VLDB 2026 Research / reviewers in the wild / expert
An Braeken
dblp:10/3184
· DBLP profile ↗
94ranked-venue papers
22as first author
46since 2021 · last 2026
0000-0002-9965-915XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 29 · 5 first-author · 18 since 2021Systems, architecture and hardware · 25 · 6 first-author · 9 since 2021Security and privacy · 19 · 7 first-author · 10 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 1 first-author · 2 since 2021Theory of computation · 4 · 3 first-authorSoftware engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | POSTER: Zero-Touch Mobility Data Governance with Differential Privacy in ZSM-Based Vehicular Edge ServicesabstractConnected-vehicle and roadside telemetry enable low-latency safety navigation, and traffic-optimisation services at the edge, but finegrained mobility streams (locations, speeds, events, and contexts) create high re-identification and linkage risk when accessed by multiple stakeholder domains. We present a Zero Touch Network and Service Management (ZSM) integrated, policy-driven data-collection service that operationalises mobility data governance through intent-based automation. Stakeholders submit high-level collection intents (purpose, fields, spatial/temporal granularity, latency, and utility targets); a policy engine evaluates and rewrites intents into compliant, effective intents; and a plan generator compiles them into executable data-collection pipelines deployable within a ZSM closed loop. Experiments on Beijing taxi mobility traces execute 87,500 DP-protected releases and achieve 1.26% relative error for Road Safety Authority (RSA) at ϵ = 8.0, while DP-Stochastic Gradient Descent (DP-SGD) risk scoring reaches 0.97 ± 0.03 test accuracy at ϵ = 0.5, with δ= 10-5. Awaneesh Kumar Yadav, Pradumn Kumar Pandey, Manoj Misra, Madhusanka Liyanage, An Braeken |
AsiaCCS | 6 |
| 2026 | Proof of Proximity: A Fair and Energy-Efficient Consensus Mechanism for Blockchain-Based IoT and Edge Networks
N. L. N. Ranawaka, L. A. M. S. Gawesh, G. O. Sundarasekara, J. A. T. K. Jayakody, Pramitha Fernando, Chatura Seneviratne, An Braeken |
COMPSAC | 7 |
| 2026 | Efficient Privacy-Preserving 5G Authentication and Key Agreement for Applications (5G-AKMA) in Multi-Access Edge ComputingabstractThe 5G Authentication and Key Management for Applications (AKMA) protocol is a 5G standard proposed by 3GPP in order to standardize the authentication procedure of mobile users towards applications based on the authentication of the user to the mobile network. As pointed out by several authors, the 5G-AKMA protocol inherently poses severe security issues, including privacy, unlinkability, ephemeral secret leakage and stolen device attacks. Also, the protocol does not offer perfect forward secrecy. In addition, the network operator is able to record all applications to which the user is subscribed and any outsider eavesdropping the communication channel is able to link requests to different applications coming from the same user. While the state of the shows that various protocols are proposed to solve the 5G-AKMA security issues, they are either vulnerable to severe attacks or are computationally extensive. In this paper, we provide a new version of the protocol able to solve these privacy issues in an effective manner. In addition, we also extend the protocol such that it can be used for communications in multiaccess edge computing (MEC) applications, taking into account handover procedures from one MEC server to another. The proposed protocol has been thoroughly compared to existing ones, revealing its efficiency in terms of communication, computation storage, and energy costs. The comparative analysis shows that the proposed 5G-AKMA reduces computational cost by 92%, communication cost by 74%, storage cost by 38%, and energy consumption cost by 58%. The security verification has been conducted using informal and formal methods (Real-Or-Random (ROR) and Scyther Validation tools) to ensure the protocol’s security. Additionally, we conduct a comparative analysis under an unknown attack scenario. Furthermore, the simulation is carried out using NS3. Awaneesh Kumar Yadav, An Braeken |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2026 | A Provably Secure Lightweight Three-Factor 5G-AKA Authentication Protocol Relying on an Extendable Output FunctionabstractCompared to 4G, the designed authentication and key agreement protocol for 5G communication (5G-AKA) offers better security. State-of-the-art shows that various protocols indicate the flaws in the 5G-AKA and suggest solutions primarily for the desynchronization attack, traceability attack, and perfect forward secrecy. However, most authentication protocols fail to facilitate the device stolen attack and are expensive; they also do not consider the prominent security issues such as post-compromise security and non-repudiation. Considering the above demerits of these protocols and the necessity to offer additional security, a provably secure lightweight 5G-AKA multi-factor authentication protocol relying on an extendable output function is proposed. The security of the proposed work has been confirmed informally and formally (ROR logic, GNY logic, and Scyther tool) to ensure that the proposed work handles all types of attacks and offers additional security features, such as post-compromise features and non-repudiation. Furthermore, we compute the performance of the proposed work and compare it with its counterparts to show that our work is less costly and more suitable for lightweight devices than others in terms of computational, communication, storage, and energy consumption cost. Awaneesh Kumar Yadav, An Braeken, Madhusanka Liyanage |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2026 | A Provably Secure Multifactor Authentication and Key Exchange Protocol With Anonymity for Next-Generation IoTabstractWith the rapid surge in IoT devices, communication between the IoT devices and the server becomes more frequent. Since IoT devices are considered at the edge of the networks, their communication is completely exposed to the server, making them prone to several attacks. In addition to this, IoT devices have limited energy and computational resources. Therefore, there is an impelling necessity for an authentication mechanism suitable for security and taking into account the resource constraints. This paper shows that a recently proposed protocol by Daojing et al. is prone to serious attacks such as stolen device attacks, suffers from integrity violations, and does not offer perfect forward secrecy. We propose an alternative and more secure authentication mechanism for this type of model and also show that this protocol offers better performance with respect to the state-of-the-art. The proposed protocol achieves reductions of 75%, 40%, 36%, and 71% in computational, communication, storage, and energy consumption costs, respectively. Additionally, the protocol only has two communication phases. Furthermore, prototype implementation and simulation with the NS3 tool are carried out to show the applicability of the proposed work in real-time scenarios. Awaneesh Kumar Yadav, An Braeken, Madhusanka Liyanage |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2026 | An Improved and Provably Secure EDHOC Protocol Supporting the Extended Canetti-Krawczyk (eCK) Security ModelabstractTransport Layer Security (TLS) is considered to be the most used standard security protocol for the Internet of Things (IoT). However, as TLS was originally designed for computer networks, it is not optimal with respect to efficiency. Therefore, a new protocol called Object Security for Constrained RESTful Environments (OSCORE) has been standardized for securing constrained devices. Currently, the Ephemeral Diffie Hellman Over COSE (EDHOC) protocol, which is a key exchange protocol to define a session key used in OSCORE, is also in the process of being standardized. This paper shows that the four authentication modes of the EDHOC protocol are vulnerable in the extended Canetti–Krawczyk (eCK) security model, which is a common security model used in IoT. In addition, also resistance to Distributed Denial of Service (DDoS) attacks is weak. Taking this into account, we propose two new variants of EDHOC. The first variant, EDHOC2, is able to overcome both issues but has a slightly higher cost for communication, computation, storage, and energy consumption. The second variant, EDHOC3, offers only additional protection in the eCK security model and has, on average, similar, even better performance in one authentication mode, compared to EDHOC. Additionally, the Real-Or-Random (ROR) logic and Scyther validation tool are employed to ensure the security of the designed variants. Furthermore, a prototype implementation is conducted to demonstrate the real-time deployment of the designed versions. Awaneesh Kumar Yadav, Madhusanka Liyanage, An Braeken |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2025 | Non-Fungible Token Enabled Resource Trading Marketplace for 6G Network SlicingabstractThe shift from fifth generation (5G) to sixth generation (6G) networks is anticipated to significantly advance network slicing. This progress is driven by the growing demand for next-generation applications and services. However, these advancements must be managed within the constraints of limited resources. This evolution opens up opportunities for resource sharing through emerging marketplaces, yet it introduces various business and technical complexities that need to be addressed. Additionally, finding cost-effective solutions is also essential for the future of networks. In this paper, we propose a blockchain-based architecture that utilizes non-fungible tokens (NFTs) for the trading of network resources within the 6G network slicing. To the best of our knowledge, this is the first study to represent network resources as NFTs within the context of network slicing. The architecture employs NFTs to authenticate and manage various network resources, providing a decentralized platform for their secure creation, management, and exchange. Using resource NFTs, our system ensures more granular and flexible control over network resources than existing state-of-the-art systems, where NFTs are tied to network slices. We implemented a prototype of this system to validate its viability. Our performance evaluation confirms that the proposed approach is efficient and cost-effective compared to baseline models in managing network resources within network slicing. These findings highlight the potential of our system to transform network management practices and effectively meet the demands of future networks. Nisita Weerasinghe, Pawani Porambage, An Braeken, Madhusanka Liyanage, Mika Ylianttila |
CCNC | 3 |
| 2025 | Demo: Blockchain-Based NFT Resource Marketplace for Efficient 6G Network SlicingabstractAs 6G networks introduce increasingly diverse and complex applications, network slicing is a key enabling technology for partitioning network resources to meet these dynamic demands. However, efficiently managing and allocating these finite resources has become vital. This necessity drives the adoption of an open marketplace model. To address the business and technical complexities associated with such open marketplaces, this paper presents the demonstration of a non-fungible token (NFT)-enabled resource trading marketplace tailored for 6G network slicing. The proposed solution is implemented on an Ethereum-based blockchain system to assess its viability. Nisita Weerasinghe, Pawani Porambage, An Braeken, Madhusanka Liyanage, Mika Ylianttila |
CCNC | 3 |
