Start with the output, not the physics
The question usually arrives after a briefing. Someone senior has heard the phrase “quantum-secure network,” and they want to know whether the organization should be buying one. The honest first answer is that the phrase describes a category of equipment rather than a capability, and the category produces a narrower set of outputs than most briefings suggest.
So it helps to work backwards. Instead of starting with photons and entanglement, start with the deliverable: what comes out of the box, in what units, at what rate, over what distance, and under whose control. Everything difficult about quantum networking follows from one number, which is the roughly 0.2 decibels of loss per kilometre in standard telecom fibre. That figure is unremarkable for classical light and decisive for single photons. Every architectural choice in the field traces back to it.
This piece is written for the architect who already owns encrypted links between sites and has to decide what, if anything, to do about this. It covers four things: what a quantum network produces today, what it does not produce, the two physical constraints that shape every published roadmap, and the questions that separate a serious vendor claim from a marketing one.
What a quantum network produces
There are four outputs, at four very different levels of maturity. Keeping them separate is most of the work.
Symmetric key material between two endpoints
This is quantum key distribution (QKD), and it is the only output you can buy as a supported product today.
A QKD link has two ends and two channels. The quantum channel carries very faint light pulses, typically at the single-photon level, down a dedicated fibre or across a line-of-sight optical path. The classical channel, which is an ordinary IP link, carries the coordination traffic that turns detected photons into usable bits. The output is a stream of identical random bits held at both ends and held nowhere else.
The security argument rests on a measurement rather than a computation. Interfering with single photons perturbs them, and that perturbation shows up as a higher error rate in a sample of the bits that both ends compare openly. The protocol then discards enough material to account for the maximum information an eavesdropper could have gained. If the error rate is too high, the link produces no key at all. That is the intended behaviour: a QKD system under attack does not leak, it stops.
What you do with the bits is conventional. They feed a symmetric encryptor, usually AES-256 on a high-speed link, and they let you rotate keys far more often than a manual or certificate-based process would. There is a standard interface for this handoff, ETSI GS QKD 014, which defines a REST API for a QKD device to deliver keys to an application or a key manager. If a vendor cannot speak it, integration becomes a bespoke project.
The practical envelope today is a point-to-point link across a metropolitan area, on dedicated fibre, with key rates that fall sharply as distance grows. A 2022 demonstration by JPMorgan Chase, Toshiba and Ciena is a useful reference point, because it multiplexed a QKD channel onto a production-grade metropolitan fibre that was simultaneously carrying 800 Gbps of ordinary traffic. That combination, quantum and classical light on one strand, is closer to what a real deployment looks like than a laboratory link on dark fibre.
Entanglement as a shared resource
The second output is entanglement, and it exists in national testbeds rather than in catalogues.
Entanglement is a correlation between two particles that is stronger than any pre-agreed classical list of answers could reproduce. If Alice and Bob each hold one photon of an entangled pair and each measures it, their results agree more often, across a range of measurement settings, than any shared cheat sheet would allow. The statistical check that establishes this is a Bell test, and its usefulness in a network is that it certifies the link rather than the device. A successful Bell test says the correlation is genuinely quantum, which in turn says that no third party holds a copy of it. Device-independent QKD builds on exactly this: security that survives even imperfect trust in your own hardware, demonstrated in the laboratory but not yet in the field.
Distributed entanglement is also the resource that everything else in this list consumes. Delft’s group built a three-node network of solid-state qubits in 2021 and used it in 2022 to move a quantum state between two nodes that were not directly connected. The distances were metres. The significance is that the protocol stack worked end to end, with a middle node participating without ever learning the state it helped move.
Quantum state transfer between processors
The third output is the transfer of an actual quantum state from one location to another, by quantum teleportation.
The name is unhelpful. Teleportation moves the information describing a qubit, not the qubit’s physical carrier, and it consumes one shared entangled pair plus two classical bits per transfer. The sending end performs a joint measurement on its data qubit and its half of the pair, which destroys the original, and sends the two-bit result over the classical channel. The receiving end applies a correction and now holds the state. Nothing travels faster than light, because the classical message is required and moves at ordinary speed.
For a security architect, this is not yet a product category. It is the mechanism by which quantum processors in different racks, and eventually different buildings, will be linked into larger machines. Teleportation over 44 km of deployed fibre was demonstrated in 2020, and the same protocol was run from the ground to the Micius satellite over roughly 1,400 km in 2017. Both are engineering milestones rather than services.
The applications that come after
A fourth group depends on all of the above and is a decade or more from operational use. Entangled clock networks would improve time transfer beyond what satellite timing provides. Entangled sensor arrays would improve sensitivity for certain distributed measurements. Blind quantum computing would let a client run a computation on a remote quantum processor without the operator learning the input, the program, or the result. Each is a real research programme with published results and none is a procurement decision this year.
What a quantum network does not produce
Four absences do more to prevent bad decisions than any of the capabilities above.
It does not carry your data. A quantum network delivers key material, and your traffic continues to ride the classical fibre next to it. The bit rates are not comparable and are not meant to be. Nobody is proposing to move payload over single photons.
It does not secure your endpoints. The physics protects light in transit between two boxes. It says nothing about the host that requests a key, the operator who configures the encryptor, the firmware in either device, or the physical security of the room. An attacker with access to one endpoint does not care how the key arrived.
It does not create authentication out of nothing. The classical channel in a QKD protocol has to be authenticated, or an attacker who sits in the middle of it can impersonate each party to the other and the quantum measurements will look perfectly healthy. Authentication comes from a pre-shared symmetric key at initial deployment, and thereafter from key material the system itself has generated. So a QKD deployment begins with a classical key-distribution problem, solved classically, at every site.
It does not replace the post-quantum cryptography migration. Post-quantum cryptography (PQC) means classical algorithms designed to resist attack by a future quantum computer, standardised by NIST as ML-KEM for key establishment and ML-DSA, SLH-DSA, and FN-DSA for signatures. PQC runs in software, works between any two endpoints with an IP path, and covers the cases QKD structurally cannot: signing firmware, authenticating a browser to a server it has never met, protecting data at rest. QKD covers symmetric keys between two fixed physical locations. The two overlap in one narrow place and diverge everywhere else.
National guidance is unusually blunt on this. The US National Security Agency does not endorse QKD for securing national security systems and directs its constituency to post-quantum algorithms. The UK’s National Cyber Security Centre published a similar position. France’s ANSSI treats QKD as a possible defence-in-depth layer alongside conventional cryptography and not as a substitute for it. If a proposal in front of you presents a quantum network as an alternative to PQC migration, that proposal is out of step with every published position from a national authority.
The two constraints that set every roadmap
Loss you cannot amplify
Classical optical networks solve distance with amplifiers. Every 80 km or so, an amplifier boosts the signal, and the copy it produces is good enough because the signal was never fragile.
That approach is unavailable here. The no-cloning theorem says an unknown quantum state cannot be duplicated, and an optical amplifier is a copying machine. Amplify a single-photon channel and you destroy exactly the property the protocol depends on.
So the light simply attenuates. At 0.2 dB/km, a 100 km fibre delivers about one percent of what entered it, and a 200 km fibre delivers about one part in ten thousand. There is a hard ceiling on how much secret key a direct link can produce, established in 2017 and generally called the repeaterless bound or the PLOB bound after its authors. It scales with transmittance, which means key rate falls off roughly in proportion to the light that survives. Real systems run below that ceiling, never above it.
Four responses exist, and each one buys distance with a different currency.
Trusted nodes buy distance with trust. A relay terminates one QKD link, holds the key in plaintext, and re-encrypts it onto the next link. Security is now per segment, and every relay is inside your trust boundary. This is how China’s Beijing-Shanghai backbone spans roughly 2,000 km; thirty-two of its nodes are trusted relays, per the 2021 Nature paper describing the integrated network. Nothing about that is illegitimate, and it is the reason the phrase “2,000 km quantum-secured link” needs an immediate follow-up question.
Measurement-device-independent QKD (MDI-QKD) buys distance by moving the detectors to an untrusted middle node. Both parties send photons to a relay that performs a joint measurement and announces the outcome. The relay learns nothing about the key, so it does not need to be trusted, and the detector-side attack surface disappears. The cost is a demanding interference requirement and lower rates.
Twin-field QKD (TF-QKD) buys distance by improving how rate scales with loss, roughly to the square root of the direct-transmission scaling. A 2023 laboratory result carried it past 1,000 km of fibre. Field deployment is another matter, since the technique requires phase stability across the whole span.
Satellites buy distance by routing most of the path through vacuum, where loss is dominated by beam spreading rather than absorption. The Micius satellite distributed entangled photon pairs to ground stations 1,200 km apart in 2017; a separate 2018 experiment used Micius as a trusted relay for a Beijing-Vienna key exchange. Europe’s EuroQCI programme is building toward a combined terrestrial and space infrastructure across the member states on the same logic.
Coherence you cannot pause
The fifth response, and the one that would remove the trust compromise entirely, is the quantum repeater. A repeater does not amplify. It establishes entanglement with each neighbour separately, then performs an operation called entanglement swapping that converts two short entangled links into one long one, without ever measuring the information being carried. Chain enough of them and two distant parties share entanglement that no intermediate node could have read.
Repeaters need quantum memory, and quantum memory has a clock running against it. A stored qubit loses coherence through interaction with its environment, so it holds usable information only for a limited window.
Put a number on the window. Light travels about 200,000 km per second in fibre, so a 100 km hop takes roughly half a millisecond in each direction. A repeater that entangles with a neighbour has to hold its half of the pair until confirmation arrives, which is a full round trip, and entanglement attempts fail often enough that the process repeats many times before it succeeds. The memory therefore has to outlast not one round trip but many, with margin for the swapping operation itself. That requirement, more than any single component, is why repeater chains remain a laboratory result. Storage times have improved by orders of magnitude over the past decade and the engineering gap is closing, but it has not closed.
