Quantum Academy begins operations on September 15, 2026. Enrollment opens soon.
Skip to content

Quantum Networking

Why Countries Disagree About QKD

Marin Ivezic9 min read

Chen and colleagues reported in Nature in January 2021 that China had joined a 2,000 km fiber backbone between Beijing and Shanghai to the Micius satellite, producing an integrated network spanning roughly 4,600 km and serving more than 150 users across banking, power, and government. The United States National Security Agency does not support quantum key distribution for national security systems and has said it does not anticipate certifying QKD products for that use, a position set out in its published guidance on Quantum Key Distribution and Quantum Cryptography. Both positions are current, and neither side disputes the physics.

Architects ask us which side is right, usually while holding a vendor proposal. The honest answer is that they’re answering different questions, and the useful work is establishing which question your organization is actually asking. What follows is the engineering behind the split rather than the diplomacy.

What a QKD Link Delivers

Quantum key distribution sends single photons over a fiber or free-space channel between two endpoints. Measurement disturbs a photon, so an eavesdropper who taps the stream pushes up the error rate and reveals the tap. What the two endpoints get out of the process is shared random bits: symmetric key material, handed to an encryptor at each end. That is the entire product, and a QKD link is a key delivery mechanism for two fixed points rather than a cryptosystem.

It doesn’t authenticate. The two endpoints still need to know they’re talking to each other and not to equipment in the middle, and the quantum channel can’t establish that. Authentication runs over a classical channel, secured either by pre-shared symmetric keys or by digital signatures. If those signatures are RSA or ECDSA, a cryptographically relevant quantum computer breaks them and the QKD link goes with them. So the authenticated channel has to be quantum-safe on its own terms, which today means a post-quantum signature scheme such as ML-DSA, standardized by NIST as FIPS 204 in August 2024 alongside the ML-KEM key encapsulation mechanism, FIPS 203. Post-quantum cryptography, or PQC, is the family of algorithms designed to withstand a quantum computer while running on ordinary hardware over ordinary networks.

Every serious national position agrees on that much. QKD does not remove the need for PQC. The NSA puts the point first among its published objections, and the 2024 Position Paper on Quantum Key Distribution, issued jointly by ANSSI in France, the BSI in Germany, the NLNCSA in the Netherlands, and Sweden’s NCSA, reaches the same conclusion and tells decision-makers to prioritize PQC migration. Divergence starts one step later, on what QKD adds once PQC is already in place.

The Trusted Node, Worked Through

Distance drives everything else. Photons are absorbed in fiber and cannot be amplified, because amplification destroys the quantum state the scheme depends on. Commercial links therefore run over tens of kilometers, or a few hundred at very low key rates. Longer routes get built by chaining short segments through relay sites.

Take a 600 km route assembled from six segments of roughly 100 km, with five relay sites in between. Each segment generates its own key, shared between the two boxes at its ends. Moving a key from one end of the route to the other means each relay decrypts it with the key it shares upstream, then re-encrypts it with the key it shares downstream. For that moment the key exists in plaintext inside the relay. Repeat five times and the security of the route rests on the physical and personnel security of five buildings.

That arithmetic explains most of the world map. An agency responsible for defending networks it does not own reads five relay sites as five new high-value targets and five new insider risks. A state building a sovereign backbone across territory it already guards reads them as five more facilities on an existing list. Same architecture, different threat model, opposite conclusion.

Research protocols chip away at the problem. Twin-field QKD, in which each endpoint sends photons to a middle station instead of to the far end, has reached hundreds of kilometers of laboratory fiber without trusted relays, far past anything deployed commercially, though the secret key rate at that range is a trickle. Quantum repeaters would remove trusted nodes altogether, and they are not a deployable technology yet.

Four Questions Behind the Split

Once the engineering is on the table, national positions stop looking like arguments about physics and start looking like different answers to four practical questions.

What Is Being Defended

Most encrypted traffic moves between endpoints that were never planned as a pair, such as browsers and servers, handsets and base stations, or workloads and cloud services. QKD cannot serve any of it at any budget, because it needs a dedicated physical channel between two known points. PQC serves all of it with a software change. If the threat model is harvest-now-decrypt-later, where an adversary records ciphertext today and decrypts it once a quantum computer arrives, and the traffic is internet-scale, then QKD is not a candidate. If it is a handful of fixed, long-lived, high-value links between sites under one owner, it becomes one.

