EDBT 2026 Demo / reviewers in the wild / expert
Benny Pinkas
dblp:31/1735
· DBLP profile ↗
94ranked-venue papers
12as first author
14since 2021 · last 2026
0000-0002-9053-3024ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 79 · 11 first-author · 13 since 2021Theory of computation · 10 · 1 since 2021Computer networks · 5Artificial intelligence and machine learning · 3 · 1 since 2021Systems, architecture and hardware · 1Databases, data management, data science and information retrieval · 1Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Weighted Batched Threshold Encryption With Applications to Mempool Privacy
Kushal Babel, Sourav Das 0001, Babak Poorebrahim Gilkalaye, Arup Mondal, Benny Pinkas, Peter Rindal, Aayush Yadav |
SP | 6 |
| 2025 | Efficiently-Thresholdizable Batched Identity Based Encryption, with Applications
Rex Fernando, Benny Pinkas |
CRYPTO (3) | 3 |
| 2025 | Distributed Randomness Using Weighted VUFs
Sourav Das 0001, Benny Pinkas, Alin Tomescu, Zhuolun Xiang |
EUROCRYPT (7) | 2 |
| 2025 | Verifiable Secret Sharing SimplifiedabstractVerifiable Secret Sharing (VSS) is a fundamental building block in cryptography. Despite its importance and extensive studies, existing VSS protocols are often complex and inefficient. Many of them do not support dual thresholds, are not publicly verifiable, or do not properly terminate in asynchronous networks. This paper presents a new and simple approach for designing VSS protocols in synchronous and asynchronous networks. Our VSS protocols are optimally fault-tolerant, i.e., they tolerate a 1/2 and a 1/3 fraction of malicious nodes in synchronous and asynchronous networks, respectively. They only require a public key infrastructure and the hardness of discrete logarithms. Our protocols support dual thresholds, and their transcripts are publicly verifiable. We implement our VSS protocols and evaluate them in a geo-distributed setting with up to 256 nodes. The evaluation demonstrates that our protocols offer asynchronous termination and public verifiability with performance that is comparable to that of existing schemes that lack these features. Compared to the existing schemes with similar guarantees, our approach lowers the bandwidth usage and latency by up to 90%. Sourav Das 0001, Zhuolun Xiang, Alin Tomescu, Alexander Spiegelman, Benny Pinkas, Ling Ren 0001 |
SP | 5 |
| 2025 | Privacy-Preserving Epidemiological Modeling on Mobile GraphsabstractThe latest pandemic COVID-19 brought governments worldwide to use various containment measures to control its spread, such as contact tracing, social distance regulations, and curfews. Epidemiological simulations are commonly used to assess the impact of those policies before they are implemented. Unfortunately, the scarcity of relevant empirical data, specifically detailed social contact graphs, hampered their predictive accuracy. As this data is inherently privacy-critical, a method is urgently needed to perform powerful epidemiological simulations on real-world contact graphs without disclosing any sensitive information. In this work, we present RIPPLE, a privacy-preserving epidemiological modeling framework enabling standard models for infectious disease on a population’s real contact graph while keeping all contact information locally on the participants’ devices. As a building block of independent interest, we present PIR-SUM, a novel extension to private information retrieval for secure download of element sums from a database. Our protocols are supported by a proof-of-concept implementation, demonstrating a 2-week simulation over half a million participants completed in 7 minutes, with each participant communicating less than 50 KB. Daniel Günther 0004, Marco Holz, Benjamin Judkewitz, Helen Möllering, Benny Pinkas, Thomas Schneider 0003, Ajith Suresh |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | Distributing Keys and Random Secrets with Constant Complexity
Benny Applebaum, Benny Pinkas |
TCC (4) | 2 |
| 2023 | Secure Statistical Analysis on Multiple Datasets: Join and Group-By
Gilad Asharov, Koki Hamada, Ryo Kikuchi, Ariel Nof, Benny Pinkas, Junichi Tomida |
CCS | 5 |
| 2023 | How to Recover a Secret with O(n) Additions
Benny Applebaum, Oded Nir, Benny Pinkas |
CRYPTO (1) | 3 |
| 2022 | Poster: Privacy-Preserving Epidemiological Modeling on Mobile GraphsabstractOver the last two years, governments all over the world have used a variety of containment measures to control the spread of \covid, such as contact tracing, social distance regulations, and curfews. Epidemiological simulations are commonly used to assess the impact of those policies before they are implemented in actuality. Unfortunately, their predictive accuracy is hampered by the scarcity of relevant empirical data, concretely detailed social contact graphs. As this data is inherently privacy-critical, there is an urgent need for a method to perform powerful epidemiological simulations on real-world contact graphs without disclosing sensitive information. Daniel Günther 0004, Marco Holz, Benjamin Judkewitz, Helen Möllering, Benny Pinkas, Thomas Schneider 0003, Ajith Suresh |
CCS | 5 |
| 2022 | Efficient Secure Three-Party Sorting with Applications to Data Analysis and Heavy HittersabstractWe present a three-party sorting protocol secure against passive and active adversaries in the honest majority setting. The protocol can be easily combined with other secure protocols which work on shared data, and thus enable different data analysis tasks, such as private set intersection of shared data, deduplication, and the identification of heavy hitters. The new protocol computes a stable sort. It is based on radix sort and is asymptotically better than previous secure sorting protocols. It improves on previous radix sort protocols by not having to shuffle the entire length of the items after each comparison step. Gilad Asharov, Koki Hamada, Dai Ikarashi, Ryo Kikuchi, Ariel Nof, Benny Pinkas, Katsumi Takahashi, Junichi Tomida |
CCS | 6 |
| 2022 | GPU-accelerated PIR with Client-Independent Preprocessing for Large-Scale Applications
Daniel Günther 0004, Maurice Heymann, Benny Pinkas, Thomas Schneider 0003 |
USENIX Security Symposium | 3 |
| 2021 | Fairness in the Eyes of the Data: Certifying Machine-Learning ModelsabstractWe present a framework that allows to certify the fairness degree of a model based on an interactive and privacy-preserving test. The framework verifies any trained model, regardless of its training process and architecture. Thus, it allows us to evaluate any deep learning model on multiple fairness definitions empirically. We tackle two scenarios, where either the test data is privately available only to the tester or is publicly known in advance, even to the model creator. We investigate the soundness of the proposed approach using theoretical analysis and present statistical guarantees for the interactive test. Finally, we provide a cryptographic technique to automate fairness testing and certified inference with only black-box access to the model at hand while hiding the participants' sensitive data. Shahar Segal, Yossi Adi, Benny Pinkas, Carsten Baum, Chaya Ganesh, Joseph Keshet |
AIES | 3 |
