惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Engineering at Meta
Engineering at Meta
D
DataBreaches.Net
云风的 BLOG
云风的 BLOG
B
Blog
T
The Blog of Author Tim Ferriss
MyScale Blog
MyScale Blog
A
About on SuperTechFans
H
Heimdal Security Blog
AI
AI
F
Full Disclosure
The Last Watchdog
The Last Watchdog
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
量子位
I
InfoQ
Martin Fowler
Martin Fowler
MongoDB | Blog
MongoDB | Blog
WordPress大学
WordPress大学
Hugging Face - Blog
Hugging Face - Blog
小众软件
小众软件
N
News and Events Feed by Topic
腾讯CDC
L
LINUX DO - 最新话题
Attack and Defense Labs
Attack and Defense Labs
Hacker News: Ask HN
Hacker News: Ask HN
Google Online Security Blog
Google Online Security Blog
博客园_首页
Forbes - Security
Forbes - Security
The Register - Security
The Register - Security
博客园 - 三生石上(FineUI控件)
PCI Perspectives
PCI Perspectives
V
Vulnerabilities – Threatpost
The Cloudflare Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
Recent Commits to openclaw:main
Recent Commits to openclaw:main
L
LangChain Blog
Security Archives - TechRepublic
Security Archives - TechRepublic
NISL@THU
NISL@THU
博客园 - Franky
Microsoft Security Blog
Microsoft Security Blog
J
Java Code Geeks
Simon Willison's Weblog
Simon Willison's Weblog
O
OpenAI News
H
Hacker News: Front Page
Project Zero
Project Zero
P
Privacy International News Feed
Cyberwarzone
Cyberwarzone
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
大猫的无限游戏
大猫的无限游戏
Application and Cybersecurity Blog
Application and Cybersecurity Blog

