EDBT 2026 Demo / reviewers in the wild / expert
Roger I. Khazan
dblp:31/3275 · also Roger Khazan
· DBLP profile ↗
13ranked-venue papers
3as first author
1since 2021 · last 2021
0000-0002-6766-9169ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 3 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 2Security and privacy · 1Databases, data management, data science and information retrieval · 1Graphics, computer vision, multimedia, augmented reality and games · 1Theory of computation · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Computer architecture, parallel and distributed computing, and storage systems
3 papers |
Distributed systems · 100% | |
| Network and information security
1 paper |
Cryptographic protocols and secure computation · 77% Hardware security and side channels · 23% | |
| Software engineering, system software, and programming languages
2 papers |
Program verification · 100% |
Topics — the 9 heaviest of 11, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Cryptographic protocols and secure computation
key management |
0.2 | 1 | 2013 | SHAMROCK: self contained cryptography and key management processor · CCS 2013 |
Distributed systems
group communication |
0.1 | 2 | 2004 | Group membership: a novel approach and the first single-round algorithm · PODC 2004 A Virtually Synchronous Group Multicast Algorithm for WANs: Formal Approach · SIAM J. Comput. 2002 |
Program verification
simulation proof |
0.1 | 2 | 2002 | An inheritance-based technique for building simulation proofs incrementally · ACM Trans. Softw. Eng. Methodol. 2002 An inheritance-based technique for building simulation proofs incrementally · ICSE 2000 |
Hardware security and side channels
cryptographic hardware |
0.0 | 1 | 2013 | SHAMROCK: self contained cryptography and key management processor · CCS 2013 |
Distributed systems › group communication
group membership |
0.0 | 1 | 2004 | Group membership: a novel approach and the first single-round algorithm · PODC 2004 |
Distributed systems
fault tolerance |
0.0 | 1 | 2002 | A Virtually Synchronous Group Multicast Algorithm for WANs: Formal Approach · SIAM J. Comput. 2002 |
Distributed systems › group communication
reliable multicast |
0.0 | 1 | 2002 | A Virtually Synchronous Group Multicast Algorithm for WANs: Formal Approach · SIAM J. Comput. 2002 |
Distributed systems › group communication
virtual synchrony |
0.0 | 1 | 2002 | A Virtually Synchronous Group Multicast Algorithm for WANs: Formal Approach · SIAM J. Comput. 2002 |
Distributed systems
consensus |
0.0 | 1 | 2004 | Group membership: a novel approach and the first single-round algorithm · PODC 2004 |
Methods — techniques the papers use, named apart from their topics
streaming encryption · 0.2automata · 0.1single-round algorithm · 0.0formal techniques · 0.0formal technique · 0.0formal specification · 0.0assertion verification · 0.0
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2021 | Practical Principle of Least Privilege for Secure Embedded SystemsabstractMany embedded systems have evolved from simple bare-metal control systems to highly complex network-connected systems. These systems increasingly demand rich and feature-full operating-systems (OS) functionalities. Furthermore, the network connectedness offers attack vectors that require stronger security designs. To that end, this paper defines a prototypical RTOS API called Patina that provides services common in featurerich OSes (e.g., Linux) but absent in more trustworthy μ -kernel based systems. Examples of such services include communication channels, timers, event management, and synchronization. Two Patina implementations are presented, one on Composite and the other on seL4, each of which is designed based on the Principle of Least Privilege (PoLP) to increase system security. This paper describes how each of these μ -kernels affect the PoLP based design, as well as discusses security and performance tradeoffs in the two implementations. Results of comprehensive evaluations demonstrate that the performance of the PoLP based implementation of Patina offers comparable or superior performance to Linux, while offering heightened isolation. Samuel Jero, Juliana Furgala, Runyu Pan, Phani Kishore Gadepalli, Alexandra Clifford, Bite Ye, Roger I. Khazan, Bryan C. Ward, Gabriel Parmer, Richard Skowyra |
RTAS | 7 |
| 2018 | Leveraging Intel SGX Technology to Protect Security-Sensitive ApplicationsabstractThis paper explains the process by which Intel Software Guard Extensions (SGX) can be leveraged into an existing codebase to protect a security-sensitive application. Intel SGX provides user-level applications with hardware-enforced confidentiality and integrity protections and incurs manageable impact on performance. These protections apply to all three phases of the operational data lifecycle: at rest, in use, and in transit. SGX shrinks the trusted computing base (and therefore the attack surface) of the application to only the hardware on the CPU chip and the portion of the application's software that is executed within the protected enclave. The SDK enables SGX integration into existing C/C++ codebases while still ensuring program support for legacy and non-Intel platforms. This paper is the first published work to walk through the step-by-step process of Intel SGX integration with examples and performance results from an actual cryptographic application produced in a standard Linux development environment. Joseph Sobchuk, Sean R. O'Melia, Daniil M. Utin, Roger I. Khazan |
