VLDB 2026 Research / reviewers in the wild / expert
Samiran Bag
dblp:13/9586
· DBLP profile ↗
22ranked-venue papers
10as first author
6since 2021 · last 2024
0000-0002-3501-0829ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 15 · 9 first-author · 4 since 2021Computer networks · 3 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Systems, architecture and hardware · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Camel: E2E Verifiable Instant Runoff Voting without Tallying AuthoritiesabstractInstant Runoff Voting (IRV) is one example of ranked-choice voting. It provides many known benefits when used in elections, such as minimising vote splitting, ensuring few votes are wasted, and providing resistance to strategic voting. However, the voting and tallying procedures for IRV are much more complicated than those of plurality and are both error-prone and tedious. Many automated systems have been proposed to simplify these procedures in IRV. Some of these also employ cryptographic techniques to protect the secrecy of ballots and enable verification of the tally. Nearly all of these cryptographic systems require a set of trustworthy tallying authorities (TAs) to perform the decryption of votes and/or running of mix servers, which adds significant complexity to the implementation and election management. We address this issue by proposing Camel: an E2E verifiable solution for IRV that requires no TAs. Camel employs a novel representation and a universally verifiable shifting procedure for ballots that facilitate the elimination of candidates as required in an IRV election. We combine these with a homomorphic encryption scheme and zero-knowledge proofs to protect the secrecy of the ballots and enable any party to verify the well-formedness of the ballots and the correctness of the tally in an IRV election. We examine the security of Camel and prove it maintains ballot secrecy by limiting the learned information (namely the tally) against a set of colluding voters. Luke Harrison, Samiran Bag, Feng Hao 0001 |
AsiaCCS | 2 |
| 2024 | Owl: An Augmented Password-Authenticated Key Exchange Scheme
Feng Hao 0001, Samiran Bag, Liqun Chen 0002, Paul C. van Oorschot |
FC (2) | 2 |
| 2022 | VERICONDOR: End-to-End Verifiable Condorcet Voting without Tallying AuthoritiesabstractCondorcet voting, first proposed by Marquis de Condorcet in the 18th century, chooses a winner of an election as one that defeats every other candidate by a simple majority. According to Condorcet's criterion, a Condorcet winner is the socially optimal choice in a multi-candidate election. However, despite the crucial importance of this voting system in social-choice theory, it has not been widely used in practical applications. This is partly due to the complex tallying procedure, and also the fact that several candidates may form a tie. Existing systems that provide online Condorcet voting services in the real world try to speed up the tallying process by collecting and tallying Condorcet ballots in a digital form. However, they require voters to completely trust the server. In this paper, we propose VERICONDO, the first end-to-end verifiable Condorcet e-voting system without any tallying authorities. Our system allows a voter to fully verify the tallying integrity without involving any trustworthy tallying authorities and provides strong protection of the ballot secrecy. One main challenge in our work lies in proving the well-formedness of an encrypted ballot while being able to tally the ballots in a publicly verifiable yet privacy-preserving manner. We overcome this challenge by adopting a pairwise comparison matrix and applying a novel vector-sum technique to achieve exceptional efficiency. The overall computational cost per ballot is O (n2) where n is the number of candidates. This is probably the best that one may hope for given the use of a n x n matrix to record a Condorcet ballot. In case of a tie, we show how to apply known Condorcet methods to break the tie in a publicly verifiable manner. Finally, we present a prototype implementation and benchmark performance to show the feasibility of our system. Luke Harrison, Samiran Bag, Hang Luo 0001, Feng Hao 0001 |
AsiaCCS | 2 |
| 2022 | A New Leakage Resilient Symmetric Searchable Encryption Scheme for Phrase SearchabstractSymmetric searchable encryption (SSE) schemes are preferred over asymmetric ones for their lower computational cost. Owing to the big data size of most of the cloud applications, SSE with keyword search often yields a large number of search results matching the search criterion, but only a small portion of them is of actual interest. This results in unnecessary increase of network traffic. A customized search against a phrase instead of keywords can yield more specific and relevant search results and can reduce the network traffic. This motivates the idea of phrase search in SSE. Most of the existing symmetric key searchable encryption schemes either