Haowen Chan

dblp:97/4228 · DBLP profile ↗
← Back
12ranked-venue papers
9as first author
0since 2021 · last 2011
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 6 first-authorComputer networks · 3 · 2 first-authorDatabases, data management, data science and information retrieval · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Computer networks
10 papers
Internet of things and sensor networks · 77% Software-defined and programmable networks · 13% Routing and switching · 6%
Network and information security
9 papers
Cryptographic protocols and secure computation · 68% Authentication and access control · 21% Cryptographic primitives and cryptanalysis · 8%

Topics — the 18 heaviest of 22, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Internet of things and sensor networks
sensor network security
0.472010
Round-Efficient Broadcast Authentication Protocols for Fixed Topology Classes · IEEE Symposium on Security and Privacy 2010
Secure hierarchical in-network aggregation in sensor networks · CCS 2006
On the Distribution and Revocation of Cryptographic Keys in Sensor Networks · IEEE Trans. Dependable Secur. Comput. 2005
Internet of things and sensor networks › sensor network security
key distribution
0.232010
Round-Efficient Broadcast Authentication Protocols for Fixed Topology Classes · IEEE Symposium on Security and Privacy 2010
PIKE: peer intermediaries for key establishment in sensor networks · INFOCOM 2005
Key Infection: Smart Trust for Smart Dust · ICNP 2004
Authentication and access control › authentication
broadcast authentication
0.222010
Round-Efficient Broadcast Authentication Protocols for Fixed Topology Classes · IEEE Symposium on Security and Privacy 2010
Efficient security primitives derived from a secure aggregation algorithm · CCS 2008
Cryptographic protocols and secure computation
secure aggregation
0.122008
Efficient security primitives derived from a secure aggregation algorithm · CCS 2008
Secure hierarchical in-network aggregation in sensor networks · CCS 2006
Cryptographic protocols and secure computation
key exchange
0.132005
PIKE: peer intermediaries for key establishment in sensor networks · INFOCOM 2005
Key Infection: Smart Trust for Smart Dust · ICNP 2004
Random Key Predistribution Schemes for Sensor Networks · S&P 2003
Cryptographic protocols and secure computation
key management
0.122008
Efficient security primitives derived from a secure aggregation algorithm · CCS 2008
On the Distribution and Revocation of Cryptographic Keys in Sensor Networks · IEEE Trans. Dependable Secur. Comput. 2005
Software-defined and programmable networks
path control
0.112011
SCION: Scalability, Control, and Isolation on Next-Generation Networks · IEEE Symposium on Security and Privacy 2011
Cryptographic protocols and secure computation › secure multiparty computation
round complexity
0.112010
Round-Efficient Broadcast Authentication Protocols for Fixed Topology Classes · IEEE Symposium on Security and Privacy 2010
Routing and switching › inter-domain routing
inter-domain routing security
0.112006
Modeling adoptability of secure BGP protocol · SIGCOMM 2006
Internet of things and sensor networks › wireless sensor network › in-network aggregation
secure in-network aggregation
0.112006
Secure hierarchical in-network aggregation in sensor networks · CCS 2006
Internet of things and sensor networks › wireless sensor network › key management
key predistribution
0.012003
Random Key Predistribution Schemes for Sensor Networks · S&P 2003
Cryptographic primitives and cryptanalysis › key generation
random key predistribution
0.012003
Random Key Predistribution Schemes for Sensor Networks · S&P 2003
Internet of things and sensor networks › sensor data management
sensor data collection
0.012009
Secure outsourced aggregation via one-way chains · SIGMOD Conference 2009
Cryptographic primitives and cryptanalysis › one-way functions
one-way function chain
0.012009
Secure outsourced aggregation via one-way chains · SIGMOD Conference 2009
Distributed systems › fault tolerance
byzantine fault tolerance
0.012006
Secure hierarchical in-network aggregation in sensor networks · CCS 2006
Distributed systems
fault tolerance
0.012006
Secure hierarchical in-network aggregation in sensor networks · CCS 2006
Cellular and mobile networks
self-organizing networks
0.012004
Key Infection: Smart Trust for Smart Dust · ICNP 2004
Internet of things and sensor networks
wireless sensor network
0.012004
Key Infection: Smart Trust for Smart Dust · ICNP 2004

Methods — techniques the papers use, named apart from their topics

protocol design · 0.4lower bound proof · 0.3symmetric-key cryptography · 0.3security analysis · 0.2verification protocol · 0.2commitment scheme · 0.2functional decomposition · 0.2simulation · 0.1attacker model analysis · 0.1game-theoretic adoption model · 0.1multipath secrecy amplification · 0.0multihop key propagation · 0.0
YearPublicationVenuePosition
2011 SCION: Scalability, Control, and Isolation on Next-Generation Networks
abstract
We present the first Internet architecture designed to provide route control, failure isolation, and explicit trust information for end-to-end communications. SCION separates ASes into groups of independent routing sub-planes, called trust domains, which then interconnect to form complete routes. Trust domains provide natural isolation of routing failures and human misconfiguration, give endpoints strong control for both inbound and outbound traffic, provide meaningful and enforceable trust, and enable scalable routing updates with high path freshness. As a result, our architecture provides strong resilience and security properties as an intrinsic consequence of good design principles, avoiding piecemeal add-on protocols as security patches. Meanwhile, SCION only assumes that a few top-tier ISPs in the trust domain are trusted for providing reliable end-to-end communications, thus achieving a small Trusted Computing Base. Both our security analysis and evaluation results show that SCION naturally prevents numerous attacks and provides a high level of resilience, scalability, control, and isolation.
Xin Zhang 0003, Hsu-Chun Hsiao, Geoffrey Hasker, Haowen Chan, Adrian Perrig, David G. Andersen
IEEE Symposium on Security and Privacy4
2010 Round-Efficient Broadcast Authentication Protocols for Fixed Topology Classes
abstract
We consider resource-constrained broadcast authentication for n receivers in a static, known network topology. There are only two known broadcast authentication protocols that do not use asymmetric cryptography, one-time signatures, multi-receiver MACs, or time synchronization. Both these protocols require three passes of a message front traversing the network. We investigate whether this amount of interaction can be improved efficiently for specific common topology classes, namely, linear topologies, tree topologies and fully connected topologies. We show modifications to the protocols allowing them to complete in just two passes in the linear and fully connected cases with a small constant factor increase in per-node communication overhead, and a further optimization that achieves the equivalent of just a single pass in the linear case with O(log n) increase in per-node communication overhead. We also prove new lower bounds for round complexity, or the maximum number of consecutive interactions in a protocol. We show that protocols with efficient per-node communication overhead (polylogarithmic in n) must require at least 2 log n rounds in any topology; this implies that our two-pass protocol in the fully-connected topology requires the fewest possible passes, and this bound is asymptotically tight for the full-duplex communication model. Furthermore, we show that communication-efficient protocols must take asymptotically more than 2 log n rounds on trees; this implies that that there are some tree topologies for which two passes do not suffice and the existing three-pass algorithms may be optimal.
Haowen Chan, Adrian Perrig
IEEE Symposium on Security and Privacy1
2009 Secure outsourced aggregation via one-way chains
abstract
We consider the Outsourced Aggregation model, where sensing services outsource their sensor data collection and aggregation tasks to third-party service providers called aggregators. As aggregators can be untrusted or compromised, it is essential for a sensing service to be able to verify the correctness of aggregation results. This work presents SECOA, a framework with a family of novel and optimally-secure protocols for secure outsourced aggregation. Our framework is based on a unified use of one-way chains. It supports a large and diverse set of aggregate functions, can have multiple hierarchically organized aggregators, can deterministically detect any malicious aggregation behavior without communication with sensors, and incurs a small and workload-independent communication load on sensors. We also present extensive evaluation results to demonstrate the feasibility of our framework.
Suman Nath, Haowen Chan
SIGMOD Conference3
2008 Efficient security primitives derived from a secure aggregation algorithm
abstract
By functionally decomposing a specific algorithm (the hierarchical secure aggregation algorithm of Chan et al. [3] and Frikken et al. [7]), we uncover a useful general functionality which we use to generate various efficient network security primitives, including: a signature scheme ensuring authenticity, integrity and non-repudiation for arbitrary node-to-node communications; an efficient broadcast authentication algorithm not requiring time synchronization; a scheme for managing public keys in a sensor network without requiring any asymmetric cryptographic operations to verify the validity of public keys, and without requiring nodes to maintain node revocation lists. Each of these applications uses the same basic data aggregation primitive and thus have O(log n) congestion performance and require only that symmetric secret keys are shared between each node and the base station. We thus observe the fact that the optimizations developed in the application area of secure aggregation can feed back into creating more optimized versions of highly general, basic security functions.
