<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Alexandru Cojocaru | LIP6 - Équipe QI</title><link>https://qi.lip6.fr/fr/people/alexandru-cojocaru/</link><atom:link href="https://qi.lip6.fr/fr/people/alexandru-cojocaru/index.xml" rel="self" type="application/rss+xml"/><description>Alexandru Cojocaru</description><generator>Hugo Blox Builder (https://hugoblox.com)</generator><language>fr</language><copyright>© 2022 LIP6 Quantum Information Team</copyright><lastBuildDate>Tue, 05 Jan 2021 00:00:00 +0000</lastBuildDate><image><url>https://qi.lip6.fr/media/icon_hu_bdeccd9e706ea09d.png</url><title>Alexandru Cojocaru</title><link>https://qi.lip6.fr/fr/people/alexandru-cojocaru/</link></image><item><title>Secure Quantum Two-Party Computation: Impossibility and Constructions</title><link>https://qi.lip6.fr/fr/publication/3096949-secure-quantum-two-party-computation-impossibility-and-constructions/</link><pubDate>Tue, 05 Jan 2021 00:00:00 +0000</pubDate><guid>https://qi.lip6.fr/fr/publication/3096949-secure-quantum-two-party-computation-impossibility-and-constructions/</guid><description>&lt;p&gt;Secure two-party computation considers the problem of two parties computing a joint function of their private inputs without revealing anything beyond the output of the computation. In this work, we take the first steps towards understanding the setting in which the two parties want to evaluate a joint quantum functionality while using only a classical channel between them. Our first result indicates that it is in general impossible to realize a two-party quantum functionality against malicious adversaries with black-box simulation, relying only on classical channels. The negative result stems from reducing the existence of a black-box simulator to an extractor for classical proof of quantum knowledge, which in turn leads to violation of the quantum no-cloning. Next, we introduce the notion of oblivious quantum function evaluation (OQFE). An OQFE is a two-party quantum cryptographic primitive with one fully classical party (Alice) whose input is (a classical description of a) quantum unitary, $U$, and a quantum party (Bob) whose input is a quantum state, $\psi$. In particular, Alice receives a classical output corresponding to the measurement of $U(\psi)$ while Bob receives no output. In OQFE, Bob remains oblivious to Alice&amp;rsquo;s input, while Alice learns nothing about $\psi$ more than what can be learned from the output. We present two constructions, one secure against semi-honest parties and the other against malicious parties. Due to the no-go result mentioned above, we consider what is arguably the best possible notion obtainable in our model concerning malicious adversaries: one-sided simulation security. Our protocol relies on the assumption of injective homomorphic trapdoor OWFs, which in turn rely on the LWE problem. As a result, we put forward a first, simple and modular, construction of one-sided quantum two-party computation and quantum oblivious transfer over classical networks.&lt;/p&gt;</description></item><item><title>Security Limitations of Classical-Client Delegated Quantum Computing</title><link>https://qi.lip6.fr/fr/publication/2997004-security-limitations-of-classical-client-delegated-quantum-computing/</link><pubDate>Mon, 07 Dec 2020 00:00:00 +0000</pubDate><guid>https://qi.lip6.fr/fr/publication/2997004-security-limitations-of-classical-client-delegated-quantum-computing/</guid><description>&lt;p&gt;Secure delegated quantum computing allows a computationally weak client to outsource an arbitrary quantum computation to an untrusted quantum server in a privacy-preserving manner. One of the promising candidates to achieve classical delegation of quantum computation is classical-client remote state preparation ($RSP_{CC}$), where a client remotely prepares a quantum state using a classical channel. However, the privacy loss incurred by employing $RSP_{CC}$ as a sub-module is unclear. In this work, we investigate this question using the Constructive Cryptography framework by Maurer and Renner (ICS'11). We first identify the goal of $RSP_{CC}$ as the construction of ideal RSP resources from classical channels and then reveal the security limitations of using $RSP_{CC}$. First, we uncover a fundamental relationship between constructing ideal RSP resources (from classical channels) and the task of cloning quantum states. Any classically constructed ideal RSP resource must leak to the server the full classical description (possibly in an encoded form) of the generated quantum state, even if we target computational security only. As a consequence, we find that the realization of common RSP resources, without weakening their guarantees drastically, is impossible due to the no-cloning theorem. Second, the above result does not rule out that a specific $RSP_{CC}$ protocol can replace the quantum channel at least in some contexts, such as the Universal Blind Quantum Computing (UBQC) protocol of Broadbent et al. (FOCS &amp;lsquo;09). However, we show that the resulting UBQC protocol cannot maintain its proven composable security as soon as $RSP_{CC}$ is used as a subroutine. Third, we show that replacing the quantum channel of the above UBQC protocol by the $RSP_{CC}$ protocol QFactory of Cojocaru et al. (Asiacrypt &amp;lsquo;19), preserves the weaker, game-based, security of UBQC.