跳至正文

证明是真的,干线是真的,中继也是真的

目录

机制裁决第 150 篇 · 对称双向第 145 篇 · section B1 · 全库第 208 篇 本篇审的是「量子通信不可破解/无条件安全/量子互联网已建成」这组话——以及它背后那套安全证明、那串侧信道攻击、那条 4600 公里可信中继网络和那张「量子互联网」名号。先读三句红线:

  1. 本篇不裁决任何国家的技术路线选择对错,不评价任何机构、公司或科学家的动机——只审「不可窃听、不可破解、无条件安全、量子互联网已到来」这些说法从文件里读出来时承重承不承得住。本篇不构成任何安全采购、投资或政策建议。
  2. 「QKD 的安全证明是定理级工作」与「这台 QKD 盒子在我的网络上不可攻破」是两件不同的事。本篇的裁决落在两者之间的缝里:安全证明是真的(且证明者自己把假设与警告印在论文里)、工程系统被反复攻破也是真的(且攻破者自己把补丁有效写进摘要)、而「无条件安全」这个词在给它下定义的文献里自带一句「它不是绝对安全的同义词」——跳变不发生在论文里,发生在论文被读成新闻稿的那个动作里。
  3. 全篇承重句均给出可点击来源;中英文逐字引用一律取自实际取回文件(含 Wayback 原件),自算部分写明算式。本篇引用的所有数字(密钥率、距离、客户数、净利润、政府补助)都给出出处与口径。

零、一句话裁决

「无条件安全」这个词是真的——它在 QKD 安全证明文献里有精确定义,而定义它的那篇权威综述在同一节逐字警告「Like many other technical terms, the wording “unconditional security” has to be used in its precise meaning given above, and not as a synonym of “absolute security” — something that does not exist」(Scarani et al., RMP 81, 1301 (2009),§II.3.1[一手逐字]);BB84 的安全性证明是真的(Shor & Preskill 2000 逐字「We prove the security of the 1984 protocol of Bennett and Brassard (BB84)」——且同文自认证明只吃完美单光子源,对当时实验普遍使用的弱相干源「no currently known proof covers this case」[一手逐字]);墨子号、京沪干线、4600 公里星地一体网络是真的(Nature 589, 214–219 (2021) 摘要逐字「Using a trusted relay structure」——可信中继四个字印在摘要里[一手逐字]);NSA 白纸黑字「does not recommend the usage of quantum key distribution」、NCSC 白纸黑字「does not endorse the use of QKD for any government or military applications」也是真的。被读成的一句假话,是把「协议在理想假设下的数学性质」读成「这台盒子在我的网络上不可攻破」的那个动作——而把这个动作做得最完整的,不是任何一家媒体,是 2016 年 8 月 16 日发射日的官方通稿本身。

本篇的独占格在第四章(原理账:安全证明到底证明了什么——九条假设全表,每条带提出者自己的逐字句)、第五章(实施安全账:2007→2026 攻破—补丁—再攻破二十年完整时间线,到 2026 年仍有黑盒渗透窃听 98.97% 筛选密钥的公开结果)、第六章(部署兑现账:所有招牌距离的可信中继口径分解+性能分母账+Wehner 2018 六级框架下「量子互联网」的真实位置)、第七章(制度与产业账:站位分裂〔NSA/NCSC/四国情报口 vs EuroQCI/中国国标〕与国盾量子年报里的补贴驱动账)、第九章(反向红跳四句审计——含「QKD 是骗局」「PQC 已彻底解决」「西方贬低因为中国领先」三句的取证)。

灵魂句:安全证明是真的,攻击史是真的,干线是真的,不背书也是真的——被读成的一句假话,是把「在明示假设下可证明安全」读成「无条件不可攻破」的那个动作。做这个动作的不是某一家媒体:是发射日通稿里的「不可窃听、不可破解、永久性解决信息安全问题」,是设备商官网的「无条件安全数据传输」,是十三年不断货的 unhackable 标题——也是每一处把「 trusted relay structure 」从摘要里剥掉的转述。而每个环节的线头,都印在档案里。

一、本篇测什么

1.1 被审对象

被审的是一组互相咬合的说法及其用法

  • 安全句:「量子通信不可窃听、不可破解、无条件安全」(从原理宣称到产品承诺)
  • 部署句:「量子安全通信时代已到来」「全球首个量子互联网已建成」(从工程里程碑到范式宣称)
  • 站位句:「QKD 是后量子威胁的(首选/唯一)解法」(从一种选项到路线答案)
  • 名号句:「量子互联网」(从学术路线图概念到已建成工程)

1.2 结构胎记

安全跳 × 部署跳 × 站位跳 + 反向红跳。

  • 安全跳:把「协议在理想假设下的数学性质(可证明安全)」读成「工程系统无条件安全」——RMP 2009 对「unconditional security」的定义与警告逐字;Shor-Preskill 对弱相干源的留白逐字;九条假设总表;然后是工程侧二十年攻破—补丁—再攻破史(2008 时移打改装 ID-500 → 2010 致盲 fully crack Clavis2+QPN 5505 → 看门狗补丁三缺陷 → MDI 关探测器侧信道 → 源侧被 hack → 2023 拿到 MDI 全部最终密钥 → 2026 黑盒窃听 98.97% 筛选密钥);ETSI GS QKD 008 自认「符合要求必要但不充分」。
  • 部署跳:把「建成可信中继 QKD 干线/星地链路」读成「量子安全通信已到来/量子互联网已建成」——京沪干线 2000 余公里与 20 kbps 的口径还原;墨子号三大成果的距离口径(1200 km 星地/1203 km 地面站间距/1400 km 上行);4600 km=可信中继拼接(Nature 2021 摘要逐字);性能分母账(全线 20 kbps、星地 47.8 kbps/次过轨、1002 km 极限 9.53×10⁻¹² bit/pulse);Wehner 2018 原文判「current status…at the lowest stage – trusted-repeater networks」。
  • 站位跳:把「QKD 是后量子威胁的一种候选解法」读成「QKD 是(首选/唯一)解法」——NSA 五条理由+「NSS owners should not use or research QKD at this time」;NCSC「not endorse…for any government or military applications」+评估框架不计分;法德荷瑞四国 2024-01-26 联合立场「the clear priority should therefore be the migration to post-quantum cryptography」;而同一批国家全部签约 EuroQCI,欧委会称其为「main pillars of the EU’s Cybersecurity Strategy」——分裂是白纸黑字的制度事实,不是任何一方的误读。
  • 反向红跳(第九章):四句反向审计——「QKD 是骗局/量子力学没用」不立(安全证明是定理级工作,攻击论文自述打的是实现);「QKD 一文不值」强版不立、弱版(场景窄、须混合)成立(选举、洲际通话、150 用户、银行电网均有一手);「PQC 已彻底解决、QKD 多余」不立(SIKE 单核十分钟、Rainbow 一周末、NIST 信心分级与 crypto-agility 官方措辞);「西方贬低 QKD 因为中国领先」不立(NSA/NCSC 全文零国别字眼,欧盟/日本/美国自建行为与之矛盾;实体清单证明地缘博弈存在但不能判定贬低动机)。

1.3 落位:section B1 与分界

本篇落 section B1(前沿兑现审计),与三篇邻近篇分界写死:

  • 与量子纠缠篇(2026-07-19:那篇裁 Bell 非局域性的物理资源账与「量子纠缠=超光速通信」的误读,其 §13.3 已裁「4600 km 网络不是量子互联网」一句话框架。本篇不重做 Bell 物理裁决(DI-QKD 的 Bell 自检验只引用其结论),本篇审的是工程兑现、制度立场与产业叙事。
  • 与容错量子计算篇(2026-08-02,第 119 篇:那篇审算力兑现(逻辑量子比特、容错阈值)。本篇审安全通信兑现;「Shor 算法威胁 RSA」作为 QKD/PQC 共同的需求侧前提只引用不重审。
  • 与 3nm 篇(第 147 篇)/NANOGrav 篇(第 146 篇)同族不同物:3nm 篇是名号跳(代号读成物理尺寸)、NANOGrav 篇是宣布学(限定语剥成完成时),本篇是「原理安全读成工程安全」——三篇共用「限定词印在文件里、错位发生在文件外」的形状。

1.4 去重实测

python 全库扫描 207 篇 / 7,636,581 字符:QKD 20 处/量子互联网 4 处/量子中继 9 处/可信中继 3 处/设备无关 21 处/墨子号/Micius 4 处——全部集中在 2026-07-19 量子纠缠篇(Bell 资源账与工程框架义);quantum key distributionquantum cryptographydecoy state诱骗态MDI-QKDtwin-field京沪干线trusted nodepost-quantum(密码义)/PQCQKDN国盾量子ID Quantique 全库零命中——QKD 兑现审计专篇零命中,处女地;与纠缠篇邻近但不重叠(分界见 1.3)。

1.5 边界

  • 不裁决量子计算/量子纠缠的物理问题(归容错量子篇与纠缠篇)。
  • 不评价任何国家发展 QKD 的政策选择;涉及中国部署处只登记官方通稿、上市公司披露与同行评议论文。
  • 涉及企业财务处只登记监管披露文件(巨潮/SEC)逐字数字,不作投资判断。
  • 本篇不提供任何安全采购建议;NSA/NCSC 等机构的立场以其官方文本为准逐字登记。

1.6 方法备案

  • 取证通路:arXiv abs 页 curl 直抓(sleep 2.5s 遵守限流);APS 摘要页可直抓;nature.com 摘要可抓、正文付费墙(Nature News 旧文走当年 Wayback 快照);nsa.gov 403 → Wayback CDX+id_ 原件;media.defense.gov 403 → Wayback;etsi.org 部分反爬(GS QKD 008 走 Wayback);巨潮 cninfo 年报 PDF 直取(国盾 2025 年报巨潮仅「XBRL 版」即 261 页全文);SEC EDGAR 直取;中国科大新闻网/央媒通稿直取。
  • 承重统计一律 python3。
  • 任务书预设勘误 9 处(全部有落盘证据,明细见附录 A):MDI-QKD 正确 arXiv 为 1109.1473(任务书 1111.3082 实为 Navier-Stokes 论文);TF-QKD 正确 arXiv 为 1811.06826(任务书 1803.00554 实为文献计量学论文);Lo-Ma-Chen 诱骗 PRL 正确号为 quant-ph/0411004(任务书 /0503004 实为 Lo 独作另一篇);DI-QKD Zhang/Liu 载体被任务书对调且「PRL 128, 090503」查无此文;Castryck-Decru SIKE 攻破正确源为 ePrint 2022/975(任务书 2207.07261 实为浅水方程论文);时移 2008 打的是改装 ID-500(Clavis2+QPN 5505 是 2010 致盲篇);墨子号星地 QKD 与地星传态载 Nature 549(非 Science)、纠缠分发载 Science 356;Nature 2021 4600km 无 arXiv 版(任务书 2011.06852 实为车辆重识别论文);东芝 pr1901 原文为「start providing…platforms」非「first commercially available」。

二、核验标记与层速览

核验标记沿用本库四档:[一手逐字]=原文逐字取自实际取回文件(含 Wayback id_ 原件);[文献较稳]=多源一致或权威评估;[需亲核]=正文未全取回或版本存疑;[多源检索]=方法学阴性检索(含「缺席即证据」登记)。

名称 核心问题 裁决方向
守真锚 证明/卫星/干线/立场/年报 一条不动
原理账 安全证明到底证明了什么 有明示条件的信息论命题
实施安全账 工程系统被攻破过吗 二十年攻破—补丁—再攻破
部署兑现账 距离与速率的真实口径 可信中继拼接+分母悬殊
制度与产业账 谁背书、谁买单 站位分裂+补贴驱动
消费与传播账 「不可破解」谁在生产 通稿源头+十三年谱系
反向红跳 四句反向读法 全不立(一句弱版成立)
母裁决 一句话裁决 见末章

三、守真锚(这一侧一条都不动)

1. BB84 是真的,原始载体可考。 1984 年 12 月班加罗尔 IEEE 国际会议(Computers, Systems & Signal Processing)会议录 175–179 页;arXiv:2003.06557 为扫描重印件,其 Comments 字段逐字「This is a best-possible quality scan of the original so-called BB84 paper as it appeared in the Proceedings of the International Conference on Computers, Systems & Signal Processing, Bangalore, India, pp. 175-179, December 1984」[一手逐字];2014 年《Theoretical Computer Science》Vol. 560 出版 30 周年重排版(pp. 7-11,DOI 10.1016/j.tcs.2014.05.025,Crossref 核验)。摘要关键句逐字:「a communications channel on which it is impossible in principle to eavesdrop without a high probability of disturbing the transmission in such a way as to be detected…to distribute random key information between two users with the assurance that it remains unknown to anyone else, even when the users share no secret information initially」[一手逐字]——注意「in principle」(原则上)这个词从第一页起就在。

2. Ekert 1991(E91)是真的,且不在 arXiv 上。 PRL 67, 661-663(1991-08-05),APS 摘要页逐字「Practical application of the generalized Bell’s theorem in the so-called key distribution process in cryptography is reported…Bell’s theorem is used to test for eavesdropping」[一手逐字];arXiv API 按提交日期升序检索 Ekert 全部 28 条最早为 1995-03-24——E91 早于 arXiv 本身(quant-ph 档案 1994 年末才建),两大奠基文中只有 BB84 有 arXiv 重印[一手逐字]。

3. Shor & Preskill 2000 的安全证明是真的,其假设与留白也印在同一篇里。 PRL 85, 441-444(2000);arXiv:quant-ph/0003004 摘要逐字「We prove the security of the 1984 protocol of Bennett and Brassard (BB84) for quantum key distribution. We first give a key distribution protocol based on entanglement purification, which can be proven secure using methods from Lo and Chau’s proof…We then show that the security of this protocol implies the security of BB84.」[一手逐字];正文末段逐字「A weakness in both the proof given in this paper and the proofs in [3, 4] is that they do not apply to imperfect sources; the sources must be perfect single-photon sources. … However, most experimental quantum key distribution systems use weak coherent sources, and no currently known proof covers this case.」[一手逐字]——证明者自己写明:证明只吃完美单光子源,而当时实验普遍使用的弱相干源没有证明覆盖。速率阈值逐字「This can work as long as the measured bit and phase error rates are less than 11%」[一手逐字]。

4. 墨子号三大成果与京沪干线开通是真的。 星地 QKD(Nature 549, 43 (2017);arXiv:1707.00542)摘要逐字「decoy-state QKD with over kHz key rate from the satellite to ground over a distance up to 1200 km, which is up to 20 orders of magnitudes more efficient than that expected using an optical fiber (with 0.2 dB/km loss) of the same length」[一手逐字];纠缠分发(Science 356, 1140-1144 (2017);arXiv:1707.01339)「distribution of entangled photon pairs to two locations separated by 1203 km on the Earth」[一手逐字];地星隐形传态(Nature 549, 70 (2017);arXiv:1707.00934)「the first quantum teleportation of independent single-photon qubits from a ground observatory to a low Earth orbit satellite…with a distance up to 1400 km」[一手逐字]。京沪干线 2017-09-29 开通:新华社通稿(人民日报海外版 2017-09-30 第 02 版)逐字「世界首条量子保密通信干线——『京沪干线』29日正式开通……连接北京、济南、合肥、上海的全长2000余公里的量子保密通信骨干线路已全线贯通……『京沪干线』线路密钥率大于20千比特/秒(kbps),可满足上万名用户的密钥分发业务需求」[一手逐字]。

5. Nature 2021 的 4600 公里集成网络是真的——可信中继四个字印在摘要里。 Chen et al., Nature 589, 214–219 (2021)(该文无 arXiv 版)摘要逐字「Here we demonstrate an integrated space-to-ground quantum communication network that combines a large-scale fibre network of more than 700 fibre QKD links and two high-speed satellite-to-ground free-space QKD links. Using a trusted relay structure, the fibre network on the ground covers more than 2,000 kilometres…The satellite-to-ground QKD achieves an average secret-key rate of 47.8 kilobits per second for a typical satellite pass…enabling any user in the network to communicate with any other, up to a total distance of 4,600 kilometres.」[一手逐字](nature.com 摘要直抓成功;正文付费墙,「150 users」原句以中科院英文官网逐字补足:「realized quantum key distribution between more than 150 users over a combined distance of 4,600 km」[一手逐字])。

6. NSA 与 NCSC 的不背书立场是真的,逐字可考。 NSA 官网「Quantum Key Distribution (QKD) and Quantum Cryptography (QC)」页(直抓 403,经 Wayback 2026-06-10 快照 id_ 原件)逐字「NSA does not recommend the usage of quantum key distribution and quantum cryptography for securing the transmission of data in National Security Systems (NSS) unless the limitations below are overcome」;结论段逐字「In summary, NSA views quantum-resistant (or post-quantum) cryptography as a more cost effective and easily maintained solution than quantum key distribution. For all of these reasons, NSA does not support the usage of QKD or QC to protect communications in National Security Systems, and does not anticipate certifying or approving any QKD or QC security products for usage by NSS customers unless these limitations are overcome.」[一手逐字];CNSA 2.0 FAQ(2024-12 v2.1,media.defense.gov 经 Wayback)逐字「Q: Can I use a QKD system to protect my national security system from a quantum computer? A: No. …NSS owners should not use or research QKD at this time without consulting NSA directly.」[一手逐字]。NCSC 白皮书(2020-03-24 发布,现行版 2026-05-15 更新)逐字「the NCSC does not endorse the use of QKD for any government or military applications, and cautions against sole reliance on QKD for business-critical networks, especially in Critical National Infrastructure sectors」「For those organisations using the NCSC Cyber Assessment Framework, a QKD system may not contribute to any assessment of principle B3.b (Data In Transit).」[一手逐字]。

7. NIST 首批 PQC 标准落地是真的。 NIST 2024-08-13 新闻稿逐字「NIST has finalized its principal set of encryption algorithms designed to withstand cyberattacks from a quantum computer」「are ready for immediate use」;FIPS 203(ML-KEM,基于 CRYSTALS-Kyber)/FIPS 204(ML-DSA)/FIPS 205(SLH-DSA);项目负责人 Dustin Moody 逐字「There is no need to wait for future standards…Go ahead and start using these three.」[一手逐字]。

8. 国盾量子(688027)年报数字是真的。 2025 年年度报告(巨潮 XBRL 版即 261 页全文,2026-03-25 披露)逐字「报告期内,公司实现营业收入 31,045.71 万元,比上年同期增长 22.53%;归属于上市公司股东的净利润 539.19 万元,比上年同期增加 3,723.33 万元,同比扭亏为盈」;扣非净利润 -43,549,741.50 元(2024 年 -62,639,950.01;2023 年 -157,579,055.39);「报告期内公司利润总额、归属于上市公司股东的净利润转正,主要系报告期内公司量子计算领域营业收入增长、计入当期损益的政府补助及投资收益增长所致」;计入当期损益的政府补助本期合计 42,924,544.79 元;「前五名客户销售额19,717.48万元,占年度销售总额63.51%;其中前五名客户销售额中关联方销售额13,485.90万元,占年度销售总额43.44%」;股东结构「中电信量子集团直接持有公司股份比例为 21.86%……拥有的股份表决权比例为 40.43%」[一手逐字]。

9. 「无条件安全」一词的谱系是真的,定义者自带警告。 Mayers 2001(JACM 48(3), 351-406;arXiv:quant-ph/9802025)定义句逐字「In quantum key distribution, and ideally in other applications of quantum cryptography, a security result is expected to hold against all attacks allowed by quantum mechanics. This is what is called an unconditional security, and this is what we will prove.」——且同文明示假设「we will assume that the source transmits a single photon per pulse with the exact polarization angle specified in the protocol」[一手逐字];RMP 2009(§II.3.1)逐字「This technical term means that security can be proved without imposing any restriction on the computational resources or the manipulation techniques that are available to the eavesdropper acting on the signal」「Like many other technical terms, the wording “unconditional security” has to be used in its precise meaning given above, and not as a synonym of “absolute security” — something that does not exist. As a matter of fact, unconditional security of QKD holds under some conditions.」[一手逐字]。

10. 洲际量子保密通信是真的——卫星持有全部密钥。 Liao et al., PRL 120, 030501 (2018);arXiv:1801.04418 摘要逐字「Then, upon request from the ground command, Micius acts as a trusted relay. It performs bitwise exclusive OR operations between the two keys and relays the result to one of the ground stations. That way, a secret key is created between China and Europe at locations separated by 7600 km on Earth.」[一手逐字];奥地利科学院官方新闻稿逐字「This first ever quantum cryptographically secured video call on 29 September 2017 between Vienna and Beijing spanned two continents.」[一手逐字](同稿宣传口径「at least a million times safer」系该院新闻措辞,如实标注)。

四、原理账:安全证明到底证明了什么(安全跳·原理侧)

本章把「无条件安全」这个词拆回它的技术定义,并把证明者自己写下的假设一条一条摆出来。结论先行:原理层证的是「在满足明示假设的模型内安全」,从未证明「任何工程实现安全」——这不是本篇的解读,是每一篇承重论文自己写的。

4.1 定义:「无条件安全」限缩的是窃听者,不是假设

「unconditional security」作为技术术语的通行定义(RMP 2009 §II.3.1,逐字见守真锚 9):对窃听者的计算资源与操作技术不设任何限制——安全由信息论保证而非由计算难题保证。但同节紧接着两句:它不是「absolute security」的同义词(「something that does not exist」),且「unconditional security of QKD holds under some conditions」。即:「无条件」限定的是对手能力模型,不是系统假设;假设清单列在证明的边界条件里。

4.2 假设总表:九条,每条带提出者自己的逐字句

# 假设 提出者逐字句 出处
1 经典信道必须认证——QKD 出厂不解决认证 「no quantum key distribution protocol can succeed if Eve has the power to impersonate Alice while communicating with Bob and to impersonate Bob while communicating with Alice…There exist unconditionally secure techniques for authentication [Wegman and Carter 1981] that require that Alice and Bob share a small secret key to begin with, so that the protocol implements key expansion rather than key distribution.」 Mayers 2001(JACM 48, 351)[一手逐字]
1′ 同上,综述权威表述 「The classical channel needs to be authenticated…Failure to authenticate the classical channel can lead to the situation where Eve impersonates one of the parties to the other, thus entirely compromising the security.」 RMP 2009 §I.2/§II.2[一手逐字]
2 真随机数必须可信 「Alice and Bob must trust the random number generators that select the state to be sent or the measurement to be performed.」 RMP 2009 §II.3.1 条件 2[一手逐字]
3 设备不被入侵(无旁路泄漏) 「Eve cannot intrude Alice’s and Bob’s devices to access either the emerging key or their choices of settings…」 RMP 2009 §II.3.1 条件 1[一手逐字]
4 完美单光子源(早期证明) 「the sources must be perfect single-photon sources…most experimental quantum key distribution systems use weak coherent sources, and no currently known proof covers this case.」 Shor-Preskill 2000 正文末段[一手逐字];Mayers 2001「the source transmits a single photon per pulse with the exact polarization angle」[一手逐字]
5 不完美设备→缺陷须小且基相关 「Our proof applies when both the source and the detector have small basis-dependent flaws, as is typical in practical implementations of the protocol.」 GLLP 2004 摘要[一手逐字]
6 弱相干源→诱骗态补丁 「We propose a decoy-state method to overcome the photon-number-splitting attack…」 Hwang 2003(2002-11-24 提交)[一手逐字]
7 探测器侧信道→MDI 移除,但源端需「几乎完美态制备」 「It not only removes all detector side channels…」+「MDI-QKD requires the additional assumption that Alice and Bob have almost perfect state preparation.」 Lo, Curty, Qi 2012 摘要+正文[一手逐字]
8 有限密钥长度修正 「existing security proofs are often only valid asymptotically for unrealistically large values of M. Here, we demonstrate that this gap between theory and practice can be overcome…security against general attacks can be guaranteed already for moderate values of M.」 Tomamichel et al., Nat. Commun. 3, 634 (2012)[一手逐字]
9 直传速率物理天花板 「Q₂ = K = −log₂(1−η) where η is the transmissivity…At high loss η≃0 we find the optimal rate-loss scaling of K≃1.44η secret bits per channel use.」 PLOB 2017(Nat. Commun. 8, 15043)[一手逐字]

第 1 条值得单独停顿:QKD 的认证信道需要预共享密钥(或经典非对称密码),因此 Mayers 逐字判定它实现的是 key expansion rather than key distribution——密钥「扩增」而非密钥「分发」。这句 2001 年的定性,二十年后原样出现在 NSA 不推荐理由的第一条(「QKD does not provide a means to authenticate the QKD transmission source」,见第七章)。

4.3 补丁史:每一代证明都在补上一代明写的洞

  • PNS 攻击出处三连:Huttner et al. 1995(PRA 51, 1863;arXiv:quant-ph/9502020)首议弱相干态窃听;Brassard, Lütkenhaus, Mor, Sanders 2000(PRL 85, 1330;arXiv:quant-ph/9911054)摘要逐字「existing experimental schemes (based on “weak-pulse”) are usually totally insecure」[一手逐字];Lütkenhaus & Jahma 2002(NJP 4, 44;arXiv:quant-ph/0112147)逐字「the most powerful tool at the disposition of an eavesdropper is the photon-number splitting attack」[一手逐字]——光子数分离攻击被命名为最强攻击。
  • 诱骗态三连:Hwang 2003(2002-11-24 提交,首发)逐字「A legitimate user intentionally and randomly replaces signal pulses by multi-photon pulses (decoy-states)…If the loss of the decoy-states is abnormally less than that of signal pulses, the whole protocol is aborted.」[一手逐字];Wang 2005(PRL 94, 230503)逐字「we show that so far our protocol is the only decoy-state protocol that really works for currently existing set-ups」(”pluses” 为原文拼写)[一手逐字];Lo, Ma, Chen 2005(PRL 94, 230504)逐字「we have the best of both worlds–enjoying unconditional security guaranteed by the fundamental laws of physics and yet dramatically surpassing even some of the best experimental performances」[一手逐字]——注意这句「unconditional security guaranteed by the fundamental laws of physics」是论文摘要原文:物理学共同体自己先把「无条件安全由物理定律保证」写进了摘要,后来的传播链只是把它放大。
  • MDI-QKD 2012Lo, Curty, Qi, PRL 108, 130503 摘要逐字「How to remove detector side channel attacks has been a notoriously hard problem in quantum cryptography. Here, we propose a simple solution…It not only removes all detector side channels, but also doubles the secure distance with conventional lasers.」[一手逐字];正文逐字「MDI-QKD requires the additional assumption that Alice and Bob have almost perfect state preparation. However, we believe that this is only a minor drawback…」[一手逐字]——信任没有消失,从探测器移到了源端;正文脚注 22 逐字「our new scheme has a tremendous advantage of being immune to all detector side channel attacks」[一手逐字]。
  • TF-QKD 2018Lucamarini, Yuan, Dynes, Shields, Nature 557, 400-403arXiv:1811.06826)Nature 版摘要逐字「The key rate of this twin-field QKD exhibits the same dependence on distance as does a quantum repeater, scaling with the square-root of the channel transmittance…unlike schemes that involve quantum repeaters, ours is feasible with current technology…This scheme is a promising step towards overcoming the rate–distance limit of QKD」[一手逐字]——措辞是「promising step towards」(有希望的一步);arXiv 版摘要多出一句 Nature 版删去的限定:「as we prove under an explicit security assumption」[一手逐字]。
  • PLOB 上限Pirandola, Laurenza, Ottaviani, Banchi, Nat. Commun. 8, 15043 (2017) 逐字「These two-way assisted capacities represent the ultimate rates that are reachable without quantum repeaters…Our findings set the limits of point-to-point quantum communications」——无中继直传的密钥率有硬上限 −log₂(1−η)(高损耗时 ≈1.44η bits/次)[一手逐字]。这是「直传光纤有物理天花板」的承重格,第六章的速率分母账以此封顶。

