{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,28]],"date-time":"2025-10-28T09:41:51Z","timestamp":1761644511806,"version":"build-2065373602"},"reference-count":42,"publisher":"MDPI AG","issue":"11","license":[{"start":{"date-parts":[[2025,10,24]],"date-time":"2025-10-24T00:00:00Z","timestamp":1761264000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62471161"],"award-info":[{"award-number":["62471161"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"National Cryptography Science Fund","award":["2025NCSF02051"],"award-info":[{"award-number":["2025NCSF02051"]}]},{"name":"Innovation Program for Quantum Science and Technology","award":["2021ZD0300701"],"award-info":[{"award-number":["2021ZD0300701"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Entropy"],"abstract":"<jats:p>Quantum key distribution (QKD) networks promise information-theoretic security for multiple nodes by leveraging the fundamental laws of quantum mechanics. In practice, QKD networks require dedicated routing protocols to coordinate secure key distribution among distributed nodes. However, most existing routing protocols operate under the assumption that all relay nodes are honest and fully trustworthy, an assumption that may not hold in realistic scenarios. Malicious nodes may tamper with routing updates, causing inconsistent key-state views or divergent routing plans across the network. Such inconsistencies increase routing failure rates and lead to severe wastage of valuable secret keys. To address these challenges, we propose a distributed routing framework that combines two key components: (i) Causal Consistency Key-State Update, which prevents malicious nodes from propagating inconsistent key states and routing plans; and (ii) Trust-Aware Multi-path Flow Optimization, which incorporates trust metrics derived from discrepancies in reported states into the path-selection objective, penalizing suspicious links and filtering fabricated demands. Across 50-node topologies with up to 30% malicious relays and under all three attack modes, our protocol sustains a high demand completion ratio (DCR) (mean 0.90, range 0.81\u20130.98) while keeping key utilization low (16.6 keys per demand), decisively outperforming the baselines\u2014Multi-Path Planned (DCR 0.48, 30.8 keys per demand) and OSPF (DCR \u22640.12, 296 keys per demand; max 1601). These results highlight that our framework balances reliability and efficiency, providing a practical and resilient foundation for secure QKD networking in adversarial environments.<\/jats:p>","DOI":"10.3390\/e27111100","type":"journal-article","created":{"date-parts":[[2025,10,27]],"date-time":"2025-10-27T00:51:42Z","timestamp":1761526302000},"page":"1100","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Trust-Aware Causal Consistency Routing for Quantum Key Distribution Networks Against Malicious Nodes"],"prefix":"10.3390","volume":"27","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1479-6081","authenticated-orcid":false,"given":"Yi","family":"Luo","sequence":"first","affiliation":[{"name":"School of Cyberspace Science, Faculty of Computing, Harbin Institute of Technology, Harbin 150001, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8627-4066","authenticated-orcid":false,"given":"Qiong","family":"Li","sequence":"additional","affiliation":[{"name":"School of Cyberspace Science, Faculty of Computing, Harbin Institute of Technology, Harbin 150001, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2025,10,24]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"7","DOI":"10.1016\/j.tcs.2014.05.025","article-title":"Quantum cryptography: Public key distribution and coin tossing","volume":"560","author":"Bennett","year":"1984","journal-title":"Theor. Comput. Sci."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"025002","DOI":"10.1103\/RevModPhys.92.025002","article-title":"Secure quantum key distribution with realistic devices","volume":"92","author":"Xu","year":"2020","journal-title":"Rev. Mod. Phys."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"011318","DOI":"10.1063\/5.0179566","article-title":"Continuous-variable quantum key distribution system: Past, present, and future","volume":"11","author":"Zhang","year":"2024","journal-title":"Appl. Phys. Rev."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"025008","DOI":"10.1103\/RevModPhys.94.025008","article-title":"Security in quantum cryptography","volume":"94","author":"Portmann","year":"2022","journal-title":"Rev. Mod. Phys."