Florian Kohnhäuser

dblp:166/7703 · DBLP profile ↗
← Back
13ranked-venue papers
8as first author
4since 2021 · last 2025
0000-0002-0084-2246ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 6 first-author · 3 since 2021Computer networks · 4 · 1 first-authorSystems, architecture and hardware · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 Lightweight and Persistent Remote Attestation: Leveraging a Continuous Chain of Trust in Software Integrity Measurements
Florian Kohnhäuser, Nicolas Coppik, Christian Göttel, Sören Finster
SEC (1)1
2022 Secure Onboarding of IIoT Devices using OPC UA
abstract
In today’s Industrial Internet of Things (IIoT), a broad range of communication protocols are utilized. Built-in security mechanisms enable these protocols to protect communication and defend against network attacks. However, before IIoT devices can utilize these security mechanisms, they need to be securely onboarded in the network. Although several onboarding solutions exist, there is no widely applicable and easy solution for all protocols. Thus, owners of IIoT devices must currently perform multiple processes until they can securely use a device in operation, which requires a high amount of manual effort and onboarding infrastructure.In this work, we present a generic secure onboarding solution for a broad range of network protocols based on OPC UA. OPC UA is particularly suited for this task, as it is one of the most widespread IIoT protocols and one of few protocols whose standard defines a secure onboarding. Our solution leverages the OPC UA onboarding process to equip other IIoT protocols with the initial trust and credentials to establish secure connections. To this end, only minor extensions to the OPC UA implementation on devices are necessary, such that device owners can reuse their OPC UA onboarding infrastructure without any modifications. As a proof of concept for our solution, we demonstrate the secure onboarding of an HTTPS web server. Our implementation fully reuses the reference implementation OPC UA sample server as infrastructure and only needs minor extensions to the IIoT device.
Florian Kohnhäuser, Sten Grüner, Jens Heuschkel
ETFA1
2022 On the Feasibility and Performance of Secure OPC UA Communication with IIoT Devices
Florian Kohnhäuser, Nicolas Coppik, Francisco Mendoza 0001, Ankita Kumari
SAFECOMP1
2022 RESCUE: A Resilient and Secure Device-to-Device Communication Framework for Emergencies
abstract
During disasters, existing telecommunication infrastructures are often congested or even destroyed. In these situations, mobile devices can form a backup communication network for civilians and emergency services using disruption-tolerant networking (DTN) principles. Unfortunately, such distributed and resource-constrained networks are particularly susceptible to a wide range of attacks such as terrorists trying to cause more harm. In this article, we presentRESCUE, a resilient and secure device-to-device communication framework for emergency scenarios that provides comprehensive protection against common attacks.RESCUEfeatures a minimalistic DTN protocol that, by design, is secure against notable attacks such as routing manipulations, dropping, message manipulations, blackholing, or impersonation. To further protect against message flooding and Sybil attacks, we present a twofold mitigation technique. First, a mobile and distributed certificate infrastructure particularly tailored to the emergency use case hinders the adversarial use of multiple identities. Second, a message buffer management scheme significantly increases resilience against flooding attacks, even if they originate from multiple identities, without introducing additional overhead. Finally, we demonstrate the effectiveness ofRESCUEvia large-scale simulations in a synthetic as well as a realistic natural disaster scenario. Our simulation results show thatRESCUEachieves very good message delivery rates, even under flooding and Sybil attacks.
Milan Stute, Florian Kohnhäuser, Lars Baumgärtner, Lars Almon, Matthias Hollick, Stefan Katzenbeisser 0001, Bernd Freisleben
IEEE Trans. Dependable Secur. Comput.2
2019 A Practical Attestation Protocol for Autonomous Embedded Systems
abstract
With the recent advent of the Internet of Things (IoT), embedded devices increasingly operate collaboratively in autonomous networks. A key technique to guard the secure and safe operation of connected embedded devices is remote attestation. It allows a third party, the verifier, to ensure the integrity of a remote device, the prover. Unfortunately, existing attestation protocols are impractical when applied in autonomous networks of embedded systems due to their limited scalability, performance, robustness, and security guarantees. In this work, we propose PASTA, a novel attestation protocol that is particularly suited for autonomous embedded systems. PASTA is the first that (i) enables many low-end prover devices to attest their integrity towards many potentially untrustworthy low-end verifier devices, (ii) is fully decentralized, thus, able to withstand network disruptions and arbitrary device outages, and (iii) is in addition to software attacks capable of detecting physical attacks in a much more robust way than any existing protocol. We implemented our protocol, conducted measurements, and simulated large networks. The results show that PASTA is practical on low-end embedded devices, scales to large networks with millions of devices, and improves robustness by multiple orders of magnitude compared with the best existing protocols.
