Christian Müller 0015

dblp:50/5380-15 · DBLP profile ↗
← Back
5ranked-venue papers
0as first author
2since 2021 · last 2024
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 2 since 2021
YearPublicationVenuePosition
2024 Towards a Cryptographic Model for Wireless Communication
abstract
The Man-in-the-Middle Model (MitMM) is commonly used in cryptography for modeling an attacker in multiparty scenarios.It essentially assumes that the attacker fully controls the communication between all parties, i. e., can stop and modify messages at her discretion.We argue that this model is too strong for realistically capturing the case of wireless communication.In consequence, schemes that exploit properties of wireless communication such as friendly jamming or distance bounding, cannot be analyzed in a common framework.Moreover, the lack of an appropriate model hinders the development of new schemes.Given the ever-increasing importance of wireless communication, e. g., in the context of the Internet of Things, we propose a new formal model for wireless communication.Starting from the formal MitMM, we identify three key aspects -communication channels, signals, and locality -that are not represented, explain how to extend the model accordingly, and propose a tailored WCM.Based thereon, we explain how these limit the capabilities of an attacker in the form of a WAM.Moreover, we demonstrate for an existing security mechanism, namely friendly jamming, which is not covered by the MitMM how the new model allows for analyzing/formalizing the security.
Frederik Armknecht, Christian Müller 0015
SECRYPT2
2022 If You Like Me, Please Don't "Like" Me: Inferring Vendor Bitcoin Addresses From Positive Reviews
abstract
Abstract Bitcoin and similar cryptocurrencies are becoming increasingly popular as a payment method in both legitimate and illegitimate online markets. Such markets usually deploy a review system that allows users to rate their purchases and help others to determine reliable vendors. Consequently, vendors are interested into accumulating as many positive reviews (likes) as possible and to make these public. However, we present an attack that exploits these publicly available information to identify cryptocurrency addresses potentially belonging to vendors. In its basic variant, it focuses on vendors that reuse their addresses. We also show an extended variant that copes with the case that addresses are used only once. We demonstrate the applicability of the attack by modeling Bitcoin transactions based on vendor reviews of two separate darknet markets and retrieve matching transactions from the blockchain. By doing so, we can identify Bitcoin addresses likely belonging to darknet market vendors.
Jochen Schäfer, Christian Müller 0015, Frederik Armknecht
Proc. Priv. Enhancing Technol.2
2019 Privacy implications of room climate data
abstract
Smart heating applications promise to increase energy efficiency and comfort by collecting and processing room climate data. While it has been suspected that the sensed data may leak crucial personal information about the occupants, this belief has up until now not been supported by evidence. In this work, we investigate privacy risks arising from the collection of room climate measurements. We assume that an attacker has access to the most basic measurements only: temperature and relative humidity. We train machine learning classifiers to predict the presence and number of room occupants and to discriminate between different types of activities. On data that was collected at three different locations, we show that occupancy can be detected from data measured by a single sensor with up to [Formula: see text] accuracy. One can even distinguish between the cases that no, one, or two persons are present with up to [Formula: see text] accuracy. Moreover, the four actions reading, working on a PC, standing, and walking, can be discriminated with up to [Formula: see text] accuracy, which is likewise clearly better than guessing ([Formula: see text]). Constraining the set of actions allows to achieve even higher prediction rates. For example, we discriminate standing and walking occupants with [Formula: see text] accuracy. In addition, we show that the accuracy can be increased in most cases if an attacker has access to measurements from two different sensors located in the same room. Our results provide evidence that even the leakage of such ‘inconspicuous’ data as temperature and relative humidity can seriously violate privacy.
Frederik Armknecht, Zinaida Benenson, Philipp Morgner, Christian Müller 0015, Christian Riess
J. Comput. Secur.4
2017 Privacy Implications of Room Climate Data
Philipp Morgner, Christian Müller 0015, Matthias Ring, Björn M. Eskofier, Christian Riess, Frederik Armknecht, Zinaida Benenson
ESORICS (2)2
2017 Insecure to the touch: attacking ZigBee 3.0 via touchlink commissioning
abstract
Hundred millions of Internet of Things devices implement ZigBee, a low-power mesh network standard, and the number is expected to be growing. To facilitate an easy integration of new devices into a ZigBee network, touchlink commissioning was developed. It was adopted in the latest specifications, ZigBee 3.0, which were released to the public in December 2016, as one of two commissioning options for ZigBee devices. ZigBee 3.0 products can be used in various applications, also including security-critical products such as door locks and intruder alarm systems. The aim of this work is to warn about a further adoption of this commissioning mode. We analyze the security of touchlink commissioning procedure and present novel attacks that make direct use of standard's features, showing that this commissioning procedure is insecure by design. We release an open-source penetration testing framework to evaluate the practical implications of these vulnerabilities. Evaluating our tools on popular ZigBee-certified products, we demonstrate that a passive eavesdropper can extract key material from a distance of 130 meters. Furthermore, an active attacker is able to take-over devices from distances of 190 meters. Our analysis concludes that even a single touchlink-enabled device is sufficient to compromise the security of a ZigBee 3.0 network, and therefore, touchlink commissioning should not be supported in any future ZigBee products.
Philipp Morgner, Stephan Mattejat, Zinaida Benenson, Christian Müller 0015, Frederik Armknecht
WISEC4