PKD Vs PQC
Quantum key distribution compared with post-quantum cryptography
Quantum key distribution uses the physical properties of light to establish a shared key between two endpoints and to detect interception. Post-quantum cryptography uses conventional algorithms designed to resist quantum attack. They solve different parts of the problem, and only one of them addresses authentication.
What is quantum key distribution?
Quantum key distribution, or QKD, is a method of establishing a shared symmetric key between two parties over a dedicated optical link, using quantum mechanical properties to detect whether the exchange has been observed. Its security derives from physics rather than from computational difficulty.
The first protocol, BB84, was described by Bennett and Brassard in 1984. Its principle is that measuring a quantum state disturbs it, so an eavesdropper on the optical channel introduces detectable errors. If the observed error rate is low enough, the parties can distil a key they know has not been intercepted. Ekert's E91 protocol achieves a comparable result using entanglement.
The output is symmetric key material, typically used to key AES. QKD does not encrypt data itself and does not replace an encryption algorithm.
What quantum key distribution does not provide
The limitations are the reason national guidance is cautious, and they are structural rather than a matter of product maturity.
QKD cannot authenticate. The classical channel used alongside the quantum channel must be authenticated, or the exchange is trivially defeated by an adversary in the middle. That authentication requires either pre-shared symmetric keys, which reintroduces the key distribution problem QKD was intended to solve, or conventional digital signatures, which means a public key infrastructure is still required and must itself be quantum-resistant.
QKD is point to point. It requires a dedicated optical path between two endpoints. Commercial systems operate over roughly 100 to 200 kilometres of fibre. Greater distances require trusted node relays, where the key is decrypted and re-encrypted at each hop, and every relay is a point at which the information-theoretic security claim no longer holds.
QKD addresses one function only. It does nothing for data at rest, code signing, document signing, device identity, software update verification or any other use of asymmetric cryptography across an estate.
QKD depends on hardware behaving as modelled. The security proofs apply to idealised devices. Practical implementations have been attacked repeatedly through detector blinding, laser damage and other side channels, and there is no established validation scheme comparable to FIPS certification for cryptographic modules.
Quantum key distribution and PQC compared

The comparison is frequently framed as a choice. It is not. An organisation deploying QKD still needs post-quantum signatures for the authentication that QKD depends on, and still needs to migrate every other use of asymmetric cryptography in its estate.
Where national guidance stands
Positions differ, and the differences are worth stating accurately rather than collapsing into a single view.
The NCSC advises against QKD for government and commercial use, on the grounds that it addresses only part of the problem, requires specialist infrastructure, and does not solve authentication. Its recommendation is post-quantum cryptography.
The US National Security Agency takes a similar position for national security systems, citing that QKD is a partial solution, requires special purpose equipment, increases infrastructure cost and insider threat exposure, raises denial of service risk, and lacks a validation regime.
France's ANSSI is more permissive, treating QKD as a potential defence-in-depth measure to be deployed alongside post-quantum cryptography rather than as an alternative to it.
Investment elsewhere has been substantial. The European Union has funded the EuroQCI initiative to build quantum communication infrastructure across member states, and China has operated a Beijing to Shanghai backbone using trusted nodes and demonstrated satellite-based distribution with the Micius satellite. These programmes reflect strategic and sovereignty considerations as much as a technical judgement that QKD outperforms post-quantum algorithms.
The case in favour of QKD
The strongest argument is independence from computational assumptions. Post-quantum algorithms rest on mathematical problems believed to be hard, and belief is not proof. Structured lattice assumptions underpin both ML-KEM and ML-DSA, and candidate algorithms have been broken during standardisation before, Rainbow and SIKE both in 2022. QKD's security does not depend on any such assumption holding.
For a small number of very high value, fixed, point-to-point links, where the endpoints are known, the distance is short, the budget is available and the confidentiality requirement extends across many decades, that argument has weight. Inter-site links between data centres in a single metropolitan area, or dedicated national security connections, are the realistic candidates.
For an enterprise estate, it does not apply. The exposure is distributed across thousands of endpoints, most of the risk is in authentication rather than key exchange, and QKD addresses neither.
Quantum random number generation is a different question
Quantum random number generators are frequently discussed alongside QKD and are a separate technology with a clearer case. A QRNG uses a quantum process to produce entropy, and it can be deployed as a source within an existing hardware security module or operating system entropy pool without changing anything else.
Poor entropy has caused real cryptographic failures, including duplicate RSA keys generated on embedded devices with insufficient randomness at boot. A QRNG addresses that specific problem. It is not a quantum-safe measure in the sense that post-quantum algorithms are, and it should not be presented as one, but it is far easier to adopt than QKD and does not carry the same architectural constraints.
What to do in practice
The sequencing question answers itself once the scope is clear. Post-quantum cryptography is required regardless of any QKD decision, because signatures, certificates, code signing and the wider estate cannot be addressed any other way. QKD, if it is adopted, is an addition to that programme rather than a substitute for part of it.
In assessments, QKD proposals usually surface for a small number of specific links, and the useful test is a short one. Are both endpoints fixed, known and within range without trusted relays. Does the confidentiality requirement extend far enough to justify the capital cost. Has the authentication requirement been identified and costed, since it does not disappear. Is the alternative, a post-quantum protected link over existing infrastructure, genuinely insufficient for the stated threat model.
Where those questions have good answers, QKD is a defensible defence-in-depth investment. Where they do not, the same budget applied to discovery, certificate lifecycle management and migration will reduce more risk.
How Unsung helps
Unsung is a UK-based, vendor-neutral consultancy specialising exclusively in public key infrastructure and cryptographic systems, working across central government, defence, healthcare, financial services and critical national infrastructure.
We assess where cryptographic risk actually sits, through our PKI health check and cryptographic bill of materials services, and design migration to post-quantum algorithms across the estate. Where QKD is under consideration, we evaluate it on the same evidence as any other control, including the authentication dependency it introduces. Being vendor-neutral, we have no position to defend either way.
For the algorithms that carry the authentication requirement, see our comparison of the NIST post-quantum algorithms.
Frequently asked questions
Is quantum key distribution better than post-quantum cryptography?
Does the NCSC recommend quantum key distribution?
How far can quantum key distribution operate?
Can QKD be broken?
Is a quantum random number generator the same as QKD?
Should we invest in QKD now?


