Skip to content

Cryptography Case Studies

A cryptography case study follows a security objective through its threat model, protocol, physical or computational assumptions, implementation, operational environment, and migration plan. It asks not merely whether a primitive is quantum, post-quantum, or asymptotically secure, but which security service is obtained, against which adversary, at what rate and cost, and under which trust assumptions.

This page examines four connected cases:

  • BB84-style quantum key distribution over a realistic lossy optical link;
  • entanglement-based QKD from metropolitan experiments to satellite and device-independent demonstrations;
  • the interface between standardized post-quantum primitives and deployed protocols;
  • Shor resource estimates as inputs to migration decisions rather than forecasts of a fixed arrival date.

Quantum Key Distribution is the canonical home for composable security, finite-key distillation, authentication, and implementation attacks. Quantum Randomness owns the entropy-source, extraction, health-test, and delivered-randomness contract on which every cryptographic branch ultimately depends. Blind and Delegated Quantum Computation owns private quantum cloud computation, including simulator-based blindness, accepted-wrong-output bounds, client capability models, and the distinction between integrity and availability. Shor Algorithm owns order finding, factoring, discrete logarithms, and the detailed resource model. This page owns the end-to-end comparison of cryptographic deployment claims.

Cryptography supplies services, not a single quantity called security. Confidentiality, peer authentication, data-origin authentication, integrity, forward secrecy, nonrepudiation, availability, and long-term artifact verification are different objectives. A key-establishment mechanism does not by itself authenticate software, and a signature scheme does not by itself hide a session.

Before selecting a technology, record:

  1. the assets and their required confidentiality or authenticity lifetimes;
  2. the endpoints, channels, operators, manufacturers, and trust roots;
  3. the adversary’s access during deployment and after archived data are obtained;
  4. whether information-theoretic, computational, or implementation-bounded security is required;
  5. the tolerated outage, latency, key rate, and geographic constraints;
  6. the mechanism for authentication, updates, revocation, and incident recovery;
  7. the version of every standard, parameter set, proof, and implementation.

A useful migration inequality separates three timescales. Let TsecretT_{\mathrm{secret}} be the period for which captured data must remain confidential, TmigrateT_{\mathrm{migrate}} the time required to replace the vulnerable system, and TCRQCT_{\mathrm{CRQC}} an organization’s planning horizon for a cryptographically relevant quantum computer. Exposure becomes plausible when

Tmigrate+Tsecret>TCRQC.T_{\mathrm{migrate}} + T_{\mathrm{secret}} > T_{\mathrm{CRQC}}.

This is a planning relation, not a prediction of when such a machine will exist. Different organizations can assign different horizons while agreeing on the engineering facts. It also makes the harvest-now-decrypt-later threat concrete: traffic copied today may be attacked after the endpoint has already been retired.

Cryptographic security stack connecting QKD, post-quantum key establishment, and post-quantum signatures to protected applications and their supporting infrastructure

QKD, post-quantum key encapsulation, and post-quantum signatures occupy different layers. All three inherit endpoint, randomness, authorization, key lifecycle, implementation-assurance, and migration obligations. A QKD link also needs an authenticated classical bootstrap; it does not manufacture identity from the quantum channel.

The canonical BB84 protocol describes single qubits prepared in one of two conjugate bases. Practical fiber systems commonly use attenuated laser pulses, phase or time-bin encoding, lossy components, imperfect detectors, and a decoy-state analysis. Those substitutions are not cosmetic: a coherent optical pulse has a nonzero probability of containing more than one photon, while detector background becomes increasingly important as the signal is attenuated.

For fiber attenuation α\alpha in decibels per kilometer and length LL, the channel transmittance is

ηch(L)=10−αL/10.\eta_{\mathrm{ch}}(L) = 10^{-\alpha L/10}.

If ηopt\eta_{\mathrm{opt}} represents receiver optics and ηdet\eta_{\mathrm{det}} detector efficiency, a simple system transmittance is

ηsys=ηchηoptηdet.\eta_{\mathrm{sys}} = \eta_{\mathrm{ch}} \eta_{\mathrm{opt}} \eta_{\mathrm{det}}.

This product omits effects such as dead time, afterpulsing, saturation, mode-dependent loss, and finite temporal gates. It is nevertheless a useful first audit of a claimed distance.

An ideal phase-randomized coherent pulse with mean photon number μ\mu is a classical mixture of photon-number states with

Pμ(n)=e−μμnn!.P_\mu(n) = e^{-\mu} \frac{\mu^n}{n!}.

Its multiphoton probability is

Pμ(n≥2)=1−e−μ(1+μ).P_\mu(n\geq2) = 1-e^{-\mu}(1+\mu).

For μ=0.5\mu=0.5, this probability is about 9.0%9.0\%. Treating every pulse as a single photon would therefore erase the very side channel that decoy-state BB84 is designed to bound.

Let Y0Y_0 be the background click probability per emitted pulse. In a threshold-detector model, the total signal-state gain is approximately

Qμ≃1−(1−Y0)e−ηsysμ.Q_\mu \simeq 1-(1-Y_0)e^{-\eta_{\mathrm{sys}}\mu}.

If random background clicks have error probability e0=1/2e_0=1/2 and optical misalignment gives signal error probability ede_d, then

EμQμ≃e0Y0+ed(1−e−ηsysμ).E_\mu Q_\mu \simeq e_0Y_0 + e_d \left( 1-e^{-\eta_{\mathrm{sys}}\mu} \right).

