Ivan Visconti

dblp:81/5771 · DBLP profile ↗
← Back
76ranked-venue papers
4as first author
16since 2021 · last 2026
0000-0003-2381-5846ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 58 · 2 first-author · 13 since 2021Theory of computation · 27 · 2 first-author · 1 since 2021Computer networks · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2026 Round-Optimal GUC-Secure Blind Signatures From Minimal Computational and Setup Assumptions - From Minimal Computational and Setup Assumptions
Michele Ciampi, Pierpaolo Della Monica, Ivan Visconti
CRYPTO (7)3
2026 Improved Concurrent-Secure Blind Schnorr Signatures
Pierpaolo Della Monica, Ivan Visconti
CRYPTO (7)2
2026 ACTS: Attestations of Contents in TLS Sessions
Pierpaolo Della Monica, Ivan Visconti, Andrea Vitaletti, Marco Zecchini
NDSS2
2025 Decentralized Fair Exchange with Advertising
Pierpaolo Della Monica, Ivan Visconti, Andrea Vitaletti, Marco Zecchini
CANS2
2025 Short Paper: Rewardable Naysayer Proofs
Gennaro Avitabile, Luisa Siniscalchi, Ivan Visconti
FC (2)3
2025 Trust Nobody: Privacy-Preserving Proofs for Edited Photos with Your Laptop
abstract
The Internet has plenty of images that are transformations (e.g., resize, blur) of confidential original images. Several scenarios (e.g., selling images over the Internet, fighting disinformation, detecting deep fakes) would highly benefit from systems allowing to verify that an image is the result of a transformation applied to a confidential authentic image. In this paper, we focus on systems for proving and verifying the correctness of transformations of authentic images guaranteeing: 1) confidentiality (i.e., the original image remains private), 2) efficient proof generation (i.e., the proof certifying the correctness of the transformation can be computed with a common laptop) even for high-resolution images, 3) authenticity (i.e., only the advertised transformations have been applied) and 4) fast detection of fraud proofs.. Our contribution consists of new definitions modelling confidentiality and adaptive adversaries, techniques to speed up the prover of a ZK-snark, an efficient construction relying on ad-hoc signatures and hashes, and a less efficient construction that works according to signatures and hashes included in the C2PA specifications. Experimental results confirm the viability of our approach, allowing to compute an authentic transformation of a high-resolution image on a common computer. Prior results instead either require expensive computing resources or provide unsatisfying confidentiality.
Pierpaolo Della Monica, Ivan Visconti, Andrea Vitaletti, Marco Zecchini
SP2
2025 Compact Proofs of Partial Knowledge for Overlapping CNF Formulae
Gennaro Avitabile, Vincenzo Botta, Daniele Friolo, Daniele Venturi 0001, Ivan Visconti
J. Cryptol.5
2024 The Right to Be Zero-Knowledge Forgotten
abstract
The main goal of the EU GDPR is to protect personal data of individuals within the EU. This is expressed in several rights and, among them, in this work we focus on the Right to Erasure, more commonly known as the Right to Be Forgotten (RtBF).
Ivan Visconti
ARES1
2024 Black-Box (and Fast) Non-malleable Zero Knowledge
Vincenzo Botta, Michele Ciampi, Emmanuela Orsini, Luisa Siniscalchi, Ivan Visconti
CRYPTO (9)5
2024 Incremental Time-Deniable Signatures
Luisa Siniscalchi, Ivan Visconti
ESORICS (4)2
2023 Doubly adaptive zero-knowledge proofs
Vincenzo Botta, Ivan Visconti
Theor. Comput. Sci.2
2022 Efficient NIZK Arguments with Straight-Line Simulation and Extraction
Michele Ciampi, Ivan Visconti
CANS2
2022 Efficient Proofs of Knowledge for Threshold Relations
Gennaro Avitabile, Vincenzo Botta, Daniele Friolo, Ivan Visconti
ESORICS (3)4
2022 Towards Data Redaction in Bitcoin
abstract
A major issue for many applications of blockchain technology is the tension between immutability and compliance to regulations. For instance, the GDPR in the EU requires to guarantee, under some circumstances, the right to be forgotten. This could imply that at some point one might be forced to delete some data from a locally stored blockchain, therefore irreparably hurting the security and transparency of such decentralized platforms. Motivated by such data protection and consistency issues, in this work we design and implement a mechanism for securely deleting data from Bitcoin blockchain. We use zero-knowledge proofs to allow any node to delete some data from Bitcoin transactions, still preserving the public verifiability of the correctness of the spent and spendable coins. Moreover, we specifically use STARK proofs to exploit the transparency that they provide. Our solution, unlike previous approaches, avoids the complications of asking nodes to reach consensus on the content to delete. In particular, our design allows every node to delete some specific data without coordinating this decision with others. In our implementation, data removal can be performed (resp., verified) in minutes (resp., seconds) on a standard laptop rather than in days as required in previous designs based on consensus.
