
Store Now, Decrypt Later: Why QKD Matters for Future-Proof Security
From online shopping invoices and YouTube viewing histories to chat messages and confidential business emails, we send and receive enormous amounts of data every day, often without giving it much thought. The Internet has fundamentally transformed the way we communicate and interact. The term itself is short for interconnected networks, highlighting the key factor behind its success: people and machines can communicate and collaborate across the globe within seconds.
However, this connectivity also introduces risks. Data that remains entirely within an organization’s internal infrastructure can be controlled directly and protected through physical security measures. Data transmitted over the Internet, on the other hand, travels through cables, wireless links, and typically multiple intermediate nodes.Classical communication signals can often be intercepted or copied without affecting the original transmission. For example, optical splitters can be used to tap into fiber-optic links and duplicate signals without modifying the transmitted data. In some cases, data may even be manipulated without the recipient immediately noticing.
To address these risks, a wide range of cryptographic techniques have been developed over the years. Based on mathematical assumptions, they enable both encryption and authentication. These mechanisms ensure that only authorized parties can access sensitive information and allow recipients to verify both the origin and integrity of the transmitted data. [1,2]
One important question, however, remains unanswered: Has an attacker secretly copied or recorded the encrypted communication?
For authentication, this risk is generally less significant. Once the communicating parties and the transmitted data have been successfully authenticated, an attacker cannot retroactively alter the communication. Replay attacks can typically be prevented through the use of unique identifiers. Confidentiality, however, is a different matter. If an attacker records encrypted traffic today, the data can potentially be decrypted weeks, months, or even years later once the attacker obtains the corresponding key or discovers a way to break the underlying cryptographic scheme. In other words, an attacker does not need to decrypt the communication immediately. It is sufficient to record and store the data today and wait for future technological advances. This threat is commonly known as “Store Now, Decrypt Later” (SNDL) [3].
For a birthday greeting, decryption five years later may not be particularly concerning. Research data, trade secrets, medical records, or confidential government communications, however, often need to remain protected for many years or even decades.The rapid progress in quantum computing has significantly increased this concern. A sufficiently powerful quantum computer could break some of today’s widely used public-key cryptographic schemes far more efficiently than classical computers, potentially exposing large volumes of previously recorded encrypted data [4].
This is where Quantum Key Distribution (QKD) offers a fundamentally different approach.
QKD uses individual quantum states to distribute cryptographic keys and relies on a fundamental principle of quantum mechanics known as the No-Cloning Theorem. First described in 1982 by William Wootters and Wojciech Zurek [5], as well as independently by Dennis Dieks [6], the theorem states that an unknown quantum state cannot be copied perfectly. When applied to secure communications, this property enables the detection of eavesdroppers on the communication channel—even if they only attempt to passively observe the transmitted information. Any attempt to measure or duplicate the quantum states inevitably introduces detectable disturbances. As a result, correctly implemented QKD can prevent undetected interception of cryptographic key material and thereby mitigate the risk of Store Now, Decrypt Later attacks.
No one can predict with certainty which cryptographic algorithms will still be considered secure in ten or twenty years. What is certain, however, is that data transmitted today may remain valuable for just as long.
For this reason, protection against Store Now, Decrypt Later attacks is becoming increasingly important. QKD is one of the few technologies capable of securing sensitive communications not only against today’s threats but also against future technological advances that could undermine conventional cryptographic assumptions.
Literature
- C. Paar and J. Pelzl, Understanding Cryptography: A Textbook for Students and Practitioners. Berlin, Germany: Springer, 2010, doi: 10.1007/978-3-642-04101-3.
- K. Scarfone, M. Souppaya, and R. Perlner, Guideline for Using Cryptographic Standards in the Federal Government: Cryptographic Mechanisms, NIST Special Publication 800-175B Rev. 1, National Institute of Standards and Technology, Gaithersburg, MD, USA, Jul. 2024. doi: 10.6028/NIST.SP.800-175Br1.
- J. Mascelli and M. Rodden, ‘Harvest Now Decrypt Later’: Examining Post-Quantum Cryptography and the Data Privacy Risks for Distributed Ledger Networks, Finance and Economics Discussion Series, no. 2025-093, Board of Governors of the Federal Reserve System, Washington, DC, USA, 2025, doi: 10.17016/FEDS.2025.093.
- National Academies of Sciences, Engineering, and Medicine, Quantum Computing: Progress and Prospects. Washington, DC, USA: The National Academies Press, 2019. doi: 10.17226/25196.
- W. K. Wootters and W. H. Zurek, A Single Quantum Cannot Be Cloned, Nature, vol. 299, no. 5886, pp. 802–803, 1982, doi: 10.1038/299802a0.
- D. Dieks, Communication by EPR Devices, Physics Letters A, vol. 92, no. 6, pp. 271–272, 1982, doi: 10.1016/0375-9601(82)90084-6.