A Quantum Key Crosses From Fiber to Open Air Without a Trusted Node
Quentir Defense Monitor
Evidence-based insights for quantum defense and security. Published by Quentir Systems LLC · August 19, 2026.

A military's secure communications live in two physical worlds that do not share an encoding. One is buried glass: the fiber backbones that carry sensitive traffic between fixed sites. The other is open air: the line-of-sight optical links that reach the places fiber cannot go, a drone overhead, a ship offshore, eventually a satellite. Quantum key distribution works in both worlds separately. The problem has always been the seam. A photon carrying quantum key material in fiber is encoded one way, a photon crossing the atmosphere is encoded another way, and until now the standard method of joining the two segments was to stop the quantum signal at the boundary, measure it, and start again. That boundary device holds the key in the clear. In the trade it is called a trusted node, and every one of them is a room you have to guard.
A team at Tel Aviv University's School of Physics and Astronomy reports a working system that removes that seam. In a preprint posted to arXiv, doctoral students Khen Cohen and Tomer Nahum, with colleagues including Prof. Yaron Oz and Prof. Haim Suchowski, Prof. Hagai Eisenberg of the Hebrew University of Jerusalem, and engineers from the Israeli vendor HEQA Security, demonstrate end-to-end quantum key distribution across a hybrid channel: standard telecom fiber joined to an outdoor free-space link, with the encoding converted between the two entirely in the optical domain. The photons are never measured at the junction, and the key exists only at the two endpoints. The system ran the decoy-state BB84 protocol at the telecom wavelength of 1550 nanometers, produced secret keys continuously over a 90-meter outdoor link on the university's rooftops, and held up over a 750-meter extension, as reported by Ynet alongside the university's announcement.
The reason this belongs in a defense reader's file rather than a physics newsletter is architectural. Every plan for a national quantum-secured network, military or civilian, is a plan for a patchwork of fiber rings, atmospheric hops, and a space segment. The count of trusted nodes in that patchwork is a direct measure of its attack surface and its manpower bill. A junction that keeps the signal quantum removes an entry from both ledgers at once.
What the converter actually does
Fiber and atmosphere disagree about how to hold a quantum bit. Inside glass, the robust choice is time-bin encoding: the bit lives in the arrival time of a photon, early or late, because fiber scrambles polarization over distance but preserves timing. In the open atmosphere the preference inverts. Turbulence wrecks the delicate interference that time-bin decoding needs, while polarization, the orientation of the photon's oscillation, travels through air essentially untouched. Two mature families of QKD hardware grew up around this split, and they cannot talk to each other directly.
The Tel Aviv interface converts one encoding into the other, and back, without reading the photon. That distinction carries the security argument. In quantum cryptography, measurement is disturbance: an eavesdropper who intercepts and re-sends photons unavoidably raises the error rate, and the legitimate parties see it. A conversion stage that measured the signal would look, to the protocol, exactly like that eavesdropper, which is why conventional network joints must be declared trusted and defended by other means. The paper's converters instead remain part of the untrusted quantum channel. Tampering at the junction shows up in the error statistics like any other intrusion on the line, and the protocol aborts before key material is compromised.
The field results say the junction holds up outdoors. Across test sessions running from hot midday into night, with atmospheric turbulence varying by more than two orders of magnitude in the standard refractive-index measure, the hybrid link kept its quantum bit error rate between 5.6 and 6.8 percent, under the protocol's 11 percent security ceiling. Continuous key generation through that entire range matters more than any single number: turbulence is the reason free-space optical links have a reputation for fair-weather performance, and a key service that dies at noon is one no signals officer will plan around.
Quantum pillar: networking (quantum key distribution links). Use posture: dual-use. Technology readiness: TRL 5 of 9. The complete system generated secret keys end to end over live urban air paths of 90 and 750 meters through daytime and nighttime turbulence, a validation in a realistic atmospheric setting that still sits well short of an engineered operational terminal.
