Attila A. Yavuz

dblp:73/4897 · also Attila Altay Yavuz · DBLP profile ↗
← Back
49ranked-venue papers
12as first author
19since 2021 · last 2026
0000-0002-8680-9307ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 31 · 8 first-author · 9 since 2021Computer networks · 11 · 2 first-author · 4 since 2021Systems, architecture and hardware · 3 · 3 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author
YearPublicationVenuePosition
2026 A Full Threshold NIST PQC-Compliant Framework for Distributed Trust in Federal Public Key Infrastructure
Kiarash Sedghighadikolaei, Changqi Sun, Thang Hoang, Bechir Hamdaoui, Attila A. Yavuz
SP5
2026 Privacy-preserving and secure spectrum sharing for database-driven cognitive radio networks
Saleh Darzi, Gökcan Cantali, Attila A. Yavuz, Gürkan Gür
Comput. Networks3
2026 Lightweight and High-Throughput Secure Logging for Internet of Things and Cold Cloud Continuum
abstract
The growing deployment of resource-limited Internet of Things (IoT) devices and their expanding attack surfaces demand efficient and scalable security mechanisms. System logs are vital for the trust and auditability of IoT, and offloading their maintenance to a Cold Storage-as-a-Service (Cold-STaaS) enhances cost-effectiveness and reliability. However, existing cryptographic logging solutions either burden low-end IoT devices with heavy computation or create verification delays and storage inefficiencies at Cold-STaaS. There is a pressing need for cryptographic primitives that balance security, performance, and scalability across IoT–Cold-STaaS continuum. In this work, we present Parallel Optimal Signatures for Secure Logging ( \(\texttt {POSLO}{}\) ), a novel digital signature framework that, to our knowledge, is the first to offer constant-size signatures and public keys, near-optimal signing efficiency, and tunable fine-to-coarse-grained verification for log auditing. \(\texttt {POSLO}{}\) achieves these properties through efficient randomness management, flexible aggregation, and multiple algorithmic instantiations. It also introduces a GPU-accelerated batch verification framework that exploits homomorphic signature aggregation to deliver ultra-fast performance. For example, \(\texttt {POSLO}{}\) can verify \(2^{31}\) log entries per second on a mid-range consumer GPU (NVIDIA GTX 3060) while being significantly more compact than state-of-the-art. \(\texttt {POSLO}{}\) also preserves signer-side efficiency, offering substantial battery savings for IoT devices, and is well-suited for the IoT–Cold-STaaS ecosystem.
Saif E. Nouma, Attila A. Yavuz
ACM Trans. Internet Things2
2025 QRSec 2025: ACM CCS First Workshop on Quantum-Resistant Cryptography and Security
abstract
Quantum computing poses transformative opportunities and challenges, with cryptography at the forefront of its impact. The ACM CCS Workshop on Quantum-Resistant Cryptography and Security (QRSec 2025) provides a forum for researchers, practitioners, and industry leaders to explore advances in post-quantum cryptography (PQC) and its integration into secure systems. Building on the momentum of the NIST PQC standardization process and the release of the first standards in 2024, QRSec 2025 highlights theoretical foundations, algorithm design, engineering, and deployment strategies alongside emerging topics such as machine learning for cryptanalysis, quantum-resistant networks, blockchain, IoT, and cloud security. The program features keynotes from leading experts, technical paper sessions, and interactive panels bridging academia, industry, and government. By fostering dialogue across these communities, QRSec 2025 aims to advance the state of the art in quantum-resistant security and chart practical paths for migration and compliance in the post-quantum era.
Ashish Kundu, Attila A. Yavuz, Cristina Nita-Rotaru
CCS2
2025 Getting Ready for the Future (or Now): Towards a Cybersecurity Fabric for Future Integrated Satellite-Terrestrial Networks
abstract
In this paper, we outline a fast and lightweight network security fabric and identify the research gaps for developing such a fabric that respects the needs of trustworthy NextG SATIN for the post-quantum era. To achieve these objectives, we identify in which research directions more innovations are needed, namely algorithmic (NIST-PQC, distributed computing, time-disclosed cryptography), architectural (decentralized SATIN, distributed key management), and evaluation aspects.
Gürkan Gür, Attila A. Yavuz
VTC2025-Spring2
2025 Standing Firm in 5G: A Single-Round, Dropout-Resilient Secure Aggregation for Federated Learning
abstract
Federated learning (FL) is well-suited to 5G networks, where many mobile devices generate sensitive edge data. Secure aggregation protocols enhance privacy in FL by ensuring that individual user updates reveal no information about the underlying client data. However, the dynamic and large-scale nature of 5G-marked by high mobility and frequent dropouts-poses significant challenges to the effective adoption of these protocols. Existing protocols often require multi-round communication or rely on fixed infrastructure, limiting their practicality. We propose a lightweight, single-round secure aggregation protocol designed for 5G environments. By leveraging base stations for assisted computation and incorporating precomputation, key-homomorphic pseudorandom functions, and t-out-of-k secret sharing, our protocol ensures efficiency, robustness, and privacy. Experiments show strong security guarantees and significant gains in communication and computation efficiency, making the approach well-suited for real-world 5G FL deployments.
Yiwei Zhang 0008, Rouzbeh Behnia, Imtiaz Karim, Attila A. Yavuz, Elisa Bertino
WISEC4
2025 Efficient Full-Stack Private Federated Deep Learning With Post-Quantum Security
abstract
Federated learning (FL) enables collaborative model training while preserving user data privacy by keeping data local. Despite these advantages, FL remains vulnerable to privacy attacks on user updates and model parameters during training and deployment. Secure aggregation protocols have been proposed to protect user updates by encrypting them, but these methods often incur high computational costs and are not resistant to quantum computers. Additionally, differential privacy (DP) has been used to mitigate privacy leakages, but existing methods focus on secure aggregation or DP, neglecting their potential synergies. To address these gaps, we introduce$\texttt {Beskar}$, a novel framework that provides post-quantum secure aggregation, optimizes computational overhead for FL settings, and defines a comprehensive threat model that accounts for a wide spectrum of adversaries. We also integrate DP into different stages of FL training to enhance privacy protection in diverse scenarios. Our framework provides a detailed analysis of the trade-offs between security, performance, and model accuracy, representing the first thorough examination of secure aggregation protocols combined with various DP approaches for post-quantum secure FL.$\texttt {Beskar}$aims to address the pressing privacy and security issues FL while ensuring quantum-safety and robust performance.
