SlideShare a Scribd company logo
Quantum-safe data center interconnects
OIDA Executive Forum 2019 – Panel 4: Commercial QKD & Encryption
Jörg-Peter Elbers
A practitioner’s guide
© 2019 ADVA Optical Networking. All rights reserved.22
Intercepting data center traffic is easy and can reveal a vast amount of critical data
Why do we care?
Data center
interconnect (DCI)
DWDM interception devices
10 to 100Gbit/s, direct detect and coherent
Data center A
Data center B
Fiber tapping devices
© 2019 ADVA Optical Networking. All rights reserved.33
On-the-fly encryption secures data communication over insecure channels
What can we do?
AES-256
Public channel
Secret key K
Message M Message M
Alice Bob
Secret key K
Cyphertext C
Diffie-
Hellman
Diffie-
Hellman
Key exchange
Encrypted
data transmission
AES-256
© 2019 ADVA Optical Networking. All rights reserved.44
Quantum computers put secrecy of encrypted data communication at risk
What changes with quantum computers?
Data center A
Data center B
© 2019 ADVA Optical Networking. All rights reserved.55
• Provides computational security
• Is based on difficulty of math problems
• Works on any communication channel
• Requires endpoint protocol access only
• Is independent of optical layer
• Provides information-theoretic security
• Is based on laws of quantum physics
• Needs optical fiber or free-space channel
• Requires access to physical infrastructure
• Depends on optical link performance
Quantum-key distribution (QKD)Post-quantum cryptography (PQC)
Note: Security is only as strong as the weakest link in the chain
How can we make the key exchange quantum-safe?
© 2019 ADVA Optical Networking. All rights reserved.66
Long-haul DCI link DCI via Layer 1 VPNMetro DCI link
What are practical DCI deployment scenarios?
Dark
fiber(s)
Amplified
optical
link
(Multi-)
operator
network
Simplest case
Can use separate
fiber for QKD
Typically <100km
QKD needs
trusted nodes
and careful link
engineering
Can only
use PQC
(no optical
layer access)
#1
#2
© 2019 ADVA Optical Networking. All rights reserved.77
UK regional network
EU research networkFinancial institution
Some quantum-safe deployment examples
Cambridge
Adastral Park,
Ipswich
QKD with trusted nodes
Encyrpted DWDM & quantum signal on same fiber
Multi-vendor QKD support
Open key exchange interface
Quantum channel
Encrypted
data channels
<40km point-to-point link
© 2019 ADVA Optical Networking. All rights reserved.88
Key exchange schemes can be combined to provide robust quantum-safe solutions
Do I need to decide on one key exchange scheme?
AES-256-GCM AES-256-GCM
Secret key K
Message M Message M
Alice Bob
Ciphertext C
Diffie-
Hellman
Diffie-
Hellman
Post
quantum
Post
quantum
Key
combiner
Key exchange
Key exchange
QKD QKD
Key exchange
Secret key K
Key
combiner
Thank you
IMPORTANT NOTICE
The content of this presentation is strictly confidential. ADVA Optical Networking is the exclusive owner or licensee of the content, material, and information in this presentation.
Any reproduction, publication or reprint, in whole or in part, is strictly prohibited.
The information in this presentation may not be accurate, complete or up to date, and is provided without warranties or representations of any kind, either express or implied. ADVA
Optical Networking shall not be responsible for and disclaims any liability for any loss or damages, including without limitation, direct, indirect, incidental, consequential and special
damages, alleged to have been caused by or in connection with using and/or relying on the information contained in this presentation.
Copyright © for the entire content of this presentation: ADVA Optical Networking.
jelbers@advaoptical.com

More Related Content

PDF
Coherent or direct detect for the data center interconnect?
PDF
World's first demo of 600G SDN-enabled automation
PDF
Why should higher-layer applications care about software-defined optics?
PDF
Introducing spectrum as a service
PDF
Open optical networks: From Lowest TCO to new revenue generation
PDF
Network management re-architected as a services incubator
PDF
Metro network transformation
PDF
Coherent technologies for short reach applications
Coherent or direct detect for the data center interconnect?
World's first demo of 600G SDN-enabled automation
Why should higher-layer applications care about software-defined optics?
Introducing spectrum as a service
Open optical networks: From Lowest TCO to new revenue generation
Network management re-architected as a services incubator
Metro network transformation
Coherent technologies for short reach applications

