Trust-aware hybrid QKD–PQC key management for quantum-safe communication networks
The security of today’s communication networks rests on public-key primitives—RSA and elliptic-curve Diffie–Hellman—that a large quantum computer would break with Shor’s algorithm, while the “harvest-now, decrypt-later” threat means traffic captured today is already at risk. Two defences exist but each is incomplete: quantum key distribution (QKD) offers information-theoretic security yet fails open under eavesdropping or channel loss, while post-quantum cryptography (PQC) is computationally secure and always available but lacks physical-layer guarantees. This paper presents a dual-layer, trust-aware key-management framework that uses BB84 QKD as the primary channel and a Ring-LWE/Kyber key-encapsulation mechanism as a quantum-safe fallback, governed by a controller monitoring the quantum bit-error rate (QBER) and a trust signal. When intercept-resend eavesdropping pushes the QBER past the 11% abort threshold—reached at roughly 40% interception—the controller falls back to PQC, holding secure availability at 100% where a QKD-only system degrades to 78.5%. The lattice fallback is cheap ( ≈ 0.47 m per operation) and Kyber-768 gives 192-bit quantum-safe security. Coupling the fallback and re-keying rate to a node trust score integrates physical-layer and computational security into one always-available, forward-secure key-management layer. To our knowledge, this is the first key-management framework in which a single network-layer trust signal jointly governs QKD/PQC layer selection and the re-keying cadence, unifying physical-layer eavesdropping detection, computational quantum-safety, and forward secrecy in one cross-layer policy.