4
program roles
50
collaborators
2009–2019
years active
Contributions
QIP QCrypt TQC talk poster presenter award · △program ◇steering ○organizing · filled = chair
8 Talks
| Title | Conference | Type | Co-authors |
|---|---|---|---|
| Composable and finite computational security of quantum message transmission | QCRYPT 2019 | regular | Fabio Banfi, Ueli Maurer, Jiamin Zhu |
Recent research in quantum cryptography has led to the development of schemes that encrypt and authenticate quantum messages with computational security. The security definitions used so far in the literature are asymptotic, game-based, and not known to be composable. We show how to define finite, composable, computational security for secure quantum message transmission. The new definitions do not involve any games or oracles, they are directly operational: a scheme is secure if it transforms an insecure channel and a shared key into an ideal secure channel from Alice to Bob, i.e., one which only allows Eve to block messages and learn their size, but not change them or read them. By modifying the ideal channel to provide Eve with more or less capabilities, one gets an array of different security notions. By design these transformations are composable, resulting in composable security. Crucially, the new definitions are finite. Security does not rely on the asymptotic hardness of a computational problem. Instead, one proves a finite reduction: if an adversary can distinguish the constructed (real) channel from the ideal one (for some fixed security parameters), then she can solve a finite instance of some computational problem. Such a finite statement is needed to make security claims about concrete implementations. We then prove that (slightly modified versions of) protocols proposed in the literature satisfy these composable definitions. And finally, we study the relations between some game-based definitions and our composable ones. In particular, we look at notions of quantum authenticated encryption and QCCA2, and show that they suffer from the same issues as their classical counterparts: they exclude certain protocols which are arguably secure. |
|||
| Quantum authentication with key recycling | QCRYPT 2017 | regular ▸ presenter | — |
| Composability in Quantum Cryptography | QCRYPT 2017 | tutorial ▸ presenter | — |
| Quantum-Proof Multi-Source Randomness Extractors in the Markov Model | QCRYPT 2016 | regular | Rotem Arnon-Friedman, Volkher Scholz |
| Quantum Boxes: A Framework for Modeling and Composing Quantum Reactive Systems | QIP 2016 | regular ▸ presenter | Christian Matt, Ueli Maurer, Renato Renner, Björn Tackmann |
| Quantum-proof multi-source randomness extractors in the Markov model | QIP 2016 | regular | ▸Rotem Arnon-Friedman, Volkher Scholz |
| Quantum cryptography with local Bell tests | QCRYPT 2012 | regular | ▸Charles Ci Wen Lim, Marco Tomamichel, Renato Renner, Nicolas Gisin |
| Key recycling in authentication | TQC 2012 | regular ▸ presenter | — |
9 Posters
| Title | Conference | Co-authors |
|---|---|---|
| Composable security in relativistic quantum cryptography | QIP 2018 | V. Vilasini, Lidia del Rio |
| Composable Security in Relativistic Quantum Cryptography* | QCRYPT 2017 | V. Vilasini, Lidia del Rio |
| Cryptographic security of quantum key distribution | QCRYPT 2013 | Renato Renner |
Although the secrecy condition for quantum key distribution (QKD) introduced by Renner is broadly accepted, it does not conform with the simulation-based notion of security used by the cryptographic community. In particular, previous arguments as to why this condition provides security do not consider parallel composition of protocols. We remedy this situation by giving the first complete proof that when combined with a notion of correctness, it implies cryptographic (simulation-based) security for QKD. To do this, we first revisit the notion of simulatable security necessary for a general protocol to be usable in a larger cryptographic context, and derive the corresponding security criterion for QKD. We then prove that the known notions of secrecy and correctness are sufficient to achieve this security criterion. We also illustrate the composition of various protocols with QKD with several examples. |
||
| Composable security of delegated quantum computation | QCRYPT 2013 | Vedran Dunjko, Joseph F. Fitzsimons, Renato Renner |
Delegating difficult computations to remote large computation facilities, with appropriate security guarantees, is a possible solution for the ever-growing needs of personal computing power. For delegated computation protocols to be usable in a larger context—or simply to securely run two protocols in parallel—the security definitions need to be composable. Here, we define composable security for delegated quantum computation, and prove that several known protocols are composable, including Broadbent, Fitzsimons and Kashefi’s Universal Blind Quantum Computation protocol.We distinguish between protocols which provide only blindness—the computation is hidden from the server—and those that are also verifiable—the client can check that it has received the correct result. We show that the composable security definition capturing both these notions can be reduced to a combination of two distinct stand-alone security definitions. |
||
| Continuous QKD and data encryption at up to 100 Gbit/s | QCRYPT 2013 | Hugo Zbinden, Nino Walenta, Olivier Guinnard, Raphael Houlmann, Charles Lim Ci Wen, Boris Korzh, Tommaso Lunghi, Nicolas Gisin, Andreas Burg, Jeremy Constantin, Matthieu Legré, Patrick Trinkler, Dario Caselunghe, Natalia Kulesza, Gregory Trolliet, Fabien Vannel, Pascal Junod, Olivier Auberson, Yoan Graf, Gilles Curchod, Gilles Habegger, Etienne Messerli, Luca Henzen, Christoph Keller, Christian Pendl, Michael Mühlberghuber, Christoph Roth, Norbert Felber, Frank Gürkaynak, Daniel Schöni, Beat Muheim |
We present the results of the project QCRYPT, a collaborate effort of eight research teams in Switzerland with the ambition to produce a complete and practical fiber based QKD and high speed encryption system. For the QKD part, we put the emphasis on continuous operation with a wavelength multiplexed service channel for synchronization and distillation, efficient hardware real-time distillation, finite key security analysis and frugal authentication. For the secure high-speed encryption of large data volumes, we present a system able to multiplex up to ten 10 Gbit/s Ethernet inputs, pass the 100 Gbit/s data stream through authenticated encryption before transmitting it over an optical fiber to the decryptor. The cipher cores apply and frequently refresh the quantum keys delivered by the QKD system. |
||
| Composability of secure delegated quantum computation | QIP 2013 | Renato Renner, Vedran Dunjko, Joseph F. Fitzsimons |
| Efficient QKD Postprocessing Algorithms | QCRYPT 2012 | Christoph Pacher, Gottfried Lechner, Oliver Maurhart, Momtchil Peev |
| On Trevisan's extractor in the context of quantum side information | QIP 2010 | Renato Renner |
| On the Power of Quantum Encryption Keys | QIP 2009 | Akinori Kawachi |
Committee service
| Conference | Committee | Position | Title |
|---|---|---|---|
| QCRYPT 2019 | program | member | — |
| TQC 2019 | program | member | — |
| QCRYPT 2018 | program | member | — |
| TQC 2016 | program | member | — |
Collaborators
| Co-author | Joint talks |
|---|---|
| Renato Renner | 6 |
| Joseph F. Fitzsimons | 2 |
| Lidia del Rio | 2 |
| Nicolas Gisin | 2 |
| Rotem Arnon-Friedman | 2 |
| Ueli Maurer | 2 |
| V. Vilasini | 2 |
| Vedran Dunjko | 2 |
| Volkher Scholz | 2 |
| Akinori Kawachi | 1 |
| Andreas Burg | 1 |
| Beat Muheim | 1 |
| Björn Tackmann | 1 |
| Boris Korzh | 1 |
| Charles Ci Wen Lim | 1 |
| Charles Lim Ci Wen | 1 |
| Christian Matt | 1 |
| Christian Pendl | 1 |
| Christoph Keller | 1 |
| Christoph Pacher | 1 |