Cybersecurity has an unusual timing problem: to defend data that must remain secret for ten or twenty years, one must prepare today for machines that do not yet exist at a useful scale. This is the principle behind the race for post-quantum cryptography and quantum networks. In India, QNu Labs has raised 200 crore rupees, roughly 21–25 million dollars depending on the exchange rate used, in a Series A1 led by the National Quantum Mission and Speciale Invest.

The company, incubated at IIT Madras and active since 2016, will use part of the capital to contribute to a quantum key distribution network roughly 2,000 kilometres long between Bengaluru and Delhi, also designed to protect critical financial infrastructure along the route.

The risk is “collect today, decrypt tomorrow”

Many cryptographic systems considered secure today rely on mathematical problems that are hard for classical computers. A sufficiently powerful quantum computer could change this equation. We do not know when a machine of that level will arrive, but an attacker can already intercept encrypted communications and store them, waiting to decrypt them in the future.

For information with a long useful lifespan, the risk is therefore not science fiction. Governments, defense, banks, and infrastructure operators must plan the migration long before the arrival of a cryptographically relevant quantum computer.

Two paths: mathematics and physics

There is no single answer. Post-quantum cryptography uses new mathematical algorithms designed to resist both classical and quantum computers. Quantum key distribution, on the other hand, leverages the properties of quantum physics to distribute keys and make certain forms of eavesdropping detectable.

The two technologies are not necessarily mutually exclusive. A critical network can combine multiple layers, selecting different solutions based on cost, distance, performance, and the required security level.

Why 2,000 kilometres matter

Taking quantum technologies out of the laboratory means dealing with existing fiber, signal attenuation, intermediate nodes, key management, and integration with legacy networks. A backbone between two major Indian tech hubs would therefore represent, above all, a test of industrialization.

The value lies not in proving once again that QKD works under controlled conditions, but in discovering whether it can become a manageable service within real-world infrastructures and under continuous operational demands.

India wants to own the technology

The presence of the National Quantum Mission as an investor also signals that quantum is being treated as strategic infrastructure. QNu Labs states that it has a team of roughly 160 engineers, physicists, and mathematicians, with products already deployed across government, critical infrastructure, and financial services.

For New Delhi, the stakes are twofold: securing its own networks and establishing a domestic supply chain in a sector that could become as crucial to national security as semiconductors.

We must not wait for the perfect quantum computer

The greatest risk would be interpreting the uncertainty surrounding timelines as a reason to do nothing. Migrating complex cryptographic systems takes years, auditing dependencies is difficult, and many industrial devices remain in service for decades.

The network engineered by QNu is therefore noteworthy precisely because it anticipates the problem. Traditional cybersecurity often reacts to vulnerabilities that have already been observed; quantum security, by contrast, forces engineers to design against a future capability. It is an exercise in technological prevention on a scale that few industries are accustomed to tackling.

Sources