# Four States and a Short Vector

*Quantum mechanics takes secrecy away with one hand and gives it back with the other. A Fourier transform dissolves the arithmetic under the padlock; a theorem about copying lets a single photon carry a key nobody can overhear; and a little deliberate noise turns a schoolroom equation into a wall. The actual mathematics of all three, made readable, and where the migration stands in September 2026.*

Mathematics · September 2026 · 18 min · by Epimystic
Canonical: https://epimystic.com/essays/four-states-and-a-short-vector/
Topics: quantum, cryptography, lattices, proof, the future

There is a way of telling this subject that makes it an arms race, and it is not wrong, but it hides the more interesting fact. Quantum mechanics is on both sides. The same handful of principles—superposition, interference, the impossibility of copying an unknown state—both destroy the secrecy we have and offer a stranger secrecy in its place. A previous essay told the story from the outside: what the machine would do, why the deadline has passed, what was quietly swapped out under your feet ([someone is already keeping your secrets](https://epimystic.com/essays/someone-is-already-keeping-your-secrets/)). This one goes inside, to the mathematics of the attack, the physical key and the new locks, at the level where you could check it—and then says plainly where the world has got to this month.

## The Fourier Transform as a Lens

Start with what Shor’s algorithm computes, because the popular gloss misleads. It does not search. It measures a frequency. Given a number N to factor and a smaller a sharing no factor with it, the sequence a, a², a³ and so on, each reduced modulo N, eventually returns to 1 and repeats. The length of that cycle is the order, r, and old number theory says that once you know r you very probably know the factors: raise a to the power r/2, add and subtract one, and the greatest common divisor of either with N is a factor. Everything hard has been pushed into finding r.

Take two registers. The first holds an exponent x, put into an equal superposition of every value from 0 up to Q, a power of two roughly the square of N. The second is loaded, in superposition, with a raised to the x modulo N—ordinary arithmetic done on every x at once, and by a wide margin the expensive part of the whole computation: the resource estimates you read about are mostly estimates of how cheaply one can multiply. The first register is now periodic in x with period r, and a periodic thing has a sharp spectrum. Apply the quantum Fourier transform and the amplitudes of the Q outcomes interfere: every y not close to a multiple of Q over r cancels itself, and the ones that are close survive. Measure, and y over Q is within one part in 2Q of some k over r; a continued-fraction expansion, which Euclid could have done, recovers k over r in lowest terms, and a few repetitions pin down r. And it works because the period lives in an abelian group—the integers modulo N under multiplication—and Fourier analysis is exactly the tool that finds hidden periodicities there. Nothing in the trick is specific to factoring. It is specific to commutativity.

> **The quantum computer is not a faster search. It is a lens that brings one frequency into focus while every other cancels.**

How big is the lens? The reference point for RSA-2048 was set in 2019 at about twenty million noisy physical qubits for eight hours. In May 2025 Craig Gidney revised his own figure to under a million for under a week, holding every physical assumption fixed: a square grid, a gate error of one in a thousand, a code cycle of one microsecond.[^2] The saving came from approximate modular arithmetic, denser storage of idle qubits and cheaper manufacture of the resource states that non-Clifford gates need—none of it a better machine. A separate line of work at CRYPTO 2025 cut the logical count to around 1,730; logical qubits are what the algorithm sees, physical qubits the several hundred it costs to keep each one alive.

Elliptic curves are worse, and this is the part people miss. Shorter keys mean smaller arithmetic. In 2017 breaking the P-256 curve was costed at 2,330 logical qubits and about 126 billion Toffoli gates; in March 2026 a paper from Google Quantum AI with the Ethereum Foundation and Stanford put the curve behind every major cryptocurrency at fewer than 1,200 logical qubits and 90 million Toffolis—under half a million physical qubits, and minutes of running time once a precomputation is done. The curve that replaced RSA because it was more efficient is, for that reason, the cheaper one to break. What exists this autumn: Google’s Willow, 105 superconducting qubits, has shown a larger error-correcting code halving the logical error at each step; Quantinuum’s Helios, 98 trapped ions, has run 48 fully error-corrected logical qubits. Nobody is within two orders of magnitude of the half-million, and everybody is closer than eighteen months ago, from both directions at once. Symmetric ciphers, which face only Grover’s serial square-root search, are fine; the public-key layer, the part that lets strangers agree a secret in public, is what goes.

