EDBT 2026 Demo / reviewers in the wild / expert
Petr Dzurenda
dblp:160/3964
· DBLP profile ↗
24ranked-venue papers
6as first author
13since 2021 · last 2024
0000-0002-4366-3950ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 23 · 6 first-author · 13 since 2021Computer networks · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Enhancing Cybersecurity Curriculum Development: AI-Driven Mapping and Optimization TechniquesabstractCybersecurity has become important, especially during the last decade. The significant growth of information technologies, internet of things, and digitalization in general, increased the interest in cybersecurity professionals significantly. While the demand for cybersecurity professionals is high, there is a significant shortage of these professionals due to the very diverse landscape of knowledge and the complex curriculum accreditation process. In this article, we introduce a novel AI-driven mapping and optimization solution enabling cybersecurity curriculum development. Our solution leverages machine learning and integer linear programming optimization, offering an automated, intuitive, and user-friendly approach. It is designed to align with the European Cybersecurity Skills Framework (ECSF) released by the European Union Agency for Cybersecurity (ENISA) in 2022. Notably, our innovative mapping methodology enables the seamless adaptation of ECSF to existing curricula and addresses evolving industry needs and trend. We conduct a case study using the university curriculum from Brno University of Technology in the Czech Republic to showcase the efficacy of our approach. The results demonstrate the extent of curriculum coverage according to ECSF profiles and the optimization progress achieved through our methodology. Petr Dzurenda, Sara Ricci, Marek Sikora, Michal Stejskal, Imre Lendak, Pedro Adão |
ARES | 1 |
| 2024 | Quantum-Resistant and Secure MQTT CommunicationabstractIn this paper, we deal with the deployment of Post-Quantum Cryptography (PQC) in Internet of Things (IoT). Concretely, we focus on the MQTT (Message Queuing Telemetry Transport) protocol that is widely used in IoT services. The paper presents our novel quantum-resistant security proposal for the MQTT protocol that supports secure broadcast. Our solution omits using TLS with the handshake causing delay and is suitable for sending irregular short messages. Finally, we show how our solution can practically affect concrete use cases by the performance results of the proposed solution. Lukas Malina, Patrik Dobias, Petr Dzurenda, Gautam Srivastava 0001 |
ARES | 3 |
| 2024 | Secure and Privacy-Preserving Car-Sharing SystemsabstractWith increasing smart transportation systems and services, potential security and privacy threats are growing. In this work, we analyze privacy and security threats in car-sharing systems, and discuss the problems with the transparency of services, users’ personal data collection, and how the legislation manages these issues. Based on analyzed requirements, we design a compact privacy-preserving solution for car-sharing systems. Our proposal combines digital signature schemes and group signature schemes, in order to protect user privacy against curious providers, increase security and non-repudiation, and be efficient even for systems with restricted devices. The evaluation of the proposed solution demonstrates its security and a practical usability for constrained devices deployed in vehicles and users’ smartphones. Lukas Malina, Petr Dzurenda, Norbert Lövinger, Ijeoma Faustina Ekeh, Raimundas Matulevicius |
ARES | 2 |
| 2024 | Lattice-based Multisignature Optimization for RAM Constrained DevicesabstractIn the era of growing threats posed by the development of quantum computers, ensuring the security of electronic services has become fundamental. The ongoing standardization process led by the National Institute of Standards and Technology (NIST) emphasizes the necessity for quantum-resistant security measures. However, the implementation of Post-Quantum Cryptographic (PQC) schemes, including advanced schemes such as threshold signatures, faces challenges due to their large key sizes and high computational complexity, particularly on constrained devices. This paper introduces two microcontroller-tailored optimization approaches, focusing on enhancing the DS2 threshold signature scheme. These optimizations aim to reduce memory consumption while maintaining security strength, specifically enabling the implementation of DS2 on microcontrollers with only 192 KB of RAM. Experimental results and security analysis demonstrate the efficacy and practicality of our solution, facilitating the deployment of DS2 threshold signatures on resource-constrained microcontrollers. Sara Ricci, Vladyslav Shapoval, Petr Dzurenda, Peter B. Rønne, Jan Oupický, Lukas Malina |
