VLDB 2026 Research / reviewers in the wild / expert
Dave Singelée
dblp:19/44
· DBLP profile ↗
32ranked-venue papers
3as first author
14since 2021 · last 2026
0000-0001-9084-698XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 19 · 1 first-author · 8 since 2021Computer networks · 4 · 1 first-author · 2 since 2021Systems, architecture and hardware · 3 · 1 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | CARPOOL: Secure And Reliable Proof of LocationabstractMultiple authentication solutions are widely deployed, such as OTP/TOTP/HOTP codes, hardware tokens, PINs, or biometrics. However, in practice, one sometimes needs to authenticate not only the user but also their location. The current state-of-the-art secure localisation schemes are either unreliable or insecure, or require additional hardware to reliably prove the user's location. This paper proposes CARPOOL, a novel, secure, and reliable approach to affirm the location of the user by solely relying on location-bounded interactions with commercial off-the-shelf devices. Our solution does not require any additional hardware, leverages devices already present in a given environment, and can be integrated effortlessly with existing security components, such as identity and access control systems. To demonstrate the feasibility of our work and to show that it can be deployed in a realistic closed environment setting, we implemented a proof of concept realisation of CARPOOL on an Android phone and multiple Raspberry Pi boards and integrated CARPOOL with Amazon Web Services (AWS) Cognito. Sayon Duttagupta, Dave Singelée, Xavier Carpent, Takahito Yoshizawa, Seyed Farhad Aghili, Aysajan Abidin, Bart Preneel |
SACMAT | 2 |
| 2026 | One Tap to Hijack Them All: A Security Analysis of the Google Fast Pair ProtocolabstractGoogle's Fast Pair Service (GFPS) extends Bluetooth pairing with one-tap setup and account synchronisation. This paper presents the first comprehensive security analysis of GFPS. By examining 25 commercial accessories from 16 vendors across 17 unique Bluetooth chipsets, we uncover systemic enforcement failures of the specification's core security requirements. Moreover, we show that the security failures we have identified in the pairing protocol can be further cascaded, amplifying their impact across the device ecosystem. Although GFPS and Google's Find Hub network are often treated as distinct services within the broader Google ecosystem, we show that failures in one can produce severe consequences in the other. We demonstrate WhisperPair, a family of practical attacks that enables unauthorised pairing, silent hijacking of audio devices, and covert account binding that registers a victim's accessory to an attacker's account, thereby enabling persistent location tracking and stalking via Google Find Hub. These vulnerabilities are not isolated incidents but symptoms of systemic, ecosystem-wide gaps in implementation, validation, and certification. Our analysis exposes that the source of these flaws lies in GFPS's reliance on fallible, application-layer state checks rather than on cryptographic enforcement, allowing them to propagate across vendors to the end users. To address the root cause, we propose IntentPair, a lightweight protocol modification that cryptographically binds the user's pairing intent into the key schedule, eliminating the vulnerability by design. Our findings show how a small usability “add-on” can introduce large-scale security and privacy risks for hundreds of millions of users. Sayon Duttagupta, Seppe Wyns, Nikola Antonijevic, Dave Singelée, Bart Preneel |
SP | 4 |
| 2026 | Certificate revocation - search for a way forwardabstractRevocation of digital certificates represents a series of improvements by IETF in order to standardize a complete and effective solution. This applies to the context of Internet web sites in which web servers and browsers use digital certificates to establish Transport Layer Security (TLS). Despite IETF’s effort over the years to establish a reliable revocation mechanism, including Certificate Revocation List (CRL), Online Certificate Status Protocol (OCSP) and its variants, various technical issues hinder complete resolution of the revocation problem. At the same time, all major browser vendors implement their own proprietary solutions to address the revocation problem. As a result, revocation solutions are fragmented, incomplete, and ineffective, and the level of real-world acceptance of standardized solutions is limited. To address this situation, in 2020, IETF has introduced short-term certificate concept to avoid revocation