NSA/CSS - National Security Agency - Central Security Service

10/01/2026 | News release | Distributed by Public on 10/01/2026 07:10

Cryptograph Solutions are Limited Compared to Quantum-Resistant Algorithms

As of June 2026, the National Security Agency (NSA) does not recommend using quantum key distribution (QKD) and quantum cryptography (QC) for securing the transmission of data in National Security Systems (NSS) unless several technical limitations are overcome. This article dives into the nuances of QKD and QC, their limitations, and how they compare to quantum-resistant algorithms.

What is Quantum Key Distribution and Quantum Cryptography?


QKD leverages the unique properties of quantum mechanical systems to generate and distribute cryptographic keying materials using special purpose technology.

QC is a broader field of study that uses similar physics principles and technology to communicate over a dedicated communications link. Theoretical models suggest that both QKD and QC can detect eavesdropping, a feature missing in traditional cryptographic methods.

Key Concepts:

  • Quantum Key Distribution: Uses quantum mechanical properties to generate and distribute cryptographic keys.
  • Quantum Cryptography: Applies quantum principles to secure quantum communications over a dedicated link.
  • Eavesdropping Detection: A theoretical advantage of QKD and QC, allowing the detection of unauthorized access to communication channels.

Quantum Key Distribution Limitations


Despite theoretical claims of guaranteed security based on the laws of physics, QKD face substantial practical challenges. The balance between communication needs and security requirements is delicate, with a low tolerance for error.

Technical limitations of QKD include:

  • Partial Solution: QKD generates keying material for encryption algorithms that ensure confidentiality. This keying material can also be used in symmetric key cryptographic algorithms for integrity and authentication, provided the original QKD transmission is authenticated. However, QKD does not authenticate the transmission source, necessitating the use of asymmetric cryptography or preplaced keys for authentication.
  • Special Purpose Equipment Requirements: QKD relies on physical properties and unique physical layer communications, requiring dedicated fiber connections or free-space transmitters. The hardware-based nature of QKD hinders future upgrades and security patches, limiting integration with existing network equipment.
  • Increased Infrastructure Costs and Insider Threat Risk: QKD networks often require trusted relays, increasing the costs for secure facilities and increasing the risk of insider threats. These constraints eliminate many potential use cases.
  • Significant Challenges to Security and Validation: The actual security of a QKD system is limited by hardware and engineering designs rather than the unconditional security modelled by physics. Changing environmental conditions and physical degradation can negatively affect operational security established at the time of certification. Specialized hardware introduces vulnerabilities, which has led to well-publicized attacks on commercial QKD systems.[1]
  • Increased Denial of Service Risk: The sensitivity to eavesdropping, while providing security, also increases the risk of denial-of-service attacks.

The practical application of QKD faces numerous technical challenges, and understanding these limitations is crucial for making informed decisions about cryptographic strategies. Meanwhile, the most robust uses of QC remain theoretical and are intended for use within a broader, fully-quantum network that may link quantum computers and quantum sensors.

Advantages of Quantum-Resistant Algorithms


In comparison, quantum-resistant algorithms are implemented on existing platforms and derive their security through mathematical complexity. These algorithms are used in cryptographic protocols, providing the means for assuring the confidentiality, integrity, and authenticity of a transmission - even against a potential future quantum computer.

Quantum-resistant algorithms also offer more cost-effective confidentiality and authentication services with a well-understood risk profile.

Key Advantages and Distinctions:

  • Implementation: Quantum-resistant algorithms are software-based and can be implemented on existing infrastructure.
  • Security: Derived from mathematical complexity rather than physical properties.
  • Flexibility: Easier to upgrade and patch compared to hardware-based QKD systems.

For immediate adoption of post-quantum cryptography, explore NSA's Post-Quantum Cryptography Resource Hub.


[1] See, for example (Note: These references are not meant to be exhaustive.):

  • Vakhitov, Makarov, and Hjelme, Large pulse attack as a method of conventional optical eavesdropping in quantum cryptography, Journal of Modern Optics 48, 2001.
  • Makarov and Hjelme, Faked states attack on quantum cryptosystems, Journal of Modern Optics, vol. 52, 2005.
  • Ferenczi, Grangier, Grosshans, Calibration Attack and Defense in Continuous Variable Quantum Key Distribution, CLEO-IQEC, 2007.
  • Zhao, Fung, Qi, Chen, and Lo, Experimental demonstration of time-shift attack against practical quantum key distribution systems, Physical Review A vol. 78, 2008.
  • Scarani and Kurtsiefer, The black paper of quantum cryptography: Real implementation problems, Theoretical Computer Science (560) 2014.
  • Marquardt et al., Implementation Attacks against QKD systems, BSI (2023)
  • Makarov et al., Preparing a Commerical Quantum Key Distribution System for Certification Against Implementation Loopholes, Physical Review Applied, 22, 044076 (2024)
  • Diamanti, Lo, Yuan, Practical Challenges in Quantum Key Distribution, Nature Partner Journals, 2, 16025 (2016)
  • Jiang et al. The Practical Issues of Side-Channel Secure Quantum Key Distribution, arXiv 2508.15197v1 (2025)
  • Tighe, Brumpton, Carney, Varcoe, The Manipulate and Observe Attack on Quantum Key Distribution, arXiv 2603.29669v1 (2026)

NSA Media Relations
[email protected]
443-634-0721

About the National Security Agency

The National Security Agency leads the U.S. Government in cryptology that encompasses both foreign signals intelligence (SIGINT) insights and cybersecurity products and services and provides the Nation decision advantage in competition, crisis, and conflict.

###

NSA/CSS - National Security Agency - Central Security Service published this content on October 01, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on October 01, 2026 at 13:10 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]