Dimitrios Serpanos

dblp:47/331 · also Demetrios Serpanos, Dimitrios N. Serpanos · DBLP profile ↗
← Back
55ranked-venue papers
19as first author
9since 2021 · last 2025
0000-0002-1385-7113ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 29 · 8 first-author · 8 since 2021Computer networks · 12 · 7 first-authorApplied, interdisciplinary, general and emerging computing · 5 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 3 · 2 first-authorSecurity and privacy · 2Artificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1
YearPublicationVenuePosition
2025 Automatic Recovery of Run-time Threats in Distributed Industrial Control Systems
abstract
Over the past few years, the transition from centralized to distributed industrial control systems (ICS) has introduced new challenges related to coordination, communication reliability, and cybersecurity. These challenges include conditions such as deadlocks and livelocks, which adversaries can exploit to compromise ICS safety and availability. To ensure secure and resilient operations in distributed ICS, run-time monitoring must go beyond detection to include responsive recovery. In this paper, we extend the ASM2S framework, a model-based inline security monitoring approach, by integrating recovery capabilities directly into the monitoring loop. Our approach uses formal specifications to allow system behavior, threat conditions, and recovery actions to be explicitly defined and evaluated at run-time. We demonstrate the approach using a water distribution system use case. Our work enhances the run-time assurance of distributed ICS by enabling automatic detection and recovery from security violations, offering a robust foundation for self-healing critical infrastructure.
George E. Raptis, Muhammad Taimoor Khan 0001, Christos Koulamas, Dimitrios Serpanos
ETFA4
2025 Synthesizing Inline Security Monitors for ICS Using Generative AI and FormalBench
abstract
Industrial Control Systems (ICS) increasingly face cybersecurity threats due to their distributed architecture and critical role in infrastructure operations. We adopt inline security monitoring as a practical run-time verification strategy to address these risks. However, authoring formal specifications remains time-consuming and error-prone, requiring deep domain expertise. In this paper, we explore how large language models (LLMs) can support the synthesis of inline security monitors by generating Java Modeling Language (JML) specifications for distributed ICS applications. We use a water distribution system (WDS) as our testbed and FormalBench to generate prompts to guide the GPT-4o model in producing JML annotations. We then evaluate these outputs using the FormalBench framework. Our findings show that LLMs capture key security properties and generate context-aware assertions with minimal intervention, taking a first step toward automating the specification process and enhancing the security and resilience of distributed ICS environments.
George E. Raptis, Muhammad Taimoor Khan 0001, Christos Koulamas, Dimitrios Serpanos
IECON4
2025 Cross-Model Evaluation of LLMs for Generating Formal Specification of Distributed Industrial Control Systems
abstract
The increasing complexity and decentralization of Industrial Control Systems (ICS) have expanded the attack surface for cyber-security threats, particularly in critical infrastructure domains. Inline monitoring using formal annotations like the Java Modeling Language (JML) offers a lightweight yet precise method to detect behavioral anomalies. However, the manual creation of such specifications is resource-intensive and requires domain expertise. This paper explores generative artificial intelligence (AI), specifically large language models (LLMs), to automate the synthesis of inline formal security monitors. We benchmark three state-of-the-art LLMs (GPT-4o, DeepSeek-V3, and Gemini 2.5 Flash) on their ability to generate JML annotations for ICS software drawn from the ASM2S water distribution system. Our evaluation across five dimensions (syntax, semantics, property coverage, alarm semantics, and effort savings) reveals distinct trade-offs. GPT-4o demonstrates strong syntactic and structural alignment with ASM2S, while DeepSeek-V3 offers richer behavioral modeling. Gemini 2.5 Flash showcases conceptual depth but introduces non-verifiable constructs. These findings demonstrate the potential of LLMs as co-pilots in secure-by-design ICS development and underscore the need for syntax-aware fine-tuning and interactive verification workflows.
George E. Raptis, Muhammad Taimoor Khan 0001, Christos Koulamas, Dimitrios Serpanos
KES4
2024 Towards Integration of EPANET and ASM2S To Enhance Security in Water Distribution Systems
abstract
In the decentralized Industrial Control Systems (ICS) era, water distribution systems (WDS) are critical in ensuring water safe and reliable delivery. However, their growing complexity, connectivity, and distributed nature expose them to cybersecurity risks. Renowned WDS software, like EPANET, lacks features to address such risks, which, however, can be addressed by complementary solutions, like ASM2S. In this paper, we compare the capabilities offered by these two tools and make a first step towards exploring their combination, aiming to equip WDS tools with enhanced hydraulic, water quality, and cybersecurity modeling and monitoring characteristics.
George E. Raptis, Muhammad Taimoor Khan 0001, Christos Koulamas, Dimitrios Serpanos
ETFA4
2024 Applying Inline Monitoring to Detect Run-Time Security Incidents in Water Distribution Systems
abstract
In the decentralized Industrial Control Systems (ICS) domain, water distribution systems (WDS) are critical in ensuring water safe and reliable delivery. However, their growing complexity, connectivity, and distributed nature expose them to cybersecurity risks. Run-time inline monitoring can address such risks. This paper focuses on implementing run-time inline security monitoring for deadlocks in WDS, providing examples and simulation results. The results indicate the run-time detection of deadlocks, enhancing WDS’s overall reliability and efficiency.
George E. Raptis, Muhammad Taimoor Khan 0001, Christos Koulamas, Dimitrios Serpanos
IECON4
2023 Towards Run-Time Security Monitoring of Distributed Industrial Control Systems
abstract
Over the past few years, there has been a noticeable transition from centralized Industrial Control Systems (ICS) to distributed systems. However, the challenges of distributed systems (e.g., communication delays and packet loss) can give rise to undesired situations like deadlocks, which malicious actors may target. To address such conditions, implementing run-time security monitoring can ensure these systems’ reliable and secure operation. In this paper, we introduce a novel approach for run-time security monitoring for distributed ICS, extending previous works that focus on autonomous and centralized systems. Our approach makes it possible to specify physical and cyber resources and their changing limitations within a distributed environment. By doing so, our approach offers a valuable contribution to ICS security by tackling limitations introduced by distributed ICS. Furthermore, it provides an efficient mechanism for monitoring the security of these systems in real time.
