Issue #5/2025
A. V. Gleim, K. S. Samburskaya, K. V. Smirnov
Trunk and Regional Quantum Network Architecture
Trunk and Regional Quantum Network Architecture
DOI: 10.22184/1993-7296.FRos.2025.19.5.348.362
The article considers the applicable approaches to the implementation of quantum communications networks in Russia, its architecture, including any relations between the individual elements or levels in the context of available statutory regulations of the quantum communications industry and its common use. The main relevant concepts and definitions are provided.
The article considers the applicable approaches to the implementation of quantum communications networks in Russia, its architecture, including any relations between the individual elements or levels in the context of available statutory regulations of the quantum communications industry and its common use. The main relevant concepts and definitions are provided.
Теги: qkd quantum receiver qkd transmitter quantum communications quantum key distribution (qkd) quantum network quantum-protected communication network квантовая сеть квантовое распределение ключей квантовозащищенная сеть связи квантовые коммуникации квантовый передатчик квантовый приемник
Trunk and Regional Quantum Network Architecture
A. V. Gleim , K. S. Samburskaya, K. V. Smirnov
Department of Quantum Communications, Russian Railways OJSC, Moscow, Russia
Emperor Alexander I Saint-Petersburg State Transport University, Saint-Petersburg, Russia
The article considers the applicable approaches to the implementation of quantum communications networks in Russia, its architecture, including any relations between the individual elements or levels in the context of available statutory regulations of the quantum communications industry and its common use. The main relevant concepts and definitions are provided.
Keywords: quantum communications, quantum key distribution (QKD), quantum network, quantum-protected communication network, QKD transmitter, QKD quantum receiver
Article received: July 01, 2025
Article accepted: July 25, 2025
Introduction
The quantum communications have long ceased to be just a theoretical concept.The quantum communications in Russia are at the stage of active development and commercial evolvement and have significant potential for its common use expansion [1–2]. At present, several areas of development of the quantum communications market are being implemented on a simultaneous basis: the development and improvement of quantum communications systems is continuing, the construction projects of quantum communication networks are being implemented, the business models for service provision using the quantum communications are being developed. Not only the researchers and developers, but also various engineers, designers, and process managers, as well as any persons who are directly interested in the technology introduction actively participate in the work.
The article considers the specific features of quantum communications in terms of applied aspects of quantum communication networking, its use and integration with the available telecommunications infrastructure. The article is devoted to the analysis of engineering principles of quantum communication networking, including its architecture, features of the components and devices in such networks, requirements for the management and monitoring of quantum networks.
Broadly speaking, the quantum networks can be considered as the secured automated systems to be complied with the statutory regulations governing the arrangement of secure data exchange and transmission [3]. Such systems in the field of information security are regulated by the Federal Service for Technical and Export Control (hereinafter referred to as the FSTEC). Therefore, the implementation of quantum communications is, above all, a matter of information security. In addition, to arrange the data transmission systems that are limited, regulated and governed by the federal legislation, it is necessary to provide for these data security by the specialized cryptographic information protection facilities (hereinafter referred to as the CIPF), with the fulfillment of requirements related to the data protection category and network management [4]. The development of quantum communications within the paradigm of practical communication system formation leads to the need to change the conventional terminology in the scientific community used for the quantum networks and quantum communications.
An important stage in the development of quantum communications has now been passed: the Federal Agency for Technical Regulation and Metrology has approved and officially introduced the statutory regulations including the general provisions, terms and definitions in the field of quantum communications, the quantum Internet of Things, architecture and interfaces to connect the typical software and hardware complex for management of keys developed by a quantum key distribution network [5–8]. This article describes the main provisions of the specified preliminary national standards of the Russian Federation (hereinafter referred to as the PNST).
1. Quantum-secure communication network
The quantum networks (quantum communication networks) shall mean the quantum-secure communication networks (hereinafter referred to as the QSCN) where the protected or encrypted information is transmitted using the quantum keys and/or quantum-secure keys. In this case, the quantum key distribution network (hereinafter referred to as the QKD network) is one of the QSCN components. The QSCN ensures the secure data transmission using the CIPFs, namely the users receiving cryptographic keys from the QKD network [5, 6].
There are five levels in the architecture of quantum-secure communication networks (Fig. 1). Substantially, these are five logical layers of hierarchy or five logical problems to be solved to develop a comprehensive QSCN infrastructure.
The first level is the quantum key level (hereinafter referred to as the QK). At this level, the QKs are generated between the modules that are the part of one QKD system and are located in various QSCN nodes. The layout and connection diagram of the QKD transmitters and receivers in the QKD network is determined with due regard to the selected QKD protocol. The second level is the key management level, represented by the key management system (hereinafter referred to as the KMS). In the KMS, the QKs are issued after being generated in the QKD system modules. The key management system, usually implemented by the encoders, is a link in the QSCN between the equipment that generates the QKs and the key information users, namely the user encoders. The quantum-secure keys are also generated in the KMS (hereinafter referred to as the QSK). The third level is the monitoring level that ensures the service quality and delivery to the user; as a typical analogy, it is possible to indicate routing, management, monitoring, SLA ensuring and all activities performed by the communications network engineering. The level of QKD network management and monitoring ensures control of the devices included in the QKD network and their status monitoring. The management process can be carried out both on a centralized basis, for example, using one management and monitoring server, and on a decentralized basis, including the separate management and monitoring systems for the QKD network devices.
