Stefan Katzenbeisser 0001

dblp:66/3585-1 · DBLP profile ↗
← Back
128ranked-venue papers
7as first author
24since 2021 · last 2025
0009-0005-3608-874XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 94 · 6 first-author · 11 since 2021Systems, architecture and hardware · 13 · 1 first-author · 8 since 2021Graphics, computer vision, multimedia, augmented reality and games · 6Computer networks · 5 · 1 since 2021Software engineering, systems software and programming languages · 4 · 2 since 2021Databases, data management, data science and information retrieval · 2Theory of computation · 2Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021
YearPublicationVenuePosition
2025 Towards Deterministic DDS Communication for Secure Service-Oriented Software-Defined Vehicles
Florian Frank 0004, Dominik Püllen, Alexandru Kampmann, Stefan Katzenbeisser 0001
ARES (1)4
2025 Towards a Holistic and Multi-modal Vehicle Security Monitoring
Ali Recai Yekta, Dominik Spychalski, Cenk Yekta, Markus Heinrich, Christoph Krauß, Stefan Katzenbeisser 0001
CRITIS6
2025 PUSH for Security: A PUF-Based Protocol to Prevent Session Hijacking
Emiliia Gelóczi, Nico Mexis, Stefan Katzenbeisser 0001
ESORICS (3)3
2025 Endless Subscriptions: Open RAN is Open to RIC E2 Subscription Denial of Service Attacks
abstract
Telecommunication services are essential in ensuring the operation of numerous critical infrastructures. While mobile network security increased with the advancement of generations, emerging concepts such as the Open Radio Access Network (O-RAN) are transforming the traditional operation of Radio Access Networks (RANs). Novel concepts and technologies are finding their way into RANs with a focus on softwareization and virtualization. This increases the overall attack surface and introduces new attack vectors not necessarily found in traditional RANs. This paper shows that Denial of Service (DoS) attacks leveraging subscription mechanisms can compromise O-RAN implementations. We present a novel DoS attack targeting the Near Real-Time (Near-RT) RAN Intelligent Controller (RIC). By deploying a malicious xApp, we demonstrate how an adversary can flood the Near-RT RIC with excessive subscription requests, leading to service disruption. This attack exploits the lack of rate-limiting mechanisms within the Service Model (SM), a critical component of the Near-RT RIC responsible for handling E2 subscription requests. We systematically evaluate various attack scenarios and investigate the underlying vulnerabilities exposed. Furthermore, we propose and assess countermeasures to safeguard publicly accessible O-RAN systems from such threats.
Felix Klement, Alessandro Brighente, Anup Kiran Bhattacharjee, Stefano Cecconello, Fernando A. Kuipers, Georgios Smaragdakis, Mauro Conti, Stefan Katzenbeisser 0001
EuroS&P8
2025 Non-Restrictive Hardware-Based Trust in Embedded High-Level Operating Systems
abstract
Hardware-based trust mechanisms are essential for securing embedded systems against physical and software attacks. Although restrictive approaches like verified boot enforce strict code integrity, they often limit device reusability and owner control. In contrast, non-restrictive methods, such as measured boot and remote attestation, assess system state without enforcing execution policies.We present a secure embedded high-level Operating System (OS) architecture that exclusively uses non-restrictive Trusted Platform Module (TPM)-based mechanisms to achieve secure storage, rollback protection, reliable updates, and remote attestation. Our design targets unattended devices like smart gateways or industrial Internet of Things (IoT) nodes, enabling maintainable and owner-controlled deployments.A key contribution is a scalable rollback protection mechanism based on TPM extend-indexes and Enhanced Authorization (EA), which avoids per-device policies and vendor lock-in. Combined with secure storage and remote attestation, our system protects application data against offline access, rollback, and replay attacks.We evaluated our prototype on real hardware, showing moderate performance overheads and strong security properties. We further identify limitations and outline future directions to improve policy management and reduce boot latency in TPM-based platforms.
Simon Unger, Sven Gebauer, Stefan Katzenbeisser 0001
TrustCom3
2025 Achieving Error-Free Lightweight Authentication With DRAM-Based Physical Unclonable Functions
abstract
In this article, we introduce a novel approach to achieving lightweight device authentication through the use of a low-complexity Convolutional Neural Network (CNN). In our work, we improve the False Authentication Rate (FAR) by transforming the standard CNN into a Bayesian CNN (BCNN or BNN). This transformation enables the use of probabilistic modelling techniques, increasing the model’s robustness and its confidence in authentication decisions. Regardless of the model used, clients authenticate with a retention-based Dynamic Random Access Memory Physical Unclonable Function (DRAM PUF) response. Our approach integrates the low computational complexity of the CNN with the intrinsic security characteristics of the DRAM PUF, offering a robust solution for lightweight and secure device authentication.
Nico Mexis, Nikolaos A. Anagnostopoulos, Stefan Katzenbeisser 0001, Elif Bilge Kavun, Sara Tehranipoor, Tolga Arul
IEEE Trans. Circuits Syst. I Regul. Pap.3
2024 Secure Data-Binding in FPGA-based Hardware Architectures utilizing PUFs
abstract
In this work, a novel FPGA-based data-binding architecture incorporating PUFs and a user-specific encryption key to protect the confidentiality of data on external non-volatile memories is presented. By utilizing an intrinsic PUF derived from the same memory, the confidential data is additionally bound to the device. This feature proves valuable in cases where software is restricted to be executed exclusively on specific hardware or privacy-critical data is not allowed to be decrypted elsewhere. To improve the resistance against hardware attacks, a novel method to randomly select memory cells utilized for PUF measurements is presented. The FPGA-based design presented in this work allows for low latency as well as small area utilization, offers high adaptability to diverse hardware and software platforms, and is accessible from bare-metal programs to full Linux kernels. Moreover, a detailed performance and security evaluation is conducted on five boards. A single read or write operation can be executed in 0.58 μs when utilizing the lightweight PRINCE cipher on an AMD Zync 7000 MPSoC. Furthermore, the entire architecture occupies only about 10% of the FPGA's available space on a resource-constrained AMD PYNQ-Z2. Ultimately, the implementation is demonstrated by storing confidential user data on new generations of network base stations equipped with FPGAs.
Florian Frank 0004, Felix Klement, Purushothaman Palani, Elif Bilge Kavun, Wenjie Xiong 0001, Tolga Arul, Stefan Katzenbeisser 0001
AsiaCCS9
2024 Investigation of Commercial Off-The-Shelf ReRAM Modules for Use as Runtime-Accessible TRNG
abstract
In this work, we analyse Commercial Off-The-Shelf (COTS) Resistive Random Access Memory (ReRAM) modules for their suitability to implement a novel runtime-accessible True Random Number Generator (TRNG). For this purpose, modules from two different manufacturers (Adesto Technologies and Fujitsu) were tested, which exhibited distinct characteristics under different conditions. If suitable parameters are selected, the proposed TRNG can successfully pass all the tests of both the NIST SP800-22 Statistical Test Suite and the NIST SP800-90B Entropy Source Test Suite at a wide range of temperatures. At the same time, the TRNG achieves a throughput of at least 28 bits per second under adverse temperature conditions and approximately 51 bits per second at room temperature, in the worst case. Therefore, the performance of the TRNG is sufficient for many practical applications such as security protocols for the Internet of Things (IoT) and in-vehicle networks [1], [2].
Tolga Arul, Nico Mexis, Aleena Elsa George, Florian Frank 0004, Nikolaos A. Anagnostopoulos, Stefan Katzenbeisser 0001
DSD6
2024 Securing the Open RAN Infrastructure: Exploring Vulnerabilities in Kubernetes Deployments
abstract
In this paper, we investigate the security implications of virtualized and software-based Open Radio Access Network (RAN) systems, specifically focusing on the architecture proposed by the O-RAN ALLIANCE and O-Cloud deployments based on the O-RAN Software Community (OSC) stack and infrastructure. Our key findings are based on a thorough security assessment and static scanning of the OSC Near Real-Time RAN Intelligent Controller (RIC) cluster. We highlight the presence of potential vulnerabilities and misconfigurations in the Kubernetes infrastructure supporting the RIC, also due to the usage of outdated versions of software packages, and provide an estimation of their criticality using various deployment auditing frameworks (e.g., MITRE ATT&CK and the NSA CISA). In addition, we propose methodologies to minimize these issues and harden the Open RAN virtualization infrastructure. These encompass the integration of security evaluation methods into the deployment process, implementing deployment hardening measures, and employing policy-based control for RAN components. We emphasize the need to address the problems found in order to improve the overall security of virtualized Open RAN systems.
Felix Klement, Alessandro Brighente, Michele Polese, Mauro Conti, Stefan Katzenbeisser 0001
NetSoft5
2024 Real-time Risk Assessment of Security Incidents for Autonomous Vehicles
abstract
The automotive industry undergoes significant advancements in terms of speed, processes, methods, and technology. A notable focus on autonomous driving gains widespread attention, leading various research groups to work on its development. The continuous development, especially with the introduction of digitization, expands the attack surface, emphasizing the need for enhanced vehicular security. Ongoing research efforts are dedicated to addressing and improving vehicular security in response to these challenges. Our study aims to respond to security incidents occurring during vehicle operation in real time and in real-world scenarios, with a particular focus on Electronic Control Units. We evaluate the performance of a recently proposed risk assessment scheme in terms of latency, scalability, and efficiency. Utilizing real-world datasets and randomly generated graphs with nodes ranging from 10 to 1,000,000, we assess how the performance of the scheme evolves. The study demonstrates the practical applicability of the risk assessment scheme in real time and real-world scenarios, as well as its adaptability across various hardware setups. Notably, our evaluation exceeds the average human reaction time threshold, with a response time of 0.24 seconds. Across a range of graph sizes, the average response time is 0.66 seconds. These findings validate the scheme’s applicability, offering rapid and efficient responses to security incidents.
Yaman Qendah, Dominik Püllen, Stefan Katzenbeisser 0001
VTC Fall3
2024 Toward Securing the 6G Transition: A Comprehensive Empirical Method to Analyze Threats in O-RAN Environments
abstract
In this paper, we present a new methodology that enables the MITRE ATT&CK framework to objectively assess specific threats in 6G Radio Access Networks (RANs). This helps address new security challenges that arise in the transition to open RANs. We analyze the O-Cloud component within the O-RAN ecosystem as a representative example, wherein no individual threat class demonstrates complete security. The inherent modularity of our approach ensures great adaptability and allows it to be applied to various other components within this system. This allows us to effectively detect and combat threats, thereby ensuring the resilience and security of future communication networks.
Felix Klement, Wuhao Liu, Stefan Katzenbeisser 0001
IEEE J. Sel. Areas Commun.3
2023 A Method to Construct Efficient Carbon-Nanotube-Based Physical Unclonable Functions and True Random Number Generators
abstract
In this work, we present a novel method of increasing the entropy of the CNT-PUF, a Physical Unclonable Function (PUF) based on Carbon-NanoTube Field Effect Transistors (CNT-FETs). The binary responses of this PUF are based on the drain current IDof each CNT-FET under the influence of a particular gate-source voltage VGS,which, through the employment of a single threshold value for ID,can indicate whether each relevant CNT cell of the array is conducting (acting either as a true conductor or as a semiconductor) or not (acting as an insulator). In this work, we propose the adoption of individual threshold values for each such cell as part of the relevant PUF challenge, thereby significantly increasing the overall entropy of this PUF, as well as the security that it can provide. Moreover, this method allows for the realisation of a source of higher entropy in the form of a True Random Number Generator (TRNG). Finally, we note that our work and its results are most probably also relevant for other CNT- based PUFs, structures, and primitives that utilise a single current (or even, voltage) threshold to determine the state of the different CNT cells utilised.
