Hardware-conditioned provenance for long-retention evidence.

Published research on measured hardware behavior as an additional verification signal. Current Ledger signing and offline verification are covered in the assurance brief. The hardware-conditioned experiments described here are separate from the current Ledger package and pilot deployment.

Where quantum actually fits

Current Ledger uses Ed25519 by default, with an optional ML-DSA-65 signing profile, hash-chained evidence, and local verification. Key custody and retained trust anchors are deployment decisions described in the assurance brief. None of it requires quantum hardware.

The published hardware-conditioned research evaluates hardware-executed measurement distributions as the verification signal for a Quantum Physical Unclonable Function, or Q-PUF: distributions shaped by backend state, calibration, gate behavior, and noise characteristics, producing device-conditioned fingerprints evaluated under disclosed hardware, parameter, and operating conditions. This is a conditioned evidence signal, not proof of physical unclonability across untested hardware. Where hardware is not used, simulation fallback is supported and labeled as a lower-trust tier, never passed off as the real thing.

Physical anchor

Quantum measurements add a hardware-conditioned signal to otherwise algorithmic provenance workflows.

Composed defense

The research verifier combines statistical policy gates with integrity signatures and profile controls.

Backend agnostic

The experiments used remote quantum providers. Owning quantum hardware is not a prerequisite for this research method.

PQC is the signing layer. Hardware-conditioned provenance is an additive evidence layer above it for long-retention or disputed-evidence workflows. It does not replace PQC.

How the research certificates work

The research implementation produces offline-verifiable certificates. Each binds content hashes, quantum measurement statistics, backend metadata, policy profile, and cryptographic signatures into a portable trust object.

1

Hash

Bind the artifact with SHA-256/SHA-512 content digests.

2

Execute

Run a parameterized circuit through simulation or available QPU backends.

3

Fingerprint

Capture measurement distributions, noise statistics, and distribution digests.

4

Sign

Bind the evidence package with modern signatures, including post-quantum options.

5

Verify

Validate the certificate later through versioned standard, hardened, strict, or offline profiles.

Post-quantum does not mean post-review.

Anthropic's July 2026 research used an AI system to find a stronger classical attack on HAWK, a post-quantum signature candidate. The research does not report attacks on ML-DSA, Ed25519, SHA-256, or FieldHash's Q-PUF verifier. It does show why no algorithm should receive permanent trust. Read the research.

Separately, current Ledger treats cryptographic algorithms as versioned assurance dependencies. If a suite is deprecated, Ledger can bind the complete historical head and entry count to a materially different replacement suite, pinned replacement signers, and a customer-held anchor. The old chain remains intact. The renewal proves continuity from the head retained at that point; it cannot repair evidence compromised earlier.

Hardware-conditioned provenance adds an independent evidence signal. It does not make signatures permanent, and it does not replace cryptographic migration.

Evidence, not assertion

The public evidence package documents real hardware execution, adversarial synthesis benchmarks, adaptive spoofing tests, cost data, and reproducibility materials. These are bounded research results under the reported hardware, attack, and verifier conditions. They do not establish a runtime speedup, general physical unclonability, or customer deployment readiness.

HardwareExecuted on IBM Quantum and Quantum Inspire, with auditable job records and reproducibility artifacts.
Standard profileUniform-blend attack accepted in 15/800 trials, a measured soft spot rather than a hidden failure.
Hardened profileThe same attack family was closed to 0/800 under tightened policy settings.
Research production-gated profileAdaptive production-gated tests produced 0/5000 successful forgeries per tested model under the no-signing-key assumption.

Next phase

The next steps are independent validation, broader backend conditions, and a separately qualified integration before a customer pilot. The current evidence does not establish performance in customer document workflows.

Independent third-party red teaming against the Q-PUF verification model.
Larger-shot, multi-backend hardware campaigns to expand the operating envelope.
Customer-specific integration and release qualification before any long-retention workflow pilot.
Economic and policy impact modeling aligned to SDG 9 and SDG 16.

The goal is practical: stronger digital trust now, using quantum hardware as a measured evidence source rather than waiting for a fault-tolerant future.

Read the advanced proof package

For qualified technical review, the evidence package includes the preprint, adversarial results, hardware reports, manifests, and reproducibility materials.