San Jose, California, United States
4K followers 500+ connections

Join to view profile

Publications

  • TPU as Cryptographic Accelerator

    MICRO

    Polynomials defined on specific rings are heavily involved in various cryptographic schemes, and the corresponding operations are usually the computation bottleneck of the whole scheme.
    We propose to utilize TPU, an emerging hardware designed for AI applications, to speed up polynomial operations and convert TPU to a cryptographic accelerator.
    We also conduct preliminary evaluation and discuss the limitations of current work and future plan.

    See publication
  • Decentralized Translator of Trust: Supporting Heterogeneous TEE for Critical Infrastructure Protection

    ACM Symposium on Information, Computer and Communications Security

    Trusted execution environment (TEE) technology has found many applications in mitigating various security risks in an efficient manner, which is attractive for critical infrastructure protection. First, the natural of critical infrastructure requires it to be well protected from various cyber attacks. Second, performance is usually important for critical infrastructure and it cannot afford an expensive protection mechanism. While a large number of TEE-based critical infrastructure protection…

    Trusted execution environment (TEE) technology has found many applications in mitigating various security risks in an efficient manner, which is attractive for critical infrastructure protection. First, the natural of critical infrastructure requires it to be well protected from various cyber attacks. Second, performance is usually important for critical infrastructure and it cannot afford an expensive protection mechanism. While a large number of TEE-based critical infrastructure protection systems have been proposed to address various security challenges (e.g., secure sensing and reliable control), most existing works ignore one important feature, i.e., devices comprised the critical infrastructure may be equipped with multiple incompatible TEE technologies and belongs to different owners. This feature makes it hard for these devices to establish mutual trust and form a unified TEE environment. To address these challenges and fully unleash the potential of TEE technology for critical infrastructure protection, we propose DHTee, a decentralized coordination mechanism. DHTee uses blockchain technology to support key TEE functions in a heterogeneous TEE environment, especially the attestation service. A Device equipped with one TEE can interact securely with the blockchain to verify whether another potential collaborating device claiming to have a different TEE meets the security requirements. DHTee is also flexible and can support new TEE schemes without affecting devices using existing TEEs that have been supported by the system.

    See publication
  • Targeted Phishing Campaigns using Large Scale Language Models

    arxiv

    In this research, we aim to explore the potential of natural language models (NLMs) such as GPT-3 and GPT-2 to generate effective phishing emails. Phishing emails are fraudulent messages that aim to trick individuals into revealing sensitive information or taking actions that benefit the attackers. We propose a framework for evaluating the performance of NLMs in generating these types of emails based on various criteria, including the quality of the generated text, the ability to bypass spam…

    In this research, we aim to explore the potential of natural language models (NLMs) such as GPT-3 and GPT-2 to generate effective phishing emails. Phishing emails are fraudulent messages that aim to trick individuals into revealing sensitive information or taking actions that benefit the attackers. We propose a framework for evaluating the performance of NLMs in generating these types of emails based on various criteria, including the quality of the generated text, the ability to bypass spam filters, and the success rate of tricking individuals. Our evaluations show that NLMs are capable of generating phishing emails that are difficult to detect and that have a high success rate in tricking individuals, but their effectiveness varies based on the specific NLM and training data used. Our research indicates that NLMs could have a significant impact on the prevalence of phishing attacks and emphasizes the need for further study on the ethical and security implications of using NLMs for malicious purposes.

    See publication
  • Decentralized Application Infrastructures as Smart Contract Codes

    IEEE International Conference on Blockchain and Cryptocurrency (ICBC)

    Legacy modeling and orchestration tools are not well-suited for decentralized cloud and computing infrastructures, which are characterized by a lack of central control. This makes it difficult to use legacy tools to automate and model decentralized infrastructures. Extending the TOSCA domain-specific language to support smart contract specification of decentralized computing infrastructures would allow smart contracts or chain codes to manage decentralized computing environments, which would be…

    Legacy modeling and orchestration tools are not well-suited for decentralized cloud and computing infrastructures, which are characterized by a lack of central control. This makes it difficult to use legacy tools to automate and model decentralized infrastructures. Extending the TOSCA domain-specific language to support smart contract specification of decentralized computing infrastructures would allow smart contracts or chain codes to manage decentralized computing environments, which would be a step forward for achieving full decentralization in general-purpose computing.

