scieee AI-readable full text Open interactive document viewer

GN5-2 Towards Quantum-Safe Networking

Naegele-Jackson, Susanne; Sanz, Ane; Parra, Xavier Jordán; Rydlichowski, Piotr; Papastamatiou, Ilias; Burkard, Vincent; Roberts, Guy; Golub, Ivana; Vuletić, Pavle

Abstract

This document provides a step-by-step approach towards quantum-safe networks where PQC and QKD technology is applied and integrated over time to harden networks and ensure quantum-safe security.

Full text

© GÉANT Association on behalf of the GN5-2 project. The research leading to these results has received funding from the European Union’s Horizon Europe research and innovation programme under Grant Agreement No. 101194278 (GN5-2). Co-funded by the European Union. Views and opinions expressed are however those of the author(s) only and do not necessarily reflect those of the European Union. The European Union cannot be held responsible for them. 31-10-2025 Towards Quantum-Safe Networking Grant Agreement No.: 101194278 Work Package: WP6 Task Item: T1 Nature of Document: White Paper Dissemination Level: PU Lead Partner: FAU/DFN Document ID: GN5-2-25-634G7D Authors: Susanne Naegele -Jackson (FAU); Ane Sanz (EHU); Xavier Jordán Parra (i2CAT); Piotr Rydlichowski (PCSS); Ilias Papastamatiou (GRNET); Vincent Burkard (FAU); Guy Roberts (GÉANT); Ivana Golub (PCSS); Pavle Vuletić (AMRES) Abstract This document provides a step-by-step approach towards quantum-safe networks where PQC and QKD technology is applied and integrated over time to harden networks and ensure quantum-safe security. Towards Quantum-Safe Networking Document ID: GN5-2-25-634G7D ii Contents Executive Summary 1 1 Introduction 2 2 Migrating to PQC 4 3 Migrating to QKD 7 3.1 Interoperability and Scalability 8 3.2 Integration with Existing Cryptography and Crypto-Agility 9 3.3 Network Management, Control and Orchestration 11 4 Standardisation and Certification 15 5 Transitioning to Quantum-Safe Networking 17 6 Assessing Maturity of Quantum-Safe Networks 19 7 Conclusions 22 Glossary 23 References 25 Figures Figure 3.1: EuroQCI ecosystem 9 Figure 3.2: Hybrid quantum-safe network 12 Figure 6.1: Post Quantum Encryption (PQE): Increasing maturity and effectiveness in 8 stages 19 Figure 6.2: Maturity stages of entanglement-assisted quantum networks 21 Tables Table 6.1: Requirements for reaching higher maturity levels 20 Towards Quantum-Safe Networking Document ID: GN5-2-25-634G7D 1 Executive Summary Quantum-safe networking refers to the adoption of cryptographic methods that are resistant to attacks by quantum computers. It involves the transition from classical cryptographic methods, which are vulnerable to quantum algorithms, to post-quantum cryptography (PQC) and quantum key distribution (QKD) systems that can withstand quantum threats. As quantum computing evolves, the security of current cryptographic systems – such as Rivest–Shamir–Adleman (RSA) and Elliptic Curve Cryptography (ECC) – will be compromised. To mitigate this risk, National Research and Education Networks (NRENs) must adopt quantum-safe protocols and integrate quantum technologies, such as QKD and PQC, to maintain secure communication for research and educational data. It is expected that the transition from quantum-vulnerable pre-quantum cryptography to quantum-resistant post-quantum cryptographic algorithms will take several years and will happen in stages. The EC therefore recommends starting out with standardised and tested hybrid solutions which include PQC, especially in highrisk scenarios, to replace vulnerable public-key encryption methods such as RSA or discrete logarithm-based algorithms wherever applicable. Such a gradual implementation approach is not only recommended when transitioning from pre-quantum cryptography to PQC, but also when integrating QKD and PQC into existing network infrastructures while the QKD standardisation and certification processes are ongoing and while QKD devices have limited terrestrial reach. Additional aspects that need to be addressed include interoperability, scalability, integration with existing cryptography and crypto-agility as well as integration with network management, control and orchestration. For the time being, therefore, it would seem that hybrid networks (defined here as the combination of PQC and QKD to offer quantum-safe resistance) offer the best path forward towards making networks more resilient and quantum-safe in the near future. This document provides a step-by-step approach towards applying and integrating PQC and QKD technology into hybrid networks over time. It provides a series of recommendations for NRENs for the gradual implementation of these steps when transitioning from pre-quantum cryptography to PQC, as well as when integrating QKD and PQC into existing network infrastructures. These recommended steps are in line with the objectives of the Quantum European Strategy [1], the EuroQCI initiative [2] and the World Economic Forum [3]. Finally, a number of maturity models are examined that could help organisations assess their capabilities to implement hybrid networks using pre-quantum cryptography, PQC and QKD technologies and guide them during their transition towards quantum-safe networks. Towards Quantum-Safe Networking Document ID: GN5-2-25-634G7D 2 1 Introduction Quantum science has driven significant technological advancements since the early 20th century, including MRI diagnostics, semiconductor-based computing, and high-speed optical communications. Modern quantum technologies focus on harnessing deep-quantum phenomena such as superposition, no-cloning, and entanglement, which enable groundbreaking new capabilities. Quantum computing offers computational power that exponentially increases with the number of qubits. With new algorithms such as Shor's algorithm for prime factorisation [4] [5], quantum computers are expected to break current public key cryptography (asymmetric cryptography) in the near future. This poses a "quantum threat" to the security of current internet communications. To counter this threat, mechanisms known as quantum-safe security (QSS) are being developed to ensure secure communications. It is interesting to note that not all public key schemes would be compromised by a quantum computer (lattice-based cryptography, for example, supports