3
program roles
24
collaborators
2020–2026
years active
Contributions
QIP QCrypt TQC talk poster presenter award · △program ◇steering ○organizing · filled = chair
11 Talks
| Title | Conference | Type | Co-authors |
|---|---|---|---|
| A Unified Approach to Quantum Key Leasing with a Classical Lessor | TQC 2026 | regular | Fuyuki Kitagawa, Shota Yamada, ▸Takashi Yamakawa |
Secure key leasing allows a cryptographic key to be leased as a quantum state in such a way that the key can later be revoked in a verifiable manner. In this work, we propose a modular framework for constructing secure key leasing with a classical-lessor, where the lessor is entirely classical and, in particular, the quantum secret key can be both leased and revoked using only classical communication. Based on this framework, we obtain classical-lessor secure key leasing schemes for public-key encryption (PKE), pseudorandom function (PRF), and digital signature. We adopt the strong security notion known as security against verification key revealing attacks (VRA security) proposed by Kitagawa et al. (Eurocrypt 2025) into the classical-lessor setting, and we prove that all three of our schemes satisfy this notion under the learning with errors assumption. Our PKE scheme improves upon the previous construction by Goyal et al. (Eurocrypt 2025), and our PRF and digital signature schemes are respectively the first PRF and digital signature with classical-lessor secure key leasing property. Along the way, we also construct a watermarking scheme and a dual-mode secure function evaluation scheme that satisfy certain useful properties, which may be of independent interest. |
|||
| The Black-Box Simulation Barrier Persists in a Fully Quantum World | TQC 2026 | regular | ▸Nai-Hui Chia, Kai-Min Chung, Xiao Liang |
Zero-Knowledge (ZK) protocols have been a subject of intensive study due to their fundamental importance and versatility in modern cryptography. However, the inherently different nature of quantum information significantly alters the landscape, necessitating a re-examination of ZK designs. A crucial aspect of ZK protocols is their round complexity, intricately linked to *simulation*, which forms the foundation of their formal definition and security proofs. In the *post-quantum* setting, where honest parties and their communication channels are all classical but the adversaries could be quantum, Chia, Chung, Liu, and Yamakawa [FOCS'21 & QIP'22] demonstrated the non-existence of constant-round *black-box-simulatable* ZK arguments (BBZK) for NP unless NP is in BQP. However, this problem remains widely open in the full-fledged quantum future that will eventually arrive, where all parties (including the honest ones) and their communication are naturally quantum. Indeed, this problem is of interest to the broader theory of quantum computing. It has been an important theme to investigate how quantum power fundamentally alters traditional computational tasks, such as the *unconditional* security of Quantum Key Distribution and the incorporation of Oblivious Transfers in MiniQCrypt. Moreover, quantum communication has led to round compression for commitments and interactive arguments. Along this line, the above problem is of great significance in understanding whether quantum computing could also change the nature of ZK protocols in some fundamentally manner. We resolved this problem by proving that only languages in *BQP* admit constant-round *fully-quantum* BBZK. This result holds significant implications. Firstly, it illuminates the nature of quantum zero-knowledge and provides valuable insights for designing future protocols in the quantum realm. Secondly, it relates ZK round complexity with the intriguing problem of BQP vs QMA, which is out of the reach of previous analogue impossibility results in the classical or post-quantum setting. Lastly, it justifies the need for the non-black-box simulation techniques or the relaxed security notions employed in existing constant-round fully-quantum BBZK protocols. |
|||
| Quantum One-Time Programs, Revisited | TQC 2025 | regular | Aparna Gupte, Justin Raizes, Bhaskar Roberts, Vinod Vaikuntanathan |
| Quantum Key Leasing for PKE and FHE with a Classical Lessor | QCRYPT 2024 | regular | Orestis Chardouvelis, Vipul Goyal, Aayush Jain |
In this work, we consider the problem of secure key leasing, also known as revocable cryptography (Agarwal et. al. Eurocrypt' 23, Ananth et. al. TCC' 23), as a strengthened security notion to its predecessor put forward in Ananth et. al. (Eurocrypt' 21). This problem aims to leverage unclonable nature of quantum information to allow a lessor to lease a quantum key with reusability for evaluating a classical functionality. Later, the lessor can request the lessee to provably delete the key and then the lessee will be completely deprived of the capability to evaluate. In this work, we construct a secure key leasing scheme to lease a decryption key of a (classical) public-key, homomorphic encryption scheme from standard lattice assumptions. Our encryption scheme is exactly identical to the (primal) version of Gentry-Sahai-Waters homomorphic encryption scheme with a carefully chosen public key matrix. We achieve strong form of security where: The entire protocol (including key generation and verification of deletion) uses merely classical communication between a classical lessor (client) and a quantum lessee (server). Assuming standard assumptions, our security definition ensures that every computationally bounded quantum adversary could only simultaneously provide a valid classical deletion certificate and yet distinguish ciphertexts with at most some negligible probability. Our security relies on subexponential time hardness of learning with errors assumption. Our scheme is the first scheme to be based on a standard assumption and satisfying the two properties mentioned above. The main technical novelty in our work is the design of an FHE scheme that enables us to apply elegant analyses done in the context of classical verification of quantumness from LWE (Brakerski et. al.(FOCS'18, JACM'21) and its parallel amplified version in Radian et. al.(AFT'21)) to the setting of secure leasing. This connection to classical verification of quantumness leads to a modular construction and arguably simpler proofs than previously known. An important technical component we prove along the way is an amplified quantum search-to-decision reduction: we design an extractor that uses a quantum distinguisher (who has an internal quantum state) for decisional LWE, to extract secrets with success probability amplified to almost one. This technique might be of independent interest. |
