EDBT 2026 Demo / reviewers in the wild / expert
Diethelm Ostry
dblp:14/5304 · also D. I. Ostry, Diet Ostry
· DBLP profile ↗
33ranked-venue papers
1as first author
2since 2021 · last 2022
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 17Security and privacy · 9 · 1 since 2021Systems, architecture and hardware · 1Software engineering, systems software and programming languages · 1 · 1 since 2021Theory of computation · 1 · 1 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
6 papers |
Authentication and access control · 32% Web and mobile security · 32% Cryptographic primitives and cryptanalysis · 12% | |
| Computer networks
11 papers |
Wireless sensing and localization · 24% Internet of things and sensor networks · 17% Routing and switching · 15% | |
| Computer architecture, parallel and distributed computing, and storage systems
1 paper |
Energy-efficient computing · 100% | |
| Theoretical computer science
1 paper |
Information theory · 100% |
Topics — the 30 heaviest of 44, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Web and mobile security › mobile security
android application security |
0.6 | 1 | 2022 | Orchestration or Automation: Authentication Flaw Detection in Android Apps · IEEE Trans. Dependable Secur. Comput. 2022 |
Authentication and access control › authentication
authentication flaw detection |
0.6 | 1 | 2022 | Orchestration or Automation: Authentication Flaw Detection in Android Apps · IEEE Trans. Dependable Secur. Comput. 2022 |
Web and mobile security
mobile application security |
0.6 | 1 | 2022 | Orchestration or Automation: Authentication Flaw Detection in Android Apps · IEEE Trans. Dependable Secur. Comput. 2022 |
Authentication and access control
password authentication |
0.6 | 1 | 2022 | Orchestration or Automation: Authentication Flaw Detection in Android Apps · IEEE Trans. Dependable Secur. Comput. 2022 |
Web and mobile security
mobile security |
0.5 | 1 | 2021 | Fine with "1234"? An Analysis of SMS One-Time Password Randomness in Android Apps · ICSE 2021 |
Authentication and access control › password authentication
one-time password |
0.5 | 1 | 2021 | Fine with "1234"? An Analysis of SMS One-Time Password Randomness in Android Apps · ICSE 2021 |
Cyber-physical and IoT security › wireless sensor network security
body area network security |
0.4 | 2 | 2014 | Securing First-Hop Data Provenance for Bodyworn Devices Using Wireless Link Fingerprints · IEEE Trans. Inf. Forensics Secur. 2014 Securing data provenance in body area networks using lightweight wireless link fingerprints · SenSys 2013 |
Digital forensics and information hiding
data provenance |
0.4 | 2 | 2014 | Securing First-Hop Data Provenance for Bodyworn Devices Using Wireless Link Fingerprints · IEEE Trans. Inf. Forensics Secur. 2014 Securing data provenance in body area networks using lightweight wireless link fingerprints · SenSys 2013 |
Routing and switching
router architecture |
0.2 | 1 | 2016 | Greening Router Line-Cards via Dynamic Management of Packet Memory · IEEE J. Sel. Areas Commun. 2016 |
Energy-efficient computing
power management |
0.2 | 1 | 2016 | Greening Router Line-Cards via Dynamic Management of Packet Memory · IEEE J. Sel. Areas Commun. 2016 |
Wireless sensing and localization › ranging
acoustic ranging |
0.2 | 2 | 2010 | Long-range detection in acoustic sensor networks · IPSN 2010 Analysis of an omni-directional narrowband ultrasonic receiver and CSS-based broadband transmission · SenSys 2009 |
Cryptographic primitives and cryptanalysis
key generation |
0.2 | 1 | 2014 | Eliminating Reconciliation Cost in Secret Key Generation for Body-Worn Health Monitoring Devices · IEEE Trans. Mob. Comput. 2014 |
Cryptographic primitives and cryptanalysis › key generation
physical-layer key generation |
0.2 | 1 | 2014 | Eliminating Reconciliation Cost in Secret Key Generation for Body-Worn Health Monitoring Devices · IEEE Trans. Mob. Comput. 2014 |
Cryptographic protocols and secure computation › key exchange
secret key generation |
0.2 | 1 | 2014 | Eliminating Reconciliation Cost in Secret Key Generation for Body-Worn Health Monitoring Devices · IEEE Trans. Mob. Comput. 2014 |
Network security › secure communication › secure communication protocol
TLS |
0.2 | 1 | 2022 | Orchestration or Automation: Authentication Flaw Detection in Android Apps · IEEE Trans. Dependable Secur. Comput. 2022 |
Optical networks › optical switching
optical packet switching |
0.2 | 2 | 2009 | Packet pacing in small buffer optical packet switched networks · IEEE/ACM Trans. Netw. 2009 Packet Pacing in Short Buffer Optical Packet Switched Networks · INFOCOM 2006 |
Transport protocols and congestion control › rate control
packet pacing |
0.2 | 2 | 2009 | Packet pacing in small buffer optical packet switched networks · IEEE/ACM Trans. Netw. 2009 Packet Pacing in Short Buffer Optical Packet Switched Networks · INFOCOM 2006 |
Cryptographic primitives and cryptanalysis
pseudorandom generators |
0.1 | 1 | 2021 | Fine with "1234"? An Analysis of SMS One-Time Password Randomness in Android Apps · ICSE 2021 |
Internet of things and sensor networks › wireless sensor network
sensor network programming |
0.1 | 1 | 2011 | Secure Multihop Network Programming with Multiple One-Way Key Chains · IEEE Trans. Mob. Comput. 2011 |
Cryptographic primitives and cryptanalysis
hash chains |
0.1 | 1 | 2011 | Secure Multihop Network Programming with Multiple One-Way Key Chains · IEEE Trans. Mob. Comput. 2011 |
Cryptographic protocols and secure computation
key management |
0.1 | 1 | 2011 | Secure Multihop Network Programming with Multiple One-Way Key Chains · IEEE Trans. Mob. Comput. 2011 |
Internet architecture and protocols › buffer management
buffer sizing |
0.1 | 1 | 2009 | Packet pacing in small buffer optical packet switched networks · IEEE/ACM Trans. Netw. 2009 |
Physical-layer communications › modulation › chirp modulation
chirp spread spectrum |
0.1 | 1 | 2009 | Analysis of an omni-directional narrowband ultrasonic receiver and CSS-based broadband transmission · SenSys 2009 |
Wireless sensing and localization
indoor localization |
0.1 | 1 | 2009 | Analysis of an omni-directional narrowband ultrasonic receiver and CSS-based broadband transmission · SenSys 2009 |
Transport protocols and congestion control › TCP performance
link asymmetry |
0.1 | 1 | 2009 | Characterization of link asymmetry in wireless sensor networks · SenSys 2009 |
Physical-layer communications
spread spectrum |
0.1 | 1 | 2009 | Analysis of an omni-directional narrowband ultrasonic receiver and CSS-based broadband transmission · SenSys 2009 |
Internet of things and sensor networks
wireless sensor network |
0.1 | 1 | 2009 | Characterization of link asymmetry in wireless sensor networks · SenSys 2009 |
Routing and switching › packet switch › router
core router |
0.1 | 1 | 2016 | Greening Router Line-Cards via Dynamic Management of Packet Memory · IEEE J. Sel. Areas Commun. 2016 |
Optical networks
packet-switched optical network |
0.1 | 1 | 2006 | Packet Pacing in Short Buffer Optical Packet Switched Networks · INFOCOM 2006 |
Transport protocols and congestion control
TCP performance |
0.1 | 1 | 2006 | Packet Pacing in Short Buffer Optical Packet Switched Networks · INFOCOM 2006 |
Methods — techniques the papers use, named apart from their topics
static analysis · 1.1orchestration · 0.6dependency analysis · 0.6simulation · 0.6testbed implementation · 0.5reverse engineering · 0.5analytical modeling · 0.5link fingerprint generation · 0.4filtering · 0.4entropy analysis · 0.4channel probing · 0.4symmetric spatio-temporal characteristics · 0.3link fingerprints · 0.3one-way hash chain · 0.1newton-raphson · 0.1iterative projection · 0.1finite impulse response filter · 0.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | Orchestration or Automation: Authentication Flaw Detection in Android AppsabstractPasswords are pervasively used to authenticate users’ identities in mobile apps. To secure passwords against attacks, protection is applied to the password authentication protocol (PAP). The implementation of the protection scheme becomes an important factor in protecting PAP against attacks. We focus on two basic protection in Android, i.e., SSL/TLS-based PAP and timestamp-based PAP. Previously, we proposed an automated tool,GLACIATE, to detect authentication flaws. We were curious whether orchestration (i.e., involving manual-effort) works better than automation. To answer this question, we propose an orchestrated approach,AuthExploitand compare its effectivenessGLACIATE. We study requirements for correct implementation of PAP and then applyGLACIATEto identify protection enhancements automatically. Through dependency analysis,GLACIATEmatches the implementations against the abstracted flaws to recognise defective apps. To evaluateAuthExploit, we collected 1,200 Android apps from Google Play. We comparedAuthExploitwith the automation tool,GLACIATE, and two other orchestration tools,${\sf MalloDroid}$and${\sf SMV-Hunter}$. The results demonstrated that orchestration tools detect flaws more precisely although the F1 score ofGLACIATEis higher thanAuthExploit. Further analysis of the results reveals that highly popular apps and e-commerce apps are not more secure than other apps. Siqi Ma 0001, Juanru Li, Surya Nepal, Diethelm Ostry, David Lo 0001, Sanjay K. Jha, Robert H. Deng, Elisa Bertino |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2021 | Fine with "1234"? An Analysis of SMS One-Time Password Randomness in Android AppsabstractA fundamental premise of SMS One-Time Password (OTP) is that the used pseudo-random numbers (PRNs) are uniquely unpredictable for each login session. Hence, the process of generating PRNs is the most critical step in the OTP authentication. An improper implementation of the pseudo-random number generator (PRNG) will result in predictable or even static OTP values, making them vulnerable to potential attacks. In this paper, we present a vulnerability study against PRNGs implemented for Android apps. A key challenge is that PRNGs are typically implemented on the server-side, and thus the source code is not accessible. To resolve this issue, we build an analysis tool, OTP-Lint, to assess implementations of the PRNGs in an automated manner without the source code requirement. Through reverse engineering, OTP-Lint identifies the apps using SMS OTP and triggers each app's login functionality to retrieve OTP values. It further assesses the randomness of the OTP values to identify vulnerable PRNGs. By analyzing 6,431 commercially used Android apps downloaded from Google Play and Tencent Myapp, OTP-Lint identified 399 vulnerable apps that generate predictable OTP values. Even worse, 194 vulnerable apps use the OTP authentication alone without any additional security mechanisms, leading to insecure authentication against guessing attacks and replay attacks. Siqi Ma 0001, Juanru Li, Hyoungshick Kim, Elisa Bertino, Surya Nepal, Diethelm Ostry, Cong Sun 0001 |
ICSE | 6 |
