Abstract
Quantum resistance is vital for emerging cryptographic systems as quantumtechnologies continue to advance towards large-scale, fault-tolerant quantumcomputers. Resistance may be offered by quantum key distribution (QKD), whichprovides information-theoretic security using quantum states of photons, butmay be limited by transmission loss at long distances. An alternative approachuses classical means and is conjectured to be resistant to quantum attacks,so-called post-quantum cryptography (PQC), but it is yet to be rigorouslyproven, and its current implementations are computationally expensive. Toovercome the security and performance challenges present in each, here wedevelop hybrid protocols by which QKD and PQC inter-operate within a jointquantum-classical network. In particular, we consider different hybrid designsthat may offer enhanced speed and/or security over the individual performanceof either approach. Furthermore, we present a method for analyzing the securityof hybrid protocols in key distribution networks. Our hybrid approach paves theway for joint quantum-classical communication networks, which leverage theadvantages of both QKD and PQC and can be tailored to the requirements ofvarious practical networks.