EDBT 2026 Demo / reviewers in the wild / expert
Sushmita Ruj
dblp:30/5711
· DBLP profile ↗
63ranked-venue papers
14as first author
20since 2021 · last 2026
0000-0002-8698-6709ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 26 · 2 first-author · 10 since 2021Computer networks · 15 · 3 first-author · 4 since 2021Systems, architecture and hardware · 10 · 5 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 4 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Post Quantum Vector Commitment Scheme with Efficient Insertions and Deletions
Vir Pathak 0001, Sushmita Ruj |
ACNS (1) | 2 |
| 2026 | SOLSTICE: Optimising Verifiable Data Retrieval for Storage Nodes in Account-based Blockchains
Nhi Luu, Asish Balasundaram, Sushmita Ruj |
DBSec | 3 |
| 2026 | Data Inclusion Proofs for Account-based Blockchains Storage Nodes
Nhi Luu, James Liu, Zhengnan Hua, Joseph Hilsberg, Sushmita Ruj |
ICBC | 6 |
| 2025 | Towards Usability of Data with Privacy: A Unified Framework for Privacy-Preserving Data Sharing with High Utility
Mahawaga Arachchige Pathum Chamikara, Seung Ick Jang, Ian J. Oppermann, Dongxi Liu, Musotto Roberto, Sushmita Ruj, Arindam Pal 0001, Meisam Mohammady, Seyit Ahmet Çamtepe, Sylvia Young, Chris Dorrian, Nasir David |
AsiaCCS | 6 |
| 2025 | Empirical Analysis of DNS Abuse Cases within Australian DomainabstractThe Domain Name System (DNS) translates human-readable domain names into machine-readable IP addresses. This critical internet infrastructure faces increasing exploitation through various malicious activities collectively known as DNS abuse. While DNS abuse has been extensively researched globally, the unique patterns and vulnerabilities within the Australian domain space remain understudied. This paper provides a comprehensive empirical analysis of DNS abuse within Australian domain names. Our thorough data collection and analysis allow us to characterize the specific nature of abuse trends within the Australian domain space. We document how malicious actors strategically employ methods to evade detection systems, and highlight the concentration of abuse among specific domain registrations. These research findings provide stakeholders with actionable, data-driven insights, emphasizing the necessity of industry-specific defensive measures and tailored state-level threat mitigation strategies. We have laid the foundation for building a more refined, risk-based Australian digital infrastructure security system. Minghao Cai, Sushmita Ruj, Rahat Masood, Salil S. Kanhere |
LCN | 2 |
| 2025 | Cumulus: Blockchain-Enabled Privacy-Preserving Data Audit in CloudabstractData owners upload large files to cloud storage servers, but malicious servers may potentially tamper data. To check integrity of remote data, Proof-of-retrievability (PoR) schemes were introduced. Existing PoR protocols assume that data owners and third-party auditors are honest and audit only the potentially malicious cloud server to check integrity of stored data. In this article, we consider a system where any party may attempt to cheat others and consider collusion cases. We design a protocol, Cumulus, that is secure under such adversarial assumptions and use blockchain smart contracts to act as mediator in case of dispute and payment settlement. We use state channels to reduce blockchain interactions in order to build a practical audit solution. The security of the protocol has been proven in Universal Composability (UC) framework. Finally, we illustrate several applications of our basic protocol and evaluate practicality of our approach via a prototype implementation for fairly selling large files over the Ethereum platform. We evaluate the prototype and show that our scheme has comparable performance. Prabal Banerjee, Nishant Nikam, Subhra Mazumdar 0001, Sushmita Ruj |
Distributed Ledger Technol. Res. Pract. | 4 |
| 2024 | DualRing-PRF: Post-quantum (Linkable) Ring Signatures from Legendre and Power Residue PRFs
Xinyu Zhang 0017, Ron Steinfeld, Joseph K. Liu, Muhammed F. Esgin, Dongxi Liu, Sushmita Ruj |
ACISP (2) | 6 |
| 2024 | Loquat: A SNARK-Friendly Post-quantum Signature Based on the Legendre PRF with Applications in Ring and Aggregate Signatures
Xinyu Zhang 0017, Ron Steinfeld, Muhammed F. Esgin, Joseph K. Liu, Dongxi Liu, Sushmita Ruj |
CRYPTO (1) | 6 |
| 2024 | SoK: Trusting Self-Sovereign IdentityabstractDigital identity is evolving from centralized systems to a decentralized approach known as Self-Sovereign Identity (SSI). SSI empowers individuals to control their digital identities, eliminating reliance on third-party data custodians and reducing the risk of data breaches. However, the concept of trust in SSI remains complex and fragmented. This paper systematically analyzes trust in SSI in light of its components and threats posed by various actors in the system. As a result, we derive three distinct trust models that capture the threats and mitigations identified across SSI literature and implementations. Our work provides a foundational framework for future SSI research and development, including a comprehensive catalogue of SSI components and design requirements for trust, shortcomings in existing SSI systems and areas for further exploration. Evan Krul, Hye-Young Paik, Sushmita Ruj, Salil S. Kanhere |
Proc. Priv. Enhancing Technol. | 3 |
| 2024 | Electric Vehicle Next Charge Location PredictionabstractBy 2050, global sales of electric vehicles (EVs) are predicted to account for approximately 70% of all vehicle sales. However, whilst transitioning from combustion engine vehicles to EVs would result in reduced carbon dioxide emissions, it would place significant strain on energy generation, and grid infrastructure. Many EV studies investigated routing or charge station management, while research on predicting energy demand at a specific location was lacking. To address this, our study focused on predicting EV’s next charge location. We developed a localised onboard Convolutional Neural Network (CNN) model that achieved accuracies up to 95%. Our proposal used community area Distributed Energy Resource Management Systems (DERMS) to train EV models during charge transactions, while predictions were made onboard each EV. To address the lack of EV mobility charge data, we created a hybrid dataset using empirical Chicago city taxi mobility data adding synthetic EV charging event states. We conducted multiple experiments over various battery charge levels to understand how far ahead in time next charge location could be predicted, achieving reliable predictions up to 3 days before requiring next charge. Finally, this study laid a foundation for future EV mobility research by providing a novel EV mobility charge dataset. Robert Marlin, Raja Jurdak, Alsharif Abuadbba, Sushmita Ruj, Dimity Miller |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2023 | Efficient Hybrid Exact/Relaxed Lattice Proofs and Applications to Rounding and VRFs
Muhammed F. Esgin, Ron Steinfeld, Dongxi Liu, Sushmita Ruj |
CRYPTO (5) | 4 |
