NSA rewrites its QKD guidance but still says no to quantum key distribution

Started by Maisie84, Today at 04:08 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: NSA rewrites its QKD guidance but still says no to quantum key distribution   Views(Read 41 times)
Active members in this topic:
Maisie84(1)

Maisie84

PostQuantum has a detailed look at the NSA's updated guidance on quantum key distribution, published on 1 October. The verdict has not changed since 2020. The NSA still does not recommend QKD or other quantum cryptography for National Security Systems. But the reasoning has shifted in interesting ways

The five main objections remain. QKD distributes keys but cannot authenticate who is sending them, so it still needs classical cryptography alongside it. It depends on special hardware rather than software, long distance networks need trusted relay sites where keys exist unencrypted, security depends heavily on hardware behaving correctly, and the sensitivity that detects eavesdroppers also makes it easy to jam. Those have been the standard criticisms for years

The new argument is about drift. The NSA now says environmental conditions and physical degradation can lower the security a QKD system had when it was certified. In other words, even if a system passes certification, its security could quietly weaken over its working life. Meanwhile, the agency dropped its earlier line saying it does not anticipate certifying or approving any QKD products, and stopped criticising vendor claims about physics based guarantees. That is a subtle but important change in tone

For US government systems, nothing changes in practice. The 2027 procurement deadlines we discussed last week require post-quantum algorithms, not QKD. European and Asian QKD vendors are unaffected, and the NSA points to networks of quantum computers and sensors as a more promising use for quantum communication than key distribution. The article's author, Marin Ivezic, agrees with the NSA on current deployment, but argues the US should fund working QKD infrastructure as a backup in case post-quantum algorithms turn out to have weaknesses, pointing to China's carrier grade network

This ties in with the Innsbruck quantum internet story, which is about linking quantum computers rather than just sharing keys. Is the NSA right to stay sceptical? And is it sensible to have QKD as a hedge, given China's head start?