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Hu, C., Wang, W., Chan, K.S., Yuan, Z., and Lo, H.K. (2023). Proof-of-Principle Demonstration of Fully-Passive Quantum Key Distribution. arXiv.","DOI":"10.1103\/PhysRevLett.131.110801"},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"21739","DOI":"10.1364\/OE.22.021739","article-title":"Field and long-term demonstration of a wide area quantum key distribution network","volume":"22","author":"Wang","year":"2014","journal-title":"Opt. Express"},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"6010","DOI":"10.1364\/OE.26.006010","article-title":"Integrating quantum key distribution with classical communications in backbone fiber network","volume":"26","author":"Mao","year":"2018","journal-title":"Opt. Express"},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"10387","DOI":"10.1364\/OE.19.010387","article-title":"Field test of quantum key distribution in the Tokyo QKD Network","volume":"19","author":"Sasaki","year":"2011","journal-title":"Opt. Express"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"101","DOI":"10.1038\/s41534-019-0221-4","article-title":"Cambridge quantum network","volume":"5","author":"Dynes","year":"2019","journal-title":"npj Quantum Inf."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"134","DOI":"10.1038\/s41534-021-00474-3","article-title":"Implementation of a 46-node quantum metropolitan area network","volume":"7","author":"Chen","year":"2021","journal-title":"npj Quantum Inf."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Tsai, C.W., Yang, C.W., Lin, J., Chang, Y.C., and Chang, R.S. (2021). Quantum Key Distribution Networks: Challenges and Future Research Issues in Security. Appl. Sci., 11.","DOI":"10.3390\/app11093767"},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"839","DOI":"10.1109\/COMST.2022.3144219","article-title":"The Evolution of Quantum Key Distribution Networks: On the Road to the Qinternet","volume":"24","author":"Cao","year":"2022","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3730575","article-title":"Quantum Key Distribution Networks\u2014Key Management: A Survey","volume":"57","author":"Dervisevic","year":"2025","journal-title":"ACM Comput. Surv."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"124","DOI":"10.1109\/MCOM.023.2300376","article-title":"Challenges of Routing in Quantum Key Distribution Networks with Trusted Nodes for Key Relaying","volume":"62","author":"Kong","year":"2023","journal-title":"IEEE Commun. Mag."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"15219","DOI":"10.1109\/JIOT.2024.3349476","article-title":"Routing with Minimum Activated Trusted Nodes in Quantum Key Distribution Networks for Secure Communications","volume":"11","author":"Kong","year":"2024","journal-title":"IEEE Internet Things J."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"168","DOI":"10.1109\/TNET.2019.2956079","article-title":"A Novel Approach to Quality-of-Service Provisioning in Trusted Relay Quantum Key Distribution Networks","volume":"28","author":"Mehic","year":"2020","journal-title":"IEEE\/ACM Trans. Netw."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"190","DOI":"10.1364\/JOCN.445621","article-title":"Routing and secret key assignment for secure multicast services in quantum satellite networks","volume":"14","author":"He","year":"2022","journal-title":"J. Opt. Commun. Netw."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Zhang, Q., Ayoub, O., Gatto, A., Wu, J., Lin, X., Musumeci, F., Verticale, G., and Tornatore, M. (2022, January 4\u20138). Joint Routing, Channel, and Key-Rate Assignment for Resource-Efficient QKD Networking. Proceedings of the GLOBECOM 2022\u20142022 IEEE Global Communications Conference, Rio de Janeiro, Brazi.","DOI":"10.1109\/GLOBECOM48099.2022.10001367"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"18317","DOI":"10.1364\/OE.516443","article-title":"Autonomic end-to-end quality-of-service assurance over QKD-secured optical networks","volume":"32","author":"Zhu","year":"2024","journal-title":"Opt. Express"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"2281","DOI":"10.1109\/TNET.2023.3246114","article-title":"Fast and Secure Routing Algorithms for Quantum Key Distribution Networks","volume":"31","author":"Akhtar","year":"2023","journal-title":"IEEE\/ACM Trans. Netw."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Kiktenko, E.O., Tayduganov, A., and Fedorov, A.K. (2024). Routing Algorithm Within the Multiple Non-Overlapping Paths\u2019 Approach for Quantum Key Distribution Networks. Entropy, 26.","DOI":"10.3390\/e26121102"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"1887","DOI":"10.1109\/JSAC.2025.3543524","article-title":"Quantum communication network routing with circuit and packet switching strategies","volume":"43","author":"Sun","year":"2025","journal-title":"IEEE J. Sel. Areas Commun."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"382","DOI":"10.1364\/JOCN.509269","article-title":"Comparison and optimization of different routing methods for meshed QKD networks using trusted nodes","volume":"16","author":"Johann","year":"2024","journal-title":"J. Opt. Commun. Netw."},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"2701","DOI":"10.1109\/JSAC.2021.3064662","article-title":"Hybrid Trusted\/Untrusted Relay-Based Quantum Key Distribution Over Optical Backbone Networks","volume":"39","author":"Cao","year":"2021","journal-title":"IEEE J. Sel. Areas Commun."