VLDB 2026 Research / reviewers in the wild / expert
Reihaneh Safavi-Naini
dblp:s/ReihanehSafaviNaini
· DBLP profile ↗
208ranked-venue papers
33as first author
22since 2021 · last 2026
0000-0002-1697-3590ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 152 · 21 first-author · 12 since 2021Theory of computation · 28 · 10 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 14 · 2 first-author · 5 since 2021Computer networks · 8Graphics, computer vision, multimedia, augmented reality and games · 6Artificial intelligence and machine learning · 4Databases, data management, data science and information retrieval · 3 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Password Protected Universal Thresholdizer
Sabyasachi Dutta, Partha Sarathi Roy 0001, Reihaneh Safavi-Naini, Willy Susilo |
ACISP (2) | 3 |
| 2026 | Hybrid Encryption with Certified Deletion in Preprocessing ModelabstractCertified deletion allows Alice to outsource data to Bob and, at a later time, obtain a verifiable guarantee that the file has been irreversibly deleted at her request. This functionality, while impossible using classical information alone, can be achieved using quantum information. Existing approaches rely either on one-time pad (OTP) encryption or on computational hardness assumptions that may be vulnerable to future advances in classical or quantum computing. In this work, we introduce and formalize hybrid encryption with certified deletion in the preprocessing model (pHE-CD) and propose two constructions. Each construction composes an information-theoretic key encapsulation mechanism (iKEM) with a data encapsulation mechanism that provides certified deletion (DEM-CD) security, offering different security guarantees depending on the properties of DEM-CD. When DEM-CD is one-time information-theoretically secure, the composition provides information-theoretic security for both encryption and certified deletion. When DEM-CD is computationally secure, the composed construction provides computationally secure (post-quantum) encryption and everlasting certified deletion, where confidentiality is computational until the deletion certificate is successfully verified. After successful verification, confidentiality becomes unconditional. That is, successful verification of the deletion certificate guarantees that the data has been removed information-theoretically from the adversary's view. Both pHE-CD constructions support the encryption of arbitrarily long messages. Construction 2 is key-efficient and uses a DEM-CD built from quantum coding and AES, providing quantum-safe security for encryption. We conclude by discussing the implications of our results and directions for future research. Kunal Dey, Reihaneh Safavi-Naini |
ISIT | 2 |
| 2025 | Secure Composition of Quantum Key Distribution and Symmetric Key EncryptionabstractQuantum key distribution (QKD) allows Alice and Bob to share a secret key with proven information-theoretic security. Composability-based security proofs for QKD ensure that using the established key to encrypt a message using a one-time-pad encryption system, will result in information-theoretic secrecy for the communication. In this paper, we consider the problem of using a QKD established key with a secure symmetrickey based encryption system with computational security, and use an extension of the framework of hybrid encryption to prove security of the composition. We use an extension of the original framework of hybrid encryption to correlated randomness setting (Sharifian et al. in ISIT 2021) and propose a quantum-enabled Key Encapsulation Mechanism (qKEM) that is used to construct a quantum-enabled hybrid encryption ($q H E$) system, and prove a composition theorem for the security of the qHE. We construct a qKEM with proven security using an existing QKD (Portmann et al. in Rev. of Mod. Physics 2022). Using this qKEM with a secure Data Encapsulation Mechanism (DEM), that can be constructed using a one-time symmetric key encryption scheme, results in an efficient encryption scheme for unrestricted length messages with proved security against an adversary with access to (efficient) quantum computations. Thus a key-efficient post-quantum secure encryption with proved security and without using any computational assumptions. Kunal Dey, Reihaneh Safavi-Naini |
ISIT | 2 |
| 2025 | Hybrid encryption in correlated randomness model and KEM combiners
Somnath Panja, Setareh Sharifian, Shaoquan Jiang, Reihaneh Safavi-Naini |
Theor. Comput. Sci. | 4 |
| 2024 | Fair Private Set Intersection Using Smart Contracts
Sepideh Avizheh, Reihaneh Safavi-Naini |
ACNS (3) | 2 |
| 2024 | Short Paper: Breaking X-VRF, A Post-quantum Verifiable Random Function
Omid Bodaghi, Reihaneh Safavi-Naini |
FC (2) | 2 |
| 2024 | Group encryption: Full dynamicity, message filtering and code-based instantiation
Khoa Nguyen 0002, Reihaneh Safavi-Naini, Willy Susilo, Huaxiong Wang, Yanhong Xu 0002, Neng Zeng |
Theor. Comput. Sci. | 2 |
| 2024 | Refereed Delegation of Computation Using Smart ContractsabstractOutsourcing computation enables a weak client to expand its computational power as the need arises. A basic requirement of outsourcing computation is the guarantee that the computation result is correct. Cryptographic solutions that provide verifiability for the computation result when the computation is outsourced to a single server, are complex and fragile. We consider the intuitive approach of verifiable computation, called verifiable computation by replication, when the computation is replicated on multiple servers, and a referee decides the result of the final computation using the outputs of all servers. We consider the case when a smart contact is used as the referee. We propose a security model in the Universal Composability (UC) framework of Canetti, and design a 2-server and an n-server protocol with proved security in our model. Our protocols build on the Refereed Delegation of Computation (RDoC) framework of Canetti, Riva, and Rothblum, underline the challenges of using a smart contract as a referee, and address those challenges in the designed protocols. We give the efficiency analysis of the protocols, provide a proof of concept implementation for our protocols using Ethereum smart contact, and give concrete cost values for an example computation. Sepideh Avizheh, Mahmudun Nabi, Reihaneh Safavi-Naini |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2023 | Lower Bounds on the Share Size of Leakage Resilient Cheating Detectable Secret Sharing
Sabyasachi Dutta, Shaoquan Jiang, Reihaneh Safavi-Naini |
CANS | 3 |
| 2023 | A One-way Secret Key Agreement with Security Against Active AdversariesabstractIn a one-way secret key agreement (OW-SKA) protocol in source model, Alice and Bob have private samples of two correlated variables X and Y that are partially leaked to Eve through the variable Z, and use a single message from Alice to Bob to obtain a shared secret key. We propose an efficient secure OW-SKA when the sent message over the public channel can be tampered with by an active adversary. Our construction uses a specially designed hash function that is used for reconciliation, as well as detection of tampering. In detection of tampering the function is a Message Authentication Code (MAC) that maintains its security when the key is partially leaked. We prove the secrecy of the established key and robustness of the protocol, and discuss our results. Somnath Panja, Shaoquan Jiang, Reihaneh Safavi-Naini |
ISIT | 3 |
| 2023 | Privacy-Preserving Proof-of-Location With Security Against Geo-TamperingabstractA Proof-of-Location (POL) system is used to issue a proof-of-location token ($pol$) to a user who has been present at a location$\ell oc$, such that it can be later presented to a verifier to assure the presence of the user at$\ell oc$. Basic POL security requirements areunforgeabilityof$pol$, and itsnon-transferability(a$pol$issued to user$u_1$cannot be used by$u_2$). An additional important property of POL systems isuser privacyagainst the issuers and verifiers. We make two contributions. First, we formalize the POL security and privacy properties, and construct the first system providing provable security and privacy against the issuer and the verifier, both. Second, we introduce ageo-tampering attackthat completely breaks POL system security, by simply changing the location of a$pol$issuing node. The attack applies to portable infrastructure nodes that are not continually monitored. We propose an algorithm that is used by a$pol$issuer to provide a location integrity “proof”, that will be embedded in a$pol$to protect against this attack. The proof relies on a novel application of euclidean Distance Matrices. We implemented our POL on an off-the-shelf Android smartphone to show the practicality of the proposed algorithms. Md. Mamunur Rashid Akand, Reihaneh Safavi-Naini, Marc Kneppers, Matthieu Giraud, Pascal Lafourcade 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | A Capability-based Distributed Authorization System to Enforce Context-aware Permission SequencesabstractControlled sharing is fundamental to distributed systems. We consider a capability-based distributed authorization system where a client receives capabilities (access tokens) from an authorization server to access the resources of resource servers. Capability-based authorization systems have been widely used on the Web, in mobile applications and other distributed systems. Adrian Shuai Li, Reihaneh Safavi-Naini, Philip W. L. Fong |
SACMAT | 2 |
| 2022 | Traceable policy-based signatures and instantiation from lattices
Yanhong Xu 0002, Reihaneh Safavi-Naini, Khoa Nguyen 0002, Huaxiong Wang |
Inf. Sci. | 2 |
| 2022 | Privacy-preserving FairSwap: Fairness and privacy interplayabstractAbstract Fair exchange protocols are among the most important cryptographic primitives in electronic commerce. A basic fair exchange protocol requires that two parties who want to exchange their digital items either receive what they have been promised, or lose nothing. Privacy of fair exchange requires that no one else (other than the two parties) learns anything about the items. Fairness and privacy have been considered as two distinct properties of an exchange protocol. In this paper, we show that subtle ways of leaking the exchange item to the third parties affect fairness in fair exchange protocols when the item is confidential. Our focus is on Fair-Swap, a recently proposed fair exchange protocol that uses a smart contract for dispute resolution, has proven security in UC (Universal Composability) framework, and provides privacy when both parties are honest. We demonstrate, however, that FairSwap’s dispute resolution protocol leaks information to the public and this leakage provides opportunities for the dishonest parties to influence the protocol’s fairness guarantee. We then propose an efficient privacy-enhanced version of Fair-Swap, prove its security and give an implementation and performance evaluation of our proposed system. Our privacy enhancement uses circuit randomization, and we prove its security and privacy in an extension of universal composability model for non-monolithic adversaries that would be of independent interest. Sepideh Avizheh, Preston Haffey, Reihaneh Safavi-Naini |
Proc. Priv. Enhancing Technol. | 3 |
| 2021 | Leakage Resilient Cheating Detectable Secret Sharing Schemes
Sabyasachi Dutta, Reihaneh Safavi-Naini |
ACISP | 2 |
| 2021 | Password Protected Secret Sharing from Lattices
Partha Sarathi Roy 0001, Sabyasachi Dutta, Willy Susilo, Reihaneh Safavi-Naini |
ACNS (1) | 4 |
| 2021 | Second-Order Asymptotics for One-way Secret Key AgreementabstractSecret key agreement (SKA) is a basic cryptographic primitive that establishes a shared secret key between parties. In the two-party source model of SKA, Alice and Bob want to share a secret key. They each have private samples of two correlated variables that are partially leaked to Eve. In a one-way SKA protocol, Alice sends a single message to Bob over a public channel, allowing the two parties to calculate a shared secret key that will be essentially unknown to Eve. The length of the key is a function of the number of samples$n$. In this paper, we prove a tight second-order asymptotic approximation of the key length of one-way SKA protocols, and propose an approach to construct a computationally efficient one-way SKA protocol with near-optimum finite key length. We compare our results with related work, and discuss future research directions. Alireza Poostindouz, Reihaneh Safavi-Naini |
ISIT | 2 |
| 2021 | Information-theoretic Key Encapsulation and its Application to Secure CommunicationabstractA hybrid encryption scheme consists of a public-key part called the key encapsulation mechanism (KEM), that is used to generate and establish a shared secret key between two parties, and a (symmetric) secret-key part called the data encapsulation mechanism (DEM) that encrypts the data using the shared key. Hybrid encryption schemes are widely used for securing Internet communication. In this paper, we initiate the study of hybrid encryption in preprocessing model which assumes access to initial correlated variables by all parties (including the eavesdropper), and define information-theoretic KEM (iKEM) that together with a (computationally) secure DEM, results in a hybrid encryption scheme in preprocessing model. We define security of each building block, and prove a composition theorem that guarantees (computational) q-chosen-plaintext attack (CPA) security of the hybrid encryption system if the iKEM and the DEM satisfy q-chosen-encapsulation attack security and one-time security, respectively. We show that an iKEM can be realized by an information-theoretic one-way secret key agreement (OW-SKA) protocol where a single message is transmitted from Alice to Bob, with a new security definition that allows$q$queries to Alice. Using a OW-SKA that satisfies this new definition of security, effectively allows the established secret key to be used with a onetime symmetric key encryption system that can be implemented, for example, by XORing the output of a (computationally) secure pseudorandom generator with the message, to provide secure encryption of$q$arbitrary messages (polynomially bounded length). We discuss our results and directions for future work. Setareh Sharifian, Reihaneh Safavi-Naini |
