Skip to content
Open access

Q-LEASE: Lifecycle-bound zero-trust authorization for HPC-to-QPU job handoffs

Aug 2026 · Open Research Europe · 0 citations · 14 references

Abstract

Background Zero-Trust access control for cloud APIs is well established, but hybrid High-Performance Computing (HPC)-to-Quantum Processing Unit (QPU) workflows have a lifecycle existing mechanisms were not built for: a job queues for minutes to days, is dispatched, executes, and only then releases results, while identity, policy, and hardware calibration state can change throughout. Existing token, proof-of-possession, and workload-identity mechanisms do not separate permission to queue from permission to execute, nor bind authorization to current hardware state. Methods We designed and implemented Q-LEASE, a two-capability protocol separating a Queue Admission Ticket from a single-use Execution Capability bound to a circuit hash, backend identity, and calibration epoch, re-evaluated by a real Open Policy Agent (OPA) engine immediately before dispatch. The prototype uses real Ed25519/PASETO tokens, DPoP-style proof-of-possession, SPIFFE-shaped workload identity, and a phase-aware revocation state machine, deployed as six containerised services on a Kubernetes (kind) cluster with Kueue-driven queueing. We compared Q-LEASE against four representative baselines across 16 attack/failure scenarios (2400 attack trials, 500 clean trials), and verified core safety properties with TLA+/TLC and token-flow security with the Tamarin prover. Results Q-LEASE blocked 90.0% of unauthorized-execution attempts (95% confidence interval (CI) 87.0–92.4%), versus 12.5–37.9% for the four baselines. The remaining gap came from queue/execution separation and circuit/backend/calibration-epoch binding, which no baseline implements. Both TLA+ safety properties held, and all five Tamarin lemmas were proved automatically. Q-LEASE’s mean policy-decision latency was 44.3 ms, approximately 34.4 ms higher than the baselines, with no measurable increase in end-to-end workflow completion time relative to a real, contention-driven queue wait, while running against a real Kueue-admitted workload on a real cluster. Conclusions Separating queue admission from execution authorization, and binding it to hardware state re-checked immediately before dispatch, closes a gap that composing existing OAuth-family mechanisms does not, at a latency cost small relative to realistic QPU queue waits.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.