
Photo: Idaho National Laboratory (BY)
Post-Quantum & BlockchainQKD vs Post-Quantum Cryptography: Which Problem Does Each Solve?
Quantum key distribution and post-quantum cryptography are routinely discussed as competing answers to the same question. They are not. They solve different problems, have different deployment profiles, and one of them is a general answer while the other is a specialised tool.
What each actually does
Post-quantum cryptography is mathematics. New algorithms built on problems believed hard for quantum computers, running as software on ordinary hardware. It replaces RSA and elliptic curve cryptography in the systems you already have.
Quantum key distribution is physics. It uses quantum properties of transmitted photons so that any interception disturbs the transmission detectably. Two parties can establish a shared key and know whether anyone observed the exchange.
The distinction that matters: PQC is a drop-in replacement for existing cryptography. QKD is a way to distribute keys that requires specialised hardware and a suitable physical channel.
Where QKD does not fit
The constraints are physical and therefore stubborn.
It needs a dedicated channel. Typically fibre, or free-space line of sight. You cannot run it over the public internet, because the internet routes packets through switches and the quantum state does not survive that.
Distance is limited. Photon loss over fibre restricts practical range. Extending it requires trusted relay nodes — which reintroduces exactly the trust assumption QKD was supposed to eliminate — or quantum repeaters, which remain a research problem.
It distributes keys and nothing else. QKD provides no digital signatures, no authentication of who is at the other end, no certificates. You still need conventional cryptography for those, and that cryptography still needs to be quantum-resistant. QKD does not remove the PQC migration; it sits alongside it.
Implementations attack differently. The theoretical guarantee assumes ideal devices. Real detectors and sources have imperfections, and a substantial body of work exists on attacking those rather than the physics.
Where QKD makes sense
Point-to-point links between fixed, high-value sites within reach of dedicated fibre. Connecting two data centres in the same metropolitan area. Government and defence links where the budget exists and the threat model justifies it. Situations where you want defence in depth and can afford a second, physically-grounded mechanism alongside mathematical cryptography.
That is a real set of use cases. It is also small, and it is not the internet.
Why PQC is the general answer
It is software. It runs on the hardware you own, over the networks you already have, between parties who have never met. It provides signatures as well as key establishment. It is standardised, with defined migration deadlines. And it scales to every device, including the constrained ones QKD could never reach.
National security agencies in several countries have reached the same conclusion in guidance to their own sectors: post-quantum cryptography is the primary path, and QKD is a supplementary technology for specific circumstances rather than a general solution.
The practical answer
If you are deciding what to do about the quantum threat, the answer is post-quantum cryptography and it is not a close call. Inventory your cryptography, deploy hybrid key exchange, plan the signature migration.
Consider QKD only if you have a specific point-to-point link, dedicated fibre, a threat model that justifies the expense, and you have already done the PQC work — because you will need it regardless.
Get new posts by email
Occasional writing on post-quantum cryptography, blockchain security and digital forensics. No more than twice a month, and nothing else.