George E. Raptis, Muhammad Taimoor Khan 0001, Kyriakos Stefanidis, Christos Koulamas, Dimitrios Serpanos
ETFA5
2023 Federated Learning in Malware Detection
abstract
Malware detection constitutes a fundamental step in safe and secure computational systems, including industrial systems and the Internet of Things (IoT). Modern malware detection is based on machine learning methods that classify software samples as malware or benign, based on features that are extracted from the samples through static and/or dynamic analysis. State-of-the-art malware detection systems employ Deep Neural Networks (DNNs) whose accuracy increases as more data are analyzed and exploited. However, organizations also have significant privacy constraints and concerns which limit the data that they share with centralized security providers or other organizations, despite the malware detection accuracy improvements that can be achieved with the aggregated data. In this paper we investigate the effectiveness of federated learning (FL) methods for developing and distributing aggregated DNNs among autonomous interconnected organizations. We analyze a solution where multiple organizations use independent malware analysis platforms as part of their Security Operations Centers (SOCs) and train their own local DNN model on their own private data. Exploiting cross-silo FL, we combine these DNNs into a global one which is then distributed to all organizations, achieving the distribution of combined malware detection models using data from multiple sources without sample or feature sharing. We evaluate the approach using the EMBER benchmark dataset and demonstrate that our approach effectively reaches the same accuracy as the non-federated centralized DNN model, which is above 93%.
Dimitrios Serpanos, Georgios Xenos
ETFA1
2022 False Data Injection Attacks on Sensor Systems
abstract
False data injection attacks on sensor systems are an emerging threat to cyberphysical systems, creating significant risks to all application domains and, importantly, to critical infrastructures. Cyberphysical systems are process-dependent leading to differing false data injection attacks that target disruption of the specific processes (plants). We present a taxonomy of false data injection attacks, using a general model for cyberphysical systems, showing that global and continuous attacks are extremely powerful. In order to detect false data injection attacks, we describe three methods that can be employed to enable effective monitoring and detection of false data injection attacks during plant operation. Considering that sensor failures have equivalent effects to relative false data injection attacks, the methods are effective for sensor fault detection as well.
Dimitrios Serpanos
ICCAD1
2021 Towards Scalable Security of Real-time Applications: A Formally Certified Approach
abstract
In this paper, we present our ongoing work to develop an efficient and scalable verification method to achieve runtime security of real-time applications with strict performance requirements. The method allows to specify (functional and non-functional) behaviour of a real-time application and a set of known attacks/threats. The challenge here is to prove that the runtime application execution is at the same time (i) correct w.r.t. the functional specification and (ii) protected against the specified set of attacks, without violating any non-functional specification (e.g., real-time performance). To address the challenge, first we classify the set of attacks into computational, data integrity and communication attacks. Second, we decompose each class into its declarative properties and definitive properties. A declarative property specifies an attack as a one big-step relation between initial and final state without considering intermediate states, while a definitive property specifies an attack as a composition of many small-step relations considering all intermediate states between initial and final state. Semantically, the declarative property of an attack is equivalent to its corresponding definitive property. Based on the decomposition and the adequate specification of underlying runtime environment (e.g., compiler, processor and operating system), we prove rigorously that the application execution in a particular runtime environment is protected against declarative properties without violating runtime performance specification of the application. Furthermore, from the specification, we generate a security monitor that assures that the application execution is secure against each class of attacks at runtime without hindering real-time performance of the application.
Muhammad Taimoor Khan 0001, Dimitrios Serpanos, Howard E. Shrobe
ETFA2
2020 Neural Network-Based Side Channel Attacks and Countermeasures
abstract
This paper surveys results in the use of neural networks and deep learning in two areas of hardware security: power attacks and physically-unclonable functions (PUFs).
Dimitrios Serpanos, Shengqi Yang, Marilyn Wolf
DAC1
2020 Rigorous Machine Learning for Secure and Autonomous Cyber Physical Systems
abstract
Machine learning (ML) based secure and autonomous cyber physical systems are often not reliable and interpretable mainly because the employed ML techniques suffer from false alarms that may result in physical and financial loss. We assert that reliability and interpret-ability of the ML methods depends on underlying statistical models that infer results. Therefore, we introduce a rigorous method for the model selection. Current selection methods choose a model using statistical criteria (e.g., AIC, BIC). These criteria may lead to selection of an inappropriate model (e.g. over/under-fitting) because they only consider relative-quality (statistical) of the model without considering absolute-quality (formal) of the model based on the model/data specification. To this end, we argue the suitability of recently developed-decidability procedures/solvers. Such solvers infer if a selected model can(not) classify a given data and produce a formal proof that can be used to assure reliability and security of modelled system. We demonstrate feasibility of the method through a simple example of an autonomous insulin pump.
