VLDB 2026 Research / reviewers in the wild / expert
Shahriar Ebrahimi
dblp:160/7653
· DBLP profile ↗
12ranked-venue papers
4as first author
8since 2021 · last 2026
0000-0003-0344-921XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 1 first-author · 5 since 2021Computer networks · 4 · 3 first-author · 2 since 2021Systems, architecture and hardware · 3 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | PIRANHAS: PrIvacy-Preserving Remote Attestation in Non-Hierarchical Asynchronous Swarms
Jonas Hofmann, Philipp-Florens Lehwalder, Shahriar Ebrahimi, Parisa Hassanizadeh, Sebastian Faust |
NDSS | 3 |
| 2026 | PEACE: Privacy-Enhanced Authentication for Cryptocurrency Environments
Stefan Dziembowski, Shahriar Ebrahimi, Pawel Kedzior, Michal Król, Tomasz Lizurej |
SECRYPT (1) | 2 |
| 2026 | Zero-Knowledge Proofs of Generalized Regular Expression Matching for Anonymized Email Verification
Shreyas Londhe, Sora Suegami, Yogesh Shahi, Rute Fgueiredo, Parisa Hassanizadeh, Shahriar Ebrahimi |
Proc. Priv. Enhancing Technol. | 7 |
| 2025 | VIMz: Private Proofs of Image Manipulation using Folding-based zkSNARKsabstractEnsuring the authenticity and credibility of daily media on internet is an ongoing problem. Meanwhile, genuinely captured images often require refinements before publication. Zero-knowledge proofs (ZKPs) offer a solution by verifying edited image without disclosing the original source. However, ZKPs typically come with high costs, particularly in terms of prover complexity and proof size. This paper presents VIMz, a framework for efficiently proving the authenticity of high-resolution images using folding-based zkSNARKs; a type of proving system that minimizes computational overhead by recursively folding multiple evaluations of the same constraints into a compact proof. As a complete proof system, VIMz proves the integrity of both the original and edited images, as well as the correctness of the transformation without revealing intermediate images within a chain of edits--only the final result is disclosed. Moreover, VIMz maintains the anonymity of the original signer and all subsequent editors while proving the authenticity of the final image. We also compare VIMz with the system model in Coalition for Content Provenance and Authenticity (C2PA) from different perspectives and show that VIMz offers higher level of security guarantee by eliminating the need to trust the editing environment. Experimental results show that VIMz performs efficiently in both prover and verifier sides. It can prove the transformations on 8K (33MP,i.e., 100MB) images with up to 13%~25% faster than the competition, while reaching to a peak memory of only 10 GB. Moreover, VIMz has a verification time of under 1 second and achieves succinct proofs of less than 11 KB for all resolutions, which is more than 90% improvement compared to the competition. VIMz's low memory complexity allows for proving multiple transformations in parallel to achieve a 3.5x additional speedup on average. Stefan Dziembowski, Shahriar Ebrahimi, Parisa Hassanizadeh |
Proc. Priv. Enhancing Technol. | 2 |
| 2024 | From Interaction to Independence: zkSNARKs for Transparent and Non-Interactive Remote Attestation
Shahriar Ebrahimi, Parisa Hassanizadeh |
NDSS | 1 |
| 2022 | High-Speed Post-Quantum Cryptoprocessor Based on RISC-V Architecture for IoTabstractPublic-key plays a significant role in today’s communication over the network. However, current state-of-the-art public-key encryption (PKE) schemes are too complex to be efficiently employed in resource-constrained devices. Moreover, they are vulnerable to quantum attacks and soon will not have the required security. In the last decade, lattice-based cryptography has been a progenitor platform of the post-quantum cryptography (PQC) due to its lower complexity, which makes it more suitable for Internet of Things applications. In this article, we propose an efficient implementation of the binary learning with errors over ring (Ring-BinLWE) on the reduced instruction set computer-five (RISC-V) platform. Our field-programmable gate array (FPGA) implementations improve the speed of scheme operations by more than 51% in terms of CPU cycles compared to previous work. The proposed hardware module has low complexity and only imposes around 6%–9% overhead to the original core. Moreover, it has constant-time operations and is resistant to timing attacks. Besides, a more reliable fault-resilient variant of the architecture with 1% area overhead is proposed. According to the application-specific integrated circuits (ASICs) implementations, the proposed architecture achieves at least 32%, 79%, and 50% lower power, energy, and area consumption compared to the previous work, respectively. Shahriar Hadayeghparast, Siavash Bayat Sarmadi, Shahriar Ebrahimi |