public key schemes); however, the most widely used ones today, such as RSA or elliptic curve, would indeed be compromised by the factorisation solved by Shor's algorithm. The risk of breaking symmetric encryption algorithms such as Advanced Encryption Standard (AES) is lower, and these are considered secure if the key length is increased from the current maximum of 256 bits (AES-256) to larger keys of 384 or 512 bits. Many widely used encryption methods in current communication systems rely on the difficulty of factoring keys with current processing technologies. For example, RSA, which is based on public keys constructed from the product of two large prime numbers (typically 1024or 2048-bit in length)., could potentially be broken by quantum computers using Shor's algorithm. While not all current cryptographic techniques may become vulnerable to this, this highlights the need for new, less sensitive cryptographic paradigms, known as Post-Quantum Cryptography (PQC). From a cryptographic perspective, three key technologies are crucial towards developing quantum-safe security: (1) PQC: Using classical cryptography with new algorithms that offer computational complexity not solvable by known quantum algorithms within reasonable time and cost frames; (2) Quantum Random Number Generation (QRNG): Implementing true random number generators (TRNG) to replace commonly used pseudo-random software-based generators, promising better unpredictability and irreproducibility; and (3) Quantum Key Distribution (QKD): Also known as quantum cryptography, promising information-theoretic security (ITS) through quantum mechanics when combined with a one-time pad (OTP) encryption mechanism. Other quantum cryptographic mechanisms include Quantum Secure Direct Communication (QSDC), SemiQuantum Key Distribution (SQKD), Secure Multiparty Communication (SMPC), Quantum Blind Computing, Quantum Digital Signature, High-Dimensional QKD, or Position-Based Quantum Cryptography [6]. Of the different mechanisms mentioned, those that that can be classified as having greater technological maturity are based on QKD, QRNG, and PQC, and the rest of the document will be focused on these. Deploying a quantum-safe network involves implementing QSS measures, i.e. using advanced cryptographic techniques designed to withstand threats such as those mentioned above. Key aspects of deploying quantumsafe networks are [7]: • PQC: This involves using cryptographic algorithms that are resistant to attacks from quantum computers. These algorithms are designed to replace or complement existing encryption methods. • QKD: QKD uses the principles of quantum mechanics to securely distribute encryption keys. This method ensures that any attempt to intercept the keys can be detected, providing a higher level of security. Introduction Towards Quantum-Safe Networking Document ID: GN5-2-25-634G7D 3 • Crypto-Agility: This is the ability to quickly switch between different cryptographic algorithms as new threats emerge. It ensures that the network can adapt to future advancements in quantum computing. • Layered Security Approach: This involves implementing multiple layers of security, including both classical and quantum-safe cryptographic methods, to provide comprehensive protection against various types of attacks. • Real-World Deployments: Ensuring that quantum-safe solutions are scalable, adaptable, and costeffective for practical use in real-world scenarios. Migration to quantum-safe networks is becoming crucial for highly critical infrastructures such as power grids, nuclear power plant infrastructures or data centre networks, but also increasingly important for NRENs running nationwide research and education networks. In February 2025, a short survey was run among 24 participants from 20 NREN organisations during the 34th Service and Technology Forum in Dublin, Ireland. Participants were asked about their priorities and activities related to making their networks quantum-safe, as well as about their short-term plans and the possibility for NRENs to work together in this area. When asked "Is achieving quantum-safe security for your network currently a strategic priority for your organisation?”, of 24 participants who responded two reported that they already undertake some activities in this area, and another two stated that they are following what is happening and/or are supporting their users who are carrying out some activities in this area. However, 19 of the NRENs reported that quantum-safe security was not yet a priority for them and a further two organisations were not sure about their status. Only three organisations provided answers to the second question about the steps they are taking to make their network quantum-safe: two indicated that there are not undertaking any activities in this area, while the third responded that quantum activities are not done on the existing “traditional” (TCP/IP) production network. When it came to future plans, of 11 who responded, 6 organisations do not have any activities planned for the next 12 months related to quantum-safe networks, 3 are continuing with their existing activities such as “implementing PQC where possible” or “expansion of the national QCI network to take in a wider area and longer spans” and 1 organisation plans to focus on knowledge gathering and training. Last but not least, participants have seen some opportunities for NREN collaboration, expressing the importance of the newly formed Special Interest Group for Quantum technologies – SIG-Quantum [8] in GÉANT for communication and collaboration, as well as training. At the time of writing, the European Network and Information Systems (NIS) Cooperation Group [9] has also started a survey [10] on the EU Roadmap on Post-Quantum Cryptography and asked the European community for feedback on its PQC deliverable (first and next steps, please see section 2 below). The results of this survey are pending. The remainder of this paper aims to set out a path forward towards quantum-safe networking by providing stepby-step descriptions for QKD and PQC migration. Section 2 first discusses the transition to post-quantum cryptography. Section 3 then describes the integration of QKD into networks, and the impact on orchestration, management and monitoring this will have. Section 