VLDB 2026 Research / reviewers in the wild / expert
Lukas Malina
dblp:48/10327
· DBLP profile ↗
38ranked-venue papers
12as first author
16since 2021 · last 2026
0000-0002-7208-2514ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 35 · 11 first-author · 15 since 2021Computer networks · 2 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SoK: Reassessing Side-Channel Vulnerabilities and Countermeasures in PQC ImplementationsabstractPost-Quantum Cryptography (PQC) algorithms should remain secure even in the presence of quantum computers. Although the security of such schemes is guaranteed at the algorithmic level, real-world implementations often suffer from other vulnerabilities like Side-Channel Analysis (SCA) attacks. This Systematization of Knowledge (SoK) paper investigates SCA attacks targeting implementations of PQC algorithms. This work categorizes attacks from an adversarial perspective to identify the most vulnerable components of the algorithms' implementations and highlights unexplored parts in current implementations. In addition, it reviews and analyzes the efficiency and efficacy of existing countermeasures to SCA attacks in current hardware implementations. This approach helps identify countermeasures that provide broader protection and highlights characteristics needed for future secure implementations. Our findings offer guidance in strengthening existing systems and developing more efficient defenses against side-channel attacks. Patrik Dobias, Azade Rezaeezade, Lejla Batina, Lukasz Chmielewski, Lukas Malina |
AsiaCCS | 5 |
| 2024 | Quantum-Resistant and Secure MQTT CommunicationabstractIn this paper, we deal with the deployment of Post-Quantum Cryptography (PQC) in Internet of Things (IoT). Concretely, we focus on the MQTT (Message Queuing Telemetry Transport) protocol that is widely used in IoT services. The paper presents our novel quantum-resistant security proposal for the MQTT protocol that supports secure broadcast. Our solution omits using TLS with the handshake causing delay and is suitable for sending irregular short messages. Finally, we show how our solution can practically affect concrete use cases by the performance results of the proposed solution. Lukas Malina, Patrik Dobias, Petr Dzurenda, Gautam Srivastava 0001 |
ARES | 1 |
| 2024 | Secure and Privacy-Preserving Car-Sharing SystemsabstractWith increasing smart transportation systems and services, potential security and privacy threats are growing. In this work, we analyze privacy and security threats in car-sharing systems, and discuss the problems with the transparency of services, users’ personal data collection, and how the legislation manages these issues. Based on analyzed requirements, we design a compact privacy-preserving solution for car-sharing systems. Our proposal combines digital signature schemes and group signature schemes, in order to protect user privacy against curious providers, increase security and non-repudiation, and be efficient even for systems with restricted devices. The evaluation of the proposed solution demonstrates its security and a practical usability for constrained devices deployed in vehicles and users’ smartphones. Lukas Malina, Petr Dzurenda, Norbert Lövinger, Ijeoma Faustina Ekeh, Raimundas Matulevicius |
ARES | 1 |
| 2024 | Comparison of Multiple Feature Selection Techniques for Machine Learning-Based Detection of IoT AttacksabstractThe Internet of Things (IoT) has become increasingly practical in applications such as smart homes, autonomous vehicles, and environmental monitoring. However, this rapid expansion has led to significant cybersecurity threats. Detecting these threats is critical, and while machine learning techniques are valuable, they struggle with high-dimensional data. Feature selection helps by reducing computational costs while maintaining model generalization. Selecting the most effective feature selection method is a crucial task. This research addresses this gap by testing five feature selection methods: Random Forest (RF), Recursive Feature Elimination (RFE), Logistic Regression (LR), XGBoost Regression (XGBoost), and Information Gain (IG) using the CIC-IoT 2023 dataset. It evaluates these methods when being used with five machine learning models: Decision Tree (DT), Random Forest (RF), k-Nearest Neighbors (k-NN), Gradient Boosting (GB), and Multi-layer Perceptron (MLP) using metrics like accuracy, precision, recall, and F1-score across three datasets. The results show that RFE, especially with the RF model, achieves the highest accuracy (99.57%) with 30 features. RF is the most stable, with accuracy from 83% to 99.56%. Additionally, the 5-feature scheme is best for implementing IDS on resource-limited IoT devices, with RFE paired with the k-NN model being the optimal combination. Viet Anh Phan, Jan Jerabek, Lukas Malina |
ARES | 3 |
| 2024 | Lattice-based Multisignature Optimization for RAM Constrained DevicesabstractIn the era of growing threats posed by the development of quantum computers, ensuring the security of electronic services has become fundamental. The ongoing standardization process led by the National Institute of Standards and Technology (NIST) emphasizes the necessity for quantum-resistant security measures. However, the implementation of Post-Quantum Cryptographic (PQC) schemes, including advanced schemes such as threshold signatures, faces challenges due to their large key sizes and high computational complexity, particularly on constrained devices. This paper introduces two microcontroller-tailored optimization approaches, focusing on enhancing the DS2 threshold signature scheme. These optimizations aim to reduce memory consumption while maintaining security strength, specifically enabling the implementation of DS2 on microcontrollers with only 192 KB of RAM. Experimental results and security analysis demonstrate the efficacy and practicality of our solution, facilitating the deployment of DS2 threshold signatures on resource-constrained microcontrollers. Sara Ricci, Vladyslav Shapoval, Petr Dzurenda, Peter B. Rønne, Jan Oupický, Lukas Malina |
ARES | 6 |
| 2024 | Open-Source Post-Quantum Encryptor: Design, Implementation and DeploymentabstractThis article describes an open-source quantum-resistant network traffic encryptor for the Linux platform. Our encryptor uses a combination of quantum and post-quantum key establishment methods to achieve quantum resistance combined with a fast encryption speed of AES to make quantum-resistant encryption readily available to the public. The packet-by-packet encryption architecture ensures that every bit of information is properly authenticated and encrypted. The combination of multiple key sources further increases the encryptor’s security – be it elliptic curve-based (Elliptic Curve Diffie Hellman, ECDH), quantum (Quantum Key Distribution, QKD) or post-quantum (CRYSTALS-Kyber). Without knowing all the keys obtained from different types of key sources, the final hybrid encryption key can only be obtained by brute-force means. Our contribution is very practical as the encryptor has reasonable performance, despite not being part of the Linux kernel. Petr Tuma 0004, Jan Hajny, Petr Muzikant, Jan Havlin, Lukas Malina, Patrik Dobias, Jan Willemson |
SECRYPT | 5 |
| 2023 | On Efficiency and Usability of Group Signatures on Smartphone and Single-board PlatformsabstractWith increasing digitalization and omnipresent data sensing, security and users’ privacy become essential requirements in new digital services. Group Signatures (GS) or also known as Anonymous Digital Signatures (ADS) are often used as a core Privacy-Enhancing Technology (PET) in order to keep users’ privacy during their access and/or authentication phases within ensuring the security of provided services. In this work, we provide a comprehensive assessment of group signatures on various small computing platforms typically used in modern digital services. Based on our analysis of well-established GS schemes and their libraries, we implement and evaluate chosen schemes on both well-known smartphone platforms (i.e., Android, iOS) and on a single-board computer. Our results indicate that current handheld devices can already effectively perform main group signatures’ phases and make these schemes practical for deployment in various privacy-requiring scenarios. Patrik Dobias, Lukas Malina, Petr Ilgner, Petr Dzurenda |
ARES | 2 |
