Cryptography Case Studies
Short Definition
Section titled “Short Definition”A cryptography case study follows a security objective through its threat model, protocol, physical or computational assumptions, implementation, operational environment, and migration plan. It asks not merely whether a primitive is quantum, post-quantum, or asymptotically secure, but which security service is obtained, against which adversary, at what rate and cost, and under which trust assumptions.
This page examines four connected cases:
- BB84-style quantum key distribution over a realistic lossy optical link;
- entanglement-based QKD from metropolitan experiments to satellite and device-independent demonstrations;
- the interface between standardized post-quantum primitives and deployed protocols;
- Shor resource estimates as inputs to migration decisions rather than forecasts of a fixed arrival date.
Quantum Key Distribution is the canonical home for composable security, finite-key distillation, authentication, and implementation attacks. Quantum Randomness owns the entropy-source, extraction, health-test, and delivered-randomness contract on which every cryptographic branch ultimately depends. Blind and Delegated Quantum Computation owns private quantum cloud computation, including simulator-based blindness, accepted-wrong-output bounds, client capability models, and the distinction between integrity and availability. Shor Algorithm owns order finding, factoring, discrete logarithms, and the detailed resource model. This page owns the end-to-end comparison of cryptographic deployment claims.
Security Question Before Technology
Section titled “Security Question Before Technology”Cryptography supplies services, not a single quantity called security. Confidentiality, peer authentication, data-origin authentication, integrity, forward secrecy, nonrepudiation, availability, and long-term artifact verification are different objectives. A key-establishment mechanism does not by itself authenticate software, and a signature scheme does not by itself hide a session.
Before selecting a technology, record:
- the assets and their required confidentiality or authenticity lifetimes;
- the endpoints, channels, operators, manufacturers, and trust roots;
- the adversary’s access during deployment and after archived data are obtained;
- whether information-theoretic, computational, or implementation-bounded security is required;
- the tolerated outage, latency, key rate, and geographic constraints;
- the mechanism for authentication, updates, revocation, and incident recovery;
- the version of every standard, parameter set, proof, and implementation.
A useful migration inequality separates three timescales. Let be the period for which captured data must remain confidential, the time required to replace the vulnerable system, and an organization’s planning horizon for a cryptographically relevant quantum computer. Exposure becomes plausible when
This is a planning relation, not a prediction of when such a machine will exist. Different organizations can assign different horizons while agreeing on the engineering facts. It also makes the harvest-now-decrypt-later threat concrete: traffic copied today may be attacked after the endpoint has already been retired.
QKD, post-quantum key encapsulation, and post-quantum signatures occupy different layers. All three inherit endpoint, randomness, authorization, key lifecycle, implementation-assurance, and migration obligations. A QKD link also needs an authenticated classical bootstrap; it does not manufacture identity from the quantum channel.
Case Study 1: BB84 Through a Lossy Link
Section titled “Case Study 1: BB84 Through a Lossy Link”From protocol symbols to optical pulses
Section titled “From protocol symbols to optical pulses”The canonical BB84 protocol describes single qubits prepared in one of two conjugate bases. Practical fiber systems commonly use attenuated laser pulses, phase or time-bin encoding, lossy components, imperfect detectors, and a decoy-state analysis. Those substitutions are not cosmetic: a coherent optical pulse has a nonzero probability of containing more than one photon, while detector background becomes increasingly important as the signal is attenuated.
For fiber attenuation in decibels per kilometer and length , the channel transmittance is
If represents receiver optics and detector efficiency, a simple system transmittance is
This product omits effects such as dead time, afterpulsing, saturation, mode-dependent loss, and finite temporal gates. It is nevertheless a useful first audit of a claimed distance.
An ideal phase-randomized coherent pulse with mean photon number is a classical mixture of photon-number states with
Its multiphoton probability is
For , this probability is about . Treating every pulse as a single photon would therefore erase the very side channel that decoy-state BB84 is designed to bound.
Let be the background click probability per emitted pulse. In a threshold-detector model, the total signal-state gain is approximately
If random background clicks have error probability and optical misalignment gives signal error probability , then
This deliberately compact model shows the high-loss transition. The signal term falls exponentially with distance, while the background term does not. As the two become comparable, the quantum bit error rate rises even if the optics themselves have not become more misaligned.
An illustrative link budget
Section titled “An illustrative link budget”Take
The resulting raw quantities are:
| Fiber length | Channel loss | Signal-state gain | Approximate QBER |
|---|---|---|---|
These are illustrative detection and error quantities, not finite secret-key rates. A defensible rate additionally needs basis probabilities, decoy statistics, error-correction leakage, finite-size confidence intervals, authentication cost, composable security parameters, detector recovery, and the number of pulses sent.
