Standardization bodies are releasing specifications that will help the adoption of Quantum Key Distribution (QKD) technology. The protocols standardized by the European Telecommunications Standards Institute (ETSI) make it possible to distribute keys to network elements operating at any layer of the protocol stack. On the other hand, the IETF released a standard mechanism to integrate post-quantum keys into IPSec. In this work, we introduce a new mechanism to provide QKD keys to IPSec endpoints. This solution was implemented in the PoliQI network at Politecnico di Milano. We also compare this solution to providing keys to applications with the same security level. We model the system using a Continuous-Time Markov Chain and conclude that the two approaches can secure a similar number of applications. Integration with the applications allows a finer control on whether to block new applications or drop rekeying requests. Integration with IPSec makes it easier to introduce QKD in an existing infrastructure.

Integration of QKD at the Application Layer vs Network Layer: a Markov-Chain Model

Shokrivahed Samin;Verticale Giacomo
In corso di stampa

Abstract

Standardization bodies are releasing specifications that will help the adoption of Quantum Key Distribution (QKD) technology. The protocols standardized by the European Telecommunications Standards Institute (ETSI) make it possible to distribute keys to network elements operating at any layer of the protocol stack. On the other hand, the IETF released a standard mechanism to integrate post-quantum keys into IPSec. In this work, we introduce a new mechanism to provide QKD keys to IPSec endpoints. This solution was implemented in the PoliQI network at Politecnico di Milano. We also compare this solution to providing keys to applications with the same security level. We model the system using a Continuous-Time Markov Chain and conclude that the two approaches can secure a similar number of applications. Integration with the applications allows a finer control on whether to block new applications or drop rekeying requests. Integration with IPSec makes it easier to introduce QKD in an existing infrastructure.
In corso di stampa
2024 IEEE Future Networks World Forum
File in questo prodotto:
File Dimensione Formato  
Samin-Shokrivahed-1571072584.pdf

accesso aperto

: Post-Print (DRAFT o Author’s Accepted Manuscript-AAM)
Dimensione 1.43 MB
Formato Adobe PDF
1.43 MB Adobe PDF Visualizza/Apri

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11311/1284169
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? ND
social impact