---
title: Quantum User Equipment (QUEs)
url: https://www.emergentmind.com/topics/quantum-user-equipment-ques
type: topic
---

# Quantum User Equipment (QUEs)

Quantum User Equipment (QUEs) denotes a class of endpoint devices whose meaning varies across the current literature. In one line of work, especially on 5G and beyond, QUEs are **post-quantum-secure or quantum-resistant user equipment**: conventional mobile UEs whose endpoint security stack is upgraded with post-quantum cryptography rather than quantum hardware. In another line of work, QUEs are **quantum-capable edge devices** that receive, store, measure, modulate, or otherwise consume quantum states in optical, wireless, satellite, or edge-cloud architectures. Taken together, these uses suggest an endpoint-centric concept: quantum or quantum-era security functionality resides at the user device, even when expensive sources, detectors, or control logic remain centralized in the network [2507.17074][2509.14731].

## 1. Terminological scope and literature usage

The term is not used uniformly. The clearest explicit wireless definition appears in the proposed 1Q architecture, where “a mobile device that has both classical and quantum capability is denoted as QUE,” in contrast to a classical user equipment (CUE) without quantum capability [2509.14731]. By contrast, the 5G post-quantum literature uses QUE to mean **quantum-resistant UE** rather than a device with photonic or quantum-memory hardware. In that interpretation, the UE remains a conventional 5G endpoint, but its application-layer secure channel uses post-quantum key establishment and, in some cases, post-quantum signatures [2408.11117][2507.17074].

Other papers do not use the term directly but define close analogues. The **Quantum Network Unit (QNU)** in continuous-variable quantum access networks is the subscriber-side quantum endpoint; the **Q-node** in metropolitan quantum networking is the communication party in the quantum network; the **terminal laboratory platform** in a provider-managed quantum internet service provider functions as the user-facing endpoint; and the **universal terminal** for mobile edge-quantum computing is explicitly framed as a user-side quantum access device [2606.18840][2104.04629][2305.09048][2204.08522].

| Literature context | Endpoint analogue | Defining role |
|---|---|---|
| 5G post-quantum security | UE / QUE | PQC-enabled endpoint TLS over 5G |
| Quantum access networks | QNU / user receiver / transmitter | Fiber-access quantum endpoint |
| Metro or provider-managed quantum networks | Q-node / terminal platform | Network-addressable quantum node |
| Wireless 1Q systems | QUE | Dual classical-quantum mobile endpoint |

A recurrent misconception is that QUE necessarily means a terminal with quantum optics or quantum memory. The post-quantum 5G papers explicitly reject that interpretation and define the problem instead as endpoint cryptographic hardening against quantum adversaries [2507.17074]. The opposite misconception also appears: that QUE must mean only software-upgraded mobile hardware. The access-network, wireless, and edge-cloud papers make clear that many authors use essentially the same idea for physically quantum-capable endpoints [2509.14731][2606.18840].

## 2. Architectural patterns of endpoint functionality

Across the literature, QUE-like devices fall into several recurring architectural classes. The first is the **central-office-heavy access endpoint**. In the round-trip multi-band quantum access network, the Quantum Line Terminal (QLT) performs source generation, LO retention, coherent detection, and DSP, while each Quantum Network Unit requires only a minimal optical edge function; the paper states that “each QNU only requires one modulator and circulator when plugging into the network” [2305.05919]. In downstream and upstream quantum access networks for QKD, the same split appears in other forms: either the central office hosts the transmitter and each subscriber hosts a receiver, or each subscriber hosts a transmit-only quantum terminal while expensive detector hardware is shared centrally [2110.14126][1309.6431].

A second class is the **coherent-receiver subscriber**. In field-deployed continuous-variable access systems, the QNU is a receiver with a local local oscillator, polarization controller, integrated coherent receiver, photodetector for clock recovery, high-speed digitization, and a substantial DSP chain. In the QTTH continuous-variable access network, the QNU performs LLO-based heterodyne detection and reverse reconciliation; in the thermal-state access network, each QNU similarly uses a single-frequency laser, polarization controller, and integrated coherent receiver, with beacon-aided DSP for phase recovery [2606.18840][2605.20077].

A third class is the **provider-managed resource consumer**. In the reconfigurable quantum internet service provider, users do not necessarily own all high-end quantum hardware locally. Instead, Quagent exposes entangled-photon-source and detector resources through RESTful interfaces, while the endpoint is a terminal platform attached to the provider’s fiber plant and scheduled access system. This suggests a QUE model in which the device is partly an optical endpoint and partly a software client for provider-controlled quantum resources [2305.09048].

A fourth class is the **active processing endpoint**. In the QoS-oriented multi-user quantum network architecture, the end node is a processing node: a few-qubit quantum computer with communication qubits, storage qubits, local quantum operations, synchronization, and controller-installed schedules. In the universal terminal architecture for mobile edge-quantum computing, the endpoint is even richer: an atomic-lattice processor inside a cavity that emits time-bin photonic qubits for heterogeneous edge/cloud interconnection [2111.13124][2204.08522].

These patterns differ sharply in where complexity resides. Some architectures reduce the endpoint to a modulating or transmitting appliance; others require coherent reception and heavy DSP; others treat the endpoint as a small quantum processor. This suggests that “QUE” is best treated as a system role rather than a fixed hardware profile.

## 3. Post-quantum-secure QUEs in 5G and beyond

In the 5G literature, QUEs are primarily **post-quantum-secure endpoints**. The 2024 demo paper on “Post-Quantum Secure UE-to-UE Communications” shows how two UEs attached to a 5G network establish a TLS 1.3 session using wolfSSL integrated with liboqs so that Kyber/ML-KEM is used in key exchange. The paper is explicit that this does **not** quantum-secure the full 5G stack: UE registration to the 5G core remains conventional, and Kyber is integrated during TLS establishment only. It also notes that the demonstrated setup focuses on “quantum-safe key exchange,” while certificate-based authentication may still rely on classical ECC-style signatures [2408.11117].

That distinction matters technically. In this line of work, the QUE is hardened mainly against quantum attacks on endpoint key establishment and against “harvest now, decrypt later” exposure of recorded application traffic, but it is not yet a fully post-quantum-authenticated mobile terminal. The 2025 performance study makes this endpoint-centric model explicit: it treats “Quantum User Equipment (QUEs)” not as quantum hardware, quantum communication devices, or QKD-enabled terminals, but specifically as **post-quantum-secure / quantum-resistant user equipment** in a 5G setting [2507.17074].

The 2025 study also provides the strongest comparative performance data. Using Open5GS and UERANSIM with BoringSSL and liboqs, it evaluates ML-KEM and HQC for key establishment, and Falcon, ML-DSA, and SPHINCS+ for signatures. The paper reports that **ML-KEM with ML-DSA consistently yields the best overall efficiency**. For a fully post-quantum configuration, `mlkem512_mldsa44` is reported at **0.20% max CPU**, **23 ms latency**, **41.14 KB/s bandwidth**, and **0.0921% retransmission rate**, while SPHINCS+-based combinations are markedly heavier; for example, `hqc256_sphincssha2256f` reaches **10.60% CPU**, **140 ms latency**, and **374.01 KB/s** in the main tables [2507.17074].

The 2026 embedded evaluation moves the same question onto Raspberry Pi 5 devices and adds direct power measurements. Its main result is that **signature choice dominates latency and energy far more than KEM choice**. Hash-based signatures incur “up to 4x higher latency and 2x energy” than lattice-based alternatives, while the impact of KEMs is comparatively smaller. Among standardized combinations, ML-KEM-512 + ML-DSA-44 is identified as a balanced option, with latency **108, 118, 315, 648, 1325 ms** and energy **180, 126, 145, 145, 140 mJ/conn** across concurrency levels \(C \in \{1,4,10,20,40\}\) [2607.03988].

These papers collectively support a narrow but operationally important interpretation: a post-quantum QUE is a conventional UE whose cryptographic locus is the device software stack. A plausible implication is that near-term “quantum user equipment” in mobile networks will appear first as endpoint PQC upgrades at TLS or QUIC layers, with radio access, identity, and network-attachment mechanisms migrating later.

## 4. Optical access and provider-managed quantum endpoints

In optical access networks, QUE-like devices are usually defined by how much optical functionality is pushed to the edge. The oldest large-scale QKD access result in the provided corpus is an upstream quantum access network in which each user hosts a **transmit-only quantum terminal** and the expensive receiver is shared at the network node. The user-side device includes a distributed-feedback laser, intensity modulator, asymmetric Mach–Zehnder interferometer, phase modulator, fiber Bragg grating, attenuator, polarization controller, and timing alignment. This architecture supports up to **64 users** over GPON-like distances, with stable operation shown in smaller configurations and clear economic motivation through detector sharing [1309.6431].

