SearcharxivSearch

arXiv subjects

Fernando Chirici

Publications and source records attributed to Fernando Chirici.

3 recordsLinked to original sources

Deploying and validating a metropolitan QKD secure network: architecture and field performance

The advent of cryptographically relevant quantum computers poses an existential threat to classical public-key infrastructure. Quantum Key Distribution (QKD) addresses this challenge by providing information-theoretic security for key establishment, independently of any computational hardness assumption. In this work, the deployment and experimental validation of a metropolitan-scale quantum-secure network between data centers in Milan is reported. The network operates over installed fiber infrastructure and implements a layered architecture integrating QKD hardware, standards-compliant Key Management (KM), and centralized Software-Defined Networking (SDN) orchestration. Dynamic path reconfiguration via active optical switching and trusted-node routing allow automated fail-over solutions. Application-layer validation across diverse protocols and workloads confirms the seamless interoperability of all system components. These results establish the technical and operational readiness of metropolitan QKD networks for production deployment, and offer a replicable blueprint for building quantum-secure communication infrastructure at metropolitan scale.

quant-ph

Send the Key in Cleartext: Halving Key Consumption while Preserving Unconditional Security in QKD Authentication

Quantum Key Distribution (QKD) protocols require Information-Theoretically Secure (ITS) authentication of the classical channel to preserve the unconditional security of the distilled key. Standard ITS schemes are based on one-time keys: once a key is used to authenticate a message, it must be discarded. Since QKD requires mutual authentication, two independent one-time keys are typically consumed per round, imposing a non-trivial overhead on the net secure key rate. In this work, we present the authentication-with-response scheme, a novel ITS authentication scheme based on $\varepsilon$-Almost Strongly Universal$_2$ ($\varepsilon$-ASU$_2$) functions, whose IT security can be established in the Universal Composability (UC) framework. The scheme achieves mutual authentication consuming a single one-time key per QKD round, halving key consumption compared to the state-of-the-art.

quant-ph

Performance of Cascade and LDPC-codes for Information Reconciliation on Industrial Quantum Key Distribution Systems

Information Reconciliation is a critical component of Quantum Key Distribution, ensuring that mismatches between Alice's and Bob's keys are corrected. In this study, we analyze, simulate, optimize, and compare the performance of two prevalent algorithms used for Information Reconciliation: Cascade and LDPC codes in combination with the Blind protocol. We focus on their applicability in practical and industrial settings, operating in realistic and application-close conditions. The results are further validated through evaluation on a live industrial QKD system.

quant-ph