Jan Willemson

dblp:22/101 · DBLP profile ↗
← Back
26ranked-venue papers
4as first author
5since 2021 · last 2025
0000-0002-6290-2099ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 24 · 4 first-author · 5 since 2021Artificial intelligence and machine learning · 1Computer networks · 1
YearPublicationVenuePosition
2025 Lattice-Based Zero-Knowledge Proofs in Action: Applications to Electronic Voting
abstract
Abstract This paper studies several building blocks needed for electronic voting in order to prepare for the post-quantum era. In particular, we present lattice-based constructions for a generic zero-knowledge (ZK) proof of ballot correctness, a ZK proof of ballot correctness applicable for the homomorphic tallying scenario, and a ZK proof to achieve cast-as-intended verification during the vote casting period. We implement and benchmark our ballot correctness proofs, giving concrete estimations comparing the performance of homomorphic tallying and mix-net based e-voting systems in case of our lattice-based constructions.
Valeh Farzaliyev, Calvin Pärn, Heleen Saarse, Jan Willemson
J. Cryptol.4
2024 Open-Source Post-Quantum Encryptor: Design, Implementation and Deployment
abstract
This article describes an open-source quantum-resistant network traffic encryptor for the Linux platform. Our encryptor uses a combination of quantum and post-quantum key establishment methods to achieve quantum resistance combined with a fast encryption speed of AES to make quantum-resistant encryption readily available to the public. The packet-by-packet encryption architecture ensures that every bit of information is properly authenticated and encrypted. The combination of multiple key sources further increases the encryptor’s security – be it elliptic curve-based (Elliptic Curve Diffie Hellman, ECDH), quantum (Quantum Key Distribution, QKD) or post-quantum (CRYSTALS-Kyber). Without knowing all the keys obtained from different types of key sources, the final hybrid encryption key can only be obtained by brute-force means. Our contribution is very practical as the encryptor has reasonable performance, despite not being part of the Linux kernel.
Petr Tuma 0004, Jan Hajny, Petr Muzikant, Jan Havlin, Lukas Malina, Patrik Dobias, Jan Willemson
SECRYPT7
2023 Creating a Decryption Proof Verifier for the Estonian Internet Voting System
abstract
This paper describes the efforts made for and lessons learnt from creating a decryption proof verifier for the Estonian IVXV Internet voting system. Our main conclusion is that cryptographic protocols aiming at providing transparency through verifiability should also take into account a non-functional requirement of low implementation complexity. We identify several steps of the verification protocol that could be made easier to implement without sacrificing security. A side-product of our effort is a fully functional IVXV decryption proof verifier written in Go that we used during the latest Estonian parliamentary elections of March 2023.
Jan Willemson
ARES1
2023 Improved lattice-based mix-nets for electronic voting
abstract
Abstract Mix‐networks were first proposed by Chaum in the late 1970s–early 1980s as a general tool for building anonymous communication systems. Classical mix‐net implementations rely on standard public key primitives (e.g., ElGamal encryption) that will become vulnerable when a sufficiently powerful quantum computer will be built. Thus, there is a need to develop quantum‐resistant mix‐nets. This article focuses on the application case of electronic voting where the number of votes to be mixed may reach hundreds of thousands or even millions. We propose an improved architecture for lattice‐based post‐quantum mix‐nets featuring more efficient zero‐knowledge proofs while maintaining established security assumptions. Our current implementation scales up to 100,000 votes, still leaving a lot of room for future optimisation.
Valeh Farzaliyev, Jan Willemson, Jaan Kristjan Kaasik
IET Inf. Secur.2
2022 Relations Between Privacy, Verifiability, Accountability and Coercion-Resistance in Voting Protocols
Alisa Pankova, Jan Willemson
ACNS2
2019 Is Your Vote Overheard? A New Scalable Side-Channel Attack Against Paper Voting
abstract
In an ongoing discussion comparing the security properties of electronic and paper voting, decreased privacy is often presented as an argument against remote Internet voting. We contribute to this discussion by presenting a side-channel attack against the physical environment of traditional paper-based elections. More precisely, we build a device based on an Arduino development board and cheap electret microphones, capable of triangulating the locations of marks made on wooden tables with high precision. In the best configuration, we are able to determine the correct cell having dimensions 4×5 cm with more than 90% accuracy. This will allow breaching privacy of ballot sheet designs that rely on the voter marking her choice(s) between a potentially high number of candidates printed on one large sheet. We complement our attack with a study on various aspects of deployment of facial recognition. This gives rise to the setup where the attacker installs cameras in the polling stations, aiming at automated detection of people leaving the voting booths. Combining the two approaches, we will have a completely automated (and hence relatively well scalable) attack against the privacy of paper-based voting.