Muhammad Taimoor Khan 0001, Dimitrios Serpanos, Howard E. Shrobe, Muhammad Murtaza Yousuf
ETFA2
2019 Fault Diagnosis in Energy Conversion Systems using Neural Networks and Statistical Decision Making
abstract
Fault diagnosis in energy conversion systems is performed with the use of neural networks and statistical decision making. An energy conversion system comprising a solar power unit, a DC-DC converter and a DC motor is considered and the related condition monitoring problem is solved. A neural network is used to model the dynamics of this energy conversion system after processing its input and output measurements, being accumulated at different operating conditions. The considered neural model is trained with the use of first-order gradient algorithms and consists of a hidden layer of Gauss-Hermite polynomial activation functions and of an output layer with linear weights. The neural network and the resulting model represents the fault-free functioning of the energy conversion system. At a next stage, the measurements of the real output of the energy conversion system are compared against the estimated outputs which are provided by the neural model. This provides, the residuals sequence. It holds that the sum of the squares of the residuals' vectors, multiplied with the inverse of the associated covariance matrix, stands for a stochastic variable (statistical test) which follows the χ2distribution. One can have a precise and almost infallible decision making tool about the appearance of faults in the energy conversion system, by selecting the 96% or the 98% confidence intervals of this distribution. When the upper or lower bound of the confidence interval are persistently exceeded one can conclude that the system has been subject to a fault. Finally, fault isolation can be also accomplished, by applying the statistical test into subspaces of the energy conversion system's state-space model.
Gerasimos G. Rigatos, Dimitrios Serpanos, Vasileios Siadimas, Pierluigi Siano, Masoud Abbaszadeh, Patrice Wira
IECON2
2018 MTF -Storm: a High Performance Fuzzer for Modbus/TCP
abstract
MTF -Storm is a highly effective fuzzer for industrial systems employing Modbus/TCP connectivity. It achieves high fault coverage, while offering high performance and quick testing of the System-Under- Test (SUT). Analogously to its predecessor MTF, MTF -Storm operates in 3 phases: reconnaissance, fuzz testing and failure detection. Reconnaissance identifies the memory organization of the SUT and the supported functionality, enabling selection and synthesis of fuzz testing sequences that are effective for the specific SUT. MTF -Storm develops its test sequences systematically, starting with single field tests and proceeding with combined field tests, adopting techniques for automated combinatorial software testing and reducing the test space through partitioning field value ranges. MTF -Storm has been used to evaluate 9 different Modbus/TCP implementations and has identified issues with all of them, ranging from out-of-spec responses to successful denial-of-service attacks and crashes.
Konstantinos Katsigiannis, Dimitrios Serpanos
ETFA2
2018 Condition monitoring of wind-power units using the Derivative-free nonlinear Kalman Filter
abstract
The article proposes a method for diagnosing faults and cyberattacks in electric power generation units that consist of a wind-turbine and of an asynchronous (DFIG) generator. The method relies on a differential flatness theory-based implementation of the nonlinear Kalman Filter, known as Derivative-free nonlinear Kalman Filter. The estimated outputs provided by the Kalman filter are subtracted from the real outputs measured from the power unit, thus generating the residuals sequence. It is proven that the sum of the squares of the residuals vectors, weighted by the inverse of the residuals covariance matrix, stands for a stochastic variable that follows the χ2distribution. By exploiting the statistical properties of the χ2distribution one can define confidence intervals which allow for deciding at a high certainty level about the appearance of a fault or cyberattack in the wind-power system.
Gerasimos G. Rigatos, Nikolaos A. Zervos, Dimitrios Serpanos, Vasileios Siadimas, Pierluigi Siano, Masoud Abbaszadeh
INDIN3
2018 Highly Assured Safety and Security of e-Health Applications
abstract
Modern medical devices aim at providing invasive e-health care services to patients with long-term conditions. Typically, these services are implemented as embedded software applications that remotely and automatically control the operations of the devices according to the patient's condition as monitored by the underlying sensors. Such applications are neither safe nor secure mainly because of unreliable sensors, which may provide incorrect input data either due to its malfunctioning or due to some accidental (by privileged user) or intentional (by adversary) interference. Hence, the incorrect sensor data may lead to identification of inaccurate patient condition, which may threaten the patient's life. To ensure safety and security of e-health applications, current approaches employ data analysis techniques to monitor sensor data and alarm when some unusual value is detected and employ access control strategies to ensure that controller decisions are consistent with sensor input data. However, such approaches fail to detect stealthy attacks, e.g. bad data (false data injection) and bad computations because they do not understand what the application or device is trying to do. To this end, we evaluate our existing approach (i.e., ARMET) to assure safety and security of an emerging and critically real-time application domain of e-health. The approach is based on the specification of the application and device, which has a design and a run-time component. Given an application specification, the design component employs logical verification methods to assure that the application design is resilient to some bad data, i.e., there are no sensor input data values with meaningful threshold which are admissible to the specification but are not true. Given the specification, the runtime component monitors application's execution and assures that the execution is consistent with the specification and alarms whenever it detects a violation, i.e., there is a bad computation. We evaluate the methodology through its application to an example medical e-health application that controls and monitors blood glucose through an insulin pump.
Muhammad Taimoor Khan 0001, Dimitrios Serpanos, Howard E. Shrobe
WiMob2
2018 ARMET: Behavior-Based Secure and Resilient Industrial Control Systems
abstract
In this paper, we introduce a design methodology to develop reliable and secure industrial control systems (ICSs) based on the behavior of their computational resources (i.e., process/application) and underlying physical resources (e.g., the controlled plant). The methodology has three independent, but complementary, components that employ novel approaches and techniques in the design of reliable and secure ICSs. First, we introduce reliable-and-secure-by-design development of secure industrial control applications through stepwise sound refinement of an executable specification, employing deductive synthesis to enforce functional and nonfunctional (e.g., security and safety) properties of ICS applications. Second, we present a runtime security monitor at the middleware level of ICSs that protects ICS operation in the field through comparison of the application execution and the application specification execution in real time; the runtime security monitor can be synthesized from the executable specification. Finally, based on the specification, we perform a vulnerability analysis for false data injection (FDI) attacks, which leads to ICS application designs that are resilient to this type of attacks. We demonstrate the methodology through its application to a basic and typical ICS example application, describing all the tools used and ARMET, the middleware monitor that constitutes the core component of the methodology.
