Abstract
The aim of this article is to provide a simple and accessible overview of the journey that begins with the fundamental concepts of quantum mechanics and leads to one of its most important applications: secure communications and cryptography. We begin with the concern that future quantum computers may be capable of breaking today’s cryptographic locks, and build upon an intriguing idea: using the laws of nature themselves to protect information.
Quantum Cryptography: When Security Is Built on the Laws of Nature, Not Mathematical Difficulty
You send an encrypted message, and an unknown passerby intercepts it somewhere along the way. Unable to decrypt it, they are forced to archive it. Ten or twenty years later, they gain access to a tool capable of breaking today’s cryptographic locks, and they begin reading through the archive of old communications one by one. Security experts refer to this scenario as “Harvest Now, Decrypt Later.” This concern is one of the main reasons quantum cryptography is being taken seriously today.
But this field is not merely a response to the threat posed by quantum computers. Its fundamental idea is more ambitious: instead of basing security on the “difficulty of a mathematical problem,” we can build it upon one of the fundamental laws of physics. This article explains, step by step, how this idea works, where it is effective, where its limitations lie, and how it relates to the Quantum Internet.
1. Why Are Today’s Cryptographic Systems Concerned About Quantum Computers?
Modern cryptography rests on two pillars. The first is symmetric cryptography, such as AES. In this approach, the sender and receiver share a common key, and the same key is used both to encrypt and decrypt the message. This method is fast and powerful, but it leaves one important question unanswered: how can two parties who have never met exchange that shared key, and through which secure channel?
The answer comes from the second pillar: asymmetric cryptography, such as RSA and elliptic-curve cryptography. In this approach, each user has a public key that can be freely distributed and a private key that never leaves their possession. This is the mechanism behind the familiar lock symbol next to the address of secure websites, and it is used billions of times every day across the Internet.
The important point is that the security of asymmetric cryptography relies on an assumption: certain mathematical problems, such as factoring a very large integer into its prime factors, are practically infeasible for conventional computers. Multiplying two large prime numbers is easy, but recovering those two prime factors from their product, at today’s scale, can take decades. So far, this assumption has held up well.
In 1994, Peter Shor showed that a sufficiently large, fault-free quantum computer could solve these same problems in a reasonable amount of time. The consequence is clear: if such a machine is built, RSA and elliptic-curve cryptography would no longer be secure. The situation is much more encouraging for symmetric cryptography. Grover’s algorithm provides only a square-root speedup for search, which represents a limited advantage that can be compensated for. For this reason, symmetric ciphers with sufficiently long keys, such as AES-256, are still considered secure.
Therefore, what is at risk is public-key cryptography and key exchange—not cryptography as a whole. Quantum cryptography seeks to shift the foundation of this security from an “assumption of computational difficulty” to a “law of nature.”
Two points should also be stated honestly. First, a large-scale, fault-tolerant quantum computer does not yet exist, so today’s concern is a future-oriented threat rather than an immediate breakdown. Second, quantum cryptography is not the only possible response. Post-quantum cryptography is another path that uses classical algorithms designed to withstand quantum attacks, although it still relies on the computational difficulty of mathematical problems.
2. Four Quantum Ideas You Need to Understand This Story
Qubit: A Bit That Hasn’t Made Up Its Mind Yet
A classical bit is either zero or one, like a switch that is either on or off. The state of a qubit can be described as a combination, or superposition, of two possibilities. This is often simplified by saying that a qubit is “both zero and one,” but a more precise interpretation is that a qubit is a state that determines the probabilities of future measurement outcomes. When measured, only one of the two possible outcomes is observed, and the state itself determines the probability with which each outcome appears.
For a physical picture, consider the simplest qubit: the polarization of a photon. Light is an electromagnetic wave, and its electric field oscillates in a specific direction perpendicular to its direction of propagation. That direction is the polarization. The glass in polarized sunglasses acts as a polarizing filter that allows only light oscillating along a particular direction to pass through. The behavior of a photon encountering such a filter is as follows:
A photon with vertical polarization passes through a vertical filter with complete certainty and never passes through a horizontal filter.
If the same photon encounters a 45-degree filter, the outcome is completely random: it passes through with a probability of 50% and is absorbed with a probability of 50%. There is no hidden information that determines the outcome in advance of the photon reaching the filter.
