← Latest papers
⚡ electrical engineering

Multi-Path Quantum Key Distribution Transport: A Four-Order Mathematical Framework with Provable Zero-Interruption Under Stated Provisioning Conditions

This paper introduces a mathematically rigorous, four-order transport framework for metropolitan multi-path Quantum Key Distribution networks that guarantees provable zero service interruption and end-to-end compositional security through optimized traffic allocation, large-deviation buffer dimensioning, and One Pass Erasable Storage, validated by simulations across diverse attack scenarios.

Original authors: ziwen wang

Published 2026-07-29
📖 1 min read☕ Coffee break read

Original authors: ziwen wang

Original paper licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Technical Summary: Multi-Path Quantum Key Distribution Transport

Problem Statement
Current Metropolitan Quantum Key Distribution (QKD) networks, such as the Beijing–Shanghai backbone and the Tokyo QKD testbed, face three structural bottlenecks preventing their transition from experimental links to usable network services:

  1. Single-Path Rate Asymmetry: Individual QKD links generate keys at rates orders of magnitude below classical throughput demands. Aggregating raw keys from multiple paths without rigorous per-path security processing introduces information-theoretic leakage.
  2. Standby Key Pool Vulnerability: Existing networks rely on standby key pools to absorb fluctuations, introducing a non-zero probability of static key theft and breaking forward secrecy.
  3. Incompatibility with Trusted Relays: Standard transport protocols (e.g., TCP/IP, MPTCP) are structurally incompatible with the hop-by-hop key management required by trusted-relay QKD topologies, which extend range beyond the ~100 km fiber limit.

Methodology: A Four-Order Mathematical Framework
The paper proposes a complete transport layer for multi-path QKD networks built upon a progressive four-order mathematical framework. This framework integrates physical layer mechanisms, transport layer protocols, and rigorous theoretical proofs.

  • Layer 0 (Physical): Utilizes BB84 with decoy states over KK independent fiber-optic paths. Innovations include WDM three-mode control (Power/Normal/Throttling) based on hot-pool levels, multi-address pool rotation (16 addresses) to mitigate DoS, and delay baseline tamper detection to identify intercept-resend attacks.
  • Layer 1 (Transport): Manages key inventory via a "Hot Pool" (real-time) and a "Cold Pool" (OPES). It employs dynamic α\alpha hybrid encryption (mixing Quantum OTP and Post-Quantum Kyber-768), SegmentGroup-based selective retransmission to save key material, and matrix-based transmission for 2D data.
  • Layer 2 (Mathematical Framework): The core theoretical engine consisting of four theorems:
    1. Theorem 1 (Decoupling): Proves via Jensen's inequality that independent per-path security processing yields strictly more secure key (KindepKconcatK_{indep} \ge K_{concat}) than physical concatenation of raw keys.
    2. Theorem 2 (Allocation): Derives a closed-form "shadow-price" solution for optimal traffic allocation (wi1/λiw^*_i \propto 1/\lambda_i), dynamically routing traffic based on marginal key consumption costs.
    3. Theorem 3 & 3' (Buffer Dimensioning): Uses Large Deviation Principles (LDP) to calculate the minimum hot-buffer capacity for thin-tailed demand. Theorem 3' extends this to subexponential heavy-tailed (Pareto) demand, providing asymptotic bounds where standard LDP fails.
    4. Theorem 4 (Zero-Interruption): Defines One-Pass Erasable Storage (OPES) with physical axioms (write-once, read-once, unidirectional flow). It proves that under specific provisioning conditions, the probability of service interruption is identically zero (Pinterruption=0P_{interruption} = 0).
  • Layer 3 (Application): Allows applications to select encryption strength via the α\alpha parameter, balancing pure quantum security against post-quantum computational efficiency.

Key Contributions

  1. First Complete Transport Layer: The paper presents the first transport layer specifically designed for multi-path QKD networks, addressing the gap between physical key generation and application-layer service.
  2. Provable Zero-Interruption: Through the OPES cold pool and Theorem 4, the framework offers a deterministic guarantee of zero service interruption, transforming resilience from a probabilistic metric (e.g., 99.999%) to a physical certainty.
  3. Composable Security Chain: The authors establish a formal security theorem (Theorem 5) chaining Shor–Preskill reduction, multi-path composition, and hybrid encryption to achieve an end-to-end security bound of ϵtotal108\epsilon_{total} \le 10^{-8}.
  4. Information-Theoretic Forward Secrecy: The OPES "read-once" axiom provides physical forward secrecy (I(Kpre;Opost)=0I(K_{pre}; O_{post}) = 0), which is stronger than computational forward secrecy as it relies on physical erasure rather than hardness assumptions.
  5. Defense-in-Depth Architecture: A four-layer defense chain (address rotation, matrix restoration, delay detection, OPES) is formalized, showing that combined bypass probabilities are orders of magnitude lower than single-layer defenses.

Results
The framework was validated via a discrete-event simulation on a K=4K=4 path, 3-hop topology over 14,400 simulated seconds (four 3,600-second scenarios: baseline, DoS jamming, delay intercept-resend, and combined attacks).

  • Interruption Rate: Zero service interruptions were observed across all scenarios.
  • Buffer Dynamics: The hot pool maintained a minimum level of 10.2%\ge 10.2\% of capacity. The OPES cold pool utilization remained low (0.65% over 3,600s), confirming the efficiency of the provisioning model.
  • Attack Resilience:
    • DoS hit rates matched the theoretical 1/N1/N bound (6.25% for N=16N=16).
    • Delay-based tamper detection achieved 100% sensitivity with zero false positives.
    • The hybrid encryption scheme successfully adapted to key supply fluctuations without service degradation.
  • Scalability: Throughput scaled nearly linearly with the number of paths (K=116K=1 \to 16), reaching ~150 kbps at K=16K=16, sufficient for real-time AES-256 key refreshing.

Significance
The paper claims to provide the first mathematically rigorous transport layer for multi-path QKD, moving the field from "QKD links exist" to "QKD is a usable network service." By establishing a provable link between physical axioms (OPES) and network performance (zero interruption), the work offers a blueprint for deploying robust, multi-hop QKD networks on existing metropolitan fiber infrastructure. The framework is presented as compatible with any QKD protocol satisfying specific assumptions (A1–A4) and serves as a complementary approach to Post-Quantum Cryptography (PQC), offering information-theoretic security for critical data segments while utilizing PQC for bulk traffic.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →