Dynamic Entanglement Distribution for Multi-User and Multi-Protocol Quantum Networking
Source: arXiv:2607.15262 · Published 2026-07-16 · By Rui Wang, Marcus J. Clark, Obada Alia, Sima Bahrani, Djeylan Aktas, Matej Peranić et al.
TL;DR
This paper addresses the challenge of scalable, dynamic entanglement distribution for multi-user and multi-protocol quantum networks over metropolitan-scale deployed optical fibre infrastructure. The authors present a quantum reconfigurable optical add-drop multiplexer (q-ROADM) that actively and programmably allocates polarisation-entangled photon pairs from a broadband source across multiple users with flexible network topologies such as full-mesh, partial-mesh, and sliced subnetworks. They experimentally demonstrate a six-user entanglement-based quantum communication network over campus and metropolitan links, maintaining stable operation and secret key generation over more than 150 hours. The paper also shows how network slicing and multi-path quantum authentication-transfer protocols can be implemented on the same physical infrastructure via dynamic reconfiguration, enhancing flexibility and security. This architecture represents a practical step toward scalable, service-oriented quantum networking capable of supporting multiple heterogeneous quantum protocols simultaneously.
Key findings
- Stable six-user full-mesh entanglement distribution was maintained over 157.3 hours with secret key rates (SKRs) ranging from 9.8 bps to 153.2 bps across the 15 quantum links (Fig. 4).
- Full-mesh configuration generated more total secret keys than time-shared partial-mesh schemes under favourable conditions (15% source heralding efficiency, <100 ps detector jitter), but partial-mesh outperformed full-mesh under challenging conditions (3% heralding efficiency, 300–350 ps jitter) due to lower accidental coincidences (Figs. 5, 6).
- A flexible quantum network slicing demonstrated partitioning the physical network into two independent three-user sub-networks with optional interconnection links that did not significantly degrade SKR or increase QBER (Fig. 7).
- The q-ROADM architecture enabled protocol-aware dynamic entanglement allocation to support multi-path Secure Inaugural Authentication-Transfer (SIAT) for onboarding a new user, achieving up to 2587 s reduction in authentication time depending on authentication order and network conditions (Fig. 9).
- Wavelength-pair assignment using ITU-T DWDM channels allowed 15 unique quantum links for 6 users using a 30-channel broadband polarisation-entangled photon source (Fig. 2).
- Polarisation control and stabilisation modules maintained consistent measurement bases across deployed fibre despite birefringence-induced fluctuations, preserving entanglement quality over long-term operation.
- The SKR and QBER were shown to be sensitive to pump power, source heralding efficiency, detector jitter, and link loss, highlighting the need for adaptive entanglement allocation enabled by q-ROADM.
Threat model
Adversaries are assumed to be eavesdroppers with access to fibres but no control over trusted network nodes or measurement devices. Physical node security and trusted detection apparatus are assumed, focusing on maintaining secure quantum key generation over noisy, lossy metropolitan deployed fibre and on protecting authentication transfer during new user onboarding.
Methodology — deep read
The threat model assumes legitimate network users communicate quantum keys securely via entangled photon pairs distributed by a trusted central source, while adversaries may attempt eavesdropping or disruption but cannot physically access internal controlled network nodes or detectors.
Data used includes secret key rates, quantum bit error rates (QBER), and coincidence correlation histograms acquired from a six-user deployed quantum network over >150 hours. The entangled photon source was a broadband type-0 SPDC source centered at 1550.12 nm, producing polarisation-entangled photon pairs with heralding efficiencies up to 15%. Users connected via campus and metropolitan fibre spanning 1.6 km to 5.6 km with losses 8.1–15.1 dB. Data collection employed timestamped coincidence measurements via time taggers and superconducting nanowire single photon detectors (SNSPDs).
The q-ROADM architecture consists of a demultiplexer dividing the broadband entangled spectrum into 30 ITU-T 100 GHz DWDM channels (±15 channel pairs), polarization controllers to stabilise signals post-fibre transmission, a 192x192 optical fibre switch enabling flexible cross-connections, wavelength selective switches (WSSs), and multiplexers to recombine selected wavelength channels for each user’s link. This optical switching layer enables programmable full-mesh, partial-mesh, and network slicing configurations without changing physical fibre paths.
User stations feature polarization analysis modules with beam splitters selecting measurement bases (HV or DA), polarization beam splitters, half-wave plates, and SNSPDs to detect photons. Coincidence correlations among detector pairs are post-processed to calculate quantum bit error rates (QBER) and sifted keys.
The six-user full-mesh network establishes all 15 bi-directional quantum links simultaneously using wavelength pairs assigned per Fig. 2b. Experiments run continually over 157 hours with intermittent re-neutralisation of polarization compensators. Secret key rates were determined following standard BBM92 entanglement-based QKD analysis including error correction and privacy amplification using the observed QBER. The asymptotic secret key length lower bound formula was applied.
The partial-mesh configurations time-share subsets of the full network, serving complementary links sequentially, each run for half the full experiment duration for fair comparison. Experiments explore different source pump powers and two detector/jitter/ heralding efficiency regimes.
Network slicing is demonstrated by logically partitioning the physical network into independent sub-networks with no overlapping quantum links, and optionally adding interconnection links under q-ROADM control, to allow separate users groups or federated services.
The Secure Inaugural Authentication-Transfer (SIAT) protocol is implemented by dynamically configuring only required quantum links for initial authentication of a new user, followed by flooding-based multi-path key establishment leveraging XORed keys to reduce trusted node dependence. The real-time application uses measured SKRs for timing analysis under two authentication strategies.
Code, seed strategies, and hyperparameters are not detailed; hardware includes continuous-wave 775 nm pump lasers, MgO:PPLN nonlinear crystals for SPDC, Polatis optical switches, Finisar WSS devices, SNSPDs, and Swabian time taggers. Experimental setups used deployed fibre links on University of Bristol campus and metropolitan network. Supplementary sections provide further polarisation control and protocol timing details.
End-to-end example: an entangled photon pair at wavelengths λi and λ−i from the SPDC source is routed via q-ROADM configured optical switches and WSSs to user pairs (e.g. Alice and Bob). Each user measures polarization basis using PAM and SNSPDs. Coincidence counts between detectors identify correlated bits after classical communication exchanges. QBER and sifted key length are calculated from these counts, then distilled into final secret keys. Network topology can be reprogrammed on demand to add/remove users, change connectivity, or implement SIAT protocol steps.
Technical innovations
- Integration of a quantum reconfigurable optical add-drop multiplexer (q-ROADM) combining wavelength multiplexing, optical switching, and polarization control for dynamic entanglement allocation in a scalable quantum network.
- Demonstration of long-term stable six-user full-mesh metropolitan-scale entanglement distribution over deployed optical fibre for more than 150 hours with consistent SKR and QBER performance.
- Implementation of quantum network slicing on the physical layer allowing logical partitioning of a single fibre infrastructure into independent quantum sub-networks with optional programmable interconnection links.
- Protocol-aware entanglement resource distribution enabling dynamic reconfiguration to support authentication-transfer protocols (SIAT) combined with multi-path flooding to enhance onboarding security and efficiency.
Datasets
- Metropolitan six-user entangled photon distribution dataset — >150 hours continuous measurement — University of Bristol deployed campus and metropolitan fibre, not publicly released
Baselines vs proposed
- Full-mesh configuration: total accumulated secret keys over 40 minutes ranges 2x10^5 to 4.5x10^5 bits depending on pump power (Fig. 5d) vs partial-mesh (two 20-minute runs): ~1x10^5 to 3.5x10^5 bits
- Under challenging conditions (3% heralding efficiency, 300-350 ps jitter), partial-mesh outperforms full-mesh on many links (Fig. 6b) due to reduced accidental counts
- SIAT authentication time for 5-user onboarding: Strategy 1 = 1356 s vs Strategy 2 = 1298 s (favourable condition); Strategy 1 = 6958 s vs Strategy 2 = 4371 s (challenging condition) (Fig. 9)
Figures from the paper
Figures are reproduced from the source paper for academic discussion. Original copyright: the paper authors. See arXiv:2607.15262.

Fig 1: A 6-user entanglement-based quantum communication network architecture enabled by a q-ROADM. A

Fig 2: (a) q-ROADM architecture for dynamic entan-

Fig 3: Temporal correlation histogram between Alice

Fig 4: SKR of all 15 links in the six-user full-mesh

Fig 5: Comparison between full-mesh and time-shared

Fig 6 (page 2).

Fig 7 (page 2).

Fig 8 (page 2).
Limitations
- The heralding efficiencies and detector jitter affect performance significantly; challenging conditions reduce key rates and increase error rates.
- The experiments are limited to six users and 15 quantum links; scalability beyond this number is not evaluated.
- Adversarial security tests such as active attacks or real adversarial nodes were not conducted; the focus was on stable entanglement distribution and protocol capability demonstration.
- The authentication-transfer protocol evaluation assumes trusted network nodes and does not address fully adversarial models or quantum repeater integration.
- Detailed code, parameter settings, and full dataset release are not provided, limiting reproducibility.
Open questions / follow-ons
- How does the q-ROADM architecture scale to networks with dozens to hundreds of users and heterogeneous quantum repeaters?
- Can active adversarial attacks on switch configurations or photon routing be detected and mitigated dynamically?
- What are the performance and security trade-offs when integrating quantum error correction or quantum memories with this architecture?
- How can the authentication-transfer protocols be made robust against malicious insider nodes or quantum hacking attempts?
Why it matters for bot defense
For bot-defense practitioners exploring quantum-safe authentication and secure communication, this paper provides valuable insights into practical dynamic entanglement distribution architectures that enable flexible, multi-user quantum networks over deployed fibre. The q-ROADM-based network can adapt topology and allocate quantum keys based on real-time conditions, which parallels adaptive bot-detection systems allocating resources dynamically. Quantum network slicing and protocol-aware resource management offer concepts potentially translatable to layered bot defense strategies, isolating suspicious traffic flows or coordinating multi-protocol authentication schemes. The demonstrated SIAT protocol combined with multi-path flooding also suggests approaches for distributed, trust-minimized secure onboarding and key handover, which is conceptually related to secure CAPTCHA challenge distribution among multiple verification nodes. While quantum hardware specifics differ, the architectural and protocol design principles for flexible, robust, and scalable entanglement distribution are informative for future-proof bot-defense systems leveraging quantum cryptographic primitives.
Cite
@article{arxiv2607_15262,
title={ Dynamic Entanglement Distribution for Multi-User and Multi-Protocol Quantum Networking },
author={ Rui Wang and Marcus J. Clark and Obada Alia and Sima Bahrani and Djeylan Aktas and Matej Peranić and Mario Stipčević and Martin Lončarić and John Rarity and Siddarth K. Joshi and Dimitra Simeonidou },
journal={arXiv preprint arXiv:2607.15262},
year={ 2026 },
url={https://arxiv.org/abs/2607.15262}
}