In general, the QSCN is an external network in relation to the QKD network. In the QSCN network, in addition to the functional levels of the QKD network, two upper levels are implemented: the QSCN data transmission level required for the developed applied transport infrastructure, and the QSCN control and monitoring level.
Various options for the architecture and topology of quantum networks can be implemented due to the combination of quantum components. The design solutions being developed have ideological differences in the implementations of key circuits and equipment layout methods by various manufacturers, methods of unification and division into the QKD modules, routing algorithms and approaches to the network management principles. Based on the final task, the certain decisions are made during the design process on how the architecture will meet the requirements of redundancy and reliability.
2. Quantum key level
The task of preparing the quantum key level for the simplest architecture of a point-to-point quantum key distribution network is essentially reduced to constructing a set of channels (a quantum channel, a synchronization channel, and a service channel) to ensure the data exchange process between two subscribers of the QKD network (Fig. 2).
In principle, the QKD equipment can be represented in the form of interacting sender and receiver modules, while the quantum channel is implemented by an optical part, including a source and receiver of quantum states.
To implement the quantum key distribution protocol, it is necessary to ensure synchronous operation of the equipment in the sender and receiver modules. The protocols and constructions principles of the quantum communication equipment correspond to those adopted for the synchronous digital hierarchy equipment (hereinafter referred to as the SDH). The quantum key distribution protocols cannot operate without an explicitly allocated synchronization channel that allows the signal interpretation in the quantum channel. The service channel is used to transmit the resulting receiver’s sequences generated after interpreting the sender’s messages. Thus, the joint operation of three channels allows developing the quantum keys used in the network encryption and data transmission processes.
The first simple case of scaling a quantum channel at the quantum key level in the QKD network is a branch implementing the connection of the sender module with several subscribers through a tapping point (Fig. 3) [5].
The available switch in the communication line affects the protocols and algorithm operation inside the QKD equipment. In fact, the switch addition can be regarded as additional losses in the communication line. In terms of encryption technology, scaling a quantum channel means an increase in the number of subscribers and the need to provide for their possible differentiation and identification in the MAC codes used for the QKD equipment. This approach can be extrapolated to the typical and understandable case of network arrangement with the passive optical couplers that allows for network scaling. In such a case, switching and communication between the subscribers are ensured through synchronization of the sender and a set of recipients, sharing of the clock frequency and the forming pulse.
Another option for scaling a quantum network can be implemented using an optical combiner instead of a switch. If the first approach is actively used in the available networks, the second one, despite being mentioned in the regulatory documents [5], is still at the development stage, and the equipment required for such an approach has not been fully implemented.
3. Key management level
In practice, the QKD systems use the attenuated optical laser pulses as a single-photon source. The quantum protocols are applied in such a way that in the actual systems the number of errors and inaccuracies related to the hardware implementation is about 1%, and they can be mathematically precisely extracted from the report results without affecting the security. The actual practical systems use the phase (the most common approach) or polarizing (less common, but also frequent) coding.
The main problem of quantum communications is the preservation of very weak power messages (single-photon), when passing through the quantum communication channel. The coding preservation for a weakened signal is the main task that is considered by the researchers and manufacturers of the QKD systems are, and up to 90% of the efforts of the developers of quantum communication equipment are directed at its solution.
The maximum optical budget for losses in the communication line (quantum channel) for the successful QKD system operation is rather limited, on the one part, by the components used, and on the other part, by the requirement to the limited power of the attenuated signal (the maximum value of the number of photons in a radiation pulse) and is about 20–23 dB. Having considered the maintenance margin and requirements for operational reliability, the actual attenuation designed during the QKD network construction is 15–16 dB that ensures possible transmission of a quantum signal over the distances of approximately 40–70 km, depending on the infrastructure condition (usually the standard single-mode optical fiber and its intermediate connections).
It should be noted that at present, the maximum distribution range values for the quantum cryptographic key were obtained in the research articles [9–10] using an untrusted central node and a twin-field protocol that additionally required a detailed study and strength analysis, as well as any limitations due to the actual service peculiarities.
Globally, there are several possibilities for increasing the range of a quantum channel; on a terminological basis, they are generalized by the concept of a quantum repeater (Fig. 4). Historically, a quantum repeater was considered as a very specific device. However, in the regulatory documents within the framework of standardization, any approach and any device that allows the signal regeneration, including restoration of its reception and transmission, are called a “repeater” [6]. The following options for implementing the quantum repeater are considered: the first one is an equipment using the reception and transmission mechanisms, the second one is a certain idealized device similar to an amplifier in the typical communication network, but for the quantum states (at the moment, its engineering implementation is absent) and the third option is satellite communication, providing interaction between the network members via the low-altitude satellites [11].
