Jan Hajny

dblp:98/7302 · DBLP profile ↗
← Back
37ranked-venue papers
13as first author
15since 2021 · last 2024
0000-0003-2831-1073ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 35 · 12 first-author · 15 since 2021Computer networks · 2 · 1 first-author
YearPublicationVenuePosition
2024 Open-Source Post-Quantum Encryptor: Design, Implementation and Deployment
abstract
This article describes an open-source quantum-resistant network traffic encryptor for the Linux platform. Our encryptor uses a combination of quantum and post-quantum key establishment methods to achieve quantum resistance combined with a fast encryption speed of AES to make quantum-resistant encryption readily available to the public. The packet-by-packet encryption architecture ensures that every bit of information is properly authenticated and encrypted. The combination of multiple key sources further increases the encryptor’s security – be it elliptic curve-based (Elliptic Curve Diffie Hellman, ECDH), quantum (Quantum Key Distribution, QKD) or post-quantum (CRYSTALS-Kyber). Without knowing all the keys obtained from different types of key sources, the final hybrid encryption key can only be obtained by brute-force means. Our contribution is very practical as the encryptor has reasonable performance, despite not being part of the Linux kernel.
Petr Tuma 0004, Jan Hajny, Petr Muzikant, Jan Havlin, Lukas Malina, Patrik Dobias, Jan Willemson
SECRYPT2
2023 Curricula Designer with Enhanced ECSF Analysis
abstract
In late 2022, the novel European Cybersecurity Skills Framework (ECSF) was officially released by the European Union Agency for Cybersecurity (ENISA). It aims to connect cybersecurity education and training with practical needs of the job market. In particular, it maps role profiles, that reflect jobs, to the knowledge and skills they require. One of the first tools that demonstrated ECSF is the Curricula Designer web application that guides cybersecurity study program administrators in designing and analyzing their curricula. In this paper, we present a major update of the Curricula Designer tool. We develop a novel method for course scoring and quantitative analysis of curricula based on the European Credit Transfer and Accumulation System (ECTS) credits. We describe the underlying methods and show their practical implementation into the publicly-available web application. Furthermore, we update the definitions of the Skills, Knowledge and Role Profiles according to the latest ECSF definition and present the mappings in comprehensive matrices in the appendices.
Jan Hajny, Marek Sikora, Konstantinos Adamos, Fabio Di Franco
ARES1
2023 On Deploying Quantum-Resistant Cybersecurity in Intelligent Infrastructures
abstract
As quantum-safe algorithms are increasingly implemented in security protocols used in current and emerging digital services, there is also a corresponding need to map the current state of security protocols and applications and their preparedness for the post-quantum era. In this paper, we review current security recommendations, existing security libraries, and the support of Post-Quantum Cryptography (PQC) in widely-used security protocols. We also present a practical assessment of recently selected PQC algorithms by the National Institute of Standards and Technologies (NIST) PQC standardization on typical platforms that can be deployed in intelligent infrastructures (e.g., smartphones and single-boards), and recently recommended hash-based signatures for software/firmware signing. Finally, we discuss how incoming post-quantum migration affects selected areas in intelligent infrastructures.
Lukas Malina, Patrik Dobias, Jan Hajny, Kim-Kwang Raymond Choo
ARES3
2022 Adding European Cybersecurity Skills Framework into Curricula Designer
abstract
We present the updated version of the Curricula Designer, a tool that is devoted to helping study program administrators and education providers to create cybersecurity curricula that are modern and reflect the needs of the job market. Our main contribution is the inclusion of the European Cybersecurity Skills Framework (ECSF) developed by ENISA to the Curricula Designer. The ECSF makes it possible to directly link knowledge and skills with professional profiles, which in turn reflect actual work roles on the job market. By adding ECSF to the Curricula Designer, we get a simple yet powerful tool that helps to identify the right content of cybersecurity curricula using rigorous, deterministic methods, applicable at any higher education provider. At the time of the paper submission, the Curricula Designer is the first practical application that is based on ECSF. However, due to its focus on practicality, usability and simplicity, we expect ECSF to become the dominant framework for cybersecurity knowledge and skills identification in Europe.
