Search arXiv⌕ Search

arXiv subjects

Ignazio Pedone

Publications and source records attributed to Ignazio Pedone.

3 recordsLinked to original sources

A Throughput-Oriented Analytical Model for Post-Quantum Security Protocols

Growing awareness of the impact of quantum threat on classical cryptography directly translates into a growing demand for accurate network simulation tools capable of estimating the integration effects of quantum-safe cryptography in current systems. In particular, the adoption of Post-Quantum Cryptography (PQC) has a direct impact on the performance of network endpoints and transmission overhead. This also affects the scalability of widely adopted security protocols such as TLS and SSH. In this paper, we present a throughput-oriented analytical model that provides a tight upper bound on the maximum sustainable rate of post-quantum secure connection establishment in TLS and SSH. This model takes into account both endpoint and network capacity constraints, decomposing the handshake process into dominant cryptographic operation time and network transmission time. Identifying the bottleneck allows us to derive the achievable throughput in terms of handshakes per second. The experimental results provided show the accuracy of the model against the data obtained from an experimental testbed using, among others, NIST standard primitives from FIPS 203, 204, and 205, including ML-KEM and ML-DSA. Finally, we integrate our model into a network environment and demonstrate how it can be leveraged to enable efficient resource allocation among multiple endpoints, optimizing PQC traffic in multiple-unicast scenarios.

cs.CR↗

Free-Space Quantum Networks and Optimized Fiber-Reinforcement

Free-space quantum communication provides a flexible complement to fiber-based quantum networks, but its point-to-point capacity is fundamentally limited by diffraction, atmospheric extinction and beam wandering induced by turbulence. In this work, we study the end-to-end performance of large-scale free-space quantum networks connecting randomly distributed fixed or mobile users, modelled as Waxman random graphs. We derive the mean network capacity, edge consumption and connectivity phase transitions for both single-path and multi-path (flooding) routing. We also study router-centered star networks, deriving the full distribution of end-to-end capacities as a function of the router's coverage radius. We then consider how performance may be improved by reinforcing free-space networks with a small number of optimally placed fiber-based backbone nodes. We prove that any optimal backbone configuration must correspond to a capacity-maximizing Voronoi tessellation of the network region, and show that this can be efficiently approximated by a centroidal Voronoi tessellation via Lloyd's algorithm, with backbone nodes connected according to a Delaunay triangulation. Numerical results show that even a modest number of backbone nodes substantially improves end-to-end capacity and reduces edge consumption for both mobile and fixed users.

quant-ph↗

SQUIRO: A Framework for Security-Aware Quantum-Classical Scheduling on Kubernetes

Distributed infrastructure schedulers traditionally optimise capacity, locality, and cost, but provide limited support for security posture and emerging quantum-classical workloads. As hybrid quantum-classical computing becomes increasingly practical and post-quantum security requirements begin to affect infrastructure deployment, schedulers must jointly reason about heterogeneous compute resources, security constraints, and quantum backend characteristics. We present SQUIRO, a framework for security-aware quantum-classical scheduling based on a platform-independent Unified Scheduling Model (USM) and a six-step Scheduler Design Methodology (SDM) that together enable the derivation of concrete schedulers for Kubernetes, high-performance computing (HPC), and federated environments. The framework combines multidimensional security posture enforcement through hard feasibility constraints with residual-risk optimisation, and introduces a circuit-aware quantum backend selector that accounts for coherence margin, calibration freshness, queue pressure, and hardware capabilities through a forward-compatible colocation hierarchy. Evaluation on synthetic Kubernetes clusters shows that the security model enforces complete compliance for regulated workloads by construction, while global optimisation reduces infrastructure cost by up to 51% and energy consumption by up to 63% compared with greedy placement in underloaded scenarios, without compromising admission priorities. Additional experiments characterise the solve-time growth of the current CP-SAT formulation and show that circuit-aware backend selection systematically diverges from naive error-rate ranking under coherence- and queue-limited conditions.

cs.ET↗