Subhra Mazumdar 0001

dblp:29/4490 · DBLP profile ↗
← Back
8ranked-venue papers
3as first author
6since 2021 · last 2025
0000-0002-3089-2535ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 2 first-author · 4 since 2021Artificial intelligence and machine learning · 1Computer networks · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Cumulus: Blockchain-Enabled Privacy-Preserving Data Audit in Cloud
abstract
Data owners upload large files to cloud storage servers, but malicious servers may potentially tamper data. To check integrity of remote data, Proof-of-retrievability (PoR) schemes were introduced. Existing PoR protocols assume that data owners and third-party auditors are honest and audit only the potentially malicious cloud server to check integrity of stored data. In this article, we consider a system where any party may attempt to cheat others and consider collusion cases. We design a protocol, Cumulus, that is secure under such adversarial assumptions and use blockchain smart contracts to act as mediator in case of dispute and payment settlement. We use state channels to reduce blockchain interactions in order to build a practical audit solution. The security of the protocol has been proven in Universal Composability (UC) framework. Finally, we illustrate several applications of our basic protocol and evaluate practicality of our approach via a prototype implementation for fairly selling large files over the Ethereum platform. We evaluate the prototype and show that our scheme has comparable performance.
Prabal Banerjee, Nishant Nikam, Subhra Mazumdar 0001, Sushmita Ruj
Distributed Ledger Technol. Res. Pract.3
2024 Securing Lightning Channels against Rational Miners
abstract
Payment channel networks (e.g., the Lightning Network in Bitcoin) constitute one of the most popular scalability solutions for blockchains. Their safety relies on parties being online to detect fraud attempts on-chain and being able to timely react by publishing certain transactions on-chain. However, a cheating party may bribe miners in order to censor those transactions, resulting in loss of funds for the cheated party: these attacks are known in the literature as timelock bribing attacks. In this work, we present the first channel construction that does not require parties to be online and, at the same time, is resistant to timelock bribing attacks.
Lukas Aumayr, Zeta Avarikioti, Matteo Maffei, Subhra Mazumdar 0001
CCS4
2023 Fidelis: Verifiable Keyword Search with No Trust Assumption
Laltu Sardar, Subhra Mazumdar 0001
SECRYPT2
2023 Chrisimos: A useful Proof-of-Work for finding Minimal Dominating Set of a graph
abstract
Hash-based Proof-of-Work (PoW) used in the Bitcoin Blockchain leads to high energy consumption and resource wastage. In this paper, we aim to re-purpose the energy by replacing the hash function with real-life problems having commercial utility. We propose Chrisimos, a useful Proof-of-Work where miners are required to find a minimal dominating set for real-life graph instances. A miner who is able to output the smallest dominating set for the given graph within the block interval time wins the mining game. Thus our protocol also realizes a decentralized minimal dominating set solver for any graph instance.
Diptendu Chatterjee, Prabal Banerjee, Subhra Mazumdar 0001
TrustCom3
2023 CryptoMaze: Privacy-Preserving Splitting of Off-Chain Payments
abstract
Payment Channel Networks or PCNs solve the problem of scalability in Blockchain by executing payments off-chain. Due to a lack of sufficient capacity in the network, high-valued payments are split and routed via multiple paths. Existing multi-path payment protocols either fail to achieve atomicity or are susceptible to wormhole attack. We propose a secure and privacy-preserving atomic multi-path payment protocol CryptoMaze. Our protocol avoids the formation of multiple off-chain contracts on edges shared by the paths routing partial payments. It also guarantees unlinkability between partial payments. We provide a formal definition of the protocol in the Universal Composability framework and analyze the security. We implement CryptoMaze on several instances of Lightning Network and simulated networks. Our protocol requires 11s for routing a payment of 0.04 BTC on a network instance comprising 25600 nodes. The communication cost is less than 1MB in the worst-case. On comparing the performance of CryptoMaze with several state-of-the-art payment protocols, we observed that our protocol outperforms the rest in terms of computational cost and has a feasible communication overhead.
Subhra Mazumdar 0001, Sushmita Ruj
IEEE Trans. Dependable Secur. Comput.1
2023 Strategic Analysis of Griefing Attack in Lightning Network
abstract
Hashed Timelock Contract (HTLC) in Lightning Network is susceptible to agriefing attack. An attacker can block several channels and stall payments by mounting this attack. A state-of-the-art countermeasure, Hashed Timelock Contract with Griefing-Penalty (HTLC-GP) is found to work under the classical assumption of participants being either honest or malicious but fails for rational participants. To address the gap, we introduce a game-theoretic model for analyzing griefing attacks inHTLC. We use this model to analyze griefing attacks inHTLC-GPand conjecture that it is impossible to design an efficient protocol that will penalize a malicious participant with the current Bitcoin scripting system. We study the impact of the penalty on the cost of mounting the attack and observe thatHTLC-GPisweakly effectivein disincentivizing the attacker in certain conditions. To further increase the cost of attack, we introduce the concept ofguaranteed minimum compensation, denoted as$\zeta $, and modifyHTLC-GPinto$\mathrm {HTLC{-}GP}^{\zeta }$. By experimenting on several instances of Lightning Network, we observe that the total coins locked in the network drops to 28% for$\mathrm {HTLC{-}GP}^{\zeta }$, unlike inHTLC-GPwhere total coins locked does not drop below 40%. These results justify that$\mathrm {HTLC{-}GP}^{\zeta }$is better thanHTLC-GPto counter griefing attacks.
Subhra Mazumdar 0001, Prabal Banerjee, Abhinandan Sinha, Sushmita Ruj, Bimal K. Roy
IEEE Trans. Netw. Serv. Manag.1
2020 Time is Money: Countering Griefing Attack in Lightning Network
abstract
Lightning Network is the most deployed Bitcoin-compatible Payment Channel Network (PCN), ensuring faster execution of transactions. However, this Layer-two solution has its fair share of problems. Topological analysis on Lightning Network reveals that Griefing Attack is a major problem whereby an adversary intentionally exhausts the channel capacity of the network. Though the attack does not always result in a direct monetary gain of the attacker, blocking of channel capacity for several days prevents several nodes from processing any future transaction request, leading to substantial collateral damage. If the attacker is able to lock funds in multiple paths simultaneously, then a major portion of the network may get stalled, reducing the throughput. Mitigating Griefing Attack still remains an open problem. In this paper, we propose an efficient countermeasure for the attack, known as Griefing-Penalty. To realize it, we propose a new payment protocol HTLC-GP or Hashed Timelock Contract with Griefing-Penalty. It not only preserves privacy but also ensures that an attacker cannot ascribe blame on any honest party present in the path relaying the payment. We evaluate the effectiveness of griefing-penalty using different attack strategies and test it on several snapshots of Lightning Network. Our evaluation results show that loss incurred is substantially high for HTLC-GP compared to HTLC.
Subhra Mazumdar 0001, Prabal Banerjee, Sushmita Ruj
TrustCom1
2015 Improved Algorithms for the Evacuation Route Planning Problem
Gopinath Mishra, Subhra Mazumdar 0001, Arindam Pal 0001
COCOA2