| 2021 | Secure Graph Analysis at ScaleabstractWe present a highly-scalable secure computation of graph algorithms, which hides all information about the topology of the graph or other input values associated with nodes or edges. The setting is where all nodes and edges of the graph are secret-shared between multiple servers, and a secure computation protocol is run between these servers. While the method is general, we demonstrate it in a 3-server setting with an honest majority, with either semi-honest security or full security. A major technical contribution of our work is replacing the usage of secure sort protocols with secure shuffles, which are much more efficient. Full security against malicious behavior is achieved by adding an efficient verification for the shuffle operation, and computing circuits using fully secure protocols. We demonstrate the applicability of this technology by implementing two major algorithms: computing breadth-first search (BFS), which is also useful for contact tracing on private contact graphs, and computing maximal independent set (MIS). We implement both algorithms, with both semi-honest and full security, and run them within seconds on graphs of millions of elements. Toshinori Araki, Jun Furukawa 0001, Kazuma Ohara, Benny Pinkas, Hanan Rosemarin, Hikaru Tsuchida 0001 |
CCS | 4 |
| 2021 | Oblivious Key-Value Stores and Amplification for Private Set Intersection
Gayathri Garimella, Benny Pinkas, Mike Rosulek, Ni Trieu, Avishay Yanai |
CRYPTO (2) | 2 |
| 2020 | Blinder - Scalable, Robust Anonymous Committed BroadcastabstractAnonymous Committed Broadcast is a functionality that extends DC-nets and allows a set of clients to privately commit messages to set of servers, which can then simultaneously open all committed messages in a random ordering. Anonymity holds since no one can learn the ordering or the content of the client's committed message. We present Blinder, the first system that provides a scalable and fully robust solution for anonymous committed broadcast. Blinder maintains both properties of security (anonymity) and robustness (aka. 'guaranteed output delivery' or 'availability') in the face of a global active (malicious) adversary. Moreover, Blinder is censorship resistant, that is, an honest client cannot be blocked from participating. Blinder obtains its security and scalability by carefully combining classical and state-of-the-art techniques from the fields of anonymous communication and secure multiparty computation (MPC). Relying on MPC for such a system is beneficial since it naturally allows the parties (servers) to enforce some properties on accepted messages prior their publication. A GPU based implementation of Blinder with 5 servers, which accepts 1 million clients, incurs a latency of less than 8 minutes; faster by a factor of $>100$ than the 3-servers Riposte protocol (S&P '15), which is not robust and not censorship resistant; we get an even larger factor when comparing to AsynchroMix and PowerMix (CCS '19), which are the only ones that guarantee fairness (or robustness in the online phase). Ittai Abraham, Benny Pinkas, Avishay Yanai |
CCS | 2 |
| 2020 | PSI from PaXoS: Fast, Malicious Private Set Intersection
Benny Pinkas, Mike Rosulek, Ni Trieu, Avishay Yanai |
EUROCRYPT (2) | 1 |
| 2020 | Flaw Label: Exploiting IPv6 Flow LabelabstractThe IPv6 protocol was designed with security in mind. One of the changes that IPv6 has introduced over IPv4 is a new 20-bit flow label field in its protocol header.We show that remote servers can use the flow label field in order to assign a unique ID to each device when communicating with machines running Windows 10 (versions 1703 and higher), and Linux and Android (kernel versions 4.3 and higher). The servers are then able to associate the respective device IDs with subsequent transmissions sent from those machines. This identification is done by exploiting the flow label field generation logic and works across all browsers regardless of network changes. Furthermore, a variant of this attack also works passively, namely without actively triggering traffic from those machines.To design the attack we reverse-engineered and cryptanalyzed the Windows flow label generation code and inspected the Linux kernel flow label generation code. We provide a practical technique to partially extract the key used by each of these algorithms, and observe that this key can identify individual devices across networks, VPNs, browsers and privacy settings. We deployed a demo (for both Windows and Linux/Android) showing that key extraction and machine fingerprinting works in the wild, and tested it from networks around the world. Jonathan Berger, Amit Klein 0001, Benny Pinkas |
SP | 3 |
| 2020 | Towards Scalable Threshold CryptosystemsabstractThe resurging interest in Byzantine fault tolerant systems will demand more scalable threshold cryptosystems. Unfortunately, current systems scale poorly, requiring time quadratic in the number of participants. In this paper, we present techniques that help scale threshold signature schemes (TSS), verifiable secret sharing (VSS) and distributed key generation (DKG) protocols to hundreds of thousands of participants and beyond. First, we use efficient algorithms for evaluating polynomials at multiple points to speed up computing Lagrange coefficients when aggregating threshold signatures. As a result, we can aggregate a 130,000 out of 260,000 BLS threshold signature in just 6 seconds (down from 30 minutes). Second, we show how "authenticating" such multipoint evaluations can speed up proving polynomial evaluations, a key step in communication-efficient VSS and DKG protocols. As a result, we reduce the asymptotic (and concrete) computational complexity of VSS and DKG protocols from quadratic time to quasilinear time, at a small increase in communication complexity. For example, using our DKG protocol, we can securely generate a key for the BLS scheme above in 2.3 hours (down from 8 days). Our techniques improve performance for thresholds as small as 255 and generalize to any Lagrange-based threshold scheme, not just threshold signatures. Our work has certain limitations: we require a trusted setup, we focus on synchronous VSS and DKG protocols and we do not address the worst-case complaint overhead in DKGs. Nonetheless, we hope it will spark new interest in designing large-scale distributed systems. Alin Tomescu, Ittai Abraham, Benny Pinkas, Guy Golan-Gueta, Srini Devadas |
SP | 5 |
