VLDB 2026 Research / reviewers in the wild / expert
Pawel Szalachowski
dblp:35/11083
· DBLP profile ↗
36ranked-venue papers
8as first author
8since 2021 · last 2024
0000-0003-0871-3729ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 27 · 5 first-author · 5 since 2021Computer networks · 5 · 2 since 2021Systems, architecture and hardware · 3 · 2 first-authorApplied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-authorTheory of computation · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Accountable Fine-Grained Blockchain Rewriting in the Permissionless SettingabstractBlockchain rewriting with fine-grained access control allows a user to create a transaction associated with a set of attributes, while a modifier who possesses sufficient rewriting privileges from a trusted authority satisfying the attribute set can anonymously rewrite the transaction. However, it lacks accountability and is not designed for open blockchains that require no centralized trust authority. In this work, we introduce accountable fine-grained blockchain rewriting in a permissionless setting. The property of accountability allows the modifier’s identity and their rewriting privileges to be held accountable for the modified transactions in case of malicious rewriting. Our contributions are three-fold. First, we present a generic framework for secure blockchain rewriting in the permissionless setting. Second, we present an instantiation of our framework and show its practicality through evaluation analysis. Last, we demonstrate that our proof-of-concept implementation can be effectively integrated into open blockchains. Yangguang Tian, Bowen Liu 0005, Yingjiu Li, Pawel Szalachowski, Jianying Zhou 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2022 | Evaluating Blockchain Protocols with Abusive ModelingabstractStrategic evaluations of blockchain systems allow a better understanding of the security of the mining process. In recent years, many researchers have focused on developing optimal strategies to evaluate the impact of an adversary on the mining process using different attack situations such as selfish mining, double-spending, feather-forking, Denial of Service. These strategies rely on the use of the Markov Decision Process (MDP) to find optimal settings that an adversary can exploit to earn maximum profit in every round. However, these strategies do not consider a case where adversaries turn abusive, and their only aim is to harm the mining process without profit. Motivated by this, a self-defying adversary model is proposed that uses ZEBRA (Zero Expectation-Based Reward Abuse) strategy to cause a maximum impact on the rewards of the honest players at lower settings. With the proposed method, the adversary itself may not be profitable, but has better control over the chain growth and causes maximum damage to reward by delaying the blocks and inducing forks subject to its compliance degree. The evaluations are demonstrated to show the reward control by the adversary along with the impact on delays and forks, followed by the possibilities of attacks using the hashing powers of different mining pools. Vishal Sharma 0001, Pawel Szalachowski, Jianying Zhou 0001 |
AsiaCCS | 2 |
| 2022 | Reinshard: An Optimally Sharded Dual-Blockchain for Concurrency ResolutionabstractDecentralized control, low-complexity, flexible and efficient communications are the requirements of an architecture that aims to scale blockchains beyond the current state. Such properties are attainable by reducing ledger size and providing parallel operations in the blockchain. Sharding is one of the approaches that lower the burden of the nodes and enhance performance. However, the current solutions lack the features for resolving concurrency during cross-shard communications. With multiple participants belonging to different shards, handling concurrent operations is essential for optimal sharding. This issue becomes prominent due to the lack of architectural support and requires additional consensus for cross-shard communications. Relying on the advantages of hybrid Proof-of-Work/Proof-of-Stake (PoW/PoS), like Ethereum , hybrid consensus and 2-hop blockchain , we propose Reinshard , a new blockchain that inherits the properties of hybrid consensus for optimal sharding. Reinshard uses PoW and PoS chain-pairs with PoS sub-chains for all the valid chain-pairs where the hybrid consensus is attained through Verifiable Delay Function (VDF). Our architecture provides a secure method of arranging nodes in shards and resolves concurrency conflicts using the delay factor of VDF. The applicability of Reinshard is demonstrated through security and experimental evaluations. A practical concurrency problem is considered to show the efficacy of Reinshard in providing optimal sharding. Vishal Sharma 0001, Zengpeng Li 0001, Pawel Szalachowski, Teik Guan Tan, Jianying Zhou 0001 |