ISIT | 2 |
| 2021 | Secret Key Capacity of Wiretapped Polytree-PINabstractIn secret key agreement (SKA) in multiterminal channel model, terminals are connected by a noisy discrete memoryless channel (DMC) with multiple input and multiple outputs. Terminals can use the DMC to obtain correlated randomness, and communicate over a noiseless public channel to establish a shared secret key among a designated subset of terminals. We focus on a special class of multiterminal channel models, called wiretapped Polytree-PIN, in which the noisy channel consists of a set of independent point-to-point channels whose underlying undirected connectivity graph forms a tree. We consider a wiretap setting, where the output of each point-to-point channel is partially leaked to a passive wiretapper adversary, Eve, through a second independent noisy channel. A secure SKA protocol generates a group secret key such that Eve has no information about it. In this paper, we derive the wiretap secret key capacity, which is the largest achievable secret key rate, of the wiretapped PolytreePIN model. Our result also implies the key capacity of the non-wiretapped Polytree-PIN model, that is the case when there is no leakage from point-to-point channels to Eve. Alireza Poostindouz, Reihaneh Safavi-Naini |
ITW | 2 |
| 2021 | Hybrid Encryption in Correlated Randomness ModelabstractA hybrid encryption scheme uses a key encapsulation mechanism (KEM) to generate and establish a shared secret key with the decrypter, and a secret key data encapsulation mechanism (DEM) to encrypt the data using the key that is established by the DEM. The decrypter recovers the key using the ciphertext that is generated by the KEM, and uses it to decrypt the ciphertext that is generated by the DEM.We motivate and propose hybrid encryption in correlated randomness model where all participants including the eavesdropper, have access to samples of their respective correlated random variables. We define information-theoretic KEM (iKEM), and prove a composition theorem for iKEM and DEM that allows us to construct an efficient hybrid encryption system in correlated randomness model, providing post-quantum security. The construction uses an information-theoretic one-way secret key agreement (OW-SKA) protocol that satisfies a new security definition, and a one-time symmetric key encryption system that can be implemented by XORing the output of a (computationally) secure pseudorandom generator with the message. We discuss our results and directions for future work. Reihaneh Safavi-Naini, Setareh Sharifian |
ITW | 1 |
| 2021 | More than a Fair Share: Network Data Remanence Attacks against Secret Sharing-based Schemes
Leila Rashidi, Daniel Kostecki, Alexander James, Anthony Peterson, Majid Ghaderi, Samuel Jero, Cristina Nita-Rotaru, Hamed Okhravi, Reihaneh Safavi-Naini |
NDSS | 9 |
| 2021 | Model Inversion for Impersonation in Behavioral Authentication Systems
Md. Morshedul Islam, Reihaneh Safavi-Naini |
SECRYPT | 2 |
| 2020 | A Channel Model of Transceivers for Multiterminal Secret Key Agreement
Alireza Poostindouz, Reihaneh Safavi-Naini |
ISITA | 2 |
| 2020 | A Capacity-achieving One-way Key Agreement with Improved Finite Blocklength Analysis
Setareh Sharifian, Alireza Poostindouz, Reihaneh Safavi-Naini |
ISITA | 3 |
| 2020 | Fuzzy Vault for Behavioral Authentication System
Md. Morshedul Islam, Reihaneh Safavi-Naini |
SEC | 2 |
| 2020 | Protecting data privacy in publicly verifiable delegation of matrix and polynomial functions
Liang Feng Zhang, Reihaneh Safavi-Naini |
Des. Codes Cryptogr. | 2 |
| 2019 | K2SN-MSS: An Efficient Post-Quantum SignatureabstractWith the rapid development of quantum technologies, quantum-safe cryptography has found significant attention. Hash-based signature schemes have been in particular of interest because of (i) the importance of digital signature as the main source of trust on the Internet, (ii) the fact that the security of these signatures relies on existence of one-way functions, which is the minimal assumption for signature schemes, and (iii) they can be efficiently implemented. Basic hash-based signatures are for a single message, but have been extended for signing multiple messages. In this paper we design a Multi-message Signature Scheme (MSS) based on an existing One-Time Signature (OTS) that we refer to as KSN-OTS. KSN uses SWIFFT, an additive homomorphic lattice-based hash function family with provable one-wayness property, as the one-way-function and achieves a short signature. We prove security of our proposed signature scheme in a new strengthened security model (multi-target multi-function) of MSS, determine the system parameters for 512 bit classical (256 bit quantum) security, and compare parameter sizes of our scheme against XMSS, a widely studied hash based MSS that has been a candidate for NIST standardization of post-quantum signature scheme. We give an efficient implementation of our scheme using Intel SIMD (Single Instruction Multiple Data) instruction set. For this, we first implement SWIFFT computation using a SIMD parallelization of Number Theoretic Transform (NTT) of elements of the ring Zp[X]/(Xn+1), that can support different levels of parallelization. We compare efficiency of this implementation with a comparable (security level) implementation of XMSS and show its superior performance on a number of efficiency parameters. Sabyasachi Karati, Reihaneh Safavi-Naini |
AsiaCCS | 2 |
| 2019 | Secret Sharing with Binary SharesabstractShamir's celebrated secret sharing scheme provides an efficient method for encoding a secret of arbitrary length $\ell$ among any $N \leq 2^\ell$ players such that for a threshold parameter $t$, (i) the knowledge of any $t$ shares does not reveal any information about the secret and, (ii) any choice of $t+1$ shares fully reveals the secret. It is known that any such threshold secret sharing scheme necessarily requires shares of length $\ell$, and in this sense Shamir's scheme is optimal. The more general notion of ramp schemes requires the reconstruction of secret from any $t+g$ shares, for a positive integer gap parameter $g$. Ramp secret sharing scheme necessarily requires shares of length $\ell/g$. Other than the bound related to secret length $\ell$, the share lengths of ramp schemes can not go below a quantity that depends only on the gap ratio $g/N$. In this work, we study secret sharing in the extremal case of bit-long shares and arbitrarily small gap ratio $g/N$, where standard ramp secret sharing becomes impossible. We show, however, that a slightly relaxed but equally effective notion of semantic security for the secret, and negligible reconstruction error probability, eliminate the impossibility. Moreover, we provide explicit constructions of such schemes. One of the consequences of our relaxation is that, unlike standard ramp schemes with perfect secrecy, adaptive and non-adaptive adversaries need different analysis and construction. For non-adaptive adversaries, we explicitly construct secret sharing schemes that provide secrecy against any $τ$ fraction of observed shares, and reconstruction from any $ρ$ fraction of shares, for any choices of $0 \leq τ< ρ\leq 1$. Our construction achieves secret length $N(ρ-τ-o(1))$, which we show to be optimal. For adaptive adversaries, we construct explicit schemes attaining a secret length $Ω(N(ρ-τ))$. Fuchun Lin, Mahdi Cheraghchi, Venkatesan Guruswami, Reihaneh Safavi-Naini, Huaxiong Wang |
ITCS | 4 |
| 2019 | Non-Malleable Codes against Active Physical Layer AdversaryabstractNon-malleable codes are randomized codes that protect coded messages against modification by functions in a tampering function class. These codes are motivated by providing tamper resilience in applications where a cryptographic secret is stored in a tamperable storage device and the protection goal is to ensure that the adversary cannot benefit from their physical tampering with the device. In this paper we consider nonmalleable codes for protection of secure communication against active physical layer adversaries. We define a class of functions that closely model tampering of communication by adversaries who can eavesdrop on a constant fraction of the transmitted codeword, and use this information to select a vector of tampering functions that will be applied to a second constant fraction of codeword components (possibly overlapping with the first set). We derive rate bounds for non-malleable codes for this function class and give a modular construction that adapts and provides new analysis for an existing construction in the new setting. We discuss our results and directions for future work. Fuchun Lin, Reihaneh Safavi-Naini, Mahdi Cheraghchi, Huaxiong Wang |
ISIT | 2 |
| 2019 | Wiretap Secret Key Capacity of Tree-PINabstractSecret key agreement (SKA) is an essential primitive in cryptography and information security. In a multiterminal key agreement problem, there are a set of terminals each having access to a component of a vector random variable, and the goal of the terminals is to establish a shared key among a designated subset of terminals. This problem has been studied under different assumptions about the adversary. In the most general model, the adversary has access to a random variable Z, that is correlated with all terminals' variables. The single-letter characterization of the secret key capacity of this model, known as the wiretap secret key capacity, is not known for an arbitrary Z. In this paper, we calculate the wiretap secret key capacity of a Tree-PIN, when Z consists of noisy version of terminals' variables. We also derive an upper bound and a lower bound for the wiretap secret key capacity of a PIN, and prove their tightness for some special cases. Alireza Poostindouz, Reihaneh Safavi-Naini |
ISIT | 2 |
| 2019 | Non-malleable Coding for Arbitrary Varying ChannelsabstractNon-malleable codes protect against an adversary who can tamper with the coded message by using a tampering function in a specified function family, guaranteeing that the tampering result will only depend on the chosen function and not the coded message. The codes have been motivated for providing protection against tampering with hardware that stores the secret cryptographic keys, and have found significant attention in cryptography. Traditional Shannon model of communication systems assumes the communication channel is perfectly known to the transmitter and the receiver. Arbitrary Varying Channels (AVCs) remove this assumption and have been used to model adversarially controlled channels. Transmission over these channels has been originally studied with the goal of recovering the sent message, and more recently with the goal of detecting tampering with the sent messages. In this paper we introduce non-malleability as the protection goal of message transmission over these channels, and study binary (discrete memoryless) AVCs where possible tampering is modelled by the set of channel states. Our main result is that non-malleability for these channels is achievable at a rate asymptotically approaching 1. We also consider the setting of an AVC with a special state s*, and the additional requirement that the message must be recoverable if s* is applied to all the transmitted bits. We give the outline of a message encoding scheme that in addition to non-malleability, can provide recovery for all s* channel. Fuchun Lin, San Ling, Reihaneh Safavi-Naini, Huaxiong Wang |
ITW | 3 |
| 2019 | A Modular Semantically Secure Wiretap Code with Shared Key for Weakly Symmetric ChannelsabstractWe study the problem of secure communication over a wiretap channel when the sender and the receiver have access to a shared secret key. We propose a modular secure construction of wiretap codes for a shared key setting that achieves secrecy capacity for weakly symmetric wiretap channels, and has computationally efficient encoding and decoding. The construction's security and reliability guarantees are in terms of semantic security, which is the strongest notion of security for these channels, and worst case error, respectively. We give concrete parameters of the construction for finite length messages to obtain a desired level of security and reliability. Setareh Sharifian, Reihaneh Safavi-Naini |
ITW | 2 |
| 2019 | Outsourcing scheme of ABE encryption secure against malicious adversaryabstractIntegrated broadcast-broadband services allow viewers to simultaneously receive broadcast content over the airwaves and additional information related to the content over the Internet. This integration provides opportunities for new services to be tailored and offered to individual viewers. Viewing histories provide a rich variety of data for service providers to learn the preferences of individual viewers and fine-tune their offerings. Each person’s viewing history, however, is privacy-sensitive data and may reveal information that the viewer does not want revealed. In this paper, we propose a system that allows viewers to specify a policy that they would like to be applied to their viewing history, when shared with service providers, by using attribute-based encryption (ABE). A ciphertext is associated with a policy, and it can be decrypted only by service providers who conform to the policy. To reduce the computations of the user terminal, we develop a system with provable security that allows the encryption to be outsourced to a cloud server, without the need to trust the cloud server. To the best of our knowledge, our construction gives the first outsourcing scheme of ABE encryption that is secure against a malicious cloud server. Although our solution is described for integrated broadcast-broadband services, the architecture and results could also be used for sharing viewing histories of OTT (Over-The-Top) services such as Netflix and location histories of mobile services. We implemented our scheme and showed that it significantly reduces the computation cost of a user terminal: about one third that of the Waters’ ABE scheme. Go Ohtake, Reihaneh Safavi-Naini, Liang Feng Zhang |
