Quantum-Resistant VPN for AWS - Secure your AWS cloud VPC with cutting-edge post-quantum encryption, genuine quantum entropy (QRNG), and ETSI QKD compatibility. Designed with Quantum Key Distribution (QKD) principles, and equipped with VPN ensures future-proof protection against evolving cyber threats. Stay ahead with next-generation security for your cloud infrastructure.
The hardware required with this listing must be obtained separately. Review the product details for more information.
pQKD Twin Cloud Edition is a solution for high-security connectivity between an AWS VPC (Virtual Private Cloud) and a client network, based on the principles of quantum cryptography realized through QKD emulation.
On the classical networking side it follows standard VPN principles, enhanced with secure symmetric key exchange provided by QKD emulation technology. This technology ensures full ETSI QKD compatibility, genuine quantum entropy from a quantum random number generator, and uses a standard post-quantum key encapsulation mechanism (FIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism Standard known also as CRYSTALS Kyber).
The solution consists of the following elements:
An EC2 server instance on AWS
A client computer on the client network
A pQKD hardware device.
The solution schema is presented below in the following picture: https://qkd-ss.s3.eu-west-2.amazonaws.com/pQKD+VPN+diagram.png
As shown in the picture, the VPN network is based on the efficient and secure WireGuard VPN. In our solution, we do not modify the essential security components of the VPN. WireGuard establishes a UDP connection (on port 51920), creating a new virtual network interface in the system. However, for maximum security, the transmitted standard key is encrypted with a presharedKey, identical on both the server and client sides, via an XOR operation, typical for One-Time Pad (OTP) mechanisms.
pQKD Twin (on the cloud side) and the pQKD hardware device (on the client network/computer side) provide mechanisms for distributing the presharedKey.
Consequently, our solution is a hybrid approach, combining the WireGuard system with a post-quantum key exchange based on quantum entropy. The service requests key generation by connecting to the pQKD service on AWS via the KME (Key Management Entity) port.
The pQKD service communicates through a TCP link (port 8000) with the client service and its pQKD device (where the quantum key is generated). The keys obtained on both the AWS server and client sides are then incorporated into the WireGuard VPN on each end.
On the AWS side, there is an EC2 instance with the following services installed:
WireGuard
A runner service for communication with WireGuard, pQKD, and the client
A software-based implementation of pQKD: pQKD Digital Twin
This server configuration has been saved as an AMI image on AWS.
On the client side, the following components are present:
WireGuard
A service for communication with WireGuard, pQKD, and the AWS server
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Try this product free for 10 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.
You pay by the hour for this cloud edition, billed through the EC2 instance type you choose to run it on. Every dimension maps to a specific AWS instance size, so your rate depends only on the compute you select. General-purpose, compute-optimized, memory-optimized, storage-optimized, GPU, and high-memory families are all available. Larger instances cost more per hour than smaller ones in the same family. There is no separate license fee or commitment; charges accrue while an instance runs and stop when you shut it down. Pick the instance that fits your workload's compute, memory, and networking needs.
Top-of-mind questions for buyers
What does one hourly unit cover, and what am I actually paying for?
Each unit is one running EC2 instance of the type you select, billed per hour. The rate reflects that instance's compute, memory, and networking capacity. You run the software that emulates key distribution and generates quantum entropy on that instance. Rates differ across instance families and sizes.
Am I charged when an instance is stopped or paused?
Hourly software charges accrue only while an instance runs. When you shut it down, software charges stop. There is no upfront license fee or commitment. Note that underlying AWS storage tied to a stopped instance may still incur separate AWS fees, but the software meters running time only.
How do I choose between instance types, and what drives my hourly cost?
Only the instance type you run drives cost. General-purpose, compute-optimized, memory-optimized, storage-optimized, GPU, and high-memory families are available. Larger sizes in a family cost more per hour. Match the instance to your workload's compute, memory, and networking needs; the software itself carries no separate fee.
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
The Post-Quantum Key Distribution (pQKD) is a comprehensive managed service offered by Quantum B. This service is centered around a hardware device called pQKD, a cybersecurity product that functions as a QKD system emulator, enabling accelerated adoption of quantum cryptography at a reasonable cost.
The QKD Solution Suite, available on AWS Marketplace and managed by Quantum B, provides a robust selection of Quantum Key Distribution (QKD) solutions from top-tier providers like HEQA Security, QNU Labs, and Quintessence Labs. This comprehensive service ensures secure and scalable quantum encryption capabilities tailored to meet your organization's needs.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.