Source author record

Paul-Olivier Dehaye

Paul-Olivier Dehaye appears in the imported research catalog. Authorship, coauthor and topic links are available while profile ownership is still unclaimed.

ResearcherUnclaimed source record

Catalog footprint

What is connected

9works
8topics
2close collaborators

Actions

Connect this record

Log in to claim

Research graph

See the researcher in context

Open full explorer

Inspect adjacent papers, topics, institutions and collaborators without losing the researcher page.

Building this map preview

BZPEER is loading the nearby papers, people, topics and institutions for this page.

Published work

9 published item(s)

preprint2020arXiv

Proximity Tracing in an Ecosystem of Surveillance Capitalism

Proximity tracing apps have been proposed as an aide in dealing with the COVID-19 crisis. Some of those apps leverage attenuation of Bluetooth beacons from mobile devices to build a record of proximate encounters between a pair of device owners. The underlying protocols are known to suffer from false positive and re-identification attacks. We present evidence that the attacker's difficulty in mounting such attacks has been overestimated. Indeed, an attacker leveraging a moderately successful app or SDK with Bluetooth and location access can eavesdrop and interfere with these proximity tracing systems at no hardware cost and perform these attacks against users who do not have this app or SDK installed. We describe concrete examples of actors who would be in a good position to execute such attacks. We further present a novel attack, which we call a biosurveillance attack, which allows the attacker to monitor the exposure risk of a smartphone user who installs their app or SDK but who does not use any contact tracing system and may falsely believe that they have opted out of the system. Through traffic auditing with an instrumented testbed, we characterize precisely the behaviour of one such SDK that we found in a handful of apps---but installed on more than one hundred million mobile devices. Its behaviour is functionally indistinguishable from a re-identification or biosurveillance attack and capable of executing a false positive attack with minimal effort. We also discuss how easily an attacker could acquire a position conducive to such attacks, by leveraging the lax logic for granting permissions to apps in the Android framework: any app with some geolocation permission could acquire the necessary Bluetooth permission through an upgrade, without any additional user prompt. Finally we discuss motives for conducting such attacks.

preprint2020arXiv

SwissCovid: a critical analysis of risk assessment by Swiss authorities

Ahead of the rollout of the SwissCovid contact tracing app, an official public security test was performed. During this audit, Prof. Serge Vaudenay and Dr. Martin Vuagnoux described a large set of problems with the app, including a new variation of a known false-positive attack, leveraging a cryptographic weakness in the Google and Apple Exposure Notification framework to tamper with the emitted Bluetooth beacons. Separately, the first author described a re-identification attack leveraging rogue apps or SDKs. The response from the Swiss cybersecurity agency and the Swiss public health authority was to claim these various attacks were unlikely as they required physical proximity of the attacker with the target (although it was admitted the attacker could be further than two meters). The physical presence of the attacker in Switzerland was deemed significant as it would imply such attackers would fall under the Swiss Criminal Code. We show through one example that a much larger variety of adversaries must be considered in the scenarios originally described and that these attacks can be done by adversaries without any physical presence in Switzerland. This goes directly against official findings of Swiss public authorities evaluating the risks associated with SwissCovid. To move the discussion further along, we briefly discuss the growth of the attack surface and harms with COVID-19 and SwissCovid prevalence in the population. While the focus of this article is on Switzerland, we emphasize the core technical findings and cybersecurity concerns are of relevance to many contact tracing efforts.

preprint2012arXiv

Combinatorics of lower order terms in the moment conjectures for the Riemann zeta function

Conrey, Farmer, Keating, Rubinstein and Snaith have given a recipe that conjecturally produces, among others, the full moment polynomial for the Riemann zeta function. The leading term of this polynomial is given as a product of a factor explained by arithmetic and a factor explained by combinatorics (or, alternatively, random matrices). We explain how the lower order terms arise, and clarify the dependency of each factor on the exponent $k$ that is considered. We use extensively the theory of symmetric functions and representations of symmetric groups, ideas of Lascoux on manipulations of alphabets, and a key lemma, due in a basic version to Bump and Gamburd. Our main result ends up involving dimensions of skew partitions, as studied by Olshanski, Regev, Vershik, Ivanov and others. In this article, we also lay the groundwork for later unification of the combinatorial computations for lower order terms in the moments conjectures across families of $L$-functions of unitary, orthogonal and symplectic types.