Nikolaos A. Anagnostopoulos, Nico Mexis, Simon Böttger, Martin Hartmann, Ali Wagdy Mohamed, Sascha Hermann, Stefan Katzenbeisser 0001, Stavros G. Stavrinides, Tolga Arul
DSD7
2023 Spatial Correlation in Weak Physical Unclonable Functions: A Comprehensive Overview
abstract
Physical Unclonable Functions (PUFs) are increasingly used in the process of securing applications. For this purpose, it is crucial that the PUF satisfies all the required properties adequately, including Unpredictability. An important aspect of Unpredictability is Randomness, which includes being free of spatial correlation effects. However, most methods for assessing randomness are not capable of detecting correlation, such that this aspect is often ignored. This work summarises the current literature to shed more light on the topic of analysing spatial correlation in weak PUFs, and evaluates the various methods proposed in the literature for detecting such effects. Additionally, the spatial correlation of a Dynamic Random Access Memory (DRAM) decay-based PUF implemented on the DRAM of a Raspberry Pi board, as well as that of a Carbon-NanoTube-based PUF (CNT-PUF), are examined, using, for the first time in the context of PUFs, not only other well-known metrics proposed in the relevant literature, but also the Getis-Ord G metric. Finally, a mitigation technique against attacks based on spatial auto-correlation is proposed and its effective application to PUF responses is discussed.
Nico Mexis, Tolga Arul, Nikolaos A. Anagnostopoulos, Florian Frank 0004, Simon Böttger, Martin Hartmann, Sascha Hermann, Elif Bilge Kavun, Stefan Katzenbeisser 0001
DSD9
2023 Keep your Enemies closer: On the minimal Distance of Adversaries when using Channel-based Key Extraction in SISO 6G Systems
abstract
We conduct a comprehensive analysis of Channel-based Key Extraction across various frequency ranges that have potential applications in the 6th generation mobile standard. Specifically, we examine the minimum distance required between an attacker and a legitimate entity to achieve secure key generation through channel measurement. By simulating various metrics across diverse configurations, we observe that in our generic model, the required distance for an attacker to attain sufficient channel correlation reduces as frequency increases. Consequently, an attacker must be within close proximity, mere centimeters away, from a legitimate node to acquire relevant information necessary for generating a potentially identical key.
Felix Klement, Shoya Takebuchi, Tolga Arul, Stefan Katzenbeisser 0001
WiMob4
2023 Abusing Commodity DRAMs in IoT Devices to Remotely Spy on Temperature
abstract
The ubiquity and pervasiveness of modern Internet of Things (IoT) devices opens up vast possibilities for novel applications, but simultaneously also allows spying on, and collecting data from, unsuspecting users to a previously unseen extent. This paper details a new attack form in this vein, in which the decay properties of widespread, off-the-shelf DRAM modules are exploited to accurately spy on the temperature in the vicinity of the DRAM-carrying device. Among others, this enables adversaries to remotely and purely digitally spy on personal behavior in users’ private homes, or to collect security-critical data in server farms, cloud storage centers, or commercial production lines. We demonstrate that our attack can be performed by merely compromising the software of an IoT device and does not require hardware modifications or physical access at attack time. It can achieve temperature resolutions of up to 0.5°C over a range of 0°C to 70°C in practice. The presented attack works in devices that do not have a dedicated temperature sensor on board; as the DRAM modules already present in the device are abused to spy on the temperature. To complete the work, the paper discusses practical attack scenarios as well as possible countermeasures against the new temperature-spying attacks.
Florian Frank 0004, Wenjie Xiong 0001, Nikolaos A. Anagnostopoulos, André Schaller, Tolga Arul, Farinaz Koushanfar, Stefan Katzenbeisser 0001, Ulrich Rührmair, Jakub Szefer
IEEE Trans. Inf. Forensics Secur.7
2022 Using Memristor Arrays as Physical Unclonable Functions
Florian Frank 0004, Tolga Arul, Nikolaos A. Anagnostopoulos, Stefan Katzenbeisser 0001
ESORICS (3)4
2022 Mainzelliste SecureEpiLinker (MainSEL): privacy-preserving record linkage using secure multi-party computation
abstract
MOTIVATION: Record Linkage has versatile applications in real-world data analysis contexts, where several datasets need to be linked on the record level in the absence of any exact identifier connecting related records. An example are medical databases of patients, spread across institutions, that have to be linked on personally identifiable entries like name, date of birth or ZIP code. At the same time, privacy laws may prohibit the exchange of this personally identifiable information (PII) across institutional boundaries, ruling out the outsourcing of the record linkage task to a trusted third party. We propose to employ privacy-preserving record linkage (PPRL) techniques that prevent, to various degrees, the leakage of PII while still allowing for the linkage of related records. RESULTS: We develop a framework for fault-tolerant PPRL using secure multi-party computation with the medical record keeping software Mainzelliste as the data source. Our solution does not rely on any trusted third party and all PII is guaranteed to not leak under common cryptographic security assumptions. Benchmarks show the feasibility of our approach in realistic networking settings: linkage of a patient record against a database of 10 000 records can be done in 48 s over a heavily delayed (100 ms) network connection, or 3.9 s with a low-latency connection. AVAILABILITY AND IMPLEMENTATION: The source code of the sMPC node is freely available on Github at https://github.com/medicalinformatics/SecureEpilinker subject to the AGPLv3 license. The source code of the modified Mainzelliste is available at https://github.com/medicalinformatics/MainzellisteSEL. SUPPLEMENTARY INFORMATION: Supplementary data are available at Bioinformatics online.
Sebastian Stammler, Tobias Kussel, Phillipp Schoppmann, Florian Stampe, Galina Tremper, Stefan Katzenbeisser 0001, Kay Hamacher, Martin Lablans
Bioinform.6
2022 Evaluation of Cache Attacks on Arm Processors and Secure Caches
abstract
Timing-based side and covert channels in processor caches continue to be a threat to modern computers. This work shows for the first time, a systematic, large-scale analysis of Arm devices and the detailed results of attacks the processors are vulnerable to. Compared to x86, Arm uses different architectures, microarchitectural implementations, cache replacement policies, etc., which affects how attacks can be launched, and how security testing for the vulnerabilities should be done. To evaluate security, this paper presents security benchmarks specifically developed for testing Arm processors and their caches. The benchmarks are evaluated with sensitivity tests, which examine how sensitive the benchmarks are to having a correct configuration in the testing phase. Further, to evaluate a large number of devices, this work leverages a novel approach of using a cloud-based Arm device testbed for architectural and security research on timing channels and runs the benchmarks on 34 different physical devices. In parallel, there has been much interest in secure caches to defend the various attacks. Consequently, this paper also investigates secure cache architectures using proposed benchmarks. Especially, this paper implements and evaluates secure PL and RF caches, showing the security of PL and RF caches, but also uncovers new weaknesses.
Shuwen Deng, Nikolay Matyunin, Wenjie Xiong 0001, Stefan Katzenbeisser 0001, Jakub Szefer
IEEE Trans. Computers4
2022 RESCUE: A Resilient and Secure Device-to-Device Communication Framework for Emergencies
abstract
During disasters, existing telecommunication infrastructures are often congested or even destroyed. In these situations, mobile devices can form a backup communication network for civilians and emergency services using disruption-tolerant networking (DTN) principles. Unfortunately, such distributed and resource-constrained networks are particularly susceptible to a wide range of attacks such as terrorists trying to cause more harm. In this article, we presentRESCUE, a resilient and secure device-to-device communication framework for emergency scenarios that provides comprehensive protection against common attacks.RESCUEfeatures a minimalistic DTN protocol that, by design, is secure against notable attacks such as routing manipulations, dropping, message manipulations, blackholing, or impersonation. To further protect against message flooding and Sybil attacks, we present a twofold mitigation technique. First, a mobile and distributed certificate infrastructure particularly tailored to the emergency use case hinders the adversarial use of multiple identities. Second, a message buffer management scheme significantly increases resilience against flooding attacks, even if they originate from multiple identities, without introducing additional overhead. Finally, we demonstrate the effectiveness ofRESCUEvia large-scale simulations in a synthetic as well as a realistic natural disaster scenario. Our simulation results show thatRESCUEachieves very good message delivery rates, even under flooding and Sybil attacks.
Milan Stute, Florian Kohnhäuser, Lars Baumgärtner, Lars Almon, Matthias Hollick, Stefan Katzenbeisser 0001, Bernd Freisleben
IEEE Trans. Dependable Secur. Comput.6
2021 Nano Security: From Nano-Electronics to Secure Systems
abstract
The field of computer hardware stands at the verge of a revolution driven by recent breakthroughs in emerging nanodevices. “Nano Security” is a new Priority Program recently approved by DFG, the German Research Council. This initial-stage project initiative at the crossroads of nano-electronics and hardware-oriented security includes 11 projects with a total of 23 Principal Investigators from 18 German institutions. It considers the interplay between security and nano-electronics, focusing on a dichotomy which emerging nano-devices (and their architectural implications) have on system security. The projects within the Priority Program consider both: potential security threats and vulnerabilities stemming from novel nano-electronics, and innovative approaches to establishing and improving system security based on nano-electronics. This paper provides an overview of the Priority Program's overall philosophy and discusses the scientific objectives of its individual projects.
Ilia Polian, Frank Altmann, Tolga Arul, Christian Boit, Ralf Brederlow, Lucas Davi, Rolf Drechsler, Nan Du 0004, Thomas Eisenbarth 0001, Tim Güneysu, Sascha Hermann, Matthias Hiller, Rainer Leupers, Farhad Merchant, Thomas Mussenbrock, Stefan Katzenbeisser 0001, Akash Kumar 0001, Wolfgang Kunz, Thomas Mikolajick, Vivek Pachauri, Jean-Pierre Seifert, Frank Sill, Jens Trommer
DATE16
2021 ISO/SAE 21434-Based Risk Assessment of Security Incidents in Automated Road Vehicles
Dominik Püllen, Jonas Liske, Stefan Katzenbeisser 0001
SAFECOMP3
2021 Improved Circuit Compilation for Hybrid MPC via Compiler Intermediate Representation
Daniel Demmler, Stefan Katzenbeisser 0001, Thomas Schneider 0003, Tom Schuster, Christian Weinert
SECRYPT2
2021 A Lightweight Architecture for Hardware-Based Security in the Emerging Era of Systems of Systems
abstract
In recent years, a new generation of the Internet of Things (IoT 2.0) is emerging, based on artificial intelligence, the blockchain technology, machine learning, and the constant consolidation of pre-existing systems and subsystems into larger systems. In this work, we construct and examine a proof-of-concept prototype of such a system of systems, which consists of heterogeneous commercial off-the-shelf components, and utilises diverse communication protocols. We recognise the inherent need for lightweight security in this context, and address it by employing a low-cost state-of-the-art security solution. Our solution is based on a novel hardware and software co-engineering paradigm, utilising well-known software-based cryptographic algorithms, in order to maximise the security potential of the hardware security primitive (a Physical Unclonable Function) that is used as a security anchor. The performance of the proposed security solution is evaluated, proving its suitability even for real-time applications. Additionally, the Dolev-Yao attacker model is considered in order to assess the resilience of our solution towards attacks against the confidentiality, integrity, and availability of the examined system of systems. In this way, it is confirmed that the proposed solution is able to address the emerging security challenges of the oncoming era of systems of systems.