Muhammad Taimoor Khan 0001, Dimitrios Serpanos, Howard E. Shrobe
Proc. IEEE2
2018 Scanning The Issue
abstract
This special issue is devoted to the safety and security issues presented by cyber–physical systems (CPSs). CPSs use cyber software/hardware to perform real-time control on physical systems. Such systems are widely used in aerospace and automotive, medical, industrial, and critical infrastructure applications.
Marilyn Wolf, Dimitrios Serpanos
Proc. IEEE2
2018 Safety and Security in Cyber-Physical Systems and Internet-of-Things Systems
abstract
Safety and security have traditionally been distinct problems in engineering and computer science. The introduction of computing elements to create cyber-physical systems (CPSs) has opened up a vast new range of potential problems that do not always show up on the radar of traditional engineers. Security, in contrast, is traditionally viewed as a data or communications security problem to be handled by computer scientists and/or computer engineers. Advances in CPSs and the Internet-of-Things (IoT) requires us to take a unified view of safety and security. This paper defines a safety/security threat model for CPSs and IoT systems and surveys emerging techniques which improve the safety and security of CPSs and IoT systems.
Marilyn Wolf, Dimitrios Serpanos
Proc. IEEE2
2017 PriviPK: Certificate-less and secure email communication
Mashael Al Sabah, Alin Tomescu, Ilia A. Lebedev, Dimitrios Serpanos, Srini Devadas
Comput. Secur.4
2017 Safety and Security of Cyber-Physical and Internet of Things Systems [Point of View]
abstract
Computer system security and engineering system safety have traditionally been very distinct topics pursued by people with very different expertise. The advent of cyber-physical systems and the Internet-of-Things (IoT) changes that dynamic. Safety and security are now inextricably linked through our linkage of computer hardware and software with complex physical plants. Computers have been added to traditional engineering systems to achieve goals that we cannot achieve using traditional mechanical control. The automobile provides an important early example of the benefits of cyber-physical systems: computer engine control allowed manufacturers to simultaneously meet stiff requirements on both fuel economy and emissions; features such as antilock brakes and traction control improved vehicle handling and safety; and a new generation of supercars use software to not only provide sophisticated vehicle capabilities but also to change the vehicle's handling characteristics at the push of a button.
Marilyn Wolf, Dimitrios Serpanos
Proc. IEEE2
2015 A Low-Latency, Low-Area Hardware Oblivious RAM Controller
abstract
We build and evaluate Tiny ORAM, an Oblivious RAM prototype on FPGA. Oblivious RAM is a cryptographic primitive that completely obfuscates an application's data, access pattern, and read/write behavior to/from external memory (such as DRAM or disk). Tiny ORAM makes two main contributions. First, by removing an algorithmic bottleneck in prior work, Tiny ORAM is the" first hardware ORAM design to support arbitrary block sizes (e.g., 64 Bytes to 4096 Bytes). With a 64 Byte block size, Tiny ORAM can " finish an access in 1:4us, over 40x faster than the prior-art implementation. Second, through novel algorithmic and engineering-level optimizations, Tiny ORAM reduces the number of symmetric encryption operations by ~ 3x compared to a prior work. Tiny ORAM is also the " first design to implement and report real numbers for the cost of symmetric encryption in hardware ORAM constructions. Putting it together, Tiny ORAM requires 18381 (5%) LUTs and 146 (13%) Block RAM on a Xilinx XC7VX485T FPGA, including the cost of encryption.
Christopher W. Fletcher, Ling Ren 0001, Albert Kwon, Marten van Dijk, Emil Stefanov, Dimitrios Serpanos, Srini Devadas
FCCM6
2014 Introduction to Special Issue on Risk and Trust in Embedded Critical Systems
abstract
No abstract available.
Judith E. Y. Rossebø, Siv Hilde Houmb, Geri Georg, Virginia N. L. Franqueira, Dimitrios Serpanos
ACM Trans. Embed. Comput. Syst.5
2013 Security challenges in embedded systems
abstract
Embedded systems security is a significant requirement in emerging environments, considering the increasing deployment of embedded systems in several application domains. The large number of deployed embedded systems, their limited resources and their increasing complexity render systems vulnerable to an increasing number of threats. Additionally, the involvement of sensitive, often private, information and the expectation for safe and dependable embedded platforms lead to strong security requirements, even legal ones, which require new technologies for their provision. In this article, we provide an overview of embedded security issues, used methods and technologies, identifying important challenges in this emerging field.
Dimitrios Serpanos, Artemios G. Voyiatzis
ACM Trans. Embed. Comput. Syst.1
2012 Power Analysis Attack Resistance Engineering by Dynamic Voltage and Frequency Scaling
abstract
This article proposes a novel approach to cryptosystem design to prevent power analysis attacks. Such attacks infer program behavior by continuously monitoring the power supply current going into the processor core. They form an important class of security attacks. Our approach is based on dynamic voltage and frequency scaling (DVFS), which hides processor state to make it harder for an attacker to gain access to a secure system. Three designs are studied to test the efficacy of the DVFS method against power analysis attacks. The advanced realization of our cryptosystem is presented which achieves enough high power and time trace entropies to block various kinds of power analysis attacks in the DES algorithm. We observed 27% energy reduction and 16% time overhead in these algorithms. Finally, DVFS hardness analysis is presented.
Shengqi Yang, Pallav Gupta, Marilyn Wolf, Dimitrios Serpanos, Narayanan Vijaykrishnan, Yuan Xie 0001
ACM Trans. Embed. Comput. Syst.4
2010 An agent based middleware imposing intelligence over critical infrastructures utilizing Wireless Sensor Networks
abstract
A modular architecture for power constrained embedded devices which leverages an agent based middleware in order to impose intelligence over critical infrastructures which require real time actions is always desirable in the case of Wireless Sensor Networks. The main objective of such architecture is the integration of a Wireless Sensor Network with the internet. This objective indicates the need of Ipv6 ready devices as well as the utilization of newly emerged standards such as the 6lowpan which forms an abstraction layer between the Medium Access control and the IP layers.
