SearcharxivSearch

arXiv subjects

Stelvio Cimato

Publications and source records attributed to Stelvio Cimato.

7 recordsLinked to original sources

After Theft: From Revocation to Neutralization in the Custody of Quantum Clones

Encrypted quantum cloning enables the creation of multiple encrypted clones of an unknown quantum state while allowing only one effective decryption, with the decryption resource being intrinsically consumed in the process. In this paper, we argue that this property supports a distinctive custodial security primitive for post-compromise response. We consider a threat model in which an adversary steals an encrypted quantum clone but does not yet possess the corresponding decryption key. In such a scenario, a legitimate custodian may unseal a different trusted clone, thereby exhausting the sole available unsealing opportunity and rendering the stolen clone permanently useless. We argue that this mechanism is not adequately described as mere revocation. Rather, it realizes a stronger form of post-theft response, which we call neutralization. We formalize this distinction, locate it within a broader post-theft response space, and introduce a temporal threat model. We compare the mechanism with its closest classical analogue, showing that the classical case can reproduce the policy outcome only through external procedural composition. We finally interpret encrypted quantum cloning as a primitive for post-compromise quantum custody in distributed preservation settings, with prospective relevance for Cyber-Humanities-oriented preservation architectures.

quant-ph

Encrypted clones can leak: Classification of informative subsets in Quantum Encrypted Cloning

Encrypted cloning enables the redundant storage of an unknown qubit while remaining compatible with the no-cloning theorem, since only one clone can later be recovered through key-consuming decryption. Because encryption in this protocol is introduced to enable cloning-compatible redundancy rather than to guarantee confidentiality by design, its secrecy properties must be assessed explicitly. Here we classify the subsets of the encrypted-clone storage register into authorized, completely non-informative, and partially informative sets. We show that intermediate non-authorized subsets may retain only a restricted residual dependence on the input state, and we characterize exactly when this dependence occurs. The resulting leakage pattern is parity-dependent, revealing a structural confidentiality limitation of encrypted cloning.

quant-ph

Full characterization of informative subsets in Quantum Encrypted Cloning

Quantum encrypted cloning, introduced by Yamaguchi and Kempf, is a Pauli-based protocol that distributes an unknown input qubit into multiple encrypted signal-noise pairs in such a way that redundancy is created without violating the no-cloning theorem, since at most one clone can later be perfectly recovered through an appropriate decoding procedure. In previous work we showed that unauthorized subsets of the storage register are not, in general, completely uninformative, and we identified a parity-dependent leakage pattern. In the present work we extend the analysis to subsets that also include the transformed source qubit A. Exploiting the purity of the global encoded state and the complementarity between storage-only subsets and subsets containing A, we derive a full classification of the informativeness of all sets of the form $H=\{A\}\cup C$. We show that these subsets are fully informative in the generic case. Two exceptions arise. First, if all pairs are incomplete and |C|<n, then the reduced state is completely uninformative. Second, if |C|=n, n is odd, and the number q of signal qubits in C is even, then the reduced state is partially informative. In this latter case, the residual dependence on the input state is confined to the y-component of the Bloch vector. These results provide a complete parity-based characterization of leakage for subsets containing the transformed input qubit.

quant-ph

Assessing the ROI of Cyber Threat Intelligence: An Operational and Financial Evaluation Framework

Quantifying the Return on Investment (ROI) of Cyber Threat Intelligence (CTI) poses a measurement problem: successful prevention produces non-events that leave no observable financial signal, which makes CTI spending resistant to traditional cost-benefit analysis. CTI's indirect contribution through downstream controls further complicates causal attribution and the investment boundary. We develop a framework with two main contributions: (i) the Threat Intelligence Effectiveness Index (TIEI), a weighted geometric maturity measure spanning intelligence quality, enrichment, integration, and operational impact that penalizes weak links; and (ii) a breakeven-first financial method that treats the annual probability of a scope-matched material event and CTI-attributable mitigation as unknowns and characterizes the combinations required for positive ROI. The financial boundary includes core CTI ownership and the incremental downstream costs required to operationalize intelligence. Applied to illustrative finance and healthcare scenarios, the method demonstrates how organizations can derive scope-matched breakeven requirements without treating broad sector prevalence as an event probability. A TIEI-conditioned PERT simulation illustrates how uncertainty can be propagated after an organization supplies a defensible event probability, while operational and qualitative indicators support attribution where avoided events cannot be observed. By linking operational maturity to an auditable financial boundary, the framework provides a reproducible basis for CTI investment decisions.

