Sascha Wessel

dblp:121/5964 · DBLP profile ↗
← Back
17ranked-venue papers
2as first author
3since 2021 · last 2023
0000-0002-9063-8416ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 17 · 2 first-author · 3 since 2021
YearPublicationVenuePosition
2023 Confidential Quantum Computing
abstract
Quantum computing is becoming more accessible with increasing numbers of quantum platforms. The confidentiality and integrity of data and algorithms running on these systems are important assets that need to be protected from untrusted parties. Previous approaches focus on the encryption of individual sub-areas, often using at least hybrid clients, and do not take the entire path from the classical client via a platform to the quantum computing hardware into consideration. Based on the classification of quantum algorithms we show the assets worth protecting, evolve the data flow on third-party quantum hardware and quantum computing platforms, and propose a concept architecture addressing confidentiality and integrity of processed data and code. Our approach shows that confidentiality can already be achieved for data with classical clients, while code confidentiality remains an open question. Our approach covers integrity for most complexity classes.
Barbora Hrdá, Sascha Wessel
ARES2
2023 Universal Remote Attestation for Cloud and Edge Platforms
abstract
With more computing workloads being shifted to the cloud, verifying the integrity of remote software stacks through remote attestation becomes an increasingly important topic. During remote attestation, a prover provides attestation evidence to a verifier, backed by a hardware trust anchor. While generating this information, which is essentially a list of hashes, is easy, examining the trustworthiness of the overall platform based on the provided list of hashes without context is difficult. Furthermore, as different trust anchors use different formats, interaction between devices using different attestation technologies is a complex problem.
Simon Ott, Monika Kamhuber, Joana Pecholt, Sascha Wessel
ARES4
2022 CoCoTPM: Trusted Platform Modules for Virtual Machines in Confidential Computing Environments
abstract
Cloud computing has gained popularity and is increasingly used to process sensitive and valuable data. This development necessitates the protection of data from the cloud provider and results in a trend towards confidential computing. Hardware-based technologies by AMD, Intel and Arm address this and allow the protection of virtual machines and the data processed in them. Unfortunately, these hardware-based technologies do not offer a unified interface for necessary tasks like secure key generation and usage or secure storage of integrity measurements. Moreover, these technologies are oftentimes limited in functionality especially regarding remote attestation. On the other hand, a unified interface is widely used in the area of bare-metal systems to provide these functionalities: the Trusted Platform Module (TPM).
Joana Pecholt, Sascha Wessel
ACSAC2
2019 Freeze and Crypt: Linux kernel support for main memory encryption
Manuel Huber 0001, Julian Horsch, Junaid Ali 0002, Sascha Wessel
Comput. Secur.4
2017 Freeze & Crypt: Linux Kernel Support for Main Memory Encryption
abstract
S.17-30
Manuel Huber 0001, Julian Horsch, Junaid Ali 0002, Sascha Wessel
SECRYPT4
2016 CoKey: fast token-based cooperative cryptography
Julian Horsch, Sascha Wessel, Claudia Eckert 0001
ACSAC2
2016 A flexible framework for mobile device forensics based on cold boot attacks
abstract
Mobile devices, like tablets and smartphones, are common place in everyday life. Thus, the degree of security these devices can provide against digital forensics is of particular interest. A common method to access arbitrary data in main memory is the cold boot attack. The cold boot attack exploits the remanence effect that causes data in DRAM modules not to lose the content immediately in case of a power cut-off. This makes it possible to restart a device and extract the data in main memory.In this paper, we present a novel framework for cold boot-based data acquisition with a minimal bare metal application on a mobile device. In contrast to other cold boot approaches, our forensics tool overwrites only a minimal amount of data in main memory. This tool requires no more than three kilobytes of constant data in the kernel code section. We hence sustain all of the data relevant for the analysis of the previously running system. This makes it possible to analyze the memory with data acquisition tools. For this purpose, we extend the memory forensics tool Volatility in order to request parts of the main memory dynamically from our bare metal application. We show the feasibility of our approach on the Samsung Galaxy S4 and Nexus 5 mobile devices along with an extensive evaluation. First, we compare our framework to a traditional memory dump-based analysis. In the next step, we show the potential of our framework by acquiring sensitive user data.
Manuel Huber 0001, Benjamin Taubmann, Sascha Wessel, Hans P. Reiser, Georg Sigl
EURASIP J. Inf. Secur.3
2015 A Lightweight Framework for Cold Boot Based Forensics on Mobile Devices
abstract
Mobile devices, like tablets and smartphones, are common place in everyday life. Thus, the degree of security these devices can provide against digital forensics is of particular interest. A common method to access arbitrary data in main memory is the cold boot attack. The cold boot attack exploits theremanence effect that causes data in DRAM modules not to lose the content immediately in case of a power cut-off. This makes it possible to restart a device and extract the data in main memory. In this paper, we present a novel framework for cold boot based data acquisition with a minimal bare metal application on a mobile device. In contrast to other cold boot approaches, our forensics tool overwrites only a minimal amount of data in main memory. This tool requires no more than five kilobytes of constant data in the kernel code section. We hence sustain all of the data relevant for the analysis of the previously running system. This makes it possible to analyze the memory with data acquisition tools. For this purpose, we extend the memory forensics tool Volatility in order to request parts of the main memory dynamically from our bare metal application. We show the feasibility of our approach by comparing it to a traditional memory dump based analysis using the Samsung Galaxy S4 mobile device.
