Quantum Academy begins operations on September 15, 2026. Enrollment opens soon.
Skip to content

Quantum Networking

Beyond BB84: A Field Guide to Newer QKD Protocols

Marin Ivezic15 min read

Quantum key distribution has one protocol that everybody can name. BB84, published by Charles Bennett and Gilles Brassard in 1984, encodes each key bit in the state of a single photon, and any attempt to measure that photon in transit disturbs it in a way the two endpoints can detect. Its security rests on that disturbance rather than on a hard mathematical problem, which is why it survives the arrival of a cryptographically relevant quantum computer. It works, and it’s also more than forty years old. The three constraints it left behind – limited reach, relay nodes you have to trust, and detectors that can be manipulated – are the same three constraints an architect has to design around today.

The protocols that came after it attack those constraints one at a time. Measurement-device-independent QKD removes the detector from the set of things you trust. Twin-field QKD changes how the key rate falls off with distance. Continuous-variable QKD replaces single-photon hardware with ordinary telecom components. Device-independent QKD removes trust in the hardware entirely, at a cost that currently keeps it inside laboratories. None of them is a drop-in upgrade to a BB84 link, and each one buys a different thing. This guide is about telling them apart well enough to read a vendor datasheet with the right questions in hand.

Three constraints inherited from BB84

Loss sets the reach. A photon travelling through standard telecom fiber has a fixed probability of being absorbed per kilometre, so the fraction that arrives falls off exponentially with distance. Amplifiers don’t help, because amplifying a quantum state destroys the property the protocol depends on. In 2017 Stefano Pirandola and colleagues put a hard number on the consequence: for a direct link of transmittance η, no protocol without repeaters can produce more than roughly η secret bits per channel use. That result, usually called the repeaterless bound or the PLOB bound, is a ceiling rather than an engineering target. Commercial links generally run to 100 km or so before the key rate becomes useless for anything but slow re-keying. Laboratory records reach several hundred kilometres using ultralow-loss fiber and detectors cooled to a few kelvin.

Trusted nodes fill the gap, and they fill it with policy. To cross a country, operators chain short links together. Each intermediate node terminates one link, holds the key in the clear for an instant, and re-encrypts it onto the next. The physics guarantee stops at every one of those nodes. What replaces it is a physically secured room, an access control regime, and a supply chain you accept. China’s integrated network, described in Nature in 2021, spans roughly 4,600 km using a 2,000 km fiber backbone with 32 trusted nodes plus satellite links, and serves more than 150 users. That architecture is real and operational, and it means the security of the whole is the security of the weakest hop.

Hardware imperfection opens side channels. A side channel is information that leaks from how a device behaves rather than from the protocol it runs. Real sources sometimes emit two photons where the protocol assumes one, which lets an eavesdropper keep a copy. The decoy-state technique handles that case by varying the pulse intensity at random and using the statistics to bound how much a multi-photon attack could have leaked; every serious commercial system uses it. Detectors have proved harder. In 2010 Lars Lydersen and colleagues showed that bright light could push single-photon detectors into a classical regime where an attacker controls what they report, and the link keeps producing keys the attacker already knows. Patching individual attacks works until the next one appears. Removing the detector from the trust model is a different kind of fix, and it is what the next protocol does.

Four questions to ask about any QKD protocol

Before the protocol descriptions, here is the frame we use with architects in our networking programs, because it makes the comparison tractable:

  1. What has to be trusted? Name the components whose correct behaviour the security proof assumes. That list is the real deliverable.
  2. How does key rate scale with loss? Linear in transmittance, square-root, or something better. This determines node spacing more than anything else does.
  3. What hardware does it demand? Cryogenic detectors, phase-locked lasers, and dark fiber each have a procurement consequence.
  4. What has actually been demonstrated, by whom, at what rate? A distance record quoted without its key rate tells you almost nothing.

That fourth question does a lot of work. Vendor material routinely pairs a headline distance from one experiment with a key rate from another, and the two numbers rarely belong in the same row of a table.

