Experimental Side Channel Analysis of Protocol Stages in Quantum Identity Authentication

📅 2026-07-27
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This study addresses a critical vulnerability in quantum identity authentication protocols, which are susceptible to side-channel attacks at the physical layer. By identifying the protocol phase, an adversary can bypass authentication and exfiltrate data. The work presents the first experimental side-channel analysis of such protocols, employing a custom-built quantum communication testbed to non-invasively capture photon arrival times and optical power via beam splitters. Leveraging feature engineering and machine learning models, the approach achieves high-accuracy protocol phase identification, attaining 98% accuracy (F1-score: 97%) at a 30% signal sampling rate and 96% accuracy (F1-score: 94%) at 10%. These results expose a novel class of security flaws and provide crucial empirical evidence for enhancing the physical-layer security design of quantum protocols.
📝 Abstract
Quantum networks can enable distributed computing and sensing. To realize these capabilities securely, quantum identity authentication is essential. Without authentication at the quantum layer, malicious repeaters may retain entanglement instead of performing swapping, enabling man-in-the-middle attacks (MitM) between communicating parties. Authentication mitigates this threat by embedding authentication qubits within data qubits at positions and bases based on a secret key shared a priori. While prior work analyzes security and MitM detection guarantees, physical layer side channel analysis remains unexplored. If an attacker infers protocol stages, it can avoid authentication qubits and extract data qubits, rendering authentication ineffective. To this end, we carry out experimental studies using a quantum communication testbed. A beam splitter is used to tap a portion of the optical signal, allowing the observer to collect side channel data without disrupting the quantum state. We evaluate two sampling settings, where 30% or 10% of the signal is diverted. The collected side channel data includes photon arrival timing and optical power data obtained using a single-photon detector and a power meter. Using this dataset, we extract and engineer features that capture both timing dynamics and signal intensity variations. We then train machine learning models to classify protocol stages based solely on side channel observations. Our results show that protocol-stage inference is feasible with high accuracy, reaching 98% (F1-score 97%) at 30% sampling and 96% (F1-score 94%) at 10% sampling. These findings reveal an overlooked vulnerability and highlight the need for robust designs against side channel inference attacks.
Problem

Research questions and friction points this paper is trying to address.

Quantum Identity Authentication
Side Channel Analysis
Protocol Stage Inference
Man-in-the-Middle Attack
Quantum Networks
Innovation

Methods, ideas, or system contributions that make the work stand out.

side channel analysis
quantum identity authentication
protocol-stage inference
machine learning
quantum networks
M
Marwan Elawady
Cybersecurity Education, Research, and Outreach Center (CEROC) and Department of Computer Science, Tennessee Tech University, Cookeville, TN, USA.
L
Lance Young
Cybersecurity Education, Research, and Outreach Center (CEROC) and Department of Computer Science, Tennessee Tech University, Cookeville, TN, USA.
C
Contessa Wilburn
Cybersecurity Education, Research, and Outreach Center (CEROC) and Department of Computer Science, Tennessee Tech University, Cookeville, TN, USA.
B
Blaine Keyton
Cybersecurity Education, Research, and Outreach Center (CEROC) and Department of Computer Science, Tennessee Tech University, Cookeville, TN, USA.
C
Carrie Houston
Cybersecurity Education, Research, and Outreach Center (CEROC) and Department of Computer Science, Tennessee Tech University, Cookeville, TN, USA.
M
Mohamed Shaban
Cybersecurity Education, Research, and Outreach Center (CEROC) and Department of Computer Science, Tennessee Tech University, Cookeville, TN, USA.; Department of Mathematics, Faculty of Education, Alexandria University, Egypt
Muhammad Ismail
Muhammad Ismail
Director of CEROC and Associate Professor of Computer Science, Tennessee Tech University
NetworksCyber-physical SecuritySmart GridSmart Grid Security