October 5, 2026
Sumanth Srirangam

From BB84 to 1,000 Kilometres: Quantum Security Has Entered Its Next Chapter

TL;DR

  • In March 2026, the ACM awarded Charles H. Bennett and Gilles Brassard the Turing Award, computing's highest honour, for the BB84 protocol they introduced in 1984: the first practical system for securing encryption with the laws of physics rather than mathematical assumptions.
  • In 2026, India demonstrated a 1,000-kilometre quantum-secure communication network, moving quantum key distribution from scientific concept to national infrastructure.
  • Between those two moments, the entire cryptographic foundation of the internet has come under quantum threat. The migration conversation is no longer optional.

In 1984, two scientists wrote a paper that most of the world would not understand for another decade. Charles H. Bennett of IBM Research and Gilles Brassard of the Université de Montréal proposed something that had no precedent: a method for two parties to share an encryption key whose security was guaranteed not by the difficulty of a mathematical problem but by the laws of physics themselves. They called the protocol BB84.

The core insight was precise. Quantum information cannot be copied or measured without disturbing it. Any attempt to intercept a quantum key exchange leaves a detectable trace before any information is compromised. For the first time, security was not a computational assumption. It was a physical fact.

On 18 March 2026, the Association for Computing Machinery awarded Bennett and Brassard the ACM A.M. Turing Award, often called the Nobel Prize of Computing, for their essential role in establishing the foundations of quantum information science. The $1 million prize, supported by Google, recognised not just BB84 but the broader theoretical framework the two built together: quantum teleportation, entanglement distillation, and the conceptual infrastructure on which every serious quantum network in the world is being constructed today.

The recognition arrived at a precise moment. Not because the science needed validation. It has been validated for decades. But because 2026 is the year the field moved from scientific validation to operational infrastructure, and the distance between those two points is the story of quantum security's first chapter.

Why BB84 Mattered Then, and Why It Matters More Now

When Bennett and Brassard wrote their paper, the threat they were designing against was abstract. A quantum computer capable of breaking RSA and elliptic curve encryption did not exist. Peter Shor would not prove that such a computer could break those algorithms until 1994. The urgency was theoretical.

In 2026, the urgency is structural. NIST finalised its first three post-quantum cryptography standards in August 2024: ML-KEM, ML-DSA and SLH-DSA. The NSA's CNSA 2.0 mandates algorithm replacement for national security systems by 2030. And the harvest-now, decrypt-later threat means adversaries are already collecting encrypted data today, storing it in archives they intend to open once quantum computing matures.

The ACM's Turing Award citation put the current position plainly: as research advances toward large-scale quantum computers, governments and industry are reassessing the long-term resilience of widely deployed public-key cryptographic systems. Quantum cryptography, the citation noted, represents one pathway toward securing digital communications in the decades ahead.

One pathway. Not the only one. Which is precisely why the field has developed in parallel: quantum key distribution for physics-based key exchange, post-quantum cryptography for algorithm-based resilience across existing infrastructure, and quantum random number generation as the entropy foundation beneath both. The three are not competing approaches. They are complementary layers of the same quantum-safe architecture.

The World Did Not Wait for the Turing Award

Between Bennett and Brassard's 1984 paper and the 2026 award, the field built quietly and continuously. Variants of BB84 were implemented in operational quantum communication networks using both fibre and free-space satellite links. Quantum key distribution moved from laboratory demonstrations to metropolitan deployments to, in 2026, national infrastructure.

India's 1,000-kilometre quantum-secure communication network, documented by the Press Information Bureau under the National Quantum Mission, is the clearest proof that the first chapter of quantum security is closed.  

The DST National Quantum Mission Task Force, reporting in February 2026, set India's Critical Information Infrastructure deadline for full post-quantum adoption at 31 December 2029, more aggressive than the UK, EU and Japan. The RBI Q-SAFE committee, constituted in May 2026, mandated the financial sector to map its cryptographic estate and deliver a quantum-safe roadmap within six months. The regulatory architecture is not catching up with the science. It is running alongside it.

A Decade in the Making

There is a timeline that runs through all of this.

1984: BB84 is published. Quantum cryptography becomes possible in principle.

1994: Shor's algorithm proves quantum computers will break RSA and elliptic curve encryption, making the migration question not if but when.

2024: NIST finalises its first post-quantum cryptography standards, moving the migration from a research agenda to a compliance programme.

2026: Bennett and Brassard receive computing's highest honour. India operates a quantum-secure network at 1,000-kilometre scale. National regulators set binding migration deadlines.

QNu Labs was founded in 2016, in the middle of that arc, built on the conviction that the transition from quantum-security theory to quantum-security infrastructure was not a future event. It was a current engineering problem. A decade of building QKD, QRNG, PQC and key management capabilities across defence, banking and critical infrastructure was not preparation for this moment. It was participation in it.

The first chapter of quantum security was about proving that it was possible. The Turing Award is its closing paragraph.

The next chapter is about making quantum security ubiquitous. That chapter is already open.

The migration window is defined by regulation, not by readiness.  

Understand where your cryptographic estate stands before the deadline sets the pace for you.

‍

Sources

  1. ACM, 2025 A.M. Turing Award: Charles H. Bennett and Gilles Brassard (18 March 2026) : https://www.acm.org/media-center/2026/march/turing-award-2025
  2. The Quantum Insider, ACM Turing Award Honors Bennett and Brassard for Quantum Information Science : https://thequantuminsider.com/2026/03/18/acm-a-m-turing-award-honors-charles-h-bennett-and-gilles-brassard-for-foundational-contributions-to-quantum-information-science/
  3. Physics World, Quantum Physicists Charles Bennett and Gilles Brassard Win $1m Turing Award : https://physicsworld.com/a/quantum-physicists-charles-bennett-and-gilles-brassard-win-1m-turing-award/
  4. EurekAlert, ACM A.M. Turing Award Honors Bennett and Brassard (BB84 information-theoretic security detail) : https://www.eurekalert.org/news-releases/1120415
  5. NIST, Post-Quantum Cryptography Standards Approved (FIPS 203, 204, 205) : https://csrc.nist.gov/news/2024/postquantum-cryptography-fips-approved
  6. NSA, Commercial National Security Algorithm Suite 2.0 : https://media.defense.gov/2025/May/30/2003728741/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS.PDF
  7. Press Information Bureau, National Quantum Mission: India's 1,000 km Quantum-Secure Communication Network : https://www.pib.gov.in/PressReleasePage.aspx?PRID=2250162
  8. Department of Science and Technology, Implementation of Quantum Safe Ecosystem in India (NQM Task Force, February 2026) : https://dst.gov.in/sites/default/files/Quantum-Safe-Ecosystem-in-India.pdf
  9. Reserve Bank of India, Q-SAFE Expert Committee (May 2026) : https://fintech.rbi.org.in/FS_PressRelease?prid=62803

‍

Frequently asked questions

What is the BB84 protocol?
Why did Bennett and Brassard win the Turing Award in 2026?
What is harvest-now, decrypt-later and why does it make migration urgent?
What are NIST's post-quantum cryptography standards?

More blogs