PQ-NEXT Core: The Pilot Edition – Telefónica Innovación Digital
Discover the PQ-NEXT Pilots
The PQ-NEXT solutions will be validated through large-scale pilots across the finance, critical infrastructure, telecommunications, and digital identity sectors, leveraging selected digital twin use cases. Throughout this blog series, we will take a closer look at each pilot, exploring its objectives, implementation, expected outcomes, and its role in advancing the transition to post-quantum security.
The Telefónica Innovación Digital Pilot
Pilot 2: Quantum-secure orchestration on a Telco Network
The Pilot
In recent years, networks have evolved into infrastructures that are more complex than they used to be, with multi-domain architectures, network programmability (SDN or NFV), and even the inclusion of AI-based automation. This is the scenario in which Pilot 2, Quantum-secure orchestration on a Telco Network, will be developed. This use case will evaluate the transition of network Operation and Management (OAM) to quantum-secure solutions. This pilot will identify the protocols and tools involved in the management plane and demonstrate the transition solution for the critical protocols. This scenario will select relevant domains in telco networks (cloud, transport, access, interconnection, etc.) and apply the best transition approach based on PQC and QKD hybridization.
This use case will be developed by TID in collaboration with UPM, using real infrastructure, since part of it will be developed and tested on a segment of MadQCI (Madrid Quantum Communication Infrastructure) in order to extract relevant information from real networks.
The Why
What is the problem the pilot will address, the sector motivation, and the quantum threat rationale?
Telecommunications networks have now reached a very high level of complexity, with many components depending on one another, including multi-domain architectures, IoT devices, and even the use of AI for automation. This creates significant security challenges, since with so many components involved, a vulnerability in just one of them may put the entire network at risk.
The threat posed by quantum attacks is particularly sensitive for telecommunications networks, as they are built upon highly heterogeneous infrastructures involving multiple vendors, technological domains, equipment generations, and software releases. This complexity is further increased by the fact that network infrastructures continuously evolve, while some components progressively become legacy systems. In many cases, these legacy devices may not be included in vendors’ quantum-safe migration roadmaps, leaving operators dependent on third-party decisions and timelines. As a result, the transition to post-quantum technologies may introduce interoperability challenges, some devices may become incompatible with others during the transition to post-quantum technologies is carried out.
Another issue that has been identified is that the roadmaps for the post-quantum transition of network equipment manufacturers are very long-term, which means that we currently cannot be certain how networks will behave once the transition to post-quantum technologies takes place. Moreover, since the telecommunications networks are already in operation, any update towards PQC-based solutions is particularly sensitive and must first be tested on a small-scale laboratory environments before being introduced into production networks. For this reason, it is very important to start carrying out this type of testing on a smaller scale in order to validate the transition.
With this use case, we aim to understand how the post-quantum transition will affect the quality of service provided by current networks, in order to fully understand all the implications it brings and to help define a set of recommendations and a roadmap for how the transition should be implemented while minimizing its impact on the current infrastructure.
The How
The technical approach, deployment environment, tools, and expected outcomes
To carry out the use case, quantum-safe implementations of the different protocols used in telecommunications networks will be tested, using standardized PQC algorithms and QKD. The pilot will test not only the security of the protocols, but also the deployment of a PKI system that uses PQC algorithms and hybridization based on the ACME (RFC 8555) and ACME-STAR standard (RFC 8739).
Another aspect to be tested in this pilot is the use of solutions that enable not only interoperability between quantum-safe solutions across devices from different manufacturers, in order to avoid dependence on third parties, but also ways to secure the legacy parts of the networks; that is, to identify mechanisms to protect equipment that does not have the capability to implement post-quantum solutions.
All these tests will be carried out both in emulated environments and in real telecommunications network environments. For the real network, MadQCI (Madrid Quantum Communication Infrastructure) will be used; it is one of the largest quantum networks in Europe. All tests performed in these environments will be aimed at assessing the feasibility of the post-quantum transition in real networks.
With all this, the pilot aims to draw conclusions on how the post-quantum transition will affect the current communications network infrastructure, studying both its impact on the quality of service provided and the impact of integrating the systems required for the transition. As a result, it is expected to define a set of guidelines or recommendations on how to carry out the transition, taking into account the importance of ensuring crypto-agility in the systems.