Alejandro Hevia

dblp:h/AlejandroHevia · DBLP profile ↗
← Back
17ranked-venue papers
7as first author
0since 2021 · last 2020
0000-0002-4774-0693ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 3 first-authorTheory of computation · 4 · 3 first-authorSystems, architecture and hardware · 2 · 1 first-authorComputer networks · 1Software engineering, systems software and programming languages · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
5 papers
Cryptographic protocols and secure computation · 57% Cryptographic primitives and cryptanalysis · 37% Authentication and access control · 6%
Computer networks
2 papers
Internet architecture and protocols · 50% Content delivery and video streaming · 50%
Computer architecture, parallel and distributed computing, and storage systems
1 paper
Distributed systems · 100%

Topics — the 13 heaviest of 13, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Cryptographic primitives and cryptanalysis
pairing-based cryptography
0.212015
QA-NIZK Arguments in Asymmetric Groups: New Tools and New Constructions · ASIACRYPT (1) 2015
Cryptographic protocols and secure computation › proof systems › zero-knowledge proofs › non-interactive zero-knowledge proofs
quasi-adaptive non-interactive zero-knowledge
0.212015
QA-NIZK Arguments in Asymmetric Groups: New Tools and New Constructions · ASIACRYPT (1) 2015
Cryptographic protocols and secure computation › proof systems
zero-knowledge proofs
0.212015
QA-NIZK Arguments in Asymmetric Groups: New Tools and New Constructions · ASIACRYPT (1) 2015
Internet architecture and protocols
network resilience
0.112005
Surviving Internet Catastrophes · USENIX ATC, General Track 2005
Content delivery and video streaming › video coding
transcoding
0.112005
End-to-end security in the presence of intelligent data adapting proxies: the case of authenticating transcoded streaming media · IEEE J. Sel. Areas Commun. 2005
Authentication and access control
authentication
0.112005
End-to-end security in the presence of intelligent data adapting proxies: the case of authenticating transcoded streaming media · IEEE J. Sel. Areas Commun. 2005
Cryptographic protocols and secure computation › broadcast
simultaneous broadcast
0.112005
Simultaneous broadcast revisited · PODC 2005
Cryptographic primitives and cryptanalysis › public-key cryptography
digital signatures
0.012002
The Provable Security of Graph-Based One-Time Signatures and Extensions to Algebraic Signature Schemes · ASIACRYPT 2002
Cryptographic primitives and cryptanalysis
provable security
0.012002
The Provable Security of Graph-Based One-Time Signatures and Extensions to Algebraic Signature Schemes · ASIACRYPT 2002
Cryptographic primitives and cryptanalysis
pseudorandom generators
0.012002
A Practice-Oriented Treatment of Pseudorandom Number Generators · EUROCRYPT 2002
Cryptographic protocols and secure computation
end-to-end security
0.012005
End-to-end security in the presence of intelligent data adapting proxies: the case of authenticating transcoded streaming media · IEEE J. Sel. Areas Commun. 2005
Distributed systems › fault tolerance › failure recovery
disaster recovery
0.012005
Surviving Internet Catastrophes · USENIX ATC, General Track 2005
Distributed systems
fault tolerance
0.012005
Surviving Internet Catastrophes · USENIX ATC, General Track 2005

Methods — techniques the papers use, named apart from their topics

provable security · 0.1digital signature · 0.1security reduction · 0.0pseudorandomness · 0.0cryptographic security analysis · 0.0
YearPublicationVenuePosition
2020 Fuzzing to Estimate Gas Costs of Ethereum Contracts
abstract
This paper studies how a simple approach based on fuzzing testing can help authors of Solidity contracts to accurately estimate the gas cost of services specified in a contract. Our fuzzer creates a private blockchain and randomly generates transactions. Such an environment is meant to simulate large scale behavior that may be seen in a public blockchain. Our fuzzer handles Ethereum starting and target endpoints in a transaction to accommodate requirements expressed in financial contracts. By comparing the gas computation made by the Ethereum Solidity compiler and the actual consumption during our fuzzing, we are able to find discrepancies between predicted and real gas consumption. Our findings are beneficial to transaction authors to correctly predict the computing resources of Ethereum miners.
