Ali Bagherzandi

dblp:45/314 · DBLP profile ↗
← Back
2ranked-venue papers
2as first author
0since 2021 · last 2011
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 2 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
2 papers
Cryptographic protocols and secure computation · 68% Cryptographic primitives and cryptanalysis · 32%

Topics — the 11 heaviest of 11, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Cryptographic protocols and secure computation
key exchange
0.112011
Password-protected secret sharing · CCS 2011
Cryptographic protocols and secure computation › key exchange › authenticated key exchange
password-authenticated key exchange
0.112011
Password-protected secret sharing · CCS 2011
Cryptographic protocols and secure computation › secret sharing
password-protected secret sharing
0.112011
Password-protected secret sharing · CCS 2011
Cryptographic protocols and secure computation
secret sharing
0.112011
Password-protected secret sharing · CCS 2011
Cryptographic protocols and secure computation › key exchange › authenticated key exchange › password-authenticated key exchange
threshold password-authenticated key exchange
0.112011
Password-protected secret sharing · CCS 2011
Cryptographic primitives and cryptanalysis
cryptographic assumptions
0.112008
Multisignatures secure under the discrete logarithm assumption and a generalized forking lemma · CCS 2008
Cryptographic primitives and cryptanalysis › public-key cryptography
digital signatures
0.112008
Multisignatures secure under the discrete logarithm assumption and a generalized forking lemma · CCS 2008
Cryptographic primitives and cryptanalysis › cryptographic assumptions
discrete logarithm assumption
0.112008
Multisignatures secure under the discrete logarithm assumption and a generalized forking lemma · CCS 2008
Cryptographic primitives and cryptanalysis › public-key cryptography › digital signatures
multi-signature
0.112008
Multisignatures secure under the discrete logarithm assumption and a generalized forking lemma · CCS 2008
Cryptographic protocols and secure computation › proof systems › zero-knowledge proofs
non-interactive zero-knowledge proofs
0.012011
Password-protected secret sharing · CCS 2011
Cryptographic protocols and secure computation › proof systems
zero-knowledge proofs
0.012011
Password-protected secret sharing · CCS 2011

Methods — techniques the papers use, named apart from their topics

random oracle model · 0.1decisional diffie-hellman assumption · 0.1generalized forking lemma · 0.1bilinear maps · 0.1
YearPublicationVenuePosition
2011 Password-protected secret sharing
abstract
We revisit the problem of protecting user's private data against adversarial compromise of user's device(s) which store this data. We formalize the solution we propose as Password-Protected Secret-Sharing (PPSS), which allows a user to secret-share her data among n trustees in such a way that (1) the user can retrieve the shared secret upon entering a correct password into a reconstruction protocol, which succeeds as long as at least t+1 uncorrupted trustees are accessible, and (2) the shared data remains secret even if the adversary which corrupts t trustees, with the level of protection expected of password-authentication, i.e. the probability that the adversary learns anything useful about the secret is at most q/|D| where q is the number of reconstruction protocol the adversary manages to trigger and |D| is the size of the password dictionary. We propose an efficient PPSS protocol in the PKI model, secure under the DDH assumption, using non-interactive zero-knowledge proofs with efficient instantiations in the Random Oracle Model. Our protocol is practical, with fewer than 16 exponentiations per trustee and 8t+17 exponentiations per user, with O(1) bandwidth between the user and each trustee, and only three message flows, implying a single round of interaction in the on-line phase. As a side benefit our PPSS protocol yields a new Threshold Password Authenticated Key Exchange (T-PAKE) protocol in the PKI model with significantly lower message, communication, and server computation complexities then existing T-PAKE's.
Ali Bagherzandi, Stanislaw Jarecki, Nitesh Saxena, Yanbin Lu
CCS1
2008 Multisignatures secure under the discrete logarithm assumption and a generalized forking lemma
abstract
Multisignatures allow n signers to produce a short joint signature on a single message. Multisignatures were achieved in the plain model with a non-interactive protocol in groups with bilinear maps, by Boneh et al, and by a three-round protocol under the Discrete Logarithm (DL) assumption, by Bellare and Neven, with multisignature verification cost of, respectively, O(n) pairings or exponentiations. In addition, multisignatures with O(1) verification were shown in so-called Key Verification (KV) model, where each public key is accompanied by a short proof of well-formedness, again either with a non-interactive protocol using bilinear maps, by Ristenpart and Yilek, or with a three-round protocol under the Diffie-Hellman assumption, by Bagherzandi and Jarecki.
Ali Bagherzandi, Jung Hee Cheon, Stanislaw Jarecki
CCS1