EDBT 2026 Demo / reviewers in the wild / expert
Jorge Guajardo
dblp:51/3023 · also Jorge Guajardo Merchan
· DBLP profile ↗
33ranked-venue papers
8as first author
6since 2021 · last 2025
0000-0002-2478-7691ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 28 · 6 first-author · 5 since 2021Systems, architecture and hardware · 3 · 2 first-authorSoftware engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Client-Efficient Online-Offline Private Information RetrievalabstractPrivate Information Retrieval (PIR) permits clients to query data entries from a public database hosted on untrusted servers while preserving client privacy. Traditional PIR models suffer from high computation and/or bandwidth overhead due to linear database processing. Recently, Online-Offline PIR (OO-PIR) has been proposed to improve PIR practicality by precomputing query-independent materials to accelerate online access. While state-of-the-art OO-PIR schemes (e.g., S&P’24, CRYPTO’23) successfully reduce online processing cost to sublinear levels, they still impose substantial bandwidth and storage burdens on the client, especially when operating on large databases. In this paper, we propose Pirex, a new two-server OO-PIR scheme with semi-honest security that offers minimal client-side inbound bandwidth and storage costs while retaining sublinear processing efficiency. The Pirex design is simple, with most operations being naturally low-cost and streamlined (e.g., XOR, PRF, modular arithmetic). We have fully implemented Pirex and evaluated its real-world performance using commodity hardware. Our results show that Pirex outperforms existing OO-PIR schemes by at least two orders of magnitude. With a 1 TB database, Pirex takes only 55 ms to retrieve a 4 KB entry, compared to 9–30 seconds for state-of-the-art approaches. For practical databases with billions of 4 KB entries, Pirex requires just 16 KB of inbound bandwidth—up to three orders of magnitude more efficient. Hoang-Dung Nguyen, Jorge Guajardo, Thang Hoang |
Proc. Priv. Enhancing Technol. | 2 |
| 2024 | Privacy-Preserving Verifiable Neural Network Inference ServiceabstractMachine learning has revolutionized data analysis and pattern recognition, but its resource-intensive training has limited accessibility. Machine Learning as a Service (MLaaS) simplifies this by enabling users to delegate their data samples to an MLaaS provider and obtain the inference result using a pre-trained model. Despite its convenience, leveraging MLaaS poses significant privacy and reliability concerns to the client. Specifically, sensitive information from the client inquiry data can be leaked to an adversarial MLaaS provider. Meanwhile, the lack of a verifiability guarantee can potentially result in biased inference results or even unfair payment issues. While existing trustworthy machine learning techniques, such as those relying on verifiable computation or secure computation, offer solutions to privacy and reliability concerns, they fall short of simultaneously protecting the privacy of client data and providing provable inference verifiabilityIn this paper, we propose vPIN, a privacy-preserving and verifiable CNN inference scheme that preserves privacy for client data samples while ensuring verifiability for the inference. vPIN makes use of partial homomorphic encryption and commit-and-prove succinct non-interactive argument of knowledge techniques to achieve desirable security properties. In vPIN, we develop various optimization techniques to minimize the proving circuit for homomorphic inference evaluation thereby, improving the efficiency and performance of our technique. We fully implemented and evaluated our vPIN scheme on standard datasets (e.g., MNIST, CIFAR-10). Our experimental results show that vPIN achieves high efficiency in terms of proving time, verification time, and proof size, while providing client data privacy guarantees and provable verifiability. Arman Riasi, Jorge Guajardo, Thang Hoang |
ACSAC | 2 |
| 2024 | MUSES: Efficient Multi-User Searchable Encrypted Database
Tung Le 0005, Rouzbeh Behnia, Jorge Guajardo, Thang Hoang |
USENIX Security Symposium | 3 |
| 2022 | Titanium: A Metadata-Hiding File-Sharing System with Malicious Security
Weikeng Chen, Thang Hoang, Jorge Guajardo, Attila A. Yavuz |
NDSS | 3 |
