Dominik Roy George

dblp:334/1390 · DBLP profile ↗
← Back
5ranked-venue papers
3as first author
5since 2021 · last 2026
0000-0002-1311-5806ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 2 first-author · 4 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Computer networks · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 MeshGuard: MUD-Based Network Access Control for Large-Scale Thread-Powered IoT Networks
abstract
The IETF standard Manufacturer Usage Description (MUD) enables manufacturers to equip IoT devices with certified URLs that provide traffic profiles for those devices, helping administrators enforce network access control. However, MUD assumes devices operate on full IP stacks and therefore does not account for constrained IoT devices running Thread–the dominant low-power mesh networking standard–which lacks complete TCP/IP functionality. While prior work proposes extensions to support MUD in Thread environments, these approaches are limited to simple topologies with a single border router and do not scale to realistic deployments with multiple, heterogeneous border routers. We introduce MeshGuard, a framework enabling MUD-based access control in complex Thread networks, with any number of border routers. MeshGuard extends the Mesh Link Establishment (MLE) protocol to deliver MUD information from constrained devices to border routers regardless of network topology. Moreover, MeshGuard leverages Software-Defined Networking (SDN) to synchronize access control lists across all routers. Experiments on our proof-of-concept with real devices (nRF5340, nRF52833, Raspberry-Pi 3) demonstrate enhanced security, minimal overhead, and linear scalability compared to state-of-the-art approaches.
Dominik Roy George, Wouter van Hoof, Habib Mostafaei, Savio Sciancalepore
DSN1
2025 ePPTM - Enhanced Privacy-Preserving Trajectory Matching on Autonomous Vehicles
abstract
Detecting in advance spatiotemporal collisions among autonomous vehicles (AVs) is crucial for enhancing safety and reducing risks. However, comparing plain-text trajectories leaks private path information, e.g., the location of storage sites, and may reveal private users’ data. Although the literature already provides a few solutions for privacy-preserving trajectory comparison, they cannot handle sparse trajectory data, leading to increased safety risks. In this article, we propose ePPTM, an enhanced fully accurate protocol for privacy-preserving trajectory matching among AVs. ePPTM combines two main building blocks, i.e., the Incremental Capsule Matching algorithm, detecting co-location using capsules defined over trajectories at an increasing level of granularity, and privacy-preserving proximity testing, allowing comparison among trajectory identifiers by revealing only colliding elements. We describe two modes of ePPTM, i.e., the Truncated Mode and Full Mode, with the former potentially decreasing processing demands while fully preserving privacy and safety (no missed collisions). We implement a proof of concept of ePPTM, release the code open source, and test it on two testbeds involving heterogeneous devices and real sparse trajectory data. We demonstrate experimentally the perfect accuracy of ePPTM, i.e., 100% accuracy in identifying collisions, while earlier approaches simply fail. We also explore the overhead of ePPTM, showing that it is lightweight when trajectories do not collide or have only a few points in common. The overhead increases when trajectories are more similar, but can be always kept under control at the expense of a little privacy leakage.
Dominik Roy George, Savio Sciancalepore
IEEE Internet Things J.1
2023 Remote Attestation with Constrained Disclosure
abstract
Trusted Platform Modules (TPMs) are used for remote attestation to ensure the authenticity and integrity of software running on a computer system. However, measuring software executed as containers or virtual machines can be challenging as it is measured concurrently, resulting in a jumbled measurement log that is difficult to disentangle. Moreover, disclosing the entire measurement log in traditional binary remote attestation raises privacy and intellectual property concerns. To address these issues, we propose a remote attestation method with constrained disclosure, allowing for selective disclosure of entries in the measurement log using a non-interactive zero-knowledge (NIZK) proof with Schnorr signatures. Our approach is evaluated for security and privacy and proven to be correct, sound, and satisfies the properties of a NIZK proof. Formal verification of our solution with ProVerif also supports our claims. Furthermore, the performance evaluation of our proof-of-concept implementation shows that our contribution is feasible, and the overhead introduced is negligible.
Michael Eckel, Dominik Roy George, Björn Grohmann, Christoph Krauß
ACSAC2
2023 Privacy-Preserving Multi-Party Access Control for Third-Party UAV Services
abstract
Third-Party Unmanned Aerial Vehicle (UAV) Services, a.k.a. Drone-as-a-Service (DaaS), are an increasingly adopted business model, which enables possibly unskilled users, with no background knowledge, to operate drones and run automated drone-based tasks. Although these services provide significant advantages, the resources provided by drones are typically owned by multiple parties. Thus, Third-Party UAV services require adopting multi-party access control solutions. In this context, the leakage of the access control policies specified by the data owners might disclose confidential information and, thus, they should be protected as well. In this work, we propose a privacy-preserving multi-party access control solution tailored to the application scenarios of Third-Party UAV Services. Our solution advances an existing privacy-preserving multi-party access control framework based on Secure Function Evaluation to fit the distributed and heterogeneous nature of drone deployments. Through an extensive experimental evaluation, we demonstrate our solution can perform private policy evaluation on constrained devices in a reasonable time while requiring limited communication, memory, and energy overhead.
Dominik Roy George, Savio Sciancalepore, Nicola Zannone
SACMAT1
2022 Privacy-Preserving Trajectory Matching on Autonomous Unmanned Aerial Vehicles
abstract
Autonomous Unmanned Aerial Vehicles (UAVs) are increasingly deployed nowadays, thanks to the additional features and enhanced flexibility they provide, e.g., for transportation and goods delivery. On the one hand, discovering in advance collisions occurring with other UAVs in the future could enhance the efficiency of the path planning, reducing further the delivery time and UAVs’ energy consumption. On the other hand, location and timestamps–key to detecting and avoiding collisions in advance–are sensitive and cannot be shared indiscriminately with untrusted entities.
Savio Sciancalepore, Dominik Roy George
ACSAC2