PRODUCT MANUAL

QuantumSafe QKD Bridge
Technical usage guide

Present QKD-derived keys through governed enterprise interfaces, synchronize approved key material with HSM/KMS controls and support PPK-based protected tunnels.

OVERVIEW

QuantumSafe QKD Bridge

QKD infrastructure exposes specialist protocols and operational constraints that existing applications, HSMs and VPNs are not designed to consume directly.

WORKFLOW

  1. 01 Receive key material from an approved QKD endpoint
  2. 02 Validate peer, key identifier, entropy metadata and policy
  3. 03 Store or wrap the key inside the approved HSM/KMS boundary
  4. 04 Expose a PKCS#11, REST or RFC 8784 PPK reference
  5. 05 Consume the key once or according to approved lifecycle rules
  6. 06 Monitor pool health, failover and cryptographic erasure

COMPONENT REFERENCE

COMPONENT ARCHITECTURE

Convert partner QKD key material into governed application key references.

ETSI QKD connectivity, key-pool state, protected storage and application interfaces remain distinct, while high availability spans every layer.

Partner QKD boundary
QKD node AQKD node BETSI QKD 014
01

ETSI QKD 014 Connector

Authenticates the approved QKD endpoint and retrieves key identifiers, material references and source metadata.

PARTNER INTERFACE
02

Quantum Key Pool

Tracks available, reserved, consumed, expired and failed key states under a versioned consumption policy.

KEY STATE
03

HSM/KMS Synchronization Service

Wraps, stores or references key material inside an approved HSM/KMS boundary and records correlation evidence.

PROTECTED STORAGE
04

PKCS#11 & REST Facade

Exposes governed key references through versioned PKCS#11 and REST profiles without leaking raw key material.

APPLICATION INTERFACE
05

RFC 8784 PPK Adapter

Maps approved key references into IPsec pre-shared post-quantum key workflows with peer and lifetime binding.

VPN INTERFACE
GOVERNED OUTPUTS
IPsec / VPNEnterprise applicationApproved key consumer

INTERFACES

  • ETSI GS QKD 014
  • PKCS#11
  • REST/mTLS
  • RFC 8784 PPK
  • HSM/KMS connectors
  • HA monitoring API

LIMITATIONS & ACCEPTANCE

  • Availability depends on supported QKD vendors, topology and partner integration.
  • QKD does not replace digital signatures, identity proofing or application-layer authorization.
  • Fallback between QKD, PQC and classical methods must be explicit and must not silently downgrade assurance.