The Quantum Internet: Teleportation, Entanglement, QKD, PQC and Hybrid Security Strategies
By our Editor
The quantum internet is a different internet. Its quantum links will distribute entanglement alongside the classical channels needed for control and authentication, its security rests on physics as well as on computational hardness, and its arrival reshuffles the cryptographic deck for governments, hospitals, banks, and the engineers who connect them. This explainer walks the stack from quantum teleportation to post-quantum standards, building on the network-science context Mauritz Kop encountered at the Center for Quantum Networks conference. It ends where every board and ministry must begin: with a hybrid migration strategy whose deadlines are already set.
Two developments make this a policy story as much as a physics story. Experimental quantum networks have left the laboratory and now run over deployed telecom fiber between cities. And the classical countermeasure, post-quantum cryptography, has its first finalized standards, which turns "someday" into a compliance calendar. Understanding how the pieces fit together, and which promises are real, is now part of technology governance literacy.
The quantum internet distributes entanglement between cities over deployed fiber, from metropolitan links today toward repeater networks later.
How entanglement and teleportation move quantum states between cities
Quantum networks distribute entangled states between distant nodes. Quantum teleportation then transfers an unknown qubit state from one node to another using that shared entanglement plus two classical bits sent over an ordinary channel. Three misconceptions fall away at once. Nothing material travels: the physical system carrying the input state stays where it is, and only the quantum state is transferred, after entanglement has been distributed. Nothing travels faster than light: the protocol is incomplete until the classical message arrives. And nothing is copied: because of the no-cloning theorem, the original state is necessarily destroyed in the process. The no-cloning theorem prevents perfect copying of an arbitrary unknown quantum state. That last property is the root of the technology's security promise and of its engineering difficulty, since signal loss cannot be repaired by amplification the way classical repeaters do it.
The experimental frontier is advancing on schedule. In October 2024, a team led by QuTech in Delft reported heralded entanglement between two independently operated quantum processors, diamond spin qubits, in Delft and The Hague, linked by 25 kilometers of deployed underground telecom fiber via a midpoint station in Rijswijk, as described in QuTech's announcement and published in Science Advances. A metropolitan-scale link between cities is the proving ground for the harder problem. Spanning countries and continents will require quantum repeaters, devices that stitch short entangled segments together through entanglement swapping and quantum memories, and those remain laboratory technology. The strategic intent is explicit: the U.S. Department of Energy published a blueprint for a national quantum internet in 2020, with its seventeen national laboratories as the backbone.
What quantum key distribution over fiber and satellite does and does not secure
Quantum key distribution (QKD) uses quantum states, typically single photons, to negotiate encryption keys such that, at the protocol level, an eavesdropper who measures the encoded quantum states disturbs them, and the resulting error statistics can reveal the interception under the protocol's stated assumptions. Real devices add side channels, implementation flaws, and denial-of-service exposure to that picture. Two precisions matter for lawyers. QKD secures the key exchange and not the message; the payload still travels under symmetric encryption such as AES-256. And QKD's guarantee is conditional on hardware behaving as the protocol assumes.
The headline demonstration remains China's Micius satellite, which in 2017 and 2018 distributed quantum keys to ground stations near Beijing and Vienna, 7,600 kilometers apart, and supported a quantum-secured 75-minute videoconference between the Chinese and Austrian academies of science, reported in Physical Review Letters and available as a preprint on arXiv. The fine print is instructive. The satellite acted as a trusted relay that held both keys and combined them, so whoever controls the satellite could, in principle, read the traffic. Physics secured each link; institutional trust secured the middle.
That fine print is why security agencies remain cool toward QKD as a general-purpose solution. The U.S. National Security Agency does not recommend QKD for national security systems unless its limitations are overcome, citing special-purpose hardware, cost, insider risk at trusted nodes, denial-of-service exposure, and the fact that QKD solves only part of the security problem, since authentication still relies on classical cryptography. QKD remains a niche instrument whose trusted-node topology and infrastructure costs must be justified case by case.
