Classical network
Delay, suppress, replay
Control the network while
valid MACs remain unforgeable.
Quantum channel
Store, measure, inject
Prepare fresh qubits from
known classical data.
An unknown qubit cannot be copied.
IEEE Quantum Week 2026
Toronto, Ontario, Canada
Ali Hamza MalikRaja Hasnain Anwar and Muhammad Taqi Raza
University of Massachusetts Amherst
September 13–18, 2026
Quantum communication
2
Quantum key distribution targets
information-theoretic security.
Its security foundation draws on quantum limits,
rather than computational hardness.
The quantum promise still depends on the complete protocol and its assumptions.
The procedure source
3
Paper study set: 8 recommendations, 11 specifications and 4 technical reports.
The security question
4
Suppose the hardware constraints
were solved today.
Would the published procedures be sufficient
to build a secure system tomorrow?
Standards-grounded symbolic models under Eve⁺, ideal primitives and single-session scope.
Prepare-and-measure QKD
5
QUANTUM CHANNEL
Disclose bases.
Keep bit values private.
Matching bases →
sifted bits.
BB84-style protocol shape with schematic bits and bases. Later attacks change the event order.
Entanglement-based QKD
6
Chosen basis+ × +
Chosen basis× + +
Correlations from the intended pairs
This model uses an untrusted external source. The records are illustrative, not a computed CHSH statistic.
The QKD procedure
7
Raw observations
Compatible bases
Keep compatible positions
Sifted observations
Data for reconciliation
Abort if disturbance is too high
Remaining observations
Reconciled data
Correct discrepancies through classical messages
Reconciled data
Final key
Apply privacy amplification
Schematic bit rows. Values and lengths are illustrative.
Modeled choices: Alice-first or Bob-first bases, with forward, reverse or two-way reconciliation.
Formal verification
8
Formal verification checks the executions allowed by a precise model.
Ask whether an allowed trace violates a security requirement.
Schematic illustration. The guarantee is limited to the model and its assumptions.
From classical protocols to QKD
9
Executions allowed by the model
Start
Property
fails
Concrete trace
1Initial state
2Permitted actions
3Violated guarantee
Specify the procedure, attacker choices and security question.
A counterexample is one allowed execution that fails the property.
Inspect the sequence to understand how the failure happens.
Schematic illustration. Verification is within the specified model and assumptions.
Classical precedent: TLS 1.3
10
SESSION 1: PSK 1
SESSION 2: PSK 2
The resumption transcripts match, but the session keys differ
Missing binding to the intended server / session
Alice intends to authenticate in her session with Charlie.
Charlie obtains the signature, then re-encrypts it for Bob.
Bob accepts it: Charlie impersonates Alice.
Proposed delayed-authentication extension to draft 10 with PSK resumption.
Base draft-10 verification was positive. The authors report a context-binding change in draft 11.
Classical precedent: EMV
11
01: Formal discovery
Tamarin model
PIN bypass
path
02: Experimental validation
Altered
data
No PIN
Studied
Visa card
Real payment terminal
The model exposed a path that bypassed cardholder verification.
Separate experiment: altered data claims “device verified.”
2020/2021 study of selected Visa contactless products.
Physical or proximity access to the card required.
Modeling challenges
12
This abstraction excludes amplitudes, channel noise and coherent quantum strategies.
From classical protocols to QKD
13
QUANTUM OBSERVATION
SYMBOLIC CLASSICAL CHECK
Measurement
Measured data
Consistent?
Symbolic dependency in the paper’s model. Physical behavior is abstracted.
Threat and scope
14
Classical network
Control the network while
valid MACs remain unforgeable.
Quantum channel
Prepare fresh qubits from
known classical data.
An unknown qubit cannot be copied.
Ideal primitives. Eve⁺ cannot forge a valid authenticated message.
Threat and scope
15
One bounded QKD session
per modeled instance.
The analysis permits unbounded protocol instances.
This does not establish security across successive sessions.
Single session. Coherent strategies, device faults
and cross-session key management excluded.
Why Tamarin fits the model
16
Symbolic operations
Idealized classical
cryptographic operations.
Execution logic
Can an attacker learn a key?
Did the intended peer participate?
Tamarin capabilities, not a list of QVerify built-ins.
Why Tamarin fits the model
17
PM preparation
Associate raw data with its preparation basis.
Measurement
Known matching basis makes raw data derivable.With a fresh basis, the symbolic operation does not derive the raw value.
Consistency checks
Use measurement-derived data to continue or abort.EB uses pair distribution and tracked pair state.
