Bennett and Brassard Win the Turing Award for Inventing Quantum Cryptography
March 18, 2026 — The Association for Computing Machinery has awarded the 2025 A.M. Turing Award to Charles H. Bennett of IBM Research and Gilles Brassard of the Université de Montréal, recognizing their foundational contributions to quantum information science and the development of quantum cryptography. The award, widely regarded as computing’s highest honor, carries a $1 million prize with financial support from Google.
Bennett, 82, an IBM Fellow and member of the U.S. National Academy of Sciences, and Brassard, 70, a professor at the Université de Montréal, received the award for “their essential role in establishing the foundations of quantum information science and transforming secure communication and computing.” Their 1984 BB84 protocol marked the first practical quantum cryptography method, demonstrating how quantum mechanics could provide information-theoretic security guarantees impossible with classical cryptographic approaches.
The two scientists met at a 1979 academic conference in Puerto Rico, where Bennett approached Brassard during a swimming break to propose developing an unforgeable quantum banknote. This chance encounter sparked a collaboration spanning more than four decades, producing breakthroughs in quantum teleportation, superdense coding, and entanglement distillation alongside their cryptographic work.
“Bennett and Brassard fundamentally changed our understanding of information itself,” said ACM President Yannis Ioannidis in the announcement.
The BB84 protocol uses quantum states of photons to distribute cryptographic keys between parties. Any attempt to intercept or measure these quantum states disturbs them in detectable ways, alerting legitimate users to eavesdropping attempts. This principle, rooted in the fundamental laws of quantum mechanics rather than computational complexity assumptions, offers security guarantees that remain valid even against adversaries with unlimited computational resources.
Bennett and Brassard previously shared the 2018 Wolf Prize in Physics.
My Analysis
Forty years after BB84, this Turing Award feels both overdue and perfectly timed. Bennett and Brassard didn’t just invent quantum cryptography; they showed us that information itself has a physical nature that we can exploit for security. As I sit here reading the announcement, I’m struck by how their work continues to shape debates about our cryptographic future.
The BB84 protocol was revolutionary precisely because it broke cryptography’s dependence on mathematical hardness. Traditional encryption relies on problems we believe are computationally intractable. Quantum key distribution (QKD) relies on physics: you literally cannot copy an unknown quantum state without disturbing it. The security guarantee comes from Heisenberg’s uncertainty principle, not from assumptions about P versus NP.
Yet here’s where I need to inject some reality into the celebration. QKD remains one of quantum technology’s most beautiful theories with one of its messiest practical track records. The physics is bulletproof. The engineering? That’s where things get complicated.
The Implementation Challenge
In my discussions with security professionals implementing quantum technologies, I consistently hear the same refrain: QKD’s theoretical elegance collides hard with operational reality. The quantum channel itself may be unconditionally secure, but the classical authenticated channel you need to run alongside it? The photon detectors that can be blinded or controlled? The imperfect single-photon sources that leak information through side channels? These remain stubbornly classical and stubbornly vulnerable.
I’ve watched China deploy thousands of kilometers of QKD networks, including the Beijing-Shanghai backbone that’s been operational since 2017. The engineering achievement is impressive. But when you dig into the details, you find trusted relay nodes every 100 kilometers or so because quantum signals attenuate over fiber. Each relay node is a potential point of classical compromise.
The recent reentry of the Micius quantum satellite reminded me how satellite QKD partially solves the distance problem but introduces new challenges. You need clear skies. You need precise tracking. You need ground stations with their own security perimeters. The quantum channel might be secure, but the infrastructure around it presents a large attack surface.
PQC Versus QKD: The False Dichotomy
The timing of this award is fascinating given where we are with post-quantum cryptography standardization. NIST’s PQC standards became official in 2024, offering quantum-resistant algorithms we can deploy today on existing infrastructure. No special hardware required. No distance limitations. No trusted relay nodes.
I often encounter people who frame this as QKD versus PQC, as if we must choose sides. This misses the point entirely. Bennett and Brassard themselves understood that different security models serve different needs. Their broader contributions to quantum information science show they were thinking about the full spectrum of quantum technologies, not just key distribution.
PQC gives us computational security against quantum computers using classical means. It’s practical, deployable today, and works over any communication channel. QKD offers information-theoretic security for key distribution specifically, but requires quantum channels and specialized hardware. They solve related but distinct problems.
In my conversations with enterprise security teams, I find the most sophisticated organizations are exploring both approaches. They’re deploying PQC now because the migration timeline is long and Q-Day timing remains uncertain. They’re also keeping tabs on QKD developments for specific high-value use cases where the additional infrastructure investment might be justified.
