Yevhen Zolotavkin

dblp:136/6744 · DBLP profile ↗
← Back
14ranked-venue papers
9as first author
9since 2021 · last 2025
0000-0002-1875-122XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 5 first-author · 5 since 2021Computer networks · 3 · 2 first-author · 2 since 2021
YearPublicationVenuePosition
2025 A New Privacy Modeling and Enhancement Methodology for JCAS-Enabled Railway Applications
Yevhen Zolotavkin, Prajnamaya Dass, Stefan Köpsell
AINA (5)1
2025 Privacy Analysis and Enhancement for Joint Communication and Sensing Applications
abstract
Joint Communication and Sensing (JCAS) technology is envisioned to become a part of many Cyber-Physical Systems (CPSs), further advancing essential capabilities provided to numerous applications in critical infrastructure. Due to the use of human-specific sensing data, JCAS systems are vulnerable to privacy threats, and there is no established method to assess the privacy of such systems efficiently. In this paper, we propose a new privacy assessment approach that quantitatively expresses the overall privacy of the JCAS-based system under consideration, for which privacy enhancements are then proposed. While we apply our approach to a railway JCAS-based CPS in this paper, it also applies to CPSs of other kinds.
Yevhen Zolotavkin, Prajnamaya Dass, Stefan Köpsell
IWCMC1
2025 Privacy Preserving Integrated Sensing and Communication Architecture for 6G Networks
Prajnamaya Dass, Yevhen Zolotavkin, Stefan Köpsell
Networking2
2025 Optimal obfuscation of awareness messages: Improving users' unlinkability in Intelligent Transport Systems
Yevhen Zolotavkin, Yurii Baryshev, Jannik Mähn, Vitalii Lukichov, Stefan Köpsell
Comput. Networks1
2023 Improving Unlinkability in C-ITS: A Methodology For Optimal Obfuscation
abstract
In this paper, we develop a new methodology to provide high assurance about privacy in Cooperative Intelligent Transport Systems (C-ITS). Our focus lies on vehicle-to-everything (V2X) communications enabled by Cooperative Awareness Basic Service. Our research motivation is developed based on the analysis of unlinkability provision methods indicating a lack of such methods. To address this, we propose a Hidden Markov Model (HMM) to express unlinkability for the situation two vehicles are communicating with a Roadside Unit (RSU) using Cooperative Awareness Messages (CAMs). Our HMM has labeled states specifying distinct origins of the CAMs observable by a passive attacker. We then establish that high assurance about the degree of uncertainty (e.g., entropy) about labeled states can be obtained for the attacker under the assumption that he knows actual positions of the vehicles (e.g., hidden states in HMM). We further demonstrate how unlinkability can be increased in C-ITS: we propose a joint probability distribution that both drivers must use to obfuscate their actual data jointly. This obfuscated data is then encapsulated in their CAMs. Finally, our findings are incorporated into an obfuscation algorithm whose complexity is linear in the number of discrete time steps in the HMM.
Yevhen Zolotavkin, Yurii Baryshev, Vitalii Lukichov, Jannik Mähn, Stefan Köpsell
ICISSP1
2023 Weak-Key Analysis for BIKE Post-Quantum Key Encapsulation Mechanism
abstract
The evolution of quantum computers poses a serious threat to contemporary public-key encryption (PKE) schemes. To address this impending issue, the National Institute of Standards and Technology (NIST) is currently undertaking the Post-Quantum Cryptography (PQC) standardization project intending to evaluate and subsequently standardize the suitable PQC scheme(s). One such attractive approach, called Bit Flipping Key Encapsulation (BIKE), has entered the final round of the competition. Despite having some attractive features, the IND-CCA security of BIKE depends on the average decoder failure rate (DFR), a higher value of which can facilitate a particular type of side-channel attack. Although BIKE adopts the Black-Grey-Flip (BGF) decoder that offers a negligible DFR, the effect of weak-keys on the average DFR has not been fully investigated. In this paper, we implement the BIKE scheme, and then through extensive experiments show that the weak-keys can be a potential threat to IND-CCA security of the BIKE scheme and thus need attention from the relevant research community. We also propose a key-check algorithm that can potentially supplement the BIKE mechanism and prevent users from adopting weak-keys.
