VLDB 2026 Research / reviewers in the wild / expert
Albert Levi
dblp:82/2842
· DBLP profile ↗
45ranked-venue papers
10as first author
6since 2021 · last 2025
0000-0002-9714-3897ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 22 · 4 first-author · 1 since 2021Security and privacy · 12 · 5 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3Databases, data management, data science and information retrieval · 2Artificial intelligence and machine learning · 1Systems, architecture and hardware · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Zero-Knowledge-Proof for Moral Hazard Detection in O-RAN without Benchmarks: Let us Play WereWolf Game!abstractThe Open Radio Access Network (O-RAN) paradigm fosters multi-vendor interoperability, allowing modules from different vendors to cooperatively handle network functions, such as temporary data processing or sensor data collection for network operations optimization. However, this integration agility introduces the risk of selecting suboptimal or adversarial modules, leading to moral hazard. Traditional Moral Hazard testing approaches typically rely on a benchmarking data set in addition to historical performance score. However, they deemed impractical, as vendor-supplied modules may not reveal their outputs before deployment, and the network may lack direct access to reference results for validation. This challenge is further compounded by the dynamic nature of network elements and AI-driven models, whose performance can degrade over time due to malicious tampering, obsolescence, or device deterioration, making historical quality assessments ineffective. In this paper, we address the challenge of identifying legitimate vendor-supplied modules among adversarial ones, with respect to a given network functionality/operation, in the absence of benchmarks. We propose a benchmark-free test framework that detects and eliminates adversarial modules using a methodology inspired by the WereWolf game, combined with zero-knowledge proof techniques. Monte Carlo simulations demonstrate that our approach effectively removes adversarial entities while preserving the privacy of legitimate modules. Damla Sariçelik, Mohaned Chraiti, Albert Levi, Özgür Erçetin |
PIMRC | 3 |
| 2024 | Dissecting Privacy Perspectives of Websites Around the World: "Aceptar Todo, Alle Akzeptieren, Accept All..."
Aysun Ogut, Berke Turanlioglu, Doruk Can Metiner, Albert Levi, Cemal Yilmaz 0001, Orçun Çetin, A. Selcuk Uluagac |
USENIX Security Symposium | 4 |
| 2024 | Blacklisting Based Anonymous Authentication Scheme for Sharing EconomyabstractAuthentication and blacklisting mechanisms have a key role for service providers to deliver the service to correct users through digital channels. Nevertheless, there always have been concerns about privacy of the users against such mechanisms. Theconditional anonymityconcept is proposed as a remedy to these concerns. A recent approach in the literature for conditional anonymity isblacklistable anonymous credentials, which allows service providers to blacklist users for an authentication session without identifying the user. In this paper, we improve user anonymity in conditionally anonymous schemes using two complementary mechanisms. First, we definewhitelisting propertyfor blacklistable anonymous credentials and give a construction of this scheme. The whitelisting property can be used to unlink an honestly behaved authentication session from the user. Second, we propose an extension of this scheme for a particular use case,sharing economy services. This scheme allows a service provider to blacklist a user only if the user have not returned the shared asset in due time. We benchmark the performance of our schemes by comparing them with the rival schemes. Our experiments show that both of our scheme have comparable performance to previous works. Cavit Özbay, Albert Levi |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2023 | Data driven intrusion detection for 6LoWPAN based IoT systemsabstractWide adoption of Internet of Things (IoT) devices and their limitations in terms of hardware cause them to be easy targets for attackers. This, in turn, requires monitoring such systems using intrusion detection systems and take mitigative actions against insider and outsider attackers. Recent studies have explored that machine learning based intrusion detection systems are quite successful in detecting different types of cyber threats targeting IoT systems. However, the proposed systems in these studies incurred limitations in terms of the characteristics of their datasets and detection models. Specifically, a big proportion of the proposed models were developed using simulation-based data generated through specific simulators. Some of these studies also used previously published testbed data that contain the samples of outdated IoT attacks and vulnerabilities. Furthermore, they focused on a lower attack variety and proposed binary classifiers which do not scale in multi-attack scenarios. In this