| 2025 | A Provably Secure Post-Quantum Based EDHOC ProtocolabstractTransport Layer Security (TLS) is considered to be the most used standard security protocol for the Internet of Things (IoT). However, as TLS was originally designed for computer networks, it is not optimal with respect to efficiency. Therefore, a new protocol called Object Security for Constrained RESTful Environments (OSCORE) has been standardized for securing constrained devices. Currently, the Ephemeral-Diffie-Hellman-Over-COSE (EDHOC) protocol, which is a key exchange protocol to define a session key used in OSCORE, is also in the process of being standardized. EDHOC consists of four authentication modes, each offering different security strengths and performance. However, these modes are not yet secure against quantum attacks. Since we are in a transition period and do not yet possess deeply analyzed post-quantum algorithms, we propose a generic hybrid protocol. As such, the protocol can easily update from one post-quantum algorithm to the other and becomes secure against either a post-quantum attack or a potential attack against a newly defined post-quantum algorithm. The proposed mode does not require any changes to the original EDHOC protocol and offers perfect backward compatibility. The security is ensured using Real-Or-Random (ROR) logic, and additional performance costs are analyzed using different variants of post-quantum algorithms. Awaneesh Kumar Yadav, Mohammad Shojafar, An Braeken |
CCNC | 3 |
| 2025 | SPARK: Secure Privacy-Preserving Anonymous Swarm Attestation for In-Vehicle NetworksabstractIn recent years, vehicles have evolved into cyberphysical autonomous systems that rely on sensor data from various sources within the vehicle. With the emergence of Vehicle-to-Everything (V2X) technology, the scope of the collaborative functionality in vehicles is now expanding to the inter-vehicular level. To support these modern capabilities, the complexity of the Electronic Control Units (ECUs) and the In-Vehicle Network (IVN) architecture is rapidly increasing. As a result, IVNs are now swarms of devices that communicate safety-critical data. Unfortunately, current vehicular networks lack security, opening the path to numerous cyberattacks. A typical solution for verifying the integrity of multiple devices is swarm attestation. However, in a typical IVN setting, only the Original Equipment Manufacturer (OEM) has access to the legitimate configuration of the ECUs and does not want to disclose this information due to intellectual property and security concerns. Therefore, state- of-the-art swarm attestation schemes, which do not provide privacy guarantees, are unsuitable for IVNs.This paper proposes Secure Privacy Preserving Anonymous Swarm Attestation for In-Vehicle Networks (SPARK), which builds upon a novel group signature scheme to enable privacy-preserving, anonymous, and traceable swarm attestation of IVNs. We validate SPARK through a proof-of-concept implementation using a standardized hardware Trusted Platform Module (TPM 2.0) and representative hardware platforms. The results demonstrate the real-world applicability of SPARK. Wouter Hellemans, Nada El Kassem, Md Masoom Rabbani, Edlira Dushku, Liqun Chen 0002, An Braeken, Bart Preneel, Nele Mentens |
EuroS&P | 6 |
| 2025 | Evaluation of Route Invalidation Mechanisms and Network Recovery in Wireless Sensor and Actuator NetworksabstractEfficiently managing route invalidation is important in Wireless Sensor and Actuator Networks (WSANs), mainly when downward traffic, from root to actuator nodes, commonly occurs. The No-Path Destination Advertisement Object (NPDAO) mechanism for route invalidation was initially proposed in RFC 6550. This approach can sometimes be inefficient, leading to stale routes, high overhead, and lower packet delivery ratios. A newer method, introduced in 2021 by RFC 9009, uses the mechanism through Destination Cleanup Object (DCO) messages for route invalidation. This paper implements DCO in Contiki-NG and compares its performance to NPDAO using the Cooja simulator. In the evaluated scenarios, the root and nodes within the tree send packets downwards to nodes that switch parent. The two route invalidation mechanisms are compared in scenarios with and without probing of the parents. The results show that in the most favourable scenario, the mechanism in RFC 9009 improves packet delivery ratio (PDR) for downward traffic from 66% (NPDAO) to 97% (DCO). Moreover, probing significantly improves network recovery times, which contributes to reliability. These findings validate and extend RFC 9009’s claims, confirming DCO’s suitability for WSANs. Diana Deac, Thibaut Vandervelden, Andreas Declerck, An Braeken, Virgil Dobrota, Kris Steenhaut |
PIMRC | 4 |
| 2025 | Ultra lightweight post-quantum resistant 5G-AKA protocol
An Braeken |
Comput. Networks | 1 |
| 2025 | Flexible hybrid post-quantum bidirectional multi-factor authentication and key agreement framework using ECC and KEM
An Braeken |
Future Gener. Comput. Syst. | 1 |
| 2025 | A Practical Transition to Post-Quantum Security in 5G-AKAabstractThe current 5G-AKA protocol faces significant security challenges, including the lack of Perfect Forward Secrecy and Post-Quantum (PQ) security. In particular, the absence of PQ protection makes current communications vulnerable to future quantum adversaries who may decrypt stored messages once large-scale quantum computers become available. To mitigate this risk, a transition to PQ security must be implemented as soon as possible. Two primary approaches exist for this transition: (1) symmetric key-based techniques, which require a secure channel for key distribution, leading to increased costs, and (2) modern PQ public-key primitives, which offer stronger security but come with high communication overhead. In this paper, we propose a solution that leverages PQ cryptographic primitives for confidentiality and privacy protection, while retaining classical public-key cryptography for authentication. This approach is viable because digital signatures must be secure today, even if they are compromised in the future. Moreover, our framework allows for a seamless transition to fully PQ-secure authentication when quantum threats become imminent. In addition, the framework also supports the zero-trust architecture in which no secure channel between Serving Network (SN) and Home Network (HN) is assumed. We have carefully analysed the security of the proposed protocol using both informal and formal (Real-Or-Random (ROR) logic and Scyther Validation tool) methods. We also compared its performance in terms of computation, communication, and storage, and found that it performs better than existing protocols. An Braeken, Awaneesh Kumar Yadav, Jorge Munilla |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | Privacy-Preserving Federated Learning Framework for Open Radio Access Networks (ORAN)abstractOpen Radio Access Network (ORAN) is considered the next-generation RAN, which enables several features such as network flexibility, interoperability, and cost efficiency. Leveraging Artificial Intelligence (AI) and Machine Learning (ML) techniques has become commonplace in ORAN applications. The modularized nature of the ORAN architecture and the limitations in traditional ML approaches intensify the requirement of Federated Learning (FL) for training ML models in ORAN environments. However, in multi-BS environments, the conventional plaintext model update sharing of FL is vulnerable to privacy breaches like inference and deep-leakage gradient attacks. Hence, our proposition introduces an innovative blockchain-based framework to conduct FL securely and protect privacy with the support of the Open Radio Access Network (ORAN). Our approach builds upon the traditional masking method for sharing model parameters and enhances it with novel features. These features include individual validation for BSs, the selection of distributed aggregators, and validation for final model aggregation. Our scheme facilitates the sharing of sensitive data among multiple BSs while bolstering privacy and adding security layers without compromising performance metrics. To assess the efficacy of our proposal, we implement the framework atop a Hyperledger Fabric blockchain. Furthermore, comprehensive formal and informal security analyses are conducted to demonstrate the robust and privacy-preserving nature. Shalitha Wijethilaka, Awaneesh Kumar Yadav, An Braeken, Madhusanka Liyanage |
GLOBECOM | 3 |
| 2024 | Zero-Touch Authentication for Device Deployment and Configuration in Industrial Internet of ThingsabstractThe wireless deployment or configuration of devices or systems without any manual intervention is essential to increase the efficiency as it allows to automate the setup process entirely, requiring minimal or no human involvement. This concept is also called zero-touch deployment and requires a proper and efficient key management strategy when constrained devices at large scale are involved. In this paper we propose a highly efficient mutual authentication and key agreement scheme, enabling devices without pre-shared key material to get access to the system network. The proposed protocol satisfies perfect forward secrecy and resistance against ephemeral session key leakage. We also discuss its feasibility for Time Slotted Channel Hopping (TSCH) based sensor networks. Roald Van Glabbeek, Ruben de Smet, Kris Steenhaut, An Braeken |
PIMRC | 4 |
| 2024 | Private Electronic Road Pricing Using Bulletproofs With Vector CommitmentsabstractWe present a novel approach to privacy preserving electronic road pricing (ERP) based on on-board units (OBUs) and zero-knowledge proofs (ZKPs), and without any need for tamper-proof elements. Since our approach issoftware-onlyandprotocol-enforced, it can be rapidly deployed on off-the-shelve or even pre-existing hardware, such as a smartphone or the on-board computer of a car. In addition, communication complexity is onlylogarithmicin function of route length, such that even for short routes the communication cost of the protocol is lower than the cost of naively transmitting the clear text route. Our implementation proves the construction to be computationally practical, especially for the verifier. Since the scheme is based on ZKPs, no unnecessary information gets leaked. At the basis of the scheme lies Bulletproofs, which is modified to provide native support for Pedersen vector commitments with logarithmic impact on proof size. Ruben de Smet, Kris Steenhaut, An Braeken |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | Blockchain-Based Group Key Management Scheme for IoT With Anonymity of Group MembersabstractGroup communications play a crucial role in enhancing the quality of service (QoS) of Internet of Things (IoT) networks, enabling efficient information dissemination while minimizing resource utilization. However, ensuring information security and privacy in IoT group communications necessitates the implementation of an efficient and lightweight key management scheme due to the limited capabilities of most IoT devices. This paper presents a novel key management protocol for group communications that employs distributed Blockchain technology in IoT networks. The proposed scheme considers nodes belonging to multiple groups. By utilizing an asymmetric key shared among group members, secure communication is established between outsiders and group members while preserving anonymity inside the group. A distinguishing feature of the protocol is its combination of group member anonymity and automatic key revocation facilitated by a Smart Contract. Furthermore, simulation results demonstrate the efficiency of the proposed scheme, consuming less than 300 mJ of energy and taking less than 7 seconds to establish a group key among 1000 nodes, outperforming several existing approaches in the literature in terms of computation and