Quantum Solutions to Q-Day, or: Quantum Secure Direct Communications for Quantum Security beyond QKD

Quantum Solutions to Q-Day, or: Quantum Secure Direct Communications for Quantum Security beyond QKD

By Dr. Bruno Avritzer

All opinions expressed here are my own and do not necessarily represent the positions of Leidos or the QED-C.


Chaos. Anarchy. Armageddon. These are the types of scary words used to drive the push for cryptographic migration ahead of Q-Day. The truth is, it is scary. The prospect of losing trust in our cryptographic systems is scary and has unimaginable ramifications, including loss of security in bank transactions, cryptocurrencies, channels with national security implications and more. Q-Day is an event representing a need to fundamentally rethink security and privacy in our nation’s communication networks and systems.

What is Q-Day?

But what is Q-Day? Q-Day represents the “day” that quantum computers, i.e. devices which perform computations by manipulating not binary data but the states of quantum systems like atoms or photons, become powerful and reliable enough to break commonly-used cryptographic primitives such as 256-bit elliptic curve cryptography schemes and RSA-2048. It is sometimes also known as Y2Q, in analogy to the Y2K enterprise data concerns of the turn of the millennium. Though there are similarities in reach, scope, and impact between the two events, there are also key differences. Y2K was a large-scale data storage format issue that would trigger on a definite date, January 1, 2000. By contrast, no one knows when quantum computing technology will reach the point of maturity that brings on Q-Day. Downstream of this, while Y2K largely did not result in significant disruptions due to active mitigation efforts and planning ahead of 2000, businesses and agencies don’t know when that “cryptographically-relevant” quantum computer will come into existence and thus face uncertainty on migration timelines and even methodologies. Further complicating this is the emergence of new quantum computing technologies, such as neutral atom-based systems, which have the potential to significantly accelerate Q-Day timelines, and the increasingly rapid scale of technological advances in this area driven by the power of new AI systems, which make estimating these timelines increasingly challenging. Coupled with the increasing disparity in data security investment across businesses and agencies, it is easy to imagine a large-scale disruption resulting from Q-Day.

Is PQC enough?

How should security-conscious enterprises mitigate the risks from Q-Day? The traditional guidance has been to transition to “post-quantum cryptographic” (PQC) primitives, such as ML-KEM and a number of other standards approved by NIST in 2024. These algorithms are thought to be resilient against attacks from quantum computers, but most candidate algorithms were invented within the last 20 years. Some of them have already been shown to be vulnerable during NIST’s selection stage, such as SIKE, GeMSS, and Rainbow. The others, such as ML-KEM, haven’t been proven secure, which is why crypto-agility is so emphasized nowadays – so that if one of these algorithms upon which our data security rests is found to be vulnerable, the world can quickly migrate its data encryption standards to another algorithm which remains safe. PQC leaves data vulnerable to Harvest Now Decrypt Later (HNDL) attacks if the deployed encryption algorithm is broken, but most data is not valuable enough to be harvested and sifted through at scale and, even if not, may not hold value on the timescales that these attacks are thought to be vulnerable. Therefore, for most organizations PQC standards and crypto-agility will likely be a “good enough” solution to the threat posed by Q-Day. For especially security-conscious organizations, however, the algorithmic security provided by PQC may not be enough. In these cases, that algorithmic encryption can be supplemented by “physical-layer” encryption which uses physics (as opposed to algorithms) to make data difficult or impossible to read.

Security from the physical layer

Often, we think about data entirely in the digital domain, and forget that it is transmitted through our networks by data carriers. Whether those are electrons, optical signals, or carrier pigeons, that physical layer provides another tool of security against hostile actors. For example, if information is transmitted at a frequency different than what can be received by an adversarial detector, that data is secure, due to physics (until the adversary brings a different detector). Telemetry also provides a safeguard that can detect different types of attacks. The ultimate version of this is quantum encryption, which can generate encryption keys like those generated by PQC algorithms, by using measurements in quantum optics devices. That procedure contains a built-in telemetry that, if implemented properly, can’t be circumvented by any type of clever scheme, guaranteeing unconditional security of the generated keys.

