Gerald Palfinger

dblp:222/1184 · DBLP profile ↗
← Back
8ranked-venue papers
4as first author
3since 2021 · last 2024
0000-0001-6633-858XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 4 first-author · 3 since 2021
YearPublicationVenuePosition
2024 AndroPROTECT: Hardening the Android API Against Fingerprinting
Gerald Palfinger
NSS1
2023 OCScraper: Automated Analysis of the Fingerprintability of the iOS API
Gerald Palfinger
SECRYPT1
2021 White-Box Traceable Attribute-Based Encryption with Hidden Policies and Outsourced Decryption
abstract
We address three practical problems of Attribute-Based Encryption (ABE) in this paper: performance, accountabil-ity and privacy. To do so, we present a novel Ciphertext-Policy Attribute-Based Encryption (CP-ABE) approach, which combines white-box accountability, hidden policies and outsourced decryption. In contrast to existing schemes, the proposed construction is not only more flexible, but also efficient enough to be used in more resource-constrained environments. This is because our construction is designed around efficient Type III bilinear maps and relies on a dedicated proxy to perform computationally ex-pensive operations. Furthermore, we provide an implementation of the proposed design. The conducted evaluation demonstrates the practicality of the approach under realistic assumptions.
Dominik Ziegler 0001, Alexander Marsalek, Gerald Palfinger
TrustCom3
2020 AndroPRINT: analysing the fingerprintability of the Android API
abstract
In recent Android versions, access to various (unique) identifiers has been restricted or completely removed for third-party applications. However, many information sources can still be combined to create a fingerprint, effectively substituting the need for these unique identifiers. Until now, finding these fingerprintable sources required manually sifting through the API documentation to identify each information source individually. This paper presents AndroPRINT, a framework that automatically recognizes fingerprintable information sources on Android devices. For this purpose it automatically invokes methods, queries fields, and retrieves data from content providers. We show that this framework allows automating the elaborate task of finding such fingerprintable information sources in different experiments. In these experiments, a variety of information sources could be identified, which provide a vast amount of unique features for fingerprinting. Furthermore, AndroPRINT detected undocumented unique device identification features, which are a result of manufacturer adaptations. These vendor customisations even revealed personal data, such as the user's email address and cryptographic keys used for cross-device communication. The fact that this information can be retrieved without the user noticing means that vendor customisations can effectively defeat the tight permission system of modern smartphone operating systems.
Gerald Palfinger, Bernd Prünster
ARES1
2020 Multiply, Divide, and Conquer - Making Fully Decentralised Access Control a Reality
Bernd Prünster, Dominik Ziegler 0001, Gerald Palfinger
NSS3
2020 AndroTIME: Identifying Timing Side Channels in the Android API
abstract
The permission system of Android has continuously evolved to better guard the privacy of users. New permissions have been introduced and existing methods which were abused now require a permission or have been entirely removed. Retrieving private data about users without their consent is thus getting continuously harder for applications. In this paper, we systematically analyse how timing-based side channels in the Android API can be used to circumvent this tight permission system. We introduce AndroTIME, a framework to automatically detect such side channels in the Android API. Using this automated approach, we were able to identify several new timing-based side-channel leaks in Android 10 and Android 11. The detected side channels enable querying for installed applications, active accounts, files, and browser logins. The leaked information could be used to fingerprint users, detect secret user habits, or even infer a concrete user identity.
Gerald Palfinger, Bernd Prünster, Dominik Ziegler 0001
TrustCom1
2019 Fine-Grained Access Control in Industrial Internet of Things - Evaluating Outsourced Attribute-Based Encryption
Dominik Ziegler 0001, Josef Sabongui, Gerald Palfinger
SEC3
2018 SCAnDroid: Automated Side-Channel Analysis of Android APIs
abstract
Although the Android system has been continuously hardened against side-channel attacks, there are still plenty of APIs available that can be exploited. However, most side-channel analyses in the literature consider specifically chosen APIs (or resources) in the Android framework, after a manual analysis of APIs for possible information leaks has been performed. Such a manual analysis is a tedious, time consuming, and error-prone task, meaning that information leaks tend to be overlooked.
Raphael Spreitzer, Gerald Palfinger, Stefan Mangard
WISEC2