EDBT 2026 Demo / reviewers in the wild / expert
Thang Hoang
dblp:132/2690
· DBLP profile ↗
34ranked-venue papers
12as first author
22since 2021 · last 2026
0000-0003-2229-3863ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 30 · 10 first-author · 19 since 2021Computer networks · 2 · 1 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Full Threshold NIST PQC-Compliant Framework for Distributed Trust in Federal Public Key Infrastructure
Kiarash Sedghighadikolaei, Changqi Sun, Thang Hoang, Bechir Hamdaoui, Attila A. Yavuz |
SP | 3 |
| 2025 | Zero-Knowledge AI Inference with High PrecisionabstractArtificial Intelligence as a Service (AIaaS) enables users to query a model hosted by a service provider and receive inference results from a pre-trained model. Although AIaaS makes artificial intelligence more accessible, particularly for resource-limited users, it also raises verifiability and privacy concerns for the client and server, respectively. While zero-knowledge proof techniques can address these concerns simultaneously, they incur high proving costs due to the non-linear operations involved in AI inference and suffer from precision loss because they rely on fixed-point representations to model real numbers. Arman Riasi, Haodi Wang, Rouzbeh Behnia, Viet Vo, Thang Hoang |
CCS | 5 |
| 2025 | Hermes: Efficient and Secure Multi-Writer Encrypted DatabaseabstractSearchable encryption (SE) enables privacy-preserving keyword search on encrypted data. Public-key SE (PKSE) supports multi-user searches but suffers from high search latency due to expensive public-key operations. Symmetric SE (SSE) offers a sublinear search but is mainly limited to single-user settings. Recently, hybrid SE (HSE) has combined SSE and PKSE to achieve the best of both worlds, including multi-writer encrypted search functionalities, forward privacy, and sublinear search with respect to database size. Despite its advantages, HSE inherits critical security limitations, such as susceptibility to dictionary attacks, and still incurs significant overhead for search access control verification, requiring costly public-key operation invocations (i.e., pairing) across all authorized keywords. Additionally, its search access control component must be rebuilt periodically for forward privacy, imposing substantial writer overhead. In this paper, we propose Hermes, a new HSE scheme that addresses the aforementioned security issues in prior HSE designs while maintaining minimal search complexity and user efficiency at the same time. Hermes enables multi-writer encrypted search functionalities and offers forward privacy along with resilience to dictionary attacks. To achieve this, we develop a new identity-based encryption scheme with hidden identity and key-aggregate properties, which could be of independent interest. We also design novel partitioning and epoch encoding techniques in Hermes to minimize search complexity and offer low user overhead in maintaining forward privacy. We conducted intensive experiments to assess and compare the performance of Hermes and its counterpart on commodity hardware. Experimental results showed that Hermes performs search one to two orders of magnitude faster than the state-of-the-art HSE while offering stronger security guarantees to prevent dictionary and injection attacks. Tung Le 0005, Thang Hoang |
SP | 2 |
| 2025 | AccuRevoke: Enhancing Certificate Revocation with Distributed Cryptographic AccumulatorsabstractCertificate revocation is essential for maintaining the security of the Public Key Infrastructure (PKI), ensuring that compromised or untrustworthy certificates are invalidated promptly. Traditional revocation mechanisms like Certificate Revocation Lists (CRLs) and the Online Certificate Status Protocol (OCSP) face significant challenges, including scalability issues, high bandwidth consumption, privacy concerns, and reliance on centralized infrastructure that can become points of failure. In this paper, we introduce AccuRevoke, a novel revocation scheme that leverages cryptographic accumulators and edge computing to address these challenges effectively. Accu Revoke enables clients to verify the revocation status of certificates efficiently without the need to contact Certificate Authorities (CAs) directly for each validation. By utilizing distributed accumulators and threshold cryptography, Accu Revoke ensures authenticity and integrity of revocation information, even when responses are generated by third-party Edge Compute Providers (ECPs). Our scheme significantly reduces bandwidth consumption by providing compact revocation proofs-approximately 21 bytes for membership proofs and 61 bytes for non-membership proofs-which are substantially smaller than traditional OCSP responses. To further optimize performance, especially in generating non-membership witnesses, we employ GPU acceleration, achieving considerable improvements in processing times. We compare AccuRevoke with existing revocation mechanisms, demonstrating advantages in bandwidth efficiency, reliability, auditability, and potential enhancements in privacy. Our evaluation shows that Accu Revoke offers a scalable and practical solution for revocation checking, improving the security and performance of TLSIPKI deployments. We plan to open-source our design and implementation to facilitate adoption and encourage further research in this area. Munshi Rejwan Ala Muid, Taejoong Chung, Thang Hoang |
