Quantum

The state that cannot be copied

Every measurement in this collection disturbs what it measures, and the obvious way round that is to make a spare first. It cannot be done, and the reason is not a practical difficulty or a limit on how good an apparatus can be: a copier is a linear machine, so fixing what it does to two states fixes what it does to their superpositions, and what it then does is not a copy.

Assumes: The answer that was not there before · The correlation no instructions can produce

A measurement gives an answer that was not there before, and having given it, the state is the answer. The obvious repair is to make a spare copy first, measure one and keep the other, and thereby find out two incompatible things about the same state.

Three copiers, and what each of them costs. How well three copying machines reproduce a qubit, against the state's angle from the pole. The first is a linear machine built to copy the two pole states perfectly; linearity then fixes what it does everywhere else, and on an equal superposition it produces an entangled pair whose overlap with the two copies wanted is exactly 0.500. That is the no-cloning theorem written as a number rather than as an argument: no adjustment is available, because the machine's behaviour on superpositions was decided the moment its behaviour on the basis was. The second measures in a fixed basis and prepares two copies of what it found, which is perfect at the poles and averages 0.6667 over the sphere — two thirds, exactly. The third is the best machine there is, and it manages 0.8333 on every state alike: five sixths, and not one.
Fig. 1 Three copying machines and how well each reproduces a qubit, against the state’s angle from the pole. The linear machine built to be perfect on the poles scores exactly one half on the equator, and the best machine there is manages five sixths everywhere.

The repair is not available, and what forbids it is not delicacy. It is linearity, and the contradiction can be computed rather than argued.

The one-line argument, done as arithmetic

Suppose a machine exists that takes an unknown state and a blank and produces two copies. Quantum evolution is linear, so the machine is a linear map, and a linear map is completely determined by what it does to a basis.

Build it to be perfect on the two basis states: 0|0\rangle becomes 00|00\rangle, 1|1\rangle becomes 11|11\rangle. Nothing has been assumed about the mechanism, and there is now no freedom left. Feed it the equal superposition +=(0+1)/2|+\rangle = (|0\rangle + |1\rangle)/\sqrt2 and linearity gives the output immediately:

12(00+11).\frac{1}{\sqrt2}\big(|00\rangle + |11\rangle\big).

That is not ++|+\rangle|+\rangle. It is an entangled pair, in which neither half is in a definite state at all. The overlap between what came out and what was wanted is computed in the figure and is exactly 0.5000.500.

The failure is total rather than marginal, and no better design is possible because no design entered the argument. The general statement is even shorter: unitary evolution preserves inner products, so cloning would require ψφ=ψφ2\langle\psi|\varphi\rangle = \langle\psi|\varphi\rangle^2, which holds only for states that are identical or orthogonal.

There is a small point about the word “unknown” that is worth making explicit, because it carries the whole theorem. If the state is known — if somebody has a description of it written down — then arbitrarily many copies can be prepared, by making them from the description. What cannot be done is copy a state whose description nobody has. The prohibition is therefore not about the state as a physical object; it is about the impossibility of obtaining the description from a single instance, which is the same statement the measurement problem makes.

What can be done instead, and how well

A machine that cannot copy perfectly might still copy badly, and how badly is a quantitative question with a quantitative answer.

The crudest approach is to measure and then prepare two copies of whatever was found. That is perfect for a state that happens to lie along the measurement axis and poor for one at right angles to it, and averaged over all states it scores 0.66670.6667 — two thirds, exactly, and the figure computes it by integrating over the sphere with the correct measure.

The best machine there is does better and is flat. The optimal universal cloner reaches 0.83330.8333 — five sixths — on every input state alike, which is the property that matters: an adversary cannot choose to be good at the states that will actually be sent.

Five sixths is not one, and the gap is where quantum key distribution lives.

A key distribution protocol sends states in two bases chosen at random, and an eavesdropper who must choose an analyser before knowing the basis is in exactly the position the fidelity bound describes. Transmission through an analyser at the wrong angle destroys the information it was trying to read and announces itself in the error rate, so the protocol’s security is not a claim about how hard the eavesdropping is. It is a claim about what the eavesdropping does.