In the real-world scenarios, a circuit with a receiver, a transmitter and an intermediate node or several intermediate nodes (quantum repeaters) is used for an extended QKD network. In the intermediate nodes, the information is decoded, the optical signal is converted into an electrical signal, the electrical signal is re-encoded and converted into an optical signal, and then transmitted to the next intermediate node via the quantum channel. In this case, the service channel remains the same for all segments of the quantum key level, ensuring logical consistency of the QKD network.
The quantum network with such intermediate nodes is generated by the separate spans or sections, each of which consists of a pair of devices that forms the quantum keys randomly, based on the physical random number generators. In order to provide some common keys for various subscribers participating in the data exchange process, a trusted intermediate node (hereinafter referred to as the TIN) is formed, that is the name most often used by the QKD equipment manufacturers, or a key management module (hereinafter referred to as the KMM), that is the name indicated in the PNST.
The TIN is operated as follows (Fig. 5). A pairwise key QK12 is generated in the first segment of the QKD network between the nodes No.1 and No.2. A key QK23 is generated in the second segment of the QKD network between the nodes No.2 and No.3. The key QK12 protected using the key QK23 is transmitted from the node No.2 to the node No.3, thereby ensuring the available identical keys on the nodes No.1 and No.3.
The quantum key obtained in the node No.3 is the result of mathematical re-encryption of the QK12 key generated in the first segment of the QKD network. In the ideal case of bitwise coding, in terms of an absolutely secure key (the additive pad method), the re-encryption process does not cause any damage to the cryptographic integrity. Thus, the key re-encryption in the successive segments of the QKD network allows obtaining the identical keys in the network nodes that are remoted from each other. In the case of practical implementations, the QKD system developers use the XOR (exclusive OR) mathematical operation and some standard encryption algorithms to re-encrypt the keys in the TIN. The convenience of this approach is that it is understandable, satisfies the regulatory policy and can be used to build the QKD networks of unlimited length. However, it somewhat contradicts the general ideology of quantum communications that proclaims the use of physical processes and denies any algorithmic encryption.
It is possible to obtain the QKD network of arbitrary topology by using the described approach to the key re-encryption in the TIN, combining several QKD modules in one DPU, as well as applying optical switches (Fig. 6). In such networks, the quantum channel is backed up that allows eliminating critical interruptions in the connection, optimizing the route for generating pairwise keys for the CIPF users, including in terms of the load optimization in the QKD modules. In addition, such networks allow servicing the CIPF users located in various QSCNs.
4. Monitoring level
of the QKD network
The QKD network is monitored for the KMM (TIN) equipment, telecommunications and auxiliary engineering and technical equipment. The control process can be carried out both on a centralized basis, for example, using a single management and monitoring server, and on a decentralized basis, including the separate management and monitoring systems for the QKD network devices (for example, a separate management and monitoring system for the QKD modules).
In terms of architectural unification, it is rather convenient to obtain a system assembled from the standard segments and control nodes that allows to develop and generate a quantum network according to the uniform principles. It should be noted that Russian Railways JSC has done great work to unify the control tools, since, as a rule, the QKD equipment manufacturers try to integrate the control modules directly onto the platform using the proprietary approaches.
The modular nature allows to obtain two network management cores. The first core includes the components of engineering implementation, data transmission channels and the functional part of quantum equipment. The second core includes the elements of cryptographic subsystem management that directly affects the data encryption process.
5. Data transmission level
of the QSCN
Generally speaking, it should be noted that the data transmission network topology is not related in any way to the quantum network topology. The quantum network can be considered as a set of geographical points of service provision, namely the QK or QSK issuance, for the user encoders (CIPF) being the users of quantum keys, while the data transmission network can be implemented according to any of the available architectures.
To implement the interaction interface, a unified approach is applied that is classified as a national standard [12]. The work results of the technical standardization committee 26 were the Recommendations for standardization that determine the procedure, format and rules for the QK/QSK transfer between the quantum cryptographic equipment for the key generation and distribution and cryptographic information protection facilities, and also establish certain requirements for the architecture and connecting interfaces of the hardware and software complex of key distribution. When developing the interaction interface, first of all, it is necessary to guarantee the absence of a leakage channel, the encoding and encryption accuracy, as well as compliance with all the data security requirements. At present, the ProtoQa standard is used between the TINs (KMMs) of the key management level of the QKD network and the CIPFs of the data transmission level in the QSCN [13]. The encryptors of various performance levels can be applied as the CIPFs of the QSCN data transmission level, both the highest-speed ones with the speeds of 100 Gbit/s and more, and the encryptors with lower speeds that allows the QSCN to be used to ensure the data transmission security, both between the data centers and during the intra-corporate interaction.
