中文
相关论文

相关论文: On the Security of SSH Client Signatures

200 篇论文

Within a trust infrastructure, a private key is often used to digitally sign a transaction, which can be verified with an associated public key. Using PKI (Public Key Infrastructure), a trusted entity can produce a digital signature,…

密码学与安全 · 计算机科学 2023-10-11 Sam Grierson , William J Buchanan , Craig Thomson , Baraq Ghaleb , Leandros Maglaras , Chris Eckl

Developers and organizations are using Large Language Models (LLMs) to generate security-critical code more frequently than ever, including cryptographic solutions for their products. This study presents an empirical evaluation of…

密码学与安全 · 计算机科学 2026-05-01 Mohamed Elsayed , Kenneth Fulton , Jeong Yang

Group oriented applications are getting more and more popular in mobile Internet and call for secure and efficient secret sharing (SS) scheme to meet their requirements. A $(t,n)$ threshold SS scheme divides a secret into $n$ shares such…

密码学与安全 · 计算机科学 2021-04-13 Fuyou Miao , Yue Yu , Keju Meng , Wenchao Huang , Yan Xiong

Mobile mini-programs in WeChat have gained significant popularity since their debut in 2017, reaching a scale similar to that of Android apps in the Play Store. Like Google, Tencent, the provider of WeChat, offers APIs to support the…

密码学与安全 · 计算机科学 2023-06-16 Yue Zhang , Yuqing Yang , Zhiqiang Lin

Self-Sovereign Digital Identity (SSDI) enables individuals to control their own identity assertions and data, rather than relying on centralized or federated systems prone to large-scale data breaches. By eliminating centralized databases…

密码学与安全 · 计算机科学 2026-03-13 Sushanth Ambati , Kainat Adeel , Jack Myers , Nikolay Ivanov

The advent of end-to-end encrypted (E2EE) messaging and backup services has brought new challenges for usable authentication. Compared to regular web services, the nature of E2EE implies that the provider cannot recover data for users who…

密码学与安全 · 计算机科学 2024-06-27 Jenny Blessing , Daniel Hugenroth , Ross J. Anderson , Alastair R. Beresford

Sniffing is one of the most prominent causes for most of the attacks in the digitized computing environment. Through various packet analyzers or sniffers available free of cost, the network packets can be captured and analyzed. The…

密码学与安全 · 计算机科学 2019-07-31 B. Prabadevi , N. Jeyanthi , Nur Izura Udzir , Dhinaharan Nagamalai

The security of modern electronic devices relies on secret keys stored on secure hardware modules as the root-of-trust (RoT). Extracting those keys would break the security of the entire system. As shown before, sophisticated side-channel…

密码学与安全 · 计算机科学 2021-02-24 Thilo Krachenfels , Tuba Kiyan , Shahin Tajik , Jean-Pierre Seifert

Recent studies have shown that a significant number of mobile applications, often handling sensitive data such as bank accounts and login credentials, suffers from SSL vulnerabilities. Most of the time, these vulnerabilities are due to…

密码学与安全 · 计算机科学 2013-07-01 Mauro Conti , Nicola Dragoni , Sebastiano Gottardo

Scalability is a common issue among the most used permissionless blockchains, and several approaches have been proposed accordingly. As Ethereum is set to be a solid foundation for a decentralized Internet web, the need for tackling…

密码学与安全 · 计算机科学 2021-01-01 Mikel Cortes-Goicoechea , Luca Franceschini , Leonardo Bautista-Gomez

The possibility of fingerprinting the search keywords issued by a user on popular web search engines is a significant threat to user privacy. This threat has received surprisingly little attention in the network traffic analysis literature.…

密码学与安全 · 计算机科学 2020-08-20 Junhua Yan , Hasan Faik Alan , Jasleen Kaur

In the digital era, accidental exposure of sensitive information such as API keys, tokens, and credentials is a growing security threat. While most prior work focuses on detecting secrets in source code, leakage in software issue reports…

软件工程 · 计算机科学 2026-04-17 Sadif Ahmed , Md Nafiu Rahman , Zahin Wahab , Gias Uddin , Rifat Shahriyar

Commit signing is a principal mechanism for verifying the origin of code in software supply chains. Security frameworks treat it as a core trust signal, assuming developers sign their commits consistently with keys they control and keep…

软件工程 · 计算机科学 2026-05-01 Abubakar Sadiq Shittu , John Sadik , Farzin Gholamrezae , Scott Ruoti

We present three private fingerprint alignment and matching protocols, based on what are considered to be the most precise and efficient fingerprint recognition algorithms, which use minutia points. Our protocols allow two or more…

密码学与安全 · 计算机科学 2017-12-19 Fattaneh Bayatbabolghani , Marina Blanton , Mehrdad Aliasgari , Michael Goodrich

Threshold Signature Scheme (TSS) protocols have gained significant attention over the past ten years due to their widespread adoption in cryptocurrencies. The adoption is mainly boosted by Gennaro and Goldfedder's TSS protocol. Since then,…

密码学与安全 · 计算机科学 2025-03-13 Faneela , Jawad Ahmad , Baraq Ghaleb , Imdad Ullah Khan , William J. Buchanan , Sana Ullah Jan , Muhammad Shahbaz Khan

This paper presents a timing attack on the FIDO2 (Fast IDentity Online) authentication protocol that allows attackers to link user accounts stored in vulnerable authenticators, a serious privacy concern. FIDO2 is a new standard specified by…

密码学与安全 · 计算机科学 2022-05-18 Michal Kepkowski , Lucjan Hanzlik , Ian Wood , Mohamed Ali Kaafar

In this paper, we propose a novel class of symmetric key distribution protocols that leverages basic security primitives offered by low-cost, hardware chipsets containing millions of synchronized self-powered timers. The keys are derived…

密码学与安全 · 计算机科学 2022-01-19 Mustafizur Rahman , Liang Zhou , Shantanu Chakrabartty

The problem of secret-key based authentication under a privacy constraint on the source sequence is considered. The identifier measurements during authentication are assumed to be controllable via a cost-constrained "action" sequence.…

信息论 · 计算机科学 2020-02-27 Onur Günlü , Kittipong Kittichokechai , Rafael F. Schaefer , Giuseppe Caire

Signed social networks are widely used to model the trust relationships among online users in security-sensitive systems such as cryptocurrency trading platforms, where trust prediction plays a critical role. In this paper, we investigate…

密码学与安全 · 计算机科学 2023-07-18 Yulin Zhu , Tomasz Michalak , Xiapu Luo , Xiaoge Zhang , Kai Zhou

The widespread use of wireless sensor networks (WSNs) that are consisted of resource-constrained sensor nodes in communication with gateways in open-space environments and industries has highlighted the need for a secure yet fast…

密码学与安全 · 计算机科学 2022-07-26 Sina Baghbanijam , Hanie Sanaei , Mahdi Farajzadeh