do not support phrase search or have unwanted leakage associated with them. In this paper, we propose a symmetric key searchable encryption scheme for phrase search that minimizes the leakage of information from search pattern and access pattern. We propose a probabilistic trapdoor generation algorithm for phrase search and thereby preve nt the leakage due to search pattern. In earlier SSE based schemes, an honest-but-curious server could always learn about the position of the sentences and keywords in the encrypted text after the search operation is performed. This is referred to as the leakage from access pattern. This may turn out to be a significant security concern owing to the prior knowledge of positions of certain sentences and keywords in certain documents. In this paper, we provide the access pattern secure encryption scheme such that, an honest-but-curious cloud server could not learn anything about the position of the phrase in the sentence even after the search. We implement a prototype of our scheme and validate it against commercial data and provide security and performance analysis to demonstrate its practicality. Samiran Bag, Indranil Ghosh Ray, Feng Hao 0001 |
SECRYPT | 1 |
| 2021 | Sharing is Caring: A collaborative framework for sharing security alerts
Muhammad Ajmal Azad, Samiran Bag, Feng Hao 0001 |
Comput. Commun. | 2 |
| 2021 | Privacy-preserving Crowd-sensed Trust Aggregation in the User-centeric Internet of People NetworksabstractToday we are relying on Internet technologies for numerous services, for example, personal communication, online businesses, recruitment, and entertainment. Over these networks, people usually create content, a skillful worker profile, and provide services that are normally watched and used by other users, thus developing a social network among people termed as the Internet of People. Malicious users could also utilize such platforms for spreading unwanted content that could bring catastrophic consequences to a social network provider and the society, if not identified on time. The use of trust management over these networks plays a vital role in the success of these services. Crowd-sensing people or network users for their views about certain content or content creators could be a potential solution to assess the trustworthiness of content creators and their content. However, the human involvement in crowd-sensing would have challenges of privacy preservation and preventing intentional assignment of the fake high score given to certain user/content. To address these challenges, in this article, we propose a novel trust model that evaluates the aggregate trustworthiness of the content creator and the content without compromising the privacy of the participating people in a crowdsource group. The proposed system has inherent properties of privacy protection of participants, performs operations in the decentralized setup, and considers the trust weights of participants in a private and secure way. The system ensures privacy of participants under the malicious and honest-but-curious adversarial models. We evaluated the performance of the system by developing a prototype and applying it to different real data from different online social networks. Muhammad Ajmal Azad, Charith Perera, Samiran Bag, Mahmoud Barhamgi, Feng Hao 0001 |
ACM Trans. Cyber Phys. Syst. | 3 |
| 2020 | Decentralized Self-Enforcing Trust Management System for Social Internet of ThingsabstractThe Internet of Things (IoT) is the network of connected computing devices that have the ability to transfer valued data between each other via the Internet without requiring human intervention. In such a connected environment, the social IoT (SIoT) has become an emerging trend where multiple IoT devices owned by users support communication within a social circle. Trust management in the SIoT network is imperative as trusting the information from compromised devices could lead to serious compromises within the network. It is important to have a mechanism where the devices and their users evaluate the trustworthiness of other devices and users before trusting the information sent by them. The privacy preservation, decentralization, and self-enforcing management without involving trusted third parties are the fundamental challenges in designing a trust management system for SIoT. To fulfill these challenges, this article presents a novel framework for computing and updating the trustworthiness of participants in the SIoT network in a self-enforcing manner without relying on any trusted third party. The privacy of the participants in the SIoT is protected by using homomorphic encryption in the decentralized setting. To achieve the properties of self-enforcement, the trust score of each device is automatically updated based on its previous trust score and the up-to-date tally of the votes by its peers in the network with zero-knowledge proofs (ZKPs) to enforce that every participant follows the protocol honestly. We evaluate the performance of the proposed scheme and present evaluation benchmarks by prototyping the main functionality of the system. The performance results show that the system has a linear increase in computation and communication overheads with more participants in the network. Furthermore, we prove the correctness, privacy, and security of the proposed system under a malicious adversarial model. Muhammad Ajmal Azad, Samiran Bag, Feng Hao 0001, Andrii Shalaginov |
IEEE Internet Things J. | 2 |
| 2020 | SEAL: Sealed-Bid Auction Without AuctioneersabstractWe propose the first auctioneer-free sealed-bid auction protocol with a linear computation and communication complexity O(c), c being the bit length of the bid price. Our protocol, called Self-Enforcing Auction Lot (SEAL), operates in a decentralized setting, where bidders jointly compute the maximum bid while preserving the privacy of losing bids. In our protocol, we do not require any secret channels between participants. All operations are publicly verifiable; everyone including third-party observers is able to verify the integrity of the auction outcome. Upon learning the highest bid, the winner comes forward with a proof to prove that she is the real winner. Based on the proof, everyone is able to check if there is only one winner or there is a tie. While our main protocol works with the first-price sealed-bid, it can be easily extended to support the second-price sealed-bid (also known as the Vickrey auction), revealing only the winner and the second highest bid, while keeping the highest bid and all other bids secret. To the best of our knowledge, this work establishes to date the best computation and communication complexity for sealed-bid auction schemes without involving any auctioneer. Samiran Bag, Feng Hao 0001, Siamak F. Shahandashti, Indranil Ghosh Ray |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2020 | Authentic Caller: Self-Enforcing Authentication in a Next-Generation NetworkabstractThe Internet of Things (IoT) or the cyber-physical system (CPS) is the network of connected devices, things, and people that collect and exchange information using the emerging telecommunication networks (4G, 5G IP-based LTE). These emerging telecommunication networks can also be used to transfer critical information between the source and destination, informing the control system about the outage in the electrical grid, or providing information about the emergency at the national express highway. This sensitive information requires authorization and authentication of source and destination involved in the communication. To protect the network from unauthorized access and to provide authentication, the telecommunication operators have to adopt the mechanism for seamless verification and authorization of parties involved in the communication. Currently, the next-generation telecommunication networks use a digest-based authentication mechanism, where the call-processing engine of the telecommunication operator initiates the challenge to the request-initiating client or caller, which is being solved by the client to prove his credentials. However, the digest-based authentication mechanisms are vulnerable to many forms of known attacks, e.g., the man-in-the-middle (MITM) attack and the password guessing attack. Furthermore, the digest-based systems require extensive processing overheads. Several public-key infrastructure (PKI)-based and identity-based schemes have been proposed for the authentication and key agreements. However, these schemes generally require a smart card to hold long-term private keys and authentication credentials. In this article, we propose a novel self-enforcing authentication protocol for the session-initiation-protocol-based next-generation network, based on a low-entropy shared password without relying on any PKI or the trusted third party system. The proposed system shows effective resistance against various attacks, e.g., MITM, replay attack, password guessing attack, etc. We analyze the security properties of the proposed scheme in comparison to the state of the art. Muhammad Ajmal Azad, Samiran Bag, Charith Perera, Mahmoud Barhamgi, Feng Hao 0001 |
IEEE Trans. Ind. Informatics | 2 |
| 2019 | E2E Verifiable Borda Count Voting System without Tallying AuthoritiesabstractAn end-to-end verifiable (E2E) voting system enables candidates, voters and observers to monitor the integrity of an election process and verify the results without relying on trusted systems. In this paper, we propose a DRE-based Borda count e-voting system called DRE-Borda. The proposed system is E2E verifiable without involving any tallying authorities. Furthermore, it outputs only the total score a candidate gets without revealing any other information such as the breakdown of scores with respect to different ranks. This reduces the information leakage from the tallying result to the minimum, hence effectively preventing Italian attacks. When the DRE machine is completely compromised, the integrity of the tallying result is still preserved and what an adversary can learn from a compromised machine is strictly limited to the partial tally at the time of compromise. Samiran Bag, Muhammad Ajmal Azad, Feng Hao 0001 |