Jan Hajny, Marek Sikora, Athanasios Vasileios Grammatopoulos, Fabio Di Franco
ARES1
2022 On Secure and Side-Channel Resistant Hardware Implementations of Post-Quantum Cryptography
abstract
Currently, many post-quantum cryptography schemes have been implemented on various hardware platforms in order to provide efficient solutions in cybersecurity services. As researchers and hardware developers focus primarily on designs providing small latency and requiring fewer hardware resources, their implementations could seldom omit protection techniques against various physical attacks. This paper studies potential attacks on the cryptography implementations that run on Field-Programmable Gate Array (FPGA) platforms. We mainly analyze how Post-Quantum Cryptography (PQC) implementations could be vulnerable on various platforms. Further, we aim at the FPGA-based implementations of National Institute of Standards and Technology (NIST)’s PQC competition finalists. Our study should present to developers the current overview of attacks and countermeasures that can be implemented on specific PQC schemes on FPGA platforms. Moreover, we present novel implementation of one universal countermeasure component and reveal additional resources that are needed.
Petr Jedlicka, Lukas Malina, Tomas Gerlich, Zdenek Martinasek, Jan Hajny, Petr Socha
ARES5
2022 Security of Smart Grid Networks in the Cyber Ranges
abstract
Smart meters are increasingly a part of everyday households. These smart meters allow remote reading of the energy but also remote disconnection of the point of consumption from the energy supply. As these devices are part of the critical infrastructure of the country, the security of these devices needs to be tested and the relevant personnel trained. We would like to contribute to the scientific community by bringing practical experience from smart meter testing into the Cyber Range virtual environment. In this environment, professionals working with smart meters can be trained and smart meter safety tests can be performed. This paper presents common smart meter vulnerabilities and their demonstration in the Cyber Range environment. The article includes a sample description of scenario for testing so anyone can try it.
Tomás Lieskovan, Jan Hajny
ARES2
2022 Implementation of Revocable Keyed-Verification Anonymous Credentials on Java Card
abstract
Java Card stands out as a good choice for the development of smart card applications due to the high interoperability between different manufacturers, its security, and wide support of cryptographic algorithms. Despite extensive cryptographic support, current Java Cards do not support non-standard cryptographic algorithms such as post-quantum, secure-multiparty computations, and privacy-enhancing cryptographic schemes. Moreover, Java Card is restricted by the Application Programming Interface (API) in algebraic operations, which are the foundation of modern cryptographic schemes. This paper addresses the issue of developing these modern schemes by exploiting the limited cryptographic API provided by these types of cards. We show how to (ab)use the Java Card’s API to perform modular arithmetic operations, as well as basic operations on elliptic curves. Furthermore, we implement an attribute-based privacy-enhancing scheme on an off-the-shelf Java Card. To do so, we use our cryptographic API and several optimization techniques to make the scheme as efficient as possible. To demonstrate the practicality of our solution, we present the implementation results and benchmark tests.
Raúl Casanova Marqués, Petr Dzurenda, Jan Hajny
ARES3
2022 On the Efficiency and Security of Quantum-resistant Key Establishment Mechanisms on FPGA Platforms
Lukas Malina, Sara Ricci, Patrik Dobias, Petr Jedlicka, Jan Hajny, Kim-Kwang Raymond Choo
SECRYPT5
2021 Secret Sharing-based Authenticated Key Agreement Protocol
abstract
In this article, we present two novel authenticated key agreement (AKA) schemes that are easily implementable and efficient even on constrained devices. Both schemes are constructed over elliptic curves and extend Schonorr’s signature of knowledge protocol. To the best of our knowledge, we introduce a first AKA protocol based on the proof of knowledge concept. This concept allows a client to prove its identity to a server via secret information while the server can learn nothing about the secret. Furthermore, we extend our protocol via secret sharing to support client multi-device authentication and multi-factor authentication features. In particular, the secret of the client can be distributed among the client’s devices.
Petr Dzurenda, Sara Ricci, Raúl Casanova Marqués, Jan Hajny, Petr Cika
ARES4
2021 Cybersecurity Curricula Designer
abstract
The paper aims at minimizing the skills gaps and skills shortages on the cybersecurity job market by empowering education and training institutions during the process of creation of new cybersecurity study programs. We provide a complex cybersecurity skills framework based on standardized definitions that helps with the identification of skills and knowledge necessary for cybersecurity work positions. Furthermore, we practically implement the framework in the form of an interactive web application for cybersecurity curricula design. The app, called Curricula Designer, is built upon the framework and allows intuitive design of higher-education curricula and their analysis with respect to requirements of work roles already defined in widely-accepted standards. Using the analytical functions, it is easy to identify missing content in the courses and precisely structure the study program so that the graduates are well-prepared to enter the job market. The Curricula Designer is described in details in this paper, including user interface and technical background, and a link for public free access is provided to serve all education and training institutions.
Jan Hajny, Sara Ricci, Edmundas Piesarskas, Marek Sikora
ARES1
2021 Building Open Source Cyber Range To Teach Cyber Security
abstract
This paper deals with the use of cyber range in education to teach cybersecurity. Particular attention is paid exclusively to open-source solutions, as such solutions are available to the general public, which is essential in raising awareness of cyber defense. First,the available open-source cyber ranges are described, their advantages and disadvantages. Subsequently, it presents our selected solution, the procedure of implementation in the Brno University of Technology laboratory, our use in our study programe and stress testing of selected cyber range. Last but not least, it provides a unique guide to designing and building own open-source cyber range LAB from scratch.
Tomás Lieskovan, Jan Hajny
ARES2
2021 PESTLE Analysis of Cybersecurity Education
abstract
Cybersecurity is a vital part of digital economies and digital governing but the discipline is suffering from a pronounced skills shortage. Nevertheless, the reasons for the inability of academia to produce enough graduates with the skills that reflect the needs of the cybersecurity industry are not well understood.
Sara Ricci, Vladimir Janout, Simon Parker, Jan Jerabek, Jan Hajny, Argyro Chatzopoulou, Rémi Badonnel
ARES5
2021 Implementing CRYSTALS-Dilithium Signature Scheme on FPGAs
abstract
In July 2020, the lattice-based CRYSTALS-Dilithium digital signature scheme has been chosen as one of the three third-round finalists in the post-quantum cryptography standardization process by the National Institute of Standards and Technology (NIST). In this work, we present the first Very High Speed Integrated Circuit Hardware Description Language (VHDL) implementation of the CRYSTALS-Dilithium signature scheme for Field-Programmable Gate Arrays (FPGAs). Due to our parallelization-based design requiring only low numbers of cycles, running at high frequency and using reasonable amount of hardware resources on FPGA, our implementation is able to sign 15832 messages per second and verify 10524 signatures per second. In particular, the signing algorithm requires 68461 Look-Up Tables (LUTs), 86295 Flip-Flops (FFs), and the verification algorithm takes 61738 LUTs and 34963 FFs on Virtex 7 UltraScale+ FPGAs. In this article, experimental results for each Dilithium security level are provided and our VHDL-based implementation is compared with related High-Level Synthesis (HLS)-based implementations. Our solution is ca 114 times faster (in the signing algorithm) and requires less hardware resources.
Sara Ricci, Lukas Malina, Petr Jedlicka, David Smékal, Jan Hajny, Peter Cíbik, Petr Dzurenda, Patrik Dobias
ARES5
2021 Anonymous Attribute-based Credentials in Collaborative Indoor Positioning Systems
abstract
Collaborative Indoor Positioning Systems have recently received considerable attention, mainly because they address some of the existing limitations of traditional Indoor Positioning System. In Collaborative Indoor Positioning Systems, Bluetooth Low Energy can be used to exchange positioning data and provide information (the Received Signal Strength Indicator) to establish the relative distance between the actors. The collaborative models exploit the position of actors and the relative position among them to allow positioning to external actors or improve the accuracy of the existing actors. However, the traditional protocols (e.g. iBeacon) are not yet ready for providing sufficient privacy protection. Therefore, this paper deals with privacy-enhancing technologies and their application in Collaborative Indoor Positioning System. In particular, we focus on cryptographic schemes which allow the verification of users without their identification, so-called Anonymous Attribute-Based Credentials schemes. As the main contribution, we present a cryptographic scheme that allows security and privacy-friendly sharing of location information sent through Bluetooth Low Energy advertising packets. In order to demonstrate the practicality of our scheme, we also present the results from our implementation and benchmarks on different devices.
