Sentinel-Based Failover for QKD-Augmented IPsec Tunnels
Juan Carlos Hernandez-Hernandez, Francesco Vista, Haftay Gebreslasie Abreha, Intidhar Bedhief, Seid Koudia, Symeon Chatzinotas
Abstract
Quantum-safe IPsec through hybrid key establishment is practical, but creates a critical operational challenge: how to maintain tunnel availability when the QKD infrastructure becomes unavailable. In this paper, we present the design, implementation, and experimental evaluation of a quantum-safe key establishment mechanism for an IPsec tunnel that combines X25519, ML-KEM, and ETSI GS QKD 014 keys through the RFC 9370 multiple key exchange mechanism, and that degrades gracefully when the QKD key delivery fails. Our open-source StrongSwan plugin uses a sentinel-based coordination protocol, thereby permitting us to complete the handshake even if the QKD leg fails, instead of aborting, restoring the QKD share at the next rekey. On a testbed connected to a metropolitan QKD link over 33 km of deployed fiber, we evaluated five configurations, from a classical X25519 with RSA baseline to a hybrid one that adds ML-KEM-1024 and a QKD key. The full hybrid authentication costs 103 ms against 61 ms for the baseline, the QKD retrieval itself adds only about 7 ms. Failure injection experiments confirm that the tunnel survives a complete KME outage without any interruption of the protected traffic.
Create a lesson
Related papers
Microcell Hot Spot and Smart Antennas Evaluation in WCDMA Macrocell System
Carlos H. M. Lima, Francisco R. P. Cavalcanti, Vicente A. de Sousa et al.
Integrating Wi-Fi into 3GPP 5G Network Slicing: An Experimental Prototype Study
Nelson Ion de Oliveira, Marília Costa Muniz, William M. C. do Nascimento et al.
Connectivity of HAPS-Based Solutions for Large-Scale Wireless Networks: A Percolation Theory Analysis
Hao Lin, Mustafa A Kishk, Mohamed-Slim Alouini
WiP: Characterizing and Defending Against Mobile-Agent-Driven MFA Automation
Yimeng Liu, Hua Huang
SoK: Where Do Flow Labels Come From? Auditing Label Provenance in Encrypted Traffic Benchmarks
Sizhe Huang, Shujie Yang
Bridging the Gap: A Longitudinal Analysis of Extended Identifiers in the Post-Cookie Era
Michael Smith, Riley Grossman, Krzysztof Franaszek et al.