The trial ran on the night of 27-28 September 2026. That detail is not incidental scheduling β it is physics, and it is the first thing worth understanding about what was demonstrated.
QNu Labs, with the Bhaskaracharya National Institute for Space Applications and Geo-informatics (BISAG-N) and IIT Gandhinagar, has demonstrated India's first free-space Quantum Key Distribution link, over 5.56 kilometres, between the BISAG-N campus and IIT Gandhinagar.
Why free-space is a different problem from fibre
India has done QKD before. C-DOT's Q-VIKRAM and Q-AMOGH products and the National Quantum Mission's work across four hubs are fibre-based. Sending single photons through open atmosphere is a materially harder engineering problem, and the differences are specific.
You need line of sight. A fibre can be laid around a hill. An optical beam cannot. Transmitter and receiver must see each other, which constrains where links can exist and is why terrain and building height matter.
The beam wanders. Atmospheric turbulence β pockets of air at slightly different temperatures and densities β bends the beam unpredictably, in the same way that makes stars twinkle. Over 5.56 km the receiving aperture is a small target and the beam will not stay on it unaided. Hence the Pointing, Acquisition and Tracking (PAT) system the trial used: it finds the counterpart, locks on, and actively corrects alignment as conditions change. Without PAT, there is no link.
The beam spreads. Diffraction means an optical beam diverges with distance, so only a fraction of transmitted photons reach the receiver. In QKD this matters more than in ordinary optical communication, because you cannot compensate by sending a stronger signal β the security of QKD depends on sending roughly one photon at a time.
And sunlight is the enemy. This is the reason for the night trial. QKD receivers are single-photon detectors: devices built to register the arrival of one photon. Daylight floods the receiver with solar photons at the same wavelength, and the detector cannot distinguish a signal photon from a background one. The result is noise β which in QKD appears as errors in the shared key. Daylight free-space QKD is possible, with narrow spectral filters, tight spatial filtering and careful wavelength choice, but it is substantially harder. A first demonstration sensibly runs at night.
What the numbers mean
Two figures were reported, and both are the right figures to report.
Quantum Bit Error Rate (QBER) below 5 per cent. When two parties compare a sample of their key bits, some disagree. The fraction that disagree is the QBER, and its sources are channel noise, detector imperfection β and, in principle, eavesdropping. This is the heart of why QKD is secure: measuring a quantum state disturbs it, so an eavesdropper intercepting photons necessarily raises the QBER. Below a threshold β around 11 per cent for the standard BB84 protocol β the parties can distil a secure key through error correction and privacy amplification. Above it, they cannot, and the correct response is to abandon the key. Below 5 per cent means the link had ample margin.
Secure key rate of 230-260 bits per second. That is slow by communications standards, and it is not meant to carry traffic. A QKD link distributes keys, which are then used by conventional high-speed symmetric encryption β typically AES β to protect the actual data. At 230 bits per second you can refresh a 256-bit AES key roughly every second, which is a far higher rate of key renewal than any operational system needs. The quantum channel is a key courier, not a data pipe.
The two layers, and why both
The demonstration deliberately combined two different kinds of quantum-era security, and the distinction is the most examinable idea here.
QNu Labs' Armos is a hardware QKD device. Its security rests on physics β the no-cloning theorem and the fact that measurement disturbs a quantum state. An eavesdropper cannot copy a photon undetected, whatever computer they possess.
BISAG-N's Vedic Kavach is a software platform implementing post-quantum cryptography (PQC) with quantum random number generation. PQC security rests on mathematics β on problems, typically lattice-based, believed hard even for a quantum computer running Shor's algorithm.
Those are complementary rather than competing, and the release states the reason precisely: the integrated architecture "ensures resilience even if the physical quantum channel is temporarily unavailable." QKD needs a working physical link; cloud cover, a blocked line of sight or a failed tracking lock takes it down. PQC runs over any network. Pairing them means the system degrades to a mathematically-secure mode rather than failing β and the quantum random number generator improves PQC too, since a cryptosystem with a predictable random number source is broken regardless of how good its mathematics is.
End-to-end encryption and decryption of test messages was demonstrated using keys from the quantum link integrated into the Vedic Kavach platform.
The point of 5.56 kilometres
A link across one city is not useful in itself. Its significance is directional.
Fibre loss is exponential with distance, and the obvious fix β an amplifier or repeater β is unavailable, because the no-cloning theorem forbids copying an unknown quantum state. You cannot amplify a qubit. True quantum repeaters remain a research problem. Practical fibre QKD is therefore limited to a few hundred kilometres between trusted nodes.
