REVIEW 2 major objections 5 minor 128 references
Access Control Threatened by Quantum Entanglement
T0 review · 2 major / 5 minor · reviewed 2026-08-06 · deepseek-v4-flash
Pith's one-line read A classically secure access control system can leak a user's secret with certainty after a straightforward quantum upgrade.
desk verdict The Mermin-based breach idea is genuinely interesting, but the central proof as written violates the paper's own access matrix, so the core theorem is not established. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The central object is the lifting (LF): a request $(s,X,\mathrm{all})$ means user $s$ may perform any quantum operation on the composite system of quantum register $X$ and user $s$'s local memory $L[s]$, which is now assumed quantum. This one interpretive choice is what allows users to create entanglement across registers without any change to the access matrix. The carrier of both proofs is the Mermin inequality: the classical security theorem is derived from the classical side of that inequality, and the quantum attack consists of the multi-party strategy that violates it. The protective models replace (LF) by explicit rights over non-empty subsets of quantum registers, group labels, or entanglement flags, so that multi-register operations and entanglement themselves become governed objects.
What would settle it
Run the execution constructed for Theorem 3.3 on a quantum simulator, following the stated scheduler and programs: $w_1$ prepares a GHZ state over the second qubits of $C_1,\dots,C_n$, each $w_j$ applies the conditional phase, Hadamard, measures its qubit, and flips $B$ if the outcome is 1; the claim fails if the empirical frequency of $B(t_2) = A(t_1)$ does not converge to 1.
Extended reading notes
Core claim
The central discovery is Theorem 3.3: if registers $C_1,\dots,C_n$ become quantum and the right 'all' is interpreted through the lifting (LF), where a request $(s,X,\mathrm{all})$ authorizes any quantum operation on the composite of register $X$ and user $s$'s local quantum memory, then there exists an execution $(S,P)$ with mutual information $I(A(t_1); Obs(w_1,t_2)) = 1$ between the secret register and what user $w_1$ can observe. In this execution the users implement the quantum strategy for the Mermin game: $w_1$ prepares a GHZ state across the second qubits of the $C_j$ registers, each $w_j$ applies a conditional phase, a Hadamard, a measurement, and flips the public register $B$ if the outcome is 1. The parity of these flips matches the parity of the random string chosen by the trusted user $v$, so $B(t_2) = A(t_1)$ with certainty, whereas the classical system leaks at most $2^{-(n-7)/2}$ bits.
Load-bearing premise
The breach only occurs under the specific lifting (LF), where a user with right 'all' on a quantum register may perform any quantum operation on that register together with the user's own quantum local memory; if local memories remain classical or authorization is required for each multi-register operation, the attack cannot be run.
Editorial extensions
If this is right
- If the paper is right, any classical-quantum hybrid that adopts the (LF) lifting of 'all' should be considered vulnerable to complete one-bit secret leakage, even when the access matrix is unchanged and the users cannot communicate directly.
- The three proposed models, namely $k$-subsystem control, $k$-group control, and $k$-entanglement control, each preserve the classical leakage bound, so they provide concrete policy designs that block the demonstrated attack.
- Larger $k$ in these models increases flexibility but raises storage cost; in particular, subsystem control with $k = |Obj_q|$ needs a matrix with exponentially many columns, while group control keeps the matrix linear in the number of quantum registers.
- The flexibility comparisons show that SUBSYS, GRP, and ENT are not all comparable, so practical deployments will likely need hybrids, choosing different models for different object classes.
Reading between the lines
- The single-bit certainty result is best read as a lower bound on damage: repeating the strategy on independent GHZ blocks or splitting a longer secret into bits should generalize the leak to more than one bit, although the paper does not prove that extension.
- A system designer could sidestep this particular attack by keeping local memories classical, but that would prevent users from holding quantum data in scratch space; the paper's protective models suggest that security comes from making every multi-register quantum operation an explicit access-control decision.
- The role of the Mermin inequality here suggests a testable design heuristic: before adding quantum registers to a classically secure policy, check whether any Bell- or Mermin-type correlation strategy can simulate the policy's authorization steps; classical correlation bounds may not survive the quantum upgrade.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper formalizes a small multi-user access control system in the access-matrix model, proves a classical information-theoretic security bound (Theorem 3.1), and then claims that if the C_j registers are made quantum and the right 'all' is lifted to allow arbitrary operations on a register together with the user's local memory (LF), the same system becomes completely insecure (Theorem 3.3) because entangled users can violate Mermin's inequality. The paper then proposes three families of quantum access control models (subsystem, group, entanglement) and analyzes their security, flexibility, and efficiency.