altogether. It is called Support for Short-Term, Automatically Renewed (STAR) which recommends a validity period of 4 days. To measure the level of adoption of this new approach in the Internet, we collected and analyzed web server certificates from 1 million websites; the result of our extensive analysis indicates that this scheme has not gained traction in reality. In fact, we found no implementation of a 4-day validity period out of more than 1.5 million server certificates that we collected. This situation indicates that the latest IETF effort to promote short-term certificates has not materialized, with no clear alternative solution in sight to resolve the revocation issue. We present our insights into the reasons for this absence of traction in reality and present our view of a possible way forward. Takahito Yoshizawa, Himanshu Agarwal, Dave Singelée, Bart Preneel |
Comput. Secur. | 3 |
| 2025 | PISA: Privacy-Preserving Smart ParkingabstractIn recent years, urban areas have experienced a rapid increase in vehicles, while parking availability has remained static, leading to a significant shortage of parking spots. This creates inconvenience for drivers and contributes to traffic congestion. A solution is the temporary use of private parking spaces by homeowners during their absence, alleviating the parking problem and generating additional income. However, current systems often neglect security and privacy, exposing users to risks. This paper presents PISA, a Privacy-Preserving Smart Parking scheme designed to address these issues through a cryptographically secure protocol. PISA enables the anonymous sharing of parking spots, allowing vehicle owners to park without revealing personal identifiers. Our contributions include a bi-directional anonymity framework ensuring neither party can identify the other and the use of formal verification to prove the soundness of our security measures. Unlike existing solutions, which often lack security focus, formal validation, or efficiency, PISA is designed to be both secure and efficient. Sayon Duttagupta, Dave Singelée |
CCNC | 2 |
| 2025 | CovFUZZ: Coverage-based fuzzer for 4G&5G protocolsabstract4G and 5G represent the current cellular communication standards utilized daily by billions of users for various applications. Consequently, ensuring the security of 4G and 5G network implementations is critically important. This paper introduces an automated fuzzing framework designed to test the security of 4G and 5G Attach procedure implementations. Our framework provides a comprehensive solution for uplink and downlink fuzzing in 4G, as well as downlink fuzzing in 5G, while supporting fuzzing on all layers except the physical layer. To guide the fuzzing process, we introduce a novel algorithm that assigns probabilities to packet fields and adjusts these probabilities based on coverage information from the device-under-test (DUT). For cases where coverage information from the DUT is unavailable, we propose a novel methodology to estimate it. When evaluating our framework, we first run the random fuzzing experiments, where the mutation probabilities are fixed throughout the fuzzing, and give an insight into how those probabilities should be chosen to optimize the Random fuzzer to achieve the best coverage. Next, we evaluate the efficiency of the proposed coverage-based algorithms by fuzzing open-source 4G stack (srsRAN) instances and show that the fuzzer guided by our algorithm outperforms the optimized Random fuzzer in terms of DUT’s code coverage. In addition, we run fuzzing tests on 13 commercial off-the-shelf (COTS) devices. In total, we discovered vulnerabilities in 10 COTS devices and all of the srsRAN 4G instances. Ilja Siros, Dave Singelée, Bart Preneel |
EuroS&P | 2 |
| 2025 | PathSafe: Secure Path Verification in Software-Defined NetworksabstractNetwork topology verification in Software-Defined Networks (SDN) poses a significant challenge, as vulnerabilities can allow attackers to deceive the controller and manipulate the data plane into incorrect topologies, thereby endangering the entire network's security. Current solutions fail to guarantee both security and efficiency in the verification process, often resulting in damaging user traffic. With the aim of solving joint objectives, in this paper, we introduce PathSafe, a novel tool constructed on top of the existing controller frameworks designed for secure path verification in SDN environments. It enables the verification of all available paths between two points in the network and ensures a secure process. Our approach requires a data plane component for real-time packet monitoring at line speed and a control plane verification step. Our research demonstrates that PathSafe effectively mitigates security risks in compromised switches and host scenarios. Alongside a theoretical exploration of this challenge, we present a proof of concept implemented in P4, a common language for programmable data planes. Results obtained in Mininet underscore the practical applicability of PathSafe that, compared to alternatives, reduces overhead in the verification process while maintaining a limited execution time. Doriana Monaco, Nikola Antonijevic, Sayon Duttagupta, Dave Singelée, Alessio Sacco, Eduard Marin, Bart Preneel |