Distributed Ledger Technol. Res. Pract. | 3 |
| 2021 | LaKSA: A Probabilistic Proof-of-Stake Protocol
Daniël Reijsbergen, Pawel Szalachowski, Junming Ke, Zengpeng Li 0001, Jianying Zhou 0001 |
NDSS | 2 |
| 2021 | Building Low-Interactivity Multifactor Authenticated Key Exchange for Industrial Internet of ThingsabstractIndustrial Internet of Things (IIoT) brings together computers, devices, advanced analytics, and people in industries, such as transportation, oil plant, and power grid that leads to major efficiency and productivity gains for almost any industrial procedures. Due to the interconnection of devices in IIoT, communication security has become a critical issue to address in many emerging industry standards that require the authentication and key exchange procedure to be done to guarantee the authorized machine access (e.g., from users) and secure the data transmission between machines. To overcome the shortcoming (i.e., low entropy) of the memorable password in user authentication, it is rightfully recommended by industry standards (such as IEC-62443 family) to use multifactor authentication (MFA) for higher security levels. Notably, latency is one of the main sources of inefficiency when a device is communicating with other machines on IIoT. To mitigate latency, a smooth projective hash function (SPHF) built from well-studied standard assumptions is used to achieve a lowinteractivity multifactor authenticated key exchange protocol (MFAKE) because SPHF allows each party to prove to the others that he knows the right authentication factor(s). In this article, we are, therefore, motivated to build a new MFAKE named “secure remote multifactor (SRMF)” to achieve the humaninvolved “machine-to-machine” secure communication in IIoT. That is, SRMF leverages multiple user-centric authentication factors (such as password, biometric fingerprints, and PIN), and it can synergistically support multifactor registration (MFR), MFA, and multifactor key exchange (MFKE). Furthermore, to prevent authentication factors stored at the server exposing to attackers, the password-harden service (i.e., Pythia-PRF and USENIX'15) inspires us to develop a multifactor hardening service (MFHS) utilizing an oblivious pseudorandom function (OPRF). The balanced security of the proposed protocol is proved under the model of Bellare-Pointcheval-Rogaway (EUROCRYPTO'00) along with theoretical and experimental evaluations. Zengpeng Li 0001, Zheng Yang 0001, Pawel Szalachowski, Jianying Zhou 0001 |
IEEE Internet Things J. | 3 |
| 2021 | Secure Keyword Search and Data Sharing Mechanism for Cloud ComputingabstractThe emergence of cloud infrastructure has significantly reduced the costs of hardware and software resources in computing infrastructure. To ensure security, the data is usually encrypted before it's outsourced to the cloud. Unlike searching and sharing the plain data, it is challenging to search and share the data after encryption. Nevertheless, it is a critical task for the cloud service provider as the users expect the cloud to conduct a quick search and return the result without losing data confidentiality. To overcome these problems, we propose a ciphertext-policy attribute-based mechanism with keyword search and data sharing (CPAB-KSDS) for encrypted cloud data. The proposed solution not only supports attribute-based keyword search but also enables attribute-based data sharing at the same time, which is in contrast to the existing solutions that only support either one of two features. Additionally, the keyword in our scheme can be updated during the sharing phase without interacting with the PKG. In this article, we describe the notion of CPAB-KSDS as well as its security model. Besides, we propose a concrete scheme and prove that it is against chosen ciphertext attack and chosen keyword attack secure in the random oracle model. Finally, the proposed construction is demonstrated practical and efficient in the performance and property comparison. Chunpeng Ge 0001, Willy Susilo, Zhe Liu 0001, Jinyue Xia, Pawel Szalachowski, Liming Fang 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2021 | Password-Authenticated Decentralized