This deliberately compact model shows the high-loss transition. The signal term falls exponentially with distance, while the background term does not. As the two become comparable, the quantum bit error rate EμE_\mu rises even if the optics themselves have not become more misaligned.

Take

α=0.20 dB/km,ηopt=0.80,ηdet=0.25,μ=0.50,Y0=10−6,ed=0.015.\begin{aligned} \alpha &= 0.20\ \mathrm{dB/km}, & \eta_{\mathrm{opt}} &= 0.80, \\ \eta_{\mathrm{det}} &= 0.25, & \mu &= 0.50, \\ Y_0 &= 10^{-6}, & e_d &= 0.015. \end{aligned}

The resulting raw quantities are:

Fiber lengthChannel lossSignal-state gain QμQ_\muApproximate QBER
50 km50\ \mathrm{km}10 dB10\ \mathrm{dB}9.95×10−39.95\times10^{-3}1.50%1.50\%
100 km100\ \mathrm{km}20 dB20\ \mathrm{dB}1.00×10−31.00\times10^{-3}1.55%1.55\%
200 km200\ \mathrm{km}40 dB40\ \mathrm{dB}1.10×10−51.10\times10^{-5}5.91%5.91\%

These are illustrative detection and error quantities, not finite secret-key rates. A defensible rate additionally needs basis probabilities, decoy statistics, error-correction leakage, finite-size confidence intervals, authentication cost, composable security parameters, detector recovery, and the number of pulses sent.

An eavesdropper can exploit photon number. In a photon-number-splitting strategy, one photon from a multiphoton pulse is retained while another continues to the receiver. The legitimate users cannot safely infer the single-photon contribution from one aggregate detection rate alone.

Decoy-State QKD is the canonical derivation of the shared-yield equations and vacuum-plus-weak bounds. Here they enter as one layer of the link-budget case study.

Decoy-state protocols randomly vary μ\mu. Because Eve does not know the intensity choice before interacting with the pulse, pulses with the same photon number must have intensity-independent yields in the model. The observed gains and error rates at several intensities then constrain the single-photon gain Q1Q_1 and error rate e1e_1.

A representative asymptotic lower bound for efficient decoy-state BB84 is

R≥q[−QμfECh2(Eμ)+Q1(1−h2(e1))],R \geq q \left[ -Q_\mu f_{\mathrm{EC}}h_2(E_\mu) + Q_1 \left( 1-h_2(e_1) \right) \right],

where qq is the sifting factor, fEC≥1f_{\mathrm{EC}}\geq1 is error-correction inefficiency, and

h2(x)=−xlog⁡2x−(1−x)log⁡2(1−x)h_2(x) = -x\log_2x -(1-x)\log_2(1-x)

is binary entropy. The negative term pays for reconciling all detected signal pulses; the positive term extracts privacy from the estimated single-photon subset.

This equation is asymptotic and protocol-specific. It must not be silently used as a finite-key guarantee. A finite experiment replaces exact expectations by confidence regions and subtracts explicit privacy amplification, verification, smoothing, and authentication terms.

Distance records and the repeaterless bound

Section titled “Distance records and the repeaterless bound”

Boaron and collaborators demonstrated secret-key generation through 421 km421\ \mathrm{km} of ultralow-loss fiber, with 6.56.5 secret bits per second reported at 405 km405\ \mathrm{km}. Their system combined a 2.5 GHz2.5\ \mathrm{GHz} three-state time-bin protocol, one-decoy estimation, low-loss components, and low-noise superconducting detectors. The result is an integrated implementation achievement, not a generic rate available on ordinary 0.20 dB/km0.20\ \mathrm{dB/km} installed fiber.

For a pure-loss bosonic channel of transmittance η\eta, the Pirandola–Laurenza–Ottaviani–Banchi repeaterless secret-key capacity is

K(η)≤−log⁡2(1−η).K(\eta) \leq -\log_2(1-\eta).

At high loss,

K(η)≃ηln⁡2bits per optical mode.K(\eta) \simeq \frac{\eta}{\ln2} \qquad \text{bits per optical mode}.

The resource denominator is essential. Bits per emitted pulse, detected pulse, temporal mode, wavelength mode, channel use, and second are not interchangeable. A protocol claiming to beat the direct-channel bound must count every independently used mode consistently. Twin-field QKD can change the loss scaling by introducing interference at an untrusted middle station, but it should be compared with the correctly normalized network bound rather than with an artificially narrow denominator.

In an entanglement-based protocol, a source distributes correlated systems to Alice and Bob. They measure in selected bases and use a subset of outcomes to estimate the correlations relevant to secrecy. E91 and Entanglement-Based QKD connects key establishment with a Bell test; later security proofs also relate entanglement purification and prepare-and-measure BB84.

If one usable pair is created with probability ppairp_{\mathrm{pair}} per clock cycle, a first coincidence estimate is

pcoin≃ppairηAηBηdet,Aηdet,B.p_{\mathrm{coin}} \simeq p_{\mathrm{pair}} \eta_A \eta_B \eta_{\mathrm{det},A} \eta_{\mathrm{det},B}.

For a source midway between two users, both channel transmittances enter. Increasing source brightness raises the raw coincidence rate but also raises multi-pair emissions, accidental coincidences, and error. Detector dark counts and timing-window width again dominate once true coincidences become rare.