ARES | 1 |
| 2019 | PriVeto: a fully private two-round veto protocolabstractIn 2006, Hao and Zieliński presented a two‐round veto protocol named anonymous veto network (AV‐net), which is exceptionally efficient in terms of the number of rounds, computation and bandwidth usage. However, AV‐net has two generic issues: (i) a participant who has submitted a veto can find out whether she is the only one who vetoed; (ii) the last participant who submits her input can pre‐compute the Boolean‐OR result before submission, and may amend her input based on that knowledge. These two issues generally apply to any multi‐round veto protocol where participants commit their input in the last round. In this study, the authors propose a novel solution to address both issues within two rounds, which are the best possible round efficiency for a veto protocol. Their new private veto protocol, called PriVeto, has similar system complexities to AV‐net, but it binds participants to their inputs in the very first round, eliminating the possibility of runtime changes to any of the inputs. At the end of the protocol, participants are strictly limited to learning nothing more than the output of the Boolean‐OR function and their own inputs. Samiran Bag, Muhammad Ajmal Azad, Feng Hao 0001 |
IET Inf. Secur. | 1 |
| 2019 | TrustVote: Privacy-Preserving Node Ranking in Vehicular NetworksabstractThe Internet of Vehicles is the network of connected vehicles and transport infrastructure units [roadside units (RSUs)], which utilizes emerging wireless systems (4G, 5G, LTE) for the communication and sharing of information. The network of connected vehicles enables users to disseminate critical information about events happening on the road (for example, accidents, traffic congestions, and hazards). The exchange of information between vehicles and RSUs could improve the driving experience and road safety, as well as help drivers to identify the hazardous and safe routes in a timely manner. The sharing of critical information between vehicles is advantageous to the driver; however, at the same time, malicious actors could mislead drivers by spreading fraudulent and fake messages. Fraudulent messages can have a negative impact on the infrastructure, and more significantly, have potential to cause threats to life. It is, therefore, essential that vehicles can evaluate the credibility of those who send messages (vehicles or RSUs) before taking any action. In this paper, we present TrustVote, a collaborative crowdsourcing-based vehicle reputation system that enables vehicles to evaluate the credibility of other vehicles in a connected vehicular network. The TrustVote system allows participating vehicles to hide their rating/feedback scores and the list of interacted vehicles under a homomorphic cryptographic layer, which can only be unfolded as an aggregate. The proposed approach also considers the trust weight of a vehicle providing the rating scores while computing the aggregate reputation of the vehicles. A prototype of TrustVote is developed and its performance is evaluated in terms of the computational and communication overheads. Muhammad Ajmal Azad, Samiran Bag, Simon Parkinson, Feng Hao 0001 |
IEEE Internet Things J. | 2 |
| 2018 | Analysis of Variance of Graph-Clique Mining for Scalable Proof of Work
Hiroaki Anada, Tomohiro Matsushima, Chunhua Su, Weizhi Meng 0001, Junpei Kawamoto, Samiran Bag, Kouichi Sakurai |
Inscrypt | 6 |
| 2018 | M2M-REP: Reputation system for machines in the internet of things
Muhammad Ajmal Azad, Samiran Bag, Feng Hao 0001, Khaled Salah 0001 |
Comput. Secur. | 2 |
| 2018 | A privacy-aware decentralized and personalized reputation system
Samiran Bag, Muhammad Ajmal Azad, Feng Hao 0001 |
Comput. Secur. | 1 |
| 2018 | PrivBox: Verifiable decentralized reputation system for online marketplaces
Muhammad Ajmal Azad, Samiran Bag, Feng Hao 0001 |
Future Gener. Comput. Syst. | 2 |
