<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Petros Wallden | LIP6 - Équipe QI</title><link>https://qi.lip6.fr/fr/people/petros-wallden/</link><atom:link href="https://qi.lip6.fr/fr/people/petros-wallden/index.xml" rel="self" type="application/rss+xml"/><description>Petros Wallden</description><generator>Hugo Blox Builder (https://hugoblox.com)</generator><language>fr</language><copyright>© 2022 LIP6 Quantum Information Team</copyright><lastBuildDate>Wed, 27 Jan 2021 00:00:00 +0000</lastBuildDate><image><url>https://qi.lip6.fr/media/icon_hu_bdeccd9e706ea09d.png</url><title>Petros Wallden</title><link>https://qi.lip6.fr/fr/people/petros-wallden/</link></image><item><title>The Quantum Cut-and-Choose Technique and Quantum Two-Party Computation</title><link>https://qi.lip6.fr/fr/publication/3123360-the-quantum-cut-and-choose-technique-and-quantum-two-party-computation/</link><pubDate>Wed, 27 Jan 2021 00:00:00 +0000</pubDate><guid>https://qi.lip6.fr/fr/publication/3123360-the-quantum-cut-and-choose-technique-and-quantum-two-party-computation/</guid><description>&lt;p&gt;The application and analysis of the Cut-and-Choose technique in protocols secure against quantum adversaries is not a straightforward transposition of the classical case, among other reasons due to the difficulty to use rewinding in the quantum realm. We introduce a Quantum Computation Cut-and-Choose (QC-CC) technique which is a generalisation of the classical Cut-and-Choose in order to build quantum protocols secure against quantum covert adversaries. Such adversaries can deviate arbitrarily provided that their deviation is not detected. As an application of the QC-CC we give a protocol for securely performing two-party quantum computation with classical input/output. As basis we use secure delegated quantum computing (Broadbent et al 2009), and in particular the garbled quantum computation of (Kashefi et al 2016) that is secure against only a weak specious adversaries, defined in (Dupuis et al 2010). A unique property of these protocols is the separation between classical and quantum communications and the asymmetry between client and server, which enables us to sidestep the quantum rewinding issues. This opens the prospect of using the QC-CC to other quantum protocols with this separation. In our proof of security we adapt and use (at different parts) two quantum rewinding techniques, namely Watrous&amp;rsquo; oblivious q-rewinding (Watrous 2009) and Unruh&amp;rsquo;s special q-rewinding (Unruh 2012). Our protocol achieves the same functionality as in previous works (e.g. Dupuis et al 2012), however using the QC-CC technique on the protocol from (Kashefi et al 2016) leads to the following key improvements: (i) only one-way offline quantum communication is necessary , (ii) only one party (server) needs to have involved quantum technological abilities, (iii) only minimal extra cryptographic primitives are required, namely one oblivious transfer for each input bit and quantum-safe commitments.&lt;/p&gt;</description></item><item><title>Security Limitations of Classical-Client Delegated Quantum Computing</title><link>https://qi.lip6.fr/fr/publication/2997004-security-limitations-of-classical-client-delegated-quantum-computing/</link><pubDate>Mon, 07 Dec 2020 00:00:00 +0000</pubDate><guid>https://qi.lip6.fr/fr/publication/2997004-security-limitations-of-classical-client-delegated-quantum-computing/</guid><description>&lt;p&gt;Secure delegated quantum computing allows a computationally weak client to outsource an arbitrary quantum computation to an untrusted quantum server in a privacy-preserving manner. One of the promising candidates to achieve classical delegation of quantum computation is classical-client remote state preparation ($RSP_{CC}$), where a client remotely prepares a quantum state using a classical channel. However, the privacy loss incurred by employing $RSP_{CC}$ as a sub-module is unclear. In this work, we investigate this question using the Constructive Cryptography framework by Maurer and Renner (ICS'11). We first identify the goal of $RSP_{CC}$ as the construction of ideal RSP resources from classical channels and then reveal the security limitations of using $RSP_{CC}$. First, we uncover a fundamental relationship between constructing ideal RSP resources (from classical channels) and the task of cloning quantum states. Any classically constructed ideal RSP resource must leak to the server the full classical description (possibly in an encoded form) of the generated quantum state, even if we target computational security only. As a consequence, we find that the realization of common RSP resources, without weakening their guarantees drastically, is impossible due to the no-cloning theorem. Second, the above result does not rule out that a specific $RSP_{CC}$ protocol can replace the quantum channel at least in some contexts, such as the Universal Blind Quantum Computing (UBQC) protocol of Broadbent et al. (FOCS &amp;lsquo;09). However, we show that the resulting UBQC protocol cannot maintain its proven composable security as soon as $RSP_{CC}$ is used as a subroutine. Third, we show that replacing the quantum channel of the above UBQC protocol by the $RSP_{CC}$ protocol QFactory of Cojocaru et al. (Asiacrypt &amp;lsquo;19), preserves the weaker, game-based, security of UBQC.&lt;/p&gt;</description></item><item><title>QFactory: classically-instructed remote secret qubits preparation</title><link>https://qi.lip6.fr/fr/publication/2164592-qfactory-classically-instructed-remote-secret-qubits-preparation/</link><pubDate>Sun, 08 Dec 2019 00:00:00 +0000</pubDate><guid>https://qi.lip6.fr/fr/publication/2164592-qfactory-classically-instructed-remote-secret-qubits-preparation/</guid><description>&lt;p&gt;The functionality of classically-instructed remotely prepared random secret qubits was introduced in (Cojocaru et al 2018) as a way to enable classical parties to participate in secure quantum computation and communications protocols. The idea is that a classical party (client) instructs a quantum party (server) to generate a qubit to the server&amp;rsquo;s side that is random, unknown to the server but known to the client. Such task is only possible under computational assumptions. In this contribution we define a simpler (basic) primitive consisting of only BB84 states, and give a protocol that realizes this primitive and that is secure against the strongest possible adversary (an arbitrarily deviating malicious server). The specific functions used, were constructed based on known trapdoor one-way functions, resulting to the security of our basic primitive being reduced to the hardness of the Learning With Errors problem. We then give a number of extensions, building on this basic module: extension to larger set of states (that includes non-Clifford states); proper consideration of the abort case; and verifiablity on the module level. The latter is based on &amp;ldquo;blind self-testing&amp;rdquo;, a notion we introduced, proved in a limited setting and conjectured its validity for the most general case.&lt;/p&gt;</description></item><item><title>Methods for Classically Simulating Noisy Networked Quantum Architectures</title><link>https://qi.lip6.fr/fr/publication/2164610-methods-for-classically-simulating-noisy-networked-quantum-architectures/</link><pubDate>Tue, 05 Nov 2019 00:00:00 +0000</pubDate><guid>https://qi.lip6.fr/fr/publication/2164610-methods-for-classically-simulating-noisy-networked-quantum-architectures/</guid><description>&lt;p&gt;As research on building scalable quantum computers advances, it is important to be able to certify their correctness. Due to the exponential hardness of classically simulating quantum computation, straight-forward verification via this means fails. However, we can classically simulate small scale quantum computations and hence we are able to test that devices behave as expected in this domain. This constitutes the first step towards obtaining confidence in the anticipated quantum-advantage when we extend to scales that can no longer be simulated. Real devices have restrictions due to their architecture and limitations due to physical imperfections and noise. In this paper we extend the usual ideal simulations by considering those effects. We provide a general methodology and framework for constructing simulations which emulate the physical system. These simulations should provide a benchmark for realistic devices and guide experimental research in the quest for quantum-advantage. To illustrate our methodology we give examples that involve networked architectures and the noise-model of the device developed by the Networked Quantum Information Technologies Hub (NQIT). For our simulations we use, with suitable modification, the classical simulator of Bravyi and Gosset while the specific problems considered belong to the Instantaneous Quantum Polynomial-time class. This class is believed to be hard for classical computational devices, and is regarded as a promising candidate for the first demonstration of quantum-advantage. We first consider a subclass of IQP, defined by Bermejo-Vega et al, involving two-dimensional dynamical quantum simulators, and then general instances of IQP, restricted to the architecture of NQIT.&lt;/p&gt;</description></item><item><title>Cyber security in the quantum era</title><link>https://qi.lip6.fr/fr/publication/2164382-cyber-security-in-the-quantum-era/</link><pubDate>Mon, 01 Apr 2019 00:00:00 +0000</pubDate><guid>https://qi.lip6.fr/fr/publication/2164382-cyber-security-in-the-quantum-era/</guid><description/></item><item><title>On the possibility of classical client blind quantum computing</title><link>https://qi.lip6.fr/fr/publication/2164617-on-the-possibility-of-classical-client-blind-quantum-computing/</link><pubDate>Mon, 27 Aug 2018 00:00:00 +0000</pubDate><guid>https://qi.lip6.fr/fr/publication/2164617-on-the-possibility-of-classical-client-blind-quantum-computing/</guid><description>&lt;p&gt;We define the functionality of delegated pseudo-secret random qubit generator (PSRQG), where a classical client can instruct the preparation of a sequence of random qubits at some distant party. Their classical description is (computationally) unknown to any other party (including the distant party preparing them) but known to the client. We emphasize the unique feature that no quantum communication is required to implement PSRQG. This enables classical clients to perform a class of quantum communication protocols with only a public classical channel with a quantum server. A key such example is the delegated universal blind quantum computing. Using our functionality one could achieve a purely classical-client computational secure verifiable delegated universal quantum computing (also referred to as verifiable blind quantum computation). We give a concrete protocol (QFactory) implementing PSRQG, using the Learning-With-Errors problem to construct a trapdoor one-way function with certain desired properties (quantum-safe, two-regular, collision-resistant). We then prove the security in the Quantum-Honest-But-Curious setting and briefly discuss the extension to the malicious case.&lt;/p&gt;</description></item><item><title>Garbled Quantum Computation</title><link>https://qi.lip6.fr/fr/publication/2164557-garbled-quantum-computation/</link><pubDate>Fri, 07 Apr 2017 00:00:00 +0000</pubDate><guid>https://qi.lip6.fr/fr/publication/2164557-garbled-quantum-computation/</guid><description>&lt;p&gt;The universal blind quantum computation protocol (UBQC) enables an almost classical client to delegate a quantum computation to an untrusted quantum server (in the form of a garbled quantum circuit) while the security for the client is unconditional. In this contribution, we explore the possibility of extending the verifiable UBQC, to achieve further functionalities following the analogous research for classical circuits (Yao 1986). First, exploring the asymmetric nature of UBQC (the client preparing only single qubits, while the server runs the entire quantum computation), we present a “Yao”-type protocol for secure two-party quantum computation. Similar to the classical setting, our quantum Yao protocol is secure against a specious (quantum honest-but-curious) garbler, but in our case, against a (fully) malicious evaluator. Unlike the previous work on quantum two-party computation of Dupuis et al., 2010, we do not require any online-quantum communication between the garbler and the evaluator and, thus, no extra cryptographic primitive. This feature will allow us to construct a simple universal one-time compiler for any quantum computation using one-time memory, in a similar way to the classical work of Goldwasser et al., 2008, while more efficiently than the previous work of Broadbent et al., 2013.&lt;/p&gt;</description></item><item><title>Optimised resource construction for verifiable quantum computation</title><link>https://qi.lip6.fr/fr/publication/2164566-optimised-resource-construction-for-verifiable-quantum-computation/</link><pubDate>Wed, 08 Mar 2017 00:00:00 +0000</pubDate><guid>https://qi.lip6.fr/fr/publication/2164566-optimised-resource-construction-for-verifiable-quantum-computation/</guid><description>&lt;p&gt;Recent developments have brought the possibility of achieving scalable quantum networks and quantum devices closer. From the computational point of view these emerging technologies become relevant when they are no longer classically simulatable. Hence a pressing challenge is the construction of practical methods to verify the correctness of the outcome produced by universal or non-universal quantum devices. A promising approach that has been extensively explored is the scheme of verification via encryption through blind quantum computation. We present here a new construction that simplifies the required resources for any such verifiable protocol. We obtain an overhead that is linear in the size of the input (computation), while the security parameter remains independent of the size of the computation and can be made exponentially small (with a small extra cost). Furthermore our construction is generic and could be applied to any universal or non-universal scheme with a given underlying graph.&lt;/p&gt;</description></item><item><title>Rigidity of quantum steering and one-sided device-independent verifiable quantum computation</title><link>https://qi.lip6.fr/fr/publication/2164570-rigidity-of-quantum-steering-and-one-sided-device-independent-verifiable-quantum-computation/</link><pubDate>Tue, 21 Feb 2017 00:00:00 +0000</pubDate><guid>https://qi.lip6.fr/fr/publication/2164570-rigidity-of-quantum-steering-and-one-sided-device-independent-verifiable-quantum-computation/</guid><description>&lt;p&gt;The relationship between correlations and entanglement has played a major role in understanding quantum theory since the work of Einstein et al (1935 Phys. Rev. 47 777–80). Tsirelson proved that Bell states, shared among two parties, when measured suitably, achieve the maximum non-local correlations allowed by quantum mechanics (Cirel&amp;rsquo;son 1980 Lett. Math. Phys. 4 93–100). Conversely, Reichardt et al showed that observing the maximal correlation value over a sequence of repeated measurements, implies that the underlying quantum state is close to a tensor product of maximally entangled states and, moreover, that it is measured according to an ideal strategy (Reichardt et al 2013 Nature 496 456–60). However, this strong rigidity result comes at a high price, requiring a large number of entangled pairs to be tested. In this paper, we present a significant improvement in terms of the overhead by instead considering quantum steering where the device of the one side is trusted. We first demonstrate a robust one-sided device-independent version of self-testing, which characterises the shared state and measurement operators of two parties up to a certain bound. We show that this bound is optimal up to constant factors and we generalise the results for the most general attacks. This leads us to a rigidity theorem for maximal steering correlations. As a key application we give a one-sided device-independent protocol for verifiable delegated quantum computation, and compare it to other existing protocols, to highlight the cost of trust assumptions. Finally, we show that under reasonable assumptions, the states shared in order to run a certain type of verification protocol must be unitarily equivalent to perfect Bell states.&lt;/p&gt;</description></item></channel></rss>