EDBT 2026 Demo / reviewers in the wild / expert
Aikaterini Mitrokotsa
dblp:22/417 · also Katerina Mitrokotsa
· DBLP profile ↗
62ranked-venue papers
5as first author
19since 2021 · last 2026
0000-0002-7073-0258ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 46 · 2 first-author · 19 since 2021Computer networks · 7 · 1 first-authorArtificial intelligence and machine learning · 4Systems, architecture and hardware · 2Human-computer interaction and ubiquitous computing · 2 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Privacy-preserving Proximity Testing from Geometric Fuzzy MatchingabstractProximity testing is crucial to location-privacy applications, from discovering nearby friends to enabling UAV collision avoidance. In such settings, users must determine proximity without revealing their exact locations. This motivates privacy-preserving proximity testing (PPPT) protocols revealing only if the proximity condition holds, while hiding both parties' inputs. However, most existing PPPT protocols rely on strong assumptions (e.g., non-colluding servers) or require simultaneous interaction, limiting their practicality. Moreover, they typically define proximity using metric distances (e.g., Euclidean distance), failing to support richer membership queries for complex regions like buildings or parks. Florias Papadopoulos, Ioannis Katis, Aikaterini Mitrokotsa |
AsiaCCS | 3 |
| 2026 | Simulation Secure Quadratic Functional Encryption for Inner-Product and Quadratic Predicates
Wilson Tsuata, Subhranil Dutta, Aikaterini Mitrokotsa |
PKC (3) | 3 |
| 2025 | A Post-quantum Distributed OPRF from the Legendre PRF
Novak Kaluderovic, Nan Cheng 0002, Aikaterini Mitrokotsa |
ESORICS (2) | 3 |
| 2025 | Multi-Client Attribute-Based Unbounded Inner Product Functional Encryption, and More
Subhranil Dutta, Aikaterini Mitrokotsa, Tapas Pal, Jenit Tomy |
PKC (5) | 2 |
| 2025 | BUFFing Threshold Signature Schemes
Marc Fischlin, Aikaterini Mitrokotsa, Jenit Tomy |
PKC (3) | 2 |
| 2024 | Decentralized Private Stream Aggregation from Lattices
Uddipana Dowerah, Aikaterini Mitrokotsa |
ACNS (2) | 2 |
| 2024 | Nomadic: Normalising Maliciously-Secure Distance with Cosine Similarity for Two-Party Biometric AuthenticationabstractComputing the distance between two non-normalized vectors x and y, represented by Δ (x, y) and comparing it to a predefined public threshold τ is an essential functionality used in privacy-sensitive applications such as biometric authentication, identification, machine learning algorithms (e.g., linear regression, k-nearest neighbors, etc.), and typo-tolerant password-based authentication. Tackling a widely used distance metric, Nomadic studies the privacy-preserving evaluation of cosine similarity in a two-party (2PC) distributed setting. We illustrate this setting in a scenario where a client uses biometrics to authenticate to a service provider, outsourcing the distance calculation to two computing servers. In this setting, we propose two novel 2PC protocols to evaluate the normalising cosine similarity between non-normalised two vectors followed by comparison to a public threshold, one in the semi-honest and one in the malicious setting. Our protocols combine additive secret sharing with function secret sharing, saving one communication round by employing a new building block to compute the composition of a function f yielding a binary result with a subsequent binary gate. Overall, our protocols outperform all prior works, requiring only two communication rounds under a strong threat model that also deals with malicious inputs via normalisation. We evaluate our protocols in the setting of biometric authentication using voice, and the obtained results reveal a notable efficiency improvement compared to existing state-of-the-art works. Nan Cheng 0002, Melek Önen, Aikaterini Mitrokotsa, Oubaïda Chouchane, Massimiliano Todisco, Alberto Ibarrondo |
AsiaCCS | 3 |
| 2024 | Efficient Two-Party Secure Aggregation via Incremental Distributed Point FunctionabstractComputing the maximum from a list of secret inputs is a widely-used functionality that is employed either indirectly as a building block in secure computation frameworks, such as ABY (NDSS'15) or directly used in multiple applications that solve optimisation problems, such as secure machine learning or secure aggregation statistics. Incremental distributed point function (I-DPF) is a powerful primitive (IEEE S&P'21) that significantly reduces the client-to-server communication and are employed to efficiently and securely compute aggregation statistics. In this paper, we investigate whether I-DPF can be used to improve the efficiency of secure two-party computation (2PC) with an emphasis on computing the maximum value and the k-th (with$k$unknown to the computing parties) ranked value from a list of secret inputs. Our answer is affirmative, and we propose novel secure 2PC protocols that use I-DPF as a building block, resulting in significant efficiency gains compared to the state-of-the-art. More precisely, our contributions are: (i) We present two new secure computation frameworks that efficiently compute secure aggregation statistics bit-wisely or batch-wisely; (ii) we propose novel protocols to compute the maximum value, the k-th ranked value from a list of secret inputs; (iii) we provide variations of the proposed protocols that can perform batch computations and thus provide further efficiency improvements; and (iv) we provide an extensive performance evaluation for all proposed protocols. Our protocols have a communication complexity that is independent of the number of secret inputs and linear to the length of the secret input domain. Our experimental results show enhanced efficiency over state-of-the-art solutions, particularly notable when handling large-scale inputs. For instance, in scenarios involving an input set of five million elements with an input domain size of 31 bits, our protocol$\Pi_{\text{Max}}$achieves an 18% reduction in online execution time and a 67% decrease in communication volume compared to the most efficient existing solution. Nan Cheng 0002, Aikaterini Mitrokotsa, Frank Hartmann |
EuroS&P | 2 |
| 2024 | SACfe: Secure Access Control in Functional Encryption with Unbounded DataabstractPrivacy is a major concern in large-scale digital applications, such as cloud-computing, machine learning services, and access control. Users want to protect not only their plain data but also their associated attributes (e.g., age, location, etc). Functional encryption (FE) is a cryptographic tool that allows fine-grained access control over encrypted data. However, existing FE fall short as they are either inefficient and far from reality or they leak sensitive user-specific information. We propose SACfe, a novel attribute-based FE scheme that provides secure, fine-grained access control and hides both the user's attributes and the function applied to the data, while preserving the data's confidentiality. Moreover, it enables users to encrypt unbounded-length messages along with an arbitrary number of hidden attributes into ciphertexts. We design SACfe, a protocol for performing linear computation on encrypted data while enforcing access control based on inner product predicates. We show how SACfe can be used for online biometric authentication for privacy-preserving access control. As an additional contribution, we introduce an attribute-based linear FE for unbounded length of messages and functions where access control is realized by monotone span programs. We implement our protocols using the CiFEr cryptographic library and show its efficiency for practical settings. Uddipana Dowerah, Subhranil Dutta, Frank Hartmann, Aikaterini Mitrokotsa, Sayantan Mukherjee, Tapas Pal |
EuroS&P | 4 |
| 2024 | Oblivious Identity-Based Encryption - (IBE Secure Against an Adversarial KGC)
Aikaterini Mitrokotsa, Sayantan Mukherjee, Jenit Tomy |
SAC (1) | 1 |
| 2024 | Constant-Round Private Decision Tree Evaluation for Secret Shared DataabstractDecision tree evaluation is extensively used in machine learning to construct accurate classification models. Often in the cloud-assisted communication paradigm cloud servers execute remote evaluations of classification models using clients' data. In this setting, the need for private decision tree evaluation (PDTE) has emerged to guarantee no leakage of information for the client's input nor the service provider's trained model i.e., decision tree. In this paper, we propose a private decision tree evaluation protocol based on the three-party replicated secret sharing (RSS) scheme. This enables us to securely classify inputs without any leakage of the provided input or the trained decision tree model. Our protocol only requires constant rounds of communication among servers, which is useful in a network with longer delays.Ma et al. (NDSS 2021) presented a lightweight PDTE protocol with sublinear communication cost with linear round complexity in the size of the input data. This protocol works well in the low latency network such as LAN while its total execution time is unfavourably increased in the WAN setting. In contrast, Tsuchida et al. (ProvSec 2020) constructed a constant round PDTE protocol at the cost of communication complexity, which works well in the WAN setting. Although their construction still requires 25 rounds, it showed a possible direction on how to make constant round PDTE protocols. Ji et al. (IEEE Transactions on Dependable and Secure Computing) presented a simplified PDTE with constant rounds using the function secret sharing (FSS) at the cost of communication complexity. Our proposed protocol only requires five rounds among the employed three servers executing secret sharing schemes, which is comparable to previously proposed protocols that are based on garbled circuits and homomorphic encryption. To further demonstrate the efficiency of our protocol, we evaluated it using real-world classification datasets. The evaluation results indicate that our protocol provides better concrete performance in the WAN setting that has a large network delay. Nan Cheng 0002, Aikaterini Mitrokotsa, Hiraku Morita, Kazunari Tozawa |