IdentitiesabstractPassword-authenticated identities, where users establish username-password pairs with individual servers and use them later on for authentication, is the most widespread user authentication method over the Internet. Although they are simple, user-friendly, and broadly adopted, they offer insecure authentication and position server operators as trusted parties, giving them full control over users’ identities. To mitigate these limitations, many identity systems have embraced public-key cryptography and the concept of decentralization. All these systems; however, require users to create and manage public-private keypairs. Unfortunately, users usually do not have the required knowledge and resources to properly handle cryptographic secrets, which arguably contributed to the failures of many end-user public-key infrastructures (PKIs). In fact, as of today, no end-user PKI, able to authenticate users to web servers, has a significant adoption rate. In this paper, we propose Password-authenticated Decentralized Identities (PDIDs), an identity and authentication framework where users can register their self-sovereign username-password pairs and use them as universal credentials. Our system provides a global namespace, human-meaningful usernames, and resilience against username collision attacks. A user’s identity can be used to authenticate the user to any server without revealing that server anything about the password, such that no offline dictionary attacks are possible against the password. We analyze PDIDs and implement it using existing infrastructures and tools. We report on our implementation and evaluation. Pawel Szalachowski |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2021 | Decentralized and Lightweight Approach to Detect Eclipse Attacks on Proof of Work BlockchainsabstractClients of permissionless blockchain systems, like Bitcoin, rely on an underlying peer-to-peer network to send and receive transactions. It is critical that a client is connected to at least one honest peer, as otherwise the client can be convinced to accept a maliciously forked view of the blockchain. In such aneclipse attack, the client is unable to reliably distinguish the canonical view of the blockchain from the view provided by the attacker. The consequences of this can be catastrophic if the client makes business decisions based on a distorted view of the blockchain transactions. In this paper, we investigate the design space and propose two approaches for Bitcoin clients to detect whether an eclipse attack against them is ongoing. Each approach chooses a different trade-off between average attack detection time and network load. The first scheme is based on the detection of suspicious block timestamps. The second scheme allows blockchain clients to utilize their natural connections to the Internet (i.e., standard Web activity) to gossip about their blockchain views with contacted servers and their other clients. Our proposals improve upon previously proposed eclipse attack countermeasures without introducing any dedicated infrastructure or changes to the Bitcoin protocol and network, and we discuss an implementation. We demonstrate the effectiveness of the gossip-based schemes through rigorous analysis using original Internet traffic traces and real-world deployment. The results indicate that our protocol incurs a negligible overhead and detects eclipse attacks rapidly with high probability, and is well-suited for practical deployment. Bithin Alangot, Daniël Reijsbergen, Sarad Venugopalan, Pawel Szalachowski, Kiat Seng Yeo |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2020 | Policy-based Chameleon Hash for Blockchain Rewriting with Black-box AccountabilityabstractPolicy-based chameleon hash is a useful primitive for blockchain rewriting. It allows a party to create a transaction associated with an access policy, while another party who possesses enough rewriting privileges satisfying the access policy can rewrite the transaction. However, it lacks accountability. The chameleon trapdoor holder may abuse his/her rewriting privilege and maliciously rewrite the hashed object in the transaction without being identified. In this paper, we introduce policy-based chameleon hash with black-box accountability (PCHBA). Black-box accountability allows an attribute authority to link modified transactions to responsible transaction modifiers in case of dispute, in which any public user identifies those transaction modifiers from interacting with an access device/blackbox. We first present a generic framework of PCHBA. Then, we present a practical instantiation, showing its practicality through implementation and evaluation analysis. Yangguang Tian, Nan Li 0007, Yingjiu Li, Pawel Szalachowski, Jianying Zhou 0001 |
ACSAC | 4 |
| 2020 | SmartOTPs: An Air-Gapped 2-Factor Authentication for Smart-Contract WalletsabstractWith the recent rise of cryptocurrencies' popularity, the security and management of crypto-tokens have become critical. We have witnessed many attacks on users and providers, which have resulted in significant financial losses. To remedy these issues, several wallet solutions have been proposed. However, these solutions often lack either essential security features, usability, or do not allow users to customize their spending rules. In this paper, we propose SmartOTPs, a smart-contract wallet framework that gives a flexible, usable, and secure way of managing crypto-tokens in a self-sovereign fashion. The proposed framework consists of four components (i.e., an authenticator, a client, a hardware wallet, and a smart contract), and it provides 2-factor authentication (2FA) performed in two stages of interaction with the blockchain. To the best of our knowledge, our framework is the first one that utilizes one-time passwords (OTPs) in the setting of the public blockchain. In SmartOTPs, the OTPs are aggregated by a Merkle tree and hash chains whereby for each authentication only a short OTP (e.g., 16B-long) is transferred from the authenticator to the client. Such a novel setting enables us to make a fully air-gapped authenticator by utilizing small QR codes or a few mnemonic words, while additionally offering resilience against quantum cryptanalysis. We have made a proof-of-concept based on the Ethereum platform. Our cost analysis shows that the average cost of a transfer operation is comparable to existing 2FA solutions using smart contracts with multi-signatures. Ivan Homoliak, Dominik Breitenbacher, Ondrej Hujnak, Pieter H. Hartel, Alexander Binder, Pawel Szalachowski |
AFT | 6 |
| 2020 | Fail-safe Watchtowers and Short-lived Assertions for Payment ChannelsabstractThe recent development of payment channels and their extensions (e.g., state channels) provides a promising scalability solution for blockchains which allows untrusting parties to transact off-chain and resolve potential disputes via on-chain smart contracts. To protect participants who have no constant access to the blockchain, a watching service named as watchtower is proposed -- a third-party entity obligated to monitor channel states (on behalf of the participants) and correct them on-chain if necessary. Unfortunately, currently proposed watchtower schemes suffer from multiple security and efficiency drawbacks. Bowen Liu 0005, Pawel Szalachowski, Siwei Sun |
AsiaCCS | 2 |
| 2020 | SMACS: Smart Contract Access Control ServiceabstractAlthough blockchain-based smart contracts promise a "trustless" way of enforcing agreements even with monetary consequences, they suffer from multiple security issues. Many of these issues could be mitigated via an effective access control system, however, its realization is challenging due to the properties of current blockchain platforms (like lack of privacy, costly on-chain resources, or latency). To address this problem, we propose the SMACS framework, where updatable and sophisticated Access Control Rules (ACRs) for smart contracts can be realized with low cost. SMACS shifts the burden of expensive ACRs validation and management operations to an off-chain infrastructure, while implementing on-chain only lightweight token-based access control. SMACS is flexible and in addition to simple access control lists can easily implement rules enhancing the runtime security of smart contracts. With dedicated ACRs backed by vulnerability-detection tools, SMACS can protect vulnerable contracts after deployment. We fully implement SMACS and evaluate it. Bowen Liu 0005, Siwei Sun, Pawel Szalachowski |
DSN | 3 |
| 2020 | Formalizing Bitcoin Crashes with Universally Composable Security
Junming Ke, Pawel Szalachowski, Jianying Zhou 0001, Qiuliang Xu |
ISC | 2 |
| 2020 | Exploring HTTPS security inconsistencies: A cross-regional perspective
Eman Salem Alashwali, Pawel Szalachowski, Andrew P. Martin |
Comput. Secur. | 2 |
| 2019 | Does "www." Mean Better Transport Layer Security?abstractExperience shows that most researchers and developers tend to treat plain-domains (those that are not prefixed with "www" subdomains, e.g. "example.com") as synonyms for their equivalent www-domains (those that are prefixed with "www" sub-domains, e.g. "www.example.com"). In this paper, we analyse datasets of nearly two million plain-domains against their equivalent www-domains to answer the following question: Do plain-domains and their equivalent www-domains differ in TLS security configurations and certificates? If so, to what extent? Our results provide evidence of an interesting phenomenon: plain-domains and their equivalent www-domains differ in TLS security configurations and certificates in a non-trivial number of cases. Furthermore, www-domains tend to have stronger security configurations than their equivalent plain-domains. Interestingly, this phenomenon is more prevalent in the most-visited domains than in randomly-chosen domains. Further analysis of the top domains dataset shows that 53.35% of the plain-domains that show one or more weakness indicators (e.g. expired certificate) that are not shown in their equivalent www-domains perform HTTPS redirection from HTTPS plain-domains to their equivalent HTTPS www-domains. Additionally, 24.71% of these redirections contains plain-text HTTP intermediate URLs. In these cases, users see the final www-domains with strong TLS configurations and certificates, but in fact, the HTTPS request has passed through plain-domains that have less secure TLS configurations and certificates. Clearly, such a set-up introduces a weak link in the security of the overall interaction. Eman Salem Alashwali, Pawel Szalachowski, Andrew P. Martin |
ARES | 2 |
| 2019 | PDFS: Practical Data Feed Service for Smart Contracts
Juan Guarnizo, Pawel Szalachowski |
ESORICS (1) | 2 |
| 2019 | PADVA: A Blockchain-Based TLS Notary ServiceabstractThe TLS protocol is a de facto standard of secure client-server communication on the Internet. Unfortunately, the public-key infrastructure (PKI) deployed by TLS is a weakest-link system introducing hundreds of links (i.e., trusted entities). Consequently, an adversary compromising a single trusted entity can impersonate any website. Notary systems, based on multi-path probing, were early and promising proposals to detect and prevent such attacks. Unfortunately, despite their benefits, they are not widely deployed, mainly due to their long-standing unresolved problems. In this paper, we present Persistent and Accountable Domain Validation (PADVA), which is a next-generation blockchain-based TLS notary service. PADVA keeps notaries auditable and accountable, introduces service-level agreements and mechanisms to enforce them, relaxes availability requirements for notaries, and works with the legacy TLS ecosystem. We implemented and evaluated PADVA, and our experiments indicate its efficiency and deployability. Pawel Szalachowski |
ICPADS | 1 |
| 2019 | IBWH: An Intermittent Block Withholding Attack with Optimal Mining Reward Rate
Junming Ke, Pawel Szalachowski, Jianying Zhou 0001, Qiuliang Xu, Zheng Yang 0001 |
ISC | 2 |
| 2019 | Towards Forward Secure Internet Traffic
Eman Salem Alashwali, Pawel Szalachowski, Andrew P. Martin |
SecureComm (1) | 2 |
| 2019 | StrongChain: Transparent and Collaborative Proof-of-Work Consensus
Pawel Szalachowski, Daniël Reijsbergen, Ivan Homoliak, Siwei Sun |
USENIX Security Symposium | 1 |
| 2019 | Network Transparency for Better Internet SecurityabstractThe lack of transparency for Internet communication prevents effective mitigation of today's security threats: i) Source addresses cannot be trusted and enable untraceable reflection attacks. ii) Malicious communication is opaque to all network entities, except for the receiver; and although ISPs are control points that can stop such attacks, effective detection and mitigation requires information that is available only at the end hosts. We propose TRIS, an architecture that bootstraps transparency for Internet communication. TRIS enables the definition of misbehavior according to the unique requirements of hosts, and then it constructs verifiable evidence of misbehavior. First, hosts express desired traffic properties for incoming traffic; a deviation from these properties signifies misbehavior. Second, ISPs construct verifiable evidence of misbehavior for the traffic they forward. If misbehavior is detected, it can then be proven to the ISPs of the communicating hosts. We implement our architecture on commodity hardware and demonstrate that verifiable proof of misbehavior introduces little overhead with respect to bandwidth and packet processing in the network: our prototype achieves line-rate performance for common packet sizes, saturating a 10 Gbps link with a single CPU core. In addition, we tackle incremental deployment issues and describe interoperability with today's Internet architecture. Christos Pappas, Taeho Lee 0003, Raphael M. Reischuk, Pawel Szalachowski, Adrian Perrig |
IEEE/ACM Trans. Netw. | 4 |
| 2018 | Towards Sustainable Evolution for the TLS Public-Key InfrastructureabstractMotivated by the weaknesses of today's TLS public-key infrastructure (PKI), recent studies have proposed numerous enhancements to fortify the PKI ecosystem. Deploying one particular enhancement is no panacea, since each one solves only a subset of the problems. At the same time, the high deployment barrier makes the benefit-cost ratio tilt in the wrong direction, leading to disappointing adoption rates for most proposals. Taeho Lee 0003, Christos Pappas, Pawel Szalachowski, Adrian Perrig |
AsiaCCS | 3 |
| 2018 | DSTC: DNS-Based Strict TLS Configurations
Eman Salem Alashwali, Pawel Szalachowski |
CRiSIS | 2 |
| 2018 | A Metapolicy Framework for Enhancing Domain Expressiveness on the Internet
Gaurav Varshney, Pawel Szalachowski |
SecureComm (2) | 2 |
| 2018 | Design, Analysis, and Implementation of ARPKI: An Attack-Resilient Public-Key InfrastructureabstractThe current Transport Layer Security (TLS) Public-Key Infrastructure (PKI) is based on a weakest-link security model that depends on over a thousand trust roots. The recent history of malicious and compromised Certification Authorities has fueled the desire for alternatives. Creating a new, secure infrastructure is, however, a surprisingly challenging task due to the large number of parties involved and the many ways that they can interact. A principled approach to its design is therefore mandatory, as humans cannot feasibly consider all the cases that can occur due to the multitude of interleavings of actions by legitimate parties and attackers, such as private key compromises (e.g., domain, Certification Authority, log server, other trusted entities), key revocations, key updates, etc. We present ARPKI, a PKI architecture that ensures that certificate-related operations, such as certificate issuance, update, revocation, and validation, are transparent and accountable. ARPKI efficiently supports these operations, and gracefully handles catastrophic events such as domain key loss or compromise. Moreover ARPKI is the first PKI architecture that is co-designed with a formal model, and we verify its core security property using the TAMARIN prover. We prove that ARPKI offers extremely strong security guarantees, where compromising even n - 1 trusted signing and verifying entities is insufficient to launch a man-in-the-middle attack. Moreover, ARPKI's use deters misbehavior as all operations are publicly visible. Finally, we present a proof-of-concept implementation that provides all the features required for deployment. Our experiments indicate that ARPKI efficiently handles the certification process with low overhead. It does not incur additional latency to TLS, since no additional round trips are required. David A. Basin, Cas Cremers, Tiffany Hyun-Jin Kim, Adrian Perrig, Ralf Sasse, Pawel Szalachowski |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2017 | Authentication Challenges in a Global EnvironmentabstractIn this article, we address the problem of scaling authentication for naming, routing, and end-entity (EE) certification to a global environment in which authentication policies and users’ sets of trust roots vary widely. The current mechanisms for authenticating names (DNSSEC), routes (BGPSEC), and EE certificates (TLS) do not support a coexistence of authentication policies, affect the entire Internet when compromised, cannot update trust root information efficiently, and do not provide users with the ability to make flexible trust decisions. We propose the Scalable Authentication Infrastructure for Next-generation Trust (SAINT), which partitions the Internet into groups with common, local trust roots and isolates the effects of a compromised trust root. SAINT requires groups with direct routing connections to cross-sign each other for authentication purposes, allowing diverse authentication policies while keeping all entities’ authentication information globally discoverable. SAINT makes trust root management a central part of the network architecture, enabling trust root updates within seconds and allowing users to make flexible trust decisions. SAINT operates without a significant performance penalty and can be deployed alongside existing infrastructures. Stephanos Matsumoto, Raphael M. Reischuk, Pawel Szalachowski, Tiffany Hyun-Jin Kim, Adrian Perrig |
ACM Trans. Priv. Secur. | 3 |
| 2016 | Source Accountability with Domain-brokered PrivacyabstractIn an ideal Internet, every packet would be attributable to its sender, while host identities and transmitted content would remain private. Designing such a network is challenging because source accountability and communication privacy are typically viewed as conflicting properties. In this paper, we propose an architecture that guarantees source accountability and privacy-preserving communication by enlisting ISPs as accountability agents and privacy brokers. While ISPs can link every packet that originates from their network to their customers, customer identity remains unknown to the rest of the Internet. In our architecture, network communication is based on Ephemeral Identifiers (EphIDs)---cryptographic tokens that can be linked to a source only by the source's ISP. We demonstrate that EphIDs can be generated and processed efficiently, and we analyze the practical considerations for deployment. Taeho Lee 0003, Christos Pappas, David Barrera 0003, Pawel Szalachowski, Adrian Perrig |
CoNEXT | 4 |
| 2016 | PKI Safety Net (PKISN): Addressing the Too-Big-to-Be-Revoked Problem of the TLS EcosystemabstractIn a public-key infrastructure (PKI), clients must have an efficient and secure way to determine whether a certificate was revoked (by an entity considered as legitimate to do so), while preserving user privacy. A few certification authorities (CAs) are currently responsible for the issuance of the large majority of TLS certificates. These certificates are considered valid only if the certificate of the issuing CA is also valid. The certificates of these important CAs are effectively too big to be revoked, as revoking them would result in massive collateral damage. To solve this problem, we redesign the current revocation system with a novel approach that we call PKI Safety Net (PKISN), which uses publicly accessible logs to store certificates (in the spirit of Certificate Transparency) and revocations. The proposed system extends existing mechanisms, which enables simple deployment. Moreover, we present a complete implementation and evaluation of our scheme. Pawel Szalachowski, Laurent Chuat, Adrian Perrig |
EuroS&P | 1 |
| 2016 | RITM: Revocation in the MiddleabstractAlthough TLS is used on a daily basis by many critical applications, the public-key infrastructure that it relies on still lacks an adequate revocation mechanism. An ideal revocation mechanism should be inexpensive, efficient, secure, and privacypreserving. Moreover, rising trends in pervasive encryption pose new scalability challenges that a modern revocation system should address. In this paper, we investigate how network nodes can deliver certificate-validity information to clients. We present RITM, a framework in which middleboxes (as opposed to clients, servers, or certification authorities) store revocation-related data. RITM provides a secure revocation-checking mechanism that preserves user privacy. We also propose to take advantage of content-delivery networks (CDNs) and argue that they would constitute a fast and cost-effective way to disseminate revocations. Additionally, RITM keeps certification authorities accountable for the revocations that they have issued, and it minimizes overhead at clients and servers, as they have to neither store nor download any messages. We also describe feasible deployment models and present an evaluation of RITM to demonstrate its feasibility and benefits in a real-world deployment. Pawel Szalachowski, Laurent Chuat, Taeho Lee 0003, Adrian Perrig |
ICDCS | 1 |
| 2016 | Communication based on per-packet One-Time AddressesabstractThe act of communication on the Internet inevitably leaks information. In particular, network headers reveal information (e.g., source address, flow information); yet, protecting the header has proven challenging. Past research successfully protected certain fields of the headers (e.g., source address), but no proposal has attempted to eliminate flow information from the header so that packets cannot be linked to flows; flow information is systematically used to subvert privacy. Hence, we investigate the following questions: Can we design an architecture that eliminates flow-packet linkability? Can we do so without imposing impractical requirements on the network infrastructure? Our proposed architecture is based on per-packet One Time Address (OTA)-an address that a host uses to send or receive exactly one packet. Furthermore, the architecture eliminates any implicit (e.g., the standard five-tuple in TCP/UDP packets) or explicit (e.g., flow identifier) flow information from packet headers. Yet, the architecture allows the communicating hosts to demultiplex seemingly unrelated packets to flows. We have implemented the proposed architecture, and our evaluation shows that it can satisfy today's packet forwarding requirements. Taeho Lee 0003, Christos Pappas, Pawel Szalachowski, Adrian Perrig |
ICNP | 3 |
| 2016 | SIBRA: Scalable Internet Bandwidth Reservation Architecture
Cristina Basescu, Raphael M. Reischuk, Pawel Szalachowski, Adrian Perrig, Hsu-Chun Hsiao, Ayumu Kubota, Junpei Urakawa |
NDSS | 3 |
| 2016 | Collusion-resilient broadcast encryption based on dual-evolving one-way function treesabstractThe Internet keeps flourishing and enables unexpected possibilities to all aspects of individuals' life. Such distributed networking systems as wireless sensor networks and Internet of things are widely deployed. Yet, in the meantime secure group communication remains a challenging task in these environments. To address this challenge, this paper aims at lightweight group key establishment with strong security properties. We propose a broadcast encryption scheme based on one-way function trees and specify a dual-evolving approach for dynamic group-membership update. Then we complement the scheme by a content-protection protocol and further optimize the protocol in terms of communication efficiency. As with our analysis, our scheme can successfully prevent a key leakage attack, namely, collusion attack. Through our comprehensive evaluations, we confirm the effectiveness and the adequacy of our solution in distributed networking systems. Zhiming Zheng 0001, Pawel Szalachowski, Qi Wang 0002 |
Secur. Commun. Networks | 3 |
| 2015 | Secure broadcast in distributed networks with strong adversariesabstractAbstract This paper proposes a framework that enables secureone‐to‐manycommunication for networks with limited capabilities in the face of a strong adversary that can capture an arbitrary set of nodes. Our approach consists of two main components: (a) group key establishment protocol and (b) special key management. Especially, we try to address the following question:How strong of security properties can we achieve for broadcast communication in hardware‐limited networks with a strong adversary?We propose approaches and their variants that neither require special hardware nor use costly cryptographic operations. With thorough security and efficiency analyses, we discuss how our solutions can be applied to a variety of hardware‐limited distributed systems. We also describe the implementation and evaluation results of the most promising variants. Copyright © 2015 John Wiley & Sons, Ltd. Pawel Szalachowski, Tiffany Hyun-Jin Kim |
Secur. Commun. Networks | 1 |
| 2014 | ARPKI: Attack Resilient Public-Key InfrastructureabstractWe present ARPKI, a public-key infrastructure that ensures that certificate-related operations, such as certificate issuance, update, revocation, and validation, are transparent and accountable. ARPKI is the first such infrastructure that systematically takes into account requirements identified by previous research. Moreover, ARPKI is co-designed with a formal model, and we verify its core security property using the Tamarin prover. We present a proof-of-concept implementation providing all features required for deployment. ARPKI efficiently handles the certification process with low overhead and without incurring additional latency to TLS. David A. Basin, Cas Cremers, Tiffany Hyun-Jin Kim, Adrian Perrig, Ralf Sasse, Pawel Szalachowski |
CCS | 6 |
| 2014 | PoliCert: Secure and Flexible TLS Certificate ManagementabstractThe recently proposed concept of publicly verifiable logs is a promising approach for mitigating security issues and threats of the current Public-Key Infrastructure (PKI). Although much progress has been made towards a more secure infrastructure, the currently proposed approaches still suffer from security vulnerabilities, inefficiency, or incremental deployment challenges. Pawel Szalachowski, Stephanos Matsumoto, Adrian Perrig |
CCS | 1 |
| 2010 | CMAC, CCM and GCM/GMAC: Advanced modes of operation of symmetric block ciphers in wireless sensor networks
Pawel Szalachowski, Bogdan Ksiezopolski, Zbigniew Kotulski |
Inf. Process. Lett. | 1 |