4.4 DI-QKD:把假设压到最薄,代价是速率

设备无关 QKD 把安全锚在 Bell 违规的实验统计上(不信任设备内部)。2022 年三篇开创实验全部逐字落盘:

  • Nadlinger et al.(牛津,囚禁离子)Nature 607, 682-686arXiv:2109.14600)摘要逐字「we obtain 95,628 key bits with device-independent security from 1.5 million Bell pairs created during eight hours of run time」「These measurements are performed without space-like separation.」「Our result shows that provably secure cryptography under general assumptions is possible with real-world devices」[一手逐字]——8 小时 150 万 Bell 对产出 95,628 密钥比特,且明示无空间分离。
  • Zhang et al.(慕尼黑,囚禁原子)Nature 607, 687-691arXiv:2110.00575)摘要逐字「two independently trapped single rubidium atoms located in buildings 400 metre apart…a significant violation of a Bell inequality of S = 2.578(75)—above the classical limit of 2…this results in a secret key rate of 0.07 bits per entanglement generation event in the asymptotic limit」[一手逐字]——每次纠缠产生 0.07 比特(渐近极限下)。
  • Liu et al.(中科大,光子)PRL 129, 050502arXiv:2110.01480,arXiv 题与 PRL 题不同)摘要逐字「detection efficiency about 87.5%…a positive key rate under the fiber length up to 220 m」「Although our experiment does not include random basis switching…」「an important step towards a full demonstration」[一手逐字]——220 米光纤、无随机基切换、仅对 collective attacks。

三篇共同格:科学价值是定理级的(密钥安全锚在量子理论有效性+实验观测统计上,Bell 违规自检验),但密钥率极低、距离极短、各带限定——DI-QKD 是原理的圣杯,不是工程的答案。

4.5 原理层小结

原理层安全证明是一部真实的、持续改进的定理级工作:从理想 BB84(SP2000)到不完美设备(GLLP)、到诱骗态(三连)、到 MDI(关探测器侧信道)、到 TF(破速率-距离标度)、到 DI(最少假设)。每一代的摘要都在宣称进展,而每一代的正文都把假设写得清清楚楚。「无条件安全」在文献内部从未意为「绝对安全」——跳变发生在文献之外。下一章看工程侧发生了什么。

五、实施安全账:攻破—补丁—再攻破二十年(安全跳·工程侧)

原理证明模型内安全,工程系统运行在现实里。本章按时间线登记 2007→2026 年公开发表的攻击与补丁,全部条目有一手摘要或全文落盘。先说一句对称的话:这不是「QKD 被打死」的历史——攻击论文的作者们自己把这定性为「识别并修补技术缺陷以强化实用 QKD」(Lydersen 2010 摘要逐字「We believe that our findings are crucial for strengthening the security of practical QKD, by identifying and patching technological deficiencies.」[一手逐字]);但这同样不是「无条件安全已兑现」的历史——攻破—补丁—再攻破的循环到 2026 年仍在继续。

5.1 第一格:时移攻击(2007 理论 / 2008 实验)

  • 理论:Qi, Fung, Lo, Ma 2007(Quant. Inf. Comput. 7, 073) 摘要逐字「we propose another “time-shift” attack that exploits the same imperfection…Eve, in principle, could acquire full information on the final key without introducing any error.」[一手逐字]——两台单光子探测器效率随时间错开,Eve 平移脉冲到达时间即可原则上零误码拿全密钥。
  • 实验:Zhao, Fung, Qi, Chen, Lo 2008(PRA 78, 042333) 摘要逐字「Here, we show experimentally for the first time a technologically feasible attack, namely the time-shift attack, against a commercial QKD system. Our result shows that, contrary to popular belief, an eavesdropper, Eve, has a non-negligible probability (~4%) to break the security of the system.」[一手逐字];全文点名被攻击系统:「The experiment is performed on top of a modified commercial ID-500 QKD setup manufactured by id Quantique.」[一手逐字]——首次对商用 QKD 的完整攻击演示,对象是改装的 ID-500(任务书把它记成 Clavis2/QPN 5505,勘误;那两台是 2010 年致盲篇的对象)。

5.2 致盲攻击:两台商用机被「fully cracked」(2010)

Lydersen et al., Nature Photonics 4, 686-689 (2010) 摘要逐字「Here we demonstrate experimentally that the detectors in two commercially available QKD systems can be fully remote-controlled using specially tailored bright illumination. This makes it possible to tracelessly acquire the full secret key; we propose an eavesdropping apparatus built of off-the-shelf components. The loophole is likely to be present in most QKD systems using avalanche photodiodes to detect single photons.」[一手逐字];全文逐字「we demonstrate how two commercial QKD systems id3110 Clavis2 and QPN 5505, from the commercial vendors ID Quantique and MagiQ Technologies, can be fully cracked. … Remarkably the detectors exactly measure what is dictated by Eve」;实验细节「each detector was blinded with 1.08 mW optical power」[一手逐字]——毫瓦级连续光把门控雪崩光电二极管打成经典线性探测器,再叠加触发脉冲,Eve 让探测器「测她指定的比特」,无痕取走全部密钥。

同月后续(Nature Photonics 同期 Correspondence):东芝剑桥 Yuan, Dynes, Shields「Avoiding the blinding attack in QKD」(Nat. Photon. 4, 800-801)+Lydersen 组同题回复(4, 801)[一手元数据]——攻击与补丁的赛跑从第一仗就开始。

5.3 补丁—再攻破循环(2010–2016)

每条均一手摘要落盘:

  1. 热致盲Lydersen et al. 2010, Opt. Express 18, 27938):「the detectors in a commercial QKD system Clavis2 can be blinded by heating the avalanche photo diodes (APDs) using bright illumination, so-called thermal blinding」——同一漏洞第二种物理机制。
  2. 门后攻击Wiechers et al. 2011, NJP 13, 013043):「We have experimentally tested detectors of the system id3110 (Clavis2) from ID Quantique. We identify the parameter regime in which the attack is feasible despite the side effect.」
  3. 主动淬灭探测器被控Sauge et al. 2011, Opt. Express 19, 23590):「the commercial detector model we tested (PerkinElmer SPCM-AQR) exhibits two new blinding mechanisms…These two new technical loopholes found just in one detector model suggest that this problem must be solved in general」——仅一个探测器型号就发现两种新机制,作者自己说问题必须一般性地解决。
  4. 完美窃听者全场实现Gerhardt et al. 2011, Nat. Commun. 2, 349):「the first full-field implementation of a complete attack on a running QKD connection. An installed eavesdropper obtains the entire ‘secret’ key, while none of the parameters monitored by the legitimate parties indicate a security breach.」——运行中的 QKD 连接被完整窃听,合法方监控的所有参数无一示警
  5. 攻击校准程序Jain et al. 2011, PRL 107, 110501):「a method to induce a large temporal detector efficiency mismatch in a commercial QKD system by deceiving a channel length calibration routine」——打的是校准流程本身。
  6. 激光损伤制造永久漏洞Bugge et al. 2014, PRL 112, 070503):「After about 1.5 W, the detectors switch permanently into the linear photodetection mode and become completely insecure for QKD applications.」——Eve 主动打坏器件来制造新漏洞。
  7. 看门狗补丁本身被攻破Sajeed et al. 2015, PRA 91, 032326):「Implementation of a monitoring detector has largely been ignored so far, except for ID Quantique’s commercial QKD system Clavis2. We scrutinize this implementation for security problems…Indeed the first implementation has three serious flaws confirmed experimentally.」——Clavis2 为防致盲加的监控探测器补丁,第一版实现有三个经实验确认的严重缺陷
  8. 激光损伤后门Makarov et al. 2016, PRA 94, 030302(R),作者含 ID Quantique 的 M. Legré):激光损伤把隔离器/衰减器打出后门[一手全文]。

5.4 其它侧信道(各至少一条一手)

5.5 MDI 之后还剩什么:源侧成为新攻击面

MDI-QKD(2012)关掉了全部探测器侧信道,但把信任移到了源端——源随即成为攻击面:

  • 激光注入(seeding)Huang et al. 2019(PR Applied 12, 064043) 摘要逐字「An essential assumption in MDI-QKD is however that the sources are trusted. Here we experimentally demonstrate that a practical source based on a semiconductor laser diode is vulnerable to a laser seeding attack…The unnoticed increase of intensity may compromise the security of QKD, as we show theoretically for the prepare-and-measure decoy-state BB84 and MDI-QKD protocols.」[一手逐字]
  • 注入锁定直接 hack MDIPang et al. 2020(PR Applied 13, 034008) 摘要逐字「we propose and experimentally demonstrate an MDI-QKD hacking strategy on the trusted source assumption by using injection locking technique…obtain a hacking success rate reaching 60.0% of raw keys.」[一手逐字]
  • MDI 全部最终密钥被拿到Lu, Ye et al. 2023(Optica 10, 520-527) Crossref 摘要逐字「However, the loopholes in the source side still open side channels to eavesdroppers. … Using our method, we experimentally hacked a MDI-QKD system and successfully obtained all final keys.」[一手元数据]——「关掉了所有探测器侧信道」的系统,在源侧被拿走了全部最终密钥
  • 高速调制强度关联Yoshino et al. 2018(npj Quantum Inf. 4, 8)「Such correlation violates the assumption of most security theories.」[一手逐字]
  • 光折变攻击Ye et al. 2023(PR Applied 19, 054052):铌酸锂光折变效应被用作源侧攻击,仅数纳瓦注入即可[一手逐字]。

5.6 攻击没有停止:2022–2026

  • 2022:Gao et al.(PRA 106, 033713) 强脉冲打高速自差分 APD[一手逐字]。
  • 2024:COW 协议零误码攻击现实可行(Rey-Domínguez et al., Quantum Sci. Technol. 9, 035044「zero-error attacks could break the security of COW QKD even assuming realistic experimental conditions」);QRate 商用机按实施漏洞做认证整改(Makarov et al., PR Applied 22, 044076)[一手逐字 ×2]。
  • 2025:1 GHz 高速系统「muted attack」(Su et al.「Eve can mute Bob’s SPADs…allowing her to learn nearly all the keys」)[一手逐字]。
  • 2026:黑盒渗透测试(Huang, Peng et al., Natl. Sci. Rev., DOI 10.1093/nsr/nwag174)逐字「toggles an optical delay in the quantum communication line…passively eavesdrop on 98.97% of the sifted key」[一手全文]——只动量子/经典公开信道,被动窃听 98.97% 的筛选密钥(被测系统为「engineering-validated QKD prototype」,非点名市售机型,如实注明);同年高速系统定制致盲脉冲(Kang et al., PR Applied 25, 024053)[一手元数据]。

5.7 产业回应侧:两个样本

  • Makarov 2014 讲座幻灯片逐字U Waterloo seminar PDF):「ID Quantique got a detailed vulnerability report – reaction: requested time, developed a patch — M. Legre, G. Ribordy, intl. patent appl. WO 2012/046135 A2 (filed in 2010). MagiQ Technologies got a detailed vulnerability report – reaction: informed us that QPN 5505 is discontinued.」[一手全文]——IDQ 要时间、打了补丁并申请了专利;MagiQ 回复涉事机型 QPN 5505 已停产。
  • 有限密钥攻击与厂商合作:Chaiwongkhot, Sajeed, Lydersen, Makarov 2016「Finite-key-size effect in commercial plug-and-play QKD system」(QCrypt 2016 投稿件,PDF 全文落盘 tmp/qkd/raw/B/,未挂公开链接)摘要逐字「We demonstrate the ability of an eavesdropper to control the raw-key size in a commercial plug-and-play QKD system Clavis2 from ID Quantique…Experimentally, we could consistently force the system to generate the key outside of the secure regime. We also test manufacturer’s software update that patches this problem.」;结论逐字「We have also investigated the security update from ID Quantique, and found that the key generated by the new software is secure under finite-key-size analysis. … We thank ID Quantique for cooperation, technical assistance, and providing us the QKD hardware.」[一手全文]——攻击组与厂商实质合作、验证软件更新有效。这是「可管理的工程问题」一侧最硬的一手证据。