| 2019 | An empirical study of SMS one-time password authentication in Android appsabstractA great quantity of user passwords nowadays has been leaked through security breaches of user accounts. To enhance the security of the Password Authentication Protocol (PAP) in such circumstance, Android app developers often implement a complementary One-Time Password (OTP) authentication by utilizing the short message service (SMS). Unfortunately, SMS is not specially designed as a secure service and thus an SMS One-Time Password is vulnerable to many attacks. To check whether a wide variety of currently used SMS OTP authentication protocols in Android apps are properly implemented, this paper presents an empirical study against them. We first derive a set of rules from RFC documents as the guide to implement secure SMS OTP authentication protocol. Then we implement an automated analysis system, AUTH-EYE, to check whether a real-world OTP authentication scheme violates any of these rules. Without accessing server source code, AUTH-EYE executes Android apps to trigger the OTP-relevant functionalities and then analyzes the OTP implementations including those proprietary ones. By only analyzing SMS responses, AUTH-EYE is able to assess the conformance of those implementations to our recommended rules and identify the potentially insecure apps. In our empirical study, AUTH-EYE analyzed 3,303 popular Android apps and found that 544 of them adopt SMS OTP authentication. The further analysis of AUTH-EYE demonstrated a far-from-optimistic status: the implementations of 536 (98.5%) out of the 544 apps violate at least one of our defined rules. The results indicate that Android app developers should seriously consider our discussed security rules and violations so as to implement SMS OTP properly. Siqi Ma 0001, Runhan Feng, Juanru Li, Yang Liu 0118, Surya Nepal, Diethelm Ostry, Elisa Bertino, Robert H. Deng, Zhuo Ma 0001, Sanjay K. Jha |
ACSAC | 6 |
| 2019 | Finding Flaws from Password Authentication Code in Android Apps
Siqi Ma 0001, Elisa Bertino, Surya Nepal, Juanru Li, Diethelm Ostry, Robert H. Deng, Sanjay K. Jha |
ESORICS (1) | 5 |
| 2017 | A Novel Algorithm for Secret Key Generation in Passive Backscatter Communication Systems
Mohammad Hossein Chinaei, Diethelm Ostry, Vijay Sivaraman |
CANS | 2 |
| 2017 | An experimental study of secret key generation for passive Wi-Fi wearable devicesabstractPassive Wi-Fi is a technology to generate 802.11b transmissions using backscatter communication, with power consumption 10000× lower than existing Wi-Fi chipsets. Since wearable devices are typically limited in resources such as power and storage, classical cryptographic security schemes are problematic for them. We instead propose to use wireless channel characteristics to secure data transfer. It has been shown that communicating wireless transceivers are able to generate shared secret keys by measuring channel characteristics at a single frequency. These methods are not applicable to passive Wi-Fi, which uses two different frequencies. In this paper, we describe a method to generate a shared secret key based on wireless channel characteristics in the passive Wi-Fi scenario where the two parties are using dual frequencies. Mohammad Hossein Chinaei, Vijay Sivaraman, Diethelm Ostry |
WoWMoM | 3 |
| 2016 | Greening Router Line-Cards via Dynamic Management of Packet MemoryabstractContinued scaling of switching capacity in the Internet core is threatened by power considerations. Internet service providers face increased carbon footprint and operational costs, while router manufacturers encounter upper limits on switching capacity per rack. This paper studies the role of packet buffer memory on the power consumption of backbone routers. Our first contribution is to estimate from published datasheets the energy costs of static RAM/dynamic RAM packet-buffer memory, showing that it accounts for over 10% of power consumption in a typical router line-card; we then show, using empirical data from core and enterprise networks, that much of this memory is used for only a small fraction of time. Our second contribution is to develop a simple yet practical algorithm for putting much of the memory components to sleep and waking them as needed, while being able to control resulting traffic performance degradation in the form of packet loss during transient congestion. Finally, we conduct a comprehensive evaluation of our scheme, via analytical models pertaining to long-range-dependent traffic, using simulations of offline traffic traces taken from carrier/enterprise networks as well as online Transmission Control Protocol flows in ns2, and by implementing our scheme on a programmable-router test bed. This paper is the first to show the feasibility of, and energy savings from, dynamic management of packet buffer memory in core routers in the market today. Vijay Sivaraman, Arun Vishwanath, Diethelm Ostry, Marina Thottan |
IEEE J. Sel. Areas Commun. | 3 |
| 2014 | Authentication of lossy data in body-sensor networks for cloud-based healthcare monitoring
Syed Taha Ali, Vijay Sivaraman, Diethelm Ostry |
Future Gener. Comput. Syst. | 3 |
