Quantum authentication is the sub-field of quantum cryptography that aims to apply quantum information theory for the purpose of authentication of quantum messages, users or devices. Counterintuitively, it refers to a different problem from the authentication of the classical channel assumed in QKD protocols, which doesn't natively require quantum resources. A number of authentication protocols have been proposed since the advent of quantum cryptography, often inspired by quantum key distribution counterparts. Ongoing research aims to both design new schemes and experimentally implement already proposed ones, as the technologies needed are mostly still under development.
History The first quantum authentication protocol was proposed in 1995, based on oblivious transfer. Subsequent results in quantum cryptography showed that unconditionally secure two-party oblivious transfer in the quantum setting is impossible, limiting the feasibility of such constructions. Early work also addressed the broader problem of quantum message authentication. It was proposed that quantum states can be authenticated against tampering using symmetric-key techniques, but that general quantum public-key authentication is not achievable without additional assumptions or restricted adversarial models. These results also influenced following work on quantum digital signatures, using pre-distributed quantum states and restricted security assumptions. Limited activity on quantum identity authentication (QIA) continued in the late 1990s, followed by a marked increase in proposals from the early 2000s onward. Many of these early QIA protocols were motivated by developments in quantum key distribution and typically assumed pre-shared entanglement or conjugate coding techniques; research on quantum message authentication and digital signatures also continued, focusing on reducing costs and formalizing security. More technologies were explored, such as entanglement swapping, multipartite entanglement and trusted third-party schemes. Security analyses narrowed down the results by clarifying limitations related to key reuse, composability and adversarial assumptions.
Types of quantum authentication Quantum authentication includes several related research areas that can be distinguished according to what is being authenticated: while some protocols authenticate the identity of a user or communicating party, others authenticate the integrity of transmitted quantum information or provide signature-like security. Although these areas share common cryptographic techniques, they address different security objectives and are often studied independently.
Quantum identity authentication Quantum identity authentication (QIA) aims to authenticate a user, device or other communicating party by exploiting quantum-mechanical properties. Unlike classical authentication, these protocols use quantum states during the authentication process, allowing eavesdropping or impersonation attempts to be detected through the disturbance introduced by quantum measurements. QIA protocols may provide one-way authentication, in which one party authenticates the other, or mutual authentication, where both parties verify each other's identity. Many schemes are inspired by classical challenge-response authentication, adapting them to quantum communication channels. They can also be classified as interactive or non-interactive depending on whether both parties must actively exchange information during the authentication phase.
Quantum message authentication In quantum message authentication (QMA), the aim is to authenticate the integrity and origin of quantum information sent over a quantum channel. Unlike classical message authentication, the message itself is a quantum state, which cannot generally be copied because of the no-cloning theorem. Quantum message authentication schemes therefore combine quantum encoding with a shared secret key, allowing the receiver to detect any modification or tampering of the transmitted state. If authentication fails, the receiver rejects the message rather than attempting to recover it. A foundational result by Barnum et al. showed that authentication of arbitrary quantum states necessarily implies their encryption, meaning that a protocol capable of detecting tampering must also conceal the quantum information from an adversary; the same work also argued that unrestricted digital signatures for unknown quantum states are impossible without additional assumptions.
Quantum digital signatures
Quantum digital signatures (QDS) are the quantum counterpart of classical digital signatures; they are intended to provide authenticity, integrity and non-repudiation while offering security based on quantum theory rather than computational assumptions. Most QDS protocols authenticate classical messages using quantum states distributed during a setup phase, instead of attempting to sign arbitrary quantum states directly: this distinguishes them from QMA.
… excerpt ends here. Continue reading the full article.