What an unbroken key path lets a force do
Read as capability, the demonstration answers a specific operational question: can quantum-grade key material move from a fixed fiber network to a platform that fiber cannot reach, without creating a manned, hardened relay at the boundary? Militaries are the clearest customer for that answer. A headquarters sits on fiber; the assets it must rekey, from ships and aircraft to forward stations and satellites, sit at the end of an air gap. Today's practice bridges that gap with couriered key material or classical cryptography. A hybrid quantum link of the kind demonstrated here would let a force extend its quantum network to the edge of the fiber map and one optical hop beyond it, with any interference at the junction announcing itself in the physics rather than waiting to be discovered by an audit.
The same architecture is what civilian infrastructure programs are building, which makes the posture reading dual-use rather than military. The European Union's EuroQCI initiative is assembling exactly this patchwork across all 27 member states: terrestrial fiber segments linking government sites, and a space segment whose Eagle-1 prototype satellite is slated for launch in late 2027. Every meeting place of those segments is a junction of this kind, and the fewer that must be trusted, the cheaper and more defensible the infrastructure becomes. The commercial supply chain is already positioned on both sides of the seam. HEQA Security, the fiber-QKD maker whose team co-authored the demonstration, sells a production 1U unit that combines a QKD transmitter and receiver with a post-quantum cryptography overlay, and lists government and defense among its target sectors alongside telecom carriers and banks. The offensive reading of the technology is thin: a key-distribution link protects traffic and stops interception, and it gives an attacker nothing to employ. The gain flows to whoever operates networks worth tapping, on either side of any border.
What stands between a rooftop and a program office
The honest distance runs through both engineering and doctrine. On engineering, 750 meters across a university campus is two orders of magnitude short of a satellite slant path, and the demonstration used fixed terminals on buildings. Reaching an aircraft or a satellite adds the acquisition and tracking of a moving platform, then Doppler management and daylight operation against a bright sky, none of which this experiment claims. The conversion stage also spends photons: every optical interface adds loss, and loss comes straight out of the secret key rate, which is already the scarce commodity in free-space QKD. A program office would want the junction holding its error rate over tens of kilometers, between platforms that move, before writing requirements around it.
The doctrinal obstacle is larger. The UK's NCSC, the government's cyber security authority, in its white paper on quantum security technologies, states plainly that it will not support QKD for government or military applications, pointing to the specialized hardware it demands, its inability to authenticate the parties at the ends of the link, and post-quantum cryptography as the mitigation it recommends instead. That position is why QKD procurement in the West today is led by civilian infrastructure programs and research ministries rather than defense ministries. Nothing in the Tel Aviv result answers the authentication objection, and its authors do not claim otherwise; their own industrial partner ships post-quantum cryptography alongside its quantum hardware precisely because the two address different parts of the problem.
What the result does change is the cost side of the argument. A fair criticism of quantum networking has been that scaling it multiplies trusted nodes until the security claim collapses into the physical security of many small rooms. A demonstrated, field-tested junction that stays quantum removes one class of those rooms, and it does so with converters that a vendor can build into terminal equipment. Buyers tracking quantum-secure communications should log this as the moment hybrid fiber-and-air key distribution moved from architecture diagrams to an outdoor link with published error rates, and should watch for two follow-ons that would each move the readiness needle: the same conversion holding over a kilometers-long link to a moving platform, and an appearance of the technique in EuroQCI or national test-bed procurements, where the trusted-node count is already a line item someone has to defend.
Sources
Primary source: Khen Cohen, Tomer Nahum, Michael Tzukran, Paz Or, Yehuda Pilnyak, Nitzan Livneh, Hagai Eisenberg, Yaron Oz, and Haim Suchowski of Tel Aviv University, the Hebrew University of Jerusalem, and HEQA Security, "End-to-End Quantum Key Distribution Across Hybrid Fiber and Free-Space Links with All-Optical Encoding Conversion," arXiv preprint 2607.12837. Other material from Ynet's report on the demonstration, the European Commission's EuroQCI program page, HEQA Security's product documentation, and the UK National Cyber Security Centre's white paper on quantum security technologies.