EDBT 2026 Demo / reviewers in the wild / expert
Ari Juels
dblp:j/AriJuels
· DBLP profile ↗
107ranked-venue papers
27as first author
11since 2021 · last 2026
0009-0002-1143-5504ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 95 · 23 first-author · 11 since 2021Systems, architecture and hardware · 4Applied, interdisciplinary, general and emerging computing · 3Computer networks · 2 · 1 first-authorTheory of computation · 2 · 2 first-authorArtificial intelligence and machine learning · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | PROF: Protected Order Flow in a Profit-Seeking WorldabstractUsers of decentralized finance (DeFi) applications face significant risks from adversarial actions that manipulate the order of transactions to extract value from users. Such actions -- an adversarial form of what is called maximal-extractable value (MEV) -- impact both individual outcomes and the stability of the DeFi ecosystem. MEV exploitation, moreover, is being institutionalized through an architectural paradigm known Proposer-Builder Separation (PBS). This work introduces a system called PROF (PRotected Order Flow) that is designed to limit harmful forms of MEV in existing PBS systems. PROF aims at this goal using two ideas. First, PROF imposes an ordering on a set ("bundle") of privately input transactions and enforces that ordering all the way through to block production -- preventing transaction-order manipulation. Second, PROF creates bundles whose inclusion is profitable to block producers, thereby ensuring that bundles see timely inclusion in blocks. PROF is backward-compatible, meaning that it works with existing and future PBS designs. PROF is also compatible with any desired algorithm for ordering transactions within a PROF bundle (e.g., first-come, first-serve, fee-based, etc.). It executes efficiently, i.e., with low latency, and requires no additional trust assumptions among PBS entities. We quantitatively and qualitatively analyze incentive structure of PROF, and its utility to users compared with existing solutions. We also report on inclusion likelihood of PROF transactions, and concrete latency numbers through our end-to-end implementation. Kushal Babel, Nerla Jean-Louis, Yan Ji 0001, Ujval Misra, Mahimna Kelkar, Kosala Yapa Mudiyanselage, Andrew Miller 0001, Ari Juels |
EuroS&P | 8 |
| 2025 | Liquefaction: Privately Liquefying Blockchain AssetsabstractInherent in the world of cryptocurrency systems and their security models is the notion that private keys-and thus assets-are controlled by individuals or individual entities. We present Liquefaction, a wallet platform that demon-strates the dangerous fragility of this foundational assumption by systemically breaking it. Liquefaction uses trusted execution environments (TEEs) to encumber private keys, i.e., attach rich, multi-user policies to their use. In this way, it enables the cryptocurrency credentials and assets of a single end-user address to be freely rented, shared, or pooled. It accomplishes these things privately, with no direct on-chain traces. Liquefaction demonstrates the sweeping consequences of TEE-based key encumbrance for the cryptocurrency land-scape. Liquefaction can undermine the security and economic models of many applications and resources, such as locked tokens, DAO voting, airdrops, loyalty points, soulbound tokens, and quadratic voting. It can do so with no on-chain and minimal off-chain visibility. Conversely, we also discuss beneficial applications of Liquefaction, such as privacy-preserving, cost-efficient DAOs and a countermeasure to dusting attacks. Importantly, we describe an existing TEE-based tool that applications can use as a countermeasure to Liquefaction. Our work prompts a wholesale rethinking of existing models and enforcement of key and asset ownership in the cryptocurrency ecosystem. James Austgen, Andrés Fábrega, Mahimna Kelkar, Dani Vilardell, Sarah Allen, Kushal Babel, Jay Yu, Ari Juels |
SP | 8 |
| 2025 | Voting-Bloc Entropy: A New Metric for DAO Decentralization
Andrés Fábrega, Amy Zhao, Jay Yu, James Austgen, Sarah Allen, Kushal Babel, Mahimna Kelkar, Ari Juels |
USENIX Security Symposium | 8 |
| 2024 | Complete Knowledge: Preventing Encumbrance of Cryptographic SecretsabstractMost cryptographic protocols model a player's knowledge of secrets in a simple way. Informally, the player knows a secret in the sense that she can directly furnish it as a (private) input to a protocol, e.g., to digitally sign a message. Mahimna Kelkar, Kushal Babel, Philip Daian, James Austgen, Vitalik Buterin, Ari Juels |
CCS | 6 |
| 2024 | GoAT: File Geolocation via Anchor Timestamping
Sai Krishna Deepak Maram, Mahimna Kelkar, Iddo Bentov, Ari Juels |
FC (2) | 4 |
| 2023 | Lanturn: Measuring Economic Security of Smart Contracts Through Adaptive LearningabstractWe introduce Lanturn: a general purpose adaptive learning-based framework for measuring the cryptoeconomic security of composed decentralized-finance (DeFi) smart contracts. Lanturn discovers strategies comprising of concrete transactions for extracting economic value from smart contracts interacting with a particular transaction environment. We formulate the strategy discovery as a black-box optimization problem and leverage a novel adaptive learning-based algorithm to address it. Kushal Babel, Mojan Javaheripi, Yan Ji 0001, Mahimna Kelkar, Farinaz Koushanfar, Ari Juels |
CCS | 6 |
| 2023 | Themis: Fast, Strong Order-Fairness in Byzantine ConsensusabstractWe introduce Themis, a scheme for introducing fair ordering of transactions into (permissioned) Byzantine consensus protocols with at most ƒ faulty nodes among n ≥ 4ƒ + 1. Themis enforces the strongest notion of fair ordering proposed to date. It also achieves standard liveness, rather than the weaker notion of previous work with the same fair ordering property. Mahimna Kelkar, Soubhik Deb, Sishan Long, Ari Juels, Sreeram Kannan |
CCS | 4 |
| 2023 | Forsage: Anatomy of a Smart-Contract Pyramid Scheme
Tyler Kell, Haaroon Yousaf, Sarah Allen, Sarah Meiklejohn, Ari Juels |
FC | 5 |
| 2023 | Clockwork Finance: Automated Analysis of Economic Security in Smart ContractsabstractWe introduce the Clockwork Finance Framework (CFF), a general purpose, formal verification framework for mechanized reasoning about the economic security properties of composed decentralized-finance (DeFi) smart contracts.CFF features three key properties. It is contract complete, meaning that it can model any smart contract platform and all its contracts—Turing complete or otherwise. It does so with asymptotically constant model overhead. It is also attack-exhaustive by construction, meaning that it can automatically and mechanically extract all possible economic attacks on users’ cryptocurrency across modeled contracts.Thanks to these properties, CFF can support multiple goals: economic security analysis of contracts by developers, analysis of DeFi trading risks by users, fees UX, and optimization of arbitrage opportunities by bots or miners. Because CFF offers composability, it can support these goals with reasoning over any desired set of potentially interacting smart contract models.We instantiate CFF as an executable model for Ethereum contracts that incorporates a state-of-the-art deductive verifier. Building on previous work, we introduce extractable value (EV), a new formal notion of economic security in composed DeFi contracts that is both a basis for CFF and of general interest.We construct modular, human-readable, composable CFF models of four popular, deployed DeFi protocols in Ethereum: Uniswap, Uniswap V2, Sushiswap, and MakerDAO, representing a combined 24 billion USD in value as of March 2022. We use these models along with some other common models such as flash loans, airdrops and voting to show experimentally that CFF is practical and can drive useful, data-based EV-based insights from real world transaction activity. Without any explicitly programmed attack strategies, CFF uncovers on average an expected $56 million of EV per month in the recent past. Kushal Babel, Philip Daian, Mahimna Kelkar, Ari Juels |
SP | 4 |
| 2021 | SquirRL: Automating Attack Analysis on Blockchain Incentive Mechanisms with Deep Reinforcement Learning
Charlie Hou, Mingxun Zhou, Yan Ji 0001, Philip Daian, Florian Tramèr, Giulia Fanti, Ari Juels |
NDSS | 7 |
| 2021 | CanDID: Can-Do Decentralized Identity with Legacy Compatibility, Sybil-Resistance, and AccountabilityabstractWe present CanDID, a platform for practical, user-friendly realization of decentralized identity, the idea of empowering end users with management of their own credentials.While decentralized identity promises to give users greater control over their private data, it burdens users with management of private keys, creating a significant risk of key loss. Existing and proposed approaches also presume the spontaneous availability of a credential-issuance ecosystem, creating a bootstrapping problem. They also omit essential functionality, like resistance to Sybil attacks and the ability to detect misbehaving or sanctioned users while preserving user privacy.CanDID addresses these challenges by issuing credentials in a user-friendly way that draws securely and privately on data from existing, unmodified web service providers. Such legacy compatibility similarly enables CanDID users to leverage their existing online accounts for recovery of lost keys. Using a decentralized committee of nodes, CanDID provides strong confidentiality for user’s keys, real-world identities, and data, yet prevents users from spawning multiple identities and allows identification (and blacklisting) of sanctioned users.We present the CanDID architecture and report on experiments demonstrating its practical performance. Sai Krishna Deepak Maram, Harjasleen Malvai, Fan Zhang 0022, Nerla Jean-Louis, Alexander Frolov 0002, Tyler Kell, Tyrone Lobban, Christine Moy, Ari Juels, Andrew Miller 0001 |