Alexandre Bergel, Alejandro Hevia
ICSME3
2018 A second note on the feasibility of generalized universal composability
abstract
Yao et al. (A note on the feasibility of generalized universal composability.Theory and Applications of Models of Computationpp. 474–485, 2007; A note on the feasibility of generalised universal composability.Mathematical Structures in Computer Science,19(1), pp. 193–205) claimed a potential limitation on the class of protocols that could be securely implemented in the generalized universal composability (GUC) framework proposed by Canetti et al. (Universally composable security with global setup.Lecture Notes in Computer Science, pp. 61–85, 2007). Specifically, Yao et al. presented a concrete attack on a GUC Zero Knowledge (GUCZK) protocol, a natural adaptation Blum's ZK proof for Directed Hamiltonicity using the general GUC feasibility of Canetti et al. (Universally composable security with global setup.Lecture Notes in Computer Science, pp. 61–85, 2007). Interestingly, the attack was not analysed in the GUC model in Yao et al. (A note on the feasibility of generalised universal composability.Mathematical Structures in Computer Science19(1), pp. 193–205, 2009) but in theFUC model, a new UC-like framework proposed in the same work. Nonetheless, Yao et al. (A note on the feasibility of generalised universal composability.Mathematical Structures in Computer Science19(1), pp. 193–205, 2009) argued that, in light of this attack, GUC would lose its concurrent general composability and proof of knowledge properties. Concretely, they argue that GUC composability would now be with respect to some adversaries with limited access to external arbitrary protocols. In this work, we show that the claimed attack from Yao et al. is indeed harmless and does not contradict the security of the mentioned GUCZK protocol, thus restoring the general feasibility for GUC.
Alonso González, Alejandro Hevia
Math. Struct. Comput. Sci.2
2015 QA-NIZK Arguments in Asymmetric Groups: New Tools and New Constructions
Alonso González, Alejandro Hevia, Carla Ràfols
ASIACRYPT (1)2
2012 Short Transitive Signatures for Directed Trees
Philippe Camacho, Alejandro Hevia
CT-RSA2
2010 Robustness Guarantees for Anonymity
abstract
Anonymous communication protocols must achieve two seemingly contradictory goals: privacy (informally, they must guarantee the anonymity of the parties that send/receive information), and robustness (informally, they must ensure that the messages are not tampered). However, the long line of research that defines and analyzes the security of such mechanisms focuses almost exclusively on the former property and ignores the latter. In this paper, we initiate a rigorous study of robustness properties for anonymity protocols. We identify and formally define, using the style of modern cryptography, two related but distinct flavors of robustness. Our definitions are general (e.g. they strictly generalize the few existent notions for particular protocols) and flexible (e.g. they can be easily adapted to purely combinatorial/probabilistic mechanisms). We demonstrate the use of our definitions through the analysis of several anonymity mechanisms (Crowds, broadcast-based mix-nets, DC-nets, Tor). Notably, we analyze the robustness of a protocol by Golle and Juels for the dining cryptographers problem, identify a robustness-related weakness of the protocol, and propose and analyze a stronger version.
Gilles Barthe, Alejandro Hevia, Zhengqin Luo, Tamara Rezk, Bogdan Warinschi
CSF2
2010 Latent semantic analysis and keyword extraction for phishing classification
abstract
Phishing email fraud has been considered as one of the main cyber-threats over the last years. Its development has been closely related to social engineering techniques, where different fraud strategies are used to deceit a naïve email user. In this work, a latent semantic analysis and text mining methodology is proposed for the characterisation of such strategies, and further classification using supervised learning algorithms. Results obtained showed that the feature set obtained in this work is competitive against previous phishing feature extraction methodologies, achieving promising results over different benchmark machine learning classification techniques.