SP | 3 |
| 2025 | Client-Efficient Online-Offline Private Information RetrievalabstractPrivate Information Retrieval (PIR) permits clients to query data entries from a public database hosted on untrusted servers while preserving client privacy. Traditional PIR models suffer from high computation and/or bandwidth overhead due to linear database processing. Recently, Online-Offline PIR (OO-PIR) has been proposed to improve PIR practicality by precomputing query-independent materials to accelerate online access. While state-of-the-art OO-PIR schemes (e.g., S&P’24, CRYPTO’23) successfully reduce online processing cost to sublinear levels, they still impose substantial bandwidth and storage burdens on the client, especially when operating on large databases. In this paper, we propose Pirex, a new two-server OO-PIR scheme with semi-honest security that offers minimal client-side inbound bandwidth and storage costs while retaining sublinear processing efficiency. The Pirex design is simple, with most operations being naturally low-cost and streamlined (e.g., XOR, PRF, modular arithmetic). We have fully implemented Pirex and evaluated its real-world performance using commodity hardware. Our results show that Pirex outperforms existing OO-PIR schemes by at least two orders of magnitude. With a 1 TB database, Pirex takes only 55 ms to retrieve a 4 KB entry, compared to 9–30 seconds for state-of-the-art approaches. For practical databases with billions of 4 KB entries, Pirex requires just 16 KB of inbound bandwidth—up to three orders of magnitude more efficient. Hoang-Dung Nguyen, Jorge Guajardo, Thang Hoang |
Proc. Priv. Enhancing Technol. | 3 |
| 2025 | An Efficient and Zero-Knowledge Classical Machine Learning Inference PipelineabstractMachine Learning as a Service (MLaaS) offers powerful data analytics services to clients with limited resources. However, it still raises concerns about the integrity of delegated computation and the privacy of the server's model parameters. To address these issues, zero-knowledge Machine Learning (zkML) has been suggested for computation verifiability with privacy guarantee for ML models. Nevertheless, the existing zkML schemes focus on only one classical ML classification algorithm or deep neural networks, which may not achieve satisfactory accuracy or require large-scale training data and model parameters, thus limiting their usefulness in certain applications. In this article, we propose ezDPS, an efficient and zero-knowledge scheme for classical ML inference that processes data in multiple stages for improved accuracy. Unlike prior works, each stage of the ezDPS pipeline is based on a well-established classical ML algorithm, including Discrete Wavelet Transformation, Zero-Score Normalization, Principal Components Analysis, and Support Vector Machine. We design new gadgets to prove various ML operations effectively. Our implementation of ezDPS has been fully tested on real datasets, and experimental results show that it is up to three orders of magnitude more efficient than generic circuit-based approaches, while also maintaining greater accuracy than single ML classification approaches. Haodi Wang, Rongfang Bie, Thang Hoang |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | Efficient Secure Aggregation for Privacy-Preserving Federated Machine LearningabstractSecure aggregation protocols ensure the privacy of users’ data in federated learning by preventing the disclosure of local gradients. Many existing protocols impose significant communication and computational burdens on participants and may not efficiently handle the large update vectors typical of machine learning models. Correspondingly, we present e-SeaFL, an efficient verifiable secure aggregation protocol taking only one communication round during the aggregation phase. e-SeaFL allows the aggregation server to generate proof of honest aggregation to participants via authenticated homomorphic vector commitments. Our core idea is the use of assisting nodes to help the aggregation server, under similar trust assumptions existing works place upon the participating users. Our experiments show that the user enjoys an order of magnitude efficiency improvement over the state-of-the-art (IEEE S&P 2023) for large gradient vectors with thousands of parameters. Our open-source implementation is available at https://github.com/vt-asaplab/e-SeaFL. Rouzbeh Behnia, Arman Riasi, Reza Ebrahimi 0001, Sherman S. M. Chow, Balaji Padmanabhan, Thang Hoang |
ACSAC | 6 |
