35
collaborators
2023–2026
years active
Contributions
QIP QCrypt TQC talk poster presenter award · △program ◇steering ○organizing · filled = chair
7 Posters
| Title | Conference | Co-authors |
|---|---|---|
| Security Proof of a Novel Authentication Scheme for Quantum Key Distribution | QCRYPT 2026 | Francesco Stocco, Edoardo Signorini, Giacomo Fregona, Fernando Chirici, Damiano Giani, Tommaso Occhipinti, Guglielmo Morgari, Alessandro Zavatta, Davide Bacco |
Quantum Key Distribution (QKD) protocols require Information‑Theoretically Secure (ITS) authentication of the classical channel to preserve the unconditional security of the distilled key. Standard ITS schemes are based on one-time keys: once a key is used to authenticate a message, it must be discarded. Since QKD requires mutual authentication, two independent one-time keys are typically consumed per round, imposing a non-trivial overhead on the net security key rate. In this work, we present the \emph{authentication-with-response} scheme, a novel ITS authentication scheme based on $\varepsilon$-Almost Strongly Universal\textsubscript{2} ($\varepsilon$-ASU\textsubscript{2}) functions, whose IT security can be established in the Universal Composability (UC) framework. The scheme achieves mutual authentication consuming a single one-time key per QKD round, halving key consumption compared to the state-of-the-art. |
||
| End-to-End Key Protection in Multi-Hop QKD Networks: Minimizing Trust in Intermediate Nodes | QCRYPT 2026 | Claudio Pereti, Davide Bacco, Alessandro Zavatta |
Trusted-node architectures enable practical metropolitan and wide-area Quantum Key Distribution (QKD) deployments by allowing intermediate relays, typically implemented as Key Management Entities (KMEs), to process and forward key material across chains of QKD links. This design enables scalability but rests on a strong assumption: each relay must be trusted not to access, store, or misuse secret key material. In large multi-hop networks, this creates a growing perimeter of trust whose security depends on the physical and operational integrity of every intermediate node. Although link-level QKD provides information-theoretic security, end-to-end confidentiality ultimately relies on this perimeter, making the protection of secret keys contingent on securing all relay nodes along the path. We propose a simple, implementation-friendly mechanism that reduces the trust required from intermediate relays without modifying the optical layer. The core idea is to mask the raw random sequence used for quantum encoding with a short pre-shared endpoint key before any photon is transmitted. Only the endpoints perform the corresponding logical unmasking after sifting and privacy amplification. Intermediate nodes can still execute standard link-level QKD operations (measurement, sifting, error correction, privacy amplification), yet remain cryptographically unable to reconstruct the final end-to-end key. The approach is fully compatible with existing QKD infrastructures and KME-based architectures and requires only software-level modifications. In summary, our method addresses the long-standing tension between link-level quantum secu- rity and end-to-end trust in multi-hop networks: it preserves the operational role of intermediate relays while preventing them from learning the secret they help deliver. |
||
| Implementation and Validation of a Quantum-Secure Metropolitan Network in Real-World Scenario | QCRYPT 2026 | Nicola Biagi, Damiano Giani, Marco Russo, Fernando Chirici, Francesco Stocco, Saverio Francesconi, Giacomo Ferranti, Alessandro Soureal, Antonella Sanguineti, Bartolomeo Montrucchio, Christian Laurenzi, Oliviero Testa, Guglielmo Morgari, Antonio Manzalini, Tommaso Occhipinti, Alessandro Zavatta, Davide Bacco |
The advent of cryptographically relevant quantum computers poses an existential threat to classical public-key infrastructure. Quantum Key Distribution (QKD) addresses this challenge by providing information-theoretic security for key establishment, independently of any computational hardness assumption. In this work, the deployment and experimental validation of a metropolitan-scale quantum-secure network between data centers in Milan is reported. The network operates over installed fiber infrastructure and implements a layered architecture integrating QKD hardware, standards-compliant Key Management (KM), and centralized Software-Defined Networking (SDN) orchestration. Dynamic path reconfiguration via active optical switching and trusted-node routing allow automated fail-over solutions. Application-layer validation across diverse protocols and workloads confirms the seamless interoperability of all system components. These results establish the technical and operational readiness of metropolitan QKD networks for production deployment, and offer a replicable blueprint for building quantum-secure communication infrastructure at metropolitan scale. |
||
| Quantum Key Distribution in the Mid-Infrared | QCRYPT 2025 | Tecla Gabrielli, Domenico Ribezzo, Francesco Cappelli, Nicola Biagi, Nicola Corrias, Davide Bacco, Simone Borri, Paolo De Natale, Alessandro Zavatta, Natalia Bruno |
Quantum technologies play a central role in establishing new ways of quantum-secured communication. We investigate Free Space Quantum Communication and explore the advantage of implementing Quantum Key Distribution with a light source in the Mid-Infrared (>3 μm) region of the electromagnetic spectrum. We simulate and show that, for non-optimal weather conditions, Mid-Infrared can outperform the most commonly used telecom wavelength. |
||
| Implementations of QKD security in different use-cases | QCRYPT 2024 | Ilaria Vagniluca, Saverio Francesconi, Nicola Biagi, Fernando Chirici, Tommaso Occhipinti, Alessandro Zavatta, Davide Bacco |
The advances in quantum key distribution (QKD) during the last 30 years have been outstanding in terms of reachable distance and key generation rate. However, the integration of quantum systems in real telecommunication networks generates multiple challenges, from technology availability to the design of inter-operable QKD systems, interconnected to key management layers and cyphers, and that can be embedded in existing telecommunication network topologies. We present several use-cases of implementation and integration of our QKD systems, in different contexts and involving Italy and neighboring countries in Europe. |
||
| Practical High-Dimensional Quantum Key Distribution Protocol over deployed Multicore fiber | QCRYPT 2023 | Mujtaba Zahidy, Domenico Ribezzo, Ilaria Vagniluca, Nicola Biagi, Tommaso Occhipinti, Leif Katsuo Oxenløwe, Michael Galili, Tetsuya Hayashi, Dajana Cassioli, Antonio Mecozzi, Cristian Antonelli, Alessandro Zavatta, Davide Bacco |
Quantum key distribution (QKD) is introduced to make encryption and transmission of data over any public channel unconditionally secure. A key requirement of such a promise is to have access to an encryption key with a similar length as the message and data itself. While QKD has become mature and the key rate significantly increased over the past 20 years, there is still a notable gap between data transmission and key generation rates. High-dimensional QKD is proposed as a method to respond to this demand. Here, we demonstrate a 4-dimensional path-\&-time encoding QKD system with more than 100\% improvement compared to a standard 2D system in the same test-bed, a 52-km deployed multicore fiber link. |
||
| Comparison of 2-dimensional and high-dimensional BB84 QKD protocols | QIP 2023 | Ilaria Vagniluca, Domenico Ribezzo, Davide Bacco, Alessandro Zavatta, Tommaso Occhipinti |