Significance. If Theorem 3.3 were valid, the paper would provide the first explicit counterexample showing that a classically secure access control policy can be broken by a seemingly natural quantum lifting, with a clean explanation via Mermin's inequality. The paper is also valuable for proposing concrete access-control models with explicit control of multi-register operations and entanglement, and for giving a self-contained proof of the Mermin inequality variant. However, the central counterexample as currently written is not a valid execution of the system: the scheduler has w1 issue requests on C_2,...,C_n that the access matrix M1 does not authorize. The main threat result is therefore not established in the submitted version.
major comments (2)
- [§3.3, Theorem 3.3 proof] The scheduler construction is not an authorized execution. The proof sets s(2)=...=s(2n+1)=w1 to execute Line 1 of Figure 5 at a time when M_acc has already been set to M1 by v's Line 1. The proof states that Line 1 can be executed by swapping each C_j into L[w1], preparing the GHZ state there, and swapping back. Each such swap requires a request (w1,C_j,all) or an equivalent authorized operation. But under M1 (Figure 3), w1 holds 'all' only on C1 and 'flip' on B; the entries for C_2,...,C_n are empty. Hence Auth(w1,C_j,all)=false for j>1 under Definition 2.5, and the generated history is not authorized. The execution (S,P) is therefore not a valid execution of the access control system, so Theorem 3.3's claimed counterexample is not established. This is an internal error in the proof, not a disagreement about quantum consensus. A repair may be possible by preparing the GHZ state during the M0 phase (where w1 does have 'all' on every C_j) and only then invoking v's Line 1, but as written the proof fails.
- [§3.3, lifting (LF); §1 abstract] The breach is conditional on the specific lifting (LF), which requires both that local memories become quantum and that 'all' on X authorizes arbitrary operations on X together with L[s]. The paper's own protective models in Section 4 restore security precisely by rejecting this lifting and keeping local memories classical. This is not an internal inconsistency, because Theorem 3.3 explicitly assumes (LF), but the abstract and introduction state the threat to 'existing computer systems' in unconditional terms. The scope of the claimed threat should be qualified, or the paper should argue why (LF) is the canonical or inevitable lifting for a quantum upgrade, otherwise the headline claim is broader than what the scenario demonstrates.
minor comments (5)
- [Theorem 3.3 title] The title contains a typo: 'qantum' should be 'quantum'.
- [Lemma 3.2 title] The title contains a typo: 'ineqality' should be 'inequality'.
- [Figure 4] The entries of M2 are ambiguous: the row for w1 reads 'read all', which could be read as granting read access on every register, whereas the text explains that each w_j can read C_j and B. The figure should be made consistent with the prose.
- [§3.3, Theorem 3.3 proof] In the proof, Obs(w1,t2) is written as an ordered list 'B(t2), C_j(t2), L[w1](t2)', but Obs is defined in Theorem 3.1 as a set determined by the read entries of the access matrix at time t2. The notation should be aligned with that definition, and the dependences on j should be made explicit (if only C1 is readable at t2, then Obs should mention C1, not an unspecified C_j).
- [Theorem 4.4] The space complexity expression contains a typo: the summand should be (N_q choose j), not (N_q choose k), so that the sum counts all non-empty subsets of size at most k.
Circularity Check
No material circularity: the main results rely on externally checkable Mermin/GHZ arguments and only a non-load-bearing self-citation; the Theorem 3.3 scheduling issue is a proof gap, not circularity.
full rationale
The claimed derivation chain is self-contained rather than circular. Theorem 3.1's classical security bound is reduced to the variant of the Mermin inequality in Lemma 3.2, and Appendix A.2 proves that inequality from first principles via elementary Fourier-style estimates, so the bound does not presuppose the theorem it supports. Theorem 3.3's quantum breach is constructed from the standard Mermin/GHZ strategy: the proof directly computes Pr[B(t2)=A(t1)]=1 from the GHZ state, and no parameter is fitted to the claimed mutual information value. The protection models in Section 4 are evaluated against Theorem 3.1 by ensuring that no entanglement is generated among C_1,...,C_n; that is a policy-construction check rather than a reuse of the breach conclusion. The only self-citation, [121] by co-author Ying, is used to motivate treating composite subsystems as virtual objects in Definitions 4.1 and 4.2; it is not the origin of Theorem 3.1 or 3.3, so it is not load-bearing. One internal issue exists but is not circular: in the proof of Theorem 3.3, the scheduler places the GHZ preparation at s(2)...s(2n+1) after v has already written M1, at which point Auth(w1,C_j,all)=false for j>1 under the matrix in Figure 3, so the constructed history is not authorised according to Definition 2.5. That is a repairable proof-ordering error rather than an equivalence-to-inputs, and therefore it does not raise the circularity score.
Assumptions & free parameters
assumptions (4)
- domain assumption The lifting (LF): request (s,X,all) authorizes any quantum operation on the composite system of quantum register X and the local memory L[s], which is assumed quantum (L: Sub -> HInt).
- domain assumption Standard quantum mechanics: unitary evolution, measurement postulates, entanglement, and the GHZ state behavior as used in the Mermin game.
- domain assumption The access matrix Macc and the fixed program P_v describe the system's behavior; subjects other than v follow their prescribed programs and the scheduler is adversarial.
- standard math Probabilistic graphical model decomposition and d-separation rules used in the proof of Theorem 3.1.
Cite this review
Pith. "Pith review of Access Control Threatened by Quantum Entanglement." pith.science (2026). https://pith.science/paper/74VNDC6I
@misc{pith2026250702622,
author = {Pith},
title = {Pith review of: Access Control Threatened by Quantum Entanglement},
year = {2026},
howpublished = {\url{https://pith.science/paper/74VNDC6I}},
note = {Machine review of arXiv:2507.02622}
}
read the original abstract
Access control is a cornerstone of computer security that prevents unauthorised access to resources. In this paper, we study access control in quantum computer systems. We present the first explicit scenario of a security breach when a classically secure access control system is straightforwardly adapted to the quantum setting. The breach is ultimately due to that quantum mechanics allows the phenomenon of entanglement and violates Mermin inequality, a multi-party variant of the celebrated Bell inequality. This reveals a threat from quantum entanglement to access control if existing computer systems integrate with quantum computing. To protect against such threat, we propose several new models of quantum access control, and rigorously analyse their security, flexibility and efficiency.
Figures
Figures from the paper (6 more)
Reference graph
Works this paper leans on
-
[1]
Dorit Aharonov, Michael Ben-Or, and Elad Eban. 2008. Interactive proofs for quantum computations. arXiv:0810.5375 [quant-ph]
arXiv 2008
-
[2]
Dorit Aharonov, Maor Ganz, and Loick Magnin. 2017. Dining philoso- phers, leader election and ring size problems, in the quantum setting. arXiv:1707.01187 [quant-ph]
work page Pith review arXiv 2017
-
[3]
Yuri Alexeev, Maximilian Amsler, Marco Antonio Barroca, Sanzio Bassini, Torey Battelle, Daan Camps, David Casanova, Young Jay Choi, Frederic T Chong, Charles Chung, et al. 2024. Quantum-centric supercomputing for materials science: A perspective on challenges and future directions. Future Generation Computer Systems 160 (2024), 666–710
2024
-
[4]
Rotem Arnon-Friedman, Renato Renner, and Thomas Vidick. 2019. Simple and tight device-independent security proofs. SIAM J. Comput. 48, 1 (2019), 181–225
2019
-
[5]
Alain Aspect, Jean Dalibard, and Gérard Roger. 1982. Experimental test of Bell’s inequalities using time-varying analyzers. Physical Review Letters 49, 25 (1982), 1804
1982
-
[6]
Jonathan Barrett, Lucien Hardy, and Adrian Kent. 2005. No signaling and quantum key distribution. Physical Review Letters 95, 1 (2005), 010503
2005
-
[7]
Elliott Bell and Leonard J
D. Elliott Bell and Leonard J. La Padula. 1976. Secure computer system: Unified exposition and Multics interpretation . Technical Report ESD-TR-75-306. The MITRE Corporation, Bedford, MA
1976
-
[8]
John S. Bell. 1964. On the Einstein Podolsky Rosen paradox. Physics Physique Fizika 1, 3 (1964), 195
1964
Show all 128 references
-
[9]
Elisa Bertino, Piero Andrea Bonatti, and Elena Ferrari. 2000. TRBAC: A temporal role-based access control model. In Proceedings of the fifth ACM workshop on Role-based access control. 21–30
2000
-
[10]
Kenneth J. Biba. 1977. Integrity considerations for secure computer systems . Technical Report ESD-TR-76-372. The MITRE Corporation, Bedford, MA
1977
-
[11]
Evered, Alexandra A
Dolev Bluvstein, Simon J. Evered, Alexandra A. Geim, Sophie H. Li, Hengyun Zhou, Tom Manovitz, Sepehr Ebadi, Madelyn Cain, Marcin Kalinowski, Dominik Hangleiter, J. Pablo Bonilla Ataides, Nishad Maskara, Iris Cong, Xun Gao, Pedro Sales Rodriguez, Thomas Karolyshyn, Giulia Seme...
2023
-
[12]
Gilles Brassard, Anne Broadbent, and Alain Tapp. 2005. Recasting Mermin’s multi-player game into the framework of pseudo-telepathy. Quantum Informa- tion and Computation 5, 7 (2005), 538–550
2005
-
[13]
Sergey Bravyi, Graeme Smith, and John A. Smolin. 2016. Trading classical and quantum computational resources. Physical Review X 6, 2 (2016), 021043
2016
-
[14]
Fitzsimons, and Elham Kashefi
Anne Broadbent, Joseph F. Fitzsimons, and Elham Kashefi. 2009. Universal blind quantum computation. In 2009 50th annual IEEE symposium on foundations of computer science. 517–526
