Listing Thumbnail

    pQKD Twin Cloud Edition with VPN

     Info
    Sold by: Quantum B 
    Deployed on AWS
    Free Trial
    Quantum-Resistant VPN for AWS - Secure your AWS cloud VPC with cutting-edge post-quantum encryption, genuine quantum entropy (QRNG), and ETSI QKD compatibility. Designed with Quantum Key Distribution (QKD) principles, and equipped with VPN ensures future-proof protection against evolving cyber threats. Stay ahead with next-generation security for your cloud infrastructure. The hardware required with this listing must be obtained separately. Review the product details for more information.

    Overview

    Open image

    pQKD Twin Cloud Edition is a solution for high-security connectivity between an AWS VPC (Virtual Private Cloud) and a client network, based on the principles of quantum cryptography realized through QKD emulation. On the classical networking side it follows standard VPN principles, enhanced with secure symmetric key exchange provided by QKD emulation technology. This technology ensures full ETSI QKD compatibility, genuine quantum entropy from a quantum random number generator, and uses a standard post-quantum key encapsulation mechanism (FIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism Standard known also as CRYSTALS Kyber). The solution consists of the following elements:

    1. An EC2 server instance on AWS
    2. A client computer on the client network
    3. A pQKD hardware device. The solution schema is presented below in the following picture: https://qkd-ss.s3.eu-west-2.amazonaws.com/pQKD+VPN+diagram.png  As shown in the picture, the VPN network is based on the efficient and secure WireGuard VPN. In our solution, we do not modify the essential security components of the VPN. WireGuard establishes a UDP connection (on port 51920), creating a new virtual network interface in the system. However, for maximum security, the transmitted standard key is encrypted with a presharedKey, identical on both the server and client sides, via an XOR operation, typical for One-Time Pad (OTP) mechanisms. pQKD Twin (on the cloud side) and the pQKD hardware device (on the client network/computer side) provide mechanisms for distributing the presharedKey. Consequently, our solution is a hybrid approach, combining the WireGuard system with a post-quantum key exchange based on quantum entropy. The service requests key generation by connecting to the pQKD service on AWS via the KME (Key Management Entity) port.

    The pQKD service communicates through a TCP link (port 8000) with the client service and its pQKD device (where the quantum key is generated). The keys obtained on both the AWS server and client sides are then incorporated into the WireGuard VPN on each end. On the AWS side, there is an EC2 instance with the following services installed:

    1. WireGuard
    2. A runner service for communication with WireGuard, pQKD, and the client
    3. A software-based implementation of pQKD: pQKD Digital Twin
      This server configuration has been saved as an AMI image on AWS. On the client side, the following components are present:
    4. WireGuard
    5. A service for communication with WireGuard, pQKD, and the AWS server
    6. A pQKD device connected to the client computer network. The hardware component (local side pQKD device) can be ordered here: https://www.quantumblockchains.io/buy-pqkd/ 

    Highlights

    • State-of-the-Art VPN: Built on WireGuard, featuring quantum-resistant encryption key exchange for next-gen security.
    • Post-Quantum Encryption: Utilizes FIPS 203-compliant Crystals-Kyber algorithms for future-proof protection.
    • Genuine Quantum Entropy: Integrated hardware-based QRNG (Quantum Random Number Generator) ensures true quantum randomness.

    Details

    Delivery method

    Delivery option
    64-bit (x86) Amazon Machine Image (AMI)

    Latest version

    Operating system
    Ubuntu 22.04

    Deployed on AWS

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Free trial

    Try this product free for 10 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.

    pQKD Twin Cloud Edition with VPN

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (622)

     Info
    • ...
    Dimension
    Cost/hour
    t3.small
    Recommended
    $0.15
    m6id.16xlarge
    $0.15
    x2idn.metal
    $0.15
    i2.4xlarge
    $0.15
    r6i.large
    $0.15
    h1.4xlarge
    $0.15
    g2.2xlarge
    $0.15
    m7i.xlarge
    $0.15
    i4i.32xlarge
    $0.15
    r5b.xlarge
    $0.15

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    64-bit (x86) Amazon Machine Image (AMI)

    Amazon Machine Image (AMI)

    An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.

    Version release notes

    Version v2.0

    Additional details

    Support

    Vendor support

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 AWS reviews
    No customer reviews yet
    Be the first to write a review for this product.