A leading next-generation firewall platform securing enterprise networks across some of the most demanding environments in the world, from global financial institutions to critical national infrastructure. Their prevention-focused architecture uses machine learning to inspect all traffic, including applications, threats, and content, tying every session to the user regardless of location or device. With deployments spanning thousands of enterprise and government customers globally, the integrity of their encrypted tunnels is not a configuration detail. It is the foundation every customer's security posture rests on.
"Quantum-derived keys protecting NGFW connections without changing the existing security architecture."
Key Facts
Sector: Network Security / Enterprise
Infrastructure: Next-Generation Firewall (NGFW) platform integrated with QNu Labs QKDN
Solutions Deployed: QKDN (Quantum Key Distribution Network) via ETSI GS QKD 014 interface
Integration Method: Standards-based, API-connected; no changes to existing NGFW architecture
Topologies Supported: Hub and spoke, trusted node, multi-hop
Standards: ETSI GS QKD 014, ITU
Operational Status: Integration tested and validated against a leading NGFW platform
Challenge
Classical key exchange won't survive the quantum era.
Adversaries capture encrypted traffic today and store it, waiting for quantum computers to break it later. NIST has set a 2030 compliance deadline, and migration takes one to two years.
Key Challenges
The threat is already active This is Harvest Now, Decrypt Later (HNDL) risk. Quantum computers will break today's encryption standards, exposing any long-lived sensitive communication.
Traditional key exchange is the exposure Site-to-site Secure Communications and firewall-tofirewall tunnels rely on classical key exchange. Once quantum computers mature, that exchange method is broken.
Extending protection has meant rearchitecting Protecting a few high-value links has historically meant redesigning the surrounding network. Enterprises need quantum-safe protection without disrupting what already runs.
Solution
Your firewall requests a key. Quantum physics supplies it.
QNu Labs QKDN distributes quantum-derived symmetric key material to a leading NextGeneration Firewall (NGFW) platform over the ETSI GS QKD 014 interface.
The existing security architecture stays as it is.
QNu Labs
QKDN — Quantum Key Distribution Network
An enterprise quantum networking platform for deploying and managing symmetric key
distribution at scale. Keys are generated and distributed over a quantum channel, where any
attempt to intercept the transmission introduces detectable changes to the quantum state.
Leading NGFW Partner
Next-Generation Firewall (NGFW)
A prevention-focused architecture that is straightforward to deploy and operate. Machine
learning inspects all traffic, including applications, threats and content, and ties that traffic
to the user regardless of location or device.
Deployment and Validation
How it works
Network orchestration QKDN functions as network orchestrator, creating largescale Quantum Key Distribution networks across metro and wide area networks.
Key distribution QKDN generates and distributes quantum-derived symmetric key material to the NGFW platform using the ETSI GS QKD 014 interface.
Secure Communication establishment Each firewall retrieves its assigned key material from the local QKD node. Key identifiers are exchanged between peers to establish shared context.
Architecture preserved This approach preserves the existing NGFW security architecture while adding a physics-based layer of protection.
Built on ETSI and ITU standards.
Hub and spoke
Several sites keyed from a central receiver, for concentrated campus or data center estates.
Trusted node
Reach extended past a single fiber span by relaying key material through a trusted intermediate node.
Multi-Hop
Metro and wide area key distribution networks spanning many sites under one orchestrated fabric.
Component
Notes
QNu Labs QKDN
Integration testing completed and validated against a leading site-to-site IPsec quantum-safe secure communication solution.
Site-to-Site IPsec Quantum-Safe Secure Communication
Each firewall retrieves its assigned key material from the local QKD node. Key identifiers are exchanged between peers to establish shared encryption context.
ETSI GS QKD 014 Interface
Standards-based quantum key distribution.
Outcome
Five outcomes from one integration
Crypto-agility through open standards Integration runs over ETSI and ITU interfaces, not a proprietary coupling between two vendors.
Scale beyond a single pair of sites Trusted-node and multi-hop deployments extend quantum-secure communications across many locations.
Readiness for emerging requirements Positions critical infrastructure ahead of the postquantum cybersecurity requirements now being drafted.
No change to the existing security architecture Existing site-to-site IPsec Secure Communications are secured in place. The existing NGFW security architecture is fully preserved.
Quantum-generated keys on high-value links Protect the communications that warrant it, without extending quantum key distribution across the whole estate at once.
Why QNu Labs
Combine industry-leading network security with standards-based Quantum Key Distribution.
QNu Labs is India's only full-stack quantum cybersecurity company, delivering QKD, QRNG, PQC and QKMS under one sovereign platform: QShield.
The QShield platform empowers enterprises, defence organisations, cloud providers, and critical infrastructure operators to seamlessly adopt quantum-safe technologies while achieving crypto-agility across their ecosystems. By combining quantum-grade hardware with software-defined control and interoperability, QNu Labs ensures alignment with NIST standards, delivers unmatched flexibility and compliance readiness, and reduces risk across data, network, and compute layers.
Frequently asked questions
Does deploying QNu Labs QKDN require replacing or reconfiguring the existing firewall?
No. The existing NGFW security architecture is fully preserved. QKDN integrates via the ETSI GS QKD 014 interface and supplies quantum-derived key material to the firewall. What changes is the quality of the key protecting it, not the architecture itself.
How does the key exchange process work?
QKDN generates and distributes quantum-derived symmetric key material to the NGFW platform. Each firewall retrieves its assigned key from the local QKD node. Key identifiers are exchanged between peers to establish shared encryption context. Any attempt to intercept the key transmission disturbs the quantum state and is immediately detectable.
Can this deployment scale beyond a single site-to-site connection?
Yes. The solution supports hub and spoke, trusted node, and multi-hop topologies, enabling quantum-secure key distribution across metro and wide area networks spanning many sites under one orchestrated fabric.
Is this solution tied to a proprietary interface?
No. Integration runs over ETSI and ITU open standards, not a proprietary coupling between vendors, ensuring interoperability and crypto-agility as standards evolve.
Why act now rather than wait for quantum computers to arrive?
Migration from classical to quantum-safe key exchange takes one to two years. NIST has set a 2030 compliance deadline. Adversaries are already capturing and storing encrypted traffic today to decrypt later. The window to act is closing.