Recent Technical Progress
The QKD field hasn’t stood still since BB84. Integrated photonics might eventually make quantum key distribution cheaper and more reliable by moving QKD systems onto chips.
Twin-field QKD itself represents a significant advance, extending secure transmission distances by having both parties send quantum states to a central measurement station. The protocol maintains security even if that central node is untrusted. It’s clever engineering that addresses one of QKD’s fundamental limitations.
I’m also watching developments in continuous-variable QKD, which uses the quadratures of electromagnetic fields rather than single photons. The equipment requirements are closer to classical optical communications, potentially making deployment more practical. Several startups are betting their futures on making CV-QKD work at scale.
Singapore’s Monetary Authority launching a QKD sandbox signals that financial regulators are taking quantum security seriously. They’re creating controlled environments to test QKD for high-value transactions where the security premium might justify the infrastructure costs.
The Broader Quantum Information Legacy
What strikes me most about this Turing Award is how it recognizes quantum information science as a coherent field. Bennett and Brassard didn’t just give us BB84. They helped establish the conceptual framework for thinking about information as a physical quantity subject to quantum laws.
Their 1993 teleportation paper, written with four co-authors, showed how quantum entanglement could transfer quantum states between distant parties. This wasn’t about beaming Captain Kirk anywhere; it was about understanding entanglement as a resource for information processing. That conceptual shift underlies much of modern quantum computing and quantum networking research.
Superdense coding, which Bennett developed with Stephen Wiesner in 1992, demonstrated how one qubit could carry two classical bits of information when combined with entanglement. Again, this wasn’t just a clever trick. It showed how quantum resources could provide advantages for certain information processing tasks.
Their work on entanglement distillation addresses one of quantum technology’s persistent challenges: maintaining quantum coherence in noisy environments. The protocols they developed for purifying entangled states from multiple noisy copies inform modern approaches to quantum error correction.
What This Means for Security Leaders
As I reflect on this award and my conversations with CISOs and security architects, several lessons emerge. First, the quantum threat to cryptography is real enough that the computing field’s highest honor goes to quantum cryptography pioneers. The academic establishment isn’t treating this as speculative.
Second, the path from theoretical breakthrough to practical deployment can span decades. BB84 is 40 years old, and we’re still working out implementation details. Security leaders planning for quantum threats need similar long-term thinking.
Third, different security models serve different purposes. Information-theoretic security sounds wonderful, but if your implementation leaks information through side channels, theoretical perfection means little. Computational security might be “merely” very strong rather than unconditionally secure, but if you can deploy it reliably on existing infrastructure, that’s often the better choice.
For organizations beginning their quantum security journey, I recommend starting with PQC migration planning. It’s actionable today, doesn’t require specialized hardware, and addresses the most pressing quantum computing threat. Get your cryptographic inventory in order. Understand your algorithm dependencies. Plan your migration timeline.
For those with specific high-security requirements and resources to invest, exploring QKD makes sense as a complementary approach. But go in with eyes open about the implementation challenges. The quantum channel is just one piece of a complex system, all of which needs securing.
Looking Forward
This Turing Award marks a generational transition in cryptography. We’re moving from a world where encryption meant mathematics to one where physics plays an increasingly central role. Whether through quantum-resistant algorithms or quantum key distribution, the future of secure communication will be shaped by quantum mechanics.
Bennett and Brassard showed us that information has physical properties we can exploit. Their intellectual framework extends far beyond the specific protocols they invented. As quantum computers grow more powerful and quantum networks more prevalent, their insights become more relevant, not less.
The award also sends a message about interdisciplinary thinking. Bennett came from physics, Brassard from computer science. Their collaboration at the intersection of these fields created entirely new possibilities. As we face the quantum future, we need more boundary crossing, not less.
I expect this award will accelerate investment in quantum information science broadly. When the Turing Award committee recognizes a field, venture capitalists and government funders pay attention. We’ll likely see increased funding for quantum networking research, more aggressive QKD commercialization efforts, and renewed focus on making quantum technologies practical.
For those of us focused on post-quantum security, this recognition validates our concerns while highlighting the complexity of solutions. The quantum threat is real enough to merit computing’s highest honor. The solutions, whether PQC or QKD or something not yet invented, require careful thought about threat models, implementation realities, and deployment timelines.
Bennett and Brassard gave us new ways to think about information and security. Forty years later, we’re still unpacking the implications of their insights. This Turing Award doesn’t mark the end of their story but rather acknowledges that quantum information science has come of age. The real work of building quantum-secure systems for the real world continues.