AnyLearn
All lessons
Scienceadvanced

Why Nobody Deploys It: The Gap Between Proof and Product

QKD has an unconditional security proof and almost no deployment. This lesson covers the authentication bootstrap it cannot solve, distance limits and the trusted node compromise, attacks on real hardware that the proof does not cover, why NSA and NCSC recommend against it, and where quantum genuinely delivers.

Updated · AI-authored, review-gated · how lessons are made

Not signed in: your progress and quiz score won't be saved.
Progress1 / 8

The authentication bootstrap

The deepest limitation is not engineering. It is that quantum key distribution cannot do the thing people assume it does, and the gap is conceptual rather than technical.

BB84 requires a classical public channel for basis reconciliation, error estimation and post-processing. The protocol allows an adversary to read that channel, which is fine. What it cannot allow is an adversary to modify it.

If the classical channel is unauthenticated, an attacker sits in the middle and runs two separate QKD sessions: one with Alice, pretending to be Bob, and one with Bob, pretending to be Alice. Both sessions are perfectly secure by the physics. Both terminate successfully with low error rates. Alice and Bob each hold a key shared with the attacker, and the attacker relays traffic between them reading everything.

No quantum mechanism prevents this, because the photons arrived exactly as physics says they should. The attack is on the classical conversation.

So QKD requires an authenticated classical channel, which means Alice and Bob must already share a secret, or must rely on a public key infrastructure, before the protocol can run.

The consequence deserves stating plainly. Quantum key distribution does not establish a secure channel between strangers. It expands an existing shared secret into more key material. It is a key growing protocol rather than a key establishment protocol.

That matters because the problem most cryptography exists to solve is establishing trust between parties who have never met, which is what public key cryptography does and what QKD does not. The hard part is the part QKD leaves for classical methods, and if those classical methods are broken by a quantum computer, the QKD system's authentication is broken with them.

Full lesson text

All 8 steps on one page, for reading, reference, and search.

Show

1. The authentication bootstrap

The deepest limitation is not engineering. It is that quantum key distribution cannot do the thing people assume it does, and the gap is conceptual rather than technical.

BB84 requires a classical public channel for basis reconciliation, error estimation and post-processing. The protocol allows an adversary to read that channel, which is fine. What it cannot allow is an adversary to modify it.

If the classical channel is unauthenticated, an attacker sits in the middle and runs two separate QKD sessions: one with Alice, pretending to be Bob, and one with Bob, pretending to be Alice. Both sessions are perfectly secure by the physics. Both terminate successfully with low error rates. Alice and Bob each hold a key shared with the attacker, and the attacker relays traffic between them reading everything.

No quantum mechanism prevents this, because the photons arrived exactly as physics says they should. The attack is on the classical conversation.

So QKD requires an authenticated classical channel, which means Alice and Bob must already share a secret, or must rely on a public key infrastructure, before the protocol can run.

The consequence deserves stating plainly. Quantum key distribution does not establish a secure channel between strangers. It expands an existing shared secret into more key material. It is a key growing protocol rather than a key establishment protocol.

That matters because the problem most cryptography exists to solve is establishing trust between parties who have never met, which is what public key cryptography does and what QKD does not. The hard part is the part QKD leaves for classical methods, and if those classical methods are broken by a quantum computer, the QKD system's authentication is broken with them.

2. Distance, and why repeaters do not exist yet

The physical constraint that shapes every deployment, and the reason it cannot simply be engineered away.

Photons are lost in fibre. At the standard telecommunications wavelength around fifteen hundred and fifty nanometres, loss is roughly zero point two decibels per kilometre, which means transmission falls exponentially with distance. Over a hundred kilometres that is about twenty decibels, so around one percent of photons survive. Over three hundred kilometres, roughly one in ten thousand.

Classical communication solves this with amplifiers and repeaters that read the signal and retransmit it. That option is closed here, because reading the signal is exactly what the no-cloning theorem forbids and what the security depends on being impossible. A repeater that measures and resends is indistinguishable from an eavesdropper, and the protocol will correctly abort.

So key rate falls exponentially with distance, and beyond a few hundred kilometres of fibre it falls below anything usable.

