Takahito Yoshizawa

dblp:205/9650 · DBLP profile ↗
← Back
6ranked-venue papers
4as first author
6since 2021 · last 2026
0000-0001-5684-9597ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 1 first-author · 2 since 2021Computer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2026 CARPOOL: Secure And Reliable Proof of Location
abstract
Multiple authentication solutions are widely deployed, such as OTP/TOTP/HOTP codes, hardware tokens, PINs, or biometrics. However, in practice, one sometimes needs to authenticate not only the user but also their location. The current state-of-the-art secure localisation schemes are either unreliable or insecure, or require additional hardware to reliably prove the user's location. This paper proposes CARPOOL, a novel, secure, and reliable approach to affirm the location of the user by solely relying on location-bounded interactions with commercial off-the-shelf devices. Our solution does not require any additional hardware, leverages devices already present in a given environment, and can be integrated effortlessly with existing security components, such as identity and access control systems. To demonstrate the feasibility of our work and to show that it can be deployed in a realistic closed environment setting, we implemented a proof of concept realisation of CARPOOL on an Android phone and multiple Raspberry Pi boards and integrated CARPOOL with Amazon Web Services (AWS) Cognito.
Sayon Duttagupta, Dave Singelée, Xavier Carpent, Takahito Yoshizawa, Seyed Farhad Aghili, Aysajan Abidin, Bart Preneel
SACMAT4
2026 Certificate revocation - search for a way forward
abstract
Revocation of digital certificates represents a series of improvements by IETF in order to standardize a complete and effective solution. This applies to the context of Internet web sites in which web servers and browsers use digital certificates to establish Transport Layer Security (TLS). Despite IETF’s effort over the years to establish a reliable revocation mechanism, including Certificate Revocation List (CRL), Online Certificate Status Protocol (OCSP) and its variants, various technical issues hinder complete resolution of the revocation problem. At the same time, all major browser vendors implement their own proprietary solutions to address the revocation problem. As a result, revocation solutions are fragmented, incomplete, and ineffective, and the level of real-world acceptance of standardized solutions is limited. To address this situation, in 2020, IETF has introduced short-term certificate concept to avoid revocation altogether. It is called Support for Short-Term, Automatically Renewed (STAR) which recommends a validity period of 4 days. To measure the level of adoption of this new approach in the Internet, we collected and analyzed web server certificates from 1 million websites; the result of our extensive analysis indicates that this scheme has not gained traction in reality. In fact, we found no implementation of a 4-day validity period out of more than 1.5 million server certificates that we collected. This situation indicates that the latest IETF effort to promote short-term certificates has not materialized, with no clear alternative solution in sight to resolve the revocation issue. We present our insights into the reasons for this absence of traction in reality and present our view of a possible way forward.
Takahito Yoshizawa, Himanshu Agarwal, Dave Singelée, Bart Preneel
Comput. Secur.1
2024 Intersections are Not Good for Your Privacy
abstract
Cooperative Awareness Messages (CAM) defined by ETSI Intelligent Transport Systems (ITS) can compromise privacy as a result of its transmission criteria. Because these transmission criteria reflect vehicle's movement, the resulting transmission patterns serve as metadata of vehicles. Passive observations of these patterns can help correlate with a specific vehicle on the road. Furthermore, in some cases, this correlation and identification of a vehicle is independent of the number of vehicles present in the vicinity. Observations from our simulation indicate that the mandatory use and occasional change of pseudonyms is a false premise as they do not protect privacy. In fact, the use of pseudonyms has no bearing with this context. Consequently, the existing CAM transmission criteria pose a tradeoff question between cooperative awareness (and ultimately road safety) and privacy. We propose that ETSI ITS standard to consider our findings and re-evaluate the CAM transmission criteria in Vehicule-to-Everything (V2X) communication.
Takahito Yoshizawa, Bart Preneel
WiMob1
2023 Post-Quantum Impacts on V2X Certificates - Already at The End of The Road
abstract
The current certificate definition for vehicle-to-everything (V2X) communication does not support forward compatibility as it does not take migration toward Post Quantum Cryptography (PQC) into account. As a result, introducing PQC-compatible certificates in V2X can result in similar to Distributed Denial-of-Service (DDoS) attack to both legacy and PQC-ready vehicles. This situation will make the deployment of PQC certificates a stalemate situation. In addition, due to the larger public key and signature sizes in PQC algorithms, V2X message size will significantly increase, causing the channel capacity and effective transmission range to decrease. This situation will negatively impact the operation of V2X communication. In this sense, any unnecessary channel usages need to be avoided. We propose to revise the certificate definitions in IEEE 1609 and ETSI Intelligent Transport System (ITS) standards to address and mitigate these issues and pave the way for the migration toward PQC algorithm.
Takahito Yoshizawa, Bart Preneel
VTC2023-Spring1
2023 DASLog: Decentralized Auditable Secure Logging for UAV Ecosystems
abstract
Rapid technological advancements in unmanned aerial vehicles (UAVs) have revolutionized intelligent platforms such as smart cities. These advancements have paved the way for an emerging class of Internet of Things (IoT) systems called the Internet of Drones (IoD), which has noteworthy security and privacy challenges. In this article, we tackle the problem of secure logging and design a novel secure logging scheme—DASLog—for the use case of aerial transport of (medical) goods via drones. Our logging scheme provides public auditability of logging records in the setting where all logging components are managed by a single entity. Our secure logging system relies on hash chains and a Merkle tree to generate proofs for stored logging records. These proofs get written on a private blockchain and can be used later by data consumers to verify the integrity and completeness of a set of logging records. We demonstrate the feasibility of our approach via a proof-of-concept prototype relying on Hyperledger Besu and implemented on multiple Amazon EC2 instances. The performance evaluation of our demonstrator shows that up to 8000 logging records per second can be processed.
Roozbeh Sarenche, Seyed Farhad Aghili, Takahito Yoshizawa, Dave Singelée
IEEE Internet Things J.3
2022 On Handling of Certificate Digest in V2X Communication
abstract
We propose a change in the IEEE 1609.2 and ETSI ITS standards that define a certificate distribution mechanism, called inline peer-to-peer certificate distribution (P2PCD). Messages exchanged in V2X messages are secured with digital signatures and digital certificates for the corresponding public keys. This P2PCD mechanism is used in Basic Safety Message (BSM) for the US and Cooperative Awareness Message (CAM) for Europe, and allows vehicles to proactively resolve unknown certificates. The unknown certificate situation occurs as not all messages contain the certificate in order to reduce overhead in these messages. This mechanism appears to be beneficial to minimize delay in verifying the authenticity and integrity of received messages. We evaluated its usefulness by conducting a simulation to recreate real-world highway traffic flow. The result indicates that, for high-way traffic, the benefit of this mechanism is negligble. At the same time, it increases unnecessary processing burden in vehicles. Based on our observation, we propose to update the IEEE 1609.2 and ETSI ITS standards in such a way that this mechanism should be restricted to traffic environments where it brings benefits.
Takahito Yoshizawa, Bart Preneel
WiMob1