T1#award#research#security
A Turing Award for Quantum Information Science — Bennett and Brassard Win for 2025

Metadata
- Date
- Decade
- 2020s
- Tier
- T1
- Sources
- 07
- Connections
- 05
- Tags
- #award#research#security
On 18 March 2026, ACM named Charles H. Bennett of IBM Research and Gilles Brassard of the Université de Montréal as recipients of the 2025 A.M. Turing Award.
The two years in that sentence are not a mistake. The Turing Award carries the year it is awarded for, and the recipients are announced the following spring — so the 2025 award was announced on 18 March 2026. Headlines used both numbers, sometimes in the same paragraph. This site places award events on the announcement date, as it does for the Nobel Prizes.
The citation: for their essential role in establishing the foundations of quantum information science and transforming secure communication and computing. The prize is US$1 million, financially supported by Google. IBM, in its own announcement, called the 2025 award ACM's first associated with quantum research.
What BB84 Actually Changed
The paper at the centre of the citation is "Quantum Cryptography: Public Key Distribution and Coin Tossing", presented in December 1984 at a conference in Bangalore and known ever since by the authors' initials and the year: BB84. ACM's release is careful to name a third figure — the protocol was introduced, it says, "inspired by the insights of their late collaborator Stephen Wiesner". Wiesner had devised a concept of uncounterfeitable quantum money in 1968 and, by IBM's account, struggled to get the idea academically accepted; Bennett helped him advance it.
The release then does something unusual for an award announcement: it builds an argument. Claude Shannon proved in 1949 that perfect secrecy requires the two parties to share, in advance, a secret key at least as long as the message. Public-key cryptography supplied a powerful way around that requirement — but it bought its way around by resting on mathematical problems believed to be hard. In 1994 Peter Shor showed that this belief expires the moment a full-scale quantum computer exists.
BB84 does not make the assumption in the first place. Its security rests on a physical fact about quantum information: it cannot be copied or measured without disturbance. Eavesdropping therefore leaves detectable traces before any information is compromised. That guarantee holds against an adversary with unlimited computational power, quantum computer included. Cryptographers call this information-theoretic security, and it is a different order of claim from the working assurance that nobody has yet found an efficient factoring algorithm.
It is worth noting what else was in that 1984 paper, because the title gives it away and almost nobody quotes it: "Public Key Distribution and Coin Tossing". The second half proposed a quantum protocol for two mutually distrustful parties to flip a fair coin remotely, and the authors themselves observed that while it resisted conventional cheating, it could be subverted by a subtler quantum effect — the Einstein–Podolsky–Rosen correlations. Nine years later the same correlations became the mechanism of quantum teleportation. The awkward loose end in one paper turned into the resource of the next, which is a fair description of how the whole field developed.
The key distribution idea did not stay on paper either. Variants of BB84 now run in operational quantum communication networks, over fibre on the ground and over free space via satellite.
A Two-Metre Apparatus in an Office
The first physical demonstration of BB84 happened in 1989, and IBM's account of it is worth keeping. Bennett and a summer student named John Smolin — now an IBM researcher himself — built the first quantum cryptography apparatus in Bennett's office out of mirrors, polarisers and photon detectors. The device was about two metres long. Brassard and his students wrote the software that drove it, and Brassard joined them for the demonstration.
The collaboration itself began a decade earlier. Bennett and Brassard met at a computer science conference in Puerto Rico in 1979, shortly after Brassard's doctorate. By 1982 they had co-authored a first-of-its-kind quantum cryptography paper with Wiesner. BB84 followed two years after that.
Teleportation, and Making Entanglement Usable
The citation is not only about cryptography.
In 1993, with other collaborators, Bennett and Brassard introduced quantum teleportation: a procedure for transmitting an arbitrary, unknown quantum state between distant parties using entanglement plus ordinary classical communication. ACM's framing is that this moved entanglement from something regarded mainly as a philosophical curiosity into a practical resource. Experimental verification of related phenomena took the 2022 Nobel Prize in Physics.
In 1996 came entanglement distillation — a method for taking imperfect, noisy entanglement and concentrating it into high-quality entanglement. Without something of this kind there is no long-distance quantum communication, because entanglement degrades over distance. Distillation, teleportation and entanglement swapping are now standard components of quantum repeater designs and of the long-run project usually called the quantum internet.
ACM summarises four decades of the partnership as having bridged physics and computer science, with consequences reaching beyond cryptography into algorithm design, computational complexity, learning theory, interactive proofs and mathematical physics.
The Two Laureates
Charles H. Bennett took his bachelor's degree at Brandeis and his PhD at Harvard, and has been at IBM Research since the early 1970s. (ACM says he joined in 1973; the caption IBM Research itself attached to his portrait says 1972. The sources differ by a year.) He was recruited by Rolf Landauer, whose work on the thermodynamics of computation argued that information is a physical quantity rather than an abstraction — the premise Bennett spent a career developing. His 1973 paper on the logical reversibility of computation showed that computing need not be inherently dissipative. He holds the Wolf Prize in Physics, the Micius Quantum Prize, the BBVA Foundation Frontiers of Knowledge Award and the Breakthrough Prize in Fundamental Physics, and is a member of the US National Academy of Sciences and a foreign member of the Royal Society. IBM says he intends to donate part of his share of the prize. He is the seventh IBM laureate of the Turing Award, after Backus, Iverson, Codd, Cocke, Brooks and Allen.
Gilles Brassard earned his bachelor's and master's degrees at the Université de Montréal and his PhD in theoretical computer science at Cornell in 1979, supervised by John E. Hopcroft, himself a Turing laureate in 1986. He returned to Montréal almost immediately afterwards and held a Canada Research Chair from 2001 to 2021. He is an Officer of the Order of Canada and of the Ordre national du Québec, a Fellow of the Royal Society and an international member of the US National Academy of Sciences. His university notes that he is only the eighth Canadian to win the award since it began in 1966, and its second laureate after Yoshua Bengio in 2018.
The Argument the Award Walked Into
The award landed just after the United Nations designated 2025 the International Year of Quantum Science and Technology, and in the middle of a live policy question about what actually replaces today's public-key infrastructure.
ACM president Yannis Ioannidis, in the release: "Bennett and Brassard fundamentally changed our understanding of information itself. Their insights expanded the boundaries of computing and set in motion decades of discovery across disciplines."
Brassard's own reaction, given to his university, was closer to a warning than a victory lap. He said it was necessary to wake up and stop relying solely on an obsolete cryptographic infrastructure that is supposed to protect us but that, since 1994, we have known will collapse as soon as a full-power quantum computer is available.
There is a real tension underneath that. The migration actually happening at scale is not to quantum key distribution but to post-quantum cryptography: classical algorithms chosen because no efficient quantum attack is known against them. ACM's release makes the contrast pointedly, describing those classical approaches as "hopefully quantum-resistant" and noting that "no proofs of security are known" for them, while BB84 achieves information-theoretic security without computational assumptions. Whether QKD's physical guarantee is worth its cost in dedicated hardware and trusted nodes, against post-quantum algorithms that drop into existing infrastructure, is unsettled and being decided by procurement offices rather than by proof.
That a protocol from 1984 is still a live party to that argument is, in the end, the clearest statement of why it was worth a Turing Award.
Sources
TertiaryGilles Brassard — Wikipedia
Last updated: