Quantum-Resistant Quantum Teleportation Xin Jin,1, ∗ Nitish Kumar Chandra,2, ∗ Mohadeseh Azari,2 Jinglei Cheng,1 Zilin Shen,3 Kaushik P. Seshadreesan,2 and Junyu Liu1, † 1 Department of Computer Science, University of Pittsburgh, Pittsburgh, Pennsylvania 15260, USA 2 Department of Informatics and Networked Systems, University of Pittsburgh, Pittsburgh, Pennsylvania 15260, USA 3 Purdue University, West Lafayette, Indiana 47907, USA
arXiv:2604.16101v1 [quant-ph] 17 Apr 2026
(Dated: April 20, 2026) Quantum teleportation requires classical control bits transmitted via a classical communication channel, which are vulnerable to quantum adversaries. We propose a quantum-resistant quantum teleportation (QRQT) framework protected by post-quantum cryptography (PQC), with a comprehensive security analysis. By applying PQC to protect the classical control bits, QRQT renders quantum teleportation fully quantum-resistant and eliminates the classical attack surface. Our analysis reveals that quantum memory is a hidden bottleneck linking physical and computational security. Its finite coherence time simultaneously limits the communication distance, constrains the tolerable PQC overhead, and restricts the adversary’s attack window. Under realistic parameters (1 ms coherence, fiber-optic propagation), the maximum secure teleportation distance ranges from ∼191 km (FrodoKEM-1344) to ∼199 km (Kyber512), quantifying the security-distance tradeoff imposed by the selected PQC scheme. We show a joint classical–quantum attack probability 𝑃 joint (𝑡) exhibits a non-monotonic, Bell-shaped profile due to the opposing time dependencies of classical cryptanalysis and quantum decoherence, thereby establishing a bounded optimal attack window after which the probability of adversarial success decays exponentially. Complementing the attack probability analysis we further analyze how leakage of the classical correction bits affects the security of quantum teleportation, where confidentiality relies on keeping these bits secret until the receiver completes the recovery. To capture realistic patterns of time dependent exposure, we consider four stochastic leakage scenarios: independent exponential, sequential, burst, and correlated leakage, when the eavesdropper manages to compromise the receiver’s quantum system. We also account for decoherence in the entangled resource by modeling amplitude damping on the receiver’s half of the shared Bell pair. For each scenario, we derive closed form expressions for the average Holevo quantity and the average teleportation fidelity as functions of time. Based on the Holevo quantity, our information theoretic analysis provides measurement independent upper bounds on the information extractable by an adversary, which can help assess leakage risks in quantum communication and assist in developing protocols that are robust against such attacks.
I.
INTRODUCTION
Quantum teleportation is a core communication primitive for quantum networks, enabling quantum states to be transferred, coordinated, and processed across remote nodes [1, 2]. Introduced by Bennett et al. in 1993, teleportation enables the transfer of an unknown quantum state using shared entanglement and classical communication, without direct physical transmission of the quantum system itself [3]. Teleportation fundamentally builds block for long distance entanglement distribution, quantum repeater protocols, and distributed quantum computing architectures [4–9]. As quantum networking advances from isolated demonstrations to scalable systems, teleportation should be viewed not merely as a canonical protocol of quantum information theory, but as an operational primitive whose security is essential to quantum network infrastructure [10–13]. While shared entanglement supplies the quantum resource for teleportation, state transfer is completed only when the associated classical information reaches the receiver. Alice (sender) performs a joint measurement on the unknown input qubit and her share of an entangled pair, while Bob (receiver) holds the other share. This measurement produces two classical outcomes that must be communicated to Bob [14]. Bob
∗ These two authors contributed equally to this work. † [email protected]
