SearcharxivSearch

arXiv subjects

Thomas Hühn

Publications and source records attributed to Thomas Hühn.

3 recordsLinked to original sources

Secure Medical Data Transmission Using Quantum Key Distribution and Post-Quantum Cryptography in Real-World Fiber Networks

The threat quantum computers pose to classical public-key cryptography motivates the deployment of quantum-safe communication for critical infrastructure such as healthcare, finance, and energy systems. Quantum key distribution (QKD) and post-quantum cryptography (PQC) offer complementary security guarantees, information-theoretic key exchange and quantum-resistant end-to-end authentication that can be combined in a layered architecture. Here, we demonstrate a field-deployed quantum-secure network integrating entanglement-based QKD with end-to-end PQC over 140 km of installed fiber in Thuringia, Germany, connecting a rural health kiosk to a university hospital via a trusted-node architecture comprising heterogeneous underground and aerial fiber links. Unlike conventional deployments that rely on a dedicated key management system to forward keys to applications, our architecture injects QKD keys directly into standard Linux-based VPN tunnels between adjacent nodes, while PQC secures the communication end-to-end, remaining fully compatible with existing infrastructure and software. Polarization-entangled photon pairs were generated at 810 nm and 1550 nm, with the telecom photon transmitted over deployed fiber. Active polarization stabilization and dispersion compensation preserve the entanglement and enable 22 days of continuous, fully autonomous operation, further underscoring the technological maturity of entanglement-based QKD approaches in a real-world fiber environment. Although the two deployed links were operated during separate rather than concurrent periods, the predominantly aerial link exhibited markedly greater instability, with QBER variations most strongly correlated with wind speed. The generated keys secured a telemedicine proof-of-concept without modifying existing medical systems, demonstrating a practical framework for quantum-safe critical infrastructures.

quant-ph

The QTF-Backbone: Proposal for a Nationwide Optical Fibre Backbone in Germany for Quantum Technology and Time and Frequency Metrology

The recent breakthroughs in the distribution of quantum information and high-precision time and frequency (T&F) signals over long-haul optical fibre networks have transformative potential for physically secure communications, resilience of timing infrastructure (such as that supporting Global Navigation Satellite Systems (GNSS)) and fundamental physics. To date, these capabilities remain confined to isolated testbeds, with quantum and T&F signals accessible, for example in Germany, to only a few institutions. In this white paper we propose the QTF Backbone: a dedicated national fibre-optic infrastructure in Germany for the networked distribution of Quantum and T&F signals using dark fibres and specialised hardware. The QTF Backbone is planned as a four-phase deployment over ten years to ensure scalable, sustainable access for research institutions and industry. The concept builds on successful demonstrations of time and frequency distribution at high Technology Readiness Levels (TRLs) across Europe, including PTB-MPQ links in Germany, REFIMEVE in France, and the Italian LIFT network. The QTF Backbone will enable transformative Research and Development (R&D), support a nationwide QTF ecosystem, and ensure the transition from innovation to deployment. As a national and European hub, it will position Germany and Europe at the forefront of quantum networking, as well as T&F transfer.

physics.ins-det

PQC-Enhanced QKD Networks: A Layered Approach

We present a layered and modular network architecture that combines Quantum Key Distribution (QKD) and Post-Quantum Cryptography (PQC) to provide scalable end-to-end security across long distance multi-hop, trusted-node quantum networks. To ensure interoperability and efficient practical deployment, hop-wise tunnels between physically secured nodes are protected by WireGuard with periodically rotated pre-shared keys sourced via the ETSI GS QKD 014 interface. On top, Rosenpass performs a PQC key exchange to establish an end-to-end data channel without modifying deployed QKD devices or network protocols. This dual-layer composition yields post-quantum forward secrecy and authenticity under practical assumptions. We implement the design using open-source components and validate and evaluate it in simulated and lab test-beds. Experiments show uninterrupted operation over multi-hop paths, low resource footprint and fail-safe mechanisms. We further discuss the design's compositional security, wherein the security of each individual component is preserved under their combination and outline migration paths for operators integrating QKD-aware overlays in existing infrastructures.

quant-ph