Quantum Network Architectures
A quantum network architecture specifies how separated quantum nodes turn unreliable physical interactions into services that applications can request, identify, coordinate, consume, and verify. The physical carriers may be photons, transported matter, microwave excitations, or combinations of them. The requested service may be a measured correlation, a stored Bell pair, a multipartite state, a remote operation, a secret key, or a synchronized quantum-enhanced estimate. Architecture begins where a successful laboratory interaction must become a dependable shared resource.
The central architectural fact is that an entangled pair is neither a packet nor a permanent wire. It is a fragile, stateful resource tied to two endpoint memories, a preparation history, a reference frame, a quality estimate, and a deadline. It cannot carry a readable header, be copied into a queue, or be retransmitted after an unknown payload has been destroyed. Classical messages must therefore identify and coordinate the quantum resource from outside it.
This page is the canonical home for multiuser and multidomain network organization: service abstractions, provisional protocol layers, quantum and classical planes, topology families, routing and scheduling, entanglement inventory, internetworking, trust boundaries, and network-level evidence. Quantum Repeaters owns long-chain link generation, stochastic synchronization, cutoffs, and repeater generations. Quantum Memories owns write–store–read hardware, while Interconnects and Transduction owns accepted-input-to-usable-output link physics. Modular Architectures owns composition inside one integrated machine. Network Case Studies owns detailed experiment-by-experiment evidence. Network Verification owns test-versus-use sampling, source and device trust, finite-data acceptance, topology tests, and service-level certification. Distributed Quantum Sensing owns weighted spatial estimands, node-separable and inter-node-entangled benchmarks, sensing information rate, and evidence for a network metrology advantage.
Begin with the Service
Section titled “Begin with the Service”A topology diagram is not yet an architecture. First specify what an application asks the network to deliver. A useful request record is
Here names the endpoints; names the state, outcome, or operation; is the requested quantity; is a quality threshold; is a deadline or timeout; is a sustained-rate requirement; bounds latency or rate jitter; is priority; and states the trust and threat model. Real interfaces need not use these exact fields, but silently omitting them moves ambiguity into the application.
The service type determines when control returns to the application and what the network may do internally.
| Service | Delivered object | Endpoint obligation | Typical use |
|---|---|---|---|
| Measure directly | Correlated classical outcomes | Choose or receive measurement settings | Prepare-and-measure protocols, clock comparison |
| Create and keep | Identified qubits sharing a state | Preserve the advertised memory slots | Teleportation, remote gates, distributed sensing |
| Remote state preparation | A state at one endpoint plus a classical record | Apply or track a correction | Client–server protocols |
| Logical entanglement | Encoded Bell pair or logical operation | Maintain code and decoder state | Fault-tolerant distributed computing |
| Multipartite resource | GHZ, graph, or other declared state | Coordinate all participants and frames | Conference key agreement, sensing, network codes |
A request for “one Bell pair” remains incomplete unless it states whether the pair may be measured immediately, must remain available for a later application trigger, or is only a precursor to a logical pair. The resources and latency distributions can differ by orders of magnitude.
Classical retransmission also needs a careful quantum translation. A network may retry resource generation before the application supplies an unknown state. Once that state has been consumed in a teleportation or remote-gate attempt, the network cannot recover it by replaying a lost quantum packet. Recovery must instead follow the protocol’s declared semantics: preserve the input until a herald, use an encoded fault-tolerant operation, abort the transaction, or repeat at the application level when the input is reproducible.
Four Graphs, Not One
Section titled “Four Graphs, Not One”One drawing of nodes and lines hides several independently changing structures. At minimum, distinguish four graphs.
- The physical quantum graph records available fibers, free-space channels, local couplers, sources, detectors, memories, and transducers.
- The classical-control graph records channels for heralds, requests, timing, corrections, authentication, and telemetry.
- The entanglement graph records the usable shared states that exist at time .
- The administrative and trust graph records ownership, policy, credential, disclosure, and fault-containment boundaries.
These graphs need not have the same edges. Two nodes can exchange classical messages without a direct quantum channel. A physical quantum edge can exist while no entangled pair is currently stored. Entanglement swapping can create an overlay edge between nodes that have never exchanged a photon directly. Conversely, policy can forbid a technically available path from crossing an administrative boundary.
A stored pair should therefore be represented by more than an unlabeled edge. An abstract resource record is
The record identifies endpoints and memory slots ; carries an estimated state or quality ; records birth and expiration times; tracks a basis, phase, or Pauli frame ; and preserves provenance and trust metadata . The quantum state is not the database row. The row is classical information correlated with the physical systems.