then uses this information to determine the corresponding Pauli correction to recover the original state. The classical channel therefore carries the measurement outcomes that determine the recovery operation at the receiver. Any delay, corruption, or compromise of this classical information directly affects the completion of the protocol, making the correction channel a critical part of both the functionality and the security of quantum teleportation [15, 16]. This reliance on classical information introduces a fundamental security asymmetry: while the quantum correlations are established without transmitting information, its successful and trustworthy completion also depends on a classical channel that can be vulnerable [17, 18]. In practice, the entangled quantum channel is often treated as the main object of protection, whereas the classical correction channel is commonly assumed to be authenticated or secured using conventional public key cryptography [19]. Such assumptions become problematic in the presence of quantum capable adversaries, because widely used public key schemes such as Rivest-Shamir-Adleman (RSA) [20] and the Digital Signature Algorithm (DSA) [21] derive their security from integer factorization and the discrete logarithm problem, both are vulnerable to Shor’s algorithm [22]. The classical correction channel thus becomes a natural attack surface: it carries the information required to complete state recovery, its protection is commonly delegated to public-key schemes that are broken by Shor’s algorithm. Protecting only the quantum states is therefore insufficient, securing teleportation end-to-
2 end requires quantum-resistant authentication of the classical correction path as well [23]. Several existing approaches can be used to authenticate or secure the classical correction channel, but they can be operationally cumbersome or infrastructure intensive in scalable teleportation networks. Wegman-Carter authentication [24] provides information theoretic message authentication, it requires pre-shared secret keys whose distribution and periodic refresh become increasingly burdensome as the number of nodes and teleportation rounds grows. Quantum key distribution (QKD), a method for establishing shared secret keys using quantum states, offers another possibility for securing the classical channel [25]. However, it still relies on an initially authenticated classical channel, and in practice it requires each protected link to be paired with dedicated QKD hardware and supporting infrastructure [26, 27]. Quantum digital signatures provide an alternative approach [28], but their practical deployment remains constrained by limitations in transmission distance, signature overhead, and multi-party scalability. As a result, a practical gap remains between solutions that provide strong security but require substantial infrastructure and coordination overhead, and those that would offer the scalable public-key functionality needed for large-scale quantum communication systems [29, 30]. Post quantum cryptography (PQC) provides a practical response to the problem of securing the classical correction channel while preserving the deployment advantages of public key cryptography. Since launching its PQC standardization effort in 2016, NIST has advanced PQC from a research direction to a deployable standards framework [31]. In 2022, NIST selected CRYSTALS Kyber for key encapsulation and CRYSTALS Dilithium and SPHINCS+ among its first post quantum digital signature candidates, and in 2024 finalized FIPS 203, FIPS 204, and FIPS 205, which specify algorithms derived from these schemes [32, 33]. Kyber and Dilithium are lattice based constructions built from module lattice assumptions related to Learning With Errors (LWE) and Short Integer Solution, while SPHINCS+ provides algorithmic diversity through a stateless hash based design [34, 35]. This progress makes it timely to revisit teleportation security from a post quantum perspective, particularly for the classical correction channel, where public key protection is especially well suited to networked settings because it can secure protocol critical classical information without requiring pairwise pre-shared secret keys or dedicated quantum security infrastructure [26, 36], while still relying on standard public key management and authentication mechanisms. Building on recent progress in post quantum cryptography, we propose the Quantum-Resistant Quantum Teleportation (QRQT) framework, which applies PQC to the classical control channel of quantum teleportation (See Fig. 1). QRQT leaves the underlying teleportation protocol and entanglement resource unchanged, but protects the Bell measurement outcomes that must be delivered to the receiver for state reconstruction. It therefore secures the protocol critical classical correction path, ensuring that the information required for Pauli correction remains protected against quantum enabled adversaries.
