Colin Boyd

dblp:b/ColinBoyd · DBLP profile ↗
← Back
116ranked-venue papers
33as first author
8since 2021 · last 2025
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 96 · 29 first-author · 5 since 2021Computer networks · 6 · 3 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 3 · 1 since 2021Systems, architecture and hardware · 2Artificial intelligence and machine learning · 1Graphics, computer vision, multimedia, augmented reality and games · 1Human-computer interaction and ubiquitous computing · 1Theory of computation · 1
YearPublicationVenuePosition
2025 TEAKEX: TESLA-Authenticated Group Key Exchange
Qinyi Li, Lise Millerjord, Colin Boyd
ACISP (1)3
2025 SafeLib: A Comprehensive Framework for Secure Outsourcing of Network Functions
abstract
Outsourcing virtual network functions (VNFs) to third-party service providers, such as public clouds, has become the norm. While outsourcing brings many benefits, including scalability, streamlined management, and lower CapEx, it also introduces security concerns. Owing to the lack of trust in the cloud, organizations may opt to shield both their network functions and the traffic flowing through them. Existing outsourcing mechanisms, however, fall short of the functionality, security, and/or performance requirements. This paper presents SafeLib, a comprehensive, Intel SGX based, open-source, secure network function outsourcing framework. To the best of our knowledge, SafeLib is the first trusted hardware based solution providing i) support for both stateful and stateless virtual NFs, ii) strong security properties with regard to both user traffic and VNF execution, state, policies, and code, iii) high performance, iv) enhanced usability for VNF developers and v) flexibility in choosing the network stack by providing support for both kernel and kernel-bypass mechanisms. We corroborate our performance claims through an extensive testbed evaluation. In addition, we provide insights on the performance penalty of major SGX limitations and also refute the popular belief that using a library OS within an SGX enclave necessarily reduces performance. We believe that SafeLib provides a flexible and performant tool with strong security guarantees for building secure, carrier-grade cloud-based services.
Enio Marku, Colin Boyd, Gergely Biczók
IEEE Trans. Netw. Serv. Manag.2
2023 Modular Design of KEM-Based Authenticated Key Exchange
Colin Boyd, Bor de Kock, Lise Millerjord
ACISP1
2023 Hybrid Group Key Exchange with Application to Constrained Networks
Colin Boyd, Elsie Mestl Fondevik, Kristian Gjøsteen, Lise Millerjord
ISC1
2021 Symmetric Key Exchange with Full Forward Security and Robust Synchronization
Colin Boyd, Gareth T. Davies, Bor de Kock, Kai Gellert, Tibor Jager, Lise Millerjord
ASIACRYPT (4)1
2021 SafeLib: a practical library for outsourcing stateful network functions securely
abstract
A recent trend is to outsource virtual network functions (VNFs) to a third-party service provider, such as a public cloud. Since the cloud is usually not trusted, redirecting enterprise traffic to such an entity introduces security concerns. In addition to protecting enterprise traffic, it is also desirable to protect VNF code, policies and states. Existing outsourcing solutions fall short in either supporting stateful VNFs, catering for all security requirements, or providing adequate performance.In this paper we present SafeLib, a trusted hardware based outsourcing solution built on Intel SGX. SafeLib provides i) support for stateful VNFs, ii) support for illegal SGX instructions by integrating Graphene-SGX, iii) protection of both packet headers and payload for enterprise user traffic, VNF policies and VNF code, and iv) integration of libVNF for streamlined VNF development. Our performance evaluation shows that SafeLib scales properly for multiple cores, and introduces a reasonable performance overhead. We also outline plans to further improve SafeLib to satisfy even more stringent functional, security and performance requirements.
Enio Marku, Gergely Biczók, Colin Boyd
NetSoft3
2021 A Modern View on Forward Security
abstract
Abstract Forward security ensures that compromise of entities today does not impact the security of cryptographic primitives employed in the past. Such a form of security is regarded as increasingly important in the modern world due to the existence of adversaries with mass storage capabilities and powerful infiltration abilities. Although the idea of forward security has been known for over 30 years, current understanding of what it really should mean is limited due to the prevalence of new techniques and inconsistent terminology. We survey existing methods for achieving forward security for different cryptographic primitives and propose new definitions and terminology aimed at a unified treatment of the notion.
