Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Breno de Medeiros

dblp:17/3069 · DBLP profile ↗
← Back
13ranked-venue papers
0as first author
0since 2021 · last 2014
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 12Computer networks · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
5 papers
Authentication and access control · 38% Cryptographic primitives and cryptanalysis · 31% Network security · 25%
Computer networks
1 paper
Routing and switching · 100%
Databases, data mining, and information retrieval
1 paper
Data mining · 100%

Topics — the 15 heaviest of 15, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Network security › covert channel
covert channel attacks
0.112009
On the Security of Route Discovery in MANETs · IEEE Trans. Mob. Comput. 2009
Authentication and access control
password guessing
0.112009
Password Cracking Using Probabilistic Context-Free Grammars · SP 2009
Authentication and access control
password security
0.112009
Password Cracking Using Probabilistic Context-Free Grammars · SP 2009
Authentication and access control › password guessing
probabilistic context-free grammar
0.112009
Password Cracking Using Probabilistic Context-Free Grammars · SP 2009
Network security
routing security
0.112009
On the Security of Route Discovery in MANETs · IEEE Trans. Mob. Comput. 2009
Cryptographic primitives and cryptanalysis
security analysis
0.112009
On the Security of Route Discovery in MANETs · IEEE Trans. Mob. Comput. 2009
Cryptographic primitives and cryptanalysis
encryption
0.112005
Untraceable RFID tags via insubvertible encryption · CCS 2005
Cryptographic primitives and cryptanalysis › public-key cryptography
digital signatures
0.012003
Efficient Group Signatures without Trapdoors · ASIACRYPT 2003
Cryptographic primitives and cryptanalysis › public-key cryptography › digital signatures
group signature
0.012003
Efficient Group Signatures without Trapdoors · ASIACRYPT 2003
Cryptographic protocols and secure computation › fair exchange
certified email
0.012001
TRICERT: A Distributed Certified E-Mail Scheme · NDSS 2001
Data mining
probabilistic model
0.012009
Password Cracking Using Probabilistic Context-Free Grammars · SP 2009
Routing and switching
ad hoc network routing
0.012009
On the Security of Route Discovery in MANETs · IEEE Trans. Mob. Comput. 2009
Routing and switching › routing protocol
route discovery
0.012009
On the Security of Route Discovery in MANETs · IEEE Trans. Mob. Comput. 2009
Privacy and data protection › social network privacy
tag privacy
0.012005
Untraceable RFID tags via insubvertible encryption · CCS 2005
Distributed systems
fault tolerance
0.012001
TRICERT: A Distributed Certified E-Mail Scheme · NDSS 2001

Methods — techniques the papers use, named apart from their topics

security model analysis · 0.2probabilistic context-free grammar · 0.2dictionary attack · 0.2composability analysis · 0.2cryptographic protocols · 0.1universal re-encryption · 0.1certificates · 0.1trapdoor-free constructions · 0.0
YearPublicationVenuePosition
2014 Certified Bitcoins
Giuseppe Ateniese, Antonio Faonio, Bernardo Magri, Breno de Medeiros
ACNS4
2009 Password Cracking Using Probabilistic Context-Free Grammars
abstract
Choosing the most effective word-mangling rules to use when performing a dictionary-based password cracking attack can be a difficult task. In this paper we discuss a new method that generates password structures in highest probability order. We first automatically create a probabilistic context-free grammar based upon a training set of previously disclosed passwords. This grammar then allows us to generate word-mangling rules, and from them, password guesses to be used in password cracking. We will also show that this approach seems to provide a more effective way to crack passwords as compared to traditional methods by testing our tools and techniques on real password sets. In one series of experiments, training on a set of disclosed passwords, our approach was able to crack 28% to 129% more passwords than John the Ripper, a publicly available standard password cracking program.
Matt Weir, Sudhir Aggarwal, Breno de Medeiros, Bill Glodek
SP3
2009 Universally Composable RFID Identification and Authentication Protocols
abstract
As the number of RFID applications grows, concerns about their security and privacy become greatly amplified. At the same time, the acutely restricted and cost-sensitive nature of RFID tags rules out simple reuse of traditional security/privacy solutions and calls for a new generation of extremely lightweight identification and authentication protocols. This article describes a universally composable security framework designed especially for RFID applications. We adopt RFID-specific setup, communication, and concurrency assumptions in a model that guarantees strong security, privacy, and availability properties. In particular, the framework supports modular deployment, which is most appropriate for ubiquitous applications. We also describe a set of simple, efficient, secure, and anonymous (untraceable) RFID identification and authentication protocols that instantiate the proposed framework. These protocols involve minimal interaction between tags and readers and place only a small computational load on the tag, and a light computational burden on the back-end server. We show that our protocols are provably secure within the proposed framework.
Mike Burmester, Tri Van Le, Breno de Medeiros, Gene Tsudik
ACM Trans. Inf. Syst. Secur.3
2009 On the Security of Route Discovery in MANETs
abstract
Mobile ad hoc networks (MANETs) are collections of wireless mobile devices with restricted broadcast range and resources, and no fixed infrastructure. Communication is achieved by relaying data along appropriate routes that are dynamically discovered and maintained through collaboration between the nodes. Discovery of such routes is a major task, both from efficiency and security points of view. Recently, a security model tailored to the specific requirements of MANETs was introduced by Acs, Buttyan, and Vajda. Among the novel characteristics of this security model is that it promises security guarantee under concurrent executions, a feature of crucial practical implication for this type of distributed computation. A novel route discovery algorithm called endairA was also proposed, together with a claimed security proof within the same model. In this paper, we show that the security proof for the route discovery algorithm endairA is flawed, and moreover, this algorithm is vulnerable to a hidden channel attack. We also analyze the security framework that was used for route discovery and argue that composability is an essential feature for ubiquitous applications. We conclude by discussing some of the major security challenges for route discovery in MANETs.
Mike Burmester, Breno de Medeiros
IEEE Trans. Mob. Comput.2
2008 The Security of EPC Gen2 Compliant RFID Protocols
Mike Burmester, Breno de Medeiros
ACNS2
2008 Provably Secure Grouping-Proofs for RFID Tags
Mike Burmester, Breno de Medeiros, Rossana Motta
CARDIS2
2008 Robust, anonymous RFID authentication with constant key-lookup
abstract
A considerable number of anonymous RFID authentication schemes have been proposed. However, current proposals either do not provide robust security guarantees, or suffer from scalability issues when the number of tags issued by the system is very large. In this paper, we focus on approaches that reconcile these important requirements. In particular, we seek to reduce the complexity of identifying tags by the back-end server in anonymous RFID authentication protocols---what we term the key-lookup problem.
Mike Burmester, Breno de Medeiros, Rossana Motta
AsiaCCS2
2007 Universally composable and forward-secure RFID authentication and authenticated key exchange
abstract
Recently, a universally composable framework for RFID authentication protocols providing availability, anonymity, and authenticity was proposed. In this paper we extend that framework to address forward-security issues in the presence of key compromise.We also introduce new, provably secure, and highly practical protocols for anonymous authentication and key-exchange by RFID devices. The new protocols are lightweight, requiring only a pseudo-random bit generator. The new protocols satisfy forward-secure anonymity, authenticity, and availability requirements in the Universal Composability model.
Tri Van Le, Mike Burmester, Breno de Medeiros
AsiaCCS3
2006 Towards Provable Security for Ubiquitous Applications
Mike Burmester, Tri Van Le, Breno de Medeiros
ACISP3
2005 Untraceable RFID tags via insubvertible encryption
abstract
We introduce a new cryptographic primitive, called insubvertible encryption, that produces ciphertexts which can be randomized without the need of any key material. Unlike plain universal re-encryption schemes, insubvertible encryption prevents against adversarial exploitation of hidden channels, by including certificates proving that the ciphertext can only be decrypted by authorized parties.The scheme can be applied to RFID tags, providing strong protection against tracing. This enables post-sale applications of manufacturer-issued RFID tags while preserving the privacy of consumers. The functionality required of the RFID tags is minimal, namely that they be re-writable (many-writable). No cryptographic capabilities are required of the tags themselves, as the readers perform all necessary computations.
Giuseppe Ateniese, Jan Camenisch, Breno de Medeiros
CCS3
2005 Sanitizable Signatures
Giuseppe Ateniese, Daniel H. Chou, Breno de Medeiros, Gene Tsudik
ESORICS3
2003 Efficient Group Signatures without Trapdoors
Giuseppe Ateniese, Breno de Medeiros
ASIACRYPT2
2001 TRICERT: A Distributed Certified E-Mail Scheme
Giuseppe Ateniese, Breno de Medeiros, Michael T. Goodrich
NDSS2