| 2024 | Privacy-Preserving Verifiable Neural Network Inference ServiceabstractMachine learning has revolutionized data analysis and pattern recognition, but its resource-intensive training has limited accessibility. Machine Learning as a Service (MLaaS) simplifies this by enabling users to delegate their data samples to an MLaaS provider and obtain the inference result using a pre-trained model. Despite its convenience, leveraging MLaaS poses significant privacy and reliability concerns to the client. Specifically, sensitive information from the client inquiry data can be leaked to an adversarial MLaaS provider. Meanwhile, the lack of a verifiability guarantee can potentially result in biased inference results or even unfair payment issues. While existing trustworthy machine learning techniques, such as those relying on verifiable computation or secure computation, offer solutions to privacy and reliability concerns, they fall short of simultaneously protecting the privacy of client data and providing provable inference verifiabilityIn this paper, we propose vPIN, a privacy-preserving and verifiable CNN inference scheme that preserves privacy for client data samples while ensuring verifiability for the inference. vPIN makes use of partial homomorphic encryption and commit-and-prove succinct non-interactive argument of knowledge techniques to achieve desirable security properties. In vPIN, we develop various optimization techniques to minimize the proving circuit for homomorphic inference evaluation thereby, improving the efficiency and performance of our technique. We fully implemented and evaluated our vPIN scheme on standard datasets (e.g., MNIST, CIFAR-10). Our experimental results show that vPIN achieves high efficiency in terms of proving time, verification time, and proof size, while providing client data privacy guarantees and provable verifiability. Arman Riasi, Jorge Guajardo, Thang Hoang |
ACSAC | 3 |
| 2024 | Exploiting Update Leakage in Searchable Symmetric EncryptionabstractDynamic Searchable Symmetric Encryption (DSSE) provides efficient techniques for securely searching and updating an encrypted database. However, efficient DSSE schemes leak some sensitive information to the server. Recent works have implemented forward and backward privacy as security properties to reduce the amount of information leaked during update operations. Many attacks have shown that leakage from search operations can be abused to compromise the privacy of client queries. However, the attack literature has not rigorously investigated techniques to abuse update leakage. Jacob Haltiwanger, Thang Hoang |
CODASPY | 2 |
| 2024 | Breaking Privacy in Model-Heterogeneous Federated LearningabstractFederated learning (FL) allows multiple distrustful clients to collaboratively train a machine learning model. In FL, data never leaves client devices; instead, clients only share locally computed gradients with a central server. As individual gradients may leak information about a given client’s dataset, secure aggregation was proposed. With secure aggregation, the server only receives the aggregate gradient update from the set of all sampled clients without being able to access any individual gradient. One challenge in FL is the systems-level heterogeneity that is quite often present among client devices. Specifically, clients in the FL protocol may have varying levels of compute power, on-device memory, and communication bandwidth. These limitations are addressed by model-heterogeneous FL schemes, where clients are able to train on subsets of the global model. Despite the benefits of model-heterogeneous schemes in addressing systems-level challenges, the implications of these schemes on client privacy have not been thoroughly investigated. Atharva Haldankar, Arman Riasi, Hoang-Dung Nguyen, Tran Phuong, Thang Hoang |
RAID | 5 |
| 2024 | MUSES: Efficient Multi-User Searchable Encrypted Database
Tung Le 0005, Rouzbeh Behnia, Jorge Guajardo, Thang Hoang |
USENIX Security Symposium | 4 |
| 2024 | Efficient Privacy-Preserving Machine Learning with Lightweight Trusted HardwareabstractIn this paper, we propose a new secure machine learning inference platform assisted by a small dedicated security processor, which will be easier to protect and deploy compared to today's TEEs integrated into high-performance processors. Our platform provides three main advantages over the state-of-the-art: (i) We achieve significant performance improvements compared to state-of-the-art distributed Privacy-Preserving Machine Learning (PPML) protocols, with only a small security processor that is comparable to a discrete security chip such as the Trusted Platform Module (TPM) or on-chip security subsystems in SoCs similar to the Apple enclave processor. In the semi-honest setting with WAN/GPU, our scheme is 4X-63X faster than Falcon (PoPETs'21) and AriaNN (PoPETs'22) and 3.8X-12X more communication efficient. We achieve even higher performance improvements in the malicious setting. (ii) Our platform guarantees security with abort against malicious adversaries under honest majority assumption. (iii) Our technique is not limited by the size of secure memory in a TEE and can support high-capacity modern neural networks like ResNet18 and Transformer. While previous work investigated the use of high-performance TEEs in PPML, this work represents the first to show that even tiny secure hardware with very limited performance can be leveraged to significantly speed-up distributed PPML protocols if the protocol can be carefully designed for lightweight trusted hardware. Pengzhi Huang, Thang Hoang, Elaine Shi, G. Edward Suh |
