Quantum Identity Authentication
- Quantum identity authentication is a protocol layer that uses quantum resources and state correlations to verify entities with high security and real-time challenge-response methods.
- It integrates techniques such as entanglement, decoy qubits, and shared secrets derived from QKD and other quantum primitives to ensure genuine user presence.
- Applications include secure communications, device-independent certification, and integration into biometric and decentralized systems to enhance network trust.
Quantum identity authentication (QIA) comprises interactive cryptographic protocols in which communicating parties authenticate identity by exploiting quantum resources rather than relying only on classical authentication primitives. In current quantum-network terminology, QIA belongs to entity authentication, which is distinct from authentication of classical messages and authentication of quantum messages; that distinction is operationally important because the security claim of a quantum protocol is meaningful only once its authentication resource and deployment assumptions are made explicit (Battarbee et al., 29 Jun 2026). Across the literature, QIA appears in entanglement-based and non-entangled forms, and also as a layer derived from QKD, QSDC, DSQC, teleportation, quantum secret sharing, blind quantum computing, zero-knowledge proofs, device-independent certification, and hardware-assisted identification (Dutta et al., 2021).
1. Role within quantum cryptography
QIA is motivated by the observation that the unconditional security of quantum key distribution depends on authenticating the identities of the communicating users. Classical identity authentication schemes were initially used in QKD implementations, but concerns regarding their vulnerability motivated the development of explicitly quantum identity authentication protocols (Dutta et al., 2024). In this setting, the task is not merely to validate the integrity of a transcript; it is to establish that the verifier is interacting with the genuine prover, in real time, under the protocol’s quantum and classical side conditions.
Recent reviews stress that entity authentication should not be conflated with message authentication. Entity authentication is challenge-response and concerns the live presence of a party, whereas message authentication concerns integrity and origin of transmitted data. This separation matters because many statements about “authentication in quantum networks” actually refer to different functionalities with different composability and scalability properties (Battarbee et al., 29 Jun 2026).
The recurring cryptographic ingredients of QIA are pre-shared secrets, authenticated enrollment, quantum state indistinguishability, entanglement correlations, measurement disturbance, and in some families Bell-nonlocality or hardware uniqueness. In many protocols, the authentication evidence is derived from the fact that only a party holding the correct secret, the correct entangled share, or the correct hardware module can produce the correlation pattern expected by the verifier.
2. Historical development and classification
The literature reviewed in recent surveys traces the first QIA protocol to Crépeau and Salvail (1995), based on oblivious transfer. Subsequent work in 1998–1999 introduced hybrid protocols combining quantum and classical techniques; the 2000s saw Bell-state and GHZ-state constructions, including controlled protocols with a third party; later work introduced non-entanglement single-photon schemes, device-independent protocols, semi-quantum variants, and physical-unclonable-function-based approaches (Dutta, 8 Aug 2025).
Two classification schemes recur throughout the literature. The first is by quantum resource: entanglement-based protocols use Bell, GHZ, or cluster states, whereas non-entangled protocols use single photons or other separable states. The second is by underlying task: QIA schemes are often derived from QKD, QSDC/DSQC, teleportation, quantum secret sharing, private comparison, or blind quantum computing (Dutta et al., 2021).
| Classification basis | Categories appearing in the literature | Typical examples in the surveys |
|---|---|---|
| Quantum resource | Entanglement-based; non-entangled; PUF/device-assisted | Bell, GHZ, cluster states; single photons; PUFs |
| Underlying task | QKD-based; QSDC/DSQC-based; teleportation-based; QSS-based; private comparison; blind quantum computing | BB84-style basis encoding, secure direct communication, entanglement swapping, delegated computation |
| Trust/topology model | Two-party; controlled with third party; multi-party; device-independent | Trent/Charlie-assisted schemes, mutual authentication, CHSH-certified protocols |
The surveys also identify structural symmetries among QIA schemes. Many protocols can be reduced to secure communication or secure computation primitives with modified post-processing, and this observation has been used to design new QIA protocols from existing QKD, QSDC, and CDSQC constructions (Dutta, 8 Aug 2025). A plausible implication is that QIA is better viewed as a protocol layer or transformation pattern than as a single cryptographic primitive.