| 2019 | How to (not) Share a Password: Privacy Preserving Protocols for Finding Heavy Hitters with Adversarial BehaviorabstractBad choices of passwords were and are a pervasive problem. Users choosing weak passwords do not only compromise themselves, but the whole ecosystem. E.g, common and default passwords in IoT devices were exploited by hackers to create botnets and mount severe attacks on large Internet services, such as the Mirai botnet DDoS attack. We present a method to help protect the Internet from such large scale attacks. Our method enables a server to identify popular passwords (heavy hitters), and publish a list of over-popular passwords that must be avoided. This filter ensures that no single password can be used to compromise a large percentage of the users. The list is dynamic and can be changed as new users are added or when current users change their passwords. We apply maliciously secure two-party computation and differential privacy to protect the users' password privacy. Our solution does not require extra hardware or cost, and is transparent to the user. Our private heavy hitters construction is secure even against a malicious coalition of devices which tries to manipulate the protocol to hide the popularity of some password that the attacker is exploiting. It also ensures differential privacy under continual observation of the blacklist as it changes over time. As a reality check we conducted three tests: computed the guarantees that the system provides wrt a few publicly available databases, ran full simulations on those databases, and implemented and analyzed a proof-of-concept on an IoT device. Our construction can also be used in other settings to privately learn heavy hitters in the presence of an active malicious adversary. E.g., learning the most popular sites accessed by the Tor network. Moni Naor, Benny Pinkas, Eyal Ronen |
CCS | 2 |
| 2019 | Make Some ROOM for the Zeros: Data Sparsity in Secure Distributed Machine LearningabstractExploiting data sparsity is crucial for the scalability of many data analysis tasks. However, while there is an increasing interest in efficient secure computation protocols for distributed machine learning, data sparsity has so far not been considered in a principled way in that setting. Phillipp Schoppmann, Adrià Gascón, Mariana Raykova 0001, Benny Pinkas |
CCS | 4 |
| 2019 | SpOT-Light: Lightweight Private Set Intersection from Sparse OT Extension
Benny Pinkas, Mike Rosulek, Ni Trieu, Avishay Yanai |
CRYPTO (3) | 1 |
| 2019 | SBFT: A Scalable and Decentralized Trust InfrastructureabstractSBFT is a state of the art Byzantine fault tolerant state machine replication system that addresses the challenges of scalability, decentralization and global geo-replication. SBFT is optimized for decentralization and is experimentally evaluated on a deployment of more than 200 active replicas withstanding a malicious adversary controlling f=64 replicas. Our experiments show how the different algorithmic ingredients of SBFT contribute to its performance and scalability. The results show that SBFT simultaneously provides almost 2x better throughput and about 1.5x better latency relative to a highly optimized system that implements the PBFT protocol. To achieve this performance improvement, SBFT uses a combination of four ingredients: using collectors and threshold signatures to reduce communication to linear, using an optimistic fast path, reducing client communication and utilizing redundant servers for the fast path. SBFT is the first system to implement a correct dual-mode view change protocol that allows to efficiently run either an optimistic fast path or a fallback slow path without incurring a view change to switch between modes. Guy Golan-Gueta, Ittai Abraham, Shelly Grossman, Dahlia Malkhi, Benny Pinkas, Michael K. Reiter, Dragos-Adrian Seredinschi, Orr Tamir, Alin Tomescu |
DSN | 5 |
| 2019 | Efficient Circuit-Based PSI with Linear Communication
Benny Pinkas, Thomas Schneider 0003, Avishay Yanai |
EUROCRYPT (3) | 1 |
| 2019 | DNS Cache-Based User Tracking
Amit Klein 0001, Benny Pinkas |
NDSS | 2 |
| 2019 | From IP ID to Device ID and KASLR Bypass
Amit Klein 0001, Benny Pinkas |
USENIX Security Symposium | 2 |
| 2019 | Efficient Constant-Round Multi-party Computation Combining BMR and SPDZ
Yehuda Lindell, Benny Pinkas, Nigel P. Smart, Avishay Yanai |
J. Cryptol. | 2 |
| 2018 | Distributed SSH Key Management with Proactive RSA Threshold Signatures
Yotam Harchol, Ittai Abraham, Benny Pinkas |
ACNS | 3 |
| 2018 | Fast Distributed RSA Key Generation for Semi-honest and Malicious AdversariesabstractWe present two new, highly efficient, protocols for securely generating a distributed RSA key pair in the two-party setting. One protocol is semi-honestly secure and the other maliciously secure. Both are constant round and do not rely on any specific number-theoretic assumptions and improve significantly over the state-of-the-art by allowing a slight leakage (which we show to not affect security). For our maliciously secure protocol our most significant improvement comes from executing most of the protocol in a “strong” semi-honest manner and then doing a single, light, zero-knowledge argument of correct execution. We introduce other significant improvements as well. One such improvement arrives in showing that certain, limited leakage does not compromise security, which allows us to use lightweight subprotocols. Another improvement, which may be of independent interest, comes in our approach for multiplying two large integers using OT, in the malicious setting, without being susceptible to a selective-failure attack. Finally, we implement our malicious protocol and show that its performance is an order of magnitude better than the best previous protocol, which provided only semi-honest security. These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves. Tore Kasper Frederiksen, Yehuda Lindell, Valery Osheter, Benny Pinkas |
CRYPTO (2) | 4 |
| 2018 | Efficient Circuit-Based PSI via Cuckoo Hashing
Benny Pinkas, Thomas Schneider 0003, Christian Weinert, Udi Wieder |
EUROCRYPT (3) | 1 |
| 2018 | Turning Your Weakness Into a Strength: Watermarking Deep Neural Networks by Backdooring
Yossi Adi, Carsten Baum, Moustapha Cissé, Benny Pinkas, Joseph Keshet |
USENIX Security Symposium | 4 |
| 2018 | Fast Garbling of Circuits Under Standard Assumptions
Shay Gueron, Yehuda Lindell, Ariel Nof, Benny Pinkas |
J. Cryptol. | 4 |
| 2018 | Scalable Private Set Intersection Based on OT ExtensionabstractPrivate set intersection (PSI) allows two parties to compute the intersection of their sets without revealing any information about items that are not in the intersection. It is one of the best studied applications of secure computation and many PSI protocols have been proposed. However, the variety of existing PSI protocols makes it difficult to identify the solution that performs best in a respective scenario, especially since they were not compared in the same setting. In addition, existing PSI protocols are several orders of magnitude slower than an insecure naïve hashing solution, which is used in practice. In this article, we review the progress made on PSI protocols and give an overview of existing protocols in various security models. We then focus on PSI protocols that are secure against semi-honest adversaries and take advantage of the most recent efficiency improvements in Oblivious Transfer (OT) extension, propose significant optimizations to previous PSI protocols, and suggest a new PSI protocol whose runtime is superior to that of existing protocols. We compare the performance of the protocols, both theoretically and experimentally, by implementing all protocols on the same platform, give recommendations on which protocol to use in a particular setting, and evaluate the progress on PSI protocols by comparing them to the currently employed insecure naïve hashing protocol. We demonstrate the feasibility of our new PSI protocol by processing two sets with a billion elements each. Benny Pinkas, Thomas Schneider 0003, Michael Zohner |
ACM Trans. Priv. Secur. | 1 |
| 2017 | Practical Multi-party Private Set Intersection from Symmetric-Key TechniquesabstractWe present a new paradigm for multi-party private set intersection (PSI) that allows $n$ parties to compute the intersection of their datasets without revealing any additional information. We explore a variety of instantiations of this paradigm. Our protocols avoid computationally expensive public-key operations and are secure in the presence of any number of semi-honest participants (i.e., without an honest majority). Vladimir Kolesnikov, Naor Matania, Benny Pinkas, Mike Rosulek, Ni Trieu |
CCS | 3 |
| 2017 | The Circle Game: Scalable Private Membership Test Using Trusted HardwareabstractMalware checking is changing from being a local service to a cloud-assisted one where users' devices query a cloud server, which hosts a dictionary of malware signatures, to check if particular applications are potentially malware. Whilst such an architecture gains all the benefits of cloud-based services, it opens up a major privacy concern since the cloud service can infer personal traits of the users based on the lists of applications queried by their devices. Private membership test (PMT) schemes can remove this privacy concern. However, known PMT schemes do not scale well to a large number of simultaneous users and high query arrival rates. We propose a simple PMT approach using a carousel: circling the entire dictionary through trusted hardware on the cloud server. Users communicate with the trusted hardware via secure channels. We show how the carousel approach, using different data structures to represent the dictionary, can be realized on two different commercial hardware security architectures (ARM TrustZone and Intel SGX). We highlight subtle aspects of securely implementing seemingly simple PMT schemes on these architectures. Through extensive experimental analysis, we show that for the malware checking scenario our carousel approach surprisingly outperforms Path ORAM on the same hardware by supporting a much higher query arrival rate while guaranteeing acceptable response latency for individual queries. Sandeep Tamrakar, Jian Liu 0012, Andrew Paverd, Jan-Erik Ekberg, Benny Pinkas, N. Asokan |
AsiaCCS | 5 |
| 2017 | Private Set Intersection for Unequal Set Sizes with Mobile ApplicationsabstractAbstract Private set intersection (PSI) is a cryptographic technique that is applicable to many privacy-sensitive scenarios. For decades, researchers have been focusing on improving its efficiency in both communication and computation. However, most of the existing solutions are inefficient for an unequal number of inputs, which is common in conventional client-server settings. In this paper, we analyze and optimize the efficiency of existing PSI protocols to support precomputation so that they can efficiently deal with such input sets. We transform four existing PSI protocols into the precomputation form such that in the setup phase the communication is linear only in the size of the larger input set, while in the online phase the communication is linear in the size of the smaller input set. We implement all four protocols and run experiments between two PCs and between a PC and a smartphone and give a systematic comparison of their performance. Our experiments show that a protocol based on securely evaluating a garbled AES circuit achieves the fastest setup time by several orders of magnitudes, and the fastest online time in the PC setting where AES-NI acceleration is available. In the mobile setting, the fastest online time is achieved by a protocol based on the Diffie-Hellman assumption. Ágnes Kiss, Jian Liu 0012, Thomas Schneider 0003, N. Asokan, Benny Pinkas |
Proc. Priv. Enhancing Technol. | 5 |
| 2017 | Securely Computing a Ground Speed ModelabstractConsider a server offering risk assessment services and potential clients of these services. The risk assessment model that is run by the server is based on current and historical data of the clients. However, the clients might prefer not sharing such sensitive data with external parties such as the server, and the server might consider the possession of this data as a liability rather than an asset. Secure multi-party computation (MPC) enables one, in principle, to compute any function while hiding the inputs to the function, and would thus enable the computation of the risk assessment model while hiding the client’s data from the server. However, a direct application of a generic MPC solution to this problem is rather inefficient due to the large scale of the data and the complexity of the function. We examine a specific case of risk assessment—the ground speed model. In this model, the geographical locations of successive user-authentication attempts are compared, and a warning flag is raised if the physical speed required to move between these locations is greater than some threshold, and some other conditions, such as authentication from two related networks, do not hold. We describe a very efficient secure computation solution that is tailored for this problem. This solution demonstrates that a risk model can be applied over encrypted data with sufficient efficiency to fit the requirements of commercial systems. Eyal Kolman, Benny Pinkas |
ACM Trans. Intell. Syst. Technol. | 2 |
| 2016 | Efficient Set Intersection with Simulation-Based Security
Michael J. Freedman, Carmit Hazay, Kobbi Nissim, Benny Pinkas |
J. Cryptol. | 4 |
| 2015 | Fast Garbling of Circuits Under Standard AssumptionsabstractProtocols for secure computation enable mutually distrustful parties to jointly compute on their private inputs without revealing anything but the result. Over recent years, secure computation has become practical and considerable effort has been made to make it more and more efficient. A highly important tool in the design of two-party protocols is Yao's garbled circuit construction (Yao 1986), and multiple optimizations on this primitive have led to performance improvements of orders of magnitude over the last years. However, many of these improvements come at the price of making very strong assumptions on the underlying cryptographic primitives being used (e.g., that AES is secure for related keys, that it is circular secure, and even that it behaves like a random permutation when keyed with a public fixed key). The justification behind making these strong assumptions has been that otherwise it is not possible to achieve fast garbling and thus fast secure computation. In this paper, we take a step back and examine whether it is really the case that such strong assumptions are needed. We provide new methods for garbling that are secure solely under the assumption that the primitive used (e.g., AES) is a pseudorandom function. Our results show that in many cases, the penalty incurred is not significant, and so a more conservative approach to the assumptions being used can be adopted. Shay Gueron, Yehuda Lindell, Ariel Nof, Benny Pinkas |
CCS | 4 |