&lt;/p&gt;</description></item><item><title>QFactory: classically-instructed remote secret qubits preparation</title><link>https://qi.lip6.fr/fr/publication/2164592-qfactory-classically-instructed-remote-secret-qubits-preparation/</link><pubDate>Sun, 08 Dec 2019 00:00:00 +0000</pubDate><guid>https://qi.lip6.fr/fr/publication/2164592-qfactory-classically-instructed-remote-secret-qubits-preparation/</guid><description>&lt;p&gt;The functionality of classically-instructed remotely prepared random secret qubits was introduced in (Cojocaru et al 2018) as a way to enable classical parties to participate in secure quantum computation and communications protocols. The idea is that a classical party (client) instructs a quantum party (server) to generate a qubit to the server&amp;rsquo;s side that is random, unknown to the server but known to the client. Such task is only possible under computational assumptions. In this contribution we define a simpler (basic) primitive consisting of only BB84 states, and give a protocol that realizes this primitive and that is secure against the strongest possible adversary (an arbitrarily deviating malicious server). The specific functions used, were constructed based on known trapdoor one-way functions, resulting to the security of our basic primitive being reduced to the hardness of the Learning With Errors problem. We then give a number of extensions, building on this basic module: extension to larger set of states (that includes non-Clifford states); proper consideration of the abort case; and verifiablity on the module level. The latter is based on &amp;ldquo;blind self-testing&amp;rdquo;, a notion we introduced, proved in a limited setting and conjectured its validity for the most general case.&lt;/p&gt;</description></item><item><title>Complexity-theoretic limitations on blind delegated quantum computation</title><link>https://qi.lip6.fr/fr/publication/2164523-complexity-theoretic-limitations-on-blind-delegated-quantum-computation/</link><pubDate>Mon, 08 Jul 2019 00:00:00 +0000</pubDate><guid>https://qi.lip6.fr/fr/publication/2164523-complexity-theoretic-limitations-on-blind-delegated-quantum-computation/</guid><description>&lt;p&gt;Blind delegation protocols allow a client to delegate a computation to a server so that the server learns nothing about the input to the computation apart from its size. For the specific case of quantum computation we know that blind delegation protocols can achieve information-theoretic security. In this paper we prove, provided certain complexity-theoretic conjectures are true, that the power of information-theoretically secure blind delegation protocols for quantum computation (ITS-BQC protocols) is in a number of ways constrained. In the first part of our paper we provide some indication that ITS-BQC protocols for delegating $\sf BQP$ computations in which the client and the server interact only classically are unlikely to exist. We first show that having such a protocol with $O(n^d)$ bits of classical communication implies that $\mathsf{BQP} \subset \mathsf{MA/O(n^d)}$. We conjecture that this containment is unlikely by providing an oracle relative to which $\mathsf{BQP} \not\subset \mathsf{MA/O(n^d)}$. We then show that if an ITS-BQC protocol exists with polynomial classical communication and which allows the client to delegate quantum sampling problems, then there exist non-uniform circuits of size $2^{n - \mathsf{\Omega}(n/log(n))}$, making polynomially-sized queries to an $\sf NP^{NP}$ oracle, for computing the permanent of an $n \times n$ matrix. The second part of our paper concerns ITS-BQC protocols in which the client and the server engage in one round of quantum communication and then exchange polynomially many classical messages. First, we provide a complexity-theoretic upper bound on the types of functions that could be delegated in such a protocol, namely $\mathsf{QCMA/qpoly \cap coQCMA/qpoly}$. Then, we show that having such a protocol for delegating $\mathsf{NP}$-hard functions implies $\mathsf{coNP^{NP^{NP}}} \subseteq \mathsf{NP^{NP^{PromiseQMA}}}$.&lt;/p&gt;</description></item><item><title>On the possibility of classical client blind quantum computing</title><link>https://qi.lip6.fr/fr/publication/2164617-on-the-possibility-of-classical-client-blind-quantum-computing/</link><pubDate>Mon, 27 Aug 2018 00:00:00 +0000</pubDate><guid>https://qi.lip6.fr/fr/publication/2164617-on-the-possibility-of-classical-client-blind-quantum-computing/</guid><description>&lt;p&gt;We define the functionality of delegated pseudo-secret random qubit generator (PSRQG), where a classical client can instruct the preparation of a sequence of random qubits at some distant party. Their classical description is (computationally) unknown to any other party (including the distant party preparing them) but known to the client. We emphasize the unique feature that no quantum communication is required to implement PSRQG. This enables classical clients to perform a class of quantum communication protocols with only a public classical channel with a quantum server. A key such example is the delegated universal blind quantum computing. Using our functionality one could achieve a purely classical-client computational secure verifiable delegated universal quantum computing (also referred to as verifiable blind quantum computation). We give a concrete protocol (QFactory) implementing PSRQG, using the Learning-With-Errors problem to construct a trapdoor one-way function with certain desired properties (quantum-safe, two-regular, collision-resistant). We then prove the security in the Quantum-Honest-But-Curious setting and briefly discuss the extension to the malicious case.&lt;/p&gt;</description></item></channel></rss>