Benjamin Taubmann, Manuel Huber 0001, Sascha Wessel, Lukas Heim, Hans P. Reiser, Georg Sigl
ARES3
2015 A Secure Architecture for Operating System-Level Virtualization on Mobile Devices
Manuel Huber 0001, Julian Horsch, Michael Velten, Sascha Wessel
Inscrypt5
2015 User Identity Verification Based on Touchscreen Interaction Analysis in Web Contexts
Michael Velten, Peter Schneider 0002, Sascha Wessel, Claudia Eckert 0001
ISPEC3
2015 Improving mobile device security with operating system-level virtualization
Sascha Wessel, Manuel Huber 0001, Frederic Stumpf, Claudia Eckert 0001
Comput. Secur.1
2014 TrustID: trustworthy identities for untrusted mobile devices
abstract
Identity theft has deep impacts in today's mobile ubiquitous environments. At the same time, digital identities are usually still protected by simple passwords or other insufficient security mechanisms. In this paper, we present the TrustID architecture and protocols to improve this situation. Our architecture utilizes a Secure Element (SE) to store multiple context-specific identities securely in a mobile device, e.g., a smartphone. We introduce protocols for securely deriving identities from a strong root identity into the SE inside the smartphone as well as for using the newly derived IDs. Both protocols do not require a trustworthy smartphone operating system or a Trusted Execution Environment. In order to achieve this, our concept includes a secure combined PIN entry mechanism for user authentication, which prevents attacks even on a malicious device. To show the feasibility of our approach, we implemented a prototype running on a Samsung Galaxy SIII smartphone utilizing a microSD card SE. The German identity card nPA is used as root identity to derive context-specific identities.
Julian Horsch, Konstantin Böttinger, Sascha Wessel, Frederic Stumpf
CODASPY4
2014 SobrTrA: a software-based trust anchor for ARM cortex application processors
abstract
In this paper, we present SobTrA, a Software-based Trust Anchor for ARM Cortex-A processors to protect systems against software-based attacks. SobTrA enables the implementation of a software-based secure boot controlled by a third party independent from the manufacturer. Compared to hardware-based trust anchors, our concept provides some other advantages like being updateable and also usable on legacy hardware. The presented software-based trust anchor involves a trusted third party device, the verifier, locally connected to the untrusted device, e.g., via the microSD card slot of a smartphone. The verifier is verifying the integrity of the untrusted device by making sure that a piece of code is executed untampered on it using a timing-based approach. This code can then act as an anchor for a chain of trust similar to a hardware-based secure boot. Tests on our prototype showed that tampered and untampered execution of SobTrA can be clearly and reliably distinguished.
Julian Horsch, Sascha Wessel, Frederic Stumpf, Claudia Eckert 0001
CODASPY2
2014 Integrity Verification and Secure Loading of Remote Binaries for Microkernel-Based Runtime Environments
abstract
While most microkernel-based systems implement non-essential software components as user space tasks and strictly separate those tasks during runtime, they often rely on a static configuration and composition of their software components to ensure safety and security. In this paper, we extend a microkernel-based system architecture with a Trusted Platform Module (TPM) and propose a verification mechanism for a microkernel runtime environment, which calculates integrity measurements before allowing to load (remote) binaries. As a result, our approach is the first to adopt the main ideas of the Integrity Measurement Architecture (IMA), which has been proposed for Linux-based systems, to a microkernel. In comparison, however, it significantly reduces the Trusted Computing Base (TCB) and allows for a strict separation of the integrity verification component from any rich operating system, such as GNU/Linux or Android, running in parallel. In our implementation, which is based on L4/Fiasco. OC with L4Re as runtime environment, we present our extension of the existing L4Re loader service that calculates integrity measurements for each binary. We also evaluate our implementation on two ARM-based developer boards and discuss code size, security, and performance of our proposed integrity verification mechanism.
Steffen Wagner, Roland Hellman, Sascha Wessel
TrustCom4
2013 Improving Mobile Device Security with Operating System-Level Virtualization
Sascha Wessel, Frederic Stumpf, Ilja Herdt, Claudia Eckert 0001
SEC1
2012 Collaboration between Competing Mobile Network Operators to Improve CIIP
Peter Schoo, Manfred Schäfer, André Egners, Hans Hofinger, Sascha Wessel, Marián Kühnel, Sascha Todt, Michael Montag
CRITIS5
2012 Attestation of Mobile Baseband Stacks
Steffen Wagner, Sascha Wessel, Frederic Stumpf
NSS2