Liaison statement
Work progress on Quantum Key Distribution (QKD) network in ITU-T SG13 (as of July 2025)
Additional information about IETF liaison relationships is available on the
IETF webpage
and the
Internet Architecture Board liaison webpage.
| State | Posted |
|---|---|
| Submitted Date | 2025-09-03 |
| From Group | ITU-T-SG-13 |
| From Contact | tsbsg13@itu.int |
| To Group | OPS |
| To Contacts | Mahesh Jethanandani <mjethanandani@gmail.com> Mohamed Boucadair <mohamed.boucadair@orange.com> |
| Cc | Scott Mansfield <Scott.Mansfield@Ericsson.com> Mahesh Jethanandani <mjethanandani@gmail.com> Mohamed Boucadair <mohamed.boucadair@orange.com> The IETF Chair <chair@ietf.org> |
| Response Contact | gmlee@kaist.ac.kr choits@etri.re.kr kaz.tanikawa@nict.go.jp |
| Technical Contact | gmlee@kaist.ac.kr |
| Action Holder Contacts | Scott Mansfield <Scott.Mansfield@Ericsson.com> |
| Purpose | For information |
| Attachments |
The initial Y.QKDN-QOdrQ “Quantum key distribution networks - Quantitative objectives for delay-related QoS parameters”
The initial Y.QKDN-qos-req-rs “Requirements of quality of service assurance for quantum key distribution network resilience” The initial Y.QDN-ekm “Framework of quantum key distribution network for supporting edge key management” The initial Y.QKDN-car-fr “Quantum key distribution networks – Framework of cryptographic application registration” The initial YSTR.QKDN-sms “Technical elements of secure multicast support in QKDN based on trusted relay” The initial YSTR.QKDN-PQQ “Plug-and-play 1 X N Quantum Key Distribution Module for QKDN” The initial YSTR.QKDN-nq-trust “Guideline for integration of QKDN, UNemc, and trust enabled service provisioning” The initial Y.supp-QENS-roadmap “Standardization roadmap on quantum enhanced networking and services for study period 2025” The updated Y.QKDN-qos-auto-fa “Quantum key distribution networks – Functional architecture enhancement for autonomic quality of service assurance” The updated Y.QKDN-nq-qos-fa “Integration of quantum key distribution network and user network supporting end-to-end modern cryptography services – functional architecture for quality of service assurance” The updated Y.QKDN-GQT “Generic common Quantum Key Distribution Network Template” The updated Y.QKDN-TLS “Quantum Key Distribution integration with Transport Layer Security 1.3” The updated Y.QKDN-safr “Quantum key distribution networks – Framework for service awareness” The updated Y.QKDN-orfr “Quantum key distribution networks - framework for orchestration” The updated Y.supp.QKDNmc-UC “Use cases of multi-point coordination in QKDN” The updated Y.QKDN-IPsec-fr “Framework for integration of quantum key distribution and IPSec” The updated Y.QKDN-nq-fa “Integration of quantum key distribution network and user network supporting end-to-end modern cryptography services - functional architecture” The updated Y.supp.TC-QN “Technical considerations towards Quantum Network” The consented Y.3829 (Y.QKDNi-qos-fa) “Quantum key distribution networks interworking – Functional architecture for quality of service assurance” The consented Y.3830 (Y.QKDN-rsff) “Quantum key distribution networks – procedures for key supply protection and recovery for resilience |
| Body |
Abstruct: This serves to communicate the progress of work on Quantum Key Distribution (QKD) network in ITU-T SG13 (as of July 2025). ITU-T Working Party 4/13 is pleased to inform you of our progress on Quantum Key Distribution (QKD) topics. SG13 has published 28 Recommendations and 6 Supplements on QKDN as follows: -Recommendation ITU-T Y.3800 “Overview on networks supporting quantum key distribution”; -Recommendation ITU-T Y.3801 “Functional requirements for quantum key distribution networks”; -Recommendation ITU-T Y.3802 “Quantum key distribution networks – Functional architecture”; -Recommendation ITU-T Y.3803 “Quantum key distribution networks – Key management”; -Recommendation ITU-T Y.3804 “Quantum key distribution networks - Control and management”; -Recommendation ITU-T Y.3805 “Quantum Key Distribution Networks - Software Defined Networking Control”; -Recommendation ITU-T Y.3806 “Quantum key distribution networks - Requirements for quality of service assurance”; -Recommendation ITU-T Y.3807 “Quantum Key Distribution networks - QoS parameters”; -Recommendation ITU-T Y.3808 “Framework for integration of quantum key distribution network and secure storage network”; -Recommendation ITU-T Y.3809 “A role-based model in quantum key distribution networks deployment”; -Recommendation ITU-T Y.3810 “Quantum key distribution network interworking - Framework”; -Recommendation ITU-T Y.3811 “Quantum key distribution networks - Functional architecture for quality of service assurance”; -Recommendation ITU-T Y.3812 “Quantum key distribution networks - Requirements for machine learning based quality of service assurance”; -Recommendation ITU-T Y.3813 “Quantum key distribution networks interworking – functional requirements”; -Recommendation ITU-T Y.3814 “Quantum key distribution networks - functional requirements and architecture for machine learning enablement”; -Recommendation ITU-T Y.3815 “Quantum key distribution networks - overview of resilience”; -Recommendation ITU-T Y.3816 “Quantum key distribution networks - Functional architecture enhancement of machine learning based quality of service assurance”; -Recommendation ITU-T Y.3817 “Quantum key distribution networks interworking - Requirements of quality of service assurance”; -Recommendation ITU-T Y.3818 “Quantum key distribution networks interworking – architecture”; -Recommendation ITU-T Y.3819 “Quantum key distribution networks - requirements and architectural model for autonomic management and control enablement”; -Recommendation ITU-T Y.3820 “Quantum Key Distribution Network Interworking - Software Defined Networking Control”; -Recommendation ITU-T Y.3821 “Quantum key distribution networks - requirements for resilience”; -Recommendation ITU-T Y.3822 “Quantum key distribution networks - Requirements for autonomic quality of service assurance”; -Recommendation ITU-T Y.3824 “Quantum key distribution network federation - Reference models”; -Recommendation ITU-T Y.3825 “Integration of quantum key distribution network and time-sensitive network - framework”; -Recommendation ITU-T Y.3826 “ Integration of quantum key distribution network and user network supporting end-to-end modern cryptography services - framework”; -Recommendation ITU-T Y.3827 “Quantum key distribution networks - Measurement methodology for QoS parameters”; -Recommendation ITU-T Y.3828 “Integration of quantum key distribution network and user network supporting end-to-end modern cryptography services – requirements for quality of service assurance”; -Supplement ITU-T Y.Sup70 to Y.3800-series “Quantum Key Distribution Networks - Applications of Machine Learning”; -Supplement ITU-T Y.Sup74 to Y.3800-series “Standardization roadmap on Quantum Key Distribution Networks”; -Supplement ITU-T Y.Sup75 to Y.3800-series “Quantum key distribution networks - Quantum-Enabled Future Networks”; -Supplement ITU-T Y.Sup79 to Y.3800-series “Quantum key distribution networks – Role in end-to-end cryptographic services with non-quantum cryptography”; -Supplement ITU-T Y.Sup80 to Y.3800-series “Use cases of quantum key distribution networks”; -Supplement ITU-T Y.Sup89 to Y.3800-series “Analysis of time synchronization in Quantum Key Distribution Networks”. 1.The items consented at the July 2025 WP4/13 meeting Draft new Recommendation ITU-T Y.3830 (Y.QKDN-rsff) “Quantum key distribution networks – procedures for key supply protection and recovery for resilience” in TD192/WP4 Recommendation ITU-T Y.3830 specifies procedures for key supply protection and recovery to enable seamless key supply even in the case of failures. It describes the configurations and operational procedures for the protection and recovery of key supply. Draft new Recommendation ITU-T Y.3829 (Y.QKDNi-qos-fa) “Quantum key distribution networks interworking – Functional architecture for quality of service assurance” in TD181-R1/WP4 Recommendation ITU-T Y.3829 specifies the functional architecture of quality of service (QoS) assurance for the quantum key distribution network interworking (QKDNi). 2.Revised ongoing work items after March 2025 SG13 meeting Draft Supplement ITU-T Y.supp.TC-QN “Technical considerations towards Quantum Network” in TD193/WP4 Quantum network is expected to provide new applications based on fundamental quantum mechanics such as entanglement, superposition and non-cloning, and those are not possible with non-quantum networks (e.g. conventional digital networks). This Supplement aims to identify technical considerations for quantum network. Draft Recommendation Y.QKDN-nq-fa “Integration of quantum key distribution network and user network supporting end-to-end modern cryptography services – functional architecture” in TD194/WP4 In order to support QKD service to mobile objects (i.e., autonomous car, mobile phone, etc.), it is challenging to establish and maintain a quantum channel stably with them and supporting KSA-keys. Such challenge calls for a solution to integrate the QKDN and user networks supporting modern cryptography services. Y.3826 addresses these challenges and specifies several architectural models, requirements, and a framework architecture for the integration. This draft Recommendation specifies functional architecture for integration of QKDN and UNemc. It will define a functional architecture, functions, reference points and operational procedures. Draft Recommendation ITU-T Y.QKD-IPSec-fr “Framework for integration of quantum key distribution and IPSec” in TD195/WP4 With the diversity of network services and the demand for security, it is necessary to use QKD to ensure the security of user networks. Therefore, it is promising to implement standardization work for the integration