Nico Mexis, Nikolaos A. Anagnostopoulos, Jan Bambach, Tolga Arul, Stefan Katzenbeisser 0001
ACM J. Emerg. Technol. Comput. Syst.6
2021 Leaking Information Through Cache LRU States in Commercial Processors and Secure Caches
abstract
The Least-Recently Used (LRU) cache replacement policy and its variants are widely deployed in modern processors. This article shows in detail that the LRU states of caches can be used to leak information: any access to a cache by a sender will modify the LRU state, and the receiver is able to observe this through a timing measurement. This article presents LRU timing-based channels both when the sender and the receiver have access to shared memory, e.g., shared library, and when they are separate processes without shared memory. In addition, the new LRU timing-based channels are demonstrated on both Intel and AMD processors in scenarios where the sender and the receiver are sharing the cache in both hyper-threaded setting and time-sliced setting. The transmission rates of the LRU channels can be up to 600 Kbps per cache set in the hyper-threaded setting. Different from the majority of existing cache channels which require the sender to trigger cache misses, the new LRU channels work with the sender only having cache hits, making the channel faster and stealthier. This article further discusses the effectiveness of the new LRU channels against a number of secure cache designs. Especially, the LRU channels are demonstrated to work against two representative secure caches, Partition-Locked (PL) cache and Random Fill (RF) cache, in the gem5 simulator, showing possible vulnerabilities in the secure cache designs in which the security of the replacement state is not protected properly.
Wenjie Xiong 0001, Stefan Katzenbeisser 0001, Jakub Szefer
IEEE Trans. Computers2
2020 Secure Two-Party Computation in a Quantum World
Niklas Büscher, Daniel Demmler, Nikolaos P. Karvelas, Stefan Katzenbeisser 0001, Juliane Krämer, Deevashwer Rathee, Thomas Schneider 0003, Patrick Struck
ACNS (1)4
2020 ASHES 2020: 4th Workshop on Attacks and Solutions in Hardware Security
Chip-Hong Chang, Stefan Katzenbeisser 0001, Ulrich Rührmair, Patrick Schaumont
CCS2
2020 Predicting Railway Signalling Commands Using Neural Networks for Anomaly Detection
Markus Heinrich, Dominik Renkel, Tolga Arul, Stefan Katzenbeisser 0001
SAFECOMP4
2020 Safety Meets Security: Using IEC 62443 for a Highly Automated Road Vehicle
Dominik Püllen, Nikolaos A. Anagnostopoulos, Tolga Arul, Stefan Katzenbeisser 0001
SAFECOMP4
2020 ELSA: efficient long-term secure storage of large datasets (full version) ∗
abstract
Abstract An increasing amount of information today is generated, exchanged, and stored digitally. This also includes long-lived and highly sensitive information (e.g., electronic health records, governmental documents) whose integrity and confidentiality must be protected over decades or even centuries. While there is a vast amount of cryptography-based data protection schemes, only few are designed for long-term protection. Recently, Braun et al. (AsiaCCS’17) proposed the first long-term protection scheme that provides renewable integrity protection and information-theoretic confidentiality protection. However, computation and storage costs of their scheme increase significantly with the number of stored data items. As a result, their scheme appears suitable only for protecting databases with a small number of relatively large data items, but unsuitable for databases that hold a large number of relatively small data items (e.g., medical record databases).In this work, we present a solution for efficient long-term integrity and confidentiality protection of large datasets consisting of relatively small data items. First, we construct a renewable vector commitment scheme that is information-theoretically hiding under selective decommitment. We then combine this scheme with renewable timestamps and information-theoretically secure secret sharing. The resulting solution requires only a single timestamp for protecting a dataset while the state of the art requires a number of timestamps linear in the number of data items. Furthermore, we extend the scheme, that supports a single client, to a multi-client setting. Subsequently, we characterize the arising challenges with respect to integrity and confidentiality and discuss how our multi-client scheme tackles them. We implemented our solution and measured its performance in a scenario where 9600 data items are aggregated, stored, protected, and verified over a time span of 80 years. Our measurements show that our new solution completes this evaluation scenario an order of magnitude faster than the state of the art.
Philipp Muth, Matthias Geihs, Tolga Arul, Johannes Buchmann 0001, Stefan Katzenbeisser 0001
EURASIP J. Inf. Secur.5
2020 In-Depth Evaluation of Redirect Tracking and Link Usage
abstract
Abstract In today’s web, information gathering on users’ online behavior takes a major role. Advertisers use different tracking techniques that invade users’ privacy by collecting data on their browsing activities and interests. To preventing this threat, various privacy tools are available that try to block third-party elements. However, there exist various tracking techniques that are not covered by those tools, such as redirect link tracking. Here, tracking is hidden in ordinary website links pointing to further content. By clicking those links, or by automatic URL redirects, the user is being redirected through a chain of potential tracking servers not visible to the user. In this scenario, the tracker collects valuable data about the content, topic, or user interests of the website. Additionally, the tracker sets not only thirdparty but also first-party tracking cookies which are far more difficult to block by browser settings and ad-block tools. Since the user is forced to follow the redirect, tracking is inevitable and a chain of (redirect) tracking servers gain more insights in the users’ behavior. In this work we present the first large scale study on the threat of redirect link tracking. By crawling the Alexa top 50k websites and following up to 34 page links, we recorded traces of HTTP requests from 1.2 million individual visits of websites as well as analyzed 108,435 redirect chains originating from links clicked on those websites. We evaluate the derived redirect network on its tracking ability and demonstrate that top trackers are able to identify the user on the most visited websites. We also show that 11.6% of the scanned websites use one of the top 100 redirectors which are able to store nonblocked first-party tracking cookies on users’ machines even when third-party cookies are disabled. Moreover, we present the effect of various browser cookie settings, resulting in a privacy loss even when using third-party blocking tools.
Martin Koop, Erik Tews, Stefan Katzenbeisser 0001
Proc. Priv. Enhancing Technol.3
2020 Software Protection Using Dynamic PUFs
abstract
Low-end computing devices are becoming increasingly ubiquitous, especially due to the widespread deployment of Internet-of-Things products. There is, however, much concern about sensitive data being processed on these low-end devices which have limited protection mechanisms in place. This paper proposes a Hardware-Entangled Software Protection (HESP) scheme that leverages hardware features to protect software code from malicious modification before or during run-time. It also enables implicit hardware authentication. Thus, the software will execute correctly only on an authorized device and if the timing of the software, e.g., control flow, was not changed through malicious modifications. The proposed ideas are based on the new concept of Dynamic Physically Unclonable Functions (PUFs). Dynamic PUFs have time-varying responses and can be used to tie the software execution to the timing of software and the physical properties of a hardware device. It is further combined with existing approaches for code self-checksumming, software obfuscation, and call graph and register value scrambling to create the HESP scheme. HESP is demonstrated on commodity, off-the-shelf computing devices, where a DRAM PUF is used as an instance of a Dynamic PUF. The protection scheme can be applied automatically to LLVM Intermediate Representation (IR) code through an AutoPatcher written in Python. For a sample program containing AES encryption and decryption routine, HESP introduces 48% execution time overhead and increases the binary file size by 32.5%, which is moderate compared to other schemes such as software obfuscation. It takes about 2.6 seconds on average for the tested programs to be patched and compiled through the modified compilation flow and scripts.
Wenjie Xiong 0001, André Schaller, Stefan Katzenbeisser 0001, Jakub Szefer
IEEE Trans. Inf. Forensics Secur.3
2020 Low-cost Security for Next-generation IoT Networks
abstract
In recent years, the ubiquitous nature of Internet-of-Things (IoT) applications as well as the pervasive character of next-generation communication protocols, such as the 5G technology, have become widely evident. In this work, we identify the need for low-cost security in current and next-generation IoT networks and address this demand through the implementation, testing, and validation of an intrinsic low-cost and low-overhead hardware-based security primitive within an inherent network component. In particular, an intrinsic Physical Unclonable Function (PUF) is implemented in the peripheral network module of a tri-band commercial off-the-shelf router. Subsequently, we demonstrate the robustness of this PUF to ambient temperature variations and to limited natural aging, and examine in detail its potential for securing the next generation of IoT networks and other applications. Finally, the security of the proposed PUF-based schemes is briefly assessed and discussed.
Nikolaos A. Anagnostopoulos, Saad Ahmad, Tolga Arul, Daniel Steinmetzer, Matthias Hollick, Stefan Katzenbeisser 0001
ACM Trans. Internet Techn.6
2019 Spying on Temperature using DRAM
abstract
Today's ubiquitous IoT devices make spying on, and collecting data from, unsuspecting users possible. This paper shows a new attack where DRAM modules, widely used in IoT devices, can be abused to measure the temperature in the vicinity of the device in order to spy on a user's behavior. Specifically, the temperature dependency of the DRAM decay is used as a proxy for user's behavior in the vicinity of the device. The attack can be performed remotely by only changing the software of an IoT device, without requiring hardware changes, and with a resolution reaching 0.5°C. Potential defenses to the temperature spying attack are presented in this paper as well.
Wenjie Xiong 0001, Nikolaos A. Anagnostopoulos, André Schaller, Stefan Katzenbeisser 0001, Jakub Szefer
DATE4
2019 Security in Autonomous Systems
abstract
Autonomous systems promise solutions to a wide range of technical and societal problems, and their use appears especially attractive in safety-critical domains, like transportation or factory automation. This paper focuses on an underestimated aspect of autonomous systems: their security implications. Many approaches to design traditional secure systems do not readily transfer to autonomous systems, due to their high complexity and exposure to a broad spectrum of threats. Moreover, autonomous systems are often designed to be extremely long-living, and any security solutions should anticipate future threats to some extent. This paper starts with an overview of security threats applicable to autonomous systems and today's countermeasures to address these threats. Then, two representative techniques are elucidated in more detail: the use of post-quantum cryptography to achieve secure communication, and remote attestation as one essential building block for platform security.
Stefan Katzenbeisser 0001, Ilia Polian, Francesco Regazzoni 0001, Marc Stöttinger
ETS1
2019 A Practical Attestation Protocol for Autonomous Embedded Systems
abstract
With the recent advent of the Internet of Things (IoT), embedded devices increasingly operate collaboratively in autonomous networks. A key technique to guard the secure and safe operation of connected embedded devices is remote attestation. It allows a third party, the verifier, to ensure the integrity of a remote device, the prover. Unfortunately, existing attestation protocols are impractical when applied in autonomous networks of embedded systems due to their limited scalability, performance, robustness, and security guarantees. In this work, we propose PASTA, a novel attestation protocol that is particularly suited for autonomous embedded systems. PASTA is the first that (i) enables many low-end prover devices to attest their integrity towards many potentially untrustworthy low-end verifier devices, (ii) is fully decentralized, thus, able to withstand network disruptions and arbitrary device outages, and (iii) is in addition to software attacks capable of detecting physical attacks in a much more robust way than any existing protocol. We implemented our protocol, conducted measurements, and simulated large networks. The results show that PASTA is practical on low-end embedded devices, scales to large networks with millions of devices, and improves robustness by multiple orders of magnitude compared with the best existing protocols.
Florian Kohnhäuser, Niklas Büscher, Stefan Katzenbeisser 0001
EuroS&P3
2019 Dynamic Physically Unclonable Functions
abstract
Physical variations in the manufacturing processes of electronic devices have been widely leveraged to design Physically Unclonable Functions (PUFs), which can be used for authentication and key storage. Existing PUFs are static, as their PUF responses remain the same regardless when the PUF is queried. Meanwhile, this paper presents the new concept of Dynamic PUFs, where the responses depend not only on the physical properties of the device but also on the timing of the PUF queries. One application of Dynamic PUFs is in dynamic software-hardware binding, where the control flow of the software can be tied to both the timing of the software and the physical properties of the hardware, in order to protect software execution. This paper presents a realization of Dynamic PUFs using DRAM modules. The evaluation is based on the decay-based DRAM PUFs, which can be realized today and were implemented on commodity devices for testing.
