Skip to main content

Liaison statement
Work progress on Quantum Key Distribution (QKD) network in ITU-T SG13 (as of July 2025)

Additional information about IETF liaison relationships is available on the IETF webpage and the Internet Architecture Board liaison webpage.
State Posted
Submitted Date 2025-09-03
From Group ITU-T-SG-13
From Contact tsbsg13@itu.int
To Group OPS
To Contacts Mahesh Jethanandani <mjethanandani@gmail.com>
Mohamed Boucadair <mohamed.boucadair@orange.com>
Cc Scott Mansfield <Scott.Mansfield@Ericsson.com>
Mahesh Jethanandani <mjethanandani@gmail.com>
Mohamed Boucadair <mohamed.boucadair@orange.com>
The IETF Chair <chair@ietf.org>
Response Contact gmlee@kaist.ac.kr
choits@etri.re.kr
kaz.tanikawa@nict.go.jp
Technical Contact gmlee@kaist.ac.kr
Action Holder Contacts Scott Mansfield <Scott.Mansfield@Ericsson.com>
Purpose For information
Attachments The initial Y.QKDN-QOdrQ “Quantum key distribution networks - Quantitative objectives for delay-related QoS parameters”
The initial Y.QKDN-qos-req-rs “Requirements of quality of service assurance for quantum key distribution network resilience”
The initial Y.QDN-ekm “Framework of quantum key distribution network for supporting edge key management”
The initial Y.QKDN-car-fr “Quantum key distribution networks – Framework of cryptographic application registration”
The initial YSTR.QKDN-sms “Technical elements of secure multicast support in QKDN based on trusted relay”
The initial YSTR.QKDN-PQQ “Plug-and-play 1 X N Quantum Key Distribution Module for QKDN”
The initial YSTR.QKDN-nq-trust “Guideline for integration of QKDN, UNemc, and trust enabled service provisioning”
The initial Y.supp-QENS-roadmap “Standardization roadmap on quantum enhanced networking and services for study period 2025”
The updated Y.QKDN-qos-auto-fa “Quantum key distribution networks – Functional architecture enhancement for autonomic quality of service assurance”
The updated Y.QKDN-nq-qos-fa “Integration of quantum key distribution network and user network supporting end-to-end modern cryptography services – functional architecture for quality of service assurance”
The updated Y.QKDN-GQT “Generic common Quantum Key Distribution Network Template”
The updated Y.QKDN-TLS “Quantum Key Distribution integration with Transport Layer Security 1.3”
The updated Y.QKDN-safr “Quantum key distribution networks – Framework for service awareness”
The updated Y.QKDN-orfr “Quantum key distribution networks - framework for orchestration”
The updated Y.supp.QKDNmc-UC “Use cases of multi-point coordination in QKDN”
The updated Y.QKDN-IPsec-fr “Framework for integration of quantum key distribution and IPSec”
The updated Y.QKDN-nq-fa “Integration of quantum key distribution network and user network supporting end-to-end modern cryptography services - functional architecture”
The updated Y.supp.TC-QN “Technical considerations towards Quantum Network”
The consented Y.3829 (Y.QKDNi-qos-fa) “Quantum key distribution networks interworking – Functional architecture for quality of service assurance”
The consented Y.3830 (Y.QKDN-rsff) “Quantum key distribution networks – procedures for key supply protection and recovery for resilience
Body
Abstruct: This serves to communicate the progress of work on Quantum Key
Distribution (QKD) network in ITU-T SG13 (as of July 2025).

ITU-T Working Party 4/13 is pleased to inform you of our progress on Quantum
Key Distribution (QKD) topics.