Measurement Changes the State
In classical physics, one can, in principle, “watch” something without disturbing it. The quantum world does not offer this privilege. A photon that has passed through a 45-degree filter is now itself polarized at 45 degrees, and the fact that it was previously vertically polarized is permanently lost.
A simple experiment makes this point intuitive. Place two filters, one vertical and one horizontal, one after the other. No light passes through both. Now insert a third filter at a 45-degree angle between them. Although the new filter only blocks light and does not add anything to it, some light now passes through the entire arrangement. The explanation is that the middle filter rewrites the polarization of the light. Photons that pass through it are no longer “vertical”; they are now polarized at 45 degrees and therefore have a chance of passing through the horizontal filter. Every measurement does not merely extract information; it also rewrites the state.
Measurement can be thought of as “asking a question,” and the type of question is called the basis—for example, “Is it vertical or horizontal?” versus “Is it at 45 or 135 degrees?” If the measurement basis matches the way the photon was prepared, the answer is definite. If it does not match, the result is random and the original state cannot be recovered.
The consequence is that no one can simply “look at” an unknown quantum state and leave it completely untouched. This is the most important idea underlying quantum cryptography. If an eavesdropper chooses the wrong basis, they obtain a random result, while a disturbed photon reaches the destination. This disturbance appears as errors in the communication between the two legitimate parties, leaving evidence of the interception.
Cloning Is Forbidden (No-Cloning)
In the classical world, copying data is almost free and leaves no trace. Someone who connects to your cable can copy the signal, and you may never find out. The No-Cloning Theorem states that this is impossible for unknown quantum states: there is no device capable of making a perfect copy of an arbitrary unknown quantum state.
The security consequence of this theorem is direct. An eavesdropper cannot copy a photon, perform experiments on their own copy at leisure, and then send the original to the destination untouched. To learn anything, they must measure the photon itself, and measurement, as we have seen, changes it.
It is important to note that the theorem does not prohibit measurement. What it prohibits is obtaining information while preserving the original quantum state completely undisturbed.
Entanglement
Two particles can be prepared in such a way that they cannot be described independently of one another; only the joint system has a well-defined state. Measurements of these particles reveal correlations that have no straightforward classical explanation, even when the particles are separated by enormous distances.
The common analogy of “two gloves placed in separate boxes” is inadequate. If the result had simply been “written” in advance into each particle, experiments would not produce correlations as strong as those that are actually observed.
However, this phenomenon should not be confused with instantaneous communication. Each party, considered individually, sees only a sequence of completely random results, and no message can be extracted from those results alone. The correlation becomes visible only when the two parties compare their results, and that comparison takes place through an ordinary communication channel that cannot transmit information faster than light.
Entanglement is raw material, not a faster-than-light telephone line. This raw material forms the foundation of the E91 protocol, quantum teleportation, and the concept of a Quantum Internet.
The Exception That Makes the Rule More Precise: Non-Demolition Measurement
Conventional photon detectors “see” a photon by absorbing it: the photon transfers its energy to the detector and ceases to exist. But physicists also know of another approach called Quantum Non-Demolition (QND) measurement. In this method, the photon interacts very subtly with an auxiliary system, such as a particular atom or an optical cavity, and the auxiliary system records evidence of the photon’s presence without absorbing it.
In this way, for example, it is possible to determine how many photons are contained in an optical pulse while allowing that same pulse to continue along its path intact.
This does not contradict the rule that “measurement changes the state.” Rather, it clarifies the precise limit of that rule. A non-demolition measurement can measure a specific quantity—for example, photon number—without disturbing that quantity, while necessarily disturbing complementary quantities.
If the encryption is encoded in the photon’s polarization and the eavesdropper measures only the photon number, the polarization remains intact. But any measurement that reveals information about the encrypted information itself necessarily changes the quantum state.
This distinction forms the basis of one of the best-known theoretical attacks against quantum cryptography. Practical transmitters typically send very weak optical pulses rather than individual photons, and sometimes a pulse contains more than one photon.
In a Photon-Number-Splitting (PNS) attack, the eavesdropper uses a non-demolition measurement to determine the number of photons in a pulse. If a pulse contains multiple photons, the eavesdropper takes one and sends the remaining photons to the destination. They keep their photon without measuring its polarization until the sender and receiver publicly announce the correct measurement basis over a public channel. The eavesdropper then measures their photon in the same basis and reads the key without introducing an error.
They block single-photon pulses, and because channel loss can occur naturally at any time, the resulting reduction in the number of photons does not necessarily appear suspicious.
This attack relies on imperfections in the equipment, not weaknesses in the laws of quantum mechanics. The standard countermeasure is the use of decoy states: the sender randomly transmits pulses with different intensities, and the statistics of their arrival at the receiver reveal the eavesdropper’s intervention.
It is worth noting that carrying out a fully effective version of this attack is extremely difficult with today’s technology. Nevertheless, the security of a protocol must be proven against everything that the laws of physics allow—not merely against what is technically feasible today.
Entanglement: From a Philosophical Dispute to a Technological Resource
Entanglement was not introduced by physicists to build technology. Rather, critics of quantum mechanics brought it into the discussion to demonstrate what they believed was a flaw in the theory.
The story began in the 1920s. Quantum mechanics was still taking shape, and its practical successes were undeniable. Yet its interpretation—particularly the idea that measurement outcomes are intrinsically probabilistic—was unsettling to many of its founders.
Albert Einstein, himself one of the pioneers of the theory, rejected this intrinsic randomness. The famous phrase “God does not play dice” is attributed to him in this context. For years, he and Niels Bohr debated whether quantum mechanics provided a complete description of reality.
The 1935 Paper: The Paradox That Was Supposed to Bring the Theory Down
In 1935, Einstein, together with Boris Podolsky and Nathan Rosen, published a paper that became known as EPR, after the initials of their surnames.
Their argument was straightforward. Prepare two particles in such a way that their properties are correlated, and then separate them. Now, by measuring the first particle, you can predict the result of a measurement on the second particle with complete certainty, without touching the second particle.
Einstein and his colleagues took two principles for granted. First, if something can be predicted with certainty and without disturbing it, then that property must have existed in the particle before the measurement. Second, an event at a distant location cannot instantaneously affect another particle.
Their conclusion was that because quantum theory did not include these pre-existing properties in its description, it must be incomplete. There had to be a deeper theory that incorporated them.
Bohr responded that same year, arguing that the two particles should not be described as separate and independent systems. Nevertheless, the philosophical debate remained, and most physicists—occupied with the practical applications of the theory—largely ignored it.
Naming the Phenomenon and the “Spooky” Effect
Erwin Schrödinger, who was deeply engaged with the questions raised by EPR, wrote a paper that same year and gave this connection a name: “Verschränkung” in German, which he translated as “entanglement.”
He regarded it not merely as one property of quantum mechanics, but as the defining feature that distinguished quantum mechanics from classical physics.
Einstein, however, was not pleased. Years later, in a letter to Max Born, he referred to it as “spooky action at a distance.” The expression remains common in popular accounts today, although, as we have seen, entanglement does not allow messages to be transmitted faster than light.
Bell’s Theorem: A Game That Puts Nature to the Test
For more than thirty years, the EPR question remained largely a philosophical dispute because it appeared that no experiment could distinguish between “quantum theory” and “a deeper theory with pre-existing properties.”
In 1964, John Bell, an Irish physicist, showed that such a test was possible. His idea can be explained without equations.
Bell’s idea can be framed as a game. Two players, Alice and Bob, sit in separate, closed rooms far apart from each other, with no means of communicating. Before they separate, they can agree on any strategy or plan they like. After that, however, each must make their decisions independently.
In each round of the game, the following happens:
- The referee gives Alice a “question” that is either zero or one, and gives Bob another question that is also either zero or one. Both questions are completely random and independent of each other.
- Without knowing the other player’s question, each player announces a “response” that is either zero or one.
- The referee compares the two responses and determines whether they have won or lost.
The winning rule is simple: the two responses must be the same, except when both questions are one; in that case, the responses must be different. The table below shows the four possible cases.
Alice | Bob | Winning Answers |
0 | 0 | Be the Same |
0 | 1 | Be the Same |
1 | 0 | Be the Same |
1 | 1 | Be Different |
Table 1: Bell's idea formed as a game.
