Darren Hurley-Smith

dblp:176/4563 · also Darren P. Smith · DBLP profile ↗
← Back
10ranked-venue papers
6as first author
6since 2021 · last 2024
0000-0002-9896-9308ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 4 first-author · 6 since 2021Computer networks · 1 · 1 first-author
YearPublicationVenuePosition
2024 Extracting Randomness from Nucleotide Sequencers for use in a Decentralised Randomness Beacon
abstract
This paper presents an investigation of nucleotide sequencing based random number generators, refutation of naive approaches to this problem, and a novel random number generator design based on the characteristics of nucleotide sequencers such as the Oxford Nanopore Technologies (ONT) MinION. Common issues include misunderstanding the statistical properties of nucleotide sequences and the provenance of entropy observed in post-processed sequences extracted from such data. We identify that the use of sequences, expressed as base-pair (ATCG) sequences, for random number generation is not possible. The process by which such sequences are observed and reported by scientific instrumentation, provide a means by which entropy associated with nucleotide sequences (or more correctly the act of observing and recording them) can be observed. We report a novel method of extracting entropy from the process of reading nucleotide sequences, as opposed to the nucleotide sequences themselves. We overcome the limitations and inherent bias of nucleotide sequences, to provide a source of randomness decoupled from biological data and records. A novel random number generator drawing on entropy extracted from nucleotide sequencing is presented with validation of its performance and characteristics.
Darren Hurley-Smith, Alastair P. Droop, Remy Lyon, Roxana Teodor
ARES1
2024 Revoke: Mitigating Ransomware Attacks Against Ethereum Validators
Alpesh Bhudia, Dan O'Keeffe, Darren Hurley-Smith
ESORICS (4)3
2023 Game Theoretic Modelling of a Ransom and Extortion Attack on Ethereum Validators
abstract
Consensus algorithms facilitate agreement on and resolution of blockchain functions, such as smart contracts and transactions. Ethereum uses a Proof-of-Stake (PoS) consensus mechanism, which depends on financial incentives to ensure that validators perform certain duties and do not act maliciously. Should a validator attempt to defraud the system, legitimate validators will identify this and then staked cryptocurrency is ‘burned’ through a process of slashing.
Alpesh Bhudia, Anna Cartwright 0001, Edward J. Cartwright, Darren Hurley-Smith, Julio César Hernández Castro
ARES4
2022 Sensitivity and uniformity in statistical randomness tests
Elena Almaraz Luengo, Marcos Brian Leiva Cerna, Luis Javier García Villalba, Darren Hurley-Smith, Julio César Hernández Castro
J. Inf. Secur. Appl.4
2022 On the Unbearable Lightness of FIPS 140-2 Randomness Tests
abstract
Random number generation is critical to many applications. Gaming, gambling, and particularly cryptography all require random numbers that are uniform and unpredictable. For testing whether supposedly random sources feature particular characteristics commonly found in random sequences, batteries of statistical tests are used. These are fundamental tools in the evaluation of random number generators and form part of the pathway to certification of secure systems implementing them. Although there have been previous studies into this subject (Becker, 2013), RNG manufacturers and vendors continue to use statistical tests known to be of dubious reliability, in their RNG verification processes. Our research shows that FIPS-140-2 cannot identify adversarial biases effectively, even very primitive ones. Concretely, this work illustrates the inability of the FIPS 140 family of tests to detect bias in three obviously flawed PRNGs. Deprecated by official standards, these tests are nevertheless still widely used, for example in hardware-level self-test schemes incorporated into the design of many True RNGs (TRNGs). They are also popular with engineers and cryptographers for quickly assessing the randomness characteristics of security primitives and protocols, and even with manufacturers aiming to market the randomness features of their products to potential customers. In the following, we present threebiased-by-designRNGs to show in explicit detail how simple, glaringly obvious biases are not detected by any of the FIPS 140–2 tests. One of these RNGs is backdoored, leaking key material, while others suffer from significantly reduced unpredictability in their output sequences. To make our point even more straightforward, we show how files containing images can also fool the FIPS 140 family of tests. We end with a discussion on the security issues affecting an interesting and active project to create a randomness beacon. Their authors only tested the quality of their randomness with the FIPS 140 family of tests, and we will show how this has led them to produce predictable output that, albeit passing FIPS fails other randomness tests quite catastrophically.
Darren Hurley-Smith, Constantinos Patsakis, Julio César Hernández Castro
IEEE Trans. Inf. Forensics Secur.1
2021 RansomClave: Ransomware Key Management using SGX
abstract
Modern ransomware often generate and manage cryptographic keys on the victim’s machine, giving defenders an opportunity to capture exposed keys and recover encrypted data without paying the ransom. However, recent work has raised the possibility of future enclave-enhanced malware that could avoid such mitigations using emerging support for hardware-enforced secure enclaves in commodity CPUs. Nonetheless, the practicality of such enclave-enhanced malware and its potential impact on all phases of the ransomware lifecyle remain unclear. Given the demonstrated capacity of ransomware authors to innovate in order to better extort their victims (e.g. through the adoption of untraceable virtual currencies and anonymity networks), it is important to better understand the risks involved and identify potential mitigations.
