Source-linked AI summary
Using quantum key distribution for cryptographic purposes: a survey
Romain Alléaume, Cyril Branciard, Jan Bouda, Thierry Debuisschert, Mehrdad Dianati, Nicolas Gisin, Mark Godfrey, Philippe Grangier, Thomas Langer, Norbert Lutkenhaus, Christian Monyk, Philippe Painchault, Momtchil Peev, Andreas Poppe, Thomas Pornin, John Rarity, Renato Renner, Gregoire Ribordy, Michel Riguidel, Louis Salvail, Andrew Shields, Harald Weinfurter, Anton Zeilinger
TL;DR
QKD offers provable information-theoretic security for established keys, but its practical value depends on how those keys support subsequent cryptographic applications. This survey compares key-establishment methods and examines QKD for point-to-point key renewal and multi-user network services, while identifying operational constraints and technology challenges.
Problem
QKD does not provide a standalone security service, so its integration requires analysis of how established keys combine with applications having different requirements and security properties.
Method
The survey reviews key-establishment techniques and studies QKD in point-to-point link encryption, multi-user networks, and practical implementation contexts.
Results
QKD links can exchange up to 1 Mbits of secret key per second over 20 km, while successive keys provide forward secrecy against compromise of a single key.
Takeaways & Limitations
The most interesting uses arise when QKD’s long-term confidentiality provides a security advantage otherwise unattainable, particularly with one-time-pad encryption.
Takeaways & Limitations
QKD security proofs depend on assumptions, and practical systems remain exposed to implementation issues such as attacks on calibration procedures.
Abstract
from arXiv · showhide
The appealing feature of quantum key distribution (QKD), from a cryptographic viewpoint, is the ability to prove the information-theoretic security (ITS) of the established keys. As a key establishment primitive, QKD however does not provide a standalone security service in its own: the secret keys established by QKD are in general then used by a subsequent cryptographic applications for which the requirements, the context of use and the security properties can vary. It is therefore important, in the perspective of integrating QKD in security infrastructures, to analyze how QKD can be combined with other cryptographic primitives. The purpose of this survey article, which is mostly centered on European research results, is to contribute to such an analysis. We first review and compare the properties of the existing key establishment techniques, QKD being one of them. We then study more specifically two generic scenarios related to the practical use of QKD in cryptographic infrastructures: 1) using QKD as a key renewal technique for a symmetric cipher over a point-to-point link; 2) using QKD in a network containing many users with the objective of offering any-to-any key establishment service. We discuss the constraints as well as the potential interest of using QKD in these contexts. We finally give an overview of challenges relative to the development of QKD technology that also constitute potential avenues for cryptographic research.
1. Introduction
QKD’s practical cryptographic usefulness remains debated, motivating a review that examines how it complements classical primitives across link and network settings.
- QKD’s role in practical cryptography is debated despite rapid progress and movement toward pre-competitive research and commercial products.
- Assessing QKD’s implications requires expertise spanning classical cryptography, quantum mechanics, and network security.
- The review identifies contexts where QKD can be useful alongside established classical cryptographic primitives.
- The analysis covers secret key agreement, secure payload transmission over point-to-point links, and network-wide key agreement.
- The paper surveys key-agreement techniques, evaluates QKD-based link encryption, and examines QKD networks and their cryptographic operation.
2. Secret key agreement
Modern cryptography relies on secret keys rather than obscurity, making secure key agreement central; the paper compares five method families and hybrid combinations under different security models.
- Modern cryptographic systems publicly announce algorithms while relying on secret keys to protect data.
- Secret key agreement distributes keys among legitimate users while protecting them from potential opponents.
- Five method families address distant-user key agreement: classical ITS, computational public-key, computational symmetric-key, QKD, and trusted couriers.
- The survey compares the security types each family provides and considers hybrid schemes combining multiple methods.
- Information-theoretic security derives purely from information theory and remains secure against adversaries with unbounded computing power.