SP | 9 |
| 2020 | BDoS: Blockchain Denial-of-ServiceabstractProof-of-work (PoW) cryptocurrency blockchains like Bitcoin secure vast amounts of money. Their operators, called miners, expend resources to generate blocks and receive monetary rewards for their effort. Blockchains are, in principle, attractive targets for Denial-of-Service (DoS) attacks: There is fierce competition among coins, as well as potential gains from short selling. Classical DoS attacks, however, typically target a few servers and cannot scale to systems with many nodes. There have been no successful DoS attacks to date against prominent cryptocurrencies. We present Blockchain DoS (BDoS), the first incentive-based DoS attack that targets PoW cryptocurrencies. Unlike classical DoS, BDoS targets the system's mechanism design: It exploits the reward mechanism to discourage miner participation. Previous DoS attacks against PoW blockchains require an adversary's mining power to match that of all other miners. In contrast, BDoS can cause a blockchain to grind to a halt with significantly fewer resources, e.g., 21% as of March 2020 in Bitcoin, according to our empirical study. We find that Bitcoin's vulnerability to BDoS increases rapidly as the mining industry matures and profitability drops. BDoS differs from known attacks like Selfish Mining in its aim not to increase an adversary's revenue, but to disrupt the system. Although it bears some algorithmic similarity to those attacks, it introduces a new adversarial model, goals, algorithm, and game-theoretic analysis. Beyond its direct implications for operational blockchains, BDoS introduces the novel idea that an adversary can manipulate miners' incentives by proving the existence of blocks without actually publishing them. Michael Mirkin, Yan Ji 0001, Jonathan Pang, Ariah Klages-Mundt, Ittay Eyal, Ari Juels |
CCS | 6 |
| 2020 | DECO: Liberating Web Data Using Decentralized Oracles for TLSabstractThanks to the widespread deployment of TLS, users can access private data over channels with end-to-end confidentiality and integrity. What they cannot do, however, is prove to third parties the provenance of such data, i.e., that it genuinely came from a particular website. Existing approaches either introduce undesirable trust assumptions or require server-side modifications. Users' private data is thus locked up at its point of origin. Users cannot export data in an integrity-protected way to other applications without help and permission from the current data holder. We propose DECO (short for decentralized oracle) to address the above problems. DECO allows users to prove that a piece of data accessed via TLS came from a particular website and optionally prove statements about such data in zero-knowledge, keeping the data itself secret. DECO is the first such system that works without trusted hardware or server-side modifications. DECO can liberate private data from centralized web-service silos, making it accessible to a rich spectrum of applications. To demonstrate the power of DECO, we implement three applications that are hard to achieve without it: a private financial instrument using smart contracts, converting legacy credentials to anonymous credentials, and verifiable claims against price discrimination. Fan Zhang 0022, Sai Krishna Deepak Maram, Harjasleen Malvai, Steven Goldfeder, Ari Juels |
CCS | 5 |
| 2020 | Order-Fairness for Byzantine Consensus
Mahimna Kelkar, Fan Zhang 0022, Steven Goldfeder, Ari Juels |
CRYPTO (3) | 4 |
| 2020 | Flash Boys 2.0: Frontrunning in Decentralized Exchanges, Miner Extractable Value, and Consensus InstabilityabstractBlockchains, and specifically smart contracts, have promised to create fair and transparent trading ecosystems.Unfortunately, we show that this promise has not been met. We document and quantify the widespread and rising deployment of arbitrage bots in blockchain systems, specifically in decentralized exchanges (or "DEXes"). Like high-frequency traders on Wall Street, these bots exploit inefficiencies in DEXes, paying high transaction fees and optimizing network latency to frontrun, i.e., anticipate and exploit, ordinary users' DEX trades.We study the breadth of DEX arbitrage bots in a subset of transactions that yield quantifiable revenue to these bots. We also study bots' profit-making strategies, with a focus on blockchain-specific elements. We observe bots engage in what we call priority gas auctions (PGAs), competitively bidding up transaction fees in order to obtain priority ordering, i.e., early block position and execution, for their transactions. PGAs present an interesting and complex new continuous-time, partial-information, game-theoretic model that we formalize and study. We release an interactive web portal, frontrun.me, to provide the community with real-time data on PGAs. We additionally show that high fees paid for priority transaction ordering poses a systemic risk to consensus-layer security. We explain that such fees are just one form of a general phenomenon in DEXes and beyond-what we call miner extractable value (MEV)-that poses concrete, measurable, consensus-layer security risks. We show empirically that MEV poses a realistic threat to Ethereum today. Our work highlights the large, complex risks created by transaction-ordering dependencies in smart contracts and the ways in which traditional forms of financial-market exploitation are adapting to and penetrating blockchain economies. Philip Daian, Steven Goldfeder, Tyler Kell, Yunqi Li 0002, Xueyuan Zhao, Iddo Bentov, Lorenz Breidenbach, Ari Juels |
SP | 8 |
| 2019 | Paralysis Proofs: Secure Dynamic Access Structures for Cryptocurrency Custody and MoreabstractThe growing adoption of digital assets---including but not limited to cryptocurrencies, tokens, and even identities---calls for secure and robust digital assets custody. A common way to distribute the ownership of a digital asset is (M, N)-threshold access structures. However, traditional access structures leave users with a painful choice. Setting M = N seems attractive as it offers maximum resistance to share compromise, but it also causes maximum brittleness: A single lost share renders the asset permanently frozen, inducing paralysis. Lowering M improves availability, but degrades security. Fan Zhang 0022, Philip Daian, Iddo Bentov, Ian Miers, Ari Juels |
AFT | 5 |
| 2019 | Multisketches: Practical Secure Sketches Using Off-the-Shelf Biometric Matching AlgorithmsabstractBiometric authentication is increasingly being used for large scale human authentication and identification, creating the risk of leaking the biometric secrets of millions of users in the case of database compromise. Powerful "fuzzy" cryptographic techniques for biometric template protection, such as secure sketches, could help in principle, but go unused in practice. This is because they would require new biometric matching algorithms with potentially much diminished accuracy. We introduce a new primitive called a multisketch that generalizes secure sketches. Multisketches can work with existing biometric matching algorithms to generate strong cryptographic keys from biometric data reliably. A multisketch works on a biometric database containing multiple biometrics --- e.g., multiple fingerprints --- of a moderately large population of users (say, thousands). It conceals the correspondence between users and their biometric templates, preventing an attacker from learning the biometric data of a user in the advent of a breach, but enabling derivation of user-specific secret keys upon successful user authentication. We design a multisketch over tenprints --- fingerprints of ten fingers --- called TenSketch. We report on a prototype implementation of TenSketch, showing its feasibility in practice. We explore several possible attacks against TenSketch database and show, via simulations with real tenprint datasets, that an attacker must perform a large amount of computation to learn any meaningful information from a stolen TenSketch database. Rahul Chatterjee 0001, M. Sadegh Riazi, Tanmoy Chowdhury, Emanuela Marasco, Farinaz Koushanfar, Ari Juels |
CCS | 6 |
| 2019 | Tesseract: Real-Time Cryptocurrency Exchange Using Trusted HardwareabstractWe propose Tesseract, a secure real-time cryptocurrency exchange service. Existing centralized exchange designs are vulnerable to theft of funds, while decentralized exchanges cannot offer real-time cross-chain trades. All currently deployed exchanges are also vulnerable to frontrunning attacks. Tesseract overcomes these flaws and achieves a best-of-both-worlds design by using a trusted execution environment. The task of committing the recent trade data to independent cryptocurrency systems presents an all-or-nothing fairness problem, to which we present ideal theoretical solutions, as well as practical solutions. Tesseract supports not only real-time cross-chain cryptocurrency trades, but also secure tokenization of assets pegged to cryptocurrencies. For instance, Tesseract-tokenized bitcoins can circulate on the Ethereum blockchain for use in smart contracts. We provide a demo implementation of Tesseract that supports Bitcoin, Ethereum, and similar cryptocurrencies. Iddo Bentov, Yan Ji 0001, Fan Zhang 0022, Lorenz Breidenbach, Philip Daian, Ari Juels |
CCS | 6 |
