Search papers, labs, and topics across Lattice.
This paper introduces a sentinel-based coordination protocol for maintaining the availability of quantum-safe IPsec tunnels during QKD infrastructure outages. By integrating X25519, ML-KEM, and ETSI GS QKD 014 keys through a multiple key exchange mechanism, the proposed solution allows for graceful degradation of service, ensuring continuous operation even when QKD key delivery fails. Experimental evaluations demonstrate that the hybrid key establishment mechanism can sustain tunnel functionality without interruption during complete key management entity outages, with only a modest increase in authentication latency.
Quantum-safe IPsec tunnels can now remain operational even when QKD infrastructure fails, ensuring uninterrupted secure communication.
Quantum-safe IPsec through hybrid key establishment is practical, but creates a critical operational challenge: how to maintain tunnel availability when the QKD infrastructure becomes unavailable. In this paper, we present the design, implementation, and experimental evaluation of a quantum-safe key establishment mechanism for an IPsec tunnel that combines X25519, ML-KEM, and ETSI GS QKD 014 keys through the RFC 9370 multiple key exchange mechanism, and that degrades gracefully when the QKD key delivery fails. Our open-source StrongSwan plugin uses a sentinel-based coordination protocol, thereby permitting us to complete the handshake even if the QKD leg fails, instead of aborting, restoring the QKD share at the next rekey. On a testbed connected to a metropolitan QKD link over 33 km of deployed fiber, we evaluated five configurations, from a classical X25519 with RSA baseline to a hybrid one that adds ML-KEM-1024 and a QKD key. The full hybrid authentication costs 103 ms against 61 ms for the baseline, the QKD retrieval itself adds only about 7 ms. Failure injection experiments confirm that the tunnel survives a complete KME outage without any interruption of the protected traffic.