| 2023 | On Deploying Quantum-Resistant Cybersecurity in Intelligent InfrastructuresabstractAs quantum-safe algorithms are increasingly implemented in security protocols used in current and emerging digital services, there is also a corresponding need to map the current state of security protocols and applications and their preparedness for the post-quantum era. In this paper, we review current security recommendations, existing security libraries, and the support of Post-Quantum Cryptography (PQC) in widely-used security protocols. We also present a practical assessment of recently selected PQC algorithms by the National Institute of Standards and Technologies (NIST) PQC standardization on typical platforms that can be deployed in intelligent infrastructures (e.g., smartphones and single-boards), and recently recommended hash-based signatures for software/firmware signing. Finally, we discuss how incoming post-quantum migration affects selected areas in intelligent infrastructures. Lukas Malina, Patrik Dobias, Jan Hajny, Kim-Kwang Raymond Choo |
ARES | 1 |
| 2023 | Lattice-Based Threshold Signature Implementation for Constrained DevicesabstractThreshold signatures have gained increased attention especially due to their recent applications in blockchain technologies. In fact, current cryptocurrencies such as Bitcoin, and Cardano started to support multi-signature transactions. Even if the Schnorr-based threshold signatures improve the blockchain's privacy and scalability, these schemes do not provide post-quantum security. In this paper, we propose the optimization of the DS2 lattice-based $(n,n)$-threshold signature scheme and present its practical implementation. Moreover, we evaluate our optimized implementation of the DS2 scheme on different platforms. The results demonstrate that our implementation is easily portable and executable on constrained devices based on ARM Cortex-A53, ARM Cortex-M3, and ESP32 architectures. Patrik Dobias, Sara Ricci, Petr Dzurenda, Lukas Malina, Nikita Snetkov |
SECRYPT | 4 |
| 2023 | Optimized Security Algorithms for Intelligent and Autonomous Vehicular Transportation SystemsabstractWith the growth of the Internet of Vehicles (IoV) in Intelligent Autonomous Transport Systems (IATS), a huge volume of data is exchanged between vehicles in these newly developed infrastructures. As a result, the requirements of securing data exchange between vehicles, autonomous or otherwise, have also increased tremendously. Securing data transfer and keeping a record of each transaction becomes a necessity in IoV/IATS. In this paper, we propose some optimized security algorithms using symmetric encryption for secure multimedia data transfer between vehicles. The main feature of these optimized algorithms is that they use a lower amount of data to generate fingerprints. The algorithms convert approximately$3.7 \times 10^{5}$samples of data into 3600 samples to generate the fingerprint. Fast Fourier Transform (FFT) is used to fetch the highest three peak values of the signal in the frequency domain. A centralized server authenticates the data transfer by comparing the$HASH$of the fingerprints and also keeps the transaction record. Through experimental analysis, the performance of proposed algorithms is confirmed by achieving reduced size samples to generate fingerprints and their authentication at the server-side. Mohsin Kamal, Muhammad Tariq 0001, Gautam Srivastava 0001, Lukas Malina |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2022 | Real-world Deployment of Privacy-Enhancing Authentication System using Attribute-based CredentialsabstractWith the daily increase in digitalization and integration of the physical and digital worlds, we need to better protect users’ privacy and identity. Attribute-based Credentials (ABCs) seem to be a promising technology for this task. In this paper, we provide comprehensive analyses of the readiness, maturity, and applicability of ABCs to real-world applications. Furthermore, we introduce our Privacy-Enhancing Authentication System (PEAS), which is based on ABCs and meets all privacy requirements such as anonymity and unlinkability of the user’s activities. Besides privacy features, PEAS also provides revocation mechanisms to identify and revoke malicious users. The system is suitable for deployment in real-world scenarios and runs on a wide range of user devices (e.g., smart cards, smartphones, and wearables). Petr Dzurenda, Raúl Casanova Marqués, Lukas Malina |
ARES | 3 |