Colin Boyd, Kai Gellert
Comput. J.1
2021 Introduction to the Special Issue on TLS 1.3
abstract
The Transport Layer Security (TLS) protocol is known as one of the most important and widely-used security protocols.It emerged in the 1990s from the proprietary SSL protocol, originally designed for securing web traffic in the Netscape browser.Since its first version the TLS protocol has seen a series of evolutions and a great deal of scrutiny from both cryptographers and security practitioners.As well as remaining the standard method to protect channels between web browsers and servers, TLS is now widely used to secure many other network services.The latest version of the TLS protocol, TLS 1.3, was published as an Internet Proposed Standard in 2018 [3].Development of the standard progressed in a way that differed from earlier TLS versions, in what Paterson and van der Merwe [2] call a proactive process in contrast to a reactive process.What they mean by this is that TLS 1.3 was developed in cooperation with the academic community, employing formal models to obtain high assurance of security before the standard was published.Earlier updates to the standard were mainly focussed on fixing security problems that had been discovered after publication.It is something of a paradox that as technology advances, providing us with ever increasing computational capabilities, the demand for more efficient protocols increases as well.Thus, in addition to providing a scientific basis for security, a driving goal for the TLS 1.3 standard was to improve efficiency of the protocol in a number of ways.These ways included measures such as simplifying the negotiation of protocol versions and cipher suites, reducing the number of handshake messages, and allowing faster resumption of previously used channels.Three of the five papers in this special issue on TLS 1.3 are concerned with security analysis of the published standard.-A Cryptographic Analysis of the TLS 1.3 Handshake Protocol by Dowling et al.,gives us proofs that the handshake protocol is secure in a computational model based on the well-established cryptographic security models for authenticated key exchange which emerged in the 1990s, starting with Bellare and Rogaway [1].
Colin Boyd
J. Cryptol.1
2020 Fast and Secure Updatable Encryption
Colin Boyd, Gareth T. Davies, Kristian Gjøsteen, Yao Jiang Galteland
CRYPTO (1)1
2020 Special Issue on Cryptographic Currency and Blockchain Technology
Man Ho Au, Jinguang Han, Qianhong Wu, Colin Boyd
Future Gener. Comput. Syst.4
2019 Towards protected VNFs for multi-operator service delivery
abstract
Value-added 5G verticals are foreseen to be delivered as a service chain over multiple network operators with extensive outsourcing of Virtual Network Functions (VNFs). In this short paper we introduce the initial design of SafeLib, a software middlebox platform based on Intel SGX, which protects user traffic, VNF code, policy input and state in such scenarios, while also retaining high performance. Augmenting the smart integration of existing hardware and software building blocks with new secure elements, the SafeLib architecture shows considerable promise in a carrier-grade service context.
Enio Marku, Gergely Biczók, Colin Boyd
NetSoft3
2018 Definitions for Plaintext-Existence Hiding in Cloud Storage
abstract
Cloud storage services use deduplication for saving bandwidth and storage. An adversary can exploit side-channel information in several attack scenarios when deduplication takes place at the client side, leaking information on whether a specific plaintext exists in the cloud storage. Generalising existing security definitions, we introduce formal security games for a number of possible adversaries in this domain, and show that games representing all natural adversarial behaviors are in fact equivalent. These results allow users and practitioners alike to accurately assess the vulnerability of deployed systems to this real-world concern.
Colin Boyd, Gareth T. Davies, Kristian Gjøsteen, Håvard Raddum, Mohsen Toorani
ARES1
2018 Offline Assisted Group Key Exchange
Colin Boyd, Gareth T. Davies, Kristian Gjøsteen, Yao Jiang Galteland
ISC1
2018 Security Notions for Cloud Storage and Deduplication
Colin Boyd, Gareth T. Davies, Kristian Gjøsteen, Håvard Raddum, Mohsen Toorani
ProvSec1
2017 Side Channels in Deduplication: Trade-offs between Leakage and Efficiency
abstract
Deduplication removes redundant copies of files or data blocks stored on the cloud. Client-side deduplication, where the client only uploads the file upon the request of the server, provides major storage and bandwidth savings, but introduces a number of security concerns. Harnik et al. (2010) showed how cross-user client-side deduplication inherently gives the adversary access to a (noisy) side-channel that may divulge whether or not a particular file is stored on the server, leading to leakage of user information. We provide formal definitions for deduplication strategies and their security in terms of adversarial advantage. Using these definitions, we provide a criterion for designing good strategies and then prove a bound characterizing the necessary trade-off between security and efficiency.
Frederik Armknecht, Colin Boyd, Gareth T. Davies, Kristian Gjøsteen, Mohsen Toorani
AsiaCCS2
2017 Security Proofs for Protocols Involving Humans
abstract
We introduce the notion of human-followable security wherein a human user can understand the process and logic behind cryptographic authentication protocols. We use Transport Layer Security, a widely used protocol, as an example to explain why human-followable security is required. From there, we define the notion of human-perceptible freshness and build on recent work by Jager et al. to provide a protocol security model incorporating this notion. We show how to transform existing authentication protocols into protocols with human-followable security and prove that this transformation turns protocols secure in the sense of Jager et al. into protocols secure in our extended model.