4 provides a brief overview of the challenges of standardisation and certification relating to quantum-safe networking. Section 5 offers considerations for a roadmap for transitioning to quantum-safe networking with a brief checklist of recommendations. The focus of Section 6 is a discussion of maturity models and how an organisation may assess its progress when it comes to quantum-safe cryptography. Finally, Section 7 outlines the conclusions to this document. Towards Quantum-Safe Networking Document ID: GN5-2-25-634G7D 4 2 Migrating to PQC In April 2024, the European Commission (EC) published its recommendation on a coordinated implementation roadmap for the transition to post-quantum cryptography [11] [ 12]. As part of this publication the EC recommended establishing a work stream on PQC within the NIS Cooperation Group (NISCG). In June 2025, the NISCG published its first deliverable [13] [14] on how to proceed with first steps by the end of 2026 to initiate the transition to PQC, which will then be followed by next steps to ensure that this transition will be completed for as many systems as possible by 2035. It is expected that the transition from quantum-vulnerable pre-quantum cryptography to quantum-resistant post-quantum cryptographic algorithms will take several years as interoperability and security standards across different platforms and devices must be maintained and as it will not be possible to transition all public-key cryptography in use in one instance. The EC therefore recommends starting out with standardised and tested hybrid solutions which include PQC to replace vulnerable public-key encryption methods such as RSA or discrete logarithm-based algorithms wherever applicable. Especially in high-risk scenarios, vulnerable public-key cryptography should not be used as a stand-alone mechanism after 2030 (and after 2035 for medium-risk scenarios). The recommended EC timeline for a successful migration to PQC is based on the three basic quantum risk levels “low”, "medium" and "high", with factors that depend on the weakness of the cryptographic mechanism used, the expected impact if the mechanism were to be broken and the estimated time and effort it would take for the migration to PQC. It refers to the PQC Migration Handbook [15] from December 2024, where risk assessment can be judged as medium or high whenever confidentiality requires protection (high risk if confidentiality needs to be protected for more than 10 years) and if the migration effort is expected to take more than 8 years (high risk if it is expected to take more than 8 years and the impact of an attack would be high). The first steps of the transition, which are recommended to be undertaken immediately, are: • Identify and involve all types of stakeholders: Providers, users, consulting companies, representatives of science and research, CTO, CISO, and CIO stakeholders from ministries, governmental bodies, and standardisation organisations. • Investigate market readiness. • Identify obstacles impacting the migration to PQC. • As an organisation, investigate your cryptographic assets, create and maintain cryptographic inventories. • Create dependency maps that help you assess both internal, third party and supply-chain dependencies when it comes to products and applications and makes it possible to set priorities and also to take cross-border alignment for interoperability at the EU level into account. • Conduct a quantum risk analysis (assess your organisations risk of vulnerabilities when it comes to quantum threats), and include it in your cyber security risk reports • Talk to your suppliers about integration of PQC and cryptographic agility (i.e. the ability to replace a cryptographic mechanism in an agile manner with very little effort). • Raise national awareness of the urgency to start now and develop product/service roadmaps in alignment with the PQC roadmap across the EU. • Share knowledge and develop an implementation plan to help synchronise the PQC migration not only within each member state but in the EU as a whole in order to ensure readiness and be quantum-safe in time. Migrating to PQC Towards Quantum-Safe Networking Document ID: GN5-2-25-634G7D 5 The recommended next steps to be approached as soon as possible include: • Offering a quantum-safe upgrade path for products and supporting crypto-agility. • Allocating resources for the transition (not only budget but also trained personnel). • Adapting certification schemes that take quantum threats into account. • Evolving regulations and cryptographic policies ensuring that they are systematically updated with the latest recommendations for PQC. • Evolving the ecosystem with funding and training, including capacity building for NRENs, cross-border cooperation, and pilot use cases over test infrastructures to ensure interoperability. • Cooperating across borders on research and training and ensuring that transversal activities are included throughout the creation and implementation of the roadmap and support PQC standardisation working groups. • Testing international interoperability of PQC solutions for a seamless and smooth PQC migration across the EU and performing pilot use cases over test infrastructures. According to the recommendation, adhering to these steps and timelines will avoid chaotic transitions that could possibly introduce new vulnerabilities stemming from solutions that are insufficiently tested. In the US, the National Institute of Standards and Technology (NIST) provides very similar guidelines for the integration of PQC into existing infrastructures in their Cybersecurity Framework Version 2.0 [16] [17] [18]: The framework lists 5 core functions for organisations to manage cybersecurity risks. These include: • Identify: learn your organisation’s quantum-related risks and how they could impact your data, systems, assets (including supply chain risks) and services, develop a strategy to transition to PQC, and set priorities for critical components. • Protect: use protective technology that supports PQC when it comes to hardware and also software upgrades and make sure that all your cryptographic mechanisms are regularly updated to integrate PQC. Protect identity management systems and access systems with PQC algorithms and also extend this to your data (in