Cyprus University of Technology Reports 99.1 Percent Mean Scheduled-Link Availability Across a Seven-Node QKD Network Over Existing Nicosia Fiber for 73 Days, arXiv 21 September 2026

Quentir Defense Monitor

Evidence-based insights for quantum defense and security. Published by Quentir Systems LLC · September 22, 2026.

Cyprus University of Technology Reports 99.1 Percent Mean Scheduled-Link Availability Across a Seven-Node QKD Network Over Existing Nicosia Fiber for 73 Days, arXiv 21 September 2026

On September 21, 2026, seven researchers from the PhOSLab at the Cyprus University of Technology in Limassol posted a paper to arXiv describing a seven-node quantum key distribution network that ran for 73 days over fiber already lying under Nicosia. Mariella Minder, Andreas Siakolas, Elizabeth Pasatembou, Stylianos Mavrikos, Stephanos Yerolatsitis, Konstantinos Katzis and Kyriacos Kalli built it to serve governmental end-users, and they call it, to their knowledge, the first multi-node QKD network demonstrated in Cyprus. The European Commission and the Cyprus Deputy Ministry of Research, Innovation and Digital Policy co-funded the work.

The interest for a defense reader lies less in the physics than in the plumbing. Nothing in the paper is a new protocol or a longer distance. The contribution is a network engineered around what a government already owns: 42 kilometers of metropolitan fiber with its patch panels, splices and losses, a set of commercial QKD units, commercial encryptors and a proprietary key management system, joined into one service by a single optical switch. The arXiv paper reports what that arrangement delivered, hour by hour, and where the layers pulled on one another.

What Cyprus University of Technology built: seven nodes, 42 kilometers of Nicosia fiber and a four-plus-three topology on QTI hardware

The seven nodes sit at governmental sites in Nicosia and fall into two functional classes, which the authors turn into two use cases. Use case one is a four-node trusted-node ring joining nodes N1, N5, N6 and N7. Use case two is a three-node subnetwork of N2, N3 and N4 with permanent links N2 to N3 and N3 to N4. Each node holds at least one QKD transmitter and one receiver. The quantum hardware is the Quell-X and Quell-XR series from Quantum Telecommunications Italy, running a time-bin, three-state protocol with one decoy state at a 600 megahertz pulse rate, and the QKME key management modules from the same vendor. Every route segment uses two fibers: the quantum channel runs on its own dark fiber, and synchronization, key management traffic and application traffic are wavelength-multiplexed onto the second, classical fiber.

The fiber is the story. Total optical path length across the eight link configurations comes to 108 kilometers, and the loss budget shows what brownfield deployment means in practice. The 18.6-kilometer link from N1 to N7 loses 19.2 decibels. The 2.3-kilometer link from N7 to N6 loses 13.0 decibels, an amount that would correspond to roughly 60 kilometers of clean fiber and instead comes from connectors, filters and switching inserted along a short urban path. The two spectral plans the paper compares are a response to exactly this. In the ring, all four QKD carriers first sat at the nominal dense-wavelength-division-multiplexing channel 40 near 1545.32 nanometers, then were offset from one another inside that channel and separated with 10-gigahertz optical filters. In the subnetwork, the quantum links occupy distinct DWDM channels instead.

Above the quantum layer sits a logically meshed key management layer. It delivers keys directly where a QKD link exists and by trusted relay where it does not, and it feeds three consumers. Adtran FSP 3000R7 Layer 1 encryptors between all ring nodes create 10-gigabit-per-second bidirectional tunnels and draw 256 bits per minute per protected connection to refresh their AES session keys. Telsy MusaX Layer 3 IP encryptors on the N2 to N4 link draw 128 bits per minute. An on-demand one-time-pad file encryption application is available to endpoint pairs. The mean quantum bit error rate across links was 1.2 percent, and secret keys were distilled from privacy amplification blocks of one million detections with a secrecy parameter of one in a billion.

What 73 days from 10 February to 25 April 2026 showed: 119.4 gigabits of key, 99.1 percent mean scheduled-link availability and 2.7 kilobits per second per link

Monitoring ran from noon on February 10, 2026 to midnight on April 25, more than 73 consecutive days. Over that window the eight link configurations generated 119.4 gigabits of secret key material with 99.1 percent mean scheduled-link availability. Availability is defined plainly: an outage is any contiguous interval longer than one hour in which a link was expected to operate and produced no secret key, and availability is the fraction of scheduled operating time outside such intervals. Per-link secret key rates ranged from 1.7 kilobits per second on the lossy N1 to N7 span to 3.9 kilobits per second on the 5-kilometer N4 to N3 span, with a mean of 2.7 kilobits per second across links.

Quentir's Medicine lane read a German rural link that carried 12.7 bits per second over 140 kilometers of aerial-heavy fiber to secure a village telemedicine kiosk; the Nicosia links run two hundred times faster because they are short, and they still supply only a few kilobits per second each. That is ample for AES key refresh at 256 bits per minute per tunnel and thin for continuous one-time-pad use of any volume.

Quantum pillar: networking (quantum key distribution links). Use posture: defensive. Technology readiness: Quentir assesses the network at TRL 7 of 9. The network combines commercial QKD units, encryptors and key management running for 73 days on government fiber, while the publication does not provide sufficient implementation and audit evidence for independent assessment of its proprietary key management, control logic and trusted-node relaying.

How one optical switch turned nine reachable endpoint pairs into 21, and what randomized end-to-end requests revealed

The paper's central experiment is a reconfiguration. A duplex two-by-one optical switch at the first optical distribution frame connects the QKD transmitter at N2 either to the receiver at N4, closing the three-node subnetwork, or to the receiver at N1, joining the subnetwork to the ring. With the switch set toward N4, the two clusters are separate and nine endpoint pairs can obtain keys. With the switch set toward N1, all seven nodes connect and all 21 endpoint pairs become logically reachable through trusted relaying. The authors put the gain at 133 percent in logical reachability without provisioning an additional QKD transmitter. The cost is time: after a switch, transmitter reuse adds 17 minutes, plus or minus five, before fresh key material is available on the new link.

A second experiment probed how the layers interact. Five endpoint pairs issued randomized end-to-end key requests over roughly five hours, each asking for between 500 and 2,001 keys of 256 bits. Completion times ran from about 27 to 82 minutes and effective delivery rates from 88.4 to 114.8 bits per second. Routes averaging 3.43 to 3.78 physical QKD hops delivered at 88.4 to 88.9 bits per second, against 109.9 to 114.8 bits per second for routes averaging fewer hops. The finding the authors draw out is that an end-to-end trusted-relay request does not require every constituent link to be generating at the moment of the request, because stored key on each hop can be spent, and that key consumption, stored-key state and quantum-layer reconfiguration are therefore coupled indirectly through the key management layer. Route selection ran on a cost function whose weights are the vendor's and are not disclosed.

Why a metropolitan trusted-node QKD network is defensive capability, and who gains from it

What this lets a government do is concrete. A ministry with seven sites across a capital can refresh the keys of its Layer 1 and Layer 3 encryptors from a source whose secrecy rests on measured photon statistics rather than on the assumed hardness of a mathematical problem, and it can do so over the fiber it already leases. Properly authenticated and implemented QKD can mitigate future quantum attacks on key establishment, subject to the security of trusted relays and endpoints. It does not stop an adversary from collecting traffic, and the paper does not provide sufficient implementation and audit evidence to establish independently that this deployment achieved that protection. The posture is defensive in the sense of the Monitor's capability map: the capability protects the operator's own traffic and offers nothing to an attacker who acquires it, beyond the same protection for their own links.