preprint2011arXiv

Integrality of hook ratios

We study integral ratios of hook products of quotient partitions. This question is motivated by an analogous question in number theory concerning integral factorial ratios. We prove an analogue of a theorem of Landau that already applied in the factorial case. Under the additional condition that the ratio has one more factor on the denominator than the numerator, we provide a complete classification. Ultimately this relies on Kneser's theorem in additive combinatorics.

preprint2010arXiv

A note on moments of derivatives of characteristic polynomials

We present a simple technique to compute moments of derivatives of unitary characteristic polynomials. The first part of the technique relies on an idea of Bump and Gamburd: it uses orthonormality of Schur functions over unitary groups to compute matrix averages of characteristic polynomials. In order to consider derivatives of those polynomials, we here need the added strength of the Generalized Binomial Theorem of Okounkov and Olshanski. This result is very natural as it provides coefficients for the Taylor expansions of Schur functions, in terms of shifted Schur functions. The answer is finally given as a sum over partitions of functions of the contents. One can also obtain alternative expressions involving hypergeometric functions of matrix arguments.

preprint2008arXiv

On an identity due to ((Bump and Diaconis) and (Tracy and Widom))

A classical question for a Toeplitz matrix with given symbol is to compute asymptotics for the determinants of its reductions to finite rank. One can also consider how those asymptotics are affected when shifting an initial set of rows and columns (or, equivalently, asymptotics of their minors). Bump and Diaconis (Toeplitz minors, J. Combin. Theory Ser. A, 97 (2002), pp. 252--271) obtained a formula for such shifts involving Laguerre polynomials and sums over symmetric groups. They also showed how the Heine identity extends for such minors, which makes this question relevant to Random Matrix Theory. Independently, Tracy and Widom (On the limit of some Toeplitz-like determinants, SIAM J. Matrix Anal. Appl., 23 (2002), pp. 1194--1196) used the Wiener-Hopf factorization to express those shifts in terms of products of infinite matrices. We show directly why those two expressions are equal and uncover some structure in both formulas that was unknown to their authors. We introduce a mysterious differential operator on symmetric functions that is very similar to vertex operators. We show that the Bump-Diaconis-Tracy- Widom identity is a differentiated version of the classical Jacobi-Trudi identity.

preprint2007arXiv

Joint moments of derivatives of characteristic polynomials

We investigate the joint moments of the 2k-th power of the characteristic polynomial of random unitary matrices with the 2h-th power of the derivative of this same polynomial. We prove that for a fixed h, the moments are given by rational functions of k, up to a well-known factor that already arises when h=0. We fully describe the denominator in those rational functions (this had already been done by Hughes experimentally), and define the numerators through various formulas, mostly sums over partitions. We also use this to formulate conjectures on joint moments of the zeta function and its derivatives, or even the same questions for the Hardy function, if we use a ``real'' version of characteristic polynomials. Our methods should easily be applicable to other similar problems, for instance with higher derivatives of characteristic polynomials. NOTE: More data is available on the author's website or attached to the LaTeX source of this arXiv submission.

preprint2006arXiv

Averages over classical compact Lie groups and Weyl characters

We compute $E_G (\prod_i \tr(g^{λ_i}))$, where $G=Sp(2n)$ or $SO(m) (m=2n, 2n+1)$ with Haar measure. This was first obtained by Persi Diaconis and Mehrdad Shahshahani, but our proof is more self-contained and gives a combinatorial description for the answer. We also consider how averages of general symmetric functions $E_G f_n$ are affected when we introduce a Weyl character $χ^G_λ$ into the integrand. We show that the value of $E_G χ^G_λf_n / E_G f_n$ approaches a constant for large $n$. More surprisingly, the ratio we obtain only changes with $f_n$ and $λ$ and is independent of the Cartan type of $G$. Even in the unitary case, Daniel Bump and Persi Diaconis have obtained the same ratio. Finally, those ratios can be combined with asymptotics for $E_G f_n$ due to Kurt Johansson and provide asymptotics for $E_G χ^G_λf_n$.