IEEE Internet Things J. | 3 |
| 2022 | Efficient Hardware Implementations of Legendre Symbol Suitable for MPC ApplicationsabstractMulti-party computation (MPC) allows each peer to take part in the execution of a common function with their private share of data without the need to expose it to other participants. The Legendre symbol is a pseudo-random function (PRF) that is suitable for MPC protocols due to their efficient evaluation process compared to other symmetric primitives. Recently, Legendre-based PRFs have also been employed in the construction of a post-quantum signature scheme, namely LegRoast. In this paper, we propose, to the best of our knowledge, the first hardware implementations for the Legendre symbol by three approaches: 1) low-area, 2) high-speed, and 3) high-frequency. The high-speed architecture outperforms state-of-the-art software implementations, which run on Intel’s Core-i5. Our evaluation results on FPGA show that this architecture reduces the Legendre calculation time by$2.56\times $compared to software implementations on Core-i5. On the other hand, the low-area architecture consumes only 5489 slices on the Artix-7 FPGA and is suitable for resource-constrained devices. Moreover, our ASIC implementation results indicate that the low-area architecture consumes 97.56K gates to implement and requires$4.01~mW$to operate on 50 MHz. The high-frequency architecture increases the frequency by$1.72\times $over the high-speed architecture and achieves 200 MHz frequency on FPGA. Farhad Taheri, Siavash Bayat Sarmadi, Shahriar Ebrahimi |
IEEE Trans. Circuits Syst. I Regul. Pap. | 3 |
| 2021 | Lightweight Fuzzy Extractor Based on LPN for Device and Biometric Authentication in IoTabstractUser and device biometrics are proven to be a reliable source for authentication, especially for the Internet-of-Things (IoT) applications. One of the methods to employ biometric data in authentication are fuzzy extractors (FE) that can extract cryptographically secure and reproducible keys from noisy biometric sources with some entropy loss. It has been shown that one can reliably build an FE based on the learning parity with noise (LPN) problem with higher error-tolerance than previous FE schemes. However, the only available LPN-based FE implementation suffers from extreme resource demands that are not practical for IoT devices. This article proposes a lightweight hardware/software (HW/SW) co-design for implementing LPN-based FE. We provide different optimizations on architecture to decrease the resource requirements of the scheme. The proposed architecture is resistant against simple side-channel analysis and improves area and area-time product (AT) by more than 89% and 83%, respectively, compared to previous work. Our experimental results indicate that the proposed architecture can be implemented on off-the-shelf resource-constrained SoC-FPGA boards from different vendors such as Xilinx, Digilent, and Trenz. Moreover, we provide the first implementation results of LPN-based FE on an application-specific integrated circuit (ASIC) platform using HW/SW co-design. Shahriar Ebrahimi, Siavash Bayat Sarmadi |
IEEE Internet Things J. | 1 |
| 2020 | Lightweight and Fault-Resilient Implementations of Binary Ring-LWE for IoT DevicesabstractWhile the Internet of Things (IoT) shapes the future of the Internet, communications among nodes must be secured by employing cryptographic schemes such as public-key encryption (PKE). However, classic PKE schemes, such as RSA and elliptic curve cryptography (ECC) suffer from both high complexity and vulnerability to quantum attacks. During the past decade, post-quantum schemes based on the learning with errors (LWEs) problem have gained high attention due to the lower complexity among PKE schemes. In addition to resistance against theoretical (quantum and classic) attacks, every practical implementation of any cryptosystem must also be evaluated against different side-channel attacks such as power analysis or fault injection ones. In this article, we analyze the vulnerability of binary ring learning with error (Ring-LWE) scheme regarding (first-order) fault attacks, such as randomization, zeroing, and skipping faults. We show that previous implementations can be easily broken by employing such fault attacks. Moreover, we propose fault-resilient software implementations of binary Ring-LWE on 8- and 32-b lightweight microcontrollers, namely, AVR ATxmega128A1 and ARM Cortex-M0 that are ideal for IoT devices. Furthermore, we formally prove the resilience of the proposed implementations against different fault attacks. To the best of our knowledge, this article is the first one to propose fault-resilient binary Ring-LWE implementations on resource-constrained microcontrollers. Our implementations on AVR ATxmega128A1 require only 80 and 120 ms for encryption and decryption, respectively. Shahriar Ebrahimi, Siavash Bayat Sarmadi |
IEEE Internet Things J. | 1 |
| 2019 | Post-Quantum Cryptoprocessors Optimized for Edge and Resource-Constrained Devices in IoTabstractBy exponential increase in applications of the Internet of Things (IoT), such as smart ecosystems or e-health, more security threats have been introduced. In order to resist known attacks for IoT networks, multiple security protocols must be established among nodes. Thus, IoT devices are required to execute various cryptographic operations, such as public key encryption/decryption. However, classic public key cryptosystems, such as Rivest-Shammir-Adlemon and elliptic curve cryptography are computationally more complex to be efficiently implemented on IoT devices and are vulnerable regarding quantum attacks. Therefore, after complete development of quantum computing, these cryptosystems will not be secure and practical. In this paper, we propose InvRBLWE, an optimized variant for binary learning with errors over the ring (Ring-LWE) scheme that is proven to be secure against quantum attacks and is highly efficient for hardware implementations. We propose two architectures for InvRBLWE: 1) a high-speed architecture targeting edge and powerful IoT devices and 2) an ultralightweight architecture, which can be implemented on resource-constrained nodes in IoT. The proposed architectures are scalable regarding security levels and we provide experimental results for two versions of the InvRBLWE scheme providing 84 and 190 bits of classic security. Our implementation results on field programmable gate array dominate the best of the classic and post-quantum previous implementations. Moreover, our two different application specific integrated circuit (ASIC) implementations show improvement in terms of speed, area, power, and/or energy. To the best of our knowledge, we are the first to implement learning with error-based cryptosystems on ASIC platform. Shahriar Ebrahimi, Siavash Bayat Sarmadi, Hatameh Mosanaei-Boorani |
IEEE Internet Things J. | 1 |
| 2018 | ReCA: An Efficient Reconfigurable Cache Architecture for Storage Systems with Online Workload CharacterizationabstractIn recent years, Solid-State Drives (SSDs) have gained tremendous attention in computing and storage systems due to significant performance improvement over Hard DiskDrives (HDDs). The cost per capacity of SSDs, however, prevents them from entirely replacing HDDs in such systems. One approach to effectively take advantage of SSDs is to use them as a caching layer to store performance critical data blocks in order to reduce the number of accesses to HDD-based disk subsystem. Due to characteristics of Flash-based SSDs such as limited write endurance and long latency on write operations, employing caching algorithms at the Operating System (OS) level necessitates to take such characteristics into consideration. Previous OS-level caching techniques are optimized towards only one type of application, which affects both generality and applicability. In addition, they are not adaptive when the workload pattern changes over time. This paper presents an efficient Reconfigurable Cache Architecture (ReCA) for storage systems using a comprehensive workload characterization to find an optimal cache configuration for I/O intensive applications. For this purpose, we first investigate various types of I/O workloads and classify them into five major classes. Based on this characterization, an optimal cache configuration is presented for each class of workloads. Then, using the main features of each class, we continuously monitor the characteristics of an application during system runtime and the cache organization is reconfigured if the application changes from one class to another class of workloads. The cache reconfiguration is done online and workload classes can be extended to emerging I/O workloads in order to maintain its efficiency with the characteristics of I/O requests. Experimental results obtained by implementing ReCA in a 4U rackmount server with SATA 6Gb/s disk interfaces running Linux 3.17.0 show that the proposed architecture improves performance and lifetime up to 24 and 33 percent, respectively. Reza Salkhordeh, Shahriar Ebrahimi, Hossein Asadi 0001 |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2015 | Operating system level data tiering using online workload characterization
Reza Salkhordeh, Hossein Asadi 0001, Shahriar Ebrahimi |
J. Supercomput. | 3 |