As of June 2026, the National Security Agency (NSA) does not recommend using quantum key distribution (QKD) and quantum cryptography (QC) for securing the transmission of data in National Security Systems (NSS) unless several technical limitations are overcome. This article dives into the nuances of QKD and QC, their limitations, and how they compare to quantum-resistant algorithms.
What is Quantum Key Distribution and Quantum Cryptography?
QKD leverages the unique properties of quantum mechanical systems to generate and distribute cryptographic keying materials using special purpose technology.
QC is a broader field of study that uses similar physics principles and technology to communicate over a dedicated communications link. Theoretical models suggest that both QKD and QC can detect eavesdropping, a feature missing in traditional cryptographic methods.
Key Concepts:
- Quantum Key Distribution: Uses quantum mechanical properties to generate and distribute cryptographic keys.
- Quantum Cryptography: Applies quantum principles to secure quantum communications over a dedicated link.
- Eavesdropping Detection: A theoretical advantage of QKD and QC, allowing the detection of unauthorized access to communication channels.
Quantum Key Distribution Limitations
Despite theoretical claims of guaranteed security based on the laws of physics, QKD face substantial practical challenges. The balance between communication needs and security requirements is delicate, with a low tolerance for error.
Technical limitations of QKD include:
- Partial Solution: QKD generates keying material for encryption algorithms that ensure confidentiality. This keying material can also be used in symmetric key cryptographic algorithms for integrity and authentication, provided the original QKD transmission is authenticated. However, QKD does not authenticate the transmission source, necessitating the use of asymmetric cryptography or preplaced keys for authentication.
- Special Purpose Equipment Requirements: QKD relies on physical properties and unique physical layer communications, requiring dedicated fiber connections or free-space transmitters. The hardware-based nature of QKD hinders future upgrades and security patches, limiting integration with existing network equipment.
- Increased Infrastructure Costs and Insider Threat Risk: QKD networks often require trusted relays, increasing the costs for secure facilities and increasing the risk of insider threats. These constraints eliminate many potential use cases.
- Significant Challenges to Security and Validation: The actual security of a QKD system is limited by hardware and engineering designs rather than the unconditional security modelled by physics. Changing environmental conditions and physical degradation can negatively affect operational security established at the time of certification. Specialized hardware introduces vulnerabilities, which has led to well-publicized attacks on commercial QKD systems.
- Increased Denial of Service Risk: The sensitivity to eavesdropping, while providing security, also increases the risk of denial-of-service attacks.
The practical application of QKD faces numerous technical challenges, and understanding these limitations is crucial for making informed decisions about cryptographic strategies. Meanwhile, the most robust uses of QC remain theoretical and are intended for use within a broader, fully-quantum network that may link quantum computers and quantum sensors.
Advantages of Quantum-Resistant Algorithms
In comparison, quantum-resistant algorithms are implemented on existing platforms and derive their security through mathematical complexity. These algorithms are used in cryptographic protocols, providing the means for assuring the confidentiality, integrity, and authenticity of a transmission — even against a potential future quantum computer.
Quantum-resistant algorithms also offer more cost-effective confidentiality and authentication services with a well-understood risk profile.
Key Advantages and Distinctions:
- Implementation: Quantum-resistant algorithms are software-based and can be implemented on existing infrastructure.
- Security: Derived from mathematical complexity rather than physical properties.
- Flexibility: Easier to upgrade and patch compared to hardware-based QKD systems.
For immediate adoption of post-quantum cryptography, explore NSA’s Post-Quantum Cryptography Resource Hub.
See, for example (Note: These references are not meant to be exhaustive.):