SG13 has published 28 Recommendations and 6 Supplements on QKDN as follows:
-Recommendation ITU-T Y.3800 “Overview on networks supporting quantum key
distribution”; -Recommendation ITU-T Y.3801 “Functional requirements for
quantum key distribution networks”; -Recommendation ITU-T Y.3802 “Quantum key
distribution networks – Functional architecture”; -Recommendation ITU-T Y.3803
“Quantum key distribution networks – Key management”; -Recommendation ITU-T
Y.3804 “Quantum key distribution networks - Control and management”;
-Recommendation ITU-T Y.3805 “Quantum Key Distribution Networks - Software
Defined Networking Control”; -Recommendation ITU-T Y.3806 “Quantum key
distribution networks - Requirements for quality of service assurance”;
-Recommendation ITU-T Y.3807 “Quantum Key Distribution networks - QoS
parameters”; -Recommendation ITU-T Y.3808 “Framework for integration of quantum
key distribution network and secure storage network”; -Recommendation ITU-T
Y.3809 “A role-based model in quantum key distribution networks deployment”;
-Recommendation ITU-T Y.3810 “Quantum key distribution network interworking -
Framework”; -Recommendation ITU-T Y.3811 “Quantum key distribution networks -
Functional architecture for quality of service assurance”; -Recommendation
ITU-T Y.3812 “Quantum key distribution networks - Requirements for machine
learning based quality of service assurance”; -Recommendation ITU-T Y.3813
“Quantum key distribution networks interworking – functional requirements”;
-Recommendation ITU-T Y.3814 “Quantum key distribution networks - functional
requirements and architecture for machine learning enablement”; -Recommendation
ITU-T Y.3815 “Quantum key distribution networks - overview of resilience”;
-Recommendation ITU-T Y.3816 “Quantum key distribution networks - Functional
architecture enhancement of machine learning based quality of service
assurance”; -Recommendation ITU-T Y.3817 “Quantum key distribution networks
interworking - Requirements of quality of service assurance”; -Recommendation
ITU-T Y.3818 “Quantum key distribution networks interworking – architecture”;
-Recommendation ITU-T Y.3819 “Quantum key distribution networks - requirements
and architectural model for autonomic management and control enablement”;
-Recommendation ITU-T Y.3820 “Quantum Key Distribution Network Interworking -
Software Defined Networking Control”; -Recommendation ITU-T Y.3821 “Quantum key
distribution networks - requirements for resilience”; -Recommendation ITU-T
Y.3822 “Quantum key distribution networks - Requirements for autonomic quality
of service assurance”; -Recommendation ITU-T Y.3824 “Quantum key distribution
network federation - Reference models”; -Recommendation ITU-T Y.3825
“Integration of quantum key distribution network and time-sensitive network -
framework”; -Recommendation ITU-T Y.3826 “  Integration of quantum key
distribution network and user network supporting end-to-end modern cryptography
services - framework”; -Recommendation ITU-T Y.3827 “Quantum key distribution
networks - Measurement methodology for QoS parameters”; -Recommendation ITU-T
Y.3828 “Integration of quantum key distribution network and user network
supporting end-to-end modern cryptography services – requirements for quality
of service assurance”; -Supplement ITU-T Y.Sup70 to Y.3800-series “Quantum Key
Distribution Networks - Applications of Machine Learning”; -Supplement ITU-T
Y.Sup74 to Y.3800-series “Standardization roadmap on Quantum Key Distribution
Networks”; -Supplement ITU-T Y.Sup75 to Y.3800-series “Quantum key distribution
networks - Quantum-Enabled Future Networks”; -Supplement ITU-T Y.Sup79 to
Y.3800-series “Quantum key distribution networks – Role in end-to-end
cryptographic services with non-quantum cryptography”; -Supplement ITU-T
Y.Sup80 to Y.3800-series “Use cases of quantum key distribution networks”;
-Supplement ITU-T Y.Sup89 to Y.3800-series “Analysis of time synchronization in
Quantum Key Distribution Networks”.

1.The items consented at the July 2025 WP4/13 meeting

Draft new Recommendation ITU-T Y.3830 (Y.QKDN-rsff) “Quantum key distribution
networks – procedures for key supply protection and recovery for resilience” in
TD192/WP4 Recommendation ITU-T Y.3830 specifies procedures for key supply
protection and recovery to enable seamless key supply even in the case of
failures. It describes the configurations and operational procedures for the
protection and recovery of key supply.

Draft new Recommendation ITU-T Y.3829 (Y.QKDNi-qos-fa) “Quantum key
distribution networks interworking – Functional architecture for quality of
service assurance” in TD181-R1/WP4 Recommendation ITU-T Y.3829 specifies the
functional architecture of quality of service (QoS) assurance for the quantum
key distribution network interworking (QKDNi).

2.Revised ongoing work items after March 2025 SG13 meeting

Draft Supplement ITU-T Y.supp.TC-QN “Technical considerations towards Quantum
Network” in TD193/WP4 Quantum network is expected to provide new applications
based on fundamental quantum mechanics such as entanglement, superposition and
non-cloning, and those are not possible with non-quantum networks (e.g.
conventional digital networks). This Supplement aims to identify technical
considerations for quantum network.

