Quantum Communication for Industry: QKD or PQC?

When the term ‘quantum communication’ comes up in an industrial context, it is very easy to fall into the narrative typically found in popular articles about the future of the internet. In practice, however, it is not about transmitting data via ‘teleportation’ or replacing traditional networks with something entirely new. Today’s quantum communication is a narrow but very specific area of transmission security technology.

In real-world industrial applications, quantum communication primarily refers to the distribution of cryptographic keys using quantum phenomena, i.e. QKD (Quantum Key Distribution). Data still travels via classical channels, using classical protocols and classical encryption. The difference lies in how the encryption key is generated and delivered.

This is an important distinction, as it allows us to immediately distinguish between technology that actually works and is being implemented, and visions that, for the time being, remain in the realm of research and long-term plans.

Why is industry interested in quantum communication at all?

Industry isn’t looking for new developments for innovation’s sake. It is concerned with risk, business continuity and the lifecycle of systems. In many sectors – energy, transport, process industries – communications infrastructure remains in operation for over a decade, and sometimes for several decades. This means that the issue of data security is no longer limited to ‘today’s attacks’.

Quantum communication has emerged as a solution to one very specific problem: how to secure cryptographic keys in the face of future computing capabilities, including quantum computers. QKD does not rely on the fact that ‘the cipher cannot be broken’, but rather on the fact that any attempt to eavesdrop leaves a physical trace that can be detected.

This is attractive to industry because it shifts some of the responsibility for safety from the algorithmic layer to the physical layer. It does not eliminate the risk, but it changes its nature.

QKD – what is realistic, and what is often mistaken for a promise?

QKD does not encrypt data. This is a very common misconception. QKD systems are used solely to establish cryptographic keys between two parties. It is only these keys that are then used in traditional encryption algorithms, such as AES.

From an industrial infrastructure perspective, QKD acts as an additional layer of security for selected connections. These are most often critical links: control centres, network nodes and management systems. It is not a technology designed for ‘every Ethernet link’ and does not claim to be.

This limitation is not a drawback. It is a consequence of the costs, the fibre-optic infrastructure and the nature of the technology itself. In practice, QKD is designed for situations where the stakes are high and the number of endpoints is limited.

Quantum communication and classical network infrastructure

One of the key reasons why quantum communication is finding its way into industry at all is its compatibility with existing infrastructure. QKD does not require the construction of a ‘new internet’. It operates in parallel with classical networks, often using the same fibre-optic routes, with a dedicated channel.

For industrial operators, this means that quantum communication can be added as a security layer rather than as an architectural revolution. This significantly lowers the barrier to entry and allows the technology to be tested under controlled conditions. At the same time, there are limitations in terms of range, stability and network topology. Without so-called quantum repeaters, which are still in the research phase, QKD systems operate over limited distances and in specific configurations.

Standards and interoperability: without these, the industry won’t get anywhere

In industry, it is not the technology that ‘works in the lab’ that wins out, but rather the technology that can be implemented, maintained and audited. When it comes to quantum communication, the key questions are: can solutions from different suppliers interoperate; can they be integrated into existing security systems; and can these requirements be specified in tender documents?

This is why ETSI plays such an important role; for several years now, it has been advancing work on QKD through its working groups. These groups produce documents on interfaces, security models and terminology – in other words, the very elements that, in practice, determine whether an operator of critical infrastructure can treat QKD as a ‘deployment-ready product’ rather than an experiment. Without interoperability, you risk a situation where you buy an expensive ‘end-to-end’ system, only to find that it cannot be extended or connected to another part of the network because everything is closed.

This is particularly important in the industrial sector, as networks are rarely homogeneous. You have different IT/OT layers, different generations of devices, and different models of identity and key management. For QKD to make sense, it needs to get down to the engineering level: ‘how do I connect this’, ‘how do I manage this’, ‘how do I monitor this’, ‘how do I integrate this with HSMs, PKI and key policies’.

What does the implementation of QKD look like in practice, rather than on slides?

The simplest illustration of QKD in practice is a pair of devices on either side of a link. They generate and agree on keys, and then pass them on to the system that will use them. And here’s a practical detail: QKD does not, in itself, handle ‘the entire encryption process’. It simply provides the key material. The actual encryption of the data is still carried out by a traditional security layer.

In a typical industrial architecture, QKD works with components such as:

  • Layer 2/3 encryption devices (e.g. inter-node link encryption),
  • key management systems (KMS),
  • HSM (hardware security modules),
  • PKI (for identities and certificates),
  • monitoring and logging in accordance with SOC policies.

This is important because the most common implementation failure is when someone buys ‘QKD boxes’ and then doesn’t know what to do next. In the industrial sector, the key question is: exactly where will these keys end up and what will the key lifecycle look like? How often do you replace the key? Who is authorised to use it? What happens if the quantum link fails? What does the degradation mode look like?

In practice, you always need to have a contingency plan in place for situations where QKD is temporarily unavailable. In such cases, the system either switches to conventional key distribution or halts transmission. In OT networks, ‘halting transmission’ can pose a real operational risk, so this issue must be addressed at the level of security policy, rather than ‘at the end of the implementation’.

EuroQCI: why is this crucial for Europe, and why should the industrial sector take note?