Yiwei Zhang 0008, Rouzbeh Behnia, Attila A. Yavuz, Reza Ebrahimi 0001, Elisa Bertino
IEEE Trans. Dependable Secur. Comput.3
2025 Efficient Fault-Detection Architectures for Barrett Reduction and Multiplication in Classical and Post-Quantum Cryptographic Systems
abstract
Barrett modular reduction and multiplication are essential primitives for efficient modular computation in cryptographic schemes, including post-quantum standards such as machine learning (ML) key encapsulation mechanism (KEM) and ML-digital signature algorithm (DSA). To protect against faults that compromise correctness and security, we introduce the first efficient fault-detection mechanisms tailored to these operations. For modular reduction, we leverage word-based representations with compact word-sum checks that exploit algebraic input-output relations to ensure computational integrity. For modular multiplication, we adopt a tunable hybrid strategy: early stages apply word-sum checks, while later stages use partial recomputation with encoded inputs, providing robust protection against injected faults. Formal analysis, fault-injection simulations, and hardware/software implementations show that our methods detect a wide range of faults with minimal performance and area overhead. Evaluation results demonstrate overheads of 3.43% and 7.15% for 512-bit and 1024-bit inputs in modular reduction, and 26.47% and 27.22% for 2048-bit inputs in modular multiplication in the number of clock cycles in software. Moreover, in hardware, we observed reasonable overheads: less than 27.5% in area and 2.1% in delay for modular reduction, and less than 23.5% in area and 16.2% in delay for modular multiplication. These results confirm the practicality of our methods for secure yet efficient integration.
Saeed Aghapour, Kiarash Sedghighadikolaei, Attila A. Yavuz, Bechir Hamdaoui, Mehran Mozaffari Kermani
IEEE Trans. Very Large Scale Integr. Syst.3
2025 Corrections to "Efficient Fault-Detection Architectures for Barrett Reduction and Multiplication in Classical and Post-Quantum Cryptographic Systems"
abstract
After the acceptance of [1], an error was introduced, which we aim to resolve here. The abbreviation ML stands for module lattice-based, not “machine learning.” The first sentence of the first paragraph is corrected from the version that was published in Early Access. It should have read, “Barrett modular reduction and multiplication are essential primitives for efficient modular computation in cryptographic schemes, including postquantum standards such as module lattice-based (ML) key encapsulation mechanism (KEM) and ML-digital signature algorithm (DSA).” In the Introduction, the same correction has been made for the abbreviation ML.
Saeed Aghapour, Kiarash Sedghighadikolaei, Attila A. Yavuz, Bechir Hamdaoui, Mehran Mozaffari Kermani
IEEE Trans. Very Large Scale Integr. Syst.3
2024 Trustworthy and Efficient Digital Twins in Post-Quantum Era with Hybrid Hardware-Assisted Signatures
abstract
Digital Twins (DT) virtually model cyber-physical objects via sensory inputs by simulating or monitoring their behavior. Therefore, DTs usually harbor vast quantities of Internet of Things (IoT) components (e.g., sensors) that gather, process, and offload sensitive information (e.g., healthcare) to the cloud. It is imperative to ensure the trustworthiness of such sensitive information with long-term and compromise-resilient security guarantees. Digital signatures provide scalable authentication and integrity with non-repudiation and are vital tools for DTs. Post-quantum cryptography (PQC) and forward-secure signatures are two fundamental tools to offer long-term security and breach resiliency. However, NIST-PQC signature standards are exorbitantly costly for embedded DT components and are infeasible when forward-security is also considered. Moreover, NIST-PQC signatures do not admit aggregation, which is a highly desirable feature to mitigate the heavy storage and transmission burden in DTs. Finally, NIST recommends hybrid PQ solutions to enable cryptographic agility and transitional security. Yet, there is a significant gap in the state of the art in the achievement of all these advanced features simultaneously. Therefore, there is a significant need for lightweight digital signatures that offer compromise resiliency and compactness while permitting transitional security into the PQ era for DTs. We create a series of highly lightweight digital signatures called Hardware-ASisted Efficient Signature ( HASES ) that meets the above requirements. The core of HASES is a hardware-assisted cryptographic commitment construct oracle ( CCO ) that permits verifiers to obtain expensive commitments without signer interaction. We created three HASES schemes: PQ-HASES is a forward-secure PQ signature, LA-HASES is an efficient aggregate Elliptic-Curve signature, and HY-HASES is a novel hybrid scheme that combines PQ-HASES and LA-HASES with novel strong nesting and sequential aggregation. HASES does not require a secure-hardware on the signer. We prove that HASES schemes are secure and implemented them on commodity hardware and and 8-bit AVR ATmega2560. Our experiments confirm that PQ-HASES and LA-HASES are two magnitudes of times more signer efficient than their PQ and conventional-secure counterparts, respectively. HY-HASES outperforms NIST PQC and conventional signature combinations, offering a standard-compliant transitional solution for emerging DTs. We open-source HASES schemes for public-testing and adaptation.
Saif E. Nouma, Attila A. Yavuz
ACM Trans. Multim. Comput. Commun. Appl.2
2023 Post-Quantum Forward-Secure Signatures with Hardware-Support for Internet of Things
abstract
Digital signatures provide scalable authentication with non-repudiation and therefore are vital tools for the Internet of Things (IoT). IoT applications harbor vast quantities of low-end devices that are expected to operate for long periods with a risk of compromise. Hence, IoT needs post-quantum cryptography (PQC) that respects the resource limitations of low-end devices while offering compromise resiliency (e.g., forward-security). However, as seen in NIST PQC efforts, quantum-safe signatures are extremely costly for low-end IoT. These costs become prohibitive when forward security is considered. We propose a highly lightweight post-quantum digital signature called HArdware-Supported Efficient Signature (HASES) that meets the stringent requirements of resource-limited signers (processor, memory, bandwidth) with forward security. HASES transforms a key-evolving one-time hash-based signature into a polynomially unbounded one by introducing a public key oracle via secure enclaves. The signer is non-interactive and only generates a few hashes per signature. Unlike existing hardware-supported alternatives, HASES does not require a secure-hardware on the signer, which is infeasible for low-end IoT. HASES also does not assume non-colluding servers that permit scalable verification. We proved that HASES is secure and implemented it on the commodity hardware and the 8-bit AVR ATmega2560 microcontroller. Our experiments confirm that HASES is$271\times\ \mathbf{and}\ 34\times$faster than (forward-secure) XMSS and (plain) Dilithium. HASES is more than twice and magnitude more energy-efficient than (forward-secure) ANT and (plain) BLISS, respectively, on an 8-bit device. We open-source HASES for public testing and adaptation.
