How Does Quantum Cryptography Work?

Quantum cryptography uses the physics of individual particles of light to protect information in a way that no amount of computing power can silently break. Unlike conventional encryption, which relies on math problems that are hard but not impossible to solve, quantum cryptography ties its security to physical laws: measuring a quantum particle changes it, so any eavesdropper trying to intercept a key leaves detectable traces. The field has moved well past the theoretical stage, with metropolitan-scale networks already running and satellite links under active development, but it also faces stubborn engineering constraints and an ongoing debate about whether it is the best path forward.

How the Core Protocol Works

The most widely studied quantum cryptography protocol is BB84, named after physicists Charles Bennett and Gilles Brassard, who proposed it in 1984. The goal is not to send a secret message directly over a quantum channel. Instead, two parties use the quantum channel to agree on a shared random key, which they then use to encrypt their actual communication over a normal connection. The process of generating that key is called quantum key distribution, or QKD.

In BB84, one party (traditionally called Alice) encodes each bit of a random sequence onto the polarization of a single photon, randomly choosing one of two encoding schemes for each bit. She sends these photons to the other party (Bob), who independently and randomly picks an encoding scheme to measure each photon he receives. After all the photons have been transmitted, Alice and Bob publicly compare which encoding scheme they used for each bit, but not the bit values themselves. They throw away every bit where they happened to use different schemes and keep the rest, forming what is called a sifted key.1arXiv. Comprehensive Analysis of BB84, A Quantum Key Distribution Protocol Because quantum mechanics forbids perfectly copying an unknown quantum state, an eavesdropper (Eve) who intercepts photons in transit inevitably introduces errors. Alice and Bob can check a sample of their sifted key: if the error rate is suspiciously high, they know someone has been listening and they discard the key entirely.

Why Real Lasers Complicate Things

BB84’s security proof assumes that Alice sends exactly one photon at a time. Real laser sources do not cooperate. A practical laser pulse sometimes contains zero photons, sometimes one, and occasionally two or more. Those multi-photon pulses create a vulnerability: an attacker could siphon off the extra photon, store it, and measure it later after Alice and Bob reveal their encoding choices, all without disturbing the single photon that reaches Bob.

The standard countermeasure is the decoy-state method. Alice randomly varies the intensity of her laser pulses, sending some bright “signal” pulses, some dimmer “decoy” pulses, and some vacuum pulses with essentially no light at all. By comparing the detection rates across these intensity levels, Alice and Bob can estimate how many of their detected signals actually came from single-photon pulses versus multi-photon ones. That estimate lets them shorten the final key just enough to cancel out whatever an attacker might have learned from multi-photon events.2PubMed. Beating the photon-number-splitting attack in practical quantum cryptography

The decoy-state approach works well against the classic multi-photon attack, but recent research has uncovered subtler vulnerabilities. If an attacker can manipulate the actual brightness of Alice’s pulses (for instance by injecting light back into her laser), the intensity labels Alice thinks she is using no longer match reality. One analysis showed that a particular measurement-based attack becomes effective at lower pulse intensities than the standard multi-photon attack, and that an attacker who actively blocks certain higher-photon detection events can push the threshold even lower.3Scientific Reports. Realistic vulnerabilities of decoy-state quantum key distribution This does not break QKD in principle, but it highlights that real-world security depends heavily on how well the hardware matches the theoretical model.

An Alternative Approach Using Continuous Variables

Not all QKD systems count individual photons. Continuous-variable QKD, or CV-QKD, encodes information in the amplitude and phase of light waves, measured with detectors borrowed from standard fiber-optic telecommunications. Instead of asking “did a photon arrive?” a CV-QKD receiver asks “what was the precise shape of this light pulse?” The appeal is practical: CV-QKD can use off-the-shelf telecom components and high-efficiency detectors rather than the specialized single-photon counters that discrete-variable systems require.4Advanced Quantum Technologies. Continuous‐Variable Quantum Key Distribution with Gaussian Modulation—The Theory of Practical Implementations

The trade-off is range. CV-QKD tends to perform well over shorter distances but struggles as fiber length increases, because the signal weakens and noise from the detector becomes harder to distinguish from the quantum signal itself. For metropolitan-scale links of a few tens of kilometers, CV-QKD is a strong candidate, especially where compatibility with existing network hardware is a priority.

