Quantum Solutions to Q-Day, or: Quantum Secure Direct Communications for Quantum Security beyond QKD
By Dr. Bruno Avritzer
All opinions expressed here are my own and do not necessarily represent the positions of Leidos or the QED-C.
Chaos. Anarchy. Armageddon. These are the types of scary words used to drive the push for cryptographic migration ahead of Q-Day. The truth is, it is scary. The prospect of losing trust in our cryptographic systems is scary and has unimaginable ramifications, including loss of security in bank transactions, cryptocurrencies, channels with national security implications and more. Q-Day is an event representing a need to fundamentally rethink security and privacy in our nation’s communication networks and systems.
What is Q-Day?
But what is Q-Day? Q-Day represents the “day” that quantum computers, i.e. devices which perform computations by manipulating not binary data but the states of quantum systems like atoms or photons, become powerful and reliable enough to break commonly-used cryptographic primitives such as 256-bit elliptic curve cryptography schemes and RSA-2048. It is sometimes also known as Y2Q, in analogy to the Y2K enterprise data concerns of the turn of the millennium. Though there are similarities in reach, scope, and impact between the two events, there are also key differences. Y2K was a large-scale data storage format issue that would trigger on a definite date, January 1, 2000. By contrast, no one knows when quantum computing technology will reach the point of maturity that brings on Q-Day. Downstream of this, while Y2K largely did not result in significant disruptions due to active mitigation efforts and planning ahead of 2000, businesses and agencies don’t know when that “cryptographically-relevant” quantum computer will come into existence and thus face uncertainty on migration timelines and even methodologies. Further complicating this is the emergence of new quantum computing technologies, such as neutral atom-based systems, which have the potential to significantly accelerate Q-Day timelines, and the increasingly rapid scale of technological advances in this area driven by the power of new AI systems, which make estimating these timelines increasingly challenging. Coupled with the increasing disparity in data security investment across businesses and agencies, it is easy to imagine a large-scale disruption resulting from Q-Day.
Is PQC enough?
How should security-conscious enterprises mitigate the risks from Q-Day? The traditional guidance has been to transition to “post-quantum cryptographic” (PQC) primitives, such as ML-KEM and a number of other standards approved by NIST in 2024. These algorithms are thought to be resilient against attacks from quantum computers, but most candidate algorithms were invented within the last 20 years. Some of them have already been shown to be vulnerable during NIST’s selection stage, such as SIKE, GeMSS, and Rainbow. The others, such as ML-KEM, haven’t been proven secure, which is why crypto-agility is so emphasized nowadays – so that if one of these algorithms upon which our data security rests is found to be vulnerable, the world can quickly migrate its data encryption standards to another algorithm which remains safe. PQC leaves data vulnerable to Harvest Now Decrypt Later (HNDL) attacks if the deployed encryption algorithm is broken, but most data is not valuable enough to be harvested and sifted through at scale and, even if not, may not hold value on the timescales that these attacks are thought to be vulnerable. Therefore, for most organizations PQC standards and crypto-agility will likely be a “good enough” solution to the threat posed by Q-Day. For especially security-conscious organizations, however, the algorithmic security provided by PQC may not be enough. In these cases, that algorithmic encryption can be supplemented by “physical-layer” encryption which uses physics (as opposed to algorithms) to make data difficult or impossible to read.
Security from the physical layer
Often, we think about data entirely in the digital domain, and forget that it is transmitted through our networks by data carriers. Whether those are electrons, optical signals, or carrier pigeons, that physical layer provides another tool of security against hostile actors. For example, if information is transmitted at a frequency different than what can be received by an adversarial detector, that data is secure, due to physics (until the adversary brings a different detector). Telemetry also provides a safeguard that can detect different types of attacks. The ultimate version of this is quantum encryption, which can generate encryption keys like those generated by PQC algorithms, by using measurements in quantum optics devices. That procedure contains a built-in telemetry that, if implemented properly, can’t be circumvented by any type of clever scheme, guaranteeing unconditional security of the generated keys.