transit and at rest). Focus on awareness and training. • Detect: implement processes that will let you identify anomalies and unusual events that could be part of a quantum-related cybersecurity activity. Monitor continuously to be able to detect possible breaches of your cryptographic systems and keep all systems up to date with regular audits and reviews. • Respond: Test and implement response plans to be able to react to attack incidents and have communication protocols in place that will allow you to inform stakeholders about the threat and its mitigation. Analyse incidents and try to learn from them in order to be able to improve your strategies. • Recover: Develop plans that will allow you to maintain resilience and be able to restore your services after an incident and keep stakeholders informed about recovery status for transparency. Aydeger et al. [19] describe these core functions of the NIST Cybersecurity Framework version 2.0 but go a bit further by offering concrete case studies, recommendations for implementation and best practices from early adopters. The authors recommend hybrid cryptographic approaches where classical cryptographic algorithms and PQC algorithms are combined. Classical cryptography distinguishes between: • Asymmetric-key algorithms such as ECC and RSA (which use two different keys – a public key and a private key – to encrypt and decrypt data); and Migrating to PQC Towards Quantum-Safe Networking Document ID: GN5-2-25-634G7D 6 • Symmetric-key algorithms such as AES (where the same secret key is used to encrypt and decrypt a message). PQC algorithms (see also Section 4 on standardisation) are categorised into: • Hash-based cryptography (algorithms such as SPHINCS+ [20][21]). • Lattice-based cryptography (algorithms such as Kyber and Dilithium [22]). • Multivariate quadratic equations (MQE)-based cryptography [23]) and algorithms such as classic McEliece [24], which remain research efforts as there are some practical issues with them (e.g. huge keys for McEliece). By combining classical and PQC algorithms in hybrid approaches, compatibility can be ensured, and security can be provided against current threats while preparing against future vulnerabilities. Aydeger et al. [25] list the following hybrid use case examples: • Authentication: Combine classical key exchange algorithms (RSA, Diffie Hellman) with PQC algorithms such as lattice-based key exchange. • Encryption: AES in connection with hybrid key encapsulation mechanism (KEM) to secure the symmetric key with both classical and PQC algorithms [26]. • Digital signatures: Both classical (such as RSA or ECC) and PQC algorithms can be employed for digital signatures. As early adopters, the authors mentioned Google’s combination of PQC (NewHope key exchange algorithm) and classical ECC in an experiment with its Chrome browser [27]. Other hybrid approaches described were Cisco’s Virtual Private Network (VPN) solutions with both classical and PQC algorithms for encryption to secure data transmissions. Adopting hybrid solutions and a phase-in approach for the new PQC algorithms seems to be the best way forward [28], as it ensures backward compatibility while the implementation challenges of PQC are still being ironed out: PQC faces challenges with standardisations and regulatory issues, but also compatibility issues with legacy systems and in cross-border environments. PQC algorithms often lead to the management of larger key sizes and requirements for more computation, hardware acceleration, optimisation or parallel processing. Performance tests should be conducted in pilot environments to assess any transition process. Towards Quantum-Safe Networking Document ID: GN5-2-25-634G7D 7 3 Migrating to QKD While PQC seems to be quantum-safe for now, it still has to pass the test of time. Just recently, the SIKEp434 algorithm, which had been one of the candidates in round 4 of the PQC standardisation process run by NIST, was broken [29]. Therefore, the option to make networks quantum-safe based on QKD is appealing as it relies on quantum mechanics rather than complex algorithms to generate keys without modifications or eavesdropping. Although QKD has been shown to be information-theoretic secure it is still unclear – due to a lack of certification – exactly what level of security the currently available physical QKD systems can offer. Another problem with QKD devices is that their terrestrial reach is still rather limited and long distances require intermediate trusted nodes to relay QKD keys to distant endpoints and satellite transmissions. However, satellite transmissions have their own set of issues, ranging from interference due to weather, sunlight and atmospheric impairments to satellite availability (orbit periodicity and geometry, pointing agility and accuracy) [30]. For the time being, therefore, it would seem that hybrid networks (defined here as the combination of PQC and QKD to offer quantum-safe resistance) are the way forward, i.e. step-by-step integration of QKD into existing infrastructures while employing PQC algorithms whenever possible as a way to make networks more resilient and quantum-safe for the near future. Klicnik et al. [31] [32] describe a real-world deployment of QKD in an academic network and the challenges that were encountered with multiplexing classical and quantum channels within the same wavelength band. Viksna et al. [33] studied another use case example of how QKD can be integrated step by step into a hybrid classicalquantum network: in their hybrid network, users wishing to communicate using quantum key distribution are connected to their nearest QKD service node originally via links protected by classical encryption such as TLS. These links are then hardened by the PQC algorithms SPHINCS+ for certificate signatures and FrodoKEM for key exchange. In addition, they propose a new protocol where half-keys of the QKD session keys are relayed crosswise in a butterfly fashion between two QKD service nodes, meaning each node contributes and exchanges part of the key so that the final session key is jointly established (assuming that there is added security since an eavesdropper would have to compromise both links). More information on this approach can be found in [34]. But when considering the integration of QKD