At the overlay level, swapping at is a stateful graph rewrite,
conditioned on a valid outcome and frame update. The two input records become consumed; the new record inherits a preparation history and a new quality and expiry estimate. The Entanglement Swapping article derives the state identity. Architecturally, the important point is atomic bookkeeping: applications must not receive an input pair after a swap has already consumed it.
A Provisional Architecture Stack
Section titled “A Provisional Architecture Stack”There is no universally adopted quantum-network stack equivalent to the mature Internet protocol suite. Research stacks and standards-oriented documents make different layer boundaries because hardware capabilities and application requirements are still evolving. The following decomposition is an enduring reasoning tool, not a claim that every system must expose five named layers.
A provisional service stack. Quantum resources move upward as identified link states, routed entanglement, and application objects; classical timing, identifiers, routing decisions, frames, telemetry, authentication, and policy coordinate every layer. Implementations may merge or split these functions.
Physical and interface layer
Section titled “Physical and interface layer”This layer owns attempts: emission, frequency and temporal modes, channel access, interference, detection, heralding signals, local gates, and hardware calibration. Its output is not merely “a click.” It should expose whether the event satisfies an accepted input/output contract, including false-herald probability, mode identity, timing, and device state. Transduction belongs at an interface boundary when carriers or encodings differ.
Link layer
Section titled “Link layer”The link layer turns repeated physical attempts into a robust service between neighbors. Demonstrated link-layer work has used requests containing a remote node, number of pairs, minimum fidelity, timeout, and delivery semantics such as create-and-keep, measure-directly, or remote state preparation. It assigns pair identifiers consistently at both ends, manages finite memory, and reports success or failure to higher layers. This is the nearest quantum analogue of turning a fallible physical medium into a usable local service, but it still delivers stateful resources rather than packets.
Network or entanglement layer
Section titled “Network or entanglement layer”This layer selects paths or subgraphs, reserves resources, coordinates link generation, schedules swaps or graph-state measurements, and returns an end-to-end state with provenance and frame information. Routing cannot be separated cleanly from resource creation: the chosen route changes memory waiting, contention, fidelity, and success probability.
Transport or session layer
Section titled “Transport or session layer”Some proposals add a layer that coordinates a longer-lived application session, admission control, reliability semantics, congestion response, ordered delivery of resource records, or a stream of entangled states. The name “transport” must not imply transparent retransmission of unknown quantum payloads. In small networks these functions may remain in the application or network layer.
Application and runtime layer
Section titled “Application and runtime layer”The application requests quantum resources and combines them with local operations and classical computation. A runtime maps high-level programs onto node instructions, waits for network events, handles measurement outcomes, and enforces the application’s causal order. NetQASM and QNodeOS are examples of work toward such an execution boundary; they are not evidence that a single universal application binary already runs across arbitrary quantum hardware.
The layer interfaces should state semantics, not just message formats. A successful return must say what exists, where it exists, how it is identified, what quality has been established or estimated, how long it remains valid, and which corrections or frames remain outstanding.
Quantum, Classical, Control, and Management Planes
Section titled “Quantum, Classical, Control, and Management Planes”Quantum networks require classical networking, but “classical side channel” is too vague to describe the dependence. Four logical planes are useful even when they share physical equipment.
The quantum data plane creates, stores, transforms, forwards, measures, and consumes quantum states. It includes pair-granularity actions initiated by classical instructions. A Bell pair has no readable in-band header. Every operation therefore depends on external identifiers that agree at all participating nodes.
The classical data plane carries application data that is part of a quantum protocol: basis announcements, teleportation outcomes, syndrome or decoder information, key post-processing, and sensing results. Its latency can set a lower bound on the useful quantum-memory lifetime.
The control plane discovers capabilities, accepts requests, chooses paths, allocates memories, schedules attempts and swaps, distributes frames, and handles failures. Whether routing is centralized, distributed, hierarchical, or source-selected is an architectural choice. A logically centralized controller can still be physically replicated; a distributed protocol still needs a policy for stale state.
The management plane configures devices, credentials, clocks, calibration, software versions, policy, telemetry retention, and maintenance. It observes slower operational state and administrative boundaries. Mixing management authority with per-pair control without explicit authorization can enlarge the security and failure domain.
Time synchronization cuts through all four planes. Coincidence windows, interference, memory leases, deadlines, and event correlation require a named clock model and uncertainty. A timestamp without its clock domain and error bound is not a portable network fact.
Topology Families
Section titled “Topology Families”Topology should be chosen for the service and failure model, not for visual symmetry. Several families recur.
| Family | Architectural strength | Characteristic bottleneck or risk |
|---|---|---|
| Point-to-point link | Minimal control and calibration surface | No alternate path; loss grows with distance |
| Switched star or hub | Efficient sharing of expensive sources or detectors | Hub contention and correlated failure |
| Repeater chain | Extends distance with local elementary links | Synchronization, memory aging, and serial cut capacity |
| Mesh | Alternate routes and concurrent demands | Routing state, resource fragmentation, and control overhead |
| Photonic graph-state fabric | Measurement can reshape connectivity | Large source, switching, loss, and feed-forward demands |
| Satellite–ground hybrid | Bypasses long terrestrial attenuation segments | Weather, pointing, daylight background, contact windows, trusted-node choices |
Point-to-point and switched networks
Section titled “Point-to-point and switched networks”A direct link is appropriate when two endpoints dominate the workload or when the experiment is characterizing one interface. A passive optical switch can connect different endpoint pairs over time without becoming a quantum repeater. It changes the physical path but does not, by itself, store adjacent entangled links and join them by entanglement swapping. Similarly, a trusted QKD relay can extend a classical key-management service while learning or handling key material; it is not an untrusted end-to-end entanglement path.
Chains and meshes
Section titled “Chains and meshes”A chain minimizes path choice but exposes the slowest cut: every end-to-end resource needs all required segments and intermediate operations. A mesh can route around failures and exploit parallel paths, yet alternative routes compete for memories, photons, detector time, and swaps. The entanglement overlay can be much denser or sparser than the physical mesh at a particular instant.
Multipartite and graph-state fabrics
Section titled “Multipartite and graph-state fabrics”Not every network should first create independent Bell pairs. A source may distribute a multipartite state, or nodes may fuse photonic graph fragments whose measurement pattern realizes routing and computation. The service record must then identify a hyperedge or graph-state resource, not force it into pairwise edges that discard useful correlations.
Free-space and satellite links
Section titled “Free-space and satellite links”Free-space links add moving geometry, atmospheric loss, turbulence, pointing, background light, and intermittent contact. A satellite may be a trusted source or relay, an entangled-pair source with photons sent to two ground stations, or part of a future memory-assisted architecture. These roles have different security claims. Orbit and contact-window scheduling also couple network planning to time more strongly than in a fixed terrestrial graph.
Routing Is Resource Creation
Section titled “Routing Is Resource Creation”Classical routing usually chooses where an already formed packet should go. Entanglement routing chooses where probabilistic resources should be created and how they should be combined before they decohere. Path selection, scheduling, and inventory allocation are therefore coupled.
For a simple path whose elementary attempts and swaps are treated as independent simultaneous events, a crude success surrogate is
where is link success and is swap success at an internal node. Then gives an additive link weight. This model can rank paths only under its assumptions. It is generally not an end-to-end rate because memories preserve early successes, attempts have unequal durations, cutoffs discard old pairs, operations contend for hardware, and fidelity changes with age and swapping.
A routing state must therefore include more than physical distance. Useful attributes include
representing success probability, attempt duration, mode or service capacity, quality, coherence scale, memory availability, queue state, operational availability, and trust. These quantities can be time-dependent and application-specific.
For concurrent demands , an idealized allocation might choose rates by solving
This is a schematic optimization, not a universal capacity theorem. The function must encode the actual protocol, synchronization, fidelity, and deadline constraints. Utility determines policy: total throughput, max-min fairness, proportional fairness, deadline success, or a weighted priority objective can select different schedules.
Routing information has a cost. A global controller with exact instantaneous pair inventory would require frequent classical updates and could act on stale data before the messages arrive. Local policies react quickly but may miss globally better allocations. Hierarchical routing can advertise aggregated capabilities across domains while keeping pair-level scheduling local. The right choice depends on network size, coherence time, trust, and traffic predictability.
Entanglement Inventory and Sessions
Section titled “Entanglement Inventory and Sessions”Because resources expire and operations consume them, a network needs an explicit lifecycle. A useful state machine is
Not every implementation needs these exact labels, but it must prevent double allocation and ambiguous ownership. State transitions should be tied to unique request, attempt, pair, and operation identifiers. A swap message that is duplicated, delayed, or delivered after a timeout must not consume a newly allocated pair that happens to occupy the same memory address.