Haowen Chan, Adrian Perrig
CCS1
2007 SIA: Secure information aggregation in sensor networks
abstract
In sensor networks, data aggregation is a vital primitive enabling efficient data queries. An on-site aggregator device collects data from sensor nodes and produces a condensed summary which is forwarded to the off-site querier, thus reducing the communication cost of the query. Since the aggregato r is on-site, it is vulnerable to physical compromise attacks. A compromised aggregator may report false aggregation results. Hence, it is essential that techniques are available to allow the querier to verify the integrity of the result returned by the aggregator node. We propose a novel framework for secure information aggregation in sensor networks. By constructing efficient random sampling mechanisms and interactive proofs, we enable the querier to verify that the answer given by the aggregator is a good approximation of the true value, even when the aggregator and a fraction of the sensor nodes are corrupted. In particular, we present efficient protocols for secure computation of the median and average of the measurements, for the estimation of the network size, for finding the minimum and maximum sensor reading, and for random sampling and leader election. Our protocols require only sublinear communication between the aggregator and the user.
Haowen Chan, Adrian Perrig, Bartosz Przydatek, Dawn Song
J. Comput. Secur.1
2006 Secure hierarchical in-network aggregation in sensor networks
abstract
In-network aggregation is an essential primitive for performing queries on sensor network data. However, most aggregation algorithms assume that all intermediate nodes are trusted. In contrast, the standard threat model in sensor network security assumes that an attacker may control a fraction of the nodes, which may misbehave in an arbitrary (Byzantine) manner.We present the first algorithm for provably secure hierarchical in-network data aggregation. Our algorithm is guaranteed to detect any manipulation of the aggregate by the adversary beyond what is achievable through direct injection of data values at compromised nodes. In other words, the adversary can never gain any advantage from misrepresenting intermediate aggregation computations. Our algorithm incurs only O(Δ log2 n) node congestion, supports arbitrary tree-based aggregator topologies and retains its resistance against aggregation manipulation in the presence of arbitrary numbers of malicious nodes. The main algorithm is based on performing the sum aggregation securely by first forcing the adversary to commit to its choice of intermediate aggregation results, and then having the sensor nodes independently verify that their contributions to the aggregate are correctly incorporated. We show how to reduce secure median, count, and average to this primitive.
Haowen Chan, Adrian Perrig, Dawn Song
CCS1
2006 Modeling adoptability of secure BGP protocol
abstract
Despite the existence of several secure BGP routing protocols, there has been little progress to date on actual adoption. Although feasibility for widespread adoption remains the greatest hurdle for BGP security, there has been little quantitative research into what properties contribute the most to the adoptability of a security scheme. In this paper, we provide a model for assessing the adoptability of a secure BGP routing protocol. We perform this evaluation by simulating incentives compatible adoption decisions of ISPs on the Internet under a variety of assumptions. Our results include: (a) the existence of a sharp threshold, where, if the cost of adoption is below the threshold, complete adoption takes place, while almost no adoption takes place above the threshold; (b) under a strong attacker model, adding a single hop of path authentication to origin authentication yields similar adoptability characteristics as a full path security scheme; (c) under a weaker attacker model, adding full path authentication (e.g., via S-BGP [9]) significantly improves the adoptability of BGP security over weaker path security schemes such as soBGP [16]. These results provide insight into the development of more adoptable secure BGP protocols and demonstrate the importance of studying adoptability of protocols.
