← New search

Other meanings of Quantum cryptography

Physics & information security

Quantum cryptography

Quantum cryptography applies quantum-mechanical principles to cryptography, especially to secure key distribution. Its best-known application, quantum key distribution (QKD), lets communicating parties detect certain kinds of interception because measuring an unknown quantum state generally disturbs it.1 QKD does not by itself encrypt ordinary messages or authenticate participants; it creates shared secret keys that conventional encryption and authentication systems can use.

1984
BB84 proposed
First widely recognized QKD protocol
2
Main protocol families
Prepare-and-measure and entanglement-based
1 key property
Security signal
Eavesdropping can create detectable errors
1

Principle and origins

Quantum cryptography derives its security signal from the behavior of quantum states rather than from the presumed difficulty of a mathematical problem. In the BB84 protocol, proposed by Charles Bennett and Gilles Brassard in 1984, one party sends single photons encoded in one of two incompatible measurement bases. The receiver chooses bases at random, and the parties later disclose only their basis choices over an authenticated classical channel. Results from matching bases form a raw key; an interceptor who measures and resends photons introduces errors that can be estimated by comparing a sample.

The protocol therefore combines a quantum channel with ordinary classical communication. Its logic rests on the no-cloning theorem, which prevents an unknown quantum state from being copied perfectly, and on measurement disturbance. Security is not equivalent to secrecy of the transmitted photons: it depends on error testing, privacy amplification, and authenticated classical discussion.

2

Protocols and security

QKD protocols fall chiefly into prepare-and-measure and entanglement-based families. BB84 is a prepare-and-measure scheme, while Ekert’s 1991 proposal uses entangled particles and tests correlations related to Bell’s theorem.1 Other protocols, including decoy-state variants, address practical weaknesses in photon sources by varying signal intensities and identifying possible multi-photon contributions.

Security proofs distinguish ideal protocols from real apparatus. Modern analyses can treat loss, detector imperfections, imperfect state preparation, and general attacks, but only when the device behavior and protocol assumptions are correctly modeled.2 After estimating the quantum bit error rate, participants reconcile discrepancies, apply privacy amplification to shorten the key, and authenticate the classical channel. Authentication remains essential: QKD cannot prevent a man-in-the-middle attack against unauthenticated parties.

3

Implementation and limits

Practical QKD is an engineering system constrained by distance, loss, detector performance, and trusted infrastructure. Fiber-based links attenuate optical signals, while free-space and satellite links face pointing, weather, and background-light problems; these constraints limit the rate and range of directly distributed keys.3 Quantum repeaters are intended to extend range through entanglement distribution and quantum memories, but large-scale, fault-tolerant repeaters remain technologically demanding.

Commercial demonstrations commonly use attenuated laser pulses rather than ideal single-photon sources, and implementation attacks have exploited detector behavior and other hardware details. Countermeasures include improved device models, monitoring, decoy states, and measurement-device-independent QKD, which moves detector trust out of the central security assumption. Device-independent approaches aim for stronger guarantees but require demanding experimental conditions.

QKD also needs key-management software, authenticated endpoints, stable optical equipment, and conventional cryptographic components. It is consequently a specialized communication technology, not a universal replacement for public-key cryptography.

4

Lesser-known aspects

The most consequential distinction is between information-theoretic security and operational security. Under appropriate assumptions, QKD can provide keys whose secrecy does not depend on an adversary’s computational power, yet compromised endpoints, poor random-number generation, stolen authentication keys, or faulty installation can still defeat the overall system.3

Entanglement is not required for every QKD system: BB84 can work without distributing entangled pairs, although entanglement-based formulations clarify some security proofs. Nor does quantum cryptography make faster-than-light communication possible; classical messages still coordinate basis choices and error correction.

A related research direction is quantum key distribution over satellites and metropolitan optical networks, while another is continuous-variable QKD, which encodes information in properties such as the quadratures of light. These approaches broaden the hardware choices but introduce different noise, calibration, and security analyses. Standards work treats QKD as one component of a wider cryptographic architecture rather than a stand-alone security product.

Glossary

Quantum key distribution (QKD)
A protocol family for establishing a shared secret key using quantum states and a classical authenticated channel.
Privacy amplification
A procedure that compresses a partially secret raw key to reduce an eavesdropper’s possible information.
No-cloning theorem
The quantum-mechanical result that an arbitrary unknown quantum state cannot be copied perfectly.
Quantum bit error rate
The observed disagreement rate used to estimate noise and possible interception in a QKD exchange.
Measurement-device-independent QKD
A QKD design that removes trust in the measurement apparatus from a central part of the security model.

QKD addresses key establishment; confidentiality, authentication, endpoint security, and system governance still require additional cryptographic and operational controls.