study, we propose a machine learning based multi-class classifier that can classify 6 attack types together with the benign traffic. Our node based feature extraction and detection methodology allows locating the network addresses of the attackers, rather than a rough network level attack existence information, by modeling their traffic characteristics over a sliding time window. For training and testing our models, we also propose an intrusion detection dataset generated using the traffic data collected from real IoT devices running with 6LoWPAN and RPL protocols. Besides having RPL routing attacks in the dataset, we leverage Mirai botnet , employed frequently to target IoT devices. The results show that the proposed intrusion detection system can detect 6 attack types with high recall scores ranging from 79% to 100%. We also illustrate the practicality of the developed model via deployment in a proof of concept implementation over a testbed. Faik Kerem Örs, Albert Levi |
Ad Hoc Networks | 2 |
| 2022 | Highly Efficient and Re-Executable Private Function Evaluation With Linear ComplexityabstractPrivate function evaluation aims to securely compute a function$f(x_1, \ldots, x_n)$without leaking any information other than what is revealed by the output, where$f$is a private input of one of the parties (say$\mathsf {Party}_1$) and$x_i$is a private input of the$i$th party$\mathsf {Party}_i$. In this article, we propose a novel and securetwo-party private function evaluation(2PFE) scheme based on the DDH assumption. Our scheme introduces a reusability feature that significantly improves the state-of-the-art. Accordingly, our scheme has two variants, one is utilized in the initial execution of the function$f$, and the other is utilized in its subsequent evaluations. To the best of our knowledge, this is the first and most efficient 2PFE scheme that enjoys a reusablity feature. Our protocols achieve linear communication and computation complexities and a constant number of rounds which is at most three. Osman Biçer, Muhammed Ali Bingöl, Mehmet Sabir Kiraz, Albert Levi |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2021 | Secure Matrix Operations for Machine Learning Classifications Over Encrypted Data in Post Quantum Industrial IoTabstractWe tackle the problem where a server owns a trained Machine Learning (ML) model and a client/user has an unclassified query that he wishes to classify in secure and private fashion using the server’s model. During the process the server learns nothing, while the user learns only his final classification and nothing else. Since several ML classification algorithms, such as deep neural networks, support vector machines-SVM (and hyperplane decisions in general), Logistic Regression, Naïve Bayes, etc., can be expressed in terms of matrix operations, initially we propose novel secure matrix operations as our building blocks. On top of them we build our secure and private ML classification algorithms under strict security and privacy requirements. As our underlying cryptographic primitives are shown to be resilient to quantum computer attacks, our algorithms are also suitable for the post-quantum world. Our theoretical analysis and extensive experimental evaluations show that our secure matrix operations, hence our secure ML algorithms build on top of them as well, outperform the state of the art schemes in terms of computation and communication costs. This makes our algorithms suitable for devices with limited resources that are often found in Industrial IoT (Internet of Things) Artrim Kjamilji, Albert Levi, Erkay Savas, Osman B. Güney |
ISNCC | 2 |
| 2020 | Secure and Privacy-Aware Gateway for Home Automation SystemsabstractIn recent years, the Internet of Things has been widely used for academic and industrial purposes. One of the applications in the field of IoT is Home Automation Systems (HAS). Home automation systems are devices that allow homeowners to monitor and control their home from remote locations. However, smart home systems raise security and privacy concerns. In this paper, we propose a privacy-aware secure identification and authentication model. In our scheme, a middleware-layer design is adapted to build a secure and efficient intercommunication platform and provide a high protection for the users. In order to provide mutual authentication, we proposed a double verification protocol. Meanwhile, for privacy reasons, we introduce a communication model by generating fake proofs in order to hide the identity of the IoT devices. The experiments are conducted for different communication scenarios. The outcomes of experiments are promising that the proposed model can readily be implemented for home automation systems. Sinem Gur, Simge Demir, Sevval Simsek, Albert Levi |
SIN | 4 |
