EDBT 2026 Demo / reviewers in the wild / expert
Harishma Boyapally
dblp:195/8125
· DBLP profile ↗
7ranked-venue papers
3as first author
6since 2021 · last 2026
0000-0002-2742-0772ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 3 first-author · 4 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Lightweight PUF-Based Secure Group Communication Scheme for Low Altitude Network With Dynamic Group MembershipabstractLow Altitude Network (LAN) has emerged as a critical infrastructure for applications such as surveillance and emergency response. Group communication for LAN offers enhanced energy efficiency and reduced network overhead. However, existing group communication protocols encounter difficulties in managing the rekeying process efficiently for a dynamic group or require computationally expensive public key primitives for shared secret handshaking to overcome this challenge. Moreover, the security of most of the existing protocols relies primarily on the safekeeping of some secrets on the group members' devices. To overcome these limitations, we propose a novel physical unclonable function (PUF)-based lightweight secure group communication protocol. The proposed protocol utilizes a combination of the device's PUF and the one-time pad (OTP) to eliminate secure key storage at both group verifier and prover nodes, and achieves perfect forward secrecy (PFS) by eliminating dependence on static long-term secrets. The proposed protocol also supports efficient group key renewal by using a full binary tree as a secret vault for sharing and updating distributed secrets with the Chinese Remainder Theorem (CRT). Meantime, this data structure also reduces the computation and communication complexity for key renewal to$O(\log _{2}N)$at the cluster head and$O(1)$at the sensor nodes. A comparative analysis shows that the proposed protocol surpasses related protocols in terms of security features and overheads in computation, communication, as well as secret storage requirements. The proposed protocol was also validated by formal security analyses and a physical LAN implementation using Ultra96-V2 boards as cluster nodes. Harishma Boyapally, Wenye Liu, Yongkui Yang, Chip-Hong Chang |
IEEE Trans. Mob. Comput. | 2 |
| 2025 | Pay What You Spend! Privacy-Aware Real-Time Pricing with High Precision IEEE 754 Floating Point Division
Soumyadyuti Ghosh, Harishma Boyapally, Ajith Suresh, Arpita Patra, Soumyajit Dey, Debdeep Mukhopadhyay |
AsiaCCS | 2 |
| 2023 | PReFeR : Physically Related Function based Remote Attestation ProtocolabstractRemote attestation is a request-response based security service that permits a trusted entity (verifier) to check the current state of an untrusted remote device (prover). The verifier initiates the attestation process by sending an attestation challenge to the prover; the prover responds with its current state, which establishes its trustworthiness. Physically Unclonable Function (PUF) offers an attractive choice for hybrid attestation schemes owing to its low overhead security guarantees. However, this comes with the limitation of secure storage of the PUF model or large challenge-response database on the verifier end. To address these issues, in this work, we propose a hybrid attestation framework, named PReFeR , that leverages a new class of hardware primitive known as Physically Related Function (PReF) to remotely attest low-end devices without the requirement of secure storage or heavy cryptographic operations. It comprises a static attestation scheme that validates the memory state of the remote device prior to code execution, followed by a dynamic run-time attestation scheme that asserts the correct code execution by evaluating the content of special registers present in embedded systems, known as hardware performance counters (HPC). The use of HPCs in the dynamic attestation scheme mitigates the popular class of attack known as the time-of-check-time-of-use (TOCTOU) attack, which has broken several state-of-the-art hybrid attestation schemes. We demonstrate our protocol and present our experimental results using a prototype implementation on Digilent Cora Z7 board, a low-cost embedded platform, specially designed for IoT applications. Anupam Mondal, Shreya Gangopadhyay, Durba Chatterjee, Harishma Boyapally, Debdeep Mukhopadhyay |
ACM Trans. Embed. Comput. Syst. | 4 |
| 2023 | Commitments via Physically Related FunctionsabstractCommitment schemes are one of the basic building blocks to construct secure protocols for multi party computation. Many recent works are exploring hardware primitives like physically unclonable functions to build keyless cryptographic protocols, with minimal assumptions. The asymmetric nature and non-invertibility property of PUFs are widely exploited to build oblivious transfer protocols that are extended to build bit-commitment schemes. However, these schemes require the physical transfer of the PUF device between the interacting parties. In this work, we introduce a new class of hardware-based primitives called physically related functions that enable hardware circuits to securely communicate with each other over insecure channels. We propose a bit-commitment protocol based on this hardware primitive without needing any physical transfer. Our scheme is statistically hiding and computationally binding, requiring only one round of communication while being practically deployable. We explore the security properties of physically related