Mark Manulis

dblp:62/484 · DBLP profile ↗
← Back
69ranked-venue papers
16as first author
12since 2021 · last 2025
0000-0002-1512-9670ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 56 · 12 first-author · 10 since 2021Computer networks · 5 · 2 first-authorApplied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 1 since 2021Systems, architecture and hardware · 2Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1
YearPublicationVenuePosition
2025 Distributed Asynchronous Remote Key Generation
Mark Manulis, Hugo Nartz
ACNS (1)1
2025 Fast SNARK-based Non-Interactive Distributed Verifiable Random Function with Ethereum Compatibility
Jia Liu 0003, Mark Manulis
AsiaCCS2
2025 Attribute-Based Key Exchange with Optimal Efficiency
Liqun Chen 0002, Long Meng, Mark Manulis, Yangguang Tian
CANS3
2024 FABESA: Fast (and Anonymous) Attribute-Based Encryption under Standard Assumption
abstract
Attribute-Based Encryption (ABE) provides fine-grained access control to encrypted data and finds applications in various domains. The practicality of ABE schemes hinges on the balance between security and efficiency. The state-of-the-art adaptive secure ABE scheme, proven to be adaptively secure under standard assumptions (FAME, CCS'17), is less efficient compared to the fastest one (FABEO, CCS'22) which is only proven secure under the Generic Group Model (GGM). These traditional ABE schemes focus solely on message privacy. To address scenarios where attribute value information is also sensitive, Anonymous ABE (A2BE) ensures the privacy of both the message and attributes. However, most A2BE schemes suffer from intricate designs with low efficiency, and the security of the fastest key-policy A2BE (proposed in FEASE, USENIX'24) relies on the GGM.
Long Meng, Liqun Chen 0002, Yangguang Tian, Mark Manulis
CCS4
2024 Fully Homomorphic Encryption Beyond IND-CCA1 Security: Integrity Through Verifiability
Mark Manulis, Jérôme Nguyen
EUROCRYPT (2)1
2024 FEASE: Fast and Expressive Asymmetric Searchable Encryption
Long Meng, Liqun Chen 0002, Yangguang Tian, Mark Manulis, Suhui Liu
USENIX Security Symposium4
2024 Practical and secure policy-based chameleon hash for redactable blockchains
abstract
Abstract Policy-based chameleon hash functions have been widely proposed for its use in blockchain rewriting systems. They allow anyone to create a mutable transaction associated with an access policy, while an authorized user who possesses sufficient rewriting privileges from a trusted authority satisfying the access policy can rewrite the mutable transaction. However, existing chameleon hash functions lack certain fundamental security guarantees, including forward security and backward security. In this paper, we introduce a new primitive called forward/backward-secure policy-based chameleon hash (FB-PCH for short). We present a practical instantiation. We prove that the proposed scheme achieves forward/backward-secure collision-resistance, and show its practicality through implementation and evaluation analysis.
Nan Li 0007, Yingjiu Li, Mark Manulis, Yangguang Tian, Guomin Yang
Comput. J.3
2023 Generalised Asynchronous Remote Key Generation for Pairing-Based Cryptosystems
Nick Frymann, Daniel Gardham, Mark Manulis, Hugo Nartz
ACNS (1)3
2023 Asynchronous Remote Key Generation for Post-Quantum Cryptosystems from Lattices
abstract
Asynchronous Remote Key Generation (ARKG), introduced by Frymann et al. at CCS 2020, allows for the generation of unlinkable public keys by third parties, for which corresponding private keys may be later learned only by the key pair’s legitimate owner. These key pairs can then be used in common public-key cryptosystems, including signatures, PKE, KEMs, and schemes supporting delegation, such as proxy signatures. The only known instance of ARKG generates discrete-log-based keys.In this paper, we introduce new ARKG constructions for lattice-based cryptosystems. The key pairs generated using our ARKG scheme can be applied to lattice-based signatures and KEMs, which have recently been selected for standardisation in the NIST PQ process, or as alternative candidates.In particular, we address challenges associated with the noisiness of lattice hardness assumptions, which requires a new generalised definition of ARKG correctness, whilst preserving the security and privacy properties of the former instantiation. Our ARKG construction uses key encapsulation techniques by Brendel et al. (SAC 2020) coined Split KEMs. As an additional contribution, we also show that Kyber (Bos et al., EuroS&P 2018) can be used to construct a Split KEM. The security of our protocol is based on standard LWE assumptions. We also discuss its use with selected candidates from the NIST process and provide an implementation and benchmarks.