Raúl Casanova Marqués, Pavel Pascacio, Jan Hajny, Joaquín Torres-Sospedra
SECRYPT3
2021 Towards CRYSTALS-Kyber VHDL Implementation
abstract
Kyber is one of the three finalists of the National Institute of Standards and Technology (NIST) post-quantum cryptography competition. This article presents an optimized Very High Speed Integrated Circuit Hardware Description Language (VHDL)-based implementation of the main components of the Kyber scheme, namely Number-Theoretic Transform (NTT) and Keccak. We focus specifically on NTT, Keccak and their derivatives since they largely determine Kyber's performance due to their wide involvement in each step of the scheme. Our high-speed implementation also takes into account the trade-off between the degree of parallelization and the resources utilization. The NTT component is more than 27\% faster than the state-of-the-art implementations. Furthermore, the optimization helps the algorithm to achieve 1 572 839 NTT operations per second.
Sara Ricci, Petr Jedlicka, Peter Cíbik, Petr Dzurenda, Lukas Malina, Jan Hajny
SECRYPT6
2019 A Secure Publish/Subscribe Protocol for Internet of Things
abstract
The basic concept behind the emergence of Internet of Things (IoT) is to connect as many objects to the Internet as possible in an attempt to make our lives better in some way. However, connecting everyday objects like your car or house to the Internet can open up major security concerns. In this paper, we present a novel security framework for the Message Queue Transport Telemetry (MQTT) protocol based on publish/subscribe messages in order to enhance secure and privacy-friendly Internet of Things services. MQTT has burst onto the IoT scene in recent years due to its lightweight design and ease of use implementation necessary for IoT. Our proposed solution provides 3 security levels. The first security level suits for lightweight data exchanges of non-tampered messages. The second security level enhances the privacy protection of data sources and data receivers. The third security level offers robust long-term security with mutual authentication for all parties. The security framework is based on light cryptographic schemes in order to be suitable for constrained and small devices that are widely used in various IoT use cases. Moreover, our solution is tailored to MQTT without using additional security overhead.
Lukas Malina, Gautam Srivastava 0001, Petr Dzurenda, Jan Hajny, Radek Fujdiak
ARES4
2019 A Privacy-Enhancing Framework for Internet of Things Services
Lukas Malina, Gautam Srivastava 0001, Petr Dzurenda, Jan Hajny, Sara Ricci
NSS4
2019 Fast Keyed-Verification Anonymous Credentials on Standard Smart Cards
Jan Camenisch, Manu Drijvers, Petr Dzurenda, Jan Hajny
SEC4
2018 Secure and efficient two-factor zero-knowledge authentication solution for access control systems
Lukas Malina, Petr Dzurenda, Jan Hajny, Zdenek Martinasek
Comput. Secur.3
2018 Multidevice Authentication with Strong Privacy Protection
abstract
Card‐based physical access control systems are used by most people on a daily basis, for example, at work, in public transportation, or at hotels. Yet these systems have often very poor cryptographic protection. User identifiers and keys can be easily eavesdropped on and counterfeited. The privacy‐preserving features are almost missing in these systems. To improve this state, we propose a novel cryptographic scheme based on efficient zero‐knowledge proofs and Boneh‐Boyen signatures. The proposed scheme is provably secure and provides the full set of privacy‐enhancing features, that is, the anonymity, untraceability, and unlinkability of users. Furthermore, our scheme supports distributed multidevice authentication with multiple RFID (Radio‐Frequency IDentification) user devices. This feature is particularly important in applications for controlling access to dangerous sites where the presence of protective equipment is checked during each access control session. Besides the full cryptographic specification, we also show the results of our implementation on devices commonly used in access control applications, particularly the smart cards and embedded verification terminals. By avoiding costly operations on user devices, such as bilinear pairings, we were able to achieve times comparable to existing systems (around 500 ms), while providing significantly higher security, privacy protection, and features for RFID multidevice authentication.