Leases and expiration
Section titled “Leases and expiration”Reservation is best treated as a lease. If a resource born at has a maximum accepted age , its local expiration time is
The scheduler must include control latency and clock uncertainty before starting an operation expected to finish at . A conservative condition is
Expiration is an application-quality decision, not necessarily the instant at which a memory state becomes physically meaningless. Different requests can assign different useful lifetimes to the same hardware.
Reactive and proactive generation
Section titled “Reactive and proactive generation”Reactive generation begins after a request arrives. It avoids storing unused pairs but exposes the application to the full stochastic setup delay. Proactive generation maintains an inventory based on forecast demand. It can reduce latency but consumes modes, memory lifetime, and energy, and may discard unused resources. Hybrid policies reserve a fraction of capacity for standing inventory while leaving room for urgent or unusual requests.
A session binds a sequence of resources to an application context. It may carry endpoint identities, authorization, reference frames, deadlines, rollback semantics, and a causal history. Sessions are especially useful when an application needs a stream of pairs, several correlated pairs at once, or conditional operations across nodes. They do not make the underlying quantum state durable; they make responsibility and failure semantics explicit.
Heterogeneity and Internetworking
Section titled “Heterogeneity and Internetworking”A useful network should tolerate evolution rather than assume every node has the same qubit, wavelength, gate set, memory, and controller. A node or domain can advertise a capability descriptor such as
The descriptor states what the node can accept and deliver, not merely its internal hardware brand. Compatibility can be direct, established by a transducer or converter, or mediated by a protocol that changes encoding. Every conversion must be included in efficiency, noise, latency, mode count, and heralding semantics; an efficient internal transducer that accepts only a small spectral fraction can still bottleneck the end-to-end service.
Internetworking introduces at least three kinds of boundary:
- a physical boundary, where carrier, wavelength, encoding, or clock changes;
- an error-management boundary, where responsibility for fidelity, purification, decoding, or frame tracking changes;
- an administrative boundary, where ownership, policy, disclosure, and trust change.
A large domain may hide internal details and advertise a virtual link or service between gateways. This recursive abstraction can reduce control traffic and protect operational information, but its contract must expose enough to make end-to-end guarantees meaningful. A domain that advertises only an average pair rate conceals latency tails, correlated outages, fidelity variation, and trust assumptions.
Names also need levels. A human or application identity is not a physical memory address; a node name is not necessarily an interface; and a stable service endpoint may move among hardware modules. Separating application, node, interface, and transient-resource identifiers prevents routing and security policy from being tied accidentally to replaceable hardware.
Application Families and Traffic
Section titled “Application Families and Traffic”There is no application-independent “best” architecture. Different workloads consume different quantum objects and tolerate different timing.
| Application family | Network object | Dominant architectural requirements |
|---|---|---|
| QKD and cryptographic setup | Detection records, secret correlations, or end-to-end entanglement | Authenticated classical channel, security model, finite-key accounting, availability |
| Blind or delegated computation | Hidden preparations, authenticated states, or verified transcripts | Client simplicity, privacy, causal interaction, verification |
| Distributed quantum computing | Bell pairs, teleported states, remote gates, logical links | Low latency, synchronized bursts, high fidelity, compiler/runtime integration |
| Distributed sensing and clocks | Multipartite probes or phase correlations | Stable reference frames, simultaneous availability, calibrated timing |
| Telescope arrays | Shared entanglement or quantum memories near receivers | Bandwidth, phase stability, low added noise, geographically coordinated capture |
| Satellite services | Photons, entanglement, or key material across contact windows | Pointing, weather, orbit schedule, background rejection, explicit satellite trust |
QKD can operate on prepare-and-measure links with no long-lived quantum memory, and deployed QKD networks can use trusted relays. That is valuable, but it does not demonstrate arbitrary entanglement routing. Distributed computing may need bursts of several high-fidelity pairs synchronized with a program; an excellent long-term average rate with unbounded latency tails can still be useless. Distributed sensing may care more about common phase references and simultaneous delivery than about arbitrary unicast routing.
Quantum Key Distribution, Blind and Delegated Quantum Computation, and the Sensing Case Studies develop those application contracts. Distributed Quantum Computing owns coherent execution, teledata, telegates, circuit partitioning, circuit cutting, and logical-network resource accounting; the present page owns the network services on which those computations depend. Distributed Quantum Sensing develops the estimator and matched-resource contract for the sensing workload; the present page owns delivery and coordination of the required shared state.
Trust, Security, and Failure Domains
Section titled “Trust, Security, and Failure Domains”Quantum communication does not make the surrounding network automatically secure. Security claims belong to an end-to-end protocol with explicit device, adversary, authentication, leakage, and availability assumptions.