3. Security models, impossibility results, and resource evaluation
A central line of criticism concerns two-party QIA without entanglement. The analysis of Zawadzki’s prepare-and-measure protocol shows that an adversary can obtain non-negligible information on the shared identification secret by measuring transmitted quantum states in a fixed basis and eliminating inconsistent keys. In that attack model, each measurement eliminates approximately one quarter of the possible keys, leaving approximately candidates after rounds (González-Guillén et al., 2020). The result is presented as consistent with the impossibility results of Lo (1997) and Buhrman et al. (2012), and the conclusion is explicit: two-party, non-entanglement QIA cannot be information-theoretically secure against an unrestricted adversary (González-Guillén et al., 2020).
That impossibility does not invalidate the whole field; it narrows the viable design space. The same analysis states that secure identification must either restrict adversarial capabilities, rely on entanglement or trusted third parties, or settle for computational rather than unconditional security (González-Guillén et al., 2020). This has directly influenced later work on entanglement-assisted, device-independent, relativistic, and hardware-assisted authentication.
A complementary perspective is quantum communication complexity. Protocols can be evaluated by the minimal amount of communication required to compute an authentication function securely in the worst case. The standard models are Yao’s model , the Cleve–Buhrman model , and the hybrid model . Within this framework, Kanamori et al. have , Li and Barnum and Zhang et al. have , and Zeng and Zhang have (Guedes et al., 2011). The same work emphasizes that comparisons are meaningful only within the same resource model.
A distinct asymptotic direction is quantum-public-key identification. Ioannou and Mosca give a protocol with pure-state public keys that is unconditionally secure against a computationally unbounded adversary and reusable in a bounded sense: up to public-key copies can circulate and up to 0 identification runs can be supported before refresh. The adversary’s success probability in one iteration is bounded by 1, and repetition over 2 rounds suppresses the overall cheating probability exponentially (Ioannou et al., 2011). This result establishes bounded reusability in a public-key setting, rather than unlimited reuse.
4. Entanglement-based mutual authentication
Bell-state protocols remain a canonical QIA family. A standard Bell-state encoding maps classical two-bit strings to
3
with corresponding Pauli operations drawn from 4 (Dutta et al., 2024). This representation is especially useful for schemes derived from entanglement swapping and controlled secure direct communication.
A representative recent construction is the simultaneous authentication protocol of Alice and Bob with the assistance of Charlie. Alice and Bob share a classical secret
5
with each element containing 2 bits. Alice prepares a Bell state from the 6 key, Bob prepares a Bell state from 7, both split their Bell pairs, and decoy qubits are inserted on transmitted sequences. Charlie performs a decoy-based security check, removes decoys, applies a random permutation 8, adds his own decoys, and forwards the permuted particles. After permutation disclosure and restoration, Alice and Bob apply key-dependent Pauli operations, perform Bell measurements, reveal complementary halves of their outcomes, and authenticate by XOR-based verification (Dutta et al., 2024).
The security analysis of that protocol is explicit. The impersonation success probability is 9, so the detection probability is
0
For intercept-resend attacks, the reduced state of intercepted particles is maximally mixed and the Holevo quantity satisfies
1
so single-particle interception yields zero key information. For impersonated fraudulent attacks, the non-detection probability is 2 for a single-qubit ancilla and 3 for an entangled ancilla (Dutta et al., 2024). The same paper highlights simultaneous bidirectional authentication, use of Bell states only rather than GHZ or cluster states, an untrusted rather than semi-honest Charlie, and high detection probability with as few as 4 pre-shared key pairs.
A related network-oriented protocol addresses malicious entanglements created by repeaters in a quantum network. In that scheme, Alice and Bob share a reusable secret key, the number of data qubits sent between authentication rounds is derived dynamically from the key, and Bob teleports authentication qubits chosen from 4 according to key bits. Alice measures in the corresponding basis and aborts on mismatch. The detection probability after 5 authentication rounds is
6
and simulation results report 100% detection after an average of 4 authentication rounds, while avoiding periodic refreshment of the shared secret key (Shaban et al., 2023).
5. Device-independent, zero-knowledge, and experimental realizations
Device-independent authentication imports Bell-nonlocality into the identity layer. In a DI-QSDC protocol with user authentication, Bob prepares EPR pairs in all four Bell states, uses identity strings 7 and 8 for authentication pairs, and Alice and Bob first perform a CHSH-based channel test. If the measured CHSH parameter satisfies 9, Bell nonlocal correlations are certified and the protocol proceeds. Mutual authentication is then realized through Bell-basis decoding of identity-encoded pairs and Pauli-encoded message or identity bits. The impersonation detection probability is 0, and the protocol is reported to require, on average, 1 qubit and half a Bell measurement per message bit (Das et al., 2023).
