VLDB 2026 Research / reviewers in the wild / expert
Sayon Duttagupta
dblp:313/5856
· DBLP profile ↗
7ranked-venue papers
5as first author
7since 2021 · last 2026
0000-0002-3495-4641ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 3 first-author · 4 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | CARPOOL: Secure And Reliable Proof of LocationabstractMultiple authentication solutions are widely deployed, such as OTP/TOTP/HOTP codes, hardware tokens, PINs, or biometrics. However, in practice, one sometimes needs to authenticate not only the user but also their location. The current state-of-the-art secure localisation schemes are either unreliable or insecure, or require additional hardware to reliably prove the user's location. This paper proposes CARPOOL, a novel, secure, and reliable approach to affirm the location of the user by solely relying on location-bounded interactions with commercial off-the-shelf devices. Our solution does not require any additional hardware, leverages devices already present in a given environment, and can be integrated effortlessly with existing security components, such as identity and access control systems. To demonstrate the feasibility of our work and to show that it can be deployed in a realistic closed environment setting, we implemented a proof of concept realisation of CARPOOL on an Android phone and multiple Raspberry Pi boards and integrated CARPOOL with Amazon Web Services (AWS) Cognito. Sayon Duttagupta, Dave Singelée, Xavier Carpent, Takahito Yoshizawa, Seyed Farhad Aghili, Aysajan Abidin, Bart Preneel |
SACMAT | 1 |
| 2026 | One Tap to Hijack Them All: A Security Analysis of the Google Fast Pair ProtocolabstractGoogle's Fast Pair Service (GFPS) extends Bluetooth pairing with one-tap setup and account synchronisation. This paper presents the first comprehensive security analysis of GFPS. By examining 25 commercial accessories from 16 vendors across 17 unique Bluetooth chipsets, we uncover systemic enforcement failures of the specification's core security requirements. Moreover, we show that the security failures we have identified in the pairing protocol can be further cascaded, amplifying their impact across the device ecosystem. Although GFPS and Google's Find Hub network are often treated as distinct services within the broader Google ecosystem, we show that failures in one can produce severe consequences in the other. We demonstrate WhisperPair, a family of practical attacks that enables unauthorised pairing, silent hijacking of audio devices, and covert account binding that registers a victim's accessory to an attacker's account, thereby enabling persistent location tracking and stalking via Google Find Hub. These vulnerabilities are not isolated incidents but symptoms of systemic, ecosystem-wide gaps in implementation, validation, and certification. Our analysis exposes that the source of these flaws lies in GFPS's reliance on fallible, application-layer state checks rather than on cryptographic enforcement, allowing them to propagate across vendors to the end users. To address the root cause, we propose IntentPair, a lightweight protocol modification that cryptographically binds the user's pairing intent into the key schedule, eliminating the vulnerability by design. Our findings show how a small usability “add-on” can introduce large-scale security and privacy risks for hundreds of millions of users. Sayon Duttagupta, Seppe Wyns, Nikola Antonijevic, Dave Singelée, Bart Preneel |
SP | 1 |
| 2025 | PISA: Privacy-Preserving Smart ParkingabstractIn recent years, urban areas have experienced a rapid increase in vehicles, while parking availability has remained static, leading to a significant shortage of parking spots. This creates inconvenience for drivers and contributes to traffic congestion. A solution is the temporary use of private parking spaces by homeowners during their absence, alleviating the parking problem and generating additional income. However, current systems often neglect security and privacy, exposing users to risks. This paper presents PISA, a Privacy-Preserving Smart Parking scheme designed to address these issues through a cryptographically secure protocol. PISA enables the anonymous sharing of parking spots, allowing vehicle owners to park without revealing personal identifiers. Our contributions include a bi-directional anonymity framework ensuring neither party can identify the other and the use of formal verification to prove the soundness of our security measures. Unlike existing solutions, which often lack security focus, formal validation, or efficiency, PISA is designed to be both secure and efficient. Sayon Duttagupta, Dave Singelée |
CCNC | 1 |
| 2025 | PathSafe: Secure Path Verification in Software-Defined NetworksabstractNetwork topology verification in Software-Defined Networks (SDN) poses a significant challenge, as vulnerabilities can allow attackers to deceive the controller and manipulate the data plane into incorrect topologies, thereby endangering the entire network's security. Current solutions fail to guarantee both security and efficiency in the verification process, often resulting in damaging user traffic. With the aim of solving joint objectives, in this paper, we introduce PathSafe, a novel tool constructed on top of the existing controller frameworks designed for secure path verification in SDN environments. It enables the verification of all available paths between two points in the network and ensures a secure process. Our approach requires a data plane component for real-time packet monitoring at line speed and a control plane verification step. Our research demonstrates that PathSafe effectively mitigates security risks in compromised switches and host scenarios. Alongside a theoretical exploration of this challenge, we present a proof of concept implemented in P4, a common language for programmable data planes. Results obtained in Mininet underscore the practical applicability of PathSafe that, compared to alternatives, reduces overhead in the verification process while maintaining a limited execution time. Doriana Monaco, Nikola Antonijevic, Sayon Duttagupta, Dave Singelée, Alessio Sacco, Eduard Marin, Bart Preneel |
NOMS | 3 |
| 2025 | ZeroTouch: Reinforcing RSS for Secure GeofencingabstractGeofencing, the virtual demarcation of physical spaces, is widely used for managing the localisation of Internet of Things (IoT) devices. However, traditional localisation techniques face security challenges indoors due to signal interference and susceptibility to spoofing, often requiring extensive calibration or extra hardware, limiting scalability. In this work, we propose ZeroTouch, a machine learning-based system that leverages Received Signal Strength (RSS) measurements from multiple receivers to improve the security of geofencing without introducing additional deployment overhead. While RSS-based localisation is known to have inherent security limitations, we show that by aggregating RSS readings from multiple anchor points and detecting anomalies using an autoencoder model, ZeroTouch provides a practical and automated mechanism for verifying whether a device is inside or outside a defined boundary. Rather than serving as a standalone security mechanism, ZeroTouch enhances existing authentication frameworks by adding an additional zero-touch security layer that operates passively in the background. ZeroTouch eliminates manual calibration, removes the human-in-the-loop element, and simplifies deployment. We evaluate our solution in a realistic simulated environment and demonstrate that it achieves high accuracy in distinguishing between in-room and out-of-room devices, even in strong adversarial settings. Nikola Antonijevic, Sayon Duttagupta, Dave Singelée, Enrique Argones-Rúa, Bart Preneel |
SACMAT | 2 |
| 2023 | HAT: Secure and Practical Key Establishment for Implantable Medical DevicesabstractDuring the last few years, Implantable Medical Devices (IMDs) have evolved considerably. IMD manufacturers are now starting to rely on standard wireless technologies for connectivity. Moreover, there is an evolution towards open systems where the IMD can be remotely monitored or reconfigured through personal commercial-off-the-shelf devices such as smartphones or tablets. Nevertheless, a major problem that still remains unsolved today is the secure establishment of cryptographic keys between the IMD and such personal devices. Researchers have already proposed various solutions, most notably by relying on an additional external device. Unfortunately, these proposed approaches are either insecure, difficult to realise in practice, or are unsuitable for the latest generation of IMDs. Motivated by this, we present HAT, a secure and practical solution to provide fine-grained and dynamic access control for the next generation of IMDs, while offering full control and transparency to the patient. The main idea behind HAT is to shift the access control responsibilities from the IMD to an external device under the user's control, such as a smartphone, acting as the IMD's Key Distribution Center. We show that HAT only introduces minimal energy and memory overhead and formally prove its security using Verifpal. Sayon Duttagupta, Eduard Marin, Dave Singelée, Bart Preneel |
CODASPY | 1 |
| 2022 | T-HIBE: A Novel Key Establishment Solution for Decentralized, Multi-Tenant IoT SystemsabstractThe Internet of Things (IoT) devices has evolved considerably in the past few years and is expected to grow exponentially in the next decade. This exponential growth makes key management in an IoT ecosystem very challenging. Traditional IoT systems are often centralized and grouped into an ecosystem. However, this type of centralized architecture is not always compatible with practical IoT deployments. This paper proposes T-HIBE, a secure key establishment and agreement solution for a decentralized multi-tenant IoT system with multiple security domains. T-HIBE relies on principles of identity-based cryptography for key transport between intra and inter-domain devices while avoiding the inherent key-escrow problem. Furthermore, we have demonstrated our proposed architecture on an ARM Cortex-M4 microcontroller and evaluated the performance to show that T-HIBE does not have a significant energy and performance cost. Sayon Duttagupta, Dave Singelée, Bart Preneel |
CCNC | 1 |