Jan Hajny, Petr Dzurenda, Lukas Malina
Wirel. Commun. Mob. Comput.1
2017 Performance Analysis and Comparison of Different Elliptic Curves on Smart Cards
abstract
Elliptic curves are very often used in the cryptographic protocol design due to their memory efficiency and useful features, such as the bilinear pairing support. However, in many cryptographic papers, elliptic curves are used as a black box, without deeper consideration of their mathematical properties and, even more importantly, without considering implementation implications. As a consequence, novel cryptographic schemes are being published without any real chance of implementation on constrained devices due to their lack of support of basic EC operations like point addition or scalar point multiplication. This paper provides the necessary theoretical overview of main forms of elliptic curves, in particular considering their computational and memory complexity. Next, all major platforms of programmable smart cards are evaluated with respect to EC support and the performance of basic arithmetic operations is assessed using benchmarks. Finally, the evaluation of the implementations of ECC schemes, such as ECDH and ECDSA, is presented.
Petr Dzurenda, Sara Ricci, Jan Hajny, Lukas Malina
PST3
2017 Anonymous Credentials with Practical Revocation using Elliptic Curves
Petr Dzurenda, Jan Hajny, Lukas Malina, Sara Ricci
SECRYPT2
2016 Multi-Device Authentication using Wearables and IoT
abstract
The paper presents a novel cryptographic authentication scheme that makes use of the presence of electronic devices around users. The scheme makes authentication more secure by involving devices that are usually worn by users (such as smart-watches, fitness bracelets and smart-cards) or are in their proximity (such as sensors, home appliances, etc.). In our scheme, the user private key is distributed over all personal devices thus cannot be compromised by breaking into only a single device. Furthermore, involving wearables and IoT devices makes it possible to use multiple authentication factors, such as user's position, his behavior and the state of the surrounding environment. We provide the full cryptographic specification of the protocol, its formal security analysis and the implementation results in this paper.
Jan Hajny, Petr Dzurenda, Lukas Malina
SECRYPT1
2016 On perspective of security and privacy-preserving solutions in the internet of things
Lukas Malina, Jan Hajny, Radek Fujdiak, Jiri Hosek
Comput. Networks2
2016 Light-weight group signatures with time-bound membership
abstract
Abstract This paper presents a novel privacy‐preserving cryptographic protocol for secure many‐to‐one communication systems, for example, data collection systems, data gathering systems, vehicular networks, smart‐grids, and so on. The proposed solution provides message authenticity, integrity, and non‐repudiation, while message senders are anonymous and untraceable. The protocol is based on group signatures with a time‐bound membership. The protocol is designed to achieve efficiency on the client side where restricted devices are usually employed. On the other hand, the verification of many messages is efficient as well. Common group signature schemes offer the verification phase that needs some pairing operations and employs a long revocation list. Generally, the revocation list grows until scheme parameters and keys are recomputed. However, the reinitialization of all keys and parameters is not practical in large‐scale communication systems. By applying the optimization techniques on the group signature scheme, the verification phase becomes more efficient, and the expiration of group member secret keys naturally reduces the length of a revocation list. In addition to the full cryptographic description, we implement the proposed protocol and outline the performance results. Copyright © 2015 John Wiley & Sons, Ltd.
Lukas Malina, Jan Hajny, Vaclav Zeman
Secur. Commun. Networks2
2015 Privacy-Enhanced Data Collection Scheme for Smart-Metering
Jan Hajny, Petr Dzurenda, Lukas Malina
Inscrypt1
2015 Secure Physical Access Control with Strong Cryptographic Protection
abstract
This paper is focused on the area of physical access control systems (PACs), particularly on the systems for building access control. We show how the application of modern cryptographic protocols, namely the cryptographic proofs of knowledge, can improve the security and privacy protection in practical access control systems. We propose a novel scheme SPAC (Secure Physical Access Control) based on modern cryptographic primitives. By employing the proofs of knowledge, the authentication process gets more secure and privacy friendly in comparison to existing schemes without negative influence on the implementation complexity or system performance. In this paper, we describe the weaknesses of existing schemes, show the full cryptographic specification of the novel SPAC scheme including its security proofs and provide benchmarks on off-the-shelf devices used in real commercial systems. Furthermore we show, that the transition from an old insecure system to strong authentication can be ea sy and cost-effective
Jan Hajny, Petr Dzurenda, Lukas Malina
SECRYPT1
2015 Towards Secure Gigabit Passive Optical Networks - Signal Propagation based Key Establishment
abstract
Nowadays, the Passive Optical Networks (PONs) technology is widely deployed in broadband access networks. This paper deals with the security issues of Gigabit PON (GPON) standardized by the International Telecommunications Union (ITU), namely, standard ITU-T G.984 that is widely implemented in Europe these days. We describe and analyze the security of this standard and show its security risks. In spite of that transmitted data are encrypted to provide their confidentiality on a multipoint fibre connection, session secret keys during their establishment can be observed by adversaries. To address this security flaw, we propose a key establishment protocol that securely sets the session secret keys between two communication parties in GPON. Furthermore, we provide the security analysis of the proposed protocol.