Send single photons polarised in one of two randomly chosen bases. An eavesdropper who intercepts them must either measure — in which case she has to guess the basis and disturbs the ones she guesses wrong — or copy, in which case the best copy she can make is a five-sixths one and her copies disagree with the originals. Either way the disturbance appears as an error rate in the legitimate channel, and there is a threshold below which the two parties can distil a key they know nobody else has.

The security does not rest on any assumption about the eavesdropper’s technology. It rests on the fidelity being bounded by five sixths for every machine allowed by the theory, which is what makes the bound worth computing exactly.

What the fidelity bound is measuring

Five sixths looks like an arbitrary fraction, and it is not. It is what remains of a state after the only operation the theory allows in place of copying, and it can be reached from two different directions.

The experiment run, and where its estimate settles. The CHSH combination estimated from 20,000 simulated coincidences at the four settings 0°, 45°, 22.5°, 67.5°, plotted against the number of pairs collected so far with the shaded band its own standard error. The estimate settles on 2.8452 ± 0.0199, which is 0.8 standard errors from 2√2 = 2.82843 and 43 above the 2 that no local theory can pass. The lower curve is a shared instruction list — one hidden angle per pair, deterministic answers, sampled the same number of times at the same settings — and it gives 1.9784 ± 0.0246, on the classical bound rather than below it, because this is the best list there is. The two are 27 combined standard errors apart. Both models give each analyser a "+" half the time; the difference is only in the coincidences.
Fig. 2 Individual outcomes from a run of measurements on entangled pairs. Every statement about fidelity in this essay is a statement about how often a machine’s output agrees with a test of this kind, run many times.

The first is a symmetry argument. A universal cloner has to treat every state alike, so its action on the Bloch sphere can only be a uniform shrinking towards the centre — no rotation, since that would favour a direction, and no distortion, for the same reason. Such a map takes a pure state to a mixture whose fidelity with the original is (1+s)/2(1+s)/2, where ss is the shrinking factor, and the theory’s constraints fix the largest allowed ss for a machine making two copies at 2/32/3. That gives 5/65/6 directly.

The second is a counting argument, and it says why the number depends on how many copies are wanted. Producing NN copies from one original has optimal fidelity (2N+1)/(3N)(2N+1)/(3N), which is 5/65/6 for two, 7/97/9 for three, and tends to 2/32/3 as NN grows without limit. That limiting value is exactly what measure-and-prepare achieves — and it must be, because making unlimited copies of a state is the same as knowing what the state is, and the best way of learning an unknown state is to measure it.

So the three numbers on the figure are one family. Two thirds is what a measurement gets, one is what is forbidden, and five sixths is the most that can be had from the one thing the theory does allow.

Why the same fact keeps entanglement from signalling

The second consequence is the one that keeps quantum mechanics compatible with relativity, and it is worth seeing that the compatibility is arithmetic rather than diplomatic.

One side changes everything, and the other side cannot tell. Two quantities against the axis one half of an entangled pair is measured along. The correlation between the two outcomes runs from perfect anticorrelation through nothing to perfect correlation — a swing of two — as that axis is turned. The other half's own state, computed by summing over the first half's outcomes, does not move at all: its Bloch vector stays at 0.0e+0 of its maximum, which is machine zero, and its trace at one to 4.4e-16. So everything about the far measurement is present in the correlations and none of it is present locally. That is why entanglement carries no signal: seeing the correlation requires both sets of results in one place, and getting them there needs an ordinary message. It is also why a copier would break the argument — two copies of the local state could be measured along two axes, and the statistics would give the far setting away.
Fig. 3 The correlation between two halves of an entangled pair as the far analyser is turned, beside the near half’s own state computed by summing over the far outcomes. One swings by two and the other is flat at machine zero.

Two entangled particles are correlated more strongly than any set of instructions could arrange, and the correlation depends on what both parties chose to measure. It is tempting to think that one party’s choice therefore has an effect at the other end, and that the effect could be used to send a message.

