Source-linked AI summary
Quantum Tagging: Authenticating Location via Quantum Information and Relativistic Signalling Constraints
Adrian Kent, William J. Munro, Timothy P. Spiller
TL;DR
The paper asks whether quantum information and relativistic signalling constraints can authenticate a device’s classical location against an adversary with unbounded quantum capabilities. It defines security models and tagging protocols, then shows that several apparently secure schemes are broken by teleportation-based attacks, while some others resist those specific attacks without a proof of unconditional security.
Problem
The paper addresses how to authenticate a classical tagging device’s location in an environment controlled by an adversary with unbounded quantum processing and transmitting power.
Method
It defines quantum-tagging security models and analyzes protocols using quantum signals, classical information, and relativistic signalling constraints.
Results
Several protocols that initially appear unconditionally secure are shown to be breakable through teleportation-based attacks, while some protocols resist those specific attacks without being proven unconditionally secure.
Takeaways & Limitations
Naive quantum-cryptographic security reasoning fails when quantum information can be delocalized through operations such as teleportation.
Takeaways & Limitations
The analysis separates cryptographic security from physical security and does not examine how well the security models apply in realistic applications.
Abstract
from arXiv · showhide
We define the task of {\it quantum tagging}, that is, authenticating the classical location of a classical tagging device by sending and receiving quantum signals from suitably located distant sites, in an environment controlled by an adversary whose quantum information processing and transmitting power is unbounded. We define simple security models for this task and briefly discuss alternatives. We illustrate the pitfalls of naive quantum cryptographic reasoning in this context by describing several protocols which at first sight appear unconditionally secure but which, as we show, can in fact be broken by teleportation-based attacks. We also describe some protocols which cannot be broken by these specific attacks, but do not prove they are unconditionally secure. We review the history of quantum tagging protocols, which we first discussed in 2002 and described in a 2006 patent (for an insecure protocol). The possibility has recently been reconsidered by other authors. All the more recently discussed protocols of which we are aware were either previously considered by us in 2002-3 or are variants of schemes then considered, and all are provably insecure.
INTRODUCTION
The paper introduces quantum tagging as a cryptographic task for authenticating a device’s location using quantum information and relativistic signalling constraints. It defines security scenarios in which Alice’s stations verify a stationary, physically constrained tag against an adversary with extensive control outside the tag.
- Quantum tagging authenticates a classical device’s location using quantum information and the impossibility of superluminal signalling.
- The analysis uses Minkowski space-time, with the physically general case having three space dimensions while lower-dimensional cases simplify the discussion.
- Security scenario I: In the main stationary scenario, Alice’s trusted stations lie on opposite sides of a finite tag region whose location is known to her.
- Security scenario I: Signals and processing are assumed to occur at light speed with negligible processing time, while Eve cannot move the tag or perform non-trivial operations inside it.
- Security scenario I: The model allows Eve to control surrounding space, transmit through the stations and tag, jam signals, and inspect the tag’s interior, which contains no data Alice can safely assume secret.
Security scenario II
Security scenario II models a physically secure tag that Eve may move, while practical tagging protocols aim to detect interference before relocation or destruction is complete. The paper focuses on verifying the location of a stationary tag and separates physical security from cryptographic security.
- Security scenario II: In scenario II, Eve may move the physically secure tag at speeds up to a known bound v, with v ≪c assumed to avoid relativistic effects.
- Security scenario II: Realistic applications may involve three-dimensional tags, multiple stations in different directions, and outputs sent toward any or all stations.
- Security scenario II: Because destroying or relocating a tag and replacing it require time, the model assumes a lower bound ∆t on these operations.
- Security scenario II: Tagging protocols seek to detect Eve’s interference before the relevant operation is complete, and stationary-location verification can generalize to bounded-speed motion.
- Practical relevance: The paper separates physical security and attachment from cryptographic security, and does not analyze all possible security scenarios or models.
Spoofing
The paper frames spoofing as Eve’s interception, processing, and retransmission of signals, and seeks protocols secure against such attacks using timed signals and relativistic constraints. It distinguishes classical and quantum signal types while considering four input-output combinations.
- Spoofing: A general spoofing attack lets Eve intercept signals, process them collectively with information she holds, and retransmit altered, rerouted, or delayed outputs.