Kenneth Radke, Colin Boyd
Comput. J.2
2016 Fair Client Puzzles from the Bitcoin Blockchain
Colin Boyd, Christopher Carr
ACISP (1)1
2016 From Stateless to Stateful: Generic Authentication and Authenticated Encryption Constructions with Application to TLS
Colin Boyd, Britta Hale, Stig Fr. Mjølsnes, Douglas Stebila
CT-RSA1
2016 Private VNFs for collaborative multi-operator service delivery: An architectural case
abstract
Flexible service delivery is a key requirement for 5G network architectures. This includes the support for collaborative service delivery by multiple operators, when an individual operator lacks the geographical footprint or the available network, compute or storage resources to provide the requested service to its customer. Network Function Virtualisation is a key enabler of such service delivery, as network functions (VNFs) can be outsourced to other operators. Owing to the (partial lack of) contractual relationships and co-opetition in the ecosystem, the privacy of user data, operator policy and even VNF code could be compromised. In this paper, we present a case for privacy in a VNF-enabled collaborative service delivery architecture. Specifically, we show the promise of homomorphic encryption (HE) in this context and its performance limitations through a proof of concept implementation of an image transcoder network function. Furthermore, inspired by application-specific encryption techniques, we propose a way forward for private, payload-intensive VNFs.
Gergely Biczók, Balázs Sonkoly, Nikolett Bereczky, Colin Boyd
NOMS4
2016 Modelling attacks on self-authentication watermarking
Hussain Nyeem, Wageeh W. Boles, Colin Boyd
Multim. Tools Appl.3
2015 Continuous After-the-Fact Leakage-Resilient eCK-Secure Key Exchange
Janaka Alawatugoda 0001, Douglas Stebila, Colin Boyd
IMACC3
2015 CHURNs: Freshness Assurance for Humans
abstract
We present CHURNs, a method for providing freshness and authentication assurances to human users. In computer-to-computer protocols, it has long been accepted that assurances of freshness such as random nonces are required to prevent replay attacks. Typically, no such assurance of freshness is presented to a human in a human-and-computer protocol. A Computer–HUman Recognisable Nonce (CHURN) is a computer-aided random sequence that the human has a measure of control over and input into. Our approach overcomes limitations such as ‘humans cannot do random’ and that humans will follow the easiest path. Our findings show that CHURNs are significantly more random than values produced by unaided humans; that humans may be used as a second source of randomness, and we give measurements as to how much randomness can be gained from humans using our approach; and that our CHURN-generator makes the user feel more in control, thus removing the need for complete trust in devices and underlying protocols. We give an example of how a CHURN may be used to provide assurances of freshness and authentication for humans in a widely used protocol.
Kenneth Radke, Colin Boyd, Juan Manuel González Nieto, Harry Bartlett
Comput. J.2
2015 Identity-based proxy signatures: a generic construction and a concrete scheme from RSA
abstract
Abstract Proxy signatures allow an entity to delegate its signing capability to a proxy which can sign messages on behalf of the delegator. We examine identity‐based versions of proxy signatures which employ identity strings in place of randomly generated public keys. First, we give a new generic construction of identity‐based proxy signatures from identity‐based standard signatures and show that our generic construction is secure if the underlying identity‐based standard signature is secure. In addition, we present the first identity‐based proxy signature from Rivest, Shamir and Adleman (RSA), secure under the one‐wayness of RSA in the random oracle model. We should highlight that the proxy key exposure attack cannot be applied to our proposed constructions. Copyright © 2015 John Wiley & Sons, Ltd.
Maryam Rajabzadeh Asaar, Mahmoud Salmasizadeh, Colin Boyd
Secur. Commun. Networks3
2014 Continuous After-the-Fact Leakage-Resilient Key Exchange
Janaka Alawatugoda 0001, Colin Boyd, Douglas Stebila
ACISP2
2014 Modelling after-the-fact leakage for key exchange
abstract
Security models for two-party authenticated key exchange (AKE) protocols have developed over time to prove the security of AKE protocols even when the adversary learns certain secret values. In this work, we address more granular leakage: partial leakage of long-term secrets of protocol principals, even after the session key is established. We introduce a generic key exchange security model, which can be instantiated allowing bounded or continuous leakage, even when the adversary learns certain ephemeral secrets or session keys. Our model is the strongest known partial-leakage-based security model for key exchange protocols. We propose a generic construction of a two-pass leakage-resilient key exchange protocol that is secure in the proposed model, by introducing a new concept: the leakage-resilient NAXOS trick. We identify a special property for public-key cryptosystems: pair generation indistinguishability, and show how to obtain the leakage-resilient NAXOS trick from a pair generation indistinguishable leakage-resilient public-key cryptosystem.
Janaka Alawatugoda 0001, Douglas Stebila, Colin Boyd
AsiaCCS3
2014 Automated Proofs for Computational Indistinguishability
abstract
We present a tool for automatic analysis of computational indistinguishability between two strings of information. This is designed as a generic tool for proving cryptographic security based on a formalism that provides computational soundness preservation. The tool has been implemented and tested successfully with several cryptographic schemes.
