by Florian Kanitschar and Christoph Pacher (Austrian Institute of Technology)

From bank transactions to medical records – our digital lives depend on secrets that may not stay secure for long. Discover how cutting-edge research collaborations are turning quantum mechanics into a guardian for our most sensitive data – and how laser pulses instead of single photons can ensure that high-performance solutions remain compatible with existing telecom infrastructure.

When exchanging confidential information, we trust that the transmitted data remains secret. This trust is founded on cryptographic encryption that uses a key to render the information inaccessible during transmission. That way, only the recipient of the message who holds the appropriate key can decrypt the original message. Thus, one key (pun intended) challenge is to securely distribute the key from the sender to the recipient.

However, today’s most established methods – Diffie-Hellman key exchange (DHKE) and its elliptic curve analog ECDH – rest on a risky assumption: that certain mathematical problems, like the discrete logarithm problem, are practically unsolvable. Since the 1990s, when Peter Shor discovered his famous algorithm, we have known that a sufficiently large quantum computer (QC) could solve these problems efficiently. One recent analysis [L1] predicts that RSA-2048, an encryption standard that is harder to attack with QCs than ECDH, could be broken by 2030. Even more alarming is the “harvest now, decrypt later” strategy, where attackers copy and store encrypted communications today, intending to decrypt them later with more advanced QCs. Corporate secrets, health data, and critical infrastructure information are therefore already at risk today.

Post-Quantum Cryptography (PQC) has already provided NIST-standardized algorithms that are currently not known to be efficiently breakable with QCs and that should be deployed now.  A fundamentally different response to the same threat comes from quantum physics itself: Quantum Key Distribution (QKD). Instead of relying on unproven mathematical conjectures, QKD exploits the fundamental properties of quantum mechanics: unknown quantum states cannot be perfectly copied and measuring them unavoidably disturbs them. These properties enable key distribution protocols whose security is routed in physical laws rather than mathematical assumptions.

While the most-studied QKD protocols rely on costly single-photon measurements, Continuous-Variable (CV) QKD measures the quadratures of faint laser pulses using homodyne detection – a technology well-known from optical data communication. This makes it possible to leverage existing telecom technology and infrastructure. The QKD protocol steps are illustrated in Figure 1 and are detailed in the following.

In each round, Alice randomly chooses and prepares one out of four coherent states in her lab and transmits them over an insecure channel that is under the control of an eavesdropper (Eve). Bob receives the states and performs homodyne detection. Based on Bob’s measurement results, Alice and Bob perform statistical tests on a random subset of the detected states. The test results are used to infer how much information about the key Eve might have gained. The remaining detected states are mapped to key symbols. This is followed by information reconciliation, where Alice and Bob correct errors in their respective shares of the key. Finally, during privacy amplification, they apply a randomly chosen hash function to their corrected raw keys. This step removes Eve’s partial knowledge about their shared key at the cost of shortening the key. If successful, they hold a shared key that is both secret and identical for Alice and Bob. An illustration of the protocol steps is shown in Figure 1.

Figure 1: Illustration of the QPSK CV-QKD protocol. In each round, Alice randomly chooses and prepares one out of four coherent states in her lab and transmits them over an insecure channel that is under the control of an eavesdropper (Eve). Bob receives the states and performs homodyne detection. Based on Bob’s measurement results, Alice and Bob perform statistical tests on a random subset of the detected states. The test results are used to infer how much information about the key Eve might have gained. The remaining detected states are mapped to key symbols. This is followed by information reconciliation, where Alice and Bob correct errors in their respective shares of the key. Finally, during privacy amplification, they apply a randomly chosen hash function to their corrected raw keys. This step removes Eve’s partial knowledge about their shared key at the cost of shortening the key. If successful, they hold a shared key that is both secret and identical for Alice and Bob.
Figure 1: Illustration of the QPSK CV-QKD protocol. In each round, Alice randomly chooses and prepares one out of four coherent states in her lab and transmits them over an insecure channel that is under the control of an eavesdropper (Eve). Bob receives the states and performs homodyne detection. Based on Bob’s measurement results, Alice and Bob perform statistical tests on a random subset of the detected states. The test results are used to infer how much information about the key Eve might have gained. The remaining detected states are mapped to key symbols. This is followed by information reconciliation, where Alice and Bob correct errors in their respective shares of the key. Finally, during privacy amplification, they apply a randomly chosen hash function to their corrected raw keys. This step removes Eve’s partial knowledge about their shared key at the cost of shortening the key. If successful, they hold a shared key that is both secret and identical for Alice and Bob.

