Claudio Soriente

dblp:57/1338 · DBLP profile ↗
← Back
55ranked-venue papers
3as first author
15since 2021 · last 2026
0000-0002-8215-5457ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 26 · 3 first-author · 10 since 2021Computer networks · 12 · 2 since 2021Systems, architecture and hardware · 7 · 3 since 2021Human-computer interaction and ubiquitous computing · 4Databases, data management, data science and information retrieval · 3Applied, interdisciplinary, general and emerging computing · 3Software engineering, systems software and programming languages · 2Artificial intelligence and machine learning · 1
YearPublicationVenuePosition
2026 On Securing the Software Development Lifecycle in IoT RISC-V Trusted Execution Environments
Annika Wilde, Samira Briongos, Claudio Soriente, Ghassan Karame
SenSys3
2025 Anonymous Authenticated Key Exchange
abstract
Abstract Authenticated Key Exchange ( $${\textsf {AKE}}$$ AKE ) can be used in client-server applications for mutual authentication and key establishment. In scenarios where client authentication is neither feasible nor desirable, One-Sided AKE ( $${\textsf {OS-AKE}}$$ OS - AKE ) allows both parties to establish a key while only the server authenticates to the client. Thus, $${\textsf {OS-AKE}}$$ OS - AKE provides client anonymity with respect to the server, but does not allow the server to enforce any form of access control—that is, the server simply establishes a key with any client. In this paper, we introduce Anonymous AKE ( $${\textsf {A-AKE}}$$ A - AKE ) to strike a balance between classical client authentication of $${\textsf {AKE}}$$ AKE and client anonymity of $${\textsf {OS-AKE}}$$ OS - AKE . In a nutshell $${\textsf {A-AKE}}$$ A - AKE is an $${\textsf {AKE}}$$ AKE protocol where (i) the server authenticates to the client, (ii) the server can enforce access control by deciding which clients are authorized to run the key-establishment protocol, (iii) a key is established between the server and the client only if the latter is one of the authorized clients as defined by the server, and (iv) the authorized client remains anonymous (within the set of all authorized clients) with respect to the server. We introduce a security model for $${\textsf {A-AKE}}$$ A - AKE that extends popular $${\textsf {AKE}}$$ AKE models and design a general framework for instantiating $${\textsf {A-AKE}}$$ A - AKE protocols based on well-established cryptographic primitives. Finally, we instantiate several $${\textsf {AKE}}$$ AKE protocols aiming at strong security guarantees in the classical and post-quantum settings. We implement a prototype of each instantiation and provide an experimental comparison of their performance.
José Ignacio Escribano Pablos, María Isabel González Vasco, Angel L. Pérez del Pozo, Claudio Soriente
ACNS (1)4
2025 A Lightweight Secure Aggregation Protocol for Federated Learning Applications
abstract
Federated learning (FL) enables a server and a set of users to jointly train a model without the need to disclose training data. To guarantee strong privacy for users, FL must be combined with a secure aggregation (SA) protocol ensuring that individual gradients remain confidential. Pioneering SA protocols for FL applications exhibit a per-user overhead that grows logarithmically with the number of users and require multiple rounds of communication.In this paper we present LISA, a lightweight SA protocol that leverages public randomness to reduce both per-user overhead and the number of rounds needed. LISA requires only two rounds of interaction for most users, offering a communication overhead asymptotically equivalent to that of a non-private protocol where the server obtains user inputs in the clear. More concretely, LISA uses public randomness to select a small committee of users tasked with aiding the server in the aggregation process. Users blind their individual inputs with random masks shared with each committee member, and after sending their blinded input to the server they can go offline. Committee members provide the server with an aggregation of the shared masks over all users, so that the server can remove all masks and obtain the aggregated input. Hence, as long as one committee member is honest, the server can only obtain the aggregation of threshold-many inputs without learning any individual input. We compare LISA with existing SA protocols through both theoretical analysis and simulations. We further integrate LISA in an FL pipeline and compare its accuracy and time to converge with those of a non-private FL application.
Elina van Kempen, Giorgia Azzurra Marson, Claudio Soriente
ICDCS4
2025 The Forking Way: When TEEs Meet Consensus
Annika Wilde, Tim Niklas Gruel, Claudio Soriente, Ghassan Karame
NDSS3
2024 SPATIAL: Practical AI Trustworthiness with Human Oversight
abstract
We demonstrate SPATIAL, a proof-of-concept system that augments modern applications with capabilities to analyze trustworthy properties of AI models. The practical analysis of trustworthy properties is key to guaranteeing the safety of users and overall society when interacting with AI -driven applications. SPATIAL implements AI dashboards to introduce human-in-the-loop capabilities for the construction of AI models. SPATIAL allows different stakeholders to obtain quantifiable insights that characterize the decision making process of AI. This information can then be used by the stakeholders to comprehend possible issues that influence the performance of AI models, such that the issues can be resolved by human operators. Through rigorous benchmarks and experiments in a real-world industrial application, we demonstrate that SPATIAL can easily augment modern applications with metrics to gauge and monitor trustworthiness. However, this, in turn, increases the complexity of developing and maintaining the systems implementing AI. Our work paves the way towards augmenting modern applications with trustworthy AI mechanisms and human oversight approaches.
