Confirm QKD or QRNG use case
PQC-versus-QKD decision framework
QKD · KEY PROTECTION PRODUCT / SOLUTION PROFILE
Assess partner-based integration of quantum key distribution or quantum random sources where the use case justifies it.
CUSTOMER PROBLEM
QKD and QRNG are not universal replacements for PQC. They require a justified use case, partner infrastructure, protected interfaces and a clear trust boundary.
PRODUCT-SPECIFIC IMPLEMENTATION FLOW
QKD networks, QRNG devices, HSM/KMS and standards-aligned connectors when available. Research note, partner scope, threat model and pilot acceptance criteria.
PQC-versus-QKD decision framework
QKD KME/SAE and HSM/KMS connector design
QRNG health and consumption model
High-availability and denial-of-service analysis
Partner interoperability and responsibility matrix
Research-to-pilot acceptance gate
NAMED COMPONENTS AND RESPONSIBILITIES
The descriptions below state concrete technical behaviour rather than generic support language.
Compares PQC, QKD and classical controls against distance, availability, key-consumption rate, threat model and operating cost before selecting a technology.
Defines KME/SAE, HSM or KMS connector boundaries, authentication, key identifiers and responsibility between Mobile-ID, customer and QKD partner.
Specifies how QRNG output is health-tested, conditioned, consumed and monitored without implying that entropy integration alone provides quantum-safe security.
Models key-pool exhaustion, link loss, denial-of-service, site failover and approved fallback to PQC or pre-shared-key profiles.
Tests cross-site key synchronization, identifier matching, deletion, renewal and error handling with exact partner versions and topology.
Requires a signed research note, threat model, interoperability report and measurable acceptance criteria before any capability is presented as a pilot.
QKD networks, QRNG devices, HSM/KMS and standards-aligned connectors when available.
HSM, QSCD, token or KMS components remain in the customer-controlled environment with documented ceremonies.
Protected key services run across approved HA/DR nodes with tested quorum, backup and recovery.
Operational responsibility is divided explicitly across customer, Mobile-ID and hardware/technology partners.
PRODUCT-SPECIFIC BOUNDARIES
These points come from the product profile, not from a shared disclaimer.
NEXT STEP
Agree the research question, partner scope, evidence and pilot threshold.