Dmitry Kogan

dblp:61/210 · DBLP profile ↗
← Back
12ranked-venue papers
6as first author
3since 2021 · last 2025
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 2 first-author · 3 since 2021Theory of computation · 3 · 2 first-authorSystems, architecture and hardware · 1 · 1 first-authorComputer networks · 1 · 1 first-author
YearPublicationVenuePosition
2025 An Attack on TON's ADNL Secure Channel Protocol
abstract
We present an attack on the Abstract Datagram Network Layer (ADNL) protocol used in The Open Network (TON), currently the 10th largest blockchain by market capitalization. In its TCP variant, ADNL secures communication between clients and specialized nodes called liteservers, which provide access to blockchain data. We identify two crypto-graphic design flaws in this protocol: a handshake that permits session-key replay and a non-standard integrity mechanism whose security critically depends on message confidentiality. We transform these vulnerabilities into an efficient plaintext-recovery attack by exploiting two ADNL communication patterns, allowing message reordering across replayed sessions. We then develop a plaintext model for this scenario and construct an efficient algorithm that recovers the keystream using a fraction of known plaintexts and a handful of replays. We implement our attack and show that an attacker intercepting the communication between a TON liteserver and a widely deployed ADNL client can recover the keystream used to encrypt server responses by performing eight connection replays to the server. This allows the decryption of sensitive data, such as account balances and user activity patterns. Additionally, the attacker can modify server responses to manipulate blockchain information displayed to the client, including account balances and asset prices.
Aviv Frenkel, Dmitry Kogan
SP2
2022 Single-Server Private Information Retrieval with Sublinear Amortized Time
Henry Corrigan-Gibbs, Alexandra Henzinger, Dmitry Kogan
EUROCRYPT (2)3
2021 Private Blocklist Lookups with Checklist
Dmitry Kogan, Henry Corrigan-Gibbs
USENIX Security Symposium1
2020 Oblivious Pseudorandom Functions from Isogenies
Dan Boneh, Dmitry Kogan, Katharine Woo
ASIACRYPT (2)2
2020 Private Information Retrieval with Sublinear Online Time
Henry Corrigan-Gibbs, Dmitry Kogan
EUROCRYPT (1)2
2019 The Function-Inversion Problem: Barriers and Opportunities
Henry Corrigan-Gibbs, Dmitry Kogan
TCC (1)2
2018 The Discrete-Logarithm Problem with Preprocessing
Henry Corrigan-Gibbs, Dmitry Kogan
EUROCRYPT (2)2
2017 T/Key: Second-Factor Authentication From Secure Hash Chains
abstract
Time-based one-time password (TOTP) systems in use today require storing secrets on both the client and the server. As a result, an attack on the server can expose all second factors for all users in the system. We present T/Key, a time-based one-time password system that requires no secrets on the server. Our work modernizes the classic S/Key system and addresses the challenges in making such a system secure and practical. At the heart of our construction is a new lower bound analyzing the hardness of inverting hash chains composed of independent random functions, which formalizes the security of this widely used primitive. Additionally, we develop a near-optimal algorithm for quickly generating the required elements in a hash chain with little memory on the client. We report on our implementation of T/Key as an Android application. T/Key can be used as a replacement for current TOTP systems, and it remains secure in the event of a server-side compromise. The cost, as with S/Key, is that one-time passwords are longer than the standard six characters used in TOTP.
Dmitry Kogan, Nathan Manohar, Dan Boneh
CCS1
2017 The Case For Secure Delegation
abstract
Today's secure stream protocols, SSH and TLS, were designed for end-to-end security and do not include a role for semi-trusted third parties. As a result, users who wish to delegate some of their authority to third parties (e.g., to run SSH clients in the cloud, or to host websites on CDNs) rely on insecure workarounds such as ssh-agent forwarding and Keyless TLS. We argue that protocol designers should consider the delegation use-case explicitly, and we propose a definition of "secure" delegation: Before a principal agrees to delegate its authority, a system should provide it with secure advance notice of who will do what to whom under that authority.
Dmitry Kogan, Henri Stern, Ashley Tolbert, David Mazières, Keith Winstein
HotNets1
2015 Sketching Cuts in Graphs and Hypergraphs
abstract
Sketching and streaming algorithms are in the forefront of current research directions for cut problems in graphs. In the streaming model, we show that (1--ε)-approximation for Max-Cut must use n{1-O(ε)} space; moreover, beating 4/5-approximation requires polynomial space. For the sketching model, we show that every r-uniform hypergraph admits a (1+ ε)-cut-sparsifier (i.e., a weighted subhypergraph that approximately preserves all the cuts) with O(ε-2n(r+log n)) edges. We also make first steps towards sketching general CSPs (Constraint Satisfaction Problems).
Dmitry Kogan, Robert Krauthgamer
ITCS1
2000 Remote Reference Counting: Distributed Garbage Collection with Low Communication and Computation Overhead
Dmitry Kogan, Assaf Schuster
J. Parallel Distributed Comput.1
1997 Collecting Garbage Pages in a Distributed Shared Memory with Reduced Memory and Communication Overhead
Dmitry Kogan, Assaf Schuster
ESA1