PostQuantum – Quantum Computing, Quantum Security, PQC

Lightning Network's Quantum Problem Ethereum's Five Quantum Vulnerabilities Bitcoin's Quantum Vulnerability — Anatomy How Close Is the Quantum Threat? Resource Estimates The Quantum Threat to Cryptocurrencies: What's Real Lattice-Based PQC "Limitations" Paper — A Reality Check China's Hanyuan-2 Dual-Core Quantum Computer Pick One Layer First for Your Post-Quantum Migration Cisco Quantum Switch: Room-Temperature Qubit Routing IonQ Claims Q-Day by 2029 — Here's What They Actually Said Project Eleven's 110-Page Quantum Blockchains Report QuantWare Raises $178M Series B Q-CTRL Claims Practical Quantum Advantage Quantum Computing Simulates 12,635-Atom Protein How Quantum Snake Oil Vendors Respond to Hard Questions Simulated Quantum Entanglement | PostQuantum.com Quantum Snake Oil: Guide to Misleading Quantum Terms Quantum AI Trading — Quantum Snake Oil Dictionary Quantum-Proof — Quantum Snake Oil Dictionary Quantum-Grade Encryption — Quantum Snake Oil Dictionary Quantum-Safe Certified — Quantum Snake Oil Dictionary Military-Grade Quantum Encryption | PostQuantum.com What Is a QBOM? Quantum Bill of Materials vs CBOM Explained Quantum-Inspired Encryption — Quantum Snake Oil Dictionary What Is Trust Now, Forge Later (TNFL)? Quantum Blockchain — Quantum Snake Oil Dictionary What Is PQC Migration? The Largest Cryptographic Overhaul Quantum Financial System (QFS) | PostQuantum.com What Is Quantum Error Correction (QEC)? Unhackable Quantum Encryption | PostQuantum.com Unconditionally Secure — Quantum Snake Oil Dictionary Perfect Secrecy — Quantum Snake Oil Dictionary Information-Theoretic Security | PostQuantum.com Quantum Encryption / Quantum Cryptography Quantum-Enhanced — Quantum Snake Oil Dictionary Quantum-Safe vs Quantum-Resistant vs Post-Quantum Anatomy of Quantum Denial: Bitcoin's Example What Is a Logical Qubit? The Metric That Actually Matters What Is a CRQC? Quantum Computer That Breaks Encryption What Is Q-Day? When Quantum Computers Break Encryption What Is Harvest Now, Decrypt Later (HNDL)? What Is Grover's Algorithm? What Is Shor's Algorithm? The Quantum Threat Explained What Is Quantum Safe? What the Label Means for CISOs What Is Quantum Computing Security? What Is Quantum Cyber Security? What Is Quantum Cryptography? QKD, PQC, and related? Quantum Security: A Complete Guide for Security Leaders What Is Post-Quantum Cryptography (PQC)? Crypto-Agility Is an Architecture Problem, Not a Library Swap IBM Quantum Advantage 2026: Heron + Fugaku Analyzed Aaronson Warns: CRQC by 2029 Is Plausible U.S. Quantum Policy: NQI Reauthorization and PQC Bills The Narrow Advantage: Why Quantum Computing Will Transform Five Industries and Disappoint Twenty The Error Correction Revolution Rewriting Quantum Timelines The Signature Supply Chain: How Deep Does Digital Trust Go? Quantum Chemistry's Honest Ledger: What the Resource Estimates Actually Say About Drug Discovery, Catalysis, and Materials Design Why Quantum Won't Save Wall Street (Yet): An Honest Assessment of Quantum Computing in Finance PQC Standards Fragmentation Quantum Sovereignty and the Utility Trap The Decoder Bottleneck: The CRQC Challenge Nobody Is Talking About IonQ Publishes Complete Fault-Tolerant Blueprint for Trapped Ions — The Walking Cat Architecture Quantum Computing by 2033: Which Industries Win, Which Wait, and Why Nature Reviews Publishes the Definitive CMOS–Spin Qubit Compatibility Assessment IonQ Photonic Interconnect: First Networked Commercial Quantum Computers QuEra Achieves 2:1 Physical-to-Logical Qubit Ratio With Ultra-High-Rate qLDPC Codes Grover's Algorithm vs AES - Why "Ignore It" Is Almost Right McKinsey Quantum Monitor 2026: Tipping Point? Meta PQC Migration Playbook: Lessons for CISOs NVIDIA Ising: Open AI Models for Quantum Calibration and Error Correction Harvard's Cascade Neural Decoder PQC Signature Migration Before Encryption Architecture Matters as Much as the Algorithm: Q-CTRL's Heterogeneous Quantum Computer Design Cuts RSA-2048 to 190k-381k Qubits China's Quantum Sensing Ecosystem: From Deep-Sea Diamonds to Drone-Mounted Submarine Hunters China's Quantum Sensing Ecosystem: From Deep-Sea Diamonds to Drone-Mounted Submarine Hunters China's Quantum Networking and QKD — World's Most Ambitious Quantum Communication Program Anthropic's Mythos Preview and the End of a Twenty-Year Cybersecurity Equilibrium China's Quantum Networking and QKD — World's Most Ambitious Quantum Communication Program Cloudflare Joins Google: Two Internet Giants Now Say 2029 for Post-Quantum Migration China's Quantum Computing Hardware: The Core Capability the West Keeps Misjudging China's Quantum Computing Hardware: The Core Capability the West Keeps Misjudging QuiX Quantum Achieves First Below-Threshold Error Mitigation in Photonic Quantum Computing China's Quantum Talent Ecosystem: Building a Superpower's Workforce Quantum Threat Timeline Report 2025: Record Predictions, But Can the Survey Keep Up? China's Quantum Talent Ecosystem: Building a Superpower's Workforce China's Hefei National Laboratory: The Nerve Center of a Quantum Superpower China's Hefei National Laboratory: The Nerve Center of a Quantum Superpower Gauge Theory Meets Quantum Computing China's 15th Five-Year Plan Makes Quantum an Industrial Imperative — Not Just a Research Priority China's 15th Five-Year Plan Makes Quantum an Industrial Imperative — Not Just a Research Priority QuantumShield360 AI Achieves World's First Complete Post-Quantum Cryptography Migration — Full Quantum Resilience Across All Enterprise Systems 10,000 Qubits to Run Shor's Algorithm Google Quantum AI Achieves 10x Reduction in Resources to Break Bitcoin's Cryptography The U.S. Intelligence Community Just Put Quantum on Equal Footing with AI. And Expanded the Threat Definition Google Just Drew a Line in the Sand: PQC Migration by 2029 Silicon Crosses the Logical Threshold: First Universal Logical Operations Demonstrated in a Silicon Quantum Processor The 1,000-Qubit Ceiling That Probably Isn't Science Confirms What Large Corporate Survivors Already Knew - Organizational Bullshit Makes You Worse at Your Job A New Algorithm Shrinks the Quantum Attack Surface for ECC Quantinuum Squeezes 94 Logical Qubits from 98 Physical — But What Does It Actually Mean?
What Is QKD (Quantum Key Distribution)?
Marin Ivezic · 2026-05-05 · via PostQuantum – Quantum Computing, Quantum Security, PQC

This is part of the Quantum Security Reference Deep Dive series. For the full landscape overview, see the capstone article on quantum security.

Introduction

Quantum key distribution (QKD) is a method for sharing cryptographic keys between two parties using quantum physics. Its defining property is that any attempt by a third party to intercept the key exchange disturbs the quantum states being transmitted, producing detectable errors. If the error rate stays below a threshold, the two parties know their key is secure. If it exceeds the threshold, they know an eavesdropper was present and discard the compromised key.