2009
-
[15]
Andrew M. Childs. 2005. Secure assisted quantum computation. Quantum Information & Computation 5, 6 (2005), 456–466
2005
-
[16]
Kai-Min Chung, Yaoyun Shi, and Xiaodi Wu. 2015. Physical random- ness extractors: Generating random numbers with minimal assumptions. arXiv:1402.4797 [quant-ph]
2015 arXiv
-
[17]
Clark and David R
David D. Clark and David R. Wilson. 1987. A comparison of commercial and military computer security policies. In 1987 IEEE Symposium on Security and Privacy. 184–184
1987
-
[18]
Clauser, Michael A
John F. Clauser, Michael A. Horne, Abner Shimony, and Richard A. Holt. 1969. Proposed experiment to test local hidden-variable theories. Physical Review Letters 23, 15 (1969), 880
1969
-
[19]
Roger Colbeck. 2009. Quantum and relativistic protocols for secure multi-party computation. Ph. D. Dissertation. University of Cambridge
2009
-
[20]
Roger Colbeck and Renato Renner. 2012. Free randomness can be amplified. Nature Physics 8, 6 (2012), 450–453
2012
-
[21]
Wu, and Dan Boneh
Henry Corrigan-Gibbs, David J. Wu, and Dan Boneh. 2017. Quantum operating systems. In Proceedings of the 16th Workshop on Hot Topics in Operating Systems . 76–81
2017
-
[22]
Matthew Coudron and Henry Yuen. 2014. Infinite randomness expansion with a constant number of devices. In Proceedings of the forty-sixth annual ACM symposium on Theory of computing . 427–436
2014
-
[23]
Wenhan Dai, Tianyi Peng, and Moe Z. Win. 2020. Quantum queuing delay. IEEE Journal on Selected Areas in Communications 38, 3 (2020), 605–618
2020
-
[24]
Tannu, Prashant J
Poulami Das, Swamit S. Tannu, Prashant J. Nair, and Moinuddin Qureshi. 2019. A case for multi-programming quantum computers. In Proceedings of the 52nd Annual IEEE/ACM International Symposium on Microarchitecture . 291–303
2019
-
[25]
Delle Donne, M
C. Delle Donne, M. Iuliano, B. van der Vecht, G. M. Ferreira, H. Jirovská, T. J. W. van der Steenhoven, A. Dahlberg, M. Skrzypczyk, D. Fioretto, M. Teller, et al
-
[26]
Dorothy E. Denning. 1976. A lattice model of secure information flow.Commun. ACM 19, 5 (1976), 236–243
1976
-
[27]
Peter J. Denning. 1971. Third generation computer systems. ACM Computing Surveys (CSUR) 3, 4 (1971), 175–216. 13
1971
-
[28]
Downs, Jerzy R
Deborah D. Downs, Jerzy R. Rub, Kenneth C. Kung, and Carole S. Jordan. 1985. Issues in discretionary access control. In 1985 IEEE symposium on security and privacy. 208–208
1985
-
[29]
Vedran Dunjko, Elham Kashefi, and Anthony Leverrier. 2012. Blind quantum computing with weak coherent pulses. Physical Review Letters 108, 20 (2012), 200502
2012
-
[30]
Frederic Dupuis and Omar Fawzi. 2019. Entropy accumulation with improved second-order term. IEEE Transactions on Information Theory 65, 11 (2019), 7596–7612
2019
-
[31]
Frederic Dupuis, Omar Fawzi, and Renato Renner. 2020. Entropy accumulation. Communications in Mathematical Physics 379, 3 (2020), 867–913
2020
-
[32]
Gujarati, Sergey Bravyi, Antonio Mezza- capo, Charles Hadfield, and Sarah Sheldon
Andrew Eddins, Mario Motta, Tanvi P. Gujarati, Sergey Bravyi, Antonio Mezza- capo, Charles Hadfield, and Sarah Sheldon. 2022. Doubling the size of quantum simulators by entanglement forging. PRX Quantum 3, 1 (2022), 010309
2022
-
[33]
Artur K. Ekert. 1991. Quantum cryptography based on Bell’s theorem. Physical Review Letters 67, 6 (1991), 661
1991
-
[34]
Yuan Feng, Runyao Duan, and Mingsheng Ying. 2012. Bisimulation for quantum processes. ACM Transactions on Programming Languages and Systems (TOPLAS) 34, 4 (2012), 1–43
2012
-
[35]
Yuan Feng, Sanjiang Li, and Mingsheng Ying. 2022. Verification of distributed quantum programs. ACM Transactions on Computational Logic (TOCL) 23, 3 (2022), 1–40
2022
-
[36]
Ferraiolo and D
David F. Ferraiolo and D. Richard Kuhn. 1992. Role-based access controls. 15th National Computer Security Conference (1992) , 554–563
1992
-
[37]
Ferraiolo, Ravi Sandhu, Serban Gavrila, D