| 2023 | Accelerated Verifiable Fair Digital ExchangeabstractA Fair Digital Exchange is defined as either all or none of the participants achieving a (predetermined) desirable outcome. This work addresses third party mediated systems for digital content where mutually unknown, and hence non-trusting, buyers, sellers and the mediator (third party) take part in an exchange protocol. We address the lack of guaranteed fairness, as defined above, in the existing platforms for this setting. We present TEDX, a decentralized solution for guaranteed three party fair exchange of digital goods with scalability and support for incremental deployment over the existing (non-fair) platforms. TEDX combines carefully crafted message exchanges with incentive schemes designed to deter malicious behavior. TEDX also leverages ideas from blockchain anchored state-channels to provide trusted execution while minimizing the operational overheads of blockchain. We present the design and a security analysis of TEDX to validate the claimed fairness properties. We also present the details of a prototype implementation of TEDX leveraging Hyperledger Fabric and performance evaluation of the same on a realistic testbed spanning five public cloud zones. Our results indicate that TEDX adds only a minimal overhead of 16% while being 46x faster than a naive blockchain solution, thereby demonstrating that TEDX is scalable. Prabal Banerjee, Dushyant Behl, Palani Kodeswaran, Chaitanya Kumar, Sushmita Ruj, Sayandeep Sen, Dhinakaran Vinayagamurthy |
Distributed Ledger Technol. Res. Pract. | 5 |
| 2023 | CryptoMaze: Privacy-Preserving Splitting of Off-Chain PaymentsabstractPayment Channel Networks or PCNs solve the problem of scalability in Blockchain by executing payments off-chain. Due to a lack of sufficient capacity in the network, high-valued payments are split and routed via multiple paths. Existing multi-path payment protocols either fail to achieve atomicity or are susceptible to wormhole attack. We propose a secure and privacy-preserving atomic multi-path payment protocol CryptoMaze. Our protocol avoids the formation of multiple off-chain contracts on edges shared by the paths routing partial payments. It also guarantees unlinkability between partial payments. We provide a formal definition of the protocol in the Universal Composability framework and analyze the security. We implement CryptoMaze on several instances of Lightning Network and simulated networks. Our protocol requires 11s for routing a payment of 0.04 BTC on a network instance comprising 25600 nodes. The communication cost is less than 1MB in the worst-case. On comparing the performance of CryptoMaze with several state-of-the-art payment protocols, we observed that our protocol outperforms the rest in terms of computational cost and has a feasible communication overhead. Subhra Mazumdar 0001, Sushmita Ruj |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2023 | Strategic Analysis of Griefing Attack in Lightning NetworkabstractHashed Timelock Contract (HTLC) in Lightning Network is susceptible to agriefing attack. An attacker can block several channels and stall payments by mounting this attack. A state-of-the-art countermeasure, Hashed Timelock Contract with Griefing-Penalty (HTLC-GP) is found to work under the classical assumption of participants being either honest or malicious but fails for rational participants. To address the gap, we introduce a game-theoretic model for analyzing griefing attacks inHTLC. We use this model to analyze griefing attacks inHTLC-GPand conjecture that it is impossible to design an efficient protocol that will penalize a malicious participant with the current Bitcoin scripting system. We study the impact of the penalty on the cost of mounting the attack and observe thatHTLC-GPisweakly effectivein disincentivizing the attacker in certain conditions. To further increase the cost of attack, we introduce the concept ofguaranteed minimum compensation, denoted as$\zeta $, and modifyHTLC-GPinto$\mathrm {HTLC{-}GP}^{\zeta }$. By experimenting on several instances of Lightning Network, we observe that the total coins locked in the network drops to 28% for$\mathrm {HTLC{-}GP}^{\zeta }$, unlike inHTLC-GPwhere total coins locked does not drop below 40%. These results justify that$\mathrm {HTLC{-}GP}^{\zeta }$is better thanHTLC-GPto counter griefing attacks. Subhra Mazumdar 0001, Prabal Banerjee, Abhinandan Sinha, Sushmita Ruj, Bimal K. Roy |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2023 | FairShare: Blockchain Enabled Fair, Accountable and Secure Data Sharing for Industrial IoTabstractIndustrial Internet of Things (IIoT) opens up a challenging research area towards improving secure data sharing which currently has several limitations. Primarily, the lack of inbuilt guarantees of honest behavior of participating, such as end-users or cloud behaving maliciously may result in disputes. Given such challenges, we propose a fair, accountable, and secure data sharing scheme, FairShare for IIoT. In this scheme, data collected from IoT devices are processed and stored in cloud servers with intermediate fog nodes facilitating computation. Authorized clients can access this data against some fee to make strategic decisions for improving the operational services of the IIoT system. By enabling blockchain, FairShare prevents fraudulent activities and thereby achieves fairness such that each party gets their rightful outcome in terms of data or penalty/rewards while simultaneously ensuring accountability of the services provided by the parties. Additionally, smart contracts are designed to act as a mediator during any dispute by enforcing payment settlement. Further, security and privacy of data are ensured by suitably applying cryptographic techniques like proxy re-encryption. We prove FairShare to be secure as long as at least one of the parties is honest. We validate FairShare with a theoretical overhead analysis. We also build a prototype in Ethereum to estimate performance and justify comparable results with a state-of-the-art scheme both via simulation and a realistic testbed setup. We observe an additional communication overhead of 256 bytes and a cost of deployment of 1.01 USD in Ethereum which are constant irrespective of file size. Jayasree Sengupta, Sushmita Ruj, Sipra Das Bit |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2022 | SPRITE: A Scalable Privacy-Preserving and Verifiable Collaborative Learning for Industrial IoTabstractRecently collaborative learning is widely applied to model sensitive data generated in Industrial loT (1IoT). It enables a large number of devices to collectively train a global model by collaborating with a server while keeping the datasets on their respective premises. However, existing approaches are limited by high overheads and may also suffer from falsified aggregated results returned by a malicious server. Hence, we propose a Scal-able, Privacy-preserving and veRIfiable collaboraTive lEarning (SPRITE) algorithm to train linear and logistic regression models for IloT. We aim to reduce burden from resource-constrained IloT devices and trust dependence on cloud by introducing fog as a middleware. SPRITE employs threshold secret sharing to guarantee privacy-preservation and robustness to IloT device dropout whereas verifiable additive homomorphic secret sharing to ensure verifiability during model aggregation. We prove the security of SPRITE in an honest-but-curious setting where the cloud is untrustworthy. We validate SPRITE to be scalable and lightweight through theoretical overhead analysis and extensive testbed experimentation on an IloT use-case with two real-world industrial datasets. For a large-scale industrial setup, SPRITE records 65% and 55% improved performance over its competitor for linear and logistic regressions respectively while reducing communication overhead for an IloT device by 90%. Jayasree Sengupta, Sushmita Ruj, Sipra Das Bit |