What's hot (20)

PDF
Open to open cable: OFC 2018 workshop on undersea systems
PDF
The 400G transition
PDF
Application-optimized 100G demarcation and aggregation
PDF
SatAware assures satellite-based timing
PDF
Security and services drive data north
PDF
Introducing G.metro
PDF
Photonic integrated circuits for data center interconnects
PDF
Photonic integrated circuits for data center interconnects
PDF
Reducing RAN infrastructure resources by leveraging 5G RAN Transport Technolo...
PDF
Introducing the FSP 150-XG118Pro
PDF
Wholesale network slicing for 5G access
PDF
FSP 150-GO102Pro Series: Redefining demarcation for the small cell era
PDF
A new benchmark for timing success - OSA 5412 and 5422 access grandmasters
PDF
Drive down latency and costs in the access network with the MicroMux™ Edge BiDi
PDF
Soldani the path_to_5_g_vtc_spring_2017_final
PDF
Solving the 5G fronthaul challenge with Ethernet and passive WDM
PDF
Transforming network operations with Ensemble Controller
PPTX
Low latency for DCI and mobile applications
PDF
Yao Wenbing, Huawei - INCA Full Fibre & 5G Seminar 12/7/17
PDF
Ericsson Radio Dot System: Introduction
Open to open cable: OFC 2018 workshop on undersea systems
The 400G transition
Application-optimized 100G demarcation and aggregation
SatAware assures satellite-based timing
Security and services drive data north
Introducing G.metro
Photonic integrated circuits for data center interconnects
Photonic integrated circuits for data center interconnects
Reducing RAN infrastructure resources by leveraging 5G RAN Transport Technolo...
Introducing the FSP 150-XG118Pro
Wholesale network slicing for 5G access
FSP 150-GO102Pro Series: Redefining demarcation for the small cell era
A new benchmark for timing success - OSA 5412 and 5422 access grandmasters
Drive down latency and costs in the access network with the MicroMux™ Edge BiDi
Soldani the path_to_5_g_vtc_spring_2017_final
Solving the 5G fronthaul challenge with Ethernet and passive WDM
Transforming network operations with Ensemble Controller
Low latency for DCI and mobile applications
Yao Wenbing, Huawei - INCA Full Fibre & 5G Seminar 12/7/17
Ericsson Radio Dot System: Introduction
Ad

Similar to Quantum-safe data center interconnects (20)

PDF
The quantum age - secure transport networks
PPTX
How to Quantum-Secure Optical Networks
PPTX
ADVA launches world’s first commercial optical transport solution with post-q...
PDF
Quantum threat: How to protect your optical network
PDF
Hao_Qin_Presentation-秦博士.pdf
PDF
(SACON) M T Karunakaran  - Quantum safe Networks
PDF
Secure WDM Connectivity for High-Bandwidth Applications
PPTX
Network Security
PPTX
Layer 1 Encryption in WDM Transport Systems
PPTX
Polymorphic Attacks on Data-in-Motion Require a New Security Approach From Bo...
PDF
20201111 kuppinger-qsn-final
PDF
Secure Optical Connectivity Solutions for High-Capacity Data Centers
PPTX
100G Metro Encryption
PDF
Transforming DCI connectivity with the FSP 3000 S-Flex
PDF
Scalable, Secure, Programmable – Cloud Connectivity for the Future
PPT
QCrypt
PDF
Exploring Quantum Engineering for Networking by Melchior Aelmans, Juniper Net...
PPTX
Secure Connectivity on Every Network Layer
PPTX
Silicon Photonics for Inter-Data Center Interconnects
PDF
ADVA ConnectGuard™
The quantum age - secure transport networks
How to Quantum-Secure Optical Networks
ADVA launches world’s first commercial optical transport solution with post-q...
Quantum threat: How to protect your optical network
Hao_Qin_Presentation-秦博士.pdf
(SACON) M T Karunakaran  - Quantum safe Networks
Secure WDM Connectivity for High-Bandwidth Applications
Network Security
Layer 1 Encryption in WDM Transport Systems
Polymorphic Attacks on Data-in-Motion Require a New Security Approach From Bo...
20201111 kuppinger-qsn-final
Secure Optical Connectivity Solutions for High-Capacity Data Centers
100G Metro Encryption
Transforming DCI connectivity with the FSP 3000 S-Flex
Scalable, Secure, Programmable – Cloud Connectivity for the Future
QCrypt
Exploring Quantum Engineering for Networking by Melchior Aelmans, Juniper Net...
Secure Connectivity on Every Network Layer
Silicon Photonics for Inter-Data Center Interconnects
ADVA ConnectGuard™
Ad

