HEQA Security

HEQA Security — From the Ground Up: Why "QKD First" is the Most Practical and Secure Transition Path to Quantum Security

HEQA Security — From the Ground Up: Why "QKD First" is the Most Practical and Secure Transition Path to Quantum Security

Regular price $0.00 TWD
Regular price Sale price $0.00 TWD
Sale Sold out
Taxes included.
Quantity

If a routine software update can lead to Blue Screens of Death for airports, banks, broadcasters, and hospitals worldwide, why would our supposedly “quantum-safe” plan involve performing *more software surgery* all at once? There’s a more robust way: start with the fiber, not with end-point-by-end-point operations.

Executive Summary

The prevailing approach: take inventory of all your encrypted data, upgrade everything to PQC, and then (maybe) later deploy QKD on a few “special” links. This is well-intentioned, but it’s expensive, slow, prone to integration vulnerabilities, and fails to immediately harden the places attackers most covet: the pipes between large data centers.1

PQC is essential, and NIST’s 2024 standards (FIPS 203–205) are a milestone. But the PQC migration is not a simple “software-only” switch; it stresses hardware/firmware, increases handshake sizes, and has already caused middleware failures in real-world applications.

QKD adds a layer that PQC does not: physically verifiable key delivery. It runs out-of-band, reduces uptime risk during changes, and immediately hardens the data flows on your most valuable links (DC↔DC, DC↔Cloud, HQ↔DC, backbone). You can deploy QKD to a small footprint first and then gradually roll out PQC across your network.

QKD is being piloted and deployed worldwide (EU testbeds and operator trials; US DoE-backed demonstration programs; national-level programs in Japan, Singapore, South Korea; China’s vast network). While security agencies remain split, operating experience is accumulating across large-scale infrastructure projects and operators.

Yes, I have skin in the game—I build quantum-safe networks for a living. If I thought “deploying PQC all at once” was the faster path to security, I’d say so. The argument here is simple: QKD-first, then PQC, is a pragmatic deployment order that reduces operational risk, immediately increases network resilience, and ultimately reaches the same goal with less cost and fuss—a hybrid PQC+QKD deployment.


What Today’s “Consensus” Says—and Where It Over-Relies on Software

Regulators prioritize PQC because it scales, in principle, without re-laying fiber. In 2024, NIST finalized ML-KEM (key establishment), ML-DSA (lattice-signatures), and SLH-DSA (hash-based signatures) as FIPS 203–205. The UK’s National Cyber Security Centre (NCSC), for example, has published a public roadmap to deploy PQC broadly (with reporting suggesting deployment for large institutions is expected by 2035). These statements aren’t wrong, just incomplete.4

What is often overlooked: “Software-only” isn’t actually software-only.

  • Larger messages and keys. FIPS 203’s ML-KEM-768 uses a 1184-byte public key and a 1088-byte ciphertext; ML-DSA-65 (Dilithium level) signature sizes are ~3.3 KB and public keys are ~1.9 KB. These are orders of magnitude larger than current X25519/ECDSA handshakes and signatures and have real-world ripple effects on devices and middleware. <sup> 5</sup>
  • Real-world issues have already emerged. When Chrome/Cloudflare trialed hybrid post-quantum TLS, some older routers and middleware could not handle the larger handshake records—proving that a “mere software update” can introduce serious problems for network hardware/firmware.6
  • Inventory first, everything else second. US guidance (CISA/NIST/NSA) effectively tells you to take a full crypto inventory and engineer crypto agility first—a daunting task before the first protected session ever flips to PQC.7

None of the above argues against PQC, but it argues against a PQC-first strategy.


What QKD Adds that PQC Cannot

  • Physics-based key distribution. Quantum Key Distribution (QKD) uses single photons; any eavesdropping causes a measurable disturbance to the signal, so you *know* if a key exchange has been tampered with. This is information-theoretic assurance, not a wager on perfect mathematics.
  • Out-of-band delivery, small blast radius. QKD systems run parallel to the data plane on specific links, so you can harden DC↔DC, DC↔Cloud PoPs (including AWS DirectConnect, Azure ExpressRoute, and GCP Cloud Interconnect), HQ↔DC, and backbone segments without modifying every workstation, application, and firmware image on Day 1.
  • Resilience to change. After the CrowdStrike incident this past summer, do you really want your first “quantum-safe” step to be a mass software update to all your Windows servers, routers, and applications? Falcon sensor content updates crashed ~8.5 million Windows devices; airlines and hospitals were immediately affected. Start where you can add protection without affecting uptime.

I’ve already analyzed this reasoning—and US agency skepticism—in detail; suffice it to say, PQC and QKD are complementary layers that are made antagonistic if we force an either/or model.9


What the World is Actually Doing

1. United States

  • Standards: NIST’s FIPS 203–205 are final—PQC is the official baseline. NSA’s CNSA 2.0 sets a PQ timeline for National Security Systems. (Notably, the NSA has long been cautious to negative on QKD for NSS.)10
  • Pilot Programs and Testbeds: The US Department of Energy and Oak Ridge National Laboratory demonstrated quantum key distribution (QKD)-secured links on in-service fiber for a utility (EPB of Chattanooga) as part of a broader “quantum internet” initiative. This means: policy leads PQC development; R&D drives QKD for high-reliability backbones.

2. European Union

  • Infrastructure: The EuroQCI initiative is building a quantum communication backbone across the EU, featuring both terrestrial and satellite segments, and expanding the OPENQKD testbed which operates in collaboration with operators such as Deutsche Telekom and Telefónica.11
  • Industry Involvement: Alliances like QSAFE and Nostradamus (DT, Thales, AIT, Telefonica) are designing architectures and interoperability, including test infrastructures for QKD devices.12
  • Security Agency Stance: EU security agencies (BSI/ANSSI and their Dutch/Swedish counterparts) still position QKD as a “niche technology” useful only in specific point-to-point or defense-in-depth scenarios, while urging immediate migration to PQC. Herein lies the contradiction: policy invests in QKD infrastructure, while agencies remain rooted in PQC-first. <sup> 13</sup>

3. United Kingdom

  • Live Networks: BT and Toshiba have operated a quantum-secured metropolitan network in London (EY was among its first customers) and deployed industrial networks between research institutes.14
  • Policy: NCSC is pushing PQC hard and has published a public roadmap for large organizations that reportedly extends to 2035—again, reflecting PQC baseline + optional high-assurance overlays.15

4. Japan

  • Operating Experience: NICT’s Tokyo QKD Network has been operating since the 2010s, and current work integrates QKD with NTT’s All-Photonics Network (IOWN) transport technology for the coexistence of high-capacity data and quantum keys. Japan’s CRYPTREC also published updated PQC guidelines in 2024. <sup> 16</sup>

5. Singapore

  • Regulator-Led Adoption: The national Quantum-Safe Network (NQSN/NQSN+) is piloting QKD and quantum-safe communication for banks and critical infrastructure. The government has committed ~S$300 million to a national quantum strategy, and S$100 million via the Monetary Authority of Singapore’s (MAS) Financial Sector Technology and Innovation (FSTI) Scheme 3.0 to foster the adoption of quantum technologies (including QKD) in finance. <sup> 17</sup>

 

6. South Korea

  • National Backbone: SK Broadband/ID Quantique built an ~800 km QKD network connecting 48 government agencies; SKT actively participates in standardization efforts for combining QKD with PQC for quantum-safe communication.18

 

7. China

  • National-level scale: This integrated terrestrial and celestial network combines a >12,000 km Beijing-Shanghai fiber optic backbone with satellite links, providing users with ~12,900 km of Quantum Key Distribution (QKD) coverage – the largest deployment of its kind in the world to date. China is the only country that has mandated (rather than just requested) post-quantum-safe measurement technologies to be operational in several key industries. In fact, China specifically mandates Quantum Key Distribution (QKD ), not Post-Quantum Cryptography (PQC). <sup> 19</sup>

Software isn't "free": The hidden costs of a PQC-first approach

Let's talk frankly about the friction you'll encounter if you try to upgrade everything at once:

  • Inventory is mandatory, and time-consuming. All credible roadmaps start with automated crypto-discovery (where is RSA/ECC used? which libraries? which versions? who owns it?). This consumes significant time and budget before the first PQC handshake takes effect. 20
  • Hardware/firmware realities. Larger keys and handshake operations stress IoT devices, routers, and firewalls; even well-resourced web stacks have shown middlebox failures in PQC tests. Expect vendor firmware updates, protocol stack upgrades, and interoperability testing. 21
  • Algorithm agility is core to design. NIST explicitly warns to remain agile, as even PQC algorithms may be deprecated. This means more migrations later. QKD keys don’t depend on unbroken math. 22

I’m not advocating avoiding PQC. I am advocating doing PQC after you lock down your largest pipes with a technology that won't impact uptime when changing engines in flight.


The Practical Flow: QKD first, then PQC

Start where the adversary gains the most (and your blast radius is smallest):

  1. Secure the core network.
    • DC↔DC Cross Connects
    • HQ↔Datacenter
    • DC↔Cloud Onramps
    • Backbone links
      These are the "big pipes." QKD sits next to the data plane, immediately hardening all key exchanges for data flows traversing these links, regardless of what each application or TLS protocol stack is currently doing.
  2. Measure Key Metrics.
    Track secure key rate, link stability, detected interference, and mean time to recovery on your quantum channels. Use these metrics to benchmark resilience improvements.
  3. Layer in PQC Methodically.
    After the core security is assured, examine cryptographic assets layer-by-layer and upgrade stacks to ML-KEM/ML-DSA/SLH-DSA. Even if software changes break, your high-value data in transit remains protected.
  4. End state: Hybrid PQC+QKD, which is the defense-in-depth pattern already being designed (and standardized towards) by the telco world. 23

This flow is similar to how operators in London, Berlin, Madrid, etc., are learning — deploying Quantum Key Distribution (QKD) on production fiber, then iterating. 24

Common Objections Addressed

  • "Our national agencies consider QKD a niche technology."
    It's true that European security agencies (Germany's BSI/France's ANSSI, and their Dutch/Swedish counterparts) prioritize PQC and today label QKD "niche." Both things can be true: their caution about wholesale replacement and the value of QKD as a defense-in-depth layer on a relatively small number of critical links. That's precisely where I recommend you start. 25
  • "Trusted nodes weaken security."
    Trusted relays are a clear engineering tradeoff, not a fatal flaw — especially on operator-controlled metro/backbone links where the facilities, racks, and lines are hardened. Today, QKD with secure nodes protects these large links; entanglement-based QKD is the future upgrade that pushes trust to zero — but not a prerequisite to genuinely reduce risk now. 26
  • "Isn't QKD still a science project?"
    It used to be, but no longer. Look at the EuroQCI initiative, the OPENQKD report, the BT/Toshiba London metro network, NICT's Tokyo network, SK Broadband's 800km deployment, and the US Department of Energy's sponsored demonstration projects. These aren't lab curiosities — they're how operators learn to run and maintain quantum-safe backbones at scale. <sup> 27</sup>
  • "What about uptime and risk?"
    Unlike PQC, QKD is deployed alongside the data path, not embedded within it. If a QKD device restarts, it does not blue-screen terminals. This is in stark contrast to CrowdStrike's software update, which took ~8.5 million Windows devices offline and grounded flights. When modernizing, pick the first step that reduces operational risk. 28

Costs and ROI (the part the Board will ask about)

  • PQC-first strategies require upfront inventorying, firmware upgrades, interoperability testing, and application refactoring. These are necessary but won’t provide noticeable short-term risk reduction for your most valuable flows until most of the work is done. 29

  • QKD-first strategies focus limited CapEx/OpEx on a tiny number of high-value links, provide measurable security assurance (eavesdropping is detectable), and do not threaten Service Level Agreements (SLAs) during software migration. In other words: boost network security posture with the highest ROI, minimize change risk—and lay the groundwork for smooth PQC (performance, quality, and control) addition.

What comes next (entanglement & integration)


The roadmap isn’t “QKD or PQC,” but QKD + PQC, then evolving as entanglement networks mature. NICT recently demonstrated integration of QKD with high-capacity optical transmission on NTT's Open APN, and the US DOE blueprint efforts are working to build a US quantum internet—both point to a future where classic and quantum layers co-evolve. Early QKD adopters will already have the operational experience required to upgrade. 30 nict.go.jp

How to brief your CISO in 15 minutes

  1. Define core flows (DC↔DC, DC↔Cloud, HQ↔DC).
  2. Deploy QKD on those links; integrate with data path's existing key management/encryption.
  3. Perform crypto asset inventory and plan PQC upgrades based on crypto agility. 31
  4. Roll out PQC application/domain by application/domain; monitor for regressions.
  5. Work towards a hybrid model (QKD-protected key delivery + PQC in the protocols).
  6. Track key performance indicators (key rate, interference events, handshake success rate, SLA impact).

