Quantum key distribution (QKD)
Establishing a shared secret key by sending single photons or weak light pulses in non-orthogonal quantum states, so that any eavesdropping raises an error rate the two parties can measure. Its reach in fiber is set by loss and detector dark counts.
Quantum key distribution lets two parties agree on a random secret key over an optical channel that an eavesdropper may control, with the secrecy resting on measurement disturbance rather than on the difficulty of a mathematical problem. The key is sent encoded in quantum states that are not orthogonal to one another; no measurement can read such a state without some chance of changing it, and a copy cannot be made. An eavesdropper who measures therefore introduces errors, and the two parties estimate the error rate by publicly comparing a sample of their bits. The resulting key is then used with ordinary symmetric encryption. QKD does not authenticate anyone: the classical channel used for comparison must itself be authenticated, which in practice requires a short key shared in advance.
The first protocol, BB84, still underlies most systems. The sender encodes each bit in one of two bases, polarization states in free space or time-bin phase in fiber, and the receiver measures in a randomly chosen basis; the two keep only the bits where the bases matched, roughly half. Error correction and privacy amplification then distill a shorter key about which the eavesdropper's information is negligible, and for BB84 with single photons a key survives up to a quantum bit error rate of about 11%. Practical transmitters use attenuated laser pulses instead of true single photons, and the occasional pulse carrying two photons would leak information; the decoy-state method, which randomly varies the pulse intensity, bounds that leak and restores security. Continuous-variable QKD encodes instead on the quadratures of coherent states and reads them with shot-noise-limited coherent receivers, the same hardware as telecom coherent detection.
Loss sets the distance, because a quantum signal cannot be amplified without destroying what makes it secure. At 0.2 dB/km, 100 km of fiber transmits 1% of the light and 200 km transmits 0.01%. For any protocol without quantum repeaters, the key rate is bounded by bits per channel use for a transmission , which evaluates to 0.0145 at 100 km and at 200 km, so each further 100 km costs a factor of 100. Twin-field QKD, in which both parties send to an untrusted middle station, scales as instead and has exceeded 800 km of fiber in the laboratory. At long range the arriving photons become rare enough to compete with detector dark counts, which is why the long-distance results use superconducting nanowire detectors, while field systems more often use gated InGaAs SPADs. The photon flux involved is small: one photon per nanosecond at 1550 nm is 0.13 nW, as computed in the photon energy entry.
The security proofs cover the protocol, not the hardware. The best-known practical attacks, such as blinding single-photon detectors with bright light so they respond classically, target the receiver; measurement-device-independent QKD removes the detector from the trusted set. Networks longer than one link rely on trusted relay nodes, and satellite links extend the geometry to intercontinental distances. Security agencies in the United States and the United Kingdom currently advise post-quantum cryptography rather than QKD for most uses, citing the authentication requirement, the cost of dedicated hardware and the trusted nodes.
References: C. H. Bennett, G. Brassard, Proc. IEEE Int. Conf. on Computers, Systems and Signal Processing, 175 (1984); S. Pirandola, R. Laurenza, C. Ottaviani, L. Banchi, Nat. Commun. 8, 15043 (2017); M. Lucamarini, Z. L. Yuan, J. F. Dynes, A. J. Shields, Nature 557, 400 (2018); S. Wang et al., Nat. Photonics 16, 154 (2022); S. Pirandola et al., Adv. Opt. Photon. 12, 1012 (2020).