QKD · KEY PROTECTION PRODUCT / SOLUTION PROFILE

QKD / QRNG Integration Track
Research / partner track

Assess partner-based integration of quantum key distribution or quantum random sources where the use case justifies it.

CUSTOMER PROBLEM

Assess partner-based integration of quantum key distribution or quantum random sources where the use case justifies it.

QKD and QRNG are not universal replacements for PQC. They require a justified use case, partner infrastructure, protected interfaces and a clear trust boundary.

Research / partner track
Portfolio class
Key protection product / solution profile
Public profile
2026.07
Version rule
Confirmed in quotation / release record

PRODUCT-SPECIFIC IMPLEMENTATION FLOW

How QKD / QRNG Integration Track operates from input to evidence.

QKD networks, QRNG devices, HSM/KMS and standards-aligned connectors when available. Research note, partner scope, threat model and pilot acceptance criteria.

01

Confirm QKD or QRNG use case

PQC-versus-QKD decision framework

02

Select partner interface and topology

QKD KME/SAE and HSM/KMS connector design

03

Bind QKD/QRNG to KMS or HSM

QRNG health and consumption model

04

Apply availability and fallback policy

High-availability and denial-of-service analysis

05

Test synchronization and failure

Partner interoperability and responsibility matrix

06

Approve research-to-pilot gate

Research-to-pilot acceptance gate

NAMED COMPONENTS AND RESPONSIBILITIES

What QKD / QRNG Integration Track contains and what each component does.

The descriptions below state concrete technical behaviour rather than generic support language.

01

PQC-versus-QKD decision framework

Compares PQC, QKD and classical controls against distance, availability, key-consumption rate, threat model and operating cost before selecting a technology.

02

QKD KME/SAE and HSM/KMS connector design

Defines KME/SAE, HSM or KMS connector boundaries, authentication, key identifiers and responsibility between Mobile-ID, customer and QKD partner.

03

QRNG health and consumption model

Specifies how QRNG output is health-tested, conditioned, consumed and monitored without implying that entropy integration alone provides quantum-safe security.

04

High-availability and denial-of-service analysis

Models key-pool exhaustion, link loss, denial-of-service, site failover and approved fallback to PQC or pre-shared-key profiles.

05

Partner interoperability and responsibility matrix

Tests cross-site key synchronization, identifier matching, deletion, renewal and error handling with exact partner versions and topology.

06

Research-to-pilot acceptance gate

Requires a signed research note, threat model, interoperability report and measurable acceptance criteria before any capability is presented as a pilot.

CUSTOMER OUTCOMES
  • PQC-versus-QKD decision
  • Connector and trust-boundary design
  • Partner interoperability plan
INTEGRATION BOUNDARY

QKD networks, QRNG devices, HSM/KMS and standards-aligned connectors when available.

DEPLOYMENT PATTERNS

Customer security boundary

HSM, QSCD, token or KMS components remain in the customer-controlled environment with documented ceremonies.

Dedicated high-availability service

Protected key services run across approved HA/DR nodes with tested quorum, backup and recovery.

Integrated managed operation

Operational responsibility is divided explicitly across customer, Mobile-ID and hardware/technology partners.

EVIDENCE REQUIRED
  • Research note, partner scope, threat model and pilot acceptance criteria.
  • Version and configuration manifest for: QKD networks, QRNG devices, HSM/KMS and standards-aligned connectors when available.
  • Negative, failure and recovery tests for “Test synchronization and failure” and “Approve research-to-pilot gate”.
  • Signed acceptance record, accountable owner, published limitations and next review date.
STANDARDS & PROFILES
  • ETSI GS QKD 014
  • RFC 8784 PPK concepts
  • PKCS#11
  • Partner-specific QKD / QRNG interfaces

PRODUCT-SPECIFIC BOUNDARIES

Conditions that must remain true for QKD / QRNG Integration Track.

These points come from the product profile, not from a shared disclaimer.

NEXT STEP

Discuss research collaboration: QKD / QRNG Integration Track

Agree the research question, partner scope, evidence and pilot threshold.