Aikaterini Mitrokotsa

dblp:22/417 · also Katerina Mitrokotsa · DBLP profile ↗
← Back
62ranked-venue papers
5as first author
19since 2021 · last 2026
0000-0002-7073-0258ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 46 · 2 first-author · 19 since 2021Computer networks · 7 · 1 first-authorArtificial intelligence and machine learning · 4Systems, architecture and hardware · 2Human-computer interaction and ubiquitous computing · 2 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2026 Privacy-preserving Proximity Testing from Geometric Fuzzy Matching
abstract
Proximity testing is crucial to location-privacy applications, from discovering nearby friends to enabling UAV collision avoidance. In such settings, users must determine proximity without revealing their exact locations. This motivates privacy-preserving proximity testing (PPPT) protocols revealing only if the proximity condition holds, while hiding both parties' inputs. However, most existing PPPT protocols rely on strong assumptions (e.g., non-colluding servers) or require simultaneous interaction, limiting their practicality. Moreover, they typically define proximity using metric distances (e.g., Euclidean distance), failing to support richer membership queries for complex regions like buildings or parks.
Florias Papadopoulos, Ioannis Katis, Aikaterini Mitrokotsa
AsiaCCS3
2026 Simulation Secure Quadratic Functional Encryption for Inner-Product and Quadratic Predicates
Wilson Tsuata, Subhranil Dutta, Aikaterini Mitrokotsa
PKC (3)3
2025 A Post-quantum Distributed OPRF from the Legendre PRF
Novak Kaluderovic, Nan Cheng 0002, Aikaterini Mitrokotsa
ESORICS (2)3
2025 Multi-Client Attribute-Based Unbounded Inner Product Functional Encryption, and More
Subhranil Dutta, Aikaterini Mitrokotsa, Tapas Pal, Jenit Tomy
PKC (5)2
2025 BUFFing Threshold Signature Schemes
Marc Fischlin, Aikaterini Mitrokotsa, Jenit Tomy
PKC (3)2
2024 Decentralized Private Stream Aggregation from Lattices
Uddipana Dowerah, Aikaterini Mitrokotsa
ACNS (2)2
2024 Nomadic: Normalising Maliciously-Secure Distance with Cosine Similarity for Two-Party Biometric Authentication
abstract
Computing the distance between two non-normalized vectors x and y, represented by Δ (x, y) and comparing it to a predefined public threshold τ is an essential functionality used in privacy-sensitive applications such as biometric authentication, identification, machine learning algorithms (e.g., linear regression, k-nearest neighbors, etc.), and typo-tolerant password-based authentication. Tackling a widely used distance metric, Nomadic studies the privacy-preserving evaluation of cosine similarity in a two-party (2PC) distributed setting. We illustrate this setting in a scenario where a client uses biometrics to authenticate to a service provider, outsourcing the distance calculation to two computing servers. In this setting, we propose two novel 2PC protocols to evaluate the normalising cosine similarity between non-normalised two vectors followed by comparison to a public threshold, one in the semi-honest and one in the malicious setting. Our protocols combine additive secret sharing with function secret sharing, saving one communication round by employing a new building block to compute the composition of a function f yielding a binary result with a subsequent binary gate. Overall, our protocols outperform all prior works, requiring only two communication rounds under a strong threat model that also deals with malicious inputs via normalisation. We evaluate our protocols in the setting of biometric authentication using voice, and the obtained results reveal a notable efficiency improvement compared to existing state-of-the-art works.
Nan Cheng 0002, Melek Önen, Aikaterini Mitrokotsa, Oubaïda Chouchane, Massimiliano Todisco, Alberto Ibarrondo
AsiaCCS3
2024 Efficient Two-Party Secure Aggregation via Incremental Distributed Point Function
abstract
Computing the maximum from a list of secret inputs is a widely-used functionality that is employed either indirectly as a building block in secure computation frameworks, such as ABY (NDSS'15) or directly used in multiple applications that solve optimisation problems, such as secure machine learning or secure aggregation statistics. Incremental distributed point function (I-DPF) is a powerful primitive (IEEE S&P'21) that significantly reduces the client-to-server communication and are employed to efficiently and securely compute aggregation statistics. In this paper, we investigate whether I-DPF can be used to improve the efficiency of secure two-party computation (2PC) with an emphasis on computing the maximum value and the k-th (with$k$unknown to the computing parties) ranked value from a list of secret inputs. Our answer is affirmative, and we propose novel secure 2PC protocols that use I-DPF as a building block, resulting in significant efficiency gains compared to the state-of-the-art. More precisely, our contributions are: (i) We present two new secure computation frameworks that efficiently compute secure aggregation statistics bit-wisely or batch-wisely; (ii) we propose novel protocols to compute the maximum value, the k-th ranked value from a list of secret inputs; (iii) we provide variations of the proposed protocols that can perform batch computations and thus provide further efficiency improvements; and (iv) we provide an extensive performance evaluation for all proposed protocols. Our protocols have a communication complexity that is independent of the number of secret inputs and linear to the length of the secret input domain. Our experimental results show enhanced efficiency over state-of-the-art solutions, particularly notable when handling large-scale inputs. For instance, in scenarios involving an input set of five million elements with an input domain size of 31 bits, our protocol$\Pi_{\text{Max}}$achieves an 18% reduction in online execution time and a 67% decrease in communication volume compared to the most efficient existing solution.
Nan Cheng 0002, Aikaterini Mitrokotsa, Frank Hartmann
EuroS&P2
2024 SACfe: Secure Access Control in Functional Encryption with Unbounded Data
abstract
Privacy is a major concern in large-scale digital applications, such as cloud-computing, machine learning services, and access control. Users want to protect not only their plain data but also their associated attributes (e.g., age, location, etc). Functional encryption (FE) is a cryptographic tool that allows fine-grained access control over encrypted data. However, existing FE fall short as they are either inefficient and far from reality or they leak sensitive user-specific information. We propose SACfe, a novel attribute-based FE scheme that provides secure, fine-grained access control and hides both the user's attributes and the function applied to the data, while preserving the data's confidentiality. Moreover, it enables users to encrypt unbounded-length messages along with an arbitrary number of hidden attributes into ciphertexts. We design SACfe, a protocol for performing linear computation on encrypted data while enforcing access control based on inner product predicates. We show how SACfe can be used for online biometric authentication for privacy-preserving access control. As an additional contribution, we introduce an attribute-based linear FE for unbounded length of messages and functions where access control is realized by monotone span programs. We implement our protocols using the CiFEr cryptographic library and show its efficiency for practical settings.
Uddipana Dowerah, Subhranil Dutta, Frank Hartmann, Aikaterini Mitrokotsa, Sayantan Mukherjee, Tapas Pal
EuroS&P4
2024 Oblivious Identity-Based Encryption - (IBE Secure Against an Adversarial KGC)
Aikaterini Mitrokotsa, Sayantan Mukherjee, Jenit Tomy
SAC (1)1
2024 Constant-Round Private Decision Tree Evaluation for Secret Shared Data
abstract
Decision tree evaluation is extensively used in machine learning to construct accurate classification models. Often in the cloud-assisted communication paradigm cloud servers execute remote evaluations of classification models using clients' data. In this setting, the need for private decision tree evaluation (PDTE) has emerged to guarantee no leakage of information for the client's input nor the service provider's trained model i.e., decision tree. In this paper, we propose a private decision tree evaluation protocol based on the three-party replicated secret sharing (RSS) scheme. This enables us to securely classify inputs without any leakage of the provided input or the trained decision tree model. Our protocol only requires constant rounds of communication among servers, which is useful in a network with longer delays.Ma et al. (NDSS 2021) presented a lightweight PDTE protocol with sublinear communication cost with linear round complexity in the size of the input data. This protocol works well in the low latency network such as LAN while its total execution time is unfavourably increased in the WAN setting. In contrast, Tsuchida et al. (ProvSec 2020) constructed a constant round PDTE protocol at the cost of communication complexity, which works well in the WAN setting. Although their construction still requires 25 rounds, it showed a possible direction on how to make constant round PDTE protocols. Ji et al. (IEEE Transactions on Dependable and Secure Computing) presented a simplified PDTE with constant rounds using the function secret sharing (FSS) at the cost of communication complexity. Our proposed protocol only requires five rounds among the employed three servers executing secret sharing schemes, which is comparable to previously proposed protocols that are based on garbled circuits and homomorphic encryption. To further demonstrate the efficiency of our protocol, we evaluated it using real-world classification datasets. The evaluation results indicate that our protocol provides better concrete performance in the WAN setting that has a large network delay.
Nan Cheng 0002, Aikaterini Mitrokotsa, Hiraku Morita, Kazunari Tozawa
Proc. Priv. Enhancing Technol.3
2023 A Framework for UC Secure Privacy Preserving Biometric Authentication Using Efficient Functional Encryption
Johannes Ottenhues, Aikaterini Mitrokotsa
ACNS2
2023 Efficient Three-party Boolean-to-Arithmetic Share Conversion
abstract
The advantage of mixed-protocol multi-party secure computation frameworks lies in their ability to utilize different sharing types optimally for diverse tasks. A key module in these frameworks are Boolean-to-arithmetic secret sharing conversion protocols, which transfer a secret value from Boolean secret sharing to arithmetic secret sharing. This conversion process can either take in the Boolean secret sharing of a bit or a secret binary string. In this work, we suggest the application of an innovative correlated random tuple for this task in the semi-honest three-party (3PC) setting. This tuple provides the basis for building Boolean-to-arithmetic share conversion protocols. Specifically, we propose two such protocols in the semi-honest 3PC setting, the first protocol takes as input the Boolean secret sharing of a bit, and the second protocol takes as input the Boolean secret sharing of a secret binary string. When it comes to concrete efficiency, the first protocol shows superior performance compared to the existing state-of-the-art in ABY3 (CCS ’18). It achieves this by reducing the total required communication from 2ℓ bits per party to 4ℓ/3+1 bits (including 4ℓ/3 bits in the setup phase, and 1 bit in the online phase) per party, while maintaining a single round of optimized communication. On the other hand, the second protocol involves two rounds of online communication and its communication cost is comparable to that of ABY2.0 (USENIX’21) that relies on correlated oblivious transfer.
Nan Cheng 0002, Aikaterini Mitrokotsa
PST3
2023 Unbounded Predicate Inner Product Functional Encryption from Pairings
abstract
Abstract Predicate inner product functional encryption (P-IPFE) is essentially attribute-based IPFE (AB-IPFE) which additionally hides attributes associated to ciphertexts. In a P-IPFE, a message $${\textbf {x}}$$ x is encrypted under an attribute $${\textbf {w}}$$ w and a secret key is generated for a pair $$({\textbf {y}}, {\textbf {v}})$$ ( y , v ) such that recovery of $$\langle {{\textbf {x}}}, {{\textbf {y}}}\rangle $$ ⟨ x , y ⟩ requires the vectors $${\textbf {w}}, {\textbf {v}}$$ w , v to satisfy a linear relation. We call a P-IPFE unbounded if it can encrypt unbounded length attributes and message vectors. $$\bullet $$ ∙ zero predicate IPFE. We construct the first unbounded zero predicate IPFE (UZP-IPFE) which recovers $$\langle {{\textbf {x}}}, {{\textbf {y}}}\rangle $$ ⟨ x , y ⟩ if $$\langle {{\textbf {w}}}, {{\textbf {v}}}\rangle =0$$ ⟨ w , v ⟩ = 0 . This construction is inspired by the unbounded IPFE of Tomida and Takashima (ASIACRYPT 2018) and the unbounded zero inner product encryption of Okamoto and Takashima (ASIACRYPT 2012). The UZP-IPFE stands secure against general attackers capable of decrypting the challenge ciphertext. Concretely, it provides full attribute-hiding security in the indistinguishability-based semi-adaptive model under the standard symmetric external Diffie–Hellman assumption. $$\bullet $$ ∙ non-zero predicate IPFE. We present the first unbounded non-zero predicate IPFE (UNP-IPFE) that successfully recovers $$\langle {{\textbf {x}}}, {{\textbf {y}}}\rangle $$ ⟨ x , y ⟩ if $$\langle {{\textbf {w}}}, {{\textbf {v}}}\rangle \ne 0$$ ⟨ w , v ⟩ ≠ 0 . We generically transform an unbounded quadratic FE (UQFE) scheme to weak attribute-hiding UNP-IPFE in both public and secret key setting. Interestingly, our secret key simulation secure UNP-IPFE has succinct secret keys and is constructed from a novel succinct UQFE that we build in the random oracle model. We leave the problem of constructing a succinct public key UNP-IPFE or UQFE in the standard model as an important open problem.
Uddipana Dowerah, Subhranil Dutta, Aikaterini Mitrokotsa, Sayantan Mukherjee, Tapas Pal
J. Cryptol.3
2022 WiP: Verifiable, Secure and Energy-Efficient Private Data Aggregation in Wireless Sensor Networks
abstract
Large amounts of data are collected by IoT devices, and transmitted wirelessly to cloud servers for aggregation. These data are often sensitive and need to remain secret. Moreover, the employed servers might be untrustworthy, and maliciously alter their results. To address this, public verifiability must be provided, i.e., anyone can check the result's correctness. Nevertheless, any such protocol must also cope with the limited battery capacity of the IoT devices.
Georgia Tsaloli, Alejandro Lancho, Aikaterini Mitrokotsa, Giuseppe Durisi
SACMAT3
2021 Non-interactive, Secure Verifiable Aggregation for Decentralized, Privacy-Preserving Learning
Carlo Brunetta, Georgia Tsaloli, Bei Liang, Gustavo Banegas, Aikaterini Mitrokotsa
ACISP5
2021 sf DEVA: Decentralized, Verifiable Secure Aggregation for Privacy-Preserving Learning
Georgia Tsaloli, Bei Liang, Carlo Brunetta, Gustavo Banegas, Aikaterini Mitrokotsa
ISC5
2021 Turn-Based Communication Channels
Carlo Brunetta, Mario Larangeira, Bei Liang, Aikaterini Mitrokotsa, Keisuke Tanaka
ProvSec4
2021 Homomorphic signcryption with public plaintext-result checkability
abstract
Abstract Signcryption originally proposed by Zheng (CRYPTO′97) is a useful cryptographic primitive that provides strong confidentiality and integrity guarantees. This article addresses the question whether it is possible to homomorphically compute arbitrary functions on signcrypted data. The answer is affirmative and a new cryptographic primitive, homomorphic signcryption (HSC) with public plaintext‐result checkability is proposed that allows both to evaluate arbitrary functions over signcrypted data and makes it possible for anyone to publicly test whether a given ciphertext is the signcryption of the message under the key. Two notions of message privacy are also investigated: weak message privacy and message privacy depending on whether the original signcryptions used in the evaluation are disclosed or not. More precisely, the contributions are two‐fold: (i) two different definitions of HSC with public plaintext‐result checkability is provided for arbitrary functions in terms of syntax, unforgeability and message privacy depending on if the homomorphic computation is performed in a private or in a public evaluation setting, (ii) two HSC constructions are proposed: one for a public evaluation setting and another for a private evaluation setting and security is formally proved.
Bei Liang, Aikaterini Mitrokotsa, Rui Xue 0001
IET Inf. Secur.3
2020 A Delegated Proof of Proximity Scheme for Industrial Internet of Things Consensus
abstract
Recently, work with Distributed Ledger Technologies (DLTs) has focussed on leveraging the decentralised, immutable ledger for use outside of cryptocurrency. One industry poised to benefit from DLTs is the Industrial Internet of Things (IIoT); as the inherent cryptographic mechanisms and alternative trust model make DLTs an attractive solution for distributed networks. Existing DLTs are unsuitable for the IIoT, owing to the large computational and energy requirements for consensus operations and the slow throughput of validated blocks. With limited processing, energy and storage resources and a deadline sensitive operational environment, DLTs in their current state could serve to introduce intolerable latency into IIoT processes and deplete constrained, device resources. Designed for the IIoT context, and based off Delegated Proof of Stake, this work serves to introduce a new consensus mechanism called Delegated Proof of Proximity (DPoP). Using existing location discovery processes, nodes in close proximity to a sensor event are elected as delegates; whose role is to handle consensus and block generation. In using information already known to IIoT devices, DPoP aims to reduce wasted effort, improve throughput by limiting the number of nodes required for consensus operations and improve scalability and flexibility of DLT solutions as the IIoT network continues to grow.
Lehlogonolo Ledwaba, Gerhard P. Hancke 0002, Aikaterini Mitrokotsa, Sherrin John Isaac
IECON3
2019 Code-Based Zero Knowledge PRF Arguments
Carlo Brunetta, Bei Liang, Aikaterini Mitrokotsa
ISC3
2019 Robust Distributed Pseudorandom Functions for mNP Access Structures
Bei Liang, Aikaterini Mitrokotsa
ISC2
2019 Multi-key homomorphic authenticators
abstract
Homomorphic authenticators (HAs) enable a client to authenticate a large collection of data elements and outsource them, along with the corresponding authenticators, to an untrusted server. At any later point, the server can generate a short authenticator vouching for the correctness of the output y of a function f computed on the outsourced data, i.e. . The notion of HAs studied so far, however, only supports executions of computations over data authenticated by a single user. Motivated by realistic scenarios in which large datasets include data provided by multiple users, we study the concept of multi‐key homomorphic authenticators. In a nutshell, multi‐key HAs are like HAs with the extra feature of allowing the holder of public evaluation keys to compute on data authenticated under different secret keys. In this paper, we introduce and formally define multi‐key HAs. Secondly, we propose a construction of a multi‐key homomorphic signature based on standard lattices and supporting the evaluation of circuits of bounded polynomial depth. Thirdly, we provide a construction of multi‐key homomorphic MACs based only on pseudorandom functions and supporting the evaluation of low‐degree arithmetic circuits.
Dario Fiore 0001, Aikaterini Mitrokotsa, Luca Nizzardo, Elena Pagnin
IET Inf. Secur.2
2019 Decentralised Functional Signatures
abstract
With the rapid development of the Internet of Things (IoT) a lot of critical information is shared however without having guarantees about the origin and integrity of the information. Digital signatures can provide important integrity guarantees to prevent illegal users from getting access to private and sensitive data in various IoT applications. Functional signatures, introduced by Boyle, Goldwasser and Ivan (PKC 2014) as signatures with a finegrained access control, allow an authority to generate signing keys corresponding to various functions such that a user with a signing key for a function f , can sign the image of the function f on a message m i.e., can sign f ( m ). Okamoto and Takashima (PKC 2013) firstly proposed the notion of a decentralized multi-authority functional signature (DMA-FS) scheme, which supports non-monotone access structures combined with inner-product relations. In this paper, we generalise the definition of DMA-FS proposed by Okamoto et al. (PKC13) for even more general policy functions, which support any polynomial-size boolean predicates other than the inner product relation and allow modifications of the original message. In our multi-authority functional signature (MAFS), there are multiple authorities and each one is able to certify a specific function and issue a corresponding functional signing key for each individual with some property, rendering them very useful in application settings such smart homes, smart cities, smart health care etc. We also provide a general transformation from a standard signature scheme to a MAFS scheme. Moreover, we present a way to build a function private MAFS from a FS without function privacy together with SNARKs.
Bei Liang, Aikaterini Mitrokotsa
Mob. Networks Appl.2
2018 Verifiable Homomorphic Secret Sharing
Georgia Tsaloli, Bei Liang, Aikaterini Mitrokotsa
ProvSec3
2018 Tangible security: Survey of methods supporting secure ad-hoc connects of edge devices with physical context
Qiao Hu 0005, Jingyi Zhang 0006, Aikaterini Mitrokotsa, Gerhard P. Hancke 0002
Comput. Secur.3
2018 HB+DB: Distance bounding meets human based authentication
Elena Pagnin, Anjia Yang, Qiao Hu 0005, Gerhard P. Hancke 0002, Aikaterini Mitrokotsa
Future Gener. Comput. Syst.5
2018 VIVO: A secure, privacy-preserving, and real-time crowd-sensing framework for the Internet of Things
Luca Luceri, Felipe Cardoso, Michela Papandrea, Silvia Giordano, Julia Buwaya, Stéphane Kuendig, Constantinos Marios Angelopoulos, José D. P. Rolim, Zhongliang Zhao, Jose Luis Carrera, Torsten Braun, Aristide C. Y. Tossou, Christos Dimitrakakis, Aikaterini Mitrokotsa
Pervasive Mob. Comput.14
2018 Two-Hop Distance-Bounding Protocols: Keep Your Friends Close
abstract
Authentication in wireless communications often depends on the physical proximity to a location. Distance-bounding (DB) protocols are cross-layer authentication protocols that are based on the round-trip-time of challenge-response exchanges and can be employed to guarantee physical proximity and combat relay attacks. However, traditional DB protocols rely on the assumption that the prover (e.g., user) is in the communication range of the verifier (e.g., access point); something that might not be the case in multiple access control scenarios in ubiquitous computing environments as well as when we need to verify the proximity of our two-hop neighbour in an ad-hoc network. In this paper, we extend traditional DB protocols to a two-hop setting, i.e., when the prover is out of the communication range of the verifier and thus, they both need to rely on an untrusted in-between entity in order to verify proximity. We present a formal framework that captures the most representative classes of existing DB protocols and provide a general method to extend traditional DB protocols to the two-hop case (three participants). We analyze the security of two-hop DB protocols and identify connections with the security issues of the corresponding one-hop case. Finally, we demonstrate the correctness of our security analysis and the efficiency of our model by transforming five existing DB protocols to the two-hop setting and we evaluate their performance with simulated experiments.
Anjia Yang, Elena Pagnin, Aikaterini Mitrokotsa, Gerhard P. Hancke 0002, Duncan S. Wong
IEEE Trans. Mob. Comput.3
2017 Revisiting Yasuda et al.'s Biometric Authentication Protocol: Are You Private Enough?
Elena Pagnin, Aikaterini Mitrokotsa
CANS3
2017 Distributed Pseudorandom Functions for General Access Structures in NP
Bei Liang, Aikaterini Mitrokotsa
ICICS2
2017 Fast and Adaptively Secure Signatures in the Random Oracle Model from Indistinguishability Obfuscation (Short Paper)
Bei Liang, Aikaterini Mitrokotsa
ISPEC2
2017 A Differentially Private Encryption Scheme
Carlo Brunetta, Christos Dimitrakakis, Bei Liang, Aikaterini Mitrokotsa
ISC4
2017 Revisiting Two-Hop Distance-Bounding Protocols: Are You Really Close Enough?
Nektaria Kaloudi, Aikaterini Mitrokotsa
WISTP2
2017 Near-optimal blacklisting
Christos Dimitrakakis, Aikaterini Mitrokotsa
Comput. Secur.2
2017 Differential Privacy for Bayesian Inference through Posterior Sampling
abstract
Differential privacy formalises privacy-preserving mechanisms that provide access to a database. Can Bayesian inference be used directly to provide private access to data? The answer is yes: under certain conditions on the prior, sampling from the posterior distribution can lead to a desired level of privacy and utility. For a uniform treatment, we define differential privacy over arbitrary data set metrics, outcome spaces and distribution families. This allows us to also deal with non-i.i.d or non-tabular data sets. We then prove bounds on the sensitivity of the posterior to the data, which delivers a measure of robustness. We also show how to use posterior sampling to provide differentially private responses to queries, within a decision-theoretic framework. Finally, we provide bounds on the utility of answers to queries and on the ability of an adversary to distinguish between data sets. The latter are complemented by a novel use of Le Cam's method to obtain lower bounds on distinguishability. Our results hold for arbitrary metrics, including those for the common definition of differential privacy. For specific choices of the metric, we give a number of examples satisfying our assumptions.
Christos Dimitrakakis, Blaine Nelson, Zuhe Zhang, Aikaterini Mitrokotsa, Benjamin I. P. Rubinstein
J. Mach. Learn. Res.4
2017 Privacy-Preserving Biometric Authentication: Challenges and Directions
abstract
An emerging direction for authenticating people is the adoption of biometric authentication systems. Biometric credentials are becoming increasingly popular as a means of authenticating people due to the wide range of advantages that they provide with respect to classical authentication methods (e.g., password-based authentication). The most characteristic feature of this authentication method is the naturally strong bond between a user and her biometric credentials. This very same advantageous property, however, raises serious security and privacy concerns in case the biometric trait gets compromised. In this article, we present the most challenging issues that need to be taken into consideration when designing secure and privacy-preserving biometric authentication protocols. More precisely, we describe the main threats against privacy-preserving biometric authentication systems and give directions on possible countermeasures in order to design secure and privacy-preserving biometric authentication protocols.
Elena Pagnin, Aikaterini Mitrokotsa
Secur. Commun. Networks2
2016 Multi-key Homomorphic Authenticators
Dario Fiore 0001, Aikaterini Mitrokotsa, Luca Nizzardo, Elena Pagnin
ASIACRYPT (2)2
2016 Efficient Verifiable Computation of XOR for Biometric Authentication
Aysajan Abidin, Abdelrahaman Aly, Enrique Argones-Rúa, Aikaterini Mitrokotsa
CANS4
2016 9th International Workshop on Artificial Intelligence and Security: AISec 2016
abstract
Artificial Intelligence (AI) and Machine Learning (ML) provide a set of useful analytic and decision-making techniques that are being leveraged by an ever-growing community of practitioners, including many whose applications have security-sensitive elements. However, while security researchers often utilize such techniques to address problems and AI/ML researchers develop techniques for Big Data analytics applications, neither community devotes much attention to the other. Within security research, AI/ML components are usually regarded as black-box solvers. Conversely, the learning community seldom considers the security/privacy implications entailed in the application of their algorithms when they are designing them. While these two communities generally focus on different directions, where these two fields do meet, interesting problems appear. Researchers working in this intersection have raised many novel questions for both communities and created a new branch of research known as secure learning. The AISec workshop has become the primary venue for this unique fusion of research. In recent years, there has been an increase of activity within the AISec/secure learning community. There are several reasons for this surge. Firstly, machine learning, data mining, and other artificial intelligence technologies play a key role in extracting knowledge, situational awareness, and security intelligence from Big Data. Secondly, companies like Google, Facebook, Amazon, and Splunk are increasingly exploring and deploying learning technologies to address Big Data problems for their customers.
David Mandell Freeman, Aikaterini Mitrokotsa, Arunesh Sinha
CCS2
2016 Special issue on recent advances in physical-layer security
Gerhard P. Hancke 0002, Aikaterini Mitrokotsa, Reihaneh Safavi-Naini, Damien Sauveron
Comput. Networks2
2015 Workshop Summary of AISec'15: 2015 Workshop on Artificial Intelligent and Security
abstract
It is our great pleasure to welcome you to the 2015 ACM Workshop Artificial Intelligence and Security (AISec 2015) - the eight annual workshop addressing technologies that fuse intelligent systems into computer security applications and the implications of these approaches. The workshop's aim is to advance research at the intersection of artificial intelligence, machine learning, privacy and security. In particular, AISec gives researchers and practitioners working within one or more of those fields a platform for interdisciplinary discussion, which would otherwise be lacking. Hopefully, the workshop leads to a high degree of cross-pollination between groups working across these areas. The papers to be presented in this year's program span topics ranging from adversarial learning, detecting fake OSN accounts, malware classification to privacy preserving data processing and game theoretic techniques in adversarial learning. We are delighted to again be co-located with the premier ACM Computer and Communication Security (CCS 2015) conference. This year we had 25 submissions from Asia, Europe and North America. After a rigorous reviewing process, involving at 2-3 referees per paper, 11 papers were accepted for presentation at the workshop, including presentation-only papers.
Christos Dimitrakakis, Aikaterini Mitrokotsa, Arunesh Sinha
CCS2
2015 HB+DB, mitigating man-in-the-middle attacks against HB+ with distance bounding
abstract
Authentication for resource-constrained devices is seen as one of the major challenges in current wireless communication networks. The HB+ protocol performs device authentication based on the learning parity with noise (LPN) problem and simple computational steps, that renders it suitable for resource-constrained devices such as radio frequency identification (RFID) tags. However, it has been shown that the HB+ protocol as well as many of its variants are vulnerable to a simple man-in-the-middle attack. We demonstrate that this attack could be mitigated using physical layer measures from distance-bounding and simple modifications to devices' radio receivers. Our hybrid solution (HB+DB) is shown to provide both effective distance-bounding using a lightweight HB+-based response function, and resistance against the man-in-the-middle attack to HB+. We provide experimental evaluation of our results as well as a brief discussion on practical requirements for secure implementation.
Elena Pagnin, Anjia Yang, Gerhard P. Hancke 0002, Aikaterini Mitrokotsa
WISEC4
2015 Practical and provably secure distance-bounding
abstract
Abstract From contactless payments to remote car unlocking, many applications are vulnerable to relay attacks. Distance bounding protocols are the main practical countermeasure against these attacks. In this paper, we present a formal analysis of SKI, which recently emerged as the first family of lightweight and provably secure distance bounding protocols. More precisely, we explicate a general formalism for distance-bounding protocols, which lead to this practical and provably secure class of protocols (and it could lead to others). We prove that SKI and its variants are provably secure, even under the real-life setting of noisy communications, against the main types of relay attacks: distance-fraud and generalised versions of mafia- and terrorist-fraud. To attain resistance to terrorist-fraud, we reinforce the idea of using secret sharing, combined with the new notion of a leakage scheme. In view of resistance to generalised mafia-frauds (and terrorist-frauds), we present the notion of circular-keying for pseudorandom functions (PRFs); this notion models the employment of a PRF, with possible linear reuse of the key. We also identify the need of PRF masking to fix common mistakes in existing security proofs/claims. Finally, we enhance our design to guarantee resistance to terrorist-fraud in the presence of noise.
Ioana Boureanu, Aikaterini Mitrokotsa, Serge Vaudenay
J. Comput. Secur.2
2015 Expected loss analysis for authentication in constrained channels
abstract
Abstract We derive bounds on the expected loss for authentication protocols in channels which are constrained due to noisy conditions and communication costs. This is motivated by a number of authentication protocols, where at least some part of the authentication is performed during a phase, lasting n rounds, with no error correction. This requires assigning an acceptable threshold for the number of detected errors and taking into account the cost of incorrect authentication and of communication. This paper describes a framework enabling an expected loss analysis for all the protocols in this family. Computationally simple methods to obtain nearly optimal values for the threshold, as well as for the number of rounds are suggested and upper bounds on the expected loss, holding uniformly, are given. These bounds are tight, as shown by a matching lower bound. Finally, a method to adaptively select both the number of rounds and the threshold is proposed for a certain class of protocols.
Christos Dimitrakakis, Aikaterini Mitrokotsa, Serge Vaudenay
J. Comput. Secur.2
2014 Robust and Private Bayesian Inference
Christos Dimitrakakis, Blaine Nelson, Aikaterini Mitrokotsa, Benjamin I. P. Rubinstein
ALT3
2014 Security of a Privacy-Preserving Biometric Authentication Protocol Revisited
Aysajan Abidin, Kanta Matsuura, Aikaterini Mitrokotsa
CANS3
2014 Workshop Summary of AISec'14: 2014 Workshop on Artificial Intelligent and Security
abstract
It is our great pleasure to welcome you to the 2014 ACM Workshop Artificial Intelligence and Security (AISec 2014) -- the seventh annual workshop addressing technologies that fuse intelligent systems into computer security applications and the implications of these approaches. The workshop's aim is to advance research at the intersection of artificial intelligence, machine learning, privacy and security. In particular, AISec gives researchers and practitioners working within one or more of those fields a platform for interdisciplinary discussion, which would otherwise be lacking. Hopefully, the workshop will lead to the initiation of knew col- laborations between groups working across these areas. The papers to be presented in this year's program include topics such as the analysis of privacy, adversarial learning models, intrusion detection and automatic advertisement filtering. We are delighted to again be co-located with the premier ACM Computer and Communication Security (CCS 2014) conference. This year we had 23 submissions from Asia, Europe and North America. This year, the workshop also includes a "presentation-only" track, for papers appearing elsewhere. After a rigorous reviewing process, 11 original papers were accepted for presentation at the workshop, while one paper was accepted for peresentation only.
Christos Dimitrakakis, Aikaterini Mitrokotsa, Benjamin I. P. Rubinstein
CCS2
2014 Location leakage in distance bounding: Why location privacy does not work
Aikaterini Mitrokotsa, Cristina Onete, Serge Vaudenay
Comput. Secur.1
2013 Towards Secure Distance Bounding
Ioana Boureanu, Aikaterini Mitrokotsa, Serge Vaudenay
FSE2
2013 Practical and Provably Secure Distance-Bounding
Ioana Boureanu, Aikaterini Mitrokotsa, Serge Vaudenay
ISC2
2013 Intrusion detection in MANET using classification algorithms: The effects of cost and model selection
Aikaterini Mitrokotsa, Christos Dimitrakakis
Ad Hoc Networks1
2013 On Selecting the Nonce Length in Distance-Bounding Protocols
abstract
Distance-bounding protocols form a family of challenge–response authentication protocols that have been introduced to thwart relay attacks. They enable a verifier to authenticate and to establish an upper bound on the physical distance to an untrusted prover. We provide a detailed security analysis of a family of such protocols. More precisely, we show that the secret key shared between the verifier and the prover can be leaked after a number of nonce repetitions. The leakage probability, while exponentially decreasing with the nonce length, is only weakly dependent on the key length. Our main contribution is a high probability bound on the number of sessions required for the attacker to discover the secret, and an experimental analysis of the attack under noisy conditions. Both of these show that the attack's success probability mainly depends on the length of the used nonces rather than the length of the shared secret key. The theoretical bound could be used by practitioners to appropriately select their security parameters. While longer nonces can guard against this type of attack, we provide a possible countermeasure which successfully combats these attacks even when short nonces are used.
Aikaterini Mitrokotsa, Pedro Peris-Lopez, Christos Dimitrakakis, Serge Vaudenay
Comput. J.1
2012 The Bussard-Bagga and Other Distance-Bounding Protocols under Attacks
Aslí Bay, Ioana Boureanu, Aikaterini Mitrokotsa, Iosif Spulber, Serge Vaudenay
Inscrypt3
2012 Expected loss bounds for authentication in constrained channels
abstract
We derive bounds on the expected loss for authentication protocols in channels which are constrained due to noisy conditions and communication costs. This is motivated by a number of authentication protocols, where at least some part of the authentication is performed during a phase, lasting n rounds, with no error correction. This requires assigning an acceptable threshold for the number of detected errors and taking into account the cost of incorrect authentication and of communication. This paper describes a framework enabling an expected loss analysis for all the protocols in this family. Computationally simple methods to obtain nearly optimal values for the threshold, as well as for the number of rounds are suggested and upper bounds on the expected loss, holding uniformly, are given. These bounds are tight, as shown by a matching lower bound. Finally, a method to adaptively select both the number of rounds and the threshold is proposed for a certain class of protocols.
Christos Dimitrakakis, Aikaterini Mitrokotsa, Serge Vaudenay
INFOCOM2
2012 Evaluation of classification algorithms for intrusion detection in MANETs
Sergio Pastrana, Aikaterini Mitrokotsa, Agustín Orfila, Pedro Peris-Lopez
Knowl. Based Syst.2
2012 User-driven RFID applications and challenges
Aikaterini Mitrokotsa, Quan Z. Sheng, Zakaria Maamar
Pers. Ubiquitous Comput.1
2012 Guest Editors' Introduction: Special Section on Learning, Games, and Security
abstract
The articles in this special section are devoted to the topic of learning, computer games and system security.
Christos Dimitrakakis, Tom Karygiannis, Aikaterini Mitrokotsa
IEEE Trans. Dependable Secur. Comput.3
2011 A Note on a Privacy-Preserving Distance-Bounding Protocol
Jean-Philippe Aumasson, Aikaterini Mitrokotsa, Pedro Peris-Lopez
ICICS2
2011 RFID technology, systems, and applications
Quan Z. Sheng, Sherali Zeadally, Aikaterini Mitrokotsa, Zakaria Maamar
J. Netw. Comput. Appl.3
2009 Statistical Decision Making for Authentication and Intrusion Detection
abstract
User authentication and intrusion detection differ from standard classification problems in that while we have data generated from legitimate users, impostor or intrusion data is scarce or non-existent. We review existing techniques for dealing with this problem and propose a novel alternative based on a principled statistical decision-making view point. We examine the technique on a toy problem and validate it on complex real-world data from an RFID based access control system. The results indicate that it can significantly outperform the classical world model approach. The method could be more generally useful in other decision- making scenarios where there is a lack of adversary data.
Christos Dimitrakakis, Aikaterini Mitrokotsa
ICMLA2
2004 DDoS attacks and defense mechanisms: classification and state-of-the-art
Christos Douligeris, Aikaterini Mitrokotsa
Comput. Networks2