Network Working Group M. Stiemerling Internet-Draft F. Seidl Intended status: Informational M. Bauch Expires: 24 April 2025 N. Schark J. Henrich Darmstadt University of Applied Sciences 21 October 2024 Initial Considerations about QDKN Protocols draft-danet-qkdn-considerations-00 Abstract Quantum communication modules connected via a link, either via fiber or free-space communications, have been used since a while to distribute random numbers as secure keys, but there are other use cases, such as time synchronization. By today, a number of research and industrial efforts are underway to built complete networks, primary for secure key distribution, i.e., so-called Quantum Key Distribution Networks (QKDN). This memo briefly explores the space of QKDNs and identifies spots of potentials interest to develop standardized protocols specific for such networks. Table of Contents 1. Introduction . . . . . . . . . . . . . . . . . . . . . . . . 2 2. Simplified Architecture . . . . . . . . . . . . . . . . . . . 2 3. Conclusion . . . . . . . . . . . . . . . . . . . . . . . . . 4 4. IANA Considerations . . . . . . . . . . . . . . . . . . . . . 4 5. Security Considerations . . . . . . . . . . . . . . . . . . . 4 6. Informative References . . . . . . . . . . . . . . . . . . . 4 Acknowledgements . . . . . . . . . . . . . . . . . . . . . . . . 4 Authors' Addresses . . . . . . . . . . . . . . . . . . . . . . . 4 Introduction Quantum communication modules connected via a link, either via fiber or free-space communications, have been used since a while [darpa-qkd] to distribute random numbers as secure keys, but there also other use cases, such as time synchronization. By today, a number of research and industrial efforts are underway to built complete networks, primary for secure key distribution, i.e., so-called Quantum Key Distribution Networks (QKDN) (see [qkd-overview] as one overview). Quantum Links (QL) are quite limited in their distance between two adjacent Quantum Communication Modules (QCM), e.g., around 100 km distance or even below. To overcome this limitation, multiple segments of Quantum Links are concatenated. This concatenation typically requires an extra level of functionality, i.e., the use of Key Management Systems (KMS). This memo briefly explores the space of QKDNs and identifies spots of potentials interest to develop standardized protocols specific for such networks. 2. Simplified Architecture The ITU defines an extensive QKDN architecture in Y.3802 [itu-y-3802]. However, for our discussion we use a simplified architecture here. Stiemerling, et al. Expires 24 April 2025 [Page 2] Internet-Draft InitConQKDNProto October 2024 The Figure below shows a simplified architecture for a single QKDN domain. The Quantum Communication Modules (QCM) are in charge of exchanging random numbers between 2 QCM, or n modules for single-source entangled based systems. The Key Management Systems (KMS) are in charge of allowing a secure end-to-end relay of a secret across the whole domain. They obtain the encryption keys, or some initial input to the encryption key, from their local KMS. The Network Controller (NW cntrl) can be used to control and managed the operations of the KMS and also the QCM. (d) +-------------+ (d) +----------| NW cntrl |----------+ | +-------------+ | | | (d) | v v v +-----+ (a) +-------------+ (a) +-----+ | KMS |<----->| KMS |<----->| KMS | +-----+ +-------------+ +-----+ ^ ^ ^ ^ | (b) | (b) | | (b) v v v v +-----+ (c) +-----+ +-----+ (c) +-----+ | QCM |<----->| QCM | | QCM |<----->| QCM | +-----+ +-----+ +-----+ +-----+ Figure 1: A simplified single Domain QKDN Architecture The interfaces between the components are: * (a) KMS-to-KMS interface: this interface is used to facilitate the secure key forwarding between the KMS * (b) KMS-to-QCM interface: this interface is used by the KMS to obtain the generated random numbers from the QCM * (c) QCM-to-QCM interface: this interface is used between adjacent Quantum Communication Modules and consists actually out of two interfaces, i.e., the quantum link and the classical channel. * (d) Network Controller to KMS interface: This interface, if a controller-based approach is used, controls the operation of the KMS. 3. Conclusion This document does not yet have a conclusion, at it is a first attempt to gather information about protocols for QDKNS. 6. Informative References [darpa-qkd] Elliott, C. and H. Yeh, "DARPA Quantum Network Testbed", July 2007, . [itu-y-3802] ITU-T, "Quantum key distribution networks – Functional architecture", December 2020, . [qkd-overview] Liu, R., "Towards the industrialisation of quantum key distribution in communication networks: A short survey", September 2022, . 