| 2022 | On Secure and Side-Channel Resistant Hardware Implementations of Post-Quantum CryptographyabstractCurrently, many post-quantum cryptography schemes have been implemented on various hardware platforms in order to provide efficient solutions in cybersecurity services. As researchers and hardware developers focus primarily on designs providing small latency and requiring fewer hardware resources, their implementations could seldom omit protection techniques against various physical attacks. This paper studies potential attacks on the cryptography implementations that run on Field-Programmable Gate Array (FPGA) platforms. We mainly analyze how Post-Quantum Cryptography (PQC) implementations could be vulnerable on various platforms. Further, we aim at the FPGA-based implementations of National Institute of Standards and Technology (NIST)’s PQC competition finalists. Our study should present to developers the current overview of attacks and countermeasures that can be implemented on specific PQC schemes on FPGA platforms. Moreover, we present novel implementation of one universal countermeasure component and reveal additional resources that are needed. Petr Jedlicka, Lukas Malina, Tomas Gerlich, Zdenek Martinasek, Jan Hajny, Petr Socha |
ARES | 2 |
| 2022 | On the Efficiency and Security of Quantum-resistant Key Establishment Mechanisms on FPGA Platforms
Lukas Malina, Sara Ricci, Patrik Dobias, Petr Jedlicka, Jan Hajny, Kim-Kwang Raymond Choo |
SECRYPT | 1 |
| 2021 | Privacy-Preserving Online Parking Based on Smart ContractsabstractThis work presents a complex privacy-preserving solution based on attribute-based credentials and smart contract techniques for emerging parking services in city zones. Our system provides the full set of privacy-enhancing features such as anonymity, untraceability, and unlinkability of user parking registrations. Thanks to that it prevents the city and service providers from profiling and tracking the users (e.g., their movement). Furthermore, we involved smart contracts and the underlying decentralized Blockchain technology in payment and verification phases to prevent the presence of a single point of failure in those processes which can endanger the system’s security and availability. We provide the full cryptographic specification of the system, its security analysis, and the implementation results in this paper. Petr Dzurenda, Carles Angles-Tafalla, Sara Ricci, Lukas Malina |
ARES | 4 |
| 2021 | Implementing CRYSTALS-Dilithium Signature Scheme on FPGAsabstractIn July 2020, the lattice-based CRYSTALS-Dilithium digital signature scheme has been chosen as one of the three third-round finalists in the post-quantum cryptography standardization process by the National Institute of Standards and Technology (NIST). In this work, we present the first Very High Speed Integrated Circuit Hardware Description Language (VHDL) implementation of the CRYSTALS-Dilithium signature scheme for Field-Programmable Gate Arrays (FPGAs). Due to our parallelization-based design requiring only low numbers of cycles, running at high frequency and using reasonable amount of hardware resources on FPGA, our implementation is able to sign 15832 messages per second and verify 10524 signatures per second. In particular, the signing algorithm requires 68461 Look-Up Tables (LUTs), 86295 Flip-Flops (FFs), and the verification algorithm takes 61738 LUTs and 34963 FFs on Virtex 7 UltraScale+ FPGAs. In this article, experimental results for each Dilithium security level are provided and our VHDL-based implementation is compared with related High-Level Synthesis (HLS)-based implementations. Our solution is ca 114 times faster (in the signing algorithm) and requires less hardware resources. Sara Ricci, Lukas Malina, Petr Jedlicka, David Smékal, Jan Hajny, Peter Cíbik, Petr Dzurenda, Patrik Dobias |
ARES | 2 |
| 2021 | Towards CRYSTALS-Kyber VHDL ImplementationabstractKyber is one of the three finalists of the National Institute of Standards and Technology (NIST) post-quantum cryptography competition. This article presents an optimized Very High Speed Integrated Circuit Hardware Description Language (VHDL)-based implementation of the main components of the Kyber scheme, namely Number-Theoretic Transform (NTT) and Keccak. We focus specifically on NTT, Keccak and their derivatives since they largely determine Kyber's performance due to their wide involvement in each step of the scheme. Our high-speed implementation also takes into account the trade-off between the degree of parallelization and the resources utilization. The NTT component is more than 27\% faster than the state-of-the-art implementations. Furthermore, the optimization helps the algorithm to achieve 1 572 839 NTT operations per second. Sara Ricci, Petr Jedlicka, Peter Cíbik, Petr Dzurenda, Lukas Malina, Jan Hajny |
