Raise the authentication of the classical channel to the security level of its quantum channel, so it is no longer the QKD link's weak point, built on information-theoretically secure cryptography.
QKD distributes keys with a security proven from physics, under its own stated device and channel assumptions. But every QKD link runs a public classical channel alongside the quantum one, and that channel has to be authenticated. Today it is authenticated with standards-based cryptography such as HMAC, AES-GMAC, RSA, and ECDSA, all based on computational hardness: a computational assumption, not a proof. A quantum computer breaks RSA and ECDSA, while AI and new cryptanalysis may break the rest, the computational MACs and post-quantum signatures included, so the algorithm authenticating your classical channel has a limited lifetime.
QuBalt secures the classical channel of QKD links through QUAUTS for QKD, its Quantum- and Cryptanalysis-Secure Authentication System, built on QuBalt's authentication core.
QUAUTS for QKD authenticates every classical-channel message, key post-processing and ciphertext alike, with an information-theoretically secure tag keyed from the QKD output itself. The classical channel is raised to the quantum channel's security level, with no dependence on a computational hardness assumption.
QUAUTS for QKD is delivered as a building block that integrates symmetrically into both QKD endpoints. At each endpoint it runs as an FPGA core, with its bootstrap key and tag-key pool, plus a software stack on the host controller; the same building block sits at each end. It draws its authentication keys from the QKD channel itself: the QKD key store feeds two streams, authentication keys for the QUAUTS for QKD tags and, where you use it, AES keys for user-data encryption. QUAUTS is validated to TRL 4 under the ESA GSTP programme and is adapted to each customer's specific requirements and hardware environment.
The same QUAUTS for QKD integration authenticates the classical channel wherever your QKD links run, so one building block covers your whole product line:
Satellite-to-ground and inter-satellite QKD links.
Metropolitan and long-haul terrestrial QKD networks.
QKD nodes, trusted-node relays, and QKD-as-a-service platforms.
For the QKD link and the manufacturer who fields it, that means the classical channel matched to the quantum channel and a key supply that sustains itself:
For a QKD link, the classical channel's security basis decides the whole link: authenticate it computationally and it stays the weak point beside a quantum channel proven from physics.
State-of-the-art QKD products authenticate the classical channel with digital signatures such as RSA and ECDSA, with the post-quantum standards, or with computational MACs such as HMAC and AES-GMAC, all standards-based and all forms of computational security: their security rests on a problem staying too hard to solve, an assumption that has never been proven. A quantum computer breaks RSA and ECDSA, while AI and new cryptanalysis may break the rest, the MACs and post-quantum standards included. QUAUTS for QKD instead uses information-theoretic authentication: provably secure under its stated assumptions of truly random, single-use keys and a correct implementation, and independent of any attacker's computing power, now or in the future. That proof covers the authentication algorithm; full system security also rests on key management and implementation assurance.
QUAUTS for QKD therefore rests on a different security basis, one that stays secure against quantum computers, AI, and future cryptanalysis, so the classical channel matches the quantum channel it runs beside for the QKD link's entire operational life.
Whether you build DV-QKD, CV-QKD, satellite-ground, or QKD-as-a-service links, our engineers will show you how to raise your classical channel to the quantum channel's security level within your existing architecture. Contact us about your link.