CCGRID | 2 |
| 2022 | Forward Traceability for Product Authenticity Using Ethereum Smart Contracts
Fokke Heikamp, Lei Pan 0002, Rolando Trujillo-Rasua, Sushmita Ruj, Robin Doss |
NSS | 4 |
| 2022 | DIMY: Enabling privacy-preserving contact tracing
Regio A. Michelin, Wanli Xue, Guntur D. Putra, Sushmita Ruj, Salil S. Kanhere, Sanjay K. Jha |
J. Netw. Comput. Appl. | 5 |
| 2022 | Secure Cloud Storage With Data Dynamics Using Secure Network Coding TechniquesabstractIn the age of cloud computing, cloud users with limited storage can outsource their data to remote servers. These servers, in lieu of monetary benefits, offer retrievability of their clients’ data at any point of time. Secure cloud storage protocols enable a client to check integrity of outsourced data. In this article, we explore the possibility of constructing a secure cloud storage for dynamic data by leveraging the algorithms involved in secure network coding. We show that some of the secure network coding schemes can be used to constructefficientsecure cloud storage protocols for dynamic data, and we construct such a protocol (DSCS I) based on a secure network coding protocol. To the best of our knowledge, DSCS I is the first secure cloud storage protocol fordynamicdata constructed using secure network coding techniques which is secure in the standard model. Although generic dynamic data support arbitrary insertions, deletions and modifications,append-onlydata find numerous applications in the real world. We construct another secure cloud storage protocol (DSCS II) specific to append-only data — that overcomes some limitations of DSCS I. Finally, we provide prototype implementations for DSCS I and DSCS II in order to evaluate their performance. Binanda Sengupta, Akanksha Dixit 0001, Sushmita Ruj |
IEEE Trans. Cloud Comput. | 3 |
| 2021 | A Secure Fog-Based Architecture for Industrial Internet of Things and Industry 4.0abstractThe advent of Industrial Internet of Things (IIoT) along with cloud computing has brought a huge paradigm shift in manufacturing industries resulting in yet another industrial revolution, Industry 4.0. Huge amounts of delay-sensitive data of diverse nature are being generated, which need to be locally processed and secured because of their sensitivity. However, the low-end Internet of Things devices are unable to handle huge computational overheads. In addition, the semi-trusted nature of cloud introduces several security concerns. To address these issues, this article proposes a secure fog-based IIoT architecture by suitably plugging a number of security features into it and by offloading some of the tasks judiciously to fog nodes. These features secure the system alongside reducing the trust and burden on the cloud and resource-constrained devices, respectively. We validate our proposed architecture through both theoretical overhead analysis and practical experimentation, including simulation study and testbed implementation. Jayasree Sengupta, Sushmita Ruj, Sipra Das Bit |
IEEE Trans. Ind. Informatics | 2 |
| 2020 | Time is Money: Countering Griefing Attack in Lightning NetworkabstractLightning Network is the most deployed Bitcoin-compatible Payment Channel Network (PCN), ensuring faster execution of transactions. However, this Layer-two solution has its fair share of problems. Topological analysis on Lightning Network reveals that Griefing Attack is a major problem whereby an adversary intentionally exhausts the channel capacity of the network. Though the attack does not always result in a direct monetary gain of the attacker, blocking of channel capacity for several days prevents several nodes from processing any future transaction request, leading to substantial collateral damage. If the attacker is able to lock funds in multiple paths simultaneously, then a major portion of the network may get stalled, reducing the throughput. Mitigating Griefing Attack still remains an open problem. In this paper, we propose an efficient countermeasure for the attack, known as Griefing-Penalty. To realize it, we propose a new payment protocol HTLC-GP or Hashed Timelock Contract with Griefing-Penalty. It not only preserves privacy but also ensures that an attacker cannot ascribe blame on any honest party present in the path relaying the payment. We evaluate the effectiveness of griefing-penalty using different attack strategies and test it on several snapshots of Lightning Network. Our evaluation results show that loss incurred is substantially high for HTLC-GP compared to HTLC. Subhra Mazumdar 0001, Prabal Banerjee, Sushmita Ruj |
TrustCom | 3 |
| 2020 | A parallelized disjunctive query based searchable encryption scheme for big data
Shahzaib Tahir, Liutauras Steponkus, Sushmita Ruj, Muttukrishnan Rajarajan, Ali Sajjad |
Future Gener. Comput. Syst. | 3 |
| 2020 | A Comprehensive Survey on Attacks, Security Issues and Blockchain Solutions for IoT and IIoT
Jayasree Sengupta, Sushmita Ruj, Sipra Das Bit |
J. Netw. Comput. Appl. | 2 |
| 2020 | Efficient Decentralized Attribute Based Access Control for Mobile CloudsabstractFine grained access control is a requirement for data stored in untrusted servers like clouds. Owing to the large volume of data, decentralized key management schemes are preferred over centralized ones. Often encryption and decryption are quite expensive and not practical when users access data from resource constrained devices. We propose a decentralized attribute based encryption (ABE) scheme with fast encryption, outsourced decryption and user revocation. Our scheme is very specific to the context of mobile cloud as the storage of encrypted data and the partial decryption of ciphertexts are dependent on the cloud and users with mobile devices can upload data to the cloud or access data from it by incurring very little cost for encryption and decryption respectively. The main idea is to divide the encryption into two phases, offline preprocessing phase which is done when the device is otherwise not in use and an online phase when the data is actually encrypted with the policy. This makes encryption faster and more efficient than existing decentralized ABE schemes. For decryption outsourcing, data users need to generate a transformed version of the decryption key allowing an untrusted proxy server to partially decrypt the ciphertext without gaining any information about the plaintext. Data users can then fully decrypt the partially decrypted ciphertext without performing any costly pairing operations. We also introduce user revocation in this scheme without incurring too much additional cost in the online phase. Comparison with other ABE schemes shows that our scheme significantly reduces computation times for both data owners and data users and highly suitable for use in mobile devices. Sourya Joyee De, Sushmita Ruj |
