André Cirne

dblp:232/9729 · DBLP profile ↗
← Back
3ranked-venue papers
2as first author
3since 2021 · last 2026
0000-0002-3433-9809ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 2 first-author · 3 since 2021
YearPublicationVenuePosition
2026 RunPBA - Runtime attestation for microcontrollers with PACBTI
abstract
The widespread adoption of embedded systems has led to their deployment in critical real-world applications, making them attractive targets for malicious actors. This paper presents RunPBA , a hardware-based runtime attestation system designed to defend against control flow attacks while maintaining minimal performance overhead and adhering to strict power consumption constraints. RunPBA leverages Pointer Authentication and Branch Target Identification (PACBTI), a new processor extension tailored for the ARM Cortex M processor family, allowing robust protection without requiring hardware modifications, a limitation present in similar solutions. We implemented a proof-of-concept and evaluated it using two benchmark suites, Coremark PRO and BEEBS. Experimental results indicate that RunPBA imposes a geometric mean performance overhead of only 1.3% and 6.8% across the benchmarks, underscoring its efficiency and suitability for real-world deployment.
André Cirne, Patrícia R. Sousa, João S. Resende, Luis Filipe Coelho Antunes
Comput. Secur.1
2023 Rogue key and impersonation attacks on FIDO2: From theory to practice
abstract
FIDO2 is becoming a defacto standard for passwordless authentication. Using FIDO2 and WebAuthn, web applications can enable users to associate cryptographic credentials to their profiles, and then rely on an external authenticator (e.g., a hardware token plugged into the USB port) to perform strong signature-based authentication when accessing their accounts. The security of FIDO2 has been theoretically validated, but these analyses follow the threat model adopted in the FIDO2 design and explicitly exclude some attack vectors as being out of scope. In this paper we show that two of these attacks, which appear to be folklore in the community, are actually straightforward to launch in practice (user PIN extraction, impersonation and rogue key registration). We demonstrate a deployment over vanilla Linux distributions and commercial FIDO2 authenticators. We discuss the potential impact of our results, which we believe will contribute to the improvement of future versions of the protocol.
Manuel Barbosa, André Cirne, Luís Esquível
ARES2
2022 IoT security certifications: Challenges and potential approaches
André Cirne, Patrícia R. Sousa, João S. Resende, Luis Filipe Coelho Antunes
Comput. Secur.1