Comput. Secur. | 2 |
| 2018 | New Attacks and Secure Design for Anonymous Distance-Bounding
Ahmad Ahmadi, Reihaneh Safavi-Naini, Md. Mamunur Rashid Akand |
ACISP | 2 |
| 2018 | In-Region Authentication
Md. Mamunur Rashid Akand, Reihaneh Safavi-Naini |
ACNS | 2 |
| 2018 | A Discussion on Security Education in AcademiaabstractThis panel will explore how security topics are integrated into academic programs and future directions for improvements. It will address how early in time security should be introduced in programs like computer science and software engineering; and identify the critical takeaways that each graduating student should learn. We will try to separate out the important, practical concepts from the purely academic ones. We will also consider how well security programs translate to industry-focused needs: do students emerge with an understanding that is both deep and broad enough to be useful? In general, we will try to identify the pitfalls of current security education and how we can move forward as an academic community, in tandem with industry and government. Kevin R. B. Butler, Robert K. Cunningham, Paul C. van Oorschot, Reihaneh Safavi-Naini, Ashraf Matrawy, Jeremy Clark |
CCS | 4 |
| 2018 | Post-quantum Security using Channel NoiseabstractPost-quantum secure communication has attracted much interest in recent years. Known computationally secure post-quantum key agreement protocols are resource intensive for small devices. These devices may need to securely send frequent short messages, for example to report the measurement of a sensor. Secure communication using physical assumptions provides information-theoretic security (and so quantum-safe) with small computational over-head. Security and efficiency analysis of these systems however is asymptotic. In this poster we consider two secure message communication systems, and derive and compare their security and efficiency for finite length messages. Our results show that these systems indeed provide an attractive alternative for post-quantum security. Setareh Sharifian, Reihaneh Safavi-Naini, Fuchun Lin |
CCS | 2 |
| 2018 | Secure Key Agreement over Partially Corrupted ChannelsabstractKey agreement (KA) is a fundamental cryptographic primitive. Assuming that Alice and Bob do not have any prior shared correlation, it has been proved that key agreement with security against a computationally unbounded adversary is impossible if communication is either over a fully public channel, or the channel is fully controlled by the adversary. In this paper we consider a setting where communication is over a partially corrupted channel, and there is no prior shared correlation. We formalize security and reliability of key agreement protocols in this setting, derive bounds on the rate of secret key agreement, and give constructions that achieve the respective bounds. Our results show that secret key agreement, and hence secret message transmission, is possible, as long as a small fraction of the transmitted symbols in each round remain untouched by the adversary. Our results can be extended to key agreement between nodes in a network, when the two nodes are connected by a set of disjoint paths, and in each round a subset of paths is eavesdropped and another subset (possibly with overlap) is tampered with. We relate our results to previous works, and discuss future directions. Reihaneh Safavi-Naini, Pengwei Wang 0006 |
ISIT | 1 |
| 2018 | HCAP: A History-Based Capability System for IoT DevicesabstractPermissions are highly sensitive in Internet-of-Things (IoT) applications, as IoT devices collect our personal data and control the safety of our environment. Rather than simply granting permissions, further constraints shall be imposed on permission usage so as to realize the Principle of Least Privilege. Since IoT devices are physically embedded, they are often accessed in a particular sequence based on their relative physical positions. Monitoring if such sequencing constraints are honoured when IoT devices are accessed provides a means to fence off malicious accesses. This paper proposes a history-based capability system, HCAP, for enforcing permission sequencing constraints in a distributed authorization environment. We formally establish the security guarantees of HCAP, and empirically evaluate its performance. Lakshya Tandon, Philip W. L. Fong, Reihaneh Safavi-Naini |
SACMAT | 3 |
| 2018 | Path Hopping: An MTD Strategy for Long-Term Quantum-Safe CommunicationabstractMoving target defense (MTD) strategies have been widely studied for securing computer systems. We consider using MTD strategies to provide long-term cryptographic security for message transmission against an eavesdropping adversary who has access to a quantum computer. In such a setting, today’s widely used cryptographic systems including Diffie-Hellman key agreement protocol and RSA cryptosystem will be insecure and alternative solutions are needed. We will use a physical assumption, existence of multiple communication paths between the sender and the receiver, as the basis of security, and propose a cryptographic system that uses this assumption and an MTD strategy to guarantee efficient long-term information theoretic security even when only a single path is not eavesdropped. Following the approach of Maleki et al., we model the system using a Markov chain, derive its transition probabilities, propose two security measures, and prove results that show how to calculate these measures using transition probabilities. We define two types of attackers that we call risk-taking and risk-averse and compute our proposed measures for the two types of adversaries for a concrete MTD strategy. We will use numerical analysis to study tradeoffs between system parameters, discuss our results, and propose directions for future research. Reihaneh Safavi-Naini, Alireza Poostindouz, Viliam Lisý |
Secur. Commun. Networks | 1 |
| 2017 | Decompression Quines and Anti-VirusesabstractData compression is ubiquitous to any information and communication system. It often reduces resources required to store and transmit data. However, the efficiency of compression algorithms also makes them an obvious target for hackers to mount denial-of-service attacks. In this work, we consider decompression quines, a specific class of compressed files that decompress to themselves. We analyze all the known decompression quines by studying their structures, and their impact on anti-viruses. Our analysis reveals that most of the anti-viruses do not have a suitable architecture in place to detect decompression quines. Even worse, some of them are vulnerable to denial-of-service attacks exploiting quines. Motivated by our findings, we study several quine detectors and propose a new one that exploits the fact that quines and non-quine files do not share the same underlying structure. Our evaluation against different datasets shows that the detector incurs no performance overhead at the expense of a low false positive rate. Margaux Canet, Amrit Kumar 0001, Cédric Lauradoux, Mary-Andréa Rakotomanga, Reihaneh Safavi-Naini |
CODASPY | 5 |
| 2017 | Distance-bounding Identification
Ahmad Ahmadi, Reihaneh Safavi-Naini |
ICISSP | 2 |
| 2017 | Outsourcing Scheme of ABE Encryption Secure against Malicious AdversaryabstractIntegrated broadcast-broadband services allow viewers to simultaneously receive broadcast content over the airwaves and additional information related to the content over the Internet. This integration provides opportunities for new services to be tailored and offered to individual viewers. Viewing histories provide a rich variety of data for service providers to learn the preferences of individual viewers and fine-tune their offerings. Each person's viewing history, however, is privacy-sensitive data and may reveal information that the viewer does not want revealed. In this paper, we propose a system that allows viewers to specify a policy that they would like to be applied to their viewing history, when shared with service providers, by using attribute-based encryption (ABE). A ciphertext is associated with a policy, and it can be decrypted only by service providers who conform to the policy. To reduce the computations of the user terminal, we develop a system with provable security that allows the encryption to be outsourced to a cloud server, without the need to trust the cloud server. Although our solution is described for integrated broadcast-broadband services, the architecture and results could also be used for sharing viewing histories of services such as Netflix. We implemented our scheme and showed that it significantly reduces the computation cost of a user terminal. Go Ohtake, Reihaneh Safavi-Naini, Liang Feng Zhang |
ICISSP | 2 |
| 2017 | Secret key agreement using a virtual wiretap channelabstractKey agreement using physical layer properties of communication channels is a well studied problem. iJam is a physical layer key agreement protocol that achieves security by creating a “virtual” wiretap channel for the adversary through a subprotocol between the sender and the receiver that uses self-jamming by the receiver. The protocol was implemented and its security was shown through extensive experiments. The self-jamming subprotocol of iJam was later modelled as a wiretap channel and used for designing a secure message transmission protocol with provable security. We use the same wiretap model of the subprotocol to design secret key agreement protocols with provable security. We propose two protocols that use the wiretap channel once from Alice to Bob, and a protocol that uses two wiretap channels, one from Alice to Bob, and one in the opposite direction. We provide security proof and efficiency analysis for the protocols. The protocols effectively give physical layer security protocols that can be implemented and have provable security. We discuss our results and propose directions for future research. Setareh Sharifian, Fuchun Lin, Reihaneh Safavi-Naini |
INFOCOM | 3 |
| 2017 | Interactive message transmission over adversarial wiretap channel IIabstractIn Wyner wiretap II model of communication, Alice and Bob are connected by a channel that can be eavesdropped by an adversary with unlimited computation who can select a fraction of communication to view, and the goal is to provide perfect information theoretic security. Information theoretic security is increasingly important because of the threat of quantum computers that can effectively break algorithms and protocols that are used in today's public key infrastructure. We consider interactive protocols for wiretap II channel with active adversary who can eavesdrop and add adversarial noise to the eavesdropped part of the codeword. These channels capture wireless setting where malicious eavesdroppers at reception distance of the transmitter can eavesdrop the communication and introduce jamming signal to the channel. We derive a new upperbound R ≤ 1 - ρ for the rate of interactive protocols over two-way wiretap II channel with active adversaries, and construct a perfectly secure protocol family with achievable rate 1 - 2ρ + ρ2. This is strictly higher than the rate of the best one round protocol which is 1 - 2ρ, hence showing that interaction improves rate. We also prove that even with interaction, reliable communication is possible only if ρ <; 1/2. An interesting aspect of this work is that our bounds will also hold in network setting when two nodes are connected by n paths, a ρ of which is corrupted by the adversary. We discuss our results, give their relations to the other works, and propose directions for future work. Pengwei Wang 0006, Reihaneh Safavi-Naini |
INFOCOM | 2 |
| 2017 | A Post-Quantum One Time Signature Using Bloom FilterabstractToday's commonly used digital signatures will not be secure if a quantum computer exists. One time signatures (OTS) base security on the one way property of hash functions and will stay secure against an adversary with access to a quantum computer. These schemes however suffer from large public and private keys, as well as large signature size. We propose an OTS that uses Bloom filters to enhance the efficiency without sacrificing security, and show the required sizes of public/private keys, as well as the signature size will all reduce for the same security level. Masoumeh Shafieinejad, Reihaneh Safavi-Naini |
PST | 2 |
| 2017 | Privacy-Enhanced Profile-Based Authentication Using Sparse Random Projection
Somayeh Taheri, Md. Morshedul Islam, Reihaneh Safavi-Naini |
SEC | 3 |
| 2016 | Privacy and Utility of Inference Control Mechanisms for Social Computing ApplicationsabstractModern social computing platforms (e.g., Facebook) are extensible. Third-party developers deploy extensions (e.g., Facebook applications) that augment the functionalities of the underlying platforms. Previous work demonstrated that permission-based protection mechanisms, adopted to control access to users' personal information, fail to control inference - the inference of private information from public information. We envision an alternative protection model in which user profiles undergo sanitizing transformations before being released to third-party applications. Each transformation specifies an alternative view of the user profile. Unlike permission-based protection, this framework addresses the need for inference control. This work lays the theoretical foundation for view-based protection in three ways. First, existing work in privacy- preserving data publishing focuses on structured data (e.g., tables), but user profiles are semi-structured (e.g., trees). In information-theoretic terms, we define privacy and utility goals that can be applied to semi-structured data. Our notions of privacy and utility are highly targeted, mirroring the set up of social computing platforms, in which users specify their privacy preferences and third-party applications focus their accesses on selected components of the user profile. Second, we define an algebra of trees in which sanitizing transformations previously designed for structured data (e.g., generalization, noise introduction, etc) are now formulated for semi-structured data in terms of tree operations. Third, we evaluate the usefulness of our model by illustrating how the privacy enhancement and utility preservation effects of a view (a sanitizing transformation) can be formally and quantitatively assessed in our model. To the best of our knowledge, ours is the first work to articulate precise privacy and utility goals of inference control mechanisms for third-party applications in social computing platforms. Seyed Hossein Ahmadinejad, Philip W. L. Fong, Reihaneh Safavi-Naini |
