Quantum-Safe MACsec Demo
RAD’s practical route to quantum-safe encryption
Quantum computers will eventually break the public-key cryptography that secures the networks we rely on. Attackers are counting on it, harvesting encrypted data now to decrypt it once quantum power catches up.
RAD’s Carrier Ethernet demarcation and aggregation devices work opposite a symmetric key orchestrator, creating encryption keys on demand so the network stays protected as the threat evolves.
Each RAD device runs a Quantum-Safe agent. The agents authenticate to the orchestrator and open a quantum-safe tunnel that carries post-quantum key material down to the devices.
For an extra layer of trust, the solution also uses a RAD key server that supplies a classical key over standard TLS.
Each device combines that classical key with the quantum-safe key to form a shared hybrid key.
The logic is simple: If either algorithm is ever weakened, the other still holds. The data stays protected by classical cryptography that has stood the test of time, until post-quantum algorithms are fully validated in the field.
From this hybrid key, the devices derive the pre-shared key that MACsec calls the Connectivity Association Key, or CAK.
With the CAK in place, the two devices establish trust and run the MACsec Key Agreement protocol, or MKA.
One device takes on the MKA Key Server role and generates the session key, known as the Secure Association Key, or SAK. It distributes the SAK to its peer over MKA, and both devices use it to encrypt live traffic.
Keys never sit still. The CAK is refreshed every minute and the SAK every ten seconds, which keeps a captured key worthless almost as soon as it is seen.
And if the link to the orchestrator drops, the agents keep deriving fresh keys on their own, so MACsec protection never pauses.
Both RAD devices show as active and provisioned in the management platform.
The same view tracks activity in detail, so operators can monitor device status and user actions from a single screen.
With registration complete, key agreement begins. Each endpoint receives key material from the orchestrator over its quantum-safe tunnel and uses it to build a matching symmetric key.
Three keys are now visible on each device. The first is the quantum-safe key. The second is the classical key from the RAD key server. The third is the hybrid key, which serves as the CAK.
In the MKA window, you can watch the two devices exchange keys. In the hardware view, both sides now hold identical keys, so MACsec-encrypted traffic is flowing between them.
Now we cut off the orchestrator.
Watch what does not happen: Nothing stops. The agents keep producing symmetric keys on their own. The CAKs stay aligned, and MKA carries on distributing session keys between the devices, so traffic keeps flowing with full MACsec protection.
When the link is restored, the agents reconnect to the orchestrator and pick up normal operation.
RAD’s practical route to quantum-safe encryption hardens the network against tomorrow’s threats. Future-proof your network with RAD’s quantum-safe MACsec.
Contact us at [email protected] to learn more.