communication costs. Julio César Pérez García, An Braeken, Abderrahim Benslimane |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | Blockchain-Based Secure Authentication and Authorization Framework for Robust 5G Network SlicingabstractThe rapid evolution of heterogeneous applications signifies the requirement for network slicing to cater to diverse network requirements. Network Functions (NFs), which are the essential elements of network slices, are required to communicate with each other securely to facilitate network services. Certificates are the established method to authenticate each other. However, dynamic certificate management while allowing NFs to communicate in a multi-operator environment is arduous. Also, sharing NFs between network slices originates authorization-related security challenges such as unauthorized service utilization, deceptive Denial of Service attacks, and data leakages from network slices. In this paper, we develop a novel framework to address the security challenges related to authentication and authorization in 5G network slicing systems. A blockchain-based multi-party distributed certificate management framework with secure communication protocols is developed using elliptic curve cryptography to facilitate certificate services for multi-operator environments. Also, we propose a blockchain-based NF authorization framework to mitigate the security vulnerabilities in NF sharing between network slices. We implement the proposed framework using Hyperledger Fabric blockchain with Java chain codes and perform comprehensive experiments to show the significance of our framework.The Ability to mitigate the single point of failure with respect to state-of-the-art, including traditional certificate authorities and blockchain-based certificate authorities, time analysis for certificate generation, and the potential to eliminate the mentioned authorization attacks are some of the experiments conducted.Also, we have shown that our framework is secure using informal and formal (using Real-Or-Random (ROR) logic and Scyther Validation tool) security verification mechanisms. Shalitha Wijethilaka, Awaneesh Kumar Yadav, An Braeken, Madhusanka Liyanage |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2023 | A Provably Secure and Efficient 5G-AKA Authentication Protocol using BlockchainabstractThe next generation of mobile communication systems must be secured because of the ongoing entrance of numerous security attacks. Thus, to secure the underlying network, the 3GPP has designed an authentication and key agreement protocol, 5G-AKA, to safely and stably access the mobile services. However, some recent observations indicate that 5G-AKA has numerous shortcomings such as perfect forward secrecy violation, malicious Serving Network (SN), de-synchronization attack, privacy theft, stolen device, and denial of Service (DoS) attacks when the user uses the roaming mobile services. Considering the shortcomings of existing protocols and the requirement to offer increased security, we propose a provable secure, efficient 5G-AKA authentication protocol using the blockchain. The security features of the proposed protocol are examined using the Real-Or-Random (ROR) logic and Scyther tool. Furthermore, the performance of the proposed protocol is evaluated, which shows that it is the least costly compared to its counterparts in terms of computational and communication costs. In addition, the comparison of the Ethereum blockchain depicts that the proposed protocol takes less transaction and execution costs compared to its counterparts. Awaneesh Kumar Yadav, An Braeken, Manoj Misra, Madhusanka Liyanage |
CCNC | 2 |
| 2023 | A Novel Blockchain-based Decentralized Multi-party Certificate Management FrameworkabstractDigital certificates play a significant role in the current communication systems. However, with the limitations in the existing Certificate Management Frameworks (CMFs), such as single point of failure, the profound nature of existing certificates, and malicious Certificate Authorities (CAs), a novel framework is required to optimize certificate management. Even though blockchain is a popular approach in designing CMFs, they also failed to address all these limitations. There are no existing frameworks that distribute the functionality of the centralized CA to address these issues. Therefore, this paper proposes a blockchain-based, lightweight CMF while distributing the centralized certificate generation process among multiple parties. Certificate generation, validation, and revocation can be performed with our framework. We design the required secure communication protocols to deploy our framework in any blockchain. The proposed framework is implemented on top of a Hyperledger Fabric environment and performed a set of experiments to evaluate the performance of the framework. Also, a formal security analysis for the proposed communication protocols is provided using known security verification methods such as BAN logic and the Scyther tool. Shalitha Wijethilaka, Awaneesh Kumar Yadav, An Braeken, Madhusanka Liyanage |
TrustCom | 3 |
| 2023 | A Secure Blockchain-based Authentication and Key Agreement Protocol for 5G RoamingabstractThe fifth generation (5G) is now widely used to access network services due to the emergence of the Internet of Things (IoT) and mobile devices. To secure 5G communication, the Third Generation Partnership Project (3GPP) organization created the 5G-Authentication and Key Agreement (AKA) protocol. Security evaluations have found a number of problems in the 5G-AKA, including a violation of perfect forward secrecy, a traceability attack, and denial of service (DoS) attacks. To address the shortcomings of 5G-AKA, several enhanced versions have been developed. However, it has been shown that either these versions are expensive or do not address security issues. Additionally, less effort is put into providing security when a user utilizes roaming mobile services while a malicious Serving Network (SN) is present. This paper introduces an authentication mechanism to handle the above issues. In addition to this, a handover mechanism is also designed for re-connection. The authentication and handover phase security assessment uses the mathematical model Real-Or-Random (ROR), AVISPA, and Scyther tool. Furthermore, the performance comparison depicts that the authentication and handover phase is more efficient than existing protocols. An assessment of the smart contract function’s cost and effectiveness is also provided. Awaneesh Kumar Yadav, Manoj Misra, An Braeken, Madhusanka Liyanage |
TrustCom | 3 |
| 2023 | Highly Efficient Bidirectional Multifactor Authentication and Key Agreement for Real-Time Access to Sensor DataabstractThis article presents an authentication and key agreement protocol for users who want to have access to constrained sensor nodes deployed in the field, e.g., doctor with healthcare nodes of patient. Both sensor and user device provide direct multifactor authentication relying on physical unclonable functions and biometrics, respectively. In addition, our scheme offers protection against the presence of a semi-trusted third party, perfect forward secrecy, anonymity, untraceability, and protection against session specific data loss attacks. The combination of all these security features is unique. Moreover, it is shown that the resulting scheme outperforms most state-of-the art schemes with respect to computation and communication costs. An Braeken |
IEEE Internet Things J. | 1 |
| 2023 | μTesla-Based Authentication for Reliable and Secure Broadcast Communications in IoD Using BlockchainabstractThe Internet of Drones (IoD) manages and coordinates communications between drones in Internet of Things (IoT) applications. Ensuring security and privacy in unmanned aerial vehicles (UAVs) networks, i.e., drones, is essential to protect data from cyber attacks. In this context, providing authentication is a major challenge due to the fact that drones are devices limited in power capabilities. The problem is aggravated by the dynamism of IoD networks due to the high mobility of drones, being sensitive to packet loss and handovers. Blockchain technology is attractive to address the problem of centralization of existing authentication protocols. In this article, we provide a decentralized, secure, and efficient authentication protocol, based on$\mu $Tesla, that relies on Blockchain to manage drone authentication. We analyze the security and performance of the proposed solution. Simulation results show that the proposed solution outperforms several approaches in the literature, achieving an authentication delay of less than 250 ms with a low information exchange of 1024 bits for 128-bit security level while maintaining low computational requirements. Julio César Pérez García, Abderrahim Benslimane, An Braeken, Zhou Su 0001 |
IEEE Internet Things J. | 3 |
| 2023 | PROVE: Provable remote attestation for public verifiabilityabstractThe expanding attack surface of Internet of Things (IoT) systems calls for innovative security approaches to verify the reliability of IoT devices. To this end, Remote Attestation (RA) serves as a key mechanism that remotely detects the presence of malware in IoT devices. Typically, RA allows a centralized trusted Verifier to retrieve reliable evidence about the software integrity of an untrusted Prover. Existing RA schemes generally rely on the assumption that the Verifier and the Prover know each other and have pre-shared cryptographic keys during the bootstrap phase. However, these assumptions are not realistic to employ over commonly used event-driven IoT networks, in which the interacting parties do not know each other and do not communicate directly. This paper proposes PROVE, a novel protocol that allows many Verifiers to attest one or more Provers without pre-shared key material and without using public-key cryptography which is often not suitable for resource-constraint IoT devices. In particular, PROVE considers a realistic IoT system where devices adopt the publish/subscribe communication paradigm. In PROVE, the subscribers act as untrusted Verifiers and attest not only the firmware integrity of the publishers that act as untrusted Provers but also the authenticity of the received data originated from these publishers. We simulate PROVE on the Contiki emulator and demonstrate the scalability of the solution. We also validate PROVE through two hardware proof-of-concept implementations: PROVE and PROVE+, which rely on different cryptographic cores. The results show that a complete execution of the protocol takes 4605 ns and 324 ns for PROVE and PROVE+, respectively. Edlira Dushku, Md Masoom Rabbani, Jo Vliegen, An Braeken, Nele Mentens |
J. Inf. Secur. Appl. | 4 |
| 2023 | Open RAN security: Challenges and opportunitiesabstractOpen RAN (ORAN, O-RAN) represents a novel industry-level standard for RAN (Radio Access Network), which defines interfaces that support inter-operation between vendors’ equipment and offer network flexibility at a lower cost. Open RAN integrates the benefits and advancements of network softwarization and Artificial Intelligence to enhance the operation of RAN devices and operations. Open RAN offers new possibilities so different stakeholders can develop the RAN solution in this open ecosystem. However, the benefits of Open RAN bring new security and privacy challenges. As Open RAN offers an entirely different RAN configuration than what exists today, it could lead to severe security and privacy issues if mismanaged, and stakeholders are understandably taking a cautious approach towards the security of Open RAN deployment. In particular, this paper analyzes the security and privacy risks and challenges associated with Open RAN architecture. Then, it discusses possible security and privacy solutions to secure Open RAN architecture and presents relevant security standardization efforts relevant to Open RAN security. Finally, we discuss how Open RAN can be used to deploy more advanced security and privacy solutions in 5G and beyond RAN. Madhusanka Liyanage, An Braeken, Shahriar Shahabuddin, Pasika Ranaweera |
