Security and Cryptography

Welcome to the web page for security and cryptography research in the Department of Computer Science and Engineering at the University of California at San Diego. Our group conducts research in areas spanning from theory to practice: we work on the theoretical foundations of cryptography; the development and analysis of cryptographic protocols and algorithms; and on applied cryptography, systems security, and network security. In line with our broad security-related research interests, we are affiliated and actively collaborate with the Theory Group, Programming Systems and the Systems and Networking Group here at UCSD.

People  |   News  |   Publications  |   Sponsors
Faculty
Mihir Bellare
Nadia Heninger
Russell Impagliazzo
Daniele Micciancio
Imani Munyaka
Stefan Savage
Aaron Schulman
Alex C. Snoeren
Deian Stefan
Geoffrey M. Voelker
Affiliated Faculty
kc claffy
Kamalika Chaudhuri
Ranjit Jhala
Ryan Kastner
Sorin Lerner
Nadia Polikarpova
Steven Swanson
Dean Tullsen
Yiying Zhang
Yuanyuan Zhou
Adjunct Faculty
Kirill Levchenko Hovav Shacham
Scientists, Postdocs and Research Staff
Daniel Moghimi Cindy Moore
PhD Students
Gautam Akiwate
Vivek Arte
Nishant Bhaskar
Alex Bellon
Sam Crow
Wei Dai
Hannah Davis
Craig Disselkoen
Alex Gamero-Garrido
Marcella Hastings
Evan Johnson
Baiyu Li
Enze Alex Liu
Ariana Mirian
Shravan Narayan
Ruth Ng
Audrey Randall
John Renner
Keegan Ryan
Mark Schultz
Laura Shea
Bingyu Shen
Mingyao Shen
Michael Smith
Jessica Sorrell
Igors Stepanovs
Adam Suhl
George Sullivan
David Thien
Alisha Ukani
Psi Vesely
Yudong Wu
Chengcheng Xiang
Recent Alumni

Sunjay Cauligi (Ph.D. 2021)
MPI Security and Privacy (postdoc)
Klaus von Gleissenthall (postdoc 2016-2020) VU Amsterdam (assistant professor)
Guo "Vector" Li (Ph.D. 2020) Google
Felix Guenther (postdoc 2018-2019) ETH Zurich (postdoc)
Joseph Jaeger (Ph.D. 2019) University of Washington (postdoc)
Nicholas Genise (Ph.D. 2019) Rutgers University (postdoc)SRI
Zhaomo Yang (Ph.D. 2019) Google
Louis DeKoven (Ph.D. 2019) Facebook
Brown Farinholt (Ph.D. 2019) Facebook

Maxwell Bland (M.S. 2019) University of Illinois Ph.D. program
Gary Soeller Mason America
Brian Johannesmeyer Vrije Universiteit Ph.D. program
Joe DeBlasio (Ph.D. 2018) Google
Michael Walter (Ph.D. 2018) IST Vienna, Austria (postdoc)
Brian Kantor (retired 2018) ARDC
Liz Izhikevich (M.S. 2018) Stanford Ph.D. program
Evan Ronceivch (M.S. 2018) Sandia National Labs
Tianyin Xu (Ph.D. 2017) Facebook (Visiting Scientist)University of Illinois Urbana Champaign
Danny Huang (Ph.D. 2017) → Princeton (postdoc)NYU Poly
Xinxin Jin (Ph.D. 2017) Whova

[All Alumni]
Recent News

March 18— Congrats to Mihir Bellare for again receiving the IACR Test of Time award (he also won it last year), this time for his Crypto 2007 paper "Deterministic and Efficiently Searchable Encryption", published jointly with then UCSD Ph.D. student Alexandra Bodyreva (now faculty at GA Tech) and then UCSD undergrad Adam O'Neil (now faculty at UMass Amherst).

Deian Stefan February 15— Another congrats to Deian Stefan. This time for receiving a Sloan Fellowship!

February 8— Congrats to Deian Stefan for being on the initial members and recipients of funding from Intel Labs' new Resilient Archiotectures and Robust Electronics (RARE) Center! Deian Stefan

January 25— More recognition for Shravan Narayan, Craig Disselkoen and their co-authors as the RLBox paper receives honorable mention in the 2021 NSA Best Scientific Cybersecurity Paper competition. Congrats all!