Integrating PQC into teleportation is not a purely cryptographic substitution. The use of PQC-protected classical communication introduces additional processing and transmission delay before Bob can obtain the measurement outcomes and apply the required Pauli correction. During this interval, the receiver’s qubit must remain stored in quantum memory, so the success of the protocol is also constrained by coherence time [37–40]. The PQC latency therefore translates into a physical resource constraint: the longer the classical correction path takes to complete, the greater the risk that decoherence will destroy the stored quantum state before recovery is possible. Computational security on the classical channel thus becomes directly coupled to physical reliability on the quantum side. We consider an adversary whose goal is to intercept and recover the transmitted quantum state, requiring simultaneous access to both the classical correction outcomes and the stored quantum state. This creates a time-dependent joint constraint on the adversary: a longer transmission window provides more time to break the PQC-authenticated classical channel, but also increases the probability that the quantum state has decohered and is no longer recoverable. Conversely, a shorter window preserves the quantum state but limits the time available for classical cryptanalysis. Successful interception therefore requires the adversary to compromise both channels within the same coherence window. To assess QRQT security comprehensively, we develop a hybrid threat model that jointly captures adversarial behavior on both the classical and quantum channels. On the classical side, we model attack success probabilities against LWE-based cryptosystems underlying standardized post-quantum encryption schemes. On the quantum side, we consider an active interception strategy in which an adversary attempts to substitute, extract, or temporarily retain entangled qubits intended for the receiver through a SWAP-type interaction; related interception and entanglement-tampering scenarios have been studied in the contexts of unreliable entanglement assistance, malicious entanglement in quantum networks, and active eavesdropping on quantum communication channels [41–43]. This formulation enables us to quantify attack success under realistic temporal constraints, thereby capturing the interplay between PQC-induced latency and decoherence in finite quantum memory. To analyze this coupled security problem, we use two complementary frameworks. The first is an explicit attack analysis that captures adversarial behavior on both the classical and quantum channels, allowing us to quantify attack success probabilities under finite computation time, communication latency, and quantum memory constraints. The second component is an information theoretic analysis based on the Holevo quantity, which quantifies the information an adversary can extract from partial correction data together with access to Bob’s quantum state. Together, the two components allow us to distinguish between concrete protocol compromise and residual information exposure, thereby providing a more complete characterization of QRQT security. The main contributions of this work are as follows: • We propose the Quantum-Resistant Quantum Telepor-
3 tation (QRQT) framework (See Fig. 2), which protects the classical correction channel of quantum teleportation using post-quantum cryptography, and identify the resulting joint security tradeoff between cryptographic protection and quantum memory constraints. Specifically, because the receiver must store the entangled qubit while awaiting PQC-protected correction bits, communication distance, tolerable cryptographic overhead, and the adversary’s attack window become fundamentally coupled. This contribution highlights that the classical attack success probability grows with computation time, whereas the quantum interception probability decays as the entangled state decoheres, giving rise to a joint security landscape that cannot be captured by analyzing either channel in isolation. • If decoherence occurs before the correction bits are received, the original quantum state cannot be faithfully reconstructed, undermining both fidelity and practical feasibility. The interaction between cryptographic latency and quantum coherence remains largely unexplored, raising a fundamental question: under what temporal and physical conditions can QRQT remain both secure and operational? Motivated by this constraint, we quantitatively analyze the feasibility of QRQT by evaluating multiple standardized PQC algorithms and estimating the minimum coherence time required for successful state reconstruction across varying communication distances and security parameters.
and discusses future directions for integrating PQC protected teleportation into scalable quantum networks.
II.
PRELIMINARIES
In this section, we review the fundamental concepts used throughout the paper. We first review the quantum teleportation protocol, examine how noise degrades quantum information through the amplitude damping channel, discuss the role of Pauli corrections as an encryption mechanism, and introduce the von Neumann entropy and the Holevo quantity used in the security analysis. We further discuss the lattice-based cryptographic hardness assumption underlying post-quantum security and the teleportation fidelity metric.
A.
Quantum Teleportation Protocol
Quantum teleportation [3, 14] is a fundamental protocol in quantum information processing that enables the transfer of an arbitrary unknown quantum state between two spatially separated parties using shared entanglement and classical communication (see Fig. 1). The protocol relies on two essential resources: • a pre-shared entangled state, typically a maximally entangled Bell pair, and • a classical communication channel used to convey measurement outcomes.
• We formulate a hybrid threat model that jointly captures lattice-based attacks on the classical channel and SWAP-based interception on the quantum channel, and characterize the resulting time-dependent joint attack probability.