Why decoy states matter
Section titled “Why decoy states matter”An eavesdropper can exploit photon number. In a photon-number-splitting strategy, one photon from a multiphoton pulse is retained while another continues to the receiver. The legitimate users cannot safely infer the single-photon contribution from one aggregate detection rate alone.
Decoy-State QKD is the canonical derivation of the shared-yield equations and vacuum-plus-weak bounds. Here they enter as one layer of the link-budget case study.
Decoy-state protocols randomly vary . Because Eve does not know the intensity choice before interacting with the pulse, pulses with the same photon number must have intensity-independent yields in the model. The observed gains and error rates at several intensities then constrain the single-photon gain and error rate .
A representative asymptotic lower bound for efficient decoy-state BB84 is
where is the sifting factor, is error-correction inefficiency, and
is binary entropy. The negative term pays for reconciling all detected signal pulses; the positive term extracts privacy from the estimated single-photon subset.
This equation is asymptotic and protocol-specific. It must not be silently used as a finite-key guarantee. A finite experiment replaces exact expectations by confidence regions and subtracts explicit privacy amplification, verification, smoothing, and authentication terms.
Distance records and the repeaterless bound
Section titled “Distance records and the repeaterless bound”Boaron and collaborators demonstrated secret-key generation through of ultralow-loss fiber, with secret bits per second reported at . Their system combined a three-state time-bin protocol, one-decoy estimation, low-loss components, and low-noise superconducting detectors. The result is an integrated implementation achievement, not a generic rate available on ordinary installed fiber.
For a pure-loss bosonic channel of transmittance , the Pirandola–Laurenza–Ottaviani–Banchi repeaterless secret-key capacity is
At high loss,
The resource denominator is essential. Bits per emitted pulse, detected pulse, temporal mode, wavelength mode, channel use, and second are not interchangeable. A protocol claiming to beat the direct-channel bound must count every independently used mode consistently. Twin-field QKD can change the loss scaling by introducing interference at an untrusted middle station, but it should be compared with the correctly normalized network bound rather than with an artificially narrow denominator.
Case Study 2: Entanglement-Based QKD
Section titled “Case Study 2: Entanglement-Based QKD”Entanglement does not eliminate loss
Section titled “Entanglement does not eliminate loss”In an entanglement-based protocol, a source distributes correlated systems to Alice and Bob. They measure in selected bases and use a subset of outcomes to estimate the correlations relevant to secrecy. E91 and Entanglement-Based QKD connects key establishment with a Bell test; later security proofs also relate entanglement purification and prepare-and-measure BB84.
If one usable pair is created with probability per clock cycle, a first coincidence estimate is
For a source midway between two users, both channel transmittances enter. Increasing source brightness raises the raw coincidence rate but also raises multi-pair emissions, accidental coincidences, and error. Detector dark counts and timing-window width again dominate once true coincidences become rare.
Entanglement-based does not automatically mean device-independent. Most deployed protocols trust a model of the sources or measurement devices and derive security within that model. Measurement-Device-Independent QKD removes detector trust by moving the joint measurement to an untrusted station. Device-Independent QKD instead certifies secrecy from loophole-controlled nonlocal correlations plus explicit laboratory, causal, and randomness assumptions. These are three distinct trust contracts.
Satellite distribution
Section titled “Satellite distribution”Yin and collaborators used the Micius satellite to distribute entanglement between ground stations separated by and reported a finite secret-key rate of . The architecture avoided a trusted relay holding the final key: the satellite distributed entangled photons rather than learning and forwarding an ordinary shared key.
The result does not remove all trust. The endpoints, measurement devices, randomness, classical authentication, satellite source behavior within the security model, and operational control still matter. Atmospheric windows, pointing, weather, orbital passes, and finite acquisition time also make the service model unlike a continuously available terrestrial network.
Device-independent demonstrations
Section titled “Device-independent demonstrations”Nadlinger and collaborators reported a device-independent QKD experiment that produced final secret bits from approximately million Bell pairs over eight hours. The experiment closed the detection loophole and used separated ion-trap systems with a security proof tailored to the implementation.
That achievement demonstrates complete device-independent key generation, not a metropolitan deployment rate. The average final throughput was about , and the experiment did not impose spacelike separation of the measurement events. Security therefore retained a laboratory isolation assumption preventing unauthorized information flow between devices during operation. Device independence reduces particular modeling trust; it does not mean assumption-free.