Stefan Savage January 24— More great news – Stefan Savage received a Diamond Award from the University of Washington School of Engineering, an award which honors outstanding alumni who have made significant contributions to the field of engineering. Stefan received the Distinguished Achievement in Academia award for his signature style of work that "challenges traditional investigation methods and redefines academic approaches to network security, privacy and reliability". Congratulations Stefan!

January 10— Congratulations to Gautam Akiwate (and his co-authors) for being named as a winner of the Internet Research Task Force's Applied Networking Research Prize for his work characterizing a domain hijacking risk that is an accidental byproduct of undocumented operational practices between domain registrars and registries. Gautam's award marks the second year in a row that the group has received the prize (Audrey Randall received it last year). Let's keep the streak going! Gautam Akiwate

Stephan Chenette December 11— Its been a long road, but after 14yrs, a bunch of jobs, founding and building up AttackIQ, the pandemic gave prodigal member Stephan Chenette the pause to finish his Masters with his master's thesis, "An Analysis Of Judgment Variability Amongst Cybersecurity Participants When Asked To Forecast Cybersecurity-related Events". A nice bit of work and proof that you can go home again. Congrats Stephan!
[All News]
Recent Publications

Evaluating Physical-Layer BLE Location Tracking Attacks on Mobile Devices, Hadi Givehchian, Nishant Bhaskar, Eliana Rodriguez Herrera, Héctor Rodrigo López Soto, Christian Dameff, Dinesh Bharadia, and Aaron Schulman, Proceedings of the IEEE Symposium on Security and Privacy, May 2022.

Risky BIZness: Risks Derived from Registrar Name Management, Gautam Akiwate, Stefan Savage, Geoffrey M. Voelker, and kc Claffy, Proceedings of the ACM Internet Measurement Conference (IMC), Virtual, November 2021.

Who’s Got Your Mail? Characterizing Mail Service Provider Usage, Enze Liu, Gautam Akiwate, Mattijs Jonker, Ariana Mirian, Stefan Savage, and Geoffrey M. Voelker, Proceedings of the ACM Internet Measurement Conference (IMC), Virtual, November 2021.

Home is Where the Hijacking is: Understanding DNS Interception by Residential Routers, Audrey Randall, Enze Liu, Ramakrishna Padmanabhan, Gautam Akiwate, Geoffrey M. Voelker, Stefan Savage, and Aaron Schulman, Proceedings of the ACM Internet Measurement Conference (IMC), Virtual, November 2021.

SugarCoat: Programmatically generating privacy-Preserving, Web-compatible resource replacements for content blocking, Michael Smith, Peter Snyder, Ben Livshits, and Deian Stefan, Proceedings of the ACM Conference on Computer and Communications Security (CCS), Seoul, Korea, November 2021.

On Bounded Distance Decoding with Predicate: Breaking the "Lattice Barrier" for the Hidden Number Problem, Martin R Albrecht and Nadia Heninger, Proceedings of Eurocrypt 2021, Zagreb, Croatia, October 2021.

On the Security of Homomorphic Encryption on Approximate Numbers, Baiyu Li and Daniele Micciancio, Proceedings of Eurocrypt 2021, Zagreb, Croatia, October 2021.

Hopper: Modeling and Detecting Lateral Movement, Grant Ho, Mayank Dhiman, Devdatta Akhawe, Vern Paxson, Stefan Savage, Geoffrey M. Voelker, and David Wagner, Proceedings of the USENIX Security Symposium, Vancouver, B.C., Canada, August 2021.

Driving 2FA Adoption at Scale: Optimizing Two-Factor Authentication Notification Design Patterns, Maximillian Golla, Grant Ho, Marika Lohmus, Monica Pulluri, and Elissa M. Redmiles, Proceedings of the USENIX Security Symposium, Vancouver, B.C., Canada, August 2021.

