This section first analyzes resource overheads of the proposed scheme and YKLY’2015, and then simulates the attacks on the proposed scheme.
5.1. Resource Overhead Analysis of the Proposed Scheme and YKLY’2015
To assess the practical cost of the security guarantees established in
Section 4.3, we now analyze the resource consumption of the proposed scheme. For a single quantum message, all core operations of the proposed scheme maintain constant-level computational complexity. In this subsection, we divide the protocol execution into the initialization stage (I1–I2) and the signal interaction stage (S1–S7) to conduct a comprehensive resource overhead analysis, covering key consumption, qubit overhead, quantum communication overhead, classical communication overhead, and computational complexity of each step.
Step (I1): This step completes QKD key generation and distribution, with a total key consumption of bits per protocol execution. The key (16 bits) is divided into three segments: (4 bits) for encrypting , (4 bits) for encrypting the Bell state particle pair, and (8 bits) for encrypting . The key (24 bits) is divided into four segments: (4 bits) for encrypting the Bell state particle pair, (8 bits) for encrypting , (4 bits) for encrypting the Bell state particle pair in the verification phase, and (8 bits) for encrypting . Each segment is used exactly once and is never reused. All keys are freshly generated via QKD for each protocol execution. The key generation involves only fixed quantum operations per key bit, with an overall computational complexity of .
Step (I2): No additional secret keys are consumed in this step. Bell states are prepared and serve as persistent entanglement resources, occupying static qubits. Among them, Bell states are shared between Alice and Bob for Step (S2), Bell states are shared between Bob and Trent for Step (S4), and Bell states are shared between Trent and Bob for Step (S6). A total of qubits are transmitted from Trent to Alice and Bob during entanglement distribution. For the Alice–Bob Bell pairs, both particles leave Trent, giving transmitted qubits. For the Bob–Trent Bell pairs used in Step (S4), one particle is sent to Bob while the other is retained by Trent, giving transmitted qubits. For the Bob–Trent Bell pairs used in Step (S6), one particle is sent to Bob while the other is retained by Trent, giving transmitted qubits. These Bell states must be preserved until their respective teleportation steps. Let denote the one-way classical communication latency between any two parties, and let denote the time for local quantum operations and measurements. Under a fully serial schedule for all physical-copy teleportations, the total protocol execution time, which determines the required storage duration, is . This latency expression corresponds to serial processing of the physical copies; parallel or pipelined execution can reduce the number of sequential communication intervals. For metropolitan-scale distances on the order of tens of kilometers, the serial estimate places on the order of milliseconds when is on the order of tens of microseconds in optical fiber. This is well within the coherence times demonstrated by current quantum memory technologies. For longer-distance applications, the required storage time increases accordingly, and practical deployment would require continued progress in coherence-preserving technologies.
Step (S1): No key resources are consumed. dynamic qubits are occupied for quantum message storage, realized as copies of , copies of , and copies of . There is no quantum or classical communication transmission overhead. The operation includes single-qubit state preparation for all physical copies, with a computational complexity of .
Step (S2): In actual execution, this step is repeated for copies of , consuming Bell pairs shared between Alice and Bob, and performing Bell measurements. No classical bits are transmitted in this step. The computational complexity is .
Step (S3): Partial segments of are consumed, including 4-bit , 4-bit , and 8-bit . No new persistent qubits are added. Alice sends copies of to Bob and copies of to Trent. In addition, for each of the copies of , Alice sends one encrypted particle pair, consisting of two qubits, to Trent, giving additional qubits. The total quantum communication in this step is therefore qubits.
Step (S4): Partial segments of are consumed, including and . In actual execution, this step is repeated for received copies. A total of encrypted Bell particle qubits are transmitted, accompanied by encrypted parameters , each transmitted as a two-qubit quantum state, adding qubits. The total quantum communication in this step is therefore qubits. The core operations are Bell measurement and QOTP encryption, and the computational complexity is .
Step (S5): No new key segments and persistent qubits are consumed. There is no quantum and classical communication overhead. In actual execution, Trent recovers copies of . Among them, copies are used in the swap test with , and the remaining copies are retained for Step (S6). The main operations are quantum state recovery and independent swap tests, with a computational complexity of .
Step (S6): It consumes partial segments of , including 4-bit and 8-bit . No extra persistent qubits are introduced. A total of encrypted Bell particle qubits are transmitted, accompanied by encrypted parameters , each transmitted as a two-qubit quantum state, adding qubits. The total quantum communication in this step is therefore qubits. The step integrates Bell measurement and QOTP encryption, with an overall computational complexity of .
