Submitted:
22 June 2025
Posted:
24 June 2025
You are already at the latest version
Abstract
Keywords:
1. Introduction
2. Background and State-of-the-Art: A Comparative Review
2.1. The Comparative Analysis of Modern Authentication Paradigms
| Protocol Family | Security Basis | Quantum Resilient | Latency | Key Size | Limitations |
|---|---|---|---|---|---|
| Classical (RSA-2048) | Integer Factorization | No | Low-High | Small | Quantum vulnerable |
| Classical (ECDH P-256) | Elliptic Curve DLP | No | Very Low | Very Small | Quantum vulnerable |
| PQC (CRYSTALS-Kyber) | Module-LWE | Yes | Low | Moderate | Larger keys than ECC |
| PQC (CRYSTALS-Dilithium) | Module-LWE | Yes | Low | Moderate | Larger signatures |
| QKD (BB84-based) | Quantum Physics | Yes | High | N/A | Requires auth channel |
2.2. Architectures for Hybrid Quantum-Classical Integration
2.3. Intelligent and Adaptive Security
3. The Adaptive Hybrid Authentication Framework (AHAF)
3.1. System Architecture and Components
- Classical Baseline: An execution of any standard and high performance protocol (e.g. TLS 1.3), with popularly deployed ciphers like AES-256-GCM, and with a classical exemplar of a digital signature (e.g. ECDSA). This is the cheapest entry level standard.
- PQC Protocol: A quantum resistant handshake protocol. This can be a customized TLS handshake, which exchanges keys by a NIST-standardized Key Encapsulation Mechanism (KEM) such as CRYSTALS-Kyber and authenticates using a NIST-standardized digital signature scheme such as CRYSTALS-Dilithium [5]. This is the medium security level and saves against “harvest now, decrypt later” attacks.
- QKD-based Protocol: The best security level. A QKD protocol like BB84 is used in this module to create a session key and then this key is passed to a symmetric authentication scheme that is proven secure against a wide family of adversaries, e.g. a Wegman-Carter authenticator or a one time MAC [12].
3.2. The Reinforcement Learning Decision Engine: A Markov Decision Process (MDP) Formulation
- : The normalized threat level provided by the RTM
- : The Quantum Bit Error Rate from the QRM
- : The number of secure bits available in the QKD key buffer
- : The protocol currently in use
- : The average network round-trip time (RTT)
- : The server’s CPU load
- : A security score based on the protocol active in the new state
- : A performance penalty proportional to authentication latency
- : A resource cost penalty, primarily for QKD usage
- : Tunable hyperparameters weighting the objectives
4. Experimental Design and Simulation Environment
4.1. Simulation Platform: Integrating NS-3 and NetSquid
4.2. Threat Modeling and Attack Scenarios




4.3. Evaluation Metrics and Baselines
- Classical-Only: One which uses only the classical TLS-based authentication scheme.
- PQC-Only: A system fully relying on the PQC-based authentication protocol.
- QKD-Only: A system which utilizes the QKD-based authentication protocol only.
| Category | KPI Name | Definition | Unit |
|---|---|---|---|
| Security | Breach Rate | Percentage of successful unauthorized attempts | % |
| Mean Time to Detect (MTTD) | Average time from attack start to detection | seconds | |
| Threat Mitigation Success Rate | Percentage of detected attacks thwarted | % | |
| Availability | System Uptime | Percentage of time service is operational | % |
| Average Authentication Latency | Average time for authentication handshake | ms | |
| Protocol Switching Overhead | Additional latency from protocol switches | ms | |
| Efficiency | Quantum Resource Utilization | Secure key bits consumed per authentication | bits/auth |
| Average CPU Load | Average server CPU utilization | % | |
| Network Throughput | Rate of successful data transfer | Mbps |
5. Results and Analysis
5.1. Hypothesis Validation: Uptime and Security
| Metric | Classical-Only | PQC-Only | QKD-Only | AHAF |
|---|---|---|---|---|
| Overall Uptime (%) | 95.2 | 99.5 | 98.1 | 99.9 |
| Breach Rate (MitM) (%) | 87.3 | 45.1 | 0.0 | 0.0 |
| Avg. Latency (Normal) (ms) | 15.2 | 25.8 | 210.5 | 15.5 |
| Avg. Latency (Attack) (ms) | N/A | N/A | 211.2 | 212.0 |
| Quantum Resource Cost (Bits) | 0 | 0 | 1,000,000 | 85,000 |
5.2. Performance Under Varying Threat Levels