## What Cannot Be Copied

Now the other hand. In 1982 Wootters and Zurek, and independently Dieks, published a theorem so short it is almost embarrassing.

> A single quantum cannot be cloned.
>
> — —William Wootters and Wojciech Zurek, Nature, 1982

The proof is three lines. Suppose a machine took any state and a blank and produced two copies. Feed it 0 and it yields 0,0; feed it 1 and it yields 1,1. Quantum evolution is linear, so feed it the superposition of 0 and 1 and linearity insists the output is the superposition of 0,0 and 1,1—an entangled pair. But two genuine copies of the superposition would be the product state, which expands to four terms, not two. The machine cannot exist. There is no engineering to be done; the impossibility is the linearity of the theory. The same linearity means any attempt to tell apart two non-orthogonal states must, on average, disturb them. An eavesdropper is not forbidden from listening. She is forbidden from listening without leaving marks.

BB84—Bennett and Brassard, 1984—turns that into a protocol using four polarisation states of a single photon. Vertical and horizontal form the rectilinear basis and encode 0 and 1; the two diagonals form a second basis and encode 0 and 1 again. A diagonal photon measured rectilinearly comes out vertical or horizontal at random and forgets which diagonal it was. Alice sends photons, choosing for each a random bit and a random basis; Bob measures each in a basis he chooses at random. Where his guess matches hers, his bit equals hers. Where it does not, his bit is a coin toss.

*Figure: the-sifting — Twelve photons of BB84. Alice picks a bit and a basis for each; Bob guesses a basis; the columns where the guesses agree are announced in public and kept, the rest thrown away. Nobody ever announces a bit.* (drawn in the essay: https://epimystic.com/essays/four-states-and-a-short-vector/)

Then the step people find hard to believe is allowed. Over an ordinary public channel Bob announces which basis he used for each photon—not what he saw, only the basis—and Alice replies which guesses were right. They discard the rest. This is the sifting, and it leaves them with half the photons and a string of bits they share and nobody has spoken aloud. An eavesdropper who intercepted a photon, measured it and sent on a fresh one had to guess a basis too; half the time she guessed wrong, and then her forwarded photon gives Bob a random bit even when his basis matches Alice’s. Intercepting everything corrupts a quarter of the sifted key, and Alice and Bob detect it by comparing a random sample in public. The proof that this is secure against every attack physics permits came sixteen years later: Shor and Preskill showed that below an error rate of about eleven per cent, error correction followed by privacy amplification—hashing the key down until whatever the eavesdropper learned is diluted to nothing—leaves a shorter key that is secret unconditionally.[^1] The surviving fraction is one minus twice the binary entropy of the error rate, which reaches zero at eleven per cent. Nothing in the argument mentions how much computing power the eavesdropper has. That is the entire appeal.

Artur Ekert’s 1991 variant moves the source into the middle: a device emits entangled pairs, one photon to each party. Measured along the same axis, their results are perfectly anti-correlated and become the key. Measured along deliberately mismatched axes, they yield the quantity John Bell wrote down, which any theory of pre-set answers keeps at or below 2 and which quantum mechanics predicts at two root two, about 2.83. See 2.83 and no third party holds a copy, because a state maximally entangled between two parties cannot be entangled with a third. The Bell violation is a certificate that the photons arrived unread—[the fact that unsettled Einstein](https://epimystic.com/essays/nobody-understands-it/), put to work as a lock.

## Where the Photons Actually Go

Photons in glass are absorbed: standard fibre loses about a twentieth of them per kilometre, half of them every fifteen. There is no amplifying a quantum signal—that would be cloning—so the distance limit is the theorem again, seen from the other side. China’s Beijing-to-Shanghai backbone, opened in 2017 at just over two thousand kilometres, gets round it with thirty-two trusted nodes, each of which receives a key from the previous hop, generates a fresh one with the next, and stitches them together in the clear inside a guarded room. The line is exactly as secure as its thirty-two rooms.