Step (S7): No key resources and persistent qubits are consumed, with zero communication overhead of quantum and classical channels. In actual execution, Bob receives copies of . He uses copies in the swap test with and retains the remaining one copy as the signed quantum message. The core operations are Pauli correction and independent swap tests, and the computational complexity is .
As above, the stepwise resource overhead summary of the proposed scheme is presented in
Table 2. By the same approach, we derive the resource overhead of the Grover-based scheme (i.e., YKLY’2015), as listed in
Table 3.
The proposed scheme differs architecturally from YKLY’2015 in several respects. The proposed scheme introduces persistent static qubits and consumes more key material ( bits per execution vs. 4 bits in YKLY’2015). These additional costs are incurred in exchange for stronger security guarantees. Unlike YKLY’2015, which is vulnerable to man-in-the-middle attacks that enable Alice’s disavowal and Bob’s forgery, the proposed scheme achieves unforgeability and non-repudiation through the combined use of strengthened QOTP encryption and arbitrated teleportation-based verification. The higher key consumption reflects the additional encryption and authentication steps required to protect against these attacks. Furthermore, quantum teleportation is adopted to reuse quantum channels, reducing the need for repeated quantum state transmissions.
The above analysis considers a single-qubit message. For a general n-qubit message , the resource requirements scale as follows.
Key consumption. Each qubit of the message requires independent encryption via the strengthened QOTP, which consumes a constant number of key bits per qubit. Specifically, for an n-qubit message, Alice must encrypt physical copies of the message and the Bell state particle pairs used in teleportation. The parameters each become -bit classical values for an n-qubit message. There are such parameters in total: values of , values of , and values of . Their encryption cost therefore scales as . The total key consumption therefore scales as , with a dominant contribution coming from the QOTP encryption of the n-qubit message copies.
Static qubits. Each teleportation of an n-qubit message consumes n Bell states. The protocol involves rounds of teleportation, requiring Bell states in total. Each Bell state occupies 2 qubits, yielding static qubits. The total number of static qubits therefore scales as .
Dynamic qubits. Alice prepares physical copies of the n-qubit message, occupying dynamic qubits. During teleportation, each message qubit temporarily interacts with one half of a Bell state, but no additional persistent storage is required beyond the message copies themselves. The total dynamic qubit requirement is therefore .
Quantum communication. In Step (S3), Alice transmits the message group ( qubits) to Bob and the encrypted message group ( qubits) to Trent. In addition, the Bell state particle pairs transmitted in Steps (S3), (S4), and (S6) scale as in total, since these steps involve , , and teleportations, respectively. The total quantum communication overhead is therefore , dominated by the transmission of the message groups.
Classical communication. The QKD initialization step (I1) requires classical bits for key distribution, as the total key length scales with . All encrypted parameters are transmitted as quantum states and are therefore counted in the quantum communication overhead rather than the classical communication overhead. The total classical communication overhead is therefore , dominated by QKD key distribution.
Computational complexity. The dominant operations are Bell measurements, QOTP encryption and decryption, and swap tests. For an n-qubit message, Bell measurements are performed qubit-wise on each of the teleportation rounds, requiring operations. The QOTP encryption applies Pauli gates independently to each qubit of the physical copies, scaling as . Each swap test compares n-qubit registers using n controlled-SWAP gates, and the test is repeated times per comparison. Two comparisons are performed (in Steps S5 and S7), yielding overall. The total computational complexity is therefore .
In summary, for an
n-qubit message, key consumption, qubit overhead, communication requirements, and computational complexity all scale as
. This scaling remains linear in the message length
n, which is a natural consequence of processing each qubit individually.
Table 4 summarizes the asymptotic resource scaling. Since
is determined by the required security level and
is an application-level threshold chosen according to the required verification strictness, both are fixed once the security level and the application scenario are specified. Consequently, all resource requirements remain linear in the message length
n.
5.2. Attack Simulations of the Proposed Scheme
To complement the formal security analysis of
Section 4.3, we now analyze the strongest attacks that a dishonest Alice or Bob can mount against the proposed scheme, and illustrate their behavior through numerical modeling. By contrast, the vulnerabilities of YKLY’2015 follow directly from its protocol structure and require no simulation to verify.
5.2.1. Alice’s Attack Simulation
For Alice’s repudiation, we construct the strongest possible attack, in which Alice deviates maximally in every step under her control.
Alice’s attack description. In Step (S3), Alice deviates from the protocol by sending a potentially forged state to Bob and to Trent, where and may differ from the honest copies. Simultaneously, she sends a forged particle pair with state and to Trent, where may differ from the true .
Verification phase Analysis. In Step (S5), Trent decrypts and verifies the received particles. We analyze three possible scenarios depending on Bob’s behavior, since Alice does not control whether Bob is honest.