Lukas Malina, Petr Munster, Jan Hajny, Tomás Horváth
SECRYPT3
2015 Attribute-based credentials with cryptographic collusion prevention
abstract
Abstract Cryptographic attribute‐based credentials (ABCs) allow users to prove their personal attributes remotely and in a privacy‐friendly way. While staying anonymous and untraceable, the users are able to prove their attributes, such as age, membership, or nationality, before using a network service. Unfortunately, there are very few practical cryptographic ABC schemes available today. Furthermore, some existing schemes rely on the hardware tamper‐resistance of smart cards to avoid collusion attacks. The trust in hardware limits the usage of such schemes on poorly protected cards and on smart phones. In this paper, we present the full cryptographic specification of an ABC scheme, which makes the collusion attacks impossible even on insecure hardware like mobile phones. Furthermore, the scheme provides features, which are difficult to achieve using existing schemes, namely the practical revocation of users, the de‐anonymization of malicious users, and the unlinkability of verification sessions. Besides the cryptographic architecture, we also present our practical implementation on a smart phone and embedded platforms. Copyright © 2015 John Wiley & Sons, Ltd.
Jan Hajny, Petr Dzurenda, Lukas Malina
Secur. Commun. Networks1
2014 Privacy-preserving framework for geosocial applications
abstract
ABSTRACT The paper deals with user privacy in geosocial applications. Geosocial applications have become very popular but can misuse user's private data and location. We propose a novel solution that prevents tracking and protects against personal identity and location being misused by external attackers or service providers. The proposed framework provides security and privacy protection for geosocial applications that provide, for example, information sharing, geotagging, and monitoring of people without revealing their identity to unauthorized persons, including the service provider. Unlike current security solutions in geosocial services, our novel framework uses advanced cryptography to secure user privacy. This protection is provided by advanced group signatures ensuring data integrity, authenticity, non‐repudiation, and strong privacy protection. The paper outputs a detailed cryptographic scheme for the protection of privacy in geosocial services and its security analysis. The proposed scheme has also been implemented, and the performance results are outlined in the paper. Copyright © 2013 John Wiley & Sons, Ltd.
Lukas Malina, Jan Hajny
Secur. Commun. Networks2
2013 Optimization of Power Analysis Using Neural Network
Zdenek Martinasek, Jan Hajny, Lukas Malina
CARDIS2
2013 Privacy-preserving SVANETs - Privacy-preserving Simple Vehicular Ad-hoc Networks
Jan Hajny, Lukas Malina, Zdenek Martinasek, Vaclav Zeman
SECRYPT1
2013 Efficient Group Signatures with Verifier-local Revocation Employing a Natural Expiration
Lukas Malina, Jan Hajny, Zdenek Martinasek
SECRYPT2
2012 Unlinkable Attribute-Based Credentials with Practical Revocation on Smart-Cards
Jan Hajny, Lukas Malina
CARDIS1
2011 Practical Anonymous Authentication - Designing Anonymous Authentication for Everyday Use
Jan Hajny, Lukas Malina, Vaclav Zeman
SECRYPT1
2010 Privacy Protection for user Authentication
Jan Hajny, Tomas Pelka, Vaclav Zeman
SECRYPT1
2009 Universal Authentication Framework - Requirements and Phase Design
Jan Hajny, Tomas Pelka, Petra Lambertova
SECRYPT1