In ordinary point-to-point QKD (BB84) the secret key rate falls off linearly with the channel's transmittance η(L), because a single photon must survive the whole fibre. Twin-field QKD splits the same distance in half: Alice and Bob each send a weak coherent pulse only as far as an untrusted central node, where the two pulses interfere on a beamsplitter. A detector click reveals the parity of Alice's and Bob's phase-encoded bits without exposing either one — so the accessible key rate scales with √η(L) instead of η(L):
η(L) = 10^(−αL/10) fibre transmittance, α ≈ 0.2 dB/km
R_BB84 = ½μ·η(L)·[1−2h₂(QBER)] (repeaterless PLOB-type bound)
R_TF = ½μ·√η(L)·s·[1−2h₂(QBER)] s ≈ system overhead of phase-locked interference
h₂(x) = −x·log₂x − (1−x)·log₂(1−x) binary (error-correction) entropy
Because √η(L) decays half as fast (in dB) as η(L), the twin-field rate eventually overtakes BB84 even though it starts lower — the crossover distance shown above is where that happens for the current settings. This is the real reason twin-field QKD (Lucamarini et al., 2018) can push secure keys past the ~400–500 km repeaterless limit that ordinary fibre QKD cannot cross without trusted relays.
- Distance L — total Alice–Bob fibre length; each arm to the central node carries L/2.
- Mean photon number μ — average photons per pulse; higher μ raises the raw rate but also the multi-photon leakage risk in a real decoy-state analysis (simplified here).
- Visibility V — how precisely the two lasers' phases are locked at the central node; lower visibility directly raises the QBER.
- Dark-count rate — spurious detector clicks with no photon present; at long distance these start to dominate the true signal, which is what ultimately caps the reach of any QKD link.