Binanda Sengupta

dblp:134/5082 · DBLP profile ↗
← Back
17ranked-venue papers
11as first author
7since 2021 · last 2025
0000-0002-2944-3783ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 3 first-author · 3 since 2021Computer networks · 4 · 4 first-author · 2 since 2021Systems, architecture and hardware · 2 · 2 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 first-author · 1 since 2021Theory of computation · 1
YearPublicationVenuePosition
2025 Message Control for Blockchain Rewriting
abstract
Blockchain rewriting is necessary for modifying illegal or invalid messages included in blockchain transactions, while maintaining the consistency of subsequent blocks in the blockchain. However, arbitrary blockchain rewriting is not desirable as it defeats the purpose of blockchain rewriting. In this work, we propose a new security primitive named message-controlled chameleon hash (MCH) and apply it for message control in blockchain rewriting to ensure that no unspecified messages are generated from blockchain rewriting. The proposed MCH enables permitted parties to select candidate messages from designated message sets for blockchain rewriting at the message level. Our evaluation shows that the performance of MCH is comparable to the classic CH [26] and the state-of-the-art CH [16]. We also show that the proposed MCH can be easily integrated into both permissioned and permissionless blockchains.
Yingjiu Li, Binanda Sengupta, Yangguang Tian, Jiaming Yuan, Tsz Hon Yuen
IEEE Trans. Dependable Secur. Comput.2
2022 SERVNET: Path Validation with Authenticated Packet Modification in Service Function Chains
abstract
A sequence of composable network functions constitutes a service function chain (SFC). Network function virtualization and software-defined networking have made SFCs feasible. With SFCs, a fundamental security requirement is that traffic, directed to traverse a path of network functions, actually follows the specified path. Current path validation enables path enforcement and verification, with on-path nodes able to verify that packets have indeed traversed the specified path. However, there is a problem — on-path service nodes, that implement network functions, might modify packets, whereas current path validation techniques do not allow packet modification.We propose SERVNET, a path validation scheme which supports authenticated packet modification. SERVNET uses a cryptographic primitive called chameleon hash function which allows packet modification without changing its associated hash value. To the best of our knowledge, SERVNET is the first work on path validation that allows authenticated packet modification by designated nodes.
Binanda Sengupta, Anantharaman Lakshminarayanan
ICC1
2022 Policy-Based Editing-Enabled Signatures: Authenticating Fine-Grained and Restricted Data Modification
abstract
Abstract Data owners often encrypt their bulk data and upload it to cloud in order to save storage while protecting privacy of their data at the same time. A data owner can allow a third-party entity to decrypt and access her data. However, if that entity wants to modify the data and publish the same in an authenticated way, she has to ask the owner for a signature on the modified data. This incurs substantial communication overhead if the data is modified often. In this work, we introduce the notion of policy-based editing-enabled signatures, where the data owner specifies a policy for her data such that only an entity satisfying this policy can decrypt the data. Moreover, the entity is permitted to produce a valid signature for the modified data (on behalf of the owner) without interacting with the owner every time the data is modified. On the other hand, a policy-based editing-enabled signature (PB-EES) scheme allows the data owner to choose any set of modification operations applicable to her data and still restricts a (possibly untrusted) entity to authenticate the data modified using operations from that set only. We provide two PB-EES constructions, a generic construction and a concrete instantiation. We formalize the security model for PB-EESs and analyze the security of our constructions. Finally, we evaluate the performance of the concrete PB-EES instantiation.
