Paper 2025/1177
HY-QSN: HYbrid Quantum Safe Networks
Abstract
A Quantum-Safe Network (QSN) enables secure quantum key exchange between consumers through interconnected Quantum Key Distribution (QKD) devices, overcoming the physical limitations of individual QKD systems. Critical sectors including telecommunications, defense, and finance access quantum-distributed keys via Quantum Key-as-a-Service (QKaaS) models. Current QKaaS implementations require both consumers to deploy QKD devices on their premises before establishing keys, creating cost and feasibility barriers that may limit adoption. While ETSI's GS QKD 014 standard defines APIs for QKD key retrieval, it does not address this deployment constraint. We identify this gap and propose a gateway-based solution that secures QKaaS models using Post-Quantum Cryptography (PQC). Our gateway transparently applies PQC-based signatures and key encapsulation mechanisms to ETSI-compliant QKD APIs without requiring infrastructure modifications. The solution supports cryptographic agility, enabling runtime switching between multiple PQC schemes. We validate our approach using both simulated QKD environments and production-grade hardware, demonstrating minimal overhead of 1.3x-1.5x compared to baseline performance. The solution scales effectively to production frameworks, successfully managing concurrent connections across multiple consumer sites.
Metadata
- Available format(s)
-
PDF
- Category
- Applications
- Publication info
- Preprint.
- Keywords
- Quantum Key DistributionPost-Quantum CryptographyCryptographic AgilityQuantum-Safe Proxies
- Contact author(s)
-
sayan005 @ e ntu edu sg
aarav varshney @ ntu edu sg
prasanna ravi @ ntu edu sg
anupam @ ntu edu sg - History
- 2025-08-27: last of 2 revisions
- 2025-06-23: received
- See all versions
- Short URL
- https://ia.cr/2025/1177
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/1177,
author = {Sayan Das and Aarav Varshney and Prasanna Ravi and Anupam Chattopadhyay},
title = {{HY}-{QSN}: {HYbrid} Quantum Safe Networks},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/1177},
year = {2025},
url = {https://eprint.iacr.org/2025/1177}
}