Twin-field protocols, in which both parties send weak pulses to an untrusted station in the middle, halve the effective loss, and the records are real: 1,002 kilometres of fibre in 2023 with no trusted node, at a secure key rate of 0.0034 bits per second—one bit every five minutes, against over a hundred kilobits a second at two hundred kilometres. The distance at which the technology works usefully is between two cities, not two continents. For continents there is orbit. Micius ran entanglement-based key exchange over 1,120 kilometres in 2020 at 0.12 bits per second; the microsatellite Jinan-1, reported in Nature in March 2025, exchanges up to a megabit of key per pass and linked Beijing to Stellenbosch, 12,900 kilometres apart—with the satellite itself as the trusted node. Every long link that exists today relies somewhere on a room or a spacecraft you have to trust.

Two further limits matter more. A quantum channel authenticates nothing: the public conversation about bases must itself be signed, classically, or an impostor runs BB84 with each party separately—so a quantum link still needs a post-quantum signature under it. And the proofs concern ideal detectors, while real ones leak. In 2010 Vadim Makarov’s group shone bright light at the photodiodes of two commercial systems, drove them out of their single-photon regime, and dictated Bob’s results with the error rate at zero. The protocol was not broken. The box was.

> NSA does not recommend the usage of quantum key distribution and quantum cryptography.
>
> — —National Security Agency, on securing national security systems

That sentence, and its British counterpart, do not dismiss the physics. They judge that a guarantee about a channel is not a guarantee about a system, and that post-quantum mathematics gives the same practical protection on equipment we already own. For a link between two fixed government sites the sum may come out the other way. For eight billion phones it does not.

## Noise as a Lock

So the world needs public-key mathematics with no commutative period for a Fourier transform to find, and the answer that won is a problem Oded Regev wrote down in 2005: learning with errors. Fix a modulus q and a secret vector s of n numbers modulo q. Publish many pairs: a random vector a, and the number b equal to the inner product of a and s plus a small error e, modulo q. Without the errors this is a system of linear equations, and elimination recovers s from n of them at once. With the errors it is not. Each row operation combines rows, and the errors combine with them; after a few dozen steps the noise is as large as q and the equations say nothing. There is no solve-and-then-denoise, because the noise is not on the answer but on every equation you would use to reach it.

*Figure: the-noisy-inner-product — Left: a lattice, the long skewed basis you are handed, and the short vector you are asked to find. Right: learning with errors. The exact inner product sits at one place on the number line modulo q; what is published is one step away.* (drawn in the essay: https://epimystic.com/essays/four-states-and-a-short-vector/)

The geometry underneath is why this is called lattice-based. The integer combinations of the vectors a, modulo q, form a lattice—a regular grid in n dimensions—and b is a point near it, displaced by the errors. Finding s is finding the lattice point nearest to b. In two dimensions your eye does it instantly. In 768, given a basis deliberately skewed so its vectors are long and nearly parallel, the best known methods, classical or quantum, take time exponential in the dimension. A short, nearly orthogonal basis for the same lattice makes the problem easy, and that is what a private key is.

Encryption is Regev’s original idea and ML-KEM’s actual one. To send a 1, add up a random handful of the published equations and add q over 2 to the b-side; to send a 0, leave it alone. The receiver, knowing s, subtracts the inner product of the summed a with s from the summed b and looks at what remains: a small accumulated error, or that plus q over 2. Rounding recovers the bit, and the scheme fails only if the errors grow past q over 4, which ML-KEM-768’s parameters—three polynomials of degree 256, hence 768, with q equal to 3,329—make happen with probability about two to the minus 164. The public key is 1,184 bytes; the ciphertext carrying a 256-bit shared secret is 1,088.

> **The lock is not the equation. The lock is the noise.**

Signatures from the same soil are harder. A signature must prove knowledge of the short secret without revealing it, and naive schemes leak a little of the secret with every signature. ML-DSA, the former Dilithium, works modulo 8,380,417 and solves the leak by Fiat-Shamir with aborts: the signer draws a random mask, computes a candidate, and checks whether its coefficients fall inside a fixed box; if not—a few times per signature—it discards the candidate and draws again, so what survives is distributed independently of the secret. The price is a 1,952-byte public key and a 3,309-byte signature. FN-DSA, the former Falcon, fits the same security into 897 and 666 bytes with a discrete Gaussian sampler that needs floating-point arithmetic done in constant time; its draft standard, FIPS 206, was only submitted for approval in August 2025 and is not final as I write.