    See publication
  • Privacy preserving event based transaction system in a decentralized environment

    Middleware '21: Proceedings of the 22nd International Middleware Conference

    In this paper, we present the design and implementation of a privacy preserving event based UTXO (Unspent Transaction Output) transaction system. Unlike the existing approaches that often depend on smart contracts where digital assets are first locked in a vault, and then released according to event triggers, the event based transaction system encodes event outcome as part of the UTXO note and safeguards event privacy by shielding it with zero-knowledge proof based protocols such that…

    In this paper, we present the design and implementation of a privacy preserving event based UTXO (Unspent Transaction Output) transaction system. Unlike the existing approaches that often depend on smart contracts where digital assets are first locked in a vault, and then released according to event triggers, the event based transaction system encodes event outcome as part of the UTXO note and safeguards event privacy by shielding it with zero-knowledge proof based protocols such that associations between UTXO notes and events are hidden from the validators. Without relying on any triggering mechanism, the proposed transaction system separates event processing from the transaction processing where confidential event based UTXO notes (event based UTXOs or conditional UTXOs) can be transferred freely with full privacy in an asynchronous manner, only with their asset values conditional to the linked event outcomes. The main advantage of such design is that it enables free trade of event based digital assets and prevents the assets from being locked. We implemented the proposed transaction system by extending the Zerocoin data model and protocols. The system is implemented and evaluated using xJsnark.

    See publication
  • Lessons Learned from Blockchain Applications of Trusted Execution Environments and Implications for Future Research

    HASP '21: Workshop on Hardware and Architectural Support for Security and Privacy

    Modern computer systems tend to rely on large trusted computing bases (TCBs) for operations. To address the TCB bloating problem, hardware vendors have developed mechanisms to enable or facilitate the creation of a trusted execution environment (TEE) in which critical software applications can execute securely in an isolated environment. Even under the circumstance that a host OS is compromised by an adversary, key security properties such as confidentiality and integrity of the software inside…

    Modern computer systems tend to rely on large trusted computing bases (TCBs) for operations. To address the TCB bloating problem, hardware vendors have developed mechanisms to enable or facilitate the creation of a trusted execution environment (TEE) in which critical software applications can execute securely in an isolated environment. Even under the circumstance that a host OS is compromised by an adversary, key security properties such as confidentiality and integrity of the software inside the TEEs can be guaranteed. The promise of integrity and security has driven developers to adopt it for use cases involving access control, PKS, IoT among other things. Among these applications include blockchain-related use cases. The usage of the TEEs doesn’t come without its own implementation challenges and potential pitfalls. In this paper, we examine the assumptions, security models, and operational environments of the proposed TEE use cases of blockchain-based applications. The exercise and analysis help the hardware TEE research community to identify some open challenges and opportunities for research and rethink the design of hardware TEEs in general.

    See publication
  • An event driven framework for smart contract execution

    Proceedings of the 15th ACM International Conference on Distributed and Event-based Systems

    Blockchain-based smart contract platforms have traditionally employed the transaction-driven execution model. This paper presents an alternate framework for blockchain-based smart contract execution called EDSC. Our platform design presents a novel approach to tackle the scalability and performance challenges facing the smart contract ecosystem. We base EDSC's design on the Ethereum template, and it can be readily implemented for other existing smart contract platforms. To evaluate our design…

    Blockchain-based smart contract platforms have traditionally employed the transaction-driven execution model. This paper presents an alternate framework for blockchain-based smart contract execution called EDSC. Our platform design presents a novel approach to tackle the scalability and performance challenges facing the smart contract ecosystem. We base EDSC's design on the Ethereum template, and it can be readily implemented for other existing smart contract platforms. To evaluate our design, we perform an experimental implementation using the Ethereum client. Our experiments with performance modeling show, on average, a 2.2 to 4.6 times reduced total latency of event-triggered smart contracts, demonstrating the effectiveness of the design in supporting time-sensitive applications. Additionally, we comment on the design's potential security aspects and demonstrate its utility by discussing potential use cases.

