VLDB 2026 Research / reviewers in the wild / expert
Tolga Arul
dblp:85/9738
· DBLP profile ↗
21ranked-venue papers
2as first author
10since 2021 · last 2025
0000-0002-2078-3976ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 10 · 2 first-author · 6 since 2021Security and privacy · 8 · 3 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021Computer networks · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Achieving Error-Free Lightweight Authentication With DRAM-Based Physical Unclonable FunctionsabstractIn this article, we introduce a novel approach to achieving lightweight device authentication through the use of a low-complexity Convolutional Neural Network (CNN). In our work, we improve the False Authentication Rate (FAR) by transforming the standard CNN into a Bayesian CNN (BCNN or BNN). This transformation enables the use of probabilistic modelling techniques, increasing the model’s robustness and its confidence in authentication decisions. Regardless of the model used, clients authenticate with a retention-based Dynamic Random Access Memory Physical Unclonable Function (DRAM PUF) response. Our approach integrates the low computational complexity of the CNN with the intrinsic security characteristics of the DRAM PUF, offering a robust solution for lightweight and secure device authentication. Nico Mexis, Nikolaos A. Anagnostopoulos, Stefan Katzenbeisser 0001, Elif Bilge Kavun, Sara Tehranipoor, Tolga Arul |
IEEE Trans. Circuits Syst. I Regul. Pap. | 6 |
| 2024 | Secure Data-Binding in FPGA-based Hardware Architectures utilizing PUFsabstractIn this work, a novel FPGA-based data-binding architecture incorporating PUFs and a user-specific encryption key to protect the confidentiality of data on external non-volatile memories is presented. By utilizing an intrinsic PUF derived from the same memory, the confidential data is additionally bound to the device. This feature proves valuable in cases where software is restricted to be executed exclusively on specific hardware or privacy-critical data is not allowed to be decrypted elsewhere. To improve the resistance against hardware attacks, a novel method to randomly select memory cells utilized for PUF measurements is presented. The FPGA-based design presented in this work allows for low latency as well as small area utilization, offers high adaptability to diverse hardware and software platforms, and is accessible from bare-metal programs to full Linux kernels. Moreover, a detailed performance and security evaluation is conducted on five boards. A single read or write operation can be executed in 0.58 μs when utilizing the lightweight PRINCE cipher on an AMD Zync 7000 MPSoC. Furthermore, the entire architecture occupies only about 10% of the FPGA's available space on a resource-constrained AMD PYNQ-Z2. Ultimately, the implementation is demonstrated by storing confidential user data on new generations of network base stations equipped with FPGAs. Florian Frank 0004, Felix Klement, Purushothaman Palani, Elif Bilge Kavun, Wenjie Xiong 0001, Tolga Arul, Stefan Katzenbeisser 0001 |
AsiaCCS | 8 |
| 2024 | Investigation of Commercial Off-The-Shelf ReRAM Modules for Use as Runtime-Accessible TRNGabstractIn this work, we analyse Commercial Off-The-Shelf (COTS) Resistive Random Access Memory (ReRAM) modules for their suitability to implement a novel runtime-accessible True Random Number Generator (TRNG). For this purpose, modules from two different manufacturers (Adesto Technologies and Fujitsu) were tested, which exhibited distinct characteristics under different conditions. If suitable parameters are selected, the proposed TRNG can successfully pass all the tests of both the NIST SP800-22 Statistical Test Suite and the NIST SP800-90B Entropy Source Test Suite at a wide range of temperatures. At the same time, the TRNG achieves a throughput of at least 28 bits per second under adverse temperature conditions and approximately 51 bits per second at room temperature, in the worst case. Therefore, the performance of the TRNG is sufficient for many practical applications such as security protocols for the Internet of Things (IoT) and in-vehicle networks [1], [2]. Tolga Arul, Nico Mexis, Aleena Elsa George, Florian Frank 0004, Nikolaos A. Anagnostopoulos, Stefan Katzenbeisser 0001 |
DSD | 1 |