Trusting Untrusted Hardware

A persistent worry in QKD is that security proofs assume the devices behave exactly as specified. A detector with a subtle flaw, whether accidental or planted by an adversary, can leak information without triggering the usual alarm bells. Device-independent QKD, or DIQKD, tackles this by removing trust assumptions about the hardware altogether. Instead of relying on device specifications, DIQKD uses a test of quantum correlations called a Bell inequality violation. If Alice’s and Bob’s measurement results violate a Bell inequality by the expected margin, the laws of physics guarantee that no eavesdropper could have extracted significant information, regardless of what is going on inside the black boxes.5arXiv. Device-Independent Quantum Key Distribution: Protocols, Quantum Games, and Security

DIQKD is the gold standard of QKD security because it resists every category of attack, including side-channel exploits that target specific hardware imperfections. The catch is that it demands extremely high-quality entanglement and very efficient detectors. Current experiments have demonstrated the concept, but the key rates are far too low for routine use. It remains an area of intense research rather than something you would deploy in a data center today.

The Distance Problem

Optical fiber absorbs photons. Over short distances the loss is manageable, but as the fiber gets longer, the fraction of photons that actually make it to the receiver shrinks exponentially. At some point the useful signal drops below the background noise, and no secure key can be extracted. Experiments with single-photon sources in standard telecom fiber have reached about 175 km before the signal-to-noise ratio collapses.6Nature Communications. Single-emitter quantum key distribution over 175 km of fibre with optimised finite key rates Newer protocols such as twin-field QKD push this boundary further by having both Alice and Bob send pulses to a middle node, but even these are limited to a few hundred kilometers under ideal conditions.

Classical networks solve long-distance problems with repeaters that amplify signals along the way. Quantum signals cannot be amplified without being measured, and measurement destroys the quantum properties that make QKD secure. True quantum repeaters, which would use entanglement swapping to extend range without measuring the key bits, are still in the laboratory stage. Until they mature, long-distance QKD networks rely on “trusted nodes,” intermediate stations that decrypt and re-encrypt the key. This works, but each trusted node is a point where the key exists in plain form and therefore must be physically secured.

Satellite Links as an Alternative

Sending photons through open air avoids the exponential absorption of fiber. In space, there is almost no material to absorb light, so a satellite overhead can exchange quantum signals with a ground station across hundreds or even thousands of kilometers. Feasibility studies have modeled both uplink and downlink configurations, accounting for atmospheric turbulence, beam spreading, and background light, and found that secure key generation is achievable for low-Earth-orbit passes using protocols like BB84 with decoy states or the entanglement-based Ekert91 protocol.7New Journal of Physics. Feasibility of satellite quantum key distribution China’s Micius satellite demonstrated the concept in practice, distributing entangled photon pairs to ground stations over 1,200 km apart. Satellite QKD has its own challenges, particularly the narrow time window during each orbital pass and the difficulty of operating during daytime when sunlight floods the detectors, but it is the most promising route to intercontinental quantum-secured communication.

Metropolitan Networks Already in Operation

QKD has moved beyond point-to-point links into multi-user networks. One of the largest demonstrations connected 46 nodes across three subnetworks in a Chinese metropolitan area, with the farthest users separated by about 45 km of fiber. The network used a mix of fully connected links between its most critical nodes and star-shaped connections for local access, with trusted nodes or optical switches at the hubs depending on user needs.8npj Quantum Information. Implementation of a 46-node quantum metropolitan area network

Scaling these networks further requires thinking carefully about topology. A systematic evaluation of five QKD protocol families across different network layouts found that twin-field QKD running on a mesh topology reached a peak secure key rate of about 18 Mbps over 80 km of fiber and could serve 48 simultaneous users.9Quantum Frontiers Journal. Quantum Key Distribution Models for Large-Scale Networks Those numbers are encouraging for government and financial-sector applications that need moderate data rates with very high security assurances.

