EDBT 2026 Demo / reviewers in the wild / expert
Riham AlTawy
dblp:132/0842
· DBLP profile ↗
33ranked-venue papers
12as first author
19since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 19 · 6 first-author · 11 since 2021Computer networks · 8 · 1 first-author · 7 since 2021Systems, architecture and hardware · 2 · 2 first-authorDatabases, data management, data science and information retrieval · 2 · 2 first-authorTheory of computation · 2 · 2 first-authorApplied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Mercurial-Based Secure Authentication and Reputation Framework for the Multi-Context MetaverseabstractThe metaverse transforms how individuals interact, work, and engage in virtual environments, creating new opportunities in gaming, education, e-commerce, and social networking. At the core of this experience are avatars (i.e., digital representations of users that serve as their proxies in virtual spaces). Ensuring secure and privacy-preserving communication between avatars presents critical challenges, particularly in protecting metaverse user privacy by preventing the linking of avatars to users' social and professional lives. Adopting anonymous schemes such as ring signature schemes requires access to all public keys within the anonymity set, which is impractical in the metaverse. In this paper, we proposeSPARTA(Secure andPrivacy-preserving protocol withRole separation andTrustworthiness forAvatars in the metaverse), a protocol that enables avatar authentication and maintains avatar unlinkability. By leveraging mercurial signatures, our approach allows metaverse users to generate multiple unlinkable avatars without requiring repeated registration with the metaverse service provider, thereby enabling seamless role separation. Additionally, by using a time-based hash chain, only avatars in possession of a reputation token from the time-based hash chain can submit their feedback on a smart contract based on their interactions. Given the soundness property of zero-knowledge proof and the origin-hiding property of mercurial signatures, we formally prove that${\sf SPARTA}$achieves mutual authentication, avatar unlinkability, and penalization enforcement. Additionally, we analyze the performance overheads introduced by its cryptographic primitives and compare${\sf SPARTA}$with existing metaverse authentication protocols. Furthermore, we implement the protocol using socket programming. This implementation simulates real-time message exchanges between protocol entities, resulting in an end-to-end latency of 105 ms. Compared to existing metaverse authentication frameworks,${\sf SPARTA}$provides unlinkable avatar authentication that achieves mutual authentication, role separation, and data sovereignty without reliance on an online trusted third party. The concurrent implementation between two Raspberry Pi devices demonstrates the scalability of${\sf SPARTA}$, achieving a total completion time of 17.338 seconds for 1000 concurrent authentications, corresponding to a throughput of approximately 57.7 authentications per second, confirming its practicality for large-scale metaverse environments. Mohamed Seifelnasr, Mohamed Mobarak, Riham AlTawy, Amr M. Youssef |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | Efficient Dynamic Group Signatures with Forward Security
Amin Mohammadali, Riham AlTawy |
ISC | 2 |
| 2025 | Privacy-Preserving Interdomain Authorization and Authentication for Internet of ThingsabstractCollaboration among various Internet of Things (IoT) application service providers has the potential to improve service quality and productivity. However, challenges arise from the complexity of interoperability, particularly in Authorization and Authentication (A&A) for devices across different domains. This paper presents a scheme designed to facilitate interdomain A&A. The proposed approach uses the BBS group signature scheme to ensure anonymous authentication between domains and introduces a privacy-preserving authorization scheme that enables domain managers to grant permissions to authenticated domains for accessing their devices. The proposed A&A does not require an online trusted third party and supports a two-level revocation mechanism: a domain can be revoked from the entire system and no longer authenticated, or an authorizing domain can revoke its permission for another domain, preventing further communication between them. Additionally, a tracing mechanism is developed, leveraging a threshold-based cryptosystem, to reveal the identity of anonymized malicious devices while preventing unauthorized tracing by a single authority. The proposed protocol ensures strong exculpability, guaranteeing that no entity, including trusted entities, can impersonate a domain server. We formally analyze the security of the proposed authorization scheme and report on the protocol’s computational and communication overheads. Finally, the proposed A&A is compared to related protocols in terms of efficiency and security guarantees. Amin Mohammadali, Riham AlTawy, Amr M. Youssef |
IEEE Internet Things J. | 2 |
| 2025 | Privacy-Preserving Authentication for Unlinkable Avatars in the MetaverseabstractThe metaverse is a virtual world that mirrors real life, allowing users to engage in activities and access services without the constraints of time and space. In the metaverse, users can create one or more avatars that reflect their personal preferences, enabling them to participate in activities that match their tastes and needs. To protect users’ freedom and anonymity, it is imperative for metaverse platforms to support the creation ofunlinkableavatars. This ensures that the different avatars a user creates cannot be connected, keeping their virtual identities separate and reducing the risk of retaliation for their actions. In this paper, we propose an unlinkable avatar authentication scheme, UAVA, which leverages cryptographic group signatures to enable metaverse users to create and certify their avatars without interaction with service providers. These certified avatars can then be anonymously authenticated, ensuring unlinkability between multiple avatars belonging to the same user. UAVA maintains anonymity between users and their avatars, while allowing service providers to trace malicious avatars back to their users. We formally define and prove the security properties of UAVA, and implement the protocol using socket programming, and report on its cryptographic overheads. We also evaluate its cryptographic overhead and compare it to related protocols in terms of efficiency, security, and scalability. Mohamed Mobarak, Riham AlTawy, Amr M. Youssef |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | A Conditional Privacy-Preserving Protocol for Cross-Domain Communications in VANETabstractVehicular Ad Hoc Networks (VANETs) empower vehicles equipped with onboard units to exchange traffic-related messages, enhancing vehicle navigation safety and efficiency. Providing secure privacy-preserving authentication schemes for VANETs is indispensable. It ensures that only legitimate vehicles can communicate, preventing external adversaries from injecting falsifiable information that could mislead vehicles, cause accidents, or disrupt traffic flow. Simultaneously, the privacy-preserving features prevent curious adversaries from compromising vehicle privacy and tracking users. Secure centralized vehicular communication protocols, where a single entity issues certificates for all vehicles, face challenges in enabling cross-domain communications. Adoption of such centralized protocols necessitates that vehicles within each domain possess their certificate authority, restricting cross-domain communication due to inherent distrust in the certificate authorities of other domains. In this paper, we propose a Conditional Privacy-preserving Message Authentication protocol for VANET Emergency message exchange (CP-MAVE), designed to ensure message authentication, integrity, and anonymity of vehicles across different domains. In the event of misbehavior, distributed key generation centers collaborate to trace back the identity of the vehicle. To evaluate the security of our protocol, we formally prove the existential unforgeability of CP-MAVE against chosen message attacks based on the intractability of the elliptic curve discrete logarithm problem. Additionally, we demonstrate that CP-MAVE achieves message authentication, conditional privacy preservation, and resilience against replay and modification attacks. Moreover, we model and analayze CP-MAVE using the Tamarin prover and show that CP-MAVE maintains the secrecy and the message authentication of the vehicle traffic messages. Furthermore, we evaluate CP-MAVE’s performance regarding communication overhead and computation complexity. On a Raspberry Pi 4 Model B/8GB, equipped with a 1.5 GHz 64-bit Quad-core ARM Cortex-A72 processor, CP-MAVE requires a 304-byte communication overhead and 9.4897 msec as cryptographic operation overhead. Finally, to simulate the flow of messages between entities in our protocol, we implement CP-MAVE using socket programming, resulting in an end-to-end delay of 111.05 msec. Mohamed Seifelnasr, Riham AlTawy, Amr M. Youssef |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2024 | Extended Policy-Based Sanitizable Signatures
Ismail Afia, Riham AlTawy |
Inscrypt (2) | 2 |
| 2024 | SKAFS: Symmetric Key Authentication Protocol With Forward Secrecy for Edge ComputingabstractThe IoT-edge-cloud paradigm enables resource-constrained IoT devices to offload their computation, thereby meeting the required quality-of-service for real-time applications. However, the deployment of IoT devices in public places, such as smart cities, exposes them to various security threats, including physical attacks. To address these security concerns, we propose a physical unclonable function (PUF)-based IoT-edge-cloud symmetric key authentication protocol with forward secrecy (SKAFS), which ensures the anonymity of transacting IoT devices, resilience to desynchronization-based denial-of-service attacks, and PUF modeling attacks. To evaluate the security of our protocol, we conduct a formal security analysis using the automated AVISPA tool. In addition, based on the indistinguishability property of the PUF, we formally prove that SKAFS is secure under the Canetti-Krawczyk-adversary model. Moreover, we implement the protocol using socket programming between a Raspberry Pi 1 as an IoT device, a Raspberry Pi 4 as an IoT gateway, and an 11th Gen Intel Core i7–11800H laptop as the cloud admin to simulate the message flow between the protocol entities in a real-time experiment and calculate its end-to-end latency. Finally, we compare SKAFS with other PUF-based protocols in terms of computation time, communication cost, and storage requirements. Mohamed Seifelnasr, Riham AlTawy, Amr M. Youssef |
IEEE Internet Things J. | 2 |
| 2024 | Privacy-Preserving Mutual Authentication Protocol With Forward Secrecy for IoT-Edge-CloudabstractThe three-tier IoT–Edge–Cloud paradigm enables low-end devices to use the computation capabilities of the more powerful edge nodes to meet efficiency constraints for real-time applications. Many symmetric-key-based schemes rely on an online trusted cloud admin (CA) to establish session keys between IoT devices and edge nodes. In this study, we propose a new provably-secure mutual authentication privacy-preserving protocol with forward secrecy (MAPFS), which eliminates the requirement for an online CA during IoT authentication. To achieve anonymity, our construction utilizes zero-knowledge proofs and randomizes the IoT authentication request. The security of our construction is based on the well-studied discrete logarithm and decisional Diffie–Hellman assumptions in elliptic curve groups. We formally prove that MAPFS ensures mutual authentication and semantic security for session keys. We also evaluate MAPFS performance in terms of the communication overhead, storage requirements, and computation complexity. Finally, we test the performance of MAPFS on a Raspberry Pi 4 and compare it against other certificate-less protocols. Mohamed Seifelnasr, Riham AlTawy, Amr M. Youssef, Essam Ghadafi |
IEEE Internet Things J. | 2 |
| 2023 | Traceable Policy-Based Signatures with Delegation
Ismail Afia, Riham AlTawy |
CANS | 2 |
| 2023 | Unlinkable Policy-Based Sanitizable Signatures
Ismail Afia, Riham AlTawy |
CT-RSA | 2 |
| 2023 | vPass: Publicly Verifiable Fair Exchange Protocol for Vehicle PassportsabstractIn second-hand vehicle markets, blockchains are being proposed as means to provide verification of vehicle history, a.k.a. vehicle passport (VP). However, given that confidentiality of VPs often contradicts public verification, blockchains are not used to their full potential in the proposed frameworks. Specifically, although blockchain smart contracts offer a decentralized mechanism for untrusted parties to fairly exchange digital assets without the need for a trusted third party, VP exchange is always carried off-chain. In this work, we investigate the problem of “fair exchange” of confidential VPs over public blockchains where its plain information must be verified against its publicly committed value. We propose a zero-knowledge proof, called Consistent Commitment Encryption (CCE), that enables the public verification of the consistency between ElGamal encryption of a given VP and its Pedersen commitment. We employ our CCE to build vPass, a decentralized vehicle passport framework that enables second-hand vehicle buyers to purchase vehicle history information from designated service providers and get it verified and delivered on-chain while preserving its confidentiality. The security of CCE relies on the intractability of the discrete logarithm problem in elliptic curve groups and it has no trusted setup. We formally prove that CCE is sound, complete, and witness indistinguishable proof of knowledge, and report on comparisons with other generic proof systems. Moreover, we show that vPass provides fair exchange and confidentiality of the vehicle history, and compare it to existing VP systems. Finally, we provide a proof of concept implementation on Ethereum and report the system performance metrics. Ismail Afia, Hisham S. Galal, Riham AlTawy, Amr M. Youssef |
ICBC | 3 |
| 2023 | GASE: A Lightweight Group Authentication Scheme With Key Agreement for Edge Computing ApplicationsabstractMotivated by the fact that mass authentication is one of the desirable security features in the edge computing paradigm, we propose a lightweight group authentication protocol with a session key-agreement. Most of the previously proposed group authentication schemes (GASs) are heavyweight and do not support multiple authentications or key-agreement. On the other hand, our protocol, which is based on secret sharing scheme and aggregated message authentication code, is lightweight and provides multiple asynchronous authentications. Furthermore, we implement a simple key refreshing mechanism in which, in each session, a new session-key between an Internet of Things node and the authenticating server is established without the need for redistributing new shares. Our security analysis includes proving that our protocol provides group authentication, message forward secrecy, and prevents several attacks. Additionally, we present a formal automated verification using Verifpal tool. Furthermore, we show that our scheme has better performance than other relative schemes in terms of communication complexity, secret-share redistribution, and session key derivations. Mouna Nakkar, Riham AlTawy, Amr M. Youssef |
IEEE Internet Things J. | 2 |
| 2023 | Lightweight Authentication Scheme for Healthcare With Robustness to Desynchronization AttacksabstractRemote healthcare monitoring systems are gaining a lot of interest as they enable doctors to use public channels to get real-time data from the sensors placed in/on the patient’s body. This necessitates the implementation of a robust authentication scheme to ensure secure communication between trusted healthcare providers and sensors which are usually low in resources. To address these issues, in 2021, Masud et al. presented a lightweight anonymous user authentication scheme for securely obtaining patient’s real-time data. Their protocol is considered practical for deployment on sensor nodes as it only utilizes hash functions and does not require any public-key cryptography. In this work, we demonstrate how their protocol loses synchronization when a message is blocked/jammed and how in some scenarios, the protocol is exposed to the risk of session key disclosure and cannot ensure forward secrecy. To overcome these threats, we proposeLAPRD, a lightweight mutual authentication protocol that provides robustness to desynchronization attacks. The proposed scheme uses a one-way hash chain technique to ensure forward secrecy and enable resynchronization between the protocol entities in the event of a desynchronization attack.LAPRDalso achieves user and sensor node anonymity, thus ensuring privacy of the communicating entities. With the demonstration of both formal and informal analyses, the proposed protocol is ensured to withstand the identified attacks in Masud et al.’s scheme. The comparative analysis in terms of security and performance with relevant protocols indicates that the proposed protocol ensures higher security with considerably low computation and communication overheads, making it suitable for practical implementation in a lightweight healthcare environment. Shamim Shihab, Riham AlTawy |
IEEE Internet Things J. | 2 |
| 2023 | Mjolnir: Breaking the Glass in a Publicly Verifiable Yet Private MannerabstractThis paper formally investigates the problem of unauthorized yet required access to electronically protected information, a.k.a. Break-the-Glass (BtG) access. Reflecting on the rising deployment of such protocols in the current digitized healthcare system, we present Mjolnir, a blockchain-based BtG framework that offers accountability of unauthorized accesses by healthcare practitioners, dependable right of notification to patients, and privacy of healthcare records accesses. Mjolnir is a smart contract-based protocol which provides undisputed public verifiability of the identity of BtG access entities while maintaining their anonymity except from concerned individual patients, hence protecting the patients’ privacy. We employ an application specific non-interactive cryptographic zero knowledge proof system which ensures that the signing entity (healthcare practitioner) belongs to a given authorized group and that the anonymity of their identity is only revocable by a given opening entity (patient). The security of our system relies on the hardness of the discrete logarithm and decisional Diffie–Hellman problems in elliptic curve groups, and the utilized proof system requires no trusted setup. We formally define and prove the security goals of Mjolnir, provide a proof of concept blockchain implementation on Ethereum, and report on performance experiments and comparisons with other generic zero knowledge proof systems. Riham AlTawy, Hisham S. Galal, Amr M. Youssef |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2022 | Garage Door Openers: A Rolling Code Protocol Case StudyabstractRolling code is a keyless access protocol used prominently for garage doors and vehicles entry. In this work, we examine the security of three garage door opener systems which are widely used in the north American markets. Such openers are electronically controlled by wireless remotes and mobile applications. We reverse engineer their rolling code protocol and demonstrate practical attacks that enable an adversary to open the garage door after wirelessly sniffing only one open/close signal produced by the remote control device owner. Our security analysis reveals that such attacks are due to vulnerabilities in the deployment of the rolling code protocol in two out of the three investigated brands. Responsible disclosure procedures have been followed prior to the dissemination of our results. Ahmed Ghanem, Riham AlTawy |
