14
collaborators
2021–2026
years active
Contributions
QIP QCrypt TQC talk poster presenter award · △program ◇steering ○organizing · filled = chair
2 Talks
| Title | Conference | Type | Co-authors |
|---|---|---|---|
|
QKD Oracles for Authenticated Key Exchange ↗
|
QCRYPT 2026 | regular | Daan Planken, Christian Schaffner, Sebastian Verschoor |
Authenticated Key Exchange (AKE) establishes shared (‘symmetric’) cryptographic keys which are essential for secure online communication. Alternatively, symmetric keys could be established via Quantum Key Distribution (QKD), which uses quantum communication. Although point-to-point QKD can offer information-theoretic security (ITS), this guarantee crucially hinges on proper implementation. In practice, QKD is expected to be combined with conventional cryptography – raising the question whether such ‘hybrid’ combinations actually preserve QKD’s main benefit, ITS. We perform an extensive review of existing AKE-QKD hybrids and their analysis. Our review shows that it is currently unclear both how to design such protocols and how to quantify their security. As our review shows, many proposed solutions do not preserve the ITS property of QKD, and finding a solution that does is less straightforward then expected. Moreover, we found that known designs do not even achieve computational security. In more detail, usage of the QKD keys needs to be coordinated across endpoints. This coordination currently requires that the keys are accompanied by a key ID. Although key IDs are introduced solely to ensure correct functionality, we show that they introduce subtle vulnerabilities – specifically, we identify dependent-key attacks on several existing protocols that arise from improper key-ID handling. To address these issues, we propose a security model for AKE-QKD hybrids that also catches dependent-key attacks. As our main conceptual contribution, we model QKD via an oracle that closely resembles the standard ETSI 014 interface. We demonstrate the usefulness of this oracle for cryptographic analyses by integrating it into a prominent security model for AKE, called CK+ model. Lastly, we present a new protocol that combines QKD with a triple-KEM handshake, and prove it secure in our integrated model. This is the first hybrid protocol that provably preserves the ITS of QKD. |
|||
| Tight adaptive reprogramming in the Quantum Random Oracle Model | QIP 2021 | regular | Alex Bredariol Grilo, Andreas Hülsing, Christian Majenz |
Abstract The random oracle model (ROM) enjoys widespread popularity, mostly because it tends to allow for tight and conceptually simple proofs where provable security in the standard model is elusive or costly. While being the adequate replacement of the ROM in the post-quantum security setting, the quantum-accessible random oracle model (QROM) has thus far failed to provide these advantages in many settings. In this work, we focus on adaptive reprogrammability, a feature of the ROM enabling tight and simple proofs in many settings. We show that the straightforward quantum-accessible generalization of adaptive reprogramming is feasible by proving a bound on the adversarial advantage in distinguishing whether a random oracle has been reprogrammed or not. We show that our bound is tight by providing a matching attack. We go on to demonstrate that our technique recovers the mentioned advantages of the ROM in three QROM applications: 1) We give a tighter proof of security of the message compression routine as used by XMSS. 2) We show that the standard ROM proof of chosen-message security for Fiat-Shamir signatures can be lifted to the QROM, straightforwardly, achieving a tighter reduction than previously known. 3) We give the first QROM proof of security against fault injection and nonce attacks for the hedged Fiat-Shamir transform. |
|||
3 Posters
| Title | Conference | Co-authors |
|---|---|---|
| QKD Oracles for Authenticated Key Exchange | QIP 2026 | ▸Daan Planken, Christian Schaffner, Sebastian Verschoor |
| Evaluating Deployed Applications of Quantum Key Distribution: A Comparative Study with Post-Quantum Cryptography | QCRYPT 2025 | Nick Aquina, Bruno Cimoli, Soumya Das, Fiona Johanna Weber, Chigo Okonkwo, Simon Rommel, Boris Skoric, Idelfonso Tafur Monroy, Sebastian Verschoor |
Quantum Key Distribution (QKD) is currently being discussed as a technology to safeguard communication in a future where quantum computers compromise traditional public-key cryptosystems. We conduct a comprehensive security evaluation of QKD-based solutions, focusing on real-world use cases sourced from academic literature and industry reports. We analyze these use cases, assess their security, and identify the possible advantages of deploying QKD-based solutions. We further compare QKD-based solutions with Post-Quantum Cryptography (PQC), the alternative approach to achieving security when quantum computers compromise traditional public-key cryptosystems, evaluating their respective suitability for each scenario. Based on this comparative analysis, we critically discuss and comment on which use cases QKD is suited for, considering factors such as implementation complexity, scalability, and long-term security. Our findings contribute to a better understanding of the role QKD could play in future cryptographic infrastructures and offer guidance to decision-makers considering the deployment of QKD. |
||
| Failing gracefully: Decryption failures and the Fujisaki-Okamoto transform | QCRYPT 2022 | Andreas Hülsing, Christian Majenz |
Collaborators
| Co-author | Joint talks |
|---|---|
| Sebastian Verschoor | 3 |
| Andreas Hülsing | 2 |
| Christian Majenz | 2 |
| Christian Schaffner | 2 |
| Daan Planken | 2 |
| Alex Bredariol Grilo | 1 |
| Boris Skoric | 1 |
| Bruno Cimoli | 1 |
| Chigo Okonkwo | 1 |
| Fiona Johanna Weber | 1 |
| Idelfonso Tafur Monroy | 1 |
| Nick Aquina | 1 |
| Simon Rommel | 1 |
| Soumya Das | 1 |