4 papers
Half-Moon Cookie: Private, Similarity-Based Blocklisting with TOCTOU-Attack Resilience
Xinyuan Zhang, Anrin Chakraborti, Michael K. Reiter
Blocklisting is a common technique for preventing the use of known malicious content. However, conventional blocklisting infrastructures require either the blocklist to be public o…
Blocklisted Oblivious Pseudorandom Functions
Xinyuan Zhang, Anrin Chakraborti, Michael Reiter
An oblivious pseudorandom function (OPRF) is a protocol by which a client and server interact to evaluate a pseudorandom function on a key provided by the server and an input provi…
Incentivizing Collaboration for Detection of Credential Database Breaches
Mridu Nanda, Michael K. Reiter
Decoy passwords, or ``honeywords,'' alert a site to its breach if entered in a login attempt on that site. However, an attacker can identify a user-chosen password from among the d…
CrudiTEE: A Stick-and-Carrot Approach to Building Trustworthy Cryptocurrency Wallets with TEEs
Lulu Zhou, Zeyu Liu, Fan Zhang +1
Cryptocurrency introduces usability challenges by requiring users to manage signing keys. Popular signing key management services (e.g., custodial wallets), however, either introdu…