Recently, an alternative QSCN schemes have also been considered promising. In such a case, the quantum network is used not as a source of keys, but as a key distribution faility developed by a key generation center or a random number generator. The difference in this approach is that if in the first case the quantum cryptography equipment is a key generation device, then in the second case the key generation device is de jure a separate module or a separate device, and the quantum network allows these keys to be transferred to another device or system.
6. Monitoring level of the QSCN
Since the control and monitoring channel of the QSCN and the QKD network is a prospective source of intruders’ access to the information system, it is considered as a separate facility in terms of design and examination of the solutions being developed.
Substantially, the task of establishing a control and monitoring system consists of three main parts: the first one is related to the quantum equipment monitoring process (i. e., the QKD network), the second one is related to the QSCN data transmission network monitoring, and the third one is related to the engineering infrastructure monitoring (Fig.7).
In terms of the control and monitoring system, there are three layers logically repeating the network architecture and determining three groups of parameters. For each of the layers (parameters), the criteria accuracy is verified and the requirements for the equipment properties are set. Information is accumulated, analyzed and registered for each of the components.
Despite the fact that the construction of a control and monitoring channel based on the data transmission channel used by the network would allow disposing of additional devices, in the case of an emergency, a break in one of the nodes in such a network architecture would lead to the loss of ability to monitor the remaining network parts. Therefore, such a network architecture is not applied in the practical implementations. It is better to designate a separate backup control channel to ensure monitoring of the state of all nodes, including any segments with possible damage.
In addition, the control and monitoring channel is subject to the data security requirements since it is a potential information leakage point (point of an intruder’s influence and unauthorized access). An additional encryptor and a backup control channel allow for permanent monitoring process by adding another channel to the quantum network.
The control and monitoring center (hereinafter referred to as the CMC) as a part of the Quantum Communications Technology Center (a branch of Russian Railways JSC) provides the overall coordination of the QKD network monitoring and management processes [14]. To ensure the functioning of available network sections, more than two hundred backbone nodes of the quantum network are constantly monitored; in total, almost three thousand sensors and three hundred thousand parameters are permanently monitore at each station node, ensuring control over each segment operation in the QKD network.
One of the important tasks of monitoring is to determine key parameters and criteria, the service quality indicators and markers of the emergency or pre-emergency situations, necessary for decision-making on amending the network and ensuring the possible predictive measures, without any reactions in the case of false alarms.
Three groups of specialists are involved in the management and monitoring procedures: network administrators, data security administrators, and engineering infrastructure administrators. In addition, the network architects are involved in the process of quantum network construction to solve the problems of network arrangement, scaling, and configuration.
Conclusion
One of the aspects of the planning process for the quantum network architecture is the need to ensure territorial contingency [15]. A separate important issue is the connection of quantum infrastructure to the user in the corporate segment and external users in general, as well as the possible application of quantum network to provide services by the telecom operators to other consumers, such as the financial sector, critical or industrial infrastructure. The currently used approach to develop the QSCN and QKD networks allows for the implementation of inter-operator interaction, when one operator transfers the certain service to another operator, and the latter in turn delivers the service to the end user. The QKD networks can be connected to a wide range of devices [5, 6], for example, the trunk high-speed encoders or customer-premises equipment. For example, there is already a separate product called a “quantum phone”. Physically, this is a secure IP telephony incorporating the CIPFs that use the quantum keys, that is, an encoder is installed that operates with a quantum network.
It should be noted that the development prospects of quantum networks are directly related to the preparation of statutory regulations and the approval of standards. At present, the primary thing in the quantum network design process is the fulfillment of requirements for the developed of secure information systems, and the network part is elaborated after the necessary documents have been agreed upon by the data security specialists. Moreover, the key feature of the regulatory framework for quantum communications is that its application domain belongs to the field of several regulators at once [16–19], therefore, its systemic development leads to a convergence of various approaches to both the architecture and the development process.
Currently, the length of backbone quantum networks is more than 7,000 km and continues to increase [20]. Simultaneously, the regional networks are being formed with their connection points to the backbone quantum network, and the end subscriber connections are being organized. It should be noted that if the development of quantum network infrastructure in Russia three or four years ago was still at the architecture elaborating stage, now it is mainly focused on the issues of standards and technological documents regulating its operation.
AUTHORS
Gleim Artur Viktorovich, Cand.of Sc.(Tech.), e-mail: gleymav@center.rzd.ru; head of the Quantum Communications Department, Russian Railways JSC, Moscow; associate professor, Department of Electrical Communications, Emperor Alexander I Saint-Petersburg State Transport University, Saint-Petersburg, Russia. Areas of work and interests: quantum communications, quantum information, quantum optics, quantum computations.
ORCID: 0000-0003-2307-5454
Samburskaya Kseniya Sergeevna, Cand.of Sc. (Phys.&Math.), e-mail: samburskayaks@center.rzd.ru; chief specialist of the Research Collaboration Division of the Quantum Communications Department, Russian Railways JSC, Moscow, Russia. Areas of work and interests: quantum communications, quantum information, quantum optics, quantum computations.