| 2019 | PIEs: Public Incompressible Encodings for Decentralized StorageabstractWe present a new primitive supporting file replication in distributed storage networks (DSNs) called a Public Incompressible Encoding (PIE). PIEs operate in the challenging public DSN setting where files must be encoded and decoded with public randomness-i.e., without encryption-and retention of redundant data must be publicly verifiable. They prevent undetectable data compression, allowing DSNs to use monetary rewards or penalties in incentivizing economically rational servers to properly replicate data. Their definition also precludes critical, demonstrated attacks involving parallelism via ASICs and other custom hardware. Our PIE construction is the first to achieve experimentally validated near-optimal performance-within a factor of 4 of optimal by one metric. It also allows decoding orders of magnitude faster than encoding, unlike other comparable constructions. We achieve this high security and performance using a graph construction called a Dagwood Sandwich Graph (DSaG), built from a novel interleaving of depth-robust graphs and superconcentrators. PIEs' performance makes them appealing for DSNs, such as the proposed Filecoin system and Ethereum data sharding. Conversely, their near-optimality establishes concerning bounds on the practical financial and energy costs of DSNs allowing arbitrary data. Ethan Cecchetti, Ben Fisch, Ian Miers, Ari Juels |
CCS | 4 |
| 2019 | CHURP: Dynamic-Committee Proactive Secret SharingabstractWe introduce CHURP (CHUrn-Robust Proactive secret sharing). CHURP enables secure secret-sharing in dynamic settings, where the committee of nodes storing a secret changes over time. Designed for blockchains, CHURP has lower communication complexity than previous schemes: $O(n)$ on-chain and $O(n^2)$ off-chain in the optimistic case of no node failures. CHURP includes several technical innovations: An efficient new proactivization scheme of independent interest, a technique (using asymmetric bivariate polynomials) for efficiently changing secret-sharing thresholds, and a hedge against setup failures in an efficient polynomial commitment scheme. We also introduce a general new technique for inexpensive off-chain communication across the peer-to-peer networks of permissionless blockchains. We formally prove the security of CHURP, report on an implementation, and present performance measurements. Sai Krishna Deepak Maram, Fan Zhang 0022, Lun Wang 0001, Andrew Low, Yupeng Zhang 0001, Ari Juels, Dawn Song |
CCS | 6 |
| 2019 | Ekiden: A Platform for Confidentiality-Preserving, Trustworthy, and Performant Smart ContractsabstractSmart contracts are applications that execute on blockchains. Today they manage billions of dollars in value and motivate visionary plans for pervasive blockchain deployment. While smart contracts inherit the availability and other security assurances of blockchains, however, they are impeded by blockchains' lack of confidentiality and poor performance. We present Ekiden, a system that addresses these critical gaps by combining blockchains with Trusted Execution Environments (TEEs). Ekiden leverages a novel architecture that separates consensus from execution, enabling efficient TEE-backed confidentiality-preserving smart-contracts and high scalability. Our prototype (with Tendermint as the consensus layer) achieves example performance of 600× more throughput and 400× less latency at 1000× less cost than the Ethereum mainnet. Another contribution of this paper is that we systematically identify and treat the pitfalls arising from harmonizing TEEs and blockchains. Treated separately, both TEEs and blockchains provide powerful guarantees, but hybridized, though, they engender new attacks. For example, in naïve designs, privacy in TEE-backed contracts can be jeopardized by forgery of blocks, a seemingly unrelated attack vector. We believe the insights learned from Ekiden will prove to be of broad importance in hybridized TEE-blockchain systems. Raymond Cheng 0001, Fan Zhang 0022, Jernej Kos, Warren He, Nicholas Hynes 0001, Noah M. Johnson, Ari Juels, Andrew Miller 0001, Dawn Song |
EuroS&P | 7 |
| 2018 | Enter the Hydra: Towards Principled Bug Bounties and Exploit-Resistant Smart Contracts
Lorenz Breidenbach, Philip Daian, Florian Tramèr, Ari Juels |
USENIX Security Symposium | 4 |
| 2018 | DelegaTEE: Brokered Delegation Using Trusted Execution Environments
Sinisa Matetic, Moritz Schneider 0001, Andrew Miller 0001, Ari Juels, Srdjan Capkun |
USENIX Security Symposium | 4 |
| 2017 | Solidus: Confidential Distributed Ledger Transactions via PVORMabstractBlockchains and more general distributed ledgers are becoming increasingly popular as efficient, reliable, and persistent records of data and transactions. Unfortunately, they ensure reliability and correctness by making all data public, raising confidentiality concerns that eliminate many potential uses. Ethan Cecchetti, Fan Zhang 0022, Yan Ji 0001, Ahmed E. Kosba, Ari Juels, Elaine Shi |
CCS | 5 |
| 2017 | A New Distribution-Sensitive Secure Sketch and Popularity-Proportional Hashing
Joanne Woodage, Rahul Chatterjee 0001, Yevgeniy Dodis, Ari Juels, Thomas Ristenpart |
CRYPTO (3) | 4 |
| 2017 | FairTest: Discovering Unwarranted Associations in Data-Driven ApplicationsabstractIn a world where traditional notions of privacy are increasingly challenged by the myriad companies that collect and analyze our data, it is important that decision-making entities are held accountable for unfair treatments arising from irresponsible data usage. Unfortunately, a lack of appropriate methodologies and tools means that even identifying unfair or discriminatory effects can be a challenge in practice. We introduce the unwarranted associations (UA) framework, a principled methodology for the discovery of unfair, discriminatory, or offensive user treatment in data-driven applications. The UA framework unifies and rationalizes a number of prior attempts at formalizing algorithmic fairness. It uniquely combines multiple investigative primitives and fairness metrics with broad applicability, granular exploration of unfair treatment in user subgroups, and incorporation of natural notions of utility that may account for observed disparities. We instantiate the UA framework in FairTest, the first comprehensive tool that helps developers check data-driven applications for unfair user treatment. It enables scalable and statistically rigorous investigation of associations between application outcomes (such as prices or premiums) and sensitive user attributes (such as race or gender). Furthermore, FairTest provides debugging capabilities that let programmers rule out potential confounders for observed unfair effects. We report on use of FairTest to investigate and in some cases address disparate impact, offensive labeling, and uneven rates of algorithmic error in four data-driven applications. As examples, our results reveal subtle biases against older populations in the distribution of error in a predictive health application and offensive racial labeling in an image tagger. Florian Tramèr, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu 0001, Jean-Pierre Hubaux, Mathias Humbert, Ari Juels, Huang Lin |
EuroS&P | 7 |
| 2017 | Sealed-Glass Proofs: Using Transparent Enclaves to Prove and Sell KnowledgeabstractTrusted hardware systems, such as Intel's new SGX instruction set architecture extension, aim to provide strong confidentiality and integrity assurances for applications. Recent work, however, raises serious concerns about the vulnerability of such systems to side-channel attacks. We propose, formalize, and explore a cryptographic primitive called a Sealed-Glass Proof (SGP) that models computation possible in an isolated execution environment with unbounded leakage, and thus in the face of arbitrary side-channels. A SGP specifically models the capabilities of trusted hardware that can attest to correct execution of a piece of code, but whose execution is transparent, meaning that an application's secrets and state are visible to other processes on the same host. Despite this strong threat model, we show that SGPs enable a range of practical applications. Our key observation is that SGPs permit safe verifiable computing in zero-knowledge, as data leakage results only in the prover learning her own secrets. Among other applications, we describe the implementation of an end-to-end bug bounty (or zero-day solicitation) platform that couples a SGX-based SGP with a smart contract. Our platform enables a marketplace that achieves fair exchange, protects against unfair bounty withdrawals, and resists denial-of-service attacks by dishonest sellers. We also consider a slight relaxation of the SGP model that permits black-box modules instantiating minimal, side-channel resistant primitives, yielding a still broader range of applications. Our work shows how trusted hardware systems such as SGX can support trustworthy applications even in the presence of side channels. Florian Tramèr, Fan Zhang 0022, Huang Lin, Jean-Pierre Hubaux, Ari Juels, Elaine Shi |
EuroS&P | 5 |
| 2017 | ROTE: Rollback Protection for Trusted Execution
Sinisa Matetic, Mansoor Ahmed, Kari Kostiainen, Aritra Dhar, David M. Sommer 0001, Arthur Gervais, Ari Juels, Srdjan Capkun |
USENIX Security Symposium | 7 |
| 2017 | REM: Resource-Efficient Mining for Blockchains
Fan Zhang 0022, Ittay Eyal, Robert Escriva, Ari Juels, Robbert van Renesse |
USENIX Security Symposium | 4 |