SECRYPT | 5 |
| 2019 | A Secure Publish/Subscribe Protocol for Internet of ThingsabstractThe basic concept behind the emergence of Internet of Things (IoT) is to connect as many objects to the Internet as possible in an attempt to make our lives better in some way. However, connecting everyday objects like your car or house to the Internet can open up major security concerns. In this paper, we present a novel security framework for the Message Queue Transport Telemetry (MQTT) protocol based on publish/subscribe messages in order to enhance secure and privacy-friendly Internet of Things services. MQTT has burst onto the IoT scene in recent years due to its lightweight design and ease of use implementation necessary for IoT. Our proposed solution provides 3 security levels. The first security level suits for lightweight data exchanges of non-tampered messages. The second security level enhances the privacy protection of data sources and data receivers. The third security level offers robust long-term security with mutual authentication for all parties. The security framework is based on light cryptographic schemes in order to be suitable for constrained and small devices that are widely used in various IoT use cases. Moreover, our solution is tailored to MQTT without using additional security overhead. Lukas Malina, Gautam Srivastava 0001, Petr Dzurenda, Jan Hajny, Radek Fujdiak |
ARES | 1 |
| 2019 | Energy Attack in LoRaWAN: Experimental ValidationabstractMyriads of new devices take their places around us every single day, making a decisive step towards bringing the concept of the Internet of Things (IoT) in reality. The Low Power Wide Area Networks (LPWANs) are today considered to be one of the most perspective connectivity enablers for the resource and traffic limited IoT. In this paper, we focus on one of the most widely used LPWAN technologies, named LoRaWAN. Departing from the traditional data-focused security attacks, in this study we investigate the robustness of LoRaWAN against energy (depletion) attacks. For many IoT devices, the energy is a limited and very valuable resource, and thus in the near future the device's energy may become the target of an intentional attack. Therefore, in the paper, we first define and discuss the possible energy attack vectors, and then experimentally validate the feasibility of an energy attack over one of these vectors. Our results decisively show that energy attacks in LoRaWAN are possible and may cause the affected device to lose a substantial amount of energy. Specifically, depending on the device's SF (Spreading Factor), the demonstrated attack increased the total energy consumption during a single communication event 36% to 576%. Importantly, the shown attack does not require the attacker to have any keys or other confidential data and can be carried against any LoRaWAN device. The presented results emphasize the importance of energy security for LPWANs in particular, and IoT in general. Konstantin Mikhaylov, Radek Fujdiak, Ari Pouttu, Miroslav Voznak, Lukas Malina, Petr Mlynek |
ARES | 5 |
| 2019 | A Privacy-Enhancing Framework for Internet of Things Services
Lukas Malina, Gautam Srivastava 0001, Petr Dzurenda, Jan Hajny, Sara Ricci |
NSS | 1 |
| 2018 | On Track of Sigfox Confidentiality with End-to-End EncryptionabstractThe last years brought many novel challenges for the Internet of Things (IoT). Low capital and operational expenditures, massive deployments of devices, reliability and security are among the most crucial ones. The recently introduced Low-power wide area (LPWA) technologies provide one possible way of addressing these challenges. In the current paper, we focus on one of the most mature LPWA technology, namely Sigfox. We provide a brief security assessment of this technology and highlight the main security imperfections. Notably, we also consider the recent changes introduced in the last revision of the Sigfox specification released in the fourth quarter of 2017. Importantly, this paper discusses the highlighted issues and compares three selected cryptographic encryption solutions (AES, ChaCha and OTP) in respect to the main IoT triad of performance, security and cost. We investigate the encryption solutions and characterize their energy consumption in a real-life implementation. The results herein presented are useful for understanding the cost of enabling security aspects and enable selecting the most efficient encryption protocol. Radek Fujdiak, Petr Blazek, Konstantin Mikhaylov, Lukas Malina, Petr Mlynek, Jiri Misurec, Vojtech Blazek |
