Hasini Gunasinghe

dblp:152/2505 · DBLP profile ↗
← Back
6ranked-venue papers
5as first author
1since 2021 · last 2024
0000-0002-4654-3436ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 3 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-authorSystems, architecture and hardware · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1Databases, data management, data science and information retrieval · 1 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
2 papers
Biometric security · 40% Cryptographic protocols and secure computation · 29% Authentication and access control · 23%

Topics — the 5 heaviest of 5, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Cryptographic protocols and secure computation › proof systems
zero-knowledge proofs
0.522019
PrivIdEx: Privacy Preserving and Secure Exchange of Digital Identity Assets · WWW 2019
PrivBioMTAuth: Privacy Preserving Biometrics-Based and User Centric Protocol for User Authentication From Mobile Phones · IEEE Trans. Inf. Forensics Secur. 2018
Authentication and access control › identity management
decentralized identity management
0.412019
PrivIdEx: Privacy Preserving and Secure Exchange of Digital Identity Assets · WWW 2019
Biometric security
biometric authentication
0.312018
PrivBioMTAuth: Privacy Preserving Biometrics-Based and User Centric Protocol for User Authentication From Mobile Phones · IEEE Trans. Inf. Forensics Secur. 2018
Biometric security › biometric authentication
privacy-preserving biometric authentication
0.312018
PrivBioMTAuth: Privacy Preserving Biometrics-Based and User Centric Protocol for User Authentication From Mobile Phones · IEEE Trans. Inf. Forensics Secur. 2018
Privacy and data protection
anonymity and unlinkability
0.112019
PrivIdEx: Privacy Preserving and Secure Exchange of Digital Identity Assets · WWW 2019

Methods — techniques the papers use, named apart from their topics

zero-knowledge proofs · 0.4blockchain · 0.4machine learning classification · 0.3feature extraction · 0.3
YearPublicationVenuePosition
2024 PEBASI: A Privacy preserving, Efficient Biometric Authentication Scheme based on Irises
abstract
We introduce a novel privacy-preserving biometric authentication scheme based on irises that allows a user to enroll once at a trusted biometric certification authority (BCA) and authenticate to online service providers (SPs) multiple times without involving the BCA during the authentication. Our scheme preserves the user’s biometric privacy from the SPs and transactional privacy from the BCA, while providing security against a malicious user. During the enrollment, the BCA issues a signed token that encrypts the user’s biometrics. We introduce techniques enabling the SP and the user to perform secure computation of biometric matching between such encrypted biometrics and the user’s biometrics captured at the authentication time. We provide a prototype implementation, a performance evaluation, and a security analysis of the protocol.
Hasini Gunasinghe, Mikhail J. Atallah, Elisa Bertino
ACM Trans. Priv. Secur.1
2019 PrivIdEx: Privacy Preserving and Secure Exchange of Digital Identity Assets
abstract
User's digital identity information has privacy and security requirements. Privacy requirements include confidentiality of the identity information itself, anonymity of those who verify and consume a user's identity information and unlinkability of online transactions which involve a user's identity. Security requirements include correctness, ownership assurance and prevention of counterfeits of a user's identity information. Such privacy and security requirements, although conflicting, are critical for identity management systems enabling the exchange of users' identity information between different parties during the execution of online transactions. Addressing all such requirements, without a centralized party managing the identity exchange transactions, raises several challenges. This paper presents a decentralized protocol for privacy preserving exchange of users' identity information addressing such challenges. The proposed protocol leverages advances in blockchain and zero knowledge proof technologies, as the main building blocks. We provide prototype implementations of the main building blocks of the protocol and assess its performance and security.
Hasini Gunasinghe, Ashish Kundu, Elisa Bertino, Hugo Krawczyk, Suresh Chari, Kapil Singh, Dong Su
WWW1
2018 PrivBioMTAuth: Privacy Preserving Biometrics-Based and User Centric Protocol for User Authentication From Mobile Phones
abstract
We introduce a privacy preserving biometrics-based authentication solution by which users can authenticate to different service providers from mobile phones without involving identity providers in the transactions. Authentication is performed via zero-knowledge proof of knowledge, based on a cryptographic identity token that encodes the biometric identifier of the user and a secret provided by the user, making it three-factor authentication. Our approach for generating a unique, repeatable, and revocable biometric identifier from the user’s biometric image is based on a machine learning-based classification technique, which involves the features extracted from the user’s biometric image. We have implemented a prototype of the proposed authentication solution and evaluated our solution with respect to its performance, security, and privacy. The evaluation has been performed on a public data set of face images.
Hasini Gunasinghe, Elisa Bertino
IEEE Trans. Inf. Forensics Secur.1
2016 Apache Airavata security manager: Authentication and authorization implementations for a multi-tenant escience framework
abstract
eScience middleware frameworks integrating multiple virtual organizations must incorporate comprehensive user identity and access management solutions. In this paper we examine usage patterns for these systems and map the patterns to widely used security standards and approaches. We focus on science gateways, a class of distributed system cyberinfrastructure. Science gateways are end user environments that provide access to a wide range of academic and commercial computing and storage resources for virtual organizations. Successful gateways focus on specific scientific communities and domains, but they build on many reusable features that can be provided by general purpose hosted platform services that can support multiple tenants. Providing a security framework for identity and access management for such hosted service removes the burden for each gateway to handle its user identity management and control access to its critical resources. From the resource provider's point of view, it provides a basis for more uniform accounting and auditing. Challenges arise from the range of gateways (both legacy and newly created), the range of technologies used to build them, and the range of end user environments (Web, mobile, desktop, and programmatic API clients) that gateways provide. Using Apache Airavata as an implementation, we examine three common gateway types based on where the user identity information is held and how these can be treated in a unified manner using OAuth2 and OpenID-Connect. Our solutions for identity and access management are not specific to Apache Airavata but can be generally applied to any e-Science platform.
Supun Nakandala, Hasini Gunasinghe, Suresh Marru, Marlon E. Pierce
eScience2
2015 RahasNym: Protecting against Linkability in the Digital Identity Ecosystem
abstract
Unlink ability and accountability are conflicting yet critical requirements for on-line transactions that need to be addressed in order to preserve users' privacy as well as to protect service providers in today identity ecosystems. In this poster paper we introduce a pseudonymous identity management system in which users can carry out unlink able on-line transactions without having to disclose their actual identity to the service providers. At the same time, the service providers have strong assurance about the authenticity of the identity and credentials. In our approach, users' identity is cryptographically encoded in pseudonymous identity tokens issued by trusted identity providers. Our system includes a lightweight policy language which enables users and service providers to express their requirements pertaining to pseudonymous identity verification and a suite of protocols based on zero-knowledge-proofs which enables the fulfillment of these requirements.
Hasini Gunasinghe, Elisa Bertino
ICDCS1
2014 Privacy Preserving Biometrics-Based and User Centric Authentication Protocol
Hasini Gunasinghe, Elisa Bertino
NSS1