| 2016 | The Ring of Gyges: Investigating the Future of Criminal Smart ContractsabstractThanks to their anonymity (pseudonymity) and elimination of trusted intermediaries, cryptocurrencies such as Bitcoin have created or stimulated growth in many businesses and communities. Unfortunately, some of these are criminal, e.g., money laundering, illicit marketplaces, and ransomware. Next-generation cryptocurrencies such as Ethereum will include rich scripting languages in support of smart contracts, programs that autonomously intermediate transactions. In this paper, we explore the risk of smart contracts fueling new criminal ecosystems. Specifically, we show how what we call criminal smart contracts (CSCs) can facilitate leakage of confidential information, theft of cryptographic keys, and various real-world crimes (murder, arson, terrorism). Ari Juels, Ahmed E. Kosba, Elaine Shi |
CCS | 1 |
| 2016 | Town Crier: An Authenticated Data Feed for Smart ContractsabstractSmart contracts are programs that execute autonomously on blockchains. Their key envisioned uses (e.g. financial instruments) require them to consume data from outside the blockchain (e.g. stock quotes). Trustworthy data feeds that support a broad range of data requests will thus be critical to smart contract ecosystems. Fan Zhang 0022, Ethan Cecchetti, Kyle Croman, Ari Juels, Elaine Shi |
CCS | 4 |
| 2016 | pASSWORD tYPOS and How to Correct Them SecurelyabstractWe provide the first treatment of typo-tolerant password authentication for arbitrary user-selected passwords. Such a system, rather than simply rejecting a login attempt with an incorrect password, tries to correct common typographical errors on behalf of the user. Limited forms of typo-tolerance have been used in some industry settings, but to date there has been no analysis of the utility and security of such schemes. We quantify the kinds and rates of typos made by users via studies conducted on Amazon Mechanical Turk and via instrumentation of the production login infrastructure at Dropbox. The instrumentation at Dropbox did not record user passwords or otherwise change authentication policy, but recorded only the frequency of observed typos. Our experiments reveal that almost 10% of login attempts fail due to a handful of simple, easily correctable typos, such as capitalization errors. We show that correcting just a few of these typos would reduce login delays for a significant fraction of users as well as enable an additional 3% of users to achieve successful login. We introduce a framework for reasoning about typo-tolerance, and investigate the seemingly inherent tension here between security and usability of passwords. We use our framework to show that there exist typo-tolerant authentication schemes that can get corrections for "free": we prove they are as secure as schemes that always reject mistyped passwords. Building off this theory, we detail a variety of practical strategies for securely implementing typo-tolerance. Rahul Chatterjee 0001, Anish Athayle, Devdatta Akhawe, Ari Juels, Thomas Ristenpart |
IEEE Symposium on Security and Privacy | 4 |
| 2016 | Stealing Machine Learning Models via Prediction APIs
Florian Tramèr, Fan Zhang 0022, Ari Juels, Michael K. Reiter, Thomas Ristenpart |
USENIX Security Symposium | 3 |
| 2015 | Falcon Codes: Fast, Authenticated LT Codes (Or: Making Rapid Tornadoes Unstoppable)abstractWe introduce Falcon codes, a class of authenticated error correcting codes that are based on LT codes and achieve the following properties, for the first time simultaneously: (1) with high probability, they can correct adversarial corruptions of an encoded message, and (2) they allow very efficient encoding and decoding times, even linear in the message length. Ari Juels, James Kelley, Roberto Tamassia, Nikos Triandopoulos |
CCS | 1 |
| 2015 | A Formal Treatment of Backdoored Pseudorandom Generators
Yevgeniy Dodis, Chaya Ganesh, Alexander Golovnev, Ari Juels, Thomas Ristenpart |
EUROCRYPT (1) | 4 |
| 2015 | Cracking-Resistant Password Vaults Using Natural Language EncodersabstractPassword vaults are increasingly popular applications that store multiple passwords encrypted under a single master password that the user memorizes. A password vault can greatly reduce the burden on a user of remembering passwords, but introduces a single point of failure. An attacker that obtains a user's encrypted vault can mount offline brute-force attacks and, if successful, compromise all of the passwords in the vault. In this paper, we investigate the construction of encrypted vaults that resist such offline cracking attacks and force attackers instead to mount online attacks. Our contributions are as follows. We present an attack and supporting analysis showing that a previous design for cracking-resistant vaults -- the only one of which we are aware -- actually degrades security relative to conventional password-based approaches. We then introduce a new type of secure encoding scheme that we call a natural language encoder (NLE). An NLE permits the construction of vaults which, when decrypted with the wrong master password, produce plausible-looking decoy passwords. We show how to build NLEs using existing tools from natural language processing, such as n-gram models and probabilistic context-free grammars, and evaluate their ability to generate plausible decoys. Finally, we present, implement, and evaluate a full, NLE-based cracking-resistant vault system called NoCrack. Rahul Chatterjee 0001, Joseph Bonneau, Ari Juels, Thomas Ristenpart |
IEEE Symposium on Security and Privacy | 3 |
| 2015 | GenoGuard: Protecting Genomic Data against Brute-Force AttacksabstractSecure storage of genomic data is of great and increasing importance. The scientific community's improving ability to interpret individuals' genetic materials and the growing size of genetic database populations have been aggravating the potential consequences of data breaches. The prevalent use of passwords to generate encryption keys thus poses an especially serious problem when applied to genetic data. Weak passwords can jeopardize genetic data in the short term, but given the multi-decade lifespan of genetic data, even the use of strong passwords with conventional encryption can lead to compromise. We present a tool, called Geno Guard, for providing strong protection for genomic data both today and in the long term. Geno Guard incorporates a new theoretical framework for encryption called honey encryption (HE): it can provide information-theoretic confidentiality guarantees for encrypted data. Previously proposed HE schemes, however, can be applied to messages from, unfortunately, a very restricted set of probability distributions. Therefore, Geno Guard addresses the open problem of applying HE techniques to the highly non-uniform probability distributions that characterize sequences of genetic data. In Geno Guard, a potential adversary can attempt exhaustively to guess keys or passwords and decrypt via a brute-force attack. We prove that decryption under any key will yield a plausible genome sequence, and that Geno Guard offers an information-theoretic security guarantee against message-recovery attacks. We also explore attacks that use side information. Finally, we present an efficient and parallelized software implementation of Geno Guard. Erman Ayday, Jacques Fellay, Jean-Pierre Hubaux, Ari Juels |
IEEE Symposium on Security and Privacy | 5 |
| 2015 | The Pythia PRF Service
Adam Everspaugh, Rahul Chatterjee 0001, Samuel Scott, Ari Juels, Thomas Ristenpart |
USENIX Security Symposium | 4 |
| 2014 | An Epidemiological Study of Malware Encounters in a Large EnterpriseabstractWe present an epidemiological study of malware encounters in a large, multi-national enterprise. Our data sets allow us to observe or infer not only malware presence on enterprise computers, but also malware entry points, network locations of the computers (i.e., inside the enterprise network or outside) when the malware were encountered, and for some web-based malware encounters, web activities that gave rise to them. By coupling this data with demographic information for each host's primary user, such as his or her job title and level in the management hierarchy, we are able to paint a reasonably comprehensive picture of malware encounters for this enterprise. We use this analysis to build a logistic regression model for inferring the risk of hosts encountering malware; those ranked highly by our model have a >3x higher rate of encountering malware than the base rate. We also discuss where our study confirms or refutes other studies and guidance that our results suggest. Ting-Fang Yen, Victor Heorhiadi, Alina Oprea, Michael K. Reiter, Ari Juels |
CCS | 5 |
| 2014 | Cross-Tenant Side-Channel Attacks in PaaS CloudsabstractWe present a new attack framework for conducting cache-based side-channel attacks and demonstrate this framework in attacks between tenants on commercial Platform-as-a-Service (PaaS) clouds. Our framework uses the FLUSH-RELOAD attack of Gullasch et al. as a primitive, and extends this work by leveraging it within an automaton-driven strategy for tracing a victim's execution. We leverage our framework first to confirm co-location of tenants and then to extract secrets across tenant boundaries. We specifically demonstrate attacks to collect potentially sensitive application data (e.g., the number of items in a shopping cart), to hijack user accounts, and to break SAML single sign-on. To the best of our knowledge, our attacks are the first granular, cross-tenant, side-channel attacks successfully demonstrated on state-of-the-art commercial clouds, PaaS or otherwise. Yinqian Zhang, Ari Juels, Michael K. Reiter, Thomas Ristenpart |
CCS | 2 |
| 2014 | Honey Encryption: Security Beyond the Brute-Force Bound
Ari Juels, Thomas Ristenpart |
EUROCRYPT | 1 |
| 2014 | PillarBox: Combating Next-Generation Malware with Fast Forward-Secure Logging