Let the input state to be teleported be a single qubit |𝜓 ⟩ = 𝛼 |0⟩ + 𝛽 |1⟩ , with |𝛼 | 2 + |𝛽 | 2 = 1. The teleportation procedure proceeds as follows:
• We further present an information theoretic analysis based on the Holevo bound and introduce four physically motivated stochastic leakage models, namely independent, sequential, burst, and correlated leakage, that capture common qualitative patterns of information exposure arising in statistical failure and communication error processes. This framework enables us to quantify the residual information available to an adversary and to characterize how partial, delayed, and correlated leakage lead to time dependent degradation of the teleported quantum state. The remainder of the paper is organized as follows. Section II reviews the background theory relevant to this work. Sections III and IV present the QRQT framework, analyze memory lifetime limitations, and develop the hybrid threat model along with the corresponding attack success probability. Sections V, VI, and VII present an information theoretic analysis of the teleportation protocol under an amplitude damping noise model for different scenarios, with particular focus on the Holevo quantity, the fidelity of the quantum state, and their time dependent behavior under four stochastic models of classical leakage. Finally, Section VIII concludes the paper
1. Alice performs a joint Bell basis measurement on the input qubit and her half of the shared entangled pair, projecting the combined system onto one of four Bell states. 2. The measurement outcome is encoded into two classical bits (𝑚 1, 𝑚 2 ) ∈ {0, 1}2 . (Throughout this paper, 𝑚 1 ≡ 𝑀1 and 𝑚 2 ≡ 𝑀2 . These symbols denote the same classical bits and are used interchangeably in some sections for notational convenience and clarity.) 3. Alice transmits these classical bits to Bob over a classical communication channel. 4. Upon receiving the measurement outcomes, Bob applies the conditional Pauli operation 𝑈𝑚1𝑚2 = 𝑍 𝑚2 𝑋 𝑚1 to his qubit, thereby recovering the original state |𝜓 ⟩. In the ideal setting, assuming perfect entanglement, noiseless quantum operations, and error free classical communication, the teleportation protocol reconstructs the input state at Bob’s location with unit fidelity.
4
𝑀2
PQC protected classical channel
Sends state |𝜓 ⟩
𝐻
Alice
Potential eavesdropper access
√ |𝛽 00 ⟩ = ( |00⟩ + |11⟩ )/ 2
𝑀1
Pre shared Bell pair 𝑋 𝑀1
𝑍 𝑀2
Recovered state |𝜓 ⟩
Bob Solid line = quantum system Blue dashed line = classical bits (𝑀1 , 𝑀2 ) Blue shaded region = PQC protected classical channel
FIG. 1: Quantum Resistant Quantum Teleportation (QRQT) framework. Alice performs a Bell state measurement on her input qubit |𝜓 ⟩ and her half of the Bell pair |𝛽 00 ⟩ = √1 (|00⟩ + |11⟩). A cnot gate followed by a Hadamard gate and computational basis measurements 2 yield two classical outcomes 𝑀1 and 𝑀2 . These control bits are sent to Bob through a PQC protected classical channel, while Bob retains his entangled qubit in quantum memory. Upon receiving the bits, Bob applies Pauli corrections 𝑋 𝑀1 and 𝑍 𝑀2 to recover |𝜓 ⟩.
(a) Traditional Quantum Teleportation
(b) QRQT Framework
(c) Joint Threat Model
(d) Information Theoretic Analysis
FIG. 2: Overview of the QRQT framework. (a) Standard teleportation with classical public-key protection, vulnerable to Shor’s algorithm. (b) QRQT replaces the classical link with PQC; Bob holds the qubit in quantum memory during PQC processing. (c) Hybrid threat model combining lattice attacks on the classical channel and SWAP interception on the quantum channel. (d) Holevo-bound analysis of information leakage under decoherence and classical key compromise.
5 B.
Quantum Noise and the Amplitude Damping Channel
In realistic settings, quantum systems inevitably interact with their surrounding environment, leading to decoherence and the loss of quantum information. Such noise processes are mathematically described by completely positive trace preserving maps, which are commonly represented using the Kraus operator formalism [14]. A particularly relevant noise model for many physical qubit implementations is the amplitude damping channel, which captures energy relaxation mechanisms such as spontaneous emission in optical platforms or energy decay in superconducting qubits [44, 45]. The amplitude damping channel acting on a single qubit is characterized by the Kraus operators √ 1 √ 0 0 𝛾 , 𝐸1 = , (1) 𝐸0 = 0 0 0 1 −𝛾 where 𝛾 ∈ [0, 1] denotes the probability of energy decay. When a qubit with density matrix 𝜌 undergoes amplitude damping, its evolution is described by EAD (𝜌) = 𝐸 0 𝜌𝐸 0† + 𝐸 1 𝜌𝐸 1† .
(2)
In this work, we use the amplitude damping channel as a representative model for such decoherence processes, which lead to degradation of the teleported quantum state.
C.
Pauli Corrections and Encryption of Quantum Information
The Pauli operators {𝐼, 𝑋, 𝑌 , 𝑍 } form a complete orthonormal basis for single qubit operators. In the quantum teleportation protocol, the specific Pauli correction applied by Bob is determined by the outcome of Alice’s Bell state measurement. The required unitary operation takes the form 𝑈 𝑀1 𝑀2 = 𝑍 𝑀2 𝑋 𝑀1 ,
(3)
where (𝑀1, 𝑀2 ) ∈ {0, 1}2 denote the classical bits communicated by Alice. This conditional correction reverses the random Pauli operator induced by the Bell measurement and enables Bob to recover the original quantum state. Prior to receiving the classical information, however, Bob’s qubit remains correlated with Alice’s measurement outcome. When averaged over the unknown correction bits, Bob’s reduced state is maximally mixed and therefore reveals no information about the input state. From an information theoretic perspective, the absence of the correction bits effectively hides the teleported quantum information. Any observer without access to the classical outcomes perceives Bob’s qubit as carrying no extractable information about the input state. In this sense, the teleportation protocol provides a form of physical layer encryption, with the classical correction bits acting as a decryption key [46]. Consequently, partial or complete leakage of the correction bits undermines this protection and can allow an adversary to infer information about the original quantum state.
D.
Von Neumann Entropy and Quantum Ensembles
The von Neumann entropy [14] is the standard measure of entropy for quantum states and generalizes classical Shannon entropy to the quantum setting. For a state described by a density matrix 𝜌, it is defined as 𝑆 (𝜌) = −Tr 𝜌 log2 𝜌 , (4) and quantifies the mixedness of the state. In quantum information theory, an ensemble of states is represented as E = {𝑝𝑖 , 𝜌𝑖 }, where 𝜌𝑖 is prepared with probability 𝑝𝑖 . The corresponding average state is ∑︁ 𝜌 avg = 𝑝𝑖 𝜌𝑖 . (5) 𝑖
The Holevo quantity is then given by ! ∑︁ ∑︁ 𝜒 (E) = 𝑆 𝑝𝑖 𝜌𝑖 − 𝑝𝑖 𝑆 (𝜌𝑖 ), 𝑖
(6)
𝑖
which upper bounds the accessible classical information that can be extracted from the ensemble by any measurement. In the present setting, the Holevo quantity provides an information theoretic upper bound on how much Eve can learn from partial classical knowledge together with access to Bob’s quantum system. In later sections, we use this framework to analyze residual information exposure under different stochastic leakage models and relate it to the information contained in the teleported quantum state.
E.