At least the following surfaces require analysis:
- Classical authentication. An attacker who can forge heralds, route updates, corrections, or key post-processing messages can defeat the protocol without violating quantum mechanics.
- False resource records. Detector artifacts, stale identifiers, or a compromised node can claim that a pair exists when the endpoint state does not satisfy the service contract.
- Control-plane denial. Memory reservations, expensive link attempts, and route computation can be exhausted by requests that never consume their resources.
- Metadata leakage. Endpoint identities, timing, volume, route choice, and success patterns can reveal sensitive activity even when quantum payloads remain private.
- Implementation side channels. Sources, detectors, transducers, and control electronics may leak or accept modes outside an abstract proof.
- Trusted intermediaries. A trusted relay, measurement node, repeater, and administrative controller have different access to keys, states, outcomes, and metadata.
- Correlated failure. Shared clocks, software, power, fiber conduits, cryogenic systems, or control authorities can invalidate independence assumptions across apparently disjoint routes.
End-to-end entanglement can remove the need to trust an intermediate node with the ideal endpoint state, but only if the endpoints validate the protocol’s assumptions and authenticate the classical transcript. It does not eliminate availability attacks or metadata exposure. Device-independent security can reduce device-trust assumptions under demanding loophole, entropy, and finite-data conditions; it does not make network operations or endpoint software irrelevant.
Trust should therefore be represented as path metadata and policy, not as a single “secure” bit. A request may allow nodes operated by a specified set of domains, forbid key exposure to relays, require disjoint control authorities, or demand evidence generated at the endpoints.
Performance and the Evidence Contract
Section titled “Performance and the Evidence Contract”A network benchmark should begin at the application boundary and expose every denominator. For accepted outputs over observation time , define a service goodput
This is not interchangeable with source repetition rate, detector clicks, link heralds, raw swaps, sifted detections, or postselected tomographic events. If a result is quoted per optical mode, channel use, memory, wavelength, or spatial path, that denominator must also be named.
Rate should be reported together with quality. A useful object is the achievable frontier
where is a latency quantile, is availability, and is a cost or resource vector. One scalar “network rate” cannot describe the trade among fidelity thresholds, memory cutoffs, fairness, and latency tails.
For concurrent flows with delivered rates , Jain’s index
is one descriptive fairness measure. It does not encode priorities or deadlines, so it should accompany rather than replace the declared policy.
A credible network report should state:
- the requested service and success criterion;
- topology, distances, loss, modes, memories, and active versus simulated components;
- whether nodes, sources, measurements, and relays are trusted;
- pair, attempt, swap, and delivery denominators;
- fidelity estimator, confidence or credible interval, and selection rule;
- latency distribution, timeout, memory ages, and control-loop timing;
- concurrent workload, routing policy, fairness, and offered load;
- calibration cadence, uptime, outages, and manual intervention;
- which conclusions were demonstrated, inferred from a model, or projected.
The Reporting Standards and Network Case Studies provide the corresponding evidence templates and worked comparisons.
Capability Roadmap, Not a Deployment Claim
Section titled “Capability Roadmap, Not a Deployment Claim”One useful roadmap classifies networks by available node capabilities. The stages below are labels for reasoning about applications, not a mandated deployment sequence, standards conformance levels, or evidence that each capability is available at scale.
| Capability stage | Added network capability | Representative service |
|---|---|---|
| Trusted relay | Intermediate nodes handle classical secret material | Long-distance key delivery under relay trust |
| Prepare and measure | End nodes prepare and measure transmitted systems | BB84-like links, selected cryptographic tasks |
| Entanglement distribution | End nodes receive shared entanglement without long storage | Bell tests, entanglement-based QKD |
| Quantum-memory network | Nodes store states long enough for coordinated operations | Teleportation through a chain, buffered entanglement |
| Fault-tolerant few-qubit network | Encoded or error-corrected network operations | Reliable remote logical primitives |
| Quantum-computing network | Larger fault-tolerant processors cooperate | General distributed quantum algorithms |
The evidence frontier is much narrower than the final row. By 2022, a link-layer stack had experimentally delivered entanglement requests over a three-node matter-qubit network. By 2025, QNodeOS had executed high-level network applications and multitasked on a two-node NV-center platform, with a separate trapped-ion hardware driver demonstration. Those are substantive software–hardware integration results. They do not establish a deployed, general-purpose, heterogeneous, multidomain entanglement internet.