Binanda Sengupta, Yingjiu Li, Yangguang Tian, Robert H. Deng, Zheng Yang 0001
Comput. J.1
2022 VALNET: Privacy-preserving multi-path validation
Binanda Sengupta
Comput. Networks1
2022 Secure Cloud Storage With Data Dynamics Using Secure Network Coding Techniques
abstract
In the age of cloud computing, cloud users with limited storage can outsource their data to remote servers. These servers, in lieu of monetary benefits, offer retrievability of their clients’ data at any point of time. Secure cloud storage protocols enable a client to check integrity of outsourced data. In this article, we explore the possibility of constructing a secure cloud storage for dynamic data by leveraging the algorithms involved in secure network coding. We show that some of the secure network coding schemes can be used to constructefficientsecure cloud storage protocols for dynamic data, and we construct such a protocol (DSCS I) based on a secure network coding protocol. To the best of our knowledge, DSCS I is the first secure cloud storage protocol fordynamicdata constructed using secure network coding techniques which is secure in the standard model. Although generic dynamic data support arbitrary insertions, deletions and modifications,append-onlydata find numerous applications in the real world. We construct another secure cloud storage protocol (DSCS II) specific to append-only data — that overcomes some limitations of DSCS I. Finally, we provide prototype implementations for DSCS I and DSCS II in order to evaluate their performance.
Binanda Sengupta, Akanksha Dixit 0001, Sushmita Ruj
IEEE Trans. Cloud Comput.1
2021 DistriTrust: Distributed and low-latency access validation in zero-trust architecture
Binanda Sengupta, Anantharaman Lakshminarayanan
J. Inf. Secur. Appl.1
2021 Lattice-based remote user authentication from reusable fuzzy signature
abstract
In this paper, we introduce a new construction of reusable fuzzy signature based remote user authentication that is secure against quantum computers. We investigate the reusability of fuzzy signature, and we prove that the fuzzy signature schemes provide biometrics reusability (aka. reusable fuzzy signature). We define formal security models for the proposed construction, and we prove that it achieves user authenticity and user privacy. The proposed construction ensures: 1) a user’s biometrics can be securely reused in remote user authentication; 2) a third party having access to the communication channel between a user and the authentication server cannot identify the user.
Yangguang Tian, Yingjiu Li, Robert H. Deng, Binanda Sengupta, Guomin Yang
J. Comput. Secur.4
2020 Editing-Enabled Signatures: A New Tool for Editing Authenticated Data
abstract
Data authentication primarily serves as a tool to achieve data integrity and source authentication. However, traditional data authentication does not fit well where an intermediate entity (editor) is required to modify the authenticated data provided by the source/data owner before sending the data to other recipients. To ask the data owner for authenticating each modified data can lead to higher communication overhead. In this article, we introduce the notion of editing-enabled signatures where the data owner can choose any set of modification operations applicable on the data and still can restrict any possibly untrusted editor to authenticate the data modified using an operation from this set only. Moreover, the editor does not need to interact with the data owner in order to authenticate the data every time it is modified. We construct an editing-enabled signature (EES) scheme that derives its efficiency from mostly lightweight cryptographic primitives. We formalize the security model for editing-enabled signatures and analyze the security of our EES scheme. Editing-enabled signatures can find numerous applications that involve generic editing tasks and privacy-preserving operations. We demonstrate how our EES scheme can be applied in two privacy-preserving applications.
Binanda Sengupta, Yingjiu Li, Yangguang Tian, Robert H. Deng
IEEE Internet Things J.1
2020 Efficient Proofs of Retrievability with Public Verifiability for Dynamic Cloud Storage
abstract
Cloud service providers offer various facilities to their clients. The clients with limited resources opt for some of these facilities. They can outsource their bulk data to the cloud server. The cloud server maintains these data in lieu of monetary benefits. However, a malicious cloud server might delete some of these data to save some space and offer this extra amount of storage to another client. Therefore, the client might not retrieve her file (or some portions of it) as often as needed. Proofs of retrievability (POR) provide an assurance to the client that the server is actually storing all of her data appropriately and they can be retrieved at any point of time. In a dynamic POR scheme, the client can update her data after she uploads them to the cloud server. Moreover, in publicly verifiable POR schemes, the client can delegate her auditing task to some third party specialized for this purpose. In this work, we exploit the homomorphic hashing technique to design a publicly verifiable dynamic POR scheme that is more efficient (in terms of bandwidth required between the client and the server) than the “state-of-the-art” publicly verifiable dynamic POR scheme. We also analyze security and performance of our scheme.