NOMS | 4 |
| 2025 | ZeroTouch: Reinforcing RSS for Secure GeofencingabstractGeofencing, the virtual demarcation of physical spaces, is widely used for managing the localisation of Internet of Things (IoT) devices. However, traditional localisation techniques face security challenges indoors due to signal interference and susceptibility to spoofing, often requiring extensive calibration or extra hardware, limiting scalability. In this work, we propose ZeroTouch, a machine learning-based system that leverages Received Signal Strength (RSS) measurements from multiple receivers to improve the security of geofencing without introducing additional deployment overhead. While RSS-based localisation is known to have inherent security limitations, we show that by aggregating RSS readings from multiple anchor points and detecting anomalies using an autoencoder model, ZeroTouch provides a practical and automated mechanism for verifying whether a device is inside or outside a defined boundary. Rather than serving as a standalone security mechanism, ZeroTouch enhances existing authentication frameworks by adding an additional zero-touch security layer that operates passively in the background. ZeroTouch eliminates manual calibration, removes the human-in-the-loop element, and simplifies deployment. We evaluate our solution in a realistic simulated environment and demonstrate that it achieves high accuracy in distinguishing between in-room and out-of-room devices, even in strong adversarial settings. Nikola Antonijevic, Sayon Duttagupta, Dave Singelée, Enrique Argones-Rúa, Bart Preneel |
SACMAT | 3 |
| 2025 | A Novel Evidence-Based Threat Enumeration Methodology for ICS
Can Özkan, Dave Singelée |
SEC (2) | 2 |
| 2024 | Entangled States and Bell's Inequality: A New Approach to Quantum Distance BoundingabstractThis paper introduces an entanglement-based Quantum Distance Bounding (QDB) protocol, whose security derived from Bell’s inequality violation. This protocol leverages the non-locality of quantum entanglement to enhance the integrity and security of quantum channels, providing device-independent assurances. We present both the theoretical framework and a practical implementation scenario using Qiskit. This study lays the groundwork for rigorous future analyses and the refinement of QDB protocols. Kevin Bogner, Dave Singelée, Aysajan Abidin |
ISCC | 2 |
| 2023 | HAT: Secure and Practical Key Establishment for Implantable Medical DevicesabstractDuring the last few years, Implantable Medical Devices (IMDs) have evolved considerably. IMD manufacturers are now starting to rely on standard wireless technologies for connectivity. Moreover, there is an evolution towards open systems where the IMD can be remotely monitored or reconfigured through personal commercial-off-the-shelf devices such as smartphones or tablets. Nevertheless, a major problem that still remains unsolved today is the secure establishment of cryptographic keys between the IMD and such personal devices. Researchers have already proposed various solutions, most notably by relying on an additional external device. Unfortunately, these proposed approaches are either insecure, difficult to realise in practice, or are unsuitable for the latest generation of IMDs. Motivated by this, we present HAT, a secure and practical solution to provide fine-grained and dynamic access control for the next generation of IMDs, while offering full control and transparency to the patient. The main idea behind HAT is to shift the access control responsibilities from the IMD to an external device under the user's control, such as a smartphone, acting as the IMD's Key Distribution Center. We show that HAT only introduces minimal energy and memory overhead and formally prove its security using Verifpal. Sayon Duttagupta, Eduard Marin, Dave Singelée, Bart Preneel |
CODASPY | 3 |