Lattice-Based Cryptography and the LWE Problem
The classical channel protection employed in this work relies on post quantum cryptographic schemes whose security reduces to lattice problems, that is, computational problems defined over highly regular geometric point sets in high dimensional spaces that are believed to be hard to solve efficiently. The central hardness assumption is the Learning With Errors (LWE) problem [47]. In this problem, one is given a public matrix 𝐴 ∈ Z𝑞𝑛×𝑚 and noisy samples of the form p = 𝐴⊤ sk + e
(mod 𝑞),
(7)
and the goal is to recover the hidden vector sk. More specifically, 𝐷 Z,𝜎𝑒 𝑞 is a secret vector that plays the role of the hidden key, 𝑞 is a modulus that fixes the arithmetic range, 𝑚 is the number of samples, and e ∈ 𝐷 Z,𝜎𝑒 𝑞 is an error vector drawn from a discrete Gaussian distribution with standard deviation 𝜎𝑒 ·𝑞. Here, the public matrix 𝐴 is known to everyone and provides the structured linear data from which the samples are formed, while the notation Z𝑞 means that all arithmetic is performed modulo 𝑞, so values wrap around after reaching the modulus. The error vector e represents deliberately added random noise, with smaller errors more likely than larger ones. Intuitively, LWE can be viewed as a noisy system of linear equations. Without the error term, the secret vector could in principle be recovered using standard linear algebra. The
6 added noise, however, makes this recovery task computationally difficult, and this difficulty is what gives LWE based cryptographic schemes their security. Standardized post quantum schemes such as CRYSTALS Kyber and FrodoKEM derive their security from module LWE and plain LWE variants, respectively [32, 33]. Here, plain LWE refers to the original form of the problem, whereas module LWE introduces additional algebraic structure that improves efficiency while maintaining the same general hardness foundation. The best known classical attacks against LWE proceed through BKZ (Block Korkine Zolotarev) lattice reduction [48, 49]. In broad terms, lattice reduction attempts to replace a given lattice basis by another basis that spans the same lattice but consists of shorter and more nearly orthogonal vectors, since such a basis is more useful for cryptanalysis. A lattice basis B = (b1, . . . , b𝑚 ) is simply a set of vectors whose integer linear combinations generate all points of the lattice. BKZ works on this basis and iteratively improves it. More precisely, BKZ applies an exact shortest vector oracle within successive blocks of dimension 𝛽 to produce a reduced basis whose Gram Schmidt vectors b̃𝑖 decrease in length at a predictable rate. The block dimension 𝛽 controls the strength of the reduction: a larger block size generally yields a better reduced basis, but at a significantly higher computational cost. The shortest vector oracle is an idealized subroutine that finds the shortest nonzero vector inside a given block, while the Gram Schmidt vectors are an orthogonalized version of the basis vectors that make the geometry of the reduced basis easier to analyze. The quality of the reduced basis is commonly characterized by the root Hermite factor 𝛿 root , defined so that the shortest reduced vector satisfies 1/𝑚 ∥b1 ∥ ≈ 𝛿 𝑚 , root (det Λ)
(8)
where Λ is the lattice and 𝑚 is its rank [50]. Here, det Λ is the determinant of the lattice, which measures the effective volume of a fundamental cell, and the rank 𝑚 is the number of basis vectors. Smaller values of 𝛿 root correspond to stronger reduction and therefore to more effective attacks. To model the structure of a BKZ reduced basis analytically, one often adopts the Geometric Series Assumption (GSA), which is a standard heuristic description of how the orthogonalized basis vectors shrink under reduction. Under this assumption, the Gram Schmidt norms decay geometrically: −2(𝑖 −1) ∥ b̃𝑖 ∥ = ∥ b̃1 ∥ 𝛿 root ,
(9)
which provides a convenient analytic approximation to the output of BKZ reduction [50]. In other words, the GSA assumes that the orthogonalized vectors decrease in a regular geometric pattern, making the behavior of BKZ easier to model mathematically. The computational cost of BKZ is commonly parameterized by 𝛿 root through the empirical relation 𝑎 log2 𝑇BKZ = − 𝑏, (10) log2 𝛿 root where 𝑎 and 𝑏 are empirical scaling constants encoding the adversary’s hardware throughput and algorithmic efficiency [49].