Saif E. Nouma, Attila A. Yavuz
ICC2
2023 Efficient Dynamic Proof of Retrievability for Cold Storage
Tung Le 0005, Pengzhi Huang, Attila A. Yavuz, Elaine Shi, Thang Hoang
NDSS3
2022 Titanium: A Metadata-Hiding File-Sharing System with Malicious Security
Weikeng Chen, Thang Hoang, Jorge Guajardo, Attila A. Yavuz
NDSS4
2022 Ultra Lightweight Multiple-Time Digital Signature for the Internet of Things Devices
abstract
Digital signatures are basic cryptographic tools to provide authentication and integrity in the emerging ubiquitous systems in which resource-constrained devices are expected to operate securely and efficiently. However, existing digital signatures might not be fully practical for such resource-constrained devices (e.g., medical implants) that have energy limitations. Some other computationally efficient alternatives (e.g., one-time/multiple-time signatures) may introduce high memory and/or communication overhead due to large private key and signature sizes. In this paper, our contributions are two-fold: First, we develop a new lightweight multiple-time digital signature scheme called Signer Efficient Multiple-time Elliptic Curve Signature ($\mathtt {SEMECS}{}$), which is suitable for resource-constrained embedded devices.$\mathtt {SEMECS}{}$achieves optimal signature and private key sizes for an EC-based signaturewithoutrequiring any EC operation (e.g., EC scalar multiplication or addition) at the signer. We prove$\mathtt {SEMECS}{}$is secure (in random oracle model) with a tight security reduction. Second, we fully implemented$\mathtt {SEMECS}{}$on 8-bit AVR microprocessor with a comprehensive energy consumption analysis and comparison. Our experiments confirm up to 19× less battery-consumption for$\mathtt {SEMECS}{}$as compared to its fastest (full-time) counterpart, SchnorrQ, while offering significant performance advantages over its multiple-time counterparts in various fronts. We open-source our implementation for public testing and adoption.
Attila A. Yavuz, Muslum Ozgur Ozmen
IEEE Trans. Serv. Comput.1
2021 Towards Practical Post-quantum Signatures for Resource-Limited Internet of Things
abstract
A digital signature is an essential cryptographic tool to offer authentication with public verifiability, non-repudiation, and scalability. However, digital signatures often rely on expensive operations that can be highly costly for low-end devices, typically seen in the Internet of Things and Systems (IoTs). These efficiency concerns especially deepen when post-quantum secure digital signatures are considered. Hence, it is of vital importance to devise post-quantum secure digital signatures that are designed with the needs of such constraint IoT systems in mind.
Rouzbeh Behnia, Attila A. Yavuz
ACSAC2
2021 Look Before You Leap: Secure Connection Bootstrapping for 5G Networks to Defend Against Fake Base-Stations
abstract
The lack of authentication protection for bootstrapping messages broadcast by base-stations makes impossible for devices to differentiate between a legitimate and a fake base-station. This vulnerability has been widely acknowledged, but not yet fixed and thus enables law-enforcement agencies, motivated adversaries and nation-states to carry out attacks against targeted users. Although 5G cellular protocols have been enhanced to prevent some of these attacks, the root vulnerability for fake base-stations still exists. In this paper, we propose an efficient broadcast authentication protocol based on a hierarchical identity-based signature scheme, Schnorr-HIBS, which addresses the root cause of the fake base-station problem with minimal computation and communication overhead. We implement and evaluate our proposed protocol using off-the-shelf software-defined radios and open-source libraries. We also provide a comprehensive quantitative and qualitative comparison between our scheme and other candidate solutions for 5G base-station authentication proposed by 3GPP. Our proposed protocol achieves at least a 6x speedup in terms of end-to-end cryptographic delay and a communication cost reduction of 31% over other 3GPP proposals.
Ankush Singla, Rouzbeh Behnia, Syed Rafiul Hussain, Attila A. Yavuz, Elisa Bertino
AsiaCCS4
2021 Proof-of-Useful-Randomness: Mitigating the Energy Waste in Blockchain Proof-of-Work
abstract
Proof-of-Work (PoW) is one of the fundamental and widely-used consensus algorithms in blockchains. In PoW, nodes compete to receive the mining reward by trying to be the first to solve a puzzle. Despite its fairness and wide-availability, traditional PoW incurs extreme computational and energy waste over the blockchain. This waste is considered to be one of the biggest problems in PoW-based blockchains and cryptocurrencies. In this work, we propose a new useful PoW called Proof-of-Useful-Randomness (PoUR) that mitigates the energy waste by incorporating pre-computed (disclosable) randomness into the PoW. The key idea is to inject special randomness into puzzles via algebraic commitments that can be stored and later disclosed. Unlike the traditional wasteful PoWs, our approach enables pre-computed commitments to be utilized by a vast array of public-key cryptography methods that require offline-online processing (e.g., digital signature, key exchange, zero-knowledge protocol). Moreover, our PoW preserves the desirable properties of the traditional PoW and therefore does not require a substantial alteration in the underlying protocol. We showed the security of our PoW, and then fully implemented it to validate its significant energy-saving capabilities.