Proc. Priv. Enhancing Technol. | 2 |
| 2023 | VTBC: Privatizing the Volume and Timing of Transactions for Blockchain ApplicationsabstractExisting privacy-preserving blockchain solutions have shown how to maintain the anonymity and confidentiality of the contents of blockchain transactions. However, due to blockchains needing to be stored and updated in a decentralized manner, metadata like the volume of transactions and the timestamp of each transaction can always be publicly observed, even with state-of-the-art solutions. Blockchain applications, especially ones with time-sensitive or volume-sensitive outcomes, may require this volume and timing information to be privatized. One example is not leaking the lateness of students' exam submissions because this could violate student privacy laws. In this paper, we propose VTBC, a blockchain system to privatize such volume and timing information for multi-party privacy-preserving blockchain applications through decoy blockchain transactions which a) do not contribute at all to the execution of the application and b) are indistinguishable from real (non-decoy) transactions. Even though the volume and timing metadata of all transactions must be public, volume and timing information for an application can be indirectly privatized (even after the application has been finalized) by carefully deciding when and how many decoy transactions are added to the blockchain. We demonstrate how these decoy transactions can be created without sacrificing the application's integrity, functionality, or verifiability, without making changes to the underlying blockchain's architecture, and always using the blockchain as the trusted timekeeper. We implemented our approach via a Dutch auction that supports decoy bid transactions and evaluated its performance on a private Ethereum blockchain network. Trevor Miller, Bobby Alvarez, Thang Hoang |
ICCCN | 3 |
| 2023 | Efficient Dynamic Proof of Retrievability for Cold Storage
Tung Le 0005, Pengzhi Huang, Attila A. Yavuz, Elaine Shi, Thang Hoang |
NDSS | 5 |
| 2023 | MAPLE: A Metadata-Hiding Policy-Controllable Encrypted Search Platform with Minimal TrustabstractCommodity encrypted storage platforms (e.g., IceDrive, pCloud) permit data store and sharing across multiple users while preserving data confidentiality. However, end-to-end encryption may not be sufficient since it only offers confidentiality when the data is at rest or in transit. Meanwhile, sensitive information can be leaked from metadata representing activities during data operations (e.g., query, processing). Recent encrypted search platforms such as DORY (OSDI’20) or DURASIFT (WPES’19) permit multi-user data query functionalities, while protecting metadata privacy. However, they either incur a high processing overhead or offer limited security/functionality, and require strong trust assumptions. We propose MAPLE, a new metadata-hiding encrypted search platform that offers query functionalities (search, update) on the shared data across multiple users with complex policy controls. MAPLE protects metadata privacy all the time during query processing, while achieving significantly (asymptotically) lower processing overhead than state-of-the-art platforms. The core technique of MAPLE is the design of oblivious data structures for search index and access control coupled with secure computation techniques to enable efficient query processing with a minimal trust. We fully implemented MAPLE and evaluated its performance on commodity cloud (Amazon EC2) under real settings. Experimental results showed that MAPLE achieved a concrete performance comparable with its counterparts, while offering provably stronger security guarantees and more diverse functionalities. Tung Le 0005, Thang Hoang |
Proc. Priv. Enhancing Technol. | 2 |