| 2021 | CANNON: Reliable and Stealthy Remote Shutdown Attacks via Unaltered Automotive MicrocontrollersabstractElectronic Control Units (ECUs) in modern vehicles have recently been targets for shutdown attacks, which can disable safety-critical vehicle functions and be used as means to launch more dangerous attacks. Existing attacks operate either by physical manipulation of the bus signals or message injection. However, we argue that these cannot simultaneously be remote, stealthy, and reliable. For instance, message injection is detected by modern Intrusion Detection System (IDS) proposals and requires strict synchronization that cannot be realized remotely. In this work, we introduce a new class of attacks that leverage the peripheral clock gating feature in modern automotive microcontroller units (MCUs). By using this capability, a remote adversary with purely software control can reliably "freeze" the output of a compromised ECU to insert arbitrary bits at any time instance. Utilizing on this insight, we develop the CANnon attack for remote shutdown. Since the CANnon attack produces error patterns indistinguishable from natural errors and does not require message insertion, detecting it with current techniques is difficult. We demonstrate this attack on two automotive MCUs used in modern passenger vehicle ECUs. We discuss potential mitigation strategies and countermeasures for such attacks. Sekar Kulandaivel, Shalabh Jain, Jorge Guajardo, Vyas Sekar |
SP | 3 |
| 2021 | A Secure Searchable Encryption Framework for Privacy-Critical Cloud Storage ServicesabstractSearchable encryption has received a significant attention from the research community with various constructions being proposed, each achieving asymptotically optimal complexity for specific metrics (e.g., search, update). Despite their elegance, the recent attacks and deployment efforts have shown that the optimal asymptotic complexity might not always imply practical performance, especially if the application demands a high privacy. In this article, we introduce a novel Dynamic Searchable Symmetric Encryption (DSSE) framework called Incidence Matrix (IM)-DSSE, which achieves a high level of privacy, efficient search/update, and low client storage with actual deployments on real cloud settings. We harness an incidence matrix along with two hash tables to create an encrypted index, on which both search and update operations can be performed effectively with minimal information leakage. This simple set of data structures surprisingly offers a high level of DSSE security while achieving practical performance. Specifically, IM-DSSE achieves forward-privacy, backward-privacy and size-obliviousness simultaneously. We also create several DSSE variants, each offering different trade-offs that are suitable for different cloud applications and infrastructures. We fully implemented our framework and evaluated its performance on a real cloud system (Amazon EC2). We have released IM-DSSE as an open-source library for wide development and adaptation. Thang Hoang, Attila A. Yavuz, Jorge Guajardo |
IEEE Trans. Serv. Comput. | 3 |
| 2020 | MACAO: A Maliciously-Secure and Client-Efficient Active ORAM Framework
Thang Hoang, Jorge Guajardo, Attila A. Yavuz |
NDSS | 2 |
| 2020 | A Multi-server ORAM Framework with Constant Client Bandwidth BlowupabstractOblivious Random Access Machine (ORAM) allows a client to hide the access pattern when accessing sensitive data on a remote server. It is known that there exists a logarithmic communication lower bound on any passive ORAM construction, where the server only acts as the storage service. This overhead, however, was shown costly for some applications. Several active ORAM schemes with server computation have been proposed to overcome this limitation. However, they mostly rely on costly homomorphic encryptions, whose performance is worse than passive ORAM. In this article, we propose S 3 ORAM, a new multi-server ORAM framework, which features O (1) client bandwidth blowup and low client storage without relying on costly cryptographic primitives. Our key idea is to harness Shamir Secret Sharing and a multi-party multiplication protocol on applicable binary tree-ORAM paradigms. This strategy allows the client to instruct the server(s) to perform secure and efficient computation on his/her behalf with a low intervention thereby, achieving a constant client bandwidth blowup and low server computational overhead. Our framework can also work atop a general k -ary tree ORAM structure ( k ≥ 2). We fully implemented our framework, and strictly evaluated its performance on a commodity cloud platform (Amazon EC2). Our comprehensive experiments confirmed the efficiency of S 3 ORAM framework, where it is approximately 10× faster than the most efficient passive ORAM (i.e., Path-ORAM) for a moderate network bandwidth while being three orders of magnitude faster than active ORAM with O (1) bandwidth blowup (i.e., Onion-ORAM). We have open-sourced the implementation of our framework for public testing and adaptation. Thang Hoang, Attila A. Yavuz, Jorge Guajardo |
ACM Trans. Priv. Secur. | 3 |