| 2014 | Securing First-Hop Data Provenance for Bodyworn Devices Using Wireless Link FingerprintsabstractWireless bodyworn sensing devices are fast becoming popular for fitness, sports training, and personalized healthcare applications. Securing data generated by these devices is essential if they are to be integrated into the current health infrastructure and employed in medical applications. In this paper, we propose a mechanism to secure the data provenance for these devices by exploiting spatio-temporal characteristics of the wireless channel that these devices use for communication. Our solution enables two parties to generate closely matching link fingerprints, which uniquely associate a data session with a wireless link such that a third party can later verify the details of the transaction, particularly the wireless link on which the data was transmitted. These fingerprints are very hard for an eavesdropper to forge; they are lightweight compared with traditional provenance mechanisms and enable interesting security properties such as accountability, nonrepudiation, and resist man-in-the-middle attacks. We validate our technique with experiments using bodyworn sensors in scenarios approximating actual device deployment and present some extensions, which reduce energy consumption. We believe this is a promising first step toward using wireless-link characteristics for the data provenance in body area networks. Syed Taha Ali, Vijay Sivaraman, Diethelm Ostry, Gene Tsudik, Sanjay K. Jha |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2014 | Eliminating Reconciliation Cost in Secret Key Generation for Body-Worn Health Monitoring DevicesabstractMedical data collected by wearable wireless sensor devices must be adequately secured. A prerequisite for mass deployment of these secure systems is the ability to periodically renew cryptographic keys without user involvement. Recent work has shown that two communicating devices can generate secret keys directly from measurements of their common wireless channel, which is symmetric but cannot be inferred in detail by an eavesdropper. These schemes may, however, yield mismatching keys at the two ends, requiring reconciliation mechanisms with high implementation and energy costs, unsuitable for resource-poor body-worn devices. In this work, we demonstrate a scheme for secret-key generation able to construct shared keys with near-perfect agreement, thereby avoiding reconciliation costs. Our specific contributions are: (1) we identify non-simultaneous probing of the channel by the link end-points as the dominant cause of channel measurement disagreement; (2) we develop a practical filtering scheme to reduce this disagreement, dramatically improving signal correlation between the two ends without affecting key entropy; and (3) we show that by restricting key generation to periods of significant channel fluctuation, we achieve near-perfect key agreement. We demonstrate in several representative body-worn settings that our scheme can generate secret bits with 99.8% agreement, and so yield near-perfect matching 128-bit keys approximately every half hour. Syed Taha Ali, Vijay Sivaraman, Diethelm Ostry |
IEEE Trans. Mob. Comput. | 3 |
| 2014 | Radio diversity for reliable communication in sensor networksabstractRadio connectivity in wireless sensor networks is highly intermittent due to unpredictable and time-varying noise and interference patterns in the environment. Because link qualities are not predictable prior to deployment, current deterministic solutions to unreliable links, such as increasing network density or transmission power, require overprovisioning of network resources and do not always improve reliability. We propose a new dual-radio network architecture to improve communication reliability in wireless sensor networks. Specifically, we show that radio transceivers operating at well-separated frequencies and spatially separated antennas offer robust communication, high link diversity, and better interference mitigation. We derive the optimal parameters for the dual-transceiver setup from frequency and space diversity in theory. We observe that frequency diversity holds the most benefits as long as the antennas are sufficiently separated to prevent coupling. Our experiments on an indoor/outdoor testbed confirm the theoretical predictions and show that radio diversity can significantly improve end-to-end delivery rates and network stability at only a small increase in energy cost over a single radio. Simulation experiments further validate the improvements in multiple topology configurations, but also reveal that the benefits of radio diversity are coupled to the number of available routing paths to the destination. Branislav Kusy, David Abbott, Cong Huynh, Mikhail Afanasyev, Wen Hu 0001, Michael Brünig, Diethelm Ostry, Raja Jurdak |
ACM Trans. Sens. Networks | 8 |
| 2013 | Securing data provenance in body area networks using lightweight wireless link fingerprintsabstractWireless bodyworn sensing devices are becoming popular for fitness, sports training and personalized healthcare applications. In this paper, we demonstrate a mechanism to secure data provenance for these devices by exploiting symmetric spatio-temporal characteristics of the wireless link between two communicating parties. Our solution enables both parties to generate closely matching 'link' fingerprints which uniquely associate a data session with a wireless link such that a third party, at a later date, can verify the links the data was communicated on. These fingerprints are unique, they are very hard for an eavesdropper to forge, lightweight compared to traditional provenance mechanisms, and allow for certain interesting security properties such as system accountability and non-repudiation. Syed Taha Ali, Vijay Sivaraman, Diethelm Ostry, Sanjay K. Jha |
SenSys | 3 |
| 2013 | A confidential and DoS-resistant multi-hop code dissemination protocol for wireless sensor networks
Hailun Tan, Diethelm Ostry, John Zic, Sanjay K. Jha |
Comput. Secur. | 2 |