cs.CR

Beyond the Canonical Protocol: Quantum Encrypted Cloning from Secret-Sharing Access Structures

Quantum encrypted cloning shows that an unknown quantum state can be distributed into multiple encrypted copies without contradicting the no-cloning theorem: each copy is unusable on its own, but can be redeemed together with a suitable quantum key. Recent work has related canonical encrypted-cloning protocols to particular forms of quantum secret sharing. Here we take the converse perspective: instead of mapping a given encrypted-cloning protocol into QSS, we use QSS access structures as a design library from which encrypted-cloning schemes can be extracted. The criterion is access-structural. A QSS scheme supports a quantum encrypted-cloning structure whenever it contains a family of qualified sets with a non-qualified common intersection. The common subsystem is interpreted as the key, while the non-common parts are interpreted as encrypted clones relative to that key. Thus quantum encrypted cloning does not require a new notion of recoverability beyond QSS; what changes is the operational reading of QSS constituents as a mechanism for delayed and alternative redemption opportunities. This viewpoint separates redemption from perfect secrecy. Perfect QSS yields encrypted-cloning schemes with forbidden non-qualified subsystems, whereas ramp QSS naturally allows intermediate, partially informative non-redeeming subsystems. The resulting framework broadens quantum encrypted cloning from a specific protocol to a general access-structure primitive. We illustrate the extraction principle with threshold-like, ramp, hierarchical, and compartmented architectures, showing how encrypted clones may be symmetric or asymmetric, individual or composite, perfectly hidden or leaky. Equivalently, these constructions can be viewed as overlapping erasure-recovery regions of an isometric quantum code. This establishes secret sharing as a systematic design language for encrypted quantum redundancy.

quant-ph

Pay-with-a-Selfie, a human-centred digital payment system

Mobile payment systems are increasingly used to simplify the way in which money transfers and transactions can be performed. We argue that, to achieve their full potential as economic boosters in developing countries, mobile payment systems need to rely on new metaphors suitable for the business models, lifestyle, and technology availability conditions of the targeted communities. The Pay-with-a-Group-Selfie (PGS) project, funded by the Melinda & Bill Gates Foundation, has developed a micro-payment system that supports everyday small transactions by extending the reach of, rather than substituting, existing payment frameworks. PGS is based on a simple gesture and a readily understandable metaphor. The gesture - taking a selfie - has become part of the lifestyle of mobile phone users worldwide, including non-technology-savvy ones. The metaphor likens computing two visual shares of the selfie to ripping a banknote in two, a technique used for decades for delayed payment in cash-only markets. PGS is designed to work with devices with limited computational power and when connectivity is patchy or not always available. Thanks to visual cryptography techniques PGS uses for computing the shares, the original selfie can be recomposed simply by stacking the shares, preserving the analogy with re-joining the two parts of the banknote.

cs.ET

Constrained Role Mining

Role Based Access Control (RBAC) is a very popular access control model, for long time investigated and widely deployed in the security architecture of different enterprises. To implement RBAC, roles have to be firstly identified within the considered organization. Usually the process of (automatically) defining the roles in a bottom up way, starting from the permissions assigned to each user, is called {\it role mining}. In literature, the role mining problem has been formally analyzed and several techniques have been proposed in order to obtain a set of valid roles. Recently, the problem of defining different kind of constraints on the number and the size of the roles included in the resulting role set has been addressed. In this paper we provide a formal definition of the role mining problem under the cardinality constraint, i.e. restricting the maximum number of permissions that can be included in a role. We discuss formally the computational complexity of the problem and propose a novel heuristic. Furthermore we present experimental results obtained after the application of the proposed heuristic on both real and synthetic datasets, and compare the resulting performance to previous proposals

cs.CR