量子即服务(QaaS)流水线的端到端威胁模型
An End-to-End Threat Model for the Quantum-as-a-Service Pipeline
中文总结 AI 辅助
本文针对QaaS流水线缺乏结构化威胁建模的问题,结合STRIDE将其工作流分解为六阶段模型,分析各层级攻击向量,研究未被充分探索的环节并区分出三条高影响跨阶段攻击链。
中文摘要 AI 辅助
基于云访问IBM Quantum、IonQ Cloud、Amazon Braket等量子即服务(QaaS)平台的应用日益普及,混合量子-经典算法(VQE、QAOA、QML)通过编排、编译、执行的多层长流水线传输数据。现有研究已在各阶段发现校准篡改、SWAP攻击、QubitHammer等关键攻击,但这些攻击因术语不同而相互孤立,且现有基于STRIDE的量子威胁建模缺乏针对QaaS栈本身的结构化视图。本文通过将工作流分解为六阶段模型并结合STRIDE威胁建模解决该问题,生成的矩阵展示了各阶段在量子特定、继承经典及合理层级的攻击向量,进一步研究了未被充分探索的否认和权限提升环节,区分出三条影响更大的跨阶段攻击链。
英文摘要
Cloud-based accessing of Quantum-as-a-Service (QaaS) platforms such as IBM Quantum, IonQ Cloud, and Amazon Braket is becoming popular day by day. Hybrid quantum-classical algorithms (VQE, QAOA, QML) transfer data via a long layered pipeline of orchestration, compilation, and execution. Recent works have demonstrated various critical attacks at individual stages: Calibration tampering, SWAP attacks, QubitHammer, and so on. However, these attacks remain separated because of their own terminology, and existing STRIDE-based threat modeling in the context of quantum lacks a structured view towards the QaaS stack itself. We address this concern by decomposing the workflow into six-stage model with STRIDE threat modeling. Our matrix demonstrated attack vectors in quantum-specific, inherited classical, and plausible tiers for each of the stages. We further investigate the underexplored sections (repudiation and elevation-of-privilege) and distinguish three different cross-stage attack chains with higher impacts.