ARES | 3 |
| 2023 | Enhancing Cybersecurity Education in Europe: The REWIRE's Course Selection MethodologyabstractThe European Cybersecurity Skills Framework (ECSF) was introduced by the European Union Agency for Cybersecurity (ENISA) to identify the necessary competencies, knowledge, and skills required for European cybersecurity professionals. The ECSF condenses all cybersecurity-related positions into 12 role profiles, aiming to establish a mutual understanding of essential roles and support the creation of cybersecurity training programs. In order to address the shortage of cybersecurity experts, a multi-criteria selection method is developed to increase the availability, accessibility, and quality of cybersecurity courses and certifications. This Course Selection methodology ensures high-quality training materials that meet the current and future needs of the cybersecurity industry and benefit a wide range of participants. The methodology considers six criteria and provides a scoring system to rank the occupational profiles and select the most relevant profiles for the course design. Our final score formula identifies Chief Information Security Officer (CISO), Cyber Incident Responder, Cyber Threat Intelligence Specialist, and Penetration Tester for the Course creation. Alan Briones, Sara Ricci, Argyro Chatzopoulou, Jakub Cegan, Petr Dzurenda, Ioannis Koutoudis |
ARES | 5 |
| 2023 | On Efficiency and Usability of Group Signatures on Smartphone and Single-board PlatformsabstractWith increasing digitalization and omnipresent data sensing, security and users’ privacy become essential requirements in new digital services. Group Signatures (GS) or also known as Anonymous Digital Signatures (ADS) are often used as a core Privacy-Enhancing Technology (PET) in order to keep users’ privacy during their access and/or authentication phases within ensuring the security of provided services. In this work, we provide a comprehensive assessment of group signatures on various small computing platforms typically used in modern digital services. Based on our analysis of well-established GS schemes and their libraries, we implement and evaluate chosen schemes on both well-known smartphone platforms (i.e., Android, iOS) and on a single-board computer. Our results indicate that current handheld devices can already effectively perform main group signatures’ phases and make these schemes practical for deployment in various privacy-requiring scenarios. Patrik Dobias, Lukas Malina, Petr Ilgner, Petr Dzurenda |
ARES | 4 |
| 2023 | Lattice-Based Threshold Signature Implementation for Constrained DevicesabstractThreshold signatures have gained increased attention especially due to their recent applications in blockchain technologies. In fact, current cryptocurrencies such as Bitcoin, and Cardano started to support multi-signature transactions. Even if the Schnorr-based threshold signatures improve the blockchain's privacy and scalability, these schemes do not provide post-quantum security. In this paper, we propose the optimization of the DS2 lattice-based $(n,n)$-threshold signature scheme and present its practical implementation. Moreover, we evaluate our optimized implementation of the DS2 scheme on different platforms. The results demonstrate that our implementation is easily portable and executable on constrained devices based on ARM Cortex-A53, ARM Cortex-M3, and ESP32 architectures. Patrik Dobias, Sara Ricci, Petr Dzurenda, Lukas Malina, Nikita Snetkov |
SECRYPT | 3 |
| 2022 | Real-world Deployment of Privacy-Enhancing Authentication System using Attribute-based CredentialsabstractWith the daily increase in digitalization and integration of the physical and digital worlds, we need to better protect users’ privacy and identity. Attribute-based Credentials (ABCs) seem to be a promising technology for this task. In this paper, we provide comprehensive analyses of the readiness, maturity, and applicability of ABCs to real-world applications. Furthermore, we introduce our Privacy-Enhancing Authentication System (PEAS), which is based on ABCs and meets all privacy requirements such as anonymity and unlinkability of the user’s activities. Besides privacy features, PEAS also provides revocation mechanisms to identify and revoke malicious users. The system is suitable for deployment in real-world scenarios and runs on a wide range of user devices (e.g., smart cards, smartphones, and wearables). Petr Dzurenda, Raúl Casanova Marqués, Lukas Malina |
ARES | 1 |
