JANUS

Quantum key distribution

Quantum key distribution (QKD) is a method for securely distributing cryptographic keys between two parties, with security guaranteed by the laws of quantum mechanics rather than computational hardness assumptions. If an eavesdropper attempts to intercept the key exchange, the quantum states are disturbed — a detectable event that alerts both parties to the compromise.

How QKD works

The most widely implemented QKD protocol, BB84, encodes each bit of the key in the quantum state of a single photon, using one of two randomly chosen bases (e.g., rectilinear or diagonal polarisation). The sender transmits the photons to the receiver over an optical fibre or free-space link. After transmission, the two parties compare their basis choices over a classical channel, discarding bits where the bases did not match. A subset of the remaining bits is used to detect eavesdropping; if none is found, the rest becomes the shared secret key.

PQC vs QKD

Post-quantum cryptography and QKD are complementary, not competing, approaches to quantum-safe security:

  • PQC is a software-based solution that can be deployed on existing infrastructure, but its security rests on mathematical assumptions yet to be proven against quantum attacks
  • QKD offers information-theoretic security based on physics, but requires dedicated optical hardware, has limited range (typically tens to hundreds of kilometres without trusted repeaters), and currently operates at lower key rates than classical key exchange

QKD in aviation

JANUS explores the feasibility of integrating QKD into ATM networks, recognising that the extreme security requirements of certain aviation applications may warrant the additional infrastructure investment. Use cases under consideration include:

  • Inter-ANSP communication over high-value ground-ground links, where the cost of a cryptographic breach is exceptionally high
  • Communication with state security services, where information-theoretic security may be mandated by national policy
  • SWIM node exchanges carrying safety-critical or security-critical data across organisational boundaries

The analysis examines technical barriers (distance, fibre availability, integration with existing PKI) and governance factors (policy alignment, standardisation, and regulatory acceptance) to produce a realistic assessment of QKD's role in the future ATM security architecture.