    See publication
  • On Conditional Cryptocurrency With Privacy

    2021 IEEE International Conference on Blockchain and Cryptocurrency (ICBC)

    In this paper, we present the design and imple-mentation of a conditional cryptocurrency system with privacy protection. Unlike the existing approaches that often depend on smart contracts where cryptocurrencies are first locked in a vault, and then released according to event triggers, the conditional cryptocurrency system encodes event outcome as part of a cryptocurrency note in a UTXO based system. Without relying on any triggering mechanism, the proposed system separates event processing…

    In this paper, we present the design and imple-mentation of a conditional cryptocurrency system with privacy protection. Unlike the existing approaches that often depend on smart contracts where cryptocurrencies are first locked in a vault, and then released according to event triggers, the conditional cryptocurrency system encodes event outcome as part of a cryptocurrency note in a UTXO based system. Without relying on any triggering mechanism, the proposed system separates event processing from conditional coin transaction processing where conditional cryptocurrency notes can be transferred freely in an asynchronous manner, only with their asset values conditional to the linked event outcomes. The main advantage of such design is that it enables free trade of conditional assets and prevents assets from being locked.

    See publication
  • Optimizing Web Virtual Reality

    Rice University

    Virtual Reality is now becoming a mainstream technology, as indicated by Oculus Rift graduating from Kickstarter to being acquired by Facebook. From HTC VIve to Google Daydream, there are now multiple stakeholders in Virtual Reality applications. One unifying solution in this fragmented ecosystem is the Web Virtual Reality (WebVR) specification. WebVR is a living specification in W3C that is implemented by multiple browser vendors, including Mozilla and Google. It utilizes WebGL in the backend…

    Virtual Reality is now becoming a mainstream technology, as indicated by Oculus Rift graduating from Kickstarter to being acquired by Facebook. From HTC VIve to Google Daydream, there are now multiple stakeholders in Virtual Reality applications. One unifying solution in this fragmented ecosystem is the Web Virtual Reality (WebVR) specification. WebVR is a living specification in W3C that is implemented by multiple browser vendors, including Mozilla and Google. It utilizes WebGL in the backend and the higher level API’s are exposed through frameworks like ThreeJS. However since many of these frameworks were not designed with WebVR in mind, they often exhibit performance bottlenecks when running Virtual Reality applications. All the WebVR code is run in browser as JavaScript applications, and the sequential nature of the JavaScript platform does not help either. In this thesis, we study and identify key performance bottlenecks in WebVR, and document their performance impact. We propose, implement and validate optimizations to address these bottlenecks, and also explore how this research benefits the Augmented Reality and Web Mixed Reality domains which are also being built upon WebVR.

    See publication
Join now to see all publications

Patents

  • Mobile Multi-Party Digitally Signed Documents and Techniques for Using These Allowing Detection of Tamper

    Issued US US20200322351A1

    Authenticated base digital document(s) are issued to client(s) by an issuing party, and aggregate digital document(s) are received. An aggregate digital document includes base digital document(s) and attachment(s). Authenticity of the aggregate digital document(s) is verified, resulting in authenticated aggregate digital document(s), which are stored and/or redistributed. Authentication challenge(s) are sent by a verifying party to a client requesting part or all of an aggregate digital…

    Authenticated base digital document(s) are issued to client(s) by an issuing party, and aggregate digital document(s) are received. An aggregate digital document includes base digital document(s) and attachment(s). Authenticity of the aggregate digital document(s) is verified, resulting in authenticated aggregate digital document(s), which are stored and/or redistributed. Authentication challenge(s) are sent by a verifying party to a client requesting part or all of an aggregate digital document from the client be verified. The part or all of the aggregate digital document is received and authenticity and integrity are verified, resulting in an authenticated aggregate digital document. The client verifies authenticity of a base digital document and receives the authentication challenge(s) for an authenticated aggregate digital document and sends part or all of the authenticated aggregate digital document to the verifying party for verification by the verifying party.

    See patent

Recommendations received

View Rabimba’s full profile

  • See who you know in common
  • Get introduced
  • Contact Rabimba directly
Join to view full profile

Other similar profiles

Explore top content on LinkedIn

Find curated posts and insights for relevant topics all in one place.

View top content

Add new skills with these courses