| 2019 | SKA-CaNPT: Secure Key Agreement using Cancelable and Noninvertible Biometrics based on Periodic TransformationabstractNowadays, many of the security-providing applications use biometrics-based authentication. However, since each person's biometrics is unique and non-replaceable, once it is compromised, it will be compromised forever. Therefore, it is hard for the users to trust biometrics. To overcome this problem, in this paper, we propose a novel secure key agreement protocol SKA-CaNPT. Here, we use a periodic transformation function to make biometrics cancelable and noninvertible. At the very end of our SKA-CaNPT protocol, the user and the server make an agreement on a symmetric shared key that is based on the feature points of the user's biometrics. Therefore, if the transformed data is compromised, then just by changing one of the inputs of the transformation function, we can renew the cryptographic key. As a proof of concept, we apply our SKA-CaNPT protocol on fingerprints. Besides, we apply different security analyses on our protocol. We use Shannon's entropy and Hamming distance metrics to analyze the randomness and the distinctiveness of the agreed keys. Moreover, according to the low IKGR (Incorrect Key Generation Rate), high CKGR (Correct Key Generation Rate) and high attack complexity possessed by our SKA-CaNPT protocol, we can conclude that our scheme is secure against brute-force, replay and impersonation attacks. Laleh Eskandarian, Dilara Akdogan, Duygu Karaoglan, Albert Levi |
CODASPY | 4 |
| 2019 | SKA-PS: Secure key agreement protocol using physiological signals
Duygu Karaoglan, Beste Seymen, Albert Levi |
Ad Hoc Networks | 3 |
| 2019 | An Efficient 2-Party Private Function Evaluation Protocol Based on Half GatesabstractPrivate function evaluation (PFE) is a special case of secure multi-party computation (MPC), where the function to be computed is known by only one party. PFE is useful in several real-life applications where an algorithm or a function itself needs to remain secret for reasons such as protecting intellectual property or security classification level. In this paper, we focus on improving 2-party PFE based on symmetric cryptographic primitives. In this respect, we look back at the seminal PFE framework presented by Mohassel and Sadeghian at Eurocrypt’13. We show how to adapt and utilize the well-known half gates garbling technique (Zahur et al., Eurocrypt’15) to their constant-round 2-party PFE scheme. Compared to their scheme, our resulting optimization significantly improves the efficiency of both the underlying Oblivious Evaluation of Extended Permutation (OEP) and secure 2-party computation (2PC) protocols, and yields a more than 40% reduction in overall communication cost (the computation time is also slightly decreased and the number of rounds remains unchanged). Muhammed Ali Bingöl, Osman Biçer, Mehmet Sabir Kiraz, Albert Levi |
Comput. J. | 4 |
| 2019 | Secure key agreement based on ordered biometric features
Dilara Akdogan, Duygu Karaoglan, Albert Levi |
Comput. Networks | 3 |
| 2019 | Two-tier anomaly detection based on traffic profiling of the home automation system
Mariusz Gajewski, Jordi Mongay Batalla, Albert Levi, Cengiz Togay, Constandinos X. Mavromoustakis, George Mastorakis |
Comput. Networks | 3 |
| 2018 | Secure key agreement protocols: Pure biometrics and cancelable biometrics
Dilara Akdogan, Duygu Karaoglan, Laleh Eskandarian, Albert Levi |
Comput. Networks | 4 |
| 2017 | Feature-level fusion of physiological parameters to be used as cryptographic keysabstractIn this paper, we propose two novel feature-level fused physiological parameter generation techniques: (i) concat-fused physiological parameter generation, and (ii) xor-fused physiological parameter generation, output of which can be used to secure the communication among the biosensors in Body Area Network (BAN). In these physiological parameter generation techniques, we combine a time-domain physiological parameter with a frequency-domain physiological parameter, in order to achieve robust performance compared to their singular versions. We analyze both the performance and the quality of the outcomes. Our results show that we generate good candidates of physiological parameters that can be used as cryptographic keys to provide security for the intra-network communication in BANs. Duygu Karaoglan, Albert Levi, Volkan Tuzcu |
ICC | 2 |
| 2017 | DKEM: Secure and efficient Distributed Key Establishment Protocol for Wireless Mesh Networks
Duygu Karaoglan, Muhammed Ali Bingöl, Albert Levi, Erkay Savas |
Ad Hoc Networks | 3 |
| 2017 | Utilizing hash graphs for key distribution for mobile and replaceable interconnected sensors in the IoT context
Albert Levi, Salim Sarimurat |
Ad Hoc Networks | 1 |
| 2017 | Deriving cryptographic keys from physiological signals
Duygu Karaoglan, Albert Levi, Volkan Tuzcu |
Pervasive Mob. Comput. | 2 |