Efe Seyitoglu, Attila A. Yavuz, Thang Hoang
SECRYPT2
2021 Efficient Oblivious Data Structures for Database Services on the Cloud
abstract
Database-as-a-service (DBaaS) allows the client to store and manage structured data on the cloud remotely. Despite its merits, DBaaS also brings significant privacy issues. Existing encryption techniques (e.g., SQL-aware encryption) can mitigate privacy concerns, but they still leak information through access patterns, which are vulnerable to statistical inference attacks. Oblivious Random Access Machine (ORAM) can seal such leakages; however, the recent studies showed significant challenges on the integration of ORAM into databases. That is, the direct usage of ORAM on databases is not only costly but also permits very limited query functionalities. In this paper, we propose new oblivious data structures called Oblivious Matrix Structure (OMAT), which allow tree-based ORAM to be integrated into database systems in a more efficient manner with diverse query functionalities supported. OMAT provides special ORAM packaging strategies for table structures, which not only offers a significantly better performance but also enables a broad range of query types that may not be efficient in existing frameworks. On the other hand, OTREE allows oblivious conditional queries to be performed on tree-indexed databases more efficiently than existing techniques. We implemented our proposed techniques and evaluated their performance on a real cloud database with various metrics, compared with state-of-the-art counterparts.
Thang Hoang, Ceyhun D. Ozkaptan, Gabriel Hackebeil, Attila A. Yavuz
IEEE Trans. Cloud Comput.4
2021 A Secure Searchable Encryption Framework for Privacy-Critical Cloud Storage Services
abstract
Searchable encryption has received a significant attention from the research community with various constructions being proposed, each achieving asymptotically optimal complexity for specific metrics (e.g., search, update). Despite their elegance, the recent attacks and deployment efforts have shown that the optimal asymptotic complexity might not always imply practical performance, especially if the application demands a high privacy. In this article, we introduce a novel Dynamic Searchable Symmetric Encryption (DSSE) framework called Incidence Matrix (IM)-DSSE, which achieves a high level of privacy, efficient search/update, and low client storage with actual deployments on real cloud settings. We harness an incidence matrix along with two hash tables to create an encrypted index, on which both search and update operations can be performed effectively with minimal information leakage. This simple set of data structures surprisingly offers a high level of DSSE security while achieving practical performance. Specifically, IM-DSSE achieves forward-privacy, backward-privacy and size-obliviousness simultaneously. We also create several DSSE variants, each offering different trade-offs that are suitable for different cloud applications and infrastructures. We fully implemented our framework and evaluated its performance on a real cloud system (Amazon EC2). We have released IM-DSSE as an open-source library for wide development and adaptation.
Thang Hoang, Attila A. Yavuz, Jorge Guajardo
IEEE Trans. Serv. Comput.2
2020 MOSE: Practical Multi-User Oblivious Storage via Secure Enclaves
abstract
Multi-user oblivious storage allows users to access their shared data on the cloud while retaining access pattern obliviousness and data confidentiality simultaneously. Most secure and efficient oblivious storage systems focus on the utilization of the maximum network bandwidth in serving concurrent accesses via a trusted proxy. How- ever, since the proxy executes a standard ORAM protocol over the network, the performance is capped by the network bandwidth and latency. Moreover, some important features such as access control and security against active adversaries have not been thoroughly explored in such proxy settings. In this paper, we propose MOSE, a multi-user oblivious storage system that is efficient and enjoys from some desirable security properties. Our main idea is to harness a secure enclave, namely Intel SGX, residing on the untrusted storage server to execute proxy logic, thereby, minimizing the network bottleneck of proxy-based designs. In this regard, we address various technical design chal- lenges such as memory constraints, side-channel attacks and scala- bility issues when enabling proxy logic in the secure enclave. We present a formal security model and analysis for secure enclave multi-user ORAM with access control. We optimize MOSE to boost its throughput in serving concurrent requests. We implemented MOSE and evaluated its performance on commodity hardware. Our evaluation confirmed the efficiency of MOSE, where it achieves approximately two orders of magnitudes higher throughput than the state-of-the-art proxy-based design, and also, its performance is scalable proportional to the available system resources.
Thang Hoang, Rouzbeh Behnia, Yeongjin Jang, Attila A. Yavuz
CODASPY4
2020 Compatible Certificateless and Identity-Based Cryptosystems for Heterogeneous IoT
Rouzbeh Behnia, Attila A. Yavuz, Muslum Ozgur Ozmen, Tsz Hon Yuen
ISC2
2020 MACAO: A Maliciously-Secure and Client-Efficient Active ORAM Framework
Thang Hoang, Jorge Guajardo, Attila A. Yavuz
NDSS3
2020 Lattice-Based Public Key Searchable Encryption from Experimental Perspectives
abstract
Public key Encryption with Keyword Search (PEKS) aims in mitigating the impacts of data privacy versus utilization dilemma by allowing any user in the system to send encrypted files to the server to be searched by a receiver. The receiver can retrieve the encrypted files containing specific keywords by providing the corresponding trapdoors of these keywords to the server. Despite their merits, the existing PEKS schemes introduce a high end-to-end delay that may hinder their adoption in practice. Moreover, they do not scale well for large security parameters and provide no post-quantum security promises. In this paper, we propose two novel lattice-based PEKS schemes that offer a high computational efficiency along with better security assurances than that of the existing alternatives. Specifically, our NTRU-PEKS scheme achieves 18 times lower end-to-end delay than the most efficient pairing-based alternatives. Our LWE-PEKS offers provable security in the standard model with a reduction to the worst-case lattice problems. We fully implemented our NTRU-PEKS scheme and benchmarked its performance as deployed on Amazon Web Services cloud infrastructures.
