In June 2017, a satellite named Micius distributed pairs of entangled photons to two ground stations 1,203 kilometres apart, at Delingha and Lijiang in China. Entangled photons are pairs prepared so that measurements on them give matching outcomes, no matter how far apart the measurements happen. Doing this across a continent, from a spacecraft, through the atmosphere, was the result that moved satellite quantum communications out of the physics literature and into national budgets.
The application driving that budget line is quantum key distribution, usually shortened to QKD. QKD is a method for two parties to agree on a shared secret key by exchanging individual photons. Measuring a photon changes it, so an eavesdropper who intercepts the stream leaves errors behind, and the two parties can see those errors before they use the key for anything. Later that year, Micius was used to establish keys between Beijing and Vienna, roughly 7,600 kilometres apart, and those keys secured a video call between the two academies of science.
Since then the field has become an infrastructure programme rather than a research programme, and that changes what an architect needs to know about it. The physics works, and what remains open is which parts of the resulting system anyone can realistically control.
Why the physics pushes these links into orbit
Optical fibre attenuates light at roughly 0.2 decibels per kilometre at telecom wavelengths. For ordinary communications this is fine, because you amplify the signal every eighty kilometres or so. Quantum signals cannot be amplified. Copying an unknown quantum state is prohibited, which is exactly the property that makes eavesdropping detectable, so every photon lost to the fibre is simply lost. Operational fibre QKD therefore runs a few hundred kilometres between endpoints, and beyond that you need something else.
There are two options, and only one of them exists today. The first is a quantum repeater, a device that extends entanglement across a chain of segments without ever exposing the key. Repeaters work in laboratories at short range and are not deployable infrastructure. The second is a trusted node. A trusted node is a relay that terminates one QKD link, holds the key in plaintext inside its own hardware, and re-encrypts it onto the next link. It works, it is in production, and it has an obvious property: whoever operates the node can read the key.
Whoever operates the trusted node can read the key, however the photons reached it. China’s integrated network, described in Nature in 2021, combines a 2,000-kilometre fibre backbone between Beijing and Shanghai with satellite links, reaching roughly 150 users across about 4,600 kilometres. The backbone runs through a chain of trusted relay nodes. Micius, in the Beijing to Vienna demonstration, was itself a trusted node: it held both keys and combined them. The satellite removed the distance problem. It did not remove the trust problem, and it relocated that problem into orbit, where the operator is a single state.
A satellite has real advantages over a fibre chain. Free-space loss through the atmosphere is dominated by the lowest few kilometres, so a spacecraft passing overhead beats several thousand kilometres of glass. One satellite can serve many ground stations on successive passes, which makes it a hub rather than a line. And low Earth orbit gives you global reach without anyone’s permission to dig a trench. Those advantages are why the money went to space. They are not an argument that the resulting network is trustless.
A satellite is a decision you cannot revise
Terrestrial cryptography is soft. When NIST published its first post-quantum standards in August 2024, organisations began replacing key-establishment algorithms across estates that were never designed for the change, and it is painful, expensive work. It is nonetheless work you can do, because the algorithm lives in software.
An orbital quantum payload is not soft. A spacecraft launched now will operate for five to fifteen years with the photon source, the detectors, the pointing system and the on-board key management it was built with. Radiation-hardened single-photon detectors degrade in orbit. Protocol choices made during design review are frozen at separation from the launch vehicle. If the community converges on a different key-agreement approach three years later, you fly what you have.
Programme risk is just as real as technical risk, and the clearest illustration is a company that has since changed course. Arqit built a business case around a constellation of QKD satellites offering key delivery as a service, with launches contracted through Virgin Orbit. Virgin Orbit failed in 2023, and Arqit subsequently abandoned the satellite programme and moved to a software-based symmetric key agreement product. Nothing in the physics went wrong. The launch dependency went wrong, and the launch dependency was one layer below the layer the company thought it was competing in.
In space-based quantum networking, the layer that constrains you is almost never the layer named in the press release.
Six layers, and where control actually sits
We find it useful to break the space-quantum stack into six layers and ask a single question of each: if this layer is supplied by someone else, what exactly have you given away?
Quantum payload
Entangled photon sources, single-photon detectors, space-qualified lasers, pointing and tracking assemblies, and in some designs an optical clock. A handful of countries and a smaller number of firms can build these to flight standard, and many of the components sit under export control regimes. For most organisations and most states, this layer offers no optionality at all. You buy it, you partner for it, or you do without it. China invested early in domestic detector and source manufacture for precisely this reason. Europe’s Eagle-1, a QKD demonstration satellite led by SES with the European Space Agency and targeted for the second half of this decade, is built by an industrial consortium that spreads the same problem across a continent.
Launch and orbit
Getting the payload up, and getting a replacement up when the first one degrades. This is the dependency that ended Arqit’s constellation. Launch cadence is strategic: a programme that can fly a replacement in six months has a different risk profile from one that queues for a rideshare slot in two years. Rideshare has made the first satellite cheap and has done nothing to make the tenth satellite reliable. Singapore’s SpooQy-1, a CubeSat that demonstrated correlated photon pairs from orbit in 2019, is a good example of how far a small team can get on a shared ride, and also of where that route stops.
Ground segment
An optical ground station is a telescope, a set of single-photon detectors, precise timing, and a link into a terrestrial network. It is expensive by the standards of a data centre and cheap by the standards of a spacecraft. This is the first layer with genuine room to manoeuvre. A country or a large operator that will never build a satellite can build receivers, and if those receivers are built to published interfaces they can work with more than one satellite. The European Quantum Communication Infrastructure, or EuroQCI, is designed around exactly this logic: national terrestrial segments in each member state, linked by shared space assets, with the quantum component intended to ride on IRIS-squared, the EU’s planned sovereign satellite communications system. Membership is bought with ground infrastructure rather than with launches.