into existing classical networks, providers still face a number of challenges in areas such as: • Interoperability and scalability • Integration with existing cryptography and crypto-agility • Integration with network management, control and orchestration As traditional network frameworks do not handle the particularities of quantum-resistant cryptographic mechanisms, which introduce new computational requirements, increased key sizes, different trust models, and new network elements, these changes impact key management, authentication and secure communication, requiring the adaptation of management mechanisms or even the definition of novel approaches that ensure seamless integration with existing infrastructures. The following sections will provide more details on these issues and how such integration can be addressed in hybrid networks where QKD is being slowly introduced. Migrating to QKD Towards Quantum-Safe Networking Document ID: GN5-2-25-634G7D 14 Orchestrators for harmonising control of classical and quantum resources currently exist mostly in the context of cloud-based hybrid workloads. Examples are Qonductor [42] for hybrid quantum-classical applications running on heterogeneous hybrid resources, or QFOR [43] for quantum scheduling and quantum fidelity-aware orchestration of tasks across heterogeneous quantum nodes. Similarly, Q-Orchestrator [44] enables the execution of quantum circuits in different providers. Other examples of orchestrators include Quantum Machines [45] for hybrid control of quantum and classical operations or Amazon Braket [46] with a fully managed service for running hybrid quantum-classical algorithms; Orquestra [47] for integrating PQC; and Qoro [48] for streamlining quantum workflows. Towards Quantum-Safe Networking Document ID: GN5-2-25-634G7D 15 4 Standardisation and Certification From the perspective of standardisation bodies, both the European Telecommunications Standards Institute (ETSI) and International Telecommunication Union (ITU) are consistent in defining a quantum-safe network as implementing technologies and standards to protect data against the potential threats posed by quantum computing, with a focus on deploying quantum safe cryptography mechanisms such as PQC and QKD. ETSI standardisation ETSI focuses on different aspects of Quantum-Safe Cryptography (QSC), which aims to develop cryptographic algorithms resistant to attacks from both classical and quantum computers. Their efforts include: • PQC: Developing and standardising cryptographic algorithms that can withstand quantum attacks. • QKD: Using quantum mechanics principles to securely distribute encryption keys, ensuring any interception attempts are detectable. • Practical Implementation: Assessing and recommending quantum-safe cryptographic primitives, protocols, and implementation considerations for real-world deployment. It is important to highlight the work of the ETSI QSC Working Group, which has led to the publication of Technical Report TR 103 619 in 2020 [49]. This report outlines migration strategies and provides recommendations for the adoption of quantum-safe schemes, as well as actions to raise cybersecurity awareness across all sectors. Also noteworthy is the extensive work carried out by the Industry Specification Group (ISG) on QKD, which has, for over a decade, produced numerous documents that serve as de facto standards for the development of QKD devices, functional blocks, and interfaces [50]. ITU standardisation ITU's approach includes developing standards for networks that support quantum-safe encryption and authentication. Key aspects covered include: • QKD: ITU standards describe the networking concepts to underpin QKD, enabling secure encryption and authentication even in the presence of quantum computing. • Security Guidelines: ITU provides guidelines for applying quantum-safe algorithms in various systems, such as IMT-2020 (5G) networks, to mitigate threats posed by quantum computing. • Interoperability and Best Practices: ITU focuses on creating standards for the interoperability of QKD equipment from different vendors and codifying best practices for QKD network implementations. Examples of released ITU documentation about QKD include [51] Y.3800 ‘Overview on networks supporting quantum key distribution’, which describes the basic conceptual structures of QKD networks as the first of a series of emerging ITU standards on network and security aspects of quantum information technologies, such as [52] X.1811, which relates to PQC strategies. CEN-CENELEC standardisation roadmap In 2023, the CEN-CENELEC Focus Group on Quantum Technologies published a Standardisation Roadmap on Quantum Technologies [ 53 ], which also includes a section on the standardisation needs for quantum communication systems, including QKD technology. Standardisation and Certification Towards Quantum-Safe Networking Document ID: GN5-2-25-634G7D 16 This extensive document covers: • QKD protocols • QKD transmitter and receiver modules • Generic QKD components • Single-link QKD • Basic standards related to QKD and quantum communication • Security evaluation/certification of quantum key distribution • Quantum repeaters Detailed analyses and considerations are given for existing and projected standards, as well as standardisation gaps and additional standardisation needs that must still be addressed. NIST standardisation In 2015, NIST started work on selecting and standardising quantum-resistant algorithms; at first four algorithm standards were selected and then approved as Federal Information Processing Standards (FIPS) by the US Secretary of Commerce: CRYSTALS-Kyber, CRYSTALS-Dilithium, Sphincs+ and FALCON. Three of these first draft standards were published in 2023 [54]. The fourth draft standard based on FALCON is currently (October 2025) pending release. A fifth algorithm – HQC – was selected in March 2025; this standard is expected to be published in 2027 [55] [56]. The first four FIPS include: • FIPS 203 [57]: primary standard for general encryption • Standard based on the CRYSTALS-Kyber algorithm (Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM)); small encryption keys for easy exchange between two parties. • HQC (fifth algorithm to be standardised in 2027) will become the backup algorithm for general encryption. • FIPS 