For years, however, the security analysis and the implementation of CV protocols relied on idealized assumptions. Recent breakthroughs have progressively closed the gap between theory and practice. Notably, the security of CV-QKD protocols using discrete modulation (DM) constellations, like Quadrature Phase Shift Keying (QPSK), has advanced considerably. Within the last two years, studies have moved these insights from theory to the lab: researchers from the Technical University in Denmark (DTU) and the Austrian Institute of Technology (AIT) implemented a full CV-QKD protocol with QPSK modulation over a 20 km fiber link at telecom wavelengths [1].

The system used advanced signal processing and simple optical modules to enable secure key exchange between sender (Alice) and receiver (Bob). By integrating hardware functions into the digital signal processing (DSP) module, the optical system was significantly simplified. The digital postprocessing of the recorded data was also fully implemented, including the correction of errors that occurred during transmission or measurement. This was followed by privacy amplification, a classical routine that hashes the recorded and corrected raw key to produce a shorter but private secret key. This work demonstrated composable secure keys, that can be safely used in any larger (“composed”) cryptographic context.

While standard lab-based QKD systems often rely on bulky tabletop setups, miniaturization is critical for large-scale deployment. In collaboration with the National University of Singapore, AIT demonstrated that high performance and practicality can coexist. The team developed a fully integrated on-chip quantum transmitter and receiver operating at 40 Gbaud at room temperature, featuring high-performance homodyne detectors [2]. For a QPSK CV-QKD protocol, the system achieved a record key rate of 1.2 Gbit/s with composable security.

The standard setting of QKD is typically limited to exactly two communicating parties, whereas modern telecom networks often involve multiple users. A recent study [3] extends the security of DM CV-QKD protocols to point-to-multipoint networks, addressing various trust scenarios. Applied to a three-party passive-optical network with a distance of 10 km between the central node and each user, this work validates the practical compatibility of CV-QKD with multi-user settings, demonstrating scalability for deployment in real-world networks.

These results underscore the rapid progress toward practical, high-performance QKD systems. By combining theoretical rigor with engineering ingenuity, researchers are paving the way for a scalable, cost-effective quantum secure communication infrastructure. As threats advance, QKD stands out as a future-proof solution, with DM CV-QKD offering robust security without sacrificing compatibility with existing infrastructure. This transition from laboratory to real-world applications marks an important step towards ensuring that the confidentiality of our digital communications remains intact in the quantum computing era.

Links: 
[L1] https://postquantum.com/q-day/q-day-y2q-rsa-broken-2030/ 

References: 
[1] A.A.E. Hajomer, et al., “Experimental composable key distribution using discrete-modulated continuous variable quantum cryptography”, Nature Light: Science&Applications, 14 (1), 255, 2025.
[2] S.Q. Ng, et al., “Gigabit-rate quantum key distribution on integrated photonic chips, Optica”, 13 (6), 1043-1055, 2026.
[3] F. Kanitschar, et al., “Composable Continuous-Variable Multi-User QKD with Discrete Modulation: Theory and Implementation”, Optica, 13 (6), 1043-1055, 2026.

Please contact: 
Florian Kanitschar
AIT – Austrian Institute of Technology, Austria
This email address is being protected from spambots. You need JavaScript enabled to view it.

Christoph Pacher
AIT – Austrian Institute of Technology, Austria
This email address is being protected from spambots. You need JavaScript enabled to view it.