Christos Panagiotou, John V. Gialelis, Stavros A. Koubias, Dimitrios Serpanos
ETFA4
2009 Adaptive DRM framework in user-converged multimedia ecosystems, utilizing MPEG-21 semantics
abstract
As dynamicity in networks and interoperability in DRM systems become the critical aspects in networked ecosystems, new emerging frameworks for secure, user-converged digital content delivery are required. In this work, we argue that the IPMP and REL components of MPEG-21 framework should be utilized in order to achieve a user-adaptive and interoperable DRM architecture.
Tasos Fragopoulos, John V. Gialelis, Dimitrios Serpanos
ISADS3
2009 Network Stack Optimization for Improved IPsec Performance on Linux
Michael G. Iatrou, Artemios G. Voyiatzis, Dimitrios Serpanos
SECRYPT3
2008 Security and Privacy in Distributed Smart Cameras
abstract
Distributed smart camera systems are becoming increasingly important in a wide range of applications. As they are often deployed in public space and/or our personal environment, they increasingly access and manipulate sensitive or private information. Their architectures need to address security and privacy issues appropriately, considering them from the inception of the overall system structure. In this paper, we present security and privacy issues of distributed smart camera systems. We describe security requirements, possible attacks, and common risks, analyzing issues at the node and at the network level and presenting available solutions. Although security issues of distributed smart cameras are analogous to networked embedded systems and sensor networks, emphasis is given to special requirements of smart camera networks, including privacy and continuous real-time operation.
Dimitrios Serpanos, Andreas Papalambrou
Proc. IEEE1
2008 The security of the Fiat-Shamir scheme in the presence of transient hardware faults
abstract
Implementation cryptanalysis has emerged as a realistic threat for cryptographic systems. It consists of two classes of attacks: fault-injection and side-channel attacks. In this work, we examine the resistance of the Fiat--Shamir scheme to fault-injection attacks, since Fiat--Shamir is a popular scheme for “light” consumer devices, such as smartcards, in a wide range of consumer services. We prove that an existing attack, known as the Bellcore attack, is incomplete. We propose an extension to the protocol that proactively secures Fiat--Shamir systems from the Bellcore attack and we prove its strength. Finally, we introduce a new attack model, which, under stronger assumptions, can derive the secret keys from both the original Fiat--Shamir scheme as well as its proposed extension. Our approach demonstrates that countermeasures for implementation cryptanalysis must be carefully designed and that deployed systems must include appropriate protection mechanisms for all known attacks and be flexible enough to incorporate countermeasures for new ones.
Artemios G. Voyiatzis, Dimitrios Serpanos
ACM Trans. Embed. Comput. Syst.2
2007 Using value locality to reduce memory encryption overhead in embedded processors
abstract
Memory encryption has gained much attention lately as a way to offer a secure environment to fight against software and hardware attacks. Many researchers provided memory encryption schemes whereby one or more levels of the memory hierarchy were encrypted using a cryptographic algorithm such as AES. Counter mode (CM) encryption, also called one-time-pad (OTP) encryption, is proven to be quite effective for main memory encryption. However, CM encryption requires an extra sequence number (counter) to be associated with every memory location (L2 block cacheline granularity is used). The per-block counters must be updated every time a block is written back to memory otherwise known-plaintext attacks may occur. Thus, the size of those counters is a critical parameter in the system design. In this work, we propose the use of silent stores as a method of providing the CM encryption with less overhead. Silent stores, i.e. stores, to memory that write the same value as already stored in that memory location, have been observed to occur frequently. These stores create redundant memory write-backs (and counter updates), so eliminating them will lower performance overheads introduced by the encyption/decryption process. Our initial results show significant benefits across the board indicating the promising nature of the proposed idea.
Georgios Keramidas, Pavlos Petoumenos, Alexandros Antonopoulos, Stefanos Kaxiras, Dimitrios Serpanos
ETFA5
2007 VLSI models of network-on-chip interconnect
abstract
We use VLSI circuit models to analyze the relative delay of interconnect subsystems for networks-on-chips (NoCs). Most work in NoCs has selected a network topology based on higher-level performance models, such as packet delay. Our model parameterizes the interconnect subsystem size by N, the number of IP cores (processors, memories, etc.) to be connected. This paper analyzes busses, crossbars, and some multi-stage networks. We compare the delay required transfer a specific amount of information (bits) between two cores. Considering the data transfer parallelism in crossbars, we make 2 different comparisons: (i) transfer between 2 devices, and (ii) parallel transfers between all devices.
Dimitrios Serpanos, Marilyn Wolf
VLSI-SoC1
2007 Chloe@University: an indoor, mobile mixed reality guidance system
abstract
With the advent of ubiquitous and pervasive computing environments, one of promising applications is a guidance system. In this paper, we propose a mobile mixed reality guide system for indoor environments, [email protected] A mobile computing device (Sony's Ultra Mobile PC) is hidden inside a jacket and a user selects a destination inside a building through voice commands. A 3D virtual assistant then appears in the see-through HMD and guides him/her to destination. Thus, the user simply follows the virtual guide. [email protected] also suggests the most suitable virtual character (e.g. human guide, dog, cat, etc.) based on user preferences and profiles. Depending on user profiles, different security levels and authorizations for content are previewed. Concerning indoor location tracking, WiFi, RFID, and sensor-based methods are integrated in this system to have maximum flexibility. Moreover smart and transparent wireless connectivity provides the user terminal with fast and seamless transition among Access Points (APs). Different AR navigation approaches have been studied: [Olwal 2006], [Elmqvist et al.] and [Newman et al.] work indoors while [Bell et al. 2002] and [Reitmayr and Drummond 2006] are employed outdoors. Accurate tracking and registration is still an open issue and recently it has mostly been tackled by no single method, but mostly through aggregation of tracking and localization methods, mostly based on handheld AR. A truly wearable, HMD based mobile AR navigation aid for both indoors and outdoors with rich 3D content remains an open issue and a very active field of multi-discipline research.