of QKDN and user networks. Combining QKD with IPsec can achieve better end-to-end encryption. QKD provides secure key distribution based on quantum mechanics to resist future quantum computing attacks. IPsec provides traditional encryption and authentication mechanisms. By combining QKD and IPsec, not only does it achieve strong defence against quantum computing attacks, but it also provides comprehensive protection from classical encryption and identity verification. This Recommendation specify the framework for integration of QKD and IPSec, including overview, application modes, requirements, reference model and overall operational procedures of QKD and IPSec integration. Draft Supplement ITU-T Y.supp.QKDNmc-UC: “Use cases of multi-point coordination in QKDN” in TD196/WP4 ITU-T has approved a series of QKDN related Recommendations, which consider the single-node service model where a user node is supplied with keys by a single QKD node, and focus on maximizing the service provision capability of the single QKD node. In practical applications, it can be exceedingly challenging for a single QKD node to handle highly concurrent key supply requests while maintaining an acceptable service-level. This Supplement considers the multi-point coordination in QKDN, also called QKDNmc. This is a service model where two or more QKD nodes are associated with a user node and coordinated by QKDN to provide superior key supply service. It aims to further improve the service provision capability and resource utilization of the QKDN, and can be seen as the supplement and enhancement to these Recommendations. Focusing on QKDNmc, this document will discuss related mechanisms and use cases. Draft Recommendation ITU-T Y.QKDN-orfr “Quantum key distribution networks – framework for orchestration” in TD197/WP4 Recommendation ITU-T Y.QKDN-orfr specifies an orchestration framework to enhance resource efficiency of quantum key distribution network (QKDN). It describes QKDN orchestration with an overview, requirements, reference models, and overall operational procedures. Draft Recommendation ITU-T Y.QKDN-safr "Quantum key distribution networks - Framework for service awareness" in TD198/WP4 Quantum key distribution network (QKDN) can be regarded as a kind of cryptographic infrastructure since it supports more and more cryptographic applications, such as video conference, VoLTE, email, etc. Diversified cryptographic applications put forward differentiated service requirements for QKDN, including low deterministic latency, low jitter, high deterministic availability, and guaranteed key supplies and so on. With the separation mechanism of QKDN and cryptographic services, the underlying QKDN network cannot perceive service characteristic information, it is difficult to identify the SLA guarantee requirements of services. Therefore, it is necessary to consider service awareness function for QKDN with the guidance of service awareness, service scheduling and service differentiation which can aware users, service requirements, QKDN resource and service status and so on in real time, so as to provide differentiated services. Meanwhile, it’s valuable to carry out necessary standardization works. This Recommendation specifies scenarios, requirements and functional model of service awareness for QKDN. Draft Recommendation Y.QKDN-TLS “Quantum Key Distribution integration with Transport Layer Security 1.3” in TD199/WP4 This Draft Recommendation specifies use cases, high-level requirements and reference models for quantum key distribution (QKD) integration with transport layer security 1.3 (TLS 1.3). Draft Recommendation Y.QKDN-GQT “Generic common Quantum Key Distribution Network Template” in TD200/WP4 For network operators to realize secure, stable, efficient, and robust operations of their existing networks while implementing quantum key distribution network (QKDN), draft Recommendation ITU-T Y.QKDN-GQT specifies Generic common Quantum Key Distribution Template (GQT). GQT provides the standardised list of attributes that can characterise a type of QKDN. Draft Recommendation Y.QKDN-da “Quantum key distribution networks - Dependability assessment” in TD182/WP4 With the increasing services supported by QKDN, and various requirements for the interoperation and coordination between QKDN and corresponding user networks, it is urgent to discuss QKDN robustness and carry out necessary standardization works. QKDN users expect continuously stable keys supply supported by QKDN, which brings strict requirements for robust QKDN operation. Network dependability assessment of QKDN is to evaluate the availability performance and its influencing factors, such as reliability, maintainability of network functions and components, quality of connections, so as to avoid destructive failures in QKDN. Besides, it can improve the level of effectiveness, precision and automation of the QKDN management in QKDN operation and maintenance. This Recommendation