Rouzbeh Behnia, Muslum Ozgur Ozmen, Attila A. Yavuz
IEEE Trans. Dependable Secur. Comput.3
2020 A Multi-server ORAM Framework with Constant Client Bandwidth Blowup
abstract
Oblivious Random Access Machine (ORAM) allows a client to hide the access pattern when accessing sensitive data on a remote server. It is known that there exists a logarithmic communication lower bound on any passive ORAM construction, where the server only acts as the storage service. This overhead, however, was shown costly for some applications. Several active ORAM schemes with server computation have been proposed to overcome this limitation. However, they mostly rely on costly homomorphic encryptions, whose performance is worse than passive ORAM. In this article, we propose S 3 ORAM, a new multi-server ORAM framework, which features O (1) client bandwidth blowup and low client storage without relying on costly cryptographic primitives. Our key idea is to harness Shamir Secret Sharing and a multi-party multiplication protocol on applicable binary tree-ORAM paradigms. This strategy allows the client to instruct the server(s) to perform secure and efficient computation on his/her behalf with a low intervention thereby, achieving a constant client bandwidth blowup and low server computational overhead. Our framework can also work atop a general k -ary tree ORAM structure ( k ≥ 2). We fully implemented our framework, and strictly evaluated its performance on a commodity cloud platform (Amazon EC2). Our comprehensive experiments confirmed the efficiency of S 3 ORAM framework, where it is approximately 10× faster than the most efficient passive ORAM (i.e., Path-ORAM) for a moderate network bandwidth while being three orders of magnitude faster than active ORAM with O (1) bandwidth blowup (i.e., Onion-ORAM). We have open-sourced the implementation of our framework for public testing and adaptation.
Thang Hoang, Attila A. Yavuz, Jorge Guajardo
ACM Trans. Priv. Secur.2
2019 ARIS: Authentication for Real-Time IoT Systems
abstract
Efficient authentication is vital for IoT applications with stringent minimum-delay requirements (e.g., energy delivery systems). This requirement becomes even more crucial when the IoT devices are battery-powered, like small aerial drones, and the efficiency of authentication directly translates to more operation time. Although some fast authentication techniques have been proposed, some of them might not fully meet the needs of the emerging delay-aware IoT. In this paper, we propose a new signature scheme called ARIS that pushes the limits of the existing digital signatures, wherein a commodity hardware can verify 83,333 signatures per second. ARIS also enables the fastest signature generation along with the lowest energy consumption and end-to-end delay among its counterparts. These significant computational advantages come with a larger storage requirement, which is a favorable trade-off for some critical delay-aware applications. These desirable features are achieved by harnessing message encoding with cover-free families and a special elliptic curve based oneway function. We prove the security of ARIS under the hardness of the elliptic curve discrete logarithm problem in the random oracle model. We provide an open-sourced implementation of ARIS on commodity hardware and 8-bit AVR microcontroller for public testing and verification.
Rouzbeh Behnia, Muslum Ozgur Ozmen, Attila A. Yavuz
ICC3
2019 TrustSAS: A Trustworthy Spectrum Access System for the 3.5 GHz CBRS Band
abstract
As part of its ongoing efforts to meet the increased spectrum demand, the Federal Communications Commission (FCC) has recently opened up 150 MHz in the 3.5 GHz band for shared wireless broadband use. Access and operations in this band, aka Citizens Broadband Radio Service (CBRS), will be managed by a dynamic spectrum access system (SAS) to enable seamless spectrum sharing between secondary users (SUs) and incumbent users. Despite its benefits, SAS's design requirements, as set by FCC, present privacy risks to SUs, merely because SUs are required to share sensitive operational information (e.g., location, identity, spectrum usage) with SAS to be able to learn about spectrum availability in their vicinity. In this paper, we propose TrustSAS, a trustworthy framework for SAS that synergizes state-of-the-art cryptographic techniques with blockchain technology in an innovative way to address these privacy issues while complying with FCC's regulatory design requirements. We analyze the security of our framework and evaluate its performance through analysis, simulation and experimentation. We show that TrustSAS can offer high security guarantees with reasonable overhead, making it an ideal solution for addressing SUs' privacy issues in an operational SAS environment.
Mohamed Grissa, Attila A. Yavuz, Bechir Hamdaoui
INFOCOM2
2019 A multi-server oblivious dynamic searchable encryption framework
abstract
Data privacy is one of the main concerns for data outsourcing on the cloud. Although standard encryption can provide confidentiality, it prevents the client from searching/retrieving meaningful information on the outsourced data thereby, degrading the benefits of using cloud services. To address this data utilization versus privacy dilemma, Dynamic Searchable Symmetric Encryption (DSSE) has been proposed. DSSE enables encrypted search and update functionality over the encrypted data via a secure index. However, the state-of-the-art DSSE constructions leak information from the access pattern, making them vulnerable against various attacks. While generic Oblivious Random Access Machine (ORAM) can hide the access pattern, it incurs a heavy communication overhead, which was shown costly to be directly used in the DSSE setting. In this article, by exploiting the multi-cloud infrastructure, we develop a comprehensive Oblivious Distributed DSSE (ODSE) framework that allows oblivious search and updates on the encrypted index with high security and improved efficiency over the use of generic ORAM. Our framework contains a series of [Formula: see text] schemes each featuring different levels of performance and security required by various types of real-life applications. ODSE offers desirable security guarantees such as information-theoretic security and robustness in the presence of a malicious adversary. We fully implemented [Formula: see text] framework and evaluated its performance in a real cloud environment (Amazon EC2). Our experiments showed that ODSE schemes are [Formula: see text]-[Formula: see text] faster than using generic ORAMs on a DSSE encrypted index under real network settings.
Thang Hoang, Attila A. Yavuz, F. Betül Durak, Jorge Guajardo
J. Comput. Secur.2
2019 Hardware-Supported ORAM in Effect: Practical Oblivious Search and Update on Very Large Dataset
abstract
Abstract The ability to query and update over encrypted data is an essential feature to enable breach-resilient cyber-infrastructures. Statistical attacks on searchable encryption (SE) have demonstrated the importance of sealing information leaks in access patterns. In response to such attacks, the community has proposed the Oblivious Random Access Machine (ORAM). However, due to the logarithmic communication overhead of ORAM, the composition of ORAM and SE is known to be costly in the conventional client-server model, which poses a critical barrier toward its practical adaptations. In this paper, we propose a novel hardware-supported privacy-enhancing platform called Practical Oblivious Search and Update Platform (POSUP), which enables oblivious keyword search and update operations on large datasets with high efficiency. We harness Intel SGX to realize efficient oblivious data structures for oblivious search/update purposes. We implemented POSUP and evaluated its performance on a Wikipedia dataset containing ≥229 keyword-file pairs. Our implementation is highly efficient, taking only 1 ms to access a 3 KB block with Circuit-ORAM. Our experiments have shown that POSUP offers up to 70× less end-to-end delay with 100× reduced network bandwidth consumption compared with the traditional ORAM-SE composition without secure hardware. POSUP is also at least 4.5× faster for up to 99.5% of keywords that can be searched compared with state-of-the-art Intel SGX-assisted search platforms.