| 2017 | M2M-REP: Reputation of Machines in the Internet of ThingsabstractThe Internet of Things (IoT) is the integration of a large number of autonomous heterogeneous devices that report information from the physical environment to the monitoring system for analytics and meaningful decisions. The compromised machines in the IoT network may not only be used for spreading unwanted content such as spam, malware, viruses etc, but can also report incorrect information about the physical world that might have a disastrous consequence. The challenge is to design a collaborative reputation system that calculates trustworthiness of machines in the IoT-based machine-to-machine network without consuming high system resources and breaching the privacy of participants. To address the challenge of privacy preserving reputation system for the decentralized IoT environment, this paper presents a novel M2M-REP (Machine to Machine Reputation) system that computes global reputation of the machine by aggregating the encrypted local feedback provided by machines in a fully decentralized and secure way. The privacy of participating machines is well protected such that machines or analyst would not learn any information about the feedback score provided by the participating machines other than the final aggregated statistical score. We present a decentralized reputation aggregation system for two scenarios: a semi-honest (honest-but-curious) setup where machines are trustworthy in providing feedback but are curious to learn sensitive information about the collaborating machines, and the malicious model where machines not only try to learn the sensitive information of participants but also do not follow the protocol specification in providing feedback. We analyzed the security and privacy properties of the M2M-REP system for different adversarial models. Muhammad Ajmal Azad, Samiran Bag, Feng Hao 0001 |
ARES | 2 |
| 2017 | Bitcoin Block Withholding Attack: Analysis and MitigationabstractWe address two problems: first, we study a variant of block withholding (BWH) attack in Bitcoins and second, we propose solutions to prevent all existing types of BWH attacks in Bitcoins. We analyze the strategies of a selfish Bitcoin miner who in connivance with one pool attacks another pool and receives reward from the former mining pool for attacking the latter. We name this attack as “sponsored block withholding attack.” We present detailed quantitative analysis of the monetary incentive that a selfish miner can earn by adopting this strategy under different scenarios. We prove that under certain conditions, the attacker can maximize her revenue by adopting some strategies and by utilizing her computing power wisely. We also show that an attacker may use this strategy for attacking both the pools for earning higher amount of incentives. More importantly, we present a strategy that can effectively counter block withholding attack in any mining pool. First, we propose a generic scheme that uses cryptographic commitment schemes to counter BWH attack. Then, we suggest an alternative implementation of the same scheme using hash function. Our scheme protects a pool from rogue miners as well as rogue pool administrators. The scheme and its variant defend against BWH attack by making it impossible for the miners to distinguish between a partial proof of work and a complete proof of work. The scheme is so designed that the administrator cannot cheat on the entire pool. The scheme can be implemented by making minor changes to existing Bitcoin protocol. We also analyze the security of the scheme. Samiran Bag, Sushmita Ruj, Kouichi Sakurai |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2016 | Yet Another Note on Block Withholding Attack on Bitcoin Mining Pools
Samiran Bag, Kouichi Sakurai |
ISC | 1 |
| 2015 | On the Application of Clique Problem for Proof-of-Work in Cryptocurrencies
Samiran Bag, Sushmita Ruj, Kouichi Sakurai |
Inscrypt | 1 |
| 2013 | Two channel hopping schemes for jamming resistant wireless communicationabstractJamming resistance is crucial for reliable wireless communication. Most of the existing schemes offering counter-measures of jamming depend on the use of a secret key shared between the communicating devices. This secret key is used to generate a random hopping sequence. The message-sender and the message-receiver hop over different wireless channels depending upon this generated sequence. But such anti-jamming mechanisms fail in broadcast communication scenarios where the number of receivers do not remain the same. There are other strategies like Uncoordinated Frequency Hopping (UFH). But this scheme has a major disadvantage that under this scheme a sender and a receiver need to hop randomly over a number of channels and they can only communicate a message only if they meet over the same channel at any instant. This limitation makes communication under UFH very slow. We propose two schemes for unicast wireless communication in presence of a jammer. Our scheme is applicable to such scenarios where one party sends messages to one recipients through wireless channels. This scheme does not require any secret keys shared between the communicating devices or users. Despite that, the communicating parties can hop over the available wireless channels and thus evading the jammer. We used combinatorial design for designing these channel hopping schemes. These schemes guaranty that in any time slot the sender and the receiver must meet on some channel every time. Samiran Bag, Bimal K. Roy |
WiMob | 1 |
| 2012 | 100% Connectivity for Location Aware Code Based KPD in Clustered WSN: Merging Blocks
Samiran Bag, Aritra Dhar, Pinaki Sarkar |
ISC | 1 |