PST | 2 |
| 2021 | Verifiable Obtained Random Subsets for Improving SPHINCS+
Mahmoud Yehia, Riham AlTawy, T. Aaron Gulliver |
ACISP | 2 |
| 2021 | GMMT: A Revocable Group Merkle Multi-tree Signature Scheme
Mahmoud Yehia, Riham AlTawy, T. Aaron Gulliver |
CANS | 2 |
| 2021 | Security Analysis of DGM and GM Group Signature Schemes Instantiated with XMSS-T
Mahmoud Yehia, Riham AlTawy, T. Aaron Gulliver |
Inscrypt | 2 |
| 2021 | Efficient Inter-Cloud Authentication and Micropayment Protocol for IoT Edge ComputingabstractIn this paper, we present a$\textsf {S}$ymmetric$\textsf {K}$ey$\textsf {I}$nter-$\textsf {C}$loud$\textsf {A}$uthentication and redeemable micropayment$\textsf {P}$rotocol ($\textsf {SKICAP}$) for IoT-Edge computing applications. The proposed protocol takes into account the mobile and limited resource nature of IoT devices by enabling them to register with their home cloud admin for computation offloading service provided by foreign Edge-Cloud instances. More precisely,$\textsf {SKICAP}$ensures that mobile IoT devices can be authenticated and serviced by edge nodes outside of their home cloud coverage, while guaranteeing the associated charge redemption. Additionally, since our protocol considers the mobile and anywhere deployable requirements of IoT devices, we utilize physical unclonable function and cryptographic hash function to make it privacy-preserving and resilient to hardware compromise. Under the assumption of an indistinguishably secure physical unclonable function, we provide a formal security analysis of our protocol. Finally, we report$\textsf {SKICAP}$performance on an ARM Cortex-A72 processor, and compare it with other closely related protocols. Mohamed Seifelnasr, Riham AlTawy, Amr M. Youssef |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2020 | Lightweight Broadcast Authentication Protocol for Edge-Based ApplicationsabstractIn this article, we propose a lightweight authentication protocol that provides forward secrecy for edge-based applications. Motivated by the general consensus that centralized authentication solutions are not suitable for an expanding Internet of Things (IoT), our edge-based authentication reduces latency for critical applications, lowers cloud dependency, and employs cryptographic primitives, which are efficiently implemented on resource-constrained low-end devices. Moreover, the edge entity broadcast messages using session keys that are derived securely from a hash function. The protocol utilizes hash chains and authenticated encryption which makes it resilient to quantum attacks. Moreover, entities are not required to hold a permanent master key, and all session keys are derived securely from a hash function. As a use case, we present a smart emergency system where an edge application broadcasts alert messages for individual responder groups when specific events occur. We formally define and prove the main security properties of our protocol, and compare it to other lightweight protocols in terms of security and performance. The computational complexity of our protocol comprises of three decryption operations, two HMAC, and five hash computations. The required storage for each node is 96 B and the communication overhead is only 56 B per session. Mouna Nakkar, Riham AlTawy, Amr M. Youssef |
IEEE Internet Things J. | 2 |
| 2019 | Mesh: A Supply Chain Solution with Locally Private Blockchain TransactionsabstractAbstract A major line of research on blockchains is geared towards enhancing the privacy of transactions through anonymity using generic non-interactive proofs. However, there is a good cluster of application scenarios where complete anonymity is not desirable and accountability is in fact required. In this work, we utilize non-interactive proofs of knowledge of elliptic curve discrete logarithms to present membership and verifiable encryption proof, which offers plausible anonymity when combined with the regular signing process of the blockchain transactions. The proof system requires no trusted setup, both its communication and computation complexities are linear in the number of set members, and its security relies on the discrete logarithm assumption. As a use-case for this scenario, we present Mesh which is a blockchain-based framework for supply chain management using RFIDs. Finally, the confidentiality of the transacted information is realized using a lightweight key chaining mechanism implemented on RFIDs. We formally define and prove the main security features of the protocol, and report on experiments for evaluating the performance of the modified transactions for this system. Riham AlTawy, Guang Gong |
Proc. Priv. Enhancing Technol. | 1 |
| 2018 | Towards a Cryptographic Minimal Design: The sLiSCP Family of PermutationsabstractThe security of highly resource constrained applications is often viewed in the literature from a single aspect of a specific cryptographic primitive. More precisely, most of the proposed lightweight cryptographic primitives focus on providing a single functionality within the available hardware area dedicated for security purposes. In this paper, we argue that for such applications, a cryptographic primitive that follows the cryptographic minimal design strategy maybe the only realistically adopted security solution where there is a constrained GE budget for all security functionalities. Indeed, it is reasonable, if not desirable, for the adopted cryptographic design to have well justified building components and to provide minimal overhead for multiple cryptographic functionalities including encryption, hashing, authentication, and pseudorandom bit generation. Following such a strategy, we propose the sLiSCP family of lightweight cryptographic permutations which employs two of the most hardware efficient and extensively cryptanalyzed constructions, namely a 4-subblock Type-2 Generalized Feistel-like Structure (GFS) and round-reduced unkeyed Simeck. In addition to the hardware efficiency, we follow restrictive security design goals which enable us to provide resistance against differential and linear cryptanalysis, as well as guaranteed resistance to diffusion-based, algebraic, and self-symmetry distinguishers, and accordingly, we claim that there exist no structural distinguishers for sLiSCP-b with a complexity below 2b=2 where b is the state size. Moreover, we present the sLiSCP duplex sponge mode to illustrate how the permutations can be used in a unified design that provides (authenticated) encryption, hashing, and pseudorandom bit generation functionalities. Finally, we report two efficient parallel hardware implementations for the sLiSCP unified duplex sponge mode when using sLiSCP-192 (resp. sLiSCP-256) in CMOS 65 nm ASIC with area of 2289 (resp. 3039) GE and a throughput of 29.62 (resp. 44.44) kbps, and their areas in CMOS 130 nm are 2498 (resp. 3319) GE. Riham AlTawy, Raghvendra Rohit 0001, Morgan He, Kalikinkar Mandal, Gangqiang Yang, Guang Gong |
IEEE Trans. Computers | 1 |
| 2018 | SLISCP-light: Towards Hardware Optimized Sponge-specific Cryptographic PermutationsabstractThe emerging areas in which highly resource constrained devices are interacting wirelessly to accomplish tasks have led manufacturers to embed communication systems in them. Tiny low-end devices such as sensor networks nodes and Radio Frequency Identification (RFID) tags are of particular importance due to their vulnerability to security attacks, which makes protecting their communication privacy and authenticity an essential matter. In this work, we present a lightweight do-it-all cryptographic design that offers the basic underlying functionalities to secure embedded communication systems in tiny devices. Specifically, we revisit the design approach of the sLiSCP family of lightweight cryptographic permutations, which was proposed in SAC 2017. sLiSCP is designed to be used in a unified duplex sponge construction to provide minimal overhead for multiple cryptographic functionalities within one hardware design. The design of sLiSCP follows a 4-subblock Type-2 Generalized Feistel-like Structure (GFS) with unkeyed round-reduced Simeck as the round function, which are extremely efficient building blocks in terms of their hardware area requirements. In S L I SCP-light, we tweak the GFS design and turn it into an elegant Partial Substitution-Permutation Network construction, which further reduces the hardware areas of the S L I SCP permutations by around 16% of their original values. The new design also enhances the bit diffusion and algebraic properties of the permutations and enables us to reduce the number of steps, thus achieving a better throughput in both the hashing and authentication modes. We perform a thorough security analysis of the new design with respect to its diffusion, differential and linear, and algebraic properties. For S L I SCP-light-192, we report parallel implementation hardware areas of 1,820 (respectively, 1,892)GE in CMOS 65 nm (respectively, 130 nm ) ASIC. The areas for S L I SCP-light-256 are 2,397 and 2,500GE in CMOS 65 nm and 130 nm ASIC, respectively. Overall, the unified duplex sponge mode of S L I SCP-light-192, which provides (authenticated) encryption and hashing functionalities, satisfies the area (1,958GE), power (3.97μ W ), and throughput (44.4kbps) requirements of passive RFID tags. Riham AlTawy, Raghvendra Rohit 0001, Morgan He, Kalikinkar Mandal, Gangqiang Yang, Guang Gong |
ACM Trans. Embed. Comput. Syst. | 1 |