Satellite QKD: single-photon downlinks can span continents, while the satellite itself acts as a trusted relay that must be governed.
Why the post-quantum migration clock is already running
The threat that sets the deadline comes from quantum computing itself. Shor's algorithm, on a future fault-tolerant machine, breaks RSA and elliptic-curve cryptography, the public-key schemes securing web traffic, software updates, and digital signatures. Grover's algorithm merely halves the effective strength of symmetric ciphers, which 256-bit keys absorb comfortably. The operative attack is harvest-now-decrypt-later: adversaries record encrypted traffic today and decrypt it once the hardware exists. For state secrets, health records, and genomic data with decade-long confidentiality horizons, interception already creates the confidentiality risk, because the retained ciphertext may become readable later. That is why migration deadlines exist now, years before any cryptographically relevant quantum computer.
The standards are ready. In August 2024, NIST finalized its first three post-quantum cryptography standards: FIPS 203 (ML-KEM, the lattice-based key-encapsulation mechanism derived from CRYSTALS-Kyber), FIPS 204 (ML-DSA, the primary digital-signature standard), and FIPS 205 (SLH-DSA, a hash-based signature fallback resting on different mathematics). In March 2025, NIST added HQC for standardization as a future backup key-encapsulation algorithm, with a draft standard expected to follow; it is code-based where the first three are lattice- or hash-based, a deliberate diversification in case lattice assumptions crack. Governments have attached dates. U.S. federal policy under National Security Memorandum 10 targets migration of federal systems by 2035, and European and allied security agencies have published timelines clustering in the same 2030 to 2035 window for critical infrastructure. Dutch organizations are already meeting ML-KEM in procurement; see our analysis of quantum-safe procurement and audit questions.
Defense in depth for the quantum transition layers post-quantum algorithms, symmetric encryption, and crypto-agility into one architecture.
How hybrid strategies layer PQC, AES-256, QKD and crypto-agility
Serious security architectures treat these instruments as layers. The near-term workhorse is hybrid key establishment: a classical algorithm combined with a post-quantum one, so that traffic stays secure as long as at least one component holds, subject to the protocol's composition assumptions, the pattern major browsers, VPNs, and messaging platforms have already adopted during the transition. PQC scales in software across the existing internet. QKD adds physics-level assurance on specific high-value point-to-point links where the infrastructure is justified. AES-256 keeps protecting payloads. Above all sits crypto-agility, the engineered ability to swap algorithms without rebuilding systems, because the one certainty in cryptography is that today's assumptions will not all survive.
For enterprises and governments the sequence is clear. First, build a cryptographic inventory: you cannot migrate what you have not mapped, and the inventory is becoming a board-level document, as we argued in the cryptographic inventory as a governance file. Second, triage by data lifetime: systems protecting data that must stay confidential beyond their expected migration date should move to post-quantum or well-designed hybrid protection now. Third, write crypto-agility and PQC requirements into procurement and audits before regulators do it for you. Fourth, treat QKD and quantum-network pilots as strategic research with explicit trusted-node risk assessments.
The governance dimension extends beyond any one organization. A network whose entangled links cross borders, and whose satellites act as trusted middlemen, raises questions of jurisdiction, lawful access, standardization, and alliance strategy that classical internet governance never fully answered. Frameworks exist. The Quantum Governance Stack maps governance models onto quantum information technologies layer by layer, the case for allied coordination is made in A Bletchley Park for the Quantum Age, and whether the G7 will govern this transition is the open question we examined in From Kananaskis to Évian. Like artificial intelligence, quantum technology will not wait for consensus. Unlike AI, it has announced its arrival in advance.
The quantum internet is a decade-scale build, and the cryptographic migration it implies is a today-scale obligation. Set the inventory, the deadlines, and the hybrid defaults now, so that the migration calendar is written by your own risk register and never by an adversary's archive.
Last updated: September 3, 2026