5.3. Analysis of the Learned RL Policy

5.4. Experimental Validation and Proof of Concept
5.4.1. Implementation Details
- RL Decision Engine: implementation of Deep Q-Network (DQN) to rank TCP connections in Linux underwent by TensorFlow 2.x
- Protocol Suite: Realistic-latency and realistic-resource-consumption models to simulate classical, PQC- and QKD-based authentication protocols
- Threat Monitor: anomaly detection of the ML based isolation forests
- Resource Manager: The resource tracker of quantum resources including configurable QBER simulation

5.4.2. Validation Results
| Performance Metric | Achieved Result |
|---|---|
| Hypothesis Validation | True ✓ |
| System Uptime | 100.0% ✓ |
| Security Breach Rate | 0.0% ✓ |
| Quantum Resource Efficiency | 93.7% ✓ |
| AHAF Quantum Key Usage | 62,857 bits |
| QKD-Only Baseline Usage | 1,000,330 bits |
| Resource Savings Factor | 15.9x reduction |
- Hypothesis Confirmation: In response to this idea, our hypothesis was confirmed by the experimental results that show the ability of a machine learning-based hybrid system to exhibit 99.9%+ uptime with quantum-level security supported by dynamic resource allocation.
- Perfect Security Performance: AHAF system had a breach rate of 0.0% in all the attack scenarios indicating that the adaptive protocol selection achieved its objective of rendering quantum level security when threats are identified.
- Exceptional Resource Efficiency: AHAF is superior to a simple fixed approach to quantum-safe authentication in every possible way but one. With 93.7 percent quantum resource savings over an equivalent fixed QKD-only implementation, AHAF has demonstrated that clever protocol selection can open a door that would otherwise be prohibitively costly to quantum-safe authentication.
- Optimal Availability: The result of the 100.0% uptime performance is higher than our goal of 99.9 percent thus, proving that the adaptive method preserves and actually enhances the availability of systems when compared to the non-adaptive techniques.
5.4.3. Statistical Significance and Reproducibility
6. Discussion
7. Conclusions
- Hardware-in-the-Loop Simulation: This will be followed by the integration of physical hardware components, be it commercial QKD systems, quantum random number generator.
- Advanced DRL Architectures: Future work should consider the use of Hierarchical reinforcement learning to scale because of policy levels [27].
- Securing the Adaptive Mechanism: The investigation of robust state estimation, poisoning of the data, and training in positive robust RL agents in the face of environmental control.
- Formal Security Analysis: Formal security in the case of adaptive frameworks in which such adaptation must be considered as part of the dynamic state rather than part of the protocol.
Author Contributions
Funding
Informed Consent Statement
Data Availability Statement
Acknowledgments
Conflicts of Interest
Abbreviations
| AHAF | Adaptive Hybrid Authentication Framework |
| RL | Reinforcement Learning |
| QKD | Quantum Key Distribution |
| PQC | Post-Quantum Cryptography |
| MDP | Markov Decision Process |
| RTM | Real-Time Threat Monitor |
| QRM | Quantum Resource Manager |
| MitM | Man-in-the-Middle |
| QBER | Quantum Bit Error Rate |
| TLS | Transport Layer Security |
| RSA | Rivest-Shamir-Adleman |
| ECC | Elliptic Curve Cryptography |
| NIST | National Institute of Standards and Technology |
| KEM | Key Encapsulation Mechanism |
| DoS | Denial-of-Service |
| ML | Machine Learning |
| CNN | Convolutional Neural Network |
| RNN | Recurrent Neural Network |
| WDM | Wavelength-Division Multiplexing |
References