David F. Ferraiolo, Ravi Sandhu, Serban Gavrila, D. Richard Kuhn, and Ra- maswamy Chandramouli. 2001. Proposed NIST standard for role-based access control. ACM Transactions on Information and System Security (TISSEC) 4, 3 (2001), 224–274
2001
-
[38]
Fitzsimons
Joseph F. Fitzsimons. 2017. Private quantum computation: an introduction to blind quantum computing and related protocols. npj Quantum Information 3, 1 (2017), 23
2017
-
[39]
Fitzsimons and Elham Kashefi
Joseph F. Fitzsimons and Elham Kashefi. 2017. Unconditionally verifiable blind quantum computation. Physical Review A 96, 1 (2017), 012303
2017
-
[40]
Freedman and John F
Stuart J. Freedman and John F. Clauser. 1972. Experimental test of local hidden- variable theories. Physical Review Letters 28, 14 (1972), 938
1972
-
[41]
Rodrigo Gallego, Lluis Masanes, Gonzalo De La Torre, Chirag Dhara, Leandro Aolita, and Antonio Acín. 2013. Full randomness from arbitrarily deterministic events. Nature communications 4, 1 (2013), 2654
2013
-
[42]
Jay Gambetta. 2022. Expanding the IBM Quantum roadmap to anticipate the future of quantum-centric supercomputing. IBM Research Blog (2022)
2022
-
[43]
Jay Gambetta. 2022. Quantum-centric supercomputing: The next wave of computing. IBM Research Blog (2022)
2022
-
[44]
Gay and Rajagopal Nagarajan
Simon J. Gay and Rajagopal Nagarajan. 2005. Communicating quantum pro- cesses. In Proceedings of the 32nd ACM SIGPLAN-SIGACT Symposium on Princi- ples of Programming languages . 145–157
2005
-
[45]
Emmanouil Giortamis, Francisco Romão, Nathaniel Tornow, and Pramod Bha- totia. 2024. QOS: A quantum operating system. arXiv:2406.19120 [quant-ph]
2024 arXiv
-
[46]
Vittorio Giovannetti, Lorenzo Maccone, Tomoyuki Morimae, and Terry G. Rudolph. 2013. Efficient universal blind quantum computation. Physical Review Letters 111, 23 (2013), 230501
2013
-
[47]
Scott Graham and Peter J
G. Scott Graham and Peter J. Denning. 1971. Protection: principles and practice. In Proceedings of the May 16-18, 1972, spring joint computer conference . 417–429
1971
-
[48]
Greenberger, Michael A
Daniel M. Greenberger, Michael A. Horne, Abner Shimony, and Anton Zeilinger
-
[49]
Lov K. Grover. 1996. A fast quantum mechanical algorithm for database search. In Proceedings of the 28th Annual ACM Symposium on Theory of Computing (STOC ’96). 212–219
1996
-
[50]
Laszlo Gyongyosi and Sandor Imre. 2019. Entanglement access control for the quantum internet. Quantum Information Processing 18 (2019), 1–17
2019
-
[51]
Steiger, Torsten Hoefler, and Matthias Troyer
Thomas Häner, Damian S. Steiger, Torsten Hoefler, and Matthias Troyer. 2021. Distributed quantum computing with QMPI. In Proceedings of the International Conference for High Performance Computing, Networking, Storage and Analysis . 1–13
2021
-
[52]
Harrison, Walter L
Michael A. Harrison, Walter L. Ruzzo, and Jeffrey D. Ullman. 1976. Protection in operating systems. Commun. ACM 19, 8 (1976), 461–471
1976
-
[53]
Harrow, Avinatan Hassidim, and Seth Lloyd
Aram W. Harrow, Avinatan Hassidim, and Seth Lloyd. 2009. Quantum algorithm for linear systems of equations. Physical Review Letters 103, 15 (2009), 150502
2009
-
[54]
Brown, Diana Franklin, Frederic T
Jeff Heckey, Shruti Patil, Ali JavadiAbhari, Adam Holmes, Daniel Kudrow, Ken- neth R. Brown, Diana Franklin, Frederic T. Chong, and Margaret Martonosi
-
[55]
Lewis, Scott Anderson, and Jake Cooke
Reid Honan, Trent W. Lewis, Scott Anderson, and Jake Cooke. 2020. A quan- tum computer operating system. In Algorithms and Architectures for Parallel Processing: 20th International Conference, ICA3PP 2020 . 415–431
2020
-
[56]
Hu, David Ferraiolo, and D
Vincent C. Hu, David Ferraiolo, and D. Richard Kuhn. 2006.Assessment of access control systems. US Department of Commerce, National Institute of Standards and Technology
2006
-
[57]
Hu, David Ferraiolo, Rick Kuhn, Arthur R
Vincent C. Hu, David Ferraiolo, Rick Kuhn, Arthur R. Friedman, Alan J. Lang, Margaret M. Cogdell, Adam Schnitzer, Kenneth Sandlin, Robert Miller, and Karen Scarfone. 2013. Guide to attribute based access control (ABAC) definition and considerations. NIST Special Publication 80...