The gain is limited by two facts that the paper states without dressing them up. The first is trust. Every path across the ring that spans more than one hop depends on trusted-node security assumptions: the intermediate node holds the key in the clear and re-encrypts it onward, so the physical security of each government site is part of the security of every key it relays. Quentir's Defense lane covered a Chicago experiment in which entangled photons shared busy commercial fiber with 800-gigabit classical channels; the Nicosia network sits one rung below that in ambition, on separate dark fiber, and one rung above it in service, with real encryptors drawing real keys. The second fact is that the network is national by design. The paper does not name the European Quantum Communication Infrastructure, though its co-funding and its 2026 timing match the first terrestrial phase of EuroQCI, in which each member state builds a domestic QKD network ahead of cross-border links and the Eagle-1 satellite.

A buyer should also read the dissent. The UK NCSC, the United Kingdom's national technical authority for cyber security, states in its paper on Quantum networking technologies that QKD provides no authentication, that combining specialized hardware with existing network infrastructure makes systems harder to secure, and that it does not support QKD for government or military use, recommending post-quantum cryptography as the primary mitigation. The Nicosia deployment does not answer that position; it illustrates it. The key management and relay logic are closed, the trusted nodes are the trust, and the paper does not describe its authentication layer.

What stands between a 73-day Nicosia demonstration and a program office relying on it

The first gap is the limited implementation and audit evidence in the publication. The authors themselves propose replacing or adapting the proprietary key management and software-defined-networking functions with an open, fully configurable framework so that the quantum layer and the key layer can be optimized together. The publication does not provide sufficient implementation and audit evidence for a program office to assess the relay independently, evaluate the undisclosed cost-function weights or reconstruct explicit per-request routes. The interfaces relevant to such assessment are the business of the ETSI Industry Specification Group on QKD, which writes the key delivery and security specifications for exactly this layer, and the paper does not say which of them the vendor stack implements.

The second gap is the optical overhead. A 2.3-kilometer link that loses 13 decibels is not a physics limit; it is the price of filters, patch panels and switches added to fiber that was never laid for single photons. The authors list lower-loss routing and filtering, and quantum-classical coexistence on shared fiber, as next steps. Lower optical loss could improve key rates, while coexistence could reduce fiber requirements but may introduce noise; its effect on secret-key rates must be measured on these routes. The third gap is scale. Seven nodes across one city is a metropolitan QKD network; the authors name inter-city links as future work, and the 17-minute penalty on every reconfiguration would matter more on a larger mesh with more contention for transmitters.

What the paper establishes is a scheduled-link measurement: commercial QKD hardware, over ordinary government fiber, with commercial encryptors on top, ran for 73 days with 99.1 percent mean scheduled-link availability and delivered enough key for every tunnel it fed, and one switch was enough to make a seven-node mesh out of two clusters. What it does not establish is that any of it is secure against an adversary inside a trusted node, and the publication does not provide sufficient implementation and audit evidence for independent assessment of the closed stack. The next results to look for are an open key management layer with published interfaces, a coexistence run on the same routes and a cross-border link out of Cyprus under the EuroQCI plan.

Sources

Primary source: Mariella Minder, Andreas Siakolas, Elizabeth Pasatembou, Stylianos Mavrikos, Stephanos Yerolatsitis, Konstantinos Katzis and Kyriacos Kalli, "A Reconfigurable Multilayer Quantum Key Distribution Network over Existing Metropolitan Fibre," arXiv 2609.24561, posted September 21, 2026. Other material: the European Commission's EuroQCI policy page; the UK NCSC whitepaper on quantum security technologies; the ETSI Industry Specification Group on Quantum Key Distribution page.

  1. arXiv paper
  2. EuroQCI
  3. Quantum networking technologies
  4. ETSI Industry Specification Group on QKD
Next
Next

Georgia Tech's Jo and Lee Cut the Quantum Elliptic Curve Attack to 5n/2 Logical Qubits and Near-Quadratic Toffoli Gates, IACR ePrint 2026/2014, 14 September 2026