arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

一种可扩展的、云编排且面向服务的集成量子后密码学的多域量子密钥分发网络

A Scalable Cloud-Orchestrated and Service-Oriented Multi-Domain QKD Network with PQC Integration

Konstantinos Krilakis, Antonia Tsili, Aikaterini Mandilara, Dimitris Syvridis

arXiv 2607.12765首次发表:更新:

AI 中文总结

针对现有QKD网络难跨异构设施和管理域扩展的问题,提出集成QKD、SDN编排和云管理信任服务的多域网络架构,基于PQC签名和密钥封装算法构建认证机制,实验验证其有效性,扩展了量子安全密钥传输边界。

AI 中文摘要

量子密钥分发(QKD)提供无条件安全性,但由于特定供应商接口、可信节点约束和有限的互操作性,现有QKD网络难以在异构基础设施和管理域中扩展。本文提出一种灵活的多域多站点量子安全网络架构,集成了与供应商无关的QKD、软件定义网络(SDN)编排和云管理信任服务。通信基于零信任网络访问协议,具有基于量子后密码学(PQC)签名和密钥封装算法的多级认证机制。该系统部署在包含来自3个供应商QKD节点的真实测试平台以及没有QKD基础设施元素的域上。实验结果表明,即使在受限设备上,PQC和SDN开销仍相对较低,主要瓶颈在于QKD密钥检索和特定供应商的密钥流限制。所提出的框架扩展了量子安全密钥传输,超越了原生QKD边界,同时保持了灵活性、互操作性以及与现有基础设施的兼容性。

英文摘要

Quantum key distribution (QKD) offers unconditional security but existing QKD networks remain difficult to scale across heterogeneous infrastructures and administrative domains due to vendor-specific interfaces, trusted-node constraints, and limited interoperability. This work presents a flexible multi-domain and multi-site quantum-secure network architecture integrating vendor-agnostic QKD, SDN orchestration, and cloud-managed trust services. Communication is based on Zero Trust Network Access protocols featuring multi-level authentication mechanisms building upon post-quantum cryptography (PQC) signature and key encapsulation algorithms. The system is deployed on a real-world testbed with domains incorporating QKD nodes from 3 vendors, as well as domains without QKD infrastructure elements. Experimental results show that PQC and SDN overhead remain relatively low even on constrained devices, with the main bottleneck being QKD key retrieval and vendor-specific key streaming limitations. The proposed framework extends quantum-safe key transport beyond native QKD boundaries while preserving flexibility, interoperability, and compatibility with existing infrastructures.

Comments18 pages, 15 figures

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