Wenjie Xiong 0001, André Schaller, Stefan Katzenbeisser 0001, Jakub Szefer
ACM Great Lakes Symposium on VLSI3
2019 Vibrational Covert Channels using Low-Frequency Acoustic Signals
abstract
In this paper, we examine how acoustic signals in sub-bass and infrasonic range can be used to establish a vibrational covert channel between speaker-equipped computers and mobile devices. We show that typical consumer speakers are capable of producing low-frequency sounds, which are not perceivable by humans. At the same time, we show that producing such sounds by the speaker's woofer inevitably generates slight vibrations of the speaker and the surface where it is located. Being unnoticeable to people, such vibrations can be captured by the accelerometer sensor of a mobile device located on the same surface. Therefore, information can be encoded into low-frequency sounds played by a speaker and received on a mobile device by analyzing the produced vibrations. Note that access to the accelerometer on modern mobile devices does not require any user permissions, making the transmission completely unnoticeable. We evaluate the presented covert channel for different speakers, apply it to several application scenarios, and give an overview of possible countermeasures.
Nikolay Matyunin, Stefan Katzenbeisser 0001
IH&MMSec3
2019 On (The Lack Of) Location Privacy in Crowdsourcing Applications
Spyros Boukoros, Mathias Humbert, Stefan Katzenbeisser 0001, Carmela Troncoso
USENIX Security Symposium3
2019 Long-term integrity protection of genomic data
abstract
Abstract Genomic data is crucial in the understanding of many diseases and for the guidance of medical treatments. Pharmacogenomics and cancer genomics are just two areas in precision medicine of rapidly growing utilization. At the same time, whole-genome sequencing costs are plummeting below $ 1000, meaning that a rapid growth in full-genome data storage requirements is foreseeable. While privacy protection of genomic data is receiving growing attention, integrity protection of this long-lived and highly sensitive data much less so.We consider a scenario inspired by future pharmacogenomics, in which a patient’s genome data is stored over a long time period while random parts of it are periodically accessed by authorized parties such as doctors and clinicians. A protection scheme is described that preserves integrity of the genomic data in that scenario over a time horizon of 100 years. During such a long time period, cryptographic schemes will potentially break and therefore our scheme allows to update the integrity protection. Furthermore, integrity of parts of the genomic data can be verified without compromising the privacy of the remaining data. Finally, a performance evaluation and cost projection shows that privacy-preserving long-term integrity protection of genomic data is resource demanding, but in reach of current and future hardware technology and has negligible costs of storage.
Johannes Buchmann 0001, Matthias Geihs, Kay Hamacher, Stefan Katzenbeisser 0001, Sebastian Stammler
EURASIP J. Inf. Secur.4
2019 Private Evaluation of Decision Trees using Sublinear Cost
abstract
Abstract Decision trees are widespread machine learning models used for data classification and have many applications in areas such as healthcare, remote diagnostics, spam filtering, etc. In this paper, we address the problem of privately evaluating a decision tree on private data. In this scenario, the server holds a private decision tree model and the client wants to classify its private attribute vector using the server’s private model. The goal is to obtain the classification while preserving the privacy of both – the decision tree and the client input. After the computation, only the classification result is revealed to the client, while nothing is revealed to the server. Many existing protocols require a constant number of rounds. However, some of these protocols perform as many comparisons as there are decision nodes in the entire tree and others transform the whole plaintext decision tree into an oblivious program, resulting in higher communication costs. The main idea of our novel solution is to represent the tree as an array. Then we execute only d – the depth of the tree – comparisons. Each comparison is performed using a small garbled circuit, which output secret-shares of the index of the next node. We get the inputs to the comparison by obliviously indexing the tree and the attribute vector. We implement oblivious array indexing using either garbled circuits, Oblivious Transfer or Oblivious RAM (ORAM). Using ORAM, this results in the first protocol with sub-linear cost in the size of the tree. We implemented and evaluated our solution using the different array indexing procedures mentioned above. As a result, we are not only able to provide the first protocol with sublinear cost for large trees, but also reduce the communication cost for the large real-world data set “Spambase” from 18 MB to 1 [triangleright] 2 MB and the computation time from 17 seconds to less than 1 second in a LAN setting, compared to the best related work.
Anselme Tueno, Florian Kerschbaum, Stefan Katzenbeisser 0001
Proc. Priv. Enhancing Technol.3
2019 Security Requirements Engineering in Safety-Critical Railway Signalling Networks
abstract
Securing a safety-critical system is a challenging task, because safety requirements have to be considered alongside security controls. We report on our experience to develop a security architecture for railway signalling systems starting from the bare safety-critical system that requires protection. We use a threat-based approach to determine security risk acceptance criteria and derive security requirements. We discuss the executed process and make suggestions for improvements. Based on the security requirements, we develop a security architecture. The architecture is based on a hardware platform that provides the resources required for safety as well as security applications and is able to run these applications of mixed-criticality (safety-critical applications and other applications run on the same device). To achieve this, we apply the MILS approach, a separation-based high-assurance security architecture to simplify the safety case and security case of our approach. We describe the assurance requirements of the separation kernel subcomponent, which represents the key component of the MILS architecture. We further discuss the security measures of our architecture that are included to protect the safety-critical application from cyberattacks.
Markus Heinrich, Tsvetoslava Vateva-Gurova, Tolga Arul, Stefan Katzenbeisser 0001, Neeraj Suri, Henk Birkholz, Andreas Fuchs 0002, Christoph Krauß, Maria Zhdanova, Don Kuzhiyelil, Sergey Tverdyshev, Christian Schlehuber
Secur. Commun. Networks4
2019 Safety and Security Coengineering in Embedded Systems
abstract
Art. 5381856, 2 S.
Daniel Schneider 0001, Jens Braband, Erwin Schoitsch, Sascha Uhrig, Stefan Katzenbeisser 0001
Secur. Commun. Networks5
2019 Decay-Based DRAM PUFs in Commodity Devices
abstract
A Physically Unclonable Function (PUF) is a unique and stable physical characteristic of a piece of hardware, which emerges due to variations in the hardware fabrication processes. Prior works have demonstrated that PUFs are a promising cryptographic primitive that can enable secure key storage, hardware-based device authentication and identification. So far, most PUF constructions have required an addition of new hardware or an FPGA implementation for their operation. Recently, intrinsic PUFs, which can be found in commodity devices, have been investigated. Unfortunately, most of them suffer from the drawback that they can only be accessed at boot time. This paper focuses on a new class of run-time accessible, decay-based, intrinsic DRAM PUFs in commercial off-the-shelf systems, which requires no additional hardware or FPGAs. In order to enable secure key storage using DRAM PUFs, this work presents a new Helper Data System (HDS) specifically tailored to the properties of the decay process inherent to DRAM cells. The decay-based DRAM PUF and the new HDS are evaluated on commodity off-the-shelf devices to demonstrate their practicality. Furthermore, a novel lightweight protocol is presented that allows for mutual authentication.
André Schaller, Wenjie Xiong 0001, Nikolaos A. Anagnostopoulos, Muhammad Umair Saleem, Sebastian Gabmeyer, Boris Skoric, Stefan Katzenbeisser 0001, Jakub Szefer
IEEE Trans. Dependable Secur. Comput.7
2018 HyCC: Compilation of Hybrid Protocols for Practical Secure Computation
abstract
While secure multi-party computation (MPC) is a vibrant research topic and a multitude of practical MPC applications have been presented recently, their development is still a tedious task that requires expert knowledge. Previous works have made first steps in compiling high-level descriptions from various source descriptions into MPC protocols, but only looked at a limited set of protocols. In this work we present HyCC, a tool-chain for automated compilation of ANSI C programs into hybrid protocols that efficiently and securely combine multiple MPC protocols with optimizing compilation, scheduling, and partitioning. As a result, our compiled protocols are able to achieve performance numbers that are comparable to hand-built solutions. For the MiniONN neural network (Liu et al., CCS 2017), our compiler improves performance of the resulting protocol by more than a factor of $3$. Thus, for the first time, highly efficient hybrid MPC becomes accessible for developers without cryptographic background.
Niklas Büscher, Daniel Demmler, Stefan Katzenbeisser 0001, David Kretzmer, Thomas Schneider 0003
CCS3
2018 SALAD: Secure and Lightweight Attestation of Highly Dynamic and Disruptive Networks
abstract
Today, tiny embedded Internet of Things (IoT) devices are increasingly used in safety- and privacy-critical application scenarios. In many of these scenarios, devices perform a certain task collectively as a swarm. Remote attestation is an important cornerstone for the security of these IoT devices, as it allows to verify the integrity of the software on remote devices. Recently proposed collective attestation protocols are able to attest entire device swarms in an efficient way. However, these protocols are inefficient or even inapplicable when devices in the network are mobile or lack continuous connectivity. This work presents SALAD, the first collective attestation protocol for highly dynamic and disruptive networks. SALAD uses a novel distributed approach, where devices incrementally establish a common view on the integrity of all devices in the network. In contrast to existing protocols, SALAD performs well in highly dynamic and disruptive network topologies, increases resilience against targeted Denial of Service (DoS) attacks, and allows to obtain the attestation result from any device. Moreover, SALAD is capable of mitigating physical attacks in an efficient manner, which is achieved by adapting and extending recently proposed aggregation schemes. We demonstrate the security of SALAD and show its effectiveness by providing large-scale simulation results.
Florian Kohnhäuser, Niklas Büscher, Stefan Katzenbeisser 0001
AsiaCCS3
2018 Low-Temperature Data Remanence Attacks Against Intrinsic SRAM PUFs
abstract
In this work, we present the first systematic study of data remanence effects on an intrinsic Static Random Access Memory Physical Unclonable Function (SRAM PUF) implemented on a commercial off-the-shelf (COTS) device in the temperature range between –110 degrees Celsius and –40 degrees Celsius. Based on our experimental results, we propose a new type of attack against intrinsic SRAM PUFs, which takes advantage of data remanence effects exhibited due to low temperatures. We demonstrate that this attack is highly resistant to memory erasure techniques and can be used to manipulate the cryptographic keys produced by the SRAM PUF. Finally, we also discuss and assess potential countermeasures against the attack we propose.
Nikolaos A. Anagnostopoulos, Tolga Arul, Markus Rosenstihl, André Schaller, Sebastian Gabmeyer, Stefan Katzenbeisser 0001
DSD6
2018 Towards Practical RAM Based Secure Computation
Niklas Büscher, Alina Weber, Stefan Katzenbeisser 0001
ESORICS (2)3
2018 Security Analysis of the RaSTA Safety Protocol
abstract
RaSTA is a transport protocol that has been designed to be deployed in the safety-critical domain of railway signalling. The protocol provides safety properties such as message authenticity, integrity, timeliness, and sequence. However, critical railway infrastructures face cyber attacks and therefore require security measures. We investigate the security properties of RaSTA by analysing weaknesses of the utilized MD4 algorithm in the context where RaSTA is utilized. To overcome the weaknesses, we propose relevant enhancements to the protocol that maintain the safety properties and additionally provide secure message authentication. We evaluate our work using the computation time for message authentication which is crucial for the utilization of RaSTA in a safety-critical network.
Markus Heinrich, Jannik Vieten, Tolga Arul, Stefan Katzenbeisser 0001
ISI4
2018 Tracking Private Browsing Sessions using CPU-based Covert Channels
abstract
In this paper we examine the use of covert channels based on CPU load in order to achieve persistent user identification through browser sessions. In particular, we demonstrate that an HTML5 video, a GIF image, or CSS animations on a webpage can be used to force the CPU to produce a sequence of distinct load levels, even without JavaScript or any client-side code.
Nikolay Matyunin, Nikolaos A. Anagnostopoulos, Spyros Boukoros, Markus Heinrich, André Schaller, Maksim Kolinichenko, Stefan Katzenbeisser 0001
WISEC7
2018 Depreciating Motivation and Empirical Security Analysis of Chaos-Based Image and Video Encryption
abstract
Over the past years, an enormous variety of different chaos-based image and video encryption algorithms have been proposed and published. While any algorithm published undergoes some more or less strict experimental security analysis, many of those schemes are being broken in subsequent publications. In this paper, we show that two main motivations for preferring chaos-based image encryption over classical strong cryptographic encryption, namely computational effort and security benefits, are highly questionable. We demonstrate that several statistical tests, commonly used to assess the security of chaos-based encryption schemes, are insufficient metrics for security analysis. We do this experimentally by constructing obviously insecure encryption schemes and demonstrating that they perform well and/or pass several of these tests. In conclusion, these tests can only give a necessary, but by no means a sufficient condition for security. As a consequence of this paper, several security analyses in related work are questionable; further, methodologies for the security assessment for chaos based encryption schemes need to be entirely reconsidered.
