VLDB 2026 Research / reviewers in the wild / expert
Omid Mir
dblp:165/0114
· DBLP profile ↗
9ranked-venue papers
6as first author
7since 2021 · last 2026
0000-0003-1691-5291ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 5 first-author · 7 since 2021Computer networks · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Topology-Hiding Path Validation for Large-Scale Quantum Key Distribution Networks
Stephan Krenn, Omid Mir, Thomas Lorünser, Sebastian Ramacher, Florian Wohner |
ACNS (3) | 2 |
| 2025 | Leap: A Fast, Lattice-Based OPRF with Application to Private Set Intersection
Lena Heimberger, Daniel Kales, Riccardo Lolato, Omid Mir, Sebastian Ramacher, Christian Rechberger |
EUROCRYPT (7) | 4 |
| 2024 | Delegatable Anonymous Credentials from Mercurial Signatures with Stronger Privacy
Scott Griffy, Anna Lysyanskaya, Omid Mir, Octavio Perez-Kempner, Daniel Slamanig |
ASIACRYPT (2) | 3 |
| 2024 | Threshold Delegatable Anonymous Credentials With Controlled and Fine-Grained DelegationabstractAnonymous credential systems allow users to obtain a credential on multiple attributes from an organization and then present it to verifiers in a way that no information beyond what attributes are required to be shown is revealed. Moreover, multiple uses of the credential cannot be linked. Thus they represent an attractive tool to realize fine-grained privacy-friendly authentication and access control. In order to avoid a single point of trust and failure, decentralized AC systems have been proposed. They eliminate the need for a trusted credential issuer, e.g., by relying on a set of credential issuers that issue credentials in a threshold manner (e.g.,$t$out of$n$f). In this paper, we present a novel AC system with such a threshold issuance that additionally provides credential delegation. It represents the first decentralizedanddelegatable AC system. We provide a rigorous formal framework for such threshold delegatable anonymous credentials ($\mathsf {TDAC}$'s). Our concrete approach departs from previous delegatable ACs and is inspired by the concept of functional credentials. More precisely, we propose a threshold delegatable subset predicate encryption ($\mathsf {TDSPE}$) scheme and use$\mathsf {TDSPE}$to construct a$\mathsf {TDAC}$scheme and present a comparison with previous work and performance benchmarks based on a prototype implementation. Omid Mir, Daniel Slamanig, René Mayrhofer |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2023 | Aggregate Signatures with Versatile Randomization and Issuer-Hiding Multi-Authority Anonymous CredentialsabstractAnonymous credentials (AC) offer privacy in user-centric identity management. They enable users to authenticate anonymously, revealing only necessary attributes. With the rise of decentralized systems like self-sovereign identity, the demand for efficient AC systems in a decentralized setting has grown. Relying on conventional AC systems, however, require users to present independent credentials when obtaining them from different issuers, leading to increased complexity. AC systems should ideally support being multi-authority for efficient presentation of multiple credentials from various issuers. Another vital property is issuer hiding, ensuring that the issuer's identity remains concealed, revealing only compliance with the verifier's policy. This prevents unique identification based on the sole combination of credential issuers. To date, there exists no AC scheme satisfying both properties simultaneously. Omid Mir, Balthazar Bauer, Scott Griffy, Anna Lysyanskaya, Daniel Slamanig |
CCS | 1 |
| 2023 | Practical Delegatable Anonymous Credentials From Equivalence Class SignaturesabstractAnonymous credentials (ACs) systems are a powerful cryptographic tool for privacy-preserving applications and provide strong user privacy guarantees for authentication and access control. ACs allow users to prove possession of attributes encoded in a credential without revealing any information beyond them. A delegatable AC (DAC) system is an enhanced AC system that allows the owners of credentials to delegate the obtained credential to other users. This allows to model hierarchies as usually encountered within public-key infrastructures (PKIs). DACs also provide stronger privacy guarantees than traditional AC systems since the identities of issuers and delegators can also be hidden. In this paper we present a novel DAC scheme that supports attributes, provides anonymity for delegations, allows the delegators to restrict further delegations, and also comes with an efficient construction. Our approach builds on a new primitive that we call structure-preserving signatures on equivalence classes on updatable commitments (SPSEQ-UC). The high-level idea is to use a