Proc. Priv. Enhancing Technol. | 3 |
| 2023 | A Framework for UC Secure Privacy Preserving Biometric Authentication Using Efficient Functional Encryption
Johannes Ottenhues, Aikaterini Mitrokotsa |
ACNS | 2 |
| 2023 | Efficient Three-party Boolean-to-Arithmetic Share ConversionabstractThe advantage of mixed-protocol multi-party secure computation frameworks lies in their ability to utilize different sharing types optimally for diverse tasks. A key module in these frameworks are Boolean-to-arithmetic secret sharing conversion protocols, which transfer a secret value from Boolean secret sharing to arithmetic secret sharing. This conversion process can either take in the Boolean secret sharing of a bit or a secret binary string. In this work, we suggest the application of an innovative correlated random tuple for this task in the semi-honest three-party (3PC) setting. This tuple provides the basis for building Boolean-to-arithmetic share conversion protocols. Specifically, we propose two such protocols in the semi-honest 3PC setting, the first protocol takes as input the Boolean secret sharing of a bit, and the second protocol takes as input the Boolean secret sharing of a secret binary string. When it comes to concrete efficiency, the first protocol shows superior performance compared to the existing state-of-the-art in ABY3 (CCS ’18). It achieves this by reducing the total required communication from 2ℓ bits per party to 4ℓ/3+1 bits (including 4ℓ/3 bits in the setup phase, and 1 bit in the online phase) per party, while maintaining a single round of optimized communication. On the other hand, the second protocol involves two rounds of online communication and its communication cost is comparable to that of ABY2.0 (USENIX’21) that relies on correlated oblivious transfer. Nan Cheng 0002, Aikaterini Mitrokotsa |
PST | 3 |
| 2023 | Unbounded Predicate Inner Product Functional Encryption from PairingsabstractAbstract Predicate inner product functional encryption (P-IPFE) is essentially attribute-based IPFE (AB-IPFE) which additionally hides attributes associated to ciphertexts. In a P-IPFE, a message $${\textbf {x}}$$ x is encrypted under an attribute $${\textbf {w}}$$ w and a secret key is generated for a pair $$({\textbf {y}}, {\textbf {v}})$$ ( y , v ) such that recovery of $$\langle {{\textbf {x}}}, {{\textbf {y}}}\rangle $$ ⟨ x , y ⟩ requires the vectors $${\textbf {w}}, {\textbf {v}}$$ w , v to satisfy a linear relation. We call a P-IPFE unbounded if it can encrypt unbounded length attributes and message vectors. $$\bullet $$ ∙ zero predicate IPFE. We construct the first unbounded zero predicate IPFE (UZP-IPFE) which recovers $$\langle {{\textbf {x}}}, {{\textbf {y}}}\rangle $$ ⟨ x , y ⟩ if $$\langle {{\textbf {w}}}, {{\textbf {v}}}\rangle =0$$ ⟨ w , v ⟩ = 0 . This construction is inspired by the unbounded IPFE of Tomida and Takashima (ASIACRYPT 2018) and the unbounded zero inner product encryption of Okamoto and Takashima (ASIACRYPT 2012). The UZP-IPFE stands secure against general attackers capable of decrypting the challenge ciphertext. Concretely, it provides full attribute-hiding security in the indistinguishability-based semi-adaptive model under the standard symmetric external Diffie–Hellman assumption. $$\bullet $$ ∙ non-zero predicate IPFE. We present the first unbounded non-zero predicate IPFE (UNP-IPFE) that successfully recovers $$\langle {{\textbf {x}}}, {{\textbf {y}}}\rangle $$ ⟨ x , y ⟩ if $$\langle {{\textbf {w}}}, {{\textbf {v}}}\rangle \ne 0$$ ⟨ w , v ⟩ ≠ 0 . We generically transform an unbounded quadratic FE (UQFE) scheme to weak attribute-hiding UNP-IPFE in both public and secret key setting. Interestingly, our secret key simulation secure UNP-IPFE has succinct secret keys and is constructed from a novel succinct UQFE that we build in the random oracle model. We leave the problem of constructing a succinct public key UNP-IPFE or UQFE in the standard model as an important open problem. Uddipana Dowerah, Subhranil Dutta, Aikaterini Mitrokotsa, Sayantan Mukherjee, Tapas Pal |
J. Cryptol. | 3 |
| 2022 | WiP: Verifiable, Secure and Energy-Efficient Private Data Aggregation in Wireless Sensor NetworksabstractLarge amounts of data are collected by IoT devices, and transmitted wirelessly to cloud servers for aggregation. These data are often sensitive and need to remain secret. Moreover, the employed servers might be untrustworthy, and maliciously alter their results. To address this, public verifiability must be provided, i.e., anyone can check the result's correctness. Nevertheless, any such protocol must also cope with the limited battery capacity of the IoT devices. Georgia Tsaloli, Alejandro Lancho, Aikaterini Mitrokotsa, Giuseppe Durisi |
SACMAT | 3 |
| 2021 | Non-interactive, Secure Verifiable Aggregation for Decentralized, Privacy-Preserving Learning
Carlo Brunetta, Georgia Tsaloli, Bei Liang, Gustavo Banegas, Aikaterini Mitrokotsa |
