Piet De Vaere

dblp:205/8958 · DBLP profile ↗
← Back
6ranked-venue papers
6as first author
4since 2021 · last 2024
0009-0004-2439-9770ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 4 first-author · 4 since 2021Computer networks · 2 · 2 first-author
YearPublicationVenuePosition
2024 The SA4P Framework: Sensing and Actuation as a Privilege
abstract
Popular consumer Internet of Things (IoT) devices provide increasingly diverse sensing and actuation capabilities. Despite their benefits, such devices prompt numerous security concerns. Typically, security is attained at device-level granularity, which relies upon device trustworthiness. However, if a device is compromised (e.g., via remote exploits), this approach fails. To this end, we construct SA4P: Sensing and Actuation as a Privilege, a framework that decouples IoT devices from their physical environment. In SA4P, whenever any software on a device wants to access a sensing or actuation peripheral, it must be authorized to do so. This is achieved by the inclusion of an on-board component, Peripheral Guard (PEG), that physically guards peripherals. Besides providing strong security guarantees, SA4P motivates developers to consider sensing and actuation as valuable resources. SA4P' design is modular, lightweight, and formally verified. It also does not require any hardware modifications for trusted execution environment (TEE)-equipped devices, while imposing only modest changes for other devices.
Piet De Vaere, Felix Stöger, Adrian Perrig, Gene Tsudik
AsiaCCS1
2023 Hey Kimya, Is My Smart Speaker Spying on Me? Taking Control of Sensor Privacy Through Isolation and Amnesia
Piet De Vaere, Adrian Perrig
USENIX Security Symposium1
2022 Hopper: Per-Device Nano Segmentation for the Industrial IoT
abstract
Today's industrial networks heavily rely on perimeter-based security. Although this has worked well in the past, the advent of the industrial IoT is blurring the network boundary, and thereby undermining the effectiveness of perimeter-based network defences. To address this, we propose Hopper: an industrial IoT security protocol that places each network host in its own access-controlled nano segment, thus minimizing the attack surface introduced by connecting devices to the network. Because Hopper enforces nano segmentation in-fabric, it does not require modifications to how packets are routed. Hopper achieves this by allowing each network node to verify that each packet it processes is part of a desired flow and was generated by an authorized host. Packets that fail any of these checks are dropped en route. By leveraging prevalent industrial network features, Hopper accomplishes low management and bandwidth overhead while being suitable for a wide range of networks. Our implementation on IoT-class hardware demonstrates that Hopper achieves high throughput and scalability, even in constrained environments.
Piet De Vaere, Andrea Tulimiero, Adrian Perrig
AsiaCCS1
2021 Tableau: Future-Proof Zoning for OT Networks
Piet De Vaere, Claude Hähni, Franco Monti, Adrian Perrig
CRITIS1
2019 Liam: An Architectural Framework for Decentralized IoT Networks
abstract
Today's IoT deployments commonly resemble walled gardens: they are closed ecosystems in which manufacturers maintain significant control over devices after they have been deployed. This is typically the result of a centralized design approach where devices heavily rely on a monolithic, vendor-operated cloud service. We propose a distributed architecture that liberates these devices-and their data-by considering IoT devices as first-class network citizens and by grouping them in trusted network zones. These network zones support the devices contained in them by allowing tasks to be delegated from the device to the zone. However, devices are considered to be independent by default, and a task is only delegated when it is impossible or undesirable for the device to perform this task itself. We demonstrate how our architecture allows for novel access-control methods and context-dependent network views.
Piet De Vaere, Adrian Perrig
MASS1
2018 Three Bits Suffice: Explicit Support for Passive Measurement of Internet Latency in QUIC and TCP
Piet De Vaere, Tobias Bühler, Mirja Kühlewind, Brian Trammell
Internet Measurement Conference1