What Counts as Assurance

The NSA and the UK’s National Cyber Security Centre certify products, not principles. QKD’s security proofs are strong. Its implementations have been broken repeatedly in laboratories through detector blinding, laser damage, and side channels the proofs never modeled. For years there was no shared framework for evaluating the hardware at all. ETSI published the first protection profile for QKD modules in 2023, a standardized requirement set a certification lab can test a product against. National programs in China and the European Union treat sustained field deployment as its own form of evidence. Those are two different standards of proof, and they produce two different answers on the same day.

Who Owns the Fiber

European and Chinese planning inherits the assumptions of the state telecom monopoly. For most of the twentieth century the national PTT, the state post, telegraph and telephone administration, owned the wires, wrote the standards, and could be directed to install new equipment on a policy timetable rather than a commercial one. That inheritance shows in EuroQCI, the European Quantum Communication Infrastructure, an EU initiative backed by all 27 member states to build a continent-wide secure network from terrestrial links and satellites, with the Eagle-1 satellite planned as its first dedicated space segment. American cyber policy is written for networks the government neither owns nor instructs. Telling a commercial carrier to install single-photon detectors in its exchanges is a recommendation somebody else has to fund, and agencies write their guidance accordingly.

Security Policy or Industrial Policy

A national QKD program buys more than key material. It builds domestic capability in single-photon detectors, cryogenics, integrated photonics, satellite payloads, and the systems integration that ties them together. That is a defensible reason to fund one, and it is a different reason from the one that appears in the press release. It also changes how the announcements should be read. A program justified on sovereignty grounds will not be cancelled because a cryptographer points out that PQC is cheaper per protected connection.

Where the Positions Agree

Three things hold across every position on record, including the skeptical ones. First, PQC comes first, and no national body recommends QKD as a substitute for algorithm migration. Second, QKD is key agreement for two fixed endpoints and nothing more; it offers no help with data integrity, identity, or the thousands of certificates in a typical enterprise. Third, the standards work is shared. ETSI’s industry specification group on QKD has run since 2008 with participants from Europe, North America, and Asia, and the ITU has published recommendations for quantum key distribution networks. Agencies and vendors that disagree in public sit in the same working groups.

The European position reads as a contradiction and isn’t one. ANSSI, BSI, and their Dutch and Swedish counterparts told member states that QKD is immature today and applies to a narrow set of cases. The European Commission is funding a network for 2030. Those are statements about different years.

Evaluating a QKD Proposal

When a proposal reaches an architect, the national debate is not the useful frame. These are the questions we would put to the vendor, in this order.

  1. What authenticates the classical channel, and with which algorithm? If the answer is RSA or ECDSA, the link is not quantum-safe end to end, whatever the quantum channel does.
  2. Point-to-point, or relayed? If relayed, name every trusted node, its owner, and the personnel regime protecting it.
  3. What is the secret key rate at the deployed distance, over the deployed fiber, in the deployed environment? Laboratory figures do not transfer.
  4. What happens when the quantum channel drops? Cutting a fiber or flooding it with light is a denial-of-service no protocol prevents, so the service degrades to something, and that something is classical cryptography.
  5. What certification does the hardware hold, against which profile, from which lab?
  6. What is the cost per protected link, set against migrating the whole estate to PQC?

The sixth question decides most cases, and in our experience it gets asked last.

The Short Answer on Skepticism

Against one claim, the skepticism is justified. QKD does not replace post-quantum cryptography, will not secure general internet traffic, and does nothing about the inventory and migration work every organization now owes its own estate. A vendor who says otherwise is selling something.

Against the broader claim, it isn’t. QKD is a point-to-point key agreement technology with one property classical cryptography cannot offer – physical detection of interception – and there is a small set of links where that property earns its cost. Long-lived government trunks, inter-site links inside a single owner’s estate, and control channels in critical infrastructure are the cases that keep recurring. Whether they justify a national program is a budget question, and reasonable agencies have answered it both ways.

Our position is that architects should stop treating the two technologies as competitors. PQC is the migration you have to do. QKD is a design option for a handful of links, assessed on the six questions above rather than on anyone’s national strategy.

Two things equip an architect for that assessment: a working model of what a QKD link does at the protocol and hardware level, and a migration plan for the cryptography already running. Quantum Academy training covers both, and the current catalog is at quantumacademy.com/. For migration methodology, including inventory and prioritization, the NIST National Cybersecurity Center of Excellence publishes its Migration to Post-Quantum Cryptography project materials. For the primary documents behind the national positions summarized here, PostQuantum.com tracks them as they publish.