The figure computes what actually happens. Turn the far analyser to any angle, sum over its two outcomes, and the near half’s density matrix is unchanged: Bloch vector zero to machine precision, trace one to a part in 101410^{14}. Every local statistic is identical whatever the far party did.

So the correlations carry everything and neither half carries anything, and seeing a correlation requires both sets of results in one place — which needs an ordinary message travelling in the ordinary way.

The connection to copying is direct and is usually stated backwards. Herbert’s proposal of 1982 was exactly a signalling scheme built on a hypothetical copier: make many copies of the near half, measure them along two different axes, and infer from the statistics which basis the far party had used. It was the attempt to find the flaw in that scheme that produced the no-cloning theorem, in the same year, from three different people.

That is a good example of an impossibility proof arriving as a consequence rather than as a principle. Nobody set out to prove that states cannot be copied; the theorem was what was left when a plausible faster-than-light scheme was taken apart.

What survives: teleporting without copying

A state cannot be duplicated. It can be moved, and the distinction is exact.

Quantum state transfer works by consuming an entangled pair and sending two classical bits, and the arithmetic of which state comes out is an interference: two paths recombining, with the measurement result deciding which of four corrections the receiver applies. Nothing was copied — the original is destroyed by the measurement that produces the bits — and nothing travelled faster than the two classical bits, which is why the theorem and the protocol coexist without tension.

Quantum teleportation takes an unknown state at one end and reproduces it at the other, using an entangled pair shared in advance and two classical bits sent down an ordinary channel. It looks like copying and is not, and two features enforce the difference.

The original is destroyed. The protocol begins with a joint measurement on the unknown state and one half of the entangled pair, which leaves neither in the original state. Afterwards there is one copy, where before there was one copy.

Nothing arrives until the classical bits do. The receiving end holds a state that is one of four possibilities and cannot tell which until told, so no information has moved faster than the message, and the ordering of the two events is not even agreed on by every observer. That is the no-signalling result again, doing the same work.

If either feature were dropped the protocol would violate the theorem, so the two constraints are not incidental restrictions on an otherwise magical process — they are the exact price at which the process is consistent.

It is worth being precise about what “one copy where before there was one copy” means for the accounting, since it is the fact that keeps the whole scheme consistent. Teleportation moves a state and does not multiply it; deleting is forbidden, so it cannot be destroyed without a record either. An unknown quantum state behaves in this respect like a conserved quantity that can be passed around but neither duplicated nor discarded, and every protocol built on it — swapping, repeating, error-correcting — is an arrangement for moving it about within that constraint.

Two further statements sit close to this one and are worth separating.

Sequential measurements along different axes are the sharpest demonstration. Measure spin along zz, then along xx, then along zz again, and the third measurement has lost what the first established — the second undid it. Copying a state would let both measurements be made on the same state at once, on two copies, which is exactly what the sequence shows cannot happen. The no-cloning theorem and the uncertainty relation are two statements of one fact about what a state is.

Deleting is also forbidden. Given two copies of an unknown state, there is no linear machine that turns them into one copy and a blank. The proof is the same, and the two statements together mean a quantum state cannot be duplicated or thrown away — an unknown state is a conserved sort of thing.

Broadcasting is forbidden more generally. A weaker request than cloning is to produce a joint state whose two halves each look like the original when examined separately. That is impossible too, for any set of states that are not all commuting.

And states drawn from a known orthogonal set can be copied perfectly. This is the exception that shows what the theorem is about. If the sender is known to be transmitting either 0|0\rangle or 1|1\rangle, both can be measured and reproduced without error, and that is why classical information — which is exactly information encoded in orthogonal states — can be copied freely, and why the discreteness that makes a state countable is what makes it copyable. The prohibition is on copying superpositions, which is to say on copying anything whose description is not already classical.

The theorem’s other career, in thermodynamics and in black holes

An impossibility about copying turns up in two places that have nothing to do with communication, and both are worth naming because they show how load-bearing it is.