| Algorithmic RSA – based on difficulty of factoring a product of primes |
Physical Spread spectrum – based on spreading signals over a wide frequency band |
Quantum QKD – physical encoding with added quantum security properties |
|
|---|---|---|---|
| Security properties | Strong (unconditional assuming hardness of some computational problem) | Medium (nothing stopping an eavesdropper from guessing the right frequencies except technical difficulty) | Unconditional or very strong (entanglement-based QKD is truly unconditionally secure, other implementations may have vulnerabilities) |
| Overhead | High – compute intensive | High – bespoke hardware overhead | Very high – bespoke hardware and nonstandardized algorithm implementation |
| Implementation | Simple, done at data layer | Complex, requires specific hardware implementations | Very complex, requires highly sensitive bespoke hardware |
| Use cases | Almost every encryption/key exchange in the world | Military, tactical networks, RF comms | Mostly banks or ultra-secure networks |
| Attacks | Quantum attacks – require a “cryptographically-relevant” quantum computer | RF signal interception – difficult but possible | For unentangled – physical layer eavesdropping (photon number splitting attack, detector blinding attack, etc.) |
Algorithmic vs. physical encryption.
This comes with a cost. Quantum key distribution (QKD) hardware is bespoke and not often standards-conforming. It also requires rethinking key management systems, which means a network with heterogeneous security solutions must now incorporate key sources from multiple potential layers of the network stack. Finally, device-independent QKD systems, the holy grail of set-it-and-forget-it QKD security, are not commercially available today (to the best of my knowledge). The systems we have today can be very difficult to secure against side-channel attacks in an operational setting, while still being very costly to integrate.
Quantum Secure Direct Communication
A promising emerging alternative is Quantum Secure Direct Communication (QSDC). This quantum hardware solution does not generate keys using quantum physics, but instead encrypts data directly into quantum photons generated by quantum devices. This allows for similarly strong guarantees of quantum security as what QKD provides, but also allows composable security with PQC standards (since there is only one source of keys) and easier integration since it is a simpler replacement of optical network terminals (ONTs) instead of a complete rehaul of key generation in secure networks. This technology is highly underexplored, and as a result not well standardized either, with both discrete-variable (DV) and continuous-variable (CV) solutions possible for both QSDC and QKD. CV systems generally suffer from worse data rates and distances but have considerable advantages in terms of cost.

The quantum security landscape, plotted by device cost against integration cost.
A closely related idea is the “quantum alarm system”, which is a quantum telemetry layer that is (for example) wavelength demultiplexed from the classical communication source. This alarm layer attempts to detect physical layer eavesdropping using sensitive measurements based on qubit information. Quantum alarms have weaker security guarantees than QKD and QSDC since they are primarily a detection rather than encryption mechanism, but the significant advantage of higher throughput (since the communication happens in the standard classical source layer).
How do these systems work?
There are many, many implementations of both quantum alarm and QSDC systems based on different physical properties of photons, but a personal favorite is the ZXFZ QSDC protocol invented some 20 years ago. In this protocol, a large number of entangled photon pairs are generated, each pair of photon 1 and photon 2 being so strongly correlated that it can be thought of as one single object. The “physics” implication of this is that one of the photons of each pair contains no information on its own – both must operate together as a unit to read any information out (but surprisingly, not to write it in). To securely transmit information, Alice applies a random variable delay to each generated pair, so that each photon 1 is decorrelated from its corresponding photon 2. Alice then transmits every photon 1 and photon 2 to Bob, writing information into half of the photon 1s and leaving the other half blank. Alice finally announces to Bob which photon 1s are blank, which allows him to perform telemetry and see if they have been tampered with. If they have, Bob throws out the photons. If not, Bob tells Alice and she tells him how to correlate the rest of the photon 1s with photon 2s, allowing him to read out the information. The key is that until this last step happens, an eavesdropper would have to guess which photon 1s are correlated with which photon 2s to get information out, which without seeding the random time delays becomes exponentially difficult as the number of photon pairs increases. Thus, we get powerful quantum security guarantees without having to rethink how we generate keys in our system. Quantum alarms also offer an attractive alternative of higher rate communications in exchange for weaker telemetry and security guarantees.
The quantum security landscape is tense and ever-evolving, but a mixed stack of PQC + quantum secure direct communications is a promising concept to address the security issues brought about by Q-Day, especially to ensure homogeneity in key standards across a network with heterogeneous risk profiles. For nearly all organizations, however, PQC and crypto-agility are the most important components of this transition, and should be addressed as soon as practical.
