David Wolinsky

dblp:13/5827 · also David Isaac Wolinsky · DBLP profile ↗
← Back
26ranked-venue papers
7as first author
0since 2021 · last 2016
0000-0002-6321-7333ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 10 · 3 first-authorSecurity and privacy · 6 · 1 first-authorComputer networks · 4 · 1 first-authorHuman-computer interaction and ubiquitous computing · 4 · 1 first-authorSoftware engineering, systems software and programming languages · 2 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
5 papers
Network security · 47% Privacy and data protection · 28% Cryptographic primitives and cryptanalysis · 13%
Computer architecture, parallel and distributed computing, and storage systems
7 papers
Distributed systems · 66% Hardware reliability and fault tolerance · 13% Cloud and datacenter computing · 12%

Topics — the 23 heaviest of 26, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Network security
anonymity networks
0.532013
Proactively Accountable Anonymous Messaging in Verdict · USENIX Security Symposium 2013
Hang with your buddies to resist intersection attacks · CCS 2013
Dissent in Numbers: Making Strong Anonymity Scale · OSDI 2012
Privacy and data protection
anonymity
0.212016
AnonRep: Towards Tracking-Resistant Anonymous Reputation · NSDI 2016
Privacy and data protection › anonymity
anonymous reputation
0.212016
AnonRep: Towards Tracking-Resistant Anonymous Reputation · NSDI 2016
Cryptographic primitives and cryptanalysis › public-key cryptography
digital signatures
0.212016
Keeping Authorities "Honest or Bust" with Decentralized Witness Cosigning · IEEE Symposium on Security and Privacy 2016
Cryptographic protocols and secure computation › authenticated data structure
transparency log
0.212016
Keeping Authorities "Honest or Bust" with Decentralized Witness Cosigning · IEEE Symposium on Security and Privacy 2016
Hardware reliability and fault tolerance › reliability analysis
correlated failures
0.212014
Heading Off Correlated Failures through Independence-as-a-Service · OSDI 2014
Distributed systems
fault tolerance
0.212014
Heading Off Correlated Failures through Independence-as-a-Service · OSDI 2014
Network security › anonymity networks › anonymous communication
anonymous messaging
0.212013
Proactively Accountable Anonymous Messaging in Verdict · USENIX Security Symposium 2013
Network security
traffic analysis
0.212013
Hang with your buddies to resist intersection attacks · CCS 2013
Distributed systems › peer-to-peer systems
overlay networks
0.222008
Improving peer connectivity in wide-area overlays of virtual workstations · HPDC 2008
Facilitating the deployment of ad-hoc virtual organizations with integrated social and overlay networks · HPDC 2008
High-performance computing
high-throughput computing
0.112012
PonD: dynamic creation of HTC pool on demand using a decentralized resource discovery system · HPDC 2012
Distributed systems › distributed resource management
resource discovery
0.112012
PonD: dynamic creation of HTC pool on demand using a decentralized resource discovery system · HPDC 2012
Cloud and datacenter computing › cloud service models
infrastructure as a service
0.112011
Experiences with self-organizing, decentralized grids using the grid appliance · HPDC 2011
Distributed systems
distributed coordination
0.112009
On the design of scalable, self-configuring virtual networks · SC 2009
Distributed systems
peer-to-peer systems
0.112009
On the design of scalable, self-configuring virtual networks · SC 2009
Distributed systems › distributed system architecture › communication architecture
virtual networks
0.112009
On the design of scalable, self-configuring virtual networks · SC 2009
Distributed systems › grid computing
virtual organizations
0.112008
Facilitating the deployment of ad-hoc virtual organizations with integrated social and overlay networks · HPDC 2008
Distributed systems › consensus
scalable consensus
0.112016
Keeping Authorities "Honest or Bust" with Decentralized Witness Cosigning · IEEE Symposium on Security and Privacy 2016
Privacy and data protection
pseudonymity
0.012013
Hang with your buddies to resist intersection attacks · CCS 2013
Network security › anonymity networks
anonymous communication
0.012012
Dissent in Numbers: Making Strong Anonymity Scale · OSDI 2012
Distributed systems
grid computing
0.012011
Experiences with self-organizing, decentralized grids using the grid appliance · HPDC 2011
Internet architecture and protocols › naming and addressing
IP address management
0.012009
On the design of scalable, self-configuring virtual networks · SC 2009
Internet architecture and protocols › middlebox
network address translation
0.012008
Improving peer connectivity in wide-area overlays of virtual workstations · HPDC 2008

Methods — techniques the papers use, named apart from their topics

signature aggregation · 0.5multisignature aggregation · 0.5cryptographic protocols · 0.2p2p overlay routing · 0.2distributed data store · 0.2trace-based simulation · 0.2cryptographic protocol design · 0.2peer-to-peer overlay · 0.1match-making · 0.1resource provisioning · 0.1decentralized deployment · 0.1structured p2p routing · 0.1social network integration · 0.1overlay networking · 0.1hole punching · 0.1
YearPublicationVenuePosition
2016 Building Privacy-Preserving Cryptographic Credentials from Federated Online Identities
abstract
Federated identity providers, e.g., Facebook and PayPal, offer a convenient means for authenticating users to third-party applications. Unfortunately such cross-site authentications carry privacy and tracking risks. For example, federated identity providers can learn what applications users are accessing; meanwhile, the applications can know the users' identities in reality.
John Maheswaran, Daniel Jackowitz, Ennan Zhai, David Wolinsky, Bryan Ford
CODASPY4
2016 AnonRep: Towards Tracking-Resistant Anonymous Reputation
Ennan Zhai, David Wolinsky, Ruichuan Chen, Ewa Syta, Chao Teng, Bryan Ford
NSDI2
2016 Keeping Authorities "Honest or Bust" with Decentralized Witness Cosigning
abstract
The secret keys of critical network authorities -- such as time, name, certificate, and software update services -- represent high-value targets for hackers, criminals, and spy agencies wishing to use these keys secretly to compromise other hosts. To protect authorities and their clients proactively from undetected exploits and misuse, we introduce CoSi, a scalable witness cosigning protocol ensuring that every authoritative statement is validated and publicly logged by a diverse group of witnesses before any client will accept it. A statement S collectively signed by W witnesses assures clients that S has been seen, and not immediately found erroneous, by those W observers. Even if S is compromised in a fashion not readily detectable by the witnesses, CoSi still guarantees S's exposure to public scrutiny, forcing secrecy-minded attackers to risk that the compromise will soon be detected by one of the W witnesses. Because clients can verify collective signatures efficiently without communication, CoSi protects clients' privacy, and offers the first transparency mechanism effective against persistent man-in-the-middle attackers who control a victim's Internet access, the authority's secret key, and several witnesses' secret keys. CoSi builds on existing cryptographic multisignature methods, scaling them to support thousands of witnesses via signature aggregation over efficient communication trees. A working prototype demonstrates CoSi in the context of timestamping and logging authorities, enabling groups of over 8,000 distributed witnesses to cosign authoritative statements in under two seconds.
Ewa Syta, Iulia Tamas, Dylan Visher, David Wolinsky, Philipp Jovanovic, Linus Gasser, Nicolas Gailly, Ismail Khoffi, Bryan Ford
IEEE Symposium on Security and Privacy4
2015 Private Eyes: Secure Remote Biometric Authentication
abstract
We propose an efficient remote biometric authentication protocol that gives strong protection to the user’s biometric data in case of two common kinds of security breaches: (1) loss or theft of the user’s token (smart card, handheld device, etc.), giving the attacker full access to any secrets embedded within it; (2) total penetration of the server. Only if both client and server are simultaneously compromised is the user’s biometric data vulnerable to exposure. The protocol works by encrypting the user’s biometric template in a way that allows it to be used for authentication without being decrypted by either token or server. Further, the encrypted template never leaves the token, and only the server has the information that would enable it to be decrypted. We have implemented our protocol using two iris recognition libraries and evaluated its performance. The overall efficiency and recognition performance is essentially the same compared to an unprotected biometric system.
Ewa Syta, Michael J. Fischer, David Wolinsky, Avi Silberschatz, Gina Gallegos-García, Bryan Ford
SECRYPT3
2014 Heading Off Correlated Failures through Independence-as-a-Service
Ennan Zhai, Ruichuan Chen, David Wolinsky, Bryan Ford
OSDI3
2014 Security Analysis of Accountable Anonymity in Dissent
abstract
Users often wish to communicate anonymously on the Internet, for example, in group discussion or instant messaging forums. Existing solutions are vulnerable to misbehaving users, however, who may abuse their anonymity to disrupt communication. Dining Cryptographers Networks (DC-nets) leave groups vulnerable to denial-of-service and Sybil attacks; mix networks are difficult to protect against traffic analysis; and accountable voting schemes are unsuited to general anonymous messaging. dissent is the first general protocol offering provable anonymity and accountability for moderate-size groups, while efficiently handling unbalanced communication demands among users. We present an improved and hardened dissent protocol, define its precise security properties, and offer rigorous proofs of these properties. The improved protocol systematically addresses the delicate balance between provably hiding the identities of well-behaved users, while provably revealing the identities of disruptive users, a challenging task because many forms of misbehavior are inherently undetectable. The new protocol also addresses several nontrivial attacks on the original dissent protocol stemming from subtle design flaws.
Ewa Syta, Henry Corrigan-Gibbs, Shu-Chun Weng, David Wolinsky, Bryan Ford, Aaron Johnson 0001
ACM Trans. Inf. Syst. Secur.4
2013 Hang with your buddies to resist intersection attacks
abstract
Some anonymity schemes might in principle protect users from pervasive network surveillance--but only if all messages are independent and unlinkable. Users in practice often need pseudonymity--sending messages intentionally linkable to each other but not to the sender--but pseudonymity in dynamic networks exposes users to intersection attacks. We present Buddies, the first systematic design for intersection attack resistance in practical anonymity systems. Buddies groups users dynamically into buddy sets, controlling message transmission to make buddies within a set behaviorally indistinguishable under traffic analysis. To manage the inevitable tradeoffs between anonymity guarantees and communication responsiveness, Buddies enables users to select independent attack mitigation policies for each pseudonym. Using trace-based simulations and a working prototype, we find that Buddies can guarantee non-trivial anonymity set sizes in realistic chat/microblogging scenarios, for both short-lived and long-lived pseudonyms.
David Wolinsky, Ewa Syta, Bryan Ford
CCS1
2013 Crypto-Book: an architecture for privacy preserving online identities
abstract
Through cross-site authentication schemes such as OAuth and OpenID, users increasingly rely on popular social networking sites for their digital identities--but use of these identities brings privacy and tracking risks. We propose Crypto-Book, an extension to existing digital identity infrastructures that offers privacy-preserving, digital identities through the use of public key cryptography and ring signatures. Crypto-Book builds a privacy-preserving cryptographic layer atop existing social network identities, via third-party key servers that convert social network identities into public/private key-pairs on demand. Using linkable ring signatures, these key-pairs along with the public keys of other identities create unique pseudonyms untraceable back to the owner yet can resist anonymous abuse.
John Maheswaran, David Wolinsky, Bryan Ford
HotNets2
2013 Proactively Accountable Anonymous Messaging in Verdict
Henry Corrigan-Gibbs, David Wolinsky, Bryan Ford
USENIX Security Symposium2
2012 PonD: dynamic creation of HTC pool on demand using a decentralized resource discovery system
abstract
High Throughput Computing (HTC) platforms aggregate heterogeneous resources to provide vast amounts of computing power over a long period of time. Typical HTC systems, such as Condor and BOINC, rely on central managers for resource discovery and scheduling. While this approach simplifies deployment, it requires careful system configuration and management to ensure high availability and scalability. In this paper, we present a novel approach that integrates a self-organizing P2P overlay for scalable and timely discovery of resources with unmodified client/server job scheduling middleware in order to create HTC virtual resource Pools on Demand (PonD). This approach decouples resource discovery and scheduling from job execution/monitoring - a job submission dynamically generates an HTC platform based upon resources discovered through match-making from a large "sea" of resources in the P2P overlay and forms a "PonD" capable of leveraging unmodified HTC middleware for job execution and monitoring. We show that job scheduling time of our approach scales with O(log N), where N is the number of resources in a pool, through first-order analytical models and large-scale simulation results. To verify the practicality of PonD, we have implemented a prototype using Condor (called C-PonD), a structured P2P overlay, and a PonD creation module. Experimental results with the prototype in two WAN environments (PlanetLab and the FutureGrid cloud computing testbed) demonstrates the utility of C-PonD as a HTC approach without relying on a central repository for maintaining all resource information. Though the prototype is based on Condor, the decoupled nature of the system components - decentralized resource discovery, PonD creation, job execution/monitoring - is generally applicable to other grid computing middleware systems.
Kyungyong Lee 0001, David Wolinsky, Renato J. O. Figueiredo
HPDC2
2012 Dissent in Numbers: Making Strong Anonymity Scale
David Wolinsky, Henry Corrigan-Gibbs, Bryan Ford, Aaron Johnson 0001
OSDI1
2011 SOLARE: Self-Organizing Latency-Aware Resource Ensemble
abstract
This paper proposes and evaluates Self-Organizing Latency-Aware Resource Ensemble (SOLARE), a peer-to-peer self-organizing and self-managing cluster system based upon network coordinates and utility functions. In contrast to previous works, SOLARE is a fully decentralized clustering algorithm without any central units such as servers, super peers, cluster heads or landmarks. Furthermore, SOLARE allows for adaptability to dynamic network changes by monitoring the utility of a cluster and migrating nodes to other higher-utility clusters when the utility of an existing cluster is low. Quantitative, simulation-driven evaluations show that SOLARE is able to satisfy user demands expressed by utility functions that integrate system parameters in terms of intra cluster latencies and the number of cluster members. Also, we verify the ability of SOLARE to adapt to dynamic network changes through simulation based experiments that consider the number of nodes which migrate into another cluster and average utility value as nodes join SOLARE.
Heungsik Eom, David Wolinsky, Renato J. O. Figueiredo
HPCC2
2011 Experiences with self-organizing, decentralized grids using the grid appliance
abstract
"Give a man a fish, feed him for a day. Teach a man to fish, feed him for a lifetime" -- Lau Tzu Large-scale grid computing projects such as TeraGrid and Open Science Grid provide researchers vast amounts of compute resources but with requirements that could limit access, results delayed due to potentially long job queues, and environments and policies that might affect a user's work flow. In many scenarios and in particular with the advent of Infrastructure-as-a-Service (IaaS) cloud computing, individual users and communities can benefit from less restrictive, dynamic systems that include a combination of local resources and on-demand resources provisioned by one or more IaaS provider. These types of scenarios benefit from flexibility in deploying resources, remote access, and environment configuration.
David Wolinsky, Renato J. O. Figueiredo
HPDC1
2010 SocialDNS: A decentralized naming service for collaborative P2P VPNs
abstract
The ability to define domain names for resources in a collaborative virtual organization is usually reserved to network administrators through centralized domain name servers. We propose SocialDNS, a decentralized, naming service that gives individual collaborators the power to choose the domain nam
Pierre St. Juste, David Wolinsky, Kyungyong Lee 0001, P. Oscar Boykin, Renato J. O. Figueiredo
CollaborateCom2
2010 On the design of autonomic, decentralized VPNs
abstract
Decentralized and P2P (peer-to-peer) VPNs (virtual private networks) have recently become quite popular for connecting users in small to medium collaborative environments, such as academia, businesses, and homes. In the realm of VPNs, there exist centralized, decentralized, and P2P solutions. Centra
David Wolinsky, Kyungyong Lee 0001, P. Oscar Boykin, Renato J. O. Figueiredo
CollaborateCom1
2010 Towards Collaborative Research and Education in Computer Architecture with the Archer System
abstract
Archer is a simulation environment and computing resource for research in the field of computer architecture. Archer facilitates the creation of an on-demand computing grid, the deployment of simulation tools on this grid and the batch scheduling of large-scale simulation jobs on this grid. These features enable the use of Archer for simulation-based research as well as dissemination of tools and results among multiple research groups. This paper overviews and reports our experience in the use of Archer for collaborative research and for education.
Girish Venkatasubramanian, David Wolinsky, Renato J. O. Figueiredo
MASCOTS2
2010 Addressing the P2P Bootstrap Problem for Small Overlay Networks
abstract
Peer-to-Peer (P2P) overlays provide a framework for building distributed applications consisting of few to many resources with features including self-configuration, scalability, and resilience to node failures. Such systems have been successfully adopted in large-scale Internet services for content delivery networks, file sharing, and data storage. In small-scale systems, they can be useful to address privacy concerns as well as support for network applications that lack dedicated servers. The bootstrap problem, finding an existing peer in the overlay, remains a challenge to enabling these services for small-scale P2P systems. In large networks, the solution to the bootstrap problem has been the use of dedicated services, though creating and maintaining these systems requires expertise and resources, which constrain their usefulness and make them unappealing for small-scale systems. This paper surveys and summarizes requirements that allow peers potentially constrained by network connectivity to bootstrap small-scale overlays through the use of existing public overlays. In order to support bootstrapping, a public overlay must support the following requirements: a method for reflection in order to obtain publicly reachable addresses, so peers behind network address translators and firewalls can receive incoming connection requests; communication relaying to share public addresses and communicate when direct communication is not feasible; and rendezvous for discovering remote peers, when the overlay lacks stable membership. After presenting a survey of various public overlays, we identify two overlays that match the requirements: XMPP overlays, such as Google Talk and Live Journal Talk, and Brunet, a structured overlay based upon Symphony. We present qualitative experiences with prototypes that demonstrate the ability to bootstrap small-scale private structured overlays from public Brunet or XMPP infrastructures.
David Wolinsky, Pierre St. Juste, P. Oscar Boykin, Renato J. O. Figueiredo
Peer-to-Peer Computing1
2010 SocialVPN: Enabling wide-area collaboration with integrated social and overlay networks
Pierre St. Juste, David Wolinsky, P. Oscar Boykin, Michael J. Covington, Renato J. O. Figueiredo
Comput. Networks2
2009 On the design of scalable, self-configuring virtual networks
abstract
Virtual networks (VNs) provide methods that simplify resource management, deal with connectivity constraints, and support legacy applications in distributed systems, by enabling global addressability of VN-connected machines through either a common layer 2 Ethernet or a NAT-free layer 3 IP network. This paper presents a novel VN design that supports dynamic, seamless addition of new resources with emphasis on scalability in a unified private IP address space. Key features of this system are: (1) Scalable connectivity via a P2P overlay with the ability to bypass overlay routing in LAN communications, (2) support for static and dynamic address allocation in conjunction with virtual nameservers through a distributed data store, and (3) support for transparent migration of IP endpoints across widearea networks.
David Wolinsky, Yonggang Liu 0004, Pierre St. Juste, Girish Venkatasubramanian, Renato J. O. Figueiredo
SC1
2008 Archer: A Community Distributed Computing Infrastructure for Computer Architecture Research and Education
Renato J. O. Figueiredo, P. Oscar Boykin, José A. B. Fortes, Tao Li 0006, Jie-Kwon Peir, David Wolinsky, Lizy Kurian John, David R. Kaeli, David J. Lilja, Sally A. McKee, Gokhan Memik, Alain J. Roy, Gary S. Tyson
CollaborateCom6
2008 Middleware Integration and Deployment Strategies for Cyberinfrastructures
Sebastien Goasguen, Krishna Madhavan, David Wolinsky, Renato J. O. Figueiredo, Jaime Frey, Alain J. Roy, Paul Ruth, Dongyan Xu
GPC3
2008 Facilitating the deployment of ad-hoc virtual organizations with integrated social and overlay networks
abstract
Deploying virtual organizations (VOs) is difficult for small- and medium-scale collaborations: the overheads in establishing and managing trust, and in deploying and managing computational resources distributed across multiple organizations are daunting to many potential users, presenting a barrier to entry that significantly hinders wider deployment of VOs. We advocate an approach where social networking and self-configuring overlay virtual networks are integrated in a novel way that allows simple deployment and management of ad-hoc infrastructures for VOs. There are three central principles in our approach: (1) user relationships which have been increasingly recorded in social networking systems provide the opportunity to bootstrap trust relationships; (2) connections established at a social networking layer can efficiently be mapped to the IP layer of virtual network overlays to support existing TCP/IP applications for collaboration and resource sharing while maintaining security against untrusted parties; and (3) systems integrating social and virtual networks can be self-configuring, enabling deployment of collaborative infrastructures by non-experts. We discuss motivations for this approach, describe a prototype implementation which integrates the Facebook social network and the IPOP overlay network, and discuss a use case scenario towards ad-hoc social cycle-sharing virtual Condor pools.
Renato J. O. Figueiredo, P. Oscar Boykin, Pierre St. Juste, David Wolinsky
HPDC4
2008 Improving peer connectivity in wide-area overlays of virtual workstations
abstract
Self-configuring virtual networks rely on structured P2P routing to provide seamless connectivity among nodes through overlay routing of virtual IP packets, support decentralized hole-punching to establish bi-directional communication links among nodes behind network address translators, and dynamic configuration of virtual IP addresses. Our experiences with deployments of virtual networks in support of wide-area overlays of virtual workstations (WOWs) reveal that connectivity constraints imposed by symmetric NATs and by Internet route outages often hinder P2P overlay structure maintenance and routability, subsequently limiting the ability of WOWs to deliver high-throughput computing through aggregation of resources in different domains.
Arijit Ganguly, P. Oscar Boykin, David Wolinsky, Renato J. O. Figueiredo
HPDC3
2008 Provisioning of virtual environments for wide area desktop grids through redirect-on-write distributed file system
abstract
We describe and evaluate a thin client solution for desktop grid computing based on virtual machine appliances whose images are fetched on-demand and on a per-block basis over wide-area networks. The approach uses a distributed file system redirection mechanism which enables the use of unmodified NFS clients/servers and local buffering of file system modifications during the appliances lifetime. The file system redirection technique is achieved through user-level proxies, and can be integrated with virtual private network overlays to provide transparent access to image servers even if they are behind firewalls. We have implemented and evaluated a prototype system which allows thin client diskless appliances to boot over a proxy VM bringing on-demand only a small fraction of the appliance image (16 MB out of WOMB) and showing low runtime overhead for CPU-intensive applications. The paper also presents decentralized mechanisms to support seamless image version upgrades.
Vineet Chadha, David Wolinsky, Renato J. O. Figueiredo
IPDPS2
2008 Simplifying resource sharing in voluntary grid computing with the grid appliance
abstract
Research projects in many fields are increasingly reliant on the use of computer-based simulation and computing grids. Many projects have successfully leveraged voluntary computing infrastructures by developing and distributing "@home" applications using the BOINC framework. Through generous contributions from the general public, these systems now have a computing backbone on which to have their data processed or simulations run. A shortcoming of such systems is that most users are often limited to contributing resources and few users are capable of developing or porting their own applications in order to use these resources. While many users are satisfied with receiving points (an intangible good) in return for their contribution, the need to port applications presents a barrier to entry to many other users who can potentially benefit from using the voluntary resources. In this paper, we describe enhancements made to the "grid appliance", a virtual machine based system which enables an execution environment in which users are given the opportunity to voluntarily share (providing and using) resources and run unmodified x86/Linux applications. Voluntary grids introduce a host of issues to tackle, most importantly getting users involved quickly. With that in mind, the grid appliance provides many tools for making a user-friendly environment for users, developers, and administrators. This paper summarizes the challenges of getting users involved, reducing the overhead for administrators, and describes the solutions used in the grid appliance.
David Wolinsky, Renato J. O. Figueiredo
IPDPS1
2007 Decentralized Dynamic Host Configuration in Wide-Area Overlays of Virtual Workstations
abstract
Wide-area overlays of virtual workstations (WOWs) have been shown to provide excellent infrastructure for deploying high throughput computing environments on commodity desktop machines by (1) offering scalability to a large number of nodes, (2) facilitating addition of new nodes even if they are behind NATs/firewalls and (3) supporting unmodified applications and middleware. However, deployment of WOWs from scratch still requires setting up a bootstrapping network and managing centralized DHCP servers for IP address management. In this paper we describe novel techniques that allow multiple users to create independent, isolated virtual IP namespaces for their WOWs without requiring a dedicated bootstrapping infrastructure, and to provision dynamic host configuration (e.g. IP addresses) to unmodified DHCP clients without requiring the setup and management of a central DHCP server. We give qualitative and quantitative arguments to establish the feasibility of our approach.
Arijit Ganguly, David Wolinsky, P. Oscar Boykin, Renato J. O. Figueiredo
IPDPS2