AsiaCCS | 3 |
| 2016 | POSTER: Privacy Enhanced Secure Location VerificationabstractWe propose a privacy enhanced location verification system that uses in-region location verification to verify if a location claim is from within an area specified by a policy. The novelty of our work is the use of distance bounding protocols to construct a pseudo-rectangle (P-rectangle) that optimizes coverage of the policy area, and uses it to verify the claim with respect to the P-rectangle, thereby minimizing error. We propose a privacy enhancement for the system that ensures that the prover's location cannot be inferred by an adversary who monitors protocol messages. We discuss our results and propose directions for future research. Md. Mamunur Rashid Akand, Reihaneh Safavi-Naini |
CCS | 2 |
| 2016 | POSTER: A Behavioural Authentication System for Mobile UsersabstractActive behavioural-based authentication systems are challenge-response based implicit authentication systems that authenticate users using the behavioural features of the users when responding to challenges that are sent from the server. They provide a flexible (no extra hardware) and secure second factor for authentication systems, with applications including protection against identity theft and password compromise of web applications. We propose a novel active behavioural authentication system for mobile devices, called DAC (Draw A Circle), where a challenge specifies a set of constraints on a circle and the response is a user drawn circle that satisfies the constraints. We carefully select a set of features that capture behavioural traits of the user which is used to construct a profile for them, then design a matching algorithm that allows users to be authenticated with approximately 95% accuracy. We discuss our implementation, and present our experimental results that show, (i) the accuracy of authentication system and (ii) non-delegateability of profile, guaranteeing that the user cannot pass their credentials to others. Md. Morshedul Islam, Reihaneh Safavi-Naini |
CCS | 2 |
| 2016 | Codes for Detection of Limited View Algebraic Tampering
Fuchun Lin, Reihaneh Safavi-Naini, Pengwei Wang 0006 |
Inscrypt | 2 |
| 2016 | Special issue on recent advances in physical-layer security
Gerhard P. Hancke 0002, Aikaterini Mitrokotsa, Reihaneh Safavi-Naini, Damien Sauveron |
Comput. Networks | 3 |
| 2016 | Automated Proofs of Block Cipher Modes of Operation
Martin Gagné, Pascal Lafourcade 0001, Yassine Lakhnech, Reihaneh Safavi-Naini |
J. Autom. Reason. | 4 |
| 2016 | Two-level security for message sequencesabstractAbstract We consider a scenario where a sequence of messages must be protected and the security requirement is that, the most recent message has high level of security while past messages could be secured at a lower level. We assume the adversary is an eavesdropping adversary and has unlimited computational power. The motivation for this problem is situations where sensitivity of messages reduce over time, and this could be used to reduce the overall required key length of the system. The aforementioned requirements suggest dynamic security level for a message: when it is the last message in the sequence, it enjoys a high level of security, but as soon as a new message arrives, its security is decreased to a second lower level.We formalize security of this scenario, construct an encryption system with provable security, and show that the required key length in some sense (that will be explained) is optimal. We discuss our results and directions for future research. Copyright © 2016 John Wiley & Sons, Ltd. Mohsen Alimomeni, Reihaneh Safavi-Naini |
Secur. Commun. Networks | 2 |
| 2016 | A Model for Adversarial Wiretap ChannelsabstractIn the wiretap model of secure communication, Alice is connected to Bob over a noisy channel that is eavesdropped by Eve. The goal is to provide (asymptotic) reliability and perfect secrecy assuming that the Eve has unlimited computational power. The model has attracted considerable attention in recent years because it provides a natural model for passive eavesdropping in wireless communication. We consider a wiretap model with active adversaries, and define adversarial wiretap (AWTP) channels using a (ρr, ρw) wiretap adversary who can read a fraction ρr, and modify a fraction ρwof a sent codeword. The code components that are read and/or modified can be chosen adaptively, and the subsets of read and modified components could be different. AWTP codes provide secrecy and reliability for communication over AWTP channels. We define the security and reliability of AWTP channels and use these definitions to evaluate the security and reliability of codes for these channels. This paper has two main contributions. First, we prove an upper bound on the rate of AWTP codes for (ρr, ρw)-AWTP channels. Second, we give an explicit construction of a perfectly secure AWTP code family with efficient decoding that achieves the bound and, hence, obtain the secrecy capacity of AWTP channels for large alphabets. AWTP model is a natural extension of Wyner's wiretap models, and somewhat surprisingly, it is also closely related to a seemingly unrelated cryptographic primitive, secure message transmission (SMT). This relation results in a new (and the only known) bound on the transmission rate of 1-round (ε, δ)-SMT protocols. We discuss our results, give their relations to other works, and propose directions for future work. Pengwei Wang 0006, Reihaneh Safavi-Naini |
IEEE Trans. Inf. Theory | 2 |
| 2015 | Batch Verifiable Computation of Polynomials on Outsourced Data
Liang Feng Zhang, Reihaneh Safavi-Naini |
ESORICS (2) | 2 |
| 2015 | An Efficient Post-Quantum One-Time Signature Scheme
Kassem Kalach, Reihaneh Safavi-Naini |
SAC | 2 |
| 2015 | How to Prevent to Delegate Authentication
Mohsen Alimomeni, Reihaneh Safavi-Naini |
SecureComm | 2 |
| 2015 | Secure Obfuscation of Authoring Style
Hoi Le Thi, Reihaneh Safavi-Naini, Asadullah Al Galib |
WISTP | 2 |
| 2015 | Reconciling user privacy and implicit authentication for mobile devices
Siamak F. Shahandashti, Reihaneh Safavi-Naini, Nashad Ahmed Safa |
Comput. Secur. | 2 |
| 2015 | Batch verifiable computation of outsourced functions
Liang Feng Zhang, Reihaneh Safavi-Naini |
Des. Codes Cryptogr. | 2 |
| 2014 | Private Message Transmission Using Disjoint Paths
Hadi Ahmadi, Reihaneh Safavi-Naini |
ACNS | 2 |
| 2014 | Verifiable Multi-server Private Information Retrieval
Liang Feng Zhang, Reihaneh Safavi-Naini |
ACNS | 2 |
| 2014 | CCSW 2014: Sixth ACM Cloud Computing Security WorkshopabstractThe 6th ACM Cloud Computing Security Workshop (CCSW 2014) is held in conjunction with the 21st ACM Conference on Computer and Communications Security (CCS 2014), on November 7 at The Scottsdale Plaza Resort, Scottsdale, Arizona, USA. Cloud computing is a new paradigm for computing as a utility and refers to aggregation of virtualized computing resources managed by a service provider and dynamically allocated to tenants on demand. The "cloud" transforms the entire IT industry, enables new business applications and services at reduced costs, but at the same time raises new security and privacy issues that must be addressed before its wide adoption. The CCSW workshop series focuses on the security challenges and exciting research opportunities that are brought about by recent developments in cloud computing. Alina Oprea, Reihaneh Safavi-Naini |
CCS | 2 |
| 2014 | Verifiable Delegation of Computations with Storage-Verification Trade-off
Liang Feng Zhang, Reihaneh Safavi-Naini |
ESORICS (1) | 2 |
| 2014 | Privacy-Preserving Distance-Bounding Proof-of-Knowledge
Ahmad Ahmadi, Reihaneh Safavi-Naini |
ICICS | 2 |
| 2014 | MOVTCHA: A CAPTCHA Based on Human Cognitive and Behavioral Features Analysis
Asadullah Al Galib, Reihaneh Safavi-Naini |
ICICS | 2 |
| 2014 | Distance Lower Bounding
Xifan Zheng, Reihaneh Safavi-Naini, Hadi Ahmadi |
ICICS | 2 |
| 2014 | Incentivize cooperative sensing in distributed cognitive radio networks with reputation-based pricingabstractIn a cognitive radio network, selfish secondary users may not voluntarily contribute to desired cooperative sensing. We design the first fully distributed scheme to incentivize participation of nodes in cooperative sensing, by connecting sensing and spectrum allocation, and offering incentive from latter to the former. Secondary users that are more active and report more accurate sensing values will be given higher reputation values, which results in lower prices in the spectrum allocation phase. Theoretical analysis and simulation results indicate that the proposed method effectively incentivizes sensing participation, and rewards truthful and accurate reporting. Our proposed system is fully distributed and does not rely on a central authority, and so is more applicable in dynamic cognitive radio networks in practice. We also show how to improve the robustness of reputation when malicious nodes report spurious reputation. Tongjie Zhang, Zongpeng Li, Reihaneh Safavi-Naini |
INFOCOM | 3 |
| 2014 | An efficient code for Adversarial Wiretap channelabstractIn the (ρr, ρw)-adversarial wiretap (AWTP) channel model of [13], a codeword sent over the communication channel is corrupted by an adversary who observes a fraction ρrof the codeword, and adds noise to a fraction ρwof the codeword. The adversary is adaptive and chooses the subsets of observed and corrupted components, arbitrarily. In this paper we give the first efficient construction of a code family that provides perfect secrecy in this model, and achieves the secrecy capacity. Pengwei Wang 0006, Reihaneh Safavi-Naini |
ITW | 2 |
| 2014 | Privacy-Preserving Implicit Authentication
Nashad Ahmed Safa, Reihaneh Safavi-Naini, Siamak F. Shahandashti |
SEC | 2 |
| 2014 | Paillier-based publicly verifiable (non-interactive) secret sharing
Mahabir Prasad Jhanwar, Ayineedi Venkateswarlu, Reihaneh Safavi-Naini |
Des. Codes Cryptogr. | 3 |
| 2014 | A Framework for Expressing and Enforcing Purpose-Based Privacy PoliciesabstractPurpose is a key concept in privacy policies. Although some models have been proposed for enforcing purpose-based privacy policies , little has been done in defining formal semantics for purpose, and therefore an effective enforcement mechanism for such policies has remained a challenge. We have developed a framework for expressing and enforcing such policies by giving a formal definition of purpose and proposing a modal-logic language for formally expressing purpose constraints. The semantics of this language are defined over an abstract model of workflows . Based on this formal framework, we discuss some properties of purpose, show how common forms of purpose constraints can be formalized, how purpose-based constraints can be connected to more general access control policies, and how they can be enforced in a workflow-based information system by extending common access control technologies. Mohammad Jafari 0003, Reihaneh Safavi-Naini, Philip W. L. Fong, Ken Barker 0001 |
ACM Trans. Inf. Syst. Secur. | 2 |
| 2013 | Private Outsourcing of Polynomial Evaluation and Matrix Multiplication Using Multilinear Maps
Liang Feng Zhang, Reihaneh Safavi-Naini |
CANS | 2 |
| 2013 | ReDiSen: Reputation-based secure cooperative sensing in distributed cognitive radio networksabstractCognitive radio techniques represent an emerging approach for mitigating the spectrum scarcity problem in wireless communications. Cooperative sensing is an effective solution to improve sensing accuracy and robustness in the presence of fading and shadowing that make individual sensing less reliable. However, when an adversary can corrupt some nodes in the network, the effectiveness of cooperative sensing may degrade dramatically. We design the first fully distributed security scheme ReDiSen to counter attacks in cooperative sensing. We apply reputation generated from exchanged sensing results as an aid to restrict the impact of the malicious behaviours. Both theoretical analysis and simulation results indicate that ReDiSen provides an effective countermeasure against security attacks by enabling secondary users to obtain more accurate cooperative sensing results in adversarial environments. ReDiSen does not rely on a central authority, nor a common control channel, and is therefore more applicable in dynamic cognitive radio networks. Tongjie Zhang, Reihaneh Safavi-Naini, Zongpeng Li |
ICC | 2 |
| 2013 | Codes for limited view adversarial channelsabstractChannels with adversarial errors have been widely considered in recent years. In this paper we propose a new type of adversarial channel that is defined by two parameters ρrand ρw, specifying the read and write power of the adversary: for a codeword of length n, adversary can read ρrn components and add an error vector of weight up to ρwn to the codeword. We give our motivations, define performance criteria for codes that provide reliable communication over these channels, and describe two constructions, one deterministic and one probabilistic, for these codes. We discuss our results and outline our direction for future research. Reihaneh Safavi-Naini, Pengwei Wang 0006 |
ISIT | 1 |
| 2013 | Human Assisted Randomness Generation Using Video Games
Mohsen Alimomeni, Reihaneh Safavi-Naini |
ISC | 2 |