| 2015 | k-strong privacy for radio frequency identification authentication protocols based on physically unclonable functionsabstractAbstract This paper examines Vaudenay's privacy model, which is one of the first and most complete privacy models that featured the notion of different privacy classes. We enhance this model by introducing two new generic adversary classes,k‐strong andk‐forward adversaries where the adversary is allowed to corrupt a tag at mostktimes. Moreover, we introduce an extended privacy definition that also covers all privacy classes of Vaudenay's model. In order to achieve highest privacy level, we study low cost primitives such as physically unclonable functions (PUFs). The common assumption of PUFs is that their physical structure is destroyed once tampered. This is an ideal assumption because the tamper resistance depends on the ability of the attacker and the quality of the PUF circuits. In this paper, we have weakened this assumption by introducing a new definitionk‐resistant PUFs.k‐PUFs are tamper resistant against at mostkattacks; that is, their physical structure remains still functional and correct until at mostkthphysical attack. Furthermore, we prove that strong privacy can be achieved without public‐key cryptography usingkPUF‐based authentication. We finally prove that our extended proposal achieves both reader authentication andk‐strong privacy. Copyright © 2014 John Wiley & Sons, Ltd. Süleyman Kardas, Serkan Çelik, Muhammed Ali Bingöl, Mehmet Sabir Kiraz, Hüseyin Demirci, Albert Levi |
Wirel. Commun. Mob. Comput. | 6 |
| 2014 | A special issue of ad hoc networks on "Smart solutions for mobility supported distributed and embedded systems"
Albert Levi, Özgür Gürbüz, Antonio Maña, Marek Klonowski, Matteo Cesana, Mona Ghassemian, Susana Sargento |
Ad Hoc Networks | 1 |
| 2014 | A Survey on the Development of Security Mechanisms for Body Area NetworksabstractAdvances in lightweight, small-sized and low-power sensors led to the development of wearable biosensors, and thus, to the accurate monitoring of human periphery. On top of this, pervasive computing has been improved and technologies have been matured enough to build plug-and-play body area networks (BANs). In a BAN, the main functionality of a node is to effectively and efficiently collect data from vital body parts, share it with the neighbors and make decisions accordingly. Because of the fact that the captured phenomenon is highly sensitive to privacy breaches in addition to being transmitted using the wireless communication medium, BANs require a security infrastructure. However, due to the extreme energy scarcity, bandwidth and storage constraints of the nodes, conventional solutions are inapplicable. In this survey, we present an overview of BANs and provide a detailed investigation into the developed security infrastructures. We examined the literature and combined the corresponding proposals under two major classes: (i) pure-cryptographic security mechanisms and (ii) bio-cryptographic security mechanisms. Pure-cryptographic methods include constructions based on the well-known symmetric or asymmetric cryptography primitives and they are suitable for securing the communication between any two network entities. On the other hand, bio-cryptographic methods benefit from the network's context-awareness and to the best of our knowledge, they have been utilized only for the communication among the biosensors. Duygu Karaoglan, Albert Levi |
Comput. J. | 2 |
| 2014 | Key distribution scheme for peer-to-peer communication in mobile underwater wireless sensor networks
Kübra Kalkan, Albert Levi |
Peer-to-Peer Netw. Appl. | 2 |
| 2013 | A New Security and Privacy Framework for RFID in Cloud ComputingabstractRFID is a leading technology that has been rapidly deployed in several daily life applications that require strong security and privacy mechanisms. However, RFID systems commonly have limited computational capacity and inefficient data management. There is a demanding urge to address these issues in the light of some mechanism which can make the technology excel. Cloud computing is one of the fastest growing segments of IT industry that provides cost effective solutions for handling and using data collected with RFID. As more and more information on companies and individuals is placed in the cloud, concerns are beginning to escalate about just how safe an environment it is. Therefore, while integrating RFID into the cloud, the security and privacy of the tag owner must be considered. Motivated by this, we first provide a new security and privacy model for RFID technology integrated to the cloud computing. In this model, we define the capabilities of the adversary and give the formal definitions. After that we propose a cloud-based RFID authentication protocol to illustrate our model. The protocol utilizes symmetric-key based cryptography. We prove that the protocol achieves destructive privacy according to our model. Süleyman Kardas, Serkan Çelik, Muhammed Ali Bingöl, Albert Levi |
CloudCom (1) | 4 |
| 2013 | HaG: Hash graph based key predistribution scheme for multiphase wireless sensor networksabstractWireless Sensor Networks (WSN) consist of small sensor nodes which operate until their energy reserve is depleted. These nodes are generally deployed to the environments where network lifespan is much longer than the lifetime of a node. Therefore, WSN are typically operated in a multiphase fashion, as in [1-3, 9-10], which use different key pools for nodes deployed at different generations. In multiphase WSN, new nodes are periodically deployed to the environment to ensure constant local and global network connectivity. Also, key ring of these newly deployed nodes is selected from their deployment generation key pool to improve the resiliency of WSN. In this paper, we propose a key predistribution scheme for multiphase WSN which is resilient against permanent and temporary node capture attacks. In our Hash Graph based (HaG) scheme, every generation has its own key pool which is generated using the key pool of the previous generation. This allows nodes deployed at different generations to have the ability to establish secure channels. Likewise, a captured node can only be used to obtain keys for a limited amount of successive generations. We compare the connectivity and resiliency performance of our scheme with other multiphase key predistribution schemes and show that our scheme performs better when the attack rate is low. When the attack rate is high, our scheme still has better resiliency performance inasmuch as using less key ring size compared to the existing multiphase schemes. Salim Sarimurat, Albert Levi |
ICC | 2 |
| 2012 | PUF-enhanced offline RFID security and privacy
Süleyman Kardas, Serkan Çelik, Muhammet Yildiz, Albert Levi |
J. Netw. Comput. Appl. | 4 |
| 2011 | Increasing Resiliency in Multi-phase Wireless Sensor Networks: Generationwise Key Predistribution ApproachabstractIn wireless sensor networks (WSNs), sensor nodes eventually die due to battery depletion. WSNs in which new nodes are periodically redeployed with certain intervals, called generations, to replace the dead nodes are called multi-phase WSNs. In the literature, there are several key predistribution schemes proposed for secure operation of WSNs. However, these schemes are designed for single-phase networks which are not resilient against continuous node capture attacks; even under temporary attacks on the network, the harm caused by the attacker does not heal in time. However, the periodic deployments in multi-phase sensor networks could be utilized to improve the resiliency of the WSNs by deploying nodes with fresh keys. In the literature, there is limited work done in this area. In this paper, we propose a key predistribution scheme for multi-phase WSNs which is resilient under node capture attacks. In our scheme, called random generation material (RGM) key predistribution scheme, each generation of deployment has its own random keying material and pairwise keys are established between node pairs of particular generations. These keys are specific to these generations. Therefore, a captured node cannot be abused to obtain keys of other generations. We compare the performance of our RGM scheme with a well-known multi-phase key predistribution scheme and show that RGM achieves up to 3-fold more resiliency. Even under heavy attacks, our scheme's resiliency performance is 35 % better in steady state. Murat Ergun, Albert Levi, Erkay Savas |
Comput. J. | 2 |
| 2010 | A game theoretic model for digital identity and trust in online communitiesabstractDigital identity and trust management mechanisms play an important role on the Internet. They help users make decisions on trustworthiness of digital identities in online communities or e-commerce environments, which have significant security consequences. This work aims to contribute to construction of an analytical foundation for digital identity and trust by adopting a quantitative approach. A game theoretic model is developed to quantify community effects and other factors in trust decisions. The model captures factors such as peer pressure and personality traits. The existence and uniqueness of a Nash equilibrium solution is studied and shown for the trust game defined. In addition, synchronous and asynchronous update algorithms are shown to converge to the Nash equilibrium solution. A numerical analysis is provided for a number of scenarios that illustrate the interplay between user behavior and community effects. Tansu Alpcan, Cengiz Örencik, Albert Levi, Erkay Savas |
AsiaCCS | 3 |
| 2010 | Using combined keying materials for key distribution in wireless sensor networksabstractIn this paper, we propose a probabilistic key predistribution scheme for wireless sensor networks that increases connectivity of the basic scheme while keeping sizes of keyring and key pool fixed. We introduce the concept of XORed key, which is the bitwise XOR of two regular (a.k.a. single) keys. Sensor nodes are preloaded with a mixture of single and XORed keys. Nodes establish secure links by using shared XORed keys whenever possible. If node pairs do not have any shared XORed or single keys, they transfer keys from their secure neighbors in a couple of ways, and use them to match with their XORed keys. In this way, the probability of securing links, i.e. local connectivity, increases. The decision of which key is to be transferred from which node is given based on local information at the hand of the nodes. We aim to control the resilience of the network against node capture attacks by using XORed keys since an attacker has to know either both single key operands or the XORed key itself. Simulations show that our scheme is up to 50% more connected as compared to basic scheme. Also it has better resilience performance at the beginning of a node capture attack. When it starts to deteriorate, the difference between the resilience of our proposed scheme and basic scheme is not greater than 5%. Murat Ergun, Albert Levi |