Florian Kohnhäuser, Niklas Büscher, Stefan Katzenbeisser 0001
EuroS&P1
2018 SALAD: Secure and Lightweight Attestation of Highly Dynamic and Disruptive Networks
abstract
Today, tiny embedded Internet of Things (IoT) devices are increasingly used in safety- and privacy-critical application scenarios. In many of these scenarios, devices perform a certain task collectively as a swarm. Remote attestation is an important cornerstone for the security of these IoT devices, as it allows to verify the integrity of the software on remote devices. Recently proposed collective attestation protocols are able to attest entire device swarms in an efficient way. However, these protocols are inefficient or even inapplicable when devices in the network are mobile or lack continuous connectivity. This work presents SALAD, the first collective attestation protocol for highly dynamic and disruptive networks. SALAD uses a novel distributed approach, where devices incrementally establish a common view on the integrity of all devices in the network. In contrast to existing protocols, SALAD performs well in highly dynamic and disruptive network topologies, increases resilience against targeted Denial of Service (DoS) attacks, and allows to obtain the attestation result from any device. Moreover, SALAD is capable of mitigating physical attacks in an efficient manner, which is achieved by adapting and extending recently proposed aggregation schemes. We demonstrate the security of SALAD and show its effectiveness by providing large-scale simulation results.
Florian Kohnhäuser, Niklas Büscher, Stefan Katzenbeisser 0001
AsiaCCS1
2017 Boot Attestation: Secure Remote Reporting with Off-The-Shelf IoT Sensors
Steffen Schulz 0001, André Schaller, Florian Kohnhäuser, Stefan Katzenbeisser 0001
ESORICS (2)3
2017 Temporal Coverage Analysis of Router-Based Cloudlets Using Human Mobility Patterns
abstract
Responsive applications such as augmented reality require nearby computational offloading units with low latency. The concept of cloudlets is one promising approach that satisfies these requirements. However, due to their wireless range restrictions cloudlets have always been faced with deployment issues of achieving high spatial coverage. In this paper, we look at the coverage issue from an end-user's perspective instead of an established provider perspective: we first argue that temporal coverage of cloudlet accessibility is preferable to spatial coverage for an end- user's experience considering his daily mobility behavior. Next, we investigate what is necessary to achieve a high temporal coverage for an individual user and to what extent is temporal coverage realizable with concepts like router- based cloudlets. To show our hypothesis and understanding the temporal coverage aspect, we collected two comprehensive datasets, an access points dataset with estimated location information and a human mobility dataset consisting of mobility traces from 30 participants within a major city over 4 weeks. Our analysis results show that high temporal coverage can be achieved by a relatively small set of router-based cloudlets since students mainly stay at two places, their homes and university, which represent a large part of the temporal coverage. The remaining rate at which coverage increases heavily depends on the user's mobility patterns. Our findings can be used to place router-based cloudlets at the right locations and estimate the number needed to achieve a certain temporal coverage in urban environments.
Christian Meurisch, Julien Gedeon, Artur Gogel, The An Binh Nguyen, Fabian Kaup, Florian Kohnhäuser, Lars Baumgärtner, Milan Stute, Max Mühlhäuser
GLOBECOM6
2017 Upgrading Wireless Home Routers as Emergency Cloudlet and Secure DTN Communication Bridge
abstract
Reliable communications are crucial for the success of emergency response and management. However, today's technologies used by rescuers and civilians mainly rely on either centralized or specialized emergency approaches, which reveal individual issues especially in infrastructure- less emergency situations (e.g., blackout). In this paper, we present a customary home router upgraded as self- sustaining emergency device which can ad hoc network with nearby devices (e.g., other upgraded routers, smartphones) using wireless communication technologies. On top of the ad-hoc networking, an upgraded router provides (1) personal computing capacities for low-latency offloading from mobile devices (aka cloudlet) using isolated lightweight containers; and (2) store-and-forward delay-tolerant data exchanges to serve as secure communication bridge for cooperation between involved or affected people (e.g., rescuers, civilians). We believe that upgrading ubiquitous routers is a very promising concept for a scalable ad-hoc networking and energy-efficient computing infrastructure in urban emergency situations.