ORCID: 0000-0003-2899-648X
Smirnov Konstantin Vladimirovich, D.Sc. (Phys.& Math.), e-mail: smirnovkv@center.rzd.ru; deputy head of the Quantum Communications Department, Russian Railways JSC, Moscow, Russia. Areas of work and interests: quantum communications, quantum information, quantum optics.
ORCID: 0000-0003-1562-0520
Conflict of interest
The review article is a joint work of all members of the author’s collective. The authors declare no controversial issues.
A. V. Gleim , K. S. Samburskaya, K. V. Smirnov
Department of Quantum Communications, Russian Railways OJSC, Moscow, Russia
Emperor Alexander I Saint-Petersburg State Transport University, Saint-Petersburg, Russia
The article considers the applicable approaches to the implementation of quantum communications networks in Russia, its architecture, including any relations between the individual elements or levels in the context of available statutory regulations of the quantum communications industry and its common use. The main relevant concepts and definitions are provided.
Keywords: quantum communications, quantum key distribution (QKD), quantum network, quantum-protected communication network, QKD transmitter, QKD quantum receiver
Article received: July 01, 2025
Article accepted: July 25, 2025
Introduction
The quantum communications have long ceased to be just a theoretical concept.The quantum communications in Russia are at the stage of active development and commercial evolvement and have significant potential for its common use expansion [1–2]. At present, several areas of development of the quantum communications market are being implemented on a simultaneous basis: the development and improvement of quantum communications systems is continuing, the construction projects of quantum communication networks are being implemented, the business models for service provision using the quantum communications are being developed. Not only the researchers and developers, but also various engineers, designers, and process managers, as well as any persons who are directly interested in the technology introduction actively participate in the work.
The article considers the specific features of quantum communications in terms of applied aspects of quantum communication networking, its use and integration with the available telecommunications infrastructure. The article is devoted to the analysis of engineering principles of quantum communication networking, including its architecture, features of the components and devices in such networks, requirements for the management and monitoring of quantum networks.
Broadly speaking, the quantum networks can be considered as the secured automated systems to be complied with the statutory regulations governing the arrangement of secure data exchange and transmission [3]. Such systems in the field of information security are regulated by the Federal Service for Technical and Export Control (hereinafter referred to as the FSTEC). Therefore, the implementation of quantum communications is, above all, a matter of information security. In addition, to arrange the data transmission systems that are limited, regulated and governed by the federal legislation, it is necessary to provide for these data security by the specialized cryptographic information protection facilities (hereinafter referred to as the CIPF), with the fulfillment of requirements related to the data protection category and network management [4]. The development of quantum communications within the paradigm of practical communication system formation leads to the need to change the conventional terminology in the scientific community used for the quantum networks and quantum communications.
An important stage in the development of quantum communications has now been passed: the Federal Agency for Technical Regulation and Metrology has approved and officially introduced the statutory regulations including the general provisions, terms and definitions in the field of quantum communications, the quantum Internet of Things, architecture and interfaces to connect the typical software and hardware complex for management of keys developed by a quantum key distribution network [5–8]. This article describes the main provisions of the specified preliminary national standards of the Russian Federation (hereinafter referred to as the PNST).
1. Quantum-secure communication network
The quantum networks (quantum communication networks) shall mean the quantum-secure communication networks (hereinafter referred to as the QSCN) where the protected or encrypted information is transmitted using the quantum keys and/or quantum-secure keys. In this case, the quantum key distribution network (hereinafter referred to as the QKD network) is one of the QSCN components. The QSCN ensures the secure data transmission using the CIPFs, namely the users receiving cryptographic keys from the QKD network [5, 6].
There are five levels in the architecture of quantum-secure communication networks (Fig. 1). Substantially, these are five logical layers of hierarchy or five logical problems to be solved to develop a comprehensive QSCN infrastructure.
The first level is the quantum key level (hereinafter referred to as the QK). At this level, the QKs are generated between the modules that are the part of one QKD system and are located in various QSCN nodes. The layout and connection diagram of the QKD transmitters and receivers in the QKD network is determined with due regard to the selected QKD protocol. The second level is the key management level, represented by the key management system (hereinafter referred to as the KMS). In the KMS, the QKs are issued after being generated in the QKD system modules. The key management system, usually implemented by the encoders, is a link in the QSCN between the equipment that generates the QKs and the key information users, namely the user encoders. The quantum-secure keys are also generated in the KMS (hereinafter referred to as the QSK). The third level is the monitoring level that ensures the service quality and delivery to the user; as a typical analogy, it is possible to indicate routing, management, monitoring, SLA ensuring and all activities performed by the communications network engineering. The level of QKD network management and monitoring ensures control of the devices included in the QKD network and their status monitoring. The management process can be carried out both on a centralized basis, for example, using one management and monitoring server, and on a decentralized basis, including the separate management and monitoring systems for the QKD network devices.