5.8 标准自己的诚实:ETSI GS QKD 008

ETSI GS QKD 008 V1.1.1 (2010-12)「QKD Module Security Specification」(etsi.org 现站 JS 挑战,走 Wayback 原件):

  • 范围段逐字「requirements that protect the QKD modules against non-invasive attacks are also provided」,并明言「conformance to them is necessary but not sufficient to ensure that a particular module is secure.」[一手逐字]——标准自己写明:符合要求是必要的,但不是充分的
  • 物理安全条款逐字「A QKD module shall employ physical security mechanisms in order to restrict unauthorized physical access to the contents of the module…」,要求表含「Vents protected from probing.」[一手逐字]——通风口防探 2010 年就写进了标准;2020 年 Clavis2 仍被从通风口注光打进(§5.4)。条款与现实的十年落差,一格尽收。

5.9 实施层小结

综述级的盖棺由领域自己写:Xu, Ma, Zhang, Lo, Pan 2020(RMP 92, 025002) 摘要逐字「After numerous attempts, researchers now thoroughly understand and are able to manage the practical imperfections. Recent advances, such as the measurement-device-independent protocol, have closed the critical side channels in the physical implementations, paving the way for secure QKD with realistic devices.」[一手逐字]——注意措辞是「closed the critical side channels」「paving the way」,不是「无条件安全已兑现」;2025 年网络安全视角综述(Gelles & Mor, arXiv:2508.04669)逐字「the ‘Bright Illumination’ attack could have been found even with minimal knowledge of the device implementation」[一手逐字]——最著名的攻击用最低限度的设备知识就能想到。实施安全是可管理但持续对抗的工程问题;「已解决」只适用于已认证、已打补丁的特定机型特定版本。

六、部署兑现账:距离、速率与可信中继(部署跳)

本章回答三个问题:那些招牌数字(2000 公里、4600 公里、7600 公里、12900 公里)的真实口径是什么;密钥率的分母有多大;按学界自己的阶段框架,「量子互联网」走到哪一级了。

6.1 京沪干线:开通口径还原

  • 名号与距离:新华社 2017-09-29 通稿逐字「世界首条量子保密通信干线——『京沪干线』29日正式开通……连接北京、济南、合肥、上海的全长2000余公里的量子保密通信骨干线路已全线贯通」[一手逐字]——「2000 余公里」是连接京沪济合四地的骨干线路总长,不是站间距,更不是单段无中继距离中国科大官网逐字:项目 2013 年 7 月国家发改委批复立项,建设周期 42 个月,2016 年底全线贯通和星地一体化对接,2017 年 8 月底在合肥完成全网技术验收[一手逐字]。
  • 速率:通稿逐字「『京沪干线』线路密钥率大于20千比特/秒(kbps),可满足上万名用户的密钥分发业务需求」[一手逐字]——20 kbps 是全线路口径。对比:同年墨子号星地链路单过轨 kHz 量级(守真锚 4)。
  • 开通日的「用户」新华网 2017-09-29(科大新闻网转载)逐字业务清单:「已实现北京、上海、济南、合肥、乌鲁木齐南山地面站和奥地利科学院6点间的洲际量子通信视频会议、交通银行京沪间远程企业网银用户的量子保密通信实时交易、中国工商银行网上银行京沪异地数据的量子加密传输和灾备、阿里征信数据的异地加密传输以及量子加密流媒体视频点播等应用示范」[一手逐字]——开通当日的真实业务是应用示范(交行网银、工行灾备、阿里征信、视频点播),不是常态付费客户清单。
  • 造价:[诚实空位] 开通通稿与科大官网均未公布造价,仅见「安徽省、山东省、合肥市和济南市共同配套投资建设」(无金额),登记空位不外推。

6.2 墨子号与洲际:三个距离口径,一个中继角色

  • 三个距离的口径分解(守真锚 4 已立):1200 km=星地链路最远距离(近地点到远地点区间,kHz 密钥率为点对点星地口径);1203 km=纠缠分发时地面两站(德令哈—丽江)间距,双下行链路总长 1600–2400 km;1400 km=地星上行隐形传态距离。三个数字在传播中常被混为一个「距离纪录」。
  • 7600 km 洲际PRL 120, 030501 (2018) 摘要逐字「Then, upon request from the ground command, Micius acts as a trusted relay. It performs bitwise exclusive OR operations between the two keys and relays the result to one of the ground stations. That way, a secret key is created between China and Europe at locations separated by 7600 km on Earth.」[一手逐字]——卫星本身持有全部密钥:可信中继的机制就写在摘要里,端到端并非「纯量子」。同文结语句逐字「Our work points towards an efficient solution for an ultralong-distance global quantum network, laying the groundwork for a future quantum internet.」[一手逐字]——注意是「laying the groundwork for a future quantum internet」(为未来的量子互联网奠基),不是「建成」。
  • 12900 km中科院微小卫星创新研究院 2025-03-20逐字:济南一号(世界首颗量子微纳卫星,2022-07-27 发射)「在国际上首次实现微纳量子卫星与小型化、可移动地面站之间的实时星地量子密钥分发……一次过轨对接实验可生成250 kbits-1Mbits的安全密钥,平均成码率可达3 kbps。以卫星作为可信中继,研究团队进一步实现了地面相距12900km北京站和南非斯泰伦博斯站之间的密钥共享和数据中继。」[一手逐字]——12900 km 仍是卫星作可信中继的端到端口径,官方稿自己写明。

6.3 4600 km 集成网络:摘要里的「trusted relay structure」

守真锚 5 已立摘要逐字。此处做口径分解:700 余条光纤 QKD 链路+2 条星地高速链路;地面光纤网「more than 2,000 kilometres」靠「Using a trusted relay structure」覆盖;星地平均密钥率 47.8 kbps 是「for a typical satellite pass」(单次典型过轨、点对点星地口径,「more than 40 times higher than achieved previously」);4600 km=把光纤网延伸到「a remote node more than 2,600 kilometres away」后任意两用户的最大跨度。整网架构在摘要中原样写明是可信中继拼接——这是对部署跳最硬的一格:里程碑是真的,中继也是真的,两者印在同一段摘要里。用户口径:央广网 2021-01-11(科大新闻网转载)逐字「整个网络覆盖我国四省三市32个节点,包括北京、济南、合肥和上海4个量子城域网,通过两个卫星地面站与『墨子号』相连,目前已接入金融、电力、政务等行业的150多家用户」[一手逐字]。

6.4 性能分母账:从城域链路到物理天花板

全部有落盘一手:

  • 京沪干线全线 20 kbps(新华社通稿);星地墨子号 kHz/次过轨、Nature 2021 平均 47.8 kbps/次典型过轨;济南一号实时平均成码率 3 kbps。
  • 合肥 46 节点城域网(Chen T.-Y. et al., npj Quantum Information 7, 134 (2021),开放获取)逐字「we construct a 46-node quantum metropolitan-area network throughout the city of Hefei, which connects 40 user nodes, three trusted relays and three optical switches」「The key rate results are summarized in Table 2, ranging from 6 to 60.5 kbps」「continuously run the network for 31 months」[一手逐字]——城域链路密钥率 6–60.5 kbps,连续运行 31 个月(运行稳定性是真的)。
  • 东京 QKD 网络 2010(NICT 新闻稿)逐字「key generation rates at around 100kbps allowing perfectly secure one-time pad encryption of video data in real time」「over 45 km」[一手逐字]。
  • 距离极限账(光纤直传、无可信中继):404 km MDI(Yin et al., PRL 117, 190501 (2016));511 km TF-QKD 现网干线盘纤Chen et al., Nat. Photonics 15, 570 (2021)「distribute secure keys without any trusted repeater over a 511 km long haul fiber trunk linking two distant metropolitans」——济南—青岛间 deployed fiber 口径);555/605 km(Pittaluga et al., Nat. Photonics 15, 530 (2021)「repeater-like key rates over communication distances of 555 km and 605 km in the finite-size and asymptotic regimes respectively」);833.8 km 实验室(Wang et al., Nat. Photonics 16, 154 (2022)「tolerate a channel loss beyond 140 dB」);1002 kmLiu et al., PRL 130, 210801 (2023))摘要逐字「The secure key rate is 9.53×10⁻¹² per pulse through 1002 km fiber in the asymptotic regime, and 8.75×10⁻¹² per pulse at 952 km considering the finite size effect.」[一手逐字]——每脉冲约 10⁻¹¹ 比特:即使乘以 GHz 级系统时钟也只有约 0.01–0.04 bps 量级(自算,算法:9.53×10⁻¹² bit/pulse × 10⁹ pulse/s ≈ 0.0095 bit/s)。这就是 PLOB 上限(第四章 9 号假设)在光纤上的形状:距离每进一步,速率按透射率指数往下掉。
  • [半空位] 星地链路的天气/时段限制:本调研未取到「墨子号仅夜间/晴好工作」的逐字一手;济南一号官方稿将「天光地影量子通信」列为新突破技术,可旁证此前受昼夜限制。登记待补。

6.5 国际部署清单:真实但全部是点/城域级

  • 日内瓦 2007 选举IDQ 官网逐字「On 21st October 2007 the Geneva government used IDQ’s hybrid quantum cryptography solution, which combines state of the art Layer 2 encryption (Centauris Ethernet Encryptors) with the Cerberis Quantum Key Distribution (QKD) servers. The solution secures a point-to-point Gigabit Ethernet link used to send ballot information for the federal and cantonal elections…」[一手逐字]——「最后一毫米」从第一天起就是经典加密:QKD 只出密钥,选票数据走 Layer 2 以太网加密机。
  • 欧盟 EuroQCI欧委会官网逐字「The European Commission is working with all 27 EU Member States, and the European Space Agency (ESA), to design, develop and deploy the EuroQCI…」「The EuroQCI was launched in 2019 with the EuroQCI Declaration, initially signed by seven Member States: all Member States subsequently joined the initiative.」[一手逐字];OpenQKD 项目逐字「38 Partners from 13 EU countries」——38 是合作伙伴数不是站点数[一手逐字]。
  • 美国 Quantum XchangePR Newswire 2019-09-09逐字「Phio Fiber Network: 1,000 kilometers of existing optical fiber and 19 co-location centers along the Boston to Washington route from strategic infrastructure partner Zayo Group…including key connections to the financial markets on Wall Street」[一手逐字]——租 Zayo 暗纤服务华尔街;现状见第七章(官网失联登记)。
  • 韩国IDQ 官网逐字「selected to secure the communication network of 48 government organizations across the country…It will constitute the largest operational QKD network in the world outside of China.」[一手逐字]。
  • 美国 EPB ChattanoogaORNL 官网 2024-09-11逐字「EPB Quantum Network currently has capacity for ten quantum interconnected user nodes across downtown Chattanooga」[一手逐字]——市中心最多 10 个用户节点。
  • 东芝-BT 伦敦 2021Toshiba Europe 官网逐字「the world’s first commercially available quantum-secured metro network…will provide data services secured using Quantum Key Distribution (QKD) and Post-Quantum Cryptography (PQC)」[一手逐字]——官方自己写成 QKD+PQC 混合;东芝欧洲量子页引 BT CTO Howard Watson 逐字「with EY as our first trial customer」——首个试用客户安永,仍是 trial 口径[一手逐字]。
  • 济南试验网济南量子技术研究院官网(经 Wayback)逐字「济南量子通信试验网于2013年底建成,是当时世界上规模最大、功能最全的实用化城域量子通信网络,业务涵盖政务、金融、政法、科研、教育等五大领域,用户节点数达到56个,用户单位28个,为100多个用户提供基于量子安全的电话、传真、文件和文本通信业务,该网络至今一直稳定运行」[一手逐字]。

6.6 「量子互联网」走到哪一级:Wehner 2018 的六级框架

Wehner, Elkouss & Hanson, Science 362, eaam9288 (2018)(TU Delft 机构库作者最终版 PDF 落盘)提出通往完整量子互联网的六级阶段,逐字:

  1. 「Trusted Repeater Networks」——「The first stage differs significantly from the others in the sense that it does not allow the end to end transmission of qubits.」(第一级与其余各级有本质不同:它不允许端到端传输量子比特)
  2. 「Prepare and Measure Networks」——「This stage is the first to offer end-to-end quantum functionality. It is sufficient to perform end-to-end QKD without the need to trust intermediary」(第二级才首次提供端到端量子功能)
  3. 「Entanglement Distribution Networks」(端到端纠缠分发)
  4. 「Quantum Memory Networks」(端节点本地量子存储+通用本地控制)
  5. 「Few Qubit fault-tolerant Networks」(少量量子比特容错网络)
  6. 「Quantum Computing Networks」(量子计算网络)

论文自己对「当前处于哪一级」的判断逐字:「The current status of long-distance quantum networks is at the lowest stage – trusted-repeater networks – with several commercial systems for quantum key distribution on the market.」[一手逐字]——2018 年世界的长途量子网络只到最低一级(可信中继),连「端到端量子功能」的第二级都没进。可信中继的机制逐字:「Each pair of adjacent nodes uses quantum key distribution (QKD) to exchange encryption keys. These pairwise keys allow the end nodes to generate their own key provided that all intermediary nodes are trusted.」[一手逐字]——所有中间节点都必须被信任