Swivel: Hardening WebAssembly against Spectre, Shravan Narayan, Craig Disselkoen, Daniel Moghimi, Sunjay Cauligi, Evan Johnson, Zhao Gang, Anjo Vahldiek-Oberwagner, Ravi Sahita, Hovav Shacham, Dean Tullsen, and Deian Stefan, Proceedings of the USENIX Security Symposium, Vancouver, B.C., Canada, August 2021.

Jetset: Targeted Firmware Rehosting for Embedded Systems, Evan Johnson, Maxwell Bland, Yifei Zhu, Joshua Mason, Stephen Checkoway, Stefan Savage, and Kirill Levchenko, Proceedings of the USENIX Security Symposium, Vancouver, B.C., Canada, August 2021.

Can Systems Explain Permissions Better? Understanding Users' Misperceptions under Smartphone Runtime Permission Model, Bingyu Shen, Lili Wei, Chengcheng Xiang, Yudong Wu, Mingyao Shen, Yuanyuan Zhou, and Xinxin Jin, Proceedings of the USENIX Security Symposium, Vancouver, B.C., Canada, August 2021.

STORM: Refinement Types for Secure Web Applications, Nico Lehmann, Rose Kunkel, Jordan Brown, Jean Yang, Niki Vazou, Nadia Polikarpova, Deian Stefan, and Ranjit Jhala, Proceedings of the 15th USENIX Symposium on Operating System Design and Implementation (OSDI), Virtual, July 2021.

Scooter & Sidecar: A Domain-Specific Approach to Writing Secure Database Migrations, John Renner, Alex Sanchez-Stern, Fraser Brown, Sorin Lerner, and Deian Stefan, Proceedings of the ACM SIGPLAN Conference onProgramming Language Design and Implementation (PLDI), Virtual, June 2021.

CoResident Evil: Covert Communications in the Cloud with Lambdas, Anil Yelam, Ariana Mirian, Keerthana Ganesan, Shibani Subbareddy, and Stefan Savage, Proceedings of the Web Conference (WWW), Ljubljana, Solvenia, arp 2021.

High-Assurance Cryptography in the Spectre Era, Gilles Barthe, Sunjay Cauligi, Benjamin Gregoire, Adrien Koutsos, Kevin Liao, Tiago Oliveira, Swarn Priya, Tamara Rezk, and Peter Schwabe, Proceedings of the IEEE Symposium on Security and Privacy, San Francisco, CA, May 2021.

Diogenes: Lightweight Scalable RSA Modulus Generation with a Dishonest Majority, Megan Chen, Carmit Hazay, Yuval Ishai, Yuriy Kashnikov, Daniele Micciancio, Tarik Riviere, Abhi Shelat, Muthuramakrishnan Venkitasubramaniam, and Ruihan Wang, Proceedings of the IEEE Symposium on Security and Privacy, San Francisco, CA, May 2021.

Clairvoyance: Inferring Blocklist Use on the Internet, Vector Guo Li, Gautam Akiwate, Kirill Levchenko, Geoffrey M. Voelker, and Stefan Savage, Proceedings of the Passive and Active Measurement Conference (PAM), Brandenburg, Germany, March 2021.

Доверя́й, но проверя́й: SFI safety for native-compiled Wasm, Evan Johnson, David Thien, Yousef Alhessi, Shravan Narayan, Fraser Brown, Sorin Lerner, Tyler McMullen, Stefan Savage, and Deian Stefan, Proceedings of the Network and Distributed System Security Symposium (NDSS), San Diego, CA, February 2021.

Automatically Eliminating Speculative Leaks from CryptograpHic Code with Blade, Marco Vassena, Craig Disselkoen, Klaus v. Gleissenthall, Sunjay Cauligi, Rami Gokhan Kici, Ranjit Jhala, Dean Tullsen, and Deian Stefan, Proceedings of the ACM SIGPLAN Symposium on Principles of Programming Languages, Internet, January 2021. (Distinguished paper).

[All Publications]
Affiliations
Center for Networked Systems (CNS)         Cooperative Association for Internet Data Analysis (CAIDA)       San Diego Super Computer Center (SDSC)        California Institute for Telecommunications and Information Technology (Cal-IT2) CalIT(2)
Sponsors