- Spoofing: Record-and-replay attacks threaten schemes without precise timing by replaying intercepted outputs from different locations after effectively jamming the original channel.
- Spoofing: The paper aims to use timed quantum or classical signals together with relativistic signalling constraints to resist general spoofing attacks.
- Spoofing: Quantum signals are single states in a fixed finite-dimensional Hilbert space, whereas classical signals are sufficiently redundant to be copied and broadcast effectively.
- Spoofing: The framework distinguishes classical or quantum input from classical or quantum output, yielding CC, QC, CQ, and QQ scheme classes.
SOME SIMPLE INSECURE SCHEMES
The simple schemes send randomly chosen quantum states and classical instructions to a tag, which immediately redirects each state toward one of Alice’s stations. They are not perfectly secure because teleportation-based attacks can spoof their authenticated location.
- SOME SIMPLE INSECURE SCHEMES: These schemes are not perfectly secure; their known attacks require perfectly efficient quantum teleportation, assumed unavailable with present technology.
- SOME SIMPLE INSECURE SCHEMES: Alice sends independently random pure qubits from one station and random classical bits from another, timed to arrive simultaneously at the tag.
- SOME SIMPLE INSECURE SCHEMES: The tag interprets each bit as an instruction to redirect the corresponding qubit toward the station selected by that bit.
- SOME SIMPLE INSECURE SCHEMES: In a generalized construction, independently random indices and qubits arrive with a second random index, jointly determining which detector receives each qubit.
Scheme III
Scheme III sends random qubits and classical trits simultaneously to a tagging device, which measures each qubit in the trit-selected basis and broadcasts the result. Alice authenticates the location if both detectors receive timely results with quantum-consistent statistics over N successive qubits.
- Scheme III: Scheme III combines independently random qubits from A0 with uniformly distributed trits from A1, arriving pairwise simultaneously at the tagging device.The trits select among three measurement bases.
- Scheme III: Each trit instructs the device to measure the received qubit in basis B_ci and immediately broadcast the classical outcome bidirectionally.The bases are B0=(|0⟩,|1⟩), B1=(|+⟩,|−⟩), and B2=(|i⟩,|−i⟩).
- Scheme III: Alice accepts the location after N successive qubits produce quantum-consistent measurement statistics and results that reach both detectors at the appropriate times.The qubits are sent within an interval Δt.
- Comment on authentication and timing: Because separated laboratories must collate and compare their data, authentication verifies that the device functioned correctly at the correct location during a past fixed interval.The verified interval lies in the past light cone of the completed verification point or points.
Discussion of (in)security of schemes I-III
Schemes I–III appear secure if no-cloning forces each qubit to follow one path, but that premise is false because quantum information can be delocalized. Teleportation and related operations therefore defeat the naive security argument.
- Discussion of (in)security of schemes I-III: The apparent security argument claims that no-cloning forces each qubit onto a unique trajectory, preventing Eve from learning the required classical information in time.The argument concludes that any spoofing attack has a nonzero detection probability and therefore treats the schemes as secure.
- Discussion of (in)security of schemes I-III: No-cloning does not imply that quantum information is localized at a single point, so the proposed trajectory-based security inference is invalid.The paper explicitly identifies localization as the crucial but unsupported implication.
- Discussion of (in)security of schemes I-III: Eve can delocalize quantum information through interferometric superpositions or teleportation while broadcasting the classical information generated by teleportation.The authors state that these operations allow Eve to exploit teleportation to break the schemes.
Teleportation attacks on schemes I and II
Eve breaks schemes I and II by teleporting incoming qubits between two intermediate laboratories and routing stored entangled qubits after the classical instructions arrive. The attack lets her infer and promptly transmit the outputs needed for Alice to accept the device location.
- Teleportation attacks on schemes I and II: Eve uses labelled entangled singlet pairs between E0 and E1, teleporting each incoming qubit at E0 while sending the teleportation data toward E1.The labels encode the signal index and the classical value ai needed to select the relevant stored qubit.
- Teleportation attacks on schemes I and II: After receiving bi, Eve routes stored qubits according to f(ai,bi), completing teleportation at E1 when the corresponding ai and teleportation signals coincide.Qubits selected for output toward A0 or A1 are transmitted at the appropriate stage of the attack.