到 2025 年位置没有变:Kumar et al. 2025 综述(arXiv:2502.01653v3)逐字「The higher stages of quantum internet that require end-to-end entanglement distribution are still in nascent stages. The experimental realisation of these types of networks is currently limited to a few nodes with varying link lengths and physical systems of qubits.」[一手逐字]——第三级起仍处萌芽。结论:QKD 作为「可信中继密钥专网」已真实落地并商用,作为「量子互联网」则尚未起步——这是学界自己的框架给出的判定。

6.7 真实使用账

  • 金融/电力/政务真实用户类别有一手:京沪干线开通日应用示范(交行/工行/阿里,§6.1);150 多家用户(§6.3);济南试验网 28 单位 100 多用户(§6.5);欧盟 JRC 官方调研报告(JRC118150)逐字「Fig. 1: users of the quantum backbone: main players (left), banks (centre), and power grid operators (right)」,并引济南网报道「The first users of this technology will be government agencies, the military, finance, and electricity sectors」[一手逐字]。
  • 「最后一毫米」一手三件套:日内瓦 2007(QKD 服务器+Layer 2 加密机组合);东芝-BT 2021(官方自称 QKD and PQC);Wehner 2018 可信中继机制句(§6.6)。用户流量始终在经典加密设备里跑——量子段出密钥,这不是缺陷披露,是架构事实。
  • 骨干网后续:国盾量子注册环节反馈回复(证监会 2020)逐字「国科量网作为目前国家发改委批复的国家量子保密通信骨干网建设运营主体……国家发改委已将国家广域量子骨干网一期项目纳入中央预算内投资计划,首批资金已足额拨付」「构建『星地一体、多横多纵』国家广域量子通信骨干网络(总长约 3.5 万公里)」[一手逐字]——「3.5 万公里」是运营方规划口径,非建成口径;武合干线 2018-11-13 建成贯通(中新网湖北逐字「世界第一条量子通信保密干线『京沪干线』的首条商业延伸线」)[一手逐字]。

七、制度与产业账:站位分裂与补贴驱动(站位跳)

7.1 NSA:五条理由与一句「No.」

NSA 官网 QKD/QC 页(直抓 403,经 Wayback 2026-06-10 快照 id_ 原件;该 URL 最早快照 2021-09-30)的五条理由,小标题与关键句逐字:

  1. 「Quantum key distribution is only a partial solution.」——「QKD does not provide a means to authenticate the QKD transmission source. Therefore, source authentication requires the use of asymmetric cryptography or preplaced keys…Moreover, the confidentiality services QKD offers can be provided by quantum-resistant cryptography, which is typically less expensive with a better understood risk profile.」(QKD 自身不提供认证——这正是 Mayers 2001「key expansion rather than key distribution」的官方版)
  2. 「Quantum key distribution requires special purpose equipment.」——「It cannot be implemented in software or as a service on a network…lacks flexibility for upgrades or security patches.」(不能软件化、不能打补丁)
  3. 「Quantum key distribution increases infrastructure costs and insider threat risks.」——「QKD networks frequently necessitate the use of trusted relays, entailing additional cost for secure facilities and additional security risk from insider threats. This eliminates many use cases from consideration.」(可信中继=额外成本+内鬼面)
  4. 「Securing and validating quantum key distribution is a significant challenge.」——「The actual security provided by a QKD system is not the theoretical unconditional security from the laws of physics (as modeled and often suggested), but rather the more limited security that can be achieved by hardware and engineering designs. … The specific hardware used to perform QKD can introduce vulnerabilities, resulting in several well-publicized attacks on commercial QKD systems.」(这一句是本篇胎记的官方表述:实际安全≠理论无条件安全;页脚列 Vakhitov/Makarov 等 5 篇攻击文献)
  5. 「Quantum key distribution increases the risk of denial of service.」——「The sensitivity to an eavesdropper as the theoretical basis for QKD security claims also shows that denial of service is a significant risk for QKD.」(窃听敏感性本身即拒绝服务面)

并逐字承认原理:「Published theories suggest that physics allows QKD or QC to detect the presence of an eavesdropper, a feature not provided in standard cryptography.」[一手逐字 ×6]——NSA 否定的是「安全由物理定律保证」的宣传式表述,并未否定原理本身(第九章读法 1 要用这句)。结论句见守真锚 6;CNSA 2.0 FAQ 的「A: No. …NSS owners should not use or research QKD at this time without consulting NSA directly.」[一手逐字]是制度侧最硬的一句。

7.2 NCSC:不背书+不计分+同文的承认段

NCSC 白皮书(现行版)三句逐字(守真锚 6 已立前两句):「NCSC advice is that the best mitigation against the threat of quantum computers is quantum-safe cryptography.」[一手逐字];QKD vs PQC 对比段逐字「These algorithms can be implemented on today’s classical computers, and, unlike QKD solutions, do not require dedicated or specialist hardware. Quantum-safe cryptographic algorithms allow two remote parties to agree a shared secret key with authentication, hence without the risk of man-in-the-middle attacks.」「However, because QKD protocols do not provide authentication, they are vulnerable to physical man-in-the-middle attacks…」[一手逐字]。

对称格(第九章读法 2 的承重件):NCSC「Quantum networking technologies」白皮书(2025-08-05 版,取代 2020 旧版)逐字「Quantum Key Distribution provides a mechanism to generate and share cryptographic keys in a way that guarantees detection against eavesdroppers and is resistant to a future quantum computer.」「It is possible that the technologies underpinning QKD could play some part in future quantum networks.」「One of these includes the target that by 2035, the UK will have deployed the world’s most advanced quantum network at scale.」[一手逐字]——同一个 NCSC,白纸黑字承认 QKD「保证可探测窃听、抗未来量子计算机」,承认其底层技术可能在未来量子网络中占一席之地,且英国自己的国家战略就有 2035 量子网络目标;但同文结论仍是「Therefore, in practice, QKD must be combined with other cryptographic services…should not be relied on as a mechanism that provides substantial security value」「The NCSC will not support the use of QKD for government or military applications.」[一手逐字]——「它有原理价值」与「我们不推荐」同文并存。

7.3 欧洲四国联合立场与 EuroQCI:分裂是制度事实

  • 法国 ANSSI(2020-05-26)逐字「QKD may find some use in a few niche applications, for instance as a defense-in-depth measure on point-to-point links. However, the use of state-of-the art classical cryptography including post-quantum algorithms is by far the preferred way…In any case, the cost incurred by the use of QKD should not jeopardize the fight against current threats to information systems which overwhelmingly do not exploit cryptographic weaknesses.」;可信中继定性逐字「users are led to negotiate keys in sections along a path composed of several QKD links, which requires trust in the intermediate nodes…and is a major regression compared to current end-to-end key negotiation methods.」(相对端到端密钥协商是「重大倒退」)[一手逐字];2022-01-04 PQC 立场逐字「except for niche applications where QKD is used for providing some extra physical security on top of algorithmic cryptography (and not as a replacement), it is not considered by ANSSI as a suitable countermeasure to mitigate the quantum threat.」「For ANSSI, PQC represents the most promising avenue to thwart the quantum threat.」[一手逐字]
  • 法德荷瑞四国联合立场文件Position Paper on Quantum Key Distribution,2024-01-26,ANSSI/BSI/NLNCSA/瑞典 NCSA)结论段逐字「Due to current and inherent limitations, QKD can however currently only be used in practice in some niche use cases. For the vast majority of use cases where classical key agreement schemes are currently used it is not possible to use QKD in practice. Furthermore, QKD is not yet sufficiently mature from a security perspective.」「In light of the urgent need to stop relying only on quantum-vulnerable public-key cryptography for key establishment, the clear priority should therefore be the migration to post-quantum cryptography in hybrid solutions with traditional symmetric keying or classically secure public-key cryptography.」;成本句逐字「the acquisition of this equipment as well as the maintenance of a QKD system or network over its entire life cycle is associated with very large costs. Needless to say, such equipment cannot be deployed to every individual user that needs secure communication, nor is it suitable for use with mobile devices.」[一手逐字 ×3]
  • 分裂的另一侧:同一批国家全部签约 EuroQCI——欧委会官网逐字「The EuroQCI is building a secure quantum communication infrastructure spanning the whole EU, including its overseas territories.」「It will reinforce the protection of Europe’s governmental institutions, their data centres, hospitals, energy grids, and more, becoming one of the main pillars of the EU’s Cybersecurity Strategy for the coming decades.」「since January 2024, the European Commission has launched a four year project (NOSTRADAMUS) setting up a testing and evaluation infrastructure that will enable QKD-based technologies and services to be assessed and validated with a view to certification」[一手逐字]——情报口的保留与工程口的推进同洲并存、同国并存:法国既是四国文件签署方,也是 EuroQCI 成员。这不是任何一方「说错话」,是制度层面的双轨。

7.4 NIST 对照组与 HNDL 账

  • NIST 2024-08-13 三标准落地(守真锚 7)。SIKE 出局:NIST 第四轮页面(Wayback 2023-07-03 快照)官方注记逐字「The SIKE teams acknowledges that SIKE and SIDH are insecure and should not be used.」[一手逐字]——第四轮候选就此出局(攻击细节见第九章读法 3)。
  • 「harvest now, decrypt later」(HNDL):CISA/NSA/NIST 联合 factsheet(2023-08-21)逐字「Early planning is necessary as cyber threat actors could be targeting data today that would still require protection in the future…using a catch now, break later or harvest now, decrypt later operation.」[一手逐字];NCSC PQC 指南逐字「for organisations that need to provide long-term cryptographic protection of very high-value data, the possibility of a CRQC in the future is a relevant threat now.」[一手逐字]。口径裁决:HNDL 威胁是真的(监管与厂商双方承认),但 QKD 自身的认证信道仍需 PQC/预置密钥(NSA 第一条)——HNDL 防御不能单独记到 QKD 账上;且无任何一方给出「QKD 已被证明防 HNDL」的命题。
  • 成本对比只有定性没有量化:NSA 逐字「quantum-resistant cryptography…is typically less expensive with a better understood risk profile」[一手逐字];对 QKD 最有利的一条反向一手:NICT/东芝/NEC 2025-09 联合新闻稿逐字「QKD networks can be built on current telecom backbone infrastructure, eliminating the need for dedicated optical fibers for QKD signals.」[一手逐字]——QKD 与数据信号复用现有骨干光纤的演示,直接削弱「必须铺专线」的成本论据。

7.5 标准化三线与中国密度

  • ETSI ISG QKD:GS QKD 004(应用接口,V2.1.1 2020-08)、011(光器件表征)、014(REST 密钥下发 API)、016(Common Criteria 保护轮廓,V1.1.1 2023-04)——覆盖「组件/接口」层,未触及端到端系统安全[一手逐字 ×4]。
  • ITU-T Y.3803逐字「Quantum key distribution networks – Key management」「Approved in 2020-12-07」「Status: In force」[一手逐字]。
  • ISO/IEC 23837-1:2023逐字「Security requirements, test and evaluation methods for quantum key distribution — Part 1: Requirements」「Publication date: 2023-08」[一手逐字](Part 2 页面 403 限流,空位登记)。
  • 中国:信通院《量子信息技术发展与应用研究报告》(2023-12)逐字「GB/T 42829-2023《量子保密通信应用基本要求》正式发布,成为我国量子通信领域的首个国家标准」「2023 年,YD/T 4303-2023《基于 IPSec 协议的量子保密通信应用设备技术规范》和 YD/T 3834.2-2023《量子密钥分发(QKD)系统技术要求 第 2 部分:基于高斯调制相干态协议的 QKD 系统》行业标准发布实施」(另有 YD/T 4301/4302.1 等)[一手逐字]——中国 QKD 标准密度高于欧美,与其工程推进姿态一致。

7.6 国盾量子年报:补贴驱动的财务形状

守真锚 8 已立 2025 年报主数字。补全链条:

  • 2024 年报巨潮 2025-03-26)逐字「报告期内,公司营业收入 25,336.89 万元,同比增加 62.30%;归属于上市公司股东的净利润为-3,184.14 万元,同比减亏 74.30%。」「研发投入总额占营业收入比例(%):36.74(上年 82.51)」;计入当期损益的政府补助「本期发生额 合计 30,357,528.14 元」;「前五名客户销售额13,782.11万元,占年度销售总额54.40%;其中前五名客户销售额中关联方销售额11,557.08万元,占年度销售总额45.61%。」[一手逐字]——2024 年计入损益的政府补助 3,036 万 ≈ 当年亏损额的 95%(自算:30,357,528.14 / 31,841,400 ≈ 0.953)。
  • 2025 年报:归母净利 539.19 万 vs 计入损益政府补助 4,292.45 万——补助是归母净利润的约 8 倍(自算:42,924,544.79 / 5,391,900 ≈ 7.96);扣非净利润连续三年为负(-1.58 亿→-6,264 万→-4,355 万);公司自己写明转正原因「主要系报告期内公司量子计算领域营业收入增长、计入当期损益的政府补助及投资收益增长所致」[一手逐字]。客户集中度升至 63.51%,其中关联方占年度销售总额 43.44%。
  • 招股书(2020-07-02,巨潮风险段逐字「报告期内,公司对政府补助存在较大依赖,利润总额中政府补助金额分别为5,413.60万元、5,948.26万元和8,440.86万元……如果未来政府补助政策发生变化,导致公司不能继续享受政府补助,将会对公司的利润水平产生一定的影响。」;现金流段逐字「剔除收到的税费返还及政府补助金额后,经营活动现金流量净额分别为-7,795.46万元、-6,104.32万元、12,171.02万元。」;季节性逐字「报告期各年12月份主营业务收入分别为17,115.82万元、20,503.62万元、20,610.72万元,占各年主营业务收入比例分别为62.81%、79.81%、80.55%。」[一手逐字 ×3]——上市前三年收入超六成在 12 月确认。
  • 控制权:2025 年报逐字「中电信量子集团直接持有公司股份比例为 21.86%,并分别与科大控股、彭承志先生签订了《一致行动协议》,拥有的股份表决权比例为 40.43%。」[一手逐字]——控股股东已变更为中国电信系国资。