Selected dependencies only. No amplitudes, noise distributions or coherent behavior.
Why Tamarin fits the model
18
One stored qubit is an available resource.
Measure it or forward it.
Either step consumes that same modeled resource.
Ask whether disclosure can precede measurement.
Completion must remain possible in at least one run.
Consumable symbolic state. Ordering restrictions are assumptions.
Before the findings
19
Secrecy and authentication are separate goals. Executability checks that the model can run.
Security requirements
20
When Alice completes, apparently with Bob…
Each level adds a requirement to the previous one.
Lowe’s hierarchy, as used by the paper. The strongest check shown does not require unique matching runs.
V1: Subverted Entanglement Injection
21
Bob can disclose his bases
before Alice starts the session.
The modeled procedure does not verify
consistent qubit receipt times.
EB procedure under Eve⁺. Symbolic, single-session model with ideal primitives.
V1: Subverted Entanglement Injection
22
EB under Eve⁺. Symbolic, single-session model with ideal primitives.
V1: Subverted Entanglement Injection
23
Correlated raw data under Eve⁺ in the symbolic, single-session model.
V1: Subverted Entanglement Injection
24
All three modeled EB secrecy rows fail. Same Eve⁺, symbolic, single-session scope.
V1: Subverted Entanglement Injection
25
Symbolic trace compatible
with simulated results
The paper reports indistinguishable CHSH error distributions for the attack and noisy honest baseline.
CHSH checks can pass.
Four Aer trials. Noiseless attack circuits.
Setup-specific evidence, not deployment validation.
V2: Basis-Deferred Measurement
26
Selected A2B configuration under Eve⁺. Fresh preparation, never cloning.
V2: Basis-Deferred Measurement
27
Public post-processing lets Eve⁺
derive the session key.
CM1 requires measurement and authenticated commitment
before basis disclosure.
All three A2B secrecy rows fail under Eve⁺ in the symbolic, single-session model.
V3: Message Reflection
28
What verifies
The attacker returns
the valid message unchanged.
What is missing
Sender, receiver, role
and session context.
MAC remains valid. The modeled input omits context binding.
V3: Message Reflection
29
MAC unchanged. Agreement fails under Eve⁺ in the modeled session.
V3: Message Reflection
30
Bob completes from inputs that
do not establish Alice’s participation.
CM2 binds identities, roles and session context
along with the authenticated data.
Both PM TWEC rows fail agreement under Eve⁺ in the symbolic, single-session model.
No separate V3 secrecy attribution.
Countermeasures: CM1 and CM2
31
Close the timing window.
Bind the authenticated context.
CM1: Both parties measure, then send MAC-protected
commitments, then disclose bases.
CM2: Authenticate sender, receiver, roles,
session context and data together.
CM1 commitment payload and physical attestation mechanism unspecified.
Countermeasures: CM1 and CM2
32
9
repaired target models
Secrecy and agreement
checks verify.
CM1 + CM2.
Quantum subroutines unchanged.
Paper-reported result under Eve⁺ and the same symbolic, single-session scope.
The reusable contribution
33
3 EB configurations
Forward, reverse
or two-way.
6 PM configurations
Alice first or Bob first,
with the three reconciliation choices.
Reusable roles, attacker fragments, restrictions and security checks.
Nine studied configurations under Eve⁺, not every flag combination.
The reusable contribution
34
01
GenerateMake procedure choices explicit.
02
VerifyAsk the security question.
03
InspectRead the concrete attack trace.
04
RepairChange the procedure and check again.
QVerify provides models, templates, scripts and reports.
Demonstrated for the studied QKD family. Extension beyond it was not evaluated.
Scope and specification requirements
35
Evidence
Formal attack traces.
V1 Aer evidence under its setup.
Repaired symbolic checks.
Outside the analysis
Coherent strategies and device faults.
Cross-session key management.
Adequacy of added deployment mechanisms.
Eve⁺. Ideal primitives. Symbolic abstraction. Single-session scope.
Scope and specification requirements
36
Timing and order
Measure and commit before basis disclosure.CM1 addresses the windows used by V1 and V2.
Authenticated context
Bind sender, receiver, roles, session and data.CM2 addresses message reflection in V3.
Next: multi-session key management and open-testbed validation.
Requirements supported by the studied models.
CM1 commitment payload and physical attestation unspecified.
Read and reproduce
37
Paper
arXiv:2608.07626
QVerify
Models and verification artifacts
IEEE Quantum Week 2026
38