← Latest papers
⚛️ quantum physics

Quantum Authenticated Key Expansion with Key Recycling

This paper presents and experimentally demonstrates a Quantum Authenticated Key Expansion (QAKE) protocol that uniquely integrates client authentication and key expansion into a single framework while enabling the full recycling of authentication keys, with security analyzed under an adapted AKE model and validated through experimental implementation.

Original authors: Wen Yu Kon, Jefferson Chu, Kevin Han Yong Loh, Obada Alia, Omar Amer, Marco Pistoia, Kaushik Chakraborty, Charles Lim

Published 2026-09-22
📖 5 min read🧠 Deep dive

Original authors: Wen Yu Kon, Jefferson Chu, Kevin Han Yong Loh, Obada Alia, Omar Amer, Marco Pistoia, Kaushik Chakraborty, Charles Lim

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

In the digital age, the safety of our online lives rests on two pillars: keeping our data private and proving who we are. When you access a bank account or a medical record from a remote location, the system must be certain you are the right person, and it must ensure that no one else can see what you are doing. For decades, the standard way to handle this has been to use mathematical puzzles to create secret codes. However, as computers become more powerful, especially with the rise of quantum computing, these old puzzles are becoming easier to solve, threatening to unlock our secrets. To counter this, scientists have developed a method called quantum key distribution, which uses the fundamental laws of physics to create unbreakable codes. The challenge has been that while this method creates the secret code, it usually requires a separate, traditional system to verify identities, creating a complex and often inefficient two-step process.

A team of researchers at JPMorgan Chase has now demonstrated a way to merge these two tasks into a single, streamlined process. They have created a new protocol that not only generates a secret key using quantum physics but also verifies the identity of the users at the same time. More importantly, their system solves a major practical headache: in previous methods, the secret keys used to verify identity had to be changed after every single use, a process that is slow and difficult to manage across large networks. This new approach allows those identity keys to be reused safely, provided the session was successful. By combining authentication and key generation, and by allowing the keys to be recycled, the researchers have made a system that is not only more secure but also significantly more efficient for real-world use.

The researchers built their system on the concept of quantum key distribution, where two parties, traditionally called Alice and Bob, exchange particles of light to create a shared secret. In a standard setup, they would first have to prove who they are using a separate digital handshake, and only then would they generate the secret key. The new protocol, which the team calls Quantum Authenticated Key Expansion, integrates these steps. Instead of a long series of back-and-forth messages to verify identity and then another series to generate the key, the system performs the verification checks only twice during the entire exchange. This drastically reduces the amount of data that needs to be sent and processed, saving time and resources.

A critical innovation in this work is the ability to recycle the authentication keys. In many current systems, once a secret key is used to verify a user's identity, it is discarded to prevent hackers from stealing it and using it later. This means that every time a user logs in, the system must update the keys on every server involved, a massive logistical burden. The new protocol uses a clever trick: if the session is successful, the system uses the newly generated secret data to "mask" the old identity keys, effectively hiding them from any potential eavesdropper. This allows the same keys to be used again in the next session without compromising security. This feature is particularly valuable for cloud services, where a user might access a server from many different locations, as it eliminates the need to constantly update keys across a vast network of servers.

To prove their idea worked, the team did not just rely on computer simulations; they built a physical system using commercial quantum hardware. They connected two devices, acting as the sender and receiver, through a fiber optic link that simulated a distance of 45 kilometers. The system sent billions of light pulses, and the researchers processed the data to see if they could successfully generate a secret key while verifying identities. The experiment was a success. Despite the natural loss of signal over the distance and a small amount of noise in the system, the protocol generated a secure key at a rate of about 10 to the power of negative 5. While this number might seem small, it is comparable to, and in some cases slightly better than, standard quantum key distribution systems that do not include this integrated authentication. The key finding is that the system maintained its security and efficiency even with the added complexity of verifying identities and reusing keys.

The researchers also analyzed the security of their method in great detail, showing that it holds up against various types of attacks. They proved that even if an attacker tries to interfere with the messages or steal information, the system will detect the tampering and refuse to generate a key. The security relies on the fact that the keys used for verification are protected by the high quality of the new secret data generated in each session. If the protocol fails, the system simply discards the attempt and updates its internal labels, ensuring that no secrets are leaked. This rigorous testing gives confidence that the method is robust enough for practical deployment.

This work represents a significant step forward in making quantum security practical for everyday use. By combining identity verification with key generation and allowing for the reuse of authentication keys, the researchers have removed some of the biggest barriers to adopting quantum technology in cloud services and remote access. The ability to run this protocol on existing commercial hardware suggests that it could be integrated into current networks without requiring a complete overhaul of infrastructure. As quantum computers continue to develop, having a system that is both secure and efficient will be essential for protecting the sensitive data that powers our modern world. The team's success in demonstrating this in a real-world setting moves the technology from theoretical possibility to a tangible solution for the future of digital privacy.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →