Quantum

The qubit that carries two bits

A single quantum two-state system, sent from one person to another, can carry at most one bit of message — a theorem, not an engineering limit. If the two already share half each of an entangled pair, the sender can do one of four things to her half alone, send just that half, and the receiver can tell which of the four she did. Two bits arrive on one qubit. Nothing is free: the shared pair had to be delivered, and counted honestly the rate is still a bit per qubit. What entanglement buys is the freedom to send half the message before the message exists, and it also buys privacy, since the qubit in transit carries nothing at all on its own.
15 min read 5 figures Who is measuringWhat stays the same

Assumes: The correlation no instructions can produce · A link between two that never met

The correlation no instructions produce established that an entangled pair is correlated in a way no pre-arranged list of answers can imitate, and what two have they cannot give a third found that this correlation is a resource with a fixed supply: the more two systems share, the less either can share with anything else. A link between two that never met showed that it can be moved, by swapping. None of those essays asked what the resource is good for in the most practical sense: whether it can make communication cheaper.

It can, in one precise way, found by Charles Bennett and Stephen Wiesner in 1992. A message is sent by sending physical things, and a quantum two-state system — a qubit — sent on its own can carry at most one bit. With an entangled pair already shared between sender and receiver, a single qubit sent carries two. The argument is short, the bookkeeping that keeps it honest is shorter, and both say something exact about what entanglement is.

One qubit, one bit

A qubit can be prepared in any of a continuum of states — any point on a sphere of polarisations, say — and it is tempting to think it could therefore carry an unlimited amount of information, by encoding a long number in a precise direction. It cannot. Whatever the receiver does to it, a measurement of a two-state system has at most two outcomes that can be told apart with certainty, and only questions that commute can be asked together, so asking a second question disturbs the answer to the first. Alexander Holevo proved in 1973 that the classical information extractable from nn qubits, by any measurement whatever, is at most nn bits. The continuum of preparations is real; the information it can deliver is not.

The reason is easiest to see in a picture. The states of a qubit can be drawn as the points of a sphere, every direction on it a possible preparation. A measurement picks an axis and returns one of its two ends, with probabilities set by how close the prepared direction lies to each. Two preparations at opposite ends of the axis are told apart perfectly; any others are confused, sometimes giving the same answer. A sender who wanted to encode four messages could use four directions — the corners of a tetrahedron inscribed in the sphere, as far apart as four directions can be — but no axis separates four directions, and the best measurement the receiver can make extracts less than one bit from them. More elaborate measurements, with more than two outcomes, exist, and none does better; that is Holevo’s theorem.

If a qubit could be copied the bound would fall, since the receiver could make many copies and measure each along a different axis. It cannot be copied, and the two facts are related: both say that the information in a quantum state is not all accessible at once.

That bound is about qubits sent on their own. It says nothing about qubits that are halves of something the receiver already holds.

Four operations on one half

Suppose sender and receiver share a pair of qubits in the entangled state

∣Φ+⟩=12(∣00⟩+∣11⟩),|\Phi^+\rangle = \frac{1}{\sqrt2}\left(|00\rangle + |11\rangle\right),

the sender holding one qubit and the receiver the other. To send two bits, the sender does one of four things to her qubit alone: nothing, a flip (XX, which exchanges 0 and 1), a phase shift (ZZ, which gives 1 a minus sign), or both. Then she sends her qubit to the receiver, who now holds both.

Four operations on one half, four states of the pair. The sender holds one half of an entangled pair prepared in the state |Φ+⟩ = (|00⟩ + |11⟩)/√2, the receiver the other. To send two bits she applies one of four operations to her half alone — do nothing, flip it (X), shift its phase (Z), or both — and sends it. The table gives, computed from the state vectors, the probability that the receiver's joint measurement of both halves in the Bell basis returns each of the four Bell states: one on the diagonal, zero everywhere else. Four perfectly distinguishable outcomes from one transmitted qubit is two bits. Sent without the pair, a qubit can carry at most one.
Fig. 1 The probability that the receiver’s joint measurement of both qubits returns each of the four Bell states, for each of the sender’s four operations on her half of |Φ+⟩, computed from the state vectors. Doing nothing leaves Φ+; a flip makes Ψ+; a phase shift makes Φ−; both make Ψ−. The table is the identity: four outcomes, each certain.

