How Quantum Key Distribution Works—And Why It’s Not Ready for Most Networks

Lars Bergman

Lars Bergman

July 7, 2026

How Quantum Key Distribution Works—And Why It's Not Ready for Most Networks

Quantum key distribution (QKD) is one of those technologies that is simultaneously genuinely based on profound physics, commercially deployed in limited contexts, and surrounded by claims that significantly overstate its practical readiness. It is not a solution to general network security. It is not coming to your bank or VPN provider anytime soon. What it is—and what the physics actually guarantees—is worth understanding carefully, because QKD illustrates a broader pattern in how quantum technologies are discussed.

The Problem QKD Solves

Classical cryptographic key exchange—the protocols by which two parties establish a shared secret over an insecure channel—rely on computational hardness. RSA and Diffie-Hellman key exchange are secure today because factoring large numbers or computing discrete logarithms is computationally infeasible with current hardware and algorithms. These mathematical problems don’t have known efficient solutions.

The threat horizon: a sufficiently powerful quantum computer running Shor’s algorithm could factor large numbers and compute discrete logarithms efficiently, breaking RSA and Diffie-Hellman. This threat is not immediate—current quantum computers are nowhere near the qubit count and error rate required to break cryptographically meaningful key sizes—but the threat is plausible on a 10–20 year horizon, and data encrypted today and stored until then could be retrospectively decrypted (“harvest now, decrypt later” attacks).

QKD takes a different approach: it uses quantum mechanical properties to generate a shared secret key in a way that is information-theoretically secure—not relying on computational hardness that could be broken by future advances, but on physical laws that cannot be circumvented regardless of computational power. The security guarantee is different in kind from computational security.

The BB84 Protocol: How QKD Actually Works

The most important QKD protocol is BB84, proposed by Charles Bennett and Gilles Brassard in 1984. Understanding BB84 reveals both what QKD does and its practical constraints.

The protocol uses single photons—individual quanta of light—as carriers of quantum information. Photons can be polarised in different orientations; quantum mechanics allows two incompatible measurement bases (rectilinear: horizontal/vertical; diagonal: 45°/135°). The key property: measuring a quantum state in the wrong basis disturbs the state in a way that is detectable.

The process:

  1. Alice sends a sequence of photons, each randomly polarised in one of four states (horizontal, vertical, 45°, 135°) and randomly using one of two bases (rectilinear or diagonal).
  2. Bob measures each photon, randomly choosing a measurement basis each time. When Bob’s basis matches Alice’s, he gets the correct bit. When it doesn’t, his result is random.
  3. After transmission, Alice and Bob publicly announce (over any channel) which basis they used for each photon—not the result, just the basis.
  4. They keep only the photons where their bases matched, discarding the rest. This is the raw key.
  5. They compare a subset of their key bits publicly to estimate the error rate. If an eavesdropper (Eve) has intercepted and remeasured photons, her measurements disturb the quantum states, introducing detectable errors.
  6. If the error rate exceeds a threshold (indicating eavesdropping), they abort and try again. If the error rate is low enough, they apply privacy amplification to extract a secure key from the agreed bits.

The security guarantee: any eavesdropping attempt disturbs the photons and introduces detectable errors. Alice and Bob can detect eavesdropping with high probability and quantify how much information was potentially leaked, allowing them to distil a secure key from the remaining correlated bits. The security relies on quantum mechanics (specifically, the no-cloning theorem—an unknown quantum state cannot be copied—and the disturbance introduced by measurement) rather than computational hardness.

Fiber optic quantum communication link between two secure nodes, photon-based key distribution infrastructure

The Physical Constraints That Limit Deployment

QKD sounds like an obvious security upgrade. The practical deployment obstacles are severe enough that QKD remains a niche technology used only in specific high-security contexts.

Distance limitation. Single photons traversing optical fiber are absorbed and scattered. The probability of a photon reaching the other end decreases exponentially with distance. In practice, QKD over standard optical fiber is limited to approximately 100–150 km before signal loss makes the key generation rate impractically low. Extending this range requires quantum repeaters—devices that can extend quantum entanglement over longer distances—which are an active research area but not commercially available at scale.

China has demonstrated QKD over longer distances using satellite links (the Micius satellite demonstrated QKD between ground stations 1,200 km apart in 2017, with photons transmitted through free space rather than fiber). Satellite-based QKD is viable for long-distance links but requires dedicated satellite infrastructure, good atmospheric conditions, and ground station coordination that is far from routine commercial deployment.