| 2023 | DASLog: Decentralized Auditable Secure Logging for UAV EcosystemsabstractRapid technological advancements in unmanned aerial vehicles (UAVs) have revolutionized intelligent platforms such as smart cities. These advancements have paved the way for an emerging class of Internet of Things (IoT) systems called the Internet of Drones (IoD), which has noteworthy security and privacy challenges. In this article, we tackle the problem of secure logging and design a novel secure logging scheme—DASLog—for the use case of aerial transport of (medical) goods via drones. Our logging scheme provides public auditability of logging records in the setting where all logging components are managed by a single entity. Our secure logging system relies on hash chains and a Merkle tree to generate proofs for stored logging records. These proofs get written on a private blockchain and can be used later by data consumers to verify the integrity and completeness of a set of logging records. We demonstrate the feasibility of our approach via a proof-of-concept prototype relying on Hyperledger Besu and implemented on multiple Amazon EC2 instances. The performance evaluation of our demonstrator shows that up to 8000 logging records per second can be processed. Roozbeh Sarenche, Seyed Farhad Aghili, Takahito Yoshizawa, Dave Singelée |
IEEE Internet Things J. | 4 |
| 2022 | T-HIBE: A Novel Key Establishment Solution for Decentralized, Multi-Tenant IoT SystemsabstractThe Internet of Things (IoT) devices has evolved considerably in the past few years and is expected to grow exponentially in the next decade. This exponential growth makes key management in an IoT ecosystem very challenging. Traditional IoT systems are often centralized and grouped into an ecosystem. However, this type of centralized architecture is not always compatible with practical IoT deployments. This paper proposes T-HIBE, a secure key establishment and agreement solution for a decentralized multi-tenant IoT system with multiple security domains. T-HIBE relies on principles of identity-based cryptography for key transport between intra and inter-domain devices while avoiding the inherent key-escrow problem. Furthermore, we have demonstrated our proposed architecture on an ARM Cortex-M4 microcontroller and evaluated the performance to show that T-HIBE does not have a significant energy and performance cost. Sayon Duttagupta, Dave Singelée, Bart Preneel |
CCNC | 2 |
| 2022 | MLS-ABAC: Efficient Multi-Level Security Attribute-Based Access Control schemeabstractRealizing access control to sensitive data offloaded to a Cloud is challenging in the Internet of Things, where various devices with low computational power and different security levels are interconnected. Despite various solutions, the National Institute of Standards and Technology (NIST)’s Attribute-Based Access Control (ABAC) model is one of the preferred techniques in the literature. In this model, users who satisfy access policies using both static and dynamic attributes are allowed to access the data. However, NIST’s ABAC model does not support encryption and therefore does not satisfy data confidentiality. Attribute-Based Encryption (ABE) is a known cryptographic primitive that enables fine-grained access control over encrypted data. However, currently the existing ABE schemes do not meet NIST’s ABAC requirements or are not computationally efficient enough for IoT applications. In this paper, we propose a Multi-Level Security ABAC (MLS-ABAC) scheme that satisfies the requirements of NIST’s ABAC model. Our construction is efficient and relies on a decryption outsourceable Ciphertext-Policy ABE scheme. Additionally, based on realistic application scenarios, only the authorized data users can decrypt the ciphertext, and check the integrity of the retrieved message. Furthermore, we present both conceptual and formal models for our proposed MLS-ABAC architecture along with performance metrics. The experimental results show that the proposed MLS-ABAC achieves a constant ciphertext size of ∼230 bytes and with encryption and decryption running times of ∼18 and ∼10 ms, respectively, independent of the number of attributes. Seyed Farhad Aghili, Mahdi Sedaghat, Dave Singelée, Maanak Gupta |
Future Gener. Comput. Syst. | 3 |
| 2021 | FuzzyKey: Comparing Fuzzy Cryptographic Primitives on Resource-Constrained Devices
Mo Zhang, Eduard Marin, David F. Oswald, Dave Singelée |
CARDIS | 4 |