Entanglement-based does not automatically mean device-independent. Most deployed protocols trust a model of the sources or measurement devices and derive security within that model. Measurement-Device-Independent QKD removes detector trust by moving the joint measurement to an untrusted station. Device-Independent QKD instead certifies secrecy from loophole-controlled nonlocal correlations plus explicit laboratory, causal, and randomness assumptions. These are three distinct trust contracts.

Yin and collaborators used the Micius satellite to distribute entanglement between ground stations separated by 1,120 km1{,}120\ \mathrm{km} and reported a finite secret-key rate of 0.12 bit/s0.12\ \mathrm{bit/s}. The architecture avoided a trusted relay holding the final key: the satellite distributed entangled photons rather than learning and forwarding an ordinary shared key.

The result does not remove all trust. The endpoints, measurement devices, randomness, classical authentication, satellite source behavior within the security model, and operational control still matter. Atmospheric windows, pointing, weather, orbital passes, and finite acquisition time also make the service model unlike a continuously available terrestrial network.

Nadlinger and collaborators reported a device-independent QKD experiment that produced 95,62895{,}628 final secret bits from approximately 1.51.5 million Bell pairs over eight hours. The experiment closed the detection loophole and used separated ion-trap systems with a security proof tailored to the implementation.

That achievement demonstrates complete device-independent key generation, not a metropolitan deployment rate. The average final throughput was about 3.32 bit/s3.32\ \mathrm{bit/s}, and the experiment did not impose spacelike separation of the measurement events. Security therefore retained a laboratory isolation assumption preventing unauthorized information flow between devices during operation. Device independence reduces particular modeling trust; it does not mean assumption-free.

Liu and collaborators reported a second distance regime in 2026 using long-lived remote ion–ion entanglement with a telecom interface. Their proof-of-principle DIQKD application included finite-size analysis over 10 km10\ \mathrm{km} of spooled fiber and a positive key rate beyond 101 km101\ \mathrm{km} in the asymptotic limit. The two clauses must not be collapsed: the work did not claim a positive finite key at 101 km101\ \mathrm{km}. It demonstrates how heralded memories can move channel loss outside the Bell trial, while low entanglement-generation probability, communication latency, and finite-block acquisition remain central rate constraints.

A long-distance number is incomplete without topology. A network can extend reach by:

  • trusted relays, which decrypt or reconstruct key material at intermediate protected nodes;
  • untrusted optical measurements, as in measurement-device-independent and twin-field designs;
  • satellite links, whose trust model depends on whether the satellite distributes entanglement or relays key;
  • quantum repeaters, which aim to distribute entanglement without trusted access to the final key but remain an active engineering frontier.

Chen and collaborators integrated a terrestrial backbone with satellite QKD into a network spanning up to 4,600 km4{,}600\ \mathrm{km}. It contained more than 700700 fiber QKD links and two satellite-to-ground links. This demonstrated large operational reach, key management, and heterogeneous integration. Its fiber backbone used trusted relays, so physical security of intermediate sites remained part of the end-to-end guarantee.

In 2026, an integrated-photonics twin-field QKD experiment connected 20 client chips through ten wavelength channels and demonstrated pairwise links over 370 km370\ \mathrm{km} of spooled fiber. The reported rates surpassed the appropriately counted direct repeaterless bound. Pairwise operation was sequential, however, and the fiber was laboratory spool rather than a simultaneously loaded field network. The strongest description is therefore a scalable-component and network-architecture proof of principle.

Every QKD network report should accompany distance with:

  • secret bits per second and security parameter;
  • optical loss, detector characteristics, and number of modes;
  • finite-key block size and acquisition time;
  • simultaneous versus sequential users;
  • trusted nodes and authenticated classical paths;
  • field fiber versus laboratory spool;
  • uptime, environmental constraints, and key-management policy;
  • whether application traffic was protected and how the generated key was consumed.

Case Study 3: The Post-Quantum Protocol Interface

Section titled “Case Study 3: The Post-Quantum Protocol Interface”

Post-quantum cryptography uses classical computation and ordinary communication channels. Its security is based on computational problems for which no efficient classical or quantum attacks are known under the selected parameters and model. It can therefore be deployed in software and hardware without waiting for a quantum network.

A key-encapsulation mechanism has the abstract interface

(pk,sk)←KeyGen(),(ct,ssA)←Encaps(pk),ssB←Decaps(sk,ct).\begin{aligned} (\mathit{pk},\mathit{sk}) &\leftarrow \mathsf{KeyGen}(), \\ (\mathit{ct},ss_A) &\leftarrow \mathsf{Encaps}(\mathit{pk}), \\ ss_B &\leftarrow \mathsf{Decaps}(\mathit{sk},\mathit{ct}). \end{aligned}

For a valid encapsulation, ssA=ssBss_A=ss_B except with the scheme’s specified failure probability. A KEM is not generally an encryption algorithm for an arbitrary file. A protocol derives traffic keys from ssAss_A, binds them to the transcript and negotiated context, and then uses authenticated symmetric encryption.

A digital-signature scheme has

(vk,sk)←SigKeyGen(),σ←Sign(sk,m),b←Verify(vk,m,σ).\begin{aligned} (\mathit{vk},\mathit{sk}) &\leftarrow \mathsf{SigKeyGen}(), \\ \sigma &\leftarrow \mathsf{Sign}(\mathit{sk},m), \\ b &\leftarrow \mathsf{Verify}(\mathit{vk},m,\sigma). \end{aligned}

Signatures authenticate protocol handshakes, certificates, software, firmware, documents, and audit artifacts. Replacing key establishment while leaving a vulnerable certificate or update-signing path intact is not a complete migration.