Nick Frymann, Daniel Gardham, Mark Manulis
EuroS&P3
2022 Revocable Hierarchical Attribute-Based Signatures from Lattices
Daniel Gardham, Mark Manulis
ACNS2
2022 Unlinkable Delegation of WebAuthn Credentials
Nick Frymann, Daniel Gardham, Mark Manulis
ESORICS (3)3
2022 TAPESTRY: A De-Centralized Service for Trusted Interaction Online
abstract
We present a novel de-centralised service for proving the provenance of online digital identity, exposed as an assistive tool to help non-expert users make better decisions about whom to trust online. Our service harnesses the digital personhood (DP); the longitudinal and multi-modal signals created through users’ lifelong digital interactions, as a basis for evidencing the provenance of identity. We describe how users may exchange trust evidence derived from their DP, in a granular and privacy-preserving manner, with other users in order to demonstrate coherence and longevity in their behaviour online. This is enabled through a novel secure infrastructure combining hybrid on- and off-chain storage combined with deep learning for DP analytics and visualization. We show how our tools enable users to make more effective decisions on whether to trust unknown third parties online, and also to spot behavioural deviations in their own social media footprints indicative of account hijacking.
Daniel Cooper, John P. Collomosse, Constantin Catalin Dragan, Mark Manulis, Jamie Steane, Arthi Kanchana Manohar, Jo Briggs, Helen S. Jones, Wendy Moncur
IEEE Trans. Serv. Comput.5
2020 Biometric-Authenticated Searchable Encryption
Daniel Gardham, Mark Manulis, Constantin Catalin Dragan
ACNS (2)2
2020 Asynchronous Remote Key Generation: An Analysis of Yubico's Proposal for W3C WebAuthn
abstract
WebAuthn, forming part of FIDO2, is a W3C standard for strong authentication, which employs digital signatures to authenticate web users whilst preserving their privacy. Owned by users, WebAuthn authenticators generate attested and unlinkable public-key credentials for each web service to authenticate users. Since the loss of authenticators prevents users from accessing web services, usable recovery solutions preserving the original WebAuthn design choices and security objectives are urgently needed. We examine Yubico's recent proposal for recovering from the loss of a WebAuthn authenticator by using a secondary backup authenticator. We analyse the cryptographic core of their proposal by modelling a new primitive, called Asynchronous Remote Key Generation (ARKG), which allows some primary authenticator to generate unlinkable public keys for which the backup authenticator may later recover corresponding private keys. Both processes occur asynchronously without the need for authenticators to export or share secrets, adhering to WebAuthn's attestation requirements. We prove that Yubico's proposal achieves our ARKG security properties under the discrete logarithm and PRF-ODH assumptions in the random oracle model. To prove that recovered private keys can be used securely by other cryptographic schemes, such as digital signatures or encryption schemes, we model compositional security of ARKG using composable games by Brzuska et al. (ACM CCS 2011), extended to the case of arbitrary public-key protocols. As well as being more general, our results show that private keys generated by ARKG may be used securely to produce unforgeable signatures for challenge-response protocols, as used in WebAuthn. We conclude our analysis by discussing concrete instantiations behind Yubico's ARKG protocol, its integration with the WebAuthn standard, performance, and usability aspects.
Nick Frymann, Daniel Gardham, Franziskus Kiefer, Emil Lundberg, Mark Manulis, Dain Nilsson
CCS5
2019 Hierarchical Attribute-Based Signatures: Short Keys and Optimal Signature Length
Daniel Gardham, Mark Manulis
ACNS2
2019 pRate: Anonymous Star Rating with Rating Secrecy
Jia Liu 0003, Mark Manulis
ACNS2
2019 Enhancing Security and Dependability of Industrial Networks with Opinion Dynamics
Juan E. Rubio, Mark Manulis, Cristina Alcaraz, Javier López 0001
ESORICS (2)2
2018 Hierarchical Attribute-Based Signatures
Constantin Catalin Dragan, Daniel Gardham, Mark Manulis
CANS3
2016 Blind Password Registration for Two-Server Password Authenticated Key Exchange and Secret Sharing Protocols
Franziskus Kiefer, Mark Manulis
ISC2
2016 Universally Composable Two-Server PAKE
Franziskus Kiefer, Mark Manulis
ISC2
2015 Oblivious PAKE: Efficient Handling of Password Trials
Franziskus Kiefer, Mark Manulis
ISC2
2014 Distributed Smooth Projective Hashing and Its Application to Two-Server Password Authenticated Key Exchange
Franziskus Kiefer, Mark Manulis
ACNS2
2014 Privacy-Enhanced Participatory Sensing with Collusion Resistance and Data Aggregation
Felix Günther 0001, Mark Manulis, Andreas Peter 0001
CANS2
2014 Zero-Knowledge Password Policy Checks and Verifier-Based PAKE
Franziskus Kiefer, Mark Manulis
ESORICS (2)2
2014 Forward-Secure Hierarchical Predicate Encryption
Juan Manuel González Nieto, Mark Manulis, Dongdong Sun
Comput. J.2
2013 Relations among Privacy Notions for Signcryption and Key Invisible "Sign-then-Encrypt"
Yang Wang 0074, Mark Manulis, Man Ho Au, Willy Susilo
ACISP2
2013 Unique Aggregate Signatures with Applications to Distributed Verifiable Random Functions
Veronika Kuchta, Mark Manulis
CANS2
2013 Pseudorandom signatures
abstract
We develop a three-level hierarchy of privacy notions for (unforgeable) digital signature schemes. We first prove mutual independence of existing notions of anonymity and confidentiality, and then show that these are implied by higher privacy goals. The top notion in our hierarchy is pseudorandomness: signatures with this property hide the entire information about the signing process and cannot be recognized as signatures when transmitted over a public network. This implies very strong unlinkability guarantees across different signers and even different signing algorithms, and gives rise to new forms of private public-key authentication.
Nils Fleischhacker, Felix Günther 0001, Franziskus Kiefer, Mark Manulis, Bertram Poettering
AsiaCCS4
2013 Security and privacy for digital ecosystems
Ioannis G. Askoxylakis, Mark Manulis, Joachim Posegga
Inf. Secur. Tech. Rep.2
2013 Publicly verifiable ciphertexts
Juan Manuel González Nieto, Mark Manulis, Bertram Poettering, Jothi Rangasamy, Douglas Stebila
J. Comput. Secur.2
2012 Topology-Driven Secure Initialization in Wireless Sensor Networks: A Tool-Assisted Approach
abstract
Secure initialization of sensor nodes with cryptographic keys is inherent to all security protocols and applicationsin the area of wireless sensor networks (WSN).We introduce a general framework, denoted TOPKEY, thatprovides tool assistance and performs secure initialization ofsensor nodes with cryptographic keys over the air by leveraging the transmission power to confine the area in which potential attackers can eavesdrop on communication. Our analysis shows that physical protection based on transmission power may, inpractice, lead to an acceptable level of key deployment security. Besides the fully automated key deployment, TOPKEY supports a five-step initialization process, suited to off-the-shelf sensor nodes that come without any pre-installed operating system. TOPKEY is currently tailored to static WSN topologies: it supports topology design and deploys topology-driven key generation for a range of WSN communication patterns. We implemented the framework and analyzed its performanceand scalability for commodity TelosB nodes and Contiki OS. Our analysis, performed with respect to different WSN topologies, shows that TOPKEY can be used to securely initialize a static network of about 100 nodes in less than one minute.