The theoretical answer is a quantum repeater, which uses entanglement swapping and quantum memories to extend range without measuring the key. This is an active research area with laboratory demonstrations of the components, and it does not exist as deployable technology. Building one requires quantum memories with long coherence times and high-fidelity entanglement swapping, which are the same hard problems that make quantum computing difficult.

One partial result worth noting. Protocols in the twin-field family improve the scaling of key rate with distance compared to conventional QKD, which has extended demonstrated ranges considerably. That is a genuine advance and it does not remove the exponential character of the underlying loss.

The practical position today. Point-to-point QKD works over metropolitan distances on dedicated fibre. Beyond that, you need one of the two workarounds in the next step, and both cost you something important.

3. The trusted node problem

The workaround that makes long-distance QKD networks possible, and what it costs.

Since quantum repeaters do not exist, long links are built as chains of shorter QKD links joined by relay stations. Alice and the first node share a key by QKD. The first and second nodes share a different key. And so on to Bob.

To get a key from Alice to Bob, each node decrypts the key it received and re-encrypts it under the next link's key. Which means every intermediate node holds the key in plaintext.

That is the entire security model of a trusted node network, and the name is accurate: the nodes must be trusted, completely. Compromise any one of them and you have the key. The physics protects each hop and protects nothing end to end.

So a network built this way has security equal to the physical and operational security of its relay stations, which is a conventional problem with conventional solutions and no quantum advantage whatsoever. An adversary skips the fibre and attacks a building.

China's backbone between Beijing and Shanghai, spanning roughly two thousand kilometres, operates on this model with a chain of trusted nodes, and it is the largest deployment of its kind.

The alternative workaround is satellites. The Micius satellite, launched in 2016 by a team led by Pan Jianwei, demonstrated entanglement distribution over more than a thousand kilometres and intercontinental key exchange, reported in Science and Physical Review Letters in 2017. Free-space loss scales far better than fibre because most of the path is vacuum.

That is a genuine achievement, and the satellite is itself a trusted node in the simplest configurations.

flowchart LR
A["Alice"] --> B["QKD link 1"]
B --> C["Relay node: holds the key in plaintext"]
C --> D["QKD link 2"]
D --> E["Relay node: holds the key in plaintext"]
E --> F["QKD link 3"]
F --> G["Bob"]
C --> H["Compromise any node and you have the key"]
E --> H
H --> I["Security equals the physical security of buildings, not physics"]

4. The proof covers the protocol, not the device

The most instructive category of failure, because it shows precisely where an unconditional security proof stops applying.

The proofs assume idealised components: a source emitting exactly one photon per pulse, detectors that respond only to the quantum states described, no unintended channels between the equipment and the outside world. Real hardware satisfies none of these exactly, and the gaps are attackable.

The photon number splitting attack. Practical sources are attenuated lasers, which emit a Poisson-distributed number of photons, so some pulses contain more than one. An eavesdropper can split off a surplus photon, store it, and measure it after the bases are announced, learning the bit with no disturbance at all. The countermeasure, decoy states, works by varying the pulse intensity to detect the characteristic signature, and it is now standard.

Detector blinding, which is the more striking case. Lydersen and colleagues showed in Nature Photonics in 2010 that shining bright light on the single-photon detectors of commercial QKD systems drives them out of their quantum regime into classical linear operation. In that state the attacker can control exactly which detector fires, recovering the full key while introducing no detectable error.

Other demonstrated attacks exploit timing differences between detectors, imperfections in the source, and light reflected back out of the receiver revealing its basis choice.

The honest conclusion. None of these break quantum mechanics or the security proof. They exploit the distance between the mathematical model and a physical instrument, which is the same class of problem that produces side-channel attacks on classical cryptographic hardware.

And it undermines the field's central marketing claim. Security guaranteed by the laws of physics is true of the protocol. What you buy is a device, and its security depends on engineering, certification and testing exactly as everything else does.

5. What the security agencies say

The institutional position is unusually blunt and it is worth reading rather than paraphrasing loosely.

The United States National Security Agency, in its published guidance on quantum computing and post-quantum cryptography, states that it does not support the use of quantum key distribution to protect communications in National Security Systems, and does not anticipate certifying or approving any such products unless the limitations are overcome. It gives five reasons.