| 2020 | Poster: Securing IoT Through Coverage-Bounding Wireless Communication With Visible LightabstractWe propose a concept of coverage-bounding and `visual' wireless communication-HODOR1-to secure the Internet of Things (IoT). Coverage-bounding means the communication coverage is controlled accurately in 3-dimensions. `Visual' implies that the communication coverage and process are visible to user, representing an important and user-friendly side-channel for se-curing IoT. HODOR can provide secure wireless communication both psychologically (visible to users) and technically (nodes only communicate with each other within their delimited coverage). It can benefit IoT applications for secure wireless communications, especially those that demand secure interactions in proximity. Qing Wang 0007, Jona Beysens, Dave Singelée, Sofie Pollin |
ICNP | 3 |
| 2019 | On the Difficulty of Using Patient's Physiological Signals in Cryptographic ProtocolsabstractWith the increasing capabilities of wearable sensors and implantable medical devices, new opportunities arise to diagnose, control and treat several chronic conditions. Unfortunately, these advancements also open new attack vectors, making security an essential requirement for the further adoption of these devices. Researchers have already developed security solutions tailored to their unique requirements and constraints. However, a fundamental yet unsolved problem is how to securely and efficiently establish and manage cryptographic keys. One of the most promising approaches is the use of patient's physiological signals for key establishment. Eduard Marin, Enrique Argones-Rúa, Dave Singelée, Bart Preneel |
SACMAT | 3 |
| 2018 | HeComm: End-to-end secured communication in a heterogeneous IoT environment via fog computingabstractIn this paper we describe the HeComm (Heterogeneous Communication) architecture. The HeComm architecture utilizes fog computing to provide end-to-end secured communication between IoT nodes residing in networks that operate over different communication protocols. While the fog serves as a bridge between the heterogeneous networks, it does not have access to the confidential data that are being exchanged between the IoT nodes. The HeComm architecture can be divided into two parts: the HeComm protocol and the HeComm communication. The HeComm protocol allows IoT network managers to establish a secret key that is used in the HeComm communication. The HeComm communication secures the exchanged data between the IoT nodes by using object security. This enables an end-to-end protection of the communicated data without putting all trust in the fog. We evaluate the HeComm architecture through a security analysis and via a proof-of-concept implementation that connects an IoT node in a 6LoWPAN network to a node in a LoRaWAN network. The results indicate that the IoT nodes in the HeComm architecture meet the requirements of Class 1 constrained nodes. Furthermore, the HeComm architecture comprises a combination of widely used algorithms and protocols that are often supported in modern IoT devices and platforms, which facilitates the practical deployment of our solution. Jori Winderickx, Dave Singelée, Nele Mentens |
CCNC | 2 |
| 2018 | Digital signatures and signcryption schemes on embedded devices: a trade-off between computation and storageabstractThis paper targets the efficient implementation of digital signatures and signcryption schemes on typical internet-of-things (IoT) devices, i.e. embedded processors with constrained computation power and storage. Both signcryption schemes (providing digital signatures and encryption simultaneously) and digital signatures rely on computation-intensive public-key cryptography. When the number of signatures or encrypted messages the device needs to generate after deployment is limited, a trade-off can be made between performing the entire computation on the embedded device or moving part of the computation to a precomputation phase. The latter results in the storage of the precomputed values in the memory of the processor. We examine this trade-off on a health sensor platform and we additionally apply storage encryption, resulting in five implementation variants of the considered schemes. Jori Winderickx, An Braeken, Dave Singelée, Roel Peeters, Thijs Vandenryt, Ronald Thoelen, Nele Mentens |
CF | 3 |
| 2018 | Securing Wireless NeurostimulatorsabstractImplantable medical devices (IMDs) typically rely on proprietary protocols to wirelessly communicate with external device programmers. In this paper, we fully reverse engineer the proprietary protocol between a device programmer and a widely used commercial neurostimulator from one of the leading IMD manufacturers. For the reverse engineering, we follow a black-box approach and use inexpensive hardware equipment. We document the message format and the protocol state-machine, and show that the transmissions sent over the air are neither encrypted nor authenticated. Furthermore, we conduct several software radio-based attacks that could compromise the safety and privacy of patients, and investigate the feasibility of performing these attacks in real scenarios. Eduard Marin, Dave Singelée, Bohan Yang 0001, Vladimir Volskiy, Guy A. E. Vandenbosch, Bart Nuttin, Bart Preneel |
