017, and the pairs arrived still entangled, violating a Bell inequality under strict locality conditions. Yin and colleagues reported the result in Science. The detected pair rate was roughly one per second, which tells you what “solved” means here: the distance problem yielded and the rate problem did not. Satellite links also need clear skies, darkness, and telescope tracking, so availability is an operational planning input rather than an assumption.
Trusted Nodes Are an Architecture Decision
Because direct transmission runs out at around 100 km, every long quantum network in service today does something else. It chops the route into short segments and puts a node between each pair of them. At that node the quantum state is measured, the resulting key material exists briefly in cleartext, and a fresh quantum signal is launched onward. The node knows the secret. That is what “trusted node” means, and the trust is not a figure of speech.
The Beijing to Shanghai backbone is the reference deployment: roughly 2,000 km of fiber connecting four cities through 32 trusted relays, operational since 2017. In 2021, Chen and colleagues reported in Nature an integrated network combining that fiber infrastructure with satellite links, reaching about 4,600 km end to end. Smaller trusted-node testbeds have run in Vienna and Tokyo, and they taught the field a great deal about routing, key management, and living alongside classical traffic.
None of this is a compromise to be embarrassed about. It is a defensible engineering choice with a clearly statable threat model, and the model is the same one we already accept for a VPN concentrator or an HSM in a colocation facility. What matters is that the trust boundary appears on the diagram. Vendors will call every one of these deployments a quantum network, and buyers should ask a single question before signing: does any intermediate device hold my key material in the clear? If the answer is yes, the physics is not doing the work the marketing implies, and the node needs the same physical and personnel controls as any other custodian of plaintext keys.
Removing that node from the trust boundary is the entire purpose of the next mechanism.
Entanglement Swapping
Put three nodes in a line. Alice and Bob share one entangled pair, Bob and Charlie share another, and Bob therefore holds two qubits, one from each pair. Alice and Charlie share nothing and have never interacted.
Bob now performs a Bell state measurement (BSM), a joint measurement on his two qubits that projects them onto the Bell basis and returns one of four outcomes. The moment he does, Alice’s qubit and Charlie’s qubit become entangled. The two original pairs are consumed, and a new pair appears between two parties that never met.
The identity behind it is worth seeing once, because the resource accounting follows from it directly. Rewriting two Bell pairs in the Bell basis of Bob’s qubits:
|Φ+⟩_AB ⊗ |Φ+⟩_CD = ½ ( |Φ+⟩_BC|Φ+⟩_AD + |Φ−⟩_BC|Φ−⟩_AD + |Ψ+⟩_BC|Ψ+⟩_AD + |Ψ−⟩_BC|Ψ−⟩_AD )
Each term pairs one outcome for Bob with one resulting state for Alice and Charlie. Bob’s measurement picks a term, and the end nodes are left holding the matching Bell state. Which one they hold depends on his outcome, so he sends them two classical bits and they apply a local correction if the protocol needs a specific state. For key distribution any known Bell state works, and the correction can often be folded into the classical post-processing instead.
Three consequences for design.
Swapping needs a classical channel. Two bits per swap, and the end nodes cannot complete the operation until those bits arrive. From this point on, every hop adds a classical round trip to the end-to-end delay.
Bob learns nothing about the resulting state. His outcome tells him which of the four Bell states Alice and Charlie share and nothing about any measurement they will later make on it. A swapping repeater is not a trusted node. This is the property that changes the threat model, and it is why the entire quantum repeater program exists.
Photonic BSMs have a hard ceiling. With linear optics and no ancillary photons, only two of the four Bell states can be distinguished, so a purely photonic swap succeeds at most half the time. Matter qubits with a genuine two-qubit gate can do better, which is one reason serious repeater designs put a quantum memory in the middle rather than a beamsplitter.
Pompili and colleagues demonstrated the full sequence in a three-node solid-state network at Delft, reported in Science in 2021. Nitrogen-vacancy centers in diamond served as the nodes. Alice and Bob entangled first, Bob stored his half in a nuclear-spin memory, Bob and Charlie entangled second, and Bob then performed the BSM across the stored qubit and the fresh one, leaving Alice and Charlie entangled. Every element a repeater needs appeared in one experiment: link generation, storage, joint measurement, heralded delivery. The rate was low enough that successful events were counted individually, and that is the honest summary of where the technology sits.
What Swapping Costs in Fidelity
Chaining swaps extends reach, and it also compounds error, so an architect needs a hop budget the same way an optical engineer needs a loss budget.
The standard model treats a noisy pair as a Werner state, which is an ideal Bell state mixed with a fraction of uniform noise. A single number w between 0 and 1 describes it, and fidelity relates to it as F = (3w + 1)/4. When two Werner-state links are swapped with a perfect Bell measurement, the resulting pair is also a Werner state, and its parameter is simply the product of the two inputs.