Likewise, satellite entanglement distribution, metropolitan QKD networks, three-node teleportation, quantum-router components, and modular processor links each establish particular capabilities. Combining their best reported numbers into one hypothetical architecture is a projection unless the interfaces, clocks, workloads, and joint operation have actually been tested.
RFC 9340 records architectural principles developed by the IRTF Quantum Internet Research Group, and RFC 9583 records application scenarios. Both are Informational RFCs, not Internet Standards Track specifications. ITU-T Y Supplement 98 surveys technical considerations and migration paths; it is a supplement, not proof of a universal adopted stack. This distinction matters: standards-oriented consensus can stabilize vocabulary and interfaces before the technology has demonstrated all end-to-end capabilities.
Architecture Design Workflow
Section titled “Architecture Design Workflow”A disciplined design proceeds from service to evidence.
- Name the application object. State whether the network delivers outcomes, physical pairs, logical pairs, multipartite states, operations, or key material.
- Declare trust and failure assumptions. Include endpoint, relay, controller, source, detector, and administrative-domain assumptions.
- Draw all four graphs. Separate physical quantum, classical control, current entanglement, and administrative/trust connectivity.
- Write each interface contract. Specify accepted inputs, outputs, identifiers, quality, timing, false-herald behavior, and failure returns.
- Budget the critical path. Include source attempts, propagation, heralds, memory waits, operations, feed-forward, and application deadlines.
- Choose inventory policy. Set leases, cutoffs, reservation rules, proactive stock, and cleanup after partial failure.
- Choose routing and scheduling together. Include contested memories, modes, switches, detectors, and classical controllers.
- Design observability and recovery. Correlate events without measuring application states; handle stale, duplicated, and missing control messages.
- Evaluate under concurrent load and faults. Report latency tails, fairness, availability, and correlated failures, not only an isolated best trial.
- Trace every claim to evidence. Keep measured, inferred, simulated, and projected quantities separate.
Common Mistakes
Section titled “Common Mistakes”Treating an entangled pair as a packet
Section titled “Treating an entangled pair as a packet”A pair has no readable header and cannot be cloned into multiple queues. Keep its identifier and lifecycle in authenticated classical state correlated with specific endpoint systems.
Drawing only the physical topology
Section titled “Drawing only the physical topology”The current entanglement overlay, classical-control reachability, and trust domains can all differ from the fiber graph. Architecture decisions made from one graph can silently assume impossible control paths or forbidden domains.
Calling every middle station a repeater
Section titled “Calling every middle station a repeater”An optical switch, trusted key relay, untrusted Bell-state-measurement node, memory-assisted repeater, and graph-state measurement station expose different services and trust. Name the operation and stored information.
Optimizing a path score as though it were throughput
Section titled “Optimizing a path score as though it were throughput”Products of success probabilities or sums of losses can be useful routing weights, but delivered rate also depends on attempt time, memory, scheduling, cutoffs, quality, and contention. Validate the metric against the service.
Ignoring classical latency
Section titled “Ignoring classical latency”Heralding, frame updates, routing, and application feed-forward consume time while memories age. “Quantum latency” that excludes required classical loops is not end-to-end latency.
Hiding postselection and idle periods
Section titled “Hiding postselection and idle periods”Report accepted service outputs over wall-clock time and declared resources. Do not normalize away weather, contact windows, calibration, failed trials, or discarded low-quality pairs without also reporting them.
Calling a proposed stack a standard
Section titled “Calling a proposed stack a standard”Protocol research, interoperable demonstrations, Informational RFCs, standards-body supplements, and deployed standards are different evidence levels. Cite the actual status.
Assuming entanglement removes all trust
Section titled “Assuming entanglement removes all trust”Endpoints still rely on authenticated classical communication, implementations, randomness, software, and the stated verification protocol. Availability and metadata threats remain.
Exercises
Section titled “Exercises”Exercise 1: Overlay graph rewrite
Section titled “Exercise 1: Overlay graph rewrite”At time , a node holds pair records and . Both have been reserved for request . A Bell measurement succeeds at with outcome . Describe the required inventory transaction. Why is it unsafe merely to add to the database?
Solution
The transaction verifies that both input records still exist, refer to the expected memory slots, are unexpired, and are reserved for . It marks both inputs consumed, creates a new record tied to the endpoint slots, records the swap outcome or corresponding Pauli-frame update, recomputes the quality and expiration estimate, and preserves provenance linking the output to both inputs and the operation at . It then reports success atomically to the next protocol stage.
Merely adding leaves the input records apparently available. A second request could allocate qubits that the Bell measurement already destroyed. It also loses the correction, causal history, and failure semantics needed to interpret the endpoint state.