Keys and protocols
QKD does not encrypt anything. It produces symmetric key material, which is then consumed by conventional encryption, typically AES. Everything around that handover is a design decision: the QKD protocol itself, the authentication of the classical channel, key lifetime, rekeying frequency, how keys are delivered to applications, and how the whole arrangement fails safe when the sky is cloudy. Much of this is software, which means it can be changed after deployment and audited before it. If your organisation ever touches a quantum network, this is the layer where your people will actually work, so it’s also where the training investment belongs.
Operations and scheduling
Someone decides which ground station gets which pass. In a shared constellation, that scheduling authority is a real form of control, and it is rarely discussed in procurement. The comparison people reach for is satellite navigation, and it holds up: users worldwide depend on GPS, and the United States operates it. Whoever runs the scheduler can prioritise, degrade or deny, and no amount of quantum physics in the payload changes that.
Regulation and export control
Spectrum and optical downlink coordination, orbital filings, export licences on detectors and cryptographic equipment, and the bilateral agreements that let two national networks interconnect at all. Large states shape these rules. Everyone else works inside them. Any organisation, though, can set its own policy floor, and many will: a requirement that key material used by regulated systems originates in hardware under domestic control is a policy decision available to a bank as much as to a ministry.
The pattern across the six is consistent. The bottom two layers are closed to almost everyone. The middle three are where sovereignty is bought at a price ordinary institutions can pay. The top layer is where states decide whether any of it interconnects.
Global coverage against national constellations
Quantum networking has an unresolved tension at its centre. The technology’s value grows with reach, and its trust model shrinks with it.
Reach argues for cooperation. A key exchanged between Frankfurt and Singapore has to cross somebody’s infrastructure, and standards bodies including the ITU have been working on QKD interoperability and security certification for years. Interoperability work of that kind only pays off if more than one operator’s spacecraft can serve the same ground station, which points towards something that looks like a network rather than a demonstration.
Trust argues the other way. Governments will not route their most sensitive traffic through a trusted node they don’t control, and the trusted-node problem means that with today’s technology there is no way to route it through a foreign satellite without controlling that satellite. Satellite navigation shows how this usually resolves. The United States built GPS, Russia built GLONASS, Europe built Galileo, China built BeiDou, and the world ended up with four overlapping systems and receivers that use all of them.
We expect the same shape here: parallel constellations, common ground station interfaces, interconnection for ordinary traffic, and closed segments for the traffic that matters most. That outcome follows from a security model that depends on who operates the relay, not from any failure of cooperation.
Where this leaves post-quantum cryptography
Now, this is important, and it’s the part most commercial material about satellite QKD leaves out: the major signals intelligence agencies do not recommend QKD for national security systems, and they have said so in writing.
Post-quantum cryptography, or PQC, is a different answer to the same threat. Instead of using physics to distribute keys, PQC uses mathematical problems believed to be hard for quantum computers, and it runs as software on existing networks. ML-KEM (Kyber), standardised by NIST as FIPS 203 in August 2024, is the key-establishment algorithm most organisations will deploy. The NSA has published its assessment of QKD’s limitations and directs national security systems instead to CNSA 2.0. That suite, the Commercial National Security Algorithm Suite, names ML-KEM and ML-DSA (Dilithium) as the required post-quantum algorithms. The UK’s National Cyber Security Centre advised against QKD for government use. France’s ANSSI treats it as a possible defence-in-depth measure alongside conventional cryptography, never as a replacement.
Their objections are architectural rather than theoretical. QKD needs a dedicated optical path and special hardware, it does not authenticate the parties on its own, it produces keys and not data confidentiality, and the trusted-node requirement reintroduces exactly the trust assumption it was supposed to remove. Marketing that presents satellite QKD as an alternative to the post-quantum migration is selling the wrong product, and an architect who cannot make this argument in a meeting will lose the meeting.
None of that makes the orbital work pointless. Space QKD is credible for a specific set of users: state communications between fixed sites, inter-agency links where the operator and the user are the same organisation, and long-horizon confidentiality where the physical security assumption is worth its cost. It is complementary infrastructure for a narrow segment. It is not the migration path for your estate, and your migration path needs to be underway regardless of what launches next year.
What this asks of the architect
Read across the six layers and the skill set is fairly specific. You need to be able to draw where key material is in plaintext and name who controls each of those points. You need to model a QKD link’s availability honestly, including weather, pass geometry and detector ageing, and to specify what the system does when the link is unavailable. You need to understand how key material gets from a key management system into an application, because that interface is where quantum links either integrate with an enterprise or don’t. And you need to hold a defensible position on QKD against PQC, with the agency guidance to hand.
Those are architecture skills, not physics skills. The physics has been demonstrated. What remains unbuilt is the engineering discipline around it, and that is the part organisations are hiring for now.
Take this further
Satellite links are one component of a quantum networking curriculum that also covers terrestrial QKD, trusted-node architecture, quantum random number generation, key management integration, and the post-quantum migration work underneath all of it. Our quantum networking architecture program (CQNA) is designed for architects who have to make these decisions and defend them, rather than describe them. The full curriculum is at quantumacademy.com/.
For the migration methodology that sits alongside this material, see pqcframework.org. For the geopolitical analysis this article draws on, see the original piece at PostQuantum.com.