will carry out standardization study and specify QKDN dependability assessment conceptual model, indicators, and dependability assessment process. Draft Recommendation Y.QKDN-nq-qos-fa “Integration of quantum key distribution network and user network supporting end-to-end modern cryptography services – functional architecture for quality of service assurance” in TD183/WP4 It is challenging to integrate a quantum key distribution network (QKDN) and a user network to support end-to-end modern cryptography services to users including mobile objects (i.e., autonomous car, mobile phone, etc.). [b-ITU-T Supplement 79 to Y.3800-series] addresses this issue and describes several use cases to deliver KSA-keys generated from QKDNs to the user applications by means of modern cryptography (e.g., PKI technology) with PQC algorithms. It also identifies various issues to be addressed for standardization. Technical implications from the three end-to-end use cases identified are related to control and management, and QoS aspects. Especially, Y.3828 addresses QoS assurance specific aspects in terms of reference models and requirements. This draft Recommendation specifies functional architecture, associated capabilities, reference points, and operational procedure of QoS assurance for integrated QKDN and UNemc based on the defined reference models and requirements in Y.3828. Draft Recommendation Y.QKDN-qos-auto-fa “Quantum key distribution networks – Functional architecture enhancement for autonomic quality of service assurance” in TD165/WP4 One of the challenges of the QKDN is to assure the network performance and different QoS/QoE requirements of different application scenarios in an autonomic way. The autonomic ability for QoS in QKDN will support the seamless intelligent decision-making feedback loop of precise monitoring of status of managed QKDN resources, intelligent decision-making and necessary policy-generation based on the monitored QKDN QoS information, and open programmable enforcement of generated policies. The architecture of autonomic management and control (AMC) enabled QKDN (QKDNamc) has been studied in ITU-T Y.3819 in a high-level way. It still needs to realize the autonomic QoS assurance in QKDN by enhancing the functional architecture of QKDNamc, and give the reference points and example operational procedures of autonomic QoS assurance in QKDN. This draft recommendation specifies the overview, functional architecture enhancement, reference points and example operational procedures of autonomic QoS assurance for QKDN. 3. New work items agreed at the July 2025 WP4/13 meeting Draft Supplement Y.supp-QENS-roadmap “Standardization roadmap on quantum enhanced networking and services for study period 2025” in TD205/WP4 Draft Supplement to ITU-T Y.3800-series Recommendations provides the standardization roadmap on quantum enhanced networking and services for study period 2025. It describes the landscape with related technical areas of quantum technologies from an ITU-T perspective and list up related standards and publications developed in standards development organizations (SDOs). Draft Technical Report YSTR.QKDN-nq-trust “Guideline for integration of QKDN, UNemc, and trust enabled service provisioning” in TD206/WP4 The current security model is based on security boundary protection which trusts internal users in the boundary. It can be venerable when internal user’s account is compromised or VPN is attacked. Also cyber attacks are increasing and their attack methods are also advancing including supply chain attack. Also, as cloud environment are expanding and remote work become routine, on-premise security policy alone cannot protect. We need a trust security model can fill the gaps that the current security model lacks. Quantum cryptography alone cannot solve potential cyberattacks by quantum computers due to the above-mentioned issues. Integrated security model of QKD, UNemc and trust enabled service provisioning is essential to protect 5G, 6G, and cloud networks and computing environment from advanced future cyberattacks. The trust security model of integrated QKD, UNemc, and trust enabled service provisioning can become a core security model due to the following: (1) internal and external threat protection by entire access request authentication, (2) overcoming current perimeter protection limitation, (3) enhancement of quantum security model enabled by AI based anomaly detection. This draft technical report presents the standardization consideration for integration of QKDN, UNemc, and trust enabled service provisioning for quantum safe security of future networks including 5GA and 6G networks. Draft Technical Report YSTR.QKDN-PQQ “Plug-and-play 1 X N Quantum Key Distribution Module for QKDN” in TD207/WP4 This Technical Report introduces a cost-effective and scalable Quantum Key Distribution (QKD) solution using a plug-and-play (P&P) 1×N module to address commercialization challenges