| 2023 | A Method to Construct Efficient Carbon-Nanotube-Based Physical Unclonable Functions and True Random Number GeneratorsabstractIn this work, we present a novel method of increasing the entropy of the CNT-PUF, a Physical Unclonable Function (PUF) based on Carbon-NanoTube Field Effect Transistors (CNT-FETs). The binary responses of this PUF are based on the drain current IDof each CNT-FET under the influence of a particular gate-source voltage VGS,which, through the employment of a single threshold value for ID,can indicate whether each relevant CNT cell of the array is conducting (acting either as a true conductor or as a semiconductor) or not (acting as an insulator). In this work, we propose the adoption of individual threshold values for each such cell as part of the relevant PUF challenge, thereby significantly increasing the overall entropy of this PUF, as well as the security that it can provide. Moreover, this method allows for the realisation of a source of higher entropy in the form of a True Random Number Generator (TRNG). Finally, we note that our work and its results are most probably also relevant for other CNT- based PUFs, structures, and primitives that utilise a single current (or even, voltage) threshold to determine the state of the different CNT cells utilised. Nikolaos A. Anagnostopoulos, Nico Mexis, Simon Böttger, Martin Hartmann, Ali Wagdy Mohamed, Sascha Hermann, Stefan Katzenbeisser 0001, Stavros G. Stavrinides, Tolga Arul |
DSD | 9 |
| 2023 | Spatial Correlation in Weak Physical Unclonable Functions: A Comprehensive OverviewabstractPhysical Unclonable Functions (PUFs) are increasingly used in the process of securing applications. For this purpose, it is crucial that the PUF satisfies all the required properties adequately, including Unpredictability. An important aspect of Unpredictability is Randomness, which includes being free of spatial correlation effects. However, most methods for assessing randomness are not capable of detecting correlation, such that this aspect is often ignored. This work summarises the current literature to shed more light on the topic of analysing spatial correlation in weak PUFs, and evaluates the various methods proposed in the literature for detecting such effects. Additionally, the spatial correlation of a Dynamic Random Access Memory (DRAM) decay-based PUF implemented on the DRAM of a Raspberry Pi board, as well as that of a Carbon-NanoTube-based PUF (CNT-PUF), are examined, using, for the first time in the context of PUFs, not only other well-known metrics proposed in the relevant literature, but also the Getis-Ord G metric. Finally, a mitigation technique against attacks based on spatial auto-correlation is proposed and its effective application to PUF responses is discussed. Nico Mexis, Tolga Arul, Nikolaos A. Anagnostopoulos, Florian Frank 0004, Simon Böttger, Martin Hartmann, Sascha Hermann, Elif Bilge Kavun, Stefan Katzenbeisser 0001 |
DSD | 2 |
| 2023 | Keep your Enemies closer: On the minimal Distance of Adversaries when using Channel-based Key Extraction in SISO 6G SystemsabstractWe conduct a comprehensive analysis of Channel-based Key Extraction across various frequency ranges that have potential applications in the 6th generation mobile standard. Specifically, we examine the minimum distance required between an attacker and a legitimate entity to achieve secure key generation through channel measurement. By simulating various metrics across diverse configurations, we observe that in our generic model, the required distance for an attacker to attain sufficient channel correlation reduces as frequency increases. Consequently, an attacker must be within close proximity, mere centimeters away, from a legitimate node to acquire relevant information necessary for generating a potentially identical key. Felix Klement, Shoya Takebuchi, Tolga Arul, Stefan Katzenbeisser 0001 |
WiMob | 3 |
| 2023 | Abusing Commodity DRAMs in IoT Devices to Remotely Spy on TemperatureabstractThe ubiquity and pervasiveness of modern Internet of Things (IoT) devices opens up vast possibilities for novel applications, but simultaneously also allows spying on, and collecting data from, unsuspecting users to a previously unseen extent. This paper details a new attack form in this vein, in which the decay properties of widespread, off-the-shelf DRAM modules are exploited to accurately spy on the temperature in the vicinity of the DRAM-carrying device. Among others, this enables adversaries to remotely and purely digitally spy on personal behavior in users’ private homes, or to collect security-critical data in server farms, cloud storage centers, or commercial production lines. We demonstrate that our attack can be performed by merely compromising the software of an IoT device and does not require hardware modifications or physical access at attack time. It can achieve temperature resolutions of up to 0.5°C over a range of 0°C to 70°C in practice. The presented attack works in devices that do not have a dedicated temperature sensor on board; as the DRAM modules already present in the device are abused to spy on the temperature. To complete the work, the paper discusses practical attack scenarios as well as possible countermeasures against the new temperature-spying attacks. Florian Frank 0004, Wenjie Xiong 0001, Nikolaos A. Anagnostopoulos, André Schaller, Tolga Arul, Farinaz Koushanfar, Stefan Katzenbeisser 0001, Ulrich Rührmair, Jakub Szefer |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2022 | Using Memristor Arrays as Physical Unclonable Functions