NIST finalized three initial post-quantum standards in 2024:

  • FIPS 203, ML-KEM, for key encapsulation;
  • FIPS 204, ML-DSA, for digital signatures;
  • FIPS 205, SLH-DSA, a stateless hash-based signature alternative.

ML-KEM and ML-DSA use module-lattice constructions; SLH-DSA uses hash-based trees. These labels identify algorithm families and parameter sets, not a drop-in guarantee for every protocol. Implementers must consult the current standard and its errata, validate implementations, and use the approved parameter set required by their environment. NIST SP 800-227, finalized in 2025, supplies broader recommendations for securely using KEMs.

Standardization does not freeze cryptanalysis. It creates a versioned interoperability and assurance target while analysis continues. It also does not imply that every legacy protocol can carry the new keys, ciphertexts, signatures, certificates, or handshake messages without redesign.

A protocol-level key schedule should domain-separate the new secret and bind it to the parties’ negotiated transcript. Schematically,

Ksession=KDF(ssPQC∥H(transcript)∥suite∥context).\begin{aligned} K_{\mathrm{session}} = \mathsf{KDF}( &ss_{\mathrm{PQC}} \mathbin\Vert H(\mathit{transcript}) \\ &\mathbin\Vert \mathit{suite} \mathbin\Vert \mathit{context} ). \end{aligned}

The transcript should cover identities, roles, algorithm choices, public keys or certificates, encapsulation ciphertexts, nonces, and downgrade- relevant negotiation. Exactly which bytes are covered is a protocol specification, not an implementation preference.

The surrounding system must also handle:

  • invalid-ciphertext behavior without creating a timing or error oracle;
  • fresh, high-quality randomness;
  • key erasure and forward-secrecy policy;
  • certificate and message-size limits;
  • retransmission, fragmentation, and denial-of-service exposure;
  • side-channel-resistant arithmetic;
  • algorithm identifiers, parameter negotiation, and rollback prevention;
  • interoperability across libraries, accelerators, hardware security modules, and middleboxes.

An implementation that passes a primitive’s known-answer tests can still fail at these interfaces.

During a transition, a protocol may combine a traditional secret ssTss_T and a post-quantum secret ssPQss_{\mathrm{PQ}}:

Ksession=KDF(ssT∥ssPQ∥H(transcript)∥context).\begin{aligned} K_{\mathrm{session}} = \mathsf{KDF}( &ss_T \mathbin\Vert ss_{\mathrm{PQ}} \\ &\mathbin\Vert H(\mathit{transcript}) \mathbin\Vert \mathit{context} ). \end{aligned}

The intended robust property is that the session remains secure if at least one component remains secure. Concatenation followed by a KDF is not a proof of that property in every model. The combiner, authentication, key reuse, contributory behavior, failure handling, and transcript binding must be analyzed together. RFC 9794 supplies terminology for post-quantum/traditional hybrid schemes; RFC 9958 gives protocol-engineering guidance and warns that migration affects far more than primitive substitution.

Hybrid deployment has a real cost: larger handshakes, two implementations, more failure modes, and a more complicated negotiation state. It can be a sound transition tool when those costs and the combiner security are explicit. It is not automatically safer merely because two algorithms appear in the configuration.

Combining QKD and post-quantum cryptography

Section titled “Combining QKD and post-quantum cryptography”

A system can also combine a QKD-derived key KQKDK_{\mathrm{QKD}} with a KEM-derived secret:

Ktraffic=KDF(KQKD∥ssPQC∥H(transcript)∥context).\begin{aligned} K_{\mathrm{traffic}} = \mathsf{KDF}( &K_{\mathrm{QKD}} \mathbin\Vert ss_{\mathrm{PQC}} \\ &\mathbin\Vert H(\mathit{transcript}) \mathbin\Vert \mathit{context} ). \end{aligned}

This can diversify assumptions, but the system inherits both infrastructures. The QKD classical channel still needs initial authentication. A post-quantum signature or pre-shared symmetric key may provide it, with a carefully defined key-refresh chain. The protocol must decide what happens when the QKD key buffer is empty, a detector alarms, the ordinary network fails, or one component rejects.

QKD does not replace digital signatures. It cannot by itself verify a software update from a vendor, establish a scalable public-key identity across disconnected parties, or preserve an artifact’s provenance after the link session ends. Conversely, a post-quantum KEM does not provide the physical-layer intrusion diagnostics or information-theoretic key agreement target of an ideal QKD construction.

The first operational deliverable is a cryptographic inventory, including:

  • protocols, cipher suites, certificate profiles, and key stores;
  • source code, libraries, firmware, appliances, and hardware accelerators;
  • keys embedded in devices with long field lifetimes;
  • update-signing and code-verification roots;
  • data whose confidentiality extends beyond the migration horizon;
  • partner, supplier, regulatory, and archival dependencies;
  • algorithm identifiers that cannot represent new schemes;
  • test, rollback, telemetry, and incident-response paths.

NIST defines cryptographic agility as the ability to replace or adapt cryptographic algorithms across protocols, software, hardware, firmware, and infrastructure while preserving security and operations. Agility is not runtime negotiation of every imaginable algorithm. Unconstrained negotiation can create downgrade paths. Mature agility uses policy-controlled suites, complete transcript binding, staged rollout, observability, and an exercised retirement procedure.

NIST IR 8547 provides a transition-plan framework but, as of this review, is an initial public draft. It should be labeled as guidance under development, not cited as a final mandatory schedule. The current final FIPS documents, sector-specific rules, and an organization’s own risk analysis determine the actual migration obligation.