A complementary downstream model appears in the practical quantum access network over 10G-EPON. There the user-side analogue of a QUE is a **receiver appliance** colocated with the ONU. Each receiver contains four InGaAs/InP single-photon detectors, a PIN detector for synchronization, and polarization-analysis optics. In the full coexistence scheme, the paper reports that a **16-user** network over **21 km** with **9 dB** OLT attenuation achieves **1.5 kbps** per user; in the partial coexistence dual-feeder scheme, **64-user** operation with full-power 10G-EPON is achieved over **11 km** [2110.14126].

Continuous-variable access systems further diversify the endpoint model. In the round-trip multi-band quantum access network, the user-side unit is reduced to a modulation appliance attached to a passive splitter; experimentally, each user is assigned a band such as **10 MHz**, **20 MHz**, or **30 MHz**, and the system achieves excess noise around **0.0040–0.0059 SNU** with secure key rates **825.82**, **674.46**, and **635.95 bits/s** after **30 km** fiber transmission [2305.05919]. In the field-demonstrated QTTH system, by contrast, the QNU is a coherent receiver with LLO-based heterodyne detection, and six representative users achieve **0.97–2.20 Mbit/s** asymptotic secure key rates in a **\(1\times 16\)** commercial-fiber deployment [2606.18840]. The thermal-state access network pushes centralization further still: a single broadband thermal source and EO-comb beacon system at the QLT supports **304 users** through \(19 \times 16\) frequency-and-splitting multiplexing, while each QNU remains a coherent receiving endpoint with DSP-defined mode selection [2605.20077].

A related but distinct model appears in the reconfigurable quantum internet service provider. There, the endpoint is not defined mainly by local source or detector ownership, but by access to centrally hosted entangled-photon-source and SNSPD resources through Quagent. The network currently involves **13 laboratories** and can support **up to 16 terminal nodes**; each user can access up to **5 EPS channels** and **4 SNSPD channels**. This is a provider-centric view of QUEs: endpoints are service consumers attached to a centrally instrumented quantum platform rather than owners of a complete quantum networking stack [2305.09048].

These architectures show that QUE complexity is not monotone. A user endpoint may be a transmit-only photonic frontend, a receiver appliance, a round-trip modulator, or a REST-addressable terminal platform. What remains constant is that the access problem is solved by choosing which optical burdens stay at the edge and which are pooled centrally.

## 5. Wireless, metropolitan, satellite, and edge-cloud interpretations

The 1Q framework is the most explicit attempt to place QUEs inside a wireless systems taxonomy. It defines quantum base stations (QBSs), quantum cells, and hybrid resource allocation across classical radio and quantum entanglement domains. In this system, a QUE has both classical RF connectivity and a free-space optical quantum interface; if it has quantum coverage, it must also have classical coverage because classical messaging is needed for quantum metadata, synchronization, and post-processing. The paper further states that QBSs act as the nodes “locally generating and distributing quantum resources among QUEs,” while QUEs act as clients “consuming and potentially storing entanglements.” It expects QUEs to be **quasi-static and nomadic rather than mobile, at least in the mid-term, due to hardware complexity and costs** [2509.14731].

The 1Q paper is also important because it gives QUEs a control-plane lifecycle. It extends cellular state management with an additional **entangled state**, and entanglement-session setup includes classical signaling of slice type, generate-and-store versus generate-and-measure mode, number of entangled pairs, maximum tolerable latency, application type and priority, and minimum acceptable fidelity. This makes the QUE not merely a physical terminal but a network-managed endpoint with joint classical–quantum admission requirements [2509.14731].

Metropolitan optical networking offers a different endpoint model. In IEQNET, the endpoint analogue is the **Q-node**, which is described as a hybrid classical/quantum system with optical and electronic interfaces controlled by an FPGA and additional software layers. A quantum endpoint is identified by the pair \(\langle \text{Q-node IP}, \text{quantum channel \#} \rangle\), and the node participates in synchronization, calibration, wavelength selection via tunable band-pass filters, and higher-layer entanglement services under SDN control [2104.04629]. This is a relatively infrastructure-heavy but network-native QUE model.

At the global scale, QuESat shows the opposite boundary condition: the paper does **not** model QUEs as first-class optimization nodes. Instead, users are attached to nearby ground stations by short-distance fiber or a quantum metropolitan area network, and the hybrid ground-satellite system acts as a global entanglement backbone. This suggests a layered interpretation in which QUEs remain local edge devices, while satellite and ground-station infrastructure provides wide-area entanglement transport [2501.15376].