2013
-
[58]
Hu and Karen Ann Kent
Vincent C. Hu and Karen Ann Kent. 2012. Guidelines for access control system evaluation metrics. US Department of Commerce, National Institute of Standards and Technology
2012
-
[59]
Philippe Jorrand and Marie Lalire. 2004. Toward a quantum process algebra. In Proceedings of the 1st Conference on Computing Frontiers . 111–119
2004
-
[60]
Richard Jozsa and Noah Linden. 2003. On the role of entanglement in quantum- computational speed-up. Proceedings of the Royal Society of London. Series A: Mathematical, Physical and Engineering Sciences 459, 2036 (2003), 2011–2032
2003
-
[61]
Max Kessler and Rotem Arnon-Friedman. 2020. Device-independent random- ness amplification and privatization. IEEE Journal on Selected Areas in Informa- tion Theory 1, 2 (2020), 568–584
2020
-
[62]
Soheil Khadirsharbiyani, Movahhed Sadeghi, Mostafa Eghbali Zarch, Jagadish Kotra, and Mahmut Taylan Kandemir. 2023. TRIM: crossTalk-awaRe qubIt Mapping for multiprogrammed quantum systems. In 2023 IEEE International Conference on Quantum Software (QSW) . 138–148
2023
-
[63]
Weicheng Kong, Junchao Wang, Yongjian Han, Yuchun Wu, Yu Zhang, Menghan Dou, Yuan Fang, and Guoping Guo. 2021. Origin Pilot: A quantum operating system for effecient usage of quantum resources. arXiv:2105.10730 [quant-ph]
2021 arXiv
-
[64]
Butler W. Lampson. 1969. Dynamic protection structures. In Proceedings of the November 18-20, 1969, fall joint computer conference . 27–38
1969
-
[65]
Butler W. Lampson. 1974. Protection. ACM SIGOPS Operating Systems Review 8, 1 (1974), 18–24
1974
-
[66]
LaPadula and D
Leonard J. LaPadula and D. Elliot Bell. 1973. Secure computer systems: A mathe- matical model. Technical Report ESD–TR–73–278–I. The MITRE Corporation, Bedford, MA
1973
-
[67]
Jinyang Li, Yuhong Song, Yipei Liu, Jianli Pan, Lei Yang, Travis Humble, and Weiwen Jiang. 2025. QuSplit: Achieving both high fidelity and throughput via job splitting on noisy quantum computers. arXiv:2501.12492 [quant-ph]
2025 arXiv
-
[68]
Zhang, and Yipeng Huang
Zirui Li, Minghao Guo, Mayank Barad, Wei Tang, Eddy Z. Zhang, and Yipeng Huang. 2024. A case for quantum circuit cutting for NISQ applications: Impact of topology, determinism, and sparsity. arXiv:2412.17929 [quant-ph]
2024 arXiv
-
[69]
Chenxu Liu, Meng Wang, Samuel A Stein, Yufei Ding, and Ang Li
-
[70]
Lei Liu and Xinglei Dou. 2021. QuCloud: A new qubit mapping mechanism for multi-programming quantum computing in cloud environment. In 2021 IEEE International Symposium on High-Performance Computer Architecture (HPCA) . 167–178
2021
-
[71]
Lei Liu and Xinglei Dou. 2024. QuCloud+: A holistic qubit mapping scheme for single/multi-programming on 2D/3D NISQ quantum computers. ACM Transactions on Architecture and Code Optimization 21, 1 (2024), 1–27
2024
-
[72]
Seth Lloyd. 1996. Universal quantum simulators. Science 273, 5278 (1996), 1073–1078
1996
-
[73]
Córcoles, and Jay Gambetta
Ryan Mandelbaum, Antonio D. Córcoles, and Jay Gambetta. 2024. IBM’s big bet on the quantum-centric supercomputer: recent advances point the way to useful classical-quantum hybrids. IEEE Spectrum 61, 9 (2024), 24–33
2024
-
[74]
Pérez-Delgado, and Joseph F
Atul Mantri, Carlos A. Pérez-Delgado, and Joseph F. Fitzsimons. 2013. Optimal blind quantum computation. Physical Review Letters 111, 23 (2013), 230502
2013
-
[75]
Dominic Mayers and Andrew Yao. 1998. Quantum cryptography with imperfect apparatus. In Proceedings 39th Annual Symposium on Foundations of Computer Science (Cat. No. 98CB36280) . 503–509
1998
-
[76]
David Mermin
N. David Mermin. 1990. Extreme quantum entanglement in a superposition of macroscopically distinct states. Physical Review Letters 65, 15 (1990), 1838–1840
1990
-
[77]
Giulia Meuli, Mathias Soeken, Martin Roetteler, Nikolaj Bjorner, and Giovanni De Micheli. 2019. Reversible pebbling game for quantum memory management. In 2019 Design, Automation & Test in Europe Conference & Exhibition (DATE) . 288–291
2019
-
[78]
Allen Mi, Shuwen Deng, and Jakub Szefer. 2022. Securing reset operations in nisq quantum computers. In Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security . 2279–2293
2022
-
[79]
Miller and Yaoyun Shi
Carl A. Miller and Yaoyun Shi. 2016. Robust protocols for securely expanding randomness and distributing keys using untrusted quantum devices. Journal of the ACM (JACM) 63, 4 (2016), 1–63
2016
-
[80]
Miller and Yaoyun Shi
Carl A. Miller and Yaoyun Shi. 2017. Universal security for randomness expan- sion from the spot-checking protocol. SIAM J. Comput. 46, 4 (2017), 1304–1335
2017
-
[81]
Kosuke Mitarai and Keisuke Fujii. 2021. Constructing a virtual two-qubit gate by sampling single-qubit operations. New Journal of Physics 23, 2 (2021), 023021
2021
-
[82]
Tomoyuki Morimae. 2012. Continuous-variable blind quantum computation. Physical Review Letters 109, 23 (2012), 230502
2012
-
[83]
Tomoyuki Morimae. 2014. Verification for measurement-only blind quantum computing. Physical Review A 89, 6 (2014), 060302. 14 Access Control Threatened by Quantum Entanglement
2014
-
[84]
Tomoyuki Morimae, Vedran Dunjko, and Elham Kashefi. 2015. Ground state blind quantum computation on AKLT state. Quantum Information & Computa- tion 15, 3–4 (2015), 200–234
