EDBT 2026 Demo / reviewers in the wild / expert
Yang Su 0001
dblp:17/686-1
· DBLP profile ↗
5ranked-venue papers
3as first author
3since 2021 · last 2023
0000-0002-4157-0021ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 3 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | NoisFre: Noise-Tolerant Memory Fingerprints from Commodity Devices for Security FunctionsabstractBuilding hardware security primitives with on-device memory fingerprints is a compelling proposition given the ubiquity of memory in electronic devices, especially for low-end Internet of Things devices for which cryptographic modules are often unavailable. However, the use of fingerprints in security functions is challenged by the small, but unpredictable variations in fingerprint reproductions from the same device due to measurement noise. Our study formulates a novel and pragmatic approach to achieve highly reliable fingerprints from device memories. We investigate the transformation of raw fingerprints into a noise-tolerant space where the generation of fingerprints is intrinsically highly reliable. We derive formal performance bounds to support practitioners to easily adopt our methods for applications. Subsequently, we demonstrate the expressive power of our formalization by using it to investigate the practicability of extracting noise-tolerant fingerprints from commodity devices. Together with extensive simulations, we have employed 119 chips from five different manufacturers for extensive experimental validations. Our results, including an end-to-end implementation demonstration with a low-cost wearable Bluetooth inertial sensor capable of on-demand and runtime key generation, show that key generators with failure rates less than$10^{-6}$can be efficiently obtained with noise-tolerant fingerprints with a single fingerprint snapshot to support ease-of-enrollment. Yansong Gao 0001, Yang Su 0001, Surya Nepal, Damith Chinthana Ranasinghe |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2023 | Wisecr: Secure Simultaneous Code Dissemination to Many Batteryless Computational RFID DevicesabstractEmerging ultra-low-power tiny scale computing devices run on harvested energy, are intermittently powered, have limited computational capability, and perform sensing and actuation functions under the control of a dedicated firmware operating without the supervisory control of an operating system. Wirelessly updating or patching firmware of such devices is inevitable. We consider the challenging problem of simultaneous and secure firmware updates or patching for a typical class of such devicesComputational Radio Frequency Identification (CRFID) devices. We propose Wisecr, the first secure and simultaneous wireless code dissemination mechanism to multiple devices that prevents malicious code injection attacks and intellectual property (IP) theft, whilst enabling remote attestation of code installation. Importantly, Wisecr is engineered to comply with existing ISO compliant communication protocol standards employed by CRFID devices and systems. We comprehensively evaluate Wisecr's overhead, demonstrate its implementation over standards compliant protocols, analyze its security, implement an end-to-end realization with popular CRFID devices and open-source the complete software package on GitHub. Yang Su 0001, Michael Chesser, Yansong Gao 0001, Alanson P. Sample, Damith Chinthana Ranasinghe |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2021 | SecuCode: Intrinsic PUF Entangled Secure Wireless Code Dissemination for Computational RFID DevicesabstractThe simplicity of deployment and perpetual operation of energy harvesting devices provides a compelling proposition for a new class of edge devices for the Internet of Things. In particular, Computational Radio Frequency Identification (CRFID) devices are an emerging class of battery free, computational, sensing enhanced devices that harvest all of their energy for operation. Despite wireless connectivity and powering, secure wireless firmware updates remains an open challenge for CRFID devices due to: intermittent powering, limited computational capabilities, and the absence of a supervisory operating system. We present,for the first time, asecurewireless code dissemination (SecuCode) mechanism for CRFIDs by entangling adevice intrinsic hardware security primitive—Static Random Access Memory Physical Unclonable Function (SRAM PUF)—to a firmware update protocol. The design of SecuCode: i) overcomes the resource-constrained and intermittently powered nature of the CRFID devices; ii) is fully compatible with existing communication protocols employed by CRFID devices—in particular, ISO-18000-6C protocol; and ii) is built upon a standard and industry compliant firmware compilation and update method realized by extending a recent framework for firmware updates provided by Texas Instruments. We build an end-to-end SecuCode implementation and conduct extensive experiments to demonstrate standards compliance, evaluate performance and security. Yang Su 0001, Yansong Gao 0001, Michael Chesser, Omid Kavehei, Alanson P. Sample, Damith Chinthana Ranasinghe |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2019 | Lightweight (Reverse) Fuzzy Extractor With Multiple Reference PUF ResponsesabstractA physical unclonable function (PUF), like a fingerprint, exploits manufacturing randomness to endow each physical item with a unique identifier. One primary PUF application is the secure derivation of volatile cryptographic keys using a fuzzy extractor (FE) comprising: 1) a secure sketch and 2) an entropy extractor. Although the entropy extractor can be lightweight, the overhead of the secure sketch responsible for correcting naturally noisy PUF responses is usually high. We observe that, in general, response unreliability with respect to an enrolled reference measurement increases with increasing differences between the in-the-field PUF operating condition and the operating condition used in evaluating the enrolled reference response. For the first time, we exploit such an inadvertent but important observation. In contrast to the conventional single reference response enrollment, we propose enrolling multiple reference responses (MRRs) subject to the same challenge but under multiple distinct operating conditions. The critical observation here is that one of the reference operating conditions is likely to be closer to the operating condition of the field deployed PUF, thus resulting in minimizing the expected unreliability when compared to the single reference under the nominal condition. As a consequence, MRR greatly reduces the demand for the expected number of erroneous bits requiring correction and, subsequently, achieves a significant reduction in the error correction overhead. The significant implementation efficiency gains from the proposed MRR method are demonstrated from software implementations of FEs on batteryless resource constraint computational radio frequency identification devices, where realistic PUF data are collected from intrinsic static random access memory PUFs. Yansong Gao 0001, Yang Su 0001, Lei Xu 0015, Damith Chinthana Ranasinghe |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2017 | USB Snooping Made Easy: Crosstalk Leakage Attacks on USB Hubs
Yang Su 0001, Daniel Genkin, Damith Chinthana Ranasinghe, Yuval Yarom |
USENIX Security Symposium | 1 |