In general, the QSCN is an external network in relation to the QKD network. In the QSCN network, in addition to the functional levels of the QKD network, two upper levels are implemented: the QSCN data transmission level required for the developed applied transport infrastructure, and the QSCN control and monitoring level.
Various options for the architecture and topology of quantum networks can be implemented due to the combination of quantum components. The design solutions being developed have ideological differences in the implementations of key circuits and equipment layout methods by various manufacturers, methods of unification and division into the QKD modules, routing algorithms and approaches to the network management principles. Based on the final task, the certain decisions are made during the design process on how the architecture will meet the requirements of redundancy and reliability.
2. Quantum key level
The task of preparing the quantum key level for the simplest architecture of a point-to-point quantum key distribution network is essentially reduced to constructing a set of channels (a quantum channel, a synchronization channel, and a service channel) to ensure the data exchange process between two subscribers of the QKD network (Fig. 2).
In principle, the QKD equipment can be represented in the form of interacting sender and receiver modules, while the quantum channel is implemented by an optical part, including a source and receiver of quantum states.
To implement the quantum key distribution protocol, it is necessary to ensure synchronous operation of the equipment in the sender and receiver modules. The protocols and constructions principles of the quantum communication equipment correspond to those adopted for the synchronous digital hierarchy equipment (hereinafter referred to as the SDH). The quantum key distribution protocols cannot operate without an explicitly allocated synchronization channel that allows the signal interpretation in the quantum channel. The service channel is used to transmit the resulting receiver’s sequences generated after interpreting the sender’s messages. Thus, the joint operation of three channels allows developing the quantum keys used in the network encryption and data transmission processes.
The first simple case of scaling a quantum channel at the quantum key level in the QKD network is a branch implementing the connection of the sender module with several subscribers through a tapping point (Fig. 3) [5].
The available switch in the communication line affects the protocols and algorithm operation inside the QKD equipment. In fact, the switch addition can be regarded as additional losses in the communication line. In terms of encryption technology, scaling a quantum channel means an increase in the number of subscribers and the need to provide for their possible differentiation and identification in the MAC codes used for the QKD equipment. This approach can be extrapolated to the typical and understandable case of network arrangement with the passive optical couplers that allows for network scaling. In such a case, switching and communication between the subscribers are ensured through synchronization of the sender and a set of recipients, sharing of the clock frequency and the forming pulse.
Another option for scaling a quantum network can be implemented using an optical combiner instead of a switch. If the first approach is actively used in the available networks, the second one, despite being mentioned in the regulatory documents [5], is still at the development stage, and the equipment required for such an approach has not been fully implemented.
3. Key management level
In practice, the QKD systems use the attenuated optical laser pulses as a single-photon source. The quantum protocols are applied in such a way that in the actual systems the number of errors and inaccuracies related to the hardware implementation is about 1%, and they can be mathematically precisely extracted from the report results without affecting the security. The actual practical systems use the phase (the most common approach) or polarizing (less common, but also frequent) coding.
The main problem of quantum communications is the preservation of very weak power messages (single-photon), when passing through the quantum communication channel. The coding preservation for a weakened signal is the main task that is considered by the researchers and manufacturers of the QKD systems are, and up to 90% of the efforts of the developers of quantum communication equipment are directed at its solution.
The maximum optical budget for losses in the communication line (quantum channel) for the successful QKD system operation is rather limited, on the one part, by the components used, and on the other part, by the requirement to the limited power of the attenuated signal (the maximum value of the number of photons in a radiation pulse) and is about 20–23 dB. Having considered the maintenance margin and requirements for operational reliability, the actual attenuation designed during the QKD network construction is 15–16 dB that ensures possible transmission of a quantum signal over the distances of approximately 40–70 km, depending on the infrastructure condition (usually the standard single-mode optical fiber and its intermediate connections).
It should be noted that at present, the maximum distribution range values for the quantum cryptographic key were obtained in the research articles [9–10] using an untrusted central node and a twin-field protocol that additionally required a detailed study and strength analysis, as well as any limitations due to the actual service peculiarities.
Globally, there are several possibilities for increasing the range of a quantum channel; on a terminological basis, they are generalized by the concept of a quantum repeater (Fig. 4). Historically, a quantum repeater was considered as a very specific device. However, in the regulatory documents within the framework of standardization, any approach and any device that allows the signal regeneration, including restoration of its reception and transmission, are called a “repeater” [6]. The following options for implementing the quantum repeater are considered: the first one is an equipment using the reception and transmission mechanisms, the second one is a certain idealized device similar to an amplifier in the typical communication network, but for the quantum states (at the moment, its engineering implementation is absent) and the third option is satellite communication, providing interaction between the network members via the low-altitude satellites [11].
In the real-world scenarios, a circuit with a receiver, a transmitter and an intermediate node or several intermediate nodes (quantum repeaters) is used for an extended QKD network. In the intermediate nodes, the information is decoded, the optical signal is converted into an electrical signal, the electrical signal is re-encoded and converted into an optical signal, and then transmitted to the next intermediate node via the quantum channel. In this case, the service channel remains the same for all segments of the quantum key level, ensuring logical consistency of the QKD network.