The universal terminal for mobile edge-quantum computing pushes the endpoint concept in a more hardware-centric direction. It proposes a user-side quantum access device built around an atomic lattice processor inside a cavity, using Rydberg-Fermi cavity-QED to emit early or late photons and support encoding-agnostic photonic interconnection to edge servers, quantum memories, and the quantum cloud. The paper reports a simulated operation fidelity of **99.6%** for the local-stationary-to-flying-qubit mapping it studies [2204.08522]. This is not a near-term telecom UE, but it defines an ambitious physical-layer endpoint model for future QUEs.

## 6. Engineering constraints, QoS, and unresolved problems

The literature converges on a set of recurring engineering constraints. First are **timing, coherence, and fidelity**. In 1Q, successful application execution depends jointly on a digital time budget \(T_d\) and a quantum/coherence budget \(T_q\), and the paper models combined protocol success via
\[
p=\left(1-P_{\text{err}}^{(q)}\right)\left(1-P_{\text{err}}^{(c)}\right),
\qquad
P_{\text{succ}} = 1-(1-p)^K
\]
for identical per-block success probability across \(K\) blocks [2509.14731]. In the QoS architecture for multi-user quantum networks, applications request tuples \((src,dst,F_{\min},R_{\min},J_{\max})\), and the network must deliver entanglement that jointly satisfies fidelity, throughput, and jitter constraints under memory-lifetime and resource-contention limits [2111.13124].

Second are **centralized orchestration and schedule awareness**. The QoS paper treats end nodes as active participants in a centralized TDMA-like schedule, with reservation managers, entanglement managers, communication qubits, and storage qubits [2111.13124]. This suggests that high-performance QUEs, especially those closer to Q-nodes than to simple access transceivers, may need explicit controller interfaces and schedule installation, rather than best-effort service semantics.

Third are **SWaP, environmental robustness, and modularization**. The ROKS CubeSat payload is not framed as QUE, but it is directly informative for low-SWaP terminal design. Its modular split into quantum source, QRNG-enabled control electronics, acquisition/pointing/tracking, cloud-aware imager, and supervisory onboard computer provides a compact-terminal design pattern. The payload is engineered for a **6U CubeSat**, with a **90 mm** aperture telescope, a **MEMS mirror** for fine steering, and tested operationally over **\(-20^\circ\mathrm{C}\) to \(50^\circ\mathrm{C}\)** [2210.11285]. This suggests that future physically quantum-capable QUEs may be realized not as monolithic devices but as modular stacks whose optics, steering, sensing, and secure control can be independently integrated.

Fourth are **minimal-capability endpoint strategies**. The semi-quantum point-to-point protocols EKSQPC and REKSQPC target portable low-capability devices by giving the weak endpoint only two operations: reflect the incoming qubit, or measure it in the \(Z\)-basis and resend \(\ket{0}\). The paper claims theoretically constant minimal entanglement-preservation time \(C+2T\), a one-bit quantum register on the strong side, and asymptotic qubit efficiency approaching **100%** for EKSQPC and **99%** for REKSQPC [1810.06337]. This is not a full networked QUE architecture, but it identifies an extreme endpoint-minimization direction.

Several unresolved issues recur across the corpus. Many access-network papers provide asymptotic or implementation-level evidence but not full finite-size composable security treatment [2606.18840][2605.20077]. The 5G post-quantum studies demonstrate feasibility on VMs or embedded boards but do not yet migrate full mobile identity and access procedures to post-quantum mechanisms [2408.11117][2607.03988]. Wireless 1Q gives a system concept and protocol vocabulary, but practical QUE hardware classes, mobility procedures, and wireless quantum error protection remain open [2509.14731]. Even where terminals are simple, such as round-trip or upstream access systems, two-way security attacks, splitter loss, circulator imperfections, calibration drift, and detector bandwidth impose nontrivial deployment limits [2305.05919][1309.6431].

A careful synthesis is that QUEs are not a single device category but a design space. At one end lie post-quantum software-defined mobile endpoints; at the other lie quantum-capable optical or free-space terminals with memories, coherent receivers, or local quantum processing. The most consistent cross-paper lesson is architectural: practical systems tend to centralize the hardest sources, detectors, and orchestration functions, while the endpoint remains the locus of user identity, session semantics, and whatever minimum quantum or post-quantum functionality the application requires.

Source: https://www.emergentmind.com/topics/quantum-user-equipment-ques