IEEE Trans. Cloud Comput. | 2 |
| 2020 | Efficient Proofs of Retrievability with Public Verifiability for Dynamic Cloud StorageabstractCloud service providers offer various facilities to their clients. The clients with limited resources opt for some of these facilities. They can outsource their bulk data to the cloud server. The cloud server maintains these data in lieu of monetary benefits. However, a malicious cloud server might delete some of these data to save some space and offer this extra amount of storage to another client. Therefore, the client might not retrieve her file (or some portions of it) as often as needed. Proofs of retrievability (POR) provide an assurance to the client that the server is actually storing all of her data appropriately and they can be retrieved at any point of time. In a dynamic POR scheme, the client can update her data after she uploads them to the cloud server. Moreover, in publicly verifiable POR schemes, the client can delegate her auditing task to some third party specialized for this purpose. In this work, we exploit the homomorphic hashing technique to design a publicly verifiable dynamic POR scheme that is more efficient (in terms of bandwidth required between the client and the server) than the “state-of-the-art” publicly verifiable dynamic POR scheme. We also analyze security and performance of our scheme. Binanda Sengupta, Sushmita Ruj |
IEEE Trans. Cloud Comput. | 2 |
| 2019 | FSPVDsse: A Forward Secure Publicly Verifiable Dynamic SSE Scheme
Laltu Sardar, Sushmita Ruj |
ProvSec | 2 |
| 2019 | Fuzzy keywords enabled ranked searchable encryption scheme for a public Cloud environment
Shahzaib Tahir, Sushmita Ruj, Ali Sajjad, Muttukrishnan Rajarajan |
Comput. Commun. | 2 |
| 2019 | Maximal contrast color visual secret sharing schemes
Sabyasachi Dutta, Avishek Adhikari, Sushmita Ruj |
Des. Codes Cryptogr. | 3 |
| 2018 | An Efficient Secure Distributed Cloud Storage for Append-Only DataabstractCloud computing enables users (clients) to outsource large volume of their data to cloud servers. Secure distributed cloud storage schemes ensure that multiple servers store these data in a reliable and untampered fashion. We propose an idea to construct such a scheme for static data by encoding data blocks (using error-correcting codes) and then attaching authentication information (tags) to these encoded blocks. We identify some challenges while extending this idea to accommodate append-only data. Then, we propose our secure distributed cloud storage scheme for append-only data that addresses the challenges efficiently. The main advantage of our scheme is that it enables the servers to update the parity blocks themselves. Moreover, the client need not download any data (or parity) block to update the tags of the modified parity blocks residing on the servers. Finally, we analyze the security and performance of our scheme. Binanda Sengupta, Nishant Nikam, Sushmita Ruj, Srinivasan Narayanamurthy, Siddhartha Nandi |
IEEE CLOUD | 3 |
| 2018 | BlockStore: A Secure Decentralized Storage Framework on BlockchainabstractIn order to ensure faster audits, higher transparency and security, many applications are being designed using blockchains. We propose BlockStore, a secure decentralized storage framework using blockchain technology. The primary motivation is efficient utilization of storage resources of users. Users often have un-utilized or underutilized storage in their devices. They can choose to host their storage resources when they are not in use. Users rent storage from the host for a fee for a fixed period of time and release back after the time expires. BlockStore keeps track of un-utilized storage of hosts in Space Wallet, a structure that helps in assigning storage to renters on request. The ownership of storage can be proved by logging all storage transactions in a public ledger (the blockchain), which can be verified by any user. A host cannot host the same storage to two users at the same time, nor can it tamper with the data of the renter. Renters cannot frame a host of cheating. BlockStore uses proofs of storage and data possession to verify that the hosts do not tamper with data and penalizes parties for misbehavior. Users can encrypt data for privacy. Payment and penalty are handled using smart contracts. BlockStore differs from existing solutions, by providing stronger audit that detects and penalizes misbehaving parties earlier than existing schemes. Sushmita Ruj, Mohammad Shahriar Rahman, Anirban Basu 0001, Shinsaku Kiyomoto |
AINA | 1 |
| 2018 | Secure Computation of Inner Product of Vectors with Distributed Entries and Its Applications to SVM
Sabyasachi Dutta, Nishant Nikam, Sushmita Ruj |
ISPEC | 3 |
| 2018 | Keyword-Based Delegable Proofs of Storage
Binanda Sengupta, Sushmita Ruj |
ISPEC | 2 |
| 2018 | On the economic significance of ransomware campaigns: A Bitcoin transactions perspective
Mauro Conti, Ankit Gangwal, Sushmita Ruj |
Comput. Secur. | 3 |
| 2017 | Certificate Transparency with Enhancements and Short Proofs
Binanda Sengupta, Sushmita Ruj |
ACISP (2) | 3 |
| 2017 | Bitcoin Block Withholding Attack: Analysis and MitigationabstractWe address two problems: first, we study a variant of block withholding (BWH) attack in Bitcoins and second, we propose solutions to prevent all existing types of BWH attacks in Bitcoins. We analyze the strategies of a selfish Bitcoin miner who in connivance with one pool attacks another pool and receives reward from the former mining pool for attacking the latter. We name this attack as “sponsored block withholding attack.” We present detailed quantitative analysis of the monetary incentive that a selfish miner can earn by adopting this strategy under different scenarios. We prove that under certain conditions, the attacker can maximize her revenue by adopting some strategies and by utilizing her computing power wisely. We also show that an attacker may use this strategy for attacking both the pools for earning higher amount of incentives. More importantly, we present a strategy that can effectively counter block withholding attack in any mining pool. First, we propose a generic scheme that uses cryptographic commitment schemes to counter BWH attack. Then, we suggest an alternative implementation of the same scheme using hash function. Our scheme protects a pool from rogue miners as well as rogue pool administrators. The scheme and its variant defend against BWH attack by making it impossible for the miners to distinguish between a partial proof of work and a complete proof of work. The scheme is so designed that the administrator cannot cheat on the entire pool. The scheme can be implemented by making minor changes to existing Bitcoin protocol. We also analyze the security of the