Christian Meurisch, The An Binh Nguyen, Julien Gedeon, Florian Kohnhäuser, Milan Stute, Stefan Niemczyk, Stefan Wullkotte, Max Mühlhäuser
ICCCN4
2017 SEDCOS: A Secure Device-to-Device Communication System for Disaster Scenarios
abstract
During disasters, existing telecommunication infrastructures are often congested or even destroyed. In these situations, mobile devices can be interconnected using wireless ad hoc and disruption-tolerant networking to establish a backup emergency communication system for civilians and emergency services. However, such communication systems entail serious security risks, since adversaries may attempt to steal confidential data, fake notifications of emergency services, or perform denial-of-service (DoS) attacks. In this paper, we present SEDCOS, a secure device-to-device communication system for disaster scenarios. SEDCOS allows new users to join the network during disasters, mitigates flooding DoS attacks, and offers role revocation for detected adversaries to withdraw their permissions and exclude them from group communication. SEDCOS mitigates flooding DoS attacks and offers role revocation for detected adversaries to withdraw their permissions and exclude them from group communication. SEDCOS mitigates flooding DoS attacks and offers role revocation for detected adversaries to withdraw their permissions. We demonstrate the effectiveness of SEDCOS by large-scale network simulations.
Florian Kohnhäuser, Milan Stute, Lars Baumgärtner, Lars Almon, Stefan Katzenbeisser 0001, Matthias Hollick, Bernd Freisleben
LCN1
2017 NICER911: Ad-hoc Communication and Emergency Services Using Networking Smartphones and Wireless Home Routers
abstract
Reliable communication and emergency services are crucial for the success of crisis response and management. However, today's emergency technologies used by rescuers and civilians mainly rely on either centralized or specialized approaches, which reveal individual issues in infrastructure-less crisis scenarios. In this paper, we propose an emergency communication system called NICER911 that uses ad-hoc device-to-device communications enabling efficient data exchanges and delay-tolerant networking. On top of that, we integrate three types of emergency services allowing cooperations between rescuers and civilians: a social network, rescue instructions, and a self-rescue system. We implement a proof-of-concept prototype to show the feasibility, resource efficiency, and ease of use by preliminary quantitative and qualitative evaluations.
Christian Meurisch, The An Binh Nguyen, Stefan Wullkotte, Stefan Niemczyk, Florian Kohnhäuser, Max Mühlhäuser
MobiHoc5
2017 SCAPI: a scalable attestation protocol to detect software and physical attacks
abstract
Interconnected embedded devices are increasingly used in various scenarios, including industrial control, building automation, or emergency communication. As these systems commonly process sensitive information or perform safety critical tasks, they become appealing targets for cyber attacks. A promising technique to remotely verify the safe and secure operation of networked embedded devices is remote attestation. However, existing attestation protocols only protect against software attacks, or show limited scalability and robustness. In this paper, we present the first scalable attestation protocol that detects physical attacks. Based on the assumption that physical attacks require an adversary to capture and disable devices for a noticeable amount of time, our protocol identifies devices with compromised hardware and software. Compared to existing solutions, our protocol reduces communication complexity and runtimes by orders of magnitude, precisely identifies compromised devices, and is robust against failures or network disruptions. We show the security of our protocol and evaluate its scalability and robustness. Our results demonstrate that our protocol is highly efficient in well-connected networks and operates robust in disruptive and very dynamic network topologies.
Florian Kohnhäuser, Niklas Büscher, Sebastian Gabmeyer, Stefan Katzenbeisser 0001
WISEC1
2016 Secure Code Updates for Mesh Networked Commodity Low-End Embedded Devices
Florian Kohnhäuser, Stefan Katzenbeisser 0001
ESORICS (2)1