Source-linked AI summary
Long term performance of the SwissQuantum quantum key distribution network in a field environment
D. Stucki, M. Legre, F. Buntschu, B. Clausen, N. Felber, N. Gisin, L. Henzen, P. Junod, G. Litzistorf, P. Monbaron, L. Monat, J. -B. Page, D. Perroud, G. Ribordy, A. Rochas, S. Robyr, J. Tavares, R. Thew, P. Trinkler, S. Ventura, R. Voirol, N. Walenta, H. Zbinden
TL;DR
The paper examines whether QKD can operate reliably and robustly when integrated into telecommunications networks outside the laboratory. It evaluates the SwissQuantum network over more than one and a half years, including its quantum and key-management layers, and reports stable long-term key generation with recovery after externally caused interruptions.
Problem
QKD needs evidence of reliable, robust integration into continuously operating telecommunications networks and production environments.
Method
The SwissQuantum project operated a three-node QKD network with customized commercial plug-and-play QKD servers and a key-management layer aggregating keys across links.
Results
The network generated a quite stable rate of 256-bit keys per day over more than 600 days, with interruptions mainly caused by external problems and recovery when conditions normalized.
Takeaways & Limitations
SwissQuantum demonstrated QKD reliability and robustness in a real-life environment and integration into quite complex network infrastructures.
Takeaways & Limitations
The paper does not consider quantum hacking or implementation-specific security loopholes.
Abstract
from arXiv · showhide
In this paper, we report on the performance of the SwissQuantum quantum key distribution (QKD) network. The network was installed in the Geneva metropolitan area and run for more than one and a half years, from the end of March 2009 to the beginning of January 2011. The main goal of this experiment was to test the reliability of the quantum layer over a long period of time in a production environment. A key management layer has been developed to manage the key between the three nodes of the network. This QKD-secure network was used by end-users through an application layer.
1. Introduction
QKD must demonstrate reliable, robust integration with telecommunications networks to achieve commercial success. Network integration requires adapting point-to-point quantum links to diverse traffic topologies while managing distance, bitrate, infrastructure, and field-condition constraints.
- QKD’s commercial success depends on demonstrating telecommunications-network integration, reliability, and robustness.
- Telecommunications integration must support unicast, multicast, and broadcast traffic despite current QKD links being basically point-to-point.Additional optical components and/or software are required to adapt QKD links to these network topologies.
- Trusted-node networks extend QKD distance but require physically secure intermediate nodes.
- Optical-component QKD networks share infrastructure without trusted nodes, but optical attenuation limits distance and bit rate.
- Reliability is essential because telecommunications networks operate continuously and QKD must not degrade quality of service.Long-term production-environment testing is therefore needed to demonstrate QKD reliability.
- Field handling can add losses, such as more than 10 km equivalent from dirty connectors, sharply reducing or eliminating secret-key generation.Unlike classical communications, QKD cannot regenerate a sufficiently attenuated quantum signal.
2. The SwissQuantum testbed
The SwissQuantum testbed combined three point-to-point QKD links across three nodes with quantum, key management, and application layers. Its design emphasized field deployment, operational reliability, key aggregation, and end-user applications.
- 2.1. Topology: The network comprised three nodes—Unige, CERN, and hepia—and three point-to-point links, with CERN in France and the other nodes in Switzerland.This made SwissQuantum the first international QKD network.
- 2.2. Structure: The SwissQuantum architecture used quantum, key management, and application layers to generate, manage, store, and deliver secret keys.The key management layer connected point-to-point QKD links with end-user applications.
- 2.4. Quantum layer: Each QKD link used commercial ID Quantique id5100 servers in a plug & play configuration that intrinsically compensated phase and polarization fluctuations.The quantum layer generated raw keys, followed by reconciliation, error correction, privacy amplification, and authentication to produce secret keys.