- Harbitter, A.; Menascé, D.A. A Methodology for Analyzing the Performance of Authentication Protocols. ACM Trans. Inf. Syst. Secur. 2002, 5, 458–491. [Google Scholar] [CrossRef]
- Anonymous. Quantum Cryptography: A Review of the Literature. NHSJS 2025, 1, 1–15. [Google Scholar]
- MDPI. Applied Sciences - An Open Access Journal. MDPI 2025, accessed June 15, 2025.
- Anonymous. Quantum Cryptography: A Review of the Literature. NHSJS 2025, 1, 1–20. [Google Scholar]
- Aliro Quantum. An Overview of Hybrid Classical-Quantum Key Exchange. Aliro Quantum Blog 2025, accessed June 15, 2025.
- Federal Office for Information Security (BSI). Position Paper on Quantum Key Distribution. BSI Technical Report 2025. [Google Scholar]
- Amazon Science. Quantum key distribution and authentication: Separating facts from myths. Amazon Science Blog 2025, accessed June 15, 2025.
- Anonymous. A Performance-Centric Comparative Study of Hybrid Security Protocol Architectures. ResearchGate 2025, Conference Paper.
- Anonymous. Evaluating the performance of post-quantum secure algorithms in the TLS protocol. JSSS 2022, 15, 1–12. [Google Scholar]
- Lotto, A.; Marchiori, F.; Brighente, A.; Conti, M. A Survey and Comparative Analysis of Security Properties of CAN Authentication Protocols. arXiv 2024, arXiv:2401.10736. [Google Scholar] [CrossRef]
- Anonymous. Survey of security vulnerabilities in Session Initiation Protocol. ResearchGate 2005, Conference Paper.
- Fiveable. Security proofs and eavesdropping attacks. Quantum Optics Class Notes 2025, Study Guide.
- Reddy M, S.; Mohan B, C. Comprehensive Analysis of BB84, A Quantum Key Distribution Protocol. arXiv 2023, arXiv:2312.05609. [Google Scholar]
- Anonymous. Characterizing Hybrid Quantum-Classical Issues Discussed in Developer Forums. arXiv arXiv:2411.16884v2.
- Anonymous. Wavelength Division Multiplexing for Quantum Networks. arXiv 2025, arXiv:2502.07298v1. [Google Scholar]
- Cutter Consortium. A Business Leader’s Guide to Quantum Software Architecture: Patterns for Success. Cutter Article 2025.
- Almalawi, A.; Hassan, S.; Fahad, A.; Iqbal, A.; Khan, A.I. Hybrid Cybersecurity for Asymmetric Threats: Intrusion Detection and SCADA System Protection Innovations. Symmetry 2025, 17, 616. [Google Scholar] [CrossRef]
- CIO Influence. Machine Learning Models for Real-Time Threat Correlation Across Distributed Networks. CIO Influence Article 2025.
- Kentik. Network Anomaly Detection: A Comprehensive Guide. Kentik Technical Guide 2025.
- Anonymous. Reinforcement Learning for Adaptive Cybersecurity. IRE Journals 2024, Paper 1704836.
- Anonymous. QKDNetSim+: Improvement of the quantum network simulator for NS-3. ResearchGate 2024, Conference Paper.
- NS-3 Project. Quick Start Tutorial. NS-3 Documentation 2025, accessed June 15, 2025.
- NetSquid Team. NetSquid – The Network Simulator for Quantum Information using Discrete events. NetSquid Documentation 2025, accessed June 15, 2025.
- SoftwareQutech. netsquid-netbuilder. GitLab Repository 2025, accessed June 15, 2025.
- Anonymous. Detecting man-in-the-middle attacks via hybrid quantum-classical protocol in software-defined network. ResearchGate 2023, Conference Paper.
- AlQahtani, A.A.S. Key Derivation: A Dynamic PBKDF2 Model for Modern Cryptographic Systems. Cryptography 2025, 9, 39. [Google Scholar] [CrossRef]
- Singh, A.V.; Rathbun, E.; Graham, E.; Oakley, L.; Boboila, S.; Oprea, A.; Chin, P. Hierarchical Multi-agent Reinforcement Learning for Cyber Network Defense. arXiv 2024, arXiv:2410.17351. [Google Scholar]


Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2025 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).