This guarantee is grounded in the laws of quantum mechanics, not in the computational difficulty of a mathematical problem. No increase in computing power, classical or quantum, can break a properly implemented QKD protocol. That distinction makes QKD the only key distribution method that offers information-theoretic security.

How BB84 Works

The BB84 protocol, proposed by Charles Bennett and Gilles Brassard in 1984, remains the most widely deployed QKD scheme. The sender (Alice) encodes random bit values in the polarization of individual photons, choosing randomly between two measurement bases for each photon. The receiver (Bob) measures each arriving photon using a randomly chosen basis.

After transmission, Alice and Bob compare their basis choices over a public classical channel (without revealing the bit values). They keep only the bits where they happened to choose the same basis, discarding the rest. An eavesdropper (Eve) who intercepted photons during transmission would have been forced to guess the basis, and incorrect guesses introduce errors that Alice and Bob can detect by comparing a sample of their shared bits.

The protocol’s security follows from a simple physical fact: measuring a photon’s polarization in the wrong basis randomizes the result, and there is no way to determine the correct basis without prior knowledge. Eve cannot copy the photons (the no-cloning theorem forbids it) and cannot measure them without risking detection.

Beyond BB84

QKD has evolved well beyond its original protocol. Entanglement-based protocols like E91 and BBM92 distribute keys using correlated photon pairs, providing security guarantees that derive from the violation of Bell inequalities rather than from trust in the source. Device-independent QKD (DI-QKD) pushes this further, offering security even when the devices themselves are untrusted, closing a class of side-channel attacks that have plagued earlier implementations.

I cover the full range of emerging approaches in my analysis of next-generation QKD protocols.

The Practical Limitations

QKD’s theoretical security is real. Its practical constraints are also real, and they limit where and how it can be deployed.

Distance is the primary constraint. Single photons are absorbed by optical fiber, limiting QKD to roughly 100-300 kilometers over terrestrial links depending on the protocol and fiber quality. Quantum repeaters can extend this range, but they remain experimental. Satellite-based QKD (demonstrated by China’s Micius satellite) bypasses the fiber limitation but introduces its own constraints around weather, orbital windows, and ground station requirements.

Dedicated infrastructure is required. QKD cannot run over the public internet. It requires either dedicated optical fiber or free-space optical links between the communicating parties. This makes it expensive and limits its applicability to point-to-point connections rather than the many-to-many communication patterns of modern networked systems.

Implementation vulnerabilities are the gap between theory and practice. QKD’s information-theoretic guarantee applies to the protocol. The hardware that implements it uses classical components: laser sources, single-photon detectors, timing electronics. These components are subject to side-channel attacks that exploit imperfections in the physical implementation rather than weaknesses in the protocol. Detector blinding, photon-number splitting, and Trojan horse attacks have all been demonstrated against QKD systems in laboratory settings.

QKD vs. PQC

QKD and post-quantum cryptography are complementary technologies, not competitors, though they are sometimes positioned as alternatives. The practical differences are significant.

PQC is software that runs on existing hardware, can be deployed across any network, and is the subject of regulatory mandates with hard deadlines. QKD requires specialized hardware, dedicated fiber, and has no regulatory mandate in most jurisdictions. For the vast majority of organizations, PQC is the path to quantum safety.

QKD’s value lies in specific high-security use cases where the physics-based guarantee matters: links between government facilities, financial data centers, or military installations where the cost of dedicated infrastructure is justified by the sensitivity of the data and the threat model includes nation-state adversaries with potential future quantum capability. Some organizations deploy QKD and PQC together in a layered defense.

The geopolitical dimension adds complexity. As I cover in my analysis of why countries differ on QKD’s future, China has built extensive operational QKD networks while the US and UK focus almost exclusively on PQC. The right answer for any given organization depends on its threat model, regulatory environment, and infrastructure constraints.

Go Deeper

What Is Quantum Cryptography? — the broader context

QKD 101: A Guide for Cybersecurity Professionals — comprehensive overview

QKD and the BB84 Protocol — detailed protocol walkthrough

Why Countries Differ on QKD’s Future — the geopolitical and technical debate

Next-Generation QKD Protocols — beyond BB84

Device-Independent QKD — security without trusting the hardware

Quantum Repeaters — extending QKD range

Quantum Upside & Quantum Risk - Handled

My company - Applied Quantum - helps governments, enterprises, and investors prepare for both the upside and the risk of quantum technologies. We deliver concise board and investor briefings; demystify quantum computing, sensing, and communications; craft national and corporate strategies to capture advantage; and turn plans into delivery. We help you mitigate the quantum risk by executing crypto‑inventory, crypto‑agility implementation, PQC migration, and broader defenses against the quantum threat. We run vendor due diligence, proof‑of‑value pilots, standards and policy alignment, workforce training, and procurement support, then oversee implementation across your organization. Contact me if you want help.

Talk to me Contact Applied Quantum