Key Management Systems (KMSs) are essential for secure and scalable Quantum Key Distribution (QKD) networks. For successful integration of QKD into existing security protocols, it is crucial that KMSs can reliably deliver keys with sufficiently low latency. Yet, the performance of practical implementations remains insufficiently characterized. We benchmarked the throughput and latency of the key-delivery interfaces of several commercial KMS solutions alongside an in-house developed system. Our evaluation reveals that the KMS performance degrades significantly under high-workload conditions, indicating that current designs require substantial optimization before they can support large-scale, high-demand QKD deployments.
We demonstrate a packaged InP photonic integrated circuit receiver for Ka- and Q/V-band satellite links, achieving up to 14 dB noise-figure reduction via phase modulation and balanced detection, matching electronic RF performance with reduced SWaP.
The convergence of classical and quantum Internet technologies promises to revolutionize communication networks by leveraging the unique properties of quantum mechanics. Already today, several efforts on quantum key distribution, post-quantum cryptography, and systems-on-chip are paving the way for a seamless and secure quantum-classical hybrid Internet. We explore the role of integrated photonics on -chip systems that generate entangled photon pairs, a critical component for quantum communication. We review how integrated photonics and associated techniques can generate and manipulate photon pairs with the prospect of miniaturization and scalability. In addition, we discuss the challenges and solutions in integrating these quantum systems with existing classical Internet infrastructure, highlighting recent advances and future directions.
We present an investigation into the use of reflectometric measurements for characterizing modal dispersion in optical fibers that support space-division multiplexing. A theoretical framework is provided to relate the dispersion characteristics observed in round-trip propagation to those measured in standard forward transmission. The proposed model is experimentally validated using a reflective configuration of an optical vector network analyzer, which enables single-ended access to the fiber. Improved experimental data are obtained with a stabilized laser source, significantly enhancing the signal quality and confirming the theoretical predictions with higher accuracy. In addition, we discuss practical considerations related to system calibration, including the compensation of temporal skew introduced by optical circulators and receiver-side polarization imbalance. The results highlight the potential of reflectometric techniques for accurately characterizing quasi-distributed advanced fiber links.
We present a vendor-agnostic heterogeneous quantum key distribution network based on trusted relay nodes. The network has a logical full-mesh topology, including classical connectivity through encrypted layer 2 tunnels, and was established using commercial equipment and an in-house developed key management system.
Quantum key distribution (QKD) allows the distribution of secret keys for quantum-secure communication between two distant parties, vital in the quantum computing era in order to protect against quantum-enabled attackers. However, overcoming rate-distance limits in QKD and the establishment of quantum key distribution networks necessitate key relaying over trusted nodes. This process may be resource-intensive, consuming a substantial share of the scarce QKD key material to establish end-to-end secret keys. Hence, an efficient scheme for key relaying and the establishment of end-to-end key pools is essential for practical and extended quantum-secured networking. In this paper, we propose and compare two protocols for managing, storing, and distributing secret key material in QKD networks, addressing challenges such as the success rate of key requests, key consumption, and overhead resulting from relaying. We present an innovative, fully decentralized key distribution strategy as an alternative to the traditional hop-by-hop relaying via trusted nodes, where three experiments are considered to evaluate performance metrics under varying key demand. Our results show that the decentralized pre-flooding approach achieves higher success rates as application demands increase. This analysis highlights the strengths of each approach in enhancing QKD network performance, offering valuable insights for developing robust key distribution strategies in different scenarios.
Quantum key distribution (QKD) is experiencing a rapid increase of interest due to its security advantages in the face of quantum computers. However, typical QKD deployments are point-to-point and limited in terms of distance, which significantly restricts their utilization for end-user applications. To overcome these restrictions, trusted relays are adopted as intermediate nodes to allow the transition to QKD networks (QKDNs), where one of the hallmarks is the key management system. In this work, we investigate different key allocation strategies as a method to enhance the performance of key management systems in QKDN from the perspective of key allocation success rate and key delivery delay. We first describe an upgrade model from classical to QKDN at three distinct network layers—quantum, key management, and service. Then, we propose a novel, to our knowledge, key allocation strategy leveraging the benefits of key storage and relaying as a solution to improve the QKDN performance. To achieve this, our method makes use of end-to-end virtual quantum key pools (VQKPs) implemented between non-adjacent nodes requesting key material. We introduce static and dynamic upper and lower threshold limits at the VQKP level, with the dynamic thresholds adapted according to application demand, to control the key distribution in the network and fill the pools ahead of end-user requests. We demonstrate through simulations that the introduction of thresholds achieves performance enhancement and explain the trade-off between the key allocation success rate and key delivery delay evaluation metrics in comparison with different on-demand key allocation strategies.