204 [58]: primary standard for protection of digital signatures • Standard based on the CRYSTALS-Dilithium algorithm (Module-Lattice-Based Digital Signature Algorithm (ML-DSA)). • FIPS 205 [59]: intended as backup method for digital signatures • Standard that uses the Sphincs+ algorithm (Stateless Hash-Based Digital Signature Algorithm (SLHDSA)). Employs a different math approach from ML-DSA in case ML-DSA turns out to be vulnerable. • FIPS 206 [60]: under development – Built around the FALCON algorithm (FFT (fast-Fourier transform) over NTRU-Lattice-Based Digital Signature Algorithm (FN-DSA)). Certification While having standards as documented guidelines is a prerequisite first step, certifying systems to confirm that that they meet the required standards in practice can present challenges. In January 2025, the first QKD product to receive an official national security approval was the Clavis XG Series of ID Quantique [61], which obtained the certification from the National Intelligence Service (NIS) of South Korea. The evaluation of the optical and digital subsystems also included the protocols and software stack of the Key Management System used (Clarion KX). The European Union has adopted the Common Criteria-based Cybersecurity Certification Scheme (EUCC) as a process to certify hardware and software [62] [63]. Certification efforts are also driven by the German Bundesamt für Sicherheit in der Informationstechnik (BSI) [64]. Towards Quantum-Safe Networking Document ID: GN5-2-25-634G7D 17 5 Transitioning to Quantum-Safe Networking As highlighted in the previous chapters, the challenges in implementing quantum-safe networking are wideranging and transitioning to quantum-safe networks using emerging technologies requires a careful, step-bystep approach. Since this process will require time, the best way forward is to initially use a hybrid approach, not only when it comes to moving from pre-quantum cryptography to PQC, but also when integrating QKD and PQC into existing network infrastructures. This section summarises recommended steps and provides a short-term, medium-term and long-term timeline towards the implementation of quantum-safe networking for network providers , in line with the objectives of the Quantum European Strategy [65], the EuroQCI initiative [66] and the World Economic Forum [67]. • Recommendation 1: Identify and Prioritise Quantum-Safe Cryptographic Algorithms ○ Understand the computational requirements and performance impacts of adopting post-quantum algorithms, which may have higher latency or resource consumption. • Recommendation 2: Implement Quantum-Safe Cryptography and QKD in Network Infrastructure ○ Quantum-safe protocols: Begin integrating post-quantum algorithms for secure communication, like Lattice-based algorithms and hash-based cryptography, into NRENs’ networking and security protocols. ○ QKD implementation: Deploy QKD infrastructure in pilot locations, focusing on high-value research applications, and gradually expand this network to cover more campus and research institution connections. Use fibre-optic networks for early-stage deployment, as fibre provides the most mature platform for QKD. ○ Work on hybrid cryptography: combining classical encryption for routine traffic with QKD for highpriority or sensitive communication, ensuring that traditional networks can interoperate with quantum-safe techniques. • Recommendation 3: Foster Collaboration and Knowledge Sharing ○ Engage in collaborations with international research bodies, industry and governments to ensure up-to-date adoption of quantum-safe technologies. Notably, integrate QKD as part of these discussions to align with global standards. ○ Participate in national and global initiatives such as the European Quantum Flagship, the EuroQCI Initiative, and Quantum Internet Alliance, which are focused on building quantum-safe infrastructures, including the development of QKD systems. • Recommendation 4: National Quantum-Safe Transition Timeline ○ Short-Term (2025–2026): Conduct an assessment of the current NREN infrastructure and perform initial trials for PQC and QKD. Begin the process of integrating quantum-safe protocols for specific use cases (e.g., secure key exchange in VPNs, securing sensitive research data). Conduct a comprehensive risk assessment to identify quantum computing threats and evaluate current NREN vulnerabilities. Begin PQC pilot programs for key services (e.g., secure key exchange in VPNs). Launch initial QKD pilot projects to test the feasibility of secure communication using quantum keys. Some recommended guidelines to follow include the EU Cybersecurity Act and ENISA guidelines on quantum-safe cryptography [68], ETSI GS QKD and PQC standards or NIST Draft Guidance (SP/IR) SP-800-227 [69], IR 8547 [70], and IR 8528 [71]. Transitioning to Quantum-Safe Networking Towards Quantum-Safe Networking Document ID: GN5-2-25-634G7D 18 ○ Medium-Term (2027–2030): Expand the integration of quantum-safe protocols and QKD in more NREN segments. Foster collaboration with other NRENs to ensure interoperability and shared learnings. Begin replacing legacy cryptographic systems in key infrastructures: — PQC Integration: Begin wider adoption of quantum-safe protocols for secure communication in more critical NREN services, ensuring robustness against quantum attacks. — QKD Expansion: Roll out QKD-based secure key exchanges across regional networks and expand QKD infrastructure to more campuses and partner research institutions. Foster collaboration and share lessons learned across NRENs to enhance collective capabilities. ○ Long-Term (2030–2035): Achieve a fully quantum-safe NREN infrastructure, with robust adoption of QKD in core and edge networks, including between universities and across international research collaborations. Achieve full integration of quantum-safe protocols across all NREN infrastructures, ensuring complete protection against quantum threats. Establish national quantum-safe network standards to ensure consistency and interoperability across NRENs and international research communities. Ensuring interoperability across national quantum communication infrastructures – particularly in cross-border scenarios envisioned by initiatives like EuroQCI –presents a highly technical and political challenge. Achieving