Liu and collaborators reported a second distance regime in 2026 using long-lived remote ion–ion entanglement with a telecom interface. Their proof-of-principle DIQKD application included finite-size analysis over of spooled fiber and a positive key rate beyond in the asymptotic limit. The two clauses must not be collapsed: the work did not claim a positive finite key at . It demonstrates how heralded memories can move channel loss outside the Bell trial, while low entanglement-generation probability, communication latency, and finite-block acquisition remain central rate constraints.
From Point-to-Point Links to Networks
Section titled “From Point-to-Point Links to Networks”A long-distance number is incomplete without topology. A network can extend reach by:
- trusted relays, which decrypt or reconstruct key material at intermediate protected nodes;
- untrusted optical measurements, as in measurement-device-independent and twin-field designs;
- satellite links, whose trust model depends on whether the satellite distributes entanglement or relays key;
- quantum repeaters, which aim to distribute entanglement without trusted access to the final key but remain an active engineering frontier.
Chen and collaborators integrated a terrestrial backbone with satellite QKD into a network spanning up to . It contained more than fiber QKD links and two satellite-to-ground links. This demonstrated large operational reach, key management, and heterogeneous integration. Its fiber backbone used trusted relays, so physical security of intermediate sites remained part of the end-to-end guarantee.
In 2026, an integrated-photonics twin-field QKD experiment connected 20 client chips through ten wavelength channels and demonstrated pairwise links over of spooled fiber. The reported rates surpassed the appropriately counted direct repeaterless bound. Pairwise operation was sequential, however, and the fiber was laboratory spool rather than a simultaneously loaded field network. The strongest description is therefore a scalable-component and network-architecture proof of principle.
Every QKD network report should accompany distance with:
- secret bits per second and security parameter;
- optical loss, detector characteristics, and number of modes;
- finite-key block size and acquisition time;
- simultaneous versus sequential users;
- trusted nodes and authenticated classical paths;
- field fiber versus laboratory spool;
- uptime, environmental constraints, and key-management policy;
- whether application traffic was protected and how the generated key was consumed.
Case Study 3: The Post-Quantum Protocol Interface
Section titled “Case Study 3: The Post-Quantum Protocol Interface”Primitives are not protocols
Section titled “Primitives are not protocols”Post-quantum cryptography uses classical computation and ordinary communication channels. Its security is based on computational problems for which no efficient classical or quantum attacks are known under the selected parameters and model. It can therefore be deployed in software and hardware without waiting for a quantum network.
A key-encapsulation mechanism has the abstract interface
For a valid encapsulation, except with the scheme’s specified failure probability. A KEM is not generally an encryption algorithm for an arbitrary file. A protocol derives traffic keys from , binds them to the transcript and negotiated context, and then uses authenticated symmetric encryption.
A digital-signature scheme has
Signatures authenticate protocol handshakes, certificates, software, firmware, documents, and audit artifacts. Replacing key establishment while leaving a vulnerable certificate or update-signing path intact is not a complete migration.
The standards snapshot
Section titled “The standards snapshot”NIST finalized three initial post-quantum standards in 2024:
- FIPS 203, ML-KEM, for key encapsulation;
- FIPS 204, ML-DSA, for digital signatures;
- FIPS 205, SLH-DSA, a stateless hash-based signature alternative.
ML-KEM and ML-DSA use module-lattice constructions; SLH-DSA uses hash-based trees. These labels identify algorithm families and parameter sets, not a drop-in guarantee for every protocol. Implementers must consult the current standard and its errata, validate implementations, and use the approved parameter set required by their environment. NIST SP 800-227, finalized in 2025, supplies broader recommendations for securely using KEMs.
Standardization does not freeze cryptanalysis. It creates a versioned interoperability and assurance target while analysis continues. It also does not imply that every legacy protocol can carry the new keys, ciphertexts, signatures, certificates, or handshake messages without redesign.
Bind the primitive to the session
Section titled “Bind the primitive to the session”A protocol-level key schedule should domain-separate the new secret and bind it to the parties’ negotiated transcript. Schematically,
The transcript should cover identities, roles, algorithm choices, public keys or certificates, encapsulation ciphertexts, nonces, and downgrade- relevant negotiation. Exactly which bytes are covered is a protocol specification, not an implementation preference.