ARES | 4 |
| 2018 | Secure and efficient two-factor zero-knowledge authentication solution for access control systems
Lukas Malina, Petr Dzurenda, Jan Hajny, Zdenek Martinasek |
Comput. Secur. | 1 |
| 2018 | Multidevice Authentication with Strong Privacy ProtectionabstractCard‐based physical access control systems are used by most people on a daily basis, for example, at work, in public transportation, or at hotels. Yet these systems have often very poor cryptographic protection. User identifiers and keys can be easily eavesdropped on and counterfeited. The privacy‐preserving features are almost missing in these systems. To improve this state, we propose a novel cryptographic scheme based on efficient zero‐knowledge proofs and Boneh‐Boyen signatures. The proposed scheme is provably secure and provides the full set of privacy‐enhancing features, that is, the anonymity, untraceability, and unlinkability of users. Furthermore, our scheme supports distributed multidevice authentication with multiple RFID (Radio‐Frequency IDentification) user devices. This feature is particularly important in applications for controlling access to dangerous sites where the presence of protective equipment is checked during each access control session. Besides the full cryptographic specification, we also show the results of our implementation on devices commonly used in access control applications, particularly the smart cards and embedded verification terminals. By avoiding costly operations on user devices, such as bilinear pairings, we were able to achieve times comparable to existing systems (around 500 ms), while providing significantly higher security, privacy protection, and features for RFID multidevice authentication. Jan Hajny, Petr Dzurenda, Lukas Malina |
Wirel. Commun. Mob. Comput. | 3 |
| 2017 | Performance Analysis and Comparison of Different Elliptic Curves on Smart CardsabstractElliptic curves are very often used in the cryptographic protocol design due to their memory efficiency and useful features, such as the bilinear pairing support. However, in many cryptographic papers, elliptic curves are used as a black box, without deeper consideration of their mathematical properties and, even more importantly, without considering implementation implications. As a consequence, novel cryptographic schemes are being published without any real chance of implementation on constrained devices due to their lack of support of basic EC operations like point addition or scalar point multiplication. This paper provides the necessary theoretical overview of main forms of elliptic curves, in particular considering their computational and memory complexity. Next, all major platforms of programmable smart cards are evaluated with respect to EC support and the performance of basic arithmetic operations is assessed using benchmarks. Finally, the evaluation of the implementations of ECC schemes, such as ECDH and ECDSA, is presented. Petr Dzurenda, Sara Ricci, Jan Hajny, Lukas Malina |
PST | 4 |
| 2017 | Anonymous Credentials with Practical Revocation using Elliptic Curves
Petr Dzurenda, Jan Hajny, Lukas Malina, Sara Ricci |
SECRYPT | 3 |
| 2016 | Multi-Device Authentication using Wearables and IoTabstractThe paper presents a novel cryptographic authentication scheme that makes use of the presence of electronic devices around users. The scheme makes authentication more secure by involving devices that are usually worn by users (such as smart-watches, fitness bracelets and smart-cards) or are in their proximity (such as sensors, home appliances, etc.). In our scheme, the user private key is distributed over all personal devices thus cannot be compromised by breaking into only a single device. Furthermore, involving wearables and IoT devices makes it possible to use multiple authentication factors, such as user's position, his behavior and the state of the surrounding environment. We provide the full cryptographic specification of the protocol, its formal security analysis and the implementation results in this paper. Jan Hajny, Petr Dzurenda, Lukas Malina |
SECRYPT | 3 |
| 2016 | On perspective of security and privacy-preserving solutions in the internet of things