Abdul-Rasheed Ottun, Rasinthe Marasinghe, Toluwani Elemosho, Mohan Liyanage, Ashfaq Hussain Ahmed, Michell Boerger, Chamara Sandeepa, Thulitha Senevirathna, Vinh Hoa La, Manh-Dung Nguyen, Claudio Soriente, Samuel Marchal, Shen Wang 0006, David Solans Noguero, Nikolay Tcholtchev, Aaron Yi Ding, Huber Flores
ICDCS11
2024 The SPATIAL Architecture: Design and Development Experiences from Gauging and Monitoring the AI Inference Capabilities of Modern Applications
abstract
Despite its enormous economical and societal impact, lack of human-perceived control and safety is re-defining the design and development of emerging AI-based technologies. New regulatory requirements mandate increased human control and oversight of AI, transforming the development practices and responsibilities of individuals interacting with AI. In this paper, we present the SPATIAL architecture, a system that augments modern applications with capabilities to gauge and monitor trustworthy properties of AI inference capabilities. To design SPATIAL, we first explore the evolution of modern system architectures and how AI components and pipelines are integrated. With this information, we then develop a proof-of- concept architecture that analyzes AI models in a human-in-the- loop manner. SPATIAL provides an AI dashboard for allowing individuals interacting with applications to obtain quantifiable insights about the AI decision process. This information is then used by human operators to comprehend possible issues that influence the performance of AI models and adjust or counter them. Through rigorous benchmarks and experiments in real- world industrial applications, we demonstrate that SPATIAL can easily augment modern applications with metrics to gauge and monitor trustworthiness, however, this in turn increases the complexity of developing and maintaining systems implementing AI. Our work highlights lessons learned and experiences from augmenting modern applications with mechanisms that support regulatory compliance of AI. In addition, we also present a road map of on-going challenges that require attention to achieve robust trustworthy analysis of AI and greater engagement of human oversight.
Abdul-Rasheed Ottun, Rasinthe Marasinghe, Toluwani Elemosho, Mohan Liyanage, Mohamad Ragab, Prachi Bagave, Marcus Westberg, Mehrdad Asadi, Michell Boerger, Chamara Sandeepa, Thulitha Senevirathna, Bartlomiej Siniarski, Madhusanka Liyanage, Vinh Hoa La, Manh-Dung Nguyen, Edgardo Montes de Oca, Tessa Oomen, João Fernando Ferreira Gonçalves, Illija Tanaskovic, Sasa Klopanovic, Nicolas Kourtellis, Claudio Soriente, Jason Pridmore, Ana R. Cavalli, Drasko Draskovic, Samuel Marchal, Shen Wang 0006, David Solans Noguero, Nikolay Tcholtchev, Aaron Yi Ding, Huber Flores
ICDCS22
2023 No Forking Way: Detecting Cloning Attacks on Intel SGX Applications
abstract
Forking attacks against TEEs like Intel SGX can be carried out either by rolling back the application to a previous state, or by cloning the application and by partitioning its inputs across the cloned instances. Current solutions to forking attacks require Trusted Third Parties (TTP) that are hard to find in real-world deployments. In the absence of a TTP, many TEE applications rely on monotonic counters to mitigate forking attacks based on rollbacks; however, they have no protection mechanism against forking attack based on cloning. In this paper, we analyze 72 SGX applications and show that approximately 20% of those are vulnerable to forking attacks based on cloning—including those that rely on monotonic counters.
Samira Briongos, Ghassan Karame, Claudio Soriente, Annika Wilde
ACSAC3
2023 Modular Sumcheck Proofs with Applications to Machine Learning and Image Processing
abstract
Cryptographic proof systems provide integrity, fairness, and privacy in applications that outsource data processing tasks. However, general-purpose proof systems do not scale well to large inputs. At the same time, ad-hoc solutions for concrete applications - e.g., machine learning or image processing - are more efficient but lack modularity, hence they are hard to extend or to compose with other tools of a data-processing pipeline.
David Balbás, Dario Fiore 0001, María Isabel González Vasco, Damien Robissout, Claudio Soriente
CCS5
2022 Auditable Asymmetric Password Authenticated Public Key Establishment
Antonio Faonio, María Isabel González Vasco, Claudio Soriente, Hien Thi Thu Truong
CANS3
2022 Subversion-Resilient Enhanced Privacy ID
Antonio Faonio, Dario Fiore 0001, Luca Nizzardo, Claudio Soriente
CT-RSA4
2022 Ring Signatures with User-Controlled Linkability
Dario Fiore 0001, Lydia Garms, Dimitris Kolonelos, Claudio Soriente, Ida Tucker
ESORICS (2)4
2022 On the Challenges of Detecting Side-Channel Attacks in SGX
abstract
Existing tools to detect side-channel attacks on Intel SGX are grounded on the observation that attacks affect the performance of the victim application. As such, all detection tools monitor the potential victim and raise an alarm if the witnessed performance (in terms of runtime, enclave interruptions, cache misses, etc.) is out of the ordinary.
Jianyu Jiang, Claudio Soriente, Ghassan Karame
RAID2
2021 User profiling by network observers
abstract
Targeted online advertising is a multi-billion dollar business based on the ability of profiling and delivering targeted ads to a wide range of users. Due to the privacy erosion associated with such business, researchers are trying to understand how profiling works and anti-tracking applications are becoming popular among users. Both research and privacy-enhancing apps, however, target ad-networks or over-the-top providers that have unrestricted access to users' online activity. There seems to be little interest in potential profiling activities by "network observers" like ISPs or VPN providers. On the one side, this may be explained by the pervasiveness of TLS that secures connections end-to-end. On the other side, TLS does leak some information, and it is not clear what an eavesdropper can learn about a user, despite her traffic being encrypted.
Roberto Gonzalez, Claudio Soriente, Juan Miguel Carrascosa, Alberto García-Durán, Costas Iordanou, Mathias Niepert
CoNEXT2
2021 Controlled Functional Encryption Revisited: Multi-Authority Extensions and Efficient Schemes for Quadratic Functions
abstract
Abstract In a Functional Encryption scheme (FE), a trusted authority enables designated parties to compute specific functions over encrypted data. As such, FE promises to break the tension between industrial interest in the potential of data mining and user concerns around the use of private data. FE allows the authority to decide who can compute and what can be computed, but it does not allow the authority to control which ciphertexts can be mined. This issue was recently addressed by Naveed et al., that introduced so-called Controlled Functional encryption (or C-FE), a cryptographic framework that extends FE and allows the authority to exert fine-grained control on the ciphertexts being mined. In this work we extend C-FE in several directions. First, we distribute the role of (and the trust in) the authority across several parties by defining multi-authority C-FE (or mCFE). Next, we provide an efficient instantiation that enables computation of quadratic functions on inputs provided by multiple data-owners, whereas previous work only provides an instantiation for linear functions over data supplied by a single data-owner and resorts to garbled circuits for more complex functions. Our scheme leverages CCA2 encryption and linearly-homomorphic encryption. We also implement a prototype and use it to showcase the potential of our instantiation.
Miguel Ambrona, Dario Fiore 0001, Claudio Soriente
Proc. Priv. Enhancing Technol.3
2021 A Key for John Doe: Modeling and Designing Anonymous Password-Authenticated Key Exchange Protocols
abstract
Anonymous Password-Authenticated Key Exchange (\sf APAKEAPAKE) can be seen as the hybrid offspring of standard key exchange and anonymous password authentication protocols. \sf APAKEAPAKE allows a client holding a low-entropy password to establish a session key with a server, provided that the client's password is in the server's set. Moreover, no information about the password input by the client or the set of valid passwords held by the server should leak to the other party-beyond whether the client's password lies or not in the server's password database. To the best of our knowledge, all \sf APAKEAPAKE proposals to date either assume client storage or force the client to remember the index assigned to its password in the server's database. Furthermore, earlier works either provide only informal definitions or fail in some sense to properly model the primitive. In this paper, we provide a formal security model for \sf APAKEAPAKE, capturing security and anonymity provisions for both clients and servers. In addition, we present two \sf APAKEAPAKE protocols that only require clients to remember a password and that attain our sought key secrecy and anonymity guarantees. Our first protocol leverages oblivious pseudo-random functions, while the second one builds upon a special type of identity-based encryption scheme.
María Isabel González Vasco, Angel L. Pérez del Pozo, Claudio Soriente
IEEE Trans. Dependable Secur. Comput.3
2019 Beyond content analysis: detecting targeted ads via distributed counting
abstract
Being able to check whether an online advertisement has been targeted is essential for resolving privacy controversies and implementing in practice data protection regulations like GDPR, CCPA, and COPPA. In this paper we describe the design, implementation, and deployment of an advertisement auditing system called eyeWnder that uses crowdsourcing to reveal in real time whether a display advertisement has been targeted or not. Crowdsourcing simplifies the detection of targeted advertising, but requires reporting to a central repository the impressions seen by different users, thereby jeopardizing their privacy. We break this deadlock with a privacy preserving data sharing protocol that allows eyeWnder to compute global statistics required to detect targeting, while keeping the advertisements seen by individual users and their browsing history private. We conduct a simulation study to explore the effect of different parameters and a live validation to demonstrate the accuracy of our approach. Unlike previous solutions, eyeWnder can even detect indirect targeting, i.e. , marketing campaigns that promote a product or service whose description bears no semantic overlap with its targeted audience.
Costas Iordanou, Nicolas Kourtellis, Juan Miguel Carrascosa, Claudio Soriente, Rubén Cuevas Rumín, Nikolaos Laoutaris
CoNEXT4
2019 ReplicaTEE: Enabling Seamless Replication of SGX Enclaves in the Cloud
abstract
With the proliferation of Trusted Execution Environments (TEEs) such as Intel SGX, a number of cloud providers will soon introduce TEE capabilities within their offering (e.g., Microsoft Azure). The integration of SGX within the cloud considerably strengthens the threat model for cloud applications. However, cloud deployments depend on the ability of the cloud operator to add and remove application dynamically; this is no longer possible given the current model to deploy and provision enclaves that actively involves the application owner. In this paper, we propose ReplicaTEE, a solution that enables seamless commissioning and decommissioning of TEE-based applications in the cloud. ReplicaTEE leverages an SGX-based provisioning service that interfaces with a Byzantine Fault-Tolerant storage service to securely orchestrate enclave replication in the cloud, without the active intervention of the application owner. Namely, in ReplicaTEE, the application owner entrusts application secret to the provisioning service; the latter handles all enclave commissioning and decommissioning operations throughout the application lifetime. We analyze the security of ReplicaTEE and show that it is secure against attacks by a powerful adversary that can compromise a large fraction of the cloud infrastructure. We implement a prototype of ReplicaTEE in a realistic cloud environment and evaluate its performance. ReplicaTEE moderately increments the TCB by approximately 800 LoC. Our evaluation shows that ReplicaTEE does not add significant overhead to existing SGX-based applications.
Claudio Soriente, Ghassan Karame, Wenting Li 0001, Sergey Fedorov
EuroS&P1
2019 DoubleEcho: Mitigating Context-Manipulation Attacks in Copresence Verification
abstract
Copresence verification based on context can improve usability and strengthen security of many authentication and access control systems. By sensing and comparing their surroundings, two or more devices can tell whether they are copresent and use this information to make access control decisions. To the best of our knowledge, all context-based copresence verification mechanisms to date are susceptible to context-manipulation attacks. In such attacks, a distributed adversary replicates the same context at the (different) locations of the victim devices, and induces them to believe that they are copresent. In this paper we propose DoubleEcho, a context-based copresence verification technique that leverages acoustic Room Impulse Response (RIR) to mitigate context-manipulation attacks. In DoubleEcho, one device emits a wide-band audible chirp and all participating devices record reflections of the chirp from the surrounding environment. Since RIR is, by its very nature, dependent on the physical surroundings, it constitutes a unique location signature that is hard for an adversary to replicate. We evaluate DoubleEcho by collecting RIR data with various mobile devices and in a range of different locations. We show that DoubleEcho mitigates context-manipulation attacks whereas all other approaches to date are entirely vulnerable to such attacks. DoubleEcho detects copresence (or lack thereof) in roughly 2 seconds and works on commodity devices.