Key generation rate. QKD generates keys slowly—thousands of bits per second over practical fiber distances, compared to the ability to exchange AES keys (which are 256 bits) nearly instantaneously using classical key exchange. For applications requiring high-bandwidth key refresh, QKD’s throughput is a constraint. For applications where key refresh is infrequent (long-lived stored data, infrequent high-value transactions), the rate may be acceptable.

Required dedicated infrastructure. QKD requires a dedicated quantum channel (a fiber specifically used for the quantum transmission) in addition to a classical channel for the announcement phase. This means deploying QKD requires either installing new dedicated fiber or reserving existing fiber capacity for quantum use—a cost that isn’t present in purely classical cryptographic upgrades.

End-to-end security requires trusted nodes. For QKD links longer than the single-span limit, the network requires intermediate “trusted nodes”—devices that receive and retransmit keys along the path. These trusted nodes must be physically secure because they temporarily store plaintext key material. The security model degrades: instead of relying only on physics, security now depends on the physical security of each intermediate node. A network with many trusted nodes is not as purely physics-secured as a direct QKD link.

The Alternative: Post-Quantum Cryptography

QKD is not the only response to the quantum computing threat. Post-quantum cryptography (PQC)—classical algorithms designed to be secure against quantum attacks—offers a software-deployable alternative that doesn’t require new physical infrastructure.

NIST completed a post-quantum cryptography standardisation process in 2024, publishing standards based on lattice problems (ML-KEM, formerly Kyber, for key encapsulation; ML-DSA, formerly Dilithium, for digital signatures) and hash-based signatures. These algorithms are believed to be resistant to both classical and quantum attacks based on mathematical problems that Shor’s algorithm doesn’t efficiently solve.

PQC can be deployed as a software update to existing cryptographic infrastructure—no new hardware, no dedicated fiber, no distance limitations. Major cloud providers and operating system vendors are in active deployment of PQC algorithms in TLS, SSH, and other protocols. NIST’s standardised algorithms are already being integrated into production systems.

The comparison between QKD and PQC is important for understanding QKD’s role:

  • QKD: information-theoretically secure key exchange; requires dedicated hardware and fiber; limited distance; expensive; practically deployable only in specific high-value corridors
  • PQC: computationally secure against quantum attacks (as far as we know); deployable as software on existing infrastructure; no distance limitations; cost-competitive with existing cryptography

For most organisations, PQC migration is the practical and appropriate response to the quantum threat. QKD is appropriate for specific scenarios where information-theoretic security is required (government communications between fixed facilities, critical infrastructure with dedicated fiber corridors, military communications).

Quantum computing laboratory with researcher operating photonic equipment for quantum communication research

Where QKD Is Actually Deployed

Commercial QKD deployments exist and are growing, but in specific contexts:

China has the most extensive QKD network, including a 2,000 km QKD backbone connecting Beijing and Shanghai with regional extensions. The network combines fiber-based QKD segments with trusted nodes and satellite QKD links for the longest distances. This is a government-funded national security infrastructure project, not a commercial product in the conventional sense.

European deployments include QKD links between financial institutions in several cities (Madrid, Rome, Amsterdam) as part of EU quantum communication initiatives. The South Korean government has funded QKD deployment in national infrastructure. Japan has operated QKD testbeds since the early 2000s and has commercial deployments in financial and government sectors.

Several commercial QKD hardware vendors exist—ID Quantique (Switzerland), Toshiba Research Europe, QuantumCTek (China)—offering rack-mounted QKD transmitter/receiver pairs for enterprise deployment over dedicated fiber. These products are real, functional, and very expensive ($50,000–$200,000+ for a link), limiting their market to well-funded government and financial sector clients.

The Realistic Assessment

QKD is a genuine technology with a genuine security advantage (information-theoretic security for key exchange) and genuine deployment constraints (distance, cost, infrastructure requirements, trusted node vulnerabilities). It is appropriate for specific use cases and not approaching general adoption.

The practical response to quantum computing threats for most organisations is PQC migration: update cryptographic libraries, negotiate TLS connections with PQC key exchange, sign certificates with PQC algorithms. This work is technically straightforward compared to QKD deployment and addresses the same threat model for the vast majority of use cases.

QKD’s value proposition is strongest in scenarios where: the adversary is a nation-state with potentially compromised classical infrastructure; the communication is between fixed high-security facilities with dedicated fiber connectivity; key exchange needs to be provably secure against any future computational advance; and cost is secondary to security assurance. This is a real but narrow use case, and being clear about that narrowness is part of accurately conveying what quantum security technologies do and don’t offer.

More articles for you