J. Netw. Comput. Appl. | 2 |
| 2023 | Symmetric key-based authentication and key agreement scheme resistant against semi-trusted third party for fog and dew computing
Awaneesh Kumar Yadav, An Braeken, Manoj Misra |
J. Supercomput. | 2 |
| 2023 | An Enhanced Cross-Network-Slice Authentication Protocol for 5GabstractNetwork slicing is considered one of the key technologies in future telecommunication networks as it can split the physical network into a number of logical networks tailored to diverse purposes that allow users to access various services speedily. The fifth-generation (5G) mobile network can support a variety of applications by using network slicing. However, security (especially authentication) is a significant issue when users access the network slice-based services. Various authentication schemes are designed to secure access, and only a few offer cross-network slice authentication. The security analysis of existing cross-network authentication schemes shows they are vulnerable to several attacks such as device stolen, ephemeral secret leakage, violation of perfect forward secrecy, identity theft. Therefore, we propose an authentication mechanism that offers cross-network slice authentication and prevents all the aforementioned vulnerabilities. The security verification of the authentication mechanism is carried out informally and formally (ROR logic and Scyther tool) to ensure that it handles all the vulnerabilities. The comparison of empirical evaluation shows that the proposed scheme is least costly than its competitors. Java-based implementations of the proposed protocols imitate a real environment, showing that our proposed protocol maintains almost the same performance as state-of-the-art solutions while providing additional security features. Awaneesh Kumar Yadav, Shalitha Wijethilaka, An Braeken, Manoj Misra, Madhusanka Liyanage |
IEEE Trans. Sustain. Comput. | 3 |
| 2023 | Identity-based and anonymous key agreement protocol for fog computing resistant in the Canetti-Krawczyk security modelabstractAbstract Fog computing allows to connect the edge of the network, consisting of low cost Internet of Things devices, with high end cloud servers. Fog devices can perform data processing, which can significantly reduce the delay for the application. Moreover, data aggregation can be carried out by fog devices which decrease the bandwidth needed being very important for the wireless part of the communication with the cloud servers. The edge-fog-cloud architecture is currently being rolled out for several applications in the field of connected cars, health care monitoring, etc. In this paper, we propose an identity-based, mutual authenticated key agreement protocol for this fog architecture, in which end device and fog are able to establish a secure communication without leakage of their identities. Only the cloud server is able to control the identities of device and fog. We formally prove that the session keys are also protected in the Canetti–Krawczyk security model, in which adversaries are considered to have access to session state specific information, previous session keys, or long-term private keys. The scheme is very efficient as it only utilises elliptic curve operations and basic symmetric key operations. Simone Patonico, An Braeken, Kris Steenhaut |
Wirel. Networks | 2 |
| 2022 | A multi-cloud service mesh approach applied to Internet of ThingsabstractThe joined use of cloud computing and Internet of Things (IoT) led to the definition of Cloud of Things (CoT), a powerful combination which builds on the strengths of both technologies. Active research in this field provides brand new solutions or improves the ones already in place, but it is hampered by the lack of standardization and by the heterogeneity of adopted technologies. The focus of this work is on the application of a service mesh network to include IoT edge devices in a multi-cloud cluster federation. As the adoption of multi-cloud is rising day by day, the integration of IoT applications in it will surely follow. Available solutions are often restricted to specific use cases and technologies or require IoT middleware to work. The goal of this paper is to propose an architecture which can be used to achieve connectivity, interaction and data exchange between multiple IoT edge devices hosted in distinct environments, through the realisation of a network service mesh. A logical architecture is proposed, defining the components needed, discussing potential applications. An implementation is realised to demonstrate the feasibility of the system. Measurements show that with a negligible increase of computational resources and time, the benefits of a service mesh can be extended to IoT edge devices and the applications deployed on them. Luca Gattobigio, Steffen Thielemans, Priscilla Benedetti, Gianluca Reali, An Braeken, Kris Steenhaut |
IECON | 5 |
| 2022 | Experiences with on-premise open source cloud infrastructure with network performance validationabstractWhen looking at cloud computing, aside from the commercial solutions like Amazon Web Services and Microsoft Azure, there are also promising open source alternatives. In this paper, our hands-on experiences are summarized with consuming, deploying and managing an on-premise Infrastructure as a Service (IaaS) cloud solution based on the open source OpenStack platform in combination with Ceph as a distributed storage solution. We introduce means on how to achieve high-availability of this small-scale on-premise cloud infrastructure solution and provide network architecture and storage recommendations. Finally, performance measurements of these network and storage solutions are presented, indicating observable throughput and latency differences between the various configurations. Steffen Thielemans, Ruben de Smet, Priscilla Benedetti, Gianluca Reali, An Braeken, Kris Steenhaut |
IECON | 5 |
| 2022 | An improved and provably secure symmetric-key based 5G-AKA Protocol
Awaneesh Kumar Yadav, Manoj Misra, Pradumn Kumar Pandey, An Braeken, Madhusanka Liyanage |
Comput. Networks | 4 |
| 2022 | Pairing free asymmetric group key agreement protocol
An Braeken |
Comput. Commun. | 1 |
| 2022 | SHA 3 and Keccak variants computation speeds on constrained devicesabstractIn 2015, the National Institute of Standards and Technology (NIST) announced Keccak as the new primitive to be used in SHA 3, not replacing but complementing SHA 2. The Keccak primitive, based on a sponge construction, has flexible parameters that can be controlled by the user to fit the needs of the application. However, the SHA 3 standard constrains and predefines the Keccak parameters to be used and thus making its use less flexible. In this paper we try to understand the influence of these parameters with respect to memory size and throughput, specifically for constrained devices used in the Internet of Things (IoT) where speed and efficiency is important. Apart from evaluations of the code on real devices, a mathematical model is also presented which helps predicting the performance of the Keccak primitive. We also compare the standard functions from SHA 2 with SHA 3 on different platforms. All implementations of SHA 2, SHA 3 and Keccak are purely written in Rust, since Rust guarantees safe memory manipulation whilst having the same performance as C. Our measurements show that for the software implementations SHA 2 is always faster than SHA 3 on all tested platforms. When only looking at the Keccak construction, Keccak- 𝑓 [ 8 0 0 ] always outperforms other permutations based on Keccak- 𝑓 when the capacity 𝑐 stays below 276 bits. In addition, Keccak- 𝑓 [ 8 0 0 ] has the added advantage of using less flash memory on 32-bit platforms. Thibaut Vandervelden, Ruben de Smet, Kris Steenhaut, An Braeken |
Future Gener. Comput. Syst. | 4 |
| 2022 | Fog Computing and Blockchain-Based Security Service Architecture for 5G Industrial IoT-Enabled Cloud ManufacturingabstractRecent evolution of the industrial Internet of Things empowers the classical manufacturing model with cloud computing integration for Industry 4.0. Cloud integration advances the capabilities of manufacturing systems with cloud-based controlling and real-time process monitoring, which is renowned as cloud manufacturing (CM). However, cloud integration exposes the entire manufacturing ecosystem to a new set of security risks and increments in end-to-end latency. Moving security services toward the edge eradicates message routing latency toward the cloud and eliminates the central point of failure while leveraging the entire system’s performance. We propose a blockchain and fog-computing-enabled security service architecture that operates on fog nodes at the edge of manufacturing equipment clusters. The proposed service facilitates CM equipment authentication and equipment-cloud channel privacy protection while preserving anonymity and unlinkability over the blockchain. We implemented the proposed architecture with hyperledger fabric and compared the performance advantage over the state-of-the-art solutions. Tharaka Mawanane Hewa, An Braeken, Madhusanka Liyanage, Mika Ylianttila |
IEEE Trans. Ind. Informatics | 2 |
| 2022 | Authenticated key agreement protocols for dew-assisted IoT systems
An Braeken |
J. Supercomput. | 1 |
| 2021 | Detection of evil flies: securing air-ground aviation communicationabstractThe aviation community is employing various air traffic control and mobile communication technologies, such as ubiquitous data links, wireless communication architectures and protocols. Recently, software-defined networking (SDN) based architectures (i.e., cockpit network communications environment testing (COMET)) have been proposed for Air-Ground communication. However, an evil can break the communication between a pilot and air traffic control, resulting in a hazardous (or life-threatening) situation up in the air or failure of ground equipment. This paper proposes an efficient evil detection and prevention mechanism (called DoEF) for the COMET architecture. The proposed DoEF utilizes a deep learning-based approach, i.e., long-short term memory (LSTM), to detect the evil flies and provide possible countermeasures. Our preliminary results show that the proposed scheme reduces the detection time and increases the detection accuracy of distributed denial of service (DDoS) attacks for the aviation network. Suleman Khan 0003, Pardeep Kumar 0001, An Braeken, Andrei V. Gurtov |
MobiCom | 3 |
| 2021 | RESERVE: Remote Attestation of Intermittent IoT devicesabstractInternet of Things (IoT) devices have enveloped our surroundings and have been increasingly deployed in many domains. Even though the IoT has generated unprecedented opportunities, the poorly secured design of IoT devices makes them an easy target for cyber attacks. Aimed at securing IoT devices, Remote Attestation (RA) is a security technique that identifies threat presence in IoT systems. Typically, RA is an atomic procedure that requires uninterrupted connectivity to execute. However, in energy harvesting context where intermittent IoT devices go into sleep mode immediately after regular operations, the atomic property is difficult to achieve. In this paper, we propose RESERVE, a novel lightweight RA protocol designed specifically for Intermittent IoT devices. RESERVE aims to improve the security of intermittent systems by detecting malware presence during online mode and guaranteeing with some probability software legitimacy during offline mode. In particular, RESERVE ensures trustworthiness by organizing the device's software into modules, and after regular operation each device attests as many modules as fit in its energy budget. Md Masoom Rabbani, Edlira Dushku, Jo Vliegen, An Braeken, Nicola Dragoni, Nele Mentens |
SenSys | 4 |
| 2021 | Device-to-device group authentication compatible with 5G AKA protocol
An Braeken |
Comput. Networks | 1 |
| 2021 | Privacy Protected Blockchain Based Architecture and Implementation for Sharing of Students' CredentialsabstractSharing of students’ credentials is a necessary and integral process of an education ecosystem that comprises various stakeholders like students, schools, companies, professors and the governmental authorities. As of today, all these stakeholders have to put-in an enormous amount of efforts to ensure the authenticity and privacy of students’ credentials. Despite these efforts, the process of sharing students’ credentials is complex, error-prone and not completely secure. Our aim is to leverage blockchain technology to mitigate the existing security-related issues concerning the sharing of students’ credentials. Thus, the paper proposes a tamper-proof, immutable, authentic, non-repudiable, privacy protected and easy to share blockchain-based architecture for secured sharing of students’ credentials. To increase the scalability, the proposed system uses a secure off-chain storage mechanism. The performance and viability of the proposed architecture is analyzed by using an Ethereum based prototypical implementation. The test results imply that requests can be executed within few seconds (without block-time) and the system has stability to process up to 1000 simultaneous requests. Raaj Anand Mishra, Anshuman Kalla, An Braeken, Madhusanka Liyanage |
Inf. Process. Manag. | 3 |
| 2021 | ECQV-IBI: Identity-based identification with implicit certification
An Braeken, Ji-Jian Chin, Syh-Yuan Tan |
J. Inf. Secur. Appl. | 1 |
| 2021 | Proxy re-encryption enabled secure and anonymous IoT data sharing platform based on blockchainabstractData is central to the Internet of Things (IoT) ecosystem. With billions of devices connected, most of the current IoT systems are using centralized cloud-based data sharing systems, which will be difficult to scale up to meet the demands of future IoT systems. The involvement of such a third-party service provider requires also trust from both the sensor owner and sensor data user. Moreover, fees need to be paid for their services. To tackle both the scalability and trust issues and to automatize the payments, this paper presents a blockchain-based marketplace for sharing of the IoT data. We also use a proxy re-encryption scheme for transferring the data securely and anonymously, from data producer to the consumer. The system stores the IoT data in cloud storage after encryption. To share the collected IoT data, the system establishes runtime dynamic smart contracts between the sensor and data consumer without the involvement of a trusted third-party. It also uses a very efficient proxy re-encryption scheme which allows that the data is only visible by the owner and the person present in the smart contract. This novel combination of smart contracts with proxy re-encryption provides an efficient, fast and secure platform for storing, trading and managing sensor data. The proposed system is implemented using off-the-shelf IoT sensors and computer devices. We also analyze the performance of our hybrid system by using the permission-less Ethereum blockchain and compare it to the IBM Hyperledger Fabric, a permissioned blockchain. Ahsan Manzoor, An Braeken, Salil S. Kanhere, Mika Ylianttila, Madhusanka Liyanage |
J. Netw. Comput. Appl. | 2 |
| 2021 | Proximity Measurement for Hierarchical Categorical Attributes in Big DataabstractNearly most of the organizations store massive amounts of data in large databases for research, statistics, and mining purposes. In most cases, much of the accumulated data contain sensitive information belonging to individuals which may breach privacy. Hence, ensuring privacy in big data is considered a very important issue. The concept of privacy aims to protect sensitive information from various attacks that may violate the identity of individuals. Anonymization techniques are considered the best way to ensure privacy in big data. Various works have been already realized, taking into account horizontal clustering. The L-diversity technique is one of those techniques dealing with sensitive numerical and categorical attributes. However, the majority of anonymization techniques using L-diversity principle for hierarchical data cannot resist the similarity attack and therefore cannot ensure privacy carefully. In order to prevent the similarity attack while preserving data utility, a hybrid technique dealing with categorical attributes is proposed in this paper. Furthermore, we highlighted all the steps of our proposed algorithm with detailed comments. Moreover, the algorithm is implemented and evaluated according to a well-known information loss-based criterion which is Normalized Certainty Penalty (NCP). The obtained results show a good balance between privacy and data utility. Zakariae El Ouazzani, An Braeken, Hanan El Bakkali |
Secur. Commun. Networks | 2 |
| 2021 | Highly efficient key agreement for remote patient monitoring in MEC-enabled 5G networks
An Braeken, Madhusanka Liyanage |
J. Supercomput. | 1 |
| 2021 | Toward the inclusion of end-to-end security in the OM2M platform
Simone Patonico, Placide Shabisha, An Braeken, Kris Steenhaut |
J. Supercomput. | 4 |
| 2021 | Lightweight PUF based authentication scheme for fog architecture
Ruben de Smet, Thibaut Vandervelden, Kris Steenhaut, An Braeken |
Wirel. Networks | 4 |
| 2020 | Multi-Access Edge Computing and Blockchain-based Secure Telehealth System Connected with 5G and IoTabstractThere is a global hype in the development of digital healthcare infrastructure to cater the massive elderly population and infectious diseases. The digital facilitation is expected to ensure the patient privacy, scalability, and data integrity on the sensitive life critical healthcare data, while aligning to the global healthcare data protection standards. The patient data sharing to third parties such as research institutions and universities is also concerned as a significant contribution to the society to sharpen the research and investigations. The emergence of 5G communication technologies eradicates the borders between patients, hospital and other institutions with high end service standards. In patients' perspective, healthcare service delivery through the digital medium is beneficial in terms of time, costs, and risks. In this paper, we propose a novel Multi-access Edge Computing(MEC) and blockchain based service architecture utilizing the lightweight ECQV (Elliptic Curve Qu-Vanstone) certificates for the realtime data privacy, integrity, and authentication between IoT, MEC, and cloud. We further attached storage offloading capability to the blockchain to ensure scalability with a massive number of connected medical devices to the cloud. We introduced a rewarding scheme to the patients and hospitals through the blockchain to encourage data sharing. The access control is handled through the smart contracts. We evaluated the proposed system in a near realistic implementation using Hyperledger Fabric blockchain platform with Raspberry Pi devices to simulate the activity of the medical sensors. Tharaka Mawanane Hewa, An Braeken, Mika Ylianttila, Madhusanka Liyanage |
GLOBECOM | 2 |
| 2020 | Blockchain-based Automated Certificate Revocation for 5G IoTabstractInternet of Things (IoT) is a key topic of interest in modern communication context with the evolution of 5G and beyond ecosystems. 5G will interconnects billions of IoT devices wirelessly. The wireless communication exposes the devices to massive security risks in different dimensions. The Public Key Infrastructure (PKI) is one of the promising solutions to eliminate security risks. It ensures the authentication and communication integrity by using public key certificates. However, the overhead of certificate storage is a significant problem for the resource constrained IoT devices. We propose an application of Elliptic Curve Qu Vanstone (ECQV) certificates, which are lightweight in size for the resource restricted IoT devices. Furthermore, we incorporate the blockchain based smart contracts to handle the certificate related operations. We utilize the smart contracts in the certificate issuance and developed a smart contract based threat scoring mechanism to automatically revoke the certificates. The lightweight nature of ECQV certificates enables the distributed ledger to store, update, and revoke the certificates. We evaluated the proposed solution in Hyperledger Fabric blockchain platform. Tharaka Mawanane Hewa, An Braeken, Mika Ylianttila, Madhusanka Liyanage |
ICC | 2 |
| 2020 | Symmetric key based 5G AKA authentication protocol satisfying anonymity and unlinkability
An Braeken |
Comput. Networks | 1 |
| 2020 | Elliptic curve-based proxy re-signcryption scheme for secure data storage on the cloudabstractSummary Consider the situation of a patient carrying a body area network with sensors measuring different body characteristics. These data should be securely sent to the cloud and only retrievable by doctors authorized by the patient. Even the cloud service provider should not be able to derive the sensible data. In order to address this problem, this paper first proposes a highly efficient certificate‐based signcryption scheme, able to execute signing and encryption in one single phase and to guarantee the link between identity and public key. We show that our proposed scheme outperforms others both in computation and communication complexity. Next, based on this primitive, a complete proxy re‐signcryption scheme is presented to be integrated in this smart body area network. The proposed schemes are based on elliptic curve operations and do not use compute intensive pairing operations, like previous proposals. We show that our scheme outperforms previous proposed proxy re‐signcryption schemes in the literature. Simone Patonico, Placide Shabisha, An Braeken, Abdellah Touhafi, Kris Steenhaut |
Concurr. Comput. Pract. Exp. | 3 |
| 2019 | Demonstration of a Multimode SoC FPGA-Based Acoustic CameraabstractThe relatively low-cost of the Micro-Electromechanical Systems (MEMS) microphones together with recent advances in the MEMS technology facilitates the construction of large MEMS microphone arrays, which are used to collect the acoustic information from certain beamed directions by applying beamforming techniques. The use of beamforming techniques to steer the microphone array response is the principle used by acoustic cameras to graphically display the acoustic information in a heatmap form. Our demonstrator exploits the heterogeneous nature of System-on-Chip (SoC) FPGA systems by generating real-time acoustic images on the FPGA component while alleviating the Wireless Sensor Networks (WSN) bandwidth limitations by performing acoustic image processing locally on the hard-core processor. As a result, a real-time acoustic heatmap is generated, enabling the visualization of the sound sources characteristics. Bruno da Silva 0001, Laurent Segers, An Braeken, Abdellah Touhafi |
FPL | 3 |