The surrounding system must also handle:
- invalid-ciphertext behavior without creating a timing or error oracle;
- fresh, high-quality randomness;
- key erasure and forward-secrecy policy;
- certificate and message-size limits;
- retransmission, fragmentation, and denial-of-service exposure;
- side-channel-resistant arithmetic;
- algorithm identifiers, parameter negotiation, and rollback prevention;
- interoperability across libraries, accelerators, hardware security modules, and middleboxes.
An implementation that passes a primitive’s known-answer tests can still fail at these interfaces.
Hybrid key establishment
Section titled “Hybrid key establishment”During a transition, a protocol may combine a traditional secret and a post-quantum secret :
The intended robust property is that the session remains secure if at least one component remains secure. Concatenation followed by a KDF is not a proof of that property in every model. The combiner, authentication, key reuse, contributory behavior, failure handling, and transcript binding must be analyzed together. RFC 9794 supplies terminology for post-quantum/traditional hybrid schemes; RFC 9958 gives protocol-engineering guidance and warns that migration affects far more than primitive substitution.
Hybrid deployment has a real cost: larger handshakes, two implementations, more failure modes, and a more complicated negotiation state. It can be a sound transition tool when those costs and the combiner security are explicit. It is not automatically safer merely because two algorithms appear in the configuration.
Combining QKD and post-quantum cryptography
Section titled “Combining QKD and post-quantum cryptography”A system can also combine a QKD-derived key with a KEM-derived secret:
This can diversify assumptions, but the system inherits both infrastructures. The QKD classical channel still needs initial authentication. A post-quantum signature or pre-shared symmetric key may provide it, with a carefully defined key-refresh chain. The protocol must decide what happens when the QKD key buffer is empty, a detector alarms, the ordinary network fails, or one component rejects.
QKD does not replace digital signatures. It cannot by itself verify a software update from a vendor, establish a scalable public-key identity across disconnected parties, or preserve an artifact’s provenance after the link session ends. Conversely, a post-quantum KEM does not provide the physical-layer intrusion diagnostics or information-theoretic key agreement target of an ideal QKD construction.
Migration is an inventory problem
Section titled “Migration is an inventory problem”The first operational deliverable is a cryptographic inventory, including:
- protocols, cipher suites, certificate profiles, and key stores;
- source code, libraries, firmware, appliances, and hardware accelerators;
- keys embedded in devices with long field lifetimes;
- update-signing and code-verification roots;
- data whose confidentiality extends beyond the migration horizon;
- partner, supplier, regulatory, and archival dependencies;
- algorithm identifiers that cannot represent new schemes;
- test, rollback, telemetry, and incident-response paths.
NIST defines cryptographic agility as the ability to replace or adapt cryptographic algorithms across protocols, software, hardware, firmware, and infrastructure while preserving security and operations. Agility is not runtime negotiation of every imaginable algorithm. Unconstrained negotiation can create downgrade paths. Mature agility uses policy-controlled suites, complete transcript binding, staged rollout, observability, and an exercised retirement procedure.
NIST IR 8547 provides a transition-plan framework but, as of this review, is an initial public draft. It should be labeled as guidance under development, not cited as a final mandatory schedule. The current final FIPS documents, sector-specific rules, and an organization’s own risk analysis determine the actual migration obligation.
Case Study 4: Shor Estimates and Migration Context
Section titled “Case Study 4: Shor Estimates and Migration Context”What is directly threatened
Section titled “What is directly threatened”A sufficiently large fault-tolerant quantum computer running Shor’s algorithms would directly attack:
| Quantum problem | Representative vulnerable uses |
|---|---|
| integer factoring | RSA encryption, key transport, and signatures |
| finite-field discrete logarithm | finite-field Diffie–Hellman, DSA, and ElGamal |
| elliptic-curve discrete logarithm | ECDH, ECDSA, and related curve protocols |
This is not a direct break of AES or a cryptographic hash function. Generic quantum exhaustive search is associated with Grover’s quadratic query improvement and has a different cost model. Security categories and parameter choices should be analyzed for the actual construction rather than derived from a slogan that quantum computers halve all key lengths.
The public-key threat also separates into two timelines:
- confidentiality: copied RSA- or ECDH-protected sessions may be decrypted later, so exposure can precede a working quantum computer;
- authenticity: a future machine could forge RSA or ECDSA signatures, but an attacker generally cannot retroactively insert a forged handshake into a correctly archived past transcript.
Long-lived signed artifacts still need special treatment. Verification keys, timestamps, transparency logs, archival signatures, and renewal procedures must remain trustworthy over the artifact’s lifetime.
