Hybrid Quantum Security for IPsec
Javier Blanco-Romero, Pedro Otero Garc\'ia, Daniel Sobral-Blanco, Florina Almenares Mendoza, Ana Fern\'andez Vilas, Manuel Fern\'andez-Veiga

TL;DR
This paper compares sequential and parallel hybrid QKD-PQC key establishment strategies for IPsec, introducing two novel approaches that improve performance and security integration of quantum key distribution into existing protocols.
Contribution
It presents the first systematic comparison of hybrid QKD-PQC strategies for IPsec and introduces two new methods supporting existing QKD standards with enhanced performance.
Findings
Parallel hybrid approaches reduce latency compared to sequential methods.
Pure QKD approach minimizes bandwidth overhead with identifier-based key coordination.
Experimental results show significant performance gains in realistic network conditions.
Abstract
Quantum Key Distribution (QKD) offers information-theoretic security against quantum computing threats, but integrating QKD into existing security protocols remains an unsolved challenge due to fundamental mismatches between pre-distributed quantum keys and computational key exchange paradigms. This paper presents the first systematic comparison of sequential versus parallel hybrid QKD-PQC key establishment strategies for IPsec, revealing fundamental protocol design principles that extend beyond specific implementations. We introduce two novel approaches for incorporating QKD into Internet Key Exchange version 2 (IKEv2) with support for both ETSI GS QKD 004 stateful and ETSI GS QKD 014 stateless API specifications: (1) a pure QKD approach that replaces computational key derivation with identifier-based quantum key coordination, and (2) a unified QKD-KEM abstraction that enables parallel…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