口径裁决:QKD 龙头的「兑现」由政策与补贴驱动,不是商业闭环——这一判断的依据全部是公司自己披露的数字。

7.7 国际产业:龙头易主、先驱转型、预测打架

  • ID Quantique → IonQIonQ 8-K 附件(SEC,2025-02-26)逐字「IonQ to Acquire Geneva-Based ID Quantique…to acquire a controlling stake in IDQ. … The transaction consideration will be paid in IonQ common stock.」「IDQ’s patent portfolio of nearly 300 patents and patent applications will bring the total count of granted and pending patents that IonQ owns or controls to nearly 900.」[一手逐字];2025-05-07 Q1 财报 8-K 逐字「Strong continued expansion of Quantum Networking Initiative via Closing Acquisition of ID Quantique」[一手逐字]——全球第一家 QKD 商业化公司(2001 年成立)2025 年被美国量子计算公司 IonQ 以股票对价收购控股,QKD 独立龙头不复存在(交易金额口径不一:Mordor 称 $250M、StartupHub.ai 称 $119M,SEC 8-K 未披露金额——以「口径不一、未获一手确认」登记)。
  • MagiQ官网(直连 200)首页逐字「MagiQ’s quantum-enabled systems recover, capture, and protect the signals modern intelligence depends on」;最新新闻为 DoE 量子传感与 Sandia 地震传感合作——官网已无任何 QKD 产品,业务转向量子传感/国防情报采集[一手逐字]。结合 §5.7(QPN 5505 停产),美国 QKD 先驱实质退出 QKD 主业。
  • Quantum Xchange:[诚实空位] 官网直连超时,Wayback 仅 2021-12/2022-02 两条记录、2024 年后零快照;咨询报告仍列其为玩家。登记「官网失联+存档断档」,不下「已倒闭」结论
  • 东芝pr1901(2020-10-19)逐字「today announced it will start providing quantum key distribution (QKD) platforms and commence deployment of a system integration business in the fourth quarter of FY2020.」(注意原文是「start providing…platforms」,非「first commercially available」,任务书预估未坐实,如实登记);自家市场口径逐字「The QKD market is expected to grow to approximately $20 billion worldwide in FY 2035. …aims to capture approximately 25% of the market (approximately $3 billion) in FY 2030」,注脚逐字「 Toshiba’s long term estimates based on short to mid-term estimates by research firms」[一手逐字]——$20B/FY2035 是厂商自注「基于短中期估计外推」的远期口径。
  • 市场预测三家收敛 vs 厂商口径MarketsandMarkets「from USD 0.48 billion in 2024 to USD 2.63 billion by 2030 at a Compound Annual Growth Rate (CAGR) of 32.6% during the forecast period」;Grand View Research「USD 446.0 million in 2024…USD 2.49 billion by 2030…CAGR of 33.5%」;Mordor Intelligence「USD 0.61 billion in 2025…USD 2.58 billion by 2030…33.78% CAGR」[智库咨询 ×3]——三家 2030 年终点收敛于 $2.5–2.6B、CAGR 约 33%;东芝自家 $20B/FY2035 大近 4 倍且年份更远。区域判断互相矛盾(GVR 称北美第一 36.8%,Mordor 称亚太居首),如实登记。
  • 中国官方表述十四五规划纲要(教育部官网全文)逐字:「聚焦量子信息、光子与微纳电子……组建一批国家实验室」「瞄准人工智能、量子信息、集成电路……实施一批具有前瞻性、战略性的国家重大科技项目」「在类脑智能、量子信息……组织实施未来产业孵化与加速计划」「加快布局量子计算、量子通信……等前沿技术」[一手逐字]——「量子信息」以「科研攻关+未来产业」框架出现于四处,未点名 QKD。国盾 2025 年报转引信通院:「目前全球已有 30 余个国家和地区推出了量子信息领域的发展战略规划或法案文件,投资总额超 350 亿美元。」(转引口径,标注)。

7.8 制度层小结

图景是「双轨分裂」而非「共识」:轨一,美英最高信号情报机构白纸黑字否定 QKD 用于政府/军事/国安系统,法德荷瑞四国情报口把「明确优先」给了混合式 PQC;轨二,欧委会把 QKD 基建列为「未来数十年网络安全战略主要支柱」,中国以国标/行标密度和十四五规划推进工程化,日本 NICT 与企业 2025 年仍在推进骨干网融合。产业账与轨一同构:国盾的账面转正主要由补助与投资收益贡献,IDQ 被收编、MagiQ 转型、Quantum Xchange 失联。站位不是「西方 vs 中国」一句话能装的——它是每个法域内部「情报口 vs 工程口」的分裂。

八、消费与传播账:「不可破解」的生产线

本章回答:把「原理安全」读成「工程不可攻破」的话术是谁生产的、经过哪些环节放大、纠偏信息在哪儿。结论先行:话术源头不是媒体的误读,是官方通稿与企业物料本身;国际媒体十三年不断货地放大;纠偏信息始终存在但位于次要版面;而对 QKD 叙事最关键的一条负向信息(NSA 不推荐)没有进入英文主流传播层——缺席本身是可登记的证据。

8.1 源头:发射日通稿已含完整话术链

新华社 2016-08-16 发射通稿(news.cn 原页已失效,落盘件为四川省国防科工办官网当日转载页,电头与行文为新华社通稿)逐字:「8月16日1时40分,我国在酒泉卫星发射中心用长征二号丁运载火箭成功将世界首颗量子科学实验卫星『墨子号』发射升空。」文中潘建伟表述逐字:「量子卫星首席科学家潘建伟院士介绍,量子通信的安全性基于量子物理基本原理,单光子的不可分割性和量子态的不可复制性保证了信息的不可窃听和不可破解,从原理上确保身份认证、传输加密以及数字签名等的无条件安全,可从根本上、永久性解决信息安全问题。」[一手逐字]——「不可窃听/不可破解/无条件安全/永久性解决信息安全问题」的完整链条,在发射日的官方通稿里已经一次配齐

同日配套:人民日报理论频道深度稿栏题逐字「『墨子』升空,无条件安全通信成可能 揭秘全球首颗量子卫星」,正文逐字「当量子密钥产生后,通信双方即可进行保密通信,这个过程从原理上已经证明是绝对不可窃听、无法破译的,因此整个通信过程是无条件安全的」,潘建伟受访逐字「这样,北京和乌鲁木齐之间就能建立绝对安全的量子密钥」[一手逐字];央视网逐字「以此构建包含国防、金融、政务、商业等领域的绝对安全的全球量子保密通信网」[一手逐字];新文化报(科大新闻网镜像)标题逐字「量子卫星有多牛?通讯『绝对安全』!」[一手逐字]。

后续官宣口径:科技日报 2017-08-10(三大成果)潘建伟逐字「传统的基于计算复杂性的加密技术,在原理上都存在着被破译的可能。而量子密钥分发则是通过量子态的传输,在遥远两地的用户共享无条件安全的密钥,利用该密钥对信息进行一次一密的严格加密,这是目前人类唯一已知的不可窃听、不可破译的无条件安全的通信方式。」[一手逐字];中新社 2017-09-29(京沪干线开通)正文逐字「量子通信是被证明无条件安全的通信方式。」[一手逐字]——无主语的断言句;光明日报 2017-09-30逐字「通过这条不可破解的保密线,白春礼与奥地利科学院院长安东·塞林格进行了世界首次洲际量子保密通信视频通话」,同篇潘建伟表述带技术边界(「量子通信网络分发的是密钥,信息依然通过传统方式传递」)但仍落「是迄今唯一被严格证明无条件安全的通信方式」[一手逐字]。

8.2 国际谱系:unhackable 十三年不断货(2013–2025)

按时间排列,标题均逐字:

  1. BBC 2013-09-04:「’Uncrackable’ codes set for step up」,导语「A system that allows electronic messages to be sent with complete secrecy could be on the verge of expanding beyond niche applications.」[一手落盘]
  2. WIRED 2013-06-07(反向样本):「Laws of Physics Say Quantum Cryptography Is Unhackable. It’s Not」,导语「A technique called quantum cryptography can, in principle, allow you to encrypt a message in such a way that it would never be read by anyone whose eyes it isn’t for. But in recent years, methods that were once thought to be fundamentally unbreakable have been shown to be anything but.」——2013 年「unhackable」话术已流行到 Wired 专门发文纠偏[一手落盘]
  3. Futurism 2015-11-25:「China’s New Quantum Communication Network Will Be “Unhackable”」,正文「It is set to become the world’s first “unhackable” internet communications network.」——京沪干线开通前两年,「世界首个不可破解互联网」已出厂[一手落盘]
  4. WIRED 2016-08-16(墨子号发射当日):页面标题「China launches the world’s first quantum satellite to create ‘unhackable’ communcations」(拼写错误为原件所有)[一手落盘]
  5. BBC 2016-08-16:「China launches quantum-enabled satellite Micius」——发射日 BBC 相对克制,未用 unhackable[一手落盘]
  6. WSJ 2017-06-15:「China Makes Leap Toward ‘Unhackable’ Quantum Network」,正文「gives China a leg up in using quantum technology to build an “unhackable” global communications network」[一手落盘]
  7. Nature News 2017-06-15:「China’s quantum satellite achieves ‘spooky action’ at record distance」(nature.com 直抓 0 字节,标题经存档 slug+新华社英文当日镜像稿双证)[半落盘]
  8. BBC 2017-06-15:「China’s quantum satellite in big leap」,导语「paves the way for a new kind of internet」[一手落盘]
  9. CGTN 2017-07-11(济南试验):「China’s “unhackable” communications network testing success」[一手落盘];其源头 FT 2017-07-10「China trial paves way for ‘unhackable’ communications network」(ft.com 付费墙,标题经两处独立学术文献脚注核实)[检索登记]
  10. OpenGov Asia 2017-10-28(京沪干线):「World’s longest unhackable communications link opened between Beijing and Shanghai」,正文「This would allow unhackable communication between the cities.」[一手落盘]
  11. 新华社英文 2018-01-20(中奥通话 PRL):「Details of China’s long-range, quantum-secured “unhackable” messaging revealed」,正文「uses single photons in quantum superposition states to guarantee unconditional security between distant parties」——官方英文稿自己把 unhackable 与 unconditional security 并置[一手落盘]
  12. AFP(经 Phys.org)2020-07-24(DOE 蓝图):「Quantum loop: US unveils blueprint for ‘virtually unhackable’ internet」,导语「US officials and scientists have begun laying the groundwork for a more secure “virtually unhackable” internet based on quantum computing technology.」[一手落盘]
  13. 新华社英文 2022-05-17:「China launches quantum-secured, “unhackable” smartphone」,导语「can ensure the user chat on the device is almost “unhackable.”」——到 2022 年官方英文稿开始给 unhackable 加「almost」缓冲[一手落盘]
  14. Tom’s Hardware 2023-11-01:「China’s Quantum Satellite Program Designed to Transmit Unhackable Information」[一手落盘]
  15. SCMP 2025-05-18:「Chinese firm launches ‘unhackable’ quantum cryptography system」(scmp.com 原页未取回,标题经 Hoover Institution 报告脚注逐字引证)[检索登记]

8.3 「量子互联网」名号账

  • 学术命名:Wehner, Elkouss & Hanson, Science 362 (2018) 标题逐字「Quantum internet: A vision for the road ahead」——路线图概念(六级框架见 §6.6)[一手落盘]。
  • 名号进入中国叙事早于 DOE:Scientific American 2017-06-15「China Shatters ‘Spooky Action at a Distance’ Record, Preps for Quantum Internet」(直抓与 Wayback 均 404/壳,标题经两处独立学术文献脚注核实)[检索登记]。
  • 名号官方化美国能源部 2020-07-23 新闻稿标题逐字「U.S. Department of Energy Unveils Blueprint for the Quantum Internet at ‘Launch to the Future: Quantum Internet’ Event」,副题「Nationwide Effort to Build Quantum Networks and Usher in New Era of Communications」,正文逐字「Scientists plan to use that trait to make virtually unhackable networks.」[一手落盘]——「量子互联网」与「virtually unhackable」在同一份官方新闻稿里并置DOE 蓝图报告(OSTI 2020-02)逐字「Although a general-purpose quantum computer still is many years away, the research community perceives a quantum Internet may be closer to realization.」「it now has reached the point where it can consider moving from small-scale experiments toward a first nationwide quantum Internet facility.」[一手落盘];Fermilab 同日发布逐字「DOE’s 17 National Laboratories will serve as the backbone of the coming quantum internet…」(芝加哥 52 英里环+80 英里三节点测试床)[一手落盘]。
  • 欧盟官方原型:Quantum Flagship逐字「The Quantum Flagship is a large-scale initiative funded at the 1b € level on a 10-year timescale」「The long-term horizon is a “Quantum Web”: Quantum computers, simulators and sensors interconnected via quantum networks…」[一手落盘]。