Thang Hoang, Muslum Ozgur Ozmen, Yeongjin Jang, Attila A. Yavuz
Proc. Priv. Enhancing Technol.4
2018 TACHYON: Fast Signatures from Compact Knapsack
abstract
We introduce a simple, yet efficient digital signature scheme which offers post-quantum security promise. Our scheme, named TACHYON, is based on a novel approach for extending one-time hash-based signatures to (polynomially bounded) many-time signatures, using the additively homomorphic properties of generalized compact knapsack functions. Our design permits TACHYON~to achieve several key properties. First, its signing and verification algorithms are the fastest among its current counterparts with a higher level of security. This allows TACHYON~to achieve the lowest end-to-end delay among its counterparts, while also making it suitable for resource-limited signers. Second, its private keys can be as small as κ bits, where κ is the desired security level. Third, unlike most of its lattice-based counterparts, TACHYON~does not require any Gaussian sampling during signing, and therefore, is free from side-channel attacks targeting this process. We also explore various speed and storage trade-offs for TACHYON, thanks to its highly tunable parameters. Some of these trade-offs can speed up TACHYON signing in exchange for larger keys, thereby permitting TACHYON~to further improve its end-to-end delay.
Rouzbeh Behnia, Muslum Ozgur Ozmen, Attila A. Yavuz, Mike Rosulek
CCS3
2018 Oblivious Dynamic Searchable Encryption on Distributed Cloud Systems
Thang Hoang, Attila A. Yavuz, F. Betül Durak, Jorge Guajardo
DBSec2
2018 Forward-Private Dynamic Searchable Symmetric Encryption with Efficient Search
abstract
Dynamic Searchable Symmetric Encryption (DSSE) allows to delegate keyword search and file update over an encrypted database via encrypted indexes, and therefore provides opportunities to mitigate the data privacy and utilization dilemma in cloud storage platforms. Despite its merits, recent works have shown that efficient DSSE schemes are vulnerable to statistical attacks due to the lack of forward-privacy, whereas forward-private DSSE schemes suffers from practicality concerns as a result of their extreme computation overhead. Due to significant practical impacts of statistical attacks, there is a critical need for new DSSE schemes that can achieve the forward-privacy in a more practical and efficient manner. We propose a new DSSE scheme that we refer to as Forward-private Sublinear DSSE (FS-DSSE). FS-DSSE harnesses special secure update strategies and a novel caching strategy to reduce the computation cost of repeated queries. Therefore, it achieves forward-privacy, sublinear search complexity, low end-to-end delay, and parallelization capability simultaneously. We fully implemented our proposed method and evaluated its performance on a real cloud platform. Our experimental evaluation results showed that the proposed scheme is highly secure and highly efficient compared with state-of-the-art DSSE techniques. Specifically, FS-DSSE is up to three magnitude of times faster than forward-secure DSSE counterparts, depending on the frequency of the searched keyword in the database.
Muslum Ozgur Ozmen, Thang Hoang, Attila A. Yavuz
ICC3
2018 Immutable Authentication and Integrity Schemes for Outsourced Databases
abstract
Database outsourcing enables organizations to offload their data management overhead to the external service providers. Immutable signatures are ideal tools to provide authentication and integrity for such applications with an important property called immutability. Signature immutability ensures that, no attacker can derive a valid signature for unposed queries from previous queries and their corresponding signatures. This prevents an attacker from creating his own de-facto services via such derived signatures. Unfortunately, existing immutable signatures are very computation/communication costly, which make them impractical for real-life applications. In this paper, we developed three new schemes called practical and immutable signature bouquets (PISB), which achieve efficient immutability for outsourced databases. PISB schemes are simple, non-interactive, and computation/communication efficient. Our generic scheme can be constructed from any aggregate signature coupled with a standard signature. Our specific scheme is constructed from Condensed-RSA and Sequential Aggregate RSA. It has a low verifier computational overhead and compact signature. Our third scheme offers the lowest end-to-end delay among existing alternatives by enabling efficient signature pre-computability. We provide formal security analysis of PISB schemes (in Random Oracle Model) and give a theoretical analysis on the relationship between signature immutability and signature extraction. We also showed that PISB schemes are more efficient than previous alternatives.
Attila A. Yavuz
IEEE Trans. Dependable Secur. Comput.1
2017 S3ORAM: A Computation-Efficient and Constant Client Bandwidth Blowup ORAM with Shamir Secret Sharing
abstract
Oblivious Random Access Machine (ORAM) enables a client to access her data without leaking her access patterns. Existing client-efficient ORAMs either achieve O(log N) client-server communication blowup without heavy computation, or O(1) blowup but with expensive homomorphic encryptions. It has been shown that O(log N) bandwidth blowup might not be practical for certain applications, while schemes with O(1) communication blowup incur even more delay due to costly homomorphic operations.
Thang Hoang, Ceyhun D. Ozkaptan, Attila A. Yavuz, Jorge Guajardo
CCS3
2017 High-Speed High-Security Public Key Encryption with Keyword Search
Rouzbeh Behnia, Attila A. Yavuz, Muslum Ozgur Ozmen
DBSec2
2017 Preserving the Location Privacy of Secondary Users in Cooperative Spectrum Sensing
abstract
Cooperative spectrum sensing, despite its effectiveness in enabling dynamic spectrum access, suffers from location privacy threats, merely because secondary users (SUs)' sensing reports that need to be shared with a fusion center to make spectrum availability decisions are highly correlated to the users' locations. It is therefore important that cooperative spectrum sensing schemes be empowered with privacy preserving capabilities so as to provide SUs with incentives for participating in the sensing task. In this paper, we propose privacy preserving protocols that make use of various cryptographic mechanisms to preserve the location privacy of SUs while performing reliable and efficient spectrum sensing. We also present cost-performance tradeoffs. The first consists on using an additional architectural entity at the benefit of incurring lower computation overhead by relying only on symmetric cryptography. The second consists on using an additional secure comparison protocol at the benefit of incurring lesser architectural cost by not requiring extra entities. Our schemes can also adapt to the case of a malicious fusion center as we discuss in this paper. We also show that not only are our proposed schemes secure and more efficient than existing alternatives, but also achieve fault tolerance and are robust against sporadic network topological changes.
