EDBT 2026 Demo / reviewers in the wild / expert
Shabnam Kasra Kermanshahi
dblp:157/5255
· DBLP profile ↗
14ranked-venue papers
7as first author
11since 2021 · last 2025
0000-0002-7928-0636ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 6 first-author · 9 since 2021Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | A Verifiable and Efficient Symmetric Searchable Encryption Scheme for Dynamic Dataset With Forward and Backward PrivacyabstractThe adoption of symmetric searchable encryption (SSE) has become increasingly common. However, many current SSE schemes assume an honest-but-curious cloud service provider (CSP) or necessitate significant overhead to manage a malicious CSP. Furthermore, most of these schemes are tailored for static datasets. Our paper presents an efficient SSE scheme that aims to address these challenges. To the best of our knowledge, this is the first scheme that supports dynamic datasets with forward and backward privacy, integrity verification of non-empty and empty search results, efficient search, non-interactive, light client, and both forward and inverted indexes simultaneously. In this paper, we present two novel approaches, Hexie and Jianding. Hexie implements secret sharing to conceal index entries, enabling dynamic updates, non-interactive interactions, and lightweight clients. To enhance the reliability of search results and address the problem of empty, incomplete, or inaccurate outcomes, we introduce the Jianding scheme as an extension of Hexie. It combines a chained MAC structure with a secret sharing scheme, which enables a client to verify the data integrity of the search result efficiently. Moreover, we propose graph-based dictionary sharding to enhance search efficiency. Finally, we conduct comprehensive experiments to validate the effectiveness of the proposed schemes. Xiaojie Zhu, Jiancong Zhou, Yueyue Dai, Peisong Shen, Shabnam Kasra Kermanshahi, Jiankun Hu |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2024 | On Sealed-Bid Combinatorial Auction with Privacy-Preserving Dynamic Programming
Hong-Yen Tran, Jiankun Hu, Shabnam Kasra Kermanshahi |
ProvSec (2) | 3 |
| 2024 | Experimental Demonstration of Risks and Influences of Cyber Attacks on Wireless Communication in MicrogridsabstractThe Microgrid allows for more efficient and lower-cost power provisions, and is therefore more flexible than traditional power ecosystems. However, the increasingly integrated nature of these systems into network and internet-connected IT systems also potentially makes them susceptible to cyber-attack. This paper examined different challenges related to the cyber attacks threatening wireless microgrid systems from the experimental view. Wireless communication and transmission methods are widely used for secondary control of energy re-sources. However, there are risks of cyber attacks during the communication process, such as Denial-of-Service (DoS) attacks. This paper reports the investigation of potential cyber attacks on wireless communications of microgrid systems. Furthermore, this paper evaluates the practical impacts of cybersecurity breaches targeting microgrid systems, with special attention to those in Australia. In brief, the main goal of this paper is to enhance the mitigation countermeasures for cyber attacks linked to wireless microgrid systems, thus guaranteeing reliable wireless communications within these systems. Zhibo Zhang 0002, Jiankun Hu, Hemanshu Roy Pota, Shabnam Kasra Kermanshahi, Benjamin P. Turnbull, Ernesto Damiani, Chan Yeob Yeun |
PST | 4 |
| 2024 | Securely sharing outsourced IoT data: A secure access and privacy preserving keyword search schemeabstractThe rapid progress in the field of IoT and its wide-ranging applications emphasize the criticality of robust security measures for effectively sharing, storing, and managing sensitive data generated by IoT devices. Regulations such as the Consumer Data Rights (CDR) highlight the need for the seamless sharing of sensitive data with authorized third parties while ensuring confidentiality and privacy. To enable such secure sharing, a data storage and sharing scheme should fulfill the following core requirements: (a) support multi-client data sharing settings, allowing IoT data owners to authorize multiple clients; (b) a dynamic storage environment permitting IoT owners to add or remove files with minimal privacy leak; (c) decentralized storage for distributing data across servers or Cloud Service Providers (CSPs) for greater security; and (d) efficient privilege revocation mechanism which incurs less computation and communication overhead. To address these requirements, we have proposed a novel keyword search scheme using computationally lightweight cryptographic primitives. Our scheme empowers IoT data owners to securely share, store and manage encrypted data in the CSPs, providing better security and privacy. We have provided formal security proof for our scheme as well as validated its efficiency via extensive experiments on the Docker platform. On a database of 12 million keyword/document pairs (with 105 documents and 103 keywords), our scheme took about 18 ms to return all matched documents. Nazatul Haque Sultan, Shabnam Kasra Kermanshahi, Hong-Yen Tran, Shangqi Lai, Vijay Varadharajan, Surya Nepal, Xun Yi |
Ad Hoc Networks | 2 |
| 2024 | Fast and private multi-dimensional range search over encrypted dataabstractFor businesses looking to outsource their data to remote servers, cloud-based data storage is a popular choice. It is popular due to its flexibility, cost-effectiveness, and widespread availability. However, ensuring the confidentiality of data is a critical challenge that must be addressed. As a response to this issue, searchable encryption techniques have been developed. These techniques enable search queries to be performed on encrypted data while still keeping the plaintext confidential. While most existing symmetric searchable encryption schemes are designed for one-dimensional data records or document-keyword inverted indices, this paper introduces MDRSSE, a novel symmetric searchable encryption scheme specifically tailored for multi-dimensional range search. MDRSSE stands out as one of the pioneering SSE schemes to support multi-dimensional range search efficiently, without incurring undetermined additional communication or computation costs. By employing a single round of communication between the client and server, MDRSSE enables an honest-but-curious server to respond to multi-dimensional range queries without gaining knowledge of the data records or revealing the search query. Notably, MDRSSE boasts the lowest overall search complexity compared to existing state-of-the-art symmetric searchable encryption schemes designed for multi-dimensional range search. Extensive experimental tests were conducted to validate the robustness and practicality of our proposed scheme. The results demonstrate that, for a dataset consisting of 100K records with 12 dimensions (with each leaf node holding 500 records), it takes only 2.2 seconds to generate the encrypted dataset, and the overall setup phase completes within 2.5 seconds. Furthermore, for a range query encompassing 50 nodes, the search time is less than 2 ms and 3 ms for the client and server, respectively. MDRSSE achieves semantic security under the IND-CPA assumption, all without requiring additional storage size at the server. Shabnam Kasra Kermanshahi, Ron Steinfeld, Xun Yi, Joseph K. Liu, Surya Nepal, Junwei Lou |
Inf. Sci. | 1 |
| 2022 | Post-Quantum Verifiable Random Function from Symmetric Primitives in PoS Blockchain
Maxime Buser, Rafael Dowsley, Muhammed F. Esgin, Shabnam Kasra Kermanshahi, Veronika Kuchta, Joseph K. Liu, Raphael C.-W. Phan, Zhenfei Zhang |
ESORICS (1) | 4 |
| 2022 | Range search on encrypted spatial data with dynamic updatesabstractDriven by the cloud-first initiative taken by various governments and companies, it has become a common practice to outsource spatial data to cloud servers for a wide range of applications such as location-based services and geographic information systems. Searchable encryption is a common practice for outsourcing spatial data which enables search over encrypted data by sacrificing the full security via leaking some information about the queries to the server. However, these inherent leakages could equip the server to learn beyond what is considered in the scheme, in the worst-case allowing it to reconstruct of the database. Recently, a novel form of database reconstruction attack against such kind of outsourced spatial data was introduced (Markatou and Tamassia, IACR ePrint 2020/284), which is performed using common leakages of searchable encryption schemes, i.e., access and search pattern leakages. An access pattern leakage is utilized to achieve an order reconstruction attack, whereas both access and search pattern leakages are exploited for the full database reconstruction attack. In this paper, we propose two novel schemes for outsourcing encrypted spatial data supporting dynamic range search. Our proposed schemes leverage R+tree to partition the dataset and binary secret sharing to support secure range search. They further provide backward and content privacy and do not leak the access pattern, therefore being resilient against the above mentioned database reconstruction attacks. The evaluations and results on the real-world dataset demonstrate the practicality of our schemes, due to (a) the minimal round-trip between the client and server, and (b) the low computation and storage overhead on the client side. Shabnam Kasra Kermanshahi, Rafael Dowsley, Ron Steinfeld, Amin Sakzad, Joseph K. Liu, Surya Nepal, Xun Yi, Shangqi Lai |
J. Comput. Secur. | 1 |
| 2022 | Geometric Range Search on Encrypted Data With Forward/Backward SecurityabstractThis article presents two dynamic symmetric searchable encryption schemes for geometric range search. Our constructions are the first to provide forward/backward security in the context of SSE-based schemes supporting geometric range search. Besides, we define a security notion called content privacy. This security notion captures the leakages that are critical in the context of geometric range search but not considered by forward/backward security. Content privacy eliminates the leakage on the updated points of the database during both search and update. Due to the inherent leakages associated with range queries, none of the existing related works can support content privacy, whereas the design of our constructions avoids such leakages. When compared to the state-of-the-art schemes, our constructions provide a higher level of security and practical efficiency supported by our experimental results. Shabnam Kasra Kermanshahi, Shifeng Sun 0001, Joseph K. Liu, Ron Steinfeld, Surya Nepal, Wang Fat Lau, Man Ho Au |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2021 | Geo-DRS: Geometric Dynamic Range Search on Spatial Data with Backward and Content Privacy
Shabnam Kasra Kermanshahi, Rafael Dowsley, Ron Steinfeld, Amin Sakzad, Joseph K. Liu, Surya Nepal, Xun Yi |
ESORICS (2) | 1 |
| 2021 | A Non-interactive Multi-user Protocol for Private Authorised Query Processing on Genomic Data
Sara Jafarbeiki, Amin Sakzad, Shabnam Kasra Kermanshahi, Ron Steinfeld, Raj Gaire 0001, Shangqi Lai |
ISC | 3 |
| 2021 | Multi-Client Cloud-Based Symmetric Searchable EncryptionabstractWe propose a multi-client Symmetric Searchable Encryption (SSE) scheme based on the single-user protocol [3] . The scheme allows any user to generate a search query by interacting with any θ is a threshold parameter) `helping' users. It preserves the privacy of a database content against the server assuming a leakage of up to θ-1 users' keys to the server while hiding the query from the θ-1 `helping users'. To achieve the query privacy, we design a new distributed key-homomorphic pseudorandom function (PRF) that hides the PRF input (search keyword) from the `helping' users. We present a concrete construction of our randomizable distributed PRF. By distributing the utilized keys among the users, the need for a constant online presence of the data owner to provide services to the users is eliminated, while providing resilience against a user key exposure. We extended our scheme to support user revocation in two different scenarios. In addition, we give a solution for fast update of the encryption key with the overhead significantly smaller than the re-encryption and re-uploading the database. Moreover, our scheme is secure against passive and active collusion between the server and a subset of users. Shabnam Kasra Kermanshahi, Joseph K. Liu, Ron Steinfeld, Surya Nepal, Shangqi Lai, Randolph Loh, Cong Zuo 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2019 | Generic Multi-keyword Ranked Search on Encrypted Cloud Data
Shabnam Kasra Kermanshahi, Joseph K. Liu, Ron Steinfeld, Surya Nepal |
ESORICS (2) | 1 |
| 2019 | Chameleon Hash Time-Lock Contract for Privacy Preserving Payment Channel Networks
Bin Yu 0009, Shabnam Kasra Kermanshahi, Amin Sakzad, Surya Nepal |
ProvSec | 2 |
| 2017 | Multi-user Cloud-Based Secure Keyword Search
Shabnam Kasra Kermanshahi, Joseph K. Liu, Ron Steinfeld |
ACISP (1) | 1 |