VLDB 2026 Research / reviewers in the wild / expert
Konrad-Felix Krentz
dblp:162/1555
· DBLP profile ↗
11ranked-venue papers
9as first author
4since 2021 · last 2024
0000-0002-3798-1733ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 7 · 5 first-author · 4 since 2021Security and privacy · 2 · 2 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Security and Privacy for Fat Intra-Body Communication: Mechanisms and Protocol StackabstractInnovative medical applications based on networked implants foster the development of in-body communication technologies. Among the in-body communication technologies that are being considered, fat intra-body communication (Fat-IBC) is a very recent approach. Its main advantage lies in its higher data rate compared to earlier approaches based on capacitive and galvanic coupling. However, Fat-IBC faces privacy-, security-, as well as safety-related attacks. In this paper, we discuss security and privacy concerns about Fat-IBC, as well as corresponding countermeasures. Furthermore, we present our secure protocol stack for Fat-IBC and suggest directions for future research. Johan Engstrand, Konrad-Felix Krentz, Noor Badariah Asan, Madhushanka Padmal, Wenqing Yan, Laya Joseph, Pramod K. B. Rangaiah, Bappaditya Mandal, Christian Rohner, Maria Mani, Robin Augustine, Thiemo Voigt |
LCN | 2 |
| 2024 | Secure opportunistic routing in 2-hop IEEE 802.15.4 networks with SMORabstractThe IEEE 802.15.4 radio standard features the possibility for IEEE 802.15.4 nodes to run on batteries for several years. This is made possible by duty-cycling medium access control (MAC) protocols, which allow IEEE 802.15.4 nodes to leave their radios in energy-saving sleep modes most of the time. Yet, duty-cycling MAC protocols usually incur long routing delays since it may take a while until a particular forwarder becomes available for forwarding a packet. Opportunistic routing alleviates this problem by opportunistically using a currently available forwarder, rather than waiting for a particular forwarder. Among all opportunistic routing schemes, so-called dynamic switch-based forwarding (DSF) schemes are most promising from a security and practical perspective, but some security and reliability issues with them persist. In this paper, we propose secure multipath opportunistic routing (SMOR), a DSF scheme that improves on current DSF schemes in three regards. First, SMOR builds on a denial-of-sleep-resilient MAC layer. Current DSF schemes, by comparison, rest on MAC protocols that put the limited energy reserves of battery-powered IEEE 802.15.4 nodes at risk. Second, SMOR operates in a distributed fashion and efficiently supports point-to-point traffic. All current DSF schemes, by contrast, suffer from a single point of failure and focus on convergecast traffic. Third, SMOR duplicates packets on purpose and routes them along disjoint paths. This makes SMOR tolerant of compromises of single IEEE 802.15.4 nodes, whereas current DSF schemes lack intrusion tolerance. We integrated SMOR into the network stack of the Contiki-NG operating system and benchmarked SMOR against the Routing Protocol for Low-Power and Lossy Networks (RPL) with the Cooja network simulator. Indeed, SMOR turns out to improve on RPL’s delays by between 33.51% and 39.84%, depending on the exact configurations and network dynamics. Furthermore, SMOR achieves between 0.16% and 2.03% higher mean packet delivery ratios (PDRs), thereby attaining mean PDRs of 99.999% or better in all simulated scenarios. Beyond that, SMOR has only a fraction of RPL’s memory requirements. SMOR’s intrusion tolerance, on the other hand, increases the mean energy consumption per IEEE 802.15.4 node by between 1.55% and 2.74% compared to RPL in our simulations. SMOR specifically targets IEEE 802.15.4 networks with a network diameter of 2, such as body area networks. Konrad-Felix Krentz, Thiemo Voigt |
Comput. Commun. | 1 |
| 2021 | Poster: Multipath Extensions for WireGuardabstractThe tunneling protocol WireGuard outperforms its main competitors OpenVPN and IPsec in terms of throughput and latencies. These improvements are due to WireGuard's use of faster crypto primitives, as well as to the implementation of WireGuard as a Linux kernel module that uses multithreading and advanced locking strategies. Independently of the WireGuard project, Lukaszewski et al. demonstrated improvements in end-to-end goodput when tunneling protocols exploit alternative communication paths. In this poster, we combine these two research directions by proposing multipath extensions for WireGuard. Our extensions involve additions to the WireGuard header, which enable obtaining real-time statistics on the performance of each path. Further, these real-time path performance statistics enable a self-adaptive selection of paths. As a proof of concept, we adapted the WireGuard Linux kernel module accordingly and prototyped four example path schedulers, two of which adopt multi-armed bandit algorithms. Konrad-Felix Krentz, Marius Iulian Corici |
Networking | 1 |
| 2021 | Enabling Offline Tuning of Fat Channel CommunicationabstractThough fat channel communication has advantages over earlier intra-body communication (IBC) technologies based on galvanic or capacitive coupling, the development of a protocol stack on top of fat channel communication is still at its infancy. In this paper, we consider Krentz's denial-of-sleep-resilient multi-channel medium access control (MAC) layer for IEEE 802.15.4 networks as a starting point for such a protocol stack. In brief, we conducted the following experiment with a phantom that mimics human tissues. Two devices exchanged IEEE 802.15.4 radio frames in a ping-pong manner on the phantom's fat tissue using Krentz's MAC layer. The data collected from this experiment lends itself to two purposes. First, it can serve to benchmark and tune algorithms for selecting radio channels. Second, it can also serve to benchmark and tune schemes for deriving cryptographic keys from received signal strength indicator (RSSI) readings. We made the data available at https://uppsala.box.com/s/z2a6jpigswpoifd5l73yophokcfwd88b. Konrad-Felix Krentz, Madhushanka Padmal, Bappaditya Mandal, Robin Augustine, Thiemo Voigt |