| 2022 | Implementation of Revocable Keyed-Verification Anonymous Credentials on Java CardabstractJava Card stands out as a good choice for the development of smart card applications due to the high interoperability between different manufacturers, its security, and wide support of cryptographic algorithms. Despite extensive cryptographic support, current Java Cards do not support non-standard cryptographic algorithms such as post-quantum, secure-multiparty computations, and privacy-enhancing cryptographic schemes. Moreover, Java Card is restricted by the Application Programming Interface (API) in algebraic operations, which are the foundation of modern cryptographic schemes. This paper addresses the issue of developing these modern schemes by exploiting the limited cryptographic API provided by these types of cards. We show how to (ab)use the Java Card’s API to perform modular arithmetic operations, as well as basic operations on elliptic curves. Furthermore, we implement an attribute-based privacy-enhancing scheme on an off-the-shelf Java Card. To do so, we use our cryptographic API and several optimization techniques to make the scheme as efficient as possible. To demonstrate the practicality of our solution, we present the implementation results and benchmark tests. Raúl Casanova Marqués, Petr Dzurenda, Jan Hajny |
ARES | 2 |
| 2021 | Privacy-Preserving Online Parking Based on Smart ContractsabstractThis work presents a complex privacy-preserving solution based on attribute-based credentials and smart contract techniques for emerging parking services in city zones. Our system provides the full set of privacy-enhancing features such as anonymity, untraceability, and unlinkability of user parking registrations. Thanks to that it prevents the city and service providers from profiling and tracking the users (e.g., their movement). Furthermore, we involved smart contracts and the underlying decentralized Blockchain technology in payment and verification phases to prevent the presence of a single point of failure in those processes which can endanger the system’s security and availability. We provide the full cryptographic specification of the system, its security analysis, and the implementation results in this paper. Petr Dzurenda, Carles Angles-Tafalla, Sara Ricci, Lukas Malina |
ARES | 1 |
| 2021 | Secret Sharing-based Authenticated Key Agreement ProtocolabstractIn this article, we present two novel authenticated key agreement (AKA) schemes that are easily implementable and efficient even on constrained devices. Both schemes are constructed over elliptic curves and extend Schonorr’s signature of knowledge protocol. To the best of our knowledge, we introduce a first AKA protocol based on the proof of knowledge concept. This concept allows a client to prove its identity to a server via secret information while the server can learn nothing about the secret. Furthermore, we extend our protocol via secret sharing to support client multi-device authentication and multi-factor authentication features. In particular, the secret of the client can be distributed among the client’s devices. Petr Dzurenda, Sara Ricci, Raúl Casanova Marqués, Jan Hajny, Petr Cika |
ARES | 1 |
| 2021 | Implementing CRYSTALS-Dilithium Signature Scheme on FPGAsabstractIn July 2020, the lattice-based CRYSTALS-Dilithium digital signature scheme has been chosen as one of the three third-round finalists in the post-quantum cryptography standardization process by the National Institute of Standards and Technology (NIST). In this work, we present the first Very High Speed Integrated Circuit Hardware Description Language (VHDL) implementation of the CRYSTALS-Dilithium signature scheme for Field-Programmable Gate Arrays (FPGAs). Due to our parallelization-based design requiring only low numbers of cycles, running at high frequency and using reasonable amount of hardware resources on FPGA, our implementation is able to sign 15832 messages per second and verify 10524 signatures per second. In particular, the signing algorithm requires 68461 Look-Up Tables (LUTs), 86295 Flip-Flops (FFs), and the verification algorithm takes 61738 LUTs and 34963 FFs on Virtex 7 UltraScale+ FPGAs. In this article, experimental results for each Dilithium security level are provided and our VHDL-based implementation is compared with related High-Level Synthesis (HLS)-based implementations. Our solution is ca 114 times faster (in the signing algorithm) and requires less hardware resources. Sara Ricci, Lukas Malina, Petr Jedlicka, David Smékal, Jan Hajny, Peter Cíbik, Petr Dzurenda, Patrik Dobias |
ARES | 7 |