Free space breaks that limit, because most of the path to a satellite is vacuum. Atmospheric attenuation applies over roughly the first ten to twenty kilometres of the vertical path; above that there is essentially nothing to absorb or scatter. A satellite can therefore establish quantum links with ground stations thousands of kilometres apart β the approach China demonstrated with the Micius satellite, and the reason every serious quantum communication programme has a space segment.
Which is why QNu Labs' Sunil Gupta framed the result as paving the way for "longer-distance quantum-secure networks and satellite-based quantum communication", and why BISAG-N is the right partner: it is an autonomous scientific society under MeitY working on space technology applications, satellite communication and geo-informatics. A ground-to-ground atmospheric link is the rehearsal for a ground-to-satellite one β the same PAT problem, the same background-light problem, the same detectors, over a shorter and more forgiving path.
Dr Vinay Thakur, Director General of BISAG-N, and Cmde Manish Tripathi (Retd.), in charge of the ISTF at IIT Gandhinagar, both framed the trial as a step towards practical deployment. QNu Labs was founded in 2016; IIT Gandhinagar in 2008.
π Revision block
- India's first free-space QKD link: 5.56 km, between BISAG-N and IIT Gandhinagar, demonstrated by QNu Labs with both partners. Field trial on the night of 27-28 September 2026; announced 3 October 2026.
- BISAG-N = Bhaskaracharya National Institute for Space Applications and Geo-informatics β an autonomous scientific society under MeitY, working on space technology applications, satellite communication and geo-informatics.
- Results: Quantum Bit Error Rate below 5%; secure key rate 230-260 bits per second.
- Free-space vs fibre challenges: requires line of sight; atmospheric turbulence causes beam wander; diffraction spreads the beam; and solar background photons swamp single-photon detectors β hence the night trial.
- Pointing, Acquisition and Tracking (PAT) system finds the counterpart, locks on and actively corrects alignment.
- QBER is the fraction of compared key bits that disagree. Because measurement disturbs a quantum state, an eavesdropper necessarily raises the QBER β this is the basis of QKD security. Secure key distillation is possible below roughly 11% for BB84.
- Key rate is not data rate. QKD distributes keys; the data is encrypted with conventional symmetric ciphers such as AES. 230 bps refreshes a 256-bit key about every second.
- Two complementary layers: QNu Labs' Armos β hardware QKD, security from physics (no-cloning, measurement disturbance); BISAG-N's Vedic Kavach β software post-quantum cryptography with quantum random number generation, security from mathematics (typically lattice problems).
- Why pair them: QKD needs a working physical link and fails if the channel is unavailable; PQC runs over any network, so the system degrades rather than fails.
- Why free space matters: fibre loss is exponential and the no-cloning theorem forbids quantum repeaters that amplify, limiting fibre QKD to a few hundred km between trusted nodes. Most of the path to a satellite is vacuum, with atmospheric attenuation only over the first 10-20 km β so satellites enable intercontinental quantum links.
- People: Dr Vinay Thakur, DG BISAG-N; Sunil Gupta, Co-founder and CEO, QNu Labs; Cmde Manish Tripathi (Retd.), In-charge ISTF, IIT Gandhinagar. QNu Labs founded 2016; IIT Gandhinagar founded 2008.
π― Practice MCQs
Q1. The field trial of India's first free-space QKD link was conducted at night principally because: (a) Solar background photons would swamp the single-photon detectors (b) Atmospheric turbulence ceases after sunset (c) The optical fibre expands in daytime heat (d) Satellite passes occur only at night
β (a) QKD receivers are single-photon detectors, and daylight floods them with solar photons at the signal wavelength, appearing as errors in the key. Turbulence does not cease at night, and no fibre was involved in a free-space link.
Q2. A Pointing, Acquisition and Tracking system in a free-space optical link is required to: (a) Encrypt the key before transmission (b) Find the counterpart terminal, lock on, and actively correct beam alignment (c) Amplify the quantum signal at intermediate points (d) Convert photons into electrical pulses for detection
β (b) Atmospheric turbulence causes the beam to wander off a small receiving aperture, so alignment must be actively maintained. Amplifying a quantum signal is forbidden by the no-cloning theorem, which rules out option (c) entirely.
Q3. Quantum Bit Error Rate (QBER) is significant for security because: (a) It measures the raw transmission speed of the link (b) A low QBER proves the link uses post-quantum cryptography (c) An eavesdropper measuring the photons necessarily increases it (d) It determines the physical length of the fibre required
β (c) Because measurement disturbs a quantum state, interception raises the QBER. The parties can therefore detect eavesdropping by comparing a sample of their key bits β the foundation of QKD's security claim.
Q4. For the standard BB84 protocol, secure key distillation is generally possible when the QBER is below approximately: (a) 1% (b) 25% (c) 50% (d) 11%
β (d) Around 11% is the commonly cited threshold for BB84. The trial's QBER of below 5% therefore had substantial margin.
Q5. The reported secure key rate of 230-260 bits per second is best understood as: (a) The rate at which encrypted data is transmitted over the link (b) The rate at which cryptographic keys are generated, for use by conventional symmetric encryption (c) The maximum bandwidth of the free-space optical channel (d) The error rate of the quantum channel
β (b) QKD distributes keys, not data. The data is encrypted by a conventional symmetric cipher such as AES, so a few hundred bits per second is ample for frequent key refresh.
Q6. The essential difference between QKD and post-quantum cryptography is that QKD's security rests on: (a) Mathematical problems believed hard for quantum computers (b) The length of the cryptographic key used (c) Physical laws governing quantum measurement (d) The secrecy of the algorithm employed
β (c) QKD derives security from physics β no-cloning and measurement disturbance. PQC derives it from mathematics, typically lattice-based problems believed hard even for a quantum computer.
Q7. Integrating a hardware QKD device with a software post-quantum cryptography platform provides resilience chiefly because: (a) PQC can operate over any network when the physical quantum channel is unavailable (b) PQC increases the quantum key rate (c) QKD cannot generate random numbers (d) The two use the same mathematical assumptions
β (a) A QKD link fails if the optical channel is blocked by cloud, obstruction or loss of tracking lock. PQC runs over any network, so the system degrades to a mathematically-secure mode rather than failing outright.
Q8. Quantum repeaters that amplify a signal, as used in classical optical networks, are not possible because: (a) Quantum signals travel too slowly (b) The no-cloning theorem forbids copying an unknown quantum state (c) Amplifiers cannot operate at single-photon wavelengths (d) Quantum states cannot be transmitted through fibre at all
β (b) The no-cloning theorem forbids making a copy of an unknown quantum state, so a qubit cannot be amplified. This is why fibre QKD is distance-limited and why satellites are the route to intercontinental links.
Q9. Free-space optical links are the viable route to satellite quantum communication because: (a) Satellites cannot carry optical receivers (b) Atmospheric turbulence assists beam collimation above the troposphere (c) Optical fibre cannot be manufactured in sufficient lengths (d) Most of the path to a satellite is vacuum, with attenuation confined to the first 10-20 km
β (d) Atmospheric attenuation applies over roughly the first 10-20 km of the vertical path; above that the path is essentially vacuum, so losses are far lower than in fibre over comparable distances.
Q10. BISAG-N is an autonomous scientific society functioning under which Ministry? (a) Ministry of Electronics and Information Technology (b) Department of Space (c) Ministry of Science and Technology (d) Ministry of Earth Sciences
β (a) BISAG-N functions under MeitY, working on space technology applications, satellite communication and geo-informatics β which is why it is the natural partner for a link intended as a rehearsal for satellite QKD.
π How this gets asked (PYQ pattern)
Quantum technology has become a standing NDA topic, and the questions divide into three groups.
The first is the two security paradigms, and this is the distinction that matters most. QKD is hardware and rests on physics; post-quantum cryptography is software and rests on mathematics. Candidates routinely treat them as synonyms. They are complementary technologies answering the same threat by different means, and almost every question in this area turns on telling them apart.
The second is the principles that make QKD work: the no-cloning theorem, measurement disturbing a quantum state, superposition, entanglement, and QBER as the detection mechanism. These are conceptual and therefore answerable by reasoning. Note particularly that no-cloning is what both secures QKD and prevents quantum repeaters β the same theorem producing a benefit and a limitation.
The third is India's institutional landscape: the National Quantum Mission with its four thematic hubs, C-DOT for telecom-sector products, BISAG-N under MeitY, DRDO's quantum work, and private firms such as QNu Labs. A question naming a body and asking its contribution is standard.
A fourth pattern worth preparing is applied optics and physics: why diffraction limits beam intensity at range, why turbulence requires active tracking, why single-photon detection fails in daylight. These reward understanding over recall, and this demonstration supplies a clean example of each.
Preparing for NDA? Hold one sentence for this whole topic: QKD secures the key using physics and needs a physical channel; PQC secures the data using mathematics and needs only a network. Nearly every question follows from that division. Build the base with our NDA general ability notes, follow the daily NDA current affairs, and prepare with our faculty in the upcoming Cavalier courses in Delhi.
βοΈ Written by Col Vijyanat Thakur β Defence studies faculty at The Cavalier. Reviewed by the Cavalier Faculty Desk.