Case Study 4: Shor Estimates and Migration Context

Section titled “Case Study 4: Shor Estimates and Migration Context”

A sufficiently large fault-tolerant quantum computer running Shor’s algorithms would directly attack:

Quantum problemRepresentative vulnerable uses
integer factoringRSA encryption, key transport, and signatures
finite-field discrete logarithmfinite-field Diffie–Hellman, DSA, and ElGamal
elliptic-curve discrete logarithmECDH, ECDSA, and related curve protocols

This is not a direct break of AES or a cryptographic hash function. Generic quantum exhaustive search is associated with Grover’s quadratic query improvement and has a different cost model. Security categories and parameter choices should be analyzed for the actual construction rather than derived from a slogan that quantum computers halve all key lengths.

The public-key threat also separates into two timelines:

  • confidentiality: copied RSA- or ECDH-protected sessions may be decrypted later, so exposure can precede a working quantum computer;
  • authenticity: a future machine could forge RSA or ECDSA signatures, but an attacker generally cannot retroactively insert a forged handshake into a correctly archived past transcript.

Long-lived signed artifacts still need special treatment. Verification keys, timestamps, transparency logs, archival signatures, and renewal procedures must remain trustworthy over the artifact’s lifetime.

Asymptotic polynomial time establishes the algorithmic threat but does not specify a machine date. A physical resource estimate composes arithmetic, logical circuit, error-correcting code, factory, routing, decoder, and timing models. Changing any layer can change the qubit and runtime headline.

Three widely cited estimates illustrate the distinction:

StudyTarget and estimateEvidence level and boundary
Roetteler et al. (2017)A 256-bit prime-field elliptic-curve discrete logarithm uses about 2,3302{,}330 logical qubits and 1.3×10111.3\times10^{11} Toffoli gates in the stated constructionReversible logical circuit; no physical error-correction forecast
Gidney and Ekerå (2021)RSA-2048 in about eight hours using about 20 million physical qubitsSurface-code architecture estimate with 10−310^{-3} physical gate error, 1 μs1\ \mu\mathrm{s} code cycle, nearest-neighbor grid, and explicit factories
Gidney (2025)RSA-2048 in less than one week using fewer than one million noisy qubitsResearch preprint using newer arithmetic, storage, and magic-state methods under related headline hardware assumptions

The 2025 result does not show that an existing million-qubit noisy machine can factor RSA-2048. The word noisy describes physical qubits inside a modeled fault-tolerant architecture. Code distance, logical failure budget, decoder throughput, factory yield, connectivity, control, cooling, and sustained operation remain part of the machine.

Nor should the two RSA estimates be reduced to one qubit number. The 2021 point spends more qubits for a shorter runtime; the 2025 point explores a different space–time tradeoff with changed circuit techniques. A useful comparison preserves:

R=(Nphys,Twall,pphys,tcycle,C,ϵfail),\mathcal R = \left( N_{\mathrm{phys}}, T_{\mathrm{wall}}, p_{\mathrm{phys}}, t_{\mathrm{cycle}}, \mathcal C, \epsilon_{\mathrm{fail}} \right),

where C\mathcal C records code, connectivity, arithmetic, factories, decoding, and control assumptions. A scalar such as physical qubit-hours can help expose tradeoffs, but it cannot prove architecture equivalence.

Resource Estimation Tools develops this contract in detail. The actionable cryptographic conclusion is not a countdown derived from any one estimate. It is that the vulnerable algorithms have known polynomial-time quantum attacks, migration takes years, and confidentiality lifetimes can extend beyond deployment cycles.

An organization need not assign a precise probability distribution to TCRQCT_{\mathrm{CRQC}} before acting. It can use robust decisions:

  1. inventory vulnerable public-key uses and long-lived data;
  2. remove algorithm and certificate-format assumptions that block change;
  3. test standardized post-quantum suites in representative protocols;
  4. deploy first where harvest-now-decrypt-later exposure and replacement lead times are greatest;
  5. use analyzed hybrid modes where continuity or policy requires them;
  6. monitor standards, errata, cryptanalysis, performance, and interoperability;
  7. rehearse rollback and emergency algorithm retirement.

This policy remains sensible if the first cryptographically relevant machine arrives earlier than expected, much later, or not through the architecture used in today’s resource estimates.

MechanismPrimary serviceMain assumptionsDeployment constraint
post-quantum KEMsession-key establishmenthardness of selected problem, correct implementation, authenticated protocolsoftware, protocol, certificate, and performance migration
post-quantum signatureidentity and artifact authenticationunforgeability of selected scheme, protected signing key, trustworthy PKIkey and signature sizes, verification ecosystem, archival policy
point-to-point QKDshared fresh key materialquantum model, authenticated classical channel, trusted endpoints and implementationdedicated optical path, distance, loss, detectors, key rate
trusted-relay QKD networkextended key reachevery relay is physically and operationally trustedprotected sites and end-to-end key management
device-independent QKDkey with reduced device-model trustvalid Bell-test assumptions, isolation, randomness, finite statisticsvery demanding loss, rate, and laboratory control
symmetric cryptographybulk data protection and authenticationsecret keys, sound construction, adequate parameterssecure key establishment, rotation, storage, and nonce discipline

These mechanisms are complements in many systems. A common architecture uses a KEM and signatures to authenticate and establish a session, a symmetric authenticated-encryption scheme for data, and possibly QKD to refresh key material on selected high-value links. The security argument must cover the composition, not award the whole system the strongest adjective attached to one component.