Kevin D. Bowers, Catherine Hart, Ari Juels, Nikos Triandopoulos |
RAID | 3 |
| 2014 | A bodyguard of lies: the use of honey objects in information securityabstractDecoy objects, often labeled in computer security with the term honey, are a powerful tool for compromise detection and mitigation. There has been little exploration of overarching theories or set of principles or properties, however. This short paper (and accompanying keynote talk) briefly explore two properties of honey systems, indistinguishability and secrecy. The aim is to illuminate a broad design space that might encompass a wide array of areas in information security, including access control, the main topic of this symposium. Ari Juels |
SACMAT | 1 |
| 2014 | Permacoin: Repurposing Bitcoin Work for Data PreservationabstractBit coin is widely regarded as the first broadly successful e-cash system. An oft-cited concern, though, is that mining Bit coins wastes computational resources. Indeed, Bit coin's underlying mining mechanism, which we call a scratch-off puzzle (SOP), involves continuously attempting to solve computational puzzles that have no intrinsic utility. We propose a modification to Bit coin that repurposes its mining resources to achieve a more broadly useful goal: distributed storage of archival data. We call our new scheme Perm coin. Unlike Bit coin and its proposed alternatives, Perm coin requires clients to invest not just computational resources, but also storage. Our scheme involves an alternative scratch-off puzzle for Bit coin based on Proofs-of-Retrievability (PORs). Successfully minting money with this SOP requires local, random access to a copy of a file. Given the competition among mining clients in Bit coin, this modified SOP gives rise to highly decentralized file storage, thus reducing the overall waste of Bit coin. Using a model of rational economic agents we show that our modified SOP preserves the essential properties of the original Bit coin puzzle. We also provide parameterizations and calculations based on realistic hardware constraints to demonstrate the practicality of Perm coin as a whole. Andrew Miller 0001, Ari Juels, Elaine Shi, Bryan Parno, Jonathan Katz |
IEEE Symposium on Security and Privacy | 2 |
| 2013 | Beehive: large-scale log analysis for detecting suspicious activity in enterprise networksabstractAs more and more Internet-based attacks arise, organizations are responding by deploying an assortment of security products that generate situational intelligence in the form of logs. These logs often contain high volumes of interesting and useful information about activities in the network, and are among the first data sources that information security specialists consult when they suspect that an attack has taken place. However, security products often come from a patchwork of vendors, and are inconsistently installed and administered. They generate logs whose formats differ widely and that are often incomplete, mutually contradictory, and very large in volume. Hence, although this collected information is useful, it is often dirty. Ting-Fang Yen, Alina Oprea, Kaan Onarlioglu, Todd Leetham, William K. Robertson, Ari Juels, Engin Kirda |
ACSAC | 6 |
| 2013 | Fifth ACM cloud computing security workshop (CCSW 2013)abstractThe Cloud Computing Security Workshop (CCSW) focuses on the security challenges and opportunities raised by cloud computing. The ``cloud'' is a general term for aggregation of computing resources within an extensive, elastic environment typically marked by a high degree of resource virtualization and sharing among tenants. As a multi-faceted trend, cloud computing creates many and varied security and privacy requirements at the intersection of a broad range of disciplines. The goal of the workshop is to elucidate the security and privacy problems raised by cloud computing and foster understanding of the connection between research and practice in this vibrant and transformative area. Ari Juels, Bryan Parno |
CCS | 1 |
| 2013 | Honeywords: making password-cracking detectableabstractWe propose a simple method for improving the security of hashed passwords: the maintenance of additional ``honeywords'' (false passwords) associated with each user's account. An adversary who steals a file of hashed passwords and inverts the hash function cannot tell if he has found the password or a honeyword. The attempted use of a honeyword for login sets off an alarm. An auxiliary server (the ``honeychecker'') can distinguish the user password from honeywords for the login routine, and will set off an alarm if a honeyword is submitted. Ari Juels, Ronald L. Rivest |
CCS | 1 |
| 2013 | Heart-to-heart (H2H): authentication for implanted medical devicesabstractWe present Heart-to-Heart (H2H), a system to authenticate external medical device controllers and programmers to Implantable Medical Devices (IMDs). IMDs, which include pacemakers and cardiac defibrillators, are therapeutic medical devices partially or wholly embedded in the human body. They often have built-in radio communication to facilitate non-invasive reprogramming and data readout. Many IMDs, though, lack well designed authentication protocols, exposing patients to over-the-air attack and physical harm. Masoud Rostami, Ari Juels, Farinaz Koushanfar |
CCS | 2 |
| 2013 | Balancing security and utility in medical devices?abstractImplantable Medical Devices (IMDs) are being embedded increasingly often in patients' bodies to monitor and help treat medical conditions. To facilitate monitoring and control, IMDs are often equipped with wireless interfaces. While convenient, wireless connectivity raises the risk of malicious access to an IMD that can potentially infringe patients' privacy and even endanger their lives. Masoud Rostami, Wayne P. Burleson, Farinaz Koushanfar, Ari Juels |
DAC | 4 |
| 2013 | Drifting Keys: Impersonation detection for constrained devicesabstractWe introduce Drifting Keys (DKs), a simple new approach to detecting device impersonation. DKs enable detection of complete compromise by an attacker of the device and its secret state, e.g., cryptographic keys. A DK evolves within a device randomly over time. Thus an attacker will create DKs that randomly diverge from those in the original, valid device over time, alerting a trusted verifier to the attack. DKs may be transmitted unidirectionally from a device, eliminating interaction between the device and verifier. Device emissions of DK values can be quite compact - even just a single bit - and DK evolution and emission require minimal computation. Thus DKs are well suited for highly constrained devices, such as sensors and hardware authentication tokens. We offer a formal adversarial model for DKs, and present a simple scheme that we prove essentially optimal (undominated) for a natural class of attack timelines. We explore application of this scheme to one-time passcode authentication tokens. Using the logs of a large enterprise, we experimentally study the effectiveness of DKs in detecting the compromise of such tokens. Kevin D. Bowers, Ari Juels, Ronald L. Rivest, Emily Shen |
INFOCOM | 2 |
| 2013 | Tailing RFID Tags for Clone Detection
Davide Zanetti, Srdjan Capkun, Ari Juels |
NDSS | 3 |
| 2013 | FlipIt: The Game of "Stealthy Takeover"
Marten van Dijk, Ari Juels, Alina Oprea, Ronald L. Rivest |
J. Cryptol. | 2 |
| 2012 | Iris: a scalable cloud file system with efficient integrity checksabstractWe present Iris, a practical, authenticated file system designed to support workloads from large enterprises storing data in the cloud and be resilient against potentially untrustworthy service providers. As a transparent layer enforcing strong integrity guarantees, Iris lets an enterprise tenant maintain a large file system in the cloud. In Iris, tenants obtain strong assurance not just on data integrity, but also on data freshness, as well as data retrievability in case of accidental or adversarial cloud failures. Emil Stefanov, Marten van Dijk, Ari Juels, Alina Oprea |
ACSAC | 3 |
| 2012 | Hourglass schemes: how to prove that cloud files are encryptedabstractWe consider the following challenge: How can a cloud storage provider prove to a tenant that it's encrypting files at rest, when the provider itself holds the corresponding encryption keys? Such proofs demonstrate sound encryption policies and file confidentiality. (Cheating, cost-cutting, or misconfigured providers may bypass the computation/management burdens of encryption and store plaintext only.) Marten van Dijk, Ari Juels, Alina Oprea, Ronald L. Rivest, Emil Stefanov, Nikos Triandopoulos |
CCS | 2 |
| 2012 | Cross-VM side channels and their use to extract private keysabstractThis paper details the construction of an access-driven side-channel attack by which a malicious virtual machine (VM) extracts fine-grained information from a victim VM running on the same physical computer. This attack is the first such attack demonstrated on a symmetric multiprocessing system virtualized using a modern VMM (Xen). Such systems are very common today, ranging from desktops that use virtualization to sandbox application or OS compromises, to clouds that co-locate the workloads of mutually distrustful customers. Constructing such a side-channel requires overcoming challenges including core migration, numerous sources of channel noise, and the difficulty of preempting the victim with sufficient frequency to extract fine-grained information from it. This paper addresses these challenges and demonstrates the attack in a lab setting by extracting an ElGamal decryption key from a victim using the most recent version of the libgcrypt cryptographic library. Yinqian Zhang, Ari Juels, Michael K. Reiter, Thomas Ristenpart |