|||
| Another Round of Breaking and Making Quantum Money: How to Not Build It from Lattices, and More | QIP 2023 | regular ▸ presenter | Hart Montgomery, Mark Zhandry |
| Collusion-Resistant Copy-Protection for Watermarkable Functionalities | QIP 2023 | regular ▸ presenter | Qipeng Liu, Luowen Qian, Mark Zhandry |
| Quantum Copy Protection and Unclonable Cryptography | QCRYPT 2022 | invited ▸ presenter | — |
| Beating Classical Impossibility of Position Verification | QIP 2022 | regular | Qipeng Liu, ▸Luowen Qian |
| Hidden Cosets and Applications to Unclonable Cryptography | QIP 2022 | regular ▸ presenter | Andrea Coladangelo, Eric Culf, Qipeng Liu, Thomas Vidick, Mark Zhandry |
| Hidden Cosets and Applications to Unclonable Cryptography | QCRYPT 2021 | regular | Andrea Coladangelo, Qipeng Liu, Mark Zhandry |
In 2012, Aaronson and Christiano introduced the idea of hidden subspace states to build public-key quantum money [STOC '12]. Since then, this idea has been applied to realize several other cryptographic primitives which enjoy some form of unclonability. In this work, we propose a generalization of hidden subspace states to hidden coset states. We study different unclonable properties of coset states and several applications: (*) We show that, assuming indistinguishability obfuscation (iO), hidden coset states possess a certain direct product hardness property, which immediately implies a tokenized signature scheme in the plain model. Previously, a tokenized signature scheme was known only relative to an oracle, from a work of Ben-David and Sattath [QCrypt '17]. (*) Combining a tokenized signature scheme with extractable witness encryption, we give a construction of an unclonable decryption scheme in the plain model. The latter primitive was recently proposed by Georgiou and Zhandry [ePrint '20], who gave a construction relative to a classical oracle. (*) We conjecture that coset states satisfy a certain natural monogamy-of-entanglement property. Assuming this conjecture is true, we remove the requirement for extractable witness encryption in our unclonable decryption construction. As potential evidence in support of the conjecture, we prove a weaker version of this monogamy property, which we believe will still be of independent interest. (*) Finally, we give the first construction of a copy-protection scheme for pseudorandom functions (PRFs) in the plain model. Our scheme is secure either assuming iO, onw-way functions (OWFs) and extractable witness encryption, or assuming iO, OWFs, compute-and-compare obfuscation and the conjectured monogamy property mentioned above. This is the first example of a copy-protection scheme with provable security in the plain model for a class of functions that is not evasive. |
|||
| New Approaches for Quantum Copy-Protection | TQC 2021 | invited ▸ presenter | Scott Aaronson, Qipeng Liu, Mark Zhandry, Ruizhe Zhang |
7 Posters
| Title | Conference | Co-authors |
|---|---|---|
| Quantum One-Time Programs, Revisited | QIP 2025 | Aparna Gupte, Justin Raizes, Bhaskar Roberts, Vinod Vaikuntanathan |
| The Black-Box Simulation Barrier Persists in a Fully Quantum World | QIP 2025 | Nai-Hui Chia, Kai-Min Chung, Xiao Liang |
| Quantum Key Leasing for PKE and FHE with a Classical Lessor | QIP 2025 | Orestis Chardouvelis, Vipul Goya, Aayush Jain |
| Unclonable Secret Sharing | QCRYPT 2024 | Prabhanjan Ananth, Vipul Goyal, Qipeng Liu |
Unclonable cryptography utilizes the principles of quantum mechanics to addresses cryptographic tasks that are impossible classically. We introduce a novel unclonable primitive in the context of secret sharing, called unclonable secret sharing (USS). In a USS scheme, there are n shareholders, each holding a share of a classical secret represented as a quantum state. They can recover the secret once all parties (or at least t parties) come together with their shares. Importantly, it should be infeasible to copy their own shares and send the copies to two non-communicating parties, enabling both of them to recover the secret. |
||
| Unclonable Secret Sharing | TQC 2024 | Prabhanjan Ananth, Vipul Goyal, Qipeng Liu |
| Collusion-Resistant Copy-Protection for Watermarkable Functionalities | QCRYPT 2022 | Qipeng Liu, Luowen Qian, Mark Zhandry |
| Quantum Copy-Protection from Hidden Subspaces | QIP 2020 | Ruizhe Zhang |
Committee service
| Conference | Committee | Position | Title |
|---|---|---|---|
| QIP 2026 | program | member | — |
| TQC 2025 | program | member | — |
| TQC 2024 | program | member | — |
Collaborators
| Co-author | Joint talks |
|---|---|
| Qipeng Liu | 8 |
| Mark Zhandry | 6 |
| Luowen Qian | 3 |
| Vipul Goyal | 3 |
| Aayush Jain | 2 |
| Andrea Coladangelo | 2 |
| Aparna Gupte | 2 |
| Bhaskar Roberts | 2 |
| Justin Raizes | 2 |
| Kai-Min Chung | 2 |
| Nai-Hui Chia | 2 |
| Orestis Chardouvelis | 2 |
| Prabhanjan Ananth | 2 |
| Ruizhe Zhang | 2 |
| Vinod Vaikuntanathan | 2 |
| Xiao Liang | 2 |
| Eric Culf | 1 |
| Fuyuki Kitagawa | 1 |
| Hart Montgomery | 1 |
| Scott Aaronson | 1 |