Mario Preishuber, Thomas Hütter, Stefan Katzenbeisser 0001, Andreas Uhl
IEEE Trans. Inf. Forensics Secur.3
2018 Eliminating Leakage in Reverse Fuzzy Extractors
abstract
In recent years, physically unclonable functions (PUFs) have been proposed as a promising building block for key storage and device authentication. PUFs are physical systems, and as such, their responses are inherently noisy, precluding a straightforward derivation of cryptographic key material from raw PUF measurements. To overcome this drawback, fuzzy extractors are used to eliminate the noise and guarantee robust outputs. A special type is reverse fuzzy extractors, shifting the computational load of error correction toward a computationally powerful verifier. However, the reverse fuzzy extractor reveals error patterns to any eavesdropper, which may cause privacy issues (due to a systematic drift of the PUF responses, the error pattern is linkable to the identity) and even security problems (if the noise is data-dependent). In this paper, we quantify the issue of leakage due to asymmetry of noise, leveraging the binary asymmetric channel (BAC) model. We further propose to concatenate two BACs to form a symmetric channel, as a solution that is able to eliminate such noise. Finally, we propose a modified reverse fuzzy extractor that does not leak via the error patterns even in the case of systematic drift of the PUF responses.
André Schaller, Taras Stanko, Boris Skoric, Stefan Katzenbeisser 0001
IEEE Trans. Inf. Forensics Secur.4
2017 Measuring privacy in high dimensional microdata collections
abstract
Microdata is collected by companies in order to enhance their quality of service as well as the accuracy of their recommendation systems. These data often become publicly available after they have been sanitized. Recent reidentification attacks on publicly available, sanitized datasets illustrate the privacy risks involved in microdata collections. Currently, users have to trust the provider that their data will be safe in case data is published or if a privacy breach occurs. In this work, we empower users by developing a novel, user-centric tool for privacy measurement and a new lightweight privacy metric. The goal of our tool is to estimate users' privacy level prior to sharing their data with a provider. Hence, users can consciously decide whether to contribute their data. Our tool estimates an individuals' privacy level based on published popularity statistics regarding the items in the provider's database, and the users' microdata. In this work, we describe the architecture of our tool as well as a novel privacy metric, which is necessary for our setting where we do not have access to the provider's database. Our tool is user friendly, relying on smart visual results that raise privacy awareness. We evaluate our tool using three real world datasets, collected from major providers. We demonstrate strong correlations between the average anonymity set per user and the privacy score obtained by our metric. Our results illustrate that our tool which uses minimal information from the provider, estimates users' privacy levels comparably well, as if it had access to the actual database.
Spyros Boukoros, Stefan Katzenbeisser 0001
ARES2
2017 Microblogging in a Privacy-Preserving way
abstract
Microblogging is a popular activity within the spectrum of Online Social Networking (OSN), which allows users to quicky exchange short messages. Such systems can be based on mobile clients that exchange their group-encrypted messages utilizing local communications such as Bluetooth. Since however in such cases, users do not want to disclose their group memberships, and thus have to wait for other group members to appear in the proximity, the message spread can be slow to non-existent. In this paper, we solve this problem and facilitate a higher message spread by employing a server that stores the messages of multiple groups in an Oblivious RAM (ORAM) data structure. The server can be accessed by the clients on demand to read or write their group-encrypted messages. Thus our solution can be used to add access pattern privacy on top of existing microblogging peer-2-peer architectures, and using an ORAM is a promising candidate to use in the given application scenario.
Nikolaos P. Karvelas, Marius Senftleben, Stefan Katzenbeisser 0001
ARES3
2017 Boot Attestation: Secure Remote Reporting with Off-The-Shelf IoT Sensors
Steffen Schulz 0001, André Schaller, Florian Kohnhäuser, Stefan Katzenbeisser 0001
ESORICS (2)4
2017 A lightweight protocol for privacy preserving division
abstract
Homomorphic encryption is a well established means for performing operations on encrypted data. In many real-world applications however, the need arises to perform division over integers and yield a floating point result. This cannot be performed in the encrypted domain of most homomorphic encryption schemes. Thus, one has to resort to Secure Two Party Computation which suffers from high communication costs or to a Fully Homomorphic encryption scheme which is still inefficient. In this work, we present a lightweight and flexible protocol that takes as input two homomorphically encrypted integers, privately divides them and returns the result in floating point format. Our tool is designed to support both additive and multiplicative homomorphic schemes. We measure the privacy offered using a well established privacy metric and provide timings for the operations. We evaluate our protocol on a real world application scenario conducting simulations of attacks and present our encouraging results.
Spyros Boukoros, Nikolaos P. Karvelas, Stefan Katzenbeisser 0001
IWCMC3
2017 SEDCOS: A Secure Device-to-Device Communication System for Disaster Scenarios
abstract
During disasters, existing telecommunication infrastructures are often congested or even destroyed. In these situations, mobile devices can be interconnected using wireless ad hoc and disruption-tolerant networking to establish a backup emergency communication system for civilians and emergency services. However, such communication systems entail serious security risks, since adversaries may attempt to steal confidential data, fake notifications of emergency services, or perform denial-of-service (DoS) attacks. In this paper, we present SEDCOS, a secure device-to-device communication system for disaster scenarios. SEDCOS allows new users to join the network during disasters, mitigates flooding DoS attacks, and offers role revocation for detected adversaries to withdraw their permissions and exclude them from group communication. SEDCOS mitigates flooding DoS attacks and offers role revocation for detected adversaries to withdraw their permissions and exclude them from group communication. SEDCOS mitigates flooding DoS attacks and offers role revocation for detected adversaries to withdraw their permissions. We demonstrate the effectiveness of SEDCOS by large-scale network simulations.
Florian Kohnhäuser, Milan Stute, Lars Baumgärtner, Lars Almon, Stefan Katzenbeisser 0001, Matthias Hollick, Bernd Freisleben
LCN5
2017 Enabling Privacy Preserving Mobile Advertising via Private Information Retrieval
abstract
We propose a privacy preserving mobile advertising system for in-app ad placement, that enables user profiling and targeted ads without revealing user interests to the mobile advertising companies. Our proposal relies on device-based user profiles, derived from app activity, on the use of Private Information Retrieval (PIR) to query ads database(s) for matching (to profile) ads, without the database(s) learning the content or the result of queries. We implement a Proof of Concept (POC) solution comprising critical system components for Android devices, including the profile builder and the PIR mechanism based on Percy++ library (ported to Android). We evaluate the practicality of selected PIR techniques in a mobile ads system using measured real world parameters. Overall, we show that a mobile PIR client can be effectively used for private advertising: for a single client connecting to a desktop PIR server, the Information theoretic (IT) and Hybrid PIR mechanisms allow close to real time ad retrieval. E.g., when querying a 1GB ad database for a block of 4 ads (total of 64KB), the ads are retrieved with a delay of around 2.5sec and utilising (for IT PIR) 1.25MB of data. The selected Computational PIR mechanism, however, introduces unacceptable overheads (the delay is of the order of 1300sec and 9.4GB of data is exchanged between the Android client and server for the same ad block). Further multi-client scalability tests indicate that, for all schemes, the server side is a performance bottleneck and, in addition to using commercial grade equipment, implementation enhancements including parallel processing would be necessary to have close to real time system responsiveness.
Imdad Ullah, Golam Sarwar, Roksana Boreli, Salil S. Kanhere, Stefan Katzenbeisser 0001, Matthias Hollick
LCN5
2017 ORAMs in a Quantum World
Tommaso Gagliardoni, Nikolaos P. Karvelas, Stefan Katzenbeisser 0001
PQCrypto3
2017 A Security Architecture for Railway Signalling
Christian Schlehuber, Markus Heinrich, Tsvetoslava Vateva-Gurova, Stefan Katzenbeisser 0001, Neeraj Suri
SAFECOMP4
2017 SCAPI: a scalable attestation protocol to detect software and physical attacks
abstract
Interconnected embedded devices are increasingly used in various scenarios, including industrial control, building automation, or emergency communication. As these systems commonly process sensitive information or perform safety critical tasks, they become appealing targets for cyber attacks. A promising technique to remotely verify the safe and secure operation of networked embedded devices is remote attestation. However, existing attestation protocols only protect against software attacks, or show limited scalability and robustness. In this paper, we present the first scalable attestation protocol that detects physical attacks. Based on the assumption that physical attacks require an adversary to capture and disable devices for a noticeable amount of time, our protocol identifies devices with compromised hardware and software. Compared to existing solutions, our protocol reduces communication complexity and runtimes by orders of magnitude, precisely identifies compromised devices, and is robust against failures or network disruptions. We show the security of our protocol and evaluate its scalability and robustness. Our results demonstrate that our protocol is highly efficient in well-connected networks and operates robust in disruptive and very dynamic network topologies.
Florian Kohnhäuser, Niklas Büscher, Sebastian Gabmeyer, Stefan Katzenbeisser 0001
WISEC4
2017 On compiling Boolean circuits optimized for secure multi-party computation
Niklas Büscher, Martin Franz, Andreas Holzer, Helmut Veith, Stefan Katzenbeisser 0001
Formal Methods Syst. Des.5
2017 Two Is Not Enough: Privacy Assessment of Aggregation Schemes in Smart Metering
abstract
Abstract The widespread deployment of smart meters that frequently report energy consumption information, is a known threat to consumers’ privacy. Many promising privacy protection mechanisms based on secure aggregation schemes have been proposed. Even though these schemes are cryptographically secure, the energy provider has access to the plaintext aggregated power consumption. A privacy trade-off exists between the size of the aggregation scheme and the personal data that might be leaked, where smaller aggregation sizes leak more personal data. Recently, a UK industrial body has studied this privacy trade-off and identified that two smart meters forming an aggregate, are sufficient to achieve privacy. In this work, we challenge this study and investigate which aggregation sizes are sufficient to achieve privacy in the smart grid. Therefore, we propose a flexible, yet formal privacy metric using a cryptographic game based definition. Studying publicly-available, real world energy consumption datasets with various temporal resolutions, ranging from minutes to hourly intervals, we show that a typical household can be identified with very high probability. For example, we observe a 50% advantage over random guessing in identifying households for an aggregation size of 20 households with a 15-minutes reporting interval. Furthermore, our results indicate that single appliances can be identified with significant probability in aggregation sizes up to 10 households.
Niklas Büscher, Spyros Boukoros, Stefan Bauregger, Stefan Katzenbeisser 0001
Proc. Priv. Enhancing Technol.4
2016 Covert channels using mobile device's magnetic field sensors
abstract
This paper presents a new covert channel using smartphone magnetic sensors. We show that modern smartphones are capable to detect the magnetic field changes induced by different computer components during I/O operations. In particular, we are able to create a covert channel between a laptop and a mobile device without any additional equipment, firmware modifications or privileged access on either of the devices. We present two encoding schemes for the covert channel communication and evaluate their effectiveness.
