<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Samuel Bouaziz--Ermann | LIP6 - Équipe QI</title><link>https://qi.lip6.fr/fr/people/samuel-bouaziz--ermann/</link><atom:link href="https://qi.lip6.fr/fr/people/samuel-bouaziz--ermann/index.xml" rel="self" type="application/rss+xml"/><description>Samuel Bouaziz--Ermann</description><generator>Hugo Blox Builder (https://hugoblox.com)</generator><language>fr</language><copyright>© 2022 LIP6 Quantum Information Team</copyright><lastBuildDate>Tue, 09 Apr 2024 00:00:00 +0000</lastBuildDate><image><url>https://qi.lip6.fr/media/icon_hu_bdeccd9e706ea09d.png</url><title>Samuel Bouaziz--Ermann</title><link>https://qi.lip6.fr/fr/people/samuel-bouaziz--ermann/</link></image><item><title>Towards the Impossibility of Quantum Public Key Encryption with Classical Keys from One-Way Functions</title><link>https://qi.lip6.fr/fr/publication/4540950-towards-the-impossibility-of-quantum-public-key-encryption-with-classical-keys-from-one-way-functions/</link><pubDate>Tue, 09 Apr 2024 00:00:00 +0000</pubDate><guid>https://qi.lip6.fr/fr/publication/4540950-towards-the-impossibility-of-quantum-public-key-encryption-with-classical-keys-from-one-way-functions/</guid><description>&lt;p&gt;There has been a recent interest in proposing quantum protocols whose security relies on weaker computational assumptions than their classical counterparts. Importantly to our work, it has been recently shown that public-key encryption (PKE) from one-way functions (OWF) is possible if we consider quantum public keys. Notice that we do not expect classical PKE from OWF given the impossibility results of Impagliazzo and Rudich (STOC'89). However, the distribution of quantum public keys is a challenging task. Therefore, the main question that motivates our work is if quantum PKE from OWF is possible if we have classical public keys. Such protocols are impossible if ciphertexts are also classical, given the impossibility result of Austrin et al.(CRYPTO'22) of quantum enhanced key-agreement (KA) with classical communication. In this paper, we focus on black-box separation for PKE with classical public key and quantum ciphertext from OWF under the polynomial compatibility conjecture, first introduced in Austrin et al.. More precisely, we show the separation when the decryption algorithm of the PKE does not query the OWF. We prove our result by extending the techniques of Austrin et al. and we show an attack for KA in an extended classical communication model where the last message in the protocol can be a quantum state.&lt;/p&gt;</description></item><item><title>Quantum security of subset cover problems</title><link>https://qi.lip6.fr/fr/publication/3832954-quantum-security-of-subset-cover-problems/</link><pubDate>Thu, 01 Jun 2023 00:00:00 +0000</pubDate><guid>https://qi.lip6.fr/fr/publication/3832954-quantum-security-of-subset-cover-problems/</guid><description>&lt;p&gt;The subset cover problem for $k \geq 1$ hash functions, which can be seen as an extension of the collision problem, was introduced in 2002 by Reyzin and Reyzin to analyse the security of their hash-function based signature scheme HORS. The security of many hash-based signature schemes relies on this problem or a variant of this problem (e.g. HORS, SPHINCS, SPHINCS+, \dots). Recently, Yuan, Tibouchi and Abe (2022) introduced a variant to the subset cover problem, called restricted subset cover, and proposed a quantum algorithm for this problem. In this work, we prove that any quantum algorithm needs to make $\Omega\left(k^{-\frac{2^{k-1}}{2^k-1}}\cdot N^{\frac{2^{k-1}-1}{2^k-1}}\right)$ queries to the underlying hash functions to solve the restricted subset cover problem, which essentially matches the query complexity of the algorithm proposed by Yuan, Tibouchi and Abe. We also analyze the security of the general $(r,k)$-subset cover problem, which is the underlying problem that implies the unforgeability of HORS under a $r$-chosen message attack (for $r \geq 1$). We prove that a generic quantum algorithm needs to make $\Omega\left(N^{k/5}\right)$ queries to the underlying hash functions to find a $(1,k)$-subset cover. We also propose a quantum algorithm that finds a $(r,k)$-subset cover making $O\left(N^{k/(2+2r)}\right)$ queries to the $k$ hash functions.&lt;/p&gt;</description></item></channel></rss>