| 2019 | Towards Energy Efficient LoRa Multihop NetworksabstractWe propose an adaptation of the well-known Time Slotted Channel Hopping (TSCH) Medium Access Control (MAC) protocol, which was initially specified for IEEE 802.15.4 based networks, for operation over the LoRa PHY layer. Thanks to its deterministic nature, multiple concurrent communications can be handled, while reducing channel collision and ensuring reliability in a power-efficient manner. The proposed solution was implemented in the Contiki-NG operating system and tested on real motes. Maite Bezunartea, Roald Van Glabbeek, An Braeken, Jacques Tiberghien, Kris Steenhaut |
LANMAN | 3 |
| 2019 | Integration of oneM2M in Inter-IoT's platform of platformsabstractA major goal of the H2020 Inter-IoT project is to provide a framework for seamless integration of different Internet of Things (IoT) platforms. To allow the Inter-IoT user to interact with those platforms, which feature their own syntax and Application Programming Interfaces (APIs), so called bridges are designed and implemented. For ensuring interoperability, semantics play a key role. The ontologies used by the different platforms need to be aligned with a central ontology. We present the features supported by Inter-IoT's Inter-MiddleWare layer and discuss the operation of a bridge towards a oneM2M based platform. Steffen Thielemans, Benjamin Sartori, An Braeken, Kris Steenhaut |
LANMAN | 3 |
| 2018 | Digital signatures and signcryption schemes on embedded devices: a trade-off between computation and storageabstractThis paper targets the efficient implementation of digital signatures and signcryption schemes on typical internet-of-things (IoT) devices, i.e. embedded processors with constrained computation power and storage. Both signcryption schemes (providing digital signatures and encryption simultaneously) and digital signatures rely on computation-intensive public-key cryptography. When the number of signatures or encrypted messages the device needs to generate after deployment is limited, a trade-off can be made between performing the entire computation on the embedded device or moving part of the computation to a precomputation phase. The latter results in the storage of the precomputed values in the memory of the processor. We examine this trade-off on a health sensor platform and we additionally apply storage encryption, resulting in five implementation variants of the considered schemes. Jori Winderickx, An Braeken, Dave Singelée, Roel Peeters, Thijs Vandenryt, Ronald Thoelen, Nele Mentens |
CF | 2 |
| 2018 | Secure and Efficient Data Accessibility in Blockchain Based Healthcare SystemsabstractThe healthcare industry is constantly reforming and adopting new shapes with respect to the technological evolutions and transitions. One of the crucial requirements in the current smart healthcare systems is the protection of patients sensitive data against the potential adversaries. Therefore, it is vital to have secure data access mechanisms that can ensure only authorized entities can access the patients medical information. Hence, this paper considers blockchain technology as a distributed approach protect the data in healthcare systems. This research proposes a blockchain based secure and efficient data accessibility mechanism for the patient and the doctor in a given healthcare system. Proposed system able to protect the privacy of the patients as well. The security analysis of our scheme shows that it can resist to well-known attacks along with maintaining the integrity of the system. Moreover, an Ethereum based implementation has used to verify the feasibility of our proposed system. Vidhya Ramani, Tanesh Kumar, An Braeken, Madhusanka Liyanage, Mika Ylianttila |
GLOBECOM | 3 |
| 2018 | Blockchain Utilization in Healthcare: Key Requirements and ChallengesabstractBlockchain is so far well-known for its potential applications in financial and banking sectors. However, blockchain as a decentralized and distributed technology can be utilized as a powerful tool for immense daily life applications. Healthcare is one of the prominent applications area among others where blockchain is supposed to make a strong impact. It is generating wide range of opportunities and possibilities in current healthcare systems. Therefore, this paper is all about exploring the potential applications of blockchain technology in current healthcare systems and highlights the most important requirements to fulfill the need of such systems such as trustless and transparent healthcare systems. In addition, this work also presents the challenges and obstacles needed to resolve before the successful adoption of blockchain technology in healthcare systems. Furthermore, we introduce the smart contract for blockchain based healthcare systems which is key for defining the pre-defined agreements among various involved stakeholders. Tanesh Kumar, Vidhya Ramani, Ijaz Ahmad 0001, An Braeken, Erkki Harjula, Mika Ylianttila |
HealthCom | 4 |
| 2018 | Multi-radio Solution for Improving Reliability in RPLabstractAs part of the recent advances in the IoT world, constrained platforms featuring more than one radio interface have emerged. Typically, they combine the more classical short-range radio and the long or medium range technologies. However, their full potential is not yet exploited. The modifications to the IPv6 routing protocol for Low-Power and Lossy Networks (RPL) and the Medium Access Control (MAC) layer presented in this paper are a first step in this direction. They allow the node to automatically select the most suitable radio link if more than one is available, improving network reliability. This can be especially relevant for monitoring and smart cities applications. The solution is implemented in the ContikiOS, and tested with the Zolertia Re-mote platform, but can be extended to any platform featuring more than one radio interface. The presented testbed experiments indicate that more investigation is needed to optimally tune RPL's metrics for networks featuring nodes with dual-band communication capabilities. Maite Bezunartea, Chenlu Wang, An Braeken, Kris Steenhaut |
PIMRC | 3 |
| 2018 | Horizontal Integration of CoAP and MQTT on Internet Protocol - based LoRaMotesabstractTo enable interoperability in the very fragmented IoT market, different integration platforms are emerging. oneM2M is one of such platforms that enables interoperability in two ways: by standardizing the HTTP, CoAP and MQTT message format as transport vehicle for oneM2M primitives, or by including custom-developed Interworking Proxy Entities (IPEs). We present an architecture that enables horizontal integration of long range low power LoRa motes that run CoAP or MQTT on a full TCP/IPv6-stack in a oneM2M framework. OneM2Ms standardized bindings are used for interoperating these disparate application layer protocols as they allow to reduce the development time of an IoT application integrated in the Internet. However, they also cause extra overhead in terms of payload size. Consequently, for LoRa motes, Time-on-Air is impacted, increasing power consumption and limiting the amount of data that can be sent over the Low Power Wide Area Network (LPWAN). Therefore, an alternative solution with reduced payload size, featuring IPEs for oneM2M, is also discussed. This paper shows that although oneM2M is a good interoperability enabler, a tradeoff exists between ease of development/deployment and the amount of useful data that can be sent over LPWANs. Simone Patonico, Maite Bezunartea, Steffen Thielemans, An Braeken, Kris Steenhaut |
PIMRC | 5 |
| 2018 | AAA - autonomous anonymous user authentication and its application in V2GabstractSummary Cloud computing offers a simple way to provide access to servers, storage, databases, and a broad set of application services over the Internet. Its popularity is growing spectacularly. Consequently, there is a need for strong authentication schemes, offering besides data privacy also identity privacy during these actions. Therefore, this paper presents 2 user‐friendly protocols, called the autonomous, anonymous, and authentication—AAA1 and AAA2—schemes, able to derive the required security material at user's side without the need of a secure channel between user and registration center. The protocol AAA2 has the added functionality to guarantee unforgeability and non‐repudiation of the request. Only simple elliptic curve operations, together with hashes and symmetric key encryptions are used. The proposed protocols are 2‐factor based, requiring the knowledge of the password and the possession of a correctly installed smartphone, and are very efficient to be executed on the smartphone because of a small amount of computations. As an application, we show how AAA1 can be utilized in a communication protocol for monitoring and AAA2 for charging and discharging of electrical vehicles with the smart grid. Moreover, these proposed solutions allow a much better performance, compared with the state of the art protocols in this field. An Braeken, Abdellah Touhafi |
Concurr. Comput. Pract. Exp. | 1 |
| 2018 | CoderLabs: A cloud-based platform for real-time online labs with user collaborationabstractIn this paper, we describe the architecture of a collaborative and real‐time environment for remote experiments. We also introduce a web‐based remote lab composer, which allows the interconnection and exchange of data between remote laboratories. The environment is created with web standards as HTML5 such that no plug‐in needs to be installed by the user. Users are able to use the remote lab simultaneously and in collaboration. This collaboration between users is made feasible by adopting a message broker. We will discuss how Google Coder is used to develop, change, or create a user interface for a remote experiment and how the labs can be shared in the cloud. Our newest addition to this research consists of a drag and drop lab composer, which allows Lab‐developers to use standard widgets, data‐visualization tools, and data‐ports to compose complex remote labs. A lab‐composer engine is developed to automate the coupling of the physical instances and collect the data to be visualized. The principles behind our lab‐composer engine are explained in the last part of the paper. Abdellah Touhafi, An Braeken, Abderrahim Tahiri, Mostapha Zbakh |
Concurr. Comput. Pract. Exp. | 2 |
| 2018 | Efficiency analysis methodology of FPGAs based on lost frequencies, area and cycles
Jan Lemeire, Bruno da Silva 0001, An Braeken, Jan G. Cornelis, Abdellah Touhafi |
J. Parallel Distributed Comput. | 3 |
| 2018 | An efficient anonymous authentication protocol in multiple server communication networks (EAAM)
An Braeken, Pardeep Kumar 0001, Madhusanka Liyanage, Ta Thi Kim Hue |
J. Supercomput. | 1 |
| 2017 | A partial reconfiguration based microphone array network emulatorabstractNowadays, microphone arrays are used in many applications for sound-source localization or acoustic enhancement. The current Micro-Electro-Mechanical Systems (MEMS) technology allows the development of networks of microphone arrays at a relatively low cost. Unfortunately, the evaluation of these networks requires controlled acoustic environments, such as anechoic chambers, to avoid possible distortions and acoustic artifacts. In this paper, we present a partial reconfigurable FPGA platform to emulate a network of microphone arrays. Our platform provides a controlled simulated acoustic environment, able to evaluate the impact of different network configurations such as the number of microphones per array, the network's topology or the used detection method. Data fusion techniques, combining the data collected by each node, are used in this platform. In addition, our platform is also capable to converge to the ideal network with regards to power consumption, while still maintaining the desired level of sound-source localization accuracy. A graphical user interface provides a friendly control of the network and the parameters under test during the execution of the partial reconfiguration operations. Several experiments are presented to demonstrate some of the capabilities of our platform. Bruno da Silva 0001, Federico Domínguez, An Braeken, Abdellah Touhafi |
