EDBT 2026 Demo / reviewers in the wild / expert
Norrathep Rattanavipanon
dblp:198/1339
· DBLP profile ↗
22ranked-venue papers
1as first author
10since 2021 · last 2026
0000-0003-1192-5079ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 13 · 1 first-author · 7 since 2021Systems, architecture and hardware · 8 · 2 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | HardaBLE: Hardening BLE Against Software CompromiseabstractBluetooth Low Energy (BLE) is a ubiquitous wireless technology used by billions of devices and defined in an open standard. The BLE specification defines two security protocols: pairing, which establishes a trust relationship between two devices by deriving the Long-Term Key (LTK), and session establishment, which generates a fresh encryption key for each (re)connection. The BLE security model and prior research primarily consider wireless-only adversaries. However, real deployments increasingly face software compromise, where an attacker exploits a vulnerability to gain arbitrary code execution or memory read/write capabilities on the device. Under such a compromise, an attacker can extract the LTK and use it to impersonate trusted devices or decrypt/forge protected traffic. Tommaso Sacchetti, Daniele Antonioli, Norrathep Rattanavipanon |
WISEC | 3 |
| 2025 | PEARTS: Provable Execution in Real-Time Embedded SystemsabstractEmbedded devices are increasingly ubiquitous and vital, often supporting safety-critical functions. However, due to strict cost and energy constraints, they are typically implemented with Micro-Controller Units (MCUs) that lack advanced architectural security features. Within this space, recent efforts have created low-cost architectures capable of generating Proofs of Execution (PoX) of software on potentially compromised MCUs. This capability can ensure the integrity of sensor data from the outset, by binding sensed results to an unforgeable cryptographic proof of execution on edge sensor MCUs. However, the security of existing PoX requires the proven execution to occur atomically (i.e., uninterrupted). This requirement precludes the application of PoX to (1) time-shared systems, and (2) applications with real-time constraints, creating a direct conflict between execution integrity and the real-time availability needs of several embedded system uses. In this paper, we formulate a new security goal called Real-Time Proof of Execution (RT-PoX) that retains the integrity guarantees of classic PoX while enabling its application to existing real-time systems. This is achieved by relaxing the atomicity requirement of PoX while dispatching interference attempts from other potentially malicious tasks (or compromised operating systems) executing on the same device. To realize the RT-PoX goal, we develop Provable Execution Architecture for Real-Time Systems (PEARTS). To the best of our knowledge, PEARTS is the first PoX system that can be directly deployed alongside a commodity embedded real-time operating system (FreeRTOS). This enables both real-time scheduling and execution integrity guarantees on commodity MCUs. To showcase this capability, we develop a PEARTS open-source prototype atop FreeRTOS on a single-core ARM Cortex- M33processor. Based on this prototype, we evaluate and report on PEARTS security and (modest) overheads. Antonio Joia, Norrathep Rattanavipanon, Ivan Oliveira Nunes |
SP | 2 |
| 2025 | Run-time Attestation and Auditing: The Verifier's PerspectiveabstractIn run-time attestation schemes, including Control Flow Attestation (CFA) and Data Flow Attestation (DFA), a remote Verifier (Vrf) requests a potentially compromised Prover device (Prv) to generate evidence of its execution control flow path (in CFA) and optionally execution data inputs (in DFA). Recent advances in this space also guarantee that Vrf eventually receives run-time evidence from Prv, even when Prv is fully compromised. Reliable delivery, in theory, enables run-time auditing in addition to attestation, allowing Vrf to examine run-time compromise traces to pinpoint/remediate attack root causes. However, Vrf's perspective in this security service remains unexplored, with most prior work focusing on the secure generation of authentic run-time evidence on Prv. Adam Caulfield, Norrathep Rattanavipanon, Ivan Oliveira Nunes |
WISEC | 2 |
| 2025 | SLAPP: Poisoning Prevention in Federated Learning and Differential Privacy via Stateful Proofs of ExecutionabstractThe rise of IoT-driven distributed data analytics, coupled with increasing privacy concerns, has led to a demand for effective privacy-preserving and federated data collection/model training mechanisms. In response, approaches such as Federated Learning (FL) and Local Differential Privacy (LDP) have been proposed and attracted much attention over the past few years. However, they still share the common limitation of being vulnerable to poisoning attacks wherein adversaries compromising edge devices feed forged (a.k.a. “poisoned”) data to aggregation back-ends, undermining the integrity of FL/LDP results. In this work, we propose a system-level approach to remedy this issue based on a novel security notion of Proofs of Stateful Execution ($\mathsf {PoSX}$) for IoT/embedded devices’ software. To realize the$\mathsf {PoSX}$concept, we design$\mathsf {SLAPP}$: a System-Level Approach for Poisoning Prevention.