Hybrid quantum and post-quantum key networks emulated with cloud scaling
Hybrid QKD-PQC Network Emulation through Automated and Scalable Cloud-Native Orchestration
Networking and Internet ArchitectureCryptography and Security
Summary
Secure communication needs to prepare for quantum computers that could break current encryption. The authors offer a new way to test combined quantum key distribution (QKD) and post-quantum cryptography (PQC) networks without expensive quantum hardware. They extended an existing platform called Quditto to automatically create and run these complex networks in the cloud at large scales. Their system also safely manages keys and successfully showed secure key exchanges on a sample network. This makes it easier to study and improve future quantum-safe communication systems.
What this means in practice
- •For network engineers: Test large-scale hybrid quantum-safe key networks before physical deployment using automated cloud emulation.
- •For cybersecurity platform developers: Integrate quantum-safe key management and hybrid QKD-PQC protocols into security products via scalable emulated networks.
Authors
Iván Melijosa, Javier Pérez, Borja Nogales, Iván Vidal, Francisco Valera
Abstract
The ongoing transition toward quantum-safe networking has motivated the development of hybrid network architectures integrating Quantum Key Distribution (QKD) and Post-Quantum Cryptography (PQC). However, the experimental evaluation of hybrid QKD-PQC network architectures remains constrained by the high cost and limited accessibility of quantum hardware, as well as by the limited support for hybrid QKD-PQC networks in existing emulation platforms. Quditto is an open-source emulation platform originally designed for QKD networks that enables cost-effective and reproducible experimentation without requiring dedicated physical quantum infrastructure. Building on this foundation, this work presents Quditto as a hybrid QKD-PQC network emulation platform featuring automated and scalable cloud-native orchestration. The proposed platform introduces four principal contributions: a cloud-native orchestrator enabling fully automated infrastructure deployment across cloud and multi-cluster environments; an optimized provisioning workflow enabling large-scale quantum-safe network emulation; native integration of post-quantum nodes enabling unified emulation of hybrid QKD-PQC networks; and a secure key management module providing persistent and access-controlled storage of cryptographic material. Experimental validation demonstrates sublinear orchestration-time scaling with network size and successful end-to-end hybrid QKD-PQC key establishment on a representative spine-leaf deployment, thereby enabling the systematic evaluation of quantum-safe networking mechanisms in large-scale heterogeneous network environments.