PQC vs QKD
Two approaches to quantum-era security. One is algorithmic and scalable. The other is physics-based and hardware-dependent. Understanding the trade-offs is essential for any migration strategy.
- Purely algorithmic and inherently scalable approach
- Provides both key establishment and authentication
- The default scalable standard for enterprises, CII, and Defence
- Relies on globally interoperable, standardised algorithms
- Physics-based and hardware-dependent
- Key distribution only (no authentication)
- Requires expensive dedicated optical channels and nodes
- Limited range. Advised against by UK, Australia, Germany, Google, Cloudflare
Post Quantum Cryptography (PQC)
Post Quantum Cryptography involves cryptographic algorithms designed to resist attacks from quantum computers while continuing to operate on existing digital infrastructure. These algorithms can be deployed through software and minimal hardware updates, integrated into current security protocols, and managed within established governance and assurance frameworks.
PQC protects both data exchange and authentication processes, enabling secure communications and digital signatures without the need for new physical infrastructure. Because PQC aligns with current networking and computational models, it can be adopted at scale and updated as standards evolve.
Quantum Key Distribution (QKD)
QKD uses quantum properties of light to generate and distribute symmetric keys between communicating parties. Its defining characteristic is that any attempt to intercept the quantum signal alters its state, providing a mechanism to detect eavesdropping.
However, QKD addresses only the distribution of keys and not the authentication of participants (devices) or the encryption of data itself. These functions still rely on classical or post-quantum cryptographic algorithms, which must remain secure for the system to be effective.
Evolution and Limits
Several national and international programmes have advanced QKD through laboratory demonstrations, pilots, and satellite-based experiments. Notable examples include the European Quantum Communication Infrastructure (EuroQCI) and China's Quantum Communication Network (CN-QCN), which have successfully demonstrated QKD over long distances.
Global Guidance & Challenges
Independent guidance from national cybersecurity agencies such as the UK's NCSC, Australia's ACSC, BSI (Germany), and enterprises like Google and Cloudflare have cautioned that QKD is not suited for broad enterprise, defence, or CII deployments at this stage.
The assessments highlight practical constraints for large-scale QKD deployments:
- Authentication Paradox: Depends on PQC/Classical cryptography for authentication. If PQC is trusted for authentication, the reliance on QKD for key establishment is often questioned.
- Supply-chain Dependency: Critical components like Single Photon Detectors are sourced from a limited number of vendors.
- Infrastructure Cost: Dedicated optical lines are expensive and often not practical for existing fibre networks.
- Sensitivity to environmental conditions and side-channel leakages.
- Limited range without specialised repeaters.
- Interoperability challenges creating potential vendor dependencies.
These factors place boundaries around QKD's applicability in heterogeneous, internet-scale enterprise environments.
Conclusion
Considering these dynamics, PQC remains the most widely deployable and infrastructure-aligned pathway for organisations seeking quantum-resilient security across diverse systems and networks, including for CII and Defence. QKD continues to evolve within research and national-security contexts, and its future capabilities may expand as underlying technologies mature.