Resource estimates are versioned models
Section titled “Resource estimates are versioned models”Asymptotic polynomial time establishes the algorithmic threat but does not specify a machine date. A physical resource estimate composes arithmetic, logical circuit, error-correcting code, factory, routing, decoder, and timing models. Changing any layer can change the qubit and runtime headline.
Three widely cited estimates illustrate the distinction:
| Study | Target and estimate | Evidence level and boundary |
|---|---|---|
| Roetteler et al. (2017) | A 256-bit prime-field elliptic-curve discrete logarithm uses about logical qubits and Toffoli gates in the stated construction | Reversible logical circuit; no physical error-correction forecast |
| Gidney and Ekerå (2021) | RSA-2048 in about eight hours using about 20 million physical qubits | Surface-code architecture estimate with physical gate error, code cycle, nearest-neighbor grid, and explicit factories |
| Gidney (2025) | RSA-2048 in less than one week using fewer than one million noisy qubits | Research preprint using newer arithmetic, storage, and magic-state methods under related headline hardware assumptions |
The 2025 result does not show that an existing million-qubit noisy machine can factor RSA-2048. The word noisy describes physical qubits inside a modeled fault-tolerant architecture. Code distance, logical failure budget, decoder throughput, factory yield, connectivity, control, cooling, and sustained operation remain part of the machine.
Nor should the two RSA estimates be reduced to one qubit number. The 2021 point spends more qubits for a shorter runtime; the 2025 point explores a different space–time tradeoff with changed circuit techniques. A useful comparison preserves:
where records code, connectivity, arithmetic, factories, decoding, and control assumptions. A scalar such as physical qubit-hours can help expose tradeoffs, but it cannot prove architecture equivalence.
Resource Estimation Tools develops this contract in detail. The actionable cryptographic conclusion is not a countdown derived from any one estimate. It is that the vulnerable algorithms have known polynomial-time quantum attacks, migration takes years, and confidentiality lifetimes can extend beyond deployment cycles.
A decision under uncertainty
Section titled “A decision under uncertainty”An organization need not assign a precise probability distribution to before acting. It can use robust decisions:
- inventory vulnerable public-key uses and long-lived data;
- remove algorithm and certificate-format assumptions that block change;
- test standardized post-quantum suites in representative protocols;
- deploy first where harvest-now-decrypt-later exposure and replacement lead times are greatest;
- use analyzed hybrid modes where continuity or policy requires them;
- monitor standards, errata, cryptanalysis, performance, and interoperability;
- rehearse rollback and emergency algorithm retirement.
This policy remains sensible if the first cryptographically relevant machine arrives earlier than expected, much later, or not through the architecture used in today’s resource estimates.
Choosing a Cryptographic Portfolio
Section titled “Choosing a Cryptographic Portfolio”| Mechanism | Primary service | Main assumptions | Deployment constraint |
|---|---|---|---|
| post-quantum KEM | session-key establishment | hardness of selected problem, correct implementation, authenticated protocol | software, protocol, certificate, and performance migration |
| post-quantum signature | identity and artifact authentication | unforgeability of selected scheme, protected signing key, trustworthy PKI | key and signature sizes, verification ecosystem, archival policy |
| point-to-point QKD | shared fresh key material | quantum model, authenticated classical channel, trusted endpoints and implementation | dedicated optical path, distance, loss, detectors, key rate |
| trusted-relay QKD network | extended key reach | every relay is physically and operationally trusted | protected sites and end-to-end key management |
| device-independent QKD | key with reduced device-model trust | valid Bell-test assumptions, isolation, randomness, finite statistics | very demanding loss, rate, and laboratory control |
| symmetric cryptography | bulk data protection and authentication | secret keys, sound construction, adequate parameters | secure key establishment, rotation, storage, and nonce discipline |
These mechanisms are complements in many systems. A common architecture uses a KEM and signatures to authenticate and establish a session, a symmetric authenticated-encryption scheme for data, and possibly QKD to refresh key material on selected high-value links. The security argument must cover the composition, not award the whole system the strongest adjective attached to one component.
Common Mistakes
Section titled “Common Mistakes”- Calling QKD quantum encryption when the protocol actually distributes key.
- Reporting fiber distance without attenuation, secret-key rate, finite-key block, security parameter, or trusted-node topology.
- Treating an attenuated laser pulse as a deterministic single photon.
- Quoting an asymptotic decoy-state rate as a finite experimental guarantee.
- Equating entanglement-based, measurement-device-independent, and device-independent QKD.
- Saying device-independent means assumption-free.
- Claiming a trusted-relay network offers end-to-end security independent of relay compromise.
