Other meanings of Quantum key distribution
Cryptography
Quantum key distribution (QKD) is a cryptographic technique using quantum mechanics to establish shared secret encryption keys. It does not encrypt ordinary messages by itself; instead, it helps two parties create and test a key whose security is tied to the disturbance of quantum states during transmission.1
QKD establishes a shared random key by exchanging quantum states and then comparing selected measurement information over an authenticated classical channel. In the best-known protocol, BB84, a sender encodes bits in one of two incompatible measurement bases, while the receiver chooses bases independently. They later disclose the bases, retain matching results, estimate the error rate, and use error correction and privacy amplification to derive a shorter secret key.1
The protocol depends on quantum properties such as measurement disturbance and the no-cloning theorem: an eavesdropper cannot copy unknown quantum states perfectly without introducing detectable changes. Other families include Ekert91, which uses entangled particles and tests correlations related to Bell inequalities, and measurement-device-independent QKD, designed to reduce vulnerabilities in detectors.2
QKD can provide information-theoretic key security only under explicit assumptions about the devices, the channel, the classical authentication method, and the post-processing implementation. The quantum exchange itself does not authenticate the communicating parties; without an initial authentication key or another trusted mechanism, an attacker could conduct a man-in-the-middle attack.
Real systems also suffer from photon loss, detector imperfections, imperfect sources, side channels, and finite data samples. Security proofs therefore use observed error rates and conservative bounds rather than assuming that hardware behaves ideally. Practical security is usually described through a secret-key rate, which falls as distance and loss increase. QKD must be combined with conventional authenticated encryption or a one-time pad, and it does not protect endpoints that are already compromised.2
Operational QKD systems commonly use fiber-optic links for metropolitan distances and free-space or satellite links for longer paths. Trusted-node networks can extend reach by decrypting and re-encrypting key material at intermediate sites, but those nodes must themselves be protected; this differs from end-to-end security against every intermediate operator.
Research demonstrations have included satellite-to-ground quantum communication and entanglement distribution, while standards bodies have worked on terminology, architectures, interfaces, and security evaluation. The International Telecommunication Union and the European Telecommunications Standards Institute describe QKD as one component of broader quantum-safe network architectures rather than a universal replacement for public-key cryptography.345
QKD's most distinctive benefit is forward-looking protection against the collection of encrypted traffic for later decryption: an adversary may store classical ciphertext today and attack vulnerable public-key systems after a sufficiently capable quantum computer exists. QKD addresses key establishment through physics, whereas post-quantum cryptography uses mathematical problems believed to resist quantum algorithms and can usually run on existing digital networks.
Several less visible design choices strongly affect performance. Decoy-state methods help detect attacks that exploit multi-photon pulses in practical weak-laser sources; finite-key analysis limits how much confidence can be drawn from a short session; and continuous-variable QKD encodes information in optical field properties rather than discrete photon states. These variants show that QKD is a family of protocols and engineering architectures, not a single device or universal security guarantee.2
QKD security claims depend on the protocol, implementation, threat model, authentication method, and security proof; laboratory demonstrations should not be treated as universal guarantees for deployed systems.
Help improve the encyclopedia. Reports go straight to the site manager.