EDBT 2026 Demo / reviewers in the wild / expert
Lukas Jäger
dblp:204/4051 · also Lukas Jaeger
· DBLP profile ↗
12ranked-venue papers
4as first author
10since 2021 · last 2024
0000-0003-3695-7165ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 4 first-author · 9 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Acceleration of DICE Key Generation using Key CachingabstractDICE is a Trusted Computing standard intended to secure resource-constrained off-the-shelf hardware. It implements a Root of Trust that can be used to construct a Chain of Trust boot system, with symmetric keys representing firmware integrity and device identity. Based on this, asymmetric keys can be generated, but this slows down the boot process significantly as the keys need to be generated on every boot. Asymmetric keys provide multiple advantages when compared to symmetric ones, especially for updateable systems. This prevents the adoption of DICE in fields with strict boot time requirements, for example in the automotive context. Dominik Lorych, Lukas Jäger, Andreas Fuchs 0002 |
ARES | 2 |
| 2024 | Towards Practical Hardware Fingerprinting for Remote Attestation
Michael Eckel, Florian Fenzl, Lukas Jäger |
SEC | 3 |
| 2023 | Risk Assessments in Virtual Power Plants with NESCOR Criteria, Practical Application, Advantages and DisadvantagesabstractCyber security in the energy sector is paramount to the safe and reliable generation, transmission, and delivery of electrical energy. In the paradigm of the Virtual Power Plant, a structure which aggregates the output of multiple Distributed Energy Resources and connects to the grid as one entity, it is particularly challenging to prioritize those security controls and countermeasures that measurably improve its security posture. Assessing and framing cyber risk is critically important to enable such endeavors. The National Electric Sector Cybersecurity Organization Resource (NESCOR) has published an assessment framework for the energy sector as part of a study on failure scenarios. This paper presents the results of a practical application of this methodology with an adaptation to VPP specifics and illuminates some of the advantages and challenges present in the process. Georgios Gkoktsis, Hagen Lauer, Lukas Jäger |
ARES | 3 |
| 2023 | Secure Multi-User Contract Certificate Management for ISO 15118-20 Using Hardware IdentitiesabstractIn recent years, traditional mobility concepts have been increasingly transformed in favor of electric mobility and vehicle sharing concepts to combat pollutant emissions and inner-city traffic congestion. While the electric charging standard ISO 15118 with its Plug&Charge (PnC) concept eases the user experience by handling the complex billing process automatically during the charging, it is currently not suitable to the new multi-user mobility concepts since it does not define how to handle charging identities for multiple users per vehicle. With the Trusted Platform Module (TPM) 2.0 already part of the current ISO 15118-20 standard, we propose a new secure and standard-compliant multi-user contract certificate management system for ISO 15118-20 that utilizes the TPM in the vehicle as hardware trust anchor to handle multiple vehicle users. Our concept has little overhead to the current standard and introduces secure TPM-based multifactor authentication into ISO 15118-20, while maintaining the convenience benefits of PnC. Christian Plappert, Lukas Jäger, Alexander Irrgang, Chandrasekhar Potluri |
ARES | 2 |
| 2023 | Evaluating the applicability of hardware trust anchors for automotive applicationsabstractThe automotive trend towards autonomous driving and advanced connected services increases both complexity of the vehicle internal network and the connections to its environment. This introduced complexity further broadens the vehicle cyberattack surface. As mitigation strategy, state-of-the-art security mechanisms utilize so-called hardware trust anchors (HTAs) to protect security-sensitive data and processes in shielded locations that are isolated utilizing hardware security mechanisms. However, there is a variety of different HTAs with different functionality and security guarantees and there is currently no work done that compares and evaluates them against current and emerging automotive requirements. In this work, we evaluate the applicability of various HTAs to secure modern as well as upcoming future automotive applications. For this, we analyze and evaluate HTAs that are already established in the automotive field as well as promising HTAs from other domains. We extend our preliminary work [1] by increasing the range of the analyzed HTAs with solutions that are feasible for the most resource constrained automotive controllers and technologies that become feasible to be utilized by the introduction of high-performance controllers in future automotive architectures. We assess the different HTAs based on the evaluation criteria and in accordance to automotive requirements. Christian Plappert, Dominik Lorych, Michael Eckel, Lukas Jäger, Andreas Fuchs 0002, Ronald Heddergott |
Comput. Secur. | 4 |
| 2022 | A Resilient Network Node for the Industrial Internet of ThingsabstractThe Industrial Internet of Things (IIoT) is a ubiquitous part of modern production processes. This introduces new challenges to classical security architectures for industrial networks like the perimeter approach. These are made obsolete by the increasing horizontal and vertical integration of industrial systems and IT systems. A promising concept to face these challenges is resilience. This term describes systems or networks that can isolate compromised parts of themselves and reset them to a trustworthy state with minimal impact to the functionality of the overall system. In order to bring this concept to IIoT networks, we present a novel embedded network node that uses Trusted Computing technology such as a Trusted Platform Module (TPM) and Remote Attestation for attack detection and reporting, virtualization for the separation of processes with different criticalities and an authenticated watchdog for guaranteed platform resets as a form of return to an uncompromised state. This combination provides secure mechanisms for resilience on a platform level and can serve as a foundation for network resilience based on Software-Defined Networking (SDN) solutions. The architecture and implementation of the proposed network node are described in detail before evaluating its resource consumption and performance in order to demonstrate its suitability for embedded and IIoT contexts. Lukas Jäger, Dominik Lorych, Michael Eckel |