  • Calling QKD quantum encryption when the protocol actually distributes key.
  • Reporting fiber distance without attenuation, secret-key rate, finite-key block, security parameter, or trusted-node topology.
  • Treating an attenuated laser pulse as a deterministic single photon.
  • Quoting an asymptotic decoy-state rate as a finite experimental guarantee.
  • Equating entanglement-based, measurement-device-independent, and device-independent QKD.
  • Saying device-independent means assumption-free.
  • Claiming a trusted-relay network offers end-to-end security independent of relay compromise.
  • Comparing a multimode protocol with a single-mode capacity bound.
  • Treating a KEM as arbitrary public-key encryption.
  • Replacing a KEM but retaining vulnerable handshake signatures or update-signing keys.
  • Concatenating secrets and calling the result a proven robust hybrid without specifying the combiner and transcript.
  • Allowing fallback or algorithm negotiation outside authenticated transcript coverage.
  • Assuming QKD replaces signatures, PKI, access control, endpoint security, or incident response.
  • Presenting a NIST draft as a final standard.
  • Quoting physical qubits without runtime, physical error, code cycle, connectivity, code, factory, and failure assumptions.
  • Treating a resource estimate as a forecast or a small factoring demonstration as a cryptographic break.
  • Saying Shor directly breaks AES or all cryptography.

For a QKD result, report:

  1. protocol variant, security definition, proof source, and security parameter;
  2. source, encoding, decoy intensities, basis probabilities, and clock rate;
  3. optical loss and mode count from transmitter to detector;
  4. detector efficiency, background, timing window, dead time, and saturation;
  5. sifted, reconciled, and final secret-key rates;
  6. finite-key block size, acquisition time, and statistical method;
  7. authentication method and net key consumption;
  8. device assumptions, trusted nodes, topology, and user concurrency;
  9. application key-use policy and behavior during link failure;
  10. field conditions, uptime, calibration, and independently reproduced components.

For a post-quantum migration result, report:

  1. exact standard, parameter set, errata state, and implementation version;
  2. protocol binding, transcript coverage, authentication, and key schedule;
  3. handshake bytes, latency, CPU time, memory, and energy on target devices;
  4. failure and side-channel behavior;
  5. certificates, HSMs, firmware, middleboxes, APIs, and partner dependencies;
  6. hybrid combiner and downgrade analysis, if used;
  7. interoperability and negative tests;
  8. rollback, observability, key lifecycle, and retirement policy.

For a Shor resource claim, report the target problem and parameter, logical circuit, non-Clifford cost, logical qubits, error-correcting code, physical error and cycle time, connectivity, factories, decoder, total failure budget, wall time, physical qubits, and publication version. Label theorem, experiment, simulation, estimate, and forecast separately.

Several conclusions are well established:

  • ideal QKD protocols admit rigorous security proofs, including composable formulations, under explicit models;
  • real optical loss, finite statistics, source imperfections, detector behavior, authentication, and endpoints determine deployed security;
  • decoy-state and entanglement-based systems have generated secret key over hundreds of kilometers of fiber and satellite-scale free-space links;
  • trusted-relay QKD networks can operate over continental reach, while repeaterless untrusted reach remains rate-limited;
  • device-independent QKD has crossed from a proof proposal to complete laboratory key generation and a 10 km10\ \mathrm{km} finite-size proof-of-principle, but remains demanding in rate, isolation, and block acquisition;
  • standardized post-quantum KEM and signature primitives now support concrete migration work on ordinary infrastructure;
  • factoring and discrete logarithms have polynomial-time fault-tolerant quantum algorithms, while cryptographically relevant physical resources remain architecture-dependent estimates rather than demonstrated machines.

Open engineering and research questions include scalable untrusted quantum networking, high-rate device-independent protocols, implementation assurance, side-channel-resistant post-quantum deployments, robust hybrid composition, cryptographic agility across long-lived infrastructure, and tighter fault-tolerant resource estimates tied to experimentally credible hardware models.

Using the illustrative BB84 parameters above, verify the 200 km200\ \mathrm{km} gain and QBER. What fraction of all clicks is due to the background model?

Solution

At 200 km200\ \mathrm{km},

ηch=10−0.2(200)/10=10−4.\eta_{\mathrm{ch}} = 10^{-0.2(200)/10} = 10^{-4}.

Therefore

ηsys=10−4(0.8)(0.25)=2.0×10−5,\eta_{\mathrm{sys}} = 10^{-4}(0.8)(0.25) = 2.0\times10^{-5},

and ηsysμ=10−5\eta_{\mathrm{sys}}\mu=10^{-5}. The gain is

Qμ=1−(1−10−6)e−10−5≃1.10×10−5.\begin{aligned} Q_\mu &= 1-(1-10^{-6})e^{-10^{-5}} \\ &\simeq 1.10\times10^{-5}. \end{aligned}

The error numerator is

EμQμ≃12(10−6)+0.015(1−e−10−5)≃6.50×10−7.\begin{aligned} E_\mu Q_\mu &\simeq \frac12(10^{-6}) \\ &\quad+ 0.015(1-e^{-10^{-5}}) \\ &\simeq 6.50\times10^{-7}. \end{aligned}

Thus Eμ≃0.0591E_\mu\simeq0.0591, or 5.91%5.91\%. Approximately Y0/Qμ≃0.0909Y_0/Q_\mu\simeq0.0909 of clicks are background clicks. They contribute disproportionately to the errors because half are wrong on average.