Draft Recommendation Y.QKDN-nq-fa “Integration of quantum key distribution
network and user network supporting end-to-end modern cryptography services –
functional architecture” in TD194/WP4 In order to support QKD service to mobile
objects (i.e., autonomous car, mobile phone, etc.), it is challenging to
establish and maintain a quantum channel stably with them and supporting
KSA-keys. Such challenge calls for a solution to integrate the QKDN and user
networks supporting modern cryptography services. Y.3826 addresses these
challenges and specifies several architectural models, requirements, and a
framework architecture for the integration. This draft Recommendation specifies
functional architecture for integration of QKDN and UNemc. It will define a
functional architecture, functions, reference points and operational procedures.

Draft Recommendation ITU-T Y.QKD-IPSec-fr “Framework for integration of quantum
key distribution and IPSec” in TD195/WP4 With the diversity of network services
and the demand for security, it is necessary to use QKD to ensure the security
of user networks. Therefore, it is promising to implement standardization work
for the integration of QKDN and user networks. Combining QKD with IPsec can
achieve better end-to-end encryption. QKD provides secure key distribution
based on quantum mechanics to resist future quantum computing attacks. IPsec
provides traditional encryption and authentication mechanisms. By combining QKD
and IPsec, not only does it achieve strong defence against quantum computing
attacks, but it also provides comprehensive protection from classical
encryption and identity verification. This Recommendation specify the framework
for integration of QKD and IPSec, including overview, application modes,
requirements, reference model and overall operational procedures of QKD and
IPSec integration.

Draft Supplement ITU-T Y.supp.QKDNmc-UC: “Use cases of multi-point coordination
in QKDN” in TD196/WP4 ITU-T has approved a series of QKDN related
Recommendations, which consider the single-node service model where a user node
is supplied with keys by a single QKD node, and focus on maximizing the service
provision capability of the single QKD node. In practical applications, it can
be exceedingly challenging for a single QKD node to handle highly concurrent
key supply requests while maintaining an acceptable service-level. This
Supplement considers the multi-point coordination in QKDN, also called QKDNmc.
This is a service model where two or more QKD nodes are associated with a user
node and coordinated by QKDN to provide superior key supply service. It aims to
further improve the service provision capability and resource utilization of
the QKDN, and can be seen as the supplement and enhancement to these
Recommendations. Focusing on QKDNmc, this document will discuss related
mechanisms and use cases. Draft Recommendation ITU-T Y.QKDN-orfr “Quantum key
distribution networks – framework for orchestration” in TD197/WP4
Recommendation ITU-T Y.QKDN-orfr specifies an orchestration framework to
enhance resource efficiency of quantum key distribution network (QKDN). It
describes QKDN orchestration with an overview, requirements, reference models,
and overall operational procedures.

Draft Recommendation ITU-T Y.QKDN-safr "Quantum key distribution networks -
Framework for service awareness" in TD198/WP4 Quantum key distribution network
(QKDN) can be regarded as a kind of cryptographic infrastructure since it
supports more and more cryptographic applications, such as video conference,
VoLTE, email, etc. Diversified cryptographic applications put forward
differentiated service requirements for QKDN, including low deterministic
latency, low jitter, high deterministic availability, and guaranteed key
supplies and so on. With the separation mechanism of QKDN and cryptographic
services, the underlying QKDN network cannot perceive service characteristic
information, it is difficult to identify the SLA guarantee requirements of
services. Therefore, it is necessary to consider service awareness function for
QKDN with the guidance of service awareness, service scheduling and service
differentiation which can aware users, service requirements, QKDN resource and
service status and so on in real time, so as to provide differentiated
services. Meanwhile, it’s valuable to carry out necessary standardization
works. This Recommendation specifies scenarios, requirements and functional
model of service awareness for QKDN.

Draft Recommendation Y.QKDN-TLS “Quantum Key Distribution integration with
Transport Layer Security 1.3” in TD199/WP4 This Draft Recommendation specifies
use cases, high-level requirements and reference models for quantum key
distribution (QKD) integration with transport layer security 1.3 (TLS 1.3).

Draft Recommendation Y.QKDN-GQT “Generic common Quantum Key Distribution
Network Template” in TD200/WP4 For network operators to realize secure, stable,
efficient, and robust operations of their existing networks while implementing
quantum key distribution network (QKDN), draft Recommendation ITU-T Y.QKDN-GQT
specifies Generic common Quantum Key Distribution Template (GQT). GQT provides
the standardised list of attributes that can characterise a type of QKDN.