CODASPY | 2 |
| 2018 | The Impact of Pulsed Electromagnetic Fault Injection on True Random Number GeneratorsabstractRandom number generation is a key function of today's secure devices. Commonly used for key generation, random number streams are more and more frequently used as the anchor of trust of several countermeasures such as masking. True Random Number Generators (TRNGs) thus become a relevant entry point for attacks that aim at lowering the security of integrated systems. Within this context, this paper investigates the robustness of TRNGs based on Ring Oscillators (focusing on the delay chain TRNG) against pulsed electromagnetic fault injection. Indeed, weaknesses in generating random bits for masking scheme degenerate the Side Channel resistance. Finally by exploiting fault results on delay chain TRNG some general guidelines to harden them are derived. Maxime Madau, Michel Agoyan, Josep Balasch, Milos Grujic, Patrick Haddad, Philippe Maurine, Vladimir Rozic, Dave Singelée, Bohan Yang 0001, Ingrid Verbauwhede |
FDTC | 8 |
| 2017 | A Privacy-Preserving Device Tracking System Using a Low-Power Wide-Area Network
Tomer Ashur, Jeroen Delvaux, Sanghan Lee, Pieter Maene, Eduard Marin, Svetla Nikova, Oscar Reparaz, Vladimir Rozic, Dave Singelée, Bohan Yang 0001, Bart Preneel |
CANS | 9 |
| 2017 | Physical-layer fingerprinting of LoRa devices using supervised and zero-shot learningabstractPhysical-layer fingerprinting investigates how features extracted from radio signals can be used to uniquely identify devices. This paper proposes and analyses a novel methodology to fingerprint LoRa devices, which is inspired by recent advances in supervised machine learning and zero-shot image classification. Contrary to previous works, our methodology does not rely on localized and low-dimensional features, such as those extracted from the signal transient or preamble, but uses the entire signal. We have performed our experiments using 22 LoRa devices with 3 different chipsets. Our results show that identical chipsets can be distinguished with 59% to 99% accuracy per symbol, whereas chipsets from different vendors can be fingerprinted with 99% to 100% accuracy per symbol. The fingerprinting can be performed using only inexpensive commercial off-the-shelf software defined radios, and a low sample rate of 1 Msps. Finally, we release all datasets and code pertaining to these experiments to the public domain. Pieter Robyns, Eduard Marin, Wim Lamotte, Peter Quax, Dave Singelée, Bart Preneel |
WISEC | 5 |
| 2016 | On the (in)security of the latest generation implantable cardiac defibrillators and how to secure them
Eduard Marin, Dave Singelée, Flavio D. Garcia, Tom Chothia, Rik Willems, Bart Preneel |
ACSAC | 2 |
| 2016 | On the Feasibility of Cryptography for a Wireless Insulin Pump SystemabstractThis paper analyses the security and privacy properties of a widely used insulin pump and its peripherals. We eavesdrop the wireless channel using Commercial Off-The-Shelf (COTS) software-based radios to intercept the messages sent between these devices; fully reverse-engineer the wireless communication protocol using a black-box approach; and document the message format and the protocol state-machine in use. The upshot is that no standard cryptographic mechanisms are applied and hence the system is shown to be completely vulnerable to replay and message injection attacks. Furthermore, sensitive patient health-related information is sent unencrypted over the wireless channel. Eduard Marin, Dave Singelée, Bohan Yang 0001, Ingrid Verbauwhede, Bart Preneel |
CODASPY | 2 |