Stanislaus Stelle, Mark Manulis, Matthias Hollick
ARES2
2012 Sufficient Condition for Ephemeral Key-Leakage Resilient Tripartite Key Exchange
Atsushi Fujioka, Mark Manulis, Koutarou Suzuki, Berkant Ustaoglu
ACISP2
2012 Fully Private Revocable Predicate Encryption
abstract
We introduce the concept of Revocable Predicate Encryption (RPE), which extends current predicate encryption setting with revocation support: private keys can be used to decrypt an RPE ciphertext only if they match the decryption policy (defined via attributes encoded into the ciphertext and predicates associated with private keys) and were not revoked by the time the ciphertext was created. We formalize the notion of attribute hiding in the presence of revocation and propose an RPE scheme, called AH-RPE, which achieves attribute-hiding under the Decision Linear assumption in the standard model. We then present a stronger privacy notion, termed full hiding, which further cares about privacy of revoked users. We propose another RPE scheme, called FH-RPE, that adopts the Subset Cover Framework and offers full hiding under the Decision Linear assumption in the standard model. The scheme offers very flexible privacy-preserving access control to encrypted data and can be used in sender-local revocation scenarios.
Juan Manuel González Nieto, Mark Manulis, Dongdong Sun
ACISP2
2012 Forward-Secure Hierarchical Predicate Encryption
abstract
Secrecy of decryption keys is an important pre-requisite for security of any encryption scheme. Forward Security (FS) reduces damage from compromised keys by guaranteeing confidentiality of messages that were encrypted prior to the compromise event. In this paper we introduce FS to the powerful setting of Hierarchical Predicate Encryption (HPE) , proposed by Okamoto and Takashima (Asiacrypt 2009). Our FS-HPE scheme guarantees forward security for plaintexts and for attributes that are hidden in HPE ciphertexts. It further allows delegation of decrypting abilities at any point in time, independent of FS time evolution. It realizes zero-inner-product predicates and is proven adaptively secure under standard assumptions. As the “cross-product” approach taken in FS-HIBE is not directly applicable to the HPE setting, our construction resorts to techniques that are specific to existing HPE schemes and extends them with what can be seen as a reminiscent of binary tree encryption from FS-PKE.
Juan Manuel González Nieto, Mark Manulis, Dongdong Sun
Pairing2
2011 Private Discovery of Common Social Contacts
Emiliano De Cristofaro, Mark Manulis, Bertram Poettering
ACNS2
2011 Non-interactive and Re-usable Universally Composable String Commitments with Adaptive Security
Marc Fischlin, Benoît Libert, Mark Manulis
ASIACRYPT3
2011 Group Signature with Constant Revocation Costs for Signers and Verifiers
Chun-I Fan, Ruei-Hau Hsu, Mark Manulis
CANS3
2011 Practical affiliation-hiding authentication from improved polynomial interpolation
abstract
Among the plethora of privacy-friendly authentication techniques, affiliation-hiding (AH) protocols are valuable for their ability to hide not only identities of communicating users behind their affiliations (memberships to groups), but also these affiliations from non-members. These qualities become increasingly important in our highly computerized user-centric information society, where privacy is an elusive good.
Mark Manulis, Bertram Poettering
AsiaCCS1
2011 UPBA: User-Authenticated Property-Based Attestation
abstract
Remote attestation of computing platforms, using trusted hardware, guarantees the integrity, and by this the trustworthiness of a host to remote parties. While classical binary attestation attests the configuration itself, property-based attestation (PBA) attests properties and thus offers higher privacy guarantees to the host and its user. Nonetheless, both techniques are free from any user authentication mechanisms. Especially in distributed applications involving user interactions, the remote party may require assurance for the trustworthiness of the host and the authenticity of its user. Independence of user authentication from platform attestation may become an obstacle due to potential relay attacks. The User-Authenticated Property-Based Attestation (UPBA), introduced in this work, can assure a remote party that some computing platform is trustworthy, and that it is used at that very moment by some particular user. Our basic protocol is secure and practical. We prove its security formally, discuss its compatibility with current trusted computing technology, and illustrate several nice enhancements.