seamless interconnection between diverse implementations of QKD and PQC requires consensus on architecture, orchestration, and key management systems. ○ Post-2035: Stay ahead of quantum advancements by continuously researching PQC and QKD technologies, updating systems as needed to keep pace with emerging quantum computing developments. Expand QKD networks globally to create a seamless quantum-safe global communications infrastructure. • Recommendation 5: Training and Education ○ Develop specialised training and make certification programs available to network engineers, administrators, and security professionals, focusing on post-quantum cryptography and QKD technologies [72]. ○ Host workshops, seminars, and webinars for researchers to educate them on the future of quantum-safe networking and the role of QKD in securing sensitive academic research data. Towards Quantum-Safe Networking Document ID: GN5-2-25-634G7D 19 6 Assessing Maturity of Quantum-Safe Networks Maturity models [73] are used to assess the capabilities of an organisation, for example when it comes to processes, services or management structures and how well these practices match with a specific purpose or goals. This approach is not only valuable for current network provider services but can be especially useful when it comes to emerging technologies or complicated processes such as migrating from PQC to QKD. The following section describes notable maturity models for both QKD networks and PQC. Maturity considerations for PQC A Post-Quantum Cryptography Maturity Model was proposed by DigiCert [74], with levels ranging from PQC Novice and Apprentice to PQC Practitioner and Master. There are also two dimensions to this maturity model that represent two important factors: how much an organisation understands and knows when it comes to quantum threats and how much preparation is actually carried out as a defence against such threats. The PKI consortium [75] suggests the use of a Post Quantum Security Maturity Index to continuously monitor progress when it comes to improving quantum defences and to fine-tune actions that should be prioritised vs. budget considerations. Eight maturity levels (stages) are used in their suggested model (see Figure 6.1), where of the first 3 levels, level 1 deals with risk analysis and strategy, level 2 focuses on discovery (random numbers, PKI cryptography), and level 3 defines an ecosystem with vendors, tools, services and open source for interoperability. Level 4 in the PKI consortium maturity model refers to a Post-Quantum Encryption (PQE) Architecture; this is elevated to a PQE test environment in level 5 and to limited trials and prototypes for crypto agility in level 6. Level 7 describes the rollout and network implementation of crypto agility, while the final level 8 encompasses management of threats and algorithms, as well as management of new automation and APIs. Figure 6.1: Post Quantum Encryption (PQE): Increasing maturity and effectiveness in 8 stages [76] Hohm et al. [77] describe a Crypto-Agility Maturity Model (CAMM) with five levels: level 0 ‘Initial/Not Possible’; level 1 ‘Possible’; level 2 ‘Prepared’; level 3 ‘Practiced’; and level 4 ‘Sophisticated’. These levels describe the ability of an organisation to select security algorithms with very little effort in an agile way in real time. This includes the ability to add new cryptographic features or algorithms to software and hardware and the ability to retire systems that have become vulnerable or are no longer needed. In order to reach the next higher maturity level, certain requirements (see Table 6.1) have to be met: the requirements are grouped under three categories: Knowledge (K), Process (P), and System property (S). Assessing Maturity of Quantum-Safe Networks Towards Quantum-Safe Networking Document ID: GN5-2-25-634G7D 20 Levels 0: Initial / Not Possible 1: Possible 2: Prepared 3: Practiced 4: Sophisticated Knowledge N/A System knowledge, cryptographic inventory Algorithm IDs Performance, awareness, security Process N/A Updateability, reversibility Policies, testing, enforceability, transition mechanism, effectiveness Automation, scalability, real-time System property N/A Extensibility Cryptographic modularity, algorithm intersection, algorithm exclusion, opportunistic security Hardware modularity, backwards compatibility, Context independence, interoperability Table 6.1: Requirements for reaching higher maturity levels [78] The Cybersecurity Framework 2.0 [79] of the National Institute of Standards and Technology is also worth mentioning in the context of maturity models, although NIST does not have a specific PQC maturity framework in place. Instead, the framework identifies four tiers to describe an organisation’s governance and management practices when it comes to cybersecurity risks, preparing systems and adopting new standards. The tiers are ‘Partial’ (tier 1), ‘Risk-Informed’ (tier 2), ‘Repeatable’ (tier 3) and ‘Adaptive’ (tier 4). Maturity considerations for QKD As quantum technologies comprise very different fields such as quantum computing, quantum sensing and quantum communication, it is beneficial to distinguish these areas when it comes to the discussion of technology readiness levels (TRLs) and maturity. Quantum communication technology, which includes QKD, is one of the fields that is experiencing rapid advancements, although there are still hurdles to clear before it can become a fully employed production technology. According to Purhoit et al. [80] a Quantum Technology Readiness Level (QTRL) of ‘seven’ could be applied to quantum communication networks which corresponds to prototype demonstrations in operational environments. Li et al. [81] do not rely on QTRLs to describe the quantum readiness for QKD Networks but instead use a six stage maturity model consisting of developmental stages (see Figure 6.2). In a first stage, QKD networks must be able to distribute keys while still relying on trusted nodes for repeaters between distant nodes. A second stage would allow end-to-end QKD without the use of trusted nodes by relying on hop-by-hop preparation and measurement (PMNs, Prepare and Measurement Networks). In stage 3, Entanglement Distribution Networks (EDNs) must be used to realise end-to-end entanglement with device-independent