Mohamed Grissa, Attila A. Yavuz, Bechir Hamdaoui
IEEE Trans. Inf. Forensics Secur.2
2017 Real-Time Digital Signatures for Time-Critical Networks
abstract
The secure and efficient operation of time-critical networks, such as vehicular networks, smart-grid, and other smart-infrastructures, is of primary importance in today's society. It is crucial to minimize the impact of security mechanisms over such networks so that the safe and reliable operations of time-critical systems are not being interfered. For instance, if the delay introduced by the crypto operations negatively affects the time available for braking a car before a collision, the car may not be able to safely stop in time. In particular, as a primary authentication mechanism, existing digital signatures introduce a significant computation and communication overhead, and therefore are unable to fully meet the real-time processing requirements of such time-critical networks. In this paper, we introduce a new suite of real-time digital signatures referred to as Structure-free and Compact Real-time Authentication (SCRA), supported by hardware acceleration, to provide delay-aware authentication in time-critical networks. SCRA is a novel signature framework that can transform any secure aggregate signature into a signer efficient signature. We instantiate SCRA framework with condensed-RSA, BGLS, and NTRU signatures. Our analytical and experimental evaluation validates the significant performance advantages of SCRA schemes over their base signatures and the state-of-the-art schemes. Moreover, we push the performance of SCRA schemes to the edge via highly optimized implementations on vehicular capable system-on-chip as well as server-grade general purpose graphics processing units. We prove that SCRA is secure (in random oracle model) and show that SCRA can offer an ideal alternative for authentication in time-critical applications.
Attila A. Yavuz, Anand Mudgerikar, Ankush Singla, Ioannis Papapanagiotou, Elisa Bertino
IEEE Trans. Inf. Forensics Secur.1
2016 Practical and secure dynamic searchable encryption via oblivious access on distributed data structure
Thang Hoang, Attila A. Yavuz, Jorge Guajardo
ACSAC2
2016 Mitigating jamming attacks in mobile cognitive networks through time hopping
abstract
5G wireless networks will support massive connectivity mainly due to device-to-device communications. An enabling technology for device-to-device links is the dynamical spectrum access. The devices, which are equipped with cognitive radios, are to be allowed to reuse spectrum occupied by cellular links. The dynamical spectrum availability makes cognitive users switch between channels. Switching leads to energy consumption, latency, and communication overhead in general. The performance degrades even more when the network is under jamming attack. This type of attack is one of the most detrimental attacks. Addressing jamming while maintaining a desired quality of service is a challenge. While existing anti-jamming mechanisms assume stationary users, in this paper, we propose and evaluate countermeasures for mobile cognitive users. We propose two time-based techniques, which, unlike other existing frequency-based techniques, do not assume accessibility to multiple channels and hence do not rely on switching to countermeasure jamming. We achieve analytical solutions of jamming, switching, and error probabilities. Based on our findings, the proposed techniques out perform other existing frequency-based techniques. Copyright © 2016 John Wiley & Sons, Ltd.
Nadia Adem, Bechir Hamdaoui, Attila A. Yavuz
Wirel. Commun. Mob. Comput.3
2015 LPOS: Location Privacy for Optimal Sensing in Cognitive Radio Networks
abstract
Cognitive Radio Networks (CRNs) enable opportunistic access to the licensed channel resources by allowing unlicensed users to exploit vacant channel opportunities. One effective technique through which unlicensed users, often referred to as Secondary Users (SUs), acquire whether a channel is vacant is cooperative spectrum sensing. Despite its effectiveness in enabling CRN access, cooperative sensing suffers from location privacy threats, merely because the sensing reports that need to be exchanged among the SUs to perform the sensing task are highly correlated to the SUs' locations. In this paper, we develop a new Location Privacy for Optimal Sensing (LPOS) scheme that preserves the location privacy of SUs while achieving optimal sensing performance through voting-based sensing. In addition, LPOS is the only alternative among existing CRN location privacy preserving schemes (to the best of our knowledge) that ensures high privacy, achieves fault tolerance, and is robust against the highly dynamic and wireless nature of CRNs.
Mohamed Grissa, Attila A. Yavuz, Bechir Hamdaoui
GLOBECOM2
2015 Dynamic Searchable Symmetric Encryption with Minimal Leakage and Efficient Updates on Commodity Hardware
Attila A. Yavuz, Jorge Guajardo
SAC1
2015 BAFi: a practical cryptographic secure audit logging scheme for digital forensics
abstract
Audit logs provide information about historical states of computer systems. They also contain highly valuable data that can be used by law enforcement in forensic investigations. Thus, ensuring the authenticity and integrity of audit logs is of vital importance. An ideal security mechanism for audit logging must also satisfy security properties such as forward-security (compromise resiliency), compactness, and computational efficiency. Unfortunately, existing secure audit logging schemes lack the computational or storage efficiency for modern performance requirements. Indeed, the practicality of such schemes has not been investigated in real-life systems, where logs generated in various occasions could be terabytes of data per day. To address this limitation, we developed an efficient, publicly verifiable, forward-secure, privacy-preserving, and aggregate logging scheme called blind-aggregate-forward improved (BAFi). BAFi is based on BAF, with new properties and performance improvements as follows: (i) BAFi improves the efficiency of BAF via implementation specific optimizations; (ii) BAFi has the option to not expose sensitive information in logs to protect valuable forensic information; (iii) BAFi was experimentally tested in real-world logs; and (iv) BAFi improves the security of BAF against log substitution. Our analysis shows that BAFi outperforms previous alternatives with similar properties and therefore is an ideal solution for nowadays highly intense logging systems. Copyright © 2015 John Wiley & Sons, Ltd.