Vincenzo Botta, Vincenzo Iovino, Ivan Visconti
IEEE Trans. Netw. Serv. Manag.3
2021 Terrorist Attacks for Fake Exposure Notifications in Contact Tracing Systems
Gennaro Avitabile, Daniele Friolo, Ivan Visconti
ACNS (1)3
2021 The Blockchain Quadrilemma: When Also Computational Effectiveness Matters
abstract
Ethereum's founder Buterin raised the challenge of solving the blockchain Trilemma towards a decentralized computer that could together achieve high degrees of security, scalability, and decentralization. Later on, Algorand claimed to have resolved Buterin's blockchain Trilemma and is nowadays increasingly adopted by designers of decentralized computations. Motivated by the need of selecting a blockchain to run some decentralized computations, we observe the limitations of using the Trilemma as benchmark, and we propose as alternative a Quadrilemma that takes into account also computational effectiveness, namely the capability of running non-trivial decentralized computations at affordable costs. For concreteness, motivated by the current trends of using blockchains for the management of non-fungible tokens (NFTs) related to highly desired items (i.e., NFTs for art), we consider the use case of decentralized auctions in various scenarios that mainly differ on the desired degree of confidentiality. Our contribution gives the following insights. Except very limited cases where also Bitcoin can be taken into account (i.e., when latency is not a big deal and only notarization is required), Algorand can often be the right choice as long as decentralized computations consist of basic operations only. Instead, Ethereum is advisable when more sophisticated computations are required, in particular when ad-hoc cryptographic tasks are essential, and one can afford the involved costs and latency. Focusing on those three blockchains, the state of affairs about resolving the blockchain Quadrilemma is somewhat unsatisfying. Even in natural cases where computations and storage requirements for a smart contract are low (e.g., public-key encryption), none of those decentralized computers achieves simultaneously low cost and fast transaction confirmations.
Francesco Mogavero, Ivan Visconti, Andrea Vitaletti, Marco Zecchini
ISCC2
2020 How to Extract Useful Randomness from Unreliable Sources
Divesh Aggarwal, Maciej Obremski, João Ribeiro 0002, Luisa Siniscalchi, Ivan Visconti
EUROCRYPT (1)5
2019 UC-Secure Multiparty Computation from One-Way Functions Using Stateless Tokens
Saikrishna Badrinarayanan, Abhishek Jain 0002, Rafail Ostrovsky, Ivan Visconti
ASIACRYPT (2)4
2019 Universally Composable Secure Computation with Corrupted Tokens
Nishanth Chandran, Wutichai Chongchitmate, Rafail Ostrovsky, Ivan Visconti
CRYPTO (3)4
2018 Non-interactive Secure Computation from One-Way Functions
Saikrishna Badrinarayanan, Abhishek Jain 0002, Rafail Ostrovsky, Ivan Visconti
ASIACRYPT (3)4
2018 Continuously Non-Malleable Codes in the Split-State Model from Minimal Assumptions
Rafail Ostrovsky, Giuseppe Persiano, Daniele Venturi 0001, Ivan Visconti
CRYPTO (3)4
2017 Delayed-Input Cryptographic Protocols
Ivan Visconti
CiE1
2017 Four-Round Concurrent Non-Malleable Commitments from One-Way Functions
Michele Ciampi, Rafail Ostrovsky, Luisa Siniscalchi, Ivan Visconti
CRYPTO (2)4
2017 Unconditional UC-Secure Computation with (Stronger-Malicious) PUFs
Saikrishna Badrinarayanan, Dakshita Khurana, Rafail Ostrovsky, Ivan Visconti
EUROCRYPT (1)4
2017 Resettably-Sound Resettable Zero Knowledge in Constant Rounds
Wutichai Chongchitmate, Rafail Ostrovsky, Ivan Visconti
TCC (2)3
2017 Round-Optimal Secure Two-Party Computation from Trapdoor Permutations
Michele Ciampi, Rafail Ostrovsky, Luisa Siniscalchi, Ivan Visconti
TCC (1)4
2017 Delayed-Input Non-Malleable Zero Knowledge and Multi-Party Coin Tossing in Four Rounds
Michele Ciampi, Rafail Ostrovsky, Luisa Siniscalchi, Ivan Visconti
TCC (1)4
2016 Concurrent Non-Malleable Commitments (and More) in 3 Rounds
Michele Ciampi, Rafail Ostrovsky, Luisa Siniscalchi, Ivan Visconti
CRYPTO (3)4
2016 Online/Offline OR Composition of Sigma Protocols
Michele Ciampi, Giuseppe Persiano, Alessandra Scafuro, Luisa Siniscalchi, Ivan Visconti
EUROCRYPT (2)5
2015 Impossibility of Black-Box Simulation Against Leakage Attacks
Rafail Ostrovsky, Giuseppe Persiano, Ivan Visconti
CRYPTO (2)3
2015 Executable Proofs, Input-Size Hiding Secure Computation and a New Ideal World
Melissa Chase, Rafail Ostrovsky, Ivan Visconti
EUROCRYPT (2)3
2014 On Input Indistinguishable Proof Systems
Rafail Ostrovsky, Giuseppe Persiano, Ivan Visconti
ICALP (1)3
2014 Black-box non-black-box zero knowledge
abstract
Motivated by theoretical and practical interest, the challenging task of designing cryptographic protocols having only black-box access to primitives has generated various breakthroughs in the last decade. Despite such positive results, even though nowadays we know black-box constructions for secure two-party and multi-party computation even in constant rounds, there still are in Cryptography several constructions that critically require non-black-box use of primitives in order to securely realize some fundamental tasks. As such, the study of the gap between black-box and nonblack-box constructions still includes major open questions.
Vipul Goyal, Rafail Ostrovsky, Alessandra Scafuro, Ivan Visconti
STOC4
2014 4-Round Resettably-Sound Zero Knowledge
Kai-Min Chung, Rafail Ostrovsky, Rafael Pass, Muthuramakrishnan Venkitasubramaniam, Ivan Visconti
TCC5
2014 Statistical Concurrent Non-malleable Zero Knowledge
Claudio Orlandi, Rafail Ostrovsky, Vanishree Rao, Amit Sahai, Ivan Visconti
TCC5
2014 The design and implementation of a secure CAPTCHA against man-in-the-middle attacks
abstract
ABSTRACT In this paper, we propose a novel security protocol for the implementation of CAPTCHA tests that feature advance mechanisms against man‐in‐the‐middle (MITM, for short) attacks. This type of attack is fulfilled by a malicious entity, the MITM, that leverages on unaware users to mass‐solve CAPTCHA tests shielding the access to a service. The protocol that we propose uses collision‐resistant hash functions modeled as random oracles to guarantee that the solution to a CAPTCHA test solved by an end user is valid only for the server to which the user is connected to. This will prevent MITM attacks because the user is not directly connected to the server. We developed a reference implementation for our protocol that has a low impact and is easy to use, featuring a software plug‐in running in the Firefox web browser, on the client side, and a Java servlet‐based application, on the server side. Copyright © 2013 John Wiley & Sons, Ltd.
Umberto Ferraro Petrillo, Giovanni Mastroianni, Ivan Visconti
Secur. Commun. Networks3
2013 Constant-Round Concurrent Zero Knowledge in the Bounded Player Model
Vipul Goyal, Abhishek Jain 0002, Rafail Ostrovsky, Silas Richelson, Ivan Visconti
ASIACRYPT (1)5
2013 Universally Composable Secure Computation with (Malicious) Physically Uncloneable Functions
Rafail Ostrovsky, Alessandra Scafuro, Ivan Visconti, Akshay Wadia
EUROCRYPT3
2013 Simultaneous Resettability from One-Way Functions
abstract
Resettable-security, introduced by Canetti, Goldreich, Goldwasser and Micali (STOC'00), considers the security of cryptographic two-party protocols (in particular zero-knowledge arguments) in a setting where the attacker may “reset” or “rewind” one of the players. The strongest notion of resettable security, simultaneous resettability, introduced by Barak, Goldreich, Goldwasser and Lindell (FOCS'01), requires resettable security to hold for both parties: in the context of zero-knowledge, both the soundness and the zero-knowledge conditions remain robust to resetting attacks. To date, all known constructions of protocols satisfying simultaneous resettable security rely on the existence of ZAPs; constructions of ZAPs are only known based on the existence of trapdoor permutations or number-theoretic assumptions. In this paper, we provide a new method for constructing protocols satisfying simultaneous resettable security while relying only on the minimal assumption of one-way functions. Our key results establish, assuming only one-way functions: Every language in NP has an ω(1)-round simultaneously resettable witness indistinguishable argument system; Every language in NP has a (polynomial-round) simultaneously resettable zero-knowledge argument system. The key conceptual insight in our technique is relying on black-box impossibility results for concurrent zero-knowledge to achieve resettable-security.