| 2013 | Scalable fragile watermarking for image authenticationabstractSemi‐fragile watermarks are used to detect unauthorised changes to an image, whereas tolerating allowed changes such as compression. Most semi‐fragile algorithms that tolerate compression assume that because compression only removes the less visually significant data from an image, tampering with any data that would normally be removed by compression cannot affect a meaningful change to the image. Scalable compression allows a single compressed image to produce a variety of reduced resolution or reduced quality images, termed subimages, to suit the different display or bandwidth requirements of each user. However, highly scaled subimages remove a substantial fraction of the data in the original image, so the assumption used by most semi‐fragile algorithms breaks down, as tampering with this data allows meaningful changes to the image content. The authors propose a scalable fragile watermarking algorithm for authentication of scalable JPEG2000 compressed images. It tolerates the loss of large amounts of image data because of resolution or quality scaling, producing no false alarms. Yet, it also protects that data from tampering, detecting even minor manipulations other than scaling, and is secure against mark transfer and collage attacks. Experimental results demonstrate this for scaling down to 1/1024th the area of the original or to 1/100th the file size. Angela Piper, Reihaneh Safavi-Naini |
IET Inf. Secur. | 2 |
| 2013 | Message transmission and key establishment: General equality for weak and strong capacities
Hadi Ahmadi, Reihaneh Safavi-Naini |
J. Inf. Secur. Appl. | 2 |
| 2012 | Private Fingerprint Matching
Siamak F. Shahandashti, Reihaneh Safavi-Naini, Philip Ogunbona |
ACISP | 2 |
| 2012 | A General Construction for 1-Round δ-RMT and (0, δ)-SMT
Reihaneh Safavi-Naini, Mohammed Ashraful Tuhin, Pengwei Wang 0006 |
ACNS | 1 |
| 2012 | An information theoretic privacy and utility measure for data sanitization mechanismsabstractData collection agencies publish sensitive data for legitimate purposes, such as research, marketing and etc. Data publishing has attracted much interest in research community due to the important concerns over the protection of individuals privacy. As a result several sanitization mechanisms with different notions of privacy have been proposed. To be able to measure, set and compare the level of privacy protection, there is a need to translate these different mechanisms to a unified system. In this paper, we propose a novel information theoretic framework for representing a formal model of a mechanism as a noisy channel and evaluating its privacy and utility. We show that deterministic publishing property that is used in most of these mechanisms reduces the privacy guarantees and causes information to leak. The great effect of adversary's background knowledge on this metric is concluded. We also show that using this framework we can compute the sanitization mechanism's preserved utility from the point of view of a data user. By using the specifications of a popular sanitization mechanism, k-anonymity, we analytically provide a representation of this mechanism to be used for its evaluation. Mina Askari, Reihaneh Safavi-Naini, Ken Barker 0001 |
CODASPY | 2 |
| 2012 | Privacy Consensus in Anonymization Systems via Game Theory
Rosa Karimi Adl, Mina Askari, Ken Barker 0001, Reihaneh Safavi-Naini |
DBSec | 4 |
| 2012 | Short Pairing-Efficient Threshold-Attribute-Based Signature
Martin Gagné, Shivaramakrishnan Narayan, Reihaneh Safavi-Naini |
Pairing | 3 |
| 2011 | Optimal message transmission protocols with flexible parametersabstractIn Secure message transmission (SMT) protocols two nodes in a network want to communicate securely, given that some of the nodes in the network are corrupted by an adversary with unlimited computational power. An SMT protocol uses multiple paths between the sender and a receiver to guarantee privacy and reliability of the message transmission. An (e, δ)-SMT protocol bounds the adversary's success probability of breaking privacy and reliability to e and δ, respectively. Rate optimal SMT protocols have the smallest transmission rate (amount of communication per one bit of message). Rate optimal protocols have been constructed for a restricted set of parameters.In this paper we use wire virtualization method to construct new optimal protocols for a wide range of parameters using previously known optimal protocols. In particular, we design, for the first time, an optimal 1-round (0, δ)-SMT protocol for n = (2 + c)t, c ≥ 1/t, where n is the number of paths between the sender and the receiver, up to t of which are controlled by the adversary. We also design an optimal 2-round (0, 0)-SMT protocol for n = (2 + c)t, c ≥ 1/t, with communication cost better than the known protocols. The wire virtualization method can be used to construct other protocols with provable properties from component protocols. Reihaneh Safavi-Naini, Mohammed Ashraful Tuhin, Hongsong Shi |
AsiaCCS | 1 |
| 2011 | Towards defining semantic foundations for purpose-based privacy policiesabstractWe define a semantic model for purpose, based on which purpose-based privacy policies can be meaningfully expressed and enforced in a business system. The model is based on the intuition that the purpose of an action is determined by its situation among other inter-related actions. Actions and their relationships can be modeled in the form of an action graph which is based on the business processes in a system. Accordingly, a modal logic and the corresponding model checking algorithm are developed for formal expression of purpose-based policies and verifying whether a particular system complies with them. It is also shown through various examples, how various typical purpose-based policies as well as some new policy types can be expressed and checked using our model. Mohammad Jafari 0003, Philip W. L. Fong, Reihaneh Safavi-Naini, Ken Barker 0001, Nicholas Paul Sheppard |
CODASPY | 3 |
| 2011 | A rights management approach to protection of privacy in a cloud of electronic health recordsabstractA patient-centric DRM approach is proposed for protecting privacy of health records stored in a cloud storage based on the patient's preferences and without the need to trust the service provider. Contrary to the current server-side access control solutions, this approach protects the privacy of records from the service provider, and also controls the usage of data after it is released to an authorized user. Mohammad Jafari 0003, Reihaneh Safavi-Naini, Nicholas Paul Sheppard |
Digital Rights Management Workshop | 2 |
| 2011 | Secure Localization Using Dynamic Verifiers
Nashad Ahmed Safa, Saikat Sarkar 0003, Reihaneh Safavi-Naini, Majid Ghaderi |
ESORICS | 3 |
| 2011 | Secret Keys from Channel Noise
Hadi Ahmadi, Reihaneh Safavi-Naini |
EUROCRYPT | 2 |
| 2011 | Practical RFID ownership transfer schemeabstractWhen an RFID tag changes hand, it is not as simply as handing over the tag secret to the new owner. Privacy is a concern if there is no secure ownership transfer scheme to aid the transfer. After sales service and temporary tag delegation are also features commonly seen in such applications. In thi s paper, we proposed a new RFID ownership transfer scheme that achieves the most security protections and properties in comparison to most of the previous schemes. We also introduced four new security properties that have not been considered before. This opens up new research directions for further development of RFID ownership transfer. Ching Yu Ng, Willy Susilo, Yi Mu 0001, Reihaneh Safavi-Naini |
J. Comput. Secur. | 4 |
| 2011 | On Optimal Secure Message Transmission by Public DiscussionabstractIn a secure message transmission (SMT) scenario, a sender wants to send a message in a private and reliable way to a receiver. Sender and receiver are connected by n wires, t of which can be controlled by an adaptive adversary with unlimited computational resources. In Eurocrypt 2008, Garay and Ostrovsky considered an SMT scenario where sender and receiver have access to a public discussion channel and showed that secure and reliable communication is possible when n ≥ t + 1. In this paper, we will show that a secure protocol requires at least three rounds of communication and two rounds invocation of the public channel and hence give a complete answer to the open question raised by Garay and Ostrovsky. We also describe a round optimal protocol that has constant transmission rate over the public channel. Hongsong Shi, Shaoquan Jiang, Reihaneh Safavi-Naini, Mohammed Ashraful Tuhin |
IEEE Trans. Inf. Theory | 3 |
| 2010 | Securing wireless sensor networks against large-scale node capture attacksabstractSecuring wireless sensor networks against node capture is a challenging task. All well-known random key pre-distribution systems, including the Eschenauer and Gligor's pioneering scheme, its extensions, as well as threshold schemes, become insecure when a large number of nodes are captured. We propose a general technique, called virtual key ring, that can effectively strengthen the resilience of random key pre-distribution systems against node capture attacks by reducing the pre-loaded keying material while maintaining secure connectivity of the network.The technique is general and applicable to many key pre-distribution systems. We however focus on the original EG scheme and propose a virtual key ring system based on this pioneering scheme. We provide detailed mathematical analysis and a security proof for the system, and use extensive simulation to validate the analysis and to compare performance of the new system with the original EG scheme. We also present simulation results for the strengthened resilience when the virtual key ring scheme is combined with the multipath key reinforcement and q-composite techniques, showing that the system resilience is substantially improved against large-scale node capture attack (e.g., 40% of nodes captured). Tuan Manh Vu, Reihaneh Safavi-Naini, Carey L. Williamson |
AsiaCCS | 2 |
| 2010 | Using digital rights management for securing data in a medical research environmentabstractWe propose a digital rights management approach for sharing electronic health records in a health research facility and argue advantages of the approach. We also give an outline of the system under development and our implementation of the security features and discuss challenges that we faced and future directions. Mohammad Jafari 0003, Reihaneh Safavi-Naini, Chad Saunders, Nicholas Paul Sheppard |
Digital Rights Management Workshop | 2 |
| 2010 | Secret key establishment over a pair of independent broadcast channelsabstractWe consider the problem of secret key establishment (SKE) in the presence of a passive adversary, Eve, when Alice and Bob are connected by a pair of independent discrete memoryless broadcast channels in opposite directions. We refer to this setup as 2DMBC. We define the secret-key capacity in this setup and provide a lower bound on the capacity by proposing a two-round SKE protocol. We also prove an upper bound and show that the two bounds coincide in the case of degraded 2DMBCs. Hadi Ahmadi, Reihaneh Safavi-Naini |
ISITA | 2 |
| 2010 | New results on Secret Key Establishment over a pair of broadcast channelsabstractSecret Key Establishment (SKE) over a pair of independent Discrete Memoryless Broadcast Channels (DMBCs) was studied in where lower and upper bounds on the secret-key capacity were provided. In this paper, we study the above setup for two cases: (1) the DMBCs have “secrecy potential”, and (2) the DMBCs are stochastically degraded with independent channels. For (1), we propose a simple SKE protocol using the novel Interactive Channel Coding (ICC) method and prove that it achieves the lower bound. For (2), we give a simplified expression for the lower bound and prove that, when one of the legitimate parties sends only i.i.d. variables, the lower bound is tight and the capacity is achieved by a two-round protocol. Hadi Ahmadi, Reihaneh Safavi-Naini |
ISITA | 2 |
| 2010 | A Rights Management Approach to Securing Data Distribution in CoalitionsabstractAs network capacity has increased over the past decade, individuals and organisations have found it increasingly appealing to make use of remote services in the form of service-oriented architectures and cloud computing services. Data processed by remote services, however, is no longer under the direct control of the individual or organisation that provided the data, leaving data owners at risk of data theft or misuse. This paper describes a model by which data owners can control the distribution and use of their data throughout a dynamic coalition of service providers using digital rights management technology. Our model allows a data owner to establish the trustworthiness of every member of a coalition employed to process data, and to communicate a machine-enforceable usage policy to every such member. Farzad Salim, Nicholas Paul Sheppard, Reihaneh Safavi-Naini |
NSS | 3 |
| 2010 | On Applicability of Random Graphs for Modeling Random Key Predistribution for Wireless Sensor Networks
Tuan Manh Vu, Reihaneh Safavi-Naini, Carey L. Williamson |
SSS | 2 |
| 2010 | Towards securing mintroute in wireless sensor networksabstractIn a Wireless Sensor Network (WSN), the sensor nodes rely upon a multi-hop routing protocol to relay their data to the base station. However, most WSN routing protocols are vulnerable to attacks in which a malicious node can disrupt the routes, drop, modify, or divert data away from the base station. In this paper, we use the ns-2 network simulator to demonstrate the vulnerability of the MintRoute protocol to link quality attacks by a malicious node. We then propose a novel "sequence number gap trick" as a lightweight means to test for and detect the presence of a malicious attacker. The simulation results show that judicious use of the sequence number gap trick provides robust detection of malicious nodes, preserving the data delivery capabilities of the WSN. Islam Hegazy, Reihaneh Safavi-Naini, Carey L. Williamson |
WOWMOM | 2 |