  Algorithmic
RSA – based on difficulty of factoring a product of primes
Physical
Spread spectrum – based on spreading signals over a wide frequency band
Quantum
QKD – physical encoding with added quantum security properties
Security properties Strong (unconditional assuming hardness of some computational problem) Medium (nothing stopping an eavesdropper from guessing the right frequencies except technical difficulty) Unconditional or very strong (entanglement-based QKD is truly unconditionally secure, other implementations may have vulnerabilities)
Overhead High – compute intensive High – bespoke hardware overhead Very high – bespoke hardware and nonstandardized algorithm implementation
Implementation Simple, done at data layer Complex, requires specific hardware implementations Very complex, requires highly sensitive bespoke hardware
Use cases Almost every encryption/key exchange in the world Military, tactical networks, RF comms Mostly banks or ultra-secure networks
Attacks Quantum attacks – require a “cryptographically-relevant” quantum computer RF signal interception – difficult but possible For unentangled – physical layer eavesdropping (photon number splitting attack, detector blinding attack, etc.)

Algorithmic vs. physical encryption.

This comes with a cost. Quantum key distribution (QKD) hardware is bespoke and not often standards-conforming. It also requires rethinking key management systems, which means a network with heterogeneous security solutions must now incorporate key sources from multiple potential layers of the network stack. Finally, device-independent QKD systems, the holy grail of set-it-and-forget-it QKD security, are not commercially available today (to the best of my knowledge). The systems we have today can be very difficult to secure against side-channel attacks in an operational setting, while still being very costly to integrate.

Quantum Secure Direct Communication

A promising emerging alternative is Quantum Secure Direct Communication (QSDC). This quantum hardware solution does not generate keys using quantum physics, but instead encrypts data directly into quantum photons generated by quantum devices. This allows for similarly strong guarantees of quantum security as what QKD provides, but also allows composable security with PQC standards (since there is only one source of keys) and easier integration since it is a simpler replacement of optical network terminals (ONTs) instead of a complete rehaul of key generation in secure networks. This technology is highly underexplored, and as a result not well standardized either, with both discrete-variable (DV) and continuous-variable (CV) solutions possible for both QSDC and QKD. CV systems generally suffer from worse data rates and distances but have considerable advantages in terms of cost.

Scatter plot of the quantum security landscape positioning DV QSDC, CV QSDC, DV QKD, and CV QKD vendors by device cost (vertical axis) against integration cost (horizontal axis).

The quantum security landscape, plotted by device cost against integration cost.

A closely related idea is the “quantum alarm system”, which is a quantum telemetry layer that is (for example) wavelength demultiplexed from the classical communication source. This alarm layer attempts to detect physical layer eavesdropping using sensitive measurements based on qubit information. Quantum alarms have weaker security guarantees than QKD and QSDC since they are primarily a detection rather than encryption mechanism, but the significant advantage of higher throughput (since the communication happens in the standard classical source layer).

How do these systems work?

There are many, many implementations of both quantum alarm and QSDC systems based on different physical properties of photons, but a personal favorite is the ZXFZ QSDC protocol invented some 20 years ago. In this protocol, a large number of entangled photon pairs are generated, each pair of photon 1 and photon 2 being so strongly correlated that it can be thought of as one single object. The “physics” implication of this is that one of the photons of each pair contains no information on its own – both must operate together as a unit to read any information out (but surprisingly, not to write it in). To securely transmit information, Alice applies a random variable delay to each generated pair, so that each photon 1 is decorrelated from its corresponding photon 2. Alice then transmits every photon 1 and photon 2 to Bob, writing information into half of the photon 1s and leaving the other half blank. Alice finally announces to Bob which photon 1s are blank, which allows him to perform telemetry and see if they have been tampered with. If they have, Bob throws out the photons. If not, Bob tells Alice and she tells him how to correlate the rest of the photon 1s with photon 2s, allowing him to read out the information. The key is that until this last step happens, an eavesdropper would have to guess which photon 1s are correlated with which photon 2s to get information out, which without seeding the random time delays becomes exponentially difficult as the number of photon pairs increases. Thus, we get powerful quantum security guarantees without having to rethink how we generate keys in our system. Quantum alarms also offer an attractive alternative of higher rate communications in exchange for weaker telemetry and security guarantees.

The quantum security landscape is tense and ever-evolving, but a mixed stack of PQC + quantum secure direct communications is a promising concept to address the security issues brought about by Q-Day, especially to ensure homogeneity in key standards across a network with heterogeneous risk profiles. For nearly all organizations, however, PQC and crypto-agility are the most important components of this transition, and should be addressed as soon as practical.

