Nikita Yadav

dblp:133/8422 · DBLP profile ↗
← Back
5ranked-venue papers
2as first author
5since 2021 · last 2025
0009-0009-2916-2875ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 2 first-author · 4 since 2021Systems, architecture and hardware · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Non-Bare-Metal User-Space Control-Flow Attestation
abstract
Control-flow attestation (CFA) allows a verifier$\mathcal{V}$to obtain fine-grained measurements of a program$\mathcal{P}$executing on a remote computing platform. This CFA measurement allows$\mathcal{V}$to precisely audit the program path followed within$\mathcal{P}$as it executes an input$I$. However, CFA measurements must be collected and stored securely, e.g., in a TEE on the platform where$\mathcal{P}$executes, failing which it will not be an accurate record of$\mathcal{P}$'s execution. These requirements are satisfied relatively easily when$\mathcal{P}$executes atop bare hardware, as most prior CFA approaches have assumed. This paper considers non-bare-metal settings in which$\mathcal{P}$executes as a user-level process atop an OS on the remote computing platform. Prior approaches to CFA are insecure in the presence of OS-level adversaries. We describe the design and implementation of a system called Sulfurthat securely enables CFA of user-space applications in non-bare-metal settings. Sulfuraccomplishes this goal via a co-developed OS called Sulfuros. Sulfuros makes novel use of security extensions available in commodity AArch64 hardware—privileged-access never and privileged-execute never. We experimentally show that Sulfurenables secure CFA with low additional runtime overheads in non-bare-metal settings.
Nikita Yadav, Hrushikesh Salunke, Dev Tejas Gandhi, Vinod Ganapathy
ACSAC1
2024 Proof of Backhaul: Trustfree Measurement of Broadband Bandwidth
Peiyao Sheng, Nikita Yadav, Vishal Sevani, Arun Babu, S. V. R. Anand, Himanshu Tyagi, Pramod Viswanath
NDSS2
2024 Orbital Trust and Privacy: SoK on PKI and Location Privacy Challenges in Space Networks
David Koisser, Richard Mitev, Nikita Yadav, Franziska Vollmer, Ahmad-Reza Sadeghi
USENIX Security Symposium3
2023 Whole-Program Control-Flow Path Attestation
abstract
Path attestation is an approach to remotely attest the execution of a program ℘. In path attestation, a prover platform, which executes ℘, convinces a remote verifier V of the integrity of ℘ by recording the path that ℘ takes as it executes a particular input. While a number of prior techniques have been developed for path attestation, they have generally been applied to record paths only for parts of the execution of ℘. In this paper, we consider the problem of whole program control-flow path attestation, i.e., to attest the execution of the entire program path in ℘. We show that prior approaches for path attestation use sub-optimal techniques that fundamentally fail to scale to whole program paths, and impose a large runtime overhead on the execution of ℘. We then develop Blast, an approach that reduces these overheads using a number of novel approaches inspired by prior work from the program profiling literature. Our experiments show that Blast makes path attestation more practical for use on a wide variety of embedded programs.
Nikita Yadav, Vinod Ganapathy
CCS1
2023 A Contributory Public-Event Recording and Querying System
abstract
CCTV (Closed-Circuit Television) systems are commonly used for security and surveillance. They provide a visual record of events, which can be used to monitor criminal activity, support investigations, and improve public safety. Many cities have implemented a number of cameras for surveillance, with Delhi, India having 1446 cameras per square mile. These cameras are installed mainly by official traffic police or city authorities, but private organizations and individuals also have their cameras pointed toward public spaces. In many cases, the city authorities or police require query capability and access of the video feed from these CCTV cameras to perform diligent inquiries but the private entities usually do not share the raw footage due to various concerns.
Nikita Yadav, Vinod Ganapathy, Dushyant Behl
SEC2