The Best Strategy Without Entanglement
If the players are allowed to make only predetermined agreements, how high can their success rate be? The simplest way to find the answer is to imagine that they both know in advance what to say for every possible question: Alice knows what to answer when she receives question 0 and what to answer when she receives question 1, and Bob does the same. We then ask whether it is possible to win all four cases in the table. To win the first three rows, Alice’s answer to question 0 must be equal to Bob’s answer to question 0; Bob’s answer to question 1 must also be equal to that same answer; and Alice’s answer to question 1 must likewise be the same. In other words, all four answers must be identical. But the fourth row requires Alice’s and Bob’s answers to question 1 to be different, which is inconsistent with the chain of equalities above. Therefore, with any predetermined agreement, at least one of the four cases must be lost, and at best, three out of four cases can be won: 75%.
Playing randomly or using randomization does not change anything, because any randomized strategy is effectively a mixture of several deterministic strategies and cannot outperform the best one. This is essentially what Einstein and his colleagues had in mind: if the particles carry an “instruction set” from the beginning that determines the outcome of every measurement—like a pair of gloves in which one is predetermined to be right-handed and the other left-handed—then such an instruction set is equivalent to the same kind of predetermined agreement and is subject to the 75% ceiling.
When the Players Have Entangled Particles
Now suppose Alice and Bob prepare a pair of entangled photons before separating, with each taking one photon. The steps of the game remain the same, except that after receiving their respective questions, each player passes their photon through a polarizing filter. Question 0 means, “Set the filter to this angle,” while question 1 means, “Set the filter to the other angle.” The answer is determined as follows: if the photon passes through, the answer is 0; if it is absorbed, the answer is 1. In the standard experimental setup, Alice chooses between angles of 0° and 45°, while Bob chooses between 22.5° and 67.5°.
Neither player sees any pattern in their individual results: each always observes a completely random sequence. But when the results from thousands of rounds are compared, Alice’s and Bob’s answers are correlated so strongly that the winning rate reaches about 85%, something that is impossible with any predetermined agreement. In other words, entanglement is something more than a pair of “predetermined gloves.”
Three points should be kept in mind:
· The players cannot send messages. If they could, winning all four cases would be easy. Entanglement does not enable communication; it only creates correlations that go beyond what predetermined agreements can produce.
· The questions must be chosen randomly after the particles have been separated. If the choice of angle were known in advance, the particles could simply carry instructions tailored to those particular angles. This is why serious experiments make the choices at the last possible moment, using fast random-number generators.
· This is an experimental test, not a philosophical argument. The prediction of 75% versus 85% can be tested in the laboratory, and measurements have repeatedly favored quantum mechanics.
Experiments: Nature Answers
The first experiments were carried out in the 1970s by John Clauser and Stuart Freedman, and the results favored quantum mechanics. In the early 1980s, Alain Aspect performed more convincing experiments by rapidly changing the orientation of the filters while the photons were in flight. Later, in 2015, several independent groups carried out experiments that simultaneously closed the main loopholes raised by critics. One of these groups worked with electrons in diamonds at two locations at Delft University. In 2022, the Nobel Prize in Physics was awarded to Clauser, Aspect, and Anton Zeilinger for these experiments and for pioneering quantum information science. In other words, what Einstein regarded as a sign of a flaw in the theory has today become one of the most thoroughly tested features of nature.
From Paradox to a Tool
What makes this story important for cryptography is that Bell’s test can also serve as a security tool. In 1991, Artur Ekert showed that entangled particles could be used to generate a key, with the sender and receiver using part of their measurement results to perform a Bell test. If an eavesdropper is present, the game score drops, and the claim of security is automatically rejected. This idea became the basis of device-independent cryptography—security that does not rely even on the assumption that the devices themselves are functioning properly.
Shortly afterward, in 1993, quantum teleportation was proposed, and a few years later it was demonstrated experimentally. In 2017, China’s Micius satellite distributed entangled photon pairs between two ground stations separated by more than 1,200 kilometers. In this way, the paradox of 1935 became one of the cornerstones of the quantum internet.
Conclusion
Quantum cryptography demonstrates that the fundamental laws of quantum mechanics can be harnessed to enhance the security of communications. Properties such as measurement-induced state disturbance, the impossibility of perfectly copying an unknown quantum state, and quantum entanglement make it possible to detect or limit eavesdropping. However, the security of real-world systems depends not only on quantum principles but also on appropriate protocol design and careful consideration of the imperfections and limitations of practical hardware. Ultimately, the combination of quantum technologies with post-quantum cryptography could play an important role in shaping the secure communication infrastructures of the future.
1The 85% figure is actually an approximate value (about 85.4%); this game is known as the CHSH game.