Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Nicolai Kuntze

dblp:33/6392 · DBLP profile ↗
← Back
19ranked-venue papers
9as first author
0since 2021 · last 2015
0009-0006-5206-7575ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 5 first-authorComputer networks · 8 · 3 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
1 paper
Cyber-physical and IoT security · 100%
Computer architecture, parallel and distributed computing, and storage systems
1 paper
Embedded and real-time systems · 100%

Topics — the 2 heaviest of 2, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Cyber-physical and IoT security
embedded system security
0.212013
Enhanced embedded device security by combining hardware-based trust mechanisms · CCS 2013
Embedded and real-time systems
embedded system security
0.012013
Enhanced embedded device security by combining hardware-based trust mechanisms · CCS 2013

Methods — techniques the papers use, named apart from their topics

trusted platform module · 0.3hardware security module · 0.3
YearPublicationVenuePosition
2015 Distributed security management for the IoT
abstract
This paper proposes a concept of a distributed, hierarchical management structure for large interconnected, dynamic and heterogeneous infrastructures. This approach supporting has the potential to enable efficient security management as well as meta-data distribution is particularly relevant for applications relying on the so-called Internet of Things (IoT). The management structure is motivated by existing and successful approaches in peer-2-peer (P2P) networks for content distribution and it shares some of the characteristics. In contrast to P2P networks with clearly defined functional goals, the IoT can support various applications. Security management functionalities as well as other management tasks need to conform to the heterogeneity of applications and devices. Further, there is no single entity in control of the complete system and applications will definitely be cross-domain. Thus, a classical middle-ware is not suitable and a distributed approach as proposed in this paper can constitute the basis for a new management core for the IoT.
Nico Lincke, Nicolai Kuntze, Carsten Rudolph
IM2
2015 On the Secure Distribution of Vendor-Specific Keys in Deployment Scenarios
Nicolai Kuntze, Andreas Fuchs 0002, Carsten Rudolph
SEC1
2014 Integrity based relationships and trustworthy communication between network participants
abstract
Establishing trust relationships between network participants by having them prove their operating system's integrity via a Trusted Platform Module (TPM) provides interesting approaches for securing local networks at a higher level. In the introduced approach on OSI layer 2, attacks carried out by already authenticated and participating nodes (insider threats) can be detected and prevented. Forbidden activities and manipulations in hard- and software, such as executing unknown binaries, loading additional kernel modules or even inserting unauthorized USB devices, are detected and result in an autonomous reaction of each network participant. The provided trust establishment and authentication protocol operates independently from upper protocol layers and is optimized for resource constrained machines. Well known concepts of backbone architectures can maintain the chain of trust between different kinds of network types. Each endpoint, forwarding and processing unit monitors the internal network independently and reports misbehaviours autonomously to a central instance in or outside of the trusted network.
Alexander Oberle, Pedro Larbig, Nicolai Kuntze, Carsten Rudolph
ICC3
2013 Enhancing Security Testing via Automated Replication of IT-Asset Topologies
abstract
Security testing of IT-infrastructure in a production environment can have a negative impact on business processes supported by IT-assets. A test bed can be used to provide an alternate testing environment in order to mitigate this impact. Unfortunately, for small and medium enterprises, maintaining a physical test bed and its consistency with the production environment is a cost-intensive task. In this paper, we present the Infrastructure Replication Process (IRP) and a corresponding Topology Editor, to provide a cost-efficient method that makes security testing in small and medium enterprises more feasible. We utilize a virtual environment as a test bed and provide a structured approach that takes into account the differences between a physical and a virtual environment. Open standards, such as SCAP, OVAL or XCCDF, and the utilization the Interconnected-asset Ontology-IO-support the integration of the IRP into existing (automated) processes. We use the implementation of a prototype to present a proof-of-concept that shows how typical challenges regarding security testing can be successfully mitigated via the IRP.
Henk Birkholz, Ingo Sieverdingbeck, Nicolai Kuntze, Carsten Rudolph
ARES3
2013 Enhanced embedded device security by combining hardware-based trust mechanisms
abstract
Nowadays embedded systems in many application areas such as automotive, medical and industrial automation are designed with well-defined hardware and software components which are not meant to be exposed for user modifications. Adding or removing components to/from such systems is not permitted and sometimes not even possible since the systems often have to be up and running in a 24/7 manner. However due to the well-known nature of these types of embedded platform configuration the effort an attacker has to invest usually is reduced. The proposed publication presents a defense in depth strategy for application specific embedded devices by combining hardware-based security enhancements of modern processors with hardware security modules.
Martin Schramm, Karl Leidl, Andreas Grzemba, Nicolai Kuntze
CCS4
2013 Demo: Zero touch configuration
Nicolai Kuntze, Pedro Larbig, Carsten Rudolph
IM1
2013 On the automatic establishment of security relations for devices
Nicolai Kuntze, Carsten Rudolph
IM1
2013 Integrating trust establishment into routing protocols of today's MANETs
