SearcharxivSearch

arXiv subjects

Francesco Stocco

Publications and source records attributed to Francesco Stocco.

3 recordsLinked to original sources

Deploying and validating a metropolitan QKD secure network: architecture and field performance

The advent of cryptographically relevant quantum computers poses an existential threat to classical public-key infrastructure. Quantum Key Distribution (QKD) addresses this challenge by providing information-theoretic security for key establishment, independently of any computational hardness assumption. In this work, the deployment and experimental validation of a metropolitan-scale quantum-secure network between data centers in Milan is reported. The network operates over installed fiber infrastructure and implements a layered architecture integrating QKD hardware, standards-compliant Key Management (KM), and centralized Software-Defined Networking (SDN) orchestration. Dynamic path reconfiguration via active optical switching and trusted-node routing allow automated fail-over solutions. Application-layer validation across diverse protocols and workloads confirms the seamless interoperability of all system components. These results establish the technical and operational readiness of metropolitan QKD networks for production deployment, and offer a replicable blueprint for building quantum-secure communication infrastructure at metropolitan scale.

quant-ph

Send the Key in Cleartext: Halving Key Consumption while Preserving Unconditional Security in QKD Authentication

Quantum Key Distribution (QKD) protocols require Information-Theoretically Secure (ITS) authentication of the classical channel to preserve the unconditional security of the distilled key. Standard ITS schemes are based on one-time keys: once a key is used to authenticate a message, it must be discarded. Since QKD requires mutual authentication, two independent one-time keys are typically consumed per round, imposing a non-trivial overhead on the net secure key rate. In this work, we present the authentication-with-response scheme, a novel ITS authentication scheme based on $\varepsilon$-Almost Strongly Universal$_2$ ($\varepsilon$-ASU$_2$) functions, whose IT security can be established in the Universal Composability (UC) framework. The scheme achieves mutual authentication consuming a single one-time key per QKD round, halving key consumption compared to the state-of-the-art.

quant-ph

European Quantum Ecosystems -- Preparing the Industry for the Quantum Security and Communications Revolution

There is mounting evidence that a second quantum revolution based on the technological capabilities to detect and manipulate single quantum particles (e.g., electrons, photons, ions, etc), a feat not achieved during the first quantum revolution, is progressing fast. It is expected that in less than 10 years, this second quantum revolution shall have a significant impact over numerous industries, including finance, medicine, energy, transportation, etc. Quantum computers threaten the status quo of cybersecurity, due to known quantum algorithms that can break asymmetric encryption, which is what gives us the ability to communicate securely using a public channel. Considering the world's dependence on digital communication through data exchange and processing, retaining the ability to communicate securely even once quantum computers come into play, cannot be stressed enough. Two solutions are available: Quantum Key Distribution (QKD) and Post-Quantum Cryptography (PQC); which, we emphasise, are not mutually exclusive. The EuroQCI initiative, of which EQUO is a part of, focuses on QKD and aims to build a network whereby EU countries can communicate securely through QKD. To this aim, the DEP (Digital Europe Programme) project aims to bring technological matureness to QKD by deploying a QKD test network and, through this exercise, understand what is lacking from an operator's point of view when the time to integrate QKD in their network comes.

quant-ph