Nikolay Matyunin, Jakub Szefer, Sebastian Biedermann, Stefan Katzenbeisser 0001
ASP-DAC4
2016 Run-Time Accessible DRAM PUFs in Commodity Devices
Wenjie Xiong 0001, André Schaller, Nikolaos A. Anagnostopoulos, Muhammad Umair Saleem, Sebastian Gabmeyer, Stefan Katzenbeisser 0001, Jakub Szefer
CHES6
2016 Compiling Low Depth Circuits for Practical Secure Computation
Niklas Büscher, Andreas Holzer, Alina Weber, Stefan Katzenbeisser 0001
ESORICS (2)4
2016 Secure Code Updates for Mesh Networked Commodity Low-End Embedded Devices
Florian Kohnhäuser, Stefan Katzenbeisser 0001
ESORICS (2)2
2016 Correcting Finite Sampling Issues in Entropy l-diversity
Sebastian Stammler, Stefan Katzenbeisser 0001, Kay Hamacher
PSD2
2016 Trust The Wire, They Always Told Me!: On Practical Non-Destructive Wire-Tap Attacks Against Ethernet
abstract
Ethernet technology dominates enterprise and home network installations and is present in datacenters as well as parts of the backbone of the Internet. Due to its wireline nature, Ethernet networks are often assumed to intrinsically protect the exchanged data against attacks carried out by eavesdroppers and malicious attackers that do not have physical access to network devices, patch panels and network outlets. In this work, we practically evaluate the possibility of wireless attacks against wired Ethernet installations with respect to resistance against eavesdropping by using off-the-shelf software-defined radio platforms. Our results clearly indicate that twisted-pair network cables radiate enough electromagnetic waves to reconstruct transmitted frames with negligible bit error rates, even when the cables are not damaged at all. Since this allows an attacker to stay undetected, it urges the need for link layer encryption or physical layer security to protect confidentiality.
Matthias Schulz 0001, Patrick Klapper, Matthias Hollick, Erik Tews, Stefan Katzenbeisser 0001
WISEC5
2016 On the Privacy and Performance of Mobile Anonymous Microblogging
abstract
Microblogging is a popular form of online social networking activity. It allows users to send messages in a one-to-many publish-subscribe manner. Most current service providers are centralized and deploy a client-server model with unencrypted message content. As a consequence, all user behavior can, by default, be monitored, and censoring based on message content can easily be enforced on the server side. A distributed, peer-to-peer microblogging system consisting of mobile smartphone-equipped users that exchange group encrypted messages in an anonymous and censorship-resistant manner can alleviate privacy and censorship issues. We experimentally evaluate message spread of such systems with simulations that run on a range of synthetic and real-world mobility inputs, thus extending the previous work. We show that such systems are feasible for a range of mobility and network settings, both under normal and under adversarial conditions, e.g., under the presence of nodes which jam the network or send spam.
Marius Senftleben, Ana Barroso, Mihai-Daniel Chiroiu, Matthias Hollick, Stefan Katzenbeisser 0001, Erik Tews
IEEE Trans. Inf. Forensics Secur.5
2015 Fifth International Workshop on Trustworthy Embedded Devices (TrustED 2015)
abstract
The Internet of Things (IoTS) is expected to seamlessly connect everything and everyone and bring about the promise of smart environments, industry 4.0, intelligent infrastructure management, environmental monitoring and disaster recovery, etc. The explosion in the number of interconnected devices makes it a challenge to guarantee their security, the security of their networks and the privacy of the data collected by them. The Workshop on Trustworthy Embedded Devices (TrustED) focuses on all aspects of security and privacy related to embedded systems and the IoTS. TrustED 2015 continues a successful series of workshops, which were held in conjunction with ESORICS 2011, IEEE Security & Privacy 2012, ACM CCS 2013 and ACM CCS 2014 (see http://www.trusted-workshop.de for details). The goal of this workshop is to bring together experts from academia and research institutes, industry, and government in the field of security and privacy in cyber physical systems.
Jorge Guajardo, Stefan Katzenbeisser 0001
CCS2
2015 Faster Secure Computation through Automatic Parallelization
Niklas Büscher, Stefan Katzenbeisser 0001
USENIX Security Symposium2
2014 AES-SEC: Improving Software Obfuscation through Hardware-Assistance
abstract
While the resilience of software-only code obfuscation remains unclear and ultimately depends only on available resources and patience of the attacker, hardware-based software protection approaches can provide a much higher level of protection against program analysis. Almost no systematic research has been done on the interplay between hardware and software based protection mechanism. In this paper, we propose modifications to Intel's AES-NI instruction set in order to make it suitable for application in software protection scenarios and demonstrate its integration into a control flow obfuscation scheme. Our novel approach provides strong hardware-software binding and restricts the attack context to pure dynamic analysis - two major limiting factors of reverse engineering - to delay a successful attack against a program.
Sebastian Schrittwieser, Stefan Katzenbeisser 0001, Georg Merzdovnik, Peter Kieseberg, Edgar R. Weippl
ARES2
2014 Hot-hardening: getting more out of your security settings
abstract
Applying optimized security settings to applications is a difficult and laborious task. Especially in cloud computing, where virtual servers with various pre-installed software packages are leased, selecting optimized security settings is very difficult. In particular, optimized security settings are not identical in every setup. They depend on characteristics of the setup, on the ways an application is used or on other applications running on the same system. Configuring optimized settings given these interdependencies is a complex and time-consuming task. In this work, we present an autonomous agent which improves security settings of applications which run in virtual servers. The agent retrieves custom-made security settings for a target application by investigating its specific setup, it tests and transparently changes settings via introspection techniques unbeknownst from the perspective of the virtual server. During setting selection, the application's operation is not disturbed nor any user interaction is needed. Since optimal settings can change over time or they can change depending on different tasks the application handles, the agent can continuously adapt settings as well as improve them periodically. We call this approach hot-hardening and present results of an implementation that can hot-harden popular networking applications such as Apache2 and OpenSSH.
Sebastian Biedermann, Stefan Katzenbeisser 0001, Jakub Szefer
ACSAC2
2014 CBMC-GC: An ANSI C Compiler for Secure Two-Party Computations
Martin Franz, Andreas Holzer, Stefan Katzenbeisser 0001, Christian Schallhart, Helmut Veith
CC3
2014 From Patches to Honey-Patches: Lightweight Attacker Misdirection, Deception, and Disinformation
abstract
Traditional software security patches often have the unfortunate side-effect of quickly alerting attackers that their attempts to exploit patched vulnerabilities have failed. Attackers greatly benefit from this information; it expedites their search for unpatched vulnerabilities, it allows them to reserve their ultimate attack payloads for successful attacks, and it increases attacker confidence in stolen secrets or expected sabotage resulting from attacks. To overcome this disadvantage, a methodology is proposed for reformulating a broad class of security patches into honey-patches - patches that offer equivalent security but that frustrate attackers' ability to determine whether their attacks have succeeded or failed. When an exploit attempt is detected, the honey-patch transparently and efficiently redirects the attacker to an unpatched decoy, where the attack is allowed to succeed. The decoy may host aggressive software monitors that collect important attack information, and deceptive files that disinform attackers. An implementation for three production-level web servers, including Apache HTTP, demonstrates that honey-patching can be realized for large-scale, performance-critical software applications with minimal overheads.
Frederico Araujo, Kevin W. Hamlen, Sebastian Biedermann, Stefan Katzenbeisser 0001
CCS4
2014 Data-centric phishing detection based on transparent virtualization technologies
abstract
We propose a novel phishing detection architecture based on transparent virtualization technologies and isolation of the own components. The architecture can be deployed as a security extension for virtual machines (VMs) running in the cloud. It uses fine-grained VM introspection (VMI) to extract, filter and scale a color-based fingerprint of web pages which are processed by a browser from the VM's memory. By analyzing the human perceptual similarity between the fingerprints, the architecture can reveal and mitigate phishing attacks which are based on redirection to spoofed web pages and it can also detect “Man-in-the-Browser” (MitB) attacks. To the best of our knowledge, the architecture is the first anti-phishing solution leveraging virtualization technologies. We explain details about the design and the implementation and we show results of an evaluation with real-world data.
Sebastian Biedermann, Tobias Ruppenthal, Stefan Katzenbeisser 0001
PST3
2014 ProofBook: An Online Social Network Based on Proof-of-Work and Friend-Propagation
Sebastian Biedermann, Nikolaos P. Karvelas, Stefan Katzenbeisser 0001, Thorsten Strufe, Andreas Peter 0001
SOFSEM3
2014 Covert Computation - Hiding code in code through compile-time obfuscation
Sebastian Schrittwieser, Stefan Katzenbeisser 0001, Peter Kieseberg, Markus Huber 0001, Manuel Leithner, Martin Mulazzani, Edgar R. Weippl
Comput. Secur.2
2013 Event-based isolation of critical data in the cloud
abstract
In this poster, we present TrustDraw, a transparent security extension for the cloud which combines Virtual Machine Introspection (VMI) and Trusted Computing (TC). TrustDraw provides secure storage of critical data like keys or passwords and allows to temporarily insert this data into a running virtual machine (VM) if required. TrustDraw improves security by allowing access to the critical data only if certain previously defined conditions are met. This way, the stealing of critical data by bypassing access permissions based on successfully executed attacks can be mitigated. TrustDraw runs isolated and transparent. No software modifications are required on a target VM. We evaluated an implementation of TrustDraw in a realistic scenario in which it only caused an acceptable run-time delay.
Sebastian Biedermann, Stefan Katzenbeisser 0001
CCS2
2013 Inherent PUFs and secure PRNGs on commercial off-the-shelf microcontrollers
abstract
Research on Physically Unclonable Functions (PUFs) has become very popular in recent years. However, all PUFs researched so far require either ASICs, FPGAs or a microcontroller with external components. Our research focuses on identifying PUFs in commercial off-the-shelf devices, e.g. microcontrollers. We show that PUFs exist in several off-theshelf products, which can be used for security applications. We present measurement results on the PUF behavior of five of the most popular microcontrollers today: ARM Cortex A,ARM Cortex-M,Atmel AVR, Microchip PIC16 and Texas Instruments MSP430. Based on these measurements, we can calculate whether these chips can be considered for applications requiring strong cryptography. As a result of these findings, we present a secure bootloader for the ARM Cortex-A9 platform based on a PUF inherent to the device, requiring no external components. Furthermore, instead of discarding the randomness in PUF responses, we utilize this to create strong seeds for pseudo-random number generators (PRNGs). The existence of a secure RNG is at the heart of virtually every cryptographic protocol, yet very often overlooked. We present the implementation of a strongly seeded PRNG for the ARM Cortex-M family, again requiring no external components.
Anthony Van Herrewege, André Schaller, Stefan Katzenbeisser 0001, Ingrid Verbauwhede
CCS3
2013 Covert computation: hiding code in code for obfuscation purposes
abstract
As malicious software gets increasingly sophisticated and resilient to detection, new concepts for the identification of malicious behavior are developed by academia and industry alike. While today's malware detectors primarily focus on syntactical analysis (i.e., signatures of malware samples), the concept of semantic-aware malware detection has recently been proposed. Here, the classification is based on models that represent the underlying machine and map the effects of instructions on the hardware. In this paper, we demonstrate the incompleteness of these models and highlight the threat of malware, which exploits the gap between model and machine to stay undetectable. To this end, we introduce a novel concept we call covert computation, which implements functionality in side effects of microprocessors. For instance, the flags register can be used to calculate basic arithmetical and logical operations. Our paper shows how this technique could be used by malware authors to hide malicious code in a harmless-looking program. Furthermore, we demonstrate the resilience of covert computation against semantic-aware malware scanners.
Sebastian Schrittwieser, Stefan Katzenbeisser 0001, Peter Kieseberg, Markus Huber 0001, Manuel Leithner, Martin Mulazzani, Edgar R. Weippl
AsiaCCS2
2013 Improving security of virtual machines during live migrations
abstract
Live migration of virtual machines (VMs) enables the transfer of a running VM to a new hardware component with minimal and hardly noticeable interruption. In cloud architectures, users are almost not able to detect live migrations of their VMs nor can they prevent them from happening. Nevertheless, if a VM is live migrated to a distant data center crossing national borders, security and privacy problems arise. This way, internal data can become subject to new national legislation without even notifying the owner of the live-migrated VM. In this paper, we propose methods to detect live migrations from the inside of an affected VM. Furthermore, we analyze how the live migration procedure can be delayed and how the additional gained time can be used to take security measures before the live migration is finished. We developed a “live migration defence framework” (LMDF) which can be used for security policy enforcement within a VM. We evaluated the proposed methods and techniques in our cloud setup and partially in the Amazon Elastic Computing Cloud (EC2).