caused by high module costs. The system uses eight tunable lasers at a central server, shared via WDM and PDM across up to 64 subscriber units, which only handle reflection and modulation, which significantly reduce device costs. A pilot in Korea (1×4 configuration) demonstrated stable performance (QBER < 5%), proving the module’s viability. The technical report suggests incorporating multi-channel star topology and key performance indicators (e.g., quantum key generation rate, QBER stability, synchronization accuracy) into the ITU-T SG13 QKDN standard. The technical report offers information to SG13 for cost-effective, interoperable QKD network (QKDN) deployment and emphasizes the importance of validating security and operational efficiency in star-topology networks to support global QKDN standardization. Draft Technical Report YSTR.QKDN-sms “Technical elements of secure multicast support in QKDN based on trusted relay” in TD208/WP4 This Technical Report aims to analyze and investigate the technical elements of QKDN for supporting secure multicast services based on trusted relay, including the following: – Feasibility of QKDN for supporting secure multicast; – Technical aspects of QKDN for supporting secure multicast; – Standardization considerations Draft Recommendation Y.QKDN-car-fr “Quantum key distribution networks – Framework of cryptographic application registration” in TD209/WP4 This draft Recommendation will specify a framework of cryptographic application registration for QKDNs (quantum key distribution networks). Draft Recommendation Y.QKDN-ekm “Framework of quantum key distribution network for supporting edge key management” in TD212/WP4 With the growing demand for scalable, low-latency and high frequency key requirements—such as IoT, 5G, and industrial control—it is necessary to enhance QKDN to support secure and efficient key delivery. Due to the low-latency and high frequency key requirements of applications, deploying full-scale QKD modules and key management systems for each service domain is impractical. To address this, a edge key management architecture is introduced, where edge key management (EKM) are introduced as lightweight key management entities deployed near applications. EKMs collaborate with KM to provide localized key access and caching, while maintaining the key requirements of applications. Therefore, this Recommendation will carry out standardization work to specify the requirements, functional model, and operation procedure of QKDN for supporting edge key management, enabling flexible, efficient, and secure QKDN support for low-latency and high frequency key requirement. Draft Recommendation Y.QKDN-qos-req-rs “Requirements of quality of service assurance for quantum key distribution network resilience” in TD186/WP4 This Recommendation specifies the requirements for QoS assurance in QKDN resilience. It focuses on standardizing the application of QoS demands to QKDN resilience, ensuring the mechanisms for QKDN resilience support consistent service-level performance during both normal operations and failure conditions, while aligning with broader QoS assurance objectives. By building upon the resilience models specified in Y.3815 and the QoS demands outlined in Y.3806, this Recommendation bridges the gap between general QoS frameworks and the specific demands of resilience in QKDNs. It addresses the requirements for ensuring resilience with minimal disruption to key supply and defines the necessary conditions for seamless key supply during and after failures. Draft Recommendation Y.QKDN-QOdrQ “Quantum key distribution networks -Quantitative objectives for delay-related QoS parameters” in TD187/WP4 If the delay associated with the generation and distribution of cryptographic keys provided by a QKDN were required to match stringently the level of delay in modern cryptographic schemes, it would be practically impossible to meet such requirements over the QKDN exceeding a certain length. However, if the QKDN is deployed within a range where secure communications are acceptable to the end users, the corresponding QoS can be regarded as satisfactory. Therefore, this Recommendation first aims to introduce the user satisfaction for cryptography service in user network , and subsequently identify the relationship between the user satisfaction and QKDN QoS, then derive calculation principle of the quantitative QoS objectives for QKDN that are capable of meeting those user satisfaction thresholds. This recommendation describes the quantitative objectives aspects for delay-related QoS parameters of QKDN. It aims to provide support for the implementation of QKD network to assure QoS requirements. 4.Conclusion ITU-T Working Party 4/13 studies the network aspects of QKD. Q16/13 and Q6/13 look forward to close cooperation with ITU-T SG2, SG11, SG15, SG17, ETSI ISG-QKD, ISO/IEC JTC1/SC27, ISO/IEC JTC3, IETF/IRTF, and relevant groups for future standardization on QKD networks. |