| 2019 | A multi-server oblivious dynamic searchable encryption frameworkabstractData privacy is one of the main concerns for data outsourcing on the cloud. Although standard encryption can provide confidentiality, it prevents the client from searching/retrieving meaningful information on the outsourced data thereby, degrading the benefits of using cloud services. To address this data utilization versus privacy dilemma, Dynamic Searchable Symmetric Encryption (DSSE) has been proposed. DSSE enables encrypted search and update functionality over the encrypted data via a secure index. However, the state-of-the-art DSSE constructions leak information from the access pattern, making them vulnerable against various attacks. While generic Oblivious Random Access Machine (ORAM) can hide the access pattern, it incurs a heavy communication overhead, which was shown costly to be directly used in the DSSE setting. In this article, by exploiting the multi-cloud infrastructure, we develop a comprehensive Oblivious Distributed DSSE (ODSE) framework that allows oblivious search and updates on the encrypted index with high security and improved efficiency over the use of generic ORAM. Our framework contains a series of [Formula: see text] schemes each featuring different levels of performance and security required by various types of real-life applications. ODSE offers desirable security guarantees such as information-theoretic security and robustness in the presence of a malicious adversary. We fully implemented [Formula: see text] framework and evaluated its performance in a real cloud environment (Amazon EC2). Our experiments showed that ODSE schemes are [Formula: see text]-[Formula: see text] faster than using generic ORAMs on a DSSE encrypted index under real network settings. Thang Hoang, Attila A. Yavuz, F. Betül Durak, Jorge Guajardo |
J. Comput. Secur. | 4 |
| 2018 | ASHES 2018- Workshop on Attacks and Solutions in Hardware SecurityabstractAs in the successful first edition, the second Workshop on Attacks and Solutions in Hardware Security (ASHES) 2018 deals with all aspects of hardware security. Among others, this year, the workshop particularly highlights emerging techniques and methods as well as recent application areas within the field. These include new attack vectors, attack countermeasures, and novel designs and implementations on the methodological side, as well as the Internet of Things, automotive security, smart homes, pervasive and wearable computing on the applications side. In order to meet the requirements of these rapidly developing subareas, ASHES calls for paper submissions in four categories: 1) classical full papers; 2) classical short papers; 3) systematization of knowledge papers which overview, structure, and categorize a subarea; and 4) wild and crazy papers whose purpose is rapid dissemination of promising, potentially game-changing ideas. Chip-Hong Chang, Jorge Guajardo, Daniel E. Holcomb, Francesco Regazzoni 0001, Ulrich Rührmair |
CCS | 2 |
| 2018 | Oblivious Dynamic Searchable Encryption on Distributed Cloud Systems
Thang Hoang, Attila A. Yavuz, F. Betül Durak, Jorge Guajardo |
DBSec | 4 |
| 2018 | Revisiting Private Stream Aggregation: Lattice-Based PSA
Daniela Becker, Jorge Guajardo, Karl-Heinz Zimmermann |
NDSS | 2 |
| 2017 | S3ORAM: A Computation-Efficient and Constant Client Bandwidth Blowup ORAM with Shamir Secret SharingabstractOblivious Random Access Machine (ORAM) enables a client to access her data without leaking her access patterns. Existing client-efficient ORAMs either achieve O(log N) client-server communication blowup without heavy computation, or O(1) blowup but with expensive homomorphic encryptions. It has been shown that O(log N) bandwidth blowup might not be practical for certain applications, while schemes with O(1) communication blowup incur even more delay due to costly homomorphic operations. Thang Hoang, Ceyhun D. Ozkaptan, Attila A. Yavuz, Jorge Guajardo |
CCS | 4 |
| 2016 | Practical and secure dynamic searchable encryption via oblivious access on distributed data structure
Thang Hoang, Attila A. Yavuz, Jorge Guajardo |
ACSAC | 3 |