Mark Manulis, Marion Steiner
PST1
2011 Affiliation-Hiding Authentication with Minimal Bandwidth Consumption
Mark Manulis, Bertram Poettering
WISTP1
2011 Key management in distributed online social networks
abstract
Decentralized approaches for online social networks (OSNs) have been of recent research interest, enabling users to create profiles and share data like in other OSNs as, e.g., Facebook. Since the decentralized architecture does not contain a central authority that is able perform access control, encryption is needed to ensure the confidentiality of published data. This paper outlines strict requirements and weak constraints for the encryption of data attributes in decentralized OSNs. Subsequently, an overview of possible cryptographic solutions is given and their suitability according to these requirements is analyzed. As a result, the differences and trade-offs between and within the given approaches are expounded. The outcome of this paper can be used as a foundation for further investigations on this topic.
Felix Günther 0001, Mark Manulis, Thorsten Strufe
WOWMOM2
2011 SWISH: Secure WiFi sharing
Damien Leroy, Gregory Detal, Julien Cathalo, Mark Manulis, François Koeune, Olivier Bonaventure
Comput. Networks4
2011 Modeling key compromise impersonation attacks on group key exchange protocols
abstract
Two-party key exchange (2PKE) protocols have been rigorously analyzed under various models considering different adversarial actions. However, the analysis of group key exchange (GKE) protocols has not been as extensive as that of 2PKE protocols. Particularly, an important security attribute called key compromise impersonation (KCI) resilience has been completely ignored for the case of GKE protocols. Informally, a protocol is said to provide KCI resilience if the compromise of the long-term secret key of a protocol participant A does not allow the adversary to impersonate an honest participant B to A . In this paper, we argue that KCI resilience for GKE protocols is at least as important as it is for 2PKE protocols. Our first contribution is revised definitions of security for GKE protocols considering KCI attacks by both outsider and insider adversaries. We also give a new proof of security for an existing two-round GKE protocol under the revised security definitions assuming random oracles. We then show how to achieve insider KCIR in a generic way using a known compiler in the literature. As one may expect, this additional security assurance comes at the cost of an extra round of communication. Finally, we show that a few existing protocols are not secure against outsider KCI attacks. The attacks on these protocols illustrate the necessity of considering KCI resilience for GKE protocols.
M. Choudary Gorantla, Colin Boyd, Juan Manuel González Nieto, Mark Manulis
ACM Trans. Inf. Syst. Secur.4
2010 Redactable Signatures for Tree-Structured Data: Definitions and Constructions
Christopher Brzuska, Heike Schröder, Özgür Dagdelen, Marc Fischlin, Martin Franz, Stefan Katzenbeisser 0001, Mark Manulis, Cristina Onete, Andreas Peter 0001, Bertram Poettering, Dominique Schröder
ACNS7
2010 Privacy-Preserving Group Discovery with Linear Complexity
Mark Manulis, Benny Pinkas, Bertram Poettering
ACNS1
2010 Affiliation-Hiding Key Exchange with Untrusted Group Authorities
Mark Manulis, Bertram Poettering, Gene Tsudik
ACNS1
2010 Security and Privacy Objectives for Sensing Applications in Wireless Community Networks
abstract
Wireless Community Networks (WCN) are formed by the integration of user-operated wireless sensor networks that are internetworked by wireless mesh networks available within urban communities. WCNs enable novel applications for the members of the community. These include different sensing applications, where individuals contribute sensor data for further use within their community at large or with well-defined restrictions to certain users. Sensing application scenarios for WCNs differ from traditional sensor network applications with respect to their security and privacy requirements. In this paper, we define three representative scenarios-personal sensing, designated sensing, and community sensing. These scenarios are then studied with respect to their privacy and security implications. In particular, we identify main research questions and highlight the challenges of using various security and privacy approaches from networking and cryptography to make sensing applications in WCNs security and privacy aware.