- 2.5. Key management layer: Link aggregation combined multiple QKD connections so applications received matching keys while key-buffer rates summed across links and service could continue if one link failed.The implementation used separate QKD device sets for the aggregated links and did not require active switches.
- 2.6. Application layer: The application layer used conventional network devices and encryptors, while dual-key agreement allowed operation during short periods when the quantum layer generated no keys.Applications requested secret keys from the key server at their local node.
3. Details on the implementation of the key management layer
The SwissQuantum key management layer used node-specific implementations, key servers, application-dedicated buffers, and redundancy mechanisms to support secure links. The CERN–Unige link received preferential treatment through commercial encryption and aggregated key exchange.
- The CERN–Unige link was prioritized using commercial encryption devices and a key-management design intended to reduce availability risks.The design favored this link relative to the other two network links.
- Three nodes used different implementations, with one key server in each node managing secret-key storage and distribution.The network included three quantum key-exchange links and encrypted data connections between CERN–Unige and Unige–hepia.
- Key buffers on the prioritized CERN–Unige link combined keys from the direct QKD link with keys distributed through hepia.This QKD link aggregation scheme provided redundancy through the two other QKD links.
- A key redundancy sender generated a random key and encrypted it with a One-Time Pad using a QKD-exchanged key.
- Before storage, secret keys underwent internal dual-key agreement; PKI-based keys were combined with QKD keys using XOR.The PKI followed X.509 recommendations and used an RSA cryptographic scheme.
4. Long term performance of the quantum layer
The SwissQuantum quantum layer was evaluated using detection probability, QBER, secret-key generation, and optical-path tracking over a 21-month field deployment. Detection probability and QBER remained generally stable, while interruptions were mainly attributed to external conditions and the systems adapted to optical-path variations.
- Performance metrics: The secret key rate was assessed from raw key rate and QBER, with detection probability and QBER recorded as performance indicators.Detection probability gives the per-gate probability of a detector click and is calculated over the time needed to fill the raw-detection buffer.
- Probability of detection: Detection probability remained rather stable over 21 months, with long-term level changes and short-term perturbations identified separately.Initial optimization occurred after about 15 days, while detector-setting changes after a CERN power cut around day 260 especially affected SQ1 and SQ2 mean levels.
- Probability of detection: Short-term detection interruptions or reductions were mainly caused by external problems rather than the quantum layer.Reported events included a software bug, power cuts, and air-conditioning problems affecting individual links.
- Quantum bit error rate: QBER remained low and stable during the 21-month experiment despite statistical and detection-probability fluctuations.QBER was recorded throughout the full experimental period.
- Secret key rate: The number of 256-bit keys generated per day was quite stable for more than 600 days.SQ3 generated more keys per day because its optical attenuation was lower, while SQ1 and SQ2 had similar key-generation rates.
- Variation of the optical fibre length: Optical-path variations required detector activation-time adjustment, and the QKD devices automatically followed these variations.Seasonal optical-length variation reached 6 meters, corresponding to 30 ns in optical fibre, while detection gates were shorter than 2 ns.
5. Performance of the application layer
Application-layer tests evaluated real-data transmission and key changes across commercial encryptors, while Figure 9 tracked long-term optical-path conditions in Geneva.
- Commercial encryptors on the CERN–Unige link worked perfectly throughout the network’s operation while transmitting real data.
- Figure 9 shows optical-fibre-length and temperature variations over 21 months and during a 3-day zoom in Geneva.
- 100 ns was required to change a 256-bit key on the 2 Gbps Fibre Channel encryptors.
6. Conclusion
The SwissQuantum network demonstrated QKD deployment in telecommunications networks, including operation outside the laboratory and integration with complex infrastructures.
- SwissQuantum demonstrated that QKD has the maturity to be deployed in telecommunications networks.
- The network proved QKD reliability and robustness in a real-life environment outside the laboratory.
- A key management layer interfaced the QKD layer with secure applications and ran for more than one and a half years.