Hien Thi Thu Truong, Juhani Toivonen, Thien Duc Nguyen, Claudio Soriente, Sasu Tarkoma, N. Asokan
PerCom4
2019 Securing Cloud Data Under Key Exposure
abstract
Recent news reveal a powerful attacker which breaks data confidentiality by acquiring cryptographic keys, by means of coercion or backdoors in cryptographic software. Once the encryption key is exposed, the only viable measure to preserve data confidentiality is to limit the attacker's access to the ciphertext. This may be achieved, for example, by spreading ciphertext blocks across servers in multiple administrative domains-thus assuming that the adversary cannot compromise all of them. Nevertheless, if data is encrypted with existing schemes, an adversary equipped with the encryption key, can still compromise a single server and decrypt the ciphertext blocks stored therein. In this paper, we study data confidentiality against an adversary which knows the encryption key and has access to a large fraction of the ciphertext blocks. To this end, we propose Bastion, a novel and efficient scheme that guarantees data confidentiality even if the encryption key is leaked and the adversary has access to almost all ciphertext blocks. We analyze the security of Bastion, and we evaluate its performance by means of a prototype implementation. We also discuss practical insights with respect to the integration of Bastion in commercial dispersed storage systems. Our evaluation results suggest that Bastion is well-suited for integration in existing systems since it incurs less than 5 percent overhead compared to existing semantically secure encryption modes.
Ghassan Karame, Claudio Soriente, Krzysztof Lichota, Srdjan Capkun
IEEE Trans. Cloud Comput.2
2019 Long-term Measurement and Analysis of the Free Proxy Ecosystem
abstract
Free web proxies promise anonymity and censorship circumvention at no cost. Several websites publish lists of free proxies organized by country, anonymity level, and performance. These lists index hundreds of thousands of hosts discovered via automated tools and crowd-sourcing. A complex free proxy ecosystem has been forming over the years, of which very little is known. In this article, we shed light on this ecosystem via a distributed measurement platform that leverages both active and passive measurements. Active measurements are carried out by an infrastructure we name ProxyTorrent, which discovers free proxies, assesses their performance, and detects potential malicious activities. Passive measurements focus on proxy performance and usage in the wild, and are accomplished by means of a Chrome extension named Ciao. ProxyTorrent has been running since January 2017, monitoring up to 230K free proxies. Ciao was launched in March 2017 and has thus far served roughly 9.7K users and generated 14TB of traffic. Our analysis shows that less than 2% of the proxies announced on the Web indeed proxy traffic on behalf of users; further, only half of these proxies have decent performance and can be used reliably. Every day, around 5%--10% of the active proxies exhibit malicious behaviors, e.g., advertisement injection, TLS interception, and cryptojacking, and these proxies are also the ones providing the best performance. Through the analysis of more than 14TB of proxied traffic, we show that web browsing is the primary user activity. Geo-blocking avoidance—allegedly a popular use case for free web proxies—accounts for 30% or less of the traffic, and it mostly involves countries hosting popular geo-blocked content.
Diego Perino, Matteo Varvello, Claudio Soriente
ACM Trans. Web3
2018 Nothing Refreshes Like a RePSI: Reactive Private Set Intersection
Andrea Cerulli, Emiliano De Cristofaro, Claudio Soriente
ACNS3
2018 There goes Wally: Anonymously sharing your location gives you away
abstract
With current technology, a number of entities have access to user mobility traces at different levels of spatio-temporal granularity. At the same time, users frequently reveal their location through different means, including geo-tagged social media posts and mobile app usage. Such leaks are often bound to a pseudonym or a fake identity in an attempt to preserve one's privacy. In this work, we investigate how large-scale mobility traces can de-anonymize anonymous location leaks. By mining the country-wide mobility traces of tens of millions of users, we aim to understand how many location leaks are required to uniquely match a trace, how spatio-temporal obfuscation decreases the matching quality, and how the location popularity and time of the leak influence de-anonymization. We also study the mobility characteristics of those individuals whose anonymous leaks are more prone to identification. Finally, by extending our matching methodology to full traces, we show how large-scale human mobility is highly unique. Our quantitative results have implications for the privacy of users' traces, and may serve as a guideline for future policies regarding the management and publication of mobility data.
Apostolos Pyrgelis, Nicolas Kourtellis, Ilias Leontiadis, Joan Serrà, Claudio Soriente
IEEE BigData5
2018 ProxyTorrent: Untangling the Free HTTP(S) Proxy Ecosystem
abstract
Free web proxies promise anonymity and censorship circumvention at no cost. Several websites publish lists of free proxies organized by country, anonymity level, and performance. These lists index hundreds of thousand of hosts discovered via automated tools and crowd-sourcing. A complex free proxy ecosystem has been forming over the years, of which very little is known. In this paper we shed light on this ecosystem via ProxyTorrent, a distributed measurement platform that leverages both active and passive measurements. Active measurements discover free proxies, assess their performance, and detect potential malicious activities. Passive measurements relate to proxy performance and usage in the wild, and are collected by free proxies users via a Chrome plugin we developed. ProxyTorrent has been running since January 2017, monitoring up to 180,000 free proxies and totaling more than 1,500 users over a 10 months period. Our analysis shows that less than 2% of the proxies announced on the Web indeed proxy traffic on behalf of users; further, only half of these proxies have decent performance and can be used reliably. Around 10% of the working proxies exhibit malicious behaviors, e.g., ads injection and TLS interception, and these proxies are also the ones providing the best performance. Through the analysis of more than 2 Terabytes of proxied traffic, we show that web browsing is the primary user activity. Geo-blocking avoidance is not a prominent use-case, with the exception of proxies located in countries hosting popular geo-blocked content.
Diego Perino, Matteo Varvello, Claudio Soriente
WWW3
2018 Toward Shared Ownership in the Cloud
abstract
Cloud storage platforms promise a convenient way for users to share files and engage in collaborations, yet they require all files to have a single owner who unilaterally makes access control decisions. Existing clouds are, thus, agnostic to the notion of shared ownership. This can be a significant limitation in much collaboration because, for example, one owner can delete files and revoke access without consulting the other collaborators. In this paper, we first formally define a notion of shared ownership within a file access control model. We then propose two possible instantiations of our proposed shared ownership model. Our first solution, called Commune, relies on secure file dispersal and collusion-resistant secret sharing to ensure that all access grants in the cloud require the support of an agreed threshold of owners. As such, Commune can be used in existing clouds without modifications to the platforms. Our second solution, dubbed Comrade, leverages the blockchain technology in order to reach consensus on access control decision. Unlike Commune, Comrade requires that the cloud is able to translate access control decisions that reach consensus in the blockchain into storage access control rules, thus requiring minor modifications to existing clouds. We analyze the security of our proposals and compare/evaluate their performance through implementations using Amazon S3.
