Hybrid Post-Quantum Cryptography and Quantum Key Distribution Co-Design for Quantum-Safe 6G, O-RAN, and IoT Infrastructure
Abstract
Cryptographically relevant quantum computers do not yet exist, but the transition away from classical public-key cryptography is already underway: adversaries can record encrypted traffic today and decrypt it once a sufficiently capable quantum computer becomes available, a threat known as harvest-now, decrypt-later. This paper examines the engineering case for combining post-quantum cryptography (PQC) with quantum key distribution (QKD) as a strategy for securing next-generation communication infrastructure, focusing on 6G core and radio-access networks, Open RAN (O-RAN), and constrained Internet of Things (IoT) deployments. Rather than treating the two mechanisms as symmetric, interchangeable layers, the paper examines what each one actually guarantees, surveys the empirical evidence available for deployment cost, and describes where national security authorities and standards bodies disagree on the value of QKD. The architecture is grounded in the finalized National Institute of Standards and Technology (NIST) PQC standards and its 2025 hybrid key-establishment guidance, drawing on empirical Open RAN latency and energy measurements published during 2025 and 2026, embedded-hardware benchmarks for constrained devices, and the small number of quantum key distribution deployments operating at metropolitan or national backbone scale today. The paper is explicit about which figures are measured results and which remain illustrative proposals, and it closes by naming the specific standardization and field-trial gaps that separate current practice from the architecture it describes. The purpose of the work is to give network architects and policymakers a single, evidence-graded reference for deciding where each mechanism belongs in a real deployment, rather than treating post-quantum and quantum-distributed keying as equivalent options.