| 2016 | MEMS Gyroscopes as Physical Unclonable FunctionsabstractA key requirement for most security solutions is to provide secure cryptographic key storage in a way that will easily scale in the age of the Internet of Things. In this paper, we focus on providing such a solution based on Physical Unclonable Functions (PUFs). To this end, we focus on microelectromechanical systems (MEMS)-based gyroscopes and show via wafer-level measurements and simulations, that it is feasible to use the physical and electrical properties of these sensors for cryptographic key generation. After identifying the most promising features, we propose a novel quantization scheme to extract bit strings from the MEMS analog measurements. We provide upper and lower bounds for the minimum entropy of the derived bit strings and fully analyze the intra- and inter-class distributions across the operation range of the MEMS device. We complement these measurements via Monte-Carlo simulations based on the distributions of the parameters measured on actual devices. We also propose and evaluate a complete cryptographic key generation chain based on fuzzy extractors. We derive a full entropy 128-bit key using the obtained min-entropy estimates, requiring 1219 bits of helper data with an (authentication) failure probability of 4 . 10-7. In addition, we propose a dedicated MEMS-PUF design, which is superior to our measured sensor, in terms of chip area, quality and quantity of key seed features. Oliver Willers, Christopher Huth, Jorge Guajardo, Helmut Seidel |
CCS | 3 |
| 2016 | Physical Layer Group Key Agreement for Automotive Controller Area Networks
Shalabh Jain, Jorge Guajardo |
CHES | 2 |
| 2015 | Fifth International Workshop on Trustworthy Embedded Devices (TrustED 2015)abstractThe Internet of Things (IoTS) is expected to seamlessly connect everything and everyone and bring about the promise of smart environments, industry 4.0, intelligent infrastructure management, environmental monitoring and disaster recovery, etc. The explosion in the number of interconnected devices makes it a challenge to guarantee their security, the security of their networks and the privacy of the data collected by them. The Workshop on Trustworthy Embedded Devices (TrustED) focuses on all aspects of security and privacy related to embedded systems and the IoTS. TrustED 2015 continues a successful series of workshops, which were held in conjunction with ESORICS 2011, IEEE Security & Privacy 2012, ACM CCS 2013 and ACM CCS 2014 (see http://www.trusted-workshop.de for details). The goal of this workshop is to bring together experts from academia and research institutes, industry, and government in the field of security and privacy in cyber physical systems. Jorge Guajardo, Stefan Katzenbeisser 0001 |
CCS | 1 |
| 2015 | Dynamic Searchable Symmetric Encryption with Minimal Leakage and Efficient Updates on Commodity Hardware
Attila A. Yavuz, Jorge Guajardo |
SAC | 2 |
| 2014 | Fourth International Workshop on Trustworthy Embedded Devices (TrustED 2014)abstractThe Internet of Things (IoTS) is expected to seamlessly connect everything and everyone and bring about the promise of smart environments, industry 4.0, intelligent infrastructure management, environmental monitoring and disaster recover, etc. In fact, ABI Research [MI-ABI2013] and Gartner [MI-Gartner2013] estimate that there will be between 20 and 30 billion devices on the IoTS by 2020. The explosion in the number of interconnected devices makes it a challenge to guarantee their security, the security of their networks and the privacy of the data collected by them. The Workshop on Trustworthy Embedded Devices (TrustED) focuses on all aspects of security and privacy related to embedded systems and the IoTS. TrustED 2014 continues a successful series of workshops, which were held in conjunction with ESORICS 2011, IEEE Security & Privacy 2012, and ACM CCS 2013 (see http://www.trusted-workshop.de for details). The goal of this workshop is to bring together experts from academia and research institutes, industry, and government in the field of security and privacy in cyber physical systems. Frederik Armknecht, Jorge Guajardo |
CCS | 2 |
| 2013 | OASIS: on achieving a sanctuary for integrity and secrecy on untrusted platformsabstractWe present OASIS, a CPU instruction set extension for externally verifiable initiation, execution, and termination of an isolated execution environment with a trusted computing base consisting solely of the CPU. OASIS leverages the hardware components available on commodity CPUs to achieve a low-cost, low-overhead design. Emmanuel Owusu, Jorge Guajardo, Jonathan M. McCune, James Newsome, Adrian Perrig, Amit Vasudevan |
CCS | 2 |
| 2010 | Anonymous Credential Schemes with Encrypted Attributes
Jorge Guajardo, Bart Mennink, Berry Schoenmakers |
CANS | 1 |
| 2010 | On Side-Channel Resistant Block Cipher Usage
Jorge Guajardo, Bart Mennink |
ISC | 1 |
| 2009 | Privacy-Preserving Face Recognition
Zekeriya Erkin, Martin Franz, Jorge Guajardo, Stefan Katzenbeisser 0001, Reginald L. Lagendijk, Tomas Toft |
Privacy Enhancing Technologies | 3 |