| 2023 | ezDPS: An Efficient and Zero-Knowledge Machine Learning Inference PipelineabstractMachine Learning as a service (MLaaS) permits resource-limited clients to access powerful data analytics services ubiquitously. Despite its merits, MLaaS poses significant concerns regarding the integrity of delegated computation and the privacy of the server’s model parameters. To address this issue, Zhang et al. (CCS'20) initiated the study of zero-knowledge Machine Learning (zkML). Few zkML schemes have been proposed afterward; however, they focus on sole ML classification algorithms that may not offer satisfactory accuracy or require large-scale training data and model parameters, which may not be desirable for some applications. We propose ezDPS, a new efficient and zero-knowledge ML inference scheme. Unlike prior works, ezDPS is a zkML pipeline in which the data is processed in multiple stages for high accuracy. Each stage of ezDPS is harnessed with an established ML algorithm that is shown to be effective in various applications, including Discrete Wavelet Transformation, Principal Components Analysis, and Support Vector Machine. We design new gadgets to prove ML operations effectively. We fully implemented ezDPS and assessed its performance on real datasets. Experimental results showed that ezDPS achieves one-to-three orders of magnitude more efficient than the generic circuit-based approach in all metrics while maintaining more desirable accuracy than single ML classification approaches. Haodi Wang, Thang Hoang |
Proc. Priv. Enhancing Technol. | 2 |
| 2023 | AVET: A Novel Transform Function to Improve Cancellable Biometrics SecurityabstractSimilarity preserving is a key ingredient of cancellable biometric scheme design. The notion ensures the accuracy performance of the biometric systems can be preserved after the cancellable biometric technique is applied. Random Projection is among the most commonly adopted method in cancellable biometric schemes. However, it is reversible subject to certain conditions, which disrupts the template irreversibility criterion. This invites vulnerabilities for random projection-based schemes. In this paper, we propose a novel transform function, namely Absolute Value Equations Transform (AVET), which non-linearly projects feature vectors to another domain. The transformed templates hold two main merits ensuring the user’s privacy, and maintaining the system’s performance simultaneously. First, by relying on the hardness of the Absolute Value Equations problem, we guarantee that AVET satisfies irreversibility. Second, by using Johnson–Lindenstrauss lemma and the inverse triangle inequality, we prove that the proposed approach has the similarity preserving property. Notably, rigorous theoretical proofs and empirical experiments are provided. The efficacy of AVET is comprehensively evaluated on both physiological and behavioral biometrics including face, ear, fingerprint, and gait. With unimodal approach, we achieve competitive performances compared to related algorithms on eight public datasets. Regarding bimodal mode, the AVET surpasses the state-of-the-art technique on all three observed datasets. To the best of our knowledge, this is the first study that attempts to develop a secure transformation to augment the role of Random Projection in the existing cancellable biometric schemes. Thao M. Dang, Thuc Dinh Nguyen, Thang Hoang, Andrew Beng Jin Teoh, Deokjai Choi 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2022 | Titanium: A Metadata-Hiding File-Sharing System with Malicious Security
Weikeng Chen, Thang Hoang, Jorge Guajardo, Attila A. Yavuz |
NDSS | 2 |
| 2022 | Polynomial Commitment with a One-to-Many Prover and Applications
Jiaheng Zhang, Tiancheng Xie, Thang Hoang, Elaine Shi, Yupeng Zhang 0001 |
USENIX Security Symposium | 3 |
| 2021 | Proof-of-Useful-Randomness: Mitigating the Energy Waste in Blockchain Proof-of-WorkabstractProof-of-Work (PoW) is one of the fundamental and widely-used consensus algorithms in blockchains. In PoW, nodes compete to receive the mining reward by trying to be the first to solve a puzzle. Despite its fairness and wide-availability, traditional PoW incurs extreme computational and energy waste over the blockchain. This waste is considered to be one of the biggest problems in PoW-based blockchains and cryptocurrencies. In this work, we propose a new useful PoW called Proof-of-Useful-Randomness (PoUR) that mitigates the energy waste by incorporating pre-computed (disclosable) randomness into the PoW. The key idea is to inject special randomness into puzzles via algebraic commitments that can be stored and later disclosed. Unlike the traditional wasteful PoWs, our approach enables pre-computed commitments to be utilized by a vast array of public-key cryptography methods that require offline-online processing (e.g., digital signature, key exchange, zero-knowledge protocol). Moreover, our PoW preserves the desirable properties of the traditional PoW and therefore does not require a substantial alteration in the underlying protocol. We showed the security of our PoW, and then fully implemented it to validate its significant energy-saving capabilities. Efe Seyitoglu, Attila A. Yavuz, Thang Hoang |
SECRYPT | 3 |
| 2021 | Efficient Oblivious Data Structures for Database Services on the CloudabstractDatabase-as-a-service (DBaaS) allows the client to store and manage structured data on the cloud remotely. Despite its merits, DBaaS also brings significant privacy issues. Existing encryption techniques (e.g., SQL-aware encryption) can mitigate privacy concerns, but they still leak information through access patterns, which are vulnerable to statistical inference attacks. Oblivious Random Access Machine (ORAM) can seal such leakages; however, the recent studies showed significant challenges on the integration of ORAM into databases. That is, the direct usage of ORAM on databases is not only costly but also permits very limited query functionalities. In this paper, we propose new oblivious data structures called Oblivious Matrix Structure (OMAT), which allow tree-based ORAM to be integrated into database systems in a more efficient manner with diverse query functionalities supported. OMAT provides special ORAM packaging strategies for table structures, which not only offers a significantly better performance but also enables a broad range of query types that may not be efficient in existing frameworks. On the other hand, OTREE allows oblivious conditional queries to be performed on tree-indexed databases more efficiently than existing techniques. We implemented our proposed techniques and evaluated their performance on a real cloud database with various metrics, compared with state-of-the-art counterparts. Thang Hoang, Ceyhun D. Ozkaptan, Gabriel Hackebeil, Attila A. Yavuz |
IEEE Trans. Cloud Comput. | 1 |
| 2021 | A Secure Searchable Encryption Framework for Privacy-Critical Cloud Storage ServicesabstractSearchable encryption has received a significant attention from the research community with various constructions being proposed, each achieving asymptotically optimal complexity for specific metrics (e.g., search, update). Despite their elegance, the recent attacks and deployment efforts have shown that the optimal asymptotic complexity might not always imply practical performance, especially if the application demands a high privacy. In this article, we introduce a novel Dynamic Searchable Symmetric Encryption (DSSE) framework called Incidence Matrix (IM)-DSSE, which achieves a high level of privacy, efficient search/update, and low client storage with actual deployments on real cloud settings. We harness an incidence matrix along with two hash tables to create an encrypted index, on which both search and update operations can be performed effectively with minimal information leakage. This simple set of data structures surprisingly offers a high level of DSSE security while achieving practical performance. Specifically, IM-DSSE achieves forward-privacy, backward-privacy and size-obliviousness simultaneously. We also create several DSSE variants, each offering different trade-offs that are suitable for different cloud applications and infrastructures. We fully implemented our framework and evaluated its performance on a real cloud system (Amazon EC2). We have released IM-DSSE as an open-source library for wide development and adaptation. Thang Hoang, Attila A. Yavuz, Jorge Guajardo |
IEEE Trans. Serv. Comput. | 1 |
| 2020 | MOSE: Practical Multi-User Oblivious Storage via Secure EnclavesabstractMulti-user oblivious storage allows users to access their shared data on the cloud while retaining access pattern obliviousness and data confidentiality simultaneously. Most secure and efficient oblivious storage systems focus on the utilization of the maximum network bandwidth in serving concurrent accesses via a trusted proxy. How- ever, since the proxy executes a standard ORAM protocol over the network, the performance is capped by the network bandwidth and latency. Moreover, some important features such as access control and security against active adversaries have not been thoroughly explored in such proxy settings. In this paper, we propose MOSE, a multi-user oblivious storage system that is efficient and enjoys from some desirable security properties. Our main idea is to harness a secure enclave, namely Intel SGX, residing on the untrusted storage server to execute proxy logic, thereby, minimizing the network bottleneck of proxy-based designs. In this regard, we address various technical design chal- lenges such as memory constraints, side-channel attacks and scala- bility issues when enabling proxy logic in the secure enclave. We present a formal security model and analysis for secure enclave multi-user ORAM with access control. We optimize MOSE to boost its throughput in serving concurrent requests. We implemented MOSE and evaluated its performance on commodity hardware. Our evaluation confirmed the efficiency of MOSE, where it achieves approximately two orders of magnitudes higher throughput than the state-of-the-art proxy-based design, and also, its performance is scalable proportional to the available system resources. Thang Hoang, Rouzbeh Behnia, Yeongjin Jang, Attila A. Yavuz |
CODASPY | 1 |
| 2020 | MACAO: A Maliciously-Secure and Client-Efficient Active ORAM Framework
Thang Hoang, Jorge Guajardo, Attila A. Yavuz |