Hubert Ritzdorf, Claudio Soriente, Ghassan Karame, Srdjan Marinovic, Damian Gruber, Srdjan Capkun
IEEE Trans. Inf. Forensics Secur.2
2017 Who is Fiddling with Prices?: Building and Deploying a Watchdog Service for E-commerce
abstract
We present the design, implementation, validation, and deployment of the Price Sheriff, a highly distributed system for detecting various types of online price discrimination in e-commerce. The Price Sheriff uses a peer-to-peer architecture, sandboxing, and secure multiparty computation to allow users to tunnel price check requests through the browsers of other peers without tainting their local or server-side browsing history and state. Having operated the Price Sheriff for several months with approximately one thousand real users, we identify several instances of cross-border price discrimination based on the country of origin. Even within national borders, we identify several retailers that return different prices for the same product to different users. We examine whether the observed differences are due to personal-data-induced discrimination or A/B testing, and conclude that it is the latter.
Costas Iordanou, Claudio Soriente, Michael Sirivianos, Nikolaos Laoutaris
SIGCOMM2
2017 Partitioned Group Password-Based Authenticated Key Exchange
abstract
Group Password-Based Authenticated Key Exchange (GPAKE) allows a group of users to establish a secret key, as long as all of them share the same password. However, in existing GPAKE protocols as soon as one user runs the protocol with a non-matching password, all the others abort and no key is established. In this paper we seek for a more flexible, yet secure, GPAKE and put forward the notion of partitionedGPAKE. Partitioned GPAKE tolerates users that run the protocol on different passwords. Through a protocol run, any subgroup of users that indeed share a password, establish a session key, factoring out the ‘noise’ of inputs by users holding different passwords. At the same time any two keys, each established by a different subgroup of users, are pair-wise independent if the corresponding subgroups hold different passwords. We also introduce the notion of password-privacy for partitioned GPAKE, which is a kind of affiliation hiding property, ensuring that an adversary should not be able to tell whether any given set of users share a password. Finally, we propose an efficient instantiation of partitioned GPAKE building on an unforgeable symmetric encryption scheme and a PAKE by Bellare et al. Our proposal is proven secure in the random oracle/ideal cipher model, and requires only two communication rounds.
Dario Fiore 0001, María Isabel González Vasco, Claudio Soriente
Comput. J.3
2016 Evaluation of Personalized Security Indicators as an Anti-Phishing Mechanism for Smartphone Applications
abstract
Mobile application phishing happens when a malicious mobile application masquerades as a legitimate one to steal user credentials. Personalized security indicators may help users to detect phishing attacks, but rely on the user's alertness. Previous studies in the context of website phishing have shown that users tend to ignore personalized security indicators and fall victim to attacks despite their deployment. Consequently, the research community has deemed personalized security indicators an ineffective phishing detection mechanism. We revisit the question of personalized security indicator effectiveness and evaluate them in the previously unexplored and increasingly important context of mobile applications. We conducted a user study with 221 participants and found that the deployment of personalized security indicators decreased the phishing attack success rate to 50%. Personalized security indicators can, therefore, help phishing detection in mobile applications and their reputation as an anti-phishing mechanism in the mobile context should be reconsidered.
Claudio Marforio, Ramya Jayaram Masti, Claudio Soriente, Kari Kostiainen, Srdjan Capkun
CHI3
2016 User Profiling in the Time of HTTPS
Roberto Gonzalez, Claudio Soriente, Nikolaos Laoutaris
Internet Measurement Conference2
2016 SALVE: server authentication with location verification
abstract
The Location Service (LCS) proposed by the telecommunication industry is an architecture that allows the location of mobile devices to be accessed in various applications. We explore the use of LCS in location-enhanced server authentication, which traditionally relies on certificates. Given recent incidents involving certificate authorities, various techniques to strengthen server authentication were proposed. They focus on improving the certificate validation process, such as pinning, revocation, or multi-path probing. In this paper, we propose using the server's geographic location as a second factor of its authenticity. Our solution, SALVE, achieves location-based server authentication by using secure DNS resolution and by leveraging LCS for location measurements. We develop a TLS extension that enables the client to verify the server's location in addition to its certificate. Successful server authentication therefore requires a valid certificate and the server's presence at a legitimate geographic location, e.g., on the premises of a data center. SALVE prevents server impersonation by remote adversaries with mis-issued certificates or stolen private keys of the legitimate server. We develop a prototype implementation and our evaluation in real-world settings shows that it incurs minimal impact to the average server throughput. Our solution is backward compatible and can be integrated with existing approaches for improving server authentication in TLS.
Der-Yeuan Yu, Aanjhan Ranganathan, Ramya Jayaram Masti, Claudio Soriente, Srdjan Capkun
MobiCom4
2015 Logical Partitions on Many-Core Platforms
abstract
Cloud platforms that use logical partitions to allocate dedicated resources to VMs can benefit from small and therefore secure hypervisors. Many-core platforms, with their abundant resources, are an attractive basis to create and deploy logical partitions on a large scale. However, many-core platforms are designed for efficient cross-core data sharing rather than isolation, which is a key requirement for logical partitions. Typically, logical partitions leverage hardware virtualization extensions that require complex CPU core enhancements. These extensions are not optimal for many-core platforms, where it is preferable to keep the cores as simple as possible.
Ramya Jayaram Masti, Claudio Marforio, Kari Kostiainen, Claudio Soriente, Srdjan Capkun
ACSAC4
2015 Commune: Shared Ownership in an Agnostic Cloud
abstract
Cloud storage platforms promise a convenient way for users to share files and engage in collaborations, yet they require all files to have a single owner who unilaterally makes access control decisions. Existing clouds are, thus, agnostic to shared ownership. This can be a significant limitation in many collaborations because, for example, one owner can delete files and revoke access without consulting the other collaborators.
