Nikolaos A. Anagnostopoulos

dblp:177/2273 · also Nikolaos Athanasios Anagnostopoulos · DBLP profile ↗
← Back
15ranked-venue papers
3as first author
8since 2021 · last 2025
0000-0003-0243-8594ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 7 · 2 first-author · 5 since 2021Security and privacy · 6 · 2 since 2021Computer networks · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1
YearPublicationVenuePosition
2025 Achieving Error-Free Lightweight Authentication With DRAM-Based Physical Unclonable Functions
abstract
In this article, we introduce a novel approach to achieving lightweight device authentication through the use of a low-complexity Convolutional Neural Network (CNN). In our work, we improve the False Authentication Rate (FAR) by transforming the standard CNN into a Bayesian CNN (BCNN or BNN). This transformation enables the use of probabilistic modelling techniques, increasing the model’s robustness and its confidence in authentication decisions. Regardless of the model used, clients authenticate with a retention-based Dynamic Random Access Memory Physical Unclonable Function (DRAM PUF) response. Our approach integrates the low computational complexity of the CNN with the intrinsic security characteristics of the DRAM PUF, offering a robust solution for lightweight and secure device authentication.
Nico Mexis, Nikolaos A. Anagnostopoulos, Stefan Katzenbeisser 0001, Elif Bilge Kavun, Sara Tehranipoor, Tolga Arul
IEEE Trans. Circuits Syst. I Regul. Pap.2
2024 Investigation of Commercial Off-The-Shelf ReRAM Modules for Use as Runtime-Accessible TRNG
abstract
In this work, we analyse Commercial Off-The-Shelf (COTS) Resistive Random Access Memory (ReRAM) modules for their suitability to implement a novel runtime-accessible True Random Number Generator (TRNG). For this purpose, modules from two different manufacturers (Adesto Technologies and Fujitsu) were tested, which exhibited distinct characteristics under different conditions. If suitable parameters are selected, the proposed TRNG can successfully pass all the tests of both the NIST SP800-22 Statistical Test Suite and the NIST SP800-90B Entropy Source Test Suite at a wide range of temperatures. At the same time, the TRNG achieves a throughput of at least 28 bits per second under adverse temperature conditions and approximately 51 bits per second at room temperature, in the worst case. Therefore, the performance of the TRNG is sufficient for many practical applications such as security protocols for the Internet of Things (IoT) and in-vehicle networks [1], [2].
Tolga Arul, Nico Mexis, Aleena Elsa George, Florian Frank 0004, Nikolaos A. Anagnostopoulos, Stefan Katzenbeisser 0001
DSD5
2023 A Method to Construct Efficient Carbon-Nanotube-Based Physical Unclonable Functions and True Random Number Generators
abstract
In this work, we present a novel method of increasing the entropy of the CNT-PUF, a Physical Unclonable Function (PUF) based on Carbon-NanoTube Field Effect Transistors (CNT-FETs). The binary responses of this PUF are based on the drain current IDof each CNT-FET under the influence of a particular gate-source voltage VGS,which, through the employment of a single threshold value for ID,can indicate whether each relevant CNT cell of the array is conducting (acting either as a true conductor or as a semiconductor) or not (acting as an insulator). In this work, we propose the adoption of individual threshold values for each such cell as part of the relevant PUF challenge, thereby significantly increasing the overall entropy of this PUF, as well as the security that it can provide. Moreover, this method allows for the realisation of a source of higher entropy in the form of a True Random Number Generator (TRNG). Finally, we note that our work and its results are most probably also relevant for other CNT- based PUFs, structures, and primitives that utilise a single current (or even, voltage) threshold to determine the state of the different CNT cells utilised.
Nikolaos A. Anagnostopoulos, Nico Mexis, Simon Böttger, Martin Hartmann, Ali Wagdy Mohamed, Sascha Hermann, Stefan Katzenbeisser 0001, Stavros G. Stavrinides, Tolga Arul
DSD1
2023 Spatial Correlation in Weak Physical Unclonable Functions: A Comprehensive Overview
abstract
Physical Unclonable Functions (PUFs) are increasingly used in the process of securing applications. For this purpose, it is crucial that the PUF satisfies all the required properties adequately, including Unpredictability. An important aspect of Unpredictability is Randomness, which includes being free of spatial correlation effects. However, most methods for assessing randomness are not capable of detecting correlation, such that this aspect is often ignored. This work summarises the current literature to shed more light on the topic of analysing spatial correlation in weak PUFs, and evaluates the various methods proposed in the literature for detecting such effects. Additionally, the spatial correlation of a Dynamic Random Access Memory (DRAM) decay-based PUF implemented on the DRAM of a Raspberry Pi board, as well as that of a Carbon-NanoTube-based PUF (CNT-PUF), are examined, using, for the first time in the context of PUFs, not only other well-known metrics proposed in the relevant literature, but also the Getis-Ord G metric. Finally, a mitigation technique against attacks based on spatial auto-correlation is proposed and its effective application to PUF responses is discussed.
