VLDB 2026 Research / reviewers in the wild / expert
Dominik Lorych
dblp:299/5950
· DBLP profile ↗
6ranked-venue papers
3as first author
6since 2021 · last 2024
0000-0002-3866-1360ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 3 first-author · 6 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Acceleration of DICE Key Generation using Key CachingabstractDICE is a Trusted Computing standard intended to secure resource-constrained off-the-shelf hardware. It implements a Root of Trust that can be used to construct a Chain of Trust boot system, with symmetric keys representing firmware integrity and device identity. Based on this, asymmetric keys can be generated, but this slows down the boot process significantly as the keys need to be generated on every boot. Asymmetric keys provide multiple advantages when compared to symmetric ones, especially for updateable systems. This prevents the adoption of DICE in fields with strict boot time requirements, for example in the automotive context. Dominik Lorych, Lukas Jäger, Andreas Fuchs 0002 |
ARES | 1 |
| 2024 | Hardware Trust Anchor Authentication for Updatable IoT DevicesabstractSecure firmware update mechanisms and Hardware Trust Anchors (HTAs) are crucial in securing future IoT networks. Among others, HTAs can be used to shield security-sensitive data like cryptographic keys from unauthorized access, using hardware isolation. Authentication mechanisms for key usage, however, are difficult to implement since corresponding credentials need to be stored outside the HTA. This makes them vulnerable against host hijacking attacks, which in the end also undermines the security gains of the HTA deployment. Dominik Lorych, Christian Plappert |
ARES | 1 |
| 2023 | Evaluating the applicability of hardware trust anchors for automotive applicationsabstractThe automotive trend towards autonomous driving and advanced connected services increases both complexity of the vehicle internal network and the connections to its environment. This introduced complexity further broadens the vehicle cyberattack surface. As mitigation strategy, state-of-the-art security mechanisms utilize so-called hardware trust anchors (HTAs) to protect security-sensitive data and processes in shielded locations that are isolated utilizing hardware security mechanisms. However, there is a variety of different HTAs with different functionality and security guarantees and there is currently no work done that compares and evaluates them against current and emerging automotive requirements. In this work, we evaluate the applicability of various HTAs to secure modern as well as upcoming future automotive applications. For this, we analyze and evaluate HTAs that are already established in the automotive field as well as promising HTAs from other domains. We extend our preliminary work [1] by increasing the range of the analyzed HTAs with solutions that are feasible for the most resource constrained automotive controllers and technologies that become feasible to be utilized by the introduction of high-performance controllers in future automotive architectures. We assess the different HTAs based on the evaluation criteria and in accordance to automotive requirements. Christian Plappert, Dominik Lorych, Michael Eckel, Lukas Jäger, Andreas Fuchs 0002, Ronald Heddergott |
Comput. Secur. | 2 |
| 2022 | A Resilient Network Node for the Industrial Internet of ThingsabstractThe Industrial Internet of Things (IIoT) is a ubiquitous part of modern production processes. This introduces new challenges to classical security architectures for industrial networks like the perimeter approach. These are made obsolete by the increasing horizontal and vertical integration of industrial systems and IT systems. A promising concept to face these challenges is resilience. This term describes systems or networks that can isolate compromised parts of themselves and reset them to a trustworthy state with minimal impact to the functionality of the overall system. In order to bring this concept to IIoT networks, we present a novel embedded network node that uses Trusted Computing technology such as a Trusted Platform Module (TPM) and Remote Attestation for attack detection and reporting, virtualization for the separation of processes with different criticalities and an authenticated watchdog for guaranteed platform resets as a form of return to an uncompromised state. This combination provides secure mechanisms for resilience on a platform level and can serve as a foundation for network resilience based on Software-Defined Networking (SDN) solutions. The architecture and implementation of the proposed network node are described in detail before evaluating its resource consumption and performance in order to demonstrate its suitability for embedded and IIoT contexts. Lukas Jäger, Dominik Lorych, Michael Eckel |
ARES | 2 |
| 2022 | Design Space Exploration of DICEabstractTrusted Computing aims to secure computer systems by ensuring that only trusted software is executed on the system, so that it behaves in expected ways. One of the approaches to this concept is the Device Identifier Composition Engine (DICE), which is specified by the Trusted Computing Group (TCG) as a solution for resource-limited devices. DICE is supposed to be a Root of Trust, which enables the implementation of a Chain of Trust on the device. It is designed for off-the-shelf hardware, such that it can be used on most modern micro-controllers. Therefore, it needs to be as minimal on resource usage as possible. Implementations until now were either focused on extending DICE with new concepts or implementing DICE with as little hardware as possible. Also they usually only implemented DICE on one single device. These factors limit the significance of their results for general DICE implementations as they mostly concentrate on evaluating their extended concepts and specific implementation features. This paper aims for the contrary, focusing more on general configuration and implementation details applicable to most DICE implementations than on specific aspects. We evaluated many different configurations for multiple devices and used these to give suggestions on possible configurations for different use cases. DICE is commonly used as he foundation to create a Chain of Trust, where firmware components get executed in sequential order. Usually a key generation component is used to generate purpose-bound keys after DICE, but specifics are application-dependent. We also implemented this component and to evaluate its key generation for different key configurations. Additionally, we implemented an example of Remote Attestation to show how the DICE architecture can be used. Dominik Lorych, Lukas Jäger |
ARES | 1 |
| 2021 | Remote Attestation Extended to the Analog DomainabstractOn embedded systems, Trusted Computing schemes can be used to detect manipulations of firmware. It is however not possible to detect a wide range of hardware manipulations such as passive listeners, active signal manipulations and circuit modifications. This work extends the Trusted Computing approach of detection through integrity measurement to the analog domain. It examines the step response of a circuit for its suitability as a component’s fingerprint. These fingerprints are combined with statistical comparison methods such as the Manhattan Distance or the Root Mean Square Error in order to provide a reliable fingerprint verification scheme. The fingerprinting and verification techniques are then combined with a remote attestation protocol based on the Device Identifier Composition Engine to yield a remote attestation scheme that covers both a device’s firmware and its peripheral hardware. This scheme is implemented and evaluated on a resource-constrained MCU in order to demonstrate its feasibility for embedded systems. Lukas Jäger, Dominik Lorych |
ARES | 2 |