| 2013 | Acoustical ranging techniques in embedded wireless sensor networked devicesabstractLocation sensing provides endless opportunities for a wide range of applications in GPS-obstructed environments, where, typically, there is a need for a higher degree of accuracy. In this article, we focus on robust range estimation , an important prerequisite for fine-grained localization. Motivated by the promise of acoustic in delivering high ranging accuracy, we present the design, implementation, and evaluation of acoustic (both ultrasound and audible) ranging systems. We distill the limitations of acoustic ranging and present efficient signal designs and detection algorithms to overcome the challenges of coverage, range, accuracy/resolution, tolerance to Doppler's effect, and audible intensity. We evaluate our proposed techniques experimentally on TWEET, a low-power platform purpose-built for acoustic ranging applications. Our experiments demonstrate an operational range of 20m (outdoor) and an average accuracy ≈2cm in the ultrasound domain. Finally, we present the design of an audible-range acoustic tracking service that encompasses the benefits of a near-inaudible acoustic broadband chirp and approximately two times increase in Doppler tolerance to achieve better performance. Prasant Misra, Navinda Kottege, Branislav Kusy, Diethelm Ostry, Sanjay K. Jha |
ACM Trans. Sens. Networks | 4 |
| 2012 | Decorrelating secret bit extraction via channel hopping in body area networksabstractRecent research has demonstrated that two communicating parties can generate shared secret keys by exploiting characteristics of the wireless fading channel between them. These channel characteristics are symmetric, dependent on position and orientation, highly sensitive to motion, and cannot be deduced in detail by an eavesdropper. One problem with this approach, however, is that over small channel sampling intervals, successively sampled values are correlated in time, which therefore yields keys with reduced entropy. In this paper, we undertake experiments to determine the efficacy of using channel hopping to increase diversity and improve secret key entropy, in the context of body area networks. We conduct extensive experiments using off-the-shelf IEEE 802.15.4 devices, mounted on the human body, in a real indoor environment. Our experimental results show that: (i) channel hopping increases frequency diversity and effectively decorre-lates successive channel samples, significantly increasing entropy (at minimum approximately 20%) and thereby improving the strength of the secret key, (ii) the benefit can be maximized by devising a hopping strategy that takes into account the number of channels available, the spacing between them, and the activity of the user. Linjia Yao, Syed Taha Ali, Vijay Sivaraman, Diethelm Ostry |
PIMRC | 4 |
| 2012 | Authentication of lossy data in body-sensor networks for healthcare monitoringabstractGrowing pressures on healthcare costs are spurring development of lightweight bodyworn sensors for real-time and continuous physiological monitoring. Data from these sensors is streamed wirelessly to a handheld device such as a mobile phone, and then archived over the Internet at a central database. Authenticating the data is vital to ensure proper diagnosis, traceability, and validation of claims. Digital signatures at the packet-level are too resource-intensive for bodyworn devices, while block-level signatures are not robust to loss. In this paper we propose, analyse, and validate a practical, lightweight robust authentication scheme suitable for health-monitoring. We make three specific contributions: (a) We develop an authentication scheme that is both low-cost (using a Merkle hash tree to amortise digital signature costs), and loss-resilient (using network coding to recover strategic nodes within the tree). (b) We develop a framework for optimising placement of network coding within the tree to maximise data verifiability for a given overhead and loss environment. (c) We validate our scheme using experimental traces of typical operating conditions to show that it achieves high success (over 99% of the medical data can be authenticated) at very low overheads (as low as 5% extra transmissions) and at very low cost (the bodyworn device has to perform a digital signature operation no more than once per hour). We believe our novel authentication scheme can be a key ingredient in the integration of wearable medical monitoring devices into current healthcare systems. Syed Taha Ali, Vijay Sivaraman, Diethelm Ostry |
SECON | 3 |
| 2012 | Zero reconciliation secret key generation for body-worn health monitoring devicesabstractWearable wireless sensor devices are key components in the emerging technology of personalized healthcare monitoring. Medical data collected by these devices must be secured, especially on the wireless link to the gateway equipment. However, it is difficult to manage the required cryptographic keys, as users may lack the awareness or requisite skills for this task. Alternatively, recent work has shown that two communicating devices can generate secret keys derived directly from symmetrical properties of the wireless channel between them. This channel is also strongly dependent on positioning and movement and cannot be inferred in detail by an eavesdropper. Existing schemes, however, yield keys with mismatching bits at the two ends, requiring reconciliation mechanisms with high implementation and energy costs that are unsuitable for resource-poor body-worn devices. Syed Taha Ali, Vijay Sivaraman, Diethelm Ostry |
WISEC | 3 |
| 2011 | Radio diversity for reliable communication in WSNs
Branislav Kusy, Wen Hu 0001, Mikhail Afanasyev, Raja Jurdak, Michael Brünig, David Abbott, Cong Huynh, Diethelm Ostry |
IPSN | 9 |
