惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Hacker News - Newest:
Hacker News - Newest: "LLM"
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
L
LINUX DO - 最新话题
Cloudbric
Cloudbric
N
News and Events Feed by Topic
S
Secure Thoughts
Vercel News
Vercel News
S
Security @ Cisco Blogs
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
S
SegmentFault 最新的问题
Hacker News: Ask HN
Hacker News: Ask HN
博客园 - 聂微东
WordPress大学
WordPress大学
Google Online Security Blog
Google Online Security Blog
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Application and Cybersecurity Blog
Application and Cybersecurity Blog
Google DeepMind News
Google DeepMind News
PCI Perspectives
PCI Perspectives
雷峰网
雷峰网
Hugging Face - Blog
Hugging Face - Blog
Blog — PlanetScale
Blog — PlanetScale
Apple Machine Learning Research
Apple Machine Learning Research
C
CXSECURITY Database RSS Feed - CXSecurity.com
T
Threat Research - Cisco Blogs
博客园 - 司徒正美
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
A
About on SuperTechFans
P
Proofpoint News Feed
大猫的无限游戏
大猫的无限游戏
V
V2EX
I
Intezer
H
Hacker News: Front Page
www.infosecurity-magazine.com
www.infosecurity-magazine.com
L
Lohrmann on Cybersecurity
F
Fortinet All Blogs
Schneier on Security
Schneier on Security
博客园 - 叶小钗
The Cloudflare Blog
月光博客
月光博客
W
WeLiveSecurity
T
Tenable Blog
P
Proofpoint News Feed
aimingoo的专栏
aimingoo的专栏
Help Net Security
Help Net Security
L
LangChain Blog
C
CERT Recently Published Vulnerability Notes
T
The Exploit Database - CXSecurity.com
美团技术团队
B
Blog