Long Ngo, Colin Boyd, Juan Manuel González Nieto
Comput. J.2
2013 ASICS: Authenticated Key Exchange Security Incorporating Certification Systems
Colin Boyd, Cas Cremers, Michèle Feltz, Kenneth G. Paterson, Bertram Poettering, Douglas Stebila
ESORICS1
2013 Counterfeiting attacks on block-wise dependent fragile watermarking schemes
abstract
In this paper, we present three counterfeiting attacks on the block-wise dependent fragile watermarking schemes. We consider vulnerabilities such as the exploitation of a weak correlation among block-wise dependent watermarks to modify valid watermarked images, where they could still be verified as authentic, though they are actually not. Experimental results successfully demonstrate the practicability and consequences of the proposed attacks for some relevant schemes. The development of the proposed attack models can be used as a means to systematically examine the security levels of similar watermarking schemes.
Hussain Nyeem, Wageeh W. Boles, Colin Boyd
SIN3
2013 Predicate encryption for multi-inner-products
abstract
ABSTRACT Predicate encryption is a new primitive that supports flexible control over access to encrypted data. We study predicate encryption systems, evaluating a wide class of predicates. Our systems are more expressive than the existing attribute‐hiding systems in the sense that the proposed constructions support not only all existing predicate evaluations but also arbitrary conjunctions and disjunctions of comparison and subset queries. Toward our goal, we propose encryption schemes supporting multi‐inner‐product predicate and provide formal security analysis. We show how to apply the proposed schemes to achieve all those predicate evaluations. Copyright © 2012 John Wiley & Sons, Ltd.
Dongdong Sun, Colin Boyd, Juan Manuel González Nieto
Secur. Commun. Networks2
2012 Minimizing Information Leakage of Tree-Based RFID Authentication Protocols Using Alternate Tree-Walking
Kaleb Lee, Colin Boyd, Juan Manuel González Nieto
ACISP2
2012 Effort-Release Public-Key Encryption from Cryptographic Puzzles
Jothi Rangasamy, Douglas Stebila, Colin Boyd, Juan Manuel González Nieto, Lakshmi Kuppusamy
ACISP3
2012 Practical client puzzles in the standard model
abstract
Client puzzles are cryptographic problems that are neither easy nor hard to solve. In this paper, we solve the problem of constructing cryptographic puzzles that are secure in the standard model and are very efficient. To prove the security of our puzzle, we introduce a new variant of the interval discrete logarithm assumption which may be of independent interest, and show this new problem to be hard under reasonable assumptions. Our experimental results show that, for 512-bit modulus, the solution verification time of our proposed puzzle can be up to 50x and 89x faster than that of the existing puzzles.
Lakshmi Kuppusamy, Jothi Rangasamy, Douglas Stebila, Colin Boyd, Juan Manuel González Nieto
AsiaCCS4
2011 An integrated approach to cryptographic mitigation of denial-of-service attacks
abstract
Gradual authentication is a principle proposed by Meadows as a way to tackle denial-of-service attacks on network protocols by gradually increasing the confidence in clients before the server commits resources. In this paper, we propose an efficient method that allows a defending server to authenticate its clients gradually with the help of some fast-to-verify measures. Our method integrates hash-based client puzzles along with a special class of digital signatures supporting fast verification. Our hash-based client puzzle provides finer granularity of difficulty and is proven secure in the puzzle difficulty model of Chen et al. (2009). We integrate this with the fast-verification digital signature scheme proposed by Bernstein (2000, 2008). These schemes can be up to 20 times faster for client authentication compared to RSA-based schemes. Our experimental results show that, in the Secure Sockets Layer (SSL) protocol, fast verification digital signatures can provide a 7% increase in connections per second compared to RSA signatures, and our integration of client puzzles with client authentication imposes no performance penalty on the server since puzzle verification is a part of signature verification.
Jothi Rangasamy, Douglas Stebila, Colin Boyd, Juan Manuel González Nieto
AsiaCCS3
2011 Automated Proofs for Diffie-Hellman-Based Key Exchanges
abstract
We present an automated verification method for security of Diffie-Hellman-based key exchange protocols. The method includes a Hoare-style logic and syntactic checking. The method is applied to protocols in a simplified version of the Bellare-Rogaway-Pointcheval model (2000). The security of the protocol in the complete model can be established automatically by a modular proof technique of Kudla and Paterson (2005).