The quantum network with such intermediate nodes is generated by the separate spans or sections, each of which consists of a pair of devices that forms the quantum keys randomly, based on the physical random number generators. In order to provide some common keys for various subscribers participating in the data exchange process, a trusted intermediate node (hereinafter referred to as the TIN) is formed, that is the name most often used by the QKD equipment manufacturers, or a key management module (hereinafter referred to as the KMM), that is the name indicated in the PNST.
The TIN is operated as follows (Fig. 5). A pairwise key QK12 is generated in the first segment of the QKD network between the nodes No.1 and No.2. A key QK23 is generated in the second segment of the QKD network between the nodes No.2 and No.3. The key QK12 protected using the key QK23 is transmitted from the node No.2 to the node No.3, thereby ensuring the available identical keys on the nodes No.1 and No.3.
The quantum key obtained in the node No.3 is the result of mathematical re-encryption of the QK12 key generated in the first segment of the QKD network. In the ideal case of bitwise coding, in terms of an absolutely secure key (the additive pad method), the re-encryption process does not cause any damage to the cryptographic integrity. Thus, the key re-encryption in the successive segments of the QKD network allows obtaining the identical keys in the network nodes that are remoted from each other. In the case of practical implementations, the QKD system developers use the XOR (exclusive OR) mathematical operation and some standard encryption algorithms to re-encrypt the keys in the TIN. The convenience of this approach is that it is understandable, satisfies the regulatory policy and can be used to build the QKD networks of unlimited length. However, it somewhat contradicts the general ideology of quantum communications that proclaims the use of physical processes and denies any algorithmic encryption.
It is possible to obtain the QKD network of arbitrary topology by using the described approach to the key re-encryption in the TIN, combining several QKD modules in one DPU, as well as applying optical switches (Fig. 6). In such networks, the quantum channel is backed up that allows eliminating critical interruptions in the connection, optimizing the route for generating pairwise keys for the CIPF users, including in terms of the load optimization in the QKD modules. In addition, such networks allow servicing the CIPF users located in various QSCNs.
4. Monitoring level
of the QKD network
The QKD network is monitored for the KMM (TIN) equipment, telecommunications and auxiliary engineering and technical equipment. The control process can be carried out both on a centralized basis, for example, using a single management and monitoring server, and on a decentralized basis, including the separate management and monitoring systems for the QKD network devices (for example, a separate management and monitoring system for the QKD modules).
In terms of architectural unification, it is rather convenient to obtain a system assembled from the standard segments and control nodes that allows to develop and generate a quantum network according to the uniform principles. It should be noted that Russian Railways JSC has done great work to unify the control tools, since, as a rule, the QKD equipment manufacturers try to integrate the control modules directly onto the platform using the proprietary approaches.
The modular nature allows to obtain two network management cores. The first core includes the components of engineering implementation, data transmission channels and the functional part of quantum equipment. The second core includes the elements of cryptographic subsystem management that directly affects the data encryption process.
5. Data transmission level
of the QSCN
Generally speaking, it should be noted that the data transmission network topology is not related in any way to the quantum network topology. The quantum network can be considered as a set of geographical points of service provision, namely the QK or QSK issuance, for the user encoders (CIPF) being the users of quantum keys, while the data transmission network can be implemented according to any of the available architectures.
To implement the interaction interface, a unified approach is applied that is classified as a national standard [12]. The work results of the technical standardization committee 26 were the Recommendations for standardization that determine the procedure, format and rules for the QK/QSK transfer between the quantum cryptographic equipment for the key generation and distribution and cryptographic information protection facilities, and also establish certain requirements for the architecture and connecting interfaces of the hardware and software complex of key distribution. When developing the interaction interface, first of all, it is necessary to guarantee the absence of a leakage channel, the encoding and encryption accuracy, as well as compliance with all the data security requirements. At present, the ProtoQa standard is used between the TINs (KMMs) of the key management level of the QKD network and the CIPFs of the data transmission level in the QSCN [13]. The encryptors of various performance levels can be applied as the CIPFs of the QSCN data transmission level, both the highest-speed ones with the speeds of 100 Gbit/s and more, and the encryptors with lower speeds that allows the QSCN to be used to ensure the data transmission security, both between the data centers and during the intra-corporate interaction.
Recently, an alternative QSCN schemes have also been considered promising. In such a case, the quantum network is used not as a source of keys, but as a key distribution faility developed by a key generation center or a random number generator. The difference in this approach is that if in the first case the quantum cryptography equipment is a key generation device, then in the second case the key generation device is de jure a separate module or a separate device, and the quantum network allows these keys to be transferred to another device or system.
6. Monitoring level of the QSCN
Since the control and monitoring channel of the QSCN and the QKD network is a prospective source of intruders’ access to the information system, it is considered as a separate facility in terms of design and examination of the solutions being developed.