8.4 企业宣传:两套措辞

  • 国盾量子官网典型案例页逐字「在阿里云网络环境建立多个量子安全域,通过量子传送门(Quantum Portal)实现同城数据中心互联组网,为客户提供无条件安全数据传输服务」;官网产品页逐字「为实现信息无条件安全传送提供智能而有弹性的设备平台」[一手落盘 ×2]。而招股说明书(2020-07-02)全文未检出「无条件安全」字样,用的是带假设前提的「信息理论安全」,逐字:「量子密钥分发往往被称为具有信息理论安全性,指的是针对信道窃听和计算破译的安全性,其假设前提是:A.量子力学物理理论是正确的;B.量子密钥分发设备的工作是符合量子密钥分发协议要求的。」[一手落盘]——同一公司:对客户的营销页写「无条件安全」,对监管的招股书写「被称为具有信息理论安全性,其假设前提是…」。两套措辞的分界线就是受众。
  • ID Quantique官网 Quantum-Safe 页逐字「Quantum Cyber Security enables unhackable communications.」「Quantum Key Distribution technology ensures unconditional data protection.」[一手落盘]——「unhackable」与「unconditional」两级话术同页。
  • Quantum Xchange:2019 年官网站名逐字「Quantum Xchange | Pioneering Unbreakable Encryption」(Wayback 快照);现行官网改用 HNDL 威胁话术[一手落盘]。
  • 东芝 pr1901:实际口径「start providing…platforms」(§7.7,未出现「first commercially available」)[一手落盘]。

8.5 三个典型误读(各取一手实例)

  1. 「量子通信=超光速/瞬移信息」:discoverwildscience.com 2025-06-18「The Star Trek Era Begins: Quantum Teleportation Becomes Reality in 2025」,正文逐字「changing one instantly influences the other」「Restricted only by the speed of light, this process allows nearly instantaneous data transfer and unhackable communication.」——与无信号定理相悖(纠缠不能传信息,归纠缠篇裁决,本篇只登记传播事实)[一手落盘]
  2. 「QKD 解决一切窃听」:Futurism 2015 断言整个通信网「Will Be Unhackable」,正文「Communication becomes “unhackable” this way because any attempt to intercept the key would be obvious to the sender and the intended recipient.」——完全不提可信中继、端点与实现漏洞;中文同款:中新社 2017「量子通信是被证明无条件安全的通信方式」[一手落盘 ×2]
  3. 「量子互联网已在中国建成」:搜狐号「智汇云帆」2025-12-17 标题逐字「全球首个量子互联网试验成功!北京-上海量子密钥分发速度破纪录」,正文逐字「2025年12月,中国科学技术大学潘建伟团队联合中科院上海微系统所,成功完成全球首个量子互联网多节点试验。在北京-上海2000公里光纤链路上,量子密钥分发(QKD)速率突破1 Mbps……」——并排对照 Nature 2021 论文自称「an integrated space-to-ground quantum communication network…Using a trusted relay structure」:论文自称「一体化量子通信网络」且明示可信中继,从不称「量子互联网」;自媒体把 QKD 干线速率纪录直接升格为「全球首个量子互联网」,与论文自称差一个范式(且与 Wehner 框架差至少两级)[一手落盘+对照件]

8.6 反向传播账:NSA 不推荐 QKD,媒体报了没有

  • 立场原文落盘(§7.1)。
  • 英文主流媒体覆盖:未检索到 BBC/Reuters/AP/NYT/WSJ 对「NSA 不推荐 QKD」的独立报道。三轮检索式登记:「NSA “does not recommend” quantum key distribution QKD news report」/「NSA advises against quantum key distribution The Register OR Reuters…」/「”quantum key distribution” NSA warns OR “not recommended” news coverage 2021 bbc OR cnn…」——结果均只命中 arXiv 反驳文、厂商博客与政府文件本身。缺席即证据:这条对 QKD 叙事最关键的负向信息没有进入主流传播层[多源检索]。
  • 中文层有报,但载体与框架值得登记:腾讯新闻(光子盒研究院出品)2022-04-27标题「美国叫停QKD,欧洲却在加快量子保密通信网络建设」,正文逐字「美国国家安全局(NSA)曾在报告中公开表示,不建议使用量子密钥分发(QKD)和量子密码技术来确保国家安全系统(NSS)中的数据传输。」[一手落盘];CN-SEC 中文网 2020-11-30「量子通信漏洞多,外国安全机构都看在眼里」逐段直译 NSA 声明与 NCSC 白皮书[一手落盘]——中文层有覆盖,但载体是安全行业站与门户自媒体,且叙事框是「美国叫停、欧洲加快」的博弈框架,不是「官方背书的安全边界」框架

8.7 科学家的降温与口径的软化

  • Zeilinger 受访(新华社维也纳 2017-12-09 电)逐字「我确信这是全球量子通信的第一步,中国在这方面的投资显然很有效益」[一手落盘]——「第一步」,不是「建成」。
  • 墨子沙龙 2019-03-14《关于量子保密通信现实安全性的讨论》(潘建伟等五位科学家联名)逐字「学界将这种安全性称之为『无条件安全』或者『绝对安全』,它指的是有严格数学证明的安全性。……后来,量子密钥分发逐步走向实用化研究,出现了一些威胁安全的攻击,这并不表示上述安全性证明有问题,而是因为实际量子密钥分发系统中的器件并不完全符合上述(理想)BB84协议的数学模型。」「虽然现实中量子通信器件并不严格满足理想条件的要求,但是在理论和实验科学家的共同努力之下,量子保密通信的现实安全性正在逼近理想系统。」[一手落盘]——「原理上无条件安全、工程上有漏洞」级的官方科学家原话,发在公众号,不在通稿标题里。
  • Makarov 受访(《中国新闻周刊》,九三学社中央官网 2019-12-25 转载)逐字「量子加密从原理上是无法攻击的,但是协调系统里的一些零部件,则可能留下人为漏洞。」[一手落盘]——一线攻击研究者自己在中文官方渠道划界。
  • 媒体侧纠偏对照:WIRED 2013(§8.2-2);观察者网 2019-04-03 李红雨文逐字「尽管面对公众,量子密码团队做过无数次无条件安全的承诺,但是对于了解原理和技术详情的我们来说,量子密码存在漏洞一点也不令人惊奇……」[一手落盘]
  • 口径软化时间点新华社 2021-01-07(4600 km)逐字「基于『不可分割』『不可克隆』等量子特性,量子通信被称为『原理上无条件安全』的通信方式」[一手落盘]——对比 2016-2017 的「不可窃听、不可破解、无条件安全」,2021 年起官方口径改为「被称为『原理上无条件安全』」;2022 年新华社英文「almost “unhackable”」。软化发生在官方文本里,但市场与自媒体话术并未同步回收(2023 Tom’s Hardware、2025 SCMP 仍无条件 unhackable)。

8.8 传播层小结

传播链的偏移是结构性、双侧的:源头话术由官方通稿与企业物料共同生产(发射日通稿已配齐「不可窃听/不可破解/无条件安全/永久性解决」);国际媒体 2013–2025 十三年「unhackable/uncrackable/unbreakable」标题不断货;2020 年 DOE 把「量子互联网」名号官方化并与「virtually unhackable」并置;自媒体把 QKD 干线升格为「全球首个量子互联网」。纠偏信息始终存在(Wired 2013、墨子沙龙 2019、NSA/NCSC 声明、观察者网 2019),但位于次要版面、行业渠道或公众号;NSA 不推荐 QKD 未进入英文主流媒体报道。2021 年后官方中文口径出现软化措辞,市场与自媒体未同步回收。

九、反向红跳:四句反向读法审计

对称双向体例:审完「夸大一侧」的跳变,必须审「贬低一侧」的反向跳变。四句逐一取证,全部结论只基于落盘证据。

9.1 读法一:「QKD 是骗局/量子力学本身没用」→ 不立(四句中最不立)

反方承重证据链:

  • 安全证明是定理级工作Shor-Preskill 2000 摘要逐字「We prove the security of the 1984 protocol of Bennett and Brassard (BB84) for quantum key distribution.」——这是数学定理层面的陈述(经纠缠纯化/CSS 码约化到 Lo-Chau),不是工程宣传[一手逐字]。
  • 综述定性Pirandola et al., RMP 92, 065002 (2020) 摘要逐字「security proofs are constantly improving, and experiments are gradually moving from proof-of-principle lab demonstrations to in-field implementations」;正文 Sec. IX-E 逐字「To refine the mathematical models on which the security proofs are based to more accurately match the quantum hardware used in the actual implementations. This is of crucial importance to decrease the vulnerability to quantum hacking, which is typically based on side channel attacks exploiting weaknesses of the quantum hardware.」——量子黑客被定性为「利用量子硬件弱点的侧信道攻击」,方向是弥合实现与证明之间的缝:攻击针对实现,不是击穿原理[一手逐字]。
  • 攻击者自己承认Lydersen 2010 摘要逐字「We believe that our findings are crucial for strengthening the security of practical QKD, by identifying and patching technological deficiencies.」——攻破商用系统的作者本人把这定性为「识别并修补技术缺陷」[一手逐字]。
  • 量子力学底层守真锚Hensen et al. 2015(无漏洞 Bell 实验) 摘要逐字「a Bell experiment that is free of any such additional assumption…We perform 245 trials testing the CHSH-Bell inequality S ≤ 2 and find S = 2.42 ± 0.20.」——局域实在论被无漏洞实验排除[一手逐字]。
  • 支持该读法的最佳证据(对称登记):最接近的一手是 NSA 的措辞限缩「Thus, security of QKD and QC is highly implementation-dependent rather than assured by laws of physics.」——但同页自认「Published theories suggest that physics allows QKD or QC to detect the presence of an eavesdropper, a feature not provided in standard cryptography.」[一手逐字]。除此之外未找到任何同行评议文献或机构文件支持「QKD 是骗局」。该读法的支持侧为空,如实登记。

9.2 读法二:「QKD 一文不值/没有任何真实用途」→ 强版不立,弱版(场景窄、须混合)成立

反方承重证据链(真实部署与真实用户):

  • 欧盟 CORDIS 官方项目页逐字「the technology was used to perform the world’s first-ever bank transfer using quantum cryptography by sending €3 000 over a 1.45-km fibre-optic link between Vienna City Hall and the headquarters of Bank-Austria Creditanstalt. In October 2007, it was also used to provide a secure line for counting votes cast in Geneva in the Swiss national elections, marking the first real-world use of the technology.」——2004 维也纳全球首次量子加密银行转账、2007 日内瓦选举计票,均为欧盟官方项目档案[一手逐字]。
  • IDQ 官网逐字「IDQ has been deploying QKD systems in production networks since 2007, and many installations have run continuously for over a decade.」(厂商口径,注意利益相关)[一手逐字]。
  • 中奥洲际加密通话(守真锚 10);Nature 2021「4600 km、150 用户」(守真锚 5);金融/电力/政务用户清单(§6.7);BT-东芝伦敦网以安永为首个试用客户(§6.5)。
  • 星地独有价值:Nature 2021 摘要同文逐字「Quantum repeaters could in principle provide a viable option for such a global network, but they cannot be deployed using current technology.」——光纤路线卡在量子中继器不可用,星地是现阶段唯一可行的洲际路径[一手逐字]。
  • DI-QKD 的科学价值Nadlinger 2022 摘要逐字「The secrecy of our key is guaranteed device-independently: it is based on the validity of quantum theory, and certified by measurement statistics observed during the experiment. Our result shows that provably secure cryptography with real-world devices is possible」——即使商用价值为零,其科学价值是定理级的[一手逐字]。
  • NCSC 2025 版白皮书的承认段(§7.2):「guarantees detection against eavesdroppers and is resistant to a future quantum computer」「could play some part in future quantum networks」——「我们不推荐」与「它有原理价值」同文并存[一手逐字]。
  • 支持该读法的最佳证据(对称登记):NCSC 同文「should not be relied on as a mechanism that provides substantial security value」;NSA「a more cost effective and easily maintained solution than quantum key distribution」;ANSSI「not…a suitable countermeasure…except for niche applications」;学界批判(arXiv:2502.04009,EPJ Quantum Technol. 录用)对已部署用例逐一做安全评估并「critically discuss…which use cases QKD is suited for」[一手逐字 ×4]。判断:上述证据支持「QKD 通用价值有限、须混合部署」的弱版,不支持「一文不值」的强版。

9.3 读法三:「PQC 已经彻底解决后量子威胁,QKD 多余」→ 不立

反方承重证据链:

  • SIKE/SIDH 2022 被攻破Castryck & Decru(IACR ePrint 2022/975,作者本人预印本)摘要逐字「We present an efficient key recovery attack on the Supersingular Isogeny Diffie-Hellman protocol (SIDH). … this is the case for SIKE, the instantiation of SIDH that recently advanced to the fourth round of NIST’s standardization effort for post-quantum cryptography. Our Magma implementation breaks SIKEp434, which aims at security level 1, in about ten minutes on a single core.」——进入 NIST 第四轮的算法,level-1 参数被单核约十分钟攻破(比媒体常说的「约一小时」更狠,以论文原文为准)[一手逐字]。
  • NIST 官方记录NISTIR 8545(第四轮状态报告)逐字「the submitters of SIKE acknowledged its insecurity and recommended against its further use」「SIKE, the sole isogeny-based candidate, was broken and thus does not satisfy IND-CCA2 security」「The only key-establishment algorithm that will be standardized is HQC」[一手逐字]。
  • Rainbow 的教训Beullens(ePrint 2022/214)摘要逐字「our attack returns the corresponding secret key after on average 53 hours (one weekend) of computation time on a standard laptop」——第三轮决赛签名算法被一台标准笔记本一个周末攻破[一手逐字]。
  • NIST 自己强调 crypto-agilityNISTIR 8105 (2016)逐字「emphasizes the need for agencies to focus on crypto agility」——体制设计前提就是「算法可能再被攻破、需可替换」[一手逐字]。
  • NSA 承认迁移是进行时CNSA 2.0 新闻稿(经 Wayback)逐字「there are neither final standards nor FIPS-validated implementations available yet」(2022-09 时点)[一手逐字]。
  • NIST 对幸存算法的信心分级:NISTIR 8545 同文逐字「However, NIST’s level of confidence in the IND-CCA2 security of these schemes is not equal. Notably, NIST has a higher level of confidence in the IND-CCA2 security of HQC than BIKE.」——「彻底解决」在官方语言里不存在[一手逐字]。
  • 支持该读法的最佳证据(对称登记):NISTIR 8545 同文「ML-KEM…is expected to serve as a general-purpose scheme」;FIPS 203/204/205 已落地(守真锚 7);NCSC「PQC algorithms have been through a rigorous standardisation process run by NIST…Implementations are already being developed and deployed in some operational systems.」[一手逐字]。判断:证据支持「PQC 是主力且已落地」,不支持「已彻底解决、QKD 多余」——SIKE/Rainbow 案例+crypto-agility 官方措辞直接否掉「彻底」。

9.4 读法四:「西方机构贬低 QKD 是因为中国领先」→ 不立(地缘背景真实存在,但立场文本本身是技术论证)

反方承重证据链:

  • 立场文本零国别字眼:NSA 五条理由全部是工程/成本论证(§7.1 逐字),并逐字承认原理「physics allows QKD or QC to detect the presence of an eavesdropper」。对落盘全文 grep china|chinese|beijing|geopolit 命中数为 0(NCSC 白皮书同样为 0)[一手逐字+python 核验]——「贬低」若存在也不在文字里
  • 欧洲内部分裂EuroQCI 官方逐字「The EuroQCI is building a secure quantum communication infrastructure spanning the whole EU」「take the first steps towards services offering operational quantum key distribution (QKD), a highly secure way of exchanging encryption keys」——若「西方贬低 QKD」,欧盟 27 国自建行为无法解释[一手逐字]。
  • 日本持续投入NICT 2025-09 新闻稿逐字「Toshiba Corporation, NEC Corporation, and the National Institute of Information and Communications Technology (NICT) have successfully conducted the world’s first demonstration of multiplexed transmission of quantum key distribution (QKD) signals and key generation within a system environment designed for the IOWN all-photonics network.」——美国盟友阵营内部不存在统一的「贬低」[一手逐字]。
  • 美国自建测试床Fermilab 2020-07-23逐字「DOE’s 17 National Laboratories will serve as the backbone of the coming quantum internet」——「贬低 QKD 是为了压中国」与「美国自己大力建网」不能同真[一手逐字]。
  • 双方都不回避的事实(对称登记)联邦公报 2021-11-26(86 FR, doc 2021-25808)逐字「The ERC decided to add three entities in China (Hefei National Laboratory for Physical Sciences at Microscale, QuantumCTek Co., and Shanghai QuantumCTeck Co., Ltd.) to the Entity List for acquiring and attempting to acquire U.S.-origin items in support of military applications.」——中国 QKD 龙头国盾量子与合肥微尺度实验室被列入实体清单[一手逐字](如实注明:该条目文本未点名 “quantum key distribution”;QuantumCTek 的 QKD 主业由 JRC 报告佐证);NSA CNSA 2.0 新闻稿唯一地缘措辞「Given foreign pursuits in quantum computing…」——地缘压力是真实语境,但该句说的是量子计算而非 QKD[一手逐字]。
  • 判断:出口管制/实体清单证明「量子领域的地缘博弈」为真;但 NSA/NCSC 立场文本本身是可独立检验的工程论证(认证缺失、不可软件化、可信中继内鬼面、DoS 面——每一条都对应本报告第四、五、六章的同行评议证据),且欧盟/日本/美国自建行为与「贬低以压制」矛盾。该读法至多成立为「语境」,不成立为「动机判定」。

9.5 反向红跳小结

四句反向读法:读法一最不立(支持侧为空);读法二强版不立、弱版成立;读法三不立(但 PQC 主线落地属实);读法四不立(地缘证据只能证明博弈存在,不能判定贬低动机)。对称双向的结论形状:把 QKD 说成「无条件不可破解」是跳变,把 QKD 说成「骗局/一文不值/已被 PQC 终结/被西方出于地缘动机贬低」同样是跳变——两个方向的跳变都被档案证伪。

十、母裁决

「量子通信不可破解」这句名号,拆回文件之后是这样一副结构:

守真的一侧一条不动。 BB84/E91 的奠基论文是真的;Shor-Preskill 的安全证明是定理级工作(且自认弱相干源留白);诱骗态、MDI、TF、DI 四代修补与推进是真的;墨子号三大成果、京沪干线、4600 公里集成网络是真实的工程里程碑,150 多家金融/电力/政务用户是真实接入;2017-09-29 的中奥洲际视频通话真实发生。

跳变的一侧同样全部有档。 「无条件安全」在定义它的文献里自带「不是绝对安全的同义词」的警告,而出厂话术把它读成「永久性解决信息安全问题」;安全证明的九条假设(认证信道、可信随机数、设备无旁路、源端态制备……)在传播链里整体消失,而工程侧二十年攻破—补丁—再攻破史(时移、致盲、热致盲、看门狗三缺陷、激光损伤后门、通风口注光、MDI 源侧被拿全部最终密钥、2026 年黑盒窃听 98.97% 筛选密钥)在传播链里同样整体消失;所有招牌距离(2000/4600/7600/12900 km)都是可信中继拼接口径——卫星与中继站本身持有全部密钥——而「可信中继」四个字印在 Nature 摘要里、消失在标题里;按学界自己的六级框架,世界部署至今压在最低一级「可信中继网络」,「量子互联网」作为工程尚未起步,作为名号已被 DOE 官方化并与「virtually unhackable」并置;NSA 与 NCSC 的不背书白纸黑字,而这条负向信息从未进入英文主流传播层;国盾量子的账面转正主要由政府补助与投资收益贡献,公司自己在年报里写明。

两个方向的极端读法都不立。「无条件安全已兑现」不立(第五章);「QKD 是骗局/一文不值」不立(第四、六、九章);「PQC 已彻底解决」不立(SIKE 单核十分钟、NIST 信心分级);「西方贬低因为中国领先」不立(文本零国别字眼+自建行为矛盾)。

灵魂句:安全证明是真的,攻击史是真的,干线是真的,不背书也是真的——被读成的一句假话,是把「在明示假设下可证明安全」读成「无条件不可攻破」的那个动作。做这个动作的不是某一家媒体:是发射日通稿里的「不可窃听、不可破解、永久性解决信息安全问题」,是设备商官网的「无条件安全数据传输」,是十三年不断货的 unhackable 标题——也是每一处把「trusted relay structure」从摘要里剥掉的转述。QKD 的真实位置:一个原理上有定理级安全证明、工程上需持续对抗侧信道、部署上以可信中继为主、制度上被美英情报口否定而被中欧工程口推进的密钥专网技术——它不是骗局,也远不是那句名号。而每个环节的线头,都印在档案里。

附录 A:任务书预设勘误表(九处,全部有落盘证据)

# 任务书预设 实测结果 正确值
1 MDI-QKD arXiv:1111.3082 该号实为 Navier-Stokes 方程论文 arXiv:1109.1473
2 TF-QKD arXiv:1803.00554 该号实为文献计量学论文 arXiv:1811.06826
3 Lo-Ma-Chen 诱骗 arXiv:quant-ph/0503004 该号实为 Lo 独作「Getting Something Out of Nothing」 arXiv:quant-ph/0411004
4 DI-QKD:Zhang PRL 128, 090503/Liu Nature 607, 687 载体对调,且 PRL 128, 090503 查无此文 Zhang=Nature 607, 687-691;Liu=PRL 129, 050502
5 Castryck-Decru arXiv:2207.07261 该号实为浅水方程数值方法论文 IACR ePrint 2022/975
6 时移 2008 打 Clavis2/QPN 5505 全文点名是改装 ID-500 Clavis2+QPN 5505 是 2010 致盲篇对象
7 墨子号星地 QKD/传态载 Science 载体核验为 Nature 549 星地 QKD=Nature 549, 43;传态=Nature 549, 70;纠缠分发=Science 356
8 Nature 2021 arXiv:2011.06852 该号实为车辆重识别论文 Nature 2021 4600km 无 arXiv 版
9 东芝 pr1901「first commercially available」 原文无此字面 原文为「start providing…platforms」

附录 B:通路登记与诚实空位汇总

  • nsa.gov 与 media.defense.gov 直抓 403 → 均经 Wayback id_ 原件落盘;nature.com 摘要可抓、正文付费墙(Nature 2021 正文「150 users」原句以中科院英文官网补足);etsi.org 反爬 → GS QKD 008 走 Wayback;BT newsroom 原稿 404 且 Wayback 无快照 → 以东芝官网引 BT CTO 原话替代;anl.gov 被 Cloudflare 拦截、quantum.gov 拦截页 → DOE 蓝图以 energy.gov+Fermilab 落盘。
  • 京沪干线造价:官方通路均未公布,登记空位不外推。
  • 星地链路天气/时段限制:未取到逐字一手,半空位(济南一号「天光地影」旁证)。
  • ANSSI/BSI/NLNCSA/瑞典 2024-01 联合文件原文 PDF 已由 ANSSI 官网落盘(§7.3);ENISA PQC 报告 PDF 被反爬,空位。
  • 「NSA-proof」字面标题(2013 前后)、FT 2017-07-10、SCMP 2025-05-18、SciAm 2017-06-15、Nature News 2017 正文:检索登记级(付费墙/反爬),均有独立文献脚注或镜像佐证。
  • Quantum Xchange 官网失联+存档断档:不下倒闭结论。
  • 「harvest now, decrypt later」最早出处未定论(可落盘最早:Nextgov 2021-11 媒体/VMware 2021-12 学界产业;NSA 2021-08 FAQ 全文无 “harvest” 字样)。
  • ISO/IEC 23837 Part 2 页面 403 限流;BSI 2023 实施攻击技术报告未取到正文;ETSI GS QKD 016 正文未取(元数据已落盘)。

附录 C:去重实测明细

python 全库扫描 207 篇 / 7,636,581 字符(2026-08-13 开题时):QKD 20 处/量子互联网 4 处/量子中继 9 处/可信中继 3 处/设备无关 21 处/墨子号·Micius 4 处——全部集中在 2026-07-19 量子纠缠篇(Bell 资源账与工程框架义);quantum key distributionquantum cryptographydecoy state诱骗态MDI-QKDtwin-field京沪干线trusted nodepost-quantum(密码义)/PQCQKDN国盾量子ID Quantique 全库零命中——专篇零命中,处女地。

附录 D:调研与核验流程记录

六捆并行一手调研(A 原理与安全证明/B 侧信道攻击/C 部署兑现/D 制度与产业/E 消费与传播/F 反向红跳),raw 抓取件 450+ 落盘 tmp/qkd/raw/;主笔亲核:正篇全部英文逐字引文 253 条经 python 归一化子串比对原始抓取件,237 条直连 PASS,16 条 MISS 逐条人工澄清=15 条摘录级(PDF 页码/引用标号插入、pdftotext 连字符合并、arXiv/期刊 TeX 记号与 Unicode 排版互转、厂商括号昵称省略——原句均目视确认逐字存在于落盘件)+1 条引文偏差(MarketsandMarkets「Compound Annual Growth Rate (CAGR)」被缩成「CAGR」,已修正);Grand View Research 页(JS 壳)经 FetchURL 服务端渲染复抓核对逐字为真;两条付费墙标题(FT 2017-07-10、SciAm 2017-06-15)按检索登记级标注、不落逐字引文库。链接核验(2026-08-13 全量实测 149 个唯一链接):56 个 arXiv ID 抓 abs 页标题逐条比对、全部与所述论文吻合;93 个外链 curl 实测——2 个 404 已修(NIST PQC 第四轮页官网改版下线 → 改挂 Wayback 2023-07-03 快照;NISTIR 8105 → 改挂 nvlpubs.nist.gov 官方 PDF),403/000 逐条登记为出版商或政务站反爬(nsa.gov、media.defense.gov、APS、iso.org、grandviewresearch、sec.gov 等 10 条 403 浏览器可达;csrc.gov.cn 年报 PDF 换浏览器 UA 实测 200;jiqt.org 原站关停、正文只挂 Wayback)。三套口径不混:论文摘要口径(含假设声明)/官方通稿口径/厂商营销口径各自单列。