This relation captures the practical tradeoff between attack quality and runtime: achieving a smaller root Hermite factor, and hence a stronger reduction, generally requires substantially more computation. Once lattice reduction has been carried out, the secret is recovered by Nearest Planes enumeration [51]. At each Gram Schmidt layer 𝑖, the algorithm searches over integer coefficients within a radius 𝑑𝑖 and succeeds with probability governed by √ (11) erf 𝑑𝑖 ∥ b̃𝑖 ∥ 𝜋/(2𝑠) , where 𝑠 is the LWE noise standard deviation. Conceptually, this step attempts to identify the lattice point closest to the noisy target after the basis has been sufficiently reduced. The search radius 𝑑𝑖 controls how far the algorithm explores at each layer, and the error function appears because the success probability is determined by the Gaussian statistics of the noise. Thus, the overall attack has two main ingredients: lattice reduction, which transforms the basis into a more favorable geometric form, and a subsequent decoding step, which uses that reduced basis to recover the hidden secret. The success of this process depends both on the quality of the reduction and on the magnitude of the underlying noise. These definitions are used in Section IV B to construct a time dependent classical attack model.
III.
QRQT FRAMEWORK AND SECURITY ANALYSIS UNDER QUANTUM-MEMORY CONSTRAINTS
QRQT Framework. The proposed Quantum-Resistant Quantum Teleportation (QRQT) framework extends the standard teleportation protocol by integrating post-quantum cryptography into the classical channel. As illustrated in Fig. 1, the system consists of two parties, Alice and Bob, sharing an entangled Bell pair and communicating via a classical control link secured by a PQC primitive EPQC . Let |𝜓 ⟩ denote the input state, {𝑀1, 𝑀2 } the measurement outcomes. This section formalizes the QRQT operations and the corresponding timing constraints. In QRQT, the teleportation process can be described as a quantum classical hybrid map: TQRQT = R Bob ◦ EPQC ◦ MAlice ◦ UBell ◦ PBell, where TQRQT represents the overall map from Alice’s input quantum state to the reconstructed state on Bob’s side under PQC secured teleportation. Specifically, PBell denotes the preparation of the shared Bell pair |𝛽 00 ⟩ = √1 (|00⟩ + |11⟩), 2 UBell denotes the Bell basis transformation implemented by a CNOT gate and a Hadamard gate, MAlice denotes Alice’s measurement, which produces the two classical bits (𝑀1, 𝑀2 ), EPQC denotes the PQC based encryption and decryption of these bits, and R Bob denotes Bob’s reconstruction by applying the Pauli corrections 𝑍 𝑀2 𝑋 𝑀1 . For successful teleportation, Bob’s quantum memory must preserve coherence throughout the entire delay of the classical channel, including both cryptographic and transmission
7 latencies: 𝜏𝑚 = 𝑇 PBell + 𝑇UBell + 𝑇 EPQC + 𝑇MAlice + 𝑇comm + 𝑇RBob
(12)
where 𝜏𝑚 denotes the effective quantum memory lifetime limit, representing the minimum coherence time required to preserve the stored qubit until the classical correction bits are received. Thus, 𝑇coh > 𝜏𝑚 . (13) The individual timing components are: 𝑇 PBell , the Bell-pair preparation and distribution time; 𝑇UBell , the Bell-basis transformation latency; 𝑇MAlice , Alice’s measurement time; 𝑇 EPQC , the PQC encryption and decryption delay; 𝑇comm = 𝑑/𝑣 fiber , the distance-dependent classical communication delay over optical fiber (𝑣 fiber ≈ 2×105 km/s); and 𝑇RBob , the time for Bob’s local Pauli corrections. Among these, 𝑇comm dominates at long distances (≈ 5 𝜇s/km), while all local operations remain in the nanosecond range (see Appendix B 1 for platform-specific estimates). 𝑇 EPQC captures the computational delay introduced by post-quantum encryption and decryption, while 𝑇comm represents the classical communication time. The interplay between these classical-layer delays and quantum-layer decoherence defines the operational feasibility region of QRQT, as quantified below and formalized in Section IV. In the QRQT protocol, Alice secures the two correction bits (𝑀1, 𝑀2 ) using a hybrid PQC scheme: a lattice-based keyencapsulation mechanism (e.g., CRYSTALS-Kyber) establishes a one-time session key 𝐾, which is then used to symmetrically encrypt the correction bits via AES, yielding ciphertext (𝐶 1, 𝐶 2 ). Bob