| 2015 | Secure Deduplication of Encrypted Data without Additional Independent ServersabstractEncrypting data on client-side before uploading it to a cloud storage is essential for protecting users' privacy. However client-side encryption is at odds with the standard practice of deduplication. Reconciling client-side encryption with cross-user deduplication is an active research topic. We present the first secure cross-user deduplication scheme that supports client-side encryption without requiring any additional independent servers. Interestingly, the scheme is based on using a PAKE (password authenticated key exchange) protocol. We demonstrate that our scheme provides better security guarantees than previous efforts. We show both the effectiveness and the efficiency of our scheme, via simulations using realistic datasets and an implementation. Jian Liu 0012, N. Asokan, Benny Pinkas |
CCS | 3 |
| 2015 | Efficient Constant Round Multi-party Computation Combining BMR and SPDZ
Yehuda Lindell, Benny Pinkas, Nigel P. Smart, Avishay Yanai |
CRYPTO (2) | 2 |
| 2015 | Phasing: Private Set Intersection Using Permutation-based Hashing
Benny Pinkas, Thomas Schneider 0003, Gil Segev 0001, Michael Zohner |
USENIX Security Symposium | 1 |
| 2015 | An Efficient Protocol for Secure Two-Party Computation in the Presence of Malicious Adversaries
Yehuda Lindell, Benny Pinkas |
J. Cryptol. | 2 |
| 2014 | Non-Interactive Secure Computation Based on Cut-and-Choose
Arash Afshar, Payman Mohassel, Benny Pinkas, Ben Riva |
EUROCRYPT | 3 |
| 2014 | Faster Private Set Intersection Based on OT Extension
Benny Pinkas, Thomas Schneider 0003, Michael Zohner |
USENIX Security Symposium | 1 |
| 2012 | Firm Grip Handshakes: A Tool for Bidirectional Vouching
Omer Berkman, Benny Pinkas, Moti Yung |
CANS | 2 |
| 2012 | Secure Two-Party Computation via Cut-and-Choose Oblivious Transfer
Yehuda Lindell, Benny Pinkas |
J. Cryptol. | 2 |
| 2011 | Proofs of ownership in remote storage systemsabstractCloud storage systems are becoming increasingly popular. A promising technology that keeps their cost down is deduplication, which stores only a single copy of repeating data. Client-side deduplication attempts to identify deduplication opportunities already at the client and save the bandwidth of uploading copies of existing files to the server. In this work we identify attacks that exploit client-side deduplication, allowing an attacker to gain access to arbitrary-size files of other users based on a very small hash signatures of these files. More specifically, an attacker who knows the hash signature of a file can convince the storage service that it owns that file, hence the server lets the attacker download the entire file. (In parallel to our work, a subset of these attacks were recently introduced in the wild with respect to the Dropbox file synchronization service.) To overcome such attacks, we introduce the notion of proofs-of-ownership (PoWs), which lets a client efficiently prove to a server that that the client holds a file, rather than just some short information about it. We formalize the concept of proof-of-ownership, under rigorous security definitions, and rigorous efficiency requirements of Petabyte scale storage systems. We then present solutions based on Merkle trees and specific encodings, and analyze their security. We implemented one variant of the scheme. Our performance measurements indicate that the scheme incurs only a small overhead compared to naive client-side deduplication. Shai Halevi, Danny Harnik, Benny Pinkas, Alexandra Shulman-Peleg |
CCS | 3 |
| 2011 | Secure Computation on the Web: Computing without Simultaneous Interaction
Shai Halevi, Yehuda Lindell, Benny Pinkas |
CRYPTO | 3 |
| 2011 | The IPS Compiler: Optimizations, Variants and Concrete Efficiency
Yehuda Lindell, Eli Oxman, Benny Pinkas |
CRYPTO | 3 |
| 2011 | Secure Set Intersection with Untrusted Hardware Tokens
Marc Fischlin, Benny Pinkas, Ahmad-Reza Sadeghi, Thomas Schneider 0003, Ivan Visconti |
CT-RSA | 2 |
| 2011 | Secure Two-Party Computation via Cut-and-Choose Oblivious Transfer
Yehuda Lindell, Benny Pinkas |
TCC | 2 |
| 2010 | Privacy-Preserving Group Discovery with Linear Complexity
Mark Manulis, Benny Pinkas, Bertram Poettering |
ACNS | 2 |
| 2010 | Oblivious RAM Revisited
Benny Pinkas, Tzachy Reinman |
CRYPTO | 1 |
| 2010 | SCiFI - A System for Secure Face IdentificationabstractWe introduce SCiFI, a system for Secure Computation of Face Identification. The system performs face identification which compares faces of subjects with a database of registered faces. The identification is done in a secure way which protects both the privacy of the subjects and the confidentiality of the database. A specific application of SCiFI is reducing the privacy impact of camera based surveillance. In that scenario, SCiFI would be used in a setting which contains a server which has a set of faces of suspects, and client machines which might be cameras acquiring images in public places. The system runs a secure computation of a face recognition algorithm, which identifies if an image acquired by a client matches one of the suspects, but otherwise reveals no information to neither of the parties. Our work includes multiple contributions in different areas: 1. A new face identification algorithm which is unique in having been specifically designed for usage in secure computation. Nonetheless, the algorithm has face recognition performance comparable to that of state of the art algorithms. We ran experiments which show the algorithm to be robust to different viewing conditions, such as illumination, occlusions, and changes in appearance (like wearing glasses). 2. A secure protocol for computing the new face recognition algorithm. In addition, since our goal is to run an actual system, considerable effort was made to optimize the protocol and minimize its online latency. 3. A system - SCiFI, which implements a secure computation of the face identification protocol. 4. Experiments which show that the entire system can run in near real-time: The secure computation protocol performs a preprocessing of all public-key cryptographic operations. Its online performance therefore mainly depends on the speed of data communication, and our experiments show it to be extremely efficient. Margarita Osadchy, Benny Pinkas, Ayman Jarrous, Boaz Moskovich |
IEEE Symposium on Security and Privacy | 2 |
| 2010 | Secure Computation of the Median (and Other Elements of Specified Ranks)
Gagan Aggarwal, Nina Mishra, Benny Pinkas |
J. Cryptol. | 3 |
| 2010 | Peer-to-peer secure multi-party numerical computation facing malicious adversaries
Danny Bickson, Tzachy Reinman, Danny Dolev, Benny Pinkas |
Peer-to-Peer Netw. Appl. | 4 |
| 2009 | Secure Hamming Distance Based Computation and Its Applications
Ayman Jarrous, Benny Pinkas |
ACNS | 2 |
| 2009 | Secure Two-Party Computation Is Practical
Benny Pinkas, Thomas Schneider 0003, Nigel P. Smart, Stephen C. Williams |
ASIACRYPT | 1 |
| 2009 | A Proof of Security of Yao's Protocol for Two-Party Computation
Yehuda Lindell, Benny Pinkas |
J. Cryptol. | 2 |
| 2009 | Cryptographic and Physical Zero-Knowledge Proof Systems for Solutions of Sudoku Puzzles
Ronen Gradwohl, Moni Naor, Benny Pinkas, Guy N. Rothblum |
Theory Comput. Syst. | 3 |
| 2009 | Cryptanalysis of the random number generator of the Windows operating systemabstractThe PseudoRandom Number Generator (PRNG) used by the Windows operating system is the most commonly used PRNG. The pseudorandomness of the output of this generator is crucial for the security of almost any application running in Windows. Nevertheless, its exact algorithm was never published. We examined the binary code of a distribution of Windows 2000. This investigation was done without any help from Microsoft. We reconstructed the algorithm used by the pseudorandom number generator (namely, the function CryptGenRandom). We analyzed the security of the algorithm and found a nontrivial attack: Given the internal state of the generator, the previous state can be computed in 2 23 steps. This attack on forward security demonstrates that the design of the generator is flawed, since it is well known how to prevent such attacks. After our analysis was published, Microsoft acknowledged that Windows XP is vulnerable to the same attack. We also analyzed the way in which the generator is used by the operating system and found that it amplifies the effect of the attack: The generator is run in user mode rather than in kernel mode; therefore, it is easy to access its state even without administrator privileges. The initial values of part of the state of the generator are not set explicitly, but rather are defined by whatever values are present on the stack when the generator is called. Furthermore, each process runs a different copy of the generator, and the state of the generator is refreshed with system-generated entropy only after generating 128KB of output for the process running it. The result of combining this observation with our attack is that learning a single state may reveal 128KB of the past and future output of the generator. The implication of these findings is that a buffer overflow attack or a similar attack can be used to learn a single state of the generator, which can then be used to predict all random values, such as SSL keys, used by a process in all its past and future operations. This attack is more severe and more efficient than known attacks in which an attacker can only learn SSL keys if it is controlling the attacked machine at the time the keys are used. Leo Dorrendorf, Zvi Gutterman, Benny Pinkas |
ACM Trans. Inf. Syst. Secur. | 3 |
| 2008 | FairplayMP: a system for secure multi-party computationabstractWe present FairplayMP (for "Fairplay Multi-Party"), a system for secure multi-party computation. Secure computation is one of the great achievements of modern cryptography, enabling a set of untrusting parties to compute any function of their private inputs while revealing nothing but the result of the function. In a sense, FairplayMP lets the parties run a joint computation that emulates a trusted party which receives the inputs from the parties, computes the function, and privately informs the parties of their outputs. FairplayMP operates by receiving a high-level language description of a function and a configuration file describing the participating parties. The system compiles the function into a description as a Boolean circuit, and perform a distributed evaluation of the circuit while revealing nothing else. FairplayMP supplements the Fairplay system [16], which supported secure computation between two parties. The underlying protocol of FairplayMP is the Beaver-Micali-Rogaway (BMR) protocol which runs in a constant number of communication rounds (eight rounds in our implementation). We modified the BMR protocol in a novel way and considerably improved its performance by using the Ben-Or-Goldwasser-Wigderson (BGW) protocol for the purpose of constructing gate tables. We chose to use this protocol since we believe that the number of communication rounds is a major factor on the overall performance of the protocol. We conducted different experiments which measure the effect of different parameters on the performance of the system and demonstrate its scalability. (We can now tell, for example, that running a second-price auction between four bidders, using five computation players, takes about 8 seconds.) Assaf Ben-David, Noam Nisan, Benny Pinkas |
CCS | 3 |
| 2008 | Peer-to-Peer Secure Multi-party Numerical ComputationabstractWe propose an efficient framework for enabling secure multi-party numerical computations in a Peer-to-Peer network. This problem arises in a range of applications such as collaborative filtering, distributed computation of trust and reputation, monitoring and numerous other tasks, where the computing nodes would like to preserve the privacy of their inputs while performing a joint computation of a certain function. Although there is a rich literature in the field of distributed systems security concerning secure multi-party computation, in practice it is hard to deploy those methods in very large scalePeer-to-Peer networks. In this work, we examine several possible approaches and discuss their feasibility. Among the possible approaches, we identify a single approach which is both scalable and theoretically secure. An additional novel contribution is that we show how to compute the neighborhood based collaborative filtering, a state-of-the-art collaborative filtering algorithm, winner of the Netflix progress prize of the year 2007. Our solution computes this algorithm in a Peer-to-Peer network, using a privacy preserving computation, without loss of accuracy. Using extensive large scale simulations on top of real Internet topologies, we demonstrate the applicability of our approach. Asfar as we know, we are the first to implement such a large scale secure multi-party simulation of networks of millions of nodes and hundreds of millions of edges. Danny Bickson, Danny Dolev, Genia Bezman, Benny Pinkas |
Peer-to-Peer Computing | 4 |
| 2007 | Cryptanalysis of the windows random number generatorabstractThe pseudo-random number generator (PRNG) used by the Windows operating system is the most commonly used PRNG. The pseudo-randomness of the output of this generator is crucial for the security of almost any application running in Windows. Nevertheless, its exact algorithm was never published. We examined the binary code of a distribution of Windows 2000, which is still the second most popular operating system after Windows XP. (This investigation was done without any help from Microsoft.) We reconstructed, for the first time, the algorithm used by the pseudo-random number generator (namely, the function CryptGenRandom). We analyzed the security of the algorithm and found a non-trivial attack: given the internal state of the generator, the previous Leo Dorrendorf, Zvi Gutterman, Benny Pinkas |
CCS | 3 |
| 2007 | An Efficient Protocol for Secure Two-Party Computation in the Presence of Malicious Adversaries
Yehuda Lindell, Benny Pinkas |
EUROCRYPT | 2 |