Kai-Min Chung, Rafail Ostrovsky, Rafael Pass, Ivan Visconti
FOCS4
2013 Concurrent Zero Knowledge in the Bounded Player Model
Vipul Goyal, Abhishek Jain 0002, Rafail Ostrovsky, Silas Richelson, Ivan Visconti
TCC5
2013 Revisiting Lower and Upper Bounds for Selective Decommitments
Rafail Ostrovsky, Vanishree Rao, Alessandra Scafuro, Ivan Visconti
TCC4
2013 SmartK: Smart cards in operating systems at kernel level
Luigi Catuogno, Roberto Gassirà, Michele Masullo, Ivan Visconti
Inf. Secur. Tech. Rep.4
2013 Special Issue: Advances in Security for Communication Networks
abstract
The success of the Internet and of communication networks in general, opened new intriguing challenges for protocol designers.Consider, for example, the classic notion of "secure computation" introduced and achieved in the seminal works of Yao and of Goldreich, Micali and Wigderson.While such a notion considers only the stand-alone setting, where parties are connected to each other but isolated from the rest of the world, security in communication networks is more demanding.Indeed, when parties are connected to a network (i.e., parties can run several instances of protocols concurrently), secure computation has been proved impossible to achieve.Therefore, achieving information security in communication networks required to solve various open problems.New security notions have been introduced in order to better model real-world scenarios.New hardness assumptions have been used in order to enable the construction of more powerful cryptographic primitives.New security protocols and proof techniques have been developed in order to defeat network attacks mounted by malicious adversaries.This special issue of the Journal of Computer Security includes six papers that cover various aspects of such recent challenges in information security in communication networks.The paper "5PM: Secure pattern matching" by Joshua Baron, Karim El Defrawy, Kirill Minkovich, Rafail Ostrovsky and Eric Tressler addresses a popular problem in information security: secure pattern matching.The authors focus on the specific case of single-character wildcards and substring matching.They show a protocol called 5PM that outperforms previous constructions.The paper "Short blind signatures" by Olivier Blazy, Georg Fuchsbauer, David Pointcheval and Damien Vergnaud introduces an improved form of blind signatures.Blind signatures are signatures of messages that remain hidden to the signer.They have various applications (e.g., e-cash).The construction given by the authors focuses on short signatures obtained with minimal interactions.The paper "Field switching in BGV-style homomorphic encryption" by Craig Gentry, Shai Halevi, Chris Peikert and Nigel P. Smart proposes a general fieldswitching transformation that can be used to outperform previous transformations needed in homomorphic encryption schemes.Such schemes are a powerful tool in client-server applications and certainly represent one of the main novelties in Cryptography.