The four operations turn ∣Φ+⟩|\Phi^+\rangle into four different states of the pair — ∣Φ+⟩|\Phi^+\rangle, ∣Ψ+⟩|\Psi^+\rangle, ∣Φ−⟩|\Phi^-\rangle and ∣Ψ−⟩|\Psi^-\rangle, the four Bell states — and those four are mutually orthogonal. Orthogonal states can be told apart with certainty by a suitable measurement, and the suitable measurement here is a Bell measurement: a joint measurement on both qubits whose four outcomes are exactly the four Bell states. The figure computes the probabilities from the state vectors: the diagonal is all ones and everything else zero. The receiver learns which of the four operations was done, which is two bits, from one qubit that travelled.

The striking feature is where the information lives. The sender acted on her qubit only. Her operations change the state of the pair, but not the state of either half on its own: before and after, each qubit by itself is completely random. The two bits are written into the correlation between the halves, and they can be read only when both halves are in one place.

Where the two bits are while they travel

It is worth stopping on the moment between the sender’s operation and the qubit’s arrival, because something there looks impossible. The sender has done one of four things; the receiver’s half has not been touched and, by the time the sender’s qubit arrives, the choice has been made and fixed. Where are the two bits in the meantime?

Not in the receiver’s qubit. Its state, by itself, is completely random before the sender acts and completely random after, whatever she did — a sender acting on her half cannot change a single probability the receiver could measure on his, which is why the correlation of an entangled pair cannot be used to signal. Not in the sender’s qubit either, for the same reason in reverse: by itself it is also completely random, both before her operation and after. The two bits are in the relation between the qubits — in which of four ways the two random halves are correlated — and a relation between two things in two places can be read only by bringing them together. That is what the travelling qubit does. It is not a carrier of the message so much as the second half of a key that the receiver has been holding all along.

The qubit in transit carries nothing

That feature has a consequence that matters as much as the doubling. Anyone who intercepts the travelling qubit alone — without the receiver’s half — holds a qubit whose state is completely random whatever the sender did. For a maximally entangled pair the four operations leave its state exactly the same, and no measurement on it can distinguish them. The message is not encrypted on the qubit; it is simply not on the qubit.

What the receiver gets, and what an eavesdropper could. For a shared pair in the state cos θ|00⟩ + sin θ|11⟩, against θ: the most classical information the receiver can extract per qubit sent (solid), 1 + H(cos²θ) bits, and the most an eavesdropper who intercepts the travelling qubit alone can extract (dashed), 1 − H(cos²θ), where H is the binary entropy. At 0°: 1.000 and 1.000; at 15°: 1.355 and 0.645; at 30°: 1.811 and 0.189; at 45°: 2.000 and 0.000. The two always sum to two bits. With no entanglement (θ = 0) the receiver gets one bit and so could anyone who caught the qubit; with a maximally entangled pair (45°) the receiver gets two and the travelling qubit, on its own, carries none at all.
Fig. 2 For a shared pair in the state cos θ|00⟩ + sin θ|11⟩: the most information the receiver can extract per qubit sent (solid), 1 + H(cos²θ) bits, and the most an eavesdropper on the travelling qubit can extract (dashed), 1 − H(cos²θ). At 0° both are one bit; at 15°, 1.355 and 0.645; at 30°, 1.811 and 0.189; at 45°, two and zero. They always sum to two.

The figure follows both quantities as the shared pair is made less entangled. With no entanglement at all, the protocol degenerates into sending a qubit, and the receiver can extract one bit — and so can an eavesdropper who catches it, since then the qubit carries the message alone. As entanglement grows the receiver’s share rises and the eavesdropper’s falls, and the two always add to exactly two bits. For a maximally entangled pair the receiver gets both bits and the qubit in transit carries nothing.

The sum is not a coincidence. It is the statement that two bits are encoded, and that whatever part of them is not in the correlation the receiver can read must be on the travelling qubit where anyone can read it. Entanglement moves information off the channel and into the correlation, and the correlation cannot be shared with a third party, which is why it is private.

Counting honestly

The bookkeeping: nothing is free. Resources spent (bars) and what they buy (right), for four ways of moving information. A qubit sent alone carries one bit. With one entangled pair shared in advance, one qubit carries two bits. But the pair had to be delivered, which took a qubit too: counted in full, dense coding sends two bits for two qubits, exactly the rate of sending them one at a time. What it changes is timing — the pair can be delivered before the message exists. Teleportation runs the same exchange backwards: two classical bits and a shared pair move one qubit.
Fig. 3 Resources spent and what they buy. A qubit alone: one bit. One qubit and one shared pair: two bits. The same with the pair’s delivery counted as the qubit it took: two qubits, two bits. Teleportation, the reverse exchange: two bits and one shared pair move one qubit.