Achille Peternier, Xavier Righetti, Mathieu Hopmann, Daniel Thalmann, Matteo Repetto, George Papagiannakis, Pierre Davy, Mingyu Lim, Nadia Magnenat-Thalmann, Paolo Barsocchi, Tasos Fragopoulos, Dimitrios Serpanos, Yiannis Gialelis, Anna Kirykou
VRST12
2006 Real-time service provisioning for mobile and wireless networks
Károly Farkas, Oliver Wellnitz, Matthias Dick, Marcel Busse, Wolfgang Effelsberg, Yacine Rebahi, Dorgham Sisalem, Dan Grigoras, Kyriakos Stefanidis, Dimitrios Serpanos
Comput. Commun.11
2005 Power Attack Resistant Cryptosystem Design: A Dynamic Voltage and Frequency Switching Approach
abstract
A novel power attack resistant cryptosystem is presented. Security in digital computing and communication is becoming increasingly important. Design techniques that can protect cryptosystems from leaking information have been studied by several groups. Power attacks, which infer program behavior from observing power supply current into a processor core, are important forms of attack. Various methods have been proposed to counter the popular and efficient power attacks. However, these methods do not adequately protect against power attacks and may introduce new vulnerabilities. We address a novel approach against power attacks, i.e., dynamic voltage and frequency switching (DVFS). Three designs, naive, improved and advanced implementations, have been studied to test the efficiency of DVFS against power attacks. A final advanced realization of our novel cryptosystem is presented; it achieves enough high power trace entropy and time trace entropy to block all kinds of power attacks, with 27% energy reduction and 16% time overhead for DES encryption and decryption algorithms.
Shengqi Yang, Marilyn Wolf, Narayanan Vijaykrishnan, Dimitrios Serpanos, Yuan Xie 0001
DATE4
2005 Efficient switch schedulers with random decisions
abstract
Appropriate use of randomness in the development of scheduling algorithms is a powerful tool, because it leads to systems that are theoretically efficient and fair, while feasible to analyze and obtain concrete performance bounds. However, randomness is hard to implement, due to the high complexity and long delay of efficient random number generators. Thus, deterministic schedulers for high-speed switches have been developed. In this paper, we introduce high-speed schedulers for packet switches, which employ randomness and provide high performance at low cost. The schedulers implement variations of an existing, optimal on-line bipartite graph matching algorithm and achieve fair service and improved performance over PIM at a significantly lower cost; PIM is the main alternative algorithm with random decisions and has been used as the basis for a wide range of deterministic algorithms.
Dimitrios Serpanos
ISADS1
2004 Scheduling objects in broadcast systems with energy-limited clients
Dimitrios Serpanos, Apostolos Traganitis
Comput. Commun.1
2004 Guest editorial: Special issue on embedded systems and security
abstract
No abstract available.
Dimitrios Serpanos, Haris Lekatsas
ACM Trans. Embed. Comput. Syst.1
2004 Evaluation of hardware and software schedulers for embedded switches
abstract
High-speed packet switches become increasingly important to embedded systems because they provide multiple parallel data paths necessary in emerging systems such as embedded multiprocessors, multiprotocol communication processors, and so on. The most promising architecture for embedded switches is the one that uses multiple input queues, due to its low-cost integration in conventional embedded systems, which include memory management subsystems. Such switches require high-speed schedulers, in order to resolve conflicts among packet destinations and to achieve low latency, high bandwidth communication, while providing fairness guarantees. In general, these schedulers are categorized as centralized or distributed, depending on their operation. In this paper, we evaluate hardware and software implementations of two schedulers: 2-dimensional round-robin and FIRM, which are centralized and distributed, respectively. The evaluation is performed for embedded system implementation, on a system that includes an FPGA and an embedded processor on-chip. The performance results show that, in contrast to expectations, centralized schedulers provide better performance than distributed ones in hardware implementations. In software implementations for embedded processors, surprisingly, distributed schedulers achieve better performance, due to better management of the processor's limited resources and simpler code; our experiments have shown that compilers for embedded systems are quite limited and require significant improvement. Finally, we evaluate the scalability of the schedulers, in terms of throughput, circuit complexity, and power consumption, based on implementation technology, considering the dramatic improvements expected in the availability of high-speed programmable logic and embedded processors on the same chip.
Dimitrios Serpanos, Xenia Mountrouidou, Maria Gamvrili
ACM Trans. Embed. Comput. Syst.1
2003 Evaluation of Switch Schedulers for Embedded Systems
abstract
We evaluate hardware and software implementations of a centralized and a distributed scheduler for embedded packet switches. The evaluation is performed for embedded system implementation, on a system that includes an FPGA and an embedded, on-chip processor. The results demonstrate that, in contrast to expectations, centralized schedulers provide better performance than distributed ones in hardware implementations. In software implementations for embedded processors, surprisingly, distributed schedulers achieve better performance, due to better management of the processor's limited resources and simpler code.
Dimitrios Serpanos, Xenia Mountrouidou, Maria Gamvrili
ISCC1
2002 Exploitation of different types of locality for Web caches
abstract
Object access distribution in the Web is governed by Zipf's law, in general. This property leads to effective Web caches, which store the most popular objects and typically employ the LFU replacement policy, which achieves high, and often the highest, cache hit rates. However, Web cache design based only on Zipf's law has two main disadvantages: (i) it does not exploit the temporal and spatial locality of user accesses on a per session basis, and (ii) LFU implementation is costly and impractical in many environments, because it requires statistics on all objects accessed since the beginning of a cache's operation. We consider all parameters of locality of references in the Web (temporal, spatial and popularity) and draw an analogy with processor caches. Given cache replacement policies that address different locality characteristics, we argue that there exist replacement algorithms that combine these characteristics and achieve high performance at a low cost. We describe the Window-LFU (W-LFU), a policy that combines LFU and LRU and achieves better performance than LFU at lower cost. W-LFU exploits both Zipf's law, and temporal locality by using the accesses in a recent time-window. Simulations with actual traces indicate that W-LFU provides better results than theoretically expected.