- Teleportation attacks on schemes I and II: Eve suppresses or hides her classical attack signals while allowing Alice’s classical signals to propagate, preventing detection of the interception process.She uses unused frequencies or jams signals so they do not reach A0 or A1.
- Teleportation attacks on schemes I and II: Through this teleportation attack, Eve can spoof schemes I and II and cause Alice to accept the tagging location as authenticated.Scheme I is treated as a special case of scheme II.
- Teleportation attacks on scheme III: For scheme III, teleportation operations preserve the three measurement bases, allowing Eve to infer the original measurement outcome from the rotated state and the teleportation data.The relevant operations are I, X, Z, and XZ.
- Teleportation attacks on scheme III: Combining signals from E0 and E1 lets Eve infer and immediately send the measurement outcomes required by scheme III.This provides the outputs needed to spoof the scheme.
SECURE TAGGING PROTOCOLS?
The teleportation vulnerability of schemes I–III motivates variants that avoid single-detector outputs or measurement bases invariant under teleportation. Scheme IV uses idealized continuous Bloch-sphere choices, while scheme V offers a concrete finite-list approximation.
- SECURE TAGGING PROTOCOLS?: Schemes I and II have a general weakness because their outputs are directed to a single detector, whereas scheme III is specifically vulnerable because its measurement bases are teleportation-invariant.These weaknesses motivate considering protocol variations.
- SECURE TAGGING PROTOCOLS?: Scheme IV sends random pure qubits and random measurement-basis choices from A0 and A1 to arrive simultaneously at T.The basis is drawn uniformly from Bloch-sphere antipodes, and T measures the qubit in the specified basis.
- SECURE TAGGING PROTOCOLS?: Scheme IV is idealized because real implementations must approximate uniform Bloch-sphere distributions using finite lists.The paper notes that infinitely many finite-list approximations are possible.
- SECURE TAGGING PROTOCOLS?: Scheme V provides a concrete simplified finite-list construction using six random qubit states and trits selecting three corresponding measurement bases.The listed states include computational, real-rotated, and imaginary-rotated pairs.
Scheme VI
Scheme VI adds a random-bit test intended to make teleportation-like attacks detectable, but the discussion provides motivation rather than a security proof.
- Scheme VI: Scheme VI adds an extra feature intended to make its security easier to prove, although the authors do not establish that it is provably secure.
- Scheme VI: The authors explicitly state that Scheme VI's informal motivation does not constitute a security proof.
- Scheme VI: If b_i = 1, Eve risks detection when extracting information from ψ_i before learning the bit, because the state may not be reliably reconstructed later.
Remarks on teleportation attacks
Schemes IV and V avoid the specific teleportation attacks discussed for Scheme III, but their general security remains unresolved and no security proof is provided.
- Remarks on teleportation attacks: Schemes IV and V lack Scheme III's specific vulnerability because no non-trivial unitary leaves all their relevant measurement bases invariant.
- Remarks on teleportation attacks: The authors propose proving security by showing that spoofing would imply an impossible physical operation or that every relevant attack is detectable.
- Remarks on teleportation attacks: They offer no security proof and leave the attainable security levels and efficiency of different tagging schemes as open problems.
- Remarks on teleportation attacks: Quantum tagging admits many design options, including classical and quantum inputs, entangled signals across sites or rounds, and varied computations at T.
BRIEF HISTORY
The authors trace quantum tagging from their 2002–3 work and 2006 patent to later rediscoveries, showing that subsequently discussed protocols were already considered and are vulnerable to known attacks.
- BRIEF HISTORY: The authors first considered quantum tagging in 2002, developed the six protocols and attacks in 2002–3, and published an insecure protocol in a 2006 patent.
- BRIEF HISTORY: Later authors [21] rediscovered insecure protocols but apparently missed the attacks, while incorrectly arguing that their protocols were secure.
- BRIEF HISTORY: The attack on the protocol in Ref. uses stored particles, local unitaries, teleportation, classical communication, and timed result transmission to reproduce expected outcomes.
- BRIEF HISTORY: Later work showed unconditional security is possible when the tag contains private data inaccessible to adversaries, while schemes IV–VI are insecure against unbounded predistributed entanglement [22] [24].