CCS | 2 |
| 2012 | More for your money: exploiting performance heterogeneity in public cloudsabstractInfrastructure-as-a-system compute clouds such as Amazon's EC2 allow users to pay a flat hourly rate to run their virtual machine (VM) on a server providing some combination of CPU access, storage, and network. But not all VM instances are created equal: distinct underlying hardware differences, contention, and other phenomena can result in vastly differing performance across supposedly equivalent instances. The result is striking variability in the resources received for the same price. Benjamin Farley, Ari Juels, Venkatanathan Varadarajan, Thomas Ristenpart, Kevin D. Bowers, Michael M. Swift |
SoCC | 2 |
| 2011 | How to tell if your cloud files are vulnerable to drive crashesabstractThis paper presents a new challenge--verifying that a remote server is storing a file in a fault-tolerant manner, i.e., such that it can survive hard-drive failures. We describe an approach called the Remote Assessment of Fault Tolerance (RAFT). The key technique in a RAFT is to measure the time taken for a server to respond to a read request for a collection of file blocks. The larger the number of hard drives across which a file is distributed, the faster the read-request response. Erasure codes also play an important role in our solution. We describe a theoretical framework for RAFTs and offer experimental evidence that RAFTs can work in practice in several settings of interest. Kevin D. Bowers, Marten van Dijk, Ari Juels, Alina Oprea, Ronald L. Rivest |
CCS | 3 |
| 2011 | Exploring implicit memory for painless password recoveryabstractKnowledge-based authentication systems generally rely upon users' explicit recollection of passwords, facts, or personal preferences. These systems impose a cognitive burden that often results in forgotten secrets or secrets with poor entropy. We propose an authentication system that instead draws on implicit memory - that is, the unconscious encoding and usage of information. In such a system, a user is initially presented with images of common objects in a casual familiarization task. When the user later authenticates, she is asked to perform a task involving a set of degraded images, some of which are based upon the images in the familiarization task. The prior exposure to those images influences the user's responses in the task, thereby eliciting authentication information. We ran a user study to investigate the plausibility of our system design. Our results suggest that implicit memory has potential as a basis for low-cognitive-overhead, high-stability, knowledge-based authentication. Tamara Denning, Kevin D. Bowers, Marten van Dijk, Ari Juels |
CHI | 4 |
| 2011 | HomeAlone: Co-residency Detection in the Cloud via Side-Channel AnalysisabstractSecurity is a major barrier to enterprise adoption of cloud computing. Physical co-residency with other tenants poses a particular risk, due to pervasive virtualization in the cloud. Recent research has shown how side channels in shared hardware may enable attackers to exfiltrate sensitive data across virtual machines (VMs). In view of such risks, cloud providers may promise physically isolated resources to select tenants, but a challenge remains: Tenants still need to be able to verify physical isolation of their VMs. We introduce Home Alone, a system that lets a tenant verify its VMs' exclusive use of a physical machine. The key idea in Home Alone is to invert the usual application of side channels. Rather than exploiting a side channel as a vector of attack, Home Alone uses a side-channel (in the L2 memory cache) as a novel, defensive detection tool. By analyzing cache usage during periods in which "friendly" VMs coordinate to avoid portions of the cache, a tenant using Home Alone can detect the activity of a co-resident "foe" VM. Key technical contributions of Home Alone include classification techniques to analyze cache usage and guest operating system kernel modifications that minimize the performance impact of friendly VMs sidestepping monitored cache portions. Home Alone requires no modification of existing hyper visors and no special action or cooperation by the cloud provider. Yinqian Zhang, Ari Juels, Alina Oprea, Michael K. Reiter |
IEEE Symposium on Security and Privacy | 2 |
| 2010 | A Clean-Slate Look at Disk Scrubbing
Alina Oprea, Ari Juels |
FAST | 2 |
| 2010 | On the Impossibility of Cryptography Alone for Privacy-Preserving Cloud Computing
Marten van Dijk, Ari Juels |
HotSec | 2 |
| 2009 | HAIL: a high-availability and integrity layer for cloud storageabstractWe introduce HAIL (High-Availability and Integrity Layer), a distributed cryptographic system that allows a set of servers to prove to a client that a stored file is intact and retrievable. HAIL strengthens, formally unifies, and streamlines distinct approaches from the cryptographic and distributed-systems communities. Proofs in HAIL are efficiently computable by servers and highly compact---typically tens or hundreds of bytes, irrespective of file size. HAIL cryptographically verifies and reactively reallocates file shares. It is robust against an active, mobile adversary, i.e., one that may progressively corrupt the full set of servers. We propose a strong, formal adversarial model for HAIL, and rigorous analysis and parameter choices. We show how HAIL improves on the security and efficiency of existing tools, like Proofs of Retrievability (PORs) deployed on individual servers. We also report on a prototype implementation. Kevin D. Bowers, Ari Juels, Alina Oprea |
CCS | 2 |
| 2009 | EPC RFID tag security weaknesses and defenses: passport cards, enhanced drivers licenses, and beyondabstractEPC (Electronic Product Code) tags are industry-standard RFID devices poised to supplant optical barcodes in many applications. We explore the systemic risks and challenges created by the increasingly common use of EPC for security applications. As a central case study, we examine the recently issued United States Passport Card and Washington State "enhanced drivers license" (WA EDL), both of which incorporate Gen-2 EPC tags. We measure multiple weaknesses, including susceptibility to cloning, extended read ranges, and the ability to remotely kill a WA EDL. We study the implications of these vulnerabilities to overall system security, and offer suggestions for improvement. We demonstrate anti-cloning techniques for off-the-shelf EPC tags, overcoming practical challenges in a previous proposal to co-opt the EPC "kill" command to achieve tag authentication. Our paper fills a vacuum of experimentally grounded evaluation of and guidance for security applications for EPC tags not just in identity documents, but more broadly in the authentication of objects and people. Karl Koscher, Ari Juels, Vjekoslav Brajkovic, Tadayoshi Kohno |
CCS | 2 |
| 2009 | Server-side detection of malware infectionabstractWe review the intertwined problems of malware and online fraud, and argue that the fact that service providers often are nancially responsible for fraud causes a relative lack of incentives for clients to manage their own security well. This suggests the need for a server-side tool to determine the security posture of clients before letting them transact. Markus Jakobsson, Ari Juels |
NSPW | 2 |
| 2009 | CCCP: Secure Remote Storage for Computational RFIDs
Mastooreh Salajegheh, Shane S. Clark, Benjamin Ransford, Kevin Fu, Ari Juels |
USENIX Security Symposium | 5 |
| 2009 | Defining strong privacy for RFIDabstractIn this work, we consider privacy in Radio Frequency IDentification (RFID) systems. Our contribution is twofold: (i) We propose a simple, formal definition of strong privacy useful for basic analysis of RFID systems, as well as a different (weaker) definition applicable to multiverifier systems; (ii) We apply our definition to reveal vulnerabilities in several proposed privacy-enhancing RFID protocols; and (iii) We formally analyze and suggest improvements to hash-locks, one of the first privacy-enhancing RFID protocols in the literature. Ari Juels, Stephen A. Weis |
ACM Trans. Inf. Syst. Secur. | 1 |
| 2008 | Unidirectional Key Distribution Across Time and Space with Applications to RFID Security
Ari Juels, Ravikanth Pappu, Bryan Parno |
USENIX Security Symposium | 1 |
| 2008 | RFID security: in the shoulder and on the loading dockabstractRFID (Radio-Frequency IDentification) tags are microchips that communicate via radio. In common use today, they promise to become a ubiquitous tool for labeling objects and identifying people. Protection against counterfeiting and privacy infringement in RFID systems is therefore an imperative. The unifying theme of this two-part talk is key distribution, a perennial security challenge in computing systems that is particularly tricky for RFID. I'll discuss human-implantable RFID devices and the intricate privacy and security problems associated with these prosthetic biometrics. I'll then introduce a new approach to distributing the keys required for privacy protection and authentication in RFID-enhanced supply chains - tracing the lifecycle of tags from the warehouse to the loading dock to the hands of the consumer. Ari Juels |
WISEC | 1 |