George Karakostas, Dimitrios Serpanos
ISCC2
2002 Object scheduling in broadcast systems for energy-limited clients
abstract
Broadcast systems are popular in push-based information distribution environments, where subscribing clients are randomly switched on. The main problem in these systems is to construct a periodic (cyclic) schedule, where in every cycle each information object is transmitted several times, depending on its size and popularity. Existing algorithms consider memory-less clients and construct optimal schedules that optimize the aggregate access delay for objects; thus, they minimize client energy consumption. In this work, we analyze broadcast systems with memory equipped (caching) clients. We change the scheduling optimization criterion to include actual object reception time and thus, we provide a more realistic model for estimation of actual client power consumption. We prove that caching clients achieve reduced object reception time, leading to improved energy consumption. We give a simple proof that perfect periodicity in object transmission within scheduling cycles is necessary for optimal schedule, and calculate the conditions that optimal schedulers must satisfy. Since perfect periodicity is an NP-hard problem, we propose and analyze heuristic schedule modifications in order to achieve perfect periodicity for the more popular objects; heuristics include object transmission interleaving, preemptive transmission and exchange of object transmission order.
Dimitrios Serpanos, Apostolos Traganitis
ISCC1
2002 Active hardware attacks and proactive countermeasures
abstract
Active hardware attacks succeed in deriving cryptographic secrets from target devices. They were originally proposed for systems implementing RSA, Fiat-Shamir (1988) scheme, and Schnorr's scheme. Common targets for these attacks are systems used for client authentication in order to access services, e.g., pay-per view TV, video distribution and cellular telephony. These client systems hold secrets, typically cryptographic keys, owned by the service provider and often implement the Fiat-Shamir identification scheme. Given the strength of active attacks and the increasingly wide deployment of client systems, it is desirable to design proactive countermeasures for them. We focus on the Fiat-Shamir scheme. We prove that the conventional active attack can be easily avoided through appropriate system and protocol configuration; we denote this configuration as the precautious Fiat-Shamir Scheme. We argue that proactive countermeasures against active attacks are feasible and lead to systems that are inherently resistant to active attacks by careful protocol design, rather than ad hoc solutions.
Artemios G. Voyiatzis, Dimitrios Serpanos
ISCC2
2001 Defense Against Man-in-the-Middle Attack in Client-Server Systems
abstract
The deployment of several client-server applications over the Internet and emerging networks requires the establishment of the client's integrity. This is necessary for the protection of copyright of distributed material and, in general, for protection from loss of "sensitive" (secret) information. Clients are vulnerable to powerful man-in-the-middle attacks through viruses, which are undetectable by conventional anti-virus technology. We describe such powerful viruses and show their ability to lead to compromised clients, that cannot protect copyrighted or "sensitive " information. We introduce a methodology based on simple hardware devices, called "spies", which enables servers to establish client integrity, and leads to a successful defense against viruses that use man-in-the-middle attacks.
Dimitrios Serpanos, Richard J. Lipton
ISCC1
2000 FIRM: A Class of Distributed Scheduling Algorithms for High-Speed ATM Switches with Multiple Input Queues
abstract
Advanced input queuing is an attractive, promising architecture for high-speed ATM switches, because it combines the low cost of input queuing with the high performance of output queuing. The need for scalable schedulers for advanced input queuing switch architectures has led to the development of efficient distributed scheduling algorithms. We introduce a new distributed scheduling algorithm, FIRM, which provides improved performance characteristics over alternative distributed algorithms. FIRM achieves saturation throughput 1 with lower delay than the most efficient alternative (up to 50% at high load). Furthermore, it provides improved fairness (it approximates FCFS) and tighter service guarantee than others. FIRM provides a basis for a class of distributed scheduling algorithms, many of which provide even more improved performance characteristics.
Dimitrios Serpanos, Panayotis Antoniadis
INFOCOM1
2000 Scalable Memory Management for ATM Systems
abstract
The scalability of SDH/SONET to high speeds places strict performance requirements on ATM systems. Throughput preservation of link speed through protocols to a higher layer application is a known problem in high-speed communication systems, which becomes more acute as link speed increases and is being addressed with designs that offer high speed data paths and high embedded processing power. We introduce a specialized, high-speed, scalable and reusable queue manager (QM) for ATM systems, which enables high-speed data transfer to/from system memory and management of logical data structures. We describe its architecture, and then we present implementations in hardware as well as in software for embedded systems. We evaluate the implementations, demonstrating the performance improvement and the system scalability.
Dimitrios Serpanos, Panagiotis Karakonstantis
ISCC1
2000 Centralized versus distributed multimedia servers
abstract
The organization of multimedia servers is important in the design of low-cost high-performance multimedia application environments. Considering video services as highly demanding applications in a multimedia environment, we analyze and compare centralized and distributed architectures for multimedia video servers. Comparisons are made in terms of the blocking probability of a video client's request, considering as important parameters the input/output capacity of the system and the amount of storage. Through a combination of analytical results and simulations, we conclude that in general a centralized architecture is preferable. The results indicate, however that in a distributed architecture containing a large number of powerful servers, performance is similar to the centralized architecture under high load conditions, while the blocking probabilities are quite small under light load conditions. Furthermore, centralized and distributed server architectures become equivalent when large amounts of storage are added to the latter or when their input/output capacity is significantly increased. The results indicate that in many practical environments, factors other than performance, such as cost of management, security, and fault tolerance, will influence the choice for the appropriate server configuration.