Lukas Malina, Jan Hajny, Radek Fujdiak, Jiri Hosek |
Comput. Networks | 1 |
| 2016 | Light-weight group signatures with time-bound membershipabstractAbstract This paper presents a novel privacy‐preserving cryptographic protocol for secure many‐to‐one communication systems, for example, data collection systems, data gathering systems, vehicular networks, smart‐grids, and so on. The proposed solution provides message authenticity, integrity, and non‐repudiation, while message senders are anonymous and untraceable. The protocol is based on group signatures with a time‐bound membership. The protocol is designed to achieve efficiency on the client side where restricted devices are usually employed. On the other hand, the verification of many messages is efficient as well. Common group signature schemes offer the verification phase that needs some pairing operations and employs a long revocation list. Generally, the revocation list grows until scheme parameters and keys are recomputed. However, the reinitialization of all keys and parameters is not practical in large‐scale communication systems. By applying the optimization techniques on the group signature scheme, the verification phase becomes more efficient, and the expiration of group member secret keys naturally reduces the length of a revocation list. In addition to the full cryptographic description, we implement the proposed protocol and outline the performance results. Copyright © 2015 John Wiley & Sons, Ltd. Lukas Malina, Jan Hajny, Vaclav Zeman |
Secur. Commun. Networks | 1 |
| 2016 | Crucial pitfall of DPA Contest V4.2 implementationabstractAbstract Differential power analysis (DPA) is a powerful side‐channel key recovery attack that efficiently breaks cryptographic algorithm implementations. In order to prevent these types of attacks, hardware designers and software programmers make use of masking and hiding techniques. DPA contest is an international framework that allows researchers to compare their power analysis attacks under the same conditions. The latest version of DPA contest, denoted as V4.2, provides an improved implementation of the rotating S‐box masking scheme where low‐entropy boolean masking is combined with the shuffling technique to protect Advanced Encryption Standard implementation on a smart card. The improvements were designed based on the awareness of implementation lacks analyzed from attacks carried out during the previous DPA contest V4. Therefore, this new approach is devised to resist most of the proposed attacks to the original rotating S‐box masking implementation. In this paper, we investigate the security of this new implementation in practice. Our analysis, focused on exploiting the first‐order leakage, discovered important lacks. The main vulnerability observed is that an adversary can mount a standard DPA attack aimed at the S‐box output in order to recover the whole secret key even when a shuffling technique is used. We tested this observation on a public dataset and implemented a successful attack that revealed the secret key using only 35 power traces. Copyright © 2017 John Wiley & Sons, Ltd. Zdenek Martinasek, Félix Iglesias, Lukas Malina, Josef Martinasek |
Secur. Commun. Networks | 3 |
| 2015 | Privacy-Enhanced Data Collection Scheme for Smart-Metering
Jan Hajny, Petr Dzurenda, Lukas Malina |
Inscrypt | 3 |
| 2015 | Secure Physical Access Control with Strong Cryptographic ProtectionabstractThis paper is focused on the area of physical access control systems (PACs), particularly on the systems for building access control. We show how the application of modern cryptographic protocols, namely the cryptographic proofs of knowledge, can improve the security and privacy protection in practical access control systems. We propose a novel scheme SPAC (Secure Physical Access Control) based on modern cryptographic primitives. By employing the proofs of knowledge, the authentication process gets more secure and privacy friendly in comparison to existing schemes without negative influence on the implementation complexity or system performance. In this paper, we describe the weaknesses of existing schemes, show the full cryptographic specification of the novel SPAC scheme including its security proofs and provide benchmarks on off-the-shelf devices used in real commercial systems. Furthermore we show, that the transition from an old insecure system to strong authentication can be ea sy and cost-effective Jan Hajny, Petr Dzurenda, Lukas Malina |