Sebastian Biedermann, Martin Zittel, Stefan Katzenbeisser 0001
PST3
2013 Group homomorphic encryption: characterizations, impossibility results, and applications
Frederik Armknecht, Stefan Katzenbeisser 0001, Andreas Peter 0001
Des. Codes Cryptogr.2
2013 Secure computations on non-integer values with applications to privacy-preserving sequence analysis
Martin Franz, Björn Deiseroth, Kay Hamacher, Somesh Jha, Stefan Katzenbeisser 0001, Heike Schröder
Inf. Secur. Tech. Rep.5
2013 Efficiently Outsourcing Multiparty Computation Under Multiple Keys
abstract
Secure multiparty computation enables a set of users to evaluate certain functionalities on their respective inputs while keeping these inputs encrypted throughout the computation. In many applications, however, outsourcing these computations to an untrusted server is desirable, so that the server can perform the computation on behalf of the users. Unfortunately, existing solutions are either inefficient, rely heavily on user interaction, or require the inputs to be encrypted under the same public key - drawbacks making the employment in practice very limited. We propose a novel technique based on additively homomorphic encryption that avoids all these drawbacks. This method is efficient, requires no user interaction whatsoever (except for data upload and download), and allows evaluating any dynamically chosen function on inputs encrypted under different public keys. Our solution assumes the existence of two non-colluding but untrusted servers that jointly perform the computation by means of a cryptographic protocol. This protocol is proven to be secure in the semi-honest model. By developing application-tailored variants of our approach, we demonstrate its versatility and apply it in two real-world scenarios from different domains, privacy-preserving face recognition and private smart metering. We also give a proof-of-concept implementation to highlight its feasibility.
Andreas Peter 0001, Erik Tews, Stefan Katzenbeisser 0001
IEEE Trans. Inf. Forensics Secur.3
2012 Secure two-party computations in ANSI C
abstract
The practical application of Secure Two-Party Computation is hindered by the difficulty to implement secure computation protocols. While recent work has proposed very simple programming languages which can be used to specify secure computations, it is still difficult for practitioners to use them, and cumbersome to translate existing source code into this format. Similarly, the manual construction of two-party computation protocols, in particular ones based on the approach of garbled circuits, is labor intensive and error-prone.
Andreas Holzer, Martin Franz, Stefan Katzenbeisser 0001, Helmut Veith
CCS3
2012 PUFs: Myth, Fact or Busted? A Security Evaluation of Physically Unclonable Functions (PUFs) Cast in Silicon
Stefan Katzenbeisser 0001, Ünal Koçabas, Vladimir Rozic, Ahmad-Reza Sadeghi, Ingrid Verbauwhede, Christian Wachsmann
CHES1
2012 Dynamic Anomaly Detection for More Trustworthy Outsourced Computation
Sami Alsouri, Jan Sinschek, Andreas Sewe, Eric Bodden, Mira Mezini, Stefan Katzenbeisser 0001
ISC6
2012 Additively Homomorphic Encryption with a Double Decryption Mechanism, Revisited
Andreas Peter 0001, Max Kronberg, Wilke Trei, Stefan Katzenbeisser 0001
ISC4
2011 Recyclable PUFs: Logically Reconfigurable PUFs
Stefan Katzenbeisser 0001, Ünal Koçabas, Vincent van der Leest, Ahmad-Reza Sadeghi, Geert Jan Schrijen, Heike Schröder, Christian Wachsmann
CHES1
2011 Physically Uncloneable Functions in the Universal Composition Framework
Christopher Brzuska, Marc Fischlin, Heike Schröder, Stefan Katzenbeisser 0001
CRYPTO4
2011 Security of copy-move forgery detection techniques
abstract
Copy-move forgery is a specific form of image tampering, where a part of a digital image is copied and pasted into a different part of the same image. There are many copy move forgery detection techniques, but their security has not been examined in detail. In this paper, we analyze the robustness and security of the detection techniques of Fridrich [1], Popescu [2], and Luo [3]. We show that all three schemes can successfully be defeated by targeted attacks, which are specifically tailored towards exploiting some characteristics of the schemes. Thus, with little effort an attacker can disguise a forged image as authentic even in presence of image forensic tools.
Hieu Cuong Nguyen, Stefan Katzenbeisser 0001
ICASSP2
2011 Performance and Robustness Analysis for Some Re-sampling Detection Techniques in Digital Images
Hieu Cuong Nguyen, Stefan Katzenbeisser 0001
IWDW2
2011 Public security: simulations need to replace conventional wisdom
abstract
Is more always better? Is conventional wisdom always the right guideline in the development of security policies that have large opportunity costs? Is the evaluation of security measures after their introduction the best way? In the past, these questions were frequently left unasked before the introduction of many public security measures. In this paper we put forward the new paradigm that agent-based simulations are an effective and most likely the only sustainable way for the evaluation of public security measures in a complex environment. As a case-study we provide a critical assessment of the power of Telecommunications Data Retention (TDR), which was introduced in most European countries, despite its huge impact on privacy. Up to now it is unknown whether TDR has any benefits in the identification of terrorist dark nets in the period before an attack. The results of our agent-based simulations suggest, contrary to conventional wisdom, that the current practice of acquiring more data may not necessarily yield higher identification rates.
Kay Hamacher, Stefan Katzenbeisser 0001
NSPW2
2011 Trustable outsourcing of business processes to cloud computing environments
abstract
Cloud Computing, the next generation of Internet-based services, will allow cost-effective outsourcing of applications and business processes. However, outsourcing business processes to potentially untrusted servers poses significant security and privacy problems. Despite having no direct control over the hardware platform on which the business processes run, clients still need to obtain assurance of correct execution. In this paper, we propose an architecture based on Trusted Computing technologies that allows fine-granular and policy-based remote attestation of outsourced business processes running on remote hosts. In particular, we let the provider generate, during execution of the business process, secure execution logs that allow to verify correct execution of the process at a later time by the client. Our architecture allows a cloud provider to host business processes for multiple tenants, considering at the same time multi-instance processes. We show how such an architecture can be implemented using Trusted Computing technologies, traditional virtualization technologies like Xen and the ODE process engine.
Sami Alsouri, Stefan Katzenbeisser 0001, Sebastian Biedermann
NSS2
2011 Tardos Fingerprinting Codes in the Combined Digit Model
abstract
We formalize a new attack model for collusion secure codes, incorporating attacks on the underlying watermarking scheme as well as cut-and-paste attacks traditionally considered for collusion secure codes. We use this model to analyze the collusion resistance of two versions of the Tardos code, both for binary and nonbinary alphabets. The model allows us to consider different signal processing attacks on the content, namely the addition of noise and averaging attacks. The latter may result in content segments that have multiple watermarks embedded. We study two versions of the$q$-ary Tardos code in which the accusation method has been modified so as to allow for the detection of multiple symbols in the same content segment. We show that both variants yield efficient codes in the new model, parametrized for realistic attacker strengths.
Boris Skoric, Stefan Katzenbeisser 0001, Hans Georg Schaathun, Mehmet Utku Celik
IEEE Trans. Inf. Forensics Secur.2
2010 A New DRM Architecture with Strong Enforcement
abstract
We propose a new DRM architecture that utilizes a two-step enforcement process to enable strong security even in the case of a compromised DRM viewer. This is achieved by using novel cryptographic techniques of attribute-based encryption that make it possible to limit access to media to a subset of users that has to fulfill certain properties which are specified during the encryption process. We call these properties static rules. Static rules add an additional layer to the dynamic DRM enforcement framework that has to be overcome by potential attackers even if a DRM media operates in an unprotected environment. Finally, we demonstrate the practicability of this architecture by describing how static rules can be automatically extracted from licenses formulated in the standardized Open Digital Rights Language (ODRL).
Sascha Müller 0003, Stefan Katzenbeisser 0001
ARES2
2010 Redactable Signatures for Tree-Structured Data: Definitions and Constructions
Christopher Brzuska, Heike Schröder, Özgür Dagdelen, Marc Fischlin, Martin Franz, Stefan Katzenbeisser 0001, Mark Manulis, Cristina Onete, Andreas Peter 0001, Bertram Poettering, Dominique Schröder
ACNS6
2010 Proactive Detection of Computer Worms Using Model Checking
abstract
Although recent estimates are speaking of 200,000 different viruses, worms, and Trojan horses, the majority of them are variants of previously existing malware. As these variants mostly differ in their binary representation rather than their functionality, they can be recognized by analyzing the program behavior, even though they are not covered by the signature databases of current antivirus tools. Proactive malware detectors mitigate this risk by detection procedures that use a single signature to detect whole classes of functionally related malware without signature updates. It is evident that the quality of proactive detection procedures depends on their ability to analyze the semantics of the binary. In this paper, we propose the use of model checking—a well-established software verification technique—for proactive malware detection. We describe a tool that extracts an annotated control flow graph from the binary and automatically verifies it against a formal malware specification. To this end, we introduce the new specification language CTPL, which balances the high expressive power needed for malware signatures with efficient model checking algorithms. Our experiments demonstrate that our technique indeed is able to recognize variants of existing malware with a low risk of false positives.
Johannes Kinder, Stefan Katzenbeisser 0001, Christian Schallhart, Helmut Veith
IEEE Trans. Dependable Secur. Comput.2
2010 Semantic integrity in large-scale online simulations
abstract
As large-scale online simulations such as Second Life and World of Warcraft are gaining economic significance, there is a growing incentive for attacks against such simulation software. We focus on attacks against the semantic integrity of the simulation. This class of attacks exploits the client-server architecture and is specific to online simulations which, for performance reasons, have to delegate the detailed rendering of the simulated world to the clients. Attacks against semantic integrity often compromise the physical laws of the simulated world—enabling the user's simulation persona to fly, walk through walls, or to run faster than anybody else. We introduce the Secure Semantic Integrity Protocol (SSIP), which enables the simulation provider to audit the client computations. Then we analyze the security and scalability of SSIP. First, we show that under standard cryptographic assumptions SSIP will detect semantic integrity attacks. Second, we analyze the network overhead, and determine the optimum tradeoff between cost of bandwidth and audit frequency for our protocol.
Somesh Jha, Stefan Katzenbeisser 0001, Christian Schallhart, Helmut Veith, Stephen Chenney
ACM Trans. Internet Techn.2
2009 Hide and Seek in Time - Robust Covert Timing Channels
Dipak Ghosal, Frederik Armknecht, Ahmad-Reza Sadeghi, Steffen Schulz 0001, Stefan Katzenbeisser 0001
ESORICS6
2009 On the Reliability of Cell Phone Camera Fingerprint Recognition
Martin Steinebach, Mohamed El Ouariachi, Huajian Liu, Stefan Katzenbeisser 0001
ICDF2C4
2009 Privacy-Preserving Face Recognition
Zekeriya Erkin, Martin Franz, Jorge Guajardo, Stefan Katzenbeisser 0001, Reginald L. Lagendijk, Tomas Toft
Privacy Enhancing Technologies4
2008 Privacy-Preserving Recommendation Systems for Consumer Healthcare Services
abstract
Advances in e-health bring new challenges with regard to the protection of sensitive patient data; an increasing number of applications require to share data with consumer healthcare services. Typically the providers of those services reside outside the traditional health care domain, where medical data protection laws (such as HIPAA) do not apply. Instead, technical means of protection should safeguard critical health data that is shared with third parties. In this paper, we show that cryptographic privacy-enhancing protocols are a key tool to protect the privacy of patients in upcoming consumer e-health services. In particular we focus on services offering health advice, allowing to locate specialists and supporting the formation of patient communities.