Exercise 2: Four graphs
Section titled “Exercise 2: Four graphs”Alice and Bob have authenticated Internet connectivity. Each has an optical fiber to a university hub, but policy forbids Alice’s project from using Bob’s laboratory equipment. Yesterday the hub generated an Alice–Bob pair; it has since expired. State whether the corresponding edge is present in each of , , , and .
Solution
The physical quantum paths through the hub remain in . Alice and Bob’s authenticated classical reachability gives a path in . The expired pair contributes no current edge to . The administrative graph records a policy boundary that forbids the requested use, so there is no authorized Alice–Bob service path in even though physical and classical paths exist. Yesterday’s pair belongs in an audit history, not the live entanglement graph.
Exercise 3: A complete link request
Section titled “Exercise 3: A complete link request”An application asks, “Give node ten Bell pairs with node .” Add at least five fields needed to make the request operational, and explain one choice that changes the resource cost substantially.
Solution
Possible fields include the target Bell state or accepted frame convention, minimum fidelity, whether pairs are measured immediately or kept in memory, deadline, sustained-rate or burst requirement, maximum inter-pair skew, priority, endpoint memory constraints, confidence requirement for the quality estimate, and trust policy.
Create-and-keep delivery can cost much more than measure-directly delivery. It requires usable endpoint memories, assigns exact slots, waits for application consumption, and risks decoherence while the ten-pair batch is assembled. Measure-directly service can release each memory immediately after the chosen measurement.
Exercise 4: Route scores are not rates
Section titled “Exercise 4: Route scores are not rates”Two candidate paths have one-shot component probabilities
and deterministic swaps. Compute the simultaneous one-shot success probabilities. Give two reasons why the lower value need not imply a lower delivered rate in a memory-assisted network.
Solution
The crude simultaneous scores are
Under that model ranks higher. In a memory-assisted protocol, however, successful links need not occur in the same attempt. Attempt durations may differ, and needs an extra intermediate memory and swap. It may suffer more contention, decoherence, classical delay, or a lower post-swap fidelity. Conversely, multiplexing could favor either path. A delivered-rate comparison requires the complete stochastic protocol and resource schedule.
Exercise 5: Shared bottleneck and fairness
Section titled “Exercise 5: Shared bottleneck and fairness”Two flows share a link that can supply at most accepted elementary pairs per second. Each end-to-end pair consumes one pair from that link, and all other resources are unconstrained. Compare the maximum total-throughput allocations with the max-min fair allocation. Compute Jain’s index for and .
Solution
Every nonnegative allocation satisfying has feasible total rate. A pure total-throughput objective is indifferent among all allocations on the boundary, including . Max-min fairness gives .
For ,
For ,
The index describes equality, not whether one flow legitimately had higher priority or a tighter deadline.
Exercise 6: Memory lease decision
Section titled “Exercise 6: Memory lease decision”A pair expires at . At , a controller considers a swap that will finish after . Control and clock uncertainty together contribute . Should the operation start under the conservative lease rule? What changes if the application’s accepted age is extended by ?
Solution
The conservative completion bound is
which exceeds the expiration time, so the scheduler should not start the operation under this contract. Extending the accepted age by moves expiration to , and the bound then satisfies the lease. That extension must come from a justified quality model or a different application threshold, not from the scheduler silently changing the contract.
Exercise 7: Trust paths
Section titled “Exercise 7: Trust paths”Compare two services: (a) a key transported through trusted classical relays, and (b) entanglement-based QKD over untrusted repeater nodes with authenticated endpoint classical communication. Which intermediate compromise is relevant to confidentiality, and which threats remain in both cases?
Solution
In the trusted-relay design, an intermediate that handles reconstructed key material can compromise end-to-end key confidentiality. In the ideal entanglement-based design, intermediate repeaters need not learn the endpoint key merely by performing the prescribed swapping operations; endpoint tests and the security proof bound adversarial influence under their assumptions.
Both designs still require authenticated classical communication and secure endpoint implementations. Both remain exposed to denial of service, traffic analysis, operational metadata leakage, compromised control software, common infrastructure failures, and implementation side channels outside the abstract model.
Exercise 8: Audit a network claim
Section titled “Exercise 8: Audit a network claim”A report states: “Our four-node quantum internet runs at .” The source emits at ; one selected four-node trial produced a tomographically reconstructed state, and the route was configured manually. Rewrite the strongest defensible claim and list missing evidence for a network-service claim.
Solution
A defensible statement is: “A four-node apparatus produced and tomographically characterized the reported state in a selected experimental trial, using a source clocked at and a manually configured route.” The source clock is not the delivered network rate.
