Overview
pQKD in desktop version
pQKD in desktop version
pQKD - Rack Mounted version
pQKD Twin Cloud Edition is a solution for high-security connectivity between an AWS VPC (Virtual Private Cloud) and a client network, based on the principles of quantum cryptography realized through QKD emulation. On the classical networking side it follows standard VPN principles, enhanced with secure symmetric key exchange provided by QKD emulation technology. This technology ensures full ETSI QKD compatibility, genuine quantum entropy from a quantum random number generator, and uses a standard post-quantum key encapsulation mechanism (FIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism Standard known also as CRYSTALS Kyber). The solution consists of the following elements:
- An EC2 server instance on AWS
- A client computer on the client network
- A pQKD hardware device. The solution schema is presented below in the following picture: https://qkd-ss.s3.eu-west-2.amazonaws.com/pQKD+VPN+diagram.png As shown in the picture, the VPN network is based on the efficient and secure WireGuard VPN. In our solution, we do not modify the essential security components of the VPN. WireGuard establishes a UDP connection (on port 51920), creating a new virtual network interface in the system. However, for maximum security, the transmitted standard key is encrypted with a presharedKey, identical on both the server and client sides, via an XOR operation, typical for One-Time Pad (OTP) mechanisms. pQKD Twin (on the cloud side) and the pQKD hardware device (on the client network/computer side) provide mechanisms for distributing the presharedKey. Consequently, our solution is a hybrid approach, combining the WireGuard system with a post-quantum key exchange based on quantum entropy. The service requests key generation by connecting to the pQKD service on AWS via the KME (Key Management Entity) port.
The pQKD service communicates through a TCP link (port 8000) with the client service and its pQKD device (where the quantum key is generated). The keys obtained on both the AWS server and client sides are then incorporated into the WireGuard VPN on each end. On the AWS side, there is an EC2 instance with the following services installed:
- WireGuard
- A runner service for communication with WireGuard, pQKD, and the client
- A software-based implementation of pQKD: pQKD Digital Twin
This server configuration has been saved as an AMI image on AWS. On the client side, the following components are present: - WireGuard
- A service for communication with WireGuard, pQKD, and the AWS server
- A pQKD device connected to the client computer network. The hardware component (local side pQKD device) can be ordered here: https://www.quantumblockchains.io/buy-pqkd/
Highlights
- State-of-the-Art VPN: Built on WireGuard, featuring quantum-resistant encryption key exchange for next-gen security.
- Post-Quantum Encryption: Utilizes FIPS 203-compliant Crystals-Kyber algorithms for future-proof protection.
- Genuine Quantum Entropy: Integrated hardware-based QRNG (Quantum Random Number Generator) ensures true quantum randomness.
Details
Features and programs
Financing for AWS Marketplace purchases
Pricing
Free trial
- ...
Dimension | Cost/hour |
---|---|
t3.small Recommended | $0.15 |
m6id.16xlarge | $0.15 |
x2idn.metal | $0.15 |
i2.4xlarge | $0.15 |
r6i.large | $0.15 |
h1.4xlarge | $0.15 |
g2.2xlarge | $0.15 |
m7i.xlarge | $0.15 |
i4i.32xlarge | $0.15 |
r5b.xlarge | $0.15 |
Vendor refund policy
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Version v2.0
Additional details
Usage instructions
See documentation: https://www.quantumblockchains.io/decks/pQKD_Twin_Cloud.pdf
Support
Vendor support
Contact us at support@quantumblockchains.io or at
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.