Ivan Visconti
J. Comput. Secur.1
2012 Secure Database Commitments and Universal Arguments of Quasi Knowledge
Melissa Chase, Ivan Visconti
CRYPTO2
2012 Impossibility Results for Static Input Secure Computation
Sanjam Garg, Abishek Kumarasubramanian, Rafail Ostrovsky, Ivan Visconti
CRYPTO4
2012 On Round-Optimal Zero Knowledge in the Bare Public-Key Model
Alessandra Scafuro, Ivan Visconti
EUROCRYPT2
2012 Constructing Non-malleable Commitments: A Black-Box Approach
abstract
We propose the first black-box construction of non-malleable commitments according to the standard notion of non-malleability with respect to commitment. Our construction additionally only requires a constant number of rounds and is based only on (black-box use of) one-way functions. Prior to our work, no black-box construction of non-malleable commitments was known (except for relaxed notions of security) in any (polynomial) number of rounds based on any cryptographic assumption. This closes the wide gap existent between black-box and non-black-box constructions for the problem of non-malleable commitments. Our construction relies on (and can be seen as a generalization of) the recent non-malleable commitment scheme of Goyal (STOC 2011). We also show how to get black-box constructions for a host of other cryptographic primitives. We extend our construction to get constant-round concurrent non-malleable commitments, constant-round multi-party coin tossing, and non-malleable statistically hiding commitments (satisfying the notion of non-malleability with respect to opening). All of the mentioned results make only a black-box use of one-way functions. Our primary technical contribution is a novel way of implementing the proof of consistency typically required in the constructions of non-malleable commitments (and other related primitives). We do this by relying on ideas from the ``zero-knowledge from secure multi-party computation" paradigm of Ishai, Kushilevitz, Ostrovsky, and Sahai (STOC 2007). We extend in a novel way this ``computation in the head" paradigm (which can be though of as bringing powerful error-correcting codes into purely computational setting). To construct a non-malleable commitment scheme, we apply our computation in the head techniques to the recent (constant-round) construction of Goyal. Along the way, we also present a simplification of the construction of Goyal where a part of the protocol is implemented in an information theoretic manner. Such a simplification is crucial for getting a black-box construction. This is done by making use of pair wise-independent hash functions and strong randomness extractors. We show that our techniques have multiple applications, as elaborated in the paper. Hence, we believe our techniques might be useful in other settings in future.
Vipul Goyal, Chen-Kuei Lee, Rafail Ostrovsky, Ivan Visconti
FOCS4
2012 Nearly Simultaneously Resettable Black-Box Zero Knowledge
Joshua Baron, Rafail Ostrovsky, Ivan Visconti
ICALP (1)3
2012 Simultaneously Resettable Arguments of Knowledge
Chongwon Cho, Rafail Ostrovsky, Alessandra Scafuro, Ivan Visconti
TCC4
2012 Resettable Statistical Zero Knowledge
Sanjam Garg, Rafail Ostrovsky, Ivan Visconti, Akshay Wadia
TCC3
2011 Secure Set Intersection with Untrusted Hardware Tokens
Marc Fischlin, Benny Pinkas, Ahmad-Reza Sadeghi, Thomas Schneider 0003, Ivan Visconti
CT-RSA5
2011 On constant-round concurrent non-malleable proof systems
Zhenfu Cao, Ivan Visconti, Zongyang Zhang
Inf. Process. Lett.2
2010 On RFID Privacy with Mutual Authentication and Tag Corruption
Frederik Armknecht, Ahmad-Reza Sadeghi, Ivan Visconti, Christian Wachsmann
ACNS3
2010 Efficiency Preserving Transformations for Concurrent Non-malleable Zero Knowledge
Rafail Ostrovsky, Omkant Pandey, Ivan Visconti
TCC3
2010 Proxy Smart Card Systems
Giuseppe Cattaneo, Pompeo Faruolo, Vincenzo Palazzo, Ivan Visconti
WISTP4
2009 Anonymizer-Enabled Security and Privacy for RFID
Ahmad-Reza Sadeghi, Ivan Visconti, Christian Wachsmann
CANS2
2009 Collusion-Free Multiparty Computation in the Mediated Model
Joël Alwen, Jonathan Katz, Yehuda Lindell, Giuseppe Persiano, Abhi Shelat, Ivan Visconti
CRYPTO6
2009 Simulation-Based Concurrent Non-malleable Commitments and Decommitments
Rafail Ostrovsky, Giuseppe Persiano, Ivan Visconti
TCC3
2008 Collusion-Free Protocols in the Mediated Model
Joël Alwen, Abhi Shelat, Ivan Visconti
CRYPTO3
2008 Improved Security Notions and Protocols for Non-transferable Identification
Carlo Blundo, Giuseppe Persiano, Ahmad-Reza Sadeghi, Ivan Visconti
ESORICS4
2008 Constant-Round Concurrent Non-malleable Zero Knowledge in the Bare Public-Key Model
Rafail Ostrovsky, Giuseppe Persiano, Ivan Visconti
ICALP (2)3
2007 Hybrid commitments and their applications to zero-knowledge proof systems
Dario Catalano, Ivan Visconti
Theor. Comput. Sci.2
2006 Efficient Zero Knowledge on the Internet
Ivan Visconti
ICALP (2)1
2006 On Non-Interactive Zero-Knowledge Proofs of Knowledge in the Shared Random String Model