functions, under which we prove the security of our scheme. We experimentally show that it is impossible to break the security of the scheme with more than negligible probability. Harishma Boyapally, Sikhar Patranabis, Debdeep Mukhopadhyay |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2022 | Safe is the New Smart: PUF-Based Authentication for Load Modification-Resistant Smart MetersabstractIn the energy sector, IoT manifests in the form of next-generation power grids that provide enhanced electrical stability, efficient power distribution, and utilization. The primary feature of a Smart Grid is the presence of an advanced bi-directional communication network between the Smart meters at the consumer end and the servers at the Utility Operators. Smart meters are broadly vulnerable to attacks on communication and physical systems. We propose a secure and operationally asymmetric mutual authentication and key-exchange protocol for secure communication. Our protocol balances security and efficiency, delegates complex cryptographic operations to the resource-equipped servers, and carefully manages the workload on the resource-constrained Smart meter nodes using unconventional lightweight primitives such as Physically Unclonable Functions. We prove the security of the protocol using well-established cryptographic assumptions. We implement the proposed scheme end-to-end in a Smart meter prototype using commercial-off-the-shelf products, a Utility server, and a credential generator as the trusted third party. Additionally, we demonstrate a physics-based attack named load modification attack on the Smart meter to demonstrate that merely securing the communication channel using authentication does not secure the meter, but requires further protections to ensure the correctness of the reported consumption. Hence, we propose a countermeasure to such an attack that goes side-by-side with our protocol implementation. Harishma Boyapally, Paulson Mathew, Sikhar Patranabis, Urbi Chatterjee, Umang Agarwal, Manu Maheshwari, Soumyajit Dey, Debdeep Mukhopadhyay |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2022 | Physically Related Functions: Exploiting Related Inputs of PUFs for Authenticated-Key ExchangeabstractThis paper initiates the study of “Cryptophasia in Hardware” – a phenomenon that allows hardware circuits/devices with no pre-established secret keys to securely exchange secret information over insecure communication networks. The study of cryptophasia is motivated by the need to establish secure communication channels between lightweight resource-constrained devices incapable of securely storing cryptographic keys and/or executing resource-intensive cryptographic protocols. In this paper, we introduce a novel concept calledPhysically Related Functions(PReFs) that can exchange secret information in a secure and authenticated manner over insecure networks. This function can be visualized as an abstraction of Strong Physically Unclonable Functions (PUFs). Strong PUFs have the limitation in communicating between two identical devices, an issue that we address in the definition of PReFs. We describe a formal framework for analyzing the functional and security requirements of PReFs. In this framework, we present a lightweight (in terms of computation cost) yet provably secure authenticated key-exchange protocol that relies only on PReFs and makes no additional assumptions (such as secure storage of cryptographic keys). Finally, we present a proof-of-concept realization of PReFs in hardware over Digilent Cora Z7 – a low-cost development platform (consisting of an ARM Cortex processor and a Xilinx FPGA) that is particularly suitable for real-world IoT applications involving resource-constrained devices. We validate that our realization of PReFs satisfies all the properties warranted by our formal framework. We further demonstrate the efficacy of our proposed protocol by analyzing its performance (in terms of computational and communication latency) over the Digilent Cora Z7 platform. Durba Chatterjee, Harishma Boyapally, Sikhar Patranabis, Urbi Chatterjee, Aritra Hazra, Debdeep Mukhopadhyay |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2018 | POSTER: Authenticated Key-Exchange Protocol for Heterogeneous CPSabstractThe widespread advent of Cyber-Physical Systems~(CPS), intertwined with the Internet of Things~(IoT), allows billions of resource-constrained embedded devices to be connected at the same time. While this significantly enhances the scope for productivity, it also throws up security issues which, unless addressed, could lead to catastrophic consequences. The biggest challenge in an IoT network is to ensure inter-device authentication and secure key-exchange, while taking into account the heterogeneous nature of the participating devices in terms of processing capacity and memory bandwidth. In this paper, we propose a secure and operationally asymmetric authenticated key-exchange protocol targeting oT networks and CPS. Our protocol balances security and efficiency, delegates complex cryptographic operations to the resource-equipped servers, and carefully manages the workload on the resource- constrained nodes via the use of unconventional lightweight primitives such as Physically Unclonable Functions (PUFs). The security of our protocol is based on well-established cryptographic assumptions. Harishma Boyapally, Sikhar Patranabis, Urbi Chatterjee, Debdeep Mukhopadhyay |
AsiaCCS | 1 |