BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//open-source-conference-luxembourg-2026//sp
 eaker//ZRCAUQ
BEGIN:VTIMEZONE
TZID:Europe/Luxembourg
BEGIN:DAYLIGHT
DTSTART:20251007T000000
TZNAME:CEST
TZOFFSETFROM:+0200
TZOFFSETTO:+0200
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20251026T030000
RDATE:20261025T030000
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20260329T030000
RDATE:20270328T030000
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:Quantum Key Distribution Across Borders: Extending the eduKMS Key-
 Management System for Cross-Operator Quantum-Key Interoperability - Sam KA
 FAI
DTSTART;TZID=Europe/Luxembourg:20261007T153000
DTEND;TZID=Europe/Luxembourg:20261007T160000
DTSTAMP:20260916T160851Z
UID:pretalx-open-source-conference-luxembourg-2026-GV8LSC@pretalx.com
DESCRIPTION:Quantum Key Distribution (QKD) provides key exchange whose sec
 recy rests on physics rather than computational hardness\, a long-term def
 ence against the "harvest now\, decrypt later" threat to today's public-ke
 y cryptography. But a QKD network is confined to a single operator until i
 ts key-management systems can hand keys across operator boundaries. This t
 alk covers extending eduKMS\, the open-source Key Management System mainta
 ined by SURF\, to do exactly that.\n\nThe work took place during an intern
 ship at the Restena Foundation\, within its network and systems activity\,
  in the context of BENELUX-QCI\, the foundation's experimental quantum-com
 munication-infrastructure project. At the start\, eduKMS implemented only 
 the application-to-local-KMS interface (ETSI GS QKD 014)\; it had no way t
 o deliver a key across the boundary between two independently operated net
 works. Implementing that missing inter-operator layer (ETSI GS QKD 020)\, 
 with the routing\, acknowledgement\, and security machinery to make a mult
 i-operator network function end to end\, was the project.\n\nI will walk t
 hrough the architecture and the decisions that mattered: enforcing one-tim
 e-pad masking so no key crosses a conventional network readable\, and the 
 single reasoned exception to that rule\; extending mutual TLS to every int
 erface\; multi-boundary forwarding so a key reaches an operator that is no
 t a direct neighbour\; and a set of real security findings surfaced by rev
 iew and realistic testing (improper certificate validation\, missing per-p
 eer authorisation\, and an SSRF-exposed acknowledgement callback that the 
 ETSI standard requires you to honour\, closed by validating it against kno
 wn peers).\n\nNo quantum-physics background is assumed\; the focus is syst
 ems\, standards\, and security engineering.
LOCATION:Workshops room 1
URL:https://pretalx.com/open-source-conference-luxembourg-2026/talk/GV8LSC
 /
END:VEVENT
END:VCALENDAR
