This paper provides a comprehensive, system-level taxonomy for designing quantum-resistant network architectures, moving beyond simple protocol substitutions to address key distribution and management challenges across diverse deployment environments.
Large-scale quantum computers threaten the public-key cryptographic foundations underpinning today's network security infrastructures. While significant progress has been made in standardizing post-quantum cryptographic (PQC) primitives and adapting individual protocols such as TLS and SSH, far less attention has been paid to the broader architectural consequences of the post-quantum transition for networked systems. In particular, many real-world deployments such as mobile networks, industrial control systems, IoT environments, and regulated infrastructures cannot assume the universal availability, deployability, or desirability of PQ public-key infrastructures. This paper presents the first comprehensive systematization of PQ-resistant network architectures, focusing on key distribution and management as a system-level design problem rather than a protocol-local substitution. We introduce a unified taxonomy spanning cryptographic foundations (symmetric-only, PQ-PKI, hybrid, and information-theoretic multi-path), key-distribution architectures (centralized, hierarchical, replicated, threshold, MPC-backed, and serverless), trust and threat models, key-management lifecycle, and deployment environments. Using this framework, we analyze the security, scalability, and operational trade-offs of a wide range of architectures under realistic PQ adversary assumptions, including harvest-now, decrypt-later attacks and partial infrastructure compromise. Our study highlights fundamental gaps in existing approaches, clarifies when PQ-PKI is necessary or avoidable, and identifies promising research directions for building cryptographically agile, quantum-resilient network infrastructures.
The Quantum-Cryptographic Co-evolution
The paper proposes a two-dimensional coordinate system to map the co-evolution o…
Quantum-Safe Code Auditing: LLM-Assisted Static Analysis and Quantum-Aware Risk Scoring for Post-Qua…
The paper introduces Quantum-Safe Code Auditor, a novel static analysis framewor…
IPsec based on Quantum Key Distribution: Adapting non-3GPP access to 5G Networks to the Quantum Era
This paper designs and validates a Quantum Key Distribution (QKD) based mechanis…
Efficient ML-DSA Public Key Management Method with Identity for PKI and Its Application
The paper proposes a novel identity-based public key management framework, IPK-p…
Quantum Bit Error Rate Analysis in BB84 Quantum Key Distribution: Measurement, Statistical Estimatio…
This paper systematically analyzes the Quantum Bit Error Rate (QBER) in the BB84…
Post-Quantum Cryptography from Quantum Stabilizer Decoding
The paper proposes that decoding random quantum stabilizer codes is a robust, no…
Empowering Mobile Networks Security Resilience by using Post-Quantum Cryptography
This paper demonstrates a non-disruptive, sidecar-based integration of NIST-stan…
Information-Theoretic Solutions for Seedless QRNG Bootstrapping and Hybrid PQC-QKD Key Combination
The paper proposes a unified, information-theoretic framework using universal ha…