Nico Mexis, Tolga Arul, Nikolaos A. Anagnostopoulos, Florian Frank 0004, Simon Böttger, Martin Hartmann, Sascha Hermann, Elif Bilge Kavun, Stefan Katzenbeisser 0001
DSD3
2023 Abusing Commodity DRAMs in IoT Devices to Remotely Spy on Temperature
abstract
The ubiquity and pervasiveness of modern Internet of Things (IoT) devices opens up vast possibilities for novel applications, but simultaneously also allows spying on, and collecting data from, unsuspecting users to a previously unseen extent. This paper details a new attack form in this vein, in which the decay properties of widespread, off-the-shelf DRAM modules are exploited to accurately spy on the temperature in the vicinity of the DRAM-carrying device. Among others, this enables adversaries to remotely and purely digitally spy on personal behavior in users’ private homes, or to collect security-critical data in server farms, cloud storage centers, or commercial production lines. We demonstrate that our attack can be performed by merely compromising the software of an IoT device and does not require hardware modifications or physical access at attack time. It can achieve temperature resolutions of up to 0.5°C over a range of 0°C to 70°C in practice. The presented attack works in devices that do not have a dedicated temperature sensor on board; as the DRAM modules already present in the device are abused to spy on the temperature. To complete the work, the paper discusses practical attack scenarios as well as possible countermeasures against the new temperature-spying attacks.
Florian Frank 0004, Wenjie Xiong 0001, Nikolaos A. Anagnostopoulos, André Schaller, Tolga Arul, Farinaz Koushanfar, Stefan Katzenbeisser 0001, Ulrich Rührmair, Jakub Szefer
IEEE Trans. Inf. Forensics Secur.3
2022 Using Memristor Arrays as Physical Unclonable Functions
Florian Frank 0004, Tolga Arul, Nikolaos A. Anagnostopoulos, Stefan Katzenbeisser 0001
ESORICS (3)3
2022 ADR-Lite: A Low-Complexity Adaptive Data Rate Scheme for the LoRa Network
abstract
The long-range and low energy consumption re-quirements in Internet of Things (IoT) applications have led to a new wireless communication technology known as Low Power Wide Area Network (LPWANs). In recent years, the Long Range (LoRa) protocol has gained a lot of attention as one of the most promising technologies in LPWAN. Choosing the right combination of transmission parameters is a major challenge in the LoRa networks. In LoRa, an Adaptive Data Rate (ADR) mechanism is executed to configure each End Device's (ED) trans-mission parameters, resulting in improved performance metrics. In this paper, we propose a link-based ADR approach that aims to configure the transmission parameters of EDs by making a decision without taking into account the history of the last received packets, resulting in a relatively low space complexity approach. In this study, we present four different scenarios for assessing performance, including a scenario where mobile EDs are considered. Our simulation results show that in a mobile scenario with high channel noise, our proposed algorithm's Packet Delivery Ratio (PDR) is 2.8 times outperforming the original ADR and 1.35 times that of other relevant algorithms.
Reza Serati, Benyamin Teymuri, Nikolaos A. Anagnostopoulos, Mehdi Rasti
WiMob3
2021 A Lightweight Architecture for Hardware-Based Security in the Emerging Era of Systems of Systems
abstract
In recent years, a new generation of the Internet of Things (IoT 2.0) is emerging, based on artificial intelligence, the blockchain technology, machine learning, and the constant consolidation of pre-existing systems and subsystems into larger systems. In this work, we construct and examine a proof-of-concept prototype of such a system of systems, which consists of heterogeneous commercial off-the-shelf components, and utilises diverse communication protocols. We recognise the inherent need for lightweight security in this context, and address it by employing a low-cost state-of-the-art security solution. Our solution is based on a novel hardware and software co-engineering paradigm, utilising well-known software-based cryptographic algorithms, in order to maximise the security potential of the hardware security primitive (a Physical Unclonable Function) that is used as a security anchor. The performance of the proposed security solution is evaluated, proving its suitability even for real-time applications. Additionally, the Dolev-Yao attacker model is considered in order to assess the resilience of our solution towards attacks against the confidentiality, integrity, and availability of the examined system of systems. In this way, it is confirmed that the proposed solution is able to address the emerging security challenges of the oncoming era of systems of systems.
