BlogsAug 2026

What ETSI GS QKD 014 actually standardises

The interface between a key delivery system and the equipment that consumes the keys is the part of a QKD deployment operators touch most. Here is what the standard covers, and what it deliberately leaves open.

Most conversations about quantum key distribution stay on the physics. For an operator planning a deployment, the more pressing question is duller and more useful: how does a key get from the QKD layer into the encryptor that needs it? That is the job of ETSI GS QKD 014.

What the standard defines

ETSI GS QKD 014 specifies a REST interface over which an application requests key material from a key management system. It defines three operations: ask what a key store can offer, request keys, and request the matching keys by identifier at the other end of the link. Everything is expressed in ordinary HTTPS with mutual TLS, which means the equipment consuming the keys needs no quantum-specific software.

Why an identifier, not a channel

The two encryptors never exchange the key itself. One side asks for a key and receives both the key and an identifier; it sends only the identifier over the classical network. The far side asks its own key store for the key with that identifier. The key never crosses the network in any form, which is the entire point.

What it leaves open

The standard says nothing about how keys are produced, how a multi-node network routes them, or how a key store behaves when it runs dry. Those are implementation decisions, and they are where deployments differ most. A key store that blocks under load and one that falls back to a slower key source will both pass a conformance test and behave very differently on a Friday afternoon.

What to ask a vendor

Three questions separate a working integration from a demonstration. Which version of the specification is implemented, and is the interface exposed per link or per domain? What happens to a key request when the key store is empty, and is that behaviour configurable? And can the key store be driven by a controller that manages more than one link, or does every pair of nodes need its own integration?

If the answers are concrete, the integration is usually a day of work. If they are not, budget for a project.

LeadershipRemon BerrevoetsCTIO
LeadershipMichiel PlaisierCFO
What is the Falqon® product portfolio?

The Falqon® portfolio brings together the core technologies required to build and operate Quantum Secure Networks (QSN). The Falqon® MDI-QKD Series enables quantum key distribution across scalable network architectures, the Falqon® Key Manager manages and delivers cryptographic keys across QKD, PQC and hybrid environments and the Falqon® Domain Controller provides centralised control, configuration and monitoring of the quantum network.

What is a Quantum Secure Network (QSN)?

A Quantum Secure Network (QSN) is an operational communication infrastructure that combines quantum key generation, secure key lifecycle management, network orchestration and interoperability within a unified product solution. Rather than protecting individual communication links, Quantum Secure Networks (QSN) embed security directly into the network architecture, enabling trusted connectivity across distributed environments. 

News and Press·September 2026

Q*Bird becomes Falqon® Systems, building the infrastructure for Quantum Secure Networks (QSN)

Read more→
Blogs·July 2026

Why “harvest now, decrypt later” is already your problem

Read more→