EuroQCI is an EU initiative to build a European quantum communication infrastructure. In practice, this is intended to be a network and a set of components enabling the deployment of highly secure communication links, initially mainly for government bodies and critical infrastructure. For the industrial market, it is important to note that such programmes usually establish the standard for the ‘first wave’ of implementations, after which the private sector begins to replicate this.

Why does this matter? Because in the industrial sector, investment decisions are rarely made in a vacuum. If the government and operators of critical infrastructure start to build up expertise, procedures and requirements around QKD, then technology providers, integrators and industrial operators get the message: ‘this isn’t just a pipe dream; it will be a reality in some form’. This does not mean that QKD will be everywhere. It means that a real market segment will emerge: premium connections with heightened security requirements.

It is also worth bearing in mind that EuroQCI is not just about ‘fibre optics’. It also includes a satellite component as a pathway for future long-distance connections. From an industry perspective, this is not a ready-made solution for ‘tomorrow’, but rather a strategic planning tool for operators considering cross-border connections and distributed networks.

QKD in industry: where does it make operational sense?

In practice, QKD is most useful where:

  • you have a limited number of nodes, but the links are critical,
  • the cost of a failure or breach is enormous,
  • you need long-term security,
  • You already have a fibre-optic infrastructure and a well-established security management system.

A good example is the links between:

  • the control centre and key nodes of the power grid,
  • telecommunications nodes supporting critical infrastructure,
  • key data processing centres and network management systems.

In industrial OT systems, the problem is not that someone will ‘break AES’. The problem is that someone will take control of the communications, impersonate a node, inject commands or intercept data that will then be used for sabotage. QKD adds a layer of key protection, but it still requires the rest of the architecture to be sound: segmentation, access control, monitoring, and change procedures. Without these, QKD can become an expensive add-on that makes little difference.

Where is QKD a bad idea?

It is a bad idea to try to use QKD as a ‘quick fix’ for a lack of security maturity. If an organisation has not got the basics right – identity management, access policies, robust logging, updates, and IT/OT segmentation – then adding QKD will not solve the problem. It would be like fitting a reinforced lock to a door that has no frame.

It is also a bad idea to try to scale QKD for mass deployment across hundreds or thousands of endpoints. In such cases, the software-based approach – namely post-quantum cryptography – usually comes out on top, as it can be implemented more quickly and cheaply on a large scale.

QKD vs PQC – how can this be realistically implemented in industry?

In industrial practice, there is no choice between ‘quantum communication or post-quantum cryptography’. This is a false dichotomy that stems mainly from oversimplified narratives. QKD and PQC address different problems at different levels and, in a well-designed security strategy, complement rather than compete with one another.

PQC operates at the algorithmic level. This is a natural direction for large-scale, distributed, software-based systems with devices that have a long lifecycle. It can be implemented via updates, it can be tested in laboratories, and it can be scaled without replacing the infrastructure. From an industry perspective, this will be a key pillar of the migration to a ‘quantum-safe’ world, simply because it is practical.

QKD comes into its own where algorithms are no longer sufficient. Where the cost of a breach is extremely high, where the number of connections is limited, and where key security is of strategic importance. It is not a technology ‘for everyone’, but a tool for very specific applications. And it is precisely in this role that it makes sense.

Why isn’t quantum communication a magic bullet?

One of the biggest misconceptions when discussing QKD is the idea that, because it is based on physics, it ‘solves the security problem’. It does not. It merely addresses one aspect of it. The rest of the system remains: people, procedures, access, configuration, updates, network segmentation and incident response.

This is particularly important in the industrial sector, as many OT systems fail not because of cryptographic breaches, but due to operational errors, poor design decisions or a lack of control over what is actually happening on the network. QKD will not fix architectural chaos. It can strengthen a well-designed system, but it will not save a poorly designed one.

That is why, where QKD is implemented sensibly, it is done so as part of a larger whole, rather than as a standalone ‘security product’. If someone tries to sell quantum communication as a ready-made solution to all threats, it is usually a red flag rather than an innovation.

What does this mean for industry right now?

The most sensible approach for industry is to treat quantum communication as a niche but strategic technology. Not for mass deployment, not for ‘securing everything’, but for specific locations where the security of key transmission is of paramount importance and where the infrastructure already supports such solutions.

At the same time, the vast majority of systems should be preparing to migrate towards PQC, as this is a viable, scalable and incomparably cheaper option to maintain. In the long term, it is precisely this combination of the two approaches that will define what ‘quantum-safe’ actually means in an industrial setting.

If we look at it dispassionately and without futuristic promises, quantum communication is not a revolution, but a specialist tool. It is extremely powerful within a narrow scope, but requires technical and organisational maturity. And that is precisely why it is worth discussing it in an industrial context – not as a miracle, but as another piece of the engineering puzzle.

Summary

Quantum communication in industry only makes sense if it is treated as a carefully selected tool for protecting specific, critical links, rather than as a universal solution to all security problems. In practice, a viable ‘quantum-safe’ strategy is built by combining a mature IT/OT architecture, the widespread use of post-quantum cryptography, and the targeted use of QKD where long-term key protection is of strategic importance and justifies the cost and complexity of the infrastructure.

0 comments
Oldest
Newest