High-throughput satellites with large-scale mmwave antenna arrays face increased SWaP from RF frontends and coaxial RF signal transport to/from the processing core. We review photonic RF frontend architectures alleviating these issues, show experimental performance evaluations, and discuss their implementation with integrated photonics.
The rapid advances in quantum computing pressure the existing essential cryptographic algorithms. In this context, Quantum Key Distribution (QKD) has been proposed as a quantum safe solution for key distribution. However, current QKD systems require an authenticated classical channel which relies on pre-shared symmetric keys that are manually distributed and do not guarantee the identity of the hardware that hosts them. This paper proposes a novel scheme, the Physically Unclonable Quantum Key Distribution (PU-QKD) system, to intrinsically authenticate the communicating endpoints in QKD. The PU-QKD scheme leverages classical Physical Unclonable Functions (PUFs) to encode the data transmission in discrete variable QKD protocols (e.g., BB84). Our scheme maintains the information-theoretic security of QKD protocols by integrating the PUF as an additional layer. Authentication is bound to hardware, providing a robust fingerprint, while lower post-processing overhead increases key rates. Additionally, the proposed scheme is resilient against state-of-the-art PUF vulnerabilities, such as modeling attacks.
We demonstrate the first D PU-based triple-hybrid IPsec tunnel that simultaneously integrates classical and post-quantum cryptography, and quantum key distribution, providing accelerated quantum-resistant communications operating at 91.1 Gbit/s line rate.
Quantum Key Distribution (QKD) is currently being discussed as a technology to safeguard communication in a future where quantum computers compromise traditional public-key cryptosystems. In this paper, we conduct a comprehensive security evaluation of QKD-based solutions, focusing on real-world use cases sourced from academic literature and industry reports. We analyze these use cases, assess their security and identify the possible advantages of deploying QKD-based solutions. We further compare QKD-based solutions with Post-Quantum Cryptography (PQC), the alternative approach to achieving security when quantum computers compromise traditional public-key cryptosystems, evaluating their respective suitability for each scenario. Based on this comparative analysis, we critically discuss and comment on which use cases QKD is suited for, considering factors such as implementation complexity, scalability, and long-term security. Our findings contribute to a better understanding of the role QKD could play in future cryptographic infrastructures and offer guidance to decision-makers considering the deployment of QKD.
The emergence of quantum computing poses a threat to classical cryptography algorithms, necessitating a shift to quantum secure cryptography. Hybrid protocols combining at least one classical and one quantum-resistant cryptographic algorithm are becoming the standard for securing communications. In this work, we present our novel solution for integrating three different cryptographic assumptions (two of them quantumresistant) into hybrid network security protocols, ensuring that three different cryptographic assumptions must be broken before the protocol becomes vulnerable. Our solution allows for a seamless integration of classical and post-quantum (PQ) cryptography, and quantum key distribution (QKD) into existing network security protocols (e.g., TLS, IPsec) without any major modifications to the protocols themselves. This crypto-agility ensures the mitigation of some of the most well known challenges of both PQ cryptography and QKD. Our findings demonstrate the feasibility of such triple-hybrid network security protocols, showing non-substantial decrease in performance and almost no added packet overhead compared to state of the art protocols. In exchange, we pave the way towards next generation networks where the potential of new quantum-resistant cryptographic schemes can be leveraged in a dynamic and agile fashion, thus fostering a new era of unbreakable communication systems.
Resource allocation in QKD networks becomes challenging once key consumption rates reach key generation, at least on certain network links. We present different allocation strategies to improve key assignment success rate and key delivery delay.