Kristjan Krips, Jan Willemson, Sebastian Värv
EuroS&P2
2018 Bits or paper: Which should get to carry your vote?
Jan Willemson
J. Inf. Secur. Appl.1
2016 Alternative Implementations of Secure Real Numbers
abstract
This paper extends the choice available for secure real number implementations with two new contributions. We will consider the numbers represented in form a-φ b where φ is the golden ratio, and in form (-1)s.2e where e is a fixed-point number. We develop basic arithmetic operations together with some frequently used elementary functions. All the operations are implemented and benchmarked on SHAREMIND secure multi-party computation framework. It turns out that the new proposals provide viable alternatives to standard floating- and fixed-point implementations from the performance/error viewpoint in various settings. However, the optimal choice still depends on the exact requirements of the numerical algorithm to be implemented.
Vassil S. Dimitrov, Liisi Kerik, Toomas Krips, Jaak Randmets, Jan Willemson
CCS5
2016 Privacy Protection for Wireless Medical Sensor Data
abstract
In recent years, wireless sensor networks have been widely used in healthcare applications, such as hospital and home patient monitoring. Wireless medical sensor networks are more vulnerable to eavesdropping, modification, impersonation and replaying attacks than the wired networks. A lot of work has been done to secure wireless medical sensor networks. The existing solutions can protect the patient data during transmission, but cannot stop the inside attack where the administrator of the patient database reveals the sensitive patient data. In this paper, we propose a practical approach to prevent the inside attack by using multiple data servers to store patient data. The main contribution of this paper is securely distributing the patient data in multiple data servers and employing the Paillier and ElGamal cryptosystems to perform statistic analysis on the patient data without compromising the patients' privacy.
Xun Yi, Athman Bouguettaya, Dimitrios Georgakopoulos 0001, Andy Song, Jan Willemson
IEEE Trans. Dependable Secur. Comput.5
2014 Hybrid Model of Fixed and Floating Point Numbers in Secure Multiparty Computations
Toomas Krips, Jan Willemson
ISC2
2014 A Secure Genetic Algorithm for the Subset Cover Problem and Its Application to Privacy Protection
Dan Bogdanov, Keita Emura, Roman Jagomägis, Akira Kanaoka, Shin'ichiro Matsuo, Jan Willemson
WISTP6
2013 From Oblivious AES to Efficient and Secure Database Join in the Multiparty Setting
Sven Laur, Riivo Talviste, Jan Willemson
ACNS3
2013 Protecting a Federated Database Infrastructure against Denial-of-Service Attacks
Arne Ansper, Ahto Buldas, Margus Freudenthal, Jan Willemson
CRITIS4
2013 Multiparty privacy protection for electronic health records
abstract
Recently, the amount of personal medical information online is increasing exponentially, opening up new avenues for hackers to expose personal data that, unlike financial information, can result in a permanent violation of privacy. To protect the privacy of patient data, such as electronic health records (EHRs), access control was used before and attributed-based encryption is used recently. These techniques can effectively prevent from the outside attacks, but are hard to withstand the inside attacks, where the database administrator or the key manager is an attacker. In this paper, we provide a solution to protect the privacy of patient data (EHRs) under the multi-party framework where all EHRs are encrypted with the common public key and an encrypted EHR can be decrypted only by the cooperation of all parties. Based on the ElGamal threshold public key encryption scheme, we propose several EHR access control protocols where multiple parties cooperate to control clinicians' access to EHRs without actually knowing EHRs. Our solution can protect the patient data against the inside attacks as long as at least one party can be trusted. Because our solution is built on Public Key Infrastructure (PKI), it facilitates the clinician registration and revocation.
Xun Yi, Yuan Miao 0001, Elisa Bertino, Jan Willemson
GLOBECOM4
2011 Round-Efficient Oblivious Database Manipulation
Sven Laur, Jan Willemson, Bingsheng Zhang
ISC2
2010 Extending the Gordon and Loeb Model for Information Security Investment
abstract
In this paper we study the information security investment model proposed by Gordon and Loeb. We argue that the original model is missing at least one important restriction concerning monotonicity of the remaining vulnerability viewed as a function of original vulnerability level, and propose adding the respective condition. We present a new family of remaining vulnerability functions satisfying all the conditions and generalizing all the currently known example function families.
Jan Willemson
ARES1
2010 On Fast and Approximate Attack Tree Computations
Aivo Kalu, Jan Willemson
ISPEC2
2008 A Secure and Scalable Infrastructure for Inter-Organizational Data Exchange and eGovernment Applications
abstract
As more and more information becomes accessible via on-line databases, more public services can be provided and more complex queries involving several registers become feasible as well. However, not all of the digitally stored data is public and thus strict access control mechanisms must be enforced. At the same time, in order to take full advantage of on-line data sources, high availability must be achieved as well. This paper describes an infrastructure developed in Estonia to satisfy these somewhat contradictory requirements. This infrastructure (called X- Road) enables different organizations to access each other's data and rely on it when taking legally binding decisions. We discuss technical details ofX-Road together with the issues arising when the infrastructure is to be implemented on national or international level.
Jan Willemson, Arne Ansper
ARES1
2008 Sharemind: A Framework for Fast Privacy-Preserving Computations
Dan Bogdanov, Sven Laur, Jan Willemson
ESORICS3
2006 Rational Choice of Security Measures Via Multi-parameter Attack Trees
Ahto Buldas, Peeter Laud, Jaan Priisalu, Märt Saarepera, Jan Willemson
CRITIS5
2005 Universally Composable Time-Stamping Schemes with Audit
Ahto Buldas, Peeter Laud, Märt Saarepera, Jan Willemson
ISC4
2003 Scalable and Efficient PKI for Inter-Organizational Communication
abstract
We propose an efficient and flexible system for a secure and authentic data exchange in a multiinstitutional environment, where the institutions maintain different databases and provide secure and limited access services to employees of other institutions. The main motivation for building such a system was to organize efficient cooperative use of state registers, in order to increase the efficiency and quality of public services in Estonia. In order to meet high security requirements, several contemporary measures are integrated (using digital signatures, distributing certificate information by means of DNS protocol and linking log files with cryptographic checksums). We give rationale for the design decisions made in the implementation process and conclude with the current state of public use of the resulting infrastructure.
Arne Ansper, Ahto Buldas, Margus Freudenthal, Jan Willemson
ACSAC4
2003 Covering the path space: a casebase analysis for mobile robot path planning
Maarja Kruusmaa, Jan Willemson
Knowl. Based Syst.2
2001 Improving the Availability of Time-Stamping Services
Arne Ansper, Ahto Buldas, Märt Saarepera, Jan Willemson
ACISP4
2000 Personal Security Environment on Palm PDA
abstract
Digital signature schemes are based on the assumption that the signing key is kept in secret. Ensuring that this assumption holds is one of the most crucial problems for all current digital signature applications. This paper describes the solution developed and prototyped by the authors - using a mobile computing device with a smart-card reader for creating digital signatures. We give an overview of several common settings for digital signature applications and the problems they have, also describing several frameworks for mobile security applications. A discussion about the choice of devices, design issues, concrete solutions and their security concerns follows. We conclude that although nothing can prevent careless private key handling, careful management is easier and more convenient when using our solution.
Margus Freudenthal, Sven Heiberg, Jan Willemson
ACSAC3
1998 Time-Stamping with Binary Linking Schemes
Ahto Buldas, Peeter Laud, Helger Lipmaa, Jan Willemson
CRYPTO4