Nico Mexis, Nikolaos A. Anagnostopoulos, Jan Bambach, Tolga Arul, Stefan Katzenbeisser 0001
ACM J. Emerg. Technol. Comput. Syst.2
2020 Safety Meets Security: Using IEC 62443 for a Highly Automated Road Vehicle
Dominik Püllen, Nikolaos A. Anagnostopoulos, Tolga Arul, Stefan Katzenbeisser 0001
SAFECOMP2
2020 Low-cost Security for Next-generation IoT Networks
abstract
In recent years, the ubiquitous nature of Internet-of-Things (IoT) applications as well as the pervasive character of next-generation communication protocols, such as the 5G technology, have become widely evident. In this work, we identify the need for low-cost security in current and next-generation IoT networks and address this demand through the implementation, testing, and validation of an intrinsic low-cost and low-overhead hardware-based security primitive within an inherent network component. In particular, an intrinsic Physical Unclonable Function (PUF) is implemented in the peripheral network module of a tri-band commercial off-the-shelf router. Subsequently, we demonstrate the robustness of this PUF to ambient temperature variations and to limited natural aging, and examine in detail its potential for securing the next generation of IoT networks and other applications. Finally, the security of the proposed PUF-based schemes is briefly assessed and discussed.
Nikolaos A. Anagnostopoulos, Saad Ahmad, Tolga Arul, Daniel Steinmetzer, Matthias Hollick, Stefan Katzenbeisser 0001
ACM Trans. Internet Techn.1
2019 Spying on Temperature using DRAM
abstract
Today's ubiquitous IoT devices make spying on, and collecting data from, unsuspecting users possible. This paper shows a new attack where DRAM modules, widely used in IoT devices, can be abused to measure the temperature in the vicinity of the device in order to spy on a user's behavior. Specifically, the temperature dependency of the DRAM decay is used as a proxy for user's behavior in the vicinity of the device. The attack can be performed remotely by only changing the software of an IoT device, without requiring hardware changes, and with a resolution reaching 0.5°C. Potential defenses to the temperature spying attack are presented in this paper as well.
Wenjie Xiong 0001, Nikolaos A. Anagnostopoulos, André Schaller, Stefan Katzenbeisser 0001, Jakub Szefer
DATE2
2019 Decay-Based DRAM PUFs in Commodity Devices
abstract
A Physically Unclonable Function (PUF) is a unique and stable physical characteristic of a piece of hardware, which emerges due to variations in the hardware fabrication processes. Prior works have demonstrated that PUFs are a promising cryptographic primitive that can enable secure key storage, hardware-based device authentication and identification. So far, most PUF constructions have required an addition of new hardware or an FPGA implementation for their operation. Recently, intrinsic PUFs, which can be found in commodity devices, have been investigated. Unfortunately, most of them suffer from the drawback that they can only be accessed at boot time. This paper focuses on a new class of run-time accessible, decay-based, intrinsic DRAM PUFs in commercial off-the-shelf systems, which requires no additional hardware or FPGAs. In order to enable secure key storage using DRAM PUFs, this work presents a new Helper Data System (HDS) specifically tailored to the properties of the decay process inherent to DRAM cells. The decay-based DRAM PUF and the new HDS are evaluated on commodity off-the-shelf devices to demonstrate their practicality. Furthermore, a novel lightweight protocol is presented that allows for mutual authentication.
André Schaller, Wenjie Xiong 0001, Nikolaos A. Anagnostopoulos, Muhammad Umair Saleem, Sebastian Gabmeyer, Boris Skoric, Stefan Katzenbeisser 0001, Jakub Szefer
IEEE Trans. Dependable Secur. Comput.3
2018 Low-Temperature Data Remanence Attacks Against Intrinsic SRAM PUFs
abstract
In this work, we present the first systematic study of data remanence effects on an intrinsic Static Random Access Memory Physical Unclonable Function (SRAM PUF) implemented on a commercial off-the-shelf (COTS) device in the temperature range between –110 degrees Celsius and –40 degrees Celsius. Based on our experimental results, we propose a new type of attack against intrinsic SRAM PUFs, which takes advantage of data remanence effects exhibited due to low temperatures. We demonstrate that this attack is highly resistant to memory erasure techniques and can be used to manipulate the cryptographic keys produced by the SRAM PUF. Finally, we also discuss and assess potential countermeasures against the attack we propose.
Nikolaos A. Anagnostopoulos, Tolga Arul, Markus Rosenstihl, André Schaller, Sebastian Gabmeyer, Stefan Katzenbeisser 0001
DSD1
2018 Tracking Private Browsing Sessions using CPU-based Covert Channels
abstract
In this paper we examine the use of covert channels based on CPU load in order to achieve persistent user identification through browser sessions. In particular, we demonstrate that an HTML5 video, a GIF image, or CSS animations on a webpage can be used to force the CPU to produce a sequence of distinct load levels, even without JavaScript or any client-side code.
Nikolay Matyunin, Nikolaos A. Anagnostopoulos, Spyros Boukoros, Markus Heinrich, André Schaller, Maksim Kolinichenko, Stefan Katzenbeisser 0001
WISEC2
2016 Run-Time Accessible DRAM PUFs in Commodity Devices
Wenjie Xiong 0001, André Schaller, Nikolaos A. Anagnostopoulos, Muhammad Umair Saleem, Sebastian Gabmeyer, Stefan Katzenbeisser 0001, Jakub Szefer
CHES3