Scenario 1: Bob is honest. Bob follows the protocol (
,
). Trent measures
from Alice’s particle pair and compares it with the decrypted
. If they match, Trent applies
and
to the state
. The recovered state is
(up to a global phase). The swap test between
and
yields the condition
This corresponds to the stronger malicious-signing adversary considered in the non-repudiation analysis of
Section 4.3, where Alice is allowed to deviate during signature generation.
Scenario 2: Bob is dishonest, but his attack prevents the protocol from proceeding. Bob applies or sends . If , the fidelity F between the state recovered by Trent and the reference state satisfies , and the swap test detects the mismatch with probability . Unless Bob’s deviation is chosen such that , this probability is close to 1, causing the protocol to abort. In this case, Bob has not accepted any signature, so Alice has nothing to repudiate. Her attack fails trivially.
Scenario 3: Bob is dishonest, but his attack inadvertently assists Alice. Bob applies
and/or sends
, but the combination happens to satisfy
. In this case, the swap test passes and the protocol proceeds despite Bob’s deviation.
Table 5 shows the required
G for each pair
. For a given pair
, Bob’s deviation
G is chosen randomly from
, and exactly one of these four choices satisfies
. Hence, if Bob chooses
G uniformly at random, the probability that his deviation inadvertently allows the protocol to proceed is
. Even in this scenario, once the protocol proceeds to Step (S7) and Bob accepts, the traceability argument of Scenario 1 applies, and Trent can still link the accepted message to Alice.
In practical systems, non-attack factors such as channel noise, device imperfections, and environmental disturbances introduce an additional baseline error rate, denoted by
. In Scenario 1 (Bob honest), the protocol proceeds deterministically from Alice’s perspective, and the only source of error is the finite failure probability
of the swap test, which is bounded by
and reduces to
when
. In Scenario 3 (Bob inadvertently assists Alice), the protocol proceeds with ideal probability
as shown above. Taking the worst-case view that Scenario 3 occurs, the total probability that Trent observes an erroneous acceptance is modeled as
, where the
term accounts for the probability that Bob’s random deviation accidentally satisfies
, and
is the baseline error rate due to physical noise, treated as an independent additive contribution in this phenomenological model. A detection threshold
is set: the transmission is accepted if the observed bit-error rate
, and rejected otherwise. The probability that Alice’s attack succeeds (remains undetected) is
For
n transmitted quantum bits, let the observed number of erroneous bits be
k. Then
k follows a binomial distribution
, and the observed bit-error rate is
. Hence,
The security requirements is
. The condition
ensures that the bit-error rate induced by Alice’s attack exceeds the detection threshold, meaning the attack leaves a detectable trace and is therefore likely to be rejected by the system. Consequently, the attack success probability
represents the probability that the system accepts the transmission despite an actual attack being present, i.e., the false negative rate. By Chernoff’s bound for the binomial distribution, for
,
For clarity, the upper bound on Alice’s attack success probability as a function of the number of quantum bits
n is shown in
Figure 5. We adopt the Monte-Carlo method to conduct numerical simulations. For each value of qubit number
n, we perform 20,000 random sampling experiments obeying binomial distribution
. We judge that the attack succeeds when
with
. It can be seen that the simulation results fit well with the theoretical binomial expression, which confirms the consistency of the numerical implementation with the probabilistic model. The MATLAB R2024a code implementing the Monte-Carlo simulation is given in the
Supplementary Material.
Finally, this constructed attack represents the strongest possible repudiation attempt, in which Alice deviates maximally in every step under her control. The analysis above covers three scenarios. If Bob is honest (Scenario 1), the protocol proceeds and Trent can trace the accepted message to Alice. If Bob’s deviation prevents the protocol from proceeding (Scenario 2), Alice has no accepted signature to repudiate. If Bob’s deviation inadvertently assists Alice (Scenario 3, probability 1/4), the protocol proceeds and Trent’s traceability still holds. Therefore, in all possible scenarios, Alice cannot successfully repudiate a signature that Bob has accepted.
5.2.2. Bob’s Attack Simulation
We now analyze Bob’s forgery attack under the assumption that Alice follows the protocol honestly. This corresponds to the standard unforgeability game in
Section 4.3. If Alice were also dishonest, the analysis of Scenario 2 and Scenario 3 in the previous subsection applies symmetrically: Alice’s deviation would either cause the protocol to abort or, with small probability, inadvertently assist Bob. In either case, Bob’s forgery success remains bounded by the same arguments.
Bob’s attack description. Bob has two attack opportunities. In the first stage (during protocol execution, Step (S3)–(S4)), Bob possesses and . He may apply a non-identity operation G on before teleporting it to Trent in Step (S4), or modify the plaintext copy . In the second stage (after protocol completion, Step (S7)), Bob holds and , and may attempt to produce a forged signature.
