On the Resilience of a QKD Key Synchronization Protocol for IPsec

01/05/2018
by   Stefan Marksteiner, et al.
0

This paper presents a practical solution to the problem of limited bandwidth in Quantum Key Distribution (QKD)- secured communication through using rapidly rekeyed Internet Protocol security (IPsec) links. QKD is a cutting-edge security technology that provides mathematically proven security by using quantum physical effects and information theoretical axioms to generate a guaranteed non-disclosed stream of encryption keys. Although it has been a field of theoretical research for some time, it has only been producing market-ready solutions for a short period of time. The downside of this technology is that its key generation rate is only around 52,000 key bits per second over a distance of 50 km. As this rate limits the data throughput to the same rate, it is substandard for normal modern communications, especially for securely interconnecting networks. IPsec, on the other hand, is a well-known security protocol that uses classical encryption and is capable of exactly creating site-to-site virtual private networks. This paper presents a solution that combines the performance advantages of IPsec with QKD. The combination sacrifices only a small portion of QKD security by using the generated keys a limited number of times instead of just once. As a part of this, the solution answers the question of how many data bits per key bit make sensible upper and lower boundaries to yield high performance while maintaining high security. While previous approaches complement the Internet Key Exchange protocol (IKE), this approach simplifies the implementation with a new key synchronization concept, proposing a lightweight protocol that uses relatively few, slim control messages and sparse acknowledgement. Furthermore, it provides a Linux-based module for the AIT QKD software using the Netlink XFRM Application Programmers Interface to feed the quantum key to the IP***ABSTRACT TRUNCATED TO 1920 CHARS***

READ FULL TEXT

page 9

page 10

research
12/24/2021

Overview of Quantum Key Distribution Technique within IPsec Architecture

Quantum Key Distribution (QKD) is an approach for establishing symmetric...
research
03/21/2023

Experimental Phase-Matching Quantum Key Distribution without Intensity Modulation

Quantum key distribution provides a promising solution for sharing secur...
research
03/25/2019

Lightweight authentication for quantum key distribution

Quantum key distribution (QKD) enables unconditionally secure communicat...
research
07/10/2020

Quantum Secured Internet Transport

Quantum computing represents an emerging threat to the public key infras...
research
10/10/2019

Adaptive-time Synchronization Algorithm for Superlattice Key Distribution

This paper presents a synchronization algorithm for superlattice key dis...
research
12/07/2017

The Engineering of a Scalable Multi-Site Communications System Utilizing Quantum Key Distribution (QKD)

Quantum Key Distribution (QKD) is a means of generating keys between a p...
research
09/14/2021

QKD parameter estimation by two-universal hashing leads to faster convergence to the asymptotic rate

This paper proposes and proves security of a QKD protocol which uses two...

Please sign up or login with your details

Forgot password? Click here to reset