Bennett and Brassard: Quantum Cryptography
Abstract
One afternoon in late October 1979, Gilles Brassard (born 1955), a new Cornell PhD, was swimming off a hotel beach in San Juan, Puerto Rico, when a stranger swam up and began telling him about quantum banknotes. The stranger was Charles Bennett (born 1943) of IBM Research, who had been failing for a decade to interest anyone in Stephen Wiesner’s rejected paper on encoding information in polarised photons. By evening they had a collaboration; by 1984 they had BB84, the first quantum key-distribution protocol, whose security rests on physics rather than on the difficulty of a sum; by 1989 a working prototype that sent a secret key 32.5 centimetres; by 1993 quantum teleportation. They shared the 2025 Turing Award, announced in March 2026, as founders of quantum information science.
Wiesner’s Banknotes
The idea was Stephen Wiesner’s. Around 1970, as a graduate student, he wrote “Conjugate Coding,” which proposed banknotes that could not be counterfeited because their serial numbers were stored in the polarisation of trapped photons, which quantum mechanics forbids anyone to copy, and a channel over which a sender could transmit two messages of which the receiver could read only one. He submitted it to the IEEE Transactions on Information Theory, which rejected it, in Brassard’s guess “probably deemed incomprehensible by the editors and referees because it was written in the technical language of physicists.” Wiesner had explained the ideas to his friend Bennett, and Bennett, Brassard wrote, “mentioned them occasionally to various people in the subsequent years, invariably meeting with very little sympathy until . . .”
The Beach
Charles Bennett was born in New York in 1943, took a BS in chemistry at Brandeis in 1964 and a Harvard PhD in 1970 under David Turnbull and Berni Alder, and joined IBM Research in 1972. His first famous paper was in a different field: “Logical Reversibility of Computation” (1973) showed that any computation could be done by a machine that never erased anything and so, by Rolf Landauer’s argument, need dissipate no energy at all. His 1982 review of the thermodynamics of computation used the same idea to lay Maxwell’s demon to rest: the demon pays not for measuring but for forgetting.
Gilles Brassard was born in Montreal on 20 April 1955, took his first degrees at the Université de Montréal and a Cornell PhD in 1979 under John Hopcroft, on relativized cryptography, and went straight back to Montreal, where he has taught since. In October 1979 both men were in San Juan for the 20th IEEE Symposium on Foundations of Computer Science. Bennett had noticed that Brassard was to speak on cryptography on the last day, and thought he might be interested in Wiesner. Brassard, who had read Martin Gardner’s column about Bennett’s work in that month’s Scientific American but did not know his face, recalled: “Imagine my surprise when this complete stranger swims up to me and starts telling me, without apparent provocation on my part, about Wiesner’s quantum banknotes! This was probably the most bizarre, and certainly the most magical, moment in my professional life.”
“Within hours,” he wrote, “we had found ways to mesh Wiesner’s coding scheme with some of the then-new concepts of public-key cryptography.” Their first paper, presented at Crypto ‘82, coined the term “quantum cryptography” and shamed SIGACT News into finally printing Wiesner’s “Conjugate Coding” in 1983, thirteen years late.
BB84
The protocol that made them famous was described at an IEEE information-theory symposium in 1983 and written up for a conference in Bangalore in December 1984, where Brassard’s friend Vijay Bhargava had a session and let him talk on anything he liked; “naturally I chose quantum cryptography, considering how difficult it was to get these ideas published at the time.” The paper, “Quantum Cryptography: Public Key Distribution and Coin Tossing,” gave the protocol its name, BB84, and was not printed in a journal until Theoretical Computer Science marked its thirtieth anniversary in 2014.
The idea is that a sender transmits single photons polarised at random in one of two incompatible bases, and the receiver measures each in a randomly chosen basis. Afterwards, over an ordinary public channel, they compare which bases they used, keep only the photons where the bases matched, and have a shared random key. An eavesdropper who intercepts a photon must measure it, does not know which basis to use, and half the time destroys the information while leaving a trace that the legitimate parties can detect by comparing a sample of their bits. The security does not depend on any problem being hard to compute; it depends on quantum mechanics being correct. When Peter Shor showed in 1994 that a quantum computer would break RSA, BB84 was the part of cryptography that had nothing to fear.
Theorists were unimpressed at first, so, Brassard wrote, “Bennett and I decided we had to show them by building a working prototype!” With John Smolin on hardware and François Bessette and Louis Salvail on software, and no budget to speak of, they made “history’s first secret quantum transmission, over a staggering distance of 32.5 centimetres” in late October 1989, ten years to the month after the beach. The power supplies for the polarisers made different noises for different settings: “we could literally hear the photons as they flew, and zeroes and ones made different noises. Thus, our prototype was unconditionally secure against any eavesdropper who happened to be deaf!” Experimentalists then took over, and quantum key distribution now runs over tens of kilometres of fibre and is sold commercially.