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"020353","DOI":"10.1103\/PRXQuantum.3.020353","article-title":"Stream Privacy Amplification for Quantum Cryptography","volume":"3","author":"Huang","year":"2022","journal-title":"PRX Quantum"},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"14","DOI":"10.1038\/s41534-019-0131-5","article-title":"Foiling covert channels and malicious classical post-processing units in quantum key distribution","volume":"5","author":"Curty","year":"2019","journal-title":"npj Quantum Inf."},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"26","DOI":"10.1038\/s41534-020-00358-y","article-title":"Secure quantum key distribution with a subset of malicious devices","volume":"7","author":"Zapatero","year":"2021","journal-title":"npj Quantum Inf."},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"1328","DOI":"10.1109\/TNET.2021.3136943","article-title":"Quantum Network: Security Assessment and Key Management","volume":"30","author":"Zhou","year":"2022","journal-title":"IEEE\/ACM Trans. Netw."},{"key":"ref_29","unstructured":"Lo, H.K., Montagna, M., and von Willich, M. (2022). Distributed Symmetric Key Exchange: A scalable, quantum-proof key distribution system. arXiv."},{"key":"ref_30","unstructured":"Moy, J. (1998). OSPF, Version 2, Internet Engineering Task Force (IETF). Available online: https:\/\/www.rfc-editor.org\/rfc\/rfc2328."},{"key":"ref_31","unstructured":"Li, T., and Atkinson, R. (2008). IS-IS Cryptographic Authentication, Internet Engineering Task Force (IETF). Available online: https:\/\/www.rfc-editor.org\/rfc\/rfc5304."},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Rescorla, E. (2018). The Transport Layer Security (TLS) Protocol Version 1.3, Internet Engineering Task Force (IETF). Available online: https:\/\/www.rfc-editor.org\/rfc\/rfc8446.","DOI":"10.17487\/RFC8446"},{"key":"ref_33","unstructured":"Kent, S., and Seo, K. (2005). Security Architecture for the Internet Protocol, Internet Engineering Task Force (IETF). Available online: https:\/\/www.rfc-editor.org\/rfc\/rfc4301."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"1484","DOI":"10.1137\/S0097539795293172","article-title":"Polynomial-Time Algorithms for Prime Factorization and Discrete Logarithms on a Quantum Computer","volume":"26","author":"Shor","year":"1997","journal-title":"SIAM J. Comput."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"382","DOI":"10.1145\/357172.357176","article-title":"The Byzantine Generals Problem","volume":"4","author":"Lamport","year":"1982","journal-title":"ACM Trans. Program. Lang. Syst."},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"37","DOI":"10.1007\/BF01784241","article-title":"Causal memory: Definitions, implementation, and programming","volume":"9","author":"Ahamad","year":"1995","journal-title":"Distrib. Comput."},{"key":"ref_37","unstructured":"Terry, D.B., Demers, A.J., Petersen, K., Spreitzer, M.J., Theimer, M.M., and Welch, B.B. (1994, January 28\u201330). Session guarantees for weakly consistent replicated data. Proceedings of the 3rd International Conference on Parallel and Distributed Information Systems, Austin, TX, USA."},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"185","DOI":"10.14778\/2735508.2735509","article-title":"Coordination avoidance in database systems","volume":"8","author":"Bailis","year":"2014","journal-title":"Proc. VLDB Endow."},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"012408","DOI":"10.1103\/PhysRevA.105.012408","article-title":"Practical quantum multiparty signatures using quantum-key-distribution networks","volume":"105","author":"Kiktenko","year":"2022","journal-title":"Phys. Rev. A"},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"956","DOI":"10.1364\/JOCN.530575","article-title":"Distributed information-theoretical secure protocols for quantum key distribution networks against malicious nodes","volume":"16","author":"Luo","year":"2024","journal-title":"J. Opt. Commun. Netw."},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"5420","DOI":"10.1109\/TCOMM.2023.3280561","article-title":"An Information-Theoretic Secure Group Authentication Scheme for Quantum Key Distribution Networks","volume":"71","author":"Luo","year":"2023","journal-title":"IEEE Trans. Commun."},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"278","DOI":"10.1007\/s11128-019-2394-3","article-title":"Modeling and simulation of practical quantum secure communication network","volume":"18","author":"Wang","year":"2019","journal-title":"Quantum Inf. Process."}],"container-title":["Entropy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1099-4300\/27\/11\/1100\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,28]],"date-time":"2025-10-28T09:36:17Z","timestamp":1761644177000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1099-4300\/27\/11\/1100"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,24]]},"references-count":42,"journal-issue":{"issue":"11","published-online":{"date-parts":[[2025,11]]}},"alternative-id":["e27111100"],"URL":"https:\/\/doi.org\/10.3390\/e27111100","relation":{},"ISSN":["1099-4300"],"issn-type":[{"type":"electronic","value":"1099-4300"}],"subject":[],"published":{"date-parts":[[2025,10,24]]}}}