Sebastian Surminski

dblp:202/5427 · DBLP profile ↗
← Back
6ranked-venue papers
3as first author
6since 2021 · last 2025
0000-0002-8399-3567ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 3 first-author · 5 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Building trust in remote attestation through transparency - a qualitative user study on observable attestation
abstract
Internet of Things (IoT) devices have become increasingly important within the smart home domain, making the security of the devices a critical aspect. The majority of IoT devices are black-box systems running closed and pre-installed firmware. This raises concerns about the trustworthiness of these devices, especially considering that some of them are shipped with a microphone or a camera. Remote attestation aims at validating the trustworthiness of these devices by verifying the integrity of the software. However, users cannot validate whether the attestation has actually taken place and has not been manipulated by an attacker, raising the need for HCI research on trust and understandability. We conducted a qualitative study with 35 participants, investigating trust in the attestation process and whether this trust can be improved by additional explanations in the application. We developed an application that allows users to attest a smart speaker using their smartphone over an audio channel to identify the attested device and observe the attestation process. In order to observe the differences between the applications with and without explanations, we performed A/B testing. We discovered that trust increases when additional explanations of the technical process are provided, improving the understanding of the attestation process.
Sebastian Linsner, Kilian Demuth, Sebastian Surminski, Lucas Davi, Christian Reuter 0001
Behav. Inf. Technol.3
2023 DMA'n'Play: Practical Remote Attestation Based on Direct Memory Access
Sebastian Surminski, Christian Niesler, Lucas Davi, Ahmad-Reza Sadeghi
ACNS1
2023 SCAtt-man: Side-Channel-Based Remote Attestation for Embedded Devices that Users Understand
abstract
From the perspective of end-users, IoT devices behave like a black box: As long as they work as intended, users will not detect any compromise. Users have minimal control over the software. Hence, it is very likely that the user misses that illegal recordings and transmissions occur if a security camera or a smart speaker is hacked. In this paper, we present SCAtt-man, the first remote attestation scheme that is specifically designed with the user in mind. SCAtt-man deploys software-based attestation to check the integrity of remote devices, allowing users to verify the integrity of IoT devices with their smartphones. The key novelty of SCAtt-man resides in the utilization of user-observable side-channels such as light or sound in the attestation protocol. Our proof-of-concept implementation targets a smart speaker and an attestation protocol that is based on a data-over-sound protocol. Our evaluation demonstrates the effectiveness of \toolname against a variety of attacks and its usability based on a user study with 20 participants.
Sebastian Surminski, Christian Niesler, Sebastian Linsner, Lucas Davi, Christian Reuter 0001
CODASPY1
2021 RealSWATT: Remote Software-based Attestation for Embedded Devices under Realtime Constraints
abstract
Smart factories, critical infrastructures, and medical devices largely rely on embedded systems that need to satisfy realtime constraints to complete crucial tasks. Recent studies and reports have revealed that many of these devices suffer from crucial vulnerabilities that can be exploited with fatal consequences. Despite the security and safety-critical role of these devices, they often do not feature state-of-the-art security mechanisms. Moreover, since realtime systems have strict timing requirements, integrating new security mechanisms is not a viable option as they often influence the device's runtime behavior. One solution is to offload security enhancements to a remote instance, the so-called remote attestation.
Sebastian Surminski, Christian Niesler, Ferdinand Brasser, Lucas Davi, Ahmad-Reza Sadeghi
CCS1
2021 My Fuzzer Beats Them All! Developing a Framework for Fair Evaluation and Comparison of Fuzzers
David Paaßen, Sebastian Surminski, Michael Rodler, Lucas Davi
ESORICS (1)2
2021 HERA: Hotpatching of Embedded Real-time Applications
Christian Niesler, Sebastian Surminski, Lucas Davi
NDSS2