The shared pair did not appear from nowhere. To share it, one of its qubits had to be sent from wherever it was made to the receiver — or to the sender — and that is a qubit sent. Counted in full, dense coding sends two bits for two qubits, exactly the rate Holevo’s bound allows. Entanglement has not made communication cheaper in total.

What it has done is separate the cost in time. The pair can be distributed in advance, when the channel is idle or cheap, before the message exists. When the message is ready, only one qubit need be sent for every two bits. A channel whose capacity matters only at certain moments — a link to a spacecraft during a short pass overhead, say — can be pre-loaded with pairs and then carry twice its normal rate when it counts.

Nor has it made communication faster. The two bits reach the receiver exactly when the qubit does, and not a moment before; until it arrives, nothing he can do to his own half reveals anything about what the sender did. Entangled pairs have been accused, over the years, of carrying influences faster than light, and dense coding is a clean demonstration that whatever they carry, it is not a message. The message rides on the qubit that travels, at the speed the qubit travels. The pair only makes that qubit worth twice as much when it gets there.

The exchange also runs backwards. Teleportation uses a shared pair and two classical bits to move a qubit’s unknown state from sender to receiver, without the qubit itself travelling. Dense coding uses a shared pair and one qubit to move two classical bits. In the language of resources, one shared pair plus one qubit is worth two bits, and one shared pair plus two bits is worth one qubit, and neither exchange can be improved. Both are ways of spending the same thing.

The pre-loading is not hypothetical. Entangled pairs are distributed for other purposes — for key exchange, and to link the nodes of future quantum networks — and the distances have grown from a laboratory bench to a satellite: in 2017 the Chinese satellite Micius sent entangled photon pairs to two ground stations twelve hundred kilometres apart. Any such pair, once delivered and stored, is a pair that a later message can use to send two bits per qubit, and protocols built on that idea, in which the shared pairs also serve to detect eavesdropping, were proposed within a decade of Bennett and Wiesner’s paper. Storing the pairs, rather than distributing them, is the hard part: a photon cannot be kept waiting for long, and a memory that holds entanglement for seconds without spoiling it is still a laboratory achievement.

Not every entangled pair will do

Real pairs are not perfect. They are made by imperfect sources and travel through channels that add noise, and what arrives is a mixture of the intended state and something random. The simplest model mixes the perfect pair, with weight pp, with complete noise.

Entangled, and still no help. The dense-coding capacity, in bits per qubit sent, for a shared pair that is a mixture of the perfect Bell state (weight p) and complete noise (weight 1 − p), computed as max(1, 2 − S) from the entropy S of the mixture's 4 × 4 density matrix. At p = 0.6: 1.000 bits; at p = 0.8: 1.152 bits; at p = 1.0: 2.000 bits. The pair beats a lone qubit only above p = 0.748, although it is entangled for every p above 1/3 (dashed). Between the two thresholds the pair holds entanglement that cannot be spent on this task: entanglement is necessary for dense coding and not sufficient.
Fig. 4 Dense-coding capacity for a pair that is the perfect Bell state with weight p and complete noise with weight 1 − p, computed as max(1, 2 − S) from the entropy S of the mixture’s density matrix. At p = 0.8 it is 1.152 bits. The pair beats a lone qubit only above p = 0.748, though it is entangled above 1/3 (dashed); between, the shaded range is entangled and useless for this.

Such a mixture is entangled whenever pp exceeds one third: below that it could have been made by preparing the two qubits separately with shared random instructions, above it it could not. Yet it helps dense coding only when pp exceeds about three quarters. The capacity is the two bits a perfect pair would give minus the entropy of the actual pair — a count of how many states it might be in — and until the entropy falls below one bit, the pair is worth nothing over a lone qubit.

Where the noise comes from matters for how to fight it. A pair made perfectly and then stored drifts towards the mixture because each half interacts, however weakly, with its surroundings, and every interaction lets the surroundings take a share of the correlation that the two halves were holding exclusively. Monogamy makes that a zero-sum process: whatever correlation the environment gains, the pair loses. Repairing it is possible in principle — many noisy pairs can be distilled into fewer good ones by local operations and classical messages between the holders — but distillation consumes pairs, so a channel that delivers noisy pairs delivers fewer useful ones. Every figure of merit for a quantum link is in the end a count of how many pairs above the relevant threshold it can deliver per second.

So entanglement is necessary for dense coding and not sufficient. There is a range of pairs that are certainly entangled — no classical recipe could make them — and still useless for this task, and other tasks draw on entanglement in other ways and have other thresholds. Asking whether a state is entangled is a yes-or-no question; asking what it is good for has a different answer for every use.

