Skip to main content
QUICK REVIEW

[Paper Review] The debate over QKD: A rebuttal to the NSA's objections

Renato Renner, Ramona Wolf|arXiv (Cornell University)|Jul 27, 2023
Quantum Computing Algorithms and Architecture4 citations
TL;DR

This paper rebuts the NSA's skepticism toward quantum key distribution (QKD), arguing that its stated limitations are either not inherent to quantum cryptography or will be resolved with emerging technologies like quantum repeaters and universal quantum computers. The authors advocate for hybrid QKD-PQC systems as a secure, interim solution, emphasizing QKD's unique advantage of everlasting security against future quantum attacks.

ABSTRACT

A recent publication by the NSA assessing the usability of quantum cryptography has generated significant attention, concluding that this technology is not recommended for use. Here, we reply to this criticism and argue that some of the points raised are unjustified, whereas others are problematic now but can be expected to be resolved in the foreseeable future.

Motivation & Objective

  • To counter the NSA's conclusion that QKD is not recommended for use due to technical limitations.
  • To demonstrate that most cited limitations are not inherent to quantum cryptography but stem from current hardware constraints.
  • To propose hybrid QKD and post-quantum cryptography (PQC) schemes as a viable, secure interim solution.
  • To argue that long-term deployment of QKD will be feasible and more secure than classical cryptography once quantum repeaters and scalable networks are realized.
  • To clarify that implementation vulnerabilities are not unique to QKD and can be mitigated with proper engineering.

Proposed method

  • Analyzing each of the NSA’s five technical limitations on QKD and assessing their validity in the short-, medium-, and long-term futures.
  • Distinguishing between protocol-level security (information-theoretic) and implementation-level risks (side-channel attacks).
  • Proposing a hybrid cryptosystem combining PQC for public-key distribution and QKD for one-time pad key generation.
  • Using the timeline of technological milestones—quantum repeaters and universal quantum computers—as benchmarks for feasibility assessment.
  • Evaluating the risk profiles of QKD versus PQC, emphasizing QKD’s stronger theoretical security foundation.
  • Highlighting that network redundancy and rerouting in future quantum networks can mitigate denial-of-service risks.

Experimental results

Research questions

  • RQ1Are the NSA’s objections to QKD based on fundamental flaws or temporary hardware limitations?
  • RQ2Can QKD’s lack of native source authentication be considered a valid criticism, given that classical cryptography also requires authentication mechanisms?
  • RQ3To what extent are implementation vulnerabilities in QKD unique compared to classical cryptographic systems?
  • RQ4How can hybrid QKD-PQC systems improve security in the medium-term future when QKD infrastructure is still evolving?
  • RQ5Will the development of quantum repeaters eliminate the need for trusted relays and thus resolve insider threat concerns?

Key findings

  • Limitation 1(a), regarding source authentication, is not a flaw of QKD but a general requirement of all cryptography, classical or quantum.
  • Limitation 1(b), concerning the risk profile of post-quantum cryptography, is less favorable than QKD’s information-theoretic security, which is mathematically proven and less prone to misjudgment.
  • Limitation 2(a), the need for dedicated hardware, is expected to diminish with future advances in optical and quantum communication technology.
  • Limitation 3, involving trusted relays and insider threats, will be resolved with the deployment of quantum repeaters, which operate on the quantum level and do not require trust.
  • Limitation 4, related to implementation security, is not unique to QKD and can be addressed through rigorous validation and side-channel countermeasures.
  • Limitation 5, the low key generation rate, is expected to improve in the medium-term future as quantum hardware matures.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.