FPL | 3 |
| 2017 | Demonstration of a partial reconfiguration based microphone array network emulatorabstractThe current Micro-Electro-Mechanical System (MEMS) technology allows to deploy relatively low-cost Wireless Sensor Networks (WSN) composed of MEMS microphone arrays for accurate sound-source localization. However, the evaluation and the selection of the most accurate and power-efficient network's topology is not trivial when considering dynamic MEMS microphone arrays. Despite software simulators are usually considered, they are high-computational intensive tasks which require hours to days to be completed. Our demonstrator is an FPGA-based network emulator, which provides a fast network design-space exploration. The user can easily evaluate a network's topology with different nodes' configurations and multiple sound sources in matter of seconds. An intuitive graphical user interface hides from the user the dynamic partial reconfigurations needed by the network emulator to set the node's configurations. As a result, a probability map generated from the fusion of the output data from the nodes and an error on the estimation of the sound-source location are graphically represented. Bruno da Silva 0001, Federico Domínguez, An Braeken, Abdellah Touhafi |
FPL | 3 |
| 2017 | Identity privacy preserving biometric based authentication scheme for Naked healthcare environmentabstractRecent developments in Internet of Things (IoT) technologies have already put a huge impact on the medical and health sector. Thus, the patient treatment can be performed in more efficient ways compared with traditional methods. Secure identification is a key system requirement for patients to acquire these health related services. Fast and convenient identification is important in the case of critical and elderly or disabled patients who required frequent health services. In this paper, we are presenting concept of the Naked environment where patients can get health services from smart and intelligent surroundings of hospital without using explicit gadgets. Patients would have direct interaction with the environment and get identified through it. We propose a biometric based authentication scheme for the Naked hospital environment that also protects the patients identity privacy. In addition, we show that this authentication scheme can resist various well known attacks such as insider attacks, replay attacks and identity privacy among others. Tanesh Kumar, An Braeken, Madhusanka Liyanage, Mika Ylianttila |
ICC | 2 |
| 2017 | An AAL-oriented measurement-based evaluation of different HTTP-based data transport protocolsabstractA key requirement for Active and Assisted Living (AAL) environments is the exchange of data between different communication endpoints to support wide range of services and applications. Used communication protocols need to support the bidirectional flow of information and have to be optimized with regard to security or latency constraints. To address these issues, RESTful approaches have recently gained much attention from the community. In this context, different application layer transport protocols can be used to realize the required data exchange. Besides HTTP/1.1, developed and standardized in the 1990s, new protocols like HTTP/2 and the QUIC transfer protocol my be suitable candidates. The impact of the different protocols on the overall performance for web and AAL services is still an open research question. This paper narrows this gap by conducting a measurement-based comparison of the three described protocols with regard to their performance in terms of web page loading times for Google web services. Thomas Zinner, Stefan Geißler, Fabian Helmschrott, Susanna Spinsante, An Braeken |
IM | 5 |
| 2017 | Enabling dual-band operation with the RPL routing protocolabstractSeveral recent sensor platforms combine long-range and more classical short-range radio technologies. In this poster we propose some modifications to the RPL routing protocol such that it automatically selects the most suitable radio link when more than one is available. The solution has been implemented in the ContikiOS and tested on the Zolertia Re-mote platform. Maite Bezunartea, Benjamin Sartori, Iñigo Francés, Jacques Tiberghien, An Braeken, Kris Steenhaut |
SenSys | 5 |
| 2017 | Enabling RPL multihop communications based on LoRaabstractNew Long-Range radio technologies have recently emerged in the IoT landscape. These technologies work in the Sub-GHz bands, allowing low-power communications over long distances. They are typically based on star-topology networks, where nodes send the data directly to a base station connected to the Internet. One of such technologies is LoRa. Enabled LoRa-based multihop communications would open up new possibilities. In this paper we present a solution allowing to have multihop LoRa communications. This is done by means of a newly designed MAC protocol (RLMAC), used to select the Spreading Factor for each available neighbor. The proposed Objective Function used by RPL will therefore be able to select the routing path that minimizes time on-air. By selecting the path with the lowest time on-air, the power consumption can be decreased, enlarging network lifetime. Preliminary validation tests are also presented in the paper. Benjamin Sartori, Steffen Thielemans, Maite Bezunartea, An Braeken, Kris Steenhaut |
WiMob | 4 |
| 2017 | BMRF: Bidirectional Multicast RPL ForwardingabstractNowadays, the transition of Wireless Sensor Networks (WSNs) to Internet Protocol version 6 (IPv6), in particular to IPv6 over Low power Wireless Personal Area Networks (6LoWPAN), is evident [1]. However, in most commonly used implementations, not all IPv6 features are available. For example, current implementations are not very optimized for multicast, despite the many benefits multicast can offer with respect to the number of radio transmissions and the amount of consumed energy. In this paper we present Bidirectional Multicast RPL Forwarding (BMRF), a new multicast protocol that combines the best features of the Routing Protocol for Low Power and Lossy Networks (RPL) multicast on the one hand and of Stateless Multicast RPL Forwarding (SMRF) on the other hand. The main features are bidirectionality and the ability to offer a choice between Link Layer broadcast and Link Layer unicast for which the threshold to decide for a mote, which link layer mode to choose, is mainly based on its number of interested children and the duty cycling rate. An implementation of BMRF is realized in Contiki. Our measurements show that BMRF, when using the optimal configuration, results in less radio transmissions, and less energy consumption, and higher packet delivery ratio compared to SMRF, often at the cost of a higher end-to-end delay. Guillermo Gastón Lorente, Bart Lemmens, Matthias Carlier, An Braeken, Kris Steenhaut |
Ad Hoc Networks | 4 |
| 2017 | Secure communication channel architecture for Software Defined Mobile Networks
Madhusanka Liyanage, An Braeken, Anca Jurcut, Mika Ylianttila, Andrei V. Gurtov |
Comput. Networks | 2 |
| 2017 | Anonymous Secure Framework in Connected Smart Home EnvironmentsabstractThe smart home is an environment, where heterogeneous electronic devices and appliances are networked together to provide smart services in a ubiquitous manner to the individuals. As the homes become smarter, more complex, and technology dependent, the need for an adequate security mechanism with minimum individual's intervention is growing. The recent serious security attacks have shown how the Internet-enabled smart homes can be turned into very dangerous spots for various ill intentions, and thus lead the privacy concerns for the individuals. For instance, an eavesdropper is able to derive the identity of a particular device/appliance via public channels that can be used to infer in the life pattern of an individual within the home area network. This paper proposes an anonymous secure framework (ASF) in connected smart home environments, using solely lightweight operations. The proposed framework in this paper provides efficient authentication and key agreement, and enables devices (identity and data) anonymity and unlinkability. One-time session key progression regularly renews the session key for the smart devices and dilutes the risk of using a compromised session key in the ASF. It is demonstrated that computation complexity of the proposed framework is low as compared with the existing schemes, while security has been significantly improved. Pardeep Kumar 0001, An Braeken, Andrei V. Gurtov, Jari H. Iinatti, Phuong Hoai Ha |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2016 | Runtime reconfigurable beamforming architecture for real-time sound-source localizationabstractSound-source localization is used in many different real-time acoustic applications. Microphone arrays have the potential capability to recognize, profile and locate sound-sources in noisy environments. The quality response of such sensor arrays, however, is determined by the quantity of microphones. A higher number of microphones increases the computational demand, making real-time response challenging. In this paper, we present a scalable and runtime reconfigurable architecture to provide accurate sound-source localization in real-time. On one hand, the reconfigurable architecture is designed to be scalable in order to support a variable number of microphones. On the other hand, we use runtime reconfigurable look-up tables (CFGLUTs) to provide a dynamic response in real-time. Experiments demonstrate how an accurate sound-source localization is obtained in less than a few hundred milliseconds. As far as we are aware, it is the first time that runtime reconfiguration is applied to a reconfigurable architecture consisting of a sensor array. Bruno da Silva 0001, Laurent Segers, An Braeken, Abdellah Touhafi |
FPL | 3 |
| 2016 | A runtime reconfigurable FPGA-based microphone array for sound source localizationabstractMicrophone arrays are able to recognize, profile and locate sound-sources in noisy environments, but their quality is determined by the number of microphones. A higher number of microphones increases the computational demand, making real-time response challenging. In this demo, we present a scalable and runtime reconfigurable architecture able to support a variable number of microphones and orientations in order to provide accurate sound-source localization in real-time. Bruno da Silva 0001, Laurent Segers, An Braeken, Abdellah Touhafi |
FPL | 3 |
| 2015 | Efficient Key Establishment for Constrained IoT Devices with Collaborative HIP-Based ApproachabstractThe Internet of Things (IoT) technologies interconnect wide ranges of network devices irrespective of their resource capabilities and local networks. The device constraints and the dynamic link creations make it challenging to use pre-shared keys for every secure end-to-end (E2E) communication scenario in IoT. Variants of Host Identity Protocol (HIP) are adopted for constructing dynamic and secure E2E connections among the heterogenous network devices with imbalanced resource profiles and less or no previous knowledge about each other. We propose a collaborative HIP solution with an efficient key establishment component for the high constrained devices in IoT, which delegates the expensive cryptographic operations to the resource rich devices in the local networks. Finally, we demonstrate the applicability of the key establishment in collaborative HIP solution for the constrained IoT devices rather than the existing HIP variants, by providing performance and security analysis. Pawani Porambage, An Braeken, Pardeep Kumar 0001, Andrei V. Gurtov, Mika Ylianttila |