$\mathsf {SLAPP}$leverages commodity security features of embedded devices – in particular ARM TrustZone-M security extensions – to verifiably bind raw sensed data to their correct usage as part of FL/LDP edge device routines. As a consequence, it offers robust security guarantees against poisoning. Our evaluation, based on real-world prototypes featuring multiple cryptographic primitives and data collection schemes, showcases$\mathsf {SLAPP}$’s security and low overhead. Norrathep Rattanavipanon, Ivan Oliveira Nunes |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | TRACES: TEE-based Runtime Auditing for Commodity Embedded SystemsabstractControl Flow Attestation (CFA) offers a means to detect control flow hijacking attacks on remote devices, enabling verification of their runtime trustworthiness. CFA generates a trace (CFLog) containing the destination of all branching instructions executed. This allows a remote Verifier (Vrf) to inspect the execution control flow on a potentially compromised Prover (Prv) before trusting that a value/action was correctly produced/performed by Prv. However, while CFA can be used to detect runtime compromises, it cannot guarantee the eventual delivery of the execution evidence (CFLog) to Vrf. In turn, a compromised Prv may refuse to send CFLogto Vrf, preventing its analysis to determine the exploit’s root cause and appropriate remediation actions.In this work, we propose TRACES: TEE-based Runtime Auditing for Commodity Embedded Systems. TRACES guarantees reliable delivery of periodic runtime reports even when Prv is compromised. This enables secure runtime auditing in addition to best-effort delivery of evidence in CFA. TRACES also supports a guaranteed remediation phase, triggered upon compromise detection to ensure that identified runtime vulnerabilities can be reliably patched. To the best of our knowledge, TRACES is the first system to provide this functionality on commodity devices (i.e., without requiring custom hardware modifications). To that end, TRACES leverages support from the ARM TrustZone-M Trusted Execution Environment (TEE). To assess practicality, we implement and evaluate a fully functional (open-source) prototype of TRACES atop the commodity ARM Cortex-M33 micro-controller unit. Adam Caulfield, Antonio Joia, Norrathep Rattanavipanon, Ivan Oliveira Nunes |
ACSAC | 3 |
| 2024 | A Query Language to Enhance Security and Privacy of Blockchain as a Service (BaaS)
Nasrin Sohrabi, Norrathep Rattanavipanon, Zahir Tari |
ICSOC (2) | 2 |
| 2023 | $\mathcal{P}\text{ARseL}$: Towards a Verified Root-of-Trust Over seL4abstractWidespread adoption and growing popularity of embedded/IoT/CPS devices make them attractive attack targets. On low-to-mid-range devices, security features are typically few or none due to various constraints. Such devices are thus subject to malware-based compromise. One popular defensive measure is Remote Attestation$(\mathcal{R}\mathrm{A})$which allows a trusted entity to determine the current software integrity of an untrusted remote device. For higher-end devices,$\mathcal{R}\mathrm{A}$is achievable via secure hardware components. For low-end (bare metal) devices, minimalistic hybrid (hardware/-software)$\mathcal{R}\mathrm{A}$is effective, which incurs some hardware modifications. That leaves certain mid-range devices (e.g., ARM Cortex-A family) equipped with standard hardware components, e.g., a memory management unit (MMU) and perhaps a secure boot facility. In this space, seL4 (a verified microkernel with guaranteed process isolation) is a promising platform for attaining$\mathcal{R}\mathrm{A}$. HYDRA [1] made a first step towards this, albeit without achieving any verifiability or provable guarantees. This paper picks up where HYDRA left off by constructing a$\mathcal{P}\text{ARseL}$architecture, that separates all user-dependent components from the TCB. This leads to much stronger isolation guarantees, based on seL4 alone, and facilitates formal verification. In$\mathcal{P}\text{ARseL}$, We use formal verification to obtain several security properties for the isolated$\mathcal{R}\mathrm{A}$TCB, including: memory safety, functional correctness, and secret independence. We implement$\mathcal{P}\text{ARseL}$in$F^{\ast}$and specify/prove expected properties using Hoare logic. Next, we automatically translate the$F^{\ast}$implementation to C using KaRaM eL, which preserves verified properties of$\mathcal{P}\text{ARseL}$, C implementation (atop seL4). Finally, we instantiate and evaluate$\mathcal{P}\text{ARseL}$on a commodity platform - a SabreLite embedded device. Ivan Oliveira Nunes, Seoyeon Hwang, Sashidhar Jakkamsetti, Norrathep Rattanavipanon, Gene Tsudik |
ICCAD | 4 |
| 2023 | ACFA: Secure Runtime Auditing & Guaranteed Device Healing via Active Control Flow Attestation
Adam Caulfield, Norrathep Rattanavipanon, Ivan Oliveira Nunes |
USENIX Security Symposium | 2 |