| 2009 | On the operational semantics of rights expression languagesabstractWe propose an operational model for formalising and enforcing rights expression languages based on the concept of a rights expression compiler. Our compiler transforms an XML-based rights expression into a programme for a virtual machine. This approach provides a formal way of defining semantics for rights expression languages that can be directly used in practice to enforce the expressions while ensuring their consistency and correctness. We further argue that our model eliminates a number of limitations in previous attempts to associate rights expression languages with formal semantics. We demonstrate the power and practicality of our model by using it to develop operational semantics for the OMA Rights Expression Language, from which a real interpreter can be derived with relatively little effort. Nicholas Paul Sheppard, Reihaneh Safavi-Naini |
Digital Rights Management Workshop | 2 |
| 2009 | Corruption-Localizing Hashing
Giovanni Di Crescenzo, Shaoquan Jiang, Reihaneh Safavi-Naini |
ESORICS | 3 |
| 2009 | New Privacy Results on Synchronized RFID Authentication Protocols against Tag Tracing
Ching Yu Ng, Willy Susilo, Yi Mu 0001, Reihaneh Safavi-Naini |
ESORICS | 4 |
| 2009 | Optimal secure message transmission by public discussionabstractSecure message transmission assumes n channels between a sender and a receiver such that up to t channels are under the control of a computationally unlimited adversary. In secure message transmission by public discussion protocol, sender and receiver have access to a public authenticated channel. In this paper we show that if n ¿ t + 1, a secure protocol requires at least 3 rounds of communication and 2 rounds invocation of the public channel. This gives a complete answer to a question raised by Garay and Ostrovsky in Eurocrypt 2008. We also describe a round optimal protocol that has constant transmission rate over the public channel. Hongsong Shi, Shaoquan Jiang, Reihaneh Safavi-Naini, Mohammed Ashraful Tuhin |
ISIT | 3 |
| 2009 | Ranking Attack Graphs with Graph Neural Networks
Reihaneh Safavi-Naini, Markus Hagenbuchner, Willy Susilo, Jeffrey Horton, Sweah Liang Yong, Ah Chung Tsoi |
ISPEC | 2 |
| 2009 | Generic constructions for universal designated-verifier signatures and identitybased signatures from standard signaturesabstractThe authors give a generic construction for universal (mutli) designated-verifier signature schemes from a large class of signature schemes, referred to as Class ℂ. The resulting schemes are efficient and have two important properties. Firstly, they are provably DV-unforgeable, non-transferable and also non-delegatable. Secondly, the signer and the designated verifier can independently choose their cryptographic settings. The authors also propose a generic construction for (hierarchical) identity-based signature schemes from any signature scheme in ℂ and prove that the construction is secure against adaptive chosen message and identity attacks. The authors discuss possible extensions of our constructions to identity-based ring signatures and identity-based designated-verifier signatures from any signature in ℂ. Finally, the authors show that it is possible to combine the above constructions to obtain signatures with combined functionalities. Siamak F. Shahandashti, Reihaneh Safavi-Naini |
IET Inf. Secur. | 2 |
| 2008 | Non-interactive conference key distribution and its applicationsabstractAbstract. A non-interactive conference key distribution system (or, a NICKDS for short) allows conference members to calculate a shared key without interacting with each other. NICKDSs have been studied in unconditional and computational settings. In both cases security has been evaluated against an adversary who can corrupt participants. In this paper we consider an adaptive adversary who can both corrupt participants and also access the keys of conference of his choice. We revisit security of a number of known NICKDSs in this new model and present characterizations and conditions that guarantee security of the system in the new model. We also give a generic construction for computationally secure (in the new model) NICKDSs, from unconditionally secure ones in corruption only model. To show the usefulness of the new security model, we consider two composition constructions. First, we compose a secure NICKDS with a secure MAC by using the key obtained from the NICKDS as the MAC key, and show that this results in a ring authentication that guarantees authenticity of the received message while the sender remains anonymous and this anonymity is unconditional. The security theorem for the composition guarantees security for unconditional and computational settings, both. We also consider composition of a NICKDS with a secure (CCA2 secure) encryption system and show this results in a broadcast encryption system (BES) that is CCA2 secure. This is the first CCA2 secure BES in symmetric key setting. We discuss future works and open problems. 1 Reihaneh Safavi-Naini, Shaoquan Jiang |
AsiaCCS | 1 |
| 2008 | RFID Privacy Models Revisited
Ching Yu Ng, Willy Susilo, Yi Mu 0001, Reihaneh Safavi-Naini |
ESORICS | 4 |
| 2008 | Public Key Encryption with Keyword Search Revisited
Joonsang Baek, Reihaneh Safavi-Naini, Willy Susilo |
ICCSA (1) | 2 |
| 2008 | Utility of Knowledge Extracted from Unsanitized Data when Applied to Sanitized DataabstractKnowledge discovery systems extract knowledge from data that can be used for making prediction about incomplete data items. Utility is a measure of the usefulness of the discovered knowledge and satisfaction of the user with that knowledge. We motivate and address the question of usefulness of sanitized data using the notion of utility in data mining systems. For this we measure the success of patterns and rules discovered from the original data to make predictions about the sanitized data using a previously developed framework. Using experimental results on a set of medical data we demonstrate that it is possible to make useful predictions about the sanitized medical data when rules discovered from the original unsanitized medical data are used. We explain our results and compare it with the case where no sanitization is involved. Michal Sramka, Reihaneh Safavi-Naini, Jörg Denzinger, Mina Askari, Jie Gao 0019 |
PST | 2 |
| 2008 | Location constraints in digital rights management
Adam Muhlbauer, Reihaneh Safavi-Naini, Farzad Salim, Nicholas Paul Sheppard, Jan Martin Surminen |
Comput. Commun. | 2 |
| 2008 | Information Theoretic Bounds on Authentication Systems in Query ModelabstractAuthentication codes provide message integrity guarantees in an information theoretic sense within a symmetric key setting. Information theoretic bounds on the success probability of an adversary who has access to previously authenticated messages have been derived by Simmons and Rosenbaum, among others. In this paper, we consider a strong attack scenario where the adversary is adaptive and has access to authentication and verification oracles. We derive information theoretic bounds on the success probability of the adversary and on the key size of the code. This brings the study of unconditionally secure authentication systems on a par with the study of computationally secure ones. We characterize the codes that meet these bounds and compare our result with the earlier ones. Reihaneh Safavi-Naini, Peter R. Wild |
IEEE Trans. Inf. Theory | 1 |
| 2007 | Non-interactive Manual Channel Message Authentication Based on eTCR Hash Functions
Reza Reyhanitabar, Reihaneh Safavi-Naini |
ACISP | 3 |
| 2007 | An Adversary Aware and Intrusion Detection Aware Attack Model Ranking Scheme
Reihaneh Safavi-Naini, Jeffrey Horton, Willy Susilo |
ACNS | 2 |
| 2007 | Achieving Mobility and Anonymity in IP-Based Networks
Rungrat Wiangsripanawan, Willy Susilo, Reihaneh Safavi-Naini |
CANS | 3 |
| 2007 | Unconditionally secure ring authenticationabstractWe propose ring authentication in unconditionally secure setting. In a ring authentication system a sender can choose a set of users and construct an authenticated message for a receiver such that the receiver can verify authenticity of the message with respect to the user group chosen by the real sender. The sender will be unconditionally secure even if the receiver has corrupted up to c users and has access to up to ℓ past messages in the system. This functionality is similar to the one provided by ring signature systems with the difference that protection is against an adversary with unlimited power. (This also implies that the verification is not public and is by group members.) In ring signatures an adversary with unlimited computational power can always forge signed messages attributing them to groups of his choice. In our proposed systems the success chance of the adversary can be reduced to the required security of the system. We define model, propose a generic construction whose security is reduced to the security of its building blocks, and give concrete examples of this construction. The construction can also be used in computational setting resulting in ring authentication systems without public key cryptography. Reihaneh Safavi-Naini, Yvo Desmedt |
AsiaCCS | 1 |
| 2007 | Concurrently-secure credential ownership proofsabstractWe address the case in credential systems where a credential owner wants to show her credential to a verifier without taking the risk that the ability to prove ownership of the same (and any other) credential is transferred to the verifier. We define credential ownership proof protocols for credentials signed by standard signature schemes. We also propose proper security definitions for the protocol, aiming to protect the security of both the credential issuer and the credential owner against concurrent attacks. We give two generic constructions of credential ownership proofs based on identity-based encryption and identity-based identification schemes. Furthermore, we show that signatures with credential ownership proofs are equivalent to identity-based identification schemes, in the sense that any secure construction of each implies a secure construction of the other. Finally, we show that the GQ identification protocol yields an efficient credential ownership proof for credentials signed by the RSA-FDH signature scheme of Bellare and Rogaway and prove the protocol concurrently-secure. Siamak F. Shahandashti, Reihaneh Safavi-Naini, Joonsang Baek |
AsiaCCS | 2 |
| 2007 | Combinatorial characterizations of authentication codes in verification oracle modelabstractWe consider unconditionally secure authentication codes where the adversary has access to a verification oracle that when presented with a message query gives a response of 1 or 0 if the query corresponds to an authenticated message or not, respectively.We define two types of attack, offline and online, and their two corresponding games. We define the advantage of the adversary in each game and obtain a lower bound on the maximum advantage when the adversary plays his optimal strategy. For each game, authentication codes that satisfy the lower bounds with equality are said to provide perfect protection and guarantee the minimum success chance for the attacker in the corresponding game. We prove that an optimal code for the offline attack is also an optimal code for the online attack. In both cases, we prove that perfect protection of order i implies perfect protection of order j for j < i and derive a lower bound on the number of keys for an optimal code. Finally we show that the encoding matrix of codes with perfect protection of order i and minimum number of keys correspond to a Steiner system. Joseph Tonien, Reihaneh Safavi-Naini, Peter R. Wild |
AsiaCCS | 2 |
| 2007 | A Maximum Likelihood Watermark Decoding SchemeabstractBased on the observation that an attack applied on a watermarked image, from a decoding point of view, modifies the distribution of the detection values away from the ideal distribution (without attack) for corresponding watermarking scheme, we propose a generic maximum likelihood decoding scheme by approximating the distribution with a finite Gaussian mixture model. The parameters of the model are estimated using expectation-maximization algorithm. The scheme allows the decoding to be automatically adapted to attacks that the watermarked images have undergone and, in consequence, to improve the decoding accuracy. Experiments on a QIM based watermarking system have clearly verified the significant improvement of the decoding accuracy achieved by the proposed maximum likelihood decoding in comparison to conventional threshold decoding. Wenming Lu, Wanqing Li 0001, Reihaneh Safavi-Naini, Philip Ogunbona |
ICME | 3 |
| 2007 | Enforcing P3P Policies Using a Digital Rights Management System
Farzad Salim, Nicholas Paul Sheppard, Reihaneh Safavi-Naini |
Privacy Enhancing Technologies | 3 |
| 2007 | Construction of deletion correcting codes using generalized Reed-Solomon codes and their subcodes
Joseph Tonien, Reihaneh Safavi-Naini |
Des. Codes Cryptogr. | 2 |
| 2007 | Comparing and debugging firewall rule tablesabstractFirewalls are one of the essential components of secure networks. However, configuring firewall rule tables for large networks with complex security requirements is a difficult and error prone task. A method of representing firewall rule table that allows comparison of two tables is developed, and an algorithm that determines if two tables are equivalent is provided. (That is the set of packets that are permitted by the two tables are the same.) How such algorithm can assist system administrators to correctly implement organisational policy is discussed. The proposed approach is implemented and the results of the experiments are shown. Reihaneh Safavi-Naini, Jeffrey Horton, Willy Susilo |
IET Inf. Secur. | 2 |
| 2007 | Classification of the Deletion Correcting Capabilities of Reed-Solomon Codes of Dimension 2 Over Prime FieldsabstractDeletion correction codes have been used for transmission synchronization and, more recently, tracing pirated media. A generalized Reed-Solomon (GRS) code, denoted by GRSk(l,q,alpha,v), is a code of length l over GF(q) with qkcodewords. These codes have an efficient decoding algorithm and have been widely used for error correction and detection. It was recently demonstrated that GRS codes are also capable of correcting deletions. We consider a subclass of GRS codes with dimension k=2 and q prime, and study them with respect to deletion correcting capability. We give transformations that either preserve the code or maintain its deletion correction capability. We use this to define equivalent codes; and then use exhaustive and selective computer searches to find inequivalent codes with the highest deletion correcting capabilities. We show that, for the class under consideration, up to l-3 deletions may be corrected. We also show that for lles36 there exist codes with q2codewords such that receiving only 3 out of t transmitted symbols of a codeword is enough to recover the codeword, thus meeting the bound specified above. We also specify some "nice" codes which are associated with the smallest field possible for codes of a given length and deletion correcting capability. Some of the identified codes are unique, with respect to the defined equivalence. Luke McAven, Reihaneh Safavi-Naini |
IEEE Trans. Inf. Theory | 2 |
| 2006 | An Efficient Single-Key Pirates Tracing Scheme Using Cover-Free Families
Joseph Tonien, Reihaneh Safavi-Naini |
ACNS | 2 |
| 2006 | Detecting Policy Violations through Traffic AnalysisabstractRestrictions are commonly placed on the permitted uses of network protocols in the interests of security. These restrictions can sometimes be difficult to enforce. As an example, a permitted protocol can be used as a carrier for another protocol not otherwise permitted. However, if the observable behaviour of the protocol exhibits differences between permitted and non-permitted uses, it is possible to detect inappropriate use. We consider SSH, the secure shell protocol. This is an encrypted protocol with several uses. We attempt firstly to classify SSH sessions according to some different types of traffic for which the sessions have been used, and secondly, given a policy that permits SSH use for interactive traffic, to identify when a session appears to have been used for some other purpose Jeffrey Horton, Reihaneh Safavi-Naini |
ACSAC | 2 |
| 2006 | X2BT Trusted Reputation System: A Robust Mechanism for P2P Networks
Lan Yu, Willy Susilo, Reihaneh Safavi-Naini |
CANS | 3 |
| 2006 | Self-organised group key management for ad hoc networksabstractWe propose a fully distributed group key distribution protocol for ad hoc networks. The protocol uses a key pre-distribution step that is performed by each node independently and generates secure links between nodes in a neighbourhood. The key pre-distribution step also allows formation of an initiator group who will generate a session key that will be distributed to all nodes using the secure links between nodes obtained in key pre-distribution stage. We describe efficient protocols for join of new nodes and revocation of compromised nodes. We analyse the system by calculating probability of success of each operation. We evaluate security of the system against outside eavesdroppers and discuss its security against an adversary that corrupts the nodes of the network. Finally we compare our system with two competing systems and show its superior performance in some scenarios. Reihaneh Safavi-Naini, Joonsang Baek, Willy Susilo |
AsiaCCS | 2 |
| 2006 | Generic Construction of Hybrid Public Key Traitor Tracing with Full-Public-Traceability
Duong Hieu Phan, Reihaneh Safavi-Naini, Joseph Tonien |
ICALP (2) | 2 |
| 2006 | A Pixel-Based Robust Imagewatermarking SystemabstractRobust image watermarking systems are required to be resistant to geometric attacks in addition to common image processing tasks, such as JPEG compression. However, robustness against geometric attacks, such as rotation, scaling and translation, still remains one of the most challenging research topics in image watermarking. We propose a new pixel-based watermarking system in which a binary logo is embedded, a bit per pixel, in the pixel domain of an image. The encoder of the proposed system is based on a sliding window embedding scheme that applies the local average quantization index modulation (QEM), to achieve geometric attack robustness. The decoder employs a maximum a posteriori (MAP) estimation supported by Markov random field (MRF) model to achieve robust decoding. Additionally, we demonstrate that the proposed scheme is also robust against possible watermark removal due to JPEG compression Wenming Lu, Wanqing Li 0001, Reihaneh Safavi-Naini, Philip Ogunbona |
ICME | 3 |
| 2006 | On the Integration of Public Key Data Encryption and Public Key Encryption with Keyword Search
Joonsang Baek, Reihaneh Safavi-Naini, Willy Susilo |
ISC | 2 |
| 2006 | Multi-party Concurrent Signatures
Joseph Tonien, Willy Susilo, Reihaneh Safavi-Naini |
ISC | 3 |
| 2006 | Secret sharing schemes with partial broadcast channels
Reihaneh Safavi-Naini, Huaxiong Wang |
Des. Codes Cryptogr. | 1 |
| 2006 | Recovering DC Coefficients in Block-Based DCTabstractIt is a common approach for JPEG and MPEG encryption systems to provide higher protection for dc coefficients and less protection for ac coefficients. Some authors have employed a cryptographic encryption algorithm for the dc coefficients and left the ac coefficients to techniques based on random permutation lists which are known to be weak against known-plaintext and chosen-ciphertext attacks. In this paper we show that in block-based DCT, it is possible to recover dc coefficients from ac coefficients with reasonable image quality and show the insecurity of image encryption methods which rely on the encryption of dc values using a cryptoalgorithm. The method proposed in this paper combines dc recovery from ac coefficients and the fact that ac coefficients can be recovered using a chosen ciphertext attack. We demonstrate that a method proposed by Tang to encrypt and decrypt MPEG video can be completely broken. Takeyuki Uehara, Reihaneh Safavi-Naini, Philip Ogunbona |
IEEE Trans. Image Process. | 2 |
| 2005 | Cancelable Key-Based Fingerprint Templates
Russell Ang, Reihaneh Safavi-Naini, Luke McAven |
ACISP | 2 |
| 2005 | Dynamic k-Times Anonymous Authentication
Lan Nguyen, Reihaneh Safavi-Naini |
ACNS | 2 |
| 2005 | Universal Designated Verifier Signature Proof (or How to Efficiently Prove Knowledge of a Signature)
Joonsang Baek, Reihaneh Safavi-Naini, Willy Susilo |
ASIACRYPT | 2 |
| 2005 | On Securing RTP-Based Streaming Content with Firewalls
Reihaneh Safavi-Naini, Jeffrey Horton, Willy Susilo |
CANS | 2 |
| 2005 | Radio Networks with Reliable Communication
Yvo Desmedt, Yongge Wang 0001, Reihaneh Safavi-Naini, Huaxiong Wang |
COCOON | 3 |
| 2005 | Token-Controlled Public Key Encryption
Joonsang Baek, Reihaneh Safavi-Naini, Willy Susilo |
ISPEC | 2 |
| 2005 | Certificateless Public Key Encryption Without Pairing
Joonsang Baek, Reihaneh Safavi-Naini, Willy Susilo |
ISC | 2 |
| 2005 | A License Transfer System for Supporting Content Portability in Digital Rights Management
Reihaneh Safavi-Naini, Nicholas Paul Sheppard |
SEC | 2 |
| 2005 | Distributing the Encryption and Decryption of a Block Cipher
Keith M. Martin, Reihaneh Safavi-Naini, Huaxiong Wang, Peter R. Wild |
Des. Codes Cryptogr. | 2 |
| 2005 | MRD Hashing
Reihaneh Safavi-Naini, Chris Charnes |
Des. Codes Cryptogr. | 1 |
| 2004 | Unconditionally Secure Encryption Under Strong Attacks
Luke McAven, Reihaneh Safavi-Naini, Moti Yung |
ACISP | 2 |
| 2004 | Linear Code Implies Public-Key Traitor Tracing with Revocation
Vu Dong Tô, Reihaneh Safavi-Naini |
ACISP | 2 |
| 2004 | X2Rep: Enhanced Trust Semantics for the XRep Protocol
Nathan Curtis, Reihaneh Safavi-Naini, Willy Susilo |
ACNS | 2 |
| 2004 | Verifiable Shuffles: A Formal Model and a Paillier-Based Efficient Construction with Provable Security
Lan Nguyen, Reihaneh Safavi-Naini, Kaoru Kurosawa |
ACNS | 2 |
| 2004 | Efficient and Provably Secure Trapdoor-Free Group Signature Schemes from Bilinear Pairings
Lan Nguyen, Reihaneh Safavi-Naini |
ASIACRYPT | 2 |
| 2004 | Tracing traitors: a selective surveyabstractDigital media provide higher portability, storage and communication efficiency, and accuracy of data. However digital objects can be easily and accurately copied. This allows unauthorized reproduction and distribution of copyrighted objects, hence bypassing the ownership and intellectual property rights of owners, creators and distributors of the object. Protection of media data such as movies, music and multimedia data against illegal copying and re-distribution has been one of the greatest challenges of digital content distribution. Protection becomes exceedingly hard if a group of users combine their privileges to overcome the protection mechanism of the system. A range of techniques have been proposed to "mark" the content, or the player of the content, so that pirate digital objects, or the illegal player, can be traced and at least one of the colluders be identified. Reihaneh Safavi-Naini |
Digital Rights Management Workshop | 1 |
| 2004 | Import/export in digital rights managementabstractThe inherently controlled nature of digital rights management systems does little to promote inter-operability of systems provided by different vendors. In this paper, we consider import and export functionality by which multimedia protected by one digital rights management regime can be made available to a multimedia device that supports a different digital rights management regime, without compromising the protection afforded to the content under the original regime. We first identify specific issues to be addressed by developers of digital rights management import/export regimes and outline a variety of methods by which these regimes may be implemented. We then apply our observations to the specific example of import and export of content between the digital rights management regimes defined by the Motion Picture Exports Group and the Open Mobile Alliance. Reihaneh Safavi-Naini, Nicholas Paul Sheppard, Takeyuki Uehara |
Digital Rights Management Workshop | 1 |
| 2004 | An MPEG tolerant authentication system for video dataabstractWe propose a secure video authentication algorithm that is tolerant to visual degradation due to MPEG lossy compression to a designed level. The authentication process generates a tag that is sent with video data and the level of protection can be adjusted so that longer tags are used for higher security, and that the protection is distributed such that higher security is provided for regions of interest in the image. The computation required for authentication and verification can be largely performed as part of MPEG compression and so generation and verification of the tag can be integrated into the compression system. Calculation of the tag can be parallelized and so made fast Takeyuki Uehara, Reihaneh Safavi-Naini, Philip Ogunbona |
ICME | 2 |
| 2004 | Weighted Segmented Digital Watermarking
Glen E. Wheeler, Reihaneh Safavi-Naini, Nicholas Paul Sheppard |
IWDW | 2 |
| 2004 | A secure and flexible authentication system for digital images
Takeyuki Uehara, Reihaneh Safavi-Naini, Philip Ogunbona |
Multim. Syst. | 2 |
| 2004 | On the Maximal Codes of Length 3 with the 2-Identifiable Parent PropertyabstractA q-ary code has identifiable parent property (IPP) if it allows one of the parents of a descendant word to be found. A 2-IPP code ensures that at least one parent of a pirate word constructed by a coalition of two users can be found. In this paper, we answer a question raised in [H. D. L. Hollmann et al., J. Combin. Theory Ser. A, 82 (1998), pp. 121--133] and show that F(q), the maximum number of codewords in a 2-IPP code of length 3, satisfies $|{\cal G}_0| \leq F(q) \leq |{\cal G}_0| +2$, where ${\cal G}_0$ is a well-defined graph. We also give an efficient algorithm (O(q 3 )) for finding maximal codes. Vu Dong Tô, Reihaneh Safavi-Naini |
SIAM J. Discret. Math. | 2 |
| 2003 | New traitor tracing schemes using bilinear mapabstractMitsunari et al [15] presented a new traitor tracing scheme which uses Weil pairing in elliptic curves. To the best of our knowledge this is the first scheme that uses bilinear map. The claimed advantage of the scheme is that the ciphertext size is independent of the number of traitors. It is shown that the problem of constructing a pirate key by k colluders is as hard as the so-called k-weak Diffie-Hellman problem.In this paper, we show an attack on this scheme in which traitors find a linear combination of their keys to construct a pirate key that can be used to decrypt the ciphertext. We identify a class of schemes, that includes MSK, with the property that correct tracing requires the ciphertext size to depend on the collusion threshold. We derive a lower bound on the size of the ciphertext that depends on the number of colluders.We propose a modification to MSK scheme, Scheme 1, which not only ensures constructing a pirate decoder is hard, but also has a number of significant advantages over the initial proposal. In particular, it is a public key traitor tracing scheme while the original scheme is a secret key traitor tracing scheme; it has a black box tracing algorithm while MSK scheme only has an open box tracing algorithm, and finally its security is provable (semantic secure against passive adversary) while there was no security proof for MSK.We also propose two other schemes based on bilinear pairing. Scheme~2, is a generic scheme and can be used with any linear error correcting code. Scheme~3 uses Shamir's secret sharing scheme and has the added property that the encrypted message can be targeted to a subset of users. This is by including user revocation property and allowing selected users to be revoked from the original set of users. We also give proof of security, similar to Scheme 1, and also a tracing algorithm for the two schemes. Finally we give an efficiency comparison for the three schemes against the most efficient schemes with similar security and traceability properties and show that all three schemes are the most efficient ones of their kind. Vu Dong Tô, Reihaneh Safavi-Naini, Fangguo Zhang |
Digital Rights Management Workshop | 2 |
| 2003 | Coefficient Selection Methods for Scalable Spread Spectrum Watermarking
Angela Piper, Reihaneh Safavi-Naini, Alfred Mertins |
IWDW | 2 |
| 2003 | Performance Measurement of Watermark Embedding Patterns
Robert Scealy, Reihaneh Safavi-Naini, Nicholas Paul Sheppard |
