Affiliate disclosure
Book titles on this page link to Amazon. As an Amazon Associate, DataField.Dev earns from qualifying purchases — at no additional cost to you.
Further Reading: Quantum Cryptography and BB84
Tagged Tier 1 (confident it exists and recommended) and Tier 2 (real and worth seeking, but verify the current version or URL).
This is the best-documented application in the book and the one with the sharpest divide between its academic literature (excellent, careful, self-critical) and its marketing literature (not). Read both, and notice which claims survive the transition.
The protocol
- Bennett and Brassard, "Quantum cryptography: Public key distribution and coin tossing" (1984), Proceedings of IEEE ICCSSP, p. 175. The original, and short. Read it for how modest the claim is — the authors are explicit about needing an authenticated classical channel, which is the point §38.5 says gets lost downstream. Tier 1.
- Ekert, "Quantum cryptography based on Bell's theorem" (1991), PRL 67, 661. The entanglement-based alternative (E91), where security follows from a Bell inequality violation rather than from no-cloning. Tier 1.
- Shor and Preskill, "Simple proof of security of the BB84 quantum key distribution protocol" (2000), PRL 85, 441. Where §38.3's $1 - 2h_2(Q)$ comes from. The proof is genuinely simple once you see the connection to CSS codes, and it is worth the effort. Tier 1.
- Gisin, Ribordy, Tittel, and Zbinden, "Quantum cryptography" (2002), RMP 74, 145. The standard review. Older but still the best single orientation. Tier 1.
Finite keys — read this before quoting 11%
- Renner, "Security of Quantum Key Distribution" (2005), PhD thesis. The smooth-entropy framework that finite-key analysis is built on. Tier 1.
- Tomamichel, Lim, Gisin, and Renner, "Tight finite-key analysis for quantum cryptography" (2012), Nature Communications 3, 634. The paper Case Study 38.2's group should have used. §38.4's model captures only QBER-estimate uncertainty and says so; this is the real calculation, with an explicit security parameter $\varepsilon$. Tier 1.
- Scarani and Renner on finite-key bounds for practical implementations. How much key you actually extract from a real block. Tier 2.
The attacks — where the deployed systems actually fail
The most instructive section of this list, because every entry attacks something the security proof did not model.
- Lydersen, Wiechers, Wittmann, Elser, Skaar, and Makarov, "Hacking commercial quantum cryptography systems by tailored bright illumination" (2010), Nature Photonics 4, 686. Full key recovery against two commercial QKD systems, by blinding the detectors with bright light so they behave classically. The proof was never wrong; the detectors were not the detectors in the proof. Tier 1 — if you read one paper from this chapter, read this one.
- Photon-number-splitting attacks and the decoy-state method (Hwang; Lo, Ma, and Chen; Wang). Real sources emit multi-photon pulses, which BB84's single-photon assumption does not cover. Decoy states are the fix and they are now standard. Tier 1.
- Trojan-horse attacks, where Eve injects light into Alice's apparatus and reads the reflection to learn her basis settings. Tier 2.
- Makarov and collaborators' broader body of QKD hacking work. A sustained programme of attacking the gap between proof and implementation. Tier 1.
- Device-independent QKD (Acín et al.; Vazirani and Vidick; recent experimental demonstrations). Security from Bell violations with untrusted devices — the principled answer to the entire attack literature above, at rates that are currently impractical. Tier 1.
Deployment reality
- The SECOQC and Tokyo QKD network papers, and the Chinese Beijing–Shanghai backbone. Read them for the trusted-node architecture and count how many relay stations hold plaintext keys. Tier 1.
- Liao et al. on satellite-to-ground QKD with Micius (2017), Nature 549, 43. Free-space links that sidestep fiber loss. Exercise 38.31's subject — compare the achieved rates to §38.6's table. Tier 1.
- The UK NCSC and NSA position papers on QKD. Both national security agencies recommend post-quantum cryptography over QKD for government use, and both state their reasoning explicitly: authentication requirements, hardware trust, and lack of a path to scale. Whatever you conclude, these are the documents to argue with. Tier 1.
- ETSI's QKD standardization work. What the industry has agreed to specify. Tier 2.
The classical answer
- NIST FIPS 203 (ML-KEM), 204 (ML-DSA), and 205 (SLH-DSA), 2024. The standardized post-quantum algorithms. FIPS 203 is what §38.7 measured. Tier 1.
- The CRYSTALS-Kyber specification and the NIST PQC process reports. The process is unusually well documented, including the schemes that were broken during it — SIKE's collapse in 2022 is essential reading on how much confidence "conjectured hard" deserves. Tier 1.
- Bernstein and Lange, "Post-quantum cryptography" (2017), Nature 549, 188. The orientation. Tier 1.
- Mosca's theorem on migration timelines — comparing how long data must stay secret, how long migration takes, and how long until a cryptographically relevant quantum computer. The framework behind harvest-now-decrypt-later. Tier 1.
Backward references
- Chapter 5 — measurement and collapse, encountered as an inconvenience and reappearing here as the product.
- Chapter 23 — the threat that sets the deadline.
- Chapter 27 §27.4 — the shot-noise floor, which §38.4 is a security-critical instance of.
- Chapter 37 §37.7 — the structurally identical finding about what an algorithm produces versus how it scores.
Forward references
- Chapter 39 — the systems that run all of this, and what they cost.
Where to go next. If one thing: Lydersen et al. on detector blinding. It is the most important paper in this chapter's list because it demonstrates full key recovery against commercial, deployed, provably secure systems — without violating the proof. The proof assumed a detector; the hardware provided a device that could be made to behave classically. That gap between a theorem and an apparatus is the real subject of QKD engineering, and no amount of reading about no-cloning prepares you for it.
If two: add the NCSC or NSA position paper, whichever you are more inclined to disagree with. They are short, they are specific about their reasoning, and they are the clearest available statement of the argument §38.7 arrives at independently.
Then Chapter 39, where the book stops asking what quantum computers could do and starts measuring what it costs to use one.