Haowen Chan, Debabrata Dash, Adrian Perrig, Hui Zhang 0001
SIGCOMM1
2005 Using Clustering Information for Sensor Network Localization
Haowen Chan, Mark Luk, Adrian Perrig
DCOSS1
2005 PIKE: peer intermediaries for key establishment in sensor networks
abstract
The establishment of shared cryptographic keys between communicating neighbor nodes in sensor networks is a challenging problem due to the unsuitability of asymmetric key cryptography for these resource-constrained platforms. A range of symmetric-key distribution protocols exist, but these protocols do not scale effectively to large sensor networks. For a given level of security, each protocol incurs a linearly increasing overhead in either communication cost per node or memory per node. We describe peer intermediaries for key establishment (PIKE), a class of key-establishment protocols that involves using one or more sensor nodes as a trusted intermediary to facilitate key establishment. We show that, unlike existing key-establishment protocols, both the communication and memory overheads of PIKE protocols scale sub-linearly (O(/spl radic/n)) with the number of nodes in the network yet achieving higher security against node compromise than other protocols.
Haowen Chan, Adrian Perrig
INFOCOM1
2005 On the Distribution and Revocation of Cryptographic Keys in Sensor Networks
abstract
Key management has two important aspects: key distribution, which describes how to disseminate secret information to the principals so that secure communications can be initiated, and key revocation, which describes how to remove secrets that may have been compromised. Key management in sensor networks face constraints of large scale, lack of a priori information about deployment topology, and limitations of sensor node hardware. While key distribution has been studied extensively in recent works, the problem of key and node revocation in sensor networks has received relatively little attention. Yet, revocation protocols that function correctly in the presence of active adversaries pretending to be legitimate protocol participants via compromised sensor nodes are essential. In their absence, an adversary could take control of the sensor network's operation by using compromised nodes which retain their network connectivity for extended periods of time. In this paper, we present an overview of key-distribution methods in sensor networks and their salient features to provide context for understanding key and node revocation. Then, we define basic properties that distributed sensor-node revocation protocols must satisfy and present a protocol for distributed node revocation that satisfies these properties under general assumptions and a standard attacker model.
Haowen Chan, Virgil D. Gligor, Adrian Perrig, Gautam Muralidharan
IEEE Trans. Dependable Secur. Comput.1
2004 Key Infection: Smart Trust for Smart Dust
abstract
Future distributed systems may include large self-organizing networks of locally communicating sensor nodes, any small number of which may be subvened by an adversary. Providing security for these sensor networks is important, but the problem is complicated by the fact that managing cryptographic key material is hard: low-cost nodes are neither tamper-proof nor capable of performing public key cryptography efficiently. We show how the key distribution problem can be dealt with in environments with a partially present, passive adversary: a node wishing to communicate securely with other nodes simply generates a symmetric key and sends it in the clear to its neighbours. Despite the apparent insecurity of this primitive, we can use mechanisms for key updating, multipath secrecy amplification and multihop key propagation to build up extremely resilient trust networks where at most a fixed proportion of communications links can be eavesdropped. We discuss applications in which this assumption is sensible. Many systems must perforce cope with principals who are authenticated weakly, if at all; the resulting issues have often been left in the 'too hard' tray. One particular interest of sensor networks is that they present a sufficiently compact and tractable version of this problem. We can perform quantitative analyses and simulations of alternative strategies, some of which we present here. We also hope that This work may start to challenge the common belief that authentication is substantially about bootstrapping trust. We argue that, in distributed systems where the opponent can subvert any small proportion of nodes, it is more economic to invest in resilience than in bootstrapping.
Ross J. Anderson, Haowen Chan, Adrian Perrig
ICNP2
2003 Random Key Predistribution Schemes for Sensor Networks
abstract
Key establishment in sensor networks is a challenging problem because asymmetric key cryptosystems are unsuitable for use in resource constrained sensor nodes, and also because the nodes could be physically compromised by an adversary. We present three new mechanisms for key establishment using the framework of pre-distributing a random set of keys to each node. First, in the q-composite keys scheme, we trade off the unlikeliness of a large-scale network attack in order to significantly strengthen random key predistribution's strength against smaller-scale attacks. Second, in the multipath-reinforcement scheme, we show how to strengthen the security between any two nodes by leveraging the security of other links. Finally, we present the random-pairwise keys scheme, which perfectly preserves the secrecy of the rest of the network when any node is captured, and also enables node-to-node authentication and quorum-based revocation.
Haowen Chan, Adrian Perrig, Dawn Song
S&P1