PostQuantum – Quantum Computing, Quantum Security, PQC

Lightning Network's Quantum Problem Bitcoin's Quantum Vulnerability — Anatomy How Close Is the Quantum Threat? Resource Estimates The Quantum Threat to Cryptocurrencies: What's Real Lattice-Based PQC "Limitations" Paper — A Reality Check China's Hanyuan-2 Dual-Core Quantum Computer Pick One Layer First for Your Post-Quantum Migration Cisco Quantum Switch: Room-Temperature Qubit Routing IonQ Claims Q-Day by 2029 — Here's What They Actually Said Project Eleven's 110-Page Quantum Blockchains Report QuantWare Raises $178M Series B Q-CTRL Claims Practical Quantum Advantage Quantum Computing Simulates 12,635-Atom Protein How Quantum Snake Oil Vendors Respond to Hard Questions Simulated Quantum Entanglement | PostQuantum.com Quantum Snake Oil: Guide to Misleading Quantum Terms Quantum AI Trading — Quantum Snake Oil Dictionary Quantum-Proof — Quantum Snake Oil Dictionary Quantum-Grade Encryption — Quantum Snake Oil Dictionary Quantum-Safe Certified — Quantum Snake Oil Dictionary Military-Grade Quantum Encryption | PostQuantum.com What Is a QBOM? Quantum Bill of Materials vs CBOM Explained Quantum-Inspired Encryption — Quantum Snake Oil Dictionary What Is Trust Now, Forge Later (TNFL)? Quantum Blockchain — Quantum Snake Oil Dictionary What Is PQC Migration? The Largest Cryptographic Overhaul Quantum Financial System (QFS) | PostQuantum.com What Is QKD (Quantum Key Distribution)? What Is Quantum Error Correction (QEC)? Unhackable Quantum Encryption | PostQuantum.com Unconditionally Secure — Quantum Snake Oil Dictionary Perfect Secrecy — Quantum Snake Oil Dictionary Information-Theoretic Security | PostQuantum.com Quantum Encryption / Quantum Cryptography Quantum-Enhanced — Quantum Snake Oil Dictionary Quantum-Safe vs Quantum-Resistant vs Post-Quantum Anatomy of Quantum Denial: Bitcoin's Example What Is a Logical Qubit? The Metric That Actually Matters What Is a CRQC? Quantum Computer That Breaks Encryption What Is Q-Day? When Quantum Computers Break Encryption What Is Harvest Now, Decrypt Later (HNDL)? What Is Grover's Algorithm? What Is Shor's Algorithm? The Quantum Threat Explained What Is Quantum Safe? What the Label Means for CISOs What Is Quantum Computing Security? What Is Quantum Cyber Security? What Is Quantum Cryptography? QKD, PQC, and related? Quantum Security: A Complete Guide for Security Leaders What Is Post-Quantum Cryptography (PQC)? Crypto-Agility Is an Architecture Problem, Not a Library Swap IBM Quantum Advantage 2026: Heron + Fugaku Analyzed Aaronson Warns: CRQC by 2029 Is Plausible U.S. Quantum Policy: NQI Reauthorization and PQC Bills The Narrow Advantage: Why Quantum Computing Will Transform Five Industries and Disappoint Twenty The Error Correction Revolution Rewriting Quantum Timelines The Signature Supply Chain: How Deep Does Digital Trust Go? Quantum Chemistry's Honest Ledger: What the Resource Estimates Actually Say About Drug Discovery, Catalysis, and Materials Design Why Quantum Won't Save Wall Street (Yet): An Honest Assessment of Quantum Computing in Finance PQC Standards Fragmentation Quantum Sovereignty and the Utility Trap The Decoder Bottleneck: The CRQC Challenge Nobody Is Talking About IonQ Publishes Complete Fault-Tolerant Blueprint for Trapped Ions — The Walking Cat Architecture Quantum Computing by 2033: Which Industries Win, Which Wait, and Why Nature Reviews Publishes the Definitive CMOS–Spin Qubit Compatibility Assessment IonQ Photonic Interconnect: First Networked Commercial Quantum Computers QuEra Achieves 2:1 Physical-to-Logical Qubit Ratio With Ultra-High-Rate qLDPC Codes Grover's Algorithm vs AES - Why "Ignore It" Is Almost Right McKinsey Quantum Monitor 2026: Tipping Point? Meta PQC Migration Playbook: Lessons for CISOs NVIDIA Ising: Open AI Models for Quantum Calibration and Error Correction Harvard's Cascade Neural Decoder PQC Signature Migration Before Encryption Architecture Matters as Much as the Algorithm: Q-CTRL's Heterogeneous Quantum Computer Design Cuts RSA-2048 to 190k-381k Qubits China's Quantum Sensing Ecosystem: From Deep-Sea Diamonds to Drone-Mounted Submarine Hunters China's Quantum Sensing Ecosystem: From Deep-Sea Diamonds to Drone-Mounted Submarine Hunters China's Quantum Networking and QKD — World's Most Ambitious Quantum Communication Program Anthropic's Mythos Preview and the End of a Twenty-Year Cybersecurity Equilibrium China's Quantum Networking and QKD — World's Most Ambitious Quantum Communication Program Cloudflare Joins Google: Two Internet Giants Now Say 2029 for Post-Quantum Migration China's Quantum Computing Hardware: The Core Capability the West Keeps Misjudging China's Quantum Computing Hardware: The Core Capability the West Keeps Misjudging QuiX Quantum Achieves First Below-Threshold Error Mitigation in Photonic Quantum Computing China's Quantum Talent Ecosystem: Building a Superpower's Workforce Quantum Threat Timeline Report 2025: Record Predictions, But Can the Survey Keep Up? China's Quantum Talent Ecosystem: Building a Superpower's Workforce China's Hefei National Laboratory: The Nerve Center of a Quantum Superpower China's Hefei National Laboratory: The Nerve Center of a Quantum Superpower Gauge Theory Meets Quantum Computing China's 15th Five-Year Plan Makes Quantum an Industrial Imperative — Not Just a Research Priority China's 15th Five-Year Plan Makes Quantum an Industrial Imperative — Not Just a Research Priority QuantumShield360 AI Achieves World's First Complete Post-Quantum Cryptography Migration — Full Quantum Resilience Across All Enterprise Systems 10,000 Qubits to Run Shor's Algorithm Google Quantum AI Achieves 10x Reduction in Resources to Break Bitcoin's Cryptography The U.S. Intelligence Community Just Put Quantum on Equal Footing with AI. And Expanded the Threat Definition Google Just Drew a Line in the Sand: PQC Migration by 2029 Silicon Crosses the Logical Threshold: First Universal Logical Operations Demonstrated in a Silicon Quantum Processor The 1,000-Qubit Ceiling That Probably Isn't Science Confirms What Large Corporate Survivors Already Knew - Organizational Bullshit Makes You Worse at Your Job A New Algorithm Shrinks the Quantum Attack Surface for ECC Quantinuum Squeezes 94 Logical Qubits from 98 Physical — But What Does It Actually Mean?
Operational Perfect Secrecy: A Name, Not a Proof
Marin Ivezic · 2026-06-25 · via PostQuantum – Quantum Computing, Quantum Security, PQC