| 2011 | TWEET: an envelope detection based broadband ultrasonic ranging systemabstractFine-grained location information at long range can benefit many applications of embedded sensor networks and robotics. In this paper, we focus on range estimation - an important prerequisite for fine-grained localization - in the ultrasonic domain for both indoor and outdoor environments, and make three contributions. First, we evaluate the characteristics of broadband signals, and provide useful statistics in their design and engineering to achieve a good trade-off between range and accuracy. Second, to overcome the inaccuracy due to correlation sidelobes, we propose a signal detection technique that estimates the envelope of the correlated pulse using a simple least-square approximation approach, and undertake a simulation study to verify its ranging efficiency on linear chirps. Third, leveraging on the insights obtained from our initial study, we present the design and implementation of TWEET: a mote-based ultrasonic broadband ranging system based on linear chirps using the CSIRO Audio nodes, which comprises of a Fleck-3z mote along with audio codecs and a Blackfin DSP. Our evaluation results indicate that the system is precise enough to support source localization applications: a reliable operational range of 20m (outdoor) and an average accuracy of < 2 cm with a 95% confidence interval of 2 cm. Prasant Misra, Diethelm Ostry, Navinda Kottege, Sanjay K. Jha |
MSWiM | 2 |
| 2011 | Improving the coverage range of ultrasound-based localization systemsabstractLocation awareness is of benefit to a rich set of applications in indoor environments such as asset tracking, resource discovery, interactive virtual games, location-aware sensor networking, navigation support for humans and robots, etc. There exists a vast array of location sensing systems, but they mostly operate under dense indoor deployment due to the limited range and coverage of the sensing device. In this paper, we focus on improving coverage range - a critical prerequisite for localization. Our experiments using the existing Cricket system reveals many of its limitations. We overcome these hurdles, and present the design, implementation and evaluation of a custom designed omni-directional ultrasonic receiver unit integrated with the existing Cricket motes. The modified Cricket system improves the coverage range by ≈20% in comparison to the original Cricket. The lessons and experiences also provide an analytical and system-level understanding of how various factors affect the ranging characteristics. Prasant Misra, Sanjay K. Jha, Diethelm Ostry |
WCNC | 3 |
| 2011 | Secure Multihop Network Programming with Multiple One-Way Key ChainsabstractCurrent network programming protocols provide an efficient way to update program images running on sensor nodes without having physical access to them. Securing these updates, however, remains a challenging and important issue, given the open environment where sensor nodes are often deployed. Several approaches addressing these issues have been reported, but their use of cryptographically strong protocols means that their computational costs (and hence, power consumption and communication costs) are relatively high. In this paper, we propose a novel scheme to secure a multihop network programming protocol through the use of multiple one-way hash chains. The scheme is shown to be lower in computational, power consumption, and communication costs yet still able to secure multihop propagation of program images. We demonstrate the use of this scheme and provide some results using the popular network programming protocol, Deluge. In addition, we include a performance evaluation of our scheme, implemented in TinyOS, in terms of latency and energy consumption. Hailun Tan, John Zic, Sanjay K. Jha, Diethelm Ostry |
IEEE Trans. Mob. Comput. | 4 |
| 2010 | Secret Key Generation Rate vs. Reconciliation Cost Using Wireless Channel Characteristics in Body Area NetworksabstractIn this paper, we investigate the feasibility of real time derivation of cryptographic keys in body area networks using unique characteristics of the underlying wireless channel. We perform experiments to confirm that motion does indeed provide significant highly correlated randomness on either end of the wireless link between base station and mobile mote to enable real-time key generation. Furthermore, we demonstrate that channel characteristics for a dynamic body area network consist of two different components, a fast and a slow component, each of which make a qualitatively different contribution to key generation. These components can be isolated to address specific needs of the application scenario: the fast component can yield high entropy keys at a fast rate between base station and mobile mote with some bit disagreement between the two devices, the slow component generates keys at a lower rate but with very high level of bit agreement. Our experimental results highlight this tradeoff, and our key generation protocol details the key extraction process. Syed Taha Ali, Vijay Sivaraman, Diethelm Ostry |
EUC | 3 |
| 2010 | Long-range detection in acoustic sensor networksabstractThe performance of various localisation schemes in sensor networks can be improved by long-range detection. However, its performance deteriorates under noisy environmental conditions. This work presents a system implementation of an acoustic ranging mechanism based on wideband ultrasonic linear chirps and time-reversal technique to counter the negative influence of channel multipath. We investigated the performance of our technique through experimentation with chirps of length 500 milliseconds. The proposed scheme provided distance ranging up to 10 meters, and showed an improvement in peak detection with respect to conventional techniques. Prasant Misra, Sanjay K. Jha, Diethelm Ostry |