Several photonic RF receiver front-end architectures for satellite payloads are investigated, comparing the key characteristics and RF performance of intensity- and phase-modulated links with single and balanced photodetection. The analysis focuses on conversion gain and noise figure as primary metrics, demonstrating, for example, that gains on the order of -12 dB and noise figures of 23 dB can be achieved under typical operating conditions with received optical powers of 10 dBm at V-pi =4V. The simulation model is validated through experiments, showing strong agreement with measured results. The influence of modulator V-pi on system performance is explored, identifying achievable performances and technology trade-offs. These findings offer insights into optimizing photonic RF front-ends for space applications, guiding the selection of modulator technology to improve RF performance.
We study the placement of trusted relay nodes (TRNs) when upgrading a network with quantum key distribution. Taking equal spacing of TRNs as first approximation, we analyze varios topologies and estimate the required TRNs.
Comprehensive component characterization is essential to unlocking the full potential of fiber systems in multiple divisions of space, providing insights into performance limitations and driving their development and deployment in real-world applications. Space-division multiplexing (SDM) systems require characterization tools capable of simultaneously measuring the properties of all modes and cores to evaluate impairments and understand interactions. The optical vector network analyzer (OVNA) fully characterizes all linear parameters of such fibers over a broad wavelength range in a single fast scan. However, characterizing kilometer-scale fibers necessitates path-length matching between the reference and measurement arms by adding a reference fiber to maintain coherence, allowing low-speed photo-detectors and digitizers to be used. Wavelength-dependent polarization rotation in the reference fiber results in fading in the captured interference pattern when the signals are recombined, severely distorting the measurements and the derived linear parameters of the device-under-test (DUT), such as insertion loss (IL). In this work, we investigate the impact of polarization-induced fading and present two optimized OVNA configurations incorporating automatic polarization control and Faraday rotator mirror techniques to mitigate fading by stabilizing the reference arm polarization across the sweep range. These methods are validated by characterizing a 10 km, 7-core uncoupled multi-core fiber, demonstrating their effectiveness in suppressing fading and eliminating distortions in IL measurements. This results in a more accurate measurement of the true fiber characteristics.
We demonstrate a 40Gbit/s PAM4 signal transmission through 10km SMF enabled by means of optical injection-locking of DML. Link performance was analyzed for various injected powers and master laser frequency offsets. We demonstrated improvement of BER for lower injection powers.
We present an experimental quantum-resistant OpenSSL-based TLS 1.3 implementation using classical cryptography and QKD. This solution is ideal for high-performance scenarios with optical fiber communication where QKD potential can be leveraged.
A new innovative Edge Micro Data Centre and its new passive two-phase cooling system are presented here. EMDC's are hyperconverged heterogenous hardware capacities ranging from 1.8kW up to 500kW. HIRO, providing Powerfull Edge as a Service (PEaaS) is seeking very high cooling energy efficiency (PUE approaching 1.0) and solutions to re-use waste heat from their locally installed EMDC's and edge services that are supporting the big data processing and AI of their customers (smart hospitals, Industry 4.0, 5G/6G MEC, smart cities, smart energy grids). The smallest EMDC with 11 nodes (8 processing and acceleration, 1 ethernet switch, 1 PCIe switch and DC power) is used in the test setup. The gravity-driven loop thermosyphon cooling system is composed of a compact monoblock for insertion and cooling of 11 EDMC nodes, a riser and downcomer and a compact aircoil condenser cooled by several fans (or by natural convection). The heat of the EDMC nodes is removed by 11 thermal bridges in the monoblock evaporator. In demonstration “stress” tests run at TUe in The Netherlands, monitoring all individual node temperatures and energy consumptions, the cooling system achieved very high cooling performance during all the tests. Defining the PUE here to be equal to the total energy consumption including fans divided by that of only the computer itself, at maximum heat load the PUE was only 1.034 while at medium heat loads using lower fan speeds values as low as 1.007 were recorded and at heat loads of 186 W and below, the fans could be turned off for completely passive cooling operation. The IP of this thermosyphon cooling for EMDC's is property of JJ Cooling and HIRO and is subject to further research. HIRO market launch of their first product line of EMDC's is planned for Q3 2024.