Measurement-device-independent QKD

Hoi-Kwong Lo, Marcos Curty and Bing Qi proposed measurement-device-independent QKD, or MDI-QKD, in 2012. Both endpoints send photons toward a middle node, conventionally called Charlie, instead of one sending to the other. Charlie performs a Bell-state measurement, an interference measurement that reveals only how the two incoming photons relate to each other and nothing about either one individually. He announces which outcome he got. Alice and Bob use those announcements, together with what they each sent, to distil a shared key.

The trust consequence is the point. Charlie holds every detector in the system, and Charlie learns nothing. He can be malicious, he can be a compromised appliance in a colocation cage, and the proof still holds. Every detector attack in the published literature, including detector blinding, becomes irrelevant, because the attacker gains control of a device that never had the key.

The demonstrated status is solid for a research protocol. A team led by Hua-Lei Yin reported MDI-QKD over 404 km of ultralow-loss fiber in 2016, at a key rate well below one bit per second – enough to prove the reach, not enough to run a link. More useful for architects is a metropolitan trial by Yan-Lin Tang and colleagues, which connected several users in a star topology through one untrusted central node across an area of roughly 200 square kilometres and ran continuously for over a week.

Where it fits: a metro network where you want many endpoints sharing infrastructure and you cannot secure the hub. The cost is that both endpoints must send photons that interfere at the middle, which requires tight timing and phase control across two separate spans, and the raw key rate is roughly half that of a comparable direct link. We’d treat MDI-QKD as the protocol to evaluate when the trusted-node room is the thing your risk register objects to.

Twin-field QKD

Marco Lucamarini, Zhiliang Yuan, James Dynes and Andrew Shields published twin-field QKD in Nature in 2018, and it changed the arithmetic of long links. The endpoints again send toward a middle node, but they send dim laser pulses whose optical phases are deliberately matched, so the two fields arriving at the middle behave like halves of one field. Charlie interferes them and reports whether the combined signal landed in one detector or the other. A single detection event carries information about the relationship between the two pulses.

Because one detection now depends on a photon having traversed only half the total path, the key rate scales with the square root of the end-to-end transmittance rather than with transmittance itself. That is the scaling a quantum repeater would give you, obtained without any quantum memory. Over a 600 km link, a square root instead of a linear factor is the difference between a dead link and a working one.

The records followed quickly. Groups at the University of Science and Technology of China have pushed variants of twin-field QKD past 1,000 km of fiber, reporting secure key generation at 1,002 km in 2023. Read that number with the fourth question in mind: it used ultralow-loss fiber and the key rate was a small fraction of one bit per second, so it establishes the scaling law rather than a service offering. At more ordinary distances of 300 to 500 km, twin-field rates are genuinely useful.

The catch is phase. The two arms must stay phase-coherent over hundreds of kilometres of fiber that expands, contracts and vibrates. Every implementation carries a phase stabilisation subsystem, usually a reference laser sharing the fiber, and that subsystem is where the engineering difficulty concentrates. Twin-field QKD inherits MDI-QKD’s immunity to detector attacks, and it adds an assumption about the phase reference that the security analysis has to cover.

Continuous-variable QKD

Continuous-variable QKD, or CV-QKD, encodes information differently. Rather than one bit per single photon, the sender modulates the amplitude and phase of a weak laser pulse – the two quadratures of the optical field – with random values drawn from a Gaussian distribution. The receiver measures those quadratures by interfering the incoming light with a strong local laser, a technique called homodyne detection, and recovers correlated analogue values. Frédéric Grosshans and Philippe Grangier described the modern form of this in 2002. Security still comes from the uncertainty principle: an eavesdropper who samples the field adds excess noise, and the endpoints see that noise in their statistics.

The appeal is entirely practical. Homodyne detection uses photodiodes that work at room temperature, the modulators are standard telecom parts, and the whole transmitter and receiver look like coherent optical equipment because that’s essentially what they are. No cryogenics, no exotic detectors, lower unit cost, and a far easier conversation with the optical transport team. CV-QKD also coexists more comfortably with classical traffic on the same fiber, since its receiver is inherently narrowband in a way that filters out much of the Raman noise a strong classical channel scatters.

The limit is range. Excess noise and the efficiency of the classical error-correction step, which is computationally heavy in CV-QKD, cause the secure rate to collapse at longer distances. A team led by Yichen Zhang reported a laboratory CV-QKD link over 202.81 km in 2020, but commercial systems are generally specified for metro spans of tens of kilometres. Security proofs have also matured on a different timeline from the discrete-variable case, with composable proofs against the most general attacks arriving later and carrying tighter finite-size requirements.

Where it fits: data centre interconnect and campus links inside a city, particularly where you need QKD to ride existing fiber alongside production traffic and the capital cost per endpoint decides whether the project happens.

Device-independent QKD

Device-independent QKD, or DI-QKD, is the strongest claim in the field and the least deployable. Alice and Bob share entangled photon pairs and measure them in randomly chosen bases. Some results build the key. The rest go into a Bell test, a statistical check on whether the correlations between the two sets of outcomes exceed what any classical explanation could produce. If they do, the entanglement was genuine and no third party held a copy, and that conclusion follows from the measured statistics alone. The devices could have been built by your adversary.

Three groups reported the first convincing demonstrations in 2022. A team at Oxford led by David Nadlinger used two trapped ions a couple of metres apart. Groups at the University of Science and Technology of China achieved a photonic version over roughly 220 metres of fiber. The distances tell the story. A Bell test only closes its loopholes if detection efficiency stays above a hard threshold end to end, and loss in fiber destroys that efficiency long before the distances a network needs.

Where it fits today: nowhere in a production design, and we’d say so plainly to anyone shown a DI-QKD roadmap by a vendor. Its value to an architect is as a reference point. When a supplier claims their system is secure regardless of implementation flaws, DI-QKD is what that claim would actually require, and the gap between the claim and the demonstrated state of the art is a useful measurement.

Techniques that sit alongside the protocols

High-dimensional encoding

Standard QKD carries one bit per transmitted state. High-dimensional protocols use states with more than two distinguishable values – a photon’s arrival time slot out of eight possibilities, for example – to carry more bits each. The second benefit is noise tolerance: the maximum error rate at which a key can still be extracted rises with dimension, which helps on links that are noisy rather than merely lossy. Generating and sorting high-dimensional states adds optical complexity, and integrated photonics is the reason this is becoming practical rather than merely elegant.

Satellites and trusted relays

Free-space loss through the atmosphere is dominated by the lowest few kilometres, so a satellite link can beat hundreds of kilometres of fiber. China’s Micius satellite demonstrated this from 2016 onward, and Europe’s EuroQCI programme pairs terrestrial national networks with planned satellite segments to link them. Satellites do not remove the trust question – a satellite that relays keys between two ground stations is a trusted node in orbit, with all that implies about who operates it. They remove a distance problem, and they add weather dependency and a scheduling constraint, since a link exists only during a pass.

Quantum repeaters

A quantum repeater stores entanglement in a quantum memory at each intermediate station, then performs entanglement swapping, an operation that fuses entanglement across two adjacent segments into entanglement across the pair of endpoints. Do that along a chain and the endpoints share entanglement directly, with no station ever holding the key. This is the architecture that ends trusted relays permanently. It is also not available. Multi-node laboratory networks exist, including a three-node link at Delft, but memory lifetimes, coupling efficiencies and error rates are all far from what a deployable repeater needs. Twin-field QKD is the near-term answer to the same problem, and it is a much weaker one, because it improves the scaling without removing the distance limit.

Maturity at a glance

ProtocolRemoves trust inDemonstrated reachStatus
Decoy-state BB84Nothing beyond the standard assumptions~100 km deployed, several hundred km in labCommercial, widely deployed
MDI-QKDThe measuring node and all detectors404 km fiber; metro star network trialField trials, limited products
TF-QKDThe measuring node and all detectors1,002 km fiber at sub-bit-per-second ratesAdvanced research
CV-QKDNothing new, but uses telecom-grade detectors~200 km in lab, tens of km commerciallyCommercial, metro focus
DI-QKDSources and detectors alikeMetres to a few hundred metresLaboratory

Read the reach column and the status column together. A protocol with a longer record and a weaker status is a protocol whose record was set on fiber and with cooling budgets that a production link will not have.