Delphine Reinhardt, Matthias Hollick, Mark Manulis
ICCCN3
2010 Taming Big Brother Ambitions: More Privacy for Secret Handshakes
Mark Manulis, Bertram Poettering, Gene Tsudik
Privacy Enhancing Technologies1
2009 Group Key Exchange Enabling On-Demand Derivation of Peer-to-Peer Keys
Mark Manulis
ACNS1
2009 Fully Robust Tree-Diffie-Hellman Group Key Exchange
Timo Brecher, Emmanuel Bresson, Mark Manulis
CANS3
2009 Authenticated wireless roaming via tunnels: making mobile guests feel at home
abstract
In wireless roaming a mobile device obtains a service from some foreign network while being registered for the similar service at its own home network. However, recent proposals try to keep the service provider role behind the home network and let the foreign network create a tunnel connection through which all service requests of the mobile device are sent to and answered directly by the home network. Such Wireless Roaming via Tunnels (WRT) offers several (security) benefits but states also new security challenges on authentication and key establishment, as the goal is not only to protect the end-to-end communication between the tunnel peers but also the tunnel itself.
Mark Manulis, Damien Leroy, François Koeune, Olivier Bonaventure, Jean-Jacques Quisquater
AsiaCCS1
2009 Transparent Mobile Storage Protection in Trusted Virtual Domains
Luigi Catuogno, Hans Löhr, Mark Manulis, Ahmad-Reza Sadeghi, Marcel Winandy
LISA3
2009 Security model and framework for information aggregation in sensor networks
abstract
Information aggregation is an important operation in wireless sensor networks (WSNs) executed for the purpose of monitoring and reporting environmental data. Due to the performance constraints of sensor nodes the in-network form of the aggregation is especially attractive since it allows saving expensive resources during frequent network queries. Easy accessibility of networks and nodes and almost no physical protection against corruptions raise high security challenges. Protection against attacks aiming to falsify the aggregated result is considered to be of prime importance. In this article we design the first general framework for secure information aggregation in WSNs focusing on scenarios where aggregation is performed by one of its nodes. The framework achieves security against node corruptions and is based solely on the symmetric cryptographic primitives that are more suitable for WSNs in terms of efficiency. We analyze performance of the framework and unlike many previous approaches increase confidence in it by a rigorous proof of security within the specially designed formal security model.
Mark Manulis, Jörg Schwenk
ACM Trans. Sens. Networks1
2008 Enforcing User-Aware Browser-Based Mutual Authentication with Strong Locked Same Origin Policy
Sebastian Gajek, Mark Manulis, Jörg Schwenk
ACISP2
2008 Securing group key exchange against strong corruptions
abstract
When users run a group key exchange (GKE) protocol, they usually extract the key from some auxiliary (ephemeral) secret information generated during the execution. Strong corruptions are attacks by which an adversary can reveal these ephemeral secrets, in addition to the possibly used long-lived keys. Undoubtedly, security impact of strong corruptions is serious, and thus specifying appropriate security requirements and designing secure GKE protocols appears an interesting yet challenging task --- the aim of our paper.
Emmanuel Bresson, Mark Manulis
AsiaCCS2
2008 Provably secure browser-based user-aware mutual authentication over TLS
abstract
The standard solution for user authentication on the Web is to establish a TLS-based secure channel in server authenticated mode and run a protocol on top of TLS where the user enters a password in an HTML form. However, as many studies point out, the average Internet user is unable to identify the server based on a X.509 certificate so that impersonation attacks (e.g., phishing) are feasible. We tackle this problem by proposing a protocol that allows the user to identify the server based on human perceptible authenticators (e.g., picture, voice). We prove the security of this protocol by refining the game-based security model of Bellare and Rogaway and present a proof of concept implementation.