Claudio Soriente, Ghassan Karame, Hubert Ritzdorf, Srdjan Marinovic, Srdjan Capkun
SACMAT1
2015 Sound-Proof: Usable Two-Factor Authentication Based on Ambient Sound
Nikolaos Karapanos, Claudio Marforio, Claudio Soriente, Srdjan Capkun
USENIX Security Symposium3
2014 Enforcing Location and Time-Based Access Control on Cloud-Stored Data
abstract
Recent incidents of data-breaches from the cloud suggest that users should not trust the cloud provider to enforce access control on their data. We focus on mitigating trust to the cloud in scenarios where granting access to data not only considers user identities (as in conventional access policies), but also contextual information such as the user's location and time of access. Previous work in this context assumes a fully trusted cloud that is further capable of locating users. We introduce LoTAC, a novel framework that seamlessly integrates the operation of a cloud provider and a localization infrastructure to enforce location- and time-based access control to cloud-stored data. In LoTAC, the two entities operate independently and are only trusted to offer their basic services: the cloud provider is used and trusted only to reliably store data, the localization infrastructure is used and trusted only to accurately locate users. Furthermore, neither the cloud provider nor the localization infrastructure can access the data, even if they collude. LoTAC protocols require no changes to the cloud provider and minimal changes to the localization infrastructure. We evaluate our protocols using a cellular network as the localization infrastructure and show that they incur in low communication and computation costs and scale well with a large number of users and policies.
Elli Androulaki, Claudio Soriente, Luka Malisa, Srdjan Capkun
ICDCS2
2014 Smartphones as Practical and Secure Location Verification Tokens for Payments
Claudio Marforio, Nikolaos Karapanos, Claudio Soriente, Kari Kostiainen, Srdjan Capkun
NDSS3
2013 SHAKE: Single HAsh key establishment for resource constrained devices
Paolo Barsocchi, Gabriele Oligeri, Claudio Soriente
Ad Hoc Networks3
2013 Extended Capabilities for a Privacy-Enhanced Participatory Sensing Infrastructure (PEPSI)
abstract
Participatory sensing is emerging as an innovative computing paradigm that targets the ubiquity of always-connected mobile phones and their sensing capabilities. In this paper, a multitude of pioneering applications increasingly carry out pervasive collection and dissemination of information and environmental data, such as traffic conditions, pollution, temperature, and so on. Participants collect and report measurements from their mobile devices and entrust them to the cloud to be made available to applications and users. Naturally, due to the personal information associated to the reports (e.g., location, movements, etc.), a number of privacy concerns need to be considered prior to a large-scale deployment of these applications. Motivated by the need for privacy protection in participatory sensing, this paper presents a privacy-enhanced participatory sensing infrastructure. We explore realistic architectural assumptions and a minimal set of formal requirements aiming at protecting privacy of both data producers and consumers. We propose two instantiations that attain privacy guarantees with provable security at very low additional computational cost and almost no extra communication overhead.
Emiliano De Cristofaro, Claudio Soriente
IEEE Trans. Inf. Forensics Secur.2
2013 United We Stand: Intrusion Resilience in Mobile Unattended WSNs
abstract
Wireless Sensor Networks (WSNs) are susceptible to a wide range of attacks due to their distributed nature, limited sensor resources, and lack of tamper resistance. Once a sensor is corrupted, the adversary learns all secrets. Thereafter, most security measures become ineffective. Recovering secrecy after compromise requires either help from a trusted third party or access to a source of high-quality cryptographic randomness. Neither is available in Unattended Wireless Sensor Networks (UWSNs), where the sink visits the network periodically. Prior results have shown that sensor collaboration is an effective but expensive means of obtaining probabilistic intrusion resilience in static UWSNs. In this paper, we focus on intrusion resilience in Mobile Unattended Wireless Sensor Networks (μUWSNs), where sensors move according to some mobility models. Note that such a mobility feature could be independent from security (e.g., sensors move to improve area coverage). We define novel security metrics to evaluate intrusion resilience protocols for sensor networks. We also propose a cooperative protocol that - by leveraging sensor mobility - allows compromised sensors to recover secure state after compromise. This is obtained with very low overhead and in a fully distributed fashion. Thorough analysis and extensive simulations support our findings.
Roberto Di Pietro, Gabriele Oligeri, Claudio Soriente, Gene Tsudik
IEEE Trans. Mob. Comput.3
2012 Relieve Internet Routing Security of Public Key Infrastructure
abstract
Lack of security mechanisms expose the Border Gateway Protocol (BGP) to a wide range of threats that are constantly undermining security of the Internet. Most prominent attacks include prefix hijacking and announcement of false routes to maliciously attract or divert traffic. A number of cryptographic solutions to prevent both attacks have been proposed but have not been adopted due to involved operations and considerable overhead. Most of them rely on digital signatures to authorize Autonomous Systems to propagate route announcements. Surprisingly, the scientific community has devoted only little interest to the problem of revocation in BGP. In particular, BGP systems based on Public Key Infrastructure allow to revoke an Autonomous System by revoking its public key certificate. However, there seem to be no solution for selective revocation of AS-path announcements. This paper introduces reBGP, an enhanced version of BGP that leverages Identity Based Cryptography to secure BGP with minimal overhead. reBGP prevents prefix hijacking and false route announcement through Aggregate Identity Based Signatures and provides an effective revocation means to invalidate AS-path announcements. reBGP enjoys a constant overhead to verify authenticity of routes and does not require a Public Key Infrastructure. Extensive testing of our implementation, show that our proposal represents a practical solution to secure BGP.
Luigi V. Mancini, Angelo Spognardi, Claudio Soriente, Antonio Villani, Domenico Vitali
ICCCN3
2012 Hummingbird: Privacy at the Time of Twitter
abstract
In the last several years, micro-blogging Online Social Networks (OSNs), such as Twitter, have taken the world by storm, now boasting over 100 million subscribers. As an unparalleled stage for an enormous audience, they offer fast and reliable centralized diffusion of pithy tweets to great multitudes of information-hungry and always-connected followers. At the same time, this information gathering and dissemination paradigm prompts some important privacy concerns about relationships between tweeters, followers and interests of the latter. In this paper, we assess privacy in today's Twitter-like OSNs and describe an architecture and a trial implementation of a privacy-preserving service called Hummingbird. It is essentially a variant of Twitter that protects tweet contents, hash tags and follower interests from the (potentially) prying eyes of the centralized server. We argue that, although inherently limited by Twitter's mission of scalable information-sharing, this degree of privacy is valuable. We demonstrate, via a working prototype, that Hummingbird's additional costs are tolerably low. We also sketch out some viable enhancements that might offer better privacy in the long term.