That multiplication is the whole story. Over a chain of n links, w decays as w^n, which is exponential in the number of hops.
Work it through with a link fidelity of 0.95, which is optimistic for deployed hardware. That corresponds to w = 0.933.
- Three links, two swaps: w = 0.933³ = 0.813, so F = 0.86.
- Ten links, nine swaps: w = 0.933¹⁰ = 0.502, so F = 0.63.
Ten hops at 95 per cent per link deliver 63 per cent end to end, and that assumes the swaps themselves are perfect. Real Bell measurements add their own infidelity and real memories decohere while they wait. A chain long enough to be useful degrades below any threshold worth having, which is why swapping alone does not produce a quantum internet. Something has to push fidelity back up between hops.
Entanglement Purification
Purification, also called distillation, converts quantity into quality. Two noisy pairs go in, one better pair comes out, and sometimes nothing comes out at all.
The mechanics are local operations plus a classical comparison. Alice and Bob each hold one qubit from each of two pairs. Each of them applies a CNOT gate between their two qubits, then measures one of them and announces the result. If the two announcements agree, they keep the surviving pair, which is now more likely to be the state they wanted. If the announcements disagree, an error was present and both pairs are discarded.
The standard version is the recurrence protocol of Bennett, Brassard, Popescu, Schumacher, Smolin and Wootters, usually shortened to BBPSSW. It takes Werner-state inputs and returns the output to Werner form before the next round, which is what keeps a single fidelity number sufficient to describe the state. For inputs of fidelity F, one round gives:
success probability p = F² + 2F(1−F)/3 + 5((1−F)/3)² output fidelity F′ = (F² + ((1−F)/3)²) / p
Whenever F is above 0.5, F′ exceeds F. Below 0.5 the protocol makes things worse, which is the same threshold from earlier arriving in a second guise.
The Resource Cost, Worked
Start at F = 0.60, which is what a long unassisted link might actually deliver, and run three rounds.
| Round | Input F | Success p | Output F |
|---|---|---|---|
| 1 | 0.600 | 0.609 | 0.620 |
| 2 | 0.620 | 0.622 | 0.645 |
| 3 | 0.645 | 0.638 | 0.673 |
Three rounds take a 60 per cent pair to 67 per cent. Convergence near the bottom of the range is slow, and that is the first surprise for anyone who has only seen the protocol described qualitatively. Now count the inputs. Each round consumes two pairs and returns one with probability p, so on average you need 2/p input pairs per output pair. That gives 3.28 pairs at round one, 3.22 at round two, and 3.13 at round three, and the rounds nest:
2 / 0.609 × 2 / 0.622 × 2 / 0.638 ≈ 33 raw pairs at F = 0.60 for one pair at F = 0.67.
Thirty-three to one, in the idealized case, with perfect local gates and memories that never decohere, and the output is still only two-thirds faithful. Pushing the same starting fidelity past 0.90 takes ten rounds of the recurrence, and the input count runs into the tens of thousands. The real ratios are worse than either figure. This is the arithmetic that decides whether a repeater architecture is viable, and it is why raw entanglement generation rate is the specification to interrogate first when evaluating hardware, alongside the fidelity you start from. A source that produces ten pairs per second on a link is not a ten-pair-per-second service. It might be a service that delivers one usable pair every three seconds at a fidelity below 0.7, and only if the memories hold.
Rate, Memory, and the Timing Budget
Purification imposes a constraint that does not appear in the fidelity mathematics at all: both pairs must exist at the same time, in memory, at both ends, while the classical messages travel.
Light moves through fiber at roughly 200,000 km per second. A 100 km link is therefore 0.5 ms one way and 1 ms for a round trip. Every round of purification costs at least one round trip, and a repeater chain needs its swap outcomes propagated as well. Three rounds of purification on a 100 km link is 3 ms of coherence, minimum, before any processing overhead. Scale the link to 500 km between repeater stations and the same three rounds need 15 ms. Memory coherence time is not a nice-to-have specification. It is the term that decides your maximum station spacing.
Two more parameters belong in the same budget.
Heralding. A heralded protocol produces a signal telling the nodes that entanglement succeeded, so they know which attempts to keep. Without heralding the network has no way to distinguish a stored pair from an empty memory, and scheduling becomes impossible. Every serious repeater design is heralded.
Multiplexing. Because entanglement generation is probabilistic, a memory that can hold only one attempt at a time wastes almost all of its duty cycle. Multiplexed memories store many distinguishable modes at once, in time, frequency, or space, and the rate improvement is close to linear in the mode count. Lago-Rivera and colleagues at ICFO reported telecom-heralded entanglement between multimode solid-state memories in Nature in 2021, using rare-earth-doped crystals with dozens of temporal modes. A group at USTC published a companion result using absorptive memories in the same issue. Mode count is the specification that turns a laboratory link into something with a throughput figure.