| 2016 | IoT: Source of test challengesabstractThe semiconductor industry has been driving a major part of its growth through first the PC and more recently the mobile market. Unfortunately, the PC market is in decline and also the end of the growth curve for mobile products is in sight now that virtually everyone on the planet has a smartphone and/or tablet. Hence, the semiconductor industry is putting its bets on `Internet of Things' (IoT) as the next application wave that will allow them to sell a lot of silicon real estate. Although what exactly IoT encompasses is under definition and hence still volatile, the first emerging products depict an image which is quite different from the traditional microprocessors or smartphone SOCs: small but with ubiquitous presence, wirelessly connected, energy harvesting, equipped with smart sensors, secure, and low cost. All these aspects have a profound impact on the challenges, solutions, and associated trade-offs for testing IoT chips and provide rich grounds for research. This paper provides seven views from different angles. Erik Jan Marinissen, Yervant Zorian, Mario Konijnenburg, Chih-Tsun Huang, Ping-Hsuan Hsieh, Peter Cockburn, Jeroen Delvaux, Vladimir Rozic, Bohan Yang 0001, Dave Singelée, Ingrid Verbauwhede, Cedric Mayor, Robert Van Rijsinge, Cocoy Reyes |
ETS | 10 |
| 2012 | Design and Implementation of a Terrorist Fraud Resilient Distance Bounding System
Aanjhan Ranganathan, Nils Ole Tippenhauer, Boris Skoric, Dave Singelée, Srdjan Capkun |
ESORICS | 4 |
| 2012 | Extending ECC-based RFID authentication protocols to privacy-preserving multi-party grouping proofs
Lejla Batina, Yong Ki Lee, Stefaan Seys, Dave Singelée, Ingrid Verbauwhede |
Pers. Ubiquitous Comput. | 4 |
| 2011 | The communication and computation cost of wireless security: extended abstractabstract\n Contains fulltext :\n 92444.pdf (Publisher’s version ) (Open Access)\n Dave Singelée, Stefaan Seys, Lejla Batina, Ingrid Verbauwhede |
WISEC | 1 |
| 2010 | Privacy-Preserving ECC-Based Grouping Proofs for RFID
Lejla Batina, Yong Ki Lee, Stefaan Seys, Dave Singelée, Ingrid Verbauwhede |
ISC | 4 |
| 2010 | Low-cost untraceable authentication protocols for RFIDabstractThe emergence of pervasive computing devices has raised several privacy issues. In this paper, we address the risk of tracking attacks in RFID networks. Our contribution is threefold: (1) We repair three revised EC-RAC protocols of Lee, Batina and Verbauwhede and show that two of the improved authentication protocols are wide-strong privacy-preserving and one wide-weak privacy-preserving; (2) We present the search protocol, a novel scheme which allows for privately querying a particular tag, and proof its security properties; and (3) We design a hardware architecture to demonstrate the implementation feasibility of our proposed solutions for a passive RFID tag. Due to the specific design of our authentication protocols, they can be realized with an area significantly smaller than other RFID schemes proposed in the literature, while still achieving the required security and privacy properties. Yong Ki Lee, Lejla Batina, Dave Singelée, Ingrid Verbauwhede |
WISEC | 3 |
| 2007 | Key Establishment Using Secure Distance Bounding ProtocolsabstractKey establishment is one of the major challenges in wireless personal area networks, as traditional security mechanisms often do not cope with the dynamic characteristics of wireless ad-hoc networks. In this paper, we present an efficient key establishment protocol, based on the basic Diffie-Hellman protocol. It enables mutual device authentication through presence and establishes a session key between personal mobile devices which do not yet share any authenticated cryptographic material. Distance bounding protocols, which have been introduced by Brands and Chaum at Eurocrypt'93 to preclude distance fraud and mafia fraud attacks, are employed to determine an upper- bound on the distance to another entity. Our solution only requires limited user-interaction: the user of a mobile device is expected to perform a visual verification within a small physical space. Dave Singelée, Bart Preneel |
MobiQuitous | 1 |
| 2005 | Location verification using secure distance bounding protocolsabstractAuthentication in conventional networks (like the Internet) is usually based upon something you know (e.g., a password), something you have (e.g., a smartcard) or something you are (biometrics). In mobile ad-hoc networks, location information can also be used to authenticate devices and users. We focus on how a provers can securely show that (s)he is within a certain distance to a verifier. Brands and Chaum proposed the distance bounding protocol as a secure solution for this problem. However, this protocol is vulnerable to a so-called "terrorist fraud attack". In this paper, we explain how to modify the distance bounding protocol to make it resistant to this kind of attacks. Recently, two other secure distance bounding protocols were published. We discuss the properties of these protocols and show how to use it as a building block in a location verification scheme Dave Singelée, Bart Preneel |
MASS | 1 |