Emiliano De Cristofaro, Claudio Soriente, Gene Tsudik, Andrew Williams 0003
IEEE Symposium on Security and Privacy2
2012 Self-healing in unattended wireless sensor networks
abstract
Wireless sensor networks (WSNs) appeal to a wide range of applications that involve the monitoring of various physical phenomena. However, WSNs are subject to many threats. In particular, lack of pervasive tamper-resistant hardware results in sensors being easy targets for compromise. Having compromised a sensor, the adversary learns all the sensor secrets, allowing it to later encrypt/decrypt or authenticate messages on behalf of that sensor. This threat is particularly relevant in the novel unattended wireless sensor networks (UWSNs) scenario. UWSNs operate without constant supervision by a trusted sink. UWSN's unattended nature and increased exposure to attacks prompts the need for special techniques geared towards regaining security after being compromised. In this article, we investigate cooperative self-healing in UWSNs and propose various techniques to allow unattended sensors to recover security after compromise. Our techniques provide seamless healing rates even against a very agile and powerful adversary. The effectiveness and viability of our proposed techniques are assessed by thorough analysis and supported by simulation results. Finally, we introduce some real-world issues affecting UWSN deployment and provide some solutions for them as well as a few open problems calling for further investigation.
Roberto Di Pietro, Di Ma 0001, Claudio Soriente, Gene Tsudik
ACM Trans. Sens. Networks3
2012 StreamCloud: An Elastic and Scalable Data Streaming System
abstract
Many applications in several domains such as telecommunications, network security, large-scale sensor networks, require online processing of continuous data flows. They produce very high loads that requires aggregating the processing capacity of many nodes. Current Stream Processing Engines do not scale with the input load due to single-node bottlenecks. Additionally, they are based on static configurations that lead to either under or overprovisioning. In this paper, we present StreamCloud, a scalable and elastic stream processing engine for processing large data stream volumes. StreamCloud uses a novel parallelization technique that splits queries into subqueries that are allocated to independent sets of nodes in a way that minimizes the distribution overhead. Its elastic protocols exhibit low intrusiveness, enabling effective adjustment of resources to the incoming load. Elasticity is combined with dynamic load balancing to minimize the computational resources used. The paper presents the system design, implementation, and a thorough evaluation of the scalability and elasticity of the fully implemented system.
Vincenzo Gulisano, Ricardo Jiménez-Peris, Marta Patiño-Martínez, Claudio Soriente, Patrick Valduriez
IEEE Trans. Parallel Distributed Syst.4
2011 Short paper: PEPSI - privacy-enhanced participatory sensing infrastructure
abstract
Participatory Sensing combines the ubiquity of mobile phones with the sensing capabilities of Wireless Sensor Networks. It targets the pervasive collection of information, e.g., temperature, traffic conditions, or medical data. Users produce measurements from their mobile devices, thus, a number of privacy concerns -- due to the personal information conveyed by reports -- may hinder the large-scale deployment of participatory sensing applications. Prior work has attempted to protect privacy in participatory sensing, but it relied on unrealistic assumptions and achieved no provably-secure guarantees. In this paper, we introduce PEPSI: Privacy-Enhanced Participatory Sensing Infrastructure. We explore realistic architectural assumptions and a minimal set of formal requirements aiming at protecting privacy of both data producers and consumers. We also present an instantiation that attains privacy guarantees with provable security at very low additional computational cost and almost no extra communication overhead. Finally, we highlight some problems that call for further research in this developing area.
Emiliano De Cristofaro, Claudio Soriente
WISEC2
2011 Intrusion-resilient integrity in data-centric unattended WSNs
Roberto Di Pietro, Claudio Soriente, Angelo Spognardi, Gene Tsudik
Pervasive Mob. Comput.2
2010 Intrusion-Resilience in Mobile Unattended WSNs
abstract
Wireless Sensor Networks (WSNs) are susceptible to a wide range of attacks due to their distributed nature, limited sensor resources and lack of tamper-resistance. Once a sensor is corrupted, the adversary learns all secrets and (even if the sensor is later released) it is very difficult for the sensor to regain security, i.e., to obtain intrusion-resilience. Existing solutions rely on the presence of an on-line trusted third party, such as a sink, or on the availability of secure hardware on sensors. Neither assumption is realistic in large-scale Unattended WSNs (UWSNs), characterized by long periods of disconnected operation and periodic visits by the sink. In such settings, a mobile adversary can gradually corrupt the entire network during the intervals between sink visits. As shown in some recent work, intrusion-resilience in UWSNs can be attained (to a degree) via cooperative self-healing techniques. In this paper, we focus on intrusion-resilience in Mobile Unattended Wireless Sensor Networks (¿UWSNs) where sensors move according to some mobility model. We argue that sensor mobility motivates a specific type of adversary and defending against it requires new security techniques. Concretely, we propose a cooperative protocol that - by leveraging sensor mobility - allows compromised sensors to recover secure state after compromise. This is obtained with very low overhead and in a fully distributed fashion. We provide a thorough analysis of the proposed protocol and support it by extensive simulation results.
Roberto Di Pietro, Gabriele Oligeri, Claudio Soriente, Gene Tsudik
INFOCOM3
2010 CReW: Cloud Resilience for Windows Guests through Monitored Virtualization
abstract
Clouds are complex systems subject to an increasing number of anomalies and threats. In this paper we briefly revisit the issues related to Windows guest cloud service resilience and later provide some preliminary results on the resilience of Windows cloud guests via virtualization. In particular, we propose an architecture, Cloud Resilience for Windows (CReW). CReW can transparently monitor guest Windows VMs and can also react to both security breaches and system integrity violation, improving the dependability of cloudified Windows systems. CReW can also improve resilience from software misconfiguration by restoring the guest latest safe state. Effectiveness and performance of a CReW prototype have been evaluated, obtained results show the feasibility of such a system.