| 2008 | RFID security and privacy: long-term research or short-term tinkering?abstractRFID technology has raised a number of both real and imagined security and privacy fears and concerns. Since roughly 2001, a number of researchers have stepped up to the plate and proposed techniques for strengthening RFID security and privacy, while others have focused on attacking (and demonstrating weaknesses in) currently deployed RFID systems. Despite a few PhD theses devoted to this topic, it remains to be seen whether there are any new long-term fundamental issues involved in RFID security & privacy. Therefore, this panel's goal is to present and debate the panelists' diverse perspectives on the future (or lack thereof) of RFID security and privacy research. Gene Tsudik, Mike Burmester, Ari Juels, Alfred Kobsa, David Molnar, Roberto Di Pietro, Melanie R. Rieback |
WISEC | 3 |
| 2007 | Two-Party Computing with Encrypted Data
Seung Geol Choi, Ariel Elbaz, Ari Juels, Tal Malkin, Moti Yung |
ASIACRYPT | 3 |
| 2007 | Covert channels in privacy-preserving identification systemsabstractWe examine covert channels in privacy-enhanced mobile identification devices where the devices uniquely identify themselves to an authorized verifier. Such devices (e.g. RFID tags) are increasingly commonplace in hospitals and many other environments. For privacy, the device outputs used for identification should "appear random" to any entity other than the verifier, and should not allow physical tracking of device bearers. Worryingly, there already exist privacy breaches for some devices [28] that allow adversaries to physically track users. Ideally, such devices should allow anyone to publicly determine that the device outputs are covert-channel free (CCF); we say that such devices are CCF-checkable. Daniel V. Bailey, Dan Boneh, Eu-Jin Goh, Ari Juels |
CCS | 4 |
| 2007 | Pors: proofs of retrievability for large filesabstractIn this paper, we define and explore proofs of retrievability (PORs). A POR scheme enables an archive or back-up service (prover) to produce a concise proof that a user (verifier) can retrieve a target file F, that is, that the archive retains and reliably transmits file data sufficient for the user to recover F in its entirety. Ari Juels, Burton S. Kaliski Jr. |
CCS | 1 |
| 2007 | Combating Click Fraud via Premium Clicks
Ari Juels, Sid Stamm, Markus Jakobsson |
USENIX Security Symposium | 1 |
| 2007 | In Response to: Letter to the Editor Regarding: "A Security Analysis of the Verichip Implantable RFID Device"abstractTo the Editor, In our article, we cited a book co-authored by Katherine Albrecht entitled Spychips: Why Christians Should Resist RFID and Electronic Surveillance. We made the citation in support of our statement that, “Religious groups have gone so far as to claim that the VeriChip may be a realization of the Mark of the Beast as described in the New Testament.” We believe that our citation was appropriate. Even in Ms. Albrecht's largely identical, secularly-oriented book, SpyChips: How Major Corporations and Government Plan to Track Your Every Move with RFID, there is a sidebar entitled, “Payment Implants and the Mark of the Beast.” It reads: The RFID implant device, [sic] known variously as the VeriChip, or VeriPay, sets off alarm bells for a lot of Christians. Many believe it may be the fulfilllment [sic] of a prophecy made back at the time of Christ. Revelation, the last book of the Bible, describes a time when all people will have to take a mark in order to buy or sell … John D. Halamka, Ari Juels |
J. Am. Medical Informatics Assoc. | 2 |
| 2006 | Fourth-factor authentication: somebody you knowabstractUser authentication in computing systems traditionally depends on three factors: something you have (e.g., a hardware token), something you are (e.g., a fingerprint), and something you know (e.g., a password). In this paper, we explore a fourth factor, the social network of the user, that is, somebody you know.Human authentication through mutual acquaintance is an age-old practice. In the arena of computer security, it plays roles in privilege delegation, peer-level certification, help-desk assistance, and reputation networks. As a direct means of logical authentication, though, the reliance of human being on another has little supporting scientific literature or practice.In this paper, we explore the notion of vouching, that is, peer-level, human-intermediated authentication for access control. We explore its use in emergency authentication, when primary authenticators like passwords or hardware tokens become unavailable. We describe a practical, prototype vouching system based on SecurID, a popular hardware authentication token. We address traditional, cryptographic security requirements, but also consider questions of social engineering and user behavior. John G. Brainard, Ari Juels, Ronald L. Rivest, Michael Szydlo, Moti Yung |
CCS | 2 |
| 2006 | The Outer Limits of RFID Security
Ari Juels |
CHES | 1 |
| 2006 | Cache Cookies for Browser Authentication (Extended Abstract)abstractLike conventional cookies, cache cookies are data objects that servers store in Web browsers. Cache cookies, however, are unintentional byproducts of protocol design for browser caches. They do not enjoy any explicit interface support or security policies. In this paper, we show that despite limitations, cache cookies can play a useful role in the identification and authentication of users. Many users today block conventional cookies in their browsers as a privacy measure. The cache-cookie tools we propose can help restore lost usability and convenience to such users while maintaining good privacy. As we show, our techniques can also help combat online security threats such as phishing and pharming that ordinary cookies cannot. The ideas we introduce for cache-cookie management can strengthen ordinary cookies as well. The full version of this paper may be referenced at www.ravenwhite.com. Ari Juels, Markus Jakobsson, Tom N. Jagatic |
S&P | 1 |
| 2006 | A Fuzzy Vault Scheme
Ari Juels, Madhu Sudan 0001 |
Des. Codes Cryptogr. | 1 |
| 2006 | Technology Evaluation: The Security Implications of VeriChip CloningabstractThe VeriChip is a Radio-Frequency Identification (RFID) tag produced commercially for implantation in human beings. Its proposed uses include identification of medical patients, physical access control, contactless retail payment, and even the tracing of kidnapping victims. As the authors explain, the VeriChip is vulnerable to simple, over-the-air spoofing attacks. In particular, an attacker capable of scanning a VeriChip, eavesdropping on its signal, or simply learning its serial number can create a spoof device whose radio appearance is indistinguishable from the original. We explore the practical implications of this security vulnerability. The authors argue that:1 The VeriChip should serve exclusively for identification, and not authentication or access control. 2 Paradoxically, for bearer safety, a VeriChip should be easy to spoof; an attacker then has less incentive to coerce victims or extract VeriChips from victims' bodies. John D. Halamka, Ari Juels, Adam Stubblefield, Jonathan Westhues |
J. Am. Medical Informatics Assoc. | 2 |
| 2006 | RFID security and privacy: a research surveyabstractThis paper surveys recent technical research on the problems of privacy and security for radio frequency identification (RFID). RFID tags are small, wireless devices that help identify objects and people. Thanks to dropping cost, they are likely to proliferate into the billions in the next several years-and eventually into the trillions. RFID tags track objects in supply chains, and are working their way into the pockets, belongings, and even the bodies of consumers. This survey examines approaches proposed by scientists for privacy protection and integrity assurance in RFID systems, and treats the social and technical context of their work. While geared toward the nonspecialist, the survey may also serve as a reference for specialist readers. Ari Juels |
IEEE J. Sel. Areas Commun. | 1 |
| 2005 | Authenticating Pervasive Devices with Human Protocols
Ari Juels, Stephen A. Weis |
CRYPTO | 1 |
| 2005 | Security and Privacy Issues in E-passportsabstractWithin the next year, travelers from dozens of nations may be carrying a new form of passport in response to a mandate by the United States government. The e-passport, as it is sometimes called, represents a bold initiative in the deployment of two new technologies: Radio-Frequency Identification (RFID) and biometrics. Important in their own right, e-passports are also the harbinger of a wave of next-generation ID cards: several national governments plan to deploy identity cards integrating RFID and biometrics for domestic use. We explore the privacy and security implications of this impending worldwide experiment in next-generation authentication technology. We describe privacy and security issues that apply to e-passports, then analyze these issues in the context of the International Civil Aviation Organization (ICAO) standard for e-passports. 1 Ari Juels, David Molnar, David A. Wagner 0001 |
SecureComm | 1 |
| 2005 | Security Analysis of a Cryptographically-Enabled RFID Device
Steve Bono, Matthew Green 0001, Adam Stubblefield, Ari Juels, Aviel D. Rubin, Michael Szydlo |
USENIX Security Symposium | 4 |
| 2004 | Parallel mixingabstractEfforts to design faster synchronous mix networks have focused on reducing the computational cost of mixing per server. We propose a different approach: our reencryption mixnet allows servers to mix inputs in parallel. The result is a dramatic reduction in overall mixing time for moderate-to-large numbers of servers. As measured in the model we describe, for n inputs and $M$ servers our parallel re encryption mixnet produces output in time at most 2n -- and only around n assuming a majority of honest servers. In contrast, a traditional, sequential, synchronous re-encryption mixnet requires time Mn. Philippe Golle, Ari Juels |
