Certifying Hidden Paths: Scalable Topology Assurance for QKD Networks

πŸ“… 2026-10-08
πŸ“ˆ Citations: 0
✨ Influential: 0
πŸ“„ PDF
πŸ€– AI Summary
This study addresses the challenge of topology privacy leakage during compliance verification of end-to-end routing policies in quantum key distribution (QKD) networks by proposing a zero-knowledge proof-based path verification scheme. The approach employs BBS multi-message signatures to independently authenticate nodes and edges, ensuring that proof size depends solely on path attributes rather than overall network scale. This enables verifiable path existence while concealing specific routing details, supported by a formal security proof. Experimental evaluations demonstrate that, under specified parameters, the proof size remains below 300 KiB, with both generation and verification times under 400 ms, indicating high scalability and practical applicability.
πŸ“ Abstract
Large-scale Quantum Key Distribution (QKD) networks rely on trusted repeaters, making the security properties of the selected communication path an essential part of end-to-end assurance. At the same time, network operators may be unwilling to disclose their internal topology. We present a topology-certification mechanism that lets a provider prove in zero knowledge that policy-compliant routes between two endpoints exist, without disclosing the routes in an individual presentation. Our main idea is to certify nodes and edges independently using multi-message signatures, rather than signing the complete graph as one object. For a route chosen in advance, proof size and cryptographic proving and verification work depend on its positions and attributes, independently of the overall network size, whereas route discovery and certification have separate graph-dependent costs. The construction hides the actual route length up to a public bound and sketches extensions to node-disjoint routes and monotonic additions within a graph epoch. We give a formal security model and conditional proofs of unforgeability and graph hiding for a generic construction. For a BBS-based construction, presentation-size estimates remain below $300$\,KiB at $\ell=m=n=50$, and measured generation and verification times remain below $400$\,ms at $\ell=64$ and $m=n=8$.
Problem

Research questions and friction points this paper is trying to address.

Quantum Key Distribution
Topology Assurance
Zero-Knowledge Proof
Trusted Repeaters
Route Certification
Innovation

Methods, ideas, or system contributions that make the work stand out.

Quantum Key Distribution
Zero-Knowledge Proof
Topology Certification
Multi-Message Signatures
BBS Signatures
πŸ’Ό Related Jobs
No related jobs found.
A
Alessandro Colombo
AIT Austrian Institute of Technology, Vienna, Austria
M
Margherita Cozzolino
Independent Researcher, Trento, Italy
Stephan Krenn
Stephan Krenn
AIT Austrian Institute of Technology GmbH
CryptographySecurityPrivacy
T
Thomas LorΓΌnser
AIT Austrian Institute of Technology, Vienna, Austria; Digital Factory Vorarlberg GmbH, Dornbirn, Austria