Dimitrios Serpanos, Tasos Bouloutas
IEEE Trans. Circuits Syst. Video Technol.1
1998 Credit-Flow-Controlled ATM for MP Interconnection: The ATLAS I Single-Chip ATM Switch
abstract
Multiprocessing (MP) on networks of workstations (NOW) is a high-performance computing architecture of growing importance. In traditional MP's, wormhole routing interconnection networks use fixed-size flits and backpressure. In NOW's, ATM-one of the major contending interconnection technologies-uses fixed-size cells, while backpressure can be added to it. We argue that ATM with backpressure has interesting similarities with wormhole routing. We are implementing ATLAS I, a single-chip gigabit ATM switch, which includes credit flow control (backpressure), according to a protocol resembling Quantum Flow Control (QFC). We show by simulation that this protocol performs better than the traditional multi-lane wormhole protocol: high throughput and low latency are provided with less buffer space. Also, ATLAS I demonstrates little sensitivity to bursty traffic, and, unlike wormhole, it is fair in terms of latency in hot-spot configurations. We use detailed switch models, operating at clock-cycle granularity.
Manolis Katevenis, Dimitrios Serpanos, Emmanuel Spyridakis
HPCA2
1998 Credit scheduling: adaptive scheduling with dynamic service quota
Dimitrios Serpanos, Asser N. Tantawi, Ahmed N. Tantawy
Comput. Commun.1
1998 Average Case Analysis of Searching in Associative Processing
Panayotis E. Nastou, Dimitrios Serpanos, Dimitris G. Maritsas
J. Parallel Distributed Comput.2
1998 MMPacking: a load and storage balancing algorithm for distributed multimedia servers
abstract
In distributed multimedia servers where client requests for different video streams may have different probabilities, placement of video streams is an important parameter because it may result in unbalanced requests to the system's stations, and thus to high blocking probabilities of requests. We present a method, MMPacking, to balance traffic load and storage use in a distributed server environment. Since different video streams are requested by clients with different rates, video stream replication is used to balance the traffic patterns of the stations; thus, the requests and I/O usage of the stations are balanced, since replication allows requests for the same video stream to be routed to different stations. MMPacking achieves load balancing by producing at most N-1 replicas of video streams in a system with N servers. These replicas are distributed among the stations so that storage balancing is achieved as well, since no station stores more than two video streams more than any other station in the system.
Dimitrios Serpanos, Leonidas Georgiadis, Tasos Bouloutas
IEEE Trans. Circuits Syst. Video Technol.1
1996 MMPacking: A Load and Storage Balancing Algorithm for Distributed Multimedia Servers
abstract
In distributed multimedia servers where client requests for different video streams may have different probabilities, placement of video streams is an important parameter, because it may result in unbalanced requests to the system's stations, and thus to high blocking probabilities of requests. We present a method, MMPacking, to balance traffic load and storage use in a distributed server environment. Since different video screams are requested by clients with different rates, video stream replication is used to balance the traffic patterns of the stations; thus, the requests and I/O usage of the stations is balanced, since replication allows requests for the same video stream to be routed to different stations. MMPacking achieves load balancing by producing at most N-1 replicas of video streams in a system with N servers. These replicas are distributed among the stations, so that storage balancing is achieved as well, since no station stores more than 2 video streams than any other station in the system.
Dimitrios Serpanos, Leonidas Georgiadis, Tasos Bouloutas
ICCD1
1994 Two-dimensional round-robin schedulers for packet switches with multiple input queues
abstract
Presents a new scheduler, the two-dimensional round-robin (2DRR) scheduler, that provides high throughput and fair access in a packet switch that uses multiple input queues. We consider an architecture in which each input port maintains a separate queue for each output. In an N/spl times/N switch, our scheduler determines which of the queues in the total of N/sup 2/ input queues are served during each time slot. We demonstrate the fairness properties of the 2DRR scheduler and compare its performance with that of the input and output queueing configurations, showing that our scheme achieves the same saturation throughput as output queueing. The 2DRR scheduler can be implemented using simple logic components, thereby allowing a very high-speed implementation.>
Richard O. LaMaire, Dimitrios Serpanos
IEEE/ACM Trans. Netw.2
1994 A high performance transparent bridge
abstract
The high performance transparent bridge (HPTB) is a multiport bridge interconnecting gigabit networks. The provision of specialized hardware support coupled with proper partitioning of bridging protocol entities makes it possible to process frames at very high rates. The HPTB architecture allows concurrent bridging of asynchronous, synchronous and isochronous traffic among heterogeneous networks. It supports both traditional networks, such as variable packet size local area networks (LANs), and cell-based net works, such as distributed queue dual bus (DQDB) and metropolitan area networks (MANs). This device is capable of interconnecting any combination of high speed LANs of rates up to 800 Mbps and/or MANs of rates up to 622 Mbps.>
Martina Zitterbart, Ahmed N. Tantawy, Dimitrios Serpanos
IEEE/ACM Trans. Netw.3
1992 An Adaptive Scheduling Scheme for Dynamic Service Time Allocation on a Shared Resource
abstract
A scheduling scheme that allows a number of customers to share a common resource in an efficient and fair way is presented. Each customer is allowed to use the resource for an amount of time that does not exceed a certain limit, the limit being a function of the waiting time elapsed between the time of its last request and the time of access to the resource. After expiration of the service time allocated to a customer, if more service is still needed, the customer has to re-enter the request queue and issue a new service request. The scheme combines the advantages of both processor-sharing and first-come, first-served disciplines in a dynamic way. The applicability and the advantages of the scheme in both open and closed system environments are discussed.>
Ahmed N. Tantawy, Asser N. Tantawi, Dimitrios Serpanos
ICDCS3
1990 Uniform-Cost Communication in Scalable Multiprocessors
Richard J. Lipton, Dimitrios Serpanos
ICPP (1)2