CCS | 2 |
| 2004 | New client puzzle outsourcing techniques for DoS resistanceabstractWe explore new techniques for the use of cryptographic puzzles as a countermeasure to Denial-of-Service (DoS) attacks. We propose simple new techniques that permit the out-sourcing of puzzles; their distribution via a robust external service that we call a bastion. Many servers can rely on puzzles distributed by a single bastion. We show how a bastion, somewhat surprisingly, need not know which servers rely on its services. Indeed, in one of our constructions, a bastion may consist merely of a publicly accessible random data source, rather than a special purpose server. Our out-sourcing techniques help eliminate puzzle distribution as a point of compromise. Brent Waters, Ari Juels, J. Alex Halderman, Edward W. Felten |
CCS | 2 |
| 2004 | Universal Re-encryption for Mixnets
Philippe Golle, Markus Jakobsson, Ari Juels, Paul F. Syverson |
CT-RSA | 3 |
| 2004 | Dining Cryptographers Revisited
Philippe Golle, Ari Juels |
EUROCRYPT | 2 |
| 2004 | RFID: Security and Privacy for Five-Cent Computers
Ari Juels |
USENIX Security Symposium | 1 |
| 2003 | The blocker tag: selective blocking of RFID tags for consumer privacyabstractWe propose the use of selective blocking by as a way of protecting consumers from unwanted scanning of RFID tags attached to items they may be carrying or wearing.While an ordinary RFID tag is a simple, cheap (e.g. five-cent) passive device intended as an electronic bar-code for use in supply-chain management, a blocker tag is a cheap passive RFID device that can simulate many ordinary RFID tags simultaneously. When carried by a consumer, a blocker tag thus blocks RFID readers. It can do so universally by simulating all possible RFID tags. Or a blocker tag can block selectively by simulating only selected subsets of ID codes, such as those by a particular manufacturer, or those in a designated zone.We believe that this approach, when used with appropriate care, provides a very attractive alternative for addressing privacy concerns raised by the potential (and likely) widespread use of RFID tags in consumer products.We also discuss possible abuses arising from blocker tags, and means for detecting and dealing with them. Ari Juels, Ronald L. Rivest, Michael Szydlo |
CCS | 1 |
| 2003 | A New Two-Server Approach for Authentication with Short Secrets
John G. Brainard, Ari Juels, Burton S. Kaliski Jr., Michael Szydlo |
USENIX Security Symposium | 2 |
| 2002 | Optimistic Mixing for Exit-Polls
Philippe Golle, Sheng Zhong 0002, Dan Boneh, Markus Jakobsson, Ari Juels |
ASIACRYPT | 5 |
| 2002 | Proprietary Certificates
Markus Jakobsson, Ari Juels, Phong Q. Nguyen |
CT-RSA | 2 |
| 2002 | Making Mix Nets Robust for Electronic Voting by Randomized Partial Checking
Markus Jakobsson, Ari Juels, Ronald L. Rivest |
USENIX Security Symposium | 2 |
| 2001 | Error-tolerant password recoveryabstractMany encryption systems require the user to memorize high entropy passwords or passphrases and reproduce them exactly. This is often a difficult task. We propose a more fault-tolerant scheme, where a high entropy key (or password) is derived from a sequence of low entropy passwords. The user is able to recover the correct key if she remembers a certain percentage of the passwords correctly. In contrast to other systems that have been proposed for fault-tolerant passwords, our basic design is provably secure against a computationally unbounded attacker. Niklas Frykholm, Ari Juels |
CCS | 2 |
| 2001 | Targeted Advertising ... And Privacy Too
Ari Juels |
CT-RSA | 1 |
| 2001 | An optimally robust hybrid mix networkabstractWe present a mix network that achieves efficient integration of public-key and symmetric-key operations. This hybrid mix network is capable of natural processing of arbitrarily long input elements, and is fast in both practical and asymptotic senses. While the overhead in the size of input elements is linear in the number of mix servers, it is quite small in practice. In contrast to previous hybrid constructions, ours has optimal robustness, that is, robustness against any minority coalition of malicious servers. Markus Jakobsson, Ari Juels |
PODC | 2 |
| 2000 | Mix and Match: Secure Function Evaluation via Ciphertexts
Markus Jakobsson, Ari Juels |
ASIACRYPT | 2 |
| 2000 | Addition of ElGamal Plaintexts
Markus Jakobsson, Ari Juels |
ASIACRYPT | 2 |
| 2000 | Funkspiel schemes: an alternative to conventional tamper resistanceabstractWe investigate a simple method of fraud management for secure devices that may serve as an alternative or complement to conventional hardware-based tamper resistance. Under normal operating conditions in our scheme, a secure device includes an authentication code in its communications, e.g., in the digital signatures it issues. This code may be verified by a fraud management center under a pre-determined key σ. When the device detects an attempted break-in, it modifies σ. This results in a change to the authentication codes issued by the device such that the fraud management center can detect the apparent break-in. Hence, in contrast to the case with typical tamper-resistance schemes, the deployer of our proposed scheme seeks to trace break-ins, rather than prevent them. In reference to the wartime practice of physically capturing and subverting underground radio transmitters – a practice analogous to the capture and use of secret information on secure devices – we denote this idea by the German term funkspiel, meaning “radio game.” One challenge in constructing a funkspiel scheme is to ensure that an attacker privy to the authentication codes of the secure device both before and after the break-in, as well as the secrets of the device following the break-in, cannot detect the alteration to σ. Additional challenges ∗Some of this work was done while visiting RSA Laboratories. Johan Håstad, Jakob Jonsson, Ari Juels, Moti Yung |
CCS | 3 |
| 2000 | Hiding Cliques for Cryptographic Security
Ari Juels, Marcus Peinado |
Des. Codes Cryptogr. | 1 |
| 2000 | How to turn loaded dice into fair coinsabstractWe present a new technique for simulating fair coin flips using a biased, stationary source of randomness. Sequences of random numbers are of pervasive importance in cryptography and vital to many other computing applications. Many sources of randomness, such as radioactive or quantum-mechanical sources, possess the property of stationarity. In other words, they produce independent outputs over fixed probability distributions. The output of such sources may be viewed as the result of rolling a biased or loaded die. While a biased die may be a good source of entropy, many applications require input in the form of unbiased bits, rather than biased ones. For this reason, von Neumann (1951) presented a now well-known and extensively investigated technique for using a biased coin to simulate a fair coin. We describe a new generalization of von Neumann's algorithm distinguished by its high level of practicality and amenability to analysis. In contrast to previous efforts, we are able to prove our algorithm optimally efficient, in the sense that it simulates the maximum possible number of fair coin flips for a given number of die rolls. In fact, we are able to prove that in an asymptotic sense our algorithm extracts the full entropy of its input. Moreover, we demonstrate experimentally that our algorithm achieves a high level of computational and output efficiency in a practical setting. Ari Juels, Markus Jakobsson, Elizabeth A. M. Shriver, Bruce Hillyer |
IEEE Trans. Inf. Theory | 1 |
| 1999 | A Fuzzy Commitment SchemeabstractWe combine well-known techniques from the areas of error-correcting codes and cryptography to achieve a new type of cryptographic primitive that we refer to as a fuzzy commitment scheme. Like a conventional cryptographic commitment scheme, our fuzzy commitment scheme is both concealing and binding: it is infeasible for an attacker to learn the committed value, and also for the committer to decommit a value in more than one way. In a conventional scheme, a commitment must be opened using a unique witness, which acts, essentially, as a decryption key. By contrast, our scheme is fuzzy in the sense that it accepts a witness that is close to the original encrypting witness in a suitable metric, but not necessarily identical. Ari Juels, Martin Wattenberg |
CCS | 1 |
| 1999 | Client Puzzles: A Cryptographic Countermeasure Against Connection Depletion Attacks
Ari Juels, John G. Brainard |
NDSS | 1 |
| 1998 | A Practical Secure Physical Random Bit GeneratorabstractWe sugg=t a practical and economical way to generate random bits using a computer disk drive * a source of randomn-.It requirw no additiond hardware (given a system with a disk), and no user involvement.As a concrete example of performance, on a Sun Wtra-1 with a Seagate Cheetah disk, it generatw bits at a rate of either 5 bits per minute or 577 bits per minute depending on the physical phenomena that we use = a source of randomness.The generated bits are random by a theoretical argument, and *O pass a severe battery of statiaticrd twts. 'InformationSciences Research Center, Bell Laboratories.{m=hsj ,sbriver,bruce} arese=.h.bell-labs .com Markus Jakobsson, Elizabeth A. M. Shriver, Bruce Hillyer, Ari Juels |
CCS | 4 |
| 1998 | Hiding Cliques for Cryptographic Security
Ari Juels, Marcus Peinado |
SODA | 1 |
| 1997 | Security of Blind Digital Signatures (Extended Abstract)
Ari Juels, Michael Luby, Rafail Ostrovsky |
CRYPTO | 1 |
| 1995 | Stochastic Hillclimbing as a Baseline Mathod for Evaluating Genetic Algorithms
Ari Juels, Martin Wattenberg |
NIPS | 1 |