Florian Frank 0004, Tolga Arul, Nikolaos A. Anagnostopoulos, Stefan Katzenbeisser 0001 |
ESORICS (3) | 2 |
| 2021 | Nano Security: From Nano-Electronics to Secure SystemsabstractThe field of computer hardware stands at the verge of a revolution driven by recent breakthroughs in emerging nanodevices. “Nano Security” is a new Priority Program recently approved by DFG, the German Research Council. This initial-stage project initiative at the crossroads of nano-electronics and hardware-oriented security includes 11 projects with a total of 23 Principal Investigators from 18 German institutions. It considers the interplay between security and nano-electronics, focusing on a dichotomy which emerging nano-devices (and their architectural implications) have on system security. The projects within the Priority Program consider both: potential security threats and vulnerabilities stemming from novel nano-electronics, and innovative approaches to establishing and improving system security based on nano-electronics. This paper provides an overview of the Priority Program's overall philosophy and discusses the scientific objectives of its individual projects. Ilia Polian, Frank Altmann, Tolga Arul, Christian Boit, Ralf Brederlow, Lucas Davi, Rolf Drechsler, Nan Du 0004, Thomas Eisenbarth 0001, Tim Güneysu, Sascha Hermann, Matthias Hiller, Rainer Leupers, Farhad Merchant, Thomas Mussenbrock, Stefan Katzenbeisser 0001, Akash Kumar 0001, Wolfgang Kunz, Thomas Mikolajick, Vivek Pachauri, Jean-Pierre Seifert, Frank Sill, Jens Trommer |
DATE | 3 |
| 2021 | A Lightweight Architecture for Hardware-Based Security in the Emerging Era of Systems of SystemsabstractIn recent years, a new generation of the Internet of Things (IoT 2.0) is emerging, based on artificial intelligence, the blockchain technology, machine learning, and the constant consolidation of pre-existing systems and subsystems into larger systems. In this work, we construct and examine a proof-of-concept prototype of such a system of systems, which consists of heterogeneous commercial off-the-shelf components, and utilises diverse communication protocols. We recognise the inherent need for lightweight security in this context, and address it by employing a low-cost state-of-the-art security solution. Our solution is based on a novel hardware and software co-engineering paradigm, utilising well-known software-based cryptographic algorithms, in order to maximise the security potential of the hardware security primitive (a Physical Unclonable Function) that is used as a security anchor. The performance of the proposed security solution is evaluated, proving its suitability even for real-time applications. Additionally, the Dolev-Yao attacker model is considered in order to assess the resilience of our solution towards attacks against the confidentiality, integrity, and availability of the examined system of systems. In this way, it is confirmed that the proposed solution is able to address the emerging security challenges of the oncoming era of systems of systems. Nico Mexis, Nikolaos A. Anagnostopoulos, Jan Bambach, Tolga Arul, Stefan Katzenbeisser 0001 |
ACM J. Emerg. Technol. Comput. Syst. | 5 |
| 2020 | Predicting Railway Signalling Commands Using Neural Networks for Anomaly Detection
Markus Heinrich, Dominik Renkel, Tolga Arul, Stefan Katzenbeisser 0001 |
SAFECOMP | 3 |
| 2020 | Safety Meets Security: Using IEC 62443 for a Highly Automated Road Vehicle
Dominik Püllen, Nikolaos A. Anagnostopoulos, Tolga Arul, Stefan Katzenbeisser 0001 |
SAFECOMP | 3 |
