What is Quantum Key Distribution?

Quantum Key Distribution is a technology that is used to provide secure communication between two parties.

Read time: 4 minutes

An introduction to Quantum Key Distribution

1. What is Quantum Key Distribution?

Quantum Key Distribution (QKD) is a cryptographic technique that enables two distant parties to establish a shared secret key, which is then used to encrypt communication using standard symmetric cryptography over a classical channel. In this sense, QKD does not replace conventional cryptographic algorithms; it provides a method to securely generate and refresh the keys they rely on.

2. How does Quantum Key Distribution work?

QKD relies on the fundamental laws of quantum physics to distribute these keys securely. In practice, this is achieved by encoding information onto individual photons, which are transmitted either through optical fiber or via free-space optical links, including satellite-based links for long distance communications. Because quantum states cannot be observed without being disturbed, any attempt to intercept or measure these photons inevitably introduces detectable anomalies. This allows the legitimate users to verify whether the communication has been compromised before using the established key.

3. What makes QKD “quantum” compared to classical cryptography?

What makes QKD fundamentally “quantum” is precisely this physical principle: information is carried by quantum states of light, rather than classical signals. Unlike conventional cryptographic mechanisms, including post-quantum cryptography, which rely on mathematical transformations, QKD relies on the laws of quantum mechanics to ensure security at the physical layer.

What are the strengths and limitations of Quantum Key Distribution (QKD)?

4. What threats does QKD protect against?

QKD does not provide universal protection in all scenarios. Its security guarantees hold under specific assumptions, including the correct functioning of the quantum channel and trusted implementation of the hardware. Moreover, QKD requires dedicated communication infrastructure—such as fiber links or free-space optical systems—and specialized devices, which makes it more suitable for high-security applications, in tightly controlled environments rather than for large-scale or consumer deployments.

5. Why is QKD considered “future-proof” against quantum computers?

QKD does not depend on the computational difficulty of mathematical problems, but on the physical impossibility of observing a quantum state without disturbing it. In theory, this makes its security independent of an attacker’s computational power, whether classical or quantum. This is why QKD is often described as “future-proof”: even powerful quantum computers do not change the underlying physical constraints that guarantee detection of eavesdropping.

6. What are the limitations or risks of QKD?

While QKD offers a highly secure way to distribute encryption keys, it is not a complete security solution. It requires dedicated fiber or optical links, which are costly and limit deployment distance. QKD offers key distribution only, so it must be combined with conventional cryptography to fully secure applications and data. Its implementation also depends on trusted hardware and correct system integration. Finally, current QKD networks remain more complex and less scalable than purely software-based cryptographic solutions.

Where is Quantum Key Distribution (QKD) used?

7. What are the use cases of QKD?

In terms of applications, QKD is primarily used to secure highly sensitive communication links. Typical use cases include inter-data-center connections, government and defense networks, financial infrastructures, and critical industrial systems. In these contexts, QKD can enable new secure key provisioning services, where cryptographic keys are continuously refreshed through physically secured channels, reducing reliance on computational assumptions.

What are the differences between Quantum Key Distribution (QKD) vs. Post-Quantum Cryptography (PQC)?

8. How is QKD different than Post-Quantum Cryptography?

QKD does not replace classical or post-quantum cryptography. Instead, it complements them. Post-Quantum Cryptography (PQC) relies on mathematical problems believed to be resistant to both classical and quantum attacks, and can be deployed in software at large scale, including on existing infrastructure. QKD, by contrast, relies on physical transmission of quantum states and provides information-theoretic guarantees at the communication link level. Because of these differences, the two approaches are not competing technologies but complementary layers in a broader security architecture.

9. If my solutions leverage PQC, do I still need QKD?

Not necessarily. PQC is resistant to both classical and future quantum computers and can be deployed on existing digital infrastructure. It is thus the most practical and scalable approach for most use cases. QKD can provide an additional layer of protection by generation and distributing keys whose security is based on different assumptions. In the most security-sensitive environments, PQC and QKD can be combined to provide complimentary protection.

10. When should organizations choose QKD vs PQC?

Organizations typically use PQC to secure end-user applications, internet protocols, and software ecosystems, while QKD is considered for securing the most sensitive backbone links where dedicated infrastructure is justified.  Combining the two approaches, which rely on different and complementary security assumptions, provides the highest level of security by significantly increasing the complexity an attacker would face.

Quantum Key Distribution
PDF version
IDEMIA

Subscribe to our newsletter

Receive our key news and keep up with the trends in our markets by subscribing to our newsletter.

By clicking on the "Subscribe" button, you confirm that you agree to IDEMIA’s Terms of Use and Privacy Policy, and agree to the processing of your personal data and acknowledge your related rights, as described therein.

Your email address will be used exclusively by IDEMIA to send you newsletters related yo your selected topics of interest. In accordance with the law, you have rights of access, rectification and erasure of your personal data, as well as opposition of processing, which can be exercised by writing to dpo@idemia.com.