QKD is only a partial solution, since it generates keying material but requires authentication by other means, which is the bootstrap problem above.

It requires special purpose equipment, being a physical-layer technology that cannot be delivered as a software update.

It increases infrastructure cost and insider threat risk, because it needs dedicated equipment in secure facilities.

Securing and validating it is a significant challenge, since actual security comes from the hardware and engineering rather than from the theoretical bounds, which is the previous step.

And it increases the risk of denial of service, because a system designed to abort when disturbed can be trivially stopped by anyone who can disturb it.

The United Kingdom's National Cyber Security Centre has taken a comparable line, considering the infrastructure cost and operational overhead disproportionate when standardised post-quantum algorithms are available as a software upgrade, and advising that QKD should not be relied on alone.

The French and German agencies have published a joint position with similar caution.

That last denial-of-service point deserves attention because it is counterintuitive. The property that makes QKD secure, aborting on disturbance, makes it fragile. A backhoe, a bright light, or anyone with access to the fibre stops the key flowing, and there is no degraded mode.

6. The case in favour, made properly

It would be easy to leave this as a dismissal, and that would be inaccurate. There are real arguments on the other side and they deserve their strongest form.

The security assumption is genuinely different. Post-quantum schemes rest on the belief that certain mathematical problems are hard, and that belief has been wrong before. Several submissions to the NIST standardisation process were broken during it, including SIKE, which fell to a classical attack in 2022 after years of scrutiny. QKD's guarantee does not depend on any such belief.

Forward secrecy against unlimited future computation. A key established by QKD cannot be recovered later by any amount of computing power, because the information was never transmitted in a form that encodes it. Harvest-now-decrypt-later, the strategy of recording encrypted traffic today to break it when quantum computers arrive, does not work against it.

Defence in depth. Nothing prevents combining QKD-derived key material with post-quantum key exchange, so that an attacker must defeat both the physics and the mathematics. Some deployments do exactly this, and it is the strongest architectural argument for the technology.

Sovereign independence from algorithm choices. A state that does not wish to rely on standards developed elsewhere may value a mechanism whose security rests on physics it can verify itself.

And genuine niches. Short, fixed, extremely high-value links where you own the fibre and the endpoints: a link between two data centres of the same bank, or two government buildings in one city. The cost is bearable, distance is not a problem, and both endpoints are already physically secured.

The fair summary. QKD is not a fraud and it is not the general solution. It is an expensive, infrastructure-heavy technology that addresses one narrow part of the problem extremely well, and for most organisations that part was not the binding constraint.

7. Where quantum actually delivers today

One application of quantum physics to cryptography is commercially deployed, unglamorous, and genuinely useful, and it is worth separating from QKD because it shares none of the problems.

Quantum random number generation. Cryptography depends absolutely on unpredictable random numbers, and generating them well is harder than it appears. Classical generators derive randomness from physical noise sources and algorithmic expansion, and failures of randomness have produced some of the most serious cryptographic breaks on record: keys that could be recovered because the generator's state was guessable, and devices generating identical keys because they were seeded identically at first boot.

A quantum random number generator uses an intrinsically indeterminate quantum process, most simply a photon meeting a beam splitter with two detectors. Quantum mechanics says the outcome is not merely unknown but undetermined, which is a stronger property than any classical source offers.

Why this succeeds where QKD struggles. It is a component rather than an infrastructure. It has no distance limit, because the randomness is generated where it is used. It needs no dedicated fibre, no trusted nodes, and no authenticated classical channel. It fits into existing systems as a source feeding the entropy pool. And it can be built into a chip.

These are commercially available and deployed in certificate authorities, gambling systems, and security hardware.

The contrast is instructive for anyone assessing quantum technologies generally. The quantum property being exploited is modest, the integration cost is near zero, and it improves something that was genuinely weak. QKD exploits a more remarkable property, requires rebuilding the infrastructure, and improves something that was mostly fine.

That ratio, between the strength of the physics and the friction of deployment, predicts adoption better than the elegance of the underlying idea.