decapsulates 𝐶 1 , decrypts 𝐶 2 , and applies Pauli corrections 𝑍 𝑀2 𝑋 𝑀1 to recover the teleported state. The full protocol specification is provided in Appendix D. Memory lifetime limit analysis. Having established 𝜏𝑚 as the lower bound on quantum memory coherence required for successful QRQT, we now demonstrate how this constraint governs the operational feasibility of the QRQT framework. By quantifying this relationship across different PQC schemes and communication distances, we identify the minimal physical conditions (e.g., communication distance) under which QRQT remains both secure and realizable. The PQC computing time is estimated using the JEDI BullSequana XH3000 supercomputer (𝑅max = 4.50 PFlop/s) benchmark [52]; the details of the estimation method are provided in Appendix C. We assume spontaneous parametric down-conversion (SPDC) Bell-pair generation [53, 54] and fiber-optic delivery for the quantum teleportation experiment; the data used for estimating the feasibility boundary are given in Appendix B 2. TABLE I: PQC overhead and maximum distance (𝑇coh = 1 ms). Algorithm
Sec. 𝑇enc (𝜇 s) Max Dist. (km)
Kyber512 Kyber768 Kyber1024 FrodoKEM-640 FrodoKEM-976 FrodoKEM-1344
128 192 256 128 192 256
2.3 3.1 4.2 15.7 28.4 45.1
198.5 198.3 198.1 195.9 194.3 191.0
Our results show the tradeoff between PQC robustness and quantum memory requirements: stronger PQC algorithms
impose heavier processing delays, which shrink the effective distance window for teleportation. PQC security levels should therefore be chosen in light of physical memory limits and network distance targets. Distance–security tradeoffs. The maximum feasible communication distance is determined by subtracting fixed delays from the coherence window and multiplying by the propagation speed in fiber: 𝑑 max = (𝑇coh − 𝑇fixed ) · 𝑣 fiber,
(14)
2 × 105 km/s.Here 𝑇fixed
with 𝑣 fiber ≈ = 𝑇 PBell + 𝑇UBell + 𝑇 EPQC + 𝑇MAlice + 𝑇RBob collects all distance-independent delays, so that the distance-dependent contribution reduces to 𝑇comm = 𝑑/𝑣 fiber . For example, with a practical coherence time of 𝑇coh = 1 ms (consistent with state-of-the-art trapped-ion and rare-earth doped solid-state memories [55–57]), the maximum distance drops from ∼ 200 km with lightweight schemes such as Kyber512 to below 192 km for heavy-weight schemes such as FrodoKEM-1344. This shows that memory lifetime, rather than raw cryptographic strength, sets the fundamental limit on secure teleportation distances. The derived linear relation provides a design guideline for balancing PQC selection with physical-layer capabilities. For a given quantum memory technology, we can invert Eq. (14) to determine the strongest PQC scheme that maintains real-time feasibility. The analysis above establishes the physical feasibility region of QRQT by quantifying how PQC overhead and communication distance jointly constrain the available coherence window. A complementary and equally important question is whether the protocol remains secure within this feasible region: specifically, can an adversary targeting both the classical and quantum channels simultaneously succeed before decoherence destroys the intercepted quantum information? We address this question in the following section by developing a joint classical–quantum threat model.
IV.
JOINT THREAT MODEL
To evaluate the overall security of the Quantum-Resistant Quantum Teleportation (QRQT) framework, we establish a joint threat model that unifies the quantum-side and classicalside adversarial assumptions. The goal is to capture the temporal coupling between physical quantum coherence and postquantum computational hardness that determines whether an attack can succeed before decoherence destroys useful information. We consider an adversary, Eve, who can target both the quantum and classical channels of the teleportation protocol. On the quantum channel, Eve is assumed capable of coherently interacting with qubits distributed over optical fiber and, in the strongest scenario, performing a SWAP-based interception that redirects Bob’s entangled qubit into her own quantum memory (detailed in Sec. IV A). We do not assume that legitimate parties perform entanglement verification or active monitoring; this deliberate omission establishes an upper bound on adversarial capability.