Q-LEASE: Lifecycle-bound zero-trust authorization for HPC-to-QPU job handoffs
Abstract
Background Zero-Trust access control for cloud APIs is well established, but hybrid High-Performance Computing (HPC)-to-Quantum Processing Unit (QPU) workflows have a lifecycle existing mechanisms were not built for: a job queues for minutes to days, is dispatched, executes, and only then releases results, while identity, policy, and hardware calibration state can change throughout. Existing token, proof-of-possession, and workload-identity mechanisms do not separate permission to queue from permission to execute, nor bind authorization to current hardware state. Methods We designed and implemented Q-LEASE, a two-capability protocol separating a Queue Admission Ticket from a single-use Execution Capability bound to a circuit hash, backend identity, and calibration epoch, re-evaluated by a real Open Policy Agent (OPA) engine immediately before dispatch. The prototype uses real Ed25519/PASETO tokens, DPoP-style proof-of-possession, SPIFFE-shaped workload identity, and a phase-aware revocation state machine, deployed as six containerised services on a Kubernetes (kind) cluster with Kueue-driven queueing. We compared Q-LEASE against four representative baselines across 16 attack/failure scenarios (2400 attack trials, 500 clean trials), and verified core safety properties with TLA+/TLC and token-flow security with the Tamarin prover. Results Q-LEASE blocked 90.0% of unauthorized-execution attempts (95% confidence interval (CI) 87.0–92.4%), versus 12.5–37.9% for the four baselines. The remaining gap came from queue/execution separation and circuit/backend/calibration-epoch binding, which no baseline implements. Both TLA+ safety properties held, and all five Tamarin lemmas were proved automatically. Q-LEASE’s mean policy-decision latency was 44.3 ms, approximately 34.4 ms higher than the baselines, with no measurable increase in end-to-end workflow completion time relative to a real, contention-driven queue wait, while running against a real Kueue-admitted workload on a real cluster. Conclusions Separating queue admission from execution authorization, and binding it to hardware state re-checked immediately before dispatch, closes a gap that composing existing OAuth-family mechanisms does not, at a latency cost small relative to realistic QPU queue waits.