GLOBECOM | 2 |
| 2015 | Group key establishment for secure multicasting in IoT-enabled Wireless Sensor NetworksabstractWireless Sensor Network (WSN) is a fundamental technology of the Internet of Things (IoT). Group communications in the form of broadcasting and multicasting incur efficient message deliveries among resource-constrained sensors in IoT-enabled WSNs. Secure and efficient key management is significant to protect the authenticity, integrity, and confidentiality of multicast messages. This paper develops two group key establishment protocols for secure multicast communications among resource-constrained devices in IoT. The applicability of the two protocols are analyzed and justified by performance and security analysis. Pawani Porambage, An Braeken, Corinna Schmitt, Andrei V. Gurtov, Mika Ylianttila, Burkhard Stiller |
LCN | 2 |
| 2013 | Performance and toolchain of a combined GPU/FPGA desktop (abstract only)abstractLow-power, high-performance computing nowadays relies on accelerator cards to speed up the calculations. Combining the power of GPUs with the flexibility of FPGAs enlarges the scope of problems that can be accelerated [2, 3]. We describe the performance analysis of a desktop equipped with a GPU Tesla 2050 and an FPGA Virtex-6 LX240T. First, the balance between the I/O and the raw peak performance is depicted using the roofline model [4]. Next, the performance of a number of image processing algorithms is measured and the results are mapped onto the roofline graph. This allows to compare the GPU and the FPGA and also to optimize the algorithms for both accelerators. A programming toolchain is implemented, consisting of OpenCL for the GPU and several High-Level Synthesis compilers for the FPGA. Our results show that the HLS compilers outperform handwritten code and offer a performance comparable to the GPU. In addition the FPGA compilers reduce the development time by an order of magnitude, at the expense of an increased resource consumption. The roofline model also shows that both accelerators are equally limited by the input/output bandwidth to the host. A well-tuned accelerator-based codesign, identifying the parallelism, the computation and data patterns of different classes of algorithms, will enable to maximize the performance of the combined GPU/FPGA system [1]. Bruno da Silva 0001, An Braeken, Erik H. D'Hollander, Abdellah Touhafi, Jan G. Cornelis, Jan Lemeire |
FPGA | 2 |
| 2013 | Compact implementation of CCM and GCM modes of AES using DSP blocksabstractIn this manuscript, we have explored how the use of DSP blocks in the implementation of two authenticated-encryption modes of AES can optimize the PAR figures. Our results reflect that a 20.98 % reduction in slice utilization can be achieved at a throughput higher than 25 Mbps (12 MHz) in the Artix-7 XC7A200TL FPGA. Antonio de la Piedra, Abdellah Touhafi, An Braeken |
FPL | 3 |
| 2013 | Comparing and combining GPU and FPGA accelerators in an image processing contextabstractNowadays, processors alone cannot deliver what computation hungry image processing applications demand. An alternative is to use hardware accelerators such as Graphics Processing Units (GPUs) or Field Programmable Gate Arrays (FPGAs). Applications, however, exhibit different performance characteristics depending on the accelerator. This paper describes the hybrid platform and the programming environment that allows to efficiently create programs on a combined GPU/FPGA desktop. We use the roofline model to identify the most appropriate accelerator for each application and High-Level Synthesis (HLS) tools to reduce the FPGA development time. To introduce our platform and tool chain both accelerators are compared by implementing a basic image operation. Next, a promising algorithm is explored and implemented, splitting and distributing the work between GPU, FPGA and CPU in order to validate the hybrid concept. Our results show that their combination exhibits a higher performance for computational intensive image processing applications than a GPU only. Bruno da Silva 0001, An Braeken, Erik H. D'Hollander, Abdellah Touhafi, Jan G. Cornelis, Jan Lemeire |
FPL | 2 |
| 2013 | Leveraging the DSP48E1 block in lightweight cryptographic implementationsabstractField programmable gate arrays (FPGAs) are generally used in sensor networks for accelerating complex algorithms, either at node or gateway level. The apparition of FPGAs in the market equipped with special blocks for performing logic operations at high-speed and reduced utilization of the platform fabric, allows the implementation of a number of algorithms mainly based on these embedded resources. In this manuscript, we have focused on the Xilinx Artix-7 platform. We have evaluated how replacing logic functions in the implementation of GF(2m) arithmetics and lightweight block ciphers can reduce the area and, consequently, the cost of the platform. Moreover, we provide an update of an IEEE 802.15.4 accelerator extended with key negotiation capabilities described in previous work. Our results suggest that FPGAs can be employed for developing infrastructure for Wireless Medical Sensor Networks (WMSNs) in cases where encrypting and authenticating a large stream of sensed data is required. In that case, traditional sensor nodes, typically based on microcontrollers and clocked at low frequencies can be ill-suited for real-time applications. Moreover, the fact that large intervals of time are required for executing both encryption and authentication schemes can impact the battery lifetime of the node in comparison of utilizing a separate coprocessor (e.g. based on FPGA) that can be turned on and off when required. Finally, promising results in terms of cost and power consumption are expected when the smallest platforms of the Artix-7 series are available. Antonio de la Piedra, An Braeken, Abdellah Touhafi |
Healthcom | 2 |
| 2012 | Comparative study of electronic visualisation techniques for e-learningabstractWe developed a learning platform that integrates three different existing methods for virtual experiments in the context of electronics and electrics. These methods include the Falstad simulator, a webservice based on the de facto SPICE simulator in electronics, and an attractive 3D visualization model called Videomodels. Based on this platform, we evaluated the representation and perception of each method. The main conclusion that could be drawn from our study was that the simple self-explaining interactive technique, obtained by the Falstad simulator, will be the perfect model in a self-study environment. On the other hand, the attractive three dimensional representation of the Videomodels, turns out to play a very important role in motivating the students during the lessons. An Braeken, Lucas Sterckx, Abdellah Touhafi, Yannick Verbelen, Francis Gueuning |
EDUCON | 1 |
| 2010 | A compact FPGA-based architecture for elliptic curve cryptography over prime fieldsabstractThis paper proposes an FPGA-based application-specific elliptic curve processor over a prime field. This research targets applications for which compactness is more important than speed. To obtain a small datapath, the FPGA's dedicated multipliers and carry-chain logic are used and no parallellism is introduced. A small control unit is obtained by following a microcode approach, in which the instructions are stored in the FPGA's Block RAM. The use of algorithms that prevent Simple Power Analysis (SPA) attacks creates an extra cost in latency. Nevertheless, the created processor is flexible in the sense that it can handle all finite field operations over 256-bit prime fields and all elliptic curves of a specified form. The comparison with other implementations on the same generation of FPGAs learns that our design occupies the smallest area. Jo Vliegen, Nele Mentens, Jan Genoe, An Braeken, Serge Kubera, Abdellah Touhafi, Ingrid Verbauwhede |
ASAP | 4 |
| 2009 | Secure FPGA technologies and techniquesabstractThis survey paper proposes an overview of contemporary FPGA-related technologies and techniques that can be used for data and system security. As such we will give an overview of the currently available features in commonly used FPGAs and link these features to established security techniques. The main goal is to evaluate the pros and contras of the different techniques and technologies in order to give directions on the security strategy. An Braeken, Serge Kubera, Frederik Trouillez, Abdellah Touhafi, Nele Mentens, Jo Vliegen |
FPL | 1 |
| 2006 | Evaluating the Resistance of Stream Ciphers with Linear Feedback Against Fast Algebraic Attacks
An Braeken, Joseph Lano, Bart Preneel |
ACISP | 1 |
| 2006 | On the security of stepwise triangular systems
Christopher Wolf, An Braeken, Bart Preneel |
Des. Codes Cryptogr. | 2 |
| 2006 | Classification of cubic (n-4)-resilient Boolean functionsabstractCarlet and Charpin classified the set of cubic (n-4)-resilient Boolean functions into four different types with respect to the Walsh spectrum and the dimension of the linear space. Based on the classification of RM(3,6)/RM(1,6), we have completed this classification of cubic (n-4)-resilient Boolean functions by deriving the corresponding algebraic normal form (ANF) and autocorrelation spectrum for each of the four types. At the same time, we have solved an open problem by proving that all plateaued cubic (n-4)-resilient Boolean functions have dimension of the linear space equal either to n-5 or n-6. An Braeken, Yuri L. Borissov, Svetla Nikova, Bart Preneel |
IEEE Trans. Inf. Theory | 1 |
| 2005 | Error-Set Codes and Related Objects
An Braeken, Ventzislav Nikov, Svetla Nikova |
COCOON | 1 |
| 2005 | A Study of the Security of Unbalanced Oil and Vinegar Signature Schemes
An Braeken, Christopher Wolf, Bart Preneel |
CT-RSA | 1 |
| 2005 | The ANF of the Composition of Addition and Multiplication mod 2n with a Boolean Function
An Braeken, Igor A. Semaev |
FSE | 1 |
| 2005 | Classification of Boolean Functions of 6 Variables or Less with Respect to Some Cryptographic Properties
An Braeken, Yuri L. Borissov, Svetla Nikova, Bart Preneel |
ICALP | 1 |
| 2005 | Probabilistic Algebraic Attacks
An Braeken, Bart Preneel |
IMACC | 1 |
| 2005 | Normality of Vectorial Functions
An Braeken, Christopher Wolf, Bart Preneel |
IMACC | 1 |
| 2005 | On the covering radii of binary Reed-Muller codes in the set of resilient Boolean functionsabstractLet R/sub t,n/ be the set of t-resilient Boolean functions in n variables, and let /spl rho//spl circ/(t,r,n) be the maximum distance between t-resilient functions and the rth-order Reed-Muller code RM(r,n). We prove that /spl rho//spl circ/(t,2,6)=16 for t=0,1,2 and /spl rho//spl circ/(3,2,7)=32, from which we derive the lower bound /spl rho//spl circ/(t,2,n) /spl ges/ 2/sup n-2/ with t /spl les/ n-4. Using a result from coding theory on the covering radius of (n-3)th- and (n-4)th-order Reed-Muller codes, we establish exact values of the covering radius of RM(n-3,n) in the set of 1-resilient Boolean functions in n variables, when /spl lfloor/n/2/spl rfloor/=1 mod 2 and lower bounds of RM(n-4,n) in the set of 2-resilient Boolean functions in n variables. This result leads again to different lower bounds for general dimensions n and r=0 or 3 mod 4. Yuri L. Borissov, An Braeken, Svetla Nikova, Bart Preneel |
IEEE Trans. Inf. Theory | 2 |
| 2003 | A Toolbox for Cryptanalysis: Linear and Affine Equivalence Algorithms
Alex Biryukov, Christophe De Cannière, An Braeken, Bart Preneel |
EUROCRYPT | 3 |
| 2003 | On the Covering Radius of Second Order Binary Reed-Muller Code in the Set of Resilient Boolean Functions
Yuri L. Borissov, An Braeken, Svetla Nikova, Bart Preneel |
IMACC | 2 |