Tipping Point: Global IPv6 Traffic Crosses the 50% Threshold on Google

The Tipping Point: Global IPv6 Traffic Crosses the 50% Threshold on Google

For over two decades, the transition to IPv6 was often described as a “looming necessity”—a project relegated to the bottom of the priority list, overshadowed by the immediate demands of digital transformation. That era has officially ended.

In October 2025, a critical milestone was reached: for the first time, IPv6 traffic on Google’s web properties globally surpassed the 50% threshold.

This is more than just a statistical curiosity. For CTOs, network engineers, and IT decision-makers, it represents a fundamental shift in the architecture of the Internet and what the “new normal” is. We are no longer living in a dual-stack world where IPv6 is the “backup” protocol; we have entered the age of IPv6 dominance, where connectivity over IPv4 increasingly represents a legacy service.

The Necessity of the Transition

The drivers behind this shift are clear and unforgiving. The pool of available IPv4 addresses has been depleted for years, creating a secondary market where the cost of a single address has skyrocketed. While prices show signs of stabilization, this has nevertheless become a significant tax on business growth.

Beyond cost, the operational complexity of managing Carrier Grade NAT (CGN) to stretch existing IPv4 assets has become a source of latency, technical debt, and security vulnerabilities. “Secondhand” IPv4 addresses may be blocked by some networks, rate-limited on some services, listed in spam blacklists, and suffer from geolocation issues, resulting in additional management complexity.

IPv6 is not merely about “more addresses.” It is about restoring the end-to-end integrity of the Internet. With 128-bit addressing, we move from the scarcity-driven mindset of the 32-bit era to a freedom of address space. This enables hierarchical network designs, simplified routing tables, and the scalability required for the AI and cloud-native era.

A Historical Perspective: From Edge to Core

The journey to 50% was long and non-linear. Initially, adoption was driven by ISPs and wholesale Internet carriers who faced immediate pressure to connect billions of new devices.

By the mid-2010s, content providers such as Google, Meta, and Akamai led the next wave, ensuring their services were reachable over the next-generation protocol.

Today, the momentum has shifted to the enterprise and cloud sectors. As major cloud providers such as AWS increasingly promote IPv6-first architectures in newer service offerings and cloud-native environments, even traditionally lagging enterprises are accelerating their IPv6 adoption.

The milestone seen by Google is the ultimate barometer of this progress: it reflects the aggregate behavior of billions of users across every continent and industry.

The Significance of the Google Signal

Why does the 50% mark on Google matter so much?

Google’s statistics are widely considered one of the most useful indicators of global IPv6 adoption because they represent real-world traffic from a diverse array of countries, client devices, and networks.

Reaching 50% means that the tipping point has been passed. In any technology transition, the middle of the curve is where momentum becomes self-sustaining. From here, the cost and complexity of maintaining legacy IPv4-only systems will only increase.

The Road Ahead: IPv6-Mostly and Beyond

As we look beyond 2026, the industry is moving from dual-stack architectures, where both protocols run in parallel, toward IPv6-mostly deployments.

Technologies such as DHCP Option 108 allow networks to signal to clients that they can operate IPv6-only, using translation mechanisms such as CLAT only when legacy IPv4 access is strictly necessary.

Large ISPs can increasingly move IPv4 resources to the network border, improving efficiency and reducing operational costs.

This glide path allows organizations to begin decommissioning legacy infrastructure today without breaking compatibility.

Strategic Call to Action

For decision-makers, the time for “wait and see” is over. To ensure infrastructure remains competitive, scalable, and secure, we recommend three immediate actions:

1. Adopt an IPv6-Mostly Strategy

Audit internal and edge networks to implement DHCP Option 108. This prioritizes IPv6-native traffic while providing a safe fallback for legacy applications.

2. Modernize Procurement Policies

Mandate that all new hardware, software, and cloud services be IPv6-first. Avoid technical debt by refusing to purchase equipment that requires legacy NAT workarounds.

3. Optimize Cloud-Native Workloads

Transition cloud infrastructure to use IPv6-native networking. This reduces costs associated with IPv4 address leasing and improves the performance of modern distributed applications.

The 50% milestone is a celebration of our collective progress, but it is also a starting gun. The next 50% will move much faster.

References