application protocols. The authors describe stage 4 as Quantum Memory Networks (QMNs), with local quantum memories at each node so that a deterministic transmission of unknown qubits between any pair of quantum nodes would be possible. Assessing Maturity of Quantum-Safe Networks Towards Quantum-Safe Networking Document ID: GN5-2-25-634G7D 21 Stage 5 would then be Fault-Tolerant Qubit Networks (FQNs) where all operations can be performed in a faulttolerant way, enabling high-accuracy quantum computation and protocols. The final stage 6 of Quantum Information Networks (QINs) will be a network where each node will have the ability to prepare, store, manipulate and transmit qubits. Figure 6.2: Maturity stages of entanglement-assisted quantum networks [82] Similar stages based on functionality of the technology are also used initially by Wehner et al. [83] to assess the development of a future large-scale quantum internet. Towards Quantum-Safe Networking Document ID: GN5-2-25-634G7D 22 7 Conclusions For current cryptography, NRENs predominantly rely on RSA, ECC, and other classical cryptographic protocols to secure their communication channels. However, these are vulnerable to quantum computing’s ability to break these systems using algorithms such as Shor’s. Quantum computers could break the cryptographic primitives widely used today, making it essential for NRENs to prepare for these threats by moving to quantum-safe methods before large-scale quantum computers become a reality. The integration of post-quantum cryptographic algorithms and Quantum Key Distribution offers the most promising defence mechanisms in this scenario. QKD uses quantum mechanics to securely exchange cryptographic keys, which are immune to attacks from quantum computers. Transitioning to quantum-safe networking presents a range of complex challenges that NRENs must carefully navigate. Some of those challenges that lie ahead include: • One of the most significant challenges lies in the transition from existing cryptographic standards, such as RSA and ECC, to PQC algorithms. Widespread adoption will require extensive protocol updates and software modifications. • Initially, small pilot testbeds and smaller-scale deployments will be needed to ensure interoperability and shared learnings towards bringing about the establishment of essential common guidelines and reference architectures. • The relative maturity and availability of quantum-safe technologies also present obstacles. While promising developments are underway with current NIST PQC standardisations, QKD technologies, on the other hand, are commercially available but differ widely in terms of compatibility, performance, and interoperability. The lack of standardised, vendor-neutral benchmarks and test environments further complicates comparative assessments and strategic planning. • Integrating QKD into existing network infrastructures presents additional complexities. QKD systems demand high-quality physical infrastructures, including low-loss optical fibre and closely spaced trusted nodes, which may not align with the current network topology of many NRENs. Moreover, ensuring the coexistence of classical encryption with QKD through hybrid models introduces the need for rigorous testing and architectural redesign to guarantee both performance and security. A possible path forward is set out in this document to tackle these challenges using a step-by-step approach that is two-fold: • Towards hybrid networks employing both pre-quantum cryptography and PQC during a transition period to harden the systems until all components are quantum-secure with PQC algorithms. • Towards hybrid networks slowly integrating QKD technology and PQC over time. The document also provides a very short overview of where things currently stand with standardisation and certification. The included checklist-oriented roadmap and timeline describe a series of objectives to focus on in this transition period. Maturity models that NRENs may use to assess their progress as well as future steps are discussed. Since it is expected that the transition to quantum-safe networks will take years, during which interoperability and security standards across different platforms and devices will have to be maintained, the EC recommends starting out with standardised and tested hybrid solutions wherever applicable. It is also recommended that these steps should be taken without delay. Towards Quantum-Safe Networking Document ID: GN5-2-25-634G7D 23 Glossary AES Advanced Encryption Standard API Application programming interface BSI Bundesamt für Sicherheit in der Informationstechnik CA Certificate Authority CAMM Crypto-Agility Maturity Model CEN European Committee for Standardization (CEN, French; Comité Européen de Normalisation CENELEC European Committee for Electrotechnical Standardization CRL Certificate Revocation List E2E End-to-end ECC Elliptic Curve Cryptography EDN Entanglement Distribution Network ENISA The European Union Agency for Cybersecurity ETSI European Telecommunications Standards Institute EUCC Common Criteria-based Cybersecurity Certification Scheme FIPS Federal Information Processing Standards FQN Fault-Tolerant Qubit Network gNMI gRPC Network Management Interface gRPC A cross-platform remote procedure call (RPC) framework ISG Industry Specification Group ITS Information-theoretic security ITU International Telecommunication Union KEM Key encapsulation mechanism KMS Key Management Service MQE Multivariate quadratic equation MRI Magnetic Resonance Imaging NatQCI National Quantum Communications Infrastructure NFV Network Functions Virtualisation NIS National Intelligence Service; Network and Information Systems NISCG NIS Cooperation Group NIST National Institute of Standards and Technology NREN National Research and Education Network OCSP Online Certificate Status Protocol OTP One-time pad PMN Prepare and Measurement Network PQC Post-Quantum Cryptography PQE Post-Quantum Encryption QCI Quantum Communication Infrastructure QIN Quantum Information Network QKD Quantum Key Distribution QMN Quantum Memory Network QRNG Quantum Random Number Generation QSC Quantum-Safe Cryptography QSDC Quantum Secure Direct Communication QSS Quantum-safe security QTRL Quantum Technology Readiness Level REST Representational State Transfer