Long Ngo, Colin Boyd, Juan Manuel González Nieto
CSF2
2011 Stronger Difficulty Notions for Client Puzzles and Denial-of-Service-Resistant Protocols
Douglas Stebila, Lakshmi Kuppusamy, Jothi Rangasamy, Colin Boyd, Juan Manuel González Nieto
CT-RSA4
2011 On Forward Secrecy in One-Round Key Exchange
Colin Boyd, Juan Manuel González Nieto
IMACC1
2011 Tensions in Developing a Secure Collective Information Practice - The Case of Agile Ridesharing
Kenneth Radke, Margot Brereton, Seyed Hadi Mirisaee, Sunil Ghelawat, Colin Boyd, Juan Manuel González Nieto
INTERACT (2)5
2011 User-representative feature selection for keystroke dynamics
abstract
Continuous user authentication with keystroke dynamics uses characters sequences as features. Since users can type characters in any order, it is imperative to find character sequences (n-graphs) that are representative of user typing behavior. The contemporary feature selection approaches do not guarantee selecting frequently-typed features which may cause less accurate statistical user-representation. Furthermore, the selected features do not inherently reflect user typing behavior. We propose four statistical-based feature selection techniques that mitigate limitations of existing approaches. The first technique selects the most frequently occurring features. The other three consider different user typing behaviors by selecting: n-graphs that are typed quickly; n-graphs that are typed with consistent time; and n-graphs that have large time variance among users. We use Gunetti's keystroke dataset and k-means clustering algorithm for our experiments. The results show that among the proposed techniques, the most-frequent feature selection technique can effectively find user-representative features. We further substantiate our results by comparing the most-frequent feature selection technique with three existing approaches (popular Italian words, common n-graphs, and least frequent n-graphs). We find that it performs better than the existing approaches after selecting a certain number of most-frequent n-graphs.
Eesa Alsolami, Colin Boyd, Andrew J. Clark, Irfan Ahmed 0001
NSS2
2011 Ceremony Analysis: Strengths and Weaknesses
Kenneth Radke, Colin Boyd, Juan Manuel González Nieto, Margot Brereton
SEC2
2011 Modeling key compromise impersonation attacks on group key exchange protocols
abstract
Two-party key exchange (2PKE) protocols have been rigorously analyzed under various models considering different adversarial actions. However, the analysis of group key exchange (GKE) protocols has not been as extensive as that of 2PKE protocols. Particularly, an important security attribute called key compromise impersonation (KCI) resilience has been completely ignored for the case of GKE protocols. Informally, a protocol is said to provide KCI resilience if the compromise of the long-term secret key of a protocol participant A does not allow the adversary to impersonate an honest participant B to A . In this paper, we argue that KCI resilience for GKE protocols is at least as important as it is for 2PKE protocols. Our first contribution is revised definitions of security for GKE protocols considering KCI attacks by both outsider and insider adversaries. We also give a new proof of security for an existing two-round GKE protocol under the revised security definitions assuming random oracles. We then show how to achieve insider KCIR in a generic way using a known compiler in the literature. As one may expect, this additional security assurance comes at the cost of an extra round of communication. Finally, we show that a few existing protocols are not secure against outsider KCI attacks. The attacks on these protocols illustrate the necessity of considering KCI resilience for GKE protocols.
M. Choudary Gorantla, Colin Boyd, Juan Manuel González Nieto, Mark Manulis
ACM Trans. Inf. Syst. Secur.2
2010 Attribute-Based Authenticated Key Exchange
M. Choudary Gorantla, Colin Boyd, Juan Manuel González Nieto
ACISP2
2010 Continuous Biometric Authentication: Can It Be More Practical?
abstract
Continuous biometric authentication schemes (CBAS) are built around the biometrics supplied by user behavioural characteristics and continuously check the identity of the user throughout the session. The current literature for CBAS primarily focuses on the accuracy of the system in order to reduce false alarms. However, these attempts do not consider various issues that might affect practicality in real world applications and continuous authentication scenarios. One of the main issues is that the presented CBAS are based on several samples of training data either of both intruder and valid users or only the valid users' profile. This means that historical profiles for either the legitimate users or possible attackers should be available or collected before prediction time. However, in some cases it is impractical to gain the biometric data of the user in advance (before detection time). Another issue is the variability of the behaviour of the user between the registered profile obtained during enrollment, and the profile from the testing phase. The aim of this paper is to identify the limitations in current CBAS in order to make them more practical for real world applications. Also, the paper discusses a new application for CBAS not requiring any training data either from intruders or from valid users.
Eesa Alsolami, Colin Boyd, Andrew J. Clark, Asadul K. Islam
HPCC2
2010 Automating Computational Proofs for Public-Key-Based Key Exchange
Long Ngo, Colin Boyd, Juan Manuel González Nieto
ProvSec2
2010 Delegation in Predicate Encryption Supporting Disjunctive Queries
Dongdong Sun, Colin Boyd, Juan Manuel González Nieto
SEC2
2010 Delaying Mismatched Field Multiplications in Pairing Computations
Craig Costello, Colin Boyd, Juan Manuel González Nieto, Kenneth Koon-Ho Wong
WAIFI2
2009 How to Extract and Expand Randomness: A Summary and Explanation of Existing Results
Yvonne Cliff, Colin Boyd, Juan Manuel González Nieto
ACNS2
2009 Universally composable contributory group key exchange
abstract
We treat the security of group key exchange (GKE) in the universal composability (UC) framework. Analyzing GKE protocols in the UC framework naturally addresses attacks by malicious insiders. We define an ideal functionality for GKE that captures contributiveness in addition to other desired security goals. We show that an efficient two-round protocol securely realizes the proposed functionality in the random oracle model. As a result, we obtain the most efficient UC-secure contributory GKE protocol known.