- Comparing a multimode protocol with a single-mode capacity bound.
- Treating a KEM as arbitrary public-key encryption.
- Replacing a KEM but retaining vulnerable handshake signatures or update-signing keys.
- Concatenating secrets and calling the result a proven robust hybrid without specifying the combiner and transcript.
- Allowing fallback or algorithm negotiation outside authenticated transcript coverage.
- Assuming QKD replaces signatures, PKI, access control, endpoint security, or incident response.
- Presenting a NIST draft as a final standard.
- Quoting physical qubits without runtime, physical error, code cycle, connectivity, code, factory, and failure assumptions.
- Treating a resource estimate as a forecast or a small factoring demonstration as a cryptographic break.
- Saying Shor directly breaks AES or all cryptography.
A Reproducible Cryptography Report
Section titled “A Reproducible Cryptography Report”For a QKD result, report:
- protocol variant, security definition, proof source, and security parameter;
- source, encoding, decoy intensities, basis probabilities, and clock rate;
- optical loss and mode count from transmitter to detector;
- detector efficiency, background, timing window, dead time, and saturation;
- sifted, reconciled, and final secret-key rates;
- finite-key block size, acquisition time, and statistical method;
- authentication method and net key consumption;
- device assumptions, trusted nodes, topology, and user concurrency;
- application key-use policy and behavior during link failure;
- field conditions, uptime, calibration, and independently reproduced components.
For a post-quantum migration result, report:
- exact standard, parameter set, errata state, and implementation version;
- protocol binding, transcript coverage, authentication, and key schedule;
- handshake bytes, latency, CPU time, memory, and energy on target devices;
- failure and side-channel behavior;
- certificates, HSMs, firmware, middleboxes, APIs, and partner dependencies;
- hybrid combiner and downgrade analysis, if used;
- interoperability and negative tests;
- rollback, observability, key lifecycle, and retirement policy.
For a Shor resource claim, report the target problem and parameter, logical circuit, non-Clifford cost, logical qubits, error-correcting code, physical error and cycle time, connectivity, factories, decoder, total failure budget, wall time, physical qubits, and publication version. Label theorem, experiment, simulation, estimate, and forecast separately.
Current Evidence
Section titled “Current Evidence”Several conclusions are well established:
- ideal QKD protocols admit rigorous security proofs, including composable formulations, under explicit models;
- real optical loss, finite statistics, source imperfections, detector behavior, authentication, and endpoints determine deployed security;
- decoy-state and entanglement-based systems have generated secret key over hundreds of kilometers of fiber and satellite-scale free-space links;
- trusted-relay QKD networks can operate over continental reach, while repeaterless untrusted reach remains rate-limited;
- device-independent QKD has crossed from a proof proposal to complete laboratory key generation and a finite-size proof-of-principle, but remains demanding in rate, isolation, and block acquisition;
- standardized post-quantum KEM and signature primitives now support concrete migration work on ordinary infrastructure;
- factoring and discrete logarithms have polynomial-time fault-tolerant quantum algorithms, while cryptographically relevant physical resources remain architecture-dependent estimates rather than demonstrated machines.
Open engineering and research questions include scalable untrusted quantum networking, high-rate device-independent protocols, implementation assurance, side-channel-resistant post-quantum deployments, robust hybrid composition, cryptographic agility across long-lived infrastructure, and tighter fault-tolerant resource estimates tied to experimentally credible hardware models.
Exercises
Section titled “Exercises”1. Loss and background crossover
Section titled “1. Loss and background crossover”Using the illustrative BB84 parameters above, verify the gain and QBER. What fraction of all clicks is due to the background model?
Solution
At ,
Therefore
and . The gain is
The error numerator is
Thus , or . Approximately of clicks are background clicks. They contribute disproportionately to the errors because half are wrong on average.
2. Multiphoton exposure
Section titled “2. Multiphoton exposure”For a phase-randomized coherent source with , calculate the vacuum, single-photon, and multiphoton probabilities. Explain why lowering alone does not solve long-distance QKD.
Solution
The probabilities are
and
Reducing suppresses multiphoton pulses, but it also suppresses useful single-photon detections. At long distance, background clicks then dominate sooner. Decoy states estimate the single-photon contribution without requiring the signal intensity to approach zero.
3. Repeaterless capacity
Section titled “3. Repeaterless capacity”A direct pure-loss channel has . Evaluate the PLOB capacity bound exactly to leading numerical precision and with its high-loss approximation. How many secret bits per second would the bound permit at one billion independently counted modes per second?