| 2017 | MILP-Based Cube Attack on the Reduced-Round WG-5 Lightweight Stream Cipher
Raghvendra Rohit 0001, Riham AlTawy, Guang Gong |
IMACC | 2 |
| 2017 | Lelantos: A Blockchain-Based Anonymous Physical Delivery SystemabstractReal world physical shopping offers customers the privilege of maintaining their privacy by giving them the option of using cash, and thus providing no personal information such as their names and home addresses. On the contrary, electronic shopping mandates the use of all sorts of personally identifiable information for both billing and shipping purposes. Cryptocurrencies such as Bitcoin have created a stimulated growth in private billing by enabling pseudonymous payments. However, the anonymous delivery of the purchased physical goods is still an open research problem. In this work, we present a blockchain-based physical delivery system called Lelantos1 that within a realistic threat model, offers customer anonymity, fair exchange and merchant-customer unlinkability. Our system is inspired by the onion routing techniques which are used to achieve anonymous message delivery. Additionally, Lelantos relies on the decentralization and pseudonymity of the blockchain to enable pseudonymity that is hard to compromise, and the distributed consensus mechanisms provided by smart contracts to enforce fair irrefutable transactions between distrustful contractual parties. Riham AlTawy, Muhammad ElSheikh, Amr M. Youssef, Guang Gong |
PST | 1 |
| 2017 | sLiSCP: Simeck-Based Permutations for Lightweight Sponge Cryptographic Primitives
Riham AlTawy, Raghvendra Rohit 0001, Morgan He, Kalikinkar Mandal, Gangqiang Yang, Guang Gong |
SAC | 1 |
| 2017 | Security, Privacy, and Safety Aspects of Civilian Drones: A SurveyabstractThe market for civilian unmanned aerial vehicles, also known as drones, is expanding rapidly as new applications are emerging to incorporate the use of civilian drones in our daily lives. On one hand, the convenience of offering certain services via drones is attractive. On the other hand, the mere operation of these airborne machines, which rely heavily on their cyber capabilities, poses great threats to people and property. Also, while the Federal Aviation Administration NextGen project aims to integrate civilian drones into the national airspace, the regulation is still a work-in-progress and does not cope with their threats. This article surveys the main security, privacy, and safety aspects associated with the use of civilian drones in the national airspace. In particular, we identify both the physical and cyber threats of such systems and discuss the security properties required by their critical operation environment. We also identify the research challenges and possible future directions in the fields of civilian drone security, safety, and privacy. Based on our investigation, we forecast that security will be a central enabling technology for the next generation of civilian unmanned aerial vehicles. Riham AlTawy, Amr M. Youssef |
ACM Trans. Cyber Phys. Syst. | 1 |
| 2015 | Differential Fault Analysis of Streebog
Riham AlTawy, Amr M. Youssef |
ISPEC | 1 |
| 2015 | Watch your constants: malicious StreebogabstractIn August 2012, the Streebog hash function was selected as the new Russian cryptographic hash standard (GOST R 34.11‐2012). In this study, the authors investigate the new standard in the context of malicious hashing and present a practical collision for a malicious version of the full hash function. In particular, they apply the rebound attack to find three solutions for three different differential paths for four rounds. Then, using the freedom of the round constants they connect them to obtain a collision for the 12 rounds of the compression function. Additionally, and because of the simple processing of the counter, they bypass the barrier of the checksum finalisation step and transfer the compression function collision to the hash function output with no additional cost. The presented attack has a practical complexity and is verified by an example. Although the results of this study may not have a direct impact on the security of the current Streebog hash function, it presents an urge for the designers to publish the origin of the used parameters and the rational behind their choices in order for this function to gain enough confidence and widespread adoption by the security community. Riham AlTawy, Amr M. Youssef |
IET Inf. Secur. | 1 |
| 2014 | Second Preimage Analysis of Whirlwind
Riham AlTawy, Amr M. Youssef |
Inscrypt | 1 |
| 2014 | Integral distinguishers for reduced-round Stribog
Riham AlTawy, Amr M. Youssef |
Inf. Process. Lett. | 1 |
| 2013 | A Heuristic for Finding Compatible Differential Paths with Application to HAS-160
Aleksandar Kircanski, Riham AlTawy, Amr M. Youssef |
ASIACRYPT (2) | 2 |
| 2013 | Second order collision for the 42-step reduced DHA-256 hash function
Riham AlTawy, Aleksandar Kircanski, Amr M. Youssef |
Inf. Process. Lett. | 1 |