Stefan Katzenbeisser 0001, Milan Petkovic
ARES1
2008 Symmetric Tardos fingerprinting codes for arbitrary alphabet sizes
Boris Skoric, Stefan Katzenbeisser 0001, Mehmet Utku Celik
Des. Codes Cryptogr.2
2008 Lookup-Table-Based Secure Client-Side Embedding for Spread-Spectrum Watermarks
abstract
Today, mass-scale electronic content distribution systems embed forensic tracking watermarks primarily at the distribution server. For limiting the bandwidth usage and server complexity and enhancing scalability, it is preferable to embed the watermark at the client. Embedding in these untrusted clients requires secure embedding methods that do not leak unmarked content or the watermarking secrets. In this work, we propose a secure watermark embedding scheme based on lookup tables for spread-spectrum watermarks, which are robust to noise and can be detected without comparison to the original content. We also develop fast detection mechanisms that make the watermark detection feasible for tracking systems with a large number of clients. Our fast detection algorithm improves detection speed of existing methods by six orders of magnitude in a typical system with millions of clients.
Mehmet Utku Celik, Aweke N. Lemma, Stefan Katzenbeisser 0001, Michiel van der Veen
IEEE Trans. Inf. Forensics Secur.3
2008 A Buyer-Seller Watermarking Protocol Based on Secure Embedding
abstract
In a forensic watermarking architecture, a buyer-seller protocol protects the watermark secrets from the buyer and prevents false infringement accusations by the seller. Existing protocols encrypt the watermark and the content with a homomorphic public-key cipher and perform embedding under encryption. When used for multimedia data, these protocols create a large computation and bandwidth overhead. In this correspondence, we show that the same functionality can be achieved efficiently using recently proposed secure watermark embedding algorithms.
Stefan Katzenbeisser 0001, Aweke N. Lemma, Mehmet Utku Celik, Michiel van der Veen, Martijn Maas
IEEE Trans. Inf. Forensics Secur.1
2007 Privacy preserving error resilient dna searching through oblivious automata
abstract
Human Desoxyribo-Nucleic Acid (DNA) sequences offer a wealth of information that reveal, among others, predisposition to various diseases and paternity relations. The breadth and personalized nature of this information highlights the need for privacy-preserving protocols. In this paper, we present a new error-resilient privacy-preserving string searching protocol that is suitable for running private DNA queries. This protocol checks if a short template (e.g., a string that describes a mutation leading to a disease), known to one party, is present inside a DNA sequence owned by another party, accounting for possible errors and without disclosing to each party the other party's input. Each query is formulated as a regular expression over a finite alphabet and implemented as an automaton. As the main technical contribution, we provide a protocol that allows to execute any finite state machine in an oblivious manner, requiring a communication complexity which is linear both in the number of states and the length of the input string.
Juan Ramón Troncoso-Pastoriza, Stefan Katzenbeisser 0001, Mehmet Utku Celik
CCS2
2007 Secure Embedding of Spread Spectrum Watermarks using Look-up-Tables
abstract
In an electronic content distribution system, it is preferable to embed forensic tracking watermarks at the client-side to limit bandwidth usage and server complexity. Embedding in these untrusted clients, however, requires secure embedding methods that do not leak unmarked contents or the watermarking secrets. In this work, we propose a look-up-table (LUT) based cipher, similar to Andersen's Chameleon cipher, for securely embedding spread-spectrum watermarks, which are noise robust and detectable without the original content. We also develop fast detection mechanisms that make the watermark detection feasible for tracking systems with large number of clients. Our fast detection algorithm improves detection speed six orders of magnitude in a typical system.
Mehmet Utku Celik, Aweke N. Lemma, Stefan Katzenbeisser 0001, Michiel van der Veen
ICASSP (2)3
2007 Camcorder Capture Robust Low-Complexity Watermarking of MPEG-2 Bit-Streams
abstract
Unauthorized re-distribution remains a significant threat for emerging electronic movie distribution services. In this paper, we propose a forensic tracking watermark for MPEG-2 bit-streams that can be employed to complement Digital Rights Management and conditional access systems in electronic movie distribution. The watermark is embedded by modulating a subset of quantization matrix entries, which are periodically present in the MPEG-2 headers. When observed over time the watermark can be detected even after cropping, de-interlacing, resizing and DivX compression at 300 kbps or after being captured with a video camera from a flat-screen TV. As the method modifies only a small part of the bit-stream (ap100 bytes per second), it can be readily implemented in resource constrained environments like the current generation set-top boxes, without costly hardware upgrades.
Mehmet Utku Celik, Joop Talstra, Aweke N. Lemma, Stefan Katzenbeisser 0001
ICIP (5)4
2007 Forensic Watermarking During AAC Playback
abstract
We propose a method for embedding a robust forensic tracking watermark within the AAC decoder during audio playback. For predefined frequency bands, the method intercepts and modifies the scale-factors, which are present in the AAC bit-stream. It thereby modulates the short-time envelope of the band-limited audio and embeds a watermark which is robust to various attacks such as recompression and acoustic transmission. Due to its low complexity - a few additions per AAC frame - the method is suitable for implementation even in resource constrained devices such as portable players. Furthermore, decode-time embedding enables dynamic payload assignments which may be used to signal playback time and location.
Serap Kirbiz, Mehmet Utku Celik, Aweke N. Lemma, Stefan Katzenbeisser 0001
ICME4
2007 Computing under occupation
abstract
Recent investigations have found a massively increasing professionalisation and organization of attacks executed on consumer computing systems. Simultaneously, the systems we are trying to defend are getting more and more complex and networked, while promising security technologies---such as trusted boot and strong process isolation---appear to have troubles finding their way into mainstream devices.
Klaus Kursawe, Stefan Katzenbeisser 0001
NSPW2
2007 Enforcing Semantic Integrity on Untrusted Clients in Networked Virtual Environments
abstract
In the computer gaming industry, large-scale simulations of realistic physical environments over the Internet have attained increasing importance. Networked virtual environments (NVEs) are typically based on a client-server architecture where part of the simulation workload is delegated to the clients. This architecture renders the simulation vulnerable to attacks against the semantic integrity of the simulation: malicious clients may attempt to compromise the physical and logical rules governing the simulation, or to alter the causality of events. This paper initiates the systematic study of semantic integrity in NVEs from a security point of view. We present a new provably secure semantic integrity protocol which enables the server system to audit the local computations of the clients on demand.
Somesh Jha, Stefan Katzenbeisser 0001, Christian Schallhart, Helmut Veith, Stephen Chenney
S&P2
2007 NS2: Networked Searchable Store with Correctness
Radu Sion, Sumeet Bajaj, Bogdan Carbunar, Stefan Katzenbeisser 0001
VLDB4
2007 Protection and Retrieval of Encrypted Multimedia Content: When Cryptography Meets Signal Processing
abstract
The processing and encryption of multimedia content are generally considered sequential and independent operations. In certain multimedia content processing scenarios, it is, however, desirable to carry out processing directly on encrypted signals. The field of secure signal processing poses significant challenges for both signal processing and cryptography research; only few ready-to-go fully integrated solutions are available. This study first concisely summarizes cryptographic primitives used in existing solutions to processing of encrypted signals, and discusses implications of the security requirements on these solutions. The study then continues to describe two domains in which secure signal processing has been taken up as a challenge, namely, analysis and retrieval of multimedia content, as well as multimedia content protection. In each domain, state-of-the-art algorithms are described. Finally, the study discusses the challenges and open issues in the field of secure signal processing.
Zekeriya Erkin, Alessandro Piva, Stefan Katzenbeisser 0001, Reginald L. Lagendijk, Jamshid Shokrollahi, Gregory Neven, Mauro Barni
EURASIP J. Inf. Secur.3
2007 Signal Processing in the Encrypted Domain
abstract
Article ID 82790
Alessandro Piva, Stefan Katzenbeisser 0001
EURASIP J. Inf. Secur.2
2007 Decode-Time Forensic Watermarking of AAC Bitstreams
abstract
In digital rights-management systems, forensic watermarking complements encryption and deters the capture and unauthorized redistribution of the rendered content. In this paper, we propose a novel watermarking method which is integrated into the advanced audio coding (AAC) standard's decoding process. For predefined frequency bands, the method intercepts and modifies the scale factors, which are utilized for dequantization of spectral coefficients. It thereby modulates the short-time envelope of the bandlimited audio and embeds a watermark which is robust to various attacks, such as capture with a microphone and recompression at lower bit rates. Inclusion of watermark embedding in the AAC decoder has practically no effect on the decoding complexity. As a result, the proposed method can be integrated even into resource-constrained devices, such as portable players without any additional hardware.
Serap Kirbiz, Aweke N. Lemma, Mehmet Utku Celik, Stefan Katzenbeisser 0001
IEEE Trans. Inf. Forensics Secur.4
2006 Graceful infringement reactions in DRM systems
abstract
In this paper, we propose an alternative DRM technology for next-generation optical media. Instead of implementing a hard access control mechanism, we propose a scheme that monitors the behavior of users in a privacy-preserving manner, detects potential infringement actions and reacts in a graceful way, which is dependent on the severity of infringements. The scheme is based on blacklists of known unauthorized content and compromised players, which are maintained by content providers and shipped alongside the content. Most of the functionality is implemented by content code provided on the disc, allowing for player independent and flexible reactions.
Stefan Katzenbeisser 0001, Klaus Kursawe, Joop Talstra
Digital Rights Management Workshop1
2006 Secure Watermark Embedding Through Partial Encryption
Aweke N. Lemma, Stefan Katzenbeisser 0001, Mehmet Utku Celik, Michiel van der Veen
IWDW2
2006 The influence of neighbourhood and choice on the complexity of finding pure Nash equilibria
Felix A. Fischer, Markus Holzer 0001, Stefan Katzenbeisser 0001
Inf. Process. Lett.3
2005 Detecting Malicious Code by Model Checking
Johannes Kinder, Stefan Katzenbeisser 0001, Christian Schallhart, Helmut Veith
DIMVA2
2005 Ensuring Media Integrity on Third-Party Infrastructures
Jana Dittmann, Stefan Katzenbeisser 0001, Christian Schallhart, Helmut Veith
SEC2
2004 Towards Human Interactive Proofs in the Text-Domain (Using the Problem of Sense-Ambiguity for Security)
Richard Bergmair, Stefan Katzenbeisser 0001
ISC2
2003 Watermarking schemes provably secure against copy and ambiguity attacks
abstract
Protocol attacks against watermarking schemes pose a threat to modern digital rights management systems; for example, a successful attack may allow to copy a watermark between two digital objects or to forge a valid watermark. Such attacks enable a traitor to hinder a dispute resolving process or accuse an innocent party of a copyright infringement. Secure DRM systems based on watermarks must therefore prevent such protocol attacks. In this paper we introduce a formal framework that enables us to assert rigorously the security of watermarks against protocol attacks. Furthermore, we show how watermarking schemes can be secured against some protocol attacks by using a cryptographic signature of a trusted third party.
André Adelsbach, Stefan Katzenbeisser 0001, Helmut Veith
Digital Rights Management Workshop2
2003 On the Insecurity of Non-invertible Watermarking Schemes for Dispute Resolving
André Adelsbach, Stefan Katzenbeisser 0001, Ahmad-Reza Sadeghi
IWDW2
2003 On the Integration of Watermarks and Cryptography
Stefan Katzenbeisser 0001
IWDW1
2003 Watermark detection with zero-knowledge disclosure
André Adelsbach, Stefan Katzenbeisser 0001, Ahmad-Reza Sadeghi
Multim. Syst.2
2003 Editorial
Jana Dittmann, Stefan Katzenbeisser 0001, Nasir Memon
Multim. Syst.2