Substantially, the task of establishing a control and monitoring system consists of three main parts: the first one is related to the quantum equipment monitoring process (i. e., the QKD network), the second one is related to the QSCN data transmission network monitoring, and the third one is related to the engineering infrastructure monitoring (Fig.7).
In terms of the control and monitoring system, there are three layers logically repeating the network architecture and determining three groups of parameters. For each of the layers (parameters), the criteria accuracy is verified and the requirements for the equipment properties are set. Information is accumulated, analyzed and registered for each of the components.
Despite the fact that the construction of a control and monitoring channel based on the data transmission channel used by the network would allow disposing of additional devices, in the case of an emergency, a break in one of the nodes in such a network architecture would lead to the loss of ability to monitor the remaining network parts. Therefore, such a network architecture is not applied in the practical implementations. It is better to designate a separate backup control channel to ensure monitoring of the state of all nodes, including any segments with possible damage.
In addition, the control and monitoring channel is subject to the data security requirements since it is a potential information leakage point (point of an intruder’s influence and unauthorized access). An additional encryptor and a backup control channel allow for permanent monitoring process by adding another channel to the quantum network.
The control and monitoring center (hereinafter referred to as the CMC) as a part of the Quantum Communications Technology Center (a branch of Russian Railways JSC) provides the overall coordination of the QKD network monitoring and management processes [14]. To ensure the functioning of available network sections, more than two hundred backbone nodes of the quantum network are constantly monitored; in total, almost three thousand sensors and three hundred thousand parameters are permanently monitore at each station node, ensuring control over each segment operation in the QKD network.
One of the important tasks of monitoring is to determine key parameters and criteria, the service quality indicators and markers of the emergency or pre-emergency situations, necessary for decision-making on amending the network and ensuring the possible predictive measures, without any reactions in the case of false alarms.
Three groups of specialists are involved in the management and monitoring procedures: network administrators, data security administrators, and engineering infrastructure administrators. In addition, the network architects are involved in the process of quantum network construction to solve the problems of network arrangement, scaling, and configuration.
Conclusion
One of the aspects of the planning process for the quantum network architecture is the need to ensure territorial contingency [15]. A separate important issue is the connection of quantum infrastructure to the user in the corporate segment and external users in general, as well as the possible application of quantum network to provide services by the telecom operators to other consumers, such as the financial sector, critical or industrial infrastructure. The currently used approach to develop the QSCN and QKD networks allows for the implementation of inter-operator interaction, when one operator transfers the certain service to another operator, and the latter in turn delivers the service to the end user. The QKD networks can be connected to a wide range of devices [5, 6], for example, the trunk high-speed encoders or customer-premises equipment. For example, there is already a separate product called a “quantum phone”. Physically, this is a secure IP telephony incorporating the CIPFs that use the quantum keys, that is, an encoder is installed that operates with a quantum network.
It should be noted that the development prospects of quantum networks are directly related to the preparation of statutory regulations and the approval of standards. At present, the primary thing in the quantum network design process is the fulfillment of requirements for the developed of secure information systems, and the network part is elaborated after the necessary documents have been agreed upon by the data security specialists. Moreover, the key feature of the regulatory framework for quantum communications is that its application domain belongs to the field of several regulators at once [16–19], therefore, its systemic development leads to a convergence of various approaches to both the architecture and the development process.
Currently, the length of backbone quantum networks is more than 7,000 km and continues to increase [20]. Simultaneously, the regional networks are being formed with their connection points to the backbone quantum network, and the end subscriber connections are being organized. It should be noted that if the development of quantum network infrastructure in Russia three or four years ago was still at the architecture elaborating stage, now it is mainly focused on the issues of standards and technological documents regulating its operation.
AUTHORS
Gleim Artur Viktorovich, Cand.of Sc.(Tech.), e-mail: gleymav@center.rzd.ru; head of the Quantum Communications Department, Russian Railways JSC, Moscow; associate professor, Department of Electrical Communications, Emperor Alexander I Saint-Petersburg State Transport University, Saint-Petersburg, Russia. Areas of work and interests: quantum communications, quantum information, quantum optics, quantum computations.
ORCID: 0000-0003-2307-5454
Samburskaya Kseniya Sergeevna, Cand.of Sc. (Phys.&Math.), e-mail: samburskayaks@center.rzd.ru; chief specialist of the Research Collaboration Division of the Quantum Communications Department, Russian Railways JSC, Moscow, Russia. Areas of work and interests: quantum communications, quantum information, quantum optics, quantum computations.
ORCID: 0000-0003-2899-648X
Smirnov Konstantin Vladimirovich, D.Sc. (Phys.& Math.), e-mail: smirnovkv@center.rzd.ru; deputy head of the Quantum Communications Department, Russian Railways JSC, Moscow, Russia. Areas of work and interests: quantum communications, quantum information, quantum optics.
ORCID: 0000-0003-1562-0520
Conflict of interest
The review article is a joint work of all members of the author’s collective. The authors declare no controversial issues.
Readers feedback
rus