Verification phase Analysis. For the first stage, if Bob applies , the state reaching Trent becomes . After Trent applies and in Step (S5), the recovered state is (up to a global phase). Trent compares this with via the swap test. Since was encrypted by Alice with , Bob cannot alter it. The swap test detects the mismatch with probability at least , where is the fidelity between the tampered state and the reference state. For orthogonal states (), this reduces to . If Bob modifies instead, the swap test in Step (S7) detects the mismatch with the same probability guarantee.
For the second stage, after recovering and verifying it against , Bob already holds the valid message. To forge a different message, Bob would need to produce a new and corresponding evidence that Trent accepts as originating from Alice. However, Trent retains the encrypted record and the particle pairs from both Alice and Bob, all protected by that Bob does not possess. Bob’s knowledge of and provides no advantage, as these are random Bell measurement outcomes independent of the message content.
In summary, the above analysis shows that neither opportunity allows Bob to forge Alice’s signature with non-negligible probability. This is consistent with the formal unforgeability proof in
Section 4.3.
5.3. Numerical Simulations
To complement the analytical security discussion, we performed numerical and hardware evaluations of the verification model. Reference implementations are provided in the
Supplementary Material. The numerical simulations and hardware-evaluation workflows were implemented in Python 3.12.5 using Qiskit 2.0.0, qiskit-aer 0.17.0, qiskit-ibm-runtime 0.40, NumPy 2.1.1, pandas 3.0.2, and Matplotlib 3.10.1. IBM Quantum hardware jobs were executed through Qiskit Runtime using QiskitRuntimeService and SamplerV2.
Figure 6 summarizes the batch-mode performance and resource overhead.
Figure 6a shows the detection probability as a function of the number of verification instances
m for fidelity values
F from 0 to 0.99. The analytical curves agree with Monte Carlo simulations across the tested range. For small and moderate
F, the detection probability increases rapidly with
m; however, when
F approaches unity, such as
, the detection rate remains limited even at
, reflecting the inherent difficulty of distinguishing near-identical states.
Figure 6b shows that as the batch parameter
grows, the acceptance probabilities of the modeled tampering, impersonation, record-tampering, and replay-mismatch scenarios generally decrease, while the honest acceptance probability remains high. Alice scenario 1 remains statistically close to honest execution in this consistency-only diagnostic. The suppression is quantitative rather than absolute: the modeled attack-acceptance probabilities become small but do not necessarily reach zero for finite batch sizes.
Figure 6c compares the exact binomial probability, the seeded Monte Carlo estimate, and the Chernoff upper bound for the separate statistical model of Alice’s repudiation behavior.
Figure 6d quantifies the cumulative physical-resource scaling versus the number of message qubits for a fixed batch parameter
, under the stated resource-counting definitions.
We note three limitations of the numerical evaluation. First, the
detection formula applies only to orthogonal inputs with
; for high-fidelity cases such as
, the detection probability grows much more slowly with
m, and this should not be interpreted as a general closed-form detection law. Second, the batch-level curves are evaluated in the physical-copy batch model under a simplified state-level noise model, in which each relevant state is subjected to a fixed noise level. This model is not a device-level noise simulation and does not correspond to independent protocol instances. Under nonzero noise, even the honest acceptance probability decreases with
, because every selected comparison must pass. Third, the binomial curve for Alice’s repudiation probability in
Figure 6c is a statistical illustration under an independent binomial model; it does not by itself establish non-repudiation, which relies on the full protocol records and the adversarial analysis of
Section 4.3.
Figure 7 presents circuit-level hardware evaluation results obtained from IBM Quantum devices and local simulations.
Figure 7a,b show that quantum teleportation and the strengthened-QOTP roundtrip achieve correct-output probabilities mostly above 0.94 across different input states and keys, indicating basic feasibility despite noticeable hardware noise.
Figure 7c reveals a significant gap between ideal/simulated and real-hardware Swap-test detection, highlighting the sensitivity of this operation to current-device noise.
Figure 7d further shows that an optimized composed circuit candidate with batch parameter
performs acceptably on hardware, albeit below simulator levels. These hardware runs are circuit-level benchmarks of the protocol’s core primitives; they do not constitute a full implementation of the complete
-Bell-pair physical-copy batch protocol. In particular, the Swap-test gap between simulation and hardware indicates that direct deployment of the full batch protocol would require either noise suppression or additional error mitigation, and the present experiments should not be taken as an end-to-end hardware demonstration.
Overall, these evaluations show that the verification behavior is consistent with the fidelity-based analysis for the tested instances, that the batch structure and resource accounting follow the stated numerical model, and that the selected circuit-level quantum operations can be executed on current noisy quantum devices at a small scale.