Sebastian Gajek, Mark Manulis, Ahmad-Reza Sadeghi, Jörg Schwenk
AsiaCCS2
2008 A Browser-Based Kerberos Authentication Scheme
Sebastian Gajek, Tibor Jager, Mark Manulis, Jörg Schwenk
ESORICS3
2008 Secure Multi-Coupons for Federated Environments: Privacy-Preserving and Customer-Friendly
Frederik Armknecht, Alberto N. Escalante, Hans Löhr, Mark Manulis, Ahmad-Reza Sadeghi
ISPEC4
2008 Property-Based Attestation without a Trusted Third Party
Liqun Chen 0002, Hans Löhr, Mark Manulis, Ahmad-Reza Sadeghi
ISC3
2008 Universally Composable Security Analysis of TLS
Sebastian Gajek, Mark Manulis, Olivier Pereira, Ahmad-Reza Sadeghi, Jörg Schwenk
ProvSec2
2008 Contributory group key exchange in the presence of malicious participants
abstract
In a group key exchange (GKE) protocol, the resulting group key should be computed by all participants such that none of them can gain any advantage concerning the protocol's output: misbehaving participants might have personal advantage in influencing the value of the group key. In fact, the absence of trust relationship is the main feature of GKE (when compared with group key transport) protocols. The existing notions of security are enlarged by identifying limitations in some previously proposed security models while taking into account different types of corruptions (weak and strong). To illustrate these notions, two efficient and provably secure generic solutions, compilers, are presented.
Emmanuel Bresson, Mark Manulis
IET Inf. Secur.2
2007 Malicious Participants in Group Key Exchange: Key Control and Contributiveness in the Shadow of Trust
Emmanuel Bresson, Mark Manulis
ATC2
2007 Provably Secure Framework for Information Aggregation in Sensor Networks
Mark Manulis, Jörg Schwenk
ICCSA (1)1
2007 Tree-based group key agreement framework for mobile ad-hoc networks
Lijun Liao, Mark Manulis
Future Gener. Comput. Syst.2
2006 Tree-Based Group Key Agreement Framework for Mobile Ad-Hoc Networks
abstract
In this paper we focus on the establishment of the shared key in mobile ad-hoc groups using a contributory group key agreement (CGKA). Based on the comparison results of most suitable contributory group key agreement (CGKA) protocols we propose a new framework for the group key agreement in mobile ad-hoc networks. Theoretical analysis results show that our framework achieves optimal trade-off between communication and computation costs compared to other protocols
Lijun Liao, Mark Manulis
AINA (2)2
2006 Property-Based Taming of Lying Mobile Nodes
abstract
Intelligent security protocols can verify whether the involved principals have properties that are defined based on certain functional and security policies. The property we focus on is the performance of mobile devices participating in a security protocol. In this context, the protocol should distribute the computation, communication and storage costs fairly among all devices. However, the protocol should foresee against cheating participants who may lie about their properties to gain advantage.
Mark Manulis, Ahmad-Reza Sadeghi
AINA (2)1
2006 Democratic group signatures: on an example of joint ventures
abstract
We propose a novel group-oriented signature scheme, called a democratic group signature (DGS). In DGS the scheme setting is controlled on a contributory basis, i.e., without any centralized trusted authority (group manager). Group members agree on a common tracing trapdoor, i.e., every member can trace issued signatures individually. Members are able to sign on behalf of the group while remaining anonymous only to third parties. DGS supports dynamic changes of the group formation (joins and leaves of members). For security reasons the tracing trapdoor is updated after every dynamic change. The DGS model results from strong changes to the standard model of group signatures caused by elimination of the group manager's role and distribution of the tracing rights to individuals.
Mark Manulis
AsiaCCS1
2006 Linkable Democratic Group Signatures
Mark Manulis, Ahmad-Reza Sadeghi, Jörg Schwenk
ISPEC1
2005 Contributory group key agreement protocols, revisited for mobile ad-hoc groups
abstract
Security of various group-oriented applications for mobile ad-hoc groups requires a group secret shared between all participants. Contributory group key agreement (CGKA) protocols, originally designed for peer groups in local- and wide-area wired networks, can also be used in ad-hoc scenarios because of the similar security requirements and trust relationship between participants that excludes any trusted central authority (e.g., a group manager) from the computation of the group key. We revise original protocols from the perspective of the mobile ad-hoc communication, classify mobile ad-hoc groups based on the performance of involved mobile devices, specify trust relationship between participants, propose further optimizations to original protocols to achieve better communication, computation and memory complexities. 1.
Mark Manulis
MASS1