Quantum Key Distribution (QKD) is a process to establish a symmetric key between two parties using the principles of quantum mechanics. Currently, commercial QKD systems are still expensive, they require specific infrastructure, and they are impractical for deployment in portable or resource-constrained devices. In this article, we introduce the Butterfly Protocol (and its extended version) that enables QKD to be offered as a service to non-QKD-capable (portable or IoT) devices. Our key contributions include (1) resilience to the compromise of any single classical link, (2) protection against malicious QKD users, (3) implicit mutual authentication between users without relying on large post-quantum certificates, and (4) the Double Butterfly extension, which secures communication even when the underlying QKD network cannot be fully trusted. We also demonstrate how to integrate the Butterfly Protocol into TLS 1.3 and provide its initial security analysis. We present preliminary performance results and discuss the main bottlenecks in the Butterfly Protocol implementation. We believe that our solution represents a practical step toward integrating QKD into classical networks and extending its use to portable devices.
Kozlovičs et al. (Wed,) studied this question.