| 2020 | ELSA: efficient long-term secure storage of large datasets (full version) ∗abstractAbstract An increasing amount of information today is generated, exchanged, and stored digitally. This also includes long-lived and highly sensitive information (e.g., electronic health records, governmental documents) whose integrity and confidentiality must be protected over decades or even centuries. While there is a vast amount of cryptography-based data protection schemes, only few are designed for long-term protection. Recently, Braun et al. (AsiaCCS’17) proposed the first long-term protection scheme that provides renewable integrity protection and information-theoretic confidentiality protection. However, computation and storage costs of their scheme increase significantly with the number of stored data items. As a result, their scheme appears suitable only for protecting databases with a small number of relatively large data items, but unsuitable for databases that hold a large number of relatively small data items (e.g., medical record databases).In this work, we present a solution for efficient long-term integrity and confidentiality protection of large datasets consisting of relatively small data items. First, we construct a renewable vector commitment scheme that is information-theoretically hiding under selective decommitment. We then combine this scheme with renewable timestamps and information-theoretically secure secret sharing. The resulting solution requires only a single timestamp for protecting a dataset while the state of the art requires a number of timestamps linear in the number of data items. Furthermore, we extend the scheme, that supports a single client, to a multi-client setting. Subsequently, we characterize the arising challenges with respect to integrity and confidentiality and discuss how our multi-client scheme tackles them. We implemented our solution and measured its performance in a scenario where 9600 data items are aggregated, stored, protected, and verified over a time span of 80 years. Our measurements show that our new solution completes this evaluation scenario an order of magnitude faster than the state of the art. Philipp Muth, Matthias Geihs, Tolga Arul, Johannes Buchmann 0001, Stefan Katzenbeisser 0001 |
EURASIP J. Inf. Secur. | 3 |
| 2020 | Low-cost Security for Next-generation IoT NetworksabstractIn recent years, the ubiquitous nature of Internet-of-Things (IoT) applications as well as the pervasive character of next-generation communication protocols, such as the 5G technology, have become widely evident. In this work, we identify the need for low-cost security in current and next-generation IoT networks and address this demand through the implementation, testing, and validation of an intrinsic low-cost and low-overhead hardware-based security primitive within an inherent network component. In particular, an intrinsic Physical Unclonable Function (PUF) is implemented in the peripheral network module of a tri-band commercial off-the-shelf router. Subsequently, we demonstrate the robustness of this PUF to ambient temperature variations and to limited natural aging, and examine in detail its potential for securing the next generation of IoT networks and other applications. Finally, the security of the proposed PUF-based schemes is briefly assessed and discussed. Nikolaos A. Anagnostopoulos, Saad Ahmad, Tolga Arul, Daniel Steinmetzer, Matthias Hollick, Stefan Katzenbeisser 0001 |
ACM Trans. Internet Techn. | 3 |
| 2019 | Security Requirements Engineering in Safety-Critical Railway Signalling NetworksabstractSecuring a safety-critical system is a challenging task, because safety requirements have to be considered alongside security controls. We report on our experience to develop a security architecture for railway signalling systems starting from the bare safety-critical system that requires protection. We use a threat-based approach to determine security risk acceptance criteria and derive security requirements. We discuss the executed process and make suggestions for improvements. Based on the security requirements, we develop a security architecture. The architecture is based on a hardware platform that provides the resources required for safety as well as security applications and is able to run these applications of mixed-criticality (safety-critical applications and other applications run on the same device). To achieve this, we apply the MILS approach, a separation-based high-assurance security architecture to simplify the safety case and security case of our approach. We describe the assurance requirements of the separation kernel subcomponent, which represents the key component of the MILS architecture. We further discuss the security measures of our architecture that are included to protect the safety-critical application from cyberattacks. Markus Heinrich, Tsvetoslava Vateva-Gurova, Tolga Arul, Stefan Katzenbeisser 0001, Neeraj Suri, Henk Birkholz, Andreas Fuchs 0002, Christoph Krauß, Maria Zhdanova, Don Kuzhiyelil, Sergey Tverdyshev, Christian Schlehuber |
Secur. Commun. Networks | 3 |
