Raphael Schermann

dblp:299/5614 · DBLP profile ↗
← Back
4ranked-venue papers
4as first author
4since 2021 · last 2024
0009-0006-6238-8778ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 3 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2024 PAKA: Pseudonymous Authenticated Key Agreement without bilinear cryptography
abstract
Anonymity and pseudonymity are important concepts in the domain of the Internet of Things. The existing privacy-preserving key agreement schemes are only concerned with maintaining the privacy of the communicated data that appears on the channel established between two honest entities. However, privacy should also include anonymity or pseudonymity of the device identity. This means there should not exist any correlation handle to associate different communications done by the device.
Raphael Schermann, Simone Bussa, Rainer Urian, Ronald Toegl, Christian Steger
ARES1
2023 Integration of the TPM in the AACKA Protocol
abstract
Anonymous credential schemes are commonly used to implement privacy-preserving cryptographic protocols. While Trusted Computing platforms are used to establish trust within a network. In this paper we show how a recently proposed Anonymous Authenticated Credential Key Agreement scheme (AACKA) can be used with a off-the-shelf TPM and what is necessary for it. We also introduce promising TPM-related use cases where the AACKA protocol can be applied. Finally, we evaluate the implementation with a hardware TPM and propose extensions for a standard TPM2.0 in order to enhance security.
Raphael Schermann, Rainer Urian, Christian Steger
DSD1
2022 Enabling Anonymous Authenticated Encryption with a Novel Anonymous Authenticated Credential Key Agreement (AACKA)
abstract
Anonymous credential schemes based on elliptic curve pairings are often used to implement privacy-friendly cryptographic protocols, with Direct Anonymous Attestation and Enhanced Privacy IDentification being the most prominent anonymous credential schemes. However, all those schemes are signature-based and do not immediately provide for agreement of (symmetric) encryption keys.In this paper we present a scheme for Anonymous Authenticated Credential Key Agreement, which can be used in anonymously authenticated encryption schemes. This novel building-block combines Camenisch-Lysyanskaya credentials with elliptic curve Diffie-Hellman key agreement.We show how the Authenticated Anonymous Key Agreement protocol can be used to design an anonymous credential based Elliptic Curve Integrated Encryption scheme and argue that it is more efficient than conventional hybrid approaches. We show the applicability of our scheme on performance-restricted Internet of Things devices in Cloud-, Fog-, or Edge-Computing scenarios. In particular, we provide an implementation and a performance evaluation for a standard-compliant Java Card 3.1 device.
Raphael Schermann, Rainer Urian, Ronald Toegl, Holger Bock, Christian Steger
TrustCom1
2021 Managing Anonymous Keys in a Fog-Computing Platform
abstract
Fog Computing is a decentralized infrastructure layer between Cloud and Edge Devices moving the computation closer to the edge, allowing good latency and bandwidth even for large-scale Internet of Things deployments. Still, devices using fog services are exposed to the immediate application environment and potentially malicious users, thus security, privacy, and trust are critical issues. To provide trust and privacy within fog infrastructures, enabling the secured execution of future Internet of Things services, lightweight collective and distributed attestation mechanism for the bulk attestation of the edge devices and the fog infrastructure can be used, especially leveraging Direct Anonymous Attestation, an anonymous attestation signature that allows attesting to the state of the host system, without violating the specified privacy of the host. As in all cryptographic schemes the management and protection of keys is of the highest significance. We present key management for a fog architecture in the context of the RAINBOW fog platform and show how the computations of a recently published proof-of-concept implementation of Direct Anonymous Attestation can be distributed in our specific fog environment. We provide details on an embedded system-level implementation and performance benchmarks for Internet of Things applications keys stored with proper hardware-based protection within a Trusted Platform Module.
Raphael Schermann, Ronald Toegl
ARES1