IPSN | 3 |
| 2010 | Secure key loss recovery for network broadcast in single-hop wireless sensor networks
Syed Taha Ali, Vijay Sivaraman, Ashay Dhamdhere, Diethelm Ostry |
Ad Hoc Networks | 4 |
| 2009 | Characterization of link asymmetry in wireless sensor networksabstractRecent experimental studies in wireless sensor networks (WSNs) have confirmed that asymmetry in the wireless links has a significant effect on the performance of WSN network protocols. Protocols which work in simulation studies often fail when link asymmetry is encountered in real deployments. Characterization of link asymmetry is thus of paramount importance for the design and operation of re-silient WSN protocols in real scenarios. This paper details an empirical study to characterize link asymmetry in WSNs.There are several factors that contribute to link asymmetry in WSNs, the major ones being environmental effects and hardware performance. In this work, we used a systematic approach to measure the effects of hardware performance, i.e. transmitter, receiver and antenna characteristics, on link asymmetry using off-the-shelf WSN devices such as Xbow Mica2 and MicaZ motes. We conducted experiments to study the variations in spectrum utilization in these WSN devices, for both wired and wireless connections, and to ascertain the effects of any frequency and amplitude mismatches on link symmetry between nodes in transmission and reception. Prasant Misra, Sanjay K. Jha, Diethelm Ostry |
SenSys | 4 |
| 2009 | Analysis of an omni-directional narrowband ultrasonic receiver and CSS-based broadband transmissionabstractUltrasound (US) based Cricket indoor location system has limited range when the transmitter and receiver motes are not in the line-of-sight (LOS) positions. It uses narrowband US transducers which are unidirectional and require tilting of the motes in order to improve the signal reception quality. The main focus of this work is to improve the ranging distance of the ultrasound based sensor motes with an objective of successfully deploying in harsh environments where the prime challenge is that of gracefully sustaining the signal characteristics for the purpose of distance estimation. We implement and provide an analysis of two different techniques with respect to the original Cricket: 1) Omni-directional receiver: A dodecahedron arrangement of an array of 3 US transducers. 2) Chirp spread spectrum based broadband transmission scheme and signal correlation technique. Prasant Misra, Sanjay K. Jha, Diethelm Ostry |
SenSys | 3 |
| 2009 | A confidential and DoS-resistant multi-hop code dissemination protocol for wireless sensor networksabstractCode dissemination protocols provide a convenient way to update program images via wireless communication. Due to the open environment in which Wireless Sensor Networks (WSNs) are typically deployed, it is important that a code dissemination protocol ensures that a program image update can be authenticated as coming from a trusted source. In some applications it is also required that the data be kept confidential in spite of the possibility of message interception. Authentication and confidentiality are implemented through cryptographic operations which may be expensive in power consumption, making a protocol with these features vulnerable to attack by an adversary who transmits forged data, forcing nodes to waste energy in identifying it as invalid i.e., a signature-based DoS attack). Additionally, in multi-hop dissemination protocols, each sensor node is required to broadcast its program image when requested by its neighbors. An adversary could repeatedly send spurious program image requests to its neighbors, making them exhaust their energy reserves i.e., request-based DoS attack). In this paper, we present a new approach to achieve confidentiality in multi-hop code dissemination. We propose counter-measures against both types of DoS attacks mentioned above. To our knowledge, we are the first to integrate confidentiality and DoS-attack-resistance in a multi-hop code dissemination protocol. Our approach is based on Deluge, an open source, state-of-the-art code dissemination protocol for WSNs. In addition, We provide a performance evaluation in terms of latency and energy consumption in our scheme, compared with the original Deluge and the existing secure Deluge. Hailun Tan, Diethelm Ostry, John Zic, Sanjay K. Jha |
WISEC | 2 |
| 2009 | Packet pacing in small buffer optical packet switched networks
Vijay Sivaraman, Hossam A. ElGindy, David Moreland, Diethelm Ostry |
IEEE/ACM Trans. Netw. | 4 |
| 2008 | A key loss recovery scheme for secure broadcasts in wireless sensor networksabstractAuthenticity and secrecy of broadcast message content is important in wireless sensor networks deployed for battlefield control, emergency response, and natural resource management. Encryption of broadcast data requires the key to vary in time, typically via a key chain, so that a key compromised at a receiver does not compromise broadcast security for the entire network. An unfortunate consequence of time-varying keys is that a receiver that misses (due to packet loss) one or more keys from the chain cannot decrypt subsequent messages, thereby getting excluded from all broadcasts. In this paper we develop a scheme that allows receivers to recover from one or a few lost keys by having the transmitter probabilistically reuse old keys from the chain. Our scheme makes the broadcast system more robust to packet loss, at the expense of increasing vulnerability to compromised old keys. Analysis of our scheme shows how the trade-off can be controlled by tuning parameters, and a prototype implementation on a MicaZ mote testbed demonstrates the feasibility of our scheme in real sensor network platforms. Syed Taha Ali, Vijay Sivaraman, Ashay Dhamdhere, Diethelm Ostry |
