EDBT 2026 Demo / reviewers in the wild / expert
Amir Sharif
dblp:193/0245
· DBLP profile ↗
16ranked-venue papers
7as first author
11since 2021 · last 2026
0000-0001-6290-3588ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 4 first-author · 11 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 1 first-authorArtificial intelligence and machine learning · 2 · 2 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Best current practices for privacy-preserving OpenID Connect: A study of their adoption in the wildabstractThe transition from centralized identity architecture to a decentralized one introduces profound shifts in the privacy protection of users’ data. Yet, as decentralized identity continues to mature, today’s online services still overwhelmingly depend on centralized and federated identity management solutions built on top of OpenID Connect (OIDC) as the most widespread solution. Ensuring privacy-preserving OIDC deployments is therefore critical for safeguarding users’ personal data and maintaining compliance with regulatory frameworks such as the General Data Protection Regulation (GDPR) and trust frameworks such as the Electronic Identification, Authentication and Trust Services (eIDAS). However, the current OIDC ecosystem lacks a coherent set of privacy Best Current Practices (BCPs) and a study of how widely these privacy-enhancing features are adopted in real-world deployments. To this end, this work addresses the aforementioned gaps on two fronts. First, we propose a structured set of privacy BCPs derived from official OIDC specifications and current implementation trends, identifying easy-to-deploy privacy-enhancing features that strengthen the OIDC deployments’ baseline privacy without altering the protocol or compromising interoperability. Furthermore, the BCPs also help achieve the GDPR privacy principles, such as data minimization, confidentiality, and unlinkability. Second, this work provides a comprehensive survey of OpenID Providers (OPs) in the wild to identify gaps in privacy-preserving configurations in both private and public (i.e., national) sectors OPs. The study employs a dual methodology: first, a manual review performed in 2022; subsequently, an automated compliance analysis performed in 2025 surveying a dataset of 10000 OPs worldwide. The results reveal a concerning lack of privacy-enhancing features among private OPs and a wide gap between private and national OPs, with the latter group providing, on average, much higher baseline privacy. We have also found a prevalence of OPs not complying with the OIDC specifications, resulting in misconfigured OPs hampering interoperability and, in some cases, security. The paper emphasizes the importance of adopting actionable BCPs to improve baseline privacy and demonstrates the need for an automated framework for ongoing privacy compliance assessments in OIDC ecosystems. Gianluca Sassetti, Amir Sharif, Giada Sciarretta, Roberto Carbone, Silvio Ranise |
Comput. Secur. | 2 |
| 2025 | Secure and Reliable Digital Wallets: A Threat Model for Secure Storage in eIDAS 2.0
Zahra Ebadi Ansaroudi, Amir Sharif, Giada Sciarretta, Francesco Antonio Marino, Silvio Ranise |
DBSec | 2 |
| 2025 | Enhancing National Digital Identity Systems: A Framework for Institutional and Technical Harm Prevention Inspired by Microsoft's Harms Modeling
Giovanni Corti, Gianluca Sassetti, Amir Sharif, Roberto Carbone, Silvio Ranise |
SECRYPT | 3 |
| 2024 | Protecting Digital Identity Wallet: A Threat Model in the Age of eIDAS 2.0
Amir Sharif, Zahra Ebadi Ansaroudi, Giada Sciarretta, Daniela Pöhn, Majid Mollaeefar, Wolfgang Hommel, Silvio Ranise |
CRiSIS | 1 |
| 2024 | On cryptographic mechanisms for the selective disclosure of verifiable credentialsabstractVerifiable credentials are a digital analogue of physical credentials. Their authenticity and integrity are protected by means of cryptographic techniques, and they can be presented to verifiers to reveal attributes or even predicates about the attributes included in the credential. One way to preserve privacy during presentation consists in selectively disclosing the attributes in a credential. In this paper we present the most widespread cryptographic mechanisms used to enable selective disclosure of attributes identifying two categories: the ones based on hiding commitments - e.g., mdl ISO/IEC 18013-5 - and the ones based on non-interactive zero-knowledge proofs - e.g., BBS signatures. We also include a description of the cryptographic primitives used to design such cryptographic mechanisms. We describe the design of the cryptographic mechanisms and compare them by performing an analysis on their standard maturity in terms of standardization, cryptographic agility and quantum safety, then we compare the features that they support with main focus on the unlinkability of presentations, the ability to create predicate proofs and support for threshold credential issuance. Finally we perform an experimental evaluation based on the Rust open source implementations that we have considered most relevant. In particular we evaluate the size of credentials and presentations built using different cryptographic mechanisms and the time needed to generate and verify them. We also highlight some trade-offs that must be considered in the instantiation of the cryptographic mechanisms. Andrea Flamini, Giada Sciarretta, Mario Scuro, Amir Sharif, Alessandro Tomasi 0001, Silvio Ranise |
J. Inf. Secur. Appl. | 4 |
| 2023 | Cross-Domain Sharing of User Claims: A Design Proposal for OpenID Connect Attribute AuthoritiesabstractAn Attribute Authority is an entity responsible for establishing, maintaining, and sharing a subject’s qualified attributes, such as titles and qualifications. In the OpenID Connect digital identity ecosystem, In the OpenID Connect digital identity ecosystem, for privacy reasons, this entity is distinct from Identity Providers that manage only the basic identity profile information. A relevant scenario is as follows: the User first logs in to an online service using his/her identity managed by an Identity Provider. Then, the online service asks the Attribute Authority for the additional User’s attributes (e.g., entitlements) before granting access to its resources. In some high-sensitive cases, an Attribute Authority needs proof of the User’s authentication before releasing the User’s attributes to the online service. The challenge of this scenario involving usability, security, and privacy requirements lies in finding the right mechanism to share (the minimum and necessary set of) claims of the User who is currently authenticated with the online service across multiple domains without requiring his or her re-authentication. In this paper, we present the design of two solutions based on OpenID Connect to share User claims across domains. We provide security and privacy analysis for the two solutions and a brief comparison between them. Amir Sharif, Francesco Antonio Marino, Giada Sciarretta, Giuseppe De Marco, Roberto Carbone, Silvio Ranise |
ARES | 1 |
| 2023 | Assurance, Consent and Access Control for Privacy-Aware OIDC Deployments
Gianluca Sassetti, Amir Sharif, Giada Sciarretta, Roberto Carbone, Silvio Ranise |
DBSec | 2 |
| 2023 | A First Appraisal of Cryptographic Mechanisms for the Selective Disclosure of Verifiable Credentials
Andrea Flamini, Silvio Ranise, Giada Sciarretta, Mario Scuro, Amir Sharif, Alessandro Tomasi 0001 |
SECRYPT | 5 |
| 2022 | SoK: A Survey on Technological Trends for (pre)Notified eIDAS Electronic Identity SchemesabstractThe eIDAS Regulation aims to provide an interoperable European framework to enable EU citizens to authenticate and communicate with services of other Member States by using their national electronic identity. While a set of high-level requirements (e.g., related to privacy and security) are established to make interoperability among Member States possible, the eIDAS Regulation does not explicitly specify the technologies that can be adopted during the development phase to meet the requirements as mentioned earlier. This paper considers the technological trends of (pre)notified eIDAS electronic identity schemes used by Member States, and they satisfy the eIDAS regulation requirements. We do this by defining a set of research questions that allow us to investigate the correlations between different design dimensions such as security, privacy, and usability. Based on these findings, we provide a set of lessons learned that can be used by the security community to protect interoperable national digital identities more efficiently. Amir Sharif, Matteo Ranzi, Roberto Carbone, Giada Sciarretta, Silvio Ranise |
ARES | 1 |
| 2022 | Best current practices for OAuth/OIDC Native Apps: A study of their adoption in popular providers and top-ranked Android clients
Amir Sharif, Roberto Carbone, Giada Sciarretta, Silvio Ranise |
J. Inf. Secur. Appl. | 1 |
| 2021 | Automated Risk Assessment and What-if Analysis of OpenID Connect and OAuth 2.0 Deployments
Salimeh Dashti, Amir Sharif, Roberto Carbone, Silvio Ranise |
DBSec | 2 |
| 2019 | Locomotion Mode Selection Plus (LMS+) Algorithm for Resource Efficient Outdoor Navigation
Amir Sharif, Hubert Roth |
ICINCO (2) | 1 |
| 2018 | Energy Efficient Path Planning of Hybrid Fly-Drive Robot (HyFDR) using A* Algorithm
Amir Sharif, H. M. Lahiru, S. Herath, Hubert Roth |
ICINCO (2) | 1 |
| 2017 | A novel encryption scheme for colored image based on high level chaotic maps
Majid Mollaeefar, Amir Sharif, Mahboubeh Nazari |
Multim. Tools Appl. | 2 |
| 2017 | An improved method for digital image fragile watermarking based on chaotic maps
Mahboubeh Nazari, Amir Sharif, Majid Mollaeefar |
Multim. Tools Appl. | 2 |
| 2017 | A novel method for digital image steganography based on a new three-dimensional chaotic map
Amir Sharif, Majid Mollaeefar, Mahboubeh Nazari |
Multim. Tools Appl. | 1 |