Семинар на тема "QKD Network Architectures and Standardization of Quantum Communication"

На 16.09.2026 г. (сряда) от 14:00 ч. в зала 300 на ИЯИЯЕ, ще се проведе семинар на тема:

"QKD Network Architectures and Standardization of Quantum Communication"

от Момчил Пеев, представител на "Huawei Germany".

Резюме:

We present a novel three-segment architecture for quantum key distribution (QKD) networks, comprising a Key Distribution Plane (Segment 1), a Control Plane (Segment 2), and a Key Provision Plane (Segment 3). Segment 1 operates with ε-secure, composable mechanisms—information-theoretically (IT) authenticated key forwarding via one-time pad (XOR) encryption with Wegman–Carter message authentication codes (MACs). Segments 2 and 3, which lack an internal quantum key source, rely on computationally secure proto-cols, creating a fundamental security mismatch. Segment 2 is decomposed into an automatic control subsegment (2a) and a policy/operator subsegment (2b), reflecting the distinction between real-time routing and topology-switching decisions and strategic operator overrides. Segment 3 is decomposed into a key-holding and delivery subsegment (3a) and an application and account management subsegment (3b), separating key-material handling from metadata-only operations. Two forwarding regimes are presented: hop-by-hop Information.

Theoretically Secure (ITS) encryption (Regime 1) and XOR-based forwarding (Regime 2). Regime 2 is further decomposed into standard XOR forwarding (Regime 2a) and per-hop authenticated forwarding (Regime 2b), with distinct trust models and authentication requirements. We analyse the security mismatch, enumerate threat scenarios, and propose mitigations ensuring that compromise of the computationally secure segments can cause denial of service but never key disclosure. A composable security bound is stated. We address the critical distinction between physical hardening and logical isolation: a compromised Segment 3 connected to the external world can serve as a backdoor into a physically hardened Segment 1 unless the S1→S3 interface is a unidirectional security boundary—key material flows from Segment 1 to Segment 3, but no data of any kind flows back. The key-store architecture partitions Segment 1's persistent store into four pools by purpose (forwarding encryption, authentication, application supply, verification), plus a separate Bootstrap Store with two filling options (ITS/organizational, including an ITS Kerberos method, or PQC), and a per-node source of unpredictable randomness (QRNG) that supplements QKD-derived payload. We note the important caveat that real-world QKD and QRNG implementations may not achieve information-theoretic security in practice, and include a QRNG-specific term in the composable bound.

We extend the three-segment QKD architecture—comprising key distribution (S1), control (S2), and key provisioning (S3)—from a single-network setting to the interconnection of independently operated QKD networks. Current standards (ETSI GS QKD 020, the ITU-T Y.3800 series including Y.3810, Y.3813, Y.3818, and Y.3820) address boundary links, functional architectures, and inter-domain control but bundle key material, control metadata, and service provisioning into monolithic interfaces without segment-level security delineation.

We propose a segment-to-segment peering model—S1-to-S1 at the quantum boundary, S2-to-S2 for control-plane peering, S3-to-S3 for service handoff—with three distinct trust models at three distinct interfaces. We show that the composable security bound of the single-network architecture extends to the multi-network case with one additional term εorg capturing organizational boundary risk, that XOR-based forwarding (Regime 2, decomposed into standard XOR forwarding (2a) and per-hop authenticated forwarding (2b)) is preferred at inter-network boundaries because Kglobal never traverses any channel in plaintext, and that the one-way degradation principle is preserved: compromise of computational peering segments degrades to denial of service, never to key disclosure.

The present work is intended as a blueprint for a QKD network architecture, currently developed in ETSI ISG QKD under Work Item WI-022. Generically, it is a part of an overall effort to standardize QKD and Quantum Communication at large and certify those aspects that are security relevant. We give an overview of today's standardization efforts and the now being developed CEN/CENELEC Roadmap (on Quantum Technology at large and Quantum Communication specifically). Further we address the distribution of the world-wide effort in the field and try to link it to on-going research, technology and demonstration advances.