| 2006 | Analysis of the Linux Random Number GeneratorabstractLinux is the most popular open source project. The Linux random number generator is part of the kernel of all Linux distributions and is based on generating randomness from entropy of operating system events. The output of this generator is used for almost every security protocol, including TLS/SSL key generation, choosing TCP sequence numbers, and file system and email encryption. Although the generator is part of an open source project, its source code (about 2500 lines of code) is poorly documented, and patched with hundreds of code patches. We used dynamic and static reverse engineering to learn the operation of this generator. This paper presents a description of the underlying algorithms and exposes several security vulnerabilities. In particular, we show an attack on the forward security of the generator which enables an adversary who exposes the state of the generator to compute previous states and outputs. In addition we present a few cryptographic flaws in the design of the generator, as well as measurements of the actual entropy collected by it, and a critical analysis of the use of the generator in Linux distributions on diskless devices. Zvi Gutterman, Benny Pinkas, Tzachy Reinman |
S&P | 2 |
| 2006 | Oblivious Polynomial EvaluationabstractOblivious polynomial evaluation is a protocol involving two parties, a sender whose input is a polynomial P, and a receiver whose input is a value $\alpha$. At the end of the protocol the receiver learns $P(\alpha)$ and the sender learns nothing. We describe efficient constructions for this protocol, which are based on new intractability assumptions that are closely related to noisy polynomial reconstruction. Oblivious polynomial evaluation can be used as a primitive in many applications. We describe several such applications, including protocols for private comparison of data, for mutually authenticated key exchange based on (possibly weak) passwords, and for anonymous coupons. Moni Naor, Benny Pinkas |
SIAM J. Comput. | 2 |
| 2005 | Keyword Search and Oblivious Pseudorandom Functions
Michael J. Freedman, Yuval Ishai, Benny Pinkas, Omer Reingold |
TCC | 3 |
| 2005 | Computationally Secure Oblivious Transfer
Moni Naor, Benny Pinkas |
J. Cryptol. | 2 |
| 2004 | Secure Computation of the k th-Ranked Element
Gagan Aggarwal, Nina Mishra, Benny Pinkas |
EUROCRYPT | 3 |
| 2004 | Efficient Private Matching and Set Intersection
Michael J. Freedman, Kobbi Nissim, Benny Pinkas |
EUROCRYPT | 3 |
| 2004 | Fairplay - Secure Two-Party Computation System
Dahlia Malkhi, Noam Nisan, Benny Pinkas, Yaron Sella |
USENIX Security Symposium | 3 |
| 2004 | Efficient State Updates for Key ManagementabstractEncryption is widely used to enforce usage rules for digital content. In many scenarios content is encrypted using a group key which is known to a group of users that are allowed to use the content. When users leave or join the group, the group key must be changed. The logical key hierarchy (LKH) algorithm is a very common method of managing these key changes. In this algorithm every user keeps a personal key composed of log n keys (for a group of n users). A key update message consists of O(log n) keys. A major drawback of the LKH algorithm is that users must update their state whenever users join or leave the group. When such an event happens, a key update message is sent to all users. A user who is offline during t key updates, and who needs to learn the keys sent in these updates as well as update its personal key, should receive and process the t key update messages, of total length O(t log n) keys. In this paper, we show how to reduce this overhead to a message of O(log t) keys. We also note that one of the methods that are used in this work to reduce the size of the update message can be used in other scenarios as well. It enables one to generate n pseudorandom keys of length k bits each, such that any successive set of t keys can be represented by a string log(t)/spl middot/k bits, without disclosing any information about the other keys. Benny Pinkas |
Proc. IEEE | 1 |
| 2003 | Fair Secure Two-Party Computation
Benny Pinkas |
EUROCRYPT | 1 |
| 2003 | The Design and Implementation of Protocol-Based Hidden Key Recovery
Eu-Jin Goh, Dan Boneh, Benny Pinkas, Philippe Golle |
ISC | 3 |
| 2002 | Securing passwords against dictionary attacksabstractThe use of passwords is a major point of vulnerability in computer security, as passwords are often easy to guess by automated programs running dictionary attacks. Passwords remain the most widely used authentication method despite their well-known security weaknesses. User authentication is clearly a practical problem. From the perspective of a service provider this problem needs to be solved within real-world constraints such as the available hardware and software infrastructures. From a user's perspective user-friendliness is a key requirement.In this paper we suggest a novel authentication scheme that preserves the advantages of conventional password authentication, while simultaneously raising the costs of online dictionary attacks by orders of magnitude. The proposed scheme is easy to implement and overcomes some of the difficulties of previously suggested methods of improving the security of user authentication schemes.Our key idea is to efficiently combine traditional password authentication with a challenge that is very easy to answer by human users, but is (almost) infeasible for automated programs attempting to run dictionary attacks. This is done without affecting the usability of the system. The proposed scheme also provides better protection against denial of service attacks against user accounts. Benny Pinkas, Tomas Sander |
CCS | 1 |
| 2002 | Privacy Preserving Data Mining
Yehuda Lindell, Benny Pinkas |
J. Cryptol. | 2 |
| 2001 | Securely combining public-key cryptosystemsabstractIt is a maxim of sound computer-security practice that a cryptographic key should have only a single use. For example, an RSA key pair should be used only for public-key encryption or only for digital signatures, and not for both.In this paper we show that in many cases, the simultaneous use of related keys for two cryptosystems, e.g. for a public-key encryption system and for a public-key signature system, does not compromise their security. We demonstrate this for a variety of public-key encryption schemes that are secure against chosen-ciphertext attacks, and for a variety of digital signature schemes that are secure against forgery under chosen-message attacks. The precise form of the statement of security that we are able to prove depends on the particular cryptographic schemes in question and on the cryptographic assumptions needed for their proofs of security; but in every case, our proof of security does not require any additional cryptographic assumptions.Among the cryptosystems that we analyze in this manner are the public-key encryption schemes of Cramer and Shoup, Naor and Yung, and Dolev, Dwork, and Naor, which are all defined in them standard model, while in the random-oracle model we analyze plaintext-aware encryption schemes (as defined by Bellare and Rogaway) and in particular the OAEP+ cryptosystem. Among public-key signature schemes, we analyze those of Cramer and Shoup and of Gennaro, Halevi, and Rabin in the standard model, while in the random-oracle model we analyze the RSA PSS scheme as well as variants of the El Gamal and Schnorr schemes. (See references within.) Stuart Haber, Benny Pinkas |
CCS | 2 |
| 2001 | Escrow services and incentives in peer-to-peer networksabstractDistribution of content, such as music, remains one of the main drivers of P2P development. Subscription-based services are currently receiving a lot of attention from the content industry as a viable business model for P2P content distribution. One of the main problems that such services face is that users may choose to redistribute content outside the community of subscribers, thereby facilitating large-scale piracy. Digital Rights Management (DRM) systems typically employ tamper resistance techniques to control this risk. We propose a system architecture that uses economic incentives instead of tamper resistance to motivate users to keep the content within the subscription community. The key technical contribution we make is to integrate a P2P file sharing service with an escrow service that reliably "pays" the party that is serving up the content. The payment itself can be realized in a number of ways, using "actual" money or bonus points such as frequent flyer miles.Moreover, our architecture facilitates trust between two unacquainted parties by offloading risk to a trusted third party, which can acquire a revenue stream by assuming this risk. To implement the escrow service securely we use cryptographic techniques, such as encryption, hashing, and error correcting codes. Our system motivates users to serve up content of high quality and verifies that users only share legitimate content and not spam, viruses or content that is not part of the subscription. We thereby address other important security concerns in P2P systems and problems like the free-rider phenomenon. Bill G. Horne, Benny Pinkas, Tomas Sander |
EC | 2 |
| 2001 | Efficient oblivious transfer protocols
Moni Naor, Benny Pinkas |
SODA | 2 |
| 2000 | Distributed Oblivious Transfer
Moni Naor, Benny Pinkas |
ASIACRYPT | 2 |
| 2000 | Privacy Preserving Data Mining
Yehuda Lindell, Benny Pinkas |
CRYPTO | 2 |
| 2000 | Tracing traitorsabstractWe give cryptographic schemes that help trace the source of leaks when sensitive or proprietary data is made available to a large set of parties. A very relevant application is in the context of pay television, where only paying customers should be able to view certain programs. In this application, the programs are normally encrypted, and then the sensitive data is the decryption keys that are given to paying customers. If a pirate decoder is found, it is desirable to reveal the source of its decryption keys. We describe fully resilient schemes which can be used against any decoder which decrypts with nonnegligible probability. Since there is typically little demand for decoders which decrypt only a small fraction of the transmissions (even if it is nonnegligible), we further introduce threshold tracing schemes which can only be used against decoders which succeed in decryption with probability greater than some threshold. Threshold schemes are considerably more efficient than fully resilient schemes. Benny Chor, Amos Fiat, Moni Naor, Benny Pinkas |
IEEE Trans. Inf. Theory | 4 |
| 1999 | Oblivious Transfer with Adaptive Queries
Moni Naor, Benny Pinkas |
CRYPTO | 2 |
| 1999 | Distributed Pseudo-random Functions and KDCs
Moni Naor, Benny Pinkas, Omer Reingold |
EUROCRYPT | 2 |
| 1999 | Multicast Security: A Taxonomy and Some Efficient ConstructionsabstractMulticast communication is becoming the basis for a growing number of applications. It is therefore critical to provide sound security mechanisms for multicast communication. Yet, existing security protocols for multicast offer only partial solutions. We first present a taxonomy of multicast scenarios on the Internet and point out relevant security concerns. Next we address two major security problems of multicast communication: source authentication, and key revocation. Maintaining authenticity in multicast protocols is a much more complex problem than for unicast; in particular, known solutions are prohibitively inefficient in many cases. We present a solution that is reasonable for a range of scenarios. This approach can be regarded as a 'midpoint' between traditional message authentication codes and digital signatures. We also present an improved solution to the key revocation problem. Ran Canetti, Juan A. Garay 0001, Gene Itkis, Daniele Micciancio, Moni Naor, Benny Pinkas |
INFOCOM | 6 |
| 1999 | Privacy preserving auctions and mechanism designabstractWe suggest an architecture for executing protocols for auctions and, more generally, mechanism design. Our goal is to preserve the privacy of the inputs of the participants (so that no nonessential information about them is divulged, even a posteriori) while maintaining communication and computational efficiency. We achieve this goal by adding another party - the auction issuer - that generates the programs for computing the auctions but does not take an active part in the protocol. The auction issuer is not a trusted party, but is assumed not to collude with the auctioneer. In the case of auctions, barring collusion between the auctioneer and the auction issuer, neither party gains any information about the bids, even after the auction is over. Moreover, bidders can verify that the auction was performed correctly. The protocols do not require any communication between the bidders and the auction issuer and the computational efficiency is very reasonable. This architecture can be used to implement any mechanism design where the important factor is the complexity of the decision procedure. Moni Naor, Benny Pinkas, Reuban Sumner |
EC | 2 |
| 1999 | Oblivious Transfer and Polynomial EvaluationabstractWe describe efficient constructions for two oblivious twoparty computation problems: l-out-of-N Oblivious Transfer &d 'Oblivious Poly&nial Evaluation.The oblivious polynomial evaluation protocol is based on a new intractability assumption which is closely related to noisy polynomial re construction.A direct corollary of the l-out-of-N OT protccol is an efficient transformation of any Private Information Retrieval (PIR) protocol to a Symmetric PIR (SPIR) prc-tow1 without increasing the number of databases.The new construction for l-out-of-N OT is highly efficient -it requires only log N executions of a l-out-of-2 OT protocol.We also present a construction for k-out-of-N OT which is more efficient than k repetitions of l-out-of-N OT.The efficiency of the new OT protocols makes them useful for a variety of applications.These include oblivious sampling which can be used to securely compare the sizes of web search engines, protocols for privately solving the list intersection problem and for mutually authenticated key exchange based on (possibly weak) passwords, and protocols for anonymity preserving web usage metering. Moni Naor, Benny Pinkas |
STOC | 2 |
| 1999 | On the Security of Pay-per-Click and Other Web Advertising Schemes
Vinod Anupam, Alain J. Mayer, Kobbi Nissim, Benny Pinkas, Michael K. Reiter |
Comput. Networks | 4 |
| 1998 | Threshold Traitor Tracing
Moni Naor, Benny Pinkas |
CRYPTO | 2 |
| 1998 | Secure and Efficient Metering
Moni Naor, Benny Pinkas |
EUROCRYPT | 2 |
| 1998 | Secure Accounting and Auditing on the Web
Moni Naor, Benny Pinkas |
Comput. Networks | 2 |
| 1997 | Visual Authentication and Identification
Moni Naor, Benny Pinkas |
CRYPTO | 2 |
| 1990 | On the Impossibility of Private Key Cryptography with Weakly Random Keys
James L. McInnes, Benny Pinkas |
CRYPTO | 2 |