Giuseppe Persiano, Ivan Visconti
MFCS2
2006 Mercurial Commitments: Minimal Assumptions and Efficient Constructions
Dario Catalano, Yevgeniy Dodis, Ivan Visconti
TCC3
2005 Impossibility and Feasibility Results for Zero Knowledge with Public Keys
Joël Alwen, Giuseppe Persiano, Ivan Visconti
CRYPTO3
2005 Hybrid Trapdoor Commitments and Their Applications
Dario Catalano, Ivan Visconti
ICALP2
2005 Concurrent Zero Knowledge in the Public-Key Model
Giovanni Di Crescenzo, Ivan Visconti
ICALP2
2005 Single-Prover Concurrent Zero Knowledge in Almost Constant Rounds
Giuseppe Persiano, Ivan Visconti
ICALP2
2005 Securing Operating System Services Based on Smart Cards
Luigi Catuogno, Roberto Gassirà, Michele Masullo, Ivan Visconti
TrustBus4
2004 Improved Setup Assumptions for 3-Round Resettable Zero Knowledge
Giovanni Di Crescenzo, Giuseppe Persiano, Ivan Visconti
ASIACRYPT3
2004 Constant-Round Resettable Zero Knowledge with Concurrent Soundness in the Bare Public-Key Model
Giovanni Di Crescenzo, Giuseppe Persiano, Ivan Visconti
CRYPTO3
2004 An Architecture for Kernel-Level Verification of Executables at Run Time
abstract
Digital signatures have been proposed by several researchers as a way of preventing execution of malicious code. In this paper, we propose a general architecture for performing the signature verification as part of the kernel execution process. The proposed architecture does not require any change in the interpreters used to execute code and it can accommodate any executable format. We also report on our implementation for the Linux operating system that focuses on ELF and script executables. Experimental results show that our solution is of potential interest as virtually no slowdown is experienced in the execution.
Luigi Catuogno, Ivan Visconti
Comput. J.2
2003 An Anonymous Credential System and a Privacy-Aware PKI
Giuseppe Persiano, Ivan Visconti
ACISP2
2003 A secure and private system for subscription-based remote services
abstract
In this paper we study privacy issues regarding the use of the SSL/TLS protocol and X.509 certificates. Our main attention is placed on subscription-based remote services (e.g., subscription to newspapers and databases) where the service manager charges a flat fee for a period of time independent of the actual number of times the service is requested.We start by pointing out that restricting the access to such services by using X.509 certificates and the SSL/TLS protocol, while preserving the interests of the service managers, neglects the right to privacy of the users.We then propose the concept of a crypto certificate and the Secure and Private Socket Layer protocol (SPSL protocol, in short) and show how they can be used to preserve user privacy and, at the same time, protecting the interests of the service managers. The SPSL protocol only requires the user to have a standard X.509 certificate (with an RSA key) and does not require the user to get any special ad hoc certificate.Finally, we show the viability of the proposed solution by describing a system based on SPSL for secure and private access to subscription-based web services. Our implementation includes an SPSL proxy for a TLS-enabled web client and a module for the Apache web server along with administrative tools for the server side. The system has been developed starting from the implementation of an API for the SPSL protocol that we describe in the paper.
Giuseppe Persiano, Ivan Visconti
ACM Trans. Inf. Syst. Secur.2
2000 User privacy issues regarding certificates and the TLS protocol: the design and implementation of the SPSL protocol
abstract
The aim of this paper is two-fold.1) We raise concerns regarding possible violations of user privacy relative to the use of X509 Certi cates and the Transport Layer Security protocol.We stress that this approach to secure network transactions, while preserving the interests of service providers, neglects to consider the right to privacy of the users.2) We propose the concept of a crypto certi cate and the Secure and Private Socket Layer protocol (SPSL protocol, in short) and show their eectiveness in preserving user privacy and, at the same time, protecting the interests of service providers.Focusing on the particular case of web transactions, we describe a system based on SPSL for secure and private web navigation.Our implementation includes an SPSL-proxy for an SSL-enabled web client and a module for the Apache web server along with administrative tools for the server side.The system has been developed starting from the implementation of an API for the SPSL protocol that we d escribe in the paper.Experimental results show t h a t S P S L i s an eective and ecient solution to the problem of privacy in web transaction.The protocol we propose and, consequently, the implementation we describe are fully dynamic and provide an adjustable level of privacy.Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page.
Giuseppe Persiano, Ivan Visconti
CCS2