What none of these protocols does

QKD distributes symmetric keys over a link. That is the whole function, and four things fall outside it.

Authentication. Every QKD protocol needs an authenticated classical channel alongside the quantum one, or an attacker simply sits in the middle and runs the protocol twice. That authentication comes from a pre-shared symmetric key or from a signature scheme, which today means post-quantum cryptography. A QKD deployment therefore depends on classical or post-quantum cryptography at its root. It does not replace it.

Endpoints. The key arrives at a device. If that device is compromised, the attacker reads the plaintext and the physics guarantee is irrelevant. QKD protects a span, not a system.

Anything past the first hop. Key relay through a trusted node, network-layer key management, and the API that hands keys to an encryptor are all classical systems with classical failure modes.

National authorities have been direct about the consequences. The US National Security Agency has published its position that it does not support the use of QKD for national security systems and does not anticipate certifying it, citing among other things the requirement for special-purpose equipment and the difficulty of validating implementations. The UK’s National Cyber Security Centre has advised against QKD for government and defence use and recommends post-quantum cryptography instead. A joint position paper from the national cybersecurity agencies of France, Germany, the Netherlands and Sweden reaches a similar conclusion for high-security applications while supporting continued research. Europe is simultaneously funding EuroQCI, so the picture is genuinely mixed rather than settled, and an architect proposing QKD in a regulated environment should expect to be asked about these documents by name.

Designing a link around what the protocol gives you

Assume hybrid. The mainstream architecture combines a post-quantum key exchange with a QKD-delivered key, mixing both into the final session key through a key derivation function. Breaking the session then requires breaking a mathematical assumption and a physical channel. This also solves the deployment problem, because the link degrades to post-quantum-only security when the quantum channel drops. If you are building the post-quantum half first, the migration methodology at pqcframework.org covers the inventory and agility work that has to happen regardless of whether QKD ever enters the design.

Treat the key delivery interface as the integration point. The specifications from the European Telecommunications Standards Institute (ETSI), particularly GS QKD 014, define a REST interface through which an application requests keys from a QKD system by key identifier. The International Telecommunication Union’s telecommunication standardization sector (ITU-T) covers the network framework around it in the Y.3800 series. Designing against these interfaces rather than a vendor’s native API is the difference between a QKD segment you can re-tender and one you cannot.

Budget for the fiber, not just the boxes. Coexistence with classical traffic on the same fiber is demonstrated and increasingly routine, and it depends on wavelength planning, filtering, and how much power the classical channels carry. Where coexistence is marginal, the answer is dark fiber, and dark fiber between two specific sites is a procurement question with a long lead time. MDI-QKD and twin-field QKD add a further constraint, since the middle node has to sit at a location with suitable fiber to both endpoints.

Plan for the link going down. Quantum bit error rate, the fraction of sifted bits where the two ends disagree, rises with temperature swings, mechanical disturbance and construction work along the route. Above a protocol-specific threshold, key generation stops. A QKD deployment needs a key buffer sized for the outage you’re willing to ride out, a monitored fallback, and an operational decision about what happens when the buffer empties. We see more projects stall on this question than on any point of quantum physics.

Match the protocol to the span you actually have. Two sites 40 km apart in one city, sharing a fiber with production traffic and a tight capital budget: CV-QKD is the honest first evaluation. A metro network with a dozen endpoints and a hub you do not control: MDI-QKD. A 400 km link between two data centres with no acceptable intermediate site: twin-field QKD, as a research collaboration rather than a purchase. Anything transcontinental: satellite plus trusted nodes, with the trust written into the risk register in plain language.

Where to take this next

The protocol families above are stable enough to learn once and use for years, and the numbers attached to them are not. What changes is reach, rate and product availability, which means an architect’s real skill is reading a new result or a new datasheet against the four questions and working out what it changes in a design.

That skill is what our networking programs are built around. The CQNE program covers quantum network engineering, including the optical layer, key management and the operational side of running a quantum channel. The CQNA program is the architecture-level path, aimed at professionals who specify these systems and defend the specification to a security committee. Both are available through Quantum Academy. For deeper technical background on the protocols themselves, the original analysis on PostQuantum.com goes further into the physics than a field guide can.