Teleportation and the Rest
In March 1993, in Physical Review Letters, Bennett, Brassard, Claude Crépeau, Richard Jozsa, Asher Peres and William Wootters showed that an unknown quantum state could be moved from one place to another by sending two classical bits and consuming one entangled pair, and called it quantum teleportation. With Smolin, Wootters, David DiVincenzo and others, Bennett then worked out entanglement distillation (1996), which turns many weakly entangled pairs into fewer good ones, the basis of any quantum repeater; with Brassard and others he proved the first lower bound on quantum search, and developed privacy amplification, the classical post-processing that turns a partly compromised key into a fully secret shorter one. Bennett became an IBM Fellow in 1995 and remains at IBM Research. The wider field they started is in Quantum Computing.
The prizes came together and late: the Wolf Prize in Physics in 2018, the 2023 Breakthrough Prize in Fundamental Physics, the Royal Society for Brassard in 2013 and the Order of Canada the same year. The ACM announced on 18 March 2026 that the two had received the 2025 Turing Award, with its $1 million prize, “for their essential role in establishing the foundations of quantum information science and transforming secure communication and computing.” It was the first Turing Award for quantum information, given forty-two years after the paper and forty-seven after the swim.
Dead End: Secure Against the Deaf
Quantum key distribution is the rare cryptographic idea whose security is a theorem about the world, and it has spent forty years failing to displace the mathematics it was meant to replace. The reasons are practical. It needs a dedicated optical channel, it does not scale to the internet’s topology, its range without trusted relays is limited by fibre loss, and every real device leaks through side channels of exactly the kind the 1989 prototype leaked through its power supply: the theorem is about ideal photons and the attacks are on real detectors. When Shor’s algorithm made the threat concrete, the industry’s response was post-quantum cryptography, new hard problems for ordinary computers, standardised in 2024, rather than new hardware. Bennett and Brassard’s protocol survives as the thing that is sold to governments and banks that want physics on their side, and as the founding document of a field that grew far past its original purpose. The field kept the name they coined on the beach; the world mostly kept its old locks.
📚 Sources
- Gilles Brassard, “Brief History of Quantum Cryptography: A Personal Perspective,” arXiv quant-ph/0604072, 2006 — Wiesner’s rejection, the San Juan beach and all quotations, Crypto ‘82, SIGACT News 1983, the ISIT 1983 talk and Bangalore 1984, the 1989 prototype and the deaf eavesdropper
- Wikipedia: Charles H. Bennett (physicist) — birth, degrees and advisors, IBM 1972, reversible computing, Maxwell’s demon, teleportation, distillation, IBM Fellow 1995, prizes
- Wikipedia: Gilles Brassard — birth, Cornell PhD 1979 under Hopcroft, Montreal, honours
- Wikipedia: BB84 — the 1984 paper, Wiesner’s conjugate coding, the 1989 experiment, the 2014 journal publication
- Bennett & Brassard, “Quantum Cryptography: Public Key Distribution and Coin Tossing,” Theoretical Computer Science 560, December 2014, pp. 7–11 (DOI 10.1016/j.tcs.2014.05.025; reprint of the 1984 Bangalore paper)
- Bennett, Brassard, Crépeau, Jozsa, Peres & Wootters, “Teleporting an Unknown Quantum State via Dual Classical and Einstein-Podolsky-Rosen Channels,” Physical Review Letters 70 (13), 29 March 1993, pp. 1895–1899 (DOI 10.1103/PhysRevLett.70.1895)
- Bennett, “Logical Reversibility of Computation,” IBM Journal of Research and Development 17 (6), November 1973, pp. 525–532 (DOI 10.1147/rd.176.0525)
- Bennett, “The Thermodynamics of Computation: A Review,” International Journal of Theoretical Physics 21 (12), December 1982, pp. 905–940 (DOI 10.1007/BF02084158)
- ACM press release, “ACM A.M. Turing Award Honors Charles H. Bennett and Gilles Brassard for Foundational Contributions to Quantum Information Science,” 18 March 2026 — citation, $1 million, Ioannidis and Dean quotations, biographical notes
- Image: Gilles Brassard (2019).jpg by Lëa-Kim Châteauneuf (CC BY-SA 4.0), via Wikimedia Commons
- Image: Dr. Charles Bennett IBM Fellow.jpg by IBM Research (CC BY-SA 2.0), via Wikimedia Commons