Search arXiv⌕ Search

arXiv · 2609.35358

Hybrid QKD-PQC Network Emulation through Automated and Scalable Cloud-Native Orchestration

Abstract

The ongoing transition toward quantum-safe networking has motivated the development of hybrid network architectures integrating Quantum Key Distribution (QKD) and Post-Quantum Cryptography (PQC). However, the experimental evaluation of hybrid QKD-PQC network architectures remains constrained by the high cost and limited accessibility of quantum hardware, as well as by the limited support for hybrid QKD-PQC networks in existing emulation platforms. Quditto is an open-source emulation platform originally designed for QKD networks that enables cost-effective and reproducible experimentation without requiring dedicated physical quantum infrastructure. Building on this foundation, this work presents Quditto as a hybrid QKD-PQC network emulation platform featuring automated and scalable cloud-native orchestration. The proposed platform introduces four principal contributions: a cloud-native orchestrator enabling fully automated infrastructure deployment across cloud and multi-cluster environments; an optimized provisioning workflow enabling large-scale quantum-safe network emulation; native integration of post-quantum nodes enabling unified emulation of hybrid QKD-PQC networks; and a secure key management module providing persistent and access-controlled storage of cryptographic material. Experimental validation demonstrates sublinear orchestration-time scaling with network size and successful end-to-end hybrid QKD-PQC key establishment on a representative spine-leaf deployment, thereby enabling the systematic evaluation of quantum-safe networking mechanisms in large-scale heterogeneous network environments.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Iván Melijosa, Javier Pérez, Borja Nogales, Iván Vidal, Francisco Valera. 2026-09-28. Hybrid QKD-PQC Network Emulation through Automated and Scalable Cloud-Native Orchestration. https://arxiv.org/abs/2609.35358

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Can LLMs help find Ambiguities in Protocol Specifications?

Internet protocol specifications written in RFCs are subject to ambiguities and multiple interpretations that can cause interoperability failure. While these have presumably cleared up after years of experience, such ambiguities can bedevil the adoption of newer protocols like 5G. The 5G specifications pair a formal message syntax (ASN.1) with message-handling procedures written in natural language. This creates semantic underspecification: a syntactically valid message can reach a state whose procedures never say how to handle it, so standard-compliant implementations diverge. We frame this as a gap or a fork in a partially specified communicating state machine, and present SpecLens, which puts that view in front of a language model as a scaffold. Stronger models do not remove the need for it: they broaden the search without disciplining it, and fewer than half their findings survive inspection. Across 36 procedures from six 3GPP and O-RAN protocols, experts accept 185 of 197 SpecLens findings, and 60 drive observable divergence between the OpenAirInterface and srsRAN implementations under differential test. While we use 5G as a canonical example of a newer protocol, we also show ambiguity results for the more mature DNS protocol.

cs.NI↗

SHORTCUT: In-Collective Topology Reconfiguration for Low-Latency AllReduce

Distributed ML training relies on efficient AllReduce communication to aggregate data across nodes. In this setting, reconfigurable optical interconnects offer high-bandwidth, energy-efficient direct links between accelerators but often produce ring-based topologies that remain static during a collective. The Ring AllReduce algorithm naturally matches these topologies but its cumulative latency grows linearly with node count. Low-latency algorithms such as Recursive Doubling (RD) instead achieve logarithmic cumulative per-step latency, but their long-distance exchanges incur dilation and congestion costs on a static ring. In-collective topology reconfiguration can eliminate these penalties but each topology change adds reconfiguration delay. The key question to improve AllReduce completion time is therefore not only how to reconfigure RD efficiently, but when selectively reconfigured RD becomes faster than the topology-matched Ring algorithm. We present Shortcut: an effective strategy for topology reconfiguration that enables RD to shortcut costly multi-hop communication only when it pays off - beyond the performance of the Ring algorithm. Across small and medium messages on 32 nodes, Shortcut achieves $4.4\times$-$6.0\times$ speedups over Ring. At 128 nodes, it remains up to $7\times$ faster with a $10\,μs$ reconfiguration delay, showing that selective reconfiguration is especially effective in latency-sensitive, large-scale settings.

cs.NI↗

Enhancing BGP Security by Understanding BGP's Language with LLMs

The trust-based nature of Border Gateway Protocol (BGP) makes it vulnerable to prefix hijacking and misconfigurations. Traditional BGP anomaly detection relies on manual inspection with poor scalability, while Machine/Deep Learning (M/DL)-based approaches suffer from suboptimal precision, limited generalizability, and high retraining cost. This is because existing M/DL methods focus on topological structures rather than semantic characteristics of Autonomous Systems (ASes), assigning dissimilar embeddings to functionally similar but topologically distant ASes. To address this, we propose BGPShield, a novel anomaly detection framework built on an Adaptive LLM BGP Encoder that captures each AS's Behavior Portrait and Routing Policy Rationale beyond topology. Inspired by multimodal LLMs, the encoder generates embeddings representing both routing behaviors and semantics of ASes via contrastive learning. We further introduce SAM-ED to quantify BGP-specific semantic deviations between historical and updated paths, rather than naively accumulating distances without awareness of BGP-specific structures. Evaluated on 16 real-world datasets, BGPShield detects 100% of verified anomalies with an average false discovery rate below 5%. The open-source LLMs used by BGPShield were released prior to several evaluation events, verifying generalizability on unseen events. Furthermore, BGPShield can construct the representation for a previously unseen AS within one second, significantly outperforming BEAM which demands thorough retraining (averagely 65 hours).

cs.NI↗