More from ADVA (20)

PDF
Industrial optically pumped cesium beam clock
PDF
The need for GBaaS as GPS/GNSS is no longer a reliable source for critical PN...
PDF
Industry's longest holdover with the OSA 3350 SePRC™ optical cesium clock
PDF
Addressing PNT threats in critical defense infrastructure
PDF
Precise and assured timing for enterprise networks
PDF
Introducing Ensemble Cloudlet for on-premises cloud demand
PDF
ePRTC in data centers - GNSS-backup-as-a-service (GBaaS)
PDF
Sync on TAP - Syncing infrastructure with software
PDF
Meet stringent latency demands with time-sensitive networking
PDF
Making networks secure with multi-layer encryption
PDF
Optical networks and the ecodesign tradeoff between climate change mitigation...
PDF
Trends in next-generation data center interconnects (DCI)
PPTX
Open optical edge connecting mobile access networks
PDF
Introducing Adva Network Security – a trusted German anchor
PDF
Meet the industry's first pluggable 10G demarcation device
PDF
Introducing ADVA AccessWave25™
PDF
10G edge technology for outdoor environments
PDF
From leased lines to optical spectrum services
PDF
The coherent optical edge
PDF
Get your timing right for 5G OpenRAN!
Industrial optically pumped cesium beam clock
The need for GBaaS as GPS/GNSS is no longer a reliable source for critical PN...
Industry's longest holdover with the OSA 3350 SePRC™ optical cesium clock
Addressing PNT threats in critical defense infrastructure
Precise and assured timing for enterprise networks
Introducing Ensemble Cloudlet for on-premises cloud demand
ePRTC in data centers - GNSS-backup-as-a-service (GBaaS)
Sync on TAP - Syncing infrastructure with software
Meet stringent latency demands with time-sensitive networking
Making networks secure with multi-layer encryption
Optical networks and the ecodesign tradeoff between climate change mitigation...
Trends in next-generation data center interconnects (DCI)
Open optical edge connecting mobile access networks
Introducing Adva Network Security – a trusted German anchor
Meet the industry's first pluggable 10G demarcation device
Introducing ADVA AccessWave25™
10G edge technology for outdoor environments
From leased lines to optical spectrum services
The coherent optical edge
Get your timing right for 5G OpenRAN!

Recently uploaded (20)

PDF
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
PPTX
SOPHOS-XG Firewall Administrator PPT.pptx
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
NewMind AI Weekly Chronicles - August'25-Week II
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PPTX
Programs and apps: productivity, graphics, security and other tools
PPTX
Tartificialntelligence_presentation.pptx
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
PDF
gpt5_lecture_notes_comprehensive_20250812015547.pdf
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
cuic standard and advanced reporting.pdf
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
Approach and Philosophy of On baking technology
PDF
Machine learning based COVID-19 study performance prediction
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
SOPHOS-XG Firewall Administrator PPT.pptx
Building Integrated photovoltaic BIPV_UPV.pdf
NewMind AI Weekly Chronicles - August'25-Week II
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Digital-Transformation-Roadmap-for-Companies.pptx
Programs and apps: productivity, graphics, security and other tools
Tartificialntelligence_presentation.pptx
Network Security Unit 5.pdf for BCA BBA.
Reach Out and Touch Someone: Haptics and Empathic Computing
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Unlocking AI with Model Context Protocol (MCP)
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
gpt5_lecture_notes_comprehensive_20250812015547.pdf
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
cuic standard and advanced reporting.pdf
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
Per capita expenditure prediction using model stacking based on satellite ima...
Approach and Philosophy of On baking technology
Machine learning based COVID-19 study performance prediction

