quantum encryption abstract
– Getty Images

QuSecure said it helped a tier-one telecommunications operator deploy post-quantum transport layer security (TLS) across its network infrastructure without rewriting legacy applications, offering a potential migration path for telecom providers preparing for quantum-safe encryption.

The post-quantum cryptography (PQC) vendor presented the case study at Mobile World Congress in Barcelona. It described how the unnamed operator upgraded services to the latest TLS 1.3 protocol using hybrid post-quantum key exchange while maintaining compatibility with existing applications and infrastructure.

According to QuSecure, the deployment combined classical X25519 key exchange with the National Institute of Standards and Technology (NIST)-selected ML-KEM-768 post-quantum key encapsulation mechanism algorithm. Together, these create hybrid post-quantum TLS sessions that support quantum-resistant encryption while preserving interoperability with existing systems.

Rather than modifying application code across hundreds of services, the operator introduced a gateway proxy architecture that terminates TLS connections and applies encryption upgrades at the network layer. This approach enabled the operator to secure legacy services, including those still using older protocols or plaintext communications, without changes to underlying applications.

“This case study serves as a playbook for other telcos looking to operationalize post-quantum cryptographic readiness while building in control and agility for continued visibility,” Garfield Jones, SVP of global strategy and research at QuSecure, explained.

QuSecure worked with Accenture to roll out the deployment in phases across the operator’s infrastructure, beginning with edge services before expanding to internal service-to-service communications and hardened core transport links.

Large telecom networks often carry significant “cryptographic debt,” created by outdated or hard-coded encryption embedded in legacy systems. Many services still rely on older protocols such as TLS 1.2. Upgrading those systems typically requires coordination across multiple development teams, extensive testing, and scheduled maintenance windows.

By introducing encryption upgrades through a centralized proxy layer, the operator in the latest test was able to modernize its security architecture while avoiding large-scale application refactoring.

The case study also highlighted a broader shift in telecom security strategies. After experimenting with quantum key distribution (QKD) pilots, the operator concluded that deploying post-quantum cryptography through crypto-agile infrastructure offered a more scalable and cost-effective approach for global deployment.

As telecom operators prepare for the eventual threat posed by quantum computers to existing public-key cryptography, approaches that allow them to introduce post-quantum algorithms incrementally are attracting growing attention across the industry.