PIMRC | 2 |
| 2010 | Two-Tier, Scalable and Highly Resilient Key Predistribution Scheme for Location-Aware Wireless Sensor Network Deployments
Abdülhakim Ünlü, Albert Levi |
Mob. Networks Appl. | 2 |
| 2009 | Dynamic Resiliency Analysis of Key Predistribution in Wireless Sensor NetworksabstractWireless sensor networks have been analyzed for more than a decade from operational and security points of view. Several key predistribution schemes have been proposed in the literature. Although valuable and state-of-the-art proposals have been made, their corresponding security analyses have not been performed by considering the dynamic nature of networking behavior and the time dimension. The sole metric used for resiliency analysis of key predistribution schemes is "fraction of links compromised" which is roughly defined as the ratio of secure communication links that the adversary can compromise over all secure links. However, this metric does not consider the dynamic nature of the network; it just analyzes a snapshot of the network without considering the time dimension. For example, possible dead nodes may cause change of routes and some captured links become useless for the attacker as time goes by. Moreover, an attacker cannot perform sensor node capturing at once, but performs over time. That is why a methodology for dynamic security analysis is needed in order to analyze the change of resiliency in time a more realistic way. In this paper, we propose such a dynamic approach to measure the resiliency of key predistribution schemes in sensor networks. We take the time dimension into account with a new performance metric, "captured message fraction". This metric is defined as the percentage of the messages generated within the network to be forwarded to the base station (sink) that are captured and read by the attacker. Our results show that for the cases where the static fraction of links compromised metric indicates approximately 40% of the links are compromised, our proposed captured message fraction metric shows 80% of the messages are captured by the attacker. This clearly proves the limitations of the static resiliency analysis in the literature. Ahmet Onur Durahim, Albert Levi |
ICC | 2 |
| 2009 | Public key cryptography based privacy preserving multi-context RFID infrastructure
Selim Volkan Kaya, Erkay Savas, Albert Levi, Özgür Erçetin |
Ad Hoc Networks | 3 |
| 2009 | Understanding the limitations of S/MIME digital signatures for e-mails: A GUI based approach
Albert Levi, Can Berk Güder |
Comput. Secur. | 1 |
| 2008 | Multiphase Deployment Models for Fast Self Healing in Wireless Sensor Networks
Omer Zekvan Yilmaz, Albert Levi, Erkay Savas |
SECRYPT | 2 |
| 2008 | Disclosure Risks of Distance Preserving Data Transformations
E. Onur Turgay, Thomas Brochmann Pedersen, Yücel Saygin, Erkay Savas, Albert Levi |
SSDBM | 5 |
| 2007 | Privacy-Aware Multi-Context RFID Infrastructure Using Public Key Cryptography
Selim Volkan Kaya, Erkay Savas, Albert Levi, Özgür Erçetin |
Networking | 3 |
| 2007 | Key Predistribution Schemes for Sensor Networks for Continuous Deployment Scenario
Abdülhakim Ünlü, Önsel Armagan, Albert Levi, Erkay Savas, Özgür Erçetin |
Networking | 3 |
| 2007 | Privacy preserving clustering on horizontally partitioned data
Ali Inan, Selim Volkan Kaya, Yücel Saygin, Erkay Savas, Ayça Azgin Hintoglu, Albert Levi |
Data Knowl. Eng. | 6 |
| 2006 | Quarantine Region Scheme to Mitigate Spam Attacks in Wireless Sensor NetworksabstractThe quarantine region scheme (QRS) is introduced to defend against spam attacks in wireless sensor networks where malicious antinodes frequently generate dummy spam messages to be relayed toward the sink. The aim of the attacker is the exhaustion of the sensor node batteries and the extra delay caused by processing the spam messages. Network-wide message authentication may solve this problem with a cost of cryptographic operations to be performed over all messages. QRS is designed to reduce this cost by applying authentication only whenever and wherever necessary. In QRS, the nodes that detect a nearby spam attack assume themselves to be in a quarantine region. This detection is performed by intermittent authentication checks. Once quarantined, a node continuously applies authentication measures until the spam attack ceases. In the QRS scheme, there is a trade-off between the resilience against spam attacks and the number of authentications. Our experiments show that, in the worst-case scenario that we considered, a not quarantined node catches 80 percent of the spam messages by authenticating only 50 percent of all messages that it processes Vedat Coskun, Erdal Cayirci, Albert Levi, Serdar Sancak |