States in a box are each a distinct member of an orthogonal set, and anything encoded in such a set can be copied freely — a machine that recognises which member it has been given and prepares another of the same kind violates nothing. That is why classical information is copyable and why this essay’s prohibition never seems to apply to anything ordinary: the prohibition bites only on superpositions of the set, and a bit that is definitely zero or definitely one is never one of those.

A copier would be a perpetual motion machine of the second kind. Given a copier, an unknown state could be duplicated many times, measured in many bases and thereby identified; and an identified state can be transformed reversibly into a standard one, extracting work in the process. Running that cycle would extract work from a single heat bath. The argument is due to Bennett and runs in both directions, so the bit that has to be paid for and the impossibility of copying are two faces of one prohibition.

And a black hole cannot be allowed to copy either. A quantum state falling through a horizon appears, to a distant observer, to be re-emitted eventually in the radiation; to a falling observer it is inside. If both accounts are literally true the state has been duplicated, which is the black hole information paradox in its sharpest form. The proposed resolution — that no single observer can ever check both copies, because doing so would require signalling faster than light between the inside and the outside — is called complementarity, and its whole force comes from the fact that no-cloning must not be violated in a way anybody can detect.

That last qualification is a strange one and it is deliberate. The argument does not deny that two copies appear to exist; it argues that the theorem’s content is about what can be verified, and that the verification is unavailable. Whether that is a resolution or a restatement is still argued about.

The noise every amplifier has to add

The prohibition has a consequence that every optical engineer meets as a number in a datasheet, and the connection is rarely drawn.

An amplifier takes a weak signal and produces a strong one. If it did so noiselessly it would be a copier: take the output, split it into two beams of the original strength, and there are two copies of a state that arrived once. So a noiseless amplifier is forbidden by the theorem, and the interesting question is how much noise the theorem requires.

The answer is exact. A phase-insensitive linear amplifier of power gain GG must add at least G1G-1 quanta of noise per mode, which at high gain corresponds to a noise figure of three decibels — the signal-to-noise ratio of anything passing through it is halved, at best, no matter how the amplifier is built. Every erbium-doped fibre amplifier in every submarine cable sits against that bound and the good ones come within a decibel of it.

There is a way round it and the way round is instructive. An amplifier that treats the two quadratures of the field differently can amplify one of them without adding noise, at the price of adding more to the other — which is squeezing, and it is the same trade as the fidelity bound above. Nothing is copied, because what comes out is a distorted version of the input rather than two of it, and the theorem is respected by an amplifier that is not universal.

Why a quantum network cannot have repeaters

The same fact is the central engineering obstacle to quantum communication, and it is worth stating because it explains a great deal of apparently exotic hardware.

A classical optical link over a long distance works by amplification: the signal is regenerated every eighty kilometres or so, and the distance a link can span is essentially unlimited. That is only possible because a classical bit can be copied — a repeater reads the arriving pulse, decides what it was, and sends a fresh one.

A quantum state cannot be regenerated that way. Nothing may read it, and nothing may amplify it without adding the noise the previous section requires, so the signal simply attenuates. Fibre at its best loses a fifth of a decibel per kilometre, so five hundred kilometres is a hundred decibels — a transmission of one part in ten thousand million, at which even a source firing a thousand million times a second delivers a useful photon every few seconds and the detectors’ own dark counts swamp it. The reach of a direct link is therefore a few hundred kilometres and no amount of engineering extends it.

Two answers exist and both are elaborate. A quantum repeater distributes entanglement over short hops, purifies it, and then swaps entanglement between adjacent segments to join them — a scheme that needs a quantum memory at every node and is still largely a laboratory demonstration. Or leave the fibre: a beam sent up through the atmosphere and across vacuum suffers far less loss than one sent through glass, and a satellite has distributed entangled pairs between ground stations over a thousand kilometres apart and carried a key between continents.

Both are consequences of a theorem about linearity, proved in 1982 by people who were trying to find the flaw in somebody else’s faster-than-light communication scheme.