That's it. Calm. Boring. Defensible.


Conclusion

We all carry biases—mine included. But facts speak for themselves: PQC is necessary, and QKD can be deployed now on specific links carrying your highest-value data. You don’t need to choose; you need to do things in sequence. Start at the pipes.


By Nir Bar Lev, CEO, HEQA Security


  1. https://www.cisa.gov/resources-tools/resources/quantum-readiness-migration-post-quantum-cryptography? ↩︎
  2. https://csrc.nist.gov/pubs/fips/203/ipd
    ↩︎
  3. https://digital-strategy.ec.europa.eu/en/policies/european-quantum-communication-infrastructure-euroqci?
    ↩︎
  4. https://csrc.nist.gov/pubs/fips/203/ipd ↩︎
  5. https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.203.ipd.pdf ↩︎
  6. https://quantum.lanl.gov/cryptography.shtml? ↩︎
  7. https://www.cisa.gov/resources-tools/resources/quantum-readiness-migration-post-quantum-cryptography? ↩︎
  8. https://www.reuters.com/technology/microsoft-says-about-85-million-its-devices-affected-by-crowdstrike-related-2024-07-20/? ↩︎
  9. https://heqa-sec.com/blog/the-peculiar-stance-of-nist-and-the-nsa-on-quantum-cryptography-and-why-theyre-wrong/ ↩︎
  10. https://csrc.nist.gov/pubs/fips/203/ipd ↩︎
  11. https://digital-strategy.ec.europa.eu/en/policies/european-quantum-communication-infrastructure-euroqci? ↩︎
  12. https://www.telekom.com/en/media/media-information/archive/deutsche-telekom-partners-quantum-communication-infrastructure-642332? ↩︎
  13. https://cyber.gouv.fr/sites/default/files/2020/05/anssi-technical_position_papers-qkd.pdf? ↩︎
  14. https://www.toshiba.eu/solutions/quantum/wp-content/uploads/resources/London-Quantum-Secured-Metro-Network.pdf? ↩︎
  15. https://www.theguardian.com/technology/2025/mar/20/uk-cybersecurity-agency-quantum-hackers? ↩︎
  16. https://www.itu.int/en/ITU-T/Workshops-and-Seminars/2023/0724/Documents/Kenyoshi.pdf? ↩︎
  17. https://nqsn.sg/? ↩︎
  18. https://www.idquantique.com/quantum-safe-security/nation-wide-quantum-safe-key-distribution-network-in-south-korea/? ↩︎
  19. https://merics.org/en/report/chinas-long-view-quantum-tech-has-us-and-eu-playing-catch ↩︎
  20. https://www.cisa.gov/resources-tools/resources/quantum-readiness-migration-post-quantum-cryptography? ↩︎
  21. https://quantum.lanl.gov/cryptography.shtml? ↩︎
  22. https://csrc.nist.gov/pubs/ir/8547/ipd? ↩︎
  23. https://www.cmorg.org.uk/sites/default/files/2025-06/CMORG%20-%20Guidance%20for%20Post-Quantum%20Cryptography%20-%20April%202025%20-%20TLP%201%
  24. https://www.toshiba.eu/solutions/quantum/wp-content/uploads/resources/London-Quantum-Secured-Metro-Network.pdf? ↩︎
  25. https://cyber.gouv.fr/sites/default/files/2020/05/anssi-technical_position_papers-qkd.pdf? ↩︎
  26. https://www.nict.go.jp/en/press/2025/09/16-1.html? ↩︎
  27. https://digital-strategy.ec.europa.eu/en/policies/european-quantum-communication-infrastructure-euroqci? ↩︎
  28. https://www.reuters.com/technology/microsoft-says-about-85-million-its-devices-affected-by-crowdstrike-related-2024-07-20/? ↩︎
  29. https://www.cisa.gov/resources-tools/resources/quantum-readiness-migration-post-quantum-cryptography? ↩︎
  30. https://www.nict.go.jp/en/press/2025/09/16-1.html? ↩︎
  31. https://www.cisa.gov/resources-tools/resources/quantum-readiness-migration-post-quantum-cryptography? ↩︎
View full details