Zero-knowledge constructions provide another QIA route. One proposal translates Schnorr-style logic into quantum circuits by replacing modular arithmetic with single-qubit rotations
1
The prover demonstrates knowledge of a secret encapsulated in quantum states without revealing the secret itself. The security basis shifts from the hardness of the discrete logarithm problem to the hardness of quantum state estimation. The adversary’s success probability is bounded by 2, or by 3 when the quantum channel has error parameter 4, and the protocol states the zero-knowledge condition as 5 (Carney, 2022).
An experimentally implemented quantum zero-knowledge protocol for user authentication adapts discrete-variable QKD devices. Alice and Bob pre-share a secret 6, derive bitstrings 7 and 8 from a timestamped KDF, use 9 to determine preparation and measurement bases, and use an OTP-encrypted substring with 0 to let the verifier estimate the QBER without learning the secret. Authentication is accepted when 1. In a back-to-back configuration, the reported QBER is 2 in the honest case and 3 for a malicious prover; the implementation was validated from a back-to-back setup to more than 60 km, and the paper states completeness, soundness, and zero-knowledge properties (Garcia-Cid et al., 2024).
Hardware-assisted hybrid protocols introduce a different trust anchor. One recent pair of protocols combines weak classical PUFs with entanglement and local indistinguishability. The offline protocol uses pre-distributed Bell states and no quantum communication during authentication; the online protocol introduces a Hybrid Entangled PUF (HEPUF), requires quantum communication, and uses local indistinguishability to prevent an adversary from identifying or simulating the correct authentication states. The offline forging probability is 4, while the online forging probability is
5
which remains exponentially small for small or moderate PUF bias 6 (Goswami et al., 15 Apr 2025).
6. Applications, network integration, and adjacent directions
QIA increasingly appears as a subsystem inside larger quantum-network applications. In multi-party verifiable blind quantum computing, three protocols are proposed for clients who can only measure, prepare single qubits, or perform a few single-qubit gates. Each protocol has registration, identity authentication, and blind computation phases. Shared keys are established with the assistance of a semi-honest certificate authority and load balancers, Bell-state measurements and decoy qubits are used in registration and authentication, and the resulting construction is intended to resist both insider and outsider attacks in quantum networks (Quan et al., 2022).
In decentralized biometric systems, the authentication problem is recast as mutual trust establishment between biometric sensors and verification agents before transferring sensitive biometric data. One proposed protocol combines ML-KEM on the classical channel with authentication and decoy qubits on the quantum channel before running QKD. The reported QBER threshold is 3%, the simulated key generation rate is 15 bits/sec, and the efficiency is 89% (Qasim et al., 8 Jan 2026). This suggests that some current “quantum-secure authentication” systems are best understood as layered architectures that borrow QIA mechanisms without being reducible to the older two-party identification model.
An adjacent but distinct direction is quantum device attestation. QDNA-ID builds a trust-chain from physical quantum behavior to digitally signed records by combining Bell or CHSH verification, entropy/divergence/bias fingerprints, HMAC-SHA256, RSA-SHA256 signatures, timestamps, hierarchical indexing, and machine-learning-based drift analysis. The framework explicitly contrasts itself with typical QIA by arguing that protocol-level proof of “genuine quantum” does not by itself provide persistent provenance, time binding, or long-term auditability (Neamah, 21 Nov 2025). Its subject is device native authentication rather than human or protocol-party identity authentication, but it addresses a closely related trust problem in quantum infrastructures.
Relativistic zero-knowledge identity verification represents another neighboring approach. A graph 3-coloring protocol with spatially separated provers and verifiers enforces non-signaling through spacetime constraints, relaxes the engineering distance from 60 m to 30 m, and extends from two provers to three provers to strengthen security against entangled malicious provers (Ma et al., 18 Jul 2025). Although this is framed as quantum-safe identity verification rather than standard QIA, it exemplifies the broader movement away from purely computational identity assumptions toward physics-based authentication.
Across these strands, no single architecture dominates. The literature instead presents a family of authentication mechanisms whose suitability depends on the required functionality, trust model, communication complexity, setup assumptions, composability, and scalability. In that sense, QIA is a central but non-uniform layer of quantum cryptography: its concrete security guarantees are inseparable from the physical, network, and cryptographic assumptions under which the protocol is deployed (Battarbee et al., 29 Jun 2026).