IWDW | 2 |
| 2003 | Sequential traitor tracingabstractWe consider a new type of traitor tracing scheme, called sequential traitor tracing, that protects against rebroadcasting of decrypted content. Sequential traceability (TA) schemes trace all up to c traitors and remove the shortcomings of dynamic tracing schemes. We give two general constructions and show the relationship between c-TA codes and sequential tracing schemes. Reihaneh Safavi-Naini, Yejing Wang |
IEEE Trans. Inf. Theory | 1 |
| 2003 | Linear authentication codes: bounds and constructionsabstractIn this paper, we consider a new class of unconditionally secure authentication codes, called linear authentication codes (or linear A-codes). We show that a linear A-code can be characterized by a family of subspaces of a vector space over a finite field. We then derive an upper bound on the size of the source space when other parameters of the system, that is, the sizes of the key space and the authenticator space, and the deception probability, are fixed. We give constructions that are asymptotically close to the bound and show applications of these codes in constructing distributed authentication systems. Huaxiong Wang, Chaoping Xing, Reihaneh Safavi-Naini |
IEEE Trans. Inf. Theory | 3 |
| 2002 | A Secure Re-keying Scheme with Key Recovery Property
Hartono Kurnio, Reihaneh Safavi-Naini, Huaxiong Wang |
ACISP | 2 |
| 2002 | Optimal Parallel I/O for Range Queries through Replication
Keith B. Frikken, Mikhail J. Atallah, Sunil Prabhakar 0001, Reihaneh Safavi-Naini |
DEXA | 4 |
| 2001 | On Classifying Conference Key Distribution Protocols
Shahrokh Saeednia, Reihaneh Safavi-Naini, Willy Susilo |
ACISP | 2 |
| 2001 | How to Construct Fail-Stop Confirmer Signature Schemes
Reihaneh Safavi-Naini, Willy Susilo, Huaxiong Wang |
ACISP | 1 |
| 2001 | Broadcast anti-jamming systems
Yvo Desmedt, Reihaneh Safavi-Naini, Huaxiong Wang, Lynn Margaret Batten, Chris Charnes, Josef Pieprzyk |
Comput. Networks | 2 |
| 2001 | Broadcast authentication for group communication
Reihaneh Safavi-Naini, Huaxiong Wang |
Theor. Comput. Sci. | 1 |
| 2001 | New results on frame-proof codes and traceability schemesabstractWe derive lower bounds on the maximum number of codewords in a class of frame-proof codes and traceability schemes, and give constructions for both with more codewords than the best known. Reihaneh Safavi-Naini, Yejing Wang |
IEEE Trans. Inf. Theory | 1 |
| 2000 | Key Management for Secure Multicast with Dynamic Controller
Hartono Kurnio, Reihaneh Safavi-Naini, Willy Susilo, Huaxiong Wang |
ACISP | 2 |
| 2000 | New constructions for multicast re-keying schemes using perfect hash familiesabstractA secure multicast scheme allows a group controller (or a centre) to send messages securely over a multicast channel to a dynamically changing group of users.In this paper we show eÆcient methods of establishing a common key among dynamic subgroups of a multicast group such that collusion of up to w malicious users cannot have information about the established key.W e call this re-keying problem.We proposetwo basic constructions, called AND and OR schemes, for multicast re-keying problem using perfect hash families.We show that one scheme is most eÆcient when the subgroup size is close to the full group, and the other when the subgroup size is very small.Both schemes require O(log n) keys storage for both the group controller and the user, and achieve O(log n) communication complexity in their optimal applications.We further show h o w to improve communication eÆciency of the basic OR scheme using erasure codes.Finally we extend the model of the single controller to dynamic controller in which a n y user of the group can establish a common key with a subgroup of the original group, and give extensions of AND and OR schemes for this case. Reihaneh Safavi-Naini, Huaxiong Wang |
CCS | 1 |
| 2000 | A Combinatorial Approach to Asymmetric Traitor Tracing
Reihaneh Safavi-Naini, Yejing Wang |
COCOON | 1 |
| 2000 | Sequential Traitor Tracing
Reihaneh Safavi-Naini, Yejing Wang |
CRYPTO | 1 |
| 2000 | A New and Efficient Fail-stop Signature SchemeabstractThe security of ordinary digital signature schemes relies on a computational assumption. Fail-stop signature schemes provide security for a sender against a forger with unlimited computational power by enabling the sender to provide a proof of forgery if it occurs. In this paper we give an efficient fail-stop signature scheme that uses two hard problems, discrete logarithm and factorization, as the basis of a receiver's security. We show that the scheme has provable security against adaptively chosen message attack, and is the most efficient scheme with respect to the ratio of the message length to the signature length. The scheme provides an efficient solution to signing messages up to 1881 bits. Willy Susilo, Reihaneh Safavi-Naini, Marc Gysin, Jennifer Seberry |
Comput. J. | 2 |
| 1999 | Changing Thresholds in the Absence of Secure Channels
Keith M. Martin, Josef Pieprzyk, Reihaneh Safavi-Naini, Huaxiong Wang |
ACISP | 3 |
| 1999 | Characterization of Optimal Authentication Codes with Arbitration
Dingyi Pei, Yejing Wang, Reihaneh Safavi-Naini |
ACISP | 4 |
| 1999 | Fail-Stop Threshold Signature Schemes Based on Elliptic Curves
Willy Susilo, Reihaneh Safavi-Naini, Josef Pieprzyk |
ACISP | 2 |
| 1999 | Broadcast Authentication in Group Communication
Reihaneh Safavi-Naini, Huaxiong Wang |
ASIACRYPT | 1 |
| 1999 | A3-Codes under Collusion Attacks
Yejing Wang, Reihaneh Safavi-Naini |
ASIACRYPT | 2 |
| 1999 | Bounds and Techniques for Efficient Redistribution of Secret Shares to New Access StructuresabstractWe consider the problem of redistributing shares in a secret sharing scheme in such a way that shareholders of a scheme with one access structure can transfer information to a new set of shareholders, resulting in a sharing of the old secret among a new access structure. We describe a number of different scenarios and applications within which such a redistribution might be required, give some techniques for conducting a redistribution, and discuss the optimisation of the efficiency of such a process. Keith M. Martin, Reihaneh Safavi-Naini, Huaxiong Wang |
Comput. J. | 2 |
| 1999 | Multireceiver Authentication Codes: Models, Bounds, Constructions, and Extensions
Reihaneh Safavi-Naini, Huaxiong Wang |
Inf. Comput. | 1 |
| 1998 | Secret Sharing in Multilevel and Compartmented Groups
Hossein Ghodosi, Josef Pieprzyk, Reihaneh Safavi-Naini |
ACISP | 3 |
| 1998 | On Construction of Cumulative Secret Sharing Schemes
Hossein Ghodosi, Josef Pieprzyk, Reihaneh Safavi-Naini, Huaxiong Wang |
ACISP | 3 |
| 1998 | Efficient Identity-Based Conference Key Distribution Protocols
Shahrokh Saeednia, Reihaneh Safavi-Naini |
ACISP | 2 |
| 1998 | Bounds and Constructions for A3-code with Multi-senders
Reihaneh Safavi-Naini, Yejing Wang |
ACISP | 1 |
| 1998 | Bounds and Constructions for Multireceiver Authentication Codes
Reihaneh Safavi-Naini, Huaxiong Wang |
ASIACRYPT | 1 |
| 1998 | New Results on Multi-Receiver Authentication Codes
Reihaneh Safavi-Naini, Huaxiong Wang |
EUROCRYPT | 1 |
| 1998 | MRD Hashing
Reihaneh Safavi-Naini, Shahram Bakhtiari, Chris Charnes |
FSE | 1 |
| 1998 | Three Systems for Threshold Generation of Authenticators
Reihaneh Safavi-Naini |
Des. Codes Cryptogr. | 1 |
| 1997 | A Message Authentication Code Based on Latin Squares
Shahram Bakhtiari, Reihaneh Safavi-Naini, Josef Pieprzyk |
ACISP | 2 |
| 1997 | Democratic Key Escrow Scheme
Chor Wah Man, Reihaneh Safavi-Naini |
ACISP | 2 |
| 1997 | Secret sharing in hierarchical groups
Chris Charnes, Keith M. Martin, Josef Pieprzyk, Reihaneh Safavi-Naini |
ICICS | 4 |
| 1997 | Remarks on the multiple assignment secret sharing scheme
Hossein Ghodosi, Josef Pieprzyk, Reihaneh Safavi-Naini |
ICICS | 3 |
| 1997 | Multisender authentication systems with unconditional security
Keith M. Martin, Reihaneh Safavi-Naini |
ICICS | 2 |
| 1997 | A Multi-Level View Model for Secure Object-Oriented Databases
Ahmad Baraani-Dastjerdi, Josef Pieprzyk, Reihaneh Safavi-Naini |
Data Knowl. Eng. | 3 |
| 1996 | On selectable collisionful hash functions
Shahram Bakhtiari, Reihaneh Safavi-Naini, Josef Pieprzyk |
ACISP | 2 |
| 1996 | On password-based authenticated key exchange using collisionful hash functions
Shahram Bakhtiari, Reihaneh Safavi-Naini, Josef Pieprzyk |
ACISP | 2 |
| 1996 | Modeling a multi-level secure object-oriented database using views
Ahmad Baraani-Dastjerdi, Josef Pieprzyk, Reihaneh Safavi-Naini |
ACISP | 3 |
| 1996 | Evidential reasoning in network intrusion detection systems
Mansour Esmaili, Reihaneh Safavi-Naini, Josef Pieprzyk |
ACISP | 2 |
| 1996 | Cryptosystems for hierarchical groups
Hossein Ghodosi, Josef Pieprzyk, Chris Charnes, Reihaneh Safavi-Naini |
ACISP | 4 |
| 1996 | Cryptography based on transcendental numbers
Josef Pieprzyk, Hossein Ghodosi, Chris Charnes, Reihaneh Safavi-Naini |
ACISP | 4 |
| 1996 | Case-Based Reasoning for Intrusion DetectionabstractRecently there has been significant interest in applying artificial intelligence (AI) techniques to the intrusion detection problem. Attempts have been made to develop rule based and model based expert systems for intrusion detection. Although these systems have been useful for detecting intruders, they face difficulties in acquiring and representing the knowledge. We present and describe a case based reasoning approach to intrusion detection which alleviates some of the difficulties of current approaches. Mansour Esmaili, Bala Balachandran, Reihaneh Safavi-Naini, Josef Pieprzyk |
ACSAC | 3 |
| 1996 | Three Systems for Shared Generation of Authenticators
Reihaneh Safavi-Naini |
COCOON | 1 |
| 1996 | Computer Intrusion Detection and Incomplete Information
Mansour Esmaili, Reihaneh Safavi-Naini, Josef Pieprzyk |
IEA/AIE | 2 |
| 1996 | Authentication Codes in Plaintext and Chosen-Content Attacks
Reihaneh Safavi-Naini, Leonid M. Tombak |
Des. Codes Cryptogr. | 1 |
| 1994 | Combinatorial Structure of A-codes with r-fold Security
Reihaneh Safavi-Naini, Leonid M. Tombak |
ASIACRYPT | 1 |
| 1994 | Conditionally Secure Secret Sharing Schemes with Disenrollment CapabilityabstractThe paper describes an implementation of Shamir secret sharing schemes based on exponentiation in Galois fields. It is shown how to generate shares so the scheme has the disenrollment capability. Next a family of conditionally secure Shamir schemes is defined and the disenrollment capability is investigated for the family. The paper also examines a problem of covert channels which are present in any secret sharing scheme. Chris Charnes, Josef Pieprzyk, Reihaneh Safavi-Naini |
CCS | 3 |
| 1994 | Authentication Codes That Are r-Fold Secure Against SpoofingabstractIn this paper we study authentication codes (A-codes) that are r-fold secure against spoofing. We obtain necessary and sufficient conditions for such codes and give a characterization of codes with a minimum number of encoding rules. We will show that if the source is uniform, A-codes that provide perfect protection against spoofing attack of order r are r-fold secure. Leonid M. Tombak, Reihaneh Safavi-Naini |
CCS | 2 |
| 1994 | Automated Cryptanalysis of Transposition CiphersabstractIn this paper we use simulated annealing for automatic cryptanalysis of transposition ciphers. Transposition ciphers are a class of ciphers that in conjunction with substitution ciphers form the basis of all modern symmetric algorithms. In transposition ciphers, a plaintext block is encrypted into a ciphertext block using a fixed permutation. We formulate cryptanalysis of the transposition cipher as a combinatorial optimization problem, and use simulated annealing to find the global minimum of a cost function which is a distance measure between a possible decipherment of the given ciphertext and a sample of plaintext language. The success of the algorithm depends on the ratio of the length of ciphertext to the size of the block. For lower ratios there are cases that the plaintext cannot be correctly found. This is the expected behaviour of all cryptanalysis methods. However, in this case, examining the output of the algorithm provides valuable ‘clues’ for guiding the cryptanalysis. In summary, simulated annealing greatly facilities cryptanalysis of transposition ciphers and provides a potentially powerful method for analyzing more sophisticated ciphers. Jonathan Giddy, Reihaneh Safavi-Naini |
Comput. J. | 2 |
| 1992 | Partial Belief and Probabilistic Reasoning in the Analysis of Secure ProtocolsabstractThe authors propose an extension of the BAN logic to reason about a secure protocol in a hostile and/or unknown environment. Probabilities, attached to the sentences and rules of the logic, allow them to quantify the beliefs of principals and represent the insecurities and uncertainties of a real life situation. They develop a probabilistic logic and obtain tight lower bounds on the probability of the conclusion which correspond to the minimum trust that can be put on the goal of the protocol. This gives them a powerful tool to model and study the performance of secure protocols. They discuss a probabilistic semantic for BAN logic and apply the results to the Needham-Schroeder protocol. The paper concludes by discussing the merits of these results and mentioning some open problems.> E. A. Campbell, Reihaneh Safavi-Naini, P. A. Pleasants |
CSFW | 2 |
| 1991 | Feistel Type Authentication Codes
Reihaneh Safavi-Naini |
ASIACRYPT | 1 |
| 1991 | Error-correcting codes for authentication and subliminal channelsabstractThe application of coding theory to security scenarios is studied. Authentication systems are introduced that are based on algebraic codes and provide high protection against an intruder's impersonation and substitution attacks. It is shown that a subliminal channel can be embedded into these systems and that there is a trade-off between the authentication capability, subliminal capacity, and error protection capability.> Reihaneh Safavi-Naini, Jennifer Seberry |
IEEE Trans. Inf. Theory | 1 |
| 1979 | Generalized t-Designs and Weighted Majority Decoding
Reihaneh Safavi-Naini, Ian F. Blake |
Inf. Control. | 1 |