IEEE Trans. Mob. Comput. | 3 |
| 2004 | Sensor wars: detecting and defending against spam attacks in wireless sensor networksabstractAnti-nodes deployed inside a wireless sensor network can frequently generate dummy data packets that make the nodes relaying them deplete their energy. Especially the nodes closer to the sink fail sooner, because they convey more data packets. This causes the sink to be disconnected from the sensor network. The counter-measures for this type of attacks, namely spam attacks, should consider that the sensor nodes have limited energy, computational power and memory. In this paper, we propose detect and defend against spams (DADS) scheme. In DADS the vicinity of the detected malicious node is notified about the quarantine region, and nodes do not relay unauthenticated messages coming from a node in the quarantine region. Our experiments show that our scheme fits the requirements of the sensor network. Serdar Sancak, Erdal Cayirci, Vedat Coskun, Albert Levi |
ICC | 4 |
| 2004 | Use of nested certificates for efficient, dynamic, and trust preserving public key infrastructureabstractCertification is a common mechanism for authentic public key distribution. In order to obtain a public key, verifiers need to extract a certificate path from a network of certificates, which is called public key infrastructure (PKI), and verify the certificates on this path recursively. This is classical methodology. Nested certification is a novel methodology for efficient certificate path verification. Basic idea is to issue special certificates (called nested certificates) for other certificates. Nested certificates can be used together with classical certificates in PKIs. Such a PKI, which is called nested certificate-based PKI (NPKI), is proposed in this paper as an alternative to classical PKI. The concept of "certificates for other certificates" results in nested certificate paths in which the first certificate is verified cryptographically while others are verified by just fast hash computations. Thus, we can employ efficiently verifiable nested certificate paths instead of classical certificate paths. NPKI is a dynamic system and involves several authorities in order to add a new user to the system. This uses the authorities' idle time to the benefit of the verifiers. We formulate the trade-off between the nested certification overhead and the time improvement on certificate path verification. This trade-off is numerically analyzed for a 4-level 20-ary balanced tree-shaped PKI and it has been shown that the extra cost of nested certification is in acceptable limits in order to generate quickly verifiable certificate paths for certain applications. Moreover, PKI-to-NPKI transition preserves the existing hierarchy and trust relationships in the PKI, so that it can be used for PKIs with fixed topology. Although there are many certificates in NPKI, certificate revocation is no more of a problem than with classical PKIs. NPKI even has an advantage on the number of certificate revocation controls: at most two certificate revocation controls are sufficient independent of the path length. Nested certificates can be easily adopted into X.509 standard certificate structure. Both verification efficiency and revocation advantage of NPKI and nested certificates make them suitable for hierarchical PKIs of wireless applications where wireless end users have limited processing power. Albert Levi, M. Ufuk Çaglayan, Çetin Kaya Koç |
ACM Trans. Inf. Syst. Secur. | 1 |
| 2003 | Performance Evaluation of Public-Key Cryptosystem Operations in WTLS ProtocolabstractWTLS (wireless transport layer security) is an important standard protocol for secure wireless access to Internet services. WTLS employs public-key cryptosystems during the handshake between mobile client and WAP gateway (server). Several cryptosystems at different key strengths can be used in WTLS. The trade-off is security versus processing and transmission time. In this paper, an analytical performance model for public-key cryptosystem operations in WTLS protocol is developed. Different handshake protocols, different cryptosystems and key sizes are considered. Public-key cryptosystems are implemented using state-of-the-art performance improvement techniques, yielding actual performance figures for individual cryptosystems. These figures and the analytical model are used to calculate the cost of using public-key cryptosystems in WTLS. Results for different cryptosystems and handshake protocols are comparatively depicted and interpreted. It has been observed that ECC (elliptic curve cryptography) performs better than its rival RSA cryptosystem in WTLS. Performance of some stronger ECC curves, which are not considered in WTLS standard, is also analyzed. Results showed that some of those curves could be used in WTLS for high security applications with an acceptable degradation in performance. Albert Levi, Erkay Savas |
