← Latest papers
🔬 physics

Security evaluation of quantum distance-bounding protocols via semidefinite programming

This paper evaluates the security of quantum distance-bounding protocols by isolating their fast phase and utilizing semidefinite programming to compute optimal one-round distance-fraud and mafia-fraud attack probabilities for discrete-variable systems, while also providing estimates for continuous-variable scenarios.

Original authors: Kevin Bogner, Aysajan Abidin, Dave Singelée, Bart Preneel

Published 2026-09-15
📖 5 min read🧠 Deep dive

Original authors: Kevin Bogner, Aysajan Abidin, Dave Singelée, Bart Preneel

Original paper licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine a world where your car unlocks only when your key fob is physically right next to you, and a thief cannot trick the system by relaying signals from a fob that is actually miles away. This is the promise of distance-bounding protocols: digital systems that verify not just that you have the right secret code, but that you are standing exactly where you claim to be. In the classical world, this relies on measuring how long a radio signal takes to bounce back. But as technology advances, scientists are moving these checks into the quantum realm, using particles of light to create unbreakable timing guarantees. The challenge, however, has been that every new quantum design behaves differently, making it nearly impossible to compare their security fairly. One design might be strong against a specific type of trick, while another fails against a different one, leaving researchers without a common yardstick to judge which systems are truly safe.

A team of researchers at KU Leuven in Belgium has now solved this comparison problem by creating a universal testing ground for these quantum distance checks. They focused on the most critical moment in these protocols: the "fast phase," a split-second exchange where the prover must answer a challenge before light could possibly travel from a distant location. By isolating this single round of communication, the team developed a mathematical method to calculate the absolute best possible success rate for an attacker trying to deceive. Instead of guessing or simulating specific tricks, they used a powerful optimization tool called semidefinite programming to map out every single strategy an attacker could possibly use, ensuring that no potential loophole was missed. This approach allowed them to determine the exact security limits for several leading quantum protocols, revealing which ones hold up and which ones are more vulnerable than previously thought.

The researchers applied this method to four distinct quantum protocols, three of which use individual particles of light and one that uses continuous waves of light. For the particle-based systems, the math provided exact, unshakeable answers. They found that for the most common type of deception, where a dishonest user tries to pretend they are closer than they are, the success rate is exactly fifty percent across all the particle-based protocols they studied. This means that in a single round, a distant cheater has no better chance than flipping a coin. However, the story changes for the protocol using continuous waves of light, where the success rate for this same type of deception drops significantly to about thirty-six percent. The story also changes when looking at a more complex attack, where a criminal team works together—one standing near the verifier and another near the honest user—to relay information. In this scenario, the protocols performed very differently. The team discovered that the most widely studied protocol, known as QDB 2019, is actually less secure than previously believed, with a new analysis showing an attacker could succeed about ninety percent of the time. Another protocol, called Mutual QDB, also proved weaker than earlier estimates, with a success rate for attackers rising to seventy-five percent.

Perhaps the most significant finding was for two protocols that had never been rigorously tested in this way before. For a protocol based on the famous E91 entanglement design, the researchers calculated the first-ever security numbers, finding that an attacker could succeed roughly ninety-three percent of the time in the mafia-style fraud scenario. Similarly, for a protocol using continuous waves of light, they provided the first estimates, showing a success rate of about ninety-one percent for the same type of attack. These numbers are not just theoretical guesses; for the particle-based protocols, the team generated mathematical certificates that prove no other strategy could possibly do better. It is a bit like finding the absolute highest peak in a mountain range: once you have the map and the proof, you know for certain that no one can climb higher.

The study also clarified why some older designs are not included in this comparison. One early protocol relied on a final digital signature to prove authenticity, but when the researchers stripped away that signature to test the timing mechanism alone, the system collapsed completely, allowing an attacker to succeed one hundred percent of the time. This confirmed a vital principle: the timing mechanism itself must be strong enough to authenticate the user, not just rely on a later check. The researchers emphasized that these results apply to a single round of communication. In a real-world system with many rounds, the security would be even higher, but knowing the exact limit of a single round is the essential first step to building a secure whole. By providing these precise, comparable numbers, the team has given engineers a clear way to choose the most robust protocols for the future of secure, location-aware technology.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →