





















Matvey Romanowski, Technische Universität Berlin
Orr Dunkelman, Technische Universität Berlin
Elham Amini, Technische Universität Berlin
Jean-Pierre Seifert, Technische Universität Berlin
Quantum Key Distribution (QKD) enables two par- ties to establish fresh cryptographic key material with information- theoretic security guarantees, given an authenticated classical channel and appropriate device and threat models. As QKD deployments mature from laboratory settings into production- grade field infrastructure, a practical gap emerges: protocol-level metrics such as quantum bit error rate (QBER) and secret key rate (SKR) characterise the quantum link but do not directly specify how exported key blocks as consumed by downstream key management systems (KMS) and cryptographic applications should be validated for stable, anomaly-free behaviour at the delivery interface. This paper addresses that operational gap. We present an anonymised benchmark study of three commercial QKD systems using SENTRY-Q, a reproducible measurement workflow that computes five block-level indicators Hamming weight balance, min-entropy proxy, Lempel–Ziv complexity, Borel normality deviation, and serial correlation complemented by a long-stream NIST SP 800-22 sanity check applied to the concatenated key pool. The study covers N =10,000 exported 256- bit keys per system, spanning a laboratory DV-QKD link (System- 1,∼20 km), a dark-fibre field DV-QKD deployment (System-2, ∼100 km), and a laboratory CV-QKD system (System-3). We scope the contribution as model-based output benchmarking, not as a proof of conditional secrecy. Within that scope, all three systems exhibit block-level distributions consistent with unbiased reference expectations with Hamming weight medians of exactly 128.0 bits and min-entropy medians of 241.85 bits across all systems however, the NIST long-stream sanity check reveals system-differentiated anomalies: a Non-Overlapping Template Matching failure in System-2 and an Overlapping Template Matching failure with borderline Binary Matrix Rank in System-3, that are invisible to block-level analysis. These anomalies do not constitute proven security vulnerabilities; rather, they represent operationally signif- icant signals that warrant engineering investigation. Critically, the block-level and long-stream analysis layers detect fundamentally different failure classes and cannot substitute for one another, both are necessary components of a complete key-delivery-pipeline benchmarking workflow. We discuss deployment implications and provide a standardised regression-testing artefact suitable for acceptance and longitudinal monitoring workflows.
Note: https://sentry-q.sect.tu-berlin.de/
BibTeX
@misc{cryptoeprint:2026/529,
author = {Darshit Suratwala and Matvey Romanowski and Orr Dunkelman and Elham Amini and Jean-Pierre Seifert},
title = {Benchmarking Exported Key Material from Commercial {QKD} Systems Using {SENTRY}-Q: A Model-Based Output Validator},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/529},
year = {2026},
url = {https://eprint.iacr.org/2026/529}
}
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。