For a phase-randomized coherent source with μ=0.5\mu=0.5, calculate the vacuum, single-photon, and multiphoton probabilities. Explain why lowering μ\mu alone does not solve long-distance QKD.

Solution

The probabilities are

P0=e−0.5≃0.6065,P_0 = e^{-0.5} \simeq 0.6065, P1=0.5e−0.5≃0.3033,P_1 = 0.5e^{-0.5} \simeq 0.3033,

and

P≥2=1−P0−P1≃0.0902.\begin{aligned} P_{\geq2} &= 1-P_0-P_1 \\ &\simeq 0.0902. \end{aligned}

Reducing μ\mu suppresses multiphoton pulses, but it also suppresses useful single-photon detections. At long distance, background clicks then dominate sooner. Decoy states estimate the single-photon contribution without requiring the signal intensity to approach zero.

A direct pure-loss channel has η=10−4\eta=10^{-4}. Evaluate the PLOB capacity bound exactly to leading numerical precision and with its high-loss approximation. How many secret bits per second would the bound permit at one billion independently counted modes per second?

Solution

The exact expression is

−log⁡2(1−10−4)≃1.44277×10−4-\log_2(1-10^{-4}) \simeq 1.44277\times10^{-4}

bits per mode. The approximation is

10−4ln⁡2≃1.44270×10−4,\frac{10^{-4}}{\ln2} \simeq 1.44270\times10^{-4},

which is already very close. At 10910^9 modes per second, the upper bound is approximately

1.44×105 bit/s.1.44\times10^5 \ \mathrm{bit/s}.

This multiplication is valid only if the billion modes are the independent channel uses counted by the capacity theorem. A source clock alone does not settle that accounting for a multimode protocol.

The 2022 device-independent experiment produced 95,62895{,}628 secret bits in eight hours from 1.51.5 million Bell pairs. Compute the average secret-bit rate and secret bits per Bell pair. Why are neither quantities a universal device-independent QKD efficiency?

Solution

Eight hours is 28,80028{,}800 seconds, so

95,62828,800≃3.32 bit/s.\frac{95{,}628}{28{,}800} \simeq 3.32\ \mathrm{bit/s}.

The secret yield per generated Bell pair is

95,6281.5×106≃0.0638.\frac{95{,}628}{1.5\times10^6} \simeq 0.0638.

Both values depend on the source cycle, heralding, detector efficiency, basis choices, finite-key proof, observed Bell violation, security parameters, and which generated or attempted events enter the denominator. They characterize this experiment under its accounting rules, not every device-independent protocol.

Archived clinical records must remain confidential for 18 years. Replacing the vulnerable public-key infrastructure is expected to take six years. An organization uses a 20-year CRQC planning horizon. Apply the migration inequality and explain what it does and does not conclude.

Solution

Here

Tmigrate+Tsecret=6+18=24 years,T_{\mathrm{migrate}} + T_{\mathrm{secret}} = 6+18 = 24\ \mathrm{years},

which exceeds the 2020-year planning horizon. Under the organization’s chosen horizon, captured records could remain valuable when the modeled capability arrives, so migration should already be treated as exposure reduction.

The calculation does not predict that a CRQC will exist in 20 years, assign a probability to that event, or prove that every captured session is decryptable. It combines an explicit planning assumption with known data and migration lifetimes.

A protocol negotiates either ECDH alone or ECDH plus ML-KEM. Its Finished message authenticates the public keys but not the suite identifier or the ML-KEM ciphertext. Identify two attacks or ambiguities and state the repair.

Solution

Because the suite identifier is unauthenticated, an active attacker may alter negotiation and attempt to force the ECDH-only mode. Because the ML-KEM ciphertext is outside transcript authentication, the parties may derive keys from different encapsulations or expose malformed-ciphertext and identity- binding ambiguities.

The authenticated transcript and KDF context should include the roles, offered and selected suites, traditional public shares, ML-KEM public key and ciphertext, nonces, identities, and protocol version. The hybrid combiner and failure behavior must then be analyzed for that complete protocol.

Using only the rounded headlines, estimate physical qubit-hours for the 2021 RSA-2048 point and the upper corner of the 2025 claim. Why does the result not show that the estimates have equal physical difficulty?

Solution

For 2021,

(20×106)(8)=1.6×108(20\times10^6)(8) = 1.6\times10^8

physical qubit-hours. One million qubits for one week would give

(106)(7×24)=1.68×108(10^6)(7\times24) = 1.68\times10^8

physical qubit-hours. Because the 2025 statement is fewer than one million and less than one week, this is only an upper-corner proxy.

Similar rounded qubit-hours do not align logical circuit, error allocation, code layout, storage method, factory throughput, reaction latency, routing, decoder work, power, cooling, or control complexity. Space–time volume is one useful ledger entry, not a complete hardware equivalence.

A company must protect a software update channel for ten million intermittently connected devices and a continuously staffed fiber link between two data centers. Which roles could post-quantum signatures, a post-quantum KEM, and QKD reasonably play?

Solution

The device fleet needs scalable artifact authentication that works while devices are offline. A post-quantum signature, protected vendor signing key, compatible bootloader, update metadata, rollback control, and revocation or renewal plan address that role. QKD cannot distribute a publicly verifiable software signature to disconnected devices.