ACISP | 5 |
| 2021 | sf DEVA: Decentralized, Verifiable Secure Aggregation for Privacy-Preserving Learning
Georgia Tsaloli, Bei Liang, Carlo Brunetta, Gustavo Banegas, Aikaterini Mitrokotsa |
ISC | 5 |
| 2021 | Turn-Based Communication Channels
Carlo Brunetta, Mario Larangeira, Bei Liang, Aikaterini Mitrokotsa, Keisuke Tanaka |
ProvSec | 4 |
| 2021 | Homomorphic signcryption with public plaintext-result checkabilityabstractAbstract Signcryption originally proposed by Zheng (CRYPTO′97) is a useful cryptographic primitive that provides strong confidentiality and integrity guarantees. This article addresses the question whether it is possible to homomorphically compute arbitrary functions on signcrypted data. The answer is affirmative and a new cryptographic primitive, homomorphic signcryption (HSC) with public plaintext‐result checkability is proposed that allows both to evaluate arbitrary functions over signcrypted data and makes it possible for anyone to publicly test whether a given ciphertext is the signcryption of the message under the key. Two notions of message privacy are also investigated: weak message privacy and message privacy depending on whether the original signcryptions used in the evaluation are disclosed or not. More precisely, the contributions are two‐fold: (i) two different definitions of HSC with public plaintext‐result checkability is provided for arbitrary functions in terms of syntax, unforgeability and message privacy depending on if the homomorphic computation is performed in a private or in a public evaluation setting, (ii) two HSC constructions are proposed: one for a public evaluation setting and another for a private evaluation setting and security is formally proved. Bei Liang, Aikaterini Mitrokotsa, Rui Xue 0001 |
IET Inf. Secur. | 3 |
| 2020 | A Delegated Proof of Proximity Scheme for Industrial Internet of Things ConsensusabstractRecently, work with Distributed Ledger Technologies (DLTs) has focussed on leveraging the decentralised, immutable ledger for use outside of cryptocurrency. One industry poised to benefit from DLTs is the Industrial Internet of Things (IIoT); as the inherent cryptographic mechanisms and alternative trust model make DLTs an attractive solution for distributed networks. Existing DLTs are unsuitable for the IIoT, owing to the large computational and energy requirements for consensus operations and the slow throughput of validated blocks. With limited processing, energy and storage resources and a deadline sensitive operational environment, DLTs in their current state could serve to introduce intolerable latency into IIoT processes and deplete constrained, device resources. Designed for the IIoT context, and based off Delegated Proof of Stake, this work serves to introduce a new consensus mechanism called Delegated Proof of Proximity (DPoP). Using existing location discovery processes, nodes in close proximity to a sensor event are elected as delegates; whose role is to handle consensus and block generation. In using information already known to IIoT devices, DPoP aims to reduce wasted effort, improve throughput by limiting the number of nodes required for consensus operations and improve scalability and flexibility of DLT solutions as the IIoT network continues to grow. Lehlogonolo Ledwaba, Gerhard P. Hancke 0002, Aikaterini Mitrokotsa, Sherrin John Isaac |
IECON | 3 |
| 2019 | Code-Based Zero Knowledge PRF Arguments
Carlo Brunetta, Bei Liang, Aikaterini Mitrokotsa |
ISC | 3 |
| 2019 | Robust Distributed Pseudorandom Functions for mNP Access Structures
Bei Liang, Aikaterini Mitrokotsa |
ISC | 2 |
| 2019 | Multi-key homomorphic authenticatorsabstractHomomorphic authenticators (HAs) enable a client to authenticate a large collection of data elements and outsource them, along with the corresponding authenticators, to an untrusted server. At any later point, the server can generate a short authenticator vouching for the correctness of the output y of a function f computed on the outsourced data, i.e. . The notion of HAs studied so far, however, only supports executions of computations over data authenticated by a single user. Motivated by realistic scenarios in which large datasets include data provided by multiple users, we study the concept of multi‐key homomorphic authenticators. In a nutshell, multi‐key HAs are like HAs with the extra feature of allowing the holder of public evaluation keys to compute on data authenticated under different secret keys. In this paper, we introduce and formally define multi‐key HAs. Secondly, we propose a construction of a multi‐key homomorphic signature based on standard lattices and supporting the evaluation of circuits of bounded polynomial depth. Thirdly, we provide a construction of multi‐key homomorphic MACs based only on pseudorandom functions and supporting the evaluation of low‐degree arithmetic circuits. Dario Fiore 0001, Aikaterini Mitrokotsa, Luca Nizzardo, Elena Pagnin |
IET Inf. Secur. | 2 |