ISCC | 1 |
| 2001 | CONSEPP: CONvenient and Secure Electronic Payment Protocol Based on X9.59abstractThe security of electronic payment protocols is of interest to researchers in academia and industry. While the ultimate objective is the safest and most secure protocol, convenience and usability should not be ignored, or the protocol may not be suitable for large-scale deployment. Our aim is to design a practical electronic payment protocol which is both secure and convenient. ANSI X9.59 standard describes secure payment objects to be used in electronic payment in a convenient and secure way. It has many useful convenience features for large-scale consumer market deployment, the best being the elimination of consumer certificates. Consumer public keys are stored in account records at financial institutions; the digital signatures issued by consumers are verified by financial institutions. Encryption is deliberately not provided by X9.59. We propose a new Internet e-payment protocol, namely CONSEPP (CONvenient and Secure E-Payment Protocol), based on the account authority model of ANSI X9.59 standard. CONSEPP is the specialized version of X9.59 for Internet transactions (X9.59 is multi-purpose). It has some extra features on top of the X9.59 standard. X9.59 requires merchant certificates; in CONSEPP we propose a lightweight method to avoid the need for merchant certificates. Moreover, we propose a simple method for secure shopping experience between merchant and consumer. Merchant authentication is embedded in the payment cycle. CONSEPP aims to use current financial transaction networks, like VisaNet, BankNet and ACH networks, for communications among financial institutions. No certificates (in the classical sense) or certificate authorities exist in CONSEPP. Convenience is not traded for security; basic security requirements are fulfilled in the payment authorization cycle without extra messaging and significant overhead. Albert Levi, Çetin Kaya Koç |
ACSAC | 1 |
| 2001 | Reducing Certificate Revocating Cost using NPKI
Albert Levi, Çetin Kaya Koç |
SEC | 1 |
| 2000 | An Efficient, Dynamic and Trust Preserving Public Key InfrastructureabstractNested certification is a methodology for efficient certificate path verification. Nested certificates can be used together with classical certificates in the Public Key Infrastructures (PKIs). Such a PKI, which is called nested certificate based PKI (NPKI), is proposed as an alternative to classical PKI. The NPKI formation model is a transition from an existing PKI by issuing nested certificates. Thus, we can extract efficiently verifiable nested certificate paths instead of classical certificate paths. NPKI is a dynamic system and involves several authorities in order to add a new user to the system. This uses the authorities' idle time to the benefit of the verifiers. We analyze the trade-off between the nested certification overhead and the time improvement on the certificate path verification. This trade-off is acceptable in order to generate quickly verifiable certificate paths. Moreover, PKI-to-NPKI transition preserves the existing hierarchy and trust relationships in the PKI, so that it can be used for strictly hierarchical PKIs. Albert Levi, M. Ufuk Çaglayan |
S&P | 1 |
| 1999 | Verification of classical certificates via nested certificates and nested certificate pathsabstractNested certificates are used to certify their subject certificates. In this way, the subject certificates can be verified via their nested certificates without using signature verification methods based on public key cryptosystems. Such a verification method is called subject certificate verification. In this paper, a subject certificate verification method will be introduced. It will be shown that subject certificate verification has the same confidence as the cryptographic certificate verification. Moreover, subject certificate verification is faster than cryptographic certificate verification. It will also be shown that a classical certificate can be verified via a sequence of nested certificates-called nested certificate path-and such verification has the same confidence as the cryptographic verification of the same certificate. Nested certificate path verification is faster than the classical certificate path verification also. Moreover in this paper, simulation results will be presented for efficiency improvement in the nested certificate path verification method over the cryptographic classical certificate path verification method. Albert Levi, M. Ufuk Çaglayan |
ICCCN | 1 |
| 1999 | Analytical Performance Evaluation of Nested Certificates
Albert Levi, M. Ufuk Çaglayan |
Perform. Evaluation | 1 |