abstract
Conventional network protocols and its security mechanisms fail to cope with arising challenges in trust. Well known concepts from the domain of Trusted Computing can be applied to the example of mobile ad-hoc networks (MANETs) in order to establish extended trust capabilities between devices. The approach of such an anchor of trust in MANETs shows interesting possibilities since no central instances such as Access Points are involved in those networks. The communication between directly connected devices of the network is protected by a cryptographic protocol making use of a Trusted Platform Module (TPM) that serves as root-of-trust on each device. Such a hardware chip allows devices to attest the local system state and assess states of remote systems. Building on this, transmission of routing and payload data can be restricted to devices in trustworthy states. The resulting mobile ad-hoc network, by using this protocol, is protected against many of today's security threats. Single malicious devices are automatically recognised and excluded from participation in the network by all devices. Especially the dissemination of misleading routing information, which affects the availability of the whole network, is effectively prevented by the developed protocol. Thus, it is shown that the device itself is secured by a hardware TPM. Also the communication is secured, by verifying the device's state between the counterparts.
Alexander Oberle, Andre Rein, Nicolai Kuntze, Carsten Rudolph, Janne Paatero, Andrew Lunn, Péter Rácz
WCNC3
2012 Trusted service access with dynamic security infrastructure configuration
abstract
The increasing complexity of IT infrastructures and the integration of mobile end-user devices requires more sophisticated approaches in network perimeter protection. Currently, the state of the art in network safeguarding is represented by firewalls restricting and filtering the traffic entering and leaving the network. In most cases firewalls are static with respect to their configuration. This publication aims to introduce a generic approach that will enable dynamic configuration to these firewalls. Such a dynamic change allows for fine-grained policies supporting elaborate rules concerning the service usage within a network infrastructure.
Ronald Marx, Nicolai Kuntze, Carsten Rudolph, Ingo Bente, Jörg Vieweg
APCC2
2012 On the Creation of Reliable Digital Evidence
Nicolai Kuntze, Carsten Rudolph, Aaron Alva, Barbara Endicott-Popovsky, John Christiansen, Thomas Kemmerich
IFIP Int. Conf. Digital Forensics1
2010 Secure Mobile Business Information Processing
abstract
An ever increasing amount of functionality is incorporated into mobile phones-this trend will continue as new mobile phone platforms are more widely used such as the iPhone or Android. Along with this trend, however, new risks arise, especially for enterprises using mobile phones for security-critical applications such as business intelligence (BI). Although platforms like Android have implemented sophisticated security mechanisms, security holes have been reported. In addition, different stakeholders have access to mobile phones such as different enterprises, service providers, operators, or manufacturers. In order to protect security-critical business applications, a trustworthy mobile phone platform is needed. Starting with typical attack scenarios, we describe a security architecture for Android mobile phones based on the concepts of Trusted Computing. In particular, this architecture allows for a dynamic policy change to reflect the current environment the phone is being used in.
Nicolai Kuntze, Roland Rieke, Günther Diederich, Richard Sethmann, Karsten Sohr, Tanveer Mustafa, Kai-Oliver Detken
EUC1
2010 Authentic Refinement of Semantically Enhanced Policies in Pervasive Systems
Julian Schütte, Nicolai Kuntze, Andreas Fuchs 0002, Atta Badii
SEC2
2010 Trust in Peer-to-Peer Content Distribution Protocols
Nicolai Kuntze, Carsten Rudolph, Andreas Fuchs 0002
WISTP1
2009 Implementation of a Trusted Ticket System
Andreas Leicher, Nicolai Kuntze, Andreas U. Schmidt
SEC2
2008 Trust for Location-Based Authorisation
abstract
We propose a concept for authorisation using the location of a mobile device and the enforcement of location- based policies. Mobile devices enhanced by trusted computing capabilities operate an autonomous and secure location trigger and policy enforcement entity. Location determination is two-tiered, integrating cell-based triggering at handover with precision location measurement by the device.
Andreas U. Schmidt, Nicolai Kuntze, Joerg Abendroth
WCNC2
2008 On the Deployment of Mobile Trusted Modules
abstract
In its recently published TCG mobile reference architecture, the TCG Mobile Phone Work Group specifies a new concept to enable trust into future mobile devices. For this purpose, the TCG devises a trusted mobile platform as a set of trusted engines on behalf of different stakeholders supported by a physical trust-anchor. In this paper, we present our perception on this emerging specification. We propose an approach for the practical design and implementation of this concept and how to deploy it to a trustworthy operating platform. In particular we propose a method for the take-ownership of a device by the user and the migration (i.e., portability) of user credentials between devices.
Andreas U. Schmidt, Nicolai Kuntze, Michael Kasper
WCNC2
2007 Trusted Ticket Systems and Applications
Nicolai Kuntze, Andreas U. Schmidt
SEC1
2007 Non-Repudiation in Internet Telephony
Nicolai Kuntze, Andreas U. Schmidt, Christian Hett
SEC1
2007 Trustworthy Content Push
abstract
Delivery of content to mobile devices gains increasing importance in industrial environments to support employees in the field. An important application is e-mail push services like the fashionable Blackberry. These systems are facing security challenges regarding data transport to, and storage of the data on the end user equipment. The emerging trusted computing technology offers new answers to these open questions.
Nicolai Kuntze, Andreas U. Schmidt
WCNC1