| 2018 | Low-Temperature Data Remanence Attacks Against Intrinsic SRAM PUFsabstractIn this work, we present the first systematic study of data remanence effects on an intrinsic Static Random Access Memory Physical Unclonable Function (SRAM PUF) implemented on a commercial off-the-shelf (COTS) device in the temperature range between –110 degrees Celsius and –40 degrees Celsius. Based on our experimental results, we propose a new type of attack against intrinsic SRAM PUFs, which takes advantage of data remanence effects exhibited due to low temperatures. We demonstrate that this attack is highly resistant to memory erasure techniques and can be used to manipulate the cryptographic keys produced by the SRAM PUF. Finally, we also discuss and assess potential countermeasures against the attack we propose. Nikolaos A. Anagnostopoulos, Tolga Arul, Markus Rosenstihl, André Schaller, Sebastian Gabmeyer, Stefan Katzenbeisser 0001 |
DSD | 2 |
| 2018 | Security Analysis of the RaSTA Safety ProtocolabstractRaSTA is a transport protocol that has been designed to be deployed in the safety-critical domain of railway signalling. The protocol provides safety properties such as message authenticity, integrity, timeliness, and sequence. However, critical railway infrastructures face cyber attacks and therefore require security measures. We investigate the security properties of RaSTA by analysing weaknesses of the utilized MD4 algorithm in the context where RaSTA is utilized. To overcome the weaknesses, we propose relevant enhancements to the protocol that maintain the safety properties and additionally provide secure message authentication. We evaluate our work using the computation time for message authentication which is crucial for the utilization of RaSTA in a safety-critical network. Markus Heinrich, Jannik Vieten, Tolga Arul, Stefan Katzenbeisser 0001 |
ISI | 3 |
| 2016 | Subscription-free Pay-TV over IPTV
Tolga Arul, Abdulhadi Shoufan |
J. Syst. Archit. | 1 |
| 2011 | A novel architecture for a secure update of cryptographic engines on trusted platform moduleabstractTrusted computing is gaining an increasing acceptance in the industry and finding its way to cloud computing. With this penetration, the question arises whether the concept of hard-wired security modules will cope with the increasing sophistication and security requirements of future IT systems and the ever expanding threats and violations. So far, embedding cryptographic hardware engines into the Trusted Platform Module (TPM) has been regarded as a security feature. However, new developments in cryptanalysis, side-channel analysis, and the emergence of novel powerful computing systems, such as quantum computers, can render this approach useless. Given that, the question arises: Do we have to throw away all TPMs and loose the data protected by them, if someday a cryptographic engine on the TPM becomes insecure? To address this question, we present a novel architecture called Sustainable Trusted Platform Module (STPM), which guarantees a secure update of the TPM cryptographic engines without compromising the system's trustworthiness. The STPM architecture has been implemented as a proof-of-concept on top of a Xilinx Virtex-5 FPGA platform, demonstrating a test case with an update of the fundamental hash engine of the TPM. Sunil Malipatlolla, Thomas Feller 0002, Abdulhadi Shoufan, Tolga Arul, Sorin A. Huss |
FPT | 4 |
| 2011 | A novel architecture for a secure update of cryptographic engines on trusted platform moduleabstractTrusted computing is gaining an increasing acceptance in the industry and finding its way to cloud computing. With this penetration, the question arises whether the concept of hard-wired security modules will cope with the increasing sophistication and security requirements of future IT systems and the ever expanding threats and violations. So far, embedding cryptographic hardware engines into the Trusted Platform Module (TPM) has been regarded as a security feature. However, new developments in cryptanalysis, side-channel analysis, and the emergence of novel powerful computing systems, such as quantum computers, can render this approach useless. Given that, the question arises: Do we have to throw away all TPMs and loose the data protected by them, if someday a cryptographic engine on the TPM becomes insecure? To address this question, we present a novel architecture called Sustainable Trusted Platform Module (STPM), which guarantees a secure update of the TPM cryptographic engines without compromising the system's trustworthiness. The STPM architecture has been implemented as a proof-of-concept on top of a Xilinx Virtex-5 FPGA platform, demonstrating a test case with an update of the fundamental hash engine of the TPM. Sunil Malipatlolla, Thomas Feller 0002, Abdulhadi Shoufan, Tolga Arul, Sorin A. Huss |
FPT | 4 |
| 2011 | A benchmarking environment for performance evaluation of tree-based rekeying algorithms
Abdulhadi Shoufan, Tolga Arul |
J. Syst. Softw. | 2 |