| 2021 | Towards CRYSTALS-Kyber VHDL ImplementationabstractKyber is one of the three finalists of the National Institute of Standards and Technology (NIST) post-quantum cryptography competition. This article presents an optimized Very High Speed Integrated Circuit Hardware Description Language (VHDL)-based implementation of the main components of the Kyber scheme, namely Number-Theoretic Transform (NTT) and Keccak. We focus specifically on NTT, Keccak and their derivatives since they largely determine Kyber's performance due to their wide involvement in each step of the scheme. Our high-speed implementation also takes into account the trade-off between the degree of parallelization and the resources utilization. The NTT component is more than 27\% faster than the state-of-the-art implementations. Furthermore, the optimization helps the algorithm to achieve 1 572 839 NTT operations per second. Sara Ricci, Petr Jedlicka, Peter Cíbik, Petr Dzurenda, Lukas Malina, Jan Hajny |
SECRYPT | 4 |
| 2019 | A Secure Publish/Subscribe Protocol for Internet of ThingsabstractThe basic concept behind the emergence of Internet of Things (IoT) is to connect as many objects to the Internet as possible in an attempt to make our lives better in some way. However, connecting everyday objects like your car or house to the Internet can open up major security concerns. In this paper, we present a novel security framework for the Message Queue Transport Telemetry (MQTT) protocol based on publish/subscribe messages in order to enhance secure and privacy-friendly Internet of Things services. MQTT has burst onto the IoT scene in recent years due to its lightweight design and ease of use implementation necessary for IoT. Our proposed solution provides 3 security levels. The first security level suits for lightweight data exchanges of non-tampered messages. The second security level enhances the privacy protection of data sources and data receivers. The third security level offers robust long-term security with mutual authentication for all parties. The security framework is based on light cryptographic schemes in order to be suitable for constrained and small devices that are widely used in various IoT use cases. Moreover, our solution is tailored to MQTT without using additional security overhead. Lukas Malina, Gautam Srivastava 0001, Petr Dzurenda, Jan Hajny, Radek Fujdiak |
ARES | 3 |
| 2019 | A Privacy-Enhancing Framework for Internet of Things Services
Lukas Malina, Gautam Srivastava 0001, Petr Dzurenda, Jan Hajny, Sara Ricci |
NSS | 3 |
| 2019 | Fast Keyed-Verification Anonymous Credentials on Standard Smart Cards
Jan Camenisch, Manu Drijvers, Petr Dzurenda, Jan Hajny |
SEC | 3 |
| 2018 | Secure and efficient two-factor zero-knowledge authentication solution for access control systems
Lukas Malina, Petr Dzurenda, Jan Hajny, Zdenek Martinasek |
Comput. Secur. | 2 |
| 2018 | Multidevice Authentication with Strong Privacy ProtectionabstractCard‐based physical access control systems are used by most people on a daily basis, for example, at work, in public transportation, or at hotels. Yet these systems have often very poor cryptographic protection. User identifiers and keys can be easily eavesdropped on and counterfeited. The privacy‐preserving features are almost missing in these systems. To improve this state, we propose a novel cryptographic scheme based on efficient zero‐knowledge proofs and Boneh‐Boyen signatures. The proposed scheme is provably secure and provides the full set of privacy‐enhancing features, that is, the anonymity, untraceability, and unlinkability of users. Furthermore, our scheme supports distributed multidevice authentication with multiple RFID (Radio‐Frequency IDentification) user devices. This feature is particularly important in applications for controlling access to dangerous sites where the presence of protective equipment is checked during each access control session. Besides the full cryptographic specification, we also show the results of our implementation on devices commonly used in access control applications, particularly the smart cards and embedded verification terminals. By avoiding costly operations on user devices, such as bilinear pairings, we were able to achieve times comparable to existing systems (around 500 ms), while providing significantly higher security, privacy protection, and features for RFID multidevice authentication. Jan Hajny, Petr Dzurenda, Lukas Malina |
Wirel. Commun. Mob. Comput. | 2 |