This article is part of the Quantum Snake Oil Dictionary a series examining terms used in quantum technology marketing. The series is divided into Red Flag Terms (terms with no established technical meaning that almost always signal hype or fraud) and Misused Terms (legitimate concepts routinely stripped of context in marketing). This entry is a Red Flag Term.

A note before we begin. This entry examines the phrase “Operational Perfect Secrecy” as it appears in product marketing and self-published research. I am not writing about any specific company, product, or individual. A vendor using this term might have interesting engineering underneath. The problem is the label and the implied/ guarantee, and the gap between what the name promises and what any scheme using shorter-than-message keys can deliver.

What the Term Claims

In 1949, Claude Shannon proved that a cipher achieves perfect secrecy when observing the ciphertext gives an adversary zero additional information about the plaintext. The one-time pad (OTP) is the only cipher family that meets this definition. Shannon also proved the cost: the key must be at least as long as the message, used exactly once, and truly random. That cost is why the OTP is impractical for most applications, and why the entire field of modern cryptography exists as a set of carefully studied compromises.

“Operational Perfect Secrecy” (OPS) typically claims to generalize Shannon’s result. The pitch goes roughly like this: Shannon’s definition is too strict for real-world use, so OPS relaxes it from a binary pass/fail condition to a bounded adversarial success probability. Instead of requiring that the adversary learn nothing, OPS bounds the probability of successful decryption to some negligibly small value, such as 2-t for a security parameter t. The marketing then treats this bounded version as though it inherits the authority of Shannon’s original theorem, using phrases like “information-theoretic security” and “mathematically unbreakable.”

The implication, sometimes stated outright, is that OPS delivers OTP-grade protection without the OTP’s impractical key requirements. Encryption you can prove, the sales copy says. Shannon made deployable.

Where It Breaks Down

The relaxation itself is the problem, and it is a well-understood one.

Shannon’s key-length requirement is not an arbitrary design choice that cleverer engineering can optimize away. It is a mathematical consequence of the security definition. If the key is shorter than the message, there exist ciphertexts that are more likely under some plaintexts than others, and an adversary gains information. Shannon proved this. Any scheme that uses shorter keys has, by mathematical necessity, moved away from perfect secrecy. Calling the result “Operational Perfect Secrecy” is like calling a 90% success rate “Operational Perfection.” The qualifier undoes the noun.

Bounding adversarial success probability to 2-t is a real and useful concept. Cryptographers have studied relaxations of perfect secrecy for decades. Maurer’s conditional perfect secrecy (1992), the bounded-storage model, and various flavors of computational and statistical security all live in this space. The researchers who built that literature were careful with their terminology. They did not call their results “perfect secrecy” with a marketing prefix. They gave them distinct names precisely because the relaxation changes what is being guaranteed, and honest naming matters when the audience includes people making security decisions.

