🤖 AI Summary
Although quantum key distribution (QKD) offers information-theoretic security, its hybrid architectures exhibit cross-layer security blind spots due to the integration of classical post-processing with quantum stages, and existing standards inadequately assess the impact of classical control on overall security. This work proposes the first holistic QKD security verification framework encompassing the classical control plane, constructing a formal symbolic model in the Tamarin prover based on ETSI and ITU-T specifications to enable automated protocol analysis. The study uncovers three novel vulnerabilities stemming from omissions in classical procedures within current standards—sub-version entanglement injection, basis-delayed measurement, and message reflection—and introduces two innovative countermeasures: measurement commitment and identity-binding MAC. Formal verification confirms that the proposed enhancements effectively eliminate these vulnerabilities, and the findings have been submitted to relevant standardization bodies.
📝 Abstract
Quantum Key Distribution (QKD) protocols provide information-theoretic security by using quantum mechanical principles. Yet QKD is fundamentally a hybrid protocol: its security depends on the correct integration of the quantum phase with classical post-processing. While ETSI and ITUT specifications standardize QKD architectures and interfaces, they evaluate protocol security in isolation, leaving cross-layer interactions as an underexplored attack surface. This paper introduces a formal verification framework that holistically models QKD protocols based on ETSI and ITUT QKD specifications. Our model is the first hybrid QKD protocol model that supports automated analysis of protocollevel security focusing on how classical operations influence the security guarantees provided by the quantum phase of the QKD protocol. We formalize a comprehensive symbolic model of QKD protocols, based on ETSI and ITU-T QKD specifications, in Tamarin, an automated protocol verifier. Applying this framework, we obtain formal evidence of three specification-level vulnerabilities in ETSI- and ITU-T-grounded protocol models under adversary Eve+: subverted entanglement injection, basis-deferred measurement, and message reflection. Each arises from a classical control-plane omission in the procedure text and is established under a symbolic abstraction rather than as a claim about all practical deployments. We introduce two protocol improvements: measurement commitment and identitybound message authentication codes (MACs). Tamarin verification confirms that these countermeasures eliminate the identified vulnerabilities under Eve+. We have communicated our results and recommendations to relevant standardization organizations.