2.2 Classical public-key cryptography and secret key agreement
Classical public-key cryptography enables key agreement over open channels, but its security depends on unproven computational assumptions and its performance is constrained by costly asymmetric operations.
- Classical information-theoretic key agreement uses channel coding to tolerate transmission errors while limiting information leakage to eavesdroppers.
- Classical ITS key-agreement schemes require additional assumptions, such as bounded adversary storage, to restrict the eavesdropper’s power.
- Public-key cryptography supports encryption and key-pair operations in which public keys encrypt messages and private keys enable decryption.
- Diffie-Hellman establishes a shared secret over an unprotected classical channel without a prior shared secret, but requires additional authentication.
- Public-key security relies on the presumed computational difficulty of problems such as discrete logarithms and integer factorization, rather than unconditional security.
2.3 Classical computationally secure symmetric-key cryptography and secret key agreement
Computational public-key cryptography is unsuitable for bulk data encryption because asymmetric operations are costly, so it is mainly used for initial session-key agreement.
- RSA-based key exchange takes roughly 10 ms on a 2.93 GHz Intel Pentium IV for one encryption and decryption.
- Dedicated coprocessors can make RSA exchange approximately ten times faster, while smart-card coprocessors can make it ten times slower.
- Elliptic-curve schemes use shorter keys but provide only slightly better speed performance than RSA-based protocols.
- Public-key cryptography is too slow for network communication encryption and is commonly limited to initial secret session-key agreement.
2.3. Classical computationally secure symmetric-key cryptography and secret key agreement
Classical symmetric-key cryptography can support secret key agreement when Alice and Bob initially share a small secret, but this provides key expansion rather than unconditional key establishment. Its security depends on computational assumptions, while quantum attacks require larger keys to preserve comparable search complexity.
- Symmetric-key cryptography uses a shared secret key and includes block and stream ciphers, with AES as a standardized block cipher.
- A symmetric encryption scheme combined with symmetric authentication can establish keys when Alice and Bob initially share a small secret key.
- Classical symmetric-key schemes cannot provide unconditionally secure key expansion from a shorter shared key, because Shannon’s result requires encryption-key entropy at least as large as message entropy.
- Their practical security instead depends on the underlying computationally secure primitives and their composability.
- Doubling the key size preserves today’s classical security level against quantum computers because Grover’s algorithm offers only a polynomial search reduction.
- 128-bit AES encryptors can operate at Gbit/s rates, explaining the widespread preference for symmetric schemes in deployed networks.
- Under exhaustive-search assumptions, a 103-bit symmetric key is roughly comparable in computational requirements to a 2048-bit RSA modulus.
2.4. Quantum key agreement - quantum key distribution (QKD)
QKD uses quantum physics to establish keys with information-theoretic security, while practical deployment depends on authenticated classical communication and assumptions about physics, laboratories, and implementations. Modern security proofs use composable criteria and finite-signal information measures, and QKD can remain secure against quantum computers.
- QKD is a quantum cryptographic alternative for secret key agreement whose security has been proven independent of the adversary’s computing power.
- QKD can provide unconditional security against quantum computers without requiring legitimate users to possess quantum computers themselves.
- QKD security proofs exploit the impossibility of learning information about non-orthogonal quantum states without perturbing them.
- Recent proof techniques use composable security criteria and smooth min- and max-entropies, supporting operational analysis with a finite number of signals.
- A practical QKD link connects Alice and Bob through quantum and classical channels: encoded quantum states are measured, then classical data are tested for correlations.
- Strong quantum-channel perturbation above the security threshold can disrupt key generation and enable denial-of-service attacks.
- Information-theoretically secure QKD requires an authenticated classical channel, which can use universal-hashing message authentication with a short pre-shared secret key.
- Using non-information-theoretic authentication can yield everlasting security rather than strict unconditional security.
2.5 Trusted couriers key distribution (TCKD)
The supplied passages connect QKD security to device-independent protocols and to assumptions about trusted implementations, but do not describe trusted-courier key distribution itself.
