QSTARS: Quantum-Secure Transmission, Authentication, Resilience and Sensing

The security of digital networks is entering a new phase. Future communication infrastructures must not only protect data against today’s cyberattacks, but also remain secure in the presence of quantum computers, increasingly complex network architectures, and changing physical environments.

The QSTARS project addresses this challenge through a holistic approach: Quantum Secure Transmission, Authentication, Resilience and Sensing. Its goal is to investigate how future networks can combine cryptographic security, physical-layer security, network-based sensing, and adaptive resilience into one integrated security architecture.

At the core of QSTARS is the idea that secure communication should not rely on a single protection mechanism. Instead, transmission and authentication at every network endpoint should be protected by two independent security factors:

  • Post-Quantum Cryptography (PQC), which provides cryptographic protection against quantum attacks, and
  • Physical Layer Security (PLS), which exploits the physical properties of the communication channel itself.

Together, these two factors can strengthen both the confidentiality and the authenticity of network communication.

Two Security Technologies: PQC and PLS

QSTARS builds on two complementary technology families.

The first is Post-Quantum Cryptography. PQC is the cryptographic answer to the quantum threat. It uses mathematical problems that are believed to remain hard even for quantum computers. PQC is attractive because it can be implemented in software, integrated into existing protocols, and used for true end-to-end security between communicating endpoints.

The second technology family is Physical Layer Security. PLS takes a fundamentally different approach. Instead of relying only on computational assumptions, it uses the physical properties of the transmission channel. Under suitable conditions, PLS can provide information-theoretic security, meaning that security does not depend on the limited computing power of an attacker.

PLS can appear in different forms. One important approach is wiretap coding, where the sender exploits differences between the legitimate receiver’s channel and a potential eavesdropper’s channel. The message is encoded in such a way that the legitimate receiver can recover it, while the attacker only observes a degraded or unusable version.

Another approach is Quantum Key Distribution, or QKD, where quantum effects are used to generate shared secret keys. QKD can provide strong security guarantees, but it also comes with practical limitations, especially in terms of key rate, infrastructure requirements, and network architecture.

The Security Triangle: Data Rate, Security and End-to-End Protection

A useful way to compare these technologies is the three-dimensional security triangle. It captures three essential dimensions of secure communication:

  • data rate, meaning how much secure information can be transmitted;
  • security metrics, meaning whether the system provides computational or information-theoretic protection; and
  • end-to-end capability, meaning whether protection holds directly from sender to receiver without relying on trusted intermediate nodes.

Figure 1: The security triangle for PQC, PLS, QKD, Quantum Repeater and QSTARS technology.

Post-Quantum Cryptography performs very well in two of these dimensions. It supports high data rates and enables true end-to-end communication. However, PQC is not information-theoretically secure. Its security is based on mathematical assumptions. These assumptions are designed to withstand quantum attacks, but they remain assumptions.

Physical Layer Security performs strongly in the security dimension. It can provide information-theoretic guarantees because its protection comes from physical channel properties rather than computational hardness. However, PLS often depends on channel conditions, channel knowledge, and sometimes trusted network nodes. This can limit its end-to-end character.

QKD, as a special PLS implementation, also provides strong security, but typically at a much lower key rate than classical data transmission. When QKD is deployed with trusted nodes, it is not fully end-to-end. Quantum repeaters could help QKD become end-to-end in future quantum networks, but they introduce additional technological complexity and can reduce the already limited achievable key rate even further.

This means that no single technology maximizes all three dimensions on its own. PQC is fast and end-to-end, but not information-theoretically secure. PLS can be information-theoretically secure, but is often not fully end-to-end. QKD is highly secure, but limited by key rate and infrastructure constraints.

QSTARS: Combining the Strengths of PQC and PLS

The central idea of QSTARS is to investigate the combination of Post-Quantum Cryptography and Physical Layer Security.

This combination is powerful because the two technologies compensate for each other’s weaknesses. PQC contributes high data rates, practical integration, and end-to-end protection. PLS contributes security properties that originate from the physical channel and can provide an additional, independent layer of protection.

In QSTARS, this combination is not limited to data transmission alone. It is also applied to authentication. Every network endpoint should be secured using two factors: a cryptographic factor based on PQC and a physical-layer factor based on PLS, for example making use of (Quantum) Physical Unclonable Functions. This creates a stronger security model. Even if one factor were weakened, the second factor would still provide protection.

The result is a two-factor security architecture for both transmission and authentication.

Network as a Sensor

A further key element of QSTARS is the concept of the Network as a Sensor (NaaS).
Modern communication networks constantly produce measurable physical and technical artefacts. These may include channel state information, signal quality, noise levels, interference patterns, latency variations, packet loss, link stability, and other observable classical or quantum characteristics of the transmission environment.

QSTARS investigates how such measured artefacts can be used to determine the security metrics of a network. Instead of treating the network merely as a passive transport infrastructure, the network becomes an active source of security-relevant information.

This sensing capability can help answer questions such as:

  • How good is the legitimate communication channel?
  • How much uncertainty does a potential attacker face?
  • How suitable is the current channel for physical-layer security?
  • Has the security situation changed due to interference, mobility, attacks, faults, or environmental effects?
  • Which security parameters are currently required to maintain a desired level of protection?
  • Do the security proof assumptions still hold?

Hence, sensing becomes a foundation for measurable and adaptive security.

Resilience Through Adaptive Security Parameters

Security is not static. Network conditions can change over time. A channel that is secure under one set of conditions may become less favorable later. Interference may increase. Signal quality may degrade. A new attacker may appear. Network topology may change. Physical-layer assumptions may become weaker.

QSTARS addresses this through resilience.

Resilience means that the network does not merely detect a deterioration of the security situation, but can react to it. If measured artefacts indicate that the security level has decreased, the system could respond by adapting its security parameters.

For example, the network may increase coding redundancy, change wiretap coding parameters, adjust key-generation mechanisms, strengthen authentication requirements, modify cryptographic parameter choices, change routing decisions, or combine PQC and PLS more conservatively.

The basic principle is simple: measure, evaluate, adapt.

The network senses its physical and technical environment. From these measurements, it derives security metrics. If these metrics indicate a weaker security situation, the system responds with improved security parameters. This creates a feedback loop that turns security from a fixed configuration into an adaptive capability.

The QSTARS Vision

QSTARS stands for a broader vision of future network security:

  • Quantum Secure Transmission, protecting data against quantum-era threats.
  • Authentication, securing every endpoint with both PQC and PLS.
  • Resilience, enabling the network to react to deteriorating security conditions.
  • Sensing, using the network itself to measure artefacts and derive security metrics.

The project investigates how these elements can work together in one integrated architecture.

The key idea is that future secure networks should combine the advantages of cryptography and physical-layer security. PQC provides scalability, end-to-end capability, and high data rates. PLS provides an additional layer of security based on the physical channel. Sensing provides the measurements needed to understand the current security state. Resilience provides the ability to adapt when that state changes.

Together, these components move the security triangle closer to its ideal form: high data rate, strong security, and end-to-end protection. This makes QSTARS more than a project about quantum-safe communication. It is a step toward adaptive, measurable, and multi-layered security for future networks, where transmission, authentication, resilience, and sensing are designed together from the beginning.