PIMRC | 4 |
| 2008 | Secure multi-hop network programming with multiple one-way key chainsabstractCurrent network programming protocols provide an efficient way to update the program image running on sensor nodes without physical access to them. However, given the open environment in which sensor nodes are deployed, securing network programming is a challenging task. Existing work addressing this issue either lack consideration of securing multi-hop network programming protocols, or are not cost-efficient. To our knowledge, none of them have evaluated the power consumption. In this paper, we propose a novel scheme to secure multi-hop network programming protocols using multiple one-way hash chains. This scheme is resilient to malicious program image injection by the compromised nodes and it secures multi-hop propagation of program images for sensor nodes. Based on the most popular network programming protocol, Deluge, an overhead analysis on this schemes is given. In addition, our scheme is implemented in TinyOS and a performance evaluation in terms of latency and energy consumption is presented. Hailun Tan, Sanjay K. Jha, Diethelm Ostry, John Zic, Vijay Sivaraman |
WISEC | 3 |
| 2007 | Confidential and Secure Broadcast in Wireless Sensor NetworksabstractWireless sensor networks need broadcast for operations such as software updates, network queries, and command dissemination. Alongside ensuring authenticity of the source and data, keeping the broadcast data secret is vital in certain applications such as battlefield control, emergency response, and natural resource management. In this paper we propose and prototype a mechanism for ensuring confidentiality and authenticity of broadcast data in single-hop networks, and discuss possible extensions to multi-hop settings. Our scheme uses known low-complexity symmetric encryption techniques for confidentiality, while changing the encryption key on a per-packet basis in a verifiable but non-forgeable way to ensure authenticity. Message integrity, freshness, and semantic security are also provided, and the broadcast data can be dynamic and incrementally processed. We incorporate our security scheme into Deluge, the de facto network programming protocol in TinyOS, and quantify the cost in terms of broadcast data transfer time and node memory space on a TelosB mote based platform. Jaleel Shaheen, Diethelm Ostry, Vijay Sivaraman, Sanjay K. Jha |
PIMRC | 2 |
| 2006 | Packet Pacing in Short Buffer Optical Packet Switched NetworksabstractAbstract — In the absence of a cost-effective technology for storing optical signals, emerging optical packet switched (OPS) networks are expected to have severely limited buffering capability. This paper investigates the resulting impact on end-to-end loss and throughput, and proposes that the optical edge switches “pace ” packets into the OPS core to improve performance without adversely affecting end-to-end delays. In this context, our contributions are three-fold. We first evaluate the impact of short buffers on the performance of real-time and TCP traffic. This helps us identify short-time-scale burstiness as the major contributor to performance degradation, so we propose that the optical edge switches pace the transmission of packets into the OPS core while respecting their delay-constraints. Our second contribution develops algorithms of poly-logarithmic complexity that can perform optimal real-time pacing of high data rate traffic. Lastly, we show via simulations of a realistic network carrying real-time traffic that pacing can significantly reduce losses at the expense of a bounded increase in end-to-end delay. The loss-delay trade-off mechanism provided by pacing can help achieve desired OPS network performance. I. Vijay Sivaraman, Hossam A. ElGindy, David Moreland, Diethelm Ostry |
INFOCOM | 4 |
| 2006 | Synthesis of accurate fractional Gaussian noise by filteringabstractThis paper describes a method for generating long sample paths of accurate fractional Gaussian noise (fGn), the increment process of fractional Brownian motion (fBm). The method is based on a Wold decomposition in which fGn is expressed as the output of a finite impulse response filter with discrete white Gaussian noise as input. The form of the ideal filter is derived analytically in the continuous-time case. For the finite-length discrete-time case, an iterative projection algorithm incorporating a Newton-Raphson step is described for computing the coefficients of a length-N filter in a time approximately proportional to N. Fast convolution of discrete white Gaussian noise with the computed filter impulse response yields arbitrarily long sequences which exactly match the correlation structure of fGn over a finite range of lags. For values of the Hurst parameter H smaller than a critical value Hcritap0.85, and large N, the finite-length autocorrelation sequence of fGn is positive definite and this range of lags can be as large as the filter autocorrelation length. When H>Hcrit, the finite-length autocorrelation sequence of fGn is no longer positive definite and a modification is made to allow a Wold decomposition. The generated sequences then exactly match the autocorrelation structure of fGn over a more restricted range of lags which becomes smaller as H approaches unity Diethelm Ostry |
IEEE Trans. Inf. Theory | 1 |