special signature scheme that can sign vectors of set commitments, where signatures can be extended by additional set commitments. Signatures additionally include a user's public key, which can be switched. This allows us to efficiently realize delegation in the DAC. Similar to conventional SPSEQ, the signatures and messages can be publicly randomized and thus allow unlinkable delegation and showings in the DAC system. We present further optimizations such as cross-set commitment aggregation that, in combination, enable efficient selective showing of attributes in the DAC without using costly zero-knowledge proofs. We present an efficient instantiation that is proven to be secure in the generic group model and finally demonstrate the practical efficiency of our DAC by presenting performance benchmarks based on an implementation. Omid Mir, Daniel Slamanig, Balthazar Bauer, René Mayrhofer |
Proc. Priv. Enhancing Technol. | 1 |
| 2022 | Decentralized, Privacy-Preserving, Single Sign-OnabstractIn current single sign-on authentication schemes on the web, users are required to interact with identity providers securely to set up authentication data during a registration phase and receive a token (credential) for future access to services and applications. This type of interaction can make authentication schemes challenging in terms of security and availability. From a security perspective, a main threat is theft of authentication reference data stored with identity providers. An adversary could easily abuse such data to mount an offline dictionary attack for obtaining the underlying password or biometric. From a privacy perspective, identity providers are able to track user activity and control sensitive user data. In terms of availability, users rely on trusted third-party servers that need to be available during authentication. We propose a novel decentralized privacy-preserving single sign-on scheme through the Decentralized Anonymous Multi-Factor Authentication (DAMFA), a new authentication scheme where identity providers no longer require sensitive user data and can no longer track individual user activity. Moreover, our protocol eliminates dependence on an always-on identity provider during user authentication, allowing service providers to authenticate users at any time without interacting with the identity provider. Our approach builds on threshold oblivious pseudorandom functions (TOPRF) to improve resistance against offline attacks and uses a distributed transaction ledger to improve availability. We prove the security of DAMFA in the universal composibility (UC) model by defining a UC definition (ideal functionality) for DAMFA and formally proving the security of our scheme via ideal-real simulation. Finally, we demonstrate the practicability of our proposed scheme through a prototype implementation. Omid Mir, Michael Roland 0001, René Mayrhofer |
Secur. Commun. Networks | 1 |
| 2018 | Recovery of Encrypted Mobile Device Backups from Partially Trusted Cloud ServersabstractIncluding electronic identities (eIDs), such as passports or driving licenses in smartphones transforms them into a single point of failure: loss, theft, or malfunction would prevent their users even from identifying themselves e.g. during travel. Therefore, a secure backup of such identity data is paramount, and an obvious solution is to store encrypted backups on cloud servers. However, the critical challenge is how a user decrypts the encrypted data backup if the user's device gets lost or stolen and there is no longer a secure storage (e.g. smartphone) to keep the secret key. To address this issue, Password-Protected Secret Sharing (PPSS) schemes have been proposed which allow a user to store a secret key among n servers such that the user can later reconstruct the secret key. Unfortunately, PPSS schemes are not appropriate for some applications. For example, users will be highly unlikely to remember a cryptographically strong password when the smartphone is lost. Also, they still suffer from inefficiency. In this paper, we propose a new secret key reconstruction protocol based recently popular PPSS schemes with a Fuzzy Extractor which allows a client to recover secret keys from an only partially trusted server and an auxiliary device using multiple key shares and a biometric identifier. We prove the security of our proposed protocol in the random oracle model where the parties can be corrupted separately at any time. An initial performance analysis shows that it is efficient for this use case. Omid Mir, René Mayrhofer, Michael Hölzl |
ARES | 1 |
| 2017 | Efficient anonymous authentication with key agreement protocol for wireless medical sensor networks
Omid Mir, Jorge Munilla, Saru Kumari |
Peer-to-Peer Netw. Appl. | 1 |