| 2009 | Physical Unclonable Functions and Their Applications to Vehicle System SecurityabstractIn recent years, there has been a tremendous increase in the usage of IT based systems in vehicles, with predictions that in the near future, more than 90% of innovations in the automotive sector will be centered on IT software and hardware. However, innovation also means that intellectual property (IP) is created, which is valuable to third (potentially) untrusted and malicious parties. In particular, automobiles are already suffering from security issues, such as illegal copying of software IP, counterfeiting of electronic components, illegal tampering with digital data inside the electronic control units (ECUs), etc. Recently, physical unclonable functions (PUFs) attracted significant interest for numerous applications such as protection of software and hardware IP, secure key storage and component identification, to name a few. In this paper, we describe how PUFs can be used for secure key storage, component identification, IP protection in vehicle applications, and their suitability for vehicle insurance applications. Muhammad Asim 0007, Jorge Guajardo, Sandeep S. Kumar, Pim Tuyls |
VTC Spring | 2 |
| 2008 | Efficient Helper Data Key Extractor on FPGAs
Christoph Bösch 0001, Jorge Guajardo, Ahmad-Reza Sadeghi, Jamshid Shokrollahi, Pim Tuyls |
CHES | 2 |
| 2008 | Brand and IP protection with physical unclonable functionsabstractIn this paper we provide an overview of physical unclonable functions and explain why they are a very valuable technology to protect a company's IP and hence at the same time its brand. Physical unclonable functions are unclonable physical structures that map challenges to responses. They inherit their unclonability from the (deep sub-micron) process variations during manufacturing. They can be turned into a useful tool to generate very secure secret keys in ICs and to provide keys to protect valuable IP of fabless IC companies, IP Vendors and design houses. We will present several examples and explain cryptographic algorithms and protocols to use them in IP protection applications. Jorge Guajardo, Sandeep S. Kumar, Geert Jan Schrijen, Pim Tuyls |
ISCAS | 1 |
| 2007 | FPGA Intrinsic PUFs and Their Use for IP Protection
Jorge Guajardo, Sandeep S. Kumar, Geert Jan Schrijen, Pim Tuyls |
CHES | 1 |
| 2007 | Physical Unclonable Functions, FPGAs and Public-Key Crypto for IP ProtectionabstractIn recent years, IP protection of FPGA hardware designs has become a requirement for many IP vendors. To this end solutions have been proposed based on the idea of bitstream encryption, symmetric-key primitives, and the use of Physical Unclonable Functions (PUFs). In this paper, we propose new protocols for the IP protection problem on FPGAs based on public-key (PK) cryptography, analyze the advantages and costs of such an approach, and describe a PUF intrinsic to current FPGAs based on SRAM properties. A major advantage of using PK-based protocols is that they do not require the private key stored in the FPGA to leave the device, thus increasing security. This added security comes at the cost of additional hardware resources but it does not cause significant performance degradation. Jorge Guajardo, Sandeep S. Kumar, Geert Jan Schrijen, Pim Tuyls |
FPL | 1 |
| 2004 | Security on FPGAs: State-of-the-art implementations and attacksabstractIn the last decade, it has become apparent that embedded systems are integral parts of our every day lives. The wireless nature of many embedded applications as well as their omnipresence has made the need for security and privacy preserving mechanisms particularly important. Thus, as field programmable gate arrays (FPGAs) become integral parts of embedded systems, it is imperative to consider their security as a whole. This contribution provides a state-of-the-art description of security issues on FPGAs, both from the system and implementation perspectives. We discuss the advantages of reconfigurable hardware for cryptographic applications, show potential security problems of FPGAs, and provide a list of open research problems. Moreover, we summarize both public and symmetric-key algorithm implementations on FPGAs. Thomas J. Wollinger, Jorge Guajardo, Christof Paar |
ACM Trans. Embed. Comput. Syst. | 2 |
| 2003 | Hyperelliptic Curve Cryptosystems: Closing the Performance Gap to Elliptic Curves
Jan Pelzl, Thomas J. Wollinger, Jorge Guajardo, Christof Paar |
CHES | 3 |
| 2003 | Efficient GF(pm) Arithmetic Architectures for Cryptographic Applications
Guido Bertoni, Jorge Guajardo, Sandeep S. Kumar, Gerardo Orlando, Christof Paar, Thomas J. Wollinger |
CT-RSA | 2 |
| 2002 | Itoh-Tsujii Inversion in Standard Basis and Its Application in Cryptography and Codes
Jorge Guajardo, Christof Paar |
Des. Codes Cryptogr. | 1 |
| 1997 | Efficient Algorithms for Elliptic Curve Cryptosystems
Jorge Guajardo, Christof Paar |
CRYPTO | 1 |