Solution
The exact expression is
bits per mode. The approximation is
which is already very close. At modes per second, the upper bound is approximately
This multiplication is valid only if the billion modes are the independent channel uses counted by the capacity theorem. A source clock alone does not settle that accounting for a multimode protocol.
4. Device-independent throughput
Section titled “4. Device-independent throughput”The 2022 device-independent experiment produced secret bits in eight hours from million Bell pairs. Compute the average secret-bit rate and secret bits per Bell pair. Why are neither quantities a universal device-independent QKD efficiency?
Solution
Eight hours is seconds, so
The secret yield per generated Bell pair is
Both values depend on the source cycle, heralding, detector efficiency, basis choices, finite-key proof, observed Bell violation, security parameters, and which generated or attempted events enter the denominator. They characterize this experiment under its accounting rules, not every device-independent protocol.
5. A migration inequality
Section titled “5. A migration inequality”Archived clinical records must remain confidential for 18 years. Replacing the vulnerable public-key infrastructure is expected to take six years. An organization uses a 20-year CRQC planning horizon. Apply the migration inequality and explain what it does and does not conclude.
Solution
Here
which exceeds the -year planning horizon. Under the organization’s chosen horizon, captured records could remain valuable when the modeled capability arrives, so migration should already be treated as exposure reduction.
The calculation does not predict that a CRQC will exist in 20 years, assign a probability to that event, or prove that every captured session is decryptable. It combines an explicit planning assumption with known data and migration lifetimes.
6. Audit a hybrid handshake
Section titled “6. Audit a hybrid handshake”A protocol negotiates either ECDH alone or ECDH plus ML-KEM. Its Finished message authenticates the public keys but not the suite identifier or the ML-KEM ciphertext. Identify two attacks or ambiguities and state the repair.
Solution
Because the suite identifier is unauthenticated, an active attacker may alter negotiation and attempt to force the ECDH-only mode. Because the ML-KEM ciphertext is outside transcript authentication, the parties may derive keys from different encapsulations or expose malformed-ciphertext and identity- binding ambiguities.
The authenticated transcript and KDF context should include the roles, offered and selected suites, traditional public shares, ML-KEM public key and ciphertext, nonces, identities, and protocol version. The hybrid combiner and failure behavior must then be analyzed for that complete protocol.
7. Compare resource headlines cautiously
Section titled “7. Compare resource headlines cautiously”Using only the rounded headlines, estimate physical qubit-hours for the 2021 RSA-2048 point and the upper corner of the 2025 claim. Why does the result not show that the estimates have equal physical difficulty?
Solution
For 2021,
physical qubit-hours. One million qubits for one week would give
physical qubit-hours. Because the 2025 statement is fewer than one million and less than one week, this is only an upper-corner proxy.
Similar rounded qubit-hours do not align logical circuit, error allocation, code layout, storage method, factory throughput, reaction latency, routing, decoder work, power, cooling, or control complexity. Space–time volume is one useful ledger entry, not a complete hardware equivalence.
8. Select a portfolio
Section titled “8. Select a portfolio”A company must protect a software update channel for ten million intermittently connected devices and a continuously staffed fiber link between two data centers. Which roles could post-quantum signatures, a post-quantum KEM, and QKD reasonably play?
Solution
The device fleet needs scalable artifact authentication that works while devices are offline. A post-quantum signature, protected vendor signing key, compatible bootloader, update metadata, rollback control, and revocation or renewal plan address that role. QKD cannot distribute a publicly verifiable software signature to disconnected devices.
The data-center session can use a standardized KEM plus post-quantum authentication, possibly in an analyzed hybrid during transition. If the fiber route, operational budget, threat model, and required fresh-key rate justify dedicated optical equipment, QKD could additionally feed key material to that link. It would still require authenticated bootstrap, endpoint security, a failure policy, and ordinary symmetric data protection.
References
Section titled “References”- C. H. Bennett and G. Brassard, “Quantum cryptography: Public key distribution and coin tossing,” Theoretical Computer Science 560, 7–11, 2014, reprint of the 1984 proceedings paper, doi:10.1016/j.tcs.2014.05.025.
- A. K. Ekert, “Quantum cryptography based on Bell’s theorem,” Physical Review Letters 67, 661–663, 1991, doi:10.1103/PhysRevLett.67.661.
- P. W. Shor and J. Preskill, “Simple proof of security of the BB84 quantum key distribution protocol,” Physical Review Letters 85, 441–444, 2000, doi:10.1103/PhysRevLett.85.441.