The second problem is the information-theoretic claim. A security bound qualifies as information-theoretic only if it holds against an adversary with unlimited computational power. When a scheme hides a key inside a block of random data and relies on the adversary being unable to try all possible extraction patterns, the security depends on the size of the search space. A computationally unbounded adversary ignores that cost. If searching all patterns recovers the key, the scheme is computationally secure, however large the search space may be. Labeling it “information-theoretic” because the numbers are big confuses the scale of a computation with the category of security.

The third problem is where the secret state lives. Any scheme that replaces the OTP’s key-length requirement with a shorter secret (a ratchet state, extraction metadata, a registration token) has not eliminated the key management problem. It has relocated it. Whatever mechanism initializes, shares, rotates, and protects that shorter secret is the actual security bottleneck. The system’s real security properties are the security properties of that mechanism. If the mechanism relies on computational assumptions (as any practical key-management system must), the entire chain inherits those assumptions, regardless of what the data-plane cipher does.

This pattern has a name in the field. It is the “Shannon fork”: any claim that the OTP has been made practical should be checked by asking what replaced the key-length requirement, and whether that replacement reintroduces the computational assumptions the OTP was supposed to avoid. In every known case, it does.

What Legitimate Practice Looks Like

Strong cryptographic systems are honest about what they assume. AES assumes that no efficient key-recovery attack exists. ML-KEM assumes that certain lattice problems are hard. QKD achieves information-theoretic security for key distribution, with explicit and well-documented assumptions about the hardware and the quantum channel.

The OTP achieves perfect secrecy. It also requires key distribution at the scale of the data being protected, which is why the OTP is used in narrow, high-value contexts and not as a general-purpose cipher. The entire post-quantum cryptography program at NIST exists because the cryptographic community chose honest computational assumptions over impractical perfection.

Claiming to have bridged that gap is an extraordinary claim. It requires extraordinary evidence: peer review at a dedicated cryptography venue (CRYPTO, Eurocrypt, Asiacrypt), independent reproduction, and sustained scrutiny from the community that has spent decades studying exactly these tradeoffs. A self-coined term and a set of unreviewed preprints do not meet that bar, however many pages they contain.

Questions Worth Asking Any Vendor

Does the system’s security bound hold against a computationally unbounded adversary? If so, where is the formal proof, and has it been reviewed at a cryptography-specific venue?

What specific assumption from Shannon’s theorem has been relaxed, and what is the quantified security loss?

If the system depends on a secret state shorter than the message (a ratchet, a shared seed, extraction metadata), what protects that state? What are the security assumptions of that protection mechanism?

Has the scheme received independent cryptanalysis from researchers unaffiliated with the vendor?

If the answer to the first question is “no,” then the system is computationally secure, and the information-theoretic marketing is inaccurate. That does not make the system worthless. It makes the label wrong. In cryptography, wrong labels get people hurt.

The Bottom Line

Shannon’s perfect secrecy theorem comes with a cost that no amount of engineering can remove, because the cost is a mathematical theorem, not a limitation of 1949-era technology. Any scheme that claims to deliver OTP-grade security without OTP-grade key distribution has changed the security model. Changing the security model can be valid and useful work. Concealing the change behind a name that borrows the authority of the original is not.

When a vendor puts “perfect secrecy” in the product name but ships shorter-than-message keys, the question is always the same: what did you trade away, and are you telling your customers?

Quantum Upside & Quantum Risk - Handled

My company - Applied Quantum - helps governments, enterprises, and investors prepare for both the upside and the risk of quantum technologies. We deliver concise board and investor briefings; demystify quantum computing, sensing, and communications; craft national and corporate strategies to capture advantage; and turn plans into delivery. We help you mitigate the quantum risk by executing crypto‑inventory, crypto‑agility implementation, PQC migration, and broader defenses against the quantum threat. We run vendor due diligence, proof‑of‑value pilots, standards and policy alignment, workforce training, and procurement support, then oversee implementation across your organization. Contact me if you want help.

Talk to me Contact Applied Quantum