| 2017 | Performance Analysis and Comparison of Different Elliptic Curves on Smart CardsabstractElliptic curves are very often used in the cryptographic protocol design due to their memory efficiency and useful features, such as the bilinear pairing support. However, in many cryptographic papers, elliptic curves are used as a black box, without deeper consideration of their mathematical properties and, even more importantly, without considering implementation implications. As a consequence, novel cryptographic schemes are being published without any real chance of implementation on constrained devices due to their lack of support of basic EC operations like point addition or scalar point multiplication. This paper provides the necessary theoretical overview of main forms of elliptic curves, in particular considering their computational and memory complexity. Next, all major platforms of programmable smart cards are evaluated with respect to EC support and the performance of basic arithmetic operations is assessed using benchmarks. Finally, the evaluation of the implementations of ECC schemes, such as ECDH and ECDSA, is presented. Petr Dzurenda, Sara Ricci, Jan Hajny, Lukas Malina |
PST | 1 |
| 2017 | Anonymous Credentials with Practical Revocation using Elliptic Curves
Petr Dzurenda, Jan Hajny, Lukas Malina, Sara Ricci |
SECRYPT | 1 |
| 2016 | Multi-Device Authentication using Wearables and IoTabstractThe paper presents a novel cryptographic authentication scheme that makes use of the presence of electronic devices around users. The scheme makes authentication more secure by involving devices that are usually worn by users (such as smart-watches, fitness bracelets and smart-cards) or are in their proximity (such as sensors, home appliances, etc.). In our scheme, the user private key is distributed over all personal devices thus cannot be compromised by breaking into only a single device. Furthermore, involving wearables and IoT devices makes it possible to use multiple authentication factors, such as user's position, his behavior and the state of the surrounding environment. We provide the full cryptographic specification of the protocol, its formal security analysis and the implementation results in this paper. Jan Hajny, Petr Dzurenda, Lukas Malina |
SECRYPT | 2 |
| 2015 | Privacy-Enhanced Data Collection Scheme for Smart-Metering
Jan Hajny, Petr Dzurenda, Lukas Malina |
Inscrypt | 2 |
| 2015 | Secure Physical Access Control with Strong Cryptographic ProtectionabstractThis paper is focused on the area of physical access control systems (PACs), particularly on the systems for building access control. We show how the application of modern cryptographic protocols, namely the cryptographic proofs of knowledge, can improve the security and privacy protection in practical access control systems. We propose a novel scheme SPAC (Secure Physical Access Control) based on modern cryptographic primitives. By employing the proofs of knowledge, the authentication process gets more secure and privacy friendly in comparison to existing schemes without negative influence on the implementation complexity or system performance. In this paper, we describe the weaknesses of existing schemes, show the full cryptographic specification of the novel SPAC scheme including its security proofs and provide benchmarks on off-the-shelf devices used in real commercial systems. Furthermore we show, that the transition from an old insecure system to strong authentication can be ea sy and cost-effective Jan Hajny, Petr Dzurenda, Lukas Malina |
SECRYPT | 2 |
| 2015 | Attribute-based credentials with cryptographic collusion preventionabstractAbstract Cryptographic attribute‐based credentials (ABCs) allow users to prove their personal attributes remotely and in a privacy‐friendly way. While staying anonymous and untraceable, the users are able to prove their attributes, such as age, membership, or nationality, before using a network service. Unfortunately, there are very few practical cryptographic ABC schemes available today. Furthermore, some existing schemes rely on the hardware tamper‐resistance of smart cards to avoid collusion attacks. The trust in hardware limits the usage of such schemes on poorly protected cards and on smart phones. In this paper, we present the full cryptographic specification of an ABC scheme, which makes the collusion attacks impossible even on insecure hardware like mobile phones. Furthermore, the scheme provides features, which are difficult to achieve using existing schemes, namely the practical revocation of users, the de‐anonymization of malicious users, and the unlinkability of verification sessions. Besides the cryptographic architecture, we also present our practical implementation on a smart phone and embedded platforms. Copyright © 2015 John Wiley & Sons, Ltd. Jan Hajny, Petr Dzurenda, Lukas Malina |
Secur. Commun. Networks | 2 |