There is a third quiet constraint. Many good memory materials absorb and emit at wavelengths that fiber treats badly, so a quantum frequency converter has to shift the photon into the 1310 nm or 1550 nm telecom bands and back without destroying the entanglement. Every conversion stage adds loss and infidelity. Memories that work natively at telecom wavelengths avoid the problem entirely, and that is why the telecom-band results carry more architectural weight than their distances suggest.
What Is Actually Deployed
Setting the marketing aside, the field divides cleanly into three tiers.
In production. Trusted-node key distribution networks over metropolitan and national fiber, with the Beijing to Shanghai backbone and its satellite extension as the largest example. Short direct-transmission links inside a campus or a metro ring. These work, they are buyable, and the trust boundary includes the operator.
Demonstrated at record distances, not deployed. Satellite entanglement distribution at 1,200 km. Deployed-fiber entanglement at 248 km. Quantum teleportation across a 44 km metropolitan fiber loop with fidelity above 90 per cent, reported by the Caltech and Fermilab collaboration in PRX Quantum in 2020. Each of these is a single link operated by specialists, not a service.
Prototype. Multi-node entanglement swapping, as at Delft. Multiplexed telecom-heralded memories, as at ICFO and USTC. Nothing in this tier has yet been assembled into a chain that beats a trusted-node network end to end, and that crossover is the milestone worth watching for.
Wehner, Elkouss and Hanson set out a six-stage capability model in Science in 2018 that remains the cleanest way to place a given deployment. It runs from trusted-repeater networks at the bottom, through prepare-and-measure and entanglement distribution networks, up to quantum memory networks and finally fault-tolerant quantum computing networks. Almost everything in the field today sits at stage one, with laboratory demonstrations reaching into the middle stages. Ask any vendor which stage they are selling, and the conversation gets more precise immediately.
Designing Around What Exists
Here is what all of the above turns into when you have a diagram in front of you.
Fix the trust boundary before the topology. If the requirement is end-to-end security with no trusted intermediary, no trusted-node product satisfies it at any price today, and the honest answer is a shorter direct link or a wait. If trusted relays are acceptable, say so in writing, and give each relay the physical and personnel controls that a plaintext key custodian deserves.
Budget hops, not just kilometers. Fidelity multiplies across swaps. Two links at 0.95 give 0.90 in Werner terms; ten give 0.63. Decide the end-to-end fidelity the application requires, then work backward to a maximum hop count, then place stations accordingly. A topology with fewer, longer links can beat one with more, shorter links, even when the total loss is higher.
Treat coherence time as station spacing. One classical round trip per purification round, at 200,000 km per second in fiber. If the memory holds for 10 ms and the protocol needs three rounds plus overhead, the geography is already decided for you.
Ask for rate at a stated fidelity. A raw pair rate with no fidelity attached is not a specification. The useful number is delivered pairs per second above the fidelity threshold your application needs, after purification, and the ratio between the two can be thirty to one or worse.
Ask for mode count. Multiplexing is the difference between a link that produces a pair every few minutes and one that produces a stream. It is the least discussed and most consequential number on a memory datasheet.
Plan the classical network alongside the quantum one. Swapping outcomes, purification comparisons, and basis sifting all need low-latency, authenticated classical channels running in parallel with the quantum channels. Delft’s link layer protocol work, published at SIGCOMM in 2019, is the first serious attempt at what this layer should look like, and the network stack question is still open. Whoever designs the quantum layer will inherit the classical timing requirements whether or not they planned for them.
Assume coexistence with classical traffic. Quantum signals are single photons in fibers that may also carry watts of classical light. Wavelength separation and filtering make coexistence possible, and Raman scattering from the classical channels sets the limit. Dedicated dark fiber removes the problem and adds a recurring cost. Both are legitimate answers, and the choice belongs in the design phase rather than the commissioning phase.
Where This Sits in a Career Path
Entanglement distribution is one of the few areas in quantum technology where the engineering questions are already concrete enough to specify, procure, and argue about. The physics has settled. What remains is loss budgets, coherence budgets, scheduling, trust boundaries, and the honest comparison between a trusted-node deployment available now and a repeater architecture that isn’t. Those are architecture problems, and the people who will answer them are network architects who took the time to learn the constraint set.
That is the ground the Certified Quantum Network Architect (CQNA) program covers. We build it around the same material treated here, worked at specification depth: link and fidelity budgets, repeater topologies, memory and timing constraints, the trust-boundary analysis that separates a quantum-secured network from a quantum-marketed one, and the vendor questions that get you a straight answer. Candidates finish able to read a quantum network proposal and say precisely what it delivers and what it does not.
You can review the program and its prerequisites at Quantum Academy. For deeper technical treatment of the underlying physics and the current experimental record, PostQuantum.com carries a longer analysis of entanglement distribution techniques.