| 2019 | Decentralised Functional SignaturesabstractWith the rapid development of the Internet of Things (IoT) a lot of critical information is shared however without having guarantees about the origin and integrity of the information. Digital signatures can provide important integrity guarantees to prevent illegal users from getting access to private and sensitive data in various IoT applications. Functional signatures, introduced by Boyle, Goldwasser and Ivan (PKC 2014) as signatures with a finegrained access control, allow an authority to generate signing keys corresponding to various functions such that a user with a signing key for a function f , can sign the image of the function f on a message m i.e., can sign f ( m ). Okamoto and Takashima (PKC 2013) firstly proposed the notion of a decentralized multi-authority functional signature (DMA-FS) scheme, which supports non-monotone access structures combined with inner-product relations. In this paper, we generalise the definition of DMA-FS proposed by Okamoto et al. (PKC13) for even more general policy functions, which support any polynomial-size boolean predicates other than the inner product relation and allow modifications of the original message. In our multi-authority functional signature (MAFS), there are multiple authorities and each one is able to certify a specific function and issue a corresponding functional signing key for each individual with some property, rendering them very useful in application settings such smart homes, smart cities, smart health care etc. We also provide a general transformation from a standard signature scheme to a MAFS scheme. Moreover, we present a way to build a function private MAFS from a FS without function privacy together with SNARKs. Bei Liang, Aikaterini Mitrokotsa |
Mob. Networks Appl. | 2 |
| 2018 | Verifiable Homomorphic Secret Sharing
Georgia Tsaloli, Bei Liang, Aikaterini Mitrokotsa |
ProvSec | 3 |
| 2018 | Tangible security: Survey of methods supporting secure ad-hoc connects of edge devices with physical context
Qiao Hu 0005, Jingyi Zhang 0006, Aikaterini Mitrokotsa, Gerhard P. Hancke 0002 |
Comput. Secur. | 3 |
| 2018 | HB+DB: Distance bounding meets human based authentication
Elena Pagnin, Anjia Yang, Qiao Hu 0005, Gerhard P. Hancke 0002, Aikaterini Mitrokotsa |
Future Gener. Comput. Syst. | 5 |
| 2018 | VIVO: A secure, privacy-preserving, and real-time crowd-sensing framework for the Internet of Things
Luca Luceri, Felipe Cardoso, Michela Papandrea, Silvia Giordano, Julia Buwaya, Stéphane Kuendig, Constantinos Marios Angelopoulos, José D. P. Rolim, Zhongliang Zhao, Jose Luis Carrera, Torsten Braun, Aristide C. Y. Tossou, Christos Dimitrakakis, Aikaterini Mitrokotsa |
Pervasive Mob. Comput. | 14 |
| 2018 | Two-Hop Distance-Bounding Protocols: Keep Your Friends CloseabstractAuthentication in wireless communications often depends on the physical proximity to a location. Distance-bounding (DB) protocols are cross-layer authentication protocols that are based on the round-trip-time of challenge-response exchanges and can be employed to guarantee physical proximity and combat relay attacks. However, traditional DB protocols rely on the assumption that the prover (e.g., user) is in the communication range of the verifier (e.g., access point); something that might not be the case in multiple access control scenarios in ubiquitous computing environments as well as when we need to verify the proximity of our two-hop neighbour in an ad-hoc network. In this paper, we extend traditional DB protocols to a two-hop setting, i.e., when the prover is out of the communication range of the verifier and thus, they both need to rely on an untrusted in-between entity in order to verify proximity. We present a formal framework that captures the most representative classes of existing DB protocols and provide a general method to extend traditional DB protocols to the two-hop case (three participants). We analyze the security of two-hop DB protocols and identify connections with the security issues of the corresponding one-hop case. Finally, we demonstrate the correctness of our security analysis and the efficiency of our model by transforming five existing DB protocols to the two-hop setting and we evaluate their performance with simulated experiments. Anjia Yang, Elena Pagnin, Aikaterini Mitrokotsa, Gerhard P. Hancke 0002, Duncan S. Wong |
IEEE Trans. Mob. Comput. | 3 |
| 2017 | Revisiting Yasuda et al.'s Biometric Authentication Protocol: Are You Private Enough?
Elena Pagnin, Aikaterini Mitrokotsa |
CANS | 3 |
| 2017 | Distributed Pseudorandom Functions for General Access Structures in NP
Bei Liang, Aikaterini Mitrokotsa |
ICICS | 2 |
| 2017 | Fast and Adaptively Secure Signatures in the Random Oracle Model from Indistinguishability Obfuscation (Short Paper)
Bei Liang, Aikaterini Mitrokotsa |
ISPEC | 2 |
| 2017 | A Differentially Private Encryption Scheme
Carlo Brunetta, Christos Dimitrakakis, Bei Liang, Aikaterini Mitrokotsa |
ISC | 4 |
| 2017 | Revisiting Two-Hop Distance-Bounding Protocols: Are You Really Close Enough?
Nektaria Kaloudi, Aikaterini Mitrokotsa |
WISTP | 2 |
| 2017 | Near-optimal blacklisting
Christos Dimitrakakis, Aikaterini Mitrokotsa |
Comput. Secur. | 2 |
| 2017 | Differential Privacy for Bayesian Inference through Posterior SamplingabstractDifferential privacy formalises privacy-preserving mechanisms that provide access to a database. Can Bayesian inference be used directly to provide private access to data? The answer is yes: under certain conditions on the prior, sampling from the posterior distribution can lead to a desired level of privacy and utility. For a uniform treatment, we define differential privacy over arbitrary data set metrics, outcome spaces and distribution families. This allows us to also deal with non-i.i.d or non-tabular data sets. We then prove bounds on the sensitivity of the posterior to the data, which delivers a measure of robustness. We also show how to use posterior sampling to provide differentially private responses to queries, within a decision-theoretic framework. Finally, we provide bounds on the utility of answers to queries and on the ability of an adversary to distinguish between data sets. The latter are complemented by a novel use of Le Cam's method to obtain lower bounds on distinguishability. Our results hold for arbitrary metrics, including those for the common definition of differential privacy. For specific choices of the metric, we give a number of examples satisfying our assumptions. Christos Dimitrakakis, Blaine Nelson, Zuhe Zhang, Aikaterini Mitrokotsa, Benjamin I. P. Rubinstein |
J. Mach. Learn. Res. | 4 |
| 2017 | Privacy-Preserving Biometric Authentication: Challenges and DirectionsabstractAn emerging direction for authenticating people is the adoption of biometric authentication systems. Biometric credentials are becoming increasingly popular as a means of authenticating people due to the wide range of advantages that they provide with respect to classical authentication methods (e.g., password-based authentication). The most characteristic feature of this authentication method is the naturally strong bond between a user and her biometric credentials. This very same advantageous property, however, raises serious security and privacy concerns in case the biometric trait gets compromised. In this article, we present the most challenging issues that need to be taken into consideration when designing secure and privacy-preserving biometric authentication protocols. More precisely, we describe the main threats against privacy-preserving biometric authentication systems and give directions on possible countermeasures in order to design secure and privacy-preserving biometric authentication protocols. Elena Pagnin, Aikaterini Mitrokotsa |
Secur. Commun. Networks | 2 |
| 2016 | Multi-key Homomorphic Authenticators
Dario Fiore 0001, Aikaterini Mitrokotsa, Luca Nizzardo, Elena Pagnin |
ASIACRYPT (2) | 2 |
| 2016 | Efficient Verifiable Computation of XOR for Biometric Authentication
Aysajan Abidin, Abdelrahaman Aly, Enrique Argones-Rúa, Aikaterini Mitrokotsa |
CANS | 4 |
| 2016 | 9th International Workshop on Artificial Intelligence and Security: AISec 2016abstractArtificial Intelligence (AI) and Machine Learning (ML) provide a set of useful analytic and decision-making techniques that are being leveraged by an ever-growing community of practitioners, including many whose applications have security-sensitive elements. However, while security researchers often utilize such techniques to address problems and AI/ML researchers develop techniques for Big Data analytics applications, neither community devotes much attention to the other. Within security research, AI/ML components are usually regarded as black-box solvers. Conversely, the learning community seldom considers the security/privacy implications entailed in the application of their algorithms when they are designing them. While these two communities generally focus on different directions, where these two fields do meet, interesting problems appear. Researchers working in this intersection have raised many novel questions for both communities and created a new branch of research known as secure learning. The AISec workshop has become the primary venue for this unique fusion of research. In recent years, there has been an increase of activity within the AISec/secure learning community. There are several reasons for this surge. Firstly, machine learning, data mining, and other artificial intelligence technologies play a key role in extracting knowledge, situational awareness, and security intelligence from Big Data. Secondly, companies like Google, Facebook, Amazon, and Splunk are increasingly exploring and deploying learning technologies to address Big Data problems for their customers. David Mandell Freeman, Aikaterini Mitrokotsa, Arunesh Sinha |
CCS | 2 |
| 2016 | Special issue on recent advances in physical-layer security
Gerhard P. Hancke 0002, Aikaterini Mitrokotsa, Reihaneh Safavi-Naini, Damien Sauveron |
Comput. Networks | 2 |
| 2015 | Workshop Summary of AISec'15: 2015 Workshop on Artificial Intelligent and SecurityabstractIt is our great pleasure to welcome you to the 2015 ACM Workshop Artificial Intelligence and Security (AISec 2015) - the eight annual workshop addressing technologies that fuse intelligent systems into computer security applications and the implications of these approaches. The workshop's aim is to advance research at the intersection of artificial intelligence, machine learning, privacy and security. In particular, AISec gives researchers and practitioners working within one or more of those fields a platform for interdisciplinary discussion, which would otherwise be lacking. Hopefully, the workshop leads to a high degree of cross-pollination between groups working across these areas. The papers to be presented in this year's program span topics ranging from adversarial learning, detecting fake OSN accounts, malware classification to privacy preserving data processing and game theoretic techniques in adversarial learning. We are delighted to again be co-located with the premier ACM Computer and Communication Security (CCS 2015) conference. This year we had 25 submissions from Asia, Europe and North America. After a rigorous reviewing process, involving at 2-3 referees per paper, 11 papers were accepted for presentation at the workshop, including presentation-only papers. Christos Dimitrakakis, Aikaterini Mitrokotsa, Arunesh Sinha |
CCS | 2 |
| 2015 | HB+DB, mitigating man-in-the-middle attacks against HB+ with distance boundingabstractAuthentication for resource-constrained devices is seen as one of the major challenges in current wireless communication networks. The HB+ protocol performs device authentication based on the learning parity with noise (LPN) problem and simple computational steps, that renders it suitable for resource-constrained devices such as radio frequency identification (RFID) tags. However, it has been shown that the HB+ protocol as well as many of its variants are vulnerable to a simple man-in-the-middle attack. We demonstrate that this attack could be mitigated using physical layer measures from distance-bounding and simple modifications to devices' radio receivers. Our hybrid solution (HB+DB) is shown to provide both effective distance-bounding using a lightweight HB+-based response function, and resistance against the man-in-the-middle attack to HB+. We provide experimental evaluation of our results as well as a brief discussion on practical requirements for secure implementation. Elena Pagnin, Anjia Yang, Gerhard P. Hancke 0002, Aikaterini Mitrokotsa |
WISEC | 4 |
| 2015 | Practical and provably secure distance-boundingabstractAbstract From contactless payments to remote car unlocking, many applications are vulnerable to relay attacks. Distance bounding protocols are the main practical countermeasure against these attacks. In this paper, we present a formal analysis of SKI, which recently emerged as the first family of lightweight and provably secure distance bounding protocols. More precisely, we explicate a general formalism for distance-bounding protocols, which lead to this practical and provably secure class of protocols (and it could lead to others). We prove that SKI and its variants are provably secure, even under the real-life setting of noisy communications, against the main types of relay attacks: distance-fraud and generalised versions of mafia- and terrorist-fraud. To attain resistance to terrorist-fraud, we reinforce the idea of using secret sharing, combined with the new notion of a leakage scheme. In view of resistance to generalised mafia-frauds (and terrorist-frauds), we present the notion of circular-keying for pseudorandom functions (PRFs); this notion models the employment of a PRF, with possible linear reuse of the key. We also identify the need of PRF masking to fix common mistakes in existing security proofs/claims. Finally, we enhance our design to guarantee resistance to terrorist-fraud in the presence of noise. Ioana Boureanu, Aikaterini Mitrokotsa, Serge Vaudenay |
J. Comput. Secur. | 2 |
| 2015 | Expected loss analysis for authentication in constrained channelsabstractAbstract We derive bounds on the expected loss for authentication protocols in channels which are constrained due to noisy conditions and communication costs. This is motivated by a number of authentication protocols, where at least some part of the authentication is performed during a phase, lasting n rounds, with no error correction. This requires assigning an acceptable threshold for the number of detected errors and taking into account the cost of incorrect authentication and of communication. This paper describes a framework enabling an expected loss analysis for all the protocols in this family. Computationally simple methods to obtain nearly optimal values for the threshold, as well as for the number of rounds are suggested and upper bounds on the expected loss, holding uniformly, are given. These bounds are tight, as shown by a matching lower bound. Finally, a method to adaptively select both the number of rounds and the threshold is proposed for a certain class of protocols. Christos Dimitrakakis, Aikaterini Mitrokotsa, Serge Vaudenay |
J. Comput. Secur. | 2 |
| 2014 | Robust and Private Bayesian Inference
Christos Dimitrakakis, Blaine Nelson, Aikaterini Mitrokotsa, Benjamin I. P. Rubinstein |
ALT | 3 |
| 2014 | Security of a Privacy-Preserving Biometric Authentication Protocol Revisited
Aysajan Abidin, Kanta Matsuura, Aikaterini Mitrokotsa |
CANS | 3 |
| 2014 | Workshop Summary of AISec'14: 2014 Workshop on Artificial Intelligent and SecurityabstractIt is our great pleasure to welcome you to the 2014 ACM Workshop Artificial Intelligence and Security (AISec 2014) -- the seventh annual workshop addressing technologies that fuse intelligent systems into computer security applications and the implications of these approaches. The workshop's aim is to advance research at the intersection of artificial intelligence, machine learning, privacy and security. In particular, AISec gives researchers and practitioners working within one or more of those fields a platform for interdisciplinary discussion, which would otherwise be lacking. Hopefully, the workshop will lead to the initiation of knew col- laborations between groups working across these areas. The papers to be presented in this year's program include topics such as the analysis of privacy, adversarial learning models, intrusion detection and automatic advertisement filtering. We are delighted to again be co-located with the premier ACM Computer and Communication Security (CCS 2014) conference. This year we had 23 submissions from Asia, Europe and North America. This year, the workshop also includes a "presentation-only" track, for papers appearing elsewhere. After a rigorous reviewing process, 11 original papers were accepted for presentation at the workshop, while one paper was accepted for peresentation only. Christos Dimitrakakis, Aikaterini Mitrokotsa, Benjamin I. P. Rubinstein |
CCS | 2 |
| 2014 | Location leakage in distance bounding: Why location privacy does not work
Aikaterini Mitrokotsa, Cristina Onete, Serge Vaudenay |
Comput. Secur. | 1 |
| 2013 | Towards Secure Distance Bounding
Ioana Boureanu, Aikaterini Mitrokotsa, Serge Vaudenay |
FSE | 2 |
| 2013 | Practical and Provably Secure Distance-Bounding
Ioana Boureanu, Aikaterini Mitrokotsa, Serge Vaudenay |
ISC | 2 |
| 2013 | Intrusion detection in MANET using classification algorithms: The effects of cost and model selection
Aikaterini Mitrokotsa, Christos Dimitrakakis |
Ad Hoc Networks | 1 |
| 2013 | On Selecting the Nonce Length in Distance-Bounding ProtocolsabstractDistance-bounding protocols form a family of challenge–response authentication protocols that have been introduced to thwart relay attacks. They enable a verifier to authenticate and to establish an upper bound on the physical distance to an untrusted prover. We provide a detailed security analysis of a family of such protocols. More precisely, we show that the secret key shared between the verifier and the prover can be leaked after a number of nonce repetitions. The leakage probability, while exponentially decreasing with the nonce length, is only weakly dependent on the key length. Our main contribution is a high probability bound on the number of sessions required for the attacker to discover the secret, and an experimental analysis of the attack under noisy conditions. Both of these show that the attack's success probability mainly depends on the length of the used nonces rather than the length of the shared secret key. The theoretical bound could be used by practitioners to appropriately select their security parameters. While longer nonces can guard against this type of attack, we provide a possible countermeasure which successfully combats these attacks even when short nonces are used. Aikaterini Mitrokotsa, Pedro Peris-Lopez, Christos Dimitrakakis, Serge Vaudenay |
Comput. J. | 1 |
| 2012 | The Bussard-Bagga and Other Distance-Bounding Protocols under Attacks
Aslí Bay, Ioana Boureanu, Aikaterini Mitrokotsa, Iosif Spulber, Serge Vaudenay |
Inscrypt | 3 |
| 2012 | Expected loss bounds for authentication in constrained channelsabstractWe derive bounds on the expected loss for authentication protocols in channels which are constrained due to noisy conditions and communication costs. This is motivated by a number of authentication protocols, where at least some part of the authentication is performed during a phase, lasting n rounds, with no error correction. This requires assigning an acceptable threshold for the number of detected errors and taking into account the cost of incorrect authentication and of communication. This paper describes a framework enabling an expected loss analysis for all the protocols in this family. Computationally simple methods to obtain nearly optimal values for the threshold, as well as for the number of rounds are suggested and upper bounds on the expected loss, holding uniformly, are given. These bounds are tight, as shown by a matching lower bound. Finally, a method to adaptively select both the number of rounds and the threshold is proposed for a certain class of protocols. Christos Dimitrakakis, Aikaterini Mitrokotsa, Serge Vaudenay |
INFOCOM | 2 |
| 2012 | Evaluation of classification algorithms for intrusion detection in MANETs
Sergio Pastrana, Aikaterini Mitrokotsa, Agustín Orfila, Pedro Peris-Lopez |
Knowl. Based Syst. | 2 |
| 2012 | User-driven RFID applications and challenges
Aikaterini Mitrokotsa, Quan Z. Sheng, Zakaria Maamar |
Pers. Ubiquitous Comput. | 1 |
| 2012 | Guest Editors' Introduction: Special Section on Learning, Games, and SecurityabstractThe articles in this special section are devoted to the topic of learning, computer games and system security. Christos Dimitrakakis, Tom Karygiannis, Aikaterini Mitrokotsa |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2011 | A Note on a Privacy-Preserving Distance-Bounding Protocol
Jean-Philippe Aumasson, Aikaterini Mitrokotsa, Pedro Peris-Lopez |
ICICS | 2 |
| 2011 | RFID technology, systems, and applications
Quan Z. Sheng, Sherali Zeadally, Aikaterini Mitrokotsa, Zakaria Maamar |
J. Netw. Comput. Appl. | 3 |
| 2009 | Statistical Decision Making for Authentication and Intrusion DetectionabstractUser authentication and intrusion detection differ from standard classification problems in that while we have data generated from legitimate users, impostor or intrusion data is scarce or non-existent. We review existing techniques for dealing with this problem and propose a novel alternative based on a principled statistical decision-making view point. We examine the technique on a toy problem and validate it on complex real-world data from an RFID based access control system. The results indicate that it can significantly outperform the classical world model approach. The method could be more generally useful in other decision- making scenarios where there is a lack of adversary data. Christos Dimitrakakis, Aikaterini Mitrokotsa |
ICMLA | 2 |
| 2004 | DDoS attacks and defense mechanisms: classification and state-of-the-art
Christos Douligeris, Aikaterini Mitrokotsa |
Comput. Networks | 2 |