- Device-independent QKD protocols can prove unconditional security independently of Alice and Bob’s hardware implementation.
- QKD security formally relies on assumptions including trustworthy implementations, although device-independent QKD can relax the hardware-trust assumption.
2.5. Trusted couriers key distribution (TCKD)
Trusted courier key distribution relies on physically securing key transport between legitimate users, offering practical rather than information-theoretic security and becoming costly at large scale. It resembles QKD in several operational respects but differs from it in important ways.
- A trusted courier physically transports secret keys between legitimate users, relying on practical security measures against interception or corruption.
- Trusted couriers become costly and impractical when deployed across large systems.
- TCKD, like QKD, relies on the physical security of the Alice–Bob communication line and is sensitive to distance and line conditions.
- TCKD can serve as a secret key agreement protocol and requires initial trust in Alice’s and Bob’s identities.
- That initial authentication trust may be established through a pre-distributed secret such as a password or an identity certificate issued by a trusted third party.
- TCKD is applied where classical secret key agreement schemes are considered insufficiently secure.
- Despite these similarities, the paper identifies important differences between QKD and TCKD.
2.6 Cascaded schemes and dual key agreement
QKD networks are presented as more reliable, automatable, and cost-effective than trusted-courier infrastructures, while trusted couriers retain advantages in distance and rate. QKD networks may also overcome point-to-point distance limits and provide on-demand key distribution.
- QKD networks are expected to improve reliability, automation, cost effectiveness, and key-management efficiency.
- Trusted couriers are not intrinsically limited in distance or rate because portable classical memories can store gigabytes of key data.
- QKD networks could extend beyond point-to-point link distance limits and distribute secret keys on demand to end users.
2.6. Cascaded schemes and dual key agreement
The paper describes dual secret key agreement as combining independently established keys through XOR, including combinations of QKD and classical schemes. This composition can preserve at least the security of the classical scheme and support certification under existing classical standards.
- Cascaded schemes: Cascaded ciphers sequentially apply multiple encryption primitives, with the first layer directly applied to the message being the most important.
- Dual secret key agreement: Dual secret key agreement establishes two equal-length keys through separate schemes and XORs them to obtain the final key.
- Dual secret key agreement: Combining RSA-based and QKD-based keys means compromising the entire agreement requires breaking both key-establishment schemes.
- Dual secret key agreement: Dual secret key agreement can preserve security at least at the level of the classical scheme and enable certification under existing classical criteria.
3. Securing a point-to-point classical communication link by combining QKD with symmetric encryption
This section examines how QKD-generated keys can secure classical point-to-point links when combined with symmetric encryption, authentication, or one-time-pad encryption. It weighs performance, long-term and forward secrecy, key-renewal benefits, and assumptions limiting those benefits.
- Link-encryption scenario: QKD-generated keys support secure classical-link transmission when combined with symmetric encryption and authentication, using initially shared authentication keys.The generic protocol establishes KS = Kencrypt · Kauth, then encrypts and authenticates payload M over the classical channel.
- Performance of QKD link devices: QKD links can currently exchange up to 1 Mbits of secret key per second over 20 km, while maximum spans reach roughly 100–140 km depending on detector type.Comparable distances have also been reached for ground-to-ground free-space QKD, supporting prospects for satellite-to-ground links.
- QKD with one-time-pad: One-time-pad encryption combined with QKD provides perfect secrecy and prevents future events from altering the secrecy of encrypted messages.QKD’s universal composability supports composition with other information-theoretically secure and universally composable protocols.
- Security of the key: QKD is the only practically implementable key-agreement scheme identified here as offering information-theoretic security, unlike VPN key establishment based on asymmetric cryptography.This gives QKD a long-term security advantage against present or future computational attacks on public-key schemes.
- Security of the key: Sequential QKD key generation provides forward secrecy because successive keys are independent, so compromising one key does not compromise others.The paper characterizes forward secrecy as weaker than the everlasting secrecy available from QKD combined with one-time-pad encryption.