8. How to assess a claim in this field

The transferable skill, since this field generates more marketing than most.

Ask what the classical channel is authenticated with. Every QKD system has one, and the answer is a pre-shared key or public key cryptography. If a vendor's answer is vague, the system's trust bootstrap is undefined, which is the whole security model.

Ask whether the network uses trusted nodes. If it spans more than a few hundred kilometres of fibre, it does. Then the security is the physical security of the relay sites, and the physics claim applies per hop rather than end to end.

Ask what cipher consumes the key. If it is AES rather than a one-time pad, the system is computationally secure and the information-theoretic language applies only to key distribution.

Ask about device certification and which implementation attacks have been tested. The proof assumes ideal components, and the demonstrated attacks were against commercial products.

Ask what happens under denial of service. A system that aborts on disturbance has no degraded mode, and that is a design property rather than a defect.

And ask what problem it solves that post-quantum cryptography does not. There are honest answers, chiefly forward secrecy against unlimited future computation and independence from mathematical assumptions. If those are not the answers given, the pitch is probably not describing the technology accurately.

The broader lesson, which applies well beyond this subject. An unconditional security proof is a statement about a model. The gap between that model and a manufactured device is where the security of real systems is decided, and it is not closed by strengthening the proof.

Which is why the third lesson turns to post-quantum cryptography: less elegant, no physics, and the thing that is actually being deployed.

Check your understanding

The lesson ends with a 5-question quiz. Take it in the player above to see your score.

  1. Why is QKD described as a key-growing rather than key-establishment protocol?
    • It produces keys faster than classical exchange
    • It requires an authenticated classical channel, so the parties must already share a secret or rely on PKI
    • It can only extend keys that were generated quantum-mechanically
    • Key length grows with the distance of the link
  2. Why can a conventional repeater not extend a QKD link?
    • Repeaters introduce too much timing jitter
    • Fibre amplifiers do not operate at 1550 nm
    • Reading and retransmitting is exactly what no-cloning forbids, so a repeater is indistinguishable from an eavesdropper
    • Repeaters cannot handle single-photon power levels
  3. What is the security model of a trusted node QKD network?
    • End-to-end information-theoretic security across all hops
    • Security equal to the physical and operational security of the relay sites, since each node holds the key in plaintext
    • Security determined by the weakest fibre segment
    • Entanglement is swapped so no node sees the key
  4. What does the detector blinding attack demonstrate?
    • That quantum mechanics is incomplete
    • That the BB84 security proof contains an error
    • That decoy states are ineffective
    • That bright light can push detectors into classical operation, letting an attacker control which fires and recover the key without detectable error
  5. Why has quantum random number generation succeeded commercially where QKD has not?
    • It exploits a stronger quantum property
    • It offers information-theoretic security for messages
    • It is a component with no distance limit, no dedicated fibre, and near-zero integration cost, improving something genuinely weak
    • It was standardised earlier by NIST

Related lessons

Science
advanced

Quantum Key Distribution: BB84 and Why Eavesdropping Shows

Quantum cryptography uses physics rather than computational hardness. This lesson covers the no-cloning theorem, the BB84 protocol step by step, why measurement in the wrong basis leaves a detectable trace, the error rate threshold, and the entanglement-based alternative.

8 steps·~12 min
Programming
advanced

The Runtime Stack, and What Isolation Is Worth

One command hides four layers of software and a set of standards that made them interchangeable. This lesson takes the stack apart, then asks the question the whole path has been building toward: given a shared kernel, how much is container isolation actually worth, and what has to be added before it is a security boundary.

8 steps·~12 min
Business
beginner

The Risk You Bring In: Your Own AI Tools

The other direction of the problem. Employees using AI tools create exposure through data leaving the organisation, prompt injection turning an assistant against its user, malicious extensions, and code suggestions nobody verified. This lesson covers what to worry about and what is overstated.

8 steps·~12 min
Business
beginner

Verifying the Request, Not the Person

If recognition no longer establishes identity, verification has to move to the channel. This lesson builds the practice: out-of-band confirmation, which requests need it, designing protocols people will actually follow under pressure, the household version, and what to do in the first hour after something goes wrong.

8 steps·~12 min