| 2022 | ASAP: reconciling asynchronous real-time operations and proofs of execution in simple embedded systemsabstractEmbedded devices are increasingly ubiquitous and their importance is hard to overestimate. While they often support safety-critical functions (e.g., in medical devices and sensor-alarm combinations), they are usually implemented under strict cost/energy budgets, using low-end microcontroller units (MCUs) that lack sophisticated security mechanisms. Motivated by this issue, recent work developed architectures capable of generating Proofs of Execution (PoX) for the correct/expected software in potentially compromised low-end MCUs. In practice, this capability can be leveraged to provide "integrity from birth" to sensor data, by binding the sensed results/outputs to an unforgeable cryptographic proof of execution of the expected sensing process. Despite this significant progress, current PoX schemes for low-end MCUs ignore the real-time needs of many applications. In particular, security of current PoX schemes precludes any interrupts during the execution being proved. We argue that lack of asynchronous capabilities (i.e., interrupts within PoX) can obscure PoX usefulness, as several applications require processing real-time and asynchronous events. To bridge this gap, we propose, implement, and evaluate an Architecture for Secure Asynchronous Processing in PoX (ASAP). ASAP is secure under full software compromise, enables asynchronous PoX, and incurs less hardware overhead than prior work. Adam Caulfield, Norrathep Rattanavipanon, Ivan Oliveira Nunes |
DAC | 2 |
| 2021 | On the TOCTOU Problem in Remote AttestationabstractMuch attention has been devoted to verifying software integrity of remote embedded (IoT) devices. Many techniques, with different assumptions and security guarantees, have been proposed under the common umbrella of so-called Remote Attestation (RA). Aside from executable's integrity verification, RA serves as a foundation for many security services, such as proofs of memory erasure, system reset, software update, and verification of runtime properties. Prior RA techniques verify the remote device's binary at the time when RA functionality is executed, thus providing no information about the device's binary before current RA execution or between consecutive RA executions. This implies that presence of transient malware (in the form of modified binary) may be undetected. In other words, if transient malware infects a device (by modifying its binary), performs its nefarious tasks, and erases itself before the next attestation, its temporary presence will not be detected. This important problem, called Time-Of-Check-Time-Of-Use ( TOCTOU ), is well-known in the research literature and remains unaddressed in the context of hybrid RA. Ivan Oliveira Nunes, Sashidhar Jakkamsetti, Norrathep Rattanavipanon, Gene Tsudik |
CCS | 3 |
| 2020 | Towards Automated Augmentation and Instrumentation of Legacy Cryptographic Executables
Karim M. El Defrawy, Michael E. Locasto, Norrathep Rattanavipanon, Hassen Saïdi |
ACNS (2) | 3 |
| 2020 | APEX: A Verified Architecture for Proofs of Execution on Remote Devices under Full Software Compromise
Ivan Oliveira Nunes, Karim M. El Defrawy, Norrathep Rattanavipanon, Gene Tsudik |
USENIX Security Symposium | 3 |
| 2019 | PURE: Using Verified Remote Attestation to Obtain Proofs of Update, Reset and Erasure in low-End Embedded SystemsabstractRemote Attestation ( RA) is a security service that enables a trusted verifier ( Vrf) to measure current memory state of an untrusted remote prover ( Prv). If correctly implemented, RA allows Vrf to remotely detect if Prv's memory reflects a compromised state. However, RA by itself offers no means of remedying the situation once P rv is determined to be compromised. In this work we show how a secure RA architecture can be extended to enable important and useful security services for low-end embedded devices. In particular, we extend the formally verified RA architecture, VRASED, to implement provably secure software update, erasure, and system-wide resets. When (serially) composed, these features guarantee to Vrf that a remote Prv has been updated to a functional and malware-free state, and was properly initialized after such process. These services are provably secure against an adversary (represented by malware) that compromises Prv and exerts full control of its software state. Our results demonstrate that such services incur minimal additional overhead (0.4% extra hardware footprint, and 100-s milliseconds to generate combined proofs of update, erasure, and reset), making them practical even for the lowest-end embedded devices, e.g., those based on MSP430 or AVR ATMega micro-controller units (MCUs). All changes introduced by our new services to VRASED trusted components are also formally verified. Ivan Oliveira Nunes, Karim M. El Defrawy, Norrathep Rattanavipanon, Gene Tsudik |
ICCAD | 3 |
| 2019 | Towards Systematic Design of Collective Remote Attestation ProtocolsabstractNetworks of and embedded (IoT) devices are becoming increasingly popular, particularly, in settings such as smart homes, factories and vehicles. These networks can include numerous (potentially diverse) devices that collectively perform certain tasks. In order to guarantee overall safety and privacy, especially in the face of remote exploits, software integrity of each device must be continuously assured. This can be achieved by Remote Attestation (RA) - a security service for reporting current software state of a remote and untrusted device. While RA of a single device is well understood, collective RA of large numbers of networked embedded devices poses new research challenges. In particular, unlike single-device RA, collective RA has not benefited from any systematic treatment. Thus, unsurprisingly, prior collective RA schemes are designed in an ad hoc fashion. Our work takes the first step toward systematic design of collective RA, in order to help place collective RA onto a solid ground and serve as a set of design guidelines for both researchers and practitioners. We explore the design space for collective RA and show how the notions of security and effectiveness can be formally defined according to a given application domain. We then present and evaluate a concrete collective RA scheme systematically designed to satisfy these goals. Ivan Oliveira Nunes, Ghada Dessouky, Ahmad Ibrahim 0002, Norrathep Rattanavipanon, Ahmad-Reza Sadeghi, Gene Tsudik |
ICDCS | 4 |
| 2019 | VRASED: A Verified Hardware/Software Co-Design for Remote Attestation
Ivan Oliveira Nunes, Karim M. El Defrawy, Norrathep Rattanavipanon, Michael Steiner 0001, Gene Tsudik |
USENIX Security Symposium | 3 |
| 2019 | Remote Attestation via Self-MeasurementabstractRemote attestation (RA) is a popular means of detecting malware in embedded and IoT devices. RA is usually realized as an interactive protocol, whereby a trusted party ( verifier ) measures software integrity of a potentially compromised remote device ( prover) . Early work focused on purely software-based and fully hardware-based techniques, neither of which is ideal for low-end embedded devices. More recent results yielded hybrid (SW/HW) architectures with a minimal set of features to support efficient and secure RA on low-end devices. All prior techniques require on-demand operation , i.e., RA is performed in real time . We identify some drawbacks of this general approach in the context of unattended devices: First, it fails to detect mobile malware that enters and leaves prover between successive RA instances. Second, it requires prover to engage in a potentially expensive (in terms of time and energy) computation, which can be harmful for mission-critical or real-time devices. To address these drawbacks, we introduce the concept of self-measurement , whereby prover periodically and securely measures and records its own software state, based on a pre-established schedule. A (possibly untrusted) verifier occasionally collects and verifies these measurements. We present the design of a concrete technique, called Efficient Remote Attestation via Self-Measurement for Unattended Settings, (ERASMUS), justify its features and evaluate its performance. In the process, we also define a new metric, Quality of Attestation (QoA). We believe that ERASMUS is well suited for time-sensitive and/or safety-critical applications that are not served well by on-demand RA. Finally, we show that ERASMUS is a promising stepping stone toward handling attestation of multiple devices (i.e., a group or swarm) with high mobility. Xavier Carpent, Norrathep Rattanavipanon, Gene Tsudik |
ACM Trans. Design Autom. Electr. Syst. | 2 |
| 2018 | Temporal Consistency of Integrity-Ensuring Computations and Applications to Embedded Systems SecurityabstractAssuring integrity of information (e.g., data and/or software) is usually accomplished by cryptographic means, such as hash functions or message authentication codes (MACs). Computing such integrity-ensuring functions can be time-consuming if the amount of input data is large and/or the computing platform is weak. At the same time, in real-time or safety-critical settings, it is often impractical or even undesirable to guarantee atomicity of computing a time-consuming integrity-ensuring function. Meanwhile, standard correctness and security definitions of such functions assume that input data (regardless of its size) remains consistent throughout computation. However, temporal consistency may be lost if another process interrupts execution of an integrity-ensuring function and modifies portions of input that either or both: (1) were already processed, or (2) were not processed yet. Lack of temporal consistency might yield an integrity result that is non-sensical or simply incorrect. Such subtleties and discrepancies between (implicit) assumptions in definitions and implementations can be a source of inconsistenceies, which might lead to vulnerabilities. Xavier Carpent, Karim M. El Defrawy, Norrathep Rattanavipanon, Gene Tsudik |
AsiaCCS | 3 |