2015
-
[85]
Tomoyuki Morimae and Keisuke Fujii. 2012. Blind topological measurement- based quantum computation. Nature communications 3, 1 (2012), 1036
2012
-
[86]
Tomoyuki Morimae and Keisuke Fujii. 2013. Blind quantum computation protocol in which Alice only makes measurements. Physical Review A 87, 5 (2013), 050301
2013
-
[87]
Tomoyuki Morimae and Takeshi Koshiba. 2013. Composable security of measuring-Alice blind quantum computation. arXiv:1306.2113 [quant-ph]
2013 arXiv
-
[88]
Nielsen and Isaac L
Michael A. Nielsen and Isaac L. Chuang. 2010. Quantum Computation and Quantum Information: 10th Anniversary Edition . Cambridge University Press
2010
-
[89]
Siyuan Niu and Aida Todri-Sanial. 2023. Enabling multi-programming mecha- nism for quantum computing in the NISQ era. Quantum 7 (2023), 925
2023
-
[90]
Yasuhiro Ohkura, Takahiko Satoh, and Rodney Van Meter. 2022. Simultaneous execution of quantum circuits on current and near-future NISQ systems. IEEE Transactions on Quantum Engineering 3 (2022), 1–10
2022
-
[91]
Aaron Orenstein and Vipin Chaudhary. 2024. QGroup: Parallel quantum job scheduling using dynamic programming. In 2024 IEEE International Conference on Quantum Computing and Engineering (QCE) , Vol. 1. 990–999
2024
-
[92]
Jaehong Park and Ravi Sandhu. 2004. The UCONABC usage control model. ACM Transactions on Information and System Security (TISSEC) 7, 1 (2004), 128–174
2004
-
[93]
Pascuzzi and Antonio D
Vincent R. Pascuzzi and Antonio D. Córcoles. 2024. Quantum-centric super- computing for physics research. arXiv:2408.11741 [quant-ph]
2024 arXiv
-
[94]
Judea Pearl. 2000. Causality: Models, Reasoning, and Inference . Cambridge University Press, USA
2000
-
[95]
Harrow, Maris Ozols, and Xiaodi Wu
Tianyi Peng, Aram W. Harrow, Maris Ozols, and Xiaodi Wu. 2020. Simulating large quantum circuits on a small quantum computer. Physical review letters 125, 15 (2020), 150504
2020
-
[96]
Stefano Pironio, Antonio Acín, Nicolas Brunner, Nicolas Gisin, Serge Massar, and Valerio Scarani. 2009. Device-independent quantum key distribution secure against collective attacks. New Journal of Physics 11, 4 (2009), 045021
2009
-
[97]
Boyer de La Giroday, Dzmitry N
Stefano Pironio, Antonio Acín, Serge Massar, A. Boyer de La Giroday, Dzmitry N. Matsukevich, Peter Maunz, Steven Olmschenk, David Hayes, Lefroy Luo, T. An- drew Manning, et al. 2010. Random numbers certified by Bell’s theorem. Nature 464, 7291 (2010), 1021–1024
2010
-
[98]
Christophe Piveteau and David Sutter. 2024. Circuit knitting with classical com- munication. IEEE Transactions on Information Theory 70, 4 (2024), 2734–2745
2024
-
[99]
Puterman
Martin L. Puterman. 2014. Markov decision processes: discrete stochastic dynamic programming. John Wiley & Sons
2014
-
[100]
Michael O. Rabin. 1980.𝑁 -process synchronization by 4· log2𝑁 -valued shared variable. In 21st Annual Symposium on Foundations of Computer Science (sfcs 1980). 407–410
1980
-
[101]
Smith, Prakash Murali, and Frederic T
Gokul Subramanian Ravi, Kaitlin N. Smith, Prakash Murali, and Frederic T. Chong. 2021. Adaptive job and resource management for the growing quan- tum cloud. In 2021 IEEE International Conference on Quantum Computing and Engineering (QCE). 301–312
2021
-
[102]
Reichardt, Falk Unger, and Umesh Vazirani
Ben W. Reichardt, Falk Unger, and Umesh Vazirani. 2013. Classical command of quantum systems. Nature 496, 7446 (2013), 456–460
2013
-
[103]
Salonik Resch, Anthony Gutierrez, Joon Suk Huh, Srikant Bharadwaj, Yasuko Eckert, Gabriel Loh, Mark Oskin, and Swamit Tannu. 2021. Accelerating varia- tional quantum algorithms using circuit concurrency. arXiv:2109.01714 [cs.ET]
2021 arXiv
-
[104]
Jerome H. Saltzer. 1974. Protection and the control of information sharing in Multics. Commun. ACM 17, 7 (1974), 388–402
1974
-
[105]
Saltzer and Michael D
Jerome H. Saltzer and Michael D. Schroeder. 1975. The protection of information in computer systems. Proc. IEEE 63, 9 (1975), 1278–1308
1975
-
[106]
Ravi Sandhu and Jaehong Park. 2003. Usage control: A vision for next generation access control. In Computer Network Security: Second International Workshop on Mathematical Methods, Models, and Architectures for Computer Network Security, MMM-ACNS 2003. 17–31
2003
-
[107]
Sandhu, Edward J
Ravi S. Sandhu, Edward J. Coyne, Hal L. Feinstein, and Charles E. Youman. 1996. Role-based access control models. In IEEE Computer. Vol. 29. 38–47
1996
-
[108]
Sandhu and Pierangela Samarati
Ravi S. Sandhu and Pierangela Samarati. 1994. Access control: principle and practice. IEEE communications magazine 32, 9 (1994), 40–48
1994
-
[109]
Peter W. Shor. 1994. Algorithms for quantum computation: discrete logarithms and factoring. In Proceedings 35th Annual IEEE Symposium on Foundations of Computer Science (FOCS ’94) . 124–134
1994
-
[110]
Wei Tang, Teague Tomesh, Martin Suchara, Jeffrey Larson, and Margaret Martonosi. 2021. CutQC: Using small quantum computers for large quan- tum circuit evaluations. In Proceedings of the 26th ACM International Conference on Architectural Support for Programming Languages and O...