Missing evidence includes attempted and heralded-event counts, selection rules, wall-clock duration, end-to-end accepted-output rate, fidelity uncertainty, latency distribution, memory ages, mode count, route setup time, concurrent traffic, automated control behavior, uptime, failure recovery, trust assumptions, and evidence that arbitrary requests rather than one preconfigured trial can be served.
References
Section titled “References”- H. J. Kimble, “The quantum internet,” Nature 453, 1023–1030 (2008), doi:10.1038/nature07127.
- S. Wehner, D. Elkouss, and R. Hanson, “Quantum internet: A vision for the road ahead,” Science 362, eaam9288 (2018), doi:10.1126/science.aam9288.
- W. Kozlowski et al., “Architectural Principles for a Quantum Internet,” RFC 9340, IRTF Quantum Internet Research Group (2023), doi:10.17487/RFC9340.
- C. Wang, A. Rahman, R. Li, M. Aelmans, and K. Chakraborty, “Application Scenarios for the Quantum Internet,” RFC 9583, IRTF Quantum Internet Research Group (2024), doi:10.17487/RFC9583.
- A. Dahlberg et al., “A Link Layer Protocol for Quantum Networks,” Proceedings of ACM SIGCOMM 2019, 159–173 (2019), doi:10.1145/3341302.3342070.
- A. Pirker and W. Dür, “A quantum network stack and protocols for reliable entanglement-based networks,” New Journal of Physics 21, 033003 (2019), doi:10.1088/1367-2630/ab05f7.
- M. Pant et al., “Routing entanglement in the quantum internet,” npj Quantum Information 5, 25 (2019), doi:10.1038/s41534-019-0139-x.
- W. Kozlowski, A. Dahlberg, and S. Wehner, “Designing a Quantum Network Protocol,” Proceedings of ACM CoNEXT 2020, 1–16 (2020), doi:10.1145/3386367.3431293.
- M. Pompili et al., “Experimental demonstration of entanglement delivery using a quantum network stack,” npj Quantum Information 8, 121 (2022), doi:10.1038/s41534-022-00631-2.
- A. Dahlberg et al., “NetQASM—a low-level instruction set architecture for hybrid quantum–classical programs in a quantum internet,” Quantum Science and Technology 7, 035023 (2022), doi:10.1088/2058-9565/ac753f.
- C. Delle Donne et al., “An operating system for executing applications on quantum network nodes,” Nature 639, 321–328 (2025), doi:10.1038/s41586-025-08704-w.
- R. Van Meter et al., “A Quantum Internet Architecture,” 2022 IEEE International Conference on Quantum Computing and Engineering, 341–352 (2022), doi:10.1109/QCE53715.2022.00055.
- S. Lee et al., “A quantum router architecture for high-fidelity entanglement flows in quantum networks,” npj Quantum Information 8, 75 (2022), doi:10.1038/s41534-022-00582-8.
- K. Azuma et al., “Quantum repeaters: From quantum networks to the quantum internet,” Reviews of Modern Physics 95, 045006 (2023), doi:10.1103/RevModPhys.95.045006.
- M. Pompili et al., “Realization of a multinode quantum network of remote solid-state qubits,” Science 372, 259–264 (2021), doi:10.1126/science.abg1919.
- S. L. N. Hermans et al., “Qubit teleportation between non-neighbouring nodes in a quantum network,” Nature 605, 663–668 (2022), doi:10.1038/s41586-022-04697-y.
- P. Kómár et al., “A quantum network of clocks,” Nature Physics 10, 582–587 (2014), doi:10.1038/nphys3000.
- D. Gottesman, T. Jennewein, and S. Croke, “Longer-baseline telescopes using quantum repeaters,” Physical Review Letters 109, 070503 (2012), doi:10.1103/PhysRevLett.109.070503.
- E. T. Khabiboulline et al., “Optical interferometry with quantum networks,” Physical Review Letters 123, 070504 (2019), doi:10.1103/PhysRevLett.123.070504.
- X. Guo et al., “Distributed quantum sensing in a continuous-variable entangled network,” Nature Physics 16, 281–284 (2020), doi:10.1038/s41567-019-0743-x.
- Y.-A. Chen et al., “An integrated space-to-ground quantum communication network over 4,600 kilometres,” Nature 589, 214–219 (2021), doi:10.1038/s41586-020-03093-8.
- International Telecommunication Union, “Technical considerations towards quantum networks,” ITU-T Y Supplement 98 (2025), official record.