SECRYPT | 3 |
| 2015 | Towards Secure Gigabit Passive Optical Networks - Signal Propagation based Key EstablishmentabstractNowadays, the Passive Optical Networks (PONs) technology is widely deployed in broadband access networks. This paper deals with the security issues of Gigabit PON (GPON) standardized by the International Telecommunications Union (ITU), namely, standard ITU-T G.984 that is widely implemented in Europe these days. We describe and analyze the security of this standard and show its security risks. In spite of that transmitted data are encrypted to provide their confidentiality on a multipoint fibre connection, session secret keys during their establishment can be observed by adversaries. To address this security flaw, we propose a key establishment protocol that securely sets the session secret keys between two communication parties in GPON. Furthermore, we provide the security analysis of the proposed protocol. Lukas Malina, Petr Munster, Jan Hajny, Tomás Horváth |
SECRYPT | 1 |
| 2015 | Attribute-based credentials with cryptographic collusion preventionabstractAbstract Cryptographic attribute‐based credentials (ABCs) allow users to prove their personal attributes remotely and in a privacy‐friendly way. While staying anonymous and untraceable, the users are able to prove their attributes, such as age, membership, or nationality, before using a network service. Unfortunately, there are very few practical cryptographic ABC schemes available today. Furthermore, some existing schemes rely on the hardware tamper‐resistance of smart cards to avoid collusion attacks. The trust in hardware limits the usage of such schemes on poorly protected cards and on smart phones. In this paper, we present the full cryptographic specification of an ABC scheme, which makes the collusion attacks impossible even on insecure hardware like mobile phones. Furthermore, the scheme provides features, which are difficult to achieve using existing schemes, namely the practical revocation of users, the de‐anonymization of malicious users, and the unlinkability of verification sessions. Besides the cryptographic architecture, we also present our practical implementation on a smart phone and embedded platforms. Copyright © 2015 John Wiley & Sons, Ltd. Jan Hajny, Petr Dzurenda, Lukas Malina |
Secur. Commun. Networks | 3 |
| 2014 | Privacy-preserving framework for geosocial applicationsabstractABSTRACT The paper deals with user privacy in geosocial applications. Geosocial applications have become very popular but can misuse user's private data and location. We propose a novel solution that prevents tracking and protects against personal identity and location being misused by external attackers or service providers. The proposed framework provides security and privacy protection for geosocial applications that provide, for example, information sharing, geotagging, and monitoring of people without revealing their identity to unauthorized persons, including the service provider. Unlike current security solutions in geosocial services, our novel framework uses advanced cryptography to secure user privacy. This protection is provided by advanced group signatures ensuring data integrity, authenticity, non‐repudiation, and strong privacy protection. The paper outputs a detailed cryptographic scheme for the protection of privacy in geosocial services and its security analysis. The proposed scheme has also been implemented, and the performance results are outlined in the paper. Copyright © 2013 John Wiley & Sons, Ltd. Lukas Malina, Jan Hajny |
Secur. Commun. Networks | 1 |
| 2013 | Optimization of Power Analysis Using Neural Network
Zdenek Martinasek, Jan Hajny, Lukas Malina |
CARDIS | 3 |
| 2013 | Privacy-preserving SVANETs - Privacy-preserving Simple Vehicular Ad-hoc Networks
Jan Hajny, Lukas Malina, Zdenek Martinasek, Vaclav Zeman |
SECRYPT | 2 |
| 2013 | Efficient Group Signatures with Verifier-local Revocation Employing a Natural Expiration
Lukas Malina, Jan Hajny, Zdenek Martinasek |
SECRYPT | 1 |
| 2012 | Unlinkable Attribute-Based Credentials with Practical Revocation on Smart-Cards
Jan Hajny, Lukas Malina |
CARDIS | 2 |
| 2011 | Practical Anonymous Authentication - Designing Anonymous Authentication for Everyday Use
Jan Hajny, Lukas Malina, Vaclav Zeman |
SECRYPT | 2 |