2021
-
[111]
Seiichiro Tani, Hirotada Kobayashi, and Keiji Matsumoto. 2012. Exact quantum algorithms for the leader election problem. ACM Transactions on Computation Theory (TOCT) 4, 1 (2012), 1–24
2012
-
[112]
Theodoros Trochatos, Sanjay Deshpande, Chuanqi Xu, Yao Lu, Yongshan Ding, and Jakub Szefer. 2024. Dynamic pulse switching for protection of quantum computation on untrusted clouds. In 2024 IEEE International Symposium on Hardware Oriented Security and Trust (HOST) . 404–414
2024
-
[113]
Theodoros Trochatos and Jakub Szefer. 2024. Quantum operating system support for quantum trusted execution environments. arXiv:2410.08486 [quant- ph]
2024 arXiv
-
[114]
Theodoros Trochatos, Chuanqi Xu, Sanjay Deshpande, Yao Lu, Yongshan Ding, and Jakub Szefer. 2023. Hardware architecture for a quantum computer trusted execution environment. arXiv:2308.03897 [cs.ET]
2023 arXiv
-
[115]
Theodoros Trochatos, Chuanqi Xu, Sanjay Deshpande, Yao Lu, Yongshan Ding, and Jakub Szefer. 2023. A quantum computer trusted execution environment. IEEE Computer Architecture Letters 22, 2 (2023), 177–180
2023
-
[116]
Umesh Vazirani and Thomas Vidick. 2012. Certifiable quantum dice: or, true random number generation secure against quantum adversaries. In Proceedings of the forty-fourth annual ACM symposium on Theory of computing . 61–76
2012
-
[117]
Umesh Vazirani and Thomas Vidick. 2014. Fully device-independent quantum key distribution. Physical Review Letters 113 (2014), 140501. Issue 14
2014
-
[118]
Anbang Wu, Hezi Zhang, Gushu Li, Alireza Shabani, Yuan Xie, and Yufei Ding. 2022. AutoComm: a framework for enabling efficient communication in distributed quantum programs. In 2022 55th IEEE/ACM International Symposium on Microarchitecture (MICRO). 1027–1041
2022
-
[119]
Chuanqi Xu, Jessie Chen, Allen Mi, and Jakub Szefer. 2023. Securing nisq quantum computer reset operations against higher energy state attacks. In Pro- ceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security. 594–607
2023
-
[120]
Chuanqi Xu, Ferhat Erata, and Jakub Szefer. 2023. Exploration of power side- channel vulnerabilities in quantum computer controllers. In Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security . 579–593
2023
-
[121]
Mingsheng Ying, Yuan Feng, and Nengkun Yu. 2013. Quantum information- flow security: Noninterference and access control. In 2013 IEEE 26th Computer Security Foundations Symposium. 130–144
2013
-
[122]
Mingsheng Ying, Li Zhou, Yangjia Li, and Yuan Feng. 2022. A proof system for disjoint parallel quantum programs. Theoretical Computer Science 897 (2022), 164–184
2022
-
[123]
Xinwen Zhang, Francesco Parisi-Presicce, Ravi Sandhu, and Jaehong Park. 2005. Formal model and policy specification of usage control. ACM Transactions on Information and System Security (TISSEC) 8, 4 (2005), 351–387
2005
-
[124]
Zhicheng Zhang and Mingsheng Ying. 2024. Atomicity in distributed quantum computing. arXiv:2404.18592 [quant-ph] 15 A Proof Details A.1 Proof of Theorem 3.1 In this appendix, we present the full proof of Theorem 3.1. The proof uses notations and tools in probabilistic graphica...
2024 arXiv
-
[1990]
American Journal of Physics 58, 12 (1990), 1131–1143
Bell’s theorem without inequalities. American Journal of Physics 58, 12 (1990), 1131–1143
1990
-
[2015]
In Proceedings of the Twentieth International Conference on Archi- tectural Support for Programming Languages and Operating Systems
Compiler management of communication and parallelism for quantum computation. In Proceedings of the Twentieth International Conference on Archi- tectural Support for Programming Languages and Operating Systems . 445–456
-
[2023]
arXiv:2309.14432 [quant-ph]
Quantum memory: A missing piece in quantum computing units. arXiv:2309.14432 [quant-ph]
-
[2025]
Nature 639, 8054 (2025), 321–328
An operating system for executing applications on quantum network nodes. Nature 639, 8054 (2025), 321–328
2025
Reviewed August 6, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.