Draft Recommendation Y.QKDN-da “Quantum key distribution networks -
Dependability assessment” in TD182/WP4 With the increasing services supported
by QKDN, and various requirements for the interoperation and coordination
between QKDN and corresponding user networks, it is urgent to discuss QKDN
robustness and carry out necessary standardization works. QKDN users expect
continuously stable keys supply supported by QKDN, which brings strict
requirements for robust QKDN operation. Network dependability assessment of
QKDN is to evaluate the availability performance and its influencing factors,
such as reliability, maintainability of network functions and components,
quality of connections, so as to avoid destructive failures in QKDN. Besides,
it can improve the level of effectiveness, precision and automation of the QKDN
management in QKDN operation and maintenance. This Recommendation will carry
out standardization study and specify QKDN dependability assessment conceptual
model, indicators, and dependability assessment process.

Draft Recommendation Y.QKDN-nq-qos-fa “Integration of quantum key distribution
network and user network supporting end-to-end modern cryptography services –
functional architecture for quality of service assurance” in TD183/WP4 It is
challenging to integrate a quantum key distribution network (QKDN) and a user
network to support end-to-end modern cryptography services to users including
mobile objects (i.e., autonomous car, mobile phone, etc.). [b-ITU-T Supplement
79 to Y.3800-series] addresses this issue and describes several use cases to
deliver KSA-keys generated from QKDNs to the user applications by means of
modern cryptography (e.g., PKI technology) with PQC algorithms. It also
identifies various issues to be addressed for standardization. Technical
implications from the three end-to-end use cases identified are related to
control and management, and QoS aspects. Especially, Y.3828 addresses QoS
assurance specific aspects in terms of reference models and requirements. This
draft Recommendation specifies functional architecture, associated
capabilities, reference points, and operational procedure of QoS assurance for
integrated QKDN and UNemc based on the defined reference models and
requirements in Y.3828.

Draft Recommendation Y.QKDN-qos-auto-fa “Quantum key distribution networks –
Functional architecture enhancement for autonomic quality of service assurance”
in TD165/WP4 One of the challenges of the QKDN is to assure the network
performance and different QoS/QoE requirements of different application
scenarios in an autonomic way. The autonomic ability for QoS in QKDN will
support the seamless intelligent decision-making feedback loop of precise
monitoring of status of managed QKDN resources, intelligent decision-making and
necessary policy-generation based on the monitored QKDN QoS information, and
open programmable enforcement of generated policies. The architecture of
autonomic management and control (AMC) enabled QKDN (QKDNamc) has been studied
in ITU-T Y.3819 in a high-level way. It still needs to realize the autonomic
QoS assurance in QKDN by enhancing the functional architecture of QKDNamc, and
give the reference points and example operational procedures of autonomic QoS
assurance in QKDN. This draft recommendation specifies the overview, functional
architecture enhancement, reference points and example operational procedures
of autonomic QoS assurance for QKDN.

3. New work items agreed at the July 2025 WP4/13 meeting

Draft Supplement Y.supp-QENS-roadmap “Standardization roadmap on quantum
enhanced networking and services for study period 2025” in TD205/WP4 Draft
Supplement to ITU-T Y.3800-series Recommendations provides the standardization
roadmap on quantum enhanced networking and services for study period 2025. It
describes the landscape with related technical areas of quantum technologies
from an ITU-T perspective and list up related standards and publications
developed in standards development organizations (SDOs).

Draft Technical Report YSTR.QKDN-nq-trust “Guideline for integration of QKDN,
UNemc, and trust enabled service provisioning” in TD206/WP4 The current
security model is based on security boundary protection which trusts internal
users in the boundary. It can be venerable when internal user’s account is
compromised or VPN is attacked. Also cyber attacks are increasing and their
attack methods are also advancing including supply chain attack. Also, as cloud
environment are expanding and remote work become routine, on-premise security
policy alone cannot protect. We need a trust security model can fill the gaps
that the current security model lacks. Quantum cryptography alone cannot solve
potential cyberattacks by quantum computers due to the above-mentioned issues.
Integrated security model of QKD, UNemc and trust enabled service provisioning
is essential to protect 5G, 6G, and cloud networks and computing environment
from advanced future cyberattacks. The trust security model of integrated QKD,
UNemc, and trust enabled service provisioning can become a core security model
due to the following: (1) internal and external threat protection by entire
access request authentication, (2) overcoming current perimeter protection
limitation, (3) enhancement of quantum security model enabled by AI based
anomaly detection. This draft technical report presents the standardization
consideration for integration of QKDN, UNemc, and trust enabled service
provisioning for quantum safe security of future networks including 5GA and 6G
networks.