Where the model runs out

The theorem is about exact, deterministic, universal copying, and each of those words is doing work. Probabilistic cloning is possible for a set of linearly independent states, with a success probability below one and a flag saying whether it worked. That is not a loophole in the security arguments, because a protocol can be designed against the flagged failures.

The CHSH combination, against what any instruction list can reach. The CHSH combination |S| for analysers set to 0°, θ, 2θ and 3θ, plotted against θ. For the singlet it rises from 2 to a maximum of 2.82843 — 2√2, Tsirelson's bound — at θ = 22.500°, which is the setting every Bell experiment is built around, and it stays above 2 for every θ up to 34.26°. The straight lines are the same combination for the best shared instruction list: exactly 2 while 3θ is still inside the first quarter turn, then falling away. It never exceeds 2 anywhere on the sweep, and no list of pre-agreed answers can — that is Bell's inequality. The gap at the optimum is 0.8284, which is what an experiment measures.
Fig. 4 The CHSH combination against the analyser settings. A copier good enough to beat the fidelity bound would let one party determine the other’s setting, so the bound and this correlation are two statements about the same constraint.

The five-sixths bound is for a single qubit and for one copy from one original. The optimal fidelity for NN copies from MM originals is a known function that rises towards one as MM grows, which is the formal version of the statement that many copies of a state amount to knowing it.

Nothing here says a measurement gains no information. It says that the information gained and the disturbance caused are traded against each other, quantitatively. The extreme cases are a measurement that learns nothing and disturbs nothing, and one that learns everything about one observable and destroys everything about its conjugate — which is the uncertainty relation stated as a property of an apparatus rather than of a state.

And all of it assumes the evolution is unitary and the theory is exactly linear. Proposals for nonlinear modifications of quantum mechanics have been made, and the interesting thing about them is that they generically permit both cloning and superluminal signalling. That is now one of the strongest arguments against them: the linearity is load-bearing for relativity, and a theory that gives it up has to explain why no signal has ever been seen.

One side changes everything, and the other side cannot tell. Two quantities against the axis one half of an entangled pair is measured along. The correlation between the two outcomes runs from perfect anticorrelation through nothing to perfect correlation — a swing of two — as that axis is turned. The other half's own state, computed by summing over the first half's outcomes, does not move at all: its Bloch vector stays at 0.0e+0 of its maximum, which is machine zero, and its trace at one to 4.4e-16. So everything about the far measurement is present in the correlations and none of it is present locally. That is why entanglement carries no signal: seeing the correlation requires both sets of results in one place, and getting them there needs an ordinary message. It is also why a copier would break the argument — two copies of the local state could be measured along two axes, and the statistics would give the far setting away.
Fig. 5 The two curves again. Every protocol that survives the no-cloning theorem — teleportation, key distribution, error correction — is an arrangement that keeps everything in the correlations and nothing in either half.

The ladder from here

Later rungs on this anchor: the information–disturbance tradeoff made quantitative, where the fidelity of a measurement’s outcome and the fidelity of the surviving state are bounded against each other; weak measurement, where a little is learned and little is disturbed, repeatedly; quantum error correction, which protects information without ever copying it by spreading it across entangled carriers; and the monogamy of entanglement, which is the same prohibition read as a limit on how many parties can share a correlation.

The neighbouring ladders are the answer that was not there before, which is why a spare copy would be so useful, the measurement that never touched it, which is how much can be learned without interacting, and the correlation no instructions can produce, whose correlations this essay shows cannot be used to send anything.

Part 4 of 4

This essay is one argument about Measurement. The others:

What links here

Essays that reach for this one mid-argument — the half of a link its own author cannot write down.

What this makes readable

Essays that declare this one a prerequisite.

The objects named here

The third axis, after the field and the reading path: the things themselves, and every essay that touches each one.

Density matrixEavesdroppingEntanglementFidelityInformationLinearityMeasurementNo-cloningNo-signallingQuantum key distributionSuperpositionUnitarity