NDSS | 1 |
| 2020 | A Multi-server ORAM Framework with Constant Client Bandwidth BlowupabstractOblivious Random Access Machine (ORAM) allows a client to hide the access pattern when accessing sensitive data on a remote server. It is known that there exists a logarithmic communication lower bound on any passive ORAM construction, where the server only acts as the storage service. This overhead, however, was shown costly for some applications. Several active ORAM schemes with server computation have been proposed to overcome this limitation. However, they mostly rely on costly homomorphic encryptions, whose performance is worse than passive ORAM. In this article, we propose S 3 ORAM, a new multi-server ORAM framework, which features O (1) client bandwidth blowup and low client storage without relying on costly cryptographic primitives. Our key idea is to harness Shamir Secret Sharing and a multi-party multiplication protocol on applicable binary tree-ORAM paradigms. This strategy allows the client to instruct the server(s) to perform secure and efficient computation on his/her behalf with a low intervention thereby, achieving a constant client bandwidth blowup and low server computational overhead. Our framework can also work atop a general k -ary tree ORAM structure ( k ≥ 2). We fully implemented our framework, and strictly evaluated its performance on a commodity cloud platform (Amazon EC2). Our comprehensive experiments confirmed the efficiency of S 3 ORAM framework, where it is approximately 10× faster than the most efficient passive ORAM (i.e., Path-ORAM) for a moderate network bandwidth while being three orders of magnitude faster than active ORAM with O (1) bandwidth blowup (i.e., Onion-ORAM). We have open-sourced the implementation of our framework for public testing and adaptation. Thang Hoang, Attila A. Yavuz, Jorge Guajardo |
ACM Trans. Priv. Secur. | 1 |
| 2019 | A multi-server oblivious dynamic searchable encryption frameworkabstractData privacy is one of the main concerns for data outsourcing on the cloud. Although standard encryption can provide confidentiality, it prevents the client from searching/retrieving meaningful information on the outsourced data thereby, degrading the benefits of using cloud services. To address this data utilization versus privacy dilemma, Dynamic Searchable Symmetric Encryption (DSSE) has been proposed. DSSE enables encrypted search and update functionality over the encrypted data via a secure index. However, the state-of-the-art DSSE constructions leak information from the access pattern, making them vulnerable against various attacks. While generic Oblivious Random Access Machine (ORAM) can hide the access pattern, it incurs a heavy communication overhead, which was shown costly to be directly used in the DSSE setting. In this article, by exploiting the multi-cloud infrastructure, we develop a comprehensive Oblivious Distributed DSSE (ODSE) framework that allows oblivious search and updates on the encrypted index with high security and improved efficiency over the use of generic ORAM. Our framework contains a series of [Formula: see text] schemes each featuring different levels of performance and security required by various types of real-life applications. ODSE offers desirable security guarantees such as information-theoretic security and robustness in the presence of a malicious adversary. We fully implemented [Formula: see text] framework and evaluated its performance in a real cloud environment (Amazon EC2). Our experiments showed that ODSE schemes are [Formula: see text]-[Formula: see text] faster than using generic ORAMs on a DSSE encrypted index under real network settings. Thang Hoang, Attila A. Yavuz, F. Betül Durak, Jorge Guajardo |
J. Comput. Secur. | 1 |
| 2019 | Hardware-Supported ORAM in Effect: Practical Oblivious Search and Update on Very Large DatasetabstractAbstract The ability to query and update over encrypted data is an essential feature to enable breach-resilient cyber-infrastructures. Statistical attacks on searchable encryption (SE) have demonstrated the importance of sealing information leaks in access patterns. In response to such attacks, the community has proposed the Oblivious Random Access Machine (ORAM). However, due to the logarithmic communication overhead of ORAM, the composition of ORAM and SE is known to be costly in the conventional client-server model, which poses a critical barrier toward its practical adaptations. In this paper, we propose a novel hardware-supported privacy-enhancing platform called Practical Oblivious Search and Update Platform (POSUP), which enables oblivious keyword search and update operations on large datasets with high efficiency. We harness Intel SGX to realize efficient oblivious data structures for oblivious search/update purposes. We implemented POSUP and evaluated its performance on a Wikipedia dataset containing ≥229 keyword-file pairs. Our implementation is highly efficient, taking only 1 ms to access a 3 KB block with Circuit-ORAM. Our experiments have shown that POSUP offers up to 70× less end-to-end delay with 100× reduced network bandwidth consumption compared with the traditional ORAM-SE composition without secure hardware. POSUP is also at least 4.5× faster for up to 99.5% of keywords that can be searched compared with state-of-the-art Intel SGX-assisted search platforms. Thang Hoang, Muslum Ozgur Ozmen, Yeongjin Jang, Attila A. Yavuz |
Proc. Priv. Enhancing Technol. | 1 |
| 2018 | Oblivious Dynamic Searchable Encryption on Distributed Cloud Systems
Thang Hoang, Attila A. Yavuz, F. Betül Durak, Jorge Guajardo |
DBSec | 1 |
| 2018 | Forward-Private Dynamic Searchable Symmetric Encryption with Efficient SearchabstractDynamic Searchable Symmetric Encryption (DSSE) allows to delegate keyword search and file update over an encrypted database via encrypted indexes, and therefore provides opportunities to mitigate the data privacy and utilization dilemma in cloud storage platforms. Despite its merits, recent works have shown that efficient DSSE schemes are vulnerable to statistical attacks due to the lack of forward-privacy, whereas forward-private DSSE schemes suffers from practicality concerns as a result of their extreme computation overhead. Due to significant practical impacts of statistical attacks, there is a critical need for new DSSE schemes that can achieve the forward-privacy in a more practical and efficient manner. We propose a new DSSE scheme that we refer to as Forward-private Sublinear DSSE (FS-DSSE). FS-DSSE harnesses special secure update strategies and a novel caching strategy to reduce the computation cost of repeated queries. Therefore, it achieves forward-privacy, sublinear search complexity, low end-to-end delay, and parallelization capability simultaneously. We fully implemented our proposed method and evaluated its performance on a real cloud platform. Our experimental evaluation results showed that the proposed scheme is highly secure and highly efficient compared with state-of-the-art DSSE techniques. Specifically, FS-DSSE is up to three magnitude of times faster than forward-secure DSSE counterparts, depending on the frequency of the searched keyword in the database. Muslum Ozgur Ozmen, Thang Hoang, Attila A. Yavuz |
ICC | 2 |
| 2017 | S3ORAM: A Computation-Efficient and Constant Client Bandwidth Blowup ORAM with Shamir Secret SharingabstractOblivious Random Access Machine (ORAM) enables a client to access her data without leaking her access patterns. Existing client-efficient ORAMs either achieve O(log N) client-server communication blowup without heavy computation, or O(1) blowup but with expensive homomorphic encryptions. It has been shown that O(log N) bandwidth blowup might not be practical for certain applications, while schemes with O(1) communication blowup incur even more delay due to costly homomorphic operations. Thang Hoang, Ceyhun D. Ozkaptan, Attila A. Yavuz, Jorge Guajardo |
CCS | 1 |
| 2017 | Improving Gait Cryptosystem Security Using Gray Code Quantization and Linear Discriminant Analysis
Lam Tran, Thang Hoang, Thuc Dinh Nguyen, Deokjai Choi 0001 |
ISC | 2 |
| 2016 | Practical and secure dynamic searchable encryption via oblivious access on distributed data structure
Thang Hoang, Attila A. Yavuz, Jorge Guajardo |
ACSAC | 1 |
| 2015 | On the Instability of Sensor Orientation in Gait Verification on Mobile PhoneabstractAuthentication schemes using tokens or biometric modalities have been proposed to ameliorate the security strength on mobile devices. However, the existing approaches are obtrusive since the user is required to perform explicit gestures in order to be authenticated. While the gait signal captured by inertial sensors is understood to be a reliable profile for effective implicit authentication, recent studies have been conducted in ideal conditions and might therefore be inapplicable in the real mobile context. Particularly, the acquiring sensor is always fixed to a specific position and orientation. This paper mainly focuses on addressing the instability of sensor's orientation which mostly happens in the reality. A flexible solution taking advantages of available sensors on mobile devices which can help to handle this problem is presented. Moreover, a novel gait recognition method utilizes statistical analysis and supervised learning to adapt itself to the instability of the biometric gait under various circumstances is also proposed. By adopting PCA+SVM to construct the gait model, the proposed method outperformed other state-of-the-art studies, with an equal error rate of 2.45\% and accuracy rate of 99.14\% in terms of the verification and identification aspects being achieved, respectively. Thang Hoang, Deokjai Choi 0001, Thuc Dinh Nguyen |
SECRYPT | 1 |
| 2013 | A Lightweight Gait Authentication on Mobile Phone Regardless of Installation Error
Thang Hoang, Deokjai Choi 0001, Viet Vo, Huy Anh Nguyen, Thuc Dinh Nguyen |
SEC | 1 |