Quantum-safe data center interconnects

  • 1. Quantum-safe data center interconnects OIDA Executive Forum 2019 – Panel 4: Commercial QKD & Encryption Jörg-Peter Elbers A practitioner’s guide
  • 2. © 2019 ADVA Optical Networking. All rights reserved.22 Intercepting data center traffic is easy and can reveal a vast amount of critical data Why do we care? Data center interconnect (DCI) DWDM interception devices 10 to 100Gbit/s, direct detect and coherent Data center A Data center B Fiber tapping devices
  • 3. © 2019 ADVA Optical Networking. All rights reserved.33 On-the-fly encryption secures data communication over insecure channels What can we do? AES-256 Public channel Secret key K Message M Message M Alice Bob Secret key K Cyphertext C Diffie- Hellman Diffie- Hellman Key exchange Encrypted data transmission AES-256
  • 4. © 2019 ADVA Optical Networking. All rights reserved.44 Quantum computers put secrecy of encrypted data communication at risk What changes with quantum computers? Data center A Data center B
  • 5. © 2019 ADVA Optical Networking. All rights reserved.55 • Provides computational security • Is based on difficulty of math problems • Works on any communication channel • Requires endpoint protocol access only • Is independent of optical layer • Provides information-theoretic security • Is based on laws of quantum physics • Needs optical fiber or free-space channel • Requires access to physical infrastructure • Depends on optical link performance Quantum-key distribution (QKD)Post-quantum cryptography (PQC) Note: Security is only as strong as the weakest link in the chain How can we make the key exchange quantum-safe?
  • 6. © 2019 ADVA Optical Networking. All rights reserved.66 Long-haul DCI link DCI via Layer 1 VPNMetro DCI link What are practical DCI deployment scenarios? Dark fiber(s) Amplified optical link (Multi-) operator network Simplest case Can use separate fiber for QKD Typically <100km QKD needs trusted nodes and careful link engineering Can only use PQC (no optical layer access) #1 #2
  • 7. © 2019 ADVA Optical Networking. All rights reserved.77 UK regional network EU research networkFinancial institution Some quantum-safe deployment examples Cambridge Adastral Park, Ipswich QKD with trusted nodes Encyrpted DWDM & quantum signal on same fiber Multi-vendor QKD support Open key exchange interface Quantum channel Encrypted data channels <40km point-to-point link
  • 8. © 2019 ADVA Optical Networking. All rights reserved.88 Key exchange schemes can be combined to provide robust quantum-safe solutions Do I need to decide on one key exchange scheme? AES-256-GCM AES-256-GCM Secret key K Message M Message M Alice Bob Ciphertext C Diffie- Hellman Diffie- Hellman Post quantum Post quantum Key combiner Key exchange Key exchange QKD QKD Key exchange Secret key K Key combiner
  • 9. Thank you IMPORTANT NOTICE The content of this presentation is strictly confidential. ADVA Optical Networking is the exclusive owner or licensee of the content, material, and information in this presentation. Any reproduction, publication or reprint, in whole or in part, is strictly prohibited. The information in this presentation may not be accurate, complete or up to date, and is provided without warranties or representations of any kind, either express or implied. ADVA Optical Networking shall not be responsible for and disclaims any liability for any loss or damages, including without limitation, direct, indirect, incidental, consequential and special damages, alleged to have been caused by or in connection with using and/or relying on the information contained in this presentation. Copyright © for the entire content of this presentation: ADVA Optical Networking. jelbers@advaoptical.com