M. Choudary Gorantla, Colin Boyd, Juan Manuel González Nieto
AsiaCCS2
2009 Faster Pairings on Special Weierstrass Curves
Craig Costello, Hüseyin Hisil, Colin Boyd, Juan Manuel González Nieto, Kenneth Koon-Ho Wong
Pairing3
2009 Strongly Secure Certificateless Key Agreement
Georg Lippold, Colin Boyd, Juan Manuel González Nieto
Pairing2
2009 A novel identity-based strong designated verifier signature scheme
Baoyuan Kang, Colin Boyd, Ed Dawson
J. Syst. Softw.2
2008 Efficient One-Round Key Exchange in the Standard Model
Colin Boyd, Yvonne Cliff, Juan Manuel González Nieto, Kenneth G. Paterson
ACISP1
2008 A Multiple-Control Fuzzy Vault
abstract
We introduce multiple-control fuzzy vaults allowing generalized threshold, compartmented and multilevel access structure. The presented schemes enable many useful applications employing multiple users and/or multiple locking sets. Introducing the original single control fuzzy vault of Juels and Sudan we identify several similarities and differences between their vault and secret sharing schemes which influence how best to obtain working generalizations. We design multiple-control fuzzy vaults suggesting applications using biometric credentials as locking and unlocking values. Furthermore we assess the security of our obtained generalizations for insider/ outsider attacks and examine the access-complexity for legitimate vault owners.
Marianne Hirschbichler, Colin Boyd, Wageeh W. Boles
PST2
2007 Toward Non-parallelizable Client Puzzles
Suratose Tritilanunt, Colin Boyd, Ernest Foo, Juan Manuel González Nieto
CANS2
2007 On the Connection Between Signcryption and One-Pass Key Establishment
M. Choudary Gorantla, Colin Boyd, Juan Manuel González Nieto
IMACC2
2007 Verifier-Key-Flexible Universal Designated-Verifier Signatures
Raylin Tso, Juan Manuel González Nieto, Takeshi Okamoto, Colin Boyd, Eiji Okamoto
IMACC4
2007 A Comparison of DCT and DWT Block Based Watermarking on Medical Image Quality
Jason Dowling, Birgit M. Planitz, Anthony J. Maeder, Jiang Du 0002, Binh Pham 0001, Colin Boyd, Shaokang Chen, Andrew P. Bradley, Stuart Crozier
IWDW6
2007 A survey of trust and reputation systems for online service provision
Audun Jøsang, Roslan Ismail, Colin Boyd
Decis. Support Syst.3
2007 Batch zero-knowledge proof and verification and its applications
abstract
The batch verification technique of Bellare et al. is extended to verification of several frequently employed zero-knowledge proofs. The new techniques are correct, sound, efficient, and can be widely applied. Specific applications are discussed in detail, including batch ZK proof and verification of validity of encryption (or reencryption) and batch ZK proof and verification of validity of decryption. Considerable efficiency improvements are gained in these two applications without compromising security. As a result, efficiency of the practical cryptographic systems (such as mix networks) based on these two applications is dramatically improved.
Colin Boyd, Ed Dawson
ACM Trans. Inf. Syst. Secur.2
2006 An Extension to Bellare and Rogaway (1993) Model: Resetting Compromised Long-Term Keys
Colin Boyd, Kim-Kwang Raymond Choo, Anish Mathuria
ACISP1
2006 A Novel Range Test
Colin Boyd, Ed Dawson, Eiji Okamoto
ACISP2
2006 Password Based Server Aided Key Exchange
Yvonne Cliff, Yiu Shing Terry Tin, Colin Boyd
ACNS3
2006 Concrete Chosen-Ciphertext Secure Encryption from Subgroup Membership Problems
Jaimee Brown, Juan Manuel González Nieto, Colin Boyd
CANS3
2006 Sealed-Bid Micro Auctions
abstract
In electronic auction applications, small-value merchandise is often distributed. We call this kind of auction micro auction. Compared to traditional general-purpose electronic auction, micro electronic auction has its own special requirements. Especially, micro auction must be very efficient: the cost of the auction protocol must not be over the cost of the merchandise for sale. Although the merchandise to distribute are of small value in micro auctions, bid privacy is still needed in many circumstances. So sealed-bid auction mechanism has to be employed in micro auction. Therefore, a question is raised: how to balance between the high efficiency requirement of micro auction and the high cost needed to keep bid privacy. In this paper, the traditional sealed-bid e-auction techniques are modified to satisfy the special requirements of sealed-bid micro auction. Two existing general-purpose electronic sealed-bid auction schemes are modified into micro sealed-bid auction schemes. The new schemes are secure and suitable for micro auction. One of them is further improved in efficiency to meet more critical requirements in certain micro auction applications.
Colin Boyd, Ed Dawson
SEC2
2006 A Secure E-Tender Submission Protocol
Colin Boyd, Ernest Foo
TrustBus2
2006 The importance of proofs of security for key establishment protocols: Formal analysis of Jan-Chen, Yang-Shen-Shieh, Kim-Huh-Hwang-Lee, Lin-Sun-Hwang, and Yeh-Sun protocols
Kim-Kwang Raymond Choo, Colin Boyd, Yvonne Hitchcock
Comput. Commun.2
2006 Batch verification of validity of bids in homomorphic e-auction
Colin Boyd, Ed Dawson
Comput. Commun.2
2005 Examining Indistinguishability-Based Proof Models for Key Establishment Protocols
Kim-Kwang Raymond Choo, Colin Boyd, Yvonne Hitchcock
ASIACRYPT2
2005 Errors in Computational Complexity Proofs for Protocols
Kim-Kwang Raymond Choo, Colin Boyd, Yvonne Hitchcock
ASIACRYPT2
2005 Simple and Efficient Shuffling with Provable Correctness and ZK Privacy
Colin Boyd, Ed Dawson
CRYPTO2
2005 Ciphertext Comparison, a New Solution to the Millionaire Problem
Colin Boyd, Ed Dawson, Byoungcheon Lee
ICICS2
2005 A Multiplicative Homomorphic Sealed-Bid Auction Based on Goldwasser-Micali Encryption
Colin Boyd, Ed Dawson
ISC2
2005 Designing Secure E-Tendering Systems
Ernest Foo, Juan Manuel González Nieto, Colin Boyd
TrustBus4
2005 A Public Key Cryptosystem Based On A Subgroup Membership Problem
Juan Manuel González Nieto, Colin Boyd, Ed Dawson
Des. Codes Cryptogr.2
2004 Protocols with Security Proofs for Mobile Applications
Yiu Shing Terry Tin, Harikrishna Vasanta, Colin Boyd, Juan Manuel González Nieto
ACISP3
2004 Batch Verification for Equality of Discrete Logarithms and Threshold Decryptions
Riza Aditya, Colin Boyd, Ed Dawson, Byoungcheon Lee
ACNS3
2004 Key Agreement Using Statically Keyed Authenticators
Colin Boyd, Wenbo Mao, Kenneth G. Paterson
ACNS1
2004 An Efficient Mixnet-Based Voting Scheme Providing Receipt-Freeness
Riza Aditya, Byoungcheon Lee, Colin Boyd, Ed Dawson
TrustBus3
2003 Provably Secure Mobile Key Exchange: Applying the Canetti-Krawczyk Approach
Yiu Shing Terry Tin, Colin Boyd, Juan Manuel González Nieto
ACISP2
2002 Co-operatively Formed Group Signatures
Greg Maitland, Colin Boyd
CT-RSA2
2002 Robust, Privacy Protecting and Publicly Verifiable Sealed-Bid Auction
Colin Boyd, Ed Dawson, Kapali Viswanathan
ICICS2
2002 Hybrid Key Escrow: A New Paradigm
Kapali Viswanathan, Colin Boyd, Ed Dawson
Comput. Secur.2
2001 Elliptic Curve Based Password Authenticated Key Exchange Protocols
Colin Boyd, Paul Montague, Khanh Quoc Nguyen
ACISP1
2001 Cryptographic Salt: A Countermeasure against Denial-of-Service Attacks
DongGook Park, JungJoon Kim, Colin Boyd, Ed Dawson
ACISP3
2001 Attacks Based on Small Factors in Various Group Structures
Christopher J. Pavlovski, Colin Boyd
ACISP2
2001 Fair Electronic Cash Based on a Group Signature Scheme
Greg Maitland, Colin Boyd
ICICS2
2001 A Public Key Cryptosystem Based on the Subgroup Membership Problem
Juan Manuel González Nieto, Colin Boyd, Ed Dawson
ICICS2
2000 Passive Entities: A Strategy for Electronic Payment Design
Ernest Foo, Colin Boyd
ACISP2
2000 Key Recovery System for the Commercial Environment
Juan Manuel González Nieto, Kapali Viswanathan, Colin Boyd, Ed Dawson
ACISP3
2000 A Three Phased Schema for Sealed Bid Auction System Design
Kapali Viswanathan, Colin Boyd, Ed Dawson
ACISP2
2000 Attacking and Repairing Batch Verification Schemes
Colin Boyd, Christopher J. Pavlovski
ASIACRYPT1
2000 Key establishment protocols for secure mobile communications: a critical survey
Colin Boyd, Anish Mathuria
Comput. Commun.1
1999 Efficient Electronic Cash Using Batch Signatures
Colin Boyd, Ernest Foo, Christopher J. Pavlovski
ACISP1
1999 Publicly Verifiable Key Escrow with Limited Time Span
Kapali Viswanathan, Colin Boyd, Ed Dawson
ACISP2
1999 Detachable Electronic Coins
Christopher J. Pavlovski, Colin Boyd, Ernest Foo
ICICS2
1999 Signature Scheme for Controlled Environments
Kapali Viswanathan, Colin Boyd, Ed Dawson
ICICS2
1999 A Unified Code
Patrick Guy Farrell, Colin Boyd
IMACC3
1998 Key Establishment Protocols for Secure Mobile Communications: A Selective Survey
Colin Boyd, Anish Mathuria
ACISP1
1998 Off-Line Fair Payment Protocols Using Convertible Signatures
Colin Boyd, Ernest Foo
ASIACRYPT1
1997 On Key Agreement and Conference Key Agreement
Colin Boyd
ACISP1
1997 Cryptanalysis of Adaptive Arithmetic Coding Encryption Schemes
Jen Lim, Colin Boyd, Ed Dawson
ACISP2
1997 Digital signature and public key cryptosystems in a prime order subgroup of Zn*
Colin Boyd
ICICS1
1997 Enforcing traceability in software
Colin Boyd
ICICS1
1997 Resisting the Bergen-Hogan Attack on Adaptive Arithmetic Coding
Patrick Guy Farrell, Colin Boyd
IMACC3
1997 A taxonomy of electronic cash schemes
Ernest Foo, Colin Boyd, William J. Caelli, Ed Dawson
SEC2
1997 Integrating error detection into arithmetic coding
abstract
Arithmetic coding for data compression has gained widespread acceptance as the right method for optimum compression when used with a suitable source model. A technique to implement error detection as part of the arithmetic coding process is described. Heuristic arguments are given to show that a small amount of extra redundancy can be very effective in detecting errors very quickly, and practical tests confirm this prediction.
Colin Boyd, John G. Cleary, Sean A. Irvine, Ingrid Rinsma-Melchert, Ian H. Witten
IEEE Trans. Commun.1
1996 A Framework for Design of Key Establishment Protocols
Colin Boyd
ACISP1
1996 A Class of Flexible and Efficient Key Management Protocols
abstract
Cryptographic protocols for key establishment normally include some means to allow participants to ensure that a key is new and not replayed from an old protocol run. When the key is generated by a mutually trusted server this is usually achieved by sending with the key a quantity known to be new. A different general method for achieving freshness in this content is proposed. A number of specific example protocols are given which have some practical advantages over previous published protocols.
Colin Boyd
CSFW1
1995 Towards a classification of key agreement protocols
abstract
The fundamental requirements for key agreement protocols are explored. As a result, a generalisation of the notion of one-way junctions is proposed and some properties of the definition are described. Three classes of key agreement protocol are identified and concrete examples of each class given.
Colin Boyd
CSFW1
1995 An Elliptic Curve Analogue of McCurley's Key Agreement Scheme
Colin Boyd
IMACC2
1994 Design and Analysis of Key Exchange Protocols via Secure Channel Identification
Colin Boyd, Wenbo Mao
ASIACRYPT1
1994 Development of Authentication Protocols: Some Misconceptions and a New Approach
abstract
Various published authentication protocols that employ symmetric cryptographic algorithms are examined. A number of misconceptions found in the specification, design and implementation of these protocols are revealed. Some misconceptions are considered responsible for definite security flaws, while others are shown to cause weaknesses which may help in attacks on the cryptographic mechanisms. We identify an underlying problem and attempt a remedy by developing a methodology for the development of secure and strong authentication protocols.>
Wenbo Mao, Colin Boyd
CSFW2
1994 Designing Secure Key Exchange Protocols
Colin Boyd, Wenbo Mao
ESORICS1
1994 On Strengthening Authentication Protocols to Foil Cryptanalysis
Wenbo Mao, Colin Boyd
ESORICS2
1993 Towards Formal Analysis of Security Protocols
abstract
The pioneering and well-known work of M. Burrows, M. Abadi and R. Needham (1989), (the BAN logic) which dominates the area of security protocol analysis is shown to take an approach which is not fully formal and which consequently permits approval of dangerous protocols. Measures to make the BAN logic formal are then proposed. The formalisation is found to be desirable not only for its potential in providing rigorous analysis of security protocols, but also for its readiness for supporting a computer-aided fashion of analysis.>
Wenbo Mao, Colin Boyd
CSFW2
1993 Security Architectures Using Formal Methods
abstract
A model describing secure communications architectures is developed using the formal language Z. The model is based on fundamental cryptographic properties. Some basic constraints are derived for the design of secure architectures which allow problems to be identified prior to the design of security protocols. A simple criterion is derived for ensuring that all pairs of users can set up secure communications channels.>
Colin Boyd
IEEE J. Sel. Areas Commun.1
1992 A Formal Framework for Authentication
Colin Boyd
ESORICS1