NCA | 4 |
| 2013 | SHAMROCK: self contained cryptography and key management processorabstractIn this poster, we describe a one-size-fits-many Intellectual Property (IP) core which integrates advanced key management technology and streaming encryption into a single component to protect data in-transit. Daniil M. Utin, Roger I. Khazan, Joshua Kramer, Michael Vai, David Whelihan |
CCS | 2 |
| 2010 | GROK: A Practical System for Securing Group CommunicationsabstractWe have designed and implemented a general-purpose cryptographic building block, called GROK, for securing communication among groups of entities in networks composed of high-latency, low-bandwidth, intermittently connected links. During the process, we solved a number of non-trivial system problems. This paper describes these problems and our solutions, and motivates and justifies these solutions from three viewpoints: usability, efficiency, and security. The solutions described in this paper have been tempered by securing a widely-used group-oriented application, group text chat. We implemented a prototype extension to a popular text chat client called Pidgin and evaluated it in a real-world scenario. Based on our experiences, these solutions are useful to designers of group-oriented systems specifically, and secure systems in general. Joseph A. Cooley, Roger I. Khazan, Benjamin Fuller 0001, Galen E. Pickard |
NCA | 2 |
| 2010 | ASE: Authenticated Statement ExchangeabstractApplications often re-transmit the same data, such as digital certificates, during repeated communication instances. Avoiding such superfluous transmissions with caching, while complicated, may be necessary in order to operate in low-bandwidth, high-latency wireless networks or in order to reduce communication load in shared, mobile networks. This paper presents a general framework and an accompanying software library, called "Authenticated Statement Exchange'' (ASE), for helping applications implement persistent caching of application-specific data. ASE supports secure caching of a number of pre-defined data types common to secure communication protocols and allows applications to define new data types to be handled by ASE. ASE is applicable to many applications. The paper describes the use of ASE in one such application, secure group chat. In a recent real-use deployment, ASE was instrumental in allowing secure group chat to operate over low-bandwidth satellite links. Benjamin Fuller 0001, Roger I. Khazan, Joseph A. Cooley, Galen E. Pickard, Daniil M. Utin |
NCA | 2 |
| 2005 | A Wide Area Network Simulation of Single-Round Group Membership AlgorithmsabstractA recent theoretical result proposed Sigma, a novel GM protocol that forms views using a single-round of message exchange. Prior GM protocols have required more rounds in the worst-case. In this paper, we investigate how well Sigma performs in practice. We simulate Sigma using WAN connectivity traces and compare its performance to two leading GM protocols, Moshe and Ensemble. Our simulations show, consistently with theoretical results, that Sigma always terminates within one round of message exchange, faster than Moshe and Ensemble. Moreover, Sigma has less message overhead and produces virtually the same quality of views. We also observe that view-oriented GM in dynamic WAN-like environments is practical only in applications where GM need not respond to every disconnect immediately when detected. These applications are able, and prefer, to delay GM response and ignore transient disconnects avoiding frequent futile view changes and associated overhead. We reference some applications in this category Roger I. Khazan, Sophia Yuditskaya |
NCA | 1 |
| 2004 | Group membership: a novel approach and the first single-round algorithmabstractWe establish a new worst-case upper bound on the Membership problem: We present a simple algorithm that is able to always achieve Agreement on Views within a single message latency after the final network events leading to stability of the group become known to the membership servers. In contrast, all of the existing membership algorithms may require two or more rounds of message exchanges. Our algorithm demonstrates that the Membership problem can be solved simpler and more efficiently than previously believed.By itself, the algorithm may produce disagreement (that is, inconsistent, transient views) prior to the "final" view. Even though this is allowed by the problem specification, such views may create overhead at the application level, and are therefore undesirable.We propose a new approach for designing group membership services in which our algorithm for reaching Agreement on Views is combined with a filter-like mechanism for reducing disagreements. This approach can use the mechanisms of existing algorithms, yielding the same multi-round performance as theirs.However, the power of this approach is in being able to use other mechanisms. These can be tailored to the specifics of the deployment environments and to the desired combinations of the speed of agreement vs. the amount of preceding disagreement. We describe one mechanism that keeps the combined performance to within a single-round, and sketch another two. Roger I. Khazan |
PODC | 1 |
| 2002 | A Virtually Synchronous Group Multicast Algorithm for WANs: Formal ApproachabstractThis paper presents a formal design for a novel group communication service targeted for wide-area networks (WANs). The service provides virtual synchrony semantics. Such semantics facilitate the design of fault tolerant distributed applications. The presented design is more suitable for WANs than previously suggested ones. In particular, it features the first algorithm to achieve virtual synchrony semantics in a single communication round. The design also employs a scalable WAN-oriented architecture: it effectively decouples the main two components of virtually synchronous group communication---group membership and reliable group multicast. The design is carried out formally and rigorously. This paper includes formal specifications of both safety and liveness properties. The algorithm is formally modeled and assertionally verified. Idit Keidar, Roger I. Khazan |
SIAM J. Comput. | 2 |
| 2002 | An inheritance-based technique for building simulation proofs incrementallyabstractThis paper presents a formal technique for incremental construction of system specifications, algorithm descriptions, and simulation proofs showing that algorithms meet their specifications.The technique for building specifications and algorithms incrementally allows a child specification or algorithm to inherit from its parent by two forms of incremental modification: (a) signature extension , where new actions are added to the parent, and (b) specialization (subtyping), where the child's behavior is a specialization (restriction) of the parent's behavior. The combination of signature extension and specialization provides a powerful and expressive incremental modification mechanism for introducing new types of behavior without overriding behavior of the parent; this mechanism corresponds to the subclassing for extension form of inheritance.In the case when incremental modifications are applied to both a parent specification S and a parent algorithm A, the technique allows a simulation proof showing that the child algorithm A′ implements the child specification S′ to be constructed incrementally by extending a simulation proof that algorithm A implements specification S. The new proof involves reasoning about the modifications only, without repeating the reasoning done in the original simulation proof.The paper presents the technique mathematically, in terms of automata. The technique has been used to model and verify a complex middleware system; the methodology and results of that experiment are summarized in this paper. Idit Keidar, Roger I. Khazan, Nancy A. Lynch, Alexander A. Schwarzmann |
ACM Trans. Softw. Eng. Methodol. | 2 |
| 2000 | A Client-Server Approach to Virtually Synchronous Group Multicast: Specifications and AlgorithmsabstractThis paper presents a formal design for a novel group multicast service that provides virtually synchronous semantics in asynchronous fault-prone environments. The design employs a client-server architecture in which group membership is maintained not by every process but only by dedicated membership servers, while virtually synchronous group multicast is implemented by service end-points running at the clients. Specifically, the paper defines service semantics for the client-server interface, that is, for the group membership service. The paper then specifies virtually synchronous semantics for the new group multicast service, as a collection of commonly used safety and liveness properties. Finally, the paper presents new algorithms that use the defined group membership service to implement the specified properties. The algorithm that provides the complete virtually synchronous semantics executes in a single message round in parallel with the membership service's agreement on views, and is therefore more efficient than previously suggested algorithms providing such semantics. Idit Keidar, Roger I. Khazan |
ICDCS | 2 |
| 2000 | An inheritance-based technique for building simulation proofs incrementallyabstractThis paper presents a technique for incrementally constructing safety specifications, abstract algorithm descriptions, and simulation proofs showing that algorithms meet their specifications. Idit Keidar, Roger I. Khazan, Nancy A. Lynch, Alexander A. Schwarzmann |
ICSE | 2 |
| 1998 | Multicast Group Communication as a Base for a Load-Balancing Replicated Data Service
Roger I. Khazan, Alan D. Fekete, Nancy A. Lynch |
DISC | 1 |
| 1996 | Parsing with Prefix and Suffix DictionariesabstractWe show that greedy left-to-right (right-to-left) parsing is optimal w.r.t. a suffix (prefix) dictionary. To exploit this observation, we show how to construct a static suffix dictionary that supports on-line, linear-time optimal parsing. From this we derive an adaptive on-line method that yields compression comparing favorably to LZW. Martin Cohn, Roger I. Khazan |
Data Compression Conference | 2 |