Flavio Lombardi, Roberto Di Pietro, Claudio Soriente
SRDS3
2010 Securing Mobile Unattended WSNs against a Mobile Adversary
abstract
One important factor complicating security in Wireless Sensor Networks (WSNs) is lack of inexpensive tamper-resistant hardware in commodity sensors. Once an adversary compromises a sensor, all memory and forms of storage become exposed, along with all secrets. Thereafter, any cryptographic remedy ceases to be effective. Regaining sensor security after compromise (i.e., intrusion-resilience) is a formidable challenge. Prior approaches rely on either (1) the presence of an on-line trusted third party (sink), or (2) the availability of a True Random Number Generator (TRNG) on each sensor. Neither assumption is realistic in large-scale Unattended Wireless Sensor Networks (UWSNs) composed of low-cost commodity sensors. periodic visits by the sink. Previous work has demonstrated that sensor collaboration is an effective, yet expensive, means of attaining intrusion-resilience in UWSNs. In this paper, we explore intrusion resilience in Mobile UWSNs in the presence of a powerful mobile adversary. We show how the choice of the sensor mobility model influences intrusion resilience with respect to this adversary. We also explore self healing protocols that require only local communication. Results indicate that sensor density and neighborhood variability are the two key parameters affecting intrusion resilience. Our findings are supported by extensive analyses and simulations.
Roberto Di Pietro, Gabriele Oligeri, Claudio Soriente, Gene Tsudik
SRDS3
2010 Security and privacy issues in the Portable Document Format
Aniello Castiglione, Alfredo De Santis, Claudio Soriente
J. Syst. Softw.3
2009 On the difficulty of software-based attestation of embedded devices
abstract
Device attestation is an essential feature in many security protocols and applications. The lack of dedicated hardware and the impossibility to physically access devices to be attested, makes attestation of embedded devices, in applications such as Wireless Sensor Networks, a prominent challenge. Several software-based attestation techniques have been proposed that either rely on tight time constraints or on the lack of free space to store malicious code. This paper investigates the shortcomings of existing software-based attestation techniques. We first present two generic attacks, one based on a return-oriented rootkit} and the other on code compression. We further describe specific attacks on two existing proposals, namely SWATT and ICE-based schemes, and argue about the difficulty of fixing them. All attacks presented in this paper were implemented and validated on commodity sensors.
Claude Castelluccia, Aurélien Francillon, Daniele Perito, Claudio Soriente
CCS4
2009 Collaborative authentication in unattended WSNs
abstract
An unattended wireless sensor network (UWSN) might collect valuable data representing an attractive target for the adversary. Since a sink visits the network infrequently, unattended sensors cannot immediately off-load data to some safe external entity. With sufficient time between sink visits, a powerful mobile adversary can easily compromise sensor-collected data.
Roberto Di Pietro, Claudio Soriente, Angelo Spognardi, Gene Tsudik
WISEC2
2009 Playing hide-and-seek with a focused mobile adversary in unattended wireless sensor networks
Roberto Di Pietro, Luigi V. Mancini, Claudio Soriente, Angelo Spognardi, Gene Tsudik
Ad Hoc Networks3
2009 Data Security in Unattended Wireless Sensor Networks
abstract
In recent years, wireless sensor networks (WSNs) have been a very popular research topic, offering a treasure trove of systems, networking, hardware, security, and application-related problems. Much of prior research assumes that the WSN is supervised by a constantly present sink and sensors can quickly offload collected data. In this paper, we focus on unattended WSNs (UWSNs) characterized by intermittent sink presence and operation in hostile settings. Potentially lengthy intervals of sink absence offer greatly increased opportunities for attacks resulting in erasure, modification, or disclosure of sensor-collected data. This paper presents an in-depth investigation of security problems unique to UWSNs (including a new adversarial model) and proposes some simple and effective countermeasures for a certain class of attacks.
Roberto Di Pietro, Luigi V. Mancini, Claudio Soriente, Angelo Spognardi, Gene Tsudik
IEEE Trans. Computers3
2008 HAPADEP: Human-Assisted Pure Audio Device Pairing
Claudio Soriente, Gene Tsudik, Ersin Uzun
ISC1
2008 Catch Me (If You Can): Data Survival in Unattended Sensor Networks
abstract
Unattended sensor networks operating in hostile environments might collect data that represents a high-value target for the adversary. The unattended sensor's inability to off-load - in real time - sensitive data to a safe external entity makes it easy for the adversary to mount a focused attack aimed at eliminating certain target data. In order to facilitate survival of this data, sensors can collectively attempt to confuse the adversary by changing its location and content, i.e., by periodically moving the data around the network and encrypting it. In this paper, we focus on data survival in unattended sensor networks faced with an adversary intent on surgically destroying data which it considers to be of high value. After motivating the problem and considering several attack flavors, we propose several simple techniques and provide their detailed evaluation.
Roberto Di Pietro, Luigi V. Mancini, Claudio Soriente, Angelo Spognardi, Gene Tsudik
PerCom3
2008 POSH: Proactive co-Operative Self-Healing in Unattended Wireless Sensor Networks
abstract
Unattended Wireless Sensor Networks (UWSNs) are composed of many small resource-constrained devices and operate autonomously, gathering data which is periodically collected by a visiting sink. Unattended mode of operation, deployment in hostile environments and value (or criticality) of collected data are some of the factors that complicate UWSN security. This paper makes two contributions. First, it explores a new threat model involving a mobile adversary who periodically compromises and releases sensors aiming to maximize its advantage and overall knowledge of collected data. Second, it constructs a self-healing protocol that allows sensors to continuously and collectively recover from compromise. The proposed protocol is both effective and efficient, as supported by analytical and simulation results.
Roberto Di Pietro, Di Ma 0001, Claudio Soriente, Gene Tsudik
SRDS3
2007 Taking advantages of a disadvantage: Digital forensics and steganography using document metadata
Aniello Castiglione, Alfredo De Santis, Claudio Soriente
J. Syst. Softw.3