Panos Kampanakis, Attila A. Yavuz
Secur. Commun. Networks2
2014 An Efficient Real-Time Broadcast Authentication Scheme for Command and Control Messages
abstract
Broadcast (multicast) authentication is crucial for large and distributed systems, such as cyber-physical infrastructures (e.g., power-grid/smart-grid) and wireless networks (e.g., intervehicle networks, military ad hoc networks). These time-critical systems require real-time authentication of command and control messages in a highly efficient, secure, and scalable manner. However, existing solutions are either computationally costly (e.g., asymmetric cryptography) or unscalable/impractical (e.g., symmetric cryptography, one-time signatures, delayed key disclosure methods). In this paper, we develop a new broadcast authentication scheme that we call rapid authentication (RA), which is suitable for time-critical authentication of command and control messages in large and distributed systems. We exploit the semistructured nature of command and control messages to construct special digital signatures, which are computationally efficient both at the signer and verifier sides. We show that RA achieves several desirable properties that are not available in existing alternatives simultaneously: 1) fast signature generation and verification; 2) immediate verification; 3) constant size public key; 4) compact authenticating tag; 5) packet loss tolerance; 6) being free from time synchronization requirement; and 7) provable security.
Attila A. Yavuz
IEEE Trans. Inf. Forensics Secur.1
2013 Practical Immutable Signature Bouquets (PISB) for Authentication and Integrity in Outsourced Databases
Attila A. Yavuz
DBSec1
2013 ETA: efficient and tiny and authentication for heterogeneous wireless systems
abstract
Authentication and integrity are vital security services for wireless ubiquitous systems, which require various resource-constrained devices to operate securely and efficiently. Digital signatures are basic cryptographic tools to provide these security services. However, existing digital signatures are not practical for resource-constrained systems (e.g., wireless sensors, RFID-tags). That is, traditional signatures (e.g., RSA, DSA) require expensive operations (e.g., modular exponentiation) that bring high computational cost and power-consumption. Some alternative schemes (e.g., multiple-time signatures, online/offline signatures, pre-computed tokens) are computationally efficient. However, they have large key and signature sizes and therefore are impractical for resource-constrained systems.
Attila A. Yavuz
WISEC1
2012 Self-sustaining, efficient and forward-secure cryptographic constructions for Unattended Wireless Sensor Networks
Attila A. Yavuz, Peng Ning
Ad Hoc Networks1
2012 BAF and FI-BAF: Efficient and Publicly Verifiable Cryptographic Schemes for Secure Logging in Resource-Constrained Systems
abstract
Audit logs are an integral part of modern computer systems due to their forensic value. Protecting audit logs on a physically unprotected machine in hostile environments is a challenging task, especially in the presence of active adversaries. It is critical for such a system to have forward security and append-only properties such that when an adversary compromises a logging machine, she cannot forge or selectively delete the log entries accumulated before the compromise. Existing public-key-based secure logging schemes are computationally costly. Existing symmetric secure logging schemes are not publicly verifiable and open to certain attacks. In this article, we develop a new forward-secure and aggregate signature scheme called Blind-Aggregate-Forward (BAF) , which is suitable for secure logging in resource-constrained systems. BAF is the only cryptographic secure logging scheme that can produce publicly verifiable, forward-secure and aggregate signatures with low computation, key/signature storage, and signature communication overheads for the loggers, without requiring any online trusted third party support . A simple variant of BAF also allows a fine-grained verification of log entries without compromising the security or computational efficiency of BAF. We prove that our schemes are secure in Random Oracle Model (ROM). We also show that they are significantly more efficient than all the previous publicly verifiable cryptographic secure logging schemes.
Attila A. Yavuz, Peng Ning, Michael K. Reiter
ACM Trans. Inf. Syst. Secur.1
2009 BAF: An Efficient Publicly Verifiable Secure Audit Logging Scheme for Distributed Systems
abstract
Audit logs, providing information about the current and past states of systems, are one of the most important parts of modern computer systems. Providing security for audit logs on an untrusted machine in a large distributed system is a challenging task, especially in the presence of active adversaries. In such a system, it is critical to have forward security such that when an adversary compromises a machine, she cannot modify or forge the log entries accumulated before the compromise. Unfortunately, existing secure audit logging schemes have significant limitations that make them impractical for real-life applications: existing public key cryptography (PKC) based schemes are computationally expensive for logging in task intensive or resource-constrained systems, while existing symmetric schemes are not publicly verifiable and incur significant storage and communication overheads. In this paper, we propose a novel forward secure and aggregate logging scheme called blind-aggregate-forward (BAF) logging scheme, which is suitable for large distributed systems. BAF can produce publicly verifiable forward secure and aggregate signatures with near-zero computational, storage, and communication costs for the loggers, without requiring any online trusted third party (TTP) support. We prove that BAF is secure under appropriate computational assumptions, and demonstrate that BAF is significantly more efficient and scalable than the previous schemes. Therefore, BAF is an ideal solution for secure logging in both task intensive and resource-constrained systems.
Attila A. Yavuz, Peng Ning
ACSAC1
2009 Hash-Based Sequential Aggregate and Forward Secure Signature for Unattended Wireless Sensor Networks
abstract
Unattended Wireless Sensor Networks (UWSNs) operating in hostile environments face great security and performance challenges due to the lack of continuous real-time communication between senders (sensors) and receivers (e.g., mobile data collectors, static sinks). The lack of real-time communication
Attila A. Yavuz, Peng Ning
MobiQuitous1
2006 NAMEPS: N -Tier Satellite Multicast Security Protocol Based on Signcryption Schemes
abstract
In this paper, we propose a new N-tier sAtellite Multicast sEcurity Protocol based on multi-recipient Signcryption schemes (NAMEPS). Our protocol is especially designed for very large and highly dynamic satellite multicast systems which require high security and reliability. Our N-tier architecture significantly reduces workload of the satellite layers especially for bandwidth consumption, computation resources and storage requirements. N-tier approach localizes effects of the rekeying operation (forward-backward security) and provides significant performance gain. Moreover, batch keying and ticketing mechanisms are used which additionally reduce workload of the satellite and terrestrial layers. Also, as a novel approach for cryptographic method, our protocol uses multi-recipient signcryption scheme, which provides confidentiality, authentication, unforgeability and non-repudiation together, more efficiently than classical sign-then-encrypt approaches. As a result, NAMEPS has many advantages for very large, dynamic and security critic satellite multicast systems.
Attila A. Yavuz, Fatih Alagöz, Emin Anarim
GLOBECOM1