Seema Kumar

dblp:240/3550 · DBLP profile ↗
← Back
2ranked-venue papers
1as first author
2since 2021 · last 2022
0000-0002-4754-588XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 1 first-author · 2 since 2021
YearPublicationVenuePosition
2022 Software-Based Remote Network Attestation
abstract
Internet of Things (IoT) applications build upon resource-constrained, distributed devices that generate data and enable communication. For such applications to be truly trustworthy, it must be ensured that the devices are not compromised by malicious software. Remote attestation (RA), a prominent technique, exploits challenge-response protocols to detect malware on remote devices. Given the increasing scale and number of IoT deployments, recent work on RA has explored collective attestation ofswarmsof devices. However state-of-the-art swarm attestation techniques require trusted hardware which makes them inapplicable to both legacy and next generation IoT deployments without trusted hardware. We present SWARNA, asoftware-basedswarm attestation for IoT devices. After highlighting the challenges in designing such a solution, we present two protocol variants for IEEE 802.15.4 TSCH networks. We assess their performance analytically and empirically through testbed experiments. SWARNA maintains a constant payload size whereas, it increases linearly with the network size for existing solutions requiring trusted hardware. The two protocol variants attest 30 nodes networks, in 6s and 1.5s to 8.2s, respectively, depending on the number of malicious nodes. Further, we demonstrate that attestation traffic has a negligible impact on the packet delivery ratio (0.4 percent drop) of a typical data collection application.
Seema Kumar, Patrick Eugster, Silvia Santini
IEEE Trans. Dependable Secur. Comput.1
2022 C3PO: Cloud-based Confidentiality-preserving Continuous Query Processing
abstract
With the advent of the Internet of things (IoT), billions of devices are expected to continuously collect and process sensitive data (e.g., location, personal health factors). Due to the limited computational capacity available on IoT devices, the current de facto model for building IoT applications is to send the gathered data to the cloud for computation. While building private cloud infrastructures for handling large amounts of data streams can be expensive, using low-cost public (untrusted) cloud infrastructures for processing continuous queries including sensitive data leads to strong concerns over data confidentiality. This article presents C3PO, a confidentiality-preserving, continuous query processing engine, that leverages the public cloud. The key idea is to intelligently utilize partially homomorphic and property-preserving encryption to perform as many computationally intensive operations as possible—without revealing plaintext—in the untrusted cloud. C3PO provides simple abstractions to the developer to hide the complexities of applying complex cryptographic primitives, reasoning about the performance of such primitives, deciding which computations can be executed in an untrusted tier, and optimizing cloud resource usage. An empirical evaluation with several benchmarks and case studies shows the feasibility of our approach. We consider different classes of IoT devices that differ in their computational and memory resources (from a Raspberry Pi 3 to a very small device with a Cortex-M3 microprocessor) and through the use of optimizations, we demonstrate the feasibility of using partially homomorphic and property-preserving encryption on IoT devices.
Savvas Savvides, Seema Kumar, Julian James Stephen, Patrick Eugster
ACM Trans. Priv. Secur.2