The hard part is reading it

The protocol needs the receiver to perform a Bell measurement, a joint measurement on two qubits that sorts them into the four Bell states. For qubits that interact, such as trapped ions, that is a pair of standard operations followed by measuring each qubit. For photons, the most natural carriers of a message, it is hard, because photons do not interact with each other.

How much of the two bits a photon experiment can read. Bits per transmitted photon in dense coding: the one-bit limit of a lone qubit; the log₂3 = 1.585 bits available when the receiver uses beam splitters and detectors alone, which can tell apart only three of the four Bell states (two of them land in the same detectors); 1.63 bits measured in 2008 with photon pairs entangled in polarisation and in orbital angular momentum at once, the second entanglement serving to tell all four apart; and the ideal two. The protocol is simple; what limits it with light is the joint measurement, which needs the two photons to interact and photons do not.
Fig. 5 Bits per photon sent in dense coding: one for a lone qubit; log₂3 = 1.585 when the receiver uses only beam splitters and detectors, which can separate three of the four Bell states; 1.63 measured in 2008 with photon pairs entangled two ways at once; and the ideal two.

With beam splitters and photon detectors alone, two photons can be sorted into at most three classes that separate the Bell states, because identical photons meeting at a beam splitter leave together in two of the four cases and in the same way, so two of the states cannot be told apart. The first experiment, by Klaus Mattle, Harald Weinfurter, Paul Kwiat and Anton Zeilinger in 1996, therefore sent “trits” — one of three distinguishable messages per photon, log⁡23=1.585\log_2 3 = 1.585 bits at best. In 2008 Julio Barreiro, Tzu-Chieh Wei and Kwiat used photon pairs entangled both in their polarisation and in the twist of their wavefronts, used the second entanglement to help read the first, and measured a capacity of 1.63 bits per photon — beyond the linear-optics limit for photons entangled in one way only.

Qubits that do interact avoid the problem entirely. In 2004 a group at the National Institute of Standards and Technology in Boulder carried out dense coding with two beryllium ions in a trap, where a Bell measurement is a pair of laser-driven operations followed by reading each ion’s fluorescence, and distinguished all four encodings well enough for a capacity above the one-bit limit. The ions travelled nowhere — they sat micrometres apart — so the experiment demonstrated the protocol’s logic rather than a communication link; photons travel well and are hard to read jointly, and ions read well and are hard to send, which is the general shape of the engineering problem behind every quantum network.

What the pictures cannot show

The protocol figure is the ideal: perfect operations, a perfect pair and a perfect Bell measurement. Every real implementation loses some of each, and what is measured is a channel capacity below two, as the last figure shows. The tradeoff figure assumes the eavesdropper intercepts only the travelling qubit; an eavesdropper who had also tampered with the distribution of the pair, earlier, is a different problem, and the security of dense coding against that is a question for the protocols that check the pairs before use.

And no figure shows why the Bell measurement is the right one, beyond the arithmetic. The four Bell states are the natural basis for a pair whose information is all in its correlations, and the measurement that reads them reads only correlations — which is why it destroys the entanglement it reads.

The domain of the argument is two parties sharing an entangled pair and a quantum channel. Inside it, one qubit carries up to two bits, and the excess is paid for by the pair. Without the pair, Holevo’s bound holds and one qubit is one bit.

Still open: how far the advantage scales

For larger systems the arithmetic generalises: a pair of dd-level systems, maximally entangled, lets one dd-level system carry 2log⁡2d2\log_2 d bits. With several senders sharing one entangled state with a single receiver, the gains combine in ways that depend on the structure of the shared state, and for most multi-party states the dense-coding capacity is not known in closed form. Experimentally, high-dimensional entanglement — photons entangled in many paths, or in many values of their wavefronts’ twist — has been made, and the hard part remains the joint measurement, which for photons needs either interactions that photons lack or extra degrees of freedom to borrow. How large a dense-coding advantage can be realised in practice, and whether it will matter in quantum networks, where shared pairs are already being distributed for other purposes, is open.

What is not open is the accounting. A qubit sent alone carries at most one bit; one qubit sent against a shared entangled pair carries two, because the sender’s four operations on her half of |Φ+⟩ give four orthogonal states of the pair, each found with certainty — and the travelling qubit, on its own, carries none of it. Counted with the pair’s delivery, it is still a bit per qubit: entanglement buys the freedom to send half the cost in advance, and privacy for the half sent later.

Part 6 of 6

This essay is one argument about Entanglement. The others:

The objects named here

The third axis, after the field and the reading path: the things themselves, and every essay that touches each one.

Bell stateEntanglementEntropyHolevo boundMeasurementQuantum informationQubitTeleportation