Overview
ISO/IEC 23837-2:2023 defines test and evaluation methods for the security evaluation of Quantum Key Distribution (QKD) systems. As Part 2 of the ISO/IEC 23837 series, this international standard specifies practical evaluation activities (EAs) used to verify security functional requirements (SFRs) and supplementary security assurance requirements (SARs) for QKD modules, including both quantum optical components and conventional network components. The standard provides structured test procedures, thresholds, input parameters and pass/fail criteria to support consistent security assessments at appropriate assurance levels.
Key topics and technical requirements
The standard focuses on concrete, measurable evaluation methods rather than high-level policy. Major technical topics include:
- Evaluation activities (EAs) for SFRs and SARs: defined procedures to test protocol implementation, component behaviour and assurance controls.
- Quantum transmission and post‑processing tests: tests of quantum-state transmission, sifting, error correction and other post‑processing steps.
- Parameter adjustment procedures: verification of procedures that tune QKD performance and security parameters.
- Transmitter (TX) module tests:
- Photon-number distribution and mean photon number stability
- Intensity independence, state‑encoding accuracy and indistinguishability
- Global phase distribution, optical isolation, injected‑light monitor sensitivity
- Robustness against laser injection
- Receiver (RX) module tests:
- Detection probability consistency and temporal detection profile
- Back‑flash information leakage, optical isolation and injected‑light monitoring
- Robustness against bright‑light blinding and laser injection
- Dead time appropriateness and homodyne detector detection limits
- Test procedures and pass/fail criteria: clear step‑by‑step test methods and evaluation thresholds to determine compliance.
Practical applications and users
This standard is intended for stakeholders involved in designing, evaluating, certifying and deploying QKD systems:
- QKD equipment manufacturers - to validate component and module security during development and QA
- Independent test laboratories and certification bodies - to perform repeatable security evaluations and issue compliance reports
- System integrators and network operators - to assess QKD products prior to deployment in secure networks
- Procurement teams and auditors - to specify and verify security assurance levels for QKD solutions
Adopting ISO/IEC 23837-2:2023 helps ensure consistent, reproducible security testing of QKD modules and supports trustworthy integration of QKD into real‑world cryptographic infrastructures.
Related standards
- Other parts of the ISO/IEC 23837 series (companion documents) and existing information‑security and quantum‑cryptography standards are typically used together with this document when building a complete QKD assurance and certification framework.