Gaston L'Huillier, Alejandro Hevia, Richard Weber 0002, Sebastián A. Ríos
ISI2
2008 Strong Accumulators from Collision-Resistant Hashing
Philippe Camacho, Alejandro Hevia, Marcos A. Kiwi, Roberto Opazo
ISC2
2008 An Indistinguishability-Based Characterization of Anonymous Channels
Alejandro Hevia, Daniele Micciancio
Privacy Enhancing Technologies1
2005 Simultaneous broadcast revisited
abstract
Simultaneous Broadcast protocols allow different parties to broadcast values in parallel while guaranteeing mutual independence of the broadcast values. In this work, we study various definitions of independence proposed in the literature by Chor, Goldwasser, Micali and Awerbuch (FOCS 1985), Chor and Rabin (PODC 1987) and Gennaro (IEEE Trans. on Parallel and Distributed Systems, 2000), and prove implications and separations among them. In summary, we show that each definition (generalized to allow arbitrary input distributions) is characterized by a class of “achievable” input distributions such that there is a single protocol that simultaneously meets the definition for all distributions in the class, while for any distribution outside the class no protocol can possibly achieve the definition. When comparing sets of achievable distributions, the definition of Gennaro is the most stringent (followed by the Chor and Rabin one, and Chor, Goldwasser, Micali and Awerbuch as the most relaxed) in the sense that it is achievable for the smallest class of distributions. This demonstrates that the definitions of Gennaro, and Chor and Rabin are of limited applicability. Then, we compare the definitions when restricted to achievable distributions. This time
Alejandro Hevia, Daniele Micciancio
PODC1
2005 Surviving Internet Catastrophes
Flavio Paiva Junqueira, Ranjita Bhagwan, Alejandro Hevia, Keith Marzullo, Geoffrey M. Voelker
USENIX ATC, General Track3
2005 End-to-end security in the presence of intelligent data adapting proxies: the case of authenticating transcoded streaming media
abstract
We consider the problem of maintaining end-to-end security in the presence of intelligent proxies that may adaptively modify data being transmitted across a network. The video coding community considers this problem in the context of transcoding media streams, but their approaches either fail to address authentication or fail to provide meaningful security guarantees. We present two provably-secure schemes, LISSA and TRESSA, that allow an intelligent network intermediary to intercept a stream signed by a content provider, and adapt it dynamically, while preserving the ultimate receiver's ability to securely verify the content provider's signature (and, hence, authenticity and integrity of the data received). Our schemes allow the intermediary to selectively remove portions of the stream and, thus, permit common media transcoding techniques such as scalable compression and multiple file switching. Moreover, a content provider only has to encode and sign its entire data stream once, as opposed to nondynamically encoding and signing different versions for each anticipated combination of device, network configuration, and channel condition. Our implementation results demonstrate efficiency.
Craig Gentry, Alejandro Hevia, Ravi Jain, Toshiro Kawahara, Zulfikar Ramzan
IEEE J. Sel. Areas Commun.2
2004 Electronic jury voting protocols
Alejandro Hevia, Marcos A. Kiwi
Theor. Comput. Sci.1
2002 The Provable Security of Graph-Based One-Time Signatures and Extensions to Algebraic Signature Schemes
Alejandro Hevia, Daniele Micciancio
ASIACRYPT1
2002 A Practice-Oriented Treatment of Pseudorandom Number Generators
Anand Desai, Alejandro Hevia, Yiqun Lisa Yin
EUROCRYPT2
2002 Electronic Jury Voting Protocols
Alejandro Hevia, Marcos A. Kiwi
LATIN1
1999 Strength of two data encryption standard implementations under timing attacks
abstract
We study the vulnerability of two implementations of the Data Encryption Standard (DES) cryptosystem under a timing attack. A timing attack is a method, recently proposed by Paul Kocher, that is designed to break cryptographic systems. It exploits the engineering aspects involved in the implementation of cryptosystems and might succeed even against cryptosys-tems that remain impervious to sophisticated cryptanalytic techniques. A timing attack is, essentially, a way of obtaining some users private information by carefully measuring the time it takes the user to carry out cryptographic operations. In this work, we analyze two implementations of DES. We show that a timing attack yields the Hamming weight of the key used by both DES implementations. Moreover, the attack is computationally inexpensive. We also show that all the design characteristics of the target system, necessary to carry out the timing attack, can be inferred from timing measurements.
Alejandro Hevia, Marcos A. Kiwi
ACM Trans. Inf. Syst. Secur.1
1998 Strength of Two Data Encryption Standard Implementations under Timing Attacks
Alejandro Hevia, Marcos A. Kiwi
LATIN1