PQC-Enhanced QKD Networks: A Layered Approach

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Spooren, Paul, Neuhold, Andreas, Ramacher, Sebastian, Hühn, Thomas
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914562315386880
author Spooren, Paul
Neuhold, Andreas
Ramacher, Sebastian
Hühn, Thomas
author_facet Spooren, Paul
Neuhold, Andreas
Ramacher, Sebastian
Hühn, Thomas
contents We present a layered and modular network architecture that combines Quantum Key Distribution (QKD) and Post-Quantum Cryptography (PQC) to provide scalable end-to-end security across long distance multi-hop, trusted-node quantum networks. To ensure interoperability and efficient practical deployment, hop-wise tunnels between physically secured nodes are protected by WireGuard with periodically rotated pre-shared keys sourced via the ETSI GS QKD 014 interface. On top, Rosenpass performs a PQC key exchange to establish an end-to-end data channel without modifying deployed QKD devices or network protocols. This dual-layer composition yields post-quantum forward secrecy and authenticity under practical assumptions. We implement the design using open-source components and validate and evaluate it in simulated and lab test-beds. Experiments show uninterrupted operation over multi-hop paths, low resource footprint and fail-safe mechanisms. We further discuss the design's compositional security, wherein the security of each individual component is preserved under their combination and outline migration paths for operators integrating QKD-aware overlays in existing infrastructures.
format Preprint
id arxiv_https___arxiv_org_abs_2604_05599
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle PQC-Enhanced QKD Networks: A Layered Approach
Spooren, Paul
Neuhold, Andreas
Ramacher, Sebastian
Hühn, Thomas
Quantum Physics
Cryptography and Security
We present a layered and modular network architecture that combines Quantum Key Distribution (QKD) and Post-Quantum Cryptography (PQC) to provide scalable end-to-end security across long distance multi-hop, trusted-node quantum networks. To ensure interoperability and efficient practical deployment, hop-wise tunnels between physically secured nodes are protected by WireGuard with periodically rotated pre-shared keys sourced via the ETSI GS QKD 014 interface. On top, Rosenpass performs a PQC key exchange to establish an end-to-end data channel without modifying deployed QKD devices or network protocols. This dual-layer composition yields post-quantum forward secrecy and authenticity under practical assumptions. We implement the design using open-source components and validate and evaluate it in simulated and lab test-beds. Experiments show uninterrupted operation over multi-hop paths, low resource footprint and fail-safe mechanisms. We further discuss the design's compositional security, wherein the security of each individual component is preserved under their combination and outline migration paths for operators integrating QKD-aware overlays in existing infrastructures.
title PQC-Enhanced QKD Networks: A Layered Approach
topic Quantum Physics
Cryptography and Security
url https://arxiv.org/abs/2604.05599