## Hashes, Codes, and the One That Died

The hedge against lattices being wrong takes two forms, both older than lattice cryptography. The first assumes only that a hash function behaves like one: a one-time key signs a bit by revealing one of two hashed secrets, and a Merkle tree of many such keys lets one root stand for thousands of signatures. SLH-DSA, the former SPHINCS+, stacks such trees into a hypertree so that it never has to remember which leaf it used; its public key is 32 bytes and its signature, in the small-and-slow set, 7,856. The stateful cousins XMSS and LMS, approved for firmware signing in 2020, are far smaller but must never reuse a leaf: restore a backup with an old counter and the scheme is broken.

The second hedge is error-correcting codes. Robert McEliece proposed it in 1978 and it has never been broken: the public key is a scrambled generator matrix for a Goppa code, encryption adds a fixed number of random errors to a codeword, and decrypting is decoding, easy with the unscrambled code and apparently hard without it. The cost is the matrix: the smallest Classic McEliece set has a 261,120-byte public key and a 96-byte ciphertext. HQC, chosen by NIST in March 2025 as the deliberately non-lattice backup to ML-KEM, uses a quasi-cyclic code to bring the key to 2,249 bytes at the price of a 4.5-kilobyte ciphertext.[^3] The bet across the three families is that one new idea does not fell hashes, codes and lattices on the same afternoon.

*Figure: the-weight-of-a-key — What a public key and a signature, or ciphertext, weigh, in bytes, on a logarithmic scale. The two classical schemes at the top are what most of the internet used until 2024; everything below is what replaces them.* (drawn in the essay: https://epimystic.com/essays/four-states-and-a-short-vector/)

That afternoon has happened once. SIKE was built on isogenies, maps between elliptic curves, and its assumption—that finding an isogeny between two given curves is hard—is still believed. But to let the two parties’ walks commute, each had to publish the images of certain torsion points under their secret map. On 30 July 2022 Wouter Castryck and Thomas Decru saw that a 1997 theorem of Ernst Kani—about when a product of two elliptic curves, glued into a two-dimensional abelian surface, splits again into a product—turns exactly that auxiliary information into a test for the secret. The main parameter set fell in about an hour on one core. The underlying problem was never touched; the protocol had been obliged to say too much, and a corner of geometry nobody in the competition was reading had been waiting to hear it. The family has regrouped around SQIsign, which publishes nothing about torsion and has the smallest signatures of any candidate, one of nine NIST advanced to a third round this May.

## Where We Stand, September 2026

None of this can wait for the machine, because ciphertext keeps. Anyone recording encrypted traffic today can open it the week the lens is ready, and for most secrets worth keeping that week is inside their useful life. Key exchange, which protects against exactly that, has largely moved. In July the IETF published the hybrid design for TLS 1.3 as RFC 9954, and the combination the browsers had already shipped—X25519 and ML-KEM-768 run together, the secrets concatenated so an attacker must break both—became RFC 10024. Chrome, Edge and Firefox negotiate it by default; Apple’s systems have advertised it since iOS 26 shipped last September. By spring about two-thirds of human traffic reaching Cloudflare used it, and roughly half of surveyed domains supported it. Messaging went further: Signal added a lattice agreement to its handshake in 2023 and last October threaded ML-KEM-768 through the ongoing ratchet in erasure-coded chunks; Apple’s PQ3 for iMessage has done the equivalent since early 2024.

Authentication has not moved. Not one public certificate on the web is signed with a post-quantum algorithm today. Every handshake protected against recording is still authenticated by an elliptic curve, because a chain carrying three ML-DSA signatures adds around ten kilobytes to every connection and the whole ecosystem must move together. Cloudflare’s plan is ML-DSA to its own origins this year and a Merkle-tree certificate format for the last hop in 2027; Google and Cloudflare both say their stacks will be post-quantum by 2029. A forged signature is useless until the machine exists, so the threat comes later—but signatures live in firmware nobody plans to replace.

*Figure: the-migration-band — Fourteen years on one line. Above it, what has happened since SIKE fell; below it, the dates governments and the two largest networks have committed to; shaded, the years in which the people building the machines think one arrives.* (drawn in the essay: https://epimystic.com/essays/four-states-and-a-short-vector/)

Governments have written dates down. NIST’s transition document, still an unfinalised draft from November 2024, deprecates RSA and elliptic curves after 2030 and disallows them after 2035. An executive order of 22 June this year makes 2030 the deadline for post-quantum key establishment on federal high-value systems, 2031 for signatures, 2035 for everything. The European Union asks every member state to have started by the end of this year, secured high-risk systems by 2030 and finished by 2035; Britain asks for an inventory by 2028, priority migrations by 2031 and the rest by 2035. Read these as what they are: instruments for making institutions begin, calibrated against a distribution of guesses.

## The Two Guarantees

For the first time there are two different kinds of secrecy on offer. One is physical: the key on a quantum link is secret because copying is forbidden by the linearity of the theory, and no computer changes that. The other is computational: the lattice key is secret because nobody knows how to find a short vector in seven hundred dimensions, a statement about present knowledge and nothing more. The physical guarantee is stronger and reaches, today, between two rooms in one country. The computational one is weaker and reaches into your pocket. It would be wrong to call the first real and the second a stopgap. The physical guarantee is about a channel; everything at either end—the detector, the node, the classical authentication—is a system, and systems are where secrets leak. And the computational guarantee can be hedged, which the physical one cannot. Every deployment above runs the old curve and the new lattice together: the people who built this were not confident in mathematics twenty years old, so they bought the right to be wrong about it—[doubt given a structural role](https://epimystic.com/essays/doubt-as-a-load-bearing-wall/).

What I hold onto is smaller than any of this. A theorem three lines long, about copying, has been turned into a lock. A theorem about hidden periods has been turned into a key. And a problem a schoolchild can solve has been made unsolvable by adding one to some of the answers. The privacy of the coming decades rests on those three pieces of arithmetic, and they are worth knowing not because they will make you safer but because each is a small, exact, unlikely thing to be true about the world.


---

[^1]: Bennett and Brassard (in Further reading) give the four states, the sifting and the intercept-resend argument, though not a proof; Shor and Preskill (also there) supply the proof and the threshold. Eleven per cent is for one-way error correction; with two-way post-processing the tolerable error rises to around twenty.
[^2]: Gidney’s preprint (in Further reading) lists its assumptions in an opening table: a square grid with nearest-neighbour connections, a physical gate error of one in a thousand, a code cycle of one microsecond and a control system that reacts within ten. Change any of those and the million moves.
[^3]: HQC’s ciphertext has been quoted as 4,433 and as 4,497 bytes in different versions of the submission; the figure uses the later. NIST promised a draft standard for HQC in 2026, and at the time of writing I have not been able to find it published.

## Further reading

- **Quantum Cryptography: Public Key Distribution and Coin Tossing** — Charles Bennett and Gilles Brassard. The 1984 conference paper that is the whole of BB84 in five pages. It was ignored for years, partly because it appeared in the proceedings of a signal-processing conference in Bangalore, and it reads today like a letter from someone who already knew how the story ended.
- **Simple Proof of Security of the BB84 Quantum Key Distribution Protocol** — Peter Shor and John Preskill. Four pages in Physical Review Letters, 2000, that turn the protocol from a plausible idea into a theorem. The eleven per cent threshold quoted here is theirs, and the argument—relating BB84 to an error-correcting code that never has to be built—is one of the loveliest in the field.
- **How to Factor 2048 Bit RSA Integers with Less Than a Million Noisy Qubits** — Craig Gidney. The 2025 preprint whose title is its abstract. The middle sections, on approximate residue arithmetic and on storing idle qubits more densely, are where the twentyfold reduction actually comes from, and they are legible to anyone who can follow a cost estimate.
- **On Lattices, Learning with Errors, Random Linear Codes, and Cryptography** — Oded Regev. The 2005 paper that defined learning with errors and proved the worst-case reduction everything lattice-based now leans on. The encryption scheme in its fifth section is essentially what ML-KEM still does, twenty years and one standardisation later.
- **An Efficient Key Recovery Attack on SIDH** — Wouter Castryck and Thomas Decru. The paper that removed a whole family from the competition in an afternoon. Its importance is not the attack but the shape of it: a theorem from 1997, in a neighbouring corner of geometry, waiting for someone to notice what the protocol was giving away.
- **Timelines for Migration to Post-Quantum Cryptography** — UK National Cyber Security Centre. The clearest of the national roadmaps, and the one that admits most plainly that a date is an instrument for making organisations start, not a prediction of when a machine arrives. The 2028, 2031 and 2035 milestones on this essay’s last figure are from here.