For QKD to become commercially viable at scale, it also needs to coexist on the same fiber that carries ordinary internet traffic. Integrating QKD with dense wavelength division multiplexing, the standard technique for packing many data channels onto a single fiber, is an active area of engineering. The core challenge is that conventional data signals are billions of times brighter than single-photon QKD pulses, and their stray light can swamp the quantum channel. Careful wavelength planning and filtering can manage this, and reviews of the field have identified workable configurations, but the engineering is nontrivial.10IET Quantum Communication. Quantum key distribution integration with optical dense wavelength division multiplexing: a review

How QKD Compares to Post-Quantum Cryptography

QKD is not the only response to the threat of quantum computers breaking current encryption. The other major approach is post-quantum cryptography, or PQC: new mathematical algorithms designed to be hard even for quantum computers to crack. PQC has a significant practical advantage. It is software, so it can run on existing phones, laptops, and servers with no new hardware. QKD requires dedicated optical equipment, specialized detectors, and in many cases dedicated fiber or satellite links.

A comprehensive security evaluation of real-world QKD deployments compared them against PQC alternatives for each use case. The analysis found that PQC is suitable for most conventional communication scenarios, while QKD offers a distinct edge in situations demanding the highest security guarantees, particularly when protection against future, unknown algorithmic breakthroughs is required.11Cryptology ePrint Archive. A Critical Analysis of Deployed Use Cases for Quantum Key Distribution and Comparison with Post-Quantum Cryptography The “harvest now, decrypt later” threat, where adversaries record encrypted traffic today and wait for a powerful quantum computer to break it, is one area where QKD’s physics-based security provides something PQC cannot fully match: even if a new mathematical attack is discovered decades from now, a QKD-protected key exchange from today remains secure because its safety never depended on a math problem in the first place.

In practice, the two approaches are more complementary than competitive. Many real-world deployments use QKD to distribute keys that then feed into conventional encryption algorithms, and future systems could layer PQC algorithms on top of QKD keys for defense in depth. The choice between them comes down to the specific threat model, budget, and infrastructure available.

Beyond Key Distribution

Quantum cryptography has expanded beyond simply distributing encryption keys. One growing area is quantum digital signatures, which let a sender sign a document in a way that the recipient can verify but cannot forge, with security guaranteed by quantum physics rather than computational assumptions. A recent protocol demonstrated dramatic efficiency gains: using a 384-bit quantum key to sign documents up to enormous lengths, with a forgery probability bounded at one in ten quintillion. The same research group built a network integrating quantum digital signatures with encrypted communication, secret sharing, and multi-party conference key agreement into a single platform.12PubMed Central. Experimental quantum secure network with digital signatures and encryption

Another frontier is blind quantum computing, which addresses a different security problem entirely. If you want to run a computation on someone else’s quantum computer, perhaps a cloud provider’s machine, you normally have to reveal your data and your algorithm to that provider. Blind quantum computing lets a client delegate a computation to a remote quantum server in such a way that the server learns nothing about the input, the computation being performed, or the result.13Physical Review A. Blind quantum computing with different qudit resource state architectures An experimental demonstration confirmed this is more than theory: researchers showed that a client with minimal quantum capabilities could use a quantum server to carry out a computation while keeping all three elements, input, process, and output, hidden from the server.14PubMed. Demonstration of blind quantum computing As quantum cloud computing grows, this kind of cryptographic privacy guarantee could become essential for industries handling sensitive data.

What the Hardware Gaps Actually Look Like

Reading about QKD protocols can give the impression that the physics is settled and only engineering details remain. The reality is messier. Every QKD security proof starts from a mathematical model of the devices involved, and real devices deviate from those models in ways that open side channels. Detectors can be blinded by bright light, causing them to respond only when an attacker tells them to. Laser sources can leak information through their timing, spectrum, or intensity fluctuations. Even the random number generators that drive the protocol can have subtle biases.

Closing these gaps requires constant back-and-forth between theorists and experimentalists. When a new side-channel attack is demonstrated, the protocol model gets updated to account for it, and either the hardware is modified or the key rate is reduced to compensate. The decoy-state vulnerabilities described earlier are a good example of this cycle: a method that was considered a solved problem turned out to have blind spots when attacker capabilities were modeled more realistically. This iterative process is healthy, but it means that claims of “unconditional security” for any specific deployed system should be taken with a grain of salt. The security is unconditional relative to a model; the model’s match to reality is always an open question.

Device-independent protocols, as discussed above, offer a principled way out of this problem by removing device assumptions entirely. But their extreme hardware requirements push them years away from practical deployment. The field sits in an interesting middle ground: the theoretical foundations are strong, the threat QKD addresses is real and growing, and the engineering is advancing rapidly, but the gap between what the theorems promise and what deployed boxes deliver remains wide enough to keep researchers busy for a long time.