scheme. Samiran Bag, Sushmita Ruj, Kouichi Sakurai |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2016 | Failure Tolerant Rational Secret SharingabstractIn existing rational secret sharing protocols, players follow a strategy that causes them to abort the protocol as soon as even a single player does not send its share. Such secret reconstruction protocols run over several rounds and it may be reasonable for a party to fail or not send its share by mistake sometimes. In practical situations, where failures (such as network failure, power outage, low battery power for mobile devices etc.) are common, this would lead to diminished chances of reconstructing the secret due to the unforgiving nature of the strategy followed. In this work, we introduce a forgiving strategy based on ostracism for one round. Here, a player that defects, i.e., does not send a share, is punished for a single round after its defection and is allowed to rejoin the game in the subsequent round. In this sense, we propose a failure-tolerant rational secret sharing protocol in the simultaneous channel model. Of course, we tolerate only occasional failures, mistakes and even intentional silence within a reasonable limit. Our protocol is suitable for a scenario where the reconstruction of the secret is absolutely necessary and failures are common. Sourya Joyee De, Sushmita Ruj |
AINA | 2 |
| 2016 | Preferential Attachment Model with Degree Bound and Its Application to Key Predistribution in WSNabstractPreferential attachment models have been widely studied in complex networks, because they can explain the formation of many networks like social networks, citation networks, power grids, and biological networks, to name a few. Motivated by the application of key predistribution in wireless sensor networks (WSN), we initiate the study of preferential attachment with degree bound. Our paper has two important contributions to two different areas. The first is a contribution in the study of complex networks. We propose preferential attachment model with degree bound for the first time. In the normal preferential attachment model, the degree distribution follows a power law, with many nodes of low degree and a few nodes of high degree. In our scheme, the nodes can have a maximum degree dmax, where dmaxis an integer chosen according to the application. The second is in the security of wireless sensor networks. We propose a new key predistribution scheme based on the above model. The important features of this model are that the network is fully connected, it has fewer keys, has larger size of the giant component and lower average path length compared with traditional key predistribution schemes and comparable resilience to random node attacks. We argue that in many networks like key predistribution and Internet of Things, having nodes of very high degree will be a bottle-neck in communication. Thus, studying preferential attachment model with degree bound will open up new directions in the study of complex networks, and will have many applications in real world scenarios. Sushmita Ruj, Arindam Pal 0001 |
AINA | 1 |
| 2016 | Publicly Verifiable Secure Cloud Storage for Dynamic Data Using Secure Network CodingabstractCloud service providers offer storage outsourcing facility to their clients. In a secure cloud storage (SCS) protocol, the integrity of the client's data is maintained. In this work, we construct a publicly verifiable secure cloud storage protocol based on a secure network coding (SNC) protocol where the client can update the outsourced data as needed. To the best of our knowledge, our scheme is the first SNC-based SCS protocol for dynamic data that is secure in the standard model and provides privacy-preserving audits in a publicly verifiable setting. Furthermore, we discuss, in details, about the (im)possibility of providing a general construction of an efficient SCS protocol for dynamic data (DSCS protocol) from an arbitrary SNC protocol. In addition, we modify an existing DSCS scheme (DPDP I) in order to support privacy-preserving audits. We also compare our DSCS protocol with other SCS schemes (including the modified DPDP I scheme). Finally, we figure out some limitations of an SCS scheme constructed using an SNC protocol. Binanda Sengupta, Sushmita Ruj |
AsiaCCS | 2 |
| 2016 | Expressive Rating Scheme by Signatures with Predications on Ratees
Hiroaki Anada, Sushmita Ruj, Kouichi Sakurai |
NSS | 2 |
| 2015 | Achieving Data Survivability and Confidentiality in Unattended Wireless Sensor NetworksabstractIn Unattended Wireless Sensor Networks (UWSNs) the nodes are subjected to hostile environment for sensing critical data. Due to the unattended nature of the network the sink is not always present. Hence, the nodes in the network are required to function in a distributed way in order to ensure Data Survivability and Data Confidentiality. In this work we address these two issues. We have proposed algorithm (s) to ensure Data Survivability by encryption and data replication. We propose a simple scheme for key management which ensures confidentiality by sharing the key among various nodes in the network so that the adversary cannot read the data by compromising a node in the network. We have compared our scheme with the existing ones, both mathematically and by simulations. Analysis shows that our scheme performs better in terms of overheads and efficiency. Arpan Sen, Shrestha Ghosh, Arinjoy Basak, Harsh Parsuram Puria, Sushmita Ruj |
AINA | 5 |
| 2015 | On the Application of Clique Problem for Proof-of-Work in Cryptocurrencies
Samiran Bag, Sushmita Ruj, Kouichi Sakurai |
Inscrypt | 2 |
| 2015 | Decentralized Access Control on Data in the Cloud with Fast Encryption and Outsourced DecryptionabstractFine grained access control is a requirement for data stored in untrusted servers like clouds. Owing to the large volume of data, decentralized key management schemes are preferred over centralized ones. Often encryption and decryption are quite expensive and not practical when users access data from resource constrained devices. We propose a decentralized attribute based encryption (ABE) scheme with fast encryption and outsourced decryption. The main idea is to divide the encryption into two phases, offline preprocessing phase which is done when the device is otherwise not in use and an online phase when the data is actually encrypted with the policy. This makes encryption faster and more efficient than existing decentralized ABE schemes. For decryption outsourcing, data users need to generate a transformed version of the decryption key allowing an untrusted proxy server to partially decrypt the ciphertext without gaining any information about the plaintext. Data users can then fully decrypt the partially decrypted ciphertext without performing any costly pairing operations. Comparison with other CP-ABE schemes shows that our scheme significantly reduces computation times for both data owners and data users. Sourya Joyee De, Sushmita Ruj |
GLOBECOM | 2 |
| 2015 | CITEX: A new citation index to measure the relative importance of authors and papers in scientific publicationsabstractEvaluating the performance of researchers and measuring the impact of papers written by scientists is the main objective of citation analysis. Various indices and metrics have been proposed for this. In this paper, we propose a new citation index CITEX, which gives normalized scores to authors and papers to determine their rankings. To the best of our knowledge, this is the first citation index which simultaneously assigns scores to both authors and papers. Using these scores, we can get an objective measure of the reputation of an author and the impact of a paper. We model this problem as an iterative computation on a publication graph, whose vertices are authors and papers, and whose edges indicate which author has written which paper. We prove that this iterative computation converges in the limit, by using a powerful theorem from linear algebra. We run this algorithm on several examples, and find that the author and paper scores match closely with what is suggested by our intuition. The algorithm is theoretically sound and runs very fast in practice. We compare this index with several existing metrics and find that CITEX gives far more accurate scores compared to the traditional metrics. Arindam Pal 0001, Sushmita Ruj |
ICC | 2 |
| 2014 | Analyzing Cascading Failures in Smart Grids under Random and Targeted AttacksabstractWe model smart grids as complex interdependent networks, and study targeted attacks on smart grids for the first time. A smart grid consists of two networks: the power network and the communication network, interconnected by edges. Occurrence of failures (attacks) in one network triggers failures in the other network, and propagates in cascades across the networks. Such cascading failures can result in disintegration of either (or both) of the networks. Earlier works considered only random failures. In practical situations, an attacker is more likely to compromise nodes selectively. We study cascading failures in smart grids, where an attacker selectively compromises the nodes with probabilities proportional to their degrees, high degree nodes are compromised with higher probability. We mathematically analyze the sizes of the giant components of the networks under targeted attacks, and compare the results with the corresponding sizes under random attacks. We show that networks disintegrate faster for targeted attacks compared to random attacks. A targeted attack on a small fraction of high degree nodes disintegrates one or both of the networks, whereas both the networks contain giant components for random attack on the same fraction of nodes. Sushmita Ruj, Arindam Pal 0001 |
AINA | 1 |
| 2014 | Should Silence be Heard? Fair Rational Secret Sharing with Silent and Non-silent Players
Sourya Joyee De, Sushmita Ruj, Asim K. Pal |
CANS | 2 |
| 2014 | Temporal Access Control with User Revocation for Cloud DataabstractWe propose a temporal access control scheme to protect and selectively access data in clouds. In many applications like healthcare, online tests, social networks, data should be accessed within a certain period of time. Although access control has been widely studied, temporal access control has not received attention. Ours is the first scheme on temporal access control with user revocation. Our scheme encrypts and stores data in clouds in such a way that only authorized users are able to decrypt it within a specified time period. We use a new variant of attribute-based encryption in order to achieve our objective. To reduce computational load during decryption, we partially outsource the decryption to a proxy server, who can gain no information about the data. We analytically show that our scheme has comparable computation and communication costs, but also supports revocation, which was not present in previous schemes. Nihal Balani, Sushmita Ruj |
TrustCom | 2 |
| 2014 | A social network approach to trust management in VANETs
Sushmita Ruj, Marcos Antonio Cavenaghi, Milos Stojmenovic, Amiya Nayak |
Peer-to-Peer Netw. Appl. | 2 |
| 2014 | Decentralized Access Control with Anonymous Authentication of Data Stored in CloudsabstractWe propose a new decentralized access control scheme for secure data storage in clouds that supports anonymous authentication. In the proposed scheme, the cloud verifies the authenticity of the series without knowing the user's identity before storing data. Our scheme also has the added feature of access control in which only valid users are able to decrypt the stored information. The scheme prevents replay attacks and supports creation, modification, and reading data stored in the cloud. We also address user revocation. Moreover, our authentication and access control scheme is decentralized and robust, unlike other access control schemes designed for clouds which are centralized. The communication, computation, and storage overheads are comparable to centralized approaches. Sushmita Ruj, Milos Stojmenovic, Amiya Nayak |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2013 | Secure and privacy preserving hierarchical wireless sensor networks using hybrid key management techniqueabstractWe propose a key management scheme for two-tire hierarchical mobile network using triple key distribution. Sensor nodes are divided into clusters managed by cluster heads which collect and aggregate data and send to base stations. The use of both symmetric and public key techniques makes the network highly resilient to node compromise. The nodes are resource constrained and thus communicate securely using symmetric triple key distribution technique. The cluster heads are powerful and use asymmetric key distribution techniques. The anonymity of cluster heads while forwarding messages is also preserved in our protocol. To the best of our knowledge, this is the first key management scheme which uses both symmetric and asymmetric triple key distribution mechanism. The analysis shows that our scheme is highly secure, preserves privacy of cluster heads and can support efficient addition and deletion of nodes. Sushmita Ruj, Kouchui Sakurai |
GLOBECOM | 1 |
| 2013 | Enhanced privacy and reliability for secure geocasting in VANETabstractCurrent geocasting algorithms for VANETs are being designed to enable either private or reliable communications, but not both. Existing algorithms preserve privacy by minimizing the information used for routing, and sacrifice message delivery success. On the other hand, reliable protocols often store node information that can be used to compromise a vehicle's privacy. We propose a secure, privacy-preserving geocasting protocol for VANETs that uses direction-based dissemination and ensures confidentiality. Privacy is achieved via unlinkable pseudonymous channels, and encryption and authentication with a public key technique. To reduce message duplication, we apply dynamic traffic restriction and probabilistic forwarding techniques, which depend on message rate and cumulative payload, as well as the value of the angle of spreading of the direction-based scheme. Our analysis shows that due to dynamic traffic restriction, node density does not meaningfully affect reliability, while the angle of spreading does have a significant influence. Antonio Prado, Sushmita Ruj, Amiya Nayak |
ICC | 2 |
| 2013 | Data authentication scheme for Unattended Wireless Sensor Networks against a mobile adversaryabstractAn Unattended Wireless Sensor Network (UWSN) is a type of sensor network where a trusted sink visits each node periodically to collect the data. Due to the offline nature of this network, every node has to secure its data until the next visit of the sink which makes the network susceptible of attacks focusing on the data collected. In this work, we focus on the data authentication in the presence of a mobile adversary aiming to modify the data without being detected. We propose a data authentication scheme which uses inexpensive cryptographic primitives and few message exchanges. The proposed scheme is analyzed both mathematically and using simulations proving that the proposed scheme is better than the previous schemes in terms of security and communication overhead. Sasi Kiran V. L. Reddy, Sushmita Ruj, Amiya Nayak |
WCNC | 2 |
| 2013 | Pairwise and Triple Key Distribution in Wireless Sensor Networks with ApplicationsabstractWe address pairwise and (for the first time) triple key establishment problems in wireless sensor networks (WSN). Several types of combinatorial designs have already been applied in key establishment. A BIBD(v, b, r, k, λ) (or t - (v, b, r, k, λ) design) can be mapped to a sensor network, where v represents the size of the key pool, b represents the maximum number of nodes that the network can support, and k represents the size of the key chain. Any pair (or t-subset) of keys occurs together uniquely in exactly λ nodes; λ = 2 and λ = 3 are used to establish unique pairwise or triple keys. We use several known constructions of designs with λ = 2, to predistribute keys in sensors. We also describe a new construction of a design called strong Steiner trade and use it for pairwise key establishment. To the best of our knowledge, this is the first paper on application of trades to key distribution. Our scheme is highly resilient against node capture attacks (achieved by key refreshing) and is applicable for mobile sensor networks (as key distribution is independent on the connectivity graph), while preserving low storage, computation and communication requirements. We introduce a novel concept of triple key distribution, in which three nodes share common keys, and discuss its application in secure forwarding, detecting malicious nodes and key management in clustered sensor networks. We present a polynomial-based and a combinatorial approach (using trades) for triple key distribution. We also extend our construction to simultaneously provide pairwise and triple key distribution scheme, and apply it to secure data aggregation. Sushmita Ruj, Amiya Nayak, Ivan Stojmenovic |
IEEE Trans. Computers | 1 |
| 2012 | Privacy Preserving Access Control with Authentication for Securing Data in CloudsabstractIn this paper, we propose a new privacy preserving authenticated access control scheme for securing data in clouds. In the proposed scheme, the cloud verifies the authenticity of the user without knowing the user's identity before storing information. Our scheme also has the added feature of access control in which only valid users are able to decrypt the stored information. The scheme prevents replay attacks and supports creation, modification, and reading data stored in the cloud. Moreover, our authentication and access control scheme is decentralized and robust, unlike other access control schemes designed for clouds which are centralized. The communication, computation, and storage overheads are comparable to centralized approaches. Sushmita Ruj, Milos Stojmenovic, Amiya Nayak |
CCGRID | 1 |
| 2012 | Distributed data survivability schemes in mobile Unattended Wireless Sensor NetworksabstractIn a mobile Unattended Wireless Sensor Network (UWSN), a trusted sink visits each sensor node periodically to collect data. Data has to be secured until the next visit of the sink. Securing the data from an adversary in UWSN with mobile nodes is a challenging task.We present two non-cryptographic algorithms (DS-PADV and DS-RADV) to ensure data survivability in mobile UWSN. The DS-PADV protects against proactive adversary which compromises nodes before identifying its target. DS-RADV makes the network secure against reactive adversary which compromises nodes after identifying the target. We analyze memory overheads and communication costs both mathematically and using simulations. In existing schemes, sensors remain static between visits from the sink, whereas in our scheme sensors can move between successive visits from the sink. We show that our approaches perform better than known schemes in terms of communication overheads. Sasi Kiran V. L. Reddy, Sushmita Ruj, Amiya Nayak |
GLOBECOM | 2 |
| 2012 | Improved distinguishers for HC-128
Paul Stankovski Wagner, Sushmita Ruj, Martin Hell, Thomas Johansson 0001 |
Des. Codes Cryptogr. | 2 |
| 2011 | Fully secure pairwise and triple key distribution in wireless sensor networks using combinatorial designsabstractWe address pairwise and (for the first time) triple key establishment problems in wireless sensor networks (WSN). We use combinatorial designs to establish pairwise keys between nodes in a WSN. A BIBD(v; b; r; k; λ) (or t - (v; b; r; k; λ)) design can be mapped to a sensor network, where v represents the size of the key pool, b represents the maximum number of nodes that the network can support, k represents the size of the key chain. Any pair (or t-subset) of keys occurs together uniquely in exactly λ nodes. λ = 2 and λ = 3 are used to establish unique pairwise or triple keys. Our pairwise key distribution is the first one that is fully secure (none of the links among uncompromised nodes is affected) and applicable for mobile sensor networks (as key distribution is independent on the connectivity graph), while preserving low storage, computation and communication requirements. We also use combinatorial trades to establish pairwise keys. This is the first time that trades are being applied to key management. We describe a new construction of Strong Steiner Trades. We introduce a novel concept of triple key distribution, in which a common key is established between three nodes. This allows secure passive monitoring of forwarding progress in routing tasks. We present a polynomial-based approach and a combinatorial approach (using trades) for triple key distribution. Sushmita Ruj, Amiya Nayak, Ivan Stojmenovic |
INFOCOM | 1 |
| 2011 | Distributed Fine-Grained Access Control in Wireless Sensor NetworksabstractIn mission-critical activities, each user is allowed to access some specific, but not all, data gathered by wireless sensor networks. Yu et al recently proposed a centralized fine grained data access control mechanism for sensor networks, which exploits a cryptographic primitive called attribute based encryption (ABE). There is only one trusted authority to distribute keys to the sensor nodes and the users. Compromising the single authority can undermine the whole network. We propose a fully distributed access control method, which has several authorities instead of one. Each sensor has a set of attributes and each user has an access structure of attributes. A message from a sensor is encrypted such that only a user with matching set of attributes can decrypt. Compared to, our schemes need simpler access structure which make secret key distribution more computation efficient, when user rights are modified. We prove that our scheme can tolerate compromising all but one distribution centers, which independently distribute their contributions to a single user key. Our scheme do not increase the computation and communication costs of the sensors, making it highly desirable for fine grained access control. Sushmita Ruj, Amiya Nayak, Ivan Stojmenovic |
IPDPS | 1 |
| 2011 | Limitations of trust management schemes in VANET and countermeasuresabstractVehicular networks ensure that the information received from any vehicle is promptly and correctly propagated to nearby vehicles, to prevent accidents. A crucial point is how to trust the information transmitted, when the neighboring vehicles are rapidly changing and moving in and out of range. Current trust management schemes for vehicular networks establish trust by voting on the decision received by several nodes, which might not be required for practical scenarios. It might just be enough to check the validity of incoming information. Due to the ephemeral nature of vehicular networks, reputation schemes for mobile ad hoc networks (MANETs) cannot be applied to vehicular ad hoc networks (VANET). We point out several limitations of trust management schemes for VANET. In particular, we identify the problem of information cascading and oversampling, which commonly arise in social networks. Oversampling is a situation in which a node observing two or more nodes, takes into consideration both their opinions equally without knowing that they might have influenced each other in decision making. We show that simple voting for decision making, leads to oversampling and gives incorrect results. We propose an algorithm to overcome this problem in VANET. This is the first paper which discusses the concept of cascading effect and oversampling effects to ad hoc networks. Sushmita Ruj, Marcos Antonio Cavenaghi, Amiya Nayak |
PIMRC | 2 |
| 2011 | DACC: Distributed Access Control in CloudsabstractWe propose a new model for data storage and access in clouds. Our scheme avoids storing multiple encrypted copies of same data. In our framework for secure data storage, cloud stores encrypted data (without being able to decrypt them). The main novelty of our model is addition of key distribution centers (KDCs). We propose DACC (Distributed Access Control in Clouds) algorithm, where one or more KDCs distribute keys to data owners and users. KDC may provide access to particular fields in all records. Thus, a single key replaces separate keys from owners. Owners and users are assigned certain set of attributes. Owner encrypts the data with the attributes it has and stores them in the cloud. The users with matching set of attributes can retrieve the data from the cloud. We apply attribute-based encryption based on bilinear pairings on elliptic curves. The scheme is collusion secure; two users cannot together decode any data that none of them has individual right to access. DACC also supports revocation of users, without redistributing keys to all the users of cloud services. We show that our approach results in lower communication, computation and storage overheads, compared to existing models and schemes. Sushmita Ruj, Amiya Nayak, Ivan Stojmenovic |
TrustCom | 1 |
| 2011 | On Data-Centric Misbehavior Detection in VANETsabstractDetecting misbehavior (such as transmissions of false information) in vehicular ad hoc networks (VANETs) is a very important problem with wide range of implications, including safety related and congestion avoidance applications. We discuss several limitations of existing misbehavior detection schemes (MDS) designed for VANETs. Most MDS are concerned with detection of malicious nodes. In most situations, vehicles would send wrong information because of selfish reasons of their owners, e.g. for gaining access to a particular lane. It is therefore more important to detect false information than to identify misbehaving nodes. We introduce the concept of data-centric misbehavior detection and propose algorithms which detect false alert messages and misbehaving nodes by observing their actions after sending out the alert messages. With the data-centric MDS, each node can decide whether an information received is correct or false. The decision is based on the consistency of recent messages and new alerts with reported and estimated vehicle positions. No voting or majority decisions is needed, making our MDS resilient to Sybil attacks. After misbehavior is detected, we do not revoke all the secret credentials of misbehaving nodes, as done in most schemes. Instead, we impose fines on misbehaving nodes (administered by the certification authority), discouraging them to act selfishly. This reduces the computation and communication costs involved in revoking all the secret credentials of misbehaving nodes. Sushmita Ruj, Marcos Antonio Cavenaghi, Amiya Nayak, Ivan Stojmenovic |
VTC Fall | 1 |
| 2009 | Key predistribution using combinatorial designs for grid-group deployment scheme in wireless sensor networksabstractWe propose a new grid-group deployment scheme in wireless sensor networks. We use combinatorial designs for key predistribution in sensor nodes. The deployment region is divided into square regions. The predistribution scheme has the advantage that all nodes within a particular region can communicate with each other directly and nodes which lie in a different regions can communicate via special nodes called agents which have more resources than the general nodes. The number of agents in a region is always three, whatever the size of the network. We give measures of resiliency taking the Lee distance into account. Apart from considering the resiliency in terms of fraction of links broken, we also consider the resiliency as the number of nodes and regions disconnected when some sensor are compromised. This second measure, though very important, had not been studied so far in key predistribution schemes which use deployment knowledge. We find that the resiliency as the fraction of links compromised is better than existing schemes. The number of keys preloaded in each sensor node is much less than all existing schemes and nodes are either directly connected or connected via two hop paths. The deterministic key predistribution schemes result in constant-time computation overhead for shared key discovery and path key establishment. Sushmita Ruj, Bimal K. Roy |
ACM Trans. Sens. Networks | 1 |
| 2008 | Key Predistribution Schemes Using Codes in Wireless Sensor Networks
Sushmita Ruj, Bimal K. Roy |
Inscrypt | 1 |
| 2007 | Key Predistribution Using Partially Balanced Designs in Wireless Sensor Networks
Sushmita Ruj, Bimal K. Roy |
ISPA | 1 |