- Key renewal rate: Frequent key renewal can reduce the impact of key leakage and may benefit AES security, but its justification depends on assumptions about the best available attack.If AES is considered perfectly secure, renewing keys several times per second is not practically required to avoid collision-related problems; post-processing can also bottleneck QKD key rates.
4. Key agreement over a network of QKD links : QKD Networks
QKD networks extend point-to-point QKD toward network-wide key agreement, with architectures distinguished by node functionality and trusted relaying currently offering the most practical deployment path. Their security, initialization, scalability, and availability depend on trust assumptions, pre-distributed authentication keys, network connectivity, and resistance to denial-of-service attacks.
- Standalone QKD is limited to point-to-point links with constrained rate, distance, and deployable network topology.
- QKD network models are categorized by node functionality: optical switching, quantum relaying, and classical trusted relaying.
- Quantum repeaters require quantum memories unavailable with current technology, while quantum relays remain difficult and cannot extend QKD to arbitrary distances.
- Trusted repeater networks can provide unconditional key-agreement security over long distances, but only when intermediate nodes are trusted; path diversity can tolerate limited node corruption.
- Initialization can scale linearly with network size when authentication keys are pre-distributed only across QKD links forming a covering graph, rather than every user pair.
- QKD links face denial-of-service through channel disruption, induced noise, or authentication-key exhaustion, although path diversity offers network-level mitigation.
- QKD networks are unsuitable for open networks because users need pre-established secrets or trust relations, while their physical channels impose distance limits.
5. Challenges and future directions
The paper identifies practical security, implementation, standardization, and cryptographic challenges that constrain QKD adoption while motivating new research directions. These include side-channel resistance, device-independent security, post-quantum cryptography, historical security, and the treatment of QKD networks as cryptographic primitives.
- 5.1 Practical security of QKD implementations and implementation loopholes: QKD security proofs rely on secure laboratories and trustworthy implementations, but real-device imperfections can invalidate these assumptions through side-channel attacks.
- 5.1.1. Physical side-channels: Conventional side-channels, including acoustic and electromagnetic emissions, remain serious threats alongside quantum-specific loopholes.
- 5.1 Practical security of QKD implementations and implementation loopholes: Calibration procedures for source intensity, channel length, detector timing, and shot-noise parameters must be treated adversarially because attacks can cause security breaches.
- 5.2. Device-independent security: fundamental quantum mechanics as a tool against side-channels: Device-independent QKD can provide unconditional security without trusted hardware assumptions and is intrinsically resistant to side-channel attacks.
- 5.2. Device-independent security: fundamental quantum mechanics as a tool against side-channels: Loophole-free Bell-inequality testing remains experimentally challenging, leaving practical long-distance device-independent QKD out of reach for now.
- QKD adoption also requires historical security, practical-security research, and standards and certification procedures for evaluating devices.
- Post-quantum cryptography addresses the possibility that large quantum computers could break factoring- and discrete-log-based public-key systems, but candidate schemes remain less practical or incompletely established.
- 5.5 Classical Cryptographic Primitives built on top of QKD networks: QKD networks operated with trusted repeaters can be deployed today and may be studied as cryptographic primitives for unconditionally secure keys among trusted centers.
6. Conclusion
QKD remains distinctive because it is the only known technique with formally established unconditional security for secret key agreement. The survey emphasizes practical uses where QKD’s long-term key confidentiality provides security advantages, especially in link encryption and managed medium-sized networks.
- QKD is currently the only known technique whose secret key agreement protocols have formally established unconditional security.
- The survey focuses on practical QKD deployment for link encryption, network-scale operation, and cryptographic technology development.
- Combining QKD with one-time-pad encryption can exploit long-term key confidentiality to provide otherwise unattainable security advantages.
- For QKD networks, the survey recommends focusing on medium-sized closed networks while carefully managing established keys and authentication.
- Future QKD development may benefit from cross-disciplinary work on ITS network protocols, hardware side-channels, network security, industry, and certification.