- H.-K. Lo, X. Ma, and K. Chen, “Decoy state quantum key distribution,” Physical Review Letters 94, 230504, 2005, doi:10.1103/PhysRevLett.94.230504.
- X. Ma, B. Qi, Y. Zhao, and H.-K. Lo, “Practical decoy state for quantum key distribution,” Physical Review A 72, 012326, 2005, doi:10.1103/PhysRevA.72.012326.
- A. Boaron et al., “Secure quantum key distribution over 421 km of optical fiber,” Physical Review Letters 121, 190502, 2018, doi:10.1103/PhysRevLett.121.190502.
- S. Pirandola, R. Laurenza, C. Ottaviani, and L. Banchi, “Fundamental limits of repeaterless quantum communications,” Nature Communications 8, 15043, 2017, doi:10.1038/ncomms15043.
- F. Xu, X. Ma, Q. Zhang, H.-K. Lo, and J.-W. Pan, “Secure quantum key distribution with realistic devices,” Reviews of Modern Physics 92, 025002, 2020, doi:10.1103/RevModPhys.92.025002.
- J. Yin et al., “Entanglement-based secure quantum cryptography over 1,120 kilometres,” Nature 582, 501–505, 2020, doi:10.1038/s41586-020-2401-y.
- D. Nadlinger et al., “Experimental quantum key distribution certified by Bell’s theorem,” Nature 607, 682–686, 2022, doi:10.1038/s41586-022-04941-5.
- W.-Z. Liu et al., “Long-lived remote ion–ion entanglement for scalable quantum repeaters,” Nature 652, 51–57, 2026, doi:10.1038/s41586-026-10177-4.
- Y.-A. Chen et al., “An integrated space-to-ground quantum communication network over 4,600 kilometres,” Nature 589, 214–219, 2021, doi:10.1038/s41586-020-03093-8.
- M. Pittaluga et al., “A 20-client chip-based quantum communication network,” Nature 651, 68–75, 2026, doi:10.1038/s41586-026-10152-z.
- C. Portmann and R. Renner, “Security in quantum cryptography,” Reviews of Modern Physics 94, 025008, 2022, doi:10.1103/RevModPhys.94.025008.
- National Institute of Standards and Technology, Module-Lattice-Based Key-Encapsulation Mechanism Standard, FIPS 203, 2024, doi:10.6028/NIST.FIPS.203.
- National Institute of Standards and Technology, Module-Lattice-Based Digital Signature Standard, FIPS 204, 2024, doi:10.6028/NIST.FIPS.204.
- National Institute of Standards and Technology, Stateless Hash-Based Digital Signature Standard, FIPS 205, 2024, doi:10.6028/NIST.FIPS.205.
- National Institute of Standards and Technology, Recommendations for Key-Encapsulation Mechanisms, SP 800-227, 2025, doi:10.6028/NIST.SP.800-227.
- National Institute of Standards and Technology, Transition to Post-Quantum Cryptography Standards, IR 8547 initial public draft, 2024, doi:10.6028/NIST.IR.8547.ipd.
- National Institute of Standards and Technology, Considerations for Achieving Cryptographic Agility: Strategies and Practices, Cybersecurity White Paper 39 update 1, 2026, doi:10.6028/NIST.CSWP.39-upd1.
- D. Driscoll et al., “Terminology for Post-Quantum Traditional Hybrid Schemes,” RFC 9794, 2025, doi:10.17487/RFC9794.
- M. Campagna et al., “Post-Quantum Cryptography for Engineers,” RFC 9958, 2026, doi:10.17487/RFC9958.
- P. W. Shor, “Polynomial-time algorithms for prime factorization and discrete logarithms on a quantum computer,” SIAM Journal on Computing 26, 1484–1509, 1997, doi:10.1137/S0097539795293172.
- M. Roetteler, M. Naehrig, K. M. Svore, and K. Lauter, “Quantum resource estimates for computing elliptic curve discrete logarithms,” in Advances in Cryptology – ASIACRYPT 2017, 241–270, 2017, doi:10.1007/978-3-319-70697-9_9.
- C. Gidney and M. Ekerå, “How to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubits,” Quantum 5, 433, 2021, doi:10.22331/q-2021-04-15-433.
- C. Gidney, “How to factor 2048 bit RSA integers with less than a million noisy qubits,” research preprint, 2025, doi:10.48550/arXiv.2505.15917.
- International Telecommunication Union, Security Framework for Quantum Key Distribution Networks, ITU-T Recommendation X.1711, 2021, official recommendation.