ARES | 1 |
| 2022 | Design Space Exploration of DICEabstractTrusted Computing aims to secure computer systems by ensuring that only trusted software is executed on the system, so that it behaves in expected ways. One of the approaches to this concept is the Device Identifier Composition Engine (DICE), which is specified by the Trusted Computing Group (TCG) as a solution for resource-limited devices. DICE is supposed to be a Root of Trust, which enables the implementation of a Chain of Trust on the device. It is designed for off-the-shelf hardware, such that it can be used on most modern micro-controllers. Therefore, it needs to be as minimal on resource usage as possible. Implementations until now were either focused on extending DICE with new concepts or implementing DICE with as little hardware as possible. Also they usually only implemented DICE on one single device. These factors limit the significance of their results for general DICE implementations as they mostly concentrate on evaluating their extended concepts and specific implementation features. This paper aims for the contrary, focusing more on general configuration and implementation details applicable to most DICE implementations than on specific aspects. We evaluated many different configurations for multiple devices and used these to give suggestions on possible configurations for different use cases. DICE is commonly used as he foundation to create a Chain of Trust, where firmware components get executed in sequential order. Usually a key generation component is used to generate purpose-bound keys after DICE, but specifics are application-dependent. We also implemented this component and to evaluate its key generation for different key configurations. Additionally, we implemented an example of Remote Attestation to show how the DICE architecture can be used. Dominik Lorych, Lukas Jäger |
ARES | 2 |
| 2022 | Towards a Privacy-Aware Electric Vehicle ArchitectureabstractConnected vehicles need to generate, store, process, and exchange a multitude of information with their environment. Much of this information is privacy-critical and thus regulated by privacy laws like the GDPR for Europe. In this paper, we analyze and rate exemplary data (flows) of the electric driving domain with regard to their criticality based on a reference architecture. We classify the corresponding ECUs based on their processed privacy-critical data and propose technical mitigation measures and technologies in form of generic privacy-enhancing building blocks according to the classification and requirements derived from the GDPR. Christian Plappert, Jonathan Stancke, Lukas Jäger |
PDP | 3 |
| 2021 | Remote Attestation Extended to the Analog DomainabstractOn embedded systems, Trusted Computing schemes can be used to detect manipulations of firmware. It is however not possible to detect a wide range of hardware manipulations such as passive listeners, active signal manipulations and circuit modifications. This work extends the Trusted Computing approach of detection through integrity measurement to the analog domain. It examines the step response of a circuit for its suitability as a component’s fingerprint. These fingerprints are combined with statistical comparison methods such as the Manhattan Distance or the Root Mean Square Error in order to provide a reliable fingerprint verification scheme. The fingerprinting and verification techniques are then combined with a remote attestation protocol based on the Device Identifier Composition Engine to yield a remote attestation scheme that covers both a device’s firmware and its peripheral hardware. This scheme is implemented and evaluated on a resource-constrained MCU in order to demonstrate its feasibility for embedded systems. Lukas Jäger, Dominik Lorych |
ARES | 1 |
| 2021 | Secure Role and Rights Management for Automotive Access and Feature ActivationabstractThe trend towards fully autonomous vehicles changes the concept of car ownership drastically. Purchasing a personal car becomes obsolete. Thus, business models related to feature activation are gaining even higher importance for car manufacturers in order to retain their customers. Various recent security incidents demonstrated however that vehicles are a valuable attack goal ranging from illegal access to car features to the theft of the whole vehicles. Christian Plappert, Lukas Jäger, Andreas Fuchs 0002 |
AsiaCCS | 2 |
| 2020 | DICE harder: a hardware implementation of the device identifier composition engineabstractThe specification of the Device Identifier Composition Engine (DICE) has been established as a minimal solution for Trusted Computing on microcontrollers. It allows for a wide range of possible implementations. Currently, most implementations use hardware that was not specifically designed for this purpose. These implementations are reliant on black box MPUs and the implementation process has certain pitfalls due to the use of hardware that was not originally designed for the use in DICE. Lukas Jäger, Richard Petri 0001 |
ARES | 1 |
| 2017 | Rolling DICE: Lightweight Remote Attestation for COTS IoT HardwareabstractThe specification Device Identity Composition Engine (DICE) provides a novel basis for remote attestations specifically suitable in the IoT context. Its purpose is to provide means for remote attestations to devices that are too size-, cost-, energy- or otherwise constrained to have Trusted Platform Module attached. Lukas Jäger, Richard Petri 0001, Andreas Fuchs 0002 |
ARES | 1 |