Mohammad Reza Nosouhi, Syed Wajid Ali Shah, Lei Pan 0002, Yevhen Zolotavkin, Ashish Nanda, Praveen Gauravaram, Robin Doss
IEEE Trans. Inf. Forensics Secur.4
2022 Improving Unlinkability of Attribute-based Authentication through Game Theory
abstract
This article first formalizes the problem of unlinkable attribute-based authentication in the system where each user possesses multiple assertions and uses them interchangeably. Currently, there are no recommendations for optimal usage of assertions in such authentication systems. To mitigate this issue, we use conditional entropy to measure the uncertainty for a Relying Party who attempts to link observed assertions with user labels. Conditional entropy is the function of usage statistics for all assertions in the system. Personaldecisionsmade by the users about the usage of assertions contribute to these statistics. This collective effect from all the users impacts the unlinkability of authentication and must be studied using game theory. We specify several instances of the game where context information that is provided to the users differs. Through game theory and based on conditional entropy, we demonstrate how each user optimizes usage for the personal set of assertions. In the experiment, we substantiate the advantage of the proposed rational decision-making approaches: Unlinkability that we obtain under Nash equilibrium is higher than in the system where users authenticate using their assertions at random. We finally propose an algorithm that calculates equilibrium and assists users with the selection of assertions. This manifests that described techniques can be executed in realistic settings. This does not require modification of existing authentication protocols and can be implemented in platform-independent identity agents. As a use case, we describe how our technique can be used in Digital Credential Wallets: We suggest that unlinkability of authentication can be improved for Verifiable Credentials.
Yevhen Zolotavkin, Jongkil Jeong, Veronika Kuchta, Maksym Slavnenko, Robin Doss
ACM Trans. Priv. Secur.1
2021 Evaluating the Current State of Application Programming Interfaces for Verifiable Credentials
abstract
One of the challenges to the adoption of the decentralised approach to digital ID is a lack of consensus and standardisation of how different stakeholders within the ecosystem can inter-operate. As a means to address this issue, we examine the use of standard application programming interfaces (API) to integrate decentralised digital identification systems to preexisting ones. We first examine the current literature and solutions to (a) assess the attributes necessary to compare and contrast APIs, and (b) create a list of API providers within the decentralised digital ID marketplace, (c) compare the API providers against the attributes established. Based on an API Usability and Adoption framework as our lens, we assessed 19 service providers of APIs against their use cases. We identified that whilst the APIs are maturing, the APIs remain inconsistent and poorly adopted. A clear standard API could assist in better adoption. The guidance provided can inform organisations implementing digital identity and VCs along their adoption journey
Nikesh Lalchandani, Frank Jiang 0001, Jongkil Jeong, Yevhen Zolotavkin, Robin Doss
PST4
2021 Enhancing Privacy Through DMMA: Decision-Making Method for Authentication
abstract
Attribute-Based Authentication (ABA) is becoming more prevalent in everyday interactions. In this paper, we propose the Decision-Making Method for Authentication (DMMA) to address the privacy concerns in ABA. The need for DMMA is supported through multiple observations. First, in practice, the indistinguishability of crypto-proof-based assertions (that are posessed by different users) fails with non-zero probability. This explains why cryptographic means alone are insufficient to provide a substantial level of unlinkability in ABA systems with n users. Second, each user in ABA possesses multiple credentials: they can be used interchangeably to get access to the service(s) which is provided by a relying party (RP). DMMA addresses the challenge of interchangeable usage. As an initial step, we synthesized the criterion of unlinkability: it is based on the definitions of international standard ISO 27551 as well as the information theoretic measure of conditional entropy. We then use that criterion to formalize the task of authentication as a non-cooperative coordination game. In this game, players (targets of the attack) maximize their utilities by using their assertions interchangeably. The experiment demonstrates that a number of equilibria with substantially higher unlinkability can be achieved. Unlinkability vary depending on: i) the information (and its trustworthiness) about the moves of the other players in the game; ii) the statistical distribution of user attributes. DMMA demonstrates how users may be provided recommendations over the optimal selection of assertions for ABA. These recommendations can have a practical impact if DMMA is implemented as a feature within Digital Credential Wallets (DCWs).
Maksym Slavnenko, Yevhen Zolotavkin, Jongkil Jeong, Veronika Kuchta, Robin Doss
TrustCom2
2020 Game Theoretic Analysis of Reputation Approach on Block Withholding Attack
Lianyang Yu, Jiangshan Yu, Yevhen Zolotavkin
NSS3
2019 Time-Dependent Decision-Making and Decentralization in Proof-of-Work Cryptocurrencies
abstract
Pool mining is a common way to reduce income variance for miners in Proof of Work Cryptocurrencies. A vast majority of mining does happen in pools, where a popular scheme to distribute rewards is Pay per last N Shares (PPLNS). In PPLNS and related schemes, miners are frequently making decisions whose rewards are not immediate and will only manifest in the future. This implies that models of inter-temporal utility are relevant when considering the incentives of miners. We show that when including these features of human behaviour in models of rational pool miners, the conditions that lead to decentralisation are hampered because larger pools may be more attractive to miners. We present a new game theoretical model of PPLNS where rational miners have time preferences. In this setup, the incentives of miners to work for a pool depend on the initial distribution of power between mining pools, as well as the specific details of how time is discounted. Agents jumping to larger pools face a trade-off between reducing the expected payoff from their shares in their current pool, or getting faster rewards in the future by joining a larger pool. We consider a case where pools of different mining power have the same size of reward window N. According to our study, in equilibrium larger pools have a tendency to accumulate a disproportionate share of the network power at the expense of smaller pools. This outcome is prevalent over a large range of realistic model parameters. Our model shows that PPLNS may be harmful to the decentralised governance of cryptocurrencies. A way to ameliorate these negative effects, is to encourage pools to have diverse window sizes, or use different reward mechanisms. Doing this in a decentralised fashion is an open challenge.
Yevhen Zolotavkin, Julián García, Joseph K. Liu
CSF1
2019 Incentives for Harvesting Attack in Proof of Work Mining Pools
Yevhen Zolotavkin, Veronika Kuchta
ESORICS (1)1
2019 Incentives for Stable Mining in Pay Per Last N Shares Pools
abstract
A large number of blockchain consensus protocols 7 use the Proof of Work (PoW) principle, which relies on miners who exchange computation for newly minted currency. Their) task is to support consensus, safeguarding the immutability of the chain's history. For the sake of regular income, a vast majority of miners team-up in large independent pools. These pools distribute among all their members the rewards gathered from individual miners, thus guaranteeing a stable income for each miner in the pool. The monetary compensation follows a specific reward system enforced by the pool administrator. Pay Per Last N Shares (PPLNS) is one of the most popular reward systems in PoW pools. Despite many desirable properties, in this paper, we show that composition of PPLNS pools may be unstable. To better understand the incentives of miners, we explore the effect of time preferences in the mining decisions of miners. Using a) game-theoretical model we study conditions for equilibrium in a) game with two different PPLNS pools. We find that the range of parameters that support equilibria between the pools with large number of miners is minuscule. This implies that in many cases, miners may have incentives to migrate towards larger pools, harming decentralization in the process.
Yevhen Zolotavkin, Julián García
Networking1
2013 SVD-based Digital Image Watermarking on approximated Orthogonal Matrix
Yevhen Zolotavkin, Martti Juhola
SECRYPT1