| 2018 | Reconciling remote attestation and safety-critical operation on simple IoT devicesabstractRemote attestation (RA) is a means of malware detection, typically realized as an interaction between a trusted verifier and a potentially compromised remote device (prover). RA is especially relevant for low-end embedded devices that are incapable of protecting themselves against malware infection. Most current RA techniques require on-demand and uninterruptible (atomic) operation. The former fails to detect transient malware that enters and leaves between successive RA instances; the latter involves performing potentially time-consuming computation over prover's memory and/or storage, which can be harmful to the device's safety-critical functionality and general availability. However, relaxing either on-demand or atomic RA operation is tricky and prone to vulnerabilities. This paper identifies some issues that arise in reconciling requirements of safety-critical operation with those of secure remote attestation, including detection of transient and self-relocating malware. It also investigates mitigation techniques, including periodic self-measurements as well as interruptible attestation modality that involves shuffled memory traversals and various memory locking mechanisms. Xavier Carpent, Karim M. El Defrawy, Norrathep Rattanavipanon, Ahmad-Reza Sadeghi, Gene Tsudik |
DAC | 3 |
| 2018 | ERASMUS: Efficient remote attestation via self-measurement for unattended settingsabstractRemote attestation (RA) is a popular means of detecting malware in embedded and IoT devices. RA is usually realized as a protocol via which a trusted verifier measures software integrity of an untrusted remote device called prover. All prior RA techniques require on-demand operation. We identify two drawbacks of this approach in the context of unattended devices: First, it fails to detect mobile malware that enters and leaves the prover between successive RA instances. Second, it requires the prover to engage in a potentially expensive computation, which can negatively impact safety-critical or real-time devices. To this end, we introduce the concept of self-measurement whereby a prover periodically (and securely) measures and records its own software state. A verifier then collects and verifies these measurements. We demonstrate a concrete technique called ERASMUS, justify its features, and evaluate its performance. We show that ERASMUS is well-suited for safety-critical applications. We also define a new metric — Quality of Attestation (QoA). Xavier Carpent, Gene Tsudik, Norrathep Rattanavipanon |
DATE | 3 |
| 2018 | ASSURED: Architecture for Secure Software Update of Realistic Embedded DevicesabstractSecure firmware update is an important stage in the Internet of Things (IoT) device life-cycle. Prior techniques, designed for other computational settings, are not readily suitable for IoT devices, since they do not consider idiosyncrasies of a realistic large-scale IoT deployment. This motivates our design of architecture for secure software update of realistic embedded devices (ASSURED), a secure and scalable update framework for IoT. ASSURED includes all stakeholders in a typical IoT update ecosystem, while providing end-to-end security between manufacturers and devices. To demonstrate its feasibility and practicality, ASSURED is instantiated and experimentally evaluated on two commodity hardware platforms. Results show that ASSURED is considerably faster than current update mechanisms in realistic settings. N. Asokan, Thomas Nyman, Norrathep Rattanavipanon, Ahmad-Reza Sadeghi, Gene Tsudik |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 3 |
| 2017 | Lightweight Swarm Attestation: A Tale of Two LISA-sabstractIn the last decade, Remote Attestation (RA) emerged as a distinct security service for detecting attacks on embedded devices, cyber-physical systems (CPS) and Internet of Things (IoT) devices. RA involves verification of current internal state of an untrusted remote hardware platform (prover) by a trusted entity (verifier). RA can help the latter establish a static or dynamic root of trust in the prover and can also be used to construct other security services, such as software updates and secure deletion. Various RA techniques with different assumptions, security features and complexities, have been proposed for the single-prover scenario. However, the advent of IoT brought about the paradigm of many interconnected devices, thus triggering the need for efficient collective attestation of a (possibly mobile) group or swarm of provers. Though recent work has yielded some initial concepts for swarm attestation, several key issues remain unaddressed, and practical realizations have not been explored. Xavier Carpent, Karim M. El Defrawy, Norrathep Rattanavipanon, Gene Tsudik |
AsiaCCS | 3 |
| 2017 | HYDRA: hybrid design for remote attestation (using a formally verified microkernel)abstractRemote Attestation (RA) allows a trusted entity (verifier) to securely measure internal state of a remote untrusted hardware platform (prover). RA can be used to establish a static or dynamic root of trust in embedded and cyber-physical systems. It can also be used as a building block for other security services and primitives, such as software updates and patches, verifiable deletion and memory resetting. There are three major types of RA designs: hardware-based, software-based, and hybrid, each with its own set of benefits and drawbacks. Karim M. El Defrawy, Norrathep Rattanavipanon, Gene Tsudik |
WISEC | 2 |