SenSys | 1 |
| 2019 | Denial-of-sleep defenses for IEEE 802.15.4 coordinated sampled listening (CSL)
Konrad-Felix Krentz, Christoph Meinel |
Comput. Networks | 1 |
| 2018 | Denial-of-Sleep-Resilient Session Key Establishment for IEEE 802.15.4 Security: From Adaptive to Responsive
Konrad-Felix Krentz, Christoph Meinel, Hendrik Graupner |
EWSN | 1 |
| 2017 | Countering Three Denial-of-Sleep Attacks on ContikiMAC
Konrad-Felix Krentz, Christoph Meinel, Hendrik Graupner |
EWSN | 1 |
| 2017 | Secure self-seeding with power-up SRAM statesabstractGenerating seeds on Internet of things (IoT) devices is challenging because these devices typically lack common entropy sources, such as user interaction or hard disks. A promising replacement is to use power-up static random-access memory (SRAM) states, which are partly random due to manufacturing deviations. Thus far, there, however, seems to be no method for extracting close-to-uniformly distributed seeds from power-up SRAM states in an information-theoretically secure and practical manner. Moreover, the min-entropy of power-up SRAM states reduces with temperature, thereby rendering this entropy source vulnerable to so-called freezing attacks. In this paper, we mainly make three contributions. First, we propose a new method for extracting uniformly distributed seeds from power-up SRAM states. Unlike current methods, ours is information-theoretically secure, practical, and freezing attack-resistant rolled into one. Second, we point out a trick that enables using power-up SRAM states not only for self-seeding at boot time, but also for reseeding at runtime. Third, we compare the energy consumption of seeding an IoT device either with radio noise or power-up SRAM states. While seeding with power-up SRAM states turned out to be more energy efficient, we argue for mixing both these entropy sources. Konrad-Felix Krentz, Christoph Meinel, Hendrik Graupner |
ISCC | 1 |
| 2017 | Enabling En-Route Filtering for End-to-End Encrypted CoAP MessagesabstractIoT devices usually are battery-powered and directly connected to the Internet. This makes them vulnerable to so-called path-based denial-of-service (PDoS) attacks. For example, in a PDoS attack an adversary sends multiple Constrained Application Protocol (CoAP) messages towards an IoT device, thereby causing each IoT device along the path to expend energy for forwarding this message. Current end-to-end security solutions, such as DTLS or IPsec, fail to prevent such attacks since they only filter out inauthentic CoAP messages at their destination. This demonstration shows an approach to allow en-route filtering where a trusted gateway has all necessary information to check the integrity, decrypt and, if necessary, drop a message before forwarding it to the constrained mote. Our approach preserves precious resources of IoT devices in the face of path-based denial-of-service attacks by remote attackers. Klara Seitz, Sebastian Serth, Konrad-Felix Krentz, Christoph Meinel |
SenSys | 3 |
| 2016 | POTR: Practical On-the-Fly Rejection of Injected and Replayed 802.15.4 FramesabstractThe practice of rejecting injected and replayed 802.15.4 frames only after they were received leaves 802.15.4 nodes vulnerable to broadcast and droplet attacks. Basically, in broadcast and droplet attacks, an attacker injects or replays plenty of 802.15.4 frames. As a result, victim 802.15.4 nodes stay in receive mode for extended periods of time and expend their limited energy. He et al. considered embedding one-time passwords in the synchronization headers of 802.15.4 frames so as to avoid that 802.15.4 nodes detect injected and replayed 802.15.4 frames in the first place. However, He et al.'s, as well as similar proposals lack support for broadcast frames and depend on special hardware. In this paper, we propose Practical On-the-fly Rejection (POTR) to reject injected and replayed 802.15.4 frames early during receipt. Unlike previous proposals, POTR supports broadcast frames and can be implemented with many off-the-shelf 802.15.4 transceivers. In fact, we implemented POTR with CC2538 transceivers, as well as integrated POTR into the Contiki operating system. Furthermore, we demonstrate that, compared to using no defense, POTR reduces the time that 802.15.4 nodes stay in receive mode upon receiving an injected or replayed 802.15.4 frame by a factor of up to 16. Beyond that, POTR has a small processing and memory overhead, and incurs no communication overhead. Konrad-Felix Krentz, Christoph Meinel, Maxim Schnjakin |
ARES | 1 |
| 2015 | Handling Reboots and Mobility in 802.15.4 SecurityabstractTo survive reboots, 802.15.4 security normally requires an 802.15.4 node to store both its anti-replay data and its frame counter in non-volatile memory. However, the only non-volatile memory on most 802.15.4 nodes is flash memory, which is energy consuming, slow, as well as prone to wear. Establishing session keys frees 802.15.4 nodes from storing anti-replay data and frame counters in non-volatile memory. For establishing pairwise session keys for use in 802.15.4 security in particular, Krentz et al. proposed the Adaptable Pairwise Key Establishment Scheme (APKES). Yet, APKES neither supports reboots nor mobile nodes. In this paper, we propose the Adaptive Key Establishment Scheme (AKES) to overcome these limitations of APKES. Above all, AKES makes 802.15.4 security survive reboots without storing data in non-volatile memory. Also, we implemented AKES for Contiki and demonstrate its memory and energy efficiency. Of independent interest, we resolve the issue that 802.15.4 security stops to work if a node's frame counter reaches its maximum value, as well as propose a technique for reducing the security-related per frame overhead. Konrad-Felix Krentz, Christoph Meinel |
ACSAC | 1 |