Draft Technical Report YSTR.QKDN-PQQ “Plug-and-play 1 X N Quantum Key
Distribution Module for QKDN” in TD207/WP4 This Technical Report introduces a
cost-effective and scalable Quantum Key Distribution (QKD) solution using a
plug-and-play (P&P) 1×N module to address commercialization challenges caused
by high module costs. The system uses eight tunable lasers at a central server,
shared via WDM and PDM across up to 64 subscriber units, which only handle
reflection and modulation, which significantly reduce device costs. A pilot in
Korea (1×4 configuration) demonstrated stable performance (QBER < 5%), proving
the module’s viability. The technical report suggests incorporating
multi-channel star topology and key performance indicators (e.g., quantum key
generation rate, QBER stability, synchronization accuracy) into the ITU-T SG13
QKDN standard. The technical report offers information to SG13 for
cost-effective, interoperable QKD network (QKDN) deployment and emphasizes the
importance of validating security and operational efficiency in star-topology
networks to support global QKDN standardization.

Draft Technical Report YSTR.QKDN-sms “Technical elements of secure multicast
support in QKDN based on trusted relay” in TD208/WP4 This Technical Report aims
to analyze and investigate the technical elements of QKDN for supporting secure
multicast services based on trusted relay, including the following: –
Feasibility of QKDN for supporting secure multicast; – Technical aspects of
QKDN for supporting secure multicast; – Standardization considerations

Draft Recommendation Y.QKDN-car-fr “Quantum key distribution networks –
Framework of cryptographic application registration” in TD209/WP4 This draft
Recommendation will specify a framework of cryptographic application
registration for QKDNs (quantum key distribution networks).

Draft Recommendation Y.QKDN-ekm “Framework of quantum key distribution network
for supporting edge key management” in TD212/WP4 With the growing demand for
scalable, low-latency and high frequency key requirements—such as IoT, 5G, and
industrial control—it is necessary to enhance QKDN to support secure and
efficient key delivery. Due to the low-latency and high frequency key
requirements of applications, deploying full-scale QKD modules and key
management systems for each service domain is impractical.

To address this, a edge key management architecture is introduced, where edge
key management (EKM) are introduced as lightweight key management entities
deployed near applications. EKMs collaborate with KM to provide localized key
access and caching, while maintaining the key requirements of applications.
Therefore, this Recommendation will carry out standardization work to specify
the requirements, functional model, and operation procedure of QKDN for
supporting edge key management, enabling flexible, efficient, and secure QKDN
support for low-latency and high frequency key requirement.

Draft Recommendation Y.QKDN-qos-req-rs “Requirements of quality of service
assurance for quantum key distribution network resilience” in TD186/WP4 This
Recommendation specifies the requirements for QoS assurance in QKDN resilience.
It focuses on standardizing the application of QoS demands to QKDN resilience,
ensuring the mechanisms for QKDN resilience support consistent service-level
performance during both normal operations and failure conditions, while
aligning with broader QoS assurance objectives.

By building upon the resilience models specified in Y.3815 and the QoS demands
outlined in Y.3806, this Recommendation bridges the gap between general QoS
frameworks and the specific demands of resilience in QKDNs. It addresses the
requirements for ensuring resilience with minimal disruption to key supply and
defines the necessary conditions for seamless key supply during and after
failures. Draft Recommendation Y.QKDN-QOdrQ “Quantum key distribution networks
-Quantitative objectives for delay-related QoS parameters” in TD187/WP4 If the
delay associated with the generation and distribution of cryptographic keys
provided by a QKDN were required to match stringently the level of delay in
modern cryptographic schemes, it would be practically impossible to meet such
requirements over the QKDN exceeding a certain length. However, if the QKDN is
deployed within a range where secure communications are acceptable to the end
users, the corresponding QoS can be regarded as satisfactory.

Therefore, this Recommendation first aims to introduce the user satisfaction
for cryptography service in user network , and subsequently identify the
relationship between the user satisfaction and QKDN QoS, then derive
calculation principle of the quantitative QoS objectives for QKDN that are
capable of meeting those user satisfaction thresholds. This recommendation
describes the quantitative objectives aspects for delay-related QoS parameters
of QKDN. It aims to provide support for the implementation of QKD network to
assure QoS requirements.

4.Conclusion

ITU-T Working Party 4/13 studies the network aspects of QKD. Q16/13 and Q6/13
look forward to close cooperation with ITU-T SG2, SG11, SG15, SG17, ETSI
ISG-QKD, ISO/IEC JTC1/SC27, ISO/IEC JTC3, IETF/IRTF, and relevant groups for
future standardization on QKD networks.