Alpesh Bhudia, Dan O'Keeffe, Daniele Sgandurra, Darren Hurley-Smith
ARES4
2020 Quantum Leap and Crash: Searching and Finding Bias in Quantum Random Number Generators
abstract
Random numbers are essential for cryptography and scientific simulation. Generating truly random numbers for cryptography can be a slow and expensive process. Quantum physics offers a variety of promising solutions to this challenge, proposing sources of entropy that may be genuinely unpredictable, based on the inherent randomness of certain physical phenomena. These properties have been employed to design Quantum Random Number Generators (QRNGs), some of which are commercially available. In this work, we present the first published analysis of the Quantis family of QRNGs (excluding AIS-31 models), designed and manufactured by ID Quantique (IDQ). Our study also includes Comscire’s PQ32MU QRNG, and two online services: the Australian National University’s (ANU) QRNG, and the Humboldt Physik generator. Each QRNG is analysed using five batteries of statistical tests: Dieharder, National Institute of Standards and Technology (NIST) SP800-22, Ent, Tuftests and TestU01, as part of our thorough examination of their output. Our analysis highlights issues with current certification schemes, which largely rely on NIST SP800-22 and Diehard tests of randomness. We find that more recent tests of randomness identify issues in the output of QRNG, highlighting the need for mandatory post-processing even for low-security usage of random numbers sourced from QRNGs.
Darren Hurley-Smith, Julio César Hernández Castro
ACM Trans. Priv. Secur.1
2018 Certifiably Biased: An In-Depth Analysis of a Common Criteria EAL4+ Certified TRNG
abstract
This paper reports the first in-depth analysis of the DESFire EV1's EAL4+ certified TRNG and raises some difficult questions regarding the certification of non-deterministic random number generators. We start by analyzing the quality of the purportedly true random number generator (TRNG) on the DESFire EV1 card. Clear and consistent biases are identified, despite good performance in most randomness tests. These statistical tests, commonly used in popular certification processes, such as Common Criteria EAL4+, are found not to be able to detect these anomalies. The means we employ for the detection and characterization of the bias are explored, highlighting both novel and existing ways of spotting deficient TRNG output. Further analysis shows systemic issues affecting TRNG output at the byte level, for which we have developed an accurate explanation. Our results have been acknowledged by the manufacturer, after responsible disclosure.
Darren Hurley-Smith, Julio César Hernández Castro
IEEE Trans. Inf. Forensics Secur.1
2017 SUPERMAN: Security Using Pre-Existing Routing for Mobile Ad hoc Networks
abstract
The flexibility and mobility of Mobile Ad hoc Networks (MANETs) have made them increasingly popular in a wide range of use cases. To protect these networks, security protocols have been developed to protect routing and application data. However, these protocols only protect routes or communication, not both. Both secure routing and communication security protocols must be implemented to provide full protection. The use of communication security protocols originally developed for wireline and WiFi networks can also place a heavy burden on the limited network resources of a MANET. To address these issues, a novel secure framework (SUPERMAN) is proposed. The framework is designed to allow existing network and routing protocols to perform their functions, whilst providing node authentication, access control, and communication security mechanisms. This paper presents a novel security framework for MANETs, SUPERMAN. Simulation results comparing SUPERMAN with IPsec, SAODV, and SOLSR are provided to demonstrate the proposed frameworks suitability for wireless communication security.
Darren Hurley-Smith, Jodie Wetherall, Andrew A. Adekunle
IEEE Trans. Mob. Comput.1
2014 A Cluster-Based Approach to Consensus Based Distributed Task Allocation
abstract
This paper presents a novel extension to the Consensus-Based Bundle Algorithm (CBBA), which we have named Cluster-Formed Consensus-Based Bundle Algorithm (CFCBBA). CF-CBBA is designed to reduce the amount of communication required to complete a distributed task allocation process, by partitioning the problem and processing it in parallel clusters. CF-CBBA has been shown, in comparison with baseline CBBA, to require less communication when allocating tasks. Three key aspects of task allocation have been investigated, (a) the time taken to allocate tasks, (b) the amount of communication necessary to satisfy the requirements of distributed task allocation algorithms such as CBBA, and (c) the efficiency with which a collection of tasks (a mission) is completed by a group of robots (a collective).
Darren Hurley-Smith, Jodie Wetherall, Stephen R. Woodhead, Andrew A. Adekunle
PDP1