The data-center session can use a standardized KEM plus post-quantum authentication, possibly in an analyzed hybrid during transition. If the fiber route, operational budget, threat model, and required fresh-key rate justify dedicated optical equipment, QKD could additionally feed key material to that link. It would still require authenticated bootstrap, endpoint security, a failure policy, and ordinary symmetric data protection.

  • C. H. Bennett and G. Brassard, “Quantum cryptography: Public key distribution and coin tossing,” Theoretical Computer Science 560, 7–11, 2014, reprint of the 1984 proceedings paper, doi:10.1016/j.tcs.2014.05.025.
  • A. K. Ekert, “Quantum cryptography based on Bell’s theorem,” Physical Review Letters 67, 661–663, 1991, doi:10.1103/PhysRevLett.67.661.
  • P. W. Shor and J. Preskill, “Simple proof of security of the BB84 quantum key distribution protocol,” Physical Review Letters 85, 441–444, 2000, doi:10.1103/PhysRevLett.85.441.
  • H.-K. Lo, X. Ma, and K. Chen, “Decoy state quantum key distribution,” Physical Review Letters 94, 230504, 2005, doi:10.1103/PhysRevLett.94.230504.
  • X. Ma, B. Qi, Y. Zhao, and H.-K. Lo, “Practical decoy state for quantum key distribution,” Physical Review A 72, 012326, 2005, doi:10.1103/PhysRevA.72.012326.
  • A. Boaron et al., “Secure quantum key distribution over 421 km of optical fiber,” Physical Review Letters 121, 190502, 2018, doi:10.1103/PhysRevLett.121.190502.
  • S. Pirandola, R. Laurenza, C. Ottaviani, and L. Banchi, “Fundamental limits of repeaterless quantum communications,” Nature Communications 8, 15043, 2017, doi:10.1038/ncomms15043.
  • F. Xu, X. Ma, Q. Zhang, H.-K. Lo, and J.-W. Pan, “Secure quantum key distribution with realistic devices,” Reviews of Modern Physics 92, 025002, 2020, doi:10.1103/RevModPhys.92.025002.
  • J. Yin et al., “Entanglement-based secure quantum cryptography over 1,120 kilometres,” Nature 582, 501–505, 2020, doi:10.1038/s41586-020-2401-y.
  • D. Nadlinger et al., “Experimental quantum key distribution certified by Bell’s theorem,” Nature 607, 682–686, 2022, doi:10.1038/s41586-022-04941-5.
  • W.-Z. Liu et al., “Long-lived remote ion–ion entanglement for scalable quantum repeaters,” Nature 652, 51–57, 2026, doi:10.1038/s41586-026-10177-4.
  • Y.-A. Chen et al., “An integrated space-to-ground quantum communication network over 4,600 kilometres,” Nature 589, 214–219, 2021, doi:10.1038/s41586-020-03093-8.
  • M. Pittaluga et al., “A 20-client chip-based quantum communication network,” Nature 651, 68–75, 2026, doi:10.1038/s41586-026-10152-z.
  • C. Portmann and R. Renner, “Security in quantum cryptography,” Reviews of Modern Physics 94, 025008, 2022, doi:10.1103/RevModPhys.94.025008.
  • National Institute of Standards and Technology, Module-Lattice-Based Key-Encapsulation Mechanism Standard, FIPS 203, 2024, doi:10.6028/NIST.FIPS.203.
  • National Institute of Standards and Technology, Module-Lattice-Based Digital Signature Standard, FIPS 204, 2024, doi:10.6028/NIST.FIPS.204.
  • National Institute of Standards and Technology, Stateless Hash-Based Digital Signature Standard, FIPS 205, 2024, doi:10.6028/NIST.FIPS.205.
  • National Institute of Standards and Technology, Recommendations for Key-Encapsulation Mechanisms, SP 800-227, 2025, doi:10.6028/NIST.SP.800-227.
  • National Institute of Standards and Technology, Transition to Post-Quantum Cryptography Standards, IR 8547 initial public draft, 2024, doi:10.6028/NIST.IR.8547.ipd.
  • National Institute of Standards and Technology, Considerations for Achieving Cryptographic Agility: Strategies and Practices, Cybersecurity White Paper 39 update 1, 2026, doi:10.6028/NIST.CSWP.39-upd1.
  • D. Driscoll et al., “Terminology for Post-Quantum Traditional Hybrid Schemes,” RFC 9794, 2025, doi:10.17487/RFC9794.
  • M. Campagna et al., “Post-Quantum Cryptography for Engineers,” RFC 9958, 2026, doi:10.17487/RFC9958.
  • P. W. Shor, “Polynomial-time algorithms for prime factorization and discrete logarithms on a quantum computer,” SIAM Journal on Computing 26, 1484–1509, 1997, doi:10.1137/S0097539795293172.
  • M. Roetteler, M. Naehrig, K. M. Svore, and K. Lauter, “Quantum resource estimates for computing elliptic curve discrete logarithms,” in Advances in Cryptology – ASIACRYPT 2017, 241–270, 2017, doi:10.1007/978-3-319-70697-9_9.
  • C. Gidney and M. Ekerå, “How to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubits,” Quantum 5, 433, 2021, doi:10.22331/q-2021-04-15-433.
  • C. Gidney, “How to factor 2048 bit RSA integers with less than a million noisy qubits,” research preprint, 2025, doi:10.48550/arXiv.2505.15917.
  • International Telecommunication Union, Security Framework for Quantum Key Distribution Networks, ITU-T Recommendation X.1711, 2021, official recommendation.