Binanda Sengupta, Sushmita Ruj
IEEE Trans. Cloud Comput.1
2020 Leakage-resilient biometric-based remote user authentication with fuzzy extractors
Yangguang Tian, Yingjiu Li, Binanda Sengupta, Nan Li 0007, Chunhua Su
Theor. Comput. Sci.3
2020 Privacy-preserving Network Path Validation
abstract
The end-users communicating over a network path currently have no control over the path. For a better quality of service, the source node often opts for a superior (or premium) network path to send packets to the destination node. However, the current Internet architecture provides no assurance that the packets indeed follow the designated path. Network path validation schemes address this issue and enable each node present on a network path to validate whether each packet has followed the specific path so far. In this work, we introduce two notions of privacy— path privacy and index privacy —in the context of network path validation. We show that, in case a network path validation scheme does not satisfy these two properties, the scheme is vulnerable to certain practical attacks (that affect the privacy, reliability, neutrality and quality of service offered by the underlying network). To the best of our knowledge, ours is the first work that addresses privacy issues related to network path validation. We design PrivNPV, a privacy-preserving network path validation protocol, that satisfies both path privacy and index privacy. We discuss several attacks related to network path validation and how PrivNPV defends against these attacks. Finally, we discuss the practicality of PrivNPV based on relevant parameters.
Binanda Sengupta, Yingjiu Li, Kai Bu, Robert H. Deng
ACM Trans. Internet Techn.1
2019 Anonymous Asynchronous Payment Channel from k-Time Accountable Assertion
Yangguang Tian, Yingjiu Li, Binanda Sengupta, Nan Li 0007, Yong Yu 0002
CANS3
2018 An Efficient Secure Distributed Cloud Storage for Append-Only Data
abstract
Cloud computing enables users (clients) to outsource large volume of their data to cloud servers. Secure distributed cloud storage schemes ensure that multiple servers store these data in a reliable and untampered fashion. We propose an idea to construct such a scheme for static data by encoding data blocks (using error-correcting codes) and then attaching authentication information (tags) to these encoded blocks. We identify some challenges while extending this idea to accommodate append-only data. Then, we propose our secure distributed cloud storage scheme for append-only data that addresses the challenges efficiently. The main advantage of our scheme is that it enables the servers to update the parity blocks themselves. Moreover, the client need not download any data (or parity) block to update the tags of the modified parity blocks residing on the servers. Finally, we analyze the security and performance of our scheme.
Binanda Sengupta, Nishant Nikam, Sushmita Ruj, Srinivasan Narayanamurthy, Siddhartha Nandi
IEEE CLOUD1
2018 Privacy-Preserving Remote User Authentication with k-Times Untraceability
Yangguang Tian, Yingjiu Li, Binanda Sengupta, Robert H. Deng, Albert Ching, Weiwei Liu 0005
Inscrypt3
2018 Keyword-Based Delegable Proofs of Storage
Binanda Sengupta, Sushmita Ruj
ISPEC1
2017 Certificate Transparency with Enhancements and Short Proofs
Binanda Sengupta, Sushmita Ruj
ACISP (2)2
2016 Publicly Verifiable Secure Cloud Storage for Dynamic Data Using Secure Network Coding
abstract
Cloud service providers offer storage outsourcing facility to their clients. In a secure cloud storage (SCS) protocol, the integrity of the client's data is maintained. In this work, we construct a publicly verifiable secure cloud storage protocol based on a secure network coding (SNC) protocol where the client can update the outsourced data as needed. To the best of our knowledge, our scheme is the first SNC-based SCS protocol for dynamic data that is secure in the standard model and provides privacy-preserving audits in a publicly verifiable setting. Furthermore, we discuss, in details, about the (im)possibility of providing a general construction of an efficient SCS protocol for dynamic data (DSCS protocol) from an arbitrary SNC protocol. In addition, we modify an existing DSCS scheme (DPDP I) in order to support privacy-preserving audits. We also compare our DSCS protocol with other SCS schemes (including the modified DPDP I scheme). Finally, we figure out some limitations of an SCS scheme constructed using an SNC protocol.
Binanda Sengupta, Sushmita Ruj
AsiaCCS1