Everything in the published national roadmaps is downstream of these two constraints. When a roadmap promises repeaters by a given year, it is promising a memory-and-fidelity milestone, and that is the milestone to track.
Reading a quantum network claim
Three questions will resolve most of what an architect needs to know from a vendor conversation.
A distance without a node count
Any claimed link length above roughly 200 km involves trusted relays, satellites, or a laboratory bench. Ask which, and ask how many relays, and ask who operates the sites they occupy. For a link crossing a jurisdiction or a third-party facility, the relay locations are the security architecture. A trusted-node network is a chain of secure rooms connected by physics, and the rooms are the part your risk register cares about.
A rate without a distance
Key rate figures quoted without the distance and the loss budget they were measured at cannot be compared with anything. Ask for the rate at your actual span, on the fibre type you have, with the multiplexing arrangement you intend to use, since sharing a strand with classical traffic adds noise. Then ask for the finite-key security parameter, which is the bound the vendor is claiming on how much information an adversary could hold given the finite amount of data actually processed. Asymptotic rates assume infinite data and always look better.
Unhackable, in what sense?
The security proof describes an idealised device. Real devices deviate from that ideal, and published attacks exploit exactly those deviations.
A photon source that occasionally emits two identical photons instead of one allows an attacker to keep a copy of the extra photon undetected. The countermeasure, called the decoy-state method, varies the source intensity randomly so that this behaviour becomes statistically visible. Detectors have been attacked by bright light that pushes them out of single-photon mode and into a classical regime the attacker can steer, which was demonstrated against commercial systems in 2010. Trojan-horse attacks inject light into a device and read what comes back out to learn its internal settings. Germany’s Federal Office for Information Security commissioned a study cataloguing this class of attack against QKD systems. Request that study before evaluating any vendor’s countermeasures.
Every one of these has a countermeasure, and mature vendors implement them. The question is not whether attacks exist. It is which ones the vendor tests against, who did the testing, and whether the results are available to you.
Where the security professional’s work actually is
Almost none of the work is quantum physics. It is the work you already do, applied to an unfamiliar component.
Draw the trust boundary. For each segment, mark whether the endpoints trust each other directly or through a relay. A trusted-node architecture has as many trust boundaries as it has relays, and each one needs an owner, a physical control set, and an incident procedure.
Trace the authentication dependency. Find the pre-shared key that bootstraps the classical channel. Establish who generated it, how it was transported, where the backup copy lives, and what happens on rotation. This is a conventional key-management problem and it sits underneath the quantum guarantee.
Specify the key handoff. A key management system (KMS) is the component that stores, distributes, and rotates cryptographic keys for your applications. Decide how QKD-derived keys enter yours, whether through the ETSI interface or a vendor SDK, and what the system does when the quantum link stops producing key. That fallback behaviour is a design decision. A link that fails closed will take an application with it; a link that fails over to conventional key establishment needs that path defined in advance and covered by the same policy.
Scope the site work early. Dedicated or dark fibre where the loss budget demands it, duct access, distance between endpoints measured along the cable route rather than on a map, rack space, power, and cooling for detectors that may require cryogenics. In most pilots the civil and facilities work dominates the timeline.
Check the jurisdiction. QKD hardware can fall under export control, and procurement rules for cryptographic equipment vary. Where a sector regulator or a national authority has published a position, that position will shape what an auditor accepts.
What to do about it now
For most organizations the sequence is not in doubt.
The PQC migration comes first, because it is standardised, it is mandated in a growing number of jurisdictions, and it addresses the store-now-decrypt-later exposure across the whole estate rather than across two sites. That work starts with a cryptographic inventory and continues into crypto-agility, and the methodology is documented at pqcframework.org.
Quantum networking belongs on the watch list with defined triggers. Reasonable ones: a repeater demonstration outside a laboratory, a national infrastructure programme reaching your region, a sector regulator naming quantum-safe link protection in guidance, or a specific link whose data has a confidentiality lifetime measured in decades and whose two endpoints you physically control.
And the literacy is worth building now, ahead of the deployment, because the vendor conversations are already happening and the questions in this article only work if someone in the room can follow the answers. For deeper technical background on the underlying protocols, the quantum networks primer on PostQuantum.com goes further into the physics than we have here.
Where to take this next
Quantum Academy’s networking certification track is built for exactly the reader this article assumes: a professional who owns real links, real key management, and real procurement decisions, and who needs to evaluate quantum networking claims rather than reproduce the derivations behind them. The engineering path covers link budgets, protocol selection, trusted-node architectures, and integration with existing key management. The architecture path takes the same material up a level into network design, trust-boundary modelling, and vendor evaluation.
Both are private, industry-issued credentials rather than academic qualifications, and both are assessed against what a candidate can actually specify and defend. You can see the current programs, prerequisites and access terms at quantumacademy.com/. If you are earlier in the decision and want to understand where these skills sit in a career path, QuantumCareers.com maps the roles this track feeds.