Published August 28, 2026 | Version v1

Quantum-secure Software Network Environments for Telco Operators

Description

The transition towards quantum-safe secure communications requires current network infrastructures to support the coexistence of multiple cryptographic technologies. In this context, crypto-agility becomes a key requirement, enabling the coordinated use of Quantum Key Distribution (QKD), Post-Quantum Cryptography (PQC), and classical cryptographic mechanisms during a progressive migration process. This paper presents a general, standards-based architecture for crypto-agile IPsec service provisioning in Software-Defined Networking (SDN) environments. The proposal combines modular functional blocks that support the integration of QKD-, PQC-,
and classical-derived key material under a common operational framework. The architecture builds on existing specifications, including RFC 9061 and ETSI GS QKD 004. Rather than focusing on implementation details or performance evaluation, this work describes the needs addressed by the architecture, its main components, and the operational workflows supporting secure tunnel establishment, rekeying, and attestation-related actions.

Files

QSNS26_Quantum_secure_Software_Network_Environments_for_Telco_Operators.pdf

Additional details

Funding

European Commission
QUBIP - Quantum-oriented Update to Browsers and Infrastructures for the PQ Transition 101119746
European Commission
QSNP - Quantum Secure Networks Partnership 101114043